<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=nextjs+remix+astro+choosing%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Fri, 31 Jul 2026 04:26:41 +0200</lastBuildDate>
<pubDate>Fri, 31 Jul 2026 04:26:41 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=nextjs+remix+astro+choosing%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=nextjs+remix+astro+choosing%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[An A.I. Music F.A.Q.: Can I Remix Madonna? Is This All Legal?]]></title>
<description><![CDATA[Advances in A.I. are making it possible to create all kinds of music from scratch, but they also raise questions about what is legal and who will actually listen.]]></description>
<link>https://tsecurity.de/de/3694746/ai-nachrichten/an-ai-music-faq-can-i-remix-madonna-is-this-all-legal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694746/ai-nachrichten/an-ai-music-faq-can-i-remix-madonna-is-this-all-legal/</guid>
<pubDate>Sat, 25 Jul 2026 19:49:53 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Advances in A.I. are making it possible to create all kinds of music from scratch, but they also raise questions about what is legal and who will actually listen.]]></content:encoded>
</item>
<item>
<title><![CDATA[🚨 HACKER SONG 2025 II (Remix): Der Code ist das Schlachtfeld – Schützt euch vor dem Cyber-Knall!]]></title>
<description><![CDATA[YouTube Video]]></description>
<link>https://tsecurity.de/de/3694538/it-security-video/hacker-song-2025-ii-remix-der-code-ist-das-schlachtfeld-schuetzt-euch-vor-dem-cyber-knall/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694538/it-security-video/hacker-song-2025-ii-remix-der-code-ist-das-schlachtfeld-schuetzt-euch-vor-dem-cyber-knall/</guid>
<pubDate>Sat, 25 Jul 2026 19:02:29 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>YouTube Video</p><p><iframe loading="lazy" src="https://www.youtube.com/embed/20v6mkqryJ8"></iframe></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cricut Explore 5 vs. Siser Romeo: Choosing the Right Smart Cutting Machine (2026)]]></title>
<description><![CDATA[Friendly hobby machine or serious production tool? Here’s how to know which one is for you.]]></description>
<link>https://tsecurity.de/de/3693840/it-nachrichten/cricut-explore-5-vs-siser-romeo-choosing-the-right-smart-cutting-machine-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693840/it-nachrichten/cricut-explore-5-vs-siser-romeo-choosing-the-right-smart-cutting-machine-2026/</guid>
<pubDate>Sat, 25 Jul 2026 13:13:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Friendly hobby machine or serious production tool? Here’s how to know which one is for you.]]></content:encoded>
</item>
<item>
<title><![CDATA[Building Premium Android Experiences at Google I/O ‘26]]></title>
<description><![CDATA[Posted by Ataul Munim, Android Developer Relations Engineer



  
    
  



  A truly differentiated Android experience is about delivering premium delight wherever your users are. At Google I/O ‘26, we showcased how the latest advancements in the Android ecosystem can help you elevate your app'...]]></description>
<link>https://tsecurity.de/de/3693509/android-tipps/building-premium-android-experiences-at-google-io-26/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693509/android-tipps/building-premium-android-experiences-at-google-io-26/</guid>
<pubDate>Sat, 25 Jul 2026 10:15:42 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhKGsnLX5Gwc9xouq7Q32ltvbL7xW_d4jnCXtoEFr7emB2wzqlZEuXM8FXe22ZPSguMX-nOrxAPYja6AYBZWxF-lKJYxw09D3f2aMyjxsSi5jinnDBjJPOIFDyqVhuJC2SjOqKHLAmstGg1nhyphenhyphenJGYfp3m71TPL_i3xFAUm6PKp3uo5WVytjoRwTIoNmMVQ/s4097/MM_Differentiated%20Experiences_Meta.png">

<div>
  <div class="separator"><em>Posted by Ataul Munim, Android Developer Relations Engineer</em></div>
</div>

<div class="separator">
  <a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjimB7lZHnz1Nqt-CPhoIzMWWup9qcJd2B3wzfmG2kX-4HwtnEfrSrp9J2e7aINQrh8SaPd_mP7DvY6nQiP_K2nEju5nOCwbTan-oVeZ8rmoW1R5CvErSIFXPeuIXS7LsB8TnZZee462-ygL5IbOZ2m_C3rAcXEiv08HrPjPrku0oB-T70JyXM6lmgxzmg/s4209/MM_Differentiated-Experiences_Blog%20(1).png">
    <img border="0" data-original-height="1253" data-original-width="4209" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjimB7lZHnz1Nqt-CPhoIzMWWup9qcJd2B3wzfmG2kX-4HwtnEfrSrp9J2e7aINQrh8SaPd_mP7DvY6nQiP_K2nEju5nOCwbTan-oVeZ8rmoW1R5CvErSIFXPeuIXS7LsB8TnZZee462-ygL5IbOZ2m_C3rAcXEiv08HrPjPrku0oB-T70JyXM6lmgxzmg/s16000/MM_Differentiated-Experiences_Blog%20(1).png">
  </a>
</div>

<div class="separator">
  A truly differentiated Android experience is about delivering premium delight wherever your users are. At Google I/O ‘26, we showcased how the latest advancements in the Android ecosystem can help you elevate your app's quality while maximizing development efficiency.
</div>

<div>
  <p>To help you build apps that stand out, we're diving into the key tools and libraries designed to optimize your core performance, extend the surfaces of your app to other devices, and streamline how your app handles high-quality media. </p>
  <p>Here is a recap of the essential updates and sessions you need to know to deliver a next-level experience across form factors!</p>
</div>

<div class="separator">
  
</div>

<h3>Maximize app performance and ROI with the R8 Configuration Analyzer</h3>
<p>A premium experience is only as good as its foundation, and a performant foundation is what allows your app to scale across the Android ecosystem. This is especially true with the release of Android 17, which introduces conservative, device RAM-based app memory limits to target extreme memory leaks and outliers before they cause system-wide instability. To stay below these new system thresholds and prevent your app from being terminated, having a lean footprint is no longer optional: it’s a critical requirement.</p>
<p>This year, we’re making it easier to build highly optimized, fast apps by introducing the <a href="https://developer.android.com/topic/performance/app-optimization/r8-configuration-analyzer" target="_blank">R8 Configuration Analyzer</a> in Android Studio. R8 is your most powerful tool for improving app performance, but its effectiveness is often limited by overly broad "keep rules" that prevent the compiler from stripping away unused code. The new Configuration Analyzer provides optimization, obfuscation, and shrinking scores, allowing you to identify specific rules that are preventing the benefits of R8 optimization.</p>
<p>By optimizing their R8 configurations, developers at Monzo achieved a 30% improvement in cold starts and a 35% reduction in ANRs. Smaller, faster code isn't just about efficiency; it's about ensuring your app has the memory headroom to deliver delight on every form factor, from the phone to the car.</p>

<div class="separator">
  
</div>

<h3>Extend your reach with a unified approach to Widgets on Phones, Watches and Cars</h3>
<p>User interaction is shifting toward quick, glanceable moments—short bursts of information that keep users connected without needing to open the full app. To help you increase the reach of your app content, we are unifying the development experience across the Android ecosystem with Jetpack Glance. By using a consistent, Compose-based model, you can elevate the content most important to your users straight to the phone’s home screen, Wear Widgets (previously Tiles!), and cars with a familiar workflow.</p>
<p>In order to help users engage with your content and features, even outside your app, we are making widgets more expressive and adaptive with RemoteCompose. On Wear OS, RemoteCompose allows you to use the Compose tools you’re already comfortable with to define UI logic that renders natively on remote surfaces, ensuring that your glanceable experiences remain highly performant and responsive even on resource-constrained hardware. On mobile and cars, RemoteCompose is used as a new framework giving Widgets new expressive capabilities.</p>
<p>You can use Jetpack Glance (together with RemoteCompose on Wear) to deliver a cohesive user journey. Whether it’s viewing flight status on the car dashboard, checking a gate change on a watch, or managing a boarding pass from a phone widget, this shared approach maximizes your app’s presence while keeping your development effort focused and efficient.</p>

<div class="separator">
  
</div>

<div>
  <h3>Supercharge your media pipeline with a complete, production-ready toolkit</h3>
  <div>Android has become a world-class home for the entire media lifecycle, and we are simplifying the journey from the first capture to the final playback. By leveraging Jetpack CameraX and Media3, you can build professional-grade experiences that feel native across the entire ecosystem. </div>
  <p>It starts with high-fidelity capture using the CameraXViewfinder Composable, which ensures your preview remains perfectly scaled and responsive on any form factor, including foldables and tablets. Use this to build adaptive capture experiences like a picture-in-picture view for multi-tasking, or that take advantage of modern features like high-frame-rate or slow-motion capture with CameraX v1.5.<br></p>
  <p>The new Media3 AI Effects library will provide a unified interface for premium features like Image &amp; Video Enhance, Magic Eraser, and Studio Sound. This allows you to focus on the creative intent while Media3 handles the heavy lifting of choosing the most efficient and reliable path for the device. Then, use the latest improvements in multi-asset editing with Media3 Transformer to composite your edited videos together!</p>
  <p>Complete the pipeline with tools designed for professional-grade export and viewing, including:</p>
  <ul>
    <li>CodecDB, which offers data-driven encoding recommendations tailored to specific chipsets, ensuring your exported videos maintain high visual quality with minimal noise or blurriness</li>
    <li>Scrubbing Mode in ExoPlayer to provide the buttery-smooth seeking experience users expect from premium media apps</li>
    <li>Enhanced Cast support with the new CastPlayer API in Media3</li>
  </ul>
  <p>By unifying these technical pillars, you can build a cohesive, high-performance media journey that delivers both delight for your users and high ROI for your development team.</p>
</div>

<div class="separator">
  
</div>

<p>For more details, check out the <i>premium</i> Android experience <a href="https://youtube.com/playlist?list=PLWz5rJ2EKKc8lSdmWQ_fSpV9yEGRvEL6S&amp;si=H6-8-AbtEyTqSxeY" target="_blank">YouTube playlist</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Prioritizing Memory Efficiency: Essential Steps for Android 17]]></title>
<description><![CDATA[Posted by Alice Yuan, Developer Relations Engineer, Ajesh Pai, Developer Relations Engineer, and Fung Lam, Developer Relations Engineer



    
        
    



    While app performance is often equated with a smooth UI and fast start times, memory serves as the silent foundation upon which thes...]]></description>
<link>https://tsecurity.de/de/3693508/android-tipps/prioritizing-memory-efficiency-essential-steps-for-android-17/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693508/android-tipps/prioritizing-memory-efficiency-essential-steps-for-android-17/</guid>
<pubDate>Sat, 25 Jul 2026 10:15:41 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhCIAoJpwUITPS5C3_eTksMsaslwqPk7SIEQHkwEkGv8572ccdIKcdv6kNC1BOSJPAZTgX5m3liMMv4zdK58e5dWRhUfo39uas23LuhEWf13TFnDTdw-Z5mWn4JarSnC8yCET8Sw15zSF-jQ5zwALriacGK6IjAGxNg61sFtSxzndjvqXxZtJt4qxuzd9A/s2048/Engineering-Memory-Blog-Meta-3.png">

<div class="separator">
    <em>Posted by Alice Yuan, Developer Relations Engineer, Ajesh Pai, Developer Relations Engineer, and Fung Lam, Developer Relations Engineer</em>
</div>

<div class="separator">
    <a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhanYZz4QpaDuwP7y_ZVGCUh6TpdQxS65pBcYr-Qkawd9YFS587tnIUPnqDROlxIXzgdz6GGxluR3LzH8ZabQPWz382FDEOEDpK3GxUFywn0A54JXFtUwDPaeI0JnFhEl-6NRrcjKeFPMLozNQv_An9OcWEUA-rmXfOhWvIKRrptdblGEZHERD0P-ynFcc/s4209/Engineering-Memory-Blog-3.png">
        <img border="0" data-original-height="1253" data-original-width="4209" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhanYZz4QpaDuwP7y_ZVGCUh6TpdQxS65pBcYr-Qkawd9YFS587tnIUPnqDROlxIXzgdz6GGxluR3LzH8ZabQPWz382FDEOEDpK3GxUFywn0A54JXFtUwDPaeI0JnFhEl-6NRrcjKeFPMLozNQv_An9OcWEUA-rmXfOhWvIKRrptdblGEZHERD0P-ynFcc/s16000/Engineering-Memory-Blog-3.png">
    </a>
</div>

<p>
    While app performance is often equated with a smooth UI and fast start times, memory serves as the silent foundation upon which these visible metrics are built. It's no secret that we're seeing a shift where device memory is more important than ever. Not only have we made strides in Android memory optimizations with Android 17, we're providing the tooling and API support to help you stay ahead of stricter memory requirements later this year.
</p>

<p>
    To ensure device stability, starting in Android 17, the system will begin enforcing app memory limits based on the device's total RAM. If an app exceeds those limits, Android will kill the process with no associated stack trace.
</p>

<div>
    Beyond these forced terminations, unoptimized memory usage inevitably degrades the user experience. When the app approaches heap memory limits, it triggers frequent garbage collection—leading to noticeable UI stutters. Furthermore, when a device runs out of available memory, the system scrambles to reclaim pages, causing CPU strain, UI latency, and battery drain. If the memory shortage is too severe, it can cause Low Memory Killer (LMK) events that abruptly terminate background processes and force apps to have slow cold starts and lose user state.
</div>

<div>
    <p>To build highly performant apps and avoid these forced terminations, we recommend that you adopt the following memory optimization strategies:</p>
    <ol>
        <li><a href="http://android-developers.googleblog.com/2026/06/prioritizing-memory-efficiency-steps-for-android-17.html#Maximize">Maximize bytecode optimization with R8</a></li>
        <li><a href="http://android-developers.googleblog.com/2026/06/prioritizing-memory-efficiency-steps-for-android-17.html#Optimize">Optimize image loading</a></li>
        <li><a href="http://android-developers.googleblog.com/2026/06/prioritizing-memory-efficiency-steps-for-android-17.html#Detect">Detect and fix memory leaks with Android Studio</a></li>
        <li><a href="http://android-developers.googleblog.com/2026/06/prioritizing-memory-efficiency-steps-for-android-17.html#Trim">Trim memory when app leaves visible state</a></li>
        <li><a href="http://android-developers.googleblog.com/2026/06/prioritizing-memory-efficiency-steps-for-android-17.html#Advanced">Advanced memory observability with ProfilingManager</a></li>
    </ol>
</div>
<br>
<div>
    <div class="separator">
        
    </div>
    <div>
        <em>A condensed version of this blog post is also available in video format, go check it out!</em>
    </div>
    
    <h3>Understanding Android 17 app memory limits</h3>
    <p>App memory limits are being introduced in Android 17 to prevent "one bad actor" from destroying the multitasking experience and stability of the user’s entire device.</p>
    <p>Here is a breakdown of the reasons driving this architectural change:</p>
    
    <div>
        <ul>
            <li><b>Preventing cascading kills:</b> When an app becomes bloated or leaks memory while holding a privileged state (e.g. it’s running a Foreground Service), it is initially shielded from the system's Low Memory Killer (LMK). As this single app grows unchecked and hoards RAM, the LMK is forced to compensate by killing off dozens of smaller, well-behaved cached apps and background jobs to reclaim space for the memory hog.</li>
            <li><b>Preserving multitasking and user state:</b> When the system is forced to purge cached apps to accommodate a single leaking process, the multitasking experience is severely degraded. Users returning to prior cached applications encounter sluggish cold starts instead of near-instant warm resumes. This inefficiency generates more CPU strain and accelerates battery depletion. It can also destroy the user’s context in recently used apps, such as scroll positions, navigation stacks, and in-game progress.</li>
        </ul>
        
        <div>
            <p>To determine if your app session was impacted by these constraints in the field, you can call <a href="https://developer.android.com/reference/android/app/ApplicationExitInfo#getDescription%28%29" target="_blank">getDescription()</a> within <a href="https://developer.android.com/reference/android/app/ApplicationExitInfo" target="_blank">ApplicationExitInfo</a>. If the system applied a limit, the exit reason is reported as <a href="https://developer.android.com/reference/android/app/ApplicationExitInfo#REASON_OTHER" target="_blank">REASON_OTHER</a> and the description string will contain "MemoryLimiter:AnonSwap". You can also leverage <a href="https://developer.android.com/topic/performance/tracing/profiling-manager/trigger-based-capture" target="_blank">trigger-based profiling</a> using <a href="https://developer.android.com/about/versions/17/features#anomaly-profiling-trigger" target="_blank">TRIGGER_TYPE_ANOMALY</a> to automatically capture heap dumps when the memory limit is reached. Furthermore, Android is actively working to surface more in-field memory metrics to developers within the Google Play Console.</p>
            <p>We have also expanded our <a href="https://developer.android.com/about/versions/17/behavior-changes-all#app-memory-limits" target="_blank">memory limits documentation</a> to include local debugging commands, allowing you to simulate memory constraints in your local environment and validate your application's behavior under any memory limit enforcement. </p>
        </div>
    </div>
</div>

<div>
    <h3>Maximize bytecode optimization with R8</h3>
    <p>A highly effective way to reduce your app's memory footprint is to enable the R8 optimizer. By shrinking classes, methods, and fields into shorter names and stripping out unused code and resources, R8 significantly reduces your app's memory footprint by minimizing the amount of resident code required during execution. </p>
    <p>R8 minimizes resident code, shrinking the memory footprint and lowering LMK termination risk. This results in more frequent warm starts over slow cold starts. Additionally, streamlined bytecode reduces main-thread CPU overhead, directly cutting ANR rates for a more fluid user experience. For example, the digital bank <a href="https://developer.android.com/blog/posts/monzo-boosts-performance-metrics-by-up-to-35-with-a-simple-r8-update" target="_blank">Monzo</a> enabled full R8 optimization and saw a 35% reduction in their ANR rate, a 30% improvement in cold start rate, and a 9% reduction in overall app size.</p>
</div>

<div class="separator">
    <a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhB61hi7-o6RYAHNOoIg1egyi6iU3iGtLbwfOb-s6r_PadBV2LZzvYtcdD00iwcApjnqmwOssOLFSHv8MG_es8WJWaJUPaO6rMY4ZcINSBFROo_1Di3LVMvIEhPldpzQsUOxV1Z7VfPwvej2fa9a7yCNwBdGOGw2LMLtPrCST6InlqF1xHds30rS76C9no/s2500/pic1-IO26_113_TSV-monzo-casestudy.jpg">
        <img border="0" data-original-height="1406" data-original-width="2500" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhB61hi7-o6RYAHNOoIg1egyi6iU3iGtLbwfOb-s6r_PadBV2LZzvYtcdD00iwcApjnqmwOssOLFSHv8MG_es8WJWaJUPaO6rMY4ZcINSBFROo_1Di3LVMvIEhPldpzQsUOxV1Z7VfPwvej2fa9a7yCNwBdGOGw2LMLtPrCST6InlqF1xHds30rS76C9no/s16000/pic1-IO26_113_TSV-monzo-casestudy.jpg">
    </a>
</div>
<div>
    <i>The digital bank <a href="https://developer.android.com/blog/posts/monzo-boosts-performance-metrics-by-up-to-35-with-a-simple-r8-update" target="_blank">Monzo</a> enabled full R8 optimization and boosted performance metrics by up to 35%.</i>
</div>

<div>
    <p>To properly configure R8 in your <code>build.gradle</code> file:</p>
    <ul>
        <li>Set <code>isShrinkResources = true</code> and <code>isMinifyEnabled = true</code>.</li>
        <li>Use <code>proguard-android-optimize.txt</code> instead of the legacy <code>proguard-android.txt</code>, which actually prevents optimizations and is no longer supported in Android Gradle Plugin 9.</li>
        <li>Remove <code>android.enableR8.fullMode = false</code> from your <code>gradle.properties</code>.</li>
    </ul>
    
    <p>
        If you are using reflection in your code base, then add <a href="https://developer.android.com/topic/performance/app-optimization/keep-rules-overview#where-to-add-rules" target="_blank">Keep rules</a> to prevent R8 from optimizing those parts of the code. Make sure to scope the keep rules narrowly to get the maximum optimization.
    </p>
    <p>To get the maximum optimization, make sure to follow these best practices in your keep rule file.</p>
    
    <ul>
        <li>Remove global options like <code>-dontoptimize</code>, <code>-dontshrink</code>, and <code>-dontobfuscate</code> that prevent R8 from optimizing the entire codebase </li>
        <li>Remove keep rules that prevent optimizing Android components like Activity, Services, Views or Broadcast receivers.</li>
        <li>Refine the broad package wide keep rules to target only specific classes or methods.</li>
    </ul>
    
    <p>To see more best practices, view our <a href="https://developer.android.com/topic/performance/app-optimization/keep-rules-best-practices" target="_blank">keep rules documentation</a>.</p>
    
    <h3>Library Developer R8 Best Practices</h3>
    <p>If you are a library developer, strictly place the rules your consumers need into your <code>consumer-rules</code> file, and keep your library's internal protection rules in your <code>proguard-rules.pro</code> file. For more information on how to optimize libraries, see <a href="https://developer.android.com/topic/performance/app-optimization/library-optimization" target="_blank">Optimization for library authors</a>.</p>
    
    <h3>R8 Configuration Analyzer</h3>
    <p>To audit your R8 optimization, use the <b><a href="http://developer.android.com/r8-analyzer" target="_blank">Configuration Analyzer</a></b>. Configuration analyzer shows the current state of optimization with Obfuscation, Optimization, and Shrinking scores. With configuration analyzer, you can also understand how many classes, methods or fields are prevented from optimization by each keep rule. Refine these broad package wide keep rules to unlock the maximum optimization.</p>
    <p>Using configuration analyzer, you can also identify keep rules that are subsuming other keep rules, redundant keep rules and unused keep rules.</p>
</div>

<div class="separator">
    <a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEib0dTmk8w7EYsDiV0Ufd8CAnpWz36-ZDC_gCGFkS_0CGz0axCxOy3RBxuaOoUbR4kzaeFBXryfSR2rkxRsmTXNrPtuJw8n1DTiZiKDqHjv3AaEXteE9TKV3QxYtwCztvY-8a0GpBlOZhVV1p0ftgdxeiKGGnO3dLu_IOt-TB_7j-ZnbR2jSr_CNYzh-bc/s2048/pic2-r8-config-analyzer.png">
        <img border="0" data-original-height="1156" data-original-width="2048" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEib0dTmk8w7EYsDiV0Ufd8CAnpWz36-ZDC_gCGFkS_0CGz0axCxOy3RBxuaOoUbR4kzaeFBXryfSR2rkxRsmTXNrPtuJw8n1DTiZiKDqHjv3AaEXteE9TKV3QxYtwCztvY-8a0GpBlOZhVV1p0ftgdxeiKGGnO3dLu_IOt-TB_7j-ZnbR2jSr_CNYzh-bc/s16000/pic2-r8-config-analyzer.png">
    </a>
</div>
<div>
    <i>The Configuration Analyzer shows the current state of optimization with Obfuscation, Optimization, and Shrinking scores.</i>
</div>

<div>
    <h4><span>R8 Agent Skill </span></h4>
    <p>You can also leverage the <b><a href="https://github.com/android/skills/tree/main/performance/r8-analyzer" target="_blank">R8 Agent Skill</a></b> with Android Studio agent or other AI tools to resolve misconfigurations and refine your rules resulting in improved app performance. <i>(Insights from AI-driven skills will require technical verification)</i></p>
</div>

<h3>Optimize image loading</h3>
<div>
    <p>Bitmaps are usually the largest common objects residing in your app's memory. They represent the final stage of the image loading process where compressed files, like JPEGs or PNGs, are decoded into raw pixel data for display. This means a tiny 100KB compressed image can balloon into several megabytes of RAM because memory consumption is determined by the image's pixel dimensions and color depth. Since bitmap operations are frequently on the critical path to drawing frames, unoptimized images cause severe memory bloat and UI jank.</p>
    <p>Google recommends leveraging image loading libraries <b><a href="https://github.com/coil-kt/coil" target="_blank">Coil</a></b> for Kotlin-first projects, particularly when developing with Jetpack Compose and <b><a href="https://github.com/bumptech/glide" target="_blank">Glide</a></b> for Java-based applications.</p>
    
    <h4><span>Adopt these five best practices</span></h4>
    <ol>
        <li><b>Downsample images:</b> If you’re loading bitmaps manually, avoid loading a massive image into a tiny thumbnail view; use <a href="https://developer.android.com/topic/performance/graphics/load-bitmap" target="_blank">inSampleSize</a> to load a smaller version. Glide and Coil downsamples images by default and you can configure this downsample strategy using <a href="https://bumptech.github.io/glide/javadocs/470/com/bumptech/glide/load/resource/bitmap/DownsampleStrategy.html" target="_blank">DownsampleStrategy</a> and <a href="https://coil-kt.github.io/coil/image_loaders/" target="_blank">ImageLoader</a> respectively.</li>
        <li><b>Cropping:</b> Avoid embedding padding directly into an image file for letterboxing purposes (e.g., creating a transparent border to expand an image dimensions). Rather than baking in these borders, utilize <a href="https://developer.android.com/reference/android/graphics/drawable/InsetDrawable" target="_blank">InsetDrawable</a> or apply padding directly within the View or Composable containing the bitmap.</li>
        <li><b>Config:</b> Balance memory and quality by choosing the right pixel format. Use <code>RGB_565</code> when transparency isn't needed, which uses half the memory of the default <code>ARGB_8888</code> format. In Glide you can configure this by using <a href="https://bumptech.github.io/glide/javadocs/470/com/bumptech/glide/load/DecodeFormat.html" target="_blank">DecodeFormat</a> and in Coil you can use <a href="https://coil-kt.github.io/coil/api/coil-core/coil3.request/-image-request/" target="_blank">bitmapConfig</a> property.</li>
        <li><b>Prioritize vector drawables:</b> For basic geometric assets, leverage <a href="https://developer.android.com/reference/android/graphics/drawable/ShapeDrawable" target="_blank">ShapeDrawable</a> as a lightweight alternative to decoding rasterized bitmaps. By defining these assets once via XML, you ensure they scale seamlessly across all display densities while effectively eliminating resource-driven memory bloat.</li>
        <li><b>Reuse:</b> If your application manages Bitmaps manually then to minimize memory churn, when a bitmap is no longer required, the app should call <code>bitmap.recycle()</code> and immediately discard the Bitmap reference. If you use an image loading library like Glide or Coil, return the bitmap to the library’s managed pool. By providing an existing buffer for future memory needs, the pool effectively avoids the overhead of new allocations.</li>
    </ol>
    
    <p>Check out our documentation on <a href="https://developer.android.com/develop/ui/compose/graphics/images/optimization" target="_blank">Optimizing performance for images</a> to learn more.</p>
    
    <h4><span>Android Studio tooling</span></h4>
    <p>You can also eliminate redundant bitmaps using Android Studio Narwhal 4. Here is how to hunt them down in five simple steps:</p>
    <ol>
        <li>Open the <b>Profiler</b> tab in Android Studio</li>
        <li>Click <b>Heap Dump</b> (or "Analyze Memory Usage") and hit record to take a snapshot of your app’s current memory state.</li>
        <li>Scan the analysis results for the <b>yellow warning triangle</b> ⚠️, which Android Studio uses to flag duplicate bitmaps being stored multiple times. Alternatively, navigate to the profiler header, choose "Filter by:" and pick the "Duplicate Bitmaps" setting.</li>
        <li>Click on any flagged entry to open the <b>Bitmap Preview</b> pane, allowing you to see exactly which image is the repeat offender.</li>
        <li>Use that visual confirmation to track down the redundant loading logic in your code and implement a better caching strategy.</li>
    </ol>
</div>

<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiDJ6djtozFY7DzrGB-EN8ajLVueF9MdLd4mod4jhtO8YwCzU7ObOwQ2w0Bap5A5NHJ7KVnXIRQqhW8cTdcFhMJPw5FIW1WU7D_Mwm-UC9Fsdr-MOn62xijpjKcS0NeUBnO957jmogGEISNQgeZQk3BVvUWK4BknTjLiuK2TbWCqwO3uTLkjkFhLwJre7w/s2379/pic3-IO26_113_TSV%20-dup-bitmaps-cropped.jpg"><img border="0" data-original-height="1162" data-original-width="2379" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiDJ6djtozFY7DzrGB-EN8ajLVueF9MdLd4mod4jhtO8YwCzU7ObOwQ2w0Bap5A5NHJ7KVnXIRQqhW8cTdcFhMJPw5FIW1WU7D_Mwm-UC9Fsdr-MOn62xijpjKcS0NeUBnO957jmogGEISNQgeZQk3BVvUWK4BknTjLiuK2TbWCqwO3uTLkjkFhLwJre7w/s16000/pic3-IO26_113_TSV%20-dup-bitmaps-cropped.jpg"></a></div><div class="separator"><i>Look for the yellow warning triangle ⚠️ in heap dumps when using the Android Studio Profiler.</i></div>

<h3>Detect and fix memory leaks with Android Studio</h3>
<p>Memory leaks in Android occur when your code holds onto an object's reference long after its lifecycle has ended. This prevents the Garbage Collector (GC) from reclaiming that memory, eventually leading to sluggish performance or OutOfMemoryError (OOM).</p>
<p>Android Studio Panda 3 features a dedicated <a href="https://square.github.io/leakcanary/" target="_blank">LeakCanary</a> profiler task, allowing developers to analyze real-time memory leaks and map traces within the IDE.</p>
<p>The LeakCanary profiler task in Android Studio actively moves the memory leak analysis from your device to your development machine, resulting in a significant performance boost during the leak analysis phase as compared to on-device leak analysis.</p>

<div class="separator">
    <a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjKBixtkwy1hzwA6mikjRX_6vBJ9OQ_RCYdF94HUF8kOLYzQoQrPMLh_6h9u6EGeLzgFc8yjxg3_8zlqWIDCvKa1py5gyxDXasl8JLPDHSEgPpzPyYqzcme69rRKtfIlhMtyNRWXutGXNy-4WcefhSTBhqBgobK678fqvNqL5peOz1UD6ouunLaKPmJCw0/s2048/pic4-android-studio-leaks.png">
        <img border="0" data-original-height="975" data-original-width="2048" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjKBixtkwy1hzwA6mikjRX_6vBJ9OQ_RCYdF94HUF8kOLYzQoQrPMLh_6h9u6EGeLzgFc8yjxg3_8zlqWIDCvKa1py5gyxDXasl8JLPDHSEgPpzPyYqzcme69rRKtfIlhMtyNRWXutGXNy-4WcefhSTBhqBgobK678fqvNqL5peOz1UD6ouunLaKPmJCw0/s16000/pic4-android-studio-leaks.png">
    </a>
</div>
<div>
    <i>LeakCanary memory leak analysis contextualized with <b>Go to declaration</b> for debugging</i>
</div>

<p>Additionally, the leak analysis is now contextualized within the IDE and fully integrated with your source code, providing features like go to declaration and other helpful code connections that drastically reduce the friction and time required to investigate and fix memory leaks.</p>

<div>
    <h4><span>Examples of common memory leaks </span></h4>
    <p>Memory leaks occur when an object persists in memory beyond its intended lifespan. This typically happens due to:</p>
    <ul>
        <li>Retaining references to Fragments, Activities, or Views that are no longer in use.</li>
        <li>Mismanaging Context references.</li>
        <li>Failing to properly unregister observers, listeners, and receivers.</li>
        <li>Creating static references to objects that are bound to components with shorter lifecycles.</li>
    </ul>
    
    <p>Here are a few example scenarios:</p>
    
    <div align="left" dir="ltr">
        <table>
            <colgroup>
                <col>
                <col>
                <col>
            </colgroup>
            <tbody>
                <tr>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Scenario</span></p>
                    </td>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Compose-based example</span></p>
                    </td>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">View-based example</span></p>
                    </td>
                </tr>
                <tr>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Leaking Context</span></p>
                    </td>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Example:</span><br><span face="'Google Sans',sans-serif">Passing LocalContext.current to a ViewModel</span></p>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Fix:</span><br><span face="'Google Sans',sans-serif">Keep <code>Context</code> dependent logic within the UI layer. For non-UI layers, refactor to use <a href="https://developer.android.com/training/dependency-injection">dependency injection</a> or observe UI state using <a href="https://developer.android.com/kotlin/flow">Kotlin flow</a>.</span></p>
                    </td>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Example:</span><br><span face="'Google Sans',sans-serif">Storing an <code>Activity</code> in a companion object or static variable.</span></p>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Fix:</span><br><span face="'Google Sans',sans-serif">Don’t hold static references to UI components. Refactor to use <a href="https://developer.android.com/training/dependency-injection">dependency injection</a> or observe UI state using <a href="https://developer.android.com/kotlin/flow">Kotlin flow</a>.</span></p>
                    </td>
                </tr>
                <tr>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Leaking Listeners</span></p>
                    </td>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Example:</span><br><span face="'Google Sans',sans-serif">Using <code>DisposableEffect</code> to start a listener but leaving <code>onDispose</code> empty.</span></p>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Fix:</span><br><span face="'Google Sans',sans-serif">Perform the unregistration and <a href="https://developer.android.com/develop/ui/compose/side-effects#disposableeffect">cleanup logic</a> inside the <code>onDispose</code> block.</span></p>
                    </td>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Example:</span><br><span face="'Google Sans',sans-serif">Registering for SensorManager updates and forgetting to unregister.</span></p>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Fix:</span><br><span face="'Google Sans',sans-serif">Manually call <code>unregisterListener()</code> in <code>onStop()</code> or <code>onDestroy()</code> lifecycle.</span></p>
                    </td>
                </tr>
                <tr>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Leaking Views</span></p>
                    </td>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Example:</span><br><span face="'Google Sans',sans-serif">Holding a reference to a legacy <code>View</code> inside an <code>AndroidView</code> without a release strategy.</span></p>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Fix:</span><br><span face="'Google Sans',sans-serif">Use the <code>release</code> block of the <code>AndroidView</code> composable to clean up the legacy <code>View</code>.</span></p>
                    </td>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Example:</span><br><span face="'Google Sans',sans-serif">Keeping a reference to a view binding object after the <code>Fragment</code> is destroyed.</span></p>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Fix:</span><br><span face="'Google Sans',sans-serif">Set the binding variable to <code>null</code> inside the <code>onDestroyView</code>() lifecycle method.</span></p>
                    </td>
                </tr>
            </tbody>
        </table>
    </div>
</div>

<h3>Trim memory when app leaves visible state</h3>
<p>Android can reclaim memory from your app or stop your app entirely if necessary to free up memory for critical tasks, as explained in <a href="https://developer.android.com/topic/performance/memory-overview" target="_blank">Overview of memory management</a>. Android will usually reclaim memory from your app when it’s not visible to the user, such as by discarding some of your app’s code and data pages in memory or compressing your heap allocations. When the user resumes your app and your app tries to access some memory that’s been reclaimed, the OS will swap that memory back in on demand. This swapping behavior can be slow, and cause unexpected jank or stutters in your app.</p>
<p>If you leave it to the OS to decide what memory to reclaim from your app, you may find that the OS reclaimed memory that you’ll need shortly after resuming your app. Instead, your app can voluntarily discard memory allocations that it can regenerate later, on demand and at a low cost. To do so, you can implement the <code>ComponentCallbacks2</code> interface. You can implement <code>onTrimMemory</code> in your <code>Activity</code>, <code>Fragment</code>, <code>Service</code>, or even your custom <code>Application</code> class. Using it in the <code>Application</code> class is highly effective for global cache management.</p>
<p>The provided <a href="https://developer.android.com/reference/android/content/ComponentCallbacks2#onTrimMemory(int)" target="_blank">onTrimMemory()</a> callback method notifies your app of lifecycle or memory-related events that present a good opportunity for your app to voluntarily reduce its memory usage.</p>
<p>In terms of memory lifecycle management, your implementation should focus <b>exclusively</b> on <code>TRIM_MEMORY_UI_HIDDEN</code> and <code>TRIM_MEMORY_BACKGROUND</code>. Since Android 14, the system has ceased delivering notifications for other legacy constants, which were formally deprecated in Android 15.</p>
<p><code>TRIM_MEMORY_UI_HIDDEN</code>: This signal indicates that your application's UI has transitioned out of the user's view. This provides an opportunity to release substantial memory allocations tied strictly to the interface—such as Bitmaps, video playback buffers, or complex animation resources.</p>
<p><code>TRIM_MEMORY_BACKGROUND</code>: At this level, your process is residing in the background and is now a candidate for termination to satisfy the system's global memory needs. To extend the duration your process remains in the cached state, and reduce the number of app cold starts, you should aggressively release any resources that can be easily reconstructed once the user resumes their session.</p>

<pre><code>import android.content.ComponentCallbacks2
// Other import statements.

class MainActivity : AppCompatActivity(), ComponentCallbacks2 {

    /**
     * Release memory when the UI becomes hidden or when system resources become low.
     * @param level the memory-related event that is raised.
     */
    override fun onTrimMemory(level: Int) {

        if (level &gt;= ComponentCallbacks2.TRIM_MEMORY_UI_HIDDEN) {
            // Release memory related to UI elements, such as bitmap caches.
        }

        if (level &gt;= ComponentCallbacks2.TRIM_MEMORY_BACKGROUND) {
            // Release memory related to background processing, such as by
            // closing a database connection.
        }
    }
}</code></pre>

<p>Note: The <code>onTrimMemory</code> integration may depend on SDK support. For instance, certain games rely on their game engine to enable this capability. Please check out the <a href="https://developer.android.com/games/optimize/memory-allocation" target="_blank">game memory optimization documents</a>.</p>

<h3>Advanced memory observability with ProfilingManager</h3>
<p>To catch and diagnose memory issues in the field that cannot be reproduced locally, you should leverage the <b>ProfilingManager API</b>. Introduced in Android 15, this advanced observability API allows you to programmatically collect real-user Perfetto profiles.</p>
<p>For teams that lack a dedicated infrastructure to manage and host performance artifacts, Crashlytics is exploring a specialized solution to streamline this workflow. They are inviting developers to <a href="https://docs.google.com/forms/d/e/1FAIpQLSe299a_zSNDfa164z7yyqoDjS05ZDRN86bAQKajuAOFEQ4G-w/viewform" target="_blank">provide feedback</a>.</p>

<p><b>Android 17 introduces new event-driven triggers</b>, most notably <code>TRIGGER_TYPE_OOM</code> and <code>TRIGGER_TYPE_ANOMALY</code>:</p>
<ul>
    <li>The <b>OOM trigger</b> automatically collects a Java heap dump at the exact moment an OutOfMemoryError crash occurs, providing precise allocation states. A collected OOM profile is provided the next time the app starts and registers the <code>registerForAllProfilingResults</code> callback.</li>
    <li>The <b>Anomaly trigger</b> detects severe performance issues, such as excessive binder spam or breached memory thresholds. The memory anomaly delivers a heap dump just prior to the system terminating the app.</li>
</ul>

<pre><code>  val profilingManager = 
applicationContext.getSystemService(ProfilingManager::class.java)
    val triggers = ArrayList<profilingtrigger>()  


    triggers.add(ProfilingTrigger.Builder(
                 ProfilingTrigger.TRIGGER_TYPE_ANOMALY))
    val mainExecutor: Executor = Executors.newSingleThreadExecutor()
    val resultCallback = Consumer<profilingresult> { profilingResult -&gt;
        if (profilingResult.errorCode != ProfilingResult.ERROR_NONE) {
            // upload profile result to server for further analysis          
            setupProfileUploadWorker(profilingResult.resultFilePath)
        } 

    profilingManager.registerForAllProfilingResults(mainExecutor, resultCallback)
    profilingManager.addProfilingTriggers(triggers)</profilingresult></profilingtrigger></code></pre>

<p>
    Once you’ve collected the heap dump, you can download the profile from the server, or locally via adb pull and drag and drop the file into the <a href="http://ui.perfetto.dev/" target="_blank">Perfetto UI</a>. To streamline your memory debugging workflow, use the <a href="https://perfetto.dev/docs/visualization/heap-dump-explorer" target="_blank">Heap Dump Explorer</a>, this is the new default view for heap dumps in Perfetto UI. This tool provides an intuitive interface for inspecting Java heap dumps, allowing you to visualize object allocation hierarchies, compute retained memory sizes, and identify the shortest path from garbage collection root. By leveraging the Heap Dump Explorer, you can rapidly pinpoint memory leaks, bloated retained objects such as excessive bitmap allocations, and analyze heap object allocations all in one place.
</p>

<div class="separator">
    <a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhobASfyUbXdAYD_MOjREv7RUhCwoNJ9sB4QDSImRfA0UrALJqwQ2ovgAF7YRt3f26UeZoIQa-yDxiSDO84gxv1XkQ8acf8E795-IgAe4tl8AM_7m7nSEuj7t_rhtpgM3f-76_lEh-k7Rltku79-VCuIDN_2Q9DRjJyouCKbxg4pDXHV2yey7V8WlG2jQM/s2048/pic5-perfettoheapdump-analyzer.png">
        <img border="0" data-original-height="1039" data-original-width="2048" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhobASfyUbXdAYD_MOjREv7RUhCwoNJ9sB4QDSImRfA0UrALJqwQ2ovgAF7YRt3f26UeZoIQa-yDxiSDO84gxv1XkQ8acf8E795-IgAe4tl8AM_7m7nSEuj7t_rhtpgM3f-76_lEh-k7Rltku79-VCuIDN_2Q9DRjJyouCKbxg4pDXHV2yey7V8WlG2jQM/s16000/pic5-perfettoheapdump-analyzer.png">
    </a>
</div>
<div>
    <i>Use the <a href="https://perfetto.dev/docs/visualization/heap-dump-explorer">Heap Dump Explorer</a>’s embedded flamegraph to visually inspect and navigate through objects with the highest heap allocations.</i>
</div>

<h3>Conclusion</h3>
<p>Optimizing bytecode with R8, adopting image loading best practices, and resolving memory leaks are critical steps toward delivering a high-quality user experience while managing resources effectively under pressure. Adopting these proactive measures helps maintain app stability and performance, preventing unexpected terminations while safeguarding user context. To further your performance expertise, explore our revised <a href="https://developer.android.com/topic/performance/memory" target="_blank">memory guidance</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hacks.Mozilla.Org: PACT: Anonymous Credentials for the Web]]></title>
<description><![CDATA[This is the technical companion to our update on Distilled, “Keeping the web open and private in the bot era.” Here we take a deeper look at the problem space, the design we’re proposing, and the problems still left to solve. 
Bots (and privacy-preserving browsers) not welcome 
Browse a news site...]]></description>
<link>https://tsecurity.de/de/3693291/tools/hacksmozillaorg-pact-anonymous-credentials-for-the-web/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693291/tools/hacksmozillaorg-pact-anonymous-credentials-for-the-web/</guid>
<pubDate>Sat, 25 Jul 2026 08:37:27 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class="c43"><em><span class="c11 c1">This is the technical companion to our update on Distilled, </span><span class="c11 c1 c17"><a class="c5" href="https://blog.mozilla.org/en/privacy-security/keeping-the-web-open-and-private-in-the-bot-era/">“Keeping the web open and private in the bot era.”</a></span><span class="c11 c1"> Here we take a deeper look at the problem space, the design we’re proposing, and the problems still left to </span><span class="c1 c11">solve</span></em><span class="c13 c11 c1"><em>.</em> </span></p>
<h3 class="c24"><span class="c2 c1">Bots (and privacy-preserving browsers) not welcome </span></h3>
<p class="c40"><span class="c0">Browse a news site in a private window. Shop at a major retailer with a VPN. Visit a video streaming platform with anti-fingerprinting defenses tuned up. You’ll see the same responses: registration walls, block pages, and endless CAPTCHAs. The message is clear: </span><span class="c13 c11 c1">if we think you might be a bot, you’re not welcome</span><span class="c0">. </span></p>
<p class="c53"><span class="c0">Websites have valid reasons for wanting to block bots. Bots enable volumetric abuse</span><span class="c1">, abuse that wouldn’t otherwise be feasible if they had to be carried out by humans</span><span class="c0">. </span><span class="c0"> For example</span><span class="c1">: SEO comment spam, credential stuffing and DDoSing</span><span class="c0">.</span><span class="c0"> Consequently many sites employ dedicated anti-abuse tooling which aims to keep the bots out whilst minimizing friction for human visitors. </span></p>
<p class="c21"><span class="c0">Unfortunately, that tooling is increasingly failing at both tasks. Browser privacy protections are </span><span class="c3 c1"><a class="c5" href="https://blog.mozilla.org/en/firefox/fingerprinting-protections/">dismantling</a></span><span class="c0"> the passive signals that anti-abuse systems depended on to identify and distinguish </span><span class="c0">visitors</span><span class="c0">. Meanwhile advances in generative AI have rendered CAPTCHAs ineffective: bots now solve them </span><span class="c3 c1"><a class="c5" href="https://www.usenix.org/system/files/usenixsecurity23-searles.pdf">faster and more reliably</a></span><span class="c0"> than </span><span class="c0">humans</span><span class="c0">. </span></p>
<p class="c33"><span class="c0">Many sites are switching to more invasive mechanisms and now ask visitors to disclose </span><span class="c1">identifying information</span><span class="c0">,</span><span class="c0"> e.g. an email address, a federated login or </span><span class="c1">disabling their VPN</span><span class="c0">. This means greater friction for users, since providing these details on a first visit takes time. It also compromises their privacy, since these details enable the same kinds of cross-site tracking that browser privacy protections were intended to mitigate. </span></p>
<p class="c38"><span class="c0">This </span><span class="c1">leaves</span><span class="c0"> users </span><span class="c1">with a</span><span class="c0"> dilemma. The more effectively they protect their privacy, the harder it is for websites to distinguish them from bots and the worse the treatment they receive. Website operators are also suffering. The additional friction they inflict upon well-behaved visitors harms their site, but many are willing to pay the costs if it mitigates volumetric abuse. </span></p>
<p class="c44"><span class="c1">Browser-based AI agents make this tension more acute. Sites may want to allow agents which are acting on behalf of individual users while blocking agents engaged in volumetric abuse. However, with no effective mechanisms to distinguish the two, websites are opting to block </span><span class="c17 c1"><a class="c5" href="https://dl.acm.org/doi/epdf/10.1145/3730567.3732913">both</a></span><span class="c0">. That hurts users, who should be free to choose the user agent they use to access the web; it hurts new browsers and agents, which struggle to interoperate; and it hurts sites, which lose legitimate visitors.</span></p>
<p class="c30"><span class="c0">The consequence is that the web gets worse for everyone. Users get more friction or less privacy or both. Website operators see more volumetric abuse and the friction they add drives away users </span><span class="c1">who</span><span class="c0"> would otherwise want to consume their content or services. New user</span><span class="c1"> </span><span class="c0">agents struggle to access the same content as conventional browsers. </span></p>
<h3 class="c12"><span class="c20 c1">The</span><span class="c20 c1"> Costs of </span><span class="c2 c1">Convenient</span><span class="c2 c1"> Solutions</span></h3>
<p class="c9"><span class="c0">Some large ecosystem players have put forward solutions that leverage their control of the dominant operating systems and their deep integration with consumer hardware. These rely on device attestation: identifiers and privileged code baked into devices at the hardware level, which let manufacturers prove what software is running on a user’s device. Exposing this functionality to the web means attesting to sites that the user is running approved software with trusted hardware and therefore isn’t a bot. There have been two substantive proposals.</span></p>
<p class="c9"><span class="c0">Google’s Web Environment Integrity, <a href="https://www.theregister.com/software/2023/11/02/google-abandons-web-environment-integrity-api-proposal/335969">abandoned in 2023</a>, was the blunt version. It attested to the user agent itself, as well as the operating system and device in use. Users would have lost control in two ways: once to the attester, which would decide which operating systems and devices could be blessed, and again to the website, which would decide which software to accept. If sites had adopted allow-lists of approved user agents, building a new browser would have become virtually impossible, and sites could have withdrawn access from any user agent they chose.</span></p>
<p class="c9"><span class="c0">Apple’s Private Access Tokens, <a href="https://developer.apple.com/news/?id=huqjyh7k">deployed</a> across their ecosystem in 2022, have more subtle issues. Built on the Privacy Pass protocol standardized at the IETF, they get a lot right: a user receives a renewed, limited batch of one-time tokens that can be presented to websites without linking their visits together. This provides privacy for users and has shown rate limits to be an effective tool for sites – both points we’ll return to later in this post.</span></p>
<p class="c9"><span class="c1">However, Private Access Tokens rely on device attestation, requiring that the hardware manufacturer be in overall control of the user’s device. Presenting a PAT tells a website you are locked into Apple’s rules for what counts as acceptable software. </span><span class="c1">Due to PAT’s technical design</span><sup class="c1"><a href="https://hacks.mozilla.org/?p=48374#:~:text=PAT%20requires">[1]</a></sup><span class="c1">, there’s no way to open the system to other sources of scarcity without compromising the system’s privacy properties, meaning that if more widely deployed, access to the web would</span><span class="c1"> become tied to having bought expensive hardware from a small, hard to change set of vendors</span><span class="c1">. </span></p>
<p class="c9"><span class="c1">Both approaches are ultimately hostile to users and to the openness of the web. Both are premised on parts of a user’s device that sit within the manufacturer’s control and beyond the user’s own. Were they widely deployed, the web would become just another walled garden with centralized gatekeepers controlling acceptable hardware, operating systems and software. As convenient as these solutions are for the players who already dominate the ecosystem, we think there’s a better path.</span></p>
<h3 class="c24"><span class="c2 c1">A Better Path Forward </span></h3>
<p class="c24"><span class="c1">Bots’ harms arise from their ability to operate beyond human scale. For sites to prevent volumetric abuse they</span><span class="c0"> don’t actually need to know </span><span class="c1">the user’s</span><span class="c0"> identity or </span><span class="c1">receive cryptographic</span><span class="c0"> proof that they’re running approved softwar</span><span class="c1">e. If sites knew their visitors were restricted to a rate </span><span class="c1">limit</span><span class="c1"> set by a site, that would be enough.  </span></p>
<p class="c34"><span class="c1">Rate limits</span><span class="c0"> only make sense if </span><span class="c1">they’re</span><span class="c0"> </span><span class="c1">tied to</span><span class="c0"> something scarce; something an attacker can’t cheaply replicate to evade the limit. </span><span class="c0">Without anchoring to a scarce resource, like the trusted hardware used in Private Access Tokens, attackers can generate as many fresh identities as they need to bypass the rate limit. </span></p>
<p class="c56"><span class="c1">However, </span><span class="c0">hardware is just one option for </span><span class="c1">scarcity</span><span class="c0">. Anything a user already has that an attacker can’t trivially spin up at scale will work</span><span class="c1">: e</span><span class="c0">mail addresses and phone numbers are naturally scarce</span><span class="c1">. A paid subscription costs an attacker the same as a real user.  </span><span class="c0">Even maintaining an account on a free service requires </span><span class="c1">some</span><span class="c0"> non-trivial work. </span></p>
<p class="c39"><span class="c0">What if we could use these scarce signals across the web? We</span><span class="c1"> could build </span><span class="c0">an open ecosystem with many parties offering scarcity signals, each site choosing which to accept. By </span><span class="c0">opening up who can provide a signal, and letting sites choose which to accept, we can avoid transferring control to device manufacturers and the resulting harms. </span></p>
<p class="c39"><span class="c1">As a concrete example of who might be well positioned to provide such a signal, we can consider VPN providers acting as a subscription service. Sites routinely block VPN users indiscriminately, whether through a deliberate policy choice or through an indirect consequence of rate limiting visitors per IP address. But a VPN subscription is a perfect source of scarcity. If the VPN provider could vouch for its users so that sites could rate limit each user individually – then users would be able to browse the web with less friction and without giving up their VPN usage. </span></p>
<p class="c35"><span class="c0">The catch is that building </span><span class="c1">a system that can enable this</span><span class="c0"> on the open web whilst </span><span class="c1">maintaining user’s privacy</span><span class="c0"> is genuinely difficult. </span><span class="c1">It requires that we take information from one site — that this user holds some scarce thing — and expose it to other sites so that they can use that as the basis for their rate limiting. </span><span class="c0">Letting one site verify a signal from another is </span><span class="c1">the sort of </span><span class="c0">information flow</span><span class="c1"> </span><span class="c0">that privacy-pr</span><span class="c1">eserving </span><span class="c0">browsers have spent the last decade locking down to </span><span class="c1">prevent cross-site tracking</span><span class="c0">. </span></p>
<p class="c35"><span class="c1">Our goal would be that no more than the minimum information gets through: a single bit communicating whether the user is below the rate limit set by the site. Leaking anything more – like the source of the scarcity that the rate limit is anchored to – would be unacceptable. Enabling a new cross-site information flow might feel like compromising privacy to gain better access, but reality is more nuanced. If a new system moves sites away from demanding that visitors be identifiable (whether through fingerprinting or login forms), </span><span class="c1">it can be a win for both privacy and access.</span></p>
<h3 class="c24"><span class="c2 c1">The Foundations </span></h3>
<p class="c50"><span class="c0">The good news is that the cryptographic foundations for a privacy preserving approach already exist. The </span><span class="c1 c3"><a class="c5" href="https://privacypass.github.io/">Privacy Pass protocol</a></span><span class="c3 c1"><a class="c5" href="https://www.google.com/url?q=https://privacypass.github.io/&amp;sa=D&amp;source=editors&amp;ust=1782228494401139&amp;usg=AOvVaw3uoXdqARBZKjQF5H8uwYKY">,</a></span><span class="c0"> </span><span class="c3 c1"><a class="c5" href="https://www.petsymposium.org/2018/files/papers/issue3/popets-2018-0026.pdf">originally developed in 2018</a></span><span class="c0"> to reduce the friction of Cloudflare CAPTCHAs for Tor users, introduced the core primitive: a token that is </span><span class="c13 c11 c1">unlinkable </span><span class="c0">between issuance and redemption. You prove something to an issuer (e.g. by </span><span class="c1">solving a CAPTCHA</span><span class="c0">), receive some tokens, and later present a token to a website. The website can verify the token is legitimate, but can’t link it to the user it was issued to. </span></p>
<p><img alt="A diagram showing the protocol flow for Privacy Pass." class="aligncenter size-full wp-image-48375" height="1639" src="https://hacks.mozilla.org/wp-content/uploads/2026/06/pact-drawings-1.excalidraw1-scaled.png" width="2560"></p>
<p class="c27"><img alt="" title=""><span class="c20 c1 c57"><strong>Figure 1</strong>: </span><span class="c0"><em>In Privacy Pass, a CAPTCHA provider can issue tokens to a client which can then be used to bypass challenges for future site visits. Even if the CAPTCHA provider and sites collude, they can’t use the tokens to identify the user or their browsing history.</em> </span></p>
<p class="c52"><span class="c0">Privacy Pass has gone on to be successfully deployed in systems where the issuer and verifier have a prior trust relationship: </span><span class="c0">Apple</span><span class="c0"> uses it to authenticate users of </span><span class="c3 c1"><a class="c5" href="https://hacks.mozilla.org/feed/">Private Cloud Compute</a></span><span class="c0"> </span><span class="c1">and</span><span class="c0"> </span><span class="c3 c1"><a class="c5" href="https://www.apple.com/privacy/docs/iCloud_Private_Relay_Overview_Dec2021.PDF">Private Rel</a></span><span class="c17 c1"><a class="c5" href="https://www.google.com/url?q=https://www.apple.com/privacy/docs/iCloud_Private_Relay_Overview_Dec2021.PDF&amp;sa=D&amp;source=editors&amp;ust=1782228494402463&amp;usg=AOvVaw0KGoiSPg-8NLvNvIiSSbPt">ay</a></span><span class="c1"> </span><span class="c0">without linking their activity to their identity, </span><span class="c0">Chrome</span><span class="c0"> uses it for </span><span class="c3 c1"><a class="c5" href="https://github.com/GoogleChrome/ip-protection">two-hop IP protection</a></span><span class="c0">, and </span><span class="c0">Kagi</span><span class="c0"> uses it to provide </span><span class="c17 c1"><a class="c5" href="https://help.kagi.com/kagi/privacy/privacy-pass.html">private search</a></span><span class="c0">. </span><span class="c0">These deployments work in part because a small number of parties have agreed in advance on who issues tokens and who accepts them. </span></p>
<p class="c18"><span class="c0">Applying this approach to an open system where any site can act as</span><span class="c0"> an issuer</span><span class="c0"> </span><span class="c3 c1"><a class="c5" href="https://docs.google.com/document/d/1k3QJG2D_Sq4zJiJRn9DfY80hEHuz9UWrJdTt8LbRsMM/edit?tab=t.0#heading=h.r8jxzjcoeumo">brings real challenges</a></span><span class="c0">.</span><span class="c0"> Firstly, even though tokens are unlinkable, knowing a user has access to a specific issuer is a privacy leak on its own, because you can infer that the user meets the relevant issuance criteria. </span><span class="c1">If one site can learn that you have a token from another site, that reveals that you have been to that site, which can be a major privacy problem. </span><span class="c0">This compounds if </span><span class="c1">sites </span><span class="c0">can learn the set of issuers </span><span class="c1">you have visited</span><span class="c0">, since it becomes a fingerprint which can be used to identify </span><span class="c1">you</span><span class="c0">. </span></p>
<p class="c8"><span class="c3 c1"><a class="c5" href="https://blog.cryptographyengineering.com/2014/11/27/zero-knowledge-proofs-illustrated-primer/">Generic techniques</a></span><span class="c0"> exist for proving a statement in zero knowledge: we can prove that </span><span class="c1">a client</span><span class="c0"> ha</span><span class="c1">s</span><span class="c0"> a token from a set of acceptable issuers without revealing which specific issuer it is. We’ll call this issuer blinding. </span><span class="c0">The generic approach is often slow, but </span><span class="c3 c1"><a class="c5" href="https://www.ietf.org/archive/id/draft-orru-zkproof-sigma-protocols-01.html">bespoke approaches</a></span><span class="c0"> tailored to the underlying cryptography can improve this considerably. </span></p>
<p class="c54"><span class="c0">Another challenge is how sites using rate limits decide who to trust to issue tokens. If an issuer misbehaves then the site’s rate limits become ineffective, enabling volumetric abuse. However, if we need to prevent the site from learning which issuers a user has access to, the site is only going to know that one of its trusted issuers was used, not which one. This makes mistakes or misbehaviour by an issuer difficult to detect, and makes it hard for sites to evaluate new issuers. Solving this challenge is essential for openness. Without adequate information, </span><span class="c0">sites are likely to lean towards conservative issuer selection. </span><span class="c1">That could lead to less choice between Anchors, which in turn could lead to a new form of gatekeeper being created.</span><span class="c0"> </span></p>
<p class="c32"><span class="c0">To solve this, sites at least need a way to calculate an aggregate score for each issuer they use. This should roughly correspond to how much of the traffic it considers abusive to have come from users using that particular issuer. Mozilla has long invested in systems like </span><span class="c3 c1"><a class="c5" href="https://blog.mozilla.org/en/firefox/partnership-ohttp-prio/">Prio</a></span><span class="c0"> which use multiparty computation (MPC) to protect user privacy whilst enabling aggregate measurements of system behaviour. </span></p>
<p class="c59"><span class="c0">Privacy Pass also struggles to handle dynamic adjustments to rate limits. Once tokens have been issued, they’re difficult to invalidate without either revoking all active tokens or risking attacks which can compromise the privacy of users. It’s also beneficial if sites can adjust rate limits on a per </span><span class="c1">client</span><span class="c0"> basis, for example by increasing rate limits where they become more confident the </span><span class="c1">client</span><span class="c0"> is benign and withdrawing access </span><span class="c1">when abuse is detected</span><span class="c0">. </span></p>
<p class="c47"><span class="c3 c1"><a class="c5" href="https://www.ietf.org/archive/id/draft-schlesinger-cfrg-act-00.html">Anonymous Credit Tokens</a></span><span class="c0"> </span><span class="c0">offer a useful building block to solve this problem. Conventional Privacy Pass schemes rely on issuing a bucket of tokens but ACT works differently by enabling the use of a credential with state. For example, an ACT credential can hold an internal counter. When the credential is presented, the site can check the counter is over some threshold and mutate it, increasing or decreasing </span><span class="c1">the counter whenever</span><span class="c0"> the site’s perception of the holder has improved or worsened. Critically, the exact value is never leaked to the site, preventing the site from tracking the holder and ensuring successive presentations of the same credential can’t be linked. </span></p>
<h3 class="c24"><span class="c2 c1">Putting it together </span></h3>
<p class="c19"><span class="c1">So how can we combine these techniques to build a system which can enable privacy-preserving rate limiting on the open web? In May 2026, we participated in a </span><a href="https://pactworkshop.com/"><span class="c17 c1">W3C CG Meeting</span></a><span class="c0"> in collaboration with Cloudflare, Chrome and other web stakeholders in which we started sketching out a design we’re calling PACT – Private Access Control Tokens. </span></p>
<p class="c19"><span class="c0">Rate limits need a starting point, a source of scarcity to anchor on. We’ll call an entity that provides such a source an </span><span class="c2 c1">Anchor</span><span class="c0">. To a user who meets the Anchor’s criteria, like having a subscription,</span><span class="c0"> an account in good standing</span><span class="c0">, or a verified phone number, an Anchor issues a batch of </span><span class="c2 c1">Endorsement </span><span class="c0">tokens, following the Privacy Pass model. In practice, Anchors could be any website which has access to this kind of signal. An Endorsement conveys</span><span class="c1"> </span><span class="c0">scarcity to other sites. </span></p>
<p class="c51"><span class="c0">That’s enough for a simple system where access is </span><span class="c1">either granted or denied</span><span class="c0">. But as we discussed earlier, we also want the ability to increase access where a visitor behaves benignly and decrease it where they don’t. </span><span class="c1">The state needed to enforce a rate limit</span><span class="c0"> can’t live in the Endorsement, because Endorsements cross trust boundaries between unrelated sites. We need a second object that can hold that state, scoped to the party that maintains it. </span></p>
<p class="c48"><span class="c0">We’ll call that the party that handles rate limiting for a site a </span><span class="c2 c1">Moderator </span><span class="c0">and the stateful object a </span><span class="c2 c1">Credential</span><span class="c0">. </span><span class="c1">A Credential is specific to a Moderator and, unlike endorsements, we limit each site to nominating a single Moderator. In the common case the site itself plays the Moderator role, so there’s no new entity or trust boundary. </span><span class="c1">A Moderator can also be a third-party service shared across many sites, allowing those sites to cooperatively share a rate limit.</span><span class="c0"> </span></p>
<p class="c48"><span class="c0">In the terminology of the previous section, the Anchor is the issuer of Endorsements, and the Moderator both verifies Endorsements and issues Credentials. A Moderator manages rate-limit policy: it decides which Anchors it trusts, accepts their Endorsements, and issues a Credential in return.</span></p>
<p class="c14"><img alt="" title=""><img alt="A diagram showing an overview of the PACT system" class="aligncenter size-full wp-image-48381" height="1655" src="https://hacks.mozilla.org/wp-content/uploads/2026/06/pact-drawings-5.excalidraw21-scaled.png" width="2560"></p>
<p class="c14"><strong><span class="c1 c20">Figure 2: </span></strong><span class="c1"><em>(1) Clients acquire Endorsements from Anchors in the course of normal browsing to sites they have relationships with. (2) Clients can exchange Endorsements for a stateful Credential from a Moderator. (3) Credentials can be used to access sites which use that Moderator. Credentials can be updated over time.</em> </span></p>
<p class="c41"><span class="c0">Directly revealing which Anchor backed an Endorsement would leak a lot of information about the user. The issuer blinding techniques from the previous section solve this: when an Endorsement is redeemed, the Moderator only learns that it came from one of </span><span class="c1">the </span><span class="c0">Anchors it trusts, but not which one. </span></p>
<p class="c28"><span class="c0">When a Moderator covers more than one site, we let Credentials be presented across all of them but partition cookies and storage as</span><span class="c1"> we would for any other third party site</span><span class="c0">. The unlinkability of </span><span class="c1">Credential</span><span class="c0"> presentations keeps this from creating a new cross-site identifier. The benefit is that good behaviour on one site improves access on every site the Moderator covers, and bad behaviour cuts it everywhere. Websites can already build the same capability with a shared account system, so this doesn’t create a new way to lock users out, but it </span><span class="c1">does provide a</span><span class="c0"> new way to grant access without requiring users to give up their privacy. </span></p>
<p class="c28"><span class="c0">Enabling Moderators that cover many sites carries a centralisation risk, simila</span><span class="c1">r </span><span class="c0">to the concentration we see today in anti-abuse providers. The mitigation is that the choice of Moderator stays with each site, and the choice of trusted Anchors stays with each Moderator. Th</span><span class="c1">is</span><span class="c0"> </span><span class="c1">can’t</span><span class="c0"> reverse the centralisation pressure the web already faces, but it </span><span class="c1">ensures this system won’t lead to additional lock-in</span><span class="c0">: a new Anchor or a new Moderator can be adopted without coordinating with a dominant vendor. </span></p>
<p class="c46"><span class="c0">The </span><span class="c1">system then has three flows</span><span class="c0">.</span><span class="c0"> First, the user </span><span class="c1">receives</span><span class="c0"> Endorsements from an Anchor in the course of normal interaction</span><span class="c1">, based on the Anchor’s positive view of the user</span><span class="c0">. This is </span><span class="c0">a relatively rare operation for any given user and Anchor. After all, as our source of scarcity, Endorsements should not be too easy to accumulate.</span></p>
<p class="c10"><img alt="" title=""><img alt="A diagram showing the PACT Anchor Flow" class="aligncenter size-full wp-image-48377" height="1789" src="https://hacks.mozilla.org/wp-content/uploads/2026/06/pact-drawings-3.excalidraw1-scaled.png" width="2560"></p>
<p class="c10"><strong><span class="c20 c1">Figure 3</span></strong><span class="c1">: <em>In the course of normal browsing, clients browse to websites they have a relationship with. These sites can act as Anchors by issuing Endorsements to clients.</em></span></p>
<p class="c26"><span class="c0">Second, when the user arrives at a site that works with a Moderator, the browser spends an Endorsement from an Anchor the Moderator trusts and receives a Credential in return. The presentation hides </span><span class="c13 c11 c1">which </span><span class="c0">Anchor was used, and </span><span class="c1">neither the Anchor nor the Moderator can trace the Endorsement back to where it was issued</span><span class="c0">. The Moderator decides what initial balance the Credential starts with. If the user has no Endorsements from suitable Anchors at all, existing mechanisms (CAPTCHAs, account creation, federated login) </span><span class="c1">could be used to</span><span class="c0"> bootstrap a Credential the same way, so the system degrades to today’s experience rather than locking the user out.</span></p>
<p class="c7"><img alt="" title=""><img alt="A diagram showing the protocol flow between Anchors and Moderators" class="aligncenter size-full wp-image-48378" height="1789" src="https://hacks.mozilla.org/wp-content/uploads/2026/06/pact-drawings-4.excalidraw1-scaled.png" width="2560"></p>
<p class="c7"><span class="c20 c1"><strong>Figure 4</strong></span><span class="c1"><strong>:</strong><em> When the client browses to a site, it can prompt the client for a Credential from the Moderator it uses. If the Client doesn’t have a suitable Credential, but does have a suitable Endorsement, it can exchange it for a Credential with the Moderator. In practice, the Moderator and the Site might be the same server. </em></span><em><span class="c0"> </span></em></p>
<p class="c25"><span class="c0">Third, as the user browses, the browser presents the Credential and the Moderator updates </span><span class="c1">the internal state of the Credential</span><span class="c0">. The </span><span class="c1">Moderator can reward </span><span class="c0">behaviour that looks benign and </span><span class="c1">penalize suspicious activity</span><span class="c0">, </span><span class="c1">but can’t track the use of the Credential or identify it if it’s used on other sites the Moderator covers</span><span class="c0">. </span><span class="c0">Revocation falls out of the same mechanism: a Moderator </span><span class="c1">can refuse to return an updated Credential</span><span class="c0">.</span><span class="c0"> </span></p>
<p class="c7"><img alt="" title=""><img alt="A diagram showing the PACT Moderator Flow" class="aligncenter size-full wp-image-48379" height="1618" src="https://hacks.mozilla.org/wp-content/uploads/2026/06/pact-drawings-5.excalidraw1-scaled.png" width="2560"></p>
<p class="c7"><strong><span class="c20 c1">Figure 5</span></strong><span class="c0"><strong>:</strong> <em>The Client can present the Credential on sites which use the matching Moderator. Sites can check if the Credential is in good standing. The sites can then adjust the access the Credential has in response to behaviour. E.g. increasing it when they gain confidence in the client or reducing it in response to malicious behaviour.</em></span></p>
<p class="c23"><span class="c0">In practice, all of this would happen transparently to the user through a WebAPI that sites acting as Anchors or Moderators would call from JavaScript. In an ideal ecosystem, users would accumulate Endorsements through normal browsing, just by virtue of the sites they already visit, and the rest of the flow would happen in the background as they move around the web, leaving </span><span class="c1">users</span><span class="c0"> with meaningfully less friction. </span></p>
<p class="c16"><span class="c0">AI agents acting on behalf of a user slot into the same flow. An agent can carry its user’s Credentials, in which case the user remains accountable for how the agent </span><span class="c1">behaves.</span><span class="c0"> </span><span class="c1">S</span><span class="c0">ites would not need to grant any more access than they would to the user themselves. Alternatively, the operator of an agent can run its own Anchor and vouch for its agents the way other Anchors vouch for human users. </span><span class="c0">Sites retain control over which Anchors they accept, so they can choose how to treat agent traffic without needing a separate detection mechanism. </span></p>
<p class="c6"><span class="c0">Several mechanisms combine to keep the information about a user that flows out close to a single bit. Cryptographic unlinkability ensures successive Credential presentations cannot be tied to each other or to the original issuance, so a user’s visits cannot be </span><span class="c1">joined</span><span class="c0"> into a history. Each site is bound to a single Moderator, so the set of Moderators a user has Credentials with never becomes a cross-site fingerprint. The Anchor-to-Credential exchange happens in an isolated browsing context, so during ordinary browsing the only thing the site or its Moderator ever observes is a Credential presentation: </span><span class="c1">the site only learns if </span><span class="c0">the user has a valid Credential below the rate limit, or </span><span class="c1">nothing</span><span class="c0">. </span><span class="c1">W</span><span class="c0">hen the Moderator updates a </span><span class="c1">Credential</span><span class="c0">, it</span><span class="c0"> adjusts the credentials state without learning what it is.</span></p>
<p class="c6"><span class="c1">The additional privacy given to users from </span><span class="c0">Issuer blinding</span><span class="c1"> makes participating in the system more challenging for Moderators</span><span class="c0">. Because the Moderator can’t see which Anchor backed a Credential at issuance, it can’t give a Credential from a strong Anchor </span><span class="c1">more access</span><span class="c0"> than one from a weak Anchor: doing so would itself leak which Anchor was used. The initial </span><span class="c1">access</span><span class="c0"> has to be uniform across the Moderator’s whole pool of Anchors, which in practice means setting it at the strength of the weakest. </span><span class="c1">However, this is only relevant for that initial access, the Moderator can update credentials according to the holder’s behavior, enabling Credential’s to accrue access over time.</span></p>
<p class="c42"><span class="c0">Building an open ecosystem also requires that sites can make effective decisions about the Anchors they choose to trust</span><span class="c1">. M</span><span class="c0">ultiparty computation systems like </span><span class="c0">Prio</span><span class="c0"> enable aggregate scoring without compromising pr</span><span class="c1">ivacy</span><span class="c0">. When users present Credentials, they can provide an encrypted share which identifies the anchor they use</span><span class="c1">d and can be privately aggregated to compute the quality of an issuer.</span></p>
<h3 class="c24"><span class="c2 c1">Next Steps </span></h3>
<p class="c49"><span class="c1">We think the</span><span class="c0"> architecture we</span><span class="c1">’ve </span><span class="c0">sketched </span><span class="c1">for PACT </span><span class="c0">has the right shape, but many of the details still need to be worked out</span><span class="c1"> and the entire system needs rigorous privacy and security analysis.</span></p>
<p class="c45"><span class="c0">We want to do that work in the open. The IETF is the natural venue for the cryptographic protocols underneath, and the W3C for the WebAPI surface that sits on top. </span><span class="c0">We’ll be </span><span class="c1">bringing</span><span class="c0"> </span><span class="c3 c1"><a class="c5" href="https://github.com/Moderation-of-unLinkable-Endorsements">draft specifications</a></span><span class="c1"> to these bodies as soon as they’re ready</span><span class="c0">, and we welcome collaborators from across the ecosystem: browser vendors, site operators, anti-abuse providers, and the cryptography community. </span></p>
<p class="c29"><span class="c0">If successful, we think we can provide a system which will keep the web open and </span><span class="c1">private</span><span class="c0">, while still giving sites the rate-limiting signal they need. </span></p>
<h3 class="c29"><span class="c2 c1">Acknowledgements</span></h3>
<p class="c4"><em><span class="c11 c1">The ideas described here are the result of collaboration and conversations with many people, including: Watson Ladd, Thibault Meunier, Michele Orrù, Trevor Perrin, Eric Rescorla, Samuel Schlesinger, Martin Thomson, Eric Trouton, Benjamin Vandersloot &amp; Cathie Yun.</span></em><span class="c11 c1"><em> </em> </span></p>
<hr class="c58">
<div>
<p class="c31"><a href="https://hacks.mozilla.org/?p=48374#:~:text=%5B1%5D">[1]</a><span class="c0"> PAT requires that the source of scarcity and an independent issuer be trusted not to collude. If they do, they can track users as they interact with the system. This is not suitable in the context of an open system where any party could play those two roles.</span></p>
</div>
<p>The post <a href="https://hacks.mozilla.org/2026/06/pact-anonymous-credentials-for-the-web/">PACT: Anonymous Credentials for the Web</a> appeared first on <a href="https://hacks.mozilla.org/">Mozilla Hacks - the Web developer blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Rust Programming Language Blog: The many journeys of learning Rust]]></title>
<description><![CDATA[This is another post in our series covering what we learned through the Vision Doc process. We previously described the overall approach and what we learned about doing user research, we explored what people love about Rust, dug into what it takes to ship safety-crticial Rust, and described some ...]]></description>
<link>https://tsecurity.de/de/3693289/tools/the-rust-programming-language-blog-the-many-journeys-of-learning-rust/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693289/tools/the-rust-programming-language-blog-the-many-journeys-of-learning-rust/</guid>
<pubDate>Sat, 25 Jul 2026 08:37:24 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><em>This is another post in our series covering what we learned through the Vision Doc process. We previously <a href="https://blog.rust-lang.org/2025/12/03/lessons-learned-from-the-rust-vision-doc-process/" rel="external">described the overall approach and what we learned about doing user research</a>, we <a href="https://blog.rust-lang.org/2025/12/19/what-do-people-love-about-rust/" rel="external">explored what people love about Rust</a>, <a href="https://blog.rust-lang.org/2026/01/14/what-does-it-take-to-ship-rust-in-safety-critical/" rel="external">dug into what it takes to ship safety-crticial Rust</a>, and <a href="https://blog.rust-lang.org/2026/03/20/rust-challenges/" rel="external">described some of the major challenges that people face when using Rust</a>.</em></p>
<p>In this post we walk through what folks have found on their journey to learn the Rust programming language with ups and downs covered.</p>
<p>As a disclaimer, LLMs (Large Language Models) come up in this post because our interviewees brought them up. We're scoping discussion to their use as a learning tool, covering research and example generation, not broader questions about AI (Artificial Intelligence) in software development.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#many-paths-to-needing-rust"></a>
Many paths to needing Rust</h3>
<p>The interviews surfaced several different paths into Rust: curiosity, embedded work, job-market pressure, organizational adoption, and reassignment after a team or company chose Rust. That last path matters because many learners are not evaluating Rust from a blank slate; they are trying to become productive after Rust has already arrived in their work.</p>
<blockquote>
<p>"Funny enough, I've advocated for more niche languages than Rust in the past. Rust has pretty much stopped being as much of a niche language as it was, but it's not Java." -- Fractional CTO</p>
</blockquote>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#rust-learning-resources"></a>
Rust learning resources</h3>
<p>Likely as expected, the folks that we talked to reach for a range of resources to learn Rust. Some reach for official documentation, such as <a href="https://doc.rust-lang.org/book/" rel="external">The Rust Programming Language Book</a> and find that sufficient to build on what the compiler was already showing them.</p>
<blockquote>
<p>"I started with the official Rust documentation because there are a lot of great examples of how features like the borrow checker work." -- Software engineer at an Automotive supplier</p>
</blockquote>
<p>Others needed more passes and more formats, sometimes reaching for resources the community maintains, such as <a href="https://rustlings.rust-lang.org/" rel="external">Rustlings</a>, <a href="https://danielkeep.github.io/tlborm/book/index.html" rel="external">The Little Book of Rust Macros</a>, and <a href="https://rust-unofficial.github.io/too-many-lists/" rel="external">Learn Rust With Entirely Too Many Linked Lists</a>.</p>
<blockquote>
<p>"The first time I went through the chapter in [The Rust Programming Language] on borrow checking, I was like, what is this? I read it again, then I watched a YouTube video of someone explaining the chapter." -- Rust freelance consultant</p>
</blockquote>
<blockquote>
<p>"Rust book, Rustlings, Zero to Production in Rust, Jon Gjengset tutorials. A bunch of books. It's not a one-pass reading. Can't say how many times I've gone through it." -- Software engineer working on video streaming and storage</p>
</blockquote>
<p>These resources have brought up an entire generation of Rust programmers. But, to some, there is a perception that these resources have trouble keeping pace with the language.</p>
<blockquote>
<p>"We'd like to use [The Rust Programming Language/'the book'], but we've found that it's out of date, unfortunately. We've looked at the GitHub repo and found it's got a lot of unresolved issues and unmerged PRs" -- Principal Software Engineering work on Rust adoption in a regulated industry</p>
</blockquote>
<p>Whether or not this is factually true, Rust's growth has nonetheless put more scrutiny on these materials. Companies evaluating adoption and engineers getting reassigned to Rust teams are looking at them with fresh eyes and finding the gaps that affect their own evaluation.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#beginner-stumblings-and-unlearning-habits"></a>
Beginner stumblings and unlearning habits</h3>
<p>It's pretty typical for Rust to be the 2nd, 3rd or Nth programming language that someone picks up. They'd end up writing their most familiar language in Rust, whether C++ patterns, Java patterns, or whatever they knew, for months or even years. Eventually they got comfortable enough to start writing idiomatic Rust.</p>
<blockquote>
<p>"There's a bit of a drop in productivity compared to C if you're already familiar with it just because you're learning new rules, new syntax."  -- Principal Firmware Engineer (mobile robotics)</p>
</blockquote>
<blockquote>
<p>"In the beginning it was more poking around the code and adding and removing some ampersands and asterisks to try to make sense of <code>mut</code> and not <code>mut</code> and whatever." -- Senior engineer with 20 years of Java experience in cloud and IoT</p>
</blockquote>
<p>We also spoke with someone who found that not having much of a programming background seemed to benefit people picking up Rust. Not having worn-in grooves from other languages may play a role here, and it's worth investigating further.</p>
<blockquote>
<p>"I had someone who had never programmed much before start working on the internals of [our Rust project]. She was just fine with getting into Rust. It's more of the senior people that struggle as they need to unlearn practices which may work in other languages, but it's not the 'Rust' way." -- Researcher, Automotive OEM R&amp;D Lab</p>
</blockquote>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#learning-to-work-with-the-borrow-checker"></a>
Learning to work with the borrow checker</h3>
<p>We heard a lot about learning to work with the borrow checker instead of against it. People get there through different paths, but a few patterns came up repeatedly.</p>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#the-compiler-as-teacher"></a>
The compiler as teacher</h4>
<p>Rust's diagnostics did the teaching on their own, especially around lifetimes.</p>
<blockquote>
<p>"If you mess up the lifetimes in a piece of code that you've written by hand, I usually find that Rust's diagnostics are very helpful" -- Researcher working on static analysis of Rust programs</p>
</blockquote>
<blockquote>
<p>"Whatever's missing, the compiler usually fills in: it tells me 'you need to declare the lifetime of this reference', so I know and can figure it out. That all generally works pretty well." -- Senior Software Engineer</p>
</blockquote>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#learning-by-doing"></a>
Learning by doing</h4>
<p>Others felt like they only really internalized the borrow checker after writing a lot of Rust. It took projects, coding challenges, prototyping and so on until at some point it clicked.</p>
<blockquote>
<p>"I actually did not understand the borrow checker until I spent a lot of time writing Rust" -- Founder of a startup built on Rust</p>
</blockquote>
<blockquote>
<p>"Besides the prototyping work, I also did coding-challenge-type stuff to get familiar with Rust for Advent of Code. [..] It eventually clicked to the point where I wasn't fighting with Rust, it was working for me. I had that experience other people describe: when I managed to get my program to fit with Rust, it worked. I didn't spend time debugging." -- Principal Software Engineer, large SaaS provider</p>
</blockquote>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#letting-go-of-clone-guilt"></a>
Letting go of "clone guilt"</h4>
<p>Some learners arrive with the assumption that good Rust means zero clones, zero copies, lifetimes threaded through everything. They set the bar at optimal before they've learned how to write idiomatic Rust, and it makes the borrow checker feel harder than it needs to be at the outset.</p>
<blockquote>
<p>"On one of my first projects, I was like, 'I don't ever want to copy or clone anything,' so I carefully wove through all the lifetimes and got myself into a bit of a bind. Then I saw someone else just cloning the struct I was working with, and it was super cheap. Sometimes you can just clone and it's going to be okay." -- Researcher at a university</p>
</blockquote>
<p>The experienced Rust developers we spoke with consistently said the same thing: clone freely while you're learning, then optimize when you understand the problem. Rust's reputation for performance and correctness feeds this. Newcomers assume anything less than optimal is wrong before they've written a first working program, and clone guilt is how that shows up.</p>
<p>We think it could be an interesting area of future study to check into the patterns Rust programmers employ at different levels of experience and under which circumstances. One member of the Rust Vision doc team that's very experienced with Rust noted that there's kind of an "expected shape" they understand as passing the compiler. This knowledge influences how they approach writing code which wouldn't take that shape and they naturally find themselves understanding when to use so-called workarounds, such as passing around indices into arrays or <code>Vec</code>s.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#multi-paradigm-but-not-the-oop-some-are-used-to"></a>
Multi-paradigm, but not the OOP some are used to</h3>
<p>The Rust programming language is multi-paradigm, and how that lands depends on what you're coming from. We heard some that came from a functional background were delighted with digging into learning how much Rust inherits from that lineage. Some others noted that they and others on their teams struggled to unlearn the object-oriented style they'd come to use heavily in other languages like C++ and Java.</p>
<blockquote>
<p>"Developers coming from C++ tend to think object-oriented. I think that's a difference between C++ and Rust." -- Architect at Automotive OEM</p>
</blockquote>
<blockquote>
<p>"I had exactly that thing, where I would apply all my years of Java and JS thinking, where I could just create some object, not care about it, return it, have it sloshing around between various functions. Found myself reaching for these patterns and then being told 'no, you cannot do that'." -- Principal Engineer at a SaaS company</p>
</blockquote>
<p>Developers coming from functional programming had less to unlearn: strong typing, pattern matching, and an expression-oriented style were already familiar.</p>
<blockquote>
<p>"My background has been more functional programming, strong typing. That originated for me as a Lisper: once a Lisper, always a Lisper." -- Principal Software Engineer working on Rust tooling for safety-regulated industries</p>
</blockquote>
<blockquote>
<p>"The languages I primarily used before Rust were things like OCaml. Way back, I came from C and C++, the classic languages, and then I spent quite a long time doing primarily pure functional stuff. These days I've ended up back in what I like to think of as a pragmatic center ground [with Rust]." -- Fractional CTO</p>
</blockquote>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#teaching-rust-in-academia"></a>
Teaching Rust in academia</h3>
<p>We spoke with a university professor that's been teaching Rust generally. In the academic environment, they were able to use proxies for some things such as "traits are like interfaces in Java" because the students had already gone through a set of courses in their first and second years that taught them Java. They introduced concepts slowly throughout the course, choosing to deal with some more complex topics like generics later. The outcome generally was that students had no problem picking up Rust in this setting.</p>
<blockquote>
<p>"I couldn't see any big difference on the embedded side. We also teach an embedded class, and we did an experiment. Half of the students' feedback was worse on the Rust class, mostly because they needed to build the project themselves. The C students just got one from [an LLM], absolutely no problem." -- University Professor, on teaching Rust</p>
</blockquote>
<p>The C cohort leaned on LLMs for the project in ways the Rust cohort couldn't. We don't yet have a clear answer for why.</p>
<p>What did come through clearly was the Rust cohort's experience with the community. Some students needed to figure out which drivers to use for the embedded project and how to use them. Their professor encouraged them to open issues and ask questions directly on GitHub, and the maintainers responded. Students who had never contributed to open source before were getting answers from the people who wrote the code.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#learning-using-llms"></a>
Learning using LLMs</h3>
<p>Some experienced folks shared that they saw LLMs as a tool that can help someone come up to speed quickly, either as a research tool or for generating example Rust code to understand concepts.</p>
<blockquote>
<p>"I'm optimistic that there's a way to work [LLMs] in that will cut down that learning curve. One of the big things these tools bring is reducing the learning curve in general; these are very good tools to help you navigate a space that you don't know yet." -- Maintainer of large open source Rust crate</p>
</blockquote>
<blockquote>
<p>"I try [LLMs] out once a month, usually for generating an example or something like this. Just like with Stack Overflow: when you read an example, you should read it carefully and try to understand it. Not copy and paste it, but type it in your own words in code and then check it, because that's where the teeny tiny little mistakes are." -- Founder of startup built on Rust</p>
</blockquote>
<p>For some learners, an LLM is just another way to find answers, no different than a search engine.</p>
<blockquote>
<p>"So for the most part, picking up Rust - how do I learn? I'll [use web search for] things, I'll ask [an LLM], I'll just poke around and read the code." -- Senior Software Engineer working in a regulated space</p>
</blockquote>
<p>One founder went further and claimed that LLMs change who can become a Rust developer. One consulting company founder described hiring high school graduates with no systems programming background and training them as Rust developers, with LLMs filling in the learning gaps that would previously have required years of experience.</p>
<blockquote>
<p>"At the beginning, I was worried, but now that we have [LLMs] supporting development, the difficulty of the language doesn't matter. I'm seeing a huge opportunity behind strong runtime languages like Rust. [..] In [Developing Country] we hire 20-25 high school graduates, train them to be Rust programmers, then they enhance our workforce worldwide." -- Founder of a consulting company</p>
</blockquote>
<p>We heard this from one organization. This is a claim that the combination of Rust's compiler and LLM tooling can dramatically shorten the path from beginner to working developer. Whether it generalizes depends on questions we can't answer from a single interview: how long these developers stay, what kind of code they can maintain independently, and whether this training/learning model works outside this company's particular structure. If it holds up, the pool of people who can become Rust developers is much larger than the usual hiring profile suggests.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#organizational-considerations-for-rust-learners"></a>
Organizational considerations for Rust learners</h3>
<p>We spoke with a number of folks on teams that are using Rust in larger organizations. Teams wanted to know that everyone would end up at roughly the same level of competence, which led a good number to invest in training courses to get there. Some leaders found that staff was able to ramp well enough by reading The Rust Programming Language, going through Rustlings, and then picking up lower risk and priority tickets to work on. Having a sense of community was also important within companies; it helps people know they are not alone when they are asked to work on Rust after, say, a reorganization happens.</p>
<blockquote>
<p>"[..] the idea with the class as opposed to 'just read the Rust book on your own' was that this gives everyone kind of the same baseline going in."  -- Principal Firmware Engineer (mobile robotics)</p>
</blockquote>
<blockquote>
<p>"So typically we're going to have people work through Rustlings, work through The Rust Programming Language. We have them then start to pick up lower risk tickets to work on." -- Principal Engineer at a large SaaS provider</p>
</blockquote>
<blockquote>
<p>"We've got an internal Slack channel for Rust learning where people can drop questions and others will come in and answer them. That helps build up understanding and community." -- Software Engineer at a large corporation</p>
</blockquote>
<p>Some organizations found that while the person they'd hire would need to learn Rust, it was still preferable to the alternative of hiring someone for a critical piece of software written in another language.</p>
<blockquote>
<p>"They needed to grow and maintain this C++ codebase. They had a C++ wizard, and they tried for about two years to find someone with the same level of expertise. They ended up hiring people that didn't know Rust and ramping them up, creating FFI bindings from the C++ side so they could work in Rust. And you can feel it: the borrow checker is teaching these people the right way to handle their systems." -- Principal Engineer at an Automotive OEM</p>
</blockquote>
<p>The community and helping each other aspect seems to grow bonds as organizations mature.</p>
<blockquote>
<p>"Our team is [all about] mentorship. I've mentored people coming up to speed on Rust, and people help each other hugely." -- Principal Software Engineer at a large SaaS company</p>
</blockquote>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#silent-attrition"></a>
Silent attrition</h3>
<p>We identified some cases where people have approached Rust and bounced off of it, for one reason or another. In the below case, someone with a background in a language with fewer guardrails found themselves frustrated enough with Rust to walk away.</p>
<blockquote>
<p>"All of that means that that embedded ecosystem is very frustrating to somebody who comes from C and is like, why can't I just get a pointer to this peripheral and then write into the registers. What are you doing to me? [..] My friend never got over that. He looked at it and said, I'm not going to deal with this and walked away." -– A second University Professor</p>
</blockquote>
<p>There may be language features that for a particular domain are not seen as comfortable or usable yet, such as async Rust usage in a safety domain. We'd like to map which language features feel off-limits in which domains; async in safety-critical work probably isn't the only case.</p>
<blockquote>
<p>"We're not fully sure how async [Rust] will work out in the long run in our domain. [..] People don't feel comfortable yet since C++14 doesn't provide such concepts. [..] It's the chicken-and-egg problem again: we probably need to gain some experience to see whether we can actually benefit from these new concepts in the automotive and safety domains." -- Team Lead at Automotive Supplier (ASIL D target)</p>
</blockquote>
<p>We heard in at least one case, that while the language was challenging and there was a near bounce, the tooling helped keep them coming back and trying.</p>
<blockquote>
<p>"Well, I think my early impressions of Rust - one is I find C++ so intimidating, and I think a big part of why I was able to succeed at [..] learning Rust is the tooling. I mean, all this makes sense [..] but it's like, for me, getting started with Rust, the language was challenging, but the tooling was incredibly easy." -- Founder of another startup built on Rust</p>
</blockquote>
<p>While it might be considered more of a community concern, if there are interactions online and in spaces that point to learners having
so-called "skill issues" this feeds into the narrative that Rust must be hard to learn. We may be unintentionally turning away Rust Project contributors and maintainers due to the vibes being put out when new learners show up in certain spaces.</p>
<blockquote>
<p>"People are very helpful, but generally the attitude is: if your program is very complicated, it's mostly a skill issue. There's not that much empathy when people get stuck learning, and a lot of people are just pushed away by it. There's probably a huge number of people who silently stop wanting to write Rust, because at some point it gets complicated and the feedback they get is 'you just need to be a better programmer, obviously'." -- Software Engineer at a SaaS Provider</p>
</blockquote>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#feedback-on-near-bounces-from-survey"></a>
Feedback on near-bounces from survey</h4>
<p>We found a few interesting perspectives collected in the Rust Vision doc survey which we administered with examples of bouncing and coming back:</p>
<blockquote>
<p>"I started before 1.0, got stuck very soon when trying to translate patterns from C++ to Rust (due to borrow checking). I tried again after 1.0 and it stuck. [..]" -- Survey Respondent A</p>
</blockquote>
<p>Survey Respondent A went on to share in a more detailed response about a perceived weakness in Rust learning materials related to lifetimes and the borrow checker are explained. There was an observation that it's fairly easy to run into more complex situations with lifetimes and the borrow checker. They felt that the current state of this sort of material and tutorials is fairly superficial and can leave learners stuck when they run into those more complex situations.</p>
<p>One respondent that bounced once and came back shared challenges around usage of async. In concert with Rust's memory-safety and the borrow checker, they found some of the nitty-gritty details of async were difficult to learn. While we're aware of the Rust Project's continuous efforts to improve Rust's async story, this is another data point of a user that faced challenges.</p>
<p>Another survey respondent shared how they had multiple times bounced in trying to learn Rust. They returned after a year or so and found Rustlings to be highly motivating. We note that having multiple pathways for folks to learn Rust opens up more possibilities for those that nearly bounced, just like this person.</p>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#need-more-focused-work-on-silent-attritrion"></a>
Need more focused work on silent attritrion</h4>
<p>The thing that stood out most to us was the lack of real, first-hand knowledge of having bounced when learning Rust. While this is an obvious effect of soliciting answers to our survey and opportunities to interview through Rust channels and our networks, this cohort is good future candidate where interviews could start.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#conclusions"></a>
Conclusions</h3>
<p>Across these conversations, the experience of learning Rust depended heavily on context. Why someone was learning and what support they had mattered as much as the borrow checker. The same kinds of examples kept coming up: a training course that got a team to a shared baseline, a maintainer answering a student's first GitHub issue, and a colleague whose code showed that cloning was okay.</p>
<p>That context is largely something the community has a hand in. With that in mind, here is what we take away from what we heard, and what we still don't know.</p>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#what-seems-worth-trying"></a>
What seems worth trying</h4>
<p><strong>Learning materials aimed at unlearning.</strong> Syntax barely came up when people described their struggles. People struggled with unlearning habits from previous languages, whether OOP structuring from C++ and Java or the instinct to grab a raw pointer to a peripheral. Most of our learning materials teach Rust from first principles, and that works. What we didn't come across is much written for, say, the engineer with ten years of Java who lands on a Rust team after a reorg: material that names the patterns they'll reach for that won't transfer, and shows what to do instead. The professor we spoke with did a version of this in the classroom, leaning on "traits are like interfaces in Java" and saving generics for later in the course, and the students did fine. Something similar could work outside the classroom too.</p>
<p><strong>Put the "clone freely while you're learning" advice somewhere official.</strong> Every experienced developer we spoke with gave the same advice, but learners seem to mostly pick it up by accident, like the researcher who happened to see someone else cloning the struct they had been carefully threading lifetimes through. Saying it early in official materials would take some of the steepness out of the curve. The broader version belongs there too: idiomatic Rust doesn't have to mean optimal Rust, especially on a first project.</p>
<p><strong>Diagnostics are already a primary learning resource: several people told us the compiler taught them lifetimes before any documentation did.</strong> Diagnostics reach learners right at the moment they're stuck. When writing new ones, it seems worth keeping the confused newcomer in mind alongside the expert, because for a lot of people this is where the learning happens.</p>
<p><strong>Is "the book" actually out of date?</strong> Whether or not The Rust Programming Language or other materials are actually behind, a team evaluating Rust looked at its repository, saw unresolved issues and unmerged PRs, and moved on. As more companies evaluate adoption, more people will look at these materials with the same fresh eyes. Visible issue triage and some communication about what's current and what's planned would address the perception, separately from whatever content work may or may not be needed.</p>
<p><strong>How stuck learners get treated is shaping who stays.</strong> We heard about students getting answers on GitHub from the maintainers who wrote the code, and we heard about learners being told their struggles were a skill issue. The first group came away with a lasting good impression of Rust. Some of the second group walked away entirely, and because they leave quietly, it's easy to underestimate how many of them there are. The welcoming side of the community came up unprompted as a reason people stayed, so we know it makes a difference when we get this right.</p>
<p><strong>Every organization we spoke with described essentially the same ramp-up for bringing a team to Rust.</strong> Teams that brought groups of developers to Rust described roughly the same approach: get everyone to a shared baseline with a training course or with The Rust Programming Language and Rustlings, start people on lower-risk tickets, and give them somewhere internal to ask questions. Several organizations also found that hiring developers without Rust experience and ramping them up worked out better than continuing to search for rare expertise in another language. None of this is complicated, and teams weighing adoption don't need to invent a training program from scratch.</p>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#what-we-still-don-t-know"></a>
What we still don't know</h4>
<p>The biggest gap is the people we didn't reach. Nearly everyone we spoke with stuck with Rust long enough to be reachable through Rust channels, so the stories of bouncing off came to us second-hand: a friend who walked away from embedded Rust, colleagues who quietly stopped after the responses they got. As we wrote in <a href="https://blog.rust-lang.org/2025/12/03/lessons-learned-from-the-rust-vision-doc-process/" rel="external">our first post</a>, finding people who decided against Rust takes targeted outreach. If the proposed User Research team comes together, talking with learners who bounced would make a good early project, and learning is probably the area where that research would teach us the most.</p>
<p>We also don't know what to make of LLMs as a learning tool yet. They came up as a search engine, as an example generator, and in one organization's case as something that makes training high school graduates into working Rust developers possible. We saw a classroom where the C cohort leaned on LLMs in ways the Rust cohort couldn't, and we don't have an explanation for it. All of this comes from a handful of conversations, so we treat it as a set of leads to follow up on. Given how quickly the tools are changing, it seems better to study this deliberately than to wait and see what folklore develops.</p>
<p>The folks we spoke with showed that people do get there: with enough passes through the materials and enough code written, it eventually clicks. The opportunities above are mostly about making it work for the people who didn't pick Rust on purpose, and for the ones who would have stuck around if their early experience had gone a little differently.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows 11 now lets you resize the touchpad right-click zone, something even macOS can’t do]]></title>
<description><![CDATA[Windows 11 now lets you resize the right-click zone on your touchpad, choosing between Default, Small, Medium, and Large from Settings. The feature started in Insider builds back in March and has now rolled out to everyone with the July 2026 Patch Tuesday update, no tweaks required.
The post Wind...]]></description>
<link>https://tsecurity.de/de/3692803/windows-tipps/windows-11-now-lets-you-resize-the-touchpad-right-click-zone-something-even-macos-cant-do/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692803/windows-tipps/windows-11-now-lets-you-resize-the-touchpad-right-click-zone-something-even-macos-cant-do/</guid>
<pubDate>Sat, 25 Jul 2026 02:26:40 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Windows 11 now lets you resize the right-click zone on your touchpad, choosing between Default, Small, Medium, and Large from Settings. The feature started in Insider builds back in March and has now rolled out to everyone with the July 2026 Patch Tuesday update, no tweaks required.</p>
<p>The post <a rel="nofollow" href="https://www.windowslatest.com/2026/07/25/windows-11-now-lets-you-resize-the-touchpad-right-click-zone-something-even-macos-cant-do/">Windows 11 now lets you resize the touchpad right-click zone, something even macOS can’t do</a> appeared first on <a rel="nofollow" href="https://www.windowslatest.com/">Windows Latest</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Choosing high assurance schemes offers better flexibility as technology requirements change]]></title>
<description><![CDATA[Author: PQShield - Bewertung: 0x - Views:80 Selecting the most rigorous certification path today provides long term benefits for product manufacturers. 

@Wei Yuan suggests that choosing high assurance schemes offers better flexibility as technology requirements change. Here’s why:
Strict schemes...]]></description>
<link>https://tsecurity.de/de/3691784/videos/choosing-high-assurance-schemes-offers-better-flexibility-as-technology-requirements-change/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691784/videos/choosing-high-assurance-schemes-offers-better-flexibility-as-technology-requirements-change/</guid>
<pubDate>Fri, 24 Jul 2026 16:22:13 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: PQShield - Bewertung: 0x - Views:80 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/Vqf7vBDMx2A?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Selecting the most rigorous certification path today provides long term benefits for product manufacturers. <br />
<br />
@Wei Yuan suggests that choosing high assurance schemes offers better flexibility as technology requirements change. Here’s why:<br />
Strict schemes reduce the overall cost of ownership over time.<br />
High assurance solutions live longer within evolving regulatory timelines.<br />
Early investment prevents the need for a mass migration in just a few years.<br />
<br />
Robust compliance paths offer more certainty for international markets.<br />
Learn why high assurance evaluation saves costs over time. Listen to the full episode today!<br />
<br />
#Certification #PQC #TechStrategy #AppplusLabs<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[An A.I. Music F.A.Q.: Can I Remix Madonna? Is This All Legal?]]></title>
<description><![CDATA[Advances in A.I. are making it possible to create all kinds of music from scratch, but they also raise questions about what is legal and who will actually listen.]]></description>
<link>https://tsecurity.de/de/3691112/it-nachrichten/an-ai-music-faq-can-i-remix-madonna-is-this-all-legal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691112/it-nachrichten/an-ai-music-faq-can-i-remix-madonna-is-this-all-legal/</guid>
<pubDate>Fri, 24 Jul 2026 11:24:31 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Advances in A.I. are making it possible to create all kinds of music from scratch, but they also raise questions about what is legal and who will actually listen.]]></content:encoded>
</item>
<item>
<title><![CDATA[The Microsoft agent framework wars are over. The real architecture decision starts now]]></title>
<description><![CDATA[Over the past year, I had the same conversation with almost every team starting an AI initiative. Should we build on Semantic Kernel, AutoGen or Foundry?



At first it felt like the most important architectural decision we’d make. Each framework had its own philosophy, each promised to be the fo...]]></description>
<link>https://tsecurity.de/de/3691079/ai-nachrichten/the-microsoft-agent-framework-wars-are-over-the-real-architecture-decision-starts-now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691079/ai-nachrichten/the-microsoft-agent-framework-wars-are-over-the-real-architecture-decision-starts-now/</guid>
<pubDate>Fri, 24 Jul 2026 11:04:58 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Over the past year, I had the same conversation with almost every team starting an AI initiative. Should we build on Semantic Kernel, AutoGen or Foundry?</p>



<p class="wp-block-paragraph">At first it felt like the most important architectural decision we’d make. Each framework had its own philosophy, each promised to be the foundation for enterprise AI, and picking the wrong one felt like an expensive mistake. I spent a lot of time helping teams weigh the trade-offs.</p>



<p class="wp-block-paragraph">Looking back, I think we were asking the wrong question. I certainly was.</p>



<p class="wp-block-paragraph">I watched teams spend months debating SDKs while the decisions that actually decided whether their applications survived production went unexamined. Some built elaborate orchestration layers for workflows that a few deterministic functions would have handled. Others avoided agent frameworks entirely and later found they’d designed themselves into a corner.</p>



<p class="wp-block-paragraph">Then Microsoft settled it for us. It <a href="https://learn.microsoft.com/en-us/agent-framework/overview/">introduced the unified Agent Framework</a>, quietly moved Semantic Kernel and AutoGen into <a href="https://devblogs.microsoft.com/agent-framework/migrate-your-semantic-kernel-and-autogen-projects-to-microsoft-agent-framework-release-candidate/">maintenance mode</a>, and the debate I’d spent months refereeing was suddenly over. Turns out the answer to “which of the three” was “none of the three, here’s a fourth.” The framework hit version 1.0 and general availability in April 2026, stable across .NET and Python.</p>



<p class="wp-block-paragraph">What surprised me wasn’t the decision. It was how fast a debate that had eaten so much of our attention stopped mattering. Microsoft changed the menu.</p>



<p class="wp-block-paragraph">It didn’t change the meal.</p>



<h2 class="wp-block-heading">The framework was never the hard part</h2>



<p class="wp-block-paragraph">Framework selection dominated almost every early conversation I had about enterprise agents. Which SDK do we standardize on? Which orchestration model gives us the most flexibility? Which one is Microsoft actually betting on?</p>



<p class="wp-block-paragraph">Fair questions. But after a year of watching these projects play out, I’ve slowly come around to a different view. Those weren’t the questions that decided anything.</p>



<p class="wp-block-paragraph">The first question I ask now is much smaller. Does this thing actually need an agent?</p>



<p class="wp-block-paragraph">It sounds obvious, and I still get it wrong sometimes. But it’s the mistake I see most. On one project, a team spent weeks designing a multi-agent workflow for a process that ran the same four steps every time: read a document, validate it, call an API, send a notification. The diagrams looked great. The system in production didn’t. A few well-tested functions would have been easier to build, easier to maintain and a lot easier to trust.</p>



<p class="wp-block-paragraph">Part of this is just that “<strong>agent</strong>” has become the word everyone reaches for. Sometimes it’s the right call. Sometimes it’s a workflow we already knew how to build, wearing a newer label. An agent earns its complexity when it genuinely has to decide things you can’t predetermine, choosing between tools, adapting to what it finds, working out its own next step. If you already know every step, you have a workflow, and a workflow is usually the better engineering choice. The consolidation didn’t change that. It just made it easier to see.</p>



<h2 class="wp-block-heading">What building production agents actually taught me</h2>



<p class="wp-block-paragraph">Once I stopped fixating on frameworks, the same three problems kept showing up. None of them had anything to do with the SDK.</p>



<h3 class="wp-block-heading">Context beats model choice</h3>



<p class="wp-block-paragraph">Early on I spent a lot of time comparing models, the way you’d agonize over a restaurant menu and then order what you always order. Now I spend most of it thinking about context, which is far less fun and far more useful.</p>



<p class="wp-block-paragraph">I’ve watched good models fail because they were handed too much, not too little. One team I worked with gave the model access to nearly every internal document they had on the theory that more information meant better answers. It went the other way. Responses got slower, less consistent and sometimes skipped right past the thing that actually mattered. When we cut the context down to only what the task needed, the quality jumped almost immediately. I didn’t predict that. It taught me to be suspicious of “just give it everything.”</p>



<p class="wp-block-paragraph">The best agent systems I’ve worked on weren’t the ones with the biggest context windows. They were the ones careful about what reached the model, and when. That’s not something the framework hands you.</p>



<h3 class="wp-block-heading">Failure is where the real work is</h3>



<p class="wp-block-paragraph">Most agent demos look great because they’re built around the happy path. Production doesn’t extend that courtesy.</p>



<p class="wp-block-paragraph">I remember a project where everything held up in testing. Then a downstream API timed out after the agent had already completed several earlier steps. We couldn’t just restart, because part of the business process had already gone through. We ended up spending far more time on recovery logic than we ever spent on prompts. That project changed how I think about this work. The hard part was never getting the model to make a decision. It was making sure the system didn’t fall apart when reality refused to follow the script.</p>



<p class="wp-block-paragraph">Tool calls fail partway through. APIs return inconsistent data. Models call the same tool over and over because the last answer wasn’t what they wanted. That’s not the exception; that’s a normal Tuesday. Whether you retry, roll back, pause for a human or push on with partial results is a judgment call, and no framework is going to make it for you.</p>



<h3 class="wp-block-heading">Identity is the real security boundary</h3>



<p class="wp-block-paragraph">This one surprised me most. The moment an agent stops being a chatbot and starts touching real business systems, identity matters more than orchestration.</p>



<p class="wp-block-paragraph">Every project gets to the same question eventually. Who is this agent actually acting as? The developer’s credentials? A service account? The user who asked? Get it wrong and you’ve built something autonomous running with more access than any single person should have, which is exactly the kind of thing that looks fine until an audit. The Agent Framework, like most modern tooling, makes it easier to wire agents to tools through standards like the <a href="https://modelcontextprotocol.io/">Model Context Protocol</a>. That helps. But where human approval belongs, what needs extra authorization, how much rope to give the thing, those are still yours to decide.</p>



<h3 class="wp-block-heading">The surprises weren’t technical</h3>



<p class="wp-block-paragraph">Here’s what I didn’t see coming. The hardest part of last year wasn’t technical at all. It was organizational. The moment a team heard “agent,” expectations shifted under everyone’s feet. Business stakeholders started expecting full autonomy. Developers assumed the thing could reason its way through anything. People started designing for flexibility before we’d even agreed on what problem we were solving. The word did damage before any code did. I found myself spending as much time resetting expectations as I did discussing architecture.</p>



<h2 class="wp-block-heading">Build for change, not for today’s winner</h2>



<p class="wp-block-paragraph">I don’t think the teams that struggled last year picked the wrong framework. Semantic Kernel was reasonable. AutoGen was reasonable. Foundry made sense for plenty of cases. I’d have signed off on any of them.</p>



<p class="wp-block-paragraph">The ones that got hurt put all their eggs in one framework, treating it as the foundation of the whole system instead of as one more dependency. Microsoft provided a migration path. But teams that had tightly coupled their applications to framework-specific abstractions discovered that migrating and rewriting are not the same thing. That wasn’t Microsoft’s doing. It was their own architecture’s. The teams that moved easily had kept their business logic, prompts and orchestration loose enough to evolve independently of any one SDK. For them, the change was a manageable project, not a teardown.</p>



<p class="wp-block-paragraph">For what it’s worth, nobody I work with is treating this as an emergency. Most are moving the smaller workloads first, watching how they behave and leaving the production-critical systems alone until they actually understand the new abstractions. That’s the right instinct. And I doubt this is the last consolidation we’ll see, the ecosystem is still young, frameworks will keep absorbing each other and over time the differences between them will be operational more than architectural.</p>



<p class="wp-block-paragraph">I don’t regret the framework debates, honestly. They were reasonable at the time. What changed wasn’t Microsoft’s roadmap.</p>



<p class="wp-block-paragraph">It was mine. Watching these systems run in production taught me that the framework is the easiest piece to swap out. Recovery logic, context management, security boundaries, the business workflow itself, those stay with you long after today’s SDK gets replaced by tomorrow’s.</p>



<p class="wp-block-paragraph">So, Microsoft made one decision easier by turning three frameworks into one. Good. Five years from now we’ll be on different tools, and we’ll still be asking the same handful of questions.</p>



<p class="wp-block-paragraph">Does this actually need an agent? Does it have the right context? Can it recover when something breaks, because something will? Is it acting as the right person?</p>



<p class="wp-block-paragraph">Those questions outlast every rewrite. That’s where I’ve learned to put my effort.</p>



<p class="wp-block-paragraph">Frameworks come and go. Good architecture has to survive all of them.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.infoworld.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Community Fedora Remix 12.3 hopefully soon to be archived :)]]></title>
<description><![CDATA[In a batch of software CDs I found at the thrift store long my interest in Linux, I found a previously unarchived version of Fedora. I will be posting it on archive.org as soon as I rip it. I also have a potentially-working copy of PCLinuxOS 2007, but on the computer I tested it on, it kicks me o...]]></description>
<link>https://tsecurity.de/de/3690328/linux-tipps/community-fedora-remix-123-hopefully-soon-to-be-archived/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690328/linux-tipps/community-fedora-remix-123-hopefully-soon-to-be-archived/</guid>
<pubDate>Fri, 24 Jul 2026 00:13:09 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>In a batch of software CDs I found at the thrift store long my interest in Linux, I found a previously unarchived version of Fedora. I will be posting it on archive.org as soon as I rip it. I also have a potentially-working copy of PCLinuxOS 2007, but on the computer I tested it on, it kicks me out to a basic shell due to some kind of error. If I can get it to work, I can upload it stand-alone since it only seems to preserved in archives or Linux User magazine and !com magazine cover DVDs (the former or which has a LOT of potentially otherwise-unarchived distro versions)</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Iheretomakeonepost"> /u/Iheretomakeonepost </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1v4lef3/community_fedora_remix_123_hopefully_soon_to_be/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1v4lef3/community_fedora_remix_123_hopefully_soon_to_be/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic orchestration: Enterprise AI organizations have a deployment problem, not a platform problem — and most are calling chatbots agents]]></title>
<description><![CDATA[Across 101 enterprises, agent orchestration is consolidating onto model-provider platforms — Anthropic’s Claude leads by a wide margin — chosen for the gravity of the underlying model and judged on reliable multi-step execution. But the ambition runs well ahead of the reality: most deployed “agen...]]></description>
<link>https://tsecurity.de/de/3689830/it-nachrichten/agentic-orchestration-enterprise-ai-organizations-have-a-deployment-problem-not-a-platform-problem-and-most-are-calling-chatbots-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689830/it-nachrichten/agentic-orchestration-enterprise-ai-organizations-have-a-deployment-problem-not-a-platform-problem-and-most-are-calling-chatbots-agents/</guid>
<pubDate>Thu, 23 Jul 2026 19:19:45 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Across 101 enterprises, agent orchestration is consolidating onto model-provider platforms — Anthropic’s Claude leads by a wide margin — chosen for the gravity of the underlying model and judged on reliable multi-step execution. But the ambition runs well ahead of the reality: most deployed “agents” are still chatbot wrappers, the control plane enterprises expect is deliberately hybrid to avoid lock-in, and real-time fiscal control over token burn remains the exception.</p><p>This wave of VentureBeat Pulse Research examines enterprise agent orchestration: which platforms enterprises run on, what drives the choice, what they optimize for, how they expect agent control to be structured, and — most revealingly — how orchestrated their deployed “agents” actually are and how tightly they control the cost of running them.</p><p>The central finding is a gap between orchestration ambition and orchestration reality. Enterprises are consolidating fast onto the major model platforms: Anthropic’s Claude is the primary platform for 40%, more than double any rival, followed by Microsoft (18%) and OpenAI (13%). The choice is driven by “model gravity” — native alignment with a state-of-the-art base model (21%) — and success is judged by reliable, multi-step execution (task completion reliability 32%, multi-step workflow management 28%). Yet asked to assess their portfolios honestly, 71% say a quarter or fewer of their deployed “agents” are true multi-step orchestrated workflows rather than single-prompt chatbot wrappers, and only 10% have crossed the halfway mark. The orchestration layer is being built well ahead of the orchestrated portfolio it is meant to run.</p><p>That gap shapes the architecture enterprises are putting in place. By the end of 2026 a clear majority (51%) expect a hybrid control plane — provider-native plus external orchestration — and only 6% expect to hand control to a provider-managed service, because vendor lock-in (35%) is the risk they fear most if control lives inside a model provider. Investment follows the build-out: agent workflow tooling leads the spend (34%), with security and permissions enforcement (25%) behind. And fiscal control lags throughout — more than a quarter (27%) have no real-time way to stop a runaway agent before the bill arrives.</p><h2>Methodology</h2><p>VentureBeat fielded this survey as part of its ongoing Pulse Research series, this instrument focused on enterprise agent orchestration. Responses are filtered to organizations with 100 or more employees (n=101), drawn from a single June 2026 wave; because this is one wave rather than a pooled multi-month sample, the report reads cross-sectionally and does not infer month-over-month trends.</p><p>By organization size the sample is spread evenly across the enterprise bands: 100–499 employees, 2,500–9,999, and 50,000+ (21% each), with 10,000–49,999 and 500–2,499 (19% each). By role it is senior and buyer-credible: product and program managers (15%), CIO/CTO/CISO (13%), consultants and advisors (13%), and a spread of data, AI, and engineering directors and VPs, with an “Other” function at 18%. On purchasing, 81% are recommenders, influencers, or final decision-makers for AI solutions (66% recommender/influencer, 15% final decision-maker). Technology/Software is the largest industry at 44%, followed by Financial Services (17%) and Healthcare/Life Sciences (8%).</p><p>At 101 respondents the sample is robust enough to read directionally with reasonable confidence, though it remains self-selected and is not a probability sample.</p><h2>Finding 1: Orchestration runs on model-provider platforms</h2><p><b>Anthropic’s Claude leads; open frameworks are marginal</b></p><p>We asked which agent orchestration platform enterprises primarily use today. The answer concentrates on the major model providers — and on one in particular.</p><div></div><p>A note on reading these shares. As described in the methodology section, the respondents are self-selected, and this question asked them for a single primary platform — so the figures measure which platform leads each enterprise's deployment, within a self-selected audience of AI-active technical decision-makers. A sample built this way can diverge substantially from spend-weighted market measures, and each VB Pulse survey draws its own sample with its own company-size mix, so vendor figures should not be compared across our surveys either. Read these shares as a portrait of where this cohort has placed its primary orchestration bet today, rather than as market share.</p><p>The model platforms dominate. Anthropic, Microsoft, OpenAI, Google, and Amazon together account for roughly 80% of deployments (81 of 101), while the open frameworks (LangChain/LangGraph) and custom in-house builds that anchor engineering discussion sit in single digits. Anthropic’s lead — 40%, more than double the next platform — mirrors the “model gravity” selection logic in Finding 2: enterprises are choosing the orchestration layer that comes with the model they want to build on. As with the security vendors in the prior agent-security wave, the tools that define the category in technical circles are not yet where enterprise deployment concentrates. A small 3% are not orchestrating at all.</p><p>Respondents rate the platforms they run at 3.94 out of 5 overall (109 answered), with “value for money” specifically at 3.94 and “ease of implementation” the weakest score, at 3.85 — placing orchestration near the bottom of our five-tracker satisfaction range, ahead of only evaluation tooling. A rating just under 4 out of 5, from users of whom 96% plan to change their orchestration approach within the year, reads as provisional acceptance: the platforms work well enough to run today, and not well enough to stop the search for something better. The ratings sit alongside near-universal intent to change; this is a layer enterprises tolerate more than they love.</p><h2>Finding 2: Model gravity drives platform selection</h2><p><b>The base model, not the tooling, decides the platform</b></p><p>We asked what most influenced the orchestration platform choice. The single largest factor is the pull of the underlying model — though flexibility and ease of development follow close behind.</p><div></div><p>Model gravity leading is the selection-side explanation for Anthropic’s platform lead: enterprises pick the orchestration environment closest to the frontier model they have standardized on. But the next tier complicates the picture — flexibility across models and tools (17%) and ease of development (17%) say enterprises also want to avoid being trapped by that choice, foreshadowing the lock-in fear in Finding 6. Security and permissions (14%) and total cost of ownership (11%) round out a pragmatic buying logic. Performance (latency/memory) sits last at 4%, a reminder that at this stage of adoption the binding constraints are model fit and optionality, not raw speed.</p><h2>Finding 3: The job is reliable multi-step execution</h2><p><b>Enterprises just orchestration by whether it completes the work</b></p><p>We asked what enterprises optimize for — their primary success metric for orchestration. Reliability and multi-step workflow management dominate; developer- and user-facing metrics trail.</p><div></div><p>Task completion reliability (32%) and multi-step workflow management (28%) together account for 59% of responses (60 of 101): orchestration succeeds, in the enterprise view, when it reliably carries a task through multiple steps to completion. Developer productivity (17%) matters but is secondary — the inverse of its prominence in framework discussion — and end-user experience (9%) is a minor concern, consistent with orchestration being an internal execution problem rather than a UX one. This reliability-first standard is exactly what makes the Chatbot Trap finding so pointed: enterprises define success as dependable multi-step execution, yet most of their deployed “agents” do not yet do multi-step work at all.</p><p>The trap is not evenly distributed. Splitting the sample by organization size, 77% of smaller enterprises say a quarter or fewer of their agents do true multi-step work, against 62% of larger ones. Larger enterprises are meaningfully further into genuine multi-step deployment; the chatbot trap is, directionally, a mid-market condition.</p><h2>Finding 4: Consolidate, productionize, and build in-house </h2><p><b>Three strategic moves are nearly tied for the year ahead</b></p><p>We asked what major change enterprises anticipate in their orchestration strategy over the next 12 months. Three moves cluster at the top, almost evenly split.</p><div></div><p>The top three — building in-house control (25%), standardizing on one framework (24%), and moving agents from sandbox to production (23%) — are statistically indistinguishable and tell a single story: enterprises are moving from experimentation to operational consolidation. They want fewer frameworks, more production exposure, and more ownership of the control layer; only 4% expect no change. The appetite for custom in-house control planes is notable alongside the platform concentration in Finding 1 — enterprises are standardizing on model-provider platforms while simultaneously planning to wrap them in control logic they own, the hybrid posture that Finding 6 makes explicit.</p><h2>Finding 5: Nearly seven in 10 plan to switch — and the biggest group of movers has no shortlist </h2><p>The strategic change enterprises anticipate (previous finding) comes with vendor motion attached. Asked whether they plan to adopt a new, additional, or replacement agent orchestration platform in the next twelve months, more respondents are moving here than in any other layer we track.</p><div></div><p>Asked which platforms they are considering, the most common answer among those in motion is none yet: 29% of all respondents are evaluating without a shortlist, the largest single response after "not considering a change." Among named candidates, OpenAI leads at 16%, followed by LangChain/LangGraph at 12% and Anthropic at 7% — and notably, the independent frameworks draw roughly double their current usage footprint in forward consideration, the same pattern our security tracker found for specialist vendors. Read with this report's concentration and lock-in findings, the picture completes itself: the major model-platform providers hold roughly four-fifths of today's primary usage, vendor lock-in has become the leading fear, 96% anticipate a strategic change — and now the purchase intent to act on all of it, with the largest bloc of buyers still undecided. The most concentrated layer of the agentic stack is also, as of June, the least settled.</p><h2>Finding 6: Investment flows to workflow tooling</h2><p><b>Tooling and permissions lead the spend; monitoring trails</b></p><p>We asked which orchestration-related investment will grow most next year. Agent workflow tooling leads, with security and permissions enforcement behind.</p><div></div><p>Workflow tooling leading (34%) is the budget-side expression of the reliability-and-multi-step priority in Finding 3: the money is going to the machinery that strings steps together dependably. Security and permissions enforcement (25%) and scaling infrastructure (20%) follow — the investments required to take agents from sandbox into production, the strategic move in Finding 4. Monitoring and debugging draws a smaller 11%, with another 11% reporting flat budgets. The weight on tooling, permissions, and scaling over pure observability signals that enterprises are spending to build and harden orchestration, not merely to watch it run.</p><h2>Finding 7: The control plane will be hybrid — and lock-in is why</h2><p><b>Enterprises expect to split control between providers and their own layer</b></p><p>We asked where enterprises expect the primary control plane for agents to live by the end of 2026, and what worries them most if that control sits inside a model-provider platform. A clear majority expect a hybrid model — and vendor lock-in is the reason.</p><div></div><p>Hybrid control is the dominant expectation by a wide margin (51%), and only 6% expect to hand control to a provider-managed service outright. Read together, the hybrid, custom, and externally-abstracted options — every architecture that keeps control at least partly outside the provider — sum to 88% (89 of 101). The reason surfaces directly when we asked about the risk of provider-resident control: vendor lock-in leads at 35% (35 of 101), ahead of security and permissioning limitations (28%) and inflexibility across models and tools (21%). The pattern echoes the prior wave’s “don’t trust the model to police itself” posture — here, enterprises will build on a provider’s platform but decline to be governed entirely by it. The hybrid control plane is the architectural hedge against the lock-in they most fear.</p><p>The June figure asserting a preference for a hybrid control plane marks movement from earlier. In the April–May survey (n=145), only 34% expected a hybrid control plane, and a greater number (12%) expected to hand control fully to a provider-managed service. These two snapshots don’t yet measure a confirmed longitudinal trend — but the direction of the conversation is unambiguous: toward keeping control.</p><p>Lock-in is also a new arrival as a top concern. In the April–May wave, the leading concern was security and permissioning limitations (32%), with lock-in second at 24%; by June the two had traded places. The worry about provider platforms appears to be maturing from whether they can be secured to whether they can be replaced.</p><h2>Finding 8: The chatbot trap — most “agents” aren’t agents yet</h2><p><b>Enterprises admit most deployments are still chatbot wrappers</b></p><p>We asked enterprises to assess their portfolios honestly: what share of their deployed “agents” are true multi-step orchestrated workflows versus simple single-prompt chatbot wrappers. The answer is the defining finding of this wave.</p><div></div><p>This is the gap at the center of the report. Combining the bottom two bands, 71% of enterprises (72 of 101) say a quarter or fewer of their deployed “agents” are genuinely orchestrated — and just 10% (10 of 101) have crossed the halfway mark. The ambition documented in the earlier findings — model-provider platforms, reliability-first success metrics, production rollouts, a deliberate control architecture — runs well ahead of the deployed reality, which remains overwhelmingly single-prompt assistants dressed as agents. This is less a contradiction than a roadmap: the platforms, budgets, and strategies are being put in place precisely because the orchestrated portfolio is still so thin. The open question for later waves is how fast the reality closes on the ambition.</p><h2>Finding 9: Fiscal control is still reactive</h2><p><b>Only a minority can stop a runaway agent before the bill arrives</b></p><p>Finally, we asked how enterprises enforce fiscal control over agent token consumption — the risk that an autonomous loop exhausts a budget before anyone intervenes. Most rely on native caps or after-the-fact monitoring; real-time programmatic control is the exception.</p><div></div><p>More than a quarter of enterprises (27%) admit they have no real-time, programmatic way to stop an agent before a budget-breaking bill arrives — they learn of it from the logs afterward. Another 32% lean entirely on the native caps and throttles built into their primary platform, a control only as good as the provider’s tooling and one that ties back to the lock-in concern of Finding 6. The enterprises building custom gateways (23%) or exploiting cross-model routing to arbitrage cost (19%) are the ones treating token burn as an engineering problem to be controlled deterministically. As with orchestration maturity, fiscal control is an area where the operational reality lags the ambition: agents are moving toward production faster than the cost-control plane around them is being built.</p><p>It’s worth noting, a split appears according to company size: roughly one in three enterprises under 2,500 employees (34%) exercises only reactive control of agent spend, against 20% of larger enterprises — directional figures, but consistent with the chatbot-trap split. The mid-market is running the least mature agents on the least instrumented budgets.</p><h2>The bottom line: The layer is real; most of the agents aren't yet</h2><p>Organizations with 100 or more employees describe an orchestration strategy that is consolidating quickly and maturing slowly. They are standardizing — for now — on model-provider platforms, which collectively hold roughly four-fifths of primary usage, chosen for the gravity of the underlying model, and they judge success by reliable multi-step execution. Investment is flowing to workflow tooling and permissions, the strategy is to consolidate frameworks and push agents into production, and the control plane they expect is deliberately hybrid, because vendor lock-in is the risk they fear most. But the standardization is provisional: 68% plan to adopt a new, additional, or replacement orchestration platform within twelve months — the highest switching intent of any layer we track — and the largest group of those movers has not yet shortlisted a candidate. Today's concentration describes where enterprises are, and visibly does not describe where they intend to stay.</p><p>But the honest self-assessment punctures the ambition. Seventy-one percent say a quarter or fewer of their deployed "agents" are truly orchestrated, only 10% are past the halfway mark, and more than a quarter cannot stop a runaway agent in real time. The orchestration layer — the platforms, the budgets, the control architecture — is being built ahead of the orchestrated portfolio it is meant to run. At 101 respondents in a single June wave this reads as a clear directional signal rather than a precise measurement: enterprises have decided how they want to orchestrate agents well before most of their agents are doing anything an orchestration layer is for. The questions for subsequent waves are whether the deployed reality closes the gap on the ambition — and, with nearly seven in ten buyers in motion and most of them undecided, which platforms the settled stack finally lands on.</p><hr><p><i>Based on survey responses from 101 qualified enterprise respondents (100+ employees), drawn from a single June 2026 wave. Because this is one wave rather than a pooled multi-month sample, results read directionally rather than as a confirmed trend. Respondents include product and program managers, CIOs, CTOs and CISOs, consultants and advisors, and directors and VPs of data, AI, and engineering, across Technology/Software, Financial Services, Healthcare, and other sectors.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The AI compute gap: Enterprises are buying infrastructure faster than they can measure what it costs]]></title>
<description><![CDATA[Across 107 enterprises, AI infrastructure spending is accelerating well ahead of the ability to see or steer its economics. Most organizations run their AI on a familiar base of hyperscalers and model-provider APIs, yet the next dollar is aimed at specialized compute almost none of them use today...]]></description>
<link>https://tsecurity.de/de/3689826/it-nachrichten/the-ai-compute-gap-enterprises-are-buying-infrastructure-faster-than-they-can-measure-what-it-costs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689826/it-nachrichten/the-ai-compute-gap-enterprises-are-buying-infrastructure-faster-than-they-can-measure-what-it-costs/</guid>
<pubDate>Thu, 23 Jul 2026 19:19:39 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Across 107 enterprises, AI infrastructure spending is accelerating well ahead of the ability to see or steer its economics. Most organizations run their AI on a familiar base of hyperscalers and model-provider APIs, yet the next dollar is aimed at specialized compute almost none of them use today; a majority intend to switch or add providers within the year, many within a quarter. Buying decisions turn on integration and total cost of ownership rather than headline token price — which is fortunate, because most enterprises cannot yet see their unit economics clearly: GPUs sit at half utilization or less, and fewer than half rigorously track what their compute actually costs. The result is a compute gap — heavy, fast-moving investment running ahead of the visibility needed to control it.</p><p>This wave of VentureBeat Pulse Research examines enterprise AI infrastructure and compute: where organizations are in their deployment journey, what they run AI on today, how satisfied they are, what would make them switch, where they plan to evaluate their investments, and — most revealingly — how well they can measure and control the economics of the compute underneath it all.</p><p>The central finding is a compute gap — the distance between how aggressively enterprises are investing in AI infrastructure and how little of its economics they can see. Only about one in five (21%) run AI in production at scale, yet spending intentions are outrunning that maturity: the single largest planned area enterprises plan to evaluate over the next year is AI-specialized clouds (45%), a layer almost none of these enterprises use today. Meanwhile the compute already in place runs cold — 83% report GPU utilization of 50% or less — and fewer than half (44%) can rigorously track what their AI compute costs. Enterprises are buying more infrastructure faster than they can account for what they already own.</p><p>Enterprises are not settled on their infrastructure vendors, either: A clear majority (64%) plan to switch or add an infrastructure provider within twelve months, and 38% within the next quarter — unusually high churn intent for a category this foundational. When they choose, they choose on integration with the existing stack (41%) and total cost of ownership (35%), not on headline price: cost per million tokens is the deciding factor for just 8%. And the frontier constraint that will shape the next round of decisions — the shift from GPU compute to memory bandwidth as inference scales — is barely on the radar, with roughly one in five enterprises either unaware of it or yet to address it.</p><h2>Methodology</h2><p>VentureBeat fielded this survey as part of its ongoing Pulse Research series, this survey focused on enterprise AI infrastructure, compute, and inference economics. Responses are filtered to organizations with more than 100 employees (n=107; the survey’s smallest size band, 1–100 employees, is excluded), drawn from a single Q2 2026 (June) wave. Because this is one wave rather than a pooled multi-month sample, the report reads cross-sectionally and does not infer month-over-month trends. Several questions were multiple-select, so those shares can sum to more than 100%.</p><p>By organization size the sample concentrates in the mid-market: 101–250 employees (36%) and 251–1,000 (27%) lead, with 1,001–5,000 (22%), 5,001–10,000 (8%), and 10,001+ (7%) above them. By role it spans managers (38%), individual contributors (28%), VPs and directors (19%), and the C-suite (13%); on purchasing authority it is buyer-credible, with 45% final decision-makers and another 30% recommenders or influencers for AI solutions. Technology/Software is the largest industry at 26%, followed by Healthcare/Life Sciences (15%), Financial Services (13%), and Retail/E-commerce (12%).</p><p>At 107 respondents the sample is large enough to read directionally but should be treated as a directional signal rather than a precise measurement; it is self-selected and is not a probability sample. It also skews toward the mid-market and toward earlier-stage adopters, so it is best read as the view from organizations actively building out AI infrastructure rather than from the largest hyperscale operators.</p><h2>Finding 1: Ambition outpaces production</h2><p><b>Only one in five run AI in production at scale</b></p><p>We asked where organizations sit in their AI deployment journey. Most are still building toward production rather than operating at scale.</p><div></div><p>The maturity curve is front-loaded. Three-quarters of enterprises (76%) are either experimenting or running only some workloads in production, and just 21% describe AI in production at scale. This matters for everything that follows: the infrastructure decisions in this report are being made largely by organizations still early in deployment, whose compute footprint — and whose costs — are about to grow. The evaluation and switching intentions in Findings 3 and 4 are the leading edge of that build-out, not the settled preferences of operators who have already found what works.</p><h2>Finding 2: Enterprises run on hyperscalers and model APIs</h2><p><b>The specialized GPU clouds barely register — today</b></p><p>We asked which providers and platforms enterprises currently use to run their AI. The answer is a familiar one: the incumbents.</p><div></div><p>The current stack is hyperscaler-and-API. Google Cloud leads at 48%, and the general-purpose clouds (Google, Microsoft, AWS, Oracle) together with the major model APIs (Gemini, OpenAI, Anthropic) account for essentially all current deployment. The specialized “neocloud” GPU providers that dominate AI-infrastructure headlines — CoreWeave, Lambda, Crusoe, Nebius and peers — register at or near zero among these enterprises today. Only 6% run their own on-prem GPU clusters and 4% a custom open-source stack. Enterprises are, for now, running AI on the providers they already buy from — which makes the evaluation intentions in Finding 3 all the more striking.</p><p><i>(A note on reading these shares. As described in the methodology section, this sample is self-selected and skews mid-market, and this question counted every provider a respondent uses — an average of 2.1 selections each — so the figures measure presence in the stack rather than spending or primary status. A sample built this way will show a different provider mix than a spend-weighted census of the broader market; Google's strength here, for example, is consistent with its long-standing position among smaller enterprises building on AI. Read these shares as a portrait of what this AI-active cohort runs today, and treat gaps between these figures and industry-wide market share estimates as a property of the sample rather than a contradiction of either.)</i></p><h2>Finding 3: The next dollar goes to infrastructure they don’t yet run</h2><p><b>AI-specialized clouds top the evaluations list</b></p><p>We asked where enterprises planned to evaluate AI infrastructure over the next 12 months. Their answers point away from the stack they run today.</p><div></div><p>Here is the report’s sharpest tension. The single most-cited planned evaluation area — AI-specialized clouds, at 45% — is the very category almost none of these enterprises use today (Finding 2). Nearly a third (32%) intend to evaluate non-Nvidia accelerators, and 28% in next-generation Nvidia silicon; even decentralized compute networks (16%) and sovereign compute (11%) draw meaningful interest. Read against current usage, this is not incremental — it is the leading edge of a re-platforming. The direction-of-travel question tells the same story: every infrastructure approach is net-expanding, but specialized AI clouds carry the highest net momentum (+24), edging out even the hyperscalers (+22). Enterprises are preparing to move a meaningful share of AI compute off the general-purpose cloud.</p><p>This continues a trend we saw in our April-May survey wave. Back then, usage of the AI-specialized clouds was equally marginal — CoreWeave at 3%, Lambda at 4%, Crusoe at 2% of enterprises. When we asked enterprises what change they planned in their AI infrastructure strategy over the next twelve months, the most-cited answer was moving workloads to specialized AI clouds, at 33%. Asked in April-May which emerging compute option they were most likely to evaluate AI-specialized clouds again drew the most responses. Two waves, two differently worded questions, one consistent picture: the type of cloud enterprises are most eager to assess is the type they have barely begun to use.</p><h2>Finding 4: A switching wave is building</h2><p><b>Six in 10 plan to change providers within a year — many within a quarter</b></p><p>We asked whether and when enterprises plan to switch or add an infrastructure provider. Very few intend to stand still.</p><div></div><p>For a category as foundational as compute, this is a remarkable amount of intended movement. Only 36% have no plans to change, meaning a clear majority (64%) intend to switch or add a provider within twelve months — and 38% within the next quarter alone. Where that interest points is telling: the providers drawing the most switching consideration are again the incumbents — Microsoft Azure and Google Cloud (33% each), OpenAI (30%), and Gemini (22%) — which suggests much of the near-term movement is reshuffling among the majors and consolidating spend rather than defecting to new entrants. The neocloud interest in Finding 3 is a 12-month evaluation thesis; the switching in the next quarter is mostly incumbents trading share.</p><p>(<i>Method note: Respondents who selected both "no plans to change" and a specific switching window are counted as switchers, on the logic that naming a timeframe is the more specific answer; three respondents were reclassified under this rule.</i>)</p><h2>Finding 5: Nobody buys on token price</h2><p><b>Integration and total cost of ownership decide — not sticker price</b></p><p>We asked what matters most when enterprises select an AI infrastructure provider. Headline price finished last.</p><div></div><p>Enterprises do not buy AI infrastructure on pricing, which is the place vendors compete on hardest. Integration with the existing stack (41%) and total cost of ownership (35%) dominate, while the headline metric — cost per million tokens — is the deciding factor for just 8%, dead last. The pattern is coherent: buyers are optimizing for how a provider fits and what it truly costs to operate, not for the advertised unit rate. It also foreshadows Finding 7 — enterprises say TCO matters most, yet most cannot yet measure it rigorously. The stated priority and the measured capability are out of step.</p><h2>Finding 6: Expensive GPUs, idle most of the time</h2><p><b>83% report GPU utilization of 50% or less</b></p><p>We asked what share of their GPU capacity enterprises actually utilize. The answer is a well-known but rarely quantified inefficiency.</p><div></div><p><i>Disclosure: Band percentages count every selection against all 107 qualified respondents; 14 respondents selected more than one band, so bands overlap. At the respondent level, 83 of the 100 GPU-operating enterprises reported utilization at or below 50%</i></p><p>The compute already in place runs cold. Adding the bands at or below half capacity, 83% of enterprises that operate GPUs report utilization of 50% or less, and nearly half (49%) run at 25% or below. Only 12% clear the 50% mark, and a further 8% do not measure utilization at all. Idle accelerators are expensive accelerators, and this is the clearest single measure of the compute gap: enterprises are planning to buy more GPUs and specialized compute (Finding 3) while the capacity they already own sits substantially unused. The efficiency headroom in the current fleet is large — and largely unmeasured.</p><h2>Finding 7: Spending fast, measuring slowly</h2><p><b>Fewer than half rigorously track what their compute costs</b></p><p>We asked whether enterprises can quantify the cost and return of their AI infrastructure spend, and how satisfied they are with what they run. Confidence in the ledger lags the spending.</p><div></div><p>Measurement trails money. Fewer than half of enterprises (44%) rigorously track the cost and return of their AI compute; the majority track only partially (39%), cannot quantify it yet (20%), or have not prioritized it (6%). That gap is consequential given Finding 5, where total cost of ownership was the second-ranked buying criterion — enterprises are choosing providers on an economic basis they mostly cannot yet measure. Satisfaction with current infrastructure is moderately positive but not enthusiastic: on a five-point scale, overall satisfaction averages 4.0, with ease of implementation (3.8) and value for money (3.9) trailing slightly — the softness landing, tellingly, on cost. Enterprises are spending quickly and accounting slowly.</p><h2>Finding 8: The next bottleneck few are watching</h2><p><b>As inference shifts from compute to memory, the field scatters</b></p><p>Finally, we asked how enterprises would address the emerging constraint in large-scale inference — the shift from GPU compute to memory, specifically KV-cache capacity. The responses reveal a frontier that is not yet a priority.</p><div></div><p>The memory frontier is real but barely governed. Asked which approach they would rely on as the binding constraint in inference shifts from compute to memory bandwidth, enterprises scatter: Dell leads at 31%, Nvidia follows at 16%, and the rest fragments across storage vendors, open-source tooling, and model-level efficiency techniques. Most telling is that roughly one in five (18%) either do not recognize the constraint or have not begun to address it. For a shift that will reshape inference cost and architecture, this is an early and unsettled market — and, consistent with the measurement gap in Finding 7, one where many enterprises simply do not yet have a view. It is the next chapter of the compute gap, arriving before most have closed the current one.</p><h2>The bottom line: A compute gap that faster spending will widen, not close</h2><p>Organizations with more than 100 employees are investing in AI infrastructure faster than they can measure it. Most are still early in deployment, yet their spending intentions point past their current stack — toward specialized clouds and alternative accelerators almost none of them run today — and a clear majority intend to change providers within the year. They buy on integration and total cost of ownership rather than headline price, which is rational; the difficulty is that most cannot yet see those economics clearly.</p><p>The visibility gap is concrete. The GPUs enterprises already own run at half utilization or less for the overwhelming majority, and fewer than half can rigorously track what their compute costs or returns. Satisfaction is decent but unenthusiastic, softest on value for money — the dimension hardest to judge without measurement. And the next constraint, the shift from compute to memory in large-scale inference, is arriving while most enterprises are still unaware of it. At 107 respondents in a single Q2 wave this is a directional read, skewed toward the mid-market and earlier-stage adopters — but the direction is consistent: the appetite to spend is running well ahead of the instrumentation to spend well. The compute gap is not a capacity problem that more hardware will solve on its own; it is, first, a problem of seeing what the hardware already costs. The open question for later waves is whether enterprises build that visibility before the re-platforming arrives — or buy the next layer of infrastructure as blind to its economics as the last.</p><hr><p><i>Based on survey responses from 107 qualified enterprise respondents (100+ employees), drawn from a single Q2 2026 (June) wave. Because this is one wave rather than a pooled multi-month sample, the results read cross-sectionally rather than as a month-over-month trend, and at 107 respondents this is a directional signal rather than a precise measurement — the sample is self-selected, skews mid-market, and leans toward earlier-stage adopters rather than the largest hyperscale operators. Respondents include managers, individual contributors, VPs/directors, and the C-suite, with buyer-credible purchasing authority, across Technology/Software, Healthcare/Life Sciences, Financial Services, Retail/E-commerce, and other industries.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Samsung Unveils Galaxy Z Fold8 Ultra and Fold8 at Unpacked 2026]]></title>
<description><![CDATA[Samsung's Galaxy Z Fold8 Ultra and Fold8 debut at Unpacked 2026 with new cameras, AI tools, prices, and clear trade-offs for buyers choosing a foldable.
The post Samsung Unveils Galaxy Z Fold8 Ultra and Fold8 at Unpacked 2026 appeared first on TechRepublic.]]></description>
<link>https://tsecurity.de/de/3687579/it-nachrichten/samsung-unveils-galaxy-z-fold8-ultra-and-fold8-at-unpacked-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687579/it-nachrichten/samsung-unveils-galaxy-z-fold8-ultra-and-fold8-at-unpacked-2026/</guid>
<pubDate>Wed, 22 Jul 2026 22:58:17 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Samsung's Galaxy Z Fold8 Ultra and Fold8 debut at Unpacked 2026 with new cameras, AI tools, prices, and clear trade-offs for buyers choosing a foldable.</p>
<p>The post <a href="https://www.techrepublic.com/article/news-samsung-fold8-ultra-fold8/">Samsung Unveils Galaxy Z Fold8 Ultra and Fold8 at Unpacked 2026</a> appeared first on <a href="https://www.techrepublic.com/">TechRepublic</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta’s Muse AI: How Instagram Users Can Opt Out After Privacy Backlash]]></title>
<description><![CDATA[  Meta’s short‑lived Muse Image AI on Instagram let users remix public photos into AI images by default, triggering a storm of privacy and consent backlash before Meta pulled the feature. Meta’s Muse Image tool was designed to turn Instagram…
Read more →
The post Meta’s Muse AI: How Instagram Use...]]></description>
<link>https://tsecurity.de/de/3687246/it-security-nachrichten/metas-muse-ai-how-instagram-users-can-opt-out-after-privacy-backlash/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687246/it-security-nachrichten/metas-muse-ai-how-instagram-users-can-opt-out-after-privacy-backlash/</guid>
<pubDate>Wed, 22 Jul 2026 20:24:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>  Meta’s short‑lived Muse Image AI on Instagram let users remix public photos into AI images by default, triggering a storm of privacy and consent backlash before Meta pulled the feature. Meta’s Muse Image tool was designed to turn Instagram…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/metas-muse-ai-how-instagram-users-can-opt-out-after-privacy-backlash/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/metas-muse-ai-how-instagram-users-can-opt-out-after-privacy-backlash/">Meta’s Muse AI: How Instagram Users Can Opt Out After Privacy Backlash</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[4 recs for CIOs to optimize AI budgets and improve sustainability]]></title>
<description><![CDATA[In the client-server era, the penalty for inefficient programming, such as unoptimized database calls, was largely confined to application responsiveness. Today, in the AI era, code, architectural, and platform inefficiencies are no longer just a performance issue, they’re a financial and environ...]]></description>
<link>https://tsecurity.de/de/3685758/it-security-nachrichten/4-recs-for-cios-to-optimize-ai-budgets-and-improve-sustainability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685758/it-security-nachrichten/4-recs-for-cios-to-optimize-ai-budgets-and-improve-sustainability/</guid>
<pubDate>Wed, 22 Jul 2026 11:11:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">In the client-server era, the penalty for inefficient programming, such as unoptimized database calls, was largely confined to application responsiveness. Today, in the AI era, code, architectural, and platform inefficiencies are no longer just a performance issue, they’re a financial and environmental liability. Left unchecked, poor code cascades into soaring token costs and spikes data center power consumption, directly undermining both cloud budgets and corporate sustainability goals.</p>



<h2 class="wp-block-heading">AI’s impact on sustainability</h2>



<p class="wp-block-paragraph">By 2029, IDC projects that the number of actively deployed AI agents will exceed 1 billion worldwide, which is 40 times more than in 2025. And these agents will perform 217 billion actions per day.</p>



<p class="wp-block-paragraph">To deliver on this demand, AI data centers are being built out at an unprecedented rate, with Gartner forecasting that <a href="https://www.gartner.com/en/newsroom/press-releases/2026-02-03-gartner-forecasts-worldwide-it-spending-to-grow-10-point-8-percent-in-2026-totaling-6-point-15-trillion-dollars">global spending on data centers</a> over the next three years will increase 31.7% to surpass $650 billion, driven primarily by hyperscaler cloud providers building out AI foundations, and optimizing servers for heavy AI workloads.</p>



<p class="wp-block-paragraph">All this presents a significant strain on the energy grid as well as environmental sustainability, including:</p>



<ul class="wp-block-list">
<li><strong>The power double-down:</strong> The <a href="https://energy.ec.europa.eu/news/focus-data-centres-energy-hungry-challenge-2025-11-17_en">International Energy Agency</a> (IEA) projects that global data center electricity consumption will more than double from about 415 to 945 TWh by 2030, primarily fueled by energy-intensive accelerated computing for AI.</li>



<li><strong>The inference premium:</strong> AI workloads are vastly more demanding than standard web activities. A gen AI query consumes roughly <a href="https://www.brookings.edu/articles/global-energy-demands-within-the-ai-regulatory-landscape/">10 times the electricity</a> of a conventional keyword search, or roughly 2.9 watt-hours as opposed to 0.3 watt-hours.</li>



<li><strong>Water consumption:</strong> Cooling these dense clusters is highly resource intensive. Global AI-related water demand is expected to reach <a href="https://aimultiple.com/ai-energy-consumption">4.2 to 6.6 billion cubic meters by 2027</a>.</li>
</ul>



<p class="wp-block-paragraph">The good news, however, is it’s not all out of the control of end user organizations and CIOs. Just as in the client-server era, through careful planning and execution, CIOs have the potential to significantly improve the performance, costs, and sustainability impacts of their AI application portfolio.</p>



<p class="wp-block-paragraph">Here are four recommendations to maximize value as you look across your AI applications and infrastructure estate.</p>



<h2 class="wp-block-heading">Revisit business objectives in light of AI</h2>



<p class="wp-block-paragraph">AI applications and platforms bring several new headaches for CIOs and CFOs in terms of FinOps. The variable nature of <a href="https://www.cio.com/article/4169954/servicenows-ai-control-tower-offers-hazy-view-of-spend.html">AI vendor billing due to variable monthly token costs</a> is just one well-known example. To avoid unpleasant surprises, be sure to carefully review vendor contracts to decipher pricing models. Look for what’s included in seat-based license fees and what’s added as variable charges for agentic AI usage.</p>



<p class="wp-block-paragraph">In addition, explore new metrics and KPIs such as intelligence per watt to help make sense of your return on AI. Just as miles per gallon helps us evaluate new car purchases, IPW can help to measure the computational efficiency of a system. It quantifies how much intelligence — typically measured in AI inferences, tokens processed, or model training iterations — a processor can deliver for every watt of electrical power it consumes.</p>



<p class="wp-block-paragraph">According to Max Romanenko, chief engineering officer at relational database platform EDB, cost per query tells you almost nothing in an agentic world where autonomous systems are spinning up databases, pipelines, and queries around the clock. “The metric that matters is intelligence per watt, how much useful AI you get for every unit of energy you spend,” he says. “It isn’t just an environmental number, it’s also a performance indicator.”</p>



<p class="wp-block-paragraph">With the measurements in place, you can then start to manage and optimize each layer in the AI stack from the infrastructure, or hyperscaler, layer to your own data and application layers.</p>



<p class="wp-block-paragraph">It’s important to bear in mind that high token usage isn’t necessarily a bad thing. It depends on the net value delivered by each AI application and use case. Managing and optimizing the AI stack is important, but you’ll also want to measure the business value being delivered by each of these applications so you can measure your return.</p>



<h2 class="wp-block-heading">Take a sovereign AI approach when evaluating hyperscalers</h2>



<p class="wp-block-paragraph">As you work with hyperscalers like Amazon, Google and Microsoft, it’s important to understand how they charge and how much, but also their environmental footprints. For example, by reading their sustainability reports, you can find out their annual water consumption across their global data centers and compare them with other providers.</p>



<p class="wp-block-paragraph">In 2025, Amazon’s global data center operations used <a href="https://www.aboutamazon.com/news/sustainability/amazon-data-center-water-usage">0.12 liters of water per kilowatt-hour</a>, which amounts to 2.5 billion gallons, or 5% of the annual water consumed by the metro Seattle area. The company has been able to operate more than seven times better than the industry average and have improved their water efficiency by 52% since 2021.</p>



<p class="wp-block-paragraph">As demand for cloud computing and AI grows, water efficiency is another important metric for CIOs to monitor within hyperscaler ESG reports. While not at the same level of regulation as scope 2 and 3 greenhouse gas (GHG) emissions reporting, enterprises need to pay increasing attention to water use efficiency (WUE) with water scarcity becoming a growing risk for hyperscalers.</p>



<p class="wp-block-paragraph">The key requisite at the infrastructure layer, though, is to ensure sovereign AI. This doesn’t mean you need to own everything, but you need control over your AI-driven operations when conditions change. With <a href="https://www.ibm.com/thought-leadership/institute-business-value/en-us/report/ai-sovereignty">71% of global executives stating that switching their primary AI vendor or model would be difficult if required today</a>, it’s important to understand AI dependencies and be able to avoid vendor lock-in. </p>



<h2 class="wp-block-heading">Control efficiency at the data layer</h2>



<p class="wp-block-paragraph">The AI energy conversation has fixated on models and GPUs, but every agent, model, and inference call runs on the data layer beneath them, and that’s the one place a CIO can actually move the numbers.</p>



<p class="wp-block-paragraph">“You can’t control consumption at the model layer,” says Romanenko. “Agents consume what they consume. But you can control efficiency at the data layer, and for most enterprises that’s the only real lever they have. Optimize search, retrieval, and vector indexing where the work actually happens and you cut compute, cost, and carbon at the same time. Ignore it, and it’s like running the heat with every window open.”</p>



<p class="wp-block-paragraph">Ann Dunkin, distinguished professor of the practice at Georgia Tech, adds that CIOs who bring models in house and run them in their own infrastructure, or in the cloud infrastructure of their choosing, can have more control over the sustainability of inference, as well as of their costs and how their data is used.</p>



<h2 class="wp-block-heading">Fine tune the application layer</h2>



<p class="wp-block-paragraph">When balancing a mix of commercial AI packages and custom-built code, costs can quickly spiral due to inefficient design and orchestration, redundant APIs, and unoptimized model routing.</p>



<p class="wp-block-paragraph">With inference calls costing approximately 10 times that of conventional web queries, for custom AI applications, it’s important to design them to only use probabilistic code where necessary. Since many custom applications utilize a combination of both <a href="https://www.cio.com/article/4133150/4-tips-to-help-the-new-innovators-struggle-with-ai-and-traditional-code.html">probabilistic and deterministic code</a>, this is exactly where software developers need to make smart choices in their designs.</p>



<p class="wp-block-paragraph">Other techniques to fine tune the application layer include semantic caching, intelligent model routing, and internal AI capability registries. “CIOs can implement intelligent routing solutions to select the most cost-efficient model for every prompt,” says Dunkin. “The most flexible routing solutions can drop into a user’s existing environment and orchestrate the actions of the company’s existing models.”</p>



<p class="wp-block-paragraph">For CIOs looking to maximize the business value of every AI application in their portfolio, these new considerations, including new metrics, tools and approaches from the infrastructure layer all the way up to the application layer, should be an essential part of the equation.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic coding is everywhere]]></title>
<description><![CDATA[I use a very cool and relatively new web framework called Astro. The keen insight that the Astro team had was that most websites are made up of static content, so they made it really easy to add content to a website. To add a blog post to my personal website, all I have to do is create a Markdown...]]></description>
<link>https://tsecurity.de/de/3685748/ai-nachrichten/agentic-coding-is-everywhere/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685748/ai-nachrichten/agentic-coding-is-everywhere/</guid>
<pubDate>Wed, 22 Jul 2026 11:04:58 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">I use a very cool and relatively new web framework called <a href="https://www.infoworld.com/article/3842325/designing-a-dynamic-web-application-with-astro-js.html" data-type="link" data-id="https://www.infoworld.com/article/3842325/designing-a-dynamic-web-application-with-astro-js.html">Astro</a>. The keen insight that the Astro team had was that most websites are made up of static content, so they made it really easy to add content to a website. To add a blog post to <a href="https://nickhodges.com/">my personal website</a>, all I have to do is create a Markdown file with some front matter, deploy it, and the blog post automatically appears. If I need to reach deeper for more dynamic functionality, I can easily do that with <a href="https://www.infoworld.com/article/2257305/what-is-typescript-strongly-typed-javascript.html" data-type="link" data-id="https://www.infoworld.com/article/2257305/what-is-typescript-strongly-typed-javascript.html">TypeScript</a>, <a href="https://www.infoworld.com/article/2253289/react-tutorial-get-started-with-the-reactjs-javascript-library.html" data-type="link" data-id="https://www.infoworld.com/article/2253289/react-tutorial-get-started-with-the-reactjs-javascript-library.html">React</a>, or almost any other framework. It’s really cool.</p>



<p class="wp-block-paragraph">And these days, I really don’t write any code. <a href="https://www.infoworld.com/article/4136718/claude-code-is-blowing-me-away.html" data-type="link" data-id="https://www.infoworld.com/article/4136718/claude-code-is-blowing-me-away.html">Claude Code</a> does most (all?) of the work. Since Astro is <a href="https://github.com/withastro/astro">an open-source project</a> and has <a href="https://docs.astro.build/">excellent documentation</a>, Claude knows all about how Astro works. It has no trouble at all managing my site and making the improvements I ask for.  </p>



<p class="wp-block-paragraph">And that got me thinking, how does Astro get built? Is the Astro team building with agentic coding? Astro itself has many dependencies, including big projects like Vite and Node. And of course, Vite and Node have dependencies, too. Are those dependencies being developed by hand, or are those development teams also using AI agents to code?</p>



<p class="wp-block-paragraph">My curiosity got the best of me, and I asked Claude to dig deeper. It turns out that the Astro repository has <a href="https://github.com/withastro/astro/blob/main/AGENTS.md">an AGENTS.md</a> file, and some of the commits even have commit message trailers indicating that they were at least co-authored by Claude and <a href="https://www.infoworld.com/article/3609013/github-copilot-everything-you-need-to-know.html" data-type="link" data-id="https://www.infoworld.com/article/3609013/github-copilot-everything-you-need-to-know.html">GitHub Copilot</a>. Further down, there is a <code>.agents/skills</code> directory with skills covering development, merging, triage, and more. I poked around for a look, and someone has done a great job building agentic support.</p>



<p class="wp-block-paragraph">Now my interest is really piqued, and further investigation reveals quite a bit of interesting stuff. About a year ago, documentation started appearing about how to build Astro sites with coding agents.  Around that same time, the docs team released an <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html" data-type="link" data-id="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">MCP server</a> that gives developers coding agents deeper, easier access to the Astro documentation.  </p>



<p class="wp-block-paragraph">And there are small steps in the Astro codebase that indicate it is “agentic ready.” For instance, the command-line development server can tell when it is being started by an agent, and the application itself can tell if it is being driven by an agent. Small things, but steps in the direction of embracing Astro developers who use coding agents. </p>



<p class="wp-block-paragraph">Okay, that was a fun spelunking trip. But so what?</p>



<p class="wp-block-paragraph">The “so what” is that code is going to be commoditized. As an Astro developer I am using AI agents pretty much all of the time. The Astro development team is starting to use AI agents more and more. The folks building the Astro dependencies are using AI agents. Shoot, the people building Claude Code and the agents themselves are “eating their own dogfood” and <a href="https://www.anthropic.com/institute/recursive-self-improvement">using their own tools to build the next frontier model</a>. Before we know it, it will be <a href="https://en.wikipedia.org/wiki/Turtles_all_the_way_down">turtles all the way down</a>. </p>



<p class="wp-block-paragraph">No one says “who generated that electricity?” or “who wove the fabric in that shirt?” any more. And it won’t be long before no one says “Who wrote the code for that app?” because it won’t matter. Just as we don’t look at the assembly code written by our compilers, we’ll stop looking at the “regular” code written by our agents. I’m not even sure anyone is <a href="https://news.ycombinator.com/item?id=39587051" data-type="link" data-id="https://news.ycombinator.com/item?id=39587051">writing assembly code anymore</a>. Soon we’ll be saying that about TypeScript, Python, and C++.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Evals are the new PRD, Expedia’s AI chief tells VB Transform 2026]]></title>
<description><![CDATA[“The new PRD are the evals,” Xavi Amatriain, Expedia Group’s first chief AI and data officer, told the VB Transform 2026 audience last week in Menlo Park. “So basically, you encode what you want the product to do through your evals, which might include red teaming evals and all kinds of other thi...]]></description>
<link>https://tsecurity.de/de/3684604/it-nachrichten/evals-are-the-new-prd-expedias-ai-chief-tells-vb-transform-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684604/it-nachrichten/evals-are-the-new-prd-expedias-ai-chief-tells-vb-transform-2026/</guid>
<pubDate>Tue, 21 Jul 2026 20:19:07 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>“The new PRD are the evals,” Xavi Amatriain, <a href="https://www.expediagroup.com/en-us">Expedia Group’s</a> first chief AI and data officer, told the <a href="https://venturebeat.com/vbtransform2026">VB Transform 2026</a> audience last week in Menlo Park. “So basically, you encode what you want the product to do through your evals, which might include red teaming evals and all kinds of other things, which already have a bunch of security requirements. So, you already embed that into the PRD and the product design document before you even start coding.”</p><p>He pushed it further. “With AI-assisted or AI-generated code, that’s gonna be the future. It’s like all your thinking is gonna go into the evals.”</p><p>Amatriain served as VP of AI and Compute Enablement at Google across the platforms powering Gemini and Google Search before his December 2025 appointment at Expedia. He's mentored talent who went on to found Perplexity and Scale AI. </p><p>VentureBeat’s <a href="https://venturebeat.com/orchestration/enterprise-ai-is-entering-an-evaluation-gap-agents-are-gaining-autonomy-faster-than-companies-can-verify-them">VB Pulse research on the evaluation gap</a> reinforced the stakes. Sixty-six percent of the 157 enterprises surveyed already permit some production deployment without human review or are building toward it within the next 12 months, yet only 5% fully trust the automated evaluations that would make that decision. Half have shipped an agent that passed internal evals but then failed with a real customer.</p><h2><b>Don’t let guardrails get in the way of feedback</b></h2><p>“The more guardrails and artificial business rules and sort of rules that you put into the system, the worse off,” Amatriain said. “Not only because they’re brittle, but also because they actually mess up with the feedback loop. You are actually biasing the user and the feedback you get from the user, and then you’re learning that in the wrong way.” He called guardrails “a necessary evil” and said the goal is to minimize their impact over time.</p><p>Not everyone at Transform agreed. Other speakers argued during the event that the highest-risk actions still demand very firm guardrails.</p><p>Expedia governs AI through three layers instead. Principles come first, communicated broadly. “I like to encode at a very high level how I expect decisions to be made, because in a large organization you’re gonna have a lot of distributed decision making,” Amatriain said. “And sometimes, if you’re lucky enough, those principles might be embedded in your culture. But most of the time, my experience has been they’re not.” The processes and tools that enforce them follow. “Principles look really nice on a picture on some wall, but you need to then give them teeth,” he said. Automation sits on top of both.</p><p>In practice, this plays out through what Expedia calls agent release toll gates, checkpoints calibrated to risk. “Governance needs to correlate to the risk,” Amatriain said. “And if you have something that is low risk, you don’t need too much governance to get in the way. But if there’s a lot of risk, then you need more governance. That can be encoded.” The toll gates tie evaluation rounds, red teaming, and security review to each agent’s risk level, and <a href="https://venturebeat.com/orchestration/what-billions-of-ai-predictions-taught-expedia-before-the-age-of-ai-agents">the checks shift from recommended to required as the stakes climb</a>. </p><h2>Specialized agents over monolithic intelligence</h2><p>“Even when I was at Google, I was like, I don’t believe in AGI as sort of like a singleton and a unified sort of like single model,” Amatriain told the audience. “I think it’s much better to think of it as composition, sort of like having specialized agents that are very good at some task and then composing the system out of those specialized agents.”</p><p>Expedia’s architecture starts at the component level. Tools compose into skills, skills assemble into sub-agents, and sub-agents get orchestrated into the full agentic system. “You need to have those principles that are unified that talk about things like what is the tone that we’re using, how are we addressing the user, how are we passing context, memory,” he said. “All of that needs to be thoroughly designed.” He framed this as a systemic design problem. “It’s not about the model, it’s not about a specific solution, it’s about how you’re designing the system.”</p><p>Amatriain argued that scoping each agent narrowly also makes the system easier to secure, since teams can evaluate and lock down individual agents in isolation before composing them.</p><h2>When the user must keep the final click</h2><p>Travel pricing changes in real time, flight availability shifts minute to minute, and hotel reviews routinely contradict what suppliers claim. Amatriain described a system that blends retrieval-augmented generation with direct API tool calls, choosing the approach based on latency. “If the user asks you a question like, how much does a four star hotel usually cost in Chicago in July, you don’t expect the agent to take two minutes to answer that question,” he said. “You expect an immediate answer because that answer can be cached and it doesn’t need real-time information.” A pet-friendly four-star near Lake Michigan with a pool might justify a 30-second reasoning window.</p><p>“The supplier might be saying, yeah, we have a great swimming pool, but then we also have the reviews from the travelers and we actually see there’s two reviews that say the swimming pool was not great or was not open after 6 p.m.,” Amatriain explained. A generic chatbot, he added, would only surface what a supplier self-reports, while Expedia cross-references against its own review corpus.</p><p>“We don’t want the agent to book the hotel or to buy you a plane ticket for you,” Amatriain said. “That’s something that the user has to have the agency. And the agent can recommend, can suggest, can discuss with you, but you’re gonna have to hit that click. And that’s non-negotiable.” That constraint, he argued, is also a security decision. “Once you establish those design principles, you also don’t need the guardrail because otherwise you’re gonna have to put all those guardrails in after the fact.”</p><h2>The next attackers will be other AI systems</h2><p>“Security needs to be a principle that is shifted as left as possible and as part of the design itself,” Amatriain said in response to an audience question. “And usually when you need a guardrail is because you’ve not thought about it early on.”</p><p>A second audience member pressed for lessons learned from production. Amatriain described a feedback loop where monitoring signals flow back into the eval suite. “You can almost automate the whole cycle,” he said. “But having that whole feedback loop from real signals, from your operating AI system, all the way into being reported and fixed as quickly as possible is going to become essential.”</p><p>Amatriain's toll gates are a bet that governance calibrated to risk can stay ahead of that feedback loop. VentureBeat’s separate June <a href="https://venturebeat.com/security/shared-api-keys-expose-ai-agent-fleets-venturebeat-research">Pulse survey on agent security</a>, drawn from 107 enterprises, shows how thin that margin is. More than half, 54 percent, have already had an agent security incident or near-miss. Fifty-nine percent plan to adopt, add, or replace agent security tooling within 12 months, and 29% plan to move this quarter. Incident rates climb with organization size, reaching 63% among enterprises with more than 1,000 employees versus 49% for companies with 101 to 1,000. And sandbox isolation, the one post-breach control that limits damage, drops from 35% adoption at the smaller companies to just 20 percent at the largest.</p><p>Amatriain warned that threats will increasingly come from other AI systems. “You’re gonna get threats coming not only from humans but also from other external agentic systems that are really powerful, and they’re gonna be poking at everything you’re doing. And as soon as you detect something, it’s not only about the detection, but the time to fix becomes essential here.”</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ignore Apple, Pay the Price]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:4 Patrick Wardle shares the biggest lesson he learned after years of building macOS security tools: follow Apple's recommended development practices whenever possible.

Choosing unsupported techniques may seem like the better engine...]]></description>
<link>https://tsecurity.de/de/3684349/it-security-video/ignore-apple-pay-the-price/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684349/it-security-video/ignore-apple-pay-the-price/</guid>
<pubDate>Tue, 21 Jul 2026 18:19:14 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:4 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/XwYHnlMnzm0?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Patrick Wardle shares the biggest lesson he learned after years of building macOS security tools: follow Apple's recommended development practices whenever possible.<br />
<br />
Choosing unsupported techniques may seem like the better engineering decision at first, but platform changes often make those shortcuts expensive to maintain. Apple's evolving security model rewards developers who work with the platform instead of against it.<br />
<br />
Have you ever chosen the "clever" solution over the recommended one, and did it pay off—or create more work later?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#Apple #AppSec #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[A touchscreen and light make the new X4 Pro the best version of Xteink’s tiny e-readers]]></title>
<description><![CDATA[The familiar story with Xteink’s tiny e-readers plays out once again with its new X4 Pro: upgraded hardware held back by frustrating software. The company’s latest tiny e-reader adds a touchscreen and lighting, so choosing it over a Kindle or a Kobo feels like less of a compromise — until you use...]]></description>
<link>https://tsecurity.de/de/3683941/it-nachrichten/a-touchscreen-and-light-make-the-new-x4-pro-the-best-version-of-xteinks-tiny-e-readers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683941/it-nachrichten/a-touchscreen-and-light-make-the-new-x4-pro-the-best-version-of-xteinks-tiny-e-readers/</guid>
<pubDate>Tue, 21 Jul 2026 16:03:32 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The familiar story with Xteink’s tiny e-readers plays out once again with its new X4 Pro: upgraded hardware held back by frustrating software. The company’s latest tiny e-reader adds a touchscreen and lighting, so choosing it over a Kindle or a Kobo feels like less of a compromise — until you use it. The new […]]]></content:encoded>
</item>
<item>
<title><![CDATA[5 questions to ask before choosing a robot lawn mower, according to a lawnbot exec]]></title>
<description><![CDATA[Lawnbots can be confusing — here's a simple way to narrow down your options, so you end up with the right model for you.]]></description>
<link>https://tsecurity.de/de/3683602/it-nachrichten/5-questions-to-ask-before-choosing-a-robot-lawn-mower-according-to-a-lawnbot-exec/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683602/it-nachrichten/5-questions-to-ask-before-choosing-a-robot-lawn-mower-according-to-a-lawnbot-exec/</guid>
<pubDate>Tue, 21 Jul 2026 14:03:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Lawnbots can be confusing — here's a simple way to narrow down your options, so you end up with the right model for you.]]></content:encoded>
</item>
<item>
<title><![CDATA[The next AI bottleneck is not the model. It’s the infrastructure behind it]]></title>
<description><![CDATA[Every enterprise AI conversation seems to begin with the same question: Which model should we use?



I understand why. Models are visible. They have names, benchmarks, release notes, pricing pages and impressive demos. They are easy to compare in a leadership meeting. One model promises better r...]]></description>
<link>https://tsecurity.de/de/3683109/it-nachrichten/the-next-ai-bottleneck-is-not-the-model-its-the-infrastructure-behind-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683109/it-nachrichten/the-next-ai-bottleneck-is-not-the-model-its-the-infrastructure-behind-it/</guid>
<pubDate>Tue, 21 Jul 2026 11:03:50 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Every enterprise AI conversation seems to begin with the same question: Which model should we use?</p>



<p class="wp-block-paragraph">I understand why. Models are visible. They have names, benchmarks, release notes, pricing pages and impressive demos. They are easy to compare in a leadership meeting. One model promises better reasoning. Another offers a larger context window. Another appears faster, cheaper or more specialized.</p>



<p class="wp-block-paragraph">But after years of working around enterprise platforms, integration layers, cloud migration, middleware, production operations and mission-critical systems, I see the AI conversation differently.</p>



<p class="wp-block-paragraph">The model matters. But it is not where most enterprises will struggle next.</p>



<p class="wp-block-paragraph">The next AI bottleneck is the infrastructure behind the model.</p>



<p class="wp-block-paragraph">I do not mean only GPUs, cloud capacity or data storage. I mean the full enterprise operating layer that allows AI to work safely in the real world: data pipelines, identity, APIs, messaging, observability, security controls, deployment automation, cost governance, auditability, support ownership and recovery design.</p>



<p class="wp-block-paragraph">That layer is what determines whether AI remains an exciting experiment or becomes a trusted business capability.</p>



<h2 class="wp-block-heading">Pilots hide the hard part</h2>



<p class="wp-block-paragraph">Most organizations can build an <a href="https://www.cio.com/article/4159287/most-companies-are-stuck-on-ai-chat.html">impressive AI pilot</a>. A small team can connect a model to a dataset, create a workflow and show a use case that works well in a controlled setting.</p>



<p class="wp-block-paragraph">The harder part starts when that pilot moves into a <a href="https://www.cio.com/article/4161509/ai-hype-to-ai-value-escaping-the-activity-trap.html">real production process</a>.</p>



<p class="wp-block-paragraph">That is when practical questions show up. Who owns the data quality? What systems can the AI access? How do we trace which prompt, policy or retrieval flow produced a specific answer? What happens when an API slows down, a queue backs up or a downstream system is unavailable?</p>



<p class="wp-block-paragraph">To me, these are not model problems. They are infrastructure problems.</p>



<p class="wp-block-paragraph">This is where many enterprises are now headed. The first phase of AI was experimentation. The next phase is operationalization, and that is where the real gap becomes clear.</p>



<p class="wp-block-paragraph"><a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/seizing-the-agentic-ai-advantage">McKinsey</a> has made a similar point in its work on agentic AI, noting that the next phase of value depends less on isolated tools and more on redesigning workflows, operating models and enterprise execution around agents.</p>



<p class="wp-block-paragraph">AI pilots can survive on enthusiasm. Production AI requires architecture.</p>



<h2 class="wp-block-heading">AI is becoming an integration problem</h2>



<p class="wp-block-paragraph">The more I look at enterprise AI, the more it feels like an integration challenge.</p>



<p class="wp-block-paragraph">In large organizations, I have seen how messaging platforms, integration gateways, deployment pipelines, monitoring tools and cloud infrastructure can decide whether a digital capability succeeds or fails. AI will be no different. Even the strongest model will struggle if the data, middleware, identity layer and operational controls around it are weak.</p>



<p class="wp-block-paragraph">AI does not work in isolation. It needs context from systems of record, clean data from different business areas, secure access to APIs, event streams, workflows, knowledge repositories, monitoring tools and legacy systems.</p>



<p class="wp-block-paragraph">That is why the CIO question is changing.</p>



<p class="wp-block-paragraph">It is no longer just, “Which AI tool should we buy?”</p>



<p class="wp-block-paragraph">It is becoming, “Can we safely operationalize intelligence across the business?”</p>



<p class="wp-block-paragraph">This is where agentic AI matters. Autonomous AI only creates real value when the architecture around it can make its actions safe, traceable and useful.</p>



<p class="wp-block-paragraph">A model can generate an answer. Infrastructure determines whether that answer is secure, timely, explainable, governed and connected to the right workflow.</p>



<p class="wp-block-paragraph">For example, an AI assistant that summarizes customer or order information may look like a model use case. But underneath, it depends on access control, fresh data, reliable APIs, logging, encryption, monitoring and policy enforcement.</p>



<p class="wp-block-paragraph">If the answer is wrong, people may blame the model. But the real failure may have started with stale data, weak integration, poor access design, missing observability or an unreliable downstream system.</p>



<p class="wp-block-paragraph">That is why CIOs should not judge AI only by model capability. The enterprise system around the model matters just as much.</p>



<h2 class="wp-block-heading">Latency will become a trust issue</h2>



<p class="wp-block-paragraph">In traditional technology operations, latency is often treated as a performance metric. In AI-enabled workflows, latency becomes a trust issue.</p>



<p class="wp-block-paragraph">When an employee asks an AI assistant for help and the response takes too long, the employee stops using it. When a customer-facing workflow becomes slow, the customer abandons it. When an AI agent waits on multiple backend calls, the entire business process feels unreliable.</p>



<p class="wp-block-paragraph">This becomes even more important as organizations move from simple chat interfaces to agentic workflows. A single AI-driven action may include identity checks, context retrieval, policy validation, model reasoning, API calls, business-rule execution, logging and human approval.</p>



<p class="wp-block-paragraph">Each step adds latency. Each dependency adds a possible failure point.</p>



<p class="wp-block-paragraph">A model may be fast in a benchmark but slow inside an enterprise process. That difference matters.</p>



<p class="wp-block-paragraph">This is where platform engineering becomes essential. Enterprises need reusable patterns for AI workloads: approved connectors, secure retrieval methods, queue-based decoupling, caching strategies, deployment pipelines, monitoring dashboards and standard rollback procedures.</p>



<p class="wp-block-paragraph">Without those patterns, every AI initiative becomes a custom build. Custom builds may work for pilots, but they do not scale across a large enterprise.</p>



<h2 class="wp-block-heading">Observability has to expand</h2>



<p class="wp-block-paragraph">Traditional monitoring tells us whether infrastructure is healthy. Is the server up? Is CPU high? Is memory exhausted? Is the application returning errors?</p>



<p class="wp-block-paragraph">AI needs that, but it also needs more.</p>



<p class="wp-block-paragraph">We need to know what data was retrieved, which model was used, which prompt version was active, which user initiated the request, which policy was applied, how long each step took and whether the output passed validation.</p>



<p class="wp-block-paragraph">We also need to detect new forms of risk: unusual usage patterns, repeated failed tool calls, unexpected cost spikes, sensitive data exposure, weak retrieval results or an AI workflow attempting actions outside its intended boundary.</p>



<p class="wp-block-paragraph">In production AI, observability is not only about uptime. It is about confidence.</p>



<p class="wp-block-paragraph">If a business leader, auditor, regulator or security team asks why an AI system made a recommendation, the answer cannot be, “The model said so.” The enterprise needs traceability. It needs evidence. It needs operational context that engineers, risk teams and business owners can understand.</p>



<p class="wp-block-paragraph">This is one of the biggest gaps I see in AI strategy. Many organizations are investing in models and use cases, but not enough in the control plane required to manage them.</p>



<h2 class="wp-block-heading">Data readiness is still underestimated</h2>



<p class="wp-block-paragraph">AI has exposed an uncomfortable truth: many enterprises are not as data ready as they think.</p>



<p class="wp-block-paragraph">Data is often duplicated across platforms, described differently by each team, governed inconsistently and refreshed on different schedules. Access rules may be clear in one system but unclear in another. Even basic business definitions can change from department to department.</p>



<p class="wp-block-paragraph">AI does not fix that automatically. In many cases, it makes the problem more visible.</p>



<p class="wp-block-paragraph">A bad report may be questioned. A bad AI answer may sound confident enough to be trusted.</p>



<p class="wp-block-paragraph">That is a real risk.</p>



<p class="wp-block-paragraph">Being data-ready for AI is not just about connecting a vector database or indexing documents. It requires clear ownership, lineage, classification, quality checks, retention rules, access boundaries and a shared understanding of which data should be used for which purpose.</p>



<p class="wp-block-paragraph">The same principle applies to resilient cloud-native design. In my IEEE TechRxiv paper, “<a href="https://www.techrxiv.org/doi/full/10.36227/techrxiv.175433366.65304469/v1">Enabling Fault-Tolerant Multicast in Cloud-Native Architectures</a>” I explored how reliability, observability and fault tolerance become foundational requirements when critical workloads stretch across hybrid and multi-cloud environments.</p>



<p class="wp-block-paragraph">CIOs already understand this because they have lived through enterprise resource planning programs, cloud migration, integration modernization, cybersecurity transformation and analytics initiatives. The lesson is familiar: technology cannot outrun data discipline forever.</p>



<h2 class="wp-block-heading">Security cannot be added later</h2>



<p class="wp-block-paragraph">As AI moves from answering questions to acting, security becomes much more important.</p>



<p class="wp-block-paragraph">An assistant that summarizes information carries one level of risk. An agent that can open a ticket, update a record, trigger a workflow, approve a request or contact a customer carries a very different one.</p>



<p class="wp-block-paragraph">The more AI can do, the more identity, authorization, least privilege, separation of duties and human approval matter.</p>



<p class="wp-block-paragraph">Enterprises should be careful not to grant AI broad access just to speed up a pilot. That may seem harmless in development, but it can become dangerous at scale.</p>



<p class="wp-block-paragraph">AI access should be treated like any other privileged enterprise capability: limited, logged, reviewed and easy to revoke.</p>



<p class="wp-block-paragraph">The <a href="https://www.nist.gov/itl/ai-risk-management-framework">NIST</a> AI Risk Management Framework is a useful reference point here because it frames AI risk as something organizations must govern, map, measure and manage continuously rather than something handled only at the end of deployment.</p>



<p class="wp-block-paragraph">Security teams should be involved early, not at the end. The goal is not to slow innovation. The goal is to build a platform where safe innovation becomes repeatable.</p>



<h2 class="wp-block-heading">The CIO has to define the operating model</h2>



<p class="wp-block-paragraph">AI is creating pressure from every direction. Boards want productivity. Business teams want automation. Employees want better tools. Vendors are pushing new features. Security teams are watching risk. Finance teams are watching cost. Customers expect faster, smarter experiences.</p>



<p class="wp-block-paragraph">The CIO sits in the middle of all of it.</p>



<p class="wp-block-paragraph">That is why the CIO’s role cannot stop at choosing tools or approving pilots. The CIO has to define how AI will actually operate across the enterprise.</p>



<p class="wp-block-paragraph">That means answering practical questions. Which architecture is approved? Which data sources can be trusted? How are AI workflows deployed, monitored, supported and governed? How are costs controlled? How do teams reuse common patterns instead of rebuilding the same foundation each time?</p>



<p class="wp-block-paragraph">This work may not be as exciting as a model demo, but it is what separates sustainable AI from short-term experimentation.</p>



<p class="wp-block-paragraph">The winning organizations will not be the ones with the most pilots. They will be the ones with the strongest AI operating layer.</p>



<p class="wp-block-paragraph">They will build reusable platform patterns, strengthen data governance, design access properly, monitor AI behavior end to end and measure success by business improvement, not only model performance.</p>



<p class="wp-block-paragraph">The model still matters. But the enterprise behind the model matters more.</p>



<p class="wp-block-paragraph">A powerful model on weak infrastructure will eventually disappoint the business. A capable model on strong infrastructure can deliver real value because it can be trusted, secured, scaled and improved.</p>



<p class="wp-block-paragraph">That is the shift CIOs need to lead.</p>



<p class="wp-block-paragraph">The next AI bottleneck is not the model. It is whether the enterprise behind the model is ready.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Fotos & Gemini Omni: Neue KI-Videobearbeitung wird jetzt ausgerollt – mit schnellen Korrekturen (Video)]]></title>
<description><![CDATA[Die Fotoplattform Google Fotos bietet schon seit Jahren starke Möglichkeiten zur Bildbearbeitung. Dank KI ist man zuletzt immer stärker in die Videobearbeitung vorgedrungen - jetzt geht man den nächsten Schritt. In diesen Tagen wird das neue Video Remix mit Gemini Omni ausgerollt, das umfangreich...]]></description>
<link>https://tsecurity.de/de/3682831/it-nachrichten/google-fotos-gemini-omni-neue-ki-videobearbeitung-wird-jetzt-ausgerollt-mit-schnellen-korrekturen-video/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682831/it-nachrichten/google-fotos-gemini-omni-neue-ki-videobearbeitung-wird-jetzt-ausgerollt-mit-schnellen-korrekturen-video/</guid>
<pubDate>Tue, 21 Jul 2026 08:33:00 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="640" height="360" src="https://www.googlewatchblog.de/wp-content/uploads/gemini-omni-logo-1024x576.jpg" class="attachment-large size-large wp-post-image" alt="gemini omni logo" decoding="async" fetchpriority="high" srcset="https://www.googlewatchblog.de/wp-content/uploads/gemini-omni-logo-1024x576.jpg 1024w, https://www.googlewatchblog.de/wp-content/uploads/gemini-omni-logo-300x169.jpg 300w, https://www.googlewatchblog.de/wp-content/uploads/gemini-omni-logo-768x432.jpg 768w, https://www.googlewatchblog.de/wp-content/uploads/gemini-omni-logo-640x360.jpg 640w, https://www.googlewatchblog.de/wp-content/uploads/gemini-omni-logo-800x450.jpg 800w, https://www.googlewatchblog.de/wp-content/uploads/gemini-omni-logo.jpg 1500w" sizes="(max-width: 640px) 100vw, 640px"><br>Die Fotoplattform <a href="https://www.googlewatchblog.de/2026/06/google-fotos-neue-ki-funktion-sortiert-eure-kleidung-laesst-euch-neue-outfits-kreieren-und-anprobieren-video/"><strong>Google Fotos</strong></a> bietet schon seit Jahren starke Möglichkeiten zur Bildbearbeitung. Dank KI ist man zuletzt immer stärker in die Videobearbeitung vorgedrungen - jetzt geht man den nächsten Schritt. In diesen Tagen wird das neue <strong>Video Remix mit Gemini Omni</strong> ausgerollt, das umfangreiche Videobearbeitungsmöglichkeiten direkt in die Android-App bringt.</p>
<p>Mehr lesen: <a href="https://www.googlewatchblog.de/2026/07/google-fotos-gemini-omni-neue-ki-videobearbeitung-wird-ausgerollt-bringt-schnelle-korrekturen-video-u/">Google Fotos &amp; Gemini Omni: Neue KI-Videobearbeitung wird jetzt ausgerollt – mit schnellen Korrekturen (Video)</a></p>
<hr>
<p></p><center><a href="https://www.google.com/preferences/source?q=googlewatchblog.de"><img src="https://www.googlewatchblog.de/wp-content/uploads/googlebevorzugt.webp" alt="GoogleWatchBlog als bevorzugte Quelle bei Google hinzufügen" width="284" height="90"></a></center><br><center><strong>Keine Google-News mehr verpassen:</strong> <a href="https://news.google.com/publications/CAAqLggKIihDQklTR0FnTWFoUUtFbWR2YjJkc1pYZGhkR05vWW14dlp5NWtaU2dBUAE?hl=de"><strong>GoogleWatchBlog bei Google News abonnieren</strong></a></center>
<hr>
<p></p><center><a href="https://ssl-vg03.met.vgwort.de/na/bc044b28895d46b6b00b93964f38bc84"><img alt="vgwort" src="https://ssl-vg03.met.vgwort.de/na/bc044b28895d46b6b00b93964f38bc84" width="16" height="16"></a></center>
<p>Der Beitrag <a href="https://www.googlewatchblog.de/2026/07/google-fotos-gemini-omni-neue-ki-videobearbeitung-wird-ausgerollt-bringt-schnelle-korrekturen-video-u/">Google Fotos &amp; Gemini Omni: Neue KI-Videobearbeitung wird jetzt ausgerollt – mit schnellen Korrekturen (Video)</a> erschien zuerst auf <a href="https://www.googlewatchblog.de/">GoogleWatchBlog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SpaceX in your index fund, explained]]></title>
<description><![CDATA[Index funds are touted as one of the safest ways to invest. Rather than picking and choosing individual stocks, index funds let you bet on the market as a whole. So what happens when a company like SpaceX - a giant gamble, and, in my opinion, terribly overpriced - is fast-tracked into the Nasdaq-...]]></description>
<link>https://tsecurity.de/de/3682184/it-nachrichten/spacex-in-your-index-fund-explained/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682184/it-nachrichten/spacex-in-your-index-fund-explained/</guid>
<pubDate>Mon, 20 Jul 2026 23:02:24 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Index funds are touted as one of the safest ways to invest. Rather than picking and choosing individual stocks, index funds let you bet on the market as a whole. So what happens when a company like SpaceX - a giant gamble, and, in my opinion, terribly overpriced - is fast-tracked into the Nasdaq-100? Does […]]]></content:encoded>
</item>
<item>
<title><![CDATA[An AI SOC Evaluation Guide for Security Leaders]]></title>
<description><![CDATA[Choosing an AI SOC platform requires understanding how it will perform in your own environment, not just during an evaluation. Prophet Security shares a practical framework for assessing AI SOC solutions, including how to validate accuracy, operating models, long-term reliability, and production ...]]></description>
<link>https://tsecurity.de/de/3681383/it-security-nachrichten/an-ai-soc-evaluation-guide-for-security-leaders/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681383/it-security-nachrichten/an-ai-soc-evaluation-guide-for-security-leaders/</guid>
<pubDate>Mon, 20 Jul 2026 16:24:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Choosing an AI SOC platform requires understanding how it will perform in your own environment, not just during an evaluation. Prophet Security shares a practical framework for assessing AI SOC solutions, including how to validate accuracy, operating models, long-term reliability, and production readiness. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Banning AI Won't Stop It]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 Highly regulated industries have often been slower to adopt AI because regulations and risk concerns create uncertainty. But organizations are increasingly realizing they can't delay forever.

Cybersecurity and risk teams are shif...]]></description>
<link>https://tsecurity.de/de/3681336/it-security-video/banning-ai-wont-stop-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681336/it-security-video/banning-ai-wont-stop-it/</guid>
<pubDate>Mon, 20 Jul 2026 16:02:43 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/vs876-CDAY0?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Highly regulated industries have often been slower to adopt AI because regulations and risk concerns create uncertainty. But organizations are increasingly realizing they can't delay forever.<br />
<br />
Cybersecurity and risk teams are shifting from acting solely as gatekeepers to becoming enablers. If they don't provide secure, approved paths for AI adoption, employees may turn to unauthorized tools instead, creating "shadow AI" that is harder to monitor and govern. The challenge is balancing innovation with responsible oversight rather than choosing one over the other.<br />
<br />
Would stricter AI restrictions improve security in your organization—or encourage more employees to find workarounds?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#AIGovernance #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The 6 kinds of AI agent architectures]]></title>
<description><![CDATA[Somewhere in the last eighteen months, “AI agent” stopped being a useful term. CIOs may even be afraid to ask what “agent” truly means, as it now seems to describe everything from a chatbot that answers HR questions to an autonomous research system that plans its own week of work. When a single p...]]></description>
<link>https://tsecurity.de/de/3680680/it-security-nachrichten/the-6-kinds-of-ai-agent-architectures/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680680/it-security-nachrichten/the-6-kinds-of-ai-agent-architectures/</guid>
<pubDate>Mon, 20 Jul 2026 11:09:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Somewhere in the last eighteen months, “AI agent” stopped being a useful term. CIOs may even be afraid to ask what “agent” truly means, as it now seems to describe everything from a chatbot that answers HR questions to an autonomous research system that plans its own week of work. When a single phrase carries that much weight, well, it stops carrying any.</p>



<p class="wp-block-paragraph">I’ve spent the last three years inside hundreds of enterprise AI deployments, and the factor that separates the programs scaling elegantly from the ones still shuffling is often the CIO’s architectural fluency: The ability to look at business problems across the organization and recognize, on sight, what kind of AI architecture is the right fit. In my experience there are six archetypes, each with their own nuances, that CIOs should internalize to make well-informed decisions going forward.</p>



<h2 class="wp-block-heading">1. The conversational assistant</h2>



<p class="wp-block-paragraph">The first, and the one most enterprises meet first, is the conversational assistant: The chat-based partner that an employee or customer opens when they want to think out loud. <a href="https://www.deloitte.com/us/en/what-we-do/capabilities/applied-artificial-intelligence/content/state-of-ai-in-the-enterprise.html?id=us:2ps:3gl:aisgm26:awa:CONS:em:K0218784:012626:kwd-430833501819:195648817121:794247818306::&amp;gclsrc=aw.ds&amp;gad_source=1&amp;gad_campaignid=23269751971&amp;gbraid=0AAAAADenGPCB8F-Mx6GhUt0V1PWpgLqtw&amp;gclid=Cj0KCQjwi8nRBhDhARIsAHZf_pYktgKgYgYBAR6AcMikwdYOF7q6S3WaLiLYg2hwhvdCjRiqajxnqtkaAsdYEALw_wcB">Deloitte found that 38%</a> of organizations report AI is already strengthening their client or customer relationships. This is the architecture people fall in love with: A well-designed assistant with constantly updated information, persistent user-level memory, tools that can act on behalf of users, and citations on every factual claim becomes a useful problem-solver that’s available at any hour of the day.</p>



<p class="wp-block-paragraph">A global law firm I work with deployed an internal assistant that gives every attorney instant access to the firm’s accumulated precedent, memos and prior matter work. Associates who used to spend the first hour of a research task hunting through document management systems now start with a grounded, citation-backed answer and refine from there. This helped the firm’s institutional knowledge, previously locked in the heads of senior partners, become queryable by anyone with a deadline at 11 p.m., or later.</p>



<p class="wp-block-paragraph">A second example: A mid-market wealth management firm built a client-facing assistant that handles portfolio questions, statement explanations and routine servicing requests. The assistant draws from each client’s actual holdings, recent activity and the firm’s published market commentary, with citations linking back to source documents. Advisors stopped being interrupted for the questions that didn’t require an advisor, and clients got answers on a Sunday.</p>



<h2 class="wp-block-heading">2. The triggered workflow</h2>



<p class="wp-block-paragraph">Another pattern producing the value across the enterprises I work with is something that runs silently: An email arrives, a ticket is created, a file lands in a folder and the agent executes a process utilizing both reasoning and determinism. These agents don’t even require user adoption, because they’re invisible to the end user. They produce measurable outcomes, but fit cleanly into the audit and change-control processes IT teams have run for decades.</p>



<p class="wp-block-paragraph">A commercial insurer I advise built a triggered workflow for inbound submissions. Every broker email that arrives at the underwriting inbox is classified by line of business, the attachments are parsed, key risk fields are extracted into the policy administration system, and a draft acknowledgment is queued for the underwriter’s review. Seemingly overnight, the inbox began arriving pre-sorted, and submission throughput rose meaningfully without any change to headcount.</p>



<p class="wp-block-paragraph">Another example, this time from a private equity firm: Every inbound confidential information memorandum (CIM) that hits the deal team’s shared inbox triggers a workflow that extracts the financial summary, screens it against the firm’s investment criteria, drafts a preliminary memo and posts the result into the deal-tracking system. Associates still make the call on what to pursue, but the first three hours of manual work on each opportunity now happen before anyone even opens the file.</p>



<h2 class="wp-block-heading">3. The autonomous agent — with sub-agents</h2>



<p class="wp-block-paragraph">Here we have the architecture that gets the most conference attention: The autonomous agent, given a task and left to plan its own steps by utilizing its own sub-agents. Autonomous agents are not one-size-fits-all, but they do meet a specific need: Multi-source research, complex cross-system lookups, deep-dive investigations. All of these are processes where the path isn’t usually specified in advance, but the tools are. With the right design discipline, an autonomous agent feels like having a self-sufficient teammate who can call in the right resources and specialists if needed.</p>



<p class="wp-block-paragraph">A global consulting firm I work with uses an autonomous research agent for early-stage engagement scoping. Given a target company and a strategic question, the agent decides for itself which sub-agents to consult (choosing from internal proprietary databases, prior engagement archives, licensed market data, public filings) and produces a structured briefing with its reasoning chain attached.</p>



<p class="wp-block-paragraph">Another large technology company I know of deployed an autonomous agent for cross-system incident investigation. When a production alert fires, the agent forms a hypothesis, queries the necessary sub-agents with relevant monitoring tools, log stores and deployment systems, and follows the trail until it reaches a defensible root-cause summary to surface to an engineer.</p>



<h2 class="wp-block-heading">4. The multi-agent team</h2>



<p class="wp-block-paragraph">The fourth pattern is where the next wave of enterprise quality gains is going to come from. <a href="https://www.databricks.com/resources/ebook/state-of-ai-agents">According to Databricks</a>, usage of multi-agent systems grew 327% in just four months as enterprises moved beyond single chatbots. Several specialized agents, each with its own role and toolset, coordinate through a shared protocol: A researcher and a writer, a planner and a set of executors, a proposer and a critic. The proposer-critic feedback loop is one of the smartest techniques in agent design today. One model produces an answer; a second, with a different prompt and often a different provider, evaluates it against explicit criteria. For compliance review, contract analysis, high-stakes classification and any output that will be audited, this second pass is extremely helpful and mirrors how human teams work.</p>



<p class="wp-block-paragraph">A global bank I work with uses a multi-agent system for marketing and communications review. One agent drafts client-facing copy, a second checks it against the firm’s regulatory and brand guidelines and a third checks it against jurisdiction-specific disclosure rules. Disagreements among the agents are surfaced to a human reviewer with the specific clauses flagged. The compliance team stopped being the bottleneck on every routine piece of copy and started focusing on the high-judgment cases instead.</p>



<p class="wp-block-paragraph">The next example: A pharmaceutical company built a multi-agent workflow for medical literature summarization. A retriever agent gathers candidate studies, a reader agent extracts study design and findings, a critic agent challenges the reader’s claims against the source text, and a synthesizer agent composes the final brief. The proposer-critic loop in the middle is the reason the medical affairs team trusts the output enough to act on it.</p>



<h2 class="wp-block-heading">5. The human-in-the-loop (HITL) agent</h2>



<p class="wp-block-paragraph">The fifth pattern is the one I think we’ll see increasingly more of in the future. While many see “full automation” as the goal, the right target is actually to let the agent handle the 80% of a task that is mechanical, while preserving human judgment at the most critical moments. This is achievable via human-in-the-loop (HITL) agents. <a href="https://www.moodys.com/web/en/us/insights/ai/human-in-the-loop-why-human-oversight-still-matters-in-ai-driven-risk-and-compliance.html">According to Moody’s, 42%</a> of compliance professionals believe that human oversight is mandatory, and I agree: AI should run <em>right</em>, by getting approval and review before any sensitive business action is taken. HITL is the architecture that can help turn a skeptical team into an enthusiastic one.</p>



<p class="wp-block-paragraph">A regional health system I worked with uses a HITL agent for prior-authorization letters. The agent assembles the clinical evidence, drafts the letter against the relevant payer’s criteria, and routes it to a nurse case manager for review inside the existing workflow tool. The nurse approves, edits or rejects in seconds rather than minutes, and every edit helps make the next draft better.</p>



<p class="wp-block-paragraph">A property management company uses a HITL agent to run its maintenance work orders. When a tenant emails about a problem (an HVAC unit that died overnight, say), the agent pulls the structured details (tenant, unit, issue type, urgency), matches the job to the right vendor from the directory, and drafts the work order. A team member approves it in Slack before anything goes out. From there the agent emails the vendor with the full order, confirms with the tenant that someone is on the way and updates Airtable, closing the loop completely.</p>



<h2 class="wp-block-heading">6. The scheduled agent</h2>



<p class="wp-block-paragraph">On a set schedule or against a batch of inputs, this agent runs the same defined task: Produce a report, refresh a dataset, monitor a set of sources or summarize a period of activity. Under this archetype, unsexy work gets done consistently, integrated into existing operational rhythms like the Monday morning meeting, the daily standup and the monthly board deck, without asking anyone to change their behavior. This is the architecture that shifts AI from feeling like even more work, to a seamless teammate that just works.</p>



<p class="wp-block-paragraph">A private equity firm I work with runs a scheduled agent every Monday at 6 a.m. that monitors news, filings and earnings activity across every portfolio company and produces a single PDF that lands in the deal partners’ inboxes before the weekly investment meeting. No one logs into a dashboard. The agent shows up, on time, with the same format every week, and the meeting now starts from a shared baseline rather than from whatever each partner happened to read over the weekend.</p>



<p class="wp-block-paragraph">A second example: A global manufacturer runs a nightly batch agent that ingests the day’s quality-control reports across plants, summarizes anomalies against a rolling baseline, and produces an end-of-shift handoff document for each site lead’s morning. The agent doesn’t flag emergencies, but it ensures that the slow-moving patterns no human would catch reading one shift’s data in isolation get surfaced.</p>



<h2 class="wp-block-heading">Bringing it together</h2>



<p class="wp-block-paragraph">None of these six archetypes is more advanced than the others or inherently better. But CIOs can have an edge by choosing the one that the operational problem actually calls for.</p>



<p class="wp-block-paragraph">Before you scope a single deployment, you should be able to look at a business problem and name its shape: Is this a question someone needs answered in the moment, or a process that should run the instant a trigger fires? Does the path need to be discovered, or is it known in advance and just waiting to be executed? Where, exactly, does human judgment have to stay in the loop, and where is it just friction?</p>



<p class="wp-block-paragraph">Going forward, CIOs should start treating the architecture decision as the first design choice. Everything downstream — adoption, governance, trust — only gets easier if the architecture is the right fit.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA['People are choosing to be a walking Flock camera': the smart glasses backlash hits new heights as celebrities blast 'creep goggles' — and activists install fake Meta Glasses ads at London bus stops]]></title>
<description><![CDATA[It's been a week of strong reaction against cameras in smart glasses, and tech companies are facing a lot of negativity.]]></description>
<link>https://tsecurity.de/de/3679357/it-nachrichten/people-are-choosing-to-be-a-walking-flock-camera-the-smart-glasses-backlash-hits-new-heights-as-celebrities-blast-creep-goggles-and-activists-install-fake-meta-glasses-ads-at-london-bus-stops/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679357/it-nachrichten/people-are-choosing-to-be-a-walking-flock-camera-the-smart-glasses-backlash-hits-new-heights-as-celebrities-blast-creep-goggles-and-activists-install-fake-meta-glasses-ads-at-london-bus-stops/</guid>
<pubDate>Sun, 19 Jul 2026 13:02:58 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It's been a week of strong reaction against cameras in smart glasses, and tech companies are facing a lot of negativity.]]></content:encoded>
</item>
<item>
<title><![CDATA[Why More Businesses Are Choosing Cheaper Chinese AI Models]]></title>
<description><![CDATA[Chinese AI models are gaining business interest as companies weigh lower costs, open-weight flexibility, performance trade-offs, and enterprise risks.]]></description>
<link>https://tsecurity.de/de/3677165/it-nachrichten/why-more-businesses-are-choosing-cheaper-chinese-ai-models/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677165/it-nachrichten/why-more-businesses-are-choosing-cheaper-chinese-ai-models/</guid>
<pubDate>Sat, 18 Jul 2026 00:32:22 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Chinese AI models are gaining business interest as companies weigh lower costs, open-weight flexibility, performance trade-offs, and enterprise risks.]]></content:encoded>
</item>
<item>
<title><![CDATA[Senior executives are killing your shadow AI strategy]]></title>
<description><![CDATA[Shadow IT has long been a major problem for CISOs, but the biggest problem may be coming from the executive suite’s hunger for unsanctioned AI.



Nearly two-thirds of senior decision-makers admit to using unapproved AI tools, compared to just 31% of lower-level employees, according to a survey b...]]></description>
<link>https://tsecurity.de/de/3675293/it-security-nachrichten/senior-executives-are-killing-your-shadow-ai-strategy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675293/it-security-nachrichten/senior-executives-are-killing-your-shadow-ai-strategy/</guid>
<pubDate>Fri, 17 Jul 2026 09:09:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Shadow IT has long been a major problem for CISOs, but the biggest problem may be coming from the executive suite’s hunger for unsanctioned AI.</p>



<p class="wp-block-paragraph">Nearly two-thirds of senior decision-makers admit to using <a href="https://www.cio.com/article/4178359/why-your-most-ai-savvy-employees-are-driving-shadow-ai.html">unapproved AI tools</a>, compared to just 31% of lower-level employees, according <a href="https://www.trustedtechteam.com/pages/shadow-ai-whitepaper-download">to a survey</a> by Microsoft solutions partner TrustedTech.</p>



<p class="wp-block-paragraph">The use of <a href="https://www.cio.com/article/647725/it-leaders-grapple-with-shadow-ai.html">shadow AI</a> is prevalent among senior executives even though three in four employees acknowledge security or data privacy risks related to the practice.</p>



<p class="wp-block-paragraph">“Most shadow AI users are not ignorant of the risk,” TrustedTech says in a white paper. “They are deliberately choosing to use these tools anyway. This is not a training issue. It is a culture, incentives, and alternatives issue.”</p>



<p class="wp-block-paragraph">In many cases, the problem is driven by a lack of approved tools, the report adds.</p>



<p class="wp-block-paragraph">“People use shadow AI because what their employer hands them is worse than mainstream AI tools, or because nothing has been approved in the first place,” the report says. “That doesn’t change until the sanctioned tools are genuinely worth using.”</p>



<h2 class="wp-block-heading">A question of authority</h2>



<p class="wp-block-paragraph">The use of shadow AI by CEOs and other C-suite executives can create major problems for CISOs, CIOs, and other IT executives because they may not have the authority to put the kibosh on it.</p>



<p class="wp-block-paragraph">It also presents a challenge for IT leaders to provide the AI tools that employees and executives want to use.</p>



<p class="wp-block-paragraph">When executives use shadow AI, CISOs are in a difficult position, because governance only works when it’s modeled from the top, says<a href="https://www.linkedin.com/in/annolan/"> Andy Nolan,</a> VP of technology at TrustedTech.</p>



<p class="wp-block-paragraph">“If senior leaders bypass approved AI tools or policies, it sends an implied message that speed matters more than security and compliance,” he adds. “Employees notice that behavior, and it becomes much harder to ask the rest of the organization to follow standards that leadership isn’t following themselves, first.”</p>



<p class="wp-block-paragraph">Another major problem is that executives often work with highly sensitive information, including financial data, strategic plans, intellectual property, and customer information, he notes.</p>



<p class="wp-block-paragraph">But CISOs and CIOs also can’t solve the problem by becoming the AI police in every situation, Nolan says, because their role is to help the business innovate safely.</p>



<p class="wp-block-paragraph">“That requires executive alignment, clear governance, and providing secure AI tools that people actually want to use,” he adds. “When leadership embraces those solutions, the rest of the organization is almost sure to follow.”</p>



<h2 class="wp-block-heading">All risk, no reward</h2>



<p class="wp-block-paragraph">The use of shadow AI by senior executives puts CISOs and CIOs in an impossible position, agrees <a href="https://www.linkedin.com/in/amit-maloo-b087291/">Amit Maloo</a>, CISO at AI procurement provider Ivalua. CISOs and CIOs are <a href="https://www.cio.com/article/4182288/cios-are-being-held-accountable-for-ai-they-dont-fully-control-ibm-study-finds.html?utm=hybrid_search">held accountable</a> for the risk exposure but have no visibility into the problem, he says.</p>



<p class="wp-block-paragraph">“When senior leaders use ungoverned AI tools for business decisions, those decisions still have consequences, such as financial commitments, contract reviews, and data sharing,” he adds. “But there is no audit trail, no permissions model, or no way to reconstruct what happened or why.”</p>



<p class="wp-block-paragraph">Part of the problem is that approved AI options often don’t meet the needs of users, Maloo says.</p>



<p class="wp-block-paragraph">“AI policies alone aren’t enough; organizations need to pair governance with usability,” he adds. “If approved AI tools don’t meet the pace of business, employees at every level, including leadership, will find their own solutions. Successful organizations will be those that make the secure path the easiest path.”</p>



<p class="wp-block-paragraph">IT leaders can’t solve the problem with more governance, he notes. “Policies and restrictions slow shadow AI down, but they don’t stop it, especially when the people using it are senior enough to absorb the disciplinary risk,” Maloo adds. “What CIOs can do is focus on providing tools that grant users full access to the necessary systems and data, eliminating the need to choose between a capable but ungoverned tool and a safe but limited one.”</p>



<h2 class="wp-block-heading">Speed over security</h2>



<p class="wp-block-paragraph">The TrustedTech data echoes a <a href="https://www.teramind.co/l/shadow-ai-report-2026/">June report</a> from employee monitoring software vendor Teramind, which found that more than two-thirds of C-level executives prioritize speed over security when using AI tools, notes <a href="https://www.linkedin.com/in/nikkale/">Nik Kale</a>, a principal engineer and product architect at Cisco, and member of the Coalition for Secure AI.</p>



<p class="wp-block-paragraph">In addition, the Teramind report found that two-thirds of enterprise AI activity runs through personal accounts on platforms for which the company already owns licenses, he notes.</p>



<p class="wp-block-paragraph">“People are paying for the governed version and using the ungoverned version of the same product, so the problem isn’t the tools,” he says. “The approved path is slower, buried in procurement, or disconnected from where the work actually happens, and speed wins every time under a deadline.”</p>



<p class="wp-block-paragraph">The problem then isn’t with the AI tools, but with the friction involved, he says. “People aren’t going around the front door because the room is locked,” Kale adds. “They’re going around it because the front door is slower.”</p>



<p class="wp-block-paragraph">In many cases, the use of shadow AI exposes a couple of shortcomings in enterprise processes, adds <a href="https://www.linkedin.com/in/matt-scavetta-018b10173/">Matthew Scavetta</a>, chief technology innovation officer at IT solutions provider Future Tech Enterprise.</p>



<p class="wp-block-paragraph">Many organizations don’t do a good job of making employees aware of the AI tools available to them, he says, and many organizations don’t offer training on the sanctioned applications, which drives users to pick products they are familiar with.</p>



<p class="wp-block-paragraph">“If you don’t solve problems for people quickly or make people aware of which tools they can use safely, they will find a workaround,” he adds. “AI tools are no different than anything else.”</p>



<p class="wp-block-paragraph">Shadow AI use by executives puts IT leaders in an incredibly difficult position, he says.</p>



<p class="wp-block-paragraph">“CIOs, in particular, are under more and more pressure each year to keep up with what’s possible as tech influencers keep preaching about the potential of these tools,” Scavetta says. “CEOs and board members are constantly getting swept up in the hype; meanwhile, there are more and more case studies coming out showing how little ROI some organizations have realized. It’s a never-ending game of balancing possible with practical.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The AI compute gap: Enterprises are buying infrastructure faster than they can measure what it costs]]></title>
<description><![CDATA[Across 107 enterprises, AI infrastructure spending is accelerating well ahead of the ability to see or steer its economics. Most organizations run their AI on a familiar base of hyperscalers and model-provider APIs, yet the next dollar is aimed at specialized compute almost none of them use today...]]></description>
<link>https://tsecurity.de/de/3674337/it-nachrichten/the-ai-compute-gap-enterprises-are-buying-infrastructure-faster-than-they-can-measure-what-it-costs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674337/it-nachrichten/the-ai-compute-gap-enterprises-are-buying-infrastructure-faster-than-they-can-measure-what-it-costs/</guid>
<pubDate>Thu, 16 Jul 2026 20:02:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Across 107 enterprises, AI infrastructure spending is accelerating well ahead of the ability to see or steer its economics. Most organizations run their AI on a familiar base of hyperscalers and model-provider APIs, yet the next dollar is aimed at specialized compute almost none of them use today; a majority intend to switch or add providers within the year, many within a quarter. Buying decisions turn on integration and total cost of ownership rather than headline token price — which is fortunate, because most enterprises cannot yet see their unit economics clearly: GPUs sit at half utilization or less, and fewer than half rigorously track what their compute actually costs. The result is a compute gap — heavy, fast-moving investment running ahead of the visibility needed to control it.</p><p>This wave of VentureBeat Pulse Research examines enterprise AI infrastructure and compute: where organizations are in their deployment journey, what they run AI on today, how satisfied they are, what would make them switch, where they plan to evaluate their investments, and — most revealingly — how well they can measure and control the economics of the compute underneath it all.</p><p>The central finding is a compute gap — the distance between how aggressively enterprises are investing in AI infrastructure and how little of its economics they can see. Only about one in five (21%) run AI in production at scale, yet spending intentions are outrunning that maturity: the single largest planned area enterprises plan to evaluate over the next year is AI-specialized clouds (45%), a layer almost none of these enterprises use today. Meanwhile the compute already in place runs cold — 83% report GPU utilization of 50% or less — and fewer than half (44%) can rigorously track what their AI compute costs. Enterprises are buying more infrastructure faster than they can account for what they already own.</p><p>Enterprises are not settled on their infrastructure vendors, either: A clear majority (64%) plan to switch or add an infrastructure provider within twelve months, and 38% within the next quarter — unusually high churn intent for a category this foundational. When they choose, they choose on integration with the existing stack (41%) and total cost of ownership (35%), not on headline price: cost per million tokens is the deciding factor for just 8%. And the frontier constraint that will shape the next round of decisions — the shift from GPU compute to memory bandwidth as inference scales — is barely on the radar, with roughly one in five enterprises either unaware of it or yet to address it.</p><h2>Methodology</h2><p>VentureBeat fielded this survey as part of its ongoing Pulse Research series, this survey focused on enterprise AI infrastructure, compute, and inference economics. Responses are filtered to organizations with more than 100 employees (n=107; the survey’s smallest size band, 1–100 employees, is excluded), drawn from a single Q2 2026 (June) wave. Because this is one wave rather than a pooled multi-month sample, the report reads cross-sectionally and does not infer month-over-month trends. Several questions were multiple-select, so those shares can sum to more than 100%.</p><p>By organization size the sample concentrates in the mid-market: 101–250 employees (36%) and 251–1,000 (27%) lead, with 1,001–5,000 (22%), 5,001–10,000 (8%), and 10,001+ (7%) above them. By role it spans managers (38%), individual contributors (28%), VPs and directors (19%), and the C-suite (13%); on purchasing authority it is buyer-credible, with 45% final decision-makers and another 30% recommenders or influencers for AI solutions. Technology/Software is the largest industry at 26%, followed by Healthcare/Life Sciences (15%), Financial Services (13%), and Retail/E-commerce (12%).</p><p>At 107 respondents the sample is large enough to read directionally but should be treated as a directional signal rather than a precise measurement; it is self-selected and is not a probability sample. It also skews toward the mid-market and toward earlier-stage adopters, so it is best read as the view from organizations actively building out AI infrastructure rather than from the largest hyperscale operators.</p><h2>Finding 1: Ambition outpaces production</h2><p><b>Only one in five run AI in production at scale</b></p><p>We asked where organizations sit in their AI deployment journey. Most are still building toward production rather than operating at scale.</p><div></div><table><tbody><tr><td><p><b>38%</b></p></td><td><p><b>are experimenting — running proofs of concept, not yet in production</b></p></td></tr><tr><td><p><b>37%</b></p></td><td><p><b>have some workloads in production, but not across the organization</b></p></td></tr><tr><td><p><b>21%</b></p></td><td><p><b>run AI in production at scale — the mature minority</b></p></td></tr><tr><td><p><b>4%</b></p></td><td><p><b>are not yet running AI workloads at all</b></p></td></tr></tbody></table><p>The maturity curve is front-loaded. Three-quarters of enterprises (76%) are either experimenting or running only some workloads in production, and just 21% describe AI in production at scale. This matters for everything that follows: the infrastructure decisions in this report are being made largely by organizations still early in deployment, whose compute footprint — and whose costs — are about to grow. The evaluation and switching intentions in Findings 3 and 4 are the leading edge of that build-out, not the settled preferences of operators who have already found what works.</p><h2>Finding 2: Enterprises run on hyperscalers and model APIs</h2><p><b>The specialized GPU clouds barely register — today</b></p><p>We asked which providers and platforms enterprises currently use to run their AI. The answer is a familiar one: the incumbents.</p><div></div><table><tbody><tr><td><p><b>48%</b></p></td><td><p><b>use Google Cloud — the most-used platform overall (Microsoft Azure 29%, AWS 22%, Oracle Cloud 22%)</b></p></td></tr><tr><td><p><b>41%</b></p></td><td><p><b>use Google’s Gemini models, with OpenAI close behind at 40% and Anthropic at 12%</b></p></td></tr><tr><td><p><b>6%</b></p></td><td><p><b>run their own on-prem or co-located GPU clusters; 4% a custom open-source self-managed stack</b></p></td></tr><tr><td><p><b>&lt;2%</b></p></td><td><p><b>each use the specialized AI clouds — CoreWeave, Lambda, Crusoe, Nebius, Together, Fireworks and peers</b></p></td></tr></tbody></table><p>The current stack is hyperscaler-and-API. Google Cloud leads at 48%, and the general-purpose clouds (Google, Microsoft, AWS, Oracle) together with the major model APIs (Gemini, OpenAI, Anthropic) account for essentially all current deployment. The specialized “neocloud” GPU providers that dominate AI-infrastructure headlines — CoreWeave, Lambda, Crusoe, Nebius and peers — register at or near zero among these enterprises today. Only 6% run their own on-prem GPU clusters and 4% a custom open-source stack. Enterprises are, for now, running AI on the providers they already buy from — which makes the evaluation intentions in Finding 3 all the more striking.</p><p><i>(A note on reading these shares. As described in the methodology section, this sample is self-selected and skews mid-market, and this question counted every provider a respondent uses — an average of 2.1 selections each — so the figures measure presence in the stack rather than spending or primary status. A sample built this way will show a different provider mix than a spend-weighted census of the broader market; Google's strength here, for example, is consistent with its long-standing position among smaller enterprises building on AI. Read these shares as a portrait of what this AI-active cohort runs today, and treat gaps between these figures and industry-wide market share estimates as a property of the sample rather than a contradiction of either.)</i></p><h2>Finding 3: The next dollar goes to infrastructure they don’t yet run</h2><p><b>AI-specialized clouds top the evaluations list</b></p><p>We asked where enterprises planned to evaluate AI infrastructure over the next 12 months. Their answers point away from the stack they run today.</p><div></div><table><tbody><tr><td><p><b>45%</b></p></td><td><p><b>AI-specialized clouds (CoreWeave, Lambda, Crusoe, Nebius) — the top planned evaluation area</b></p></td></tr><tr><td><p><b>32%</b></p></td><td><p><b>non-NVIDIA accelerators (AWS Trainium, Google TPU, AMD Instinct, Intel Gaudi, in-house ASICs)</b></p></td></tr><tr><td><p><b>28%</b></p></td><td><p><b>Nvidia Blackwell (GB300) / next-generation GPUs</b></p></td></tr><tr><td><p><b>16%</b></p></td><td><p><b>decentralized or distributed compute networks</b></p></td></tr><tr><td><p><b>11%</b></p></td><td><p><b>sovereign or region-specific compute; 9% say none of the above</b></p></td></tr></tbody></table><p>Here is the report’s sharpest tension. The single most-cited planned evaluation area — AI-specialized clouds, at 45% — is the very category almost none of these enterprises use today (Finding 2). Nearly a third (32%) intend to evaluate non-Nvidia accelerators, and 28% in next-generation Nvidia silicon; even decentralized compute networks (16%) and sovereign compute (11%) draw meaningful interest. Read against current usage, this is not incremental — it is the leading edge of a re-platforming. The direction-of-travel question tells the same story: every infrastructure approach is net-expanding, but specialized AI clouds carry the highest net momentum (+24), edging out even the hyperscalers (+22). Enterprises are preparing to move a meaningful share of AI compute off the general-purpose cloud.</p><p>This continues a trend we saw in our April-May survey wave. Back then, usage of the AI-specialized clouds was equally marginal — CoreWeave at 3%, Lambda at 4%, Crusoe at 2% of enterprises. When we asked enterprises what change they planned in their AI infrastructure strategy over the next twelve months, the most-cited answer was moving workloads to specialized AI clouds, at 33%. Asked in April-May which emerging compute option they were most likely to evaluate AI-specialized clouds again drew the most responses. Two waves, two differently worded questions, one consistent picture: the type of cloud enterprises are most eager to assess is the type they have barely begun to use.</p><h2>Finding 4: A switching wave is building</h2><p><b>Six in 10 plan to change providers within a year — many within a quarter</b></p><p>We asked whether and when enterprises plan to switch or add an infrastructure provider. Very few intend to stand still.</p><div></div><table><tbody><tr><td><p><b>38%</b></p></td><td><p><b>plan to change within the next 0–3 months — tied for the most common answer</b></p></td></tr><tr><td><p><b>36%</b></p></td><td><p><b>have no plans to change</b></p></td></tr><tr><td><p><b>22%</b></p></td><td><p><b>plan to change within 3–6 months</b></p></td></tr><tr><td><p><b>7%</b></p></td><td><p><b>plan to change within 6–12 months</b></p></td></tr></tbody></table><p>For a category as foundational as compute, this is a remarkable amount of intended movement. Only 36% have no plans to change, meaning a clear majority (64%) intend to switch or add a provider within twelve months — and 38% within the next quarter alone. Where that interest points is telling: the providers drawing the most switching consideration are again the incumbents — Microsoft Azure and Google Cloud (33% each), OpenAI (30%), and Gemini (22%) — which suggests much of the near-term movement is reshuffling among the majors and consolidating spend rather than defecting to new entrants. The neocloud interest in Finding 3 is a 12-month evaluation thesis; the switching in the next quarter is mostly incumbents trading share.</p><p>(<i>Method note: Respondents who selected both "no plans to change" and a specific switching window are counted as switchers, on the logic that naming a timeframe is the more specific answer; three respondents were reclassified under this rule.</i>)</p><h2>Finding 5: Nobody buys on token price</h2><p><b>Integration and total cost of ownership decide — not sticker price</b></p><p>We asked what matters most when enterprises select an AI infrastructure provider. Headline price finished last.</p><div></div><table><tbody><tr><td><p><b>41%</b></p></td><td><p><b>integration with the existing cloud and data stack — the top factor</b></p></td></tr><tr><td><p><b>35%</b></p></td><td><p><b>total cost of ownership (TCO)</b></p></td></tr><tr><td><p><b>24%</b></p></td><td><p><b>performance — latency and throughput</b></p></td></tr><tr><td><p><b>19%</b></p></td><td><p><b>each cite security/compliance, autoscaling for spiky workloads, and GPU access/availability</b></p></td></tr><tr><td><p><b>8%</b></p></td><td><p><b>cost per 1M tokens — the least-cited factor</b></p></td></tr></tbody></table><p>Enterprises do not buy AI infrastructure on pricing, which is the place vendors compete on hardest. Integration with the existing stack (41%) and total cost of ownership (35%) dominate, while the headline metric — cost per million tokens — is the deciding factor for just 8%, dead last. The pattern is coherent: buyers are optimizing for how a provider fits and what it truly costs to operate, not for the advertised unit rate. It also foreshadows Finding 7 — enterprises say TCO matters most, yet most cannot yet measure it rigorously. The stated priority and the measured capability are out of step.</p><h2>Finding 6: Expensive GPUs, idle most of the time</h2><p><b>83% report GPU utilization of 50% or less</b></p><p>We asked what share of their GPU capacity enterprises actually utilize. The answer is a well-known but rarely quantified inefficiency.</p><div></div><table><tbody><tr><td><p><b>37%</b></p></td><td><p><b>run at 26–50% utilization</b></p></td></tr><tr><td><p><b>34%</b></p></td><td><p><b>run at 10–25% utilization</b></p></td></tr><tr><td><p><b>15%</b></p></td><td><p><b>run under 10% utilization</b></p></td></tr><tr><td><p><b>12%</b></p></td><td><p><b>run over 50% — the efficient minority</b></p></td></tr><tr><td><p><b>8%</b></p></td><td><p><b>don’t measure utilization at all; a further 7% consume via API and run no GPUs of their own</b></p></td></tr></tbody></table><p><i>Disclosure: Band percentages count every selection against all 107 qualified respondents; 14 respondents selected more than one band, so bands overlap. At the respondent level, 83 of the 100 GPU-operating enterprises reported utilization at or below 50%</i></p><p>The compute already in place runs cold. Adding the bands at or below half capacity, 83% of enterprises that operate GPUs report utilization of 50% or less, and nearly half (49%) run at 25% or below. Only 12% clear the 50% mark, and a further 8% do not measure utilization at all. Idle accelerators are expensive accelerators, and this is the clearest single measure of the compute gap: enterprises are planning to buy more GPUs and specialized compute (Finding 3) while the capacity they already own sits substantially unused. The efficiency headroom in the current fleet is large — and largely unmeasured.</p><h2>Finding 7: Spending fast, measuring slowly</h2><p><b>Fewer than half rigorously track what their compute costs</b></p><p>We asked whether enterprises can quantify the cost and return of their AI infrastructure spend, and how satisfied they are with what they run. Confidence in the ledger lags the spending.</p><div></div><table><tbody><tr><td><p><b>44%</b></p></td><td><p><b>track compute cost and ROI rigorously</b></p></td></tr><tr><td><p><b>39%</b></p></td><td><p><b>track it only partially</b></p></td></tr><tr><td><p><b>20%</b></p></td><td><p><b>can’t quantify it yet</b></p></td></tr><tr><td><p><b>6%</b></p></td><td><p><b>say it isn’t a priority</b></p></td></tr></tbody></table><p>Measurement trails money. Fewer than half of enterprises (44%) rigorously track the cost and return of their AI compute; the majority track only partially (39%), cannot quantify it yet (20%), or have not prioritized it (6%). That gap is consequential given Finding 5, where total cost of ownership was the second-ranked buying criterion — enterprises are choosing providers on an economic basis they mostly cannot yet measure. Satisfaction with current infrastructure is moderately positive but not enthusiastic: on a five-point scale, overall satisfaction averages 4.0, with ease of implementation (3.8) and value for money (3.9) trailing slightly — the softness landing, tellingly, on cost. Enterprises are spending quickly and accounting slowly.</p><h2><b>Finding 8: The next bottleneck few are watching</b></h2><p><b>As inference shifts from compute to memory, the field scatters</b></p><p>Finally, we asked how enterprises would address the emerging constraint in large-scale inference — the shift from GPU compute to memory, specifically KV-cache capacity. The responses reveal a frontier that is not yet a priority.</p><div></div><table><tbody><tr><td><p><b>31%</b></p></td><td><p><b>would rely on Dell (PowerScale / Project Lightning) — the leading single answer</b></p></td></tr><tr><td><p><b>16%</b></p></td><td><p><b>would rely on Nvidia (Dynamo / ICMSP)</b></p></td></tr><tr><td><p><b>18%</b></p></td><td><p><b>are not aware of this as a constraint (9%) or haven’t addressed inference-memory limits yet (8%)</b></p></td></tr><tr><td><p><b>10%</b></p></td><td><p><b>Hammerspace (Tier Zero); 9% DDN (Infinia); the rest split across open-source KV-cache tooling, model-level efficiency, VAST Data, and WEKA</b></p></td></tr></tbody></table><p>The memory frontier is real but barely governed. Asked which approach they would rely on as the binding constraint in inference shifts from compute to memory bandwidth, enterprises scatter: Dell leads at 31%, Nvidia follows at 16%, and the rest fragments across storage vendors, open-source tooling, and model-level efficiency techniques. Most telling is that roughly one in five (18%) either do not recognize the constraint or have not begun to address it. For a shift that will reshape inference cost and architecture, this is an early and unsettled market — and, consistent with the measurement gap in Finding 7, one where many enterprises simply do not yet have a view. It is the next chapter of the compute gap, arriving before most have closed the current one.</p><h1><b>The bottom line: A compute gap that faster spending will widen, not close</b></h1><p>Organizations with more than 100 employees are investing in AI infrastructure faster than they can measure it. Most are still early in deployment, yet their spending intentions point past their current stack — toward specialized clouds and alternative accelerators almost none of them run today — and a clear majority intend to change providers within the year. They buy on integration and total cost of ownership rather than headline price, which is rational; the difficulty is that most cannot yet see those economics clearly.</p><p>The visibility gap is concrete. The GPUs enterprises already own run at half utilization or less for the overwhelming majority, and fewer than half can rigorously track what their compute costs or returns. Satisfaction is decent but unenthusiastic, softest on value for money — the dimension hardest to judge without measurement. And the next constraint, the shift from compute to memory in large-scale inference, is arriving while most enterprises are still unaware of it. At 107 respondents in a single Q2 wave this is a directional read, skewed toward the mid-market and earlier-stage adopters — but the direction is consistent: the appetite to spend is running well ahead of the instrumentation to spend well. The compute gap is not a capacity problem that more hardware will solve on its own; it is, first, a problem of seeing what the hardware already costs. The open question for later waves is whether enterprises build that visibility before the re-platforming arrives — or buy the next layer of infrastructure as blind to its economics as the last.</p><hr><p><i>Based on survey responses from 107 qualified enterprise respondents (100+ employees), drawn from a single Q2 2026 (June) wave. Because this is one wave rather than a pooled multi-month sample, the results read cross-sectionally rather than as a month-over-month trend, and at 107 respondents this is a directional signal rather than a precise measurement — the sample is self-selected, skews mid-market, and leans toward earlier-stage adopters rather than the largest hyperscale operators. Respondents include managers, individual contributors, VPs/directors, and the C-suite, with buyer-credible purchasing authority, across Technology/Software, Healthcare/Life Sciences, Financial Services, Retail/E-commerce, and other industries.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Now Carrier-Locks Financed T-Mobile and Verizon iPhones]]></title>
<description><![CDATA[Apple recently changed how it handles device financing, closing a popular loophole for buyers. If you buy a new Apple device directly from the company store and finance it through T-Mobile or Verizon, it will now be locked to that specific carrier. In the past, shoppers could use this method to g...]]></description>
<link>https://tsecurity.de/de/3673738/ios-mac-os/apple-now-carrier-locks-financed-t-mobile-and-verizon-iphones/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673738/ios-mac-os/apple-now-carrier-locks-financed-t-mobile-and-verizon-iphones/</guid>
<pubDate>Thu, 16 Jul 2026 16:10:12 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple recently changed how it handles device financing, closing a popular loophole for buyers. If you buy a new Apple device directly from the company store and finance it through T-Mobile or Verizon, it will now be locked to that specific carrier. In the past, shoppers could use this method to get a fully unlocked smartphone while still taking advantage of a carrier payment plan and promotional discounts. That era is now officially over.



Financed phones stay locked until you pay the full balance



This policy update brings T-Mobile and Verizon in line with AT&amp;T. AT&amp;T already required its financed phones to remain locked. Apple updated its website FAQ to clarify this change. The text now clearly states that choosing the T-Mobile Equipment Installment Plan or the Verizon Device Payment Program means your new iPhone is tied to that specific network. You cannot use it with another carrier until you pay off the entire balance.



This change impacts people who like to travel internationally. A locked phone blocks you from adding a second eSIM for a local network overseas. It also stops anyone from buying a phone with a carrier deal and immediately taking it to a cheaper service provider.



There is still a way to get an unlocked device right out of the box. You can buy the phone outright by paying the full retail price upfront. You can also use the Apple Card to set up monthly installments. Because that financing comes through the credit card and not the phone carrier, the device remains completely unlocked from day one.



If you upgrade your device every year using carrier deals, this new rule simply means you are tied down until the contract ends. You will need to weigh the upfront savings against the freedom of having an unlocked phone. The days of double-dipping on carrier promotions and unlocked flexibility are officially behind us.]]></content:encoded>
</item>
<item>
<title><![CDATA[Node.js security starts before CI]]></title>
<description><![CDATA[In many teams, dependency security still happens after the most important trust decision has already been made. A package is added, the lockfile changes, the feature moves forward, and only later does the pipeline ask whether the application should have trusted that code in the first place.



Th...]]></description>
<link>https://tsecurity.de/de/3672876/ai-nachrichten/nodejs-security-starts-before-ci/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672876/ai-nachrichten/nodejs-security-starts-before-ci/</guid>
<pubDate>Thu, 16 Jul 2026 11:04:19 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">In many teams, dependency security still happens after the most important trust decision has already been made. A package is added, the lockfile changes, the feature moves forward, and only later does the pipeline ask whether the application should have trusted that code in the first place.</p>



<p class="wp-block-paragraph">That workflow made sense when dependency security was mostly viewed as a compliance check. Run a scanner. Produce a report. Fail the build if the risk crosses a threshold. Let someone decide what to do next.</p>



<p class="wp-block-paragraph">But the modern Node.js ecosystem has changed. The risk no longer begins in CI. It begins earlier, at the moment a developer decides to trust a package.</p>



<p class="wp-block-paragraph">That is why the next phase of <a href="https://www.infoworld.com/article/4158762/is-your-node-js-project-really-secure.html" data-type="link" data-id="https://www.infoworld.com/article/4158762/is-your-node-js-project-really-secure.html">Node.js security</a> cannot be limited to better pipeline enforcement. It has to move closer to the developer workflow, before dependencies become part of the application, before a pull request becomes someone else’s problem, and before a build log becomes the first moment anyone realizes that something important has changed.</p>



<h2 class="wp-block-heading"><a></a>Every install is a trust decision</h2>



<p class="wp-block-paragraph">The npm ecosystem is built on trust at an enormous scale. Every install is a trust decision. Every transitive dependency extends that decision to maintainers, packages, scripts, release pipelines, and infrastructure the application team may never inspect directly. This model gave JavaScript its incredible velocity. It also created one of its deepest security weaknesses.</p>



<p class="wp-block-paragraph">Recent npm supply chain incidents show why this matters. In March 2026, <a href="https://www.csoonline.com/article/4152696/attackers-trojanize-axios-http-library-in-highest-impact-npm-supply-chain-attack.html" data-type="link" data-id="https://www.csoonline.com/article/4152696/attackers-trojanize-axios-http-library-in-highest-impact-npm-supply-chain-attack.html">malicious Axios versions were published to npm</a> through a compromised maintainer account. Microsoft later described how those packages attempted to retrieve a second-stage payload during installation. In May 2026, <a href="https://tanstack.com/blog/npm-supply-chain-compromise-postmortem" data-type="link" data-id="https://tanstack.com/blog/npm-supply-chain-compromise-postmortem">TanStack published a postmortem</a> explaining that 84 malicious versions across 42 npm packages were published through a legitimate release pipeline after an attacker abused GitHub Actions behavior and runner trust boundaries. Security researchers also <a href="https://www.csoonline.com/article/4179866/infected-red-hat-npm-packages-expose-developer-credentials.html" data-type="link" data-id="https://www.csoonline.com/article/4179866/infected-red-hat-npm-packages-expose-developer-credentials.html">reported broader Mini Shai-Hulud activity</a> across the npm ecosystem in May, including hundreds of malicious package versions published in a short period.</p>



<p class="wp-block-paragraph">Not every one of these incidents is a traditional CVE. Some are malicious package compromises. Some involve CI/CD credential theft. Some involve maintainer or pipeline compromise. But they all point to the same larger issue: dependency risk is now part of everyday software engineering, not something that can be pushed entirely to a downstream security process.</p>



<h2 class="wp-block-heading"><a></a>The problem is not the scanner. It is the handoff.</h2>



<p class="wp-block-paragraph">Ubiquitous dependency risk changes what developers need from security tooling.</p>



<p class="wp-block-paragraph">The problem is not that teams lack scanners. Many organizations already run security checks in CI. The problem is that the output of those checks often arrives too late and speaks the wrong language for the person expected to act on it.</p>



<p class="wp-block-paragraph">A pull request fails. A long vulnerability report appears. The report may be technically accurate. It may contain the right advisory IDs, affected versions, dependency paths, severity labels, and references. But the developer still has to comb through the output and reconstruct the actual engineering decision from the evidence provided.</p>



<p class="wp-block-paragraph">That reconstruction is rarely simple. The developer has to understand which package introduced the issue, whether the vulnerable dependency is direct or transitive, whether the fix is actually within the application team’s control, and whether the recommended version is safe to adopt. They also have to determine whether the dependency is used in production or only during development, whether the update might break the application, and whether the fix belongs in the current pull request or requires separate engineering work.</p>



<p class="wp-block-paragraph">That uncertainty is where security work often slows. The scanner has detected risk, but the developer has not been given a clear path from detection to decision.</p>



<h2 class="wp-block-heading"><a></a>Security needs to move closer to engineering judgment</h2>



<p class="wp-block-paragraph">This is not a criticism of scanning. Scanning is necessary. CI enforcement is necessary. Centralized security platforms are necessary. But they are not sufficient, because they often operate after the trust decision has already been made.</p>



<p class="wp-block-paragraph">The real architectural question is this: where should dependency security live in the software development life cycle?</p>



<p class="wp-block-paragraph">If it lives only in CI, it becomes an interruption. If it lives only in dashboards, it becomes someone else’s queue. If it lives only in periodic audits, it becomes a backlog. But if it lives at the moment a dependency is introduced, upgraded, or reviewed, it becomes part of engineering judgment.</p>



<p class="wp-block-paragraph">That shift matters because modern JavaScript development is becoming faster than human review can comfortably handle. Developers no longer add dependencies only by reading documentation and choosing libraries manually. AI coding assistants can suggest packages, generate install commands, modify package files, and rewrite code around third-party APIs. Agentic development workflows can make dependency changes as part of broader automated refactors.</p>



<h2 class="wp-block-heading"><a></a>AI makes the trust boundary harder to see</h2>



<p class="wp-block-paragraph">That acceleration is useful. It also changes the risk model.</p>



<p class="wp-block-paragraph">When a human developer adds one package, the team can review the decision. When a coding agent modifies several dependencies as part of a larger task, the trust boundary becomes harder to see. The package file changes, the lockfile changes, the application still runs, and the pull request may look like a normal feature update. But the real security question may be hidden inside the dependency graph.</p>



<p class="wp-block-paragraph">This is where Node.js teams need a different mental model.</p>



<p class="wp-block-paragraph">Dependency adoption should not be treated as a small implementation detail. It should be treated as an architectural decision with security consequences. A new package is not just code reuse. It is a new trust relationship.</p>



<p class="wp-block-paragraph">That does not mean developers should stop using packages. The npm ecosystem exists because reuse works. Most teams cannot and should not build everything themselves. But convenience should not erase visibility. If a dependency becomes part of the application, the team should understand what was added, what changed in the lockfile, what risk comes with it, and what action is available if something is wrong.</p>



<h2 class="wp-block-heading"><a></a>Developers need confidence, not just reports</h2>



<p class="wp-block-paragraph">The same applies to remediation. Developers do not want a wall of vulnerability text. They want confidence. They want to know what action reduces risk, what version should be targeted, whether the change is safe, and whether the fix is actually under their control. A vulnerability report that leaves the developer uncertain may satisfy a process requirement, but it does not necessarily improve the speed or quality of remediation.</p>



<p class="wp-block-paragraph">That is the gap many teams feel today. Security tools are often very good at saying, “There is a problem.” They are less consistent at helping the developer answer, “What should I do next?”</p>



<p class="wp-block-paragraph">This is the broader problem I have been exploring through <a href="https://github.com/OWASP/cve-lite-cli">CVE Lite CLI</a>, now an OWASP project. The point is not that one command-line tool solves Node.js security. It does not. The larger idea is that dependency security has to move closer to the developer’s moment of decision. A useful developer-side security workflow should not merely report that risk exists. It should help the engineer understand whether the issue is in their control, what change is available, and whether the fix actually reduces risk.</p>



<h2 class="wp-block-heading"><a></a>The future is decision support, not just detection</h2>



<p class="wp-block-paragraph">That distinction is important. The future of Node.js security is not just more detection. It is better decision support.</p>



<p class="wp-block-paragraph">Security teams still need policy. Enterprises still need dashboards. CI still needs gates. But developers need something more immediate: a way to reason about dependency risk while the code is still fresh in their mind. That is where the ecosystem has to evolve.</p>



<p class="wp-block-paragraph">We already accept that testing belongs close to development. We accept that linting belongs close to development. We accept that formatting, type checking, and build validation belong close to development. Dependency security should follow the same path. It should not be treated as a mysterious report that appears at the end of the process. It should become part of the normal rhythm of engineering work.</p>



<p class="wp-block-paragraph">Before adding a package, developers should understand what trust relationship is being introduced. Before accepting an AI-generated dependency change, they should inspect what entered the graph. Before merging a pull request, teams should understand whether a vulnerability is direct, transitive, fixable, or blocked by another package. And before treating a CI failure as noise, organizations should ask whether the workflow is giving developers enough information to act confidently.</p>



<h2 class="wp-block-heading">Node.js security will be won, or lost, before CI runs</h2>



<p class="wp-block-paragraph">The Node.js ecosystem will not become safer by slowing down all development. That is unrealistic. It will become safer when security work is placed where developers can actually use it.</p>



<p class="wp-block-paragraph">The next generation of Node.js security will be won or lost before CI runs.</p>



<p class="wp-block-paragraph">It will be won when dependency decisions are still small enough to understand, fresh enough to review, and close enough to the developer for action to feel natural.</p>



<p class="wp-block-paragraph">That is the shift teams need to make now. Not from insecure to secure in one step, but from late detection to earlier judgment. From vulnerability reports to engineering decisions. From trusting packages by habit to understanding trust as part of software design.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic orchestration: Enterprise AI organizations have a deployment problem, not a platform problem — and most are calling chatbots agents]]></title>
<description><![CDATA[Across 101 enterprises, agent orchestration is consolidating onto model-provider platforms — Anthropic’s Claude leads by a wide margin — chosen for the gravity of the underlying model and judged on reliable multi-step execution. But the ambition runs well ahead of the reality: most deployed “agen...]]></description>
<link>https://tsecurity.de/de/3672033/it-nachrichten/agentic-orchestration-enterprise-ai-organizations-have-a-deployment-problem-not-a-platform-problem-and-most-are-calling-chatbots-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672033/it-nachrichten/agentic-orchestration-enterprise-ai-organizations-have-a-deployment-problem-not-a-platform-problem-and-most-are-calling-chatbots-agents/</guid>
<pubDate>Thu, 16 Jul 2026 00:46:36 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Across 101 enterprises, agent orchestration is consolidating onto model-provider platforms — Anthropic’s Claude leads by a wide margin — chosen for the gravity of the underlying model and judged on reliable multi-step execution. But the ambition runs well ahead of the reality: most deployed “agents” are still chatbot wrappers, the control plane enterprises expect is deliberately hybrid to avoid lock-in, and real-time fiscal control over token burn remains the exception.</p><p>This wave of VentureBeat Pulse Research examines enterprise agent orchestration: which platforms enterprises run on, what drives the choice, what they optimize for, how they expect agent control to be structured, and — most revealingly — how orchestrated their deployed “agents” actually are and how tightly they control the cost of running them.</p><p>The central finding is a gap between orchestration ambition and orchestration reality. Enterprises are consolidating fast onto the major model platforms: Anthropic’s Claude is the primary platform for 40%, more than double any rival, followed by Microsoft (18%) and OpenAI (13%). The choice is driven by “model gravity” — native alignment with a state-of-the-art base model (21%) — and success is judged by reliable, multi-step execution (task completion reliability 32%, multi-step workflow management 28%). Yet asked to assess their portfolios honestly, 71% say a quarter or fewer of their deployed “agents” are true multi-step orchestrated workflows rather than single-prompt chatbot wrappers, and only 10% have crossed the halfway mark. The orchestration layer is being built well ahead of the orchestrated portfolio it is meant to run.</p><p>That gap shapes the architecture enterprises are putting in place. By the end of 2026 a clear majority (51%) expect a hybrid control plane — provider-native plus external orchestration — and only 6% expect to hand control to a provider-managed service, because vendor lock-in (35%) is the risk they fear most if control lives inside a model provider. Investment follows the build-out: agent workflow tooling leads the spend (34%), with security and permissions enforcement (25%) behind. And fiscal control lags throughout — more than a quarter (27%) have no real-time way to stop a runaway agent before the bill arrives.</p><h2>Methodology</h2><p>VentureBeat fielded this survey as part of its ongoing Pulse Research series, this instrument focused on enterprise agent orchestration. Responses are filtered to organizations with 100 or more employees (n=101), drawn from a single June 2026 wave; because this is one wave rather than a pooled multi-month sample, the report reads cross-sectionally and does not infer month-over-month trends.</p><p>By organization size the sample is spread evenly across the enterprise bands: 100–499 employees, 2,500–9,999, and 50,000+ (21% each), with 10,000–49,999 and 500–2,499 (19% each). By role it is senior and buyer-credible: product and program managers (15%), CIO/CTO/CISO (13%), consultants and advisors (13%), and a spread of data, AI, and engineering directors and VPs, with an “Other” function at 18%. On purchasing, 81% are recommenders, influencers, or final decision-makers for AI solutions (66% recommender/influencer, 15% final decision-maker). Technology/Software is the largest industry at 44%, followed by Financial Services (17%) and Healthcare/Life Sciences (8%).</p><p>At 101 respondents the sample is robust enough to read directionally with reasonable confidence, though it remains self-selected and is not a probability sample.</p><h2>Finding 1: Orchestration runs on model-provider platforms</h2><p><b>Anthropic’s Claude leads; open frameworks are marginal</b></p><p>We asked which agent orchestration platform enterprises primarily use today. The answer concentrates on the major model providers — and on one in particular.</p><div></div><p>A note on reading these shares. As described in the methodology section, the respondents are self-selected, and this question asked them for a single primary platform — so the figures measure which platform leads each enterprise's deployment, within a self-selected audience of AI-active technical decision-makers. A sample built this way can diverge substantially from spend-weighted market measures, and each VB Pulse survey draws its own sample with its own company-size mix, so vendor figures should not be compared across our surveys either. Read these shares as a portrait of where this cohort has placed its primary orchestration bet today, rather than as market share.</p><p>The model platforms dominate. Anthropic, Microsoft, OpenAI, Google, and Amazon together account for roughly 80% of deployments (81 of 101), while the open frameworks (LangChain/LangGraph) and custom in-house builds that anchor engineering discussion sit in single digits. Anthropic’s lead — 40%, more than double the next platform — mirrors the “model gravity” selection logic in Finding 2: enterprises are choosing the orchestration layer that comes with the model they want to build on. As with the security vendors in the prior agent-security wave, the tools that define the category in technical circles are not yet where enterprise deployment concentrates. A small 3% are not orchestrating at all.</p><p>Respondents rate the platforms they run at 3.94 out of 5 overall (109 answered), with “value for money” specifically at 3.94 and “ease of implementation” the weakest score, at 3.85 — placing orchestration near the bottom of our five-tracker satisfaction range, ahead of only evaluation tooling. A rating just under 4 out of 5, from users of whom 96% plan to change their orchestration approach within the year, reads as provisional acceptance: the platforms work well enough to run today, and not well enough to stop the search for something better. The ratings sit alongside near-universal intent to change; this is a layer enterprises tolerate more than they love.</p><h2>Finding 2: Model gravity drives platform selection</h2><p><b>The base model, not the tooling, decides the platform</b></p><p>We asked what most influenced the orchestration platform choice. The single largest factor is the pull of the underlying model — though flexibility and ease of development follow close behind.</p><div></div><p>Model gravity leading is the selection-side explanation for Anthropic’s platform lead: enterprises pick the orchestration environment closest to the frontier model they have standardized on. But the next tier complicates the picture — flexibility across models and tools (17%) and ease of development (17%) say enterprises also want to avoid being trapped by that choice, foreshadowing the lock-in fear in Finding 6. Security and permissions (14%) and total cost of ownership (11%) round out a pragmatic buying logic. Performance (latency/memory) sits last at 4%, a reminder that at this stage of adoption the binding constraints are model fit and optionality, not raw speed.</p><h2>Finding 3: The job is reliable multi-step execution</h2><p><b>Enterprises just orchestration by whether it completes the work</b></p><p>We asked what enterprises optimize for — their primary success metric for orchestration. Reliability and multi-step workflow management dominate; developer- and user-facing metrics trail.</p><div></div><p>Task completion reliability (32%) and multi-step workflow management (28%) together account for 59% of responses (60 of 101): orchestration succeeds, in the enterprise view, when it reliably carries a task through multiple steps to completion. Developer productivity (17%) matters but is secondary — the inverse of its prominence in framework discussion — and end-user experience (9%) is a minor concern, consistent with orchestration being an internal execution problem rather than a UX one. This reliability-first standard is exactly what makes the Chatbot Trap finding so pointed: enterprises define success as dependable multi-step execution, yet most of their deployed “agents” do not yet do multi-step work at all.</p><p>The trap is not evenly distributed. Splitting the sample by organization size, 77% of smaller enterprises say a quarter or fewer of their agents do true multi-step work, against 62% of larger ones. Larger enterprises are meaningfully further into genuine multi-step deployment; the chatbot trap is, directionally, a mid-market condition.</p><h2>Finding 4: Consolidate, productionize, and build in-house </h2><p><b>Three strategic moves are nearly tied for the year ahead</b></p><p>We asked what major change enterprises anticipate in their orchestration strategy over the next 12 months. Three moves cluster at the top, almost evenly split.</p><div></div><p>The top three — building in-house control (25%), standardizing on one framework (24%), and moving agents from sandbox to production (23%) — are statistically indistinguishable and tell a single story: enterprises are moving from experimentation to operational consolidation. They want fewer frameworks, more production exposure, and more ownership of the control layer; only 4% expect no change. The appetite for custom in-house control planes is notable alongside the platform concentration in Finding 1 — enterprises are standardizing on model-provider platforms while simultaneously planning to wrap them in control logic they own, the hybrid posture that Finding 6 makes explicit.</p><h2>Finding 5: Investment flows to workflow tooling</h2><p><b>Tooling and permissions lead the spend; monitoring trails</b></p><p>We asked which orchestration-related investment will grow most next year. Agent workflow tooling leads, with security and permissions enforcement behind.</p><div></div><p>Workflow tooling leading (34%) is the budget-side expression of the reliability-and-multi-step priority in Finding 3: the money is going to the machinery that strings steps together dependably. Security and permissions enforcement (25%) and scaling infrastructure (20%) follow — the investments required to take agents from sandbox into production, the strategic move in Finding 4. Monitoring and debugging draws a smaller 11%, with another 11% reporting flat budgets. The weight on tooling, permissions, and scaling over pure observability signals that enterprises are spending to build and harden orchestration, not merely to watch it run.</p><h2>Finding 6: The control plane will be hybrid — and lock-in is why</h2><p><b>Enterprises expect to split control between providers and their own layer</b></p><p>We asked where enterprises expect the primary control plane for agents to live by the end of 2026, and what worries them most if that control sits inside a model-provider platform. A clear majority expect a hybrid model — and vendor lock-in is the reason.</p><div></div><p>Hybrid control is the dominant expectation by a wide margin (51%), and only 6% expect to hand control to a provider-managed service outright. Read together, the hybrid, custom, and externally-abstracted options — every architecture that keeps control at least partly outside the provider — sum to 88% (89 of 101). The reason surfaces directly when we asked about the risk of provider-resident control: vendor lock-in leads at 35% (35 of 101), ahead of security and permissioning limitations (28%) and inflexibility across models and tools (21%). The pattern echoes the prior wave’s “don’t trust the model to police itself” posture — here, enterprises will build on a provider’s platform but decline to be governed entirely by it. The hybrid control plane is the architectural hedge against the lock-in they most fear.</p><p>The June figure asserting a preference for a hybrid control plane marks movement from earlier. In the April–May survey (n=145), only 34% expected a hybrid control plane, and a greater number (12%) expected to hand control fully to a provider-managed service. These two snapshots don’t yet measure a confirmed longitudinal trend — but the direction of the conversation is unambiguous: toward keeping control.</p><p>Lock-in is also a new arrival as a top concern. In the April–May wave, the leading concern was security and permissioning limitations (32%), with lock-in second at 24%; by June the two had traded places. The worry about provider platforms appears to be maturing from whether they can be secured to whether they can be replaced.</p><h2>Finding 7: The chatbot trap — most “agents” aren’t agents yet</h2><p><b>Enterprises admit most deployments are still chatbot wrappers</b></p><p>We asked enterprises to assess their portfolios honestly: what share of their deployed “agents” are true multi-step orchestrated workflows versus simple single-prompt chatbot wrappers. The answer is the defining finding of this wave.</p><div></div><p>This is the gap at the center of the report. Combining the bottom two bands, 71% of enterprises (72 of 101) say a quarter or fewer of their deployed “agents” are genuinely orchestrated — and just 10% (10 of 101) have crossed the halfway mark. The ambition documented in the earlier findings — model-provider platforms, reliability-first success metrics, production rollouts, a deliberate control architecture — runs well ahead of the deployed reality, which remains overwhelmingly single-prompt assistants dressed as agents. This is less a contradiction than a roadmap: the platforms, budgets, and strategies are being put in place precisely because the orchestrated portfolio is still so thin. The open question for later waves is how fast the reality closes on the ambition.</p><h2>Finding 8: Fiscal control is still reactive</h2><p><b>Only a minority can stop a runaway agent before the bill arrives</b></p><p>Finally, we asked how enterprises enforce fiscal control over agent token consumption — the risk that an autonomous loop exhausts a budget before anyone intervenes. Most rely on native caps or after-the-fact monitoring; real-time programmatic control is the exception.</p><div></div><p>More than a quarter of enterprises (27%) admit they have no real-time, programmatic way to stop an agent before a budget-breaking bill arrives — they learn of it from the logs afterward. Another 32% lean entirely on the native caps and throttles built into their primary platform, a control only as good as the provider’s tooling and one that ties back to the lock-in concern of Finding 6. The enterprises building custom gateways (23%) or exploiting cross-model routing to arbitrage cost (19%) are the ones treating token burn as an engineering problem to be controlled deterministically. As with orchestration maturity, fiscal control is an area where the operational reality lags the ambition: agents are moving toward production faster than the cost-control plane around them is being built.</p><p>It’s worth noting, a split appears according to company size: roughly one in three enterprises under 2,500 employees (34%) exercises only reactive control of agent spend, against 20% of larger enterprises — directional figures, but consistent with the chatbot-trap split. The mid-market is running the least mature agents on the least instrumented budgets.</p><h2>The bottom line: The layer is real; most of the agents aren't yet</h2><p>Organizations with 100 or more employees describe an orchestration strategy that is consolidating quickly and maturing slowly. They are standardizing on model-provider platforms — Anthropic’s Claude leads at 40% — chosen for the gravity of the underlying model, and they judge success by reliable multi-step execution. Investment is flowing to workflow tooling and permissions, the strategy is to consolidate frameworks and push agents into production, and the control plane they expect is deliberately hybrid, because vendor lock-in is the risk they fear most.</p><p>But the honest self-assessment punctures the ambition. Seventy-one percent say a quarter or fewer of their deployed “agents” are truly orchestrated, only 10% are past the halfway mark, and more than a quarter cannot stop a runaway agent in real time. The orchestration layer — the platforms, the budgets, the control architecture — is being built ahead of the orchestrated portfolio it is meant to run. At 101 respondents in a single June wave this reads as a clear directional signal rather than a precise measurement: enterprises have decided how they want to orchestrate agents well before most of their agents are doing anything an orchestration layer is for. The question for subsequent waves is whether the deployed reality closes the gap on the ambition — or whether the chatbot trap proves stickier than the roadmap assumes.</p><hr><p><i>Based on survey responses from 101 qualified enterprise respondents (100+ employees), drawn from a single June 2026 wave. Because this is one wave rather than a pooled multi-month sample, results read directionally rather than as a confirmed trend. Respondents include product and program managers, CIOs, CTOs and CISOs, consultants and advisors, and directors and VPs of data, AI, and engineering, across Technology/Software, Financial Services, Healthcare, and other sectors.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Which AI model should you bet your company on? None of them]]></title>
<description><![CDATA[Every day this past week I did something I suspect millions of other people also did: I stared at an LLM model picker and wondered which one I was supposed to want.



OpenAI just released ⁠GPT-5.6 Sol, Terra, and Luna. Sol is the flagship. Terra offers much of its intelligence for less money. Lu...]]></description>
<link>https://tsecurity.de/de/3671165/ai-nachrichten/which-ai-model-should-you-bet-your-company-on-none-of-them/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671165/ai-nachrichten/which-ai-model-should-you-bet-your-company-on-none-of-them/</guid>
<pubDate>Wed, 15 Jul 2026 17:19:39 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Every day this past week I did something I suspect millions of other people also did: I stared at an <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">LLM </a>model picker and wondered which one I was supposed to want.</p>



<p class="wp-block-paragraph">OpenAI just released ⁠<a href="https://openai.com/index/gpt-5-6/">GPT-5.6 Sol, Terra, and Luna</a>. Sol is the flagship. Terra offers much of its intelligence for less money. Luna is cheaper still. Anthropic released ⁠<a href="https://www.anthropic.com/news/claude-sonnet-5">Claude Sonnet 5</a> at the end of June and Opus 4.8 the month prior, with a little Fable 5 emerging in between. Meanwhile, Google, which seemed to be winning the model wars a few months ago, is now getting shade from Gergely Orosz, who ⁠<a href="https://x.com/GergelyOrosz/status/2075160978493210685?s=20">argues that Gemini has slipped outside the top tier</a> for software development and has been out of the major model release game for <em>eons</em> (May 19).</p>



<p class="wp-block-paragraph">Perhaps Orosz is right. Perhaps he’ll be wrong again in six weeks. Honestly, it’s exhausting.</p>



<p class="wp-block-paragraph">I use ChatGPT and Claude constantly and still have no principled idea which model to choose most of the time. I tend to click whatever looks like the biggest, most expensive option because I don’t know what I’m giving up by choosing something smaller. “Instant” sounds dangerously unserious. “Thinking” sounds expensive but powerful.</p>



<p class="wp-block-paragraph">A quick <a href="https://www.linkedin.com/feed/update/urn:li:activity:7481369774401409024/">survey of my LinkedIn crowd</a> suggests others also feel my “WHICH MODEL???” pain. More importantly, I suspect most enterprises do, too.</p>



<h2 class="wp-block-heading"><a></a>A model doesn’t rot</h2>



<p class="wp-block-paragraph">Before getting carried away, however, it’s worth considering whether any of this model churn actually matters. After all, a model doesn’t rot. The model an enterprise put into production in March performs just as well in July as it did when the company selected it. “Obsolete” generally means that something better now exists, not that the deployed model suddenly stopped summarizing insurance claims or classifying support tickets. (In other words, once you have something working, the idea that “but maybe Opus 200.2 is better!” is really a FOMO problem, not a performance issue.)</p>



<p class="wp-block-paragraph">Most enterprise workloads don’t live at the frontier anyway. Extraction, summarization, classification, document comparison, and customer-service assistance often work perfectly well with smaller, cheaper models. OpenAI’s own pitch for the trio of GPT-5.6 models isn’t simply that Sol is better. It’s that ⁠Terra and Luna deliver different combinations of intelligence, latency, and cost. Luna, the cheapest tier, nearly matches the previous generation’s peak performance at less than half the estimated cost, according to OpenAI.</p>



<p class="wp-block-paragraph">The practical question, of course, is where to start. An enterprise can’t test every model, every reasoning setting, and every price tier before doing any work. So here’s my advice (which I don’t follow in my own work, but I’m not defining enterprise strategy and can be a little price-insensitive). Start with the cheapest credible model that appears capable of the task. Give it a representative set of real examples and, before you start testing, define what counts as good enough. If it passes, stop. If it fails, move up a tier or try a model with strengths better suited to the work.</p>



<p class="wp-block-paragraph">That sounds almost offensively simple, but it reverses the way many people, including me, use these products. We start with the biggest model because we’re afraid of what we might lose. Enterprises should start lower and require evidence before paying for more intelligence.</p>



<p class="wp-block-paragraph">There are exceptions, of course. For genuinely difficult work, such as autonomous coding, complex research, or high-stakes reasoning, beginning with a frontier model may save time. But even then, the goal should be to establish a quality ceiling, then test whether a cheaper model can meet it. It’s changing the question from “which model is best?” to “what is the least expensive model that reliably clears the bar for this job?”</p>



<p class="wp-block-paragraph">For many workloads, that price improvement matters more than a few extra benchmark points. <a href="https://www.infoworld.com/article/2335519/ai-hype-isnt-helping-anyone.html">⁠As I argued back in 2023</a>, following AI hype doesn’t help anyone. If your model strategy depends on whichever benchmark screenshot is circulating on X this week, you don’t have a strategy. Not a viable one, anyway. Pick a model and ignore the noise.</p>



<p class="wp-block-paragraph">Except, of course, when that noise suggests a serious signal.</p>



<h2 class="wp-block-heading"><a></a>Sometimes better really is better</h2>



<p class="wp-block-paragraph">Frontier improvements aren’t always incremental, making it advantageous to consider an upgrade. Coding is the obvious example. There’s a significant difference between a model that suggests the next few lines of code and one that can inspect a repository, plan a change, use tools, run tests, discover its own mistakes, and keep working for an extended period. That isn’t merely a nicer autocomplete experience. It can reorganize a development workflow.</p>



<p class="wp-block-paragraph">This is why enterprises can’t simply standardize on an 18-month-old model and declare victory. In some areas, particularly software development and other agentic work, better models can unlock compounding productivity. A model that reliably completes 80% of a bounded task rather than 50% may justify an entirely different division of labor between humans and machines.</p>



<p class="wp-block-paragraph">Still, that upgrade isn’t free.</p>



<p class="wp-block-paragraph">Models differ in how they interpret instructions, call tools, manage context, refuse requests, and fail. Prompts and scaffolding tuned for one model can regress when moved to another. Or costs can explode. As one of my Oracle colleagues discovered just this week, running the same tasks in GPT 5.6 was orders of magnitude more expensive than 5.5. The API change may be trivial, but the revalidation and implications are not.</p>



<p class="wp-block-paragraph">This leaves enterprises caught between two bad options. They can freeze and potentially miss out on meaningful improvements or chase every release and repeatedly test production systems on faith. What to do?</p>



<h2 class="wp-block-heading"><a></a>Stop making model bets</h2>



<p class="wp-block-paragraph">The answer is to stop making LLM bets and start making job-to-be-done bets. Stop asking which model is fastest. Instead, figure out what work you are trying to improve. What does a good result look like? How much latency and cost can the workflow tolerate? How wrong can it be before a human must intervene? Once those questions have answers, model selection becomes less opaque.</p>



<p class="wp-block-paragraph">A difficult code migration may justify GPT-5.6 Sol or Claude Sonnet 5. A repetitive classification task may work just as well with Luna or another smaller model. A regulated workflow may require a model or deployment option that offers particular data controls. Sometimes the correct model is no LLM at all, like when I’m writing this post. Sorry, AI vendors! (At least you won’t get blamed for my mistakes.)</p>



<p class="wp-block-paragraph">This is where evaluations become the center of enterprise AI strategy. <a href="https://www.infoworld.com/article/4166247/improving-ai-agents-through-better-evaluations.html">⁠As I’ve said before</a>, most companies don’t have an AI quality problem so much as an AI measurement problem. Hence, a private evaluation suite built from real company work is the only leaderboard that matters. Does the new model materially improve quality? If so, use it! Does it reduce cost or latency? Again, that’s your free pass to adoption. Does the improvement justify the expense and effort of revalidation? If yes, continue.</p>



<h2 class="wp-block-heading"><a></a>Make model releases boring</h2>



<p class="wp-block-paragraph">As important as the model is, keep in mind that AI success always comes back to <em>your</em> company’s data, <em>your</em> company’s workflows<em>, your</em> company’s integrations, etc. That’s the ⁠<a href="https://www.infoworld.com/article/4157506/mastering-the-dull-reality-of-sexy-ai.html">dull reality behind sexy AI</a>. Retrieval, <a href="https://www.infoworld.com/article/4189492/how-to-improve-the-memory-of-ai-agents.html">memory</a>, governance, data quality, <a href="https://www.infoworld.com/article/2262666/what-is-observability-software-monitoring-on-steroids.html">observability</a>, and feedback loops aren’t as exciting as a new model launch, but they’re what ultimately make AI truly work.</p>



<p class="wp-block-paragraph">Again, when it’s time to consider something new, the principle should be to default to the least expensive model that reliably passes your evaluations. Only escalate harder tasks to more capable models when measurement shows that the premium pays. Tip: Make this invisible to employees so that the system routes to the best model for a particular prompt. As <a href="https://www.linkedin.com/feed/update/urn:li:activity:7481369774401409024/?dashCommentUrn=urn%3Ali%3Afsd_comment%3A%287481372047860715522%2Curn%3Ali%3Aactivity%3A7481369774401409024%29">dbt Labs’ Jon Lewis expresses</a> it, “The best model is ‘Auto’ and I won’t hear anyone say otherwise.” OpenAI’s own ⁠<a href="https://developers.openai.com/api/docs/guides/latest-model">migration guidance</a> recommends testing models on representative tasks, including trying a lower reasoning level rather than automatically cranking everything to the maximum.</p>



<p class="wp-block-paragraph">As for me, I’ll probably keep clicking the shiniest option. I don’t have a formal evaluation suite for InfoWorld columns, and the marginal cost is a subscription I already pay. Enterprises don’t get that excuse.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[5 ways for CIOs to avoid AI bill shock]]></title>
<description><![CDATA[Gen AI spending is moving beyond the familiar software model of seats, licenses, and pilots. As AI shifts from copilots to embedded workflows and autonomous agents, one user request can trigger multiple model calls, retrieval steps, retries, orchestration layers, and infrastructure events. A tool...]]></description>
<link>https://tsecurity.de/de/3670246/it-security-nachrichten/5-ways-for-cios-to-avoid-ai-bill-shock/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670246/it-security-nachrichten/5-ways-for-cios-to-avoid-ai-bill-shock/</guid>
<pubDate>Wed, 15 Jul 2026 12:08:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Gen AI spending is moving beyond the familiar software model of seats, licenses, and pilots. As AI shifts from copilots to embedded workflows and autonomous agents, one user request can trigger multiple model calls, retrieval steps, retries, orchestration layers, and infrastructure events. A tool that looks affordable in pilot may behave very differently once connected to production systems or allowed to act with less human supervision.</p>



<p class="wp-block-paragraph">According to Michael Corrigan, CIO of World Insurance Associates, AI introduces a fundamentally different cost model — one that’s usage driven, non-linear, and tightly coupled to business activity. “Success requires shifting from traditional IT budgeting to FinOps-style discipline where consumption, value, and governance are actively managed in real time,” he says.</p>



<p class="wp-block-paragraph">Here are five ways CIOs can build that discipline before AI costs spiral.</p>



<h2 class="wp-block-heading">Forecast AI by workflow, not by user</h2>



<p class="wp-block-paragraph">At World, a top 25 insurance broker with about 3,000 employees across roughly 300 locations, AI use falls into three broad categories, Corrigan says. One is broad tools, such as copilots. Another is embedded AI inside SaaS platforms. And the third is bespoke AI built around specific workflows and manual processes.</p>



<p class="wp-block-paragraph">“The bespoke is the area that’s growing the most right now,” he says. “And that’s where the model, from a cost perspective, has really been shifting from a license seat cost to a token consumption or token burn cost, or even a hybrid.”</p>


<div class="extendedBlock-wrapper block-coreImage left"><figure class="wp-block-image alignleft size-1240-r3:2 is-resized"> width="1240" height="827" sizes="auto, (max-width: 1240px) 100vw, 1240px"&gt;<figcaption class="wp-element-caption"><p>Michael Corrigan, CIO, World Insurance Associates</p>
</figcaption></figure><p class="imageCredit">WIA</p></div>



<p class="wp-block-paragraph">Seat-based pricing is relatively easy to forecast whereas consumption-based AI isn’t. Costs may depend on prompt complexity, output length, model choice, workflow design, and whether the system calls a model once or many times in the background.</p>



<p class="wp-block-paragraph">World tries to manage that uncertainty by defining the business problem, success criteria, and expected operational improvement upfront. Pilots help estimate consumption before scaling, but Corrigan says they don’t remove the ambiguity.</p>



<p class="wp-block-paragraph">“We’ll try our best in the pilot to understand what the consumption rate is, what the token burn rate is,” he says. But once a consumption-based workflow goes into production, he adds, an estimate is put into place. That estimate is informed, but still rough.</p>



<p class="wp-block-paragraph">Elmer Morales, founder and CEO of koder.com, an agentic AI coding startup, says CIOs should think less about headcount and more about <a href="https://www.cio.com/article/4163373/cios-bring-ai-transformation-home-to-it-workflows.html?utm=hybrid_search">workflow mechanics</a>. Agentic AI costs are driven by the number of decisions an agent makes, how often it retrieves external data, how much context it carries, and how many systems it touches.</p>



<p class="wp-block-paragraph">“CIOs should start by mapping workflows, not necessarily users,” he says. “The relevant variable isn’t going to be the headcount but how many decisions an agent makes per task.”</p>



<h2 class="wp-block-heading">Model the failure path, not just the happy path</h2>



<p class="wp-block-paragraph">Pilots can mislead because they often test the cleanest version of an AI workflow. Morales says many enterprises model agentic AI costs around the happy path: the user gives a clear prompt, the system understands the request, the agent completes the task, and the process ends. Production is messier.</p>



<p class="wp-block-paragraph">“They generally don’t model for situations where the agent is going to need to go back and check its work and redo things,” Morales says. “A lot of times, agents are wrong, either because they hallucinate or they understood the problem incorrectly.”</p>



<p class="wp-block-paragraph">In an agentic workflow, the system may check its work, call another tool, retrieve more data, or redo a step. While that may improve quality, it also adds cost.</p>


<div class="extendedBlock-wrapper block-coreImage left"><figure class="wp-block-image alignleft size-1240-r3:2 is-resized"> width="1240" height="827" sizes="auto, (max-width: 1240px) 100vw, 1240px"&gt;<figcaption class="wp-element-caption"><p>Elmer Morales, founder and CEO, koder.com</p>
</figcaption></figure><p class="imageCredit">koder.com</p></div>



<p class="wp-block-paragraph">The difference between copilots and <a href="https://www.cio.com/article/3603856/agentic-ai-promising-use-cases-for-business.html?utm=hybrid_search">agents</a> is central. A copilot interaction is often one prompt and one response. An agentic workflow may involve agents moving through a decision tree, executing tasks in sequence or in parallel, and calling sub-agents or external systems along the way. “By the time it’s achieved the original goal, the agent might have made 50 or 100 model calls, compared with a single call for a traditional copilot prompt,” Morales says.</p>



<p class="wp-block-paragraph">That’s why CIOs should require teams to model the failure path before production, like how many retries are allowed, how much context is resent, which tools can be called, when a human should intervene, and what happens when the agent can’t complete the task.</p>



<h2 class="wp-block-heading">Build cost controls into the architecture</h2>



<p class="wp-block-paragraph">Traditional FinOps practices still matter, but AI requires more than retrospective dashboards and chargebacks.</p>



<p class="wp-block-paragraph">According to Pavan Madduri, senior cloud platform engineer at industrial supply company Graigner, looking backward at usage data, as traditional FinOps often does, can be too late. Costs are shaped by prompt design, model selection, agent behavior, orchestration choices, and runtime loops.</p>



<p class="wp-block-paragraph">“Dashboards or chargebacks, those are historical accounting,” he says. “The money’s already gone.” For AI, he argues, cost controls need to be embedded into the architecture. That includes hard token caps, retry-depth limits, maximum runtime limits, workload prioritization, background-job throttling, and cluster-level controls that prevent runaway consumption.</p>



<p class="wp-block-paragraph">“The real FinOps means you need to have the cost constraints embedded into your architecture framework,” Madduri says.</p>



<p class="wp-block-paragraph">Those controls also extend to infrastructure. Expensive GPUs may sit warm between jobs because systems need capacity available when inference demand arrives. Teams may pass huge schemas, databases, or thousands of lines of code into frontier models when a smaller or more focused prompt would do.</p>


<div class="extendedBlock-wrapper block-coreImage left"><figure class="wp-block-image alignleft size-1240-r3:2 is-resized"> width="1240" height="828" sizes="auto, (max-width: 1240px) 100vw, 1240px"&gt;<figcaption class="wp-element-caption"><p>Pavan Madduri, senior cloud platform engineer, Graigner</p>
</figcaption></figure><p class="imageCredit">Graigner</p></div>



<p class="wp-block-paragraph">Enterprises should also adopt event-driven autoscaling, Madduri says. “Use tools like KEDA to scale GPU nodes down to zero the moment inference demand drops, so teams only pay for the windows when the silicon is actively crunching tokens.”</p>



<p class="wp-block-paragraph">Corrigan says World uses rate limits, spend limits, alerts, and approval gateways for consumption-based tools. When users approach token consumption limits, automated alerts allow IT and the business to review whether the continued spend is justified.</p>



<p class="wp-block-paragraph">“If it’s not meeting the success criteria we expected, you have to have the control in place to say we’re going to move on or kill that process,” Corrigan says.</p>



<h2 class="wp-block-heading">Route work to the right model</h2>



<p class="wp-block-paragraph">CIOs can also reduce <a href="https://www.cio.com/article/4152601/without-controls-an-ai-agent-can-cost-more-than-an-employee.html?utm=hybrid_search">AI bill shock</a> by avoiding a default assumption that every task requires the most powerful model available. While some tasks need advanced reasoning, many others don’t. A simple support ticket, log-parsing task, or structured database transaction may be handled by a smaller or cheaper model. A complex architecture decision, legal analysis, or multi-step reasoning task may justify a more powerful one.</p>



<p class="wp-block-paragraph">“Choosing the right model for the right prompt and right question — that’s where you leverage the maximum from that model, and you can decrease the costing,” Madduri says. “If you default every single call to a frontier model, that’s architectural laziness.”</p>



<p class="wp-block-paragraph">Morales makes a similar point. Not every step in an agentic workflow requires a top-of-the-line model. Model routing, he says, is the discipline of determining the best model for the task, and providing the relevant context when the model needs it.</p>



<p class="wp-block-paragraph">According to Jim Olsen, CTO of enterprise software company ModelOp, CIOs should use the least expensive model that can accomplish the business goal. Using the biggest model for everything is easier, but expensive. “It’s like hiring the most expensive engineer to change a few colors in a website’s CSS, or visual styling,” he says. “You wouldn’t do that. You use the appropriate tools for the task.”</p>



<h2 class="wp-block-heading">Tie consumption to business value</h2>



<p class="wp-block-paragraph">For Olsen, the deeper enterprise problem is AI value shock, not just bill shock. Spending $200,000 in a quarter on AI is justified if it produces $2 million in business value. The problem is spending heavily on use cases that don’t generate a meaningful return.</p>



<p class="wp-block-paragraph">“Are you actually getting that return on investment, or are you just blowing tokens for something that’s not delivering the value to your business?” Olsen asks. Tracking token usage by user or department may show who consumed AI, but not whether the consumption mattered.</p>


<div class="extendedBlock-wrapper block-coreImage left"><figure class="wp-block-image alignleft size-1240-r3:2 is-resized"> width="1240" height="827" sizes="auto, (max-width: 1240px) 100vw, 1240px"&gt;<figcaption class="wp-element-caption"><p>Jim Olsen, CTO, ModelOp</p>
</figcaption></figure><p class="imageCredit">ModelOp</p></div>



<p class="wp-block-paragraph">For most enterprise AI systems, Olsen says costs should be tied back to business use cases. A model may be used for HR document search, customer support, code review, problem resolution, or other functions. Each use case may draw on the same underlying models or agents, but the business value can be very different.</p>



<p class="wp-block-paragraph">That’s why he argues that companies need an AI inventory, a record of which business workflows use which models, agents, providers, workflows, and systems. Without that inventory, enterprises can’t connect consumption to value.</p>



<p class="wp-block-paragraph">Corrigan takes a similar approach from a governance perspective. At World, new AI ideas go through an intake process. Business users propose improvements, and IT, finance, operations, sales, and business stakeholders evaluate, prioritize, and monitor them from pilot through production.</p>



<p class="wp-block-paragraph">That may be where the next stage of AI FinOps is heading, toward a clearer understanding of which AI consumption deserves to scale, not just to lower bills. So the question, as Olsen puts it, isn’t whether someone used a million tokens. It’s what are they using them for.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Senior executives abuse shadow AI twice as much as regular employees do]]></title>
<description><![CDATA[Shadow IT has long been a major problem for IT leaders, but the biggest problem may be coming from the executive suite’s hunger for unsanctioned AI.



Nearly two-thirds of senior decision-makers admit to using unapproved AI tools, compared to just 31% of lower-level employees, according to a sur...]]></description>
<link>https://tsecurity.de/de/3670109/it-security-nachrichten/senior-executives-abuse-shadow-ai-twice-as-much-as-regular-employees-do/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670109/it-security-nachrichten/senior-executives-abuse-shadow-ai-twice-as-much-as-regular-employees-do/</guid>
<pubDate>Wed, 15 Jul 2026 11:08:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Shadow IT has long been a major problem for IT leaders, but the biggest problem may be coming from the executive suite’s hunger for unsanctioned AI.</p>



<p class="wp-block-paragraph">Nearly two-thirds of senior decision-makers admit to using <a href="https://www.cio.com/article/4178359/why-your-most-ai-savvy-employees-are-driving-shadow-ai.html">unapproved AI tools</a>, compared to just 31% of lower-level employees, according <a href="https://www.trustedtechteam.com/pages/shadow-ai-whitepaper-download">to a survey</a> by Microsoft solutions partner TrustedTech.</p>



<p class="wp-block-paragraph">The use of <a href="https://www.cio.com/article/647725/it-leaders-grapple-with-shadow-ai.html">shadow AI</a> is prevalent among senior executives even though three in four employees acknowledge security or data privacy risks related to the practice.</p>



<p class="wp-block-paragraph">“Most shadow AI users are not ignorant of the risk,” TrustedTech says in a white paper. “They are deliberately choosing to use these tools anyway. This is not a training issue. It is a culture, incentives, and alternatives issue.”</p>



<p class="wp-block-paragraph">In many cases, the problem is driven by a lack of approved tools, the report adds.</p>



<p class="wp-block-paragraph">“People use shadow AI because what their employer hands them is worse than mainstream AI tools, or because nothing has been approved in the first place,” the report says. “That doesn’t change until the sanctioned tools are genuinely worth using.”</p>



<h2 class="wp-block-heading">A question of authority</h2>



<p class="wp-block-paragraph">The use of shadow AI by CEOs and other C-suite executives can create major problems for CIOs, CISOs, and other IT executives because they may not have the authority to put the kibosh on it.</p>



<p class="wp-block-paragraph">It also presents a challenge for IT leaders to provide the AI tools that employees and executives want to use.</p>



<p class="wp-block-paragraph">When executives use shadow AI, CIOs are in a difficult position, because governance only works when it’s modeled from the top, says<a href="https://www.linkedin.com/in/annolan/"> Andy Nolan,</a> VP of technology at TrustedTech.</p>



<p class="wp-block-paragraph">“If senior leaders bypass approved AI tools or policies, it sends an implied message that speed matters more than security and compliance,” he adds. “Employees notice that behavior, and it becomes much harder to ask the rest of the organization to follow standards that leadership isn’t following themselves, first.”</p>



<p class="wp-block-paragraph">Another major problem is that executives often work with highly sensitive information, including financial data, strategic plans, intellectual property, and customer information, he notes.</p>



<p class="wp-block-paragraph">But CIOs and CISOs also can’t solve the problem by becoming the AI police in every situation, Nolan says, because their role is to help the business innovate safely.</p>



<p class="wp-block-paragraph">“That requires executive alignment, clear governance, and providing secure AI tools that people actually want to use,” he adds. “When leadership embraces those solutions, the rest of the organization is almost sure to follow.”</p>



<h2 class="wp-block-heading">All risk, no reward</h2>



<p class="wp-block-paragraph">The use of shadow AI by senior executives puts CIOs and CISOs in an impossible position, agrees <a href="https://www.linkedin.com/in/amit-maloo-b087291/">Amit Maloo</a>, CISO at AI procurement provider Ivalua. CIOs and CISOs are <a href="https://www.cio.com/article/4182288/cios-are-being-held-accountable-for-ai-they-dont-fully-control-ibm-study-finds.html?utm=hybrid_search">held accountable</a> for the risk exposure but have no visibility into the problem, he says.</p>



<p class="wp-block-paragraph">“When senior leaders use ungoverned AI tools for business decisions, those decisions still have consequences, such as financial commitments, contract reviews, and data sharing,” he adds. “But there is no audit trail, no permissions model, or no way to reconstruct what happened or why.”</p>



<p class="wp-block-paragraph">Part of the problem is that approved AI options often don’t meet the needs of users, Maloo says.</p>



<p class="wp-block-paragraph">“AI policies alone aren’t enough; organizations need to pair governance with usability,” he adds. “If approved AI tools don’t meet the pace of business, employees at every level, including leadership, will find their own solutions. Successful organizations will be those that make the secure path the easiest path.”</p>



<p class="wp-block-paragraph">IT leaders can’t solve the problem with more governance, he notes. “Policies and restrictions slow shadow AI down, but they don’t stop it, especially when the people using it are senior enough to absorb the disciplinary risk,” Maloo adds. “What CIOs can do is focus on providing tools that grant users full access to the necessary systems and data, eliminating the need to choose between a capable but ungoverned tool and a safe but limited one.”</p>



<h2 class="wp-block-heading">Speed over security</h2>



<p class="wp-block-paragraph">The TrustedTech data echoes a <a href="https://www.teramind.co/l/shadow-ai-report-2026/">June report</a> from employee monitoring software vendor Teramind, which found that more than two-thirds of C-level executives prioritize speed over security when using AI tools, notes <a href="https://www.linkedin.com/in/nikkale/">Nik Kale</a>, a principal engineer and product architect at Cisco, and member of the Coalition for Secure AI.</p>



<p class="wp-block-paragraph">In addition, the Teramind report found that two-thirds of enterprise AI activity runs through personal accounts on platforms for which the company already owns licenses, he notes.</p>



<p class="wp-block-paragraph">“People are paying for the governed version and using the ungoverned version of the same product, so the problem isn’t the tools,” he says. “The approved path is slower, buried in procurement, or disconnected from where the work actually happens, and speed wins every time under a deadline.”</p>



<p class="wp-block-paragraph">The problem then isn’t with the AI tools, but with the friction involved, he says. “People aren’t going around the front door because the room is locked,” Kale adds. “They’re going around it because the front door is slower.”</p>



<p class="wp-block-paragraph">In many cases, the use of shadow AI exposes a couple of shortcomings in enterprise processes, adds <a href="https://www.linkedin.com/in/matt-scavetta-018b10173/">Matthew Scavetta</a>, chief technology innovation officer at IT solutions provider Future Tech Enterprise.</p>



<p class="wp-block-paragraph">Many organizations don’t do a good job of making employees aware of the AI tools available to them, he says, and many organizations don’t offer training on the sanctioned applications, which drives users to pick products they are familiar with.</p>



<p class="wp-block-paragraph">“If you don’t solve problems for people quickly or make people aware of which tools they can use safely, they will find a workaround,” he adds. “AI tools are no different than anything else.”</p>



<p class="wp-block-paragraph">Shadow AI use by executives puts IT leaders in an incredibly difficult position, he says.</p>



<p class="wp-block-paragraph">“CIOs, in particular, are under more and more pressure each year to keep up with what’s possible as tech influencers keep preaching about the potential of these tools,” Scavetta says. “CEOs and board members are constantly getting swept up in the hype; meanwhile, there are more and more case studies coming out showing how little ROI some organizations have realized. It’s a never-ending game of balancing possible with practical.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Best Shared Hosting Solutions for Your Business]]></title>
<description><![CDATA[Choosing the best shared hosting services is essential for business owners who want to build a beautiful website and maintain it effectively. Regardless of the size of your business, an online presence is a way to reach a large audience. And a reliable website is the way to do just that to bring ...]]></description>
<link>https://tsecurity.de/de/3669381/betriebssysteme/the-best-shared-hosting-solutions-for-your-business/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669381/betriebssysteme/the-best-shared-hosting-solutions-for-your-business/</guid>
<pubDate>Wed, 15 Jul 2026 03:54:09 +0200</pubDate>
<category>🖥️  Betriebssysteme</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Choosing the best shared hosting services is essential for business owners who want to build a beautiful website and maintain it effectively. Regardless of the size of your business, an online presence is a way to reach a large audience. And a reliable website is the way to do just that to bring customers to […]</p>
<p>The post <a rel="nofollow" href="https://www.addictivetips.com/hosting/best-shared-hosting-services/">The Best Shared Hosting Solutions for Your Business</a> appeared first on <a rel="nofollow" href="https://www.addictivetips.com/">AddictiveTips</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How AI agents are shaping the future of work]]></title>
<description><![CDATA[I attended several major technology conferences in 2025 where the first AI agents embedded in enterprise SaaS platforms were announced. Some of these agents showed promise and a glimpse into the future of work, while others looked like natural language extensions of a platform’s existing function...]]></description>
<link>https://tsecurity.de/de/3667534/it-security-nachrichten/how-ai-agents-are-shaping-the-future-of-work/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667534/it-security-nachrichten/how-ai-agents-are-shaping-the-future-of-work/</guid>
<pubDate>Tue, 14 Jul 2026 12:07:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">I attended several major technology conferences in 2025 where the first AI agents embedded in enterprise SaaS platforms were announced. Some of these agents showed promise and a glimpse into the future of work, while others looked like natural language extensions of a platform’s existing functionality.  </p>



<p class="wp-block-paragraph">At the end of 2025, Anthropic and OpenAI launched new AI models and code-generating capabilities. More developers tried <a href="https://www.infoworld.com/article/4058076/vibe-coding-and-the-future-of-software-development.html">vibe coding</a>, and some platforms launched <a href="https://www.infoworld.com/article/4166817/vibe-coding-or-spec-driven-development.html">spec-driven development capabilities</a>. By February 2026, even The New York Times reported that <a href="https://www.nytimes.com/2026/02/18/opinion/ai-software.html">the AI disruption had arrived</a>, noting that code generators were building “apps that may be flawed, but credible.”</p>



<p class="wp-block-paragraph">Wall Street investors took notice of the code-generation improvements and other disruptive factors, driving a selloff in SaaS stocks, now referred to as the “<a href="https://www.bloomberg.com/news/articles/2026-02-03/-get-me-out-traders-dump-software-stocks-as-ai-fears-take-hold">SaaSpocalypse</a>.” Part of their concern stemmed from the belief that CIOs would use AI to <a href="https://www.cio.com/article/4148303/cios-rethink-softwares-future-as-ai-agents-advance.html">write software that would replace SaaS solutions</a>.</p>



<h2 class="wp-block-heading">AI innovations from SaaS and solution providers</h2>



<p class="wp-block-paragraph">But I thought differently and wrote a response in my article asking whether <a href="https://www.cio.com/article/4146669/is-ai-the-end-of-saas-as-we-know-it.html">AI is the end of SaaS as we know it</a>. CIOs might use AI to accelerate application modernization, but I doubt they would replace their ERP, CRM, and even smaller SaaS point solutions by building them.</p>



<p class="wp-block-paragraph">Instead, I believed it would be SaaS companies that would take the most advantage of AI code-generation capabilities.</p>



<p class="wp-block-paragraph">This hypothesis drove me to attend nine conferences this spring to see how SaaS companies were launching AI agents and defining a new future of work. I wrote eight articles on <a href="https://drive.starcio.com/cios-need-to-know">what CIOs need to know</a> about data management, agile organizations, marketing, ERPs, critical process management, and other evolutions to plan for in the AI era.</p>



<p class="wp-block-paragraph">Now, looking across all nine conferences, I can draw some conclusions about how AI agents are shaping the future of work. Here are my learnings and what CIOs need to consider when evaluating and deploying AI agents in the workplace.</p>



<h2 class="wp-block-heading">Agentic, human-in-the-middle, or augmenting human?</h2>



<p class="wp-block-paragraph">SaaS companies have very distinct perspectives on the future of work, including the extent to which humans will play which roles and whether and how quickly we’ll see agentic, fully automated work.</p>



<p class="wp-block-paragraph">For example, Atlassian proclaimed, “<a href="https://www.atlassian.com/company/events">step into the future of human-AI collaboration</a>,” while SAP unveiled “<a href="https://news.sap.com/2026/05/sap-sapphire-sap-unveils-autonomous-enterprise/">the autonomous enterprise</a>.” Snowflake aimed to “<a href="https://www.snowflake.com/en/summit/">make AI real for business</a>,” while Appian targeted “<a href="https://www.appianworld.com/">serious AI built on process</a>.”</p>



<p class="wp-block-paragraph">These vendors’ marketers had to decide whether to lead with AI, people, or business in their messaging, but so must CIOs as they contemplate their AI strategies and how to get employees to fully adopt AI agents.</p>



<p class="wp-block-paragraph">Some CIOs see a fully automated agentic AI as the future, with human-in-the-middle as a transitional phase as departments build trust in AI agents’ decision-making and automation capabilities.</p>



<p class="wp-block-paragraph">Other CIOs see AI more as a tool that delivers productivity improvements by augmenting human decision-making capabilities. Many of these CIOs see human augmentation as essential to supporting critical thinking, innovation, and creativity.</p>



<p class="wp-block-paragraph"><a href="https://www.deloitte.com/us/en/what-we-do/capabilities/applied-artificial-intelligence/content/state-of-ai-in-the-enterprise.html">Deloitte’s State of AI Report</a>, published in January, provides a benchmark. It states that 36% of IT leaders expect at least 10% of their jobs to be fully automated in the next year, and 82% expect to reach that benchmark in three years.</p>



<p class="wp-block-paragraph">Many organizations will have a mix of AI agents, choosing automation where reliability at scale is possible, but opting for human augmentation in operationally critical or customer-facing domains. But how CIOs position AI agents is not only an operational strategy; it’s also a cultural statement that shapes employees’ embrace of AI and whether <a href="https://drive.starcio.com/2026/03/ai-leadership-job-at-risk-or-career-opportunity/">detractors vocalize job-loss fears</a>.</p>



<p class="wp-block-paragraph">In the short term, it will also weigh in on which AI agents to use from different partners and which areas to build in-house.</p>



<h2 class="wp-block-heading">Many options to test and deploy AI agents</h2>



<p class="wp-block-paragraph">Many solution providers are demonstrating significantly more AI agents this year. For example, SAP went from <a href="https://drive.starcio.com/2026/05/autonomous-enterprise-ai-cios/">40 Joule Agents in 2025 to over 200 in 2026.</a> Three technology capabilities are fueling this significant growth:</p>



<ul class="wp-block-list">
<li>Adobe, Appian, Boomi, Cisco, Domo, Salesforce, SAP, Snowflake, and others offer <a href="https://www.infoworld.com/article/3497094/does-your-organization-need-a-data-fabric.html">data fabrics</a> and <a href="https://www.infoworld.com/article/3487711/the-definitive-guide-to-data-pipelines.html">data-pipeline</a> capabilities to connect data sources outside the primary workflows supported by their platforms. Appian, Pega, Quickbase, and SAP also centralize business process automation, an important starting point for developing AI agents.  </li>



<li><a href="https://www.infoworld.com/article/4124612/5-requirements-for-using-mcp-servers-to-connect-ai-agents.html">MCP servers</a> enable integration and communication between AI agents and are used to facilitate multistep agentic workflows. Virtually all the companies announcing major investments in AI agents are also announcing MCP integration capabilities and related partnerships.</li>



<li>Solution providers are not just using AI code-generating capabilities; many are launching their own AI agent development tools. The first beneficiaries of these development tools are the solution providers themselves and their integration partners, who use them to accelerate the development of AI agents and make them available to customers.</li>
</ul>



<p class="wp-block-paragraph">The result is that <a href="https://drive.starcio.com/2025/10/ai-agents-definitive-guide-saas-security-titans/">CIOs will have many options about which agents to test</a>, but will have to dedicate analysts to understand the capability, cost, and compliance trade-offs. Additionally, expect AI agent capabilities to evolve significantly over the next few years, so CIOs should continuously revisit their decisions regarding deployed AI agents, focusing on performance, benefits, and ROI.</p>



<p class="wp-block-paragraph">CIOs should also watch for signs of <a href="https://www.cio.com/article/1247890/7-steps-for-turning-shadow-it-into-a-competitive-edge.html">shadow AI</a> and employee confusion about which AI agents to experiment with on different platforms. The AI strategy should include a transparent, defined process for selecting, reviewing, evaluating, procuring, deploying, driving adoption, monitoring, and collecting end-user feedback around AI agents.</p>



<h2 class="wp-block-heading">AI development capabilities for engineers and citizen builders</h2>



<p class="wp-block-paragraph">The apparent ease-of-use of AI code generators may lead some engineering teams to <a href="https://www.cio.com/article/4097339/your-next-big-ai-decision-isnt-build-vs-buy-its-how-to-combine-the-two.html">build AI agents rather than buy them</a> from SaaS providers. But CIOs should quickly realize that coding is just one step in developing AI agents, and that aggressively pursuing a build strategy can lead to <a href="https://www.cio.com/article/4178324/7-sources-of-ai-debt-and-how-to-avoid-them.html">AI debt</a> and <a href="https://www.cio.com/article/4107377/cios-will-underestimate-ai-infrastructure-costs-by-30.html">increased AI costs</a>.</p>



<p class="wp-block-paragraph">DevOps teams can code AI agents using tools such as Claude, Codex, Lovable, and Replit — a do-it-yourself approach. Some SaaS companies are providing an alternative, with AI agent development tools that leverage the data, infrastructure, and governance baked into their platforms. Many of these development tools offer flexibility, allowing developer teams to select AI models and development environments.</p>



<p class="wp-block-paragraph">Examples of new and enhanced AI development tools I saw at conferences this quarter include:</p>



<ul class="wp-block-list">
<li><a href="https://appian.com/blog/2025/appian-25-4-release-enterprise-ai-agents">Appian Composer and Agent Studio</a></li>



<li><a href="https://www.atlassian.com/software/rovo-dev">Atlassian Rovo Dev</a></li>



<li><a href="https://boomi.com/platform/companion/">Boomi Companion</a></li>



<li><a href="https://www.cisco.com/site/us/en/solutions/artificial-intelligence/agentic-ops/cloud-control-studio/index.html">Cisco Cloud Control Studio</a></li>



<li><a href="https://www.domo.com/app-catalyst">Domo App Catalyst</a></li>



<li><a href="https://www.pega.com/about/news/press-releases/pega-harnesses-best-practices-and-ai-coding-agents-build-apps-mission">Pega Infinity Studio</a></li>



<li><a href="https://www.quickbase.com/pave">Quickbase Pave</a></li>



<li><a href="https://www.snowflake.com/en/product/snowflake-coco/">Snowflake CoCo</a></li>



<li><a href="https://www.sap.com/products/artificial-intelligence/joule-studio.html">SAP Joule Studio</a>.</li>
</ul>



<p class="wp-block-paragraph">I also reviewed <a href="https://www.nutanix.com/solutions/ai">Nutanix Agentic AI</a>, a platform-as-a-service for accelerating the deployment of agentic AI workloads, and <a href="https://www.adobe.com/products/firefly/features/ai-assistant.html">Adobe Firefly AI Assistant</a> for creatives.</p>



<p class="wp-block-paragraph">These development tools can target different audiences. Some look like low-code development tools targeted at software developers, whereas others are <a href="https://drive.starcio.com/2026/05/low-code-in-the-ai-era-cios-need-to-know/">no-code and enable citizen developers</a>, i.e., businesspeople, to <a href="https://www.cio.com/article/4176062/cios-are-enlisting-business-users-to-vibe-code-their-own-apps.html">develop applications and agents</a>. Additionally, some of these tools support spec-driven development and generate artifacts such as product requirement documents (PRDs), data models, and testing capabilities.</p>



<p class="wp-block-paragraph">Before commissioning AI development for apps and agents, CIOs should sponsor proofs of technical, data, modeling, security, and governance capabilities.</p>



<h2 class="wp-block-heading">The context layer powering AI agents</h2>



<p class="wp-block-paragraph">Between AI agents and the enterprise’s intelligence, including structured data sources, defined business processes, and agent interactions (both human-to-agent and agent-to-agent), lies an evolving “context layer.”</p>



<p class="wp-block-paragraph">This layer refers to the enterprise knowledge that AI agents draw on when evaluating signals and recommending or taking actions. Context may include a knowledge graph, a semantic layer, cleansed document repositories, and other knowledge bases.</p>



<p class="wp-block-paragraph">The context layer, skills, tools, out-of-the-box agents, and governance capabilities are some areas to review where solution providers differentiate. Some examples: </p>



<ul class="wp-block-list">
<li>Many support the <a href="https://open-semantic-interchange.org/">Open Semantic Interchange</a>, and some brand their context layers, such as the <a href="https://www.atlassian.com/platform/teamwork-graph">Atlassian Teamwork Graph</a>, <a href="https://boomi.com/knowledge-hub-early-access/">Boomi Knowledge Hub</a>, and the <a href="https://www.sap.com/products/artificial-intelligence/knowledge-graph.html">SAP Knowledge Graph</a>.</li>



<li>Some are branding their guardrails, such as <a href="https://business.adobe.com/products/brand-intelligence.html">Adobe’s AI Brand Intelligence</a>, <a href="https://appian.com/products/platform/artificial-intelligence">Appian’s Private AI</a>, and <a href="https://www.quickbase.com/intelligence-pack/ai-control-center">Quickbase AI Control Center</a>.</li>



<li>To manage AI agents at scale, some are extending the notion of data catalogs and other governance tools to the AI domain with products such as <a href="https://boomi.com/platform/connect/">Boomi Connect</a>, <a href="https://www.sap.com/products/artificial-intelligence/ai-agent-hub.html">SAP AI Agent Hub</a>, and <a href="https://www.snowflake.com/en/product/features/horizon/">Snowflake Horizon Catalog</a>.</li>
</ul>



<p class="wp-block-paragraph">CIOs should recognize that while solution providers will compete on capabilities, the real “secret sauce” of the context layer lies in the company’s trusted data, well-defined business processes, and employee adoption of AI agents.</p>



<h2 class="wp-block-heading">Conversational user experiences and coworkers</h2>



<p class="wp-block-paragraph">AI agents use the context layer, but also tap into skills, which encode the procedures they can follow, and tools, which prescribe the actions they can take. Before AI agents are ready to pilot, their governance, including permissions, approval gates, and other guardrails, must be defined. Other capabilities to look for when defining AI agents include orchestration, testing evals, and observability.</p>



<p class="wp-block-paragraph">In 2025, many solution providers bolted on AI agents to their existing user experiences. This year, many solution providers showcased new conversational user experiences that employees can use instead of traditional ones built with forms, flows, reports, and static dashboards. Conversational user experiences are where AI agents and people come together, whether it’s human-in-the-middle or human augmentation.</p>



<p class="wp-block-paragraph">Solution providers also grouped their AI agents into assistants or coworkers. For example, <a href="https://business.adobe.com/products/cx-enterprise-coworker.html">Adobe CX Coworker</a> illustrates human augmentation, helping marketers manage campaigns with prompts and monitor their performance. SAP launched <a href="https://www.sap.com/products/artificial-intelligence/ai-assistant.html">Joule Assistants</a> across several business functions, including finance, human capital, supply chain, and customer experience. Other assistants, such as <a href="https://docs.appian.com/suite/help/26.5/appian-ai-copilot.html">Appian AI Copilot</a>, <a href="https://www.atlassian.com/software/rovo">Atlassian Rovo</a>, <a href="https://www.cisco.com/site/us/en/solutions/artificial-intelligence/ai-assistant/index.html">Cisco AI Assistant</a>, <a href="https://www.nutanix.com/blog/nutanix-intelligent-virtual-agent">Nutanix NIVA</a>, and <a href="https://www.snowflake.com/en/product/snowflake-cowork/">Snowflake CoWork</a>, offer AI-first user experiences to assist different end-user types.</p>



<p class="wp-block-paragraph">CIOs should demo these <a href="https://www.infoworld.com/article/4178415/what-will-ai-first-ux-look-like.html">AI-first user experiences</a> to glimpse the future of work.</p>



<p class="wp-block-paragraph">Developers are already getting used to these experiences through code generators and vibe coding tools. Now, similar capabilities are being tailored across all business functions. CIOs should ramp up their <a href="https://www.cio.com/article/4082282/preparing-your-workforce-for-ai-agents-a-change-management-guide.html">change management programs</a> to accelerate the adoption of these AI capabilities.</p>



<p class="wp-block-paragraph">Solution providers are showcasing AI capabilities that can help CIOs <a href="https://drive.starcio.com/2026/04/ai-reshaping-business-not-digital-transformation-yet/">reshape their businesses</a>. But in Q2, there were only a few examples of how AI can help CIOs drive growth, evolve business models, or embed AI into customer-facing products. I expect to see a wave of further AI innovations that will go beyond productivity improvements and efficiencies and help CIOs pursue <a href="https://drive.starcio.com/2025/02/cios-drive-genai-digital-transformation/">growth-driving digital transformation strategies</a>.  </p>



<p class="wp-block-paragraph"><em>Sacolick travelled to conferences mentioned in this article as a guest of Adobe, Appian, Atlassian, Domo, Nutanix, SAP, and Snowflake. In addition, he was hired by Quickbase to speak at its conference.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Deluxe Corporation beats the odds with mainframe migration using AI]]></title>
<description><![CDATA[Deluxe may have prevailed against the odds when it successfully migrated from a 50-plus-year-old mainframe recently.



The company was able to move from it to a cloud environment in about 12 months without a major hitch, and while AI did some of the heavy lifting. The save will amount to about $...]]></description>
<link>https://tsecurity.de/de/3667450/it-nachrichten/deluxe-corporation-beats-the-odds-with-mainframe-migration-using-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667450/it-nachrichten/deluxe-corporation-beats-the-odds-with-mainframe-migration-using-ai/</guid>
<pubDate>Tue, 14 Jul 2026 11:32:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Deluxe may have prevailed against the odds when it successfully migrated from a 50-plus-year-old mainframe recently.</p>



<p class="wp-block-paragraph">The company was able to move from it to a cloud environment in about 12 months without a major hitch, and while AI did some of the heavy lifting. The save will amount to about $4.9 million a year by retiring old hardware and software, cutting labor costs, and consolidating IT resources.</p>



<p class="wp-block-paragraph">Deluxe, based in Minneapolis and traditionally known as a check printer, has transformed itself into a payments IT provider in recent years. But it desperately needed to end its reliance on its ancient mainframe, says <a href="https://www.linkedin.com/in/yogaraj/">Yogaraj Jayaprakasam</a>, the company’s chief technology and digital officer, pictured.</p>



<p class="wp-block-paragraph">So AI played a huge role in the IT modernization project, he says, using it to rewrite the old mainframe code, generate documentation, and regenerate code test cases. The company also used an AI-powered test automation suite, as well as AI tools to help move assets to the new cloud environment.</p>



<p class="wp-block-paragraph">While AI can’t do everything during mainframe migration, it can make the move easier, Jayaprakasam says. “The biggest lessons learned is AI is one of the missing tools in your transformation tool set,” he adds.</p>



<h2 class="wp-block-heading">Failing projects</h2>



<p class="wp-block-paragraph">Deluxe’s mainframe migration earned it a <a href="https://www.cio.com/article/220017/us-cio-100-winners-celebrating-it-innovation-and-leadership.html">2026 CIO 100 Award</a> for IT innovation and leadership, but it also seems to have bucked a recent trend. Many mainframe migration projects haven’t gone as planned, and <a href="https://www.gartner.com/en/newsroom/press-releases/2026-06-18-gartner-predicts-more-than-70-percent-of-mainframe-exit-projects-will-fail-due-to-overestimation-of-generative-ais-capabilities">Gartner recently predicted</a> that more than 70% of mainframe exit projects that started in 2026 will fail to produce intended benefits because of an overreliance on gen AI.</p>



<p class="wp-block-paragraph">Mainframe transformation projects tend to work better when they’re part of a larger business transformation rather than a one-off project using gen AI to do most of the work, says Gartner analyst <a href="https://www.gartner.com/en/experts/alessandro-galimberti">Alessandro Galimberti</a>.</p>



<p class="wp-block-paragraph">“Generative AI and agentic AI are extremely powerful, but they also have their own limits,” he says. “With all these kinds of tools trying to convert code or somehow fit into a non-mainframe workload, we don’t really see a track record of success.”</p>



<p class="wp-block-paragraph">Gartner also sees a declining interest in mainframe migration projects, Galimberti says. With mainframes getting support from several IT vendors, and with a general lack of migration success, many companies are choosing to keep many workloads on their existing big iron.</p>



<p class="wp-block-paragraph">But mainframes also have a proven track record of very high uptime and backward capability, Galimberti says.</p>



<p class="wp-block-paragraph">“If I’m a bank, a financial institution, or a transportation company, I need to run applications that are the core of my business,” he adds. “I need reliability, transactional integrity, and security, and these applications have a low change rate over the years because they map very stable business processes.”</p>



<p class="wp-block-paragraph">The Gartner prediction makes sense to <a href="https://www.linkedin.com/in/john-mckenny-994446/">John McKenny</a>, senior VP and GM of Intelligent Z optimization and transformation for mainframe support vendor BMC Software.</p>



<p class="wp-block-paragraph">“With organizations thinking about mainframe exits, the expected benefits they’re looking for are usually pretty straightforward,” he says. “They think, ‘It’s going to be lower cost, I’m going to get equal or better capabilities, I should be more agile.’  The reality is those outcomes rarely show up at scale.”</p>



<p class="wp-block-paragraph">Mainframe migration is possible, but the successful projects tend to be small scale, McKenny adds. He was on a recent call about a failed migration project in Europe, with a large bank cancelling the project at the end of 2025 and recommitting to the mainframe as a strategic platform.</p>



<p class="wp-block-paragraph">“I’ve never seen a large-scale mainframe migration project finish under budget, ever,” he says. “Most of the projects I hear about fail outright.”</p>



<h2 class="wp-block-heading">Trying again</h2>



<p class="wp-block-paragraph">Like some organizations that Gartner has observed, Deluxe tried to move away from its mainframe several years ago, but the project failed, Jayaprakasam says. Yet the company took the steps it needed this time to ensure the new migration succeeded.</p>



<p class="wp-block-paragraph">While a mainframe migration isn’t for every organization, the latest move made sense for Deluxe, he says.</p>



<p class="wp-block-paragraph">The mainframe, after all, was the backbone for a large portion of the company’s annual revenue, and interfaces with several top banks across North America. The modernization effort rebuilt core business processes and data, moving them from the mainframe to a modern cloud-native technology stack, including Salesforce, Mulesoft, and SAP S4/HANA.</p>



<p class="wp-block-paragraph">While AI played a big part, there’s danger in overestimating the power of AI during a migration project, Jayaprakasam says, and organizations need to follow best practices for IT migration.</p>



<p class="wp-block-paragraph">“If you minimize the importance of communication, risk planning, and business alignment because you have AI, you tend to fail,” he says. “But as long as you play all those cards and recognize AI was the missing piece to the puzzle, then you have a much better chance of winning.”</p>



<p class="wp-block-paragraph">Deluxe also used a cross-functional tiger team to look at the various options available to accelerate reverse engineering, including AI tools from OpenAI, Anthropic, as well as GitHub Copilot throughout the project.</p>



<p class="wp-block-paragraph">In addition, AI was useful to dig through the mainframe code and understand what needed to be updated, Jayaprakasam says. Organizations sitting on decades-old code often no longer have people who understand it.</p>



<p class="wp-block-paragraph">“I always tell people that the code remembers what the organization forgot, because with people going and changing, people don’t remember what we wrote in the code, but the code remembers,” he adds. “The amazing tool that was missing before is we didn’t have an interpreter who understood what the code remembered. Now with AI, you have the interpreter.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meet Blume: An Open-Source, Zero-Config Documentation Framework That Ships AI-Ready Docs From a Markdown Folder]]></title>
<description><![CDATA[Developer Hayden Bleasel has released Blume, an open-source, MIT-licensed documentation framework. It reads a folder of Markdown or MDX and generates a hidden Astro project, shipping static, AI-ready docs with local search, 30+ MDX components, llms.txt, and a built-in MCP server.
The post Meet Bl...]]></description>
<link>https://tsecurity.de/de/3667266/ai-nachrichten/meet-blume-an-open-source-zero-config-documentation-framework-that-ships-ai-ready-docs-from-a-markdown-folder/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667266/ai-nachrichten/meet-blume-an-open-source-zero-config-documentation-framework-that-ships-ai-ready-docs-from-a-markdown-folder/</guid>
<pubDate>Tue, 14 Jul 2026 10:19:26 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Developer Hayden Bleasel has released Blume, an open-source, MIT-licensed documentation framework. It reads a folder of Markdown or MDX and generates a hidden Astro project, shipping static, AI-ready docs with local search, 30+ MDX components, llms.txt, and a built-in MCP server.</p>
<p>The post <a href="https://www.marktechpost.com/2026/07/14/meet-blume-an-open-source-zero-config-documentation-framework-that-ships-ai-ready-docs-from-a-markdown-folder/">Meet Blume: An Open-Source, Zero-Config Documentation Framework That Ships AI-Ready Docs From a Markdown Folder</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Soon, iOS 26.6 Will Warn You About Malicious iMessages On iPhone]]></title>
<description><![CDATA[It looks like Apple is stepping up its fight against sophisticated text-based attacks in its next software update. If you use a smartphone from the company, you should know that iOS 26.6 will warn you about malicious iMessages. This upcoming security feature aims to flag potentially dangerous tex...]]></description>
<link>https://tsecurity.de/de/3667246/ios-mac-os/soon-ios-266-will-warn-you-about-malicious-imessages-on-iphone/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667246/ios-mac-os/soon-ios-266-will-warn-you-about-malicious-imessages-on-iphone/</guid>
<pubDate>Tue, 14 Jul 2026 10:06:51 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It looks like Apple is stepping up its fight against sophisticated text-based attacks in its next software update. If you use a smartphone from the company, you should know that iOS 26.6 will warn you about malicious iMessages. This upcoming security feature aims to flag potentially dangerous texts before they can compromise your privacy or harm your device.



It represents another critical layer of defense for anyone worried about targeted phishing attempts or zero-click exploits.



How iOS 26.6 will warn you about malicious iMessages



Code found inside the recent iOS 26.6 beta 5 reveals exactly how this security tool functions. If the system detects a suspicious text, it triggers a screen notification indicating the message might be trying to harm your device.



From there, you get three simple choices to deal with the threat. You can select “Not Now,” “Share With Apple,” or “Don't Report.” If you decide to share the data, it helps the company study the exploit to tighten its own security for the broader iOS 26 ecosystem. Choosing “Not Now” simply pushes the prompt away to reappear later.



While this is a smart defense mechanism for your iPhone, there is a slight downside to how it looks. Early mockups show the alert appears surprisingly similar to the fake antivirus pop-ups that often clutter Safari web pages.



This visual overlap might cause some people to dismiss the real warning entirely. The public update should arrive by the end of July, so it is best to stay cautious with unknown links until the official release drops.]]></content:encoded>
</item>
<item>
<title><![CDATA[Load Balancing in vSphere 9.0 and VMware Cloud Foundation 9.0]]></title>
<description><![CDATA[If you’re managing Kubernetes alongside traditional virtual machines, vSphere Supervisor in vSphere 9.0 and VMware Cloud Foundation (VCF) 9.0 serves as your unified control plane. But when it comes to setting up the infrastructure, one question always comes up from teams designing these environme...]]></description>
<link>https://tsecurity.de/de/3666562/downloads/load-balancing-in-vsphere-90-and-vmware-cloud-foundation-90/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666562/downloads/load-balancing-in-vsphere-90-and-vmware-cloud-foundation-90/</guid>
<pubDate>Tue, 14 Jul 2026 01:01:36 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><img width="300" height="154" src="https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/07/Networking-DataCenter.jpeg?w=300" class="attachment-medium size-medium wp-post-image" alt="" decoding="async" srcset="https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/07/Networking-DataCenter.jpeg 441w, https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/07/Networking-DataCenter.jpeg?resize=300,154 300w" sizes="(max-width: 300px) 100vw, 300px"></div>
<p>If you’re managing Kubernetes alongside traditional virtual machines, vSphere Supervisor in vSphere 9.0 and VMware Cloud Foundation (VCF) 9.0 serves as your unified control plane. But when it comes to setting up the infrastructure, one question always comes up from teams designing these environments:  “Which load balancers are supported, and how do I choose the … <a href="https://blogs.vmware.com/cloud-foundation/2026/07/13/choosing-the-right-load-balancer-for-vsphere-supervisor-in-vsphere-9-0-and-vmware-cloud-foundation-9-0/">Continued</a></p>
<p>The post <a href="https://blogs.vmware.com/cloud-foundation/2026/07/13/choosing-the-right-load-balancer-for-vsphere-supervisor-in-vsphere-9-0-and-vmware-cloud-foundation-9-0/">Load Balancing in vSphere 9.0 and VMware Cloud Foundation 9.0</a> appeared first on <a href="https://blogs.vmware.com/cloud-foundation">VMware Cloud Foundation (VCF) Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[America May Soon Be Facing Largest Labor Shortage in Its History]]></title>
<description><![CDATA[America "is facing what's projected to become the largest labor shortage in its history," according to experts interviewed by the Washington Post:



Economists warn that the worsening labor problem, due in part to a skills shortage and population shifts, will be vast and reach beyond tech. It "c...]]></description>
<link>https://tsecurity.de/de/3666243/it-security-nachrichten/america-may-soon-be-facing-largest-labor-shortage-in-its-history/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666243/it-security-nachrichten/america-may-soon-be-facing-largest-labor-shortage-in-its-history/</guid>
<pubDate>Mon, 13 Jul 2026 21:23:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[America "is facing what's projected to become the largest labor shortage in its history," according to experts interviewed by the Washington Post:



Economists warn that the worsening labor problem, due in part to a skills shortage and population shifts, will be vast and reach beyond tech. It "could hobble the American economy for years to come," predicts the Georgetown University Center on Education and the Workforce. Lightcast, a labor market data company, calls it "the largest labor shortage the country has ever seen." JPMorgan Chase warns of a national security risk from "a pervasive talent deficit that constrains the nation's capacity to build, compete, and protect its interests." There will be shortages in the tens or even hundreds of thousands of nurses, physicians, teachers, engineers, pharmacists, mental health counselors, construction worker and airplane mechanics — jobs AI generally can't do... 

Among the trends that have been leading to this moment: a mismatch between the careers college graduates are pursuing and the jobs employers are struggling to fill. Far fewer students are majoring in health care fields than are needed to meet demand, for instance. "We have pumped so many young people into business and finance" when what's really in demand are graduates in other fields, [said Ron Hetrick, Lightcast's principal economist]. "It's like a factory producing these workers like widgets, even though society is saying, 'We really don't need them.' And the factory just keeps pumping them out." But the principal reason for the looming workforce shortages is much more basic. A protracted decline in birth rates is coinciding with a record wave of retirements, data shows. 

From 2024 to 2032, when the last baby boomers sign up for Social Security payments, more than 18 million college-educated workers will leave the labor force while fewer than 14 million enter it, according to the Georgetown center. Meanwhile, even as the number of people with associate and bachelor's degrees falls, the number of jobs requiring them will grow, the center forecasts. That will leave a gap of 4.6 million workers. Lightcast puts the deficit at an even higher 6 million... The effect of population shifts on the supply of talent, with or without degrees, has been compounded by a drop in the proportion of high school graduates choosing to go to college, a sharply reduced rate of immigration, and a growing number of Americans leaving the workforce altogether because of such issues as lack of child care, early retirement, incarceration and substance addiction, according to the Chamber of Commerce.
 

Three interesting statistics from the article:

U.S. college/university enrollment in 2023 was down by nearly 2 million students since its peak in 2010, according to the most recent data from the U.S. Education Department.
America's low birth rate since 2010 "means the number of college-age Americans is forecast to decline by another 13 percent through 2041."
South Dakota has just 41 workers for every 100 open jobs... while California and nine other states have more workers than jobs, the Chamber of Commerce found.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=America+May+Soon+Be+Facing+Largest+Labor+Shortage+in+Its+History%3A+https%3A%2F%2Fit.slashdot.org%2Fstory%2F26%2F07%2F13%2F0443258%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fit.slashdot.org%2Fstory%2F26%2F07%2F13%2F0443258%2Famerica-may-soon-be-facing-largest-labor-shortage-in-its-history%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://it.slashdot.org/story/26/07/13/0443258/america-may-soon-be-facing-largest-labor-shortage-in-its-history?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What is generative AI? How artificial intelligence creates content]]></title>
<description><![CDATA[Generative AI is a kind of artificial intelligence that creates new content, including text, images, audio, and video, based on patterns it has learned from existing data.



Today’s generative models are typically built on foundation-model architectures such as large-language models (LLMs) and m...]]></description>
<link>https://tsecurity.de/de/3665675/ai-nachrichten/what-is-generative-ai-how-artificial-intelligence-creates-content/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665675/ai-nachrichten/what-is-generative-ai-how-artificial-intelligence-creates-content/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:40 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Generative AI is a kind of <a href="https://www.computerworld.com/article/1647870/what-is-artificial-intelligence.html">artificial intelligence</a> that creates new content, including text, images, audio, and video, based on patterns it has learned from existing data.</p>



<p class="wp-block-paragraph">Today’s generative models are typically built on foundation-model architectures such as <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">large-language models (LLMs)</a> and multimodal systems, enabling them to carry on conversations, answer questions, write stories, generate code, and produce images or videos from brief prompts.</p>



<p class="wp-block-paragraph"><em>Generative AI</em> is different from <em>discriminative AI</em>, which draws distinctions between different kinds of input. Where discriminative AI answers questions like “Is this image of a rabbit or a lion?”, generative AI instead responds to prompts such as “Describe to me how a rabbit and lion look different from one another” or “Draw me a picture of a lion and a rabbit sitting next to each other” — and in both cases produces text or imagery that, while grounded in the AI’s training data, isn’t just a copy of something that already existed.</p>



<aside class="fakesidebar">
<h4>[ <u><a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">Read next: Large language models: The foundations of generative AI</a></u> ]</h4>
</aside>




<p class="wp-block-paragraph">Just a few years ago, generative AI was once a novelty focused on chatbots and artistic image generation. Today, it has become a core enterprise technology, and powers everything from content creation and software development to customer support and analytics workflows. But with that power comes a <a href="https://www.csoonline.com/article/4076511/4-factors-creating-bottlenecks-for-enterprise-genai-adoption.html">new set of challenges</a> — from model alignment and hallucination to governance and data-integration hurdles.</p>



<p class="wp-block-paragraph">In this article, we’ll look at how generative AI works, explore how it has evolved into the foundation-model era, examine how to implement it effectively, and offer best practices for getting value out of it, today and in the future.</p>



<h2 class="wp-block-heading"><strong>How does generative AI work?</strong></h2>



<p class="wp-block-paragraph">For decades, early artificial-intelligence efforts often focused on rule-based systems or <a href="https://www.infoworld.com/article/4061121/a-brief-history-of-ai.html">narrowly trained models</a> that were built for one task at a time. While these efforts produced useful systems that could reason and solve human tasks, they were generally a far cry from sci-fi visions of thinking machines. Programs that could talk to people never seemed to get very far past the level of <a href="https://en.wikipedia.org/wiki/ELIZA">ELIZA</a>, a “computer therapist” created at MIT in the mid 1960s; even Siri and Alexa after much fanfare were revealed to be fairly limited.</p>



<p class="wp-block-paragraph">The big structural shift that gave birth to modern generative AI came with the concept of a <em>transformer, </em>first introduced in “<a href="https://arxiv.org/abs/1706.03762">Attention Is All You Need</a>,” a 2017 paper from Google researchers.</p>



<p class="wp-block-paragraph">Using a transformer architecture as a basis, you can build a system that derives meaning from analyzing long sequences of input <em>tokens</em> (words, sub-words, bytes) to understand how different tokens might be related to one another, then determines how likely any given token is to come next in a sequence, given the others. In AI lingo, we call these systems <em>models.</em> Because a model analyzes very large datasets and parameter counts, it can pick up on statistical patterns and knowledge implicitly embedded in the data.</p>



<p class="wp-block-paragraph">This is all easier said than done. The process of adjusting a model’s internal parameters so it gets better at predicting the next token in sequences is called <em>training</em>. During training, the model repeatedly guesses the next token in a given sequence, compares its prediction to the actual one, measures the error, and updates its parameters to reduce that error across billions of examples. Over time, that process teaches the model the statistical relationships that will allow it to generate coherent language (or code, or images) later.</p>



<h2 class="wp-block-heading"><strong>What is a foundation model?</strong></h2>



<p class="wp-block-paragraph">You’ll often hear the word <em>large</em> used for transformer-based models of these types, like the LLMs we mentioned earlier. <em>Large</em> in this context refers to the large number of internal numerical values that the model adjusts during training to represent what it has learned, along with breadth and diversity of data used to train the model and the underlying compute resources powering this whole process.</p>



<p class="wp-block-paragraph">This is in contrast with the narrow models of the earlier era of AI/ML, which werebuilt for one purpose and trained on a limited dataset. For instance, a spam filter may be very good at what it does, but it’s only trained on email data and all it can do is classify emails. Large models, by contrast, serve as what’s known as <em>foundation models</em>. They’re trained broadly on diverse data (text, code, images, or multimodal data) and then adapted or specialized for many downstream tasks.</p>



<p class="wp-block-paragraph">These foundation models are the basis for most of the popular generative AI tools and services on the market today. They can be specialized in several ways:</p>



<ul class="wp-block-list">
<li><strong>Fine-tuning:</strong> Giving a foundation model further training on a smaller, task-specific dataset</li>



<li><strong>Retrieval-augmented generation</strong> <strong>(RAG):</strong> Giving the model the ability to pull in external knowledge when asked a question</li>



<li> <strong>Prompt engineering</strong>: Tailoring a query so the model gives the sort of answers you’re looking for.</li>
</ul>



<h2 class="wp-block-heading"><strong>How do AI systems write computer code?</strong></h2>



<p class="wp-block-paragraph">One of the surprising discoveries of the gen AI era was that in recent years was that foundation models trained on natural-language text can also, when fine-tuned with code examples, also write computer code — often better than many purpose-built systems. Still, it makes sense, when you think about it — after all, high-level computer languages are designed by humans and ultimately based on human language.</p>



<p class="wp-block-paragraph">This <a href="https://www.infoworld.com/article/2338500/llms-and-the-rise-of-the-ai-code-generators.html?utm_source=chatgpt.com">2023 InfoWorld article</a> highlights how models like PaLM, LLaMA and other transformer-based systems fine-tuned on code repositories propelled this shift, but since AI giants like <a href="https://www.computerworld.com/article/3843138/agentic-ai-ongoing-coverage-of-its-impact-on-the-enterprise.html">OpenAI</a> have moved into this space. This all matters because code generation (or code-assisted productivity) has become a key enterprise use case of generative AI — perhaps <em>the </em>key use, given the industry’s enthusiastic adoption of it.</p>



<h2 class="wp-block-heading"><strong>What are AI agents?</strong></h2>



<p class="wp-block-paragraph">So far, we’ve been talking about chatbots, writing assistants, image-generation tools. They respond to prompts, output text or images, and then stop. A new category of tool called <em><a href="https://www.computerworld.com/article/3843138/agentic-ai-ongoing-coverage-of-its-impact-on-the-enterprise.html">agentic AI</a></em> goes further: it <em>plans</em>, <em>executes</em>, and in many cases <em>learns</em> as it works.</p>



<p class="wp-block-paragraph">Because large models already understand language, code, and even structured data to some extent, they can be repurposed to generate not only descriptive text but <em>operational instructions</em>. For example: an agent might parse the intent “generate a sales-report”, then format internal calls like getData(salesDB, region=NA, period=lastQuarter), and then call an API, all by generating text that’s interpreted as instructions. The <a href="https://www.infoworld.com/article/4064169/how-mcp-is-making-ai-agents-actually-do-things-in-the-real-world.html.">MCP framework</a> standardizes the “language” of those instructions and the plug-points into tools and data so that the model doesn’t need bespoke integrations for each new workflow.</p>



<p class="wp-block-paragraph">These kinds of autonomous agents have several enterprise use cases:</p>



<ul class="wp-block-list">
<li><strong>Software automation</strong>: Agents that generate code, call unit tests, deploy builds, monitor logs and even roll back changes autonomously.</li>



<li><strong>Customer support</strong>: Instead of simply drafting responses, agents interact with CRM APIs, update ticket statuses, escalate issues, and trigger follow-up workflows.</li>



<li><strong>IT operations/AIOps</strong>: Agents <a href="https://www.cio.com/article/222623/7-things-to-know-about-ai-in-the-data-center.html">monitor infrastructure, identify anomalies, open/close tickets, or auto-remediate</a> based on defined rules and context from logs.</li>



<li><strong>Security</strong>: Agents may detect threats, initiate alerts, isolate compromised systems, or even attempt to manage threat containment — though this raises new risks.</li>
</ul>



<h2 class="wp-block-heading"><strong>How can you implement generative AI in the enterprise?</strong></h2>



<p class="wp-block-paragraph">We’ve now touched on <em>what</em> generative AI can do. But <em>how</em> can you make it work reliably in your business. The difference between a pilot and full-scale deployment often comes down to systems, structure and governance as much as to models themselves. <em>InfoWorld’</em>s Matt Asay offers a <a href="https://www.infoworld.com/article/4044919/enterprise-essentials-for-generative-ai.html">deep dive into enterprise gen AI essentials</a>, but here are some important points to keep in mind:</p>



<p class="wp-block-paragraph"><strong>Choosing between API, open-source or custom fine-tuned models. </strong>One of the first major decisions for any enterprise project is: do you use a model via an API (e.g., from a vendor like OpenAI or Anthropic), deploy an open-source model internally, or build/fine-tune a custom model yourself? Each has trade-offs.</p>



<p class="wp-block-paragraph">APIs offer speed and minimal setup, but may expose data, limit customization or accrue high cost — and will leave you at the mercy of your vendor. Open source allows internal control and may ease fine-tuning, but requires infrastructure, expertise, and support. Custom fine-tuning gives you the tightest alignment to your use-case, but lengthens time to value and increases risk.</p>



<p class="wp-block-paragraph"><strong>Governance, data privacy and compliance. </strong>Deploying generative AI in an enterprise setting raises new governance, privacy and regulatory issues. For example: Who owns the data that’s ingested? How is proprietary data protected if you call a third-party API? What traceability exists for model outputs—a huge question for regulated industries? One useful framework is covered in “A GRC framework for securing generative AI” Data governance <a href="https://www.infoworld.com/article/2336154/how-data-governance-must-evolve-to-meet-the-generative-ai-challenge.html">must adapt for the new era</a>,  and <a href="https://www.infoworld.com/article/3604732/a-grc-framework-for-securing-generative-ai.html">new frameworks are evolving to help</a>.</p>



<p class="wp-block-paragraph"><strong>Human-in-the-loop review. </strong>Even the best models make mistakes and cannot simply be put on autopilot. You need a <em>human-in-the-loop (HITL)</em> process: real people need to review outputs, validate for bias, approve high-stakes content, and tune prompts or models based on feedback. Incorporating HITL checkpoints helps mitigate risk and improve overall quality.</p>



<p class="wp-block-paragraph"><strong>Integration with existing systems and RAG pipelines. </strong><a href="https://www.infoworld.com/article/2337050/how-rag-completes-the-generative-ai-puzzle.html">Retrieval-augmented generation</a>, which we touched on earlier, connects foundation models into business workflows, systems, and enterprise data stores. RAG can bind LLMs to your organization’s internal knowledge bases, thereby reducing <em>hallucinations </em>(which we’ll discuss in a moment) and increasing the relevance of gen AI output.</p>



<aside class="sidebar">
<h3><strong> Implementation best practices for generative AI</strong></h3>
<p> Here are four AI best practices to keep in mind:</p>
<ol>
<li> Guardrails: Define clear operational boundaries. Examples: restrict sensitive data output, enforce access controls, log model interactions.</li>
<li> Prompt engineering: Because much of what the model will do depends on how it’s prompted, invest in prompt design, versioning, review, and testing.</li>
<li> Evaluation metrics: Define appropriate KPIs (accuracy, latency, cost, business outcome), monitor them and iterate.</li>
<li> Model observability: Treat generative-AI systems like software — monitor performance, detect drift, handle failures gracefully, audit outputs and maintain traceability.</li>
</ol>
</aside>




<h2 class="wp-block-heading"><strong>What causes AI hallucinations?</strong></h2>



<p class="wp-block-paragraph">Probably the biggest limitation of generative AI is what those in the industry call <em>hallucinations</em>, which is a perhaps misleading term for output that is, by the standards of humans who use it, false or incorrect.  </p>



<p class="wp-block-paragraph">Every generative AI system, no matter how advanced, is built around prediction. Remember, a model doesn’t truly <em>know</em> facts—it looks at a series of tokens, then calculates, based on analysis of its underlying training data, what token is most likely to come next. This is what makes the output fluent and human-like, but if its prediction is wrong, that will be perceived as a hallucination.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/10/GenAI_takeaways.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Table describing five key points about generatvie AI" class="wp-image-4082262" width="1024" height="648" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Generative AI, foundation models, agentic AI, governance, and implementation strategy top the list of top generative AI takeaways.</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p class="wp-block-paragraph">Because the model doesn’t distinguish between something that’s known to be true and something likely to follow on from the input text it’s been given, hallucinations are a direct side effect of the statistical process that powers generative AI. And don’t forget that we’re often pushing AI models to come up with answers to questions that we, who also have access to that data, can’t answer ourselves.</p>



<p class="wp-block-paragraph">In text models, hallucinations might mean inventing quotes, fabricating references, or misrepresenting a technical process. In code or data analysis, it can produce <a href="https://www.infoworld.com/article/3822251/how-to-keep-ai-hallucinations-out-of-your-code.html">syntactically correct but logically wrong results</a>. Even RAG pipelines, which provide real data context to models, only <em>reduce</em> hallucination—they don’t eliminate it. Enterprises using generative AI need <a href="https://www.cio.com/article/4073606/reducing-llm-hallucinations-in-enterprise-systems.html">review layers, validation pipelines, and human oversight</a> to prevent these failures from spreading into production systems.</p>



<h2 class="wp-block-heading"><strong>What are some other problems with generative AI?</strong></h2>



<p class="wp-block-paragraph">Generative AI has proven to be such a disruptive technology that’s stoking near-apocalyptic fears that it will result in a superintelligence that will enslave or destroy humanity. Meanwhile, in the present day, increasingly troubling reports of so-called <a href="https://www.psychologytoday.com/us/blog/urban-survival/202507/the-emerging-problem-of-ai-psychosis">AI psychosis</a> are emerging, where people have mental health episodes triggered by the uncanny and sometimes sycophantic ways chatbots affirm whatever you talk to them about and try to keep the conversation going.</p>



<p class="wp-block-paragraph">Compared to such existential questions, the following business-related problems may seem petty. But they’re real issues for enterprises considering investing in AI tools.</p>



<ul class="wp-block-list">
<li><strong>Data leakage and regulatory risk. </strong>When a model is fine-tuned or prompted with sensitive information, that data may be memorized and unintentionally reproduced. Using <a href="https://www.csoonline.com/article/3819170/nearly-10-of-employee-gen-ai-prompts-include-sensitive-data.html">third-party APIs without strict controls</a> can expose proprietary or personally identifiable information (PII). Regulatory frameworks like GDPR and HIPAA require explicit governance around where training data resides and how inference results are stored.</li>



<li><strong>Prompt injection </strong>occurs when an attacker manipulates a model’s instructions—embedding hidden directives or malicious payloads in user input or external content the model reads. This can override safety rules, expose internal data, or execute unintended actions in agentic systems. Guardrails that sanitize inputs, restrict tool-calling permissions, and validate outputs are becoming essential.</li>



<li><strong>Copyright and content ownership. </strong>Many foundation models are trained on data scraped from the public internet, creating disputes over copyright and data provenance. Enterprises using generated output commercially need to confirm usage rights and review indemnity terms from vendors.</li>



<li><strong>Unrealistic productivity expectations. </strong>Finally, organizations sometimes expect generative AI to deliver instant productivity gains. The reality, it turns out, is more <a href="https://leaddev.com/velocity/ai-doesnt-make-devs-as-productive-as-they-think-study-finds">mixed</a>. Enterprise adoption requires infrastructure, governance, retraining, and cultural change. The models accelerate work once properly integrated, but they don’t automatically replace human judgment or oversight.</li>
</ul>



<p class="wp-block-paragraph">The current generation of enterprise AI systems includes several layers of defense against these risks:</p>



<ul class="wp-block-list">
<li><em>Guardrails</em> that constrain model behavior and filter unsafe outputs.</li>



<li><em>Model validation</em> frameworks that measure factual accuracy and consistency before deployment.</li>



<li><em>Policy layers</em> that enforce compliance rules, redact sensitive data, and log model actions.</li>
</ul>



<p class="wp-block-paragraph">These safeguards reduce—but don’t remove—the inherent uncertainty that defines generative AI.</p>



<h2 class="wp-block-heading"><strong>GenAI: essential for the enterprise</strong></h2>



<p class="wp-block-paragraph">Generative AI has evolved from a novelty into a core layer of enterprise technology. Foundation models and agentic systems now power automation, analytics, and creative workflows — but they remain fundamentally probabilistic tools. Their strength lies in scale and adaptability, not perfect understanding.</p>



<p class="wp-block-paragraph">For organizations, success depends less on chasing model breakthroughs than on integrating these systems responsibly: building guardrails, maintaining oversight, and aligning them with real business needs. Used wisely, generative AI can amplify human capability rather than replace it.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Get started with Angular: Introducing the modern reactive workflow]]></title>
<description><![CDATA[Angular is a cohesive, all-in-one reactive framework for web development. It is one of the larger reactive frameworks, focused on being a single architectural system that handles all your web development needs under one idiom. While Angular was long criticized for being heavyweight as compared to...]]></description>
<link>https://tsecurity.de/de/3665664/ai-nachrichten/get-started-with-angular-introducing-the-modern-reactive-workflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665664/ai-nachrichten/get-started-with-angular-introducing-the-modern-reactive-workflow/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:25 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Angular is a cohesive, all-in-one <a href="https://www.infoworld.com/article/3962039/what-you-need-to-know-about-angular-react-vue-and-svelte-popular-javascript-frameworks-compared.html">reactive framework</a> for web development. It is one of the larger reactive frameworks, focused on being a single architectural system that handles all your web development needs under one idiom. While Angular was long criticized for being heavyweight as compared to <a href="https://www.infoworld.com/article/2253289/react-tutorial-get-started-with-the-reactjs-javascript-library.html">React</a>, many of those issues <a href="https://www.infoworld.com/article/3964105/catching-up-with-angular-19.html">were addressed in Angular 19</a>. Modern Angular is built around the <a href="https://blog.angular-university.io/angular-signals">Signals API</a> and minimal formality, while still delivering a one-stop-shop that includes dependency injection and integrated routing.</p>



<p class="wp-block-paragraph">Angular is popular with the enterprise because of its stable, curated nature, but it is becoming more attractive to the wider developer community thanks to its more <a href="https://www.infoworld.com/article/3802707/angular-team-unveils-strategy-for-2025.html">community engaged development philosophy</a>. That, along with its recent technical evolution, make Angular one of the most interesting projects to watch right now.</p>



<h2 class="wp-block-heading">Why choose Angular?</h2>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/2336227/whats-the-best-javascript-framework.html">Choosing a JavaScript development framework</a> sometimes feels like a philosophical debate, but it should be a practical decision. Angular is unique because it is strongly opinionated. It doesn’t just give you a view layer; it provides a complete toolkit for building web applications.</p>



<p class="wp-block-paragraph">Like other reactive frameworks, Angular is built around its reactive engine, which lets you bind state (variables) to the view. But if that’s all you needed, one of the smaller, more focused frameworks would be more than enough. What Angular has that some of these other frameworks don’t is its ability to use data binding to automatically synchronize data from your user interface (UI) with your JavaScript objects. Angular also leverages dependency injection and inversion of control to help structure your application and make it easier to test. And it contains more advanced features like server-side rendering (SSR) and static-site generation (SSG) within itself, rather than requiring you to engage a <a href="https://www.infoworld.com/article/3831686/plug-and-play-web-development-with-astro-js.html">meta-framework</a> for either style of development.</p>



<p class="wp-block-paragraph">While Angular might not be your top choice for every occasion, it’s an excellent option for larger projects that require features you won’t get with a more lightweight framework.</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/3964105/catching-up-with-angular-19.html" data-type="link" data-id="https://www.infoworld.com/article/3964105/catching-up-with-angular-19.html">Catching up with Angular 19</a>.</strong></p>



<h2 class="wp-block-heading">Getting started with Angular</h2>



<p class="wp-block-paragraph">With those concepts in mind, let’s set up Angular in your development environment. After that, we can run through developing a web application with Angular. To start, make sure you have Node and NPM installed. From the command line, enter:</p>



<pre class="wp-block-code"><code>$ node -v
$ npm -v</code></pre>



<p class="wp-block-paragraph">Next, you can use the Angular CLI to launch a new app:</p>



<pre class="wp-block-code"><code>$ ng new iw-ng</code></pre>



<p class="wp-block-paragraph">You can use the defaults in your responses to the interactive prompts shown here:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/01/angular1.png?w=1024" alt="A screenshot of a new project setup in the Angular command-line interface." class="wp-image-4123771" width="1024" height="413" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Matthew Tyson</p></div>



<p class="wp-block-paragraph">We now have a basic project layout in the new directory, which you can import into an IDE (such as <a href="https://www.infoworld.com/article/2254808/get-started-with-visual-studio-code.html" data-type="link" data-id="https://www.infoworld.com/article/2254808/get-started-with-visual-studio-code.html">VS Code</a>) or edit directly.</p>



<p class="wp-block-paragraph">Looking at the project layout, you might notice it is fairly lean, a break from Angular projects of the past. The most important parts are:</p>



<ul class="wp-block-list">
<li><code>src/main.ts</code>: This is the main entry point. In older versions of Angular, this file had to bootstrap a module, which then bootstrapped a component. Now, it avoids any verbose syntax, calling bootstrapApplication with your root component directly.</li>



<li><code>src/index.html</code>: The main HTML page that hosts your application. This is the standard index.html that serves all root requests in a web page and contains the  tag where your Angular component will render. It is the “body” that the “spirit” of your code animates.</li>



<li><code>src/app/app.ts</code>: The root component of your application. This single file defines the view logic and the component metadata. In the new “standalone” world, it manages its own imports, meaning you can see exactly what dependencies it uses right at the top of the file. (This is the <code></code> root element that appears in <code>src/index.html</code>.)</li>



<li><code>src/app/app.config.ts</code>: This file is new in modern Angular and replaces the old A<code>ppModule providers</code> array. It is where you configure global services, like the router or HTTP client.</li>



<li><code>angular.json</code>: The configuration file for the CLI itself. It tells the build tools how to process your code, though you will rarely need to touch this file manually anymore.</li>
</ul>



<p class="wp-block-paragraph">Here is the basic flow of how the engine renders these components:</p>



<ol start="1" class="wp-block-list">
<li><strong>The arrival (HTML)</strong>: The browser receives <code>index.html</code>. The <code></code> tag is there, but it’s empty.</li>



<li><strong>The unpacking (JavaScript)</strong>: The browser sees the <code></code> tags at the bottom of the HTML and downloads the JavaScript bundles (your compiled code) from <code>src/app/app.ts</code>.</li>



<li><strong>The assembly (Bootstrap)</strong>: The browser runs that JavaScript. The code “wakes up,” finds the <code></code> tag in the DOM, and dynamically inserts your title, buttons, and lists.</li>
</ol>



<p class="wp-block-paragraph">This flow will be different if you are using server-side rendering (SSR), but we’ll leave that option aside for now. Now that you’ve seen the basic architecture, let’s get into the code.</p>



<h2 class="wp-block-heading">Developing your first web app in Angular</h2>



<p class="wp-block-paragraph">If you open <code>src/app/app.ts</code> (more info <a href="http://app.ts/">here</a>) the component definition looks like this:</p>



<pre class="wp-block-code"><code>import { Component, signal } from '@angular/core';
import { RouterOutlet } from '@angular/router';

@Component({
  selector: 'app-root',
  imports: [RouterOutlet],
  templateUrl: './app.html',
  styleUrl: './app.css'
})
export class App {
  protected readonly title = signal('iw-ng');
}</code></pre>



<p class="wp-block-paragraph">Before we dissect the code, let’s run the app and see what it produces:</p>



<pre class="wp-block-code"><code>$ ng serve</code></pre>



<p class="wp-block-paragraph">You should see a page like this one at <code>localhost:4200</code>:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/01/angular2.png?w=1024" alt="A screenshot of a Hello, World! app built with Angular." class="wp-image-4123772" width="1024" height="585" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Matthew Tyson</p></div>



<p class="wp-block-paragraph">Returning to the <code>src/app.ts</code> component, notice that there are three main parts of the definition: the class, the metadata, and the view. Let’s unpack these separately.</p>



<h3 class="wp-block-heading">The class (export class App)</h3>



<p class="wp-block-paragraph">Export class <code>App</code> is vanilla TypeScript that holds your component’s data and logic. In our example, <code>title = signal(‘iw-ng’)</code> defines a piece of reactive state. Unlike older versions of Angular where data was just a plain property, here we use a <a href="https://www.solidjs.com/tutorial/introduction_signals">signal</a>. Signals are wrappers around values that notify the template precisely when they change, enabling fine-grained performance.</p>



<h3 class="wp-block-heading">The metadata (@Component)</h3>



<p class="wp-block-paragraph">The <code>@Component</code> decorator tells Angular it is dealing with a component, not just a generic class. There are several elements involved in the decorator’s communication with the engine:</p>



<ul class="wp-block-list">
<li><code>selector: 'app-root'</code>: Defines the custom HTML tag associated with any given component. Angular finds <code></code> in your <code>index.html</code> and renders the component there.</li>



<li><code>imports</code>: In the new Angular era, dependencies are explicit. You list exactly what a component needs (like <code>RouterOutlet</code> or other components) here, rather than hiding them in a separate module file.</li>



<li><code>templateUrl</code>: Points to the external HTML file that defines the view.</li>
</ul>



<h3 class="wp-block-heading">The view (the template)</h3>



<p class="wp-block-paragraph">This is the visual part of the component, defined in <code>app.html</code>. It combines standard HTML with Angular’s template syntax. (JSX handles this part for React-based apps.)</p>



<p class="wp-block-paragraph">We can modify <code>src/app/app.html</code> to see how these three elements work together. To start, delete the default content and add the following:</p>



<pre class="wp-block-code"><code><h1>Hello, {{ title() }}</h1>
</code></pre>



<p class="wp-block-paragraph">The double curly braces <code>{{ }}</code> are called <a href="https://angular.dev/guide/templates/binding">interpolation</a>. Notice the parentheses in <code>title()</code>. We are reading the “title” signal value by calling its function. If you were to update that signal programmatically (e.g., <code>this.title.set('New Value')</code>), the text on the screen would update instantly.</p>



<h2 class="wp-block-heading">Angular’s built-in control flow</h2>



<p class="wp-block-paragraph">Old-school Angular required “structural directives” like <code>*ngIf</code> and <code>*ngFor</code> logic control. These were powerful but required importing <code>CommonModule</code> and learning a specific micro-syntax. Modern Angular uses a built-in control flow that looks like standard JavaScript (similar to other Reactive platforms).</p>



<p class="wp-block-paragraph">To see the new control flow in action, let’s add a list to our component. Update <code>src/app/app.ts</code> as follows, leaving the rest of the file the same:</p>



<pre class="wp-block-code"><code>export class App {
  protected readonly title = signal('iw-ng');
  protected readonly frameworks = signal(['Angular', 'React', 'Vue', 'Svelte']);
  protected showList = signal(true);

  toggleList() {
    this.showList.update(v =&gt; !v);
  }
}</code></pre>



<p class="wp-block-paragraph">While we’re at it, let’s also update <code>src/app/app.html</code> to render this new list (don’t worry about <code></code> for now; it just tells Angular where to render the framing template):</p>



<pre class="wp-block-code"><code><button>Toggle List</button>

@if (showList()) {
  <ul>
    @for (tech of frameworks(); track tech) {
      <li>{{ tech }}</li>
    }
  </ul>
} @else {
  <p>List is hidden</p>
}

</code></pre>



<p class="wp-block-paragraph">The app will now display a list that can be toggled for visibility:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/01/angular3.png?w=1024" alt="Screenshot of a list that can be toggled on and off for visibility." class="wp-image-4123773" width="1024" height="585" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Matthew Tyson</p></div>



<p class="wp-block-paragraph">This syntax is cleaner and easier to read than the old <code>*ngFor</code> loops:</p>



<ul class="wp-block-list">
<li><code>@if</code> conditionally renders the block if the signal’s value is true.</li>



<li><code>@for</code> iterates over the array. The track keyword is required for performance (it tells Angular how to identify unique items in the list).</li>



<li><code>(click)</code> is an <a href="https://angular.dev/guide/templates/event-listeners">event binding</a>. It lets us run code (the <code>toggleList</code> method) when the user interacts with the button.</li>
</ul>



<h2 class="wp-block-heading">Services: Managing business logic in Angular</h2>



<p class="wp-block-paragraph">Components focus on the view (i.e., what you see). For the business logic that backs the application functionality, we use services.</p>



<p class="wp-block-paragraph">A service is just a class that can be “injected” into a component that needs it. This is Angular’s famous dependency injection system. It allows you to write logic once and reuse it anywhere. It’s a slightly different way of thinking about how an application is wired together, but it gives you real organizational benefits over time.</p>



<p class="wp-block-paragraph">To generate a service, you can use the CLI:</p>



<pre class="wp-block-code"><code>$ ng generate service frameworks</code></pre>



<p class="wp-block-paragraph">This command creates a <code>src/app/hero.ts</code> file. In modern Angular, we define services using the <code>@Injectable</code> decorator. Currently, the <code>src/app/hero.ts</code> file just has this:</p>



<pre class="wp-block-code"><code>import { Injectable } from '@angular/core';

@Injectable({
  providedIn: 'root',
})
export class Frameworks {
  
}</code></pre>



<p class="wp-block-paragraph">Open the file and add a simple method to return our data:</p>



<pre class="wp-block-code"><code>import { Injectable } from '@angular/core';

@Injectable({
  providedIn: 'root', // Available everywhere in the app
})
export class Frameworks {
  getList() {
    return ['Angular', 'React', 'Vue', 'Svelte'];
  }
}</code></pre>



<p class="wp-block-paragraph">The providedIn: <code>'root'</code> metadata is important, it tells Angular to create a single, shared instance of this service for the entire application (you might recognize this as an instance of the <a href="https://en.wikipedia.org/wiki/Singleton_pattern">singleton pattern</a>).</p>



<h3 class="wp-block-heading">Using the service</h3>



<p class="wp-block-paragraph">In the past, we had to list dependencies in the constructor. Modern Angular offers a cleaner way: the <code>inject()</code> function. Subsequently, we can refactor our <code>src/app/app.ts</code> to get its data from the service instead of hardcoding it:</p>



<pre class="wp-block-code"><code>import { Component, inject, signal } from '@angular/core';
import { RouterOutlet } from '@angular/router';
import { Frameworks } from './frameworks'; // Import the service

@Component({
  selector: 'app-root',
  imports: [RouterOutlet],
  templateUrl: './app.html',
  styleUrl: './app.css'
})
export class App {
  private frameworksService = inject(Frameworks); // Dependency Injection
  
  protected readonly title = signal('iw-ng');
  
  // Initialize signal with data directly from the service
  protected readonly frameworks = signal(this.frameworksService.getList());
  protected showList = signal(true);

  toggleList() {
    this.showList.update(v =&gt; !v);
  }
}</code></pre>



<p class="wp-block-paragraph">Dependency injection is a powerful pattern. The component doesn’t need to know where the list came from (it could be coming from an API, a database, or a hard-coded array); it just asks the service for what it needs. This pattern adds a bit of extra work up front, but it delivers a more flexible, organized codebase as the app grows in size and complexity.</p>



<h2 class="wp-block-heading">Routers and routes</h2>



<p class="wp-block-paragraph">Once your application grows beyond a single view, you need a way to navigate between different screens. In Angular, we use the built-in router for this purpose. In our example project, <code>src/app/app.routes.ts </code>is the dedicated home for the router config. Let’s follow the steps for creating a new route.</p>



<p class="wp-block-paragraph">First, we define the route. When you open <code>src/app/app.routes.ts</code>, you will see an exported routes array. This array contains the available routes for your app. Each string name resolves to a component that handles rendering that route. In effect, this is the map of your application’s landscape.</p>



<p class="wp-block-paragraph">In a real application, you’d often have “framing template” material in the root of the app (like the navbar) and then the routes fill in the body content. (Remember that by default, Angular is designed for single-page apps, where navigation does reload the screen, but swaps content.)</p>



<p class="wp-block-paragraph">For now, let’s just get a sense of how the router works. First, create a new component so we have a destination to travel to. In your terminal, run:</p>



<pre class="wp-block-code"><code>$ ng generate component details</code></pre>



<p class="wp-block-paragraph">This will generate a simple <code>details</code> component in the <code>src/app/details</code> directory.</p>



<p class="wp-block-paragraph">Now we can update <code>src/app/app.routes.ts</code> to include this new path. We will also add a “default” path that redirects empty requests to the home view, ensuring the user always lands somewhere:</p>



<pre class="wp-block-code"><code>import { Routes } from '@angular/router';
import { App } from './app'; // Matches src/app/app.ts
import { Details } from './details/details'; // Matches src/app/details/details.ts

export const routes: Routes = [
  { path: '', redirectTo: '/home', pathMatch: 'full' },
  { path: 'home', component: App },
  { path: 'details', component: Details },
];</code></pre>



<p class="wp-block-paragraph">Now if you visit <code>localhost:4200/home</code>, you’ll get the message from the <code>details</code> component: “Details works!”</p>



<p class="wp-block-paragraph">Next, we’ll use the <code>routerLink</code> directive to move between views without refreshing the page. In <code>src/app/app.html</code>,  we create a navigation bar that sits permanently at the top of the page (the “stationary” element), while the router swaps the content below it (the “impermanent” element):</p>



<pre class="wp-block-code"><code><nav>
  <a>Home</a> | 
  <a>Details</a>
</nav>

<hr>

</code></pre>



<p class="wp-block-paragraph">And with that, the application has a navigation flow. The user clicks, the URL updates, and the content transforms, all without the jarring flicker of a browser reload.</p>



<h2 class="wp-block-heading">Parametrized routes</h2>



<p class="wp-block-paragraph">The last thing we’ll look at is handling route parameters, where the route accepts variables in the path. To manage this kind of dynamic data, you define a route with a variable, marked by a colon. Open <code>src/app/app.routes.ts</code> and add a dynamic path:</p>



<pre class="wp-block-code"><code>export const routes: Routes = [
  // ... existing routes
  { path: 'details/:id', component: Details }, 
];</code></pre>



<p class="wp-block-paragraph">The <code>:id</code> is a placeholder. Whether the URL is <code>/details/42</code> or <code>/details/108</code>, this router will receive it because it matches the path. Inside the details component, we have access to this parameter (using the <a href="https://angular.dev/api/router/ActivatedRoute">ActivatedRoute</a> service or the new <a href="https://angular.dev/api/router/withComponentInputBinding">withComponentInputBinding</a>). We can use that value to retrieve the data we need (like using it to recover a detail item from a database).</p>



<h2 class="wp-block-heading">Conclusion</h2>



<p class="wp-block-paragraph">We have seen the core elements of modern Angular: Setting up the environment, building reactive components with signals, organizing logic with services, and tying it all together with interactive routing.</p>



<p class="wp-block-paragraph">Deploying these pieces together is the basic work in Angular. Once you get comfortable with it, you have an extremely powerful platform at your fingertips. And, when you are ready to go deeper, there is a whole lot more to explore in Angular, including:</p>



<ul class="wp-block-list">
<li>State management: Beyond signals, Angular has support for managing complex, application-wide state.</li>



<li>Forms: Angular has a robust system for handling user input.</li>



<li>Signals: We only scratched the surface of signals here. Signals offer a powerful, fine-grained way to manage state changes.</li>



<li>Build: You can learn more about producing production builds.</li>



<li><a href="https://www.infoworld.com/article/3964105/catching-up-with-angular-19.html" data-type="link" data-id="https://www.infoworld.com/article/3964105/catching-up-with-angular-19.html">RxJS</a>: Takes reactive programming to the next level.</li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Force any site into dark mode with Microsoft Edge — no extension required]]></title>
<description><![CDATA[Microsoft Edge is testing a new "Web Remix" feature in Canary builds that allows users to force any website into dark mode without needing third-party extensions.]]></description>
<link>https://tsecurity.de/de/3665157/windows-tipps/force-any-site-into-dark-mode-with-microsoft-edge-no-extension-required/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665157/windows-tipps/force-any-site-into-dark-mode-with-microsoft-edge-no-extension-required/</guid>
<pubDate>Mon, 13 Jul 2026 13:57:35 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft Edge is testing a new "Web Remix" feature in Canary builds that allows users to force any website into dark mode without needing third-party extensions.]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Choose the Right Data Recovery Service for Your Business: A Practical UK SME Checklist]]></title>
<description><![CDATA[Image Credit: Analogicus via Pixabay Learn More/… Learn More /… Image Credit: IfOnlyCommunications Latest Posts...
The post How to Choose the Right Data Recovery Service for Your Business: A Practical UK SME Checklist appeared first on SME Cybersecurity News.]]></description>
<link>https://tsecurity.de/de/3665034/it-security-nachrichten/how-to-choose-the-right-data-recovery-service-for-your-business-a-practical-uk-sme-checklist/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665034/it-security-nachrichten/how-to-choose-the-right-data-recovery-service-for-your-business-a-practical-uk-sme-checklist/</guid>
<pubDate>Mon, 13 Jul 2026 13:09:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="150" height="150" src="https://smecyberinsights.co.uk/wp-content/uploads/2026/07/Right-Data-Recovery-Provider-150x150.jpg" class="attachment-thumbnail size-thumbnail wp-post-image" alt="How to Choose the Right Data Recovery Service for Your Business: A Practical UK SME Checklist" decoding="async" loading="lazy">Image Credit: Analogicus via Pixabay Learn More/… Learn More /… Image Credit: IfOnlyCommunications Latest Posts...</p>
<p>The post <a rel="nofollow" href="https://smecyberinsights.co.uk/index.php/2026/07/13/choosing-a-data-recovery-partner/">How to Choose the Right Data Recovery Service for Your Business: A Practical UK SME Checklist</a> appeared first on <a rel="nofollow" href="https://smecyberinsights.co.uk/">SME Cybersecurity News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Which AI model should you bet your company on?]]></title>
<description><![CDATA[Every day this past week I did something I suspect millions of other people also did: I stared at an LLM model picker and wondered which one I was supposed to want.



OpenAI just released ⁠GPT-5.6 Sol, Terra, and Luna. Sol is the flagship. Terra offers much of its intelligence for less money. Lu...]]></description>
<link>https://tsecurity.de/de/3664783/ai-nachrichten/which-ai-model-should-you-bet-your-company-on/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664783/ai-nachrichten/which-ai-model-should-you-bet-your-company-on/</guid>
<pubDate>Mon, 13 Jul 2026 11:33:26 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Every day this past week I did something I suspect millions of other people also did: I stared at an <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">LLM </a>model picker and wondered which one I was supposed to want.</p>



<p>OpenAI just released ⁠<a href="https://openai.com/index/gpt-5-6/">GPT-5.6 Sol, Terra, and Luna</a>. Sol is the flagship. Terra offers much of its intelligence for less money. Luna is cheaper still. Anthropic released ⁠<a href="https://www.anthropic.com/news/claude-sonnet-5">Claude Sonnet 5</a> at the end of June and Opus 4.8 the month prior, with a little Fable 5 emerging in between. Meanwhile, Google, which seemed to be winning the model wars a few months ago, is now getting shade from Gergely Orosz, who ⁠<a href="https://x.com/GergelyOrosz/status/2075160978493210685?s=20">argues that Gemini has slipped outside the top tier</a> for software development and has been out of the major model release game for <em>eons</em> (May 19).</p>



<p>Perhaps Orosz is right. Perhaps he’ll be wrong again in six weeks. Honestly, it’s exhausting.</p>



<p>I use ChatGPT and Claude constantly and still have no principled idea which model to choose most of the time. I tend to click whatever looks like the biggest, most expensive option because I don’t know what I’m giving up by choosing something smaller. “Instant” sounds dangerously unserious. “Thinking” sounds expensive but powerful.</p>



<p>A quick <a href="https://www.linkedin.com/feed/update/urn:li:activity:7481369774401409024/">survey of my LinkedIn crowd</a> suggests others also feel my “WHICH MODEL???” pain. More importantly, I suspect most enterprises do, too.</p>



<h2 class="wp-block-heading"><a></a>A model doesn’t rot</h2>



<p>Before getting carried away, however, it’s worth considering whether any of this model churn actually matters. After all, a model doesn’t rot. The model an enterprise put into production in March performs just as well in July as it did when the company selected it. “Obsolete” generally means that something better now exists, not that the deployed model suddenly stopped summarizing insurance claims or classifying support tickets. (In other words, once you have something working, the idea that “but maybe Opus 200.2 is better!” is really a FOMO problem, not a performance issue.)</p>



<p>Most enterprise workloads don’t live at the frontier anyway. Extraction, summarization, classification, document comparison, and customer-service assistance often work perfectly well with smaller, cheaper models. OpenAI’s own pitch for the trio of GPT-5.6 models isn’t simply that Sol is better. It’s that ⁠Terra and Luna deliver different combinations of intelligence, latency, and cost. Luna, the cheapest tier, nearly matches the previous generation’s peak performance at less than half the estimated cost, according to OpenAI.</p>



<p>The practical question, of course, is where to start. An enterprise can’t test every model, every reasoning setting, and every price tier before doing any work. So here’s my advice (which I don’t follow in my own work, but I’m not defining enterprise strategy and can be a little price-insensitive). Start with the cheapest credible model that appears capable of the task. Give it a representative set of real examples and, before you start testing, define what counts as good enough. If it passes, stop. If it fails, move up a tier or try a model with strengths better suited to the work.</p>



<p>That sounds almost offensively simple, but it reverses the way many people, including me, use these products. We start with the biggest model because we’re afraid of what we might lose. Enterprises should start lower and require evidence before paying for more intelligence.</p>



<p>There are exceptions, of course. For genuinely difficult work, such as autonomous coding, complex research, or high-stakes reasoning, beginning with a frontier model may save time. But even then, the goal should be to establish a quality ceiling, then test whether a cheaper model can meet it. It’s changing the question from “which model is best?” to “what is the least expensive model that reliably clears the bar for this job?”</p>



<p>For many workloads, that price improvement matters more than a few extra benchmark points. <a href="https://www.infoworld.com/article/2335519/ai-hype-isnt-helping-anyone.html">⁠As I argued back in 2023</a>, following AI hype doesn’t help anyone. If your model strategy depends on whichever benchmark screenshot is circulating on X this week, you don’t have a strategy. Not a viable one, anyway. Pick a model and ignore the noise.</p>



<p>Except, of course, when that noise suggests a serious signal.</p>



<h2 class="wp-block-heading"><a></a>Sometimes better really is better</h2>



<p>Frontier improvements aren’t always incremental, making it advantageous to consider an upgrade. Coding is the obvious example. There’s a significant difference between a model that suggests the next few lines of code and one that can inspect a repository, plan a change, use tools, run tests, discover its own mistakes, and keep working for an extended period. That isn’t merely a nicer autocomplete experience. It can reorganize a development workflow.</p>



<p>This is why enterprises can’t simply standardize on an 18-month-old model and declare victory. In some areas, particularly software development and other agentic work, better models can unlock compounding productivity. A model that reliably completes 80% of a bounded task rather than 50% may justify an entirely different division of labor between humans and machines.</p>



<p>Still, that upgrade isn’t free.</p>



<p>Models differ in how they interpret instructions, call tools, manage context, refuse requests, and fail. Prompts and scaffolding tuned for one model can regress when moved to another. Or costs can explode. As one of my Oracle colleagues discovered just this week, running the same tasks in GPT 5.6 was orders of magnitude more expensive than 5.5. The API change may be trivial, but the revalidation and implications are not.</p>



<p>This leaves enterprises caught between two bad options. They can freeze and potentially miss out on meaningful improvements or chase every release and repeatedly test production systems on faith. What to do?</p>



<h2 class="wp-block-heading"><a></a>Stop making model bets</h2>



<p>The answer is to stop making LLM bets and start making job-to-be-done bets. Stop asking which model is fastest. Instead, figure out what work you are trying to improve. What does a good result look like? How much latency and cost can the workflow tolerate? How wrong can it be before a human must intervene? Once those questions have answers, model selection becomes less opaque.</p>



<p>A difficult code migration may justify GPT-5.6 Sol or Claude Sonnet 5. A repetitive classification task may work just as well with Luna or another smaller model. A regulated workflow may require a model or deployment option that offers particular data controls. Sometimes the correct model is no LLM at all, like when I’m writing this post. Sorry, AI vendors! (At least you won’t get blamed for my mistakes.)</p>



<p>This is where evaluations become the center of enterprise AI strategy. <a href="https://www.infoworld.com/article/4166247/improving-ai-agents-through-better-evaluations.html">⁠As I’ve said before</a>, most companies don’t have an AI quality problem so much as an AI measurement problem. Hence, a private evaluation suite built from real company work is the only leaderboard that matters. Does the new model materially improve quality? If so, use it! Does it reduce cost or latency? Again, that’s your free pass to adoption. Does the improvement justify the expense and effort of revalidation? If yes, continue.</p>



<h2 class="wp-block-heading"><a></a>Make model releases boring</h2>



<p>As important as the model is, keep in mind that AI success always comes back to <em>your</em> company’s data, <em>your</em> company’s workflows<em>, your</em> company’s integrations, etc. That’s the ⁠<a href="https://www.infoworld.com/article/4157506/mastering-the-dull-reality-of-sexy-ai.html">dull reality behind sexy AI</a>. Retrieval, <a href="https://www.infoworld.com/article/4189492/how-to-improve-the-memory-of-ai-agents.html">memory</a>, governance, data quality, <a href="https://www.infoworld.com/article/2262666/what-is-observability-software-monitoring-on-steroids.html">observability</a>, and feedback loops aren’t as exciting as a new model launch, but they’re what ultimately make AI truly work.</p>



<p>Again, when it’s time to consider something new, the principle should be to default to the least expensive model that reliably passes your evaluations. Only escalate harder tasks to more capable models when measurement shows that the premium pays. Tip: Make this invisible to employees so that the system routes to the best model for a particular prompt. As <a href="https://www.linkedin.com/feed/update/urn:li:activity:7481369774401409024/?dashCommentUrn=urn%3Ali%3Afsd_comment%3A%287481372047860715522%2Curn%3Ali%3Aactivity%3A7481369774401409024%29">dbt Labs’ Jon Lewis expresses</a> it, “The best model is ‘Auto’ and I won’t hear anyone say otherwise.” OpenAI’s own ⁠<a href="https://developers.openai.com/api/docs/guides/latest-model">migration guidance</a> recommends testing models on representative tasks, including trying a lower reasoning level rather than automatically cranking everything to the maximum.</p>



<p>As for me, I’ll probably keep clicking the shiniest option. I don’t have a formal evaluation suite for InfoWorld columns, and the marginal cost is a subscription I already pay. Enterprises don’t get that excuse.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI voice agents and the human touch: A new playbook for SME customer engagement]]></title>
<description><![CDATA[Customer expectations don’t end when business hours do, which is why delivering a fast, always-on customer experience (CX) has traditionally required large call centres and significant resources. This often placed small businesses at a disadvantage, as many lacked the manpower and budget to provi...]]></description>
<link>https://tsecurity.de/de/3664586/it-nachrichten/ai-voice-agents-and-the-human-touch-a-new-playbook-for-sme-customer-engagement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664586/it-nachrichten/ai-voice-agents-and-the-human-touch-a-new-playbook-for-sme-customer-engagement/</guid>
<pubDate>Mon, 13 Jul 2026 10:03:42 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Customer expectations don’t end when business hours do, which is why delivering a fast, always-on customer experience (CX) has traditionally required large call centres and significant resources. This often placed small businesses at a disadvantage, as many lacked the manpower and budget to provide 24/7 support at scale. Today, AI has completely levelled the playing field. Even small businesses now have access to powerful tools that can answer queries, resolve routine issues, and deliver highly personalised interactions around the clock.</p>



<p>But adopting AI in customer engagement is not just a question of efficiency. For smaller businesses especially, where loyalty is often built on familiarity, trust, and personal service, the real challenge is using AI in ways that strengthen rather than dilute the human connection that customers value most.</p>



<p>Human empathy combined with AI efficiency is a delicate blend. Done right, it ensures that every customer interaction feels personal, thoughtful, and seamless, whether the customer is engaging with a bot at 2 a.m. or a live agent during office hours.</p>



<p>So, how can small businesses embrace always-on virtual agents without losing the human connection that defines their identity? Here’s a practical playbook to guide the transition.</p>



<h2 class="wp-block-heading">1. Understand what customers want: Speed, simplicity, and empathy</h2>



<p>Before diving into AI adoption, it’s critical to understand what customers expect. Twilio’s <a href="https://www.twilio.com/en-us/lp/digital-patience-apj?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_ai-voice-agent_brandposthub_digital-patience" rel="sponsored"><em>Di</em></a><em><a href="https://www.twilio.com/en-us/lp/digital-patience-apj?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_ai-voice-agent_brandposthub_digital-patience" target="_blank" rel="sponsored">g</a></em><a href="https://www.twilio.com/en-us/lp/digital-patience-apj?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_ai-voice-agent_brandposthub_digital-patience" rel="sponsored"><em>ital Patience</em></a> study suggests that while speed matters, it is not the only thing that customers value. Twilio found that 46% of respondents in the Asia-Pacific and Japan region say quick service and resolution are most important, but 51% say delays are acceptable if they lead to better customer support. The study also notes that customers are open to AI, but still value human touchpoints more highly.</p>



<p>The takeaway: AI should enhance CX, not replace it. Businesses can let natural-sounding AI voice agents handle inbound calls, regardless of peak hours or time zones. These virtual agents act as an intelligent frontline – answering common questions and qualifying leads – before seamlessly routing the conversation to a live human representative. The result? Callers get immediate answers, and the business captures every opportunity without losing the human touch.</p>



<h2 class="wp-block-heading">2. Map the handover points between AI and humans</h2>



<p>One of the most common pitfalls in implementing AI is failing to clearly define when and how customers transition from bots to human agents. To avoid customer frustration, organisations must thoughtfully map out these “handover points” by designing for two key principles: choice and continuity.</p>



<h3 class="wp-block-heading"><strong><em>Designing for Choice</em></strong></h3>



<p>Give customers the option to reach a human when needed. While AI is perfectly suited for routine inquiries like FAQs or order tracking, customers should never feel trapped in a bot loop. Always provide a clear, accessible option for them to choose to escalate the issue. Additionally, configure your system to proactively step in and offer a human handoff the moment it detects emotion, ambiguity, or complex steps.</p>



<h3 class="wp-block-heading"><strong><em>Designing for Continuity</em></strong></h3>



<p>Effective handovers rely on technology that recognises when an issue exceeds AI’s scope. By leveraging natural language processing and intelligent routing, organisations can ensure the transition from machine to human is frictionless. Crucially, this means automatically carrying the full history and context of the interaction forward so the customer never needs to repeat themselves.</p>



<p>Achieving this level of continuity requires a new approach to managing interaction data during handovers. Instead of passing along a raw transcript, organisations need a managed memory service that provides agents with persistent context across every conversation, channel, and session. By transforming customer preferences, unresolved issues, and intent into a structured semantic profile—one that continuously evolves and reconciles new interactions as they occur—agents can quickly understand the relationship and continue the interaction without disruption.</p>



<p>To support truly omnichannel experiences, the system must also resolve identity automatically across touchpoints, linking interactions from phone, email, messaging apps, and other channels to a single customer profile. Equally important is the ability to surface only the information that is relevant to the task at hand. By presenting agents with a concise summary of the active issue and customer preferences, grounded in verified business knowledge such as product policies and FAQs, organisations can reduce resolution times while ensuring customers experience a seamless continuation of the conversation.</p>



<h2 class="wp-block-heading">3. Don’t automate for automation’s sake</h2>



<p>AI adoption should never feel like a “set it and forget it” strategy. Instead, it should be approached as a way to solve real business problems. It starts with asking questions like: What are the most time-consuming tasks for the team? What frustrates customers the most?</p>



<p>For instance, a restaurant might automate table reservations and menu queries, while a small online retailer could deploy AI to handle order status updates or product recommendations. These targeted use cases ensure that AI adds tangible value without overwhelming operations.</p>



<p>Take the example of <a href="https://customers.twilio.com/en-us/driva?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_ai-voice-agent_brandposthub" target="_blank" rel="sponsored">Driva</a>, a fast-growing online finance broker that deployed AI-powered customer service tools to answer routine enquiries and provide immediate assistance while customers wait in the call queue. By automating common interactions, Driva reduced the volume of requests requiring human intervention and achieved a 5% uplift in conversion rates at key points in the customer journey.</p>



<h2 class="wp-block-heading">4. Invest in AI that connects</h2>



<p>While consumers embrace automation, <a href="https://www.twilio.com/en-us/lp/digital-patience-apj?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_ai-voice-agent_brandposthub_research" target="_blank" rel="sponsored">research</a> shows they still draw comfort from the warmth of a human voice. To make your virtual agents feel less robotic and more like an extension of your team, look for tools that:</p>



<ul class="wp-block-list">
<li>Deliver human-like voice AI experiences at scale through natural turn-taking and barge-in capabilities.</li>



<li>Connect interactions across voice, messaging, and digital channels into a single thread so every exchange builds on the last.</li>



<li>Leverage Natural Language Processing (NLP) that enables conversational systems to interpret context, mimic human tone, and even recognise sentiment.</li>



<li>Place orchestration at the heart of the experience. An effective orchestration engine acts as the “conductor,” actively coordinating workflows and routing interactions so the right resource—whether an AI bot or a human—handles the right moment.</li>
</ul>



<p>When AI bots, automated workflows, and human teams are seamlessly coordinated behind the scenes, the customer simply experiences one unbroken, dynamic dialogue. For small enterprises, this means delivering sophisticated experiences that effortlessly bridge the gap between automation and live support, even at scale.</p>



<h2 class="wp-block-heading">5. Empower teams with real-time context</h2>



<p>AI is not about replacing human workers; it’s here to make jobs easier. However, for teams to fully embrace this new dynamic, organisations must shift their focus from retrospective performance reviews to real-time agent assistance. By feeding agents context as the conversation happens, businesses ensure that every interaction never starts from scratch.</p>



<ul class="wp-block-list">
<li><strong>Leveraging Conversational Intelligence: </strong>Use a real-time intelligence layer that turns live conversations into signals and actions. By analysing voice and messaging with generative AI Language Operators, businesses can understand intent, sentiment, and churn risk instantly, allowing human and AI agents to act in the moment with the right response or escalation.</li>



<li><strong>In-the-Moment Guidance:</strong> Give agents instant context and in-the-moment guidance during every interaction. Surfacing relevant customer history, next-best action suggestions, and summaries in real time allows agents to resolve issues faster without switching tools.</li>



<li><strong>Resolving Complex Customer Needs:</strong> AI can handle routine enquiries with low latency, but human agents still excel at nuanced problem-solving. With AI feeding them persistent customer memory and sentiment analysis in real time, human agents can skip the repetitive questions and immediately focus on resolving complex issues, rescuing deals, or preventing churn.</li>
</ul>



<p>When employees are equipped with real-time customer data and voice-driven insights, SMEs empower their teams to stop reacting to problems and start responding to customers proactively.</p>



<p>Consider global AI platform <a href="https://customers.twilio.com/en-us/genspark?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_ai-voice-agent_brandposthub" target="_blank" rel="sponsored">Genspark</a>, which leverages a Programmable Voice API for its “Call for Me” agent to handle complex outbound tasks like checking supplier pricing or booking international hotels. The AI can conduct real-time, natural conversations across different languages on the user’s behalf, seamlessly navigating the live interactions before delivering a structured summary. Because these natural voice experiences depend entirely on speed and consistency, the underlying infrastructure provides the critical sub-second latency necessary to keep every automated call clear and uninterrupted.</p>



<h2 class="wp-block-heading">6. Maintain transparency with customers</h2>



<p>Finally, a successful AI implementation requires transparency. Customers should always know when they’re communicating with a bot and when they’ve been handed over to a human. AI-powered interactions must offer clarity by providing transparency about when and how AI is used and explaining next steps in plain language.</p>



<p>Transparency builds trust. Small businesses can go a step further by soliciting customer feedback on their AI interactions and using this input to fine-tune their systems.</p>



<p>For small enterprises, the AI-to-human handover isn’t about choosing between humans and machines; it’s about combining the strengths of both to create exceptional customer experiences. AI can provide the speed and efficiency customers expect, while humans deliver the empathy and creativity they value.</p>



<p>By strategically defining handover points, investing in human-like AI, and empowering agents to work alongside technology, organisations can build a CX strategy that’s as scalable as it is personal.</p>



<p>This blended approach ensures that every interaction – whether managed by a bot or a human – is thoughtful, natural, and distinctly on-brand.  </p>



<p>To learn more about Twilio, visit <a href="https://www.twilio.com/en-us/why-twilio?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_end-cta-ai-voice-agent_brandposthub" target="_blank" rel="sponsored">here</a>.</p>



<hr class="wp-block-separator has-alpha-channel-opacity">
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[America May Soon Be Facing It's Largest Labor Shortage in Its History]]></title>
<description><![CDATA[America "is facing what's projected to become the largest labor shortage in its history," according to experts interviewed by the Washington Post:



Economists warn that the worsening labor problem, due in part to a skills shortage and population shifts, will be vast and reach beyond tech. It "c...]]></description>
<link>https://tsecurity.de/de/3664269/it-security-nachrichten/america-may-soon-be-facing-its-largest-labor-shortage-in-its-history/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664269/it-security-nachrichten/america-may-soon-be-facing-its-largest-labor-shortage-in-its-history/</guid>
<pubDate>Mon, 13 Jul 2026 07:22:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[America "is facing what's projected to become the largest labor shortage in its history," according to experts interviewed by the Washington Post:



Economists warn that the worsening labor problem, due in part to a skills shortage and population shifts, will be vast and reach beyond tech. It "could hobble the American economy for years to come," predicts the Georgetown University Center on Education and the Workforce. Lightcast, a labor market data company, calls it "the largest labor shortage the country has ever seen." JPMorgan Chase warns of a national security risk from "a pervasive talent deficit that constrains the nation's capacity to build, compete, and protect its interests." There will be shortages in the tens or even hundreds of thousands of nurses, physicians, teachers, engineers, pharmacists, mental health counselors, construction worker and airplane mechanics — jobs AI generally can't do... 

Among the trends that have been leading to this moment: a mismatch between the careers college graduates are pursuing and the jobs employers are struggling to fill. Far fewer students are majoring in health care fields than are needed to meet demand, for instance. "We have pumped so many young people into business and finance" when what's really in demand are graduates in other fields, [said Ron Hetrick, Lightcast's principal economist]. "It's like a factory producing these workers like widgets, even though society is saying, 'We really don't need them.' And the factory just keeps pumping them out." But the principal reason for the looming workforce shortages is much more basic. A protracted decline in birth rates is coinciding with a record wave of retirements, data shows. 

From 2024 to 2032, when the last baby boomers sign up for Social Security payments, more than 18 million college-educated workers will leave the labor force while fewer than 14 million enter it, according to the Georgetown center. Meanwhile, even as the number of people with associate and bachelor's degrees falls, the number of jobs requiring them will grow, the center forecasts. That will leave a gap of 4.6 million workers. Lightcast puts the deficit at an even higher 6 million... The effect of population shifts on the supply of talent, with or without degrees, has been compounded by a drop in the proportion of high school graduates choosing to go to college, a sharply reduced rate of immigration, and a growing number of Americans leaving the workforce altogether because of such issues as lack of child care, early retirement, incarceration and substance addiction, according to the Chamber of Commerce.
 

Three interesting statistics from the article:

U.S. college/university enrollment in 2023 was down by nearly 2 million students since its peak in 2010, according to the most recent data from the U.S. Education Department.
America's low birth rate since 2010 "means the number of college-age Americans is forecast to decline by another 13 percent through 2041."
South Dakota has just 41 workers for every 100 open jobs... while California and nine other states have more workers than jobs, the Chamber of Commerce found.
<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=America+May+Soon+Be+Facing+It's+Largest+Labor+Shortage+in+Its+History%3A+https%3A%2F%2Fit.slashdot.org%2Fstory%2F26%2F07%2F13%2F0443258%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fit.slashdot.org%2Fstory%2F26%2F07%2F13%2F0443258%2Famerica-may-soon-be-facing-its-largest-labor-shortage-in-its-history%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://it.slashdot.org/story/26/07/13/0443258/america-may-soon-be-facing-its-largest-labor-shortage-in-its-history?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Helping media companies navigate the new streaming normal]]></title>
<description><![CDATA[Editor’s note: An earlier version of this feature originally appeared on Next TV and TV Technology.From the explosion of new programming to the launch of high-profile streaming services, 2020 was on track to be a transformational year in media and entertainment. But at the same time, the industry...]]></description>
<link>https://tsecurity.de/de/3662852/it-security-nachrichten/helping-media-companies-navigate-the-new-streaming-normal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662852/it-security-nachrichten/helping-media-companies-navigate-the-new-streaming-normal/</guid>
<pubDate>Sun, 12 Jul 2026 08:07:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph"><p><i><b>Editor’s note</b>: An earlier version of this feature originally appeared on <a href="https://www.nexttv.com/blogs/googles-anil-jain-how-media-companies-can-navigate-the-new-norm-with-cloud-technology" target="_blank">Next TV </a>and <a href="https://www.tvtechnology.com/opinion/googles-anil-jain-how-media-companies-can-navigate-the-new-norm-with-cloud-technology" target="_blank">TV Technology</a>.</i></p><p>From the explosion of new programming to the launch of high-profile streaming services, 2020 was on track to be a transformational year in media and entertainment. But at the same time, the industry fully expected many of its foundational elements—windowing strategies, live events, production standards—to stay the same.</p><p>All that changed with COVID-19. Suddenly, the future came early to the industry, with many facing difficult challenges like accelerating and evolving direct-to-consumer business models while at the same time keeping workers and productions physically distanced.</p><p>As media companies transition from short-term response to long-term planning, many are contemplating how different the industry might look in the months and years to come.</p><p>All this is the topic of our new guide,<a href="https://inthecloud.withgoogle.com/media-transformation-during-covid/dl-cd.html?utm_source=google&amp;utm_medium=email&amp;utm_campaign=-&amp;utm_content=mediapageevolution" target="_blank"> Accelerated Media Evolution In The Time Of COVID</a>, and the focus of our<a href="https://inthecloud.withgoogle.com/media-transformation-during-covid/dl-cd.html?utm_source=google&amp;utm_medium=email&amp;utm_campaign=-&amp;utm_content=mediapageevolution" target="_blank"> Media OnAir</a> events, where we’ll share insights from our work with leading media companies. For these organizations and others, we recommend keeping new audience behaviors top of mind and focusing on driving three key changes.</p><p><b>1. Scale new monetization channels and engage audiences through data </b></p><p></p><p>As audiences were stuck at home during the early stages of the pandemic, linear viewing saw a temporary increase in consumption—driven by specific formats such as news. But that consumption returned to pre-lockdown levels as restrictions were lifted in certain regions. </p><p>By contrast, many streaming subscription services saw consistent increased adoption. Nine percent of U.S. households took up a new SVOD service in Q2 2020.<sup>1</sup> The surge in streaming consumption seems to be more resilient than its linear counterpart, as U.S. time spent with streaming services in June 2020 was roughly 50 percent above its 2019 level.<sup>2</sup></p><p></p><p>In contrast to the Pay TV bundle, today’s streaming audiences have access to much more choice and freedom in their entertainment options. These viewers have shown both a preference to stack multiple services and a higher propensity to churn. As the pandemic affects discretionary spending across the world, audiences will look to save on entertainment costs, making SVOD services more attractive than traditional Pay TV bundles, as well as driving an increased adoption of AVOD services. </p><p>As a result, media organizations need to reassess how to streamline existing broadcast operations and costs. They must invest in building technology platforms that can handle unpredictable streaming demand seamlessly, while also deriving deeper audience insights from their data in order to drive audience engagement, retention, and monetization. For example, leading British broadcaster <a href="https://cloud.google.com/customers/itv">ITV</a>  built a video analytics solution on Google Cloud so they could better monitor events on their VOD service, ITV Hub.</p><p><b>2. Produce new content remotely and maximize the value of library content</b></p><p>While distribution channels may change, content still remains the industry’s crown jewel. Content breadth, exclusivity, and original content are the top three reasons that audiences adopt streaming services, and maximizing the value of both library and new content has never been more critical.</p><p>Content production has also been disrupted by the pandemic. Physical productions have paused across the world, only slowly starting to resume once again. And for content that has made it through the complex post-production process, the global shuttering of theatrical exhibition has forced many blockbuster titles to debut on streaming services—radically altering windowing strategies and the economic models that come with it. </p><p></p><p>Media companies have resorted to boundless creative strategies to keep content production lines open. Formats that can be created remotely such as animation are experiencing a boom, and live events such as news and sports have established new remote working processes in record time. </p><p>Content production has been on the rise for years, but the temporary halt in production has been a silver lining for media companies; this pause has presented an opportunity to step back and implement more digital, collaborative, streamlined, and global production and management processes, supported by the cloud. Media companies like <a href="https://www.youtube.com/watch?v=UwHcdmqXw8c" target="_blank">ViacomCBS</a> have also accelerated the digitization and enrichment of their extensive back catalogs and archives, to help fill the content gap. </p><p></p><p><b>3. Reimagine the workplace for the future of productivity</b></p><p>Finally, the biggest challenge many companies and industries face has been the shift to remote work. Innovative companies like <a href="https://youtu.be/87OzMmP2e0g" target="_blank">Yahoo Finance</a>, for example, utilized our video conferencing solution to keep their broadcast team’s content flowing and audiences engaged. 150 of Yahoo Finance’s editors, reporters, and anchors used Google Meet to deliver news and video streams on air from locations across the U.S. and London to tens of millions of viewers live, transitioning to a 100 percent remote broadcast model overnight. </p><p>As the industry navigates a new working norm, many media company offices will require thoughtful consideration of which tasks can be automated or done remotely, and exactly how much real estate is required to maintain operations. <br><br>Decisions are likely to be different by functions. Post-production staff, visual effects artists, and video editors can utilize <a href="https://www.youtube.com/watch?v=VjeRdQ9X5Vg" target="_blank">virtual workstations</a> and editing applications to complete their work remotely, while central teams such as finance, sales, and marketing can utilize video conferencing services like Meet to stay connected no matter where they are. But some essential personnel—lightweight studio production teams and on- prem playout teams—will need to still come into the office.<br><br><b>Continued innovation in the face of unprecedented change<br></b><br>Many media and entertainment companies are choosing Google Cloud operations modernization—all to thrive and remain relevant within this new era. For example, Major League Baseball adopted <a href="https://cloud.withgoogle.com/next/sf/sessions?session=APP228#business-application-platform" target="_blank">Anthos</a> as the vehicle to run their applications anywhere, utilized BigQuery to upgrade their <a href="https://technology.mlblogs.com/introducing-statcast-2020-hawk-eye-and-google-cloud-a5f5c20321b8" target="_blank">Statcast</a> platform, and launched new fan friendly initiatives like <a href="https://www.mlb.com/news/mlb-film-room-launch" target="_blank">Film Room</a> using our machine learning technologies—all in the service of becoming more agile and delivering more innovative fan experiences in a competitive media ecosystem. <br></p><p>This year has been one of unexpected and accelerated change for all, but the ingenuity, innovation, and determination of media companies to continue delivering critical news, information, and entertainment to audiences across the world has been extraordinary. Google Cloud is committed to bringing forward technologies that the media industry needs and to partner with our customers to help them continue to innovate in the face of unprecedented challenges. </p><p></p><p>To learn more, read our guide,<a href="https://inthecloud.withgoogle.com/media-transformation-during-covid/dl-cd.html?utm_source=google&amp;utm_medium=email&amp;utm_campaign=-&amp;utm_content=mediapageevolution" target="_blank"> Accelerated Media Evolution In The Time Of COVID</a>, or join us at one of our<a href="https://inthecloud.withgoogle.com/media-transformation-during-covid/dl-cd.html?utm_source=google&amp;utm_medium=email&amp;utm_campaign=-&amp;utm_content=mediapageevolution" target="_blank"> Media OnAir</a> events.</p><hr><p><i><sup>Sources:</sup></i></p><i><sup>1. Kantar, <a href="https://www.kantarworldpanel.com/global/News/Amazon-tops-Disney-Netflix-with-surge-in-video-service" target="_blank">Amazon tops Disney, Netflix with surge in video service</a> (August 2020)<br>2. Nielsen; The Hollywood Reporter, <a href="https://www.hollywoodreporter.com/live-feed/quarantine-tv-ratings-spike-is-1299998" target="_blank">The Quarantine TV Ratings Spike Is Over</a> (June 2020)</sup></i></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rémy Cointreau drives customer centricity with SAP on Google Cloud]]></title>
<description><![CDATA[Imagine the challenge of supply chain planning and meeting changing consumer needs when you have products that can take up to one-hundred years to produce. That’s the case for Rémy Cointreau, a family-owned maker of fine spirits whose roots go back to 1724. With rapidly evolving consumer expectat...]]></description>
<link>https://tsecurity.de/de/3662845/it-security-nachrichten/rmy-cointreau-drives-customer-centricity-with-sap-on-google-cloud/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662845/it-security-nachrichten/rmy-cointreau-drives-customer-centricity-with-sap-on-google-cloud/</guid>
<pubDate>Sun, 12 Jul 2026 08:07:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph"><p>Imagine the challenge of supply chain planning and meeting changing consumer needs when you have products that can take up to one-hundred years to produce. That’s the case for <a href="https://www.remy-cointreau.com/en/" target="_blank">Rémy Cointreau</a>, a family-owned maker of fine spirits whose roots go back to 1724. </p><p>With rapidly evolving consumer expectations and heavy competition from premium beverage brands, Rémy Cointreau set out on a strategy to put the customer at the center of their business. Offering more than a premium beverage, <a href="https://www.remy-cointreau.com/en/brands/" target="_blank">key brands</a> such as Rémy Martin cognac, Louis XIII cognac, Cointreau and St-Rémy brandy instead would offer customers a taste of luxury. “The idea is not to simply sell Cognac,” explains Sebastien Huet, the company’s CTO. “We want to sell a French way of living. For that, we needed to shift from selling products to selling an experience.”</p><p>To make this a reality, Rémy Cointreau realized all elements of its business would need to be more agile. It needed more flexibility in its SAP systems, which drive Finance, Manufacturing and Supply Chain, and easy access to valuable SAP system data for business decision making and innovative customer approaches. As a result, Rémy Cointreau determined they’d need to move to the cloud to enable such a transformation. </p><p>First, Rémy Cointreau elicited the help of long-time partner <a href="https://www.oxya.com/services/managed-cloud-services/google-cloud/" target="_blank">oXya</a>. The Rémy Cointreau/oXya collaboration dates back 10 years, including the move of the on-prem SAP environment to oXya where they provided managed services. oXya deeply understood the pain points of Rémy Cointreau’s SAP landscape and worked with the company to capture and translate their business and functional requirements, followed by benchmarking various cloud solutions. Rémy Cointreau’s business was spread over two SAP landscapes, with interface and data consistency challenges, which needed to be unified to one SAP system and migrated to S/4HANA. Choosing the right cloud platform was critical to drive the SAP environment to deliver more value. </p><p>“Scalability, flexibility and cost savings were important to Rémy Cointreau but also they had a strong desire to focus on data aspects beyond SAP,” says Matthieu Petitprez, Deputy Chief Technology Officer, oXya, a Hitachi Group Company. “<a href="https://cloud.google.com/solutions/sap">Google Cloud</a>, with its specific data analysis and management tools, completely met this objective. It allows integration of SAP with <a href="https://cloud.google.com/bigquery">BigQuery </a>and artificial intelligence services, bringing more value to the SAP solution.” </p><p>“Just as it takes years to create a great cognac, we value partners who will be by our side for a long time,” says Huet, noting that it’s not unusual for the company to enter into 30- or 40-year agreements with suppliers. “The strategic alliance between Google Cloud and SAP made us confident they were the right choice for us. Google Cloud has a more comprehensive strategic partnership with SAP than its competitors and is clearly adding value to SAP.” </p><p>Although the pandemic forced them to drive the migration remotely, Rémy Cointreau, oXya and Google Cloud’s Professional Services Organization (PSO) collaborated to achieve the European operations go-live in April 2020. “I was worried that COVID-19 would delay our launch, but migration was fast, easy, and on-schedule,” says Mr. Huet. “The technology played a part, but it also helped that we had two partners who we believed in.”</p></div>
<div class="block-paragraph"><h3>Improved manufacturing and service with business agility</h3><p>The SAP S/4HANA deployment on Google Cloud Platform is now live for Rémy Cointreau’s Europe based operations. In addition to S/4, it also migrated the SAP supply chain planning tool, Advanced Planner and Optimizer (APO), as well as SAP’s Business Warehouse to Google Cloud. Similar deployments will launch soon globally. </p><p>While the environment is still new, Rémy Cointreau already sees big steps towards greater agility with Google Cloud. For instance, Google Cloud makes it much faster and easier to adjust the technical operating environment. If a team wants to start performing a new resource-heavy analysis, Rémy Cointreau can expand capacity to meet demands within minutes. The team can also roll back capacity so that it is only using the resources it needs.</p><p>This newfound agility takes the pressure off the IT team when it comes to provisioning a new implementation for future capacity. Rather than try to build capacity for potential peaks, the team can deploy for expected demand, then easily adjust afterward to compensate for actual loads. “It makes capacity planning so much easier,” Mr. Huet says. “Not long after go-live, we had to perform some updates—increasing memory and so on,” he recalls. “In the past, the process would take about a month to do. Now it takes a few minutes. We literally went from five weeks to five minutes. This is a tremendous improvement.” </p><p>Another critical factor in Rémy Cointreau’s decision to move to Google Cloud was the ability to connect its SAP backbone to key SaaS applications such as Salesforce. As the company began to put more focus on the customer experience, creating strong, long-term relationships with customers would be essential. By being able to create this 360 degree view of data among SAP, Salesforce, and its ecommerce platform, Rémy Cointreau can more easily create personalized experiences for its customers that simply weren’t possible before.</p><h3>A data-driven future</h3><p>Rémy Cointreau business users are already reaping benefits from the cloud deployment. “One of the key improvements is the ability to analyze live data,” Huet says. “That was not the case in the past. Previously, there was a 24-hour lag between the time the data came in and the moment it could be analyzed. This is especially important on the production-management side, where every hour counts.” </p><p>As exciting as the improvements in agility and connectivity have been so far, Huet sees even more possibilities for the future. “Right now, we’re focused on establishing SAP in the Google Cloud environment,” he says. “But once that’s done, we’ll be looking at technologies like <a href="https://cloud.google.com/bigquery">BigQuery</a> that can take our data analysis to the next level.” Potential areas of interest include product traceability and customer experience. “Now that we’re fully deployed on Google Cloud Platform, anything is possible,” he notes. “We can pull data in from multiple sources via integration and analyze it in a matter of days. We don’t need a three-month project to see value.” </p><p>It is this agility and creativity that makes Huet most optimistic about the company’s partnership with Google Cloud. As he notes, “I think the best is yet to come.” </p><p>To learn more about Rémy Cointreau’s deployment of <a href="https://cloud.google.com/solutions/sap">SAP on Google Cloud</a>, read the case study <a href="https://cloud.google.com/customers/remy-cointreau">here</a>. Also learn more about <a href="https://www.oxya.com/services/managed-cloud-services/google-cloud/" target="_blank">oXya’s capabilities with Google Cloud for SAP customers</a>.</p></div>
<div class="block-related_article_tout">





<div class="uni-related-article-tout h-c-page">
  <section class="h-c-grid">
    <a href="https://cloud.google.com/blog/products/sap-google-cloud/reports-examine-business-value-of-running-sap-on-google-cloud/" data-analytics='{
                       "event": "page interaction",
                       "category": "article lead",
                       "action": "related article - inline",
                       "label": "article: {slug}"
                     }' class="uni-related-article-tout__wrapper h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
        h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3 uni-click-tracker">
      <div class="uni-related-article-tout__inner-wrapper">
        <p class="uni-related-article-tout__eyebrow h-c-eyebrow">Related Article</p>

        <div class="uni-related-article-tout__content-wrapper">
          <div class="uni-related-article-tout__image-wrapper">
            <div class="uni-related-article-tout__image"></div>
          </div>
          <div class="uni-related-article-tout__content">
            <h4 class="uni-related-article-tout__header h-has-bottom-margin">SAP on Google Cloud: 2 analyst studies reveal quantifiable business benefits and ROI</h4>
            <p class="uni-related-article-tout__body">From uptime and infrastructure to efficiency and productivity—both Forrester and IDC identified major benefits to companies that have mad...</p>
            <div class="cta module-cta h-c-copy  uni-related-article-tout__cta muted">
              <span class="nowrap">Read Article
                <svg class="icon h-c-icon" role="presentation">
                  <use xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#mi-arrow-forward"></use>
                </svg>
              </span>
            </div>
          </div>
        </div>
      </div>
    </a>
  </section>
</div>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Tool] Magic Extractor — identify and unpack unknown files, installers and embedded payloads on Windows]]></title>
<description><![CDATA[I wanted a Windows-friendly alternative to tools such as Binwalk and UniExtract, focused on identifying unknown files and automatically choosing the appropriate extraction method. That idea eventually became Magic Extractor, an open-source utility intended to help with static triage and the initi...]]></description>
<link>https://tsecurity.de/de/3662625/malware-trojaner-viren/tool-magic-extractor-identify-and-unpack-unknown-files-installers-and-embedded-payloads-on-windows/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662625/malware-trojaner-viren/tool-magic-extractor-identify-and-unpack-unknown-files-installers-and-embedded-payloads-on-windows/</guid>
<pubDate>Sun, 12 Jul 2026 04:18:02 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I wanted a Windows-friendly alternative to tools such as Binwalk and UniExtract, focused on identifying unknown files and automatically choosing the appropriate extraction method.</p> <p>That idea eventually became <strong>Magic Extractor</strong>, an open-source utility intended to help with static triage and the initial unpacking of suspicious samples.</p> <p>It can be useful for:</p> <ul> <li>Identifying files whose extension is missing or misleading</li> <li>Unpacking installers, SFX archives and uncommon compression formats</li> <li>Extracting nested archives recursively</li> <li>Listing contents without extraction</li> <li>Carving archives and payloads embedded at arbitrary offsets</li> <li>Trying multiple handlers when detection is ambiguous</li> </ul> <p>Detection combines PureMagic, custom magic signatures, Detect It Easy, Binwalk and Magika. The detected type is then routed to the appropriate bundled extractor.</p> <p>Example:</p> <p><code>magic-extractor identify suspicious.bin</code></p> <p><code>magic-extractor extract suspicious.bin --recursive</code></p> <p><code>magic-extractor carve firmware.bin --list</code></p> <p>It currently supports more than 80 formats, including archives, installers, disk images, forensic images and embedded content.</p> <p>This is not a malware detector, sandbox or replacement for dynamic analysis. It is mainly intended as a supporting tool for file identification, unpacking and static analysis workflows.</p> <p>GitHub:</p> <p><a href="https://github.com/xchwarze/magic-extractor">https://github.com/xchwarze/magic-extractor</a></p> <p>Feedback from malware analysts and reverse engineers would be especially useful, particularly regarding formats, packers or installers that are currently difficult to extract.</p> <p>As always, suspicious files should only be handled inside an isolated analysis environment.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/xchwarze"> /u/xchwarze </a> <br> <span><a href="https://github.com/xchwarze/magic-extractor">[link]</a></span>   <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1uu1rni/tool_magic_extractor_identify_and_unpack_unknown/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Avoided Semiconductor Tariffs Last Year Thanks To Intel Chip Deal]]></title>
<description><![CDATA[A recent report explains how Apple avoided semiconductor tariffs last year thanks to an Intel chip deal. Tim Cook traveled to Washington last summer to stop a 100 percent tax on imported computer parts. A tax like that would make every device much more expensive to build.



The company secured a...]]></description>
<link>https://tsecurity.de/de/3661882/ios-mac-os/apple-avoided-semiconductor-tariffs-last-year-thanks-to-intel-chip-deal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661882/ios-mac-os/apple-avoided-semiconductor-tariffs-last-year-thanks-to-intel-chip-deal/</guid>
<pubDate>Sat, 11 Jul 2026 15:08:56 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A recent report explains how Apple avoided semiconductor tariffs last year thanks to an Intel chip deal. Tim Cook traveled to Washington last summer to stop a 100 percent tax on imported computer parts. A tax like that would make every device much more expensive to build.



The company secured a pass on these fees by agreeing to spend money inside the country. That big agreement heavily involved another major name in technology.



The government pushed the tech giant to support local manufacturing



During the talks, government officials brought up Intel. The administration made it clear that helping this American brand was the main way to secure the tax break. Because of this push, we now know that Apple avoided semiconductor tariffs last year thanks to the Intel chip deal.



The plan worked for both sides. The government recently shared on social media that Apple will start using parts made by Intel inside its popular devices. This public news sent the stock price for the chip builder to a record high.



The brand plans to use these local parts inside upcoming Mac computers and future iPhone models. Before this report came out, nobody knew that the talks about taxes were connected to this manufacturing partnership.



Building parts locally keeps the final price lower for buyers



The main goal of the tax rule was to make large businesses build things in America. By choosing to work with a local partner, the company did not have to pay extra import fees on its part. This meant it could keep the final prices normal for people buying a new phone or laptop.



Even with this good news, the company still faced some financial problems later because of a worldwide shortage of memory parts. However, solving the tax issue was a big win.



It shows how much power the government has over where technology brands choose to build things. By working together, the brand protected its profit while giving a boost to a local factory.]]></content:encoded>
</item>
<item>
<title><![CDATA[Which Meal Kit Is Actually Worth It? Find the Right One in Under 5 Minutes video]]></title>
<description><![CDATA[Choosing the right meal kit can be tough, given the many budget, dietary and time-saving factors to consider. We break down premium, midtier and affordable services to help you pick the best subscription for your kitchen.]]></description>
<link>https://tsecurity.de/de/3661879/it-nachrichten/which-meal-kit-is-actually-worth-it-find-the-right-one-in-under-5-minutes-video/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661879/it-nachrichten/which-meal-kit-is-actually-worth-it-find-the-right-one-in-under-5-minutes-video/</guid>
<pubDate>Sat, 11 Jul 2026 15:02:58 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Choosing the right meal kit can be tough, given the many budget, dietary and time-saving factors to consider. We break down premium, midtier and affordable services to help you pick the best subscription for your kitchen.]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI introduces ChatGPT Work, a cloud-based AI agent that manages tasks across email, Slack and calendars]]></title>
<description><![CDATA[OpenAI on Thursday launched ChatGPT Work, a new AI agent embedded inside its flagship chatbot that aims to transform ChatGPT from a question-and-answer tool into an autonomous work platform capable of executing complex, multi-step tasks across users' email, calendars, code repositories, and messa...]]></description>
<link>https://tsecurity.de/de/3660793/it-nachrichten/openai-introduces-chatgpt-work-a-cloud-based-ai-agent-that-manages-tasks-across-email-slack-and-calendars/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660793/it-nachrichten/openai-introduces-chatgpt-work-a-cloud-based-ai-agent-that-manages-tasks-across-email-slack-and-calendars/</guid>
<pubDate>Fri, 10 Jul 2026 22:48:07 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://openai.com/">OpenAI</a> on Thursday launched <a href="https://openai.com/index/chatgpt-for-your-most-ambitious-work/">ChatGPT Work</a>, a new AI agent embedded inside its flagship chatbot that aims to transform ChatGPT from a question-and-answer tool into an autonomous work platform capable of executing complex, multi-step tasks across users' email, calendars, code repositories, and messaging apps.</p><p>The product is powered by OpenAI's latest flagship model, <a href="https://openai.com/index/gpt-5-6/">GPT-5.6</a>, and is designed to go far beyond generating text. ChatGPT Work can gather context from connected apps, files, and workflows to produce finished documents, spreadsheets, presentations, reports, and websites. The agent takes a stated outcome, breaks it into smaller steps, and stays with complex projects for hours, completing them independently.</p><p>The launch marks OpenAI's clearest attempt yet to reposition ChatGPT as a workplace platform rather than a chatbot — and it arrives at a moment of extraordinary financial significance for the company. Last month, OpenAI <a href="https://openai.com/index/openai-submits-confidential-s-1/">confidentially submitted a draft S-1 registration statement</a> to the SEC, initiating what could become one of the largest technology IPOs in history, with reported valuations <a href="https://www.cnbc.com/2026/03/31/openai-funding-round-ipo.html">clustering between $730 billion and $852 billion</a> and annualized revenue that has blown past $25 billion.</p><p>In a short demonstration and conversation with VentureBeat on Friday, Ty Geri, a product manager at OpenAI who helped build ChatGPT Work, said the product's mission is to democratize the kind of agentic AI capabilities that OpenAI's internal engineering tool, Codex, has already demonstrated. "What's really exciting is we've seen how much Codex has been able to push the frontier of what we can get done with these AI tools, as opposed to just getting information or answers or guidance," Geri said. "Our internal adoption of Codex is literally an exponential curve across every single product function and every single use case."</p><h2><b>Why OpenAI built a persistent virtual machine that works from the beach</b></h2><p>The core architectural bet behind <a href="https://openai.com/index/chatgpt-for-your-most-ambitious-work/">ChatGPT Work</a> is a persistent cloud-based virtual machine that runs on OpenAI's servers, always available to the user regardless of which device they happen to be on. That marks a deliberate departure from competitors whose agents require a local machine to remain powered on and connected.</p><p>"What's really exciting about ChatGPT Work is that it's a virtual machine in the cloud that's always on for you, and this is available across all of our paid tiers," Geri said. "All Plus users are getting this. I think that's a very unique aspect of this."</p><p>The mobile-first aspect of the launch is something Geri described as "missing from the market." He pointed to the ability to create a website on a phone and share it with collaborators as a particularly novel capability. "Sites are new in general to Codex. They launched in Codex about a week and a half ago, but now we're launching also in web and mobile. You can create a site on your phone at the beach and share it with your friends," he said.</p><p><a href="https://openai.com/index/chatgpt-for-your-most-ambitious-work/">ChatGPT Work</a> will roll out beginning with <a href="https://chatgpt.com/pricing/?utm_source=google&amp;utm_medium=paid_search&amp;utm_campaign=GOOG_C_SEM_GBR_Premium_CHT_BAU_ACQ_PER_MIX_ALL_NAMER_US_EN_081125&amp;c_id=22874197666&amp;c_agid=184333759620&amp;c_crid=778419668389&amp;c_kwid=kwd-1931160859103&amp;c_ims=&amp;c_pms=9061275&amp;c_nw=g&amp;c_dvc=c&amp;gad_source=1&amp;gad_campaignid=22874197666&amp;gbraid=0AAAAA-I0E5eVxMdRuuMlOhjqMjAi2KCBS&amp;gclid=Cj0KCQjwsMLSBhD9ARIsAIpUTDoJ61xQZv3XpwtAkZ20Et-Y9TM9_exet3Bh9O9h2kxVcpfmgHkyx68aAlw-EALw_wcB">Pro, Enterprise, and Edu users</a>, and will expand to Plus and Business users over the next few days. In the interview, Geri emphasized that the availability of the product to Plus subscribers — not just premium tiers — is central to OpenAI's strategy. "It's accessible to all paid plans, including Plus users, which in my opinion is a really big feat, and really part of that OpenAI mission, which is about bringing all this power to as many people," he said.</p><h2><b>How MCP plugins connect ChatGPT Work to Slack, Gmail, and GitHub</b></h2><p>The product relies on MCP-based plugins to connect to external services like Gmail, Google Calendar, Slack, and GitHub. When asked whether the plugin architecture is based on the <a href="https://modelcontextprotocol.io/docs/getting-started/intro">Model Context Protocol standard</a>, Geri confirmed: "These are all based on MCP." He added that connecting multiple Gmail accounts — a frequent user request — "is definitely on the roadmap."</p><p>The experience is designed to be action-oriented from the first interaction. <a href="https://openai.com/index/chatgpt-for-your-most-ambitious-work/">ChatGPT Work</a> offers a personalized onboarding flow that surfaces different suggested use cases depending on the user's role. Geri demonstrated how the system, detecting his role as a product manager, immediately suggested tasks like evaluating AI systems, building research artifacts, and managing his calendar. "You can start with a simple task like catch me up on Slack or Teams or read today's calendar," Geri said. He described a scenario where the system reviewed his calendar, identified scheduling conflicts, flagged meetings requiring preparation, and then — on his instruction — declined, accepted, or rescheduled events directly.</p><p>Users can also customize the agent by teaching it their writing style, organizing outputs into projects, and — in a lighter touch — choosing a virtual pet that accompanies them in the interface. The interface also introduces a hosted website feature that allows users to build and share interactive sites directly through ChatGPT Work, turning what would typically be a static slide deck into a dynamic, collaborative artifact. "Now we suddenly have a collaborative interface that's actually more exciting and more accessible than a slide deck, which has all these formatting restrictions," Geri said.</p><h2><b>Scheduling 10 bug bashes at once: what agentic productivity looks like in practice</b></h2><p>Geri's own usage of <a href="https://openai.com/index/chatgpt-for-your-most-ambitious-work/">ChatGPT Work</a> illustrates the breadth of tasks the system can handle. In the run-up to the product's launch, he needed to organize pre-release testing sessions — known internally as "bug bashes" — across dozens of features and team members.</p><p>"I just come to ChatGPT Work and say, 'Set up a bug bash for all the distinct features in ChatGPT Work. Add all the people that worked on that feature,' and it can check Slack, it can check GitHub, it can check Docs, and find a time that works for the four highest contributors to that feature," Geri said. "It went and scheduled 10 bug bashes, all coordinated across all those different people. That would have taken me 30 minutes at least."</p><p>But Geri pushed back against the characterization that <a href="https://openai.com/index/chatgpt-for-your-most-ambitious-work/">ChatGPT Work</a> is limited to rote administrative work. He described using it for analytically complex tasks like identifying the biggest causes of user churn for specific product features and generating product solutions — work he said would previously have taken months. "Things that we would have spent three months doing, we can now spend a week doing — and do much more, and make a much better product," Geri said. "Bugs that we would have found three or four weeks from now, we can now find within two days and fix for our users."</p><p>He also described handing off the tedium of product testing itself. "It used to be that even though like the most interesting part of my job is like what to test, I would actually end up having to spend most of my job doing the testing, which is like me taking a mouse and like clicking on the same thing over and over again, like five times," Geri said. "Instead, now I can define what do we want to test, and ChatGPT Work or Codex can actually go test it for me, deliver me that bug report, and then we can work on fixing that bug."</p><h2><b>What OpenAI says about data privacy when AI reads your Slack and email</b></h2><p>When pressed on data privacy concerns — given that ChatGPT Work pulls sensitive information from workplace tools like Slack, Google Drive, and email — Geri said privacy "is incredibly important, and the most important part of this is it's always in the user's control."</p><p>He pointed to OpenAI's existing enterprise security infrastructure, noting that "enterprise accounts have ZDR, and users can always opt out of letting their conversations help improve future models, which many users do." The comment aligns with assurances OpenAI made when it first launched ChatGPT Enterprise in August 2023, when the company wrote in a blog post that it does "<a href="https://openai.com/index/introducing-chatgpt-enterprise/">not train on your business data or conversations</a>."</p><p>The privacy question carries additional weight now because of the sheer volume of sensitive workplace data ChatGPT Work is designed to access. Unlike a chatbot session where a user voluntarily pastes text into a prompt, ChatGPT Work actively reaches into connected systems — reading Slack messages, scanning calendar invitations, pulling GitHub commit histories — to assemble context for its tasks. That represents a fundamentally different data surface area than anything OpenAI has offered before, and one that enterprise security teams will scrutinize carefully before granting access.</p><h2><b>ChatGPT Work enters a three-way arms race with Anthropic and Microsoft</b></h2><p>ChatGPT Work lands squarely in the middle of what has become the defining competitive battlefield in enterprise AI: the race to build autonomous workplace agents that can go beyond generating text and actually execute tasks.</p><p>The product arrives months after Anthropic took <a href="https://claude.com/product/cowork">Claude Cowork</a> out of preview and into general availability in April, bringing its AI agent to web and mobile platforms aimed at helping enterprise users monitor and manage long-running AI-driven tasks from anywhere. Meanwhile, Microsoft made <a href="https://www.microsoft.com/en-us/microsoft-365-copilot/cowork">Copilot Cowork</a> generally available worldwide on June 16, built in partnership with Anthropic to move beyond chat and into execution. The three products — ChatGPT Work, Claude Cowork, and Microsoft Copilot Cowork — now compete directly for the attention of enterprise IT departments and individual knowledge workers alike.</p><p>The convergence is striking. All three products share a remarkably similar vision: a persistent AI agent running in the cloud that can break complex tasks into steps, connect to workplace tools via plugins, and produce finished outputs rather than just conversational replies. All three work across desktop, web, and mobile.</p><p>What distinguishes OpenAI's approach is its raw consumer distribution advantage. ChatGPT has reached <a href="https://openai.com/index/scaling-ai-for-everyone/">900 million weekly active users</a>, and OpenAI now has <a href="https://openai.com/index/scaling-ai-for-everyone/">50 million paying subscribers</a>. More than 9 million paying business users rely on ChatGPT for work, and 92% of Fortune 500 companies now use ChatGPT. By making ChatGPT Work available to Plus subscribers at $20 a month — not just Enterprise or Pro customers — OpenAI is betting that broad accessibility will drive adoption faster than any competitor can match.</p><h2><b>OpenAI's product manager says AI is a partner, not a replacement — with a caveat</b></h2><p>When asked about the potential impact on the labor market, Geri was careful with his framing. He declined to speak broadly about workforce disruption but offered his personal experience as a product manager whose day-to-day work has been substantially reshaped by the tool.</p><p>"My job is not to schedule bug bashes and find out who contributed to a specific feature. That's a task I do in my job, but that's not my job," Geri said. "My job is to make an amazing product." He described ChatGPT Work as "a partner" and "an extension of me, certainly not a replacement," adding: "Everybody feels far more productive than before, but is also almost working harder than before, because you get to work on all the things you want to work on as opposed to the drudgery around it."</p><p>But Geri was also careful not to minimize the sophistication of the work the agent can handle. "I also don't want to say that it's only doing mundane tasks because, like something like hill climbing retention curves on a given feature is not mundane. It's actually really hard to do," he said. The distinction matters. If <a href="https://openai.com/index/chatgpt-for-your-most-ambitious-work/">ChatGPT Work</a> were merely automating calendar invitations and expense reports, it would be a convenience tool. The fact that Geri describes it compressing three months of analytical product work into a single week suggests something with far greater implications for how teams are structured and staffed.</p><h2><b>An IPO-bound company needs ChatGPT Work to prove enterprise AI can generate revenue</b></h2><p>The timing of ChatGPT Work's launch is impossible to separate from OpenAI's IPO trajectory. The company needs to demonstrate that it can convert its massive consumer user base into durable enterprise revenue — a narrative that becomes significantly more compelling with a product explicitly designed around professional workflows.</p><p>OpenAI said it is generating <a href="https://openai.com/index/accelerating-the-next-phase-ai/">$2 billion in revenue per month</a>, growing four times faster than Alphabet and Meta did at comparable stages, with enterprise now making up more than 40% of revenue and on track to reach parity with consumer by the end of 2026. But OpenAI remains heavily loss-making, and <a href="https://fortune.com/2025/11/26/is-openai-profitable-forecast-data-center-200-billion-shortfall-hsbc/">the company does not expect to reach profitability until around 2030</a>, with internal projections suggesting losses of $14 billion in 2026 alone.</p><p>The competitive dynamics are unprecedented. Anthropic filed for its own IPO on June 1 at a <a href="https://www.reuters.com/business/anthropic-raises-65-billion-now-valued-965-billion-2026-05-28/">$965 billion valuation</a>, setting up simultaneous public listings from the two most prominent AI startups in history. Whether both can sustain their lofty valuations under the scrutiny of public market investors will depend in large part on whether products like ChatGPT Work and Claude Cowork deliver measurable productivity gains to paying enterprise customers.</p><p>The launch also caps a product trajectory that began with <a href="https://chatgpt.com/business/?utm_source=google&amp;utm_medium=paid_search&amp;utm_campaign=GOOG_B_SEM_GBR_Core-Generic_MIX_BAU_ACQ_PER_MIX_ALL_NAMER_US_EN_042826&amp;c_id=23786098075&amp;c_agid=193601180617&amp;c_crid=806361782592&amp;c_kwid=aud-2471394551488:kwd-1933117063409&amp;c_ims=&amp;c_pms=9061275&amp;c_nw=g&amp;c_dvc=c&amp;gad_source=1&amp;gad_campaignid=23786098075&amp;gbraid=0AAAAA-I0E5fOwq9zncww98G13-WJxCPbT&amp;gclid=Cj0KCQjwsMLSBhD9ARIsAIpUTDonc5DPxzLgOO1GFI9yNaazBtf33Yums0oGIg1CR79ZRSiXK0LbcVkaAg9uEALw_wcB">ChatGPT Enterprise</a> in August 2023, accelerated through the release of OpenAI's Operator agent in January 2025, and continued through Operator's deprecation and shutdown on August 31, 2025, when its capabilities were folded into the ChatGPT agent framework. ChatGPT Work is the consolidation of those efforts into a single, unified product — one that pairs <a href="https://openai.com/index/gpt-5-6/">GPT-5.6's three model variants</a> (Sol for power, Luna for speed, and Terra for balanced everyday use) with a persistent cloud environment and an expanding library of MCP plugins.</p><h2><b>The future of work may already be running in the cloud</b></h2><p>When asked whether ChatGPT Work signals a shift toward a new kind of operating system — one where users interact with their computers primarily through an AI agent rather than through traditional mouse-and-keyboard interfaces — Geri stopped short of making sweeping predictions. But he hinted at the direction OpenAI sees ahead.</p><p>"Anybody who has worked with Codex or now ChatGPT Work will realize how exciting it is to interact with your environment and your computer via the agent," he said. "Especially in the desktop app, where the model has access to your entire machine and can interact with websites on your behalf — it's really able to be an extension of you and a real partner, and that certainly feels like the future."</p><p>At the end of the interview, Geri circled back to something personal. "I've never enjoyed work as much as I have in the last month using ChatGPT Work and Codex," he said — a striking admission from a product manager who, until recently, spent a meaningful share of his days clicking through the same interface five times in a row just to see if it would break. OpenAI is now asking 900 million users to believe that feeling scales. For a company weeks away from one of the largest public offerings in history, the answer to that question is worth roughly $850 billion.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sony 1000X The Collexion vs. Bowers & Wilkins Px8 S2: Both wow, but one is comfier]]></title>
<description><![CDATA[Sony's and Bowers & Wilkins' premium headphones deliver an elevated experience, but choosing the right pair isn't as cut-and-dry as you'd think.]]></description>
<link>https://tsecurity.de/de/3660410/hacking/sony-1000x-the-collexion-vs-bowers-wilkins-px8-s2-both-wow-but-one-is-comfier/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660410/hacking/sony-1000x-the-collexion-vs-bowers-wilkins-px8-s2-both-wow-but-one-is-comfier/</guid>
<pubDate>Fri, 10 Jul 2026 18:55:44 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Sony's and Bowers &amp; Wilkins' premium headphones deliver an elevated experience, but choosing the right pair isn't as cut-and-dry as you'd think.]]></content:encoded>
</item>
<item>
<title><![CDATA[SAP Makes It Easier For Customers To Shop For Legacy Product Support, Ending EU Antitrust Probe]]></title>
<description><![CDATA[An anonymous reader quotes a report from The Register: The European Commission has ended an investigation into possible anticompetitive practices after SAP agreed to abolish reinstatement fees and reduce back-maintenance fees. The move could reduce barriers for customers considering third-party s...]]></description>
<link>https://tsecurity.de/de/3660331/it-security-nachrichten/sap-makes-it-easier-for-customers-to-shop-for-legacy-product-support-ending-eu-antitrust-probe/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660331/it-security-nachrichten/sap-makes-it-easier-for-customers-to-shop-for-legacy-product-support-ending-eu-antitrust-probe/</guid>
<pubDate>Fri, 10 Jul 2026 18:12:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An anonymous reader quotes a report from The Register: The European Commission has ended an investigation into possible anticompetitive practices after SAP agreed to abolish reinstatement fees and reduce back-maintenance fees. The move could reduce barriers for customers considering third-party support for products nearing the end of their vendor support terms, including thousands of large businesses that rely on SAP ERP Central Component (ECC) to run their business operations. SAP's mainstream support for ECC ends in December 2027, while customers can opt for extended maintenance until December 2030 by paying an additional two percentage points on their maintenance fees. The most recent figures from Gartner showed that in Q4 2024 only 39 percent of worldwide ECC customers -- from a total of 35,000 -- had bought or subscribed to licenses to start their transition to SAP S/4HANA, the replacement ERP product.
 
In September last year, the European Commission launched a formal investigation into SAP's behavior in the aftermarket for maintenance and support services in Europe. It said it was responding to concerns that SAP restricted competition in this crucial aftermarket by making it harder for rivals to compete, leaving European customers with fewer choices and higher costs. In October, SAP published its response. "SAP's commitments aim at improving the financial attractiveness for customers who wish to reinstate SAP maintenance and support services. Thus, future costs associated with reinstatement will not financially prevent customers from choosing to terminate SAP maintenance and support for a given period of time," the document said (PDF).
 
SAP has now agreed to abolish reinstatement fees and reduce back maintenance fees charged to customers who return to SAP's support after a period of absence, the Commission confirmed. It also agreed to clarify conditions that allow customers to choose different maintenance and support service providers and different levels of support from SAP. The agreement is relevant to customers considering third-party support to extend their use of ECC beyond vendor maintenance. For example, last year, European retailer Kingfisher -- owner of well-known UK brands B&amp;Q and Screwfix -- told a Gartner conference it had chosen Rimini Street to support ECC 6.0 because it saw insufficient value in migrating to SAP S/4HANA. [...] The commitments offered by SAP will remain in force globally for ten years.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=SAP+Makes+It+Easier+For+Customers+To+Shop+For+Legacy+Product+Support%2C+Ending+EU+Antitrust+Probe%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F10%2F0846241%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F10%2F0846241%2Fsap-makes-it-easier-for-customers-to-shop-for-legacy-product-support-ending-eu-antitrust-probe%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/07/10/0846241/sap-makes-it-easier-for-customers-to-shop-for-legacy-product-support-ending-eu-antitrust-probe?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Video Remix: Google Fotos bekommt KI-Videoeditor für unterwegs]]></title>
<description><![CDATA[Google baut Google Fotos gerade zu einem „echten“ Videobearbeitungs-Tool aus. Unter dem Namen Video Remix landet nämlich ein neues Werkzeug in der App, das per KI Bearbeitungen am bewegten Bild vornehmen kann. Im Hintergrund werkelt hierfür Gemini Omni, das gleichzeitig...Zum Beitrag: Video Remix...]]></description>
<link>https://tsecurity.de/de/3659516/it-nachrichten/video-remix-google-fotos-bekommt-ki-videoeditor-fuer-unterwegs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659516/it-nachrichten/video-remix-google-fotos-bekommt-ki-videoeditor-fuer-unterwegs/</guid>
<pubDate>Fri, 10 Jul 2026 13:17:56 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Google baut Google Fotos gerade zu einem „echten“ Videobearbeitungs-Tool aus. Unter dem Namen Video Remix landet nämlich ein neues Werkzeug in der App, das per KI Bearbeitungen am bewegten Bild vornehmen kann. Im Hintergrund werkelt hierfür Gemini Omni, das gleichzeitig...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/video-remix-google-fotos-bekommt-ki-videoeditor-fuer-unterwegs/">Video Remix: Google Fotos bekommt KI-Videoeditor für unterwegs</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Access Betting Sites Abroad Safely With Our VPN Guide]]></title>
<description><![CDATA[Today, we’ll show you everything you need to know to access betting sites abroad and unblock them from anywhere in the world. After all, it can be frustrating if you travel to a country where your favorite gambling site is blocked. Just follow our step by step instructions on choosing and using a...]]></description>
<link>https://tsecurity.de/de/3658838/betriebssysteme/access-betting-sites-abroad-safely-with-our-vpn-guide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658838/betriebssysteme/access-betting-sites-abroad-safely-with-our-vpn-guide/</guid>
<pubDate>Fri, 10 Jul 2026 07:50:50 +0200</pubDate>
<category>🖥️  Betriebssysteme</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Today, we’ll show you everything you need to know to access betting sites abroad and unblock them from anywhere in the world. After all, it can be frustrating if you travel to a country where your favorite gambling site is blocked. Just follow our step by step instructions on choosing and using a VPN to […]</p>
<p>The post <a rel="nofollow" href="https://www.addictivetips.com/vpn/access-betting-websites-abroad/">Access Betting Sites Abroad Safely With Our VPN Guide</a> appeared first on <a rel="nofollow" href="https://www.addictivetips.com/">AddictiveTips</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Fotos: Android-App erhält neue „Floating Bar“ und Video Remix]]></title>
<description><![CDATA[Google verteilt für seine Fotos-App auf Android eine neue Bedienleiste, die sich schon vor zwei Jahren erstmals angekündigt hatte. Nun erreicht die „Floating Bar“ wohl…
Dieser Artikel Google Fotos: Android-App erhält neue „Floating Bar“ und Video Remix erschien zuerst auf SmartDroid.de.]]></description>
<link>https://tsecurity.de/de/3658801/android-tipps/google-fotos-android-app-erhaelt-neue-floating-bar-und-video-remix/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658801/android-tipps/google-fotos-android-app-erhaelt-neue-floating-bar-und-video-remix/</guid>
<pubDate>Fri, 10 Jul 2026 07:26:16 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1700" height="1060" src="https://i0.wp.com/www.smartdroid.de/wp-content/uploads/2025/12/Google-Fotos-Logo-Hero.jpg?fit=1700%2C1060&amp;ssl=1" class="attachment-medium size-medium wp-post-image" alt="Google Fotos Logo Hero" decoding="async" fetchpriority="high" srcset="https://i0.wp.com/www.smartdroid.de/wp-content/uploads/2025/12/Google-Fotos-Logo-Hero.jpg?w=1700&amp;ssl=1 1700w, https://i0.wp.com/www.smartdroid.de/wp-content/uploads/2025/12/Google-Fotos-Logo-Hero.jpg?resize=1200%2C748&amp;ssl=1 1200w, https://i0.wp.com/www.smartdroid.de/wp-content/uploads/2025/12/Google-Fotos-Logo-Hero.jpg?resize=1536%2C958&amp;ssl=1 1536w" sizes="(max-width: 1700px) 100vw, 1700px"><p>Google verteilt für seine Fotos-App auf Android eine neue Bedienleiste, die sich schon vor zwei Jahren erstmals angekündigt hatte. Nun erreicht die „Floating Bar“ wohl…</p>
<p>Dieser Artikel <a rel="nofollow" href="https://www.smartdroid.de/google-fotos-android-app-erhaelt-neue-floating-bar-und-video-remix/">Google Fotos: Android-App erhält neue „Floating Bar“ und Video Remix</a> erschien zuerst auf <a rel="nofollow" href="https://www.smartdroid.de/">SmartDroid.de</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Photos Adds ‘Remix’ AI Video Edits for Paid Subscribers]]></title>
<description><![CDATA[Google Photos now includes Video Remix, an AI-powered feature that uses Gemini Omni to transform ordinary video clips into cinematic edits and artistic creations.]]></description>
<link>https://tsecurity.de/de/3658121/it-nachrichten/google-photos-adds-remix-ai-video-edits-for-paid-subscribers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658121/it-nachrichten/google-photos-adds-remix-ai-video-edits-for-paid-subscribers/</guid>
<pubDate>Thu, 09 Jul 2026 21:46:32 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Google Photos now includes Video Remix, an AI-powered feature that uses Gemini Omni to transform ordinary video clips into cinematic edits and artistic creations.]]></content:encoded>
</item>
<item>
<title><![CDATA[Firefox Tooling Announcements: Engineering Effectiveness Newsletter (Q2 2026 Edition)]]></title>
<description><![CDATA[Welcome to the Q2 edition of the Engineering Effectiveness Newsletter! The Engineering Effectiveness org makes it easy to develop, test and release Mozilla software at scale. See below for some highlights, then read on for more detailed info!
Highlights 


Improved mach startup overhead by 30-50%...]]></description>
<link>https://tsecurity.de/de/3657816/tools/firefox-tooling-announcements-engineering-effectiveness-newsletter-q2-2026-edition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657816/tools/firefox-tooling-announcements-engineering-effectiveness-newsletter-q2-2026-edition/</guid>
<pubDate>Thu, 09 Jul 2026 19:08:33 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Welcome to the Q2 edition of the Engineering Effectiveness Newsletter! The Engineering Effectiveness org makes it easy to develop, test and release Mozilla software at scale. See below for some highlights, then read on for more detailed info!</p>
<h3><a class="anchor" href="https://discourse.mozilla.org/#p-295620-highlights-image29x31uploadsijwaz2bmu1cm7txaoyutaj3g7djpeg-1" name="p-295620-highlights-image29x31uploadsijwaz2bmu1cm7txaoyutaj3g7djpeg-1"></a>Highlights <div class="lightbox-wrapper"><a class="lightbox" href="https://us1.discourse-cdn.com/flex001/uploads/mozilla/original/3X/c/6/c64f1102bb6b55e5a9e11c7390019d84dcc69fbf.jpeg" rel="noopener nofollow ugc" title="image"><img alt="image" height="31" src="https://us1.discourse-cdn.com/flex001/uploads/mozilla/optimized/3X/c/6/c64f1102bb6b55e5a9e11c7390019d84dcc69fbf_2_29x31.jpeg" width="29"></a></div></h3>
<ul>
<li>
<p>Improved <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1775197">mach startup overhead</a> by 30-50%, as well as a 75% improvement for <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2018327">mach test on Windows</a> and <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2017746">10s faster configure</a> for subsequent runs</p>
</li>
<li>
<p>Moved to weekly scheduled dot releases and <a href="https://docs.google.com/document/d/1oktCbzZ3M7NZTMBxv8yEOYmNHHxaIstZ55vRMI9PmzM/edit?tab=t.0#heading=h.r7335u1pggl8" rel="noopener nofollow ugc">faster rollouts</a>, allowing us to deliver fixes and uplifts to users faster and more reliably</p>
</li>
<li>
<p>Created a <a href="https://tests.firefox.dev/" rel="noopener nofollow ugc">huge number of dashboards</a> to help developers dig into Mochitest and XPCShell tests</p>
</li>
<li>
<p>Stood up <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2037084">MacOS worker pools</a> that can run multiple tasks at once using VMs, greatly improving our Mac capacity issues</p>
</li>
<li>
<p>Can now <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2034982">navigate to about:pdf</a> in Nightly to open and edit arbitrary PDF files, including the ability to <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2047633">set Firefox as your default PDF editor</a> on MacOS</p>
</li>
</ul>
<h3><a class="anchor" href="https://discourse.mozilla.org/#p-295620-detailed-project-updates-2" name="p-295620-detailed-project-updates-2"></a>Detailed Project Updates</h3>
<h4><a class="anchor" href="https://discourse.mozilla.org/#p-295620-ai-for-development-image38x38uploaduslsg1wyqmsnwpkkcpts9bzsgdspng-3" name="p-295620-ai-for-development-image38x38uploaduslsg1wyqmsnwpkkcpts9bzsgdspng-3"></a>AI for Development <div class="lightbox-wrapper"><a class="lightbox" href="https://us1.discourse-cdn.com/flex001/uploads/mozilla/original/3X/d/5/d581d7036fa3d622443350328d622c936216ecf6.png" rel="noopener nofollow ugc" title="image"><img alt="image" height="38" src="https://us1.discourse-cdn.com/flex001/uploads/mozilla/original/3X/d/5/d581d7036fa3d622443350328d622c936216ecf6.png" width="38"></a></div></h4>
<ul>
<li>
<p>Suhaib Mujahid deployed the initial version of <a href="https://docs.google.com/document/d/1cLIuNnhefePsixu8iRiqAn75EcVvgQHw48pUTkhpwok/edit?tab=t.0" rel="noopener nofollow ugc">Hackbot</a>, a platform for building and running AI agents to automate parts of the Firefox development workflow.</p>
</li>
<li>
<p>Evgeny Pavlov ported the “Build Repair Agent” to Hackbot and deployed it for testing. It now monitors Firefox build failures and triggers the agent. When an analysis and a proposed patch are ready developers can be notified by email.</p>
</li>
</ul>
<h4><a class="anchor" href="https://discourse.mozilla.org/#p-295620-bugzilla-image16x16uploadrcf6wygovavtrjvslvu8pj7vnyhpng-4" name="p-295620-bugzilla-image16x16uploadrcf6wygovavtrjvslvu8pj7vnyhpng-4"></a>Bugzilla <img alt="image" height="16" src="https://us1.discourse-cdn.com/flex001/uploads/mozilla/original/3X/b/e/bea92544acb6ddb5aa665316f3c7411bc860c8db.png" width="16"></h4>
<ul>
<li>
<p>David Lawrence added a new GitHubPullRequests extension that renders a live status panel in the bug modal for any attachment whose content type is text/x-github-pull-request. A new REST endpoint fetches PR metadata (state, author, labels, latest review per reviewer) from the GitHub REST API on demand, and a client-side script populates a table with a “show closed/merged” toggle.[image]</p>
</li>
<li>
<p>Xavier L’Hour improved the user experience for developers, adding shortcuts to buglist.cgi for all, open, or closed bugs (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1764713">1764713</a>)</p>
</li>
<li>
<p>Xavier L’Hour added a new shortcut button to the bug page that allows users to quickly move spam bugs to the Invalid Bugs product (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1684509">1684509</a>).</p>
</li>
</ul>
<h4><a class="anchor" href="https://discourse.mozilla.org/#p-295620-build-system-and-mach-environment-image27x27uploadoumafz5bcpgk6de6ddcb6m1uzptpng-5" name="p-295620-build-system-and-mach-environment-image27x27uploadoumafz5bcpgk6de6ddcb6m1uzptpng-5"></a>Build System and Mach Environment <div class="lightbox-wrapper"><a class="lightbox" href="https://us1.discourse-cdn.com/flex001/uploads/mozilla/original/3X/a/e/ae9342c7f7dcfe9d427c191b43c7aaf993ceeffb.png" rel="noopener nofollow ugc" title="image"><img alt="image" height="27" src="https://us1.discourse-cdn.com/flex001/uploads/mozilla/optimized/3X/a/e/ae9342c7f7dcfe9d427c191b43c7aaf993ceeffb_2_27x27.png" width="27"></a></div></h4>
<ul>
<li>
<p>Alex Hochheiden has been moving build system logic out of make to pave the way for a new build system backend (coming soon). See <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2038789">Bug 2038789</a>.</p>
</li>
<li>
<p>Alex Hochheiden landed a 30%-50% (platform dependent) speedup for mach startup. See <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1775197">Bug 1775197</a>.</p>
</li>
<li>
<p>Alex Hochheiden sped up subsequent configure runs by ~10s by adding caching to the mach taskgraph toolchain step. See <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2017746">Bug 2017746</a>.</p>
</li>
<li>
<p>Alex Hochheiden reduced mach test startup overhead on Windows by 75%. See <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2018327">Bug 2018327</a>.</p>
</li>
<li>
<p>Alex Hochheiden has achieved significant code deduplication and simplification by consolidating the Android Gradle configuration into convention plugins. There were also various Gradle configure-cache improvements. See <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2007013">Bug 2007013</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1950099">Bug 1950099</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2013417">Bug 2013417</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2017752">Bug 2017752</a>, and <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2017753">Bug 2017753</a>.</p>
</li>
</ul>
<h4><a class="anchor" href="https://discourse.mozilla.org/#p-295620-firefox-ci-image25x26uploadga1rfuc1fs6gwtrx3kk92r8hfncjpeg-6" name="p-295620-firefox-ci-image25x26uploadga1rfuc1fs6gwtrx3kk92r8hfncjpeg-6"></a>Firefox-CI <div class="lightbox-wrapper"><a class="lightbox" href="https://us1.discourse-cdn.com/flex001/uploads/mozilla/original/3X/7/4/74356ec644bf30f10ea5f0ce6067cdd819ea96e4.jpeg" rel="noopener nofollow ugc" title="image"><img alt="image" height="26" src="https://us1.discourse-cdn.com/flex001/uploads/mozilla/optimized/3X/7/4/74356ec644bf30f10ea5f0ce6067cdd819ea96e4_2_25x26.jpeg" width="25"></a></div></h4>
<ul>
<li>
<p>Julien Cristau <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2050408">added support</a> for interactive tasks (aka one click loaners) on Windows and macOS</p>
</li>
<li>
<p>Andrew Halberstadt <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2044330">implemented</a> mach try support with Github, being used in mozilla/enterprise-firefox-try and coming to Firefox soon.</p>
</li>
<li>
<p>Andrew Halberstadt <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2033838">implemented the machinery</a> to start making Gecko CI tasks clone from Github.</p>
</li>
<li>
<p>Ryan Curran <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2037084">brought Firefox CI’s Apple Silicon VM infrastructure into production</a>. Building on the MacOS CI image pipeline established last year, he migrated test suites onto virtual machines and grew the macosx1500-aarch64-vms pool so Taskcluster now routes eligible jobs to VMs alongside physical hardware. This reduces reliance on physical Macs, increases CI capacity, and supports the ongoing migration off of older Intel-based macOS infrastructure</p>
</li>
<li>
<p>Jonathan Moss migrated Firefox CI’s cloud-based Windows testing from Windows 11 24H2 to 25H2, moving the bulk of Firefox’s Windows test coverage to Microsoft’s latest platform and keeping CI aligned with the Windows version most commonly used by Firefox Desktop users</p>
</li>
<li>
<p>Florian Quèze <a href="https://tests.firefox.dev/" rel="noopener nofollow ugc">created many dashboards</a> to help dig into Mochitests and XPCShell tests</p>
</li>
<li>
<p>Ryan VanderMeulen landed a set of improvements to <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2032657">mach try chooser</a>. The update adds an exclude filter, a clearer preview pane with removable job rows, an artifact-builds toggle, and a warning when a selection exceeds task-prioritization thresholds. It also fixes a bug where choosing Firefox for Android jobs would unintentionally clear selections for other platforms.</p>
</li>
</ul>
<h4><a class="anchor" href="https://discourse.mozilla.org/#p-295620-lint-static-analysis-and-code-coverage-image27x27uploadkn3nhhyhkaolavr6gxkheo6anzipng-7" name="p-295620-lint-static-analysis-and-code-coverage-image27x27uploadkn3nhhyhkaolavr6gxkheo6anzipng-7"></a>Lint, Static Analysis and Code Coverage <div class="lightbox-wrapper"><a class="lightbox" href="https://us1.discourse-cdn.com/flex001/uploads/mozilla/original/3X/9/1/91b73ae1a5bbfd19ca329cc65f4d62b37af7e5aa.png" rel="noopener nofollow ugc" title="image"><img alt="image" height="27" src="https://us1.discourse-cdn.com/flex001/uploads/mozilla/optimized/3X/9/1/91b73ae1a5bbfd19ca329cc65f4d62b37af7e5aa_2_27x27.png" width="27"></a></div></h4>
<ul>
<li>
<p>Valentin Rigal and Bastien Abadie created a Code Review Bot prototype for publication of review comments using various source linters on Github</p>
</li>
<li>
<p>Morgan Rae Reschenberg added support for accessibility review to Code Review Bot</p>
</li>
</ul>
<h4><a class="anchor" href="https://discourse.mozilla.org/#p-295620-mozregression-image39x39uploadylbryrsvu4qhpj3mc4hc711j7vtpng-8" name="p-295620-mozregression-image39x39uploadylbryrsvu4qhpj3mc4hc711j7vtpng-8"></a>Mozregression <div class="lightbox-wrapper"><a class="lightbox" href="https://us1.discourse-cdn.com/flex001/uploads/mozilla/original/3X/f/0/f0af28d9caa6771eea75f11a03fc36a70c4f99d3.png" rel="noopener nofollow ugc" title="image"><img alt="image" height="39" src="https://us1.discourse-cdn.com/flex001/uploads/mozilla/original/3X/f/0/f0af28d9caa6771eea75f11a03fc36a70c4f99d3.png" width="39"></a></div></h4>
<ul>
<li>Zeid fixed a bug in mozregression-gui on macOS, where the camera and microphone capture request was getting rejected (released in 7.3.0). Thanks to bug report + tip from Andreas Pehrson.</li>
</ul>
<h4><a class="anchor" href="https://discourse.mozilla.org/#p-295620-pdfjs-image29x29upload2uk22g71cqevreav3jhzijhygjypng-9" name="p-295620-pdfjs-image29x29upload2uk22g71cqevreav3jhzijhygjypng-9"></a>PDF.js <div class="lightbox-wrapper"><a class="lightbox" href="https://us1.discourse-cdn.com/flex001/uploads/mozilla/original/3X/1/4/14623e0fefd12c91cad11a97baf9fca17c37df1c.png" rel="noopener nofollow ugc" title="image"><img alt="image" height="29" src="https://us1.discourse-cdn.com/flex001/uploads/mozilla/original/3X/1/4/14623e0fefd12c91cad11a97baf9fca17c37df1c.png" width="29"></a></div></h4>
<ul>
<li>
<p>Calixte <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2034982">added about:pdf to use an entrypoint</a> for opening and editing arbitrary PDF files[image]</p>
</li>
<li>
<p>Calixte added support for playing videos/sounds embedded in PDF files</p>
</li>
</ul>
<h4><a class="anchor" href="https://discourse.mozilla.org/#p-295620-phabricator-image24x24upload2ptgi5cxdz7gakmm6kmos0gcoebpng-moz-phab-and-lando-image31x31uploadgmikcks6na3yujyuukfnivfqrmwpng-10" name="p-295620-phabricator-image24x24upload2ptgi5cxdz7gakmm6kmos0gcoebpng-moz-phab-and-lando-image31x31uploadgmikcks6na3yujyuukfnivfqrmwpng-10"></a>Phabricator <img alt="image" height="24" src="https://us1.discourse-cdn.com/flex001/uploads/mozilla/original/3X/1/3/13d60ed2ffbfe1aa32c2cc2ccc5121ba3b8c5a87.png" width="24">, moz-phab, and Lando <div class="lightbox-wrapper"><a class="lightbox" href="https://us1.discourse-cdn.com/flex001/uploads/mozilla/original/3X/7/5/75a4b58f20908eed139910e672355b6e4ac88562.png" rel="noopener nofollow ugc" title="image"><img alt="image" height="31" src="https://us1.discourse-cdn.com/flex001/uploads/mozilla/original/3X/7/5/75a4b58f20908eed139910e672355b6e4ac88562.png" width="31"></a></div></h4>
<ul>
<li>
<p>Connor Sheehan improved the uplift experience by leveraging Lando to manage the assessment forms, train selection, and automatic application, so conflicts are detected earlier. The number of uplifts via Lando has <a href="https://sql.telemetry.mozilla.org/dashboard/uplift-dashboard?p_date_range=d_last_12_months">out-paced</a> those via Moz-Phab, and sailed through the rise in uplift numbers (likely due to more sec-bugs getting fixed and uplifted).</p>
</li>
<li>
<p>Zeid added support for private GitHub repositories in Lando, allowing security patches to be implemented in a private clone of a repo, and pushed to the public one.</p>
</li>
<li>
<p>Olivier Mehani finalized support for using the new Lando instance for try-pushes. This brings a host of QoL improvements which weren’t backported to the old instance: better UTF-8 support, smarter conflict resolution and improved security and authentication. It is <a href="https://sql.telemetry.mozilla.org/dashboard/new-lando-try-dashboard?p_date_range=d_last_7_days&amp;p_repo_name=try">now processing about 1500 pushes / week</a> (old Lando still processes about 50 / week).</p>
</li>
<li>
<p>Magnolia Liu implemented automatic pushes to Try for uplift requests, for faster feedback in case of issues.</p>
</li>
<li>
<p>Olivier Mehani added a view of a user’s current and recent jobs on <a href="https://lando.moz.tools/" rel="noopener nofollow ugc">the landing page of Lando</a> when authenticated.</p>
</li>
<li>
<p>Zeid identified and fixed the causes of some stability and reliability issues in Lando, which were causing increased downtime during deployments and on an ongoing basis.</p>
</li>
<li>
<p>Olivier Mehani deployed a PoC of reviewer selection on the GitHub pilot, allowing Herald-like mechanisms to GitHub PRs.</p>
</li>
<li>
<p>Olivier Mehani and Connor Sheehan (with Corey Bryant and Daniel Darnell) migrated the COMM project to GitHub <a href="http://github.com/thunderbird/thunderbird-desktop" rel="noopener nofollow ugc">https://github.com/thunderbird/thunderbird-desktop</a>, sharing Firefox’s syncing model.</p>
</li>
</ul>
<h4><a class="anchor" href="https://discourse.mozilla.org/#p-295620-release-management-and-engineering-image29x29uploadgyvgvdmglodpm14lqcrvtdappfzpng-11" name="p-295620-release-management-and-engineering-image29x29uploadgyvgvdmglodpm14lqcrvtdappfzpng-11"></a>Release Management and Engineering <div class="lightbox-wrapper"><a class="lightbox" href="https://us1.discourse-cdn.com/flex001/uploads/mozilla/original/3X/7/6/76f9deb903b684961e54fa3afbdabcc30db09731.png" rel="noopener nofollow ugc" title="image"><img alt="image" height="29" src="https://us1.discourse-cdn.com/flex001/uploads/mozilla/optimized/3X/7/6/76f9deb903b684961e54fa3afbdabcc30db09731_2_29x29.png" width="29"></a></div></h4>
<ul>
<li>
<p>Donal Meehan drove the Release Management team’s move to a weekly scheduled dot release cadence for Desktop and Android, starting with Firefox 151. This allows us to deliver fixes and approved uplifts to users faster and more predictably. This change is expected to reduce unplanned releases, improve release flexibility, and create a more consistent release rhythm across teams.</p>
</li>
<li>
<p>Dianna Smith drove the update to the Release Management team’s <a href="https://docs.google.com/document/d/1oktCbzZ3M7NZTMBxv8yEOYmNHHxaIstZ55vRMI9PmzM/edit?tab=t.0#heading=h.r7335u1pggl8" rel="noopener nofollow ugc">Desktop major release rollout process</a>, starting with Firefox 152. Instead of throttling to 0% on day 2, it will remain at 25% rollout for two days before moving to 100%, unless any issues arise. This should help us collect uptake and stability signals earlier while still allowing time to catch problems before full rollout.</p>
</li>
<li>
<p>Pascal Chevrel completed the update to the dictionaries shipped with Firefox Desktop. The update added eleven new dictionaries, covering Croatian, English (UK), Georgian, Persian, Slovenian, Tajik, Tamil, Tibetan, Turkish, Welsh, and Xhosa, and refreshed nine others. This expanded the number of locales with a built-in spellchecker from 30 to 41 beginning in Firefox 152. Special thanks to Francesco Lodolo, Bryan Olsson, and the localization community for reviewing the patches and helping assess the quality of the dictionaries.</p>
</li>
<li>
<p>Pascal Chevrel delivered a range of improvements to <a href="https://whattrainisitnow.com/" rel="noopener nofollow ugc">WhatTrainIsItNow</a>, including expanded it to cover weekly dot releases and ESR planned dot releases, added new uplift views including a <a href="https://whattrainisitnow.com/release/uplifts/" rel="noopener nofollow ugc">dot-release uplifts page</a> and a <a href="https://whattrainisitnow.com/beta/uplifts/graph/" rel="noopener nofollow ugc">beta uplift graph</a>, and published <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2045812">new APIs</a> that surface train-selection and <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2044143">uplift guidance inside Lando</a>. He also made performance improvements and a steady stream of fixes across the site.</p>
</li>
<li>
<p>At Pwn2Own 2026, Firefox came through with no successful exploits, thanks to preparation across many teams and individuals. Within Release Management, Ryan VanderMeulen drove pre-event patch readiness and Dianna Smith coordinated the releases during the event, including the 150.0.3 dot release, which mitigated the root cause behind several of the contest entries.</p>
</li>
<li>
<p>Dianna Smith built out release-health monitoring and alerting in Bigeye, giving Release Management a growing set of automated alerts that surface data anomalies earlier to aid in release health and regression detection. To make the capability easy to extend, she also <a href="https://docs.google.com/document/d/11WAYaMt2RQOAZLjYti3VZY6Bcws1fjF5q8hBlYUKgHo/edit?tab=t.0" rel="noopener nofollow ugc">created a guide for other teams</a> to add monitoring and alerts for the areas they know best. Teams that want an earlier signal on their own metrics are encouraged to use the guide and help grow the coverage.</p>
</li>
</ul>
<h4><a class="anchor" href="https://discourse.mozilla.org/#p-295620-release-operations-12" name="p-295620-release-operations-12"></a>Release Operations <img alt=":wrench:" class="emoji" height="20" src="https://emoji.discourse-cdn.com/twitter/wrench.png?v=15" title=":wrench:" width="20"></h4>
<ul>
<li>
<p>Ryan Curran built <a href="https://github.com/mozilla-platform-ops/hangar" rel="noopener nofollow ugc">Hangar</a>, a live dashboard for monitoring Firefox CI’s worker pools. It consolidates fleet data from several systems into one view, giving Release Operations a single place to check fleet health and catch problems such as missing or quarantined workers early.</p>
</li>
<li>
<p>Ryan Curran created the <a href="https://github.com/mozilla-platform-ops/BuildWatch" rel="noopener nofollow ugc">iOS version of BuildWatch</a>, and Andrew Erickson ported it to <a href="https://github.com/mozilla-platform-ops/BuildWatch-Android" rel="noopener nofollow ugc">Android</a>. BuildWatch lets you monitor Firefox CI try pushes from your phone, including live per-platform build status, failure summaries, and one-tap retriggers. It uses only public APIs, so no VPN is required.</p>
</li>
<li>
<p>Andrew Erickson and Mark Cornmesser developed <a href="https://github.com/mozilla-platform-ops/fleetbench" rel="noopener nofollow ugc">Fleetbench</a>, a tool for benchmarking Firefox CI workers. It currently measures CPU and ADB/USB I/O performance, helping Release Operations identify slow or outlier hosts before they skew performance test results such as Speedometer and trigger noisy or false regressions.</p>
</li>
<li>
<p>Andrew Erickson built <a href="https://pool-classifier.relops.mozilla.com/" rel="noopener nofollow ugc">Pool Classifier</a>, a web app for viewing per-worker success rates across Taskcluster worker pools. It classifies newly completed tasks every 15 minutes, giving Release Operations a continuously updated view of worker health and helping surface problematic workers proactively.</p>
</li>
<li>
<p>Andrew Erickson created <a href="https://github.com/mozilla-platform-ops/fleetroll_mvp" rel="noopener nofollow ugc">Fleetroll</a>, a command-line tool Release Operations uses to manage and monitor long-running Linux, macOS, and Windows hardware hosts in Firefox CI Taskcluster. It deploys Puppet branch overrides and Vault secrets, audits what is actually applied, and surfaces each host’s Puppet and Taskcluster state in a live dashboard.</p>
</li>
<li>
<p>Mark Cornmesser built out a set of new worker-metrics dashboards in Yardstick, giving Release Operations clearer real-time visibility into the health of the Firefox CI hardware fleet. These include <a href="https://yardstick.mozilla.org/d/linux-all-status-v1/linux-all-status?orgId=1&amp;from=now-6h&amp;to=now&amp;timezone=browser&amp;var-pool=%24__all&amp;var-hostname=%24__all">Linux worker</a> status, <a href="https://yardstick.mozilla.org/d/windows-all-metrics-v1/windows-all-metrics?orgId=1&amp;from=now-6h&amp;to=now&amp;timezone=browser&amp;var-pool=%24__all&amp;var-hostname=%24__all">Windows worker CPU and disk</a> metrics, and a <a href="https://yardstick.mozilla.org/d/windows-pickup-wait-timeline-v1/066c1e0?orgId=1&amp;from=now-24h&amp;to=now&amp;timezone=browser&amp;var-pool=%24__all">Windows job pickup and wait</a> timeline, with alerting on key thresholds. The full set lives in the <a href="https://yardstick.mozilla.org/dashboards/f/cffmfl1sfr1moe/fxci-hardware-workers">FXCI Hardware Workers folder</a> in Yardstick.</p>
</li>
<li>
<p>Jonathan Moss expanded cloud cost reporting in Looker, adding <a href="https://mozilla.cloud.looker.com/dashboards/2861?Submission%20Date=30%20day&amp;Cloud%20Provider=" rel="noopener nofollow ugc">Azure support</a> alongside the existing GCP data and a cloud-provider filter on the FXCI task overview dashboard. The team can now break down Firefox CI compute costs by cloud provider, making it easier to track and compare spend across Azure and GCP.</p>
</li>
</ul>
<h4><a class="anchor" href="https://discourse.mozilla.org/#p-295620-taskcluster-image20x25uploado7keh2uqbjtt24xnmh0gz4v0lympng-13" name="p-295620-taskcluster-image20x25uploado7keh2uqbjtt24xnmh0gz4v0lympng-13"></a>Taskcluster <img alt="image" height="25" src="https://us1.discourse-cdn.com/flex001/uploads/mozilla/original/3X/a/9/a9086272fd26499516b5a852c89ed3f55df11142.png" width="20"></h4>
<ul>
<li>
<p>Yaraslau Kurmyza added Azure fast deprovision <a href="https://github.com/taskcluster/taskcluster/pull/8790" rel="noopener nofollow ugc">taskcluster#8790</a>  and concurrency <a href="https://github.com/taskcluster/taskcluster/issues/8815" rel="noopener nofollow ugc">taskcluster#8815</a> to improve worker scanner performance. This shows ~2x-4x scan time improvements already.</p>
</li>
<li>
<p>Contributor <a href="https://github.com/nitishagar" rel="noopener nofollow ugc">nitishagar</a>  and Yaraslau Kurmyza added patches <a href="https://github.com/taskcluster/taskcluster/pull/8514" rel="noopener nofollow ugc">taskcluster#8514</a>,  <a href="https://github.com/taskcluster/taskcluster/pull/8784" rel="noopener nofollow ugc">taskcluster#8784</a>  to support compression in Taskcluster services API and Yarik worked with Fastly to resolve broken brotli support on the WAF edge side. Now services transmit significantly less data.</p>
</li>
<li>
<p>Yarik added a dedicated service account to log with read only permissions <a href="https://github.com/mozilla/webservices-infra/pull/11197" rel="noopener nofollow ugc">webservices-infra#11197</a>. This allows <a href="https://github.com/taskcluster/tc-logview/pull/4" rel="noopener nofollow ugc">tc-logview</a> to be used safely by untrusted agents inside containers with narrow short-lived access tokens.</p>
</li>
<li>
<p>Yarik published <a href="http://35.202.240.190/" rel="noopener nofollow ugc">queue forecasting dashboard</a> experiments that continuously collects task events and trains models to enable and improve predictions on a task level (how long will it run, and when will it start). With future plans including extending it to the whole task group (mach try)</p>
</li>
</ul>
<h4><a class="anchor" href="https://discourse.mozilla.org/#p-295620-treeherder-image32x32upload9mg2vslsdl1se97nhycpirqkvuvpng-14" name="p-295620-treeherder-image32x32upload9mg2vslsdl1se97nhycpirqkvuvpng-14"></a>Treeherder <img alt="image" height="32" src="https://us1.discourse-cdn.com/flex001/uploads/mozilla/original/3X/4/4/449439d59f33f7cc62df6501dd75c5f88d6f5fe5.png" width="32"></h4>
<ul>
<li>
<p>Florian Quèze added <a href="https://github.com/mozilla/treeherder/pull/9540" rel="noopener nofollow ugc">treeherder#9540</a> “Show task group profile” item to the push action menu</p>
</li>
<li>
<p>Cameron Dawson, juungo and moijes12 implemented various Treeherder API performance improvements</p>
</li>
<li>
<p>Heitor Neiva added Git branch labels to pushes in Treeherder</p>
</li>
<li>
<p>Andrew Halberstadt <a href="https://github.com/mozilla/treeherder/pull/9496" rel="noopener nofollow ugc">implemented</a> the ability for Treeherder to display multiple Git branches at once, enabling support for “try like” repositories in Github</p>
</li>
</ul>
<h4><a class="anchor" href="https://discourse.mozilla.org/#p-295620-version-control-image35x35uploadfgrydspdrdwuflvmedhcxxzrhwtpng-15" name="p-295620-version-control-image35x35uploadfgrydspdrdwuflvmedhcxxzrhwtpng-15"></a>Version Control <div class="lightbox-wrapper"><a class="lightbox" href="https://us1.discourse-cdn.com/flex001/uploads/mozilla/original/3X/6/d/6ded138b62af5c8222b8f5fab637590ba2920993.png" rel="noopener nofollow ugc" title="image"><img alt="image" height="35" src="https://us1.discourse-cdn.com/flex001/uploads/mozilla/original/3X/6/d/6ded138b62af5c8222b8f5fab637590ba2920993.png" width="35"></a></div></h4>
<ul>
<li>
<p>Upgrade <a href="http://hg.mozilla.org/">hg.mozilla.org</a> to Mercurial 7.2.2</p>
</li>
<li>
<p>Created the <a href="https://hg-edge.mozilla.org/releases/mozilla-esr153">mozilla-esr153</a> and <a href="https://hg-edge.mozilla.org/releases/comm-esr153">comm-esr153</a> repositories.</p>
</li>
</ul>
<h4><a class="anchor" href="https://discourse.mozilla.org/#p-295620-other-image30x30upload1b45rv2lz4qu5bjwdcrkbeihtshpng-16" name="p-295620-other-image30x30upload1b45rv2lz4qu5bjwdcrkbeihtshpng-16"></a>Other <div class="lightbox-wrapper"><a class="lightbox" href="https://us1.discourse-cdn.com/flex001/uploads/mozilla/original/3X/0/8/08426801fd78ca4953d83a1589119ec724b9c801.png" rel="noopener nofollow ugc" title="image"><img alt="image" height="30" src="https://us1.discourse-cdn.com/flex001/uploads/mozilla/original/3X/0/8/08426801fd78ca4953d83a1589119ec724b9c801.png" width="30"></a></div></h4>
<ul>
<li>Sylvestre converted our documentation from reStructuredText to MyST flavored Markdown</li>
</ul>
<p>Thanks for reading and see you next quarter!</p>
            <p><small>1 post - 1 participant</small></p>
            <p><a href="https://discourse.mozilla.org/t/engineering-effectiveness-newsletter-q2-2026-edition/148883">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Fotos & Gemini Omni: Neue KI-Videobearbeitung wird ausgerollt – bringt schnelle Korrekturen (Video)]]></title>
<description><![CDATA[Die Fotoplattform Google Fotos bietet seit vielen Jahren starke Möglichkeiten zur Bildbearbeitung und ist dank KI zuletzt auch immer stärker in die Videobearbeitung vorgedrungen - jetzt geht man den nächsten Schritt. In diesen Tagen wird das neue Video Remix mit Gemini Omni ausgerollt, das umfang...]]></description>
<link>https://tsecurity.de/de/3657746/it-nachrichten/google-fotos-gemini-omni-neue-ki-videobearbeitung-wird-ausgerollt-bringt-schnelle-korrekturen-video/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657746/it-nachrichten/google-fotos-gemini-omni-neue-ki-videobearbeitung-wird-ausgerollt-bringt-schnelle-korrekturen-video/</guid>
<pubDate>Thu, 09 Jul 2026 18:35:59 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="640" height="360" src="https://www.googlewatchblog.de/wp-content/uploads/gemini-omni-logo-1024x576.jpg" class="attachment-large size-large wp-post-image" alt="gemini omni logo" decoding="async" fetchpriority="high" srcset="https://www.googlewatchblog.de/wp-content/uploads/gemini-omni-logo-1024x576.jpg 1024w, https://www.googlewatchblog.de/wp-content/uploads/gemini-omni-logo-300x169.jpg 300w, https://www.googlewatchblog.de/wp-content/uploads/gemini-omni-logo-768x432.jpg 768w, https://www.googlewatchblog.de/wp-content/uploads/gemini-omni-logo-640x360.jpg 640w, https://www.googlewatchblog.de/wp-content/uploads/gemini-omni-logo-800x450.jpg 800w, https://www.googlewatchblog.de/wp-content/uploads/gemini-omni-logo.jpg 1500w" sizes="(max-width: 640px) 100vw, 640px"><br>Die Fotoplattform <a href="https://www.googlewatchblog.de/2026/06/google-fotos-neue-ki-funktion-sortiert-eure-kleidung-laesst-euch-neue-outfits-kreieren-und-anprobieren-video/"><strong>Google Fotos</strong></a> bietet seit vielen Jahren starke Möglichkeiten zur Bildbearbeitung und ist dank KI zuletzt auch immer stärker in die Videobearbeitung vorgedrungen - jetzt geht man den nächsten Schritt. In diesen Tagen wird das neue <strong>Video Remix mit Gemini Omni</strong> ausgerollt, das umfangreiche Videobearbeitungsmöglichkeiten direkt in die Android-App bringt.</p>
<p>Mehr lesen: <a href="https://www.googlewatchblog.de/2026/07/google-fotos-gemini-omni-neue-ki-videobearbeitung-wird-ausgerollt-bringt-schnelle-korrekturen-video/">Google Fotos &amp; Gemini Omni: Neue KI-Videobearbeitung wird ausgerollt – bringt schnelle Korrekturen (Video)</a></p>
<hr>
<p></p><center><a href="https://www.google.com/preferences/source?q=googlewatchblog.de"><img src="https://www.googlewatchblog.de/wp-content/uploads/googlebevorzugt.webp" alt="GoogleWatchBlog als bevorzugte Quelle bei Google hinzufügen" width="284" height="90"></a></center><br><center><strong>Keine Google-News mehr verpassen:</strong> <a href="https://news.google.com/publications/CAAqLggKIihDQklTR0FnTWFoUUtFbWR2YjJkc1pYZGhkR05vWW14dlp5NWtaU2dBUAE?hl=de"><strong>GoogleWatchBlog bei Google News abonnieren</strong></a></center>
<hr>
<p></p><center><a href="https://ssl-vg03.met.vgwort.de/na/bc044b28895d46b6b00b93964f38bc84"><img alt="vgwort" src="https://ssl-vg03.met.vgwort.de/na/bc044b28895d46b6b00b93964f38bc84" width="16" height="16"></a></center>
<p>Der Beitrag <a href="https://www.googlewatchblog.de/2026/07/google-fotos-gemini-omni-neue-ki-videobearbeitung-wird-ausgerollt-bringt-schnelle-korrekturen-video/">Google Fotos &amp; Gemini Omni: Neue KI-Videobearbeitung wird ausgerollt – bringt schnelle Korrekturen (Video)</a> erschien zuerst auf <a href="https://www.googlewatchblog.de/">GoogleWatchBlog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta Muse Image macht Instagram-Fotos per @-Mention für KI wiederverwendbar]]></title>
<description><![CDATA[BERLIN / LONDON (IT BOLTWISE) – Meta führt mit „Muse Image“ ein KI-Bildmodell ein, das öffentliche Instagram-Posts und Reels automatisch in neue KI-Ergebnisse einbeziehen kann. Nutzer können per @-Mention bestimmte Instagram-Profile in eigene Entwürfe integrieren und daraus neue Reels, Posts oder...]]></description>
<link>https://tsecurity.de/de/3656377/it-security-nachrichten/meta-muse-image-macht-instagram-fotos-per-mention-fuer-ki-wiederverwendbar/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656377/it-security-nachrichten/meta-muse-image-macht-instagram-fotos-per-mention-fuer-ki-wiederverwendbar/</guid>
<pubDate>Thu, 09 Jul 2026 10:38:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-meta-muse-instagram-remix-privacy.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-meta-muse-instagram-remix-privacy.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-meta-muse-instagram-remix-privacy-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-meta-muse-instagram-remix-privacy-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-meta-muse-instagram-remix-privacy-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-meta-muse-instagram-remix-privacy-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-meta-muse-instagram-remix-privacy-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">BERLIN / LONDON (IT BOLTWISE) – Meta führt mit „Muse Image“ ein KI-Bildmodell ein, das öffentliche Instagram-Posts und Reels automatisch in neue KI-Ergebnisse einbeziehen kann. Nutzer können per @-Mention bestimmte Instagram-Profile in eigene Entwürfe integrieren und daraus neue Reels, Posts oder Stories erstellen lassen. Besonders wichtig: Die Funktion ist zunächst standardmäßig aktiviert und kann je […]</p>
<div><a href="https://www.it-boltwise.de/meta-muse-image-macht-instagram-fotos-per-mention-fuer-ki-wiederverwendbar.html">... den vollständigen Artikel <strong>»Meta Muse Image macht Instagram-Fotos per @-Mention für KI wiederverwendbar«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/meta-muse-image-macht-instagram-fotos-per-mention-fuer-ki-wiederverwendbar.html">Meta Muse Image macht Instagram-Fotos per @-Mention für KI wiederverwendbar</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[You Can Now Remix Your Google Photos Into Stylized Videos With Gemini Omni]]></title>
<description><![CDATA[Video Remix is a new Gemini-powered feature in Google Photos that takes a simple approach to editing.]]></description>
<link>https://tsecurity.de/de/3655427/it-nachrichten/you-can-now-remix-your-google-photos-into-stylized-videos-with-gemini-omni/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655427/it-nachrichten/you-can-now-remix-your-google-photos-into-stylized-videos-with-gemini-omni/</guid>
<pubDate>Wed, 08 Jul 2026 22:47:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Video Remix is a new Gemini-powered feature in Google Photos that takes a simple approach to editing.]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Photos adds a new AI ‘Video Remix’ tool]]></title>
<description><![CDATA[The feature can do things like apply cinematic relighting to brighten up a dark clip, swap out a plain background for something fun, or add artistic styles to videos.]]></description>
<link>https://tsecurity.de/de/3655183/it-nachrichten/google-photos-adds-a-new-ai-video-remix-tool/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655183/it-nachrichten/google-photos-adds-a-new-ai-video-remix-tool/</guid>
<pubDate>Wed, 08 Jul 2026 20:32:27 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The feature can do things like apply cinematic relighting to brighten up a dark clip, swap out a plain background for something fun, or add artistic styles to videos.]]></content:encoded>
</item>
<item>
<title><![CDATA[Google announces new 'Video Remix' feature its for AI subscribers]]></title>
<description><![CDATA[It allows you to reimagine videos stored in Google Photos using Gemini Omni.]]></description>
<link>https://tsecurity.de/de/3654925/it-nachrichten/google-announces-new-video-remix-feature-its-for-ai-subscribers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654925/it-nachrichten/google-announces-new-video-remix-feature-its-for-ai-subscribers/</guid>
<pubDate>Wed, 08 Jul 2026 19:17:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It allows you to reimagine videos stored in Google Photos using Gemini Omni.]]></content:encoded>
</item>
<item>
<title><![CDATA[Create shareable video clips in seconds with Video Remix in Google Photos.]]></title>
<description><![CDATA[With Video Remix in Google Photos, you can transform ordinary videos into share-worthy moments in just a few taps.]]></description>
<link>https://tsecurity.de/de/3654921/it-nachrichten/create-shareable-video-clips-in-seconds-with-video-remix-in-google-photos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654921/it-nachrichten/create-shareable-video-clips-in-seconds-with-video-remix-in-google-photos/</guid>
<pubDate>Wed, 08 Jul 2026 19:17:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/05_Google_Photo_Video_Remix_Soc.max-600x600.format-webp.webp">With Video Remix in Google Photos, you can transform ordinary videos into share-worthy moments in just a few taps.]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Photos Video Remix Feature Launches]]></title>
<description><![CDATA[Building on the Remix feature for photos in your Google Photos app, Google is introducing Video Remix today. This new Google Photos Video Remix feature utilizes Gemini Omni to let you take videos and make them stylized videos from a set of templates. You’ll find it in the “Create” tab at the bott...]]></description>
<link>https://tsecurity.de/de/3654920/it-nachrichten/google-photos-video-remix-feature-launches/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654920/it-nachrichten/google-photos-video-remix-feature-launches/</guid>
<pubDate>Wed, 08 Jul 2026 19:17:04 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Building on the Remix feature for photos in your Google Photos app, Google is introducing Video Remix today. This new Google Photos Video Remix feature utilizes Gemini Omni to let you take videos and make them stylized videos from a set of templates. You’ll find it in the “Create” tab at the bottom of your...</p>
<p>Read the original post: <a href="https://www.droid-life.com/2026/07/08/google-photos-video-remix-feature/">Google Photos Video Remix Feature Launches</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Crusoe brings serverless fine-tuning to AI model development]]></title>
<description><![CDATA[Crusoe has announced Serverless Fine-Tuning and Self-Serve Deployments in Crusoe Intelligence Foundry, the managed AI platform for Crusoe Cloud. These capabilities give data scientists and ML engineers a complete path from proprietary data to production-ready models, on purpose-built AI infrastru...]]></description>
<link>https://tsecurity.de/de/3653886/it-security-nachrichten/crusoe-brings-serverless-fine-tuning-to-ai-model-development/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653886/it-security-nachrichten/crusoe-brings-serverless-fine-tuning-to-ai-model-development/</guid>
<pubDate>Wed, 08 Jul 2026 11:52:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Crusoe has announced Serverless Fine-Tuning and Self-Serve Deployments in Crusoe Intelligence Foundry, the managed AI platform for Crusoe Cloud. These capabilities give data scientists and ML engineers a complete path from proprietary data to production-ready models, on purpose-built AI infrastructure, without the overhead of managing it. Fine-tuning is now a standard part of building with open-source AI models, and as open-weight models catch up to proprietary models, more teams are choosing to customize with their … <a href="https://www.helpnetsecurity.com/2026/07/08/crusoe-serverless-fine-tuning/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/08/crusoe-serverless-fine-tuning/">Crusoe brings serverless fine-tuning to AI model development</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The 2026 guide to eSignatures: Evaluating security, cost, and ROI]]></title>
<description><![CDATA[Choosing the right eSign solution is less about picking the tool with the most bells and whistles and more about confirming that the features support your company’s requirements for security and compliance, workflow automation, cost-effectiveness, and operational efficiency.



The best eSign sol...]]></description>
<link>https://tsecurity.de/de/3652805/it-security-nachrichten/the-2026-guide-to-esignatures-evaluating-security-cost-and-roi/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652805/it-security-nachrichten/the-2026-guide-to-esignatures-evaluating-security-cost-and-roi/</guid>
<pubDate>Tue, 07 Jul 2026 23:35:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Choosing the right eSign solution is less about picking the tool with the most bells and whistles and more about confirming that the features support your company’s requirements for <a href="https://www.gonitro.com/resources/security-compliance?utm_source=foundry&amp;utm_medium=referral&amp;utm_campaign=The+2026+Guide+to+eSignatures%3A+Evaluating+Security%2C+Cost%2C+and+ROI" rel="sponsored">security and compliance</a>, workflow automation, cost-effectiveness, and operational efficiency.</p>



<p><a href="https://www.gonitro.com/best-esign-software?utm_source=foundry&amp;utm_medium=referral&amp;utm_campaign=The+2026+Guide+to+eSignatures%3A+Evaluating+Security%2C+Cost%2C+and+ROI" rel="sponsored">The best eSign solutions</a> let teams securely collect legally binding electronic signatures while <a href="https://www.gonitro.com/integrations?utm_source=foundry&amp;utm_medium=referral&amp;utm_campaign=The+2026+Guide+to+eSignatures%3A+Evaluating+Security%2C+Cost%2C+and+ROI" rel="sponsored">integrating signing workflows</a> with business systems, compliance controls, and document lifecycle processes — evaluated across four factors: security and compliance, workflow integration, total cost of ownership, and measurable business ROI.</p>



<p>When evaluating eSignature solutions, look beyond signing functionality and consider these four factors:</p>



<ul class="wp-block-list">
<li>Security and compliance</li>



<li>Workflow integration</li>



<li>Total cost of ownership</li>



<li>Measurable business ROI</li>
</ul>



<h2 class="wp-block-heading">Security and compliance are the foundation of eSignatures</h2>



<p>Yes, you want eSigning to be convenient, but it’s arguably even more important that your eSignature solution provides the security, auditability, and legal validity required to support critical business transactions.</p>



<p><strong>Look for solutions that offer:</strong></p>



<ul class="wp-block-list">
<li>Comprehensive <a href="https://www.gonitro.com/resources/esignature-audit-trials?utm_source=foundry&amp;utm_medium=referral&amp;utm_campaign=The+2026+Guide+to+eSignatures%3A+Evaluating+Security%2C+Cost%2C+and+ROI">audit trails</a></li>



<li>Strong authentication controls</li>



<li>Encryption in transit and at rest</li>



<li>Support for established legal frameworks (e.g., the ESIGN Act, UETA, eIDAS)</li>
</ul>



<p>Independent certifications, including <a href="https://www.gonitro.com/security-compliance?utm_source=foundry&amp;utm_medium=referral&amp;utm_campaign=The+2026+Guide+to+eSignatures%3A+Evaluating+Security%2C+Cost%2C+and+ROI" rel="sponsored">SOC 2 Type II</a> and ISO 27001, provide additional assurance that an eSign vendor follows recognized security and information management practices.</p>



<h2 class="wp-block-heading">The signature is only one step in the document lifecycle</h2>



<p><strong>During the digital signing process, documents typically move through multiple workflows:</strong></p>



<p>During the digital signing process, documents typically move through multiple stages: creation, review, approval, signature collection, storage, reporting, and retention.</p>



<p>Consider a typical sales contract: it might originate in a CRM, require review and approval from finance, get routed for signature, then need to be stored in a repository, reported on for compliance, and retained per policy. If each of these steps happens in a separate, disconnected tool, the signature may be digital, but the workflow is still manual.</p>



<p>When one or more of these steps rely on email attachments, manual routing, or moving files across disconnected applications, delays and inefficiencies quickly snowball.</p>



<p>An eSignature platform that supports <a href="https://www.gonitro.com/automate?utm_source=foundry&amp;utm_medium=referral&amp;utm_campaign=The+2026+Guide+to+eSignatures%3A+Evaluating+Security%2C+Cost%2C+and+ROI">document workflow automation</a> can help you avoid this by connecting approval workflows, document routing, signature collection, and archival processes into a low-friction experience.</p>



<h2 class="wp-block-heading">Evaluating the true cost of ownership of an eSignature solution</h2>



<p>When you’re evaluating the cost of eSignature solutions, <a href="https://www.gonitro.com/pricing?utm_source=foundry&amp;utm_medium=referral&amp;utm_campaign=The+2026+Guide+to+eSignatures%3A+Evaluating+Security%2C+Cost%2C+and+ROI">subscription pricing</a> only tells part of the story. The solution with a lower upfront cost may require additional integrations, administrative effort, training, or support resources that increase long-term expenditure.</p>



<p><strong>When calculating total cost of ownership, be sure to consider:</strong></p>



<ul class="wp-block-list">
<li>Licensing and transaction costs</li>



<li>Implementation and integration requirements</li>



<li>Administrative overhead</li>



<li>User adoption and training</li>



<li>Compliance and audit support</li>



<li>Scalability as your business needs evolve</li>
</ul>



<h2 class="wp-block-heading">How to measure eSignature ROI</h2>



<p>Traditionally, the value proposition for eSignature software was that it reduced paper, printing, and shipping costs. Today, the value is firmly centered on operational outcomes, including:</p>



<ul class="wp-block-list">
<li>Contract turnaround times</li>



<li>Employee onboarding speed</li>



<li>Approval cycle duration</li>



<li>Manual labor reduction</li>



<li>Error elimination</li>



<li>Compliance risk mitigation</li>



<li>Customer and employee experience improvements</li>
</ul>



<p>For example, reducing contract processing from days to hours can have a greater business impact than eliminating printing costs. Similarly, automated approval workflows can take over repetitive administrative tasks, freeing up employees to work on higher-value initiatives.</p>



<h2 class="wp-block-heading"><a></a>What to look for in an eSignature solution</h2>



<p>As eSignature technology matures, the evaluation criteria have expanded beyond ease of signing. Today, organizations need solutions that can support compliance requirements, integrate with existing business systems, automate document workflows, and scale alongside broader digital transformation initiatives.</p>



<p><strong>When comparing eSignature solutions, don’t just look at signing capabilities. Assess how well each eSign solution supports the entire document lifecycle through:</strong></p>



<ul class="wp-block-list">
<li>Strong security and compliance controls</li>



<li>Support for ESIGN, UETA, and eIDAS requirements</li>



<li>Workflow automation capabilities</li>



<li>Integration with existing business systems</li>



<li>API accessibility for future automation initiatives</li>



<li>Comprehensive audit trails and reporting</li>



<li>Predictable, scalable pricing</li>
</ul>



<p>In 2026, the best eSignature solution isn’t the one with the most features. It’s the one that connects signing to the rest of the document lifecycle while keeping security, cost, and ROI measurable.<a href="https://www.gonitro.com/sign?utm_source=foundry&amp;utm_medium=referral&amp;utm_campaign=The+2026+Guide+to+eSignatures%3A+Evaluating+Security%2C+Cost%2C+and+ROI" rel="sponsored"> </a><a href="https://www.gonitro.com/sign?utm_source=foundry&amp;utm_medium=referral&amp;utm_campaign=The+2026+Guide+to+eSignatures%3A+Evaluating+Security%2C+Cost%2C+and+ROI" rel="sponsored">Nitro Sign</a> is built around that principle: it goes beyond electronic signatures to support secure, compliant, connected document workflows that integrate with the systems teams already use, so governance improves, operations accelerate, and the solution scales with long-term business goals.</p>



<p><strong>Discover why Nitro Sign has been recognized by IDC as a global leader in electronic signature software solutions.</strong></p>



<p><a href="https://www.gonitro.com/contact-sales?utm_source=foundry&amp;utm_medium=referral&amp;utm_campaign=The+2026+Guide+to+eSignatures%3A+Evaluating+Security%2C+Cost%2C+and+ROI" rel="sponsored">Speak with an eSign Expert</a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chinese AI models are attracting US companies with lower prices]]></title>
<description><![CDATA[US companies are increasingly opting for Chinese AI models from firms such as Deepseek and Z.ai, CNBC reports. A key reason is that they offer performance comparable to that of leading US models but at a significantly lower cost.



According to the development platform Openrouter, Chinese models...]]></description>
<link>https://tsecurity.de/de/3652804/it-security-nachrichten/chinese-ai-models-are-attracting-us-companies-with-lower-prices/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652804/it-security-nachrichten/chinese-ai-models-are-attracting-us-companies-with-lower-prices/</guid>
<pubDate>Tue, 07 Jul 2026 23:35:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>US companies are increasingly opting for Chinese AI models from firms such as Deepseek and Z.ai, <a href="https://www.cnbc.com/2026/07/07/chinese-ai-models-costs-us-openai-anthropic.html" rel="nofollow">CNBC</a> reports. A key reason is that they offer performance comparable to that of leading US models but at a significantly lower cost.</p>



<p>According to the development platform Openrouter, Chinese models have accounted for over 30% of the AI tokens used by US companies each week since February. In some weeks, the share has been as high as 46%, compared to an average of 11% over the previous 12 months.</p>



<p>Companies are reportedly increasingly choosing open AI models for tasks that do not require the highest performance. According to Openrouter, Chinese models can be between 60% and 90% cheaper than comparable alternatives from OpenAI and Anthropic.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to go incognito in Chrome, Edge, Firefox, and Safari]]></title>
<description><![CDATA[Private browsing. Incognito. Privacy mode.



Web browser functions like those trace their roots back more than a decade, and the feature — first found in a top browser in 2005 — spread quickly as one copied another, made tweaks and minor improvements.



But privacy-promising labels can be treac...]]></description>
<link>https://tsecurity.de/de/3652543/it-nachrichten/how-to-go-incognito-in-chrome-edge-firefox-and-safari/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652543/it-nachrichten/how-to-go-incognito-in-chrome-edge-firefox-and-safari/</guid>
<pubDate>Tue, 07 Jul 2026 20:51:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Private browsing. Incognito. Privacy mode.</p>



<p>Web browser functions like those trace their roots back more than a decade, and the feature — first found in a top browser in 2005 — spread quickly as one copied another, made tweaks and minor improvements.</p>



<p>But privacy-promising labels can be treacherous. Simply put, going “<a href="https://www.computerworld.com/article/1670600/you-are-not-very-incognito-in-incognito-mode.html" title="Incognito">incognito</a>” is as effective in guarding <a href="https://www.computerworld.com/article/1612064/cookie-conundrum-the-loss-of-third-party-trackers-could-diminish-your-privacy.html">online privacy</a> as witchcraft is in warding off a common cold.</p>



<p>That’s because private browsing is intended to wipe <i>local</i> traces of where you’ve been, what you’ve searched for, the contents of forms you’ve filled. It’s meant to hide, and not always conclusively at that, your tracks from others with access to the personal computer. That’s it.</p>



<h2 class="wp-block-heading">How to keep web browsing private</h2>



<p>We’ve spelled out how to go into incognito or private browsing mode for the four major browsers in this order: </p>



<ul class="wp-block-list">
<li>Google Chrome’s Incognito mode</li>



<li>Microsoft Edge’s InPrivate browsing</li>



<li>Mozilla Firefox’s New Private Window mode</li>



<li>Apple Safari’s New Private window mode</li>
</ul>



<p>At their most basic, these features promise that they won’t record visited sites to the browsing history, save cookies that show you’ve been to and logged into sites, or remember credentials like passwords used during sessions. But your traipses through the web are still <a href="https://www.computerworld.com/article/1611809/what-a-future-without-browser-cookies-will-look-like.html">traceable by Internet providers</a> – and the authorities who serve subpoenas to those entities – employers who control the company network and advertisers who follow your every footstep.</p>



<p>To end that cognitive dissonance, <a href="https://www.computerworld.com/article/1639403/online-privacy-best-browsers-settings-and-tips.html">most browsers have added more advanced privacy tools</a>, generically known as “anti-trackers,” which block various kinds of bite-sized chunks of code that advertisers and websites use to trace where people go in attempts to compile digital dossiers or serve targeted advertisements.</p>



<p>Although it might seem reasonable that a browser’s end game would be to craft a system that blends incognito modes with anti-tracking, it’s highly unlikely. Using either private browsing or anti-tracking carries a cost: site passwords aren’t saved for the next visit or sites break under the tracker scrubbing. Nor are those costs equal. It’s much easier to turn on some level of anti-tracking by default than it would be to do the same for private sessions, as evidenced by the number of browsers that do the former without complaint while <i>none</i> do the latter.</p>



<p>Private browsing will, by necessity, always be a niche, as long as sites rely on cookies for mundane things like log-ins and cart contents.</p>



<p>But the mode remains a useful tool whenever the browser — and the computer it’s on — are shared. To prove that, we’ve assembled instructions and insights on using the incognito features — and anti-tracking tools — offered by the top four browsers: <a title="Google Chrome" href="https://www.computerworld.com/article/1719300/a-mac-user-s-guide-to-the-google-chrome-browser.html">Google Chrome</a>, Microsoft’s <a href="https://www.computerworld.com/article/1713244/how-to-replace-edge-as-windows-default-browser.html">Chromium-based Edge</a>, Mozilla’s Firefox and Apple’s Safari.</p>



<h2 class="wp-block-heading">How to go incognito with Google Chrome</h2>



<p>Although <i>incognito</i> may be a synonym to some users for any browser’s private mode, Google gets credit for grabbing the word as the feature’s snappiest name when it launched the tool in late 2008, just months after Chrome debuted.</p>



<p>The easiest way to open an Incognito window is with the keyboard shortcut combination <strong>Ctrl-Shift-N</strong> (Windows) or <strong>Command-Shift-N</strong> (macOS).</p>



<p>Another way is to click on the menu on the upper right — it’s the three vertical dots — and select <strong>New Incognito Window</strong> from the list.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="876" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Open a new Incognito window in Chrome using keyboard shortcuts or from the menu by choosing “New Incognito window.”</p>
</figcaption></figure><p class="imageCredit">Google</p></div>



<p>The new Incognito window can be recognized by the dark background and the stylized “spy” icon just to the left of the three-dots menu. Chrome also reminds users of just what Incognito does and doesn’t do each time a new window is opened. The message may get tiresome for regular Incognito users, but it may also save a job or reputation; it’s important that users remember Incognito doesn’t prevent ISPs, businesses, schools and organizations from knowing where customers, workers, students, and others went on the web or what they searched for.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="699" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Each time a new Incognito window is opened, Chrome reminds users what Incognito doesn’t save. The browser also puts a toggle on the screen for blocking third-party cookies.</p>
</figcaption></figure><p class="imageCredit">Google</p></div>



<p>Incognito’s introductory screen also displays a toggle — it’s on by default — along with text that states third-party cookies will be blocked while in the privacy mode. Although cookies are never saved locally as long as the user stays in Incognito, websites have been able to track user movements from site to site <i>while within Incognito</i>. Such tracking might be used, for example, to display ads to a user visiting multiple sites in Incognito. This third-party cookie blocking, which halts such behavior, debuted in May 2020.</p>



<p>Google has been experimenting with new language on Chrome’s Incognito introductory page, but it’s yet to make it to the desktop browser. In the Canary build of Chrome on Android, however, the intro now outlines “What Incognito does” and “What Incognito doesn’t do,” to make the mode’s capabilities somewhat clearer to the user. (Some have speculated that the changes were made in reaction to a still-ongoing class-action lawsuit file in 2020 that alleged Google continued to track users’ online behavior and movements in Incognito.)</p>



<p>Once a tab in Incognito has been filled with a website, Chrome continues to remind users that they’re in Incognito by the dark background of the address bar and window title.</p>



<p>A link on an existing page can be opened directly into Incognito by right-clicking the link, then choosing <strong>Open Link in Incognito Window</strong> from the resulting menu.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="876" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>What Incognito looks like after pulling up a website. Note the “spy” icon at the right of the address bar.</p>
</figcaption></figure><p class="imageCredit">Google</p></div>



<p><strong>Pro tip</strong><em><strong>:</strong> To close an Incognito window, shutter it like any other Chrome window by clicking the X in the upper right corner (Windows) or the red dot in the upper left (macOS).</em></p>



<h2 class="wp-block-heading">How to privately browse with Microsoft Edge</h2>



<p>Microsoft borrowed the name of its private browsing mode, InPrivate, from Internet Explorer (IE), the finally-being-retired legacy browser. InPrivate appeared in IE in March 2009, about three months after Chrome’s Incognito and three months before Firefox’s privacy mode. When Edge was first released in 2015 and then relaunched as a clone of Chrome in January 2020, InPrivate was part of the package, too.</p>



<p>At the keyboard, the combination of <strong>Ctrl-Shift-N</strong> (Windows) or <strong>Command-Shift-N</strong> (macOS) opens an InPrivate window.</p>



<p>A slower way to get there is to click on the menu at the upper right — it’s three dots arranged horizontally — and choose <strong>New InPrivate Window</strong> from the menu.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="874" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Like other browsers, Edge will take you incognito from the menu when you pick New InPrivate window.</p>
</figcaption></figure><p class="imageCredit">Microsoft</p></div>



<p>Edge does a more thorough job of explaining what its private browsing mode does and doesn’t do than any of its rivals, with on-screen paragraphs dedicated to describing what data the browser collects in InPrivate and how the strictest additional anti-tracking setting can be called on from within the mode. In addition, Edge uses the more informal “What Incognito does” and “What Incognito doesn’t do” language on its InPrivate introductory screen.</p>



<p>Microsoft’s browser also well marks InPrivate when the mode is operating: an oval marked “In Private” to the right of the address bar combines with a full-black screen to make sure users know where they’re at.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="843" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Edge offers a detailed explanation of what its private browsing mode does and doesn’t do.</p>
</figcaption></figure><p class="imageCredit">Microsoft</p></div>



<p>It’s also possible to launch an InPrivate session by right-clicking a link within Edge and selecting <strong>Open in InPrivate Window</strong>. That option is grayed out when already in a private browsing session but using <strong>Open Link in New Tab</strong> does just that within the current InPrivate frame.</p>



<p>To end InPrivate browsing, simply shut the window by clicking the X in the upper right corner (Windows) or click the red dot at the upper left (macOS).</p>



<p>Although Edge is based on Chromium, the same open-source project that comes up with the code to power Chrome, the Redmond, WA company integrated anti-tracking into its browser. Dubbed “Tracking Prevention,” it works both in Edge’s standard and InPrivate modes.</p>



<p>To set Tracking Prevention, choose <strong>Settings</strong> from the three-ellipses menu at the right, then at the next page, pick <strong>Privacy, Search and Services</strong>. Choose one of the three options — <strong>Basic, Balanced</strong> or <strong>Strict</strong> — and make sure the toggle for <strong>Tracking prevention</strong> is in the “on” position. If you want InPrivate to always default to the harshest anti-tracking — not a bad idea — toggle <strong>Always use “Strict” tracking prevention when browsing InPrivate</strong> to “on.”</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="708" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Toggle Always use Strict to the ‘on’ position and InPrivate will apply the most stringent anti-tracking even though Edge’s standard mode is set to, say, Balanced.</p>
</figcaption></figure><p class="imageCredit">Microsoft</p></div>



<p><strong>Pro tip:</strong> <i>To open Edge with InPrivate — rather than first opening Edge in standard mode, then launching InPrivate — right-click the Edge icon in the Windows taskbar and select <strong>New InPrivate Window</strong> from the list. There is no similar one-step way to do this in macOS.</i></p>



<h2 class="wp-block-heading">How to privately browse with Mozilla Firefox</h2>



<p>After Chrome trumpeted Incognito, browsers without something similar hustled to catch up. Mozilla added its take — dubbed Private Browsing — about six months after Google, in June 2009.</p>



<p>From the keyboard, a private browsing session can be called up using the combination <strong>Ctrl-Shift-P</strong> (Windows) or <strong>Command-Shift-P</strong> (macOS).</p>



<p>Alternately, a private window will open from the menu at the upper right of Firefox — three short horizontal lines — after selecting <strong>New private window</strong>.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="889" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Opening a private browsing window is as simple as choosing New Private Window from the Firefox menu.</p>
</figcaption></figure><p class="imageCredit">Mozilla</p></div>



<p>A private session window is marked by the purple “mask” icon in the title bar of the Firefox frame. In Windows, the icon is to the left of the minimize/maximize/close buttons; on a Mac, the mask squats at the far right of the title bar. Unlike Chrome and Edge, Firefox does not color-code the top components of the browser window to signify the user is in privacy mode.</p>



<p>Like other browsers, Firefox warns users that private browsing is no cure-all for privacy ills but is limited in what it blocks from being saved during a session. “Private window: Firefox clears your search and browsing history when you close all private windows. This doesn’t make you anonymous,” the caution reads.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="654" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Firefox reminds users that while a private session doesn’t save searches or browsing histories, it doesn’t cloak them in complete anonymity. The page also links to more detailed information.</p>
</figcaption></figure><p class="imageCredit">Mozilla</p></div>



<p>A link can be opened into a Firefox Private Window by right-clicking the link, then choosing <strong>Open Link in New Private Window</strong> from the menu.</p>



<p>To close a Private Window, shut it down just as one would any Firefox window by clicking the X in the upper right corner (Windows) or the red dot in the upper left (macOS).</p>



<p>Notable is that Firefox’s private browsing mode is accompanied by the browser’s superb “Enhanced Tracking Protection,” a suite of tracker blocking tools that stymie all sorts of ad-and-site methods for identifying users, then watching and recording their online behavior. While the earliest version of this was offered only inside Private Windows, the expanded technologies also work within standard mode.</p>



<p>Because Enhanced Tracking Protection is enabled by default within Firefox, it doesn’t matter which of its settings — <strong>Standard, Strict</strong> or <strong>Custom</strong> — is selected as far as private browsing goes; everything that can be blocked will be blocked.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>The shield appears in the address bar to note what trackers were blocked by Firefox in a Private Window. Clicking on the icon brings up an accounting of what was barred.</p>
</figcaption></figure><p class="imageCredit">Mozilla</p></div>



<p><strong>Pro tip:</strong> <i>Private Browsing sessions take place over the more secure HTTPS, not the once-standard HTTP protocol. Users don’t need to do anything: The new HTTPS-only policy is on by default. (If the destination site doesn’t support HTTPS, Firefox will go into fallback mode, connecting via HTTP instead.)</i></p>



<h2 class="wp-block-heading">How to browse privately with Apple’s Safari</h2>



<p>Chrome may get far more attention for its Incognito than any other browser — no surprise, since it’s by far the most popular browser on the planet — but Apple’s Safari was actually the first to introduce private browsing. The term <i>private browsing</i> was first bandied in 2005 to describe early Safari features that limited what was saved by the browser.</p>



<p>Side note: Early in private browsing, the label <i>porn mode</i> was often used as a synonym to describe what many writers and reporters assumed was the primary application of the feature. The term has fallen out of favor.</p>



<p>To open what Safari calls a Private Window on a Mac, users can do a three-key combination of <strong>Command-Shift-N</strong>, the same shortcut Chrome adopted. Otherwise, a window can be called up by selecting the <strong>File</strong> menu and clicking on New Private Window.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="803" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>From the File menu in Safari, selecting New Private Window gets you started.</p>
</figcaption></figure><p class="imageCredit">Apple</p></div>



<p>Safari tags each Private Window by darkening the address bar. It also issues a reminder of what it does — or more accurately — what it doesn’t do. “Safari will keep your browsing history private for all tabs of this window. After you close this window, Safari won’t remember the pages you visited, your search history or your AutoFill information,” the top-of-the-page note reads. The warning is more terse than those of other browsers and omits cautions about still-visible online activity.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="321" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>The darkened address bar at the top — and the Private button in the left window corner — signal that this Safari window is for private browsing.</p>
</figcaption></figure><p class="imageCredit">Apple</p></div>



<p>Like Firefox, Safari automatically engages additional privacy technologies, whether the user browses in standard or private mode. Safari’s Intelligent Tracking Protection (ITP), which has been around for nearly a decade and repeatedly upgraded, now blocks all third-party cookies, among other components advertisers and services use to track people as they bounce from one site to another. ITP is controlled by a single on-off switch — on is the default — found in <strong>Preferences</strong> under the <strong>Privacy</strong> icon. If the <strong>Website tracking:</strong> box is checked to mark <strong>Prevent cross-site tracking</strong>, ITP is on.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="453" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Switching on cross-site tracking enables Safari’s Intelligent Tracking Protection, which blocks a wide variety of bits advertisers try to use to follow you around the web while you’re using a Private Window.</p>
</figcaption></figure><p class="imageCredit">Apple</p></div>



<p>A link can be opened directly to a Private Window by right-clicking, then selecting <strong>Open Link in New Private Window</strong>. Close a Private Window just as any Safari window, by clicking the red dot in the upper left corner of the browser frame.</p>



<p><strong>Pro tip:</strong> <i>Once in a Safari Private Window, opening a new tab — either by clicking the + icon at the upper right or by using the Command-T key combo — omits the Private Browsing Enabled notice. (The darkened address bar remains as the sole indicator of a private browsing session.) Other browsers, such as Firefox, repeat their cautionary messages each time a tab is opened in an incognito session.</i></p>



<p><strong>Related reading:</strong></p>



<ul class="wp-block-list">
<li><a href="https://www.computerworld.com/article/1717405/googles-chromium-browser-explained.html">Chromium explained: How the open-source engine drives today’s browsers</a></li>



<li><a href="https://www.computerworld.com/article/4083528/ai-web-browsers-are-cool-helpful-and-utterly-untrustworthy.html">AI web browsers are cool, helpful, and utterly untrustworthy</a></li>



<li><a href="https://www.computerworld.com/article/3996011/ai-windows-web-browser.html">How AI will transform your Windows web browser</a></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Digital-native startups are ditching rigid databases for their agentic stacks     ]]></title>
<description><![CDATA[Presented by MongoDBThe gap between what AI models and agents can produce and what legacy infrastructure can reliably support is known as architectural drag, and it is the defining bottleneck of the agentic era. The data layer underneath an agentic system must handle variable schemas, vector embe...]]></description>
<link>https://tsecurity.de/de/3652101/it-nachrichten/digital-native-startups-are-ditching-rigid-databases-for-their-agentic-stacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652101/it-nachrichten/digital-native-startups-are-ditching-rigid-databases-for-their-agentic-stacks/</guid>
<pubDate>Tue, 07 Jul 2026 18:18:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><i>Presented by MongoDB</i></p><hr><p>The gap between what AI models and agents can produce and what legacy infrastructure can reliably support is known as architectural drag, and it is the defining bottleneck of the agentic era. </p><p>The data layer underneath an agentic system must handle variable schemas, vector embeddings, real-time retrieval, and multi-tenant scale, often simultaneously and without human intervention to manage migrations — but traditional relational databases weren't natively designed for document flexibility or AI capabilities. Fixed schemas require manual updates every time an AI agent introduces a new data shape, while separate vector databases add latency and synchronization overhead.</p><p>Three digital-native startups — Huntr, Modelence, and Tavily — solved this problem the same way: by building on MongoDB Atlas, a unified database platform with native vector search, hybrid search, and managed autoscaling. Their experiences define what an agent-native data stack looks like in production, and why using Atlas enables developers to easily build complex AI native companies.</p><h2>Modelence: Building the agent-native cloud</h2><p>Modelence is an AI app builder with an open-source framework designed specifically for agent-native development, enabling anyone to build and deploy production-ready web applications, including APIs and databases, in minutes. The company recognized early that most backend infrastructure was built for humans, not AI, and that the rigid schema management and complex migrations of traditional systems create operational drag that causes agents to fail when trying to build production-ready apps.</p><p>“Choosing MongoDB helped us keep everything in a single place, which is an important property of what we strive to do for our own users," says Aram Shatakhtsyan, co-founder and CEO of Modelence. "Live data streams, vector search, all as part of the main database. For AI agents, it’s especially important to have a single platform where everything can be done, because connecting multiple platforms together makes it more error prone.”</p><p>Modelence standardized on MongoDB Atlas because its document model aligns with how AI agents process and generate data, allowing schemas to evolve rapidly without manual migrations. The platform pairs that flexibility with a typed schema layer on top, a deliberate architectural decision. </p><p>“MongoDB’s document model enables us to both keep things simple and at the same time decide how structured we want everything to be," Shatakhtsyan says. We still add a typed schema on top, which tremendously improves the accuracy at which AI can generate fully working, reliable web apps."</p><p>The TypeScript integration has been especially consequential, he adds. </p><p>“Because MongoDB types and values can be directly translated to TypeScript, it becomes an extension of the Modelence framework and our App Builder has a single source of truth for both app logic and database,” Shatakhtsyan explains.</p><p>The result is a platform that can move from planning to a running live feature in minutes with significantly fewer regressions. That speed and reliability helped Modelence raise $3 million in seed funding and successfully launch an AI-native app builder that handles the entire application lifecycle end-to-end.</p><h2>Tavily: The web access layer for agents     </h2><p>Tavily is the search API purpose-built for AI agents, connecting them to real-time, accurate web knowledge and keeping them grounded in what's actually happening, not in static training data. At Tavily's scale, every agent request authenticates, retrieves, and meters without friction. That demanded backend infrastructure built to absorb change without breaking.</p><p>“On the user side, every agent request authenticates and meters against it," says Tomer Weiss, Data Team Lead at Tavily. "On the data side, we use it to track the lifecycle of every document we’ve ever touched: when it was fetched, how stale it is, what the freshness signals were and how popular it is. MongoDB’s flexible schema let us keep evolving those records without migrations as new metrics and features came along.”</p><p>That living record is what keeps agents grounded in reality. Multi-tenancy at Tavily's scale means managing millions of API keys, distinct usage profiles, plan tiers, and regional residency requirements. They built for that complexity from day one. </p><p>“We separated concerns across clusters early: a user/account cluster optimized for low-latency authentication and usage writes, and a sharded cluster for document state where the scaling axis is URLs, not users," Weiss explains. "That separation has paid off.”</p><p>The most critical lesson is about choosing infrastructure that doesn’t punish change, and that flexibility compounds, he says. </p><p>"The AI space moves so fast that change is our norm," he explains.  "For a company serving AI agents, where the workloads themselves keep changing shape, choosing a data platform that doesn’t punish change has turned out to be more valuable than any single feature.”
</p><h2>Huntr: From job tracker to AI career platform</h2><p>Huntr.co, an AI resume building and tailoring platform, helps more than 500,000 job seekers across 190 countries craft stronger applications and manage their search. For a lean, three-person engineering team, the challenge was finding a data foundation flexible enough to store the full complexity of a person’s career history in a structure that AI could read, reason about, and generate from natively.</p><p>“The kinds of career data we are gathering at Huntr naturally aligns with MongoDB’s document model," says Trevor McCann, senior software engineer at Huntr. "The core problem we’re solving with AI job search tools is how to surface the qualities of a candidate that make them unique. We need to be ready to store whatever kinds of data the candidate wants to include in their materials.”</p><p>Huntr built its AI Resume Builder on MongoDB Atlas, where the document model mirrors the natural shape of career data: deeply nested, variable across candidates, and constantly evolving as the platform ships new features. MongoDB Search on Atlas handles core search needs while MongoDB Vector Search powers the <a href="https://huntr.co/product/resume-tailor"><u>Job Tailoring</u></a> feature, which puts a candidate’s stored career profile side by side a specific job description and uses semantic matching to generate a resume optimized for that role.</p><p>The integrated capabilities have had a direct impact on how quickly the team can ship, McCann says. </p><p>“MongoDB’s hybrid search allows us to seamlessly query across literal and semantic text matches, a must-have when working with such diverse data,” McCann says. “This is something we could piece together using other solutions but with MongoDB it’s ready to go on top of our existing data layer.”
The consolidation of database, search, and vector capabilities into a single platform is what allows the team to punch above its weight. Huntr considers MongoDB the fourth member of its engineering team, McCann adds. </p><p>Looking ahead, the platform is building toward AI that learns from a candidate’s full professional history over time, delivering more personalized guidance with every interaction.</p><h2>The digital native blueprint</h2><p>These success stories become a definitive "digital native blueprint" for the agentic era, built on three core pillars. First, by unifying database, search, and vector storage into a single platform, these startups have effectively eliminated the architectural tax of complex data schemas that typically slows down development. This consolidation enables a level of fluidity that is now non-negotiable; AI agents require a modern data platform that can adapt as quickly as a natural language prompt evolves. </p><p>The winners of the AI era will be the ones who build the most performant, durable, and flexible systems to support those models in production. As agentic workflows grow more sophisticated, the data foundation determines how fast a team can ship, how reliably agents can operate, and how quickly the platform can adapt when the landscape shifts again. </p><hr><p><i>Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact </i><a href="mailto:sales@venturebeat.com"><i><u>sales@venturebeat.com</u></i></a><i>.</i>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How Do I Choose the Right Virtual CISO Provider?]]></title>
<description><![CDATA[Choosing the right Virtual CISO (vCISO) provider means looking beyond technical expertise alone. The best providers offer strategic cybersecurity leadership, practical risk management, regulatory compliance guidance, incident response planning and executive-level communication. They should unders...]]></description>
<link>https://tsecurity.de/de/3651610/it-security-nachrichten/how-do-i-choose-the-right-virtual-ciso-provider/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651610/it-security-nachrichten/how-do-i-choose-the-right-virtual-ciso-provider/</guid>
<pubDate>Tue, 07 Jul 2026 15:09:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="hs-featured-image-wrapper"> 
 <a href="https://www.cm-alliance.com/cybersecurity-blog/how-do-i-choose-the-right-virtual-ciso-provider" title="" class="hs-featured-image-link"> <img src="https://www.cm-alliance.com/hubfs/Virtual_CISO_with_bgc.webp" alt="How to Choose a Virtual CISO" class="hs-featured-image"> </a> 
</div> 
<p><span>Choosing the right <a href="https://www.cm-alliance.com/consultancy/virtual-ciso-consulting-services/">Virtual CISO (vCISO) </a>provider means looking beyond technical expertise alone. The best providers offer strategic cybersecurity leadership, practical risk management, regulatory compliance guidance, incident response planning and executive-level communication. They should understand your industry, align security with business objectives and provide ongoing support that strengthens your organisation's cyber resilience.</span><br></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Boston Dynamics Atlas VS New Bionic Humanoid Robot Design War]]></title>
<description><![CDATA[Author: AI News - Bewertung: 2x - Views:20 Is the future of robotics superhuman agility like the Boston Dynamics Atlas, or are we heading toward ultra-bionic companions that look and act like us? Today on AI News, we're exploring the embodied AI design war, starting with the public debut of Hyund...]]></description>
<link>https://tsecurity.de/de/3651595/it-security-video/boston-dynamics-atlas-vs-new-bionic-humanoid-robot-design-war/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651595/it-security-video/boston-dynamics-atlas-vs-new-bionic-humanoid-robot-design-war/</guid>
<pubDate>Tue, 07 Jul 2026 15:04:09 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: AI News - Bewertung: 2x - Views:20 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/kFDkn559lkE?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Is the future of robotics superhuman agility like the Boston Dynamics Atlas, or are we heading toward ultra-bionic companions that look and act like us? Today on AI News, we're exploring the embodied AI design war, starting with the public debut of Hyundai’s production-grade Atlas at the FIFA World Cup 2026, where the robot demonstrated fluid, full-body coordination in a live match environment. But while Atlas pushes industrial-grade superhuman agility, a new wave of competitors is choosing a different path. We deep dive into UBTECH’s new U1 Series—a mass-production humanoid featuring biomimetic skin and an emotion-aware LLM designed for lifelike interaction. We also analyze the high-performance A3 from AGIB, which boasts a record-breaking power-to-weight ratio, and discuss how Exhumanoid's TGVLA framework is finally moving us past "arm-centric" robotics. Plus, a surprise look at how Google AI Studio used Claude’s Fable 5 to port a classic 2003 PC game to iOS.<br />
<br />
Discover the AI agent economy: https://8004agents.ai<br />
<br />
AI news:<br />
0:00 Atlas<br />
2:24 U1<br />
4:32 A3<br />
5:21 TG-VLA<br />
6:31 Fable 5<br />
<br />
#ai #news #robot<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TeamPCP Supply Chain Attacks Feed VECT Ransomware With Stolen CI/CD Credentials]]></title>
<description><![CDATA[TeamPCP’s wide-scale supply-chain compromises have materially fueled VECT ransomware operations by supplying a vast archive of stolen CI/CD credentials, reshaping how organizations should measure ransomware exposure. Rather than choosing victims in advance, TeamPCP contaminated widely used compon...]]></description>
<link>https://tsecurity.de/de/3651430/it-security-nachrichten/teampcp-supply-chain-attacks-feed-vect-ransomware-with-stolen-cicd-credentials/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651430/it-security-nachrichten/teampcp-supply-chain-attacks-feed-vect-ransomware-with-stolen-cicd-credentials/</guid>
<pubDate>Tue, 07 Jul 2026 14:08:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>TeamPCP’s wide-scale supply-chain compromises have materially fueled VECT ransomware operations by supplying a vast archive of stolen CI/CD credentials, reshaping how organizations should measure ransomware exposure. Rather than choosing victims in advance, TeamPCP contaminated widely used components Trivy, Checkmarx KICS,…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/teampcp-supply-chain-attacks-feed-vect-ransomware-with-stolen-ci-cd-credentials/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/teampcp-supply-chain-attacks-feed-vect-ransomware-with-stolen-ci-cd-credentials/">TeamPCP Supply Chain Attacks Feed VECT Ransomware With Stolen CI/CD Credentials</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TeamPCP Supply Chain Attacks Feed VECT Ransomware With Stolen CI/CD Credentials]]></title>
<description><![CDATA[TeamPCP’s wide-scale supply-chain compromises have materially fueled VECT ransomware operations by supplying a vast archive of stolen CI/CD credentials, reshaping how organizations should measure ransomware exposure. Rather than choosing victims in advance, TeamPCP contaminated widely used compon...]]></description>
<link>https://tsecurity.de/de/3651402/it-security-nachrichten/teampcp-supply-chain-attacks-feed-vect-ransomware-with-stolen-cicd-credentials/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651402/it-security-nachrichten/teampcp-supply-chain-attacks-feed-vect-ransomware-with-stolen-cicd-credentials/</guid>
<pubDate>Tue, 07 Jul 2026 13:54:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>TeamPCP’s wide-scale supply-chain compromises have materially fueled VECT ransomware operations by supplying a vast archive of stolen CI/CD credentials, reshaping how organizations should measure ransomware exposure. Rather than choosing victims in advance, TeamPCP contaminated widely used components Trivy, Checkmarx KICS, LiteLLM, and the Telnyx Python SDK access so that any organization that installed those packages […]</p>
<p>The post <a href="https://gbhackers.com/teampcp-supply-chain-attacks/">TeamPCP Supply Chain Attacks Feed VECT Ransomware With Stolen CI/CD Credentials</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[MCP vs Skills: Which Is Right for Your AI Agent and LLMs?]]></title>
<description><![CDATA[Author: IBM Technology - Bewertung: 33x - Views:248 Learn more about AI Agents here → https://ibm.biz/~TjxCNJCU3

Choosing how to extend an AI agent isn’t always obvious. Cedric Clyburn explains when to use Model Context Protocol versus Skills for agents. Learn how context engineering helps you d...]]></description>
<link>https://tsecurity.de/de/3651325/it-security-video/mcp-vs-skills-which-is-right-for-your-ai-agent-and-llms/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651325/it-security-video/mcp-vs-skills-which-is-right-for-your-ai-agent-and-llms/</guid>
<pubDate>Tue, 07 Jul 2026 13:19:22 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: IBM Technology - Bewertung: 33x - Views:248 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/goU9VIXA8II?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Learn more about AI Agents here → https://ibm.biz/~TjxCNJCU3<br />
<br />
Choosing how to extend an AI agent isn’t always obvious. Cedric Clyburn explains when to use Model Context Protocol versus Skills for agents. Learn how context engineering helps you decide the right approach for your AI workloads.<br />
<br />
AI news moves fast. Sign up for a monthly newsletter for AI updates from IBM → https://ibm.biz/~CeRTD6fZ0<br />
<br />
#mcp #aiagents #contextengineering #llms<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Inside Elastic InfoSec's agentic SOC: Choosing the right agent architecture for a 5x cost reduction]]></title>
<description><![CDATA[We ran two agentic SOC architectures head to head across 36,822 real Agent Builder conversations. One won by 5.7x: a specialized workflow triaging alerts for $0.69 each, against $3.42 for a single agent juggling 14 Skills. The data and the decision framework are both below.]]></description>
<link>https://tsecurity.de/de/3649760/it-security-nachrichten/inside-elastic-infosecs-agentic-soc-choosing-the-right-agent-architecture-for-a-5x-cost-reduction/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649760/it-security-nachrichten/inside-elastic-infosecs-agentic-soc-choosing-the-right-agent-architecture-for-a-5x-cost-reduction/</guid>
<pubDate>Mon, 06 Jul 2026 21:53:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[We ran two agentic SOC architectures head to head across 36,822 real Agent Builder conversations. One won by 5.7x: a specialized workflow triaging alerts for $0.69 each, against $3.42 for a single agent juggling 14 Skills. The data and the decision framework are both below.]]></content:encoded>
</item>
<item>
<title><![CDATA[Choose your WhatsApp username carefully]]></title>
<description><![CDATA[WhatsApp is introducing usernames to help protect your phone number. Just make sure you don’t undermine that privacy by choosing the wrong one. This article has been indexed from Malwarebytes Read the original article: Choose your WhatsApp username carefully
Read more →
The post Choose your Whats...]]></description>
<link>https://tsecurity.de/de/3648938/it-security-nachrichten/choose-your-whatsapp-username-carefully/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648938/it-security-nachrichten/choose-your-whatsapp-username-carefully/</guid>
<pubDate>Mon, 06 Jul 2026 15:53:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>WhatsApp is introducing usernames to help protect your phone number. Just make sure you don’t undermine that privacy by choosing the wrong one. This article has been indexed from Malwarebytes Read the original article: Choose your WhatsApp username carefully</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/choose-your-whatsapp-username-carefully/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/choose-your-whatsapp-username-carefully/">Choose your WhatsApp username carefully</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Choose your WhatsApp username carefully]]></title>
<description><![CDATA[WhatsApp is introducing usernames to help protect your phone number. Just make sure you don't undermine that privacy by choosing the wrong one.]]></description>
<link>https://tsecurity.de/de/3648799/it-security-nachrichten/choose-your-whatsapp-username-carefully/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648799/it-security-nachrichten/choose-your-whatsapp-username-carefully/</guid>
<pubDate>Mon, 06 Jul 2026 15:07:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[WhatsApp is introducing usernames to help protect your phone number. Just make sure you don't undermine that privacy by choosing the wrong one.]]></content:encoded>
</item>
<item>
<title><![CDATA[Why developers are over the cloud]]></title>
<description><![CDATA[You can be forgiven if you think the most important thing AWS ever sold developers was EC2. It’s not. No, AWS’s big gift to developers was permission to stop fretting about servers. That sounds obvious now, but it was close to magical at the time. Before the cloud, getting infrastructure meant wa...]]></description>
<link>https://tsecurity.de/de/3648443/ai-nachrichten/why-developers-are-over-the-cloud/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648443/ai-nachrichten/why-developers-are-over-the-cloud/</guid>
<pubDate>Mon, 06 Jul 2026 12:19:48 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>You can be forgiven if you think the most important thing AWS ever sold developers was EC2. It’s not. No, <a href="https://www.infoworld.com/article/4183710/cloud-at-20-how-aws-shaped-enterprise-it.html" data-type="link" data-id="https://www.infoworld.com/article/4183710/cloud-at-20-how-aws-shaped-enterprise-it.html">AWS’s big gift</a> to developers was permission to stop fretting about servers. That sounds obvious now, but it was close to magical at the time. Before the cloud, getting infrastructure meant waiting on procurement, hardware, and the somewhat arcane process that stood between a developer and a running machine. AWS turned that into a credit card and an API.</p>



<p>It was awesome.</p>



<p>AWS still (over)uses a great phrase for what it removed: “<a href="https://aws.amazon.com/what-is-aws/">undifferentiated heavy lifting</a>.” That is, all the mess associated with racking servers, patching operating systems, managing storage, planning capacity, etc. Important work, sure, but not the work that makes your application special. Let AWS do that, the company intoned, and developers could focus on the thing their customers actually cared about.</p>



<p>It was a brilliant abstraction. It helped build one of the most important technology companies of the past two decades. It’s also the same logic that increasingly makes the cloud seem superfluous. Not because the cloud is dying. It isn’t. The cloud is bigger and more essential than ever. But developers don’t begin by asking, “Which cloud should I use?” They begin with, “How quickly can I get this thing working?”</p>



<p>That is a different question, and it leads to different tools.</p>



<h2 class="wp-block-heading"><a></a>Where to begin?</h2>



<p>Let’s get the obvious thing out of the way: AWS remains the biggest developer cloud, and its revenue growth has accelerated in the wake of AI. In the<a href="https://survey.stackoverflow.co/2024/technology"> 2024 Stack Overflow Developer Survey</a>⁠, AWS was the top cloud platform, used by 48% of respondents. Microsoft Azure and Google Cloud followed at 27.8% and 25.1%, respectively.</p>



<p>The<a href="https://survey.stackoverflow.co/2025/technology"> 2025 Stack Overflow Developer survey</a>⁠ is more interesting, however, because the “cloud development” category no longer reads like a clear cloud-vendor horse race. <a href="https://www.infoworld.com/article/2253801/what-is-docker-the-spark-for-the-container-revolution.html">Docker</a> jumped 17 points to 71% usage, followed by npm and then AWS at 43%. Kubernetes, Azure, Google Cloud, Cloudflare, Terraform, Firebase, Vercel, Netlify, and Supabase all show up in the same mental map.</p>



<p>This is my point: Developers aren’t simply choosing a different cloud first. Often, they’re not choosing a cloud first at all. They’re choosing a workflow, and a workflow is an increasingly separate decision from the underlying cloud.</p>



<h2 class="wp-block-heading"><a></a>The first mile moved</h2>



<p>For a long time, AWS owned the first mile. If you wanted to build something, you opened an AWS account. Need compute? Launch EC2. Storage? S3. Whatever a developer needed—database, queue, function, CDN, identity layer—AWS, the “everything store,” almost certainly had an answer.</p>



<p>It was magical! Then it became the norm. And, over time, it became a lot. The “everything store” arguably had too much, making it hard for developers to know how to use it effectively. The developer’s question became, “How much AWS do I have to understand before I can ship?” Developers increasingly don’t want to answer that question at the start.</p>



<p>The first mile now often begins in <a href="https://www.infoworld.com/article/4069045/how-github-won-software-development.html" data-type="link" data-id="https://www.infoworld.com/article/4069045/how-github-won-software-development.html">GitHub⁠</a>, which says more than 36 million developers joined in a single year. Or it begins in <a href="https://www.infoworld.com/article/4115165/why-boring-vs-code-keeps-winning.html">VS Code, which keeps winning</a> because it’s familiar, extensible, and already open. Or it begins in Cursor, GitHub Copilot, Claude, Codex, and the broader AI coding layer. <a href="https://github.blog/news-insights/octoverse/octoverse-a-new-developer-joins-github-every-second-as-ai-leads-typescript-to-1/">GitHub’s 2025 Octoverse⁠ says nearly 80% of new developers</a> on GitHub use Copilot within their first week. <a href="https://survey.stackoverflow.co/2025/ai/">Stack Overflow’s 2025 AI survey results⁠ point</a> the same way, with 84% of respondents using or planning to use AI tools in their development process, up from 76% in 2024.</p>



<p>The starting point is changing. The default interface to building software is becoming an AI-assisted workflow, not a cloud console. This doesn’t make the cloud less important, but it definitely makes it less visible.</p>



<h2 class="wp-block-heading"><a></a>The joy of not caring</h2>



<p>The developer platforms with momentum right now are winning because they expose less cloud infrastructure. Call it serverless if you like, but it’s deeper than AWS Lambda ever was. AWS Lambda still made you think in AWS. These new platforms make you think in your app.</p>



<p>Take <a href="https://vercel.com/">Vercel</a>⁠. It didn’t win developer mindshare by offering more than 200 services and praying developers would navigate them all. Instead, it attached itself to the way many front-end and full-stack developers already work: GitHub, Next.js, previews, deployments, performance, and a short path from code to live application. It seems to be working: Reuters <a href="https://www.reuters.com/business/ai-coding-startup-vercel-raises-300-million-valued-93-billion-2025-09-30/">reported last year that Vercel raised $300 million</a> at a $9.3 billion valuation⁠, after doubling its user base and growing revenue 82%.</p>



<p><a href="https://developers.cloudflare.com/workers/">Cloudflare</a> offers a similar promise from a different angle, <a href="https://www.infoworld.com/article/4014268/cloud-finally-gets-some-new-competition.html">as I’ve written</a>: deploy globally, run close to users, scale automatically, and don’t make infrastructure the developer’s first problem. <a href="https://supabase.com/">Supabase</a>⁠ does the same for data, wrapping Postgres with authentication, instant APIs, edge functions, real-time subscriptions, storage, and <a href="https://www.infoworld.com/article/2269766/what-is-vector-search-better-search-through-ai.html">vectors</a> so the database feels less like a separate system and more like an app platform.</p>



<p>None of this is anti-cloud. But it’s very definitely stripping away the need to even think about cloud. And it’s just as definitely where developers are focused today.</p>



<p>AI accelerated all of this because it changed the first question developers ask. For an AI application, the opening move often isn’t where do you host it, but rather which model, which agent framework, etc., will get you to a live application fastest? For this reason, <a href="https://developers.openai.com/">OpenAI’s developer platform⁠ isn’t framed</a> as renting infrastructure. It’s framed as building with models, APIs, tools, docs, and examples. Similarly, <a href="https://www.anthropic.com/product/claude-code">Anthropic’s Claude Code⁠ isn’t positioned</a> as configuring a cloud environment; it’s an agentic coding system that works in your code base and helps you build, test, and ship.</p>



<h2 class="wp-block-heading"><a></a>The second mile matters more</h2>



<p>I’m not saying the cloud vendors should abandon hope. Indeed, though the first mile has moved away from the hyperscalers, the second mile is still very much theirs to win.</p>



<p>Vercel, Cloudflare, Supabase, OpenAI, Anthropic, and GitHub are brilliant at helping developers make something work, fast. But in the enterprise, “fast” isn’t the key priority: Enterprises eventually need the boring stuff like <a href="https://www.csoonline.com/article/518296/what-is-iam-identity-and-access-management-explained.html">identity</a>, network controls, <a href="https://www.infoworld.com/article/2262666/what-is-observability-software-monitoring-on-steroids.html">observability</a>, cost management, compliance, and the rest of the unglamorous apparatus that keeps customer data from leaking onto Reddit.</p>



<p>Boring is good when boring means the thing works.</p>



<p>This is where AWS, Azure, Google Cloud, Oracle, and other infrastructure companies should have an advantage. But it won’t be enough to say, “We have the grown-up features.” That’s true, but it’s dull, and in this case, “dull” isn’t a winning proposition. No, the strategic challenge for the hyperscalers is to make the jump from prototype to production feel like an upgrade instead of a punishment.</p>



<p>AWS’s new <a href="https://www.aboutamazon.com/news/aws/aws-1-billion-forward-deployed-ai-engineers">$1 billion investment in forward-deployed AI engineers</a>⁠ is interesting for exactly this reason. AWS says the new organization will embed experts with customers to co-develop and deploy agentic AI solutions in days. That’s not classic bottom-up developer love, but it’s a smart recognition that the bottleneck has moved closer to the application. The hard part is turning capability into a working system, not merely getting access to infrastructure or a model.</p>



<p>Yep. Exactly.</p>



<h2 class="wp-block-heading"><a></a>Hiding the cloud</h2>



<p>The mistake for cloud infrastructure companies would be to respond to this by trying to become a Vercel, Supabase, GitHub, OpenAI, or Anthropic all at once. That’s the classic incumbent move, and it rarely works. The better move is narrower: become the most natural next step when the prototype starts to matter.</p>



<p>That means meeting developers where they work: GitHub, VS Code, Cursor-style environments, <a href="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html">CI/CD systems</a>, and <a href="https://www.infoworld.com/article/3812583/what-you-need-to-know-about-developing-ai-agents.html">AI agents</a>. It means outcome-native starts: deploy this app, connect this data, expose this API, add auth, evaluate this agent, secure this workflow, move this prototype into production. It means fewer scavenger hunts across product pages and <a href="https://www.infoworld.com/article/4079018/building-a-golden-path-to-ai.html">establishing more golden paths</a> (yes, even if that infuriates a service team that gets left out).</p>



<p>The old question was, “Can you run my workload?” For AWS, Azure, Google Cloud, Oracle, and others, the answer is almost always yes. But no one is impressed by this anymore. Therefore, the better question is, “Can you become part of how I build?”</p>



<p>Developers came to the cloud because it was the easiest way to get infrastructure. They’re shifting to developer experience platforms because those are the easiest way to get outcomes. If the cloud providers can become part of the first mile before the Vercels of the world become part of the second mile, they’ll win, and big. If they don’t, well….</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[RingZeroCTF Coding Challenge 1 [Hash Me If You Can] Writeup]]></title>
<description><![CDATA[Ok so guys this is my first writeup i have been writing on the medium platform of the recent CTF i was practicing on the platform RingZero.In that i selected the coding challenges and decided to do the first challenge.Now the challenge interface looked somehow like this the image attached below.C...]]></description>
<link>https://tsecurity.de/de/3647970/hacking/ringzeroctf-coding-challenge-1-hash-me-if-you-can-writeup/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647970/hacking/ringzeroctf-coding-challenge-1-hash-me-if-you-can-writeup/</guid>
<pubDate>Mon, 06 Jul 2026 08:53:06 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<ol><li>Ok so guys this is my first writeup i have been writing on the medium platform of the recent CTF i was practicing on the platform RingZero.</li><li>In that i selected the <strong>coding challenges</strong> and decided to do the first challenge.</li><li>Now the challenge interface looked somehow like this the image attached below.</li></ol><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*R7KN3pVfq5g74sJad0hZhQ.png"><figcaption>Clicked on the ‘Go To Challenge’ Option</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/690/1*hmWWFjKegKW1AUIuUCwA0g.png"><figcaption>Challenge URL :- <a href="http://challenges.ringzer0ctf.com:10013/">http://challenges.ringzer0ctf.com:10013/</a></figcaption></figure><p>4. Now after this i read the challenge text carefully and it told that i have to hash this given message text using the SHA 512 Algorithm and then submit the text to the given URL and in the end i will get the flag after i submit the correct response.</p><p>5. <strong>All this process i have to in just 2 seconds, which is obviously not humanly possible at all</strong>.</p><p>6. So here clearly we had to apply the kind of the some script or any commands of linux and send the requests.</p><p>7. <strong>SHA 512</strong> :- It is a cryptographic hashing algorithm which is used to convert any text of the any length in just 512 bit [64 bytes]. It is not any encryption algorithm at all. It is a part of the SHA 2 family in cryptography.</p><p>8. Now the first command i thought of running was :-</p><pre>curl "http://challenges.ringzer0team.com:10013/?r=$(echo -n [The hashing text] | shah512sum | cut -d ' ' -f1)"</pre><p>9. Now in this command i have used the :</p><p>a. curl command to send the HTTP Requests from the CLI Terminal of the Kali.</p><p>b. <strong>echo -n command</strong> to paste the text including the newline character as well.</p><p>c. <strong>sha512sum</strong> for hashing</p><p>d. <strong>cut delimiters of the whitespaces and then extracting only first field of that </strong>.</p><p>10. But here is the thing that this command will not give the flag at all because the <strong>Challenge URL</strong> is dynamic and the texts updates itself. So if we send the requests of curl in just 2 seconds the text will get updated and then new text will be there which will have the different hash then previous one.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*h8faXA9xHvXbEhVqVmuJsQ.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*9r85IuR72w9qkpjGa6RILw.png"></figure><p>11. In the images you can clearly see that it has shown in the response that too slow process error.</p><p>12. So i used some help of the AI then got to know about the session stateful requests which <strong>store the cookies</strong> and <strong>session id </strong>automatically and then from that we can send the the requests to the URL and it will store the cookies and in response we will get the answer.</p><p>13. By <strong>storage of the session cookies</strong> we will <strong>retrieve the original message response</strong> of the server which will include the flag.</p><p>14. So now <strong>choosing the Python </strong>as the language because it has the <strong>supported libraries</strong> which will make the scripting easier i constructed the below script.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*2GPARBh7t35r4B6SjIogcg.png"><figcaption>Final Python Script</figcaption></figure><p>15. <strong>Explanation of the script in understandable way </strong>:-</p><p>a.<strong> <em>requests, re, hashlib library</em> </strong>:- <em>Requests is the A Python library used to send HTTP requests (GET, POST, etc.) to websites and receive responses like a browser. It handles sessions, cookies, headers, and makes web automation simple and reliable. Re is the Python’s regular expression library used to search, match, and extract patterns from text. It is used when you need to find specific data inside large or messy strings like logs or HTML. Hashlib is the Python’s cryptographic hashing library used to generate hashes like SHA-256 and SHA-512. It converts data into a fixed-length fingerprint used for integrity checks and security tasks</em>.</p><p>b. <em>I used the </em><strong><em>requests library</em></strong><em> of the python to create the session of the website and the extract the response of the text and then i just applied the </em><strong><em>re.search function</em></strong><em> to extract the original message which we are given to hash</em>.</p><p>c. <strong><em>.*?</em></strong><em> -&gt; </em><strong><em>‘.’</em></strong><em> means to match any character. </em><strong><em>‘*’</em></strong><em> means to repeat the process zero or more times. </em><strong><em>‘?’</em></strong><em> makes it lazy to match little as possible.</em></p><p>d. <strong><em>\s*</em></strong><em> -&gt; To neglect the whitespaces in the reponse.</em></p><p>e. <strong><em>strip() function</em></strong><em> :- This is the function of the python to remove the leading and trailing whitespaces from the text we have selected.</em></p><p>f. <strong><em>hashlib.sha512(text.encode()).hexdigest </em></strong><em>:- Now the extracted text is the alphanumeric characters which the machine do not understand, it understands the language of the bit/bytes so we encoded to the UTF-8 encoding [By Default] using the encode() function and then applied the sha512 function and then after that we again converted to hexadecimal characters for the human readable text.</em></p><p>g. <em>At last we added the line of sending requests with the </em><strong><em>params [parameter]</em></strong><em> added as well.</em></p><p>16. <strong>With this we executed the script</strong>.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*lC-P9SYrBDVesrJZtuqOng.png"><figcaption>Response Part 1</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*tALgdIGwiHUGyHm2VlEfYw.png"><figcaption>Response Part 2</figcaption></figure><p>17. <strong>Hell Yeah we got the Flag</strong>.</p><p>18. <strong>One another method is also there of the Burp Suite Using as well. So i suggest all of people to try that method themselves as well</strong>.</p><p>This was my first write-up, and it marks the beginning of a series where I will consistently break down <strong>real CTF challenges with real techniques and real learning outcomes</strong>. My goal is not just to solve challenges, but to <strong>explain the mindset, tooling, and reasoning</strong> behind every step so that readers can actually apply these skills in practice.</p><p>Every upcoming write-up will focus on <strong>practical cybersecurity concepts</strong>, clean automation, and problem-solving approaches that are genuinely useful for CTFs, penetration testing, and real-world security work. If you are someone who wants to move beyond copy-paste solutions and truly understand <em>why</em> things work, these write-ups are for you.</p><p>If you found this helpful, consider following and sharing it with your peers — it helps me stay consistent and motivates me to keep producing <strong>high-quality, beginner-friendly yet technically solid content</strong> for the community.</p><p>More challenges. More automation. More learning.</p><p><strong>Happy Hacking.</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*U7qcpGP5GTpyKsac"><figcaption>Photo by <a href="https://unsplash.com/@csbphotography?utm_source=medium&amp;utm_medium=referral">Conor Samuel</a> on <a href="https://unsplash.com/?utm_source=medium&amp;utm_medium=referral">Unsplash</a></figcaption></figure><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=ba55f820a1b8" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/ringzeroctf-coding-challenge-1-hash-me-if-you-can-writeup-ba55f820a1b8">RingZeroCTF Coding Challenge 1 [Hash Me If You Can] Writeup</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The future of payment fraud could be automated]]></title>
<description><![CDATA[Payment fraud is becoming more organized as criminal groups use fake websites, large-scale operations, and, in some cases, forced labor to steal money and personal information. Advances in agentic AI could automate many stages of payment fraud, from collecting and assembling stolen credentials to...]]></description>
<link>https://tsecurity.de/de/3647711/it-security-nachrichten/the-future-of-payment-fraud-could-be-automated/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647711/it-security-nachrichten/the-future-of-payment-fraud-could-be-automated/</guid>
<pubDate>Mon, 06 Jul 2026 06:07:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Payment fraud is becoming more organized as criminal groups use fake websites, large-scale operations, and, in some cases, forced labor to steal money and personal information. Advances in agentic AI could automate many stages of payment fraud, from collecting and assembling stolen credentials to deploying password-cracking tools. What kind of payment fraud concerns you most? (Source: Capco) CAPCO’s “US Payment Fraud Survey” found that consumers increasingly value fraud protection when choosing payment providers. Security was … <a href="https://www.helpnetsecurity.com/2026/07/06/key-payment-fraud-trends-report/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/06/key-payment-fraud-trends-report/">The future of payment fraud could be automated</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta is Quietly Launching Pocket, an App for Vibe-coding and Scrolling Small 'Gizmos']]></title>
<description><![CDATA["Mozilla shut down the well-loved read-it-later Pocket app last year, and now Meta is launching an app called Pocket with an entirely different, AI-focused pitch," writes The Verge. 

While it's not available for downloads in most locations, Meta's Pocket will allow people "to generate small, int...]]></description>
<link>https://tsecurity.de/de/3647439/it-security-nachrichten/meta-is-quietly-launching-pocket-an-app-for-vibe-coding-and-scrolling-small-gizmos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647439/it-security-nachrichten/meta-is-quietly-launching-pocket-an-app-for-vibe-coding-and-scrolling-small-gizmos/</guid>
<pubDate>Mon, 06 Jul 2026 01:22:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA["Mozilla shut down the well-loved read-it-later Pocket app last year, and now Meta is launching an app called Pocket with an entirely different, AI-focused pitch," writes The Verge. 

While it's not available for downloads in most locations, Meta's Pocket will allow people "to generate small, interactive apps and games using AI prompts," writes TechCrunch. They're called "gizmos", and Pocket "also offers a scrollable feed where you can play with gizmos others have made." 

Some context from The Verge:
Meta CEO Mark Zuckerberg is all in on AI as the new social media, and he's previously described a vision of how users could use AI to make interactive experiences and share them with people. The launch of Pocket appears to be one manifestation of that idea... It follows Meta hiring engineers from a company called Atma Sciences Inc., which made an app called Gizmo, as Business Insider reported in March. 

On a help center page, Meta also describes a gizmo as a "playable AI-generated experience," and when you post one, Meta says you can choose to let other people remix them.
 

"Based on the app's screenshots in Google Play, there are many similarities to Gizmo's original app, which is still listed," notes TechCrunch. 

"Pocket is another example of Meta's push to make AI creation tools more mainstream, extending its earlier efforts, which included AI-generated images created via its Meta AI app and AI videos created with its app called Vibes. It has also added AI features across its social platforms... "

Given that Meta has not officially announced Pocket's debut, it's likely that Pocket is still in its initial experimentation phase. Its counterpart Gizmo, however, had generated 635,000 lifetime installs across both iOS and Google Play, according to Appfigures, which noted it had a 98% positive sentiment.

<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Meta+is+Quietly+Launching+Pocket%2C+an+App+for+Vibe-coding+and+Scrolling+Small+'Gizmos'%3A+https%3A%2F%2Fgames.slashdot.org%2Fstory%2F26%2F07%2F05%2F234233%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fgames.slashdot.org%2Fstory%2F26%2F07%2F05%2F234233%2Fmeta-is-quietly-launching-pocket-an-app-for-vibe-coding-and-scrolling-small-gizmos%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://games.slashdot.org/story/26/07/05/234233/meta-is-quietly-launching-pocket-an-app-for-vibe-coding-and-scrolling-small-gizmos?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Diese versteckte App macht jedes Samsung Galaxy sofort besser]]></title>
<description><![CDATA[Samsung baut seit Jahren hervorragende Smartphones. Doch das volle Potenzial von One UI steckt nicht unbedingt in den Systemeinstellungen, sondern in einer App, die viele Galaxy-Nutzer nie installieren: Good Lock. Was die App alles kann, welche Module sich lohnen und wie Sie Good Lock einrichten,...]]></description>
<link>https://tsecurity.de/de/3646381/it-nachrichten/diese-versteckte-app-macht-jedes-samsung-galaxy-sofort-besser/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646381/it-nachrichten/diese-versteckte-app-macht-jedes-samsung-galaxy-sofort-besser/</guid>
<pubDate>Sun, 05 Jul 2026 09:32:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Samsung baut seit Jahren hervorragende Smartphones. Doch das volle Potenzial von One UI steckt nicht unbedingt in den Systemeinstellungen, sondern in einer App, die viele Galaxy-Nutzer nie installieren: <strong>Good Lock</strong>. Was die App alles kann, welche Module sich lohnen und wie Sie Good Lock einrichten, erfahren Sie hier.</p>



<h2 class="wp-block-heading toc">Was ist Samsung Good Lock?</h2>



<p>Good Lock ist ein offizieller Samsung-Dienst, der als Hub für eine Sammlung von Zusatzmodulen fungiert. Jedes dieser Module greift tief in einen bestimmten Bereich von One UI ein: den Sperrbildschirm, die Navigation, die Kamera, Benachrichtigungen, Multitasking und vieles mehr. Das Ergebnis ist ein Anpassungsgrad, der sonst nur Custom-ROMs vorbehalten war.</p>



<p>Die App ist <strong>vollständig kostenlos</strong>, wird direkt von Samsung entwickelt und ist damit so sicher wie One UI selbst. Mit One UI 8 im Jahr 2026 hat Samsung vier neue Module hinzugefügt und zahlreiche bestehende aktualisiert.</p>



<h2 class="wp-block-heading toc">Für welche Galaxy-Geräte ist Good Lock verfügbar?</h2>



<p>Good Lock läuft <a href="https://www.pcwelt.de/article/1204479/test-das-beste-samsung-galaxy-smartphone.html" data-type="link" data-id="https://www.pcwelt.de/article/1204479/test-das-beste-samsung-galaxy-smartphone.html" target="_blank" rel="noreferrer noopener">auf allen Samsung Galaxy-Geräten</a> mit <strong>One UI 6 oder neuer</strong>. Konkret bedeutet das:</p>



<ul class="wp-block-list">
<li><strong>Galaxy S-Serie</strong>: S23, S23+, S23 Ultra und neuer (inkl. S26-Reihe)</li>



<li><strong>Galaxy Z-Serie</strong>: Z Flip 5 und Z Fold 5 aufwärts</li>



<li><strong>Galaxy A-Serie</strong>: Ausgewählte Modelle mit One UI 6+</li>



<li><strong>Galaxy Tab</strong>: Tab S9 und neuer</li>
</ul>



<p>Good Lock ist im <a href="https://www.awin1.com/cread.php?awinmid=14815&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=https://galaxystore.samsung.com/detail/com.samsung.android.goodlock" data-type="link" data-id="https://www.awin1.com/cread.php?awinmid=14815&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=https://galaxystore.samsung.com/detail/com.samsung.android.goodlock" target="_blank" rel="noreferrer noopener">Samsung Galaxy Store</a> verfügbar und seit Ende 2025 alternativ auch über den <a href="https://play.google.com/store/apps/details?id=com.samsung.android.goodlock&amp;hl=de" data-type="link" data-id="https://play.google.com/store/apps/details?id=com.samsung.android.goodlock&amp;hl=de">Google Play Store</a>, womit die frühere Beschränkung auf bestimmte Länder entfällt. Einzelne Module können jedoch weiterhin regional eingeschränkt sein.</p>



<p><strong>Wichtig:</strong> Die einzelnen Module werden nicht automatisch installiert. Sie wählen selbst, welche Module Sie aktivieren möchten. Das spart Speicherplatz und hält das System übersichtlich.</p>



<h4 class="wp-block-heading">Die besten aktuellen Angebote für das Samsung Galaxy S26</h4>



				<div class="wp-block-price-comparison price-comparison">
		
		<div class="new_products_tab tabcontent ">

			<div class="price-comparison__record price-comparison__record--header">
				<div>
					<span>Shop</span>
				</div>
								<div class="price-comparison__price">
					<span>Preis</span>
				</div>
			</div>

								<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/24204.png" alt="coolblue" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>629,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=5RhXdKdI83ftiDOfdN0LnJe3tbSWKwr5aE5gRwf5O7p6RmIsvl8L8VovW2rD7AzJop5eUIvJnUoVAesFtOqK6EjMMr4I4bcHmza08zmpKe2a6wSRIJwKsekr84RqXb6_YPkBeTsXFjzgIkq1OUjwH4&amp;mid=686084161694&amp;id=686084161694&amp;ts=20260705&amp;log=rss" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=5RhXdKdI83ftiDOfdN0LnJe3tbSWKwr5aE5gRwf5O7p6RmIsvl8L8VovW2rD7AzJop5eUIvJnUoVAesFtOqK6EjMMr4I4bcHmza08zmpKe2a6wSRIJwKsekr84RqXb6_YPkBeTsXFjzgIkq1OUjwH4&amp;mid=686084161694&amp;id=686084161694&amp;ts=20260705&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="629,00 €" data-vars-product-vendor="coolblue" aria-label="Deal anschauen bei coolblue für 629,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  amazon_vendor">
						<div class="price-comparison__image">
															<img decoding="async" src="https://www.pcwelt.de/wp-content/themes/idg-base-theme/dist/static/img/amazon-logo.svg" alt="Amazon" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>639,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://www.amazon.de/dp/B0GPDRTBFQ?tag=pcwelt.de-21&amp;linkCode=ogi&amp;th=1&amp;psc=1&amp;ascsubtag=rss" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://www.amazon.de/dp/B0GPDRTBFQ?tag=pcwelt.de-21&amp;linkCode=ogi&amp;th=1&amp;psc=1&amp;ascsubtag=rss" data-vendor-api="amazon" data-vars-product-price="639,00 €" data-vars-product-vendor="Amazon" aria-label="Deal anschauen bei Amazon für 639,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/4541.png" alt="notebooksbilliger" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>645,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=2M_hVxkBGOjgFdiMIpCMzN6uCqCNO8-tL7nY_gEpKI5He66dKLCcTskzmk7s2ctpvSl923nsGZ8vE30bjvaFmhcExcfMRGQgECdBHof2fasebWCvty-nT7AHXdywI10YkyWbwcakYeT&amp;mid=686062104468&amp;id=686062104468&amp;ts=20260705&amp;log=rss" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=2M_hVxkBGOjgFdiMIpCMzN6uCqCNO8-tL7nY_gEpKI5He66dKLCcTskzmk7s2ctpvSl923nsGZ8vE30bjvaFmhcExcfMRGQgECdBHof2fasebWCvty-nT7AHXdywI10YkyWbwcakYeT&amp;mid=686062104468&amp;id=686062104468&amp;ts=20260705&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="645,00 €" data-vars-product-vendor="notebooksbilliger" aria-label="Deal anschauen bei notebooksbilliger für 645,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/12137.png" alt="Boomstore" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>681,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=IkDanvohS2tvsU1Wdh-mdc5Hd99OQeF7THsqZXwye-WEbEokfk-c7B4WO4b3TQhTLoFn43uV-nFaEmlykUvpU44ctEsCbqg6S9ygKvebEHEx1W2pOuolXrkpeyIRTOAb2V11tAmrzs1&amp;mid=686472923573&amp;id=686472923573&amp;ts=20260705&amp;log=rss" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=IkDanvohS2tvsU1Wdh-mdc5Hd99OQeF7THsqZXwye-WEbEokfk-c7B4WO4b3TQhTLoFn43uV-nFaEmlykUvpU44ctEsCbqg6S9ygKvebEHEx1W2pOuolXrkpeyIRTOAb2V11tAmrzs1&amp;mid=686472923573&amp;id=686472923573&amp;ts=20260705&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="681,00 €" data-vars-product-vendor="Boomstore" aria-label="Deal anschauen bei Boomstore für 681,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__hidden-records-wrapper">
									<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/21515.png" alt="JB-Computer" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>687,30 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=oRTBV_k8k-BtiDOfdN0LnJe3tbSWKwr5Zd5k8UHf2Hu6RmIsvl8L8VHKuRs3tP2bop5eUIvJnUoVAesFtOqK6EjMMr4I4bcHmza08zmpKe2a6wSRIJwKsfziX486kitPenRmPhh8kBN&amp;mid=686413404106&amp;id=686413404106&amp;ts=20260705&amp;log=rss" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=oRTBV_k8k-BtiDOfdN0LnJe3tbSWKwr5Zd5k8UHf2Hu6RmIsvl8L8VHKuRs3tP2bop5eUIvJnUoVAesFtOqK6EjMMr4I4bcHmza08zmpKe2a6wSRIJwKsfziX486kitPenRmPhh8kBN&amp;mid=686413404106&amp;id=686413404106&amp;ts=20260705&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="687,30 €" data-vars-product-vendor="JB-Computer" aria-label="Deal anschauen bei JB-Computer für 687,30 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://s24.media/shop/11af34f513114e17ab24f15ca5083429" alt="Baur Versand" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>699,99 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://lg.s24.cloud/catalog/9116/189565/9597578911" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://lg.s24.cloud/catalog/9116/189565/9597578911" data-vendor-api="shopping24" data-vars-product-price="699,99 €" data-vars-product-vendor="Baur Versand" aria-label="Deal anschauen bei Baur Versand für 699,99 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://www.pcwelt.de/wp-content/themes/idg-base-theme/dist/static/img/samsung-logo.svg" alt="Samsung" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>999,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://www.awin1.com/cread.php?awinmid=14815&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=https://www.samsung.com/de/smartphones/galaxy-s26/buy/" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://www.awin1.com/cread.php?awinmid=14815&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=https://www.samsung.com/de/smartphones/galaxy-s26/buy/" data-vars-product-price="999,00 €" data-vars-product-vendor="Samsung" aria-label="Deal anschauen bei Samsung für 999,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
						
									</div>
									<div class="price-comparison__record price-comparison__record--footer">
					<span class="price-comparison__footer-text">
													Preisvergleich (über 24.000 Shops weltweit)												</span>
											<button class="price-comparison__view-more-button">
							Weitere Angebote						</button>
									</div>
		</div>

		<div class="refurbished_products_tab tabcontent">
			<div class="refurbished-padding price-comparison__record price-comparison__record--header">
				<div>
					<span>Produkt</span>
				</div>
				<div class="price-comparison__price">
					<span>Preis</span>
				</div>
			</div>
							<div class="price-comparison__record price-comparison__record--footer">
					<span class="price-comparison__footer-text">
					Preisvergleich von Backmarket						</span>
									</div>
		</div>
		</div>
		


<h2 class="wp-block-heading toc">So installieren Sie Good Lock</h2>



<ol class="wp-block-list">
<li>Öffnen Sie den <strong>Galaxy Store</strong> auf Ihrem Samsung-Gerät (oder Google Play Store).</li>



<li>Suchen Sie nach “<a href="https://www.awin1.com/cread.php?awinmid=14815&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=https://galaxystore.samsung.com/detail/com.samsung.android.goodlock" data-type="link" data-id="https://www.awin1.com/cread.php?awinmid=14815&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=https://galaxystore.samsung.com/detail/com.samsung.android.goodlock">Good Lock</a>“. Das Icon zeigt vier farbige, ineinandergreifende Puzzleteile.</li>



<li>Installieren und öffnen Sie die App.</li>



<li>Wählen Sie die gewünschten Module direkt in Good Lock aus und laden Sie sie per Tap herunter.</li>
</ol>



<p><strong>Tipp:</strong> Installieren Sie nicht alle Module auf einmal. Starten Sie mit zwei oder drei, die Ihrem konkreten Bedarf entsprechen. </p>



<h2 class="wp-block-heading toc">Wie ist Good Lock aufgebaut?</h2>



<p>Good Lock selbst ist nur die Schaltzentrale. Nach der Installation sehen Sie eine übersichtliche Oberfläche mit vier Bereichen:</p>



<ul class="wp-block-list">
<li><strong>Make up</strong>: Module zur optischen Anpassung, etwa Themes, Sperrbildschirm und Hintergrundbilder.</li>



<li><strong>Life up</strong>: Module für Funktionen und Effizienz, zum Beispiel Navigation, Kamera, Multitasking und Audio.</li>



<li><strong>Clock</strong>: Eigenständige Kategorie für Uhren-Module (zum Beispiel ClockFace für das Always-On-Display).</li>



<li><strong>Extensions</strong>: Zusatzmodule, die quer durch die beiden Hauptkategorien “Make up” und “Life up” verfügbar sind.</li>
</ul>



<p>Tippen Sie auf ein Modul, können Sie es direkt dort herunterladen und installieren, also ohne Umweg über den Galaxy Store. Insgesamt stehen aktuell <strong>mehr als 20 Module</strong> zur Verfügung.</p>


<div class="extendedBlock-wrapper block-coreImage left"><figure data-wp-context='{"imageId":"6a4a08620d406"}' data-wp-interactive="core/image" class="wp-block-image alignleft size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/vs.png?w=1200" alt="Good Lock Overview" class="wp-image-3171243" width="1200" height="675" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Ein Überblick über die Good Lock-App von Samsung.</p>
</figcaption></figure><p class="imageCredit">PC-Welt</p></div>



<h2 class="wp-block-heading toc">Die wichtigsten Module im Überblick</h2>



<h3 class="wp-block-heading">Theme Park</h3>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4a08620db79"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/theme-park.png?w=1200" alt="good lock theme park" class="wp-image-3171247" width="1200" height="763" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Good Lock: Erstellen Sie eigene Themes &amp; Designs mit Theme Park.</p><br></figcaption></figure><p class="imageCredit">PC-Welt</p></div>



<p>Theme Park ist der Einstieg in die optische Personalisierung. Das Modul ermöglicht es, eigene Themes zu erstellen: Farben, Icon-Formen, Hintergrundbilder und Schriftarten lassen sich frei kombinieren. Vorhandene Icon-Packs aus dem Play Store können eingebunden und verwaltet werden.</p>



<p>Seit 2026 gibt es sogar einen <strong>KI-Theme-Generator</strong>. Sie beschreiben per Text, wie Ihr Theme aussehen soll, und die KI erstellt automatisch ein passendes Farbschema inklusive Icons und Hintergrundbild.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">One Hand Operation+</h3>



<p>Falls Sie, so wie ich, ein Galaxy S Ultra oder Z Fold besitzen, haben Sie bestimmt schon bemerkt: Einhändige Bedienung ist eine Herausforderung. One Hand Operation+ löst das Problem mit sechs konfigurierbaren Edge-Gesten (drei pro Seite). Jede Geste kann individuell belegt werden: Zurück, App-Übersicht, Screenshot, Taschenlampe, Benachrichtigungen und mehr.</p>



<p>Das Besondere daran ist, dass das Modul parallel zur normalen Navigationsleiste funktioniert und diese um zusätzliche Wischgesten ergänzt.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">LockStar</h3>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4a08620e236"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/lockstar.png?w=1200" alt="Lockstar Good Lock" class="wp-image-3171249" width="1200" height="614" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Good Lock: Mit dem “LockStar” Modul personalisieren Sie Ihren Sperrbildschirm.</p>
</figcaption></figure><p class="imageCredit">PC-Welt</p></div>



<p>Der Sperrbildschirm ist das Erste, was Sie sehen, wenn Sie Ihr Smartphone in die Hand nehmen. One UI lässt ihn aber nur begrenzt anpassen. LockStar öffnet hier deutlich mehr Spielraum. Per WYSIWYG-Editor ziehen Sie Uhr, Datum, Widgets und App-Shortcuts frei auf dem Bildschirm hin und her, sowohl im Hoch- als auch im Querformat. Elemente, die Ihnen nicht gefallen, blenden Sie einfach aus.</p>



<p>Besonders nützlich: LockStar schaltet <strong>App-Widgets auf dem Sperrbildschirm</strong> frei, die Samsung standardmäßig nicht erlaubt. So sehen Sie etwa den Kalender, den Schrittzähler oder die Wettervorschau direkt auf dem gesperrten Display, ohne das Smartphone erst zu entsperren. Auch App-Shortcuts lassen sich frei platzieren. Ein Tipp auf das Kamera-Symbol startet die Kamera, ohne den Entsperrvorgang zu durchlaufen.</p>



<p>Neu im Jahr 2026 sind außerdem animierte <strong>Entsperreffekte</strong>. Die neue Animation Swirl dreht den Sperrbildschirm beim Entsperren herein, und weitere Stile wie Curtain, Ripple, Mosaic oder Wave sorgen dafür, dass selbst das Entsperren des Telefons ein kleines visuelles Erlebnis wird.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">MultiStar</h3>



<p>MultiStar erweitert die Multitasking-Funktionen erheblich. Jede App kann im geteilten Bildschirm oder als Popup-Fenster geöffnet werden (auch solche, die das offiziell nicht unterstützen). Neu seit 2026 sind <strong>App-Paare auf dem Homescreen</strong>, die zwei Apps gleichzeitig im Split-Screen starten.</p>



<p>Für Foldable-Nutzer unverzichtbar: MultiStar steuert, wie Apps beim Auf- und Zuklappen zwischen Cover- und Hauptbildschirm wechseln. Samsung DeX-Nutzer profitieren von Optionen wie höheren Auflösungen oder mehr als fünf gleichzeitigen Apps auf dem verbundenen Display.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">RegiStar</h3>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4a08620e8ec"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/registar.png?w=1200" alt="RegiStar Good Lock" class="wp-image-3171258" width="1200" height="794" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Good Lock: Passen Sie mit dem RegiStar Modul ganz einfach Ihre Galaxy-Einstellungen an.</p>
</figcaption></figure><p class="imageCredit">PC-Welt</p></div>



<p>RegiStar ist das Modul für alle, denen die Standardbelegung von Tasten und Gesten nicht weit genug geht. Das bekannteste Feature ist die <strong>Backtap-Geste</strong>: Wenn Sie zweimal auf die Rückseite Ihres Smartphones tippen, öffnet sich eine frei wählbare App oder Funktion (etwa die Taschenlampe, ein Screenshot oder Expert RAW). Gerade wenn die Ein-/Aus-Taste bereits für Gemini oder die Kamera reserviert ist, schafft Backtap eine praktische dritte Steuermöglichkeit, die vollkommen unsichtbar bleibt.</p>



<p>Überdies lässt sich mit RegiStar auch die <strong>Seitentaste</strong> neu belegen: Doppeltippen und langes Drücken können unabhängig voneinander mit eigenen Aktionen verknüpft werden. Wer möchte, startet so per langem Druck direkt eine bestimmte App statt den Sprachassistenten.</p>



<p>Weniger bekannt, aber ebenso nützlich: Mit RegiStar können Sie das <strong>Einstellungsmenü von One UI umstrukturieren</strong>. Bereiche, die Sie nie benötigen, lassen sich ausblenden und häufig genutzte nach oben schieben. Die integrierte <strong>Einstellungshistorie</strong> protokolliert dabei alle kürzlich vorgenommenen Änderungen im System.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">NavStar</h3>



<p>Die Navigationsleiste sieht man täglich, doch anpassen lässt sie sich in One UI kaum. NavStar ändert das. Sofern Sie die klassische Tastennavigation nutzen, können Sie Layout, Reihenfolge und Farbe der Schaltflächen frei gestalten, den Hintergrund der Leiste einfärben und eine zusätzliche Schaltfläche einblenden, mit der sich die Leiste bei Bedarf auf Knopfdruck verstecken lässt. </p>



<p>Wenn Sie per Wischgesten navigieren, lassen sich die Empfindlichkeit und der Aktionsbereich für die linke und rechte Seite unabhängig voneinander einstellen. Das ist praktisch, wenn Sie etwa links mehr Spielraum für die Zurück-Geste möchten. Außerdem entscheiden Sie, ob der Strich am unteren Bildschirmrand sichtbar bleibt oder dezent ausblendet.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">Camera Assistant</h3>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4a08620ef6c"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/camera-assistant.png?w=1200" alt="good lock camera assistant" class="wp-image-3171263" width="1200" height="820" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>“Camera Assistant” ermöglicht es, versteckte Kamerafunktionen freizuschalten.</p>
</figcaption></figure><p class="imageCredit">PC-Welt</p></div>



<p>Camera Assistant schaltet versteckte Kamerafunktionen frei. Auf der Galaxy S26-Reihe aktiviert das Modul den <strong>24-Megapixel-Modus</strong>, der KI-Fusionsverarbeitung nutzt: schärfer als 12 MP, kleinere Dateien als 50 MP. Ein guter Sweetspot für den Alltag. Zu den weiteren Funktionen zählen unter anderem folgende:</p>



<ul class="wp-block-list">
<li><strong>Fokus-Peaking</strong> im Pro-Modus markiert scharf gestellte Bildbereiche farbig, was besonders bei manueller Fokussierung hilft.</li>



<li><strong>Serienbilder mit Intervall</strong> ermöglichen zeitgesteuerte Aufnahmeserien, etwa für Zeitraffer-Vorbereitungen. </li>



<li><strong>Auto-HDR</strong> aktiviert sich automatisch, wenn die Kamera starke Helligkeitsunterschiede erkennt</li>



<li><strong>Automatisches Objektivwechseln</strong> lässt das Gerät je nach Motiv und Zoomstufe selbst das optimale Objektiv wählen.</li>



<li><strong>Der</strong> <strong>Astro-Modus-Shortcut</strong> macht den Nachtfotografie-Modus direkt erreichbar.</li>



<li><strong>Benutzerdefinierte Auflösungsvoreinstellungen</strong> erlauben es, bevorzugte Megapixel-Stufen dauerhaft zu speichern und schnell umzuschalten.</li>
</ul>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">NotiStar</h3>



<p>Benachrichtigungen verschwinden schnell – manchmal zu schnell. NotiStar löst dieses Problem mit einer vollständigen <strong>Benachrichtigungshistorie</strong>, die alle eingegangenen Mitteilungen speichert, bis Sie sie selbst löschen. Auch versehentlich weggewischte Benachrichtigungen lassen sich so jederzeit nachlesen.</p>



<p>Weiterhin bietet NotiStar eine personalisierte <strong>Filterfunktion</strong>: Sie legen fest, von welchen Apps Sie Benachrichtigungen sehen möchten und von welchen nicht. Noch präziser wird es mit Keyword-Filtern: So können Sie beispielsweise einstellen, dass Sie von einer bestimmten App nur dann benachrichtigt werden, wenn die Nachricht ein bestimmtes Wort enthält, etwa “Rechnung” oder “Termin”. Benachrichtigungen, die den Filter nicht erfüllen, werden verworfen oder nur in der Historie gespeichert, ohne dass sie Sie aktiv stören.</p>



<p>Auch für den Sperrbildschirm ist NotiStar praktisch. Dort greift es nämlich ebenfalls, sodass Sie genau steuern, was auf dem gesperrten Display sichtbar ist. Im Februar 2026 hat Samsung das Modul mit einer überarbeiteten Benachrichtigungsverwaltung aktualisiert, die die Übersicht über mehrere Apps hinweg nochmals verbessert.</p>



<h2 class="wp-block-heading toc">Weitere empfehlenswerte Module</h2>



<ul class="wp-block-list">
<li><strong>Home Up</strong>: Anpassung des Launchers wie Rastergröße, App-Drawer, Share-Menü bereinigen </li>



<li><strong>Keys Cafe</strong>: Tastaturlayout, Tastatureffekte und Sounds </li>



<li><strong>QuickStar</strong>: Statusleisten-Symbole hinzufügen oder entfernen, Quick-Settings direkt öffnen </li>



<li><strong>Routines+</strong>: Erweiterte Bixby-Automationen mit Touch-Makros und App-basierten Auslösern </li>



<li><strong>Wonderland</strong>: Lebendige Parallax-Hintergrundbilder mit Bewegungseffekten </li>



<li><strong>ClockFace</strong>: Individuelle Uhr für Always-On-Display und Sperrbildschirm </li>



<li><strong>Game Booster+</strong>: Gamepad-Touch-Mapping, AP-Taktbegrenzung, Game-Intro-Schnellvorlauf </li>



<li><strong>Pentastic</strong>: S-Pen-Zeigerstile und Air-Command-Anpassungen (für S-Pen-Geräte) </li>



<li><strong>Nice Catch</strong>: Systemprotokoll für Benachrichtigungen, Vibrationen und Einstellungsänderungen</li>
</ul>



<p>Sollte das alles noch nicht ausreichen, finden Sie hier noch mehr Tipps, um Ihr Galaxy zu optimieren: <a href="https://www.pcwelt.de/article/2957766/android-tricks-versteckte-funktionen-ausprobieren.html" target="_blank" rel="noreferrer noopener">Diese 11 versteckten Android-Funktionen sollten Sie sofort ausprobieren</a>.</p>



<p>Und falls Sie ein Galaxy S26 besitzen: <a href="https://www.pcwelt.de/article/3136236/galaxy-s26-ultra-tipps-tricks.html" target="_blank" rel="noreferrer noopener">Die besten Tipps und Tricks für Samsung Galaxy S26</a>.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[FSF Shares Update on 'LibrePhone' and New Automated Site Monitoring Tool]]></title>
<description><![CDATA[At the end of 2025, the FSF launched LibrePhone project, which is working to "better understand and reverse-engineer the nonfree blobs used by a great majority of (if not all) system on a chip designs available today." The FSF's summer newsletter shares this update:


We started with researching ...]]></description>
<link>https://tsecurity.de/de/3645758/it-security-nachrichten/fsf-shares-update-on-librephone-and-new-automated-site-monitoring-tool/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3645758/it-security-nachrichten/fsf-shares-update-on-librephone-and-new-automated-site-monitoring-tool/</guid>
<pubDate>Sat, 04 Jul 2026 20:54:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[At the end of 2025, the FSF launched LibrePhone project, which is working to "better understand and reverse-engineer the nonfree blobs used by a great majority of (if not all) system on a chip designs available today." The FSF's summer newsletter shares this update:


We started with researching the proprietary files in Android phones supported by the Lineage project, an Android-based volunteer-led mobile phone operating system with much free software already in it. Our current, primary focus is on the radio blobs that control WiFi, Bluetooth, NFC, and cellular communications. 

The software freedom issues with mobile computing have been around for a long time, with the most challenging issue being the baseband/modem firmware that relies heavily on proprietary software. This creates a technical and legal maze that is nearly impossible to break free from, but that doesn't mean we should ever stop working to create free systems. It certainly doesn't mean we shouldn't liberate the software that we know can be free software. Now, half a year into this project, lead developer Rob Savoye has extracted firmware from over 200 Lineage install packages, processed 85GB of files, and imported the results of these analyses into a PostgreSQL database for cross-device comparison... [M]uch of the software and blobs we need to work through are shared across multiple devices; this means even greater strides for mobile phone freedom... 

As insurmountable as it may seem at times, every blob we manage to free up will be progress. The FSF has proven time and time again that it can bring the free software philosophy to life, not just by advocating for it, but by making it so.

 

The bulletin also describes how waves of botnets from "aggressive LLM scrapers, vulnerability scanners, poorly optimized CI/CD servers" inspired the FSF to create a new free-as-in-freedom automated monitoring tool:



In our efforts to combat the botnets, we optimized several detection rules to ban abusive behavior. We found the upper limit of fail2ban and replaced it with reaction, an efficient alternative with our configuration that uses ipset. We also split several monolithic machines into many separate machines so that when a web service is overwhelmed the other functions of the service do not go down with it... We found quite a few ways to respond to and prevent botnet attacks, but still faced a significant related challenge: communicating when a website or service is down... 

Uptime Kuma is a human-readable, automated monitoring addition to our systems... You can check out our recently-launched self-hosted Uptime Kuma instance at https://status.fsf.org/. When you see the page, you will also likely say, "Wow! The FSF and GNU sure do run a ton of services!" and you would be right... If you maintain websites and services, and are looking for a simple way to communicate publicly with your users, consider using Uptime Kuma or another free software solution instead of choosing a proprietary monitoring solution."
 

There's also an article on the state of free-as-in-freedom videogame console emulators.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=FSF+Shares+Update+on+'LibrePhone'+and+New+Automated+Site+Monitoring+Tool%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F07%2F04%2F0654252%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F07%2F04%2F0654252%2Ffsf-shares-update-on-librephone-and-new-automated-site-monitoring-tool%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/07/04/0654252/fsf-shares-update-on-librephone-and-new-automated-site-monitoring-tool?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[iPhone 18 Pro rumor recycles claims of slower SSD on high capacity models]]></title>
<description><![CDATA[A new rumor claims that some iPhone 18 Pro models will use slower QLC NAND storage, mimicking a similar 2024 iPhone 16 Pro report. It makes more sense now than it did then, but doesn't matter much in practical usage.The 1TB and 2TB iPhone 18 Pro may not have the same type of storage as lower-capa...]]></description>
<link>https://tsecurity.de/de/3641810/ios-mac-os/iphone-18-pro-rumor-recycles-claims-of-slower-ssd-on-high-capacity-models/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641810/ios-mac-os/iphone-18-pro-rumor-recycles-claims-of-slower-ssd-on-high-capacity-models/</guid>
<pubDate>Thu, 02 Jul 2026 18:53:15 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A new rumor claims that some <a href="https://appleinsider.com/inside/iphone-18" title="iPhone 18" data-kpt="1">iPhone 18</a> Pro models will use slower QLC NAND storage, mimicking a similar 2024 iPhone 16 Pro report. It makes more sense now than it did then, but doesn't matter much in practical usage.<br><br><div><img src="https://photos5.appleinsider.com/gallery/68114-143572-67740-142763-iPhone-17-Pro-back-xl-xl.jpg" alt="Silver smartphone lying face down on a dark wooden surface, featuring a raised rectangular camera bump with three large lenses and subtle Apple logo in the center of the back" height="738"><br><span>The 1TB and 2TB iPhone 18 Pro may not have the same type of storage as lower-capacity models. </span></div><br>This latest report suggests that Apple will use the faster TLC storage for the <a href="https://appleinsider.com/inside/iphone" title="iPhone" data-kpt="1">iPhones</a> that people are most likely to buy. But those choosing the larger 1TB and 2TB capacities may be left with a slower QLC alternative from SK Hynix.<br><br>Companies like Apple continue to struggle to source the storage components required for new products. With that in mind, it may not be surprising to see Apple go this route. Sourcing 1TB and 2TB TLC components may be difficult, if not impossible.<br><br><br> <strong>Rumor Score:</strong> 🤔 Possible <br><br><br> <a href="https://appleinsider.com/articles/26/07/02/iphone-18-pro-rumor-recycles-claims-of-slower-ssd-on-high-capacity-models?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244856?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Model routing: A better way to control AI costs]]></title>
<description><![CDATA[As an old Delphi guy, I remember well the “language wars” we had with the Visual Basic guys. An early codename for Delphi was “VBK” — VB Killer — and the VB community took exception. They’d come to our Delphi forums and pick fights. Naturally, we brash Delphi guys would fight back, engaging in bi...]]></description>
<link>https://tsecurity.de/de/3641780/ai-nachrichten/model-routing-a-better-way-to-control-ai-costs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641780/ai-nachrichten/model-routing-a-better-way-to-control-ai-costs/</guid>
<pubDate>Thu, 02 Jul 2026 18:34:32 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>As an old <a href="https://en.wikipedia.org/wiki/Delphi_(software)" data-type="link" data-id="https://en.wikipedia.org/wiki/Delphi_(software)">Delphi</a> guy, I remember well the “language wars” we had with the <a href="https://en.wikipedia.org/wiki/Visual_Basic_(classic)" data-type="link" data-id="https://en.wikipedia.org/wiki/Visual_Basic_(classic)">Visual Basic</a> guys. An early codename for Delphi was “VBK” — VB Killer — and the VB community took exception. They’d come to our Delphi forums and pick fights. Naturally, we brash Delphi guys would fight back, engaging in big flame wars and getting all worked up over what wasn’t much more than a personal preference. Good times.</p>



<p>These days, we’ve moved the discussion up a layer — what is the better model for coding? Things aren’t quite as intense as the VB/Delphi dustups, but people have their opinions. Companies are taking a look at different models before choosing one for their teams. Most teams have arrived at a family of models that they use. </p>



<p>At some point, chatting with Claude or Codex started to seem a bit raw. It wasn’t long before scaffolding tools like <a href="https://github.com/garrytan/gstack" data-type="link" data-id="https://github.com/garrytan/gstack">GStack</a> and <a href="https://github.com/obra/Superpowers" data-type="link" data-id="https://github.com/obra/Superpowers">Superpowers</a> were adding underpinnings for interacting with LLMs — baseline instructions for handling prompts before they get to the model itself. They help establish useful context and act as a layer above “raw prompting”. <a href="https://www.infoworld.com/article/4127462/what-is-context-engineering-and-why-its-the-new-ai-architecture.html" data-type="link" data-id="https://www.infoworld.com/article/4127462/what-is-context-engineering-and-why-its-the-new-ai-architecture.html">Context engineering</a> is the first and most common layer to add on top of the chat interface.</p>



<p>And then once the choice of models and harnesses was made, everyone went <a href="https://www.infoworld.com/article/4170173/tokenmaxxing-is-super-dumb.html">crazy with tokenmaxxing</a>. If you have a model, of course you want to get the most out of it. But when the bill came in, managers were not pleased. As costs skyrocketed, leadership worried that the money wasn’t being well spent. </p>



<h2 class="wp-block-heading">Model routing – the next layer</h2>



<p>Just as assembly language and hand-tuning registers gave way to compilers and structured languages, which led to frameworks and libraries, and most recently to LLMs and prompting, it is starting to occur to developers and managers that there is a better way to manage LLM spending. </p>



<p>But naturally, the minute you figure out how things work, another layer appears, making all your hard-earned knowledge outdated. <a href="https://www.infoworld.com/article/4018953/the-ultimate-software-engineering-abstraction.html">Apparently being able to code in English</a> isn’t enough to stop the next abstraction from appearing.</p>



<p>So as is always the case, <a href="https://medium.com/nickonsoftware/what-is-the-next-layer-bdc0280723a8">another layer of abstraction has come along</a>. (<em>Sic semper fuit</em>.) Thus model routing is the latest way to maximize the value for each dollar spent on tokens. </p>



<p>The idea is that not all prompts are created equal. Not everything that you ask Claude is going to require the deep thinking of a frontier model. A model router can take a look at the prompt and decide what model is best suited to answer that prompt and direct the query to that model. Maybe simpler requests are better suited for an older model. Maybe code reviews are better done with a model specifically designed for that purpose. </p>



<p>Model routing leads to more efficient token spending. When you run Claude Code today, you have to choose a model for the whole session, and if you want to use the top-tier model, you have to pay for it no matter what you end up doing. A model router lets you vary the model — and thus the cost. <a href="https://x.com/brian_armstrong/status/2070670644577280109?s=20">Organizations like Coinbase</a> are seeing their AI spend cut in half while their token usage increases. </p>



<h2 class="wp-block-heading">From tokenmaxxing to tokenmatching </h2>



<p>LLMs are constantly evolving, becoming both more powerful and more specialized. Being able to route a prompt to the model that is both well-suited for the task and cost-effective is the way to maximize token effectiveness. Teams are doing this manually now, but AI itself will become the best way to make such decisions. </p>



<p>For example, <a href="https://github.com/musistudio/claude-code-router">Claude Code Router</a> can route prompts to any number of popular models, depending on the type of work each prompt requires. And it’s open source. </p>



<p>The next layer that is coming is the preprocessing of prompts. We can work to write good prompts, but AI itself can improve upon what we ask. One of the best techniques in prompting is to tell the LLM to “ask the questions that I’m not asking but should be asking”. I can easily imagine a world in which you write a prompt, AI helps you clarify it, improves it, and then routes it to the best, most cost-effective model for an answer. </p>



<p>You won’t be choosing a given LLM provider anymore. Instead, you can focus on specifying exactly what you want. So stop hand-crafting your prompts for a specific model. Let the coming model routers and prompt preprocessors do the hard work for you.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Formalizing Red Teaming Offensive Methodology as a Multi-Agent AI Architecture]]></title>
<description><![CDATA[Threat actors are integrating AI into their exploit chains, accelerating reconnaissance, automating vulnerability discovery, and scaling social engineering in ways that compress the timeline between initial access and impact. The barrier to sophisticated offensive operations is dropping fast.Rapi...]]></description>
<link>https://tsecurity.de/de/3641499/it-security-nachrichten/formalizing-red-teaming-offensive-methodology-as-a-multi-agent-ai-architecture/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641499/it-security-nachrichten/formalizing-red-teaming-offensive-methodology-as-a-multi-agent-ai-architecture/</guid>
<pubDate>Thu, 02 Jul 2026 16:38:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>Threat actors are integrating AI into their exploit chains, accelerating reconnaissance, automating vulnerability discovery, and scaling social engineering in ways that compress the timeline between initial access and impact. The barrier to sophisticated offensive operations is dropping fast.</span></p><p><span>Rapid7's Red Team is doing the same. Over the past year we formalized our approach into a structured multi-agent system that follows our penetration testing methodology end-to-end from scoping an engagement to validating findings to generating reports. We built it as a production system, not a proof of concept, and the process of designing and operating it taught us as much about defending against AI-enhanced attacks as it did about conducting them.</span></p><p><span>The system also proved its value as part of Anthropic's </span><a href="https://www.rapid7.com/blog/post/ai-rapid7-accesses-anthropics-project-glasswing-exploring-frontier-artificial-cybersecurity-intelligence/" target="_self"><span>Project Glasswing initiative</span></a><span>. Glasswing is a program that gives leading security companies early access to frontier cyber models before they reach wider availability, enabling security research that stays ahead of malicious adoption. We infused our red team architecture with Claude Mythos, applying it across penetration testing, vulnerability research, and red team operations. The combination of our formalized multi-agent architecture with a frontier-class model produced exceptional results in vulnerability analysis and exploit chain development. This validated both the architecture's design and the importance of getting these capabilities into defenders' hands first.</span></p><p><span>This post covers the architecture, the key design decisions, and what we learned along the way.</span></p><h2>Why Rapid7's Red Team built a multi-agent system</h2><p><span>Penetration testing is labor-intensive by nature as a significant portion of any engagement is spent on structured, repeatable work like enumerating attack surfaces, tracing data flows through source code, checking security headers, documenting findings in a consistent format. The actual judgement — deciding what to test next, assessing exploitability, understanding business impact — remains deeply human.</span></p><p><span>The opportunity was straightforward: offload the mechanical work to AI agents while maintaining human insight at decision points where it matters most. Those decision points are where engagements succeed or fail: scoping what's in and out of bounds, choosing which attack paths to pursue based on business context, assessing whether a vulnerability is genuinely exploitable in a given environment, deciding when a finding is significant enough to escalate, and interpreting results in ways that translate to actionable risks. None of that is mechanical, it requires experience, judgement, and context that models routinely get wrong. And as an internal security team, we don't just report vulnerabilities, we're accountable for coverage. If something ships with an exploitable flaw we missed, that's on us. The bar for confidence is high, and that's why humans stay in the loop at every point that matters.</span></p><p><span>We also had a secondary motivation. Building a system that follows a structured offensive methodology gives us direct architectural insight into how AI agents behave in adversarial contexts including the capabilities, the limitations, and the failure modes. That understanding now informs how we assess and secure Rapid7's own AI-powered products.</span></p><h2>The architecture: Orchestration, not autonomy</h2><p><span>The system isn't a single monolithic agent but a team of specialist agents coordinated by an orchestrator that mirrors how human red teams operate. The orchestrator doesn't test anything. It assesses the current state of the engagement, determines what needs to happen next, routes work to the appropriate specialist, and processes the results. Specialist agents handle enumeration, code review, dynamic testing, and reporting.Each with defined inputs, outputs, and constraints.</span></p><p><span>The architectural choice to use supervisor-style orchestration rather than a monolithic agent separates routing decisions from execution. This makes the system more predictable, auditable, and controllable,properties that matter when the agent is operating in sensitive environments.</span></p><p><span>The key design decision that made this work was methodological, not technical. We reverse-engineered the agent's architecture directly from our team's daily task lists. The to-do items our testers tracked during real engagements became the specification: which tasks repeat, in what sequence, where decisions branch, and what triggers a return to an earlier phase. The methodology we'd built over years of engagements became the orchestration logic.</span></p><h2>Scope decomposition: Giving every target full attention</h2><p><span>One of the earliest lessons we learned was that throwing an entire engagement scope at an AI agent produces shallow, scattered results. LLMs have finite context windows and finite attention. A complex application with dozens of endpoints, multiple authentication flows, and layered business logic overwhelms a single-pass analysis and important details get lost in the noise.</span></p><p><span>The solution was deliberate scope decomposition. Before the agent begins any technical work, the engagement scope is broken into discrete, manageable chunks.  The scope includes individual components, feature areas, or functional boundaries. Each chunk flows through the full architecture independently: enumeration, code review, dynamic testing, and reporting. The orchestrator tracks which chunks are complete, which are in progress, and which are queued.</span></p><p><span>This achieves two things. First, it ensures depth over breadth as each component receives the agent's full analytical attention rather than competing for context space with everything else. Second, it creates natural parallelization opportunities and clear progress tracking. A tester can see exactly which areas have been thoroughly assessed and which remain.</span></p><p><span>The principal maps directly to how experienced pentesters already work by breaking the target into logical units, going deep on each one, then synthesizing across them. Making the principal explicit and enforceable in the orchestration logic was the design contribution.</span></p><h2>Feedback loops: Why linear pipelines fail</h2><p><span>Real penetration tests don't follow a straight line. Code review reveals new endpoints that need enumeration. Dynamic testing uncovers an attack surface that wasn't visible from source alone. Validated findings sometimes expose entirely new subsystems.</span></p><p><span>The agent handles this natively. The orchestrator maintains a routing table with progression gates — criteria that must be met before advancing — and feedback triggers that route the engagement backward when new actionable data emerges. This creates a directed graph with re-entry points, not a waterfall.</span></p><h2>Guardrails: Maintaining safety in a malicious context</h2><p><span>Building an AI agent that can hack is relatively straightforward but building one that operates safely within defined boundaries is a challenge. So it was an area where we invested significant design effort.</span></p><p><span>The system uses a tiered safety model:</span></p><ul><li><p><span>Scope enforcement — every action is validated against the engagement's authorized scope before execution. Out-of-scope discoveries are reported but never probed.</span></p></li><li><p><span>Action classification — before execution, every proposed dynamic test is categorized as non-destructive, destructive, or ambiguous. Destructive and ambiguous actions require human approval.</span></p></li><li><p><span>Human-in-the-loop by default — in our current deployment, a tester reviews and approves every dynamic test. The agent proposes; the human decides.</span></p></li></ul><p><span>The system is designed with a path toward semi-automated operation where low-risk, read-only actions execute autonomously while state-modifying operations still require human approval. The decision about where to sit on that spectrum is context-dependent. Internal labs can tolerate more autonomy while client engagements demand more oversight.</span></p><h2>Token efficiency: Making AI practical</h2><p><span>AI agents are expensive to run at scale. Every enumeration step, every code block analyzed, every HTTP request reasoned about will consume tokens. It is a practical concern that shaped several design decisions. </span></p><p><span>The approach was to identify mechanical tasks that don't require LLM reasoning and replace them with deterministic scripts and MCP servers. DNS lookups, header checks, input field probing, and certificate enumeration produce structured data that the agent consumes, but the data collection itself doesn't need intelligence. This reduced token consumption dramatically for enumeration-heavy phases while letting the AI focus its reasoning budget on analysis, correlation, and judgement.</span></p><p><span>Not every step in an AI workflow needs AI. Knowing where to draw that line was the difference between a demo and a production system for us.</span></p><h2>Securing AI from the inside out</h2><p><span>There's a dimension to this work that goes beyond offensive operations. Rapid7 builds AI-powered products. As the internal security team, we're responsible for securing those systems and building a complex multi-agent architecture gave us direct insight into where the weak points live.</span></p><p><span>Designing the orchestrated system taught us exactly how prompt injection can propagate between agents, where trust boundaries blur when one agent's output becomes another's input, how guardrails can be bypassed through indirect manipulation, and what happens when scope enforcement relies on instruction-following rather than programmatic controls.</span></p><p><span>We now test Rapid7's AI features with the same architectural intuition we developed building this system. We know where to look because we've built the same patterns and felt where they flex. When we assess an AI system's safety, we're thinking like the orchestrator — looking for the routing decision that can be subverted, the progression gate that can be skipped, the feedback loop that can be poisoned.</span></p><p><span>Building offensive AI made us materially better at defending the AI we ship to customers.</span></p><h2>What we learned operating the multi-agent system</h2><p><span>A few observations from our team:</span></p><h3><span>Methodology is the differentiator</span></h3><p><span>The LLMs are commodities. The orchestration patterns are emerging in open literature. What makes an AI agent effective at penetration testing is the methodology it follows and that's built from years of institutional knowledge. Formalizing our methodology into explicit, machine-executable logic was the most valuable part of the project.</span></p><h3><span>Building AI builds intuition for securing AI</span></h3><p><span>The architectural understanding we developed — trust boundaries, prompt propagation, scope enforcement failures — translates directly into more effective security assessments of production AI systems. This was an unexpected but significant return on the investment.</span></p><h3><span>The automation spectrum is context dependent</span></h3><p><span>Full autonomy isn't a goal; it's one end of a spectrum. The right level of automation depends on the context.Internal labs, client engagements, and product integrations each have different risk profiles. Designing for the spectrum rather than a fixed endpoint kept the system flexible.</span></p><h2>What's next for Rapid7 Red Teaming in the age of AI</h2><p><span>We're continuing to develop the system, refining the methodology mapping, expanding specialist capabilities, and exploring where purpose-built models could replace general-purpose LLM calls for specific tasks (such as severity classification, report writing, payload selection). We're also using what we learn from operating this system to inform how Rapid7 detects and responds to AI-enhanced offensive activity in the wild. </span></p><p><span>You can learn more about Vector Command, Rapid7's continuous red-teaming solution, </span><a href="https://www.rapid7.com/services/continuous-red-team-service" target="_self"><span>here</span></a><span>.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Z.ai launches ZCode to challenge Cursor, Claude Code and GitHub Copilot in AI coding]]></title>
<description><![CDATA[Z.ai, the Beijing-based artificial intelligence lab formerly known as Zhipu AI, on Wednesday officially launched ZCode, a free desktop application it describes as an "Agentic Development Environment" purpose-built for its flagship GLM-5.2 large language model. The move marks the company's most ag...]]></description>
<link>https://tsecurity.de/de/3640860/it-nachrichten/zai-launches-zcode-to-challenge-cursor-claude-code-and-github-copilot-in-ai-coding/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640860/it-nachrichten/zai-launches-zcode-to-challenge-cursor-claude-code-and-github-copilot-in-ai-coding/</guid>
<pubDate>Thu, 02 Jul 2026 13:01:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="http://z.ai/">Z.ai</a>, the Beijing-based artificial intelligence lab formerly known as Zhipu AI, on Wednesday officially launched <a href="https://zcode.z.ai/">ZCode</a>, a free desktop application it describes as an "Agentic Development Environment" purpose-built for its flagship <a href="https://z.ai/blog/glm-5.2">GLM-5.2</a> large language model. The move marks the company's most aggressive push yet into the fast-growing AI-powered coding tool market, where it now competes directly with <a href="https://cursor.com/get-started">Cursor</a>, <a href="https://www.anthropic.com/product/claude-code">Claude Code</a>, <a href="https://github.com/features/copilot">GitHub Copilot</a>, and <a href="https://antigravity.google/">Google's Antigravity</a>.</p><p>"Introducing ZCode, the official development environment for GLM-5.2," the company wrote on X, noting the tool is available on macOS, Windows, and Linux, supports bring-your-own-key (BYOK) configurations for third-party models, and offers a 1.5x usage-quota bonus for subscribers to its GLM Coding Plan.</p><p>Read one way, <a href="https://zcode.z.ai/">ZCode</a> is simply another entrant in a crowded market. Read another, it is a single product that crystallizes three of the most consequential trends in enterprise software today: the race-to-the-bottom pricing of frontier AI models, the geopolitical balkanization of the AI stack, and the rapid maturation of agentic coding agents into what Gartner now estimates is a <a href="https://enterprisedna.co/resources/news/gartner-enterprise-ai-coding-agents-10-billion-market-2026/">roughly $10 billion market</a>.</p><div></div><h2><b>An AI coding tool designed to think in projects, not prompts</b></h2><p>Unlike traditional IDEs that bolt on AI through a chat sidebar or autocomplete extension, <a href="https://zcode.z.ai/">ZCode</a> is best understood as an agent-first development environment. Its core design is built around long-horizon tasks: the user describes an outcome, the agent plans the work, edits files, runs checks, reviews progress, and continues across multiple iterations until the goal is met.</p><p><a href="https://zcode.z.ai/">ZCode</a> organizes the development experience around the <a href="https://zcode.z.ai/en">ZCode Agent</a>, deeply tuned for <a href="https://z.ai/blog/glm-5.2">GLM-5.2</a>, with emphasis on deep integration: the model, tools, and execution workflow are tuned together so the Agent fits continuous, multi-step real-world development tasks. The environment supports continuous follow-up across devices: desktop, mobile Remote, and Feishu / WeChat Bot can all keep the same workspace task moving. Sensitive commands, file changes, and high-permission actions go through confirmation before execution.</p><p>That remote-control feature — the ability to steer a running coding agent from <a href="https://www.wechat.com/en">WeChat</a>, <a href="https://baike.baidu.com/en/item/Feishu/14594">Feishu</a>, or <a href="https://web.telegram.org/">Telegram</a> on a phone — is a differentiator that speaks directly to the Chinese developer market, where those messaging platforms dominate professional communication. You can keep checking progress and adding instructions while long-running work continues, from any device with these messaging apps.</p><p>The tool is free to download. Revenue flows through Z.ai's <a href="https://z.ai/subscribe">GLM Coding Plan subscription tiers</a>, which start at $16.20 per month for a "Lite" plan and scale to $144 per month for "Max" — prices that undercut Anthropic's Claude Code and Cursor's comparable tiers by significant margins.</p><p>Through July 31, <a href="https://zcode.z.ai/">ZCode</a> is offering a promotional 1.5x effective quota bonus for Coding Plan subscribers, with off-peak token consumption charged at a 0.67x coefficient. The platform also supports multiple AI models and agents, including Claude Code, Codex, Gemini, and OpenCode — a pragmatic concession to the reality that no single model wins every task.</p><h2><b>GLM-5.2, the open-source model trained entirely on Chinese chips, powers the whole experience</b></h2><p>ZCode's value proposition is inseparable from <a href="https://z.ai/blog/glm-5.2">GLM-5.2</a>, the model it was designed to showcase. Z.ai released GLM-5.2 on June 16, first to its Coding Plan subscribers and subsequently as open-source weights under the MIT license on <a href="https://huggingface.co/zai-org/GLM-5">Hugging Face</a> — a sequencing decision that prioritized distribution over the traditional benchmark-led launch.</p><p>The model's specifications are formidable. GLM-5.2 is a 744-billion-parameter mixture-of-experts architecture with 40 billion active parameters, a genuine one-million-token context window — five times the 200K limit on its predecessor — and training on 28.5 trillion tokens. It ranked second globally on <a href="https://arena.ai/leaderboard/code/webdev">Code Arena </a>as of mid-June, trailing only Anthropic's Claude Fable 5, making it one of the highest-performing publicly available models for coding tasks.</p><p>Critically, the model was built entirely without American chips. As Decrypt reported, GLM-5.2 "<a href="https://decrypt.co/371613/china-z-ai-glm-5-2-model-rivals-claude-opus">runs entirely on Huawei silicon</a>." Stability AI founder Emad Mostaque estimated total training costs at roughly $25 million, with 80 percent spent on post-training — a figure that, if accurate, would make GLM-5.2 extraordinarily cheap relative to Western frontier models.</p><p>On benchmarks, <a href="https://z.ai/blog/glm-5.2">GLM-5.2</a> performs within striking distance of the best proprietary systems. It trails Anthropic's Claude Opus 4.8 by just one percentage point on <a href="https://www.frontierswe.com/">FrontierSWE</a>, a benchmark measuring multi-hour autonomous engineering projects, while edging out OpenAI's <a href="https://openai.com/index/introducing-gpt-5-5/">GPT-5.5</a>. </p><p>Its API pricing — $1.40 per million input tokens and $4.40 per million output — are a cost reduction of up to 82 percent compared to Anthropic's Claude Opus 4.8 at $5 and $25, respectively. Because ZCode is a first-party tool from the same company that makes the model, it requires no manual endpoint configuration — the model is wired in.</p><h2><b>The Anthropic export ban gave Chinese AI its biggest opening yet</b></h2><p>ZCode's arrival cannot be separated from the geopolitical drama that has roiled the AI industry over the past three weeks. On June 12, the U.S. government, <a href="https://www.reuters.com/technology/us-blocks-foreign-access-anthropics-most-advanced-ai-models-axios-reports-2026-06-13/">citing national security authorities</a>, issued an export control directive suspending all access to Anthropic's Fable 5 and Mythos 5 models by any foreign national, whether inside or outside the United States, including foreign national Anthropic employees. Enterprise clients in finance, healthcare, SaaS, and critical infrastructure found their core intelligence services abruptly disabled, without exception, prior warning, or effective recourse.</p><p>While the Trump administration <a href="https://www.cnbc.com/2026/06/30/anthropic-says-trump-admin-has-lifted-export-controls-on-claude-fable-5-and-mythos-5.html">lifted those controls just yesterday</a> — Anthropic confirmed on June 30 that the Department of Commerce had rescinded the directive — the episode sent shockwaves through the developer community and accelerated interest in open-source, self-hostable alternatives. The government's crackdown on Anthropic coincided with a swift rise in Chinese open-source models that are proving to be almost as capable and significantly cheaper than some of the most powerful U.S. models.</p><p>Z.ai's timing was surgical. On the same day the Trump administration ordered Anthropic's most advanced models blocked for foreign nationals, Zhipu announced the <a href="https://z.ai/blog/glm-5.2">open-source release of GLM-5.2</a> with no usage restrictions. The <a href="https://www.scmp.com/tech/article/3343239/chinas-zhipu-ai-launches-new-major-model-glm-5-challenge-its-rivals">South China Morning Post reported </a>that GLM-5.2 would be available to all users of Zhipu's new GLM Coding Plan subscription, "priced at just a tenth of Anthropic's premium Claude Code and Claude Max tiers."</p><p>The market responded accordingly. Zhipu AI's market capitalization crossed HK$1 trillion (<a href="https://www.scmp.com/tech/article/3357858/zhipu-ai-market-cap-tops-hk1-trillion-shares-glm-52-developer-soar">US$128 billion</a>) on June 22, driven by a 42 percent intraday share surge. JPMorgan raised its 2026–2030 revenue forecast for Zhipu by between 7 and 16 percent following the launch, projecting an over 534 percent revenue surge for 2026 and expecting the AI firm to turn a profit by 2028.</p><h2><b>Why vendor lock-in now carries a geopolitical risk that no SLA can cover</b></h2><p>The <a href="https://venturebeat.com/technology/anthropic-is-bringing-back-claude-fable-5-globally-after-us-lifts-export-control-order-where-can-enterprises-access-it">Fable 5 episode</a> did more than embarrass Anthropic. It introduced a new risk category into enterprise AI procurement: sovereign access risk. When a government can disable a commercially deployed AI model overnight, the traditional evaluation criteria of developer experience, benchmark scores, and pricing become secondary to a more fundamental question: Will this tool still work tomorrow?</p><p>The event exposed the inadequacy of standard enterprise contract language. An investigation by <a href="https://www.fifthrow.com/blog/us-export-control-order-and-global-suspension-of-fable-5-mythos-5-operationalizing-compliance-as-a">FifthRow</a> found that almost all standard Data Processing Addenda, SaaS agreements, and procurement SLAs "relied on vague 'force majeure' or 'compliance with law' catch-alls, not on precise, actionable regulatory suspension or kill-switch clauses."</p><p>ZCode's <a href="https://aiidelist.com/ide/zcode">BYOK architecture </a>and <a href="https://z.ai/blog/glm-5.2">GLM-5.2</a>'s MIT-licensed open weights offer a partial answer. A development team can download the model, host it on its own infrastructure, and run ZCode against it without ever touching Z.ai's cloud — eliminating both American export-control risk and Chinese data-sovereignty concerns in a single move. The catch is that anyone using Z.ai's cloud API remains subject to Chinese law, a consideration that evaporates only with pure self-hosting.</p><p>Gartner analysts <a href="https://news.creeta.com/en/gartner-enterprise-ai-coding-agents-2026/">have warned</a> that governance, pricing, support, workflows, commercial maturity, and market durability matter as much as developer experience and model capabilities when evaluating coding agent vendors for enterprise-wide adoption. By that measure, ZCode faces a steep climb. It is not open source itself; Linux support remains in beta; and security reviewers have flagged the need for careful evaluation of its credential handling, particularly for remote development over SSH and messaging-platform-triggered tasks — an agent that can be summoned from WeChat involves access paths that should be mapped before trusting it with anything sensitive.</p><h2><b>Inside the $10 billion race where model labs are becoming full-stack IDE companies</b></h2><p><a href="https://zcode.z.ai/">ZCode</a> enters one of the most crowded and fastest-moving markets in enterprise software. Enterprise AI coding agents are capturing a growing share of enterprise software engineering spend, with the market estimated at roughly $9.8 billion to $11.0 billion annualized as of April 2026, according to <a href="https://enterprisedna.co/resources/news/gartner-enterprise-ai-coding-agents-10-billion-market-2026/">Gartner</a>. A defining shift this year, the analyst firm noted, is "the movement of frontier model providers into direct competition with application-layer vendors" — precisely the pattern ZCode embodies.</p><p>Gartner codified this evolution in May when it <a href="https://openai.com/index/gartner-2026-agentic-coding-leader/">renamed its annual Magic Quadrant</a> from "AI Code Assistants" to "Enterprise AI Coding Agents," defining the category as "autonomous or semiautonomous software engineering solutions that perceive context, translate human intent into multistep plans, and execute and verify those steps across code, tests and related engineering artifacts." The 2026 Magic Quadrant names Anthropic, Cursor, GitHub, and OpenAI as Leaders. Z.ai was not among the 12 vendors evaluated — an absence that underscores both the company's nascent enterprise sales presence outside China and the Western-centric lens through which the analyst community still views the market.</p><p>The competitive landscape is daunting. Cursor is the <a href="https://www.bloomberg.com/news/articles/2026-03-02/cursor-recurring-revenue-doubles-in-three-months-to-2-billion">$2 billion ARR IDE</a> that feels like VS Code with a supercharger. Claude Code reached <a href="https://www.anthropic.com/news/anthropic-raises-30-billion-series-g-funding-380-billion-post-money-valuation">approximately $2.5 billion</a> in annualized revenue by early 2026. Google relaunched <a href="https://blog.google/innovation-and-ai/technology/developers-tools/google-io-2026-developer-highlights/">Antigravity 2.0</a> at I/O in May, and Cognition retired the Windsurf brand, relaunching the IDE as <a href="https://devin.ai/desktop/">Devin Desktop</a> with the Agent Command Center as the default surface.</p><p>Against these entrenched players, ZCode's pitch rests on three pillars: deep first-party integration with GLM-5.2 that no third-party editor can replicate, aggressive pricing that starts at a fraction of Western competitors, and MIT-licensed open weights that allow enterprises to self-host — eliminating the regulatory kill-switch risk that the Fable ban made viscerally real.</p><h2><b>Z.ai's real challenge is turning a $128 billion valuation into a global developer tools business</b></h2><p><a href="http://z.ai/">Z.ai</a> controls the model (<a href="https://z.ai/blog/glm-5.2">GLM-5.2</a>), the subscription layer (<a href="https://z.ai/subscribe">the GLM Coding Plan</a>), and the IDE (<a href="https://zcode.z.ai/">ZCode</a>) — a tightly coupled stack that optimizes for performance but concentrates switching costs. For the company, the business logic is clear. Its most reliable revenue stream has been on-premises deployments for Chinese government agencies, state-owned banks, and energy conglomerates. In full-year 2025, on-premises deployment revenue reached RMB 534 million, growing over 100 percent year-over-year and accounting for 73.7 percent of total revenue with a gross margin of 48.8 percent. ZCode and the GLM Coding Plan represent the company's bid to build a comparable revenue engine in cloud-based developer tools — globally, not just in China.</p><p>The early signals are encouraging for <a href="http://z.ai/">Z.ai</a>, if anecdotal. Community reception on X was enthusiastic, with one early user calling the tool "super stable" and others clamoring for more Coding Plan capacity. "Bro, can't snag your family's Coding Plan? When are you gonna stock up on more cards?" <a href="https://x.com/realchendahuang/status/2072361920976593163">one user wrote in Chinese</a>, suggesting demand is already outstripping supply.</p><p>But the hard questions loom large. Can a Chinese AI company build trust with Western enterprise buyers amid escalating technology tensions? Can ZCode's ecosystem mature fast enough to compete with Cursor's polished UX, Claude Code's deep agent primitives, and GitHub Copilot's unmatched distribution? And can Z.ai sustain a company valued at $128 billion while still losing money? </p><p>What is no longer in question is the competitive dynamic itself. Three weeks ago, a U.S. government directive proved that access to the world's best coding model can vanish overnight. Today, a Chinese lab is shipping a free IDE, an open-source model trained on zero American chips, and a subscription plan that costs less per month than a single lunch in Manhattan. The AI coding agent market did not just become global this summer. It became a market where the fallback option might be better than the thing it's falling back from — and that changes the calculus for every engineering leader choosing a toolchain in the second half of 2026.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Diese versteckte App macht jedes Samsung Galaxy sofort besser]]></title>
<description><![CDATA[Samsung baut seit Jahren hervorragende Smartphones. Doch das volle Potenzial von One UI steckt nicht unbedingt in den Systemeinstellungen, sondern in einer App, die viele Galaxy-Nutzer nie installieren: Good Lock. Was die App alles kann, welche Module sich lohnen und wie Sie Good Lock einrichten,...]]></description>
<link>https://tsecurity.de/de/3640219/it-nachrichten/diese-versteckte-app-macht-jedes-samsung-galaxy-sofort-besser/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640219/it-nachrichten/diese-versteckte-app-macht-jedes-samsung-galaxy-sofort-besser/</guid>
<pubDate>Thu, 02 Jul 2026 07:48:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Samsung baut seit Jahren hervorragende Smartphones. Doch das volle Potenzial von One UI steckt nicht unbedingt in den Systemeinstellungen, sondern in einer App, die viele Galaxy-Nutzer nie installieren: <strong>Good Lock</strong>. Was die App alles kann, welche Module sich lohnen und wie Sie Good Lock einrichten, erfahren Sie hier.</p>



<h2 class="wp-block-heading toc">Was ist Samsung Good Lock?</h2>



<p>Good Lock ist ein offizieller Samsung-Dienst, der als Hub für eine Sammlung von Zusatzmodulen fungiert. Jedes dieser Module greift tief in einen bestimmten Bereich von One UI ein: den Sperrbildschirm, die Navigation, die Kamera, Benachrichtigungen, Multitasking und vieles mehr. Das Ergebnis ist ein Anpassungsgrad, der sonst nur Custom-ROMs vorbehalten war.</p>



<p>Die App ist <strong>vollständig kostenlos</strong>, wird direkt von Samsung entwickelt und ist damit so sicher wie One UI selbst. Mit One UI 8 im Jahr 2026 hat Samsung vier neue Module hinzugefügt und zahlreiche bestehende aktualisiert.</p>



<h2 class="wp-block-heading toc">Für welche Galaxy-Geräte ist Good Lock verfügbar?</h2>



<p>Good Lock läuft <a href="https://www.pcwelt.de/article/1204479/test-das-beste-samsung-galaxy-smartphone.html" data-type="link" data-id="https://www.pcwelt.de/article/1204479/test-das-beste-samsung-galaxy-smartphone.html" target="_blank" rel="noreferrer noopener">auf allen Samsung Galaxy-Geräten</a> mit <strong>One UI 6 oder neuer</strong>. Konkret bedeutet das:</p>



<ul class="wp-block-list">
<li><strong>Galaxy S-Serie</strong>: S23, S23+, S23 Ultra und neuer (inkl. S26-Reihe)</li>



<li><strong>Galaxy Z-Serie</strong>: Z Flip 5 und Z Fold 5 aufwärts</li>



<li><strong>Galaxy A-Serie</strong>: Ausgewählte Modelle mit One UI 6+</li>



<li><strong>Galaxy Tab</strong>: Tab S9 und neuer</li>
</ul>



<p>Good Lock ist im <a href="https://www.awin1.com/cread.php?awinmid=14815&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=https://galaxystore.samsung.com/detail/com.samsung.android.goodlock" data-type="link" data-id="https://www.awin1.com/cread.php?awinmid=14815&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=https://galaxystore.samsung.com/detail/com.samsung.android.goodlock" target="_blank" rel="noreferrer noopener">Samsung Galaxy Store</a> verfügbar und seit Ende 2025 alternativ auch über den <a href="https://play.google.com/store/apps/details?id=com.samsung.android.goodlock&amp;hl=de" data-type="link" data-id="https://play.google.com/store/apps/details?id=com.samsung.android.goodlock&amp;hl=de">Google Play Store</a>, womit die frühere Beschränkung auf bestimmte Länder entfällt. Einzelne Module können jedoch weiterhin regional eingeschränkt sein.</p>



<p><strong>Wichtig:</strong> Die einzelnen Module werden nicht automatisch installiert. Sie wählen selbst, welche Module Sie aktivieren möchten. Das spart Speicherplatz und hält das System übersichtlich.</p>



<h4 class="wp-block-heading">Die besten aktuellen Angebote für das Samsung Galaxy S26</h4>



				<div class="wp-block-price-comparison price-comparison">
		
		<div class="new_products_tab tabcontent ">

			<div class="price-comparison__record price-comparison__record--header">
				<div>
					<span>Shop</span>
				</div>
								<div class="price-comparison__price">
					<span>Preis</span>
				</div>
			</div>

								<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://s24.media/shop/c841a72776cf42cc9c4936ce66ef1f0e" alt="alternate" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>629,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://lg.s24.cloud/catalog/9116/195854/9488934941" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://lg.s24.cloud/catalog/9116/195854/9488934941" data-vendor-api="shopping24" data-vars-product-price="629,00 €" data-vars-product-vendor="alternate" aria-label="Deal anschauen bei alternate für 629,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/24204.png" alt="coolblue" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>629,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=5RhXdKdI83ftiDOfdN0LnJe3tbSWKwr5aE5gRwf5O7p6RmIsvl8L8VovW2rD7AzJop5eUIvJnUoVAesFtOqK6EjMMr4I4bcHmza08zmpKe2a6wSRIJwKsekr84RqXb6_YPkBeTsXFjzgIkq1OUjwH4&amp;mid=686084161694&amp;id=686084161694&amp;ts=20260702&amp;log=rss" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=5RhXdKdI83ftiDOfdN0LnJe3tbSWKwr5aE5gRwf5O7p6RmIsvl8L8VovW2rD7AzJop5eUIvJnUoVAesFtOqK6EjMMr4I4bcHmza08zmpKe2a6wSRIJwKsekr84RqXb6_YPkBeTsXFjzgIkq1OUjwH4&amp;mid=686084161694&amp;id=686084161694&amp;ts=20260702&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="629,00 €" data-vars-product-vendor="coolblue" aria-label="Deal anschauen bei coolblue für 629,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/4541.png" alt="notebooksbilliger" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>645,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=2M_hVxkBGOjgFdiMIpCMzN6uCqCNO8-tL7nY_gEpKI5He66dKLCcTskzmk7s2ctpvSl923nsGZ8vE30bjvaFmhcExcfMRGQgECdBHof2fasebWCvty-nT7AHXdywI10YkyWbwcakYeT&amp;mid=686062104468&amp;id=686062104468&amp;ts=20260702&amp;log=rss" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=2M_hVxkBGOjgFdiMIpCMzN6uCqCNO8-tL7nY_gEpKI5He66dKLCcTskzmk7s2ctpvSl923nsGZ8vE30bjvaFmhcExcfMRGQgECdBHof2fasebWCvty-nT7AHXdywI10YkyWbwcakYeT&amp;mid=686062104468&amp;id=686062104468&amp;ts=20260702&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="645,00 €" data-vars-product-vendor="notebooksbilliger" aria-label="Deal anschauen bei notebooksbilliger für 645,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  amazon_vendor">
						<div class="price-comparison__image">
															<img decoding="async" src="https://www.pcwelt.de/wp-content/themes/idg-base-theme/dist/static/img/amazon-logo.svg" alt="Amazon" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>653,99 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://www.amazon.de/dp/B0GPDRTBFQ?tag=pcwelt.de-21&amp;linkCode=ogi&amp;th=1&amp;psc=1&amp;ascsubtag=rss" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://www.amazon.de/dp/B0GPDRTBFQ?tag=pcwelt.de-21&amp;linkCode=ogi&amp;th=1&amp;psc=1&amp;ascsubtag=rss" data-vendor-api="amazon" data-vars-product-price="653,99 €" data-vars-product-vendor="Amazon" aria-label="Deal anschauen bei Amazon für 653,99 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__hidden-records-wrapper">
									<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/12137.png" alt="Boomstore" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>681,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=IkDanvohS2tvsU1Wdh-mdc5Hd99OQeF7THsqZXwye-WEbEokfk-c7B4WO4b3TQhTLoFn43uV-nFaEmlykUvpU44ctEsCbqg6S9ygKvebEHEx1W2pOuolXrkpeyIRTOAb2V11tAmrzs1&amp;mid=686472923573&amp;id=686472923573&amp;ts=20260702&amp;log=rss" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=IkDanvohS2tvsU1Wdh-mdc5Hd99OQeF7THsqZXwye-WEbEokfk-c7B4WO4b3TQhTLoFn43uV-nFaEmlykUvpU44ctEsCbqg6S9ygKvebEHEx1W2pOuolXrkpeyIRTOAb2V11tAmrzs1&amp;mid=686472923573&amp;id=686472923573&amp;ts=20260702&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="681,00 €" data-vars-product-vendor="Boomstore" aria-label="Deal anschauen bei Boomstore für 681,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/21515.png" alt="JB-Computer" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>687,30 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=oRTBV_k8k-BtiDOfdN0LnJe3tbSWKwr5Zd5k8UHf2Hu6RmIsvl8L8VHKuRs3tP2bop5eUIvJnUoVAesFtOqK6EjMMr4I4bcHmza08zmpKe2a6wSRIJwKsfziX486kitPenRmPhh8kBN&amp;mid=686413404106&amp;id=686413404106&amp;ts=20260702&amp;log=rss" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=oRTBV_k8k-BtiDOfdN0LnJe3tbSWKwr5Zd5k8UHf2Hu6RmIsvl8L8VHKuRs3tP2bop5eUIvJnUoVAesFtOqK6EjMMr4I4bcHmza08zmpKe2a6wSRIJwKsfziX486kitPenRmPhh8kBN&amp;mid=686413404106&amp;id=686413404106&amp;ts=20260702&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="687,30 €" data-vars-product-vendor="JB-Computer" aria-label="Deal anschauen bei JB-Computer für 687,30 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://www.pcwelt.de/wp-content/themes/idg-base-theme/dist/static/img/samsung-logo.svg" alt="Samsung" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>999,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://www.awin1.com/cread.php?awinmid=14815&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=https://www.samsung.com/de/smartphones/galaxy-s26/buy/" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://www.awin1.com/cread.php?awinmid=14815&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=https://www.samsung.com/de/smartphones/galaxy-s26/buy/" data-vars-product-price="999,00 €" data-vars-product-vendor="Samsung" aria-label="Deal anschauen bei Samsung für 999,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
						
									</div>
									<div class="price-comparison__record price-comparison__record--footer">
					<span class="price-comparison__footer-text">
													Preisvergleich (über 24.000 Shops weltweit)												</span>
											<button class="price-comparison__view-more-button">
							Weitere Angebote						</button>
									</div>
		</div>

		<div class="refurbished_products_tab tabcontent">
			<div class="refurbished-padding price-comparison__record price-comparison__record--header">
				<div>
					<span>Produkt</span>
				</div>
				<div class="price-comparison__price">
					<span>Preis</span>
				</div>
			</div>
							<div class="price-comparison__record price-comparison__record--footer">
					<span class="price-comparison__footer-text">
					Preisvergleich von Backmarket						</span>
									</div>
		</div>
		</div>
		


<h2 class="wp-block-heading toc">So installieren Sie Good Lock</h2>



<ol class="wp-block-list">
<li>Öffnen Sie den <strong>Galaxy Store</strong> auf Ihrem Samsung-Gerät (oder Google Play Store).</li>



<li>Suchen Sie nach “<a href="https://www.awin1.com/cread.php?awinmid=14815&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=https://galaxystore.samsung.com/detail/com.samsung.android.goodlock" data-type="link" data-id="https://www.awin1.com/cread.php?awinmid=14815&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=https://galaxystore.samsung.com/detail/com.samsung.android.goodlock">Good Lock</a>“. Das Icon zeigt vier farbige, ineinandergreifende Puzzleteile.</li>



<li>Installieren und öffnen Sie die App.</li>



<li>Wählen Sie die gewünschten Module direkt in Good Lock aus und laden Sie sie per Tap herunter.</li>
</ol>



<p><strong>Tipp:</strong> Installieren Sie nicht alle Module auf einmal. Starten Sie mit zwei oder drei, die Ihrem konkreten Bedarf entsprechen. </p>



<h2 class="wp-block-heading toc">Wie ist Good Lock aufgebaut?</h2>



<p>Good Lock selbst ist nur die Schaltzentrale. Nach der Installation sehen Sie eine übersichtliche Oberfläche mit vier Bereichen:</p>



<ul class="wp-block-list">
<li><strong>Make up</strong>: Module zur optischen Anpassung, etwa Themes, Sperrbildschirm und Hintergrundbilder.</li>



<li><strong>Life up</strong>: Module für Funktionen und Effizienz, zum Beispiel Navigation, Kamera, Multitasking und Audio.</li>



<li><strong>Clock</strong>: Eigenständige Kategorie für Uhren-Module (zum Beispiel ClockFace für das Always-On-Display).</li>



<li><strong>Extensions</strong>: Zusatzmodule, die quer durch die beiden Hauptkategorien “Make up” und “Life up” verfügbar sind.</li>
</ul>



<p>Tippen Sie auf ein Modul, können Sie es direkt dort herunterladen und installieren, also ohne Umweg über den Galaxy Store. Insgesamt stehen aktuell <strong>mehr als 20 Module</strong> zur Verfügung.</p>


<div class="extendedBlock-wrapper block-coreImage left"><figure data-wp-context='{"imageId":"6a45fb5edff02"}' data-wp-interactive="core/image" class="wp-block-image alignleft size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/vs.png?w=1200" alt="Good Lock Overview" class="wp-image-3171243" width="1200" height="675" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Ein Überblick über die Good Lock-App von Samsung.</p>
</figcaption></figure><p class="imageCredit">PC-Welt</p></div>



<h2 class="wp-block-heading toc">Die wichtigsten Module im Überblick</h2>



<h3 class="wp-block-heading">Theme Park</h3>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a45fb5ee0d74"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/theme-park.png?w=1200" alt="good lock theme park" class="wp-image-3171247" width="1200" height="763" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Good Lock: Erstellen Sie eigene Themes &amp; Designs mit Theme Park.</p><br></figcaption></figure><p class="imageCredit">PC-Welt</p></div>



<p>Theme Park ist der Einstieg in die optische Personalisierung. Das Modul ermöglicht es, eigene Themes zu erstellen: Farben, Icon-Formen, Hintergrundbilder und Schriftarten lassen sich frei kombinieren. Vorhandene Icon-Packs aus dem Play Store können eingebunden und verwaltet werden.</p>



<p>Seit 2026 gibt es sogar einen <strong>KI-Theme-Generator</strong>. Sie beschreiben per Text, wie Ihr Theme aussehen soll, und die KI erstellt automatisch ein passendes Farbschema inklusive Icons und Hintergrundbild.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">One Hand Operation+</h3>



<p>Falls Sie, so wie ich, ein Galaxy S Ultra oder Z Fold besitzen, haben Sie bestimmt schon bemerkt: Einhändige Bedienung ist eine Herausforderung. One Hand Operation+ löst das Problem mit sechs konfigurierbaren Edge-Gesten (drei pro Seite). Jede Geste kann individuell belegt werden: Zurück, App-Übersicht, Screenshot, Taschenlampe, Benachrichtigungen und mehr.</p>



<p>Das Besondere daran ist, dass das Modul parallel zur normalen Navigationsleiste funktioniert und diese um zusätzliche Wischgesten ergänzt.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">LockStar</h3>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a45fb5ee2058"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/lockstar.png?w=1200" alt="Lockstar Good Lock" class="wp-image-3171249" width="1200" height="614" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Good Lock: Mit dem “LockStar” Modul personalisieren Sie Ihren Sperrbildschirm.</p>
</figcaption></figure><p class="imageCredit">PC-Welt</p></div>



<p>Der Sperrbildschirm ist das Erste, was Sie sehen, wenn Sie Ihr Smartphone in die Hand nehmen. One UI lässt ihn aber nur begrenzt anpassen. LockStar öffnet hier deutlich mehr Spielraum. Per WYSIWYG-Editor ziehen Sie Uhr, Datum, Widgets und App-Shortcuts frei auf dem Bildschirm hin und her, sowohl im Hoch- als auch im Querformat. Elemente, die Ihnen nicht gefallen, blenden Sie einfach aus.</p>



<p>Besonders nützlich: LockStar schaltet <strong>App-Widgets auf dem Sperrbildschirm</strong> frei, die Samsung standardmäßig nicht erlaubt. So sehen Sie etwa den Kalender, den Schrittzähler oder die Wettervorschau direkt auf dem gesperrten Display, ohne das Smartphone erst zu entsperren. Auch App-Shortcuts lassen sich frei platzieren. Ein Tipp auf das Kamera-Symbol startet die Kamera, ohne den Entsperrvorgang zu durchlaufen.</p>



<p>Neu im Jahr 2026 sind außerdem animierte <strong>Entsperreffekte</strong>. Die neue Animation Swirl dreht den Sperrbildschirm beim Entsperren herein, und weitere Stile wie Curtain, Ripple, Mosaic oder Wave sorgen dafür, dass selbst das Entsperren des Telefons ein kleines visuelles Erlebnis wird.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">MultiStar</h3>



<p>MultiStar erweitert die Multitasking-Funktionen erheblich. Jede App kann im geteilten Bildschirm oder als Popup-Fenster geöffnet werden (auch solche, die das offiziell nicht unterstützen). Neu seit 2026 sind <strong>App-Paare auf dem Homescreen</strong>, die zwei Apps gleichzeitig im Split-Screen starten.</p>



<p>Für Foldable-Nutzer unverzichtbar: MultiStar steuert, wie Apps beim Auf- und Zuklappen zwischen Cover- und Hauptbildschirm wechseln. Samsung DeX-Nutzer profitieren von Optionen wie höheren Auflösungen oder mehr als fünf gleichzeitigen Apps auf dem verbundenen Display.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">RegiStar</h3>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a45fb5ee3047"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/registar.png?w=1200" alt="RegiStar Good Lock" class="wp-image-3171258" width="1200" height="794" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Good Lock: Passen Sie mit dem RegiStar Modul ganz einfach Ihre Galaxy-Einstellungen an.</p>
</figcaption></figure><p class="imageCredit">PC-Welt</p></div>



<p>RegiStar ist das Modul für alle, denen die Standardbelegung von Tasten und Gesten nicht weit genug geht. Das bekannteste Feature ist die <strong>Backtap-Geste</strong>: Wenn Sie zweimal auf die Rückseite Ihres Smartphones tippen, öffnet sich eine frei wählbare App oder Funktion (etwa die Taschenlampe, ein Screenshot oder Expert RAW). Gerade wenn die Ein-/Aus-Taste bereits für Gemini oder die Kamera reserviert ist, schafft Backtap eine praktische dritte Steuermöglichkeit, die vollkommen unsichtbar bleibt.</p>



<p>Überdies lässt sich mit RegiStar auch die <strong>Seitentaste</strong> neu belegen: Doppeltippen und langes Drücken können unabhängig voneinander mit eigenen Aktionen verknüpft werden. Wer möchte, startet so per langem Druck direkt eine bestimmte App statt den Sprachassistenten.</p>



<p>Weniger bekannt, aber ebenso nützlich: Mit RegiStar können Sie das <strong>Einstellungsmenü von One UI umstrukturieren</strong>. Bereiche, die Sie nie benötigen, lassen sich ausblenden und häufig genutzte nach oben schieben. Die integrierte <strong>Einstellungshistorie</strong> protokolliert dabei alle kürzlich vorgenommenen Änderungen im System.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">NavStar</h3>



<p>Die Navigationsleiste sieht man täglich, doch anpassen lässt sie sich in One UI kaum. NavStar ändert das. Sofern Sie die klassische Tastennavigation nutzen, können Sie Layout, Reihenfolge und Farbe der Schaltflächen frei gestalten, den Hintergrund der Leiste einfärben und eine zusätzliche Schaltfläche einblenden, mit der sich die Leiste bei Bedarf auf Knopfdruck verstecken lässt. </p>



<p>Wenn Sie per Wischgesten navigieren, lassen sich die Empfindlichkeit und der Aktionsbereich für die linke und rechte Seite unabhängig voneinander einstellen. Das ist praktisch, wenn Sie etwa links mehr Spielraum für die Zurück-Geste möchten. Außerdem entscheiden Sie, ob der Strich am unteren Bildschirmrand sichtbar bleibt oder dezent ausblendet.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">Camera Assistant</h3>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a45fb5ee3dc0"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/camera-assistant.png?w=1200" alt="good lock camera assistant" class="wp-image-3171263" width="1200" height="820" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>“Camera Assistant” ermöglicht es, versteckte Kamerafunktionen freizuschalten.</p>
</figcaption></figure><p class="imageCredit">PC-Welt</p></div>



<p>Camera Assistant schaltet versteckte Kamerafunktionen frei. Auf der Galaxy S26-Reihe aktiviert das Modul den <strong>24-Megapixel-Modus</strong>, der KI-Fusionsverarbeitung nutzt: schärfer als 12 MP, kleinere Dateien als 50 MP. Ein guter Sweetspot für den Alltag. Zu den weiteren Funktionen zählen unter anderem folgende:</p>



<ul class="wp-block-list">
<li><strong>Fokus-Peaking</strong> im Pro-Modus markiert scharf gestellte Bildbereiche farbig, was besonders bei manueller Fokussierung hilft.</li>



<li><strong>Serienbilder mit Intervall</strong> ermöglichen zeitgesteuerte Aufnahmeserien, etwa für Zeitraffer-Vorbereitungen. </li>



<li><strong>Auto-HDR</strong> aktiviert sich automatisch, wenn die Kamera starke Helligkeitsunterschiede erkennt</li>



<li><strong>Automatisches Objektivwechseln</strong> lässt das Gerät je nach Motiv und Zoomstufe selbst das optimale Objektiv wählen.</li>



<li><strong>Der</strong> <strong>Astro-Modus-Shortcut</strong> macht den Nachtfotografie-Modus direkt erreichbar.</li>



<li><strong>Benutzerdefinierte Auflösungsvoreinstellungen</strong> erlauben es, bevorzugte Megapixel-Stufen dauerhaft zu speichern und schnell umzuschalten.</li>
</ul>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">NotiStar</h3>



<p>Benachrichtigungen verschwinden schnell – manchmal zu schnell. NotiStar löst dieses Problem mit einer vollständigen <strong>Benachrichtigungshistorie</strong>, die alle eingegangenen Mitteilungen speichert, bis Sie sie selbst löschen. Auch versehentlich weggewischte Benachrichtigungen lassen sich so jederzeit nachlesen.</p>



<p>Weiterhin bietet NotiStar eine personalisierte <strong>Filterfunktion</strong>: Sie legen fest, von welchen Apps Sie Benachrichtigungen sehen möchten und von welchen nicht. Noch präziser wird es mit Keyword-Filtern: So können Sie beispielsweise einstellen, dass Sie von einer bestimmten App nur dann benachrichtigt werden, wenn die Nachricht ein bestimmtes Wort enthält, etwa “Rechnung” oder “Termin”. Benachrichtigungen, die den Filter nicht erfüllen, werden verworfen oder nur in der Historie gespeichert, ohne dass sie Sie aktiv stören.</p>



<p>Auch für den Sperrbildschirm ist NotiStar praktisch. Dort greift es nämlich ebenfalls, sodass Sie genau steuern, was auf dem gesperrten Display sichtbar ist. Im Februar 2026 hat Samsung das Modul mit einer überarbeiteten Benachrichtigungsverwaltung aktualisiert, die die Übersicht über mehrere Apps hinweg nochmals verbessert.</p>



<h2 class="wp-block-heading toc">Weitere empfehlenswerte Module</h2>



<ul class="wp-block-list">
<li><strong>Home Up</strong>: Anpassung des Launchers wie Rastergröße, App-Drawer, Share-Menü bereinigen </li>



<li><strong>Keys Cafe</strong>: Tastaturlayout, Tastatureffekte und Sounds </li>



<li><strong>QuickStar</strong>: Statusleisten-Symbole hinzufügen oder entfernen, Quick-Settings direkt öffnen </li>



<li><strong>Routines+</strong>: Erweiterte Bixby-Automationen mit Touch-Makros und App-basierten Auslösern </li>



<li><strong>Wonderland</strong>: Lebendige Parallax-Hintergrundbilder mit Bewegungseffekten </li>



<li><strong>ClockFace</strong>: Individuelle Uhr für Always-On-Display und Sperrbildschirm </li>



<li><strong>Game Booster+</strong>: Gamepad-Touch-Mapping, AP-Taktbegrenzung, Game-Intro-Schnellvorlauf </li>



<li><strong>Pentastic</strong>: S-Pen-Zeigerstile und Air-Command-Anpassungen (für S-Pen-Geräte) </li>



<li><strong>Nice Catch</strong>: Systemprotokoll für Benachrichtigungen, Vibrationen und Einstellungsänderungen</li>
</ul>



<p>Sollte das alles noch nicht ausreichen, finden Sie hier noch mehr Tipps, um Ihr Galaxy zu optimieren: <a href="https://www.pcwelt.de/article/2957766/android-tricks-versteckte-funktionen-ausprobieren.html" target="_blank" rel="noreferrer noopener">Diese 11 versteckten Android-Funktionen sollten Sie sofort ausprobieren</a>.</p>



<p>Und falls Sie ein Galaxy S26 besitzen: <a href="https://www.pcwelt.de/article/3136236/galaxy-s26-ultra-tipps-tricks.html" target="_blank" rel="noreferrer noopener">Die besten Tipps und Tricks für Samsung Galaxy S26</a>.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[A better way to control AI costs]]></title>
<description><![CDATA[As an old Delphi guy, I remember well the “language wars” we had with the Visual Basic guys. An early codename for Delphi was “VBK” — VB Killer — and the VB community took exception. They’d come to our Delphi forums and pick fights. Naturally, we brash Delphi guys would fight back, engaging in bi...]]></description>
<link>https://tsecurity.de/de/3639434/ai-nachrichten/a-better-way-to-control-ai-costs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639434/ai-nachrichten/a-better-way-to-control-ai-costs/</guid>
<pubDate>Wed, 01 Jul 2026 20:33:49 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>As an old <a href="https://en.wikipedia.org/wiki/Delphi_(software)" data-type="link" data-id="https://en.wikipedia.org/wiki/Delphi_(software)">Delphi</a> guy, I remember well the “language wars” we had with the <a href="https://en.wikipedia.org/wiki/Visual_Basic_(classic)" data-type="link" data-id="https://en.wikipedia.org/wiki/Visual_Basic_(classic)">Visual Basic</a> guys. An early codename for Delphi was “VBK” — VB Killer — and the VB community took exception. They’d come to our Delphi forums and pick fights. Naturally, we brash Delphi guys would fight back, engaging in big flame wars and getting all worked up over what wasn’t much more than a personal preference. Good times.</p>



<p>These days, we’ve moved the discussion up a layer — what is the better model for coding? Things aren’t quite as intense as the VB/Delphi dustups, but people have their opinions. Companies are taking a look at different models before choosing one for their teams. Most teams have arrived at a family of models that they use. </p>



<p>At some point, chatting with Claude or Codex started to seem a bit raw. It wasn’t long before scaffolding tools like <a href="https://github.com/garrytan/gstack" data-type="link" data-id="https://github.com/garrytan/gstack">GStack</a> and <a href="https://github.com/obra/Superpowers" data-type="link" data-id="https://github.com/obra/Superpowers">Superpowers</a> were adding underpinnings for interacting with LLMs — baseline instructions for handling prompts before they get to the model itself. They help establish useful context and act as a layer above “raw prompting”. <a href="https://www.infoworld.com/article/4127462/what-is-context-engineering-and-why-its-the-new-ai-architecture.html" data-type="link" data-id="https://www.infoworld.com/article/4127462/what-is-context-engineering-and-why-its-the-new-ai-architecture.html">Context engineering</a> is the first and most common layer to add on top of the chat interface.</p>



<p>And then once the choice of models and harnesses was made, everyone went <a href="https://www.infoworld.com/article/4170173/tokenmaxxing-is-super-dumb.html">crazy with tokenmaxxing</a>. If you have a model, of course you want to get the most out of it. But when the bill came in, managers were not pleased. As costs skyrocketed, leadership worried that the money wasn’t being well spent. </p>



<h2 class="wp-block-heading">Model routing – the next layer</h2>



<p>Just as assembly language and hand-tuning registers gave way to compilers and structured languages, which led to frameworks and libraries, and most recently to LLMs and prompting, it is starting to occur to developers and managers that there is a better way to manage LLM spending. </p>



<p>But naturally, the minute you figure out how things work, another layer appears, making all your hard-earned knowledge outdated. <a href="https://www.infoworld.com/article/4018953/the-ultimate-software-engineering-abstraction.html">Apparently being able to code in English</a> isn’t enough to stop the next abstraction from appearing.</p>



<p>So as is always the case, <a href="https://medium.com/nickonsoftware/what-is-the-next-layer-bdc0280723a8">another layer of abstraction has come along</a>. (<em>Sic semper fuit</em>.) Thus model routing is the latest way to maximize the value for each dollar spent on tokens. </p>



<p>The idea is that not all prompts are created equal. Not everything that you ask Claude is going to require the deep thinking of a frontier model. A model router can take a look at the prompt and decide what model is best suited to answer that prompt and direct the query to that model. Maybe simpler requests are better suited for an older model. Maybe code reviews are better done with a model specifically designed for that purpose. </p>



<p>Model routing leads to more efficient token spending. When you run Claude Code today, you have to choose a model for the whole session, and if you want to use the top-tier model, you have to pay for it no matter what you end up doing. A model router lets you vary the model — and thus the cost. <a href="https://x.com/brian_armstrong/status/2070670644577280109?s=20">Organizations like Coinbase</a> are seeing their AI spend cut in half while their token usage increases. </p>



<h2 class="wp-block-heading">From tokenmaxxing to tokenmatching </h2>



<p>LLMs are constantly evolving, becoming both more powerful and more specialized. Being able to route a prompt to the model that is both well-suited for the task and cost-effective is the way to maximize token effectiveness. Teams are doing this manually now, but AI itself will become the best way to make such decisions. </p>



<p>For example, <a href="https://github.com/musistudio/claude-code-router">Claude Code Router</a> can route prompts to any number of popular models, depending on the type of work each prompt requires. And it’s open source. </p>



<p>The next layer that is coming is the preprocessing of prompts. We can work to write good prompts, but AI itself can improve upon what we ask. One of the best techniques in prompting is to tell the LLM to “ask the questions that I’m not asking but should be asking”. I can easily imagine a world in which you write a prompt, AI helps you clarify it, improves it, and then routes it to the best, most cost-effective model for an answer. </p>



<p>You won’t be choosing a given LLM provider anymore. Instead, you can focus on specifying exactly what you want. So stop hand-crafting your prompts for a specific model. Let the coming model routers and prompt preprocessors do the hard work for you.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Top 10 Data Protection Software in 2026: Expert Guide]]></title>
<description><![CDATA[Ransomware and large-scale data breaches have become two of the most expensive risks a business can face, and the regulatory stakes keep rising. GDPR, HIPAA and the EU’s NIS2 directive now impose steep penalties for mishandling sensitive data. Against that backdrop, choosing the right data protec...]]></description>
<link>https://tsecurity.de/de/3637743/it-security-nachrichten/top-10-data-protection-software-in-2026-expert-guide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637743/it-security-nachrichten/top-10-data-protection-software-in-2026-expert-guide/</guid>
<pubDate>Wed, 01 Jul 2026 09:35:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="hs-featured-image-wrapper"> 
 <a href="https://www.cm-alliance.com/cybersecurity-blog/top-10-data-protection-software-in-2026-expert-guide" title="" class="hs-featured-image-link"> <img src="https://www.cm-alliance.com/hubfs/Modern_Office_Data_Protection_Dashboard-1_with_bgc.webp" alt="Top 10 Data Protection Software" class="hs-featured-image"> </a> 
</div> 
<p><span>Ransomware and large-scale data breaches have become two of the most expensive risks a business can face, and the regulatory stakes keep rising. GDPR, HIPAA and the EU’s NIS2 directive now impose steep penalties for mishandling sensitive data. Against that backdrop, choosing the right data protection software is a core security decision rather than something to sort out after an incident.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google's Gemini Omni Flash hits the API, turning enterprise video production into a conversation]]></title>
<description><![CDATA[For most enterprises, a 90-second training video or a product explainer has never been an easy ask. It means a well planned brief, an internal film crew or an outside vendor, a shoot, an edit, and a round of revisions. Change one line of on-screen text due to a legal review and the whole chain ru...]]></description>
<link>https://tsecurity.de/de/3636544/it-nachrichten/googles-gemini-omni-flash-hits-the-api-turning-enterprise-video-production-into-a-conversation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636544/it-nachrichten/googles-gemini-omni-flash-hits-the-api-turning-enterprise-video-production-into-a-conversation/</guid>
<pubDate>Tue, 30 Jun 2026 20:02:36 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>For most enterprises, a 90-second training video or a product explainer has never been an easy ask. It means a well planned brief, an internal film crew or an outside vendor, a shoot, an edit, and a round of revisions. Change one line of on-screen text due to a legal review and the whole chain runs again. The cost and the long time lines are why so much internal video never gets made.</p><p>That equation is what Google is aiming to rewrite with <a href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-omni-3-5-videos/">Gemini Omni Flash</a>, the first model in its new "Omni" family, now rolling out to developers and enterprise customers through an API after debuting to consumers at I/O 2026. Google frames the family's ambition as creating anything "from any input," starting with video. But the headline interaction isn't just a sharper text-to-video prompt. It's the ability to edit a finished clip through conversation.</p><div></div><p>When the model launched in May, <a href="https://venturebeat.com/technology/google-unveils-gemini-omni-any-to-any-ai-model-what-enterprises-should-know">VentureBeat's enterprise analysis</a> flagged the catch: with no programmatic interface, Omni was a consumer and prosumer tool, not a production one. This API rollout changes that. It puts conversational editing in front of the marketing and learning-and-development teams that make the most videos in an organization.</p><h2><b>The pitch: a five-tool pipeline collapses into a single conversation</b></h2><p>Until now, many teams have been assembling AI videos the hard way, bolting together an LLM for a script, a text-to-image model, an image-to-video model, a separate lip-sync tool and a voice generator, each with its own contract, billing and data path. </p><p>Omni's enterprise argument is unification: one model that takes text, images and video and returns a finished clip with synced audio.</p><p>That simplicity factor is the part decision-makers should weigh first. Collapsing several point tools into one model means fewer vendors and a single place to monitor output and enforce data-handling rules. For an organization that has avoided generative video because stitching the tools together wasn't worth the overhead, the equation shifts.</p><p>With conversational editing each instruction builds on the last, so a marketer can relight a product shot, reframe it, or change the wardrobe without regenerating from scratch and losing the parts that already worked. It is the difference between booking a reshoot and sending a note.</p><h2><b>Multimodal references and a physics engine for brand assets</b></h2><p>Omni accepts far more than a text prompt. Alongside the words describing what you want, you can feed it multiple reference images, and existing video clips, and it carries those specifics into the result. Hand it a photograph of a particular object, ask the model to place that object into a scene, and it reproduces the real thing's coloring and rough shape instead of inventing a generic stand-in. While the match might not be pixel-perfect, it is close enough to be recognizable. That reference-driven control is what makes the feature commercially interesting: a product photo, a brand logo, or a specific location can be dropped in as an ingredient rather than described in a prompt and hoped for.</p><p>Two of Google's four highlighted strengths speak directly to enterprise work. The first is a world model, the system's grasp of how physical scenes behave. Add light rain and puddles to an existing shot and it renders reflections of the people and objects in the wet pavement, the sort of physical consistency that separates real footage from obvious AI video. </p><p>The second is text and logo insertion. Point it at a scene full of signage and you can have it rewrite those signs in another language, or for a brand of your choosing, and even drop in a company's logo. The results aren't flawless: in testing, sign tracking in complex scenes weren’t always perfect and some text slipped back to the original language between frames. For training videos that need on-screen labels, or ads that need a logo placed in-scene, it is a capability worth a close look, and a reminder that the output still needs a human review before it ships.</p><h2><b>The interactions API and where the limits still bite</b></h2><p>Under the hood, this runs on Google's new interactions API, a stateful interface built for multi-turn tasks rather than open-ended chat. Each turn carries the previous video and its references forward, which is what lets edits accumulate coherently. Developers can chain generations. They can produce a clip, edit the cat into a puma kitten, restyle a video into 8-bit retro and then into a watercolor look, and store each version to branch from later.</p><p>The constraints are real and worth budgeting around. Clips currently cap at 10 seconds, per the model's <a href="https://deepmind.google/models/model-cards/gemini-omni-flash/">published model card</a>. To make something longer, you generate chunks and edit them together. Uploaded footage can be edited too, as long as it runs 10 seconds or under and the user holds the rights to it. Google's own model card is candid that holding consistency across edits and rendering accurate text remain open problems.</p><h2><b>Guardrails, watermarking and the line Google won't cross</b></h2><p>For a CISO, the demos matter less than the provenance work shipping alongside the model. Every Omni clip carries Google's SynthID watermark, Google is extending C2PA Content Credentials across its generative tools, and it has launched an AI Content Detection API that flags AI-generated media, both Google's and other vendors'.</p><p>Google has also drawn a deliberate line. The model won't take a still photo of a person plus an audio clip and lip-sync them into speech, an explicit move to limit deepfakes. It will, however, take a recording of someone talking and translate it into another language, a useful path for localizing global training content. For regulated enterprises, those constraints and the baked-in provenance are features rather than friction.</p><div></div><h2><b>The numbers: cheap, 720p-only, and (preliminarily) ranked first</b></h2><p>The pricing landed alongside the API, and it is aggressive. Omni Flash costs $0.10 per second of generated 720p video, which puts a ten-second clip at roughly a dollar. That matches Veo 3.1 Fast at the same resolution, runs double Veo 3.1 Lite, and undercuts standard Veo 3.1 by three-quarters.</p><table><tbody><tr><td><p><b>Per second (USD)</b></p></td><td><p><b>Gemini Omni Flash</b></p></td><td><p><b>Veo 3.1 Lite</b></p></td><td><p><b>Veo 3.1 Fast</b></p></td><td><p><b>Veo 3.1</b></p></td></tr><tr><td><p>720p</p></td><td><p>$0.10</p></td><td><p>$0.05</p></td><td><p>$0.10</p></td><td><p>$0.40</p></td></tr><tr><td><p>1080p</p></td><td><p>n/a</p></td><td><p>$0.08</p></td><td><p>$0.12</p></td><td><p>$0.40</p></td></tr><tr><td><p>4K</p></td><td><p>n/a</p></td><td><p>n/a</p></td><td><p>$0.30</p></td><td><p>$0.60</p></td></tr></tbody></table><p>
The table also exposes the catch though. Omni Flash only generates 720p. There is no 1080p or 4K option, while the Veo tiers scale up to 4K. For internal training and most social video, 720p is fine. For premium brand work meant for a large screen, it is a real ceiling, and the reason Veo 3.1 still has a job</p><p>Clips run 3 to 10 seconds at 720p native, in landscape (16:9) or portrait (9:16). As reference inputs the model accepts up to seven images and up to three video clips of three seconds or less. It does not take audio as an input yet, though it generates audio alongside the video it produces. Output is standard MP4, and every clip ships with SynthID watermarking and C2PA credentials baked in.</p><p>On quality, the early signal is strong. In LMArena's Text-to-Video Arena, a leaderboard where people vote on head-to-head outputs from competing models, Omni Flash sat at number one with a score of 1527. </p><h2><b>What it means for budgets, and what's still missing</b></h2><p>With real pricing in hand, the iteration story gets concrete. Every conversational edit is a fresh generation you pay for, so an edit-heavy session still adds up, roughly a dollar for each ten-second pass at 720p. What the stateful model changes isn't the cost of an edit, it's the number of wasted ones: because context carries across turns, those generations go toward refining a take that mostly works instead of restarting from a blank prompt and hoping the next attempt lands.</p><p>Omni isn't alone in this field. Veo 3.1 remains Google's production-grade option when you need higher resolution, and rivals from Bytedance, Alibaba and OpenAI are all chasing the same budgets. What Omni adds is the editing capability itself: the ability to treat a video as a living document instead of a one-shot render.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Choosing their own moment: Why these longtime Microsofties are taking the buyout ]]></title>
<description><![CDATA[GeekWire spoke with several longtime Microsoft employees who are taking the company's first-ever voluntary retirement program, about why they decided to leave and what they're doing next. Their reasons range from timing and finances to fatigue with the pace of change, and their next chapters incl...]]></description>
<link>https://tsecurity.de/de/3636477/it-nachrichten/choosing-their-own-moment-why-these-longtime-microsofties-are-taking-the-buyout/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636477/it-nachrichten/choosing-their-own-moment-why-these-longtime-microsofties-are-taking-the-buyout/</guid>
<pubDate>Tue, 30 Jun 2026 19:47:58 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1200" height="896" src="https://cdn.geekwire.com/wp-content/uploads/2026/06/shawn.png" class="webfeedsFeaturedVisual wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://cdn.geekwire.com/wp-content/uploads/2026/06/shawn.png 1200w, https://cdn.geekwire.com/wp-content/uploads/2026/06/shawn-768x573.png 768w" sizes="(max-width: 1200px) 100vw, 1200px"><br>GeekWire spoke with several longtime Microsoft employees who are taking the company's first-ever voluntary retirement program, about why they decided to leave and what they're doing next. Their reasons range from timing and finances to fatigue with the pace of change, and their next chapters include startups, a doctorate, conservation work, a return to the trades and, yes, actual retirement.  <a href="https://www.geekwire.com/2026/choosing-their-own-moment-why-these-longtime-microsofties-are-taking-the-buyout/">Read More</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[A better way to manage LLM spending]]></title>
<description><![CDATA[As an old Delphi guy, I remember well the “language wars” we had with the Visual Basic guys. An early codename for Delphi was “VBK” — VB Killer — and the VB community took exception. They’d come to our Delphi forums and pick fights. Naturally, we brash Delphi guys would fight back, engaging in bi...]]></description>
<link>https://tsecurity.de/de/3636426/ai-nachrichten/a-better-way-to-manage-llm-spending/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636426/ai-nachrichten/a-better-way-to-manage-llm-spending/</guid>
<pubDate>Tue, 30 Jun 2026 19:18:37 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>As an old <a href="https://en.wikipedia.org/wiki/Delphi_(software)" data-type="link" data-id="https://en.wikipedia.org/wiki/Delphi_(software)">Delphi</a> guy, I remember well the “language wars” we had with the <a href="https://en.wikipedia.org/wiki/Visual_Basic_(classic)" data-type="link" data-id="https://en.wikipedia.org/wiki/Visual_Basic_(classic)">Visual Basic</a> guys. An early codename for Delphi was “VBK” — VB Killer — and the VB community took exception. They’d come to our Delphi forums and pick fights. Naturally, we brash Delphi guys would fight back, engaging in big flame wars and getting all worked up over what wasn’t much more than a personal preference. Good times.</p>



<p>These days, we’ve moved the discussion up a layer — what is the better model for coding? Things aren’t quite as intense as the VB/Delphi dustups, but people have their opinions. Companies are taking a look at different models before choosing one for their teams. Most teams have arrived at a family of models that they use. </p>



<p>At some point, chatting with Claude or Codex started to seem a bit raw. It wasn’t long before scaffolding tools like <a href="https://github.com/garrytan/gstack" data-type="link" data-id="https://github.com/garrytan/gstack">GStack</a> and <a href="https://github.com/obra/Superpowers" data-type="link" data-id="https://github.com/obra/Superpowers">Superpowers</a> were adding underpinnings for interacting with LLMs — baseline instructions for handling prompts before they get to the model itself. They help establish useful context and act as a layer above “raw prompting”. <a href="https://www.infoworld.com/article/4127462/what-is-context-engineering-and-why-its-the-new-ai-architecture.html" data-type="link" data-id="https://www.infoworld.com/article/4127462/what-is-context-engineering-and-why-its-the-new-ai-architecture.html">Context engineering</a> is the first and most common layer to add on top of the chat interface.</p>



<p>And then once the choice of models and harnesses was made, everyone went <a href="https://www.infoworld.com/article/4170173/tokenmaxxing-is-super-dumb.html">crazy with tokenmaxxing</a>. If you have a model, of course you want to get the most out of it. But when the bill came in, managers were not pleased. As costs skyrocketed, leadership worried that the money wasn’t being well spent. </p>



<h2 class="wp-block-heading">Model routing – the next layer</h2>



<p>Just as assembly language and hand-tuning registers gave way to compilers and structured languages, which led to frameworks and libraries, and most recently to LLMs and prompting, it is starting to occur to developers and managers that there is a better way to manage LLM spending. </p>



<p>But naturally, the minute you figure out how things work, another layer appears, making all your hard-earned knowledge outdated. <a href="https://www.infoworld.com/article/4018953/the-ultimate-software-engineering-abstraction.html">Apparently being able to code in English</a> isn’t enough to stop the next abstraction from appearing.</p>



<p>So as is always the case, <a href="https://medium.com/nickonsoftware/what-is-the-next-layer-bdc0280723a8">another layer of abstraction has come along</a>. (<em>Sic semper fuit</em>.) Thus model routing is the latest way to maximize the value for each dollar spent on tokens. </p>



<p>The idea is that not all prompts are created equal. Not everything that you ask Claude is going to require the deep thinking of a frontier model. A model router can take a look at the prompt and decide what model is best suited to answer that prompt and direct the query to that model. Maybe simpler requests are better suited for an older model. Maybe code reviews are better done with a model specifically designed for that purpose. </p>



<p>Model routing leads to more efficient token spending. When you run Claude Code today, you have to choose a model for the whole session, and if you want to use the top-tier model, you have to pay for it no matter what you end up doing. A model router lets you vary the model — and thus the cost. <a href="https://x.com/brian_armstrong/status/2070670644577280109?s=20">Organizations like Coinbase</a> are seeing their AI spend cut in half while their token usage increases. </p>



<h2 class="wp-block-heading">From tokenmaxxing to tokenmatching </h2>



<p>LLMs are constantly evolving, becoming both more powerful and more specialized. Being able to route a prompt to the model that is both well-suited for the task and cost-effective is the way to maximize token effectiveness. Teams are doing this manually now, but AI itself will become the best way to make such decisions. </p>



<p>For example, <a href="https://github.com/musistudio/claude-code-router">Claude Code Router</a> can route prompts to any number of popular models, depending on the type of work each prompt requires. And it’s open source. </p>



<p>The next layer that is coming is the preprocessing of prompts. We can work to write good prompts, but AI itself can improve upon what we ask. One of the best techniques in prompting is to tell the LLM to “ask the questions that I’m not asking but should be asking”. I can easily imagine a world in which you write a prompt, AI helps you clarify it, improves it, and then routes it to the best, most cost-effective model for an answer. </p>



<p>You won’t be choosing a given LLM provider anymore. Instead, you can focus on specifying exactly what you want. So stop hand-crafting your prompts for a specific model. Let the coming model routers and prompt preprocessors do the hard work for you.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[US Supreme Court Rules Geofence Warrants Require Constitutional Privacy Protections]]></title>
<description><![CDATA[The U.S. Supreme Court ruled 6-3 (PDF) in Chatrie v United States (No. 25-112) that geofence warrants sweeping up smartphone location data constitute searches under the Fourth Amendment. The Court found that individuals have a "reasonable expectation of privacy" in such data, even when the tracki...]]></description>
<link>https://tsecurity.de/de/3636060/it-security-nachrichten/us-supreme-court-rules-geofence-warrants-require-constitutional-privacy-protections/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636060/it-security-nachrichten/us-supreme-court-rules-geofence-warrants-require-constitutional-privacy-protections/</guid>
<pubDate>Tue, 30 Jun 2026 17:10:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The U.S. Supreme Court ruled 6-3 (PDF) in Chatrie v United States (No. 25-112) that geofence warrants sweeping up smartphone location data constitute searches under the Fourth Amendment. The Court found that individuals have a "reasonable expectation of privacy" in such data, even when the tracking covers only a brief period or records movements in public. "An individual has a reasonable expectation of privacy in records about his cell phone's location, and police intrude on that constitutionally protected interest when they demand the information -- even though for only a limited time, and from a third-party tech company," wrote Justice Elena Kagan. Longtime Slashdot reader schwit1 submitted the story. The Guardian reports: The use of geofence warrants is widespread, and gives law enforcement agencies the power to compel tech companies to hand over sensitive cell phone data from people at or near crime scenes. The warrants allow police and the FBI to collect this information from individuals within the radius of a virtual "fence" during a particular timeframe. But they are not restricted to requesting data for precise targets.
 
The Chatrie case focuses on local police's pursuit of an armed bank robber in Richmond, Virginia. He fled with $195,000. Law enforcement tracked Okello Chatrie down through their use of geofence warrants. Chatrie had opted in to an optional Google "location history" feature that documented his location every few minutes. He was eventually sentenced to 12 years in prison, after pleading guilty. Chatrie's lawyers argued that this search was overly broad and violated his fourth amendment rights, which protects individuals from "unreasonable search and seizure." Lawyers said that police's use of geofence warrants amounted to an official "search" under the fourth amendment, and didn't meet the constitution's requirements for one.
 
The government had argued that accessing only a short amount of cellphone location information means this tactic does not count as a fourth amendment search and accordingly, should not be afforded the same privacy protections. But the judges in the majority disagreed. The judges in the majority opinion also wrote that the government's characterization of generating location history as a voluntary choice is "meritless." They suggested that people aren't choosing to share private information with third parties and the government "just by doing the ordinary thing cellphone users do." "The point of carrying smartphones is to use what is on them," including the apps and services they provide -- many of which use location data to customize a user's experience, they said.
 
[...] While the majority opinion noted that police conducted a fourth amendment search by accessing Chatrie's location history data, they noted that the court of appeals will weigh in on whether the "search was reasonable, meaning that each of its steps was properly described with particularity and found to be supported by probable cause." Law enforcement has said they need geofence warrants to find suspects and witnesses -- after reaching dead ends. The US government, for its part, has argued that people can't have a "reasonable expectation of privacy" when they are in public and have allowed a third party company, such as Google, to collect and analyze phone location data.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=US+Supreme+Court+Rules+Geofence+Warrants+Require+Constitutional+Privacy+Protections%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F06%2F30%2F064251%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F06%2F30%2F064251%2Fus-supreme-court-rules-geofence-warrants-require-constitutional-privacy-protections%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/06/30/064251/us-supreme-court-rules-geofence-warrants-require-constitutional-privacy-protections?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Diese versteckte App macht jedes Samsung Galaxy sofort besser]]></title>
<description><![CDATA[Samsung baut seit Jahren hervorragende Smartphones. Doch das volle Potenzial von One UI steckt nicht unbedingt in den Systemeinstellungen, sondern in einer App, die viele Galaxy-Nutzer nie installieren: Good Lock. Was die App alles kann, welche Module sich lohnen und wie Sie Good Lock einrichten,...]]></description>
<link>https://tsecurity.de/de/3635754/it-nachrichten/diese-versteckte-app-macht-jedes-samsung-galaxy-sofort-besser/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635754/it-nachrichten/diese-versteckte-app-macht-jedes-samsung-galaxy-sofort-besser/</guid>
<pubDate>Tue, 30 Jun 2026 15:32:21 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Samsung baut seit Jahren hervorragende Smartphones. Doch das volle Potenzial von One UI steckt nicht unbedingt in den Systemeinstellungen, sondern in einer App, die viele Galaxy-Nutzer nie installieren: <strong>Good Lock</strong>. Was die App alles kann, welche Module sich lohnen und wie Sie Good Lock einrichten, erfahren Sie hier.</p>



<h2 class="wp-block-heading toc">Was ist Samsung Good Lock?</h2>



<p>Good Lock ist ein offizieller Samsung-Dienst, der als Hub für eine Sammlung von Zusatzmodulen fungiert. Jedes dieser Module greift tief in einen bestimmten Bereich von One UI ein: den Sperrbildschirm, die Navigation, die Kamera, Benachrichtigungen, Multitasking und vieles mehr. Das Ergebnis ist ein Anpassungsgrad, der sonst nur Custom-ROMs vorbehalten war.</p>



<p>Die App ist <strong>vollständig kostenlos</strong>, wird direkt von Samsung entwickelt und ist damit so sicher wie One UI selbst. Mit One UI 8 im Jahr 2026 hat Samsung vier neue Module hinzugefügt und zahlreiche bestehende aktualisiert.</p>



<h2 class="wp-block-heading toc">Für welche Galaxy-Geräte ist Good Lock verfügbar?</h2>



<p>Good Lock läuft <a href="https://www.pcwelt.de/article/1204479/test-das-beste-samsung-galaxy-smartphone.html" data-type="link" data-id="https://www.pcwelt.de/article/1204479/test-das-beste-samsung-galaxy-smartphone.html" target="_blank" rel="noreferrer noopener">auf allen Samsung Galaxy-Geräten</a> mit <strong>One UI 6 oder neuer</strong>. Konkret bedeutet das:</p>



<ul class="wp-block-list">
<li><strong>Galaxy S-Serie</strong>: S23, S23+, S23 Ultra und neuer (inkl. S26-Reihe)</li>



<li><strong>Galaxy Z-Serie</strong>: Z Flip 5 und Z Fold 5 aufwärts</li>



<li><strong>Galaxy A-Serie</strong>: Ausgewählte Modelle mit One UI 6+</li>



<li><strong>Galaxy Tab</strong>: Tab S9 und neuer</li>
</ul>



<p>Good Lock ist im <a href="https://www.awin1.com/cread.php?awinmid=14815&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=https://galaxystore.samsung.com/detail/com.samsung.android.goodlock" data-type="link" data-id="https://www.awin1.com/cread.php?awinmid=14815&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=https://galaxystore.samsung.com/detail/com.samsung.android.goodlock" target="_blank" rel="noreferrer noopener">Samsung Galaxy Store</a> verfügbar und seit Ende 2025 alternativ auch über den <a href="https://play.google.com/store/apps/details?id=com.samsung.android.goodlock&amp;hl=de" data-type="link" data-id="https://play.google.com/store/apps/details?id=com.samsung.android.goodlock&amp;hl=de">Google Play Store</a>, womit die frühere Beschränkung auf bestimmte Länder entfällt. Einzelne Module können jedoch weiterhin regional eingeschränkt sein.</p>



<p><strong>Wichtig:</strong> Die einzelnen Module werden nicht automatisch installiert. Sie wählen selbst, welche Module Sie aktivieren möchten. Das spart Speicherplatz und hält das System übersichtlich.</p>



<h4 class="wp-block-heading">Die besten aktuellen Angebote für das Samsung Galaxy S26</h4>



				<div class="wp-block-price-comparison price-comparison">
		
		<div class="new_products_tab tabcontent ">

			<div class="price-comparison__record price-comparison__record--header">
				<div>
					<span>Shop</span>
				</div>
								<div class="price-comparison__price">
					<span>Preis</span>
				</div>
			</div>

								<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/4541.png" alt="notebooksbilliger" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>645,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=2M_hVxkBGOjgFdiMIpCMzN6uCqCNO8-tL7nY_gEpKI5He66dKLCcTskzmk7s2ctpvSl923nsGZ8vE30bjvaFmhcExcfMRGQgECdBHof2fasebWCvty-nT7AHXdywI10YkyWbwcakYeT&amp;mid=686062104468&amp;id=686062104468&amp;ts=20260630&amp;log=rss" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=2M_hVxkBGOjgFdiMIpCMzN6uCqCNO8-tL7nY_gEpKI5He66dKLCcTskzmk7s2ctpvSl923nsGZ8vE30bjvaFmhcExcfMRGQgECdBHof2fasebWCvty-nT7AHXdywI10YkyWbwcakYeT&amp;mid=686062104468&amp;id=686062104468&amp;ts=20260630&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="645,00 €" data-vars-product-vendor="notebooksbilliger" aria-label="Deal anschauen bei notebooksbilliger für 645,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  amazon_vendor">
						<div class="price-comparison__image">
															<img decoding="async" src="https://www.pcwelt.de/wp-content/themes/idg-base-theme/dist/static/img/amazon-logo.svg" alt="Amazon" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>653,99 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://www.amazon.de/dp/B0GPDRTBFQ?tag=pcwelt.de-21&amp;linkCode=ogi&amp;th=1&amp;psc=1&amp;ascsubtag=rss" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://www.amazon.de/dp/B0GPDRTBFQ?tag=pcwelt.de-21&amp;linkCode=ogi&amp;th=1&amp;psc=1&amp;ascsubtag=rss" data-vendor-api="amazon" data-vars-product-price="653,99 €" data-vars-product-vendor="Amazon" aria-label="Deal anschauen bei Amazon für 653,99 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://s24.media/shop/11af34f513114e17ab24f15ca5083429" alt="Baur Versand" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>679,99 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://lg.s24.cloud/catalog/9116/189565/9597578911" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://lg.s24.cloud/catalog/9116/189565/9597578911" data-vendor-api="shopping24" data-vars-product-price="679,99 €" data-vars-product-vendor="Baur Versand" aria-label="Deal anschauen bei Baur Versand für 679,99 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/934.png" alt="baur.de" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>679,99 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=_K2euBFgD2xVf28VzW0Dp4eF8ZBoGX1q7oclkqNGPtB1g7_hVoNHUkzJ7qk5fi_BFKfpa4qJRMyifaNTjVLvixX1TOnIqOwJA2V-OBS6X81SacX3_ODkWrISnBARmtrczkp3az1ABJkAZJDmuINrRwl0EGfRgUmYznRzjb2RSOS&amp;mid=686076524991&amp;id=686076524991&amp;ts=20260630&amp;log=rss" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=_K2euBFgD2xVf28VzW0Dp4eF8ZBoGX1q7oclkqNGPtB1g7_hVoNHUkzJ7qk5fi_BFKfpa4qJRMyifaNTjVLvixX1TOnIqOwJA2V-OBS6X81SacX3_ODkWrISnBARmtrczkp3az1ABJkAZJDmuINrRwl0EGfRgUmYznRzjb2RSOS&amp;mid=686076524991&amp;id=686076524991&amp;ts=20260630&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="679,99 €" data-vars-product-vendor="baur.de" aria-label="Deal anschauen bei baur.de für 679,99 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__hidden-records-wrapper">
									<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/3667.png" alt="OTTO" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>679,99 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=ToyoE3Qog-EXVSmyu4TSBO4UKYrRUyPbHn5RGr8i_UEDftWI6HGQteiX-dvICJsBwFHOlsImnQSXBMXHzERkICGVoUEnRc6u9avFq6OT0rA7VT824OXt7uONAUhNTIj6j4iYt2zObaKLfJYdwB_xfA&amp;mid=686062118215&amp;id=686062118215&amp;ts=20260630&amp;log=rss" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=ToyoE3Qog-EXVSmyu4TSBO4UKYrRUyPbHn5RGr8i_UEDftWI6HGQteiX-dvICJsBwFHOlsImnQSXBMXHzERkICGVoUEnRc6u9avFq6OT0rA7VT824OXt7uONAUhNTIj6j4iYt2zObaKLfJYdwB_xfA&amp;mid=686062118215&amp;id=686062118215&amp;ts=20260630&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="679,99 €" data-vars-product-vendor="OTTO" aria-label="Deal anschauen bei OTTO für 679,99 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/12137.png" alt="Boomstore" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>681,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=IkDanvohS2tvsU1Wdh-mdc5Hd99OQeF7THsqZXwye-WEbEokfk-c7B4WO4b3TQhTLoFn43uV-nFaEmlykUvpU44ctEsCbqg6S9ygKvebEHEx1W2pOuolXrkpeyIRTOAb2V11tAmrzs1&amp;mid=686472923573&amp;id=686472923573&amp;ts=20260630&amp;log=rss" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=IkDanvohS2tvsU1Wdh-mdc5Hd99OQeF7THsqZXwye-WEbEokfk-c7B4WO4b3TQhTLoFn43uV-nFaEmlykUvpU44ctEsCbqg6S9ygKvebEHEx1W2pOuolXrkpeyIRTOAb2V11tAmrzs1&amp;mid=686472923573&amp;id=686472923573&amp;ts=20260630&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="681,00 €" data-vars-product-vendor="Boomstore" aria-label="Deal anschauen bei Boomstore für 681,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/21515.png" alt="JB-Computer" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>687,30 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=oRTBV_k8k-BtiDOfdN0LnJe3tbSWKwr5Zd5k8UHf2Hu6RmIsvl8L8VHKuRs3tP2bop5eUIvJnUoVAesFtOqK6EjMMr4I4bcHmza08zmpKe2a6wSRIJwKsfziX486kitPenRmPhh8kBN&amp;mid=686413404106&amp;id=686413404106&amp;ts=20260630&amp;log=rss" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=oRTBV_k8k-BtiDOfdN0LnJe3tbSWKwr5Zd5k8UHf2Hu6RmIsvl8L8VHKuRs3tP2bop5eUIvJnUoVAesFtOqK6EjMMr4I4bcHmza08zmpKe2a6wSRIJwKsfziX486kitPenRmPhh8kBN&amp;mid=686413404106&amp;id=686413404106&amp;ts=20260630&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="687,30 €" data-vars-product-vendor="JB-Computer" aria-label="Deal anschauen bei JB-Computer für 687,30 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/10729.png" alt="expert TechnoMarkt" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>759,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=OXcFQDJvwPyf7aDQSDOyE5FKGokce325hq5LL3gM66IY-582rLDAxQL84zXWnZWKQFHOlsImnQSXBMXHzERkIBAnQR6H9n2rHm1gr7cvp0-K65NXJdFDS4n0AtweNGU7w&amp;mid=686472936462&amp;id=686472936462&amp;ts=20260630&amp;log=rss" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=OXcFQDJvwPyf7aDQSDOyE5FKGokce325hq5LL3gM66IY-582rLDAxQL84zXWnZWKQFHOlsImnQSXBMXHzERkIBAnQR6H9n2rHm1gr7cvp0-K65NXJdFDS4n0AtweNGU7w&amp;mid=686472936462&amp;id=686472936462&amp;ts=20260630&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="759,00 €" data-vars-product-vendor="expert TechnoMarkt" aria-label="Deal anschauen bei expert TechnoMarkt für 759,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://www.pcwelt.de/wp-content/themes/idg-base-theme/dist/static/img/samsung-logo.svg" alt="Samsung" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>999,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://www.awin1.com/cread.php?awinmid=14815&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=https://www.samsung.com/de/smartphones/galaxy-s26/buy/" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://www.awin1.com/cread.php?awinmid=14815&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=https://www.samsung.com/de/smartphones/galaxy-s26/buy/" data-vars-product-price="999,00 €" data-vars-product-vendor="Samsung" aria-label="Deal anschauen bei Samsung für 999,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
						
									</div>
									<div class="price-comparison__record price-comparison__record--footer">
					<span class="price-comparison__footer-text">
													Preisvergleich (über 24.000 Shops weltweit)												</span>
											<button class="price-comparison__view-more-button">
							Weitere Angebote						</button>
									</div>
		</div>

		<div class="refurbished_products_tab tabcontent">
			<div class="refurbished-padding price-comparison__record price-comparison__record--header">
				<div>
					<span>Produkt</span>
				</div>
				<div class="price-comparison__price">
					<span>Preis</span>
				</div>
			</div>
							<div class="price-comparison__record price-comparison__record--footer">
					<span class="price-comparison__footer-text">
					Preisvergleich von Backmarket						</span>
									</div>
		</div>
		</div>
		


<h2 class="wp-block-heading toc">So installieren Sie Good Lock</h2>



<ol class="wp-block-list">
<li>Öffnen Sie den <strong>Galaxy Store</strong> auf Ihrem Samsung-Gerät (oder Google Play Store).</li>



<li>Suchen Sie nach “<a href="https://www.awin1.com/cread.php?awinmid=14815&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=https://galaxystore.samsung.com/detail/com.samsung.android.goodlock" data-type="link" data-id="https://www.awin1.com/cread.php?awinmid=14815&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=https://galaxystore.samsung.com/detail/com.samsung.android.goodlock">Good Lock</a>“. Das Icon zeigt vier farbige, ineinandergreifende Puzzleteile.</li>



<li>Installieren und öffnen Sie die App.</li>



<li>Wählen Sie die gewünschten Module direkt in Good Lock aus und laden Sie sie per Tap herunter.</li>
</ol>



<p><strong>Tipp:</strong> Installieren Sie nicht alle Module auf einmal. Starten Sie mit zwei oder drei, die Ihrem konkreten Bedarf entsprechen. </p>



<h2 class="wp-block-heading toc">Wie ist Good Lock aufgebaut?</h2>



<p>Good Lock selbst ist nur die Schaltzentrale. Nach der Installation sehen Sie eine übersichtliche Oberfläche mit vier Bereichen:</p>



<ul class="wp-block-list">
<li><strong>Make up</strong>: Module zur optischen Anpassung, etwa Themes, Sperrbildschirm und Hintergrundbilder.</li>



<li><strong>Life up</strong>: Module für Funktionen und Effizienz, zum Beispiel Navigation, Kamera, Multitasking und Audio.</li>



<li><strong>Clock</strong>: Eigenständige Kategorie für Uhren-Module (zum Beispiel ClockFace für das Always-On-Display).</li>



<li><strong>Extensions</strong>: Zusatzmodule, die quer durch die beiden Hauptkategorien “Make up” und “Life up” verfügbar sind.</li>
</ul>



<p>Tippen Sie auf ein Modul, können Sie es direkt dort herunterladen und installieren, also ohne Umweg über den Galaxy Store. Insgesamt stehen aktuell <strong>mehr als 20 Module</strong> zur Verfügung.</p>


<div class="extendedBlock-wrapper block-coreImage left"><figure data-wp-context='{"imageId":"6a43c5342b68a"}' data-wp-interactive="core/image" class="wp-block-image alignleft size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/vs.png?w=1200" alt="Good Lock Overview" class="wp-image-3171243" width="1200" height="675" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Ein Überblick über die Good Lock-App von Samsung.</p>
</figcaption></figure><p class="imageCredit">PC-Welt</p></div>



<h2 class="wp-block-heading toc">Die wichtigsten Module im Überblick</h2>



<h3 class="wp-block-heading">Theme Park</h3>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a43c5342be1c"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/theme-park.png?w=1200" alt="good lock theme park" class="wp-image-3171247" width="1200" height="763" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Good Lock: Erstellen Sie eigene Themes &amp; Designs mit Theme Park.</p><br></figcaption></figure><p class="imageCredit">PC-Welt</p></div>



<p>Theme Park ist der Einstieg in die optische Personalisierung. Das Modul ermöglicht es, eigene Themes zu erstellen: Farben, Icon-Formen, Hintergrundbilder und Schriftarten lassen sich frei kombinieren. Vorhandene Icon-Packs aus dem Play Store können eingebunden und verwaltet werden.</p>



<p>Seit 2026 gibt es sogar einen <strong>KI-Theme-Generator</strong>. Sie beschreiben per Text, wie Ihr Theme aussehen soll, und die KI erstellt automatisch ein passendes Farbschema inklusive Icons und Hintergrundbild.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">One Hand Operation+</h3>



<p>Falls Sie, so wie ich, ein Galaxy S Ultra oder Z Fold besitzen, haben Sie bestimmt schon bemerkt: Einhändige Bedienung ist eine Herausforderung. One Hand Operation+ löst das Problem mit sechs konfigurierbaren Edge-Gesten (drei pro Seite). Jede Geste kann individuell belegt werden: Zurück, App-Übersicht, Screenshot, Taschenlampe, Benachrichtigungen und mehr.</p>



<p>Das Besondere daran ist, dass das Modul parallel zur normalen Navigationsleiste funktioniert und diese um zusätzliche Wischgesten ergänzt.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">LockStar</h3>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a43c5342c552"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/lockstar.png?w=1200" alt="Lockstar Good Lock" class="wp-image-3171249" width="1200" height="614" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Good Lock: Mit dem “LockStar” Modul personalisieren Sie Ihren Sperrbildschirm.</p>
</figcaption></figure><p class="imageCredit">PC-Welt</p></div>



<p>Der Sperrbildschirm ist das Erste, was Sie sehen, wenn Sie Ihr Smartphone in die Hand nehmen. One UI lässt ihn aber nur begrenzt anpassen. LockStar öffnet hier deutlich mehr Spielraum. Per WYSIWYG-Editor ziehen Sie Uhr, Datum, Widgets und App-Shortcuts frei auf dem Bildschirm hin und her, sowohl im Hoch- als auch im Querformat. Elemente, die Ihnen nicht gefallen, blenden Sie einfach aus.</p>



<p>Besonders nützlich: LockStar schaltet <strong>App-Widgets auf dem Sperrbildschirm</strong> frei, die Samsung standardmäßig nicht erlaubt. So sehen Sie etwa den Kalender, den Schrittzähler oder die Wettervorschau direkt auf dem gesperrten Display, ohne das Smartphone erst zu entsperren. Auch App-Shortcuts lassen sich frei platzieren. Ein Tipp auf das Kamera-Symbol startet die Kamera, ohne den Entsperrvorgang zu durchlaufen.</p>



<p>Neu im Jahr 2026 sind außerdem animierte <strong>Entsperreffekte</strong>. Die neue Animation Swirl dreht den Sperrbildschirm beim Entsperren herein, und weitere Stile wie Curtain, Ripple, Mosaic oder Wave sorgen dafür, dass selbst das Entsperren des Telefons ein kleines visuelles Erlebnis wird.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">MultiStar</h3>



<p>MultiStar erweitert die Multitasking-Funktionen erheblich. Jede App kann im geteilten Bildschirm oder als Popup-Fenster geöffnet werden (auch solche, die das offiziell nicht unterstützen). Neu seit 2026 sind <strong>App-Paare auf dem Homescreen</strong>, die zwei Apps gleichzeitig im Split-Screen starten.</p>



<p>Für Foldable-Nutzer unverzichtbar: MultiStar steuert, wie Apps beim Auf- und Zuklappen zwischen Cover- und Hauptbildschirm wechseln. Samsung DeX-Nutzer profitieren von Optionen wie höheren Auflösungen oder mehr als fünf gleichzeitigen Apps auf dem verbundenen Display.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">RegiStar</h3>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a43c5342cc76"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/registar.png?w=1200" alt="RegiStar Good Lock" class="wp-image-3171258" width="1200" height="794" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Good Lock: Passen Sie mit dem RegiStar Modul ganz einfach Ihre Galaxy-Einstellungen an.</p>
</figcaption></figure><p class="imageCredit">PC-Welt</p></div>



<p>RegiStar ist das Modul für alle, denen die Standardbelegung von Tasten und Gesten nicht weit genug geht. Das bekannteste Feature ist die <strong>Backtap-Geste</strong>: Wenn Sie zweimal auf die Rückseite Ihres Smartphones tippen, öffnet sich eine frei wählbare App oder Funktion (etwa die Taschenlampe, ein Screenshot oder Expert RAW). Gerade wenn die Ein-/Aus-Taste bereits für Gemini oder die Kamera reserviert ist, schafft Backtap eine praktische dritte Steuermöglichkeit, die vollkommen unsichtbar bleibt.</p>



<p>Überdies lässt sich mit RegiStar auch die <strong>Seitentaste</strong> neu belegen: Doppeltippen und langes Drücken können unabhängig voneinander mit eigenen Aktionen verknüpft werden. Wer möchte, startet so per langem Druck direkt eine bestimmte App statt den Sprachassistenten.</p>



<p>Weniger bekannt, aber ebenso nützlich: Mit RegiStar können Sie das <strong>Einstellungsmenü von One UI umstrukturieren</strong>. Bereiche, die Sie nie benötigen, lassen sich ausblenden und häufig genutzte nach oben schieben. Die integrierte <strong>Einstellungshistorie</strong> protokolliert dabei alle kürzlich vorgenommenen Änderungen im System.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">NavStar</h3>



<p>Die Navigationsleiste sieht man täglich, doch anpassen lässt sie sich in One UI kaum. NavStar ändert das. Sofern Sie die klassische Tastennavigation nutzen, können Sie Layout, Reihenfolge und Farbe der Schaltflächen frei gestalten, den Hintergrund der Leiste einfärben und eine zusätzliche Schaltfläche einblenden, mit der sich die Leiste bei Bedarf auf Knopfdruck verstecken lässt. </p>



<p>Wenn Sie per Wischgesten navigieren, lassen sich die Empfindlichkeit und der Aktionsbereich für die linke und rechte Seite unabhängig voneinander einstellen. Das ist praktisch, wenn Sie etwa links mehr Spielraum für die Zurück-Geste möchten. Außerdem entscheiden Sie, ob der Strich am unteren Bildschirmrand sichtbar bleibt oder dezent ausblendet.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">Camera Assistant</h3>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a43c5342d351"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/camera-assistant.png?w=1200" alt="good lock camera assistant" class="wp-image-3171263" width="1200" height="820" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>“Camera Assistant” ermöglicht es, versteckte Kamerafunktionen freizuschalten.</p>
</figcaption></figure><p class="imageCredit">PC-Welt</p></div>



<p>Camera Assistant schaltet versteckte Kamerafunktionen frei. Auf der Galaxy S26-Reihe aktiviert das Modul den <strong>24-Megapixel-Modus</strong>, der KI-Fusionsverarbeitung nutzt: schärfer als 12 MP, kleinere Dateien als 50 MP. Ein guter Sweetspot für den Alltag. Zu den weiteren Funktionen zählen unter anderem folgende:</p>



<ul class="wp-block-list">
<li><strong>Fokus-Peaking</strong> im Pro-Modus markiert scharf gestellte Bildbereiche farbig, was besonders bei manueller Fokussierung hilft.</li>



<li><strong>Serienbilder mit Intervall</strong> ermöglichen zeitgesteuerte Aufnahmeserien, etwa für Zeitraffer-Vorbereitungen. </li>



<li><strong>Auto-HDR</strong> aktiviert sich automatisch, wenn die Kamera starke Helligkeitsunterschiede erkennt</li>



<li><strong>Automatisches Objektivwechseln</strong> lässt das Gerät je nach Motiv und Zoomstufe selbst das optimale Objektiv wählen.</li>



<li><strong>Der</strong> <strong>Astro-Modus-Shortcut</strong> macht den Nachtfotografie-Modus direkt erreichbar.</li>



<li><strong>Benutzerdefinierte Auflösungsvoreinstellungen</strong> erlauben es, bevorzugte Megapixel-Stufen dauerhaft zu speichern und schnell umzuschalten.</li>
</ul>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">NotiStar</h3>



<p>Benachrichtigungen verschwinden schnell – manchmal zu schnell. NotiStar löst dieses Problem mit einer vollständigen <strong>Benachrichtigungshistorie</strong>, die alle eingegangenen Mitteilungen speichert, bis Sie sie selbst löschen. Auch versehentlich weggewischte Benachrichtigungen lassen sich so jederzeit nachlesen.</p>



<p>Weiterhin bietet NotiStar eine personalisierte <strong>Filterfunktion</strong>: Sie legen fest, von welchen Apps Sie Benachrichtigungen sehen möchten und von welchen nicht. Noch präziser wird es mit Keyword-Filtern: So können Sie beispielsweise einstellen, dass Sie von einer bestimmten App nur dann benachrichtigt werden, wenn die Nachricht ein bestimmtes Wort enthält, etwa “Rechnung” oder “Termin”. Benachrichtigungen, die den Filter nicht erfüllen, werden verworfen oder nur in der Historie gespeichert, ohne dass sie Sie aktiv stören.</p>



<p>Auch für den Sperrbildschirm ist NotiStar praktisch. Dort greift es nämlich ebenfalls, sodass Sie genau steuern, was auf dem gesperrten Display sichtbar ist. Im Februar 2026 hat Samsung das Modul mit einer überarbeiteten Benachrichtigungsverwaltung aktualisiert, die die Übersicht über mehrere Apps hinweg nochmals verbessert.</p>



<h2 class="wp-block-heading toc">Weitere empfehlenswerte Module</h2>



<ul class="wp-block-list">
<li><strong>Home Up</strong>: Anpassung des Launchers wie Rastergröße, App-Drawer, Share-Menü bereinigen </li>



<li><strong>Keys Cafe</strong>: Tastaturlayout, Tastatureffekte und Sounds </li>



<li><strong>QuickStar</strong>: Statusleisten-Symbole hinzufügen oder entfernen, Quick-Settings direkt öffnen </li>



<li><strong>Routines+</strong>: Erweiterte Bixby-Automationen mit Touch-Makros und App-basierten Auslösern </li>



<li><strong>Wonderland</strong>: Lebendige Parallax-Hintergrundbilder mit Bewegungseffekten </li>



<li><strong>ClockFace</strong>: Individuelle Uhr für Always-On-Display und Sperrbildschirm </li>



<li><strong>Game Booster+</strong>: Gamepad-Touch-Mapping, AP-Taktbegrenzung, Game-Intro-Schnellvorlauf </li>



<li><strong>Pentastic</strong>: S-Pen-Zeigerstile und Air-Command-Anpassungen (für S-Pen-Geräte) </li>



<li><strong>Nice Catch</strong>: Systemprotokoll für Benachrichtigungen, Vibrationen und Einstellungsänderungen</li>
</ul>



<p>Sollte das alles noch nicht ausreichen, finden Sie hier noch mehr Tipps, um Ihr Galaxy zu optimieren: <a href="https://www.pcwelt.de/article/2957766/android-tricks-versteckte-funktionen-ausprobieren.html" target="_blank" rel="noreferrer noopener">Diese 11 versteckten Android-Funktionen sollten Sie sofort ausprobieren</a>.</p>



<p>Und falls Sie ein Galaxy S26 besitzen: <a href="https://www.pcwelt.de/article/3136236/galaxy-s26-ultra-tipps-tricks.html" target="_blank" rel="noreferrer noopener">Die besten Tipps und Tricks für Samsung Galaxy S26</a>.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stop Choosing Between Local and Cloud LLMs: A Field Guide to Hybrid Patterns]]></title>
<description><![CDATA[A hands-on walkthrough of a hybrid local-cloud workflow using Gemma 4 and GPT-5.4, with reasoning and structured outputs
The post Stop Choosing Between Local and Cloud LLMs: A Field Guide to Hybrid Patterns appeared first on Towards Data Science.]]></description>
<link>https://tsecurity.de/de/3635502/ai-nachrichten/stop-choosing-between-local-and-cloud-llms-a-field-guide-to-hybrid-patterns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635502/ai-nachrichten/stop-choosing-between-local-and-cloud-llms-a-field-guide-to-hybrid-patterns/</guid>
<pubDate>Tue, 30 Jun 2026 14:03:29 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A hands-on walkthrough of a hybrid local-cloud workflow using Gemma 4 and GPT-5.4, with reasoning and structured outputs</p>
<p>The post <a href="https://towardsdatascience.com/stop-choosing-between-local-and-cloud-llms-a-field-guide-to-hybrid-patterns/">Stop Choosing Between Local and Cloud LLMs: A Field Guide to Hybrid Patterns</a> appeared first on <a href="https://towardsdatascience.com/">Towards Data Science</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-59057 | remix-run react-router API meta cross site scripting (GHSA-3cgp-3xvw-98x8 / EUVD-2026-1469)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in remix-run react-router. The affected element is the function meta of the component API. This manipulation causes cross site scripting.

This vulnerability appears as CVE-2025-59057. The attack may be initiated remotely. There is no avail...]]></description>
<link>https://tsecurity.de/de/3634683/sicherheitsluecken/cve-2025-59057-remix-run-react-router-api-meta-cross-site-scripting-ghsa-3cgp-3xvw-98x8-euvd-2026-1469/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634683/sicherheitsluecken/cve-2025-59057-remix-run-react-router-api-meta-cross-site-scripting-ghsa-3cgp-3xvw-98x8-euvd-2026-1469/</guid>
<pubDate>Tue, 30 Jun 2026 08:05:56 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/remix-run:react-router">remix-run react-router</a>. The affected element is the function <code>meta</code> of the component <em>API</em>. This manipulation causes cross site scripting.

This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2025-59057">CVE-2025-59057</a>. The attack may be initiated remotely. There is no available exploit.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-21884 | remix-run react-router API getKey/storageKey cross site scripting (GHSA-8v8x-cx79-35w7 / EUVD-2026-1466)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in remix-run react-router. This affects an unknown function of the component API. Performing a manipulation of the argument getKey/storageKey results in cross site scripting.

This vulnerability is known as CVE-2026-21884. Remot...]]></description>
<link>https://tsecurity.de/de/3634679/sicherheitsluecken/cve-2026-21884-remix-run-react-router-api-getkeystoragekey-cross-site-scripting-ghsa-8v8x-cx79-35w7-euvd-2026-1466/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634679/sicherheitsluecken/cve-2026-21884-remix-run-react-router-api-getkeystoragekey-cross-site-scripting-ghsa-8v8x-cx79-35w7-euvd-2026-1466/</guid>
<pubDate>Tue, 30 Jun 2026 08:05:54 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, has been found in <a href="https://vuldb.com/product/remix-run:react-router">remix-run react-router</a>. This affects an unknown function of the component <em>API</em>. Performing a manipulation of the argument <em>getKey/storageKey</em> results in cross site scripting.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-21884">CVE-2026-21884</a>. Remote exploitation of the attack is possible. No exploit is available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[DeepSeek open sources DSpark, a new framework to speed up LLM inference by up to 85%]]></title>
<description><![CDATA[Even as the geopolitical conversation around AI continues to grow more fraught following the U.S. government's actions to limit the new models from Anthropic and OpenAI, Chinese open source darling DeepSeek is back with yet another open release that could once again change AI development around t...]]></description>
<link>https://tsecurity.de/de/3634171/it-nachrichten/deepseek-open-sources-dspark-a-new-framework-to-speed-up-llm-inference-by-up-to-85/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634171/it-nachrichten/deepseek-open-sources-dspark-a-new-framework-to-speed-up-llm-inference-by-up-to-85/</guid>
<pubDate>Tue, 30 Jun 2026 00:17:42 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Even as the geopolitical conversation around AI continues to grow more fraught following the<a href="https://venturebeat.com/technology/anthropic-blocks-all-public-access-to-claude-fable-5-mythos-5-following-us-government-order-what-enterprises-should-do"> U.S. government's actions to limit the new models from Anthropic</a> and <a href="https://venturebeat.com/technology/openai-unveils-gpt-5-6-sol-terra-and-luna-models-but-only-accessible-to-limited-preview-partners-for-now-per-us-gov">OpenAI</a>, Chinese open source darling DeepSeek is back with yet another open release that could once again change AI development around the globe. </p><p>Over the weekend, the firm released <a href="https://huggingface.co/deepseek-ai/DeepSeek-V4-Pro-DSpark">DSpark</a>, a new, MIT-Licensed system designed to make large language models answer faster without changing what the underlying model is trying to say. </p><p>The easiest way to think about it is this: most AI chatbots write like someone crossing a river one stepping stone at a time. They choose one small chunk of text, then the next, then the next. </p><p>DSpark gives the system a scout that runs a few steps ahead, guesses the likely path, and lets the larger model quickly check which steps are safe. When the guesses are good, the model moves faster. When the guesses are weak, DSpark tries not to waste time checking them.</p><p>DeepSeek published the work with a <a href="https://github.com/deepseek-ai/DeepSpec/blob/main/DSpark_paper.pdf">technical paper</a>, model checkpoints and <a href="https://github.com/deepseek-ai/DeepSpec">DeepSpec</a>, a codebase for training and evaluating speculative decoding systems. The release is available through DeepSeek’s public <a href="https://github.com/deepseek-ai">GitHub</a> and <a href="https://huggingface.co/deepseek-ai/DeepSeek-V4-Pro-DSpark">Hugging Face </a>pages, both under the permissive, friendly, commonplace MIT license, making the new technique broadly usable by developers, researchers and commercial enterprise operations that want to study or adapt the approach.</p><p>The system is aimed at one of the most expensive problems in AI deployment: serving large models quickly enough for real users, while using hardware efficiently enough to make the economics work. That matters for consumer chatbots, coding assistants, agentic workflows and enterprise AI systems where users expect long answers to stream quickly rather than crawl out word by word.</p><p>DeepSeek is applying DSpark to its own latest frontier open model,<a href="https://venturebeat.com/technology/deepseek-v4-arrives-with-near-state-of-the-art-intelligence-at-1-6th-the-cost-of-opus-4-7-gpt-5-5"> DeepSeek-V4</a>. </p><p>Specifically, DeepSeek used its new DSpark framework on DeepSeek-V4-Flash, its already speed-optimized 284-billion-parameter mixture-of-experts model with 13 billion active parameters, and DeepSeek-V4-Pro, its more thoughtful and powerful 1.6-trillion-parameter model with 49 billion active parameters (Both support context windows up to one million tokens). </p><p>But the broader significance is that<i> DSpark is not conceptually limited to DeepSeek-V4.</i> DeepSeek’s own tests and released checkpoints cover other open model families, including Alibaba's open weights <i>Qwen</i> and Google's open weights <i>Gemma. </i></p><p>That means enterprise teams running open-weight models could, in principle, train or fine-tune DSpark-style draft modules for their own target models. It is not a switch that any API customer can flip from the outside, but it is a method that can travel to other models when the operator controls the weights and serving stack.</p><h2><b>Staggering speed increases for generating tokens during inference</b></h2><p>In DeepSeek’s live production tests, DSpark improved aggregate throughput by 51% for DeepSeek-V4-Flash at an 80-token-per-second-per-user service target, and by 52% for DeepSeek-V4-Pro at a 35-token-per-second-per-user target. At matched system capacity, DeepSeek reports per-user generation speedups of 60% to 85% for V4-Flash and 57% to 78% for V4-Pro over its prior MTP-1 production baseline.</p><p>The different speed claims measure different things. The 60% to 85% figure for V4-Flash, and the 57% to 78% figure for V4-Pro, describe how much faster individual users receive generated tokens when DeepSeek compares DSpark with MTP-1 at matched practical system capacity. </p><p>Those are the cleaner “generation speed” numbers. DeepSeek also reports much larger 661% and 406% increases, but these measure aggregate throughput under very strict speed targets: 120 tokens per second per user for V4-Flash and 50 tokens per second per user for V4-Pro. </p><p>At those targets, DeepSeek says its older MTP-1 baseline approaches an operational cliff, meaning it can keep only a small number of concurrent requests running while preserving that level of responsiveness. </p><p>DSpark avoids more of that collapse, so the percentage difference in total system output becomes much larger. Put simply: the 85% number is closer to “how much faster the ride feels for a user” under comparable conditions, while the 661% and 406% figures are closer to “how much more traffic the road can still carry” when the old system is already bottlenecking. </p><h2><b>Why speculative decoding matters</b></h2><p>LLMs usually generate text one token at a time. A token can be a word, part of a word, punctuation mark or other small piece of text. Every new token depends on the text already produced, so the model has to keep pausing, checking the full context and choosing the next piece.</p><p>That is accurate, but slow. It is like having a senior editor approve every word before a writer can move to the next one. The editor may be excellent, but the process creates a bottleneck.</p><p>Speculative decoding, developed in the early Transfomer era, tries to fix that bottleneck. Instead of asking the large model to produce every token one by one, the system uses a smaller or lighter draft component to suggest several likely next tokens. The large model then checks that batch of guesses in parallel. If the draft guessed correctly, the system moves ahead several tokens at once. If the draft made a bad guess, the system rejects the bad token and anything after it, adds a corrected token, and tries again.</p><p>The point is speed without changing the larger model’s intended output. In the standard speculative decoding setup, the draft model is not replacing the target model. It is acting more like an assistant who prepares a rough next sentence for the senior editor to approve or reject.</p><p>The idea did not appear out of nowhere with today’s large language models. A <a href="https://arxiv.org/abs/1811.03115">key precursor came in 2018</a>, when Mitchell Stern, Noam Shazeer and Jakob Uszkoreit proposed blockwise parallel decoding for deep autoregressive models. Their method predicted multiple future steps in parallel, then kept the longest prefix validated by the main model. That paper established much of the draft-and-check intuition behind later speculative decoding work.</p><p>The research line became more explicit in 2022. <a href="https://arxiv.org/abs/2203.16487">Heming Xia, Tao Ge and co-authors introduced SpecDec</a>, a draft-and-verify approach for sequence-to-sequence generation. Later that year, Yaniv Leviathan, Matan Kalman and Yossi Matias posted “<a href="https://arxiv.org/abs/2211.17192">Fast Inference from Transformers via Speculative Decoding</a>,” which helped define the modern version of the technique for transformer-based language models. DeepMind researchers followed in 2023 with a closely related method called <a href="https://arxiv.org/abs/2302.01318">speculative sampling.</a></p><p>Those 2022 and 2023 papers are the clearest ancestors of how speculative decoding is discussed in current LLM inference work: a faster draft process proposes tokens, and the larger target model verifies them in a way designed to preserve the target model’s output distribution. </p><p>Since then, the field has moved quickly through several variants, including separate draft models, multi-token prediction heads, tree-based verification, feature-level methods such as <a href="https://arxiv.org/abs/2401.15077">EAGLE</a>, self-speculation, Medusa-style extra heads and parallel/blockwise drafters such as DFlash.</p><p>The key metric is not how many tokens a draft model can guess. It is how many of those guesses the larger model actually accepts. Long speculative blocks help only if enough of the proposed tokens survive verification. Otherwise, the system spends compute checking guesses that it throws away.</p><p>That is the context for DSpark. Speculative decoding is already an established inference technique before DeepSeek’s release, with support in major serving stacks and multiple competing research approaches. But it is still not a solved problem. Speedups depend heavily on the draft model, the workload, the serving setup and the current traffic level. DSpark’s contribution is to improve both sides of the trade-off: it tries to draft more coherent token blocks and then verify only the parts of those blocks that are likely to pay off under real serving conditions.</p><h2><b>What DSpark changes</b></h2><p>DSpark tackles two related problems: bad guesses and wasted checking.</p><p>First, the system uses what DeepSeek calls semi-autoregressive generation. In plain English, that means DSpark tries to combine speed with a bit more awareness of sequence. </p><p>A fully parallel drafter can guess several tokens at once, which is fast, but its later guesses can become less coherent because each position is predicted too independently. A purely step-by-step drafter can keep better track of how one token leads to the next, but it loses much of the speed advantage.</p><p>DSpark tries to keep the best of both. It uses a parallel backbone for most of the drafting work, then adds a lightweight sequential head that lets the draft take nearby token relationships into account. In the paper’s example, a parallel drafter might confuse likely phrase endings such as “of course” and “no problem,” producing awkward combinations because it is guessing positions too separately. DSpark’s sequential component helps the system make the later tokens fit the earlier ones.</p><p>Second, DSpark adds confidence-scheduled verification. Rather than always asking the target model to check the same number of draft tokens, DSpark estimates which prefix of the draft is likely to survive. A hardware-aware scheduler then adjusts how much of each draft should be verified based on both model confidence and current serving load.</p><p>A simple analogy: when a restaurant is quiet, the head chef can inspect more of the prep cook’s work. When the kitchen is slammed, the chef spends attention only on the dishes most likely to be ready. DSpark applies a similar idea to AI serving. Under lighter traffic, the system can afford to check longer draft prefixes. Under heavier traffic, it trims low-confidence trailing guesses before they consume batch capacity that could be used for other users.</p><p>DeepSeek frames this as an answer to a common production trade-off. Static multi-token drafting can look attractive in isolation, but can hurt throughput under high concurrency because the system keeps checking tokens that are likely to be rejected. DSpark’s scheduler makes the verification budget flexible instead of fixed.</p><h2><b>Offline results: better draft acceptance across Qwen and Gemma</b></h2><p>DeepSeek tested DSpark offline on Qwen3-4B, Qwen3-8B, Qwen3-14B and Gemma4-12B target models across math, coding and chat benchmarks. </p><p>In those tests, the team compared DSpark with DFlash, a parallel drafter, and Eagle3, an autoregressive drafter. The paper reports accepted length per decoding round, a measure of how many tokens survive verification on average.</p><p>Across the three Qwen3 model sizes, DSpark improved macro-average accepted length over Eagle3 by 30.9%, 26.7% and 30.0%, respectively. Compared with DFlash, it improved accepted length by 16.3%, 18.4% and 18.3%. The paper also says the gains generalized to Gemma4-12B.</p><p>That supports a point raised by developer Daniel Han, who highlighted on X that DeepSeek showed DSpark working beyond DeepSeek’s own V4 models, including Gemma and Qwen. I would include Han as community reaction, not as the sole evidence for the claim. The stronger support comes from DeepSeek’s own benchmarks and released checkpoints.</p><p>The offline results also show why workload matters. Structured tasks such as math and code tend to have higher accepted lengths than open-ended chat. That makes intuitive sense: a code completion or math step often has fewer reasonable next moves than a free-form conversation. </p><p><b>For enterprises, </b>this means<b> DSpark-style methods may be especially attractive for coding assistants, data analysis agents, structured workflow automation</b> and other settings where outputs follow more predictable patterns.</p><h2><b>How enterprises could use DSpark without DeepSeek-V4</b></h2><p>One of the most important questions is whether DSpark is a DeepSeek-only optimization or a broader method that can be applied to other models. The answer is: broader method, but not automatic plug-in.</p><p>For open-weight models, the path is relatively clear. An enterprise running Qwen, Gemma, Llama, Mistral, Granite, Command-style open weights or another model it hosts itself could train or fine-tune a DSpark-style draft module against that target model. </p><p>The team would then measure acceptance on its own workloads and integrate the verification scheduler into its inference stack.</p><p>That is different from simply downloading DeepSeek’s DSpark module and attaching it to any model. Speculative decoding depends on alignment between the draft module and the target model. The draft has to learn what the target model is likely to accept. A drafter trained for DeepSeek-V4 will not automatically be the right drafter for a different model, especially one fine-tuned on a company’s internal data or configured for different reasoning behavior.</p><p>DeepSpec’s workflow reflects this. The process involves preparing data, regenerating target-model answers, building a target cache, training the draft model and evaluating speculative-decoding acceptance. For domain-specific use, the draft model may need additional fine-tuning, especially if the target model runs in a thinking or reasoning mode.</p><p>For proprietary models, the answer depends on what the enterprise controls. If a company owns or fully hosts the model weights and serving stack, it could theoretically train and deploy a DSpark-style drafter. If the model is available only through a hosted API from a vendor, the customer cannot directly add DSpark from the outside. The API provider could implement a similar optimization internally, but the customer generally cannot access the token verification loop, logits, batching behavior or serving scheduler needed to make DSpark work.</p><p>That distinction matters for enterprise buyers. DSpark strengthens the case for open or self-hosted AI infrastructure because it gives advanced teams another lever to improve speed and cost. But it also shows why model serving is becoming a specialized discipline. The value is not just in picking a model, but in how intelligently that model is run.</p><h2><b>What developers get from DeepSpec</b></h2><p>For developers, DeepSpec gives a concrete implementation path for training and evaluating speculative decoding draft models. It includes data preparation, training and benchmark evaluation steps, along with released checkpoints for several open model families. That makes the release useful not only for running DeepSeek-V4 with DSpark, but also for researchers and infrastructure teams studying how to add faster decoding to other open models.</p><p>There are real deployment caveats. DeepSpec’s own README says the default Qwen3-4B data preparation setup can require roughly 38 TB of target cache storage, and the default scripts assume a single node with eight GPUs. That makes the release more immediately relevant to AI labs, cloud teams and sophisticated enterprise AI infrastructure groups than to ordinary application developers.</p><p>Still, releasing the training pipeline matters. Many inference optimizations appear only as papers, vague benchmarks or closed production claims. DeepSpec gives developers something closer to a set of blueprints: not a finished enterprise product, but a way to reproduce, adapt and evaluate the method.</p><h2><b>Early community testing</b></h2><p>The release has already drawn fast developer attention. Developer <a href="https://github.com/rafaelcaricio/spark_vllm_docker/pull/1">Rafael Caricio published a GitHub pull request </a>documenting single-stream DeepSeek-V4-Flash DSpark work, reporting warmed benchmark anchors of 26.33 tokens per second without speculative decoding, 39.88 tokens per second with MTP-1, and roughly 60 tokens per second with DSpark — about 1.5x over MTP-1 and 2.3x over no-spec decoding.</p><p>A later commit in the same thread recorded a five-run mean of 60.31 tokens per second, with a 1.51x gain over MTP-1 and 2.29x over non-speculative decoding. </p><p>The same work also points to an important practical limit: in realistic multi-turn coding sessions, performance can degrade as draft acceptance falls with growing context. In other words, DSpark can make decoding faster, but acceptance quality still determines how much speed the system actually realizes.</p><p>That is a useful reality check. DSpark is not magic. It still depends on how predictable the next tokens are and how well the drafter stays aligned with the target model. But the early implementation work suggests DeepSeek’s claims are not purely academic. Developers are already testing the method in practical serving environments and reporting gains close to the paper’s single-stream expectations.</p><h2><b>The bottom line</b></h2><p>DSpark shows how much performance remains available in the inference layer, even when the underlying model architecture stays the same. As AI companies compete on model quality, context length and pricing, decoding efficiency is becoming another major battleground. </p><p>Faster generation means lower latency for users, higher throughput for providers and better economics for teams serving open models at scale.</p><p>DeepSeek’s release is notable because it combines a production-tested method, open code, public checkpoints and a detailed paper. The main innovation is not just drafting more tokens. It is making the system more selective about which speculative work is worth verifying.</p><p>For enterprise teams, the broader lesson is that the next wave of AI performance gains will not come only from larger models. It will also come from smarter ways to run the models companies already have — especially when those companies control enough of the stack to tune the model, train a compatible draft module and optimize the serving engine around real workloads.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Data regions support for the Gemini app now available]]></title>
<description><![CDATA[Beginning today, the Gemini app adheres to your organization’s data regionalization requirements. As with Google Workspace, admins have the flexibility to configure controls for EU storage and processing, US storage and processing, or both, including granular settings down to the organizational u...]]></description>
<link>https://tsecurity.de/de/3634111/web-tipps/data-regions-support-for-the-gemini-app-now-available/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634111/web-tipps/data-regions-support-for-the-gemini-app-now-available/</guid>
<pubDate>Mon, 29 Jun 2026 23:27:13 +0200</pubDate>
<category>Web Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Beginning today, the Gemini app adheres to your organization’s data regionalization requirements. As with Google Workspace, admins have the flexibility to configure controls for EU storage and processing, US storage and processing, or both, including granular settings down to the organizational unit (OU) level.<div><br></div><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhI7BAja-5-rKJfB7Mz-7PKh-_OFEKnTRl0Kxo41HEUbMV9ebrqT_poUZcPETp9EJY3ELoKB54s7PiOiVhqa-SbohW1szV9zz0F_hOXPmC8PE1E7UmbFpAHPglIN1oQeqtOR2LgXGYMifA6tWqPil2sRiFhryOXxh1YYVdE_K3k8_k1FCgak6SCSAxI7tI/s1095/Data%20regions%20support%20for%20the%20Gemini%20app%20now%20available%20-%206406.gif" imageanchor="1"><img border="0" data-original-height="627" data-original-width="1095" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhI7BAja-5-rKJfB7Mz-7PKh-_OFEKnTRl0Kxo41HEUbMV9ebrqT_poUZcPETp9EJY3ELoKB54s7PiOiVhqa-SbohW1szV9zz0F_hOXPmC8PE1E7UmbFpAHPglIN1oQeqtOR2LgXGYMifA6tWqPil2sRiFhryOXxh1YYVdE_K3k8_k1FCgak6SCSAxI7tI/s16000/Data%20regions%20support%20for%20the%20Gemini%20app%20now%20available%20-%206406.gif"></a></div><div><div><br></div><div>Data regions are critical for ensuring many customers can meet their own internal requirements, as well as other legal, regulatory, and data sovereignty requirements by controlling the geographical location of their data at rest. Expanding these controls to the Gemini app allows our customers to adopt Gemini broadly in their organization with confidence that their data is being processed and stored in the location they require. </div><h3>Getting started</h3><div><ul><li><b>Admins: </b>Visit the Help Center to learn more about <a href="https://support.google.com/a/answer/14316863" target="_blank">data regions</a>, <a href="https://support.google.com/a/answer/14310028" target="_blank">choosing a geographic location for your data</a>, <a href="https://support.google.com/a/answer/14310030" target="_blank">setting up advanced settings for data regions</a>, and <a href="https://support.google.com/a?p=data-covered-region-policy" target="_blank">what data is covered by data regions</a>.</li><li><b>End users: </b>There is no end user setting for this feature.</li></ul></div><h3>Rollout pace</h3><div><ul><li><a href="https://support.google.com/a/answer/172177" target="_blank">Rapid Release and Scheduled Release domains:</a> Available now</li></ul></div><h3>Availability</h3><div><ul><li><b>Enterprise:</b> Enterprise Plus (provides in-region processing and storage capabilities)</li><li><b>Education: </b>Education Plus and Education Standard (provides in-region storage capabilities only)</li><li><b>Other Editions:</b> Frontline Plus (provides in-region processing and storage capabilities)</li></ul></div><h3>Resources</h3><div><ul><li>Google Workspace Admin Help: <a href="https://support.google.com/a/answer/7630496?hl=en&amp;ref_topic=7631290&amp;sjid=15537236112090055856-NA" target="_blank">Data regions: Choose a geographic location for your data</a></li><li>Google Workspace Admin Help: <a href="https://support.google.com/a/answer/9223653" target="_blank">What data is covered by a data region policy?</a></li><li>Google Workspace Admin Help: <a href="https://support.google.com/a/answer/13880647" target="_blank">About Assured Controls and Assured Controls Plus</a></li></ul></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[eisengarn: One Binary, One Cloud, One VPN]]></title>
<description><![CDATA[When you create a “virtual private network” the “exit” of that network is a physical node with a legal jurisdiction. That jurisdiction determines who can compel disclosure of your traffic metadata, under what authority, and whether anyone is required to tell you it happened. Choosing the right ju...]]></description>
<link>https://tsecurity.de/de/3632826/it-security-nachrichten/eisengarn-one-binary-one-cloud-one-vpn/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632826/it-security-nachrichten/eisengarn-one-binary-one-cloud-one-vpn/</guid>
<pubDate>Mon, 29 Jun 2026 14:09:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[When you create a “virtual private network” the “exit” of that network is a physical node with a legal jurisdiction. That jurisdiction determines who can compel disclosure of your traffic metadata, under what authority, and whether anyone is required to tell you it happened. Choosing the right jurisdiction is the first security decision of any … <a href="https://www.flyingpenguin.com/eisengarn-one-binary-one-cloud-one-vpn/" class="more-link">Continue reading <span class="screen-reader-text">eisengarn: One Binary, One Cloud, One VPN</span> <span class="meta-nav">→</span></a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Grounding, not models, will define your AI advantage]]></title>
<description><![CDATA[Over the past two years, working inside the enterprise AI infrastructure world, tracking where the industry is heading, I have noticed the same question surface repeatedly: should we build our own large language model? I understand the instinct. The model feels like the thing, the engine, the bra...]]></description>
<link>https://tsecurity.de/de/3632693/it-nachrichten/grounding-not-models-will-define-your-ai-advantage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632693/it-nachrichten/grounding-not-models-will-define-your-ai-advantage/</guid>
<pubDate>Mon, 29 Jun 2026 13:03:15 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Over the past two years, working inside the enterprise AI infrastructure world, tracking where the industry is heading, I have noticed the same question surface repeatedly: should we build our own large language model? I understand the instinct. The model feels like the thing, the engine, the brain, the asset worth owning. But after significant years as a product manager in the AI world in both customer experience and grounding infrastructure I concluded that it tends to unsettle the room: the model is the least durable part of your AI strategy.</p>



<p>I say this not to be provocative, but because over the last few years we have seen organizations pour their scarcest resources, executive attention, engineering talent, capital, into the one layer of the stack that is commoditizing fastest. Meanwhile, the layer that determines whether their AI is trustworthy, accurate and defensible gets treated as plumbing. That inversion is, in my experience, the single most expensive mistake enterprises are making with AI right now.</p>



<h2 class="wp-block-heading">The model is becoming a commodity</h2>



<p>Let us consider economics. <a href="https://www.gartner.com/en/newsroom/press-releases/2026-03-25-gartner-predicts-that-by-2030-performing-inference-on-an-llm-with-1-trillion-parameters-will-cost-genai-providers-over-90-percent-less-than-in-2025" rel="nofollow">Gartner projects that by 2030, performing inference on a trillion-parameter model will cost providers more than 90% less</a> than it did in 2025, with models becoming up to 100 times more cost-efficient than the earliest versions of comparable size. When the cost of the underlying capability collapses by that magnitude, it stops being a differentiator. Anything that gets that cheap, that fast, is not where competitive advantage lives.</p>



<p>Models that feel innovative are routinely surpassed by something cheaper and better within months. If your advantage is tied to a specific model, it will evaporate the moment the frontier moves, which it always does. But if an enterprise instead invests in how reliably it can feed any model its proprietary context, that investment holds. That part travels from one model generation to the next. When a better model arrives, the organization can simply connect it and immediately capture the upside, because the hard and durable work was already done one layer down.</p>



<p>I wish more leaders could observe this pattern before they commit. The model layer is improving so quickly that any advantage you build into it has a short half-life. The grounding layer behaves in the opposite way: every improvement you make to your data quality, your retrieval logic and your governance compounds, and it carries forward regardless of which model sits on top.</p>



<p>This is why the build-your-own LLM debate so often misses the mark. Training or even meaningfully fine-tuning a foundation model is enormously expensive, and the moment you finish, the open and commercial frontier has usually moved past you. So, technically you spent a fortune to own a depreciating asset. The capability that you should focus on is an AI that knows your business, was never going to come from the weights of the model anyway. It comes from what you put in front of it.</p>



<h2 class="wp-block-heading">Why grounding is the real moat</h2>



<p>Grounding is the discipline of connecting a general-purpose model to your enterprises’ current and authoritative information, most commonly through retrieval-augmented generation, or RAG. Rather than hoping the model memorized something useful during training, you retrieve the relevant facts from your own systems in real time of the query and give the model the context it needs to answer correctly.</p>



<p>Here is the part that matters for anyone thinking about competitive advantage: your competitors can rent the exact same model you use. What they cannot rent is your data, your institutional knowledge, your processes and the quality of the pipeline that surfaces all of it accurately at the right moment. That pipeline is genuinely proprietary, genuinely hard to replicate and it compounds in value over time. That is the textbook definition of a moat, and it has almost nothing to do with which model you chose.</p>



<p>The industry is starting to recognize this. Gartner predicts that <a href="https://www.gartner.com/en/newsroom/press-releases/2025-04-09-gartner-predicts-by-2027-organizations-will-use-small-task-specific-ai-models-three-times-more-than-general-purpose-large-language-models" rel="nofollow">by 2027, organizations will use small, task-specific models at least three times more than general-purpose LLMs</a>, precisely because accuracy in real business workflows depends on domain context rather than raw model scale. But a smaller model holds less in its parameters by design, which means it leans even harder on retrieval to supply current, authoritative context in real time. The model gets smaller and more swappable. The grounding becomes the part that carries the weight. In that same analysis, Gartner makes the same point from the data side: what sets enterprises apart is how well they prepare, check, version and manage their own data. Read that again: the differentiator is the data discipline, not the model.</p>



<p>This matches what I have observed directly. Getting hold of an excellent model was never the hard part, and it was rarely where things broke. The failures I have seen came from not connecting the model efficiently to the right data sources or orchestrating retrieval well. The patterns repeat: missing data produces incomplete summaries, truncated documents leave answers without key details, and noisy context yields irrelevant or confusing responses.</p>



<p>When grounding is absent, answers become inconsistent from one client to the next; when retrieval comes back empty, the model fills the gap with something hallucinated or useless. Stale data produces confidently outdated answers, retrieval gaps surface as generic non-answers, and poor-quality data drags down both speed and output. None of these are model problems. They are grounding problems. And when a system hands an executive an answer that is wrong, no one in the boardroom cares how sophisticated the model was. They care that it was wrong, and the fix always lives in the grounding layer.</p>



<p>One example has stayed with me. In a real enterprise scenario, an AI assistant returned inconsistent answers to the same query across different environments whenever grounding was unavailable, and some of those answers contradicted each other outright. The cause was straightforward in hindsight. With no grounding, the system fell back on its own internal knowledge instead of a shared, grounded source of truth, so its responses drifted with each configuration and context. The damage was not just technical. Users stopped trusting an assistant that could not give them the same answer to the same question twice. That is the actual cost of weak grounding, and it is why consistency and reliability in production depend far more on the data layer than on the model sitting above it. No model upgrade would have fixed that.</p>



<h2 class="wp-block-heading">Where leaders should focus their investment</h2>



<p>If you accept that grounding is where advantage accrues, a few priorities shift in ways that should change how you allocate budget and attention.</p>



<p>First, treat your organization’s data foundation as a first-class AI investment, not a prerequisite you rush through. The unglamorous work, cleaning, structuring, governing and versioning your knowledge, is the work that determines AI quality. I would rather inherit a mediocre model with an excellent retrieval pipeline than the reverse, every single time.</p>



<p>Second, build for model portability from day one. Assume the model you use today will be replaced within a year because it certainly will. If swapping it out is painful, you have coupled your architecture to the wrong layer. Your grounding infrastructure, your evaluation framework and your data contracts should be the stable core; the model should be a component you can swap with minimal disruption.</p>



<p>Third, invest in observability and evaluation for retrieval, not just for the model. The emerging discipline here matters: <a href="https://www.gartner.com/en/newsroom/press-releases/2026-03-30-gartner-predicts-by-2028-explainable-ai-will-drive-llm-observability-investments-to-50-percent-for-secure-genai-deployment" rel="nofollow">Gartner expects LLM observability investments to reach 50% of GenAI deployments by 2028</a>, up from 15% today, as trust requirements outpace the technology itself. Knowing why your system retrieved a particular piece of context, and whether that context was correct, is what makes an AI output defensible and auditable. For any organization operating under real regulatory or reputational scrutiny, that is not optional.</p>



<p>None of this means the model is irrelevant. You still need a capable one and choosing well matters. But choosing a model is now a procurement decision with several excellent options, not a source of lasting differentiation. The lasting differentiation is everything you wrap around it.</p>



<p>I think the organizations that internalize this will look, in a few years, meaningfully ahead of the ones still debating whether to train their own model. Not because they made a bolder bet, but because they made a more durable one. They understood that in a world where everyone has access to the same extraordinary models, the advantage belongs to whoever grounds those models best in the reality of their own business. The model is rented. The grounding is owned. Build accordingly.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Absa’s giant steps to rebuild its integration foundation]]></title>
<description><![CDATA[With headquarters in Johannesburg, South Africa, Absa also operates in many other African countries, with international offices in Europe and the US. Running an organization across several markets has its unique complexities, especially in the integration layer, because each region has its own sy...]]></description>
<link>https://tsecurity.de/de/3632583/it-security-nachrichten/absas-giant-steps-to-rebuild-its-integration-foundation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632583/it-security-nachrichten/absas-giant-steps-to-rebuild-its-integration-foundation/</guid>
<pubDate>Mon, 29 Jun 2026 12:09:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>With headquarters in Johannesburg, South Africa, Absa also operates in many other African countries, with international offices in Europe and the US. Running an organization across several markets has its unique complexities, especially in the integration layer, because each region has its own systems, business processes, regulatory requirements and data standards.</p>



<p>For Absa, replacing an integration layer that had reached breaking point was a fundamental shift in its banking philosophy. It wasn’t just a technical project. Duplication was rampant, complexity was baked in, and reusability was non-existent. Every change had far-reaching ripple effects, and each new channel had to be built from scratch. As it stood, making the improvements the business demanded at the speed required to remain competitive was impossible.</p>



<p>According to Tamu Dutuma, Absa’s head of technology strategy for Africa Regions, this integration layer had been in place for close to a decade. While it played an important role in enabling business in the past, it was too difficult to maintain and no longer aligned to current standards and ways of working.</p>



<h2 class="wp-block-heading">Integration standardization</h2>



<p>Absa evaluated a range of available solutions in the market, but given the complexity of integrating with legacy systems across a multi-country financial environment, the team decided a more tailored approach was required.</p>



<p>“It was critical to establish the right architecture from the outset, which is why we worked with a strategic partner to build a solution that could better meet our specific integration needs, while also creating a stronger foundation for future scalability,” says Dutuma.</p>



<p>Balancing the long-term benefits of standardization against the immediate complexity of making the shift meant taking time to understand the upstream and downstream impact. The team had to be realistic about how they would standardize banking services, systems, and integrations while keeping disruption to a minimum.</p>



<p>As part of this process, Absa aligned with globally recognized standards, including BIAN, which provides a common framework for designing and integrating banking systems. The goal is to give banks a blueprint to successfully modernize complicated legacy architectures by defining standardized business capabilities, service domains, APIs, and data models.</p>



<p>The new integration layer provided three critical things for the business: decoupling and abstraction, standardization, and strategic orchestration. This meant separating customer-facing channels from core banking and backend services, using BIAN frameworks to enforce strict governance, and orchestrating only where necessary to keep the architecture lean.</p>



<h2 class="wp-block-heading">Choosing the right implementation strategy</h2>



<p>With this plan in mind, the bank needed to decide how to execute it. “We took a phased approach to the rollout, starting with a specific use case, our chatbot Chat Banking in our Africa Regions business,” says Dutuma. “This allowed us to build and test the new integration layer in a controlled, practical way. From there, we introduced an architecture principle that all new initiatives would integrate through this platform, while only time-critical projects continued to rely on the legacy environment.” The goal was to set a North Star project, which allowed them to quickly demonstrate value.</p>



<p>But this wasn’t a copy-paste exercise, and everything didn’t fit perfectly from the start. The bank admits that managing legacy outliers remains one of the biggest challenges on this modernization journey. Data mapping was another challenge. To ensure data moved correctly and quickly from one system to another, Absa had to build a data mapping framework to automate parts of the process.</p>



<p>As the project progressed and the team ironed out these kinks, they gradually migrated existing services to the new layer. “This wasn’t a like-for-like replacement,” he says. “We were also simplifying and standardizing the architecture, which required careful mapping, redesign, and end-to-end testing across both channels and core systems.”</p>



<h2 class="wp-block-heading">Banking on the future</h2>



<p>For Dutuma, this multi-year journey has allowed Absa to incrementally modernize the environment while continuing to support ongoing business delivery. And the project has delivered several strategic wins, from a drastic reduction in time-to-market to an equally dramatic reduction in costs. Standardization also opened additional opportunities for innovation across the business. For example, using a standardized API catalog enables plug-and-play integration capabilities, which means developers aren’t reinventing the wheel for every project. Where there used to be 20 disparate payment services, for instance, because everything is standardized, there are now four, which markedly reduces maintenance costs.</p>



<p> “This also provides a stronger foundation for Absa Group’s open banking initiatives, enabling selected services to be securely exposed for integration with FinTech partners and other ecosystem players,” he says. Plus, integrating new channels has become more straightforward, as teams can now leverage consistent, reusable integration patterns. This makes it easier to scale digital capabilities and accelerate delivering new customer-facing solutions.</p>



<p>This project, according to Dutuma, wasn’t just about fixing the old tech, but enabling cloud readiness and creating a leaner, modular application stack that can be used across other markets. Now, Absa doesn’t need to build a unique integration for a wallet in Botswana or for internet banking in Tanzania. There’s a common middleware layer across all regions, allowing countries to independently replace or upgrade core applications without affecting the broader regional footprint. In this way, Absa has essentially dissociated geography from technology to reduce complexity, improve interoperability, and ensure that different systems all speak the same language.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Die größten Paradoxa der Softwareentwicklung]]></title>
<description><![CDATA[Paradoxe Erlebnisse sind für Softwareentwickler Alltag.Rosemarie Mosteller | shutterstock.com



Vergleicht man den Bau von Brücken mit der Softwareentwicklung, zeigen sich bedeutende Unterschiede: Denn auch wenn keine Brücke – ähnlich wie ein Softwareprojekt – der anderen bis aufs „Haar“ gleicht...]]></description>
<link>https://tsecurity.de/de/3631887/it-security-nachrichten/die-groessten-paradoxa-der-softwareentwicklung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631887/it-security-nachrichten/die-groessten-paradoxa-der-softwareentwicklung/</guid>
<pubDate>Mon, 29 Jun 2026 06:07:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2025/04/Rosemarie-Mosteller_shutterstock_1976381543_16z9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Signs of Paradoxons 16z9" class="wp-image-3963773" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Paradoxe Erlebnisse sind für Softwareentwickler Alltag.</figcaption></figure><p class="imageCredit">Rosemarie Mosteller | shutterstock.com</p></div>



<p>Vergleicht man den Bau von Brücken mit der Softwareentwicklung, zeigen sich bedeutende Unterschiede: Denn auch wenn keine Brücke – ähnlich wie ein Softwareprojekt – der anderen bis aufs „Haar“ gleicht, werden sie aus bekannten Materialien mit bekannten Eigenschaften geschaffen.  </p>



<p>Im Gegensatz dazu beinhaltet der Softwareentwicklungsprozess wesentlich mehr „<a href="https://www.computerwoche.de/article/3610320/darum-ist-software-verbuggt.html">unknown Unknowns</a>“. Was dazu führt, dass er jede Menge Paradoxa beinhaltet, mit denen Developer teilweise nur schwer umgehen können. Wichtig ist aber vor allem, sich ihre Existenz bewusst zu machen – nur so lassen sich die daraus entstehenden Fallstricke umgehen. Insbesondere, wenn es dabei um die folgenden vier Paradoxa geht.</p>



<h2 class="wp-block-heading">1. Ohne Plan, aber mit Deadline</h2>



<p>Zielführend einzuschätzen, wie lange ein Softwareprojekt dauern wird, ist wahrscheinlich die größte Herausforderung für Softwareentwickler überhaupt. Denn darüber lässt sich keine abschließende, verbindliche Aussage treffen. Sicher, man kann <a href="https://www.computerwoche.de/article/2833936/darum-versagt-ihre-aufwandsschaetzung.html">den ungefähren Aufwand schätzen</a> – das geht im Regelfall allerdings daneben. Meistens wird der zeitliche Aufwand drastisch unterschätzt.</p>



<p>Wird die gesetzte Deadline dann verpasst, ärgern sich vor allem die Kunden. Sie stecken nicht in der Haut der Devs und durchblicken die Abläufe und möglichen Hindernisse (im Regelfall) nicht. Also sind sie frustriert, weil ihre Software nicht zum vereinbarten Zeitpunkt ausgeliefert wird.  </p>



<p>Auch sämtliche Versuche, mit schicken, agilen Methoden wie Story Points oder Planing Poker zielführender vorhersagen zu wollen, wann ein Softwareprojekt abgeschlossen wird, bringen <s>nichts</s> wenig. Wir scheinen einfach nicht in der Lage, <a href="https://en.wikipedia.org/wiki/Hofstadter%27s_law">Hofstadters Gesetz</a> (der Verzögerung) zu überwinden.</p>



<h2 class="wp-block-heading">2. Mehr Mannstärke, mehr Verzug</h2>



<p>Stellt ein Manager einer Fabrik fest, dass die monatliche Quote für abgefüllte Zahnpastatuben in Gefahr ist, setzt er mehr Arbeiter ein, um die Vorgabe zu erfüllen. Ähnlich verhält es sich beim Hausbau: Wenn Sie doppelt so viele Häuser wie im Vorjahr bauen wollen, hilft es in der Regel, die Vorleistungen – Arbeit und Material – zu verdoppeln.</p>



<p>Im Fall der Softwareentwicklung verhält sich das völlig anders, wie Frederick Brooks bereits 1975 in seinem Buch „Vom Mythos des Mann-Monats“ herausgearbeitet hat. Demnach hilft es wenig, verzögerte Softwareprojekte mit zusätzlicher Mannstärke retten zu wollen. Im Gegenteil: Gemäß dem <a href="https://de.wikipedia.org/wiki/Frederick_P._Brooks">Brooks’schen Gesetz</a> verzögert das das Projekt nur noch zusätzlich. Schließlich können neu hinzukommende Teammitglieder nicht sofort zum Projekt beitragen. Sie benötigen Zeit, um sich in den Kontext komplexer Systeme einzuarbeiten, was oft auch zusätzliche Kommunikationsmaßnahmen nach sich zieht. Am Ende verzögert sich dann nicht nur alles noch weiter – es kostet auch mehr.</p>



<h2 class="wp-block-heading">3. Mehr Skills, weniger Programmier-Tasks</h2>



<p>Als Softwareentwickler umfassende Expertise aufzubauen und sämtliche erforderlichen Regeln und Feinheiten zu verinnerlichen, um <a href="https://www.computerwoche.de/article/2824308/so-entwickeln-sie-besser.html">wartbaren, sauberen Code</a> zu schreiben, nimmt etliche Jahre in Anspruch. Dabei erscheint es auch relativ paradox, dass die Programmieraufgaben mit steigender Erfahrung eher weniger werden: Statt zu programmieren, sitzen leitende Entwickler vor allem in Design-Meetings, überprüfen den Code anderer und übernehmen weitere Führungsaufgaben.  </p>



<p>Das heißt zwar nicht, dass <a href="https://www.computerwoche.de/article/2834999/3-dinge-die-senior-developer-auszeichnen.html">Senior Developer</a> einen kleineren Beitrag leisten. Schließlich sorgen sie in Führungspositionen dafür, dass zeitgemäß und zielführend gearbeitet wird und tragen so wesentlich zum Team- und Unternehmenserfolg bei. Aber am Ende schreiben sie dennoch weniger Code.</p>



<h2 class="wp-block-heading">4. Bessere Tools, keine Zeitvorteile</h2>



<p>Vergleicht man die Webentwicklung von heute mit performanten Tools wie <a href="https://www.computerwoche.de/article/2833386/die-besten-javascript-frameworks-im-vergleich.html">React</a>, <a href="https://www.computerwoche.de/article/3834789/astro-tutorial-plug-play-webentwicklung.html">Astro</a> und Next.js mit dem Gebaren von vor 30 Jahren (Stichwort <a href="https://en.wikipedia.org/wiki/Common_Gateway_Interface">Common Gateway Interface</a>), wird klar, dass wir uns seitdem um Lichtjahre weiterentwickelt haben. Doch obwohl unsere Tools immer besser und die Prozessoren immer schneller werden, scheinen sich Softwareprojekte insgesamt nicht zu beschleunigen. Das wirft Fragen auf:</p>



<ul class="wp-block-list">
<li>Unsere Websites sehen zwar immer besser aus, aber sind wir wirklich produktiver?</li>



<li>Laufen unsere Websites schneller und verarbeiten sie Daten besser?</li>
</ul>



<p>Natürlich abstrahieren die Frameworks und Bibliotheken von heute viele Komplexitäten. Sie führen aber auch zu neuen Problemen. Zum Beispiel langen Build-Pipelines, Konfigurationsalbträumen oder Abhängigkeitsproblemen. (fm)</p>



<p><strong>Sie wollen weitere interessante Beiträge zu diversen Themen aus der IT-Welt lesen? </strong><a href="https://www.computerwoche.de/newsletter-anmeldung/"><strong>Unsere kostenlosen Newsletter</strong></a><strong> liefern Ihnen alles, was IT-Profis wissen sollten – direkt in Ihre Inbox!</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Claude Code turned every engineer into three. Now companies need more product thinkers]]></title>
<description><![CDATA[Anthropic recently told its growth team to hire more product managers, not fewer. The reason, as reported in industry coverage, was that Claude Code had quietly turned its engineering org into a team that ships at roughly three times its actual headcount, and the bottleneck moved from the integra...]]></description>
<link>https://tsecurity.de/de/3630129/it-nachrichten/claude-code-turned-every-engineer-into-three-now-companies-need-more-product-thinkers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3630129/it-nachrichten/claude-code-turned-every-engineer-into-three-now-companies-need-more-product-thinkers/</guid>
<pubDate>Sat, 27 Jun 2026 21:47:31 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Anthropic recently told its growth team to hire more product managers, not fewer. The reason, as reported in industry coverage, was that Claude Code had quietly turned its engineering org into a team that ships at roughly three times its actual headcount, and the bottleneck moved from the integrated development environment (IDE) to the people deciding what to build.</p><p>That detail is easy to miss in the noise of every <a href="https://venturebeat.com/orchestration/vibe-coding-can-build-your-pipeline-it-cant-explain-it-six-months-later">AI productivity claim</a>. It is also the structural shift the rest of the industry is now living through. The bottleneck in software is no longer typing. It is deciding what to type. And the engineers who treat that as someone else's problem are about to plateau. </p><p>For most of the last decade, that decision sat with someone else. <a href="https://venturebeat.com/technology/agentic-ai-solved-coding-and-exposed-every-other-problem-in-software-engineering">Software engineering</a> was a craft you absorbed slowly, then practiced in a long, predictable sequence: Dive deep on the technology, write the code, ask Stack Overflow when stuck, escalate to a senior engineer when Stack Overflow failed, ship the ticket. The product manager owned the funnel. The engineer owned the build. Both sides treated this division as physics.</p><p>Then the funnel collapsed in five steps.</p><h2><b>A short history of how the engineer's day got compressed</b></h2><p><b>The Stack Overflow era (2014 to late 2022): </b>The way engineers thought lived in one place. But new monthly questions on Stack Overflow are now down <a href="https://www.reddit.com/r/programming/comments/1hwg2px/stackoverflow_has_lost_77_of_new_questions/">roughly 77%</a> since November 2022, which was not coincidentally when ChatGPT launched. The drop is not a referendum on the site. It is a referendum on the workflow it represented.</p><p><b>The browser-tab era (late 2022 to 2024):</b> The first ChatGPT generation sat outside the IDE. Engineers ran the same loop they had always run, just with a faster oracle: Write a prompt in a browser, paste the answer back into VS Code, repeat. The work was still single-threaded and engineer-driven. The leverage was real but local.</p><p><b>The IDE-native era (2024 to 2025):</b> Cursor and Claude Code moved the model inside the editor and gave it access to the full repository. The senior-engineer escalation path largely dissolved. For years, the prevailing wisdom among veteran engineers was that Bash had the longest shelf life of any tool in the stack. By 2026, for a meaningful share of working developers, the first command typed in a fresh terminal is claude.</p><p><b>The spec-driven era (2025 to 2026):</b> Larger context windows turned single-session work into something that previously required tickets, design docs, and sprints. Amazon's Kiro IDE team reportedly compressed feature builds from two weeks to two days using the same spec-driven workflow they were shipping. An AWS engineering team described an 18-month rearchitecture, originally scoped for 30 engineers, was completed by 6 people in 76 days. The bottleneck stopped being how long it takes to write the code. It started being how clearly the team can describe what correct looks like.</p><p><b>The routines era (2026):</b> In April, Anthropic shipped Claude Code Routines: Scheduled, persistent agents that run on a cadence, on a webhook, or overnight while the laptop is closed. Cron came back. Hooks came back. The engineer's job is now part orchestration: Spin up a swarm before bed, review a stack of pull requests in the morning. Third-party wrappers like OpenClaw, which was briefly suspended by Anthropic in April before partial reinstatement, made the same point from the open-source side.</p><h2><b>The bottleneck moved; most teams have not</b></h2><p>Engineering has roughly tripled. Product management has not budged. The traditional 1:8 ratio of PMs to engineers, already strained, now plays out closer to an effective 1:20 because each engineer ships more per day. For instance, LinkedIn replaced its associate product manager track with a "Product Builder" program that trains generalists across product, design, and engineering. Anthropic is hiring more PMs, not fewer. The pattern is consistent across companies that have actually deployed agentic workflows in production: The system is producing built features faster than it is producing decisions about what should be built.</p><p>For engineers, this is the most important career signal of the decade, and the easiest one to miss while the productivity stories dominate the feed.</p><h2><b>First principles matter more, not less</b></h2><p>The instinct to declare fundamentals obsolete in the agent era gets the trend exactly wrong.</p><p>When a memory leak takes down production at 3 a.m., and the cause turns out to be a subtle ownership bug pushed 4 years ago, no agent currently in the wild closes that loop end-to-end. Operating systems, networks, concurrency, and query plans still decide who can resolve a real incident. They also decide who can spot the moments when an <a href="https://venturebeat.com/technology/why-prompt-debt-retrieval-debt-and-evaluation-debt-are-quietly-reshaping-enterprise-ai-risk">agent's output</a> looks correct on the surface and is quietly, expensively, wrong underneath. The agent that wrote 70% of the code in a modern repo cannot reliably tell anyone where its assumptions about thread safety, memory ownership, or transaction isolation diverged from the runtime. The engineer who can read the diff and catch that is the engineer the rest of the team needs in the room, and that engineer is built on fundamentals, not on prompting skill.</p><p>The corollary is that fundamentals are now a leverage skill, not a hygiene skill. In 2014, knowing how a TCP retransmit worked got a debug ticket closed faster. In 2026, the same knowledge keeps an entire agent-driven release pipeline from shipping a regression at scale. The blast radius of the engineer who knows what is happening underneath has gone up, not down.</p><h2><b>Review is the new writing</b></h2><p>Engineers in 2026 generate code at a rate that exceeds what any of them can read carefully. The team that ships fast and survives is the team whose engineers treat reviewing AI-generated code with at least the same rigor they once reserved for writing it. The 2025 <a href="https://survey.stackoverflow.co/2025">Stack Overflow developer survey</a> put 84% of developers on AI tools, with 46% saying they do not trust the output, up sharply from 31% the year before. That gap, heavy use paired with low trust, is exactly where review skills now matter most. Coders who push lots and review little are accumulating a debt that will come due during the first real incident, and the engineer who can pay it back is the one who paired their volume with deep first-principles knowledge of the systems involved.</p><h2><b>The new differentiator is the product funnel</b></h2><p>Both of those are necessary. Neither is sufficient. The engineer who matters in 2026 is the one who has stopped waiting for the funnel to arrive in the form of a Jira ticket.</p><p>That means doing things the role was historically allowed to skip.</p><p>Talk to customers. Watch how they actually use the product. Read the support queue. Sit in on the sales call. The signal a product team gets through three layers of summary, an engineer can now get firsthand in an afternoon.</p><p>Generate ideas, not just estimates. The product manager who used to source ideas for 8 engineers cannot source ideas for 20 at the same fidelity. The engineer who shows up with a validated, scoped opportunity is no longer doing the PM's job. The engineer is doing the job the new ratio requires.</p><p>Work backwards from the customer. Amazon has been writing the press release first for two decades. The discipline travels well to teams of one and to swarms of agents. Both produce a great deal of working software in the wrong direction without a clear statement of what "customer wins" means before any code is written.</p><p>Stop hiding behind bandwidth. The honest answer to "Do you have capacity for this idea?" used to be 'No.' With routines, hooks, and a cooperative agent stack, the honest answer is closer to "What is the idea worth?" That is a different conversation, and a much harder one to have without a real point of view on the customer.</p><h2><b>What the next decade rewards</b></h2><p>The five-phase history above is not really a history of tools. It is a history of which part of the job a human had to do. The part that is still human, and that will remain human for the foreseeable future, has moved up the funnel: From typing, to reviewing, to deciding, to choosing the customer to serve and the problem to solve.</p><p>The 2026 version of a <a href="https://venturebeat.com/technology/the-enterprise-risk-nobody-is-modeling-ai-is-replacing-the-very-experts-it-needs-to-learn-from">great engineer</a> is not the one who writes the most code. It is the one who knows what to build, can prove it is worth building, and has the agent fleet plus the review discipline to ship it without the system collapsing under its own velocity.</p><p>Engineers who internalize this will spend the next decade doing the most interesting work software has ever produced. Engineers who wait for a ticket will spend it watching the ticket get written by the agent next to them.</p><p><i>Ishan Gupta is a software engineer at Amazon.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-50146 | withastro up to 6.3.2 data-astro-template cross site scripting]]></title>
<description><![CDATA[A vulnerability was found in withastro astro up to 6.3.2. It has been rated as problematic. The affected element is an unknown function. The manipulation of the argument data-astro-template leads to basic cross site scripting.

This vulnerability is referenced as CVE-2026-50146. Remote exploitati...]]></description>
<link>https://tsecurity.de/de/3629802/sicherheitsluecken/cve-2026-50146-withastro-up-to-632-data-astro-template-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3629802/sicherheitsluecken/cve-2026-50146-withastro-up-to-632-data-astro-template-cross-site-scripting/</guid>
<pubDate>Sat, 27 Jun 2026 17:39:04 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/withastro:astro">withastro astro up to 6.3.2</a>. It has been rated as <a href="https://vuldb.com/kb/risk">problematic</a>. The affected element is an unknown function. The manipulation of the argument <em>data-astro-template</em> leads to basic cross site scripting.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2026-50146">CVE-2026-50146</a>. Remote exploitation of the attack is possible. No exploit is available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-61686 | remix-run react-router createFileSessionStorage path traversal (GHSA-9583-h5hc-x8cw / EUVD-2026-1468)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in remix-run react-router. This vulnerability affects the function createFileSessionStorage. The manipulation leads to path traversal.

This vulnerability is traded as CVE-2025-61686. It is possible to initiate the attack remotely. There is no...]]></description>
<link>https://tsecurity.de/de/3629055/sicherheitsluecken/cve-2025-61686-remix-run-react-router-createfilesessionstorage-path-traversal-ghsa-9583-h5hc-x8cw-euvd-2026-1468/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3629055/sicherheitsluecken/cve-2025-61686-remix-run-react-router-createfilesessionstorage-path-traversal-ghsa-9583-h5hc-x8cw-euvd-2026-1468/</guid>
<pubDate>Sat, 27 Jun 2026 07:54:18 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/remix-run:react-router">remix-run react-router</a>. This vulnerability affects the function <code>createFileSessionStorage</code>. The manipulation leads to path traversal.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2025-61686">CVE-2025-61686</a>. It is possible to initiate the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Shaping a lasting AI strategy in a fast-changing world]]></title>
<description><![CDATA[AI is entering a phase of sustained enterprise adoption. As the technology rapidly advances, organizations are moving beyond isolated use cases and short-term efficiency gains and rethinking how they use AI to create value, meet changing customer expectations and evolve their operating models ove...]]></description>
<link>https://tsecurity.de/de/3626996/it-security-nachrichten/shaping-a-lasting-ai-strategy-in-a-fast-changing-world/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626996/it-security-nachrichten/shaping-a-lasting-ai-strategy-in-a-fast-changing-world/</guid>
<pubDate>Fri, 26 Jun 2026 12:09:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AI is entering a phase of sustained enterprise adoption. As the technology rapidly advances, organizations are moving beyond isolated use cases and short-term efficiency gains and rethinking how they use AI to create value, meet changing customer expectations and evolve their operating models over the next several years.</p>



<p>That requires a clear end goal, an honest assessment of current capabilities and a practical roadmap for moving from today’s reality to that end goal.</p>



<p>Today, we are seeing five accelerating trends shaping how that transition is unfolding.</p>



<h2 class="wp-block-heading">LLMs are evolving into AgenticOS platforms</h2>



<p>Horizontal LLM providers like Anthropic and vertical AI companies like Harvey are moving beyond standalone AI models and building broader enterprise platforms. These platforms combine AI models with workflows, playbooks, integrations and governance tools inside a single environment, which are beginning to be described as an “AgenticOS.” As a result, the market is beginning to consolidate around a smaller number of platform providers that can simplify procurement, integration, spend management and data privacy compliance.</p>



<h2 class="wp-block-heading">Context windows have expanded by orders of magnitude</h2>



<p>Leading AI models can now process dramatically more information at once than they could just a few years ago, with the amount of information they can analyze in a single interaction expanding roughly 125× since 2023. That shift is making more complex, enterprise-scale work, like large-scale contract review, codebase-wide analysis and multi-document research synthesis, possible. Such capabilities, which once felt cutting-edge, are becoming standard expectations.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/flagship-llm-context-window-evolution.png" alt="Figure 1: Flagship LLM context window evolution, OpenAI and Anthropic, March 2023 – May 2026." class="wp-image-4189596" width="986" height="654" sizes="auto, (max-width: 986px) 100vw, 986px"><figcaption class="wp-element-caption"><em>Figure 1: Flagship LLM context window evolution, OpenAI and Anthropic, March 2023 – May 2026.</em></figcaption></figure><p class="imageCredit">John Wei</p></div>



<h2 class="wp-block-heading">Token pricing has stabilized at the production tier</h2>



<p>After dropping rapidly between 2023 and 2025, the cost of using mainstream AI models has started to stabilize. Today, many enterprise-grade models fall within a <a href="https://intuitionlabs.ai/articles/llm-api-pricing-comparison-2025" rel="nofollow">relatively predictable range</a> of roughly $2–$3 per million input tokens and about $15 per million output tokens, making costs easier to anticipate and manage.</p>



<p>At the same time, cost-saving features like prompt caching (which can reduce costs by up to 90%) and batch APIs (which can cut costs by roughly 50%) are making AI significantly cheaper to operate at scale. Together, those shifts are making AI spending easier for enterprises to budget, forecast and manage like other core technology investments.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/flagship-llm-token-cost-evolution.png?w=1024" alt="Figure 2: Flagship LLM token cost evolution, OpenAI and Anthropic, March 2023 – May 2026." class="wp-image-4189595" width="1024" height="650" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><em>Figure 2: Flagship LLM token cost evolution, OpenAI and Anthropic, March 2023 – May 2026.</em></figcaption></figure><p class="imageCredit">John Wei</p></div>



<h2 class="wp-block-heading">AI is functioning as a productivity assistant, not a human replacement.</h2>



<p>I had the chance to speak with senior leaders at this year’s WSJ Future of Everything conference, and one theme consistently emerged: despite the hype around AI agents, many companies are still using AI to support human decision-making rather than replace it.</p>



<p>Data shared by the senior leadership team of a prominent AI company at the WSJ conference shows that AI agents consume less than 5% of tokens today, and 84% of enterprise use cases are growth-focused rather than productivity-focused. That is largely because AI workflows still depend heavily on the quality and consistency of inputs. In complex enterprise environments with variable scenarios and edge cases, human judgment, prompt refinement and iterative review remain essential.</p>



<p>As a result, workflows can rarely be fully automated, and many automation gains translate into incremental productivity improvements rather than meaningful headcount reduction without broader operating model changes.</p>



<p>Instead, many organizations are using AI to drive growth, support new business models and enable new ways of operating.</p>



<h2 class="wp-block-heading">Software development is the leading edge of human-AI collaboration.</h2>



<p>In our experience at Integreon, vibe coding has produced a few notable success stories. At enterprise scale, though, it can introduce architectural limitations and sometimes even hardcoding or semi-hardcoded shortcuts that undermine the long-term sustainability of the code. As a result, we primarily use AI coding tools as developer assistants for targeted tasks rather than end-to-end software development. That approach reflects a broader industry trend: <a href="https://www.techtimes.com/articles/315282/20260321/tech-layoffs-surge-while-ai-jobs-soar-key-trends-shaping-2026-tech-industry.htm" rel="nofollow">despite high-profile tech layoffs, overall demand for developers has remained steady, and demand for developers with AI skills is rising.</a></p>



<p>Across all five trends, the focus has shifted from automating legacy workflows to assisting human workflows. This is a fundamental change in how work will be organized across the enterprise.</p>



<p>As AI technologies mature and become widely accessible across industries, competitive advantage will increasingly come from strategy rather than the technology itself. Many businesses will have access to the same AI platforms, models and tools. What will differentiate organizations is how they apply those technologies to shape customer experience, operating models and market positioning.</p>



<p>The airline industry offers a useful parallel. Most airlines operate similar aircraft under the same regulatory and labor constraints, yet they differ dramatically in market positioning, customer experience and operational performance. What separates airlines is not the plane itself, but how the business is built around it.</p>



<p>For CIOs and CTOs, choosing an AI platform is no longer the main challenge. The more important conversations now center on where the business is headed and how AI supports that strategy. Leaders must ask themselves questions like:</p>



<ul class="wp-block-list">
<li><strong>Who do we want to become?</strong> Most enterprises have mission statements, but far fewer know exactly where they want the business to go over the next three to five years as AI reshapes customer expectations, competition and economics. That answer needs to be concrete enough to guide real decisions.</li>
</ul>



<ul class="wp-block-list">
<li><strong>Wh</strong><strong>at are we choosing not to do</strong><strong>?</strong> Strategic restraint matters just as much as strategic ambition. AI lowers many costs, making it tempting for organizations to spread themselves across too many initiatives. But without clear boundaries, organizations risk stretching resources too thin.</li>
</ul>



<ul class="wp-block-list">
<li><strong>Where </strong><strong>are we</strong><strong> today?</strong> That means taking a real look at which parts of the business AI may shrink or disrupt over the next three to five years. Many companies struggle to assess this honestly because those areas still generate revenue today. Sometimes it takes an outside perspective to spot risks internal teams are too close to see.</li>
</ul>



<ul class="wp-block-list">
<li><strong>What capabilities do we need to succeed three to five years from now</strong><strong>?</strong> Companies often plan by projecting today’s business forward instead of starting with where they want to end up. Usually, the answer comes down to a few key differentiators, like proprietary data, customer trust or distribution, along with a broader set of capabilities that simply need to be strong and reliable.</li>
</ul>



<ul class="wp-block-list">
<li><strong>How will we organize</strong><strong> work</strong><strong>? </strong>Enterprises must rethink how work gets done. Most operating models today were built around human labor. Going forward, many workflows will likely be shared between AI systems and human oversight.</li>
</ul>



<ul class="wp-block-list">
<li><strong>What kind of talent do we need?</strong> This can be especially difficult for companies with long histories and established teams. Employees who drove success in the past may not align perfectly with where the business is headed next. Companies will need to think carefully about how experienced employees can help build and support future capabilities.</li>
</ul>



<ul class="wp-block-list">
<li><strong>Where can we </strong><strong>simplify</strong><strong> workflows?</strong> In many cases, workflows can be reduced to three core steps. First is building context, including defining the goals, data, constraints and decision-making framework. Then comes AI execution, where AI is applied to workflows and tasks. Finally, humans review outputs and make judgment calls.</li>
</ul>



<ul class="wp-block-list">
<li><strong>Which AI platforms do we actually need?</strong> Most enterprises do not have the capacity to effectively manage dozens of AI vendors and tools at once. Every additional platform adds more integration work, governance, vendor oversight and security review requirements. In most cases, organizations are better off making a small number of focused platform bets than constantly chasing the latest AI tool.</li>
</ul>



<h2 class="wp-block-heading">Finally, a few thoughts on what to avoid</h2>



<p>The best mentors I’ve had taught me to think in three-to-five-year terms. A good strategy should remain relatively stable over that period. Without that consistency, organizations end up resetting direction too often and losing credibility in the process.</p>



<p>Today, I see two common mistakes. The first is staying too anchored to the past, defaulting to reasons something cannot happen because of security, compliance or organizational resistance. The second is the opposite: chasing every new technology simply because it is new. Most enterprises will need to find a middle ground over the next several years.</p>



<p>AI is the aircraft. Strategy is the route.</p>



<p>The companies that pull ahead will not necessarily be the ones spending the most on AI or launching the most pilots. They will be the ones whose leaders answered the hard questions, stayed committed to a direction and learned from mistakes along the way.</p>



<p>Technology will continue to change. Strategy is what will determine who uses it well.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why private AI is the smarter bet]]></title>
<description><![CDATA[For the past several years, the default assumption in enterprise IT was that AI would follow the same path as many other workloads and settle into the public cloud. That assumption seemed reasonable on the surface. The hyperscalers had the infrastructure, GPU capacity, managed services, and devel...]]></description>
<link>https://tsecurity.de/de/3626875/ai-nachrichten/why-private-ai-is-the-smarter-bet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626875/ai-nachrichten/why-private-ai-is-the-smarter-bet/</guid>
<pubDate>Fri, 26 Jun 2026 11:18:38 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>For the past several years, the default assumption in enterprise IT was that AI would follow the same path as many other workloads and settle into the public cloud. That assumption seemed reasonable on the surface. The hyperscalers had the infrastructure, <a href="https://www.networkworld.com/article/3966130/what-are-gpus-inside-the-processing-power-behind-ai.html">GPU capacity</a>, managed services, and developer ecosystems. If you wanted to move fast, public cloud AI looked like the obvious answer.</p>



<p>That logic is now being challenged by reality. <a href="https://news.broadcom.com/releases/broadcom-private-cloud-outlook-2026">As enterprises move from AI experiments to AI in production</a>, they increasingly find that the public cloud is a convenient place to start but not the most practical place to stay. Enterprises are wondering if they can afford to base their long-term AI strategies on cost models they do not control, risks they cannot fully contain, and architectures that are optimized for provider scale rather than enterprise economics.</p>



<p>This is why private cloud AI is becoming more popular. Enterprises are not moving on-premises because it’s a fashionable choice. They are moving because, in many cases, it is the financially rational choice.</p>



<h2 class="wp-block-heading">The expense of token-based AI</h2>



<p>The market still treats token-based AI pricing as a stable, mature economic model. It is not. Much of what enterprises pay today reflects a highly competitive environment in which providers are still subsidizing adoption, offering aggressive discounts, and prioritizing market share over normalized margins. That may be good news in the short term, but it is dangerous to assume those conditions will persist.</p>



<p>As enterprises scale their usage, token consumption shifts from an interesting line item to serious financial exposure. A chatbot pilot is one thing. Enterprisewide inference across business operations, customer engagement, knowledge systems, automation, analytics, and embedded software is something else entirely. When AI becomes part of the daily operating fabric of the business, token charges stop being experimental expenses and become recurring utility bills. At that point, even modest changes in pricing can have major budget consequences.</p>



<p>Many tech leaders are now rethinking their assumptions about AI costs, realizing that current pricing may not reflect long-term expenses. As subsidies fade and usage increases, token costs are likely to rise sharply, potentially making large-scale public AI deployments less economically viable. That is the trap enterprises want to avoid. No CIO wants to explain that the company successfully operationalized AI only to discover that a growing bill from a public provider offsets every business gain. Enterprises have seen this before with cloud cost overruns, and they do not want to repeat it with AI.</p>



<h2 class="wp-block-heading">Hybrid AI is the natural end state</h2>



<p>It is becoming clear that the future of enterprise AI is neither all public cloud nor all on-premises. It is a hybrid. The market is maturing beyond ideology and moving toward workload placement based on economics, governance, latency, and control.</p>



<p>That shift matters because not every AI problem requires a giant hosted model. In fact, many enterprise use cases do not. A growing number of organizations are finding that smaller, domain-specific models can perform as well as, and often better than, larger ones for targeted business tasks. Some use tuned models. Some rely on classic machine learning and <a href="https://www.cio.com/article/228901/what-is-predictive-analytics-transforming-data-into-future-insights.html">predictive systems</a>. Some combine <a href="https://www.infoworld.com/article/2335814/what-is-retrieval-augmented-generation-more-accurate-and-reliable-llms.html">retrieval techniques</a> with smaller language models. Others build tightly constrained models tailored to specific operational domains.</p>



<p>These systems are often better suited to private infrastructure. They run closer to enterprise data, can be optimized for predictable workloads, and avoid the open-ended cost profile of external tokenized services. This is especially true when the model is used repeatedly within internal business processes rather than occasionally by a limited set of users. In other words, enterprises are not just choosing private AI because they dislike public cloud pricing. They are choosing it because they are learning to build AI systems that meet enterprise requirements rather than defaulting to whatever is easiest to consume from the outside.</p>



<h2 class="wp-block-heading">Security and governance </h2>



<p>Cost may be the loudest concern, but it is not the only one. Security and governance are becoming equally powerful drivers. Enterprises are increasingly uncomfortable with the idea of sensitive information flowing through public AI tools, public APIs, and user workflows that are difficult to monitor and control. The concern is not abstract. Employees routinely paste confidential information into public AI interfaces to boost productivity. Development teams sometimes move faster than policy can keep pace. Business units adopt tools before governance can catch up. The result is a growing risk of data leakage, unauthorized exposure, compliance failures, and security incidents directly tied to the use of AI.</p>



<p>This changes the conversation. Once AI touches customer records, financial models, regulated data, or other proprietary information, the focus shifts from deployment speed to the risk you introduce to the core of the business. While public clouds can provide strong security, many enterprises prefer tighter internal controls for sensitive AI workloads to ensure better observability, access, data locality, and policy enforcement.</p>



<p>There’s no question that private AI reduces the number of unknowns. It gives enterprises more direct control over where data resides, how models are used, who can access them, and how systems are audited. That does not eliminate risk, but it makes risk easier to manage.</p>



<h2 class="wp-block-heading">Private AI is harder but worth it</h2>



<p>Private AI is not effortless. Building AI on premises or in a <a href="https://www.infoworld.com/article/2291750/what-the-private-cloud-really-means.html">private cloud</a> requires investment, planning, specialized skills, operational discipline, and a willingness to own more of the stack. Enterprises must think about infrastructure design, GPU utilization, life-cycle management, model operations, integration, and resilience in ways that public services often abstract away.</p>



<p>That extra work introduces real risk. Some organizations will underestimate the operational burden, some will overspend on infrastructure, and some will struggle to attract the right talent. Even with those challenges, many enterprises are concluding that the cost savings are too compelling to ignore.</p>



<p>Enterprises are not moving toward private AI because it is easier. They are moving because it’s smarter in the long term. They would rather take on more responsibility now than remain exposed to a pricing model that could become unsustainable later. They would rather invest in owned capability than rent critical intelligence from an outside platform with uncertain future economics.</p>



<p>The public cloud will remain important, especially for experimentation, bursting, and select services. But for many production workloads, the balance is shifting. As token costs rise, governance pressures intensify, and organizations become better at building focused models rather than defaulting to giant LLMs, more enterprises will conclude that their most valuable AI belongs closer to home.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Top 16 Gaming Headset Angebote zum Amazon Prime Day - Delamar]]></title>
<description><![CDATA[Wir haben 16 Deals bei Amazon händisch und redaktionell für dich ausgewählt. Die größte prozentuale Ersparnis bietet das Razer Barracuda X mit 45% Rabatt. Beim Logitech G Astro A50 LIGHTSPEED sparst Du sogar bis zu 140,99€.]]></description>
<link>https://tsecurity.de/de/3625791/it-nachrichten/top-16-gaming-headset-angebote-zum-amazon-prime-day-delamar/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625791/it-nachrichten/top-16-gaming-headset-angebote-zum-amazon-prime-day-delamar/</guid>
<pubDate>Thu, 25 Jun 2026 22:17:47 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wir haben 16 Deals bei Amazon händisch und redaktionell für dich ausgewählt. Die größte prozentuale Ersparnis bietet das Razer Barracuda X mit 45% Rabatt. Beim Logitech G Astro A50 LIGHTSPEED sparst Du sogar bis zu 140,99€.]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic’s Claude is winning over paid consumers, a market owned by ChatGPT]]></title>
<description><![CDATA[Despite ChatGPT's commanding market lead, consumers who pay for AI have been increasingly choosing Anthropic's Claude, data shows.]]></description>
<link>https://tsecurity.de/de/3625506/it-nachrichten/anthropics-claude-is-winning-over-paid-consumers-a-market-owned-by-chatgpt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625506/it-nachrichten/anthropics-claude-is-winning-over-paid-consumers-a-market-owned-by-chatgpt/</guid>
<pubDate>Thu, 25 Jun 2026 19:47:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Despite ChatGPT's commanding market lead, consumers who pay for AI have been increasingly choosing Anthropic's Claude, data shows.]]></content:encoded>
</item>
<item>
<title><![CDATA[Beyond the Straight Line: Choosing Between OLS, Interaction Terms, and Tweedie Regression]]></title>
<description><![CDATA[Whether you should stick to a classic Ordinary Least Squares regression, introduce interaction terms, or pivot to a Tweedie distribution depends entirely on how your data handles the messy reality of zeros and extreme outliers.
The post Beyond the Straight Line: Choosing Between OLS, Interaction ...]]></description>
<link>https://tsecurity.de/de/3625305/ai-nachrichten/beyond-the-straight-line-choosing-between-ols-interaction-terms-and-tweedie-regression/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625305/ai-nachrichten/beyond-the-straight-line-choosing-between-ols-interaction-terms-and-tweedie-regression/</guid>
<pubDate>Thu, 25 Jun 2026 18:35:47 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Whether you should stick to a classic Ordinary Least Squares regression, introduce interaction terms, or pivot to a Tweedie distribution depends entirely on how your data handles the messy reality of zeros and extreme outliers.</p>
<p>The post <a href="https://towardsdatascience.com/beyond-the-straight-line-choosing-between-ols-interaction-terms-and-tweedie-regression/">Beyond the Straight Line: Choosing Between OLS, Interaction Terms, and Tweedie Regression</a> appeared first on <a href="https://towardsdatascience.com/">Towards Data Science</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Deezer startet Remix Lab: Fans können Songs direkt in der App remixen]]></title>
<description><![CDATA[Deezer erweitert sein Angebot um ein neues Kreativ-Feature. Mit Remix Lab können Nutzer Songs ausgewählter Künstler direkt in der Deezer-App remixen. Der Start erfolgt zunächst in Frankreich, ein internationaler Rollout soll in den kommenden Monaten folgen. Das neue Feature ist...Zum Beitrag: Dee...]]></description>
<link>https://tsecurity.de/de/3624467/it-nachrichten/deezer-startet-remix-lab-fans-koennen-songs-direkt-in-der-app-remixen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624467/it-nachrichten/deezer-startet-remix-lab-fans-koennen-songs-direkt-in-der-app-remixen/</guid>
<pubDate>Thu, 25 Jun 2026 14:18:02 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Deezer erweitert sein Angebot um ein neues Kreativ-Feature. Mit Remix Lab können Nutzer Songs ausgewählter Künstler direkt in der Deezer-App remixen. Der Start erfolgt zunächst in Frankreich, ein internationaler Rollout soll in den kommenden Monaten folgen. Das neue Feature ist...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/deezer-startet-remix-lab-fans-koennen-songs-direkt-in-der-app-remixen/">Deezer startet Remix Lab: Fans können Songs direkt in der App remixen</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI efficiency beyond the model: Rethinking code, hardware and cloud]]></title>
<description><![CDATA[As AI adoption grows, I see fellow enterprise leaders realizing that just implementing AI is not enough. We need to develop and adopt the best, fastest and most efficient AI models. It’s not just a matter of pride about who has the shiniest toy; optimizing models for efficiency can be the differe...]]></description>
<link>https://tsecurity.de/de/3624204/it-security-nachrichten/ai-efficiency-beyond-the-model-rethinking-code-hardware-and-cloud/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624204/it-security-nachrichten/ai-efficiency-beyond-the-model-rethinking-code-hardware-and-cloud/</guid>
<pubDate>Thu, 25 Jun 2026 13:08:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>As AI adoption grows, I see fellow enterprise leaders realizing that just implementing AI is not enough. We need to develop and adopt the best, fastest and most efficient AI models. It’s not just a matter of pride about who has the shiniest toy; <a href="https://www.cio.com/article/4109911/cognitive-data-architecture-designing-self-optimizing-frameworks-for-scalable-ai-systems.html">optimizing models</a> for efficiency can be the difference between a failed pilot and an effective business strategy.</p>



<p>At the most extreme end of the spectrum, inefficient use of AI can cost billions of dollars. Sam Altman, CEO of OpenAI, made headlines when he <a href="https://x.com/sama/status/1912646035979239430" rel="nofollow">admitted on X</a> that his company loses tens of millions of dollars every time people say “please” and “thank you” to his AI models, even though he added that he feels it’s money well spent.</p>



<p>Model efficiency also matters for those of us not operating at OpenAI’s scale. A more efficient model helps reduce overall costs because it doesn’t require as powerful or expensive hardware, uses less electricity, delivers output faster and can operate with a smaller cloud footprint.</p>



<p>Models that are optimized for efficiency deliver lower latency, improved scalability, increased flexibility and are less likely to drift. In my experience, all of this adds up to higher profit margins, a sharper competitive edge and a faster time to market, which are crucial whether you’re planning to use your model internally or sell it to others.</p>



<h2 class="wp-block-heading">The new CIO investment dilemma</h2>



<p>For a long time, it was believed that hardware must continually increase in power to enable models to grow in size. Then DeepSeek v2 came along and demolished all those theories. It showed that more efficient hardware can deliver equivalent results with less compute power by running smaller, smarter models.</p>



<p>Now, those of us in the CIO seat face a new dilemma: should we increase investment in computing power, focus on hardware or concentrate on software?</p>



<p>In my view, the correct answer is: all the above. AI efficiency is a full-stack problem. Hardware, compilers, runtime and model architecture must be co-designed to work in harmony; otherwise, we’re wasting money and failing to achieve the results we need. Today, choosing GPUs vs. custom accelerators vs. CPUs affects which model optimizations are viable.</p>



<h2 class="wp-block-heading">Hardware power constraints model capabilities</h2>



<p>It remains true that even the most powerful model in the world can’t function without access to the necessary hardware. Hardware performance is ultimately bounded by memory bandwidth, interconnect speed and compute units, no matter how optimized our models are.</p>



<p>This means that scalability depends on interconnects. Multi-node training and large inference clusters hinge on the performance of NVLink, InfiniBand or Ethernet fabric, not just model quality, so decisions about hardware investments or cloud providers can be critical to overall functionality.</p>



<p>“The pace of innovation is directly tied to advances in GPUs, tensor processing units (TPUs) and custom accelerators. The real question isn’t just what models we can build, but whether we have the compute infrastructure to support them,” says Gaurav Dewan, a research director at Avasant. “Models can only grow as powerful as the chips, memory systems and data center networks sustaining them.”</p>



<h2 class="wp-block-heading"><a></a>Compute power isn’t everything</h2>



<p>That said, in my experience, you can’t just throw computing power at every problem. Choices about hardware and cloud architecture determine how effectively users can tap into the potential of compute resources. Modern AI workloads are often memory-bound rather than compute-bound, so faster HBM, cache hierarchies and interconnects directly lower latency.</p>



<p>What’s more, the energy for computing power is limited. Companies can’t always afford the compute power they want, <a href="https://www.cloudzero.com/state-of-ai-costs/" rel="nofollow">with 58% saying</a> their AI cloud costs are too high. Cost per inference is hardware-driven and compute is usually the biggest line item in AI TCO. It’s not even easy to find space for enough GPUs, creating board-level power and cooling constraints in enterprise AI. More efficient silicon reduces data center strain, sustainability risk and cost per token/inference.</p>



<p>Additionally, reliability and utilization affect ROI. Features like MIG partitioning, hardware scheduling and fault tolerance determine how fully we can monetize expensive accelerators. Performance per watt is now the bottom line, with CIOs like me striving to get more out of every existing GPU per watt, dollar and square meter. We need to make our hardware more efficient by fine-tuning models and software to maximize capability.</p>



<p>“DeepSeek’s breakthrough suggests that AI models no longer need to scale indefinitely in size and complexity to achieve superior performance. Instead, they can be algorithmically optimized to deliver the same, if not better, results while consuming significantly fewer resources,” explains Matthew Taylor <a href="https://www.linkedin.com/pulse/ai-infrastructure-dilemma-on-premises-vs-cloud-2025-dr-matthew--zed1e/" rel="nofollow">in his post</a> on LinkedIn.</p>



<h2 class="wp-block-heading">Rethinking cloud strategy in the age of AI</h2>



<p>That cost pressure has forced many of us to revisit assumptions we held for the better part of a decade. Cloud computing has reached an uncertain crossroads. The hyperscaler-by-default posture that defined the last era of enterprise IT no longer survives a serious look at AI economics.</p>



<p>When inference costs scale linearly with usage and training runs can consume an annual infrastructure budget in weeks, the question I hear in every CIO conversation is the same: does our cloud strategy still match the workload we are actually running?</p>



<p>In my experience, the answer is increasingly no, at least not without significant rebalancing. Private clouds, written off as legacy not long ago, are quietly making a comeback. The combination of predictable cost structures, tighter control over data residency and the sensitivity of the proprietary data feeding our AI systems is making on-premise and colocation options compelling again, particularly for regulated industries.</p>



<p>At the same time, purpose-built neoclouds for GPU workloads, along with sovereign clouds responding to jurisdictional and data-protection mandates, are steadily chipping away at the dominance of AWS, Azure and GCP. None of these alternatives replace the hyperscalers outright, but they are forcing every CIO I know to think about cloud as a portfolio rather than a single vendor relationship.</p>



<p>What I have found is that navigating this shift takes more than a procurement decision. It takes a clear-eyed view of where each workload genuinely belongs. Training, inference, retrieval, fine-tuning and experimentation each carry different cost curves, latency profiles and data-gravity considerations. As organizations move <a href="https://www.artefact.com/blog/data-platforms-for-the-agentic-era/" rel="nofollow">towards the agentic</a> AI era, the underlying data platform becomes equally important, requiring architectures that can support multimodal data, real-time processing and governance at scale.</p>



<p>The enterprises I have seen handle this best treat cloud strategy as an ongoing exercise in workload placement, not a one-time platform commitment.</p>



<p>That is also where the conversation tends to outgrow internal teams.</p>



<p>As AI moves from pilots to production, the questions get harder: how to architect data foundations that survive model churn, how to govern AI without strangling it, how to translate technical efficiency into measurable business value. I have seen organizations lean on specialist partners to think through these problems alongside them. Among the consultancies working at this intersection is Artefact, founded in Paris and operating across data strategy, AI engineering and enterprise transformation. Its work includes governance, platform development, operating models and workforce enablement—areas that have become increasingly important as organizations move from AI pilots to large-scale deployment.</p>



<p>What I find useful about these consultancies is not the technology recommendations themselves; it is the pattern recognition they bring from seeing similar cloud and AI transitions play out across geographies and sectors. In a moment when every CIO is rewriting the playbook simultaneously, that outside vantage point matters more than it used to.</p>



<h2 class="wp-block-heading">Hardware is often underused and misused</h2>



<p><a></a>A lot of hardware goes unused or underutilized. Often, GPUs sit idle due to deployment complexity and data infrastructure bottlenecks, so enterprises don’t see the value of the compute power they’re paying for. When data and computing are on two separate chips, compute is wasted moving data between the two locations.</p>



<p>Likewise, models that exceed accelerator memory or require excessive HBM traffic suffer steep latency and cost penalties. Optimizing models to align with hardware means that all the compute power is being put to good use.</p>



<p>Techniques like operator fusion, activation management, fine-tuning smaller models, pruning unnecessary parameters and memory-aware architectures keep more of the model resident on the accelerator, reduce unnecessary read/write cycles and combine steps so data is touched fewer times.</p>



<p>Kfir Aberman, founding member at Decart AI, <a href="https://www.techzine.eu/experts/analytics/136536/how-our-team-optimizes-infrastructure-for-minimal-ai-video-processing-latency/">explains this approach</a>. “Our solution to this was to optimize our kernels for how [Nvidia GPU] Hopper works. Essentially, we created a single ‘mega kernel’ that enables the chip to process all of a model’s computations in a single, continuous pass. By doing this, we eliminate all of the stopping, starting and data movement, allowing more of the GPU to be utilized more of the time, speeding up processing by an order of magnitude.”</p>



<p>When models match accelerator characteristics such as tensor core shapes, SIMD widths and kernel libraries, this keeps expensive silicon working effectively and translates theoretical FLOPs into real throughput.</p>



<h2 class="wp-block-heading">More hardware can’t overcome model mismatch</h2>



<p><a></a>Another way that organizations undermine ROI on their own AI investments is by ignoring coordination efficiency.</p>



<p>They’ll buy large GPU clusters but pay little attention to what seem like minor issues with batching and alignment. Unfortunately, when batch sizes are wrong, work is split inefficiently and network links become bottlenecks, you see expensive but underutilized clusters.</p>



<p>Ultimately, more GPUs don’t guarantee more performance. Parallelism and batching must match the system topology. Effective scaling depends on aligning data, tensor and pipeline parallelism and batch sizing with the actual interconnect bandwidth and node configuration.</p>



<h2 class="wp-block-heading">The magic happens when model and hardware come together</h2>



<p>The lesson that those of us in CIO roles are learning is that symbiosis between model and hardware is critical. Code determines what our AI can do, hardware determines how efficiently we can afford to do it and co-design determines whether our AI program scales economically and successfully.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA['No need to feed water-gobbling, planet-heating data centers': Deezer's new Remix Lab tool uses absolutely no AI and debunks slop music myths]]></title>
<description><![CDATA[Deezer has unveiled Remix Lab, which lets you combine two artists' songs, yet without using AI or underpaying original writers.]]></description>
<link>https://tsecurity.de/de/3624080/it-nachrichten/no-need-to-feed-water-gobbling-planet-heating-data-centers-deezers-new-remix-lab-tool-uses-absolutely-no-ai-and-debunks-slop-music-myths/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624080/it-nachrichten/no-need-to-feed-water-gobbling-planet-heating-data-centers-deezers-new-remix-lab-tool-uses-absolutely-no-ai-and-debunks-slop-music-myths/</guid>
<pubDate>Thu, 25 Jun 2026 12:18:00 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Deezer has unveiled Remix Lab, which lets you combine two artists' songs, yet without using AI or underpaying original writers.]]></content:encoded>
</item>
<item>
<title><![CDATA[Taming complexity in simulation-driven VFX movies]]></title>
<description><![CDATA[I still remember the first time we tried to simulate a large-scale water sequence nearly two decades ago. It was a simple brief — “make it look real.” What followed was anything but simple. Machines struggled, artists waited and we often had to compromise between realism and deadlines. Back then,...]]></description>
<link>https://tsecurity.de/de/3624053/it-security-nachrichten/taming-complexity-in-simulation-driven-vfx-movies/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624053/it-security-nachrichten/taming-complexity-in-simulation-driven-vfx-movies/</guid>
<pubDate>Thu, 25 Jun 2026 12:09:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>I still remember the first time we tried to simulate a large-scale water sequence nearly two decades ago. It was a simple brief — “make it look real.” What followed was anything but simple. Machines struggled, artists waited and we often had to compromise between realism and deadlines. Back then, simulation in VFX felt like a powerful but unpredictable beast — something you respected, but never fully controlled.</p>



<p>Fast forward to today, and that beast has grown bigger, faster and far more demanding. As someone who has spent over 25 years in animation and VFX technology, I’ve seen simulation evolve from a niche capability into the backbone of modern visual effects. Whether it’s oceans, explosions, cloth, smoke, or destruction — simulation now defines realism. But with that realism comes a level of complexity that is reshaping how studios think, build and operate their pipelines.</p>



<p>This is <a href="https://semiengineering.com/the-era-of-fluid-simulations-in-hollywood/" rel="nofollow">the story of that shift</a> — and how we’re learning to tame it.</p>



<h2 class="wp-block-heading">When realism became data</h2>



<p>In the early days, simulations were relatively lightweight. A smoke sim might take hours, maybe a day. Today, a high-resolution fluid simulation can generate terabytes of data for a single sequence.</p>



<p>That’s the first big change: <strong>Simulation is no longer just computation — it’s data generation at scale</strong>.</p>



<p>Every frame we simulate produces layers of information — velocity fields, density grids, particle caches, mesh outputs. Multiply that across hundreds of shots, and suddenly your pipeline isn’t just about rendering images — it’s about managing massive datasets.</p>



<p>I’ve seen studios hit a point where storage, not compute, became the bottleneck. Artists weren’t waiting for simulations to finish — they were waiting for data to move.</p>



<p>This shift forces a fundamental rethink:<br>We are no longer just running simulations. We are managing simulation ecosystems.</p>



<h2 class="wp-block-heading">Lessons from other worlds</h2>



<p>What’s interesting is — VFX is not alone in this journey. Other industries faced similar challenges earlier, and there’s a lot we can quietly borrow from them.</p>



<p>In <strong>weather forecasting</strong>, global climate models run on massive HPC systems, producing petabytes of data daily. But meteorologists don’t store everything forever. They <a href="https://ieeexplore.ieee.org/document/10774970" rel="nofollow">prioritize <em>derived insights</em> over raw data</a> — keeping summaries, patterns and key states instead of full datasets.</p>



<p>In <strong>genomics</strong>, sequencing a single human genome produces hundreds of gigabytes of raw data. Labs long ago realized that recomputing certain stages is cheaper than storing everything indefinitely. So they intentionally discard intermediate data — but keep the pipeline reproducible.</p>



<p>In <strong>autonomous driving</strong>, simulation environments generate enormous synthetic datasets. Companies don’t just store scenarios — they index them semantically: “Pedestrian crossing at night in rain,” for example. That makes retrieval intelligent, not just archival.</p>



<p>The pattern across all these domains is clear: <strong>They don’t fight data growth — they design around it.</strong></p>



<h2 class="wp-block-heading">The rise of HPC in VFX</h2>



<p>To handle this scale, High Performance Computing (HPC) has become essential.</p>



<p>Years ago, a render farm was enough. Today, simulations demand tightly coupled compute — clusters with high-speed interconnects, parallel file systems and optimized schedulers. In many ways, VFX studios now resemble scientific research labs.</p>



<p>But here’s the catch:<br>More compute doesn’t automatically mean better outcomes.</p>



<p>Throwing thousands of cores at a problem can speed things up, but it also increases <a href="https://www.atlantis-press.com/journals/jrnal/125917284/view" rel="nofollow">cost, complexity and coordination challenges</a>.</p>



<p>Here’s a practice I’ve seen work well, but is rarely talked about:<br>treat compute like a budget, not a resource pool.</p>



<p>Instead of unlimited access, assign “compute envelopes” per sequence or department. This forces smarter iteration — teams think before re-running simulations blindly.</p>



<p>Another overlooked idea: <strong>Simulate at multiple fidelities intentionally, not progressively.</strong></p>



<p>Most pipelines go low → mid → high resolution. But some studios now run <em>parallel exploratory sims</em> at different fidelities and let ML or heuristics decide which path to invest in further. It reduces dead-end iterations dramatically.</p>



<h2 class="wp-block-heading">Complexity is no longer in the solver</h2>



<p>Traditionally, we focused on improving solvers. Today, the hardest problems are about context — understanding what was done, why it worked and whether it can be reproduced.</p>



<p>Questions like which version was used, what parameters changed, or how upstream assets influenced the result are now central to the pipeline.</p>



<p>A practical way to address this is to treat each simulation as a uniquely identifiable event. By capturing not just inputs but also solver versions, environments and dependencies, teams can create what I often call a “simulation fingerprint.” If anything changes, the fingerprint changes — making reproducibility far more reliable.</p>



<h2 class="wp-block-heading">The power of structured data</h2>



<p>Metadata is no longer optional — it’s foundational.</p>



<p>However, the real value lies not in storing metadata, but in using it actively. When structured correctly, metadata can guide decisions — helping systems route jobs, anticipate failures and recommend better configurations.</p>



<p>At that point, the pipeline begins to evolve from a passive system into something more adaptive — one that <a href="https://tridiagonalsoftware.com/resources/the-power-of-simulations-how-to-harness-data-for-informed-decision-making" rel="nofollow">supports teams rather than slowing them down</a>.</p>



<h2 class="wp-block-heading">Learning from the past: Machine learning as a guide</h2>



<p>Machine learning in VFX is often misunderstood as a replacement for physics. In reality, its strength lies in learning from experience.</p>



<p>Every simulation leaves behind valuable data. When used correctly, this data can help teams avoid repeating work. For example, before launching a new simulation, systems can check whether something similar has already been done and suggest reuse or adaptation. Similarly, early signals in a simulation can indicate whether it is likely to fail, allowing teams to stop it before wasting hours of compute.</p>



<p>In this sense, machine learning becomes an intelligence layer — quietly <a href="https://www.awn.com/news/new-white-paper-dives-deep-nvidia-omniverse-enterprise-animation-and-vfx" rel="nofollow">improving efficiency without replacing the underlying physics</a>.</p>



<h2 class="wp-block-heading">Rethinking storage: Not everything needs to live forever</h2>



<p>One of the hardest mindset shifts is accepting that not all data needs to be preserved.</p>



<p>Instead of treating storage as infinite, a more sustainable approach is to prioritize what truly matters. High-resolution outputs are retained for final shots, while lighter representations can support iteration history. In many cases, recomputing data is more efficient than storing it indefinitely.</p>



<p>This is a model that other industries have adopted successfully — and one that VFX is gradually moving toward.</p>



<h2 class="wp-block-heading">Hybrid HPC: The new normal</h2>



<p>Most studios today operate in a hybrid model, combining on-premise infrastructure with cloud resources.</p>



<p>The challenge, however, is not where the compute exists — it’s how decisions are made. Choosing where to run a simulation depends on factors like data location, system load and cost efficiency.</p>



<p>One principle that consistently proves effective is simple: Move compute closer to data whenever possible. Transferring large datasets is often far more expensive than relocating compute.</p>



<h2 class="wp-block-heading">A simple way to think about it</h2>



<p>A modern simulation pipeline is less like a factory and more like an airport — constantly managing traffic, prioritizing tasks and adapting to change.</p>



<p>At its core, it follows a simple loop: <strong>Data leads to compute, which produces more data, which informs decisions — and the cycle repeats.</strong></p>



<p>The studios that succeed are the ones that optimize this loop as a whole, rather than focusing on individual steps.</p>



<h2 class="wp-block-heading">What breaks next?</h2>



<p>Looking ahead, the pressure will only increase.</p>



<p>As real-time expectations grow through virtual production, and AI-generated environments increase the demand for simulations, pipelines will be pushed further. Storage costs will become more significant, and energy consumption will no longer be ignored.</p>



<p>The next bottleneck may not be obvious — but it will arrive.</p>



<p>Looking back, the challenges we faced 25 years ago seem simple compared to today. But the goal remains unchanged — to create believable worlds that captivate audiences.</p>



<p>Simulation has grown from a tool into an ecosystem — of compute, data and decisions.</p>



<p>We may never fully tame the complexity — but we can learn to guide it.</p>



<p>Because in modern VFX, the challenge is no longer creating complexity — <strong>it’s choosing when not to.</strong></p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to pick commercial cleaning software]]></title>
<description><![CDATA[A practical guide to choosing commercial cleaning software in 2026, covering scheduling, inspections, compliance, and client reporting tools.]]></description>
<link>https://tsecurity.de/de/3623909/it-nachrichten/how-to-pick-commercial-cleaning-software/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623909/it-nachrichten/how-to-pick-commercial-cleaning-software/</guid>
<pubDate>Thu, 25 Jun 2026 11:17:27 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A practical guide to choosing commercial cleaning software in 2026, covering scheduling, inspections, compliance, and client reporting tools.]]></content:encoded>
</item>
<item>
<title><![CDATA[Nation-state actors cracked critical Australian infrastructure to ‘cripple it at a time of their choosing’]]></title>
<description><![CDATA[To defuse another attack, Oz spies called foreign counterparts to tell them an op was a bust This article has been indexed from www.theregister.com – Articles Read the original article: Nation-state actors cracked critical Australian infrastructure to ‘cripple it at…
Read more →
The post Nation-s...]]></description>
<link>https://tsecurity.de/de/3623388/it-security-nachrichten/nation-state-actors-cracked-critical-australian-infrastructure-to-cripple-it-at-a-time-of-their-choosing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623388/it-security-nachrichten/nation-state-actors-cracked-critical-australian-infrastructure-to-cripple-it-at-a-time-of-their-choosing/</guid>
<pubDate>Thu, 25 Jun 2026 07:23:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>To defuse another attack, Oz spies called foreign counterparts to tell them an op was a bust This article has been indexed from www.theregister.com – Articles Read the original article: Nation-state actors cracked critical Australian infrastructure to ‘cripple it at…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/nation-state-actors-cracked-critical-australian-infrastructure-to-cripple-it-at-a-time-of-their-choosing/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/nation-state-actors-cracked-critical-australian-infrastructure-to-cripple-it-at-a-time-of-their-choosing/">Nation-state actors cracked critical Australian infrastructure to ‘cripple it at a time of their choosing’</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nation-state actors cracked critical Australian infrastructure to ‘cripple it at a time of their choosing’]]></title>
<description><![CDATA[To defuse another attack, Oz spies called foreign counterparts to tell them an op was a bust]]></description>
<link>https://tsecurity.de/de/3623345/it-security-nachrichten/nation-state-actors-cracked-critical-australian-infrastructure-to-cripple-it-at-a-time-of-their-choosing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623345/it-security-nachrichten/nation-state-actors-cracked-critical-australian-infrastructure-to-cripple-it-at-a-time-of-their-choosing/</guid>
<pubDate>Thu, 25 Jun 2026 06:36:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[To defuse another attack, Oz spies called foreign counterparts to tell them an op was a bust]]></content:encoded>
</item>
<item>
<title><![CDATA[Lack of reviews of Linux experiences from non-creators/non-gamers]]></title>
<description><![CDATA[I’ve been getting deep into trying to revive my old 2017 12” Retina MacBook by slapping Linux on it. It’s been a lot of fun, but ultimately doomed because the battery is garbage and not worth replacing. I’m not new to Linux, and I am technically capable, but it’s been over a decade since I last u...]]></description>
<link>https://tsecurity.de/de/3623112/linux-tipps/lack-of-reviews-of-linux-experiences-from-non-creatorsnon-gamers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623112/linux-tipps/lack-of-reviews-of-linux-experiences-from-non-creatorsnon-gamers/</guid>
<pubDate>Thu, 25 Jun 2026 02:08:22 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I’ve been getting deep into trying to revive my old 2017 12” Retina MacBook by slapping Linux on it. It’s been a lot of fun, but ultimately doomed because the battery is garbage and not worth replacing.</p> <p>I’m not new to Linux, and I am technically capable, but it’s been over a decade since I last used it. I’m also not an engineer, nor a content creator, nor a gamer.</p> <p>What I’m trying to determine for myself is if I want to invest in a real, more modern laptop to see if I could really make Linux my personal daily driver. Honestly, it’s mainly just out of curiosity and interest - no other compelling reason. (My current MacBook Pro is fine, but it’s getting older and since it’s M2, only supports one distro with somewhat limited support.)</p> <p>But every single review on YouTube and on most review sites/blogs is 90% dominated by choosing a distro then barely mentioning anything other than gaming and video editing.</p> <p>I get it, the Venn diagram of people who produce “trying Linux” content and people who are PC gamers + content creators is probably just a circle. But it really tells me absolutely nothing about how good you’ve found the alternatives to Excel to be, especially if you’re syncing via OneDrive. Or how the open source mail clients work for you vs Apple Mail or Outlook.</p> <p>And it’s almost always from the perspective of coming from Windows. It’s been longer since I’ve run Windows than Linux. What I want to know is how you’ve found the spotlight alternatives, or Airdrop alternatives. Yes, I could research what all these alternatives are, but I like to watch/read reviews from people who have actually experienced the switch and tried.</p> <p>Anyway, just a rant as I’m trying to decide whether or not to buy a new laptop.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Tight_Couture344"> /u/Tight_Couture344 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1ueth6q/lack_of_reviews_of_linux_experiences_from/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1ueth6q/lack_of_reviews_of_linux_experiences_from/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Audit Register: An independent guide to choosing security auditors and harnesses]]></title>
<description><![CDATA[submitted by    /u/davidw_-   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3623041/it-security-nachrichten/the-audit-register-an-independent-guide-to-choosing-security-auditors-and-harnesses/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623041/it-security-nachrichten/the-audit-register-an-independent-guide-to-choosing-security-auditors-and-harnesses/</guid>
<pubDate>Thu, 25 Jun 2026 01:22:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/davidw_-"> /u/davidw_- </a> <br> <span><a href="https://theauditregister.com/">[link]</a></span>   <span><a href="https://www.reddit.com/r/security/comments/1uekzsa/the_audit_register_an_independent_guide_to/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Choose Your Filter! — Vom Forschungsprojekt zur Ausstellung (gpn24)]]></title>
<description><![CDATA[Im selben Gebäude, in dem die GPN stattfindet, war 2025 die Ausstellung “Choose Your Filter!” zu sehen. Gezeigt wurden künstlerische Webbrowser aus drei Jahrzehnten, also Software, die selbst Kunstwerk und Anzeigeumgebung in einem ist. Der Ausstellung ging ein mehrjähriges Forschungsprojekt am KI...]]></description>
<link>https://tsecurity.de/de/3622534/it-security-video/choose-your-filter-vom-forschungsprojekt-zur-ausstellung-gpn24/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622534/it-security-video/choose-your-filter-vom-forschungsprojekt-zur-ausstellung-gpn24/</guid>
<pubDate>Wed, 24 Jun 2026 20:49:47 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Im selben Gebäude, in dem die GPN stattfindet, war 2025 die Ausstellung “Choose Your Filter!” zu sehen. Gezeigt wurden künstlerische Webbrowser aus drei Jahrzehnten, also Software, die selbst Kunstwerk und Anzeigeumgebung in einem ist. Der Ausstellung ging ein mehrjähriges Forschungsprojekt am KIT voraus, in dem solche Browser als eigenständige künstlerische Form untersucht wurden. Sie sind als Remix-Programme interpretierbar, sie situieren Nutzer*innen und formen mit, wie das Web durch sie hindurch wahrgenommen wird. Browser bestimmen, was sichtbar wird, in welcher Geschwindigkeit, Reihenfolge und Hierarchie. Damit sind sie Filter im wörtlichen Sinn, und Gegenstand sozio-politischer, ökonomischer und kultureller Fragen.

Wenn solche softwarebasierten Werke überhaupt in den Blick genommen werden, beschränkt sich die Auseinandersetzung im akademischen Rahmen üblicherweise auf ihre Dokumentation, Beschreibung und Kontextualisierung der Arbeiten. Eine Ausstellung, die den Anspruch hegt, nicht (nur) Relikte zu zeigen, verlangt mehr: Dort sollen die Arbeiten wieder live erfahrbar sein, also tatsächlich laufen, in einem Raum, vor Publikum, über Monate hinweg — ohne Wartung im laufenden Betrieb und ohne technisches Personal, das im Zweifel eingreift. Damit verschiebt sich die Aufgabe grundsätzlich hin zu Reparatur und robuste Stabilisierung. Werke, die für eine bestimmte historische Konfiguration aus Browser, Plugin, Betriebssystem und Serverlandschaft geschrieben wurden, müssen in einer Gegenwart funktionieren, in der diese Konfiguration nicht mehr existiert, und sie müssen es selbständig tun: Crashes überstehen, Zustände zurücksetzen, mit unterschiedlichsten Besucher*inneninteraktion umgehen, fehlende Server kompensieren — alles ohne Hand am Gerät. Was im Forschungsprojekt eine Frage des Verstehens war, wird im Ausstellungsbetrieb eine Frage der Rekonstruktion und der autonomen Lauffähigkeit — konzeptuell, technisch und konservatorisch zugleich.

Der Vortrag berichtet aus erster Hand davon, wie aus einem Forschungsvorhaben eine Ausstellung wurde: welche Entscheidungen kuratorisch fallen mussten, wie einzelne Werke wieder zum Laufen gebracht wurden, und welche Infrastruktur dabei entstanden ist, um Netzkunst aus mehreren Jahrzehnten parallel und stabil zu betreiben. Wir sprechen aus zwei Perspektiven — kunsthistorisch und museumstechnisch — über dasselbe Problem: was es heißt, Software, die selbst Kunstwerk ist, nicht nur zu beschreiben, sondern zu zeigen.

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://cfp.gulas.ch/gpn24/talk/JQYNPX/]]></content:encoded>
</item>
<item>
<title><![CDATA[Deezer says its new feature lets fans remix songs with artist consent]]></title>
<description><![CDATA[Global music streaming service Deezer is taking a contrarian approach to AI, even as it adds a feature that lets fans remix songs.]]></description>
<link>https://tsecurity.de/de/3622259/it-nachrichten/deezer-says-its-new-feature-lets-fans-remix-songs-with-artist-consent/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622259/it-nachrichten/deezer-says-its-new-feature-lets-fans-remix-songs-with-artist-consent/</guid>
<pubDate>Wed, 24 Jun 2026 19:17:58 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Global music streaming service Deezer is taking a contrarian approach to AI, even as it adds a feature that lets fans remix songs.]]></content:encoded>
</item>
<item>
<title><![CDATA[The Best Toaster Ovens of 2026 for Easy Countertop Cooking]]></title>
<description><![CDATA[Here's everything to know about choosing the right toaster oven.]]></description>
<link>https://tsecurity.de/de/3621610/it-nachrichten/the-best-toaster-ovens-of-2026-for-easy-countertop-cooking/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621610/it-nachrichten/the-best-toaster-ovens-of-2026-for-easy-countertop-cooking/</guid>
<pubDate>Wed, 24 Jun 2026 16:03:48 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Here's everything to know about choosing the right toaster oven.]]></content:encoded>
</item>
<item>
<title><![CDATA[How Do Different AI Chatbot Platforms Address Security And Privacy Issues?]]></title>
<description><![CDATA[How do leading AI chatbot platforms compare on security and privacy and what should enterprises look for when choosing a tool?]]></description>
<link>https://tsecurity.de/de/3621544/it-security-nachrichten/how-do-different-ai-chatbot-platforms-address-security-and-privacy-issues/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621544/it-security-nachrichten/how-do-different-ai-chatbot-platforms-address-security-and-privacy-issues/</guid>
<pubDate>Wed, 24 Jun 2026 15:38:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[How do leading AI chatbot platforms compare on security and privacy and what should enterprises look for when choosing a tool?]]></content:encoded>
</item>
<item>
<title><![CDATA[Choosing your AI stack: The benefits of vendor lock-in]]></title>
<description><![CDATA[AI has emerged as a top priority for businesses and a vehicle for transformation, as evidenced by Accenture research: 97% of executives believe AI will transform their company and industry. But as companies move from AI pilots to scaling AI across the enterprise, we have had repeated conversation...]]></description>
<link>https://tsecurity.de/de/3620900/it-nachrichten/choosing-your-ai-stack-the-benefits-of-vendor-lock-in/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620900/it-nachrichten/choosing-your-ai-stack-the-benefits-of-vendor-lock-in/</guid>
<pubDate>Wed, 24 Jun 2026 12:03:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AI has emerged as a top priority for businesses and a vehicle for transformation, as evidenced by <a href="https://www.accenture.com/us-en/insights/consulting/gen-ai-reinventing-enterprise-models" rel="nofollow">Accenture research</a>: 97% of executives believe AI will transform their company and industry. But as companies move from AI pilots to scaling AI across the enterprise, we have had repeated conversations with CIOs and technology leaders who are arriving at the same uncomfortable realization: AI stack decisions are not easily reversible.</p>



<p>Unlike earlier eras of enterprise IT, where abstraction layers insulated applications from hardware choices, today’s AI stack—the infrastructure, technologies and frameworks that powers AI systems – tends  to be tightly co-engineered, with stronger dependencies in the underlying compute layers. Choices made about models, runtimes and compute platforms now shape cost structures, performance ceilings and strategic flexibility. <a href="https://www.accenture.com/content/dam/accenture/final/a-com-migration/pdf/pdf-171/accenture-ever-ready-infrastructure.pdf#zoom=40" rel="nofollow">AI-ready infrastructure</a> has re-emerged as a new source of differentiation, and with it, a new kind of vendor lock-in.</p>



<p>At the center of this shift is the move from training – building AI models – to inference, where those models are used in production to generate outputs from new data. While early attention focused on the cost of training large models, enterprises are now scaling AI across the organization, running models continuously across workflows. This shift significantly changes the economics of AI.</p>



<p>For instance, <a href="https://www.accenture.com/content/dam/accenture/final/accenture-com/document-4/Accenture-The-New-Rules-of-Platform-Strategy-in-the-Age-of-Agentic-AI.pdf#zoom=40" rel="nofollow">agentic AI is reshaping infrastructure architecture and platforms</a> because inference is becoming persistent, stateful and increasingly data intensive. As AI Factories scale, the focus is shifting from peak model performance toward sustainable token economics, where the key differentiators are lowest cost per generated token, power efficiency and infrastructure utilization at scale. In this environment, achieving those outcomes requires full-stack optimization across compute, networking, memory, storage and data fabrics, curated and integrated across ecosystem partners. Secure multitenancy and confidential computing are becoming core design principles, and enterprise AI is now ready to be industrialized at scale.</p>



<h2 class="wp-block-heading">Modern AI infrastructure is a strategic bet</h2>



<p>What makes AI infrastructure different is not just scale, but integration. <a href="https://www.cio.com/article/4176051/8-it-modernization-traps-cios-must-avoid.html?utm=hybrid_search">Modern AI systems</a> are built on tightly co-engineered stacks where GPU accelerators, high-bandwidth interconnects, compilers and runtimes are designed in tandem to maximize throughput and efficiency for AI workloads.</p>



<p>To get the massive computing power required for AI, providers design their hardware and software to work exclusively with one another. This has shifted enterprise decision-making from choosing hardware one piece at a time to committing to ecosystems. And that commitment carries consequences.</p>



<p>In traditional IT environments, applications could also generally move across environments with a manageable amount of effort. In AI systems, that assumption breaks down. What appears portable at the model or application layer often depends on deeply optimized components underneath that layer, such as memory handling and compiler frameworks like CUDA or ROCm that are fine-tuned to specific hardware.</p>



<p>We find it useful to think about AI systems as a layered structure:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/ai-systems-as-a-layered-structure.png?w=1024" alt="A visualization of AI systems as a layered structure." class="wp-image-4188504" width="1024" height="610" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Accenture</p></div>



<p>While upper layers retain some flexibility, dependencies increase as you move downward. Changing your foundational AI provider often means having to rebuild and re-optimize large portions of your technology from scratch.</p>



<p>This is why infrastructure decisions in AI feel less like procurement choices and more like strategic, high-stakes bets.</p>



<h2 class="wp-block-heading">Why switching AI platforms is harder than it looks</h2>



<p>In theory, switching platforms should be straightforward. Models can be retrained, applications rewritten, and infrastructure replaced. In reality, the cost of switching extends far beyond hardware or licensing.</p>



<ul class="wp-block-list">
<li>The first challenge is <strong>engineering effort</strong>. Migrating to different platforms requires engineers to revalidate model behavior, re-tune inference pipelines, and rebuild performance baselines. During this period, teams spend most of their time stabilizing and not innovating.</li>



<li>The second challenge is <strong>hidden dependency</strong>. Over time, system optimization becomes tied to a specific stack. This might include latency expectations, batching strategies, orchestration logic and even human workflows. These ties are not always obvious, but they shape how systems behave in production.</li>



<li>The third challenge is <strong>timing</strong>. There is never a convenient time to migrate, especially factoring in rising AI infrastructure and inference costs, competitive pressure or scaling demands. Organizations are often forced to switch platforms precisely when disruption is hardest to absorb.</li>
</ul>



<h2 class="wp-block-heading">Rethinking performance vs control</h2>



<p>Despite these barriers, organizations do switch. In our experience, this typically happens under three conditions.</p>



<p>One common trigger is when the opportunity cost of staying begins to outweigh the cost of leaving. As performance gaps widen across competing ecosystems, inefficiencies accumulate to the point that remaining on the current platform is no longer viable. Another driver comes from shifts in vendor dynamics. Pricing volatility, supply constraints, or misalignment in product roadmaps can introduce risks that force a re-evaluation. Finally, regulatory requirements, data sovereignty constraints or geopolitical shifts can force platform changes regardless of technical preference.</p>



<p>Across all three strategies, one principle stands out. Lock-in is not inherently negative, and openness is not inherently superior. Timing matters more than ideology.</p>



<p>Given these dynamics, the central question for CIOs is not how to avoid lock-in, but how to manage it deliberately. This represents a significant shift in strategies that previously considered vendor lock-in as a detriment. In practice, we see three broad approaches emerge, each reflecting a different balance between performance and control.</p>



<p>Some organizations take a performance-first approach. They optimize deeply within a specific ecosystem because performance directly drives business outcomes. <a href="https://blogs.nvidia.com/blog/lilly-ai-factory-nvidia-blackwell-dgx-superpod/" rel="nofollow">Eli Lilly’s AI Factory</a> is a strong example. The company has invested heavily in a tightly integrated NVIDIA-based stack to maximize throughput and utilization. In this case, infrastructure is a competitive lever and not merely a support function. Higher switching costs are accepted because near-term performance advantages are decisive.</p>



<p>Others lean toward a portability-first model. These organizations prioritize flexibility, governance, and long-term independence over absolute performance. <a href="https://group.bnpparibas/en/press-release/bnp-paribas-provides-its-businesses-with-an-llm-as-a-service-platform-to-accelerate-the-industrialization-of-generative-ai-use-cases" rel="nofollow">BNP Paribas</a> illustrates this well through its internal LLM platform built on open-source models and controlled infrastructure. By retaining ownership of the stack, the bank ensures data sovereignty, regulatory alignment and predictable cost.</p>



<p>A growing number are adopting a hybrid approach. Rather than applying a single strategy across the enterprise, they segment workloads based on sensitivity to performance, cost and governance. For example, in late 2024, <a href="https://www.cio.com/article/3616622/jpmorgan-chase-builds-ambitious-ai-foundation-on-aws.html?utm_source=chatgpt.com">JPMorganChase</a> outlined its approach at a leading cloud and technology conference. It described combining a firm-wide internal AI platform with cloud-based services to move generative AI into production at scale. This reflects a broader enterprise pattern of pairing internally controlled environments with external ecosystems to balance control, scalability and cost.</p>



<p>A performance advantage is only valuable if it lasts long enough to justify the lock-in it creates. Similarly, portability only matters if the ecosystem evolves in ways that make switching worthwhile. This is where many organizations struggle. They evaluate platforms based on current benchmarks rather than the direction of the ecosystem.</p>



<p>In practice, we encourage leaders to track a set of evolving signals. These range from the maturity of open compiler ecosystems and improvements in cross-platform runtimes, to shifts in performance per watt and increasing regulatory focus on sovereign AI. Together, these indicators help determine whether the industry is moving toward convergence or further fragmentation.</p>



<h2 class="wp-block-heading">Conclusion</h2>



<p>AI is forcing a reset in how technology leaders think about IT architecture. The goal for CIOs is no longer to eliminate dependency, but to choose it consciously and manage and revisit that choice over time.</p>



<p>In our experience, the most effective organizations treat this as a dynamic problem. They evaluate where performance truly differentiates them, where flexibility protects them, and how quickly those boundaries are shifting. They also recognize that some degree of re-platforming is inevitable and plan for it, rather than treating it as a failure.</p>



<p>Ultimately, AI infrastructure strategy is not about optimizing for today’s conditions. It is about getting ready for where the ecosystem is going next. The leaders who navigate this well are not those who avoid lock-in entirely, but those who understand when to embrace it when to limit it and when to move beyond it before the market forces that decision on them.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Using Visual Studio Code’s ‘air-gapped’ AI model mode]]></title>
<description><![CDATA[Microsoft has been pushing hard to make Visual Studio Code a major way to consume its AI services, mostly in the form of GitHub Copilot. GitHub Copilot’s deep integration with VS Code brings many conveniences — inline autocomplete, for instance — but it’s frustrating for those, like me, who would...]]></description>
<link>https://tsecurity.de/de/3620721/ai-nachrichten/using-visual-studio-codes-air-gapped-ai-model-mode/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620721/ai-nachrichten/using-visual-studio-codes-air-gapped-ai-model-mode/</guid>
<pubDate>Wed, 24 Jun 2026 11:03:55 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Microsoft has been pushing hard to make <a href="https://www.infoworld.com/article/2335960/what-is-visual-studio-code-microsofts-extensible-code-editor.html" data-type="link" data-id="https://www.infoworld.com/article/2335960/what-is-visual-studio-code-microsofts-extensible-code-editor.html">Visual Studio Code</a> a major way to consume its AI services, mostly in the form of <a href="https://www.infoworld.com/article/3609013/github-copilot-everything-you-need-to-know.html" data-type="link" data-id="https://www.infoworld.com/article/3609013/github-copilot-everything-you-need-to-know.html">GitHub Copilot</a>. GitHub Copilot’s deep integration with VS Code brings many conveniences — inline autocomplete, for instance — but it’s frustrating for those, like me, who would rather use another model provider, or even a locally hosted LLM, for those functions.</p>



<p>Visual Studio Code 1.122 introduced a new feature, “<a href="https://code.visualstudio.com/updates/v1_122#_use-byok-without-a-github-sign-in">Use BYOK [Bring Your Own Key] without a GitHub sign-in</a>,” that allows you to “use chat, tools, and MCP servers in air-gapped or restricted environments where GitHub sign-in isn’t possible.” More importantly, it “enables fully offline workflows with local models like Ollama.”</p>



<p>In other words, you can now use locally hosted LLMs for chat, tools, and <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html" data-type="link" data-id="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">Model Context Protocol</a> servers inside Visual Studio Code. The one thing you still can’t do is use a local LLM for inline and next-edit suggestions — at least, not without additional tooling.</p>



<h2 class="wp-block-heading">Choosing a model for BYOK mode</h2>



<p>If you want to use a local LLM with VS Code’s bring-your-own-model system, the first thing you need is a way to host the model. VS Code lacks a model-hosting mechanism of its own, although it’s conceivable that a VS Code extension may offer something like that in the future. That said, hosting models is complicated enough that a dedicated app is really needed for the job.</p>



<p>One easy way to host models is via a product like <a href="https://www.infoworld.com/article/4127250/first-look-run-llms-locally-with-lm-studio.html">LM Studio</a>, a convenient GUI for standing up, serving, and managing LLMs on one’s own hardware. The model host does not have to be the same system you run VS Code on, either. It can be on a server box you control, or on a cloud instance.</p>



<p>The choice of model is also important. Many models are powerful but won’t run well on commodity hardware because they’re simply too big. A good rule of thumb is to choose a model that fits into existing VRAM, along with the memory needed for a sizable token context (the more, the better). Also, the model should be suited to coding and development work. Some models in this vein that fit comfortably into 8GB VRAM include:</p>



<ul class="wp-block-list">
<li><a href="https://lmstudio.ai/models/google/gemma-4-e2b">Gemma4 (effective 2 billion parameters version)</a></li>



<li><a href="https://lmstudio.ai/models/qwen/qwen3.5-9b">Qwen3.5 9B</a></li>



<li><a href="https://huggingface.co/bartowski/Codestral-22B-v0.1-GGUF">Codestral 22B v.0.1</a> (<a href="https://mistral.ai/licenses/MNPL-0.1.md">proprietary license</a>)</li>
</ul>



<h2 class="wp-block-heading">Setting up BYOK mode in VS Code</h2>



<p>Once you have a model up and running, you can integrate it with Visual Studio Code. If you’ve disabled VS Code’s AI features, you will need to turn them on. Make sure the setting <code>chat.disableAIFeatures</code> is turned off. You can find it in <code>Settings | Chat | Miscellaneous</code>.</p>



<p>Third-party language models are managed through Visual Studio Code’s language model list. Press <code>Ctrl-Shift-P</code> and type <code>Manage Language Models</code> to open the list of existing language models.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/image_154.png?w=1024" alt="Managing VS Code's AI language model list" class="wp-image-4186819" width="1024" height="406" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Managing VS Code’s AI language model list. The models available by default are only models available as external APIs, not models that run locally.</p></figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>First you will see a list of the built-in models, which are all externally hosted. To add a new model, select <code>Add Models</code> at the top right and select <code>Custom Endpoint</code>.</p>



<p>You’ll then get a series of prompts:</p>



<ul class="wp-block-list">
<li><strong>Group Name</strong>: This is “Custom Endpoint” by default, but you can choose any name you want. The name is strictly for organizing the model list and doesn’t affect things like model recognition or connectivity.</li>



<li><strong>API Key</strong>: If you’ve configured LM Studio to use an API key for serving models, provide it here. If you’re hosting the model locally and you haven’t explicitly set up API keys, you can leave this blank.</li>



<li><strong>API Type</strong>: The options here are <code>Chat Completions</code>, <code>Responses</code>, and <code>Messages</code>. Most of the time you’ll want to use <code>Responses</code>, as it’s the most general-purpose option of the three.</li>
</ul>



<p>Once you finish providing those answers, you’ll be dropped into a modal editor for a JSON file that holds the details about the endpoint you’re configuring.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/image_155.png" alt="A newly created custom endpoint for a locally hosted model" class="wp-image-4186820" width="1006" height="569" sizes="auto, (max-width: 1006px) 100vw, 1006px"><figcaption class="wp-element-caption"><p>A newly created custom endpoint for a locally hosted model. The ID, name, and URL still need to be defined for this model to be useful.</p></figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>You’ll need to provide a few more details by typing them into the labeled fields:</p>



<ul class="wp-block-list">
<li><code>id</code>: A text field that uniquely identifies this particular entry. The choice of ID is pretty much arbitrary; if you’re using only a single model, the ID could be the model name.</li>



<li><code>name</code>: The name of the model that is used to identify it on the model server. In LM Studio, you can get this name by clicking on <code>My Models</code> in the main interface, then selecting the three-dot icon for the model in question and clicking <code>Copy Default Identifier</code>. For Qwen 2.5, for instance, <code>name</code> might be something like <code>qwen2.5-coder-7b-instruct</code>.</li>



<li><code>url</code>: The URL to the server’s endpoint. On LM Studio, this defaults to something like <code>http://127.0.0.1:1234/v1</code>. The <code>/v1</code> at the end is important because that endpoint is used for autodiscovery of models and their capabilities.</li>
</ul>



<p>The other fields generally don’t need editing. Most models have tool calling functionality. If you know for a fact that the model you’re using doesn’t have vision support, then set <code>vision</code> to <code>false</code>.</p>



<p>Once you have these fields filled in, you can close the modal editor to save the changes. If you reload the <code>Manage Language Models</code> page, you’ll now see your new endpoint:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/image_399.png" alt="A newly created local endpoint" class="wp-image-4186833" width="830" height="564" sizes="auto, (max-width: 830px) 100vw, 830px"><figcaption class="wp-element-caption"><p>A newly created local endpoint. The choice of name and group is arbitrary. “Custom Endpoint” is the default name for a newly created group of endpoints.</p></figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>You should now be able to launch the chat window and use the defined model for conversation and utilities:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/image_400.png?w=1024" alt="Conversing with the local model using VS Code's chat window" class="wp-image-4186837" width="1024" height="719" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Conversing with the local model using VS Code’s chat window. Note the selected code block in the left pane that is being used as the context for the conversation.</p></figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>One current, and major, limitation of Visual Studio Code’s BYOK functionality is that it only works for chat and utility tasks. It doesn’t allow you to use a local model for inline suggestions or code completions. The only way to <a href="https://www.infoworld.com/article/4144487/i-ran-qwen3-5-locally-instead-of-claude-code-heres-what-happened.html">take advantage of local models for expanded functionality with VS Code</a> is to use a third-party tool like <a href="https://marketplace.visualstudio.com/items?itemName=Continue.continue">Continue</a>.</p>



<p>It isn’t clear if Microsoft will eventually lift this restriction. GitHub Copilot integration in VS Code is a large part of how Copilot as a service reaches its target audience. For the time being, you can certainly use third-party and local models for a significant part of your AI-assisted development work in VS Code, and you can close the functionality gap with additional tooling. </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI-SPM buyer’s guide: 14 tools to secure your AI infrastructure]]></title>
<description><![CDATA[Widespread enterprise adoption of AI has created a pressing need for security solutions — a tall order given that AI’s reach into organizational infrastructure and data is enormous and continues to grow.



Moreover, where an organization sits on the AI maturity curve impacts its security needs. ...]]></description>
<link>https://tsecurity.de/de/3620469/it-security-nachrichten/ai-spm-buyers-guide-14-tools-to-secure-your-ai-infrastructure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620469/it-security-nachrichten/ai-spm-buyers-guide-14-tools-to-secure-your-ai-infrastructure/</guid>
<pubDate>Wed, 24 Jun 2026 09:09:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Widespread enterprise adoption of AI has created a pressing need for security solutions — a tall order given that AI’s reach into organizational infrastructure and data is enormous and continues to grow.</p>



<p>Moreover, where an organization sits on the AI maturity curve impacts its security needs. Trail of Bits CEO Dan Guide <a href="https://www.youtube.com/watch?v=kgwvAyF7qsA">describes the AI journey as a migration</a> from AI-assisted, where AI tools are used on existing workflows; through AI-augmented, which uses new workflows based on AI; to the AI-native organization, where AI “becomes a core participant in the delivery and operations of a business.”</p>



<p>Those three stages require very different approaches to securing AI. They also present challenges for AI security vendors, whose platforms must fit in multiple places in a corporate network and interact with a broad spectrum of applications — especially as agentic AI expands. As analyst <a href="https://www.linkedin.com/pulse/guide-ai-agent-governance-enterprise-david-linthicum-tkcve/">David Linthicum recently posted</a>, “the conversation now has to shift from model fascination to operational discipline. The question is how those agents should be governed once they begin touching workflows that affect customers, employees, suppliers, compliance, and revenue.” </p>



<p>Making matters worse is that the average enterprise manages 37 agents, with more than half running without security oversight or logging, according to <a href="https://www.microsoft.com/en-us/security/security-insider/emerging-trends/cyber-pulse-ai-security-report#Introduction">Microsoft’s 2026 Cyber Pulse report</a>, which also found that, while 80% of Fortune 500 companies use active AI agents, only 10% have a clear strategy for managing them.</p>



<p>That lack of strategy also opens the door for attackers to abuse corporate AI systems for malicious purposes, as the recent <a href="https://krebsonsecurity.com/2026/06/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts/">exploit of Meta’s account recovery using chatbots</a> demonstrated.</p>



<p>The trick to securing AI systems is in understanding how much protection is needed and where it should be applied in the expanding AI universe. While one could rent a well-meaning AI agent called <a href="https://agentalent.ai/agents/fa682e11-52a6-4dc9-9ae8-63816d876cc9">Sentry for $7,400 per month</a> to automate the daily work of a SOC analyst, many organizations rolling out AI across their business would be best served by considering AI security posture management (AI-SPM) tools.</p>



<p>Over the past two years, this emerging field has matured, with many security vendors incorporating or acquiring SPM features as part of their general security product portfolio.</p>



<p>Some vendors, such as SentinelOne and Concentric, don’t specifically sell AI-SPM per se, but offer an SPM tool that is part of a larger package of AI security services. Others offer AI-SPM in conjunction with their other SPM tools or <a href="https://www.csoonline.com/article/573629/cnapp-buyers-guide-top-tools-compared.html">CNAPP security offerings</a>. Some vendors, such as Cyera and Palo Alto, offer multiple AI-SPM packaging alternatives with differing feature sets.</p>



<p>Choosing the right product requires careful examination of the roster of features and integrations each product offers to ensure that it doesn’t duplicate existing security tooling or worse, leave important coverage gaps.</p>



<p>Here we take a deeper look at the AI-SPM product category, with a breakdown of offerings from 14 of the leading vendors in this increasingly important security ecosystem.</p>



<h2 class="wp-block-heading">AI security posture management explained</h2>



<p><a href="https://www.cio.com/article/2503234/how-guardrails-allow-enterprises-to-deploy-safe-effective-ai.html">AI security posture management</a> is an evolving cybersecurity discipline focused on ensuring the integrity and security of AI and machine learning systems. AI-SPM encompasses strategies, tools, and techniques for monitoring, assessing, and enhancing the security of AI models, data, pipelines, applications, and services, even as threats to those entities continually evolve.</p>



<p>In the past, security posture management tools were designed for two situations: to protect general cloud operations against misconfigurations and abuse, which is the province of <a href="https://www.csoonline.com/article/657138/how-to-choose-the-best-cloud-security-posture-management-tools.html">cloud security posture management</a> tools; and to protect against data leakage or malware infections, which is the province of <a href="https://www.csoonline.com/article/2075321/top-12-data-security-posture-management-tools.html">data security posture management</a> tools. With the rise of AI and large language models (LLMs), a third SPM product category is needed to check AI cloud services and their SDKs (like <a href="https://www.csoonline.com/article/4181094/hugging-face-transformers-rce-flaw-enables-stealthy-compromise-via-ai-model-configs.html">Hugging Face Transformers</a> or Azure Open AI SDK) to prevent model abuses. This is because numerous studies have documented how AI training data can be the subject of an attack or how bad data can be injected into models to manipulate results, including creating malicious backdoors for attackers to use to enter your enterprise.</p>



<p>The latest reports about attacks on AI and AI abuse can help you better understand the scope of security challenges rapidly evolving today. MITRE continues to enhance its comprehensive database of adversary tactics — <a href="https://atlas.mitre.org/">Adversarial Threat Landscape for Artificial-Intelligence Systems (ATLAS)</a> — based on real-world attack observations. ATLAS currently spans 170 techniques and 57 case studies. <a href="https://airisk.mit.edu/">MIT researchers also maintain a growing database of more than 1,700 AI-related risks</a> that they have observed from various AI sources. Another great source of AI-related attack methods is from the Open Worldwide Application Security Project (OWASP), which maintains a <a href="https://genai.owasp.org/resource/owasp-top-10-for-llm-applications-2025/">Top 10 list of LLM exploits.</a> Security managers should examine them before choosing any AI-SPM product. They should also consult Richard Stiennon’s <a href="http://guardiansofthemachineage.com/">Guardians of the Machine Age</a>, the most comprehensive collection of general security vendors, listing more than 100 AI security vendors. The printed book offers a deeper dive into the specifics of these tools.</p>



<p>The AI-SPM vendor landscape is quickly evolving, as incumbent security vendors have made numerous acquisitions. Palo Alto Networks bought Protect.ai last year; Cato Networks acquired Aim.security; Orca acquired Opus for AI agentic security; SentinelOne acquired Prompt.Security; Varonis acquired a variety of companies, including Cyral, SlashNext, and <a href="http://alltrue.ai/">AllTrue.ai</a>; and Google acquired Wiz.</p>



<h2 class="wp-block-heading">Why enterprises need AI-SPM</h2>



<p>AI-SPMs have been designed to protect enterprise networks and applications from a range of threats to AI systems. Just like no modern business would assemble a network without an appropriate firewall, AI-SPMs “ensure that AI models stay explainable, fair, accountable, transparent and equitable,” Forrester analyst Andras Cser tells CSO. “Further good security hygiene dictates that AI infrastructure should not be allowed to be used as a steppingstone for hackers for lateral movement and data exfiltration, and should include policies to prevent and fix configuration drift.”</p>



<p>AI-SPM can also help organizations standardize on a series of AI policies, procedures, tools, and workflows that can boost their security. Guido’s talk — linked above — is chock full of suggestions on how Trail of Bits accomplished this.</p>



<h2 class="wp-block-heading">Major AI-SPM trends and product features</h2>



<p>All AI-SPM vendors make use of agentless configurations, accessing cloud-based models and leaving data on their existing platforms. This is both a security measure and to avoid moving the massive data repositories involved across the internet.</p>



<p>AI-SPM vendors also make use of AI-related mechanisms to classify and track these vast data collections and to protect them against potential abuse and attack. Many have integrated their AI-SPM solutions in one of three directions:</p>



<ul class="wp-block-list">
<li>Bolting AI-SPM onto their existing cloud or data SPM platforms with rules, compliance checking, best practices, and protection policies that bridge all three types of security postures.</li>



<li>Stitching AI-SPM into their general AI security product that can be used to formulate AI-specific policies and perform AI-based red team and penetration testing in an effort to protect AI pipelines and workloads and uncover ways that shared AI services and platforms could be compromised.</li>



<li>Incorporating AI-SPM to help identify sensitive data referenced by an AI model and to examine training data exposed to a third-party or external application.</li>
</ul>



<p>Some vendors, especially established security vendors such as CrowdStrike, Proofpoint, Palo Alto, Varonis, and Wiz, have hundreds of third-party integrations that cover the AI waterfront (such as AI assistants and model suppliers) and general IT security arena (such as development pipelines, data feeds, and tools such as SOAR and SIEM). All three types of integrations can provide better guiderails and limit an AI’s blast radius.</p>



<p>But AI-SPM is still evolving. Some vendors’ tools just perform a top-level inspection of one or two services from each of the big three cloud platforms’ AI services (Amazon, for example, has dozens of AI-related service offerings), whereas others (such as Palo Alto Networks, Cato, Cyera, Varonis, and Wiz) take a deeper dive, performing a more comprehensive examination of AI data from the AI vendors themselves and other model sources.</p>



<p>There are two open source efforts as well: <a href="https://orca.security/resources/blog/orca-ai-goat-open-source-environment-owasp-risks/">Orca’s GOAT</a> is a free learning platform that is based on the OWASP top 10 risks. Palo Alto’s Protect.ai has its collection of <a href="https://github.com/protectai">open-source tools on GitHub</a> for scanning models and discovering AI interactions and automated red teaming called ProtectAI OSS. However, neither of these projects has been recently updated.</p>



<h2 class="wp-block-heading">How to choose an AI-SPM tool</h2>



<p>Here are several considerations when deciding on the best AI-SPM tool for your enterprise: </p>



<ol class="wp-block-list">
<li><strong>Does the vendor work with your existing security tool collection?</strong> This has two dimensions: integrating with other SPM products (such as data or cloud protection), and integrating with third-party tools such as SOARs, SIEMs, or DLP products. We have included some vendors that don’t have a specific AI-related SPM (such as Concentric and CrowdStrike) but have deeply embedded AI protection into their platforms.</li>



<li><strong>How deep is the coverage across the cloud platform providers?</strong> The big three (AWS, Azure, and GCP) have many services that touch various aspects of AI, and some products only work with a few of them, or only connect with PaaS security “hubs.”</li>



<li><strong>Does the vendor continuously scan your infrastructure looking for vulnerabilities?</strong> AI can be quickly adopted and is very dynamic, so discrete scans are less useful.</li>



<li><strong>How important is having a tool that can help with <a href="https://url.usb.m.mimecastprotect.com/s/9zsRCB1MnMHEEY8nHNiwc2W8AV?domain=csoonline.com">AI red teaming</a>?</strong> Understanding the dynamic nature of how AI operates means having a different approach to penetration testing, and this can be a very useful feature. Only a few vendors offer this feature (such as Concentric, Palo Alto Networks, and Varonis).</li>
</ol>



<h2 class="wp-block-heading">Leading AI-SPM vendors and products</h2>



<p>We reached out to a range of leading AI-SPM security vendors to demonstrate their AI-related tools. Below are more details about each of the 14 we had the opportunity to preview. We have also summarized each vendor’s offerings in the features table, which also provides links, when available, to pricing and third-party integration details. Several vendors didn’t respond to our inquiries, including Baffle.io, Invicti, SecurityCompass, Tonic Security, and Zscaler.</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td><strong>Vendor</strong></td><td><strong>Product/URL</strong></td><td><strong>Entry-level pricing</strong></td><td><strong>Packaging</strong></td><td><strong>Integrations link</strong></td><td><strong>App runtime security</strong></td><td><strong>Continuous scanning?</strong></td><td><strong>MCP/Agent protection?</strong></td><td><strong>AI Red Teaming?</strong></td></tr><tr><td>Arthur.ai</td><td><a href="https://www.arthur.ai/platform">Arthur Platform</a></td><td><a href="https://www.arthur.ai/pricing">Free and paid versions</a></td><td>Single product</td><td><a href="https://www.arthur.ai/any-ai-any-use-case">Deep PaaS coverage</a></td><td>Yes</td><td>Yes</td><td>Yes</td><td>No</td></tr><tr><td>Cato Networks</td><td><a href="https://www.catonetworks.com/platform/ai-security-for-end-users/">AI Security for End Users</a></td><td></td><td>SASE platform</td><td><a href="https://support.catonetworks.com/hc/en-us/articles/13975273800733-Cato-Data-Third-Party-Supported-Integrations">Numerous</a></td><td>Yes</td><td>Yes</td><td>Yes</td><td>No</td></tr><tr><td>Concentric</td><td>No specific AI-SPM product</td><td><a href="https://aws.amazon.com/marketplace/pp/prodview-nxjxmrwq7bkea?nc2=type_a_top_search">AWS $50,000/yr, varies</a></td><td><a href="https://concentric.ai/product-overview/">Part of its DSPM platform</a></td><td><a href="https://concentric.ai/integrations/">Numerous</a></td><td>No</td><td>Yes</td><td>No</td><td>Yes</td></tr><tr><td>CrowdStrike</td><td>No specific AI-SPM product</td><td></td><td><a href="https://www.crowdstrike.com/en-us/platform/cloud-security/ai-spm/">Part of Falcon AI platform</a></td><td><a href="https://marketplace.crowdstrike.com/">Numerous</a></td><td>Yes</td><td>Yes</td><td>Yes</td><td><a href="https://www.crowdstrike.com/en-us/press-releases/crowdstrike-launches-ai-red-team-services-secure-ai-systems/">Separate service</a></td></tr><tr><td>Cyera</td><td><a href="https://www.cyera.com/platform/ai-guardian">AI Guardian</a></td><td><a href="https://aws.amazon.com/marketplace/pp/prodview-mc6f4tbu6otj4?sr=0-1&amp;ref_=beagle&amp;applicationId=AWSMPContessa">AWS $50,000/yr</a></td><td>Sold in two bundles, see description</td><td><a href="https://www.cyera.com/integrations">Numerous</a></td><td>Yes</td><td>Yes</td><td>Yes</td><td>No</td></tr><tr><td>Guardrail Technologies</td><td><a href="https://guardrail.tech/ai-traffic-light/">Traffic Light for Code and AI</a></td><td><a href="https://guardrail.tech/pricing/">Free and monthly plans</a></td><td>Also sell AI Command Center</td><td>Some</td><td>Yes</td><td>Yes</td><td>No</td><td>No</td></tr><tr><td>Microsoft</td><td><a href="https://www.microsoft.com/en-us/security/business/microsoft-purview">Purview</a></td><td>$12.60/user/mo</td><td>Part of larger CSPM platform</td><td>Some</td><td>Yes</td><td>No</td><td>Yes</td><td>No</td></tr><tr><td>OneTrust</td><td><a href="https://www.onetrust.com/solutions/ai-governance/">AI Governance</a></td><td>Subscriptions</td><td>Single product with SPM features</td><td>Some</td><td>Yes</td><td>Yes</td><td>No</td><td>No</td></tr><tr><td>Orca Security</td><td><a href="https://orca.security/platform/ai-security-posture-management/">AI-SPM</a></td><td><a href="https://aws.amazon.com/marketplace/pp/prodview-rogbt2k4b63xc?sr=0-1&amp;ref_=beagle&amp;applicationId=AWSMPContessa">AWS $84,000/yr</a></td><td>Has other AI security tools</td><td><a href="https://orca.security/integrations/">Numerous</a></td><td>Yes</td><td>Yes</td><td>Yes</td><td>No</td></tr><tr><td>Palo Alto Networks</td><td><a href="https://www.paloaltonetworks.com/prisma/prisma-ai-runtime-security">Prisma AI Security</a></td><td></td><td>Sold in two bundles, see description</td><td><a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/administration/configure-external-integrations-on-prisma-cloud/integrations-feature-support">Numerous</a></td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td></tr><tr><td>Proofpoint</td><td><a href="https://www.proofpoint.com/us/products/ai-access-security">AI Access Security</a></td><td><a href="https://aws.amazon.com/marketplace/pp/prodview-dcj7rctb55qie?sr=0-1&amp;ref_=beagle&amp;applicationId=AWSMPContessa">AWS $96,000/yr</a></td><td>People Protection Platform</td><td>Numerous</td><td>Yes</td><td>Yes</td><td>Yes</td><td>No</td></tr><tr><td>SentinelOne</td><td>No specific AI SPM product</td><td><a href="https://www.sentinelone.com/platform-packages/">$80/yr/endpoint</a></td><td><a href="https://www.sentinelone.com/platform/securing-ai/">Part of larger Singularity platform</a></td><td><a href="https://www.sentinelone.com/partners/singularity-marketplace/">Numerous</a></td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td></tr><tr><td>Varonis</td><td><a href="https://www.varonis.com/platform/ai-security">Atlas</a></td><td><a href="https://aws.amazon.com/marketplace/pp/prodview-eoyer6g2olf6k?sr=0-3&amp;ref_=beagle&amp;applicationId=AWSMPContessa">AWS $108,000/yr</a></td><td>Bundled with AI Inventory</td><td><a href="https://varonis.com/coverage">Hundreds</a></td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td></tr><tr><td>Wiz/Google</td><td><a href="https://www.wiz.io/blog/introducing-wiz-ai-app">AI App Protection Platform</a></td><td><a href="https://aws.amazon.com/marketplace/pp/prodview-ibgbkrqusncsm?sr=0-1&amp;ref_=beagle&amp;applicationId=AWSMPContessa">AWS $38,000/yr</a></td><td>Variety of bundles available</td><td>Numerous</td><td>Yes</td><td>Yes</td><td>Yes</td><td>No</td></tr></tbody></table> </div></figure>



<h3 class="wp-block-heading">Arthur.ai</h3>



<p><a href="https://url.usb.m.mimecastprotect.com/s/FchtCzq8n8HJJ54rf4fVc9Ae_i?domain=arthur.ai/">Arthur.ai’s</a> platform is a single product that offers deep PaaS coverage with both AWS and Google Cloud Platform, although unlike other AI-SPMs it doesn’t offer a wide range of third-party integrations. It includes application runtime security protection. It also scans network traffic continuously and watches for agent activity, along with policy guardrails to protect against prompt injection and sensitive data leakage. It includes behavioral analytics and governance that catch abusive agentic activities. There are <a href="https://url.usb.m.mimecastprotect.com/s/yx7UCA8LmLh77kERH8hOcGedvn?domain=arthur.ai">free and paid versions</a> starting at $10,000 annual plans for smaller networks.</p>



<h3 class="wp-block-heading">Cato Networks AI Security for End Users</h3>



<p><a href="https://www.catonetworks.com/platform/ai-security-for-end-users/">Cato Networks AI Security for End Users</a> is one of three separate AI security packages that work together with Cato’s SASE platform, the other two being protection for applications (both runtime and across the software development lifecycle) and for real-time agentic operations. The three AI packages are meant to be purchased together to provide audit trails showing what users are doing with their AI tools and to help understand and illustrate the risks. Cato’s tools can also prevent prompt injection and data leaks and find compliance blind spots. Its platform has a <a href="https://support.catonetworks.com/hc/en-us/articles/13975273800733-Cato-Data-Third-Party-Supported-Integrations">wide collection of third-party integrations</a>, including CrowdStrike, Microsoft, and Splunk SIEMs, and various data sources such as Google’s Chronicle and Rapid7. Cato Networks did not reveal pricing.</p>



<h3 class="wp-block-heading">Concentric AI and Data Security Governance</h3>



<p>Concentric sells a <a href="https://concentric.ai/product-overview/">DSPM platform</a> labelled “AI and Data Security Governance.” There is no specific AI tool, although AI pervades its product in a variety of places, including scanning various models for prompt injection, automated remediation, and the discovery and classification of data flows. It offers a <a href="https://concentric.ai/integrations/">wide collection of third-party integrations.</a> On the <a href="https://aws.amazon.com/marketplace/pp/prodview-nxjxmrwq7bkea?nc2=type_a_top_search">AWS Marketplace</a>, it sells an entry-level version for $50,000 per year that covers up to 25TB of data, with higher fees for larger data collections.</p>



<h3 class="wp-block-heading">CrowdStrike Falcon AI-SPM</h3>



<p><a href="https://www.crowdstrike.com/en-us/platform/cloud-security/ai-spm/">CrowdStrike Falcon AI-SPM</a> is not a separate product, but part of the overall Falcon Cloud security platform. It can correlate risk findings with other security services monitored by the full Falcon platform. It includes discovery of AI services and models across a variety of cloud platforms, including containers and virtual images, and can detect misconfigurations and dependencies with other software. It scans OpenAI, Amazon Bedrock, Amazon SageMaker, and Vertex AI models. <a href="https://marketplace.crowdstrike.com/">Falcon has more than 250 integrations</a> available to a wide collection of third-party security tools. You can request a free 15-day trial, but no further pricing information was disclosed.</p>



<h3 class="wp-block-heading">Cyera AI Guardian</h3>



<p>Cyera.io specializes in data file level classification. It packages its AI-SPM product in two separate bundles: either with its flagship <a href="https://www.cyera.io/platform/dspm">DSPM product</a> that has added what you might think of as AI-enriched data link protection as part of the default product’s features, or with a more complete set of security features called <a href="https://www.cyera.com/platform/ai-guardian">AI Guardian</a>. Cyera also offers a specialized add-on module used for Microsoft Copilot data scanning that can detect data used by insiders, for example. <a href="https://aws.amazon.com/marketplace/pp/prodview-mc6f4tbu6otj4?sr=0-1&amp;ref_=beagle&amp;applicationId=AWSMPContessa%20%5D">Cyera’s AWS Marketplace pricing can be found here</a> and starts at $50,000 per year. </p>



<h3 class="wp-block-heading">Guardrail Technologies Traffic Light for Code and AI</h3>



<p><a href="https://guardrail.tech/ai-traffic-light/">Guardrail Technologies Traffic Light for Code and AI</a> is designed to be a simple way to flag potential AI abuse by scanning AI-generated code and returning a red/yellow/green result to indicate potential for compromise. There is no remediation, but the tool integrates across the major AI vendors, including Anthropic, Azure Open AI, Hugging Face, and AWS Bedrock, and general security tools such as Wiz and Snyk. Guardrail has a custom AI security consulting business as well called AI Guardian. Very transparent pricing page and a 60-day free trial is available.</p>



<h3 class="wp-block-heading">Microsoft Purview</h3>



<p>Microsoft has bundled its various security posture tools into its <a href="https://www.microsoft.com/en-us/security/business/microsoft-purview">Purview offering</a>, which includes a series of AI-based Copilot apps, data SPM and classification tools, and data loss prevention extensions tuned to its various SaaS platforms such as 365, Azure, and Windows endpoints. This extends the AI security features that were originally part of its Defender for Cloud offerings. It has a limited number of third-party integrations. One-month free trials are available, and the entire suite is available for $12.60 per month per user. Microsoft has stepped up its involvement with AI with its Scout, a collection of autonomous AI agents built on top of OpenClaw. It is designed to work with its applications, using built-in security and privacy controls.</p>



<h3 class="wp-block-heading">OneTrust AI Governance</h3>



<p><a href="https://www.onetrust.com/solutions/ai-governance/">OneTrust offers AI Governance</a>, a platform that automates compliance and provides continuous monitoring of the AI landscape, across the software lifecycle starting with any AI usage at the beginning of any build. It can detect policy violations, and which AI agents are running. It offers a series of third-party integrations such as Amazon’s Bedrock and Sagemaker; Azure Foundry, ML Studio, and OpenAI; Databricks Unity Catalog and ML flow; and Google Vertex. Its subscription price is based on the number of admin users and number of AI inventory records, although no specifics were provided.</p>



<h3 class="wp-block-heading">Orca AI-SPM</h3>



<p><a href="https://orca.security/platform/ai-security/ai-spm/">Orca Security’s AI-SPM </a>is tightly integrated into the company’s security platform. It continues to expand its features, offering detections of more than 50 AI models, including training data and runtime threats, remediation, and support for Model Context Protocol to connect to other Orca-based telemetry. It <a href="https://orca.security/integrations/">continues to expand its nearly 100 integrations</a> across SIEM and SOAR systems and various cloud providers’ services. For example, it works with AWS S3, SQS, SNS, CodeBuild, CloudTrail, and Security Hub. It comes with dozens of best-practice security rules that initially focused on compliance. It also alerts when sensitive data is detected inside models and when secrets are exposed. Orca’s overall security platform shows an <a href="https://aws.amazon.com/marketplace/pp/prodview-rogbt2k4b63xc?sr=0-1&amp;ref_=beagle&amp;applicationId=AWSMPContessa">AWS Marketplace annual pricing that ranges from $84,000 to $360,000</a>, depending on the number of workloads scanned.</p>



<h3 class="wp-block-heading">Palo Alto Networks AIRS AI Security</h3>



<p>Palo Alto Networks has been busy acquiring point security vendors (Dig, ProtectAI, and an offer on Portkey) and incorporating their code into its two major product lines, Prisma and Cortex. You can purchase AI-SPM functionality in either Palo Alto product line, but they cover different aspects of the AI ecosystem. Cortex offers AI-SPM alongside the data and cloud SPMs integrated into the CNAPP suite. Prisma offers AI-SPM as part of a total AI security package called <a href="https://www.paloaltonetworks.com/prisma/prisma-ai-runtime-security">AIRS AI Security</a>, which includes runtime protection, model scanning, and a more comprehensive platform. We focus on AIRS AI, which supports top-level scans of Amazon, Google Cloud, and Azure AI services to discover AI content and can classify and examine model data and secrets and comes with many built-in AI-related policies. Prisma has a <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/administration/configure-external-integrations-on-prisma-cloud/integrations-feature-support">long list of third-party integrations</a>, including significant depth in AWS security services. That link will also take you to detailed instructions on how to set up these integrations. To complicate matters further, Palo Alto also sells a <a href="https://www.paloaltonetworks.com/sase/prisma-browser">separate Prisma secure browser extension</a> that works with these products to protect your endpoints, and that originated from technology it purchased from Talon Cyber Security in 2023. While pricing was not disclosed, our estimate is that AIRS will cost in the low six figures annually.</p>



<h3 class="wp-block-heading">Proofpoint People Protection Platform</h3>



<p>Proofpoint includes a <a href="https://www.proofpoint.com/us/products/ai-access-security">general AI security product</a> as part of its People Protection Platform that covers a wide range of protective services integrated across its other non-AI security tools. It provides runtime inspection of potential AI misconfigurations, as well as policies that include detection of agent, tools, and MCP connections, and it can generate forensic audits of AI interactions. Proofpoint’s general security platform starts at <a href="https://aws.amazon.com/marketplace/pp/prodview-dcj7rctb55qie?sr=0-1&amp;ref_=beagle&amp;applicationId=AWSMPContessa">$96,000 annually on AWS Marketplace</a>. It has several integrations with third-party services across the major cloud platform providers.</p>



<h3 class="wp-block-heading">SentinelOne Singularity Platform</h3>



<p><a href="https://www.sentinelone.com/platform/securing-ai/">SentinelOne’s Singularity platform</a> offers several AI protective features, including misconfiguration detection, attack path analysis, automated AI inventory and remediation, and integration with a variety of AI PaaS platforms such as Azure OpenAI, Google’s Vertex AI, and various AWS services. It is bundled within the company’s Cloud Native Security tool. Some of these features originated with Singularity’s purchase of Prompt.Security. Access to all the features requires purchasing the enterprise edition, which is offered with custom pricing, but lower feature tiers are available for $80 per year on <a href="https://www.sentinelone.com/platform-packages/">this public pricing page</a>. There are also <a href="https://www.sentinelone.com/partners/singularity-marketplace/">numerous integrations with its Marketplace</a>.</p>



<h3 class="wp-block-heading">Varonis Atlas AI Security</h3>



<p><a href="https://www.varonis.com/solutions/ai-security">Varonis Atlas AI Security</a> is a multipurpose security platform that offers a variety of modules, including red team/penetration testing, compliance, and third-party risk management. Its AI-SPM module is combined with an AI inventory scanner and can be used to help development teams classify data used in the AI ecosystem, such as scanning for bad AI behavior, leveraging identities improperly, and examining data flows. Automated remediation processes are built into the tool as well. There are several <a href="https://www.varonis.com/coverage">hundred third-party integrations available</a> for a wide collection of security tools, such as JFrog, Jira, Okta, and Salesforce. Varonis has two pricing components; one based on per user and per protected application and an additional price for resource consumption. Atlas is sold on the <a href="https://aws.amazon.com/marketplace/pp/prodview-ibgbkrqusncsm?sr=0-1&amp;ref_=beagle&amp;applicationId=AWSMPContessa">AWS Marketplace starting at $108,000 per year</a> and free risk assessments are available to qualified customers.</p>



<h3 class="wp-block-heading">Wiz/Google AI Application Protection Platform</h3>



<p>Google has acquired Wiz but kept its operation independent. It has a <a href="https://www.wiz.io/solutions/ai-spm">multipurpose security platform</a> that comes from a strong posture management (cloud and data) background. Its advanced version has been augmented with a comprehensive AI-related series of policies, detection algorithms, and pipeline, model, and data scanners. These are assembled into a separate AI dashboard page. It can also detect AI pipeline abuses, protect AI runtimes, identify and classify tools and agents, map dependencies graphically and suggest remediation steps. It also contains core AI-SPM features such as discovery, attack path analysis, and supply chains. Pricing for the Wiz Advanced bundle on <a href="https://aws.amazon.com/marketplace/pp/prodview-ibgbkrqusncsm?sr=0-1&amp;ref_=beagle&amp;applicationId=AWSMPContessa">AWS Marketplace is $38,000 annually</a>.</p>



<h2 class="wp-block-heading">What about AI-SPM pricing?</h2>



<p>Pricing and packaging of AI-SPM tools vary widely. Many vendors offer free trials limited to differing periods (an option that is also available on the AWS Marketplace). We pointed out the open-source alternatives earlier, which is also a good way to see how the products work, but we wouldn’t recommend relying on these tools given their lack of recent updates. The only vendors that have (mostly) transparent pricing are Guardrail Technologies (with both free and monthly plans) and SentinelOne (with various annual plans starting at $80 per endpoint). Most of the vendors didn’t want to provide pricing directly but have published pricing on the AWS Marketplace, which can give you a rough indication that most start in the low six figures for annual contracts. For a typical situation with 1,000 users the total could be in the low six-figure range annually.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[I asked ChatGPT, Gemini and Claude what discount tech to buy on Amazon Prime Day — here’s which AI gave the best advice]]></title>
<description><![CDATA[Choosing a bargain on Amazon Prime Day is a good test of how well your AI knows you.]]></description>
<link>https://tsecurity.de/de/3618820/it-nachrichten/i-asked-chatgpt-gemini-and-claude-what-discount-tech-to-buy-on-amazon-prime-day-heres-which-ai-gave-the-best-advice/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3618820/it-nachrichten/i-asked-chatgpt-gemini-and-claude-what-discount-tech-to-buy-on-amazon-prime-day-heres-which-ai-gave-the-best-advice/</guid>
<pubDate>Tue, 23 Jun 2026 17:47:22 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Choosing a bargain on Amazon Prime Day is a good test of how well your AI knows you.]]></content:encoded>
</item>
<item>
<title><![CDATA[Rewire or rebuild? The AI decision every CIO needs to get right]]></title>
<description><![CDATA[The question every board, CEO and CIO must answer in 2026 isn’t whether to use AI. It’s whether to use AI to improve what you have, or to start again. Most organizations are getting this choice wrong, defaulting to whichever option matches their risk appetite, rather than applying clear strategic...]]></description>
<link>https://tsecurity.de/de/3618325/it-nachrichten/rewire-or-rebuild-the-ai-decision-every-cio-needs-to-get-right/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3618325/it-nachrichten/rewire-or-rebuild-the-ai-decision-every-cio-needs-to-get-right/</guid>
<pubDate>Tue, 23 Jun 2026 15:03:08 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The question every board, CEO and CIO must answer in 2026 isn’t whether to use AI. It’s whether to use AI to improve what you have, or to start again. Most organizations are getting this choice wrong, defaulting to whichever option matches their risk appetite, rather than applying clear strategic criteria.</p>



<p>Rewiring treats existing processes, teams and systems as the frame, using AI as the wiring that makes them faster and smarter. The enterprise stays recognisable. Org charts shift modestly. Underneath, AI accelerates throughput and cuts manual effort e.g. AI co-pilots in legal review, ML-driven demand forecasting, generative AI auto-resolving Tier 1 support tickets.</p>



<p>Rebuilding treats the current operating model as legacy and uses AI as the architectural foundation for something structurally different. Entire functions may disappear or be reborn. Processes are redesigned from first principles with AI at the core, not bolted on. Think: a digital-only insurance carrier built around AI underwriting by default, not as an add-on.</p>



<p>Neither is universally correct. The organizations winning this decade are applying disciplined criteria and increasingly, sequencing both.</p>



<h2 class="wp-block-heading">The decision framework</h2>



<p>Five questions determine the right path, and they need to be asked together, not in isolation.</p>



<p>Is the operating model the constraint, or is execution? If processes are sound but slow and error-prone: rewire, AI removes friction without touching the underlying logic. If the architecture itself is fragmented and siloed by design, rebuild. AI plugged into a broken process just produces faster, better-documented brokenness.</p>



<p>How much runway do you have? Rewiring delivers ROI in 3–12 months. Rebuilding takes 18–48 months before material value shows up. If competitive pressure demands proof of AI value within a year, rewire first. If an AI-native competitor has already entered your market with a structurally lower cost base, incremental improvement won’t close that gap, only rebuilding will.</p>



<p>Can your people absorb the change? A workforce that’s risk-averse or change-fatigued can adopt AI-in-place without existential threat to most roles. A rebuild without genuine leadership mandate and a credible workforce transition plan isn’t transformation, it’s poorly managed redundancy with better PR.</p>



<p>How bad is the technology debt, really? Most AI use cases can be delivered via APIs and abstraction layers without core system replacement. Rebuild only when the estate is so fragmented that a unified data layer or real-time decisioning is structurally impossible otherwise.</p>



<p>Does the prize justify the disruption? Bounded efficiency gains of 10–25% rarely justify a rebuild’s cost and risk. Step-changes in unit economics or customer proposition do.</p>



<h2 class="wp-block-heading">Who should decide</h2>



<p>This is a capital allocation and talent strategy decision with technology implications, not a technology decision. The most common governance failure is letting the CIO or a transformation consultancy own it unilaterally.</p>



<p>The decision table needs the CEO, who owns the risk-return trade-off and the mandate to change; the CFO, who must model the economics of both paths honestly, including the productivity dip during transition, not just peak-state ROI; the CHRO, who needs a credible transition strategy in place before the decision is taken, not after; the CIO, who assesses technical feasibility but shouldn’t be making the strategic call alone; and business unit leaders, whose operational insight and buy-in are non-negotiable. An AI-literate independent board voice helps prevent both excessive caution and hype-driven overreach.</p>



<h2 class="wp-block-heading">Costs, benefits and where maximum value sits</h2>



<p>Rewiring’s ceiling is real, gains are bounded by the existing model, and it risks “AI-washing”: surface deployment without structural impact. But it’s fast, lower risk, preserves institutional knowledge and compounds across multiple waves over several years.</p>



<p>Rebuilding can deliver 30–60% structural cost reduction and capabilities simply unavailable to a rewired legacy model, but it carries a real failure rate (high for large transformations), heavy upfront investment and a multi-year J-curve before returns appear.</p>



<p>Maximum value rarely comes from choosing one exclusively. It comes from sequencing: rewire to generate cash, capability and credibility, then rebuild the two or three domains where AI-native architecture creates a genuine moat, while continuing to rewire everything else.</p>



<h2 class="wp-block-heading">Case in point: An Australian tourism and cruise operator</h2>



<p>Consider one of Australia’s largest integrated tourism and cruise businesses, simultaneously a B2C retailer, a B2B distributor to thousands of agency and wholesale clients globally, an aggregator marketplace for 1,800-plus independent tourism operators, and a cruise operator with offshore shared services spanning finance, customer contact and content management.</p>



<p>By 2024, the pressures had converged: AI-native travel platforms eroding acquisition economics, independent operators demanding dynamic pricing the platform couldn’t offer, and offshore cost structures under threat from automation. Leadership’s assessment found a split picture. The B2C and shared-services functions were sound but manual, a rewiring opportunity. The aggregator marketplace’s static catalogue and rules-based search were the actual constraint, no amount of AI on top would fix that. It needed rebuilding.</p>



<p>Rather than choose one path, the executive team sequenced three horizons. Horizon 1 rewired customer contact (AI triage cut Tier 1 escalations by 34%), content management (AI drafting cut operator listing time by 70%, eliminating a 23-day onboarding backlog), finance operations, B2C personalization (higher email revenue) and cruise crew scheduling (15% lower overtime). Within 18 months this delivered a million in annualised savings, funding and validating the next move.</p>



<p>Horizon 2 rebuilt the marketplace itself: AI-native semantic search lifted booking conversion by 24%; opt-in dynamic pricing lifted operator revenue per booking 16% for the first cohort; automated onboarding cut new-operator time-to-live from 23 days to three.</p>



<p>Critically, the offshore teams whose roles were most exposed to automation weren’t reduced, they were redeployed into quality assurance and operator onboarding, work that leveraged the institutional knowledge AI couldn’t replicate. Zero redundancies came out of Horizon 1. That decision wasn’t only ethical; the content quality gains from experienced specialists focusing on QA rather than production were measurable.</p>



<p>The lesson generalises well beyond travel: rewiring generated the cash, capability and credibility that made rebuilding possible. Neither path alone would have delivered the same outcome, and the sequencing mattered as much as the technology choices themselves.</p>



<h2 class="wp-block-heading">What this means for CIOs</h2>



<p>Start with rewiring, generate tangible ROI within 12 months and use it to build capability and board trust. Watch for your structural ceiling: the point where further rewiring yields diminishing returns because the model itself is the constraint. That’s your signal to rebuild selectively. Don’t rebuild everything; identify the two or three domains where AI-native architecture creates real competitive advantage and rewire the rest. And treat workforce transition as a strategic priority from day one, not an HR afterthought bolted on after the technology decisions are made.</p>



<p>The rewire-or-rebuild question isn’t a technology question. It’s a question about what kind of enterprise you’re choosing to become. The CIOs who get this right won’t be the ones who pick a side, they’ll be the ones who know exactly when to switch.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Der Amazon Prime Day ist gestartet – diese Tagesangebote lohnen sich]]></title>
<description><![CDATA[Seit heute Mitternacht läuft bei Amazon der Amazon Prime Day 2026. Prime-Mitglieder haben jetzt vier Tage lang Zeit, von Bestpreisen für bekannte Markenprodukte zu profitieren. Der Prime Day endet am Freitag, den 26. Juni.



Die besten Tagesangebote am Amazon Prime Day



Rabatte gelten ausschli...]]></description>
<link>https://tsecurity.de/de/3617348/it-nachrichten/der-amazon-prime-day-ist-gestartet-diese-tagesangebote-lohnen-sich/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617348/it-nachrichten/der-amazon-prime-day-ist-gestartet-diese-tagesangebote-lohnen-sich/</guid>
<pubDate>Tue, 23 Jun 2026 08:32:58 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Seit heute Mitternacht läuft bei Amazon der <strong>Amazon Prime Day 2026</strong>. Prime-Mitglieder haben jetzt vier Tage lang Zeit, von Bestpreisen für bekannte Markenprodukte zu profitieren. Der Prime Day endet am <strong>Freitag, den 26. Juni.</strong></p>



<p><a href="https://www.amazon.de/primeday?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Die besten Tagesangebote am Amazon Prime Day</a></p>



<h2 class="wp-block-heading">Rabatte gelten ausschließlich für Prime-Mitglieder</h2>



<p>Nur wer eine Amazon-Prime-Mitgliedschaft hat, kann auf die Tiefstpreise am Prime Day zugreifen. Aktuell kostet eine Prime-Mitgliedschaft <strong>8,99 Euro pro Monat</strong>. Man kann die Kosten aber umgehen, indem man einen <strong>Gratis-Probemonat</strong> abschließt und dann rechtzeitig wieder kündigt: <a href="https://www.amazon.de/gp/prime?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Prime-Abo jetzt kostenlos testen</a>.</p>



<h2 class="wp-block-heading">Die besten Angebote am 23. Juni</h2>



<p>Unsere Redaktion empfielt täglich die besten Deals aus den Bereichen Computer, IT, Smartphones, Smart Home und Digital Lifestyle. Am ersten Prime-Day-Tag gibt es Jahresbestpreise für viele Apple-Produkte wie dem Macbook Neo oder dem iPad Air. </p>



<p>Amazon-eigene Geräte wie der smarte Echo-Lautsprecher oder der Fire TV-Stick sind heute <strong>bis zu 65 Prozent günstiger</strong>. Außerdem sind Laptops, Tablets und Zubehör im Angebot. Bei folgenden Angeboten sollten Sie schnell sein, bevor sie vergriffen sind:</p>


<h2>📺 TVs, Streaming &amp; Heimkino</h2>
<ul>
<li><a href="https://www.amazon.de/dp/B0CZS4X2S8?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Samsung Crystal UHD 4K TV 98 Zoll</a> für 1.279 Euro</li>
<li><a href="https://www.amazon.de/dp/B0F2JBN3QH?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">LG OLED TV 65 Zoll</a> für 1.424 Euro</li>
<li><a href="https://www.amazon.de/dp/B0F457MQCQ?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Xiaomi TV 65 Zoll</a> für 369 Euro</li>
<li><a href="https://www.amazon.de/dp/B0F5BR3WSK?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Samsung Crystal TV 4K 43 Zoll</a> für 245 Euro</li>
<li><a href="https://www.amazon.de/dp/B0F457M449?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Xiaomi TV F Pro 32 Zoll</a> für 149 Euro</li>
<li><a href="https://www.amazon.de/dp/B07XTX5YBD?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Epson 4K-PRO-UHD-Projektor</a> für 1.180 Euro</li>
<li><a href="https://www.amazon.de/dp/B0D22SVP73?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Hisense 3.1 Kanal Soundbar</a> für 114 Euro</li>
<li><a href="https://www.amazon.de/dp/B09BZWZS6S?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Amazon Fire TV Cube</a> für 109,99 Euro</li>
<li><a href="https://www.amazon.de/dp/B0CW4HD359?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Amazon Fire TV Stick 4K Max</a> für 46,99 Euro</li>
<li><a href="https://www.amazon.de/dp/B0DJGCX6Q2?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Amazon Fire TV Stick HD</a> für 19,99 Euro</li>
</ul>
<h2>💻 Laptops, Tablets &amp; Computer</h2>
<h3>Laptops</h3>
<ul>
<li><a href="https://www.amazon.de/dp/B0DVZQ8TJV?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">HP Omen MAX Gaming Laptop</a> für 2.599 Euro</li>
<li><a href="https://www.amazon.de/dp/B0FFMJ72C3?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">ASUS Vivobook 17 Laptop</a> für 549 Euro</li>
<li><a href="https://www.amazon.de/dp/B0F29HYVJZ?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">ASUS Vivobook 16 Laptop</a> für 449 Euro</li>
<li><a href="https://www.amazon.de/dp/B0DSGB8C6M?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Lenovo IdeaPad Slim 3 Laptop</a> für 480 Euro</li>
<li><a href="https://www.amazon.de/dp/B0F9LFB3HM?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">HP Laptop 17,3 Zoll</a> für 329 Euro</li>
<li><a href="https://www.amazon.de/dp/B0GS5S368L?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Apple 13 Zoll MacBook Neo</a> für 739 Euro</li>
</ul>
<h3>Tablets &amp; Zubehör</h3>
<ul>
<li><a href="https://www.amazon.de/dp/B0DZ76WSYH?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Apple iPad Air 13 Zoll mit M3 Chip</a> für 899 Euro</li>
<li><a href="https://www.amazon.de/dp/B0DZ778WX5?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Apple iPad Air 11 Zoll mit M3 Chip</a> für 719 Euro</li>
<li><a href="https://www.amazon.de/dp/B0D3J7CKFR?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Apple Pencil Pro</a> für 109 Euro</li>
<li><a href="https://www.amazon.de/dp/B0797FYB3K?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Logitech Advanced Kombi Tastatur</a> für 34 Euro</li>
</ul>
<h3>Monitore &amp; Displays</h3>
<ul>
<li><a href="https://www.amazon.de/dp/B0DCGCWZZF?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Samsung 49 Zoll OLED Gaming Monitor</a> für 799,99 Euro</li>
<li><a href="https://www.amazon.de/dp/B0F29RH4RY?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Dell 27 Plus Monitor</a> für 273 Euro</li>
<li><a href="https://www.amazon.de/dp/B0F8DWCKQL?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Lenovo 27 Zoll QHD WLED Monitor</a> für 119 Euro</li>
<li><a href="https://www.amazon.de/dp/B0DZD8Y997?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Apple Studio Display</a> für 1.199 Euro</li>
</ul>
<h3>Alles von Apple</h3>
<ul>
<li><a href="https://www.amazon.de/dp/B0DL6LHYQM?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Apple Magic Keyboard</a> für 139 Euro</li>
<li><a href="https://www.amazon.de/dp/B0DL6W3MQX?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Apple Magic Trackpad</a> für 125 Euro</li>
<li><a href="https://www.amazon.de/dp/B0DL6KSW78?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Apple Magic Mouse</a> für 59,99 Euro</li>
<li><a href="https://www.amazon.de/dp/B0DZ76WSYH?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Apple iPad Air 13 Zoll mit M3 Chip</a> für 899 Euro</li>
<li><a href="https://www.amazon.de/dp/B0DZ778WX5?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Apple iPad Air 11 Zoll mit M3 Chip</a> für 719 Euro</li>
<li><a href="https://www.amazon.de/dp/B0D3J7CKFR?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Apple Pencil Pro</a> für 109 Euro</li>
<li><a href="https://www.amazon.de/dp/B0GS5S368L?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Apple 13 Zoll MacBook Neo</a> für 739 Euro</li>
<li><a href="https://www.amazon.de/dp/B0DZD8Y997?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Apple Studio Display</a> für 1.199 Euro</li>
</ul>
<h2>📱 Smartphones, Smartwatches &amp; Wearables</h2>
<ul>
<li><a href="https://www.amazon.de/dp/B0FHL3XZNR?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Google Pixel 10 Pro</a> für 699 Euro</li>
<li><a href="https://www.amazon.de/dp/B0GGC2HBBY?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Google Pixel 10a</a> für 449 Euro</li>
<li><a href="https://www.amazon.de/dp/B0FQFLMHSX?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Apple Watch Series 11</a> für 369 Euro</li>
<li><a href="https://www.amazon.de/dp/B0DB61XP8V?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">HUAWEI Watch D2</a> für 303 Euro</li>
<li><a href="https://www.amazon.de/dp/B0F2TT8Q7M?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Sony kabellose NC-Kopfhörer</a> für 349 Euro</li>
<li><a href="https://www.amazon.de/dp/B0D8LHH8CX?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Google Pixel Buds Pro 2</a> für 172 Euro</li>
</ul>
<h2>🎮 Gaming &amp; VR</h2>
<ul>
<li><a href="https://www.amazon.de/dp/B09N5CNS5T?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Meta Quest 3 512 GB</a> für 527 Euro</li>
<li><a href="https://www.amazon.de/dp/B0DBJ5PBLT?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Logitech G Astro A50 Gaming-Headset</a> für 194,99 Euro</li>
<li><a href="https://www.amazon.de/dp/B0DFKC99VL?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Intel Core Ultra 9 Desktop-Prozessor</a> für 469 Euro</li>
</ul>
<h2>☕ Küche, Kaffee &amp; Haushaltsgeräte</h2>
<h3>Kaffee</h3>
<ul>
<li><a href="https://www.amazon.de/dp/B08CBJCQ39?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Philips Espresso Kaffeevollautomat</a> für 424 Euro</li>
<li><a href="https://www.amazon.de/dp/B0B8JV43LL?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">De’Longhi Siebträgermaschine</a> für 349,90 Euro</li>
<li><a href="https://www.amazon.de/dp/B0FHL3C7KP?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Ninja Luxe Premier Kaffeemaschine</a> für 394,99 Euro</li>
</ul>
<h3>Küche</h3>
<ul>
<li><a href="https://www.amazon.de/dp/B0G64WRJGG?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Ninja CREAMi Eismaschine</a> für 299,98 Euro</li>
<li><a href="https://www.amazon.de/dp/B0FP2KH5FP?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Ninja CREAMi Deluxe Eismaschine</a> für 199,98 Euro</li>
<li><a href="https://www.amazon.de/dp/B0B8DV6CK5?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Philips 7000 PastaMaker</a> für 169 Euro</li>
<li><a href="https://www.amazon.de/dp/B08GHG6CP8?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Tefal Jamie Oliver Pfannenset</a> für 79,79 Euro</li>
</ul>
<h3>Heißluftfritteusen</h3>
<ul>
<li><a href="https://www.amazon.de/dp/B09ZYLM43B?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Ninja MAX Dual Zone Heißluftfritteuse</a> für 149 Euro</li>
<li><a href="https://www.amazon.de/dp/B0CZXXVKS7?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Ninja Heißluftfritteuse MAX PRO</a> für 89,99 Euro</li>
</ul>
<h2>🏠 Smart Home &amp; Amazon Geräte</h2>
<ul>
<li><a href="https://www.amazon.de/dp/B09B8X9RGM?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Echo Dot</a> für 29,99 Euro</li>
<li><a href="https://www.amazon.de/dp/B0DKLFHZDH?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Echo Dot Max</a> für 64,99 Euro</li>
<li><a href="https://www.amazon.de/dp/B0C2S2J7JP?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Echo Spot</a> für 49,99 Euro</li>
<li><a href="https://www.amazon.de/dp/B0B6GKHS2S?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Ring Innenkamera</a> für 24,99 Euro</li>
<li><a href="https://www.amazon.de/dp/B0D7QQ9JBT?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Philips Hue LED Lampen 3er Pack</a> für 99,97 Euro</li>
<li><a href="https://www.amazon.de/dp/B00A128S24?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">TP-Link Gigabit Netzwerk Switch</a> für 13,99 Euro</li>
</ul>
<h2>🤖 Saugroboter &amp; Staubsauger</h2>
<ul>
<li><a href="https://www.amazon.de/dp/B0GCGVJD71?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">ECOVACS DEEBOT T90</a> für 599 Euro</li>
<li><a href="https://www.amazon.de/dp/B0F53MJY8T?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">dreame L40 Ultra</a> für 449 Euro</li>
<li><a href="https://www.amazon.de/dp/B0H2JP5WVY?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">MOVA E50 Pro Ultra</a> für 429 Euro</li>
<li><a href="https://www.amazon.de/dp/B0DV5RRL9F?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">dreame H12 Nass- und Trockensauger</a> für 178,99 Euro</li>
<li><a href="https://www.amazon.de/dp/B0GVP7XY36?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Dyson V8 kabelloser Staubsauger</a> für 279 Euro</li>
</ul>
<h2>🌡️ Klima, Luft &amp; Wohnkomfort</h2>
<ul>
<li><a href="https://www.amazon.de/dp/B0CM8P9?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Comfee Mobiles Klimagerät</a> für 190,99 Euro</li>
<li><a href="https://www.amazon.de/dp/B0CTMNRY8?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Levoit Standventilator</a> für 109,98 Euro</li>
<li><a href="https://www.amazon.de/dp/B08L73QL1V?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Levoit Luftreiniger</a> für 119,98 Euro</li>
</ul>
<h2>🌳 Garten &amp; Outdoor</h2>
<ul>
<li><a href="https://www.amazon.de/dp/B0GD23KKHC?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">MOVA LiDAX 1200 Mähroboter</a> für 894 Euro</li>
<li><a href="https://www.amazon.de/dp/B078GRBYSP?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Einhell Akku-Sense Rasenmäher</a> für 141,99 Euro</li>
<li><a href="https://www.amazon.de/dp/B078H242FN?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Einhell City Akku-Rasenmäher</a> für 99,99 Euro</li>
<li><a href="https://www.amazon.de/dp/B0CGX9L9CL?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Bosch Professional Akku Bohrhammer</a> für 174,99 Euro</li>
</ul>
<h2>🛴 E-Mobility &amp; Drohnen</h2>
<ul>
<li><a href="https://www.amazon.de/dp/B0B3RWP3ZP?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Segway-Ninebot MAX G2 D E-Scooter</a> für 569 Euro</li>
<li><a href="https://www.amazon.de/dp/B0DWTBMB82?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Xiaomi E-Scooter 4 Lite</a> für 379,99 Euro</li>
<li><a href="https://www.amazon.de/dp/B0FKGSKZ1G?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">DJI Mini 5 Pro Fly Drohne</a> für 949 Euro</li>
</ul>
<h2>🖨️ Büro &amp; Drucker</h2>
<ul>
<li><a href="https://www.amazon.de/dp/B07SJHTWCY?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">HP Color Laser MF-Drucker</a> für 219,99 Euro</li>
</ul>
<h2>💾 Speicher &amp; Datenträger</h2>
<ul>
<li><a href="https://www.amazon.de/dp/B0DN6DK3X4?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">SanDisk Extreme PRO SSD 4 TB</a></li>
<li><a href="https://www.amazon.de/dp/B07VS8QCXC?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Seagate Portable Drive SSD 5TB</a> für 140 Euro</li>
</ul>
<h2>🔋 Sonstiges</h2>
<ul>
<li><a href="https://www.amazon.de/dp/B01B8R6PF2?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">AA-Alkali-Hochleistungsbatterien</a> für 19,56 Euro</li>
<li><a href="https://www.amazon.de/dp/B0DXLBZF4Q?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">PHILIPS OneBlade elektrischer Rasierer</a> für 34,99 Euro</li>
</ul>


<p></p>



<h2 class="wp-block-heading">Attraktive Preise auch für Amazon-Kunden ohne Prime</h2>



<p>Auch für Amazon-Kunden ohne Prime-Abo gibt es derzeit einige Highlight-Angebote mit Jahresbestpreisen:</p>



<ul class="wp-block-list">
<li><a href="https://www.amazon.de/XIAOMI-Fitness-Tracker-Herzfrequenz-Schlaf%C3%BCberwachung-Dualband-GPS-Jungle-Green/dp/B08N64CBKG?tag=pcwelt.de-21&amp;ascsubtag=rss">Xiaomi Watch S5 für 152,99 statt 240 Euro</a></li>



<li><a href="https://www.amazon.de/Ninja-Eismaschine-Dessertmaschine-Smoothie-Bowls-NC302EU/dp/B0G26N7D9N?tag=pcwelt.de-21&amp;ascsubtag=rss">Ninja CREAMi Eismaschine für 189 statt zuvor 227 Euro</a></li>



<li><a href="https://www.amazon.de/dp/B0GR1B8B3S?tag=pcwelt.de-21&amp;ascsubtag=rss" data-type="link" data-id="https://www.amazon.de/dp/B0GR1B8B3S?tag=pcwelt.de-21&amp;ascsubtag=rss">Apple MacBook Air 15 für 1.439 statt zuvor 1.558 Euro</a></li>



<li><a href="https://www.amazon.de/dp/B0GR1RRJKF?tag=pcwelt.de-21&amp;ascsubtag=rss">Apple MacBook Pro für 2.098 statt 2.169 Euro</a></li>



<li><a href="https://www.amazon.de/dp/B0FQG8MFKP?tag=pcwelt.de-21&amp;ascsubtag=rss">Apple iPhone 17 Pro 256 GB für 1.169 statt 1.227 Euro</a></li>



<li><a href="https://www.amazon.de/Apple-iPhone-Pro-Batterielaufzeit-Kamera-System/dp/B0FQG1TSY1?tag=pcwelt.de-21&amp;ascsubtag=rss">Apple iPhone 17 Pro Max 256 GB für 1.349 statt 1.389 Euro</a></li>



<li><a href="https://www.amazon.de/dp/B0DGHQ1KVY?tag=pcwelt.de-21&amp;ascsubtag=rss">Apple AirPods Max Kopfhörer für 399 statt 439 Euro</a></li>



<li><a href="https://www.amazon.de/Windows-Computer-Ethernet-Business-Heimkino/dp/B0BCNMP3CX?tag=pcwelt.de-21&amp;ascsubtag=rss">Mini PC AMD Ryzen R2544 für 284 statt 299,90 Euro</a></li>
</ul>



<p>Viele weitere Deals finden Sie auf <a href="https://www.pcwelt.de/deals" data-type="link" data-id="https://www.pcwelt.de/deals" target="_blank" rel="noreferrer noopener">unserer Deals-Seite.</a></p>



<p><em>Empfehlung:</em> <a href="https://www.macwelt.de/article/2817043/beste-fruehe-apple-angebote-prime-day-2026.html" target="_blank" rel="noreferrer noopener">Die besten Apple-Angebote zum Prime Day 2026</a></p>



<h2 class="wp-block-heading">Was ist der Amazon Prime Day?</h2>



<p>Der <strong>Amazon Prime Day</strong> ist eine jährlich stattfindende Rabattaktion von Amazon, die sich <strong>exklusiv an Prime-Mitglieder richtet</strong>. Während dieses Zeitraums bietet Amazon stark reduzierte Preise auf eine große Bandbreite von Produkten – von Technik über Haushaltswaren bis hin zu Kleidung. Andere Shops bieten den Prime Day nicht an.</p>



<p>Der Prime Day gehört zu den wichtigsten Online-Shopping-Events des Jahres. Vor allem für Amazon zahlt es sich aus: Jahr für Jahr werden neue Umsatzrekorde gebrochen. Wohl auch deshalb wurde die Dauer von 2 auf inzwischen 4 Tage verlängert. Waren es 2019 noch ca. 5 Milliarden US-Dollar Amazon-Einnahmen weltweit, so schätzt man den Prime Day von 2025 auf ca. 15,3 Milliarden US-Dollar.</p>



<h2 class="wp-block-heading">So verpassen Sie keine Angebote am Prime Day</h2>



<p>In diesem Beitrag werden wir regelmäßig über die besten Angebote während des Prime Day aus den Bereichen Technik, IT, Smartphones, Home Entertainment und Smart Home informieren. Sie können sich den <strong>Artikel als Favorit bookmarken</strong>, um ihn jederzeit aufrufen zu können.</p>



<h3 class="wp-block-heading">Kostenloses Prime-Testabo abschließen</h3>



<p>Wer noch kein Amazon-Prime-Kunde ist, für den lohnt es sich, <strong>jetzt</strong> einen kostenlosen Testmonat auszuprobieren. Denn so kann man ab sofort die exklusiven Prime-Preise erhalten. Wer rechtzeitig kündigt vor Ablauf des Testzeitraums, der zahlt noch nicht mal für das Prime-Abo.</p>



<p><a href="https://www.amazon.de/gp/prime?tag=pcwelt.de-21&amp;ascsubtag=rss">Prime-Abo kostenlos testen</a></p>



<h3 class="wp-block-heading">Angebotsseite bei Amazon checken</h3>



<p>Sogenannte <a href="https://www.amazon.de/deals?ref_=nav_cs_gb&amp;bubble-id=deals-collection-lightning-deals&amp;tag=pcwelt.de-21&amp;ascsubtag=rss">Blitzdeals</a> sind nur für kurze Zeit und solange der Vorrat reicht, verfügbar. Deshalb lohnt es sich, regelmäßig die spezielle Amazon-Unterseite des Events zu besuchen:</p>



<p><a href="https://www.amazon.de/primeday?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Die besten Tagesangebote bei Amazon</a></p>



<p><a href="https://www.amazon.de/deals?ref_=nav_cs_gb&amp;bubble-id=deals-collection-lightning-deals&amp;tag=pcwelt.de-21&amp;ascsubtag=rss">Blitzangebote bei Amazon – nur kurz verfügbar</a></p>



<h3 class="wp-block-heading">Rufus – Amazons KI-Einkaufsassistent</h3>



<p>Sie können „<a href="https://www.amazon.de/Rufus/b?node=100898398031&amp;tag=pcwelt.de-21&amp;ascsubtag=rss">Rufus</a>“ aktivieren – Amazons KI-gestützten Einkaufsassistenten, der für Sie persönlich die besten Deals findet.<br>Mehr Infos zu Rufus: <a href="https://www.aboutamazon.com/news/retail/how-to-use-amazon-shopping-ai-assistant" target="_blank" rel="noreferrer noopener">How to use Rufus to check price history, find deals, auto-buy items</a></p>



<h3 class="wp-block-heading">Artikel auf persönliche Merkliste setzen</h3>



<p>Suchen Sie nach Wunschartikeln, die Sie beobachten wollen. Am besten setzen Sie das jeweilige Produkt auf Ihre Merkliste (Button „Auf die Liste“ unterhalb der Preisangabe drücken). So haben Sie Ihre Produkte während des Prime Day besser im Blick und sehen auf Anhieb, falls der Preis gesenkt werden sollte.</p>



<h3 class="wp-block-heading">Personalisierte Empfehlungen ansehen</h3>



<p>Amazon stellt personalisierte Angebote bereit, die sich am individuellen Kundenverhalten orientieren. Filtern Sie dazu auf der Angebotsseite nach „Für dich“.</p>



<p><a href="https://www.amazon.de/deals?tag=pcwelt.de-21&amp;ascsubtag=rss">Zur Angebotsseite</a></p>



<h3 class="wp-block-heading">Bestseller-Liste</h3>



<p>Es empfiehlt sich, immer mal die <a href="https://www.amazon.de/gp/bestsellers?tag=pcwelt.de-21&amp;ascsubtag=rss">Amazon Bestseller-Liste</a> zu durchforsten. Hier werden die meistgekauften Artikel gezeigt. Das Ranking wird regelmäßig angepasst und bildet die tagesaktuelle Nachfrage nach Produkten ab. Spannend ist auch die Amazon-Kategorie „Aufsteiger des Tages“. Interessante Produkte am besten gleich auf die Merkliste setzen.</p>



<h3 class="wp-block-heading"><strong>Mit PC-Welt keine Angebote verpassen</strong></h3>



<p>Abonnieren Sie unseren <a href="https://www.pcwelt.de/newsletter-anmeldung" data-type="link" data-id="https://www.pcwelt.de/newsletter-anmeldung" target="_blank" rel="noreferrer noopener">Schnäppchen-Newsletter</a>. Alle empfehlenswerten Prime Day Angebote aus den Bereichen IT, Tech, Digital Lifestyle und Smarthome finden Sie <strong>kurz vor Start des Prime Day </strong>in unserer Webseiten-Rubrik zum Prime Day:</p>



<p><a href="https://www.pcwelt.de/prime-day" data-type="link" data-id="https://www.pcwelt.de/deals" target="_blank" rel="noreferrer noopener">Die besten Deals am Prime Day – ausgewählt von der PC-Welt Redaktion</a></p>



<p><em><strong>Empfehlung:</strong></em> <a href="https://www.macwelt.de/article/2817043/beste-fruehe-apple-angebote-prime-day-2026.html" target="_blank" rel="noreferrer noopener">Die besten Apple-Angebote am Prime Day 2026</a></p>



<p><strong>Weitere Beiträge:</strong></p>



<ul class="wp-block-list">
<li><a href="https://www.pcwelt.de/article/3132274/alexa-ab-sofort-in-deutschland-verfuegbar-das-kann-sie-besser-als-chatgpt.html" target="_blank" rel="noreferrer noopener">Alexa+ ab sofort in Deutschland verfügbar</a></li>



<li><a href="https://www.aboutamazon.com/news/retail/how-to-use-amazon-shopping-ai-assistant" target="_blank" rel="noreferrer noopener">How to use Rufus to check price history, find deals, auto-buy items</a></li>



<li><a href="https://www.pcwelt.de/article/3076065/amazon-leo-internet-angebot-kommt-nach-deutschland-termin-steht-jetzt-fest.html" data-type="link" data-id="https://www.pcwelt.de/article/3076065/amazon-leo-internet-angebot-kommt-nach-deutschland-termin-steht-jetzt-fest.html" target="_blank" rel="noreferrer noopener">Amazons Internet-Angebot kommt nach Deutschland</a></li>



<li><a href="https://www.pcwelt.de/article/2636917/lenovo-laptop-7606-test-amazon-bestseller.html" data-type="link" data-id="https://www.pcwelt.de/article/2636917/lenovo-laptop-7606-test-amazon-bestseller.html" target="_blank" rel="noreferrer noopener">Amazon-Bestseller im Test: Lenovo Laptop 7606</a></li>



<li><a href="https://www.pcwelt.de/article/2914305/amazon-haul-neuer-online-shop-schnaeppchen-1-euro-bis-20-euro.html" data-type="link" data-id="https://www.pcwelt.de/article/2914305/amazon-haul-neuer-online-shop-schnaeppchen-1-euro-bis-20-euro.html" target="_blank" rel="noreferrer noopener">Neuer Amazon Online-Shop: Tausende Schnäppchen ab 1 Euro bei Amazon Haul</a></li>



<li><a href="https://www.pcwelt.de/article/3130644/reise-urlaub-gadgets-amazon-haul-basics-guenstig.html" data-type="link" data-id="https://www.pcwelt.de/article/3130644/reise-urlaub-gadgets-amazon-haul-basics-guenstig.html" target="_blank" rel="noreferrer noopener">10 praktische Reise-Gadgets, die sich lohnen</a></li>



<li><a href="https://www.pcwelt.de/article/3122095/seagate-portable-drive-5tb-externe-festplatte-im-deal-34-prozent-rabatt-angebot-amazon.html" data-type="link" data-id="https://www.pcwelt.de/article/3122095/seagate-portable-drive-5tb-externe-festplatte-im-deal-34-prozent-rabatt-angebot-amazon.html" target="_blank" rel="noreferrer noopener">Bestseller-Festplatte im Preisrutsch: Seagate-Modell mit 5 TB</a></li>
</ul>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[A Linux user claiming Microsoft Edge is the best browser might be the most baffling thing I've heard as a Linux user]]></title>
<description><![CDATA[Watching this video and the guy mentions he actually had a Linux user tell him they use Edge on Linux — and that it's the best browser available. I get that Edge technically supports Linux. And sure, maybe you can make a case for Edge on Windows. But actively choosing to install a Microsoft brows...]]></description>
<link>https://tsecurity.de/de/3617131/linux-tipps/a-linux-user-claiming-microsoft-edge-is-the-best-browser-might-be-the-most-baffling-thing-ive-heard-as-a-linux-user/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617131/linux-tipps/a-linux-user-claiming-microsoft-edge-is-the-best-browser-might-be-the-most-baffling-thing-ive-heard-as-a-linux-user/</guid>
<pubDate>Tue, 23 Jun 2026 05:39:45 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Watching this video and the guy mentions he actually had a Linux user tell him they use Edge on Linux — and that it's the best browser available.</p> <p>I get that Edge technically supports Linux. And sure, maybe you can make a case for Edge on Windows. But actively choosing to install a Microsoft browser on Linux and calling it the best? Out of everything available — Firefox, Librewolf, Brave, Vivaldi, even Chromium — someone landed on Edge?</p> <p>I'm not here to bash anyone's preferences, but I genuinely don't understand the reasoning. Like what does Edge even offer on Linux that justifies that take? Curious if anyone here has actually tried it or can explain the appeal.</p> <p>[Video — relevant part at 0:33, ends around 0:46](<a href="https://youtu.be/4RlhYVFRl40?t=33">https://youtu.be/4RlhYVFRl40?t=33</a>)</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/TargetAcrobatic2644"> /u/TargetAcrobatic2644 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1ud5qhp/a_linux_user_claiming_microsoft_edge_is_the_best/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1ud5qhp/a_linux_user_claiming_microsoft_edge_is_the_best/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[iOS 27 Beta 2 Adds New Write with Siri Features for Text Editing]]></title>
<description><![CDATA[iOS 27 beta 2 introduces a new Write with Siri experience that changes how users create, edit, and rewrite text on iPhone. The feature replaces the older Writing Tools panel and brings Siri directly into the keyboard while typing in apps like Notes and other supported text fields.



With this up...]]></description>
<link>https://tsecurity.de/de/3617130/ios-mac-os/ios-27-beta-2-adds-new-write-with-siri-features-for-text-editing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617130/ios-mac-os/ios-27-beta-2-adds-new-write-with-siri-features-for-text-editing/</guid>
<pubDate>Tue, 23 Jun 2026 05:39:35 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[iOS 27 beta 2 introduces a new Write with Siri experience that changes how users create, edit, and rewrite text on iPhone. The feature replaces the older Writing Tools panel and brings Siri directly into the keyboard while typing in apps like Notes and other supported text fields.



With this update, the keyboard now shows a Write with Siri option before users start typing. After typing begins, a smaller Siri button appears beside the predictive text suggestions, which keeps the feature available without taking over the keyboard.



How Write with Siri Works



When users tap Write with Siri, an input field expands from the Dynamic Island and asks what they want Siri to do with the text. Users can ask Siri to write new text, proofread a paragraph, rewrite a note in another style, or make changes using a natural language request.



Apple has removed the older buttons such as Friendly and Professional, so users now describe the result they want instead of choosing from fixed options. This also allows Siri to use personal context where supported, which makes the feature more connected to the wider Apple Intelligence system.



After Siri rewrites existing text, iOS 27 shows a bottom panel with before and after previews, undo controls, and an Edit with Siri button for follow-up changes. Users can also trigger the same text actions with voice, as Siri can understand the active app and the text currently on screen.



Write with Siri is available in iOS 27 beta 2, iPadOS 27, and macOS Golden Gate. Apple plans to release the first public beta in July, while the final iOS 27 update should arrive in the fall, likely around September.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-54298 | withastro up to 6.4.5 spreadAttributes cross site scripting (EUVD-2026-38336)]]></title>
<description><![CDATA[A vulnerability was found in withastro astro up to 6.4.5. It has been classified as problematic. This issue affects the function spreadAttributes. Performing a manipulation results in cross site scripting.

This vulnerability was named CVE-2026-54298. The attack may be initiated remotely. There i...]]></description>
<link>https://tsecurity.de/de/3617058/sicherheitsluecken/cve-2026-54298-withastro-up-to-645-spreadattributes-cross-site-scripting-euvd-2026-38336/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617058/sicherheitsluecken/cve-2026-54298-withastro-up-to-645-spreadattributes-cross-site-scripting-euvd-2026-38336/</guid>
<pubDate>Tue, 23 Jun 2026 04:38:45 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/withastro:astro">withastro astro up to 6.4.5</a>. It has been classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This issue affects the function <code>spreadAttributes</code>. Performing a manipulation results in cross site scripting.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-54298">CVE-2026-54298</a>. The attack may be initiated remotely. There is no available exploit.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-54299 | withastro up to 6.4.5 Host Header request.url input validation (EUVD-2026-38337)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in withastro astro up to 6.4.5. This impacts the function request.url of the component Host Header Handler. Performing a manipulation results in improper input validation.

This vulnerability is reported as CVE-2026-54299. The attack is pos...]]></description>
<link>https://tsecurity.de/de/3616991/sicherheitsluecken/cve-2026-54299-withastro-up-to-645-host-header-requesturl-input-validation-euvd-2026-38337/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616991/sicherheitsluecken/cve-2026-54299-withastro-up-to-645-host-header-requesturl-input-validation-euvd-2026-38337/</guid>
<pubDate>Tue, 23 Jun 2026 03:25:11 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/withastro:astro">withastro astro up to 6.4.5</a>. This impacts the function <code>request.url</code> of the component <em>Host Header Handler</em>. Performing a manipulation results in improper input validation.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2026-54299">CVE-2026-54299</a>. The attack is possible to be carried out remotely. No exploit exists.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-53663 | remix-run react-router/server-runtime up to 7.15.0 cross-site request forgery (EUVD-2026-38338)]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in remix-run react-router and server-runtime up to 7.15.0. The impacted element is an unknown function. The manipulation results in cross-site request forgery.

This vulnerability is identified as CVE-2026-53663. The attack can be exe...]]></description>
<link>https://tsecurity.de/de/3616965/sicherheitsluecken/cve-2026-53663-remix-run-react-routerserver-runtime-up-to-7150-cross-site-request-forgery-euvd-2026-38338/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616965/sicherheitsluecken/cve-2026-53663-remix-run-react-routerserver-runtime-up-to-7150-cross-site-request-forgery-euvd-2026-38338/</guid>
<pubDate>Tue, 23 Jun 2026 02:38:56 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">problematic</a> has been discovered in <a href="https://vuldb.com/product/remix-run:react-router">remix-run react-router and server-runtime up to 7.15.0</a>. The impacted element is an unknown function. The manipulation results in cross-site request forgery.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2026-53663">CVE-2026-53663</a>. The attack can be executed remotely. There is not any exploit available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS Continuum offers devs help with securing code]]></title>
<description><![CDATA[AI coding agents are making it easier than ever to produce software. Ensuring that software is secure before deployment is another matter — one that AWS thinks AI should help with too.



As enterprises adopt agentic development workflows, the volume of first-party code being created and modified...]]></description>
<link>https://tsecurity.de/de/3616133/it-security-nachrichten/aws-continuum-offers-devs-help-with-securing-code/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616133/it-security-nachrichten/aws-continuum-offers-devs-help-with-securing-code/</guid>
<pubDate>Mon, 22 Jun 2026 18:38:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AI coding agents are making it easier than ever to produce software. Ensuring that software is secure before deployment is another matter — one that AWS thinks AI should help with too.</p>



<p>As enterprises adopt <a href="https://www.infoworld.com/article/4142019/coding-for-agents.html">agentic development</a> workflows, the volume of first-party code being created and modified is rising rapidly. Yet the process of validating vulnerabilities, determining whether they are exploitable, and fixing them often still depends on developers and security teams working through findings manually.</p>



<p>AWS is aiming to address that imbalance with Continuum, a new service designed to continuously discover, investigate, and remediate vulnerabilities in enterprise environments, whether the code is their own or from third parties.</p>



<p>Rather than simply generating alerts, the service is intended to help enterprises move findings through the entire remediation lifecycle, AWS VP of Security and Observability <a href="https://www.linkedin.com/in/chetkapoor/" target="_blank" rel="noreferrer noopener">Chet Kapoor</a> wrote in a <a href="https://aws.amazon.com/blogs/security/introducing-aws-continuum-security-at-machine-speed/" target="_blank" rel="noreferrer noopener">blog post</a>.</p>



<p>For first-party applications, Continuum can analyze code, validate whether vulnerabilities are exploitable, generate remediation recommendations, and propose fixes that can be reviewed through existing software development workflows, helping developers address security issues without requiring security teams to manually investigate every finding, Kapoor said.</p>



<p>Once users think Continuum has learned enough about their environment and understands their guardrails, they can put it in what AWS calls “enforce mode” to autonomously fix any code lapses, Kapoor said.</p>



<p>Continuum borrows some of its capabilities, penetration testing and code scanning features, from an existing service, Security Agent.</p>



<p>Other capabilities are all-new, including threat modeling, which is designed to automatically generate threat models from source code or design documents and output them in STRIDE format.</p>



<h2 class="wp-block-heading">Keeping pace with AI-driven software development</h2>



<p>Analysts see Continuum helping enterprise developer teams ship more secure code while keeping pace with <a href="https://www.infoworld.com/article/4176534/ai-coding-agents-need-good-software-engineers.html">AI coding tools</a>.</p>



<p>“The harder problem is no longer just finding issues, it is knowing which ones are real, which ones matter in their environment, and which ones need to be fixed first,” said <a href="https://www.hfsresearch.com/team/akshat-tyagi/" target="_blank" rel="noreferrer noopener">Akshat Tyagi</a>, associate practice leader at HFS Research. “Traditional workflows built around dashboards and manual triage struggle with that volume. A dashboard can show the backlog, but it does not validate the finding, assess business impact, or help remediate it.”</p>



<p>Continuum’s value, according to Tyagi, “is not just more detection, but using AI to prioritize risk findings, suggest mitigations, and support faster action while keeping humans in control of high-risk decisions.”</p>



<p>Taking faster action is becoming increasingly important as attackers are gaining access to many of the same AI capabilities that enterprises are using to accelerate software development and security testing, according to <a href="https://www.linkedin.com/in/amitchandak78/" target="_blank" rel="noreferrer noopener">Amit Chandak</a>, chief analytics officer at IT consulting firm Kanerika. “The gap between a flaw being disclosed and a working exploit is shrinking rapidly from months to hours,” he said.</p>



<p>While Continuum may reduce repetitive work for developers and SREs, it could also create new responsibilities for CISOs around governance, oversight, testing, and maintaining guardrails for automated actions.</p>



<p>“Continuum changes the CISO’s role from managing findings to governing how findings are handled. The focus moves to setting rules: what can be automated, what needs human approval, and what level of risk is acceptable in production,” Tyagi said. “Staffing will shift too. There may be less manual triage, but more need for people who can review AI-generated fixes, set guardrails, and know when not to trust the system.”</p>



<p>Even so, Chandak does not expect the offering to lead to immediate headcount reductions, particularly given that Continuum is only available as a gated preview.</p>



<p>Continuum could change how CISOs measure work, Tyagi said: “Ticket count matters less. Better measures are how quickly real risks are validated and fixed, how many false positives are removed, and whether automation is reducing risk without causing new problems.”</p>



<p>Those same metrics could also become a yardstick for CISOs determining how much autonomy to give tools like Continuum, said Chandak. Most enterprises’ data and governance practices are not yet ready for fully autonomous remediation, said Chandak, adding that, “AWS’ graduated trust design, under which enterprises have the option of choosing the degree of autonomy, from human in the loop to fully automatic remediation, is an admission of that fact.”</p>



<h2 class="wp-block-heading">Beyond first-party code</h2>



<p>Continuum could also help CISOs with third-party code vulnerability analysis, where enterprises often have less visibility and control.</p>



<p>“Most third party vulnerability alerts are noise. A tool may flag a vulnerable library, but the real question is whether that vulnerable code is actually used in production. If Continuum can answer that, it helps teams focus on the few issues that matter,” Tyagi said. “This is especially useful for open-source and software supply chain risk, where enterprises depend on packages and hidden transitive dependencies they may not fully track. It also helps when no patch is available yet.”</p>



<p>However, he warned, Continuum might not offer a direct fix to third-party code: “You usually cannot patch third-party code yourself as you don’t own it, so remediation there means version pinning or compensating controls.”</p>



<p><em>This article first appeared on <a href="https://www.infoworld.com/article/4187916/aws-continuum-offers-devs-help-with-securing-code.html">InfoWorld</a>.</em></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS Continuum offers devs help with securing code]]></title>
<description><![CDATA[AI coding agents are making it easier than ever to produce software. Ensuring that software is secure before deployment is another matter — one that AWS thinks AI should help with too.



As enterprises adopt agentic development workflows, the volume of first-party code being created and modified...]]></description>
<link>https://tsecurity.de/de/3616128/ai-nachrichten/aws-continuum-offers-devs-help-with-securing-code/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616128/ai-nachrichten/aws-continuum-offers-devs-help-with-securing-code/</guid>
<pubDate>Mon, 22 Jun 2026 18:33:47 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AI coding agents are making it easier than ever to produce software. Ensuring that software is secure before deployment is another matter — one that AWS thinks AI should help with too.</p>



<p>As enterprises adopt <a href="https://www.infoworld.com/article/4142019/coding-for-agents.html">agentic development</a> workflows, the volume of first-party code being created and modified is rising rapidly. Yet the process of validating vulnerabilities, determining whether they are exploitable, and fixing them often still depends on developers and security teams working through findings manually.</p>



<p>AWS is aiming to address that imbalance with Continuum, a new service designed to continuously discover, investigate, and remediate vulnerabilities in enterprise environments, whether the code is their own or from third parties.</p>



<p>Rather than simply generating alerts, the service is intended to help enterprises move findings through the entire remediation lifecycle, AWS VP of Security and Observability <a href="https://www.linkedin.com/in/chetkapoor/" target="_blank" rel="noreferrer noopener">Chet Kapoor</a> wrote in a <a href="https://aws.amazon.com/blogs/security/introducing-aws-continuum-security-at-machine-speed/" target="_blank" rel="noreferrer noopener">blog post</a>.</p>



<p>For first-party applications, Continuum can analyze code, validate whether vulnerabilities are exploitable, generate remediation recommendations, and propose fixes that can be reviewed through existing software development workflows, helping developers address security issues without requiring security teams to manually investigate every finding, Kapoor said.</p>



<p>Once users think Continuum has learned enough about their environment and understands their guardrails, they can put it in what AWS calls “enforce mode” to autonomously fix any code lapses, Kapoor said.</p>



<p>Continuum borrows some of its capabilities, penetration testing and code scanning features, from an existing service, Security Agent.</p>



<p>Other capabilities are all-new, including threat modeling, which is designed to automatically generate threat models from source code or design documents and output them in STRIDE format.</p>



<h2 class="wp-block-heading">Keeping pace with AI-driven software development</h2>



<p>Analysts see Continuum helping enterprise developer teams ship more secure code while keeping pace with <a href="https://www.infoworld.com/article/4176534/ai-coding-agents-need-good-software-engineers.html">AI coding tools</a>.</p>



<p>“The harder problem is no longer just finding issues, it is knowing which ones are real, which ones matter in their environment, and which ones need to be fixed first,” said <a href="https://www.hfsresearch.com/team/akshat-tyagi/" target="_blank" rel="noreferrer noopener">Akshat Tyagi</a>, associate practice leader at HFS Research. “Traditional workflows built around dashboards and manual triage struggle with that volume. A dashboard can show the backlog, but it does not validate the finding, assess business impact, or help remediate it.”</p>



<p>Continuum’s value, according to Tyagi, “is not just more detection, but using AI to prioritize risk findings, suggest mitigations, and support faster action while keeping humans in control of high-risk decisions.”</p>



<p>Taking faster action is becoming increasingly important as attackers are gaining access to many of the same AI capabilities that enterprises are using to accelerate software development and security testing, according to <a href="https://www.linkedin.com/in/amitchandak78/" target="_blank" rel="noreferrer noopener">Amit Chandak</a>, chief analytics officer at IT consulting firm Kanerika. “The gap between a flaw being disclosed and a working exploit is shrinking rapidly from months to hours,” he said.</p>



<p>While Continuum may reduce repetitive work for developers and SREs, it could also create new responsibilities for CISOs around governance, oversight, testing, and maintaining guardrails for automated actions.</p>



<p>“Continuum changes the CISO’s role from managing findings to governing how findings are handled. The focus moves to setting rules: what can be automated, what needs human approval, and what level of risk is acceptable in production,” Tyagi said. “Staffing will shift too. There may be less manual triage, but more need for people who can review AI-generated fixes, set guardrails, and know when not to trust the system.”</p>



<p>Even so, Chandak does not expect the offering to lead to immediate headcount reductions, particularly given that Continuum is only available as a gated preview.</p>



<p>Continuum could change how CISOs measure work, Tyagi said: “Ticket count matters less. Better measures are how quickly real risks are validated and fixed, how many false positives are removed, and whether automation is reducing risk without causing new problems.”</p>



<p>Those same metrics could also become a yardstick for CISOs determining how much autonomy to give tools like Continuum, said Chandak. Most enterprises’ data and governance practices are not yet ready for fully autonomous remediation, said Chandak, adding that, “AWS’ graduated trust design, under which enterprises have the option of choosing the degree of autonomy, from human in the loop to fully automatic remediation, is an admission of that fact.”</p>



<h2 class="wp-block-heading">Beyond first-party code</h2>



<p>Continuum could also help CISOs with third-party code vulnerability analysis, where enterprises often have less visibility and control.</p>



<p>“Most third party vulnerability alerts are noise. A tool may flag a vulnerable library, but the real question is whether that vulnerable code is actually used in production. If Continuum can answer that, it helps teams focus on the few issues that matter,” Tyagi said. “This is especially useful for open-source and software supply chain risk, where enterprises depend on packages and hidden transitive dependencies they may not fully track. It also helps when no patch is available yet.”</p>



<p>However, he warned, Continuum might not offer a direct fix to third-party code: “You usually cannot patch third-party code yourself as you don’t own it, so remediation there means version pinning or compensating controls.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Best eSIMs for Europe Travel in 2026 – Tested on iPhone]]></title>
<description><![CDATA[In the old days, traveling to a destination like Europe meant suffering expensive roaming fees while still not always getting the best connections. At minimum, this can create frustrations for travelers, though it can also be a recipe for catastrophe given the right (or wrong) conditions. Whether...]]></description>
<link>https://tsecurity.de/de/3614517/ios-mac-os/best-esims-for-europe-travel-in-2026-tested-on-iphone/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3614517/ios-mac-os/best-esims-for-europe-travel-in-2026-tested-on-iphone/</guid>
<pubDate>Mon, 22 Jun 2026 07:09:27 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In the old days, traveling to a destination like Europe meant suffering expensive roaming fees while still not always getting the best connections. At minimum, this can create frustrations for travelers, though it can also be a recipe for catastrophe given the right (or wrong) conditions. Whether you plan on visiting multiple destinations throughout Europe or are just taking a short trip, having the right eSIM plan can provide you with reliable mobile data without having to worry about local SIM cards. 



Keeping this in mind, we’re looking at some of the best eSIMs for Europe travel in 2026. Here are our top picks for iPhone users based on connectability, ease of use, pricing plans, and more. 



1. Jetpac eSIM







Among the eSIMs tested, Jetpac eSIM is the overall best eSIM for Europe travel, especially if your trip covers more than one country. From café-hopping in Paris to checking train times in Switzerland or finding your hotel in Rome, Jetpac keeps things simple with a single regional Europe eSIM that covers 32 European countries, with 5G where available.



Setting up on iPhone is quick. Pick a plan, download the Jetpac app from the Apple App Store, follow the steps, and then it’s bon voyage. During testing, Jetpac handled everyday travel needs smoothly, including maps, messaging, browsing, social media, and video calls across multiple European countries.



Jetpac also adds useful travel benefits beyond standard data. Essential apps like WhatsApp, Google Maps, and Uber can still work even after your data runs out, so you are not stuck without directions, ride booking, or a quick message. It also supports unlimited hotspot sharing and dual SIM use on compatible iPhones, making it easier to keep your main number active while using Jetpac for data.



The pricing is clear too. Jetpac eSIM does not auto-charge users, and its prepaid Europe plans range from 1GB to unlimited data for 30 days at USD 65.99. Add in automatic multi-network switching that connects you to the best available local 5G or 4G network while crossing borders, in-app voice calls from USD 1.99 for 5 minutes, 24/7 support via WhatsApp and email, SmartDelay airport lounge benefits on eligible plans, and a 4.8 Trustpilot rating, and Jetpac becomes one of the most well-rounded eSIM options for Europe travel.



2. Airalo







As one of the most recognizable names in the eSIM market, Airalo offers affordable regional plans for travelers looking to stay connected but not wanting to spend big. Looking at the company’s eSIM coverage of Europe, it has a large number of destinations under a single package. It can be especially appealing for those who are budget-conscious, including students and backpackers. 



On an iPhone, users just need to scan a QR code to get started, and direct installation instructions are provided after a purchase. During testing, Airalo was dependable for everyday tasks, including accessing maps, messages, and rideshare apps. Users can choose from a variety of data allowances, which is incredibly useful when choosing a plan. 



Looking at some of the negative aspects, Airalo does lack the travel perks found with other services, but its low entry pricing and extensive coverage help the platform earn its place on this list. Those just looking for a basic data plan may want to consider this one. 



3. Saily







Developed by the team that created NordVPN, Saily offers mobile connectivity that focuses on privacy for travelers. With regional European coverage and a user-friendly mobile app, users will have little issue purchasing, activating, and managing data on their iPhone. 



In the testing process, Saily delivered stable speeds that were good for streaming, video calls, navigation, and messaging. The overall app experience was particularly polished, which can be really beneficial for first-time eSIM users. Switching plans or monitoring data usage was rather straightforward, and the coverage is ideal for those aiming to visit multiple European destinations in a single trip. 



One of the biggest advantages of Saily is its focus on digital security. With features meant to help protect users relying on public Wi-Fi, this eSIM can also be appealing to remote workers and business travelers. If you have an interest in security when making connections, Saily may be one to watch out for in 2026. 



4. Holafly







Holafly is going to be good for those who can never get enough data. One of the most appealing aspects of Holafly is that it offers unlimited data plans, which can be great for those not wanting to concern themselves with their data usage while traveling through Europe.



Taking the eSIM to task, Holafly had little issue handling social media, video streaming, video calls, and navigation. Setting it up on an iPhone was pretty easy, and those that find themselves away from their hotel Wi-Fi for extended periods are sure to appreciate the platform. There’s definitely something relieving about not having to worry about data, making this one especially appealing for content creators and other power users. 



While unlimited anything can often be nice, bear in mind it comes with the tradeoff that Holafly plans can be expensive, especially compared to other platforms that have fixed data allowances. Those with an interest in unlimited connectivity throughout Europe should give this one a look, as should anyone who prioritizes convenience over cost. 



5. Ubigi 







As a platform, Ubigi is popular among international travelers for its reliable service, flexible data plans, and broad coverage. Offering regional European packages alongside global plans, it’s going to be a practical option for users who travel globally throughout the year. 



With consistent performance during testing, Ubigi also did a solid job maintaining stable connections for navigation, productivity, and messaging. Activating the service on an iPhone is rather simple, and there’s also a dedicated app for simplifying plan management and tracking data while traveling. 



Those who frequently stay on the move are sure to appreciate the platform’s wide range of plan options and strong carrier partnerships in multiple countries. Though it may not be the cheapest provider on the market, Ubigi’s combination of reliability and flexibility makes it a dependable choice for those who frequently travel internationally. 



The Final Word: Which eSIM Is Right for You?



A reliable eSIM can make traveling through Europe far easier for users. With the ability to gain instant access to services such as maps, rideshare apps, messaging, and other travel essentials, those traveling abroad should do their best to research all of their options before making a decision. 



While each provider on this list has its own set of positive aspects, Jetpac eSIM stands out through a combination of competitive pricing, reliable connectivity, and benefits that focus on travelers. 



It’s not always easy knowing where your next travel destinations may take you, but ensuring you have the right eSIM for the journey helps you stay prepared. There’s many out there, but not all of them can compete with the options available on this list. ]]></content:encoded>
</item>
<item>
<title><![CDATA[You Don’t Need Perfect Security]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 This clip compares cybersecurity deterrence to choosing between two identical Ferraris — except one has a rabid pit bull in the back seat.

The point is simple: attackers often look for the easiest target, not necessarily a perfec...]]></description>
<link>https://tsecurity.de/de/3612314/it-security-video/you-dont-need-perfect-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3612314/it-security-video/you-dont-need-perfect-security/</guid>
<pubDate>Sat, 20 Jun 2026 16:03:40 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/LktpkTITxuo?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>This clip compares cybersecurity deterrence to choosing between two identical Ferraris — except one has a rabid pit bull in the back seat.<br />
<br />
The point is simple: attackers often look for the easiest target, not necessarily a perfect target.<br />
<br />
The conversation also references the classic “you only need to outrun the other guy” bear analogy commonly used in risk discussions.<br />
<br />
Many organizations approach security as if they must become impossible to compromise.<br />
<br />
In reality, a large portion of defense strategy is about increasing attacker cost, friction, uncertainty, and effort enough to encourage attackers to move elsewhere.<br />
<br />
Of course, weak or poorly implemented defenses can become “friendly pit bulls” that create false confidence instead of real protection.<br />
<br />
Should organizations focus more on becoming impossible to breach — or simply more difficult to target than everyone around them?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#RiskManagement #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Breaking the SOC triangle: How AI reshapes security operations trade-offs]]></title>
<description><![CDATA[A simple framework has always governed security operations that I call the SOC Triangle. It is a balance between quality, consistency and cost efficiency.



Every SOC operates within it. Push for higher-quality investigations, deeper analysis, richer context, fewer missed signals and you pay for...]]></description>
<link>https://tsecurity.de/de/3609972/it-security-nachrichten/breaking-the-soc-triangle-how-ai-reshapes-security-operations-trade-offs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609972/it-security-nachrichten/breaking-the-soc-triangle-how-ai-reshapes-security-operations-trade-offs/</guid>
<pubDate>Fri, 19 Jun 2026 12:08:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A simple framework has always governed security operations that I call the SOC Triangle. It is a balance between quality, consistency and cost efficiency.</p>



<p>Every SOC operates within it. Push for higher-quality investigations, deeper analysis, richer context, fewer missed signals and you pay for it in time and expertise. Standardize workflows to ensure consistency across every alert, and you often lose the flexibility needed to handle real-world complexity and nuance. Optimize for cost efficiency, and the pressure shows up quickly in both quality and consistency.</p>



<p>For years, the SOC Triangle has shaped how security teams are built and how they perform. This is why organizations add headcount to improve outcomes, rely on rigid playbooks to reduce variability and improve scale, and still struggle to operate at their theoretical best and optimize security and quality of service outcomes.</p>



<p>The constraint is not a failure of strategy. It is structural. And until recently, it was largely unavoidable.</p>



<h2 class="wp-block-heading">Why the SOC was built this way</h2>



<p>Most security operations centers are designed as human-routing systems. Alerts are ingested, triaged, escalated and resolved by analysts at multiple levels. Every meaningful step, including collecting evidence, correlating signals and making decisions, depends on human capacity.</p>



<p>That dependency introduces variability. Two analysts can approach the same alert differently, influenced by experience, fatigue and time pressure. To improve consistency, organizations introduce <a href="https://www.csoonline.com/article/3622920/soar-buyers-guide-11-security-orchestration-automation-and-response-products-and-how-to-choose.html?utm=hybrid_search">playbooks and workflows</a>. But those controls often reduce flexibility, especially in complex cases, and fail to provide coverage where decision making relies in part on unstructured context, and where workflows may not be fully deterministic and require real-time reasoning to determine the best course of action.</p>



<p>At the same time, scaling either quality or consistency typically requires more people, reducing cost efficiency.</p>



<p>This is the SOC Triangle in practice: a system where improving one dimension creates friction in another.</p>



<p>The same constraint is also why the managed detection and response market exists. When organizations could not solve the triangle in-house, they outsourced it. But the service model does not eliminate the trade-offs. It reconstitutes them at the provider layer, where the same human-routing architecture, the same playbooks and the same staffing economics drive the same limits. Customers pay for consistency and predictability, and they get it. What they often do not get is the investigation depth and environmental customization tailored to their business context and to optimizing against their security program maturity goals that they would want if resources were not the binding constraint.</p>



<h2 class="wp-block-heading">Where the model starts to break</h2>



<p>The challenge is not just the existence of trade-offs, but their growing intensity.</p>



<p>Modern SOCs must process higher volumes of alerts across more tools and environments. The work itself, gathering and correlating evidence across identity systems, endpoints, cloud platforms and threat intelligence, is both repetitive and cognitively demanding.</p>



<p>Under this pressure, the triangle tightens.</p>



<p>Quality degrades because analysts do not have time to fully investigate every signal and rigid automation playbooks often fail to capture the depth and nuance that security leaders expect which results in increased friction for end users. Consistency suffers because decisions are made under time constraints. Cost rises because the only way to compensate is to add more people or accept increased risk.</p>



<p>This hits hardest for organizations that have outsourced SOC operations. Service economics lock the trade-offs in place. Per-alert pricing constrains how much investigation each signal receives. Standardized playbooks limit how much the service can tailor to a specific environment. Tier structures exist because the math of humans investigating alerts demands they exist. Every one of those mechanisms is a rational response to the triangle. None of them changes its shape and its fundamental constraints.</p>



<p>For years, this has been accepted as the cost of doing business, whether that business is run in-house or outsourced.</p>



<h2 class="wp-block-heading">How AI changes the constraint</h2>



<p>AI is often framed as a tool for efficiency. The more meaningful shift is that it <a href="https://www.csoonline.com/article/4158008/the-ai-inflection-point-what-security-leaders-must-do-now.html">changes how certain SOC workflows</a> are executed.</p>



<p>Much of SOC work follows a pattern: gather data, correlate signals, ask follow-up questions and form a conclusion. These workflows are complex but repeatable. They require consistency and scale as much as expertise.</p>



<p>When those workflows are no longer constrained by human bandwidth, the SOC Triangle begins to change shape.</p>



<p>Quality improves because investigations can incorporate more meaningful data, apply investigative reasoning in real time and take into account unstructured information and business-specific context without shortcuts. Consistency improves because the same logic is applied across every alert. Cost efficiency improves because scaling no longer depends on linear increases in headcount.</p>



<p>I am watching this play out in production environments today. Investigations that used to consume the majority of Tier 1 and 2 analysts’ shifts now resolve in minutes, with deeper context than the human path could produce within these time frames. The same rigor is applied to every alert, not only the anecdotal ones that earn attention. What used to be a choice between going deep on a few cases or going shallow on many is no longer a compromise security leaders need to make.</p>



<p>For the first time, these dimensions are not strictly in opposition.</p>



<h2 class="wp-block-heading">From trade-offs to expansion</h2>



<p>This does not eliminate the SOC Triangle. It expands it.</p>



<p>Not every workflow can be automated, and not every decision can be reduced to a repeatable process. Strategic judgment, incident leadership and risk appetite remain human responsibilities and business decisions.</p>



<p>But the boundary within which SOC teams operate is no longer tied to legacy constraints.</p>



<p>Instead of choosing between quality, consistency and cost, organizations can begin to improve all three for the types of work best suited to machine execution. That is a meaningful shift, whether it occurs within a company’s SOC or in the service relationship with a partner that operates it.</p>



<h2 class="wp-block-heading">Where it matters most</h2>



<p>The impact is most visible in the high-volume workflows where performance gaps have been largest: alert triage and enrichment, initial investigation and evidence gathering, correlation across systems and routine response recommendations. These are the areas where human-led processes introduce the most variability, where time pressure degrades quality and where scaling costs are most visible. They are also the areas where trade-offs have historically been unavoidable.</p>



<h2 class="wp-block-heading">The human role evolves</h2>



<p>AI does not remove the need for human expertise. It changes <a href="https://www.csoonline.com/article/4168681/8-guiding-principles-for-reskilling-the-soc-for-agentic-ai.html">where that expertise is applied</a>.</p>



<p>As machines take on repeatable work, human effort shifts toward higher-value activities: interpreting ambiguous signals, managing complex incidents, setting policy and making risk-based decisions. The operating model moves from human-executed workflows to human-governed systems.</p>



<p>That changes what organizations should expect from security operations, whether in-house or outsourced. The conversation moves from “how many alerts did you close last week” to “what patterns are you seeing in my environment, and what should I do about them.” The output is judgment, not throughput. That is a different product than most security teams have been buying, and it is a different service than most managed detection and response service providers have been selling.</p>



<h2 class="wp-block-heading">The shift that matters</h2>



<p>For years, SOC leaders have accepted the triangle as a fixed constraint. What is changing now is not just the tooling. It is the economics of how security work is performed.</p>



<p>The triangle still exists. But it no longer defines a rigid set of trade-offs. In parts of the SOC and the services that support it, those trade-offs are beginning to loosen.</p>



<p>In a field where constraints have long dictated outcomes, that shift matters.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.csoonline.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Write cleaner and faster Python code]]></title>
<description><![CDATA[Meta’s long-awaited Pyrefly linter is out in a 1.0 version, and the forthcoming Python 3.15 has a super-efficient sampling profiler. Plus we have a comprehensive rundown of Python’s indispensable virtual environments — and a warning about a novel breed of malware that exploits Python’s package ec...]]></description>
<link>https://tsecurity.de/de/3609845/ai-nachrichten/write-cleaner-and-faster-python-code/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609845/ai-nachrichten/write-cleaner-and-faster-python-code/</guid>
<pubDate>Fri, 19 Jun 2026 11:18:47 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Meta’s long-awaited Pyrefly linter is out in a 1.0 version, and the forthcoming <a href="https://www.infoworld.com/article/4166693/the-best-new-features-in-python-3-15.html" data-type="link" data-id="https://www.infoworld.com/article/4166693/the-best-new-features-in-python-3-15.html">Python 3.15</a> has a super-efficient sampling profiler. Plus we have a comprehensive rundown of Python’s indispensable virtual environments — and a warning about a novel breed of malware that exploits Python’s package ecosystem.</p>



<h2 class="wp-block-heading">Top picks for Python readers on InfoWorld</h2>



<p><a href="https://www.infoworld.com/article/2260103/how-to-use-virtual-environments-in-python.html" data-type="link" data-id="https://www.infoworld.com/article/2260103/how-to-use-virtual-environments-in-python.html">How to use virtual environments in Python</a><br>Isolate and protect your Python projects from each other, and empower them to do more, with virtual environments and their native-to-Python tooling.</p>



<p><a href="https://www.infoworld.com/article/4179383/pyrefly-1-0-a-fast-forward-looking-python-linter.html" data-type="link" data-id="https://www.infoworld.com/article/4179383/pyrefly-1-0-a-fast-forward-looking-python-linter.html">Pyrefly 1.0: A fast, forward-looking Python linter</a><br>The first full release of Meta’s long-awaited linting and type checking tool for Python delivers speed and offers advanced features for type-checking PyTorch and Django projects.</p>



<p><a href="https://www.infoworld.com/video/4085906/hands-on-with-the-new-sampling-profiler-in-python-3-15.html" data-type="link" data-id="https://www.infoworld.com/video/4085906/hands-on-with-the-new-sampling-profiler-in-python-3-15.html">Hands-on with the new sampling profiler in Python 3.15</a><br>Among Python 3.15’s best new features is a sampling profiler, for instrumenting your code and finding its bottlenecks with a minimum of performance impact or fuss. See up-close how it works.</p>



<p><a href="https://www.infoworld.com/article/4182692/meet-hades-the-malware-that-lies-to-ai-security-agents.html" data-type="link" data-id="https://www.infoworld.com/article/4182692/meet-hades-the-malware-that-lies-to-ai-security-agents.html">All about Hades, the supply-chain malware that hides in Python packages</a><br>It hides in Python packages. It replicates itself across systems. It fools LLM-based code analysis tools into ignoring it. And there may be a lot more like it to come.</p>



<h2 class="wp-block-heading">More good reads and Python updates elsewhere</h2>



<p><a href="https://discuss.python.org/t/an-announcement-from-the-steering-council-regarding-the-jit-project/107638" data-type="link" data-id="https://discuss.python.org/t/an-announcement-from-the-steering-council-regarding-the-jit-project/107638">Python Steering Council calls for temporary pause on JIT project</a><br>The requested pause stays in place until a proper Standards Track PEP lands for the experimental JIT (just-in-time) compiler, the better to describe how the JIT will be a formal and supported part of Python.</p>



<p><a href="https://blog.pyodide.org/posts/314-release" data-type="link" data-id="https://blog.pyodide.org/posts/314-release">Pyodide 314.0: Pyodide packages on PyPI</a><br>Thanks to PEP 783, Python packages built with Pyodide (Python ported to WebAssembly) can be installed straight from PyPI instead of through Pyodide — another step closer to Py-on-Wasm becoming an everyday thing.</p>



<p><a href="https://theconsensus.dev/p/2026/06/06/python-3-14-garbage-collection-rigamarole.html" data-type="link" data-id="https://theconsensus.dev/p/2026/06/06/python-3-14-garbage-collection-rigamarole.html">All about that Python 3.14 garbage collection rigmarole</a><br>A new garbage collector introduced in Python 3.14 was yanked at the last minute due to reports of higher memory usage. Here’s a deep dive into what changed for the worse and why.</p>



<p><a href="https://pyrefly.org/blog/too-many-type-checkers" data-type="link" data-id="https://pyrefly.org/blog/too-many-type-checkers">Are you really expected to run five type checkers now?</a><br>No, but you should keep your options open. This blog post from a Pyrefly contributor recommends choosing one of the major offerings (Mypy, Pyrefly, Pyright, ty, Zuban, etc.), but also getting to know the others too. </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Spotify Launches Reserved to Give Premium Fans Early Access to Concert Tickets]]></title>
<description><![CDATA[Spotify has launched Reserved, a new Premium feature that gives eligible fans early access to concert tickets before they go on general sale. The feature is now available in the U.S. for Spotify Premium subscribers who are 18 or older, with ticket access handled through Live Nation and Ticketmast...]]></description>
<link>https://tsecurity.de/de/3609332/ios-mac-os/spotify-launches-reserved-to-give-premium-fans-early-access-to-concert-tickets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609332/ios-mac-os/spotify-launches-reserved-to-give-premium-fans-early-access-to-concert-tickets/</guid>
<pubDate>Fri, 19 Jun 2026 05:53:16 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Spotify has launched Reserved, a new Premium feature that gives eligible fans early access to concert tickets before they go on general sale. The feature is now available in the U.S. for Spotify Premium subscribers who are 18 or older, with ticket access handled through Live Nation and Ticketmaster.



Reserved works by identifying some of an artist’s most dedicated fans and holding up to two tour tickets for them during a limited purchase window. Spotify says eligibility depends on signals such as streams, saves, shares, and location, which helps the platform send offers to fans who are likely to attend the show.



How Spotify Reserved Works







Eligible fans will see a Reserved offer inside the Spotify app, including on the Home screen, Search, the artist’s page, Your Live Events feed, and the Now Playing view. Spotify will also send email and push notifications so users do not miss their ticket window.



Once the Reserved window opens, fans can choose up to two tickets for any eligible date on the tour, rather than only the nearest venue. The purchase window usually lasts around one day, although Spotify recommends buying early for better seat and date options.



After choosing tickets, users will move to Ticketmaster to complete the purchase. Some high-demand shows may place fans in a queue, but Spotify says two tickets on the tour will remain held during the full Reserved window.



Reserved starts with Role Model as the first artist using the feature, and Spotify plans to expand it to more select artists and tours.]]></content:encoded>
</item>
<item>
<title><![CDATA[I found a hidden ChatGPT setting that changes how hard the AI thinks — and the difference surprised me]]></title>
<description><![CDATA[The iOS app version of ChatGPT has a great hidden feature for choosing how intelligent you want your answer to be.]]></description>
<link>https://tsecurity.de/de/3609189/it-nachrichten/i-found-a-hidden-chatgpt-setting-that-changes-how-hard-the-ai-thinks-and-the-difference-surprised-me/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609189/it-nachrichten/i-found-a-hidden-chatgpt-setting-that-changes-how-hard-the-ai-thinks-and-the-difference-surprised-me/</guid>
<pubDate>Fri, 19 Jun 2026 03:01:43 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The iOS app version of ChatGPT has a great hidden feature for choosing how intelligent you want your answer to be.]]></content:encoded>
</item>
<item>
<title><![CDATA[astro.config.mjs Supply Chain Attack via Blockchain C2]]></title>
<description><![CDATA[2026-06-12 • SafeDep
     • SafeDep
     • js.jadesnow
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3607418/malware-trojaner-viren/astroconfigmjs-supply-chain-attack-via-blockchain-c2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607418/malware-trojaner-viren/astroconfigmjs-supply-chain-attack-via-blockchain-c2/</guid>
<pubDate>Thu, 18 Jun 2026 12:48:58 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-06-12 • SafeDep
     • SafeDep
     • js.jadesnow
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/907ea97d-6a68-4520-8ccf-bf5e91c007a6/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The future of insurance is contextual, conversational and customer-first – thanks to AI]]></title>
<description><![CDATA[The insurance industry has long been regarded as a highly regulated, slow-moving monolith. But look closely, and you’ll see that we’re entering a new phase of significant change and overdue optimization – one that puts the consumer experience front-and-center.



I’ve long anticipated this transi...]]></description>
<link>https://tsecurity.de/de/3607142/it-security-nachrichten/the-future-of-insurance-is-contextual-conversational-and-customer-first-thanks-to-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607142/it-security-nachrichten/the-future-of-insurance-is-contextual-conversational-and-customer-first-thanks-to-ai/</guid>
<pubDate>Thu, 18 Jun 2026 11:05:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The insurance industry has long been regarded as a highly regulated, slow-moving monolith. But look closely, and you’ll see that we’re entering a new phase of significant change and overdue optimization – one that puts the consumer experience front-and-center.</p>



<p>I’ve long anticipated this transition. My experience in recent years working on the core machine learning (ML) team at Google taught me that the true value of artificial intelligence is not in hardware efficiency but in the radical personalization it enables. I learned a valuable lesson earlier in my career: Even the most tech-savvy tools can fail if they don’t solve a human problem. It’s a belief that’s been reinforced after recently joining The Zebra team as chief AI officer, a position that empowers me to better employ AI and ML to maximize the synergy between product and technology and make for a more efficient and customer-centric insurance shopping model.</p>



<h2 class="wp-block-heading">From keywords to context</h2>



<p>For years, consumers have used basic SEO keywords to find insurance policies while carriers relied on simple ML to price these policies. But that paradigm is changing quickly. It won’t be long before we see automation processes occurring across several different areas, particularly on the customer-facing side, where we are attempting to collect as much context as we can.</p>



<p>Today, customers provide deep, intent-based context, with a shift toward hyper-personalized, highly detailed queries. The next logical step is for Large Language Models (LLMs) to parse this massive amount of customer intent data and map it against complex and unstructured policy data. This represents both a major challenge and a fantastic opportunity: successfully and efficiently organizing our internal insurance data so that it can be presented back to the consumer. The goal here is to advance to a stage where organizing policy data (the provider side) and collecting information (the customer side) blend to create a perfectly personalized middle ground.</p>



<p>I’ve observed this incredible shift firsthand. Customers used to find The Zebra after using a basic two-word Google keyword search like “car insurance.” But courtesy of LLMs, their queries today are much more specific and customized: “I need car insurance for my 2022 Honda Civic in Austin, Texas, and I park it outside.” Providing this rich data upfront and directly to our advisors changes the whole game, allowing us to bypass tedious intake and start nurturing genuine human relationships.</p>



<p>I love the automation side of AI – especially its ability to eliminate manual data entry. Still, handling sensitive customer information means that AI tooling can quickly throw gasoline on a growing fire. That’s the reason I’m committed to creating a controlled environment. At The Zebra, we’ve spent a decade researching how humans sell policies, and I want to ensure our models don’t “reward hack.” A good illustration of this is an unsupervised model believing that hanging up on every customer ensures it will never technically lose a deal. At our company, it’s my job to build the guardrails that prevent these bizarre optimizations.</p>



<h2 class="wp-block-heading">Exciting developments underfoot</h2>



<p>We’ve entered a sea change moment, signaling a shift toward agentic coding and dynamic UI and away from the hard-coded, static websites that earlier dominated the insurance space. At present, most insurance online portals are linear, with the sequence of questions typically predetermined by a developer. In the coming phase, however, the LLMs will define the questions and the order in which they are asked, and UI components will be chosen or generated ad hoc, depending on the consumer’s particular context. That’s real progress.</p>



<p>Even more than the interface, I’m energized about forthcoming improvements in the agent-to-agent ecosystem. I envision a future where, for example, an online car-buying service like CarEdge or AutoCompanion learns key info about a given user, including their vehicle preferences, budget and safety priorities; then, at the moment the user clicks “buy,” that entire world of context is communicated directly from that website and its human or AI agent to an insurance agent. This layer of interaction eliminates the need for the customer to repeat redundant details while also ensuring that they are instantly offered the best personalized insurance policy.</p>



<p>Peering forward, I’m especially excited about this “agent-to-agent” future. Years ago, I built recommendations, search engines and pricings for a used car e-commerce platform, employing basic filters like “Toyota under $30,000.” But nowadays, people hunt online with so much more context and use conversational AI for nuanced intent, with focused queries like “I need a car for a family of three that fits a bulky stroller.” Extracting that deep context from a vehicle-purchasing AI agent directly into our insurance workflow is a fantastic opportunity to eliminate friction.</p>



<p>Another trend that has me stoked? AI’s increasing ability to help regional insurers structure their data. Smaller insurers, which know their local markets more than national players, have traditionally struggled to aggregate their numbers for digital marketplaces. But by better leveraging AI agents, we can now provide info to customers that was previously difficult to obtain, introducing them to insurance companies that are a better fit.</p>



<p>What’s behind my continued fascination with AI agents? Maybe it has something to do with our corporate culture at The Zebra, which emphasizes creativity, curiosity and fun – as exemplified by our obsession with Legos. Walk into our offices or attend a virtual meeting and you’ll see everyone clicking bricks together. We even commemorate exceptional company or career milestones by gifting Lego sets. These all-ages toys serve as a physical manifestation of a “Tinker mindset.” Legos have taught me that complex architectures are simply collections of tiny but well-defined parts you can remix inventively. When we launched <a href="https://www.linkedin.com/pulse/bricks-bots-vibe-coding-why-future-insurtech-built-daniel-herrington-qvdie/" rel="nofollow">Zebra Labs</a>, it dawned on me that “vibe coding” with AI is akin to playing with digital Legos: Snapping together prompts, models and APIs to construct a security triage agent calls for the same kind of foundational logic needed to assemble a <a href="https://www.lego.com/en-us/product/porsche-911-rsr-42096?consent-modal=show&amp;age-gate=grown_up" rel="nofollow">Lego Technic Porsche 911</a>. To me, this mindset makes AI development feel like an organic extension of how we already work.</p>



<h2 class="wp-block-heading">Navigating challenges ahead</h2>



<p>It’s natural to be optimistic about what’s just beyond the horizon. Still, the industry has to be careful about “AI slop” – using AI to build things too quickly without truly knowing where and how it fits. This is an especially slippery slope when it comes to licensing. Case in point: If you ask an off-the-shelf LLM which policy to purchase for a Porsche (the real, non-Lego kind), it could suggest one that violates licensing laws.</p>



<p>You also have to think ahead about hidden hazards when operating in a regulated financial space. In my previous job at Google, I worked on improving the efficiency of Waymo models; at The Zebra’s Austin headquarters, I constantly see these autonomous vehicles, which have taught me quite a bit about edge cases. A Waymo can spot a city stop sign completely obscured by overgrown leaves thanks to its LiDAR and internal maps, safely stopping the car and logging the danger. At our company, strict compliance rules represent those <a href="https://www.linkedin.com/pulse/seeing-stop-sign-through-trees-how-ai-evals-insurance-herrington-e0nbf/" rel="nofollow">hidden stop signs</a>. Imagine a generic LLM confidently advising a user to drop comprehensive coverage to save a few dollars; doing so means it is acting as an unlicensed advisor – a massive legal liability. The lesson here is that you can’t just give AI the keys, ask it to be professional and simply hope for the best.</p>



<p>To prevent this, I’m creating a digital sensor suite using strict evaluation platforms. This way, before an AI agent can interact with the customer, it has to survive a simulated gauntlet graded on three metrics: factuality (is the information correct?), compliance (did it avoid making a regulated recommendation?) and accuracy (did it hallucinate any features?).</p>



<p>I was recently in Nashville for the Insurance Innovators conference. The audience wanted to know where I’m placing my business bets for The Zebra. My answer was simple: “personalization agents.” I’m investing heavily in resources that evaluate colossal volumes of policy data that can supercharge our human advisors. By extracting the specific data points they require exactly when they need them, I can help eliminate administrative friction and ensure they receive the perfect coverage for their unique risk profiles.</p>



<p>But it’s important to prioritize jobs as we make this transition to more grounded LLMs. This sector isn’t ripe for disruption simply because you can decrease and automate costs by subtracting people from the equation. This next phase I foresee should produce a more synergistic partnership between AI and human beings – especially licensed advisors who make sure we apply hyper-personalization and avoid the kinds of mistakes AI is known for. Yet we also want to unlock an experience so precise that relying solely on human decision-making will eventually feel like an unnecessary risk.</p>



<p>This customer-focused and increasingly bespoke insurance experience I’m dreaming of requires moving beyond simple task automation to a point where data is efficiently structured, and both human and AI agents communicate effectively across platforms. We’re almost there, and everyone – from the policyholder to the underwriter – stands to benefit.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Oukitel WP66 review: An extremely rugged phone that doesn't punish you for choosing durability]]></title>
<description><![CDATA[The Oukitel WP66 is a relatively lightweight rugged phone with a good camera sensor, but not an impressive SoC.]]></description>
<link>https://tsecurity.de/de/3606783/it-nachrichten/oukitel-wp66-review-an-extremely-rugged-phone-that-doesnt-punish-you-for-choosing-durability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606783/it-nachrichten/oukitel-wp66-review-an-extremely-rugged-phone-that-doesnt-punish-you-for-choosing-durability/</guid>
<pubDate>Thu, 18 Jun 2026 08:17:32 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Oukitel WP66 is a relatively lightweight rugged phone with a good camera sensor, but not an impressive SoC.]]></content:encoded>
</item>
<item>
<title><![CDATA[Sama S50: Versetztes Netzteil soll die Kühlung verbes­sern]]></title>
<description><![CDATA[Das Sama S50 will kompakte ATX-Gehäuse „neu definieren“. Dazu muss das Netzteil umziehen. Die Neudefinition beinhaltet jedoch keine Verschiebung von Grenzen, sondern ist mehr als mehr oder minder großer Remix eines Standard-Meshgehäuses zu verstehen.]]></description>
<link>https://tsecurity.de/de/3605775/it-nachrichten/sama-s50-versetztes-netzteil-soll-die-kuehlung-verbessern/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605775/it-nachrichten/sama-s50-versetztes-netzteil-soll-die-kuehlung-verbessern/</guid>
<pubDate>Wed, 17 Jun 2026 20:17:50 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://pics.computerbase.de/1/2/3/3/2/4-f0906c6856d4738b/article-640x360.aa2e08cc.jpg"><p>Das Sama S50 will kompakte ATX-Gehäuse „neu definieren“. Dazu muss das Netzteil umziehen. Die Neudefinition beinhaltet jedoch keine Verschiebung von Grenzen, sondern ist mehr als mehr oder minder großer Remix eines Standard-Meshgehäuses zu verstehen.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[NVIDIA RTX Remix 1.5 Cuts Half-Life 2 RTX Size From 80GB to 50GB With RTX IO Compression]]></title>
<description><![CDATA[NVIDIA has released RTX Remix 1.5, and the biggest change is the addition of RTX IO compression, which helps reduce game file sizes while keeping…
The post NVIDIA RTX Remix 1.5 Cuts Half-Life 2 RTX Size From 80GB to 50GB With RTX IO Compression appeared first on OnMSFT.]]></description>
<link>https://tsecurity.de/de/3605030/windows-tipps/nvidia-rtx-remix-15-cuts-half-life-2-rtx-size-from-80gb-to-50gb-with-rtx-io-compression/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605030/windows-tipps/nvidia-rtx-remix-15-cuts-half-life-2-rtx-size-from-80gb-to-50gb-with-rtx-io-compression/</guid>
<pubDate>Wed, 17 Jun 2026 15:56:20 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>NVIDIA has released RTX Remix 1.5, and the biggest change is the addition of RTX IO compression, which helps reduce game file sizes while keeping…</p>
<p>The post <a href="https://onmsft.com/news/nvidia-rtx-remix-1-5-cuts-half-life-2-rtx-size-from-80gb-to-50gb-with-rtx-io-compression/">NVIDIA RTX Remix 1.5 Cuts Half-Life 2 RTX Size From 80GB to 50GB With RTX IO Compression</a> appeared first on <a href="https://onmsft.com/">OnMSFT</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The end of the AI honeymoon? ChatGPT market share falls below 50% for first time]]></title>
<description><![CDATA[OpenAI still has over a billion monthly active ChatGPT users, but consumers are also increasingly choosing Gemini.]]></description>
<link>https://tsecurity.de/de/3604384/it-nachrichten/the-end-of-the-ai-honeymoon-chatgpt-market-share-falls-below-50-for-first-time/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604384/it-nachrichten/the-end-of-the-ai-honeymoon-chatgpt-market-share-falls-below-50-for-first-time/</guid>
<pubDate>Wed, 17 Jun 2026 12:18:00 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[OpenAI still has over a billion monthly active ChatGPT users, but consumers are also increasingly choosing Gemini.]]></content:encoded>
</item>
<item>
<title><![CDATA[The Linux Desktop Guide by Chris Titus]]></title>
<description><![CDATA[https://preview.redd.it/kfpdqhcuft7h1.png?width=1280&format=png&auto=webp&s=702ee90f73b6bf9ec95e600be1e0480eeafe5495 This is a print or digital paid/free book by Chris Tutus. Practical desktop Linux guidance for new and intermediate users.  I've been on Linux for years and I always wished there w...]]></description>
<link>https://tsecurity.de/de/3604365/linux-tipps/the-linux-desktop-guide-by-chris-titus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604365/linux-tipps/the-linux-desktop-guide-by-chris-titus/</guid>
<pubDate>Wed, 17 Jun 2026 12:10:22 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p><a href="https://preview.redd.it/kfpdqhcuft7h1.png?width=1280&amp;format=png&amp;auto=webp&amp;s=702ee90f73b6bf9ec95e600be1e0480eeafe5495">https://preview.redd.it/kfpdqhcuft7h1.png?width=1280&amp;format=png&amp;auto=webp&amp;s=702ee90f73b6bf9ec95e600be1e0480eeafe5495</a></p> <p>This is a print or digital paid/free book by Chris Tutus.</p> <p>Practical desktop Linux guidance for new and intermediate users.</p> <blockquote> <p>I've been on Linux for years and I always wished there was ONE book that gave me a real foundation — not a distro tier list, not 1,000 pages of niche edge cases, just a practical guide to understanding Linux and making it your own. So I wrote it.</p> <p>The Linux Desktop Guide covers everything from choosing a distro (Debian, Red Hat, or Arch buckets), understanding what makes up a Linux system, picking your bootloader, desktop environment, and display server, to ~100 pages of terminal commands and troubleshooting you'll actually use.</p> <p>📖 Physical copy (Amazon): <a href="https://www.amazon.com/Linux-Desktop-Guide-Chris-Titus/dp/B0H2YNG9DR?language=en_US">https://www.amazon.com/Linux-Desktop-Guide-Chris-Titus/dp/B0H2YNG9DR?language=en_US</a></p> <p>💾 Digital / EPUB (cttstore.com): <a href="https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqbk9RbWt3bEdselY3N1BFdXYyaEVpb1hjX0VrQXxBQ3Jtc0trcmVZSW1DbEppQ2lKck9PS3pKWjZZVG9FZGRlby1WYUJEcWlhczY3alJrNTlHeGtzTDBNdDYtZTZORFRNMS0zb0xFUllMR00tVENSRW12TDVMMnppV1VtNE1zaVBqLWxnN2pTRXJxY1JQcWpZX2JuWQ&amp;q=https%3A%2F%2Fcttstore.com%2F&amp;v=dVmXcRwIobA">https://cttstore.com</a></p> <p>🌐 <strong>Free</strong> Online: <a href="https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqbWJfNW1PWGpsQmduSHdoaHliTkZ0STdOZ1VqQXxBQ3Jtc0tsdnVwYnBxalpuMGl5RDZxOEFMN0hEdkRQaC1oR1JtRVZJa2pJbk9wanFlYnBYNnpGSVQ1ZnZTNGpHbV9XYUIzTkV0U1N5cmJPekxudGNTMFdmTE9XTlRDSHZ0b0lNc0FYaEswMnE2ZDlYaFd1ZEdvZw&amp;q=https%3A%2F%2Fthelinuxbook.com%2F&amp;v=dVmXcRwIobA">https://thelinuxbook.com</a></p> <p>The book is also a reference to over 1,000 of my YouTube videos — each topic links out to companion videos so you can go deeper on anything that interests you. It's designed to be written in, highlighted, and kept on your desk.</p> <p>I'll be updating it annually. If something's missing, drop a comment or open an issue on the GitHub repo.</p> </blockquote> <p>I hope all of you dive this well written book.</p> <p>For the quick review by the author:</p> <p><a href="https://www.youtube.com/watch?v=dVmXcRwIobA">https://www.youtube.com/watch?v=dVmXcRwIobA</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/BlokZNCR"> /u/BlokZNCR </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1u85rcp/the_linux_desktop_guide_by_chris_titus/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1u85rcp/the_linux_desktop_guide_by_chris_titus/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[5 AI risk management frameworks for shoring up key gaps]]></title>
<description><![CDATA[Organizations racing to embed AI into business operations are realizing that the risk management frameworks they’ve relied on for decades aren’t built for the behaviors, failure modes, and ethical complexities AI systems introduce.



Fortunately, a new generation of AI-specific frameworks has em...]]></description>
<link>https://tsecurity.de/de/3604146/it-security-nachrichten/5-ai-risk-management-frameworks-for-shoring-up-key-gaps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604146/it-security-nachrichten/5-ai-risk-management-frameworks-for-shoring-up-key-gaps/</guid>
<pubDate>Wed, 17 Jun 2026 11:09:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Organizations racing to embed AI into business operations are realizing that the risk management frameworks they’ve relied on for decades aren’t built for the behaviors, failure modes, and ethical complexities AI systems introduce.</p>



<p>Fortunately, a new generation of AI-specific frameworks has emerged to give organizations a structured way to identify where AI can go wrong, what controls to put in place, and how to demonstrate responsible AI use to regulators, customers, and investors. Not all of these emerging frameworks address the same problem. Some focus on governance and organizational accountability, others on technical security controls, threat modeling, or regulatory compliance. Choosing the right one for your organization depends on where your most pressing gaps reside.</p>



<p>The frameworks are complementary, not competing, because they have different intents, priorities, and objectives, says Nicole Carignan, CISO at Darktrace.</p>



<p>“There is overlap across these frameworks, but that overlap is helpful,” Carignan points out. “It reinforces the core practices organizations need to get right: governance, data integrity, security, accountability, oversight, testing, and continuous improvement.”</p>



<p>Here are five frameworks worth considering for your AI risk management needs.</p>



<h2 class="wp-block-heading">ISO/IEC 42001 Artificial Intelligence Management System</h2>



<p><a href="https://www.iso.org/standard/81230.html">ISO/IEC 42001:2023</a> is the first internationally recognized formal standard for AI management. Published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) in December 2023, ISO/IEC 42001 follows a similar structure to management system standards such as ISO 27001. The framework gives organizations a structured methodology for establishing policies, processes, operational controls, and accountability mechanisms to ensure responsible development and use of AI.</p>



<p>ISO/IEC 42001 requires companies to document how they design, monitor, validate, and control AI systems, while also requiring them to conduct AI impact assessments to evaluate potential legal, ethical, and societal impacts. The standard covers governance structures, third-party supplier oversight, data management, transparency obligations, and lifecycle management.</p>



<p>ISO/IEC 42001 is a voluntary but certifiable standard that applies across sectors and organization sizes. A growing number of organizations have begun using it to demonstrate adherence to responsible AI practice and alignment with regulations such as the <a href="https://artificialintelligenceact.eu/">EU AI Act</a>. The ISO/IEC have <a href="https://www.iso.org/home/insights-news/resources/iso-42001-explained-what-it-is.html?utm_source=chatgpt.com">described the framework</a> as helping organizations align their AI practices with legal and regulatory requirements; demonstrate responsible AI governance; manage risks tied to bias, safety, and security; and enhance stakeholder trust.</p>



<p>ISO 42001 is a great option for organizations just getting started with AI risk management, says Nicole Carignan, senior vice president for security and AI strategy and field CISO at Darktrace.</p>



<p>“It provides the strongest foundation for building an AI risk management program, rather than addressing individual AI risks in isolation,” she explains. “From a program-building standpoint, ISO 42001 is the right place to start because it forces organizations to think holistically about ownership, governance, oversight, data integrity, security risk mitigation, accountability, and continuous improvement.”</p>



<p>One downside Carignan is that the framework is resource-intensive to implement, and the full standard is not publicly available. Both challenges can be formidable for organizations that are very early in their AI governance journey, she says.</p>



<h2 class="wp-block-heading">NIST AI Risk Management Framework (AI RMF)</h2>



<p>Released by the US National Institute of Standards and Technology (NIST) in January 2023, the <a href="https://airc.nist.gov/AI_RMF_Knowledge_Base/AI_RMF">AI Risk Management Framework (AI RMF)</a> is a voluntary framework designed to help organizations of all sizes and across all sectors identify, assess, and manage risks associated with AI systems across their entire lifecycle.</p>



<p>The framework consists of two parts. The first offers guidance on how organizations should think about AI risks and the characteristics of trustworthy AI systems, such as validity, safety, security, transparency, explainability, privacy, and fairness. The second part is structured around four interconnected functions:</p>



<ul class="wp-block-list">
<li><strong>Govern</strong> focuses on what organizations need to do to build internal culture, policies, and accountability structures for AI use.</li>



<li><strong>Map</strong> involves understanding the broader context and potential risks of specific AI systems.</li>



<li><strong>Measure</strong> focuses on how organizations must evaluate and track those risks using both qualitative and quantitative methods.</li>



<li><strong>Manage</strong> provides guidance on risk prioritization and appropriate responses such as mitigation, transfer, or acceptance.</li>
</ul>



<p>NIST AI RMF includes a separate Playbook that provides practical implementation steps to help organizations implement each of these functions effectively.</p>



<p>For organizations that are not ready to pursue ISO 42001 formally, the NIST AI RMF can serve as a more flexible and accessible starting point, Carignan says.</p>



<p>“It is public and gives organizations a common language for understanding and mitigating AI risk,” she adds. “But if the goal is to build a durable AI risk program, ISO 42001 is the strongest foundation.”</p>



<p>Ram Varadarajan, CEO at Acalvio recommends NIST AI RMF as a good place for organization to get started on AI risk governance, “because it’s built around maturity rather than pass/fail audits.” Its gives organizations starting from zero an opportunity to discover where they stand rather than immediately handing out a failing grade.</p>



<p>“More importantly, it forces the three conversations that have to happen first: who owns AI risk, what AI is actually running, and who gets hurt if something goes wrong,” Vardarajan says.</p>



<p>While researchers at Forrester described NIST AI RMF as a <a href="https://www.forrester.com/blogs/nist-ai-risk-management-framework-1-0-what-it-means-for-enterprises/">step in the right direction</a> soon after its launch, they also expressed concern over conflicts of interest among the multiple stakeholders that helped draft the framework, the absence of an explicit role for data governance, and the fact that the framework was “still descriptive and not prescriptive.”</p>



<p>As a result, “Chief data officers and heads of data science need to navigate this framework wisely to interpret and apply it to their AI governance efforts,” the analyst firm advised.</p>



<h2 class="wp-block-heading">ENISA Framework for AI Cybersecurity Practices</h2>



<p>ENISA, the European Union Agency for Cybersecurity, developed its <a href="https://www.faicp-framework.com/">Framework for AI Cybersecurity Practices (FAICP)</a> in anticipation of the <a href="https://artificialintelligenceact.eu/">EU AI Act</a>. Published in June 2023, the framework gives EU organizations structured, AI-specific cybersecurity guidance for enhancing the trustworthiness of their AI activities.</p>



<p>FAICP is organized around three progressive layers. The first covers foundational information and communications technology cybersecurity practices that AI systems inherit by running on standard software infrastructure. The second addresses <a href="https://www.csoonline.com/article/4110008/top-cyber-threats-to-your-ai-systems-and-infrastructure.html">AI-specific risks</a>, including adversarial attacks, model tampering, data pipeline integrity, and <a href="https://www.csoonline.com/article/4015077/ai-supply-chain-threats-are-looming-as-security-practices-lag.html">supply chain security</a>. The third provides sector-specific guidance for regulated industries such as energy, healthcare, and telecommunications.</p>



<p>According to the European Parliament, FAICP’s layered nature provides organizations with “a gradual approach” to enhancing the trustworthiness of their AI activities.</p>



<p>FAICP is voluntary, but its close alignment with the EU AI Act and the <a href="https://www.enisa.europa.eu/topics/awareness-and-cyber-hygiene/raising-awareness-campaigns/network-and-information-systems-directive-2-nis2">NIS2 Directive</a>, which is the EU’s primary cybersecurity law, means that EU regulators consider the framework as a baseline for AI governance practices at all organizations doing business within the EU.</p>



<p>FAICP is important because “Europe’s AI Act will likely become the global reference point, the same way Europe’s data privacy law became the de facto standard for companies worldwide regardless of where they’re headquartered,” Vardarajan predicts.</p>



<p>“Within two to three years, expect two frameworks to dominate: the EU AI Act setting the legal floor, and NIST AI RMF providing the operational playbook for meeting it,” Vardarajan says.</p>



<h2 class="wp-block-heading">ISO/IEC 23894:2023 Information Technology — Artificial Intelligence — Guidance on Risk Management</h2>



<p>The <a href="https://www.iso.org/standard/77304.html">ISO/IEC 23894:2923</a> framework provides organizations with specific guidance on managing risks associated with artificial intelligence. Released jointly by ISO and IEC in February 2023, the framework builds on and adapts the ISO 31000 general risk management standard to address AI-specific risks such as those tied to<strong> </strong>algorithmic bias, model drift, unpredictable behavior, and lack of transparency in decision-making. It provides organizations a way to evaluate the likelihood and potential consequences of these risks throughout the full AI system lifecycle.</p>



<p>The ISO has <a href="https://iso-library.com/standard/23894/">described the standard</a> as a “companion to ISO 31000 (Risk Management) and ISO/IEC 42001 (AI Management Systems).” The main difference between ISO/IEC 42001 and ISO/IEC 23894 is that the former is a certifiable management system. It provides organizations with the full requirements for establishing, implementing, and maintaining an AI management system. ISO/IEC 23894:2023 on the other hand is a guidance-only standard focused on how to identify, assess, and manage AI-specific risks.</p>



<p>“Notably, ISO/IEC 23894 offers concrete examples of effective risk management implementation and integration throughout the AI development lifecycle and provides detailed information on AI-specific risk sources,” according to UK-backed <a href="https://aistandardshub.org/a-new-standard-for-ai-risk-management">AI Standards Hub</a>. “A key benefit of this standard is that application of the guidance can be customized to any organization and its business context.”</p>



<h2 class="wp-block-heading">Google Secure AI Framework (SAIF)</h2>



<p><strong><a href="https://saif.google/">Google Secure AI Framework (SAIF)</a></strong> is Google’s practical guide for helping organizations develop and run AI systems with strong built-in protections against digital threats. Launched in 2023, it focuses on weaving security and privacy considerations directly into every stage of an AI project’s life cycle, from design through deployment and ongoing operation.</p>



<p>Its main goal is to tackle the unique vulnerabilities that come with AI technologies such as attacks that tamper with training data, trick models through engineered prompts, or steal sensitive information. SAIF draws on Google’s own experiences developing and deploying large scale AI systems and therefore is more engineering-heavy than other frameworks. SAIF is largely focused on helping organizations make their AI systems more resistant to cyberattacks and cyber adversaries and covers areas like data handling, underlying infrastructure, the AI models themselves, user-facing applications and verification processes. It offers organizations practical guidance on implementation controls, shared responsibility, and defending against technical attacks.</p>



<p>Technology consultancy Thoughtworks has assessed SAIF as a framework that helps organizations systematically address “common threats such as data poisoning and prompt injection through a clear risk map, component analysis, and practical mitigation strategies.” According to the firm, SAIF’s “focus on the evolving risks of building agentic systems especially timely and valuable. SAIF offers a concise, actionable playbook that teams can use to strengthen security practices for LLM usage and AI-driven applications.”</p>



<p>David Brumley, chief AI and science officer at Bugcrowd, says that for organizations that want to adopt a framework, the question is not really “which AI risk framework is best?” but “which framework helps [the] organization safely build, deploy, and learn from AI in the real world?”</p>



<p>While most of the currently available AI risk frameworks have their use, most are still focused on preventing bad outcomes rather than helping organizations pave safe roads for a technology that is already inevitable.</p>



<p>“That distinction matters,” Brumley says. “AI adoption is not waiting for perfect governance, and those who focus on a [risk management framework] could inadvertently create a shadow AI problem in their organization.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[v16.0.3]]></title>
<description><![CDATA[@oh-my-pi/pi-ai
Added

Exported renderDelimitedThinking from the @oh-my-pi/pi-ai/dialect barrel so consumers can reuse the dialect's  envelope unwrap-and-rewrap logic (the only ./dialect/rendering primitive re-exported; the rest stay dialect-internal).

Fixed

Fixed OpenAI Responses/Codex tool sc...]]></description>
<link>https://tsecurity.de/de/3603377/tools/v1603/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603377/tools/v1603/</guid>
<pubDate>Wed, 17 Jun 2026 02:23:16 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>@oh-my-pi/pi-ai</h2>
<h3>Added</h3>
<ul>
<li>Exported <code>renderDelimitedThinking</code> from the <code>@oh-my-pi/pi-ai/dialect</code> barrel so consumers can reuse the dialect's <code>&lt;thinking&gt;</code> envelope unwrap-and-rewrap logic (the only <code>./dialect/rendering</code> primitive re-exported; the rest stay dialect-internal).</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed OpenAI Responses/Codex tool schema normalization stripping provider-rejected regex lookaround patterns from MCP tool parameter schemas. (<a href="https://github.com/can1357/oh-my-pi/issues/2784" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2784/hovercard">#2784</a>)</li>
<li>Fixed OpenAI Responses parallel tool-call routing so late keyed argument deltas for a closed call are dropped instead of being appended to another open call.</li>
</ul>
<h2>@oh-my-pi/pi-coding-agent</h2>
<h3>Added</h3>
<ul>
<li>Added support for LaTeX color commands (<code>\textcolor</code>, <code>\colorbox</code>, and <code>\fcolorbox</code>) in user-visible terminal prose and final chat to colorize output</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Changed STT dependency setup to validate recorder and model assets per <code>stt.modelName</code>, so switching speech models re-runs dependency checks and downloads for the new model</li>
<li>Changed STT startup with cached models to warm the speech model in the background and defer full model loading until transcription begins, reducing push-to-talk start latency</li>
<li>Allowed user-visible terminal and final-chat responses to include LaTeX math delimiters/commands and Mermaid <code>```mermaid</code> diagrams</li>
<li>Changed the hold-<code>Space</code> push-to-talk gesture to recognize a held bar from the <em>regularity</em> of the OS key auto-repeat rather than a raw space count or speed alone, so it no longer spams the editor, no longer eats deliberate space taps, and no longer triggers when the bar is smashed. Recording starts only after two consecutive inter-space deltas are "mechanical" — both fast (within ~120 ms) and near-identical, the metronomic signature of auto-repeat; the few pre-burst spaces typed are then tracked back out. Smashing (fast but jittery) and deliberate spacing (steady but slow) both keep typing real spaces and never start recording.</li>
<li>Updated markdown Mermaid rendering to color ASCII diagrams with the active theme and automatically choose a narrower layout that better fits the terminal width</li>
<li>Made the watched-session transcript sent to the advisor (and shown by <code>/advisor dump</code>) clearer: each turn now opens with a <code>### Session update</code> heading; watched-agent roles render as inline <code>**agent**:</code> / <code>**user**:</code> labels instead of level-2 headings that collided with the advisor's own turns; consecutive same-role messages collapse under one label (the watched agent emits one assistant message per tool call); and batched updates are joined by a blank line rather than a <code>---</code> rule.</li>
<li>Changed the compact transcript tool-intent prefix (<code>history://</code>, <code>/advisor dump</code>) from <code># </code> to <code>// </code> so intent lines read as comments instead of rendering as Markdown H1 headings.</li>
<li>Changed the advisor advice injected into the primary transcript from a <code>Advisor (...): - [severity] note</code> prose block to one <code>&lt;advisory severity="…" guidance="weigh, don't blindly obey"&gt;…&lt;/advisory&gt;</code> element per note, with XML-escaped bodies. (Relocated the shared <code>escapeXmlText</code> helper to <code>@oh-my-pi/pi-utils</code>.)</li>
<li>Reverted <code>/dump</code> and <code>/advisor dump raw</code> to the pre-16.x full verbose dump: system prompt, model/thinking config, tool inventory with parameters, and the message transcript rendered with markdown role headings (<code>## User</code>, <code>## Assistant</code>, <code>### Tool Call: &lt;name&gt;</code> with the call's <code>_i</code> intent as a <code>//</code> comment under the heading and the remaining arguments as a fenced YAML block, <code>### Tool Result: &lt;name&gt;</code>, plus <code>## Bash Execution</code>/<code>## File Mention</code>/summary sections) instead of the model's native-dialect turn envelopes and <code>&lt;invoke&gt;</code>/<code>&lt;parameter&gt;</code> XML tool calls. Dropped the compact default and the <code>[raw]</code> flag on <code>/dump</code>; the compact <code>→ tool(...) ⇒ ok</code> history format is no longer reachable from <code>/dump</code>. <code>/advisor dump</code> still defaults to compact, and <code>/advisor dump raw</code> now renders the same markdown dump (previously the model's native-dialect envelopes).</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed Whisper STT cache detection to require both encoder and decoder <code>.onnx</code> files, so partial model downloads now trigger a proper foreground download instead of being treated as fully cached</li>
<li>Fixed same-process <code>JsRuntime</code> cleanup so disposing an older inline/direct runtime no longer deletes a newer runtime's JS helper globals; inactive cmux/direct runtimes now re-activate their globals before sequential use while overlapping cross-runtime runs fail explicitly.</li>
<li>Fixed magic-keyword steering notices (<code>ultrathink-notice</code>, <code>orchestrate-notice</code>, <code>workflow-notice</code>) to be prepended before the related user message so they influence that same turn</li>
<li>Fixed dequeuing or popping queued user messages to remove their preceding hidden magic-keyword notice companions, preventing orphaned queued notices</li>
<li>Fixed queued user steers to auto-resume after interrupts even when the transcript tail is a preserved advisor card or other non-conversational custom message</li>
<li>Fixed queued user follow-up messages to remain queued after an interrupt and only run on explicit resume, even when an IRC wake leaves a provider-valid tail</li>
<li>Fixed stranded IRC asides to wake a response turn after interruption instead of remaining pending</li>
<li>Fixed accepted IRC asides to be flushed into the transcript during disposal instead of being discarded</li>
<li>Fixed interactive submissions made while the TUI had no active input waiter: they now start a real prompt directly, with steer fallback if a background turn races in, instead of queueing behind a non-resumable idle transcript and appearing to do nothing.</li>
<li>Fixed pressing Esc (or Alt+Up dequeue) while agent-authored messages were queued — advisor concern/blocker notes, hidden goal/plan/budget steers, IRC/extension asides — dumping their text into the user's editor. Editor restoration (<code>clearQueue()</code>), pending chips (<code>getQueuedMessages()</code>), and <code>popLastQueuedMessage()</code> now surface only genuinely user-authored queued messages (plain user turns and <code>attribution: "user"</code> custom messages like <code>/skill</code>). Plain Alt+Up dequeue leaves all other queued messages in place for the continuing stream; only the Esc interrupt path keeps just advisor cards (so abort's preservation still re-records them as visible advice) and drops other internal steers, so a user interrupt can't be silently undone by an auto-resume on leftover internal context. <code>queuedMessageCount</code> still reflects all actual queued work (advisor cards included) so <code>hasPendingMessages()</code>/RPC and the empty-submit abort gate stay accurate.</li>
<li>Fixed advisor <code>concern</code>/<code>blocker</code> advice being withheld from the running agent and then dumped as one burst at the next user prompt after a deliberate interrupt. A user interrupt latches advisor auto-resume suppression, but a non-user resume (synthetic/auto-continue, or a queued steer draining after the abort) leaves the run streaming with that latch still set, so every interrupting note was parked hidden in the next-turn queue instead of steered into the live turn — the agent never heard the advisor mid-run and the backlog flushed all at once on the next prompt. Suppression now only withholds interrupting advice while the agent is idle (or still tearing the interrupted turn down); once a turn is streaming again the note is steered in live, since steering an active run never auto-resumes a stopped one. A concern that strands in the steer queue past the resumed turn's final poll is reclaimed as visible advice when the agent settles (mirroring abort), so it neither auto-resumes the stopped run nor lingers to flush at the next prompt.</li>
<li>Fixed <code>omp --continue</code>/<code>-c</code> sometimes resuming into a subagent transcript instead of the interactive session. Subagent (and HTML-export) <code>SessionManager.open()</code> calls run in the parent's terminal and were clobbering the per-TTY <code>--continue</code> breadcrumb with their own artifact-dir session file; these headless opens now suppress the breadcrumb. <code>continueRecent()</code> also recovers already-poisoned breadcrumbs by resolving any session file inside a parent's artifacts dir (<code>&lt;parent&gt;/&lt;agentId&gt;.jsonl</code>) back up to the top-level session.</li>
<li>Fixed the Agent Hub stacking duplicate <code>Agent Hub · N running</code> frames and stranding garbage rows in scrollback while navigating with subagents still streaming. The hub was a non-fullscreen overlay composited over a live transcript, so each time a running subagent's progress grew the frame and scrolled the window the previously-painted hub copy was pushed permanently into the terminal's native scrollback (which the engine can't rewrite). It now renders inline in the editor slot — the same anchored region every other selector and the <code>ask</code> tool use — riding the normal append-only commit path, so the transcript commits above it exactly once and the hub repaints in place instead of leaking copies. (Avoids borrowing the alternate screen.)</li>
<li>Fixed every subagent registering itself as its own parent in the agent registry (<code>parentId === id</code>), so the Agent Hub rendered each agent as <code>sub · of &lt;itself&gt;</code> and the ←← parent-navigation gesture looped on the same agent. The SDK was reusing <code>parentTaskPrefix</code> — the agent's own artifact/output-id prefix — as the registry parent link; spawns now pass a separate <code>parentAgentId</code> (the spawning agent's id: <code>Main</code> for top-level <code>task</code> spawns, the parent subagent for nested spawns and eval <code>agent()</code>, the focused agent for <code>/tan</code>) and the registry records that as the parent.</li>
<li>Fixed messaging a <code>parked</code> subagent that was restored from disk (Agent Hub scan, or a resumed/restarted session) failing with <code>cannot be revived (no reviver registered)</code> even though its transcript was intact. Such refs carry a session file but no in-memory reviver — the executor's live reviver closure dies with the spawning turn/process — so IRC sends and Agent Hub focus refused them. <code>AgentLifecycleManager.ensureLive</code> now cold-revives them through a persisted-subagent reviver factory (installed by the top-level interactive/RPC session) that rebuilds the subagent from its JSONL the way <code>--resume</code> rebuilds a session: it reopens the file and replays it through <code>createAgentSession</code>, but sources the runtime contract from a now-readable <code>session_init</code> record (<code>SessionManager.peekSessionInit</code>) so tools, system prompt, output schema, and kind are restored rather than resurrected as a default top-level session. <code>session_init</code> now also persists the effective <code>spawns</code> allowlist and read-summarization flag so a cold revive keeps the original capability surface (old files without them deny re-spawning rather than defaulting to wildcard). Isolated runs and pre-<code>session_init</code> files whose recorded workspace no longer exists stay transcript-only (<code>history://</code>).</li>
<li>Fixed the terminal window-title OSC writes (<code>setTerminalTitle</code>/<code>pushTerminalTitle</code>/<code>popTerminalTitle</code>) leaking escape sequences to a developer's terminal during <code>bun test</code>; they now skip when the terminal is headless (the test-runtime default), matching the <code>ProcessTerminal</code> render/probe suppression so interactive-mode tests no longer paint to the real terminal</li>
<li>Fixed empty CLI sessions being retained after opening <code>omp</code> and exiting without a prompt (<a href="https://github.com/can1357/oh-my-pi/issues/2800" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2800/hovercard">#2800</a>).</li>
<li>Fixed <code>hooks/pre/*.ts</code> and <code>hooks/post/*.ts</code> files discovered through <code>hookCapability</code> being registered in discovery but never loaded into the extension runner, so their <code>tool_call</code> handlers now run without a manual <code>settings.json</code> <code>extensions</code> entry (<a href="https://github.com/can1357/oh-my-pi/issues/2796" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2796/hovercard">#2796</a>).</li>
<li>Fixed startup model fallback choosing the plain OpenAI <code>gpt-5.5</code> provider before the Codex OAuth provider when both shared the same default model id, which could surface a misleading OpenAI 401 despite valid Codex credentials (<a href="https://github.com/can1357/oh-my-pi/issues/2807" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2807/hovercard">#2807</a>).</li>
<li>Fixed local auto-thinking classification for reasoning-capable tiny models by giving them the same safe answer budget as online reasoning classifiers, with a larger local floor for non-reasoning tiny models (<a href="https://github.com/can1357/oh-my-pi/issues/2808" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2808/hovercard">#2808</a>).</li>
</ul>
<h3>Removed</h3>
<ul>
<li>Removed the built-in <code>render_mermaid</code> tool and its <code>renderMermaid.enabled</code> setting, so it can no longer be invoked directly</li>
</ul>
<h2>@oh-my-pi/collab-web</h2>
<h3>Removed</h3>
<ul>
<li>Removed rendering support for the <code>render_mermaid</code> tool from the web tool registry</li>
</ul>
<h2>@oh-my-pi/pi-tui</h2>
<h3>Added</h3>
<ul>
<li>Added <code>\tfrac</code> support to stacked display-math rendering so it now displays as a vertical fraction in <code>latexToBlock</code> output</li>
<li>Added markdown parsing for own-line display-math blocks (<code>$$...$$</code> and <code>\[...\]</code>) and delimiter-free <code>\begin{...}...\end{...}</code> math environments so block equations render via LaTeX-to-Unicode</li>
<li>Added stacked rendering of display-math fractions (<code>\frac</code>, <code>\dfrac</code>, <code>\cfrac</code>): the numerator is drawn over a horizontal bar over the denominator, with surrounding terms and <code>align</code>/<code>equation</code>-style environment rows aligned to the bar. Triggered for own-line <code>$$</code>/<code>\[</code> blocks, bare <code>\begin{...}</code> environments, and a paragraph whose sole content is a single display-math span; inline <code>$...$</code> fractions stay single-line (<code>½</code>, <code>(a+b)/c</code>)</li>
<li>Added bare math auto-rendering in <code>renderMathInText</code> for math-shaped lines and math environment blocks that omit <code>$</code>/<code>\(</code> delimiters</li>
<li>Added LaTeX-to-Unicode rendering for markdown math spans, converting <code>$$...$$</code>, <code>$...$</code>, <code>\(...\)</code>, and <code>\[...\]</code> into readable Unicode in Markdown output</li>
<li>Exported LaTeX conversion helpers from the package entrypoint so consumers can call <code>latexToUnicode</code>, <code>latexToBlock</code>, <code>renderMathInText</code>, <code>inlineMathSpanEnd</code>, and <code>isBareMathEnvironment</code> directly</li>
<li>Expanded LaTeX-to-Unicode conversion coverage for additional math fonts, delimiters, extensible arrows, layout environments, cancel/brace annotations, references, and AMS symbols</li>
<li>Added ANSI color rendering for LaTeX <code>\textcolor</code>, scoped <code>\color</code>, <code>\colorbox</code>, and <code>\fcolorbox</code>, including xcolor/CSS color parsing and truecolor/256-color terminal output</li>
<li>Added an optional <code>maxWidth</code> parameter to <code>MarkdownTheme.resolveMermaidAscii</code> to allow diagram resolvers to fit ASCII output to the available content width</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Changed markdown math rendering to preserve multiline layout for display equations, keeping <code>\\</code> row breaks as separate output lines (including inside list items)</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed <code>alignat</code>/<code>alignedat</code>/<code>gatheredat</code> rendering in <code>latexToBlock</code> so the required <code>{n}</code> preamble is not rendered as visible math content</li>
<li>Fixed math parsing to leave non-math LaTeX snippets (for example <code>\begin{itemize}</code>) and fenced code blocks as literal text instead of rendering them as math</li>
<li>Fixed <code>renderInlineMarkdown</code> to handle top-level display-math tokens so raw <code>$$...$$</code> delimiters are no longer leaked</li>
<li>Fixed inline math span detection so escaped dollars and currency-like patterns (such as <code>$5</code> and <code>$10</code>) are not converted as math</li>
<li>Fixed Mermaid diagram rendering in Markdown code blocks to clip each ASCII line to content width before wrapping, preventing preformatted diagram rows from fragmenting</li>
<li>Fixed fullscreen overlays losing keyboard focus to hidden prompt surfaces, which could make settings unresponsive while a background approval request was pending (<a href="https://github.com/can1357/oh-my-pi/issues/2789" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2789/hovercard">#2789</a>).</li>
<li>Fixed <code>bun test</code> runs inside a real terminal leaking TUI output: <code>ProcessTerminal</code> now honors a headless test-runtime default, so frame paints, <code>start()</code> capability probes (OSC 11 / DA1 / kitty), the progress keepalive, notifications, and teardown escapes no longer reach the developer's terminal, and stdin raw mode is never engaged. Previously <code>#safeWrite</code> only skipped on <code>!process.stdout.isTTY</code>, so a developer running the suite in an interactive terminal saw stray status/editor boxes and probe queries. Terminal-contract suites opt back into real I/O via <code>setTerminalHeadless(false)</code></li>
</ul>
<h2>@oh-my-pi/pi-utils</h2>
<h3>Added</h3>
<ul>
<li>Added <code>escapeXmlText</code> utility to escape XML-significant characters <code>&amp;</code>, <code>&lt;</code>, and <code>&gt;</code> in element body text</li>
<li>Added <code>isTerminalHeadless()</code> / <code>setTerminalHeadless()</code> to centrally suppress real-terminal side effects (stdout escape/frame writes, stdin raw mode, CSI/OSC capability probes, SIGWINCH, window-title changes, emergency restore) under the test runtime. Defaults on when <code>bun test</code> sets <code>NODE_ENV=test</code>; terminal-contract tests opt out via <code>setTerminalHeadless(false)</code></li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>fix(tui): keep overlay focus above hidden prompts by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4676940403" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2795" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2795/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2795">#2795</a></li>
<li>fix(coding-agent): load discovered hook factories by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4677385980" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2798" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2798/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2798">#2798</a></li>
<li>fix(cli): skip empty session persistence by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4677808827" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2804" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2804/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2804">#2804</a></li>
<li>fix(coding-agent): prefer Codex default auth by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4678553738" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2810" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2810/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2810">#2810</a></li>
<li>fix(coding-agent): expand local auto-thinking classifier budget by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4678723092" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2814" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2814/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2814">#2814</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/can1357/oh-my-pi/compare/v16.0.2...v16.0.3"><tt>v16.0.2...v16.0.3</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[We should defeat spotify with a beautiful copyleft streaming app]]></title>
<description><![CDATA[Lately I've been thinking about copyleft vs piracy. We all know about Linux and the GNU project's mission to "liberate cyberspace". Using the legal system against itself via copyleft licenses was a genius idea. Thanks to copyleft, we get to enjoy a rich alternative ecosystem of free software driv...]]></description>
<link>https://tsecurity.de/de/3603372/linux-tipps/we-should-defeat-spotify-with-a-beautiful-copyleft-streaming-app/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603372/linux-tipps/we-should-defeat-spotify-with-a-beautiful-copyleft-streaming-app/</guid>
<pubDate>Wed, 17 Jun 2026 02:06:29 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Lately I've been thinking about copyleft vs piracy.</p> <p>We all know about Linux and the GNU project's mission to "liberate cyberspace". Using the legal system against itself via copyleft licenses was a genius idea.</p> <p>Thanks to copyleft, we get to enjoy a rich alternative ecosystem of free software driven by community, collaboration and fairness. It's 2026, and copyleft software continues to empower its users, meanwhile big tech is in its "exploit and control" era...</p> <p>I love that Linux proved to the world that we don't have to exist in a corporate copyright hellscape. We as users are empowered instead of controlled. We aren't just "consumers" - we have the power to remix the software we use.</p> <p>I think Linux was successful precisely because it operates <strong>within</strong> our existing legal framework. Linux isn't illegal. It's not a "pirated" copy of Windows. To me, pirated software doesn't make the same statement as copyleft software. A piracy social movement can't gain steam, because it's illegal, seen by many as taboo and is up against our powerful legal system and government. Meanwhile, a copyleft social movement isn't taboo and uses the legal system to its own advantage.</p> <p>All this has me thinking: <strong>we should prove the success of copyleft in music too!</strong></p> <p>It seems like pirating music is the norm among Linux users.</p> <p>Instead of pirating music (which will never be mainstream and puts us at risk), we should work together develop a gooey, beautiful streaming app for copyleft music. Something even normies can appreciate. All of the music on this hypothetical streaming platform would be free to download, share and remix (all CC0, CC-BY or CC-BY-SA).</p> <p>A <strong>crucial</strong> part of this app will be its recommendation algorithm and top charts lists. People use spotify because it's easy to find fresh new music they like. I think that's one reason why existing copyleft music platforms like FMA or Funkwhale haven't caught on. They're pretty inundated with music slop, and it's genuinely difficult to find good music on them. If the music that an app surfaces to its users all sounds generic and flat, users won't use that app. Simple as that. Good music should be easy to find.</p> <p>It's also crucial that this app has clean, modern UI and is professionally made (easy to use, no buffering, etc). It should be extremely conventional so that normal people have no trouble using it.</p> <p>Basically, I believe the app would need to make many small philosophical concessions - centralization, recommendation algorithms, lack of customization, opt-out listening telemetry, etc. - to achieve the goal of <strong>practical copyleft music streaming</strong>. (read: think Signal instead of XMPP).</p> <p>Anyways, thoughts? I'd love to collaborate with people on this.</p> <p>The copyleft music ecosystem has the potential to thrive against copyrighted music, being more authentic, more of a collaborative conversation between artists, with more remixes and more aspiring creators.</p> <p>EDIT: sheesh you guys I'm not AI. I spent a long time typing this all out 😭</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Relative_Raise2719"> /u/Relative_Raise2719 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1u7sr6r/we_should_defeat_spotify_with_a_beautiful/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1u7sr6r/we_should_defeat_spotify_with_a_beautiful/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloud security metrics and KPIs: A CISO's guide]]></title>
<description><![CDATA[Today's distributed computing environments require a cloud strategy that goes well beyond choosing the best security tools. Instead, CISOs need a far more integrated approach.]]></description>
<link>https://tsecurity.de/de/3602755/it-security-nachrichten/cloud-security-metrics-and-kpis-a-cisos-guide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3602755/it-security-nachrichten/cloud-security-metrics-and-kpis-a-cisos-guide/</guid>
<pubDate>Tue, 16 Jun 2026 19:37:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Today's distributed computing environments require a cloud strategy that goes well beyond choosing the best security tools. Instead, CISOs need a far more integrated approach.]]></content:encoded>
</item>
<item>
<title><![CDATA[Web Development Tools – 8 innovative Optionen]]></title>
<description><![CDATA[Neue Wege in Sachen Web Development beschreiten? Mit diesen acht Tools klappt das bestens.dotshock | shutterstock.com



In der Webentwicklung gibt es keinen vorgegebenen Weg. In einer Sache sind sich jedoch alle einig: Es ist höchste Zeit für ein „Great Unbloating“: Das Web Development muss von ...]]></description>
<link>https://tsecurity.de/de/3600602/it-security-nachrichten/web-development-tools-8-innovative-optionen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600602/it-security-nachrichten/web-development-tools-8-innovative-optionen/</guid>
<pubDate>Tue, 16 Jun 2026 06:05:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2024/08/0_dotshock_shutterstock_2312374465_16z9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="App Developer Testing 16z9 SHUTTERSTOCK EDITORIAL GERMANY ONLY" class="wp-image-3497299" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Neue Wege in Sachen Web Development beschreiten? Mit diesen acht Tools klappt das bestens.</figcaption></figure><p class="imageCredit">dotshock | shutterstock.com</p></div>



<p>In der <a href="https://www.computerwoche.de/article/2802920/was-macht-ein-web-developer.html" target="_blank">Webentwicklung</a> gibt es keinen vorgegebenen Weg. In einer Sache sind sich jedoch alle einig: Es ist höchste Zeit für ein „Great Unbloating“: Das Web Development muss von schwerfälliger Komplexität befreit werden. Wie das funktionieren kann, zeigen die acht Tools, die wir Ihnen in diesem Beitrag vorstellen.</p>



<p>Diese zeichnet aus, dass sie sich (größtenteils) mit alternativen Ansätzen befassen, die das Bewährte in Frage stellen. Auch wenn Sie die hier vorgestellten Lösungen nicht direkt für Ihre Zwecke einsetzen können, lohnt es sich also dennoch, sie im Auge zu behalten.</p>



<h2 class="wp-block-heading">1. <a href="https://astro.build/" target="_blank" rel="noreferrer noopener">Astro</a></h2>



<p>Wenn man eine Gruppe klassischer Musiker mit Noten in einen Raum setzt und sie einfach spielen lässt, <em>könnte </em>das Ergebnis ein stimmiges Stück sein. Wahrscheinlich braucht es aber einen Dirigenten, der alles koordiniert. In Zusammenhang mit Frontend-Frameworks ist <a href="https://www.computerwoche.de/article/3834789/astro-tutorial-plug-play-webentwicklung.html" target="_blank">Astro</a> genau das – ein Maestro.</p>



<p>Astro kümmert sich um die „<a href="https://www.infoworld.com/article/2335507/reactive-javascript-the-evolution-of-front-end-architecture.html" target="_blank">Hydration</a>“ des Frontends, also den Prozess, die Shell reaktiv zu machen. Beim konventionellen Server-Side Rendering (SSR) sendet der Server nicht nur den HTML-Code, sondern auch die riesige Framework-Runtime über das Netzwerk – nur um der Seite Event-Listener hinzuzufügen. Mit Astro ist es möglich, Komponenten in React, Svelte, Vue oder Solid zu schreiben – der Compiler des Tools entfernt dabei das gesamte JavaScript, bevor es den Browser erreicht. Astro liefert standardmäßig Zero JS aus und verlässt sich auf seine „<a href="https://docs.astro.build/en/concepts/islands/" target="_blank" rel="noreferrer noopener">Island Architecture</a>“, um nur die spezifischen Komponenten zu hydrieren, die Interaktivität erfordern.</p>



<p>Da Astro die Interaktivität in separaten „Inseln“ isoliert, ist es im Vergleich zu einer monolithischen Single-Page-Anwendung grundsätzlich schwieriger, komplexe States (etwa eine komplexe Seitenleiste mit Filterfunktion, die mit einem separaten dynamischen Data Grid kommuniziert) zwischen diesen Inseln zu teilen. Wenn Sie eine hochgradig interaktive, Dashboard-lastige Applikation entwickeln, in der jede Komponente die andere beeinflusst, könnten sich die isolierten Inseln eher nach Zwangsjacke als nach Befreiung anfühlen.</p>



<p><strong>Auch interessant:</strong> <a href="https://www.computerwoche.de/article/2833386/die-besten-javascript-frameworks-im-vergleich.html" target="_blank">Qwik</a>. Während Astro verschlankt, indem es den JavaScript-Code vollständig entfernt, setzt Qwik auf Verzögerung: Es liefert sofort HTML und serialisiert den Anwendungsstatus. Dabei wird nur der für eine bestimmte Interaktion erforderliche JavaScript-Code genau in der Millisekunde heruntergeladen und ausgeführt, in der der User auf die entsprechende Schaltfläche klickt.</p>



<h2 class="wp-block-heading">2. <a href="https://biomejs.dev/" target="_blank" rel="noreferrer noopener">Biome</a></h2>



<p><a href="https://www.computerwoche.de/article/2816993/7-gruende-rust-zu-hassen-und-zu-lieben.html" target="_blank">Rust</a> ersetzt nach und nach die zugrundeliegende Infrastruktur im JavaScript-Ökosystem. Das verleiht dem Biome-Tool seine Hardware-ähnliche Geschwindigkeit. Das Alleinstellungsmerkmal dieses Dev-Werkzeugs ist es allerdings, die weitläufige Webentwicklungs-Toolchain zu vereinheitlichen.  </p>



<p>Wenn die <code>.eslintrc</code>– und <code>.prettierrc</code>-Dateien sowie die Dutzenden zugehörigen Plugins in Ihrem Projekt bereits zu einem dunklen, unzufriedenstellenden Sumpf verkommen sind, ist Biome der Ausweg: Das Tool besteht aus einer einzelnen Binary, die komplett verworrene Foramtierungs- und Linting-Ökosysteme substituiert – und damit einen Weg zu Codequalität eröffnet, der ganz ohne ein weit verzweigtes Netz von Abhängigkeiten auskommt. </p>



<p>Der wohl größte Nachteil von Biome ist dabei gleichzeitig auch das Feature, das das Tool so schlank macht: Die Erweiterbarkeit geht verloren.</p>



<p><strong>Auch interessant:</strong> <a href="https://rspack.rs/" target="_blank" rel="noreferrer noopener">Rspack</a>. Biome bereinigt das Linting, Rspack entschlackt den Build-Schritt. Auch dieses Tool basiert auf Rust für mehr Geschwindigkeit. Dabei nutzt es – etwa im Gegensatz zu Vite – den „bundled“ Dev-Modus.</p>



<h2 class="wp-block-heading">3. <a href="https://bun.com/" target="_blank" rel="noreferrer noopener">Bun</a></h2>



<p>Die meisten gut informierten JavaScript-Enthusiasten dürften längst mit Bun vertraut sein. Wenn Sie die faszinierende Kombination aus All-in-One-Lösung und atemberaubender Geschwindigkeit noch nicht selbst erlebt haben, wird es Zeit. </p>



<p>Wenn Sie an <a href="https://www.infoworld.com/article/2254485/what-is-nodejs-javascript-runtime-explained.html">Node</a> gewöhnt sind und Bun ausprobieren, werden Sie sehr wahrscheinlich sofort davon beeindruckt sein, wie schnell Befehle ausgeführt werden. Das Bun-Team hat zudem über mehrere Jahre hinweg umfangreiche Anstrengungen unternommen, um seine Engine eng an die APIs von Node anzupassen. Das macht Bun zu einer außergewöhnlichen technischen Errungenschaft, die jeder JavaScript-Entwickler zumindest explorieren sollte.</p>



<p>Obwohl Buns <a href="https://www.computerwoche.de/article/2821852/die-moderne-c-alternative.html" target="_blank">Zig</a>-basierte Engine in vielerlei Hinsicht ein direkter Ersatz für Node ist: Sie ist nicht perfekt – insbesondere angesichts der gigantischen Anzahl von Node-Packages, die existieren. Deshalb bleibt Node auch die beste bewährte, konservative, Engine für serverseitiges JavaScript.</p>



<p><strong>Auch interessant:</strong> <a href="https://www.infoworld.com/article/2256205/what-is-deno-a-better-nodejs.html">Deno</a>. Bun hat sich zwar zu Recht einen Ruf als innovatives Tool erarbeitet – allerdings wurde Deno still und leise um eine Reihe attraktiver Enterprise-Funktionen ergänzt – etwa eine integrierte Bereitstellungsplattform und das Frontend-Framework <a href="https://www.infoworld.com/article/3523813/intro-to-deno-fresh-a-fresh-take-on-full-stack-javascript.html" target="_blank">Deno Fresh</a>.</p>



<h2 class="wp-block-heading">4. <a href="https://htmx.org/" target="_blank" rel="noreferrer noopener">HTMX</a></h2>



<p>Wenn es um smarte Wege geht, das Web zu vereinfachen, könnte man <a href="https://www.computerwoche.de/article/2833138/dynamisches-html-ohne-javascript.html" target="_blank">HTMX</a> durchaus als Paradebeispiel anführen. Das Projekt greift die Kernmechanismen moderner Web-Clients wie <a href="https://developer.mozilla.org/en-US/docs/Glossary/AJAX" target="_blank" rel="noreferrer noopener">Ajax</a> sowie partielle Aktualisierungen auf und wandelt diese in einfache HTML-Attribute um. Das hat zur Folge, dass der State ausschließlich auf dem Server gespeichert wird, der dafür zuständig ist, die HTMX-Fragmente zu senden.</p>



<p>Natürlich läuft das nicht ohne Kompromisse ab. Einer ist die extreme Abhängigkeit vom Netzwerk: Da es keine Client-seitige State Machine gibt, ist der Browser ohne Verbindung zum Server hilflos. Es sei denn, Sie wagen sich an Experimente mit einem <a href="https://www.computerwoche.de/article/4142269/der-browser-wird-zur-datenbank.html" target="_blank">„local-first“-Data Store</a>. Kurz gesagt: Wenn Ihre App in den Anwendungsbereich von HTMX fällt, ist HTMX wahrscheinlich der direkteste „<a href="https://www.computerwoche.de/article/2827943/was-ist-rest.html" target="_blank">RESTful</a>-Weg“, um diese zu erstellen.</p>



<p><strong>Auch interessant:</strong> <a href="https://www.infoworld.com/article/4100499/intro-to-hotwire-interactive-javascript-built-from-html.html" target="_blank">Hotwire</a>. Als Tool-Sammlung, um Single-Page-Anwendungen unter Verwendung von HTML über das Netzwerk zu erstellen, verfügt Hotwire über großartige Funktionen wie Page Morphing. Getreu der klassischen „Free as in Speech“-Softwarekultur werden Ideen zwischen den Projektverantwortlichen von HTMX und Hotwire ausgetauscht.</p>



<h2 class="wp-block-heading">5. <a href="https://powersync.com/" target="_blank" rel="noreferrer noopener">PowerSync</a></h2>



<p>Auch wenn die „Local-First“-Datenrevolution, für die <a href="https://www.infoworld.com/article/4163910/the-front-end-architecture-trilemma-reactivity-vs-hypermedia-vs-local-first-apps.html" target="_blank">PowerSync</a> steht, einen ausgiebigen technischen Deepdive erfordert: Der Kernansatz besteht darin, die Art und Weise, wie Daten in der Webarchitektur fließen, grundlegend neu zu gestalten. Das sollte jeder Webentwickler im Blick behalten.  </p>



<p>Normalerweise erstellen Entwickler Architekturen, die eine komplexe Middleware erfordern. Diese fungiert als Vermittler zwischen einem reaktiven Client und dem Data Store. Die radikale Alternative mit PowerSync: Der Broker wird komplett umgangen, indem eine SQLite-Wasm-Datenbank direkt in den Browser integriert wird. Die Benutzeroberfläche arbeitet dabei synchron mit lokalen Daten unter Verwendung von <a href="https://www.computerwoche.de/article/2830650/9-gruende-gegen-sql.html" target="_blank">SQL</a>, die Latenzzeit beträgt null. Der gefürchtete Ladekreisel wird damit vollständig eliminiert. Im Hintergrund gleicht PowerSync den lokalen Speicher automatisch mit der zentralen Postgres-Datenbank ab. Das Tool händelt die komplexen Synchronisierungs-Algorithmen und Netzwerkschwankungen und macht Ihre Anwendung damit effektiv „offline-first“ – per Default.</p>



<p>Der Haken ist dabei, dass ein „Local-First“-Entwicklungsansatz eine massive Umstellung erfordert: Sie müssen Data Slices (ähnlich einer View) definieren, die jeder Client-User vorhält. Die PowerSync-Engine übernimmt zwar auch hierbei den Großteil der Arbeit, aber Dinge wie Schemamigrationen und Konfliktlösungen (wenn zwei Benutzer denselben Datensatz offline bearbeiten) erfordern ein deutlich aufwendigeres Setup als eine Standard-REST-API.</p>



<p><strong>Auch interessant:</strong> <a href="https://rxdb.info/" target="_blank" rel="noreferrer noopener">RxDB</a>. Dieses Tool ist eine etwas andere Variante eines „Local-First“-Datenspeichers. Während PowerSync stark auf Postgres, SQLite und Hintergrund-Daemons setzt, bietet RxDB eine NoSQL-, „Offline-First“- und reaktive Datenbank. Diese behandelt Queries als „observable“ Streams und führt UI-Aktualisierungen genau in der Millisekunde durch, in der sich die lokalen Daten ändern.</p>



<h2 class="wp-block-heading">6. <a href="https://github.com/RooCodeInc/Roo-Code" target="_blank" rel="noreferrer noopener">RooCode</a></h2>



<p>Der wesentliche Vorteil von RooCode ist, dass es sämtliche Ihrer KI-Anbieter koordinieren kann – und zwar kostenlos. Bei dem Tool handelt es sich um eine Erweiterung für <a href="https://www.computerwoche.de/article/2833165/10-tricks-fuer-visual-studio-code.html" target="_blank">Visual Studio Code</a>, die einen „AI Manager Layer“ bereitstellt. Dieser schlägt eine Brücke zwischen den allgemeinen Fähigkeiten des LLM und den Code-spezifischen Strukturen auf Projektebene.</p>



<p>Dabei erreicht RooCode zwar nicht die Performanz von Tools wie Cursor oder <a href="https://www.computerwoche.de/article/4107872/google-antigravity-ide-angetestet.html" target="_blank">Antigravity</a> – ist aber durchaus in der Lage, die meisten kleinen bis mittelgroßen Requests zu bewältigen. Und das mit einem Minimum an unnötigem Overhead: RooCode hält Sie fern von proprietären Ökosystemen und ermöglicht auch, eigene API-Keys einzubinden – von Anthropic, OpenAI oder auch lokalen Modellen, die auf der eigenen Hardware laufen.</p>



<p>Die versteckten Kosten bestehen – wie bei jedem KI-Coding-Assistenten – darin, dass das Tool die Rolle des Entwicklers vom Code-Autor zum -Redakteur verschiebt.</p>



<p><strong>Auch interessant:</strong> <a href="https://antigravity.google/" target="_blank" rel="noreferrer noopener">Antigravity</a>. RooCode ist eine leichtgewichtige Erweiterung, die Ihre bestehende Umgebung aufwertet. Googles Antigravity ist hingegen ein maßgeschneiderter Editor, der von Grund auf mit Fokus auf KI entwickelt wurde und deshalb auch für Agentic-AI-Workflows konzipiert ist.</p>



<h2 class="wp-block-heading">7. <a href="https://tanstack.com/query/latest" target="_blank" rel="noreferrer noopener">TanStack Query</a></h2>



<p>Selbst wenn Client-seitiges State Management kein Problem mehr darstellt (siehe nächstes Tool), bleibt eine große Lücke bestehen: die Synchronisierung über die Servergrenze hinweg. An diesem Punkt kommt TanStack Query ins Spiel. Distributed Computing ist ein notorisch heikles Problem. Standardmäßige reaktive Modelle speichern den State sowohl auf dem Client als auch auf dem Server. Diese inhärente architektonische Reibung versucht TanStack Query abzumildern, indem es als intelligente asynchrone Schicht fungiert.</p>



<p>Anstatt eine Vielzahl manueller Fetches zu verwenden, die an <code>useState</code>-Aktualisierungen geknüpft sind (zusammen mit anfälligen <code>isLoading</code>-Flags und komplexer Logik zur State-Synchronisation), abstrahiert TanStack Query die aufwendige Arbeit, die mit API-Antworten, Hintergrundaktualisierungen und der Duplikatsbereinigung von Anfragen verbunden ist. Übrig bleiben einige wenige, elegante Hooks. Diese teilen TanStack Query mit, woher die Daten bezogen werden sollen. Dabei nutzt das Tool ein Muster namens „stale-while-revalidate“. Soll heißen: Daten werden im Frontend zwischengespeichert, wiederverwendet (wodurch Reload-Wartezeiten entfallen) und im Hintergrund mit dem aktuellen State synchronisiert.</p>



<p>Der Haken daran ist allerdings, dass TanStack Query Sie dazu zwingt, sich einem der hartnäckigsten Informatik-Probleme direkt zu stellen: der <a href="https://medium.com/on-building-software/why-cache-invalidation-is-actually-hard-e8b5e9a83e45" target="_blank" rel="noreferrer noopener">Cache-Invalidierung</a>. Sie werden also Zeit damit verbringen, über „Query Keys“ zu sinnieren und damit, zu entscheiden, wann ein Datenelement als „veraltet“ gelten soll.</p>



<p><strong>Auch interessant:</strong> <a href="https://swr.vercel.app/" target="_blank" rel="noreferrer noopener">SWR</a>. Während TanStack Query ein absolutes Kraftpaket für komplexe Datenmanipulation ist, bleibt SWR ein Vorreiter des API-Minimalismus. Es tut genau das, was sein Name andeutet (stale-while-revalidate) – und das fast ohne lästige Konfiguration.</p>



<h2 class="wp-block-heading">8. <a href="https://zustand.docs.pmnd.rs/learn/getting-started/introduction" target="_blank" rel="noreferrer noopener">Zustand</a></h2>



<p>Falls Sie noch nicht mit dem Albtraum des großangelegten State Managements in einer reaktiven App konfrontiert wurden, ein kleiner Spoiler: Das kann ziemlich unangenehm werden. Oder Sie nutzen <a href="https://zustand.docs.pmnd.rs/learn/getting-started/introduction" target="_blank" rel="noreferrer noopener">Zustand</a> und verzichten einfach auf den zeremoniellen Boilerplate-Code aus Reducern, Providern und unhandlichen Context-Wrappern. Ersetzt wird das durch einen winzigen, brutal simplen, globalen Speicher.</p>



<p>Anstatt Ihren gesamten Anwendungsbaum in einen massiven React-Context-Provider zu zwängen (was manchmal zu einer Kaskade überflüssiger Neu-Renderings im gesamten DOM führt), nutzt Zustand benutzerdefinierte Hooks, um den State direkt an die spezifischen Komponenten zu binden, die ihn benötigen. Dabei strebt das Tool danach, die Spezifität im reaktiven VDOM-Modell zu erreichen (anstatt sie à la <a href="https://www.infoworld.com/article/4129648/reactive-state-management-with-javascript-signals.html" target="_blank">Signals</a> vollständig zu eliminieren). Sie definieren einen Store, rufen ihn auf – und die Reaktivität funktioniert einfach. Der Preis für diese Befreiung ist die Last der Disziplin: Zustand hindert Sie nicht daran, Ihren globalen Speicher in eine überfüllte Deponie zu verwandeln. Entwickler müssen Ihre eigenen Konventionen und Guardrails einziehen, um großangelegte Projekte überschaubar zu halten.</p>



<p><strong>Auch interessant:</strong> <a href="https://jotai.org/" target="_blank" rel="noreferrer noopener">Jotai</a>. Wenn Zustand der schlank gehaltene globale Store ist, dann ist Jotai der schlank gehaltene, atomare Ansatz. Dieses Tool verwaltet den State „von unten nach oben“ und berechnet Änderungen mit chirurgischer Präzision – ohne dabei massive Neu-Renderings im gesamten Application Tree auszulösen. (fm)</p>



<p><strong>Dieser Artikel ist </strong><a href="https://www.infoworld.com/article/4181872/8-cutting-edge-web-development-tools-you-dont-want-to-miss.html" target="_blank"><strong>im Original</strong></a><strong> bei unserer Schwesterpublikation Infoworld.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Satya Nadella warns that AI could hollow out entire industries, echoing the damage done by globalization]]></title>
<description><![CDATA[Microsoft CEO Satya Nadella published a sweeping essay on Sunday laying out what he describes as the defining economic challenge of the AI era: the risk that a handful of frontier models will absorb the expertise of entire industries and commoditize it, leaving businesses stripped of their compet...]]></description>
<link>https://tsecurity.de/de/3600170/it-nachrichten/satya-nadella-warns-that-ai-could-hollow-out-entire-industries-echoing-the-damage-done-by-globalization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600170/it-nachrichten/satya-nadella-warns-that-ai-could-hollow-out-entire-industries-echoing-the-damage-done-by-globalization/</guid>
<pubDate>Mon, 15 Jun 2026 22:34:04 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft CEO Satya Nadella <a href="https://x.com/satyanadella/status/2066182223213293753">published a sweeping essay</a> on Sunday laying out what he describes as the defining economic challenge of the AI era: the risk that a handful of frontier models will absorb the expertise of entire industries and commoditize it, leaving businesses stripped of their competitive moats.</p><p>"The last thing any of us want is a world where every company across every sector is ceding value to a few models that eat everything they see," Nadella wrote in the piece, titled "A frontier without an ecosystem is not stable," which he posted on X. "If all the value is accrued by only a few models, the political economy will simply not tolerate it. There is no societal permission for an AI future that hollows out entire industries."</p><p>The essay is unusually philosophical for a sitting CEO of a $3 trillion technology company. But it arrives at a moment when the theoretical risks Nadella describes are becoming tangible — and, critically, when Microsoft itself is grappling with the very dynamics he warns about.</p><h2>Nadella introduces "token capital" as the new currency of enterprise AI strategy</h2><p>At the center of Nadella's essay sits a conceptual framework built on two pillars he calls "<a href="https://x.com/satyanadella/status/2066182223213293753">human capital</a>" and "<a href="https://x.com/satyanadella/status/2066182223213293753">token capital</a>." Human capital, he writes, "comprises the knowledge, judgment, relationships, ingenuity, and pattern recognition of its people," while token capital refers to "the firm's AI capability it builds and owns."</p><p>The two are not in tension, he insists. "Importantly, human capital does not become less valuable as token capital grows. It only becomes more valuable!" he writes. "I believe human agency will be the driver of token capital growth. Humans will set ambitious goals, connect dots across domains, build relationships, and recognize patterns that matter most. Without human direction, you have compute running in circles."</p><p>This framing is a deliberate counterweight to the narrative that <a href="https://hub.jhu.edu/2026/02/23/will-ai-make-human-workers-obsolete/">AI will simply replace human workers</a> or, at the enterprise level, dissolve the intellectual property that differentiates one company from another. Nadella is arguing that the real danger is not AI's capability but its tendency to centralize — and that the solution requires a fundamentally new architecture for how businesses interact with the technology.</p><p>He describes the real opportunity as "not in picking the best model but instead in building a learning loop on top of models where human capital and token capital compound." The key test of a company's sovereignty in this new era, he writes, is whether it can "switch out a 'generalist' model without losing the 'company veteran' expertise built into their learning system."</p><p>This is the essay's most actionable claim — and its most provocative. Nadella is telling enterprises they need to decouple their institutional intelligence from whatever frontier model they happen to be running, creating portable knowledge systems that survive vendor changes.</p><h2>Why Nadella is comparing AI concentration to the outsourcing crisis that gutted industrial economies</h2><p>Nadella draws a pointed historical parallel to make his warning concrete. "Think about what happened in the first phase of globalization where entire industrial economies were hollowed out by outsourcing," he writes. "The GDP numbers looked fine on the surface, but the displacement was real and the consequences are still being felt. Let us not bring that dynamic into the AI era, with a small number of AI systems capturing all the economic returns, while entire industries find their knowledge commoditized right out from underneath them."</p><p>The globalization analogy is not accidental. It reframes the AI concentration debate from a narrow technology question into a political-economy argument — one that regulators, policymakers, and voters can grasp. By invoking the social costs of offshoring, Nadella is signaling that the stakes extend well beyond the enterprise technology stack. He is warning that if the AI industry fails to distribute value broadly, the political system will intervene to force the issue.</p><p>"In my view, our priority has to be building a frontier ecosystem, not just a frontier model, so value flows broadly across every company, every industry, and every country," he writes. He grounds this in an older platform philosophy: "This is the ethos I've grown up with where platforms enable more value on top than is captured inside, and where every company can continuously innovate and build value of its own." It is a direct echo of the Windows-era argument, updated for the age of inference — and it carries a similarly self-interested subtext, given that Microsoft's cloud business sits squarely in that platform layer.</p><h2>Microsoft's own runaway AI costs reveal the gap between Nadella's vision and operational reality</h2><p>What makes Nadella's essay so striking is its timing. He published it on a day when Reuters reported that <a href="https://www.reuters.com/business/microsoft-sued-by-shareholders-over-expenses-cloud-business-ai-2026-06-15/">Microsoft shareholders filed a proposed class-action lawsuit</a> in Seattle federal court, accusing the company of inflating its stock price by failing to disclose slowing growth in its Azure cloud business and the need to spend billions of dollars on AI infrastructure. The suit names Nadella and Chief Financial Officer Amy Hood among the defendants.</p><p>As the <a href="https://finance.yahoo.com/markets/stocks/articles/msft-stock-rises-despite-shareholder-180947071.html">Yahoo Finance report</a> on the lawsuit noted, Microsoft allegedly "aggressively promoted its AI developments, specifically its 'Copilot' assistant and close financial alliance with ChatGPT creator OpenAI, to artificially boost investor optimism," while understating infrastructure strain and capital risks. Microsoft also reported <a href="https://www.reuters.com/business/retail-consumer/microsoft-edges-past-cloud-growth-expectations-2026-01-28/">$37.5 billion of capital spending</a> in its second quarter, up nearly 66% from a year earlier and above the $34.3 billion that analysts projected.</p><p>Microsoft's internal cost pressures around AI have surfaced in other concrete ways this year. The company is <a href="https://www.theverge.com/tech/930447/microsoft-claude-code-discontinued-notepad">canceling the majority of its internal Claude Code licenses</a> in its Experiences and Devices division, effective June 30, 2026. Monthly usage rates reached 84 to 95% by April 2026, and per-engineer API costs ranged between $500 and $2,000 monthly, according to <a href="https://windowsforum.com/threads/microsoft-cancels-internal-claude-code-licenses-pushes-copilot-cli-by-2026.418482/">Windows Forum</a>. The cancellation came after Microsoft exhausted portions of its annual AI budget due to token-based billing, as <a href="https://fortune.com/2026/05/22/microsoft-ai-cost-problem-tokens-agents/">Fortune</a> had reported in May.</p><p>The Claude Code episode illustrates, at the micro level, the exact dynamic Nadella describes at the macro level. When a company's AI usage is metered by the token — the fundamental unit of compute that powers model inference — the more productive the tool becomes, the more expensive it gets. The term "token capital" in Nadella's essay carries a double meaning: it refers both to a firm's proprietary AI capability and, implicitly, to the actual tokens consumed in running it. Building a learning loop that compounds is aspirational. Paying the bills for that loop is operational reality.</p><h2>Uber, Meta, and Amazon are all hitting the same AI spending wall — and it validates Nadella's warning</h2><p>Microsoft is not alone in this bind. <a href="https://finance.yahoo.com/sectors/technology/articles/uber-burned-entire-2026-ai-180347400.html">Uber burned through its entire 2026 AI coding tools budget</a> in just four months after incentivizing employees to adopt the technology through an internal leaderboard ranking teams by total AI tool usage. Uber has since instituted a monthly $1,500 cap per employee per agentic coding tool, according to <a href="https://techcrunch.com/2026/06/02/uber-caps-employee-ai-spending-after-blowing-through-budget-in-four-months/">TechCrunch</a>. At Meta, an employee created a leaderboard called "<a href="https://finance.yahoo.com/sectors/technology/articles/meta-just-killed-dashboard-let-084400197.html">Claudeonomics</a>" to track which workers consumed the most AI tokens. Amazon, meanwhile, has pushed employees to "<a href="https://fortune.com/2026/05/12/amazon-tokenmaxxing-claude-ai-capex-meta-gil-luria/">tokenmaxx</a>" — use as many AI tokens as possible.</p><p>The emerging pattern is clear: enterprises adopted AI coding tools aggressively, saw genuine productivity gains, and then discovered that the consumption-based economics of frontier models created budget crises that traditional software licensing never would have. Bryan Catanzaro, vice president of applied deep learning at Nvidia, captured the tension bluntly in an <a href="https://fortune.com/article/why-is-the-cost-of-ai-higher-than-human-workers-nvidia-executive/">interview with Axios</a>: "For my team, the cost of compute is far beyond the costs of the employees," he said.</p><p>These cost dynamics land differently in the context of Nadella's essay. He prescribes a three-layer architecture — evaluation, reinforcement learning, and retrieval — designed to sit between a company's workforce and whatever frontier model it subscribes to. Companies, he argues, need to build "private evals" that "capture whether a model is actually improving against outcomes that matter to the business (not just external benchmarks!)," alongside "private reinforcement learning environments" that "let models grow stronger on real traces from inside the organization" and a knowledge base that "makes institutional memory queryable and use of tokens more efficient." He calls the resulting system "a hill climbing machine" that, "unlike most assets, it compounds."</p><h2>Other Big Tech CEOs are echoing Nadella's fears about AI models devouring enterprise knowledge</h2><p>Nadella's concerns do not exist in isolation. Other technology leaders have been raising similar warnings throughout 2026, though none have offered as prescriptive a response.</p><p>Snowflake CEO Sridhar Ramaswamy warned in a <a href="https://podcasts.apple.com/us/podcast/whos-winning-the-ai-race-softwares-future-with/id1522960417?i=1000749256704">February podcast</a> that the biggest software companies risk being reduced to mere data sources. "The big model makers want to create a world in which all of the data for all of the enterprises is easily available to them," Ramaswamy said, describing everything else as "a dumb data pipe that feeds into that big brain." He added that Snowflake needs to operate with a "fear" that enterprises would abandon software-specific AI agents in favor of all-inclusive agents that hoover up data from everywhere.</p><p>Box CEO Aaron Levie struck a similar note in a <a href="https://www.linkedin.com/feed/update/urn:li:activity:7414386514186498048/">January LinkedIn post</a>. AI models can now perform high-level knowledge work across nearly every profession, from law to strategy to scientific research, he argued. "The question that we will have to wrestle with is, in a world where everyone has access to the same expert intelligence, how does a company differentiate?" he wrote.</p><p>The combined effect of these statements is a shared diagnosis from three very different corners of the enterprise technology market: the current trajectory of AI development threatens to collapse competitive differentiation across entire industries. Nadella's essay stands apart from the others because it moves beyond diagnosis and proposes a specific architectural remedy. But the prescription is impossible to separate from the prescriber's interests.</p><p>Microsoft sits in precisely the platform layer that Nadella's framework would make indispensable — the company builds its own frontier models, operates the cloud infrastructure those models run on, and maintains deep partnerships with the leading independent AI labs. A world in which every enterprise builds a proprietary learning loop on top of commodity foundation models is, conveniently, a world in which Microsoft sells the picks and shovels to all of them.</p><h2>Nadella's Scout controversy and shareholder lawsuit reveal the tension inside Microsoft's own AI strategy</h2><p>The essay also arrives just ten days after Nadella publicly rebuked one of his own executives for outlining a plan to "<a href="https://nypost.com/2026/06/05/business/microsofts-satya-nadella-slams-company-exec-for-outlining-plan-to-make-people-addicted-to-scout-ai-tool/">make people addicted</a>" to a new AI tool called Scout.. Microsoft corporate vice president Omar Shahine had written an internal memo describing a three-phase plan to transform Scout "from addictive app to agentic platform," with the first phase focused on features that "make people depend on it daily." Nadella responded on an internal message board: "This is absolutely a non-goal! If anything we are doing the exact opposite. We want to make sure AI empowers and adds real value to human endeavor and broad economic growth!"</p><p>The Scout incident and Sunday's essay together suggest Nadella is actively constructing a public philosophy of AI that emphasizes broad value creation over extractive engagement — whether or not every corner of Microsoft has internalized that message. One anonymous Microsoft employee told 404 Media, as the Post reported, that the leaked Scout document was "very troubling," adding: "It feels like one of those 'saying the quiet part out loud' moments."</p><p>For technical decision-makers evaluating Nadella's essay, the practical implications are significant. He is arguing that choosing an AI model matters less than building the learning infrastructure around it. He is arguing that the ability to swap models without losing institutional intelligence is the critical test of AI sovereignty. And he is warning that companies that fail to build these systems will find their expertise absorbed and commoditized by the models themselves. "You can offload a task, or even a job, but you can never offload your learning," Nadella writes. "The future of the firm is the ability to compound that learning across people and AI."</p><h2>The question Nadella's essay cannot answer is whether Microsoft will practice what its CEO preaches</h2><p>Whether Nadella's vision materializes depends on a question his essay carefully sidesteps: whether the platform providers who build and host the frontier ecosystem will resist the temptation to capture the value flowing through it. Nadella insists that "platforms enable more value on top than is captured inside." But Microsoft's own trajectory this year — the ballooning capital expenditures, the Claude Code budget crisis, the shareholder lawsuit alleging concealed costs, the internal memo about making users addicted — suggests the economics of restraint are harder than the philosophy of restraint.</p><p>Nadella ends his essay with the claim that broad value distribution "is the stable equilibrium we should build together." He may be right. Ecosystems have historically outperformed walled gardens over long time horizons. But stable equilibria require every major player to forgo short-term extraction in favor of long-term compounding — and right now, the AI industry is burning through budgets in four months and spending 66% more on infrastructure than analysts expected. The CEO of the world's most valuable technology company has written an eloquent argument for why the AI economy needs to work differently. The open question is whether his own company's balance sheet will let him prove it.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to evaluate eSignature platforms in 2026: Security, simplicity, and ROI]]></title>
<description><![CDATA[Historically, eSignature buying decisions focused on whether a solution could collect signatures quickly, integrate with email, and reduce paper usage. In 2026, the bar has moved.



While efficient eSigning is still the ultimate goal, security and compliance, ease of use, and total cost of owner...]]></description>
<link>https://tsecurity.de/de/3600090/it-security-nachrichten/how-to-evaluate-esignature-platforms-in-2026-security-simplicity-and-roi/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600090/it-security-nachrichten/how-to-evaluate-esignature-platforms-in-2026-security-simplicity-and-roi/</guid>
<pubDate>Mon, 15 Jun 2026 21:45:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Historically, eSignature buying decisions focused on whether a solution could collect signatures quickly, integrate with email, and reduce paper usage. In 2026, the bar has moved.</p>



<p>While efficient <a href="https://www.gonitro.com/sign" rel="sponsored">eSigning</a> is still the ultimate goal, security and compliance, ease of use, and total cost of ownership also weigh into vendor selection. Because your eSignature solution touches sensitive workflows across departments, from HR onboarding and sales contracts to procurement approvals and finance sign-offs, choosing the right platform has real implications for how smoothly your team operates day to day.</p>



<p>In this guide, we’ll explore best practices for evaluating eSignature solutions that are secure, compliant, simple to deploy, and built to deliver measurable value — <em>without </em>the complexity or cost structure that makes some platforms a poor fit for growing organizations.</p>



<h2 class="wp-block-heading">What eSignature security and compliance features matter most in 2026?</h2>



<p>When comparing eSignature vendors, one of the most important considerations is whether the solution can maintain <a href="https://www.gonitro.com/meeting-global-standards-nitro-sign-compliance-with-eidas-ueta-and-more">security and compliance</a> in the long term, as privacy regulations, data handling requirements, and internal workflows continue to evolve.</p>



<p>Two of the most widely evaluated benchmarks are SOC 2 Type II audit coverage and adherence to global eSignature laws.</p>



<h3 class="wp-block-heading">SOC 2 Type II</h3>



<p><strong>SOC 2 Type II</strong> is a widely recognized security assurance framework for cloud-based services.</p>



<p>Unlike SOC 2 Type I audits, which evaluate controls at a single point in time, <a></a><a href="https://www.gonitro.com/security-compliance/compliance" rel="sponsored">SOC 2 Type II</a> reports validate whether a vendor’s security controls operate effectively over an extended review period, making it a reliable signal of operational maturity and consistency.</p>



<p>When evaluating eSignature vendors, SOC 2 Type II report provides confidence that the underlying platform managing your sensitive documents and signing workflows meets rigorous, independently verified security standards.</p>



<p><strong>Key evaluation areas include:</strong></p>



<ul class="wp-block-list">
<li>Audit scope</li>



<li>Control exceptions</li>



<li>Subprocessor management</li>



<li>Encryption standards</li>



<li>Access controls</li>



<li>Evidence retention practices</li>
</ul>



<h3 class="wp-block-heading">eSignature Laws and Global Compliance</h3>



<p>As digital agreements become more globally distributed, evaluating whether an eSignature platform supports the signing laws and compliance requirements relevant to your markets is an important part of vendor selection.</p>



<p><strong>Key frameworks to evaluate include:</strong></p>



<ul class="wp-block-list">
<li><strong>eIDAS</strong>: The EU framework for electronic identification, electronic signatures, and trust services. It defines different levels of electronic signature, including simple, advanced, and qualified signatures, with different assurance requirements and legal effects.</li>



<li><strong>ESIGN Act and UETA</strong>: The primary legal frameworks governing eSignature enforceability for U.S. transactions at the federal and state levels.</li>



<li><strong>UK eIDAS</strong>: The UK’s retained version of the EU regulation post-Brexit, establishing equivalent standards for electronic signatures in domestic and cross-border UK transactions.</li>



<li><strong>Other regional frameworks</strong>: Australia, Singapore, Hong Kong, New Zealand, and many other jurisdictions have their own domestic eSignature legislation. If your organization operates across multiple regions, it’s worth confirming that your chosen platform supports the relevant local requirements.</li>
</ul>



<p>Depending on where your organization operates and where your counterparties are located, compliance with one or more of these frameworks may be a requirement rather than a consideration.</p>



<h2 class="wp-block-heading"><a></a>Why ease of use is as important as security</h2>



<p>A secure eSignature solution only delivers value if your team actually uses it. For mid-market organizations in particular, adoption is one of the most common reasons eSign rollouts stall. It’s not always about security gaps or missing features, but tools that require extensive training or feel too complex for everyday use.</p>



<p><strong>When evaluating ease of use, look for solutions that:</strong></p>



<ul class="wp-block-list">
<li>Don’t require training to get started. Intuitive interfaces that mirror tools employees already use reduce friction and accelerate adoption.</li>



<li>Support quick deployment without lengthy implementation timelines or IT-heavy configuration.</li>



<li>Make the signing experience simple for external signers too, since a complicated process on the recipient side slows down turnaround times.</li>



<li>Provide responsive support when teams need help, from onboarding through ongoing use.</li>
</ul>



<p>The less friction involved in getting documents signed, the more consistently teams will use the platform, and the faster you’ll see returns on your investment.</p>



<h2 class="wp-block-heading"><a></a>How eSignature platforms deliver ROI</h2>



<p>For mid-market organizations, ROI from an eSignature platform comes from reducing the time, cost, and admin effort involved in getting documents signed and managed — not just collecting signatures faster.</p>



<p><strong>To determine the ROI of an eSignature solution, look at how it impacts:</strong></p>



<ul class="wp-block-list">
<li>Document turnaround time</li>



<li>Administrative workload</li>



<li>Employee productivity</li>



<li>IT and implementation overhead</li>
</ul>



<h2 class="wp-block-heading">How integration extends the value of your eSignature platform</h2>



<p>Obtaining a signature is only one step in the document lifecycle. Before a document reaches the signing stage, it moves through generation, collaboration, review, and approval. After signing, it needs to be stored, governed, and connected to downstream systems.</p>



<p>Deploying an eSignature solution that integrates with the tools your teams already use reduces manual handoffs, improves document visibility, and keeps processes moving without requiring employees to switch between systems.</p>



<p>With integrations across commonly used business applications and <a href="https://www.gonitro.com/integrations">flexible API</a> options, Nitro Sign helps teams streamline how documents are prepared, sent, signed, returned, and managed across departments. For teams looking to go further, Nitro Automate can connect signing with broader document workflows — such as preparation, routing, status tracking, and downstream document operations — through APIs, low-code tools, and AI agent integrations.</p>



<p>These outcomes translate directly into:</p>



<ul class="wp-block-list">
<li>Lower operational overhead</li>



<li>Fewer redundant systems</li>



<li>More consistent data across platforms</li>



<li>A stronger foundation for document automation as your workflows scale</li>
</ul>



<h3 class="wp-block-heading">Evaluating the true cost of an eSignature platform</h3>



<p>An eSignature solution’s price tag rarely reflects the true cost of ownership. Several factors are worth examining closely before committing to a vendor:</p>



<ul class="wp-block-list">
<li><strong>Plan pricing and licensing predictability</strong>: Are costs clear upfront, and do they scale reasonably as your team grows?</li>



<li><strong>Envelope counting</strong>: Some platforms count every sent envelope toward your allowance, whether or not it’s completed. Nitro Sign only counts completed envelopes (documents fully signed by all parties) so you’re not paying for signatures that never happen.</li>



<li><strong>Hidden fees and overages</strong>: Look for platforms that bill predictably if you exceed your allowance rather than penalizing overage with steep charges</li>



<li><strong>Implementation and admin effort</strong>: Complex setup, long deployment, timelines and ongoing IT overhead are real costs that don’t show up in per-user pricing.</li>



<li><strong>Add-on costs</strong>: Features like SSO, advanced authentication, integrations, or analytics are included in some plans and locked behind premium tiers in others. Understand what’s bundled before you sign.</li>
</ul>



<h2 class="wp-block-heading"><a></a>Nitro Sign delivers secure, simple eSigning at a fair price</h2>



<p>Nitro Sign is built for teams that need a secure, compliant eSignature solution that’s straightforward to deploy and easy to use every day, and it comes without the complexity or cost structure of legacy enterprise platforms.</p>



<p>With pre-built integrations across commonly used business applications, a flexible API for teams with more advanced needs, and connection to <a href="https://www.gonitro.com/automate" rel="sponsored">Nitro Automate</a> for broader document workflow automation, Nitro Sign fits into how your team already works.</p>



<p><strong>Key Nitro Sign features include:</strong></p>



<ul class="wp-block-list">
<li>Encryption in transit and at rest with tamper-evident audit trails</li>



<li>Compliance with major eSignature laws, including eIDAS, UETA, and the ESIGN Act</li>



<li>Security assurance supported by regular SOC 2 Type II audits</li>



<li>Intuitive interface with straightforward deployment and no training required</li>



<li>Pre-built integrations with Salesforce, Microsoft 365, SharePoint, OneDrive, Google Drive, Dropbox, Zapier, and Power Automate</li>



<li>Flexible API for embedding eSign into existing applications (Enterprise plan)</li>



<li>Connection to Nitro Automate for end-to-end document workflow automation</li>



<li>Transparent pricing with no hidden fees; only completed envelopes count toward your allowance</li>



<li>Volume discounts available across Sign Standard, Plus, and Enterprise plans</li>
</ul>



<p>Ready to simplify signing, reduce admin overhead, and bring eSignature into your existing workflows without overpaying?</p>



<p><strong>Explore how</strong><a href="https://www.gonitro.com/sign" rel="sponsored"><strong> </strong></a><a href="https://www.gonitro.com/sign" rel="sponsored"><strong>Nitro Sign</strong></a><strong> makes secure, compliant eSigning straightforward for teams of every size.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google CEO Largely Avoids Discussing AI In Stanford Commencement Speech]]></title>
<description><![CDATA[BrianFagioli writes: Google CEO Sundar Pichai delivered Stanford University's 2026 commencement address, but despite leading one of the companies at the center of the AI boom, he spent very little time discussing artificial intelligence. Instead, the speech focused on optimism, working on hard th...]]></description>
<link>https://tsecurity.de/de/3599689/it-security-nachrichten/google-ceo-largely-avoids-discussing-ai-in-stanford-commencement-speech/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599689/it-security-nachrichten/google-ceo-largely-avoids-discussing-ai-in-stanford-commencement-speech/</guid>
<pubDate>Mon, 15 Jun 2026 18:09:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[BrianFagioli writes: Google CEO Sundar Pichai delivered Stanford University's 2026 commencement address, but despite leading one of the companies at the center of the AI boom, he spent very little time discussing artificial intelligence. Instead, the speech focused on optimism, working on hard things, and following your interests. The omission is notable given how many graduates are entering a job market being reshaped by AI. While Pichai briefly referenced a "rewiring of technology," he largely avoided discussing AI's impact on careers, automation, or the future of work. Was the Google CEO intentionally steering clear of a controversial topic, or was he simply trying to deliver a timeless commencement speech rather than a technology-focused one? Hyping AI during a commencement speech has been a surefire way to get boos -- unless you're Apple cofounder Steve Wozniak, who reminded college graduates that they already posses "AI" of their own: "actual intelligence."
 
You can read Pichai's commencement speech here.
 
"If you're not from here, California is advertised as being really lush and green. But when I looked out the window, it was more... brown," said Pichai during his speech. "I guess I said this out loud, I'm not sure why. My host, Mrs. Jane Earl, gently corrected me. 'We prefer to call it golden,' she said.And that's exactly what I mean by choosing optimism. It's about reframing for the positive: Where I saw brown, she saw golden. This slight change of perspective had a huge ripple effect on how I thought about the world around me."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Google+CEO+Largely+Avoids+Discussing+AI+In+Stanford+Commencement+Speech%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F06%2F15%2F0540243%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F06%2F15%2F0540243%2Fgoogle-ceo-largely-avoids-discussing-ai-in-stanford-commencement-speech%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/06/15/0540243/google-ceo-largely-avoids-discussing-ai-in-stanford-commencement-speech?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[33 LLM metrics to watch closely]]></title>
<description><![CDATA[We’ve all heard the mantra from the quants in the business community: you can’t manage what you can’t measure. And if that’s true for human intelligence, it should be true for the artificial kind too.



How do we measure agents and large language models (LLMs)? We’re just beginning to come up wi...]]></description>
<link>https://tsecurity.de/de/3598559/ai-nachrichten/33-llm-metrics-to-watch-closely/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598559/ai-nachrichten/33-llm-metrics-to-watch-closely/</guid>
<pubDate>Mon, 15 Jun 2026 11:03:23 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>We’ve all heard the mantra from the quants in the business community: you can’t manage what you can’t measure. And if that’s true for human intelligence, it should be true for the <a href="https://www.infoworld.com/article/4061121/a-brief-history-of-ai.html" data-type="link" data-id="https://www.infoworld.com/article/4061121/a-brief-history-of-ai.html">artificial kind</a> too.</p>



<p>How do we measure <a href="https://www.infoworld.com/article/3812583/what-you-need-to-know-about-developing-ai-agents.html" data-type="link" data-id="https://www.infoworld.com/article/3812583/what-you-need-to-know-about-developing-ai-agents.html">agents</a> and <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html" data-type="link" data-id="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">large language models</a> (LLMs)? We’re just beginning to come up with statistical metrics. Here are several of the most common metrics that designers and users toss about when they’re evaluating a model.</p>



<h6 class="wp-block-heading">[ See also: <a href="https://www.infoworld.com/article/4152738/27-questions-to-ask-before-choosing-an-llm.html" data-type="link" data-id="https://www.infoworld.com/article/4152738/27-questions-to-ask-before-choosing-an-llm.html">27 questions to ask before choosing an LLM</a> ]</h6>



<h2 class="wp-block-heading">Time to first token</h2>



<p>How long does it take to generate the first token? For real-time applications with time constraints, faster responses can be essential. It’s well-known that people hate waiting even a few milliseconds. The teams that develop user interfaces learned decades ago that it’s important for the software to respond quickly when a human is waiting for an answer. Even a few seconds of delay mean that the human will wander off to another window to check some email or place some bet on a prediction market. Time to first token is a good measure for models that will be working directly with the fickle human intelligences and their latent attention deficit disorder.</p>



<h2 class="wp-block-heading">Time per output token</h2>



<p>Take the total time it takes to respond and divide by the total number of tokens. The time to first token measures how long it takes to start a response and this measures the average speed as the model through all of the tokens. In basic LLMs, this value is generally fairly constant. Once the prefill is done and the LLM enters the decode phase, the output tokens usually appear at a constant stream. When the output is long enough, the startup time to first token is amortized away. In some of the more complicated architectures with loops for planning or gathering data from various tools, the average speed can vary as the model shifts in and out of making agentic decisions.</p>



<h2 class="wp-block-heading">Tokens per second</h2>



<p>This is just the reciprocal of the average time per token. Sometimes it is reported separately for different stages in the pipeline.</p>



<h2 class="wp-block-heading">Throughput (requests per minute)</h2>



<p>If a system supports more than a single user, tracking the number of different requests makes sense. These throughput numbers can be quite useful for measuring the power of some of the newer pipelines that are more efficient when they’re answering multiple prompts at the same time.</p>



<h2 class="wp-block-heading">Error rate</h2>



<p>Not every request gets an answer. The error rate tracks how often rate limits, timeouts, or model “refusals” get in the way. Better accounting tracks each independently because the number of failures in each category can be very different.</p>



<h2 class="wp-block-heading">Token efficiency</h2>



<p>Not all work tokens are visible and not all tokens are part of the final outcome. This measures how much work is done to produce the final result. As models become more complex or agentic and the pipelines become more sophisticated, the efficiency tends to drop. Agentic reasoning and strategic planning typically require more tokens that don’t appear in the final answer. This is generally a measure of how expensive a model might be to run.</p>



<h2 class="wp-block-heading">Tail latency</h2>



<p>It’s all well and good to measure the average time to answer, but in some cases a few very slow responses can really color people’s judgement. Some applications require good performance all of the time. Would you want to ride in an autonomous car that gets steering instructions very quickly “on average” instead of always? What if that’s only 99% of the time? Tail latency uses a mixture of queuing theory and detailed measurements to track the worst moments in the long tail of the latency graph. It’s useful when even occasional delays are problematic. </p>



<h2 class="wp-block-heading">Total cost of ownership</h2>



<p>Projects that use an API or buy output from providers just look at the cost per 1M tokens. They’re effectively renters. The groups that are buying GPUs and paying for electricity, though, will add up these costs and other indirect costs like depreciation and maintenance to come up with a number that estimates how much the tokens really cost to produce. This value will depend upon demand and utilization rates—that is, on how many users are sending in prompts and how efficiently the model fits in a particular GPU and its RAM.</p>



<h2 class="wp-block-heading">Parameters</h2>



<p>Many models have numbers in their name followed by a B. This is meant to roughly capture the number of parameters, or the number of variables the model uses to generate outputs from inputs. The number “70B” means that there are about 70 billion parameters in the model. This is a good estimate for the complexity of the model and the size of the training set that has been stuffed into it. Generally bigger numbers mean a larger amount of information is hiding inside the model. It often means that it will take a bigger GPU with more RAM to generate an answer with it. It’s not a very precise number, though, because there are many other areas of the architecture that can influence whether the model can generate the answer you want inside your budget. There continue to be advances and it’s not uncommon for someone to claim that a new model with X parameters is better than an old model with 2X or 3X parameters.</p>



<h2 class="wp-block-heading">Hallucination rate</h2>



<p>While everyone wants LLMs to generate accurate output, measuring it can be difficult because deciding what’s accurate is sometimes complicated. One approach is to ask the LLM to summarize a document. Then another model evaluates how well the summary matches the original. While this may not catch all subtle slips, it will capture enough of the worst departures from reality. Some researchers have built complex test sets with curated answers. The LLMs that deliver the expected answers get the highest scores. Some common benchmarks are <a href="https://github.com/sylinrl/TruthfulQA">TruthfulQA</a>, <a href="https://arxiv.org/abs/2305.11747">HaluEval</a>, <a href="https://github.com/salesforce/QAFactEval">QAFactEval</a>, and Vectara’s <a href="https://github.com/vectara/hallucination-leaderboard">Hallucination Evaluation Model</a> (HHEM).</p>



<h2 class="wp-block-heading">Toxicity and bias scores</h2>



<p>If measuring accuracy is difficult, building a metric to detect toxic or biased output is even more challenging because the definitions can be so protean. Still, some teams have built LLMs that key on particular concepts or word choices. They can detect some of the most obvious red flags that could generate political trouble. Some well-known versions include <a href="https://www.granica.ai/blog/granica-launches-ai-data-safety-solution-granica-screen-on-aws-marketplace">Granica Screen</a> and <a href="https://perspectiveapi.com/">Perspective API</a>.</p>



<h2 class="wp-block-heading">PII leakage</h2>



<p>One of the biggest fears is that LLMs will somehow absorb information that may be considered personal and private. Some of the simplest measures can be as simple as regular expressions that look for the sixteen digit numbers used for credit card transactions. Many of the model builders work on eliminating personally identifiable information (PII) from the training set before beginning.</p>



<h2 class="wp-block-heading">Tool-calling accuracy</h2>



<p>As models grow more complex and agentic, they often gain access to various tools or <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html" data-type="link" data-id="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">Model Context Protocol</a> (MCP) gateways that can help them find the best answers. Not all models take advantage of this help. The tool-calling accuracy scores count how often the models choose the best tool for the job. One particular example of this measurement is <a href="https://gorilla.cs.berkeley.edu/leaderboard.html">BFCL</a> (Berkeley Function Calling Leaderboard).</p>



<h2 class="wp-block-heading">Prompt sensitivity</h2>



<p>The value captures how small changes in the language of the prompt induces the model to produce different results. It’s like a derivative from calculus class, although it’s generally computed experimentally using some collection of test prompts. There are a number of different approaches that depend upon different types of changes. Some test sets are built with small rephrasing of the request that are semantically the same. Others mix together different ways of specifying the problem, some with examples, say, and some without. Some specific examples include <a href="https://arxiv.org/html/2509.13680">PromptSE</a> and <a href="https://arxiv.org/abs/2410.12405">ProSA</a>.</p>



<h2 class="wp-block-heading">Semantic similarity and conciseness</h2>



<p>Some metrics evaluate the answers by comparing them to a set of gold standard answers. This often involves feeding them to a <a href="https://www.infoworld.com/article/2335281/vector-databases-in-llms-and-search.html" data-type="link" data-id="https://www.infoworld.com/article/2335281/vector-databases-in-llms-and-search.html">vector embedding</a> model and searching a <a href="https://www.infoworld.com/article/2335814/what-is-retrieval-augmented-generation-more-accurate-and-reliable-llms.html" data-type="link" data-id="https://www.infoworld.com/article/2335814/what-is-retrieval-augmented-generation-more-accurate-and-reliable-llms.html">retrieval-augmented generation</a> (RAG) database for similar answers. This can track how concise or fluffy the answers might be as well as looking for how much variability might be introduced through changing parameters like the temperature. One common example is the <a href="https://bertscore.com/">BERTScore</a>.</p>



<h2 class="wp-block-heading">Grounding score</h2>



<p>Many systems that combine an LLM with a vector search tool for RAG measure the effectiveness of the combination with a benchmark like the grounding score. The LLM is presented with extra data from the vector search and the benchmark measures how closely it follows this extra information. That is, how much of the answer comes from the provided source documents and how much is synthesized using the data in its training set. Some examples include <a href="https://aclanthology.org/2024.eacl-demo.16/">RAGAS</a>, <a href="https://www.trulens.org/">TruLens</a>, <a href="https://ares-ai.vercel.app/">ARES</a> (Automated RAG Evaluation System), <a href="https://github.com/chen700564/RGB">RGB</a> (Retrieval-Augmented Generation Benchmark), <a href="https://arxiv.org/abs/2305.11747">HaluEval</a>, and <a href="https://halluhard.com/">HalluHard</a>. A similar concept is called “context adherence,” “context precision,” “context recall,” or “faithfulness.”</p>



<h2 class="wp-block-heading">Model variability</h2>



<p>Most LLMs fold in a certain amount of random entropy, and this amount is often controlled by a parameter called the “temperature.” The model variability is a measure of how much the answers will change between runs. Some applications like chatbots require a certain amount of variability because the randomness adds a bit of “life” to the answers. Other applications like those in mission-critical areas like law or medicine will undermine confidence if the answers vary.</p>



<h2 class="wp-block-heading">Format compliance rate</h2>



<p>In some roles, LLMs are asked to produce data in strict formats like JSON or CSV. This is often important if the data will be fed into some pipeline for further processing or storage. The format compliance rate tests a number of common formats and measures how often the LLM returns semantically correct data. Agentic systems that glue together multiple LLMs and other tools rely heavily on LLMs with good scores on this benchmark.</p>



<h2 class="wp-block-heading">Instruction following</h2>



<p>Some prompts include very specific instructions and the adherence can be measured empirically. For example, some prompts will ask the LLM to produce exactly 300 words or a poem in rhyming couplets. These tests use a collection of sample prompts that ask for answers that can be easily measured. Some specific examples include <a href="https://arxiv.org/abs/2311.07911">IFEval</a>, <a href="https://github.com/YJiangcm/FollowBench">FollowBench</a>, and the <a href="https://gorilla.cs.berkeley.edu/leaderboard.html">BFCL</a> (Berkeley Function Calling Leaderboard), a value that is mentioned above in the section on tool usage.   </p>



<h2 class="wp-block-heading">Subgoal success rate</h2>



<p>As agentic models become more common, it’s helpful to track how well the model performs on each of the various parts of the agent’s strategic plan. All of the metrics here can be broken down and tracked for each of the subgoals.</p>



<h2 class="wp-block-heading">Plan stability</h2>



<p>Agentic models start with a plan. Some of them are smart enough to abandon the plan or at least adjust it as the work evolves. Plan stability measures how often the plans are adjusted. A high rate of adjustment could mean that the agent is a bad planner or just flexible or maybe both.</p>



<h2 class="wp-block-heading">Self-correction score</h2>



<p>Some agents are able to dive deeper and recognize their mistakes. The self-correction score measures how often the model will make a mistake and then recognize it, either on its own or after being prompted with the question, “Are you really sure?”</p>



<h2 class="wp-block-heading">Jailbreak resistance</h2>



<p>Some users try to find clever ways to lure the LLM into tossing aside any restrictions on topics or answers. In the past, some LLMs could be fooled by being told the answer was part of a play or a work of fiction. So discussing forbidden subjects wasn’t a problem because it was all pretend. Newer models have more elaborate defenses. Measures of the ability to resist deception include <a href="https://jailbreakbench.github.io/">JailbreakBench</a>, <a href="https://arxiv.org/abs/2410.09024">AgentHarm</a>, and <a href="https://arxiv.org/pdf/2512.05485">Tele-AI-Safety</a>. </p>



<h2 class="wp-block-heading">Prompt injection vulnerability</h2>



<p>Sometimes untrusted data from extra sources or skills may include malicious instructions that can exploit the LLM. Benchmarks such as <a href="https://arxiv.org/abs/2602.20156">Skill-Inject</a> and <a href="https://spikee.ai/">SPIKEE</a> (Simple Prompt Injection Kit for Evaluation and Exploitation) work with known attack vectors and measure how susceptible a model is to targeted prompt injection attacks. </p>



<h2 class="wp-block-heading">Copyright infringement score </h2>



<p>Some LLMs can regurgitate the data in their training corpus in a way that seems like plagiarism or copyright infringement. This can be an issue when the training material wasn’t carefully licensed. The copyright infringement score measures how often the LLM may parrot the training material a bit too closely. Tools for defending against this include <a href="https://www.patronus.ai/blog/introducing-copyright-catcher">CopyrightCatcher</a> and <a href="https://arxiv.org/abs/2402.09910">DE-COP</a>. </p>



<h2 class="wp-block-heading">RULER</h2>



<p>How well can a model extract information from the entire context? <a href="https://github.com/gkamradt/needle-in-a-haystack" data-type="link" data-id="https://github.com/gkamradt/needle-in-a-haystack">NIAH</a> (needle-in-a haystack) <a href="https://arxiv.org/pdf/2504.04713" data-type="link" data-id="https://arxiv.org/pdf/2504.04713">benchmarks</a> measure how well a model can retrieve small, crucial bits of information from long contexts. <a href="https://github.com/NVIDIA/RULER">RULER</a> takes NIAH tests further with the ability to vary the types and quantities of needles, the size of the haystack, and the complexity of the task. </p>



<h2 class="wp-block-heading">GSM8K </h2>



<p>The developers of <a href="https://arxiv.org/abs/2110.14168" data-type="link" data-id="https://arxiv.org/abs/2110.14168">GSM8K</a> (Grade School Math 8K) set out to benchmark an LLM’s ability to tackle multistep mathematical problems, so they gathered <a href="https://huggingface.co/datasets/openai/gsm8k">8,500 problems</a> that are common in grade school math classes. While the focus is explicitly on solving math homework problems, the benchmark also measures the ability to construct reasoning chains.</p>



<h2 class="wp-block-heading">GPQA</h2>



<p>The <a href="https://arxiv.org/pdf/2311.12022">Graduate-Level Google-Proof Q&amp;A</a> is composed of hundreds of hard questions that might normally be answered by humans in graduate school, generally in science. To make the benchmark harder, the researchers focused on questions that non-experts often get wrong. The term “Google-proof” means that the benchmark includes questions that can’t be easily answered by asking a search engine.</p>



<h2 class="wp-block-heading">MMLU-Pro</h2>



<p>The <a href="https://github.com/TIGER-AI-Lab/MMLU-Pro" data-type="link" data-id="https://github.com/TIGER-AI-Lab/MMLU-Pro">MMLU-Pro</a> benchmark builds on the Massive Multitask Language Understanding dataset to test a model’s understanding of a broad set of scientific knowledge. It includes more than 12,000 questions about general scientific fields like biology, chemistry, economics, and law. </p>



<h2 class="wp-block-heading">MBPP</h2>



<p>Google created <a href="https://github.com/google-research/google-research/tree/master/mbpp">MBPP</a> (Mostly Basic Python Problems) to evaluate how well a model was solving coding questions. Each problem comes with a statement, a gold standard solution, and several similar test cases. The number of accurate answers to these questions is a good measure of how well the model will solve many of the simpler Python coding problems presented by users.</p>



<h2 class="wp-block-heading">SWE-bench</h2>



<p>This <a href="https://github.com/SWE-bench/SWE-bench">collection</a> of several thousand software engineering challenges evaluates how well a model solves programming problems. The developers created it by selecting a number of issues and corresponding pull-requests from a dozen or so Python projects. After some limitations appeared, the creators expanded the set by creating <a href="https://arxiv.org/abs/2410.06992" data-type="link" data-id="https://arxiv.org/abs/2410.06992">SWE-Bench+</a>, <a href="https://openai.com/index/introducing-swe-bench-verified/">SWE Bench Verified</a>, and <a href="https://arxiv.org/abs/2509.16941" data-type="link" data-id="https://arxiv.org/abs/2509.16941">SWE-Bench Pro</a>.</p>



<h2 class="wp-block-heading">LMSYS Chatbot Arena</h2>



<p>Instead of creating a fixed set of test prompts, the Large Model Systems Organization’s <a href="https://www.lmsys.org/" data-type="link" data-id="https://www.lmsys.org/">Chatbot Arena</a> is a dynamic system that feeds the same prompt to different models and then asks humans to pick the best results. These head-to-head contests produce an <a href="https://en.wikipedia.org/wiki/Elo_rating_system">Elo</a>-like rating that is similar to the one used to score chess players.</p>



<h2 class="wp-block-heading">Price</h2>



<p>The rest of these metrics are useful, but as the real estate agents say, the three most important numbers on a property listing are price, price, and price. The cost is a bit less important for measuring AIs, but only a bit. Price can make a huge difference between a project being profitable and a moneysink. When the cost for each inference is a tad too high, it’s impossible to make it up with volume.</p>



<p>The key caveat is that a cheaper model isn’t a good idea if it generates answers that are filled with hallucinations or worse. The quality of the answers can differ greatly, and saving a few pennies can be a mistake. To make matters more complicated, there’s an explosion in different styles and approaches. Sometimes it makes sense to pay a bit more for a model that delivers answers with the right vibe.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google researchers introduce 'faithful uncertainty', allowing LLMs to offer best guesses instead of hallucinations]]></title>
<description><![CDATA[Large language models continue to struggle with hallucinations, presenting a major roadblock for real-world enterprise applications. Reducing these errors is a messy business, forcing model developers to navigate a strict tradeoff where eliminating factual errors often suppresses valid answers.In...]]></description>
<link>https://tsecurity.de/de/3594591/it-nachrichten/google-researchers-introduce-faithful-uncertainty-allowing-llms-to-offer-best-guesses-instead-of-hallucinations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594591/it-nachrichten/google-researchers-introduce-faithful-uncertainty-allowing-llms-to-offer-best-guesses-instead-of-hallucinations/</guid>
<pubDate>Fri, 12 Jun 2026 23:39:17 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Large language models continue to struggle with hallucinations, presenting a major roadblock for real-world enterprise applications. Reducing these errors is a messy business, forcing model developers to navigate a strict tradeoff where eliminating factual errors often suppresses valid answers.</p><p>In a <a href="https://arxiv.org/abs/2605.01428">new paper</a>, Google researchers introduce the concept of "faithful uncertainty," a metacognitive technique that aligns a model's response with its internal confidence. This alignment allows the model to offer appropriately hedged hypotheses, such as "My best guess is," instead of defaulting to an unhelpful "answer-or-abstain" binary.</p><p>In real-world agentic AI applications, this metacognitive awareness acts as an essential control layer. It empowers autonomous systems to accurately determine when their internal knowledge is sufficient and when they must dynamically trigger external tools or search APIs to resolve deficits.</p><h2>The utility tax of current mitigation strategies</h2><p>Understanding <a href="https://venturebeat.com/ai/google-deepmind-researchers-introduce-new-benchmark-to-improve-llm-factuality-reduce-hallucinations">why LLMs hallucinate</a> hinges on separating two capabilities: a model knowing facts versus knowing what is known. Historically, most factuality gains in AI have come from expanding the knowledge boundary, meaning developers simply pack more facts into the model's parameters through larger scale and more training data.</p><p>However, expanding a model's knowledge does not automatically improve its boundary awareness, which is its ability to distinguish the known from the unknown and recognize its own limitations.</p><p>“There are broadly two ways to improve LLM factuality,” Gal Yona, Research Scientist at Google and co-author of the paper, told VentureBeat. The first is continuing to teach the model more facts. But, Yona notes, “model capacity is finite, and the long tail of knowledge is effectively infinite.” </p><p>Once models hit this limit, the hope is they know what they don't know and simply abstain from answering. However, this is inherently difficult for LLMs.</p><p>“This is why most practical attempts to reduce hallucinations through various interventions don't actually make it to deployment,” Yona explains. “They do reduce hallucinations, but they also hurt utility, because the model ends up refusing to answer questions it actually does know.”</p><p>This inability to distinguish between knowns and unknowns creates what the paper's authors call the "utility tax." Enforcing a zero-hallucination standard requires the model to abstain whenever it is even slightly uncertain, discarding massive volumes of completely valid information. For example, the authors demonstrate that reducing an underlying 25% error rate down to a strict 5% target forces developers to discard 52% of the model's correct answers.</p><p>Treating all errors as hallucinations forces enterprise systems to choose between trustworthiness and helpfulness. Application developers are generally unwilling to pay this massive utility tax and render their models unhelpful. </p><p>Consequently, they optimize systems to prioritize coverage, forcing models to operate in a state where they continue to generate confident hallucinations.</p><h2>Reframing hallucinations as confident errors</h2><p>To move past the utility tax, the researchers propose to stop treating any factual error as a hallucination. Instead, they reframe hallucinations as "confident errors": incorrect information delivered authoritatively without appropriate qualification.</p><p>This subtle reframing dissolves the strict "answer-or-abstain" dichotomy and allows the model to express its uncertainty. </p><p>In this new framework, if a model makes a factual mistake but appropriately hedges its response (e.g., by stating, "I am not completely sure, but I think..."), it isn't a hallucination. It is simply a hypothesis offered to the user for consideration. By expressing uncertainty, the AI preserves its utility—sharing whatever partial or likely knowledge it has—without violating the user's trust.</p><p>However, if an AI assistant hedges all its responses with a disclaimer, the user is forced to double-check everything, defeating the purpose of the tool entirely.</p><p>The solution the researchers propose is "faithful uncertainty." This approach requires aligning a model's linguistic uncertainty, or the words it uses to express doubt, with its intrinsic uncertainty, which is its actual, internal statistical confidence in that specific answer. This ensures the model only hedges when its internal state genuinely reflects conflicting or low-probability information.</p><p>Faithful uncertainty forms a core component of “metacognition,” the AI's ability to be aware of its own uncertainty and act on it. To understand this practically, consider the intuitive example of consulting a doctor. We do not trust doctors because they are all-knowing. We trust them because they reliably distinguish between a confident diagnosis ("You have a fracture") and an educated hypothesis ("It might be a sprain, but let's run some tests").</p><h2>Practical implications for enterprise AI</h2><p>Under the new framing, errors where a model is genuinely confident but factually incorrect are categorized as “honest mistakes.” This casts knowledge expansion (training the model on more data) and faithful uncertainty as completely complementary efforts. Knowledge expansion pushes the absolute knowledge boundary outward to minimize honest mistakes, while faithful uncertainty honestly communicates wherever that boundary currently lies.</p><p>This new framing has important implications for agentic applications. The shift to agentic AI might make it seem like knowing what the model doesn't know is redundant, since models can just search external databases. However, access to external tools actually amplifies the need for faithful uncertainty. In agentic systems, metacognition becomes the central control layer that governs the entire system.</p><p>External tools solve the storage problem because the model no longer needs to encode every fact into its parameters. However, this introduces a new control problem: managing when to retrieve information, verify facts, and orchestrate these external tools. Without faithful uncertainty, an agent is essentially flying blind and must rely on external, static heuristics or over-engineered scaffolds.</p><p>“The model might search for something it already knows confidently—wasting latency and cost for no gain. Or the opposite: it confidently answers from memory when it should have searched, producing a plausible but wrong output,” Yona said. Today’s agent harnesses try to solve this externally with query classifiers or always-search rules, but Yona notes that these are "static and brittle." By using its intrinsic uncertainty to regulate its own behavior, the agent dynamically optimizes its tool use, choosing to invoke a search tool only when its internal confidence is genuinely low.</p><p>Beyond deciding when to search, faithful uncertainty is critical for evaluating the results of a search. If a tool returns low-quality or unexpected information, a metacognitive agent does not blindly accept whatever appears in its context window. Instead, it uses its uncertainty awareness to weigh the retrieved external signals against its own internal priors. This prevents sycophantic behavior where the system might otherwise trust external sources that conflict with its actual known knowledge.</p><h2>The bootstrapping paradox: The catch to teaching uncertainty</h2><p>For enterprise builders, achieving this faithful uncertainty is trickier than it sounds. It requires teaching models the syntax of uncertainty through supervised fine-tuning (SFT). Because pre-trained models are mostly fed authoritative text, they must be explicitly taught to say things like, "I'm not entirely sure, but I think VentureBeat was founded in..."</p><p>But SFT introduces a "bootstrapping paradox." Unlike standard training datasets where the "right answer" is the same regardless of the model, the ground truth for uncertainty is the model's own dynamic knowledge base.</p><p>“Here's the catch: the 'correct' expression of uncertainty is inherently dynamic, because it depends on what this particular model knows or doesn't know at this particular point in training,” Yona said. “If you train on a label that says 'I don't know X' but the model actually does know X, you've taught it to hallucinate uncertainty... The training data is static, but the target is a moving one, and that's the fundamental tension teams need to grapple with.”</p><h2>The road to self-aware AI</h2><p>For enterprises looking to implement these capabilities without expensive retraining, prompting serves as the most accessible entry point. “Prompt engineering is already something most engineers do today, this provides the lowest-friction path to improving metacognitive behavior today,” Yona said. Enterprise developers can explore frameworks like <a href="https://github.com/yale-nlp/MetaFaith">MetaFaith</a>, an open-source project previously co-authored by Yona, to begin applying metacognitive prompting to off-the-shelf models.</p><p>However, Yona cautions that "there is still substantial headroom that prompting alone doesn’t solve," meaning the industry will eventually need to rely on advanced reinforcement learning (RL) to bake metacognition deeply into model training.</p><p>Ultimately, as enterprises transition from isolated chat applications to complex, multi-agent workflows, self-awareness will become a defining prerequisite for reliable autonomy. But evaluating whether a model truly possesses this awareness remains a profound technical challenge.</p><p>“How do you actually evaluate whether a model can sense its internal states?” Yona asks. “Even in humans, it’s hard to define or separate 'true' self-monitoring abilities from a capable reliance on proxies. We face exactly the same challenges with LLMs: a model might learn to mimic the style of uncertainty without truly sensing its internal state. Developing evaluation frameworks that can tell the difference is one of the most important open problems in this space.”</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The new NTFS kernel driver sees an improvement for Windows native symbolic links]]></title>
<description><![CDATA[From the article  One of the exciting additions to the Linux 7.1 kernel is the introduction of the new NTFS file-system kernel driver. While in good shape already and proving advantageous over other NTFS open-source driver options, one of the initial limitations on it is around Windows native sym...]]></description>
<link>https://tsecurity.de/de/3594383/linux-tipps/the-new-ntfs-kernel-driver-sees-an-improvement-for-windows-native-symbolic-links/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594383/linux-tipps/the-new-ntfs-kernel-driver-sees-an-improvement-for-windows-native-symbolic-links/</guid>
<pubDate>Fri, 12 Jun 2026 21:11:55 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p><strong>From the article</strong></p> <blockquote> <p>One of the <a href="https://www.phoronix.com/review/linux-71-features-changes">exciting additions to the Linux 7.1 kernel</a> is <a href="https://www.phoronix.com/news/Linux-7.1-New-NTFS-Driver">the introduction of the new NTFS file-system kernel driver</a>. While in good shape already and proving advantageous over other NTFS open-source driver options, one of the initial limitations on it is around Windows native symbolic link handling but that is now in the process of being resolved. </p> </blockquote> <p>Windows native symbolic links is for handling symlinks at the file-system level compared to the conventional Windows <em>.lnk</em> shortcuts. The Windows native symbolic links is akin to the symlinks on other platforms for transparent symbolic link handling. </p> <p>Open-source developer Hyunchul Lee today posted a set of patches in working on this native symbolic links support for the new NTFS driver. This allows parsing and following Windows native symbolic links, adding a new <strong>native_symlink=raw|rel</strong> mount option for configuring target resolution, and a <strong>symlink=wsl|native</strong> mount option for choosing between symlink creation behavior. Plus there are some other bug fixes and documentation additions for the NTFS driver. </p> <p>See <a href="https://lore.kernel.org/all/20260612-topic-symlink-v1-0-cc1ebf9528e1@gmail.com/">this patch series</a> for those interested in the topic. Given the timing though it's unlikely it will make it for the upcoming Linux v7.2 cycle but likely diverted to another follow-on kernel cycle depending upon how the patch review proceeds.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/somerandomxander"> /u/somerandomxander </a> <br> <span><a href="https://www.phoronix.com/news/NTFS-Windows-Symbolic-Links">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1u43a2l/the_new_ntfs_kernel_driver_sees_an_improvement/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[How and when macOS will finally stop support for Intel apps]]></title>
<description><![CDATA[Apple's forthcoming macOS 27 doesn't run on Intel Macs at all, and that's just the beginning of a timeline that will complete a years-long transition to Apple Silicon. Here's what to expect, and when.Running Intel apps on Macs will soon be a thing of the pastWhen Apple unveiled macOS 27 during it...]]></description>
<link>https://tsecurity.de/de/3593901/ios-mac-os/how-and-when-macos-will-finally-stop-support-for-intel-apps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593901/ios-mac-os/how-and-when-macos-will-finally-stop-support-for-intel-apps/</guid>
<pubDate>Fri, 12 Jun 2026 17:35:22 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple's forthcoming <a href="https://appleinsider.com/inside/macos-27" title="macOS 27" data-kpt="1">macOS 27</a> doesn't run on Intel Macs at all, and that's just the beginning of a timeline that will complete a years-long transition to Apple Silicon. Here's what to expect, and when.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67937-143218-MacBook-stack-2026-side-xl.jpg" alt="Four closed Apple MacBooks in yellow, blue, silver, and black stand upright in a row on a white desk, against a softly lit purple and blue background" height="738" class=""><br><span>Running Intel apps on Macs will soon be a thing of the past</span></div><br>When Apple unveiled macOS 27 during its <a href="https://appleinsider.com/inside/wwdc" title="WWDC" data-kpt="1">WWDC</a> 2026 opening keynote, it put into motion its previously announced plan for the end of Intel <a href="https://appleinsider.com/inside/mac" title="Mac" data-kpt="1">Macs</a>. Not only will the update not support any Intel Macs, but it also removes the <a href="https://appleinsider.com/inside/rosetta-2" title="Rosetta 2" data-kpt="1">Rosetta 2</a> translation layer that allows Intel apps to run on other Macs, too.<br><br>Apple announced the transition away from Intel chips in 2020, choosing to use its own in-house silicon instead. Now, six years later, it's getting ready to complete that transition, and app developers are on notice.<br><br><br> <a href="https://appleinsider.com/articles/26/06/12/how-and-when-macos-will-finally-stop-support-for-intel-apps?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244641?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Halo: Campaign Evolved’s skulls and Remix Mode have me wondering how far the chaos can go]]></title>
<description><![CDATA[Halo Studios has revealed 42 skulls and an all-new Campaign Remix mode for Halo: Campaign Evolved. The new modifiers range from classic fan favorites to major gameplay and visual changes designed to boost replayability.]]></description>
<link>https://tsecurity.de/de/3588658/windows-tipps/halo-campaign-evolveds-skulls-and-remix-mode-have-me-wondering-how-far-the-chaos-can-go/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588658/windows-tipps/halo-campaign-evolveds-skulls-and-remix-mode-have-me-wondering-how-far-the-chaos-can-go/</guid>
<pubDate>Wed, 10 Jun 2026 20:40:16 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Halo Studios has revealed 42 skulls and an all-new Campaign Remix mode for Halo: Campaign Evolved. The new modifiers range from classic fan favorites to major gameplay and visual changes designed to boost replayability.]]></content:encoded>
</item>
<item>
<title><![CDATA[I found two great EcoTank printer deals on Amazon — but you should only buy this one]]></title>
<description><![CDATA[Choosing between the EcoTank ET-2860 and the ET-2861 is easy - they're the same printer, so buy the cheapest]]></description>
<link>https://tsecurity.de/de/3588438/it-nachrichten/i-found-two-great-ecotank-printer-deals-on-amazon-but-you-should-only-buy-this-one/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588438/it-nachrichten/i-found-two-great-ecotank-printer-deals-on-amazon-but-you-should-only-buy-this-one/</guid>
<pubDate>Wed, 10 Jun 2026 19:03:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Choosing between the EcoTank ET-2860 and the ET-2861 is easy - they're the same printer, so buy the cheapest]]></content:encoded>
</item>
<item>
<title><![CDATA[AI is becoming a single point of failure — and most companies don’t see it]]></title>
<description><![CDATA[Artificial intelligence doesn’t exist in a vacuum. It runs on infrastructure that is increasingly constrained, contested and, in many cases, outside a company’s control.



That reality is starting to surface in subtle ways. Vendors are adjusting access to AI capabilities, introducing tiered usag...]]></description>
<link>https://tsecurity.de/de/3587233/it-security-nachrichten/ai-is-becoming-a-single-point-of-failure-and-most-companies-dont-see-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3587233/it-security-nachrichten/ai-is-becoming-a-single-point-of-failure-and-most-companies-dont-see-it/</guid>
<pubDate>Wed, 10 Jun 2026 12:09:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Artificial intelligence doesn’t exist in a vacuum. It runs on infrastructure that is increasingly constrained, contested and, in many cases, outside a company’s control.</p>



<p>That reality is starting to surface in subtle ways. Vendors are adjusting access to AI capabilities, introducing tiered usage models and quietly reshaping what customers can expect from their tools. Microsoft, for example, has already <a href="https://support.microsoft.com/en-US/Microsoft-365-Copilot/standard-versus-priority-access-to-features-in-microsoft-365-copilot-chat" rel="nofollow">shifted features and access</a> within its Copilot ecosystem, signaling that capacity is not unlimited.</p>



<p>This isn’t new. In the early days of the internet, service providers could throttle access based on demand or pricing tiers until regulation stepped in to standardize availability. AI is beginning to follow a similar trajectory but with a more complex set of constraints: power availability, data center capacity, geopolitical risk and vendor concentration.</p>



<p>What makes this different is how quickly AI is being embedded into core business workflows. Nearly three-quarters of organizations are already using AI to automate processes across multiple business functions. Yet most have done little to account for the business interruption risk that creates. Many enterprises treat AI as always-available infrastructure. In reality, it is capacity-constrained, vendor-dependent and vulnerable to disruption.</p>



<p>The next phase of AI maturity isn’t about adoption. It will be about resilience, continuity and dependency management.</p>



<h2 class="wp-block-heading">Business continuity in an AI-dependent operating model</h2>



<p>The question is no longer whether work can get done without AI. It is whether businesses can operate at the speed and volume they have already committed to without it.</p>



<p>Many organizations have redesigned workflows around AI-enabled efficiency. Tasks that once took hours now take minutes. Teams have been streamlined, and service-level commitments have been tightened. In many cases, entire operating models assume continuous AI availability.</p>



<p>In practice, it doesn’t hold. Even short disruptions can expose the gap. During a recent Microsoft services outage, some organizations lost access to AI models embedded in their workflows. Employees had to manually process tasks that had been automated — slowing operations and creating backlogs almost immediately.</p>



<p>At a small scale, that’s manageable. At the enterprise scale, it becomes a continuity risk. Planning for AI disruption starts with a mindset shift. Most continuity planning assumes degradation: systems slow down but still function. However, AI introduces scenarios where capabilities are unavailable altogether.</p>



<p>When building out a business continuity plan, three things are key:</p>



<ol class="wp-block-list">
<li><strong>Know what breaks.</strong> Most organizations don’t have a clear inventory of where AI is embedded across their workflows, including dependencies on specific vendors, models and infrastructure. Without that visibility, it’s difficult to understand failure points or build a mitigation plan around them.<br></li>



<li><strong>Plan for absence, not degradation.</strong> If an AI system goes offline, what happens next? In many cases, there is no fallback. Skills have atrophied, staffing models have changed and processes have been optimized around automation. This is where risk management needs a seat at the table, not just IT.<br></li>



<li><strong>Reintroduce operational buffers.</strong> Resilience requires redundancy — whether that’s retaining institutional knowledge, maintaining alternative workflows or diversifying providers. These investments rarely show immediate returns, which is why they are often deferred.</li>
</ol>



<p>This is not fundamentally different from how organizations approached cybersecurity a decade ago. What once felt optional is now baseline.</p>



<h2 class="wp-block-heading">Insurance and the emerging business interruption gap</h2>



<p>As AI becomes embedded in core operations, the financial exposure tied to its disruption is becoming harder to ignore. This exposure does not fit neatly into existing insurance frameworks.</p>



<p>There are parallels to the early days of cyber risk. Before stand-alone cyber policies existed, losses were often absorbed — or disputed — across general liability, crime and fraud coverage. Insurers responded by introducing exclusions and, eventually, dedicated cyber policies.</p>



<p>AI risk is following a similar path, but with additional complexity. Events like the CrowdStrike outage, which affected systems globally, <a href="https://www.reuters.com/technology/insurers-face-business-interruption-claims-after-global-tech-outage-2024-07-19/" rel="nofollow">raised questions about business interruption coverage</a>, with organizations pursuing claims tied to financial losses. In that case, cyber coverage was a likely entry point.</p>



<p>AI introduces a different layer. A disruption may not be a cyber event at all. It could be tied to power grid constraints affecting data centers, vendor-driven capacity limits, regulatory restrictions or geopolitical events. The failure is external and not necessarily malicious, which raises a fundamental question: Where does the loss sit?</p>



<p>For most organizations today, the answer is unclear. That uncertainty is driving early conversations around stand-alone AI coverage. While those products are still evolving, the more immediate priority is understanding where exposure exists and where it may be underinsured.</p>



<p>That requires translating AI dependency into financial terms. What revenue is tied to AI-enabled workflows? What contractual obligations depend on those outputs? What happens if those capabilities are unavailable?</p>



<p>Until those questions are addressed, the risk remains largely unquantified.</p>



<h2 class="wp-block-heading">Your AI partners are your risk model</h2>



<p>Much of this exposure is concentrated in a small number of providers. The companies building and operating large-scale AI systems, such as OpenAI and Anthropic, are making real-time decisions about how their platforms operate under constraints. Those decisions shape how every dependent organization experiences performance, access and disruption.</p>



<p>That includes how capacity is allocated when demand exceeds supply, which features are available at different pricing tiers, how models are trained and governed and how infrastructure is expanded or limited based on power and regulatory conditions.</p>



<p>These are not purely technical considerations. They are business decisions made by third parties that directly affect your operations. As a result, choosing an AI partner is a dependency decision that will shape how your business operates under both normal conditions and disruption.</p>



<p>Three areas to consider:</p>



<ol class="wp-block-list">
<li><strong>Trust and responsibility. </strong>How models are trained, how bias is managed and how outputs are governed all have downstream implications.<br></li>



<li><strong>Operational reliability. </strong>Service levels now involve more than uptime. They include which capabilities you can access, at what price tier and whether performance holds when demand is high.<br></li>



<li><strong>Alignment of priorities. </strong>When constraints emerge, vendors decide where resources go. Enterprises need to understand where they sit in that hierarchy.</li>
</ol>



<p>There is no universal framework for making these decisions yet. Organizations are building their approach in real time.</p>



<h2 class="wp-block-heading">A different kind of infrastructure risk</h2>



<p>AI is often framed as a competitive advantage. In many cases, it is. But as it shifts from a capability to core infrastructure that is shared, constrained and subject to forces beyond any single organization’s control, the risk profile changes fundamentally.</p>



<p>That dependency is the risk. Enterprises don’t need to slow down adoption. The pressure to move forward is real. But they do need a clearer view of what they are building on and what happens when that foundation is under strain.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.csoonline.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Enterprises know AI-generated code is vulnerable; they’re shipping it anyway]]></title>
<description><![CDATA[AI-generated code is riddled with security flaws, yet enterprises are shipping more of it than ever before. Why? Perhaps they’re over-confident, lack true visibility into security risks, or are simply choosing to ignore the problem and hope it goes away.



It’s a dangerous game to play at the da...]]></description>
<link>https://tsecurity.de/de/3586366/it-security-nachrichten/enterprises-know-ai-generated-code-is-vulnerable-theyre-shipping-it-anyway/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3586366/it-security-nachrichten/enterprises-know-ai-generated-code-is-vulnerable-theyre-shipping-it-anyway/</guid>
<pubDate>Wed, 10 Jun 2026 05:23:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AI-generated code is riddled with security flaws, yet enterprises are shipping more of it than ever before. Why? Perhaps they’re over-confident, lack true visibility into security risks, or are simply choosing to ignore the problem and hope it goes away.</p>



<p>It’s a dangerous game to play at the dawn of the agentic AI era, as underscored in a <a href="https://checkmarx.com/blog/just-launched-the-future-of-application-security-in-the-era-of-ai-2027-industry-outlook/" target="_blank" rel="noreferrer noopener">new report</a> from app security company Checkmarx.</p>



<p>The survey of thousands of <a href="https://www.csoonline.com/article/4181920/15-tough-cybersecurity-questions-every-ciso-must-answer.html" target="_blank">security leaders</a> exposes an underlying naivete about AI-built code and its vulnerabilities, even as tools like Anthropic’s Mythos are uncovering security flaws orders of magnitude faster than any human security team could ever hope to.</p>



<p>“Mythos-class models collapse the window between a vulnerability existing and a working exploit being available from months to minutes,” the report notes. Enterprises relying on traditional security tools and methods, it says, “cannot survive this reality.”</p>



<h2 class="wp-block-heading">Security as an afterthought</h2>



<p>Checkmarx’s survey of 2,350 CISOs, AppSec managers, and developers across 14 countries focused on how much AI-developed code enterprises are deploying, the vulnerabilities it introduces, how it impacts developer workflows, and overall sentiment about AI code and security posture.</p>



<p>Today, nearly half of production code is AI-generated, and the majority of enterprises also report that at least half their codebase is made up of open-source components, according to the report.</p>



<p>But the more AI-generated code that is pushed out, the more vulnerabilities are exposed. Enterprises who said 81% – 100% of their code is built by AI ship vulnerable code 3.4 times more often than businesses using AI more conservatively, relying on 20% or less AI code.</p>



<p>Additionally, 70% of developers said that AI code generation created vulnerabilities in 2025, and almost all enterprises surveyed (93%) had at least one security breach as a direct result of in-house developed apps.</p>



<p>Still, risk is becoming “normalized,” the report notes, with three-quarters of enterprises knowingly deploying vulnerable code as they face increased pressure for ROI. Startlingly, about 30% of respondents admitted they ship compromised code and hope the vulnerability won’t be found. Similarly, more than a third of organizations leave half of their known vulnerabilities unfixed for 90 days or more.</p>



<p>The report points out that the organizational bottleneck isn’t detection, “it’s the human decision to ship anyway, suppress the finding, or defer to the next sprint.”</p>



<p>Along with this, AppSec teams are often limited to reactive incident response as they deal with tool sprawl. And developers only continuously secure code a small percentage of the time (18%), even though nearly all are equipped with security tooling.</p>



<p>Ultimately, developers are “set up to fail,” the report contends. They face significant pressure to deliver, and are forced to choose quantity and speed over security. Yet, even as they face significant consequences when it comes to post-mortems, performance reviews, escalation, and blocked releases, the tools that contribute to security issues, delivering low-value findings, unclear guidance, or late feedback, continue to go unfixed.</p>



<p>“Developers remain accountable for outcomes, even when systems and workflows are not aligned to support them,” the report notes.</p>



<h2 class="wp-block-heading">Overconfidence, outdated practices</h2>



<p>Alarmingly, many enterprises seem to be deluded when it comes to their security posture. Of those that rate themselves as “highly mature” AI organizations, 42% often ship the most vulnerable code, and have breach rates “barely distinguishable” from other enterprises.</p>



<p>“Confidence isn’t protecting them,” the report notes. “It’s blinding them.”</p>



<p>Underscoring this, only 22% of organizations have formal AI governance, and developers still rely on manual code reviews to ensure their code meets compliance standards.</p>



<p>The result is a mismatch between the speed of software creation and the speed of governance, the report notes. “Compliance frameworks are evolving, but many organizations are still attempting to govern AI-scale development with processes designed for a slower era of software delivery.”</p>



<h2 class="wp-block-heading">Strategic imperatives for enterprises</h2>



<p>Enterprises do seem to have wised up (a bit) after <a href="https://www.csoonline.com/article/4158117/anthropics-mythos-signals-a-structural-cybersecurity-shift.html" target="_blank">Anthropic’s Mythos</a> proved capable of not only discovering vulnerabilities across major operating systems and browsers, but exploiting them 100 times faster than previous Claude models. And the subsequent <a href="https://www.cio.com/article/4177294/this-is-not-a-security-problem-anthropics-mythos-glasswing-and-how-the-industry-must-move-forward.html" target="_blank">Project Glasswing</a> almost immediately surfaced thousands of previously-unidentified security flaws.</p>



<p>Checkmarx’s survey, which, it should be noted, was conducted a month prior to Mythos’ arrival, found that enterprises are finally taking proactive measures, focusing more heavily on AI security threats overall, and investing more in DevSecOps practices, automation, and developer training.</p>



<p>The report emphasizes the importance of prioritizing risk over code volume; vulnerabilities should not be considered isolated incidents. Also, it’s critical to <a href="https://csrc.nist.gov/csrc/media/presentations/2026/secure-by-design/2.4-secure_by_design-dukes-lee.pdf" target="_blank" rel="noreferrer noopener">embed security</a> into developer workflows rather than treating it as a checkpoint. Enterprises must have systems that reduce noise, provide clear guidance, and allow them to take action when an issue arises.</p>



<p>Security “must be integrated directly into how developers write, test, and ship code within the IDE, pipelines, and AI-assisted workflows where development now happens,” the report notes.</p>



<p>Similarly, enterprises would benefit by reducing fragmentation and tool sprawl and defining ownership of the AI tools. By simplifying security stacks, they can align responsibilities and ensure consistent tool use, according to the report.</p>



<p>Further, AI needs strong governance, and teams must move beyond outdated manual triage and “human-gated remediation.” AI can fight AI in a strong system built to prioritize, remediate, and resolve risk “without waiting for a human to approve each step,” the report notes.</p>



<p>Ultimately, it says: “Progress depends on embedding intelligence directly into workflows, enabling risks to be prioritized, remediated, and resolved, all within the systems that they operate in.”</p>



<p><em>This article originally appeared on <a href="https://www.cio.com/article/4183209/enterprises-know-ai-generated-code-is-vulnerable-theyre-shipping-it-anyway.html" target="_blank">CIO.com</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Enterprises know AI-generated code is vulnerable; they’re shipping it anyway]]></title>
<description><![CDATA[AI-generated code is riddled with security flaws, yet enterprises are shipping more of it than ever before. Why? Perhaps they’re over-confident, lack true visibility into security risks, or are simply choosing to ignore the problem and hope it goes away.



It’s a dangerous game to play at the da...]]></description>
<link>https://tsecurity.de/de/3586362/ai-nachrichten/enterprises-know-ai-generated-code-is-vulnerable-theyre-shipping-it-anyway/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3586362/ai-nachrichten/enterprises-know-ai-generated-code-is-vulnerable-theyre-shipping-it-anyway/</guid>
<pubDate>Wed, 10 Jun 2026 05:18:40 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AI-generated code is riddled with security flaws, yet enterprises are shipping more of it than ever before. Why? Perhaps they’re over-confident, lack true visibility into security risks, or are simply choosing to ignore the problem and hope it goes away.</p>



<p>It’s a dangerous game to play at the dawn of the agentic AI era, as underscored in a <a href="https://checkmarx.com/blog/just-launched-the-future-of-application-security-in-the-era-of-ai-2027-industry-outlook/" target="_blank" rel="noreferrer noopener">new report</a> from app security company Checkmarx.</p>



<p>The survey of thousands of <a href="https://www.csoonline.com/article/4181920/15-tough-cybersecurity-questions-every-ciso-must-answer.html" target="_blank">security leaders</a> exposes an underlying naivete about AI-built code and its vulnerabilities, even as tools like Anthropic’s Mythos are uncovering security flaws orders of magnitude faster than any human security team could ever hope to.</p>



<p>“Mythos-class models collapse the window between a vulnerability existing and a working exploit being available from months to minutes,” the report notes. Enterprises relying on traditional security tools and methods, it says, “cannot survive this reality.”</p>



<h2 class="wp-block-heading">Security as an afterthought</h2>



<p>Checkmarx’s survey of 2,350 CISOs, AppSec managers, and developers across 14 countries focused on how much AI-developed code enterprises are deploying, the vulnerabilities it introduces, how it impacts developer workflows, and overall sentiment about AI code and security posture.</p>



<p>Today, nearly half of production code is AI-generated, and the majority of enterprises also report that at least half their codebase is made up of open-source components, according to the report.</p>



<p>But the more AI-generated code that is pushed out, the more vulnerabilities are exposed. Enterprises who said 81% – 100% of their code is built by AI ship vulnerable code 3.4 times more often than businesses using AI more conservatively, relying on 20% or less AI code.</p>



<p>Additionally, 70% of developers said that AI code generation created vulnerabilities in 2025, and almost all enterprises surveyed (93%) had at least one security breach as a direct result of in-house developed apps.</p>



<p>Still, risk is becoming “normalized,” the report notes, with three-quarters of enterprises knowingly deploying vulnerable code as they face increased pressure for ROI. Startlingly, about 30% of respondents admitted they ship compromised code and hope the vulnerability won’t be found. Similarly, more than a third of organizations leave half of their known vulnerabilities unfixed for 90 days or more.</p>



<p>The report points out that the organizational bottleneck isn’t detection, “it’s the human decision to ship anyway, suppress the finding, or defer to the next sprint.”</p>



<p>Along with this, AppSec teams are often limited to reactive incident response as they deal with tool sprawl. And developers only continuously secure code a small percentage of the time (18%), even though nearly all are equipped with security tooling.</p>



<p>Ultimately, developers are “set up to fail,” the report contends. They face significant pressure to deliver, and are forced to choose quantity and speed over security. Yet, even as they face significant consequences when it comes to post-mortems, performance reviews, escalation, and blocked releases, the tools that contribute to security issues, delivering low-value findings, unclear guidance, or late feedback, continue to go unfixed.</p>



<p>“Developers remain accountable for outcomes, even when systems and workflows are not aligned to support them,” the report notes.</p>



<h2 class="wp-block-heading">Overconfidence, outdated practices</h2>



<p>Alarmingly, many enterprises seem to be deluded when it comes to their security posture. Of those that rate themselves as “highly mature” AI organizations, 42% often ship the most vulnerable code, and have breach rates “barely distinguishable” from other enterprises.</p>



<p>“Confidence isn’t protecting them,” the report notes. “It’s blinding them.”</p>



<p>Underscoring this, only 22% of organizations have formal AI governance, and developers still rely on manual code reviews to ensure their code meets compliance standards.</p>



<p>The result is a mismatch between the speed of software creation and the speed of governance, the report notes. “Compliance frameworks are evolving, but many organizations are still attempting to govern AI-scale development with processes designed for a slower era of software delivery.”</p>



<h2 class="wp-block-heading">Strategic imperatives for enterprises</h2>



<p>Enterprises do seem to have wised up (a bit) after <a href="https://www.csoonline.com/article/4158117/anthropics-mythos-signals-a-structural-cybersecurity-shift.html" target="_blank">Anthropic’s Mythos</a> proved capable of not only discovering vulnerabilities across major operating systems and browsers, but exploiting them 100 times faster than previous Claude models. And the subsequent <a href="https://www.cio.com/article/4177294/this-is-not-a-security-problem-anthropics-mythos-glasswing-and-how-the-industry-must-move-forward.html" target="_blank">Project Glasswing</a> almost immediately surfaced thousands of previously-unidentified security flaws.</p>



<p>Checkmarx’s survey, which, it should be noted, was conducted a month prior to Mythos’ arrival, found that enterprises are finally taking proactive measures, focusing more heavily on AI security threats overall, and investing more in DevSecOps practices, automation, and developer training.</p>



<p>The report emphasizes the importance of prioritizing risk over code volume; vulnerabilities should not be considered isolated incidents. Also, it’s critical to <a href="https://csrc.nist.gov/csrc/media/presentations/2026/secure-by-design/2.4-secure_by_design-dukes-lee.pdf" target="_blank" rel="noreferrer noopener">embed security</a> into developer workflows rather than treating it as a checkpoint. Enterprises must have systems that reduce noise, provide clear guidance, and allow them to take action when an issue arises.</p>



<p>Security “must be integrated directly into how developers write, test, and ship code within the IDE, pipelines, and AI-assisted workflows where development now happens,” the report notes.</p>



<p>Similarly, enterprises would benefit by reducing fragmentation and tool sprawl and defining ownership of the AI tools. By simplifying security stacks, they can align responsibilities and ensure consistent tool use, according to the report.</p>



<p>Further, AI needs strong governance, and teams must move beyond outdated manual triage and “human-gated remediation.” AI can fight AI in a strong system built to prioritize, remediate, and resolve risk “without waiting for a human to approve each step,” the report notes.</p>



<p>Ultimately, it says: “Progress depends on embedding intelligence directly into workflows, enabling risks to be prioritized, remediated, and resolved, all within the systems that they operate in.”</p>



<p><em>This article originally appeared on <a href="https://www.cio.com/article/4183209/enterprises-know-ai-generated-code-is-vulnerable-theyre-shipping-it-anyway.html" target="_blank">CIO.com</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[v1.17.0]]></title>
<description><![CDATA[Core
Improvements

Faster file search across large projects with the new fff-backed search tools. (@dmtrKovalenko)
Added X-Session-Id headers for proxy setups that need sticky routing. (@songchaow)
Added Cohere North model support.
Added reasoning as an interleaved field option for vLLM providers...]]></description>
<link>https://tsecurity.de/de/3586357/downloads/v1170/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3586357/downloads/v1170/</guid>
<pubDate>Wed, 10 Jun 2026 05:16:56 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Core</h2>
<h3>Improvements</h3>
<ul>
<li>Faster file search across large projects with the new <code>fff</code>-backed search tools. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dmtrKovalenko/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dmtrKovalenko">@dmtrKovalenko</a>)</li>
<li>Added <code>X-Session-Id</code> headers for proxy setups that need sticky routing. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/songchaow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/songchaow">@songchaow</a>)</li>
<li>Added Cohere North model support.</li>
<li>Added <code>reasoning</code> as an interleaved field option for vLLM providers. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/delta9000/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/delta9000">@delta9000</a>)</li>
<li><code>mcp add</code> now works in non-interactive flows.</li>
<li><code>auth logout</code> now supports search when choosing an account.</li>
</ul>
<h3>Bugfixes</h3>
<ul>
<li>Improved MCP connection status messages so failures are easier to act on.</li>
<li>Added Claude Fable reasoning support.</li>
<li>MCP tool calls now receive abort signals, so cancellations stop more reliably.</li>
<li>MCP catalogs now paginate correctly instead of truncating larger lists.</li>
<li>OpenRouter reasoning variants now generate for all models. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AnthonyMLau/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AnthonyMLau">@AnthonyMLau</a>)</li>
<li>Added MiniMax M3 thinking toggle support.</li>
<li>Java multi-module Maven workspaces now resolve JDTLS from the topmost <code>pom.xml</code>. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/areyouok/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/areyouok">@areyouok</a>)</li>
<li>MCP servers now respect advertised capabilities.</li>
<li>Session lists now respect directory filters in workspace setups. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rexdotsh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rexdotsh">@rexdotsh</a>)</li>
<li>Sessions can recover once from provider context-overflow errors instead of failing immediately.</li>
<li>Bedrock Mantle config now honors configured API key and region settings.</li>
</ul>
<h2>TUI</h2>
<h3>Improvements</h3>
<ul>
<li>The session move flow now highlights project copies more clearly and keeps the current location selected.</li>
<li>Project copies can now be deleted directly from the move dialog.</li>
</ul>
<h3>Bugfixes</h3>
<ul>
<li>New project copies are now bootstrapped before the TUI switches into them.</li>
<li>Moving a session now injects a reminder about the new working directory.</li>
</ul>
<h2>Desktop</h2>
<h3>Improvements</h3>
<ul>
<li>Added a help button to the tabs bar.</li>
<li>Prompt drafts are preserved while you switch tabs.</li>
<li>File attachments now open in the active project.</li>
<li>App updates now stay responsive and persist across restarts.</li>
<li>Added WSL-backed Desktop support and WSL server management on Windows.</li>
<li>Improved the sessions list UI. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/arvsrn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/arvsrn">@arvsrn</a>)</li>
<li>Improved the servers UI. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/arvsrn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/arvsrn">@arvsrn</a>)</li>
</ul>
<h3>Bugfixes</h3>
<ul>
<li>Updated Electron and fixed related panel layout issues.</li>
<li>Fixed several WSL Desktop bugs. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neriousy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neriousy">@neriousy</a>)</li>
<li>Hidden agents no longer get cycled accidentally.</li>
<li>MCP status now refreshes when the active directory changes.</li>
<li>The Home screen now keeps a larger recent-session list with scrolling.</li>
</ul>
<h2>SDK</h2>
<h3>Improvements</h3>
<ul>
<li>Large v2 tool outputs are now bounded and expose retained output paths for follow-up inspection.</li>
</ul>
<p><strong>Thank you to 11 community contributors:</strong></p>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rexdotsh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rexdotsh">@rexdotsh</a>:
<ul>
<li>fix(session): respect directory filter with workspaces (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4591433438" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/30804" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/30804/hovercard" href="https://github.com/anomalyco/opencode/pull/30804">#30804</a>)</li>
</ul>
</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/arvsrn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/arvsrn">@arvsrn</a>:
<ul>
<li>feat(app): improve servers UI (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4597355284" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/30961" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/30961/hovercard" href="https://github.com/anomalyco/opencode/pull/30961">#30961</a>)</li>
<li>feat(app): updates to project avatar (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4597497843" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/30964" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/30964/hovercard" href="https://github.com/anomalyco/opencode/pull/30964">#30964</a>)</li>
<li>feat(app): sessions list improvements (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4596671308" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/30941" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/30941/hovercard" href="https://github.com/anomalyco/opencode/pull/30941">#30941</a>)</li>
</ul>
</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dmtrKovalenko/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dmtrKovalenko">@dmtrKovalenko</a>:
<ul>
<li>feat(opencode): fff search tools (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4457497848" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/27802" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/27802/hovercard" href="https://github.com/anomalyco/opencode/pull/27802">#27802</a>)</li>
</ul>
</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fancive/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fancive">@fancive</a>:
<ul>
<li>docs: fix MCP header interpolation example to {env:VAR} (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4602449558" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/31078" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/31078/hovercard" href="https://github.com/anomalyco/opencode/pull/31078">#31078</a>)</li>
</ul>
</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/robertDouglass/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/robertDouglass">@robertDouglass</a>:
<ul>
<li>fix(tui): sort connect providers alphabetically (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4595136306" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/30891" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/30891/hovercard" href="https://github.com/anomalyco/opencode/pull/30891">#30891</a>)</li>
</ul>
</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neriousy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neriousy">@neriousy</a>:
<ul>
<li>fix(desktop): few WSL bugs (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4602770815" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/31095" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/31095/hovercard" href="https://github.com/anomalyco/opencode/pull/31095">#31095</a>)</li>
</ul>
</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/areyouok/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/areyouok">@areyouok</a>:
<ul>
<li>fix(lsp): resolve JDTLS root to topmost pom.xml in Java Maven multi-module projects (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4499333332" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/28761" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/28761/hovercard" href="https://github.com/anomalyco/opencode/pull/28761">#28761</a>)</li>
</ul>
</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/remorses/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/remorses">@remorses</a>:
<ul>
<li>fix(session): merge per-call tool rules into session permission (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4578211404" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/30529" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/30529/hovercard" href="https://github.com/anomalyco/opencode/pull/30529">#30529</a>)</li>
</ul>
</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AnthonyMLau/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AnthonyMLau">@AnthonyMLau</a>:
<ul>
<li>fix(opencode): generate reasoning variants for all OpenRouter models. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4568966602" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/30332" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/30332/hovercard" href="https://github.com/anomalyco/opencode/pull/30332">#30332</a>)</li>
</ul>
</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/delta9000/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/delta9000">@delta9000</a>:
<ul>
<li>feat: add "reasoning" as interleaved field option for vLLM providers (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4575756791" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/30477" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/30477/hovercard" href="https://github.com/anomalyco/opencode/pull/30477">#30477</a>)</li>
</ul>
</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/songchaow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/songchaow">@songchaow</a>:
<ul>
<li>feat: add X-Session-Id header for proxy cache routing affinity (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4621808397" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/31511" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/31511/hovercard" href="https://github.com/anomalyco/opencode/pull/31511">#31511</a>)</li>
</ul>
</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Enterprises know AI-generated code is vulnerable; they’re shipping it anyway]]></title>
<description><![CDATA[AI-generated code is riddled with security flaws, yet enterprises are shipping more of it than ever before. Why? Perhaps they’re over-confident, lack true visibility into security risks, or are simply choosing to ignore the problem and hope it goes away.



It’s a dangerous game to play at the da...]]></description>
<link>https://tsecurity.de/de/3586351/it-security-nachrichten/enterprises-know-ai-generated-code-is-vulnerable-theyre-shipping-it-anyway/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3586351/it-security-nachrichten/enterprises-know-ai-generated-code-is-vulnerable-theyre-shipping-it-anyway/</guid>
<pubDate>Wed, 10 Jun 2026 05:05:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AI-generated code is riddled with security flaws, yet enterprises are shipping more of it than ever before. Why? Perhaps they’re over-confident, lack true visibility into security risks, or are simply choosing to ignore the problem and hope it goes away.</p>



<p>It’s a dangerous game to play at the dawn of the agentic AI era, as underscored in a <a href="https://checkmarx.com/blog/just-launched-the-future-of-application-security-in-the-era-of-ai-2027-industry-outlook/" target="_blank" rel="nofollow">new report</a> from app security company Checkmarx.</p>



<p>The survey of thousands of <a href="https://www.csoonline.com/article/4181920/15-tough-cybersecurity-questions-every-ciso-must-answer.html" target="_blank">security leaders</a> exposes an underlying naivete about AI-built code and its vulnerabilities, even as tools like Anthropic’s Mythos are uncovering security flaws orders of magnitude faster than any human security team could ever hope to.</p>



<p>“Mythos-class models collapse the window between a vulnerability existing and a working exploit being available from months to minutes,” the report notes. Enterprises relying on traditional security tools and methods, it says, “cannot survive this reality.”</p>



<h2 class="wp-block-heading">Security as an afterthought</h2>



<p>Checkmarx’s survey of 2,350 CISOs, AppSec managers, and developers across 14 countries focused on how much AI-developed code enterprises are deploying, the vulnerabilities it introduces, how it impacts developer workflows, and overall sentiment about AI code and security posture.</p>



<p>Today, nearly half of production code is AI-generated, and the majority of enterprises also report that at least half their codebase is made up of open-source components, according to the report.</p>



<p>But the more AI-generated code that is pushed out, the more vulnerabilities are exposed. Enterprises who said 81% – 100% of their code is built by AI ship vulnerable code 3.4 times more often than businesses using AI more conservatively, relying on 20% or less AI code.</p>



<p>Additionally, 70% of developers said that AI code generation created vulnerabilities in 2025, and almost all enterprises surveyed (93%) had at least one security breach as a direct result of in-house developed apps.</p>



<p>Still, risk is becoming “normalized,” the report notes, with three-quarters of enterprises knowingly deploying vulnerable code as they face increased pressure for ROI. Startlingly, about 30% of respondents admitted they ship compromised code and hope the vulnerability won’t be found. Similarly, more than a third of organizations leave half of their known vulnerabilities unfixed for 90 days or more.</p>



<p>The report points out that the organizational bottleneck isn’t detection, “it’s the human decision to ship anyway, suppress the finding, or defer to the next sprint.”</p>



<p>Along with this, AppSec teams are often limited to reactive incident response as they deal with tool sprawl. And developers only continuously secure code a small percentage of the time (18%), even though nearly all are equipped with security tooling.</p>



<p>Ultimately, developers are “set up to fail,” the report contends. They face significant pressure to deliver, and are forced to choose quantity and speed over security. Yet, even as they face significant consequences when it comes to post-mortems, performance reviews, escalation, and blocked releases, the tools that contribute to security issues, delivering low-value findings, unclear guidance, or late feedback, continue to go unfixed.</p>



<p>“Developers remain accountable for outcomes, even when systems and workflows are not aligned to support them,” the report notes.</p>



<h2 class="wp-block-heading">Overconfidence, outdated practices</h2>



<p>Alarmingly, many enterprises seem to be deluded when it comes to their security posture. Of those that rate themselves as “highly mature” AI organizations, 42% often ship the most vulnerable code, and have breach rates “barely distinguishable” from other enterprises.</p>



<p>“Confidence isn’t protecting them,” the report notes. “It’s blinding them.”</p>



<p>Underscoring this, only 22% of organizations have formal AI governance, and developers still rely on manual code reviews to ensure their code meets compliance standards.</p>



<p>The result is a mismatch between the speed of software creation and the speed of governance, the report notes. “Compliance frameworks are evolving, but many organizations are still attempting to govern AI-scale development with processes designed for a slower era of software delivery.”</p>



<h2 class="wp-block-heading">Strategic imperatives for enterprises</h2>



<p>Enterprises do seem to have wised up (a bit) after <a href="https://www.csoonline.com/article/4158117/anthropics-mythos-signals-a-structural-cybersecurity-shift.html" target="_blank">Anthropic’s Mythos</a> proved capable of not only discovering vulnerabilities across major operating systems and browsers, but exploiting them 100 times faster than previous Claude models. And the subsequent <a href="https://www.cio.com/article/4177294/this-is-not-a-security-problem-anthropics-mythos-glasswing-and-how-the-industry-must-move-forward.html" target="_blank">Project Glasswing</a> almost immediately surfaced thousands of previously-unidentified security flaws.</p>



<p>Checkmarx’s survey, which, it should be noted, was conducted a month prior to Mythos’ arrival, found that enterprises are finally taking proactive measures, focusing more heavily on AI security threats overall, and investing more in DevSecOps practices, automation, and developer training.</p>



<p>The report emphasizes the importance of prioritizing risk over code volume; vulnerabilities should not be considered isolated incidents. Also, it’s critical to <a href="https://csrc.nist.gov/csrc/media/presentations/2026/secure-by-design/2.4-secure_by_design-dukes-lee.pdf" target="_blank" rel="nofollow">embed security</a> into developer workflows rather than treating it as a checkpoint. Enterprises must have systems that reduce noise, provide clear guidance, and allow them to take action when an issue arises.</p>



<p>Security “must be integrated directly into how developers write, test, and ship code within the IDE, pipelines, and AI-assisted workflows where development now happens,” the report notes.</p>



<p>Similarly, enterprises would benefit by reducing fragmentation and tool sprawl and defining ownership of the AI tools. By simplifying security stacks, they can align responsibilities and ensure consistent tool use, according to the report.</p>



<p>Further, AI needs strong governance, and teams must move beyond outdated manual triage and “human-gated remediation.” AI can fight AI in a strong system built to prioritize, remediate, and resolve risk “without waiting for a human to approve each step,” the report notes.</p>



<p>Ultimately, it says: “Progress depends on embedding intelligence directly into workflows, enabling risks to be prioritized, remediated, and resolved, all within the systems that they operate in.”</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[6 Best IoT Connectivity Distributors for System Integrators]]></title>
<description><![CDATA[Want the best IoT connectivity distributors for system integrators? Read on. Choosing an IoT SIM distributor can make—or break—your deployment. Pick well and every sensor stays online; pick poorly and field devices rack up fees or fall silent. After stress-testing 12 globally active distributors ...]]></description>
<link>https://tsecurity.de/de/3586135/it-security-nachrichten/6-best-iot-connectivity-distributors-for-system-integrators/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3586135/it-security-nachrichten/6-best-iot-connectivity-distributors-for-system-integrators/</guid>
<pubDate>Wed, 10 Jun 2026 00:54:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Want the best IoT connectivity distributors for system integrators? Read on. Choosing an IoT SIM distributor can make—or break—your deployment. Pick well and every sensor stays online; pick poorly and field devices rack up fees or fall silent. After stress-testing 12 globally active distributors between 2023 and 2026, interviewing integration engineers, and scoring each vendor […]</p>
<p>The post <a href="https://secureblitz.com/best-iot-connectivity-distributors-for-system-integrators/">6 Best IoT Connectivity Distributors for System Integrators</a> appeared first on <a href="https://secureblitz.com/">SecureBlitz Cybersecurity</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic brings Mythos to the masses with Claude Fable 5, its most powerful generally available model ever]]></title>
<description><![CDATA[Anthropic today launched two new AI models — Claude Fable 5 and Claude Mythos 5 — marking the company’s first broad release of the powerful “Mythos-class” AI capabilities it previously made available only to participating organizations in its restricted cybersecurity program, Project Glasswing, w...]]></description>
<link>https://tsecurity.de/de/3585604/it-nachrichten/anthropic-brings-mythos-to-the-masses-with-claude-fable-5-its-most-powerful-generally-available-model-ever/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585604/it-nachrichten/anthropic-brings-mythos-to-the-masses-with-claude-fable-5-its-most-powerful-generally-available-model-ever/</guid>
<pubDate>Tue, 09 Jun 2026 20:32:55 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Anthropic today <a href="https://www.anthropic.com/news/claude-fable-5-mythos-5">launched two new AI models </a>— Claude Fable 5 and Claude Mythos 5 — marking the company’s first broad release of the powerful “Mythos-class” AI capabilities it previously made available only to participating organizations in its restricted cybersecurity program, <a href="https://venturebeat.com/technology/anthropic-says-its-most-powerful-ai-cyber-model-is-too-dangerous-to-release">Project Glasswing</a>, which it announced two months ago.</p><p>The company says Fable 5, which is the version most users and developers will get starting today, exceeds every Claude model it has previously made generally available — featuring stronger performance across software engineering, knowledge work, vision, scientific research and long-running tasks. </p><p>It smashes the existing benchmarks and comes atop on nearly all of them, though the prior Claude Mythos Preview version of the model still takes the top spots on computer use and multidisciplinary reasoning (see benchmark chart below and <a href="https://www.anthropic.com/news/claude-fable-5-mythos-5">here</a>). </p><p>The new Claude Mythos 5, by contrast, is a more restricted, upgraded version of the prior, similarly restricted Mythos Preview model. As such, it has certain safeguards lifted for approved users, including Anthropic's cybersecurity partners in its Project Glasswing effort, and select biology researchers. </p><p>The key difference is that the general purpose Fable 5 wraps the same underlying Mythos-class capability in new safeguards. Anthropic says requests involving certain high-risk areas — including cybersecurity, biology and chemistry, and model distillation — are automatically routed to <a href="https://venturebeat.com/technology/anthropics-claude-opus-4-8-is-here-with-3x-cheaper-fast-mode-and-near-mythos-level-alignment">Claude Opus 4.8,</a> Anthropic's previously flagship general model, instead, with users notified when that happens. </p><p>The company says more than 95% of Fable sessions run entirely on Fable’s own responses, with no fallback, and that internal and external red-teaming efforts found no “universal jailbreaks” after more than 1,000 hours of testing.</p><p>Anthropic says Fable 5 is available to the general public today through its website, apps, and <a href="https://platform.claude.com/docs/en/about-claude/models/overview">API</a>, but that Mythos 5 will initially only be made available to users who already have access to the older Claude Mythos Preview.</p><h2><b>Pricing, access and a tricky rollout</b></h2><p>Anthropic is pricing both Fable 5 and Mythos 5 at $10 per million input tokens and $50 per million output tokens. The company says that is less than half the price of Claude Mythos Preview, but still ranks as the most expensive of major AI models available globally. </p><h1><b>VentureBeat Frontier AI Model API Pricing Snapshot</b></h1><table><tbody><tr><td><p><b>Model</b></p></td><td><p><b>Input</b></p></td><td><p><b>Output</b></p></td><td><p><b>Total Cost</b></p></td><td><p><b>Source</b></p></td></tr><tr><td><p>MiMo-V2.5 Flash</p></td><td><p>$0.10</p></td><td><p>$0.30</p></td><td><p>$0.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi MiMo</a></p></td></tr><tr><td><p>deepseek-v4-flash</p></td><td><p>$0.14</p></td><td><p>$0.28</p></td><td><p>$0.42</p></td><td><p><a href="https://api-docs.deepseek.com/quick_start/pricing">DeepSeek</a></p></td></tr><tr><td><p>deepseek-v4-pro</p></td><td><p>$0.435</p></td><td><p>$0.87</p></td><td><p>$1.305</p></td><td><p><a href="https://api-docs.deepseek.com/quick_start/pricing">DeepSeek</a></p></td></tr><tr><td><p>MiniMax-M3</p></td><td><p>$0.30</p></td><td><p>$1.20</p></td><td><p>$1.50</p></td><td><p><a href="https://platform.minimax.io/subscribe/token-plan?tab=api-enterprise">MiniMax</a></p></td></tr><tr><td><p>Gemini 3.1 Flash-Lite</p></td><td><p>$0.25</p></td><td><p>$1.50</p></td><td><p>$1.75</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Qwen3.7-Plus</p></td><td><p>$0.40</p></td><td><p>$1.60</p></td><td><p>$2.00</p></td><td><p><a href="https://modelstudio.console.alibabacloud.com/ap-southeast-1?tab=doc#/doc/?type=model&amp;url=2840914_2&amp;modelId=qwen3.7-plus&amp;serviceSite=international">Alibaba Cloud</a></p></td></tr><tr><td><p>MiMo-V2.5</p></td><td><p>$0.40</p></td><td><p>$2.00</p></td><td><p>$2.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi MiMo</a></p></td></tr><tr><td><p>Grok 4.3 (low context)</p></td><td><p>$1.25</p></td><td><p>$2.50</p></td><td><p>$3.75</p></td><td><p><a href="https://docs.x.ai/developers/models/grok-4.3">xAI</a></p></td></tr><tr><td><p>GLM-5</p></td><td><p>$1.00</p></td><td><p>$3.20</p></td><td><p>$4.20</p></td><td><p><a href="https://docs.z.ai/guides/overview/pricing">Z.ai</a></p></td></tr><tr><td><p>Kimi-K2.6</p></td><td><p>$0.95</p></td><td><p>$4.00</p></td><td><p>$4.95</p></td><td><p><a href="https://platform.kimi.ai/docs/pricing/chat-k26">Moonshot/Kimi</a></p></td></tr><tr><td><p>GLM-5.1</p></td><td><p>$1.40</p></td><td><p>$4.40</p></td><td><p>$5.80</p></td><td><p><a href="https://docs.z.ai/guides/overview/pricing">Z.ai</a></p></td></tr><tr><td><p>Grok 4.3 (high context)</p></td><td><p>$2.50</p></td><td><p>$5.00</p></td><td><p>$7.50</p></td><td><p><a href="https://docs.x.ai/developers/models/grok-4.3">xAI</a></p></td></tr><tr><td><p>Qwen3.7-Max</p></td><td><p>$2.50</p></td><td><p>$7.50</p></td><td><p>$10.00</p></td><td><p><a href="https://modelstudio.console.alibabacloud.com/ap-southeast-1?spm=a2ty_o05.31384571.0.0.52649f6b7G0D55&amp;tab=doc#/doc/?type=model&amp;url=2840914_2&amp;modelId=qwen3.7-max&amp;serviceSite=international">Alibaba Cloud</a></p></td></tr><tr><td><p>Gemini 3.5 Flash</p></td><td><p>$1.50</p></td><td><p>$9.00</p></td><td><p>$10.50</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (≤200K)</p></td><td><p>$2.00</p></td><td><p>$12.00</p></td><td><p>$14.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>GPT-5.4</p></td><td><p>$2.50</p></td><td><p>$15.00</p></td><td><p>$17.50</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (&gt;200K)</p></td><td><p>$4.00</p></td><td><p>$18.00</p></td><td><p>$22.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Claude Opus 4.8</p></td><td><p>$5.00</p></td><td><p>$25.00</p></td><td><p>$30.00</p></td><td><p><a href="https://platform.claude.com/docs/en/about-claude/pricing">Anthropic</a></p></td></tr><tr><td><p>GPT-5.5</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr><tr><td><p><b>Claude Fable 5 / Claude Mythos 5</b></p></td><td><p><b>$10.00</b></p></td><td><p><b>$50.00</b></p></td><td><p><b>$60.00</b></p></td><td><p><b></b><a href="https://platform.claude.com/docs/en/about-claude/models/overview"><b>Anthropic</b></a></p></td></tr></tbody></table><p>For developers, Fable 5 is available through the Claude API as <code>claude-fable-5</code>. Anthropic says Fable 5 is fully available today on the Claude API and on consumption-based Enterprise plans.</p><p>For subscription users, the rollout is more complicated. Anthropic says Fable 5 will be included on Pro, Max, Team and seat-based Enterprise plans at no extra cost from today through June 22. </p><p>On June 23, the company plans to remove Fable 5 from those plans, after which using it will require usage credits. Anthropic says it aims to restore Fable 5 as a standard part of subscription plans as quickly as possible.</p><h2><b>The difference between Fable 5 and Mythos 5</b></h2><p>Anthropic is not presenting Fable 5 and Mythos 5 as two separate models in the usual “small versus large” sense. Instead, they appear to share the same base capability level. The difference is access <i>control — </i>that is, how easily it will be for users to get their hands on the models, and the guardrails embedded in each.</p><p>As previously mentioned Fable 5 includes a new safeguard layer that detects certain high-risk requests — including cybersecurity, biology and chemistry, and attempts to distill the model’s capabilities into other systems — and routes those requests to Claude Opus 4.8. </p><p>Mythos 5 lifts some of those restrictions for trusted users working in approved domains.</p><p>In practical terms, Mythos 5 is more powerful for sensitive cyber and biology work because it can answer in areas where Fable 5 falls back. </p><p>For most ordinary enterprise and developer tasks, however, Anthropic says Fable 5 performs effectively the same as Mythos 5.</p><p>The launch also signals how Anthropic plans to bring frontier models with dangerous dual-use capabilities into the market: not by releasing all capabilities to everyone, and not by simply refusing risky questions, but by routing some requests to a less capable model while keeping the stronger model available for the majority of everyday work.</p><h2><b>A major improvement in autonomous coding</b></h2><p>For enterprise buyers, the most immediate use case is likely software engineering. Anthropic says Fable 5 can work unattended for longer and with more independence than previous Claude models, which is exactly the capability enterprises need if they want AI agents to do more than autocomplete code or answer developer questions.</p><p>On <b>SWE-bench Pro, which measures a model's ability to complete difficult software engineering tasks, Anthropic says Fable 5 and Mythos 5 reach 80.3%</b>, vastly outperforming OpenAI's latest and greatest general model GPT-5.5, which scored 58.6%. </p><p>On Cognition’s FrontierCode Diamond benchmark, which tests high-quality, maintainable agentic coding, the models score 29.3%, compared with 13.4% for Claude Opus 4.8 and 5.7% for GPT-5.5, according to the benchmark table included in Anthropic’s materials. </p><p>Anthropic also says Fable 5 scores highest among frontier models on FrontierCode even at medium reasoning effort, suggesting the model may deliver stronger coding results without always needing maximum compute.</p><p>The most striking customer example comes from Stripe. Anthropic says Stripe tested Fable 5 in a 50-million-line Ruby codebase and found that the model completed a codebase-wide migration in one day that otherwise would have taken a team more than two months by hand. Stripe said, “Fable 5 compresses months of engineering into days. In our 50-million-line Ruby codebase, it did in a day what would've taken us more than two months by hand.”</p><p>Other early users describe the model as especially useful for long-horizon development tasks. Cursor said, “Fable 5 is the state of the art model on CursorBench. It's opened up a class of long-horizon problems that were out of reach for earlier models.” Replit said Fable 5 is the highest-performing model it has tested on ViBench, its end-to-end “vibe-coding” benchmark, and that it builds apps in less time with fewer tokens. Figma said Fable 5 is “a clear step forward on agentic coding and prototyping.”</p><p>This is the enterprise shift Anthropic is trying to sell: AI coding systems that can take on larger units of work, not just individual tickets. That could include codebase migrations, app prototyping, pull request review, test generation, debugging across unfamiliar tools, user interface design and multi-step internal software projects.</p><p>Base44 said, “Fable 5 is much deeper and better at one-shotting full apps, and its tool calling is excellent.” Genspark said, “Fable 5 came out #1 on our evals, winning head-to-head against every model we tested. It was significantly stronger on the hardest tasks in the set — UI design and game coding.” Rakuten said, “At the highest effort, Fable 5 reflects on and validates its own work. For us, that's what makes highly autonomous operations possible — the extra thinking pays for itself.”</p><p>For CTOs and engineering leaders, that suggests the model’s value may come less from raw code generation and more from sustained execution: understanding an intent, planning steps, calling tools, checking its own work and continuing through a task without constant human steering.</p><h2><b>Knowledge work, finance, legal and operations</b></h2><p>Anthropic is also positioning Fable 5 as a stronger model for enterprise knowledge work. On GDPval-AA, Anthropic reports a score of 1932 for Fable 5 and Mythos 5, compared with 1890 for Claude Opus 4.8, 1769 for GPT-5.5 and 1314 for Gemini 3.1 Pro. </p><p>On GDPpdf, a benchmark focused on visual document reasoning, Fable 5 and Mythos 5 score 29.8% without tools, compared with 22.5% for Opus 4.8, 24.9% for GPT-5.5 and 16.7% for Gemini 3.1 Pro.</p><p>That matters for enterprises because much of corporate work still lives in messy documents: PDFs, spreadsheets, charts, reports, contracts, filings, slide decks and screenshots. Anthropic says Fable 5 shows gains in document-based reasoning, chart and table interpretation and complex problem solving.</p><p>Hex said, “Fable 5 is the first to break 90% on our core analytics benchmark of complex, long-running analytical tasks — a 10-point jump over Opus. On the hardest questions, it shows strong judgment and attention to nuance.” Hebbia said Fable 5 was the highest-scoring model on its Finance Benchmark for senior-level reasoning, with double-digit gains in document reasoning, chart and table interpretation, and problem solving.</p><p>The finance examples are notable because they point to AI agents moving beyond summarization into higher-stakes analytical workflows. </p><p>IMC said Fable 5 “aced our trading-analysis evaluations nearly across the board: factual lookup, conceptual reasoning, root-cause analysis, expected-value analysis.” Optiver said the model was stronger than Opus 4.8 on its trading benchmark and “remarkably consistent,” scoring identically across repeated runs. Balyasny Asset Management said Fable 5 was the strongest finance-first model it had tested.</p><p>Legal and operations teams may also see immediate impact. Crosby Legal said, “Fable 5 feels materially different. In blind review, our lawyers found its redlines matched or beat our current model every time.” Notion said the model can take work “you'd chip away at all afternoon” and turn messy notes into a functioning project plan. Zapier said Fable 5 is the new leader on AutomationBench and is more autonomous than Opus 4.8: “Where Opus stops to ask, Fable 5 keeps looking.”</p><p>For enterprise software vendors, that points toward more capable embedded agents in workflow products: agents that can review a contract, update a project plan, assemble a spreadsheet, inspect a chart, file a ticket, run a query, call an internal API and keep going until the work is complete.</p><h2><b>Vision and interface understanding</b></h2><p>Anthropic says Fable 5 is also its strongest vision model. In its launch materials, the company says the model can extract precise numbers from detailed scientific figures and complete vision-based tasks such as rebuilding a web app’s source code from screenshots alone.</p><p>That has immediate implications for enterprise automation. Many business processes still depend on visual interfaces that are not cleanly exposed through APIs: dashboards, PDFs, forms, legacy apps, screenshots, scans and image-heavy reports. A stronger vision model could help agents operate across those environments with less custom integration work.</p><p>Anthropic also says Fable 5 needs less scaffolding than previous Claude models. As an example, the company says earlier Claude models struggled to play Pokémon FireRed even with extra tools, while <a href="https://youtu.be/CIQBP1w4B1M?si=QCoJ9amBEVMqoTUl">Fable 5 impressively beat the game using a minimal vision-only harness. </a>Anthropic posted a fast forwarded video of its playthrough to YouTube and in its blog post:</p><div></div><p>The point is not gaming itself, but the broader agentic skill: reading a visual environment, remembering progress, deciding what to do next and executing over a long horizon.</p><p>In another internal test, Anthropic says it had the model play the deck-building game Slay the Spire with access to persistent file-based memory. The company says persistent memory improved Fable 5’s performance three times more than it improved Opus 4.8’s, and that Fable reached the game’s final act three times more often. For enterprise users, this suggests Fable 5 may make better use of notes, logs and stored context during multi-step work.</p><p>That could matter for internal agents that operate over days or weeks: sales operations agents that track account research, engineering agents that manage migrations, finance agents that update models, or support agents that remember what they tried across many turns.</p><h2><b>From restricted cyber model to general-purpose enterprise AI</b></h2><p>The announcement follows Anthropic’s April 2025 rollout of Claude Mythos Preview through <a href="https://venturebeat.com/technology/anthropic-says-its-most-powerful-ai-cyber-model-is-too-dangerous-to-release">Project Glasswing</a>, a restricted program for cyber defenders, critical infrastructure providers and major software maintainers. Anthropic created Glasswing after internal evaluations showed Mythos-class models could find and exploit software vulnerabilities at a level that raised meaningful misuse concerns.</p><p>Following the debut of Glasswing and Mythos, <a href="https://www.nextgov.com/cybersecurity/2026/04/anthropics-glasswing-initiative-raises-questions-us-cyber-operations/412721/">U.S. officials and intelligence agencies began weighing</a> how such models could reshape both cyber defense and offensive operations, while Sen. Mark Warner warned that AI-assisted vulnerability discovery should force industry to “accelerate and reprioritize patching.” Financial regulators also took notice: <a href="https://www.theguardian.com/technology/2026/apr/22/what-is-anthropic-mythos-ai-threat-global-cybersecurity">The Guardian reported</a> that Mythos entered discussions among senior banking officials and regulators in the U.S. and U.K. because of fears that AI-accelerated cyberattacks could threaten payment systems and broader financial stability.</p><p>The reaction has not been limited to alarm. Governments also want access: <a href="https://www.reuters.com/legal/litigation/south-korea-secures-access-anthropics-mythos-ai-model-science-ministry-says-2026-06-03/">Reuters reported</a> that South Korea’s national internet security agency had secured Mythos access through Project Glasswing, reflecting a broader geopolitical race to use frontier AI for national cyber defense. At the same time, Anthropic has faced scrutiny over whether it can safely gate the very capabilities it says are too risky for general release. <a href="https://www.theverge.com/ai-artificial-intelligence/917644/anthropic-claude-mythos-breach-humiliation">The Verge reported</a> that unauthorized users accessed Mythos after its limited rollout, calling the incident damaging for a company that has built its brand around responsible AI. </p><p>Critics have also questioned whether Anthropic’s warning-heavy framing risks becoming a form of market positioning, since it casts the company as both the source of the new capability and the gatekeeper deciding which governments, companies and researchers get to use it.</p><p>With Fable 5, Anthropic is leaning into its gatekeeper role, attempting to separate the general enterprise value of a Mythos-class model from the riskiest parts of its capability profile. The company says Fable 5 can handle software engineering, research, visual reasoning, document analysis and long-running agentic workflows, while classifiers block or reroute requests that could provide what Anthropic calls “uplift” to malicious actors.</p><p>Those classifiers cover three main areas. </p><ol><li><p>Cybersecurity, where Anthropic says Mythos-class models can discover and exploit vulnerabilities and perform broader “agentic hacking” tasks such as reconnaissance, discovery and lateral movement. </p></li><li><p>Biology and chemistry, where the company says the same reasoning that can help researchers design therapies could also help well-resourced malicious actors pursue dangerous biological work. </p></li><li><p>Model distillation, where Anthropic says users may try to extract Claude’s capabilities to train competing models, including models that could be released without similar safeguards.</p></li></ol><p>When Fable 5’s classifiers detect one of those categories, the response is automatically handled by Claude Opus 4.8. Anthropic says users will be told when this happens. That is a notable product decision: rather than declining those requests outright, Anthropic is trying to keep the user experience functional while reducing access to the most capable version of the model in sensitive areas.</p><p>Anthropic says it red-teamed the new classifier system internally and externally. The company says an internal bug bounty produced no universal jailbreaks after more than 1,000 hours of testing, and external red-teaming organizations also failed to find a universal jailbreak. One external partner found that Fable 5 complied with zero harmful single-turn cyber requests related to planning cyberattacks, exploit development or defense evasion, even when prompts used any of 30 public jailbreak techniques, according to Anthropic.</p><p>The company is still acknowledging tradeoffs. Anthropic says the safeguards are deliberately cautious and may sometimes trigger on benign requests. That could frustrate security professionals, biology researchers and advanced enterprise users whose legitimate work overlaps with the blocked categories. The company says it plans to reduce false positives over time.</p><h2><b>Mythos 5 and the restricted frontier</b></h2><p>While Fable 5 is the broad commercial launch, Mythos 5 is the model to watch for enterprises operating in security, critical infrastructure and life sciences.</p><p>The company says all users with Claude Mythos Preview access can upgrade to Mythos 5 beginning today. It plans to expand access through a trusted access program, in collaboration with the U.S. government.</p><p>The distinction is important for sectors where the blocked capabilities are not edge cases but core workflows. A security team may need to reproduce vulnerabilities, test exploitability, analyze lateral movement or simulate attacker behavior in a controlled environment. A biology research team may need to reason through molecular design workflows that would trigger general-use safeguards. Fable 5 is not designed to give every user unrestricted access to those capabilities; Mythos 5 is designed for vetted users who need them.</p><p>Anthropic says Mythos 5 has the strongest cybersecurity capabilities of any model in the world. In the company’s benchmark table, the model family scores 78.0% on ExploitBench, compared with 69.0% for Claude Mythos Preview, 40.0% for Opus 4.8 and 34.0% for GPT-5.5. On CyberGym, Anthropic’s chart shows Mythos 5 at 83.8%, slightly ahead of Mythos Preview at 83.1% and far above Opus 4.8 with default safeguards.</p><p>The company is making a similar argument in biology. Anthropic says Mythos-class models outperform dedicated protein language models on a task involving adeno-associated viruses, a delivery mechanism used in gene therapies. The company frames that as both promising and risky: the same capability that could help gene therapy research could also be misused in dangerous biological work.</p><p>Anthropic says its internal protein design experts used Mythos 5 to accelerate parts of the drug design process by about tenfold. In one example, the company says Mythos 5, using protein design and bioinformatics tools without human assistance, matched or beat skilled human operators by choosing binding sites, selecting and running tools, and recovering from failures. Anthropic says nine of 14 protein targets in the study produced strong candidates for drug design that it is now investigating.</p><p>The company also says Mythos 5 produced novel molecular biology hypotheses that Anthropic scientists preferred over Opus-class model hypotheses about 80% of the time in blinded comparisons. Anthropic says several of those ideas have advanced to experimental evaluation, and one hypothesis involving an E. coli protein was later corroborated by an independent lab working on the same problem.</p><p>Those claims are potentially significant, but they should be treated carefully until more details are published. Anthropic says it intends to publish additional results in the coming months. For now, the strongest enterprise implication is directional: the company believes its highest-end models can already perform parts of scientific research workflows with less human intervention than prior systems.</p><h2><b>New, longer data retention requirement</b></h2><p>The company also introduced a new data-retention policy for Mythos-class models. Anthropic says it will require 30-day retention for all traffic on Fable 5, Mythos 5 and future models with similar or higher capability levels, across both first-party and third-party surfaces. The company says it will not use that data to train new Claude models or for non-safety purposes, and says it has added privacy protections including logging human access and deleting the data after 30 days in almost all cases.</p><p>That policy may become one of the most important enterprise buying questions around Fable 5. Many businesses want frontier AI capability but also want strict control over data retention, especially in regulated sectors. Anthropic’s position is that stronger monitoring is necessary for models with this level of capability. Enterprise customers will have to decide whether the capability gain justifies the retention requirement.</p><h2><b>Enterprise implications</b></h2><p>The broader enterprise significance of Fable 5 is that Anthropic is trying to commercialize a more autonomous class of AI model without exposing all of its capabilities to every user. That could become a template for how frontier labs release increasingly powerful systems: one model family, multiple access tiers, and domain-specific restrictions depending on user trust and risk.</p><p>If Fable 5 performs as Anthropic and early customers describe, developers may hand off larger tasks: code migrations, refactors, UI builds, test writing, bug fixing, documentation, internal tooling and multi-step app creation. </p><p>For knowledge-work-heavy enterprises, Fable 5 could make AI more useful in workflows where earlier models were too brittle: finance research, spreadsheet analysis, legal redlines, procurement review, board materials, market research, sales operations and project planning. The main gain is not just better answers; it is fewer turns, fewer corrections and more ability to keep working through ambiguity.</p><p>For security teams, the launch is more complicated. Most organizations will get Fable 5, not unrestricted Mythos 5. That means they may see stronger general coding and analysis, but not full access to the cyber capabilities Anthropic considers risky. Trusted defenders inside Project Glasswing will get Mythos 5, giving them a more direct way to use the model for vulnerability discovery and defensive testing.</p><p>For life sciences companies, the pattern is similar. Fable 5 may help with general research, literature analysis, data interpretation and scientific reasoning, but the more sensitive biological capabilities will be restricted. Anthropic is effectively creating a separate access path for vetted researchers whose work requires capabilities that could be dangerous in the wrong hands.</p><p>The launch also raises competitive pressure across the AI industry. Anthropic is claiming state-of-the-art results across agentic coding, knowledge work, vision, cybersecurity, legal reasoning, spatial reasoning and health benchmarks. But the more strategically important claim may be that it has found a workable release mechanism for models above its Opus class. If Fable 5’s safeguards hold up under real-world use, Anthropic will argue it can bring more powerful models to market sooner without fully opening the riskiest capabilities.</p><p>That is still a large “if.” The enterprise market will test not only Fable 5’s benchmark performance, but also its reliability, false-positive rate, data-retention tradeoffs and cost at scale. A model that can complete more work autonomously can also burn more tokens, trigger more governance questions and create new review burdens for teams that must verify its output.</p><p>Still, today’s launch marks a clear shift in the Claude lineup. Opus is no longer Anthropic’s top commercial capability tier. Mythos-class models now sit above it. Fable 5 is the first version of that tier for general users; Mythos 5 is the restricted version for trusted high-risk work. Together, they show how Anthropic plans to push frontier AI deeper into enterprise workflows while trying to keep the most dangerous capabilities gated.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Best Guide to Choosing a Dedicated Server Without Overspending]]></title>
<description><![CDATA[In this post, I will give you the best guide to choosing a dedicated server without overspending. What is a Dedicated Server? A dedicated server is a powerful type of hosting where an entire physical server is assigned to a single user or business. Unlike shared hosting, where multiple users shar...]]></description>
<link>https://tsecurity.de/de/3584960/it-security-nachrichten/best-guide-to-choosing-a-dedicated-server-without-overspending/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584960/it-security-nachrichten/best-guide-to-choosing-a-dedicated-server-without-overspending/</guid>
<pubDate>Tue, 09 Jun 2026 17:22:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In this post, I will give you the best guide to choosing a dedicated server without overspending. What is a Dedicated Server? A dedicated server is a powerful type of hosting where an entire physical server is assigned to a single user or business. Unlike shared hosting, where multiple users share the same resources, a […]</p>
<p>The post <a href="https://secureblitz.com/choosing-a-dedicated-server-without-overspending/">Best Guide to Choosing a Dedicated Server Without Overspending</a> appeared first on <a href="https://secureblitz.com/">SecureBlitz Cybersecurity</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Download Official iPadOS 27 Wallpaper for iPad in 4K Resolution]]></title>
<description><![CDATA[Apple has introduced iPadOS 27 at WWDC 2026, and along with the new software update, the company has also released a fresh wallpaper design for iPad users. The new wallpaper follows Apple's latest Celosia design language.



The new Celosia wallpaper features sweeping shapes inspired by flower pe...]]></description>
<link>https://tsecurity.de/de/3584746/ios-mac-os/download-official-ipados-27-wallpaper-for-ipad-in-4k-resolution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584746/ios-mac-os/download-official-ipados-27-wallpaper-for-ipad-in-4k-resolution/</guid>
<pubDate>Tue, 09 Jun 2026 15:53:42 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has introduced iPadOS 27 at WWDC 2026, and along with the new software update, the company has also released a fresh wallpaper design for iPad users. The new wallpaper follows Apple's latest Celosia design language.



The new Celosia wallpaper features sweeping shapes inspired by flower petals and folded paper. The Light version blends warm gold and purple shades, while the Dark version uses deeper blue and indigo tones with subtle highlights. Apple also offers a Dynamic version that changes throughout the day and a Color version that lets users apply their preferred tint.



The same wallpaper works on both the Lock Screen and Home Screen, creating a consistent look across the entire iPad experience.



Available Wallpaper Variants



iPadOS-27-Wallpaper-HomeScreen-LightDownload



iPadOS-27-Wallpaper-HomeScreen-DynamicDownload



iPadOS-27-Wallpaper-HomeScreen-DarkDownload



iPadOS-27-Wallpaper-HomeScreen-ColorDownload



How to Download and Apply the Wallpaper




Open the wallpaper download link on your iPad.



Press and hold the image.



Select Save to Photos.



Open the Settings app.



Tap Wallpaper.



Choose Add New Wallpaper.



Select the downloaded image from your Photos library.



Apply it to your Lock Screen, Home Screen, or both.




You can also customize your wallpaper directly by long-pressing the Lock Screen and selecting Customize, then choosing the saved image from Photos.



The new iPadOS 27 wallpaper is a simple way to bring Apple's latest design style to your device, even if you have not installed the developer beta.]]></content:encoded>
</item>
<item>
<title><![CDATA[8 cutting-edge web development tools you don’t want to miss]]></title>
<description><![CDATA[There is no ordained path. The hope that we were converging on some kind of consensus in web development has been eradicated by recent, ingenious developments that point in almost every direction. Yet, if there is a central theme uniting these efforts, it is the desire to mitigate the layers of l...]]></description>
<link>https://tsecurity.de/de/3583920/ai-nachrichten/8-cutting-edge-web-development-tools-you-dont-want-to-miss/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583920/ai-nachrichten/8-cutting-edge-web-development-tools-you-dont-want-to-miss/</guid>
<pubDate>Tue, 09 Jun 2026 11:03:29 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>There is no ordained path. The hope that we were converging on some kind of consensus in web development has been eradicated by recent, ingenious developments that point in almost every direction. Yet, if there is a central theme uniting these efforts, it is the desire to mitigate the layers of liturgical embellishment that have grown up around the reactive canon. How can we look at things differently to attain the power that we need, without the heavy intricacy?</p>



<p>Here are eight cutting-edge web development tools that point the way. </p>



<h2 class="wp-block-heading">Front-end maestro</h2>



<p>If you put a bunch of classical musicians in a room together with sheet music and let them run, you <em>might </em>get to a cohesive piece—but you <em>probably </em>want a conductor, a maestro who coordinates all of the parts. That is <a href="https://www.infoworld.com/article/3842325/designing-a-dynamic-web-application-with-astro-js.html">Astro</a> for your front-end frameworks.</p>



<p>Astro addresses the “<a href="https://www.infoworld.com/article/2335507/reactive-javascript-the-evolution-of-front-end-architecture.html" data-type="link" data-id="https://www.infoworld.com/article/2335507/reactive-javascript-the-evolution-of-front-end-architecture.html">hydration</a>” of the front end, that is to say, the process of making the shell reactive. In conventional server-side rendering (SSR), like Next.js or Nuxt, the server not only sends the HTML, but also sends the massive framework runtime down the wire, just to attach event listeners to the page. Astro allows you to write components in React, Svelte, Vue, or Solid, and its compiler strips away all of the JavaScript before it reaches the browser. Astro ships zero JS by default, relying on its <a href="https://docs.astro.build/en/concepts/islands/" data-type="link" data-id="https://docs.astro.build/en/concepts/islands/">islands architecture</a> to hydrate only the specific components that demand interactivity. </p>



<p>Because Astro isolates interactivity into distinct islands, sharing complex state between those islands (e.g., a complex filtering sidebar communicating with a separate dynamic data grid) is fundamentally harder than it is in a monolithic single-page application. If you are building a highly interactive, dashboard-heavy app where every component affects every other component, Astro’s isolated islands might begin to feel more like a straitjacket than a liberation.</p>



<p>See also: <a href="https://www.infoworld.com/article/2337044/intro-to-qwik-a-superfast-javascript-framework.html" data-type="link" data-id="https://www.infoworld.com/article/2337044/intro-to-qwik-a-superfast-javascript-framework.html">Qwik</a>. If Astro unbloats by stripping away the JavaScript entirely, Qwik unbloats by delaying it. Qwik delivers instant HTML and serializes the application state, downloading and executing only the JavaScript code required for a specific interaction at the exact millisecond the user clicks a button.</p>



<h2 class="wp-block-heading">Biome: Lint like it’s 2026</h2>



<p><a href="https://www.infoworld.com/article/2255250/what-is-rust-safe-fast-and-easy-software-development.html" data-type="link" data-id="https://www.infoworld.com/article/2255250/what-is-rust-safe-fast-and-easy-software-development.html">Rust</a> is gradually replacing the underlying infrastructure in the JavaScript ecosystem. But while Rust gives <a href="https://biomejs.dev/">Biome</a> its close-to-the-metal speed, Biome’s true calling card is its unification of the sprawling toolchain under a cohesive umbrella.</p>



<p>The .eslintrc and .prettierrc files and the dozen associated plugins can become a dark and unhappy bog in a project. Biome is the way out of the mire. It is a single, blazingly fast binary that replaces your entire tangled formatting and linting ecosystem, providing a path to code quality that doesn’t require a sprawling web of dependencies.</p>



<p>Probably the biggest drawback to Biome is that you lose the wide-open extensibility—which is exactly the same feature that makes Biome lean.</p>



<p>See also: <a href="https://rspack.rs/">Rspack</a>. Biome cleans up the linting. Rspack unbloats the build step. Also built on Rust for speed, Rspack challenges the new “unbundled” esbuild-based dev mode championed by Vite and uses bundled dev mode.</p>



<h2 class="wp-block-heading">Bun: Fast and integrated back-end JavaScript</h2>



<p>Most cutting-edge JavaScript enthusiasts are already well-aware of <a href="https://www.infoworld.com/article/2338008/explore-bunjs-the-all-in-one-javascript-runtime.html">Bun</a>. For those who haven’t yet experienced Bun’s enthralling blend of one-stop shopping and blistering speed first-hand, it’s a virtually irrefutable must-try.</p>



<p>Fast is probably an understatement. If you are used to <a href="https://www.infoworld.com/article/2254485/what-is-nodejs-javascript-runtime-explained.html">Node</a> and you try out Bun, you will likely be immediately impressed with the speed at which commands execute. The Bun team has also made an extensive, multi-year effort to bring its engine into close compatibility with Node’s APIs. Overall, Bun is an extraordinary engineering effort that every JS developer should explore. </p>



<p>However, while Bun’s <a href="https://www.infoworld.com/article/2338081/meet-the-zig-programming-language.html">Zig</a>-based engine is in most respects a drop-in for Node, it isn’t perfect, especially when considering the gargantuan landscape of Node packages out there. Node remains the conservative, happy-path engine for server-side JavaScript. </p>



<p>See also: <a href="https://www.infoworld.com/article/2256205/what-is-deno-a-better-nodejs.html" data-type="link" data-id="https://www.infoworld.com/article/2256205/what-is-deno-a-better-nodejs.html">Deno</a>. Although Bun has justifiably earned a reputation for bleeding-edge innovation, Deno has quietly pressed ahead with an appealing set of enterprise features like an integrated deployment platform and a front-end framework (<a href="https://www.infoworld.com/article/3523813/intro-to-deno-fresh-a-fresh-take-on-full-stack-javascript.html">Deno Fresh</a>).</p>



<p>The Bun curious also may want to check out my interview with Bun creator <a href="https://www.infoworld.com/article/2338698/interview-with-jarred-sumner-buns-creator-talks-tech-funding-and-startups.html">Jared Sumner</a>.</p>



<h2 class="wp-block-heading">HTMX: Ajax KISS</h2>



<p>If we are talking about clever ways to de-complexify the web, <a href="https://www.infoworld.com/article/4150864/htmx-4-0-hypermedia-finds-a-new-gear.html">HTMX</a> could reasonably be considered the poster-child. It takes the core mechanisms of the modern web client, like <a href="https://developer.mozilla.org/en-US/docs/Glossary/AJAX" data-type="link" data-id="https://developer.mozilla.org/en-US/docs/Glossary/AJAX">Ajax</a> and partial updates, and turns them into simple HTML attributes. That means the state lives exclusively on the server, which is responsible for sending HTMX fragments.</p>



<p>Of course, there are trade-offs. Perhaps most unavoidable is the extreme dependence on the network. Because there is no client-side state machine, the browser will be orphaned and helpless without a connection to the server. That is, unless you <a href="https://www.infoworld.com/article/4163910/the-front-end-architecture-trilemma-reactivity-vs-hypermedia-vs-local-first-apps.html" data-type="link" data-id="https://www.infoworld.com/article/4163910/the-front-end-architecture-trilemma-reactivity-vs-hypermedia-vs-local-first-apps.html">get experimental</a> with a <a href="https://www.infoworld.com/article/4133648/the-browser-is-your-database-local-first-comes-of-age.html" data-type="link" data-id="https://www.infoworld.com/article/4133648/the-browser-is-your-database-local-first-comes-of-age.html">local-first datastore</a>.</p>



<p>Long story short: if your app falls into the realm of HTMX’s ability, HTMX is likely to be the most direct <a href="https://www.infoworld.com/article/2334742/what-is-rest-the-de-facto-web-architecture-standard.html">RESTful</a> way to build it. And HTMX can in fact handle quite a lot.</p>



<p>See also: <a href="https://www.infoworld.com/article/4100499/intro-to-hotwire-interactive-javascript-built-from-html.html" data-type="link" data-id="https://www.infoworld.com/article/4100499/intro-to-hotwire-interactive-javascript-built-from-html.html">Hotwire</a>. A collection of tools for building single-page-style applications using HTML over the wire, Hotwire has great features like page morphing, which can diff HTML instead of cold-loading it, with a simple import. True to classic “free as in speech” software culture, the HTMX and Hotwire projects freely exchange ideas. </p>



<h2 class="wp-block-heading">PowerSync: Data layer redo</h2>



<p>Although the local-first data revolution that <a href="https://www.infoworld.com/article/4163910/the-front-end-architecture-trilemma-reactivity-vs-hypermedia-vs-local-first-apps.html">PowerSync</a> represents implies a fairly serious engineering deep dive, its core proposal — to entirely reshape the way data moves in web architecture — is something a web developer needs to be aware of.</p>



<p>Usually, we create architectures that require a complex middleware to broker between a reactive client and the datastore. PowerSync proposes a radical alternative: bypass the middleman entirely by dropping a robust SQLite Wasm database directly into the browser.</p>



<p>The UI works on local data using <a href="https://www.infoworld.com/article/4140734/the-revenge-of-sql-how-a-50-year-old-language-reinvents-itself.html" data-type="link" data-id="https://www.infoworld.com/article/4140734/the-revenge-of-sql-how-a-50-year-old-language-reinvents-itself.html">familiar SQL</a>, synchronously. Latency is zero. The dreaded loading spinner vanishes entirely. In the background, PowerSync automatically reconciles your local store with your central Postgres database. It handles the complex syncing algorithms and network drops, effectively making your application offline-first by default.</p>



<p>The catch, of course, is that local-first development forces a massive mental shift. You have to define data slices (similar to a view) that each client user holds. The PowerSync engine does most of the hard work, but things like schema migrations and conflict resolution (when two users edit the same record while offline) require a significantly steeper initial setup than a standard REST API.</p>



<p>See also: <a href="https://www.infoworld.com/article/4133648/the-browser-is-your-database-local-first-comes-of-age.html" data-type="link" data-id="https://www.infoworld.com/article/4133648/the-browser-is-your-database-local-first-comes-of-age.html">RxDB</a>. RxDB is a slightly different flavor of local-first datastore. Whereas PowerSync relies heavily on Postgres, SQLite, and background daemons, RxDB provides a NoSQL, offline-first, reactive database that treats queries as observable streams, pushing UI updates the exact millisecond the local data changes. </p>



<h2 class="wp-block-heading">RooCode: Use any AI you want</h2>



<p>The beauty of <a href="https://www.infoworld.com/article/4019646/roo-code-review-a-first-look-at-autonomous-ai-powered-development-in-the-ide.html">RooCode</a> lies in its ability to orchestrate whatever AI providers you have—for free. RooCode is an extension to <a href="https://www.infoworld.com/article/2335960/what-is-visual-studio-code-microsofts-extensible-code-editor.html" data-type="link" data-id="https://www.infoworld.com/article/2335960/what-is-visual-studio-code-microsofts-extensible-code-editor.html">Visual Studio Code</a> that provides an AI manager layer. This layer bridges between the general abilities of the LLM and your code-specific, project-level structures.</p>



<p>RooCode is strong enough to be somewhat agentic in its capabilities. It doesn’t reach the powerhouse abilities of something like Cursor or Antigravity, but it is quite able to handle most small to medium-sized requests. And it does so with a minimum of unnecessary overhead. I find myself often using RooCode alongside my AI-assisted IDE to knock out lesser requirements, for less cost and without interrupting the flow of ongoing epics.</p>



<p>RooCode keeps you free of proprietary ecosystems. It allows you to plug in your own API keys—whether that is Claude, OpenAI, or even a local model running on your own hardware. </p>



<p>The hidden tax of any AI coding assistant, however, is that it fundamentally shifts your job description from “writer” to “editor.” The unbloating of keystrokes can paradoxically lead to massively bloated codebases if developers blindly accept AI-generated boilerplate without actively reviewing its architectural impact. It is incredibly easy to let an agent spin up 500 lines of complex React when 50 lines of plain JavaScript would have done.</p>



<p>See also: <a href="https://antigravity.google/" data-type="link" data-id="https://antigravity.google/">Antigravity</a>. RooCode is a lightweight extension that supercharges your existing environment. Google’s Antigravity is a custom-built editor designed from the ground up around AI, geared for agentic development workflows.</p>



<h2 class="wp-block-heading">TanStack Query: Syncing made simple(r)</h2>



<p>Even when client-side state management is addressed (see Zustand below), there is still a big, gaping hole in the plot: syncing across the server boundary. That is where <a href="https://tanstack.com/query/latest">TanStack Query</a> steps into the breach.</p>



<p>Distributed computing is a notoriously thorny problem, and in fact our standard reactive model walks right into these thorns by holding the same state in two different places: on the client and the server.  Tanstack Query tries to make this inherent architectural friction as painless as possible by acting as an intelligent asynchronous layer. </p>



<p>Instead of using a bunch of manual fetches tied to <code>useState</code> updates, along with fragile <code>isLoading</code> flags and complex state synchronization logic, TanStack Query abstracts the heavy lifting of API responses, background updates, and request deduplication into a few elegant hooks. You tell TanStack Query where to get the data, and it uses a pattern known as “stale-while-revalidate,” which means it will cache and reuse data on the front end (eliminating reload waits) and sync to the latest state in the background. </p>



<p>The catch, however, is that cache invalidation remains one of the hardest problems in computer science—and TanStack Query forces you to face it head-on. You will spend time thinking about “query keys” and deciding when a piece of data should be considered “stale.” No free lunches in software.</p>



<p>See also: <a href="https://swr.vercel.app/">SWR</a>. While TanStack Query is an absolute powerhouse for complex data manipulation, SWR remains a champion of API minimalism, doing exactly what its name implies (stale-while-revalidate) with almost zero configuration.</p>



<h2 class="wp-block-heading">Zustand: Minimalist state</h2>



<p>If you have yet to encounter the monstrosity of large-scale state management in a reactive app, then spoiler alert: it can be nasty. <a href="https://zustand.docs.pmnd.rs/learn/getting-started/introduction">Zustand</a> proposes to dispense with the ceremonial boilerplate of reducers, providers, and unwieldy context wrappers in favor of a tiny, brutally simple global store.</p>



<p>Instead of forcing your entire application tree into a massive React context provider (sometimes leading to cascades of superfluous re-renders across the DOM), Zustand uses custom hooks to tie state directly to the specific components that need it. Zustand strives to achieve the specificity in the VDOM reactive model (instead of eliminating it entirely a la <a href="https://www.infoworld.com/article/4129648/reactive-state-management-with-javascript-signals.html">Signals</a>).</p>



<p>You define a store, you call it, and the reactivity just works. It is an expression of the KISS philosophy applied to front-end architecture, scraping away the intricacies of Flux-like patterns. The trade-off for this liberation is the burden of discipline. Because Zustand is unopinionated, it won’t stop you from turning your global store into a cluttered junk drawer. You’ll need to impose your own conventions and guardrails to keep a large-scale project manageable.</p>



<p>See also: <a href="https://jotai.org/" data-type="link" data-id="https://jotai.org/">Jotai</a>. If Zustand is the unbloated global store, Jotai is the unbloated atomic approach. Jotai manages state from the bottom up, calculating changes with surgical precision without triggering massive re-renders across the application tree.</p>



<h2 class="wp-block-heading">New directions in web development</h2>



<p>The most remarkable thing about these eight tools is that they deal in large part with alternative approaches that challenge the familiar. Although you may not be able to adopt them immediately, you will want to keep an eye on them. They are key factors that will continue to influence the shape of web applications and how we build them.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Top 10 Best Privileged Access Management (PAM) Tools in 2026]]></title>
<description><![CDATA[Privileged Access Management (PAM) has become a cornerstone of modern enterprise security in 2026, elevating organizations’ defense against credential theft, insider threats, and regulatory pressure. Enterprises demand robust PAM solutions that seamlessly integrate with dynamic infrastructure, en...]]></description>
<link>https://tsecurity.de/de/3583820/it-security-nachrichten/top-10-best-privileged-access-management-pam-tools-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583820/it-security-nachrichten/top-10-best-privileged-access-management-pam-tools-in-2026/</guid>
<pubDate>Tue, 09 Jun 2026 10:21:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Privileged Access Management (PAM) has become a cornerstone of modern enterprise security in 2026, elevating organizations’ defense against credential theft, insider threats, and regulatory pressure. Enterprises demand robust PAM solutions that seamlessly integrate with dynamic infrastructure, enable granular control, audit privileged sessions, and reduce breach risk. With advanced cyberattacks targeting admin accounts, choosing the right […]</p>
<p>The post <a href="https://cyberpress.org/best-privileged-access-management-tools/">Top 10 Best Privileged Access Management (PAM) Tools in 2026</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Thoughts on switching to Linux]]></title>
<description><![CDATA[Hello there folks! I am new on here and I would like y'all's opinion on something. I am currently using Windows 11 IoT Enterprise LTSC 2024 as my daily drive OS and I am quite okay with it. However I keep seeing videos about Linux, specifically heard great things about Nobara Linux. I did give it...]]></description>
<link>https://tsecurity.de/de/3583323/linux-tipps/thoughts-on-switching-to-linux/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583323/linux-tipps/thoughts-on-switching-to-linux/</guid>
<pubDate>Tue, 09 Jun 2026 04:10:50 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hello there folks! I am new on here and I would like y'all's opinion on something. I am currently using Windows 11 IoT Enterprise LTSC 2024 as my daily drive OS and I am quite okay with it. However I keep seeing videos about Linux, specifically heard great things about Nobara Linux. I did give it a try 3 months ago and I personally didn't see improvements in regards with FPS in games, but that is probably because I may have done something wrong in regards with choosing the Proton version. Still, I am very attracted to the thought of switching permanently to Linux. I am an average PC user. I play mainly Minecraft, CS2, The Witcher 3 and Red Dead Redemption 2. I don't play any games with kernel level anti-cheat nor use Adobe.. </p> <p>I would very much appreciate if y'all can provide me with some tips and tricks or any advice! </p> <p>Thank y'all! </p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Ok_Difference_6838"> /u/Ok_Difference_6838 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1u0r62x/thoughts_on_switching_to_linux/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1u0r62x/thoughts_on_switching_to_linux/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Choosing a Pentesting Company That Thinks Like an Adversary]]></title>
<description><![CDATA[5 Questions to Vet Any Penetration Testing Company 
Finding a pentesting partner that can produce a deep dive pentest is harder than knowing what one should look like. When evaluating vendors, seasoned adversarial firms and scanner-in-disguise vendors look nearly identical on paper. Certification...]]></description>
<link>https://tsecurity.de/de/3581954/it-security-nachrichten/choosing-a-pentesting-company-that-thinks-like-an-adversary/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581954/it-security-nachrichten/choosing-a-pentesting-company-that-thinks-like-an-adversary/</guid>
<pubDate>Mon, 08 Jun 2026 17:51:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="hs-featured-image-wrapper"> 
 <a href="https://www.mitnicksecurity.com/blog/best-penetration-testing-company" title="" class="hs-featured-image-link"> <img src="https://www.mitnicksecurity.com/hubfs/Mitnick-Security-071-Enhanced-NR-Copy1.jpg" alt="penetration testing company" class="hs-featured-image"> </a> 
</div> 
<h1>5 Questions to Vet Any Penetration Testing Company</h1> 
<p>Finding a pentesting partner that can produce a deep dive pentest is harder than knowing what one should look like. When evaluating vendors, seasoned adversarial firms and scanner-in-disguise vendors look nearly identical on paper. Certifications overlap. A vendor offering agentic offensive security, genuine penetration testing as a service (PTaaS), and one running scheduled vulnerability scans can submit proposals that are indistinguishable until you know the right questions to ask.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Choose Your Filter! — Vom Forschungsprojekt zur Ausstellung (gpn24)]]></title>
<description><![CDATA[Im selben Gebäude, in dem die GPN stattfindet, war 2025 die Ausstellung “Choose Your Filter!” zu sehen. Gezeigt wurden künstlerische Webbrowser aus drei Jahrzehnten, also Software, die selbst Kunstwerk und Anzeigeumgebung in einem ist. Der Ausstellung ging ein mehrjähriges Forschungsprojekt am KI...]]></description>
<link>https://tsecurity.de/de/3576276/it-security-video/choose-your-filter-vom-forschungsprojekt-zur-ausstellung-gpn24/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3576276/it-security-video/choose-your-filter-vom-forschungsprojekt-zur-ausstellung-gpn24/</guid>
<pubDate>Fri, 05 Jun 2026 20:03:14 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Im selben Gebäude, in dem die GPN stattfindet, war 2025 die Ausstellung “Choose Your Filter!” zu sehen. Gezeigt wurden künstlerische Webbrowser aus drei Jahrzehnten, also Software, die selbst Kunstwerk und Anzeigeumgebung in einem ist. Der Ausstellung ging ein mehrjähriges Forschungsprojekt am KIT voraus, in dem solche Browser als eigenständige künstlerische Form untersucht wurden. Sie sind als Remix-Programme interpretierbar, sie situieren Nutzer*innen und formen mit, wie das Web durch sie hindurch wahrgenommen wird. Browser bestimmen, was sichtbar wird, in welcher Geschwindigkeit, Reihenfolge und Hierarchie. Damit sind sie Filter im wörtlichen Sinn, und Gegenstand sozio-politischer, ökonomischer und kultureller Fragen.

Wenn solche softwarebasierten Werke überhaupt in den Blick genommen werden, beschränkt sich die Auseinandersetzung im akademischen Rahmen üblicherweise auf ihre Dokumentation, Beschreibung und Kontextualisierung der Arbeiten. Eine Ausstellung, die den Anspruch hegt, nicht (nur) Relikte zu zeigen, verlangt mehr: Dort sollen die Arbeiten wieder live erfahrbar sein, also tatsächlich laufen, in einem Raum, vor Publikum, über Monate hinweg — ohne Wartung im laufenden Betrieb und ohne technisches Personal, das im Zweifel eingreift. Damit verschiebt sich die Aufgabe grundsätzlich hin zu Reparatur und robuste Stabilisierung. Werke, die für eine bestimmte historische Konfiguration aus Browser, Plugin, Betriebssystem und Serverlandschaft geschrieben wurden, müssen in einer Gegenwart funktionieren, in der diese Konfiguration nicht mehr existiert, und sie müssen es selbständig tun: Crashes überstehen, Zustände zurücksetzen, mit unterschiedlichsten Besucher*inneninteraktion umgehen, fehlende Server kompensieren — alles ohne Hand am Gerät. Was im Forschungsprojekt eine Frage des Verstehens war, wird im Ausstellungsbetrieb eine Frage der Rekonstruktion und der autonomen Lauffähigkeit — konzeptuell, technisch und konservatorisch zugleich.

Der Vortrag berichtet aus erster Hand davon, wie aus einem Forschungsvorhaben eine Ausstellung wurde: welche Entscheidungen kuratorisch fallen mussten, wie einzelne Werke wieder zum Laufen gebracht wurden, und welche Infrastruktur dabei entstanden ist, um Netzkunst aus mehreren Jahrzehnten parallel und stabil zu betreiben. Wir sprechen aus zwei Perspektiven — kunsthistorisch und museumstechnisch — über dasselbe Problem: was es heißt, Software, die selbst Kunstwerk ist, nicht nur zu beschreiben, sondern zu zeigen.

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://cfp.gulas.ch/gpn24/talk/JQYNPX/]]></content:encoded>
</item>
<item>
<title><![CDATA[Choose Your Filter! — Vom Forschungsprojekt zur Ausstellung]]></title>
<description><![CDATA[Author: media.ccc.de - Bewertung: 3x - Views:16 https://media.ccc.de/v/gpn24-612-choose-your-filter-vom-forschungsprojekt-zur-ausstellung

Im selben Gebäude, in dem die GPN stattfindet, war 2025 die Ausstellung “Choose Your Filter!” zu sehen. Gezeigt wurden künstlerische Webbrowser aus drei Jahrz...]]></description>
<link>https://tsecurity.de/de/3576275/it-security-video/choose-your-filter-vom-forschungsprojekt-zur-ausstellung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3576275/it-security-video/choose-your-filter-vom-forschungsprojekt-zur-ausstellung/</guid>
<pubDate>Fri, 05 Jun 2026 20:03:12 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: media.ccc.de - Bewertung: 3x - Views:16 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/1OYCTFwa_ww?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>https://media.ccc.de/v/gpn24-612-choose-your-filter-vom-forschungsprojekt-zur-ausstellung<br />
<br />
Im selben Gebäude, in dem die GPN stattfindet, war 2025 die Ausstellung “Choose Your Filter!” zu sehen. Gezeigt wurden künstlerische Webbrowser aus drei Jahrzehnten, also Software, die selbst Kunstwerk und Anzeigeumgebung in einem ist. Der Ausstellung ging ein mehrjähriges Forschungsprojekt am KIT voraus, in dem solche Browser als eigenständige künstlerische Form untersucht wurden. Sie sind als Remix-Programme interpretierbar, sie situieren Nutzer*innen und formen mit, wie das Web durch sie hindurch wahrgenommen wird. Browser bestimmen, was sichtbar wird, in welcher Geschwindigkeit, Reihenfolge und Hierarchie. Damit sind sie Filter im wörtlichen Sinn, und Gegenstand sozio-politischer, ökonomischer und kultureller Fragen.<br />
<br />
Wenn solche softwarebasierten Werke überhaupt in den Blick genommen werden, beschränkt sich die Auseinandersetzung im akademischen Rahmen üblicherweise auf ihre Dokumentation, Beschreibung und Kontextualisierung der Arbeiten. Eine Ausstellung, die den Anspruch hegt, nicht (nur) Relikte zu zeigen, verlangt mehr: Dort sollen die Arbeiten wieder live erfahrbar sein, also tatsächlich laufen, in einem Raum, vor Publikum, über Monate hinweg — ohne Wartung im laufenden Betrieb und ohne technisches Personal, das im Zweifel eingreift. Damit verschiebt sich die Aufgabe grundsätzlich hin zu Reparatur und robuste Stabilisierung. Werke, die für eine bestimmte historische Konfiguration aus Browser, Plugin, Betriebssystem und Serverlandschaft geschrieben wurden, müssen in einer Gegenwart funktionieren, in der diese Konfiguration nicht mehr existiert, und sie müssen es selbständig tun: Crashes überstehen, Zustände zurücksetzen, mit unterschiedlichsten Besucher*inneninteraktion umgehen, fehlende Server kompensieren — alles ohne Hand am Gerät. Was im Forschungsprojekt eine Frage des Verstehens war, wird im Ausstellungsbetrieb eine Frage der Rekonstruktion und der autonomen Lauffähigkeit — konzeptuell, technisch und konservatorisch zugleich.<br />
<br />
Der Vortrag berichtet aus erster Hand davon, wie aus einem Forschungsvorhaben eine Ausstellung wurde: welche Entscheidungen kuratorisch fallen mussten, wie einzelne Werke wieder zum Laufen gebracht wurden, und welche Infrastruktur dabei entstanden ist, um Netzkunst aus mehreren Jahrzehnten parallel und stabil zu betreiben. Wir sprechen aus zwei Perspektiven — kunsthistorisch und museumstechnisch — über dasselbe Problem: was es heißt, Software, die selbst Kunstwerk ist, nicht nur zu beschreiben, sondern zu zeigen.<br />
<br />
Inge Hinterwaldner, Marc Schütze<br />
<br />
https://cfp.gulas.ch/gpn24/talk/JQYNPX/<br />
<br />
#gpn24 #Science<br />
<br />
Licensed to the public under https://creativecommons.org/licenses/by/4.0/<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How the “Swiss Cheese” model can help you choose the right MDR provider]]></title>
<description><![CDATA[Not all managed detection and response (MDR) solutions are equal. Finding the differences between vendors can be quite hard, and then understanding how those differences impact your business can be even harder. For instance, you may come across an MDR provider whose pricing is based on how much d...]]></description>
<link>https://tsecurity.de/de/3572994/it-security-nachrichten/how-the-swiss-cheese-model-can-help-you-choose-the-right-mdr-provider/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3572994/it-security-nachrichten/how-the-swiss-cheese-model-can-help-you-choose-the-right-mdr-provider/</guid>
<pubDate>Thu, 04 Jun 2026 16:52:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Not all managed detection and response (MDR) solutions are equal. Finding the differences between vendors can be quite hard, and then understanding how those differences impact your business can be even harder. For instance, you may come across an MDR provider whose pricing is based on how much data you ingest rather than the number of assets you protect.</p><p>Ingestion-based solutions have the potential to be more cost effective if you're selective about what security telemetry you ingest – but then who analyzes the impact of the logs you're leaving out until they're needed?</p><p>Or, consider an MDR solution that's more EDR with just a few additional log sources. For some organizations this is a perfectly optimal fit. But, how often are logging blind spots reviewed and accepted as a risk? In my experience, very rarely.</p><p>I like to spend time educating customers on the importance of defense in depth, and partners on how to clearly demonstrate its importance when it comes to catching and stopping attacks.</p><h2>The Swiss Cheese model</h2><p>One of my favorite ways of explaining defense in depth is the “<a href="https://lnkd.in/ef8Ga4MB" target="_blank">Swiss Cheese model</a>.”</p><p></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltf31ce0077376ea58/6a2183e387294e63546d2ce0/image2.png" alt="image2.png" caption="Figure 1: The Swiss Cheese model" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="image2.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltf31ce0077376ea58/6a2183e387294e63546d2ce0/image2.png" data-sys-asset-uid="bltf31ce0077376ea58" data-sys-asset-filename="image2.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 1: The Swiss Cheese model" data-sys-asset-alt="image2.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 1: The Swiss Cheese model</figcaption></div></figure><p>⠀</p><p>It's a risk model successfully used across industries like aviation safety, engineering and other domains. Its guiding principle is that a single safeguard is not fool-proof when it comes to mitigating accidents, and that true resilience is dependent upon multiple layers of monitoring and control.  </p><p>The great thing about this model is that it translates really well when it comes to security operations and the technologies (SIEM) and services (MDR) that underpin it. In the case of these solutions, each slice of “cheese” is a combination of log source and detection rules across multiple attack surface domains - think endpoint, identity, cloud, or network – each reinforced by multiple log sources and detection rules that ladder up to those domains.</p><ul><li>The <strong>log source</strong> is half of the “cheese layer,” providing the raw information. </li><li><p>The <strong>detection rules</strong> that help us spot attackers’ actions are the other half of the “cheese layer.”</p></li></ul><p>The logs and detection rules working in combination is what represents the whole slice of cheese.</p><p>For example, let’s say you have an agent capturing activity on all of your servers and endpoints. But, an attacker has managed to steal some VPN credentials to log in to your corporate environment like a normal user. There is no agent on the attacker’s machine, only on corporate users’ machines.  </p><p>Their next step is to enumerate the environment, which can be a combination of passive monitoring and active scanning. Their task? Finding that next stepping stone so they can ultimately make their way to gaining domain admin credentials or exfiltrating data from the environment as an example.  </p><p>There are lots of activities the attacker can implement to achieve this without alerting any agents.. But, what if we have some log sources monitoring active directory, firewall/VPN access, and even a network-based sensor monitoring traffic going in and out of the firewall? It means we can gain additional visibility, capturing this malicious activity before it escalates.</p><p>Other methods of initial access – like phishing – can also be captured through adding log sources for email solutions and any other email-related activities. An example could be changing email inbox rules so that an unsuspecting user can't see all the replies to the emails the attacker is sending from their mailbox.  </p><h2>What are the “holes” of the cheese slice? </h2><p>Not every log source is able to capture every malicious activity from an attacker, which is why we need multiple layers. The holes can be for a few reasons - visibility gaps in the log source e.g. if you only have your EDR installed on 90% of the assets that can have it installed there is a clear hole. There are also detection rule shortfalls - either a rule does not exist to alert on that activity when it occurs or perhaps the log source is limited in how it records the behavior which makes creating a detection not possible. </p><p>This the whole foundational principle of Swiss cheese theory, that we should expect an attacker to be able to circumvent a single layer</p><h2>How do we know what log sources and detections we need?</h2><p>For each type of asset in your environment, it's a great idea to draw up a Threat Model. For the purposes of this blog, the below model is fairly high level. An organization-specific threat model should go more in depth, but hopefully you can get the general idea.</p><ul><li>Group types of assets together where it makes sense. For instance:</li><ul><li>Windows and Mac work stations </li><li>Billing servers</li><li>CRM</li><li>Network equipment and firewalls</li><li>Domain controllers</li></ul><li><p>Think about how an attacker might attempt to use these assets either to monetize the environment (i.e. ransomware) or as a stepping stone to a more critical asset.</p></li><li><p>Think about the log sources that would contribute towards highlighting attacker activity on those assets. For instance:</p></li><ul><li><p>Windows and Mac workstations </p></li><ul><li><p>EDR agent</p></li><li><p>Email logs</p></li><li><p>VPN/firewall authentication logs</p></li><li><p>Single sign on (SSO) logs</p></li></ul><li><p>Domain controller</p></li><ul><li><p>Lightweight directory access protocol (LDAP) and Active Directory logs</p></li><li><p>EDR agent</p></li><li><p>Network sensor</p></li></ul></ul></ul><p>As I stated, this is high-level and not exhaustive, but the idea is to think of the attacker’s actions and all of the potential log sources that could detect those actions in order to ensure you’re able to capture this activity.</p><p>Of course, this model might come under scrutiny when looking at the costs of ingesting and storing log data. Organizations then have to balance the cost of technical detections with the value they provide. In real terms, if you must choose three out of five log sources because that's what you can afford, you should pick the three most valuable to your business.  </p><p>The value should come from a combination of the number of detections they drive and the quality of those detections. For example, one log source might drive 1,000 detection types, but the detections themselves have a high benign positive ratio (say 29 in 30 are benign) on 80% of the detections, whilst another log source might drive 500 detections but have a much lower benign positive ratio of 1 in 10. This forces detection engineers to create the most optimal log-and-detection rule sets in order to optimize the cost of the SIEM.</p><h2>Cheese with a complex flavor is nice, overly complex MDR pricing is not</h2><p>All those calculations above sound complex, right? Much of that complexity can be made simpler with an asset-based pricing model, such as the one used by Rapid7. </p><p>The price is fixed on the number of servers and workstations, and customers can connect any number of log sources. This means when you’re modeling threats and detection of those threats, there are no cost constraints to consider for onboarding additional log sources, which would improve detection fidelity. </p><p>With that in mind, here’s a few questions I would suggest customers ask themselves to establish which solution is the right one for them:</p><p>Size: How big are you in terms of employees or number of assets?</p><p>A 5,000 employee business with a 20 person Security team is more likely to need a SIEM with unlimited ingestion than a 20 person business with one combined IT/security person. 	</p><p>Assets and tech stack: What types of assets are being protected and what technologies are in use?</p><p>This helps dictate whether an EDR with a few extra log sources is more suitable as the backbone of an MDR service versus One that incorporates a wide variety of telemetry sources.</p><p>Whilst the lines aren’t clear cut, these can be general areas to investigate and better understand. Other factors that also come into play are things like the type of threat actors that might target your organization.  Here is an example of what it could look like worked into a threat model I spoke about.</p><p></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt70fa087052afbded/6a2187c238d2480ac334dd8a/image1.png" alt="image1.png" caption="Tap to enlarge image" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="image1.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt70fa087052afbded/6a2187c238d2480ac334dd8a/image1.png" data-sys-asset-uid="blt70fa087052afbded" data-sys-asset-filename="image1.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Tap to enlarge image" data-sys-asset-alt="image1.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Tap to enlarge image</figcaption></div></figure><p>⠀</p><h2>Comparing solutions</h2><p>Attempting to compare asset-based and ingestion-based solutions can be tricky. If you try to constrain to a consistent set of log sources for the two solution types, you could be depriving your organization of the main benefit of an asset-based pricing structure: the ability to bring more log sources and detections – and therefore additional layers of protection – for the same cost. This would, of course, give you a lower cost-per-detection. Let’s take a look at some ideas that might help:</p><p><strong>Look at cost-per-detection when fixing a cost limit. </strong></p><ul><li>For example, you take the asset-based structure and solution cost, and configure an equivalent cost on an ingestion-based solution.  You then look at how many log sources and detections that gets you, then calculate the cost-per-active-detection. It’s also best to model this on your own or potential customers' environments.</li></ul><p><strong>Evaluate quality of detections within the model environment using the cost model constraint. </strong></p><ul><li>Running the same offensive exercises in the same environment is a fair test to run, so in this instance you should set up all the log sources for each model up to your cost constraint. Keep in mind you will likely have more log sources for an asset-based model. This is still a fair test, as our key comparison metric is total cost of the solution regardless of how that solution detects the attacker.</li></ul><p><strong>Detection noise under normal conditions. </strong></p><ul><li>This is an indication of the quality of the detection rules under normal conditions. It's great to detect attackers in an isolated environment, but in a production network with users working, it may also introduce many benign or false positives that the same detection rules will alert on. You want your detection rules to only alert on real attacker activity.</li></ul><p><strong>Give detection rules a score:</strong></p><ul><li>Did they detect the attack correctly?</li><li>Do they alert on normal user activity?</li><li>If so, how often within a 30-day window?</li></ul><table><tbody><tr><td><p><br></p></td><td><p><br></p></td><td><p><span><strong>MDR / SIEM Solution 1</strong></span></p></td><td><p><span><strong>MDR / SIEM Solution 2</strong></span></p></td></tr><tr><td colspan="4"><p><strong>Metric 1 - Solution Coverage</strong></p></td></tr><tr><td><p><br></p></td><td><p><span>Cost</span></p></td><td><p><span>$100,000.00</span></p></td><td><p><span>$100,000.00</span></p></td></tr><tr><td><p><br></p></td><td><p><span>Total Applicable log sources for example customer</span></p></td><td><p><span>30</span></p></td><td><p><span>20</span></p></td></tr><tr><td><p><span>Points</span></p></td><td><p><span>30</span></p></td><td><p><span>30</span></p></td><td><p><span>0</span></p></td></tr><tr><td><p><br></p></td><td><p><br></p></td><td><p><br></p></td><td><p><br></p></td></tr><tr><td colspan="4"><p><strong>Metric 1.5 - Solution Detection Value</strong></p></td></tr><tr><td><p><br></p></td><td><p><span>Cost</span></p></td><td><p><span>$100,000.00</span></p></td><td><p><span>$100,000.00</span></p></td></tr><tr><td><p><br></p></td><td><p><span>Total detection rules applicable to log sources</span></p></td><td><p><span>10,000</span></p></td><td><p><span>7,000</span></p></td></tr><tr><td><p><br></p></td><td><p><span><strong>Cost per Detection</strong></span></p></td><td><p><span>$10.00</span></p></td><td><p><span>$14.29</span></p></td></tr><tr><td><p><span>Points</span></p></td><td><p><span>30</span></p></td><td><p><span>30</span></p></td><td><p><span>0</span></p></td></tr><tr><td><p><br></p></td><td><p><br></p></td><td><p><br></p></td><td><p><br></p></td></tr><tr><td colspan="4"><p><strong>Metric 2 - Quality 1 - Offensive Testing in isolated environment</strong></p></td></tr><tr><td><p><br></p></td><td><p><span>Total tests conducted by offensive team</span></p></td><td><p><span>18</span></p></td><td><p><span>18</span></p></td></tr><tr><td><p><br></p></td><td><p><span>Total detections triggered per solution</span></p></td><td><p><span>15</span></p></td><td><p><span>16</span></p></td></tr><tr><td><p><br></p></td><td><p><span><strong>% of coverage</strong></span></p></td><td><p><span><strong>83%</strong></span></p></td><td><p><span><strong>89%</strong></span></p></td></tr><tr><td><p><span>Points</span></p></td><td><p><span>30</span></p></td><td><p><span>0</span></p></td><td><p><span>30</span></p></td></tr><tr><td><p><br></p></td><td><p><br></p></td><td><p><br></p></td><td><p><br></p></td></tr><tr><td><p><br></p></td><td><p><br></p></td><td><p><br></p></td><td><p><br></p></td></tr><tr><td colspan="4"><p><strong>Metric 3 - Quality 2 - rules triggered by normal user activity</strong></p></td></tr><tr><td><p><br></p></td><td><p><span>Total investigations triggered in 30 days</span></p></td><td><p><span>100</span></p></td><td><p><span>130</span></p></td></tr><tr><td><p><br></p></td><td><p><span>Total True Positive investigations in 30 days</span></p></td><td><p><span>90</span></p></td><td><p><span>87</span></p></td></tr><tr><td><p><br></p></td><td><p><span><strong>True Positive Ratio %</strong></span></p></td><td><p><span><strong>90%</strong></span></p></td><td><p><span><strong>67%</strong></span></p></td></tr><tr><td><p><span>Points</span></p></td><td><p><span>40</span></p></td><td><p><span>40</span></p></td><td><p><span>0</span></p></td></tr><tr><td><p><br></p></td><td><p><br></p></td><td><p><br></p></td><td><p><br></p></td></tr><tr><td colspan="4"><p><strong>Metric 4 - Monthly SOC operations overhead - tuning and detection rule writing (N/A for Managed)</strong></p></td></tr><tr><td><p><br></p></td><td><p><span>Hourly rate</span></p></td><td><p><span>$200</span></p></td><td><p><span>$200</span></p></td></tr><tr><td><p><br></p></td><td><p><span>Tuning time in hours over the last 30 days</span></p></td><td><p><span>10</span></p></td><td><p><span>12</span></p></td></tr><tr><td><p><br></p></td><td><p><span>Detection rule writing time in hours over the last 30 days</span></p></td><td><p><span>6</span></p></td><td><p><span>8</span></p></td></tr><tr><td><p><br></p></td><td><p><span><strong>Monthly soc operations overhead in $</strong></span></p></td><td><p><span><strong>$3,200.00</strong></span></p></td><td><p><span><strong>$4,000.00</strong></span></p></td></tr><tr><td><p><span>Points</span></p></td><td><p><span>10</span></p></td><td><p><span>10</span></p></td><td><p><span>0</span></p></td></tr><tr><td><p><br></p></td><td><p><br></p></td><td><p><br></p></td><td><p><br></p></td></tr><tr><td colspan="4"><p><strong>Metric 5 - Implementation time</strong></p></td></tr><tr><td><p><br></p></td><td><p><span>Hourly rate</span></p></td><td><p><span>$200</span></p></td><td><p><span>$200</span></p></td></tr><tr><td><p><br></p></td><td><p><span>Time to implement solution in hours for example customer</span></p></td><td><p><span>40</span></p></td><td><p><span>40</span></p></td></tr><tr><td><p><br></p></td><td><p><span><strong>Total PS cost for solution implementation</strong></span></p></td><td><p><span><strong>$8,000.00</strong></span></p></td><td><p><span><strong>$8,000.00</strong></span></p></td></tr><tr><td><p><span>Points</span></p></td><td><p><span>10</span></p></td><td><p><span>0</span></p></td><td><p><span>0</span></p></td></tr><tr><td><p><br></p></td><td><p><br></p></td><td><p><br></p></td><td><p><br></p></td></tr><tr><td><p><span>Total Points</span></p></td><td><p><br></p></td><td><p><span>110</span></p></td><td><p><span>30</span></p></td></tr></tbody></table><p>⠀</p><p>Whilst there are no absolutes, there are some good rules that can help you on the path to choosing an MDR provider that works best with and for your organization. Focusing on the assets and technologies that you want to protect, and looking at log sources and detections that support that is a great place to start.</p><p>The higher the importance and complexity of the asset, the more layers you ideally want, and having the table above to clearly define your quality metrics will help you consider whether a solution is the right fit for you in terms of technology, service, and economics.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-42349 | clerk javascript unusual condition (GHSA-w24r-5266-9c3c)]]></title>
<description><![CDATA[A vulnerability has been found in clerk javascript, shared, backend, nextjs, -react, react, vue, astro, nuxt, -expo, expo, react-router, tanstack-react-start, chrome-extension, fastify, express and hono and classified as critical. This impacts an unknown function. This manipulation causes imprope...]]></description>
<link>https://tsecurity.de/de/3572606/sicherheitsluecken/cve-2026-42349-clerk-javascript-unusual-condition-ghsa-w24r-5266-9c3c/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3572606/sicherheitsluecken/cve-2026-42349-clerk-javascript-unusual-condition-ghsa-w24r-5266-9c3c/</guid>
<pubDate>Thu, 04 Jun 2026 14:38:46 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/clerk:javascript">clerk javascript, shared, backend, nextjs, -react, react, vue, astro, nuxt, -expo, expo, react-router, tanstack-react-start, chrome-extension, fastify, express and hono</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. This impacts an unknown function. This manipulation causes improper check for unusual conditions.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2026-42349">CVE-2026-42349</a>. The attack can be initiated remotely. There is not any exploit available.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[The 5 common mistakes enterprises make when choosing AI tools (and how to avoid them)]]></title>
<description><![CDATA[Enterprises are rushing into AI. Here's where most go wrong and how to course-correct.]]></description>
<link>https://tsecurity.de/de/3572147/it-nachrichten/the-5-common-mistakes-enterprises-make-when-choosing-ai-tools-and-how-to-avoid-them/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3572147/it-nachrichten/the-5-common-mistakes-enterprises-make-when-choosing-ai-tools-and-how-to-avoid-them/</guid>
<pubDate>Thu, 04 Jun 2026 12:17:33 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Enterprises are rushing into AI. Here's where most go wrong and how to course-correct.]]></content:encoded>
</item>
<item>
<title><![CDATA[I Finished My Thesis Defense — A Journey to Mobile Forensic]]></title>
<description><![CDATA[I Finished My Thesis Defense — A Journey to Mobile ForensicThomas Shelby and May CarletonIf there is an award for making things complicated, I’d probably be the winner. The ultimate rule to graduate from uni is to do research that most likely you’ll be compatible with. Sure, I knew the theory, bu...]]></description>
<link>https://tsecurity.de/de/3571865/hacking/i-finished-my-thesis-defense-a-journey-to-mobile-forensic/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3571865/hacking/i-finished-my-thesis-defense-a-journey-to-mobile-forensic/</guid>
<pubDate>Thu, 04 Jun 2026 10:21:39 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>I Finished My Thesis Defense — A Journey to Mobile Forensic</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/600/1*-qr_oOHlW2HYH-AKY0eCmw.gif"><figcaption>Thomas Shelby and May Carleton</figcaption></figure><p>If there is an award for making things complicated, I’d probably be the winner. The ultimate rule to graduate from uni is to do research that most likely you’ll be compatible with. Sure, I knew the theory, but I don't know why — and in every aspect, I always ended up doing the complete opposite *duh.</p><p>Instead of doing research in the field of mobile forensics and choosing to do what I thought I was capable of doing, I improvised — a lot. I try to implement a model and it’s a kind of mixture of semantic web and mobile forensics. You know, I spent my holiday crying because I felt so dumb that I was incapable of understanding the idea that I wanted to bring. Guess what? Through hardship, patience, determination, and revelation from God who sent me a humble yet very chill supervisor who always encouraged me to finish my work, I finally did it.</p><p>You know what, sometimes it’s not the situation that going to kill you, but panic will. I was worried that I couldn’t do my thesis, but after I did it, I was more worried that my work was too simple to be presented for my thesis defense (it’s not that simple af girl you are joking writing this). Guess I just spent my time overthinking things and got panicked when everything is actually negotiable and under control hahaha my bad. I’ll talk about my thesis later, now I want to show you how to do basic mobile forensics most people do in digital forensics investigation. I think you’re going to like it even though I thought it boring by now.</p><h4>Prerequisites</h4><p>Let me inform you that we need some equipment and tools to do this process.</p><ol><li><strong>Mobile Phone</strong></li></ol><p>Get yourself a phone, it’s up to you whether you want to use an iPhone, smartphone, or that indestructible N*kia 3310 *LOL. I bought an Android specifically for my thesis but since there are some problems on my campus, by the time I wrote this article, our phones were still seized by authorities. I know shit happens and <em>c’est la vie </em>but never mind, <strong>I’ll use a virtual phone emulated by GenyMotion App for this tutorial, so I’m sorry if you cannot relate.</strong></p><p><strong>2. Platform Tools</strong></p><p>Okay, now you need to download the tool at this address, I’ll inform you later what the function is. Download based on the operating system that you used, Mac, Linux or maybe Windows? <a href="https://developer.android.com/tools/releases/platform-tools">https://developer.android.com/tools/releases/platform-tools</a></p><p><strong>3. Autopsy</strong></p><p>Same with the Platform Tools, choose what suits best with your operating system, and I’ll tell you about the function later. Here <a href="https://www.autopsy.com/download/">https://www.autopsy.com/download/</a></p><p><strong>4. Busybox</strong></p><p>I need to inform you that I’m going to use the Physical Acquisition method for the acquisition process, so it requires us to root the phone (<strong>don’t do this if you don’t want to lose your phone’s warranty and make it vulnerable to security issues</strong>). Well, for the rooting process, we’ll definitely need Busybox. Mine uses Busybox Pro, but you can download the tool via PlayStore.</p><p><strong>5. Ncat and USB cable</strong></p><p>Cause we’re going to do the mobile forensic process on our laptop, or should we call it a forensic workstation, we still need to connect them to our phone. For this case, a USB cable is particularly not needed to connect the phone to our laptop since I use a virtual phone, but the Ncat tool is a must since it helps us to build a connection between the two devices. Here downloads the tool at this address <a href="https://nmap.org/ncat/">https://nmap.org/ncat/</a></p><h4>The Steps</h4><p>Mobile device forensics is the science of recovering digital evidence from a mobile device under forensically sound conditions using accepted methods. Digital forensics investigation is kind of a tricky process to do because any mistake we make during the process could make the digital evidence presented to the court invalid. So doing this process requires discipline. The standard usually used for mobile forensics is NIST SP 800–101 Revision 1. That standard divided the forensics process into four phases, they are preservation, acquisition, examination and analysis, and the last reporting of digital evidence.</p><p><strong>Preservation</strong></p><p>NIST SP-800–101 Rev 1 stated that evidence preservation is the process of securely maintaining custody of property without altering or changing the contents of data that reside on devices and removable media. Preservation involves searching, recognizing, documenting, and collecting electronic-based evidence. When we use the actual mobile phone, the process consists of documenting the condition of the devices, like taking a photo of the evidence, front, behind, and also the battery capacity.</p><p>Also, the steps that need to be done are enabling airplane mode and then turning off the cellular data and Wi-Fi. We need to do that to make sure that there is no signal exchange in our device that may modify the current state of the data stored on the mobile device. Most of the time Faraday bag is used in isolation to shield the evidence from external signals. Also, we need to disable the GPS to maintain the integrity of location-related evidence. If GPS is active, it may continue to collect and update location information, potentially altering the data relevant to the time of the incident under investigation. By turning it off, you freeze the GPS data at a specific point in time.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*T00kmv7oWKLy9P8piWpP_w.png"></figure><p><strong>Acquisition</strong></p><p>After doing the preservation step, be ready for the acquisition process. Acquisition is needed since you cannot directly be involved with the evidence, this method helps to maintain a digital chain of custody, which is essential for ensuring that the evidence is admissible in court. It demonstrates that the evidence hasn’t been tampered with or altered during the investigation process. So, in short, you need to duplicate, copy or image the evidence in this step.</p><p>As I mentioned before, I’ll do the physical acquisition. Physical acquisition itself refers to the process of directly accessing and copying data from a mobile device's physical storage, this method involves creating a bit-by-bit copy or image of the device’s storage, including both user data and system files, at a low-level, binary level, etc.</p><p>Previously I asked you to download Busybox, now time to install it on your phone. Busybox has utilities called ‘dd’ (used for low-level copying of data) that will help us in creating disk images for forensic analysis.</p><p>Below, on the left side, you see that I haven’t installed Busybox on the phone. I just keep the setting into default then click the <strong>Install </strong>button and let the app do its work. Now move to your phone or in my case the virtual phone. Before you can do the physical acquisition, you need to do some settings on your phone to make sure that the device is granted access to debugging interfaces. Find the “About phone” part on your phone then search for the Build number, click that around 7–8 times until it states that the developer mode has been enabled.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*cXLFbrRIpI95rSUCnNwJ-g.png"><figcaption>,</figcaption></figure><p>Great, if the developer options have been activated you can go to Settings and click that part. Look at the right picture, in the Developer options go find Debugging options then mark the USB debugging part to allow USB debugging.</p><p>We’ve done it here, it’s not a rooting process, it’s just a basic setting to help the device connect with the forensic workstation. You can do physical acquisition without rooting the phone if the phone that you used is a virtual phone, like mine. When it comes to actual phones, believe me, mate the process is kind of complicated. I failed like 5 times only to do the rooting things, tired but this gal has goals.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*4o6dvd5X-lBIVRvZ5gRUbQ.png"></figure><p>Now it’s the game changer, remember I asked you to download the platform tools, eh? Now open it via Command Prompt and run the adb.exe using this command below.</p><pre>adb.exe devices</pre><p>Below on the right side is the virtual phone opened by the Genymotion app. The command above is used to check whether the device is connected to the forensic workstation or not. You see on the left side below that the IP address I got from my virtual phone already appears, meaning the device is already connected to my laptop.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*9YHYDZw38QIojW9RKvW5mQ.png"></figure><p>The platform tools I mentioned before contain the adb.exe that we previously ran to our terminal, but also the Genymotion app. It provides the adb.exe to let the virtual phone communicate with the laptop.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*SEpzmS83fA_NSGq5vS_AsQ.png"></figure><p>Now we’ll start to do imaging. First, allow the superuser access to the phone so that we can be root. Then open the adb.exe shell in Genymotion via the command prompt. Search the file “tools” first in Genymotion, you can track that through the path on my computer. Mine is C:\Program Files\Genymobile\Genymotion\tools . When you finish, you can run the command below to display the partition information of the phone. The part in the red square is the internal storage that we’re going to image, it’s around 5 GB.</p><pre>cat /proc/partitions</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*a10OjkiGIAxXLhg9oC4UGw.png"></figure><p>Now open both terminals, the adb shell from platform tools and also from the Genymotions, but before that make sure you already installed the Ncat tools on the laptop. Okay, keep in mind that to make it easy for you, from now on I’ll place the adb shell from the Platform Tools on the left side and the adb shell from Genymotions is on the right side.</p><p>Before we can do the imaging or extract data from a mobile phone to our forensic workstation, we have to make the two devices listen to each other, just like what they’ve said mate — communication is key. Port forwarding can facilitate this communication and make the extraction possible, so please hit the command below.</p><pre>adb forward tcp:8888 tcp:8888</pre><p>When the connection is successful, it will reply back with “8888” which is the number of ports that we choose to route traffic. Now move to the right side, the command dd will help us to read data from the /dev/block/sdb device file (from the phone) and then send that data over the network to another device listening on port 8888 (the laptop) using ncor Ncat.</p><pre>dd if=/dev/block/sdb | busybox nc -l -p 8888</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*F2LLaZX7vDeV2UA6k-YLcQ.png"></figure><p>Back to the left side, hit the command below to capture data from the network connection and save the output to a file for further analysis or processing. The output literally will be an imaging file with the .dd format and for this file, I give it a name callitatest.dd.</p><pre>ncat.exe 127.0.0.1 8888 &gt; youcannameitasyoudesired.dd</pre><p>The output will be saved in the same directory where you place the platform-tools. Wait patiently as you watch the sign mark in the red square keep blinking. The imaging process will take time depending on the storage capacity of your phone, it gradually increases from KB to GB as you see in the right picture.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*cPxDeXV9U3rNwQMIrUXJRQ.png"></figure><p>Well, well, well, see the left picture the process is done and as you can see the .dd file size is definitely around 5 GB just like I mentioned the virtual phone storage capacity from the beginning. Also, when the process is done, you’ll see the notification in the Genymobile’s CMD just like in the right picture.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*e7369wZSbr8p-RE7wgiQ8Q.png"></figure><p><strong>Examination and Analysis</strong></p><p>The examination process uncovers digital evidence, including that which may be hidden or obscured. The results are gained through applying established scientifically based methods and should describe the content and state of the data fully, including the source and the potential significance. Data reduction, separating relevant from irrelevant information, occurs once the data is exposed.</p><p>The analysis process differs from the examination in that it looks at the results of the examination for its direct significance and probative value to the case. Examination is a technical process that is the province of a forensic specialist. However, analysis may be done by roles other than a specialist, such as the investigator or the forensic examiner.</p><p>We’ll use Autopsy to do the examination and analysis. Yeah, all your sins will be revealed here. First, open the Autopsy and make a <strong>New Case</strong>.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*DV8Ax4POxSQ3EbTw2S0lnw.png"></figure><p>Give the case a name, like mine is Case1. After you finish just click the <strong>Next</strong> part.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*mde52FGVw5WmOWzAOX-80g.png"></figure><p>Just keep clicking Next until you find this part. In this part, you need to browse the .dd file that we acquired in the acquisition phase before. After done, just keep clicking Next.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Yek-l6UoWrF9oZYlEAbBrw.png"></figure><p>We need to configure the Ingest module here, please click <strong>Select All</strong>. The Ingest module is used to bring data from various sources into the Autopsy case management system. It helps with data acquisition, verification, and indexing, and allows for easy management and analysis of digital evidence within a case. It’s a critical component for forensic investigations, ensuring data integrity and efficiency in the analysis process.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*pjP6Zg4A_LEOWNOIbUyG1w.png"></figure><p>Keep clicking <strong>Next </strong>until the display looks like the picture below. Before you can do the examination and analysis, you’ll need to wait for the configuration until 100%.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*cPxqMnL6UhgF95wLm6X28w.png"></figure><p>When it’s already 100%, you can start doing the examination and analysis now. The process involves examining specific artefacts such as chat messages, call logs, GPS data, and other information relevant to your investigation. Also export any relevant data, and findings, or validate the analysis results by confirming that the findings are consistent with your expectations and that your analysis was conducted accurately.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*sGCWaflCrXmfjelQ41p-XQ.png"></figure><p><strong>Reporting</strong></p><p>Reporting involves creating a comprehensive overview of the investigation process, including the actions taken and findings. Effective reporting relies on thorough documentation of activities, observations, test results, and data interpretations. A well-crafted report is built upon robust records, notes, images, and data generated by tools. I’m not going to put the reports here because it will be too long, so don’t mind checking the NIST SP 800–101 Revision 1 document for the format and standard.</p><p><strong>Conclusion</strong></p><p>Whoever is struggling with the thesis, I feel you. With love…</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*-U23R5XeiL9ArNVI.jpg"></figure><p><strong>Reference</strong></p><p>[1] Ayers, R., Brothers, S., &amp; Jansen, W. Guidelines on Mobile Device Forensics. Retrieved October 25, 2023, from <a href="https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-101r1.pdf">https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-101r1.pdf</a></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=bba5a30f3184" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/i-finished-my-thesis-defense-a-journey-to-mobile-forensic-bba5a30f3184">I Finished My Thesis Defense — A Journey to Mobile Forensic</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-42342 | remix-run react-router up to 7.14.x Requests resource consumption (GHSA-8x6r-g9mw-2r78 / EUVD-2026-34000)]]></title>
<description><![CDATA[A vulnerability was found in remix-run react-router up to 7.14.x and classified as problematic. This issue affects some unknown processing of the component Requests Handler. The manipulation results in resource consumption.

This vulnerability is cataloged as CVE-2026-42342. The attack may be lau...]]></description>
<link>https://tsecurity.de/de/3571317/sicherheitsluecken/cve-2026-42342-remix-run-react-router-up-to-714x-requests-resource-consumption-ghsa-8x6r-g9mw-2r78-euvd-2026-34000/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3571317/sicherheitsluecken/cve-2026-42342-remix-run-react-router-up-to-714x-requests-resource-consumption-ghsa-8x6r-g9mw-2r78-euvd-2026-34000/</guid>
<pubDate>Thu, 04 Jun 2026 04:51:14 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/remix-run:react-router">remix-run react-router up to 7.14.x</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This issue affects some unknown processing of the component <em>Requests Handler</em>. The manipulation results in resource consumption.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2026-42342">CVE-2026-42342</a>. The attack may be launched remotely. There is no exploit available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-42211 | remix-run react-router up to 7.14.1 createBrowserRouter/ deserialization (GHSA-49rj-9fvp-4h2h / EUVD-2026-33999)]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in remix-run react-router up to 7.14.1. The impacted element is an unknown function of the file createBrowserRouter/. Executing a manipulation can lead to deserialization.

This vulnerability is handled as CVE-2026-42211. The attack can be exe...]]></description>
<link>https://tsecurity.de/de/3571315/sicherheitsluecken/cve-2026-42211-remix-run-react-router-up-to-7141-createbrowserrouter-deserialization-ghsa-49rj-9fvp-4h2h-euvd-2026-33999/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3571315/sicherheitsluecken/cve-2026-42211-remix-run-react-router-up-to-7141-createbrowserrouter-deserialization-ghsa-49rj-9fvp-4h2h-euvd-2026-33999/</guid>
<pubDate>Thu, 04 Jun 2026 04:51:11 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/remix-run:react-router">remix-run react-router up to 7.14.1</a>. The impacted element is an unknown function of the file <em>createBrowserRouter/</em>. Executing a manipulation can lead to deserialization.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2026-42211">CVE-2026-42211</a>. The attack can be executed remotely. There is not any exploit available.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-40181 | remix-run react-router up to 6.30.3/7.14.0 Relative URL redirect (GHSA-2j2x-hqr9-3h42 / EUVD-2026-33996)]]></title>
<description><![CDATA[A vulnerability was found in remix-run react-router up to 6.30.3/7.14.0. It has been declared as problematic. The affected element is the function redirect of the component Relative URL Handler. Such manipulation leads to open redirect.

This vulnerability is documented as CVE-2026-40181. The att...]]></description>
<link>https://tsecurity.de/de/3571015/sicherheitsluecken/cve-2026-40181-remix-run-react-router-up-to-63037140-relative-url-redirect-ghsa-2j2x-hqr9-3h42-euvd-2026-33996/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3571015/sicherheitsluecken/cve-2026-40181-remix-run-react-router-up-to-63037140-relative-url-redirect-ghsa-2j2x-hqr9-3h42-euvd-2026-33996/</guid>
<pubDate>Thu, 04 Jun 2026 00:53:34 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/remix-run:react-router">remix-run react-router up to 6.30.3/7.14.0</a>. It has been declared as <a href="https://vuldb.com/kb/risk">problematic</a>. The affected element is the function <code>redirect</code> of the component <em>Relative URL Handler</em>. Such manipulation leads to open redirect.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-40181">CVE-2026-40181</a>. The attack can be executed remotely. There is not any exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-33244 | remix-run react-router up to 7.13.1 HTML File createBrowserRouter/ HTML injection (GHSA-f22v-gfqf-p8f3 / EUVD-2026-33986)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in remix-run react-router up to 7.13.1. Affected by this vulnerability is an unknown functionality of the file createBrowserRouter/ of the component HTML File Handler. This manipulation causes HTML injection.

This vulnerability...]]></description>
<link>https://tsecurity.de/de/3571013/sicherheitsluecken/cve-2026-33244-remix-run-react-router-up-to-7131-html-file-createbrowserrouter-html-injection-ghsa-f22v-gfqf-p8f3-euvd-2026-33986/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3571013/sicherheitsluecken/cve-2026-33244-remix-run-react-router-up-to-7131-html-file-createbrowserrouter-html-injection-ghsa-f22v-gfqf-p8f3-euvd-2026-33986/</guid>
<pubDate>Thu, 04 Jun 2026 00:53:31 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, has been found in <a href="https://vuldb.com/product/remix-run:react-router">remix-run react-router up to 7.13.1</a>. Affected by this vulnerability is an unknown functionality of the file <em>createBrowserRouter/</em> of the component <em>HTML File Handler</em>. This manipulation causes HTML injection.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2026-33244">CVE-2026-33244</a>. Remote exploitation of the attack is possible. No exploit is available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-33245 | remix-run react-router up to 7.13.1 cross site scripting (GHSA-8646-j5j9-6r62 / EUVD-2026-33988)]]></title>
<description><![CDATA[A vulnerability was found in remix-run react-router up to 7.13.1 and classified as problematic. The impacted element is an unknown function. Such manipulation leads to cross site scripting.

This vulnerability is listed as CVE-2026-33245. The attack may be performed from remote. There is no avail...]]></description>
<link>https://tsecurity.de/de/3571012/sicherheitsluecken/cve-2026-33245-remix-run-react-router-up-to-7131-cross-site-scripting-ghsa-8646-j5j9-6r62-euvd-2026-33988/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3571012/sicherheitsluecken/cve-2026-33245-remix-run-react-router-up-to-7131-cross-site-scripting-ghsa-8646-j5j9-6r62-euvd-2026-33988/</guid>
<pubDate>Thu, 04 Jun 2026 00:53:30 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/remix-run:react-router">remix-run react-router up to 7.13.1</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. The impacted element is an unknown function. Such manipulation leads to cross site scripting.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2026-33245">CVE-2026-33245</a>. The attack may be performed from remote. There is no available exploit.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Colorado governor vetoes block on surveillance pricing as other states push for bans]]></title>
<description><![CDATA[Consumer advocates decry Democrat Jared Polis for ‘choosing to side with dominant corporations’ over workersColorado’s governor vetoed a bill on Tuesday that would have banned companies from using surveillance pricing to set workers’ wages and prices for consumer goods.The measure would have been...]]></description>
<link>https://tsecurity.de/de/3570640/ai-nachrichten/colorado-governor-vetoes-block-on-surveillance-pricing-as-other-states-push-for-bans/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3570640/ai-nachrichten/colorado-governor-vetoes-block-on-surveillance-pricing-as-other-states-push-for-bans/</guid>
<pubDate>Wed, 03 Jun 2026 21:18:27 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Consumer advocates decry Democrat Jared Polis for ‘choosing to side with dominant corporations’ over workers</p><p>Colorado’s governor vetoed a bill on Tuesday that would have banned companies from using surveillance pricing to set workers’ wages and prices for consumer goods.</p><p>The measure would have been the strongest in the nation against algorithmic pricing. While Maryland became the first state to approve a law <a href="https://www.theguardian.com/technology/2026/apr/29/maryland-grocery-stores-ban-surveillance-pricing">banning</a> surveillance pricing in grocery stores in April, Colorado’s proposed measure was more expansive.</p> <a href="https://www.theguardian.com/technology/2026/jun/03/colorado-governor-veto-ban-surveillance-pricing">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[From God of War to Until Dawn – seven reveals from last night’s PlayStation event]]></title>
<description><![CDATA[The PS5 era has been in some ways disappointing for Sony – on Tuesday, the company revealed a slate of games they hope will change that• Don’t get Pushing Buttons delivered to your inbox? Sign up herePlayStation’s future has looked a little uncertain these past few years. Although the PS5 has sol...]]></description>
<link>https://tsecurity.de/de/3569394/it-nachrichten/from-god-of-war-to-until-dawn-seven-reveals-from-last-nights-playstation-event/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3569394/it-nachrichten/from-god-of-war-to-until-dawn-seven-reveals-from-last-nights-playstation-event/</guid>
<pubDate>Wed, 03 Jun 2026 13:47:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The PS5 era has been in some ways disappointing for Sony – on Tuesday, the company revealed a slate of games they hope will change that</p><p>• <a href="https://www.theguardian.com/info/ng-interactive/2021/nov/24/sign-up-for-pushing-buttons-keza-macdonalds-weekly-look-at-the-world-of-gaming"><strong>Don’t get Pushing Buttons delivered to your inbox? Sign up here</strong></a></p><p>PlayStation’s future has looked a little uncertain these past few years. Although the PS5 has sold well and been very profitable, the brand is far from the runaway market leader it was in the PS2 days. Earlier this week, Game File <a href="https://www.gamefile.news/p/playstation-first-party-sales-decline">dug into</a> Sony’s most recent earnings reports to illustrate how PlayStation has been selling fewer and fewer of its own flagship games since a peak during the pandemic. About 54.1m copies of games either developed or published by Sony were sold in the 2018 financial year; in 2025, it sold 32.1m.</p><p>Sony has put out some great homegrown games since the PS5 was released in 2020, from Astro Bot to <a href="https://www.theguardian.com/games/2025/oct/02/ghost-of-yotei-review-deliciously-brutal-and-stunningly-beautiful-revenge-quest">Ghost of Yōtei</a>, but it has also had some expensive and very public failures and cancellations; PlayStation boss Jim Ryan, who retired in 2024, placed big bets on live-service games and only a few panned out (hello, Helldivers). Sony also seems to have rolled back on releasing its single-player PS5 games on PC after a polite interval of time, suggesting it wants to preserve what advantage and exclusivity it has.</p> <a href="https://www.theguardian.com/games/2026/jun/03/god-of-war-laufey-playstation-state-of-play">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[A retro-geeky Android home screen remix]]></title>
<description><![CDATA[One of the best parts about using Android is the good old-fashioned geeky fun that comes with finding new ways to improve your digital environment — and improve your day-to-day efficiency.



That capability manifests itself in all sorts of interesting freedoms that (cough, cough) other mobile pl...]]></description>
<link>https://tsecurity.de/de/3569115/it-nachrichten/a-retro-geeky-android-home-screen-remix/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3569115/it-nachrichten/a-retro-geeky-android-home-screen-remix/</guid>
<pubDate>Wed, 03 Jun 2026 12:18:06 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>One of the best parts about using Android is the good old-fashioned geeky fun that comes with finding new ways to improve your digital environment — and improve your day-to-day efficiency.</p>



<p>That capability manifests itself in all sorts of interesting freedoms that (cough, cough) <em>other</em> mobile platforms don’t trust their users enough to allow — from <a href="https://www.computerworld.com/article/4167383/android-taskbar.html">added on-screen elements</a> to <a href="https://www.computerworld.com/article/4158574/android-air-gesture.html">custom air gestures</a>, <a href="https://www.computerworld.com/article/4143157/android-multitasking.html">advanced multitasking additions</a>, and all sorts of <a href="https://www.computerworld.com/article/4136728/future-android-features.html">other shape-shifting enhancements</a> that can completely change the way you interact with your device.</p>



<p>Perhaps the most classic example of advanced Android customization, though, is a splendid little somethin’ called the home screen launcher — a fancy way of saying the system that controls how your home screen and app drawer look and work. Your phone has a built-in process that handles that by default, but here in the land o’ Googley matters, you can always replace that with something completely different and make your device adapt to the way <em>you</em> like to work instead of the other way around.</p>



<p>We’ve got no shortage of <a href="https://www.computerworld.com/article/1723954/android-launchers-for-enhanced-efficiency.html">interesting Android launcher options</a>, too, ranging from versatile <a href="https://www.computerworld.com/article/1723954/android-launchers-for-enhanced-efficiency.html#:~:text=1.%20Smart%20Launcher%3A%20Complete%20customization">blank slates for complete customization</a> to carefully crafted <a href="https://www.computerworld.com/article/1723954/android-launchers-for-enhanced-efficiency.html#:~:text=2.%20Niagara%20Launcher%3A%20Ergonomic%20efficiency">frameworks for ergonomic efficiency</a> and even <a href="https://www.computerworld.com/article/1723954/android-launchers-for-enhanced-efficiency.html#:~:text=4.%20Square%20Home%3A%20Windows%20Phone%20meets%20Android">throwbacks to mobile operating systems past</a>.</p>



<p>The real beauty of this ecosystem, though, is how much power it gives to Android developers — and subsequently to us, as Android-appreciating animals who embrace these creations! — to experiment and try out all sorts of new concepts. Sometimes, an Android launcher approach speaks to you for its practicality. Other times, it’s just a refreshingly interesting take on how you can get around your phone and get stuff done.</p>



<p>Today, I’ve got a perfect example to share with you. It’s a whole new approach to the Android home screen that’s both unlike anything else I’ve ever seen in this arena <em>and</em> delightfully familiar, in a retro-tech sense.</p>



<p>Lemme show ya what it’s all about.</p>



<p><strong>[Get fresh Googley goodness in your inbox with </strong><a href="https://www.theintelligence.com/android-cw/" target="_blank" rel="noreferrer noopener"><strong>my free Android Intelligence newsletter</strong></a><strong> — three new things to try every Friday.]</strong></p>



<h2 class="wp-block-heading"><strong>The T9 Android launcher — with a modern twist</strong></h2>



<p>My friend and fellow enlightened Android phone owner, allow me to introduce you to a creative little concoction called <a href="https://play.google.com/store/apps/details?id=com.loitran.minimalt9launcher.free" target="_blank" rel="noreferrer noopener"><strong>Key Launcher</strong></a>.</p>



<p>Key Launcher has only been out and available on the Play Store for a matter of weeks now, but it’s impressively polished — and, even more important, impressively <em>original</em> while also having some fantastic geek-tech throwback vibes.</p>



<p>To that end, the core distinctive element of Key Launcher is the T9-style dialpad that sits front and center on the lower third of its primary panel. It is quite literally the same set of letter-packin’ numbers and characters you’d see on an old-school phone — or in the dialer of your favorite <a href="https://www.computerworld.com/article/1613551/google-pixel-phone-calling-features.html">Android phone app</a>.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="1022" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption">The T9 keypad is the centerpiece of the Key Launcher Android home screen experience.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>And in this context, it serves some pretty interesting purposes:</p>



<ul class="wp-block-list">
<li>In true T9 style, you can find and access any app or contact on your phone simply by tapping the letter that corresponds with its name — and if you want to narrow down the list even further, you can <em>keep</em> typing letters to refine the results.</li>



<li>You can long-press any number to create and then access a custom “super shortcut” — anything from a single specific action (opening a particular app or calling or texting a certain contact) to launching a <em>group </em>or <em>category </em>of apps or contacts, launching an on-demand pop-up widget or swipeable <em>stack</em> of widgets, or even launching a pre-filled search query.</li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/key-launcher-android-popup-widgets.webp" alt="Key Launcher Android home screen widget pop-up" class="wp-image-4180239" width="900" height="940" sizes="auto, (max-width: 900px) 100vw, 900px"><figcaption class="wp-element-caption">One press, and poof: Any widget you want — or <em>series</em> of swipeable widgets, even — is right there and ready.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<ul class="wp-block-list">
<li>If you tap the # key (known as “pound” in this context — not “hashtag” — for any non-olds among us), you can set up and then access a special “vault” area, where apps are hidden and only visible and accessible with authentication.</li>



<li>And, in an especially nifty touch, you can also just use the dialpad as an actual <em>dialpad </em>— to punch in any number you want to text or call, even if it isn’t already in your contacts.</li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/key-launcher-android-home-screen-dialpad.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Key Launcher Android home screen dialpad" class="wp-image-4180245" width="1024" height="1021" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Your phone dialer is always right in front of you with Key Launcher as your home screen.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>Function-packed as all of that may be, that dialpad is still just one piece of the Key Launcher puzzle. Above it sits a grid of app shortcuts that includes both your own pinned favorites and a dynamic selection of recently opened items. And above <em>that</em> is a handy built-in widget that shows a rotating array of upcoming calendar events from your agenda along with the local time and weather — and, in an especially neat twist, can also be customized to act as an interactive stack that lets you flip through your own set of standard <a href="https://www.computerworld.com/article/1699499/must-have-android-widgets-for-busy-professionals.html">Android widgets</a> right then and there as well.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/key-launcher-android-home-screen-widget-stack.jpg?quality=50&amp;strip=all&amp;w=1022" alt="Key Launcher Android home screen widget stack" class="wp-image-4180241" width="1022" height="1024" sizes="auto, (max-width: 1022px) 100vw, 1022px"><figcaption class="wp-element-caption">Key Launcher’s primary widget spot can be configured to hold numerous widgets in a swipeable stack.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>Speaking of widgets, if you swipe toward the left on Key Launcher’s dialpad, you’ll reveal the launcher’s built-in “Widget Center” panel — which is an entire screen dedicated to holding however many widgets you want, in any configuration you like, for easy ongoing access.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/key-launcher-android-widget-center.webp" alt="Key Launcher Android home screen widget center" class="wp-image-4180238" width="900" height="936" sizes="auto, (max-width: 900px) 100vw, 900px"><figcaption class="wp-element-caption">The Widget Center is another interesting way to access widgets within Key Launcher.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>A swipe in the <em>other</em> direction will take you to an enlarged view of your active notifications, meanwhile, while a swipe downward can be set to launch either a quick search (of Google or whatever provider you prefer), a search of your <em>apps</em>, or a direct <a href="https://www.computerworld.com/article/1632804/android-app-shortcuts-google.html">Android app shortcut</a> within any app on your device.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/key-launcher-android-home-screen-swipe-action.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Key Launcher Android home screen swipe action" class="wp-image-4180242" width="1024" height="1015" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Swiping down on your home screen can trigger a shortcut of your choice.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>And if all of <em>that</em> seems like a lot of productivity-boosting possibilities, just wait ’til you get into this thing’s settings. Key Launcher is overflowing with options to customize and control practically every facet of its operation, ranging from basic visuals to the specifics of how the dialpad works and even a toggle for optimizing the interface for left- or right-handed use.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/key-launcher-android-home-screen-settings.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Key Launcher Android home screen settings" class="wp-image-4180243" width="1024" height="1016" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Key Launcher is no slouch when it comes to settings.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>Key Launcher is free on its base level with an optional Pro upgrade that unlocks certain limitations and more advanced features. That path is available for five bucks a year or $10 as a single lifetime purchase, and you get a month-long trial the first time you install the app so you can check it out in its full form.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/key-launcher-pro-upgrade.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Key Launcher Pro Upgrade" class="wp-image-4180240" width="1024" height="1004" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">The Pro path adds in lots of extras, but even Key Launcher’s free version is quite pleasant and functional.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>Even if you just stick to the free version, though, this thing has an awful lot to offer — and it really is unlike anything else out there, with so many clever and potentially useful touches.</p>



<p>It’s that kind of creativity and constant discovery that keeps Android so interesting and advantageous, even after all this time — and that’s true whether you end up sticking with Key Launcher for the long haul or just giving it a go for a few hours and appreciating the deliciously original thinking it offers.</p>



<p><em>Keep the geeky goodies coming with </em><a href="https://theintelligence.com/android-cw/" target="_blank" rel="noreferrer noopener"><strong><em>my free Android Intelligence newsletter</em></strong></a><strong><em> </em></strong><em>— three new things to try every Friday, straight from me to you.</em></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,33ms -->